Why we should stay away from PRISM

The recent surveillance scandal where US basically monitors all data through routers in the US is one of the most important events this century. It also scares me when I hear the "I have nothing to hide"-argument frequently that I ask myself "Did we even learn anything from the cold war?". In this post, I will discuss some of the key aspects of why PRISM is a bad thing for society and why we should stay away from it as good as we can.

#1: Having a system designed for surveillance breaks its security model

It was a decision I even had to make myself a while ago. Should I distribute software with a built in backdoor which only I know of in case my software gets in the wrong hands? FBI already does something familiar which I got aware of during infosec-class last year. They often make software distributors such as Apple or Microsoft to distribute software updates which has built in backdoors FBI can use in order to track people where Windows is a good example. When I considered distributing software with backdoors to users I trust, I made the decision that it could also work the other way. Imagine if a hacker gets access to the software, reverse engineers the code and finds all the backdoors. It could have a devastating affect if I where to be unavailable once the attack occurred. There are also ethical questions such as "If I don't trust my users, how can I expect them to trust me?", but I will get back to that point later.

#2: Doing something out of the ordinary? You could be a terrorist!

Getting bored of doing the same crap every day? Tired of being one of the masses? (Hipsters?) Be careful, some systems might interpret you as a terrorist. The documentary Naked Citizens tells us how an individual wearing winter clothes on a summer day triggered a terrorist algorithm which then led to an arrest and a search through all his stuff. There was nothing which indicated that he was an terrorist, he was a free citizen doing something out of the ordinary and as an affect of that, he has no longer any privacy, he is constantly monitored by feds and is not allowed to obtain a visa. 

#3: Is it a good idea to say everyone is a criminal?

Let us say you are Barack Obama. You are going to have to earn the trust of the United States to function as the president, or else the system just does not work. But by monitoring every single citizen, logging every single bit going out from their computer through the internet by not giving them any privacy at all, you are implicitly saying that those individuals are potential terrorists. And that is everyone, including yourself. Think about it. You are the president, and you are going to get the trust of your people. How can you get the trust of your people when you don't even trust your people? 

#4: What if anyone gets their hands on their data

Imagine if a part of the PRISM database where to be published on the Internet. That would have been the greatest security breach in the history of mankind. The information stored there - everything from user credentials to meaningless update checks from iTunes would be exposed. By analyzing this data, you can learn a lot about the person who just got their entire private life exposed to the public. Their bank balance, who they are, where they are, where they have been, what they have been doing, basically all the online activity. The online activity reflects who the user is as an individual, a bit like DNA. So the user who just got all of their privacy exposed had some pretty graphical conversation about his/hers boss through Facebook? Whopes!

#5: Data manipulation to spread propaganda

One large concern is manipulation of data on the Internet. The government could suddenly decide that The Guardian has posted some really "inappropriate" news regarding data monitoring about US citizens and that their citizens should not see this information. Or even worse, make it look like it is the EU monitoring their citizens. This can also be used as a weapon to manipulate conversations between corporations or even nations! Sure, you got cryptography today but the NSA has even said that it stores encrypted data to be decoded later once they know how to decode it.

#6: Abuse against democratic actions

If someone arranges a protest, or maybe they believe in other social values than what the government approves, this may even trigger the alarm to make the government think they are terrorists. What are they? Citizens who has done nothing illegal who has a right to free speech, maybe we even have something to learn from them? This has already happened several times in the US and the UK. Once a surveillance algorithm thinks a person does anything wrong, everything which that person has done is "theoretically wrong" and is used against that individual. And once they are in this "evil ring of surveillance", there is no way of getting out. You have some signs you COULD be a terrorist, we haven't found anything but you could still be a terrorist, so we will watch you more closely! Government blaming other groups as terrorist could be an easy way to blame them and eventually get rid of them. 

