Showing posts with label u.k.. Show all posts
Showing posts with label u.k.. Show all posts

Wednesday, March 24, 2010

U.K. Internet Cafes Asked to Monitor Web Usage for Terrorism

After several terrorism related convictions in the U.K. where suspects were believed to have used Internet cafes, police are seeking cooperation for the cafe owners:
"The new initiative involves getting internet cafe owners to monitor the websites their customers view and to pass on any worries over suspicious activity to the police."
and additionally,
"The police want internet cafe owners to check the hard drives of their computers to help spot any suspicious activity."
It should probably go without having to say, there are critics of the program(me). One commentator is quoted::

"What is dangerous about this initiative is that it does not just focus on preventing access to illegal material but also material that is defined as 'extremist' without offering an objective definition of what that is.

"It thus potentially criminalises people for accessing material that is legal but which expresses religious and political opinions that police officers find unacceptable."


Anti-terror police seek help from internet cafes

Sunday, January 31, 2010

Wide Ranging Espionage by China in Britian

The Sunday Times reports on a leaked MI5 memo warning UK companies of extensive espionage by China including both traditional means and cyber attacks.

The targets are described as:
"UK defence, energy, communications and manufacturing companies in a concerted hacking campaign. It claims China has also gone much further, targeting the computer networks and email accounts of public relations companies and international law firms."

Several methods are mentioned in the article including "sexual entrapment" knowledge of "illegal activities to pressurise individuals to co-operate with them", bugging hotel rooms in China and other countries, and:

"...that undercover intelligence officers from the People’s Liberation Army and the Ministry of Public Security have also approached UK businessmen at trade fairs and exhibitions with the offer of “gifts” and “lavish hospitality”.

"The gifts — cameras and memory sticks — have been found to contain electronic Trojan bugs which provide the Chinese with remote access to users’ computers."

An important point, left to the end of the article, provides some insight into the seriousness that the UK government gives the problem:
"The growing threat from China has led [Jonathan] Evans [Jonathan Evans, the director-general of MI5] to complain that his agency is being forced to divert manpower and resources away from the fight against Al-Qaeda."

China bugs and burgles Britain

Tuesday, March 31, 2009

Intercept Modernisation Programme to Include Social Networks

Following the implementation of the EU Data Retention Directive requiring member states to retain communication traffic information for law enforcement, the U.K. developed the "Intercept Modernisation Programme".
"The Home Office already has plans to log details of all phone calls, emails and websites visited by web users in the UK, as part of a grander scheme, a massive "mother of all databases" under the "Intercept Modernisation Programme" umbrella."
The Home Office is now looking at expanding beyond the EU Directive to include communications between users of social networking sites such as Facebook and Twitter:
"The Home Office minister Vernon Coaker told MPs that the fact that the EU Data Retention Directive lacks some features is "why the Government is looking at what we should do about the intercept modernisation programme because there are certain aspects of communications which are not covered by the directive."
This, of course, is stirring a significant debate on civil liberties. However, when investigating large-scale crimes involving the Internet (and especially international activity), traffic analysis of communications is probably the single best investigative tool available and this is one of the arguments put forth by proponents of the activity:
"The government said that it will not be interested in what is being discussed but rather who talks to whom online, something that the government says is vital in preventing criminals and terrorists' communicating facilities."


As an aside:

The keywords "Intercept Modernisation Programme" generates more traffic to this blog than any other so I'm always interested in performing traffic analysis on the spike after an article on the subject is posted. Historically, over 80% of traffic can be traced to U.K. defense or other governmental contractors.

UK Government Plans To Monitor Social Networking Websites


Social network sites 'monitored'

Sunday, March 29, 2009

U.K. Intelligence Fears Chinese Made Telecommunication Systems

The Sunday Times report on U.K. intelligence officers' fear China may be able to disrupt British telecommunications via Chinese systems provided to British Telecom (BT):
"A confidential document circulating in Whitehall says that while BT has taken steps to reduce the risk of attacks by hackers or organised crime, “we believe that the mitigating measures are not effective against deliberate attack by China”."
The primary concern is BT using systems manufactured by Huawei:

"According to the sources, the ministerial committee on national security was told at the January meeting that Huawei components that form key parts of BT’s new network might already contain malicious elements waiting to be activated by China.

