Like the Kindle, netbooks are going to be a popular gift for Xmas. Also like the Kindle, you should understand their limitations - there's a good chance the recipient won't like the limitations.
The primary limitation of a netbook is speed, no CD-ROM, and keyboard/screen size. In exchange, you get increased portability and longer battery life. You can't play games well on it, but you can carry it with you wherever you go and sit for hours in a café typing away.
Tuesday, December 08, 2009
Friday, December 04, 2009
Shodan scares me
One of the problems of being white-hat hacker is that we scare ourselves. Such is the case of the "Shodan" engine that was released last month. It's a simple idea, one that has been discussed before. It simply scans the Internet for likely web server ports and indexes the HTTP headers that come back. Now that somebody has actually done it, and we can play with it, we find it's a lot scarier than we had imagined.What this means is that instead of finding an exploit that works on a target system, you can grab any exploit then find a system vulnerable to it.
Thursday, December 03, 2009
Ironic...

"It's what you do next that counts"
It seems that Accenture is a bit of a precog. Although Tiger Woods is the best baseball player of all time. Since Mr. Woods problems are a private matter and have nothing to do with cybersecurity, I will not comment any further than to say this ad gave me a chuckle!
Xmas: to Kindle or not to Kindle
Xmas is coming up quick, and people are asking me whether they should get eBook readers as a present, specifically the Kindle.
First of all, if they don't read at least one book a month, then it wouldn't be a good gift. It's like exercise equipment: if you don't already exercise, then getting exercise equipment won't make you exercise. Getting somebody a Kindle won't make them start exercising their brain.
Thursday, November 26, 2009
Xgiving: Fixing the TV
Thanksgiving is not simply a ritual of coming together at grandma’s house for a meal, but of also fixing the grandparents electronic equipment. In the past, it meant fixing the blinking 12:00 time on the VCR, either by setting the time, or more often putting a piece of tape over it.
These days, it’s more complex. If you are like me, when they turn on the TV and start watching a standard definition TV (480i), you get a little annoyed. Why aren’t they watching the same channel in high definition (720p or 1080i)?
The solution to this problem is easy: parental controls. Simply use the parentl control feature to lock your parents out of the standard definition channels, forcing them to watch the same channels in high definition. Just sneak out quietly between the turkey and the pumpkin pie. After dinner, when the family convenes to watch a “Charlie Brown Thanksgiving”, you’ll be able to watch the show in its high def glory.
PS: While fiddling with the TV, you might want to disable South Park too. It’s not age appropriate for anybody over 60.
These days, it’s more complex. If you are like me, when they turn on the TV and start watching a standard definition TV (480i), you get a little annoyed. Why aren’t they watching the same channel in high definition (720p or 1080i)?
The solution to this problem is easy: parental controls. Simply use the parentl control feature to lock your parents out of the standard definition channels, forcing them to watch the same channels in high definition. Just sneak out quietly between the turkey and the pumpkin pie. After dinner, when the family convenes to watch a “Charlie Brown Thanksgiving”, you’ll be able to watch the show in its high def glory.
PS: While fiddling with the TV, you might want to disable South Park too. It’s not age appropriate for anybody over 60.
Tuesday, November 24, 2009
Climategate hack used open proxies
More details are emerging about the "Climategate" hack. It appears that the hacker used an "open proxy" in order to hide the origin of the attack. However, the hacker may have made a mistake, and a review of the logs at RealClimate and ClimateAudit may reveal his/her identity.
Friday, November 20, 2009
Hacker exposes global warming researcher (Climategate)
Hackers broke in and revealed the private e-mails of Phil Jones (NYTimes, BBC ), a famous climatologist. This is going to be one of the most politically relevant hacks of the last few years. When hackers broke into Sarah Palin's e-mails during the presidential campaign, they failed to find any interesting dirt. Phil Jones' e-mails, though, are full of dirt. There's no proof of a "conspiracy" or "cover-up", but a lot of the e-mails look bad for Jones and some of his fellow researchers.
As a cybersecurity expert and a climate skeptic, I thought I'd give some background on what happened.
10 Facebook Don'ts

Facebook is more popular than ever. The site frequently goes through
changes, but how many people use the same schedule of improvements on
their own profile? The new features added to Facebook are opening new
windows for vulnerability. A compromised account is a backdoor to more
serious attacks on email or banking.
Today I will show you 10 things
you should stop doing on Facebook in order to take back your security
and close the open door.
Monday, November 09, 2009
Law & Tech Geek Alert: Future of Software and Technology Patents in Supreme Court's Hands
by Elizabeth Wharton **
The future of thousands of technology patents is playing out in front of the Supreme Court today. At stake are patent protections, possible infringement lawsuits, and millions of dollars of profits to inventors. The Bilski case asks the Supreme Court to determine whether business-methods (those that are more of a mental-process as opposed to those tied to manufacturing or a tangible product) may be patented. Starting with the State Street Bank decision in 1998, the Federal Circuit recognized that software programs that transform data, but do not physically transform an article or create a machine, are patentable. Thousands of patents were issued to technology companies, researchers and innovators based on this decision.
