Here is the Statewatch newsletter of 22 January 2008 (01/08)Home page: http://www.statewatch.org - Enlightening if applied to cybercrime... Note also the old partnership bewteen UK and USA
"6. UK-USA: 1948 UKUSA agreement and ECHELON states behind "Server inthe Sky" project: Press coverage reporting that the FBI is seeking toset up a global alliance to target suspected terrorists and criminalshas not so far noted the historical origins of "Server in the Sky"project to collect and exchange personal biometrics and data. Thegroup behind the initiative is the "International InformationConsortium" comprised of the USA, UK, Australia, Canada and NewZealand. The same five states started intelligence gathering in theCold War era under the 1948 UKUSA agreement which set up a globalmonitoring system led by the NSA (USA) and Government CommunicationsHQ in the UK (GCHQ).And the very same five states set up the ECHELON surveillance systemin the 1980s which extended communications gathering on a huge scalefrom military objectives to political and economic targets bytrawling the ether for keywords, phrases and groups.Tony Bunyan, Statewatch editor, comments:"The USA and the UK have been running global surveillance systemssince the start of the Cold War through the NSA and GCHQ and theirscope was extended by the ECHELON system in the 1980s. For nearly 60years, since 1948, these hidden systems have been beyond democraticcontrol and now we see this alliance extending its tentacles to covernot just suspected terrorists but criminals as well. Its activitiesare likely to be as unaccountable as ever, by-passing standards ofprivacy and data protection."
Background
- European Parliament: Echelon report:http://www.statewatch.org/news/2001/sep/echelon.pdf
- Appraisal of technologies of political control (for the EP STOA Committee):http://www.statewatch.org/news/2005/may/steve-wright-stoa-rep.pdf
- European Union and the FBI launch global surveillance system: AStatewatch report, 10 February 1997:http://www.statewatch.org/NEWS4A.HTM
- News report: FBI wants instant access to British identity data -Americans seek international database to carry iris, palm and fingerprints (Guardian, link):http://www.guardian.co.uk/print/0%2C%2C332065468-103690%2C00.html
Tuesday, 29 January 2008
Spamming: money, money, money..
Like hacking and the like, spamming is very profitable an activity, especially when linked with stock trading. According to this article, £1.5m in one summer, more than the salary in one's life time for most of us; and guess where they are coming from, sadly? Russia, HK and Canada, highlighting a constant feature of cybercrime, i.e. it is global crime.
The article does not hint on how the investigation has been done, but i'll be curious to know if the stock exchanges internal police were involved...
"US indicts pump-and-dump 'spam king' " (4 January 2008)
http://news.zdnet.co.uk/security/0,1000000189,39291884,00.htm
The article does not hint on how the investigation has been done, but i'll be curious to know if the stock exchanges internal police were involved...
"US indicts pump-and-dump 'spam king' " (4 January 2008)
http://news.zdnet.co.uk/security/0,1000000189,39291884,00.htm
Hacking, extorsion, espionage...: money and political motives
Nothing new; most hacks aim at money.
Extorsion (or blackmail) is very profitable. see Tom Espiner, "Schneier: Cyber-extersion on the increase" ZDNet (23 january 2008) http://news.zdnet.co.uk/security/0,1000000189,39292357,00.htm
as well as corporate espionage, ZDNet (7 january 2008) http://resources.zdnet.co.uk/articles/0,1000001991,39291900,00.htm
and ZDNet (28 January 2008) where Greek Police arrested a hacker selling the corporate secrets of Dassault (French military company) http://news.zdnet.co.uk/security/0,1000000189,39292445,00.htm
and in general, about profits made by selling hack services and other tools: "Cracking open the cybercrime economy" (14 December 2007)
http://resources.zdnet.co.uk/articles/features/0,1000002000,39291463,00.htm
And when it is not hacking, it is modifying data, for revenge... An employee in the US was found guilty of computer damage and got 30 months imprisonment, a particularly harsh sentence comparing to customary sanctions applied (9 January 2008) http://news.zdnet.co.uk/security/0,1000000189,39292027,00.htm
And from time to time, political motives are not forgotten: "Hackers crash Panama's National Assembly website" (22 January 2008) http://news.zdnet.co.uk/security/0,1000000189,39292320,00.htm
Extorsion (or blackmail) is very profitable. see Tom Espiner, "Schneier: Cyber-extersion on the increase" ZDNet (23 january 2008) http://news.zdnet.co.uk/security/0,1000000189,39292357,00.htm
as well as corporate espionage, ZDNet (7 january 2008) http://resources.zdnet.co.uk/articles/0,1000001991,39291900,00.htm
and ZDNet (28 January 2008) where Greek Police arrested a hacker selling the corporate secrets of Dassault (French military company) http://news.zdnet.co.uk/security/0,1000000189,39292445,00.htm
and in general, about profits made by selling hack services and other tools: "Cracking open the cybercrime economy" (14 December 2007)
http://resources.zdnet.co.uk/articles/features/0,1000002000,39291463,00.htm
And when it is not hacking, it is modifying data, for revenge... An employee in the US was found guilty of computer damage and got 30 months imprisonment, a particularly harsh sentence comparing to customary sanctions applied (9 January 2008) http://news.zdnet.co.uk/security/0,1000000189,39292027,00.htm
And from time to time, political motives are not forgotten: "Hackers crash Panama's National Assembly website" (22 January 2008) http://news.zdnet.co.uk/security/0,1000000189,39292320,00.htm
Hacking: anatomy of an attack
Several comments sprung to mind when I read the article:
1) the liability of the hacker, what if he was employed by security firm?