"Working through Huawei, China was already equipped to make “covert modifications” or to “compromise equipment in ways that are very hard to detect” and that might later “remotely disrupt or even permanently disable the network...”

Spy chiefs fear Chinese cyber attack

Friday, March 27, 2009

Cat and Mouse: Social Networks Help Protesters and Police

In a classic study of the power of online communications, social networking sites such as Twitter will be used both by protesters of the G20 meeting in London and by law enforcement to monitor the protesters:

"Marina Pepper, one of the organizers of G20 Meltdown, said that Twitter, the blogging tool that allows short updates to be filed, published and read via cellphones, would be used to coordinate the protests -- and warn participants of possible trouble.

"In terms of mobilizing people and shifting them around, Twitter will be used next week," Pepper told CNN. "We can also keep people empowered, because information is power."

"But Commander Simon O'Brien, one of the senior officers involved in policing security around the G20, said social networking sites would also be a "key area of our intelligence gathering."

"That's where we are picking up a lot of our intelligence about numbers and what certain groups are aiming to achieve," O'Brien said."


Protesters, police go online in G20 battle

Tuesday, March 10, 2009

Recommended Reading: Combating Extremists Online

The U.K. based International Centre for the Study of Radicalisation and Political Violence (ICSR) has released a paper on "Countering Online Radicalisation: A Strategy for Action".

This extensive report looks at a wide range of extremist-generated content on the Internet - from traditional terrorist organizations to white supremacist groups.

The paper begins with a look at why and how radical groups use the Internet. The power of the Internet (for all of society) is:
  1. Low cost of communication;

  2. Unlimited access knowledge;

  3. Create networks irrespective of boarders; and,

  4. Enables ‘risky’ or ‘embarrassing’ behavior.
However, extremist groups take this to, well, an extreme level:
  • "The internet can be used by extremists to illustrate and reinforce ideological messages and/or narratives. Through the internet, potential recruits can gain near-instantaneous access to visually powerful video and imagery which appear to substantiate the extremists’ political claims.

  • "The internet makes it easier to join and integrate into more formal organisations. It provides a comparatively risk-free way for potential recruits to find like-minded individuals and network amongst them, enabling them to reach beyond an isolated core group of conspirators.

  • "It creates a new social environment in which otherwise unacceptable views and behaviour are normalised. Surrounded by other radicals, the internet becomes a virtual ‘echo chamber’ in which the most extreme ideas and suggestions receive the most encouragement and support.
"It seems obvious, then, that the internet can have a role in intensifying and accelerating radicalisation. In fact, one may argue that the internet is of particular benefit to marginal and/or illegal groups and movements, because it facilitates the formation of (virtual) communities which would be more ‘risky’, if not impossible, to establish in the real world. There can be no doubt, therefore, that the internet is problematic, but is it the problem?"
The researchers propose four measures to combat online radicalization:
  • "Deterring producers - The selective use of takedowns in conjunction with prosecutions would signal that individuals engaged in online extremism are not beyond the law.

  • "Empowering online communities - The creation of an Internet Users Panel in order to strengthen reporting mechanisms and complaints procedures would allow users to make their voices heard.

  • "Reducing the appeal - More attention must be paid to media literacy, and a comprehensive approach in this area is badly needed.

  • "Promoting positive messages - The establishment of an independent start-up fund would provide seed money for grassroots online projects aimed at countering extremism."
The report looks at the pros, cons, tools and methods related to each of these areas. Of particular note, the paper rejects the all-to-common, knee-jerk reaction to just ban offensive material:
"Traditionally, most governments have focused on identifying technical solutions, believing that if somehow radicalising material can be removed from the web or made unavailable for viewing, the problem will go away. Yet, as this report has shown, any strategy that relies on reducing the availability of content alone is bound to be crude, expensive and counterproductive.

