John Scott-Railton Profile picture
Chasing digital badness. Sr. Researcher @citizenlab @UofT @munkschool. Fmr.Ed. @SecPlanner. Tweets mine. Other platforms @jsrailton too.
45 subscribers
Jan 23 7 tweets 5 min read
NEW: US seeks extradition of Israeli private spy over sprawling hacking against 🇺🇸American nonprofits.

Amit Forlit's alleged customer? US lobbying firm @DCIGroup... representing @exxonmobil

Extradition filings in UK give fresh peek into this wild case 1/Image
Image
Image
Image
2/ The case was triggered back in 2018, when US-based nonprofits targeted by hackers requested that @citizenlab notify the authorities.

In 2020, we went public with the investigation, alongside @jc_stubbs @razhael & @Bing_Chris 👇

Dec 23, 2024 4 tweets 1 min read
The volume of scam phone calls targeting elderly people in the US is insane.

Anyone that has visited an aging person knows what I'm talking about.

Ring after ring.

Several calls a day isn't out of the ordinary each of them a risk of wiping out their savings.

It's an untenable situation and will only get worse without focused government action. Phone predators constantly target your parents.

Foreign scam call centers are running on an industrial scale.

Efforts phone companies are making are obviously not up to the task.

Just ask any retired person you know when they last got a scam call.
Dec 23, 2024 7 tweets 2 min read
VPN advertising is the most common source of security misinformation that I encounter.

By far.

So many people misplace their trust in dubious consumer VPN products.

The industry is a scourge. VPNs don't do most of the things that podcasters imply they do.

Security:
Coffee shop attacks on unencrypted logins are a thing of a decade ago.

VPNs won't stop even the dumbest spyware & phishing.

Privacy:
Advertisers still know it's you when you turn on a VPN... they use many other identifying signals from your device, like your browser & advertising IDs. Those don't change when you turn on a VPN.
Dec 21, 2024 12 tweets 12 min read
BREAKING: NSO Group liable for #Pegasus hacking of @WhatsApp users.

Big win for spyware victims.

Big loss for NSO.

Bad time to be a spyware company.

Landmark case. Huge implications. 1/ 🧵Image
Image
Image
Image
2/ In 2019, 1,400 @WhatsApp users were targeted with #Pegasus.

WhatsApp did the right thing & sued NSO Group.

NSO has spent 5 years trying to claim that they are above the law.

And engaged in all sorts of maneuvering.

With this order, the music stopped and NSO is now without a chair.Image
Image
Dec 18, 2024 4 tweets 3 min read
NEW: US considering ban on @TPLINK routers.

Company has a majority of the US market share for homes & small biz.

Concerns stem from repeated use in cyberattacks from #China & concerns over supply chain security.

Reportedly an office of @CommerceGov has subpoenaed the company. 1/

Story by @heathersomervil @dnvolz & @aviswanathaImage
Image
Image
Image
2/ @TPLINK has quickly grown market share, even as concerns have grown over vulnerabilities in the routers being used in #China-linked hacking operations.

wsj.com/politics/natio…Image
Dec 18, 2024 4 tweets 3 min read
Use only end-to-end encrypted communications says @CISAgov.

YES!

End-to-end encryption is critical infrastructure for a safe society.

Plenty of other solid guidance for mobile users at risk here.

Let's look at their #iPhone & #Android-specific recs... 1/Image
Image
Image
2/ @CISAgov's top recommendation for Apple users is to✅ enable #LockdownMode

It's my top guidance for high-risk #iPhone users..

Because as researchers tracking sophisticated threats we see Lockdown Mode blunt advanced attacks...

Other solid guidance:

✅Protect your DNS
✅Disable fallback to SMS
✅Enroll in iCloud Private Relay
✅Trim App permissions.Image
Image
Dec 17, 2024 5 tweets 3 min read
NEW: #China #Russia #Iran & #Israel are spying on 🇺🇸Americans using telecom weaknesses says @DHSgov

Deeply concerning on heels of #SaltTyphoon breaches.

All US carriers vulnerable to some extent.

We know this thanks to Sen @RonWyden's tireless work to expose #SS7 & #Diameter vulnerabilities.

Here's how they work...

Story by @josephfcox 1/Image
Image
2/ Here's the thing about the global network for routing calls.

Requests are trusted by default. Whatever operator they come from!

Since requests can let you do things like intercept calls, texts & track phones locations...

...a lot of governments & some shady companies have come running.

All they needed was a "Global Title" which is not hard to get in some jurisdictions.