When Bernard Bilski’s and Rand Warsaw’s patent application for a unique set of mathematical formulas to crunch numbers and manage risks associated with weather patterns and utilities was rejected 13 years ago, a landmark patent case was born. The patent office determined that their process dealt with solving a purely mathematical problem and rejected their application. Mr. Bilski and Mr. Warsaw fought for their patent all the way through the court system. In October 2008, the Federal Circuit upheld the patent office decision, reigning in their earlier State Street Bank decision, and determined that an application must meet a machine or transformation test in order to be patentable.
The Federal Circuit's Bilski decision marked a dramatic shift from the past ten plus years and sparked a controversy in the current technology innovation era - not only for software companies but also biomedical and technology companies. Over 67 amicus briefs were filed in connection with the Bilski case. Among those filing briefs in support of one side or the other in Bilski are the likes of computer and technology giants IBM, Novartis, Microsoft, Google, Symantec Corp., and others such as Bank of America and clothier L.L. Bean. At risk are software, technology, and biomedical patents held by such companies as IBM, Nortel, Medtronics, and many others. As pointed out by Judge Newman in her dissent, many technology innovations and inventions today are novel ways to approach data and information.
Narrowing technology patents to exclude processes that produce a “useful, concrete, and tangible result”, per the State Street Bank decision, will stifle technology innovation and product development. More and more users will listen to a presentation, take out the original and unique content, and ultimately circumvent the inventor. The inventor of this content will not have the patent protections for their unique solutions and ideas. Part of the inventor’s incentive in working to develop the solution has been stripped away.
The amicus briefs and legal arguments today are just the start of the Supreme Court’s review of the case. Legal geeks and technology geeks, along with thousands of patent holders, will be anxiously watching and waiting for the Supreme Court’s final decision in the months to come.
(For more in-depth discussions about this case and intellectual property law, I recommend the following websites - Law.com and IPwatchdog.com.)
** Reminder, these are just my thoughts and are not intended to provide advice, legal or otherwise. While I am a lawyer, I am not your lawyer.
The future of thousands of technology patents is playing out in front of the Supreme Court today. At stake are patent protections, possible infringement lawsuits, and millions of dollars of profits to inventors. The Bilski case asks the Supreme Court to determine whether business-methods (those that are more of a mental-process as opposed to those tied to manufacturing or a tangible product) may be patented. Starting with the State Street Bank decision in 1998, the Federal Circuit recognized that software programs that transform data, but do not physically transform an article or create a machine, are patentable. Thousands of patents were issued to technology companies, researchers and innovators based on this decision.
When Bernard Bilski’s and Rand Warsaw’s patent application for a unique set of mathematical formulas to crunch numbers and manage risks associated with weather patterns and utilities was rejected 13 years ago, a landmark patent case was born. The patent office determined that their process dealt with solving a purely mathematical problem and rejected their application. Mr. Bilski and Mr. Warsaw fought for their patent all the way through the court system. In October 2008, the Federal Circuit upheld the patent office decision, reigning in their earlier State Street Bank decision, and determined that an application must meet a machine or transformation test in order to be patentable.
The Federal Circuit's Bilski decision marked a dramatic shift from the past ten plus years and sparked a controversy in the current technology innovation era - not only for software companies but also biomedical and technology companies. Over 67 amicus briefs were filed in connection with the Bilski case. Among those filing briefs in support of one side or the other in Bilski are the likes of computer and technology giants IBM, Novartis, Microsoft, Google, Symantec Corp., and others such as Bank of America and clothier L.L. Bean. At risk are software, technology, and biomedical patents held by such companies as IBM, Nortel, Medtronics, and many others. As pointed out by Judge Newman in her dissent, many technology innovations and inventions today are novel ways to approach data and information.
Narrowing technology patents to exclude processes that produce a “useful, concrete, and tangible result”, per the State Street Bank decision, will stifle technology innovation and product development. More and more users will listen to a presentation, take out the original and unique content, and ultimately circumvent the inventor. The inventor of this content will not have the patent protections for their unique solutions and ideas. Part of the inventor’s incentive in working to develop the solution has been stripped away.
The amicus briefs and legal arguments today are just the start of the Supreme Court’s review of the case. Legal geeks and technology geeks, along with thousands of patent holders, will be anxiously watching and waiting for the Supreme Court’s final decision in the months to come.
(For more in-depth discussions about this case and intellectual property law, I recommend the following websites - Law.com and IPwatchdog.com.)
** Reminder, these are just my thoughts and are not intended to provide advice, legal or otherwise. While I am a lawyer, I am not your lawyer.
How to change iPhone passwd
Jailbreaking an iPhone installs SSH with a default password of "alpine". Most people don't change the password. Thus, some hacker has written a worm (called "Ikee") that travels via SSH from iPhone to iPhone using that password.
