Showing posts with label Public Policy. Show all posts
Showing posts with label Public Policy. Show all posts

Tuesday, July 21, 2015

CyberCalifornia Launch



As we have seen in recent news headlines, security breaches can bring entire organizations, states and countries to their knees. In today's connected world, making security a top priority is no longer a choice - it's a must. As public and private organizations continue to operate within this new era of the Internet, security will become critical to maintaining trust with the public, building company reputation, as well as safeguarding data, IP and critical infrastructure.

California is at the center of the digital revolution that is shaping the world around us. Already a national center of commercial cybersecurity activities, California is home to companies building the cybersecurity products and solutions that are securing commercial businesses, academic institutions and governmental organizations across the globe.

In an effort to help advance the goals and promote the accomplishments of the Governor's Cybersecurity Task Force, CyberTECH, among other state and local leaders, recently launch CyberCalifornia.



CyberCalifornia will organize public-private partnerships in cybersecurity, with the goals of facilitating research and innovation in cybersecurity, educating California businesses about cybersecurity needs and resources, and connecting California's robust workforce development system with the needs of California employers.

Led by its Board of Advisors, CyberCalifornia activities include:
Assisting in the organization of private sector advisory groups by vertical industry such as banking and finance, high technology, agriculture, etc.
Assisting in the development and promotion of cybersecurity career pathways
Partnering with local and regional economic development organizations to inform California's small business community about cybersecurity needs and solutions
Establishing connections between the cybersecurity and Internet of Things sectors through activities such as conferences and media events

To learn more about CyberCalifornia, please contact darin@cyberhivesandiego.org.



Darin Andersen, CEO, CyberUnited, Co-Chair, CyberTECH, Co-Chair, Economic Development Subcommittee, California Cybersecurity Task Force

"CyberCalifornia: Cybersecurity and IoT Gold Rush"

Recently, CyberTECH helped launch CyberCalifornia with other State and local leaders. The initiative is organized in conjunction with the Innovative Hub (iHub) Network, a program administered by the State Office of Economic Development and in partnership with Governor Brown's Cybersecurity Task Force.


Jerry Brown, Governor of California

CyberCalifornia will organize public-private partnerships in cybersecurity to better protect California's critical infrastructure, businesses and citizens from cyber threats, facilitate research and innovation in cybersecurity, educate California businesses about cybersecurity needs and resources, and connect California's robust workforce development system with the needs of California employers.

Center of Cybersecurity and Internet of Things Excellence (CCIoTE)
California is home to the personal computer, the firewall, anti-virus and many other cybersecurity products. Today, California companies are at the forefront of new technologies ushering in the Internet of Things (IoT), the term for the phenomenon where people and things are connected to the Internet, leveraging sensors and real time analytics and cloud technologies.

California's leadership role in advanced technology sectors including autonomous vehicles, biotechnology, precision in medicine and advanced manufacturing, will contribute to the State's continued excellence in cybersecurity and privacy. The powerful combination of cyber and the emergence of these innovative intensive sectors make California the perfect place to build secure next generation technologies.

California has a rapidly growing information technology industry cluster and offers the full spectrum of cybersecurity capabilities. Our Golden State has tremendous assets to keep our Country safe, advance innovation with security and privacy built in and be a beacon for other States in our Nation to follow.


Charles "Chuck" Brooks, Vice President, Government Relations and Marketing, Sutherland Global Services

"Adopting a Cooperative Global Cyber Security Framework to Mitigate Cyber Threats (Before it is too Late)"
The recent OPM cyber breach at the U.S. Government's Office of Personnel Management (OPM) provided a wakeup call to the seriousness and sophistication of the cyber security threat aimed at both the public and private sectors. The fact is that over 43% of companies had breaches last year (including mega companies such as Home Depot, JPMorgan, and Target). Moreover, the intrusion threats are not diminishing. For example, British Petroleum (BP) faces 50,000 attempts at cyber intrusion every day.

According to the think tank Center for Strategic and International Studies (CSIS), cyber related crime now costs the global economy about $445 billion every year. These cyber security breaches demonstrate that there is a continued need for protocols and enhanced collaboration between government and industry.

In 2014 code vulnerabilities such as Heartbleed, Shellshock, Wirelurker, POODLE and other open source repositories caused chaos and harm. The cyber security community responded to those vulnerabilities with "react and patch." Unfortunately, this means of response has been for the most part, a cosmetic or band aid approach.

The cyber security community's posture must change to one of wait and react to that of being proactive and holistic. It is not really a question of which policies, processes and technologies are ready and best, that will always be debatable. Being proactive means adopting a working Industry and Government Global Cyber Security Framework that would include measures for encryption, authentication, biometrics, analytics, automated network security, and a whole host of other topics related to cyber threats.

CONTINUE READING



LIFARS, Featured CyberTECH Member

LIFARS is a digital forensics and cybersecurity intelligence firm based in New York City. With its history of investigating cybersecurity breaches across a number of industries, LIFARS is uniquely positioned to help increase cybersecurity posture to protect organizations and individuals from real-life hackers and advanced persistent threat actors. By bringing in LIFARS, you can maximize your existing investment into the cybersecurity infrastructure and make sure that your future investments are strategically placed – delivering maximum protection while preserving the productivity of your employees. For these and other reasons, LIFARS was recently ranked as the #2 cybersecurity company in New York Metro area on the Cybersecurity 500 list.

LIFARS WEBSITE

In addition to providing robust security solutions based on best practices and personal hands-on experiences, LIFARS continuously explores the latest innovations in the cybersecurity field and always seeks to find what is shaping tomorrow's industry landscape. In a recent interview with Founder and CTO of LIFARS, Ondrej Krehel, and LIFARS' Digital Forensic Examiner, Paul Kubler, they discussed strategies and policies for cybersecurity in the world today, including common mistakes and how to make them right.

