Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Tuesday, 2 March 2010

Leaked intelligence documents:Facebook,Comcast, Microsoft




Leaked intelligence documents: Here's what Facebook and Comcast will tell the police about you!!!

Leaked Microsoft intelligence document: Here's what Microsoft will reveal to police about you

FTC: Identity Theft Is No. 1 Consumer Complaint


Are you really you? It’s hard to say.

That’s because identity theft was the top consumer complaint for 2009, the Federal Trade Commission reported Wednesday.

It was also the top complaint from the year before, although 5 percent fewer consumers reported it in 2009, the commission said.

Overall, of the 1.3 million complaints the agency received last year, 21 percent were for identity theft. Debt collection agencies ranked second, with 9 percent of complaints, according to the Consumer Sentinel Network Data Book released Wednesday.

Credit card fraud was the top complaint when it comes to identity theft, followed by fraud related to government benefits, utilities, phones and loans.

The FTC did not verify the complaints lodged with it. It said 72 percent of those reporting identity theft also notified a police department.

The complete 101-page report (.pdf) is available here.

By David Kravets

Tuesday, 2 February 2010

One in four children sent pornography, says surveyOne in four children have sent or been sent inappropriate material including pornography via email,


Photo: GETTY

One in four children have sent or been sent inappropriate material including pornography via email, according to a survey.
The research also found that one in 20 children, aged between six and 15, had communicated with a stranger via webcam and one in 50 have actually met a stranger they first contacted online.

The report, which surveyed 500 children, found that many children are getting away with behaviour online that they wouldn’t get away with in the real world, largely because of their parents’ lack of understanding and awareness of their internet habits and of safety precautions.
More than six out of 10 children (62 per cent) said they lie to parents about what they have been looking at online and over half (53 per cent) delete the history on their web browser so their parents can’t see what they have been looking at.

The survey, by TalkTalk, the broadband provider, also found that and one in nine (11 per cent) have either bullied someone online or been bullied online themselves.

In December, the Government announced that every primary schoolchild in the country will be taught about the dangers of the internet and how to safely surf online.

The “Click Clever, Click Safe’ campaign comes in response to a report by Prof Tanya Byron, the child psychologist and broadcaster, who was asked by the Government to consider how to protect children online.

Prof Tanya Byron, who oversaw the TalkTalk research, said: “It’s crucial that parents educate themselves about what’s going on online and what their kids are doing there.”

By Urmee Khan, Digital and Media Correspondent

Thursday, 21 January 2010



Imperva, a data security firm, said it had analysed around 32 million passwords that had been exposed in a recent hack of the RockYou website.

In December last year a hacker breached the site's company database and gained access to the unencrypted usernames and passwords of all its 32 million users.
After studying the security breach Imperva has come up with a list of the most commonly used passwords which website users should avoid.

“Everyone needs to understand what the combination of poor passwords means in today’s world of automated cyber attacks: with only minimal effort, a hacker can gain access to one new account every second—or 1000 accounts every 17 minutes,” said Amichai Shulman, Imperva’s chief technical officer.

“Employees using the same passwords on Facebook that they use in the workplace bring the possibility of compromising enterprise systems with insecure passwords, especially if they are using easy to crack passwords like ‘123456’,” he added.

“The problem has changed very little over the past 20 years. It’s time for everyone to take password security seriously; it’s an important first step in data security.”

The ten most commonly used passwords analysed in the study were:

1. 123456

2. 12345

3. 123456789

4. Password

5. iloveyou

6. princess

7. rockyou

8. 1234567

9. 12345678

10. abc123

Tuesday, 5 January 2010

New airport scanners break child porn laws


A 12-month trial at Manchester airport of full body scanners only went ahead last month after under-18s were exempted. Photograph: Paul Ellis/AFP/Getty Images

The rapid introduction of full body scanners at British airports threatens to breach child protection laws which ban the creation of indecent images of children, the Guardian has learned.

Privacy campaigners claim the images created by the machines are so graphic they amount to "virtual strip-searching" and have called for safeguards to protect the privacy of passengers involved.

Ministers now face having to exempt under 18s from the scans or face the delays of introducing new legislation to ensure airport security staff do not commit offences under child pornography laws.

