The successor to Do Not Track is the Global Privacy Control, which companies are required to respect in several states, including California and Colorado. Support for GPC is already built into Firefox and Brave, but must be enabled in the privacy settings. Users of other browsers can get the benefits of the GPC opt-out using third party extensions like EFF's Privacy Badger.
DHS is a law enforcement agency, which regularly uses surveillance techniques, some of which exploit security flaws in devices and software. When you share information about security flaws with DHS, you're sharing them with ICE and the Secret Service.
The FTC, in contrast, is a consumer protection agency. They don't kick down doors and they don't arrest people.
And yes, many security researchers have shared their prepublication research with the FTC.
I think that some webcam indicator lights are vulnerable to remote disabling. Although it is certainly possible that some are not, I and most other users have no way of knowing which lights are reliable, and which ones are vulnerable.
As such, I put a Band-Aid over my webcam.
Now if only I could figure out an equally easy way to reliably disable my laptop microphone without opening up the laptop and cutting the cable.
1. My employer, the ACLU, filed two comments in the Rule 41 process.
The first, before public comments were even solicited, resulted in DOJ dropping one of their proposed changes to rule 41, which would have permitted the gov to piggyback from a hacked target's computer to a cloud account (such as Dropbox or Google), rather than the gov going to the cloud provider with a warrant.
While our first comment does indeed describe and quote from some alternative language proposed by Orin Kerr, I don't think it is fair to describe that as evidence of ACLU approval of hacking of users whose location cannot be determined. For example, in that comment, we note that:
[U]nder Professor Kerr’s language, the government would still be able to obtain warrants to use malware, zero-day exploits, and other techniques that raise serious constitutional and policy questions.
2. While some public interest groups and tech policy advocates are publicly (or, in some cases, privately) embracing the idea of giving law enforcement formal, regulated hacking powers, in a desperate attempt to push back against legislative pressure for crypto backdoors, I'm thankful that the ACLU has not done so. If the organization does at some point decide to come out in favor of law enforcement hacking, I strongly doubt my name will be on that document.
[I'll note, however, that one of the great perks that come with working for the ACLU is that it's perfectly OK to disagree with some of the organizations' official policy positions. I'm not forced to tow the company line publicly on issues in which I disagree.]
3. Just so all of my cards are on the table. I'm volunteering, unpaid, as an expert for the defense in several of the Playpen FBI watering hole cases. I am strongly opposed to bulk hacking, enough so to volunteer my time to helping to fight the FBI's use of this outrageous surveillance technique.
4. The FBI being able to remotely activate webcams without the light turning on is not an "unsourced anonymous claim".
From the Washington Post story, linked to in my comment above:
The FBI has been able to covertly activate a computer’s camera — without triggering the light that lets users know it is recording — for several years, and has used that technique mainly in terrorism cases or the most serious criminal investigations, said Marcus Thomas, former assistant director of the FBI’s Operational Technology Division in Quantico.
I've researched this issue extensively, and I've not found a case before where a thousand people in the same place were searched pursuant to a single search warrant, let alone a thousand people or items located in different places around the country.
On the issue of courts authorizing the searching of wrong people, we don't know if the court in Freedom Hosting even knew that the government would deliver the malware to innocent people who were merely visiting other websites hosted from the same server as the contraband sites targeted by the warrant. We don't know this, because three years later, the freedom hosting search warrant is still sealed.
The FBI has been using malware since at least 2003 [1], probably a few years before that. Today, the FBI has a dedicated team, the Remote Operations Unit, based out of Quantico, which does nothing but hack into the computers and mobile phones of targets. According to one former top FBI official, among the team's many technical capabilities, is the ability to remotely enable a webcam without the indicator light turning on [2].
Although DOJ has been using malware for nearly fifteen years, it never sought a formal expansion of legal authority from Congress. There has never been a Congressional hearing, nor do DOJ/FBI officials ever talk explicitly about this capability.
The Rule 41 proposal before this advisory committee was the first ever opportunity for civil society groups, including my employer, the ACLU, to weigh in. We, along with several other groups, submitted comments and testified in person.
Our comments can be seen here [3,4]. Incidentally, it was while doing the research for our second comment that I discovered that the FBI had impersonated the Associated Press as part of a malware operation in 2007 [5].
Ultimately, the committee voted to approve the change to the rules requested by DOJ. In doing so, the committee dismissed the criticism from the civil society groups, by saying that we misunderstood the role of the committee, that the committee was not being asked to weigh in on the legality of the use of hacking by law enforcement, and that "[m]uch of the opposition [to the proposed rule change] reflected a misunderstanding of the scope of the proposal...The proposal addresses venue; it does not itself create authority for electronic searches or alter applicable statutory or constitutional requirements."
This isn't just about the district where the judge is based. There is also the bigger question of whether or not judges should be authorizing bulk hacking operations.
The three Tor watering hole operations (Freedom Hosting, Torpedo and Playpen) are the only cases we know of where DOJ has obtained a warrant from a single judge which it then used to conduct searches on hundreds or thousands of computers. DOJ did not seek new powers to conduct bulk searches/hacks from Congress, they just went ahead and got an ex-parte warrant from a judge. In the case of Freedom Hosting, it looks like they also screwed up and then hacked the computers of innocent people visiting other, non contraband sites, hosted on the same server.
I think that reasonable people can disagree about whether or not it makes sense to allow a judge to sign a warrant to hack a single computer in an unknown location which is probably outside of his or her district. Bulk hacks are very, very different, and a very new thing for our legal system.
Pay an award booking service to find you the best flights possible. There are several out there, and they know a lot more than you about how to find obscure flights/routing. it's worth the $150.
You say "Redphone? Whisper? and various other projects - while very cool - didn't achieve even as much popularity as GnuPG"
The Axolotl protocol that was created for Whisper System's TextSecure is now used, by default, by Cyanogenmod (10 million users) and the Android version of WhatsApp (more than 500 million installs from the play store).
I'd say Moxie's tech has been pretty widely adopted.
I pitch stories regularly to reporters. Dan is by far one of the best reporters in the business, and is the person I go to whenever I have something that is interesting, but far too technical for the mainstream press. He always does an excellent job with it, particularly if I give him a few days.
I've worked with plenty of unprofessional reporters who butcher stuff, and don't care about the details. Dan isn't like that.
The US Marshals are not the only federal law enforcement agency doing something like this. According to documents I obtained through a FOIA in 2012, ICE has purchased an airbourne mounting kit and paid for airbourne training for their Stingray II cell phone tracking gear.
See: https://www.documentcloud.org/documents/479397-#document/p44
As one of the complainers (and the person who filed the bug you linked to), I'm happy to see Google make some progress here. I'm even happier to see that they hired Adrienne Felt, who is excellent, and are letting her improve the usability of Chrome's warnings.
The government obtained a 2703(d) order for the stored non-content data of a particular user (suspected to be Snowden, but redacted from the court documents). They then obtained a pen register order, for real-time metadata about that same user. Lavabit told them they couldn't comply, so the government sought to use the 3rd party assistance language in the pen register statute to compel the company to provide its private SSL keys. The government then followed up with a grand jury subpoena and Stored Communications Act warrant specifically seeking Lavabit's private SSL keys.
So, no. The warrant the government obtained was not specifically for the data relating to Mr Snowden, but rather, was for the SSL keys.
See: https://globalprivacycontrol.org/