Between the NHS desktops that were hacked and controlled as part of a botnet, and facebook accounts also hacked, it is obvious that security and privacy are at the heart of cybercrime. Accessing illegally and controlling data/computers is at the heart of a successful criminal entreprise.
"Over 1,000 NHS desktops part of botnet, says Symantec" (ZDnet.co.uk, 23 April 2010)
"iDefense: 1.5 million Facebook accounts for sale" (ZDnet.co.uk, 23 April 2010)
Therefore, one wonders why employers ease restrictions on employees using social networking sites, when usually the security of their own IT systems is average or bad. "Managers ease restrictions on Facebook use" (ZDnet.co.uk, 23 April 2010)
especially when a study by the French CNIL reveals that the most common password used is "123456"!!!!!! JDN, 22 January 2010
Showing posts with label Prevention - Security. Show all posts
Showing posts with label Prevention - Security. Show all posts
Friday, 7 May 2010
Privacy of Wi-fi data: Google Street View
A very interesting story that does not seem to make the big headlines despite its crucial importance in my view.
Google Street View, already criticised for other reasons, all linked to privacy, acknowledged that it takes the Wi-Fi details of people, i.e. their MAC addresses, that will be able to any user using location-based services. In other words, your neighbour or your potential hacker can know all about your Wi-fi, making easier to hack into your computer.
A "bemol" though: if you have configured your Wi-Fi device not to broadcast, the signal and information should not be available. Another reason to do it, if you have not already done so.
"Google explains why Street View cars record Wi-Fi data"
when we know that Google will have 96 pc of the UK roads on it: "Google Street View to cover 96pc of UK roads"
For a general view of privacy issues Google services raise, see the letter addressed to the company ten European authorities in charge of protecting IT users privacy, CNIL, press release 20 April 2010. See also (in French), "Les gardiens de la vie privée exhortent Google à respecter les lois" (Depeches du Juris-Classeur, 23 April 2010)
Google Street View, already criticised for other reasons, all linked to privacy, acknowledged that it takes the Wi-Fi details of people, i.e. their MAC addresses, that will be able to any user using location-based services. In other words, your neighbour or your potential hacker can know all about your Wi-fi, making easier to hack into your computer.
A "bemol" though: if you have configured your Wi-Fi device not to broadcast, the signal and information should not be available. Another reason to do it, if you have not already done so.
"Google explains why Street View cars record Wi-Fi data"
when we know that Google will have 96 pc of the UK roads on it: "Google Street View to cover 96pc of UK roads"
For a general view of privacy issues Google services raise, see the letter addressed to the company ten European authorities in charge of protecting IT users privacy, CNIL, press release 20 April 2010. See also (in French), "Les gardiens de la vie privée exhortent Google à respecter les lois" (Depeches du Juris-Classeur, 23 April 2010)
Security again
Security seems to be the word of the week.
- The EU commission wants to create an agency to foster better collaboration in cyber-investigations, albeit the UK, Germany and France remain to be convinced. One concerns is also the overlap with ENISA, in addition to the fact that ENISA has not been the success story that it was hoped for when it was launched. "EU to establish cybercrime agency" -Euractiv, 28 April 2010
- The UK is worried that it does not have enough IT engineers able to implement security and is targeting A-levels pupils and UG to recruit more IT students "UK-wide Cyber Security Challenge kicks off" (ZDnet.co.uk, 29 April 2010)
- And Beijing is imposing an authorisation on firms developing IT security softwares/solutions, probably less for security reasons than for protectionist motives. JDN, 29 April 2010 (in French)
Security review by Symantec and other issues of web security
Symantec published its report analysing cyber-issues in 2009. Most of the attacks continue to come from the US (19%), followed by China (8%) and a new comer, Brazil (6%). The bulk of the attacks (37%) focuses on acquiring data, then it is accessing structural tools of companies (26%) and piracy (15%). Fraud represents only 2%. It confirms that the new value or currency today is data, rather than money itself as a direct target. In other words, data is worth more than currencies.