"The comparison with efforts to counter child sexual abuse on the internet is flawed, because much of the material involved in child sexual abuse is clearly illegal and there are no political constituencies which might be offended if repressive action is taken against it. Child sexual abuse is not a free speech issue, whereas radical political propaganda is.

"Any strategy hoping to counter online radicalisation must aim to create an environment in which the production and consumption of such materials become not just more difficult in a technical sense but unacceptable as well as less desirable."
The solutions offered are correct. The problem is, they are not easy answers and whether we are looking at protecting personal information in a commercial organization or combating extremists, most institutions only want easy answers.

Countering Online Radicalisation A Strategy for Action

Tuesday, February 17, 2009

New Arrest in Indymedia Investigation in the U.K.

The investigation of the online activist site, Indymedia, as discussed several weeks ago, continues in the U.K. with the arrest of an individual hosting a server for the group. Police are investigating the publication of personal information belonging to a judge in an animal rights trial.

This case is an excellent study of the conflicting issues related to free speech and political dissent, the need to investigative crimes, international and cultural differences concerning privacy and how laws passed to give investigative powers in one area (terrorism) are quickly applied in unrelated areas (invasion of privacy).

Indymedia's view of the situation and events is provided below:

"This Monday, Kent Police arrested a man in Sheffield under the Serious Crime Act 2007 in relation to the recent Indymedia server seizure. His home was raided, all computer equipment and related papers taken. He was released after eight hours. The person had neither technical, administrative nor editorial access to the Indymedia UK website. He was only associated to the project by hosting its server.

"The arrest took place under Section 44-46 of the Serious Crime Act, which was passed into law on 1st October 2008 to combat serious international crime like drug trafficking, prostitution, money laundering and armed robbery. Sections 44-46 refer to “encouraging or assisting offences”.

"Kent police claim that they are after the IP address of the poster of two anonymous comments to a report about a recent animal liberation court case, which included personal details of the Judge. The IP address of the poster is not stored as Indymedia does not log IP addresses. This was acknowledged by British Transport Police in 2005, after the Bristol IMC server seizure.

"For the police to arrest the person who happened to sign the contract for server hosting, is sheer intimidation, in light of Indymedia’s openly stated policy of no IP logging.

"With the implementation of the EU Data Retention Directive in March 2009, the UK government attempts to turn every internet service provider in the country into part of the law enforcement apparatus. This legislation will provide a legal basis to track, intimidate, harass, and arrest people who are doing valuable and necessary work for social change, for example as peace activists, campaigners for economic and social justice or against police brutality."

Also of interest are the comments to this post discussing activists perceptions of this situation and similiar issues encountered by other political activists around the world.

Monday, February 02, 2009

Indymedia Server Seized - A Lesson in Network Resilience

Indymedia - one of the largest international clearinghouses of news and information for social activism - was recently raided by police in the UK. The raid was apparently the result of an investigation into the publication of personal information belonging to a trail judge in a comment to an article on an animal rights trial.

Indymedia had already removed the offending article per their own policies, however, police seized a server containing a large quantity of information:
"...by seizing this server they [the police] are not only getting information on Indymedia but also on wholly unrelated groups."
However, the seizure of the server did not interrupt Indymedia operations. Indymedia's network is highly distributed and redundant with extensive mirroring of data:
"As with previous cases, Indymedia UK stayed online this time. This was possible due to a system of "mirrors", which was set up to protect the technical infrastructure of the alternative media project. Despite the resource intensive interruptions caused by server seizures, the DIY-media activists continue to provide a platform for "news straight from the streets"."
Although it appears the police were not attempting to censor the information, this case shows both the flexibility, power and dynamic nature of online communication. However, this resilience cuts both ways: Activists and other politically motivated sites are difficult to censor or disrupt, but likewise, when commercial or government sites are the target of online protests by hacktivists, their online attacks often have limited or no operational impact on their targets for the same reason.