They also face demands from civil liberties groups for safeguards to ensure that images from the £80,000 scanners, including those of celebrities, do not end up on the internet. The Department for Transport confirmed that the "child porn" problem was among the "legal and operational issues" now under discussion in Whitehall after Gordon Brown's announcement on Sunday that he wanted to see their "gradual" introduction at British airports.

A 12-month trial at Manchester airport of scanners which reveal naked images of passengers including their genitalia and breast enlargements, only went ahead last month after under-18s were exempted.

The decision followed a warning from Terri Dowty, of Action for Rights of Children, that the scanners could breach the Protection of Children Act 1978, under which it is illegal to create an indecent image or a "pseudo-image" of a child.

Dowty told the Guardian she raised concerns with the Metropolitan police five years ago over plans to use similar scanners in an anti-knife campaign, and when the Department for Transport began a similar trial in 2006 on the Heathrow Express rail service from Paddington station.

"They do not have the legal power to use full body scanners in this way," said Dowty, adding there was an exemption in the 1978 law to cover the "prevention and detection of crime" but the purpose had to be more specific than the "trawling exercise" now being considered.

A Manchester airport spokesman said their trial had started in December, but only with passengers over 18 until the legal situation with children was clarified. So far 500 people have taken part on a voluntary basis with positive feedback from nearly all those involved.

Passengers also pass through a metal detector before they can board their plane. Airport officials say the scanner image is only seen by a single security officer in a remote location before it is deleted.

A Department for Transport spokesman said: "We understand the concerns expressed about privacy in relation to the deployment of body scanners. It is vital staff are properly trained and we are developing a code of practice to ensure these concerns are properly taken into account. Existing safeguards also mean those operating scanners are separated from the device, so unable to see the person to whom the image relates, and these anonymous images are deleted immediately."

But Shami Chakrabarti, of Liberty, had concerns over the "instant" introduction of scanners: "Where are the government assurances that electronic strip-searching is to be used in a lawful and proportionate and sensitive manner based on rational criteria rather than racial or religious bias?" she said.

Her concerns were echoed by Simon Davies of Privacy International who said he was sceptical of the privacy safeguards being used in the United States. Although the American system insists on the deletion of the images, he believed scans of celebrities or of people with unusual or freakish body profiles would prove an "irresistible pull" for some employees.

The disclosures came as Downing Street insisted British intelligence information that the Detroit plane suspect tried to contact radical Islamists while a student in London was passed on to the US.

Umar Farouk Abdulmutallab's name was included in a dossier of people believed to have made attempts to deal with extremists, but he was not singled out as a particular risk, Brown's spokesman said.

President Barack Obama has criticised US intelligence agencies for failing to piece together information about the 23-year-old that should have stopped him boarding the flight.

Brown's spokesman said "There was security information about this individual's activities and that was shared with the US authorities."

by
Alan Travis, home affairs editor
guardian.co.uk

Wednesday, 25 November 2009

Εναντίον του Google Analytics στρέφονται οι γερμανικές υπηρεσίες προστασίας δεδομένων

Associated Press

Βερολίνο

Παράνομη θεωρούν οι γερμανικές υπηρεσίες προστασίας προσωπικών δεδομένων τη χρήση του Google Analytics, της υπηρεσίας που παρουσιάζει τα «δημογραφικά χαρακτηριστικά» των επισκεπτών ιστοσελίδων.

Το Google Analytics χρησιμοποιείται για τη δημιουργία «προφίλ» των επισκεπτών συγκεκριμένων ιστοσελίδων, εξακριβώνοντας όχι μόνο το πόσοι και από πού είναι οι επισκέπτες τους, αλλά και το «διαδικτυακό» ιστορικό τους. Έτσι, ο ιδιοκτήτης της ιστοσελίδας ή ο όποιος ενδιαφερόμενος μπορεί να σχηματίσει μία εικόνα των επισκεπτών της και των προτιμήσεών τους.

Οι γερμανικές υπηρεσίες προστασίας προσωπικών δεδομένων όμως, τόσο σε ομοσπονδιακό επίπεδο όσο και σε διάφορα κρατίδια, θεωρούν ότι η χρήση του Google Analytics αντιτίθεται στο γερμανικό δίκαιο.

