Showing posts with label internet security. Show all posts
Showing posts with label internet security. Show all posts

Thursday, March 30, 2017

The U.S. government won't protect your internet privacy, so here's how to do it yourself.


The U.S. government won't protect your internet privacy, so here's how to do it yourself. (Popsci).

Yesterday, by a vote of 215 to 205, the House of Representatives voted to strip privacy safeguards from people who use the internet. The measure already cleared the Senate with a narrow majority, and experts expect that President Trump will sign the bill into law. When he does so, ISPs, the companies that connect people to the internet, will be able to collect and sell information about specific users without their permission.

More specifically, the bill nullifies a set of rules put in place by the FCC. Collectively, the rules—which have been in the works in the works for months and years and are built on prior rulemaking—are newly formalized: The FCC published the final version last December, and most took effect in January, with one part coming into effect this March.

Some of those protections provided by these rules are, technologically speaking, ancient—like extending 1934 privacy requirements originally written for telecommunication companies to also cover broadband internet service. Modern additions deal more explicitly with consumer consent and privacy online. The rules mandate that ISPs do three things: Let customers know about (and opt-in or opt-out of) any sharing of their information; get affirmative consent when offering customers financial incentives in exchange for selling their data; and not offer cheaper service to people on the condition that they surrender privacy rights.

Without these measures in place, ISPs will be freed up to turn user data into a lucrative business—and to do so without the users' knowledge or consent. Nullifying these rules, after all the time it took to create and implement them, gives companies implicit permission to do exactly what the rules protect against. The Electronic Frontier Foundation, a major online privacy rights organization, describes it succinctly:
Putting the interests of internet providers over internet users, Congress today voted to erase landmark broadband privacy protections. If the bill is signed into law, companies like Cox, Comcast, Time Warner, AT&T, and Verizon will have free rein to hijack your searches, sell your data, and hammer you with unwanted advertisements. Worst yet, consumers will now have to pay a privacy tax by relying on VPNs to safeguard their information. That is a poor substitute for legal protections.
This change in rules means ISPs can profit off a captive customer base twice: first, by charging them for the service, and second, by collecting data on what users do online and selling it to a third party.

“I’m concerned about their stewardship of the data,” says Shauna Dillavou, a former member of the D.C. intelligence community who now runs CommunityRED, a nonprofit that works on finding and providing secure technology tools for citizen reporters operating in journalism-unfriendly places abroad. “We still have to pay for their service, for the most part, and a lot of the tools you’ll have to use to safeguard your privacy and your security will slow your connection down, so then you have to upgrade your service and pay even more, because ISPs are sucking your data out.”

To make matters worse for users, should the bill be signed into law, ISPs will no longer be required to disclose data breaches. That means people could have their information stolen from the company that collected it without their consent, and then not even know that the data theft took place.

We’ve put the entire responsibility of security on the users,” says Dillavou.

Restoring consumer protections will likely take either legislative or legal action, which means waiting until the next Congress takes office in 2019 at the earliest—or hoping a privacy-relevant case works through the courts before then.

Still, that doesn’t mean individual users are completely powerless to protect their own data. Here are some steps a user can take to secure their privacy: Read the full story here.

Monday, August 31, 2015

Microsoft Adding Windows 10 Style Spyware in 'upgrades' to Windows 7 and Windows 8.


Microsoft Adding Windows 10 Style Spyware in 'upgrades' to Windows 7 and Windows 8. HT: Ghack.

Microsoft has been criticized by privacy advocates in regards to the data hunger of its Windows 10 operating system. The operating system slurps data like there is no tomorrow, especially when systems are set up using the express settings.

Experienced users may disable telemetry and data collection partially during setup, and then some more afterwards using the Registry or Group Policy.

What makes this problematic however is the fact that it is nearly impossible to stop all of the data collecting that is taking place.

While users may disable some, for instance by using privacy tools (of which there are plenty), others cannot be disabled or stopped that easily, for instance because of hardcoded host and IP address information that bypass the Hosts file of the operating system.


