Showing posts with label policy. Show all posts
Showing posts with label policy. Show all posts

Saturday, March 26, 2011

Hey AT&T customers: Your Facebook data went to China and S. Korea this morning…

From Barrett Lyons's Blog,

Quietly this morning customers of AT&T browsing Facebook did so by way of China then Korea. Typically AT&T customers’ data would have routed over the AT&T network directly to Facebook’s network provider but due to a routing mistake their private data went first to Chinanet then via Chinanet to SK Broadband in South Korea, then to Facebook. This means that anything you looked at via Facebook without encryption was exposed to anyone operating Chinanet, which has a very suspect Modus operandi.
This morning’s route to Facebook from AT&T:

route-server>show ip bgp 69.171.224.13 (Facebook's www IP address)
BGP routing table entry for 69.171.224.0/20, version 32605349
Paths: (18 available, best #6, table Default-IP-Routing-Table)
Not advertised to any peer
7018 4134 9318 32934 32934 32934

The AS path (routing path) translates to this:

1. AT&T (AS7018)
2. Chinanet (Data in China AS4134)
3. SK Broadband (Data in South Korea AS9318)
4. Facebook (Data back to US 32934)

Current route to Facebook via AT&T:

route-server>sho ip bgp 69.171.224.0/20
BGP routing table entry for 69.171.224.0/20, version 32743195
Paths: (18 available, best #6, table Default-IP-Routing-Table)
Not advertised to any peer
7018 3356 32934 32934, (received & used)

Translated: Your data goes from AT&T’s network to US based Level3 Communications to Facebook’s servers.

What could have happened with your data? Most likely absolutely nothing. Yet, China is well known for it’s harmful networking practices by limiting network functionality and spying on its users, and when your data is flowing over their network, your data could be treated as any Chineese citizens’. Does that include capturing your session ID information, personal information, emails, photos, chat conversations, mappings to your friends and family, etc? One could only speculate, however it’s possible.

This brings up a lot of questions:


  • Should Facebook and or AT&T have notified their customers that their personal information was flowing over a network that they may not trust?
  • Should Facebook enable SSL on all accounts by default?
  • Was this actually a privacy breach or just the way the Internet functions?
  • Does Facebook have an ethical responsibility to buy additional IP connectivity to major broadband and mobile networks to prevent routing mishaps?
  • Is it time to focus on new options within BGP to prevent high profile sites from routing to non-authenticated networks?


This happens all the time — the Internet is just not a trusted network. Yet, I prefer to know that when I am on AT&T’s network, going to US located sites, my packets are not accidentally leaving the country and being subject to another nation’s policies. I guess that’s why you should not use Facebook in “bareback” mode and use HTTPS (SSL) any time you can.

Food for thought.

It’s Tracking Your Every Move and You May Not Even Know

via Noam Cohen at the New York Times,

A favorite pastime of Internet users is to share their location: services like Google Latitude can inform friends when you are nearby; another, Foursquare, has turned reporting these updates into a game.

But as a German Green party politician, Malte Spitz, recently learned, we are already continually being tracked whether we volunteer to be or not. Cellphone companies do not typically divulge how much information they collect, so Mr. Spitz went to court to find out exactly what his cellphone company, Deutsche Telekom, knew about his whereabouts.

The results were astounding. In a six-month period — from Aug 31, 2009, to Feb. 28, 2010, Deutsche Telekom had recorded and saved his longitude and latitude coordinates more than 35,000 times. It traced him from a train on the way to Erlangen at the start through to that last night, when he was home in Berlin.

Mr. Spitz has provided a rare glimpse — an unprecedented one, privacy experts say — of what is being collected as we walk around with our phones. Unlike many online services and Web sites that must send “cookies” to a user’s computer to try to link its traffic to a specific person, cellphone companies simply have to sit back and hit “record.”

“We are all walking around with little tags, and our tag has a phone number associated with it, who we called and what we do with the phone,” said Sarah E. Williams, an expert on graphic information at Columbia University’s architecture school. “We don’t even know we are giving up that data.”

Tracking a customer’s whereabouts is part and parcel of what phone companies do for a living. Every seven seconds or so, the phone company of someone with a working cellphone is determining the nearest tower, so as to most efficiently route calls. And for billing reasons, they track where the call is coming from and how long it has lasted.

“At any given instant, a cell company has to know where you are; it is constantly registering with the tower with the strongest signal,” said Matthew Blaze, a professor of computer and information science at the University of Pennsylvania who has testified before Congress on the issue.

Mr. Spitz’s information, Mr. Blaze pointed out, was not based on those frequent updates, but on how often Mr. Spitz checked his e-mail.

Mr. Spitz, a privacy advocate, decided to be extremely open with his personal information. Late last month, he released all the location information in a publicly accessible Google Document, and worked with a prominent German newspaper, Die Zeit, to map those coordinates over time.

“This is really the most compelling visualization in a public forum I have ever seen,” said Mr. Blaze, adding that it “shows how strong a picture even a fairly low-resolution location can give.”

In an interview from Berlin, Mr. Spitz explained his reasons: “It was an important point to show this is not some kind of a game. I thought about it, if it is a good idea to publish all the data — I also could say, O.K., I will only publish it for five, 10 days maybe. But then I said no, I really want to publish the whole six months.”

In the United States, telecommunication companies do not have to report precisely what material they collect, said Kevin Bankston, a lawyer at the Electronic Frontier Foundation, who specializes in privacy. He added that based on court cases he could say that “they store more of it and it is becoming more precise.”

“Phones have become a necessary part of modern life,” he said, objecting to the idea that “you have to hand over your personal privacy to be part of the 21st century.”

In the United States, there are law enforcement and safety reasons for cellphone companies being encouraged to keep track of its customers. Both the F.B.I. and the Drug Enforcement Administration have used cellphone records to identify suspects and make arrests.

If the information is valuable to law enforcement, it could be lucrative for marketers. The major American cellphone providers declined to explain what exactly they collect and what they use it for.

Verizon, for example, declined to elaborate other than to point to its privacy policy, which includes: “Information such as call records, service usage, traffic data,” the statement in part reads, may be used for “marketing to you based on your use of the products and services you already have, subject to any restrictions required by law.”

AT&T, for example, works with a company, Sense Networks, that uses anonymous location information “to better understand aggregate human activity.” One product, CitySense, makes recommendations about local nightlife to customers who choose to participate based on their cellphone usage. (Many smartphone apps already on the market are based on location but that’s with the consent of the user and through GPS, not the cellphone company’s records.)

