Saturday, March 10, 2018

Regulation Banning Bump Stocks


Department of Justice Submits Notice of Proposed Regulation Banning Bump Stocks

Today (March 10, 2018) the Department of Justice submitted to the Office of Management and Budget a notice of a proposed regulation to clarify that the definition of "machinegun" in the National Firearms Act and Gun Control Act includes bump stock type devices, and that federal law accordingly prohibits the possession, sale, or manufacture of such devices.

Bump fire is a technique that anyone can learn in an afternoon. Banning bump fire stocks does nothing to limit the ability of a shooter to empty a magazine rapidly. While I am not a fan of bump fire stocks, or bump firing in general - it is not accurate and tends to waste ammo - there is no security benefit to banning bump fire stocks. Furthermore, there are other devices that allow rapid manipulation of a trigger, such as the BMF Activator. 

(Replacing the hand crank on the BMF Activator with a small electric motor would allow very rapid manipulation of the trigger with the press of a switch. Making this modification to a BMF Activator is likely illegal.)  

You Don't Need a Special Stock to Bump Fire, as can be seen in the following YouTube videos:

How to Bumpfire without a Bumpfire Stock

'Bump Fire' without a Bump-fire Stock, courtesy of ThatGunGuy45

How to Bump Fire without a Bumpfire Stock in Detail!

Former ATF Analyst - Bump Fire without Slide Fire Stock



FBI Secret Surveillance...


Senator Rand Paul (R-KY) published a link to the following NBC News article on his Facebook page on March 5, 2018:

The FBI's secret warrant to surveil Carter Page should scare all Americans and spur reform

As technology makes state scrutiny increasingly easy, America has seen a corresponding increase in the abuse of its surveillance tools. With a legal framework, first created in the 1970s - before the widespread use of computers, email or cell phones - the few safeguards we have are evaporating rapidly.

When a physical search occurs in accordance with American criminal law, law enforcement must show probable cause and obtain permission from a judge, and then present a given suspect with a warrant, and a receipt for the items removed. When law enforcement wants to obtain a criminal wiretap, they similarly have to show probable cause to obtain a warrant, carefully collect information related to potential crimes, and then disclose that information if charges are wrought. The key difference, is that with the latter, the suspect will only discover they've had their privacy violated after they've been indicted. With a FISC warrant, it's possible a suspect will never find out, even if charges are eventually filed.

In the case of Carter Page, his private life was monitored, for almost a year, without his knowledge, and then placed on display for strangers at the FBI to peruse, all based on a suspicion that he was colluding with Russia. On the basis of hearsay, business associations, and possibly Page's political opinions, the FBI received a classified surveillance warrant and then renewed it three times. And yet, Page was never officially charged - suggesting that, even given the ability to surveil him in ways that might make the general public cringe, the FBI was never able to find enough evidence for a single crime.

--

A February 27, 2018 article in Tech Crunch stated: "The warrantless surveillance law, otherwise known as Section 702 of the Foreign Intelligence Surveillance Act, gained mass attention back in 2013 when Edward Snowden leaked information that the NSA was using it to spy on Americans’ text messages, phone calls, emails and internet activity - all legally, and without warrants. That bill has been passed by the U.S. Senate for another six years and has now been signed into law by President Trump - a further extension of what should be an Orwellian clichĂ© but remains quite real... Senators Rand Paul (R-KY), Michael Lee (R-UT), Patrick Leahy (D-VT) and Ron Wyden (D-OR) agree, presenting a bipartisan letter to colleagues stating that "this bill allows an end-run on the Constitution by permitting information collected without a warrant to be used against Americans in domestic criminal investigations."

"Section 702’s intended purpose is to protect American soldiers, keep U.S. decision-makers informed about the intentions of adversary nations and help federal agents detect and prevent terrorist attacks on U.S. soil. However, the evaluation of 160,000 emails and instant messenger conversations collected under Section 702 between 2009 and 2012 (leaked by Snowden in 2013) showed that 90 percent of them were from online accounts that were not foreign surveillance targets, according to The Washington Post. And nearly half of those belonged to U.S. citizens or residents. That’s tens of thousands of emails from regular people, collected without our approval, say-so or, indeed, knowledge."

"It’s time to take this into our own hands. Privacy solutions and applications have been skyrocketing in demand, and with news that this law will likely prevail for another six years - as well as the recent scrapping of net neutrality - that demand is only going to increase as people seek to take their online security and privacy into their own hands."

--

The ability of the government, whether it is the FBI or your local police department, to conduct secret investigations, and create secret and hidden files where your personal information becomes part of a government database, record, or system of records is a significant threat to your privacy, violates your rights, and infringes upon your civil liberties.

If you are concerned about inappropriate investigations, and hidden records being kept about you, contact your Senator and/or Congressional Representative and express your concern.

