Tuesday, August 30, 2011










Wikileaks: MPAA ‘Secret Pusher’ of BitTorrent Trial Against Aussie ISP

 

AFACT wants to hold iiNet responsible for the copyright infringing activities of their users, but they have been unsuccessful thus far.
Interestingly enough, a Wikileaks cable that was just released reveals that the MPAA (thus the American movie studios) are a main facilitator of the legal action.
“The case was filed by the Australian Federation Against Copyright Theft (AFACT) on behalf of the Motion Picture Association of America (MPAA) and its international affiliate, the Motion Picture Association (MPA), but does not want that fact to be broadcasted,” the summary of the diplomatic cable reads (emphasis added).
“Despite the lead role of AFACT and the inclusion of Australian companies Village Roadshow and the Seven Network, this is an MPAA/American studios production,” then-US Ambassador Robert McCallum writes.
So there we have it.
The landmark case wasn’t really about protecting the interests of Aussie filmmakers.
That was just a side-effect.
The revenues of American companies was what really started this case. But that was supposed to be a secret….






o
Share/Bookmark









Life After Anonymous – Interview with a Former Hacker

 

The hacker group Anonymous has been in the news recently for a variety of reasons, including WikiLeaks, the HBGary breach, and other things. One recent item was a relatively high-profile defection from the organization, the departure of SparkyBlaze for a variety of reasons, including being “fed up with anon putting people’s data online and then claiming to be the big heroes.”
I run the @CiscoSecurity Twitter feed, so I spend a lot of time on Twitter, and saw that @SparkyBlaze was an active user, so I pinged him with a DM in an effort to get his side of the story. I also wanted to get a glimpse into things on the other side – it is probably in the best interest of everyone in the security industry to have a better understanding of Anonymous and others in the underground hacker community. While the human factors were of some interest, I was also really curious about his take on the state of corporate security and wanted to see what he had in the way of concrete recommendations for organizations wanting to prevent breaches and break-ins.
Some might ask, are we giving an illegal hacker a platform? I would say, no. Sparky himself says it very clearly: “Stay away from black hat hacking. White hat hacking is a lot more fun, you get paid for it, it is legal. A conviction for hacking and leaking a database will affect you for the rest of your life.”
Beyond the handle @SparkyBlaze and a Hushmail address, we know little about him, and beyond what we have below, he wasn’t talking. That said, here’s the interview:
JL: Can you tell us a little bit about your background?
SparkyBlaze: Well, I am from Manchester. I went through school not caring… my teachers always said I knew the stuff but I couldn’t be bothered to do anything. They were right, as nothing interested me. I am only hard-working if I am passionate about something, like computers. I went through my childhood bored as hell till I found computers. I love things like Defcon and hacker conferences and talking to other hackers. I love managing servers (and making sure they are secure).
I am white, in my 20′s and planning on moving to America to study computing and ethical hacking (I think it is best if they don’t know about me and anon ;D). I plan to live there as I have always wanted to. I love guns also, but it is mostly illegal in Britain and there are no ranges to shoot on.
JL: How did you get into computers and security?
SparkyBlaze: I got into computers as I grew up around them. I like physical security and just applied my interest to computers. Then I started to learn about firewalls and exploits… things like that.
JL: And how did you get hooked up with Anonymous?
SparkyBlaze: Well I got into Anonymous like most people there. I love hacking and I believe in things such as  free speech. I came across a page on Anonymous and was interested in them so I just started hanging out in IRC with them and it went from there.
JL: What are your thoughts on hacktivism?
SparkyBlaze: Hacktivism is an interesting subject. I love hacking and I believe in free speech and anti-censorship, so putting both together was easy for me. I feel that it is ok if you are attacking the governments. Getting files and giving them to WikiLeaks, that sort of thing, that does hurt governments. But putting user names and passwords on a pastebin doesn’t [impact governments], and posting the info of the people you fight for is just wrong.
JL: How do you think the rest of the world views hackers?
SparkyBlaze: Hackers and computer savvy people are just frowned upon. Hackers are the big, bad wolf and computer savvy people need to “get out of there basement.” Most people don’t know what hacking is, they use the same passwords everywhere and don’t use antivirus/firewalls. For them it’s an “out of the box” Windows install with IE7. This is the issue with people nowadays; they don’t understand the importance of computers and computer security.
JL: What is your take on the current status of the security industry?
SparkyBlaze: Information security is a mess, like I have just mentioned. Companies don’t want to spend the time/money on computer security because they don’t think it matters. They don’t encrypt the data nor do they get the right software, hardware and people required to stay secure. They don’t train their staff not to open attachments from people they don’t know. The problem isn’t the software/hardware being used… it is the people using it. You need to teach these companies why they need a good information security policy.
JL: What are some of the biggest challenges you see out there?
SparkyBlaze: In my mind social engineering is the biggest issue today. We have the software/hardware to defend buffer overflows, malware, DDoS and code execution. But what good is that if you can get someone to give you their password or turn off the firewall because you say you are Greg from computer maintenance just doing testing. It all comes down to lies, everyone does it and some people get good at it.
JL: So what sort of advice would you give enterprises and other organizations out there as they grapple with security-related issues?
SparkyBlaze: Here’s the advice I would give to companies:
Deploy defense-in-depth
Use a strict information security policy
Have regular audits of your security by an outside firm
Use IDS or IPS
Teach your staff about information security
Teach your staff about social engineering
Keep your software and hardware up to date
Watch security sites for news on computer security and learn what the new attacks are
Let your sysadmins go to defcon ;D
Get good sysadmins who understand security
Encrypt your data (something like AES-256)
Use spam filters
Keep an eye on what information you are letting out into the public domain
Use good physical security. What good is all the [security] software if someone could just walk in and take [your “secure” systems]?
JL: What kind of advice would you have for young folks who are interested in working in security?
SparkyBlaze: Stay away from black hat hacking. White hat hacking is a lot more fun, you get paid for it, it is legal. A conviction for hacking and leaking a database will affect you for the rest of your life.
For example:  You go for a job and it is down to you and someone else. You both have the same qualifications and are good at what you do. They do a background check on both of you… his is clean, yours says you hacked a server and put all the data online… Who will they give the job? It won’t be you.