The recent story about a Twitter user confirms that data is gold. He was able, after numerous tweets to different users including to a Twitter employee, to find the ID and password of that employee and conduct himself as an Twitter administrator (JDN, 6 May 2010). He has been arrested in France in the Massif Central, after collaboration with the FBI (Obama's account was hacked).
A lot of those attacks are performed by users dowloading PDF documents and believing that their banks would send them e-mails requesting for their information (74% of phishing). It confirms that users are "culprits" as much as the perpetrators. If people were a bit more careful in what they download and read, there would be less succesful attacks. It is certainly the message of Remy Fevrier from the French Gendarmerie Nationale (the French police under the military umbrella) at the FIC or Forum International sur la Cybercriminalite held in Lille from the 31 March to 1st April 2010. He explained that some firms went bankrupt because precious data was stolent by a competitor which was then able to offer the product at a lesser price because it did not have the costs of research and development.
Coming back to the Symantec report, to control other computers, attackers continue to use keystroke softwares, uploading users' details and zombies/botnets I suppose.
Firefox and Safari are the most vulnerable browsers on the web currently. IE and Chrome being stable and quite below (50 instead of around 100).
See the summary in French on JDN "Les menaces IT n'ont pas connu la crise en 2009" (6 May 2010)
The recent story about a Twitter user confirms that data is gold. He was able, after numerous tweets to different users including to a Twitter employee, to find the ID and password of that employee and conduct himself as an Twitter administrator (JDN, 6 May 2010). He has been arrested in France in the Massif Central, after collaboration with the FBI (Obama's account was hacked).
A lot of those attacks are performed by users dowloading PDF documents and believing that their banks would send them e-mails requesting for their information (74% of phishing). It confirms that users are "culprits" as much as the perpetrators. If people were a bit more careful in what they download and read, there would be less succesful attacks. It is certainly the message of Remy Fevrier from the French Gendarmerie Nationale (the French police under the military umbrella) at the FIC or Forum International sur la Cybercriminalite held in Lille from the 31 March to 1st April 2010. He explained that some firms went bankrupt because precious data was stolent by a competitor which was then able to offer the product at a lesser price because it did not have the costs of research and development.
Coming back to the Symantec report, to control other computers, attackers continue to use keystroke softwares, uploading users' details and zombies/botnets I suppose.
Firefox and Safari are the most vulnerable browsers on the web currently. IE and Chrome being stable and quite below (50 instead of around 100).
See the summary in French on JDN "Les menaces IT n'ont pas connu la crise en 2009" (6 May 2010)
Thursday, 18 March 2010
Discipline and surveillance: school's attitude
Pretty silly attitude for a school: education should be about transparency of thinking.
And of course completely illegal, thus scary:
"School Accused Of Spying On Kids In Their Homes With Spyware That Secretly Activated Webcams" TechDirt 18 February 2010
And of course completely illegal, thus scary:
"School Accused Of Spying On Kids In Their Homes With Spyware That Secretly Activated Webcams" TechDirt 18 February 2010
Labels:
Discipline,
Prevention - Security,
Surveillance
Passport control: awaking the dead
"Is Elvis Dead? Who Knows, But His Passport Made It Through Airport Security In Amsterdam", TechDirt 01 March 2010
I like the irony of it all. Trying to secure identities of people, and yet failing badly...
I like the irony of it all. Trying to secure identities of people, and yet failing badly...
Labels:
Anonymity,
Prevention - Security,
Privacy
Tuesday, 16 March 2010
The power of images and data
Three articles, all connected around several themes.
The first one is about Chatroulette's site which works on the basis of logging in for random chats with people all over the world (well, at least that is what they tell you). The principle may seem great but exhibitionists and voyeurs populate the site so much that whoever uses it is sure to encounter some unpleasant images or chat on a regular basis, about one every ten chats. The problem is that students, children, anybody has access to it.
What I found fascinating is the fact that people want to spend time at random with images displayed, often of their own private homes. There is a sense that their privacy is not infringed because the others do not know where they live... But that is on the basis that they reveal nothing of themselves. Yet, even with one image (that can be captured from the webcam), somebody can start tracking down the person since some websites allow to search for matching pictures. Anonymity cannot really exist.
