Any activity at JDFPG? Perhaps they’ve ordered a lot of pizza delivery today? 🤔 #auspol #FVEY #Iran
Atomic Mail has been launched as a next-generation encrypted email platform, designed to address growing concerns over digital privacy and cybersecurity threats. With client-side encryption, zero-access architecture, and decentralized account recovery. Based in Tallinn, Estonia, a country with great internet privacy laws.
Link: https://atomicmail.io
#atomicmail #bigbrother #email #encrypted #encryption #fvey #privacy
Hi #FVEY we need you
This could be very, very bad for the US.
The #FVEY won’t be too happy, either.
#cybersecurity #Aukus
RE: https://bsky.app/profile/did:plc:ycqyqrun3gujy7wf5ymftpio/post/3llxg3j33nc2y
Alec’s Personal, Utterly Speculative Opinion: Why does the UK Government want a Backdoor into Apple iCloud Encryption? Answer: “Corporate & Foreign Government Espionage for Five Eyes”
In case this is not clear enough from the headline, I’ll repeat: the following is utterly personal and very speculative speculation re: why the UK Home Office are pursuing a backdoor into Apple’s iCloud product, a privacy weakness that will be local in scope but global in nature — although we can all be reassured that they pinky-promise to be nice and not abuse that privilege.
All this said: since ~1990 I have, almost non-stop, sought to promote adoption of — and prevent restriction upon — cryptography, so maybe my opinion now carries a bit of weight.
Therefore:
I believe that the purpose of the UK TCN backdoor into iCloud is primarily to enable Corporate, Government, & various other Espionage across Five Eyes
That’s it. There’s also a bit of historical baggage which the late and lamented Professor Ross Anderson used to describe along the lines of:
“…[elements within] the UK Home Office believe, and have always believed, that they have a god-given right to read all message content…”
(personal communication)
— and they’ve been trying to hold back the flood of encryption for 40 years, so why stop now? But…
Answer: Corporations & Governments using MDM.
Rationale
ADP is both a nerd technology, and a niche technology; it’s not the default. It might provide a protective blanket for content generated and shared by a bunch of terrorists or abusers who are simultaneously smart enough to enable it, but yet stupid enough to open themselves to seriously well-resourced tracking and analysis of their metadata footprint.
But you know who will really be making major, mass use of ADP?
Answer: big corporations and governments which switch it on for hundreds, perhaps even many thousands of iPhones at a time, by means of Mobile Device Management (MDM).
Brazilian mining companies that compete with Canada and the USA, the UK spying on Belgian Telcos, there are legion reasons for spying on corporates around the world, and as GCHQ puts it:
https://www.gchq.gov.uk/information/investigatory-powers-act
These grounds are that interception is necessary:
- In the interests of national security; or
- In the interests of the economic well-being of the UK; or
- In support of the prevention or detection of serious crime
IPA also requires safeguards to be in place to limit the use of intercepted material and related communications data.
The act itself constrains those powers:
A targeted interception warrant or targeted examination warrant is necessary on grounds falling within this section if … in the interests of the economic well-being of the United Kingdom so far as those interests are also relevant to the interests of national security
But continues…
A warrant may be considered necessary … only if the information which it is considered necessary to obtain is information relating to the acts or intentions of persons outside the British Islands.
…which (“may?”) does not strike me as a terribly onerous nor an insurmountable barrier to operation, especially if this is all hush-hush top-secret.
tl;dr
I can’t see any incremental benefit to the pursuit of abusers and terrorists to be worth the necessary expenditure of political capital necessary to obtain a backdoor into Apple iCloud.
But: I can totally see an “economic well-being” cost/benefit argument.
#apple #endToEndEncryption #feed #fvey #homeOffice #surveillance #tcn
Alec’s Personal, Utterly Speculative Opinion: Why does the UK Government want a Backdoor into Apple iCloud Encryption? Answer: “Corporate & Foreign Government Espionage for Five Eyes”
https://alecmuffett.com/article/112813
#EndToEndEncryption #HomeOffice #apple #fvey #surveillance #tcn
“[Trump] wanted to eject Canada out of an intelligence-sharing group known as the Five Eyes that also includes Britain, Australia & New Zealand”
https://alecmuffett.com/article/112669
#fvey #trump
“[Trump] wanted to eject Canada out of an intelligence-sharing group known as the Five Eyes that also includes Britain, Australia & New Zealand”
The other four are going to have serious opinions about this, not least because they have a single shared monarchy:
I'm sure that Trump's threat to kick Canada out of Five Eyes didn't come out of nowhere. It's a reaction. My guess is Tulsi dug around in the office she should absolutely not be within 1000 miles of, and found out that Canada and hopefully others have limited their intelligence sharing to things that are not sensitive, and she complained to Cheeto Mussolini about it because she was personally hoping for some top secret gold she could leverage (Trump's own behavior being the model for others to follow). #coup #corruption #intelligence #FVEY #treason
Canada Taps into MUOS (Mobile User Objective System) Satellite System in Collaborative Effort with Space Systems Command 🇺🇸
#Canada #FMS #FVEY #MUOS #PartnertoWin #USSF
▶️ 1 new picture from U.S. Space Force/Command (DVIDS) https://commons.wikimedia.org/wiki/File:Canada_Taps_into_MUOS_%28Mobile_User_Objective_System%29_Satellite_System_in_Collaborative_Effort_with_Space_Systems_Command_%288715066%29.jpg
Leaked unofficially verified documents indicate that New Zealand was in the loop about a planned attack on Iran by Israel.
