Friday, November 26, 2010

Pirate Bay founders lose appeal

Three founders of The Pirate Bay have lost an appeal against a conviction for illegally sharing copyrighted content.

The Swedish appeals court upheld the 2009 ruling against the site's founders which saw them sentenced to a year in jail and heavily fined.

The ruling reduces the sentences the men face but increases fines to 46m crowns (�4.1m).

Three of The Pirate Bay's four founders were in court for the verdict. The other was too ill to attend.

The original verdict on Peter Sunde, Fredrik Neij, Gottfrid Svartholm Warg and Carl Lundstrom was handed down in April 2009 following a lengthy trial.

Lawyers acting for music labels and movie studios alleged that via The Pirate Bay, the four men helped people circumvent copyright controls.

The founders defended themselves by saying that The Pirate Bay did not host any pirated material directly.

The appeal court ruling will see Mr Neij serve a 10 month sentence; Mr Sunde eight months and Mr Lundstrom four months. Once Mr Svartholm Warg is fit his "criminal liability" will be tested by the appeals court.

Throughout the legal action and appeal hearing The Pirate Bay website has continued to function.

"Today's judgment confirms the illegality of The Pirate Bay and the seriousness of the crimes of those involved," said the International Federation for the Phonographic Industry in a statement.

"It is now time for The Pirate Bay, whose operators have twice been convicted in court, to close. We now look to governments and ISPs to take note of this judgment, do the responsible thing and take the necessary steps to get The Pirate Bay shut down."



Powered by WizardRSS | Best Membership Site Software

Police seek domain closure powers

The police are seeking powers to shut down websites deemed to be engaged in "criminal" activity.

The Serious and Organised Crime Agency (SOCA) has tabled a plan for Nominet, which oversees .uk web addresses, to be given the domain closing power.

Nominet said the idea was only a proposal and invited people to join the debate on the form of the final policy.

IT lawyers said the proposal would be "worrying" if it led to websites going offline without judicial oversight.

"It's not policy at this stage," said Eleanor Bradley, director of operations at Nominet.

She said SOCA's proposal emerged from changes made to Nominet's policy development process earlier in 2010, as well as experiences with closing down a series of criminal sites in the last 12 months.

In the proposal, SOCA pointed out that Nominet currently has no obligation to close down criminal websites. SOCA wants this changed so domains can be cancelled if law enforcement agencies deem them to be engaged in criminal activities, and inform Nominet of their conclusion.

Ms Bradley SOCA's proposal was the "very beginning of the process" to update Nominet's policies.

"We now need to get a balanced group of stakeholders together to talk about the policy and its implications," she said.

Since SOCA's proposal was posted on the Nominet site, feedback had started to come in that was helping to define who should be invited to join a formal discussion of the plan, said Ms Bradley.

She invited those to whom the proposal was relevant to get in touch. "We want to make sure the stakeholder group is balanced," she said.

No timetable has been drawn up for when the proposal would be discussed or when any resulting policy would be adopted.

"If you are going to do this, then fine, but it needs judicial oversight," said barrister and IT lawyer David Harris, adding that that conferring these powers might be better done by updating the Computer Misuse Act.

Nick Lockett, a lawyer at DLL specialising in computer law, said he was "deeply concerned" about SOCA's proposal if it meant it could act before a conviction had been secured.

"In a world of online retailing, the ability for a police officer to seize any business, whether that is blocking a domain or seizing the servers - pre-conviction or certainly pre-warrant - would be a dramatic change in the relationship between the police and the internet community," he told BBC News.

He also said the police would have to be very careful about the sites they judged to be engaged in criminal activity. Mistakes that resulted in shutting down a legitimate site would leave them open to claims for "massive damages" he warned.



Powered by WizardRSS | Best Membership Site Software

Net-dedicated satellite to launch

The first satellite dedicated to delivering broadband services to Europe is all set for launch.

The Hylas spacecraft is designed to fill so-called "not spots" - remote locations such as rural villages where it is currently not possible to get a fast internet connection.

The satellite will be carried into orbit on an Ariane 5 rocket.

The vehicle is expected to lift off from the Kourou spaceport in French Guiana at 1539 local time (1839 GMT).

