Showing posts with label WEB. Show all posts
Showing posts with label WEB. Show all posts

Monday, September 9, 2013

Yahoo demands US government allow disclosure of data requests

Yahoo has begun legal action demanding it be allowed to disclose details of US national security agencies' requests to access the personal data of its users.
The move comes a few days after Yahoo published its first transparency report, detailing the overall number of global government requests for data.
US law prohibits organisations from providing a breakdown of these figures.
Yahoo said withholding such information from the public "breeds mistrust and suspicion" about the 

US government.

The web company followed Google and Microsoft in releasing its first transparency report last week, detailing requests for users' data by 17 countries in which it has a legal entity.
The publication followed increased pressure by privacy groups for technology companies to disclose details of their collaboration with law enforcement agencies.
Yahoo had previously taken legal action to require the US government to publish documents over the next few months, which it said would show the company had objected to the establishment of Prism, a surveillance programme uncovered by whistleblower Edward Snowden.

Under the US government's Foreign Intelligence Surveillance Act (Fisa), companies are not allowed to publicly disclose details of requests via programs like Prism, unless the data is released in an aggregated fashion, mixed together with less sensitive information.
"The United States should lead the world when it comes to transparency, accountability, and respect of civil liberties and human rights," wrote Yahoo lawyer Ron Bell in a blog about the latest case.
"We filed the [law]suit today because we are not authorised at present to break out the number of requests, if any, that we receive for user data under specific national security statutes."
He added: "We believe that the US government's important responsibility to protect public safety can be carried out without precluding internet companies from sharing the number of national security requests they may receive."

US requests 

Yahoo's transparency report revealed that 12,444 disclosure requests were made by the US between January and June of this year - by far the highest of all the countries detailed.
Only 2% of requests in the US were rejected. Although in a further 801 requests with which Yahoo complied, the company had found no data on the users in question. 

The report, which Yahoo said would now be updated every six months, also said 1,709 disclosure requests had been made in the UK, although 27% of those had been rejected.
Google last published a transparency report in December 2012, which showed 8,438 applications from government officers and courts in the US over the last six months of 2012. It had 1,458 requests from UK officials in the same period.

Ron Bell blogged about the release of the report and emphasised the measures the company's legal department took to reject data requests whenever possible.
The highest number of rejected disclosure requests was in Germany, where Yahoo refused to disclose the details of 816 users. Singapore had the greatest percentage of refusals, with 41% of all requests denied.

The report does not include requests for data on users of Tumblr, a microblogging site recently acquired by Yahoo, although the company says details will be made available at a later date.


Friday, September 6, 2013

N.S.A. Able to Foil Basic Safeguards of Privacy on Web

This undated photo released by the United States government shows the National Security Agency campus in Fort Meade, Md.

The National Security Agency is winning its long-running secret war on encryption, using supercomputers, technical trickery, court orders and behind-the-scenes persuasion to undermine the major tools protecting the privacy of everyday communications in the Internet age, according to newly disclosed documents. 

The agency has circumvented or cracked much of the encryption, or digital scrambling, that guards global commerce and banking systems, protects sensitive data like trade secrets and medical records, and automatically secures the e-mails, Web searches, Internet chats and phone calls of Americans and others around the world, the documents show.
Many users assume — or have been assured by Internet companies — that their data is safe from prying eyes, including those of the government, and the N.S.A. wants to keep it that way. The agency treats its recent successes in deciphering protected information as among its most closely guarded secrets, restricted to those cleared for a highly classified program code-named Bullrun, according to the documents, provided by Edward J. Snowden, the former N.S.A. contractor.
Beginning in 2000, as encryption tools were gradually blanketing the Web, the N.S.A. invested billions of dollars in a clandestine campaign to preserve its ability to eavesdrop. Having lost a public battle in the 1990s to insert its own “back door” in all encryption, it set out to accomplish the same goal by stealth.
The agency, according to the documents and interviews with industry officials, deployed custom-built, superfast computers to break codes, and began collaborating with technology companies in the United States and abroad to build entry points into their products. The documents do not identify which companies have participated. 

