Showing posts with label Offences - Hacking (unauthorised access). Show all posts
Showing posts with label Offences - Hacking (unauthorised access). Show all posts

Friday, 7 May 2010

The gold mine: ID and other data thefts

Between the NHS desktops that were hacked and controlled as part of a botnet, and facebook accounts also hacked, it is obvious that security and privacy are at the heart of cybercrime. Accessing illegally and controlling data/computers is at the heart of a successful criminal entreprise.

"Over 1,000 NHS desktops part of botnet, says Symantec" (ZDnet.co.uk, 23 April 2010)

"iDefense: 1.5 million Facebook accounts for sale" (ZDnet.co.uk, 23 April 2010)

Therefore, one wonders why employers ease restrictions on employees using social networking sites, when usually the security of their own IT systems is average or bad. "Managers ease restrictions on Facebook use" (ZDnet.co.uk, 23 April 2010)

especially when a study by the French CNIL reveals that the most common password used is "123456"!!!!!! JDN, 22 January 2010

Security review by Symantec and other issues of web security

Symantec published its report analysing cyber-issues in 2009. Most of the attacks continue to come from the US (19%), followed by China (8%) and a new comer, Brazil (6%). The bulk of the attacks (37%) focuses on acquiring data, then it is accessing structural tools of companies (26%) and piracy (15%). Fraud represents only 2%. It confirms that the new value or currency today is data, rather than money itself as a direct target. In other words, data is worth more than currencies.
The recent story about a Twitter user confirms that data is gold. He was able, after numerous tweets to different users including to a Twitter employee, to find the ID and password of that employee and conduct himself as an Twitter administrator (JDN, 6 May 2010). He has been arrested in France in the Massif Central, after collaboration with the FBI (Obama's account was hacked).

A lot of those attacks are performed by users dowloading PDF documents and believing that their banks would send them e-mails requesting for their information (74% of phishing). It confirms that users are "culprits" as much as the perpetrators. If people were a bit more careful in what they download and read, there would be less succesful attacks. It is certainly the message of Remy Fevrier from the French Gendarmerie Nationale (the French police under the military umbrella) at the FIC or Forum International sur la Cybercriminalite held in Lille from the 31 March to 1st April 2010. He explained that some firms went bankrupt because precious data was stolent by a competitor which was then able to offer the product at a lesser price because it did not have the costs of research and development.

Coming back to the Symantec report, to control other computers, attackers continue to use keystroke softwares, uploading users' details and zombies/botnets I suppose.
Firefox and Safari are the most vulnerable browsers on the web currently. IE and Chrome being stable and quite below (50 instead of around 100).

See the summary in French on JDN "Les menaces IT n'ont pas connu la crise en 2009" (6 May 2010)

Friday, 23 April 2010

Hyping issues up: distortions when it comes to internet

1 - "The Real Problem With Internet Comments Isn't Anonymity" (TechDirt, 12 April 2010). That I would agree; people before internet could be anonymous for the better or for the worse (blackmail...). They could also be discovered and were accepting the risk; so why not now? Why the internet should change anything in us allowing anonymity? What we need is better education for people to understand the impact of their behaviours and better policing, but not an end to anonymity.
"Judge Who Was Revealed As Anonymous Commenter Sues Newspaper For $50 Million" (TechDirt, 8 April 2010)
"Israeli Supreme Court Says There Is No Legal Way To Reveal Anonymous Commenters Online" (TechDirt, 1 April 2010)
Columnist Claims Anonymity Is Bad For Our Country (TechDirt, 31 March 2010)


2 - "Dear Journalists: There Is No Cyberwar" (TechDirt, 9 April 2010). I don't completely agree. Governments use and will use the new technologies to attack and the disruptions will be different.

3 - As Cyberbullying Moral Panics Heat Up, Actual Rates Of Cyberbullying Decreasing (TechDirt, 9 April 2010). Well yes and no. Cyberbullying is a problem like its off-line version, but it is probably not so much of a problem as it is made up.

