Monday, March 7, 2011

Net set to make cookies crumble

How websites track visitors and tailor ads to their behaviour is about to undergo a big shake-up.

From 25 May, European laws dictate that "explicit consent" must be gathered from web users who are being tracked via text files called "cookies".

These files are widely used to help users navigate faster around sites they visit regularly.

Businesses are being urged to sort out how they get consent so they can keep on using cookies.

Track changes

The changes are demanded by the European e-Privacy directive which comes into force in the UK in late May.

The section of the directive dealing with cookies was drawn up in an attempt to protect privacy and, in particular, limit how much use could be made of behavioural advertising.

This form of marketing involves people being tracked across websites, with their behaviour used to create a profile that dictates the type of adverts they see.

As part of its work to comply with the directive, the IAB - an industry body that represents web ad firms - created a site that explains how behavioural advertising works and lets people opt out of it.

The directive demands that users be fully informed about the information being stored in cookies and told why they see particular adverts.

"Start Quote

It's going to happen and it's the law."

End Quote Christopher Graham Information Commissioner

Specifically excluded by the directive are cookies that log what people have put in online shopping baskets.

However, the directive is likely to have an impact on the more general use of cookies that remember login details and enable people to speed up their use of sites they visit regularly.

It could mean that after 25 May, users see many more pop-up windows and dialogue boxes asking them to let sites gather data.

Data delay

The exact steps that businesses have to go through to comply with the law and gain consent from customers and users are being drawn up by the Department for Culture, Media and Sport (DCMS).

A spokesman for the DCMS said that work on the regulations was "ongoing" but would not be complete by 25 May.

In a statement, Ed Vaizey, minister for Culture, Communications and the Creative Industries, said he recognised that the delay would "cause uncertainty for businesses and consumers".

"Therefore we do not expect the Information Commissioner's Office (ICO) to take enforcement action in the short term against businesses and organisations as they work out how to address their use of cookies," he added.

Information Commissioner Christopher Graham said: "I cannot bark at the industry at the moment because I have not got the regulations."

However, Mr Graham stressed that the government's confession that the regulations will be delayed should not be a spur to inaction.

"My message is that this is not your 'get out of jail free' card," he said.

The response to complaints about firms that flout the directive will be viewed in light of what they have done to prepare for it, continued Mr Graham.

Businesses should be considering how they will communicate with customers to get consent and look at the technical steps that might make that process easier, he explained.

Early work by the ICO suggests that gathering consent by changing settings on browsers may not be sophisticated enough for the demands of the directive.

"They have to think seriously about this," said Mr Graham. "It's going to happen and it's the law."



Powered By WizardRSS.com | Full Text RSS Feeds | Amazon WordPress PluginHud 1 Settlement Statement

Facebook adds suicide help system

Facebook is launching a system that allows users to report friends who they think may be contemplating suicide.

The feature is being run in conjunction with the Samaritans, which said several people had used it during a test phase.

Anyone worried about a friend can fill out a form, detailing their concerns, which is passed to the site's moderators.

It follows reports of several cases where Facebook users announced their intention to commit suicide online.

The reporting page asks for the address (URL) of the Facebook page where the messages are posted, the full name of the user and details of any networks they are members of.

Suicide-related alerts will be escalated to the highest level, for attention by Facebook's user operations team.

Police alert

"When a report is made, they then assess whether they need to call the police immediately or forward it on to us," said the Samaritans' Nicola Peckett.

Facebook said that it had always been its policy to notify police if a user was at risk of imminent bodily harm.

The system had been operating in a trial mode, without publicity for three months, during which it received several genuine reports and no hoaxes, according to the Samaritans.

It is hoped that the new reporting mechanism will help prevent cases like that of Simone Back, who died on Christmas day after taking a drug overdose.

The charity worker from Brighton had written about her intention to kill herself on her Facebook page.

Several of her friends commented on the message, however no-one raised the alarm.

The Samaritans said that the new system was not launched in relation to one specific case, but to raise awareness of the ways in which people could get help.



