re-evaluating Orwellian surveillance today, the ongoing FBI Apple Encryption Challenge, and the dangers of IoT and Iran. These stories are more in this week's ISNG Security Report. Hello, I'm Nick Holland. The author George Orwell published Nine Books.
This is the last one that re-semented his name with the adjective Orwellian, published in 1949, which started Second World War 1984, details the consequences of government overreach, totalitarianism, and repressive regimentation of all persons and behaviours within society. Orwellian has come to conduct things such as official deception, secret surveillance, brazenly misleading terminology, a manipulation of recorded history by a totalitarian or authoritarian state. What Orwell fails to imagine was perhaps just how voluntarily people would walk into a world of secret surveillance and manipulated truths through social media platforms, selfies, and smart home devices. This week, ISNG's executive editor, Richard Aynter, Matthew Schwartz, kicks off the Security Report podcast with a re-evaluation of just how Big Brother is watching you today.
Here he is. Not even too much more, could have predicted nation-state surveillance in the 21st century, give us free, instant messaging for our smartphones, and faster than you can say, viral kitten video, we're collectively part of a mass surveillance nightmare. Keep privacy lulls, or just give in and download the popular and free TOTOC app, which until recently was top of the charts for social messaging apps in United Arab Emirates and U.S. Until last month, that is, when The New York Times reported that American intelligence officials believe TOTOC is really a nation-state surveillance operation being run by the Emirati government.
The Times says it's used to try and track every conversation, movement, relationship, appointment, sound, and image of those who install it on their phones. After receiving inquiries from the Times, Apple and Google both ceased distributing the app, removing it from their app stores. Apple's man appears to be holding steady, but on Sunday, Google reinstated TOTOC on Google Play. Now, no one considers the UAE to be a powerhouse of human rights or press freedom, and the surveillance genius, if you will, of TOTOC would be how the UAE government apparently served it up.
While the government permits TOTOC use, it bans rival offerings, including WhatsApp and Skype, and blocks VPN services users might have otherwise employed to bypass those restrictions. Another surveillance innovation is that the app does exactly what it says it does, according to Patrick Wardell, a security researcher at software firm Jamf. He formerly worked as a U.S. National Security Agency hacker, and he was approached by the Times to help it analyze TOTOC.
Wardell notes that the permissions demanded by the app access to your microphone, camera, contacts, photos, and location are all legitimate types of access for an app such as this one. In other words, if this is a mass surveillance operation, it's being accomplished by tricking users into giving a nation-state surveillance apparatus just what it needs to keep times on them. George Orwell in his novel 1984 imagined how the rulers of an authoritarian society would watch individuals via their televisions, but he did not force smartphones and messaging apps. Then again, who did?
Last month, the Guardian named smartphones as one of 15 supertrends that defined the 2010s. Better known now simply as a phone, they are firmly established as central to productivity, to entertainment, to communication, and to education, the Guardian said, and they have replaced the notion of being online. Thanks to our smartphones, we're always online. That underpins a revolution that has led us to rely on new tools for everyday convenience, including the apps that run on smartphones, which often collect myriad amounts of personal data and send it back to cloud-based servers, which the U.S.
and governments, apparently also monitor and mass. Other modern conveniences with potential privacy and personal security downsides include wearable fitness devices, which can track our outdoor workout routines and share it with friends, but which also can inadvertently reveal the location and layout of secret military bases. Not to mention, pinpoint for robbers, the shed where we store our expensive bicycle. And of course, who doesn't love their smart home AI assistant that literally listens for our every word.
Actually, Orwell still looks pretty prescient. Only now, the everyday tool potentially being used to conduct surveillance isn't always connected to device that we carry with us and use to document our everyday lives. Forget 1984 and welcome to 2020. For Information Security Media Group, I'm Matthew Schwartz.
A letter to Apple asking for help in accessing encrypted data from two iPhones. The phones belonged to a Saudi military trainee who killed three people and injured eight with a handgun in December at Naval Air Station Pensacola. NBC News reported earlier this week that the FBI had search warrants for the phones. The devices, however, are encrypted and efforts to guess the passwords have been unsuccessful.
The move by the FBI is reminiscent of 2016 when it sought Apple's help for decrypting an iPhone 5C. At that time, it went to federal court. The phone belonged to one of the perpetrators of a mass shooting in San Bernardino, California in December 2015. In that case, a federal judge ordered Apple to disable the phone's security.
That order meant Apple would have had to create a new iOS software update that, if leaked, could have disabled the security features for any iPhone. Apple CEO Tim Cook said developing such software was the equivalent of creating cancer. So Apple refused to do so. The FBI later dropped the legal action after it successfully used a tool from a phone cracking vendor.
The resolution left unanswered whether a court could order a company to undermine its own encryption, which the technology industry fiercely opposes. In the latest incident, Apple says it received a request from the FBI a month ago and turned over all the data it had. That may have included iCloud backups which Apple does have access to, but it appears the FBI wants more. If the Saudi military trainee didn't frequently back up to iCloud, then there may be data on the iPhones that hasn't been seen by investigators.
If guessing passwords doesn't work, law enforcement could try third-party phone cracking tools along the lines that it used in 2016. But the FBI's letter to Apple, this time, indicates that may not be a possibility for some reason. The New York Times reports that the FBI has checked with other US government agencies and allies to see if they could crack the phone, but it's so far come up empty. The US government has continued to call for technology companies to design encryption so that law enforcement can get full access when needed.
The technical experts say it's impossible to design a system that wouldn't also pose hacking risks from cyber criminals in nation states. Other countries, including the UK and Australia, have passed laws that allow for more pressure on technology companies. Australia's goes to the far list. It can issue a notice to a company forcing it to create a new technical way to get into a device, but the government refutes that such an order amounts to a backdoor.
All this shows that this year we're going to see more tug-of-war battles over encryption. For Information Security Media Group, I'm Jeremy Kirk. There are new vulnerabilities and things that are significantly changing how much at risk you are. Probably the biggest change we've seen over the past few years is the growth of the Internet of Things.
Ten years ago, you had your phone and your computer. Maybe there was some intelligence built into your TV. You got a smart doorbell, smart refrigerator, smart thermostat, a smart toaster. All of these things are talking to the Internet.
Your TV would have been a super computer 20 years ago. The ability for hackers to get into those things and cause more damage, even if it just means breaking a device, is much more significant than it was a few years ago. When you've got a traffic light and the traffic light is controlled by a fairly complicated set of custom switches, you know, it's probably a little bit harder to attack. When your traffic light is controlled by Raspberry Pi running Linux software and it's remotely accessible to the Internet, then you can cause a lot more damage.
And from a harassment and actual threats to the economy and to people, the broad threat from the Internet of Things remains the thing that keeps me up the most. I still do worry about things like attacks on the financial system or on the power grid. Those are huge existential threats, but they're, I think, much less likely than the sort of attacks that could cause mass economic damage and adversely affect people's eyes through the Internet of Things. That's it for this week's Ice and Security Report.
Theme music is by Ethical Audio. I'm Nick Collins. Catch you next time.