The N.S.A. hacked into target computers to snare messages before they were encrypted. In some cases, companies say they were coerced by the government into handing over their master encryption keys or building in a back door. And the agency used its influence as the world’s most experienced code maker to covertly introduce weaknesses into the encryption standards followed by hardware and software developers around the world. 

“For the past decade, N.S.A. has led an aggressive, multipronged effort to break widely used Internet encryption technologies,” said a 2010 memo describing a briefing about N.S.A. accomplishments for employees of its British counterpart, Government Communications Headquarters, or GCHQ. “Cryptanalytic capabilities are now coming online. Vast amounts of encrypted Internet data which have up till now been discarded are now exploitable.”
When the British analysts, who often work side by side with N.S.A. officers, were first told about the program, another memo said, “those not already briefed were gobsmacked!”
An intelligence budget document makes clear that the effort is still going strong. “We are investing in groundbreaking cryptanalytic capabilities to defeat adversarial cryptography and exploit Internet traffic,” the director of national intelligence, James R. Clapper Jr., wrote in his budget request for the current year. 

In recent months, the documents disclosed by Mr. Snowden have described the N.S.A.’s reach in scooping up vast amounts of communications around the world. The encryption documents now show, in striking detail, how the agency works to ensure that it is actually able to read the information it collects. 

But some experts say the N.S.A.’s campaign to bypass and weaken communications security may have serious unintended consequences. They say the agency is working at cross-purposes with its other major mission, apart from eavesdropping: ensuring the security of American communications. 

Some of the agency’s most intensive efforts have focused on the encryption in universal use in the United States, including Secure Sockets Layer, or SSL; virtual private networks, or VPNs; and the protection used on fourth-generation, or 4G, smartphones. Many Americans, often without realizing it, rely on such protection every time they send an e-mail, buy something online, consult with colleagues via their company’s computer network, or use a phone or a tablet on a 4G network.
For at least three years, one document says, GCHQ, almost certainly in collaboration with the N.S.A., has been looking for ways into protected traffic of popular Internet companies: Google, Yahoo, Facebook and Microsoft’s Hotmail. By 2012, GCHQ had developed “new access opportunities” into Google’s systems, according to the document. (Google denied giving any government access and said it had no evidence its systems had been breached). 
“The risk is that when you build a back door into systems, you’re not the only one to exploit it,” said Matthew D. Green, a cryptography researcher at Johns Hopkins University. “Those back doors could work against U.S. communications, too.”
Paul Kocher, a leading cryptographer who helped design the SSL protocol, recalled how the N.S.A. lost the heated national debate in the 1990s about inserting into all encryption a government back door called the Clipper Chip.
“And they went and did it anyway, without telling anyone,” Mr. Kocher said. He said he understood the agency’s mission but was concerned about the danger of allowing it unbridled access to private information.
“The intelligence community has worried about ‘going dark’ forever, but today they are conducting instant, total invasion of privacy with limited effort,” he said. “This is the golden age of spying.” 

A Vital Capability
 
The documents are among more than 50,000 shared by The Guardian with The New York Times and ProPublica, the nonprofit news organization. They focus on GCHQ but include thousands from or about the N.S.A.
Intelligence officials asked The Times and ProPublica not to publish this article, saying it might prompt foreign targets to switch to new forms of encryption or communications that would be harder to collect or read. The news organizations removed some specific facts but decided to publish the article because of the value of a public debate about government actions that weaken the most powerful privacy tools. 

The files show that the agency is still stymied by some encryption, as Mr. Snowden suggested in a question-and-answer session on The Guardian’s Web site in June.
“Properly implemented strong crypto systems are one of the few things that you can rely on,” he said, though cautioning that the N.S.A. often bypasses the encryption altogether by targeting the computers at one end or the other and grabbing text before it is encrypted or after it is decrypted.
The documents make clear that the N.S.A. considers its ability to decrypt information a vital capability, one in which it competes with China, Russia and other intelligence powers.
“In the future, superpowers will be made or broken based on the strength of their cryptanalytic programs,” a 2007 document said. “It is the price of admission for the U.S. to maintain unrestricted access to and use of cyberspace.” 