"Online voyeurs flock to the random thrills of Chatroulette", The Observer, 14 February 2010 page 20
On an anedoctal use of Chatroulette, "Band 'Releases' New Album Via Chatroulette" 15 February 2010
and for the French Secretary of State to ask for regulation of Internet at an international level: "Nadine Morano demande à l’ONU de réguler Internet", 01net, 25 February 2010
The second article is about comments made by Mark Zuckerberg, one of the founders of Facebook that "people have gotten really comfortable not only sharing more information and different kinds, but more openly and with more people", and that lack of privacy as a "social norm". The article astutely points out the constrast between the affirmation and the reality of Mr Zuckerberg's behaviour to withdraw pictures from his facebook page! We may feel comfortable with others' lack of privacy, but not with our own. There is here an element of voyeurism, like with gossip: it is fine to gossip about others, but not about ourselves!
Even more interesting is a Sunday Times poll explained in the article, where 63% disagree with the statement that privacy matters less than before and 70% say they are worried about communication of private data.
There is an obvious need to redefine privacy in the internet age, I would add, in the Facebook age. What does it mean in legal terms?
There is also a question of education and responsiblity here. All those examples of people having posted images of others (without their knowledge) in embarrassing situations with unintended consequences of loss of jobs, refusal of qualification etc... There is a need to learn about our responsiblity towards others, like when on the road, and seeing a bad driver - one cannot pretend not seeing him/her and continue driving, one has to adapt-; but there is also a need to learn not to take images at face value, that seeing somebody being drunk once does not mean s/he is unfit for a job. Relativity... a new relationship to images and words on the net...
"Facebook’s Mark Zuckerberg says privacy is dead. So why does he want to keeps this picture hidden?" The Sunday Times, 17 January 2010 page 12
For an earlier version of the same problem on Facebook, "Public lives: Does the internet know too much about us?", The Independent, 30 June 2008
The third article is about the EU being worried about Google and the YouTube case in Italy. Europe Looms as Major Battleground for Google, The NY Times, 14 February 2010 (the printed version is titled: In Europe, Unease with Google's Power Grows - bad English by the way)
On the issue of privacy and speech, see Global Network Initiative
The first one is about Chatroulette's site which works on the basis of logging in for random chats with people all over the world (well, at least that is what they tell you). The principle may seem great but exhibitionists and voyeurs populate the site so much that whoever uses it is sure to encounter some unpleasant images or chat on a regular basis, about one every ten chats. The problem is that students, children, anybody has access to it.
What I found fascinating is the fact that people want to spend time at random with images displayed, often of their own private homes. There is a sense that their privacy is not infringed because the others do not know where they live... But that is on the basis that they reveal nothing of themselves. Yet, even with one image (that can be captured from the webcam), somebody can start tracking down the person since some websites allow to search for matching pictures. Anonymity cannot really exist.
"Online voyeurs flock to the random thrills of Chatroulette", The Observer, 14 February 2010 page 20
On an anedoctal use of Chatroulette, "Band 'Releases' New Album Via Chatroulette" 15 February 2010
and for the French Secretary of State to ask for regulation of Internet at an international level: "Nadine Morano demande à l’ONU de réguler Internet", 01net, 25 February 2010
The second article is about comments made by Mark Zuckerberg, one of the founders of Facebook that "people have gotten really comfortable not only sharing more information and different kinds, but more openly and with more people", and that lack of privacy as a "social norm". The article astutely points out the constrast between the affirmation and the reality of Mr Zuckerberg's behaviour to withdraw pictures from his facebook page! We may feel comfortable with others' lack of privacy, but not with our own. There is here an element of voyeurism, like with gossip: it is fine to gossip about others, but not about ourselves!
Even more interesting is a Sunday Times poll explained in the article, where 63% disagree with the statement that privacy matters less than before and 70% say they are worried about communication of private data.
There is an obvious need to redefine privacy in the internet age, I would add, in the Facebook age. What does it mean in legal terms?
