Showing posts with label ICT Regulation. Show all posts
Showing posts with label ICT Regulation. Show all posts

Monday, June 22, 2015

Supreme Court declares warrantless searches of hotel registries illegal


Data included credit card, home address, driver's license, and vehicle license.


by David Kravets - Jun 22, 2015 11:00am PDT  Ars Technica


Todd Lappin

The Supreme Court gave a big boost to privacy Monday when it ruled that hotels and motels could refuse law enforcement demands to search their registries without a subpoena or warrant. The justices were reviewing a challenge to a Los Angeles ordinance requiring hotels to provide information to law enforcement—including guests' credit card number, home address, driver's license details, and vehicle license number—at a moment's notice. Similar ordinances exist in about a hundred other cities stretching from Atlanta to Seattle.

Los Angeles claimed the ordinance (PDF) was needed to battle gambling, prostitution, and even terrorism, and that guests would be less likely to use hotels and motels for illegal purposes if they knew police could access their information at will.

Justice Sonia Sotomayor, writing for the 5-4 majority, ruled (PDF) that the Los Angeles ordinance violated the Fourth Amendment and is an illegal "pretext to harass hotel operators and their guests."

"Even if a hotel has been searched 10 times a day, every day, for three months, without any violation being found, the operator can only refuse to comply with an officer’s demand to turnover the registry at his or her own peril," Sotomayor wrote.

Enlarge

The hotel operators who brought the challenge faced six months in jail and a $1,000 fine for refusing to comply.

But the decision doesn't mean that hotel operators are forbidden from divulging the information upon demand if they choose to do so, the majority ruled.

"To be clear, we hold only that a hotel owner must be afforded an opportunity to have a neutral decision maker review an officer's demand to search the registry before he or she faces penalties for failing to comply. Actual review need only occur in those rare instances where a hotel operator objects to turning over the registry," Sotomayor wrote.

Justice Antonin Scalia, writing for the dissent, said that "The law is constitutional in most, if not all, of its applications." He scoffed at Sotomayor saying the authorities should get a subpoena or warrant to acquire such information, which Los Angeles requires hotels to keep for at least 90 days. He said Monday's majority decision would hinder sex trafficking and human smuggling investigations, too.

"This proposal is equal parts 1984 and Alice in Wonderland," he wrote.

Sotomayor was joined by Justices Anthony Kennedy, Ruth Bader Ginsburg, Stephen Breyer, and Elena Kagan.

The case is the third high-profile Fourth Amendment decision the court has issued in three years. In 2012, the justices ruled that authorities generally need search warrants when they affix GPS devices to vehicles. And last year, the justices ruled that the authorities need warrants to peek into the mobile phones of suspects they arrest.

In the case decided Monday, Los Angeles hoteliers argued that the law violated their rights, and the San Francisco-based 9th US Circuit Court of Appeals agreed in 2013. The city of Los Angeles appealed, arguing (PDF) that the ordinance helps both local and federal authorities in investigations of all types. The case's briefs can be viewed here.

Monday, June 15, 2015

ITIF: Beyond the USA Freedom Act: How U.S. Surveillance Still Subverts U.S. Competitiveness


Daniel Castro and Alan McQuinn
June 9, 2015  ITIF

A failure to sufficiently reform U.S. surveillance policies is hurting U.S. technology companies, costing American jobs, and weakening the U.S. trade balance.

View Report


Almost two years ago, ITIF described how revelations about pervasive digital surveillance by the U.S. intelligence community could severely harm the competitiveness of the United States if foreign customers turned away from U.S.-made technology and services. Since then, U.S. policymakers have failed to take sufficient action to address these surveillance concerns; in some cases, they have even fanned the flames of discontent by championing weak information security practices. In addition, other countries have used anger over U.S. government surveillance as a cover for implementing a new wave of protectionist policies specifically targeting information technology. The combined result is a set of policies both at home and abroad that sacrifices robust competitiveness of the U.S. tech sector for vague and unconvincing promises of improved national security.

ITIF estimated in 2013 that even a modest drop in the expected foreign market share for cloud computing stemming from concerns about U.S. surveillance could cost the United States between $21.5 billion and $35 billion by 2016. Since then, it has become clear that the U.S. tech industry as a whole, not just the cloud computing sector, has under-performed as a result of the Snowden revelations. Therefore, the economic impact of U.S. surveillance practices will likely far exceed ITIF’s initial $35 billion estimate. This report catalogues a wide range of specific examples of the economic harm that has been done to U.S. businesses. In short, foreign customers are shunning U.S. companies. The policy implication of this is clear: Now that Congress has reformed how the National Security Agency (NSA) collects bulk domestic phone records and allowed private firms—rather than the government—to collect and store approved data, it is time to address other controversial digital surveillance activities by the U.S. intelligence community.

The U.S. government’s failure to reform many of the NSA’s surveillance programs has damaged the competitiveness of the U.S. tech sector and cost it a portion of the global market share. This includes programs such as PRISM—the controversial program authorized by the FISA Amendments Act, which allows for warrantless access to private-user data on popular online services both in the United States and abroad—and Bullrun—the NSA’s program to undermine encryption standards both at home and abroad. Foreign companies have seized on these controversial policies to convince their customers that keeping data at home is safer than sending it abroad, and foreign governments have pointed to U.S. surveillance as justification for protectionist policies that require data to be kept within their national borders. In the most extreme cases, such as in China, foreign governments are using fear of digital surveillance to force companies to surrender valuable intellectual property, such as source code.