The full extent of the N.S.A.’s decoding capabilities is known only to a limited group of top analysts from the so-called Five Eyes: the N.S.A. and its counterparts in Britain, Canada, Australia and New Zealand. Only they are cleared for the Bullrun program, the successor to one called Manassas — both names of an American Civil War battle. A parallel GCHQ counterencryption program is called Edgehill, named for the first battle of the English Civil War of the 17th century.
Unlike some classified information that can be parceled out on a strict “need to know” basis, one document makes clear that with Bullrun, “there will be NO ‘need to know.’ ”
Only a small cadre of trusted contractors were allowed to join Bullrun. It does not appear that Mr. Snowden was among them, but he nonetheless managed to obtain dozens of classified documents referring to the program’s capabilities, methods and sources.
Ties to Internet Companies
 
When the N.S.A. was founded, encryption was an obscure technology used mainly by diplomats and military officers. Over the last 20 years, it has become ubiquitous. Even novices can tell that their exchanges are being automatically encrypted when a tiny padlock appears next to a Web address.

Webcam Maker Takes FTC's Heat for Internet-of-Things Security Failure

Remember last month's hack of a baby monitor in a Texas home, which allowed an intruder to spy on and say terrible things to a sleeping infant? Though it quickly gained notoriety, that was far from the first or only such incident. In fact, any webcam or Web-connected device is vulnerable, and a spate of webcam hacks last year prompted the FTC to take action.

The United States Federal Trade Commission on Wednesday announced a settlement with Trendnet over its lax security practices. The action stemmed from privacy invasions that occurred in January 2012, when hackers posted live feeds to the Web from nearly 700 cameras made by the company.
"Right now, we're doing enforcement, as you can see from the Trendnet case," FTC spokesperson Peter Kaplan told TechNewsWorld.
The incident gave Trendnet an opportunity to improve best practices and augment product security, the company said in a statement. On becoming aware of the 2012 hacks, it released a firmware update to rectify the vulnerability, stopped product shipments, and updated all affected models. It also dedicated "substantive resources" to notify consumers.
Spokesperson Tamika Harrison declined to provide further details.

What Happened at Trendnet

Trendnet marketed its SecurView cameras for various uses ranging from home security to baby monitoring and claimed they were secure, the FTC said. However, they had faulty software that let anyone who obtained a camera's IP address look through it -- and sometimes listen as well.
Further, from at least April 2010, Trendnet transmitted user login credentials in clear, readable text over the Internet, and its mobile apps for the cameras stored consumers' login information in clear, readable text on their mobile devices, the FTC said.
It is basic security practice to secure IP addresses against hacking and to encrypt login credentials or at least password-protect them, and Trendnet's failure to do so was surprising.
"It's important for device makers to consider the entire security lifecycle, from inception to design and deployment, and [do so] continuously once their product is in the market," Philip DesAutels, vice president of technology at Xively.

The Walk of Punishment

Trendnet's settlement prohibits it from misrepresenting the security of its cameras or the security, privacy, confidentiality or integrity of the information that its devices transmit.
Further, it cannot misrepresent consumer control over the security of information the devices store, capture, access or transmit; it must notify customers about security issues with the cameras and the availability of a firmware update; and it must provide customers with free tech support for updating or uninstalling their cameras for the next two years.
Finally, Trendnet must establish a comprehensive information security program designed to address security risks that could let hackers access or use its devices; protect the security, confidentiality and integrity of information stored, captured, accessed or transmitted by its devices; and get third-party security audits biennially for the next 20 years.

Frail Grasp on the Big Picture

The hacking of Trendnet's cameras is only the tip of the iceberg as the world moves toward total connectivity in the Internet of Things, which forms the basis for IBM's Smarter Planet Initiative. The IoT will link automobiles, household appliances, mobile devices and just about everything else that accesses the Web.
Cybercriminals and pranksters may have a field day when IoT reaches critical mass.
"Invasion of privacy is only one aspect of the security challenge around the Internet of Things," Jarad Carleton, principal analyst at Frost & Sullivan, told TechNewsWorld. Cybercriminals will be able to hack Web-connected front door locks, and pranksters might turn on the air conditioning of a house in mid-winter or turn lights on or off, for instance.

