Thursday, May 8, 2008

Computer Privacy

This week the topics have centered around computer security and privacy. So far, we have looked at the security side, today we will look at the privacy perspective. Why is privacy so important? You might say - "I have nothing to hide." While that may be true, you may not realize that you may already be a target based on information you have looked at through internet searches or websites you have visited.

To explore this matter further, I found another Mark Nestmann article that deals with this topic. It is titled " WARNING: Uncle Sam and Hollywood Want to Root Through Your PC" which will be shared with you today and tomorrow. Since the article is rather lengthy, the first part will be about what the government and Hollywood is doing to invade your computer privacy. Tomorrow, the second part will provide some suggestions to protect yourself.

WARNING: Uncle Sam and Hollywood Want to Root Through Your PC

The FBI wants to look inside your PC. So does Hollywood. Together, their efforts could doom any semblance of computer privacy…unless you take the precautions outlined in this article.

Big Brother and Big Entertainment are both trying to shut down computer privacy, but for different reasons. BB says it needs to eliminate computer privacy to fight the "War on Terror." BE wants to end it to eliminate theft of copyrighted materials over the Internet. They are now acting in concert—a frightening trend. But by taking the simple but effective steps outlined in this column, you can still protect yourself.

The Government's War on Computer Privacy

To "bug" your PC (yes, it can be done quite easily) or read your e-mail, US law enforcement agencies must still obtain a search warrant approved by a judge, based on probable cause that you are involved in illegal (not necessarily terrorist) activity.

But obtaining information on "traffic data"—the origination or destination address for e-mails or list of Web sites you visit—is much easier. Indeed, police need only stipulate that such data is relevant to a criminal investigation. And, with the technology the FBI is currently using, it is almost impossible to review only traffic data and not ALSO the content of the messages. Customer payment records—finding the identity behind an e-mail address—don't require a warrant, either.

What's more, the grossly misnamed "USA PATRIOT Act" permits US Internet Service Providers (ISPs) to "voluntarily" disclose information connected to any "immediate threat to a national-security interest" to police. Since this law came into effect in 2002, requests from government agencies for ISPs to "voluntarily" relinquish e-mail and browsing data have grown exponentially.

The newly enacted Homeland Security Act goes a step further. It permits voluntary disclosure to any federal, state or local government entity and removes any requirement that the ISP "reasonably believe" that an "immediate threat to a national-security interest" exists.


Yes, You Probably DO Have Something to Hide

You might be thinking, "But I'm not a terrorist…I don't do anything illegal or suspicious on my PC…I don't have anything to hide."

But consider…

* Have you ever looked on a search engine for word pairs such as "offshore" AND "privacy?" This could be viewed as evidence that you are considering illegally laundering terrorist assets offshore—even if your actual intent is merely to educate yourself on how to legally protect your privacy internationally. Your "patriotic" ISP disclosing this information to the IRS might result in a long and arduous tax audit.

* Have you ever visited a Web site that might be a target of a government investigation; e.g., one that explores "alternative views" of current events? This could be viewed as evidence of terrorist leanings and, if misinterpreted, result in the freezing of all your assets and your indefinite detention without arrest or trial under "emergency orders" signed by President Bush.

* Have you ever received a message or browsed to a Web site that someone—anyone—might believe to be indicate that you are breaking the law—any law? For instance, millions of Americans visit online pornography or gambling sites daily. Yet many of them are unknowingly violating state and federal laws against child pornography or online gambling. If for any reason your ISP has a grudge against you—or win brownie points from police—it could "voluntarily" turn over browsing records to police, resulting in possible investigation, arrest, imprisonment and confiscation of your property.

Hollywood to the Rescue?

Or perhaps you occasionally use your PC to make copies of your own, legally acquired, CDs or DVDs. Perhaps you "burn" copies of your favorite CDs to listen to in your car, for instance. Or perhaps you duplicate DVDs so that you can keep one copy at your summer home and the master copy at your winter home.

These innocent actions, some entertainment companies believe, constitute "copyright theft." And in response, the next generation of PCs, for instance, will be equipped with CD and DVD players that incorporate a technology called "digital rights management" (DRM). Essentially, what they will do is "report back" to Hollywood whenever you make a copy of a copyrighted CD or DVD. Microsoft's newest operating system, Windows XP, incorporates DRM technology to streamline this process.

What's more, Hollywood is now demanding that digital broadcast "flag" be built into every new digital-TV receiver. This would allow copyright owners to track and/or designate which programming is copied to a PC—how often, and by whom.

The Bush Administration announced similar initiatives in its "cyber-terrorism" policy unveiled in January 2003. It includes a plan to require every Internet user to register their identity with their local Internet Service Provider and to provide a "live feed" of all Internet activity direct to law enforcement agencies, without a warrant. To make this possible, the FBI has developed new surveillance capabilities that aggregate Internet traffic in several key locations to facilitate eavesdropping. In this way, Hollywood and Big Brother are working hand-in-hand to terminate your PC privacy!

