Showing posts with label skype. Show all posts
Showing posts with label skype. Show all posts

Thursday, July 26, 2012

Skype makes chats and user data more available to police

The Washington Post has entered the discussion on Skype and cooperation with law enforcement with an interesting and more through canvass of the debate and the facts. It includes information obtained from unnamed insiders who the Post says are familiar with the situation.

But it does seem to affirm that Microsoft, consistent with its past track record of cooperation with law enforcement, can and does make customer information and chat records available to law enforcement. (Customer information would require a subpoena, which chat records would require a court order. What their thresholds are for non-US legal process or whether they will abide by non-American court orders is unclear.)

With respect to the actual contents of Skype audio or video calls, the article notes:

Surveillance of the audio and video feeds remains impractical — even when courts issue warrants, say industry officials with direct knowledge of the matter.

That could change if the FBI gets its wish to have VoIP services added to the Communications Assistance to Law Enforcement Act. Currently, such services are not required to be wiretap-ready.

Here's the Washington Post article:

Skype makes chats and user data more available to police - The Washington Post

Skype makes chats and user data more available to police

By Craig Timberg and Ellen Nakashima, Published: July 25

Skype, the online phone service long favored by political dissidents, criminals and others eager to communicate beyond the reach of governments, has expanded its cooperation with law enforcement authorities to make online chats and other user information available to police, said industry and government officials familiar with the changes.

Surveillance of the audio and video feeds remains impractical — even when courts issue warrants, say industry officials with direct knowledge of the matter. But that barrier could eventually vanish as Skype becomes one of the world’s most popular forms of telecommunication.

The changes to online chats, which are written messages conveyed almost instantaneously between users, result in part from technical upgrades to Skype that were instituted to address outages and other stability issues since Microsoft bought the company last year. Officials of the United States and other countries have long pushed to expand their access to newer forms of communications to resolve an issue that the FBI calls the “going dark” problem.

Microsoft has approached the issue with “tremendous sensitivity and a canny awareness of what the issues would be,” said an industry official familiar with Microsoft’s plans, who like several people interviewed for this story spoke on the condition of anonymity because they weren’t authorized to discuss the issue publicly. The company has “a long track record of working successfully with law enforcement here and internationally,” he added.

The changes, which give the authorities access to addresses and credit card numbers, have drawn quiet applause in law enforcement circles but hostility from many activists and analysts.

Authorities had for years complained that Skype’s encryption and other features made tracking drug lords, pedophiles and terrorists more difficult. Jihadis recommended the service on online forums. Police listening to traditional wiretaps occasionally would hear wary suspects say to one another, “Hey, let’s talk on Skype.”

Hacker groups and privacy experts have been speculating for months that Skype had changed its architecture to make it easier for governments to monitor, and many blamed Microsoft, which has an elaborate operation for complying with legal government requests in countries around the world.

“The issue is, to what extent are our communications being purpose-built to make surveillance easy?” said Lauren Weinstein, co-founder of People for Internet Responsibility, a digital privacy group. “When you make it easy to do, law enforcement is going to want to use it more and more. If you build it, they will come.’’

Skype was slow to clarify the situation, issuing a statement recently that said, “As was true before the Microsoft acquisition, Skype cooperates with law enforcement agencies as is legally required and technically feasible.”

But changes allowing police surveillance of online chats had been made since late last year, a knowledgeable industry official said Wednesday.

In the United States, such requests require a court order, though in other nations rules vary. Skype has more than 600 million users, with some in nearly every nation in the world. Political dissidents relied on it extensively during the Arab Spring to communicate with journalists, human rights workers and each other, in part because of its reputation for security.

Skype’s resistance to government monitoring, part of the company ethos when European engineers founded it in 2003, resulted from both uncommonly strong encryption and a key technical feature: Skype calls connected computers directly rather than routing data through central servers, as many other Internet-based communication systems do. That makes it more difficult for law enforcement to intercept the call. The authorities long have been able to wiretap Skype calls to traditional phones.

The company created a law-enforcement compliance team not long after eBay bought the company in 2005, putting it squarely under the auspices of U.S. law. The company was later sold to private investors before Microsoft bought it in May 2011 for $8.5 billion.

The new ownership had at least an indirect role in the security changes. Skype has endured periodic outages, including a disastrous one in December 2010. Company officials concluded that a more robust system was needed if the company was going to reach its potential.

Industry officials said the resulting push for the creation of so-called “supernodes,” which routed some data through centralized servers, made greater cooperation with law enforcement authorities possible.