2) why goverment as a target? government is not the only institution to have information. Tesco has probably more about us that government.
3) the IT team seems doing its work; how efficient is technology to counterattack technology?
4) the key role IT team plays in safeguarding evidence which for criminal investigation purposes can only be crucial...
Sally Whittle, "Anatomy of an attack", ZDNet (7 January 2008)
http://resources.zdnet.co.uk/articles/0,1000001991,39291953,00.htm
1) the liability of the hacker, what if he was employed by security firm?
2) why goverment as a target? government is not the only institution to have information. Tesco has probably more about us that government.
3) the IT team seems doing its work; how efficient is technology to counterattack technology?
4) the key role IT team plays in safeguarding evidence which for criminal investigation purposes can only be crucial...
Sally Whittle, "Anatomy of an attack", ZDNet (7 January 2008)
http://resources.zdnet.co.uk/articles/0,1000001991,39291953,00.htm
Thursday, 3 January 2008
Preventing crime: internet, a help to police forces
Often, internet is viewed as a threat by police forces because of its elusive character and the challenges it creates in relation to criminal procedure. But sometimes new technologies can be for the better: see the FBI thinking of using it to list all crimes having recently occured, a bit like the TV series Crimewatch... with the same dangers? " Crowdsourcing Law Enforcement" (28 December 2007) http://www.techdirt.com/articles/20071228/145343.shtml
and for a similar theme, but with a real case of a Japanese criminal wanted for 25 years who indicated on his blog his travel to US territory and obviously got! (29 February 2008)http://www.techdirt.com/articles/20080229/080250385.shtml
and for a similar theme, but with a real case of a Japanese criminal wanted for 25 years who indicated on his blog his travel to US territory and obviously got! (29 February 2008)http://www.techdirt.com/articles/20080229/080250385.shtml
Criminal procedure: intercepting and posting
Intercepting communications is not new (remember the old days where post mail was opened and retained...) and the requirement to do it openly or at least within a framework where effective control exists has never been well accepted by investigatory forces. So it should not come as a surprise that the FBI does not particularly appreciate to follow court orders "FBI Apparently Believes That Court Orders Are For Suckers" (21 December 2007)http://www.techdirt.com/articles/20071221/141358.shtml
A bit more problematic, but among similar lines because of conflicting interests, the possibility nowadays for anybody to post videos about other people including when they behave badly. Should it be allowed? or should we be a bit more responsible? TechDirt made a stark comment about students not being allowed to post bad behaviour of their teachers; but is it their job to do so? Are there not other means to deal with problematic behaviour? My concern moreover is the effect on potentially disciplinary proceedings to be started on the teacher on the basis of the video without any regulation about it. And what if the video is a fake? At least, regulations for videos in criminal procedure are there to ensure the media's reliability... "Student Films Principal Fighting Another Student... School Board Bans Mobile Phones" (21 December 2007) http://www.techdirt.com/articles/20071218/224449.shtml
A bit more problematic, but among similar lines because of conflicting interests, the possibility nowadays for anybody to post videos about other people including when they behave badly. Should it be allowed? or should we be a bit more responsible? TechDirt made a stark comment about students not being allowed to post bad behaviour of their teachers; but is it their job to do so? Are there not other means to deal with problematic behaviour? My concern moreover is the effect on potentially disciplinary proceedings to be started on the teacher on the basis of the video without any regulation about it. And what if the video is a fake? At least, regulations for videos in criminal procedure are there to ensure the media's reliability... "Student Films Principal Fighting Another Student... School Board Bans Mobile Phones" (21 December 2007) http://www.techdirt.com/articles/20071218/224449.shtml
Cybercrime, copyrights: what is free information?
