Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Government use of private tech companies to spy on citizens
#7

Spyware used by governments poses as Firefox, and Mozilla is angry

Mozilla sends cease and desist letter to maker of FinFisher software.

by Jon Brodkin - May 2 2013, 2:41am AUSEST



Mozilla has sent a cease-and-desist letter to a company that sells spyware allegedly disguised as the Firefox browser to governments. The action follows a report by Citizen Lab, which identifies 36 countries (including the US) hosting command and control servers for FinFisher, a type of surveillance software. Also known as FinSpy, the software is sold by UK-based Gamma International to governments, which use it in criminal investigations and allegedly for spying on dissidents.
Mozilla revealed yesterday in its blog that it has sent the cease and desist letter to Gamma "demanding that these illegal practices stop immediately." Gamma's software is "designed to trick people into thinking it's Mozilla Firefox," Mozilla noted. (Mozilla declined to provide a copy of the cease and desist letter to Ars.)
The spyware doesn't infect Firefox itself, so a victim's browser isn't at risk. But the spyware "uses our brand and trademarks to lie and mislead as one of its methods for avoiding detection and deletion" and is "used by Gamma's customers to violate citizens' human rights and online privacy," Mozilla said. Mozilla continues:
Through the work of the Citizen Lab research team, we believe Gamma's spyware tries to give users the false impression that, as a program installed on their computer or mobile device, it's related to Mozilla and Firefox, and is thus trustworthy both technically and in its content. This is accomplished in two ways:
1. When a user examines the installed spyware on his/her machine by viewing its properties, Gamma misrepresents its program as "Firefox.exe" and includes the properties associated with Firefox along with a version number and copyright and trademark claims attributed to "Firefox and Mozilla Developers."
2. For an expert user who examines the underlying code of the installed spyware, Gamma includes verbatim the assembly manifest from Firefox software.
The Citizen Lab research team has provided us with samples from the following three instances that demonstrate how this misuse of our brand, trademarks and public trust is a designed feature of Gamma's spyware products and not unique to a single customer's deployment:
  • A spyware attack in Bahrain aimed at pro-democracy activists;
  • The recent discovery of Gamma's spyware apparently in use amidst Malaysia's upcoming General Elections; and
  • A promotional demo produced by Gamma.
Each sample demonstrates the exact same pattern of falsely designating the installed spyware as originating from Mozilla. Gamma's own brochures and promotional videos tout one of the essential features of its surveillance software is that it can be covertly deployed on the person's system and remain undetected.
The Citizen Lab report provides pictorial evidence of the impersonation:
[Image: fake-firefox-640x455.png]Enlarge
Citizen Lab
FinFisher doesn't just masquerade as Firefox. The Citizen Lab report says it has also been used to target Malay language speakers by "masquerading as a document discussing Malaysia's upcoming 2013 General Elections."
The countries where Citizen Lab identified FinFisher command-and-control servers are Australia, Austria, Bahrain, Bangladesh, Brunei, Bulgaria, Canada, Czech Republic, Estonia, Ethiopia, Germany, Hungary, India, Indonesia, Japan, Latvia, Lithuania, Macedonia, Malaysia, Mexico, Mongolia, Netherlands, Nigeria, Pakistan, Panama, Qatar, Romania, Serbia, Singapore, South Africa, Turkey, Turkmenistan, United Arab Emirates, United Kingdom, United States, and Vietnam.
We've asked Gamma if the company has a response to Mozilla's cease and desist letter but haven't heard back yet.
http://arstechnica.com/information-techn...-is-angry/
"The philosophers have only interpreted the world, in various ways. The point, however, is to change it." Karl Marx

"He would, wouldn't he?" Mandy Rice-Davies. When asked in court whether she knew that Lord Astor had denied having sex with her.

“I think it would be a good idea” Ghandi, when asked about Western Civilisation.
Reply


Messages In This Thread
Government use of private tech companies to spy on citizens - by Magda Hassan - 03-05-2013, 12:23 PM

Possibly Related Threads…
Thread Author Replies Views Last Post
  New Malware spying at Internet service & telecommunications companies..and you! Peter Lemkin 2 6,061 25-11-2014, 09:13 AM
Last Post: Magda Hassan
  US Executive Order Grants Authority to Seize Private Communications Facilities Ed Jewett 2 3,334 13-07-2012, 05:05 AM
Last Post: Peter Lemkin
  Best Short Video On State Of US/NSA Electronic Spying on Citizens! Peter Lemkin 6 7,998 26-04-2012, 08:54 PM
Last Post: Peter Lemkin
  Non-profit ISP start up promises fully encrypted, private Internet Magda Hassan 0 2,587 13-04-2012, 02:50 PM
Last Post: Magda Hassan
  Discovery News: Earth, Space, Tech, Animals, History, Adventure, Human, Autos Bernice Moore 0 2,912 15-03-2012, 09:25 PM
Last Post: Bernice Moore
  Canadian government is 'muzzling its scientists' Magda Hassan 1 3,276 18-02-2012, 08:26 AM
Last Post: Harry Dean
  Georgia Tech Online Spying Ed Jewett 0 2,291 07-12-2011, 06:55 AM
Last Post: Ed Jewett
  WMR report on U.S. government-engineered novel flu validated by science panel Ed Jewett 0 2,582 01-12-2011, 07:05 PM
Last Post: Ed Jewett
  U.S. Government Refuses FOIA Request to Turn Over ‘Secret’ Interpretation of Patriot Act Ed Jewett 0 2,594 17-10-2011, 05:15 PM
Last Post: Ed Jewett
  ... German Security Agencies Caught Planting Spyware on Private Computers Ed Jewett 0 3,229 16-10-2011, 10:32 PM
Last Post: Ed Jewett

Forum Jump:


Users browsing this thread: 1 Guest(s)