Friday, July 1, 2016
Worcestershire, home at 3.30am thanks to ECB fixture list, can't awaken to task
Other Sites :
Technical Guide Travel Guide
Cybersecurity forecast: Heavy smug
When you think of rockstar hackers and infosec pundits, I'm sure it's easy to imagine people who are humble, kind and patient, and never look down on anyone who would reuse a password.
Okay, maybe infosec isn't known for doing benevolence all that well when they need to communicate with those not in the know about computer security. And when they do, they seem to prefer to do it from a stage and safely behind the title of "expert." Case in point: the much-ballyhooed talk being given at the Aspen Ideas Festival, where professor at Rochester Institute of Technology Josephine Wolff is making a case today for punishing people when they're not good at computer security.
For "Who Should Safeguard Our Data" Professor Wolff seems to think the sheep need to be taught a lesson. Specifically, she's proposing to the elite thought leaders gathered at Aspen that the careless should be punished for getting hacked or for being in the vulnerability chain, even if unknowingly.
The underlying reason for swapping out the carrot for the stick is that, according to Wolff, the only way to get Internet users to take things seriously is to make them pay. Specifically, to create "concrete penalties and consequences" for what she calls our "liability" and "complicity" in "participating in bots, falling for phishing attacks, failing to install security updates, and other basics of computer hygiene."
She explains more in a little pre-Aspen piece called Should the Careless Be Punished for Getting Hacked? that was framed with the subhead, "A computer security expert grapples with how to better protect us from cyberattacks."
In a tone that's not at all reproachful, Wolff suggests that botnet and ransomware victims, or those who click "links and attachments in those phishing emails and carelessly surrender their login credentials or the contents of their hard drives" might be well-meaning. Yet these witless yet earnest idiots, I mean, us, "play an enormous and devastating role in many (perhaps most) of the major cybersecurity incidents that occur today."
Like, maybe instead of presenting Aspen attendees like Secretary of State John Kerry, Vice President Joe Biden, and Mitt Romney with bad ideas for computer security policy, we could instead present the powerful upper crusts with innovations around teaching basic security practices to the greater public. Or we could talk about influencing enterprise decision-makers to allocate big budgets into security-savvy employee trainings.
Better yet, we could press the bigwigs at Aspen to push for digital privacy and security lessons in public schools. Because maybe, just maybe, it might be the jobs of computer security "experts" to make users smarter and safer, and places of heavy influence like Aspen might be a place for crazy ideas such as this. Rather than more of the smarter-than-you, smug, and dangerously reductive mentality that's alienating hackers and infosec from the very people they're supposed to be helping in the first place.
Unless it's easier to adopt an us-versus-them mentality, and then throwing a user screwed by unknowingly becoming part of a botnet in jail becomes a pretty attractive way of waging someone's perverse infosec class war. Wolff was clear to make a distinction between those who are targeted by "sophisticated" attackers, and everyone else whose mistakes earn her description of "stupid." Because enforcement is challenging, she extrapolates, in her apparent class system of hacking victim crime and punishment. She's not doing the growing perception of hackers, computer security "experts" and infosec academics as smug jerks any favors.
Don't worry, Professor Wolff finds this all as distasteful as we do. "All of these are questions worthy of greater discussion and debate––as unpalatable as it may seem, at first glance, to contemplate the possibility of individual liability for unintentional complicity in computer crimes."
Knowing the infosec "expert" juggernaut and how it rolls along, I'm sure there will be a good number of people who agree with the professor. There are definitely a lot of hackers and infosec personalities who might think punishment would be better than doing the work of figuring out how to actually help people who don't know the first thing about security. I mean, when someone's calling you an expert and giving you a sliver of fame or notoriety, it's far easier to fall into lockstep with Wolff as she characterizes commoner, I mean users, as liable for being complicit with their "poor computer hygiene" and "stupid mistakes."
Maybe I'm being harsh. But let's not forget that for every Wolff, there's a Facebook CEO, a Google CEO, and a Spotify CEO who make "stupid" mistakes and practice "poor computer hygiene" by reusing passwords, and got hacked. One has to wonder where these rich and powerful men would end up in Wolff's world, though I doubt it would be the same as everyone else.