There is also a question of education and responsiblity here. All those examples of people having posted images of others (without their knowledge) in embarrassing situations with unintended consequences of loss of jobs, refusal of qualification etc... There is a need to learn about our responsiblity towards others, like when on the road, and seeing a bad driver - one cannot pretend not seeing him/her and continue driving, one has to adapt-; but there is also a need to learn not to take images at face value, that seeing somebody being drunk once does not mean s/he is unfit for a job. Relativity... a new relationship to images and words on the net...
"Facebook’s Mark Zuckerberg says privacy is dead. So why does he want to keeps this picture hidden?" The Sunday Times, 17 January 2010 page 12
For an earlier version of the same problem on Facebook, "Public lives: Does the internet know too much about us?", The Independent, 30 June 2008
The third article is about the EU being worried about Google and the YouTube case in Italy. Europe Looms as Major Battleground for Google, The NY Times, 14 February 2010 (the printed version is titled: In Europe, Unease with Google's Power Grows - bad English by the way)
On the issue of privacy and speech, see Global Network Initiative
Fraud, spam and co
An old article I retrieved today from my pile. The author, Charles Arthur, wonder whether convicting spammers in the US will put an end to spam. A rather pessimist response, understandably. What interested me was the fact that spam can be linked to fraud and criminal organisations with data collected beeing sold back or with botnet spamming created and then offered to eastern European criminal gangs.
So as usual, if people were not so gullable, there will be a bit less fraud and spam.
"Will convicting five major spammers put an end to spam?" The Guardian, 24 June 2010
For other articles on sale of private data and fraud,
"Welcome to DarkMarket – global one-stop shop for cybercrime and banking fraud", The Guardian, 15 January 2010, page 3
"T-Mobile staff sold customers' details to rivals", The independent, 18 November 2009
Further fraud this time with carbon trading, "Fraud Besets E.U. Carbon Trade System", The NY Times, 8 February 2010
and issues of security for smartphones: "Mobile security: Hackers kept at bay by lack of a standard platform" Financial TImes 15 February 2010
So as usual, if people were not so gullable, there will be a bit less fraud and spam.
"Will convicting five major spammers put an end to spam?" The Guardian, 24 June 2010
For other articles on sale of private data and fraud,
"Welcome to DarkMarket – global one-stop shop for cybercrime and banking fraud", The Guardian, 15 January 2010, page 3
"T-Mobile staff sold customers' details to rivals", The independent, 18 November 2009
Further fraud this time with carbon trading, "Fraud Besets E.U. Carbon Trade System", The NY Times, 8 February 2010
and issues of security for smartphones: "Mobile security: Hackers kept at bay by lack of a standard platform" Financial TImes 15 February 2010
Labels:
Offences - Fraud,
Prevention - Security,
Privacy,
Spamming
Friday, 5 February 2010
Surveillance
Apparently, "Obama Quietly Issues Ruling Saying It's Legal For The FBI To Break The Law On Accessing Phone Records" (TechDirt, 22 January 2010)
and I find this even more astonishing: the harm exists, it is to each individual. "Judge Dismisses Lawsuit Over Warrantless Wiretapping, Appeal Planned" (TechDirt, 22 January 2010)
It is as astonishing as Bill Gates stating it's business and if Google does not want to comply to China, too bad! http://www.business-humanrights.org/Documents/MicrosoftreChinacensorship (25 January 2010)
and I find this even more astonishing: the harm exists, it is to each individual. "Judge Dismisses Lawsuit Over Warrantless Wiretapping, Appeal Planned" (TechDirt, 22 January 2010)
It is as astonishing as Bill Gates stating it's business and if Google does not want to comply to China, too bad! http://www.business-humanrights.org/Documents/MicrosoftreChinacensorship (25 January 2010)
Anonymity on the web
A very simple explanation, common sense, but as true as for anonymity by post mail: can't certify identities without using existing means of identification...