    

 

 

 

 

o
Share/Bookmark









Putin arrives at biker event to strains of Night Wolves anthem




A biker show hosted by the Night Wolves motorcycle club was held on the waterfront in Novorossiysk on August 29. A stage was set up especially for the occasion on the Mikhail Kutuzov, the USSR's largest cruiser, which was moored at the waterfront. Prime Minister Vladimir Putin thanked participants from the stage for their patriotism.










o
Share/Bookmark









Offender breaks curfew after security staff tag his false leg

 

Two members of staff at a private security firm have been sacked after an electronic tag was put on an offender's false leg. 

 

Christopher Lowcock, 29, wrapped his prosthetic limb in a bandage and fooled G4S staff who failed to carry out the proper tests when they set up the tag and monitoring equipment at his Rochdale home.
Lowcock could then simply remove his leg - and the tag - whenever he wanted to breach his court-imposed curfew for driving and drug offenses, as well as possession of an offensive weapon.
A second G4S officer who went to check the monitoring equipment also failed to carry out the proper test.
Managers became suspicious last month, but when they returned to the address a third time Lowcock had already been arrested and was back in custody accused of driving while banned and without insurance.
A G4S spokeswoman said: ''G4S tags 70,000 subjects a year on behalf of the Ministry of Justice.
''Given the critical nature of this service we have very strict procedures in place which all of our staff must follow.
''In this individual's case two employees failed to adhere to the correct procedures when installing the tag. Had they done so, they would have identified his prosthetic leg.
''Failure to follow procedure is a serious disciplinary offence, and the two employees responsible for the installation of the tag have now been dismissed.''
A Ministry of Justice spokesman added: ''We expect the highest level of professionalism from all our contractors, and there are strict guidelines which must be followed when tagging offenders.
''Procedures were clearly not followed in this case and G4S have taken action against the staff involved.
''Two thousand offenders are tagged every week and incidents like this are very rare.''
As well as the electronic tagging of offenders, G4S also runs private prisons including Altcourse, in Liverpool; Parc, in Bridgend, south Wales; Rye Hill, in Willoughby, near Rugby; and Wolds, in Brough, East Yorkshire.
It will also run Birmingham Prison when it becomes the first to be transferred from the public to private sector in October. 






o
Share/Bookmark









Abramovich wants the most expensive house in the world

Billionaire Abramovich is said to have the 
French Villa Leopolda in Sight


Only recently did Roman Abramovich with his new luxury Boat listen attentively. With the "Eclipse", with its 162.5 meters, the Russian billionaire has finally gained the longest yacht in the world.
Accustomed to the luxury Chelsea FC Owner is the largest yacht in the world is not enough. Now ask him to the ruins of the world's most expensive, the Villa Leopolda on the French Riviera, Bild.de reported on Tuesday.

