Tuesday, October 24, 2017

National Gang Report - 2015

 
 
 
 
After I posted the link to the 2017 National Drug Assessment, some readers asked if there was a similar assessment for gangs in the United States. Yes, there is, but the latest public version of that report is 2015. It should be noted that the 2015 National Gang Report is not an extension of the 2013 or 2011 installments. Rather, it is an independent overview of data obtained between 2013 and 2015.
 
I recommend that you read each of these reports 2011, 2013, and 2015 to gain the most complete understanding of the national gang threat.

 


Monday, October 23, 2017

National Drug Threat Assessment - 2017

 
 
 
The Drug Enforcement Administration (DEA) released the 2017 National Drug Threat Assessment today.
 
You can download a PDF copy of the assessment here:
 
Over the past 10 years, the drug landscape in the United States has shifted, with the opioid threat (controlled prescription drugs, synthetic opioids, and heroin) reaching epidemic levels, impacting significant portions of the United States. While the current opioid crisis has deservedly garnered significant attention, the methamphetamine threat has remained prevalent; the cocaine threat appears to be rebounding; new psychoactive substances (NPS) continue to be a challenge; and the focus of marijuana enforcement efforts continues to evolve. Drug poisoning deaths are the leading cause of injury death in the United States; they are currently at their highest ever recorded level and, every year since 2011, have outnumbered deaths by firearms, motor vehicle crashes, suicide and homicide.
 
 



SecureDrop

 
 
SecureDrop is an open-source whistleblower submission system that media organizations can use to securely accept documents from and communicate with anonymous sources. It was originally created by the late Aaron Swartz and is currently managed by Freedom of the Press Foundation.
 
Review the SecureDrop web-site (listed above), and try the demo to see how the system works. A few news agencies that use SecureDrop are listed below. Reading their SecureDrop pages will provide additional tips for providing information anonymously.

Although SecureDrop is intended for media organizations to receive information from anonymous and confidential sources, any organization with the ability to set-up and run a server can install and use SecureDrop. Of course, it helps to have the clout and infrastructure of a major news service to maintain your SecureDrop and ensure that it isn't seized or otherwise compromised. Still, if you have an organization that needs to communicate with anonymous and confidential sources, SecureDrop may be an option.
 
 
 



Saturday, October 21, 2017

ProtonMail + TOR

 
I have previously recommended using ProtonMail to protect your personal communications. Now there is an additional reason to like ProtonMail. You can add a degree of anonymity to your ProtonMail by creating and always accessing your account via TOR. ProtonMail has created a TOR hidden service at https://protonirockerxow.onion. (You will, of course, need TOR installed on your computer in order to access this .onion web-site. Download your copy of TOR here: https://www.torproject.org.)
 
Additional details about the integration of ProtonMail and TOR can be found on the ProtonMail blog at: https://protonmail.com/blog/tor-encrypted-email/.
 
 





Financial Privacy - Opt-Out Info

 
 
According to the Federal Deposit Insurance Corporation (FDIC) companies that offer financial services may share your private financial information with others. Companies that offer financial services include:
  • Banks, savings and loans, and credit unions
  • Insurance companies
  • Securities and commodities brokerage firms
  • Retailers that directly issue their own credit cards (such as department stores or gas stations)
  • Mortgage brokers
  • Automobile dealerships that extend or arrange financing or leasing
  • Check cashers and payday lenders
  • Financial advisors and credit counseling services
  • Sellers of money orders or travelers checks.
 
According to Federal law these companies must send you an annual privacy notice, giving you the opportunity to opt-out of the sharing of some parts of your personal financial information with others. The FDIC points out that “Financial companies share information for many reasons: to offer you more services, to introduce new products, and to profit from the information they have about you… If you prefer to limit the promotions you receive or do not want marketers and others to have your personal financial information, you must take some important steps.”
 
Unfortunately, you cannot opt-out of all sharing of your private financial information. The law lets financial companies share your information for some purposes without your permission. For example, a financial company can share your private financial information with
  • firms that help promote and market the company's own products or products offered under a joint agreement between two financial companies
  • Records of your transactions--such as your loan payments, credit card or debit card purchases, and checking and savings account statements--to firms that provide data processing and mailing services for your company
  • Information about you in response to a court order
  • Your payment history on loans and credit cards to credit bureaus.
 
