A US district court has ordered the largest "spam gang" in the world to pay nearly $15.2 million (£9.4 million) for sending unsolicited email messages marketing male-enhancement pills, prescription drugs and weight-loss supplements, the US Federal Trade Commission said Monday.
Spamhaus, the antispam organisation, called the email marketing network the "No. 1 worst spam gang" on the Internet for much of 2007 and 2008.
Australian resident Lance Atkinson, the spam ring's leader, has paid more than $80,000 to New Zealand authorities after confirming his involvement in the spam network, and accomplice Jody Smith, a US resident, has agreed to an order that he turn over nearly all his assets to the FTC, the agency said.
In October 2008, a judge in the US District Court for the Northern District of Illinois, Eastern Division, ordered an asset freeze and a halt to the network's operation, which generated more than 3 million complaints to law enforcement authorities, the FTC said.
Earlier this month, the court issued a default judgment against Atkinson, his company, and three companies affiliated with Smith. In addition to the $15.2 million that Atkinson and his company have been ordered to pay, the three companies affiliated with Smith are liable for nearly $3.8 million.
Atkinson and Smith recruited spammers from around the world, according to the FTC’s complaint, filed last year. Those spammers sent billions of e-mail messages directing consumers to websites operated by an affiliate program called Affking, according to the complaint. The spammers used false header information to hide the origin of the messages and failed to provide an opt-out link or list a physical postal address, violations of the US CAN-SPAM Act, the FTC said.
The spam network, using the Canadian Healthcare brand name and other labels, marketed a male-enhancement pill, prescription drugs and a weight-loss pill, the FTC said. The e-mail messages falsely claimed that the medications came from a US-licensed pharmacy that dispenses US Federal Food and Drug Administration-approved generic drugs.
The defendants did not operate a pharmacy licensed in the US, the FTC said. The drugs they sold were shipped from India and had not been approved by the FDA, the agency.
The FTC alleged that Atkinson and Smith made false claims about the security of consumers’ credit card information and other personal data consumers provided when they bought goods. The defendants’ Web site assured potential consumers that the pharmacy "treats your personal information (including credit card data) with the highest level of security.”
The website went on to describe its encryption process, which supposedly involved “Secure Socket Layer (SSL) technology.” However, there was no indication that consumers’ information was encrypted using SSL technology.
To settle FTC charges that he helped send spam e-mails to millions of consumers, Smith will turn over nearly all his assets. Under the terms of the settlement, Smith will pay approximately $212,000. He also will assign any rights he has to $91,000 frozen in the name of one of his co-defendants, and $547,000 that may be held for his benefit in an Israeli bank.
Smith pled guilty in August to the criminal charge of conspiracy to traffic counterfeit goods, and faces up to five years in prison. He is scheduled to be sentenced in December in US District Court for the Eastern District of Missouri.
By Grant Gross
http://news.techworld.com
Showing posts with label news. Show all posts
Showing posts with label news. Show all posts
Wednesday, 2 December 2009
Tuesday, 30 June 2009
China not backing off despite filter code post on Wikileaks
China still plans to implement the controversial Internet access control software "Green Dam Youth Escort" as of July 1 on every new PC sold in the country. This is despite warnings from security researchers and concerns from the US Embassy, not just over the restriction of information, but the security implications of what appears to be such vulnerable software.
hina is filtering out criticism and diving in headfirst with its plan to roll out controversial filtering software on all PCs sold in China. The Chinese media quoted an unnamed source inside the Ministry of Industry and Information Technology, saying that the software will still come with all computers as of July 1 despite the discovery of massive security holes and vulnerabilities by security researchers.
News came out about China's plan to implement Internet access control software, called the "Green Dam Youth Escort" earlier this month. The Windows-only software provides a mix of features, including whitelists, blacklists, and on-the-fly content-based filtering. The blacklists can be updated remotely, however, making Green Dam quite an attractive option for a government that likes to keep tight control over what kind of content its citizens are exposed to.
Unfortunately for everyone buying a computer in China after July 1, researchers at the University of Michigan soon discovered that Green Dam was plagued with serious security vulnerabilities. Not only can malicious websites easily take advantage of the security bugs to run arbitrary code on the user's computer, much of the blacklist content was stolen verbatim from commercial filtering programs sold in the US. Just yesterday, code to exploit the Green Dam software was published publicly on Wikileaks, thereby giving the entire world the ability to mess around with the software once it hits Chinese computers in just over a week.
None of this has stopped the Chinese government, though, who apparently told People's Daily that it will still mandate that Green Dam either come preinstalled or on a CD with every new computer. This, of course, continues to ruffle the feathers of US officials who not only condemn the filtering of Internet access on a government level but also share concerns about the software's security holes.
"We are concerned about Green Dam both in terms of its potential impact on trade and the serious technical issues raised by use of the software," the US Embassy said in a press briefing on Monday. "We believe there are other commercially available software programs which provide users with a wide range of choices for shielding minors from illicit or inappropriate internet contact—content, which is the ostensible rationale for this. We’ve also asked the Chinese to engage in a dialogue on how to address these concerns."
By Jacqui Cheng
Thursday, 11 June 2009
Data Protection Makes Identifying Online Pirates a Nightmare
Norway’s data protection department has indicated that ISPs must delete all personal IP address-related data just 3 weeks after collection. The instruction, initially given to two ISPs but applicable to them all, means that it will be incredibly difficult to take action against file-sharers.
Previously it hasn’t been particularly easy for copyright holders to go after alleged infringers in Norway, but just recently the country’s telecoms regulator said that file-sharers’ identities can be given to copyright holders, providing a court agrees there is a good reason to hand them over. This means that these individuals can be pursued through the courts, or through “pay up or else” type threats.
However, the authority in charge of data protection in Norway has just made that process much, much harder for the copyright holders, since it has instructed two ISPs - Tele2 and Lyse Tele - to delete all IP address-related personal information they hold on their customers which is more than 3 weeks old.
According to Aftenposten the decision, borne of the Personal Data Act which prohibits the storage of unnecessary data, will apply to all ISPs in Norway such as Canal Digital, NextGenTel, Telenor and others.
The fact that data can only be held for just 21 days will see the immediate deletion of IP information held on around 1.6 million subscribers by these Norwegian ISPs. However, the decision flies in the face of European Union rules which say that this type of data must be held for at least 6 months - right now in Norway, data retention can be anything from a few days to five months.
The process of monitoring file-sharers, gathering evidence and then collating it all into an acceptable format can be time consuming. Add this to the time taken to get into the system to obtain a court order from a judge to force the ISPs to hand over data on their customers, and you end up with a period longer than 21 days. By which time the data has gone and the evidence becomes useless, since it’s impossible to identity the alleged infringer.
Written by enigmax Torrent freak
Previously it hasn’t been particularly easy for copyright holders to go after alleged infringers in Norway, but just recently the country’s telecoms regulator said that file-sharers’ identities can be given to copyright holders, providing a court agrees there is a good reason to hand them over. This means that these individuals can be pursued through the courts, or through “pay up or else” type threats.
However, the authority in charge of data protection in Norway has just made that process much, much harder for the copyright holders, since it has instructed two ISPs - Tele2 and Lyse Tele - to delete all IP address-related personal information they hold on their customers which is more than 3 weeks old.
According to Aftenposten the decision, borne of the Personal Data Act which prohibits the storage of unnecessary data, will apply to all ISPs in Norway such as Canal Digital, NextGenTel, Telenor and others.
The fact that data can only be held for just 21 days will see the immediate deletion of IP information held on around 1.6 million subscribers by these Norwegian ISPs. However, the decision flies in the face of European Union rules which say that this type of data must be held for at least 6 months - right now in Norway, data retention can be anything from a few days to five months.
The process of monitoring file-sharers, gathering evidence and then collating it all into an acceptable format can be time consuming. Add this to the time taken to get into the system to obtain a court order from a judge to force the ISPs to hand over data on their customers, and you end up with a period longer than 21 days. By which time the data has gone and the evidence becomes useless, since it’s impossible to identity the alleged infringer.
Written by enigmax Torrent freak
Friday, 15 May 2009
Graham: CIA Gave Me False Information About Interrogation Briefings
n testimony that could bolster Speaker Nancy Pelosi's claim that the CIA misled her during briefings on detainee interrogations, former Senator Bob Graham insisted on Thursday that he too was kept in the dark about the use of waterboarding, and called the agency's records on these briefings "suspect."
In an interview with the Huffington Post, the former Senate Intelligence Committee Chairman said that approximately a month ago, the CIA provided him with false information about how many times and when he was briefed on enhanced interrogations.
"When this issue started to resurface I called the appropriate people in the agency and said I would like to know the dates from your records that briefings were held," Graham recalled. "And they contacted me and gave me four dates -- two in April '02 and two in September '02. Now, one of the things I do, and for which I have taken some flack, is keep a spiral notebook of what I do throughout the day. And so I went through my records and through a combination of my daily schedule, which I keep, and my notebooks, I confirmed and the CIA agreed that my notes were accurate; that three of those four dates there had been no briefing. There was only one day that I had been briefed, which was September the 27th of 2002."
As for the one briefing he did attend, the Florida Democrat said that he had "no recollection that issues such as waterboarding were discussed." He was not, per the sensitive nature of the matters discussed, allowed to take notes at the time. But he did highlight what he considered to be pretty strong proof that the controversial technique was not discussed.
"What struck me...was the fact that in that briefing, there were also two staff members," he said. "As you know, the general rule is that the executive is to brief the full committees of the House and Senate Intelligence committees about any ongoing or proposed action. The exception to that is what is called "covert action," where the president...only briefs the Gang of Eight, which is the four congressional leaders and the four intelligence committee leaders. Those sessions are generally conducted at an executive site, primarily at the White House itself. And they are conducted with just the authorized personnel, not with any staff or any other member of the committee.... Which leads me to conclude that this was not considered by the CIA to be a Gang of Eight briefing. Otherwise they would not have had staff in the room. And that leads me to then believe that they didn't brief us on any of the sensitive programs such as the waterboarding or other forms of excessive interrogation."
