Scrolling box

computer hardware

Breaking News

Social Icons

Recent Comments

Showing posts with label Social. Show all posts
Showing posts with label Social. Show all posts

Thursday, March 13, 2014

Does Twitter's Vine have a porn problem?

Perhaps it was a foregone conclusion, what with the Internet's proven ability to turn any new technology into a platform for showing naked people.
Does Twitter's Vine have a porn problem?

But Twitter's new video-sharing app, Vine, is under scrutiny after early adopters started using it to flash six-second porn clips to the app's users and to the larger Twitter community.
READ: On data Privacy Day, Twitter and Google focus on government requests
It's an issue that has Twitter scrambling to appease concerns. And it's raising questions about how Apple, the only place where smartphone users can download the app, will respond after recently banning other apps that provide access to sexual content.
The issue gained attention Monday when Vine users noticed a video of what was described as hard-core pornography showcased in the prominent Editor's Picks section of the mobile app.
READ: Twitter must identify racist, anti-Semitic posters, French court says
Users took to the comment section of that video to complain. Twitter apologized Monday, saying it was a mistake.
A human error resulted in a video with adult content becoming one of the videos in Editor's Picks, and upon realizing this mistake we removed the video immediately," the company said in a statement sent to CNN. "We apologize to our users for the error."
Released Thursday, Vine is a Twitter-owned app that lets users create and share videos lasting up to six seconds. As with photo-sharing app Instagram, Vine users can follow other people, whose posted videos show up in a feed on their phones or can be shared on Twitter and Facebook. The app is available only for the iPhone, iPad and iPod touch.
Vine's Apple-only status raises interesting questions. Just last week, Apple  banned image-sharing app 500px  from its App Store because it could give users access to sexual content. The 500px app features artistically rendered nudes among lots of other photos, but so do other apps with user-generated content, such as Tumblr, which remain available on Apple's iOS mobile system.
The Vine app is rated 12+ on iTunes for "infrequent/mild sexual content or nudity," among other reasons, meaning it's deemed appropriate for users 12 or older. As of Monday, it was the fifth most popular free app in the App Store.
Apple did not immediately reply to a message seeking comment for this story. Vine had been listed on Apple's own Editor's Choice list as early as Monday morning, but appeared to have been removedby Monday afternoon.
Apple observers Monday were noting the strange position the company finds itself in. Apple has famously kept tight reins on what appears in its App Store and on its mobile operating system in general. The late CEO Steve Jobs famously argued that control on the front end delivers a user experience free from porn, spam and other digital unpleasantness.
But as the digital Web grows and evolves, it's becoming tougher to parse the blurry line between apps that promote adult content (and which are turned down or banned by Apple as a matter of course) and those which simply provide access to such fare.
What, for example, is the distinction between the banned 500px app and the app for Tumblr, the blogging platform which, among its millions of blogs, includes many that host explicit sexual content?
"From the start, Apple has said they'd get the App Store wrong, and come across things they didn't anticipate, but that they'd learn and grow," said Rene Richie, editor of Apple-centric blog iMore, in a post Monday. "This particular problem has been around for years, but as social sharing has become easier, it's come to the surface again."
Interestingly, it was just a little less than a year ago that Apple banned Viddy, a video-sharing app that has been compared to Vine, because it gave access to user-generated adult videos. The Viddy app was eventually returned to the App Store.
On Twitter's end, the anything-goes aspect of Vine jibes with the site's overall philosophy. Compared to Facebook, which believes social sharing is best when tied to a user's true identity and real-world networks, Twitter allows its users to register under fake names and has fought governments and law-enforcement agencies seeking user information .
As such, Twitter has taken a more hands-off approach on adult content. It's not hard to hunt down hashtags its users are employing to share adult content on a daily basis. (#TwitterAfterDark becomes a trending topic on the site nearly every day -- clicker beware).
By contrast, searching for several suggestive hashtags (such as #naked or #porn) on Instagram, the popular photo-sharing app bought by Facebook last year, render no results. Because Instagram is an Apple-like closed environment, sexually explicit images are difficult, if not impossible, to find there.
By Monday afternoon, hours after Vine had apologized and deleted the porn video from its Editors Picks, what uproar there was online was subsiding.
As some observers noted, Vine isn't otherwise experiencing anything new in the tech world.
"As virtually every new video or photo-sharing service has shown us since the dawn of the Internet, from Flickr to ChatRoulette, it's very difficult to keep these sites or apps G-rated. So the companies either learn how to police it well, like Flickr does, or they wither and die, as ChatRoulette did," wrote The Atlantic Wire's Adam Clark Estes in a post titled "Vine has a porn problem because, of course it does."
In a statement to CNN, Twitter noted what had already become apparent on the app -- that users can report videos they deem inappropriate.
"Videos that have been reported as inappropriate have a warning message that a viewer must click through before viewing the video," a spokesperson said in the statement. Reported videos that are determined to violate Vine guidelines will be removed from the site and the user account that posted them may be terminated, according to the statement.

Vine's terms of service ban illegal activity, harassment or abuse and behavior such as impersonating another user or violating trademark and copyright.
Read more ...

Will Twitter war become the new norm?

War is not just about bombs and rockets. It's about words.
That's been true for centuries, of course. But the public got a rude awakening this week about just how much those words can matter in the digital age when the Israel Defense Force live tweeted its strike that killed a Hamas leader.
Will Twitter war become the new norm?

