Selling Your Secrets : The Invisible World of Software Backdoors and Bounty Hunters

?akid=11483.108806.sARdjq&rd=1&s

  • Selling Your Secrets: The Invisible World of Software Backdoors and Bounty Hunters | Alternet
    http://www.alternet.org/selling-your-secrets-invisible-world-software-backdoors-and-bounty-hunters

    Back in the 1990s, the Clinton administration promoted a special piece of NSA-designed hardware that it wanted installed in computers and telecommunication devices. Called the Clipper Chip, it was intended to help scramble data to protect it from unauthorized access — but with a twist. It also transmitted a “Law Enforcement Access Field” signal with a key that the government could use if it wanted to access the same data.

    Activists and even software companies fought against the Clipper Chip in a series of political skirmishes that are often referred to as the Crypto Wars. One of the most active companies was RSA from California. It even printed posters with a call to “Sink Clipper.” By 1995, the proposal was dead in the water, defeated with the help of such unlikely allies as broadcaster Rush Limbaugh and Senators John Ashcroft and John Kerry.

    A decade after the Crypto Wars, RSA, now a subsidiary of EMC, a Massachusetts company, had changed sides. According to an investigative report by Joseph Menn of Reuters, it allegedly took $10 million from the National Security Agency in exchange for embedding an NSA-designed mathematical formula called the Dual Elliptic Curve Deterministic Random Bit Generator inside its Bsafe software products as the default encryption method.

    Take Vupen, a French company that offers a regularly updated catalogue of global computer vulnerabilities for an annual subscription of $100,000. If you see something that you like, you pay extra to get the details that would allow you to hack into it. A Vupen brochure released by Wikileaks in 2011 assured potential clients that the company aims “to deliver exclusive exploit codes for undisclosed vulnerabilities” for “covertly attacking and gaining access to remote computer systems.”

    It’s increasingly clear that the online world is, for both government surveillance types and corporate sellers, a new Wild West where anything goes. This is especially true when it comes to spying on you and gathering every imaginable version of your “data.”

    The simple truth of the matter is that most individuals are easy targets for both the government and corporations. They either pay for software products like Pages and Office from well known manufacturers like Apple and Microsoft or download them for free from game companies like Activision, Rovio, and Zynga for use inside “reputable” mobile devices like Blackberries and iPhones.

    These manufacturers jealously guard access to the software that they make available, saying that they need to have quality control. Some go even further with what is known as the “walled garden” approach, only allowing pre-approved programs on their devices. Apple’s iTunes, Amazon’s Kindle, and Nintendo’s Wii are examples of this.

    But as the Snowden revelations have helped make clear, such devices and software are vulnerable both to manufacturer’s mistakes, which open exploitable backdoors into their products, and to secret deals with the NSA.