Advertise On EU-Digest

Annual Advertising Rates
Showing posts with label Internet Security. Show all posts
Showing posts with label Internet Security. Show all posts

1/3/17

Security on-line: An Internet primer for healthy web habits - by Doug Bernard

I
Internet surveillance by Government and the Private sector
nformation may want to flow freely, but there are plenty of forces that want to dam up the web’s flow of information and punish those who try to fight back.
In particular, some governments are working hard to wall off parts of the Internet by filtering and blocking what people can see. Others are exploiting the open nature of the web to spy on individuals and punish them for what they do Internet Surveillance online.

As surveillance and censoring technologies advance, so, too, do new tools for your computer or mobile device that help protect your privacy and break through Internet censorship.

Think of this project as something like a primer on Internet circumvention and anonymity.

This is a basic overview on what the challenges are and how to fight back, emphasis on “basic.”  This is not a complete, iron-clad, never-changing rule book. Rather, think of this as a general guide to discuss a few key concepts and introduce several tools that can help you keep the Internet relatively free and safe.

Circumvention is not anonymity: Breaking through a firewall does not equal keeping yourself anonymous online. Some of the tools we’ll focus on will help you both circumvent blocks as well as shield your identity while online. Others tend to do one or the other, but not both.

Every country, just like every user, is different: If you’re planning on doing a lot of uploading, or live in a country where the government actively spies on what users are doing, you probably want to select a tool with high anonymity. If you mostly just want to reach websites that your government blocks, you may be OK using tools that just help you do that. And remember, no one tool can do everything, so you may want to try your own mix of protection and circumvention.

Sometimes government isn’t the problem: In the early 2000s, two Chinese dissidents, Wang Xiaoning and Shi Tao, were jailed by China for their online activities. What wasn’t widely known at the time is that Yahoo voluntarily turned over the pair’s email records to Chinese authorities, which were then used by prosecutors. It’s important to remember that private corporations which operate websites and ISPs are constantly gathering all sorts of data on you – sometimes for their own profit, and sometimes at the order of a government.

Some tools are better than others: In 2009 during what some called the “Twitter Revolution,” Iranians took to the streets to protest recent elections and used websites, social media and other online tools to organize. That is, until the government cracked down. Then along came a new tool called “Haystack” that was supposed to help Iranians evade government blocks. However, because of a programming flaw, “Haystack” also likely exposed many of its users to Iranian authorities before it was shut down.  Lesson: new isn’t necessarily better.

Practice good web hygiene: Just like you need a little discipline in your personal life, you should always employ some basic habits when going online. Try not to use public WiFi, as anyone can easily monitor what you’re doing and steal personal information. If you’re using a web browser, try to use HTTPS encryption as often as you can. Don’t open emails from people you don’t know, or attachments you haven’t asked for. Clear your browser’s history and cookies file as often as you can. You don’t need to be fearful about using the web, but a little skepticism goes a long way.

Nothing’s perfect: If there’s one thing that can be said with perfect certainty, it’s that there is no 100 percent guarantee of anonymity and free access online. If a government wants badly enough to control what you do online, specially if you are a criminal or terrorist, they’ll probably find a way.

Here are some of the  links too tools you can download to circumvent potential surveillance services whatever they may be.


\
DNS



Freegate



PGP



Psiphon



TOR (The Onion Router)



UltraSurf



VPN (Virtual Private Network)

Read more: An Internet primer for healthy web habits | VOA Special Report

8/27/15

Iran and Internet Security: Here’s How Iran Resets Your Gmail Password - by Ben Collins

Tehran’s hackers are getting trickier—and finding new ways to get into your Gmail.
Iranian hackers have now found a way to get around Google’s two-step verification system and infiltrate GMail’s most elaborate consumer security system, according to a new report.

The Citizen Lab’s John Scott-Railton and Katie Kleemola outlined a few new ways that Iranian hackers can compromise the accounts of political dissidents, or even everyday citizens.

“Their targets are political, and include Iranian activists, and even a director at the Electronic Frontier Foundation,” said Scott-Railton in an email, referring to the digital rights organization. “In some cases they even pretend to be Reuters journalists calling to set up interviews.”

The report says attacks on political targets are new. But the methodology of the hack has been going on for years, especially as reliance on so-called “two-factor authentication”—using something in addition to a password to get into your account—has gone up.

Read more: Here’s How Iran Resets Your Gmail Password - The Daily Beast

8/9/15

Internet Security: Are hackers helping or harming us? - by Mark Ward

Every week, almost every day, hackers are poking holes in the devices we carry, drive and use. Over the past couple of weeks the numbers and severity of the flaws these technical wizards have found have hit fever pitch.