Similar distortion in the understanding of the law in order to catch behaviours we find offensive but which are not necessarily legal:
Son Gets Mom Charged With Harassment Over Facebook Account Hijacking (TechDirt, 8 April 2010) - apparently, the son lets the computer logged in; that is unauthorised access in the UK!
And if this is true, it is even worse: Sarkozy Kicks Off Criminal Investigation Into Blog/Twitter Reports He Had An Affair (TechDirt, 7 April 2010)

4 - or distortion in the use of the law: "Court Says President Bush Violated Wiretapping Laws With Warrantless Wiretap" (TechDirt, 31 March 2010) with Wired having published the decision from NorthDistrict Court of California http://www.wired.com/images_blogs/threatlevel/2010/03/walker.pdf

This affair echoes two others about procedure and the difficulties to conceptualise it:
"Leaving Your WiFi Open Decreases Your Fourth Amendment Rights To Privacy?" (TechDirt, 10 February 2010) - I can't see how there is less privacy if you leave your mobile phone or your landline accessible to people from the outside
"Duh, Don't Leave A Thumb Drive With Child Porn Plugged Into A Shared Computer" (TechDirt, 22 April 2010) - no expectation of privacy for a US court when the thumb drive is plugged in. I would agree (like Masnick and unlike Kerr with whom I seem to disagree quite a lot - he writes on VWs). Kerr argues the thumb drive is like a suitcase in a public space; inaccurate if it is plugged in as everybody can see what's in it, like an open suitcase (aka Masnick).

and see "Les points-clés du projet de loi Loppsi" (LeMonde, 09 February 2010)

Tuesday, 23 March 2010

Interpretation of traditional offences

Three scenari demonstrating how the internet affects the interpretation of criminal law

Sexting: no child porn for the US courts
"Court Rejects PA DAs Attempt To Charge Teens For Sexting Themselves", TechDirt, 18 March 2010 - The court is right in legal terms. The child porn offence was meant to protect children against others (and adults) rather than against themselves (and their peers). But morally and practically, it is not satisfying. The DA could have used the money spent in prosecuting differently? I think this is one of the offences most deeply affected by our ways of consuming the new technologies

"California Court Says Online Bullying Is Not Protected Free Speech" TechDirt, 19 March 2010. Decision justified as long as the "bullying" fits the definition of harassment; calling somebody a jerk without a pattern of abuse is no harassment.


"ACS:Law Now Using Dubious Legal Theories To Threaten Slyck.com", TechDirt, 22 March 2010. It is not so much the headline that interests me than the details of the article: NY has passed a legislation to avoid forum shopping in liber law. In effect, libel decisions from foreign jurisdiction are unenforceable on its territory. This destroys the idea that one can be liable from anything published on the web by any jurisdiction; indeed, a condemnation can only be enforced if the country of residence accepts the enforcement! Remains the issue of the trial by abstentia and the difficulties the person may have to travel to the country who took the original decision as traditionally, stepping on one's territory is to accept its jurisdiction. So the ban is enforced differently!

But for no change in the law, just change in illegal methods to act: "Disgruntled Ex-Auto Dealer Employee Hacks Computer System To Disable Over 100 Cars" TechDirt, 18 March 2010

Meaning of "without authorisation"

Quite interesting facts and legal issue of defining what is "without authorisation". In the US, an employee used his employer's computer to access personal information that he then deleted. The seventh circuit court found it was hacking but the ninth circuit court rejected the interpretation. I quote from TechDirt:
"In declining to adopt the Seventh Circuit's interpretation of "without authorization," the court held that a "person uses a computer 'without authorization'... [only] [1] when the person has not received permission to use the computer for any purpose (such as when a hacker accesses someone's computer without any permission), or [2] when the employer has rescinded to access the computer and the defendant uses the computer anyway."... The Ninth Circuit declined to hold that the "defendant's authorization to obtain information stored in a company computer is 'exceeded' if the defendant breaches a state law duty of loyalty to an employer" because no such language was found in the CFAA.... The Ninth Circuit noted that because the CFAA was "primarily a criminal statute," and because there was ambiguity as to the meaning of the phrase "without authorization," it would construe any ambiguity against the government.... "
Compared with the UK, I thought of the Brown case where two police officers accessed the database (vehicle registration) for personal purposes, and then the Alison case in similar fashion: originally, the courts found there was no hacking; but the HL in Alison considered that "without authorisation" meant that without authorisation for the purpose involved.
Applied to the UK, the comment would meant that the HL got it wrong? I would disagree

"Courts Stretching Computer Hacking Law In Dangerous Ways" TechDirt, 18 March 2010

Tuesday, 16 March 2010

Climate change and hacking: does the end justify the means?

