Tuesday, 18 May 2010

Critical Legal Studies Conference 2010

With a vested interest as I am chairing stream 9 of the Critical Legal Conference 2010 @ Utrecht in September 2010 : The WWW: great expectations or great disenchantments?

To see all the streams of the Conference on Modernities, click here

Friday, 7 May 2010

enforcing the law: France and US updates

In France, JDN reported on the Institut de la recherche criminelle de la gendarmerie nationale (the Institute on criminal research of the Gendarmerie nationale, the French police force) and its work in the Fort Rosny-sous-bois (the Fortress...). databases, recognition of images, techniques to recover data... - 12 February 2010


More recently, news on the US Cybersecurity Act which first draft was anti-libertarian, "Les Etats-Unis toilettent leur plan de lutte contre la cybercriminalité" JDN, 13 March 2010

Patterns

"Cybercriminals target non-conventional appliances" (ZDnet.co.uk, 09 April 2010). not surprising, and among the devices: mobiles phones, USB flash drives and peripherals.

and DDOS attacks linked with extortion/blackmail notices, "Chinese DDoS attacks hit News Limited" (ZDnet.co.uk, 14 April 2010)

Criminalisation of DRM bypassing - ACTA becoming transparent?

If the process was certainly not transparent, the draft is at last published. Will comments be published and listened to?

"Acta copyright treaty draft gets first public airing" (ZDnet.co.uk, 21 April 2010)

and earlier on, the EU Parliament's rejection of the treaty by 633 to 13! "European Parliament votes down Acta treaty" (ZDnet.co.uk, 11 March 2010)

The gold mine: ID and other data thefts

Between the NHS desktops that were hacked and controlled as part of a botnet, and facebook accounts also hacked, it is obvious that security and privacy are at the heart of cybercrime. Accessing illegally and controlling data/computers is at the heart of a successful criminal entreprise.

"Over 1,000 NHS desktops part of botnet, says Symantec" (ZDnet.co.uk, 23 April 2010)

"iDefense: 1.5 million Facebook accounts for sale" (ZDnet.co.uk, 23 April 2010)

Therefore, one wonders why employers ease restrictions on employees using social networking sites, when usually the security of their own IT systems is average or bad. "Managers ease restrictions on Facebook use" (ZDnet.co.uk, 23 April 2010)

especially when a study by the French CNIL reveals that the most common password used is "123456"!!!!!! JDN, 22 January 2010

Privacy of Wi-fi data: Google Street View

A very interesting story that does not seem to make the big headlines despite its crucial importance in my view.
Google Street View, already criticised for other reasons, all linked to privacy, acknowledged that it takes the Wi-Fi details of people, i.e. their MAC addresses, that will be able to any user using location-based services. In other words, your neighbour or your potential hacker can know all about your Wi-fi, making easier to hack into your computer.
A "bemol" though: if you have configured your Wi-Fi device not to broadcast, the signal and information should not be available. Another reason to do it, if you have not already done so.
"Google explains why Street View cars record Wi-Fi data"

when we know that Google will have 96 pc of the UK roads on it: "Google Street View to cover 96pc of UK roads"

For a general view of privacy issues Google services raise, see the letter addressed to the company ten European authorities in charge of protecting IT users privacy, CNIL, press release 20 April 2010. See also (in French), "Les gardiens de la vie privée exhortent Google à respecter les lois" (Depeches du Juris-Classeur, 23 April 2010)

Security again

Security seems to be the word of the week.
  • The EU commission wants to create an agency to foster better collaboration in cyber-investigations, albeit the UK, Germany and France remain to be convinced. One concerns is also the overlap with ENISA, in addition to the fact that ENISA has not been the success story that it was hoped for when it was launched. "EU to establish cybercrime agency" -Euractiv, 28 April 2010
  • The UK is worried that it does not have enough IT engineers able to implement security and is targeting A-levels pupils and UG to recruit more IT students "UK-wide Cyber Security Challenge kicks off" (ZDnet.co.uk, 29 April 2010)
  • And Beijing is imposing an authorisation on firms developing IT security softwares/solutions, probably less for security reasons than for protectionist motives. JDN, 29 April 2010 (in French)

