A big security news event last night and today is that the Twitter.com Web site was hacked and content on the site replaced. TechCrunch reported it and it has been picked up globally. But - was the Twitter.com website really hacked? We now know it was not so. There are four ways that users typing in Twitter.com would have seen the Iranian Cyber Army page. more
As founder and CTO of Ellacoya Networks, a pioneer in Deep Packet Inspection (DPI), and now having spent the last year at Arbor Networks, a pioneer in network-based security, I have witnessed first hand the evolution of DPI. It has evolved from a niche traffic management technology to an integrated service delivery platform. Once relegated to the dark corners of the central office, DPI has become the network element that enables subscriber opt-in for new services, transparency of traffic usage and quotas, fairness during peak busy hours and protection from denial of service attacks, all the while protecting and maintaining the privacy of broadband users. Yet, DPI still gets a bad rap... more
There has been quite a bit of talk lately about the best way to secure a domain, mainly centered in two camps: using Secure Socket Layer (SSL), or using DNS Security Extensions (DNSSEC). The answer is quite simple -- you should use both. The reason for this is that they solve different problems, using different methods, and operate over different data. more
An article based on the most recent study for the European Commission on the Policy Implications of Convergence in the Field of Naming, Numbering and Addressing written by Joe McNamee and Tiina Satuli of Political Intelligence.
"With relation to the Internet and also IP addresses, the "scarcity" is more complicated: there are not only intellectual property issues with regards to domain names, but there is also an issue of managing the integrity of the system. For any naming or numbering system to work, it is essential that the names and addresses used cannot be confused with any other -- in other words, no one system can have two end-points with the same fully qualified number or name..." more
Today the FCC announced the winners of the 700 MHz auction -- and you can see from pp. 62-63 of this document that Verizon won Block C. (Block C was set up in two nationwide paired blocks of 11 MHz each, which were auctioned off in very large geographic areas -- 12 licenses, each covering a "Regional Economic Area Grouping". Verizon won seven of the twelve licenses, covering all of the US except Alaska, Puerto Rico, American Samoa, Guam, and the Northern Mariana Islands.) Why does this matter? more
Despite a recent Ninth Circuit decision denying immunity to malware detection software for targeting competitor's software, court holds that Section 230 protected Malwarebytes from liability for designating software driver program as potentially unwanted program. Plaintiff provided software that works in real-time in the background of the operating system to optimize processing and locate and install missing and outdated software drivers. more
E-commerce has revolutionized how businesses sell to consumers -- including those involved in illicit activities, such as websites peddling illegal narcotics, pirated movies and music, or counterfeit handbags. For example, 96 percent of Internet pharmacies do not comply with U.S. laws, and as they ship pills tainted with paint thinner, arsenic, and rat poison, they put the health and safety of consumers at risk. Why don't law enforcement officials do more to combat this problem? Partly because of the difficulty of identifying who is actually operating the illegal pharmacies. It is time to fix this, while allowing anonymity for those who deserve it. more
These cute rodents are the number one culprit for animal damage to aerial fiber. To a lesser degree, fiber owners report similar damage by rats and mice. Squirrels mainly chew on cables as a way to sharpen their teeth. Squirrel teeth grow up to 8 inches per year and if squirrels aren't wearing their teeth down from their diet, they look for other things to chew. more
Has your organization recently received an email claiming to be from NABP's Internet Drug Outlet Identification Program (IDOI)? If so, it is possible that someone is trying to trick you. The NABP IDOI team's email account has recently been illegally "spoofed" by unaffiliated persons or organizations. Email spoofing involves the forgery of an email header so that the email appears to have originated from someone other than the actual source. more
If you have been following the debate over Internet governance over the past few years, you know that while ICANN supporters (U.S., Canadian, Australian governments; business lobby) and critics (developing world and occasionally Europe) argue over the optimal approach, particularly with respect to government involvement in the domain name system, the reality has been that possession is all. ...The alternate root has always lurked in the background as a possibility that would force everyone to rethink their positions since it would enable a single country (or group of countries) to effectively pack up their bags and start a new game. ...It is with that background in mind that people need to think about a press release issued yesterday in China announcing a revamping of its Internet domain name system. Starting tomorrow, China's Ministry of Information Industry plans to begin offering four country-code domains. more
After some years of accelerating IPv6 deployment, we are now into a period of slower growth and it's not clear where we are heading. It is therefore interesting to try to predict the future of IPv6 over the coming years. At Ericsson Research, we have been working on this topic since 2013, but just recently created a forecast model that seems to be quite accurate. However, it gives a disappointing message of a very low final level of IPv6 deployment at less than 30%! more
Today, the ITU launched a new survey asking member states, ccTLDs and other ITU member organizations to provide answers to a specialized questionnaire asking for their experiences on the use of IDNs. The ITU states that it is reaching out to ccTLDs to "collect information and experiences on Internationalized Domain Names under ccTLD (country code Top Level Domain) around the globe." One of the goals of this survey is to collate information on the "needs and practices" of each ccTLD that is surveyed -- so as to compile a report from the ITU that speaks to the implementation of IDNs around the world... more
The Sponsored TLD .CAT got the green light to move ahead from ICANN this week, another of the sTLD proposals in the second round of submissions to gain momentum toward being added to the root. When I shared the news today with folks, the most common response was a tongue in cheek response, 'Where is .DOG?'. ...Still, comedy aside, this is not a TLD for animal species, but rather for a language. more
It is now clear that by sending its letter of August 12 blocking approval of the .XXX domain, the US Government has done more to undermine ICANN's status as a non-governmental, multi-stakeholder policy body than any of its Internet governance "enemies" in the ITU, China, Brazil, or Iran. And despite all the calls for a government role that would ensure "rule of law" and "accountability" of ICANN, the interventions of governments are making this aspect of Internet governance more arbitrary and less accountable. more
In 2001, I published an article on "virtual crime." It analyzed the extent to which we needed to create a new vocabulary -- and a new law -- of "cybercrimes." The article consequently focused on whether there is a difference between "crime" and "cybercrime." It's been a long time, and cybercrime has come a long way, since I wrote that article. I thought I'd use this post to look at what I said then and see how it's held up, i.e., see if we have any additional perspective on the relationship between crime and cybercrime... more
Sponsored byIPv4.Global
Sponsored byWhoisXML API
Sponsored byCSC
Sponsored byVerisign
Sponsored byVerisign
Sponsored byRadix
Sponsored byDNIB.com