Result? A tidal wave from around the globe of shady requests for the purpose of spying on people.

Including Americans. In the US.

We @citizenlab exposed Circles, one such player...

Story: 404media.co/dhs-says-china…Image
Dec 16, 2024 7 tweets 4 min read
NEW: police in #Serbia caught unlocking activists phones with @Cellebrite's mobile forensic tools & planting spyware on them.

Incredibly troubling investigation by @AmnestyTech delves into how the Serbian authorities mix a toxic brew of repression out of homegrown + foreign mercenary spyware like #Pegasus + $CLBT's forensic tools possibly supplied as part of foreign assistance from #Norway. 1/

Read: amnesty.org/en/documents/e…Image
Image
Image
Image
2/ From Traffic Stop to Spyware Victim...

As costs increase for zero-click spyware, expect to see authorities getting creative...

Rolling their own tech & finding novel ways to plant it on activists' devices with physical access.
Dec 5, 2024 10 tweets 7 min read
🚨NEW INVESTIGATION: Russia's 🇷🇺 FSB beat & detained this programmer.

They demanded he inform on contacts in #Ukraine.

When he was finally released, Kirill Parubets got his phone back.

It was bugged with spyware. 1/

Investigative collab by us @citizenlab w/@DeptFirst.Image
Image
2/ Russian authorities descended on Kirill Parubets & his spouse. Raiding their apartment.

Beating him for his passwords.

Accusation? Money transfers to #Ukraine.

Then they threw the couple into custody.

The #FSB threatened life imprisonment if he didn't agree to become an informant.

citizenlab.ca/2024/12/device…Image
Image
Dec 3, 2024 5 tweets 3 min read
Good! Finally a path to crackdown on data brokers.

Americans are constantly victimized by these companies.

Privacy shouldn't be partisan, so pay close attention to see who comes out against these common-sense plans from the @CFPB. 1/

By Dell Cameron & Andrew Couts @wired.Image
Image
Image
2/ The volume of data constantly collected & sold on Americans puts the US at a global disadvantage.

The data-broker firehose is a hostile foreign intelligence service's delight.

But that's just the beginning.
Dec 3, 2024 9 tweets 6 min read
Meet 'decolonization' expert Nomma Zarubina.

FSB codename "Alyssa"

All over the Washington DC think tank circuit. Had a knack for meeting US officials. Even attended some protests against Russia.

Just last week she spoke at an event on Parliament Hill in #Canada.

She's just been charged by the #FBI for lying about taking direction from the FSB. 1/Image
Image
Image
Image
2/ Nomma Zarubina was collecting photos with current & former officials like Pokemon.

Wearing some NGO bona-fides, she also shows up at a lot of events with prominent exiles from #Russia & figures from #Ukraine.

She also got into all sorts of meetings... Image
Image
Image
Nov 27, 2024 4 tweets 3 min read
BREAKING: #ExxonMobil lobbyist investigated over hacking of American nonprofits.

Hacked material fed PR campaigns & lawsuits against environmental advocacy orgs. 1/

By @razhael & @Bing_Chris Image
Image
Image
Image
2/ The case goes back years & centers around a massive hack-for-hire operation based in #India....

...that did the dirty work for powerful people & companies around the world.

Nov 24, 2024 6 tweets 3 min read
First time I've seen what I think is AI-generated fake satellite imagery.*

Interesting. 1/ 2/ With a squint this vibes. Try it for yourself on the first pic without zooming in.

Notice anything that just isn't quite right?

First thing: the marina / oceanfront areas don't follow a coherent logic. Image
Image
Nov 14, 2024 7 tweets 5 min read
Whoa: NSO Group allegedly rolled a @WhatsApp exploit to implant #Pegasus spyware even after WhatsApp sued them.

This previously-unrevealed "Erised" vector was later disabled by #WhatsApp.

These un-redacted filings are quite the read. Even some footnotes have scoops. 1/Image 2/ We learn that NSO Group had at least three @whatsapp exploits: Heaven, Eden & Erised.

The first, called Heaven, was active some time prior to Sept-Dec 2018. It worked by using manipulated messages to direct targeted devices to a malicious WhatsApp relay controlled by NSO Group.

Heaven was ultimately disabled by changes made in Sept & December 2018 by WhatsApp.

storage.courtlistener.com/recap/gov.usco…Image
Image
Image
Image
Oct 31, 2024 4 tweets 2 min read
WILD: actual photo of Musk-hired door knockers being driven around #Michigan.