"You Can't Get Rid Of Anonymity Online, Even If You Wanted To" (TechDirt, 4 February 2010) refering to the blog of Bruno Schneier http://www.schneier.com/blog/archives/2010/02/anonymity_and_t_3.html
A change compared to the UK court position earlier on a blog written by a police officer:
"Israeli Court Supports Anonymity For Online Commenters" (TechDirt 26 January 2010)
"You Can't Get Rid Of Anonymity Online, Even If You Wanted To" (TechDirt, 4 February 2010) refering to the blog of Bruno Schneier http://www.schneier.com/blog/archives/2010/02/anonymity_and_t_3.html
A change compared to the UK court position earlier on a blog written by a police officer:
"Israeli Court Supports Anonymity For Online Commenters" (TechDirt 26 January 2010)
Labels:
Anonymity,
Prevention - Security,
Privacy
Tuesday, 8 December 2009
Surveillance
"US gov't agencies sued over Facebook surveillance" (ZDnet.co.uk, 02 December 2009) Different watchdogs decided to ask the US federal government for their guidelines in how they use social networks to monitor citizens' behaviours.
A similar policy would not be amiss in the UK given the new UK cybersecurity Centre and the complete inadequacy of the RIPA to protect citizens' privacy from interference by whichever government agencies "Government curbs councils' Ripa powers" (ZDnet.co.uk, 04 November 2009)
"UK cybersecurity centre starting operations in March" (ZDnet.co.uk, 13 November 2009)
and the more general view of Thomas Berners-Lee "Web under threat from 'snooping' authorities" (Euractiv, 04 December 2010)
A similar policy would not be amiss in the UK given the new UK cybersecurity Centre and the complete inadequacy of the RIPA to protect citizens' privacy from interference by whichever government agencies "Government curbs councils' Ripa powers" (ZDnet.co.uk, 04 November 2009)
"UK cybersecurity centre starting operations in March" (ZDnet.co.uk, 13 November 2009)
and the more general view of Thomas Berners-Lee "Web under threat from 'snooping' authorities" (Euractiv, 04 December 2010)
Smartphones and malwares
Not a surprise that smartphones start to be the target of viruses and other malwares. They are powerful computers when one think of their size.
"iPhone worm could be used to create botnets" (ZDnet.co.uk, 23 November 2009)
"Un nouveau virus s'attaque à l'iPhone" (JDN. 24 November 2009)
which in turn, means good jobs for technicians and ex-hackers/malware writers "Rickroll virus author hired by iPhone app company" (ZDnet.co.uk, 27 November 2009)
"iPhone worm could be used to create botnets" (ZDnet.co.uk, 23 November 2009)
"Un nouveau virus s'attaque à l'iPhone" (JDN. 24 November 2009)
which in turn, means good jobs for technicians and ex-hackers/malware writers "Rickroll virus author hired by iPhone app company" (ZDnet.co.uk, 27 November 2009)
Monday, 26 October 2009
Uses of social networking
Research was done to understand where the eye is set on various pages: Facebook, YouTube, Twitter. It is the technology of eye-tracking with the movements of the eyes being captured and giving an image of where the eye goes. The study is in English by OneUpWeb (oneupweb.com) but the comments are here in French by Journal du Net -26 August 2009. In red, is where the internet user stays, in green where s/he barely has a look.
It is quite fascinating in terms of what it reveals: how people use different websites and adapt to them, how adverts could better target consumers...
For a less positive outlook on social networking, a series of reports/news:
- the EU preoccupation with Facebook as a portal to cybercrime. Facebook: A new battleground for cyber-crime (Euractiv, 27 July 2009)
- the security issues Facebook faced and that allowed for data to be 'stolen'. Warning as rogue Facebook apps steal log-in data (ZDNet.co.uk, 20 August 2009)
It is quite fascinating in terms of what it reveals: how people use different websites and adapt to them, how adverts could better target consumers...