Hylas (Highly Adaptable Satellite) is a commercial venture operated by start-up Avanti Communications of London, but the spacecraft itself incorporates technology developed with public funding through the European Space Agency (Esa).

The satellite's payload will automatically vary the amounts of power and bandwidth needed to match peaks and troughs in demand for net access across its European "footprint".

Hylas was prepared at the Portsmouth, UK, factory of EADS Astrium, Europe's largest space company, and Antrix, a commercial arm of the Indian space agency (Isro).

The 2.6-tonne spacecraft will operate in the Ka radio band and deliver broadband services to some 350,000 subscribers.

The UK government put �40m into the Hylas development programme.

It has a commitment that everyone in Britain should have access to a decent net connection by 2015.�That means a minimum of two megabits per second (Mbps).

Some three million UK homes currently fall below this standard; and across Europe, there are many millions more who cannot currently get an adequate connection through terrestrial technology.

<!-- Embedding the audio player --> <!-- This is the embedded player component -->
<!-- embedding script -->
<!-- end of the embedded player component --> <!-- Player embedded -->

Hylas will be offering up to 10Mbps to its users.

"It is the first of what will be many satellites," explained Avanti CEO David Williams. "We've already got our second satellite under construction at the moment and that launches in about 15 months' time.

"That will put more capacity into the UK but also it puts new capacity into new areas in Africa and the Middle East. And then we are planning more satellites for Latin America, India and other parts of Asia."

In Europe, Avanti faces competition from the long-established Eutelsat space communications company, which is putting up its own net-dedicated Ka-band satellite for Europe, delivering 10Mbps through its Tooway service.

Eutelsat's KA-Sat is due for launch on a Russian Proton rocket on 20 December.

Astrium worked on both Hylas-1 and KA-Sat, and at one stage the two satellites were sitting inside the same Portsmouth cleanroom separated by a few metres.

Friday's Ariane will also be orbiting a telecommunications spacecraft for Intelsat. The US platform will deliver a wide range of services across Europe, the Middle East, Russia and Asia.

Intelsat-17 will be ejected by the Ariane upper-stage 27 minutes into the flight; Hylas will come out seven minutes later.



Powered by WizardRSS | Best Membership Site Software

Thursday, November 25, 2010

ISP to test controversial alerts

Talk Talk is launching trials of a controversial anti-malware system following intervention by the Information Commissioner (ICO).

The Virus Alert system keeps an eye on the websites customers visit to stop them accidentally going to places riddled with viruses.

The ICO admonished the ISP when the service was debuted because customers were not told it was going ahead.

Talk Talk said the trials would be with customers that have opted in to use it.

In a blog posting, Clive Dorsman, managing director of Talk Talk Technology, wrote that trials of the system with a limited number of customers would start in a "few weeks".

The malware watching service first came to light in early September following a Freedom of Information request to the Information Commissioner to see if it had been notified about the system.

In response, Information Commissioner Christopher Graham said he had been in touch with Talk Talk to express his concern that customers were not told they were being enrolled into the system.

Some compared the malware watching technology to the controversial ad system Phorm, which planned to target adverts based on a person's browsing habits.

Talk Talk defended the security system saying that it did not log browsing habits and only scanned pages people wanted to visit to ensure they did not stray onto sites booby-trapped with malware.

In its blog posting, Talk Talk said it talked with "relevant public bodies" over the service and had received a lot of feedback about its plans.

In a statement the ICO said: "We have advised Talk Talk on the safeguards which are necessary to comply with the Data Protection Act and the Privacy and Electronic Communications Regulations."

It warned: "We expect them to make sure they are effective in practice."

The statement added that it would take seriously any complaints it received about the service but said it had not received any to date.



Powered by WizardRSS | Best Membership Site Software

Wednesday, November 24, 2010

Facebook feeds beset with malware

One fifth of Facebook users are exposed to malware contained in their news feeds, claim security researchers.

Security firm BitDefender said it had detected infections contained in the news feeds of around 20% of Facebook users.

By clicking on infected links in a news feed, users risk having viruses installed on their computer.

Facebook said it already had steps in place to identify and remove malware-containing links.