In the short term, U.S. companies lose out on contracts, and over the long term, other countries create protectionist policies that lock U.S. businesses out of foreign markets. This not only hurts U.S. technology companies, but costs American jobs and weakens the U.S. trade balance. To reverse this trend, ITIF recommends that policymakers:
  • Increase transparency about U.S. surveillance activities both at home and abroad.
  • Strengthen information security by opposing any government efforts to introduce backdoors in software or weaken encryption.
  • Strengthen U.S. mutual legal assistance treaties (MLATs).
  • Work to establish international legal standards for government access to data.
  • Complete trade agreements like the Trans Pacific Partnership that ban digital protectionism, and pressure nations that seek to erect protectionist barriers to abandon those efforts.

Thursday, May 14, 2015

US House passes Bill to end domestic NSA bulk data collection


Summary:American residents could soon be exempt from the NSA's dragnet, unless surveillance is approved by the secretive FISA court, with the USA Freedom Act passing the US House of Representatives and heading to the Senate.



By Chris Duckett | May 14, 2015 -- 07:04 GMT (00:04 PDT)
ZDNet

The US House of Representatives has voted 338 for and 88 against ending the NSA's dragnet collection of telephone, email, and other online data from millions of Americans, a controversial program that was revealed in 2013 by former security contractor Edward Snowden.

The USA Freedom Act is seen as a big win for privacy and civil rights advocates. The White House backs the reforms, saying the Bill protects privacy while preserving essential national security authorities.

After passing the House, the measure is now heading for a vote in the Senate, where the clash between reformists and supporters of the intelligence community, coming within the context of warnings on the increasing digital reach of the Islamic State terror group, transcends party lines.

Both liberals and staunch conservatives, often at odds on most major legislation, have united in opposition against domestic spying by the National Security Agency.

The Bill, which focuses on people in the US and not overseas, would amend controversial sections of the USA Patriot Act, which was passed in the wake of the September 11, 2001, attacks and will expire on June 1.

The reforms scrap the bulk collection detailed in Section 215 of the Patriot Act, replacing it with a targeted program that allows intelligence agencies to collect data from specific individuals or groups, but only with prior approval of the secret national security FISA court.


Under Section 215, the government stored the acquired data, but the new reforms would compel telcos and other data companies to keep the information to be accessible to intelligence agencies only through court order.The data dragnet was operating in complete secrecy after 2001, and has been under the supervision of the FISA court since 2006. It was consistently renewed by the administrations of George W Bush and Barack Obama.

"Today's vote was a major win for surveillance reform and a major rebuke for those who want to reauthorise the Patriot Act without change," said Center for Democracy & Technology president Nuala O'Connor.

Passage through the House was welcomed by Mozilla, whose head of public policy Chris Riley called for the Senate to swiftly pass the legislation.

"This legislation significantly curtails bulk collection under the Patriot Act and other authorities, and puts us on a path to a more private and secure internet," Riley said.

"We are staunchly opposed to any short- or long-term reauthorisation of these sections of the Patriot Act absent meaningful reforms. Now is not the time to delay on these much-needed reforms."

The Electronic Frontier Foundation (EFF) said US business is being hurt by the NSA's actions, and it hopes the Senate will add amendments to strengthen the Bill.

"The legislation is a good start to shutting backdoors," the EFF said. "The time to fix the backdoor problem is now."

The vote came just a week after a US appeals court ruled that the bulk data collection goes far beyond what congress authorised.

"The text of [section 215] cannot bear the weight the government asks us to assign to it, and that it does not authorize the telephone metadata program," wrote judge Gerard E Lynch last week.

Earlier this month, the French lower house approved legislation allowing authorities to spy on suspected terrorists without prior authorisation from a judge.

The new law, to go before the French Senate later this month, allows authorities to spy on the digital and mobile communications of anyone linked to a "terrorist" inquiry without judicial authorisation, and forces internet service providers and phone companies to give up data upon request.

Intelligence services will have the right to place cameras and recording devices in private dwellings and install keylogging devices.

As the US restricts some of its data surveillance schemes, Australia is in the midst of setting up its own data-retention scheme.

In this week's Australian Budget, AU$131 million was allocated by the government for the creation and maintenance of systems to store all Australians' telecommunications data for two years for warrantless access by law enforcement.

However, the money from the government is expected to cover only between one third and half of the cost to implement the scheme.

The Internet Society of Australia CEO Laurie Patton said the government should guarantee to top up the funding if it is inadequate for all ISPs.

"The government's original cost estimate was not based on widespread industry consultation, and the Internet Society is concerned that the costs have been significantly underestimated, especially in respect of small to medium-sized ISPs that don't have the resources to undertake the work in-house, and therefore will be required to pay for external assistance," he said in a statement.

Tuesday, May 12, 2015

BBC: Staff-tracking app faces legal scrutiny in US

BBC

The woman is alleging that an app which tracks movements 24/7 invaded her privacy
A US sales executive is suing her employer for invasion of privacy, alleging that she was fired after deleting an app which tracked her movements.
The action alleges that Intermex, a firm which arranges money transfers, tracked employees even when off-duty.

Myrna Arias alleges that she was "scolded" for removing the app and fired a few weeks later.

The company has not responded to the allegations.

According to court documents published by website Ars Technica, employees were instructed to download the app, called Xora, to their phones in April 2014.

Xora is described on its website as a workplace management app which allows companies to "remotely manage" their workers by keeping track of their hours and other aspects of their job.

Xora's website says that the app uses GPS to allow bosses "to see the location of every mobile worker on a Google Map".