Because of Germany’s history, courts place a greater emphasis on personal privacy. Mr. Spitz first went to court to get his entire file in 2009 but Deutsche Telekom objected.

For six months, he said, there was a “Ping Pong game” of lawyers’ letters back and forth until, separately, the Constitutional Court there decided that the existing rules governing data retention, beyond those required for billing and logistics, were illegal. Soon thereafter, the two sides reached a settlement: “I only get the information that is related to me, and I don’t get all the information like who am I calling, who sent me a SMS and so on,” Mr. Spitz said, referring to text messages.

Even so, 35,831 pieces of information were sent to him by Deutsche Telekom as an encrypted file, to protect his privacy during its transmission.

Deutsche Telekom, which owns T-Mobile, Mr. Spitz’s carrier, wrote in an e-mail that it stored six months’ of data, as required by the law, and that after the court ruling it “immediately ceased” storing data.

And a year after the court ruling outlawing this kind of data retention, there is a movement to try to get a new, more limited law passed. Mr. Spitz, at 26 a member of the Green Party’s executive board, says he released that material to influence that debate.

“I want to show the political message that this kind of data retention is really, really big and you can really look into the life of people for six months and see what they are doing where they are.”

While the potential for abuse is easy to imagine, in Mr. Spitz’s case, there was not much revealed.

“I really spend most of the time in my own neighborhood, which was quite funny for me,” he said. “I am not really walking that much around.”

Any embarrassing details? “The data shows that I am flying sometimes,” he said, rather than taking a more fuel-efficient train. “Something not that popular for a Green politician.”

Thursday, February 17, 2011

Federal Officials Call For Better Privacy, Security Protections Online

Via Dennis Fisher at ThreatPost ...

The Obama administration's top information security officials hit the stage at the RSA Conference Tuesday, looking to drum up support for several of the president's key security and privacy initiatives, including a still-nebulous plan for protecting users' freedom and privacy on the Web.

The plea for help from the thousands of security experts and enterprise executives gathered here for RSA came from Howard Schmidt, the president's cybersecurity adviser and Philip Reitinger, the deputy undersecretary of the National Protection and Programs directorate at the Department of Homeland Security, who spoke as part of a town hall meeting on cybersecurity. Schmidt, a former top security official at Microsoft and eBay, used the Internet shutdown that accompanied the recent revolution in Egypt as an example of what President Obama wants to prevent.

"It is incumbent upon all of us to make sure that we preserve those freedoms," Schmidt said. "We're going to hold others accountable on Internet freedom and make sure that we do those same things ourselves. We need to lead by example."

Earlier in the day, Secretary of State Hillary Clinton gave a similar speech to a group of students at George Washington University in which she emphasized the need for some framework of rules to help guarantee a basic level of freedom online.

"For the United States, the choice is clear. On the spectrum of Internet freedom, we place ourselves on the side of openness. Now, we recognize that an open Internet comes with challenges. It calls for ground rules to protect against wrongdoing and harm. And Internet freedom raises tensions, like all freedoms do. But we believe the benefits far exceed the costs," Clinton said.

What's less clear in all of this is exactly what the Obama administration intends to do to achieve these goals. At RSA, Schmidt and Reitinger both said that in order to improve both security and privacy online, the government needs help from the private sector. This has been a common theme in government information security plans for more than a decade and the idea of more public-private partnerships has been dismissed by many in the industry as futile. But Reitinger said that they can work if done correctly.

"When we say public-private partnership, people don't know what we mean. Neither the government nor the private sector can solve these problems on their own," he said. "People hear this and think we're just going to walk away saying kumbaya. That's not what we're talking about. The successful ones actually are a partnership and they're real and outcome-focused."

None of the panelists offered much in the way of specifics on what the administration planned to do, aside from previously announced initiatives such as the plan to create online IDs. But Schmidt stressed that there were plans in the works that would get things moving.

"We need to ensure we have the safeguards in place to protect people," he said. "It's all about collaboration. We need new ways to work faster. It's critical to our future and having that economic engine that we all need."

Sunday, February 13, 2011

Lawmaker Introduces New Privacy Bill

Via the Wall Street Journal ...

Rep. Jackie Speier, D-Calif., introduced a bill Friday that would give the Federal Trade Commission authority to establish an online do-not-track system.

The bill is the first in this session to specifically tackle the creation of a do-not-track system, according to a spokesman for Ms. Speier. In December, the FTC issued a report recommending the creation of a do-not-track system and suggested that lawmakers use the report as a template for legislation.

Since the FTCs recommendation, Mozilla Corp. has said it will include a do-not-track feature in an upcoming version of its Firefox Web browser. But so far, no tracking companies have publicly stated that they will participate in a do-not-track system.

In its newest Internet Explorer browser, Microsoft will allow users to stop certain websites and tracking companies from monitoring them. And Google last month began offering a tool that lets users of its Chrome browser permanently opt out of ad-tracking cookies.

Representatives of the three companies sparred gently over the merits of the differing approaches at a conference Wednesday at the University of California, Berkeley. Alex Fowler, Mozilla’s global privacy and public-policy leader, said it wanted to give users flexibility in choosing the companies they will and won’t allow to track them.

“We’ve done this intentionally because there is a spectrum of values across our users,” Mr. Fowler said. Some “don’t want to see ads or be tracked” at all, while others “see value in free services by receiving free advertising.”

Privacy issues are heating up on Capitol Hill. Earlier this week, Rep. Bobby Rush, D-Ill., re-introduced privacy legislation that he introduced during the last session of Congress. His bill would establish baseline federal privacy laws around the collection of personal data. Rep. John Kerry, D-Mass., is also expected to introduce privacy legislation in the coming weeks.

There is no comprehensive U.S. law that protects consumer privacy online. Internet privacy issues generally are policed by the FTC, which can take action only if a privacy-violating action is deemed “deceptive” or “unfair.” Last year, the Obama Administration called for a Web privacy “bill of rights” to help regulate the personal data collection industry.

Of course, these Democratic bills face challenges in the Republican House of Representatives. Ms. Speier said while the bill has two co-sponsors, both Democrats, she is “hopeful we’ll find Republican co-sponsors — we’re hopeful of finding Tea Party-Republicans, because that’s a closely held value” of Tea Party Conservatives, she told Digits.

Ms. Speier also noted support from the Consumers’ Union, Consumer Action, Consumer Federation of America, Consumers Watchdog and the American Civil Liberties Union. The Congresswoman predicted broad support because “86 percent of the public that has been polled nationally wants to have the option of not being tracked.”