Abramovich hungry for a "bloody Villa"

The roughly 2,700 m² of comprehensive Villa Leopolda with its 19 bedrooms, a swimming pool, an avenue of cypresses, olive groves and an eight-acre park and a fsmystery, their history stretches almost a trail of blood.
The villa was built in 1900 by the Belgian King Leopold II as a gift to his wife. He founded the Congo Free State in Africa. Under him, the natives living there were abused not only heavy but also systematically exploited and murdered. Thousands left in the wake of the so-called Congo atrocities their lives.
In the 50 years was the "lock" into the possession of Giovanni Agnelli, who later resold it to finally Edmond Jacob Safra. Safra, a banker who eventually died an excruciating as mysterious as fire- Death, which still provides for speculation.
Abramovich seems the secretive history of the Villa Leopolda however, not interested. Who has the biggest yacht in the world comes to the most expensive villa in the world hardly seems over.






o
Share/Bookmark









China's Huang Nubo seeks Iceland land for eco-resort

The area is close to Iceland's 
Vatnajokull National Park


A Chinese business tycoon is hoping to buy a large area of north-east Iceland to build a luxury hotel and eco-resort.


Huang Nubo is reported to have offered a billion krona (£5.4m: $8.8m) for the 300sq km (155 sq mile) Grimsstadir a Fjollum region.
Critics of the plan fear it could be used by China to gain a strategic foothold in Iceland.
But Icelandic officials have welcomed the purchase and the further 20bn krona Mr Huang says he intends to invest.
Mr Huang is the chairman of the Zhongkun investment group, and is also reported to have worked as a minister in the Chinese Central Propaganda Department and Ministry of Construction.

Iceland's Foreign Ministry said Mr Huang's plans involved linking up the Vatnajokull and and Jokulsargljufur national parks, in line with his company's "emphasis on nature conservation and environmental tourism".
Mr Huang had promised to co-operate fully with the Icelandic authorities, said the ministry, and to renounce any claims to water from the Jokulsa a Fjollum river which crosses the property.
Iceland's once booming economy suffered a dramatic crash in 2008 with three of its major banks collapsing and is in urgent need of growth and foreign investment.
'Tread carefully'
While the purchase has been approved by the local landlords, officials said Mr Huang had yet to apply for an exemption from laws barring non-EU nationals from buying land.
Some in Iceland have raised concerns about the long term implications of Icelandic territory entering foreign hands, and that the land could give China future access to deep sea ports in the area.



 
"We face the fact that a foreign tycoon wants to buy 300sq km of Icelandic land. This has to be discussed and not swallowed without chewing," Interior Minister Ogmundur Jonasson wrote on his website.
He said China was known for its "long term thinking alongside buying up the world" and warned against Iceland accepting the purchase without full consideration.
Mr Jonasson said Iceland needed to learn its lesson from the banking crisis and listen to those people cautioning against accepting any investment offered.
"Isn't it necessary to pause and think when we offer Iceland up for sale again?"
However, Iceland's Minister for Industry, Katrin Juliusdottir, told reporters it was clear the country had to "tread carefully".
But she said there was "no reason to get hysterical just because one Chinese man wants to buy some land and invest in tourism in Iceland".
"Foreigners already own quite a bit of land here and I don't think there is anything to fear from that."






o
Share/Bookmark

Monday, August 29, 2011










WikiLeaks cables detail Apple's battle with counterfeits in China

 
Apple operates four stores in China, which is becoming an important market for Apple but also a haven for counterfeit goods.