According to the lawsuit, Ms Arias's manager "admitted that employees would be monitored while off-duty and bragged that he knew how fast she was driving at specific moments ever since she had installed the app on her phone".

"He confirmed that she was required to keep her phone's power on 24/7 to answer phone calls from clients," reads the court document.

It goes on to detail that Ms Arias had "no objection" to being monitored at work but felt that monitoring her location during non-work hours was an invasion of her privacy.

She likened the app to a prisoner's ankle bracelet.
Tracking employees
Her boss "scolded the plaintiff when she de-installed the app in late April in order to protect her privacy", reads the court document.

She was fired on 5 May.

Ms Arias is seeking damages for lost earnings in excess of $500,000.

Mark Weston, a partner at law firm Matthew Arnold & Baldwin, tod the BBC that an employer "would not be allowed to track an employee without the consent of that employee".

Clauses that allow for tracking apps would have to be built into contracts, he said.

As for the legality of firing an employee for refusing to use such an app, Mr Weston said: "In the US, things may be looser because many employees there are employees 'at will'. Accordingly, employers have far greater flexibility than in Europe to dismiss an employee who is not playing ball."

Monday, May 11, 2015

AOL: 2.1 million people still subscribe to dial-up Internet


BY BRANDON RUSSELL | MAY 9, 2015 TechnoBuffalo



AOL on Friday revealed that 2.1 million people in the U.S. still subscribe to its dial-up service, an astonishing and surprising number in the year 2015. A large majority of Americans have ditched the comatose service as faster broadband has become more accessible. But, either through ignorance, stubbornness, or sheer unavailability in certain areas, people are still clinging to the good old days of the early Internet.

Back in 2010, AOL revealed it had about 4.6 million dial-up users, so usage is on the decline, but it’s a slow, slow process, not unlike the service these people still get.

CNN Money notes that over 70-percent of Americans are connected through faster broadband, with an average speed of 11.4 Mbps, which is lighting quick compared to AOL’s 56k speeds. Compared to what the Internet looked like 20 years ago, 56k connections probably wouldn’t even be able to load a modern day website, much less stream a video on YouTube or Netflix.

Without fast Internet, online tech journalism just wouldn’t exist in the way it does today. And there would be no Twitch or Spotify. It would be a cruel, apocalyptic world.

The most shocking thing of all? Customers are paying AOL $20 a month for dial-up access, which means the company is still making a killing each year from these subscriptions. If you or someone you know is still using dial-up, it might be time for an intervention.

I get it: not everyone can afford broadband Internet, and there’s a minuscule chance they don’t have access to the faster speeds in their remote part of the wilderness. But 2.1 million is a hefty figure, and so long as people subscribe, AOL will continue to be an enduring time capsule of despair.

Wednesday, May 6, 2015

Warrants not required for police to get your cell phone cell-site records

Mobile callers' cell-tower history is fair game for cops—probable cause unnecessary.

by David Kravets - May 5, 2015 3:25pm PDT  ars technica


Michael Dorausch

A federal appeals court ruled Tuesday that the government does not need a warrant to obtain a suspect's cell-site location data records.

The 9-2 decision (PDF) by the 11th US Circuit Court of Appeals said that the records of towers that a mobile phone uses to make calls are considered "business records" maintained by a "third party" and are not protected by the Fourth Amendment. That means the government may obtain these records if it believes they are relevant to an investigation.

The case concerns a Florida man, Quartavious Davis, who was sentenced to life in prison for a string of robberies in a prosecution that was built with the suspect's cell site records.

...Davis can assert neither ownership nor possession of the third-party’s business records he sought to suppress. Instead, those cell tower records were created by MetroPCS, stored on its own premises, and subject to its control. Cell tower location records do not contain private communications of the subscriber. This type of non-content evidence, lawfully created by a third-party telephone company for legitimate business purposes, does not belong to Davis, even if it concerns him. Like the security camera surveillance images introduced into evidence at his trial, MetroPCS’s cell tower records were not Davis’s to withhold. Those surveillance camera images show Davis’s location at the precise location of the robbery, which is far more than MetroPCS’s cell tower location records show.

The majority ruling by Judge Frank Hull is a big boost to the government. Warrantless cell-site tracking has become among the government's preferred methods of electronically tracking suspects in the wake of a 2012 Supreme Court ruling that the authorities generally needed a warrant to attach GPS devices onto vehicles and track their every move.

Meanwhile, the Atlanta-based appeals court had ruled the opposite way last year by a vote of 2-1. But the 11th Circuit revisited the case with a larger panel of 11 judges at the government's request. The outcome brings the number of appellate courts that have ruled for the authorities to four. There are 13 appeals courts nationwide. None have gone the other way. Without conflicting rulings, the US Supreme Court might not take up the issue any time soon.

In all the decisions, the appellate courts cited analog-aged 1979 US Supreme Court precedent, known as Smith v. Maryland, that allows the government's telephone metadata snooping program that Edward Snowden exposed.

Orin Kerr, a former federal prosecutor and a Fourth Amendment expert, said he agreed with the court's ruling—to an extent.

Granted, I want there to be a circuit split to get the case up to the Supremes. That leaves me in an odd position: Although I think a judge should follow Smith, I also kinda want a lower court to not follow precedent in order to tee up the issue for the Supreme Court.
The 11th Circuit originally decided in June that a warrant was required because the public had a reasonable expectation of privacy in their public movements.