The military's live spin about the strike, and Hamas' response on a separate Twitter feed, have been called an unprecedented use of social media. BuzzFeed wrote that it "may well be the most meaningful change in our consumption of war in over 20 years." It's raising questions about the ethics and implications of live-tweeting a violent conflict. And it's calling into question the democratic, everyone-has-a-voice nature of Twitter, which is known more for giving a voice to protesters and civilians than military spokespeople.
In this case, it seems to be giving a megaphone to the military.
"Armies and militaries and governments have done this kind of thing with radio broadcasts and whatever tools they have at their disposal," said Mathew Ingram, a senior writer for the tech site GigaOm. "What changes it is the reach and the speed" of the messages in the social media age. "Twitter and Facebook haven't reinvented communications, but they sure have changed it in some pretty important ways."
Amid fears the violence could escalate, Israel has reported three people killed and Hamas says 20 Palestinians are dead. At least 274 rockets have been fired from Gaza into Israel, according to the Israeli military. More than 140 strikes have hit Gaza, sources with Hamas say. Both sides say they were retaliating against the other's actions.
Tweets from the official @IDFSpokesperson account, which had about 100,000 followers on Thursday, announced an attack on Gaza and reported on its aftermath.
"The IDF has begun a widespread campaign on terror sites & operatives in the #Gaza Strip," the feed wrote on Wednesday, "chief among them #Hamas & Islamic Jihad targets."
The feed followed that up with this stark image:
And it issued warnings to Hamas:
A Twitter feed for the Izzedine al Qassam Brigades, the military wing of Hamas, which controls the Palestinian territory of Gaza, responded to another one of the IDF's tweets this way:
@idfspokesperson Our blessed hands will reach your leaders and soldiers wherever they are (You Opened Hell Gates on Yourselves)
— Alqassam Brigades (@AlqassamBrigade) November 14, 2012
The account, which had about 11,000 followers on Thursday, also says Israel's airstrikes are hitting civilians:
#Israel's military still targeting civilians in #Gaza kills a child and fourty others #hamas#GazaUnderAttack #Egypt
— Alqassam Brigades (@AlqassamBrigade) November 14, 2012
The live updates -- which include some graphic images -- also raise questions for Web companies like Twitter and Google, which owns YouTube, about what content they will allow to be posted to their sites. YouTube briefly removed a video that appeared to show an Israel strike on a car that killed a high-ranking member of Hamas. The company since has restored the video, according to a YouTube spokeswoman.
"With the massive volume of videos on our site, sometimes we make the wrong call," the spokeswoman said in an e-mail to CNN. "When it's brought to our attention that a video has been removed mistakenly, we act quickly to reinstate it."
The video site has a policy that bans "graphic or gratuitous violence." It makes exceptions, however, for content that has documentary or news value.
Others have raised the idea that Twitter should censor the official IDF and Al Qassam Brigades feeds, since they could be viewed as inciting violence.
"This clearly puts Twitter in a difficult position. They want to preserve their position as a carrier service that doesn't editorialize," Benedict Evans, from Enders Analysis, told the BBC. "On the other hand, they have terms and conditions that must be adhered to."
Twitter did not immediately respond to a CNN request for comment.
More lasting than the free-speech debate at the tech companies, however, may be the fact that future conflicts will have to include live updates from official military sources, said Ingram, as armies try to spin the public in real time.
"If you're an Israeli supporter, your view is that you need to do this because you need to get the information out that you believe isn't reaching people properly because of bias in the media," Ingram said. "And presumably Palestinians believe the same thing."
That could have important ramifications.
"If the Egyptian government had been doing what the IDF is doing during the Arab Spring, it would have been a very different picture," he said, referring to the activists who used social media to organize protests that toppled Egypt's Hosni Mubarak last year. "Mostly what we got was people on the ground -- participants, dissidents -- because the Egyptian government was clueless."
These groups are not clueless when it comes to social media. But their efforts to spin the public may backfire because it can't silence other voices, said Zeynep Tufekci, a fellow at Princeton's Center for Information Technology Policy.
Tufekci said she's having a hard time opening her Twitter timeline because it's littered with people on the ground who are posting "pictures of mangled children's dead bodies." Those photos -- and tweets from people on the ground who are experiencing the violence -- make the spin-heavy feeds from both sides of the conflict seem "hollow" and distortionist, Tufekci said.
She said it's especially jarring because the messages are stacked right on top of each other in her feed.
"I really think that the power of social media in such cases is to make real -- and very excruciatingly real, and horrifyingly real -- what war actually looks like," she said. "These (official) Twitter accounts, (from what) I've seen of IDF, they're trying to make it unreal. They're trying to spin it and have PR, and that is really not working because there are so many pictures coming out of the reality of what it looks like."
She hopes the graphic tweets will remind the public of the grave consequences for both sides. "It's not a social media war," she said. "It's a real war."


Read more ...

Apple deletes app for 'porn' -- what it means

The removal of 500px from Apple's App Store raises questions over review equity, fairness and API functionality.
Apple deletes app for 'porn' -- what it means