Windows 7 and 8.

Windows 7 and 8 users have been plagued by "upgrade preparation" updates but left alone otherwise up until recently when it comes to this new level of data collecting.
This changed recently with the release of several updates for both operating systems that step up the game.
  • KB3068708 Update for customer experience and diagnostic telemetry - This update introduces the Diagnostics and Telemetry tracking service to existing devices. By applying this service, you can add benefits from the latest version of Windows to systems that have not yet upgraded. The update also supports applications that are subscribed to Visual Studio Application Insights. (Windows 8.1, Windows Server 2012 R2, Windows 7 Service Pack 1 (SP1), and Windows Server 2008 R2 SP1)
  • KB3022345 (replaced by KB3068708) Update for customer experience and diagnostic telemetry - This update introduces the Diagnostics and Telemetry tracking service to in-market devices. By applying this service, you can add benefits from the latest version of Windows to systems that have not yet been upgraded. The update also supports applications that are subscribed to Visual Studio Application Insights. (Windows 8.1, Windows Server 2012 R2, Windows 7 Service Pack 1 (SP1), and Windows Server 2008 R2 SP1)
  • KB3075249 Update that adds telemetry points to consent.exe in Windows 8.1 and Windows 7 - This update adds telemetry points to the User Account Control (UAC) feature to collect information on elevations that come from low integrity levels. (Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 7 Service Pack 1 (SP1), and Windows Server 2008 R2 SP1)
  • KB3080149 Update for customer experience and diagnostic telemetry - This package updates the Diagnostics and Telemetry tracking service to existing devices. This service provides benefits from the latest version of Windows to systems that have not yet upgraded. The update also supports applications that are subscribed to Visual Studio Application Insights. (Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 7 Service Pack 1 (SP1), and Windows Server 2008 R2 SP1)
If these updates are installed on the system, data is sent to Microsoft regularly about various activities on it.
Microsoft lists two host names in KB3068708 that data is received from and sent to:
  • vortex-win.data.microsoft.com
  • settings-win.data.microsoft.com

These, and maybe others, appear to be hardcoded which means that the Hosts file is bypassed automatically.

What you can do about it. Read the full story here, MUST READ more here.

Saturday, April 25, 2015

'Nothing is beyond our reach' - “How Tor Is Building a New Dark Net with Help from the U.S. Military”


'Nothing is beyond our reach' - “How Tor Is Building a New Dark Net with Help from the U.S. Military” (DD).

To stay ahead in the security race, Tor is building the next-generation Dark Net in part with funding from the Defense Advanced Research Projects Agency, the U.S. military agency charged with inventing the cutting edge of new technology.

The funding, which began in 2014, comes as part of DARPA’s Memex project, a “groundbreaking” search engine designed to best commercial titans like Google at searching the Deep Web and other oft-ignored terrain for the U.S. intelligence, law enforcement, and military. To build Memex, DARPA is partnered with universities like Carnegie Mellon, NASA, private research firms, and several Tor Project developers.

DARPA is funding multiple projects focused on improving Tor’s hidden services across “1-3 years,” Tor’s director of communications Kate Krauss told the Daily Dot via email. Tor declined to give more specifics on the grant, like its monetary value and terms, and DARPA didn’t respond to a request for comment. Hmmm......Still feel 'safe' using Tor?Read the full story here.

Friday, October 10, 2014

Snapchat Hack: 200,000 'Self-Destruct' Nude Images Set to Leak in 'The Snappening'.


Snapchat Hack: 200,000 'Self-Destruct' Nude Images Set to Leak in 'The Snappening'. (IBTimes).

Hackers have warned that thousands of nude images sent via the mobile-messaging service Snapchat, many of which users believed self-destructed after being sent, are to be released online in a searchable database.

Messaging boards on the notorious website 4chan have been filling up with news of the imminent leak, already being referred to as "The Snappening".