Denying allegations

Interesting thoughts from Lawrence on maintaining our reputations in the digital age ...

Trust and reputation are two important aspects of civilization. The former is often influenced by the latter. You would not trust someone who has been charged with fraud or other such crimes. You would not vote for a politician that has been accused of (often sexually) harassing interns. In the last century, we relied on a wide array of evidence to judge whether the individual was guilty or not. Evidence such as video surveillance tapes, phone records, credit card bills and many other things. I listed these forms of evidence because I want to discuss their legitimacy in court in the 21st century.

Technology has a advanced dramatically in the recent years and we have become capable of incredible feats often experienced in movies (i.e. avatar) or less often in the form online theft (by hackers all over the world) draining your bank account.
My worry is that video surveillance and many other things might be easily altered to fit the crime (or not). Thus undermining their validity as evidence in court.
I’ll give you a few illustrations. Facebook accounts can be hacked, therefor the content also, can be altered. Imagine someone ‘unearthing’ incriminating pictures of you on Facebook and consequently, you are arrested and put on trial. You know that the pictures are fake because you never found yourself in the situation depicted on the picture. Of course you don’t, they were photo-shopped by someone who has something to gain by you going to prison. The jury does not believe your account and sends you to prison for whatever you have done (not fair, I know). Replace Facebook in this whole story with other things like credit card bills or phone call records and come to the same conclusion.

The modern court of tomorrow will pick up on these practices and revise their list of approved forms of evidence (excluding things like mentioned above).
Imagine a politician that did sexually harass an intern and it was caught on tape. This politician happened to have many allies and enemies. In court, the politician could clame that the person on the video is not really him, but a virtually rendered version of him by animators and programmers (think about animated movies these days). The court has reason to believe him because he has many enemies who would gain by faking something like this.

Therefore, technology (hacking etc) can render many forms of evidence useless.

My concern is the way we use the internet and how we behave on it. How will we be able to hold each other accountable (online) if all the things we do (good or bad) can be brushed off as conspiracy if someone presses charges?

Exabytes: Documenting the 'digital age' and huge growth in computing capacity

A hat tip to two of your classmates Katharina and Katie for pointing this Washington Post article out to me ...

Megabytes are dead.

Gigabytes are passe.

So much digital data now moves around the globe that those who endeavor to measure it employ a new - or new to non-nerds - term.

Meet the exabyte.

How much data is an exabyte? It's a billion gigabytes - and it signifies just how digital and data-intensive the world has become.

In 2007, the global capacity to store digital information - on computer hard disks, smartphones, CDs and other digital media - totaled 276 exabytes, a new report finds.

How much is that? Imagine a stack of CDs - each holding an album's worth of digital music - shooting from the top of your desk to 50,000 miles beyond the moon.

But not everyone has equal access to those resources. In fact, the digital gap between rich and poor countries appears to be growing, said Martin Hilbert of the University of Southern California, who led the audacious effort to tally all of civilization's information and computing power.

In 2002, people in developed countries had access to eight times the bandwidth - or information-carrying capacity - of people in poorer nations, Hilbert said, citing data he will publish soon. By 2007, that gap had almost doubled.

"If we want to understand the vast social changes underway in the world, we have to understand how much information people are handling," Hilbert said.

To address that question, Hilbert and co-author Priscila Lopez spent four years poring over 1,110 sources of information spanning from 1986 to 2007, including sales data from computer and cellphone makers and the music and movie industries.

In 1986, a year after digital CDs widely debuted, vinyl records still accounted for 14 percent of all data on Earth, with audiocassettes holding an additional 12 percent.

By 2000, digital media accounted for just 25 percent of all information in the world.

After that, the prevalence of digital media began to skyrocket. In 2002, digital storage capacity outstripped the non-digital variety - mostly paper and videotapes - for the first time.

"That was the turning point," said Hilbert, who published the report in the journal Science. "You could say the digital age started in 2002. It continued tremendously from there."

By 2007, the last year documented in the study, 94 percent of all information storage capacity on Earth was digital. The other 6 percent resided in books, magazines and other non-digital formats, particularly videotape, Hilbert and Lopez found.

But despite the forecasts of futurists, a paperless world has not arrived. Although stupendously outstripped in growth by digital media, the amount of paper produced for books, magazines, newspapers and office use climbed steadily over the two decades of the study.

As for computing power - the number of calculations per second available in all of the computers in the world - that grew faster than even information storage, muscling ahead at an average annual growth rate of 58 percent over 21 years. Information storage, in contrast, grew at a rate of 23 percent.

Of course, for anyone tethered to an iPhone, Gmail and Facebook all day, all of this probably comes as no surprise.

That daily digital activity contributes to a churning information tsunami. Humans generate enough data - from TV and radio broadcasts, telephone conversations and, of course, Internet traffic - to fill our 276 exabyte storage capacity every eight weeks, Hilbert said. Of course, most of the digital traffic is never stored long term, evaporating into the ether.

The study prompts deep questions, one of which Hilbert plans to explore soon: How much of this data deluge is truly useful? Or, as Hilbert distilled it, "What's the value of watching a silly cat video versus reading an overpriced book?"

While we wait for an answer, social scientists worry that the mounting data carry a hidden cost: disconnection from one another.

"We'd like to think that [information technology] changes everything, that the amazing statistics these authors cite mean that our society has fundamentally and irreversibly changed," said Thomas J. Misa, who studies the history of technology at the University of Minnesota. "I'm a bit more skeptical." After all, Misa said, "there are still secret prisons in Cairo where government agents savagely beat people. Cellphones and social media didn't change that."

Perhaps not, but widespread reports from Egypt suggest that online social networking contributed to - or even prompted - the ongoing demonstrations there.

The study also found that Earth had 3.4 billion cellphones in 2007, with telecommunications traffic growing at an average rate of 28 percent per year between 1986 and 2007. That's a lot of minutes on your plan.

In a second report Hilbert plans to publish in a few months, he found that an ever-increasing slice of our daily data resides not on home computers and the smartphones in our pockets, but in giant data warehouses owned by Google, Facebook, Citibank, the federal government and other huge entities. Microsoft's recent ad campaign touts the benefits of moving all of your personal data to "the cloud," invoking white puffs that magically - and cleanly - store our home photos.

The reality is much dirtier. In 2006, the nation's "server farms" - the home of the cloud - sucked down 1.5 percent of all electricity in the United States, double the amount used in 2000, the Environmental Protection Agency reported. Congress ordered the report out of concern that our insatiable demand for Facebook and YouTube would push the United States to build 10 new pollution-spewing coal plants.