They brought to light a security bug in almost one billion Android phones.

Then there was the car hack that led to 1.4 million vehicles being recalled for a software upgrade.

Don't forget the vulnerability found in an obscure bit of software that, if exploited, could have shut down big chunks of the net. We've also have emergency patches for Windows and Flash.

Read more: Are hackers helping or harming us? - BBC News

2/6/15

EU wants to snoop on Skype to combat terrorist threat

The EU agency for judicial cooperation says the bloc needs to develop a common approach to lawfully intercept services like Skype and Viber, to help keep track of European militants arriving back home from the Middle East.

The measures were outlined in a Eurojust report, which was discussed by a committee of the European Parliament on Thursday, said Reuters after they saw the report.
 
Following deadly terror attacks in Paris last month, EU nations are worried about the danger of radicalized and trained Islamists returning from the Middle East. Militants have often used social networks to spread ideas, jihadist propaganda and recruit new members.

"The use of the internet for terrorist purposes creates an additional burden for investigations and prosecutions of foreign fighters," the Eurojust report said.

The report touched on the fact that "the interception of Voice over Internet Protocol (VoIP) communications (e.g. Skype, Viber, etc.) is problematic and seriously hinders relevant investigations." It believes that "a harmonized approach at EU level may be necessary to address technical difficulties and legal challenges in the gathering and admissibility of e-evidence.”
 
Eurojust highlights the problem in securing convictions in suspected terrorist cases by pointing out that evidence tracked online may not be accepted in some courts due to national laws. The report urges cooperation between judicial authorities within the bloc.

Read more: EU wants to snoop on Skype to combat terrorist threat – report — RT News

5/19/13

Consumer Privacy - Google Glass: A Privacy Concern?

Perhaps you’ve seen them already—people walking around with glasses that don’t resemble eyeglasses, with a tiny little box on one side. While they may look funny and awkward, many people are very nervous about what Google Glass means for your privacy.

As wearable technology goes, Google Glass is exciting. The idea of wearing a computer that you can tell it what to do, get the answers you need, and be able to engage with friends over social media effortlessly seems like something out of the future. With Google Glass, wearers can surf the Web and look up answers to questions, take pictures and record video and upload them to Google+ and YouTube, initiate a Hangout, and get turn-by-turn navigation directions. Initial reports from people who are testing the headgear report a surprisingly comfortable fit and smooth online experience.

But as all things Google, there are some people increasingly worried about the erosion of privacy. It’s one thing for Google Glass wearers to agree to share more of their information—where they go in the physical and virtual world and what pictures they are taking—with Google. But it’s a whole new level of privacy concerns when taking pictures and taking video may violate someone else’s privacy.

Read more: Google Glass: A Privacy Concern? - ZoneAlarm Blog

4/3/13

Internet - Free WiFi: Surf Safe Tips While On “FREE Wi-Fi” - by Andrea Eldridge,

It seems every shop and gathering place proclaims “Free Wi-Fi,” but is it safe to check your email at the airport, library or McDonalds?  There are risks to accessing private data while connected to an unsecured, community network.  Here’s how to surf safely when you’re on public Wi-Fi.

When you access the Internet on a public network, your computer or Smartphone is at risk of being accessed by other users on the same network.  It’s surprisingly easy for the person sipping the Macchiato next to you to run simple programs to collect passwords and information entered by fellow patrons.

Most Wi-Fi “hotspots” are unencrypted since it’s a hassle to make every customer find out the day’s Wi-Fi password, meaning even if you’re alone in the store someone sitting in the parking lot could be connected to the network.

It may seem unlikely that your data will be hacked, and that’s probably true.  But just like you might be able to leave your car unlocked and never suffer a break-in, is it worth the risk?  Anyone who’s had their Facebook account hacked or banking password compromised can attest that it can take months or more to put your online identity back in order.

Luckily there are some easy steps you can take to protect yourself on public Wi-Fi.  Since logging on to a network gives other users on that network access to your shared folders, the first thing to do when you’re on a public network is to turn off sharing.  Windows users should navigate to the Control Panel, then Network and Internet.  Select the option to “Choose homegroup and sharing options” and then select “Change advanced sharing settings…” Turn off file and printer sharing and public folder sharing.  If you’re using a Mac, go to System Preferences and then Sharing.  Make sure all boxes are unchecked.

Consider also disabling network discovery as it prevents others from seeing your machine on the network.  You can re-enable it when you’re no longer logged on to a public network.