LIFARS INTERVIEW




NXT Robotics is a San Diego-based company that designs and builds service robots to support the increasing needs of the hospitality industry. NXT Robotics' service robot platforms are able to provide delivery, security and guest-related services to customers - all while maintaining a consistent and high degree of quality.

The company's founder, Jeff Debrosse has over 20 years of software engineering, cybersecurity R&D and enterprise product management and deployment experience. "This is an exciting time for NXT Robotics," said Jeff. "With access to the CyberTECH community and its resources, our success is further guaranteed."

The company will be providing CyberTECH's incubator and shared workspace offices, CyberHive and iHive, with its own Nixie. "Your team, tenants and guests will find Nixie to be amazingly pleasant to deal with - not to mention, very useful!" Jeff stated.

"NXT Robotics understands the importance of making cyber part of the foundation. We are thrilled to have NXT Robotics join CyberTECH as a member and look forward to working closely with Jeff and his team." said CyberTECH Co-Chair and Founder, Darin Andersen.

We are proud to recognize NXT Robotics as a featured CyberTECH Member for July 2015.



NXT ROBOTICS WEBSITE




Bird Rock Systems, Featured CyberTECH Member
Bird Rock Systems is a company that has been built on a foundation of exceptional customer service, technology and long-term partnership. Bird Rock Systems excels at deploying the latest enterprise class technologies including: security, routing, switching, traffic management, WAN acceleration, wireless, IP communications, storage area networking, performance computing and virtualization. Bird Rock typically begins a new client engagement by completing a network or security assessment. Their many loyal customers represent enterprise business, casino, university, Fortune 500 and government organizations requiring 'Best in Class' secure technical solutions.

BIRD ROCK SYSTEMS WEBSITE



iWebGate, Featured CyberTECH Member
Founded in Australia in 2004 with global corporate operations in North America, iWebGate has pioneered a new form of virtualization technology - the Virtualization of Network Services. iWebGate's LaunchPad allows organizations to properly and securely segment networks, connectivity and devices, eliminating the need for Firewalls and VPNs as primary security and connectivity solutions. By deploying the iWebGate Workspace Suite, organizations can then integrate security and business applications into the iWebGate LaunchPad transforming them from "enterprise friendly" products into "enterprise ready" solutions. The result is faster, more secure and reliable access to networks and network services.

IWEBGATE WEBSITE



San Diego Venture Group Selects Fhoosh as a 2015 Cool Company
Cybersecurity software development firm FHOOSH, Inc. has been chosen as a "Cool Company" by the San Diego Venture Group (SDVG) for a second year. One of 31 Cool Companies selected this year from over 160 applicants, FHOOSH continues to represent the leading edge of San Diego-area tech innovation.

FHOOSH helps corporations, institutions and government organizations protect and power valuable stored digital information with its cybersecurity platform and productivity software. FHOOSH bankLevel+ cybersecurity safeguards an organization's critical business and customer data from cyber threats by storing it in a state that is useless to hackers. It does this approximately five times faster than storing data unencrypted, with technology that breaks apart, disassociates, separately encrypts, and then disperses the data. The system also quickly notifies network administrators when unauthorized individuals try to access FHOOSH-protected databases, object stores and file systems. FHOOSH implements with existing infrastructure and allows corporate partners to dial in the security, big data/analytics and performance they need. With 15 patents pending, FHOOSH technology has been validated by the foremost cybersecurity response and assessment firm.

CONTINUE READING


Maggey Felix, Featured CyberTECH Advisor

Maggey Felix specializes in Marketing and Operations with 5+ years of experience in the technology and cybersecurity industry. Her passion for cybersecurity and cutting-edge technologies is shown through her dedication to helping companies better prepare, organize and market their solutions.

Over the past two years, Maggey has worked closely with the CyberTECH organization to support various marketing and operational activities. Her ongoing effort and commitment to CyberTECH makes Maggey an invaluable member of the community.

We are proud to recognize Maggey Felix as the featured CyberTECH Advisor for July 2015.


Julia Scholl, CyberTECH Director of Marketing and Operations

Julia Scholl is a strategic and forward-thinking public relations and marketing professional with over five years of experience working with non-profit and startup organizations. A capable self-starter with excellent organizational and communication skills, Julia is passionate about building and fostering lasting relationships within the CyberTECH community.

As Marketing and Operations Director, Julia will assist with daily operations, provide membership support as well as ongoing support with events, programs, and all other CyberTECH initiatives.

We are excited to welcome Julia to CyberTECH. Please feel free to contact Julia directly at julia@cyberhivesandiego.org.



Jessica Herrmann, CyberTECH Events Coordinator

Jessica Herrmann has over 20 years of experience applying key leadership, communication and problem solving skills within the hospitality industry. As Catering and Events Manager, Jessica has worked with a number of organizations to develop, manage and execute top quality events.

Jessica recently joined CyberTECH as Events Coordinator where she will help with the planning, organization, preparation and execution of CyberTECH events.

Please join us in formally welcoming Jessica to the CyberTECH community.

Upcoming Events
Internet of Things (IoT) Meetup - September 17, 2015

SAM Fest (Startups + Art + Music) - September 23-24, 2015

IoT Startup Table Breakfast - October 13, 2015









Check out their new brand video and you’ll see why Webpass isn’t just another ISP. They're leaders and innovators on a mission to change the way people think about the Internet. You can contact them at 1-800-Webpass!



Step Inside Webpass!
CyberTECH 2015 Newsletter Sponsor
Webpass, a leading Internet service provider in the San Diego area is now delivering residential Internet connections at 100, 200, or 500 Mbps and business Internet connections from 10-1000 Mbps. There has never been a better time to cut the cable and switch to Webpass for your Internet needs! As the owner and operator of its Ethernet network, Webpass promises customers a simple urban Internet experience. They distinguish themselves from the competition through the simplicity of set-up, absence of contracts and personable customer service.