But Hilbert offers a humbling comparison. Despite our gargantuan digital growth, the DNA in a single human body still stores far more information - and a single human brain computes far more calculations - than all the technology on Earth.

"Compared to Mother Nature," Hilbert said, "we are humble apprentices."

Monday, February 7, 2011

Fake Dating Site Lifts Pictures And Names from Facebook -- Without Asking

From the San Francisco Chronicle ...

A pair of artists gathered the public profiles of more than 1 million Facebook users, then took the pictures and created a fake dating site called Lovely-Faces.com.

Users can search based on nationality, traits like "easy going," and gender, or can simply enter a name and see if they're in the database. When users click a result to "arrange a date," they're taken to the person's public Facebook profile.

The site scraped Facebook data without permission, and the company told Wired that it's not amused and will "take appropriate action."

Basically, it looks like an awkward commentary on the shallowness of online dating profiles and Facebook's confusing privacy policies, but violating privacy to make a point about privacy doesn't work very well.The artists, Paolo Cirio and Alessandro Ludovico, tried to explain their point in a press release issued yesterday (PDF here), but it's basically a bunch of gibberish -- or maybe that's part of the art.

Did the Internet Kill Privacy?

From CBSNews ...

"For the first time, people were sneaking around taking photos of other people without their permission," said Lane.

It sparked a 1890 Harvard Law Review article in which future Supreme Court Justice Louis Brandeis and attorney Samuel Warren warned against an ongoing loss of privacy!

Today, one of the fastest-growing businesses on the Internet is something called data mining: companies collecting our private information, packaging it, using it, selling it.

Michael Fertik, a Harvard Law School grad who runs a company called Reputation.com, came up with information I thought was private. I was wrong.

"I think this is your Social Security number," Fertik said. It was!

He also revealed what he called my "online reputation," based mainly on where I happen to live.

"Our query is pretty confident that you're a Democrat and pretty confident that you're a Catholic," Fertik said.

"But that may not be correct," said Moriarty.

"It may just not be correct," he explained.

And then there's something that could cause a real headache down the road …

"There's an Erin F. Moriarty who grew up just a few miles where you did, who has been convicted of serving alcohol to minors," Fertik said. "And it'd be very easy for a machine to confuse you and that person, and to think that you are a convicted criminal."

Even though the OTHER Erin is 20 years younger!

Fertik's company helps people track down and correct misinformation. But most of us will never even know it's there.

"The dossier on each of us that is easily aggregated digitally is now probably, let's call it ten pages," Fertik said. "Four years ago it was two pages. In four or five years, it's going to be 100 pages. Why? Because the amount of data that is being collected about each of us, proliferates. Your phone records, your rental records, those different databases that no one originally intended to be combined with one another are being combined now with blazing speed."

But David J. Moore, who runs 24/7 RealMedia, an Internet advertising firm, seems unfazed.

He points out that marketing information about potential customers is really nothing new.

"Magazine publishers for years have been selling the list of subscribers they have to the advertisers that want to send a mailing to them," he said.

And keep in mind: the more specific and detailed the information, the better companies can target their advertisements to customers who really want it.

"Let's ask the 500 million people that are on Facebook how concerned are they about their privacy," Moore said. "Or the 100 million that are on MySpace? Most of them really don't care."

Don't tell that to high school teacher Ashley Payne.

"Yes, I put it on the Internet, so you can make that argument," she said. "But it sort of feels like the same thing as if I had put the pictures in a shoebox in my house and someone came in and took them and showed one of them to the principal."

What's worse, after she resigned her job at Apalachee High School, Payne says she learned the original complaint came in an anonymous e-mail - not in a phone call from an angry parent.

"No parent has ever claimed it," Payne said. "There's never been any other complaints against me at this school from teachers, students or parents."

Officials at the Barrow County Schools, who declined to speak to "Sunday Morning," have so far refused to re-hire Payne.

In court documents, they say teachers were warned about "unacceptable online activities" by the district. Payne's page, they say, "promoted alcohol use" and "contained profanity."

She is now in graduate school and is suing the district. She says she wants to be sure that the Internet won't just record how Ashley Payne lost her job, but that she fought back.

"I want to clear my name, first of all," she said. "And I just want to be back in the classroom, if not that classroom, a classroom. I want to get back doing what I went to school for, my passion in life."

Thursday, February 3, 2011

Vodafone network 'hijacked' by Egypt

From the BBC ...

Mobile phone firm Vodafone has accused the Egyptian authorities of using its network to send unattributed text messages supporting the government.

Vodafone was told to switch off services last week when protests against President Hosni Mubarak began.

But the authorities then ordered Vodafone to switch the network back on, in order to send messages under Egypt's emergency laws, the firm said.

In a statement, Vodafone described the messages as "unacceptable".

"These messages are not scripted by any of the mobile network operators and we do not have the ability to respond to the authorities on their content."

Likely cost

The Paris-based Organisation for Economic Co-operation and Development says that the government clampdown on internet services may have cost the Egyptian economy as much as $18m (£11m) a day or $90m in total.

The impact of the communications block could be even greater, as it would be "much more difficult in the future to attract foreign companies and assure them that the networks will remain reliable", said the OECD in a statement.

In another development, the credit ratings agency Fitch has downgraded the Egypt's debt grade by one notch to BB from BB+, citing the consequences of the continuing political unrest on the economy.

The country's debt grade has already been downgraded by two other ratings agencies, Moody's and Standard & Poor's.


The estimation of the economic impacts of the network shutdown are interesting, but I found the reporting on how the Egyptian government used the Vodafone network to disseminate propaganda more relevant to our in-class discussions.

Wednesday, February 2, 2011

The Internet Should Not Be Anonymous

Via Roger Grimes at PCWorld

The news of the U.S. government's latest attempt at a national citizen "Internet ID" brought yet another round of choruses: The Internet must be free! Any government ID plan is bad! Anonymity for all forever! Perform an Internet search on "Obama national Internet ID" to see the screeds against the proposed plan. Security experts around the world are saying the government would have to pry their anonymity from their cold, dead touchscreens.

I chuckled at these angry responses because they sound like the heated calls for anarchy in the 1970s from tattooed punk rockers smoking unfiltered Camels while the Sex Pistols played in the background. The difference is the angry masses in this case are being riled up by security experts, who have been ranting wildly enough to spill their expensive Imperial Stout all over their tablet devices and brie salads.