Read more: Surf Safe Tips While On “FREE Wi-Fi” | Business 2 Community

Internet - security: Smartphones increasing global cyber crime

The flaw in the smartphone is that it is too useful and too user friendly – for users who trade convenience for security.

They collect our emails, store our bank details, we tweet and use Facebook on them. They are our bank vault, our confidante, and our guide.

Criminals use Wi-Fi connection to harvest passwords and other sensitive data from smartphones or computers – often giving their Wi-Fi hotspots fake names familiar to punters at cafes and in airports.

Many smartphones are set up to automatically leap on to available Wi-Fi hotspots and start downloading emails.

Forty per cent of mobiles sold this year have been smartphones – and this has been a bumper year for malware developers who have focussed their attention on smartphones.

Those running Google’s Android system have been especially targeted.

Note EU-Digest: the first step to take is to get an anti-virus program for your smartphone to reduce the risk of being "zapped". There are even some reputable free ones available on the market. 

Travelers should be particularly wary of cyber threats on vacation as they access free wireless networks with their smartphones, tablets or laptops, says software security company Symantec Corp.

Read more: Smartphones increasing global cyber crime - Hindustan Times

4/29/12

Internet and Privacy: U.S. turns spy agency on itself, critics of cyber bill say - by Tabassum Zakaria

(cartoon by Mark Parisi)
The U.S. House of Representatives passed a cyber security bill on Thursday that would allow the government and companies to share information about hacking, but which has raised privacy concerns and a veto threat from the White House.

The House approved the bill 248-168, prompting the top Republican and Democrat on the intelligence committee who sponsored it to issue a joint statement lauding the bipartisan approval.

The legislation allows federal agencies such as the National Security Agency, an intelligence agency that eavesdrops overseas and protects classified U.S. government computer networks, to share secret cyber threat information with American companies to help the private sector protect its networks.
Critics had raised privacy concerns that the sharing in return of “threat information” from private network operators to the government was so broad as to allow the NSA to effectively collect data on American communications, which is generally prohibited by law.

For more: U.S. turns spy agency on itself, critics of cyber bill say - The Globe and Mail

4/20/11

The Netherlands: Internet - Dutch data protection authority pursues Google

The Netherlands has added itself to the list of countries taking Google to task for saving private wireless Internet connection data while cruising through Dutch cities and towns for its Street View maps.

The Dutch Data Protection Agency (DPA) on Tuesday called on Google to contact the 3.6 million WiFi network owners in the Netherlands and offer them a way to have the data the US-based Internet giant saved removed from servers.

The Dutch DPA said Google has been ordered to inform the affected parties about the company's collection of their data. "Within the same period of three months, Google must also offer an on line possibility to opt-out from the database in order to enable people to object to the processing of the data concerning their WiFi routers," the authority wrote in an English-language statement posted to its website.

Note EU-Digest: Just imagine what would have happened if a European search engine company had done the same in the US. This is unacceptable. Google must be taken to court in Europe on this issue. Google can not be allowed to get away by offering an apology and stating the information has been removed from their servers. The Netherlands should also lodge an official complain with the European Commission and the European parliament.

For more: Dutch data protection authority pursues Google | Science & Technology | Deutsche Welle | 20.04.2011

9/10/10

European police in pirate raids

Police targeted 48 sites in countries including Britain, the Netherlands, Czech Republic and Hungary. The suspects were the alleged leaders of four illegal file-sharing networks and were charged with hacking, piracy and computer fraud.

Five of the arrests were in Belgium and the others were made in Norway and Sweden.  By Wednesday evening, all of the suspects arrested in Sweden had been released, following the raid of seven premises were raided including PRQ, a web hosting firm with links to the file-sharing site Pirate Bay and whistle-blowing website WikiLeaks.

For more: BBC News - European police in pirate raids

1/18/10

Law Firm Suing China Hit By Cyber Attack - by Thomas Claburn

Last week, Santa Barbara, Calif.-based CYBERsitter sued the People's Republic of China, the two Chinese software makers, and seven computer manufacturers for distributing Web filtering software known as Green Dam with allegedly stolen code. This week, the law firm representing the company said that it had been targeted in a cyber attack from China.

In a phone interview, Elliot B. Gipson of Gipson Hoffman & Pancione described what amounts to a spear-phishing attack -- the same technique used against Google in China. "They were e-mails targeted at individuals in our law firm that were made to appears as if they were coming from other individuals at our law firm," he said. "They attempted to get the target to click on a link or attachment."

The firm's initial investigation has shown that at least some of the e-mail messages originated in China and that some of the malware payloads were on servers in China. The attacks have been reported to the FBI and members of the House Intelligence Committee.


