Showing posts with label government. Show all posts
Showing posts with label government. Show all posts

Friday, March 2, 2012

Hackers Will Replace Terrorists as Top Threat, Says FBI

Could Anonymous be the next al-Qaeda?
FBI Director Robert Mueller warned a group of cybersecurity experts on Thursday that online attacks will replace terrorism as the most serious threat facing the U.S., according to The Associated Press.
Mueller pressed private businesses and Internet security firms to secure American digital infrastructure from rogue hackers and attacks sponsored by foreign governments.
“We are losing data, we are losing money, we are losing ideas and we are losing innovation,” Mueller said at the RSA Digital Security Conference in San Francisco. “Together we must find a way to stop the bleeding.”
Counterterrorism is still the FBI’s top priority, but the agency is working to better equip itself against online attacks. Trained cyber defense divisions are now in every FBI field office. They’re watching for all kinds of digital crimes — such as mortgage fraud, terrorist recruitment drives and Internet attacks.

Mueller isn’t the only government official making such warnings. The FCC chairman recently highlighted the threat of cyberattacks. The U.S. Senate is also debating the proper approach to combating cybercrime.
Two competing bills both call for beefing up the security of government networks and increasing the amount of cybersecurity information-sharing done between government and private businesses.
The bills differ, however, on whether or not the Department of Homeland Security should be allowed to set cybersecurity standards which private companies must meet. A bill sponsored by Sens. Joe Lieberman (I-Conn.) and Susan Collins (R-Maine), gives that power to the DHS, while the other bill, backed by Sen. John McCain (R-Ariz.) and five other Republican senators, does not.

Tuesday, February 21, 2012

Official: Anonymous May Be Able to Disable Power Grids by Next Year

Anonymous, the loosely affiliated group of “hacktivists,” have had a wide array of targets: The Boston and Oakland Police Departments, the FBI, Scotland Yard and the Greek government, just to name a few. Targets are selected because of a perceived injustice: police brutality, Internet censorship or the rich oppressing the poor.
Once perceived as a minor nuisance, Anonymous is getting some serious attention: According to the Wall Street Journal, the Director of the National Security Agency, or NSA, has cautioned that Anonymous could have the capability to knock out power in the U.S. through cyberattacks within the next one to two years.
NSA director Gen. Keith Alexander issued his warning in private government meetings, and Anonymous hasn’t yet been added to any public “threat list.” However Alexander, and other government officials, have expressed growing concern about America’s vulnerability to cyberattack. President Obama’s proposed 2013 budget, for example, considers cyberattacks to be among the “emerging threats for which the United States must be prepared,” alongside nuclear war and terrorism.

Anonymous’ attacks have typically come in the form of a “Distributed Denial of Service,” or DDoS, where a target website’s server is overloaded with fake traffic and rendered useless, but a power grid knockout is a much more complex operation. There is some doubt over whether or not Anonymous could (or would) pull off such an attack. However, Internet security experts acknowledge that cyberwarfare is a growing problem and are ramping up defenses to prevent digital catastrophe.
“The industry is engaged and stepping up widely to respond to emerging cyber threats,” an electric-industry official told The Wall Street Journal. “There is a recognition that there are groups out there like Anonymous, and we are concerned, as are other sectors.”
Other countries, such as China and Russia, are believed by some to be developing cyberwarfare plans against the U.S. alongside regular warfare if conflict ever breaks out. Plus, America’s current enemies could be interested in attacking the digital infrastructure of the U.S. as well. If Anonymous or other similar groups were “hired” by these countries or organizations, the hackers could more quickly become a threat to the U.S.
An Anonymous-affiliated blog called the NSA director’s concerns “ridiculous.”
“Why should Anonymous shut off power grid?,” said the post. “Makes no sense! They just want you to feel afraid.”