The remarks made by Graham bolster the comments offered by Pelosi on Thursday. The Speaker told reporters that during her briefing session in the fall of 2002 she was not just kept in the dark about the issue of waterboarding, she was assured that it had not been used.
"Yes, I am saying that the CIA was misleading the Congress," she said.
However, records and testimony do show that high-ranking aides were present during a February 2003 briefing when waterboarding was discussed by the CIA with Reps. Porter Goss and Jane Harman.
Graham declined to speculate as to what took place during Pelosi's briefings, noting that the House and Senate had two entirely different sessions. But he did point out that, at the time, "the whole credibility of the intelligence committee, particularly the CIA, was pretty much in question" -- giving credence to Pelosi's claims that she was given faulty information.
"The irony," said Graham, "is that the whole series of events in late September of '02 were concurrent with the CIA's release of the first classified version of the National Intelligence Estimate, which was one of the key factors that led me to vote against the war in Iraq because I thought that their case was so weak. And they were making to the public these very bold statements about how we were in extreme danger if we didn't move quickly to eradicate Saddam Hussein. The whole, 'a smoking gun may appear in the form of a mushroom cloud' kind of argument."
Friday, 8 May 2009
Q&A: FBI agent looks back on time posing as a cybercriminal
In September 2008 police began arresting alleged members of Dark Market, an underground Internet forum for buying and selling credit card data used for identity fraud. The sting wouldn't have been possible without the work of FBI agent J. Keith Mularski who spent two years infiltrating the group.
FBI Special Agent J. Keith Mularski spent two years posing as a cybercriminal as part of an undercover sting operation.
(Credit: U.S. Federal Bureau of Investigation)
Mularski became hacker "Master Splynter," a play on the name of the Teenage Mutant Ninja Turtle character called "Master Splinter," a rat who lives in New York City's sewers. He was so successful in his online disguise that he ended up running the server that hosted the Dark Market forum from his offices at the National Cyber Forensics Training Alliance in Pittsburgh.
Mularski, a supervisory special agent with the FBI's Cyber Initiative & Resource Fusion Unit, spoke about the Dark Market sting during a session at the RSA security conference last month. CNET News caught up with him this week on the telephone to find out what it was like hanging out with cybercriminals.
Q: You were central to the Dark Market sting. Tell me what happened and what role you played.
Mularski: We kicked off an undercover operation to try to penetrate these underground crime groups that are running these forums on the Internet. We developed the persona of a spammer/hacker and I assumed that role. Our intention was to try to penetrate the groups and dismantle them like we would with organized crime. In this case we were very successful in getting to the upper echelons of the Dark Market group and we were actually able to run the server and host all the communications that were going on there to make our cases against the criminals. Worldwide we had 60 arrests. It was a two-year operation and we had arrests in the U.K., Germany, Turkey, and here in the U.S.
What measures did you take to try to prove you were legitimate?
I acquired the reputation of one of the world's top 5 spammers. The Spamhaus Project, which tracks spammers, made a listing for me as being a top spammer and that gave me credibility so that I didn't necessarily have to do any criminal activity. I could talk the talk. If someone wanted me to mail (send spam) for them I would (get out of it by giving them the excuse) that they were too small of a fish. If they were a big fish I'd just say I didn't have any openings or time to work with them.
What sorts of crimes were they doing on Dark Market?
They were doing all sorts of identity theft. They were hacking into companies and stealing credit card numbers and selling them. They were selling counterfeit drivers' licenses and other photo documentation, as well as manufacturing fake credit cards. They were selling harvested bank accounts and brokerage accounts and selling different types of malware or spyware programs or Trojan horses that you could infect peoples' computers with. The whole gamut of the cyber underground was available there. If you needed it you could get it there on the site.
How did being undercover interfere with your life? What extremes did you have to go to to keep up the facade?
I would have to be online all the time, basically, in case someone needed to get ahold of me. If I was at home I would always have a computer on, even while watching TV. If I went on vacation I took the computer with me to make sure I was able to log in. I would tell the (Dark Market) guys I was traveling to go surfing or something like that and I would tell them I'll be online at these times if you need to get me. I had a cell phone connected to a Gmail account and I would tell them if they had to get ahold of me to send an e-mail and it would ping me. It was like that for two solid years almost every day. My wife wasn't too happy about it (chuckling).
It was like a soap opera. There was constant drama going on. A lot of people were accusing one another of being cops.
No doubt! Was there ever a moment when you thought the jig was up and that they were on to you?
There were a couple of those. We had a problem with our backstopping right at the beginning of the operation when I took over the server. One of our rivals had hacked into the Dark Market server and was looking at who was logging in. He traced the IP address doing a "who is" (lookup) and the phone number connected to our covert IP address, which was supposed to be unlisted but instead it showed the address here at the National Cyber Forensics Training Alliance. By doing some research they determined that the IP address came from this building and they thought it came from me. I had to go on the offensive and say that it wasn't me and that it was already in the server. Eventually they believed me. There were a lot of wars between rival groups at the time. A lot of people were accusing each other of being "feds" and "cops" and I was able to use that to my advantage to create a smoke screen and create doubt.
How were you able to become administrator of the Dark Market server?
I had good relations with the administrator whose alias was "Jilsi." He wasn't a very technical guy and was having problems running the site because it was getting attacked by a rival group. So I told him about my background as a spammer and told him how good I was at setting up sites. I did some demonstrations and set up some test sites to show him I had the skills. Then there was just a lot of talk and rapport building. One night when Dark Market was getting attacked by a rival group I said I was ready and that I could secure the server for him and he said "let's move." That gave me full access to everyone using it and what they were doing.
Any anecdotes to tell about your dealings with these people?
It was like a soap opera. There was constant drama going on. A lot of people were accusing one another of being cops. It was funny being part of the discussion as people were talking about whether so and so was a cop or a fed and I was sitting there knowing full well that the person wasn't. There were a lot of egos, and a lot of funny stories where guys would brag about their close brushes with the law and how close they got to being arrested. You get 20-year-old guys, 30-year-old guys who are single and making a lot of money, so you hear a lot of stories of partying and things like that.
Did you get a sense of what these carders are like as people; what their characters are like?
There are a lot of guys who I think their curiosity just got the best of them and it led them down a dark path. One of the guys, Max Butler, who ran our rival site called Carders Market and used the hacker name Ice Man, was arrested in San Francisco. He was very intelligent. He could have been an excellent security expert. He could have given talks at RSA about vulnerabilities. A lot of these guys are just misguided. They get into a hotel and see that they have credit cards and one thing leads to another. I think that's how it all starts off and then they find they can make a lot of money and it becomes a business, a job. If you met them in person they were actually nice guys. I enjoyed a lot of my chat sessions when we were talking about other things, like traveling the world and things like that.
How old are they?
The average guy is in his mid-20s or so. We've seen guys in their 40s. Ages range from 17 to 40something, typically. A lot of the guys who we arrested were in their mid-30s.
How tied to organized crime are they?
One of the guys, "ChaO," kidnapped someone. He viewed himself as a traditional organized crime member. He was connected with organized crime groups in Turkey and they resorted to violence when they kidnapped someone who was talking too much about the operations. We're seeing more of that, especially in Romania. Also in Russia.
The attackers have changed with the emergence of organized crime into these cybercrimes...It's all about the money now and not just about how elite my hacking skills are to get into this Web site. Profit is driving these groups.
Did you hear from any of your former carder cohorts after the arrests?
I heard from sources that they couldn't believe I was an FBI agent. One of the guys whose house we raided wasn't at home and he sent me an expletive-filled message saying 'you're never going to catch me.' I told him he should give himself up rather than spend his life on the run and a week later he turned himself in.
This work sounds kind of dangerous. Did you ever feel you were in danger or are you worried now?
When you are an FBI agent there's always that threat of danger working crimes undercover. We never intended for my name to come out in this operation. But FBI agents' names are in affidavits. There was always that risk that my name could be exposed. It's always in the back of your mind but you try not to think about it.
What impact did the sting have?
It showed that we can get you no matter where you live. We were able to make internal relationships and work cases jointly with law enforcement in other countries. In the future there will be other joint cases in Europe and around the world. You don't necessarily have to be in the U.S. for us to bring you to justice. That is one of the most significant impacts it had. Another one is that it showed these guys that, yes, we do have a presence out there (on the Internet) and the U.S. is serious about targeting cybercrime. We are going to throw our resources at this problem.
How have things changed since you started the Dark Market operation in 2006?
With every operation the bad guys learn more of the undercover techniques that law enforcement is using. Everything that was successful for us in this operation would have to be tweaked because of that. The level of sophistication is so much higher. The days of a cyber investigation where you just track an IP address and that leads you to a hacker's house, those days are long gone. There are many different anonymization services the bad guys are using. The exploits and botnets they are using are so much more sophisticated than they were a couple of years ago. Just two years ago the majority of the botnets were IRC botnets, which are fairly simple. Now we're seeing botnets like the Storm worm that are very sophisticated and running peer-to-peer networks and that makes it harder for us to track down the command and control servers.
Have you been involved in any of the efforts to track down the people behind the Conficker worm?
I can't comment on that.
Anything else to add?
The message I'm trying to preach is that we have international cooperation and that other countries are starting to recognize this problem. Also, the attackers have changed with the emergence of organized crime into these cybercrimes. It's not just an 18-year-old pimply faced kid in his room committing these crimes. These are organized crime groups doing it. It's all about the money now and not just about how elite my hacking skills are to get into this Web site. Profit is driving these groups.
