Friday, 7 May 2010
The gold mine: ID and other data thefts
"Over 1,000 NHS desktops part of botnet, says Symantec" (ZDnet.co.uk, 23 April 2010)
"iDefense: 1.5 million Facebook accounts for sale" (ZDnet.co.uk, 23 April 2010)
Therefore, one wonders why employers ease restrictions on employees using social networking sites, when usually the security of their own IT systems is average or bad. "Managers ease restrictions on Facebook use" (ZDnet.co.uk, 23 April 2010)
especially when a study by the French CNIL reveals that the most common password used is "123456"!!!!!! JDN, 22 January 2010
Security review by Symantec and other issues of web security
The recent story about a Twitter user confirms that data is gold. He was able, after numerous tweets to different users including to a Twitter employee, to find the ID and password of that employee and conduct himself as an Twitter administrator (JDN, 6 May 2010). He has been arrested in France in the Massif Central, after collaboration with the FBI (Obama's account was hacked).
A lot of those attacks are performed by users dowloading PDF documents and believing that their banks would send them e-mails requesting for their information (74% of phishing). It confirms that users are "culprits" as much as the perpetrators. If people were a bit more careful in what they download and read, there would be less succesful attacks. It is certainly the message of Remy Fevrier from the French Gendarmerie Nationale (the French police under the military umbrella) at the FIC or Forum International sur la Cybercriminalite held in Lille from the 31 March to 1st April 2010. He explained that some firms went bankrupt because precious data was stolent by a competitor which was then able to offer the product at a lesser price because it did not have the costs of research and development.
Coming back to the Symantec report, to control other computers, attackers continue to use keystroke softwares, uploading users' details and zombies/botnets I suppose.
Firefox and Safari are the most vulnerable browsers on the web currently. IE and Chrome being stable and quite below (50 instead of around 100).
See the summary in French on JDN "Les menaces IT n'ont pas connu la crise en 2009" (6 May 2010)
Friday, 23 April 2010
Hyping issues up: distortions when it comes to internet
1 - "The Real Problem With Internet Comments Isn't Anonymity" (TechDirt, 12 April 2010). That I would agree; people before internet could be anonymous for the better or for the worse (blackmail...). They could also be discovered and were accepting the risk; so why not now? Why the internet should change anything in us allowing anonymity? What we need is better education for people to understand the impact of their behaviours and better policing, but not an end to anonymity.
"Judge Who Was Revealed As Anonymous Commenter Sues Newspaper For $50 Million" (TechDirt, 8 April 2010)
"Israeli Supreme Court Says There Is No Legal Way To Reveal Anonymous Commenters Online" (TechDirt, 1 April 2010)
Columnist Claims Anonymity Is Bad For Our Country (TechDirt, 31 March 2010)
2 - "Dear Journalists: There Is No Cyberwar" (TechDirt, 9 April 2010). I don't completely agree. Governments use and will use the new technologies to attack and the disruptions will be different.
3 - As Cyberbullying Moral Panics Heat Up, Actual Rates Of Cyberbullying Decreasing (TechDirt, 9 April 2010). Well yes and no. Cyberbullying is a problem like its off-line version, but it is probably not so much of a problem as it is made up.
Similar distortion in the understanding of the law in order to catch behaviours we find offensive but which are not necessarily legal:
Son Gets Mom Charged With Harassment Over Facebook Account Hijacking (TechDirt, 8 April 2010) - apparently, the son lets the computer logged in; that is unauthorised access in the UK!
And if this is true, it is even worse: Sarkozy Kicks Off Criminal Investigation Into Blog/Twitter Reports He Had An Affair (TechDirt, 7 April 2010)
4 - or distortion in the use of the law: "Court Says President Bush Violated Wiretapping Laws With Warrantless Wiretap" (TechDirt, 31 March 2010) with Wired having published the decision from NorthDistrict Court of California http://www.wired.com/images_blogs/threatlevel/2010/03/walker.pdf
This affair echoes two others about procedure and the difficulties to conceptualise it:
"Leaving Your WiFi Open Decreases Your Fourth Amendment Rights To Privacy?" (TechDirt, 10 February 2010) - I can't see how there is less privacy if you leave your mobile phone or your landline accessible to people from the outside
"Duh, Don't Leave A Thumb Drive With Child Porn Plugged Into A Shared Computer" (TechDirt, 22 April 2010) - no expectation of privacy for a US court when the thumb drive is plugged in. I would agree (like Masnick and unlike Kerr with whom I seem to disagree quite a lot - he writes on VWs). Kerr argues the thumb drive is like a suitcase in a public space; inaccurate if it is plugged in as everybody can see what's in it, like an open suitcase (aka Masnick).
