Friday, December 16, 2005

Software Thief Admits To Crimes

Nathan Peterson took on some of the world's largest computer software companies, and for a while, he won.

Thursday, December 08, 2005

One-quarter of Internet users targeted in phishing scams monthly

About one in four Internet users are hit with e-mail scams every month that try to lure sensitive personal information from unsuspecting consumers, a study says.

Sunday, December 04, 2005

IM worms up again in November

The number of worms that targeted instant-messaging services hit 62 in November, up 226 percent from October and hitting a new record, Akonix Systems said Tuesday. Of the worms, 58 were variants of previous pests, and four were new. In the same month, a total of 14 attacks hit peer-to-peer networks, such as Kazaa and eDonkey, according to Akonix, which sells security software and appliances.

ISPs may not carry int’l calls over VoIP

The Ministry of Communications has instructed Internet service providers (ISPs) to ensure that their systems do not carry international calls over VoIP, which bypass Israel’s authorized international calls carriers. The ministry sent the instruction following complaints.

EU expects a rush for .eu domain name

The European Union expects a surge of applications next week when its ``.eu'' regional domain name opens for registration.

Monday, November 28, 2005

Patients fear safety risk from electronic notes

Health campaigners fear that the switch from paper to electronic patient records will put patient confidentiality at risk, researchers said today.

EU committee backs telecoms data storage rule

A European Union committee agreed that details of all EU-wide phone calls and Internet use should be stored, but the steps did not go as far as some member states had wanted in the battle against terrorism and crime.

UN on electronic communications in contracting

25 November 2005 – Updating international trade law to take account of new technologies, the United Nations General Assembly has adopted a new convention on using electronic communications in international contracting, superseding law negotiated before the development of e-mail and the Internet.

Wednesday, November 16, 2005

A Qualified 'Non' to Snooping of P2P IP Addresses

On October 24, the French data protection authority, the Commission Nationale de I'Informatique et Libertes (CNIL), dealt a blow to music industry enforcement efforts against peer-to-peer (P2P) file-sharing by announcing that it would not permit the automated monitoring of users of P2P file sharing systems. The CNIL concluded such monitoring could lead to "a massive collection of personal data" and allow "exhaustive and continuous surveillance" of P2P sites "beyond that which was necessary for the fight against piracy". The CNIL's stance runs counter to its own ruling in April authorizing similar P2P site surveillance by the Syndicat des Editeurs de Logiciels de Loisirs (SELL), a trade association representing French video game producers, whose members include video game industry heavyweights such as Sega, Sony, and Atari. Defending its apparent volte-face, the CNIL noted that SELL had pledged to send messages to suspected P2P site users itself, rather than asking ISPs to act as third party intermediaries, and had agreed to take an anonymous approach in communicating with suspected violators. In French, we believe that's what is called "une distinction sans différence." In any event, if French Culture Minister Renaud Donnedieu de Vabres is to be believed, forthcoming consideration in the French Parliament of the implementation of the EU Copyright Directive might allow the music industry anti-piracy initiative to move forward. Consideration of the EU Copyright Directive by the French Parliament is scheduled to begin in December.

Tuesday, November 08, 2005

British teen cleared in 'e-mail bomb' case

A British teenager has been cleared of launching a denial-of-service attack against his former employer, in a ruling that delivers another blow to the U.K's Computer Misuse Act.

Study: IM threats zooming up

The number of threats targeting instant messaging has soared, according to IMlogic, which tracked a 1,500 percent increase in the past year.

Friday, October 28, 2005

A Viking Raid on EU Employee Email Monitoring?

The Norwegians have been a seafaring people at least since Viking days, and the Norwegian Society for Sea Rescue ("NSSR") is a humanitarian organization whose aim is "to save life and property at sea" (in 2004, the NSSR saved 40 people from drowning). But even an organization like NSSR is not outside the reach of the long arm of EU data protection law. In a move which will bring home to employers the risks of accessing or monitoring EU employee emails, the Norwegian Data Inspectorate has called for the NSSR to be prosecuted for breaching the country's Personal Data Act 2000, which implements the EU Data Protection Directive (although Norway is not part of the EU, it implements a substantial amount of EU legislation).
If the NSSR is prosecuted, the case will set a benchmark in determining the extent to which European employers can rely on work-related interests as grounds to access workers' electronic communications. And regardless of the outcome, the case will serve as a reminder to employers of both the precautions that need to be taken in relation to the monitoring of workers' emails and the risks of improperly doing so. Indeed, given the strict treatment of the a public service entity like the NSSR, the ramifications for for-profit corporations could be even more substantial

Steptoe & Johnson LLP. Steptoe & Johnson LLP weekly newsletter

Monday, October 24, 2005

How to Foil a Phish

What happens after phishers strike? Have a look at a midsize bank's cutting-edge incident response plan.

ID card a recipe for ID fraud

Microsoft UK National Technology Officer Jerry Fishenden has warned that the UK ID card scheme could trigger "massive identity fraud on a scale beyond anything we have seen before." Writing in today's Scotsman, Fishenden says that the security implications of storing biometrics centrally are enormous. "Unlike other forms of information such as credit card details," he says, "if core biometric details such as your fingerprints are compromised, it is not going to be possible to provide you with new ones."

Friday, October 21, 2005

Increased Organized Crime

Attacks on computer security infrastructure used to be little more than indiscriminate acts of vandalism perpetrated by hackers who desired bragging rights more than anything. But the perpetrators of attacks and their motivations have changed...read more

Wednesday, October 19, 2005

Adopt e-mail authentication

The Direct Marketing Association (DMA) will require all members to adopt authentication systems for outgoing e-mail, the group's board of directors decided today.

EFF cracks Secret Service code

EFF researchers have cracked a code which allows the US Secret Service to track information from Xerox DocuColor printers. And they believe similar codes may also feature on printers made by Canon, Epson, HP, IBM and Dell, among others

Password-based Web log-ons not sufficient

Federal regulators will require banks to strengthen security for Internet customers through authentication that goes beyond mere user names and passwords, which have become too easy for criminals to exploit.

Monday, October 17, 2005

MS, Nigeria fight e-mail scammers

Microsoft has announced an anti-fraud partnership with Nigeria, the country of origin for some of the Internet's most notorious email scams.

Is Privacy of E-Mail Messages possible?

A U.S. federal court has ruled that Interloc could intercept e-mail messages sent from Amazon.com. Never assume e-mail is safe when routed through or hosted by a third party.