Other case studies of this phenomenon are documented in Hacktivism and Politically Motivated Computer Crime.

Police Seize UK Indymedia Server (Again)

Wednesday, January 14, 2009

Online Attacks against Anti-War Group

The U.K. based anti-war group, "Stop the War", claims its website, Facebook and YouTube sites are being disrupted:

"Stop the War believes pro-Israeli groups could be behind the internet campaign, although a spokesman admitted it had no proof this was the case.

"A spokesman said of the cyber-war it was facing: "It's a well-known tactic. The same thing happened to us before our anti-Iraq war protests in 2003. We obviously can't prove any connection but the timing would suggest that it's a supporter of Israel."

"The spokesman told The Independent: "At the same time that our website was under attack, a number of videos went up on YouTube which claimed the demonstration had been cancelled. Someone posted notices on our Facebook groups saying the same thing."


Stop the War's website 'disabled by pro-Israeli hackers'

Monday, January 12, 2009

Radio Station Attacked by Jihadist Supporters

A U.K. radio station's website was defaced by Jihadist sympathizers in apparent support for Ahmed Al-Qahtani (who is suspected of involvement in the 9/11 attacks). The radio station also believes the attack may have been in retaliation for some of the Christmas music they had recently played.
"The site was compromised on Monday morning and again on Wednesday. The hijacker used the name ‘Soldier of Allah’ and ‘M03sl3m H4ck3rs’ - or Muslim Hackers written with numbers.

"The message warned: ‘Whoever thinks of insulting Islam or Muslims will suffer the same fate.
‘We are the nightmare of western websites in the cyber war.’

"The hackers claim they are defending Islam from harassment by America, Israel and Denmark."

Radio hijacked by Muslims as they are offended Cliff Richards halleluiah

Tuesday, January 06, 2009

U.K. Police Can Compromise Computer Systems without a Warrant

The U.K. Home Office has adopted plans to allow investigators to remotely search computers without a court order. The reports to date do not discuss the legal issues of using these techniques outside of the U.K.:
"Even though remote searching has existed in Britain since the '90s, when it was introduced as an amendment to the Computer Misuse Act, it has rarely been used until now and has been strictly controlled under the Regulation of Investigatory Powers Act. According to the new proposal, police forces or MI5 agents will be able to conduct such intrusive surveillance based merely on the decision of a senior officer that it is “proportionate” and necessary to the investigation of an offense that is punishable with a minimum sentence of three years in jail.

"In order to conduct the remote searching, the police will be able to act much like the cyber-criminals do, by developing malicious code, distributing the spyware via e-mail attachments, installing keylogging software or intercepting WLAN traffic. "

British Police Can Hack Computers Without Requiring Court-Issued Warrants

Friday, November 07, 2008

U.K. Interception Modernisation Programme

The U.K. government is reportedly considering requiring major ISPs to allow the gather Internet traffic data:

"At Monday's meeting in London representatives from BT, AOL Europe, O2 and BSkyB were given a presentation of the issues and the technology surrounding the Government's Interception Modernisation Programme (IMP), the name given by the Home Office to the database proposal.

"They were told that the security and intelligence agencies wanted to use the stored data to help fight serious crime and terrorism."

The Interception Modernisation Programme has received a lot of attention in the U.K. press lately including a proposal to invest billions of pounds in the programme:

"Detica will very likely be among the first to profit from the IMP bonanza. Based in Guildford, it might warrant the title of The Most Important IT Company Most People Have Never Heard Of. According to sources with knowledge of systems that have long allowed GCHQ to eavesdrop on phone calls, Detica owns and operates the current "black box" infrastructure under contracts funded by the secret intelligence budget.

"In contrast to that arrangement, the proposed central communications database would not target the content of calls, emails, texts and other communications; rather, MI6 and GCHQ want to retain the powerful, searchable data detailing who contacted whom."
As a side note, the keywords "interception modernisation programme" is a major driver of traffic to this blog...