For a less positive outlook on social networking, a series of reports/news:
- the EU preoccupation with Facebook as a portal to cybercrime. Facebook: A new battleground for cyber-crime (Euractiv, 27 July 2009)
- the security issues Facebook faced and that allowed for data to be 'stolen'. Warning as rogue Facebook apps steal log-in data (ZDNet.co.uk, 20 August 2009)
Twitter, Facebook and DoS: security and hactivism
Facts of 1st attack: a Georgian account in Twitter, Facebook and Google' blogger, was targeted by multiple attacks. It caused Twitter to shut down, Facebook had problems. And the suspicion is on Russia, obviously (although it remained to be proved).
Apart from the costs of it all, what is interesting is the fact that the attack against one person/entity triggered problems for everybody else using the services of Twitter, Facebook and Google. The collateral effects are damning.
Facts of 2nd attacks:
Apart from the costs of it all, what is interesting is the fact that the attack against one person/entity triggered problems for everybody else using the services of Twitter, Facebook and Google. The collateral effects are damning.
Blogger targeted in Twitter, Facebook DoS (ZDnet.co.uk, 7 August 2009) and Cyberattack That Brought Down Twitter & Facebook Only Highlighted The Guy It Hoped To Silence (TechDirt, 10 August 2009)
French version: Twitter rendu indisponible par une attaque visant un internaute (JDN, 7 August 2009)
Facts of 2nd attacks:
Twitter suffers outage following fresh attack (ZDnet.co.uk, 12 August 2009)
To which extend the botnet was part of the 2 attacks, it remains to be seen: Security firms reveal botnet on Twitter (ZDnet. co.uk, 17 August 2009)Thursday, 23 July 2009
Views on regulation on the net
Axel Pawlik, managing director of the Ripe NCC, writes about regulation on the net. He considers that ISPs should not take an active role in regulation, notably in relation to piracy. THey should be treated like telecom companies which list calls and that's all.
The article is definitely not a cybercrime perspective as such: there is piracy, but I think the issue of piracy is first of all an issue about what we want with copyrights; domain names attribution is looked at and again there is no incidence in criminal law for that.
However there is an interesting parallel with telephone companies when it comes to surveillance. We all know that surveillance of contents on phone conversation requires preliminary investigation: governments are not allowed to wiretap telephone conversations just to find out about illegal contents (or let's put it that way: in democracies, they are not supposed to do random wiretapping without warrant). Why should the net be treated different? Apart from the non feasibility of spying on all contents, it's nothing different and privacy is key.
Politicians should stay out of internet policing (ZDnet.co.uk, 22 July 2009)
which is obviously not what the UK Government does as it poured 10 millions pounds on monitoring.
"Gov't boosts spending on web monitoring" (ZDnet.co.uk, 13 July 2009)
whereas in France, Mr. Alain Bravo for the Assemblee Nationale (Parliament), published his report on security and digital economy to explain six scenarios, from no control apart from big firms' to too much control... http://www.assemblee-nationale.fr/13/rap-info/i1670.asp
The article is definitely not a cybercrime perspective as such: there is piracy, but I think the issue of piracy is first of all an issue about what we want with copyrights; domain names attribution is looked at and again there is no incidence in criminal law for that.
However there is an interesting parallel with telephone companies when it comes to surveillance. We all know that surveillance of contents on phone conversation requires preliminary investigation: governments are not allowed to wiretap telephone conversations just to find out about illegal contents (or let's put it that way: in democracies, they are not supposed to do random wiretapping without warrant). Why should the net be treated different? Apart from the non feasibility of spying on all contents, it's nothing different and privacy is key.
Politicians should stay out of internet policing (ZDnet.co.uk, 22 July 2009)
which is obviously not what the UK Government does as it poured 10 millions pounds on monitoring.
"Gov't boosts spending on web monitoring" (ZDnet.co.uk, 13 July 2009)
whereas in France, Mr. Alain Bravo for the Assemblee Nationale (Parliament), published his report on security and digital economy to explain six scenarios, from no control apart from big firms' to too much control... http://www.assemblee-nationale.fr/13/rap-info/i1670.asp
Friday, 26 June 2009
Security and cloud computing
Academics warn recently about the dangers of cloud computing, where softwares and data are stored in online companies' servers and accessible from the internet. E.g.: mobileme for Apple, Dropbox, etc... It's strange because it is one of the reasons why I have still not used those services, although I have to admit I am tempted sometimes for the sheer ease of accessing data anywhwere as long as I have a connection.