When Evgeny Tchebotarev started the day, he wasn't expecting to end up spending so much time fielding calls from the media. Tchebotarev is the COO and co-founder of 500px, a popular photo site and community for professional and amateur photographers.
Yet that's exactly what happened after Apple removed the 500px app from the App Store. After more than 16 months in the App Store and over 1 million downloads, a routine app update had unintended consequences.
On Monday night, Tchebotarev tells Mashable that he received a call from Apple. There was a problem with 500px. Like many other apps with photo communities, including Tumblr and Flickr, some of the photographers who use 500px use it to take photographs that contain nudity — not pornographic images, but nudity nonetheless.
According to Tchebotarev, Apple reps told him that it was too easy for users to find nude photos using the app. As a result, the app was in violation of Apple's content policy and would be removed from the App Store. Tchebotarev offered to make the necessary changes to the app to comply with Apple's rules, but it was too late. As of Tuesday morning, 500px was gone from the App Store.
A few hours later, TechCrunch reported on the story. Other outlets followed, including CNET, MacRumors and The Verge. Soon, the story was viral.
The general reaction from both 500px employees and app users was disbelief. For one thing, 500px actually makes it difficult for new users to browse or search for nude photos. A user who signs up using the app can't see those types of photos; instead, he or she must log in through their desktop, and turn off a safe-search setting.
For another, 500px is hardly the only app that could potentially expose users to nude images. Web browsers — including Apple's Safari — can display nude photos of all types. Plus, the aforementioned Tumblr and Flickr apps are much easier to use to track down nudes. To add insult to injury, while 500px is gone, a dozen apps that use 500px's API and replicate the functionality of the official app are still available.
Then, Apple released its own statement on the matter. It said:
"The app was removed from the App Store for featuring pornographic images and material, a clear violation of our guidelines. We also received customer complaints about possible child pornography. We've asked the developer to put safeguards in place to prevent pornographic images and material in their app."
This statement was confusing to Tchebotarev and other 500px execs because it was the first any of them had heard about complaints regarding "possible child pornography." Apple never mentioned that to the company before pulling the app, Tchebotarev said.
He added that 500px has made the necessary changes to its app, and re-submitted to the App Store. With any luck, the app will be back in the store very soon.
Normally, this is where the news story would end. But what the 500px incident showcases, however, is that although more than four years have passed since the App Store opened, Apple's app-review process is still occasionally hampered by incongruities and unclear policies.
App Rating Fairness
My initial guess was that 500px was removed for not having the correct content rating. Apple assigns content ratings to apps to give users an idea of who the app is suitable for.
A rating of 4+ means that there is no objectionable content in the app; a 9+ means there might be cartoon violence; a 12+ means there may be infrequent or mild sexual content/nudity and mild violence; and a 17+ means the app may contain heavy violence and mature themes.
These content ratings can be arbitrary at best. Tumblr has a rating of 4+ despite the fact that it's very easy to find hardcore pornographic images using the tag search function within the app. Third-party web browsers such as Chrome and iCab have 17+ ratings because they can be used to access any site on the Internet (assuming it doesn't use Flash).
Before Monday's incident, 500px had a content rating of 4+. Tchebotarev told me that the copy of the app in the submission queue has a rating of 12+.
Based on feedback he's heard from other developers, Tchebotarev's theory is that Apple's review team (a team that is notoriously overworked) doesn't always check to ensure that apps have the proper content rating. Instead, it takes a series of complaints or a particularly conscientious review-team member to force an app to change its rating.
This makes sense to me. Still, I'm utterly unsure how Tumblr, of all apps, has managed to avoid even a 12+ rating.
What About APIs?
Another issue raised with the 500px case is the role of an API within the app-review process.
Apple initially said it was going to pull Pulpfingers' ISO500 app from the App Store. 500px acquired Pulpfingers (and ISO500, by extension) last month.
As of this writing, ISO500 is still in the App Store, and doesn't appear to have been pulled.
It wasn't clear why ISO500 was going to be removed, but some pundits worried that it was because the app uses 500px's API. The API allows read-access to the site and search, including, presumably, access to nude photos.
This opens up an interesting question when it comes to third-party apps that use 500px's API, such as Flipboard. Flipboard can do virtually everything the official 500px and the ISO500 apps can do (at least, as far as displaying content), so would it be at risk?
Right now, that seems unlikely, but it does raise some interesting questions that few of us have considered over the years: Is an app that plugs into another app's API going to be rated based on the functionality of that API?
It's unclear.
Waiting For a Resolution
At the time of this writing, 500px is still missing from the App Store. While I fully expect the app to appear within the next day or two, I can't help but feel empathy for the startup caught in the middle of this.
What do you think of the latest App Store hijinx? Let us know in the comments below.
This post represents the opinions of the author and not necessarily those of Mashable as a publication.



 
Read more ...

6 ways Vine's six seconds may change Twitter

Call it the Twitterfication of social sharing.
As if it wasn't enough for Twitter to limit our bursts of inspiration to 140 written characters, it has now rolled out Vine, a video-sharing app that limits your videos to just six seconds.
What can you do with six seconds of smartphone video (which, for now, is available only on iPhones, causing an aggravated Android Nation to again wail and wait)?
Not re-enact "Lawrence of Arabia" using action figures. That would take 2,270 Vine posts, give or take. Nor can you document a successful rodeo bull ride; those require at least eight seconds.
As the tech press largely fawns over the new tool's potential, we're taking a look at some of the ways the tool might affect your Twitter feed and the Web as a whole.
And it seems only appropriate that we analyze Vine's six-second bursts in six points. Here's what Vine could do:
6 ways Vine's six seconds may change Twitter