For more: Law Firm Suing China Hit By Cyber Attack -- InformationWeek

Google China cyberattack part of vast espionage campaign, experts say - by Ariana Eunjung Cha and Ellen Nakashima

Computer attacks on Google that the search giant said originated in China were part of a concerted political and corporate espionage effort that exploited security flaws in e-mail attachments to sneak into the networks of major financial, defense and technology companies and research institutions in the United States, security experts said.

For more: Google China cyberattack part of vast espionage campaign, experts say - washingtonpost.com

China spinning Google report and avoids issue of Human Rights - by Owen Fletcher


Chinese state media has spun Google's threat to leave China as a purely commercial move, as authorities there apparently work to limit discussion of human rights issues raised by Google.

"Several days after the Google announcement, there seem to be fewer Google-related posts and editorials in China that include across-the-bow shots at Internet censorship," David Bandurski, a researcher at the University of Hong Kong, wrote in a blog post on Sunday.

Chinese journalists and news editors can face punishment by authorities for publishing articles on sensitive political topics. They are also sometimes ordered not to write on sensitive issues or to post only official newswire stories on them.

Note EU-Digest: Whatever spin the Chinese Government gives to the issue of Human Rights nothing will eventually help them in the long run. The "Genie is out of the bottle" and the only thing still slowing the process down is the greed of most Western Corporations who are willing to "sell their soul to the devil" for financial gain.
For more: What Gmail Hack? China Spins News of Google Threat - PC World


1/16/10

Google-China showdown may alter tech game


Few see China, whose leadership has grown more conservative and nationalistic in recent years, backing down in the face of the ultimatum. But such a declaration by a company of Google's stature could raise the ethical bar for businesses that choose to remain, and grant permission for firms without a presence there to second-guess the perceived wisdom that they should be there, observers say.

The Google-China flap has already reignited the debate over global censorship, reinvigorating human rights groups drawing attention to abuses in the country and prompting U.S. politicians to take a hard look at trade relations. The Obama administration issued statements of support for Google, and members of Congress are pushing to revive a bill banning U.S. tech companies from working with governments that digitally spy on their citizens.

For more: Google-China showdown may alter tech game


German government issues official warning. Do NOT use Internet Explorer until it is fixed


Internet Explorer just cannot catch a break these days. The German Federal Office for Security in Information Technology has officially advised people to stop using Internet Explorer, all versions, until Microsoft releases a new patch for the latest gaping security hole.

If you were not aware, in Internet Explorer there is a current security problem that allows a webpage to maliciously inject code onto the machine running the browser. This bug was used by “Operation Aurora,” which hacked Google and other companies in recent days.

In a statement, the BSI (German Federal Office for Information Security) recommends that until a full patch is released for this “zero day” flaw, that Internet Explorer is not safe, even if users run IE in protected mode.


For the complete report: German government issues official warning. Do NOT use Internet Explorer until it is fixed.

EU Commissioner Kroes calls Chinese cyber attacks 'worrying'


The woman to become the EU's top internet official has said she backs Google's threat to quit China over the government's web censorship. "We have to have freedom of speech, we have to have the possibility to put things on the net," Neelie Kroes said.

Google said earlier it would stop censoring search results in China and might shut down its China-based Google.cn site, citing attempts to break into accounts on its Gmail service used by human rights activists. Ms Kroes said these allegations, if proved, were "particularly worrying as targeting of human rights activists in China and elsewhere" violated fundamental rights such as the freedom of opinion.

Ms Kroes is currently the EU's antitrust commissioner and will likely switch to her new post next month if she receives the backing of the European Parliament later this month. EU lawmakers quizzed her at a three-hour hearing on Thursday.

She called for technology companies to take privacy concerns seriously, saying failure to do so could prevent people from using the internet frequently. Her predecessor threatened to regulate social networking sites like Facebook unless they tightened data storage and privacy standards.

For more: The Press Association: Kroes backs Google China plans


Google - China attack episode: Is Microsoft to blame?

A complex attack on the Google Gmail accounts of human rights activitists – apparently from hackers based in China – has now been indirectly blamed on Microsoft, after McAfee Labs announced last night that the attacks appear to exploit a little-known vulnerability in Microsoft Internet Explorer.

The Google Gmail attacks – which were paralleled by similar attacks on Adobe and a number of other IT companies – are the result of a complex targeted attack by hackers in China that stem from a new and little-known vulnerabiity in the Microsoft web browser.