Notably, the details behind the plan are scarce right now. The rationale, according to U.S. Commerce Secretary Gary Locke, is "enhancing online security and privacy, and reducing and perhaps even eliminating the need to memorize a dozen passwords, through creation and use of more trusted digital identities."

Even though I'm a huge privacy proponent, I get a little tired of seeing every proposal for a national or government ID met with absolute aversion. Security isn't binary. If a national ID plan offers more benefits than disadvantages, then I don't want to throw the baby out with the bathwater.

Total Internet anonymity means total anarchy

Just like the anarchist who is the first to call the police when punched in the face over his or her beliefs, the Internet would fall if we had total anonymity and no means of ensuring trust. Without strong authentication, authorization, and accounting, even places on the Internet meant for total anonymity would fail. The Internet would not be the Internet. Why? Because someone has to pay the bills and maintain control.

If the Internet was completely anarchistic, with no access control, websites would be constantly taken down, denial-of-service attacks would be even more common than they are today, and anyone could pretend to be anyone else. (This is already all too easy to do on Facebook, one of the biggest websites ever.)

Someone has to exert control and make sure ill-intentioned people don't take it all down. In the perfect world, no one would ever try to take down a website or disrupt someone else's legitimate actions. But human beings are imperfect and often seem overly capable of damaging other people's resources and experience. Case in point: I consulted for the owners of a thoroughly hacked website that had been created for collecting donations for a child's cancer treatment. I'm sure the hacker has plenty of personal excuses to rationalize his or her behavior.

Driver's licenses aren't all bad

I think most of us agree that some form of access control is needed in order for the Internet to be a useful tool for billions of people, especially as more and more critical services go online. The real question: How much control and who should control it? I'm pretty sure I don't want any government controlling the Internet, but I'm not sure a national logon ID is a complete takeover.

A lot of people whom I respect and admire are totally against any government agency requiring anyone to have a common identifier in the real world, such as a Social Security number or a passport, or on the Internet. They argue that such IDs are guaranteed to be hacked, abused, and misused -- both by malicious people and the very governments that issue them.

I understand the inherent concerns about giving any entity total trust, but a blanket statement against any common and trusted ID doesn't seem to be fair either. Although common IDs are largely imperfect, they provide value all throughout society. For example, I'm delighted that underage children aren't allowed to drive cars and that adults are forced to take a test before they can. I like that my world has street names and sequenced housing addresses so that it's easier for mail to be delivered and for the fire department and rescue squads to find my house.

For each ID we have, we should ask ourselves if society is better off with or without it. I'm not talking about using scary edge cases as the determiner, but looking at all the positives and negatives before registering complete disdain.

Know your Net neighbors

Perhaps you support the idea of driver's licenses and passports but still don't see how a national Internet ID would make the Web a safer place. Well, if the system could improve identity assurance (that is, the person is who they say they are), then it could prove useful. Maybe it would require two- or multifactor, biometric identification. A well-designed authentication system would consider all the components of the system and elevate or de-elevate assurance levels as appropriate.
This wouldn't stop hacking -- or identity theft, for that matter -- because bad guys can simply reuse credentials after the person has successfully authenticated on their compromised workstation. But it would be better than the default simple name and passwords we use today.

The details behind the Obama administration's push for a national Internet ID aren't known. But I do know that the Internet needs to be a more trustworthy place than it is today, and I'm willing to listen to new solutions that might help -- at least long enough to learn all the facts before just saying no.

In fact, I'd be happy if all it does is get the discussion to the end-game going. Anything is better than what we currently have in place
.

Google Reaches Deal With Connecticut in Data Probe

From Amir Efrati at the Wall Street Journal,

Connecticut's attorney general said Google Inc. won't have to hand over user data it collected from unsecured wireless networks as part of his office's probe of the Internet giant's privacy snafu.

Attorney General George Jepsen said Friday his office reached a deal with the Internet company that allows him to begin settlement negotiations over whether Google violated state law. Last month Google rejected a subpoena issued by Mr. Jepsen's predecessor, Richard Blumenthal, to hand over data the company collected when its Street View cars were within range of unsecured wireless Internet hotspots.

Google's world-wide fleet of Street View cars for years collected images of streets that are used in the company's online mapping service. But they also scanned for wireless networks in order to beef up certain mobile-device applications that help pinpoint the location of users. In some cases the cars inadvertently collected personal information such as email addresses and passwords, Google said last year.

As part of the deal with Connecticut, Google said it wouldn't contest the fact that its Street View cars had collected private user information including URLs of requested Web pages, partial or complete email communications or other information in 2008 and 2009, according to Mr. Jepsen.

A Google spokeswoman reiterated the company's statements that it is "profoundly sorry" for having mistakenly collected payload data from unencrypted wireless networks.

"As soon as we realized what had happened, we stopped collecting all Wi-Fi data from our Street View cars and immediately informed the authorities," she said. "We did not want and have never used the payload data in any of our products and services. We want to delete this data as soon as possible and will continue to work with the authorities to determine the best way forward, as well as to answer their further questions and concerns."

Mr. Jepsen said he is leading a 40-state coalition that is examining the issue, and that he is prepared to file a lawsuit if settlement talks break down.

The Federal Communications Commission said in November it was probing whether Google broke federal law in collecting consumer data via Wi-Fi networks. Another agency, the Federal Trade Commission, previously ended its probe and said Google had taken sufficient steps to prevent a recurrence.

When the mistakes became known earlier this year, Google initially said a review of the data it collected showed it captured fragments of data but later said it also had more-complete pieces of information about Internet users.

Google has said it doesn't believe it broke U.S. law, and the matter has been a bigger problem for the company outside the U.S., where it is facing probes in countries such as Germany, South Korea, and France. It has shown to regulators some of the data it collected.

Sunday, January 30, 2011

Facebook pwns Firesheep

From Facebook.com,

Starting today we'll provide you with the ability to experience Facebook entirely over HTTPS. You should consider enabling this option if you frequently use Facebook from public Internet access points found at coffee shops, airports, libraries or schools. The option will exist as part of our advanced security features, which you can find in the "Account Security" section of the Account Settings page.




There are a few things you should keep in mind before deciding to enable HTTPS. Encrypted pages take longer to load, so you may notice that Facebook is slower using HTTPS. In addition, some Facebook features, including many third-party applications, are not currently supported in HTTPS. We'll be working hard to resolve these remaining issues. We are rolling this out slowly over the next few weeks, but you will be able to turn this feature on in your Account Settings soon. We hope to offer HTTPS as a default whenever you are using Facebook sometime in the future
.