Wednesday, January 25, 2012

"We're just like YouTube," Megaupload lawyer tells Ars

Megaupload's US attorney, Ira Rothken, has a succinct description of the US government case against his client: "wrong on the facts and wrong on the law."
The week has been a busy one for Rothken, a San Francisco Internet law attorney who has previously represented sites like isoHunt and video game studios like Pandemic. When I call, he's eating crab cakes and waiting for yet another meeting to start, but he has plenty of time to attack the government's handling of the Megaupload case.
In Rothken's words, the government is acting like a "copyright extremist" by taking down one of the world's largest cloud storage services "without any notice or chance for Megaupload to be heard in a court of law." The result is both "offensive to the rights of Megaupload but also to the rights of millions of consumers worldwide" who stored personal data with the service.
The best way to look at Megaupload, he says, is through the lens of Viacom's $1 billion lawsuit against YouTube—an ongoing civil case which Viacom lost at trial. (It is being appealed.)
For instance, Viacom dug up an early e-mail from a YouTube co-founder to another co-founder saying: "Please stop putting stolen videos on the site. We’re going to have a tough time defending the fact that we’re not liable for the copyrighted material on the site because we didn’t put it up when one of the co-founders is blatantly stealing content from other sites and trying to get everyone to see it."
"Whatever allegations that they can make against Megaupload they could have made against YouTube," he says of the government. "And YouTube prevailed!" (Rothken made a similar case when he represented search engine isoHunt in 2010, saying it was just like Google.)

Under this view, Megaupload should have been served with DMCA takedown notices (the site did have a registered DMCA agent, as required by law, though not until 2009). If rightsholders believed that was insufficient, they should have conferred with Megaupload's US counsel (the company has retained US attorneys for some time before the current action). And if that wasn't satisfactory, a civil copyright infringement lawsuit should have been filed, one that would not have taken the site down first and asked questions later.
Instead, the government's willingness to pursue the case as an international racketeering charge meant "essentially only sticking up for one side of the copyright vs. technology debate." The result, Rothken says, is "terrible chilling effect it's having on Internet innovators" who feature cloud storage components to their business.
The US Department of Justice released a lengthy statement to the press detailing the charges against Megaupload, while New Zealand police publicly offered crazy details of their bid to arrest Megaupload founder Kim Dotcom (born Kim Schmitz). "Police arrived in two marked Police helicopters," said New Zealand Detective Inspector Grant Wormald at a press conference. "Despite our staff clearly identifying themselves, Mr. Dotcom retreated into the house and activated a number of electronic locking mechanisms. While Police neutralised these locks he then further barricaded himself into a safe room within the house which officers had to cut their way into. Once they gained entry into this room they found Mr Dotcom near a firearm which had the appearance of a shortened shotgun. It was definitely not as simple as knocking at the front door."

This sort of thing makes Rothken furious. Using "James Bond tactics with helicopters and weaponry, and breaking into homes over what is apparently a philosophical debate over the balance between copyright protection and the freedom to innovate, are heavy-handed tactics, are over-aggressive, and have a detrimental effect on society as a whole," he said. In addition, the raid was a reminder that bills like the Stop Online Piracy Act "ought not to ever be passed, because these tactics [the helicopters, etc.] are so offensive that if you take the shackles off of government, it may lead to more abuse, more aggression."
Rothken also suggested that the timing of the raid was suspicious; "over a two-year period, they happened to pick the one week where SOPA started going south."
I asked about specific allegations in the indictment, including the government's quotation of internal e-mails showing employees asking for and uploading copyrighted material. Rothken wouldn't address any specifics, but he did claim the government had engaged in some highly selective editing, choosing a few "bad communications" out of terabytes of seized data. It's as if one were to "judge the character of a person by the three worst things they ever did as a college student and ignored all the things they did as an adult."
For now, the case remains in New Zealand, where questions of bail and then extradition are being handled by local courts. Though the entire case could take a long while to wind its way to completion, Rothken concludes, "Megaupload believes strongly it's going to prevail."

Spin room

This is not a view that convinces either the US government or major copyright holders. Michael Fricklas, general counsel of Viacom and the man overseeing the company's litigation against YouTube, finds the Megaupload/YouTube comparison to be "quite a spin."