Over the debate on climate change data flaws, what struck me is that nobody questioned the hack of e-mails as if it was normal for e-mails, held on universities computers, to be accessed without authorisation. Certainly, I understand the importance of getting data right, especially for such a major issue as climate change, but does it justify the means? The hack is investigated by police officers and I wonder what would be the outcome and if the media will be so willing to tell the story.
Because, once the discussion settled, it happens that the flaws were minor and did not change the overall conclusions of the report: climate change is created by man, the rise in temperatures is alarming, and we better get going otherwise our children will not be living on this planet. So why all that fuss and nothing on hacking?

"Strange case of moving weather posts and a scientist under siege", The Guardian, 2 February 2010 (page 6)

Monday, 15 March 2010

Google, China and Co: where do we draw the line between the acceptable and the not-so-acceptable?

A long silence, partly because I was busy scrolling down the shelves at Cambridge (UK) library for books before my fellowship at CRASSH ended. I still have a few books to read, but today I am trying to go through the amassed cuts of newspapers' articles.
So let us review the story about Google rethinking its policy in China. Much ink has been spilled over the issue.
First, Google made its annoucement on 13 January 2010, a date that feels a bit like a new year/new resolution statement. The annoucement was not to censor anymore its search results on Google China, whether or not requested by Chinese authorities. The consequences, i.e. the possible end of any business presence in China, were recognised as a possibility. What seems to have triggered the decision was a series of cyberattacks against Chinese human rights activists. (Guardian, 13 January 2010, front page and page 3).
"Google to end censorship in China over cyber attacks" (Tania Branigan, TheGuardian, 13 January 2010)
"Google counts cost of censorship and draws red line under China" (Bobbie Johnson, TheGuardian, 13 January 2010)

On the details of the attacks, see Guardian 14 January 2010 and 15 January 2010.
"Google acted on censorship amid China dissident fears" (TheGuardian, printed version 14 January 2010, front page)
"Google's move on Chinese censorship welcomed by human rights activists"
(TheGuardian, 14 January 2010, page 14)
"Accounts invaded, computers infected – human rights activists tell of cyber attacks", The Guardian, printed version 15 January 2010

The attacks bring into light how internet communications are central to governmental response to politics, including war. "Cyber-warfare 'is growing threat'" The Guardian, 4 February 2010, page 7; similarly, six months ago, "MyDoom virus hits key networks in US and South Korea" The Guardian, 9 July 2009, page 16 (the title in the printed version is slightly different: "Cyber attacks paralyse government computers in US and South Korea"). But for a different vision on a 'supposed' cyberwar: "White House Cyber Security Guy: There Is No Cyberwar", TechDirt, 9 March 2010


However, the cynics add that Google never made the money it expected to make; it has only one third of the search engines market in China which is dominated by Baidu= Governmental Chinese version of search engine. So its decision may not rest so much on willingness to defend democratic values through guaranteeing freedom of expression, than on profit-making interests.
In addition, Google's decision in 2006 to censor results hurt the company's reputation, so much that one of its founder, Sergey Brin, called it a "net negative" (see Guardian's article, 13 January 2010, page 3; and page 14, 14 January 2010).

Nevertheless, cynicism may not be so much on the agenda. Let us face it: Google is not the new knight defending freedom of expression without awaiting something in return. On the other hand, personal history certainly plays a role here. Sergey Brin emigrated to the US in 1979, aged six, with his parents who were victims of anti-semitism, even under the then-USSR. (Guardian's, Tania Branigan, 14 January 2010, front page).

China's reaction was at the beginning cautious... and heavily censored as few headlines made it on the newspapers/online versions in China itself. Some commentators, pro-governmental line, did not see Google's decision as 1) affecting China much (there are other search engines), 2) as a desinterested decision (aka, Google does not make enough profit to stay).