It comes just weeks after hundreds of celebrity nudes were leaked online through the same site, following a hack of Apple's iCloud that has come to be referred to as the Fappening.

Earlier this week an anonymous 4chan user claimed to have hacked into Snapsave, an image-saving service that allows users of Snapchat to store pictures received before they self-destruct.

Given the nature of the Snapchat service, many of the images are expected to be of an explicit nature, while the young demographic of Snapchat's users could mean that some of the images released constitute child pornography.

By way of proof, the poster provided pictures allegedly from Snapsave. Read the full story here. More here from BusinessInsider.

Related:  Snapchat's expired snaps are not deleted, just hidden

Monday, February 17, 2014

Google buys SlickLogin, looks to swap passwords for inaudible sound waves.....now that's 'CHANGE'.


Google buys SlickLogin, looks to swap passwords for inaudible sound waves.....now that's 'CHANGE'. Engadget

If Google’s latest acquisition is anything to go by, entering a password on a website could soon be as easy as placing your smartphone near your computer.

Israeli startup SlickLogin confirmed today it has become the latest company join Mountain View’s ranks (although it’ll work from Google’s local offices), bringing its patented sound-based smartphone technology with it. 

While neither party has disclosed much information, Google’s intentions seem clear: the company already offers its two-factor authentication tech free to everybody, but it can be a pain to enter a six-digit authentication code (which changes every minute). Read the full story here.

Friday, February 14, 2014

Secret Military Contractors Will Soon Mine Your Tweets.


Secret Military Contractors Will Soon Mine Your Tweets.(DefenceOne).
The Army wants a contractor to conduct detailed social media data mining to “identify violent extremist influences” around the world that could affect the European Command, responsible for operations in Europe as well as Iceland, Israel, Greenland and Russia.

Though the project is classified Secret, an Army contract shop in Europe posted a wealth of information on the FedBizOps contract website Tuesday.Read the full story here.

Friday, June 21, 2013

Russia promises legal action over NSA surveillance scandal, will explore ways to allow the investigation on an international level.


Russia promises legal action over NSA surveillance scandal, will explore ways to allow the investigation on an international level.(RT).
The scandal over illegal data interception by US security services questions the correlation between the US and international law, and senior Russian officials are calling for an urgent update in Russian legislation in response.
Russia will not ignore the actions of the US authorities who had admitted leaks of personal data of Russian citizens to which the US security services had access, the Foreign Ministry’s plenipotentiary for human rights, Konstantin Dolgov, said at a special meeting initiated by the Upper House of the Russian parliament.

The move followed the revelations of former US security contractor Edward Snowden, who made public the mass surveillance and wire-tapping secretly committed by the National Security Agency in what they claimed was part of the war on terror.

The principle of observing the human rights is stated in all UN Security Council resolutions on countering terrorism without exceptions. There must be respect of the international law that is no less important than the fight against terrorism. We must analyze how the current American laws match the corresponding international norms, we have a number of doubts on this issue,” Dolgov said.

The Russian diplomat said that the US administration’s actions should be checked for falling under the fourth amendment of the US Constitution.

The access to personal data by the US is being performed in a seemingly civilized way, but in a very roundabout way, many Human Rights groups have paid attention to this,” the plenipotentiary noted.

A top official of the parliamentary majority party United Russia, Lower House vice speaker Sergey Zheleznyak also urged a detailed investigation into incidents in which US agencies collected personal data of Russian citizens. The MP ridiculed the US authorities for posing as a beacon of democracy while at the same time conducting constant eavesdropping and surveillance on millions of people, including citizens of the Russian Federation.

Americans remind us for cutting short the propaganda of sodomy among minors and at the same time they stick their noses into personal correspondence of tens of millions of citizens”, Zheleznyak said.

More than that, they are not ashamed of wire-tapping the heads of states who take part in international events,” he added, apparently hinting at the recent disclosure that in 2009 the US security services were intercepting the communications of then Russian President Dmitry Medvedev, while he was on a visit to the UK.