BitDefender arrived at its figures by analysing data from 14,000 Facebook users that had installed a security app, called safego, it makes for the social network site.

In the month since safego launched, it has analysed 17 million Facebook posts, said BitDefender.

The majority of infections were associated with apps written by independent developers, which promised enticements and rewards to trick users into installing the malware, BitDefender said.

Trusted community

These apps would then either install malware used for spying on users or to send messages containing adverts to the users' contacts.

Facebook has a thriving community of independent developers who have built apps for the social network.

The vast majority enable users to tweak their Facebook pages, adding widgets, games or extra functions, such as delivering daily horoscope predictions.

Facebook said it had processes and checks in place to guard against the risk of malware.

"Once we detect a phony message, we delete all instances of that message across the site," the site said in a statement.

Crooks have targeted social networks, such as Facebook and Twitter because of their vast number of users, said Rik Ferguson, a security researcher for anti-virus maker Trend Micro.

"Because social networks are based on a community of people you trust, they're an attractive target for malware writers," said Ferguson. "You're more likely to click on a link from someone you trust."



Powered by WizardRSS | Best Membership Site Software

Tuesday, November 23, 2010

First fines for data act breaches

A county council that faxed details of a child sex abuse case to a member of the public is to be fined �100,000 for breaching the Data Protection Act.

Hertfordshire County Council is one of two bodies fined by the Information Commissioner - both have apologised.

Sheffield-based A4e was fined �60,000 for losing an unencrypted laptop with the details of thousands of people.

The commissioner said the fines - the first he has issued - would "send a strong message" to those handling data.

Commissioner Christopher Graham was granted the authority to serve financial penalties for data protection breaches in April of this year.

Hertfordshire County Council was fined after two incidents where two faxes containing highly sensitive personal information involving a child sex abuse case and care proceedings were sent to the wrong recipients.

Fax mistakes

The breaches occurred in June, when employees in the council's childcare litigation unit accidentally sent two faxes to the wrong recipients on two separate occasions. The council reported both breaches to the Information Commissioner's Office (ICO).

The first misdirected fax was meant for a barristers' chambers but was sent instead to a member of the public.

"Start Quote

These first monetary penalties send a strong message to all organisations handling personal information - get it wrong and you do substantial harm to individuals and the reputation of your business"

End Quote Christopher Graham Information Commissioner

The council subsequently obtained a court injunction prohibiting any disclosure of the facts of the court case or circumstances of the data breach.

The second misdirected fax, sent 13 days later by another member of the council's childcare litigation unit, contained information relating to the care proceedings of three children, the previous convictions of two individuals, domestic violence records and care professionals' opinions on the cases.

The fax was intended for Watford County Court but was mistakenly sent to a barristers' chambers unconnected with the case.

The commissioner ruled that a penalty of �100,000 was appropriate, given that the council's procedures failed to stop two serious breaches taking place.

And after the first breach occurred, the council did not take sufficient steps to reduce the likelihood of another breach occurring, the ICO said.

Laptop theft

Mr Graham said: "It is difficult to imagine information more sensitive than that relating to a child sex abuse case. I am concerned at this breach - not least because the local authority allowed it to happen twice within two weeks."

A spokesman for Hertfordshire County Council said it accepted the commissioner's findings.

"We are sorry that these mistakes happened and have put processes in place to try and prevent any recurrence," he added.

The A4e data breach also occurred in June, after the company - a private sector company which provides information on employment and starting a business - issued an unencrypted laptop to an employee so they could work at home.

The computer contained personal information relating to 24,000 people who had used community legal advice centres in Hull and Leicester.

But it was later stolen from the employee's house and an unsuccessful attempt to access the data was made shortly afterwards.

Personal details recorded on the system included full names, dates of birth, postcodes, employment status, income level, information about alleged criminal activity and whether an individual had been a victim of violence.

A4e reported the incident to the ICO and the company subsequently notified the people whose data could have been accessed.

'Substantial harm'

The commissioner ruled that A4e did not take reasonable steps to avoid the loss of the data when it issued the employee with an unencrypted laptop, despite knowing the amount and type of data that would be on it.