House Considers Mandating Internet Data Retention For Crime Solving

ABC News' Mary Bruce reports:

Criminal investigations are “being frustrated” because internet providers are not required by law to retain information on what their customers are doing online, the Department of Justice testified before a House hearing today.

“The gap between providers retention practices and the needs of law enforcement can be extremely harmful to investigations that are critical to protecting the public from predators,” Justice Department Deputy Assistant Attorney General Jason Weinstein told a House Justice Committee hearing on “data retention as a tool for investigating internet child pornography and other internet crimes.”

“The lack of adequate, uniform and consistent data retention policies threatens our ability to use the legal tools Congress has provided to law enforcement to protect public safety,” he said.

While some internet providers voluntarily retain user data for months or years, others do not retain data at all. Under current law, officers can issue subpoenas, court orders and search warrants to require an internet service provider to hand over user data. The problem, Weinstein testified, is that “those authorities are only useful if the data is still in existence at the time the government seeks to obtain it.”

Judiciary Committee Chair Rep. Lamar Smith, R-Texas, agreed. “When law enforcement officers do develop leads that might ultimately result in saving a child or apprehending a pornographer, their efforts should not be frustrated because vital records were destroyed simply because there was no requirement to retain them. Every piece of discarded information could be the footprint of a child predator,” he said.

Other committee members and the Internet Service Provider Association expressed concern, however, that retaining internet data could infringe on users’ privacy.

“A data retention mandate would raise a number of serious privacy and free speech concerns… Congress should be very hesitant to require service providers to create databases to track the internet activities of 230 million innocent Americans,” said John Morris, General Counsel for the Center for Democracy and Technology.

Florida Democrat Rep. Debbie Wasserman Schultz reiterated “this is not about watching or tracking people’s behavior online… it’s about helping law enforcement connect the dots.”

Beyond privacy concerns, Morris argued that requiring internet providers to extend their data retention for longer periods would be so cost prohibitive that it would harm competition, innovation and ultimately internet users.

Kate Dean, the Executive Director of the Internet Service Provider Association, questioned how companies would keep track of a growing amount of personal user data.

“We’re dealing with people’s lives and liberty here and out of all of this data we have to make sure that, say 18 months down the road, that tiny particular piece of information is exactly the right information linking that exact target,” she said.

Looking ahead, Rep. Jim Sensenbrenner, R-Wis., asked Dean if, in place of a Congressional mandate, her member companies would be willing to come together and develop their own voluntary compliance order.

“I am a firm believer in carrots and sticks and I am tossing you a carrot now… If you aren’t a good rabbit and don’t start eating the carrot, I’m afraid that we’re all going to be throwing the stick at you. So this is an opportunity for you to come up with some kind of a solution,” Sensenbrenner said.

Dean said the Association would be willing to sit down with all parties involved and take an active role in a larger dialogue.

Egypt Disconnected

Image courtesy of Craig Labovitz - the chief scientist at Arbor Networks.



Egypt's ability to cut itself of from the Internet helps demonstrates that nation-states still do have some ability to control the free flow of information in the digital age.

Internet ‘Kill Switch’ Legislation Back in Play

From David Kravets at Wired's Threat Level Blog,

The resurgence of the so-called “kill switch” legislation came the same day Egyptians faced an internet blackout designed to counter massive demonstrations in that country.

The bill, which has bipartisan support, is being floated by Sen. Susan Collins, the Republican ranking member on the Homeland Security and Governmental Affairs Committee. The proposed legislation, which Collins said would not give the president the same power Egypt’s Hosni Mubarak is exercising to quell dissent, sailed through the Homeland Security Committee in December but expired with the new Congress weeks later.

The bill is designed to protect against “significant” cyber threats before they cause damage, Collins said.

“My legislation would provide a mechanism for the government to work with the private sector in the event of a true cyber emergency,” Collins said in an e-mail Friday. “It would give our nation the best tools available to swiftly respond to a significant threat.”

The timing of when the legislation would be re-introduced was not immediately clear, as kinks to it are being worked out.


An aide to the Homeland Security committee described the bill as one that does not mandate the shuttering of the entire internet. Instead, it would authorize the president to demand turning off access to so-called “critical infrastructure” where necessary.

An example, the aide said, would require infrastructure connected to “the system that controls the floodgates to the Hoover dam” to cut its connection to the net if the government detected an imminent cyber attack.

What’s unclear, however, is how the government would have any idea when a cyber attack was imminent or why the operator wouldn’t shutter itself if it detected a looming attack.

About two dozen groups, including the American Civil Liberties Union, the American Library Association, Electronic Frontier Foundation and Center for Democracy & Technology, were skeptical enough to file an open letter opposing the idea. They are concerned that the measure, if it became law, might be used to censor the internet.

“It is imperative that cyber-security legislation not erode our rights,” (.pdf) the groups wrote last year to Congress.

A congressional white paper (.pdf) on the measure said the proposal prohibits the government from targeting websites for censorship “based solely on activities protected by the First Amendment of the United States Constitution.”

Oddly, that’s exactly the same language in the Patriot Act used to test whether the government can wiretap or investigate a person based on their political beliefs or statements.


A couple thoughts on this bill:

- what are the implications for our digital privacy? in order to detect cyber threats is intrusive monitoring of the internet required?
- and why the *#$! would the hoover dam need to be connected to the Internet?

Monday, November 15, 2010

The Plan To Quarantine Infected Computers

From Bruce Schneier's column at Forbes Magazine ...

Last month Scott Charney of Microsoft proposed that infected computers be quarantined from the Internet. Using a public health model for Internet security, the idea is that infected computers spreading worms and viruses are a risk to the greater community and thus need to be isolated. Internet service providers would administer the quarantine, and would also clean up and update users' computers so they could rejoin the greater Internet.

This isn't a new idea. Already there are products that test computers trying to join private networks, and only allow them access if their security patches are up-to-date and their antivirus software certifies them as clean. Computers denied access are sometimes shunned to a limited-capability sub-network where all they can do is download and install the updates they need to regain access. This sort of system has been used with great success at universities and end-user-device-friendly corporate networks. They're happy to let you log in with any device you want--this is the consumerization trend in action--as long as your security is up to snuff.

Charney's idea is to do that on a larger scale. To implement it we have to deal with two problems. There's the technical problem--making the quarantine work in the face of malware designed to evade it, and the social problem--ensuring that people don't have their computers unduly quarantined. Understanding the problems requires us to understand quarantines in general.