Zheleznyak told the meeting that Russian laws should be urgently amended with an obligation to store all information of official bodies only on servers that physically are on the territory of the Russian Federation. The MP said that the Lower House could pass such bill, which he called “digital sovereignty”, in its Fall session. Finally, the parliamentarian urged other officials to give more support to Russia's own electronics industry and software sector. “We should produce our own electronic products instead of using someone else’s,” Zheleznyak noted.

Upper House MP Ruslan Gattarov promised that a working group will be set up before the end of the week to investigate the access of US agencies to personal data of Russian internet users. Gattarov suggested the group is comprised of representatives of the Russian Communications Ministry and Russian consumer rights watchdog Roskomnadzor as well as experts from leading Russian IT companies, such as Kaspersky Lab.

The senator added that lawmakers would explore ways to allow the investigation on an international level. “We cannot let this issue sink into an abyss, as many people desire, we will not allow the question to vanish without result”, he stressed.Read the full story here.

Friday, March 29, 2013

New malware goes directly to US ATMs and cash registers for card info.


New malware goes directly to US ATMs and cash registers for card info.(RT).
Research conducted by the Russian-based security company Group-IB recently discovered malware called “Dump Memory Grabber,” which it believes has already been used to steal debit and credit card information from customers using major US banks including Chase, Citibank and Capital One, Security Weekly reports.
The malicious code is evidently being installed directly into point-of-sale (POS) hardware (meaning registers or kiosks) and ATMs, and transmitting the harvested information straight out of the magnetic stripes on credit and debit cards - which includes everything from account numbers, to first and last names and expiration dates.
And just how are attackers infecting physical systems? Security researchers point to USB drives as the likely culprits, as modern register systems often have accessible ports, as well as direct connections to the Web.
According to Security Weekly, the harvested information can then be used to produce cloned cards, and they are likely succeeding with the help of individuals with direct access to the POS systems and ATMs - which could include employees.
Group-IB analyzed a video evidently posted by the coder behind Dump Memory Grabber, which includes stolen card numbers, and suggests he (or perhaps she) goes by the name “Wagner Richard,” and is likely inside Russia.
This is of course not the first time that attacks have been directed at physical machines like registers or bank ATMs, though using malware is a stealthier approach than physical “skimmer” ploys, which involve mouldings placed on top of the ATM card slots and keypads that log information from unsuspecting customers.
Researchers with Group-IB believe that Dump Memory Grabber is likely part of a larger cyber-crime gang, a Russian-offshoot of the amorphous Anonymous community, and include members in Ukraine and Armenia. In addition to this latest malware, the group is allegedly also for hire to carry out DDoS attacks.Read the full story here.

Tuesday, July 3, 2012

F.B.I. warning :"You may not be able to connect to the internet after July 9".


F.B.I. warning :"You may not be able to connect to the internet after July 9". HT: IsraelMatzav.On July 9, 2012, there is a chance that many computers will cease to be able to surf the web because of malware that proliferated among millions of computers starting in 2007. You can find out if your computer is among them.
Starting in 2007, an Internet fraud ring running out of Estonia infected millions of computers worldwide with a virus to manipulate internet advertising. The way they did this was by redirecting users to rogue DNS servers which gave the cyber thieves the ability to manipulate users’ web activity by redirecting them from legitimate websites to fraudulent ones.
US authorities seized the rogue servers and replaced them with legitimate ones in order not to disrupt victims’ access to the web. However, those servers have been funded by US taxpayer dollars since November 2011, and of course this cannot go on indefinitely. The planned date for turning off the servers is July 9, which means that computers that have been accessing the web via these rogue-turned-legit servers, will lose that ability.