Σύμφωνα με την εφημερίδα Zeit, περίπου το 13% των γερμανικών ιστοσελίδων χρησιμοποιούν την υπηρεσία -ανάμεσά τους φαρμακευτικές εταιρείες, πολιτικά κόμματα και ΜΜΕ. Μεταξύ άλλων, το νομικό πρόβλημα δημιουργείται από το κατά πόσον η διεύθυνση IP, η «προσωπική υπογραφή» του κάθε υπολογιστή στο διαδίκτυο, αποτελεί δεδομένο «προσωπικώς συσχετίσιμο». Οι γερμανικές υπηρεσίες θεωρούν πως αυτό συμβαίνει ενώ η Google το βλέπει διαφορετικά, αλλά φαίνεται ότι και η γερμανική νομολογία παρουσιάζεται εξίσου αμφίσημη.

Οι υπηρεσίες φοβούνται ότι η Google θα μπορούσε να δημιουργήσει «προφίλ» εκατομμυρίων χρηστών του διαδικτύου, τα οποία θα συμπεριλαμβάνουν τα ενδιαφέροντά τους, τις συνήθειες ζωής τους, την καταναλωτική τους συμπεριφορά και τις πολιτικές ή ακόμη και σεξουαλικές προτιμήσεις τους.

Οι χρήστες, τονίζουν σύμφωνα με το δημοσίευμα οι γερμανικές υπηρεσίες, δεν έχουν τη δυνατότητα να επιλέξουν ενεργητικά τη μη υπαγωγή τους στο λογισμικό (opt-out), χωρίς το οποίο «δεν στέκει τίποτα». Εξίσου ενοχλημένες παρουσιάζονται οι υπηρεσίες με το γεγονός ότι τα προσωπικά δεδομένα μπορούν να γίνουν αντικείμενο επεξεργασίας από εταιρείες ή φορείες επί αμερικανικού εδάφους.

Η Google υποστηρίζει ότι η επεξεργασία των δεδομένων στις ΗΠΑ καλύπτεται απολύτως από τη συμφωνία «Safe Harbour» μεταξύ Ευρώπης και Ουάσιγκτον, ενώ θεωρεί περιττό το «opt-out» καθώς οι χρήστες μπορούν «να απενεργοποιήσουν τα cookies».

Thursday, 19 November 2009

Ethics leaks spur House bill banning P2P apps on .gov PCs


Over the past year, there have been several embarrassing incidents where private government documents have leaked because employees didn't know how to properly configure P2P client software. For the US House of Representatives, the last straw came when ethics documents were leaked. A bill has been introduced to ban the use of P2P apps by federal employees.

Peer-to-peer filesharing applications have been wildly popular, especially among those interested in accessing pirated software, music, and media. But not everyone who operates a P2P client knows how to properly configure the software, and some clients may share entire directories unless explicitly directed not to. Apparently, some government employees have exhibited this sort of carelessness, as private and secret government documents have shown up on P2P networks. Now, at least one Congressman has had enough, and has introduced a bill that would ban the use of P2P software by government employees.

The Congressman in question is Edolphus Towns of New York, who chairs the Committee on Oversight and Government Reform. In a statement announcing the bill's introduction, Towns highlights a number of embarrassing incidents in which sensitive government files showed up on P2P networks. These include schematics for the Presidential helicopter and the location of a first-family safe house, as well as the financial records of a Supreme Court Justice.

But the cynic would suggest that the real spur to action was the leak of a whole series of documents related to ethics investigations of Towns' fellow House members, which he also cited in the announcement. This included a full list of ongoing investigations and details on a number of them. The committee that suffered the leak issued a statement (PDF) at the end of October which indicated that P2P software was involved in the leak, so this appears to involve a relatively quick response.

The bill itself, termed the Secure Federal File Sharing Act, calls on the Director of the Office of Management and Budget to issue guidance on the use of P2P software, and provides the Director some guidance on what it should be: P2P software will be banned on government-owned computers. The OMB Director will have 90 days to come up with rules for government workers and contractors that have access to documents at home. Procedures will also be put in place for government agencies that have legitimate need for P2P software, in order to grant them exceptions.

By 180 days after the bill's passage, the OMB will have to specify procedures to detect and purge P2P use from within the government's networks. After the procedures are in place, the OMB will need to provide Congress with an annual report detailing all the exemptions that are in place.

Although it's tempting to snicker at the ethics leaks being the primary event that spurred Congress to action, it wouldn't be at all surprising if some of the complaints that leaked are the result of misunderstandings or political disagreements; all of them will almost certainly be used (and abused) in future political campaigns. In any case, the other leaks are certainly more severe, and there's no reason to think that the average government employee is ever going to be more technically savvy or security-literate than the general computer using population, so the law addresses a real issue.