This happens because your iPhone will try to reconnect to WiFi in the background. The scenario is that you get on an airplane to go somewhere. While on the airplane, your phone STILL IN YOUR LUGGAGE tries to connect to "gogoinflight" airplane WiFi service. Some other phone, also in its owner's luggage, likewise connects to the hotspot. That phone is infected with the worm. The worm will search out all iPhones, finds yours, connects using the password "alpine", and infects your phone. When you land and look at your phone, it has a background picture of Rich Astley.
Preventing infection is easy. The way I did it was to use the SSH client "Putty" on my Windows machine. I connected to the iPhone, and used the 'passwd' command-line program to change the default. You have to change the password for two accounts: "root" and "mobile".
Below is a screenshot of me changing the password. The screen doesn't show the passwords, but I've typed in "alpine" for the initial logon, and then when it asked me to choose a new password, I typed "letmein".**

** Of course that's not my password, but I'm not going to tell everyone my real password, am I?
** The new worm changes the password to "ohshit".
Sunday, November 08, 2009
Brazil outage NOT caused by hackers
Wednesday, November 04, 2009
Windows 7 includes soft-ap
Follow @ErrataRob
All Windows 7 machines can become a wifi access-point, routing the connections over Ethernet or even over a client station connection on the same wifi adapter. This Slashdot article mentions this, but gets the facts slightly wrong (claiming that it's incomplete and that you need extra software). Instructions for doing this are below.
This is going to be bad, causing rogue access-points to proliferate in companies.
CONTEXT
Technically, this isn't really new. You could always setup ad-hoc wifi and connection-sharing, which is almost he same thing. Also, it's already possible on Mac OS X, Linux, Windows Mobile, and iPhones.
Yet, a full "access-point" sucks less than "ad-hoc" networking. Also, it can work over the same WiFi adapter. Thus, while you are connected to "gogoinflight" on the airplane, your friend can log onto your "buddy" access-point on your computer and share your connection.
And there is increasing reason to do this. On my last flight, I wanted to sync both my iPhone and use my notebook. I only had to pay "gogoinflight" once, but I had to keep logging in again each time I switched from one device to the other. I totally would've just enabled this feature on my notebook and synced my iPhone through a virtual access-point instead.
Note: It only supports WPA, therefore you can't make "evil twin" access-points out of this (although I bet there is a way to hack it to turn WPA off).
HOW IT WORKS
Windows 7 can create "virtual" wifi adapters based on the real adapters, with a unique MAC address and everything. This is similar to VAPs on Linux, which allows you to create one virtual adapter for logging onto an access-point, and another for running a soft-ap. The difference with Windows 7 is that it creates only a single virtual adapter for "hosted" mode -- no matter how many actual adapters you have in the system. It's called "Microsoft Virtual WiFi Miniport Adapter", with the same MAC address decremented by one.
Making it work is simply a matter of (1) configuring the SSID and WPA password, (2) configuring Internet Connection Sharing to bridge it with the network, and (3) turning it on.
WHY IT WORKS
Zune, and stuff like it.
Microsoft wants you to be able to transfer music/video from your computer to your Zune easily. This makes it easier.
It's not just soft-ap. Windows 7 allows a lot of other low-level functionality. For example, you can write applications that add custom "information elements" to the beacon and association packets sent when new wifi connection is setup. Thus, your desktop becomes not simply an "access-point", but a "media access-point".
Finally, by mandating this low-level functionality in wifi hardware drivers now, it means Windows 7 should seamlessly work with "Wi-Fi Direct" bluetooth-like functionality whenever that standard becomes solidified.
INSTRUCTIONS
STEP 0: Open a command-prompt with administrator privileges.
Click on Start menu, All Programs, Accessories, right-click on Command Prompt, select "Run as administrator"). Type in:
STEP 1: Configure the "hosted" interface:
netsh wlan set hostednetwork mode=allow ssid=Test key=letmein9
This example creates an access-point with an SSID of "Test", with a WPA password of "letmein9".
STEP 2: Configure Internet Connection Sharing (ICS)
Open up the networking control panel. Select the interface that currently has Internet connection (like your Ethernet or normal wifi), enable "Sharing", and then select the special "hosted" interface.
STEP 3: Start it
netsh wlan start hostednetwork
STEP 4: Enjoy
On your other devices (say, iPhone), connect to "Test" and give the WPA password of "letmein9".



Links:
All Windows 7 machines can become a wifi access-point, routing the connections over Ethernet or even over a client station connection on the same wifi adapter. This Slashdot article mentions this, but gets the facts slightly wrong (claiming that it's incomplete and that you need extra software). Instructions for doing this are below.
This is going to be bad, causing rogue access-points to proliferate in companies.
CONTEXT
Technically, this isn't really new. You could always setup ad-hoc wifi and connection-sharing, which is almost he same thing. Also, it's already possible on Mac OS X, Linux, Windows Mobile, and iPhones.
Yet, a full "access-point" sucks less than "ad-hoc" networking. Also, it can work over the same WiFi adapter. Thus, while you are connected to "gogoinflight" on the airplane, your friend can log onto your "buddy" access-point on your computer and share your connection.