"Thus, the exposure of the cell site location information can convert what would otherwise be a private event into a public one. When one’s whereabouts are not public, then one may have a reasonable expectation of privacy in those whereabouts," the court ruled. (PDF)

But what a different a larger panel of judges makes when it comes to deciding the constitutionality of so-called § 2703(d) orders:

The stored telephone records produced in this case, and in many other criminal cases, serve compelling governmental interests. Historical cell tower location records are routinely used to investigate the full gamut of state and federal crimes, including child abductions, bombings, kidnappings, murders, robberies, sex offenses, and terrorism-related offenses.

Such evidence is particularly valuable during the early stages of an investigation, when the police lack probable cause and are confronted with multiple suspects. In such cases, § 2703(d) orders—like other forms of compulsory process not subject to the search warrant procedure—help to build probable cause against the guilty, deflect suspicion from the innocent, aid in the search for truth, and judiciously allocate scarce investigative resources.

For the two-judge dissent, Judge Beverly Martin wrote:

"While I admire the majority’s attempt to cabin its holding to the technology of five years ago, its assurances in this regard seem naïve in practice. As a result of today’s decision, I have little doubt that all government requests for cell site location data will be approved, no matter how specific or invasive the technology."
The MetroPCS records at issue in the case were from August 1, 2010 to October 6, 2010. The defendant, Davis, made roughly 86 calls a day.

The data included the telephone numbers of calls made by and to Davis' mobile phone; whether a call was outgoing or incoming; the date, time and duration of calls. The key dispute in this case concerned other data that was turned over. That included the number assigned to the cell tower that wirelessly connected the calls from and to Davis, and the sector number associated with the tower.

Davis' attorney, Nathan Freed Wessler of the American Civil Liberties Union, said that the "dissenting judges recognized outdated legal doctrines from the analog age should not be mechanically extended to undermine our privacy rights in the voluminous digital records that come with modern life."



David Kravets / The senior editor for Ars Technica. Founder of TYDN fake news site. Technologist. Political scientist. Humorist. Dad of two boys. Been doing journalism for so long I remember manual typewriters with real paper.

Wednesday, April 22, 2015

BBC: Enraged US man shoots his malfunctioning computer


21 April 2015 BBC

Some academics argue that "computer rage" is becoming increasingly common
A man in the US city of Colorado Springs faces police action after becoming so frustrated with his computer that he took it outside and shot it eight times, police say.
"He was having technology problems, so he took it to the back alley and destroyed it," a police spokesman said.

Lucas Hinch was briefly detained for discharging a firearm within the city.

He did not realise he was breaking the law when he went "Wild West" on his machine, local media reported.

A judge is due to decide what penalty he will receive.

"He got tired of fighting with his computer for the last several months," police spokesman Jeff Strossner told the Colorado Springs Gazette.

The paper said that Mr Hinch "shot the darn thing" when ctrl+alt+delete - the traditional method used to re-boot computers - "consistently did not work" on Monday evening.

"He was able to wreak the kind of revenge most of us only dream about," the paper said. "The computer is not expected to recover."

Tuesday, April 21, 2015

The numbers behind the broadband ‘homework gap’

APRIL 20, 2015

BY JOHN B. HORRIGAN Pew Research Center

Since the dawn of the internet, there’s been much talk about the digital divide – the gap between those with access to the internet and those without. But what about the “homework gap”?

In recent years, policymakers and advocates have pushed to make it easier for low-income households with school-age children to have broadband, arguing that low-income students are at a disadvantage without online access in order to do school work these days. Later this year, the Federal Communications Commission is expected to begin a rule-making process to overhaul the Lifeline Program, an initiative that subsidizes telephone subscriptions for low-income households, so that it would also cover broadband.

In 2013, the Lifeline program provided $1.8 billion worth of telephone subsidies for qualified low-income people. The FCC has not yet provided estimates of how much it would cost to add broadband subsidies to the program, but the debate will undoubtedly focus on overall program costs and how many households would be covered.



How big is the homework gap? A new Pew Research Center analysis finds most American homes with school-age children do have broadband access – about 82.5% (about 9 percentage points higher than average for all households). With approximately 29 million households in America having children between the ages of 6 and 17, according to Pew Research Center analysis of U.S. Census Bureau’s American Community Survey data, this means that some 5 million households with school-age children do not have high-speed internet service at home. Low-income households – and especially black and Hispanic ones – make up a disproportionate share of that 5 million.

Pew Research analysis of the Census data finds that the lowest-income households have the lowest home broadband subscription rates. Roughly one-third (31.4%) of households whose incomes fall below $50,000 and with children ages 6 to 17 do not have a high-speed internet connection at home. This low-income group makes up about 40% of all families with school-age children in the United States, according to the bureau’s American Community Survey. (The survey asked questions on home internet use for the first time in 2013.)

By comparison, only 8.4% of households with annual incomes over $50,000 lack a broadband internet connection at home. In other words, low-income homes with children are four times more likely to be without broadband than their middle or upper-income counterparts.

The other notable difference in home broadband adoption pertains to the race and ethnicity of the householder. Lower-income black and Hispanic households with children trail comparable white households with children by about 10 percentage points.

Asian Americans, by contrast, outperform the other groups in broadband adoption for households with children, regardless of income level. A likely explanation is that Asian Americans have the highest educational levels of any racial group in the United States, which is a characteristic strongly associated with having broadband at home.

Note: The author is currently a senior researcher at Pew Research Center. Prior to joining the center, he served on the Federal Communications Commission team that developed the National Broadband Plan.