Sign up today and instantly browse the Internet without modems, contracts or gimmicks.

Webpass
1360 5th Avenue
San Diego, CA 92101
1-800-Webpass 


Facebook



Twitter


Website


LinkedIn


Email


Instagram


Get Involved!

A key CyberTECH operating principle is collaboration. We are always looking to partner with individuals and organizations looking to get involved in various cyber and IoT initiatives throughout the region and across the globe. Opportunitites include event chair, volunteer, champion, program chair and more. For additional information on how you can support CyberTECH, please contact Julia Scholl.



Join the CyberTECH Meetup Groups
CyberTECH Cybersecurity Meetup

CyberTECH Internet of Things Meetup



Facebook


Twitter


Website


Email


LinkedIn

Our mailing address is:
1855 1st Ave. Suite 103, San Diego, CA 92101 

Wednesday, June 24, 2015

State Department database crash strands hundreds at the border

Outage caused by corrupted data, which was mirrored to backup—making it useless.


by Sean Gallagher - Jun 23, 2015 11:14am PDT  Ars Technica

Thanks to the failure of a system used to collect and transmit fingerprints and photos, the US State Department has been unable to issue visas to travelers or guest workers for the past two weeks, The New York Times reports. While some of the systems related to visa processing have been restored, biometric information is still not being processed, leaving many travelers from outside the US and hundreds of agricultural "guest workers" stranded.

State Department officials told the Times that the issue was related to a hardware failure. In an e-mail to the paper, Consular Affairs spokesperson Ashley Garrigus said that there had been data corruption caused by a hardware failure, which had been replicated to the biometric database's backup system. “While switching to the backup system," Garrigus wrote, "we discovered that the data was damaged and unusable. We deeply regret the inconvenience to travelers and recognize the hardship to those waiting for visas, and in some cases, their family members or employers in the United States.”

The State Department normally processes about 50,000 visa applications a day, according to astatement on the outage on the agency's website. But that number surges seasonally as employers bring in laborers (mostly from Mexico) to harvest crops. On top of that, the overall number of visas annually has grown. Earlier this year, the State Department put out a "sources sought" call for a new facial recognition service because of the huge growth in visa requests, especially those driven by the H2-A and H2-B visa programs. "At present, the Visa and Passport face galleries contain over 275 million images combined, which are among the largest face recognition datasets in the world and growing annually at an anticipated rate of 23 million images per year," the State Department's procurement officer wrote in the procurement announcement . "Every passport and visa application requires a face recognition search of the legacy and watch-list galleries."

The guest worker visa program itself is a tangled web of systems. First, employers apply through the Department of Labor with candidate workers. Then the US Citizenship and Immigration Service at the Department of Homeland Security screens the individuals petitioning through the employer for visas. USCIS next sends approved petitions to the State Department’s Kentucky Consular Center to be entered into the visa database. And that in turn allows consular and embassy offices outside the US to see that the individuals are authorized to apply for a visa, thus submitting biometric data back to the Kentucky Consular Center's database to check against watch lists and other image and fingerprint data that might catch attempted visa fraud.

Because of the system failure, the State Department has delayed visas for over 1,500 guest agricultural workers in Mexico. "Last week, nearly 1,250 temporary or seasonal workers who had been issued visas in the past were issued new visas in Mexico," a State Department official said in a statement on the outage. "We have issued more than 3,000 visas globally for urgent and humanitarian travel."

According to a Reuters report, the outage is having real economic impact—especially in Washington, where cherry growers have been unable to get workers out to pick before fruit becomes unsellable. The blueberry crop may be affected next, as workers usually stay to harvest them after cherries. Washington Farm Labor Association Director Dan Fazio told Reuters, "Our farmers are all in for the guest worker program, but the government isn’t. We have a lot of cherries that are ruined and it looks like a lot of blueberries are going to be lost.”

Monday, June 22, 2015

Supreme Court declares warrantless searches of hotel registries illegal


Data included credit card, home address, driver's license, and vehicle license.


by David Kravets - Jun 22, 2015 11:00am PDT  Ars Technica


Todd Lappin

The Supreme Court gave a big boost to privacy Monday when it ruled that hotels and motels could refuse law enforcement demands to search their registries without a subpoena or warrant. The justices were reviewing a challenge to a Los Angeles ordinance requiring hotels to provide information to law enforcement—including guests' credit card number, home address, driver's license details, and vehicle license number—at a moment's notice. Similar ordinances exist in about a hundred other cities stretching from Atlanta to Seattle.

Los Angeles claimed the ordinance (PDF) was needed to battle gambling, prostitution, and even terrorism, and that guests would be less likely to use hotels and motels for illegal purposes if they knew police could access their information at will.

Justice Sonia Sotomayor, writing for the 5-4 majority, ruled (PDF) that the Los Angeles ordinance violated the Fourth Amendment and is an illegal "pretext to harass hotel operators and their guests."

"Even if a hotel has been searched 10 times a day, every day, for three months, without any violation being found, the operator can only refuse to comply with an officer’s demand to turnover the registry at his or her own peril," Sotomayor wrote.

Enlarge

The hotel operators who brought the challenge faced six months in jail and a $1,000 fine for refusing to comply.

But the decision doesn't mean that hotel operators are forbidden from divulging the information upon demand if they choose to do so, the majority ruled.

"To be clear, we hold only that a hotel owner must be afforded an opportunity to have a neutral decision maker review an officer's demand to search the registry before he or she faces penalties for failing to comply. Actual review need only occur in those rare instances where a hotel operator objects to turning over the registry," Sotomayor wrote.

