Skip to main content

Home/ Groups/ Future of the Web
Paul Merrell

ISPs say the "massive cost" of Snooper's Charter will push up UK broadband bills | Ars ... - 0 views

  • How much extra will you have to pay for the privilege of being spied on?
  • UK ISPs have warned MPs that the costs of implementing the Investigatory Powers Bill (aka the Snooper's Charter) will be much greater than the £175 million the UK government has allotted for the task, and that broadband bills will need to rise as a result. Representatives from ISPs and software companies told the House of Commons Science and Technology Committee that the legislation greatly underestimates the "sheer quantity" of data generated by Internet users these days. They also pointed out that distinguishing content from metadata is a far harder task than the government seems to assume. Matthew Hare, the chief executive of ISP Gigaclear, said with "a typical 1 gigabit connection to someone's home, over 50 terabytes of data per year [are] passing over it. If you say that a proportion of that is going to be the communications data—the record of who you communicate with, when you communicate or what you communicate—there would be the most massive and enormous amount of data that in future an access provider would be expected to keep. The indiscriminate collection of mass data across effectively every user of the Internet in this country is going to have a massive cost."
  • Moreover, the larger the cache of stored data, the more worthwhile it will be for criminals and state-backed actors to gain access and download that highly-revealing personal information for fraud and blackmail. John Shaw, the vice president of product management at British security firm Sophos, told the MPs: "There would be a huge amount of very sensitive personal data that could be used by bad guys.
  • ...2 more annotations...
  • The ISPs also challenged the government's breezy assumption that separating the data from the (equally revealing) metadata would be simple, not least because an Internet connection is typically being used for multiple services simultaneously, with data packets mixed together in a completely contingent way. Hare described a typical usage scenario for a teenager on their computer at home, where they are playing a game communicating with their friends using Steam; they are broadcasting the game using Twitch; and they may also be making a voice call at the same time too. "All those applications are running simultaneously," Hare said. "They are different applications using different servers with different services and different protocols. They are all running concurrently on that one machine." Even accessing a Web page is much more complicated than the government seems to believe, Hare pointed out. "As a webpage is loading, you will see that that webpage is made up of tens, or many tens, of individual sessions that have been created across the Internet just to load a single webpage. Bluntly, if you want to find out what someone is doing you need to be tracking all of that data all the time."
  • Hare raised another major issue. "If I was a software business ... I would be very worried that my customers would not buy my software any more if it had anything to do with security at all. I would be worried that a backdoor was built into the software by the [Investigatory Powers] Bill that would allow the UK government to find out what information was on that system at any point they wanted in the future." As Ars reported last week, the ability to demand that backdoors are added to systems, and a legal requirement not to reveal that fact under any circumstances, are two of the most contentious aspects of the new Investigatory Powers Bill. The latest comments from industry experts add to concerns that the latest version of the Snooper's Charter would inflict great harm on civil liberties in the UK, and also make security research well-nigh impossible here. To those fears can now be added undermining the UK software industry, as well as forcing the UK public to pay for the privilege of having their ISP carry out suspicionless surveillance.
Paul Merrell

Report: Germany Spied on FBI, US Companies, French Minister - 0 views

  • German public radio station rbb-Inforadio reported Wednesday that the country's foreign intelligence agency spied on the FBI and U.S. arms companies, adding to a growing list of targets among friendly nations the agency allegedly eavesdropped on.The station claimed that Germany's BND also spied on the International Criminal Court in The Hague, the World Health Organization, French Foreign Minister Laurent Fabius and even a German diplomat who headed an EU observer mission to Georgia from 2008 to 2011. It provided no source for its report, but the respected German weekly Der Spiegel also reported at the weekend that the BND targeted phone numbers and email addresses of officials in the United States, Britain, France, Switzerland, Greece, the Vatican and other European countries, as well as at international aid groups such as the Red Cross. The claims are particularly sensitive in Germany because the government reacted with anger two years ago to reports that the U.S. eavesdropped on German targets, including Chancellor Angela Merkel, who declared at the time that "spying among friends, that's just wrong."German lawmakers have broadened a probe into the U.S. National Security Agency's activities in the country to include the work of the BND.
Paul Merrell

Microsoft to host data in Germany to evade US spying | Naked Security - 0 views

  • Microsoft's new plan to keep the US government's hands off its customers' data: Germany will be a safe harbor in the digital privacy storm. Microsoft on Wednesday announced that beginning in the second half of 2016, it will give foreign customers the option of keeping data in new European facilities that, at least in theory, should shield customers from US government surveillance. It will cost more, according to the Financial Times, though pricing details weren't forthcoming. Microsoft Cloud - including Azure, Office 365 and Dynamics CRM Online - will be hosted from new datacenters in the German regions of Magdeburg and Frankfurt am Main. Access to data will be controlled by what the company called a German data trustee: T-Systems, a subsidiary of the independent German company Deutsche Telekom. Without the permission of Deutsche Telekom or customers, Microsoft won't be able to get its hands on the data. If it does get permission, the trustee will still control and oversee Microsoft's access.
  • Microsoft CEO Satya Nadella dropped the word "trust" into the company's statement: Microsoft’s mission is to empower every person and every individual on the planet to achieve more. Our new datacenter regions in Germany, operated in partnership with Deutsche Telekom, will not only spur local innovation and growth, but offer customers choice and trust in how their data is handled and where it is stored.
  • On Tuesday, at the Future Decoded conference in London, Nadella also announced that Microsoft would, for the first time, be opening two UK datacenters next year. The company's also expanding its existing operations in Ireland and the Netherlands. Officially, none of this has anything to do with the long-drawn-out squabbling over the transatlantic Safe Harbor agreement, which the EU's highest court struck down last month, calling the agreement "invalid" because it didn't protect data from US surveillance. No, Nadella said, the new datacenters and expansions are all about giving local businesses and organizations "transformative technology they need to seize new global growth." But as Diginomica reports, Microsoft EVP of Cloud and Enterprise Scott Guthrie followed up his boss’s comments by saying that yes, the driver behind the new datacenters is to let customers keep data close: We can guarantee customers that their data will always stay in the UK. Being able to very concretely tell that story is something that I think will accelerate cloud adoption further in the UK.
  • ...2 more annotations...
  • Microsoft and T-Systems' lawyers may well think that storing customer data in a German trustee data center will protect it from the reach of US law, but for all we know, that could be wishful thinking. Forrester cloud computing analyst Paul Miller: To be sure, we must wait for the first legal challenge. And the appeal. And the counter-appeal. As with all new legal approaches, we don’t know it is watertight until it is challenged in court. Microsoft and T-Systems’ lawyers are very good and say it's watertight. But we can be sure opposition lawyers will look for all the holes. By keeping data offshore - particularly in Germany, which has strong data privacy laws - Microsoft could avoid the situation it's now facing with the US demanding access to customer emails stored on a Microsoft server in Dublin. The US has argued that Microsoft, as a US company, comes under US jurisdiction, regardless of where it keeps its data.
  • Running away to Germany isn't a groundbreaking move; other US cloud services providers have already pledged expansion of their EU presences, including Amazon's plan to open a UK datacenter in late 2016 that will offer what CTO Werner Vogels calls "strong data sovereignty to local users." Other big data operators that have followed suit: Salesforce, which has already opened datacenters in the UK and Germany and plans to open one in France next year, as well as new EU operations pledged for the new year by NetSuite and Box. Can Germany keep the US out of its datacenters? Can Ireland? Time, and court cases, will tell.
  •  
    The European Community's Court of Justice decision in the Safe Harbor case --- and Edward Snowden --- are now officially downgrading the U.S. as a cloud data center location. NSA is good business for Europeans looking to displace American cloud service providers, as evidenced by Microsoft's decision. The legal test is whether Microsoft has "possession, custody, or control" of the data. From the info given in the article, it seems that Microsoft has done its best to dodge that bullet by moving data centers to Germany and placing their data under the control of a European company. Do ownership of the hardware and profits from their rent mean that Microsoft still has "possession, custody, or control" of the data? The fine print of the agreement with Deutsche Telekom and the customer EULAs will get a thorough going over by the Dept. of Justice for evidence of Microsoft "control" of the data. That will be the crucial legal issue. The data centers in Germany may pass the test. But the notion that data centers in the UK can offer privacy is laughable; the UK's legal authority for GCHQ makes it even easier to get the data than the NSA can in the U.S.  It doesn't even require a court order. 
Gonzalo San Gil, PhD.