Security review by Symantec and other issues of web security

Symantec published its report analysing cyber-issues in 2009. Most of the attacks continue to come from the US (19%), followed by China (8%) and a new comer, Brazil (6%). The bulk of the attacks (37%) focuses on acquiring data, then it is accessing structural tools of companies (26%) and piracy (15%). Fraud represents only 2%. It confirms that the new value or currency today is data, rather than money itself as a direct target. In other words, data is worth more than currencies.
The recent story about a Twitter user confirms that data is gold. He was able, after numerous tweets to different users including to a Twitter employee, to find the ID and password of that employee and conduct himself as an Twitter administrator (JDN, 6 May 2010). He has been arrested in France in the Massif Central, after collaboration with the FBI (Obama's account was hacked).

A lot of those attacks are performed by users dowloading PDF documents and believing that their banks would send them e-mails requesting for their information (74% of phishing). It confirms that users are "culprits" as much as the perpetrators. If people were a bit more careful in what they download and read, there would be less succesful attacks. It is certainly the message of Remy Fevrier from the French Gendarmerie Nationale (the French police under the military umbrella) at the FIC or Forum International sur la Cybercriminalite held in Lille from the 31 March to 1st April 2010. He explained that some firms went bankrupt because precious data was stolent by a competitor which was then able to offer the product at a lesser price because it did not have the costs of research and development.

Coming back to the Symantec report, to control other computers, attackers continue to use keystroke softwares, uploading users' details and zombies/botnets I suppose.
Firefox and Safari are the most vulnerable browsers on the web currently. IE and Chrome being stable and quite below (50 instead of around 100).

See the summary in French on JDN "Les menaces IT n'ont pas connu la crise en 2009" (6 May 2010)

Friday, 23 April 2010

Scam

US Convicts Nigerian 419 Email Scammer (TechDirt, 22 April 2010) - speaks for itself.

Google search in court

In the story below, I am troubled by two things:

- the assumption that a diversity of items being available proves that each of them are rarer to come by (here a yellow hat). How a Google search can help assessing this baffles me. Statistics of sale would be more relevant. Education of judges in how to use Google and how Google gathers its information?

- why indeed a judge can 'google' but not juries?

Judges Allowed To Use Google To 'Confirm Intuition' In Cases (TechDirt, 23 March 2010)

Copyrights

Just a few additional links about posts published earlier on:

"Copyright A Priority For The DOJ; But Identity Fraud Has Fallen Off The List" (TechDirt, 8 April 2010)

which contrats with the EU Parliament's perception: Parliament threatens court action on anti-piracy treaty (Euractiv, 10 March 2010)

and the side effects of wanting more inforcement in non-democratic countries: "Careful What You Wish For: Greater IP Enforcement In China Being Used Against Foreign Companies..." (TechDirt, 8 April 2010)

Social networking and risks

Social networks put careers at risk, survey finds (Euractiv, 1 February 2010) with employers looking on the internet profile of applicants! Question of education about impact of the internet in people's lives.

Social networks put minors at risk, EU warns (Euractiv, 10 February 2010), a campaign which echoes ENISA reports about the use of internet/virtual worlds by minors. Again, education

EU to slam new Facebook privacy settings (Euractiv, 09 February 2010) and in French "Les réglages de confidentialité de Facebook dans le collimateur de l'UE" (Euractiv, 09 February 2010)