The stakes are higher now for everyone?
Definitely.
by Elinor Mills
FBI Special Agent J. Keith Mularski spent two years posing as a cybercriminal as part of an undercover sting operation.
(Credit: U.S. Federal Bureau of Investigation)
Mularski became hacker "Master Splynter," a play on the name of the Teenage Mutant Ninja Turtle character called "Master Splinter," a rat who lives in New York City's sewers. He was so successful in his online disguise that he ended up running the server that hosted the Dark Market forum from his offices at the National Cyber Forensics Training Alliance in Pittsburgh.
Mularski, a supervisory special agent with the FBI's Cyber Initiative & Resource Fusion Unit, spoke about the Dark Market sting during a session at the RSA security conference last month. CNET News caught up with him this week on the telephone to find out what it was like hanging out with cybercriminals.
Q: You were central to the Dark Market sting. Tell me what happened and what role you played.
Mularski: We kicked off an undercover operation to try to penetrate these underground crime groups that are running these forums on the Internet. We developed the persona of a spammer/hacker and I assumed that role. Our intention was to try to penetrate the groups and dismantle them like we would with organized crime. In this case we were very successful in getting to the upper echelons of the Dark Market group and we were actually able to run the server and host all the communications that were going on there to make our cases against the criminals. Worldwide we had 60 arrests. It was a two-year operation and we had arrests in the U.K., Germany, Turkey, and here in the U.S.
What measures did you take to try to prove you were legitimate?
I acquired the reputation of one of the world's top 5 spammers. The Spamhaus Project, which tracks spammers, made a listing for me as being a top spammer and that gave me credibility so that I didn't necessarily have to do any criminal activity. I could talk the talk. If someone wanted me to mail (send spam) for them I would (get out of it by giving them the excuse) that they were too small of a fish. If they were a big fish I'd just say I didn't have any openings or time to work with them.
What sorts of crimes were they doing on Dark Market?
They were doing all sorts of identity theft. They were hacking into companies and stealing credit card numbers and selling them. They were selling counterfeit drivers' licenses and other photo documentation, as well as manufacturing fake credit cards. They were selling harvested bank accounts and brokerage accounts and selling different types of malware or spyware programs or Trojan horses that you could infect peoples' computers with. The whole gamut of the cyber underground was available there. If you needed it you could get it there on the site.
How did being undercover interfere with your life? What extremes did you have to go to to keep up the facade?
I would have to be online all the time, basically, in case someone needed to get ahold of me. If I was at home I would always have a computer on, even while watching TV. If I went on vacation I took the computer with me to make sure I was able to log in. I would tell the (Dark Market) guys I was traveling to go surfing or something like that and I would tell them I'll be online at these times if you need to get me. I had a cell phone connected to a Gmail account and I would tell them if they had to get ahold of me to send an e-mail and it would ping me. It was like that for two solid years almost every day. My wife wasn't too happy about it (chuckling).
It was like a soap opera. There was constant drama going on. A lot of people were accusing one another of being cops.
No doubt! Was there ever a moment when you thought the jig was up and that they were on to you?
There were a couple of those. We had a problem with our backstopping right at the beginning of the operation when I took over the server. One of our rivals had hacked into the Dark Market server and was looking at who was logging in. He traced the IP address doing a "who is" (lookup) and the phone number connected to our covert IP address, which was supposed to be unlisted but instead it showed the address here at the National Cyber Forensics Training Alliance. By doing some research they determined that the IP address came from this building and they thought it came from me. I had to go on the offensive and say that it wasn't me and that it was already in the server. Eventually they believed me. There were a lot of wars between rival groups at the time. A lot of people were accusing each other of being "feds" and "cops" and I was able to use that to my advantage to create a smoke screen and create doubt.
How were you able to become administrator of the Dark Market server?
I had good relations with the administrator whose alias was "Jilsi." He wasn't a very technical guy and was having problems running the site because it was getting attacked by a rival group. So I told him about my background as a spammer and told him how good I was at setting up sites. I did some demonstrations and set up some test sites to show him I had the skills. Then there was just a lot of talk and rapport building. One night when Dark Market was getting attacked by a rival group I said I was ready and that I could secure the server for him and he said "let's move." That gave me full access to everyone using it and what they were doing.
Any anecdotes to tell about your dealings with these people?
It was like a soap opera. There was constant drama going on. A lot of people were accusing one another of being cops. It was funny being part of the discussion as people were talking about whether so and so was a cop or a fed and I was sitting there knowing full well that the person wasn't. There were a lot of egos, and a lot of funny stories where guys would brag about their close brushes with the law and how close they got to being arrested. You get 20-year-old guys, 30-year-old guys who are single and making a lot of money, so you hear a lot of stories of partying and things like that.
Did you get a sense of what these carders are like as people; what their characters are like?
There are a lot of guys who I think their curiosity just got the best of them and it led them down a dark path. One of the guys, Max Butler, who ran our rival site called Carders Market and used the hacker name Ice Man, was arrested in San Francisco. He was very intelligent. He could have been an excellent security expert. He could have given talks at RSA about vulnerabilities. A lot of these guys are just misguided. They get into a hotel and see that they have credit cards and one thing leads to another. I think that's how it all starts off and then they find they can make a lot of money and it becomes a business, a job. If you met them in person they were actually nice guys. I enjoyed a lot of my chat sessions when we were talking about other things, like traveling the world and things like that.
How old are they?
The average guy is in his mid-20s or so. We've seen guys in their 40s. Ages range from 17 to 40something, typically. A lot of the guys who we arrested were in their mid-30s.
How tied to organized crime are they?
One of the guys, "ChaO," kidnapped someone. He viewed himself as a traditional organized crime member. He was connected with organized crime groups in Turkey and they resorted to violence when they kidnapped someone who was talking too much about the operations. We're seeing more of that, especially in Romania. Also in Russia.
The attackers have changed with the emergence of organized crime into these cybercrimes...It's all about the money now and not just about how elite my hacking skills are to get into this Web site. Profit is driving these groups.
Did you hear from any of your former carder cohorts after the arrests?
I heard from sources that they couldn't believe I was an FBI agent. One of the guys whose house we raided wasn't at home and he sent me an expletive-filled message saying 'you're never going to catch me.' I told him he should give himself up rather than spend his life on the run and a week later he turned himself in.
This work sounds kind of dangerous. Did you ever feel you were in danger or are you worried now?
When you are an FBI agent there's always that threat of danger working crimes undercover. We never intended for my name to come out in this operation. But FBI agents' names are in affidavits. There was always that risk that my name could be exposed. It's always in the back of your mind but you try not to think about it.
What impact did the sting have?
It showed that we can get you no matter where you live. We were able to make internal relationships and work cases jointly with law enforcement in other countries. In the future there will be other joint cases in Europe and around the world. You don't necessarily have to be in the U.S. for us to bring you to justice. That is one of the most significant impacts it had. Another one is that it showed these guys that, yes, we do have a presence out there (on the Internet) and the U.S. is serious about targeting cybercrime. We are going to throw our resources at this problem.
How have things changed since you started the Dark Market operation in 2006?
With every operation the bad guys learn more of the undercover techniques that law enforcement is using. Everything that was successful for us in this operation would have to be tweaked because of that. The level of sophistication is so much higher. The days of a cyber investigation where you just track an IP address and that leads you to a hacker's house, those days are long gone. There are many different anonymization services the bad guys are using. The exploits and botnets they are using are so much more sophisticated than they were a couple of years ago. Just two years ago the majority of the botnets were IRC botnets, which are fairly simple. Now we're seeing botnets like the Storm worm that are very sophisticated and running peer-to-peer networks and that makes it harder for us to track down the command and control servers.
Have you been involved in any of the efforts to track down the people behind the Conficker worm?
I can't comment on that.
Anything else to add?
The message I'm trying to preach is that we have international cooperation and that other countries are starting to recognize this problem. Also, the attackers have changed with the emergence of organized crime into these cybercrimes. It's not just an 18-year-old pimply faced kid in his room committing these crimes. These are organized crime groups doing it. It's all about the money now and not just about how elite my hacking skills are to get into this Web site. Profit is driving these groups.
The stakes are higher now for everyone?
Definitely.
by Elinor Mills
Sunday, 3 May 2009
Israeli hacker to be extradited to US
Canadian media report Ehud Tenenbaum, dubbed 'the analyzer', to be transferred to United States on charges of hacking scheme spanning hundreds of companies
sraeli hacker Ehud Tenenbaum will be extradited to the United States despite his previous requests to be tried in Canada, where he was arrested, Canadian media reported over the weekend.
Case History
Canada: Israeli hacker suspected of involvement in major fraud case / Liron Sinai
Ehud Tenenbaum, who 10 years ago hacked Pentagon computers, detained on fraud charges
Full Story
Tenenbaum, who was dubbed "the analyzer" after it was discovered that he was the mastermind behind the hacking of the Pentagon computer systems in the late 1990s, has been in Canadian custody since August 2008, when he and three Canadian accomplices were arrested for hacking into the computers of Canadian company 'Direct Cash' and stealing CDN$1.8 million.
Ehud's mother, Malka, confirmed the extradition to Ynet and explained that it was "by agreement and there's something to the reports."
Shortly after his arrest, Tenenbaum was scheduled to be released on CDN$30,000 bail. The court later denied bail after the prosecution entered into evidence documentation suggesting he is the leading suspect in a US case investigating the hackings of hundreds of companies around the world, including some in the US, Russia, Turkey, Holland, Sweden and Belgium.
Due to the scope of the fraud and the involvement of US companies and the Pentagon, the United States' Federal Bureau of Investigation (FBI) is involved in the investigation against him.
