Saturday, 19 July 2008
Web2& Social networking: helping police?
But a more direct move from a social networking site is not funny at all: people have been banned because of their age (over 36) for fear of porn and sex abuse. Apart from the ridicule of the situation (how on earth all over 36 can be suspected?), it is a pretty dangerous move: it's called private justice for fear of prosecution. "Social Networking Site Bans Anyone Over Age 36 To (Sorta) Deal With Sex Offender Law" http://www.techdirt.com/articles/20080522/2356201207.shtml (23 May 2008)
Hate crime and terrorism
Tuesday, 15 July 2008
Fraud: new trend or beyond credit card data
although the old way remains profitable "Stark warning as UK faces cybercrime boom" http://news.zdnet.co.uk/security/0,1000000189,39431415,00.htm?r=1 (9 june 2008)
Investigation and security
Cybercrime and the EU
A study is expected: http://www.crime-research.org/news/02.05.2008/3344/ (2 May 2008)
and the Commission recently took a Framework Decision about cyber attacks in order to clarify legal issues to facilitate responses to crime http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=COM:2008:0448:FIN:EN:PDF (14 July 2008)
Sunday, 13 July 2008
Cyber-Investigations and human rights
- practical objection: is it realistic to consider being able to control the internet? It's like wanting to monitor the mail correspondance of users throughout the world. Can we imagine the FBI or Europol controlling data held by post offices? Inachievable and therefore a pretence. I don't see how the physical world of letters could be much different from the cyberworld.
- second practical objection: how on earth can you succesfully detect crime when faced with a mass of information? the old fashioned way of doing detective work (on the web understandibly) is a much more efficient than trying to cast a net so vast it would take centuries to find the problematic fish.
- theoritical objection: again, parallels with the so-called physical world enlighten thoughts. Data "held" by post offices are private even when their contents are terrorist or criminal; why should data on the web not considered as private and thus submitted to the same regulations as for obtaining private correspondance? Where are the human rights?
And yet the FBI seriously considers asking the ISPs retention of data http://www.techdirt.com/articles/20080423/184451932.shtml (23rd April 2008)
as well as Russia's authorities who would even go further by blocking traffic like China does http://www.techdirt.com/articles/20080423/185834933.shtml (24th April 2008)
Similar problem with the 9th U.S. Circuit Court of Appeals (so federal law) agreed to let searches of laptop with no specific purposes that looking in the hard drive. Why should we set up conditions for the search of a house, but not the search of a computer when nowadays the computer is like a portable home with sometimes all the documents one needs? Where are the human rights of the accused here? Gone with the wind of fear of crime...
"Is This The Best Homeland Security Can Do In Defending Laptop Searches At The Border?" (TechDirt, 10 July 2008)
http://www.techdirt.com/articles/20080422/235343924.shtml (23rd April 2008) with an update for the Electronic Frontier Foundation asks for Congress to intervene http://www.eff.org/press/archives/2008/05/01 (1 May 2008)
Social networking, privacy and investigations
I wonder how effective it is and if privacy, which is the biggest problem on social networking, can be maintained. I would be curious to see the results of any study made on this matter.
