Dirty Politician: Rick Renzi indicted

Arizona Republican Rep. Rick Renzi has finally been indicted, on 35 counts that include extortion, embezzlement, and money laundering. The investigation has been conducted by the FBI (working on priority #4, “combat public corruption at all levels”), the IRS, the U.S. Attorney’s office, and the Department of Justice’s Office of Public Integrity.

February 23, 2008 · 1 min

More InfraGard FUD and misinformation

Gary D. Barnett, president of a financial services firm in Montana, has written an article about InfraGard for The Future of Freedom Foundation, apparently inspired by the Progressive article. Thankfully, he avoids the bogus “shoot to kill” claims, but he introduces some erroneous statements of his own. It’s apparent that he didn’t bother speaking to anyone in InfraGard or doing much research before writing his article, which is another attempt to spread fear, uncertainty, and doubt about the program. Barnett first goes wrong when he writes: ...

February 23, 2008 · 12 min

Canada busts 17 in botnet ring

This morning Canada arrested 17 people of ages ranging from 17 to 26 years old for running botnets containing “up to one million computers” in 100 countries. They face charges that could result in up to 10 years in prison. This barely scratches the surface of online criminal activity. Niels Provos of Google did a study (PDF) that found that of 4.5 million websites scanned between March of 2006 and February of 2007, 450,000 of them attempt to load malware on visiting machines. Sophos’ similar survey in July of last year that found that 29% of websites host malware, 28% host porn or gambling content, and 19% are spam-related. Drive-by malware installations (where merely visiting a website causes malware to be loaded onto your machine) are definitely the method of choice for creating botnets today. I recommend using Firefox with the NoScript plugin and the MyWOT plugin to help prevent getting infected by such sites. Tomorrow, I’ll be attending a New Mexico InfraGard conference at which I hope to learn more about recent malware trends (and get my copy of Catch Me If You Can and/or The Art of the Steal autographed by their author). This is another one open to the general public, so I expect no talk about “shoot to kill” powers except in jest. UPDATE (February 22, 2008): I’m quoted in Brian Jackson’s article on the Quebec botnet hacker bust on itbusiness.ca. I’m not entirely happy with the quotes attributed to me–I didn’t say “tens of millions,” though I said there have been botnets with more than a million hosts, and there are multiple millions of compromised hosts out there. If tens of millions is not accurate today, it will be in the future. The other quotation about IRC got a little bit garbled, but is not far off–I made the point that the bots of today have evolved from a combination of IRC bots of the past combined with denial of service attack tools, remote access trojans, and other malware, and many of them still use IRC as their mode of communication.

February 21, 2008 · 2 min

Con artists in desperate need of money

Although I’ve gone for the last several years with extremely few illegal prerecord telemarketing calls, I’ve received three to my cell phone in the last three weeks, all scams. (I wonder how many of these people were working in the mortgage business until recently?) Two of them came from faked caller IDs that look like UK telephone numbers (starting with +44), but which appear to actually be from Florida, a popular location for all kinds of scammers. The first call, on January 30, came from 44-207-490-6113and was selling auto warranties, no doubt at far above market prices, and was phrased in such a way as to attempt to deceive the recipient into thinking they needed to renew an existing warranty that is expiring. When I got to a human operator and asked to be put on their do-not-call list, the woman hung up on me. I need to learn to be more subtle in my questioning to get more information from these con artists. The second call, on February 12, gave caller ID of 866-526-9732, and said that I had won a no-catch, all-expenses-paid vacation for two, and asked me for my name and number so that I could be called and told where to pick it up. Unfortunately, it hung up on me while I was trying to provide a fake name and real phone number, so that I could identify the caller and sue them. The third call, today, gave caller ID of 44-207-414-4370 and was offering a credit card deal to “reduce my interest rate.” Again the wording expressed urgency about a limited-time offer and made it sound like it was with regard to a card I already hold. This time, I asked the human operator (after waiting quite some time to get one) what company he’s with. I had to ask three times–he kept repeating his script about “any Mastercard or Visa,” and I kept saying “no, what company are YOU with.” Finally, he said “United Debt Aid,” which is no doubt a fake name. I asked him to put me on their do-not-call list and again was hung up on as I was telling him he was working for a bunch of criminals. I didn’t get a chance to ask for a written do-not-call policy from any of these three, but I’m sure they don’t have them since they’re violating the law in several ways already. Prerecord calls with advertising to cell phones are flat out illegal, just as prerecord calls with advertising to residential phones is illegal (without an existing business relationship, according to the FCC, which has incorrectly added an exception not present in the actual statute). So is falsifying caller ID information, so is failing to identify the business calling or on whose behalf the call is being made. So is failing to put me on their do-not-call list, and so is failing to send a written do-not-call policy upon request. If anybody happens to come across more information that might identify who is behind these calls, let me know–I’d love to sue them. UPDATE (February 25, 2008): I got another auto warranty one today, Caller ID said 442074791697 and it began “Your auto warranty has expired” and claimed they had been trying unsuccessfully to contact me via mail–two lies in the first two sentences. I pressed 1 to talk to a live operator, who immediately asked me for the year and make of my car. I asked what company is providing the warranty, and he hung up on me. Apparently any questioning at all is reason for these scammers to proceed to the next call recipient. UPDATE (March 27, 2008): I received two more of these in quick succession–one on March 17 (auto warranty call from 505-217-2684) and one on March 19 (credit card rate reduction call from 305-654-1842). ConsumerAffairs.com has a story about ripoff auto warranties sold by companies in St. Louis. Verizon Wireless has filed a law suit against John Does to go after these auto warranty calls. UPDATE (April 7, 2008): Another auto warranty one, from 305-672-6663. I believe that at least some of these calls are coming from businesses run by former associates of Fax.com, a defunct broadcast fax and prerecord telemarketing business that received a $5,379,000 fine from the FCC in 2002 which was never collected, and was successfully sued by the D.C. law firm of Covington & Burling for $2.3 million in 2003, which I believe was also never collected. The legal system is not good at dealing with these sorts of criminals, because it’s all being left to civil enforcement, when these are the kind of people who need to be thrown in jail. UPDATE (April 10, 2008): Another from “Heather at account services,” caller ID 561-482-7092, for credit card rate reduction. The human being I spoke with confirmed that she’s in Boca Raton, FL–on a previous call the company was identified as “United Debt Aid” in Boca Raton. UPDATE (August 11, 2008): There’s a wealth of information about these calls and who’s behind them at the Stopping Heather Forums. ...