1. Spur creativity
If, as the Bard wrote, brevity is the soul of wit, the six-second time limit could in fact inspire creativity. That's the logic behind Twitter itself, really.
Once derided by critics as an example of society's increasingly gnat-like attention span, the site's 140-character limit has in many cases inspired users to be as witty, insightful or informative as they can be in as few words as possible.
Twitter is sometimes called a "microblogging" site. Considering some of the long and winding blog posts we've read over the years, there's some value in spurring users to make their point quickly. Maybe Vine will do the same for Web video.
"My guess, given the enthusiasm for Twitter so far, is that people are going to do really cool things," Scott Klemmer, co-director of the Human-Computer Interaction Group at Stanford University, told Wired, a CNN content partner.
"One of the things we know about creativity is that constraints are essential for getting people to do creative stuff. If you come up with the right constraints, that's a benefit, not a drawback."
And here's an example:
(Of course, if you desperately need a 10-minute loop of sniveling King Joffrey from "Game of Thrones" getting slapped to a Led Zeppelin soundtrack, we've still got YouTube.)
2. Spam up your feed
A vine can be a lovely thing. Think Wrigley Field or the Ivy League. But it can also be a noxious weed.
In the first 24 hours, the primary theme of most of the Vine videos we've seen has been "Hey, I'm making a Vine video!" We're not immune from this ourselves.
That will probably change, in many cases, as creative folks fine-tune their craft. But let's be honest: Among Twitter's millions of users are a lot of people who will probably be sharing the banal and the stupid. And, if Web history holds true, clips of themselves naked.
Hopefully, you've crafted your "follow" list to keep most of these people off your screen. Otherwise, you could find yourself clicking on a lot of videos of people's food.
Which, as we all know, is what Instagram is for.
3. Turn Twitter into Facebook's video alternative
It surprisingly took a few months after Facebook bought the aforementioned Instagram, an app that lets users slap groovy-looking filters onto their photos, for it to cause a falling-out with Twitter.
Facebook pulled Twitter's ability to show Instagram images in its feed. That's reserved for FB now. You can still post them to Twitter, of course, but followers see only a link that takes them to Instagram's website.
Fair enough, we suppose. Why let a competitor reap the benefits of an app you just shelled out a reported $1 billion to buy?
So, if that makes Facebook the go-to platform for social photos, maybe Vine makes Twitter the default place for fun mini-videos. As the platform strives to turn a profit, the Vine clips may give users a new reason to linger.
4. Invite more "Oops" moments
Delete all you want. Once you tweet something, it's out there forever. Ask Chris Brown. Or Gilbert Gottfried. Or Anthony Weiner.
Put videocameras in the hands of millions, give them a platform to share the results with the rest of those millions, and bad decisions are sure to ensue. Often after a few cocktails, or if you're a celebrity.
Given a new tool with which to share, or overshare, we all can expect more Twitter missteps. Many of us can't wait.
5. Continue the rebirth of "GIFs"
OK, this one is already under way. Years after the Web gave usPeanut Butter Jelly Time, folks have rediscovered the joy of watching something quick and silly happen over and over again.
Vine builds on this idea. Your six seconds (or fewer) of video loops for as long as the viewer lets it run. This can be disconcerting and annoying. But as folks get creative, it could also be clever. The first person to re-enact "Dramatic Chipmunk" has our undying devotion. (Fun discovery: That YouTube classic is exactly six seconds long).
A Vine isn't actually a GIF (Graphic Interchange Format is the full name). But it can take advantage of the same instincts that have made GIFs an enduring Web feature.
6. Press the competition
Vine isn't the only mobile app jockeying to be the "Instagram of Video."
Viddy, Tout, SocialCam and even the ill-fated Color all wanted to become the front-runner in this emerging social field. Twitter may have shut down that argument when it acquired Vine for an undisclosed amount.
Sure, the mobile space has its share of stories in which the bantamweight manages to dance around a heavy hitter. Remember when Facebook Places was supposed to crush Foursquare?
But Vine will be sitting right there in front of Twitter's more than 140 million users. The others will need to innovate or die.

Have you seen any Vine videos you really liked, or made some of your own? Let us know in the comments.
Read more ...

Twitter must identify racist, anti-Semitic posters, French court says

(CNN) -- For months now, the French-language twittersphere has lit up with a rash of racist, homophobic, and anti-Semitic tweets using the hashtags #UnBonJuif (a good Jew), #SiMonFilsEstGay (if my son is gay), and #SiMaFilleRamèneUnNoir (if my daughter brings home a black guy).
Twitter must identify racist, anti-Semitic posters, French court says

Last fall, under pressure from French advocacy group Union of Jewish Students (UEJF), Twitter agreed to remove some offensive tweets. In October 2012, at Berlin's request, Twitter also suspendeda German neo-Nazi account based in the city of Hanover, the first time the company had responded to such a government request.
However, at the time, the UEJF also wanted identifying information of the perpetrators, which Twitter was not prepared to give up. So the group went to court to force the issue.
On Thursday, the Grand Instance Court in Paris ordered Twitter to identify the authors of anti-semitic tweets by creating a mechanism(Google Translate) to alert French authorities to "illegal content," on its French site "in a visible and easily-accessible [way]."
If Twitter does not comply within two weeks, the American company faces fines of €1,000 ($1,336) per day.
How "free" should "free speech" be?
This isn't the first time that French courts and laws have butted heads over idiotic racism online. Less than a year ago, then-president Nicolas Sarkozy proposed a law that would make even viewing a hate site a crime.
Here in the United States, we have a Constitutionally protected near-blanket right to free expression. Although incitement to violence is generally not protected, hate speech -- no matter how disgusting and awful -- is. As we've reported before, the operating principle in America has generally been that undesirable speech should be countered with more speech, not less.
That's not the approach taken in Europe, where hate speech is most definitely not protected. Many European Union states (and even some non-EU countries in Europe) have various types of anti-hate speech legal mechanisms, in part to head off terrorism and far-right violence.

"We're not able to identify the individuals, only Twitter can do so," Sacha Reingewirtz, UEJF's vice president, told the French broadcaster, RFI. "We've already tweeted the decision. And we see on Twitter that the decision has apparently triggered a new rise of anti-semitic messages directed against our organization, so there is still work to be done, both by us and Twitter, but we're happy the French justice is now changing the way it is."
Read more ...