And there is increasing reason to do this. On my last flight, I wanted to sync both my iPhone and use my notebook. I only had to pay "gogoinflight" once, but I had to keep logging in again each time I switched from one device to the other. I totally would've just enabled this feature on my notebook and synced my iPhone through a virtual access-point instead.
Note: It only supports WPA, therefore you can't make "evil twin" access-points out of this (although I bet there is a way to hack it to turn WPA off).
HOW IT WORKS
Windows 7 can create "virtual" wifi adapters based on the real adapters, with a unique MAC address and everything. This is similar to VAPs on Linux, which allows you to create one virtual adapter for logging onto an access-point, and another for running a soft-ap. The difference with Windows 7 is that it creates only a single virtual adapter for "hosted" mode -- no matter how many actual adapters you have in the system. It's called "Microsoft Virtual WiFi Miniport Adapter", with the same MAC address decremented by one.Making it work is simply a matter of (1) configuring the SSID and WPA password, (2) configuring Internet Connection Sharing to bridge it with the network, and (3) turning it on.
WHY IT WORKS
Zune, and stuff like it.
Microsoft wants you to be able to transfer music/video from your computer to your Zune easily. This makes it easier.
It's not just soft-ap. Windows 7 allows a lot of other low-level functionality. For example, you can write applications that add custom "information elements" to the beacon and association packets sent when new wifi connection is setup. Thus, your desktop becomes not simply an "access-point", but a "media access-point".
Finally, by mandating this low-level functionality in wifi hardware drivers now, it means Windows 7 should seamlessly work with "Wi-Fi Direct" bluetooth-like functionality whenever that standard becomes solidified.
INSTRUCTIONS
STEP 0: Open a command-prompt with administrator privileges.
Click on Start menu, All Programs, Accessories, right-click on Command Prompt, select "Run as administrator"). Type in:
STEP 1: Configure the "hosted" interface:
netsh wlan set hostednetwork mode=allow ssid=Test key=letmein9
This example creates an access-point with an SSID of "Test", with a WPA password of "letmein9".
STEP 2: Configure Internet Connection Sharing (ICS)
Open up the networking control panel. Select the interface that currently has Internet connection (like your Ethernet or normal wifi), enable "Sharing", and then select the special "hosted" interface.
STEP 3: Start it
netsh wlan start hostednetwork
STEP 4: Enjoy
On your other devices (say, iPhone), connect to "Test" and give the WPA password of "letmein9".



Links:
Monday, October 26, 2009
Call Spoofing: So easy, even famous people do it!
A simple but effective call spoofing technique has hit the main stream. Former high profile Dolce & Gabbana publicist Ali Wise used a phone call spoofing service called SpoofCard to listen to her ex-boyfriend's voicemails. The service hides the phone number you're calling from, routes the call through their server, and spoofs the caller ID with any 10-digit number. Several years ago, Paris Hilton was also in the news for allegedly using SpoofCard to listen her friends' voicemails. Voicemail users that do not have a passcode prompt even for calling from their own number are vulnerable to this technique.
I tested the SpoofCard iPhone app, and using only the 'first 5 minutes free' I was able to prove that it does everything it claims. I called myself, spoofing the number with another 10-digit number, and disguised my voice using the built-in voice modifier. The choice of "man" or "woman" isn't good. I would know it wasn't a real voice... Unless I was expecting a call from the DaVinci Virus in Hackers. (But phishing scams are prime for automated messages) The call recording feature works perfectly and portably. With very little effort I had voicemail access without password prompting. The only part that didn't work as expected was routing the call through Google Voice. It came up "Unknown."
Besides listening to voicemails, there are reasons to be concerned. Two weeks ago, Elizabeth Wharton and I led a discussion at the Atlanta chapter meeting of NAISG about Identity Theft using Social Networks. One case in point I experienced personally. The attacker had already obtained the login credentials of a Facebook user in my friends list. They approached me via chat under my friend's name. They claimed that they had been mugged while on a trip to London and wanted to borrow $400 to pay the hotel bill. Since I knew the whereabouts of my friend, the attack ended there. But what if I wasn't so sure? Would a call from my friend's phone convince me? Since many Facebook users keep their phone numbers in their profile, this opens huge door for phishing attackers. Remember that Identity Theft is not attributed to one large vulnerability but rather to dozens of innocuous details displayed freely around the Internet. Being able to appear officially like they're calling from any other number may be the last piece the attacker needs to convince you to give up crucial information.
So should SpoofCard be able to continue this service? Their record shows that they've been keeping their nose clean for years, and even won the lawsuit against 123spoof.com for using "spoof" in their business name. Their website claims the most appropriate use for this tool is in places like doctors offices that want to have multiple numbers but don't want to appear confusing to the customers. While this sounds perfectly reasonable, I question whether this service is the optimal way to do that. They do not support misuse of the product, and "if there is illegal activity and we are served with a subpoena, we will cooperate with the court or law enforcement agency." It looks like for now the responsibility is still in our hands to be smart and protect ourselves with instinct and good judgment. (And take your phone number off the Internet!)