Previously, Tenenbaum and his associates opposed extradition because the charges levied against them in the United States are much more severe than those in Canada. Now, however, Tenenbaum appears prepared to agree to comply with extradition and even decided to forego a preliminary hearing on the matter.
In the past, Tenenbaum's mother told Ynet she objected to the extradition because it involved charges that had taken place over a decade ago. Regarding the recent decision, she said "I don't want to talk so that I don't ruin anything and you'll understand what I mean when the time comes. Any superfluous talk will harm my son."
by Daniel Edelson
Published: 05.03.09, 10:49 / Israel News
sraeli hacker Ehud Tenenbaum will be extradited to the United States despite his previous requests to be tried in Canada, where he was arrested, Canadian media reported over the weekend.
Case History
Canada: Israeli hacker suspected of involvement in major fraud case / Liron Sinai
Ehud Tenenbaum, who 10 years ago hacked Pentagon computers, detained on fraud charges
Full Story
Tenenbaum, who was dubbed "the analyzer" after it was discovered that he was the mastermind behind the hacking of the Pentagon computer systems in the late 1990s, has been in Canadian custody since August 2008, when he and three Canadian accomplices were arrested for hacking into the computers of Canadian company 'Direct Cash' and stealing CDN$1.8 million.
Ehud's mother, Malka, confirmed the extradition to Ynet and explained that it was "by agreement and there's something to the reports."
Shortly after his arrest, Tenenbaum was scheduled to be released on CDN$30,000 bail. The court later denied bail after the prosecution entered into evidence documentation suggesting he is the leading suspect in a US case investigating the hackings of hundreds of companies around the world, including some in the US, Russia, Turkey, Holland, Sweden and Belgium.
Due to the scope of the fraud and the involvement of US companies and the Pentagon, the United States' Federal Bureau of Investigation (FBI) is involved in the investigation against him.
Previously, Tenenbaum and his associates opposed extradition because the charges levied against them in the United States are much more severe than those in Canada. Now, however, Tenenbaum appears prepared to agree to comply with extradition and even decided to forego a preliminary hearing on the matter.
In the past, Tenenbaum's mother told Ynet she objected to the extradition because it involved charges that had taken place over a decade ago. Regarding the recent decision, she said "I don't want to talk so that I don't ruin anything and you'll understand what I mean when the time comes. Any superfluous talk will harm my son."
by Daniel Edelson
Published: 05.03.09, 10:49 / Israel News
Friday, 1 May 2009
New Zealand Officials To Scrap Copyright Law; Start From Scratch
There was a lot of controversy over the past few months concerning an attempt to change copyright law in New Zealand. After tremendous uproar over the fact that the law (a version of three strikes) basically would declare people guilty based on accusations, rather than proof or conviction, the government finally agreed to dump the plan with plans to revisit it. However, it looks like now the government has decided to completely start from scratch, and to recreate copyright law anew. This is quite surprising. Historically, changes in copyright law tend to be patches. Every time a new technology changes things such that copyright law doesn't make sense, regulators duct tape on some "patch" that tries to deal with that new situation. Yet, New Zealand officials seem to be recognizing this, and want to see about rewriting copyright law from scratch:
The Copyright Act was written in the pre-internet age, and does not address any of the complexities surrounding file sharing, format shifting, and other modern issues such as DVD copying -- problems the last government was attempting to fix in a piecemeal fashion.
Of course, the real question is who will rewrite the law and how the process will work. If it's the industry, then you can expect the law to be much worse. But if it's designed with the full spectrum of interests taken into account, New Zealand could represent a useful sandbox for really (finally) rethinking some of the myths and talismans that some copyright maximalists insist are true, but for which no evidence exists. Hopefully, the government will consider ideas from outside the industry, and recognize both the public interest and the intention of copyright law.
The Copyright Act was written in the pre-internet age, and does not address any of the complexities surrounding file sharing, format shifting, and other modern issues such as DVD copying -- problems the last government was attempting to fix in a piecemeal fashion.
Of course, the real question is who will rewrite the law and how the process will work. If it's the industry, then you can expect the law to be much worse. But if it's designed with the full spectrum of interests taken into account, New Zealand could represent a useful sandbox for really (finally) rethinking some of the myths and talismans that some copyright maximalists insist are true, but for which no evidence exists. Hopefully, the government will consider ideas from outside the industry, and recognize both the public interest and the intention of copyright law.
Wednesday, 29 April 2009
Threat Level Privacy, Crime and Security Online Swedish ISP Thwarts Copyright Cops by Erasing Data
The Swedish telecom operator Tele 2 plans to erase all data identifying its 600,000 customers, a decision that will undermine the new IPRED law and make the hunt for internet scofflaws more difficult.
Starting on Tuesday, Tele 2 will destroy records of IP addresses after they’ve been processed for internal use. It’s a way to secure the customers’ privacy — and, the company likely hopes, to strengthen the ISP’s market position.
“This is a strong wish from our customers and therefore we’ve decided to no longer keep records of customers’ IP addresses,” Tele2’s CEO in Sweden, Niclas Palmstierna, told the Swedish news agency TT. “We do this to strengthen the protection of customer privacy.”
“We’ve analyzed the legislation carefully and found that we have no obligations at all to store information about our customers’ IP addresses,” he continued.
The IPRED law went into effect on April 1 in Sweden and allows courts to order ISP’s to hand over details that can identify suspected illegal file sharers. Previously, the only option for copyright holders was to report alleged infringement to the police.
Tele 2 is following the example of Bahnhof and Alltele, smaller Swedish internet operators that declared early on that they would no longer store users’ IP addresses. But the announcement from Tele 2 is of considerably greater significance, since the company is one of Sweden’s main telecom providers and boasts a giant customer base.
With no data to reveal, the new law will be ineffective.
Henrik Pontén of the Swedish Anti-Piracy Bureau is very critical of the operators’ decision.
“This will cause a huge problem for the police in their investigations of severe internet crimes, such as child pornography,” he told Threat Level. “I think it’s a shame that a company puts its profit interest ahead of their customers’ safety. This will open the door to crime.”
A police official told TT that this could have a serious impact, not only on law enforcement’s bid to crack down on internet pirates, but also on other criminal investigations.
“In some cases, this will make an investigation impossible,” said Stefan Kronkvist, the head of Swedish police’s internet crime unit.
The police are now waiting for a new legislation implementing the European Union’s data retention directive, which would force ISPs to store electronic data for a minimum of six months. That law is planned to come into force this fall.
By Kerstin Sjoden
Starting on Tuesday, Tele 2 will destroy records of IP addresses after they’ve been processed for internal use. It’s a way to secure the customers’ privacy — and, the company likely hopes, to strengthen the ISP’s market position.
“This is a strong wish from our customers and therefore we’ve decided to no longer keep records of customers’ IP addresses,” Tele2’s CEO in Sweden, Niclas Palmstierna, told the Swedish news agency TT. “We do this to strengthen the protection of customer privacy.”
“We’ve analyzed the legislation carefully and found that we have no obligations at all to store information about our customers’ IP addresses,” he continued.
The IPRED law went into effect on April 1 in Sweden and allows courts to order ISP’s to hand over details that can identify suspected illegal file sharers. Previously, the only option for copyright holders was to report alleged infringement to the police.
Tele 2 is following the example of Bahnhof and Alltele, smaller Swedish internet operators that declared early on that they would no longer store users’ IP addresses. But the announcement from Tele 2 is of considerably greater significance, since the company is one of Sweden’s main telecom providers and boasts a giant customer base.
With no data to reveal, the new law will be ineffective.
Henrik Pontén of the Swedish Anti-Piracy Bureau is very critical of the operators’ decision.
“This will cause a huge problem for the police in their investigations of severe internet crimes, such as child pornography,” he told Threat Level. “I think it’s a shame that a company puts its profit interest ahead of their customers’ safety. This will open the door to crime.”
A police official told TT that this could have a serious impact, not only on law enforcement’s bid to crack down on internet pirates, but also on other criminal investigations.
“In some cases, this will make an investigation impossible,” said Stefan Kronkvist, the head of Swedish police’s internet crime unit.
The police are now waiting for a new legislation implementing the European Union’s data retention directive, which would force ISPs to store electronic data for a minimum of six months. That law is planned to come into force this fall.
By Kerstin Sjoden
Tuesday, 28 April 2009
The Pirate Bay verdict, dishing the dirt
The Pirate Bay ruling has been translated into English, and it's full of little surprises. Ars dives in to answer the big questions: who possessed those Klomifen tablets, how much did the state pay to defend The Pirate Bay admins, and why did the backers consider moving to Argentina?
Thanks to music trade group IFPI, the recent Pirate Bay ruling has now been "Englished" (PDF). While the verdict itself is well-known, numerous case details will be surprising to non-Swedish speakers—such as who paid for The Pirate Bay defense, which defendant was also arraigned on drug charges, and what happened to all that Pirate Bay computer equipment confiscated by the police?
A masterpiece of prose, the verdict is not. "A number of different filesharing programs and technologies have been developed over the years," says one representative section. "There have been or are two main types of filesharing systems."
But it does offer plenty of fascinating detail that was difficult for those not at the trial to learn. Let's take a look.
Confiscated equipment. All the confiscated servers and routing equipment from a police raid on The Pirate Bay "is declared forfeit," while other seized computers will remain confiscated "until the sentence has become legally binding." That process could take years, given the appeal already filed in the case, so by the time the equipment could be released, it will be obsolete.
Confiscated drugs. In the section devoted to defendant (and lover of wispy beards) Gottfrid Svartholm Warg, we come across this curious section. Not only were computers confiscated, but police picked up "three confiscated tablets of Klomifen," "narcotic drugs," and a "spoon containing traces of amphetamine."