On Data Privacy Day, Twitter and Google focus on government requests

In 2009 the U.S government dubbed January 28 "Data Privacy Day." Four years later, it's the government's own actions to obtain personal information that are in the spotlight, thanks to new reports from Google and Twitter.
On Data Privacy Day, Twitter and Google focus on government requests

The goal of Data Privacy Day is to educate people and companies on the vulnerability of personal data, including information shared on social networks, financial data and anything stored on cloud services. The holiday is spearheaded by the National Cyber Security Alliance (NCSA), a nonprofit organization that works with government agencies and major tech companies including Intel, Google, Microsoft and Facebook.
"We want to raise universal awareness about people respecting the privacy of others and safeguarding their data," said Michael Kaiser, NSCA's executive director.
To mark the occasion, Twitter released its latest transparency report, which breaks down government requests for user data as well as copyright complaints and "take down" requests. Google followed up on its own transparency report, released last week, with a blog post explaining how it fields government requests and a new section on its transparency report that addresses common questions about the process.
The numbers from the two companies show a steady increase in requests from the U.S. government for personal data. Usually these requests are part of criminal investigations or court cases, according to the two companies. The majority of requests from U.S. agencies are subpoenas, followed by search warrants, court orders and some emergency requests. Search warrants are more difficult to obtain than a subpoena and require a higher standard of probable cause.
In the past six months, Google received 21,389 requests for data, a 70% increase since the company first started releasing the report in 2010. The largest single entity requesting information continued to be the U.S. government, which submitted 8,438 of the requests. Google turned over some or all of the requested information 88 percent of the time, Twitter 57 percent of the time.
Twitter received 1,858 requests for information about 1,433 accounts, 815 of which were from the U.S. government. The social network added a new home for its transparency reports,transparency.twitter.com, and expanded the report to include more details about the requests and an expanded entry to cover the activity in the United States.
"It's our continued hope that providing greater insight into this information helps in at least two ways: first, to raise public awareness about these invasive requests; second, to enable policy makers to make more informed decisions," Twitter's legal policy manager Jeremy Kessel said in a blog post.
Transparency and education about what the government can access and how are important, but the companies also want to change the laws to better protect user privacy in the first place.
"We're a law-abiding company, and we don't want our services to be used in harmful ways. But it's just as important that laws protect you against overly broad requests for your personal information," said Google's chief legal officer David Drummon in a blog post on Monday.
Under the 1986 Electronic Communications Privacy Act (ECPA), a file stored on a hard drive in your home has greater protection than information stored with a third-party. Whereas the government would require a search warrant for anything in your house, it can request access to e-mails older than 180 days or information stored in the cloud with a subpoena, which is easier to obtain. Twitter and Google are both members of the Digital Due Process Coalition, an organization that is lobbying to update the act.
Drummon explained Google's process for handling requests, which involves notifying users of the requests when legally allowed, and requiring a search warrant for search query and private information from agencies conducting criminal investigations.
"We believe a warrant is required by the Fourth Amendment to the U.S. Constitution, which prohibits unreasonable search and seizure and overrides conflicting provisions in ECPA," says Drummon.
These kinds of reports and posts are important tools for educating the public about how and when government agencies can access information, but government requests are only one sliver of data privacy fluency. People can also take steps to better control what they share online on social networks or apps that collect location data. Kaiser recommends people familiarize themselves with privacy policies and regularly update privacy settings on sites such as Facebook.
The day isn't just to raise awareness among consumers. Business are also key players in data privacy, and while big names like Google and Twitter have large legal and security teams, smaller companies that also have access to personal data might not.

"We want them to be aware of their responsibility to be stewards of the data people entrust to them," said Kaiser.
Read more ...

Yik Yak chat app stirring up trouble in high schools

From Chicago, to Georgia, to Southern California, a new social media application is causing problems on middle school and high school campuses across the United States.
Yik Yak chat app stirring up trouble in high schools

It's called Yik Yak, a location-based app that creates an anonymous social chat room where up to 500 nearby users connect through GPS tracking on their phones. Less than 4 months old, Yik Yak has "a couple hundred thousand users, mainly in Southeast/East coast campuses," its co-founder Brooks Buffington said.
Users are limited to 200 characters, and no pictures are allowed. If a post is "down voted" enough times by other users on the forum, the comment disappears. Tech experts are comparing the new Atlanta-based app to a cross between SnapChat and Twitter.
"The app was made for college-age users or above, for college campuses and to act as a virtual bulletin board, so it acts as local Twitter for their campus," Buffington told CNN.
Although the app is meant for users age 17 and older, younger users can still sign up, and that's where the issues have sprouted.
School administrators in Chicago said teens in some of their schools have used the free app for cyberbullying. Others have made anonymous bomb threats that have led to school lockdowns.
"Students were actually coming downstairs to talk to administration, and they were mentioning remarks posted and student names that were obvious, so of course that is going to impact you," Melvin Soto, assistant vice principal at Whitney Young High School, told CNN affiliate WLS.
Some students have compared it to a virtual bathroom wall where users post vitriol and hate.
"They ripped on someone for getting raped, and that's just so wrong. They said a whole lot of bad things about this girl," Whitney Young student Rachel Brown told WLS.
In southern California, a San Clemente High School resource officer told CNN a threatening Yik Yak post caused a bomb scare on campus.
"The school was placed on lockdown, we conducted a sweep utilizing our bomb squad and bomb-sniffing dogs and nothing suspicious was located on or near the campus," Orange County Sheriff's spokesman Jeff Hallock told CNN.
He added that the app is so new that some students hadn't even heard about it yet.
In Georgia, the principal of Webb Bridge Middle School in Fulton County wrote a cautionary letter to parents warning them about the "inflammatory [Yik Yak] app," encouraging them to talk to their children about the "dangers of social media." The school district has blocked the app from its network, but Principal Susan Opferman writes, students have found ways around that too.
"If used inappropriately, Yik Yak posts can be especially vicious and hurtful, since there is no way to trace their source, and can be disseminated widely," Opferman said in the letter.
These types of incidents have caused the app's developers to disable it in some areas. Buffington told CNN he doesn't want high school students using the app.
"One of the things we were planning to do is to essentially geo-sense every high school and middle school in America, so if they try to open the app in their school, it will say something like 'no, no no, looks like you are trying to open the app on a high school or middle school and this is only for college kids,' and it will disable it and the app won't work," Buffington told CNN.
"That will completely eliminate the problem we have been seeing, so we geo-sensed the entire city of Chicago until we get this fix up. We are working on getting third-party help to get the fix in place as soon as possible."
But cyberbullying expert Justin W. Patchin says that's just a short-term solution. He says teens will figure out a way around it.
"It is pretty impossible to limit it to the ages that the founders have intended," said Patchin, who is the co-director at the Cyberbullying Research Center at the University of Wisconsin-Eau Claire. "When I signed up for the app, it said that you have to be 17 or above to sign in, and of course, there wasn't any way of them checking my age so anybody could sign up."
The app's developers defended their technology, saying it is used for good.
"With anonymity comes a lot of responsibility, and college kids have the maturity that it takes to handle those responsibilities," Buffington said. "One of my favorite use case stories is a freshman missed his flight for Christmas break, and he came back to campus and he posted on Yik Yak that the freshman dorms were closed, and so an upperclassman let him crash on his couch," Buffington said.
"Anonymity can be a really beautiful thing, and one of the reasons we made it anonymous is it gives people a blank slate to work from, so you're not judged on your race or sexuality or gender. On Yik Yak you are purely judged on content you create." Buffington said.
He added, "The longer that we are around on college campuses, the better it gets."
As more applications pop up and the environments of social networking sites change, Patchin says the emphasis should be on teaching younger generations about respect in online communities.