Internet black boxes to record every email and website visit
Spy chiefs plot £12bn IT spree for comms überdatabase


Friday, September 19, 2008

U.K. Sentences 18 Year Old for Downloading Terrorist Material

Eighteen year old Hammaad Munshi was sentenced in the U.K. to two years in prison for using the Internet to gather terrorist related information:
"During his trial at Blackfriars Crown Court, the jury heard that Munshi had spent many hours viewing jihadist websites and had downloaded guides to making napalm, detonators and explosives."

Computer terror teenager jailed

Tuesday, March 25, 2008

Controlling Terrorism on the Internet

IEEE has posted an article on the difficulties of combating online terrorism including the most fundamental issue: What constitutes terrorism?

The article gives several examples in the U.K. of political attempts to ban content and the difficulties, both legal and technical, in actually establishing controls.
"Blocking websites also brings into play the incredibly labyrinthine arguments around just what is terror-inducing material. For example, a website that trumpets itself as a holy warriors' resource, complete with instructions on bomb-making, might easily be called a terrorist site and treated as such under law. However, what actions could—or should—an ISP take on an arborists' informational site that includes instructions on how to make a stump-blowing charge of black powder? Or is that arborists' site a front for a terror organization?"


Terror on the Internet: A Complex Issue, and Getting Harder

Thursday, March 20, 2008

Review: The National Security Strategy of the United Kingdom

The United Kingdom has released the first ever National Security Strategy "set[ting] out the Government's approach to dealing with threats to national security, ranging from war and terrorism to climate change, disease and poverty."

The report summarizes a wide range of threats and provides a comprehensive prevention and control strategy. Within the report are several references to national threats from computer crime:

Under the heading of "Defending the United Kingdom against state-led threats" the strategy defines the requirements as:
  • "...to defend the territory of the United Kingdom, its sea and air approaches, its information and communications systems, and its other vital interests..."
  • "On intelligence, in addition to the major effort required to tackle the current level of terrorist threat, the security and intelligence agencies will continue to protect the United Kingdom against covert activity by foreign intelligence organisations aimed at political, economic and security targets, including cyber-attack."

Under the heading "Responding to global trends" the report discusses a strategy to handle cyber incidents:
"In response to the technological challenges, we are committed to working with international, public, and private sector partners to ensure that our government systems and critical national infrastructure are adequately protected against cyberattack.

"We are also investing, through the interception modernisation programme, to update our intelligence and law-enforcement capability to meet the challenges of rapidly advancing communications technology. We are committed to maximising the opportunities and benefits of the internet, by protecting the freedom to develop and host new services, while also reducing the scope for terrorists and criminals to exploit those opportunities and freedoms, and ensuring that the internet itself is resilient enough to withstand attacks and accidents.

"Finally, we support international efforts to monitor and protect the safety and security of new technology including the internet and communications networks, and the space assets that are increasingly important for communications. We will continue to explore how new confidence‑building and arms control measures might contribute to international security in this area."

Finally, under the heading "The interdependence of threats, risks and drivers – an integrated response" the report discusses how many of the threats to the United Kingdom are interrelated and discusses how cyber threats will be managed:
"The Centre for the Protection of National Infrastructure (CPNI) was established in 2007 to act as an interdepartmental organisation providing advice on information, physical and personnel security to businesses and organisations across the national infrastructure. CPNI works closely with the private sector, delivering advice to reduce the vulnerability of critical infrastructure to terrorism and other national security threats."
The full report is available at:

The National Security Strategy of the United Kingdom

Friday, March 07, 2008

NATO Recognizes Cyber Threat and U.K. Tory Party Proposes 'Cyber Securiity Minister'

The Guardian is reporting on a speech by a NATO official that cyber attacks are a major concern of the organization:
"Suleyman Anil, who is in charge of protecting Nato against computer attacks, said: "Cyber defence is now mentioned at the highest level along with missile defence and energy security."
The article also mentions a new proposal from the U.K.'s Tory party to create a ministry level position on cyber security:
"To coincide with the congress, shadow home secretary David Davis will today announce Conservative proposals on online crime - including the creation of a new post of cyber security minister. The Tory plans also outline the reinstitution of a national hi-tech crimes police squad, and forming a dedicated unit inside the Crown Prosecution Service for dealing with computer crime cases."


