Categories
Links Writing

US Internet Imperialism Strikes (Again!)

Wired has run a decent piece surrounding unilateral American seizures of domain names by acting on critical infrastructure governed by US law. A key bit from the article to get you interested:

Bodog.com was registered with a Canadian registrar, a VeriSign subcontractor, but the United States shuttered the site without any intervention from Canadian authorities or companies.

Instead, the feds went straight to VeriSign. It’s a powerful company deeply enmeshed in the backbone operations of the internet, including managing the .com infrastructure and operating root name servers. VeriSign has a cozy relationship with the federal government, and has long had a contract from the U.S. government to help manage the internet’s “root file” that is key to having a unified internet name system.

These domain seizures are a big deal. Despite what some have written, even a .ca address (such as the address country code top level domain linked to this website) could be subjected to a take down that leverages the root file. In effect, US copyright law combined with American control of critical Internet infrastructure is being used to radically extend America’s capability to mediate the speech rights of foreign citizens.

The capacity for the US to unilaterally impact the constitution of the Web is not a small matter: such actions threaten the sovereign right to establish policy and law that governs the lives of citizens living in countries like Canada, Russia, Australia, and Europe generally. Something must be done, and soon, before the Web – and the Internet with it – truly begins to fracture.

Categories
Links Writing

Data Protection Officers Needed in the EU

Peter Fleischer, Google Global Privacy Counsel, notes that most companies with over 250 employees will likely need a Data Protection Officer as a result of updates to European law . He rightly notes that such updates should increase basic data protection awareness in companies, though I have concerns about the effectiveness of securing privacy through data protection.

To be sure, breaches will hopefully be assuaged (though almost certainly not stopped) but data will be protected to the letter of the law as opposed to being secured to the level of citizens’ normative expectations of privacy. As a result, the legalization of data protection and privacy will continue to let companies engage in practices that citizens find upsetting without those practices actually being outlawed or banned.

Categories
Aside Links

Cogeco’s Meters are Still Broken

From DSLReports we find that:

The leap year appears to be the latest thing to confuse Cogeco’s metering software, with users reporting that a bug resulted in them being informed they’d already used their monthly allotment before March even really got started. Notes one of several users:

“I got my 100% warning on March 1st. I use my router as well to watch my usage. My router for Feb shows 170GB, Cogecos 254. I am going to get hit with a $75 charge and I am pissed. Measurement Canada needs to get involved here, this is getting absurd.”

Measurement Canada seems absolutely unwilling to get involved in issues related to mobile or landline data speeds and volume accuracy. We really need to get at least an OfCom level of involvement: the punting between Industry Canada, Measurement Canada, and the CRTC continues to have very real implications for citizens and consumers, and these problems have to be addressed.

 

Categories
Links Writing

How Notice-and-Takedown Hurts Real People

Under DMCA rules a copyright holder can request that content hosts, such as Flickr, take down content that is believed to infringe on the holders’ copyright. Hosts will typically take down content and subsequently notify whomever posted it. The poster can then respond (after the content is already down) to argue that they were within their rights to post the content either because (a) it was the poster’s own content; (b) it was posted under fair use provisions.

Some copyright holders assert that notice-and-takedown is an acceptable approach (others insist that even this is too onerous, and that the hosts themselves should be responsible for policing their users) on the basis that if there is an error then a poster can try and remedy the take down order. Unfortunately, this assumes that whatever is taken down can be, or is, replaced in full after the order is issued. As a recent Techdirt article reveals, this isn’t always the case:

As the system “works” today, it’s open to misuse. And despite claims from proponents of the DMCA process, there’s more at stake than simply the single item in question. With one false DMCA notice, the entire history of a popular photo was erased, taking with it the story of how this “alphabet” came to be. The “notice-and-takedown” process is very obviously broken, resulting in the sort of situation Gorman has described.

When you consider the amount of damage that a single mistaken DMCA notice can do, it’s amazing that this process is still considered to be “fair” by its users. This is yet another strong argument for a notice-and-notice process in which companies and individuals would have a chance to file a counterclaim before the content is deleted, rather than having to assert their claim post-takedown and be left to clean up the resulting mess.

As someone who writes professionally I am genuinely sympathetic to copyright holders: I get that there are prospective revenue losses from infringement and acknowledge that digital copying imposes challenges for historical business models and processes. This said, if a copyright holder demonstrably fails in its due diligence when issuing a notice-and-takedown then it should be held liable, just as it is attempting to hold liable a potentially infringing user. There must be some kind of equity in the notice-and-takedown system or, better, a move to a notice-and-notice system (such as in Canada) to limit the harms that arise from poorly targeted take down efforts.

Categories
Links

Reasons To Not Use A Proxy Server

Some of the reasons to be concerned about using unknown third-parties’ proxy services.