"It is more important to talk to the students about how to treat each other respectfully. Whether it is happening in an application like this or Facebook or on e-mail, the emphasis for us has always been on those behaviors because it is easier to teach that than to restrict that to particular technology."
Read more ...

Biz Stone: Humans can outsmart the Internet

Austin, Texas (CNN) -- At 9:45 in the morning after his 40th birthday you might expect Biz Stone, best known for co-founding Twitter, to be a little bleary. After all, many millionaire tech execs flaunt their party lifestyle like a badge of honor.
Biz Stone: Humans can outsmart the Internet

But on this Tuesday, in a quiet corner of an Austin hotel lounge, Stone is clear-eyed, animated and apparently hangover-free.
For the first time in years he's back at the South by Southwest Interactive conference, where Twitter first and famously blew up in 2007. Stone's got a book coming out next month, "Things a Little Bird Told Me," which he describes as "packed with aspirational lessons that were learned through embarrassing mistakes."
And he's recently launched his newest venture, a mobile tool called Jelly. Part social app, part visual search engine, Jelly lets users mine their social networks for answers to such questions as, "What kind of plant is this?" or "How do I hook up this TV?"
Jelly is unusual in that instead of computer algorithms like Google's, it relies on human knowledge to help users find the answers they seek. And each question must be accompanied with an image, creating a sort of visual shorthand. Users can even draw over the images with their finger.
Despite its lofty pedigree -- its investors include Bono and Al Gore -- Jelly has baffled some tech pundits who don't understand why people would use it when they can just poll their friends directly through Facebook or Twitter. But Stone, who also helped launch Blogger, remains optimistic that Jelly will catch on.
The serial entrepreneur sat down with CNN at SXSW for a chat about Jelly, social networking and why seeing Twitter hashtags sometimes seems "surreal." Here's a condensed version of our conversation:
On bringing Twitter to SXSW:
"Twitter exploded here. It was a watershed moment for Twitter, and it was an eye-opening moment for me. So for the most part after that year I never came back, because I didn't want to jinx it.
"When we came to SXSW in 2007 it was the first time we could really see Twitter being used in the wild. There was a concentration of people, and most of them were using it. And I saw that Twitter was far more powerful than I realized.
"The one example that comes to mind is ... there was this guy in a pub. And he said (on Twitter), 'This place is too loud for us to talk. Let's go to this other place.' And he named it in his tweet. And in the eight minutes it took him to walk over there, it had filled to capacity and there was a line out the door. Twitter took a bunch of loose individuals, and suddenly they became one organism, like a flock of birds.
"And I couldn't think of another technology that allowed human beings to flock in real time. We went back (to San Francisco), and a few days later we formed the company."
On the idea behind Jelly:
"We've become the most connected humanity that's ever existed. We're now connected to anyone else on the planet within four degrees of separation because of social networks and mobile phones. It's an amazing era of connectedness. And yet not a lot of people stop to think, 'Why? What's the true promise of a connected society?'
"I've been asking myself that question ever since I left Twitter. And it occurred to me the true promise of a connected society is people helping one other. Or at least it should be.
"So Jelly is a search engine, as audacious as it sounds. Everyone figures we've got search all wrapped up. There's the Internet -- it's vast and growing, and we can search it in a fraction of second to find anything we want. But the Internet is only the Internet ... it's only a collection of documents. There's way more to life than the Internet. So Jelly is like a search engine for everything else. And the reason it works is that we're all connected.
"People talk about artificial intelligence. Well, how about (human) intelligence? We have 7 billion people on this planet."
On why Jelly requires images:
"We're carrying around 8-megapixel cameras (on our phones). In a world where 140 characters is considered a maximum length, a photo really is worth 1,000 words. For almost any question, a photo can deepen the context. Also, it allows you to type less: 'Should I buy a Tesla?' How about just, 'Should I buy this (with a picture of a Tesla)?"
"A lot of people ask, 'Why not just ask my social network?' But what Jelly does is blend Twitter and Facebook together. Jelly gives you far more reach. Your friend's wife's lawyer is all of a sudden answering your question.
On how people have been using Jelly:
"Whenever you build something, the creativity in humanity comes out. I love it when I'm seeing answers to questions where people are only drawing on the photo. They're not even using language. Somebody asked, 'How do you do a screenshot on a Mac?' and all the person (answering) did was circle the three keys you touch. It was wonderful.
"I have this theory that if something isn't fun and goofy, then you won't use it on a regular basis. And then you won't think to use it when you need it. The same thing happened with Twitter."
On the future of social networking:
"Social networking is still brand new. We're still figuring it out -- how much we should share, and how much we should self-edit.
"But I think the bigger thing here is that it's growing so huge. You can now measure the number of people on planet Earth who use social networking ... (as a large percentage) of the planet. And that opens up intense possibilities of cooperation among humankind.
"In the future, what do I think will happen? I think we'll be able to accomplish in one year what used to take 100 years. Because when people get together and coordinate, they can do amazing things.
On his early days at SXSW:
"I used to come to South by Southwest in the early 2000s every year, and we'd put on a party for Blogger. It (SXSW) always falls on my birthday. So I used to pretend it was my birthday party, because we got Google money to throw around and give everyone free whiskey and beer. And we'd give out Blogger T-shirts, which of course had a B logo, like for Biz. And I'd say, 'Welcome to my birthday party! Free whiskey for everyone!' "
On the success of Twitter, which he left in 2011:
"It's incredibly weird to see, everywhere I look, the little birdie that I drew. Or hashtags on my favorite TV shows. For me personally ... that's surreal. Most importantly, it means that people are finding value in the service.