The newest initiative from Hollywood is the most threatening of all. Entertainment moguls are now sponsoring legislation that would give copyright owners the ability to break into your PC if you are SUSPECTED of a copyright violation. The copyright owner would have the right to "disable" or "destroy" offending content.

Imagine if you could do the same kind of thing where you live. You hear a dog barking all the time. You suspect it belongs to your neighbor, but you're not sure. You call your neighbor and she denies she even has a dog. Then you call the police to complain and nothing happens. So, after a few days, you break into the neighbor's home to "disable or destroy" the dog, perhaps with your .45 caliber revolver. Outrageous? Yes. But similar intrusions by copyright owners could soon be authorized by federal law.

Sun Microsystems CEO Scott McNealy spoke the truth when he announced in 2001, "You have zero privacy." But there is no reason to accept his proposed "solution" to this truth—to "get over it." There is a great deal you can do, right now, to protect your PC privacy from inquisitive investigators, nosy ISPs and remote attacks by the copyright police.

Tomorrow, I will share the second half of the article which will provide some suggestions for protecting your privacy.


"Because of the oppression of the weak
and the groaning of the needy,
I will now arise," says the LORD.
"I will protect them from those who malign them." Psalm 12:5 (NIV)

If you have comments or questions, please feel free to contact me at the address below.
Email: DeltaInspire@panama-vo.com

Wednesday, May 7, 2008

Preventing Computer Attacks

Today, we will conclude with some helpful hints on how to prevent computer intruders from attacking your computer system.
  • Consult your system support personnel if you work from home
  • If you use your broadband access to connect to your employer's network via a Virtual Private Network (VPN) or other means, your employer may have policies or procedures relating to the security of your home network. Be sure to consult with your employer's support personnel, as appropriate, before following any of the steps outlined in this document.

  • Use virus protection software
  • The CERT/CC recommends the use of anti-virus software on all Internet-connected computers. Be sure to keep your anti-virus software up-to-date. Many anti-virus packages support automatic updates of virus definitions. We recommend the use of these automatic updates when available.

    See http://www.cert.org/other_sources/viruses.html#VI for more information.

  • Use a firewall
  • We strongly recommend the use of some type of firewall product, such as a network appliance or a personal firewall software package. Intruders are constantly scanning home user systems for known vulnerabilities. Network firewalls (whether software or hardware-based) can provide some degree of protection against these attacks. However, no firewall can detect or stop all attacks, so it’s not sufficient to install a firewall and then ignore all other security measures.

  • Don't open unknown email attachments
  • Before opening any email attachments, be sure you know the source of the attachment. It is not enough that the mail originated from an address you recognize. The Melissa virus spread precisely because it originated from a familiar address. Malicious code might be distributed in amusing or enticing programs.

    If you must open an attachment before you can verify the source, we suggest the following procedure:

    1. be sure your virus definitions are up-to-date (see "Use virus protection software" above)
    2. save the file to your hard disk
    3. scan the file using your antivirus software
    4. open the file

    For additional protection, you can disconnect your computer's network connection before opening the file.

    Following these steps will reduce, but not wholly eliminate, the chance that any malicious code contained in the attachment might spread from your computer to others.

  • Don't run programs of unknown origin
  • Never run a program unless you know it to be authored by a person or company that you trust. Also, don't send programs of unknown origin to your friends or coworkers simply because they are amusing -- they might contain a Trojan horse program.

  • Disable hidden filename extensions
  • Windows operating systems contain an option to "Hide file extensions for known file types". The option is enabled by default, but you can disable this option in order to have file extensions displayed by Windows. After disabling this option, there are still some file extensions that, by default, will continue to remain hidden.

    There is a registry value which, if set, will cause Windows to hide certain file extensions regardless of user configuration choices elsewhere in the operating system. The "NeverShowExt" registry value is used to hide the extensions for basic Windows file types. For example, the ".LNK" extension associated with Windows shortcuts remains hidden even after a user has turned off the option to hide extensions.

    Specific instructions for disabling hidden file name extensions are given in http://www.cert.org/incident_notes/IN-2000-07.html

  • Keep all applications, including your operating system, patched
  • Vendors will usually release patches for their software when a vulnerability has been discovered. Most product documentation offers a method to get updates and patches. You should be able to obtain updates from the vendor's web site. Read the manuals or browse the vendor's web site for more information.

    Some applications will automatically check for available updates, and many vendors offer automatic notification of updates via a mailing list. Look on your vendor's web site for information about automatic notification. If no mailing list or other automated notification mechanism is offered you may need to check periodically for updates.

  • Turn off your computer or disconnect from the network when not in use
  • Turn off your computer or disconnect its Ethernet interface when you are not using it. An intruder cannot attack your computer if it is powered off or otherwise completely disconnected from the network.

  • Disable Java, JavaScript, and ActiveX if possible
  • Be aware of the risks involved in the use of "mobile code" such as ActiveX, Java, and JavaScript. A malicious web developer may attach a script to something sent to a web site, such as a URL, an element in a form, or a database inquiry. Later, when the web site responds to you, the malicious script is transferred to your browser.

    The most significant impact of this vulnerability can be avoided by disabling all scripting languages. Turning off these options will keep you from being vulnerable to malicious scripts. However, it will limit the interaction you can have with some web sites.

    Many legitimate sites use scripts running within the browser to add useful features. Disabling scripting may degrade the functionality of these sites.

    Detailed instructions for disabling browser scripting languages are available in http://www.cert.org/tech_tips/malicious_code_FAQ.html

    More information on ActiveX security, including recommendations for users who administer their own computers, is available in http://www.cert.org/archive/pdf/activeX_report.pdf

    More information regarding the risks posed by malicious code in web links can be found in CA-2000-02 Malicious HTML Tags Embedded in Client Web Requests.

  • Disable scripting features in email programs
  • Because many email programs use the same code as web browsers to display HTML, vulnerabilities that affect ActiveX, Java, and JavaScript are often applicable to email as well as web pages. Therefore, in addition to disabling scripting features in web browsers (see "Disable Java, JavaScript, and ActiveX if possible", above), we recommend that users also disable these features in their email programs.

  • Make regular backups of critical data
  • Keep a copy of important files on removable media such as ZIP disks or recordable CD-ROM disks (CD-R or CD-RW disks). Use software backup tools if available, and store the backup disks somewhere away from the computer.

  • Make a boot disk in case your computer is damaged or compromised
  • To aid in recovering from a security breach or hard disk failure, create a boot disk on a floppy disk which will help when recovering a computer after such an event has occurred. Remember, however, you must create this disk before you have a security event.


    Again, I want to give special thanks to US-CERT (United States Computer Emergency Readiness Team) for this list. For more information about this group and other computer security information, please consult their website http://www.cert.org/.


    Discretion will protect you,
    and understanding will guard you. Proverbs 2:11 (NIV)


    If you have comments or questions, please feel free to contact me at the address below.
    Email: DeltaInspire@panama-vo.com

    Tuesday, May 6, 2008

    How Computer Intruders Get In

    Yesterday, I began a new topic of computer security and privacy. Today, we will go into some detail as to how these computer intruders get access to your computer system and the effects.

    First of all, your information and computer files are important to you, and you will want to protect them. Information security is described under three main areas:
    • Confidentiality - information should be available only to those who rightfully have access to it
    • Integrity - information should be modified only by those who are authorized to do so
    • Availability - information should be accessible to those who need it when they need it
    These factors apply to home computer Internet users just as much as they would to any corporation or government network. As mentioned yesterday, you wouldn't want total strangers to be able to read your email or review your financial statements. Also, you should be able get to your information and files when you want to. This will require you to protect your computer system from these attacks which are described in more detail.
  • Trojan horse programs
  • Trojan horse programs are a common way for intruders to trick you (sometimes referred to as "social engineering") into installing "back door" programs. These can allow intruders easy access to your computer without your knowledge, change your system configurations, or infect your computer with a computer virus. More information about Trojan horses can be found in the following document.

    http://www.cert.org/advisories/CA-1999-02.html
  • Back door and remote administration programs
  • On Windows computers, three tools commonly used by intruders to gain remote access to your computer are BackOrifice, Netbus, and SubSeven. These back door or remote administration programs, once installed, allow other people to access and control your computer.

  • Denial of service
  • Another form of attack is called a denial-of-service (DoS) attack. This type of attack causes your computer to crash or to become so busy processing data that you are unable to use it. In most cases, the latest patches will prevent the attack. The following documents describe denial-of-service attacks in greater detail.

    http://www.cert.org/advisories/CA-2000-01.html
    http://www.cert.org/archive/pdf/DoS_trends.pdf

    It is important to note that in addition to being the target of a DoS attack, it is possible for your computer to be used as a participant in a denial-of-service attack on another system.

  • Being an intermediary for another attack
  • Intruders will frequently use compromised computers as launching pads for attacking other systems. An example of this is how distributed denial-of-service (DDoS) tools are used. The intruders install an "agent" (frequently through a Trojan horse program) that runs on the compromised computer awaiting further instructions. Then, when a number of agents are running on different computers, a single "handler" can instruct all of them to launch a denial-of-service attack on another system. Thus, the end target of the attack is not your own computer, but someone else’s -- your computer is just a convenient tool in a larger attack.

  • Unprotected Windows shares
  • Unprotected Windows networking shares can be exploited by intruders in an automated way to place tools on large numbers of Windows-based computers attached to the Internet. Because site security on the Internet is interdependent, a compromised computer not only creates problems for the computer's owner, but it is also a threat to other sites on the Internet. The greater immediate risk to the Internet community is the potentially large number of computers attached to the Internet with unprotected Windows networking shares combined with distributed attack tools such as those described in

    http://www.cert.org/incident_notes/IN-2000-01.html

    Another threat includes malicious and destructive code, such as viruses or worms, which leverage unprotected Windows networking shares to propagate. One such example is the 911 worm described in

    http://www.cert.org/incident_notes/IN-2000-03.html

    There is great potential for the emergence of other intruder tools that leverage unprotected Windows networking shares on a widespread basis.

  • Mobile code (Java/JavaScript/ActiveX)
  • There have been reports of problems with "mobile code" (e.g. Java, JavaScript, and ActiveX). These are programming languages that let web developers write code that is executed by your web browser. Although the code is generally useful, it can be used by intruders to gather information (such as which web sites you visit) or to run malicious code on your computer. It is possible to disable Java, JavaScript, and ActiveX in your web browser. We recommend that you do so if you are browsing web sites that you are not familiar with or do not trust.

    Also be aware of the risks involved in the use of mobile code within email programs. Many email programs use the same code as web browsers to display HTML. Thus, vulnerabilities that affect Java, JavaScript, and ActiveX are often applicable to email as well as web pages.

    More information on malicious code is available in http://www.cert.org/tech_tips/malicious_code_FAQ.html

    More information on ActiveX security is available in http://www.cert.org/archive/pdf/activeX_report.pdf

  • Cross-site scripting
  • A malicious web developer may attach a script to something sent to a web site, such as a URL, an element in a form, or a database inquiry. Later, when the web site responds to you, the malicious script is transferred to your browser.

    You can potentially expose your web browser to malicious scripts by

    • following links in web pages, email messages, or newsgroup postings without knowing what they link to
    • using interactive forms on an untrustworthy site
    • viewing online discussion groups, forums, or other dynamically generated pages where users can post text containing HTML tags

    More information regarding the risks posed by malicious code in web links can be found in CA-2000-02 Malicious HTML Tags Embedded in Client Web Requests.

  • Email spoofing
  • Email “spoofing” is when an email message appears to have originated from one source when it actually was sent from another source. Email spoofing is often an attempt to trick the user into making a damaging statement or releasing sensitive information (such as passwords).

    Spoofed email can range from harmless pranks to social engineering ploys. Examples of the latter include

    • email claiming to be from a system administrator requesting users to change their passwords to a specified string and threatening to suspend their account if they do not comply
    • email claiming to be from a person in authority requesting users to send them a copy of a password file or other sensitive information

    Note that while service providers may occasionally request that you change your password, they usually will not specify what you should change it to. Also, most legitimate service providers would never ask you to send them any password information via email. If you suspect that you may have received a spoofed email from someone with malicious intent, you should contact your service provider's support personnel immediately.

  • Email borne viruses
  • Viruses and other types of malicious code are often spread as attachments to email messages. Before opening any attachments, be sure you know the source of the attachment. It is not enough that the mail originated from an address you recognize. The Melissa virus (see References) spread precisely because it originated from a familiar address. Also, malicious code might be distributed in amusing or enticing programs.

    Many recent viruses use these social engineering techniques to spread. Examples include

    Never run a program unless you know it to be authored by a person or company that you trust. Also, don't send programs of unknown origin to your friends or coworkers simply because they are amusing -- they might contain a Trojan horse program.

  • Hidden file extensions
  • Windows operating systems contain an option to "Hide file extensions for known file types". The option is enabled by default, but a user may choose to disable this option in order to have file extensions displayed by Windows. Multiple email-borne viruses are known to exploit hidden file extensions. The first major attack that took advantage of a hidden file extension was the VBS/LoveLetter worm which contained an email attachment named "LOVE-LETTER-FOR-YOU.TXT.vbs". Other malicious programs have since incorporated similar naming schemes. Examples include

    • Downloader (MySis.avi.exe or QuickFlick.mpg.exe)
    • VBS/Timofonica (TIMOFONICA.TXT.vbs)
    • VBS/CoolNote (COOL_NOTEPAD_DEMO.TXT.vbs)
    • VBS/OnTheFly (AnnaKournikova.jpg.vbs)

    The files attached to the email messages sent by these viruses may appear to be harmless text (.txt), MPEG (.mpg), AVI (.avi) or other file types when in fact the file is a malicious script or executable (.vbs or .exe, for example). For further information about these and other viruses, please visit the sites listed on our Computer Virus Resource page:

    http://www.cert.org/other_sources/viruses.html
  • Chat clients
  • Internet chat applications, such as instant messaging applications and Internet Relay Chat (IRC) networks, provide a mechanism for information to be transmitted bi-directionally between computers on the Internet. Chat clients provide groups of individuals with the means to exchange dialog, web URLs, and in many cases, files of any type.