#5eyes #FVEY
https://edition.cnn.com/2024/10/19/politics/us-israel-iran-intelligence-documents/index.html
CAE Secures $250M to Support Canadian Government's MQ-9B SkyGuardian RPAS Program
https://www.defensemirror.com/news/36924/CAE_Secures__250M_to_Support_Canadian_Government_s_MQ_9B_SkyGuardian_RPAS_Program
#CAE #GeneralAtomicsAeronauticalSystems #GAASI #MQ9B #SkyGuardian #RPAS #GovernmentofCanada #RoyalCanadianAirForce #RCAF #InServiceSupport #ISS #NORAD #FiveEyesAlliance #FVEY #NATO #HellfireMissiles #Mk82Bombs @GeneralAtomicsAeronauticalSystems @RoyalCanadianAirForce @NORAD @NATO
“The Inspector-General has found significant failings in the GCSB’s hosting of a foreign partner’s system”
There’s a PDF linked in this tweet from the NZ Inspector-General of Intelligence Services, vaguely detailing how (presumably: US, UK, AU or CDN) foreign spooks parked a spooky surveillance “capability” on NZ soil and ran it without telling anyone, nor (worse) keeping proper records. Both are typical* but the latter deserves calling out as it’s yet more evidence that private industry can’t trust Governments to hold back-doors or “golden keys” to encrypted messaging. Quotes:
5.3. The record-keeping of the decision process was poor and there are significant gaps, which have made it difficult to identify reasons for certain decisions, particularly whether concerns about the capability were mitigated by redrafts to the MOU. There appears to be no substantive written legal advice, despite the GCSB’s General Counsel being involved throughout the process.
5.4. Despite the then acting Director-General anticipating that the Minister responsible for the GCSB would be informed about the capability and possibly asked to approve GCSB hosting the system, this inquiry found no evidence of the Minister being told about the capability […]
7. I found that the capability operated at GCSB:
7.1. without adequate record keeping;
7.2. without due diligence by GCSB on the capability tasking requests;
7.3. without full visibility for GCSB of the capability tasking;
7.4. without adequate training, support or guidance for GCSB operational staff;
7.5. with negligible awareness of the capability at a senior level within GCSB after the signing of the MOU in 2012 and until the system was shut down in 2020;
7.6. with no apparent access for GCSB to the outcomes of the capability’s operation at GCSB;
7.7. without any auditing;
7.8. without the required review of the MOU;
7.9. without due attention to the possibility, recognised within the Bureau, that support for the capability could contribute to military targeting; and
7.10. without clarity, in consequence, as to whether data supplied by the GCSB to the capability did in fact support military action.
The Inspector-General has found significant failings in the GCSB's hosting of a foreign partner's system. Read more here https://t.co/Zi8wa5OttB
— IGIS NZ (@igisnz) March 20, 2024
[*] as anyone who remembers the 1996 publication of this book already knows
“The Inspector-General has found significant failings in the GCSB’s hosting of a foreign partner’s system”
https://alecmuffett.com/article/109427
#fvey #gcsb #surveillance
Russian hackers shift to cloud attacks, US and allies warn
a joint advisory issued by the U.K.'s National Cyber Security Centre (NCSC), the NSA, CISA, the FBI, and cybersecurity agencies from Australia, Canada, and New Zealand warned that the Russian threat group is gradually moving to attacks against cloud infrastructure
#russia #russian #SVR #APT29 #cloud #cloudcomputing #FiveEyes #FVEY #security #cybersecurity #hackers #hacking #hacked
"How to Use a Pixel Tablet as a Secure Calling and Messaging Device" (using @calyxos)
https://yawnbox.com/blog/how-to-use-an-pixel-tablet-as-a-secure-calling-and-messaging-device/
this is a new blog post by me based on years of security and privacy research on these types of devices
feedback always welcome, i'm not perfect, and many different people have many different threat models
#google #android #pixel #tablet #security #cybersecurity #privacy #signal #baseband #nsa #fvey
Interesting deep dive into FVEY malware by Kaspersky: is it ONLY a crypto miner infection?
https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/
Albo cannot be both a reasoned diplomat and a subservient ally - Pearls and Irritations https://johnmenadue.com/albo-cannot-be-both-reasoned-diplomat-and-subservient-ally/ #FVEY++
Curious about how deep the surveillance-state goes? Here's a good article to start your trip down the rabbit hole. Make sure to bring plenty of snacks and water, this hole goes deep: https://cybernews.com/resources/5-eyes-9-eyes-14-eyes-countries/
#SurveillanceState #FVEY #FiveEyes #NineEyes FourteenEyes #COMINT #SIGINT #NSA #GCHQ #NATO #UKUSA :WeAreNameless: