Quotulatiousness

April 11, 2011

SSL is “just an illusion of security”

Filed under: Technology — Tags: , , , , — Nicholas @ 10:09

SSL (Secure Sockets Layer) is critically important to safe communications on the internet. It may also be “hopelessly broken“:

SSL made its debut in 1994 as a way to cryptographically secure e-commerce and other sensitive internet communications. A private key at the heart of the system allows website operators to prove that they are the rightful owners of the domains visitors are accessing, rather than impostors who have hacked the users’ connections. Countless websites also use SSL to encrypt passwords, emails and other data to thwart anyone who may be monitoring the traffic passing between the two parties.

It’s hard to overstate the reliance that websites operated by Google, PayPal, Microsoft, Bank of America and millions of other companies place in SSL. And yet, the repeated failures suggest that the system in its current state is hopelessly broken.

“Right now, it’s just an illusion of security,” said Moxie Marlinspike, a security researcher who has repeatedly poked holes in the technical underpinnings of SSL. “Depending on what you think your threat is, you can trust it on varying levels, but fundamentally, it has some pretty serious problems.”

Although SSL’s vulnerabilities are worrying, critics have reserved their most biting assessments for the business practices of Comodo, VeriSign, GoDaddy and the other so-called certificate authorities, known as CAs for short. Once their root certificates are included in Internet Explorer, Firefox and other major browsers, they can’t be removed without creating disruptions on huge swaths of the internet.

April 9, 2011

Upheaval in Finnish politics?

Filed under: Europe, Government, Media, Politics — Tags: , , , , — Nicholas @ 00:03

Ilkka is enjoying the spectacle of the “right-thinking” (i.e., left-thinking) folks in Finland who are horrified at the rise of a new party:

Canada will have yet another federal election that will bring yet another minority government, and back in the old country, the parliamentary elections have begun with the first early voting days, and the right-wing protest party True Finns is predicted to grab a significant chunk of the parliamentary seats. The impotent tantrum of the SWPL greens and leftists, along with the media that they still mostly control, reacting to the cognitive dissonance of the working class abandoning them has certainly been a laugh riot. Besides, this whole surge illustrates how just one voice of just the right pitch can smash a sufficiently ossified, smug and complacent echo chamber to little shards of glass by its mere existence. One can only imagine what the Finland of the 1970’s would have been like, had the Internet existed back then to give these voices a voice, as all leftism and progressivism can keep the reality at bay only if they get to have a totalitarian control of all media to constrain the parameters of debate.

April 4, 2011

Totally underground band loses millions to illegal downloads…or do they?

Filed under: Cancon, Economics, Media, Technology — Tags: , , , — Nicholas @ 09:39

An interesting article looks at a claim by an obscure band that their debut CD had been pirated over 100,000 times:

Late last week, TorrentFreak was contacted by a guy called Wayne Borean who alerted to us to a somewhat heated debate he’d been participating in on the ‘Balanced Copyright For Canada’ Facebook page.

“There’s a Rock Band called One Soul Thrust. They have a debut album, which I like (bought it off iTunes). However the first I heard of the band was when there were complaints that the band had gone Platinum — because of illegal Torrent downloads!” Borean explained.

Indeed, according to a press release from the band’s manager, Cameron Tilbury, the situation is very serious.

“The Canadian Recording Industry Association (CRIA) states that, to achieve Platinum status, an album must achieve sales of 100,000 copies/downloads of an album. Sales…that’s the key. A random polling of several torrent site’s downloads — ILLEGAL downloads — has shown that 1ST, the debut cd by ONE SOUL THRUST has been downloaded over 100,000 times,” he wrote.

That’s really terrible, isn’t it? An obscure band, hoping to make it big by selling their CD have an illegal audience more than 300 times their number of Facebook fans? How did all these illegal downloaders even find out about the band? Well, perhaps they didn’t:

At this point, since we couldn’t find any torrents on any site (Borean tried everywhere too), we have to admit we were beginning to wonder if this 100K download claim was some kind of publicity stunt. Furthermore, since Wayne Borean and Tilbury were starting to publicly tear each other apart (and getting pretty personal at times) it seemed sensible to get to the bottom of this, particularly since the band’s manager claimed that the all-powerful CRIA is supporting the band’s stance.

[. . .]

As many readers will now be aware, there is a huge problem. These results are completely fake and are generated from user input to draw traffic to site advertisers. You can type anything in the search boxes on some of these torrent sites (these apparently came from LimeTorrents) and anyone can appear to be pirated into oblivion [. . .]

We wrote back to Tilbury and explained our findings. We also asked him to comment on how he feels now that he realizes that people aren’t downloading the band’s music at all. He hasn’t responded to that question which is a real shame, because personally I think this is the most important part of the whole story.

I’m absolutely confident that there was no attempt to mislead with the band’s ‘piracy problem’ press release and that the band and their manager sincerely believed that 100K people had downloaded their album without paying for it. However, it would be intriguing to know what happened, when emotions of supposedly being ripped off by 100,000 pirates were replaced by other, perhaps more confused feelings.

Update, 5 April: Apparently you have two choices in a situation like this. 1) Own up to being mistaken and apologize for making a stink about a non-issue. 2) Double-down on stupid:

A day after One Soul Thrust’s manager had the entire Internet explain to him that his band’s music wasn’t being downloaded 100,000 times on BitTorrent sites, he’s still in deep denial. Today’s post is all about how the pirates attacked him “[b]ecause a debut album by an independent Canadian band is listed on torrent sites around the world and we had the audacity to point that out.” Um, no it’s not. It’s not listed on any torrent sites. As far as anyone can tell, not one human being on this planet has torrented this band’s CD. Dude, you made a mistake, you freaked out, you looked a little naive. Now you’re looking like an ass. Quit while you’re ahead, maybe?

Creative comments to that last post include 1) someone, somewhere actually upload the album to a torrent site, just so the band doesn’t look quite as pathetic, and 2) replace each track with varying length versions of a certain Rick Astley tune.

April 3, 2011

Richard Glover: “the internet may bring about the death of human civilisation”

Filed under: Environment, Media, Technology — Tags: , , , — Nicholas @ 12:26

Mr. Glover, a professional broadcaster and columnist, has determined that the collapse of civilization will come from internet trolling denialists:

It’s increasingly apparent that the internet may bring about the death of human civilisation, beating out previous contenders such as nuclear holocaust and the election of George W. Bush.

The agents of this planetary death will be the climate-change deniers who, it’s now clear, owe much of their existence to the internet. Would the climate-change deniers be this sure of themselves without the internet?

Somehow I doubt it. They are so damn confident.

They don’t just bury their heads in the sand, they fiercely drive their own heads energetically into the nearest beachfront, their bums defiantly aquiver as they fart their toxic message to the world. How can they be so confident, in the face of so much evidence to the contrary?

It’s the internet, of course, and the way it has given climate-change deniers the perfect forum — one in which groups of quite dim people can swap spurious information, reassuring each other there’s no evidence on the other side, right up to the point they’ve derailed all efforts to save the planet. Call it ”mutually reassured destruction”.

April 1, 2011

Google introduces “Gmail Motion”

Filed under: Humour, Technology — Tags: , , — Nicholas @ 07:35

Erasing your (digital) past

Filed under: Liberty, Media, Technology — Tags: , , — Nicholas @ 00:08

Eric Schmidt, former CEO of Google said: “I don’t believe society understands what happens when everything is available, knowable, and recorded by everyone all the time.” Privacy is dying, if not already clinically dead, in the online world. If you really want (or need) to airbrush yourself out of the picture, here are some suggestions on how to go about doing it.

The Internet has made our world a lot smaller. It has also made our histories a lot better-catalogued and more-searchable, and those developments — coupled with the weird phenomenon that people’s common sense tends to fly out the window when it comes to posting information and pictures — aren’t always beneficial to us.

[. . .]

Instead of popping you into a Witness Protection program — or changing your name — let us show you five steps on how to disappear from the Internet.

Step 1: Know Thine Enemy

Before you take any action, you need to know what you’re trying to get rid of. So first, do a search for your name — don’t just search Google, though, search online people search aggregation sites such as ZabaSearch, Intelius, Pipl, and Spokeo.

Here’s how to run an online background check (on yourself) for free.

March 29, 2011

Amazon’s “Cloud Drive” announcement

Filed under: Media, Technology — Tags: , , — Nicholas @ 08:17

Tired of moving your music from machine to machine? Feel constricted in your choices? Amazon.com thinks they’ve got an offering you won’t turn down:

Amazon.com, Inc. (NASDAQ:AMZN) today announced the launch of Amazon Cloud Drive (www.amazon.com/clouddrive), Amazon Cloud Player for Web (www.amazon.com/cloudplayer) and Amazon Cloud Player for Android (www.amazon.com/cloudplayerandroid). Together, these services enable customers to securely store music in the cloudand play it on any Android phone, Android tablet, Mac or PC, wherever they are. Customers can easily upload their music library to Amazon Cloud Drive and can save any new Amazon MP3 purchases directly to their Amazon Cloud Drive for free.

“We’re excited to take this leap forward in the digital experience,” said Bill Carr, vice president of Movies and Music at Amazon. “The launch of Cloud Drive, Cloud Player for Web and Cloud Player for Android eliminates the need for constant software updates as well as the use of thumb drives and cables to move and manage music.”

“Our customers have told us they don’t want to download music to their work computers or phones because they find it hard to move music around to different devices,” Carr said. “Now, whether at work, home, or on the go, customers can buy music from Amazon MP3, store it in the cloud and play it anywhere.”

Don’t get too excited, fellow Canadians: this is the .com company, not the .ca flavour. Since amazon.ca still can’t sell you MP3 tracks, I doubt that the Amazon Cloud will be available north of the border any time soon.

March 27, 2011

Rogers is actively throttling bandwidth for World of Warcraft players

Filed under: Cancon, Gaming, Technology — Tags: , — Nicholas @ 11:14

In what isn’t really a surprise, Justin Olivetti reports on how Canadian WoW players have been suffering from deliberate throttling:

If you play World of Warcraft in Canada and were wondering why your connection seemed a bit slow, it turns out there may be a good explanation: Rogers Communications has been deliberately throttling the game across the country.

[. . .]

Rogers said that it was Blizzard’s use of BitTorrent to deliver updates that triggered the throttling, and said that customers who disabled this setting — as well as any other peer-to-peer applications — would not see a slowdown in speed. “Rogers will engage our customers to ensure they are aware of these recommendations, while continuing to work on a longer term solution,” a spokesperson said.

March 24, 2011

Online security: compromised HTTPS certificates

Filed under: Technology — Tags: , , , — Nicholas @ 09:25

Iranian hackers (or someone trying to cast blame on Iran) managed to get a number of HTTPS certificates issued under false colours:

On March 15th, an HTTPS/TLS Certificate Authority (CA) was tricked into issuing fraudulent certificates that posed a dire risk to Internet security. Based on currently available information, the incident got close to — but was not quite — an Internet-wide security meltdown. As this post will explain, these events show why we urgently need to start reinforcing the system that is currently used to authenticate and identify secure websites and email systems.

[. . .]

Comodo also said that the attack came primarily from Iranian IP addresses, and that one of the fraudulent login.yahoo.com certs was briefly deployed on a webserver in Iran.

March 20, 2011

Hacking a secure WiFi connection not illegal, says Dutch court

Filed under: Europe, Law, Technology — Tags: , , , , — Nicholas @ 11:09

An interesting legal precedent may not be as far-reaching as the headline might imply:

Breaking in to an encrypted router and using the WiFi connection is not an criminal offence, a Dutch court ruled. WiFi hackers can not be prosecuted for breaching router security.

A court in The Hague ruled earlier this month that it is legal to break WiFi security to use the internet connection. The court also decided that piggybacking on open WiFi networks in bars and hotels can not be prosecuted. In many countries both actions are illegal and often can be fined.

[. . .]

The Judge reasoned that the student didn’t gain access to the computer connected to the router, but only used the routers internet connection. Under Dutch law breaking in to a computer is forbidden.

A computer in The Netherlands is defined as a machine that is used for three things: the storage, processing and transmission of data. A router can therefore not be described as a computer because it is only used to transfer or process data and not for storing bits and bytes. Hacking a device that is no computer by law is not illegal, and can not be prosecuted, the court concluded.

The key here is the definition of a computer under the law: I expect the Dutch to update this definition in response to the outcome of this case.

March 8, 2011

Lastest boon to spammers? The move to IPv6, apparently

Filed under: Technology — Tags: , , , — Nicholas @ 08:50

John Leyden reports that with all the good things about moving to the vastly larger address space of IPv6, we can expect at least one negative:

The migration towards IPv6, which has been made necessary by the expansion of the internet, will make it harder to filter spam messages, service providers warn.

The current internet protocol, IPv4, has a limited address space which is reaching exhaustion thanks to the fast uptake of internet technology in populous countries such as India and China and the more widespread use of smartphones. IPv6 promises 3.4 x 1038 addresses compared to the paltry 4.3 billion (4.3 x 109) addresses offered by IPv4.

While this expansion allows far more devices to have a unique internet address, it creates a host of problems for security service providers, who have long used databases of known bad IP addresses to maintain blacklists of junk mail cesspools. Spam-filtering technology typically uses these blacklists as one (key component) in a multi-stage junk mail filtering process that also involves examining message contents.

“The primary method for stopping the majority of spam used by email providers is to track bad IP addresses sending email and block them — a process known as IP blacklisting,” explained Stuart Paton, a senior solutions architect at spam-filtering outfit Cloudmark. “With IPv6 this technique will no longer be possible and could mean that email systems would quickly become overloaded if new approaches are not developed to address this.”

March 5, 2011

xkcd re-interprets the Nolan Chart

Filed under: Humour, Liberty, Media — Tags: , , , — Nicholas @ 11:36

Nolan Chart

February 26, 2011

Arrested, beaten, tortured, and charged with treason . . . for watching viral videos

Filed under: Africa, Law, Liberty, Media — Tags: , , , , , — Nicholas @ 11:00

No matter how you say it, Zimbabwe is seriously screwed up:

Munyaradzi Gwisai, a lecturer at the University of Zimbabwe’s law school, was showing internet videos about the tumult sweeping across North Africa to students and activists last Saturday, when state security agents burst into his office.

The agents seized laptop computers, DVD discs and a video projector before arresting 45 people, including Gwisai, who runs the Labor Law Center at the University of Zimbabwe. All 45 have been charged with treason — which can carry a sentence of life imprisonment or death — for, in essence, watching viral videos.

Gwisai and five others were brutally tortured during the next 72 hours, he testified Thursday at an initial hearing.

There were “assaults all over the detainees’ bodies, under their feet and buttocks through the use of broomsticks, metal rods, pieces of timber, open palms and some blunt objects,” The Zimbabwean newspaper reports, in an account of the court proceedings.

Under dictator Robert Mugabe, watching internet videos in Zimbabwe can be a capital offense, it would seem. The videos included BBC World News and Al-Jazeera clips, which Gwisai had downloaded from Kubatana, a web-based activist group in Zimbabwe.