Identity theft presupposes that the information is confidential because it is private or because of its commercial value or its intellectual value. But what about data that informs readers of the news of the world?
Newspapers struggle between two avenues: asking for payment to view contents (news of the day or/and archives), making the data available for free and finding new means to cover costs, notably to pay journalist.
Two articles shed light on the debate and can possibly help understanding when there is theft of information.
The first article, at TechDirt, gives a historical perspective to the debate by reminding us that news were usually given for free and adverts cover the most costs. "Why Journalists Demanding Newspapers Charge For News Need To Check Up On Newspaper History" 2 January 2008 http://www.techdirt.com/articles/20071231/002429.shtml
The second article, also at TechDirt, looks at a specific issue, the struggle to hire sport journalists, and put it in perspective. Maybe the difficulties newspapers have do no relate to the internet, but the evolution of society as a whole, internet being part of this evolution, but only a part of it. " The Journalism Business Is Dying? Someone Forgot To Tell Sports Reporters..." 26 December 2007 http://www.techdirt.com/articles/20071226/020326.shtml
I can't stop myself making a link with something apparently different but ultimately very close to the issue. Apparently a MIT professor was so unhappy somebody used 2 lines of his work he sued them, the money went to charities. All is well apparently because he did not get the money; but what is the value and purpose of suing for one person having used 2 lines of work? Can he not content himself with a reference to his name? I personally would not dream to ask people to pay to use my work, as long as my name is visible somewhere, and there is no commercial exploitation of my work (i.e. the idea is the fundamental basis of a new machine or service). "Professor Uses Copyright Threats After Joke Commercial Uses Some Of His Lecture" 26 December 2007 http://www.techdirt.com/articles/20071226/014929.shtml
Newspapers struggle between two avenues: asking for payment to view contents (news of the day or/and archives), making the data available for free and finding new means to cover costs, notably to pay journalist.
Two articles shed light on the debate and can possibly help understanding when there is theft of information.
The first article, at TechDirt, gives a historical perspective to the debate by reminding us that news were usually given for free and adverts cover the most costs. "Why Journalists Demanding Newspapers Charge For News Need To Check Up On Newspaper History" 2 January 2008 http://www.techdirt.com/articles/20071231/002429.shtml
The second article, also at TechDirt, looks at a specific issue, the struggle to hire sport journalists, and put it in perspective. Maybe the difficulties newspapers have do no relate to the internet, but the evolution of society as a whole, internet being part of this evolution, but only a part of it. " The Journalism Business Is Dying? Someone Forgot To Tell Sports Reporters..." 26 December 2007 http://www.techdirt.com/articles/20071226/020326.shtml
I can't stop myself making a link with something apparently different but ultimately very close to the issue. Apparently a MIT professor was so unhappy somebody used 2 lines of his work he sued them, the money went to charities. All is well apparently because he did not get the money; but what is the value and purpose of suing for one person having used 2 lines of work? Can he not content himself with a reference to his name? I personally would not dream to ask people to pay to use my work, as long as my name is visible somewhere, and there is no commercial exploitation of my work (i.e. the idea is the fundamental basis of a new machine or service). "Professor Uses Copyright Threats After Joke Commercial Uses Some Of His Lecture" 26 December 2007 http://www.techdirt.com/articles/20071226/014929.shtml
Friday, 21 December 2007
Social networking: parallels with ISPs' liability
Facebook apparently deletes what is reported as fake accounts. Apart from the doubtful justification to do so (does it harm anybody? what about this fake cat and bird account nobody could be a fool about?), the method employed does not promote fairness and accountability.
Anybody can denounce the site as fake and to take denounciations at face value is really dangerous. The article at TechDirt rightly points out the absurdity of the policy. But for me, it echoes the behaviours of ISPs when receiving postings about controversial websites: is taking down a website the only solution, especially without notice?
"What Happens If Facebook Thinks You're Not Real?" 20 December 2007
http://www.techdirt.com/articles/20071220/160220.shtml
Anybody can denounce the site as fake and to take denounciations at face value is really dangerous. The article at TechDirt rightly points out the absurdity of the policy. But for me, it echoes the behaviours of ISPs when receiving postings about controversial websites: is taking down a website the only solution, especially without notice?