And that's the problem here, isn't it? Everyone's getting hacked, and everyone's security is critical. So it's more urgent than ever to fight bullshit like Professor Wolff's, because our security is just as important and equally as vulnerable to the same things as the richest and most powerful people in the world.
And you shouldn't be punished for not being a security professional, especially by so-called "experts" who talk about pastoral responsibility while completely missing the point about who they're supposed to be protecting.
Other Sites :
Technical Guide | Travel Guide | Videos
UN rights council condemns the disruption of internet access
The United Nations Human Rights Council has had enough of state-sponsored attempts to restrict internet access and punish people who use the internet as a space for free expression. The council on Friday passed a resolution that reaffirms and expands its previous stances upholding internet rights across the globe, noting, "The same rights that people have offline must also be protected online, in particular freedom of expression." Today's resolution is non-binding, but it can be used as support in future cases of online human-rights violations.
The resolution condemns violations including torture, extrajudicial killings, enforced disappearances, arbitrary detention and gender-based violence enacted against anyone expressing themselves on the internet. Additionally, the HRC "condemns unequivocally" any attempt to intentionally restrict access to information online and calls on all nations to halt such practices.
Recently, Vietnam was caught blocking internet access amid political protests and during Obama's visit to the country. Other governments, including those of Russia, China and Turkey, have restricted the internet during times of political unrest or in an effort to block "scandalous" content. Turkey signed its name to today's resolution.
This is the HRC's third online-rights resolution since 2012 and the first to include language about blocking internet access, The Hill reports. The resolution also notes that online privacy is essential to realizing the right to freedom of expression, and it recognizes the need to remove disparities in internet access between women and men. Particularly, it stresses "the importance of empowering all women and girls by enhancing their access to information and communications technology," promoting their digital literacy, and encouraging them to pursue careers in IT fields.
Good news today: @UN Human Rights Council affirms online rights, condemns internet disruption and shutdowns. #HRC32 http://pic.twitter.com/nuxvJxOJx8
— Edward Snowden (@Snowden) July 1, 2016
Via: The Hill
Source: The Hill upload
Other Sites :
Technical Guide | Travel Guide | Videos
Klinger century crushes sub-par Somerset
Other Sites :
Technical Guide Travel Guide
Apple says Spotify wants 'preferential treatment' for iOS app
It didn't take long for Apple to respond to Spotify's claim that it's using App Store approvals a way to handle competitors. In a letter obtained by BuzzFeed, Apple general counsel Bruce Sewell described the allegation as "troubling" and that Spotify was "asking for exemptions to the rules we apply to all developers." Sewell went on to say that the streaming service was "publicly resorting to rumors and half-truths about our service" with its statements about App Store policies being designed to squash competition.
Reports surfaced yesterday that Spotify's counsel Horacio Gutierrez sent a letter to Apple last week to let the company know what it thought about a pending app update being held up. The streaming service is taking issue with the App Store's 30 percent fee for use of its billing system for subscriptions that applies to all developers. In other words, if users sign up through Spotify's iOS app, they're charged $13 a month instead of the usual $10 to cover the fee. Sewell explained that Apple treats all app devs the same across games, e-books and both video and music streaming, and more specifically that those terms didn't change when Apple Music launched and Spotify became a direct competitor.
"Ironically, it is now Spotify that wants things to be different by asking for preferential treatment from Apple," Sewell said. He went on to reiterate that nothing about how the system is set up violates antitrust laws like Gutierrez argued in his own letter last week. What's more, the Spotify app that's currently available in the App Store actually violates the company's guidelines.
"I would be happy to facilitate an expeditious review and approval of your app as soon as you provide us with something that is compliant with the App Store's rules," Sewell said.
Neither Apple nor Spotify responded to Engadget's request for comments on the matter.
Via: The Verge
Source: BuzzFeed
Other Sites :
Technical Guide | Travel Guide | Videos