Given that P2P software does have a number of legitimate uses, however, blanket restrictions and a formal approval process may turn out to be a hindrance. Assuming the bill passes, the real challenge is likely to be crafting a quick and effective exemption process.

By John Timmer

Wednesday, 4 November 2009

Secure computers aren’t so secure


Even well-defended computers can leak shocking amounts of private data. MIT researchers seek out exotic attacks in order to shut them down

You may update your antivirus software religiously, immediately download all new Windows security patches, and refuse to click any e-mail links ostensibly sent by your bank, but even if your computer is running exactly the way it’s supposed to, a motivated attacker can still glean a shocking amount of private information from it. The time it takes to store data in memory, fluctuations in power consumption, even the sounds your computer makes can betray its secrets. MIT researchers centered at the Computer Science and Artificial Intelligence Lab’s Cryptography and Information Security Group (CIS) study such subtle security holes and how to close them.

In 2005, Eran Tromer, now a postdoc at CIS, and colleagues at the Weizmann Institute in Rehovot, Israel, showed that without any breach of security in the ordinary sense, a seemingly harmless computer program could eavesdrop on other programs and steal the type of secret cryptographic key used by one of the most common Internet encryption schemes. Armed with the key, an attacker could steal a computer user’s credit card number, bank account password — whatever the encryption scheme was invoked to protect.

Computer operating systems are supposed to prevent any given program from looking at the data stored by another. But when two programs are running at the same time, they sometimes end up sharing the same cache — a small allotment of high-speed memory where the operating system stores frequently used information. Tromer and his colleagues showed that simply by measuring how long it took to store data at a number of different cache locations, a malicious program could determine how frequently a cryptographic system was using those same locations. “The memory access patterns — that is, which memory addresses are accessed — are heavily influenced by the specific secret key being used in that operation,” Tromer says. “We demonstrated a concise and efficient procedure for learning the secret keys given just this crude information about the memory access patterns.” Complete extraction of the private key, Tromer says, “takes merely seconds, and the measurements that are needed, of the actual cryptographic process being attacked, can be carried out in milliseconds.”

The encryption system that Tromer was attacking, called AES, was particularly vulnerable because it used tables of precalculated values as a computational short cut, so that encoding and decoding messages wouldn’t be prohibitively time consuming. Since Tromer and his colleagues published their results, Intel has added hardware support for AES to its chips, so that Internet encryption software won’t have to rely on such “lookup tables.”

In a statement, Intel told the MIT News Office that its decision “was mainly motivated by the performance/efficiency benefits achieved,” but that “in addition, there is a potential security benefit since these new instructions can mitigate the possibility of software side channel attacks on AES that have been described in research papers, including those discovered by Tromer, Percival, and Bernstein.”

“I think it’s fair to say that it’s a direct response to the cache-timing attacks against AES,” Pankaj Rohatgi, director of hardware security at the data security firm Cryptography Research, says of Intel’s move.

Together with CIS cofounder Ron Rivest and CSAIL’s Saman Amarasinghe, Tromer is trying to develop further techniques for thwarting cache attacks by disrupting the correlations between encryption keys and memory access patterns. A couple weeks ago, at the Association for Computing Machinery’s Symposium on Operating Systems Principles, the researchers announced that they had a “proof-of-concept prototype” of a defense system, but they plan to continue testing and refining it before publishing any papers.

Tromer has also been investigating whether cloud computing — the subcontracting of computational tasks to networked servers maintained by companies like Amazon and Google — is susceptible to cache attacks. Many web sites rely on cloud computing to handle sudden surges in their popularity: renting added server space for a few hours at a time can be much cheaper than maintaining large banks of proprietary servers that frequently stand idle.

The word “cloud” is supposed to suggest that this vast agglomeration of computing power is amorphous and constantly shifting, but Tromer and colleagues at the University of California, San Diego, were able to load their eavesdropping software onto precisely the same servers that were hosting websites they’d targeted in advance. In part, their approach involved spreading their software across a number of servers, then assailing a targeted website with traffic. By spying on the caches of the servers hosting their software, they could determine which were also trying to keep pace with their fake traffic spikes. Once they’d identified the target site’s servers, they could use cache monitoring to try to steal secrets.