Thursday, April 16, 2015

BBC: High price of '.sucks' to be investigated


13 April 2015 BBC


Vox Populi says its prices for ".sucks" website names are "well within the rules"

The authority that decides which letters a web address is allowed to finish with says it is concerned at the high charges for the new ".sucks" name.

The Internet Corporation for Assigned Names and Number (Icann) has asked the US and Canadian trade authorities to investigate Vox Populi, which secured the rights to sell the name.

The company denies any wrongdoing.

Many companies and celebrities have bought their name with controversial suffixes such as ".porn" or ".xxx".

Predatory selling

The last part of a web address that follows the final dot, such as ".com", ".org", and ".net", is referred to as a generic top level domain (gTLD).

Icann relaxed the rules governing gTLDs in 2012, and the latest to go up for sale is ".sucks".

Many companies and celebrities buy their brand or name with various gTLDs, to avoid any confusion with their official website addresses or to stop others buying them and posting negative content.

Taylorswift.xxx has been reserved but not used, to prevent others from buying it

For example, singer Taylor Swift bought up taylorswift.xxx to prevent anyone else from using it.

Specialist online website Domain Incite reports that actor "Kevin Spacey, Microsoft, Google and Apple have already bought up '.sucks' sites in a bid to protect their reputations".

This practice is known as "defensive registering".

Icann granted Vox Populi permission to sell the ".sucks" names but is now concerned at the price levels the Canadian company has set.

Kevin Murphy, from Domain Incite, told the BBC two key elements of the way Vox Populi was handling the sale were causing concern.

"They are charging a $2,000 'sunrise' premium to those wishing to register '.sucks' addresses early, before the addresses go on sale to the general public [next month]," he said.

"Also they are using a list of words or names that have been defensively registered in the past, for which they are charging the top amount."

Mr Murphy said the company was working from a list of keywords that had been part of web addresses bought up early on in similar new domain web address sales and using that to decide which ".sucks" addresses to charge more for.

The base fee for any ".sucks" web address is $199 a year

New gTLDs such as ".rocks" or ".forsale" typically sell for between $5 (£3.42) and $20 a year.

Beyond jurisdiction

But Murphy said: "They [Vox Populi] are charging a much bigger amount that you'd expect.

"They were considering a fee of $25,000 at one point when we spoke to them.

"I think they are charging as much as they can get away with.

"It [Vox Populi] justified the $2,000 premium price tag [for certain '.sucks' addresses] as being 'a reasonable part of a company's PR budget'.

"It appears they are basing prices on what firms can afford not on the product services they are providing."

In a strongly worded letter to Icann, the authority's own advisory body, the Intellectual Property Constituency (IPC), demanded a "halt" to Vox Populi's "illicit", "predatory" and "coercive" selling scheme.

But even though Icann approved the ".sucks" domain name sale and issued the licence to sell the related website addresses, it appears not to have jurisdiction over how they are sold.

There is no evidence that Vox Populi has done anything wrong, and the company told Domain Incite its pricing and policies were "well within the rules".

Icann has referred Vox Populi to the two bodies it believes may have the regulatory authority to investigate the company's practices: the Federal Trade Commission in the United States and the Canadian Office of Consumer Affairs, as the company is registered in Canada.

But unless the company has broken the law, it is not clear what powers Icann has over Vox Populi's handing of the sale of ".sucks".

Wednesday, April 8, 2015

BBC: Illegal downloading: Australia internet firms must supply data


7 April 2015
BBC

Thousands of Australians have illegally downloaded The Dallas Buyers' Club, starring Matthew McConaughey and Jared Leto

An Australian court has ordered internet service providers (ISPs) to hand over details of customers accused of illegally downloading a US movie.

In a landmark move, the Federal Court told six firms to divulge names and addresses of those who downloaded The Dallas Buyers Club.

The case was lodged by the US company that owns the rights to the 2013 movie.

The court said the data could only be used to secure "compensation for the infringements" of copyright.

In the case, which was heard in February, the applicants said they had identified 4,726 unique IP addresses from which their film was shared online using BitTorrent, a peer-to-peer file sharing network. They said this had been done without their permission.

Once they received the names of account holders, the company would then have to prove copyright infringement had taken place.

The judgment comes amidst a crackdown by the Australian government on internet piracy.

Australians are among the world's most regular illegal downloaders of digital content. The delay in release dates for new films and TV shows, and higher prices in Australia for digital content, have prompted many Australians to find surreptitious ways to watch new shows.

Australians are some of the world's most enthusiastic illegal downloaders

Deterrent

The ISPs involved in the case, including Australia's second-largest provider iiNet, said releasing customer information would be a breach of privacy and lead to what is known in the US as "speculative invoicing".

This is where account holders are threatened with court cases that could result in large damages unless smaller settlement fees are paid.

The ISPs argued also that the monetary claims which the US company, Dallas Buyers Club LLC, had against each infringer were so small "that it was plain that no such case could or would be maintained by the applicants".

But Justice Nye Perram ruled that the customer information could be released on condition it was only used to recover compensation for copyright infringement.

"I will also impose a condition on the applicants that they are to submit to me a draft of any letter they propose to send to account holders associated with the IP addresses which have been identified," he ruled.

Justice Perram said the ruling was also important for deterring illegal downloading.

"It is not beyond the realm of possibilities that damages of a sufficient size might be awarded under this provision in an appropriately serious case in a bid to deter people from the file-sharing of films," he said.

The case came to court after Dallas Buyers Club LLC contacted iiNet and other ISPs, asking them to divulge customer details without a court order. The ISPs refused.

The ISPs have yet to say if they will appeal against the court ruling.