Turns out that Warg wasn't just accused of aiding copyright infringement but also of violating Sweden's Prohibition of Certain Health-Impairing Goods Act. As part of the 2006 police raids on The Pirate Bay, the cops searched an apartment belonging to Warg's parents, where they found several of the listed items in "a drawer unit" and "a cupboard at the desk." Warg said that the apartment had been rented out to others at the time and that he had no knowledge of the drugs there; the court agreed that nothing had been proven against him.
But there was a second incident in June 2007, when a police patrol was called to an apartment and found Warg "heavily intoxicated." In his backpack, other "preparations" were found. Warg told the court "that, despite being intoxicated, he can remember the event. He has also stated that the backpack was his, but that he, at some point during the evening, had lent it to some individuals at the party. He knows 'approximately' who he lent the backpack to, but he does not want to reveal the names of these individuals."
This didn't go over well with the court, which found "beyond reasonable doubt that Gottfrid Svartholm Warg has been in possession of the preparations in question, and that he should, therefore, be sentenced for breach of the Prohibition of Certain Health-Impairing Goods Act."
Who paid for the lawyers? The older (and much richer) defendant Carl Lundström apparently paid for his own lawyer, but the three Pirate Bay admins did not. Their lawyers were all supplied an eventually paid for by the Swedish government, and they weren't cheap. Fredrik Neij's lawyer, for instance, was given 949,025 kronor (about $115,600) for his services; 35,525 kronor of that amount was given for "time wasted."
On moving to Argentina or Russia. As it became clear that Sweden might not be the best long-term base for The Pirate Bay, Carl Lundström explored the possibility of moving the site to Russia or Argentina—and he asked the Swedish Embassy for help. "A request by Carl Lundström to the Swedish Embassy in Argentina for assistance in relocating the operation there, since the situation vis a vis copyright in Argentina could be assumed to be more user-friendly than in Europe, was turned down by the Embassy," says the verdict. "Carl Lundström then contacted an Argentinean lawyer with the aim of ascertaining the cost of establishing the operation as a company in Argentina."
Similar moves were made in Russia; nothing appears to have come of them.
Legal advice. Why the interest in getting out of Sweden? A new copyright law came into effect in 2005, and Lundström worried that it would make the site illegal. "Carl Lundström contacted a lawyer," says the verdict. "Following discussions with his legal representative, he e-mailed Gottfrid Svartholm Warg and mentioned that as of 1 July 2005, the operation would be unlawful and that they should, therefore, consider relocating the operation to another country."
In the meantime, Fredrik Neij sought some legal advice of his own. Rather than pay a lawyer, though, he sought out the advice of a "law student who, in turn, checked with his teachers and professors." Based on advice from the student, Neij told the court that he believed The Pirate Bay was legal.
The Pirate Bay meets... TV? One other curious revelation was that Lundström had the idea back in 2006 "for new services in the form of a pooling of The Pirate Bay’s website and a digital television receiver." Few details are offered, but this sounds a bit like a set-top box that could tune TV and also grab video content from The Pirate Bay. As with many of the other schemes mentioned in the verdict, nothing came of this.
The Google defense. During the trial, the defendants harped on the fact that Google also indexes .torrent files, many of them infringing; why was a search engine like The Pirate Bay on trial while a search engine like Google was not?
Here is the judge's answer in its most condensed form: ""In accordance with what will be further demonstrated below, all the defendants were aware that a large number of the website’s users were engaged in the unlawful disposal of copyright-protected material. By providing a website with advanced search functions and easy uploading and downloading facilities, and by putting individual filesharers in touch with one other through the tracker linked to the site, the operation run via The Pirate Bay has, in the opinion of the District Court, facilitated and, consequently, aided and abetted these offences."
What happened to the "safe harbor"? US law offers immunity (under both the Communications Decency Act and the Digital Millennium Copyright Act) to certain websites and ISPs for the actions of their users. Europe's "Electronic Commerce Act" contains a similar provision, but the judge found that The Pirate Bay didn't qualify. Why not? Because the law requires that a service provider was "not aware of the existence of the illegal information or operation, and was not aware of facts or circumstances which made it obvious that the illegal information or operation existed or who, as soon as he received knowledge about or became aware of this, prevented the spread of the information without delay."
Since they posted many of the takedown letters sent in by copyright owners, the admins certainly knew about all sorts of copyright infringement taking place on their site. They did nothing about it and instead mocked the rightsholders. "It must have been obvious to the defendants that the website contained torrent files which related to protected works," said the court. "None of them did, however, take any action to remove the torrent files in question, despite being urged to do so. The prerequisites for freedom from liability under §18 have, consequently, not been fulfilled."
Translation: no immunity.
The end of the beginning
Despite the verdict, the case is just getting started. Defense lawyers have already filed an appeal and have since accused the judge overseeing the case of a conflict of interest. Judge Tomas Norström belongs to a couple of Swedish copyright associations, a fact no one managed to dig up before the trial.
While the court's judgment sheds plenty of light on how The Pirate Bay operated and what its backers believe, the least relevant part of it may in fact be the legal reasoning.
Thanks to music trade group IFPI, the recent Pirate Bay ruling has now been "Englished" (PDF). While the verdict itself is well-known, numerous case details will be surprising to non-Swedish speakers—such as who paid for The Pirate Bay defense, which defendant was also arraigned on drug charges, and what happened to all that Pirate Bay computer equipment confiscated by the police?
A masterpiece of prose, the verdict is not. "A number of different filesharing programs and technologies have been developed over the years," says one representative section. "There have been or are two main types of filesharing systems."
But it does offer plenty of fascinating detail that was difficult for those not at the trial to learn. Let's take a look.
Confiscated equipment. All the confiscated servers and routing equipment from a police raid on The Pirate Bay "is declared forfeit," while other seized computers will remain confiscated "until the sentence has become legally binding." That process could take years, given the appeal already filed in the case, so by the time the equipment could be released, it will be obsolete.
Confiscated drugs. In the section devoted to defendant (and lover of wispy beards) Gottfrid Svartholm Warg, we come across this curious section. Not only were computers confiscated, but police picked up "three confiscated tablets of Klomifen," "narcotic drugs," and a "spoon containing traces of amphetamine."
Turns out that Warg wasn't just accused of aiding copyright infringement but also of violating Sweden's Prohibition of Certain Health-Impairing Goods Act. As part of the 2006 police raids on The Pirate Bay, the cops searched an apartment belonging to Warg's parents, where they found several of the listed items in "a drawer unit" and "a cupboard at the desk." Warg said that the apartment had been rented out to others at the time and that he had no knowledge of the drugs there; the court agreed that nothing had been proven against him.
But there was a second incident in June 2007, when a police patrol was called to an apartment and found Warg "heavily intoxicated." In his backpack, other "preparations" were found. Warg told the court "that, despite being intoxicated, he can remember the event. He has also stated that the backpack was his, but that he, at some point during the evening, had lent it to some individuals at the party. He knows 'approximately' who he lent the backpack to, but he does not want to reveal the names of these individuals."
This didn't go over well with the court, which found "beyond reasonable doubt that Gottfrid Svartholm Warg has been in possession of the preparations in question, and that he should, therefore, be sentenced for breach of the Prohibition of Certain Health-Impairing Goods Act."
Who paid for the lawyers? The older (and much richer) defendant Carl Lundström apparently paid for his own lawyer, but the three Pirate Bay admins did not. Their lawyers were all supplied an eventually paid for by the Swedish government, and they weren't cheap. Fredrik Neij's lawyer, for instance, was given 949,025 kronor (about $115,600) for his services; 35,525 kronor of that amount was given for "time wasted."
On moving to Argentina or Russia. As it became clear that Sweden might not be the best long-term base for The Pirate Bay, Carl Lundström explored the possibility of moving the site to Russia or Argentina—and he asked the Swedish Embassy for help. "A request by Carl Lundström to the Swedish Embassy in Argentina for assistance in relocating the operation there, since the situation vis a vis copyright in Argentina could be assumed to be more user-friendly than in Europe, was turned down by the Embassy," says the verdict. "Carl Lundström then contacted an Argentinean lawyer with the aim of ascertaining the cost of establishing the operation as a company in Argentina."
Similar moves were made in Russia; nothing appears to have come of them.
Legal advice. Why the interest in getting out of Sweden? A new copyright law came into effect in 2005, and Lundström worried that it would make the site illegal. "Carl Lundström contacted a lawyer," says the verdict. "Following discussions with his legal representative, he e-mailed Gottfrid Svartholm Warg and mentioned that as of 1 July 2005, the operation would be unlawful and that they should, therefore, consider relocating the operation to another country."
In the meantime, Fredrik Neij sought some legal advice of his own. Rather than pay a lawyer, though, he sought out the advice of a "law student who, in turn, checked with his teachers and professors." Based on advice from the student, Neij told the court that he believed The Pirate Bay was legal.
The Pirate Bay meets... TV? One other curious revelation was that Lundström had the idea back in 2006 "for new services in the form of a pooling of The Pirate Bay’s website and a digital television receiver." Few details are offered, but this sounds a bit like a set-top box that could tune TV and also grab video content from The Pirate Bay. As with many of the other schemes mentioned in the verdict, nothing came of this.
The Google defense. During the trial, the defendants harped on the fact that Google also indexes .torrent files, many of them infringing; why was a search engine like The Pirate Bay on trial while a search engine like Google was not?
Here is the judge's answer in its most condensed form: ""In accordance with what will be further demonstrated below, all the defendants were aware that a large number of the website’s users were engaged in the unlawful disposal of copyright-protected material. By providing a website with advanced search functions and easy uploading and downloading facilities, and by putting individual filesharers in touch with one other through the tracker linked to the site, the operation run via The Pirate Bay has, in the opinion of the District Court, facilitated and, consequently, aided and abetted these offences."