“Imagine a stock broker that specializes in a specific company,” Tromer says. “If you observe that his virtual machine is particularly active, that could be valuable information. Or you may want to know how popular your competitors’ website is. We’ve actually demonstrated that we can very robustly estimate web server popularity.”

“This has sparked the imagination of both the research community and industry,” Rohatgi says. “I interact with a lot of people in industry, and when they say, ‘Give me the technical basis for this,’ I point to [Tromer and colleagues’] papers.”

Finally, Tromer is continuing work he began as a graduate student, on the use of a “hundred-dollar commodity microphone” to record the very sounds emitted by a computer and analyze them for information about cryptographic keys. So far, Tromer hasn’t been able to demonstrate complete key extraction, but he believes he’s getting close.

Any information at all about a computer’s internal workings “is actually fairly damaging,” Rohatgi says. “In some sense, some of these cryptographic algorithms are fairly brittle, and with a little extra information, you can break them.”

Larry Hardesty, MIT News Office

Thursday, 27 August 2009

Court’s Steroid Ruling Pumps Up Computer Privacy


A divided 11-judge federal appeals court panel has dramatically narrowed the government’s search-and-seizure powers in the digital age, ruling Wednesday that federal prosecutors went too far when seizing 104 professional baseball players’ drug results when they had a warrant for just 10.

The 9th U.S. Circuit Court of Appeals’ 9-2 decision offered Miranda-style guidelines to prosecutors and judges on how to protect Fourth Amendment privacy rights while conducting computer searches.

Ideally, when searching a computer’s hard drive, the government should cull the specific data described in the search warrant, rather than copy the entire drive, the San Francisco-based appeals court ruled. When that’s not possible, the feds must use an independent third party under the court’s supervision, whose job it would be to comb through the files for the specific information, and provide it, and nothing else, to the government.

Judges, the appellate court added, should be wary of prosecutors and perhaps “deny the warrant altogether” if the government does not consent to such a plan in data-search cases.

The government said it was weighing its options, including whether to appeal to the Supreme Court.

The ruling came in a case that dates to 2004, when federal prosecutors probing a Northern California steroid ring obtained warrants to seize the results of urine samples of 10 pro baseball players at a Long Beach, California drug-testing facility. The players had been tested as part of a voluntary drug-deterrence program implemented by Major League Baseball.

Federal agents serving the search warrant on the Comprehensive Drug Testing lab wound up making a copy of a directory containing a Microsoft Excel spreadsheet with results of every player that was tested in the program. Then, back in the office, they scrolled freely through the spreadsheet, ultimately noting the names of all 104 players who tested positive.

The government argued that the information was lawfully found in “plain site,” just like marijuana being discovered on a dining room table during a court-authorized weapons search of a home. But the court noted that the agents actively scrolled to the right side of the spreadsheet to peek at all the players test results, when they could easily have selected, copied and pasted only the rows listing the players named in the search warrant.

Chief Judge Alex Kozinski, writing for the 9-2 majority, (.pdf) said the government “must maintain the privacy of materials that are intermingled with seizable materials, and … avoid turning a limited search for particular information into a general search of office file systems and computer databases.”

George Washington University law professor and former federal cybercrime prosecutor Orin Kerr called the decision “truly astonishing.”

“The majority opinion … announces a laundry list of brand-new rules, introduced with no citations to any authority, that henceforth the government must follow when executing warrants for digital information,” Kerr wrote in a post to the Volokh Conspiracy blog. “I can’t recall having read anything quite like it, although it does bring to mind Miranda v. Arizona.”

Four players whose names were seized, and who were not linked to the BALCO investigation, have been leaked to The New York Times. They are Alex Rodriguez, David Ortiz, Manny Ramirez and Sammie Sosa.

That privacy breach was not lost on Kozinski, who said those players suffered “harm as a result of the government’s seizure.”

In dissent, Judges Consuelo Callahan and Sandra Ikuta wrote that the majority was sidestepping its own precedent in which the circuit court had denied the suppression of child pornography evidence found on a computer during a search for the production of false identification cards pursuant to a valid warrant.

“There is no rule … that evidence turned up while officers are rightfully searching a location under properly issued warrant must be excluded simply because the evidence found may support charges for a related crime,” the dissenting judges wrote.

By David Kravets