February 22, 2011

Former UK Home Secretary shocked to discover the internet awash in porn

Filed under: Britain, Government, Law, Liberty — Tags: , , , — Nicholas @ 07:52

The amusing thing is that she lead a major effort to suppress “extreme porn” while in office:

Former Home Secretary Jacqui Smith has professed herself “shocked” at the availability of porn on the internet after investigating the issue for a radio documentary.

Which raises the question of what exactly she thought she was cracking down on during her time in charge of law and order.

[. . .]

Smith told the Radio Times that during her research for the documentary, she had been “shocked” to discover how much hard-core material was washing around the net. And so much of it for absolutely no cost at all.

She admitted that after the pay-per-view smut scandal had broken, her son had said: “Dad, haven’t you heard of the internet?” Smith was also shocked by a visit to the Erotica exhibition, where confronted by the likes of the Monkey Spanker and artisan-built bondage furniture, “I felt completely innocent.

That Smith was ignorant of the amount of porn available on the internet seems incredible, given that during her time in government Labour cracked down hard on “extreme porn”. Smith’s Home Office also sought to clamp down on extremism on the internet, and to track all the UK’s browsing habits via a vast uber-database, the Interception Modernisation Programme. Surely some her staff might have noticed there’s lots of smut out there as well?

February 19, 2011

When “hacker army” is not an exaggeration

Filed under: Britain, China, Government, Military, Russia, Technology — Tags: , , , , , — Nicholas @ 10:07

Strategy Page counts noses of the various semi-organized hacker armies out in the wild:

Despite spending over a billion dollars a year defending their government networks, Britain recently complained openly of hackers getting into the communications network of the Foreign Office. The government also warned of increasing attacks on British companies. The recent attacks government and corporations were all targeting specific people and data. While China was not mentioned in these official announcements, British officials have often discussed how investigations of recent hacking efforts tended to lead back to China. There is also a strong suspicion, backed up by hacker chatter, that governments are offering large bounties for information from foreign governments. Not information from China, but from everyone else.

China one of many nations taking advantage of the Internet to encourage, or even organize, patriotic Internet users to obtain hacking services. This enables the government to use (often informally) these thousands of hackers to attack targets (foreign or domestic.) These government organizations arrange training and mentoring to improve the skills of group members. Turkey has over 45,000 of hackers organized this way, Saudi Arabia has over 100,000, Iraq has over 40,000, Russia over 100,000 and China, over 400,000. While many of these Cyber Warriors are rank amateurs, even the least skilled can be given simple tasks. And out of their ranks will emerge more skilled hackers, who can do some real damage. These hacker militias have also led to the use of mercenary hacker groups, who will go looking for specific secrets, for a price. Chinese companies are apparently major users of such services, judging from the pattern of recent hacking activity, and the fact that Chinese firms don’t have to fear prosecution for using such methods.

It was China that really pioneered the militia activity. It all began in the late 1990s, when the Chinese Defense Ministry established the “NET Force.” This was initially a research organization, which was to measure China’s vulnerability to attacks via the Internet. Soon this led to examining the vulnerability of other countries, especially the United States, Japan and South Korea (all nations that were heavy Internet users). NET Force has continued to grow. NET Force was soon joined by an irregular civilian militia; the “Red Hackers Union” (RHU). These are nearly half a million patriotic Chinese programmers, Internet engineers and users who wished to assist the motherland, and put the hurt, via the Internet, on those who threaten or insult China. The RHU began spontaneously in 1999 (after the U.S. accidentally bombed the Chinese embassy in Serbia), but the government has assumed some control, without turning the voluntary organization into another bureaucracy. The literal name of the group is “Red Honkers Union,” with Honker meaning “guest” in Chinese. But these were all Internet nerds out to avenge insults to the motherland.

You have to wonder how many script kiddies ever thought they’d end up being government operatives.

« Newer PostsOlder Posts »

Powered by WordPress