"What Happens If Facebook Thinks You're Not Real?" 20 December 2007
http://www.techdirt.com/articles/20071220/160220.shtml
Labels:
Providers' liability,
Social networking
Thursday, 20 December 2007
Crime the old fashioned way: where hacking looses all interest!
According to ZDNet: "Criminals posing as policemen conned their way into a data centre near London's King's Cross station, tying up staff and stealing computing equipment, the Metropolitan Police said on Friday." 10 December 2007
http://news.zdnet.co.uk/security/0,1000000189,39291411,00.htm
http://news.zdnet.co.uk/security/0,1000000189,39291411,00.htm
ISPs liabitiliy: the take-down notice procedure
A suit arising from claimed take-down notices sent to e-bay http://www.techdirt.com/articles/20071209/205715.shtml (13 December 2007) probably US based but interesting nonetheless...
Cyberterrorism
The usual debate about cyberterrorism's theat: a hype or a truthfully worrying fact? ZDNet (10 December 2007)http://resources.zdnet.co.uk/articles/features/0,1000002000,39291413,00.htm
Hacking and other tools: which is most efficient?
See TechDirt's article: any legal consequence? http://www.techdirt.com/articles/20071217/014457.shtml (17th December 2007)
Trojan and new victims: ISPs
Usually trojans victimise the lot of us, private users who are not careful about what we download or where we go; but this time, ironically, the victim is Google itself who is loosing money, exactly what it should not!
Google 'powerless' to stop AdSense theft (20 December 2007) http://news.zdnet.co.uk/security/0,1000000189,39291643,00.htm
Google 'powerless' to stop AdSense theft (20 December 2007) http://news.zdnet.co.uk/security/0,1000000189,39291643,00.htm
Unintended DDOS!
How efforts to fight corruption in China ended it up with the equivalent of a DDOS attack, although quite unvoluntarily (well, let's hope)
'Too many hits' crash Chinese anti-corruption website (19 December 2007)
http://news.zdnet.co.uk/internet/0,1000000097,39291622,00.htm
'Too many hits' crash Chinese anti-corruption website (19 December 2007)
http://news.zdnet.co.uk/internet/0,1000000097,39291622,00.htm
Friday, 7 December 2007
Enforcement:
probable cause or plausible reasons to ask for warrant.
In the US, but could obviously interest the UK, a practice about mobile phone data, easily transferable to cybercrime given that the mobile phone technology is now computerised to the extreme some would say http://www.techdirt.com/articles/20071126/101924.shtml (26 November 2007)
the last comment on the article could be related to the notion of private/public divide that is being eroded with the internet, and needs a rethink http://www.techdirt.com/articles/20071203/095531.shtml (3rd December 2007)
investigators as preventive hackers
see the SOCA work about Microsoft OS to reveal its frailty...http://news.zdnet.co.uk/security/0,1000000189,39290736,00.htm (13 November 2007)
And an interesting question: "Can A Computer Store Tech Look At Your Files?" without warrant, (17th December 2007) http://www.techdirt.com/articles/20071214/182720.shtml
In the US, but could obviously interest the UK, a practice about mobile phone data, easily transferable to cybercrime given that the mobile phone technology is now computerised to the extreme some would say http://www.techdirt.com/articles/20071126/101924.shtml (26 November 2007)
the last comment on the article could be related to the notion of private/public divide that is being eroded with the internet, and needs a rethink http://www.techdirt.com/articles/20071203/095531.shtml (3rd December 2007)
investigators as preventive hackers
see the SOCA work about Microsoft OS to reveal its frailty...http://news.zdnet.co.uk/security/0,1000000189,39290736,00.htm (13 November 2007)
And an interesting question: "Can A Computer Store Tech Look At Your Files?" without warrant, (17th December 2007) http://www.techdirt.com/articles/20071214/182720.shtml
Thursday, 6 December 2007
Spyware
Earlier on, I wrote a post about the downsides of spywares use for identity theft purposes
but here is a "positive" sides although regulation issues may make it scary : spyware and investigation forces http://www.techdirt.com/articles/20071126/174251.shtml (27th november 2007)
but here is a "positive" sides although regulation issues may make it scary : spyware and investigation forces http://www.techdirt.com/articles/20071126/174251.shtml (27th november 2007)
Cybersquatting
Something not often looked at in cybercrime courses, but worth having a thought: cybersquatting...