and see "Les points-clés du projet de loi Loppsi" (LeMonde, 09 February 2010)
Tuesday, 23 March 2010
Interpretation of traditional offences
Sexting: no child porn for the US courts
"Court Rejects PA DAs Attempt To Charge Teens For Sexting Themselves", TechDirt, 18 March 2010 - The court is right in legal terms. The child porn offence was meant to protect children against others (and adults) rather than against themselves (and their peers). But morally and practically, it is not satisfying. The DA could have used the money spent in prosecuting differently? I think this is one of the offences most deeply affected by our ways of consuming the new technologies
"California Court Says Online Bullying Is Not Protected Free Speech" TechDirt, 19 March 2010. Decision justified as long as the "bullying" fits the definition of harassment; calling somebody a jerk without a pattern of abuse is no harassment.
"ACS:Law Now Using Dubious Legal Theories To Threaten Slyck.com", TechDirt, 22 March 2010. It is not so much the headline that interests me than the details of the article: NY has passed a legislation to avoid forum shopping in liber law. In effect, libel decisions from foreign jurisdiction are unenforceable on its territory. This destroys the idea that one can be liable from anything published on the web by any jurisdiction; indeed, a condemnation can only be enforced if the country of residence accepts the enforcement! Remains the issue of the trial by abstentia and the difficulties the person may have to travel to the country who took the original decision as traditionally, stepping on one's territory is to accept its jurisdiction. So the ban is enforced differently!
But for no change in the law, just change in illegal methods to act: "Disgruntled Ex-Auto Dealer Employee Hacks Computer System To Disable Over 100 Cars" TechDirt, 18 March 2010
Meaning of "without authorisation"
"In declining to adopt the Seventh Circuit's interpretation of "without authorization," the court held that a "person uses a computer 'without authorization'... [only] [1] when the person has not received permission to use the computer for any purpose (such as when a hacker accesses someone's computer without any permission), or [2] when the employer has rescinded to access the computer and the defendant uses the computer anyway."... The Ninth Circuit declined to hold that the "defendant's authorization to obtain information stored in a company computer is 'exceeded' if the defendant breaches a state law duty of loyalty to an employer" because no such language was found in the CFAA.... The Ninth Circuit noted that because the CFAA was "primarily a criminal statute," and because there was ambiguity as to the meaning of the phrase "without authorization," it would construe any ambiguity against the government.... "
Compared with the UK, I thought of the Brown case where two police officers accessed the database (vehicle registration) for personal purposes, and then the Alison case in similar fashion: originally, the courts found there was no hacking; but the HL in Alison considered that "without authorisation" meant that without authorisation for the purpose involved.
Applied to the UK, the comment would meant that the HL got it wrong? I would disagree
"Courts Stretching Computer Hacking Law In Dangerous Ways" TechDirt, 18 March 2010
Tuesday, 16 March 2010
Climate change and hacking: does the end justify the means?
Because, once the discussion settled, it happens that the flaws were minor and did not change the overall conclusions of the report: climate change is created by man, the rise in temperatures is alarming, and we better get going otherwise our children will not be living on this planet. So why all that fuss and nothing on hacking?
"Strange case of moving weather posts and a scientist under siege", The Guardian, 2 February 2010 (page 6)
Monday, 15 March 2010
Google, China and Co: where do we draw the line between the acceptable and the not-so-acceptable?
So let us review the story about Google rethinking its policy in China. Much ink has been spilled over the issue.
First, Google made its annoucement on 13 January 2010, a date that feels a bit like a new year/new resolution statement. The annoucement was not to censor anymore its search results on Google China, whether or not requested by Chinese authorities. The consequences, i.e. the possible end of any business presence in China, were recognised as a possibility. What seems to have triggered the decision was a series of cyberattacks against Chinese human rights activists. (Guardian, 13 January 2010, front page and page 3).
"Google to end censorship in China over cyber attacks" (Tania Branigan, TheGuardian, 13 January 2010)
"Google counts cost of censorship and draws red line under China" (Bobbie Johnson, TheGuardian, 13 January 2010)
On the details of the attacks, see Guardian 14 January 2010 and 15 January 2010.
"Google acted on censorship amid China dissident fears" (TheGuardian, printed version 14 January 2010, front page)
"Google's move on Chinese censorship welcomed by human rights activists"
(TheGuardian, 14 January 2010, page 14)
"Accounts invaded, computers infected – human rights activists tell of cyber attacks", The Guardian, printed version 15 January 2010
The attacks bring into light how internet communications are central to governmental response to politics, including war. "Cyber-warfare 'is growing threat'" The Guardian, 4 February 2010, page 7; similarly, six months ago, "MyDoom virus hits key networks in US and South Korea" The Guardian, 9 July 2009, page 16 (the title in the printed version is slightly different: "Cyber attacks paralyse government computers in US and South Korea"). But for a different vision on a 'supposed' cyberwar: "White House Cyber Security Guy: There Is No Cyberwar", TechDirt, 9 March 2010
However, the cynics add that Google never made the money it expected to make; it has only one third of the search engines market in China which is dominated by Baidu= Governmental Chinese version of search engine. So its decision may not rest so much on willingness to defend democratic values through guaranteeing freedom of expression, than on profit-making interests.