How to check if your computer is using rogue DNS servers

To find out if your computer is clean, or is using the rogue DNS servers, take the following steps:
  1. Find out what your computer’s IP address is. You can do this by visiting this site: WhatIsMyIP. Your IP address is the 10 digit number that looks like this: 12.123.12.123. Copy it down somewhere.
  2. Visit the following page on the FBI site: https://forms.fbi.gov/check-to-see-if-your-computer-is-using-rogue-DNS. Paste your IP address in the tiny field that appears towards the top of the page.
  3. Click on Check Your DNS. If your computer is clean, you’ll see the message: “Your IP is not configured to use the rogue DNS servers,” and you can breathe a sigh of relief.
  4. If your computer is not clean, then you’ve got quite a job ahead of you. Visit this page on the DNS Changer Working Group site to see the steps you should take to clean your computer.

    The FBI is encouraging users to visit a website run by its security partner, http://www.dcwg.org, that will inform them whether they're infected and explain how to fix the problem.
    After July 9, infected users won't be able to connect to the Internet.
Will : I've posted on April 21 - 2012. a story on this before. It can be read here.

Sunday, June 17, 2012

'Stuxnet is so deeply embedded in Iran, their counterstrike plans are already known'





'Stuxnet is so deeply embedded in Iran, their counterstrike plans are already known'.HT: IsraelMatzav.Here's a blog that the 'anti-virus experts' at Symantec and Kaspersky (and others) ought to be reading. They claim - and back it up - to have known about Stuxnet and Flame (which they call Stuxnet 3.0) since 2009 (Hat Tip: Jawa Report).

If they are correct, Flame is not automatically uninstalling on every computer in Iran, but only on computers where the Iranians start to look for it. And just because it disappears doesn't meant it can't come back. Here's the key part:
Stuxnet/flame puts USA in same position
as when US was only one with atom bomb,
MAD NOT APPLICABLE, first strike
can take out everything, leaving enemy nothing
to retaliate WITH.

Stuxnet is so deeply embedded in Iran
their counterstrike plans are already known.

This powerful weapon is so comprehensive
it is a deterrent in and of its self,
You don't slap someone who has you
by the balls like stuxnet has Iran.

The flip side of the suicide function,
as the press calls it, isn't suicide at all.
Its artificial intelligence, if you start looking
for Flame it knows and disappears.
Flip side is its so easy to penetrate PCs
dumping all traces of its self isn't a problem
it will revisit later.
Read the full story here.It's fascinating.

Tuesday, June 12, 2012

The U.N. could tax U.S.-based Web sites, how long before Obama 'follows' their lead?





The U.N. could tax U.S.-based Web sites, how long before Obama 'follows' their lead?(National Review).

The U.N. recently revived its long-held desire to take control of the Internet. It is unlikely to get its way. So, led by European nations — who else? — it has hit upon another means by which to exercise its influence: Taxes. CNET reports:
The United Nations is considering a new Internet tax targeting the largest Web content providers, including Google, Facebook, Apple, and Netflix, that could cripple their ability to reach users in developing nations.
The European proposal, offered for debate at a December meeting of a U.N. agency called the International Telecommunication Union, would amend an existing telecommunications treaty by imposing heavy costs on popular Web sites and their network providers for the privilege of serving non-U.S. users, according to newly leaked documents.
The documents (No. 1 No. 2) punctuate warnings that the Obama administration and Republican members of Congress raised last week about how secret negotiations at the ITU over an international communications treaty could result in a radical re-engineering of the Internet ecosystem and allow governments to monitor or restrict their citizens’ online activities.
“It’s extremely worrisome,” Sally Shipman Wentworth, senior manager for public policy at theInternet Society, says about the proposed Internet taxes. “It could create an enormous amount of legal uncertainty and commercial uncertainty.”
The United Nations is considering a new internet tax targeting the largest Web content providers, including Google, Facebook, Apple, and Netflix, that could cripple their ability to reach users in developing nations.
The European proposal, offered for debate at a December meeting of a U.N. agency called the International Telecommunication Union, would amend an existing telecommunications treaty by imposing heavy costs on popular Web sites and their network providers for the privilege of serving non-U.S. users, according to newly leaked documents.
The documents (No. 1 No. 2) punctuate warnings that the Obama administration and Republican members of Congress raised last week about how secret negotiations at the ITU over an international communications treaty could result in a radical re-engineering of the internet ecosystem and allow governments to monitor or restrict their citizens’ online activities.
“It’s extremely worrisome,” Sally Shipman Wentworth, senior manager for public policy at theInternet Society, says about the proposed Internet taxes. “It could create an enormous amount of legal uncertainty and commercial uncertainty.”
Robert McDowell, a Republican member of the Federal Communications Commission who wrote an article (PDF) in the Wall Street Journal in February titled "The U.N. Threat to Internet Freedom," appeared to reference the ETNO's proposal for Internet taxes during last week's congressional hearing.
Proposals that foreign governments have pitched to him personally would "use international mandates to charge certain Web destinations on a 'per-click' basis to fund the build-out of broadband infrastructure across the globe," McDowell said. "Google, Tunes, Facebook, and Netflix are mentioned most often as prime sources of funding."
They could also allow "governments to monitor and restrict content or impose economic costs upon international data flows," added Ambassador Philip Verveer, a deputy assistant secretary of state.Read the full story here.