Categories
Links

Police Look Up Woman’s License 425 Times

We should never forget that a large number of data/privacy breeches start from within a bureaucracy/organization. When an audit was performed on the drivers license database in Minnesota, auditors found that a staggering number of officers had ‘checked up’ on a woman’s profile. From the article on this:

The numbers were astounding: One hundred and four officers in 18 different agencies from around the state had accessed her driver’s license record 425 times in what could be one of the largest private data breaches by law enforcement in history.

The Department of Public Safety sent letters to all 18 agencies demanding an Internal Affairs investigation of the 104 officers. If the cops are found to be in violation of federal privacy law, they could be fired.

It isn’t enough to assume that the police are all knights in shining armour, incapable of doing wrong. No: they’re people, with all the expected foibles and failings. Give them information and powers and they will abuse them. The only questions are when and with what consequence.

Categories
Links

Phishing on Mobile Devices

A good paper on (you guessed it!) phishing on mobile devices. Paper is here (.pdf) and abstract is below.

We assess the risk of phishing on mobile platforms. Mobile operating systems and browsers lack secure application identity indicators, so the user cannot always identify whether a link has taken her to the expected application. We conduct a systematic analysis of ways in which mobile applications and web sites link to each other. To evaluate the risk, we study 85 web sites and 100 mobile applications and discover that web sites and applications regularly ask users to type their passwords into contexts that are vulnerable to spoofing. Our implementation of sample phishing attacks on the Android and iOS platforms demonstrates that attackers can spoof legitimate applications with high accuracy, suggesting that the risk of phishing attacks on mobile platforms is greater than has previously been appreciated.

 

Categories
Links

Security Bugs In Google Chrome Extensions

A piece that was authored last September, enumerating some of the security issues with Google Chrome Extensions. The authors:

reviewed 100 Chrome extensions and found that 27 of the 100 extensions leak all of their privileges to a web or WiFi attacker. Bugs in extensions put users at risk by leaking private information (like passwords and history) to web and WiFi attackers. Web sites may be evil or contain malicious content from users or advertisers.  Attackers on public WiFi networks (like in coffee shops and airports) can change all HTTP content.  We’ll show you how you can prevent attacks on your extension using Content Security Policy.

In a followup, the authors have published a full report (here) that outlines their methodology and identifies the extensions that, as of February 2012, remain unpatched.

Check out the article, and some of the other great pieces that they’ve published on security.

Categories
Links

Internet Voting is a Bad, Bad Idea

Last year The Star ran an article detailing the merits of online voting. You get the usual benefits: increased turnout, happier constituents, and enhanced convenience. What the article entirely misses, of course, are the security and associated legitimacy issues linked with voting online. An academic blogger, writing before the article, notes that:

‘securing’ the Internet is a Herculean task. It absolutely cannot be regarded as a ‘secure’ development environment, especially when dealing with matters that are highly sensitive to political, technical, and social fault conditions. Such conditions may be worse that a fail condition, on the basis that faults generate fear and concern without a clear indication that something has gone wrong. In the case of an election, a perceived exploitable fault condition threatens to undermine political legitimacy and politically-generated solidarity on grounds that electoral results might be questionable. Thinking back our bridge example, a ‘fail’ might be a bridge collapsing. A ‘fault’ might include cracks spanning the support columns that cause motorists to avoid using the bridge out of fear, even though the cracks do not endanger the bridge’s stability. If ‘faults’ cannot be corrected, then there may be general fear about the validity of an election even if the election is not manipulated. If a ‘fail’ condition occurs but is not detected, then there may be a perception of electoral legitimacy without the election actually being legitimate.

Elections are not something to be trivially tampered with. Heightened conveniences should not trump electoral security and legitimacy. While paper voting is annoying it is a far more ‘secure’ method than online voting mechanisms. It really isn’t too much to ask/expect of people to mail in a vote, go to a polling station, or (quite reasonably) abstain from the process for their own reasons. We should not undermine a foundation of democracy just to make things a little bit more convenient.

Categories
Links

American Link To Greek Surveillance Debacle?

In 2004 it was discovered that parties unknown had been secretly monitoring a hundred of Greece’s top politicians and bureaucrats. An article from 2011 reveals that,

According to what sources told Kathimerini, the experts found that a mobile phone connection that had been purchased in the name of the US Embassy in Athens was used on one of these phones. Sources said that Dasoulas is now investigating whether any suspects who are not protected by diplomatic immunity could face charges.

Ericsson, which supplied the telephone exchange that was hacked into, and Vodafone, which was the service provider, were both fined by ADAE in 2007 for failing to protect the privacy of those who had their phones hacked, which included the head of the National Intelligence Service (EYP), several ministers and members of the armed forces, but the Council of State later cancelled these penalties.

The followup, of whether the Americans were actually involved, is ongoing as far as I can tell. Regardless of the culprits it’s instructive that even the head of the intelligence service was successfully targeted. We need to be mindful of how surveillance technologies are deployed in our communications networks, not just because we worry about how our own government might use the technologies, but also because of how other third-parties might use the technologies against the citizenry.