Showing posts with label internet. Show all posts
Showing posts with label internet. Show all posts

Saturday, November 9, 2013

New Bucks for Bugs Program Focuses on Open Source Software, Internet Infrastructure

Dark Reading (11/07/13) Kelly Jackson Higgins 

The Microsoft- and Facebook-sponsored Internet Bug Bounty program pays as much as $2,500 for a new vulnerability detected in key open source platforms, and offers a minimum reward of $5,000 to researchers who uncover working flaws in sandbox technologies, as well as bugs in the Internet's underlying infrastructure. "This program provides direct incentive for people to raise the quality of [software] flaw analysis," notes security researcher Dan Kaminsky. An Internet bug found under the program is only deemed worthy of compensation if it affects multiple products or a significant number of users, or is severe or novel. Researchers receive two rewards, one for bug discovery and another for correction. Veracode's Chris Wysopal says Microsoft and Facebook's collaboration reflects the pressing need for key players to counteract the black market for bugs, while also benefiting open source projects. Facebook's Alex Rice says the program is complementary to existing bounty initiatives, and covers areas of the Web that existing programs currently do not. "This bounty is a great way to support coordinated disclosure of critical vulnerabilities in shared components of the Internet stack," says Microsoft's Katie Moussouris. Kaminsky says the program "puts a stake in the ground that this is what a program should look like, these are the types of good bugs to pay for."

Wednesday, October 9, 2013

U.S. Ranks Fourth in Internet Freedom as Surveillance Grows Worldwide

Network World (10/04/13) Colin Neagle 

Although U.S. Internet freedom has decreased over the past year due to surveillance, the United States still ranks fourth in a recent Freedom House study of 60 countries. The study measured obstacles to accessing information online, content limitations, and violations of user rights. In addition, the study cites issues such as government blocking of specific Internet content, surveillance measures, and actions taken against online dissidents to governing or religious bodies. Iceland claimed the top spot on the list as the most free nation on the Internet, followed by Estonia, Germany, and the United States. The remaining top 10 included Australia, France, Japan, Hungary, Italy, and the United Kingdom. Surveillance has grown more advanced and pervasive in 35 out of the 60 countries examined, according to the study. The most restrictive countries were Iran, China, and Cuba. However, the study notes 16 countries, including Morocco, Burma, and Tunisia, that have increased Internet freedom. Meanwhile, Freedom House says India showed the biggest drop in Internet freedom over the past year. Freedom House said the drop was due to "deliberate interruptions of mobile and Internet service to limit unrest, excessive blocks on content during rioting in northeastern states, and an uptick in the filing of criminal charges against ordinary users for posts on social-media sites."

Thursday, November 22, 2012

Internet Freedom Remains U.S. Priority at U.N. Conference


IDG News Service (11/18/12) Grant Gross

The U.S. delegation to the U.N. International Telecommunication Union's (ITU's) upcoming World Conference on International Telecommunications (WCIT) will advocate for free speech online and oppose any broad new Internet regulations, says delegation head Terry Kramer.  The delegation is worried that some nations will lobby for telecom-style termination fees for Web traffic in order to raise funds for broadband implementation, while some countries might call for Internet censorship for cybersecurity reasons.  Kramer says the United States will oppose any attempt to impose online regulation.  Meanwhile, ITU's Gary Fowlie says the WCIT's regulations should be extended to support a "global information society."  Fowlie also says WCIT should investigate ways to ensure universal Internet affordability and accessibility.  However, he notes that Internet censorship efforts would run afoul of the U.N.'s Universal Declaration of Human Rights, which upholds freedom of expression "through any media and regardless of frontiers."  Syracuse University professor Milton Mueller advocates ITU jettisoning international telecom regulations, with such rules best left to private companies and civil society.
http://www.pcworld.com/article/2014714/internet-freedom-remains-us-priority-at-un-conference.html

Scientists Find Cheaper Way to Ensure Internet Security


New York Times (11/20/12) John Markoff

Scientists at Toshiba and Cambridge University have used an advanced photodetector to extract weak photons from the torrents of light pulses carried by fiber-optic cables, in a technique that offers a less expensive way to ensure the security of the Internet.  Based on quantum physics, the approach would make it possible to safely distribute secret keys necessary to scramble data over distances up to 56 miles.  Although several quantum key distribution systems are commercially available, they rely on the need to transmit the quantum key separately from communication data, often in a separate optical fiber, which adds cost and complexity, says Toshiba Research Europe's Andrew J. Shields.  Weaving quantum information into conventional networking data will lower the cost and simplify coding and decoding data.  The system developed by Toshiba and Cambridge sends the quantum information over the same fiber, but isolates it in its own frequency.  "We can pick out the quantum photons from the scattered light using their expected arrival time at the detector," Shields says.  "The quantum signals hit the detector at precisely known times--every one nanosecond, while the arrival time of the scattered light is random."
http://www.nytimes.com/2012/11/20/technology/fiber-optic-breakthrough-to-improve-internet-security-cheaply.html

Tuesday, July 24, 2012

Tech Policy Download: Cybersecurity Bill Improvements Clear Way for Vote




July 25 - Boston, MA - Deven McGraw will participate on a panel on "Best Practices in Medical Device Security and Privacy."
July 27 - Las Vegas, NV - Kevin Bankston will participate in a panel entitled "Should the Wall of Sheep Be Illegal? A Debate Over Whether and How Open WiFi Sniffing Should Be Regulated" at Defcon"


Cybersecurity legislation inched forward last week with the introduction in the Senate of a new bill with language on information sharing that is significantly more favorable to privacy than other pending bills. While major concerns still remain, the Majority Leader may push for a cloture vote this week. On the international front, the International Telecommunication Union promised greater transparency, but not nearly enough to justify the intervention of that UN body into Internet policy making. Meanwhile, CDT re-issued an important set of privacy guidelines for developers of mobile apps, just as the Commerce Department launched its mulit-stakeholder consultation on mobile privacy.