What seems to emerge on the side, with other companies finding it difficult to enter the Chinese market, is a picture of full protection of Chinese interests (economic or not) against foreign companies and Governments. It fits with a presentation I attended in September 2009 at the Society for Legal Scholars (SLS) in Keele, where the speaker demonstrated that Chinese law favoured chinese contract law in all dispute resolutions, a concept that systematically discards foreign law; in other words, private international law in China is resolved by the quasi-systemic application of local law to the exclusion of foreign law. An article on the International Herald Tribune of 14 January 2010 page 15 is quite revealing on those behaviours. The article even ends up by saying, in more polite form, that foreign companies sell their soul to China, accepting to give for free, for fear of loosing a market share, what they would never have tolerated in other countries. I know the story is not exagerated. In his second volume on Globalisation, which focuses on Water, Eric Orsenna (French Academician and writer) explains that the French company Alstom more or less gave the plans of its water turbines for the three Dams on the yellow river, in exchange for obtaining the market... Except that the turbine plan is now copied and Alstrom not needed...

"China stifles news of Google’s defiance", The International Herald Tribune, 14 January 2010 (p. 1)
"Google Is Not Alone in Discontent, But Its Threat Stands Out", The New York TImes, 14 January 2010 (by the way, this habit of the NYT and IHT not to use the same title in the printed and online version is frankly annoying).
Eric Orsenna, L'avenir de l'eau : Petit précis de mondialisation II (Broché), Fayard 2008 (The future of water: little manual on globalisation II - NB: the first volume was on coton and is as interesting as the second, if anybody can read French - by the way, it is not a complicated French although it is beautifully written).


If we take into account China's policy in conducting business, then it appears very clearly that accepting to censor the results could only amount to failure in terms of believing that the economy will allow for freedom of expression to grow. The economy is in itself a close circuit; nothing from the outside will penetrate it, especially NOT freedom of expression. After 30 years of economic "liberalisation", the West should start looking at the full picture, rather than avoiding the issue: China will not become a democracy by free market. See James Kynge, "Full circle", Financial Times 16/17 January 2010.
"China and the west: Full circle", Financial TImes, 15 January 2010 (printed version, 16/17 january 2010 (like for the Guardian, can't they just give one date???)
Viewed under that light, Bill Gates' comment is not as irresponsible as it may first appear. It is a realist comment: that anyone doing business in China has to accept the fact that democracy is out of question. Then the question is: does one have the guts, to take a familiar expression, not to do business? The West's answer so far is certainly not living to its Enlightenment's ideals.
"Playing the wall game in China" The Guardian, 18 January 2010

Additionally see:
"Google may lose business, but gains good will", Miguel Helft, International Herald Tribune, printed version January 16/17, 2010 (can't find the link online)
"Why fearful china stamps out dissent", Peter Beaumont, The Observer, 17 January 2010, p. 22 (can't find the link online either)
Will Google stand up to France and Italy, too? The Guardian, 14 January 2010

"China Issues Another Warning to Google on Enforced Censorship of the Internet" link to NY Times by Business and HR website, 12 March 2010

Friday, 22 January 2010

Privacy, piracy, copyrights and censorship

The theme of the week seems to turn around protecting privacy.

"Hacking Surpassing Human Error For Data Breaches?" (TechDirt, 19 January 2010). For the author, the answer is actually positive: hacking is a major threat, more that insiders leaking data.

In the fight against piracy, will privacy be waived? "Swedish ISP Refuses To Give Up Info; Says IPRED Violates EU Privacy Rules" (TechDirt, 18 January 2010)

"The Similarity Between ACTA And Chinese Internet Censorship" (TechDirt, 20 January 2010) in that both requires strong involvement from ISPs. I also think that both infringed on privacy. But the issue of ISPs involvement is also close to more traditional searches and seizures: "Once Again, FBI Caught Breaking The Law In Gathering Phone Call Info; But Real Issue Is Why Telcos Let Them" (TechDirt, 19 January 2010)

Obviously, all this debate supposes there is such thing as privacy about data online. Hence the issue about cloud computing and expectations of privacy. "Do You Have Any Legal Right To Privacy For Information Stored Online?" (TechDirt, 19 January 2010) THe US have actually articulated that notion of expectation of privacy, even though the answer is not satisfactory: it is not because it is online that there is no expectation of privacy. It all depends on where and what was intended to be done with the data.

