Archive for August, 2011

The Team High Tech Crime of The National Crime Squad in The Netherlands has hacked into TOR servers. Also gained root access to servers that hosted child abuse sites, gaining admin rights. In some cases the enforcement officials decided to delete questionable material.

The 220,000 pieces of content are only 5 years old and will be disseminated to enforcement authorities all around the globe.

Dutch language news article:
(UPDATED LINK)
http://nos.nl/artikel/268834-politie-kraakt-kinderpornonetwerk-robert-m.html

Robert Mikelsons sexually abused at least 87 children while being employed at two Amsterdam nurseries between February 2007 and January 2010. He also offered his services through several websites
http://www.imperfectparent.com/topics/2011/06/18/dutch-prosecutors-unable-to-outlaw-pedophile-club/ 

http://www.ispreview.co.uk/story/2011/08/31/over-19-million-households-in-the-uk-now-have-an-internet-connection.html

We hate to say it, but this may be one of those times when technology is straight-up ruining something.

http://www.wired.com/underwire/2011/08/cellphone-movie-spoilers/

Hollywood Leaks has been quietly breaking into entertainment industry insiders’ email accounts for the last few weeks and leaking what they find there.

They cracked the email account of an actor in the upcoming Tom Cruise musical, Rock of Ages and were surprised to find that the film’s director, Peter Shankman, had sent the script around to his cast via email. They downloaded it, then put it on the Pirate Bay.

They’ve posted the cell phone numbers of about a dozen celebrities to the hacker-friendly document sharing site Pastebin.com, including Miley Cyrus, Lil Jon, and Ashley Greene.

I called N’Sync’s Joey Fatone last Friday and got his voicemail.

Hollywood Leaks say they’re an offshoot of the hacktivist collective Anonymous, even appropriating their tag line “We never forgive, We Never forget.” Like Anonymous, they’re a loose-knit band of internet troublemakers—probably no more than five or six core members—who organize in raucous chat rooms and promote their hacks on their Twitter account.

But where Anonymous is super seriously concerned with world politics and the Church of Scientology, Hollywood Leaks just wants to make celebs sweat.

More:
http://gawker.com/5835611/meet-the-hollywood-hackers-coming-for-your-nude-pics

http://news.cnet.com/8301-13506_3-20099694-17/android-nabs-41-percent-share-in-u.s-study-finds/

http://news.cnet.com/8301-17938_105-20099466-1/panasonic-wants-everyone-to-capture-3d-video/

http://www.fireeye.com/resources/pdfs/FireEye_Advanced_Threat_Report_1H2011.pdf

https://plus.google.com/105636695715347097518/posts/G9hbCEMC2wF

http://www.theregister.co.uk/2011/08/31/darpa_imagery_analysis_ware/

Dutch language article:
http://webwereld.nl/nieuws/107767/java-vader-verlaat-google-na-5-maanden.html

See also:
http://nighthacks.com/roller/jag/entry/i_ve_moved_again 

http://sunbeltblog.blogspot.com/2011/08/northumbria-police-authority-website.html

http://www.reghardware.com/2011/08/31/apple_ejects_financial_times_app_from_itunes/

Dutch parliament wondering how on earth the authorities could have moved so quickly and why exactly the case was closed

Dutch language news article:
http://www.nu.nl/internet/2603111/kamervragen-sluiten-onderzoek-dpi.html

http://www.wired.com/threatlevel/2011/08/absolute-sued-for-spying/

http://gizmodo.com/5835850/every-airline-should-board-passengers-like-this-it-cuts-boarding-time-in-half

Those companies include Boeing’s own Narus, which reportedly looked into adding their own internet filtering products to Libya’s established monitoring operation, and Amesys, a French security company that provided Libya with Deep Packet Inspection software back in 2009, and intercepted messages from Hotmail, Yahoo, Gmail, MSN Messenger, and AIM.

http://gizmodo.com/5835940/international-tech-companies-helped-gaddafi-spy-on-libyans

http://gizmodo.com/5835990/this-usb-drive-is-thinner-than-a-penny-and-holds-2tb

IT departments want to control who has access to what data and for how long – this is, in fact, a big part of the job description – and with end users increasingly hot-dogging cloud-based file and data sharing services, VMware thinks it is time to rein them in.