Wednesday, June 6, 2012

GOOGLE - Security warnings for suspected state-sponsored attacks.

GOOGLE - Security warnings for suspected state-sponsored attacks.(GOS).By by Eric Grosse, VP Security Engineering.We are constantly on the lookout for malicious activity on our systems, in particular attempts by third parties to log into users’ accounts unauthorized. When we have specific intelligence—either directly from users or from our own monitoring efforts—we show clear warning signs and put in place extra roadblocks to thwart these bad actors. Today, we’re taking that a step further for a subset of our users, who we believe may be the target of state-sponsored attacks. You can see what this new warning looks like here:

 


If you see this warning it does not necessarily mean that your account has been hijacked. It just means that we believe you may be a target, of phishing or malware for example, and that you should take immediate steps to secure your account.Read the full story here.

Saturday, April 21, 2012

F.B.I. warning :"You may not be able to connect to the internet after July 9".





F.B.I. warning :"You may not be able to connect to the internet after July 9".(E24/7).For computer users, a few mouse clicks could mean the difference between staying online and losing Internet connections this summer.
Unknown to most of them, their problem began when international hackers ran an online advertising scam to take control of infected computers around the world.
In a highly unusual response, the FBI set up a safety net months ago using government computers to prevent Internet disruptions for those infected users.But that system is to be shut down.
The FBI is encouraging users to visit a website run by its security partner, http://www.dcwg.org, that will inform them whether they're infected and explain how to fix the problem.
After July 9, infected users won't be able to connect to the Internet.
Most victims don't even know their computers have been infected, although the malicious software probably has slowed their web surfing and disabled their antivirus software, making their machines more vulnerable to other problems.
Last November, the FBI and other authorities were preparing to take down a hacker ring that had been running an Internet ad scam on a massive network of infected computers.
"We started to realise that we might have a little bit of a problem on our hands because ... if we just pulled the plug on their criminal infrastructure and threw everybody in jail, the victims of this were going to be without Internet service," said Tom Grasso, an FBI supervisory special agent. "The average user would open up Internet Explorer and get ‘page not found' and think the Internet is broken."
On the night of the arrests, the agency brought in Paul Vixie, chairman and founder of Internet Systems Consortium, to install two Internet servers to take the place of the truckload of impounded rogue servers that infected computers were using.
Federal officials planned to keep their servers online until March, giving everyone opportunity to clean their computers. But it wasn't enough time. A federal judge in New York extended the deadline until July.
Now, said Grasso, "the full court press is on to get people to address this problem." And it's up to computer users to check their PCs.
Hackers infected a network of probably more than 570,000 computers worldwide. They took advantage of vulnerabilities in the Microsoft Windows operating system to install malicious software on the victim computers.
This turned off antivirus updates and changed the way the computers reconcile website addresses behind the scenes on the Internet's domain name system.
The DNS system is a network of servers that translates a web address , such as www.ap.org, into the numerical addresses that computers use.
Victim computers were reprogrammed to use rogue DNS servers owned by the attackers. This allowed the attackers to redirect computers to fraudulent versions of any website.
The hackers earned profits from advertisements that appeared on websites that victims were tricked into visiting.
The scam netted the hackers at least $14 million, according to the FBI. It also made thousands of computers reliant on the rogue servers for their Internet browsing.
When the FBI and others arrested six Estonians last November, the agency replaced the rogue servers with Vixie's clean ones. Installing and running the two substitute servers for eight months is costing the federal government about $87,000.
The number of victims is hard to pinpoint, but the FBI believes that on the day of the arrests, at least 568,000 unique Internet addresses were using the rogue servers.Five months later, FBI estimates that the number is down to at least 360,000.
The US has the most, about 85,000, federal authorities said. Other countries with more than 20,000 each include Italy, India, England and Germany. Smaller numbers are online in Spain, France, Canada, China and Mexico.
Vixie said most of the victims are probably individual home users, rather than corporations that have technology staffs who routinely check the computers.
FBI officials said they organized an unusual system to avoid any appearance of government intrusion into the Internet or private computers. And while this is the first time the FBI used it, it won't be the last.
"This is the future of what we will be doing," said Eric Strom, a unit chief in the FBI's Cyber Division.
"Until there is a change in legal system, both inside and outside the United States, to get up to speed with the cyber problem, we will have to go down these paths, trail-blazing if you will, on these types of investigations."
Now, he said, every time the agency gets near the end of a cyber case, "we get to the point where we say, how are we going to do this, how are we going to clean the system" without creating a bigger mess than before.Read the full story here.