    Because many chat clients allow for the exchange of executable code, they present risks similar to those of email clients. As with email clients, care should be taken to limit the chat client’s ability to execute downloaded files. As always, you should be wary of exchanging files with unknown parties.

  • Packet sniffing
  • A packet sniffer is a program that captures data from information packets as they travel over the network. That data may include user names, passwords, and proprietary information that travels over the network in clear text. With perhaps hundreds or thousands of passwords captured by the packet sniffer, intruders can launch widespread attacks on systems. Installing a packet sniffer does not necessarily require administrator-level access.

    Relative to DSL and traditional dial-up users, cable modem users have a higher risk of exposure to packet sniffers since entire neighborhoods of cable modem users are effectively part of the same LAN. A packet sniffer installed on any cable modem user's computer in a neighborhood may be able to capture data transmitted by any other cable modem in the same neighborhood.


    Tomorrow, there will be more about ways to protect your computer system. Stay tuned ...

    I want to give special thanks to US-CERT (United States Computer Emergency Readiness Team) for this list.

    I have done no wrong, yet they are ready to attack me.
    Arise to help me; look on my plight! Psalm 59:4 (NIV)

    If you have comments or questions, please feel free to contact me at the address below.
    Email: DeltaInspire@panama-vo.com

    Monday, May 5, 2008

    Computer Security

    This week, I will focus on a new area never addressed in this blog, but it is very important to nearly everyone - computer security and privacy. Nearly everyone in this day under the age of 60 use computers, probably on a daily basis. Even if you do not use the computer for vital financial information, there are people that can easily obtain personal information about you that could devastate you.

    Let's start with the basics - what is computer security and why is it important to you? Computer security is the process of preventing and detecting unauthorized use of your computer. Prevention measures helps you stop unauthorized users (or "intruders") from accessing any part of your computer system. Detection helps you to determine whether or not someone attempted to break into your system, if they were successful, and what they may have done.

    The typical person uses a computer for everything these days from banking and investing to shopping and staying in touch with others through email or chat programs. Although you may not consider your communications "top secret", you probably don't want strangers reading your email or online bank statements. Even worse than that, they can use your computer to "invade" or attack other computers, covering their tracks and implicating you. They could also send forged email from your computer.

    Naturally, these situations are not fun to think about the implications. Why would anyone do such things? Intruders (also referred to as hackers, attackers, or crackers) may not care about you personally or your identity although computer ID theft is a growing problem. Most often they want to gain control of your computer to launch attacks on other computer system. They can hide their actual location so they can have anonymity while they attack high-profile computer systems such as government or financial systems. Some merely want to play the latest online computer games for free while you get the bill. Some may be malicious, cause damage to your computer by erasing data and computer files or reformatting your hard drive. Some may simply watch your movements, or an 'electronic voyeur' if you will.

    Now that I have your attention, you are probably asking yourself just how easy is it for hackers to do this? Unfortunately, as technology progresses, they are always discovering new vulnerabilities (also called "holes" to exploit computer systems and software. The more complex computer software becomes, the harder it is for companies to thoroughly test their software prior to releasing it to the public. This is sad, but very true.

    When holes are discovered, the computer vendors will usually develop patches to address the problem(s). However, it is up to you, the computer user, to obtain and install the patches. Furthermore, you must correctly configure the software to operate the most securely. Many have no clue on how to do these things, so their computer is even more at risk to these computer attacks. Most attacks are preventable if the patches are kept up-to-date with the security fixes.

    Tomorrow, we will get into more detail on how hackers get access to your system. Stay tuned ...

    For out of the heart come evil thoughts, murder, adultery, sexual immorality, theft, false testimony, slander. Matthew 15:19 (NIV)

    If you have comments or questions, please feel free to contact me at the address below.
    Email: DeltaInspire@panama-vo.com

    Saturday, May 3, 2008

    Tora Tora Tora

    In the past, I expressed my love of movies. Recently, I saw again the 1970 dramatization of the attack on Pearl Harbor called "Tora, Tora, Tora". These Japanese code words used literally mean "attack" on that early Sunday morning, December 7, 1941.

    The things that always struck me about this movie are the systems in place. Throughout the movie, there are literally hundreds of extras performing various administrivia for their corresponding departments of the military. One person who would hand a message to another who would hand it to another which would open and read the message to another, who would notify a higher ranking commander. Furthermore, if items of information did not follow exact procedure for priority ranking, they would get processed for normal delivery. For example, if the radar warning from two airmen when the main attack was over 100 miles away had been listened to, how would events have been changed?