In his analysis of the saga, George Kurtz, McAfee's chief technology officer, said that, in the company's investigation it discovered that one of the malware samples involved in this broad attack exploits a new, not publicly known vulnerability in Microsoft Internet Explorer.

For more: Infosecurity (UK) - Google - China attack episode: Is Microsoft to blame?


1/13/10

Google Attack Part of Widespread Chinese Spying Effort

Google's decision Tuesday to risk walking away from the world's largest Internet market may have come as a shock, but security experts see it as the most public admission of a top IT problem for U.S. companies: ongoing corporate espionage originating from China. Google, by implying that Beijing had sponsored the attack, has placed itself in the center of an international controversy, exposing what appears to be a state-sponsored corporate espionage campaign that compromised more than 30 technology, financial and media companies, most of them global Fortune 500 enterprises.

As part of our investigation we have discovered that at least twenty other large companies from a wide range of businesses -- including the Internet, finance, technology, media and chemical sectors -- have been similarly targeted," wrote Google Chief Legal Officer David Drummond in a Tuesday blog posting. "Second, we have evidence to suggest that a primary goal of the attackers was accessing the Gmail accounts of Chinese human rights activists." Google's security team eventually managed to gain access to a server that was used to control the hacked systems, and discovered that it was not the only company to be hit. In fact, 33 other companies had also been compromised, including Adobe Systems, according to several sources familiar with the situation. On Tuesday Yahoo -- another likely target -- declined to say whether it had been hit, but the company did issue a brief statement in support of Google. These "kinds of attacks are deeply disturbing," Yahoo said.

Drummond, in his blog post, said that -- in part due to this incident -- Google would no longer censor search results in China, a move that could cause its Web site to be blocked by the Chinese government.

The U.S. government is taking the attack seriously. Late Tuesday, U.S. Secretary of State Hillary Clinton released a statement asking the Chinese government to explain itself, saying that Google's allegations "raise very serious concerns and questions. The ability to operate with confidence in cyberspace is critical in a modern society and economy," she said.

For more: Google Attack Part of Widespread Spying Effort - PC World Business Center

4/8/09

PC-World/EU-Digest: Internet-wide Problem to Be Revealed at Black Hat Conference in Amsterdam April 14-17 - by Jeremy Kirk

For the complete report from PC World click on this link

Internet-wide Problem to Be Revealed at Black Hat Conference in Amsterdam April 14-17 - by Jeremy Kirk

Organizers of next week's Black Hat Europe conference in Amsterdam are promising a security presentation that could impact anyone who uses the Internet, but no details have been released yet. They say the presentation, due to take place April 16, will be as important as the one from security researcher Dan Kaminsky at a Black Hat's conference last July about a widespread flaw in the DNS (Domain Name System). Kaminsky's research prompted a massive, industry-wide effort to patch DNS servers vulnerable to a dangerous attack that could redirect Web surfers to fraudulent Web sites even if the URL (Uniform Resource Locator) was typed in correctly, among other attack scenarios.

Black Hat's Europe conference, in Amsterdam, will also feature cutting-edge presentations on security problems in Apple's OS X operating system, the OpenOffice.org productivity suite and SAP software. Also, six new vulnerabilities will be revealed, along with 12 tools for security pros.

2/11/09

attorneyatlaw- Internet: European Leaders Pass Limits on ‘Cyber-bullying” on social networks like Facebook and MySpace, U.S. Should Follow Suit

For the complete report from the Attorney At Law click on this link

Internet: European Leaders Pass Limits on ‘Cyber-bullying” on social networks like Facebook and MySpace, U.S. Should Follow Suit

On Tuesday Seventeen social networking sites in Europe including Facebook and MySpace signed on Tuesday a pact aimed at curbing "cyber-bullying" and protecting the privacy of underage users, the European Commission said. "It is an important step forward toward making our children's clicks on social networking sites safer in Europe," Viviane Reding, EU Commissioner for Information Society and Media said in a statement. The use of social networks has grown over the past year by 35 percent in Europe and is expected to more than double to 107.4 million users by 2012, the Commission said, warning that this would expose more children to risks online.

The new EU pact is primarily focused on preventing access to children under age 18 who post on line. The agreement requires the social networking sites to make sure that profiles of users who are under age 18 are set by default to “private,” that profiles of children set to “private” cannot be found through other websites or search engines, and to provide an easy way for underage users to report abuse or unwanted contact. As in the US with the case of Megan Meier, the effects of cyber-bullying can be particularly tragic and devastating. U.S. political leaders have been approached by their European colleagues to follow the blueprint drafted in Europe and implement greater restrictions against on-line harassment of children.