Possible Solutions

The best practices for the IoT have been standard practice since the late 1990s, Kevin O'Brien, enterprise solution architect at CloudLock, told TechNewsWorld.
"Don't overconnect your systems, don't trust a locally compromised or accessible device, and do subject your code and hardware to third-party penetration testing, both in blackbox and whitebox variants," O'Brien continued.
The FTC will hold a public workshop Nov. 19 on the IoT to explore the questions of consumer privacy and security, the commission's Kaplan said.

Yahoo rolls out its new logo





After an extensive, month-long buildup, Yahoo has finally unveiled its new logo.

Overall the look is cleaner and thinner, and it is a new sans-serif typeface created by Yahoo. The logo is still purple, though a shade darker, and features all the usual uppercase letters in the same order finished off by the signature exclamation point, which dances around in some versions.
Yahoo posted two flavors of the new look to its Tumblr at midnight on Thursday. One is white text on a purple background, the other purple text on white background. Both have a slight beveled effect, though it's more noticeable on the purple text. It has already replaced the logo that appears on the top left corner of Yahoo.com.

"We knew we wanted a logo that reflected Yahoo - whimsical, yet sophisticated. Modern and fresh, with a nod to our history. Having a human touch, personal. Proud.," wrote CEO Marissa Mayer in a blog post on Tumblr, which Yahoo bought earlier this year.

"We didn't want to have any straight lines in the logo. Straight lines don't exist in the human form and are extremely rare in nature, so the human touch in the logo is that all the lines and forms all have at least a slight curve," Mayer added in her post, which goes into exhaustive detail about the thinking behind the logo.

In a recent internal poll of Yahoo employees, 87% wanted the logo changed, Mayer said.
Yahoo managed to turn a simple rebranding into an impressive marketing push by dragging it out for 30 days. For the past month, the company has rotated out the logo on its homepage daily with one of the runnersup. Some of the 29 logos were a lot more unusual than the final choice, perhaps to make fans appreciate the reserved simplicity of the final look.
"Sharing these logo variations prepares people for change, so there's less risk of what happened to Gap," said David Airey, a graphic designer specializing in brand identity.

When Gap tried changing its logo in 2010, there was an outcry among Gap loyalists and logo enthusiasts. The clothing company eventually caved and switched back to its old logo.
Yahoo's logo redesign was headed up by an in-house branding group and product designers, according to AdAge. It is likely just one of the more noticeable elements of a larger rebranding effort for the struggling company, which Mayer has re-energized since becoming CEO last year.
"The logo is only part of a brand new branding and image campaign. It signals to consumers, investors and employees that change is coming," said Columbia business school professor Bernd Schmitt.

The new logo is probably not different enough to raise much ire (or eyebrows) among Yahoo users, although some Internet critics were unimpressed.
On Twitter, the reaction to the logo was less than enthusiastic. "The new Yahoo logo looks like it got run through Alien Skin Eye Candy on Photoshop 4.0.," said Justin Williams.
"A bad logo is all it took for Yahoo! to make everyone talk about it," tweeted Preshit Deorukhkar, editor of design publication Beautiful Pixels.

Yahoo hasn't updated its logo since 2009, and it has been mostly the same since 1995. The move to change it now is logical given its Mayer's recent attempts to breathe new life into the brand.
"More often than not, when a company's identity looks a little tired (or more likely when new leadership wants to put their own stamp on things), what's already in place won't need to be thrown out. It'll just need to be freshened up," said Airey.

Sunday, September 1, 2013

The web giants pumping us for data

As society becomes more networked, the information available to the Googles, Amazons and Facebooks of this world will increase exponentially 

Rich resources … Like an oilfield, big data offers potentially huge profits for the corporations tapping into it.
Should you be looking for an example of hucksterish cynicism, then the mantra that "data is the new oil" is as good as they come. Although its first recorded utterance goes as far back as 2006, in recent times it has achieved the status of an approved corporate cliche, though nowadays "data" is generally qualified by the adjective "big". And if you want a measure of how deeply the cliche has penetrated the collective unconscious, ponder this: a Google search for "big data" turns up more than 1.5bn results. And a search for "data mining" turns up 167m results.

The idea of big data as a metaphor for oil is seductive. It's also revealing in interesting ways. Given that the oil business is one of the biggest industries in the history of the world, for example, the metaphor hints at untold future riches. But it conveniently skates over the fact that oil wealth overwhelmingly benefits either ruling elites in corrupt and/or authoritarian countries, or huge corporations in democratic states.