http://www.techdirt.com/articles/20080418/164250892.shtml (21st April 2008)
As an illustration of privacy issues, see this acknowledgment by Facebook that spammers' attacks increased, notably because the users' contact details such as e-mail adresses are available even if the users have not opted for such "transparency". "Facebook admits to increased attacks by spammers" http://news.zdnet.co.uk/security/0,1000000189,39397448,00.htm (22 April 2008)
And this is without counting on the fact that users often do not realise Facebook is about publicity not keeping details private. See this story about a US military who published photographs of his base!! http://www.techdirt.com/articles/20080423/183304931.shtml (23rd April 2008) or those Oxford students the University disciplined after scrolling Facebook postings http://www.techdirt.com/articles/20080504/2148451026.shtml (6 May 2008)
So it's not surprising that the University of Wales launches academic studies of the social networking phenomenon in relation to cyber security http://www.crime-research.org/news/09.05.2008/3355/ (9 May 2008)
Yet the reaction from N-Y to punish those incriminating themselves on YouTube (I agree, it's not social networking in the proper sense- but its audience makes it similar to social networking) is quite surprising . How can such crime deter people to put videos of illegal activities? What is the purpose of such potential legislation? "New York Wants To Punish Criminals For Incriminating Selves On YouTube" (13 May 2008)http://www.techdirt.com/articles/20080512/1802591092.shtml
Monday, 23 June 2008
Botnets - DDOS
Cyberterrorism - Definition
http://www.crime-research.org/news/17.04.2008/3316/ (16 April 2008)
compare with the FBI assertion that the internet is used by terrorists groups to communicate, which seems to suggest that it is rarely used to attack institutions: http://www.crime-research.org/news/16.04.2008/3312/ (16 April 2008)
Related to terrorism is the question of national security. The US, or at least some US MPs, seem to have a broad vision of security and include governmental websites. Timothee Lee, from Techdirt, disagrees on the basis that those websites are not linked with the military's protocols on the net. Well, I would argue that it depends of what those websites are supposed to do. If they are the main portal to a wide range of services less and less available in the "physical" world, they may be considered as primary and integrated part of the life of a nation. The building of a city hall or city council where Government offers a range of services could be classified as national security; why not the websites? Maybe the question is linked with what we mean by national security: military or beyond?
Keeping Defense.gov Up Isn't A National Security Issue http://www.techdirt.com/articles/20080518/1934151159.shtml (21 May 2008)
Tuesday, 15 April 2008
Tangible/intangible? digital goods' nature at stake
"California Lawmaker Wants To Change Law To Tax iTunes; Pretending Infinite Goods Are Tangible" (9 April 2008) http://www.techdirt.com/articles/20080408/152311789.shtml
Fraud and crime - statistics
"UK nears US in cyber-crime, ahead of Nigeria, Romania" (10 April 2008)
http://www.crime-research.org/news/10.04.2008/3303/
"UK a hotbed of cybercriminal activity" (9 April 2008)
http://news.zdnet.co.uk/security/0,1000000189,39382596,00.htm
Will that make the Government think a bit more about establishing a specific task force? or at least give money to tackle more efficiently the problem? Or at least the police? See this article about what seems to be the US:
"Cyber crime: Police not taking it seriously" (8 April 2008)
http://www.crime-research.org/news/08.04.2008/3299/
For more statistics: "Cybercrime Losses Decline for Third Consecutive Year " (31 March 2008) http://www.crime-research.org/news/31.03.2008/3282/
Cyberattacks - prevention by Governments
"International cyberattack drill tests nations' responses " (10 April 2008) http://news.zdnet.co.uk/security/0,1000000189,39383325,00.htm
The second is about the response to an attack, i.e. an early-warning system, a bit like for tsunamis in the pacific?
"US plans cyberattack early-warning system" (video- 10 April 2008) http://news.zdnet.co.uk/security/0,1000000189,39383335,00.htm
With the European COmmission (EU) urging Europe to strengthen its cyber defences "Commission eyes common cyber defences " (9 April 2008) http://www.euractiv.com/en/infosociety/commission-eyes-common-cyber-defences/article-171476
and finally NATO! "NATO agrees common approach to cyber defence" (4 April 2008) http://www.euractiv.com/en/infosociety/nato-agrees-common-approach-cyber-defence/article-171377
"Nato creates cyber-defence command" (9 April 2008)http://news.zdnet.co.uk/security/0,1000000189,39382597,00.htm, with the irony of creating a centre in Estonia! http://www.crime-research.org/news/16.05.2008/3368/ (16 May 2008)
ISPs' criminal liability - YouTube and MySpace
The only liability could be if YouTube did not remove the video once informed of it...