Privacy Amendments Strengthen Cybersecurity Bill

Cybersecurity legislation in the Senate took a welcome turn with the introduction of a new bill containing several key privacy amendments. Lawmakers have struggled to draft legislation that would allow companies and the government to share information about cyberattacks and threats without eroding privacy. The new amendments, included in a revised bill sponsored by Senators Lieberman, Collins, Feinstein and Carper, narrow the definition of what can be shared with the government, focusing more concretely on indicators of cybersecurity threats. In a second important change, companies will be encouraged to share cybersecurity information with civilian agencies, not with military entities such as the National Security Agency. Further, the amendments specify that information shared with the government would be used only for cybersecurity and to protect against serious threats to children or imminent threats of death or serious bodily injury, and not for other purposes unrelated to cybersecurity.
Concerns still remain, however, not only with the information sharing language and with provisions on countermeasures and monitoring, but also with Title I of the bill, which seeks to promote improvements in the cybersecurity practices of critical infrastructure operators. A vote testing support for the bill, on a motion to invoke cloture (that is, to limit debate), could come later this week.

ITU Gives a Nod Towards Transparency; Still a Long Road to Full Civil Society Participation

The International Telecommunication Union, in advance of a December meeting that will consider how much authority the UN body should have over Internet governance, announced that it would make public one document summarizing only some proposals under consideration and launch a platform for public comment on the document. Notably, a prior version of this document was already leaked weeks ago on WCITleaks and the document does not attribute proposals to specific governments. This limited action does not translate into meaningful transparency or participation by civil society. The vast majority of documents related to the ITU process, including specific positions governments are taking on revisions to a key ITU treaty, remain locked behind a password wall and are only available to other Member States and Sector Members. CDT and other civil society groups around the world are urging each Member State of the ITU to publicly release preparatory documents for the treaty revision process, including the Member State's own proposals for revising the treaty, and to convene open, public consultations to solicit input from all stakeholders to inform the Member State's positions in advance of the December meeting.

CDT Issues Updated Privacy Guidelines for Mobile Apps

On July 12, the Commerce Department held the first in a series of forums aimed at developing "an open, transparent, consensus-driven process to develop a code of conduct regarding mobile app transparency," according the National Telecommunications & Information Administration (NTIA), the agency hosting the meetings.
To help jumpstart the process, and to guide industry in the meantime, CDT and the Future of Privacy Forum released an updated version of their "best practices" guide for mobile app developers. The guide is intended to help developers as they build privacy into their products.
The 20-page guide, developed through a consultative process chaired by CDT and FPF is intended to be a road map for mobile app developers to build privacy into your apps, better inform and empower end-users, and foster trust and confidence in the mobile app ecosystem.

As ACTA Tanks in Europe, USTR Announces Potentially Important Shift for TPP Talks

A loose coalition of Internet companies, advocacy groups and individuals that helped defeat SOPA/PIPA have launched the Internet Defense League, which is intended to fight for an open and innovative Internet by enlisting millions of people around a shared set of values.

Victory for Internet Freedom: Data Retention Mandate Absent from Bill

Rep. Lamar Smith (R-TX) recently introduced the Child Protection Act of 2012 (HR 6063), and unlike a similar bill he introduced last year, HR 6063 does not contain a data retention mandate. CDT has long spoken out against the troubling - and unnecessary - threats data retention mandates pose to Internet users' privacy.

Friday, March 2, 2012

Removing 'Black Sheep' Could Make Internet Run More Efficiently

PhysOrg.com (02/28/12) Lisa Zyga

Chinese Academy of Sciences (CAS) researchers are improving network transmission efficiency by identifying certain links or edges that can be removed to decrease the overall congestion.  These links, known as black sheep, are those that connect the busiest hubs.  "Our main findings reveal the effect of enhancing network capacity of edge-removal in networks and the prerequisite of the effect," says CAS's Guo-Qing Zhang.  The researchers demonstrated that modifying the network does not require a complicated redesign and that significant improvement is possible by deleting just a few well-chosen links.  The researchers analyzed a network model that simulates packet traffic to choose which links to remove.  Removing the black sheep links significantly increased the network's transmission capacity.  The researchers also recently found that for this method to work effectively the network structure must be heterogeneous in terms of node betweenness values.  "Our recent paper doesn't further improve network capacity of the method, but points out that heterogeneity of network structure is a necessary condition for the effect's existence, highlights the rationality based on betweenness, and discusses the effect's applications in engineering practice," Zhang says.
http://www.physorg.com/news/2012-02-black-sheep-internet-efficiently.html