In these cases, you have no right to opt-out of the sharing of your private financial information. If you choose to do business with these financial companies, they can share and profit from your private financial data. However, you do have the right to opt-out of sharing of your private financial information for marketing purposes. When you receive a privacy notice in the mail from your financial companies, take a few minutes to read the notice and if you want to limit the sharing of your private financial information for marketing purposes – Opt-Out.
 
Examples of privacy notices can be seen at the following sites:
 
If you haven’t already reviewed the privacy notice from each of your financial companies, contact them and ask for a copy of the privacy notice and inform each of these financial companies that you wish to opt-out of the sharing of your information.
 
 
 

Thursday, October 19, 2017

Freeware Encryption

 
 
 
In 2001, I published a short book, “Freeware Encryption & Security Programs”. Although this book is now out of print, I have made a PDF copy of it available to readers of Chesbro on Security. You can download a copy from my Google Drive here: https://goo.gl/7YtDwY.
 
Some of the encryption programs I discussed in the book, are still available today. Others have been overtaken by time and technology, and are no longer available. The need and desire for encryption however have not gone away. New freeware encryption programs are now available to help you protect the content of your files, folders, and on-line communications.
 
Encryption should be used for everything, not a feature you turn on only if you're doing something you consider worth protecting. This is important. If we only use encryption when we're working with important data, then encryption signals that data's importance.  If only dissidents use encryption in a country, that country's authorities have an easy way of identifying them. But if everyone uses it all of the time, encryption ceases to be a signal. No one can distinguish simple chatting from deeply private conversation. The government can't tell the dissidents from the rest of the population. Every time you use encryption, you're protecting someone who needs to use it to stay alive.

A Google search for "encryption programs" will return a large number of results. The following encryption programs are some that I have used, at least to some extent while studying encryption.  Whether one program is better than the next depends on your specific needs, the computer operating system that you are using, and compatibility with what those with whom you share information are using to protect their own data. Experiment with the encryption programs on the following list. Save and use those programs that meet your personal needs.
   
AES Crypt (https://www.aescrypt.com)

Cyphr Encrypted Messaging App (https://www.goldenfrog.com/cyphr)

Encipher It (https://encipher.it)

GNU Privacy Guard (https://gnupg.org)

JavaScrypt: Browser-Based Cryptography (http://www.fourmilab.ch/javascrypt/)

miniLock (http://minilock.io)

Paranoia Text Encryption (PTE) (https://paranoiaworks.mobi)

Encryption is an essential part of your personal privacy and security, but it is not a 100% solution. Consider the following tips while choosing and using your encryption programs.
 
1) Hide in the network. Implement hidden services. Use Tor, I2P, Freenet, and VPNs to anonymize yourself. The less obvious you are, the safer you are.
 
2) Encrypt your communications. Use TLS. Use IPsec. While it's true that some agencies target encrypted connections - and may have explicit exploits against these protocols - you're much better protected than if you communicate in the clear. Woe betide whomever transmits plaintext.
 
3) Assume that while your computer can be compromised, it would take work and risk to do so - so it probably isn't. Still physical security is important and should be included in your overall personal security plan.
 
4) Be suspicious of commercial encryption software, especially from large vendors. My guess is that most encryption products from large US companies have back doors, and many foreign ones probably do as well. It's prudent to assume that foreign products also have foreign-installed backdoors. Closed-source software is easier to backdoor than open-source software. Systems relying on master secrets are vulnerable to adversaries, through either legal or more clandestine means.
 
5) Try to use public-domain encryption that has to be compatible with other implementations. For example, it's harder to backdoor TLS than BitLocker, because any vendor's TLS has to be compatible with every other vendor's TLS, while BitLocker only has to be compatible with itself, giving an adversary a lot more freedom to make changes. And because BitLocker is proprietary, it's far less likely those changes will be discovered. Prefer symmetric cryptography over public-key cryptography. Prefer conventional discrete-log-based systems over elliptic-curve systems; the latter have constants that governments influence when they can.
 
 


21-Day Personal Privacy Challenge

 
Day 1 – Register your telephone numbers with the National Do Not Call Registry (https://www.donotcall.gov/), and Opt-Out of sharing of your personal information with companies that offer credit and insurance (https://www.optoutprescreen.com/).
 