What happened to the "safe harbor"? US law offers immunity (under both the Communications Decency Act and the Digital Millennium Copyright Act) to certain websites and ISPs for the actions of their users. Europe's "Electronic Commerce Act" contains a similar provision, but the judge found that The Pirate Bay didn't qualify. Why not? Because the law requires that a service provider was "not aware of the existence of the illegal information or operation, and was not aware of facts or circumstances which made it obvious that the illegal information or operation existed or who, as soon as he received knowledge about or became aware of this, prevented the spread of the information without delay."
Since they posted many of the takedown letters sent in by copyright owners, the admins certainly knew about all sorts of copyright infringement taking place on their site. They did nothing about it and instead mocked the rightsholders. "It must have been obvious to the defendants that the website contained torrent files which related to protected works," said the court. "None of them did, however, take any action to remove the torrent files in question, despite being urged to do so. The prerequisites for freedom from liability under §18 have, consequently, not been fulfilled."
Translation: no immunity.
The end of the beginning
Despite the verdict, the case is just getting started. Defense lawyers have already filed an appeal and have since accused the judge overseeing the case of a conflict of interest. Judge Tomas Norström belongs to a couple of Swedish copyright associations, a fact no one managed to dig up before the trial.
While the court's judgment sheds plenty of light on how The Pirate Bay operated and what its backers believe, the least relevant part of it may in fact be the legal reasoning.
Friday, 24 April 2009
Deep packet inspection could be outlawed in US
US lawmakers are set to limit the way ISPs use deep packet inspection (DPI), even though no American service providers are using the technology.
Representative Rick Boucher, a Virginia Democrat, and three privacy experts, speaking at a hearing before the House Energy Commerce sub-committee urged lawmakers to pass comprehensive online privacy legislation in the coming months.
While DPI can be used to filter spam and identify criminals, the technology raises serious privacy concerns, Boucher said. "Its privacy-intrusion potential is nothing short of frightening," he added. "The thought that a network operator could track a user's every move on the Internet, record the details of every search and read every email ... is alarming."
Boucher, chairman of the House Subcommittee on Communications, Technology and the Internet, said he planned to introduce a privacy bill for online users. That legislation could possibly prohibit DPI for use in behavioural advertising and other uses not related to security or network management, he suggested.
Officials with Free Press, the Center for Democracy and Technology (CDT) and the Electronic Privacy Information Center (ERIC) all spoke in favour of online privacy legislation. "In our view, deep packet inspection is really no different than postal employees opening envelopes and reading letters inside," said Leslie Harris, president and CEO of CDT. "Consumers simply do not expect to be snooped on by their ISPs or other intermediaries in the middle of the network, so DPI really defies legitimate expectations of privacy that consumers have."
Comcast and Cox Communications, both cable-based broadband providers, have experimented with using DPI in conjunction with behavioural advertising, but panelists at the hearing said they knew of no US ISP now using DPI that way. However, there are about a dozen companies offering DPI services to ISPs, said Ben Scott, policy director at Free Press.
With ISPs staying away from DPI, Congress should let ISPs self-regulate, said Kyle McSlarrow, president and CEO of the trade group the National Cable and Telecommunications Association. "Any technology can be used for good purposes and for bad," he said. "We recognise that no one would want us looking at the communication in e-mail. We don't particularly want to do that."
The technology is changing so rapidly, it may be difficult to draft appropriate legislation, he added. "There are new models being created," he said. "It's fairly hard to freeze, in one point and time, a fairly immature marketplace. We should allow industry and all stakeholders to try to work together ... come up with self-regulatory principles that protect consumer privacy."
Some Republicans on the subcommittee also questioned whether legislation should be targeted only at ISPs. "Our focus should ... look at the entire Internet universe, including search engines and Internet advertising networks," said Representative Cliff Stearns, a Florida Republican. "Consumers don't care whether you are a search engine or a broadband provider; they just want to ensure that their privacy is protected."
Privacy advocates also urged lawmakers to go beyond rules that would force ISPs to get opt-in permission from customers before tracking their online activities. In many cases, customers don't completely understand what they're being asked to opt into, said Marc Rotenberg, EPIC's executive director.
"I don't think [opt-in] is sufficient because it won't be meaningful unless consumers understand what data about them is being collected and how it's being used," he said.
By Grant Gross, IDG news service
Representative Rick Boucher, a Virginia Democrat, and three privacy experts, speaking at a hearing before the House Energy Commerce sub-committee urged lawmakers to pass comprehensive online privacy legislation in the coming months.
While DPI can be used to filter spam and identify criminals, the technology raises serious privacy concerns, Boucher said. "Its privacy-intrusion potential is nothing short of frightening," he added. "The thought that a network operator could track a user's every move on the Internet, record the details of every search and read every email ... is alarming."
Boucher, chairman of the House Subcommittee on Communications, Technology and the Internet, said he planned to introduce a privacy bill for online users. That legislation could possibly prohibit DPI for use in behavioural advertising and other uses not related to security or network management, he suggested.
Officials with Free Press, the Center for Democracy and Technology (CDT) and the Electronic Privacy Information Center (ERIC) all spoke in favour of online privacy legislation. "In our view, deep packet inspection is really no different than postal employees opening envelopes and reading letters inside," said Leslie Harris, president and CEO of CDT. "Consumers simply do not expect to be snooped on by their ISPs or other intermediaries in the middle of the network, so DPI really defies legitimate expectations of privacy that consumers have."
Comcast and Cox Communications, both cable-based broadband providers, have experimented with using DPI in conjunction with behavioural advertising, but panelists at the hearing said they knew of no US ISP now using DPI that way. However, there are about a dozen companies offering DPI services to ISPs, said Ben Scott, policy director at Free Press.
With ISPs staying away from DPI, Congress should let ISPs self-regulate, said Kyle McSlarrow, president and CEO of the trade group the National Cable and Telecommunications Association. "Any technology can be used for good purposes and for bad," he said. "We recognise that no one would want us looking at the communication in e-mail. We don't particularly want to do that."
The technology is changing so rapidly, it may be difficult to draft appropriate legislation, he added. "There are new models being created," he said. "It's fairly hard to freeze, in one point and time, a fairly immature marketplace. We should allow industry and all stakeholders to try to work together ... come up with self-regulatory principles that protect consumer privacy."
Some Republicans on the subcommittee also questioned whether legislation should be targeted only at ISPs. "Our focus should ... look at the entire Internet universe, including search engines and Internet advertising networks," said Representative Cliff Stearns, a Florida Republican. "Consumers don't care whether you are a search engine or a broadband provider; they just want to ensure that their privacy is protected."
Privacy advocates also urged lawmakers to go beyond rules that would force ISPs to get opt-in permission from customers before tracking their online activities. In many cases, customers don't completely understand what they're being asked to opt into, said Marc Rotenberg, EPIC's executive director.
"I don't think [opt-in] is sufficient because it won't be meaningful unless consumers understand what data about them is being collected and how it's being used," he said.
By Grant Gross, IDG news service
Wednesday, 22 April 2009
BT blocks off Pirate Bay
BT and other mobile broadband providers are blocking access to The Pirate Bay, as part of a "self-regulation" scheme.
Read our top ten Pirate Bay putdowns here.
BT Mobile Broadband users who attempt to access the notorious BitTorrent tracker site are met with a "content blocked" message.
The warning page states the page has been blocked in "compliance with a new UK voluntary code".
"This uses a barring and filtering mechanism to restrict access to all WAP and internet sites that are considered to have 'over 18' status," the warning states. It goes on to list a series of categories that are blocked, including adult/sexually explicit content, "criminal skills" and hacking.
It's not stated which category The Pirate Bay breaches, although the site does host links to porn movies.
BT's warning message advises customers to contact customer services if they want the block on the site to be lifted. The message also invites users to seek further information on the self-regulation scheme on the Internet Watch Foundation's website, although an IWF spokesman denies any involvement with the mobile filtering scheme.
All mobile networks
The self-regulations scheme includes all five of the major mobile networks. (BT's service is based on the Vodafone network).
The Code says that members agree to block even legal "adult" content on mobile connections, in case phones or laptops fall into the hands of minors.
"The Code covers new types of content, including visual content, online gambling, mobile gaming, chat rooms and internet access," the code of practice states.
However, it then goes on to state that "the Code does not cover peer-to-peer communications but it does give assurances to customers that the mobile operators are taking action to combat illegal, bulk and nuisance communications."
Pirate Bay's founders last week lost their landmark case against several leading record companies and now face a huge fine and up to a year in jail, pending an appeal.
BT says that it alone took the decision to block The Pirate Bay site. "BT and the other UK mobile operators have agreed and implemented a voluntary Code of Practise for mobile content that restricts access to content unsuitable for customers under the age of 18," the company claims in a statement.
"The list of sites and content that is restricted is compiled by individual operators themselves. The warning that BT provides links to the IWF website is for information on the Code only. BT customers who wish to have access to particular sites reactivated can do so by calling 150."
Read our top ten Pirate Bay putdowns here.
BT Mobile Broadband users who attempt to access the notorious BitTorrent tracker site are met with a "content blocked" message.
The warning page states the page has been blocked in "compliance with a new UK voluntary code".
"This uses a barring and filtering mechanism to restrict access to all WAP and internet sites that are considered to have 'over 18' status," the warning states. It goes on to list a series of categories that are blocked, including adult/sexually explicit content, "criminal skills" and hacking.
It's not stated which category The Pirate Bay breaches, although the site does host links to porn movies.
BT's warning message advises customers to contact customer services if they want the block on the site to be lifted. The message also invites users to seek further information on the self-regulation scheme on the Internet Watch Foundation's website, although an IWF spokesman denies any involvement with the mobile filtering scheme.