Professor of Law at the University of Technology, Sydney, Michael Fraser said it was an important judgement for ISPs and customers.

"If this [judgement] is upheld then the days of anonymous pirating may be over," Prof Fraser told ABC TV.

Wednesday, March 11, 2015

Why America's Internet Is So Shitty And Slow

Why America's Internet Is So Shitty and SlowINTERNET
Adam Clark Estes-, Gawker Media  Gizmodo
You may have heard that the internet is winning: net neutrality was saved, broadband was redefined to encourage higher speeds, and the dreaded Comcast-Time Warner Cable megamerger potentially thwarted. But the harsh reality is that America's internet is still fundamentally broken, and there's no easy fix.

An Economy Built on Wires

When I say "fundamentally broken" I don't just mean that it's slow and shitty, though there is that. It's also broken as a paid service.
The internet is a tangible thing, a network of infrastructure pulsing with light, winding its way into and beneath buildings. It's also a marketplace. There is the physical location where the fiber-optic cables full of data cross, and then there are the financial deals that direct the traffic down each specific set of wires. This combination of physical wires and ephemeral business transactions will shape the future of the digital world.
In order to comprehend just how broken internet service is, you first have to understand how the physical infrastructure of the internet works. Former Gizmodo contributor Andrew Blum described the underlying infrastructure wonderfully his book about the physical heart of the internet, Tubes: A Journey to the Center of the Internet:
In the basest terms, the internet is made of pulses of light. Those pulses might seem miraculous, but they're not magic. They are produced by powerful lasers contained in steel boxes housed (predominantly) in unmarked buildings. The lasers exist. The boxes exist. The internet exists...
There's also wireless data of course, but even those signals need physical towers to send and receive them.
Those pulses of lights-which are packets of data-travel through the internet's wires, taking wrong turns, finding faster routes, and eventually reaching their destinations. But each of those routes is owned and maintained by somebody. If you think of the wires as roads, the setup is something like city streets, state highways, and interstates. In internet terms, those different kinds of roads are called tiers, and there are many network tiers stacked up across the US's continent-spanning network.
Tier 1 is the most powerful as it more or less makes up the backbone of the internet. These are the networks that span the entire globe, sending data under the ocean to far-flung places, the ones that never need to connect to another network to deliver a packet of content. There are only a handful of such networks, run by global corporations like AT&T and Verizon.
The smaller, tier 2 networks connect with each other and with the internet backbone to make it more efficient for those packets of data to reach their destinations. This is the level where a lot of corporate handshake deals to direct traffic take place. And then there's the so-called "last mile." You've probably heard a lot about this idea, and how traffic gets across it.
The last mile is the part of the data's voyage that takes it from local utility poles or underground tubes, into your house, and through the cable that plugs into your computer. It's literally the last stretch of infrastructure that data must traverse on its long journey from the server where it's hosted, to your web browser or email client or whatever. It's the physical infrastructure that connects individual homes to the rest of the network. This is the part of the internet that the new Federal Communications Commission's rules regulate.

The Decaying Last Mile

In the US, the last mile of internet infrastructure is an enormous problem. There are two reasons for this: technical restraints holding back the bandwidth needed to support modern-day internet traffic, and a lack of competition between the major carriers selling internet service to the end user.
Most of America's telecommunications infrastructure relies on outdated technology, and it runs over the same copper cables invented by Alexander Graham Bell over 100 years ago. This copper infrastructure-made up of "twisted pair" and coaxial cables-was originally designed to carry telephone and video services. The internet wasn't built to handle streaming video or audio.
When your streaming video reaches that troubled last mile of copper, those packets will slam on their brakes as they transition from fiber optic cables to copper coaxial cables. Copper can only carry so much bandwidth, far less than what the modern internet demands. Only fiber optic cables, thick twists of ultra-thin glass or plastic filaments that allow data to travel at the speed of light, can handle that bandwidth. They're also both easier to maintain and more secure than copper.
As consumers demand more bandwidth for things like streaming HD movies, carriers must augment their networks-upgrade hardware, lay more fiber, hire more engineers, etc.-to keep traffic moving freely between them. But that costs big money-like, billions of dollars in some cases. Imagine the cost of swapping out the coaxial cables in every American home with fiber optic cables. It's thousands of dollars per mile according to some government records.
And here's the kicker. The last mile infrastructure is controlled by an oligarchy-three big cable companies: Comcast, Time Warner Cable, and Verizon. You know this well. One in three Americans only have one choice for broadband service; most of the others only have two internet providers to choose from.
Without competition, there's no incentive for internet providers to improve improve infrastructure.These massive telecom companies create a bottleneck in the last mile of service by refusing to upgrade critical infrastructure. And they can charge exorbitant prices for the sub-par service while they're at it.
So your internet is shitty and slow and expensive.