Justice Antonin Scalia, writing for the dissent, said that "The law is constitutional in most, if not all, of its applications." He scoffed at Sotomayor saying the authorities should get a subpoena or warrant to acquire such information, which Los Angeles requires hotels to keep for at least 90 days. He said Monday's majority decision would hinder sex trafficking and human smuggling investigations, too.

"This proposal is equal parts 1984 and Alice in Wonderland," he wrote.

Sotomayor was joined by Justices Anthony Kennedy, Ruth Bader Ginsburg, Stephen Breyer, and Elena Kagan.

The case is the third high-profile Fourth Amendment decision the court has issued in three years. In 2012, the justices ruled that authorities generally need search warrants when they affix GPS devices to vehicles. And last year, the justices ruled that the authorities need warrants to peek into the mobile phones of suspects they arrest.

In the case decided Monday, Los Angeles hoteliers argued that the law violated their rights, and the San Francisco-based 9th US Circuit Court of Appeals agreed in 2013. The city of Los Angeles appealed, arguing (PDF) that the ordinance helps both local and federal authorities in investigations of all types. The case's briefs can be viewed here.

Friday, June 19, 2015

CETF 2015 Annual Survey of California Digital Divide


www.cetfund.org



The California Emerging Technology Fund (CETF) is pleased to share with you the results of the
2015 Annual Survey on broadband adoption in California that was released yesterday. The Annual Survey is sponsored by CETF and conducted by the Field Research Corporation in 6 languages with a sample size in excess of 1,600 randomly-selected households (50% by cell phone and a margin of error + 2.6 percentage points at the 95% confidence level). The results show that progress is being made in closing the Digital Divide with 79% of all California households now having high-speed connections at home to the Internet (8% by smart phone only), but there is still much work to be done because unacceptable percentages of disadvantaged populations remain offline—35% of low-income households (below $20,000 annual income); 30% of Latino families (37% Spanish-speaking); and 41% of people with disabilities. It is important to keep in mind that the Digital Divide is just another manifestation of the Opportunity Divide and Economic Divide, and that those who are stuck on the wrong side of the Digital Divide—urban low-income neighborhoods and remote rural communities—are faced with a multitude of challenges in daily life that CETF calls the “wall of poverty” that must be tackled with strategic interventions to improve education coupled with workforce preparation and economic development.

The Annual Survey information is very timely as the Federal Communications Commission takes up tomorrow the issue of a Broadband Lifeline Program, State policymakers continue to explore how best to tackle poverty, and local governments continue to struggle to balance budgets and generate jobs. The data underscores the need to incorporate Digital Inclusion into all major initiatives to promote economic prosperity and quality of life in California.

Please feel free to distribute the results of the 2015 Annual Survey, post it on your own website and/or link to the CETF website http://www.cetfund.org/progress/annualsurvey, and reference the data as you find useful. We look forward to continuing to work together to close the Digital Divide in California. Thank you for your commitment and leadership.

Sunne Wright McPeak
President and CEO
California Emerging Technology Fund


Monday, June 15, 2015

ITIF: Beyond the USA Freedom Act: How U.S. Surveillance Still Subverts U.S. Competitiveness


Daniel Castro and Alan McQuinn
June 9, 2015  ITIF

A failure to sufficiently reform U.S. surveillance policies is hurting U.S. technology companies, costing American jobs, and weakening the U.S. trade balance.

View Report


Almost two years ago, ITIF described how revelations about pervasive digital surveillance by the U.S. intelligence community could severely harm the competitiveness of the United States if foreign customers turned away from U.S.-made technology and services. Since then, U.S. policymakers have failed to take sufficient action to address these surveillance concerns; in some cases, they have even fanned the flames of discontent by championing weak information security practices. In addition, other countries have used anger over U.S. government surveillance as a cover for implementing a new wave of protectionist policies specifically targeting information technology. The combined result is a set of policies both at home and abroad that sacrifices robust competitiveness of the U.S. tech sector for vague and unconvincing promises of improved national security.

ITIF estimated in 2013 that even a modest drop in the expected foreign market share for cloud computing stemming from concerns about U.S. surveillance could cost the United States between $21.5 billion and $35 billion by 2016. Since then, it has become clear that the U.S. tech industry as a whole, not just the cloud computing sector, has under-performed as a result of the Snowden revelations. Therefore, the economic impact of U.S. surveillance practices will likely far exceed ITIF’s initial $35 billion estimate. This report catalogues a wide range of specific examples of the economic harm that has been done to U.S. businesses. In short, foreign customers are shunning U.S. companies. The policy implication of this is clear: Now that Congress has reformed how the National Security Agency (NSA) collects bulk domestic phone records and allowed private firms—rather than the government—to collect and store approved data, it is time to address other controversial digital surveillance activities by the U.S. intelligence community.

The U.S. government’s failure to reform many of the NSA’s surveillance programs has damaged the competitiveness of the U.S. tech sector and cost it a portion of the global market share. This includes programs such as PRISM—the controversial program authorized by the FISA Amendments Act, which allows for warrantless access to private-user data on popular online services both in the United States and abroad—and Bullrun—the NSA’s program to undermine encryption standards both at home and abroad. Foreign companies have seized on these controversial policies to convince their customers that keeping data at home is safer than sending it abroad, and foreign governments have pointed to U.S. surveillance as justification for protectionist policies that require data to be kept within their national borders. In the most extreme cases, such as in China, foreign governments are using fear of digital surveillance to force companies to surrender valuable intellectual property, such as source code.