Day 2 – Install “HTTPS Everywhere” (https://www.eff.org/https-everywhere) and “Privacy Badger” (https://www.eff.org/privacybadger) in your Firefox, Chrome, or Opera browser. Install and run Malwarebytes (https://www.malwarebytes.com) and Bleachbit (https://www.bleachbit.org) or CCleaner (https://www.piriform.com/ccleaner) on your computer.  
 
Day 3 – Sign up for an end-to-end encrypted e-mail service such as ProtonMail (https://protonmail.com/) or Tutanota (https://www.tutanota.com/). Start using this new encrypted e-mail to protect your personal communications.
 
Day 4 – Stop using SMS/Text messages for personal communication. Switch to an end-to-end encrypted messenger such as Wickr (https://www.wickr.com/personal) or Signal Private Messenger (https://signal.org/).
 
Day 5 – Start conducting your on-line searches with a search engine that does not track you, such as DuckDuckGo (https://duckduckgo.com/) or Startpage (https://www.startpage.com/).
 
Day 6 – Set up two-factor authentication on all your on-line counts where it is available (https://twofactorauth.org). Use a hardware token, such as Yubikey, where possible or as the next best option use a software token such as Google Authernticator or Authy App.
 
Day 7 – Install a Password Manager. Examples of password managers include: LastPass (https://www.lastpass.com/), KeePassXC (https://keepassxc.org), Dashlane (https://www.dashlane.com), and 1Password (https://1password.com).  
 
Day 8 – Change all of your passwords. Use a very strong password, generated by your password manager, or use an external password generator such as the GRC Ultra High Security Password Generator (https://www.grc.com/passwords.htm) to generate new passwords.
 
Day 9 – Review and strengthen the privacy settings on all of your social media accounts. The US Army CID Computer Crime Investigative Unit provides guides to assist you in securing Facebook, Twitter, LinkedIn, Google Plus. Search the help settings on other social networks for ways to improve your privacy and security.
 
Day 10 – Order and review a copy of your credit reports (https://www.annualcreditreport.com/).
 
Day 11 – Protect your financial information by adding a Credit Freeze to your account with each of the major credit reporting agencies (https://www.consumer.ftc.gov/articles/0497-credit-freeze-faqs).
 
Day 12 – Search your name and other personal information on-line. Make note of where any of your personal information appears. Set up Google Alerts (https://www.google.com/alerts) to monitor the Internet for the appearance of any new information about you.
 
Day 13 – Protect access to your smartphone with a password or long numeric PIN. Avoid using fingerprint access, a swipe pattern, or the short 4-digit PIN to protect your smartphone.
 
Day 14 – Install VeraCrypt (https://www.veracrypt.fr/en/Home.html) and create a secure / encrypted volume to protect sensitive files on your computer. Alternately use BitLocker on your Windows computer or FileVault on your Mac computer to create this encrypted volume.  
 
Day 15 – Back up your important data and store it as an encrypted volume on some type of removable media (i.e. CD/DVD or USB Drive). Store this back-up someplace safe. Note that you can create a compressed and AES-256 encrypted archive using the free program 7-Zip (http://www.7-zip.org).
 
Day 16 – Make a list of all of your credit card numbers and the telephone number from the back of the card to call and report if your cards are lost or stolen. Store this list in a secure place.
 
Day 17 – Make a list of all your high value items (i.e. electronics, jewelry, firearms, collectables). Record the serial numbers, makes, models and other descriptive information. Include photos where appropriate. Include your automobile’s license plate number and VIN. Store this list in a secure place.
 
Day 18 – Improve your cybersecurity awareness by completing these three on-line courses from the DoD Information Assurance Support Environment (IASE):
Cyber Awareness Challenge (https://iatraining.disa.mil/eta/disa_cac2018/launchPage.htm)
Phishing Awareness (https://iatraining.disa.mil/eta/disa_phishing_v31_fy17/launchPage.htm)
Social Networking (https://iatraining.disa.mil/eta/disa_sn_v21_fy17/launchPage.htm)
 
Day 19 – Download a copy of TOR (https://www.torproject.org/). Start using TOR to protect your privacy and anonymity on-line.
 
Day 20 – Start using a Virtual Private Network (VPN) to improve your on-line security. Some VPN include: Private Internet Access (https://www.privateinternetaccess.com/),  Nord VPN (https://nordvpn.com/), VyprVPN (https://www.goldenfrog.com/vyprvpn).  
 
Day 21 – Consider Abine Blur (https://www.abine.com/index.html) and Privacy.Com (https://privacy.com) to protect your financial privacy.