February 21, 2008 · 8 min

Scientology critic Shawn Lonsdale dies

Shawn Lonsdale, who began picketing the Church of Scientology in Clearwater, Florida in 2006, was found dead in his home of an apparent suicide. A garden hose was run from his car’s exhaust into a window of his home, and a suicide note was found. His protests against Scientology had declined last year, when he didn’t renew the domain registration for his critical website and stopped posting much on his blog. His conflict with Scientology began and peaked in 2006, when Scientology-hired PI’s dug up and publicized his two misdemeanor convictions for lewd and lascivious conduct, and subpoenaed him for a deposition regarding their claim that he was an agent of a group prohibited from protesting in downtown Clearwater. I would guess that the group in question was the Lisa McPherson Trust, and that the prohibition was the result of a legal settlement. Lonsdale appeared in the BBC Panorama episode on Scientology, which can be found on YouTube in its entirety. ...

February 20, 2008 · 2 min

Michael Shermer on Anonymous protest of Scientology

Monday’s Los Angeles Times featured a short op-ed piece by Michael Shermer of the Skeptics Society about Anonymous’ protests against Scientology, which is rightly both critical of Anonymous and Scientology.

February 20, 2008 · 1 min

Cayman Islands bank gets Wikileaks taken offline

As reported in Wired’s blog: Wikileaks, the whistleblower site that recently leaked documents related to prisons in Iraq and Guantanamo Bay, was taken offline last week by its U.S. host after posting documents that implicate a Cayman Islands bank in money laundering and tax evasion activities. In a pretty extraordinary ex-parte move, the Julius Baer Bank and Trust got Dynadot, the U.S. hosting company and domain registrar for Wikileaks, to agree not only to take down the Wikileaks site but also to “lock the wikileaks.org domain name to prevent transfer of the domain name to a different domain registrar.” A judge in the U.S. District Court for Northern California signed off on the stipulation between the two parties last week without giving Wikileaks a chance to address the issue in court. ...

February 20, 2008 · 4 min

Malware in digital photo frames

The Mocmex virus and other trojans have been found on digital photo frames from China sold at Target, Costco, Sam’s Club, and Best Buy. The photo frames are connected to a computer via USB to load photographs; on a Windows machine this will cause an executable stored on the photo frame to run, infecting the computer. The SANS Internet Storm Center has documented more details here and here. As more and more devices have built-in storage and can be connected via USB to PCs, we’ll see more and more attacks like this.

February 17, 2008 · 1 min

Spies who love you

Mark Fiore helps teach kids about the importance of warrantless wiretapping. (Hat tip to Bob Hagen.)

February 16, 2008 · 1 min

FBI responds to "shoot to kill" claims about InfraGard

The FBI has issued an official response to Rothschild’s Progressive article (PDF), which says, in part: In short, the article’s claims are patently false. For the record, the FBI has not deputized InfraGard, its members, businesses, or anything else in the program. The title, however catchy, is a complete fabrication. Moreover, InfraGard members have no extraordinary powers and have no greater right to “shoot to kill” than other civilians. The FBI encourages InfraGard members – and all Americans – to report crime and suspected terrorist activity to the appropriate authorities.The FBI response also states that Rothschild has “refused even to identify when or where the claimed ‘small meeting’ occurred in which issues of martial law were discussed,” and promises to follow up with further clarifying details if they get that information. I’ve updated my own response to Rothschild to include the above information.

February 16, 2008 · 1 min
Mastodon Verification