"The indictment shows that Kim Dotcom was deeply involved in every aspect of the site, designed the site to encourage infringement, helped specific users find pirated content and improve the piracy experience, paid uploaders who were also in it for money, and knew about lots of very specific infringement," he told me this afternoon. "Thus, even under YouTube's extreme view of the DMCA protections, the DMCA would provide no defense. Criminal and civil proceedings each have a different set of processes and outcomes, and are certainly not mutually exclusive. There are many times—such as in the case of Megaupload—where it is entirely appropriate for both types of action to take place."
A Department of Justice spokesperson told me that the government only goes after groups that show enough evidence of "willful" criminal conduct to take them beyond the realm of merely civil litigation, and that Megaupload certainly qualifies thanks to the same factors mentioned by Fricklas.
As for the timing of the arrests, the DOJ says it had nothing to do with the SOPA debate. After nearly two years of investigation involving many different countries, the indictment against Megaupload was returned by the grand jury investigating the group on January 5 of this year—almost two weeks before the big anti-SOPA protests captured the Web's attention. The arrests themselves—complete with their police helicopters and safe room in-breaking—took place shortly after New Zealand police obtained arrest warrants.
What the case may show more than anything else is the sheer disparity between the dueling worldviews involved. Was the Megaupload takedown an offensive assault on innovators who may have, on a few occasions, done something a tiny bit naughty—or was it a massive Mega-conspiracy worthy of an international police takedown?




Tuesday, January 24, 2012

Anonymous Threatens Facebook Shutdown Jan. 28[VIDEO]

  Anonymous claims on Twitter that the video is fake, and they do not plan to take down Facebook.
Anonymous is planning to target Facebook in an attack Jan. 28 — at least that’s what a video uploaded to YouTube Monday is claiming in the name of the hacker network.
And you thought a day without Wikipedia was bad.
“An online war has begun between Anonymous, the people and the government of the United States,” the video begins. “While SOPA and PIPA may be postponed from Congress, this doesn’t guarantee that our Internet rights will be upheld.”
Following the U.S. government shutdown of file-sharing site Megaupload Friday, Anonymous attacked the U.S. Department of Justice’s website, among others.
Monday’s YouTube video calls on the American people to participate in the hack by downloading Low Orbit Ion Cannon (LOIC), the tool that was successfully used to target the Department of Justice. LOIC crashes websites by sending thousands of information packets to their servers.
The video gives instructions for downloading and running the program, as well as a time — 12 a.m. on Jan. 28 — to launch the attack. No time zone, however, is distinguished.
“Would you like to become part of the greatest Internet protests and first official cyber war?,” the video asks. “Operation Global Blackout is ongoing and everyone can be a part of it.”


Facebook, of course, is one of the world’s largest websites, operating through thousands of servers located across the world. In the video, Anonymous acknowledges the difficulties of attacking such a large site.
“While it is true that Facebook has at least 60,000 servers, it is still possible to bring it down,” says the Anonymous voice. “Anonymous needs the help of the people.”
YouTube commenters have raised an important question, Why would Anonymous want to crash Facebook, after the site came out against SOPA and PIPA?
The video essentially equates the privately-owned company with the U.S. government, with no explanation for the linkage. CNET postulates that Zuckerberg took too long to voice his opposition, landing his social network a spot on the potential targets list.
We’ve heard this threat before from the global network of hactivists, who promised to shut down the site Nov. 5, 2011, over user privacy concerns. Ultimately, no attack was executed and the loosely-connected hacker network called the threat the work of peripheral members.

If the feds can shut down Megaupload, why do we need SOPA?