Microsoft keeps pushing Windows 10 upgrades without users' permission - 0 views

  •  
    "Microsoft says its most recent attempt to force older systems to upgrade to Windows 10 was caused by a bug in the Windows Update utility."
Gonzalo San Gil, PhD.

Review: Graylog delivers open source log management for the dedicated do-it-yourselfer ... - 0 views

  •  
    "By Joel Snyder Network World | Nov 9, 2015 3:06 AM PT RELATED TOPICS Open Source Subnet Network Management System Management Comments In most big security breaches, there's a familiar thread: something funny was going on, but no one noticed. The information was in the logs, but no one was looking for it. Logs from the hundreds or thousands of network devices are the secret sauce to problem solving, security alerting, and performance and capacity management. Gathering logs together, analyzing them, "
Gonzalo San Gil, PhD.

Review: Graylog delivers open source log management for the dedicated do-it-yourselfer ... - 0 views

  •  
    [... "Graylog is an open-source log management tool, complete with a three-tier architecture, super-scalable storage (based on Elasticsearch), an easy-to-use web interface, and a powerful toolkit to parse messages, build ad-hoc dashboards, and set alerts on logs. ...]
Gonzalo San Gil, PhD.

Tor Director Accuses FBI of Spending $1 Million to Attack Tor Users - 1 views

  •  
    "Short Bytes: In a blog post, Tor Director has outlined the unethical ways that were employed by FBI to unmask Tor users. He added that the invasion of people's privacy on a wholesale level is unacceptable by crossing the ethical lines between research and targeting innocent users."
Gonzalo San Gil, PhD.

"A Very Big Mistake": Joseph Stiglitz Slams Obama for Pushing the TPP | Democracy Now! ... - 0 views

  •  
    "Stiglitz about the trade deal. "The irony is that the president came out and said, 'This is about who makes the trade rules-China or the United States?'" Stiglitz said. "But I think the big issue is, this is about who makes the rules of trade-the American people, our democratic process, or the corporations? And who they're made for, which is, for the corporations or for all of us?""
Gonzalo San Gil, PhD.

How to record and edit screencasts in Linux | Opensource.com - 1 views

  •  
    [... One of the methods many community leads are attracted to is the creation of online videos that highlight such use cases in clear, easy-to-follow narratives. Recording screencasts like this is actually a pretty straightforward operation. ...]
Gonzalo San Gil, PhD.

Swedish Pirates are More Likely to Buy Legal Content - TorrentFreak - 0 views

  •  
    " Andy on November 12, 2015 C: 27 Breaking As the entertainment industries catch up, fewer and fewer Swedish citizens are using unauthorized file-sharing networks. That's according to a new study which has found that just 18% of the population now engages in the hobby. Nevertheless, those that do pirate are dramatically more likely to buy legal content than those who don't."
Gonzalo San Gil, PhD.

Filmmakers Sue Dutch State Over Lost Piracy Revenue - TorrentFreak - 0 views

  •  
    " Ernesto on November 12, 2015 C: 10 Breaking A coalition of Dutch film producers and distributors has today announced a lawsuit against the local Government. The filmmakers argue that the authorities are not doing enough to combat piracy and want pirate website operators and their users to face serious legal consequences."
Gonzalo San Gil, PhD.

Why e-mail is killing your business - The Globe and Mail - 0 views

  •  
    "Following a recent keynote I delivered, somebody asked me why an innovation guy like me would still be using a device as passé as a BlackBerry. "Two words," I responded: "No typos.""
Gonzalo San Gil, PhD.

House Judiciary Committee Hears Concerns From Silicon Valley About Copyright Law | Tech... - 0 views

  •  
    "Unfortunately, this aspect of the tour seems to reinforce the silly idea that copyright law is a battle between "Silicon Valley" vs. "Hollywood" -- and that what's good for one is bad for the other. "
  •  
    "Unfortunately, this aspect of the tour seems to reinforce the silly idea that copyright law is a battle between "Silicon Valley" vs. "Hollywood" -- and that what's good for one is bad for the other. "
Gonzalo San Gil, PhD.