Mr Graham said the theft of the laptop was "less shocking" than the council's security breaches.

But he said it "also warranted nothing less than a monetary penalty as thousands of people's privacy was potentially compromised by the company's failure to take the simple step of encrypting the data".

He added: "These first monetary penalties send a strong message to all organisations handling personal information - get it wrong and you do substantial harm to individuals and the reputation of your business. You could also be fined up to half a million pounds."

A4e chief executive Andrew Dutton said: "We acted very swiftly after the incident in June, including making a voluntary report to the ICO. We alerted all customers, partners and relevant authorities affected and continue to update them.

"This incident occurred as a result of a breach of our security procedures. It also came at a time when A4e was rolling out a new, robust, company-wide set of security controls and procedures.

"Our priority has always been, and remains, our customers and partners. We have apologised for any distress caused to those involved in this one-off incident in Hull and Leicester and we do so again."



Powered by WizardRSS | Best Membership Site Software

Iran denies nuclear virus damage

Iran has denied that the Stuxnet virus has caused any delays in its nuclear power programme.

It issued the denials following speculation from a former UN nuclear inspector that Stuxnet had managed to damage key equipment.

But Iran said it had caught Stuxnet before it managed to reach its intended target - controllers for centrifuges.

The country accused the West of trying to sabotage what it called its "peaceful" nuclear power plans.

The denial came from Iranian Vice President Ali Akbar Salehi who oversees the country's nuclear project.

"From more than a year ago, Westerners tried to implant the virus into our nuclear facilities in order to disrupt our activities but our young scientists stopped the virus at the very same spot they wanted to penetrate," he said in comments reported on an Iranian state television website.

Stuxnet is the first malicious program that targets key parts of industrial plants. Analysis by security firm Symantec suggest that Stuxnet was intended to wreck the centrifuges used to concentrate uranium - a key part of the nuclear power generation process.

Reports suggest that Iran has taken thousands of centrifuges offline in recent months and its nuclear programme is known to have suffered significant delays.

Speculation about whether this was caused by Stuxnet came earlier this week from two sources - an unnamed official from the UN's International Atomic Energy Agency and Olli Heinonen deputy director at the IAEA until August.

The anonymous official told AP that Western intelligence gathering suggested that Stuxnet had infected control systems in Iran's nuclear plants.

Mr Heinonen confirmed that Iran had experienced problems with centrifuges and said they could have been caused by technical problems or Stuxnet, but added that there was no proof that the worm was responsible.



Powered by WizardRSS | Best Membership Site Software

PC vaccine needed in botnet fight

The equivalent of a government-backed vaccination scheme is needed to clean up the huge numbers of PCs hijacked by cyber criminals, suggests research.

In Europe, about 5-10% of PCs on broadband net links were hijacked and part of a botnet in 2009, it suggests.

ISPs are key to wresting control of these machines away from criminals, says the Dutch report.

Initiatives in Germany and Australia show how official help can boost efforts to clean up infected machines.

Home invasion

The survey of botnet numbers was carried out in an attempt to understand the scale of the problem and reveal the forces influencing how many PCs on a particular network are hijacked.

Botnets are typically networks of home computers that malicious hackers have managed to hijack by tricking their owners into opening a virus-laden e-mail or visiting a booby-trapped website.

They are then commonly used to pump out spam and attack websites.

It drew up its by analysing a pool of 170 million unique IP addresses culled from a spam trap that amassed more than 109 billion junk mail messages between 2005 and 2009.

With 80-90% of all spam being routed through hijacked PCs these IP addresses were a good guide to where infected machines were located, said Professor Michel Van Eeten from the Delft University of Technology who lead the OECD-backed research.

Analysis of this huge corpus of data showed that about 50 ISPs were harbouring around half of all infected machines worldwide. Confirmation of this finding came from other non-spam sources - the 169 million IP addresses that were part of the Conficker botnet and 130 million IP addresses collected by net security watchdog SANS.

The numbers of machines on these networks varied widely, said Professor Van Eeten, but infected rates on individual networks were quite stable over time relative to each other.

What was also clear from the research, he said, was that ISPs were not going to be able to clean up the large numbers of infected machines without some kind of central aid. In Holland, ISPs have dramatically increased their efforts but are still only cleaning up about 10% of infected machines.