“This is a big inconvenience for us all,” explained Herrod in his keynote address on Tuesday, referring to file sharing, “and it is a big security headache for IT.”

http://www.theregister.co.uk/2011/08/30/vmware_octopus_appblast_preview/

Dutch language news article:
http://www.security.nl/artikel/38303/1/Apple-hacker_stopt_jailbreaken_wegens_stage.html

Certificates in use by specific public (tax and financial) services

Dutch language news article:
http://tweakers.net/nieuws/76475/firefox-vertrouwt-digid-toch-na-verzoek-nederlandse-overheid.html

Dutch language news articles:
http://www.security.nl/artikel/38301/1/Google_verwijdert_DigiNotar_uit_Chrome.html

and
http://www.security.nl/artikel/38302/1/247_certificaten_bij_DigiNotar-hack_aangemaakt.html

Dutch language article:
http://webwereld.nl/nieuws/107764/diginotar–mogelijk-nog-valse-certificaten-in-omloop-.html

The Melt

http://www.wired.com/video/latest-videos/latest/1815816633/flip-video-founder-takes-a-stab-at-hightech-cheese-sandwiches/1136070209001

A schoolboy sent to trial for sharing movies on two BitTorrent sites has been acquitted by a court. The 15-year-old, who said he only ever intended to download and not distribute, was cleared of all charges following a hearing.

http://torrentfreak.com/court-acquits-15-year-old-schoolboy-file-sharer-110830/

Quotes:

Our work makes three primary contributions. First, this is the largest and most detailed measurement study to date of the file hosting ecosystem, with focus on five popular hosting services, as observed from a large edge network.

Second, we use detailed HTTP transaction logs that allowed us to study how the clients identify and select the content they download. For example, we identified signatures for user clickstreams  in the transaction logs to separate free and premium user instances. This has not been previously characterized, and provides a deeper understanding of the usage of these services, as well as the dynamics of new-age content sharing and distribution.

Third, we compare and contrast these services with each other as well as with P2P file sharing and video sharing services. Our results have implications on caching, network management, content placement, and data centre provisioning, and are likely to be relevant for both network administrators and researchers.

Our study concentrates on the top five file hosting services (generating over 60% of the file hosting traffic volume) in the campus network: RapidShare, Megaupload, zSHARE, MediaFire, and Hotfile. Table 5 presents some high level characteristics of the five services. Over 90,000 files were downloaded using the top five services. In comparison, around 150,000 downloads (61 TB of P2P traffic volume) were done using BitTorrent in the campus network. The top five services were used almost every day of the year.

The file hosting ecosystem appears to be flourishing. There are hundreds of file hosting services at the disposal of users, which gives them enough choice to select a service of their liking. Our results indicate that there are a significant number of premium users, suggesting that the economic model based on advertisement and subscription revenue is sustainable.

One of the drivers of file hosting service growth is the incentive schemes instituted by the services to attract content publishers. As more content is uploaded, it causes more consumers to download the content, which in turn increases traffic. These incentive schemes have become controversial lately.

Full study:
http://www.nicta.com.au/pub?doc=4771

This is the authors’ version of a work that has been accepted for publication in IFIP Performance 2011 conference to be held in Amsterdam from 18 October 2011 until 20 October 2011. The final version will appear in a special issue of the Performance Evaluation journal (Elsevier). Changes resulting from the publishing process, such as editing, corrections, structural formatting, and other quality control mechanisms may not be reflected in this document. Changes may have been made to this work since it was submitted for publication.

http://www.ispreview.co.uk/story/2011/08/30/plusnet-study-claims-brits-love-wifi-and-spend-10-hours-a-day-on-the-internet.html

http://www.futureofcopyright.com/home/blog-post/2011/08/30/belgian-tv-stations-disagree-over-football-broadcasting-rights.html

http://www.futureofcopyright.com/home/blog-post/2011/08/30/parliamentary-questions-raised-about-dominant-position-bumastemra.html

F-Secure also comments on VASCO/DigiNotar press release

http://www.f-secure.com/weblog/archives/00002228.html

At that time, an external security audit concluded that all fraudulently issued certificates were revoked. Recently, it was discovered that at least one fraudulent certificate had not been revoked at the time.  After being notified by Dutch government organization Govcert, DigiNotar took immediate action and revoked the fraudulent certificate.

The attack was targeted solely at DigiNotar’s Certificate Authority infrastructure for issuing SSL and EVSSL certificates. No other certificate types were issued or compromised. DigiNotar stresses the fact that the vast majority of its business, including his Dutch government business (PKIOverheid) was completely unaffected by the attack.

More:
http://vasco.com/company/press_room/news_archive/2011/news_diginotar_reports_security_incident.aspx

http://www.theregister.co.uk/2011/08/30/wikileaks_leak_row/

http://www.reghardware.com/2011/08/30/elgato_to_equip_ipad_2_with_tv_tuner/

http://www.techdirt.com/articles/20110829/13225415732/doj-this-case-has-nothing-to-do-with-puerto-80-now-here-is-why-puerto-80-is-guilty.shtml

http://arstechnica.com/apple/news/2011/08/itunes-match-developer-beta-reveals-icloud-based-streaming.ars

Called edns-client-subnet in technical circles, or more ambitiously the “Global Internet Speedup,” it uses geographic information associated with IP addresses to help computers fetching data get it from the closest–and therefore fastest–server.

http://news.cnet.com/8301-30685_3-20098994-264/google-opendns-add-geo-speed-boost-to-net/