For more than a year, the Motion Picture Association of America and the Recording Industry Association of America have argued that existing laws were insufficient to deal with the problem of "rogue sites" hosted overseas. They've been pushing bills like the Stop Online Piracy Act (SOPA) and the PROTECT IP Act as essential weapons in the fight.
But evidently, American law enforcement didn't get the memo that they were powerless against overseas file-sharing services. The day after the Internet's historic protest of SOPA and PIPA last week, the United States government unsealed an indictment against the people behind Megaupload, one of the largest sites on the Internet. Four senior Megaupload officials were arrested in New Zealand on Thursday, and officials seized millions of dollars in assets.
As we reported Thursday, the FBI worked with authorities from New Zealand, Hong Kong, the Netherlands, Canada, Germany, the UK, and the Phillipines to catch the defendants and seize their assets. Law enforcement officials froze accounts at banks based in Singapore, Hong Kong, New Zealand, the Phillipines, and Germany. The feds also seized numerous servers, cars, pieces of artwork, televisions, and other assets. The list of seized assets in the indictment was six pages long.
So if the US government already has the power to arrest people and seize assets in places as far away as Germany, New Zealand, and the Philippines, are the new enforcement powers sought by content companies even necessary? We posed that question to two people on opposite sides of the SOPA debate. Cara Duckworth is a spokeswoman for the Recording Industry Association of America. And Julian Sanchez is a research fellow at the Cato Institute and an occasional contributor to Ars Technica.

Beyond domain seizures

Duckworth told Ars that "under the 2008 PRO IP law, the federal government has the authority to shut down US-registered sites that are overwhelmingly dedicated to piracy—sites with a .com or .org domain. So Megaupload.com falls within US jurisdiction." She argued that new laws are needed to deal with sites at domain names not under US control, such as .hk or .ru.
But Sanchez argued that the seizure of the megaupload.com domain was a fairly minor part of the government's offensive against Megaupload. "If you're really interested in shutting down an illegal enterprise that is located overseas, shutting down one domain or another is a lot less effective than getting your hands on the people and subjecting them to penalties or jail," he said.
By itself, seizing megaupload.com would have simply caused the site to move to megaupload.tv or megaupload.ru, he said. It was the government's ability to lock up Kim Dotcom and his lieutenants, and to take their servers and freeze their bank accounts, that took the site down for good.
We pressed Duckworth on this point, and she suggested that the Megaupload operation may not work as a good model for counter-piracy operations in general. "Law enforcement cooperation for US criminal investigations may not go as far in certain countries such as Russia and China where they have lax copyright laws and a huge piracy problem," she said. In addition, countries like Russia will also not extradite their citizens.
It's true that many countries won't help the US with such investigations (note that the countries involved in investigating Megaupload are all traditional US allies), but sticking your rogue site in such a country comes with its own set of problems. Sanchez pointed out that Megaupload's business model depends on hosting large volumes of user-submitted material without scrutinizing their contents. That business model is unlikely to work well in repressive regimes. For example, he said, it's true that the Iranian government would be unlikely to help the FBI take down an Iranian version of Megaupload. However, he said, "I hear there was quite a lot of pornography on Megaupload."
A similar point applies to China. "If you try to create Megaupload in China, SOPA would be the least of your worries," Sanchez said. China requires websites based inside its Great Firewall to comply with a comprehensive censorship regime. It would be difficult to comply with those rules while maintaining Megaupload's anything-goes philosophy to file hosting.
For rogue site operators, the trick is to find a country with great Internet infrastructure, weak IP enforcement, and little censorship. But finding all three is tricky, as shown by the fact that Megaupload actually leased hundreds of servers within the US to provide a good experience to US residents despite the obvious risks this posed.

Diplomatic pressure

Moreover, while relations between the US and countries like China and Russia can be frosty, Sanchez said it's not true that the US government has no leverage there. For example, in 2007, the Russian government shut down AllOfMP3, a notorious source of unauthorized copies of major-label music.
Sanchez pointed out that the Chinese government does conduct periodic crackdowns on traditional, physical piracy, often under pressure from the US. Shutting down a website like Megaupload would be a much easier job than clearing Chinese markets of merchants hawking bootleg DVDs.
"This is a familiar story," he told Ars. "The whole international intellectual property system has basically been operating on treaties, on diplomatic pressure. This is how we've been working internationally to have a stable IP system for decades. So I don't know why that suddenly doesn't work" for rogue sites.
Disclosure: I'm an adjunct scholar at the Cato Institute, an unpaid position.