Wednesday, October 07, 2009
Peter Principle
The Peter Principle is the principle that "In a Hierarchy Every Employee Tends to Rise to His Level of Incompetence." It was formulated by Dr. Laurence J. Peter and Raymond Hull in their 1969 book The Peter Principle. Whether intentionally or inevitably, every person who is doing a great job will be promoted until they no longer have that job. The promotion is not necessarily to a more difficult job, but it is not the job the person was trained to do. For example, a management position is a different skill set than how a programmer has proven themselves.
When we apply this principle to cybersecurity, it is referred to as "The Generalized Peter Principle." It was observed by Dr. William R. Corcoran while testing hardware in a nuclear plant. He observed the tendency to continue to use what was familiar even to the point of not being useful. People want to use old devices for new problems. Take anti-virus software for example. I was recently asked "Why, if I run A/V, do I keep getting pop-up ads on my computer?" We rely on the software to "quarantine" viruses, and it does it so well that we want Adware Blocking as well. And as long as we don't have ads, we want to block Spyware. And really we want to be notified every time there's a new call to the internet. Meanwhile, the only thing it ever did very well was scan email attachments.
In the workplace, the solution is to forgo promotions in favor of pay increases, or to offer training for the new position. In software, the solution is to recognize what problems the program is actually solving, and find separate, new solutions for new problems. Avoid product creep by building a custom arrangement instead of the all-in-one quick fix.
Monday, October 05, 2009
Hack
In 2002, there was a television show released by CBS called Hack. I had never heard of it before, and when I saw on the guide that a show dramatizing hacking was playing, I got excited. Unfortunately, the show has nothing to do with infosec. After watching it for a while, waiting patiently to see some media portrayed hacking, I couldn't figure out what it was about at all. Wikipedia finally clued me in. The show is about a hack, meaning a taxi driver.
I had never heard anyone call a taxi driver a "hack." It turns out that "hack" or "hacking" has quite a few different meanings. In dictionary.com the definition I was hoping to see, "To alter a computer program," was indeed there, but it seems to be missing something. It also means "To mutilate," "To train a falcon," and "To rent a horse by the hour." And surely we hope that the word doesn't just mean "an artist who exploits his or her talents to produce mediocre work for money."
If hacking is the cornerstone of our industry, shouldn't there be a better word for it? Or maybe just better tv shows.
Friday, October 02, 2009
Hon Hai = Foxconn
In wireless scanning, you often see "Hon Hair Precision Industry Co., Ltd." show up as the name for the manufacturer of the wireless devices. I've always wondered who the heck they were. I finally got around to Googling the company name and found the easy answer: Foxconn.
All WiFi (and Ethernet) adapters contain a 24-bit manufacturer ID. These are registered with the IEEE. You can look up any ID to find out the manufacturer at the site http://standards.ieee.org/regauth/oui/.
Most of the names are obvious, such as Apple or IBM. However, some are more obscure, such as Hon Hai Precision. While Hon Hai seems to be a popular manufacturer of WiFi equipped computers, I have never heard of them.
As this Wikipedia article explains, Hon Hai is the company better known as "Foxconn", which by a recent estimate is the #132 largest company in the world. It is big contract manufacturer of computer equipment. Some is sold under their own names, such as Foxconn motherboards or Leadtek graphics cards, but they mostly manufacture stuff for other companies. Currently, they build the MacBook, iPhone, Palm Pre, and the Amazon Kindle. They make the PlayStation 3, Wii, and XBox 360. They are one of the largest notebook manufacturers that are sold under brand names of other companies like HP. (This blog post was written on a MacBook Air, made by Foxconn, and posted while tethered through an iPhone, made by Foxconn).
Many of the notebooks made by Foxconn will contain the "Hon Hai" manufacturer ID. However, a company such as Apple has tighter control over it's branding: all the MacBooks and iPods Foxconn makes contain the Apple manufacturer ID.
So, in summary, when you see in your wireless scanner "Hon Hai Precision", think "Foxconn", or more specifically "a Windows notebook manufactured by Foxconn for a different brand company like HP".
All WiFi (and Ethernet) adapters contain a 24-bit manufacturer ID. These are registered with the IEEE. You can look up any ID to find out the manufacturer at the site http://standards.ieee.org/regauth/oui/.
Most of the names are obvious, such as Apple or IBM. However, some are more obscure, such as Hon Hai Precision. While Hon Hai seems to be a popular manufacturer of WiFi equipped computers, I have never heard of them.
As this Wikipedia article explains, Hon Hai is the company better known as "Foxconn", which by a recent estimate is the #132 largest company in the world. It is big contract manufacturer of computer equipment. Some is sold under their own names, such as Foxconn motherboards or Leadtek graphics cards, but they mostly manufacture stuff for other companies. Currently, they build the MacBook, iPhone, Palm Pre, and the Amazon Kindle. They make the PlayStation 3, Wii, and XBox 360. They are one of the largest notebook manufacturers that are sold under brand names of other companies like HP. (This blog post was written on a MacBook Air, made by Foxconn, and posted while tethered through an iPhone, made by Foxconn).