France Considers 'Right To Forget' Law, Apparently Not Realizing The Internet Never Forgets (TechDirt, 8 January 2010)


Tuesday, 8 December 2009

Virtual worlds and theft

Apparently, somebody has been arrested for theft for hacking into accounts, use avatars and steal the virtual possessions. "Real-world arrest for man who stole RuneScape virtual characters" (Times, 30 November 2009)
For disapproval, "If You Gain Unauthorized Access To A Character In A Virtual World, Is It Theft?" (TechDirt, 01 December 2009)
Contra: "Is virtual boom our industrial revolution?" (TheGuardian, 10 September 2009)
http://www.guardian.co.uk/technology/2009/sep/09/victor-keegan-virtual-world-revolution

Friday, 24 July 2009

Twitter hacked

Twitter has been hacked again (previously it was Barack Obama's account). This time it seems that the hacker obtained the passwords from an employee (probably involuntarily given by the employee) allowing him/her to access many internal documents, some confidential. So probably a mixture of lack of security and lack of careful use of computer systems.

"Twitter hacké : 310 documents confidentiels volés" (JDN, 16 July 2009)

Friday, 26 June 2009

Fraud and insider access to confidential data

The security/sofware company Cyber ARk released a report or survey on administrators' behaviours in firms. 35% of them use data they come accross because of their job or research that data in illegal ways. This is quite scary and shows how vulnerable companies can be.

http://www.cyber-ark.com/news-events/pr_20090610.asp

and a French summary of the report on JDN 17 June 2009

Un tiers des administrateurs informatiques tentés par le vol de données

Wednesday, 10 June 2009

Hacking -future of hackers

Just in case some might have some hope. It did not even occur to me that the change of Minister could modify Mr. McKinnon's situation, especially that the hearing before the Supreme Court (ex-House of Lords) is pending

"Lawyer: Home Office unlikely to U-turn on hacker " (ZDNet.co.uk, 8 June 2009)


But there may be some hope in the mid-term future: (ex) "Hacker joins US Homeland Security in advisory role" (ZDnet.co.uk, 8 June 2009)

with the following update: "Mitnick: from 'computer terrorist' to consultant " (ZDnet.co.uk, 23 June 2009)

Wednesday, 25 March 2009

Computer misuses: hacking and the rest

The Web Hacking Incidents Database just published its 2008 report. It is worth a read. Here are a few facts:

- 19% steal information in order to sell it = profit
- 24% deface a website (i.e. change its homepage with a message)
- 5% is phishing


The attacks originate for 66% from North America, 16% from Europe, 6% Asia, which is probably a reflection of internet access and use.


and Government websites & co represent 32% of the victims. Two explanations here: Government got sensitive information (hence theft and fraud) and they represent the law (thus issue of politics or hactivism)

http://www.breach.com/resources/whitepapers/downloads/WP_WebHackingIncidents_2008.pdf
for a partial translation in French see Journal du Net (March 2009)

Sunday, 1 February 2009

Nasa hacker's perception on his trial

In a press conference, Mr. McKinnon explains why he believes he would have a fair trial in the UK: no big press coverage turned against him etc...
"Nasa hacker: I'd get a fairer trial in UK" (ZDnet.co.uk, 28 January 2009 - video)

Sunday, 25 January 2009

UK institutions victims of viruses

Hospitals first, with hopefully only a few appointments cancelled as damage.
"Downadup virus hits PCs at five Sheffield hospitals " (ZDnet.co.uk, 22 January 2009)
More serious in terms of national security, and certainly more worrying, is the MoD's system victim of viruses. "Virus causes Ministry of Defence outages " (ZDnet.co.uk, 16 January 2009)

Tuesday, 6 January 2009

Hacking - twitter and security staff

Self-explanatory:

"Twitter hack targets Obama, Britney" (ZDNet.uk, 6 January 2009)

"Yeah, Your IT Guy Is Probably Reading Your Email" (TechDirt, June 2008)

Hacking e-mail - fraud and prosecution

Interesting facts, pretty scary also because it would not be easy to be so suspicious about the e-mail. "Negros doc warns vs. email hackers" (CCRC, 16 October 2008)

and on the importance of criminalising the simple act of hacking whatever the outcome is... "Is The Indictment Of The Palin Email Hacker Legally Correct?" (TechDirt, 15 October 2008)