#7: Human rights

We all want our right to free speech. PRISM is violating this right by not letting is say what we want. If you say something out of the ordinary, you could be a terrorist and you would require more surveillance. It is in fact a human right to have out freedom to write in our book that our boss is a fag and be able to communicate with our girlfriend/boyfriend without having anyone read what we have written. If I want this post to be just on my PC, I want it to stay there, not being treated as public property. I do not want to be monitored when I am on the bathroom. But why lock the bathroom door? I have nothing to hide! People actually want to stay anonymous in many situations. Want to complain about the large amount of shit the neighbours cats keeps leaving outside your entrance without destroying your relationship with your neighbours? Why are teachers not allowed to tell other people about the stupid things Jim said in class yesterday? Why don't we let other people read our diary? Why do we like to be by ourselves while showering? Why on earth do we hate when other people watch our phone while we are texting?

#8: Terrorists in 2013 is smarter than using Facebook or Skype

It is a sad fact that PRISM doesn't catch the really bad guys. To be honest, I do not believe Osama Binladen would have had a Twitter account or a Facebook group for Al Quaida. Just as every organism on earth, terrorists also adapts, just like humans. They also realized they could use heavily encrypted connections through the Internet to not be detected by anyone. By using VPN and Tor, you get pretty much close to having a perfect anonymous identity on the Internet as possible. So are those who use those terrorists then? No. What about people who sit on networks who could be monitored. Example: You are out on vacation and are connected to a open wireless network. On this network anyone can listen to the data you send. Solution: VPN. Norwegian and want to watch shit on NRK in Spain? VPN. Being haunted by some bad guys who might monitor your data to get your passwords? VPN. Want to post a complaint anonymously about your company without having your boss fire you? VPN. Terrorists today just doesn't post on their Facebook wall what they are gonna do, thanks Obama.

#9: Where do we end up?

A good question is where do we end up. Government secretly spying on each other not even trusting each other or their citizens, Obama not keeping his promises and lying governments. One of my deepest concerns is how the society will develop for the next generation coming after mine. My freedom to post what I want online without any consequences might be what the next generation looks at as luxurious or dangerous if the development of this continues. Government secretly spying on their citizens is not a good sign. Did we even learn anything from the cold war? STASI anyone? I admit I slept through most of my history classes as other things (like computers) where way more interesting. But when they say the point of history is to "not let the same mistakes happen again", I scratch my head when I see people with A's not understand how this is even related to the cold war. 

The recent leaks which Snowden has presented is one of the most important events in this century. He should get the Nobel's prize for showing that a lying government is spying on its innocent citizens without even letting them know. Many people call him a traitor, but I hope in the future they will realize what the US is doing is wrong and how PRISM is a good example on how democracy works against itself. This is one of the most important discussions of this century, where should the boarder go between privacy and the fight against terrorism. But what is the cause of terrorism? Why do they do what they do? Terrorists does what they do mostly to get heard, to cause panic, to get a message out and spread their ideas. A lack of free speech which I believe could be a factor to cause even more terrorism in the future. I'm glad Norway doesn't have a program like this (yet), but it is coming. And if there where, the probability that I would be raided next day by feds because I could potentially be a terrorist given the fact that nobody knew about PRISM yet, would be quite high. So in conclusion, thanks Obama.

Bypassing Allied Telesis iMG616BD

Fiber was the third type of internet connection I had after dial-up and ADSL. Even though I was just 14 years old at the time the fiber was set up, it felt as it was the Christmas eve when I was 5 years. I already knew back then fiber was the future of computer communication and a 10Mbit synchronous line would soon be upgraded.

 

The Black Box

However, one thing has been remaining silent since the setup of the fiber connection. The gateway (or modem/home central as some call it) has no admin panel and the documentation seemed to be close to none on the internet. The gateway was an Allied Telesis iMG616BD and had only Fast Ethernet ports. The fact that it had only Fast Ethernet ports means I can send and receive max 100Mbit through my current fiber cable unless my ISP (Eidsiva Bredbånd) gives me a new gateway and upgrades the equipment on their end. The fact I did not get any way of entering any admin web-panel on the modem or find any documentation on the device encouraged me to find more information, as this was a black box on my network I barely knew anything about.