Powered By WizardRSS.com | Full Text RSS Feeds | Amazon WordPress PluginHud 1 Settlement Statement

Sony gets PS3 hack case details

Sony has been given permission to obtain details of people who downloaded files needed to hack the PlayStation 3.

A judge in San Francisco granted the electronics giant a subpoena that would allow it to see a list of IP addresses.

The software, used to crack the PS3's operating system, was posted on the website of George Hotz, who is also known as Geohot.

Sony is suing Mr Hotz, claiming his hacks breach copyright laws, and could allow users to play pirated games.

Court documents, obtained by Wired magazine, show that the company successfully petitioned to obtain IP addresses from the web-hosting company Bluehost.

The details could be used to trace the real-world geographical locations of users who accessed George Hotz's website, Geohot.com.

However, it may not be Sony's intention to take legal action against those found to have downloaded the software crack.

Illicit conduct

Sources with knowledge of the case said there was unlikely to be the appetite for a prolonged and expensive series of legal challenges.

Rather, the subpoena document suggests that Sony wants to discover the number and location of the downloaders in order to establish jurisdiction in its case against Mr Hotz.

"SCEA [Sony Computer Entertainment America] needs to determine how rampant the access to and use of these circumvention devices has been in California in order to rebut Mr Hotz's suggestion that his illicit conduct was not aimed at the forum state," the document reads.

The subpoena also grants Sony the right to access information relating to the case from Twitter, Google Blogspot and YouTube.

Restraining order

The company had previously been granted a restraining order against Mr Hotz, banning him from revealing techniques to manipulate the PlayStation 3's operating system.

The 21-year-old, along with a number of other individuals, is charged with violating several copyright-related laws, including the Digital Millennium Copyright Act

He is also accused of offences under the United States' Computer Fraud and Abuse Act.

Mr Hotz denies that he set out to help software pirates, claiming instead that he was championing the 'home brew' community - users who write their own software for the PS3.

Sony has said it is now able to remotely identify users who are running hacked PlayStation 3 consoles and that it will ban persistent offenders from using its online services.



Powered By WizardRSS.com | Full Text RSS Feeds | Amazon WordPress PluginHud 1 Settlement Statement

Cyber attack targeted Paris G20

The French finance ministry has confirmed it came under a cyber attack in December that targeted files on the G20 summit held in Paris in February.

Budget Minister Francois Baron said an investigation had been launched, adding: "We have leads".

It follows a report in Paris Match magazine that claimed a sustained cyber attack sought documents related to the G20 and international economic affairs.

More than 150 computers at the ministry were affected.

'Determined professionals'

"We noted that a certain amount of the information was redirected to Chinese sites," an anonymous official was quoted by the French magazine. "But that [in itself] does not say very much."

An official complaint has been filed with French courts, and the matter has been taken up by the secret service.

"The actors were determined professionals and organised," Patrick Pailloux, director general of the French National Agency for IT Security told Paris Match.

"It is the first attack of this size and scale against the French state."

The summit agreed a list of targets for reducing imbalances in the global economy in order to head off future financial crises.

The topic was particularly contentious for the Chinese, who resisted calls to target exchange rate valuations, currency reserves and economic surpluses.

The US and other countries accuse China of buying up trillions of dollars in foreign reserves in order to hold down the value of the yuan and gain an unfair competitive advantage in trade.



Powered By WizardRSS.com | Full Text RSS Feeds | Amazon WordPress PluginHud 1 Settlement Statement

Friday, March 4, 2011

US and Israel blamed for Stuxnet

Israel and the United States created the Stuxnet worm to sabotage Iran's nuclear programme, a leading security expert has claimed.

Ralph Langner told a conference in California that the malicious software was designed to cripple systems that could help build an Iranian bomb.

Mr Langner was one of the first researchers to show how Stuxnet could take control of industrial equipment.

It is widely believed that its target was machinery used to enrich uranium.

Speaking at the TED conference in Long Beach, California, Mr Langner said: "My opinion is that Mossad [Israel's intelligence agency] is involved."

However he speculated that Israel was not the main driver behind the creation of Stuxnet.