Cloud computing et confidentialité des e-mails (Euractiv, 17 June 2009)
Cloud computing et confidentialité des e-mails (Euractiv, 17 June 2009)
Wednesday, 10 June 2009
Theft/acces to confidential data
BT researchers bought on e-bay 300 hard drives and checked their data content. The results are surprising and scary: 34% of the drives contain data easily identifiable to real persons or companies, some contained high security data such as log in of the French ambassador in Germany or information about US firms making missiles.
I can't believe people are silly enough to sell on e-bay disks that have not been reformated with complete erasure of data, especially in high-risk domains.
"Des disques durs d'occasion très bavards sur eBay" (JDN, 13 May 2009)
And it is no better when data is not even encrypted like the Royal Air Force's data!
Vols de données dans l'armée de l'air britannique (JDN, 28 May 2009)
"Hacked ATMs let criminals steal cash, PINs" (ZDnet.co.uk, 5 June 2009)
I can't believe people are silly enough to sell on e-bay disks that have not been reformated with complete erasure of data, especially in high-risk domains.
"Des disques durs d'occasion très bavards sur eBay" (JDN, 13 May 2009)
And it is no better when data is not even encrypted like the Royal Air Force's data!
Vols de données dans l'armée de l'air britannique (JDN, 28 May 2009)
"Hacked ATMs let criminals steal cash, PINs" (ZDnet.co.uk, 5 June 2009)
Labels:
Encryption,
Offences - Theft,
Prevention - Security,
Privacy
Thursday, 7 May 2009
Concerns of privacy
An interesting story that shows the gap between the world before and with internet. Although he has a point, that what is on the internet is not necessarily private, Justice Scalia did not understand the scale of communication and availability of details on people's life. To be offended by a research done by the US law professor Joel Reidenberg is not to understand that anyone can do so and retrieve facts with ease and within a few minutes.
I did it for myself and, having always been careful, I found what I knew would be there. The only odd thing was that there is another Audrey Guinchard living in Besançon (France) with a Facebook page and confusion of identity could be made
"Supreme Court Justice Scalia Given Lesson In Internet Privacy" (TechDirt, 5 May 2009)
Most people are more aware about privacy issues though and are notably conscious that when they use the net they leave tracks easily retrievable... But also most people (60% according to the poll) do not want to sacrifice privacy to security measures, which is quite reassuring and counteracts the Governments' claim that security measures ought to be implemented at whatever costs.
"Sécurité IT : l'ingérence de l'Etat inquiète les internautes" (JDN, may 2009)
I did it for myself and, having always been careful, I found what I knew would be there. The only odd thing was that there is another Audrey Guinchard living in Besançon (France) with a Facebook page and confusion of identity could be made
"Supreme Court Justice Scalia Given Lesson In Internet Privacy" (TechDirt, 5 May 2009)
Most people are more aware about privacy issues though and are notably conscious that when they use the net they leave tracks easily retrievable... But also most people (60% according to the poll) do not want to sacrifice privacy to security measures, which is quite reassuring and counteracts the Governments' claim that security measures ought to be implemented at whatever costs.
"Sécurité IT : l'ingérence de l'Etat inquiète les internautes" (JDN, may 2009)
Wednesday, 6 May 2009
Cybercrime policy - US, EU, France and the world
All but one in French, but I haven't finished going through my English newsletters, so should be able to complement later on with English language articles:
"International experts launch anti-cybercrime plan" (ZDnet.co.uk, 29 April 2009): not so international as it may appear as it involves primarily the US and the UK, but at least the Cyber Security Knowledge Transfer Network (KTN), a UK government-funded organisation, is supposed to "liaise[...] between agencies around the world, co-ordinated the formulation of the roadmap". A plan by N. Jones from KTN was published that argues that businesses should be more proactive and important partners in security.