Many of the notebooks made by Foxconn will contain the "Hon Hai" manufacturer ID. However, a company such as Apple has tighter control over it's branding: all the MacBooks and iPods Foxconn makes contain the Apple manufacturer ID.
So, in summary, when you see in your wireless scanner "Hon Hai Precision", think "Foxconn", or more specifically "a Windows notebook manufactured by Foxconn for a different brand company like HP".
Thursday, September 24, 2009
No Downloads Barred: Net Neutrality Fight Steps Into the Ring (Again), FCC Proposals Facing a First Amendment TKO
While I am the first one to complain when a particular download is slow, a call is dropped, or an application is not available for a particular device, I don’t think to run to the government to step in and “fix it.” I run to the source, my service provider and curse at their customer service representative. If the Federal Communications Commission (“FCC”) has its way, they will be able to not only intervene, they will force service providers to give each customer or data the same treatment. Tossing aside policy, technology and other concerns, the FCC proposals strike out based on free speech principals guaranteed by the First Amendment of the U.S. Constitution.
On Monday, Julius Genachowski, head of the FCC, proposed broad new net neutrality regulations formally entering the FCC into the fight - determining which punches, blows and kicks are required to flow over internet service providers (“ISPs”). A copy of his speech can be found here. In his speech, Genachowski broadened the four FCC net neutrality pillars of network openness originally proposed in 2005 to include two additional ones - expanding the regulations to include mobile broadband providers. In the name of providing full internet access to all, the FCC will force ISPs to provide all content and services - aka, speech - equally over their networks. The FCC proposals are still in the discussion phase, but Genachowski’s outlined plan places net neutrality in direct conflict with the First Amendment to the U.S. Constitution.
On the surface “Net Neutrality” sounds good, right? The name just rolls off the tongue - who could possibly object to free and unhampered internet access for all. Problem is, the term has been tossed around for so long that the politicians, advocates and opponents have morphed it into whatever fits their argument of the day. The current general concept of network neutrality between applications, data, and traffic was first popularized in 2003 by Tim Wu, a professor at Columbia Law School. In 2005, the FCC issued its internet policy statement outlining their four basic pillars regarding broadband network neutrality. Since then, Congress has introduced numerous pieces of legislation aimed at these issues but to no avail. Each piece of legislation has died either on the floor of the respective chamber or in committee. A comparison of various proposed bills, public speeches, and even blog articles on this subject show too many “definitions” of “Net Neutrality” to keep up. To loosely quote Inigo Montoya from the Princess Bride, I do not think that word means what you think it means. As the technology of the internet has evolved, old predictions of no “bottlenecks” for the information superhighway have been proven wrong. Cheaper and never before imagined means of internet access have cropped up since the initial 2003 net neutrality debates. Who would have thought that we would stream movies and live television over our mobile phones (using the providers networks for such access).
While the exact nature of net neutrality might be hard to pin down, the language in the First Amendment is plain, the government shall not make any law abridging freedom of speech. No footnote, asterisk, or caveats. ISPs provide “speech” and thus have First Amendment rights. Granted, the speech of an ISP is different than that of an individual, but courts have determined that these rights do exist. Just as the government cannot pass a law preventing speech, compelling speech is also prohibited. A newspaper cannot be forced to carry editorials that contain objectionable content. The Supreme Court has only waded into internet/free speech issues on a few limited cases, never establishing a clear standard for First Amendment review (for detailed discussions - see Moran Yemini’s law review article on Network Neutrality as well as Randolph J. May’s 2007 journal article “Net Neutrality Mandates: Neutering the First Amendment in the Digital Age”). The Court has generally differentiated First Amendment free speech rights between a telecommunications service (think of telephone company monopolies that do not exercise editorial or other control over the content crossing their telephone lines) and an information service provider. In Brand X Internet Services v. FCC, 345 F.3d 1120, a cable modem provider was considered an information service provider. Information service providers do not have to allow their competitors to offer services over their lines. Similarly, DSL providers are considered information service providers and not telecommunication service providers.Should this standard be applied to ISPs, then the FCC proposal is in conflict with prior case law. Granted, cable modem providers have traveled a long way to get to the services offered via ISPs of today and the courts have yet to catch up.
Bandwidth is not unlimited, period. An ISP provider should not be compelled to provide content under pre-determined government requirements if providing that content causes harm to their overall systems. Shining example: AT&T 3G network popularity. Requiring (aka “compelling”) AT&T to offer all applications over their 3G network will cause the network to crash - think of trying to make a call via AT&T 3G networks while at Caesar’s casino during the BlackHat conference in Las Vegas, NV this past August. The 3G network system could not handle the call and data volume during BlackHat with constant dropped calls or other connectivity issues....and that is before the system is required to handle larger applications. Under Genachowski’s general proposals, AT&T would have to offer all applications, sacrificing service to all for the sake of a few. If AT&T determined additional 3G traffic was not in their customers best interest, then the First Amendment bars the FCC from compelling AT&T to carry these iPhone applications. AT&T is not the only mobile carrier, customers have the option to choose another carrier or a different type of mobile phone. The customer’s ultimate access to the internet (or in this case, an application) has not been barred, the customer just has to make a choice of which mobile carrier or ISP to use based on their needs.