All mobile networks
The self-regulations scheme includes all five of the major mobile networks. (BT's service is based on the Vodafone network).
The Code says that members agree to block even legal "adult" content on mobile connections, in case phones or laptops fall into the hands of minors.
"The Code covers new types of content, including visual content, online gambling, mobile gaming, chat rooms and internet access," the code of practice states.
However, it then goes on to state that "the Code does not cover peer-to-peer communications but it does give assurances to customers that the mobile operators are taking action to combat illegal, bulk and nuisance communications."
Pirate Bay's founders last week lost their landmark case against several leading record companies and now face a huge fine and up to a year in jail, pending an appeal.
BT says that it alone took the decision to block The Pirate Bay site. "BT and the other UK mobile operators have agreed and implemented a voluntary Code of Practise for mobile content that restricts access to content unsuitable for customers under the age of 18," the company claims in a statement.
"The list of sites and content that is restricted is compiled by individual operators themselves. The warning that BT provides links to the IWF website is for information on the Code only. BT customers who wish to have access to particular sites reactivated can do so by calling 150."
Report: Payment card data was top target in 2008
More records were breached in 2008 than in the previous four years combined as a result of a few large breaches involving payment cards, according to a report released on Wednesday.
Last year, 295 million records were compromised and there were 90 confirmed breaches, the Verizon Business 2009 Data Breach Investigations Report (PDF) found.
The top five breaches accounted for 93 percent of total records compromised and as a percentage of caseload, 80 percent were payment card breaches while payment card data represented 98 percent of all records compromised last year.
PIN data was increasingly targeted in 2008 in attacks in which magnetic-stripe data and PIN data was used for identity fraud. For example, criminals used the data to make ATM withdrawals from victim's accounts.
PIN data stolen in a breach at payment processor RBS WorldPay was used to clone cards and withdraw millions of dollars from victim bank accounts last year. Meanwhile, payment processor Heartland had a huge data breach of its own last year that it reported in January and there have been reports of another breach at an unidentified institution.
More than three-fourths of organizations suffering payment card breaches were found to be not compliant with PCI data security standards or had never been audited. The typical organization had met less than a third of the requirements in the standards, the report found.
This chart shows threat categories by percent of breaches (black) and records (red).

(Credit: Verizon)
Of the total breaches, 75 percent came from external sources, 39 percent involved multiple parties, 32 percent involved business partners and in 20 percent of the cases insiders were implicated. Three-fourths of the breaches were undiscovered and uncontained for weeks or months.
As far as types of breaches, 64 percent resulted from malicious hacking, 38 percent used malware, 22 percent involved privileged misuse, and 9 percent used physical attacks such as equipment theft or tampering.
In about four of 10 hacking-related breaches, an attacker gained unauthorized access to the victim via one of the many types of remote access and management software, typically provisioned to third-parties for remote administration.
During 2008, malware was involved in more than one-third of the cases investigated and contributed to nine out of 10 of all records breached.
"Malware is now an essential component to nearly all large-scale data breach scenarios," the report said. "Hacking gets the criminal in the door, but malware gets him the data."
Last year, 295 million records were compromised and there were 90 confirmed breaches, the Verizon Business 2009 Data Breach Investigations Report (PDF) found.
The top five breaches accounted for 93 percent of total records compromised and as a percentage of caseload, 80 percent were payment card breaches while payment card data represented 98 percent of all records compromised last year.
PIN data was increasingly targeted in 2008 in attacks in which magnetic-stripe data and PIN data was used for identity fraud. For example, criminals used the data to make ATM withdrawals from victim's accounts.
PIN data stolen in a breach at payment processor RBS WorldPay was used to clone cards and withdraw millions of dollars from victim bank accounts last year. Meanwhile, payment processor Heartland had a huge data breach of its own last year that it reported in January and there have been reports of another breach at an unidentified institution.
More than three-fourths of organizations suffering payment card breaches were found to be not compliant with PCI data security standards or had never been audited. The typical organization had met less than a third of the requirements in the standards, the report found.
This chart shows threat categories by percent of breaches (black) and records (red).
(Credit: Verizon)
Of the total breaches, 75 percent came from external sources, 39 percent involved multiple parties, 32 percent involved business partners and in 20 percent of the cases insiders were implicated. Three-fourths of the breaches were undiscovered and uncontained for weeks or months.
As far as types of breaches, 64 percent resulted from malicious hacking, 38 percent used malware, 22 percent involved privileged misuse, and 9 percent used physical attacks such as equipment theft or tampering.
In about four of 10 hacking-related breaches, an attacker gained unauthorized access to the victim via one of the many types of remote access and management software, typically provisioned to third-parties for remote administration.
During 2008, malware was involved in more than one-third of the cases investigated and contributed to nine out of 10 of all records breached.
"Malware is now an essential component to nearly all large-scale data breach scenarios," the report said. "Hacking gets the criminal in the door, but malware gets him the data."
Sunday, 12 April 2009
New MS08-067 Exploit Creeps in During DOWNAD Frenzy
A new MS08-067 exploit silently made its entrance as the rest of the world was keeping watch on DOWNAD’s next step last week. In what seems to be a case of “old worm with new tricks,” the worm Neeris which has been active for a few years now was found updated with the now infamous MS08-067 exploit.
Detected by Trend Micro as WORM_NEERIS.A, the number of PCs infected by this variant reportedly spiked almost at the same time that DOWNAD was supposed to do its thing. However, despite similarities between DOWNAD and Neeris, Microsoft reports that no evidence has been found suggesting any connection between the two.
Apart from propagating through the Microsoft Server Service Vulnerability, WORM_NEERIS.A also propagates through removable drives, SQL servers, and through the instant messaging application MSN Messenger. It also drops a rootkit component, detected as RTKT.FARFLI.UW which it uses to hides its processes. This worm also opens the affected system’s port 449 and connects to a certain site where it waits for commands sent by a remote user.
If Neeris would be able to live up to the mark left by DOWNAD is anyone’s guess for now. Sadly, the fact that another threat leveraging on the same vulnerability that had just been on the global spotlight has emerged indicates that there are still users who are unable to see the importance of updating their systems. Users must realize that cyber criminals will continue to strike as long as they keep themselves vulnerable. So please, update here
Detected by Trend Micro as WORM_NEERIS.A, the number of PCs infected by this variant reportedly spiked almost at the same time that DOWNAD was supposed to do its thing. However, despite similarities between DOWNAD and Neeris, Microsoft reports that no evidence has been found suggesting any connection between the two.
Apart from propagating through the Microsoft Server Service Vulnerability, WORM_NEERIS.A also propagates through removable drives, SQL servers, and through the instant messaging application MSN Messenger. It also drops a rootkit component, detected as RTKT.FARFLI.UW which it uses to hides its processes. This worm also opens the affected system’s port 449 and connects to a certain site where it waits for commands sent by a remote user.
If Neeris would be able to live up to the mark left by DOWNAD is anyone’s guess for now. Sadly, the fact that another threat leveraging on the same vulnerability that had just been on the global spotlight has emerged indicates that there are still users who are unable to see the importance of updating their systems. Users must realize that cyber criminals will continue to strike as long as they keep themselves vulnerable. So please, update here
Tuesday, 7 April 2009
French government OKs Web piracy law
LONDON -- The French National Assembly has voted to adopt the central clause in the anti-piracy Creation and Internet Law, which would allow a state body to cut off copyright infringers' broadband access after two warnings were issued.
The three-strikes scheme proposed by the French government to tackle P2P file-sharing has met with opposition from some politicians and consumer groups, but the vote has been welcomed by parts of the international music business.
"The French government has taken a decisive step to protect artists and creators, setting an example to the rest of the world," said IFPI chairman and chief executive John Kennedy in a statement. "The great thing about this French initiative is that it will result in very sensible and achievable actions by ISPs to reduce piracy in a way that is overwhelmingly preventative and not punitive."
IMPALA, which represents 4,000 independent labels across Europe, also welcomed the vote.
"We see this as a great breakthrough. Independents produce 80% of all new releases and as a result suffer particularly from illegal downloading," said executive chair Helen Smith in a statement. "We feel that this text reaches an excellent compromise between the interests of the fans, the music companies and the ISPs."
Michel Lambot, co-president of PIAS and co-president of IMPALA, added: "This was a bold move by the French, and has brought its fare share of criticism. We hope the law will now be able to go on to be the success that we believed it would and that it will serve as an example that other countries can follow."
France's consumer rights group UFC-Que Choisir has opposed the plan.
Thursday's vote on the three-strikes measure was crucial to the legislation, which will undergo parliamentary scrutiny article by article, beginning April 9, before it is finally passed into law.
The three-strikes scheme proposed by the French government to tackle P2P file-sharing has met with opposition from some politicians and consumer groups, but the vote has been welcomed by parts of the international music business.
"The French government has taken a decisive step to protect artists and creators, setting an example to the rest of the world," said IFPI chairman and chief executive John Kennedy in a statement. "The great thing about this French initiative is that it will result in very sensible and achievable actions by ISPs to reduce piracy in a way that is overwhelmingly preventative and not punitive."
IMPALA, which represents 4,000 independent labels across Europe, also welcomed the vote.
"We see this as a great breakthrough. Independents produce 80% of all new releases and as a result suffer particularly from illegal downloading," said executive chair Helen Smith in a statement. "We feel that this text reaches an excellent compromise between the interests of the fans, the music companies and the ISPs."
Michel Lambot, co-president of PIAS and co-president of IMPALA, added: "This was a bold move by the French, and has brought its fare share of criticism. We hope the law will now be able to go on to be the success that we believed it would and that it will serve as an example that other countries can follow."
France's consumer rights group UFC-Que Choisir has opposed the plan.
Thursday's vote on the three-strikes measure was crucial to the legislation, which will undergo parliamentary scrutiny article by article, beginning April 9, before it is finally passed into law.