This group of mostly-black workers were driven in the back of a truck with no seats.

They say they were flown in, given unrealistic goals, and threatened with their lodging being cut off & being forced to pay their own way home if they couldn't meet them.

Some didn't even know which candidate they were working for.

Article by @JakeLahut
wired.com/story/elon-mus…Image Working to help the richest man in the world get his preferred candidate into office, folks. Image
Oct 26, 2024 5 tweets 3 min read
I'm excited for the #HarrisWalz plan to massively expand medicare to cover in-home care.

Beautiful. So many families are are helping loved ones get through hurdles with dignity & independence. At home.

Oh wait, you hadn't heard about this?

A study shows major broadcast networks mostly ignored the policy announcement on the day she made it.
apnews.com/article/harris…Image
Image
Home health care is ruinously expensive.

But as everyone knows, it's often better for seniors to get help in their homes.

A study found that this new #HarrisWalz #medicare benefit is likely to help more than 14 million beneficiaries.

Chart: kff.org/medicare/issue…Image
Image
Oct 21, 2024 7 tweets 3 min read
You've probably heard about Musk's petition.

It's run on the same website that ran bait-and-switch voter registration back in August.

They had to shut it down.

The goal then: probably soak up detailed voter data.

Remember, lots of shady micro-targeting is going on right now from Musk-backed PACs.

And now? Data collection is again a key priority.

I don't know why this isn't front and center in news stories about this.Image
Image
2/ Coverage of Musk's actions often treats them in isolation.

The petition for example is largely covered as "is this legal?"

Good question, but if you don't focus on the systemic effort to gather data & influence voters using that data, you miss the plot.
Oct 18, 2024 7 tweets 5 min read
BREAKING: Musk-backed PAC is micro-targeting muslim areas with ads saying Harris stands with Israel... and targeting jewish areas saying the opposite.

Writing is on the wall: Musk willing to further divide America if he thinks it will help his candidate win.

By @jason_koebler
404media.co/this-is-exactl…Image Review the @google ads data yourself.

A "PRO-ISRAEL TEAM WE CAN TRUST" designed to look like a #HarrisWalz campaign ad is micro-targeted to areas with a high muslim population around Dearborn, Michigan.

Meanwhile, same Musk-backed PAC has a "WHY PANDER TO PALESTINE?" ad micro-targeted to areas in Pennsylvania.

The ads are getting millions of impressions.

adstransparency.google.com/advertiser/AR0…Image
Image
Image
Image
Oct 17, 2024 4 tweets 4 min read
WARNING: fake pro-#HarrisWalz advertising campaign...

Is actually run by dark money network connected to Elon Musk.

The "Progress 2028" ads & text message campaigns feature lies about Harris policies about guns, immigrants & LGBTQ issues...

The goal is clearly to mislead voters.

Dirty politics that must be investigated.

By @annalecta
opensecrets.org/news/2024/10/p…Image
Image
Image
Image
This false-flag #HarrisWalz campaign is hammering #Georgia with ad buys on @meta.

$66,140k in spend in the past week alone, shown to a custom audience. I wonder who it is?

Please reply if you've seen advertisements for "Progress 2028" or gotten text messages promoting this fake campaign.

facebook.com/ads/library/?a…Image
Image
Oct 16, 2024 6 tweets 4 min read
NEW: sprawling AI bot army found attacking #HarrisWalz & dems, supporting Trump and GOP.

Researchers at @ClemsonUniv spotted & mapped the network.

It wasn't hard for them to conclude that an LLM was being used: they found tweets that leaked the prompts.

Which also helps makes the partisan objectives of the campaign crystal clear...

READ: open.clemson.edu/cgi/viewconten…Image
Image
Image
Image
2/ Beyond targeting the national election, specific Senate & House races were also a focus of efforts. As were specific figures like @SenatorBaldwin, who was apparently a perennial target. Image
Image
Image
Oct 5, 2024 10 tweets 5 min read
CATASTROPHIC: Chinese hackers massively wiretapped 🇺🇸USA by compromising the interception portals mandated under US law.

Remember this the next time a government demands encryption backdoors.

By: @bysarahkrouse @dnvolz @aviswanatha @bobmcmillan h/t @RonDeibert

READ: wsj.com/tech/cybersecu…Image
Image
Image
Image
Manufacturers of networking and phone gear must follow specific standards for 'lawful interception' in different jurisdictions (e.g. CALEA & ETSI's standards)

But as we learn time & time again, the scope of potential access & harm almost never matched by efforts to detect & block malicious use.Image