In addition, Google's decision in 2006 to censor results hurt the company's reputation, so much that one of its founder, Sergey Brin, called it a "net negative" (see Guardian's article, 13 January 2010, page 3; and page 14, 14 January 2010).
Nevertheless, cynicism may not be so much on the agenda. Let us face it: Google is not the new knight defending freedom of expression without awaiting something in return. On the other hand, personal history certainly plays a role here. Sergey Brin emigrated to the US in 1979, aged six, with his parents who were victims of anti-semitism, even under the then-USSR. (Guardian's, Tania Branigan, 14 January 2010, front page).
China's reaction was at the beginning cautious... and heavily censored as few headlines made it on the newspapers/online versions in China itself. Some commentators, pro-governmental line, did not see Google's decision as 1) affecting China much (there are other search engines), 2) as a desinterested decision (aka, Google does not make enough profit to stay).
What seems to emerge on the side, with other companies finding it difficult to enter the Chinese market, is a picture of full protection of Chinese interests (economic or not) against foreign companies and Governments. It fits with a presentation I attended in September 2009 at the Society for Legal Scholars (SLS) in Keele, where the speaker demonstrated that Chinese law favoured chinese contract law in all dispute resolutions, a concept that systematically discards foreign law; in other words, private international law in China is resolved by the quasi-systemic application of local law to the exclusion of foreign law. An article on the International Herald Tribune of 14 January 2010 page 15 is quite revealing on those behaviours. The article even ends up by saying, in more polite form, that foreign companies sell their soul to China, accepting to give for free, for fear of loosing a market share, what they would never have tolerated in other countries. I know the story is not exagerated. In his second volume on Globalisation, which focuses on Water, Eric Orsenna (French Academician and writer) explains that the French company Alstom more or less gave the plans of its water turbines for the three Dams on the yellow river, in exchange for obtaining the market... Except that the turbine plan is now copied and Alstrom not needed...
"China stifles news of Google’s defiance", The International Herald Tribune, 14 January 2010 (p. 1)
"Google Is Not Alone in Discontent, But Its Threat Stands Out", The New York TImes, 14 January 2010 (by the way, this habit of the NYT and IHT not to use the same title in the printed and online version is frankly annoying).
Eric Orsenna, L'avenir de l'eau : Petit précis de mondialisation II (Broché), Fayard 2008 (The future of water: little manual on globalisation II - NB: the first volume was on coton and is as interesting as the second, if anybody can read French - by the way, it is not a complicated French although it is beautifully written).
If we take into account China's policy in conducting business, then it appears very clearly that accepting to censor the results could only amount to failure in terms of believing that the economy will allow for freedom of expression to grow. The economy is in itself a close circuit; nothing from the outside will penetrate it, especially NOT freedom of expression. After 30 years of economic "liberalisation", the West should start looking at the full picture, rather than avoiding the issue: China will not become a democracy by free market. See James Kynge, "Full circle", Financial Times 16/17 January 2010.
"China and the west: Full circle", Financial TImes, 15 January 2010 (printed version, 16/17 january 2010 (like for the Guardian, can't they just give one date???)
Viewed under that light, Bill Gates' comment is not as irresponsible as it may first appear. It is a realist comment: that anyone doing business in China has to accept the fact that democracy is out of question. Then the question is: does one have the guts, to take a familiar expression, not to do business? The West's answer so far is certainly not living to its Enlightenment's ideals.
"Playing the wall game in China" The Guardian, 18 January 2010
Additionally see:
"Google may lose business, but gains good will", Miguel Helft, International Herald Tribune, printed version January 16/17, 2010 (can't find the link online)
"Why fearful china stamps out dissent", Peter Beaumont, The Observer, 17 January 2010, p. 22 (can't find the link online either)
Will Google stand up to France and Italy, too? The Guardian, 14 January 2010
"China Issues Another Warning to Google on Enforced Censorship of the Internet" link to NY Times by Business and HR website, 12 March 2010
Friday, 22 January 2010
Privacy, piracy, copyrights and censorship
"Hacking Surpassing Human Error For Data Breaches?" (TechDirt, 19 January 2010). For the author, the answer is actually positive: hacking is a major threat, more that insiders leaking data.