    In retrospect, this all seems absurd because we have the benefit of hindsight to pick up on all the really important pieces of information and want to shout to the TV actors to "pay attention" to the vital pieces, as if we could change history. In real life and actual time line, many pieces of vital information also pass our attention as well. Do we pay attention? Do we understand the importance?

    Think about this for a minute. How many pieces of information pass our attention on a daily basis? How about per week, per month? How do we recognize the importance or determine what is frivolous or not?

    For months, I have passed a lot of information to my readers about many topics. Most of them are extremely important to my future, your future, the future of our country, and the future of the entire world. Have you recognized the importance? Have you acted on the information? Have you taken steps to protect yourself? Or, have you confined yourself to wait and see what happens? As always, the choice is yours.

    As I have mentioned in previous posts in this blog regarding one of my mottoes
    (the IKC principle) -
    I
    nformation is not Knowledge without Action,
    K
    nowledge creates Choices,
    Choices allow us to Change our lives.

    As with all Saturdays, I review key financial indicators to give a direction on the markets and what it means. The price of gold dropped a little lower from last week to close on Friday at $856.40 per ounce. Silver also fell slightly to close at $16.46 per ounce. The relative value the US dollar as compared against the other major world currencies rose this week to 73.50. This is the up from an all time low of 71.60 set during the last week in March. The price of oil also dropped slightly to $116.59 per barrel.

    For months, these have been significant warning bells going off that our economy is in severe trouble. When precious metal prices go higher, investors are fleeing from other unstable investments to ones that have historical safety. When oil goes up, all prices follow in turn, and inflation becomes rampant. When the US dollar index continues to lose ground against other world currencies, other countries are losing faith that the government can make good on payments of US government securities and existing debt obligations. When historically strong investment banks like Bear Stearns' assets get sold as a fire sale, that is a sign of serious problems resulting from the created credit crisis. These are all warning bells, red lights, and sirens going off. Who is listening?

    What good is a warning if no one listens to it? Changes need to be done, the solutions are out there. Is anyone acting? I am. I'm also teaching and showing others how to take advantage of the situation rather than to be overwhelmed by it. What are you doing? Are you waiting for the next President-elect. I assure you, nothing will change, regardless of who wins. You need to take action. Will you survive or be swept away? Again, the choice is yours.

    Since they hated knowledge
    and did not choose to fear the LORD,

    since they would not accept my advice
    and spurned my rebuke,

    they will eat the fruit of their ways
    and be filled with the fruit of their schemes.

    For the waywardness of the simple will kill them,
    and the complacency of fools will destroy them;

    but whoever listens to me will live in safety
    and be at ease, without fear of harm. Proverbs 1:29-33 (NIV)


    If you have comments or questions, please feel free to contact me at the address below.
    Email: DeltaInspire@panama-vo.com

    Friday, May 2, 2008

    TIEA

    Yesterday, I mentioned a warning regarding Tax Information Exchange Agreements (TIEA) between the United States and another foreign country. These are typically one-sided agreements that allow the US to have access to all kinds of financial information. The best description I have found of these agreements and how they work is from another Mark Nestmann article. Mr. Nestmann is a world renowned expert and author on wealth preservation and private investment banking.

    His July 2006 article was titled "Why You Should Favor Offshore Jurisdictions without Tax Information Exchange Agreements" and is attached below.

    Imagine that you were the finance minister of a small Caribbean island in the early 1980s. We’ll call the island “Amstrandia.”

    Amstrandia doesn’t really exist, but it’s representative of more than a dozen Caribbean islands and Central American countries. It’s a U.K. colony (now called an “overseas territory”), which is almost completely dependent on outside financial aid. To cut support costs, the U.K. convinced Amstrandia to become a tax haven in the 1970s. But the 900-pound gorilla next door, the U.S., didn’t like that idea.


    Uncle Sam thought that the U.S. investors who flocked to Amstrandia to take advantage of its zero tax status and strict bank secrecy laws weren’t paying their fair share of U.S. taxes. You soon learned that the U.K. Foreign Office, despite having encouraged Amstrandia to become a tax haven, had no intention of defending its haven status.


    The U.S. Treasury Department decided to force Amstrandia and more than a dozen other jurisdictions into ratifying treaties that required them to disclose U.S. interests in banks, mutual funds, IBCs, and asset protection trusts. In return, the Treasury Department would permit U.S. corporations the negligible benefit of deducting the costs of conventions in these jurisdictions from their taxable income.


    Sign on the Dotted Line—or Else...
    The conversation between the Treasury Department treaty negotiator and the leaders of jurisdictions like Amstrandia might have gone something like this:


    “We want Amstrandia to sign a Tax Information Exchange Agreement (TIEA) that gives the IRS the right to obtain information on U.S. persons who have financial interests in Amstrandia. After all, we have the right to know, because U.S. taxpayers have stashed away billions of dollars in Amstrandian banks, mutual funds, IBCs, and asset protection trusts. Oh, yes, and the treaty will give the right to the Amstrandian Revenue Service to obtain information about Amstrandians investing in the U.S.”