In the short term, U.S. companies lose out on contracts, and over the long term, other countries create protectionist policies that lock U.S. businesses out of foreign markets. This not only hurts U.S. technology companies, but costs American jobs and weakens the U.S. trade balance. To reverse this trend, ITIF recommends that policymakers:
  • Increase transparency about U.S. surveillance activities both at home and abroad.
  • Strengthen information security by opposing any government efforts to introduce backdoors in software or weaken encryption.
  • Strengthen U.S. mutual legal assistance treaties (MLATs).
  • Work to establish international legal standards for government access to data.
  • Complete trade agreements like the Trans Pacific Partnership that ban digital protectionism, and pressure nations that seek to erect protectionist barriers to abandon those efforts.

Thursday, June 11, 2015

San Francisco votes to expand computer science education across all grades

Donations from Salesforce charity will fund the new program from pre-school onward.

This is the view from George Washington High School, in San Francisco.
Within a few years, every single student in the San Francisco Unified School District will be studying computer science, at all grade levels.
The city’s Board of Education unanimously approved the measure during its weekly meeting on Tuesday evening.
"Information technology is now the fastest growing job sector in San Francisco, but too few students currently have access to learn the Computer Science skills that are crucial for such careers," Board President Emily Murase said in a statementon Wednesday. "We are proud to be at the forefront of creating a curriculum that will build on the knowledge and skills students will need starting as early as preschool."
According to the district, computer science classes are relatively rare across the United States.
"Currently, no national, state, or local standards exist for Computer Science and the academic research in Computer Science education is quite limited," the board wrote. "As such, a cohesive progression of Computer Science knowledge and skills does not yet exist."
The effort is going to be largely funded by the Salesforce Foundation, a charitable wing of the company.
At present, only a "few hundred" San Francisco public school students took the Advanced Placement Computer Science exam in Spring 2014. Of those, just 22 percent were women, and three percent were African American, Latino or Native American.
How exactly will San Francisco’s preschool set get in on the action? SFUSD says they "will most likely be using blocks to build robots, to introduce the concepts of procedural thinking, cause and effect, decomposition of complex tasks, pattern recognition as well as the ability to notice similarities or common differences, abstraction and algorithm design and the ability to develop a step-by-step strategy for solving a problem."
According to the Bureau of Labor Statistics, "employment of computer and information research scientists is projected to grow 15 percent from 2012 to 2022, faster than the average for all occupations."
The median salary nationwide in the industry is just over $102,000—likely higher in the competitive and increasingly-expensive San Francisco Bay Area.

Thursday, May 14, 2015

US House passes Bill to end domestic NSA bulk data collection


Summary:American residents could soon be exempt from the NSA's dragnet, unless surveillance is approved by the secretive FISA court, with the USA Freedom Act passing the US House of Representatives and heading to the Senate.



By Chris Duckett | May 14, 2015 -- 07:04 GMT (00:04 PDT)
ZDNet

The US House of Representatives has voted 338 for and 88 against ending the NSA's dragnet collection of telephone, email, and other online data from millions of Americans, a controversial program that was revealed in 2013 by former security contractor Edward Snowden.

The USA Freedom Act is seen as a big win for privacy and civil rights advocates. The White House backs the reforms, saying the Bill protects privacy while preserving essential national security authorities.

After passing the House, the measure is now heading for a vote in the Senate, where the clash between reformists and supporters of the intelligence community, coming within the context of warnings on the increasing digital reach of the Islamic State terror group, transcends party lines.

Both liberals and staunch conservatives, often at odds on most major legislation, have united in opposition against domestic spying by the National Security Agency.

The Bill, which focuses on people in the US and not overseas, would amend controversial sections of the USA Patriot Act, which was passed in the wake of the September 11, 2001, attacks and will expire on June 1.

The reforms scrap the bulk collection detailed in Section 215 of the Patriot Act, replacing it with a targeted program that allows intelligence agencies to collect data from specific individuals or groups, but only with prior approval of the secret national security FISA court.


Under Section 215, the government stored the acquired data, but the new reforms would compel telcos and other data companies to keep the information to be accessible to intelligence agencies only through court order.The data dragnet was operating in complete secrecy after 2001, and has been under the supervision of the FISA court since 2006. It was consistently renewed by the administrations of George W Bush and Barack Obama.

"Today's vote was a major win for surveillance reform and a major rebuke for those who want to reauthorise the Patriot Act without change," said Center for Democracy & Technology president Nuala O'Connor.

Passage through the House was welcomed by Mozilla, whose head of public policy Chris Riley called for the Senate to swiftly pass the legislation.

"This legislation significantly curtails bulk collection under the Patriot Act and other authorities, and puts us on a path to a more private and secure internet," Riley said.

"We are staunchly opposed to any short- or long-term reauthorisation of these sections of the Patriot Act absent meaningful reforms. Now is not the time to delay on these much-needed reforms."

The Electronic Frontier Foundation (EFF) said US business is being hurt by the NSA's actions, and it hopes the Senate will add amendments to strengthen the Bill.

"The legislation is a good start to shutting backdoors," the EFF said. "The time to fix the backdoor problem is now."

The vote came just a week after a US appeals court ruled that the bulk data collection goes far beyond what congress authorised.

"The text of [section 215] cannot bear the weight the government asks us to assign to it, and that it does not authorize the telephone metadata program," wrote judge Gerard E Lynch last week.

Earlier this month, the French lower house approved legislation allowing authorities to spy on suspected terrorists without prior authorisation from a judge.

The new law, to go before the French Senate later this month, allows authorities to spy on the digital and mobile communications of anyone linked to a "terrorist" inquiry without judicial authorisation, and forces internet service providers and phone companies to give up data upon request.

Intelligence services will have the right to place cameras and recording devices in private dwellings and install keylogging devices.

As the US restricts some of its data surveillance schemes, Australia is in the midst of setting up its own data-retention scheme.