A secret, non-adversarial system of judicial review is an insufficient check to our intelligence agencies and law enforcement.


Friday, March 9, 2018

Mind Your Data - A Guide to Regain Privacy from Wirtschaftsuniversität Wien


Mind Your Data - Your Guide to Regain Privacy and Control was written by: MSc. Information System students at Vienna University (WU) of Business and Economics.

In this guide WU students at the university's Privacy & Sustainable Computing Lab review privacy in messenger apps, social networks, map & location apps, calendar apps, and e-mail apps. They provide a comparison 'scorecard' for a selection of apps and services in the above categories.

** 25 online services are benchmarked as to their privacy friendliness; including Facebook, What‘sApp, Viber, Twitter, Instagram, GoogleMaps, Gmail, etc.

** Examples are given on why you should care to regain control over your data.

** Many practical tips by the students themselves.

Download it <here> for free.

I think that the guide is very well written, and recommend it to anyone interested in improving his or her personal privacy.
 
 

2018 Identity Fraud Study


Javelin Strategy & Research has released its 2018 Identity Fraud Study.

The study found that 16.7 million U.S. consumers were victims of identity fraud, an increase of eight percent over the previous year, and a record high since 2003 when Javelin Strategy & Research began tracking identity fraud.


Five Safety Tips to Protect Consumers

Javelin believes that consumers who exercise good online security habits can minimize their risk and impact of identity fraud. The following are five recommendations for consumers to follow:

Turn on two-factor authentication wherever possible - Enabling two-factor authentication on sites that have that capability, where a separate action must be taken beyond providing a user name and password to access an account, can make it significantly more difficult for fraudsters to take over your accounts. For sites without two-factor authentication, use strong passwords or a password manager to secure accounts.
   
Secure your devices - With consumers increasingly relying on their digital devices to obtain goods and services, making purchases and sharing personal information, criminals have shifted their focus to these devices for the access they can provide to accounts and the information they store or transmit. Secure online and mobile devices by instituting a screen lock, encrypting data stored on the devices, avoiding public Wi-Fi and/or using a VPN, and installing anti-malware.
   
Place a security freeze - If you are not planning on opening new accounts in the near future, a freeze on your credit report can prevent anyone else from opening one in your name - which is especially important if you have been a victim of data breach that has exposed sensitive personally identifiable information. Credit freezes must be placed with all three credit bureaus and prevents everyone except for existing creditors and certain government agencies from accessing your credit report. While costs vary per state, typically each bureau costs below $20. Should you need to open an account requiring a credit check, the freeze can be lifted through the credit bureaus.
   
Sign up for account alerts everywhere - A variety of financial service providers, including depository institutions, credit card issuers and brokerages, provide their customers with the option to receive notifications of suspicious activity - as do businesses in other industries, such as email and social media providers. These notifications can often be received through email or text message, making some notifications immediate, and some go so far as to allow their customers to specify the scenarios under which they want to be notified, so as to reduce false alarms.
   
Protect yourself from unauthorized online transactions - As EMV makes fraud at physical stores more challenging, fraudsters are moving to target online merchants. Some financial institutions offer alerts for online transactions, the ability to institute limits on online transactions, or even advanced controls through 3-D Secure (e.g., Verified by Visa, SecureCode from Mastercard, etc.). These can help quickly detect and even prevent online fraud from occurring.



Thursday, March 8, 2018

"Geek Squad" and the FBI


According to a March 6, 2018 article by the Electronic Frontier Foundation (EFF), Best Buy's "Geek Squad" employees are working as paid informants for the FBI.

The FBI uses Geek Squad employees to flag illegal material when people pay Best Buy to repair their computers. According to documents obtained by the EFF as part of a FOIA request "Best Buy officials have enjoyed a particularly close relationship with the agency for at least 10 years."

While Best Buy insists their employees are prohibited from searching customer devices beyond "what is necessary to solve the customer’s problem," EFF points that some Geek Squad workers were incentivized [paid] by law enforcement to gather further information.

FBI agents would come and confiscate any device on which technicians found illegal content, take it to a field office, and, in some cases, obtain a warrant to search the device. Several informants received payments from $500 to $1000 for their cooperation.

Critics have raised possible Fourth Amendment issues with this unusual practice. Best Buy is paid to search a customer's devices for the purpose of repair, but the FBI is supposed to obtain a warrant to do so. Providing a monetary incentive to employees would likely encourage them to perform searches that are unnecessary to the repair.  The FBI has been paying the Best Buy Geek Squad technicians to conduct warrantless searches of customer's computers, and then to notify the FBI if potential illegal content is found.