Nato says cyber warfare poses as great a threat as a missile attack

Friday, January 18, 2008

U.K. Home Secretary Outlines Initiative to Target Online Extremism

The U.K. has announced an initiative to filter extremist information on the Internet.
"[Home Secretary] Jacqui Smith said she wanted to use technology to stop "vulnerable people" being "groomed for violent extremism".

"Because something is difficult, that is no reason not to have a go at it," she added. "The internet can't be a no-go area for government."

Few details were provided as to how this would be done.

Smith targets internet extremism

Wednesday, January 16, 2008

Insight into Al-Qaeda Use of the Internet

The Times Online published an article on Younes TSOULI aka "Irhabi 007", convicted in a U.K. court for "incitement to commit an act of terrorism through the internet."

"What makes Irhabi 007’s case so chilling is the evolution from simply setting up websites to becoming involved in terrorism itself. Increasingly he pined to go to Iraq to fight, and increasingly he became involved with others who were planning attacks. Two men who chatted with Tsouli online travelled from Atlanta, Georgia, to Canada to meet a group of extremists whom they knew from Tsouli’s forums, and then to Washington, where they took what are alleged to be reconnaissance videos of targets such as Capitol Hill. These videos were later found on Tsouli’s computer."

The article also discusses how the use of technology can be a two way street: It assists computer criminals but can also be used by investigators to track suspects and collect evidence:

"The power of the internet is its ability to put like-minded people in touch from every corner of the world. But the benefits for terrorists can also be an advantage for detectives when they catch a suspect, because they can quickly trace the people with whom the suspect was in contact.

“Once you get on to one guy who’s important in a network, because the structure of a network is flat . . . you get everyone he’s connected to,” Aaron Weisburd explains. “In the old days a terrorist organisation would have a much more hierarchical structure, you would have tight little cells and one guy would know maybe one person one step up and maybe one person one step down, but that’s it. In a network structure, if you get the right guy the whole thing goes down.”


Al-Qaeda’s 007


Friday, January 11, 2008

U.S. Cyber Command Will Have Both Offensive and Defensive Mission

In an article that discusses the new US center for cyberspace combat, The U.K. website Computing provides some more details on the new U.S. Cyber Command Center that will reportedly have a 30,000 strong staff.

"At this stage, plans for the Afcyber centre include three main elements:

- Assessment of US defence systems’ vulnerability to electronic attack, and improvements to their resilience.

- Co-ordination with the physical armed forces to attack enemies with a presence in cyberspace.

- $10m-worth (£5m) of annual funding for the largest ever research centre looking at software application weak points."

The article also mentions other military cyberwar centers:

"The US is not the only country establishing a military command centre for cyber warfare. Canada and Australia have similar programmes. But in the UK, the job is spread around civilian organisations.

The [U.K.] security services carry out intelligence operations in cyberspace. And the Centre for the Protection of National Infrastructure advises businesses."

US looks to military to take on cyber threats: Command centre to be offensive and defensive

Thursday, November 15, 2007

U.K. to Require ISPs to Control Websites of Terrorist Supporters

Prime Minister Gordon Brown announced that the U.K. Government would introduce controls on websites supporting terrorist activities as well as stricter physical controls of public places:

"Brown said Internet and technology companies will be asked to help stop online terrorist propaganda, and he announced that a meeting would be convened with leading British Internet service providers to find ways of doing that.

Along with possibly removing customers' sites, service providers also might be pressured to block ones hosted abroad. The government also could create a list of banned sites or try to persuade search engines like Google Inc. or Yahoo Inc. to filter out prohibited content from their search results."


PM: British Sites Need More Security