A simple Google search lead me to Allied Telesis' website where they have information about this device in addition to a data sheet which turned out to be quite helpful. It had came to my attention that it had a console output before I started searching for information on the net. It had one of those old-style DIN console interfaces (8-pin MINI-DIN to be accurate). It is odd that there is no USB interface for console interface, however newer models have USB console interfaces (Was DIN the old USB?). Other ways of communicating to it was through telnet and a web-gui, however no such feature was possible as I did not have any IP on the device. It also supported Allied View Network Management System, which I believe what my ISP uses to configure the gateway. I then decided to try and get a mini-din cable for it. However, the device required a special pinout which did not exist on the Internet. It was not possible to buy the console cable from the net, and it did not seem likely that anyone would allow me to buy the cable from Allied Telesis either. My ISP did also not seem so happy to allow me to access the device when I asked them, and it turned out it had been set up in bridge-mode, which seemed reasonable. Gaining access to the device seemed hopeless, so I decided to bypass it instead.

Planning

The information on the data sheet page on the Allied Telsis website turned out to give me all the information I needed in order to acquire a compatible media-converter. Internet access was simple, however telephone (VoIP) and TV (IPTV) was not exactly plug and play. Another thing which motivated me in this small networking project was the bypassing of another Norwegian fiber ISP's modem, Lyse. It came to my attention they used VLAN to run IPTV and VoIP on the same network, but I assumed Eidsiva did not use the same VLAN IDs. As I found no other information on how to do this, I had to find out which VLANs was being used. When I got the media converter, I started trying to find out which VLANs where being used by using Wireshark. However, one issue was that the VLAN tag on the Ethernet frame was removed by most of the computers I had access to. Therefore I had to use an old Dell Dimension 8400 to gain a capture which had the information I needed. A few small registry edits where also required as the VLAN tags where removed by default. By closely inspecting the traffic coming to my network interface, I quickly detected VLAN 5 and 10. I was excited about what would happen if I where to call on the phone number on the VoIP, as I did not know how it was talking to my ISP's server. I was amazed when I saw my phone number appeared on the Wireshark screen and no phone was calling. It was using SIP. Only a SIP VoIP device and a VLAN switch was required to replace my gateway (in addition to the media adapter, which I already had). I also decided to upgrade the cabled network, so I ordered an EdgeMax router and a Netgear Gigabit switch as well. 

Setup

Playing with the VoIP was perhaps the funniest part. Once I discovered the SIP protocol, I decided to get a client running on my PC. I quickly found out which servers I had to connect. Username was obvious (my phone number) and my password was only a guess (Same as webmail and access to other services on my ISP). The server was the same IP as the server I received data from, but I quickly found the DNS name of it when I managed to make an incoming call. In case anyone want to test this out themselves that are using Eidsiva as an ISP and got a VoIP, here is the setup required for MicroSIP:

SIP server: ipt-server.bb.nett

User: Phone number

Domain: ipt-server.bb.nett

Password: The password used to access Eidsiva's webmail or the password used to access customer website on "min side".

Note: In order to resolve the domain name, the DNS settings has to be set to ns1.eidsiva.net (82.147.40.2) (primary), ns2.eidsiva.net (82.147.40.34) secondary. It is possible to use other DNS servers as well, however there is then no guarantee you will connect to the correct server when connecting to an IP directly instead of resolving a hostname. 

The idea of being able to call phones from my own PC was genius, as that would give me the same cost to call someone from Sweden (or Nicaragua for that matter) that it would cost me to make the call at home. However, my ISP has blocked access to the SIP server for a good reason.: There is no good encryption on the SIP protocol and sessions can easily be taken over by a man in the middle. I did not go too deep into analysis of the SIP handshake, but at least the password is not sent in plaintext. A secure VPN tunnel back home when I am somewhere else would be secure enough, as it would then be close to impossible for others to see the traffic.