"And that's the most important thing you can do in this world before you die -- to build something of value."
Read more ...

Wednesday, March 12, 2014

15 space organizations join hunt for missing Malaysian jet

China activates an international charter started in 1999 to aggregate global space data from satellites in an effort to locate Malaysian Airlines' flight MH370.
An Indonesian Air Force military surveillance aircraft searches the Malacca Strait for Malaysian Airlines flight MH370
As the latest piece of technology to be enlisted in the search for missing Malaysian flight MH370, satellites have the eyes of the world watching them as they watch us.
On Monday, a crowdsourcing platform called Tomnod, along with parent company DigitalGlobe, launched a crowdsourcing campaign to enlist the help of citizens in scouring satellite images to search for the plane that disappeared on March 7.
China has followed that up by activating the International Charter on Space and Major Disastersto join the hunt on Tuesday. The goal of the charter is to enlist space data from 15 member organizations to provide assistance in the case of a "natural or technological disaster." The charter describes such a disaster as "a situation of great distress involving loss of human life or large-scale damage to property, caused by a natural phenomenon, such as a cyclone, tornado, earthquake, volcanic eruption, flood or forest fire, or by a technological accident, such as pollution by hydrocarbons, toxic or radioactive substances."
Now that the charter has been activated, space scientists around the planet will enlist the satellites available to them to gather images from the suspected area in which flight MH370 disappeared. The hope is that one of those images will pick up something that can direct search and recovery efforts.
Satellites are just one of the tech tools involved in the massive multi-national aircraft hunt that already includes the use of 42 sophisticated ships and 39 high-tech aircraft combing the waters according to the BBC. For example, listening devices are being lowered into the water to pick up the "ping" of the black box, and sophisticated MH60 Seahawk helicopters from the United States are employing Forward Looking Infra-red (FLIR) cameras that arm the searchers with night vision.
The International Charter on Space and Major Disasters was most recently activated on February 13 to help with monitoring the Mount Kelud volcano explosion on the Indonesian island of Java. Prior to that it's been used to monitor flooding, forest fires, snowfalls, cyclones, oil spills and other damaging events around the world. It was also used to assist in recovery efforts from earthquakes, including the one that rocked Japan in March 2011 and caused a devastating tsunami and the meltdown of the Fukushima Daiichi Nuclear plant. The charter has been activated 400 times in its history, but Tuesday represents the first time it was called into service to look for a missing aircraft. The only other transportation-related event for which it's been used was to assist in gathering data after a train full of dynamite exploded in North Korea on April 23, 2004.

The charter, which began after Vienna's Unispace III conference in 1999 with three agencies, has grown to its current membership of 15 organizations with the Russian Federal Space Agency being the most recent to join in 2013. Other member organizations include the European Space Agency, the Korea Aerospace Research Institute and China's National Space Administration. The US member organizations include the United States Geological Survey and the National Oceanic and Atmospheric Administration. After the charter has been activated, data typically starts coming in within 24 hours, according to a report in Phys.org.
Read more ...

Tuesday, March 11, 2014

Microsoft's Kurt DelBene to lead HealthCare.gov revamp

Retiring Microsoft Office Vice President Kurt DelBene is going to be heading up the revamp of the troubled HealthCare.gov site.
Kurt DelBene

Politico reported the news on Tuesday. The US Department of Health and Human Services confirmed it shortly thereafter. 
Microsoft announced in July 2013 that DelBene, a 20-year Microsoft veteran, would be retiring as Microsoft reorganized itself along more device/services-focused lines. DelBene's last day at Microsoft was Monday, a Microsoft spokesperson confirmed.
Kathleen Sebelius, US Secretary of Health and Human Services, announced DelBene's appointment in a press release today. From that release:
"Today, I am pleased to announce Kurt DelBene as my senior advisor and successor to Jeff Zients. Jeff did an outstanding job working with our team to provide management advice and counsel on the HealthCare.gov project. Today, the site is night and day from what it was when it launched on October 1. I am very grateful for his service and leadership. His role leading the management of the site proved critical and today we are announcing his successor: Kurt DelBene. Kurt, who most recently served as president of the Microsoft Office Division, will lead and manage HealthCare.gov starting this Wednesday."
Back in 2011, Ballmer appointed DelBene as president of the Office division in a move some saw as signifying CEO Steve Ballmer's decision to bring more engineering-savvy talent into Microsoft's senior leadership circles."
Related posts

HealthCare.gov site can't fix its own mistakes -- report
HealthCare.gov security -- 'a breach waiting to happen'
'Pardon Snowden,' one tech exec tells Obama, report says

The Obama administration's Healthcare.gov initiative has been plagued with problems since it launched in October 2013. While some front-facing parts are now in better shape than they were in the first few months of its operation, the back-end is still a mess, according to some accounts.
According to Sebelius' announcement, DelBene has agreed to oversee the Healthcare.gov project for "at least the first half of next year." He will be providing management expertise, operations oversight, advice on additional enrollment channels, field operations, marketing and communications. He will work alongside CMS Administrator Marilyn Tavenner and in partnership with general contractor on the project, QSSI.
As Politico noted, DelBene's wife is freshman Rep. Suzan DelBene (D-Wash.), who also formerly served as a vice president in Microsoft's mobile communications business.

