2012 will always be remembered as the Year of Wikileaks. Similarly, 2013 shall also be remembered as the year that Edward Snowden, a computer security specialist and former CIA employee and National Security Agency contractor, leaked classified information regarding the NSA global surveillance programs. Whilst Wikileaks was about US diplomatic cables, the Edward Snowden disclosure of classified NSA information to private media organizations such as the UK Guardian newspaper has had graver implications for global Internet privacy. more
COICA (Combating Online Infringement and Counterfeits Act) is a legislative bill introduced in the United States Senate during 2010 that has been the topic of considerable debate. After my name was mentioned during some testimony before a Senate committee last year I dug into the details and I am alarmed. I wrote recently about interactions between DNS blocking and Secure DNS and in this article I will expand on the reasons why COICA as proposed last year should not be pursued further in any similar form. more
From the dawn of the mainstream commercial Internet in the late 1990s until quite recently, the world trade and Internet communities have been almost entirely disconnected from one another. This isn't surprising, given that trade policy historically follows technological developments with a considerable 'lag.' As the senior-most 'permanent representative' on the ground in Geneva from the for-profit tech sector, a big part of my job is to try and translate the Internet for the Diplomatic Corps across many different policy subjects. more
I keep seeing so many articles about the Internet and related policy issues that it's hard to know how to respond. The term "IP Transition" may be a good starting point since the term is an attempt to treat the Internet as a smooth transition rather accepting the idea that we are in the midst of a disruptive change. It seems that the FCC's approach is to simply substitute IP for old protocols and to preserve policies tied to the accidental properties of a copper infrastructure. This shows a failure to come to terms with the new reality. more
Given its engineering background, many positive contributions can be made by the engineering community in the broader ICT world to assist in addressing some of the broader internet issues, often addressed within the more limited telecoms environment.. Of course some of this is already happening; however much more work would be needed to strengthen the technical foundations of the internet. Just as an example, the type of issues that could be addressed by a broader ICT engineering foundation could include... more
APNIC is a signatory to the Montevideo Statement, a declaration from members of the Internet technical community about the current state of Internet technical coordination, cooperation and governance. The statement conveys in particular an agreement on "the need for ongoing effort to address Internet Governance challenges", and a commitment to "catalyze community-wide efforts towards the evolution of global multi-stakeholder Internet cooperation". Last week during ICANN 48 in Buenos Aires, there were numerous discussions about the Montevideo Statement... more
This article was originally intended to be a short one focused on indications that ICANN was exploring the establishment of a legal nexus outside the United States and discussing what that might mean - and whether it was consistent with the Affirmation of Commitments (AOC) entered into with the United States in 2009. Then, as completion neared, came the sudden and nearly simultaneous release of the October 7th Montevideo Statement and the announcement two days later of a proposed 2014 Brazil "Summit" focused on restructuring Internet governance. At that point the task vastly expanded. more
As each day brings new revelations about surveillance online, we are starting to see increasing activity in national legislatures intended either to establish more control over what the security services can do to their nationals (in countries like the US), or to limit access by foreign secret services to the personal information of their citizens (countries like Brazil). Unfortunately, neither of these approaches address the underlying problem: we have a paradigm for surveillance that's fit for the analogue past, not the digital present, let alone the future. more
Doug Madory from Renesys reports: "In response to recent NSA spying allegations, Brazil is pressing ahead with a new law to require Internet companies like Google to store data about Brazilian users inside Brazil, where it will be subject to local privacy laws. The proposed legislation could be signed into law as early as the end of this week. However, Google's DNS service started leaving the country on September 12th, the day President Rousseff announced her intention to require local storage of user data." more
How do we harden the Internet against the kinds of pervasive monitoring and surveillance that has been in recent news? While full solutions may require political and legal actions, are there technical improvements that can be made to underlying Internet infrastructure? As discussed by IETF Chair Jari Arkko in a recent post on the IETF blog, "Plenary on Internet Hardening", the Technical Plenary at next weeks IETF 88 meeting in Vancouver, BC, Canada, will focus on this incredibly critical issue. more
If a hired philosopher graced ICANN, the work would get down to brass tacks. "What is it?", she would ask, that drives ICANN beyond the mysterious dot that apparently represents the root. One can picture subsequent appeals from senior management to its navels, for clues as to what in the end game the root truly represents. I surmise that contemplating bred-in-the-bone values does not resonate easily or often at ICANN. Its like that unreachable itch that evades our scratch; we can't get at the source. more
The idea that the US would maintain a strategic position in the Internet was always a pipe dream. Allowing the US to pick the DNS contractors is one thing, allowing the US the power to arbitrarily shut countries off the net is quite another. And that is what deployment of DNSSEC and the rPKI under the current models would do. The idea that some US congressman would promote a bill to force ICANN to drop Cuba, Palestine or the enemy of the moment off the Internet is really not far fetched. The US government was just shut down for over two weeks in a bizarre act of political theater. more
In a very casual and low-key footnote over the weekend, ICANN announced it would be further bypassing the Affirmation of Commitments and ignoring the WHOIS Review Team Report. There will be no enhanced validation or verification of WHOIS because unidentified people citing unknown statistics have said it would be too expensive... As a topic which has burned untold hours of community debate and development, the vague minimalist statement dismisses every ounce of work put in by stakeholders. more
If approved, the code would technically be voluntary for Canadian ISPs, but the active involvement of government officials suggests that most large providers would feel pressured to participate. The move toward an ISP code of conduct would likely form part of a two-pronged strategy to combat malicious software that can lead to cybercrime, identity theft, and other harms. First, the long-delayed anti-spam legislation features new disclosure requirements for the installation of software along with tough penalties for non-compliance. more
What does authorized access mean? If an employee with authorized access to a computer system goes into that system, downloads company secrets, and hands that information over to the company's competitor, did that alleged misappropriation of company information constitute unauthorized access? This is no small question. If the access is unauthorized, the employee potentially violated the Computer Fraud and Abuse Act (CFAA) (the CFAA contains both criminal and civil causes of action). But courts get uncomfortable here. more