In the fight against piracy, will privacy be waived? "Swedish ISP Refuses To Give Up Info; Says IPRED Violates EU Privacy Rules" (TechDirt, 18 January 2010)
"The Similarity Between ACTA And Chinese Internet Censorship" (TechDirt, 20 January 2010) in that both requires strong involvement from ISPs. I also think that both infringed on privacy. But the issue of ISPs involvement is also close to more traditional searches and seizures: "Once Again, FBI Caught Breaking The Law In Gathering Phone Call Info; But Real Issue Is Why Telcos Let Them" (TechDirt, 19 January 2010)
Obviously, all this debate supposes there is such thing as privacy about data online. Hence the issue about cloud computing and expectations of privacy. "Do You Have Any Legal Right To Privacy For Information Stored Online?" (TechDirt, 19 January 2010) THe US have actually articulated that notion of expectation of privacy, even though the answer is not satisfactory: it is not because it is online that there is no expectation of privacy. It all depends on where and what was intended to be done with the data.
France Considers 'Right To Forget' Law, Apparently Not Realizing The Internet Never Forgets (TechDirt, 8 January 2010)
Tuesday, 8 December 2009
Virtual worlds and theft
For disapproval, "If You Gain Unauthorized Access To A Character In A Virtual World, Is It Theft?" (TechDirt, 01 December 2009)
Contra: "Is virtual boom our industrial revolution?" (TheGuardian, 10 September 2009)
http://www.guardian.co.uk/technology/2009/sep/09/victor-keegan-virtual-world-revolution
Friday, 24 July 2009
Twitter hacked
"Twitter hacké : 310 documents confidentiels volés" (JDN, 16 July 2009)
Friday, 26 June 2009
Fraud and insider access to confidential data
http://www.cyber-ark.com/news-events/pr_20090610.asp
and a French summary of the report on JDN 17 June 2009
Un tiers des administrateurs informatiques tentés par le vol de données
Tuesday, 16 June 2009
Nasa hacker
Court hears Nasa hacker 'at risk of psychosis' (ZDnet.co.uk, 9 June 2009)
Judges delay decision in Nasa hacker case (ZDnet.co.uk, 11 June 2009)
Nasa hacker petition tops 4,000 (ZDNet.co.uk, 15 June 2009)
Wednesday, 10 June 2009
Hacking -future of hackers
"Lawyer: Home Office unlikely to U-turn on hacker " (ZDNet.co.uk, 8 June 2009)
But there may be some hope in the mid-term future: (ex) "Hacker joins US Homeland Security in advisory role" (ZDnet.co.uk, 8 June 2009)
with the following update: "Mitnick: from 'computer terrorist' to consultant " (ZDnet.co.uk, 23 June 2009)
Tuesday, 19 May 2009
Distorting offences
Thursday, 9 April 2009
Cyber attack, reaction/action
"Report: US electricity grid hacked by spies" (ZDnet.co.uk, 9 April 2009)
"Pentagon forks out $100m for cyberattack cleanup" (ZDnet.co.uk, 8 April 2009)
Wednesday, 25 March 2009
Computer misuses: hacking and the rest
- 19% steal information in order to sell it = profit
- 24% deface a website (i.e. change its homepage with a message)
- 5% is phishing
The attacks originate for 66% from North America, 16% from Europe, 6% Asia, which is probably a reflection of internet access and use.
and Government websites & co represent 32% of the victims. Two explanations here: Government got sensitive information (hence theft and fraud) and they represent the law (thus issue of politics or hactivism)
http://www.breach.com/resources/whitepapers/downloads/WP_WebHackingIncidents_2008.pdf
for a partial translation in French see Journal du Net (March 2009)
Sunday, 1 February 2009
Nasa hacker's perception on his trial
"Nasa hacker: I'd get a fairer trial in UK" (ZDnet.co.uk, 28 January 2009 - video)
Sunday, 25 January 2009
UK institutions victims of viruses
"Downadup virus hits PCs at five Sheffield hospitals " (ZDnet.co.uk, 22 January 2009)
More serious in terms of national security, and certainly more worrying, is the MoD's system victim of viruses. "Virus causes Ministry of Defence outages " (ZDnet.co.uk, 16 January 2009)
Tuesday, 6 January 2009
Hacking - twitter and security staff
"Twitter hack targets Obama, Britney" (ZDNet.uk, 6 January 2009)
"Yeah, Your IT Guy Is Probably Reading Your Email" (TechDirt, June 2008)
Hacking e-mail - fraud and prosecution
and on the importance of criminalising the simple act of hacking whatever the outcome is... "Is The Indictment Of The Palin Email Hacker Legally Correct?" (TechDirt, 15 October 2008)