Hyping issues up: distortions when it comes to internet

1 - "The Real Problem With Internet Comments Isn't Anonymity" (TechDirt, 12 April 2010). That I would agree; people before internet could be anonymous for the better or for the worse (blackmail...). They could also be discovered and were accepting the risk; so why not now? Why the internet should change anything in us allowing anonymity? What we need is better education for people to understand the impact of their behaviours and better policing, but not an end to anonymity.
"Judge Who Was Revealed As Anonymous Commenter Sues Newspaper For $50 Million" (TechDirt, 8 April 2010)
"Israeli Supreme Court Says There Is No Legal Way To Reveal Anonymous Commenters Online" (TechDirt, 1 April 2010)
Columnist Claims Anonymity Is Bad For Our Country (TechDirt, 31 March 2010)


2 - "Dear Journalists: There Is No Cyberwar" (TechDirt, 9 April 2010). I don't completely agree. Governments use and will use the new technologies to attack and the disruptions will be different.

3 - As Cyberbullying Moral Panics Heat Up, Actual Rates Of Cyberbullying Decreasing (TechDirt, 9 April 2010). Well yes and no. Cyberbullying is a problem like its off-line version, but it is probably not so much of a problem as it is made up.

Similar distortion in the understanding of the law in order to catch behaviours we find offensive but which are not necessarily legal:
Son Gets Mom Charged With Harassment Over Facebook Account Hijacking (TechDirt, 8 April 2010) - apparently, the son lets the computer logged in; that is unauthorised access in the UK!
And if this is true, it is even worse: Sarkozy Kicks Off Criminal Investigation Into Blog/Twitter Reports He Had An Affair (TechDirt, 7 April 2010)

4 - or distortion in the use of the law: "Court Says President Bush Violated Wiretapping Laws With Warrantless Wiretap" (TechDirt, 31 March 2010) with Wired having published the decision from NorthDistrict Court of California http://www.wired.com/images_blogs/threatlevel/2010/03/walker.pdf

This affair echoes two others about procedure and the difficulties to conceptualise it:
"Leaving Your WiFi Open Decreases Your Fourth Amendment Rights To Privacy?" (TechDirt, 10 February 2010) - I can't see how there is less privacy if you leave your mobile phone or your landline accessible to people from the outside
"Duh, Don't Leave A Thumb Drive With Child Porn Plugged Into A Shared Computer" (TechDirt, 22 April 2010) - no expectation of privacy for a US court when the thumb drive is plugged in. I would agree (like Masnick and unlike Kerr with whom I seem to disagree quite a lot - he writes on VWs). Kerr argues the thumb drive is like a suitcase in a public space; inaccurate if it is plugged in as everybody can see what's in it, like an open suitcase (aka Masnick).

and see "Les points-clés du projet de loi Loppsi" (LeMonde, 09 February 2010)

Circulation of information and saving of

The Economist On Why Copyright Needs To Return To Its Roots (TechDirt, 20 April 2010). The argument is that the Statute of Queen Anne granted copyrights for only 14 or 21 or 28 years maximum. It was not during the artist/writer's lifetime. Well, I would like to introduce a nuance here: the life expectation of people was probably at the time around 40 years old. If one writes the book in their twenties and one adds 14 years, that is roughly 34 minimum, so prettry much the author's lifetime. What is true though, is that the limited period made it impossible to transfer the copyrights to the descendents/heirs.
for life expectancy: http://www.napoleon-series.org/research/abstract/population/vital/c_heights1.html which cites a book

Related to this is the post on TechDirt. The clip is cleverly made, but I am still not convince completely by it. No one has ever been able to copy what one wants without 1) acknowledging the author..., 2) in some cases (commercial use mostly), ask permission from the author. So yes copying can be theft, but not always. "Copying Is Not Theft" (techDirt, 15 April 2010)
Incidentally, acknowledging an author was not an inherent practice to writers. It started when the library of Alexandria opened and started to collect 'books'. They needed to reference the books and started to enquire about their authors... In parallel, in order to get all the books of the world at the time, the scribs did not hesitate to copy the books without permission and then they would reference them.
See also: "Content Creation Is An Evolutionary Process" (TechDirt, 22 February 2010) and the more recent post: "Innovation By Imitation: Study Shows That Success Comes From Imitation" (TechDirt, 22 April 2010)
and the very interesting comment/analysis of another's post: "Understanding What's Scarce And What's Not..." TechDirt, 09 February 2010