Quarantines have been used to contain disease for millennia. In general several things need to be true for them to work. One, the thing being quarantined needs to be easily recognized. It's easier to quarantine a disease if it has obvious physical characteristics: fever, boils, etc. If there aren't any obvious physical effects, or if those effects don't show up while the disease is contagious, a quarantine is much less effective.

Similarly, it's easier to quarantine an infected computer if that infection is detectable. As Charney points out, his plan is only effective against worms and viruses that our security products recognize, not against those that are new and still undetectable.

Two, the separation has to be effective. The leper colonies on Molokai and Spinalonga both worked because it was hard for the quarantined to leave. Quarantined medieval cities worked less well because it was too easy to leave, or--when the diseases spread via rats or mosquitoes--because the quarantine was targeted at the wrong thing.

Computer quarantines have been generally effective because the users whose computers are being quarantined aren't sophisticated enough to break out of the quarantine, and find it easier to update their software and rejoin the network legitimately.

Three, only a small section of the population must need to be quarantined. The solution works only if it's a minority of the population that's affected, either with physical diseases or computer diseases. If most people are infected, overall infection rates aren't going to be slowed much by quarantining. Similarly, a quarantine that tries to isolate most of the Internet simply won't work.

Fourth, the benefits must outweigh the costs. Medical quarantines are expensive to maintain, especially if people are being quarantined against their will. Determining who to quarantine is either expensive (if it's done correctly) or arbitrary, authoritative and abuse-prone (if it's done badly). It could even be both. The value to society must be worth it.

It's the last point that Charney and others emphasize. If Internet worms were only damaging to the infected, we wouldn't need a societally imposed quarantine like this. But they're damaging to everyone else on the Internet, spreading and infecting others. At the same time, we can implement systems that quarantine cheaply. The value to society far outweighs the cost.

That makes sense, but once you move quarantines from isolated private networks to the general Internet, the nature of the threat changes. Imagine an intelligent and malicious infectious disease: That's what malware is. The current crop of malware ignores quarantines; they're few and far enough between not to affect their effectiveness.

If we tried to implement Internet-wide--or even countrywide--quarantining, worm-writers would start building in ways to break the quarantine. So instead of nontechnical users not bothering to break quarantines because they don't know how, we'd have technically sophisticated virus-writers trying to break quarantines. Implementing the quarantine at the ISP level would help, and if the ISP monitored computer behavior, not just specific virus signatures, it would be somewhat effective even in the face of evasion tactics. But evasion would be possible, and we'd be stuck in another computer security arms race. This isn't a reason to dismiss the proposal outright, but it is something we need to think about when weighing its potential effectiveness.

Additionally, there's the problem of who gets to decide which computers to quarantine. It's easy on a corporate or university network: the owners of the network get to decide. But the Internet doesn't have that sort of hierarchical control, and denying people access without due process is fraught with danger. What are the appeal mechanisms? The audit mechanisms? Charney proposes that ISPs administer the quarantines, but there would have to be some central authority that decided what degree of infection would be sufficient to impose the quarantine. Although this is being presented as a wholly technical solution, it's these social and political ramifications that are the most difficult to determine and the easiest to abuse.

Once we implement a mechanism for quarantining infected computers, we create the possibility of quarantining them in all sorts of other circumstances. Should we quarantine computers that don't have their patches up to date, even if they're uninfected? Might there be a legitimate reason for someone to avoid patching his computer? Should the government be able to quarantine someone for something he said in a chat room, or a series of search queries he made? I'm sure we don't think it should, but what if that chat and those queries revolved around terrorism? Where's the line?

Microsoft would certainly like to quarantine any computers it feels are not running legal copies of its operating system or applications software.The music and movie industry will want to quarantine anyone it decides is downloading or sharing pirated media files--they're already pushing similar proposals.

A security measure designed to keep malicious worms from spreading over the Internet can quickly become an enforcement tool for corporate business models. Charney addresses the need to limit this kind of function creep, but I don't think it will be easy to prevent; it's an enforcement mechanism just begging to be used.

Once you start thinking about implementation of quarantine, all sorts of other social issues emerge. What do we do about people who need the Internet? Maybe VoIP is their only phone service. Maybe they have an Internet-enabled medical device. Maybe their business requires the Internet to run. The effects of quarantining these people would be considerable, even potentially life-threatening. Again, where's the line?

What do we do if people feel they are quarantined unjustly? Or if they are using nonstandard software unfamiliar to the ISP? Is there an appeals process? Who administers it? Surely not a for-profit company.

Public health is the right way to look at this problem. This conversation--between the rights of the individual and the rights of society--is a valid one to have, and this solution is a good possibility to consider.

There are some applicable parallels. We require drivers to be licensed and cars to be inspected not because we worry about the danger of unlicensed drivers and uninspected cars to themselves, but because we worry about their danger to other drivers and pedestrians. The small number of parents who don't vaccinate their kids have already caused minor outbreaks of whooping cough and measles among the greater population. We all suffer when someone on the Internet allows his computer to get infected. How we balance that with individuals' rights to maintain their own computers as they see fit is a discussion we need to start having.

Sunday, November 14, 2010

US internet hosts are linchpin of criminal botnets

From the New Scientist ...

WHILE criminal gangs in Russia and China are responsible for much of the world's cybercrime, many of the servers vital to their activities are located elsewhere. An investigation commissioned by New Scientist has highlighted how facilities provided by internet companies in the US and Europe are crucial to these gangs' activities.

Researchers at Team Cymru, a non-profit internet security company based in Burr Ridge, Illinois, delved into the world of botnets - networks of computers that are infected with malicious software. Millions of machines can be infected, and their owners are rarely aware that their computers have been compromised or are being used to send spam or steal passwords.

Several botnets have been linked to gangs based in Russia, where police have a poor record on tackling the problem. But to manage their botnets these gangs often seem to prefer to use computers, known as command-and-control (C&C) servers, in western countries. More than 40 per cent of the 1500 or so web-based C&C servers Team Cymru has tracked this year were in the US. When it comes to hosting C&C servers, "the US is significantly ahead of anyone else", says Steve Santorelli, Team Cymru's director of global outreach in San Diego.

Santorelli and his colleagues also detected a daily average of 226 C&C servers in China and 92 in Russia. But European countries not usually linked with cybercrime were in a similar range, with an average of 120 C&C servers based in Germany and 64 in the Netherlands.