The access to personal information and online chats, which are kept in Skype’s systems for 30 days, remains short of what some law enforcement officials have requested.

The FBI, whose officials have complained to Congress about the “going dark” problem, issued a statement Wednesday night saying it couldn’t comment on a particular company or service but that surveillance of conversations “requires review and approval by a court. It is used only in national security matters and to combat the most serious crimes.”

Hackers in recent years have demonstrated that it was possible to penetrate Skype, but it’s not clear how often this happened. Microsoft won a patent in June 2011 for “legal intercept” of Skype and similar Internet-based voice and video systems. It is also possible, experts say, to monitor Skype chats as well as voice and video by hacking into a user’s computer, doing an end run around encryptions.

“If someone wants to compromise a Skype communication, all they have to do is hack the endpoint — the person’s computer or tablet or mobile phone, which is very easy to do,” said Tom Kellermann, vice president of cybersecurity for Trend Micro, a cloud security company.

Some industry officials, however, say Skype loses some competitive edge in the increasingly crowded world of Internet-based communications systems if users no longer see it as more private than rival services.

“This is just making Skype like every other communication service, no better, no worse,” said one industry official, speaking on the condition of anonymity. “Skype used to be very special because it really was locked up. Now it’s like Superman without his powers.”

Monday, July 23, 2012

InfoWorld critical of Microsoft-Skype snooping accusations, calls for greater transparency

InfoWorld has posted a response to the Salon blog post that I blogged about yesterday (Skype cooperation with law enforcement and privacy policy weasel words), arguing that the post was inflamatory and designed to "push all the paranoia buttons". (See: Microsoft-Skype snooping accusations push all the paranoia buttons | Cringely - InfoWorld.)

The conclusion of the InfoWorld post echoes that of the Slate post and my own post:

What Microsoft should do is issue a transparency report similar to the ones released recently by Google and Twitter, detailing the many requests it receives for user data from various and sundry government authorities. It should also officially publish the guidelines authorities must follow in order to request information, as well as what types of data are available and how long they are retained. That document [PDF] was made available via a leak to Cryptome.org and is now four years old; I'd like a fresh copy, please.

That would be one way to dispel the notion that Microsoft is the evil bogeyman -- at least, more evil than all the other bogeymen. But it won't make for a very sexy headline.

It is about transparency. As I said yesterday, "Transparency/clarity = good. Weasel words = bad".

If Microsoft and Skype aren't clear about their abilities and their practices, people will make assumptions and they'll assume the worst. If calls for transparency are evaded, it's even worse.

Sunday, July 22, 2012

Skype cooperation with law enforcement and privacy policy weasel words

Ryan Gallagher at Slate's Future Tense blog asks whether Skype can intercept VOIP conversations and whether they provide such content to law enforcement. What's more troubling is how evasive Microsoft/Skype appears to be when asked a direct question:

But when I repeatedly questioned the company on Wednesday whether it could currently facilitate wiretap requests, a clear answer was not forthcoming. Citing “company policy,” Skype PR man Chaim Haas wouldn’t confirm or deny, telling me only that the chat service “co-operates with law enforcement agencies as much as is legally and technically possible.”

The post refers to the Skype privacy policy, which appears clear but is really sketchy:

Under Section 3 of the privacy policy, it is stated that Skype or its partners “may provide personal data, communications content and/or traffic data to an appropriate judicial, law enforcement or government authority lawfully requesting such information.” It also notes that instant messages sent over Skype will be stored for a maximum 30 days “unless otherwise permitted or required by law.”

Note the use of "lawfully requesting such information". There's a very real difference between a lawful request and a lawful demand. We have in our Canadian Criminal Code the following section:

Power of peace officer

487.014 (1) For greater certainty, no production order is necessary for a peace officer or public officer enforcing or administering this or any other Act of Parliament to ask a person to voluntarily provide to the officer documents, data or information that the person is not prohibited by law from disclosing.

In Canada, the police are permitted to ask, lawfully, in circumstances where they have no court order or production order, and therefore can't legally compel the information. (As an aside, I have seen on many, many occasions in my practice "request letters" from law enforcement that use this section as their "lawful authority" to demand information from service providers. Most service providers read this as a legally-enforceable demand that can't be declined.)

Skype isn't alone in this .... many other privacy policies use this sort of language which reserves to the operator the discretion of whether they'll require legal process that compels the production of information.

Transparency/clarity = good. Weasel words = bad.

See: Skype won't comment on whether it can now eavesdrop on conversations.