Survey: Credit card fraud a top concern in U.S.
This should come as no surprise to anyone, but people in the U.S. are worried that as the economy worsens, the chances for identity fraud, particularly with regard to credit card data theft, will increase.
Nearly 75 percent of Americans believe that the global financial crisis increases their risk of identity and related fraud, according to the Unisys Security Index due to be released on Monday.
More than two-thirds surveyed said they are extremely or very concerned about other people obtaining and using their credit and debit card data, with 90 percent at least somewhat concerned.
Credit and debit card fraud is the top security concern for people, with 68 percent saying they are extremely or very concerned. And 66 percent said they are seriously concerned about unauthorized access to or misuse of personal information.
More than 40 percent of respondents said they are extremely or very concerned about security related to viruses and unsolicited e-mail.
Overall, people are more worried about their financial security and less worried about national security than in previous surveys, according to the survey.
The survey of more than 1,000 respondents in the U.S. was conducted from February 20-22.
Nearly 75 percent of Americans believe that the global financial crisis increases their risk of identity and related fraud, according to the Unisys Security Index due to be released on Monday.
More than two-thirds surveyed said they are extremely or very concerned about other people obtaining and using their credit and debit card data, with 90 percent at least somewhat concerned.
Credit and debit card fraud is the top security concern for people, with 68 percent saying they are extremely or very concerned. And 66 percent said they are seriously concerned about unauthorized access to or misuse of personal information.
More than 40 percent of respondents said they are extremely or very concerned about security related to viruses and unsolicited e-mail.
Overall, people are more worried about their financial security and less worried about national security than in previous surveys, according to the survey.
The survey of more than 1,000 respondents in the U.S. was conducted from February 20-22.
Saturday, 4 April 2009
France to Block The Pirate Bay, Disconnect File-Sharers
Despite public protests the French Parliament has passed a controversial new law that will see alleged copyright infringers disconnected from the Internet. In addition, France’s Minister of Culture Christine Albanel has stated that under the new law, ISPs may be ordered to block The Pirate Bay.
In order to clamp down on piracy the French have passed a new law requiring Internet service providers to cut off Internet access for persistent offenders. Under the new legislation ISPs have to warn alleged copyright infringers twice, and if they they ignore these warnings their Internet access is terminated for up to a year.
One of the biggest problems with the new law is that copyright infringers will be identified only by an IP-address, which will undoubtedly lead to many false accusations. Those who want to prove their innocence have only one option, namely, to install a spyware application that will monitor their every move on the Internet and report it back to the authorities. Hardly practical.
The law goes much further than disconnecting alleged file-sharers though. In addition it is now possible to take “any action” in order to put a halt to copyright infringement. Minister of Culture, Christine Albanel, explicitly named The Pirate Bay as one of the sites that could be easily blocked under the new law.
Thus, without having to provide evidence that a website is engaging in illegal activities, it can still be blocked. Potentially this could mean that access to BitTorrent sites is disallowed in France, as well as access to sites like YouTube or perhaps even Google.
In summary, the new law introduces unlimited options for the copyright holders to go after sites and people that may or may not infringe copyright, without having to actually proove that the accused are guilty. To date, this is by far the most aggressive and unbalanced piece of copyright legislation that we’ve seen.
Even more so, only last week the European Parliament spoke out against such disproportionate legislation by adopting a report that aims to protect the rights and freedoms of Internet users and excludes ‘three strikes’ as a punitive sanction. Unfortunately, members of the French parliament completely ignored this.
What struck us most is that the people who get to decide on these issues have no clue about file-sharing at all. Many of them don’t know what BitTorrent is, or how it works. Yet, they decide the fate of hundreds of thousands of Internet users.
In order to clamp down on piracy the French have passed a new law requiring Internet service providers to cut off Internet access for persistent offenders. Under the new legislation ISPs have to warn alleged copyright infringers twice, and if they they ignore these warnings their Internet access is terminated for up to a year.
One of the biggest problems with the new law is that copyright infringers will be identified only by an IP-address, which will undoubtedly lead to many false accusations. Those who want to prove their innocence have only one option, namely, to install a spyware application that will monitor their every move on the Internet and report it back to the authorities. Hardly practical.
The law goes much further than disconnecting alleged file-sharers though. In addition it is now possible to take “any action” in order to put a halt to copyright infringement. Minister of Culture, Christine Albanel, explicitly named The Pirate Bay as one of the sites that could be easily blocked under the new law.
Thus, without having to provide evidence that a website is engaging in illegal activities, it can still be blocked. Potentially this could mean that access to BitTorrent sites is disallowed in France, as well as access to sites like YouTube or perhaps even Google.
In summary, the new law introduces unlimited options for the copyright holders to go after sites and people that may or may not infringe copyright, without having to actually proove that the accused are guilty. To date, this is by far the most aggressive and unbalanced piece of copyright legislation that we’ve seen.
Even more so, only last week the European Parliament spoke out against such disproportionate legislation by adopting a report that aims to protect the rights and freedoms of Internet users and excludes ‘three strikes’ as a punitive sanction. Unfortunately, members of the French parliament completely ignored this.
What struck us most is that the people who get to decide on these issues have no clue about file-sharing at all. Many of them don’t know what BitTorrent is, or how it works. Yet, they decide the fate of hundreds of thousands of Internet users.
Monday, 23 March 2009
Save the children? ICANN opens debate on CyberSafety charter
The group behind the campaign to take porn off of port 80 is now lobbying ICANN to create a new "Cybersafety Constituency" to assist in the formulation of domain name system policy.
ICANN has been soliciting a lot of comments on its governance and future of late, including one petition to form a CyberSafety Constituency (CSC) within the Non-Commercial Stakeholders Group. (NCSG). The petition (PDF) as filed with ICANN is fairly innocuous and harmless-sounding, but the woman doing the filing—Professor Cheryl B. Preston, of Brigham Young University—has ties to other nonprofit organizations that should have been disclosed at some point within the application procedure.
Preston is general counsel for the nonprofit group CP80, which advocates for the creation of an Internet filtration system that would supposedly seek to keep porn and other adult content sandboxed away from the family-friendly tubes. The organization deserves credit for proposing a system that wouldn't automatically cripple Internet access speeds nationwide, force deep packet inspection, or turn ISPs into de facto Internet police. That said, failing to qualify as prima facie terrible does not automatically qualify CP80's legislative baby, the Internet Community Portals Act (ICPA) as a good idea.
Filtering at the port level
CP80's solution to the seemingly intractable problem of Internet filtering is to segregate traffic by port. All "normal" traffic (have fun defining that) would continue to flow over Port 80 or whatever port it's currently assigned to. Adult content, however, would be shifted away from Port 80 (hence the group's name, "Clean Port 80") and on to a new port—let's call it Port XXX. Were CP80's legislation to pass, the Internet would look something like this:
The system as illustrated would allow an ISP to sell access plans to both the filtered and unfiltered Internet, consumers could choose which they want, freedoms are preserved, and everyone goes home happy...at least in theory. CP80's proposal might deserve a small bit of credit for avoiding some of the obvious issues that sank the concept of an adult-content .XXX domain name—except for the massive technical flaws and political challenges inherent to the ICPA's design. If you're already wondering about international governance and enforcement, don't worry—CP80 has anticipated your concerns:
Got that?
The ICANN connection
Professor Preston describes the CSC as a group that would focus on Internet safety issues and cites her personal concern that "as Internet policies are developed at ICANN, the interests of families, children, consumers, victims of cybercrime, religions, and cultures become better represented...we need to carefully craft mechanisms involving law and industry that balance unfettered free speech and anonymity with some protections against exploitation of the most vulnerable, the ability to address and reduce criminal activity, and the right of Internet users to have choices in the nature of their access."
As proposed, the CSC would also function as a global outreach initiative and would attempt to coordinate international responses to what the paper posits are common cross-border, cross- cultural concerns. Again, as written, all of this is very kosher: everyone wants to balance rights and responsibilities, protect the "most vulnerable" from exploitation, and give users freedom of choice. Preston's letter advocating the creation of the CSC is consistent with her work for CP80, but some mention of the latter should occur in any discussion of the former, especially since CP80 makes it clear that they've considered the role ICANN might hypothetically play in the creation and international adoption of ICPA-equivalent legislation.
Preston's omission is made potentially more serious by the fact that CP80 itself isn't exactly a digital city on a hill. The organization is headed by Ralph Yarro III, CEO and largest shareholder of the SCO Group. He's also the Founder/CEO of ThinkAtomic; if you visit that company's website you'll note (for now, at least) that the "Featured Company" of the day is CP80. ThinkAtomic is a prominent backer of CP80, and is listed as providing the group with legal, strategic, medical, and technology contributions. Run down the page, and you'll note a common last name—Ralph, Justin, and Matthew Yarro are all listed as technology contributors.
If the BYU professor is serious about establishing the CSC, she'd do well to distance herself from either CP80 or the CSC petition before ICANN. There's nothing within the CSC's stated mission objective that would automatically create conflict with other actors interested in maintaining free speech and online anonymity. The best way to disperse accusations that she or the organization she currently represents has a hidden agenda is to cut ties with one or the other. Whether people agree or disagree with any particular position a hypothetical CSC might advocate, they won't respect the body as legitimate if its viewed as nothing more than the puppet of a US group.
As for CP80's ICPA proposal, it's a bad idea; there's no way feasibly address the political and technical challenges of the project. Even if all such barriers vanished, there would still remain the age-old question of censorship—who does the censoring and writes the standards? Pretending that these issues are irrelevant because we all agree that protecting children is important is whitewashing the topic at its finest. ICANN is accepting public comment on the issue.
By Joel Hruska
Subscribe to:
Posts (Atom)