Internet hosts in western countries appeal to criminals for the same reasons that regular computer users like them, says Santorelli: the machines are extremely reliable and enjoy high-bandwidth connections. Team Cymru's research did not identify which companies are hosting botnet servers, but Santorelli says the list would include well-known service providers.

The use of US-based C&C servers to control botnets is a source of frustration to security specialists, who have long been aware of the problem. It is happening even though most hosting companies shut down C&C servers as soon as they receive details of botnet activity from law enforcement agencies and security firms. "When we see an AT&T address serving as a botnet control point, we take it very seriously," says Michael Singer, an executive director at AT&T.

Despite these efforts, the criminals can quickly re-establish control by setting up a new C&C server with a different company, often using falsified registration information and stolen credit card details.

Hosting companies deal with botnets on a voluntary basis at present. They might be more vigilant if required to act by law, but that would create its own regulatory problems, Santorelli says. "The cops don't run or govern the internet after all, and neither do they want to," he says. For legal controls to work, it would be necessary to define who has the authority to decide whether a server is part of a botnet, and how requests from authorities abroad are dealt with.

Jeffrey Carr of security firm Taia Global, based in Washington DC, says that some less well-known providers have been warned about botnet activity on many occasions, but drag their heels when asked to shut down the criminals' servers.

The problem arises partly because web hosting can be a big earner for some firms. "They're generating millions of dollars in income," says Carr. Improvements in security, such as requiring service providers to verify the details of people who rent server facilities, could well hurt these firms' bottom line.

Monday, November 8, 2010

Metasploit and SCADA exploits: dawn of a new era?

Courtesy Shawn Merdinger

On 18 October, 2010 a significant event occurred concerning threats to SCADA (supervisory control and data acquisition) environments.

That event is the addition of a zero-day exploit for the RealFlex RealWin SCADA software product into the Metasploit repository. Here are some striking facts about this event:

  • This was a zero-day vulnerability that unfortunately was not reported publicly, to a organization like ICS-CERT or CERT/CC, or (afaik) to the RealFlex vendor.
  • This exploit was not added to the public Exploit-DB site until 27 October, 2011.
  • The existence of this exploit was not acknowledged with a ICS-CERT advisory until 1 November, 2010.
  • This is the first SCADA exploit added to Metasploit.
  • So what are the lessons learned and takeaways from this seminal event?


First, the SCADA community can expect to see an explosion of vulnerabilities and accompanying exploits against SCADA devices in the near future.

Personally, I expect we will see in the next 12 months at least a doubling of the known 16 SCADA vulnerabilities documented in NIST’s National Vulnerability Database.

Second, the diverse information sources that SCADA vulnerabilities may appear must be vigilantly monitored by numerous organizations and security researchers.

Afaik, the first widely-disseminated information on the RealFlex RealWinbuffer overflow occurred on 1 November, when I sent the information to the SCADASEC mailing list.

Third, people should recognize that the recent Stuxnet threat has cast a light on SCADA security issues. Put bluntly, there is blood in the water.

Quite a few people, companies and other organizations are currently investigating SCADA product security, buying equipment and conducting security testing for a number of differing interests and objectives.

I expect SCADA security issues will be the shiny hot topic on the 2011 security and hacker conference circuit, both in the US and abroad.

Fourth, understand that because of the current broken business model, security researchers are often frustrated by software vendors’ action, or inaction, when it comes to reporting vulnerabilities.

Often, there is no security point-of-contact at the vendor. Even worse, the technical support who are contacted by the security researcher often do not understand the technical and security implications of the issue reported.

And it is worth mentioning that a vendor acknowledging a product security issue is then“on the hook” — so there is incentive for the vendor to dismiss the vulnerability report.

Even in the case of specialty SCADA security shops reporting vulnerabilites to the vendor, we are seeing documented cases of “vendor spin” furthering the bad blood between vendors and ethical research.

All of these factors lead to frustrated security researchers, some of whom will simply expose the vulnerability and exploit to the world, rather than take a disclosure path through a CERT.

Fifth, folks should recognize that attack frameworks like Metasploit enable a never-before-seen level of integration of these kinds of targeted critical infrastructure-relate exploits into a powerful tool.

For a kinetic metaphor, Metasploit is akin to a.50 caliber sniper rifle, and a zero-day SCADA vulnerability is equivalent to a .50 caliber depleted uranium round for that rifle.

As a SCADA end user, what are you to do?

I recommend the following, at a minimum: push your vendors to have a product security POC and process, monitor resources like SCADASEC, keep current with tools like Metasploit, receive vulnerability notifications from appropriate CERT organizations like ICS-CERT.

Sunday, October 31, 2010

China Has Ability to Hijack U.S. Military Data, Report Says

From Jeff Bliss and Tony Capaccio at Bloomberg ...

China in the past year demonstrated it can direct Internet traffic, giving the nation the capability to exploit “hijacked” data from the U.S. military and other sources, according to a new report.

Recent actions raise questions that “China might seek intentionally to leverage these abilities to assert some level of control over the Internet,” according to excerpts from the final draft of an annual report by the U.S.-China Economic and Security Review Commission. “Any attempt to do this would likely be counter to the interests of the United States and other countries.”

On April 8, China Telecom Corp., the nation’s third-largest mobile-phone company, instructed U.S. and other foreign-based Internet servers to route traffic to Chinese servers, the report said. The 18-minute re-routing included traffic from the U.S. military, the Senate and the office of Defense Secretary Robert Gates.

“Although the commission has no way to determine what, if anything, Chinese telecommunications firms did to the hijacked data, incidents of this nature could have a number of serious implications,” the report said. The re-routing showed how data could be stolen and communications with websites could be disrupted, the report said.

Read more here ...

Indian OS

From Bruce Schneier ...

India is writing its own operating system so it doesn't have to rely on Western technology:

India's Defence Research and Development Organisation (DRDO) wants to build an OS, primarily so India can own the source code and architecture. That will mean the country won't have to rely on Western operating systems that it thinks aren't up to the job of thwarting cyber attacks. The DRDO specifically wants to design and develop its own OS that is hack-proof to prevent sensitive data from being stolen.


On the one hand, this is great. We could use more competition in the OS market -- as more and more applications move into the cloud and are only accessed via an Internet browser, OS compatible matters less and less -- and an OS that brands itself as "more secure" can only help. But this security by obscurity thinking just isn't true:

"The only way to protect it is to have a home-grown system, the complete architecture ... source code is with you and then nobody knows what's that," he added.


The only way to protect it is to design and implement it securely. Keeping control of your source code didn't magically make Windows secure, and it won't make this Indian OS secure.