But at least oil is a physical, non-renewable resource that is extracted from the earth. Big data, on the other hand, is extracted from the activities of people and machines. As society becomes more and more networked, and as the so-called "internet-of-things" evolves, the amounts of data available to be "mined" will increase exponentially. And, unlike fossil fuels, these data reserves are infinitely renewable.

"Big data", says Kenneth Cukier, co-author of the best book on the subject to appear so far, "will transform how we work, how we live and how we think". He argues that, at least in the case of data, "more is not just more; more is different", by which he means that quantitative abundance can lead to qualitative change. The availability of huge amounts of data turbocharges machine learning; for example, turning hitherto impossible tasks – like accurate, instantaneous language translation – into delivered realities.

The key question about any major technological development is: who benefits? The answer in the case of big data is: huge corporations – the Googles, Amazons and Facebooks of this world, which are the only outfits (outside of the US National Security Agency) with the computational resources to mine, analyse and process the data torrents unleashed by us as we go about our networked lives. The companies don't talk about it this way, of course. Instead they have soothing patter about how their analytical capabilities enable them to serve you better: how the ability to analyse the web searches conducted by you and your friends enables them to provide better search results, for example; or how analysis of your online behaviour enables Amazon to suggest products that you might like; and so on.
All true, of course, but skilfully avoiding the awkward fact that you are the resource that is being mined and that the playing field that is cyberspace is tilted in favour of the corporations who have come to dominate it.

Which brings us to another aspect of the subject: open data. Since 2005, activists have been campaigning for "open government data" initiatives – demanding the publication of public datasets in machine-readable, freely reusable formats. The argument for this is impeccable: the data is collected by public bodies; it should therefore be available to the public that paid for it. The motivations behind the campaigns are likewise admirable: if the data is available, then civic-minded geeks can do useful things with it.

The open government data campaigns have been surprisingly successful in both the US and the UK. Huge swaths of public data are now available. I can download a vast spreadsheet containing details of every contract worth more than £500 entered into by my local authority, for example. And in many cases, people have already developed useful services on top of public data. For example, busitlondon.co.uk provides a helpful online tool for planning a journey by bus in London.

There's lots more in that vein, and it's all good stuff. At first sight, therefore, open government data looks encouraging. But there are a couple of flies in the ointment. The first is that there is a difference between open data and open government. The current Hungarian administration, for example, has been quite good at publishing public data, but is morphing into one of the most secretive and authoritarian regimes in Europe.

And then there's that awkward question again: who benefits? Certainly the public, to some extent. But there are signs that open government data favours private companies bidding for local authority contracts. The companies know what it costs the authority to collect the refuse, for instance; but their own finances are opaque, so it's impossible to judge whether they would really be more efficient than a public body.
And the moral? Be careful what you wish for.

Friday, August 30, 2013

Syrian Electronic Army hackers say 'many surprises' planned

Syrian hackers behind recent attacks on the New York Times and Twitter have warned media companies to "expect us".

The firm has gained notoriety by attacking a string of media companies in recent months

The Syrian Electronic Army, which supports President Bashar al-Assad, added it had "many surprises" to come.
Interviewed via email following the UK Parliament's vote against military intervention on Thursday, a spokesman told BBC News: "It's the right thing."

He added: "Military intervention in Syria has many consequences and will affect the whole world.
"Our main mission is to spread truth about Syria and what is really happening."
The SEA has targeted various media companies, including the BBC, CNN and the Guardian.
Brian Krebs, a former Washington Post reporter, wrote that clues discovered when the SEA's own website was hacked earlier in the year pointed towards at least one member of the group being based in neighbouring country Turkey.
But the SEA's spokesman dismissed these claims, saying that "they keep publishing names so they can get attention".
"All the media outlets that we targeted were publishing false/fabricated news about the situation in Syria," he told the BBC.
"Our work doesn't need funds. It just needs a computer and internet connection."
Explosion tweet
Until this week's attacks, the SEA's efforts had largely focused on "phishing" social media accounts, tricking users into handing over log-in details.
In one particularly effective attack, the Twitter account of the Associated Press was compromised, and the group posted a tweet saying US President Barack Obama had been hurt in an explosion.
The New York Times attack was more damaging, however, as the hackers were able to redirect people trying to visit the newspaper to the SEA's website instead, albeit briefly.
"Our goal was to deliver our anti-war message on NY Times website - but our server couldn't last for three minutes," the group said.
"The Twitter attack was because of the suspension of our accounts on Twitter by its management.
"We succeeded in our attack as we expected."

