/ Most Viewed

A Cynic’s View of 2015 Security Predictions - Part 4

Lastly, and certainly not the least, part four of my security predictions takes a deeper dive into mobile threats and what companies and consumer can do to protect themselves. If there is one particular threat category that has been repeatedly singled out for the next great wave of threats, it has to be the mobile platform -- in particular, smartphones... The general consensus of prediction was that we're (once again) on the cusp of a pandemic threat. more

Digital Rights Defender Steps Aside: Cindy Cohn to Leave EFF After 25 Years

Cindy Cohn, a leading advocate for digital civil liberties, will step down as executive director of the Electronic Frontier Foundation (EFF) by mid-2026. Her departure marks the end of a tenure spanning over two decades, including ten years at the helm of the San Francisco-based nonprofit. more

Masking Identity with Proxy/Privacy Services

No censure attaches to having domain names registered by proxy/privacy services. However, while the practice has become routine for protecting privacy and sensitive information, registering in the name of a proxy is still taken into account in assessing intention, and even circumstantial evidence without contradiction or explanation can tip the scale in complainant's favor. more

Is the Internet Fragmenting? Join the Discussion Live - Tuesday, May 10, at 3:30pm US EDT

Is the global, open Internet moving away from a network of networks that is universally accessible to a series of networks fragmented along policy, technical or economic lines? As some governments pass laws related to data localization and restriction of cross-border data flows, what will the impact be? What about the increasing use of DNS and content filtering? What other factors have the potential for causing fragmentation? more

Singapore’s Fiber Infrastructure Beginning to Pay Off

It's still early days, but Singapore's approach to fiber deployment is beginning to pay off. In December 2007, Singapore announced a major program to get fiber deployed throughout their city state. A critical advantage of their approach was government mandated structural separation between the dark fiber layer deployed in the public right-of-way (a natural monopoly) and higher layer services (where competition is possible and highly desirable. more

A Secure Recursive Caching DNS Server

Over the last couple of weeks I have spent some time working on a project to develop a DNS cache for Windows that is intended to be reasonably secure against spoof attacks, in particular in situations where NAT firewalls may prevent port randomization. The program is evolving, but currently uses a couple of ideas to attempt to defeat spoof attacks... The source code is intended to be entirely un-encumbered, that is free in all respects. I would welcome any suggestions or comments on the aims of the project, the source code, the functionality of the program or other ideas. more

BGP Hijacks: Two More Papers Consider the Problem

The security of the global Default Free Zone (DFZ) has been a topic of much debate and concern for the last twenty years (or more). Two recent papers have brought this issue to the surface once again - it is worth looking at what these two papers add to the mix of what is known, and what solutions might be available. The first of these traces the impact of Chinese "state actor" effects on BGP routing in recent years. more

DHS Planning to Monitor, Collect Social Media Information on All Immigrants to US

The U.S. Department of Homeland Security (DHS) published a new rule under the Privacy Act of 1974 in the Federal Register last week, detailing how it intends to expand the information it collects when determining a person's immigration status to include social media handles and potentially even search histories. more

ICANN 48 in Buenos Aires: What Happened and What’s Next?

Last month, some of my colleagues at MarkMonitor and I traveled to Buenos Aires, Argentina for ICANN 48. With the recent delegation and launch of the first new gTLDs, the atmosphere had an air of both excitement and anxiety. In my opinion, there is much to be done before brand owners should begin to feel comfortable in the post-new gTLD Internet environment, which brings a host of new challenges, as companies attempt to scale monitoring and enforcement to the new (huge) domain name space. more

The Epsilon Phishing Model

Phishing researcher Gary Warner's always interesting blog offers some fresh perspective on clicking links on emails, as the crux of the phishing problem. Gary writes: "There is a saying 'if you give a man a fish, he'll eat for a day, but if you teach a man to fish, he can feed himself for a lifetime.' In the case of the Epsilon email breach the saying might be 'if you teach a man to be phished, he'll be a victim for a lifetime.' In order to illustrate my point, let's look at a few of the security flaws in the business model of email-based marketing, using Epsilon Interactive and their communications as some examples." more

IP Address Location Data

The last few years have shown us how the Internet shrinks distances between distributed teams, organizations and families. This poses a challenge for some organizations. Many business relationships and contractual agreements involving the Internet have geographical implications and restrictions. This matters to anyone operating a network. It is most important for networks that get new address space. more

Reselling Domain Names on the Secondary Market: Bona Fide Offering, or Not?

On the question of reselling domain names on the secondary market, a dissenting panelist in a 2005 case observed that "[t]here is no doubt Respondent is in the business of being a reseller of domain names that consist of common English words" and then suggested that the "fundamental question before the Panel is whether or not such a business should be allowed under the UDRP." He concluded that such a business should not be allowed... more

No GDPR Action Against Any Big Tech Firms Since Law Imposed Last Year, Doubts Escalate Over Enforcer

Last year Europe imposed GDPR, arguably the world's toughest standard for data privacy and now, a year later, there has yet to be any enforcement action against a big tech firm. more

Amid Shutdown, Gab.com Claims Free Speech Infringement While Many Others View Them as Hate Site

The controversial site gab.com has been shut down by GoDaddy and given 2 days to move the domain elsewhere. The deadline expires at midnight tonight Irish time. In recent days the site has seen itself become increasingly disconnected as various service providers and online platforms including PayPal have shut the door to them. At present the site is displaying this notice... more

Will 5G Trigger Smart City PPP Collaboration?

As discussed in previous analyses, the arrival of 5G will trigger a totally new development in telecommunications. Not just in relation to better broadband services on mobile phones - it will also generate opportunities for a range of IoT (internet of things) developments that among other projects are grouped together under smart cities (feel free to read 'digital' or 'connected cities'). more