The Network of Bureaucracy

If you want to load a webpage or watch a movie on Netflix, it's not just the last mile of infrastructure that slows down your internet, however. It's also the tier 2 networks, where the weird web of business connections starts tangling things up.
Like last mile infrastructure, there's only a small handful of companies controlling much of the backbone of the internet. Including, once again, telecom giants AT&T and Verizon. AT&T and Verizon not only control tier 1 network, they're also the big players on tier 2, which gives them a huge amount of bargaining power, and a huge amount of bureaucratic control over your slow and shitty internet.
The other carriers that operate tier 2 networks are companies you probably haven't heard of-Cogent, Level3, and Zayo are a few-and they're integral to the internet's success as a global network. These are the networks that manage the crossroads of the internet, making deals that dictate how traffic travels between networks.
Why America's Internet Is So Shitty and Slow
A rough sketch of how the internet works. On the left, you have end users-homes and business. On the right, you have the networks making the deals that dictate how internet traffic flows around the globe. Note how content providers (Netflix, YouTube) peer directly with carriers.
Regardless of the physical infrastructure, data can only travel as fast as its predetermined route allows. If tier 2 networks don't strike the right agreements with other networks, that could mean that your data will take a longer route to its destination.
Broadly speaking, a tier 1 network can reach every part of the internet without paying for transit on another network; these are the internet's biggest power brokers. But each of the lesser-known tier 2 middleman carriers must depend on other networks to provide their customers with access to all of the content on the internet.
So picture a map of the internet. If every single network agreed to let other networks use its infrastructure data would flow freely between all points. Unfortunately, not all of the tier 2 networks cooperate.
Why America's Internet Is So Shitty and Slow
An illustration of first and second tier networks, a sprawling 180,000 miles of fiber. The yellow lines are wholly owned and operated by top tier carriers, and the orange ones are shared with other carriers.
To keep traffic moving between networks, the carriers have to make interconnect agreements. One type is called a peering agreement, where two carriers exchange traffic freely for mutual benefit. The other is a transit agreement, exchanging traffic for a fee. The economics of these agreements are quite complex-here's a great explainer-but suffice it to say the larger the network, the fewer transit agreements it must pay for.
Tier 2 carriers also forge peering and transit agreements with content providers like Google, Amazon, and Netflix to provide more direct routes to consumers.
This gets complicated because you have a countless number of different networks relying on a limited amount of infrastructure. While fixing the decaying last mile means monopolistic telecom firms shelling out to upgrade copper wires, fiber optic cable is already the industry standard on tier 2 networks-so your internet speeds are affected more by how well these tier 2 carriers are getting along. When these deals go wrong, carriers end up in locked in negotiations that mean you'll wait longer for webpages to load.

The Fiber Future Relies on Competition

In a climate without sufficient competition, American carriers can refuse to improve infrastructure and augment capacity without the fear of losing customers. Where are they going to go? They can either pay a high price for bad service or pay nothing for no service. This has been the status quo in the USA for years, and companies like Verizon have worked hard to keep this status quo by preventing the FCC from doing its job.
That's also why carriers like Verizon are going straight to content providers like Netflix and asking it to pay for more direct routes to customers. Why would Verizon spend its own money on infrastructure, when it can get a content provider to pick up the tab?
This is where the net neutrality debate comes from. The FCC is finally getting aggressive about protecting the open web, and that's great. But net neutrality is not enough. Improving your slow and shitty internet comes down to increasing competition. We need to build new networks with better last mile technology that will give tier 2 networks an alternative to the big cable cartel.
This is going to require some radical approaches, like the bootstrapped ISPs and experimental municipal broadband networks we're starting to see.
While laying fiber is wildly expensive, startups could take a different tack. A San Francisco local ISP called Monkeybrains is using roof-mounted wireless connections and direct fiber access to data centers to offer high speed wireless internet. It costs about $2,500 to set up the equipment to join Monkeybrains' innovative network, but after that, you can get "insane speeds" for just $35 a month.
There's also the option of building a network from the ground up, like the city of Chattanooga, Tennessee did a few years ago. Starting this year, the federal government is funneling more moneytowards municipal broadband projects that treat the internet more like a public utility and offer high speeds at low prices. Now it's up to the communities to start up their municipal broadband projects.
President Obama has applauded this path forward, and the FCC is paving the way by tweaking regulations so that help municipal broadband overcome regulations that have traditionally favored big cable and discouraged competition. Some cracks in the oligarchy are starting to show.
At the end of the day, America's broken internet isn't going to fix itself. Monopolistic problems deserve capitalistic solutions. In this case, it's competition-pure and simple. The alternative isn't just frustrating.It's dysfunctional.
Illustrations by Jim Cooke

New smoking gun further ties NSA to omnipotent “Equation Group” hackers

What are the chances unrelated state-sponsored projects were both named "BACKSNARF"?
by Dan Goodin - Mar 11, 2015 6:01am PDT  Ars Technica


Niels Noordhoek

Researchers from Moscow-based Kaspersky Lab have uncovered more evidence tying the US National Security Agency to a nearly omnipotent group of hackers who operated undetected for at least 14 years.

FURTHER READING
HOW “OMNIPOTENT” HACKERS TIED TO NSA HID FOR 14 YEARS—AND WERE FOUND AT LAST

"Equation Group" ran the most advanced hacking operation ever uncovered.The Kaspersky researchers once again stopped short of saying the hacking collective they dubbed Equation Group was the handiwork of the NSA, saying only that the operation had to have been sponsored by a nation-state with nearly unlimited resources to dedicate to the project. Still, they heaped new findings on top of a mountain of existing evidence that already strongly implicated the spy agency. The strongest new tie to the NSA was the string "BACKSNARF_AB25" discovered only a few days ago embedded in a newly found sample of the Equation Group espionage platform dubbed "EquationDrug." "BACKSNARF," according to page 19 of this undated NSA presentation, was the name of a project tied to the NSA's Tailored Access Operations.



"BACKSNARF" joins a host of other programming "artifacts" that tied Equation Group malware to the NSA. They include "Grok," "STRAITACID," and "STRAITSHOOTER." Just as jewel thieves take pains to prevent their fingerprints from being found at their crime scenes, malware developers endeavor to scrub usernames, computer IDs, and other text clues from the code they produce. While the presence of the "BACKSNARF" artifact isn't conclusive proof it was part of the NSA project by that name, the chances that there were two unrelated projects with nation-state funding seems infinitesimally small.