"There is only one leading source, and that is the United States," said Mr Langner.

In a recent report on Stuxnet, the security firm Symantec said that it would have taken a team of between five and 10 developers, six months to create the worm.

Mr Langner said that the project would have required "inside information", so detailed that "they probably knew the shoe size of the operator."

Stuxnet first came to light in July 2010. Nearly 60% of reported infections were inside Iran.

Damaging centrifuges

The worm targets industrial control systems, known as programmable logic controllers (PLCs), made by Siemens.

While PLCs are used to control a wide variety of automated systems, it is believed that it was those inside Iran's nuclear facilities that were the intended target.

Analysts who have examined the Stuxnet code say it could have been used to damage centrifuges which play a crucial role in the process of enriching uranium for both nuclear power and weapons.

The United States and Israel have led an international campaign to halt Iran's nuclear programme, however there is no hard evidence to link either country to the creation of Stuxnet.

Earlier in the week Iran's Interior Ministry denied that Stuxnet had been responsible for a shutdown at the country's Bushehr nuclear reactor.

A report by the International Atomic Energy Agency showed that Russian engineers working at the plant had removed 163 fuel rods.

Iranian sources said that the action was taken as a result of problems with the rods, rather than Stuxnet.



Powered By WizardRSS.com | Full Text RSS Feeds | Amazon WordPress PluginHud 1 Settlement Statement

UK pushes on with broadband plans

The government is pushing ahead with the second wave of funding for super-fast broadband across the UK.

It comes despite the fact that no firms or technologies have yet been chosen for original pilot areas earmarked to test how to roll out next-generation broadband to remote areas.

New bids are now being invited for a further �50m.

The government has pledged to make the UK the best place for super-fast broadband in Europe by 2015.

The �50m will be made available to local authorities around the UK.

"This is very much a locally-driven process and we encourage bids from all local people with plans for improving broadband in their local area," said Chancellor of the Exchequer George Osborne.

Local councils wanting to take advantage of the latest tranche of funding will need to apply via the Broadband Delivery UK.

The government estimated that the funding would help a further 800,000 homes to benefit from next-generation broadband.

Slow progress

Some have questioned the timing of the new scheme, given that pilots intended to be testbeds for best practice in connecting the so-called 'final third' have yet to begin.

This is the third of UK homes that are not economically attractive to firms such as BT and Virgin Media because offering next-generation services there would cost too much money.

At the time they were announced Secretary of State for Culture, Media and Sport Jeremy Hunt said: "Our aim is to use these rural market testing pilots to discover exactly what needs to be done to make super-fast broadband commercially viable in rural communities".

Despite announcing the four areas in October - North Yorkshire, Cumbria, Herefordshire and the Highlands and Islands - no firm or technologies have yet been chosen for the areas.

Each trial was allocated a fund of between �5m and �10m.

Lack of progress led Labour MP Ian Lucas to ask the government to "pull its finger out" last month.

A spokesman for the Department for Culture, Media and Sport conceded that it has been a long process.

"Councils are having to get everything ready. They have to know what work needs to be done."

He said that announcements would be made soon.

In total the government has earmarked �530m of public money to be spent on bringing super-fast broadband to rural areas.

This money is drawn from the BBC license fee and was originally earmarked to help people with the switch over to digital TV.

Any funds to speed up broadband roll-out should be applauded said Sebastien Lahtinen of broadband news site ThinkBroadband.

"This crucial step will be welcomed by those living in the 'final third', the most remote areas of the UK which currently suffer from a lack of decent broadband services.

However, many in those areas will continue to be frustrated that it's going to take years to roll out across the entire country," he said.



Powered By WizardRSS.com | Full Text RSS Feeds | Amazon WordPress PluginHud 1 Settlement Statement

Blogspot banned in football row

A row over who can broadcast football matches in Turkey has led to Google's Blogger site being blocked.

A court in Turkey issued the ban in response to a copyright complaint by satellite TV firm Digiturk.

It brought the complaint when it discovered that some of the matches it was broadcasting were showing up on Blogspot pages.