Friday, April 6, 2012

"Cyber Czar" wants Homeland Security to patrol America’s Internet borders




"Cyber Czar" wants Homeland Security to patrol America’s Internet borders.(RT).Lawmakers in Washington are divided as to how to implement cybersecurity legislation to protect against infiltration from hackers, but one insider says the answer is simple: just establish border patrol for the Internet in America. Former George W Bush special adviser for cybersecurity, Richard A. Clarke, tackles the topic of America’s susceptibility to Internet crimes in an editorial published in The New York Times this week, and the ex-White House “cyber czar” says the issue could easily be resolved. Clarke argues that America loses billions of dollars every year from foreign hackers that steal information from US computers, and while Congress is at odds over which of the handful of cybersecurity bills best fits the country’s needs, Clarke — who held related positions in both the Clinton and George W. Bush administrations — offers a solution of his own. In an op-ed published on April 2, Clarke suggests that the US Department of Homeland Security stands to largely stop critical data from being accessed by foreign hackers if they can successfully implement a way to monitor what goes in and out of America’s online infrastructure. Clarke argues in his op-ed that the current administration is all too hesitant to grab the issue by the horns. Not only has Congress complicated matters by considering several similar laws to establish cybersecurity guidelines with little success, he says, but President Barack Obama himself has failed to exercise his own authority to take on the issue.
The commander-in-chief, argues Clarke, could easily let the Department of Homeland Security take a stab at the problem. In turn, all they would have to do is scan trillions upon trillions of bits and bytes being beamed out of the personal computers in each American household. “Under Customs authority, the Department of Homeland Security could inspect what enters and exits the United States in cyberspace,” writes Clarke.
“Customs already looks online for child pornography crossing our virtual borders. And under the Intelligence Act, the president could issue a finding that would authorize agencies to scan Internet traffic outside the United States and seize sensitive files stolen from within our borders.”
Clarke insists that the president could easily step up and establish these guidelines himself without dealing with a divided Congress. Currently the US House of Representatives and Senate are considering varying legislation that would let the government monitor the Web to differing degrees. According to Clarke, however, letting DHS dig into the data going in and out of America’s computer systems would be the best place to start. The op-ed, titled “How China Steals Our Secrets,” was published days after a congressional panel heard that a 10-year, $1 billion research program was copied by hackers in a single night. The US military’s Cyber Command chief called the crime at the time “the greatest transfer of wealth in history,” but Clarke fears that future attacks will only rival it. Should hackers uncover classified information and hand it over to the Chinese, writes Clarke, America’s “competitive edge” against other nations will be jeopardized. He adds that many private firms are already unknowingly being hacked by outside users with unauthorized access and the next major cybercrime could already be on the horizon. “If Congress will not act to protect America’s companies from Chinese cyberthreats, President Obama must,” writes Clarke.
