Thursday, February 25, 2010
Lawful Surveillance
Tuesday, February 23, 2010
Block all Drive-By Download Exploits
BLADE appears to be similar to Sandboxie - another tools Ive discussed in the past. Phil Porras, a Program Director for the project from SRI International, states that BLADE acts as a sandbox for the browser and prevents malware from being written to the hard drive.
Although the BLADE project team has not yet released the tool, it has published interesting statistics gathered during the testing of the software. To date BLADE has tested 5579 Drive-By Exploits from 1318 unique malicious URLs. According to these statistics, users running Microsoft Internet Explorer were successfully compromised 43.9% of the time.


Sunday, February 21, 2010
Friday, February 19, 2010
My Kind of Privacy Policy
Backupify is a strong supporter of online privacy and individual rights. We only collect data necessary to run the service effectively. Any data you store on Backupify is yours. We claim no rights to it. We don't look at it, we don't sell it, we don't analyze it, or anything else. Below are some specific questions we get and answers to them.
What information is collected about me?
We only collect data you provide us at sign-up. We do not ask for any other personal information. We do not collect data without your knowledge.How do you use collected information?
We don't use it at all. The only thing we collect and monitor is general patterns of storage and service usage so that we can make sure our architecture is optimized for speed and scalability.What security measures do you use to protect my privacy?
Any information we have about you is stored with strong encryption.Will my information be shared with others?
No. Your information will not be shared with anyone, except in cases where information may be subpoenaed by law.
School Spies Students Through Their Laptop Cameras
A lawsuit against the Lower Marion School district contends that "the school district can activate the webcams without students' knowledge or permission."
The plaintiffs in the suit allege that Lindy Matsko, an assistant principal at Harriton High School, informed them that their son had engaged in improper behavior at home. The lawsuit stated, "(Matsko) cited as evidence a photograph from the webcam embedded in minor plaintiff's personal laptop issued by the school district." Further, Matsko later confirmed to the plaintiffs that the school had the ability to remotely activate webcams in the school issued laptops.
According to Gizmodo, the school issued laptops come with Apple Remote Desktop which would allow administrators to remotely access the school issued Mac Books and to turn on the embedded iSight camera. Gizmodo's Jesus Diaz succinctly sums up my feelings about the Lower Marion School District administration writing "way to go, KGB-wannabe assclowns."
If you're going to give students laptops to aid in their academic pursuits dont effing us that same laptop as a tool of surveillance and repression. And no, I dont think im being too dramatic with my language. As Uncle Ben said to Peter Parker, "with great power comes great responsibility."
Wednesday, February 17, 2010
Please Rob Me
The creators of the PleaseRobMe.com offer this description of their website:
The danger is publicly telling people where you are. This is because it leaves one place you're definitely not... home. So here we are; on one end we're leaving lights on when we're going on a holiday, and on the other we're telling everybody on the internet we're not home. It gets even worse if you have "friends" who want to colonize your house. That means they have to enter your address, to tell everyone where they are. Your address.. on the internet.. Now you know what to do when people reach for their phone as soon as they enter your home. That's right, slap them across the face.As Van Grove points out, there is evidence that criminals are using information gleaned from these social networking services to do more than commit cyber fraud. In some cases, criminals are using this information to aid in burglary. In a separate report for Mashable.com, Van Grove wrote
Unfortunately, over-sharing of this variety has been known to cause adverse side effects. Most recently, Israel Hyman (@izzyvideo), a video podcaster, took a trip to the midwest with his family and twittered about the excursion. He came home to find that his house had been burglarized.
This site is just another example of how many in their rush to adopt the latest social media tool inadvertently share too much of their personal information.
Tuesday, February 9, 2010
Still Think You're Anonymous Online
David discusses the simplest route to uniquely identifying users on the Internet writing
if a plaintiff's lawyer cannot otherwise determine who the poster is, the lawyer will typically subpoena the forum web site, seeking the IP address of the anonymous poster. Many widely used web based discussion systems, including for example the popular Wordpress blogging platform, routinely log the IP addresses of commenters. If the web site is able to provide an IP address for the source of the allegedly defamatory comment, the lawyer will do a reverse lookup, a WHOIS search, or both, on that IP address, hoping to discover that the IP address belongs to a residential ISP or another organization that maintains detailed information about its individual users.Both David and Harlan point out that even if a user cannot be uniquely identified through these traditional means a number of techniques are still available. Harlan writes
Of course, in many cases, this method won't work. The forum web site may not have logged the commenter's IP address. Or, even if an address is available, it might not be readily traceable back to an ISP account: the anonymous commenter may been using an anonymization tool like Tor to hide his address. Or he may have been coming online from a coffee shop or similarly public place (which typically will not have logged information about its transient users). Or, even if he reached the web forum directly from his own ISP, that ISP might be located in a foreign jurisdiction, beyond the reach of an American lawyer's usual legal tools.
There are numerous third party web services that may hold just enough clues to reidentify the speaker, even without the help of the content provider or the ISP. The vast majority of websites today depend on third parties to deliver valuable services that would otherwise be too expensive or time-consuming to develop in-house. Services such as online advertising, content distribution and web analytics are almost always handled by specialized servers from third party businesses. As such, a third party can embed its service into a wide variety of sites across the web, allowing it to track users across all the sites where it maintains a presence.If you are interested in learning where you are leaving your digital foot and finger prints when you browse the web you should install the 'Ghostery' plug-in for Firefox. Ghostery will notify you when a website utilizes "third-party web bugs, ad networks and widgets."
Take for example the popular online blog Boing Boing. Upon loading its main page while recording the HTTP session, I noticed that my browser is automatically redirected to domains owned by no fewer than 17 distinct third party entities: 10 services that engage in advertising or marketing, five that embed media or integrate social networking functionality, and two that provide web analytics. By visiting this single webpage, my digital footprints have been scattered to and collected by at least 17 other online entities that I made no deliberate attempt to contact. And each of these entities will likely have stored a cookie on my web browser, allowing it to identify me uniquely later when I browse to one of its other partner sites. I don't mean to pick on Boing Boing specifically—taking advantage of third party services is a nearly universal practice on the web today, but it's exactly this pervasiveness that makes it so likely, if not probable, that all of my digital footprints together could link much of my online activities back to my actual identity.
To make this point concrete, let's say I post a potentially defamatory remark about someone using a pseudonym in the comments section of a Boing Boing article. It happens that for each article, Boing Boing displays the number of times that the article has been shared on Facebook. In order to fetch the current number, Boing Boing redirects my browser to api.facebook.com to make a real-time query to the Facebook API. Since I happen to be logged in to Facebook at the time of the request, my browser forwards with the query my unique Facebook cookie, which includes information that explicitly identifies me—namely, my e-mail address that doubles as my Facebook username.