Hackers: Pro-Assad Group Targets US Websites

The Syrian Electronic Army claims to have hacked Twitter, tweeting: 'Hi @Twitter, look at your domain, its owned by #SEA :)'

The hackers infiltrate outlets it perceives to be aligned against Mr Assad
Pro-Assad regime hackers claim to have targeted leading US media websites, shutting down the New York Times for 30 minutes.
The Syrian Electronic Army said it had hacked sites belonging to Twitter and the Huffington Post, making them unstable, as well as closing down the NYT.
The NYT attributed the meltdown to a "malicious external attack".
When users attempted to visit www.nytimes.com, the only message that appeared was "Hacked by the SEA".
Meanwhile, Twitter confirmed the hack saying "viewing of images and photos was sporadically impacted", but added that "no user information was affected".
The SEA boasted in a tweet: "Hi @Twitter, look at your domain, its owned by #SEA :)" 

The boasting tweet from the SEA hacking group


While the Twitter site continued to function as normal, the SEA claimed to have changed domain details, redirecting social media traffic to its own server.
The shadowy hacker collective has also claimed to have changed domain details belonging to the Huffington Post news site.
The latest attacks come weeks after the Twitter feed of the Associated Press news agency was targeted.
The feed falsely reported that Barack Obama was injured in an attack on the White House.
The Washington Post website was also hacked this month in an attack blamed on the same group.
The SEA infiltrates organisations it perceives to be aligned against the Assad government.
The string of cyber attacks comes as US leaders have publicly discussed the possibility of launching an attack against the Assad government.
The potential for military action comes amid claims Mr Assad deployed chemical weapons on the Syrian people, two years into the nation's civil war.



New York Times site slow to return for some users after cyber attack

Two days after hackers took down the New York Times website, some readers were still having trouble accessing it Thursday.

The Syrian Electronic Army, a hacktivist group that supports Syrian President Bashar al-Assad, has claimed responsibility for the attack on the Times site.
The Times' website went down for several hours Tuesday after an attack for which the Syrian Electronic Army, a hacktivist group, claimed responsibility. 


Marc Frons, chief information officer at the Times, told employees Tuesday that the SEA "or someone trying very hard to be them" had launched the attack on Melbourne IT, the company's domain name registrar.
The culprits rerouted traffic directed at the Times to other addresses. The Times' computer system wasn't compromised internally.
Melbourne IT said it had fixed the problem by 5 p.m. ET Tuesday, but some users were still having problems accessing the Times site on Wednesday and Thursday. The Times said in an email to readers Thursday afternoon it expected all access to be restored for all users by the end of the day. 

 
Melbourne IT chief technology officer Bruce Tonkin said in an email that users who attempted to access the site while it was down had the incorrect domain records stored temporarily on their computers or servers. It's the computer equivalent of having the wrong telephone number.
After the records are updated for those users, their computers or servers will be able to access nytimes.com again. 

"A rough rule of thumb when trying to make an intentional change to a [domain name system] setting is that it will take 48 hours for the change to fully propagate to all users on the Internet," Tonkin said.
Readers who didn't try to access the site while it was down shouldn't have any problems, he added.
Times spokeswoman Eileen Murphy said Thursday that the company was adopting additional security measures "given the vulnerabilities that this incident exposed at the registrar level."
Melbourne IT said it was reviewing what other layers of security it could add. It recommended that clients utilize special security features to lock their domain names, which the Times apparently hadn't done. 

Alex McGeorge, senior security researcher at Immunity Inc., said the attack underscored the importance of vetting business partners for security weaknesses.
"I think the lesson for companies is that if you've got something that's this significant and this sensitive, you need to demand that the people that provide services to you undergo security audits and make those results available to you," he said. 

Earlier this month, the Syrian Electronic Army breached a news recommendation engine that provides links on news sites including CNN, The Washington Post and Time.