    The Prime Minister reminds the Treasury official that Amstrandia doesn’t have an income tax, and that therefore, there’s no Amstrandian Revenue Service.


    “We thought you might say that,” said the official. “We’re prepared to allow U.S. businesses that hold conventions on your island to take a tax deduction for the money they spend here. Think of the opportunity that could bring to this island.”


    “That’s very nice,” the Prime Minister replied. “But there are no hotels big enough to host a convention, and the airfield isn’t long enough for anything larger than a commuter plane. There’s no room to build a longer runway.”

    “One thing that we could use, though,” he added, “is an actual tax treaty; the kind that the U.S. has with more than 50 nations. Our citizens and businesses investing in the U.S. would then get the benefits typically provided in tax treaties, such as reduced withholding taxes, not being discriminated against by the U.S. Treasury and the ability to avoid double taxation.”


    Call the World Bank if You Need Help
    At that, the Treasury official stood up. “It’s been a pleasure, Mr. Prime Minister. But I have a flight to catch. As for developing Amstrandia’s infrastructure for tourism, I’m sure the World Bank or the IMF might be able to help with some additional loans, if you don’t mind complying with their austerity measures, such as doubling gasoline taxes. But, a tax treaty won’t be possible. We don’t negotiate tax treaties with tax havens.”


    “Our demands for a TIEA are non-negotiable. If you’re not willing to sign the treaty, we’ll place Amstrandia on tax and money laundering blacklists, and advise U.S. banks that transactions with Amstrandian financial interests should be handled with extra scrutiny. You wouldn’t want that, would you?”


    Of course, the Prime Minister wouldn’t want that. So, he signed the TIEA and after presenting the TIEA to Amstrandia’s executive council, the treaty was duly ratified.


    Naturally, the process didn’t always go the way it did in my fictional example. Some offshore jurisdictions willingly signed TIEAs with the U.S. Others didn’t sign TIEAs until the early 2000s, when George W. Bush’s administration placed renewed pressure on offshore jurisdictions to ratify them.


    If you read the press releases from the offshore jurisdictions that signed TIEAs, you’ll come away believing that they may be invoked only in the event of probable cause of tax fraud by a particular taxpayer. But that’s not what most of the treaties actually say. Instead, most TIEAs state that any information “foreseeably relevant or material to United States federal tax administration and enforcement with respect to the person identified” for investigation must be turned over to the IRS.


    Not “probable cause” of a criminal or even civil tax offense. Not even “reasonable suspicion.” Merely “foreseeably relevant.” U.S. courts have interpreted this authority as permitting TIEA information requests “even if the United States has no tax interest and no claim for U.S. taxes are potentially due and owing.” In other words, fishing expeditions into offshore accounts are explicitly permitted. The potential for abuse is obvious.


    Nations That Have Already Given In
    TIEAs are now in effect with Antigua & Barbuda, Aruba, the Bahamas, Barbados, Bermuda, the British Virgin Islands, the Cayman Islands, Costa Rica, Dominica, Dominican Republic, Grenada, Guernsey, Guyana, Honduras, the Isle of Man, Jersey, the Marshall Islands, Mexico, Peru, St. Lucia, and Trinidad & Tobago. In a handful of these countries, including Mexico and Barbados, ordinary tax treaties are in effect, but in most jurisdictions “encouraged” to sign TIEAs, information flows only one way—to the U.S.


    TIEAs have had, from the Treasury Department’s perspective, their desired effect. U.S. investment in Caribbean havens has decreased substantially. And with disinvestment has come a resurgence of influence by narcotics traffickers and other criminal elements in the region. The U.S. policy of deliberately stifling investment has led several Caribbean governments to the brink of financial collapse. Surely, this is not in the long-term interests of the U.S., although the Treasury Department acts as though it is.


    Now that you know about TIEAs, you’ll understand why The Sovereign Society generally recommends jurisdictions that haven’t signed such agreements, e.g., Austria, Liechtenstein and Panama. (Switzerland has consented to a TIEA-like addition to the U.S.-Swiss tax treaty, but its terms are far more restrictive than typical TIEAs.) While pressure continues on these countries, and others, such as the United Arab Emirates, to ratify TIEAs, these jurisdictions have the diplomatic and financial clout to avoid being intimidated by the U.S.


    Let’s hope their determination continues.
    By Mark Nestmann, LL.M.

    As you can see, Uncle Sam wants in on everyone's business. I have exposed in this blog a number of times that the global elitists are the policy-makers behind the IMF and the World Bank. They want total control through a one world government that is in control of all money. If you control money, you control what everyone does, including eating and living. They are very few self-sufficient individuals left on the planet unless you live in a very remote area and live off the land or oceans.