Sunday, February 12, 2012

What lawful access is all about and why it matters

The Canadian federal government is expected to table its latest iteration of "lawful access" legislation in Parliament this week. This is a BIG DEAL.

First, let's set the record straight: Assuming this bill is roughly the same as the last one that fell off the order paper, it will NOT allow warrantless access to the contents of any online communications. They can't read your email or watch you surf the internet, unless they get a warrant. But what it does is requires anyone who offers telecommunications services to the public (which would include Microsoft's MSN, Google Talk, Skype, etc.) to build in a backdoor so the police can wiretap it with a warrant. This involves, in many cases, compromising the security of these systems.

But it is expected to set up a system under which the police can get a huge list of non-content personal information without a warrant. And this is very bad.


Ask yourself this:

  • Should the police be able to get access to the names and addresses of anyone who shows up at a G20 protest? An Occupy* protest? A Stanley Cup riot? Parliament Hill? The PM's residence? An abortion clinic? A sketchy part of town? If this bill looks anything like the last, they will be able to on a whim without any judicial oversight. (All they need is an "IMSI Catcher" (here's an example of one meant for law enforcement and one made by some guy for $1500), which grabs the unique identifiers of all the cell phones within range and a request to the relevant telcos to hand over the names and addresses associated with the phones. Heck, they can ask for your e-mail address while they're at it.)
  • Should be police be able to get the name and address of someone who seems to be spending an inordinate amount of time perusing the Criminal Code on the Department of Justice website? They'll be able to do just that.
  • Should the police be able to get your name and address based on your web browsing activities without having to swear before a judge that there is any compelling reason to get it? If this bill looks anything like the last, they will be able to.
  • Should the police be able to get your e-mail address, IP address and phone numbers without any probable cause? Yup, they'll be able to get that too.

The Internet is not quite like the real world. When you go to a library or a book store, you don't have to provide ID or leave a record of what you looked at or that you were even there. When you step into a store in the real world, you don't necessarily leave a trace of what you perused and what you bought (if you paid cash). You can send an anonymous letter to the editor of your local newspaper to voice an unpopular opinion without giving your name or any other identifying information. (They probably will not publish it, but that's beside the point.) But the Internet doesn't work like that.

Every device on the network has an IP address. IP addresses can be tied to an individual computer or a range of computers sitting behind a firewall or a router. Every mobile device, such as a cell phone or a smart phone, has a number of unique identifiers that it chirps out to the network that it's attached to. Every interaction that you have online, you can assume is being logged in some fashion in connection with that IP address. Many e-mails you send include in the headers the IP address of the computer it was written on.

It's just the nature of how networks work. That IP can perhaps be traced to you, to your household or to your employer. In most cases, where residential internet accounts are concerned, they are connected to the name and address of the account holder. With phones, that identifier is connected to the individual who owns the phone.

Every mobile phone regularly chirps out its location so that the phone company can route calls to your device. Your phone company always knows where you are (if you have your phone with you and it's on). That chirping is also a transmission of identifying information about your phone, which can be readily intercepted by the police or national security organizations. If your phone can be connected to you personally, it's a beacon about you and under lawful access, it's readily available to them.

In short: Everywhere you go on the internet or with your mobile phone, you leave digital footprints. That's the nature of the modern, networked world. So what protects your privacy when you do anything online? The fact that whoever allocated that IP address or provides your cell phone service has to keep it confidential unless a judge decides that the public interest (or the state interest) overrides your privacy interest. That's why we have a Charter of Rights and Freedoms in Canada and why we have an independent judiciary. There is no absolute anonymity online, but there is effective privacy by obscurity because anyone who can connect your IP address to an individual is bound to keep it confidential unless a judge says otherwise.

However, lawful access takes that important balance away. It would give police forces and national security folks virtually unfettered powers to connect those otherwise anonymous footprints to an actual person (or small group of persons).

Don't get me wrong ... The police should be able to tap phones, track people and search computers, but all with a warrant. The only thing that stands in the way of police over-reaching and the destruction of civil rights is the Charter and independent judges who are called upon every day to decide where to strike the proper balance.

The government has suggested that we shouldn't sweat it, since the information the police would have access to is just like "phone book" information. That's simply not true. Only name and phone number appear in the phone book, which you can opt out of. Lawful access would permit the police to obtain any of the following:

    name,
  • address,
  • telephone number and
  • electronic mail address,
  • Internet protocol address,
  • mobile identification number,
  • electronic serial number (ESN),
  • local service provider identifier,
  • international mobile equipment identity (IMEI) number,
  • international mobile subscriber identity (IMSI) number and
  • subscriber identity module (SIM) card number that are associated with the subscriber’s service and equipment.