About 600,000 Turkish bloggers are thought to use the Google tool to publish their personal journals.

The ban has been imposed because Turkey's copyright protection laws allow for entire services to be shut down.

In October, 2010 Turkey lifted a ban on YouTube that had been in place for two years.

Google confirmed the Blogger/Blogspot ban in a statement and said those with worries about piracy should turn to its easy to use takedown systems rather than seek a wholesale shutdown.

"The process for making a copyright claim for content uploaded to Blogger is straightforward and efficient, and we encourage all content owners to use it rather than seek a broad ban on access to the service," said a spokesperson.

"That way, people in Turkey can continue to enjoy Blogger whilst we respond to the specific complaint."

Digiturk said it went to court to protect its right to broadcast Turkey's Spor Toto Super League games on its Lig channel. Digiturk said the ban had not curbed all piracy as other sites beyond Blogger were still showing pirated streams of football matches.

Cyber-rights activist Yaman Akdeniz told the Hurriyet news site that the ban was a "disproportionate response" that would inconvenience millions of people.

"I understand there is a legitimate concern regarding Digiturk's commercial rights but banning all these websites will not solve the issue," he told the site.



Powered By WizardRSS.com | Full Text RSS Feeds | Amazon WordPress PluginHud 1 Settlement Statement

Thursday, March 3, 2011

Android hit by rogue app viruses

More than 50 applications available via the official Android Marketplace have been found to contain a virus.

Analysis suggests that the booby-trapped apps may have been downloaded up to 200,000 times.

The malicious apps were copies of existing applications, such as games, that had been repackaged to include the virus code.

All the apps found to contain the malicious code have now been removed from the Android Marketplace.

Remove and recall

The virus-laden apps were discovered by a Reddit user called Lompolo who realised that one program was listed under the name of a publisher he knew had not written it.

He found that the app, which let people play guitar on their handset, was the same as the original but for a name change and some virus code buried within it.

Lompolo said the rogue apps had been downloaded between 50,000 and 200,000 times since they were placed on the Marketplace.

Lompolo initially found 21 apps bearing the viral code but, according to an investigation by mobile security site Android Police, the final tally is believed to involve more than 50. The apps are also known to be available on unofficial Android stores too.

Once a booby-trapped application is installed and run, the virus lurking within, known as DroidDream, sends sensitive data, such as a phone's unique ID number, to a remote server.

It also checks to see if a phone has already been infected and, if not, uses known exploits to bypass security controls and give its creator access to the handset. This bestows the ability to install any code on a phone or steal any information from it.

The latest version of the Android operating system, known as Gingerbread, is not vulnerable to the exploits DroidDream uses.

Open access

As well as removing the applications from the Android Marketplace, Google has also suspended the three accounts being used by the developer behind the apps.

It also has the option to use a security tool that can recall and uninstall rogue applications from phones. It is not thought to have yet done this as its investigation continues. Google has yet to issue a formal statement about the rogue applications while it completes the investigation.

Writing on the Trend Micro security blog, Rik Ferguson, pointed out that remote removal of the booby-trapped apps may not solve all the security problems they pose.

"...this remote kill switch will not remove any other code that may have been dropped onto the device as a result of the initial infection," he wrote.

He advised anyone who believed they had installed one of the malicious apps to find out whether they need to get a new handset or re-install the operating system on the one they have.

The open nature of the Android platform was a boon and a danger, he warned.

"This greater openness of the developer environment has been argued to foster an atmosphere of creativity," he wrote, "but as Facebook have already discovered it is also a very attractive criminal playground."



Powered By WizardRSS.com | Full Text RSS Feeds | Amazon WordPress PluginHud 1 Settlement Statement

Wednesday, March 2, 2011

Apple launches second iPad tablet

Apple has launched the second generation of its iPad tablet computer at an event in California.

The company said the machine featured a faster processor, improved graphics, and front and rear cameras.

Apple has led the industry in sales of tablet devices since the launch of the first iPad in April 2010.

However, it has been losing market share to a raft of rival devices from manufacturers such as HP and Samsung.