As the debate begins on the new regulations and related proposals, the question remains: will the FCC be knocked down by the First Amendment? Until the final FCC policy takes shape, placing exact odds on the fight are premature. Legal geeks will be looking to the First Amendment as a potential knockout blow for the latest FCC proposed net neutrality regulations. Given prior case law, the First Amendment protections have the home court advantage and should beat their FCC net neutrality crosstown rivals.
Legal-E: My Views From the Bar
I am a lawyer, just not yours - My posts are intended to present issues from my point of view and are not intended to be advice, legal or otherwise.
On Monday, Julius Genachowski, head of the FCC, proposed broad new net neutrality regulations formally entering the FCC into the fight - determining which punches, blows and kicks are required to flow over internet service providers (“ISPs”). A copy of his speech can be found here. In his speech, Genachowski broadened the four FCC net neutrality pillars of network openness originally proposed in 2005 to include two additional ones - expanding the regulations to include mobile broadband providers. In the name of providing full internet access to all, the FCC will force ISPs to provide all content and services - aka, speech - equally over their networks. The FCC proposals are still in the discussion phase, but Genachowski’s outlined plan places net neutrality in direct conflict with the First Amendment to the U.S. Constitution.
On the surface “Net Neutrality” sounds good, right? The name just rolls off the tongue - who could possibly object to free and unhampered internet access for all. Problem is, the term has been tossed around for so long that the politicians, advocates and opponents have morphed it into whatever fits their argument of the day. The current general concept of network neutrality between applications, data, and traffic was first popularized in 2003 by Tim Wu, a professor at Columbia Law School. In 2005, the FCC issued its internet policy statement outlining their four basic pillars regarding broadband network neutrality. Since then, Congress has introduced numerous pieces of legislation aimed at these issues but to no avail. Each piece of legislation has died either on the floor of the respective chamber or in committee. A comparison of various proposed bills, public speeches, and even blog articles on this subject show too many “definitions” of “Net Neutrality” to keep up. To loosely quote Inigo Montoya from the Princess Bride, I do not think that word means what you think it means. As the technology of the internet has evolved, old predictions of no “bottlenecks” for the information superhighway have been proven wrong. Cheaper and never before imagined means of internet access have cropped up since the initial 2003 net neutrality debates. Who would have thought that we would stream movies and live television over our mobile phones (using the providers networks for such access).
While the exact nature of net neutrality might be hard to pin down, the language in the First Amendment is plain, the government shall not make any law abridging freedom of speech. No footnote, asterisk, or caveats. ISPs provide “speech” and thus have First Amendment rights. Granted, the speech of an ISP is different than that of an individual, but courts have determined that these rights do exist. Just as the government cannot pass a law preventing speech, compelling speech is also prohibited. A newspaper cannot be forced to carry editorials that contain objectionable content. The Supreme Court has only waded into internet/free speech issues on a few limited cases, never establishing a clear standard for First Amendment review (for detailed discussions - see Moran Yemini’s law review article on Network Neutrality as well as Randolph J. May’s 2007 journal article “Net Neutrality Mandates: Neutering the First Amendment in the Digital Age”). The Court has generally differentiated First Amendment free speech rights between a telecommunications service (think of telephone company monopolies that do not exercise editorial or other control over the content crossing their telephone lines) and an information service provider. In Brand X Internet Services v. FCC, 345 F.3d 1120, a cable modem provider was considered an information service provider. Information service providers do not have to allow their competitors to offer services over their lines. Similarly, DSL providers are considered information service providers and not telecommunication service providers.Should this standard be applied to ISPs, then the FCC proposal is in conflict with prior case law. Granted, cable modem providers have traveled a long way to get to the services offered via ISPs of today and the courts have yet to catch up.
Bandwidth is not unlimited, period. An ISP provider should not be compelled to provide content under pre-determined government requirements if providing that content causes harm to their overall systems. Shining example: AT&T 3G network popularity. Requiring (aka “compelling”) AT&T to offer all applications over their 3G network will cause the network to crash - think of trying to make a call via AT&T 3G networks while at Caesar’s casino during the BlackHat conference in Las Vegas, NV this past August. The 3G network system could not handle the call and data volume during BlackHat with constant dropped calls or other connectivity issues....and that is before the system is required to handle larger applications. Under Genachowski’s general proposals, AT&T would have to offer all applications, sacrificing service to all for the sake of a few. If AT&T determined additional 3G traffic was not in their customers best interest, then the First Amendment bars the FCC from compelling AT&T to carry these iPhone applications. AT&T is not the only mobile carrier, customers have the option to choose another carrier or a different type of mobile phone. The customer’s ultimate access to the internet (or in this case, an application) has not been barred, the customer just has to make a choice of which mobile carrier or ISP to use based on their needs.