The phone number analogy is completely inappropriate. With a phone book, if you know the name you can get the number. If you know the number, you can get the name. Not a big deal. In this case, the police can have one piece of the above information and demand the ten other pieces of data. And they'd never be asking for it in isolation, but rather they think they've seen something sketchy and want to connect it to a person.

When lawful access was last before Parliament, it was completely devoid of any measures that could be used to protect against abuses other than a closed recordkeeping requirement and the ability of the privacy commissioner to audit. It did not require any report statistics of its usage to Parliament, as is the case for most wiretaps. No requirement to notify the subject of the investigation after the fact. No requirement that there be probable cause. No requirement that the requesting officer justify the demand. No requirement that there even be an actual investigation under the Criminal Code. No oversight whatsoever.

Supporters say "think of the children!" Or we in a war against terrorism! The law could have been tailored to only apply to actual lawful investigations of child exploitation or terrorism offenses, but the government did not do that. Instead, they designed a system that could be used to target people who -- shudder -- violate parking by-laws or engage in lawful expression. It seems purpose-built for fishing expeditions.

Some supporters suggest that getting a warrant is too cumbersome and time-consuming. This suggestion is often misleading: if it's an emergency (exigent circumstances), the cops can get this information right away. And every province has a system where warrants can be issued 24/7 over the phone from a duty judge. If it's too inefficient for most routine investigations, get more judges or streamline the process.

This is important and Canadians should educate themselves about it. Here are some great resources:

Monday, March 01, 2010

Drawing the curtain on ISP cooperation with law enforcement

My latest posting on slaw.ca:

Drawing the curtain on ISP cooperation with law enforcement – Slaw

I've been a faithful follower of Cryptome for quite some time. Cryptome has been posting very interesting and controversial content on the internet since 1996. It was the first WikiLeaks. Recent readers would note some publications that are very interesting for those who are interested a look at the level of cooperation of between internet service providers and law enforcement. Some of the reaction has been overblown, in my view. Nobody should be surprised that service providers hand over customer information in response to warrants and subpoenaes. Where the law requires it, banks do it, pharmacies do it, libraries do it and credit card companies do it. I think it would be shocking if service providers didn't have policies and procedures for this. What would be more troubling would be the extent to which service providers hand over information in the absence of a lawful requirement.

Most recently, Microsoft served a DMCA notice on Cryptome and its hosting provider, demanding that their Global Criminal Compliance Handbook be removed. Cryptome countered and Microsoft ultimately caved. My personal view is that service providers should make this information public so that customers really understand their digital footprints.

So if you want to see what Facebook, AOL, PayPal, MySpace, AOL and Skype will provide in response to a lawful demand, check out Cryptome.

And for lawyers, these documents will tell you what you can expect to get in response to a lawful demand.

Sunday, September 25, 2005

Skype security and privacy concerns

News that Skype has been bought by eBay has caused some concerns among privacy advocates, principally because eBay's policy of providing extensive user information to law enforcement, even without a warrant or subpoena. In his column in Security Focus, Scott Granneman writes:

Skype security and privacy concerns

"...I'm nearly speechless after reading Sullivan's comments. Think about what he's saying: if eBay receives a fax on offical letterhead (not that that would ever be faked, oh no) - just a simple fax, mind you, just a fax, unaccompanied by a court order - it will gladly fork over the following info about you, or any other eBay user:

  • Full name
  • User ID
  • Email address
  • Street address
  • State
  • City
  • ZIP code
  • Phone number
  • Country
  • Company
  • Password
  • Secondary phone number
  • Gender
  • Shipping information (including name, street address, city, state, ZIP)
  • Bidding history on an item
  • Items for sale
  • Feedback left about the user
  • Bidding history
  • Prices paid for items
  • Feedback rating
  • Chat room and bulletin board posts

Understatement of the week: that is one hell of a list! It's long, it's scary, and it's troubling. So what do we have? Software that says it's completely secure, but without a good way to verify that claim, now owned by a company that will basically give up an astonishing amount of personal information about you at the slightest peep from the authorities. This looks and smells bad. It's a questionable act to trust your personal and business phone calls, instant messages, and file transfers to Skype already, but it seems almost the height of foolhardiness to do the same now with a Skype owned by eBay...."

Thanks to Privacy Digest for the link.