In this week's Australian Budget, AU$131 million was allocated by the government for the creation and maintenance of systems to store all Australians' telecommunications data for two years for warrantless access by law enforcement.

However, the money from the government is expected to cover only between one third and half of the cost to implement the scheme.

The Internet Society of Australia CEO Laurie Patton said the government should guarantee to top up the funding if it is inadequate for all ISPs.

"The government's original cost estimate was not based on widespread industry consultation, and the Internet Society is concerned that the costs have been significantly underestimated, especially in respect of small to medium-sized ISPs that don't have the resources to undertake the work in-house, and therefore will be required to pay for external assistance," he said in a statement.

Tuesday, May 12, 2015

BBC: Staff-tracking app faces legal scrutiny in US

BBC

The woman is alleging that an app which tracks movements 24/7 invaded her privacy
A US sales executive is suing her employer for invasion of privacy, alleging that she was fired after deleting an app which tracked her movements.
The action alleges that Intermex, a firm which arranges money transfers, tracked employees even when off-duty.

Myrna Arias alleges that she was "scolded" for removing the app and fired a few weeks later.

The company has not responded to the allegations.

According to court documents published by website Ars Technica, employees were instructed to download the app, called Xora, to their phones in April 2014.

Xora is described on its website as a workplace management app which allows companies to "remotely manage" their workers by keeping track of their hours and other aspects of their job.

Xora's website says that the app uses GPS to allow bosses "to see the location of every mobile worker on a Google Map".

According to the lawsuit, Ms Arias's manager "admitted that employees would be monitored while off-duty and bragged that he knew how fast she was driving at specific moments ever since she had installed the app on her phone".

"He confirmed that she was required to keep her phone's power on 24/7 to answer phone calls from clients," reads the court document.

It goes on to detail that Ms Arias had "no objection" to being monitored at work but felt that monitoring her location during non-work hours was an invasion of her privacy.

She likened the app to a prisoner's ankle bracelet.
Tracking employees
Her boss "scolded the plaintiff when she de-installed the app in late April in order to protect her privacy", reads the court document.

She was fired on 5 May.

Ms Arias is seeking damages for lost earnings in excess of $500,000.

Mark Weston, a partner at law firm Matthew Arnold & Baldwin, tod the BBC that an employer "would not be allowed to track an employee without the consent of that employee".

Clauses that allow for tracking apps would have to be built into contracts, he said.

As for the legality of firing an employee for refusing to use such an app, Mr Weston said: "In the US, things may be looser because many employees there are employees 'at will'. Accordingly, employers have far greater flexibility than in Europe to dismiss an employee who is not playing ball."

Monday, May 11, 2015

AOL: 2.1 million people still subscribe to dial-up Internet


BY BRANDON RUSSELL | MAY 9, 2015 TechnoBuffalo



AOL on Friday revealed that 2.1 million people in the U.S. still subscribe to its dial-up service, an astonishing and surprising number in the year 2015. A large majority of Americans have ditched the comatose service as faster broadband has become more accessible. But, either through ignorance, stubbornness, or sheer unavailability in certain areas, people are still clinging to the good old days of the early Internet.

Back in 2010, AOL revealed it had about 4.6 million dial-up users, so usage is on the decline, but it’s a slow, slow process, not unlike the service these people still get.

CNN Money notes that over 70-percent of Americans are connected through faster broadband, with an average speed of 11.4 Mbps, which is lighting quick compared to AOL’s 56k speeds. Compared to what the Internet looked like 20 years ago, 56k connections probably wouldn’t even be able to load a modern day website, much less stream a video on YouTube or Netflix.

Without fast Internet, online tech journalism just wouldn’t exist in the way it does today. And there would be no Twitch or Spotify. It would be a cruel, apocalyptic world.

The most shocking thing of all? Customers are paying AOL $20 a month for dial-up access, which means the company is still making a killing each year from these subscriptions. If you or someone you know is still using dial-up, it might be time for an intervention.

I get it: not everyone can afford broadband Internet, and there’s a minuscule chance they don’t have access to the faster speeds in their remote part of the wilderness. But 2.1 million is a hefty figure, and so long as people subscribe, AOL will continue to be an enduring time capsule of despair.

Wednesday, May 6, 2015

Warrants not required for police to get your cell phone cell-site records

Mobile callers' cell-tower history is fair game for cops—probable cause unnecessary.

by David Kravets - May 5, 2015 3:25pm PDT  ars technica


Michael Dorausch

A federal appeals court ruled Tuesday that the government does not need a warrant to obtain a suspect's cell-site location data records.

The 9-2 decision (PDF) by the 11th US Circuit Court of Appeals said that the records of towers that a mobile phone uses to make calls are considered "business records" maintained by a "third party" and are not protected by the Fourth Amendment. That means the government may obtain these records if it believes they are relevant to an investigation.

The case concerns a Florida man, Quartavious Davis, who was sentenced to life in prison for a string of robberies in a prosecution that was built with the suspect's cell site records.

...Davis can assert neither ownership nor possession of the third-party’s business records he sought to suppress. Instead, those cell tower records were created by MetroPCS, stored on its own premises, and subject to its control. Cell tower location records do not contain private communications of the subscriber. This type of non-content evidence, lawfully created by a third-party telephone company for legitimate business purposes, does not belong to Davis, even if it concerns him. Like the security camera surveillance images introduced into evidence at his trial, MetroPCS’s cell tower records were not Davis’s to withhold. Those surveillance camera images show Davis’s location at the precise location of the robbery, which is far more than MetroPCS’s cell tower location records show.

The majority ruling by Judge Frank Hull is a big boost to the government. Warrantless cell-site tracking has become among the government's preferred methods of electronically tracking suspects in the wake of a 2012 Supreme Court ruling that the authorities generally needed a warrant to attach GPS devices onto vehicles and track their every move.