see "Dell suing cybersquatters" (29 November 2007) http://www.techdirt.com/articles/20071129/015252.shtml
and the opposite approach http://news.zdnet.co.uk/internet/0,1000000097,39291329,00.htm?r=2 (6 December 2007)
see "Dell suing cybersquatters" (29 November 2007) http://www.techdirt.com/articles/20071129/015252.shtml
and the opposite approach http://news.zdnet.co.uk/internet/0,1000000097,39291329,00.htm?r=2 (6 December 2007)
I find this article interesting for several reasons:
- first the notion of public and private: yes, the internet blurred the distinction; Facebook is an excellent example where private matters become public without people realising the implications in legal terms
- second, the role of ISPs as contents providers rather than providing a telecommunication service
all that has indirect consequences for cybercrime http://www.techdirt.com/articles/20071203/095531.shtml (3rd December 2007)
and http://www.techdirt.com/articles/20071130/005506.shtml (30th November 2007)
versus ISPs just facilitators: " Citizen Journalism Site Sued Over Content Posted By User" http://www.techdirt.com/articles/20071127/224002.shtml (29 November 2007)
- first the notion of public and private: yes, the internet blurred the distinction; Facebook is an excellent example where private matters become public without people realising the implications in legal terms
- second, the role of ISPs as contents providers rather than providing a telecommunication service
all that has indirect consequences for cybercrime http://www.techdirt.com/articles/20071203/095531.shtml (3rd December 2007)
and http://www.techdirt.com/articles/20071130/005506.shtml (30th November 2007)
versus ISPs just facilitators: " Citizen Journalism Site Sued Over Content Posted By User" http://www.techdirt.com/articles/20071127/224002.shtml (29 November 2007)
Virtual worlds, social networkin, and crime: is it crime?
In virtual worlds like Second Life, can there be fraud or theft with associated real criminal liability? A real question for a virtual world which should be excluded from our physical laws, but is it that simple? Are we going to see criminal law reinvented online?
http://www.techdirt.com/articles/20071202/174819.shtml (3rd December 2007)
The following article seems to confirm we may have to think ahead "Bad Ideas: Trying To Build A Marketplace Of Virtual Goods" TechDirt (18 December 2007) http://www.techdirt.com/articles/20071217/120715.shtml
Another issue will arise with the development of e-currencies: "Virtual worlds driving move to e-payments" http://news.zdnet.co.uk/emergingtech/0,1000000183,39291065,00.htm (26 November 2007)
Bearing more connexion to reality, what about damaging statements in social networking websites that in the physical world do not constitute crime? Should criminal law be involved or should it be regulated by other means? http://www.techdirt.com/articles/20071203/180607.shtml (3rd December 2007)
http://www.techdirt.com/articles/20071202/174819.shtml (3rd December 2007)
The following article seems to confirm we may have to think ahead "Bad Ideas: Trying To Build A Marketplace Of Virtual Goods" TechDirt (18 December 2007) http://www.techdirt.com/articles/20071217/120715.shtml
Another issue will arise with the development of e-currencies: "Virtual worlds driving move to e-payments" http://news.zdnet.co.uk/emergingtech/0,1000000183,39291065,00.htm (26 November 2007)
Bearing more connexion to reality, what about damaging statements in social networking websites that in the physical world do not constitute crime? Should criminal law be involved or should it be regulated by other means? http://www.techdirt.com/articles/20071203/180607.shtml (3rd December 2007)
Friday, 23 November 2007
Cybercrime is not limited to PC
An obvious statement but often forgotten: as computers invade our daily life (Fridges, washing machines, photocopiers...), we should be a bit more careful.. See the iPhone, only one week old at the time of this post.
"Exploit turns iPhone into a spy tool" http://news.zdnet.co.uk/security/0,1000000189,39290994,00.htm
or for hacking obviously: http://news.zdnet.co.uk/security/0,1000000189,39291479,00.htm (13 December 2007)
and obviously on wireless in general (19 novembre 2007) http://resources.zdnet.co.uk/articles/comment/0,1000002985,39290910,00.htm
"Exploit turns iPhone into a spy tool" http://news.zdnet.co.uk/security/0,1000000189,39290994,00.htm
or for hacking obviously: http://news.zdnet.co.uk/security/0,1000000189,39291479,00.htm (13 December 2007)
and obviously on wireless in general (19 novembre 2007) http://resources.zdnet.co.uk/articles/comment/0,1000002985,39290910,00.htm
Subscribe to:
Posts (Atom)