In the new op-ed, however, Clarke attempts to downplay the privacy concerns that are certain to arise should his own idea for cybersecurity take off. “Because it is fearful that government monitoring would be seen as a cover for illegal snooping and a violation of citizens’ privacy, the Obama administration has not even attempted to develop a proposal for spotting and stopping vast industrial espionage,” he explains, “…But by failing to act, Washington is effectively fulfilling China’s research requirements while helping to put Americans out of work.” For now Clarke’s suggestion is merely a pipe dream for the man that spent decades working for the US government, including an impressive stint on the United States Security Council. In the meantime, though, Congress could be very close to establishing other guidelines for the World Wide Web that might eliminate online privacy in America as it currently exists. One of the proposed bills currently garnering significant support in Washington is the Cyber Intelligence Sharing and Protection Act, or CISPA, which, if passed, would let the government get into any personal online communication it wants if it can claim that efforts exist “to degrade, disrupt or destroy” either “a system or network of a government or private entity.”
“We have a number of concerns with something like this bill that creates sort of a vast hole in the privacy law to allow government to receive these kinds of information,” Kendall Burman of the DC-based Center for Democracy and Technology tells RT during a recent interview. “Cyber security, when done right and done narrowly, could benefit everyone,” she added, “but it needs to be done in an incremental way with an arrow approach, and the heavy hand that lawmakers are taking with these current bills . . . it brings real serious concerns.” To POLITICO, the CDT’s vice president of public policy, Jim Dempsey, agrees that some sort of legislation could be a blessing as far as protecting America’s cyber infrastructure goes, but that is far and away different from digging into the personal correspondence being conducted from every computer in the country. “I think the government itself is a little schizophrenic on this,” explains Dempsey.
“On the one hand, there’s clearly the appropriate desire to say, ‘When a hurricane hits, we want to get information on the ground.’ Then there are others that say, ‘We also want to hear about protests and demonstrations.’” Rep. Patrick Meehan (R-Pa.), chairman of the House Homeland Security Subcommittee on Counterterrorism and Intelligence, adds to POLITICO that the government needs to figure out how to go about handling the “gray area” between personal matters and national threats if it wants to actually establish cybersecurity legislation without losing the support of millions of Americans. “The concept that the government would somehow be monitoring and storing inquiries of individual Web activities — many would find that disconcerting,” says Meehan. In his op-ed, however, Richard Clarke says that the government could easily alleviate those concerns. “[T]his does not have to endanger citizens’ privacy rights,” urges Clarke, who at the same time suggests that the Obama administration has failed to take the initiative in the matter thus far because “it fears a negative reaction from privacy-rights and Internet-freedom advocates who do not want the government scanning Internet traffic.” The CDT’s Burman also agrees as much and warns that, should the government give CISPA or any of the other cyber-surveillance legislation the go ahead, Congress could expect a backlash like they experienced earlier this year after attempting to pass SOPA, the Stop Online Privacy Act. “One of the lessons we learned in the reaction to SOPA and PIPA is that when Congress tries to legislate on things that are going to affect Internet users’ experience, the Internet users are going to pay attention,” Burman tells RT.Hmmmm......Perhaps Obama is waiting till he has 'more flexibility'? Read the full story here.




Related Posts Plugin for WordPress, Blogger...