The Red Hat/MS Agreement Molehill | FOSS Force - 0 views

  •  
    Larry Cafiero First, let me thank those who took the time to alert me last week to the agreement between Red Hat and Microsoft on holding hands in the cloud. All the concern shown in the emails and social media posts were completely welcome, and could be broken up into two basic sentiments: curiosity about my reaction and serving me some crow to eat.
  •  
    Larry Cafiero First, let me thank those who took the time to alert me last week to the agreement between Red Hat and Microsoft on holding hands in the cloud. All the concern shown in the emails and social media posts were completely welcome, and could be broken up into two basic sentiments: curiosity about my reaction and serving me some crow to eat.
Gonzalo San Gil, PhD.

All Things Open interview with Alexis Rossi and Vicky Brasseur | Opensource.com - 0 views

  •  
    "How the Internet Archive maintains an information super highway Posted 10 Nov 2015 by Seth Kenlon"
Paul Merrell

As Belgium threatens fines, Facebook's defence of tracking visitors rings hollow | nsnb... - 0 views

  • Facebook has been ordered by a Belgian court to stop tracking non-Facebook users when they visit the Facebook site. Facebook has been given 48 hours to stop the tracking or face possible fines of up to 250,000 Euro a day.
  • Facebook has said that it will appeal the ruling, claiming that since their european headquarters are situated in Ireland, they should only be bound by the Irish Data Protection Regulator. Facebook’s chief of security Alex Stamos has posted an explanation about why non-Facebook users are tracked when they visit the site. The tracking issue centres around the creation of a “cookie” called “datr” whenever anyone visits a Facebook page. This cookie contains an identification number that identifies the same browser returning each time to different Facebook pages. Once created, the cookie will last 2 years unless the user explicitly deletes it. The cookie is created for all visitors to Facebook, irrespective of whether they are a Facebook user or even whether they are logged into Facebook at the time. According to Stamos, the measure is needed to: Prevent the creation of fake and spammy accounts Reduce the risk of someone’s account being taken over by someone else Protect people’s content from being stolen Stopping denial of service attacks against Facebook
  • The principle behind this is that if you can identify requests that arrive at the site for whatever reason, abnormal patterns may unmask people creating fake accounts, hijacking a real account or just issuing so many requests that it overwhelms the site. Stamos’ defence of tracking users is that they have been using it for the past 5 years and nobody had complained until now, that it was common practice and that there was little harm because the data was not collected for any purpose other than security. The dilemma raised by Facebook’s actions is a common one in the conflicting spheres of maintaining privacy and maintaining security. It is obvious that if you can identify all visitors to a site, then it is possible to determine more information about what they are doing than if they were anonymous. The problem with this from a moral perspective is that everyone is being tagged, irrespective of whether their intent was going to be malicious or not. It is essentially compromising the privacy of the vast majority for the sake of a much smaller likelihood of bad behaviour.
  •  
    I checked and sure enough: five Facebook cookies even though I have no Facebook account. They're gone now, and I've created an exception blocking Facebook from planting more cookies on my systems. 
Gonzalo San Gil, PhD.

HTTPS certificates with forbidden domains issued by "quite a few" CAs | Ars Technica UK - 0 views

  •  
    "Certs for "mailarchive" and other internal names could threaten entire Internet. by Dan Goodin (US) - Nov 10, 2015 7:35am CET"
Gonzalo San Gil, PhD.

WordPress now powers 25% of the Web | VentureBeat | Apps | by Emil Protalinski - 1 views

  •  
    "One in four websites is now powered by WordPress. Today is a big day for the free and open-source content management system (CMS). To be perfectly clear, the milestone figure doesn't represent a fraction of all websites that have a CMS: WordPress now powers 25 percent of the Web."
Gonzalo San Gil, PhD.

MPAA: Online Privacy Hurts Anti-Piracy Enforcement - TorrentFreak [# ! Note] - 0 views

  •  
    " Ernesto on November 9, 2015 C: 89 Breaking The MPAA has submitted an overview of international "trade barriers" to the U.S. Government, which they see as harmful to the video and movie industries. Online privacy is listed as a serious problem, as it prevents copyright holders and local authorities from going after online pirates."
Gonzalo San Gil, PhD.

The Decline of Linux Diversity - Datamation - 1 views

  •  
    "But is the decline reason for alarm? That is harder to decide until you start looking at other evidence. Diversity vs. Sufficiency"
« First ‹ Previous 1001 - 1020 of 3829 Next › Last »
Showing 20 items per page