Kaspersky Lab
The code word is included in a report Kaspersky published Wednesday detailing new technical details uncovered about Equation Group. Among other new data included in the report, the timestamps stored inside the Equation Group malware showed that members overwhelmingly worked Monday through Friday and almost never on Saturdays or Sundays. The hours in the timestamps appeared to show members working regular work days, an indication they were part of an organized software development team. Assuming they worked a regular 8 to 5 workday, the timestamps show the employees were likely in the UTC-3 or UTC-4 time zone, a finding that would be consistent with people working in the Eastern part of the US. The Kaspersky report discounted the possibility the timestamps were intentionally manipulated, since the years listed in various executable files appeared to match the availability of computer platforms the files ran on.

Previously found evidence suggesting a possible connection to the NSA included the Equation Group's aptitude for conducting interdictions that in 2009 placed highly advanced malware on a CD-ROM sent to a prestigious researcher who attended a scientific conference. That interdiction was similar to an NSA-sponsored one detailed in documents leaked by former NSA subcontractor Edward Snowden thatinstalled covert implant firmware on a Cisco Systems router as it was being shipped to its unwitting customer. Still other ties included zero-day vulnerabilities shared between Equation Group malware and the NSA-led Stuxnet worm that sabotaged Iranian uranium enrichment efforts in 2009 or so. The countries that were and were not targeted are also consistent with Equation Group being a US-sponsored project.

Most of the new details included in Tuesday's report will be of interest only to hard-core researchers. Still, they only bolster previous findings that Equation Group was hands down the world's most advanced hacking operation ever to come to light. Whereas before the sprawling Equation Drug platform was known to support 35 different modules, Kaspersky has recently unearthed evidence there are 115 separate plugins. The architecture resembles a mini operating system with kernel- and user-mode components alike. Readers can expect more revelations to come as researchers continue to analyze new samples and further examine the malware that has already come to light.

Saturday, February 21, 2015

BBC: Lenovo taken to task over 'malicious' adware



Lenova tablets and mobiles on displayA security expert said Lenovo had betrayed users' trust

Related Stories

Computer maker Lenovo has been forced to remove hidden adware that it was shipping on its laptops and PCs after users expressed anger.
The adware - dubbed Superfish - was potentially compromising their security, said experts.
The hidden software was also injecting adverts on to browsers using techniques more akin to malware, they added.
Lenovo faces questions about why and for how long it was pre-installed on machines - and what data was collected.
The company told the BBC in a statement: "Lenovo removed Superfish from the preloads of new consumer systems in January 2015. At the same time Superfish disabled existing Lenovo machines in the market from activating Superfish.
Complaining
"Superfish was preloaded on to a select number of consumer models only. Lenovo is thoroughly investigating all and any new concerns raised regarding Superfish."
Users began complaining about Superfish in Lenovo's forums in the autumn, and the firm told the BBC that it was shipped "in a short window from October to December to help customers potentially discover interesting products while shopping".
User feedback, it acknowledged, "was not positive".
Last month, forum administrator Mark Hopkins told users that "due to some issues (browser pop up behaviour, for example)", the company had "temporarily removed Superfish from our consumer systems until such time as Superfish is able to provide a software build that addresses these issues".
He added it had requested that Superfish issue an auto-update for "units already in market".
Screen grab of how Superfish issues certificatesWas Superfish given permission to issue its own certificates?
Superfish was designed to help users find products by visually analysing images on the web to find the cheapest ones.
Such adware is widely regarded in the industry as a form of malware because of the way it interacts with a person's laptop or PC.
Security expert from Surrey University Prof Alan Woodward said: "It is annoying. It is not acceptable. It pops up adverts that you never asked for. It is like Google on steroids.
"This bit of software is particularly naughty. People have shown that it can basically intercept everything and it could be really misused."
According to security experts, it appears that Lenovo had given Superfish permission to issue its own certificates, allowing it to collect data over secure web connections, known in malware parlance as a man-in-the-middle attack.
"If someone went to, say, the Bank of America then Superfish would issue its own certificate pretending to be the Bank of America and intercept whatever you are sending back and forth," said Prof Woodward.
Ken Westin, senior analyst at security company Tripwire, agreed: "If the findings are true and Lenovo is installing their own self-signed certificates, they have not only betrayed their customers' trust, but also put them at increased risk."
Clean install
Although Lenovo has said that it has removed Superfish from new machines and disabled it from others, it was unclear what the situation would be for machines where it had already been activated.
Prof Woodward said: "Lenovo is being very coy about this but it needs to explain how long it has been doing this, what the scale is and where all the data it has collected is being stored.
"There will be remnants of it left on machines and Lenovo does not ship the disks that allow people to do a clean install."
It raises wider questions about the deals that computer manufacturers do with third parties and the amount of software that comes pre-installed on machines.
Mr Westin said: "With increasingly security and privacy-conscious buyers, laptop and mobile phone manufacturers may well be doing themselves a disservice by seeking outdated advertising based monetisation strategies."
Users were particularly angry that they had not been told about the adware.
One Lenovo forum user said: "It's not like they stuck it on the flier saying... we install adware on our computers so we can profit from our customers by using hidden software.
"However, I now know this. I now will not buy any Lenovo laptop again."
The problem also caused a storm on Twitter, where both Lenovo and Superfish were among the most popular discussion topics.