At the moment, he said, two bottlenecks were preventing ISPs doing more to clean up machines.

The first, he said, was the lack of comprehensive data about the numbers and location of infected machines.

An initiative by the Australian government to pool data on infections and provide it to the nation's ISPs showed how this could be overcome, said Prof Van Eeten.

"The second bottleneck is that it costs money to notify customers and get them to clean up their machine," he said.

"An incoming call is very costly especially as those kinds of calls need experts," he said. "ISPs can completely lose their profit margin on a customer like that."

South Korean and Germany had tackled this problem, he said, by setting up national call centres to which ISPs can refer infected customers where they can get advice about disinfecting their machine. The call centres are publicly funded - though Germany will only pay for its centres temporarily.

"Governments can be very helpful," he said.

Prof Van Eeten said the numbers and prevalence of botnets suggests we should perhaps see them as the modern-day equivalent of the epidemics that struck in Victorian times and prompted the creation of government-backed vaccination schemes.

A similar system delivering a digital vaccine might again be part of the solution, he said.



Powered by WizardRSS | Best Membership Site Software

Auction of codebreaker&#39;s papers

Papers published by World War II codebreaker Alan Turing are expected to fetch about �500,000 at auction later.

The Manchester University scientist, who killed himself in 1954, created a machine at Bletchley Park to crack messages in the German Enigma code.

Last year, the then prime minister Gordon Brown gave him a posthumous apology for the "appalling" treatment he received for being gay.

The documents will go under the hammer at Christie's in London later.

Turing, who has been called the "father of the computer", published only 18 papers in his short career.

He was prosecuted for having a sexual relationship with a man and two years later he committed suicide by biting into an apple which he had laced with cyanide.

He was found dead at his home in Wilmslow, Cheshire, where a plaque has been erected to pay tribute to him.

Since it was announced that the papers were going to be sold, IT journalist Gareth Halfacree has been trying to raise the cash to buy them and donate them to Bletchley Park Trust in Milton Keynes.

So far he has raised �85,000 having just received a �62,784 donation from Google.

"We are still a bit short of what we need but I still hope that Microsoft or Apple might donate at the last minute," Mr Halfacree said.

Bids for the collection, which contain his first published paper, his pioneering work on artificial intelligence and the very foundations of the digital computer, have to be submitted by 1030 GMT.

They will go under the hammer at 1400 GMT.

Mr Halfacree added: "If we do not raise enough, which is looking increasingly unlikely, I hope whoever buys it donates the papers to Bletchley Park so we can all benefit from them."

He said the money he has raised so far will still go to the trust whether it is used to buy the papers or not.



Powered by WizardRSS | Best Membership Site Software

Challenge to Twitter &#39;joke&#39; trial

A man who was convicted and fined for a Twitter message threatening to blow up an airport has said he will take his case to the High Court.

Paul Chambers was convicted in May for sending a menacing electronic communication.

A recent appeal failed to overturn the conviction, sparking outrage amongst Twitter users.

The 27-year-old accountant will now be represented by high-profile human rights lawyer Ben Emmerson.

The challenge will centre on whether or not section 127 of the Communications Act, under which he was convicted, was "appropriately applied".

Mr Chambers and his lawyers have until 2 December to challenge the conviction.

His lawyers regard Mr Chambers' conviction as a test case, as it was the first time that the Communications Act was applied to an offence on a social network.

"We want to establish what constitutes a menacing communication, what should be the level of intent required for the offence to be committed, and whether or not Paul's message was sent by means of a public electronic communications network," said David Allen Green, his solicitor.

Doncaster Crown Court recently upheld his original conviction causing a wave of outrage on Twitter, with thousands of supporters retweeting Chambers' message, which read: "Crap! Robin Hood airport is closed. You've got a week to get your shit together, otherwise I'm blowing the airport sky high!"

The so-called "I'm Spartacus" campaign was inspired by the famous scene in the 1960s blockbuster, when slaves stood up one by one to claim "I'm Spartacus" in order to save their fellow gladiator from detection.



Powered by WizardRSS | Best Membership Site Software