"Building in… Information Security, Privacy and Assurance - A high-level roadmap" on KTN website
Viviane Reding is the European commissioner on new technologies; she suggests to create a European post/job of "internet police/policing officer" so as to coordinate European responses to cyberattacks and develop a strategy to increase cybersecurity
"Un Monsieur sécurité pour défendre l'Europe contre les cyber-attaques ?" (JDN, 27 April 2009)
This very much echoes what has already started in the US, with a change of policy under Obama new presidency, where Melissa Hathaway has already highlighted the new trends in cybersecurity the US will focus on, with notably a multi agencies and institutions cooperation "La cybercriminalité dans le collimateur de l'administration Obama" (JDN, 24 March 2009)
And for France, this interesting article decrypting the French President's promises during the election campaign and their outcomes in 2009. "Sécurité et libertés : les données personnelles en danger ?" (JDN, 5 May 2009). On security, what has been delivered so far is a Report (Livre blanc/White Book) on Defence and Security in June 2008 which highlighted the policies up to 2020 notably in terms of warfare.
In terms of right to privacy, the biometic passport has been launched despite the CNIL (a quango) opposition to it; the obligation for ISPs to block paedophilia websites, and the three strikes law on copyrights infringement. Generally, the CNIL tends to be sidelined as none of its advices has been followed by the Government.
"International experts launch anti-cybercrime plan" (ZDnet.co.uk, 29 April 2009): not so international as it may appear as it involves primarily the US and the UK, but at least the Cyber Security Knowledge Transfer Network (KTN), a UK government-funded organisation, is supposed to "liaise[...] between agencies around the world, co-ordinated the formulation of the roadmap". A plan by N. Jones from KTN was published that argues that businesses should be more proactive and important partners in security.
"Building in… Information Security, Privacy and Assurance - A high-level roadmap" on KTN website
Viviane Reding is the European commissioner on new technologies; she suggests to create a European post/job of "internet police/policing officer" so as to coordinate European responses to cyberattacks and develop a strategy to increase cybersecurity
"Un Monsieur sécurité pour défendre l'Europe contre les cyber-attaques ?" (JDN, 27 April 2009)
This very much echoes what has already started in the US, with a change of policy under Obama new presidency, where Melissa Hathaway has already highlighted the new trends in cybersecurity the US will focus on, with notably a multi agencies and institutions cooperation "La cybercriminalité dans le collimateur de l'administration Obama" (JDN, 24 March 2009)
And for France, this interesting article decrypting the French President's promises during the election campaign and their outcomes in 2009. "Sécurité et libertés : les données personnelles en danger ?" (JDN, 5 May 2009). On security, what has been delivered so far is a Report (Livre blanc/White Book) on Defence and Security in June 2008 which highlighted the policies up to 2020 notably in terms of warfare.
In terms of right to privacy, the biometic passport has been launched despite the CNIL (a quango) opposition to it; the obligation for ISPs to block paedophilia websites, and the three strikes law on copyrights infringement. Generally, the CNIL tends to be sidelined as none of its advices has been followed by the Government.
Saturday, 28 March 2009
Fight against cybercrime - Costs of
Financial crisis helping, some warn that firms may not invest as much as they should in cyber-security, with the negative consequences this could have. See the interview of Régis Fohrer, French Lieutenant Colonel (Home office): "La crise a un impact négatif sur la lutte contre la cybercriminalité"(JDN, 30 March 2009).
Maybe to palliate this pronostic, the French Home Secretary announced a series of measures to fight cybercrime. Filtering for child porn, and linking the Complaint website of Internet-signalement.gouv.fr to a European website managed by Europol. The last is good news; not sure the first is feasible...
"Michèle Alliot-Marie durcit la lutte contre la cybercriminalité" (JDN 25 March 2009)
Maybe to palliate this pronostic, the French Home Secretary announced a series of measures to fight cybercrime. Filtering for child porn, and linking the Complaint website of Internet-signalement.gouv.fr to a European website managed by Europol. The last is good news; not sure the first is feasible...
"Michèle Alliot-Marie durcit la lutte contre la cybercriminalité" (JDN 25 March 2009)
Subscribe to:
Posts (Atom)