Meanwhile, the Atlanta-based appeals court had ruled the opposite way last year by a vote of 2-1. But the 11th Circuit revisited the case with a larger panel of 11 judges at the government's request. The outcome brings the number of appellate courts that have ruled for the authorities to four. There are 13 appeals courts nationwide. None have gone the other way. Without conflicting rulings, the US Supreme Court might not take up the issue any time soon.

In all the decisions, the appellate courts cited analog-aged 1979 US Supreme Court precedent, known as Smith v. Maryland, that allows the government's telephone metadata snooping program that Edward Snowden exposed.

Orin Kerr, a former federal prosecutor and a Fourth Amendment expert, said he agreed with the court's ruling—to an extent.

Granted, I want there to be a circuit split to get the case up to the Supremes. That leaves me in an odd position: Although I think a judge should follow Smith, I also kinda want a lower court to not follow precedent in order to tee up the issue for the Supreme Court.
The 11th Circuit originally decided in June that a warrant was required because the public had a reasonable expectation of privacy in their public movements.

"Thus, the exposure of the cell site location information can convert what would otherwise be a private event into a public one. When one’s whereabouts are not public, then one may have a reasonable expectation of privacy in those whereabouts," the court ruled. (PDF)

But what a different a larger panel of judges makes when it comes to deciding the constitutionality of so-called § 2703(d) orders:

The stored telephone records produced in this case, and in many other criminal cases, serve compelling governmental interests. Historical cell tower location records are routinely used to investigate the full gamut of state and federal crimes, including child abductions, bombings, kidnappings, murders, robberies, sex offenses, and terrorism-related offenses.

Such evidence is particularly valuable during the early stages of an investigation, when the police lack probable cause and are confronted with multiple suspects. In such cases, § 2703(d) orders—like other forms of compulsory process not subject to the search warrant procedure—help to build probable cause against the guilty, deflect suspicion from the innocent, aid in the search for truth, and judiciously allocate scarce investigative resources.

For the two-judge dissent, Judge Beverly Martin wrote:

"While I admire the majority’s attempt to cabin its holding to the technology of five years ago, its assurances in this regard seem naïve in practice. As a result of today’s decision, I have little doubt that all government requests for cell site location data will be approved, no matter how specific or invasive the technology."
The MetroPCS records at issue in the case were from August 1, 2010 to October 6, 2010. The defendant, Davis, made roughly 86 calls a day.

The data included the telephone numbers of calls made by and to Davis' mobile phone; whether a call was outgoing or incoming; the date, time and duration of calls. The key dispute in this case concerned other data that was turned over. That included the number assigned to the cell tower that wirelessly connected the calls from and to Davis, and the sector number associated with the tower.

Davis' attorney, Nathan Freed Wessler of the American Civil Liberties Union, said that the "dissenting judges recognized outdated legal doctrines from the analog age should not be mechanically extended to undermine our privacy rights in the voluminous digital records that come with modern life."



David Kravets / The senior editor for Ars Technica. Founder of TYDN fake news site. Technologist. Political scientist. Humorist. Dad of two boys. Been doing journalism for so long I remember manual typewriters with real paper.

Thursday, April 23, 2015

Mountain of Electrical Waste Reaches New Peak


APR 19, 2015 09:55 AM ET // BY AFP  Discovery


Less than one-sixth of all e-waste is properly recycled.
A record amount of electrical and electronic waste hit the rubbish tips in 2014, with the biggest per-capita tallies in countries that pride themselves on environmental consciousness, a report said Sunday.

Last year, 41.8 million tons of so-called e-waste -- mostly fridges, washing machines and other domestic appliances at the end of their life -- was dumped, it said.


Researchers at the Massachusetts Institute of Technology have figured out how to track trash. They are doing this to get a better sense of people's disposal habits, which they hope will improve recycling efforts.

That's the equivalent of 1.15 million heavy trucks, forming a line 23,000 kilometers (14,300 miles) long, according to the report, compiled by the United Nations University, the UN's educational and research branch.

Less than one-sixth of all e-waste was properly recycled, it said.

In 2013, the e-waste total was 39.8 million tons -- and on present trends, the 50-million-ton mark could be reached in 2018.

Topping the list for per-capita waste last year was Norway, with 28.4 kilograms (62.5 pounds) per inhabitant.

It was followed by Switzerland (26.3 kg per capita), Iceland (26.1 kilos), Denmark (24.0 kilos), Britain (23.5 kilos), the Netherlands (23.4 kilos), Sweden (22.3 kilos), France (22.2 kilos) and the United States and Austria (22.1 kilos per person each).

The region with the lowest amount of e-waste per inhabitant was Africa, with 1.7 kilos per person. It generated a total of 1.9 million tons of waste.

In volume terms, the most waste was generated in the United States and China, which together accounted for 32 percent of the world's total, followed by Japan, Germany and India.

Waste that could have been recovered and recycled was worth $52 billion (48.5 billion euros), including 300 tons of gold -- equal to 11 percent of the world's gold production in 2013.

But it also included 2.2 million tons of harmful lead compounds, as well as mercury, cadmium and chromium, and 4,400 tons of ozone-gobbling chlorofluorocarbon (CFC) gases.

"Worldwide, e-waste constitutes a valuable 'urban mine' -- a large potential reservoir of recyclable materials," UN Under Secretary-General David Malone said.

"At the same time, the hazardous content of e-waste constitutes a 'toxic mine' that must be managed with extreme care."

Almost 60 percent of e-waste by weight came from large and small kitchen, bathroom and laundry appliances.

Seven percent was generated by thrown-out mobile phones, calculators, personal computers and printers.