As the debate begins on the new regulations and related proposals, the question remains: will the FCC be knocked down by the First Amendment? Until the final FCC policy takes shape, placing exact odds on the fight are premature. Legal geeks will be looking to the First Amendment as a potential knockout blow for the latest FCC proposed net neutrality regulations. Given prior case law, the First Amendment protections have the home court advantage and should beat their FCC net neutrality crosstown rivals.
Legal-E: My Views From the Bar
I am a lawyer, just not yours - My posts are intended to present issues from my point of view and are not intended to be advice, legal or otherwise.
Monday, September 21, 2009
Red flags at the doctor's office
It seems that the rampant, misguided identity theft prevention efforts have finally reached the doctor's office. I recently went in to the doctor I've seen a dozen times and was surprised to hear they now required my driver's license to verify my identity. After disillusioning myself that they would know who I was after all this time, I surrendered my license and watched them scan it. The receptionist apologized and said she didn't really know why they were doing this now. She guessed it was probably "a HIPAA thing."
Since this sounded like a total guess, I looked into it. Sure enough, it's not. The FTC has passed down the Red Flags Rule mandating several requirements health care organizations must now do to "fight identity theft." The basic gist is the office must verify the patient is the same person that is on file. While scanning the driver's license is NOT specifically required, it is a common way many offices are interpreting the requirements.
So if it's not explicitly required, can you opt out of this protection? Reports are mixed, and it isn't simple. Security expert Jennifer Jabbusch tweeted her experiences recently and finally convinced the office that she would not agree to a scan of her license on file. Other people have reported doctors refusing them services. Sherri Davidoff wrote a great post at http://philosecurity.org exploring the problems this mandate will give to people that don't drive, the elderly, and children.
So why is the FTC so misguided? A chat with my doctor about their security strategy tells me everything. They are using out of the box Vista anti-virus and no wireless network. It was a short conversation. Can we expect more from private health care offices? What security measures would be sufficient to protect the drivers license images? It is apparent that the FTC has pushed more responsibility on the private practice than they are willing or able to be responsible for. Instead they have sweetened the pot by creating a very attractive target of driver's license info tied to medical info. By storing this information, they may prevent some identity theft in the office, but they are actually encouraging identity theft in other places.
Friday, September 11, 2009
TwiGUARD tracked the HowToHack incident
I have updated the TwiGUARD analysts log with a followup on the HowToHack incident. You can find it here.
We cover the accounts that were spreading the malware links, how long the incidnet went on for, the number of possible tweets, and some information about the malware. Check it out!
We cover the accounts that were spreading the malware links, how long the incidnet went on for, the number of possible tweets, and some information about the malware. Check it out!
Tuesday, September 08, 2009
Tweet Theft Spam
I’ve been playing around with tracking spam and malware on Twitter, a project we call TwiGUARD, and have been learning new things.
Last night I was testing my TwiGUARD analysis tool and it marked a user as spam, but when I manually checked the profile, it looked legitimate. The user had some timely quotes and seemed to be a real person. Sure, it’s a real person who likes to retweet offers for free money, but who am I to judge?
Then a lightbulb went off in my head. I copied the non-spam looking posts into the Twitter search engine and found a young lady in Iowa had tweeted the exact quote an hour before. The spambot had simply stolen her tweet and copied it in order to appear as a legitimate person.
I found many other spambots who did the same thing. They simply track the top 10 “Tending Topics”, find people who replied to those topics, then steal other tweets those people have made.
Anyway, I feel like a parent who has been surpassed by his kid. I was fooled by the spambot, but my tool wasn’t.
Below are two screen shots of tweet theft I found while writing this post. It comes from parsing "#wheniwaslittle I", which is current the #1 “trending topic”. The first screen shot is the spammer (You can tell by the pleas to watch her dirty videos) followed up by a screen shot of the lass who made the original comment.

This is the spam!

This is the orginal comment.
Last night I was testing my TwiGUARD analysis tool and it marked a user as spam, but when I manually checked the profile, it looked legitimate. The user had some timely quotes and seemed to be a real person. Sure, it’s a real person who likes to retweet offers for free money, but who am I to judge?
Then a lightbulb went off in my head. I copied the non-spam looking posts into the Twitter search engine and found a young lady in Iowa had tweeted the exact quote an hour before. The spambot had simply stolen her tweet and copied it in order to appear as a legitimate person.
I found many other spambots who did the same thing. They simply track the top 10 “Tending Topics”, find people who replied to those topics, then steal other tweets those people have made.
Anyway, I feel like a parent who has been surpassed by his kid. I was fooled by the spambot, but my tool wasn’t.
Below are two screen shots of tweet theft I found while writing this post. It comes from parsing "#wheniwaslittle I", which is current the #1 “trending topic”. The first screen shot is the spammer (You can tell by the pleas to watch her dirty videos) followed up by a screen shot of the lass who made the original comment.

This is the spam!

This is the orginal comment.
Subscribe to:
Posts (Atom)