    So there are very good reasons why it is important to have privacy banking laws outside of criminal activity. It might be the last bastion of personal freedom and liberty left.

    What will you do when they impose a national ID card? How about an implanted RFID chip that has all your financial, medical, and personal information on it in your finger? Do you feel this is science fiction? Watch the 9 minute video below and then answer.

    http://www.youtube.com/watch?v=vuBo4E77ZXo

    As always, the choice is yours. What will you do?

    You are not a God who takes pleasure in evil;
    with you the wicked cannot dwell.

    The arrogant cannot stand in your presence;
    you hate all who do wrong.

    You destroy those who tell lies;
    bloodthirsty and deceitful men
    the LORD abhors.



    Not a word from their mouth can be trusted;
    their heart is filled with destruction.
    Their throat is an open grave;
    with their tongue they speak deceit.

    Declare them guilty, O God!
    Let their intrigues be their downfall.
    Banish them for their many sins,
    for they have rebelled against you.

    But let all who take refuge in you be glad;
    let them ever sing for joy.
    Spread your protection over them,
    that those who love your name may rejoice in you.

    For surely, O LORD, you bless the righteous;
    you surround them with your favor as with a shield. Psalm 5:4-6, 9-12 (NIV)

    If you have comments or questions, please feel free to contact me at the address below.
    Email: DeltaInspire@panama-vo.com

    Thursday, May 1, 2008

    Private Investment Banking

    This week, the topics are all related to international investing. Today, I will discuss the pinnacle of international investing, or private investment banking. Private investment banking is very different from retail banking at your local bank. They typically don't deal with the normal checking and saving accounts.

    First of all, private investment banking is usually only available to high net worth individuals with liquidity of over one million dollars. However, in some cases with some private banks, this may be lowered to much lower. Others are becoming more exclusive raising the minimum investment to open an account $1.5 million.

    The private banker is also different that your typical bank representative or bank manager. The private banker is either a wealthy owner or partner, and usually the bank takes on the name of the founder. The bank is elite, only known by a few, and has a philosophy rooted in over 200 years of tradition dedicated to private person-to-person banking.

    The private banker is bound personally, financially, and professionally to his clients investments, meaning his banking commitments are guaranteed by his entire personal fortune and he bears personal responsibility for its sound administration. It is his unlimited liability as a private banker that determines the kind of operations he engages in; thus he is known for his wisdom in risk control and asset allocation.

    He limits himself entirely to acting on his clients' best interests and instructions, managing their assets, and providing related services. Such activities are seen as an extension of the administration of his own assets. In fact, much of the time, his own wealth is invested in the same endeavors.

    Other qualities of the private investment banker are that he is a connoisseur of the international financial markets, focused on performance-oriented opportunities, and has unfailing respect of his clients' privacy. He serves both private and institutional clientele with renowned professionalism. Furthermore, he is defined by discretion, efficiency, and innovation, combined with integrity, stability, and continuity to suit multi-generational wealth building.

    You might ask why privacy may be so important to some people. Disregarding the illegal activities of embezzlement, tax evasion, and money laundering, there are many reasons for bank privacy. Here are just some of the reasons:
    • To hide it from friends, spouse or other family members
    • To prevent confiscation of money, e.g. in the case of potential bankruptcy or litigation
    • Privacy from press or publicity
    • Protection from criminals
    • Protection from over-bearing or corrupt local government agencies
    • Protection from solicitation (This might include charities, venture capitalists seeking seed money, family members, beggars, or investment salesmen)
    Unlike the United States where financial information is routinely and sometimes openly shared without your knowledge, consent, or compensation; the privacy banking laws in such countries as Switzerland, Austria, Lichtenstein, Luxembourg, Panama, and others are very strict. They will not share any information on their clients unless there is evidence that you are involved in illegal activities, and sometimes a conviction in international court or in that country is necessary. If anyone representing the bank does release any client information, they are committing a criminal offense subject to imprisonment and/or a monetary fine. The affected depositor may also sue the offending bank and bank employees involved, up to the amount of actual damages caused by the violation.

    Be wary of countries that have signed "Tax Information Exchange Agreements" with the United States. These TIEA treaties are one sided agreements that allow the IRS and US government agencies to demand information from banks and other financial institutions on their clients.

    There will be more on international investing tomorrow. Stay tuned ...

    I want to give special thanks to the Cradle of Gold Society for most of the information presented.

    A gossip betrays a confidence,
    but a trustworthy man keeps a secret.

    For lack of guidance a nation falls,
    but many advisers make victory sure. Proverbs 11:13-14 (NIV)


    If you have comments or questions, please feel free to contact me at the address below.
    Email: DeltaInspire@panama-vo.com