The event was hosted by Apple chief executive Steve Jobs, who has been on medical leave from the company since January.

It had been widely speculated that he would not appear owing to his ill health.

Mr Jobs was diagnosed with pancreatic cancer in 2004.

Speaking on stage, he said: "We have been working on this product for a while and I just didn't want to miss today."

Ovum analyst Adam Leach predicted a two-horse race in the tablet market over the coming year, between the iPad and Google's Android operating system.

"The platform dominance of Apple and Google will continue through 2011 and beyond," said Mr Leach.

"However, devices based on Google's platforms will only overtake those based on Apple's platform by 2015, when we forecast 36% and 35% market shares respectively," he added.



Powered By WizardRSS - Full Text RSS Feeds

Tuesday, March 1, 2011

Concern at broadband speed claims

Ofcom is seeking to stop internet service providers from advertising unrealistic broadband speeds.

Currently most ISPs advertise services as 'up to' a certain speed - for instance, 20Mbps (megabits per second).

But Ofcom's latest research finds that very few consumers actually get these headline speeds.

"There is a substantial gap between advertised speeds and the actual speeds people get in their homes," Ofcom chief executive Ed Richards told the BBC.

"The chances of someone receiving the advertised headline speed are fairly remote," he said.

"We would like to see clearer information provided to consumers which more accurately reflects the likely speeds they will actually receive," he added.

Ofcom's latest research into broadband speeds found that just 14% of customers on 'up to' 20Mbps services received speeds of over 12Mbps, while 58% averaged speeds of 6Mbps or less.

Consumer confusion

Cable and fibre services fared better, with 92% of Virgin Media customers on an 'up to' 50Mbps service averaging 45.6Mbps.

Its lower 10Mbps service saw average speeds of 9.6Mbps.

BT's Fibre-to-the-Cabinet technology, which is currently available to 15% of UK homes, has an average of 31.8Mbps on the 40Mbps service.

Unrealistic broadband speeds has long been an issue for consumer groups, who say such advertising is adding to consumer confusion over net services.

"Broadband speeds are a major source of dissatisfaction for UK broadband customers," says Michael Phillips, product director at comparison site Broadbandchoices.

"We have been pushing for 'typical speeds' to be made the gold standard for speed measurement since 2007 - in the same way that banks use 'typical' APR percentages."

The Advertising Standards Authority is looking into the issue.

Ofcom is recommending that ISPs use Typical Speed Rates (TSR) to avoid confusing consumers.

It has set guidelines for these speeds. It recommends that ADSL services currently advertised as 'up to' 20Mbps (megabits per second) be changed to a TSR of between 3 and 9Mbps.

Digital exclusion

BT is not impressed with Ofcom's idea.

"We have real concerns with their approach. Broadband speeds vary from line to line and so it is meaningless to use one speed for advertising. That is why we use the term 'up to'," said John Petter, managing director of BT Retail.

He said he thought such a policy "would encourage digital exclusion rather than tackle it".

"Enforcing typical speed ranges is also dangerous as it could encourage more ISPs to cherry pick customers who will increase their average, leaving customers in rural and suburban areas under-served," he said.

PlusNet defended its current advertising.

"We offer customers a personalised speed range.

"This is confirmed at application and then again once a customer has had their broadband service fully installed - we are completely honest with customers about the speeds they will receive," said chief executive Jamie Ford.

Virgin Media, which fared the best in the speed tests, welcomed the news: "Ofcom's latest report is yet another damning indictment that consumers continue to be treated like mugs and misled by ISPs that simply cannot deliver on their advertised speed claims," said Jon James, executive director of broadband at Virgin Media.

Andrew Ferguson, editor of broadband website ThinkBroadband, said using average speeds could encourage mediocrity.

"Providers who now go all out to get the best speeds could give up and make do with the average," he said.

He added that there was "no such thing as an average" because the speed of a connection depends on so many factors, including home wiring, the applications being used and where in the UK people live.

Are you a broadband customer? What is your reaction to this story? Send us your comments using the form below:



Powered By WizardRSS - Full Text RSS Feeds