(CNN) -- Apple was slow to act against the booming counterfeit industry in China and other Asian countries, according to cables obtained by WikiLeaks.
The technology giant eventually organized a team in March 2008 to curtail the explosion of knockoff iPods and iPhones, according to an electronic memo from the Beijing embassy dated September 2008.
Yet, three years after Apple moved to crack down on widespread counterfeiting and put pressure on China, progress has been slow. Gadget piracy isn't a high priority for the Chinese government, the U.S. reports and experts say.
Members of Apple's recently formed global security team were recruited from Pfizer after they executed a series of crackdowns on counterfeit Viagra production in Asia, the report says.
John Theriault, formerly Pfizer's security chief and, before that, a special agent for the Federal Bureau of Investigation, leads Apple's global security unit. Don Shruhan, who worked for Therigult at Pfizer, is now a director on Apple's security team in Hong Kong.
Shruhan told the Beijing embassy official that his group at Pfizer spent five years planning raids on counterfeit drug rings, the cable says. He said he's "afraid" of the volume of imitation Apple products being produced in China and about the inexperience of Apple's lawyers in dealing with Chinese authorities, the report says.
An Apple spokeswoman declined to comment. A Pfizer spokeswoman, who declined to comment on personnel matters, said the company has a strong global security team to handle the increase in counterfeit medicine worldwide.
WikiLeaks, a group that publishes private government documents, posted tens of thousands of previously unreleased U.S. diplomatic cables last week. The reports from the Beijing embassy detailing Apple's piracy crackdown were unclassified, but many were described as "sensitive" and "not for Internet distribution."
In December, Apple said it removed an application from its mobile store that let people browse WikiLeaks documents from their iPhones "because it violated developer guidelines." The company suggested that the app broke laws or could be harmful to people, but many free-speech advocates cried censorship, as they have in the past when Apple has pulled apps.
The fresh WikiLeaks documents shed new light on Apple's struggles with intellectual-property theft in China, but the subject hasn't completely flown under the radar.
Last month, international news media were rapt after discovering that China is home not only to fake Apple gadgets but also to imitation Apple stores, which had many of Apple's signatures. The Chinese government ordered two of the five unofficial stores to close because they had not secured proper business permits, but a spokesman for China's Kunming government defended the others, saying they sell authentic Apple merchandise, according to Reuters.
Apple owns and operates four stores in China. The three in Beijing and the one in Shanghai are Apple's highest trafficked and top grossing stores in the world, Peter Oppenheimer, Apple's financial chief, said in an earnings call in January.
But the hunger for Apple products is insatiable there. That's why stores have begun to sell the products without Apple's permission, while others are hawking cheaper, lower-quality gadgets that are aesthetically similar and bear the chic Apple logo.
China's Guangdong province, the country's most populous region, has become a hub for manufacturing and selling counterfeit Apple products, two of the newly surfaced cables say. The Foxconn Technology Group, which assembles products for Apple, operates factories in Guangdong.
Workers typically smuggle parts from the facilities in order to make replicas, said Lilach Nachum, an international business professor for Baruch College in New York who travels frequently to Asia. It's the cost of doing business in China, where many American companies go for inexpensive labor and efficient industrial plants, she said.
"Not to go to China is not really an option," Nachum said. "Companies cannot afford to do that. No one can afford to do that."
China's counterfeiting ring is responsible for supplying India with fake Apple products, the 2008 cable says. In raids, Indian officials uncovered shipments that had moved from China through Hong Kong, the report says.
Apple's early plans to go after counterfeiters, according to a cable, involved first targeting offending retailers and street vendors; next, Apple would work with police to raid manufacturing facilities; and finally, the company would pursue online resellers. The plans closely resemble Pfizer's successful strategy, the cable says, citing Shruhan, the Apple director.
"Shruhan said that low-profile retail raids are a good option for Apple, a company that wants to stay away from too much publicity surrounding this issue," the cable says. Theriault, Shruhan's boss, briefed Steve Jobs, then CEO, on the plans in 2008, the cable says.
But Apple is having limited success. In countless stores and at tables setup on streets, merchants purporting to sell iPods, iPhones and iPads at deeply discounted prices are prevalent, said Wini Chen, a student in San Francisco who recently returned from studying abroad in Beijing.
"They'll say, 'Yeah, we have iPad. We'll give you a really good deal,'" Chen recalled from her shopping trips. "If I really want to buy a knockoff Apple product, I could probably do that in 15 minutes."
Chinese officials readily cooperated with pharmaceutical companies on their raids, but that hasn't translated to software, as Microsoft has discovered, or electronics, as Apple is learning, said Nachum, the professor. Whereas a defective pill could cause sickness or death, a shoddy iPod has less dire consequences.
Apple had planned to strengthen its case with the government by arguing that defective batteries could blow up and injure people, and that lost tax revenue could have a significant economic impact, the cable says.
The arguments weren't very effective. China's government declined to investigate a facility in March 2009 that was manufacturing imitation Apple laptops because it threatened local jobs, says a cable dated April 2009. A different arm of China's government scrapped plans for a raid on an electronics mall in the Guangdong province because it could have driven away shoppers, the cable says.






o
Share/Bookmark