There have been a number of reports recently about customer lists leaking out through Email Service Providers (ESPs). In one case, the ESP attributed the leak to an outside hack. In other cases, the ESPs and companies involved have kept the information very quiet and not told anyone that data was leaked. People do notice, though, when they use single use addresses or tagged addresses and know to whom each address was submitted. Data security is not something that can be glossed over and ignored. more
My main argument is about the policy of handling vulnerabilities for 6 months without patching (such as the Google attacks 0day apparently was) and the policy of waiting a whole month before patching this very same vulnerability when it first became an in-the-wild 0day exploit (it has now been patched, ahead of schedule). Microsoft is the main proponent of responsible disclosure, and has shown it is a responsible vendor... I simply call on it to stay responsible and amend its faulty and dangerous policies. more
The debate around Network Neutrality is sometimes simplified as carriers against content providers, the owners of networks against the businesses that have grown due to Internet connectivity. So it was interesting to read that Google and Verizon filed a joint submission to the FCC last week, laying out in detail how the two companies agreed on many issues regarding an "Open Internet." more
With the prospect of broadband networks becoming more and more of a reality, it appears that concepts such as eHealth are not too far away. Digital healthcare describes the whole system of GPs, hospitals and regional healthcare centres, while eHealth describes the many health applications which will become available for people to use at home. more
Garth Bruen reports on a paper published by the American Society of Law, Medicine & Ethics of Boston University School of Law authored by Bryan A. Liang and Tim Mackey titled, "Searching for Safety: Addressing Search Engine, Website, and Provider Accountability for Illicit Online Drug Sales". From the paper: "Online sales of pharmaceuticals are a rapidly growing phenomenon. Yet despite the dangers of purchasing drugs over the Internet, sales continue to escalate. These dangers include patient harm from fake or tainted drugs, lack of clinical oversight, and financial loss. Patients, and in particular vulnerable groups such as seniors and minorities, purchase drugs online either naïvely or because they lack the ability to access medications from other sources due to price considerations. Unfortunately, high risk online drug sources dominate the Internet, and virtually no accountability exists to ensure safety of purchased products." more
I saw this case in the excellent National Association of Attorneys General publication Cyber Crime e-newsletter. Many of us host or sponsor online communities of one form or another. On occasion, this means we must engage in moderation of the discourse in that community, and, as chance may arise, on occasion, we must give some chap the boot from the community for violating the AUP or the TOS. Inevitable, the booted chap screams "First Amendment Violation," to which we must respond, "The First Amendment restrains government actors -- we are not government actors." more
Looking back at the year that just ended, here are the top ten most popular news, blogs, and industry news on CircleID in 2009 based on the overall readership of the posts. Congratulations to all the participants whose posts reached top readership in 2009 and best wishes to the entire community in 2010. more
I am just a security guy, as are many others who will read this. Perhaps it is time us "simple" security guys got together and wrote some recommendations for air travel security? Get out your voice out there as an organized professional group which can in turn lobby for our professional recommendations... Here are mine, just to get the ball rolling... more
Today's case involves the classic alleged scenario of a gripe site which used a Plaintiff's trademark in Defendant's web site domain name -- and whether this might be a violation of the Anti Cybersquatting Consumer Protection Act (ACPA). more
The French are good at 'doing' infrastructure. The country takes pride in a civil service which has been progressively centralised since the efforts of Cardinal Richelieu in the mid-17th century. The well-funded health system is among the best in Europe. The generously subsidised rail service, the SNCF, also rates highly. These and other components of the modern French State cost money, and the government has rarely proven shy in supporting big ideas, particularly if they are so readily equated with public welfare and benefit. more
Today the Swedish IT Minister Åsa Torstensson together with the Commissioner Viviane Reding sent a letter to the UN Secretary General Ban Ki-moon. I think the letter is extremely well written, but when I twittered about it, some people contacted me and asked what was so special with it? Let me try to explain... more
The Netherlands remains one of the few countries in Europe to have significant FttH networks. Until 2009, the main characteristic of Dutch fibre rollouts was the dominant role played by housing corporations and municipal governments. This focus changed following KPN's acquisition of a 41% stake in the fibre provider Reggefiber and the subsequent ramping-up of their efforts and investment through their joint venture Glashart. more
The New Zealand government has released a revamped three strikes proposal that incorporates full court hearings and the possibility of financial penalties. A prior proposal, which would have resulted in subscriber access being terminated without court oversight, was dropped earlier this year following public protest. more
It looks as if new top-level domains are getting ever closer to the opening bell. Preliminary minutes from the December 9 2009 ICANN Board of Directors meeting suggest that the Board may authorize Expressions of Interest (EOI) at their February 10th meeting. The vote was unanimous. more
The further we move into discussions about the implementation of national broadband networks the more issues crop up that need to be discussed in this context. One topic that is currently getting a great deal of attention is the need (or not) for an RF video layer to be deployed over the fibre network. Both business and technical elements are involved in this, but let's start with some of the business elements... more