The Library of Congress seems to want to save all Twitter feeds on the grounds that ordinary people participate, giving historians a unique insight into day-to-day moods and understanding of issues. Not bad, but I wonder to which extent: it violates privacy, it is that useful for historians. Library Of Congress To Store Your Inane Twitter Chatter For All Eternity (TechDirt, 16 April 2010)

Google and China

Rob Hanlon and Stephen Frost, CSR Asia, on 31 Mar 2010, criticised Google's HR motives to withdraw from Mainland China. The core of their arguments is nothing new: Google was not making any profit, to stay would have been counterproductive to their business model; to withdraw in the name of HR is not helpful to China's HR activists and it is an illusion to believe a foreign company can influence China's policies on whether to censor or not.

http://www.reports-and-materials.org/Google-Theatre-CSR-Asia-31-Mar-2010.pdf

Well, at the end of the reading, frankly, I am less than convinced by their arguments. I have no doubt that Google withdrew because it was not making enough money, but I do not think it is the only motive. I completely disagree with their stand about people/companies not being able to influence others including foreign governments. This is saying that nobody is responsible for whatever happens and history defies such argument. As we are talking about HR, let us think about Nelson Mandela. He was the catalyst of a whole movement who changed the course of history. Gandhi did the same against the then British Empire which power we forget the might.

Google's answer to the criticism is poorly drafted I think. The HRW's response is much more interesting as it points towards the weakness of Hanlon and Frost's arguments.

http://www.reports-and-materials.org/Google-response-re-CSR-Asia-19-Apr-2010.doc

http://www.reports-and-materials.org/Human-Rights-Watch-reply-re-CSR-Asia-on-Google-20-Apr-2010.doc

All the reports are on the Business and HR website at http://www.business-humanrights.org/Links/Repository/1000252

For the earlier report on Google closing its site: Google Shuts China Site in Dispute Over Censorship (NY Times 22 March 2010) and different comments on the Business and HR website: http://www.business-humanrights.org/Links/Repository/1000132

Tuesday, 6 April 2010

Beware The Seductive Power Of Surveillance

TechDirt - 5 April
Refers to an article by Jesse Hirsh http://jessehirsh.ca/the-seductive-power-of-surveillance

same as previous post: common sense means that surveillance will exist and that we need to assess the risks and stop treating the internet as something different than the telephone, for HR purposes

See the previous interview of Thomas Berners-Lee: "Web under threat from 'snooping' authorities" (TechDirt, 04 December 2010)

Once Again, A Court Overturns Internet Ban For Convicted Criminal

TechDirt, 5 April 2010 -

technology seems to make people lose their common sense. Would we agree to a ban on using the telephone because the offender committed the offence with it?

Are Computers in Africa Really Weapons of Mass Destruction?

I am as skeptic as Kevin Donovan about the correctness of the analysis made in Foreign Policy. Yes, it is true that Africa does not use the latest softwares, but nor does Europe and a lot of other countries. And to use the nicknamed Nigerian scam as an example supporting the argument seems rather week. Nigeria has not been the only country sending that type of scam and if 'Western' people were not so gullible, maybe the wave of those scams would not have reached that scale at the time.

Monday, 5 April 2010

EU divided on ways to defeat online child pornography | EurActiv

EU divided on ways to defeat online child pornography | EurActiv

The EU Commission wants members states to filter content, but Germany is not particularly happy about it and wanted that it will refuse to do so, should there be a directive in that sense. The new EU treaty forbids member states to filter content on justice and home affairs. How will this provision be interpreted?