"Video of teen beating raises questions" (11 April 2008)
http://news.yahoo.com/s/ap/20080411/ap_on_hi_te/teen_beating_ethics;_ylt=Aq3pQbSMs7fYFJrAKoBqUvch2.cA
Monday, 14 April 2008
Sentencing/ preventive measures
http://www.upi.com/NewsTrack/Top_News/2008/04/09/fraud_suspect_banned_from_computers/1256/
http://www.techdirt.com/articles/20080410/010534808.shtml (11 April 2008)
and the NY Times http://www.nytimes.com/2008/04/10/nyregion/10indict.html (10 April 2008)
ISPs as enforcers of the law
http://www.spamsuite.com.nyud.net/index.php?q=node/387
the PDF version (and full decision) is available on http://www.circleid.com/pdf/come360-counterclaim.pdf
From "Court Tells Spammer That It's Not Illegal For An ISP To Filter Its Emails" (11 April 2008) http://www.techdirt.com/articles/20080411/150256827.shtml
Friday, 4 April 2008
Sexual assault and ISPs' liability
"Mother And Daughter Still Blame MySpace For Not Protecting Her From Sexual Assault" (1 April 2008) http://www.techdirt.com/articles/20080331/172442708.shtml
Since then it has been dropped "MySpace Still Not Liable For Sexual Assault Between Two MySpace Users" http://www.techdirt.com/articles/20080517/1524041148.shtml (19 May 2008)
Censorship and China (once more)
This one is interesting: the Olympic Committee has asked China to lift its Firewall. Put aside (momentarily) the cynism of the request, I love what the request stands for: the fact that China could well acknowledge it has a firewall, which it never did up to now (even denied it if I remember well).
Going to the request itself, well, two interpretations which actually can be found in the comments attached to the post on TechDirt: the request does not engage much more the Committee nor China, for what matters is.... making money. Better to lift the veil temporarily to get the maximum profits both for the West ... and for China! Or else the Committee would have a change of heart? well in that case, why not ask for lifting of censorship indefinitely, not simply while the games are there? Plus, is the COmmittee really serious about human rights when it has allowed games in a country not only reknown for its continuous violations of basic human rights but also for its constant refusal to improve (see Tibet as the latest example...) and make the slightest concession
"IOC: No Chinese Internet Filters During Olympics; All Other Times It's Fine" (1 April 2008)http://www.techdirt.com/articles/20080401/105659717.shtml
Similar issue with iTunes http://www.techdirt.com/articles/20080825/2219562089.shtml (26 August2008)
ID fraud under the flashlights
The documentary should undoubtedly raise awareness about ID fraud online and how to protect oneself efficiently
http://www.bbc.co.uk/bbcone/listings/programme.shtml?day=today&service_id=4223&filename=20080403/20080403_2100_4223_10817_60
http://www.sophos.com/security/blog/2008/04/1255.html
One thing that always buggers me is the fact that details of the civil registry and electoral rolls are freely available (date of birth...). At a time when ID fraud is thriving and difficult to detect before it is too late, I can't understand why these personal information databases remain accessible to anyone.
Lastly, it is astonishing to realise that some do not see the threat caused by ID fraud and do not want to criminalise the use of stolen personal information! "ICO urges gov't to retain data-theft laws" (2 April 2008) http://news.zdnet.co.uk/security/0,1000000189,39378353,00.htm
Danger of terrorism...
"US reveals plans to hit back at cyber threats " (2 April 2008) http://news.zdnet.co.uk/security/0,1000000189,39378374,00.htm
"Army Sets Up Phishing Scam To See How Gullible Service Members Are" (3 April 2008) http://www.techdirt.com/articles/20080402/194347734.shtml
and businesses also take the threat seriously "Accenture and Sun aim to widen security scope" (2 April 2008) http://news.zdnet.co.uk/security/0,1000000189,39378365,00.htm
ISPs, prosecution and human rights
"Yahoo CEO: Business overseas fraught with 'grey areas' " (4 April 2008)
http://news.zdnet.co.uk/internet/0,1000000097,39379891,00.htm