The setup on the Cisco SIP box was not as trivial. The web-gui was a bit Windows 98-style and the configuration on it had the worst one I had ever seen. Some options where in hexadecimal where each bit in binary represented a boolean. A given range of bits could also mean a number (eg. which VLAN ID to use). It was technically the worst type of configuration input I had seen. Ever. When I make a value I store flags (say an 8-bit integer), I do not prompt the user to enter a hex value to change that value. That is not user-friendly and I would be way more lazy than how I currently am. Radio buttons? Back to configuration of the VoIP box, it took a few days for me to set it up right. For a long period I where only able to make outgoing calls. When I had set the SIPRegOn, it made all sense that the device had not "registered" itself on to the SIP server. 

Setting up the VLAN on the Netgear switch was not as easy as I thought it would be. As a Norwegian, I refuse to read documentation which comes with what I buy, even though it is a lot funnier (and sometimes frustrating) to figure out things by my self. Example: Reading a forum post on how to set everything here would be boring compared to figuring out how to set everything up here by myself, but frustrating when stuff gets wrongly configurated. The VLAN config allowed me to select which interface belonged to which VLAN and whether or not the Ethernet frame should be tagged. It took a while for me to realize that T was tagged ethernet frame and U was untagged ethernet frame as the documentation on the switch was not quite clear at this point. 

As Internet and VoIP was working, the TV was the only remaining part. I was confused why I had an IP address on the port for VLAN 10, but the TV refused to start. I had previously seen a continuous stream on around 3Mbit/s of MPEG TS packets when I was connected to the interface to the gateway from my ISP. I realized these came from a broadcast address and I looked on the broadcast settings on my switch. In order to get it working I had to enable IGMP snooping as this allowed the switch to forward broadcast packets from a VLAN to other ports on my switch.I also disabled the validation of broadcast packets, something I am not sure if is necessary. The ID for which VLAN broadcast packets to listen for was also specified. Suddenly, TV was working. 

 

One very good question is "why?" Why would I bypass the modem when it does not give me any benefits like faster internet or something like that? I believe the answer lies in why a radio amateur requires a huge system in order to receive radio signals. Personally I think it is funny to work with switches, routers and play around with network equipment. It also allows me to gain a deeper understanding of how my home network works beyond the black box, and it is a lot cooler to have a more "overkill network setup" for computer geeks. When I was done with this project, I ask myself if my ISP has ever thought about the cost to upgrade beyond Fast Ethernet? Today all the fiber customers have the AT gateway which only has Fast Ethernet interfaces. According to a manual to the gateway, the maximum speed they could deliver would be 90Mbit/s (I would say around 80Mbit/s because of HD TV). Beyond that, they would have to replace every single gateway for every customer who wanted faster internet. In addition to this, the equipment in their fiber centrals would have to be upgraded unless they already support faster speeds than Fast Ethernet. I also find it odd why Eidsiva does not have the VLAN information on their website, as some customers may want to bypass their gateway. Even if they had, this project would not have been as fun as if they did not post it. 

Image gallery:

 

Technical information for lazy readers:

Allied Telesis iMG616BD technical information:

http://www.alliedtelesis.com/p-2177.html

http://www.alliedtelesis.com/media/datasheets/iMG616lh-bd_ds.pdf (Data Sheet)

ftp://nas.lmkom.dk/Data/Allied%20Telesis/iMG6xx/iMG616srf+/Manualer/Software_Reference_Manual_3-8_Issue1.pdf (Manual)

Console Interface: 8-Pin mini-DIN, must have special pinout (AT-RGCONSOLECABLE (990-011748-00))

Serial access information for accessing the gateway through the console interface:

Baud rate: 38400

Data: 8 bit

Parity: none

Stop: 1 bit

Flow control: none

 

Media convert requirements:

Tx:1310nm

Rx:1550nm 

SC fiber interface

 

VLAN information:

VLAN 1: Internet

VLAN 5: VoIP

VLAN 10: IPTV

Remember to allow broadcast packets to be forwarded to the desired port for IPTV (IGMP snooping)