Tuesday, April 21, 2015

The numbers behind the broadband ‘homework gap’

APRIL 20, 2015

BY JOHN B. HORRIGAN Pew Research Center

Since the dawn of the internet, there’s been much talk about the digital divide – the gap between those with access to the internet and those without. But what about the “homework gap”?

In recent years, policymakers and advocates have pushed to make it easier for low-income households with school-age children to have broadband, arguing that low-income students are at a disadvantage without online access in order to do school work these days. Later this year, the Federal Communications Commission is expected to begin a rule-making process to overhaul the Lifeline Program, an initiative that subsidizes telephone subscriptions for low-income households, so that it would also cover broadband.

In 2013, the Lifeline program provided $1.8 billion worth of telephone subsidies for qualified low-income people. The FCC has not yet provided estimates of how much it would cost to add broadband subsidies to the program, but the debate will undoubtedly focus on overall program costs and how many households would be covered.



How big is the homework gap? A new Pew Research Center analysis finds most American homes with school-age children do have broadband access – about 82.5% (about 9 percentage points higher than average for all households). With approximately 29 million households in America having children between the ages of 6 and 17, according to Pew Research Center analysis of U.S. Census Bureau’s American Community Survey data, this means that some 5 million households with school-age children do not have high-speed internet service at home. Low-income households – and especially black and Hispanic ones – make up a disproportionate share of that 5 million.

Pew Research analysis of the Census data finds that the lowest-income households have the lowest home broadband subscription rates. Roughly one-third (31.4%) of households whose incomes fall below $50,000 and with children ages 6 to 17 do not have a high-speed internet connection at home. This low-income group makes up about 40% of all families with school-age children in the United States, according to the bureau’s American Community Survey. (The survey asked questions on home internet use for the first time in 2013.)

By comparison, only 8.4% of households with annual incomes over $50,000 lack a broadband internet connection at home. In other words, low-income homes with children are four times more likely to be without broadband than their middle or upper-income counterparts.

The other notable difference in home broadband adoption pertains to the race and ethnicity of the householder. Lower-income black and Hispanic households with children trail comparable white households with children by about 10 percentage points.

Asian Americans, by contrast, outperform the other groups in broadband adoption for households with children, regardless of income level. A likely explanation is that Asian Americans have the highest educational levels of any racial group in the United States, which is a characteristic strongly associated with having broadband at home.

Note: The author is currently a senior researcher at Pew Research Center. Prior to joining the center, he served on the Federal Communications Commission team that developed the National Broadband Plan.

Thursday, April 16, 2015

BBC: High price of '.sucks' to be investigated


13 April 2015 BBC


Vox Populi says its prices for ".sucks" website names are "well within the rules"

The authority that decides which letters a web address is allowed to finish with says it is concerned at the high charges for the new ".sucks" name.

The Internet Corporation for Assigned Names and Number (Icann) has asked the US and Canadian trade authorities to investigate Vox Populi, which secured the rights to sell the name.

The company denies any wrongdoing.

Many companies and celebrities have bought their name with controversial suffixes such as ".porn" or ".xxx".

Predatory selling

The last part of a web address that follows the final dot, such as ".com", ".org", and ".net", is referred to as a generic top level domain (gTLD).

Icann relaxed the rules governing gTLDs in 2012, and the latest to go up for sale is ".sucks".

Many companies and celebrities buy their brand or name with various gTLDs, to avoid any confusion with their official website addresses or to stop others buying them and posting negative content.

Taylorswift.xxx has been reserved but not used, to prevent others from buying it

For example, singer Taylor Swift bought up taylorswift.xxx to prevent anyone else from using it.

Specialist online website Domain Incite reports that actor "Kevin Spacey, Microsoft, Google and Apple have already bought up '.sucks' sites in a bid to protect their reputations".

This practice is known as "defensive registering".

Icann granted Vox Populi permission to sell the ".sucks" names but is now concerned at the price levels the Canadian company has set.

Kevin Murphy, from Domain Incite, told the BBC two key elements of the way Vox Populi was handling the sale were causing concern.

"They are charging a $2,000 'sunrise' premium to those wishing to register '.sucks' addresses early, before the addresses go on sale to the general public [next month]," he said.

"Also they are using a list of words or names that have been defensively registered in the past, for which they are charging the top amount."

Mr Murphy said the company was working from a list of keywords that had been part of web addresses bought up early on in similar new domain web address sales and using that to decide which ".sucks" addresses to charge more for.

The base fee for any ".sucks" web address is $199 a year

New gTLDs such as ".rocks" or ".forsale" typically sell for between $5 (£3.42) and $20 a year.

Beyond jurisdiction

But Murphy said: "They [Vox Populi] are charging a much bigger amount that you'd expect.

"They were considering a fee of $25,000 at one point when we spoke to them.

"I think they are charging as much as they can get away with.

"It [Vox Populi] justified the $2,000 premium price tag [for certain '.sucks' addresses] as being 'a reasonable part of a company's PR budget'.

"It appears they are basing prices on what firms can afford not on the product services they are providing."

In a strongly worded letter to Icann, the authority's own advisory body, the Intellectual Property Constituency (IPC), demanded a "halt" to Vox Populi's "illicit", "predatory" and "coercive" selling scheme.

But even though Icann approved the ".sucks" domain name sale and issued the licence to sell the related website addresses, it appears not to have jurisdiction over how they are sold.

There is no evidence that Vox Populi has done anything wrong, and the company told Domain Incite its pricing and policies were "well within the rules".

Icann has referred Vox Populi to the two bodies it believes may have the regulatory authority to investigate the company's practices: the Federal Trade Commission in the United States and the Canadian Office of Consumer Affairs, as the company is registered in Canada.

But unless the company has broken the law, it is not clear what powers Icann has over Vox Populi's handing of the sale of ".sucks".