Fox News Digital - The FBI paid Geek Squad employees as informants (YouTube Video)


* Added in response to a comment: Computer technicians are specifically named as mandatory reporters in many states. This is no surprise to anyone, and it has been this way for many years (here is an article from 2008 that talks about this requirement). Everyone would agree that if you come across crimes against children during the course of your job, you should report it. What the EFF's (and many others') concern seems to be isn't that Geek Squad technicians found child pornography and reported it - they are required to do so - rather that the FBI recruited these technicians to conduct warrantless searches of computers brought to them for repair in an effort to find evidence of illegal activity. The question is whether the FBI can recruit confidential human sources (CHS) to conduct searches that they cannot do themselves without a warrant.


Wednesday, March 7, 2018

FOIA Gone Wrong


According to an article in the Chicago Tribune, the city of Aurora and its former records manager could be held legally responsible for endangering police officers by mailing their personnel files to an Illinois prisoner, according to a federal judge.

In an opinion and order denying the motion to dismiss the lawsuit, U.S. District Judge Sara L. Ellis stated the officers had met their burden for pleading their case under theories including state-created danger.

"Defendants perhaps confuse 'danger' with whether the private actor needs to actually commit harm to the plaintiffs for a state-created danger theory to apply," Ellis wrote. "If the government throws an individual into a snake pit, and the individual is not harmed by the snakes, but hurts himself escaping the pit, the government has still placed the individual in danger that has caused the individual harm."

In the above case, the records manager released information, in response to a FOIA request, that created a potential danger to the police officers now bringing this lawsuit. But it's not just information released through FOIA that can create this type of danger.

An even greater danger may be created when a government employee releases official information - "which includes all information that he acquired as part of his official duties or because of his official status" - outside of his own agency without going through the FOIA office. This can include releasing information to another agency, especially if that information has the potential to become public. Remember, if you received information during the course of your official duties you generally may not release that information to another agency, organization, or individual without following proper release and documentation procedures (i.e. FOIA).

That being said, a great deal of information may be released about you under FOIA if you are a military Service Member or Federal Civilian Employee.

32 CFR 505.7 - Disclosure of personal information to other agencies and third parties, states:

The Department of the Army is prohibited from disclosing a record from a Privacy Act system of records to any person or agency without the prior written consent of the subject of the record...

Despite Privacy Act protections, all records must be disclosed if the Freedom of Information Act (FOIA) requires their release.

The following are examples of personal information that is generally not exempt from the FOIA; therefore, it must be released to the public:

(i) Military Personnel -

(A) Rank, date of rank, active duty entry date, basic pay entry date, and gross pay (including base pay, special pay, and all allowances except Basic Allowance for Housing);
(B) Present and past duty assignments, future stateside assignments;
(C) Office/unit name, duties address and telephone number (DOD policy may require withholding of this information in certain circumstances);
(D) Source of commission, promotion sequence number, military awards and decorations, and professional military education;
(E) Duty status, at any given time;
(F) Separation or retirement dates;
(G) Military occupational specialty (MOS);
(H) Active duty official attendance at technical, scientific or professional meetings; and
(I) Biographies and photos of key personnel (DOD policy may require withholding of this information in certain circumstances).

(ii) Federal civilian employees -

(A) Present and past position titles, occupational series, and grade;
(B) Present and past annual salary rates (including performance awards or bonuses, incentive awards, merit pay amount, Meritorious or Distinguished Executive Ranks, and allowances and differentials);
(C) Present and past duty stations;
(D) Office or duty telephone number (DOD policy may require withholding of this information in certain circumstances); and
(E) Position descriptions, identification of job elements, and performance standards (but not actual performance appraisals), the release of which would not interfere with law enforcement programs or severely inhibit agency effectiveness. Performance elements and standards (or work expectations) may also be withheld when they are so intertwined with performance appraisals, the disclosure would reveal an individual's performance appraisal.

There are many reason that we may choose to safeguard our personal information. The fact that it may be released to others, either because of error, misconduct, or because it is required to be released under FOIA and similar state public records laws, should be ample incentive to limit what information about ourselves we allow to be included in government records.


EFF - Surveillance Self-Defense Site (redesigned)


The Electronic Frontier Foundation (EFF) has announced the launch of its redesigned Surveillance Self-Defense site, which now contains over forty guides in eleven languages, filled with tips on how to protect your communications and privacy online!

Surveillance Self-Defense (SSD) is a guide to protecting yourself from electronic surveillance for people all over the world. Some aspects of this guide will be useful to people with very little technical knowledge, while others are aimed at an audience with considerable technical expertise and privacy/security trainers. We believe that everyone's threat model is unique - from activists in China to journalists in Europe to the LGBTQ community in Uganda. We believe that everyone has something to protect, whether it's from the government or parents or prying employers, stalkers, data-mining corporations, or an abusive partner.