Update: DelBene isn't the first Microsoft exec to move into a high-profile government job, post-Microsoft. Former Windows Server Director Steven Van Roekel was appointed the US Chief of Information Technology in 2011.
Read more ...

Colbert turns his funny gun on Snowden in RSA keynote

No joke: Stephen Colbert's not a fan of Edward Snowden's whistleblowing, the political satirist tells a packed house at the closing RSA Conference keynote speech.
Stephen Colbert kept San Francisco's Moscone Center audience of around 6,000 laughing as he mocked the state of computer security and expressed a vote of no-confidence in Edward Snowden on Feb. 28, 2014

SAN FRANCISCO -- Don't mistake this for something out of the mouth of Stephen Colbert's ultra-conservative, Bill O'Reilly-modeled TV persona: The popular funnyman actually believes that former NSA contractor and domestic spying whistleblower Edward Snowden should come back to the US and face trial.
In front of more than 6,000 people at the RSA Conference's closing keynote at the Moscone Center here, Colbert had the audience roaring within minutes over his jokes about computer security and encryption.
Related stories:

Google paves the way for more wearable apps
In most-anticipated SXSW talk in years, Snowden fires up Austin
Snowden at SXSW: The NSA set fire to the future of the Internet
EU's Neelie Kroes: 'Snowden gave us a wake-up call'
WikiLeaks' Julian Assange: NSA critics got lucky because agency had no PR strategy
Kill the Snowden interview, congressman tells SXSW
FreedomPop's 'Snowden phone' encrypts your calls and data

Colbert described the conference jokingly as a place where the best security experts "gather, talk shop, and breed with each other. That's called exchanging private keys."
He quickly changed the subject to address the petition that demanded  that he join the  RSA Conference boycott  over the conference's parent company  colluding with the National Security Agency .
Colbert said he had signed a contract with RSA that he wasn't going to break, in part because, he was "paid in Bitcoin, from Mt.Gox" -- a company that has now filed for bankruptcy protection.
Then he got serious. There was "no evidence in Reuters' story," he said of the  original report that broke the news about RSA's ties to the NSA.
"Documents leaked by former NSA contractor Edward Snowden show that the NSA created and promulgated a flawed formula for generating random numbers to create a 'back door' in encryption products," wrote reporter Joseph Menn in the story.
Menn then cited two anonymous sources who said they were familiar with an alleged $10 million contract between the NSA and the RSA division that promoted the flawed encryption as the default encryption to use in RSA's BSafe encryption tool.
While RSA told Menn and later CNET in a statement that it "does not design or enable any back doors" in its products, that word choice leaves wiggle room for a weaker or flawed encryption algorithm to be left in place over better encryption choices.

"We the people voted for the Patriot Act. We voted for the people who reauthorized it, and re-reauthorized it. The American people have spoken," he said. "You don't change horses in mid-wiretap." 
--Stephen Colbert

Colbert interwove jokes about the situation with seriousness. "I hope RSA took the money. If they didn't, they should have. We all have Uncle Sam's cameras up our junk. Shouldn't someone be getting paid for it?" he quipped.
But he also said over the course of the 45-minute keynote that Americans have proven "time and time again" that they support the policies in the Patriot Act that allowed expanded surveillance of American citizens.
"We the people voted for the Patriot Act. We voted for the people who reauthorized it, and re-reauthorized it. The American people have spoken," he said. "You don't change horses in mid-wiretap."
Colbert joked that the Patriot Act-authorized policies as "enhanced liberty," similar to how "enhanced interrogation" lets you "drink all the water you want."
He didn't have much love for the NSA either, pointing out the ridiculousness that a "sophisticated agency" like the NSA "can get pwned by a 29-year-old with a thumb drive."
Stephen Colbert listened intently to a woman in the audience and projected on-screen behind him ask about his dislike of whistleblower Edward Snowden, in San Francisco on Feb. 28, 2014.
(Credit: Seth Rosenblatt/CNET)
He explained the NSA's tortured logic: "We have solid proof that this program saved zero lives. It was designed to root out terrorists. It shouldn't bother you if you're not hiding anything, and since you can't hide anything from the NSA, nothing is bothering you."
He closed his monologue by saying that he was going to turn his back on the audience for 30 seconds while they cheered. The crowd obliged.
At the following question-and-answer session, Colbert interacted more playfully and more forthrightly than might have been expected for such a popular TV personality.
One woman asked him what the meaning of life was. He replied, "42!" to the delight of Douglas Adams fans in the audience. Another fan set him up by saying that Jon Stewart has had Neil deGrasse Tyson on 10 times, while Colbert has only hosted the popular astronomer 9 times.
"Why do you hate space?" came the fan's punchline.
"I had [Tyson] on first," said Colbert, "but he demoted Pluto, so he's not getting a 10th."

"I hope RSA took the money. If they didn't, they should have. We all have Uncle Sam's cameras up our junk. Shouldn't someone be getting paid for it?" 
--Stephen Colbert

Some audience members were surprised by Colbert's take on the Snowden situation and asked more serious questions.
When asked whether it was what Snowden did, or how he did it, that had turned Colbert against him, Colbert was silent for a minute.
When he spoke, he said that his problem was that Snowden released too much top secret information to the world about how the US conducts its spying practices.
"Why, if Snowden was concerned with letting us know how we are spied on, why did he let us know how we spy on other countries? I think we should spy on other countries," Colbert said. Snowden, he said, should be taken to court over the espionage charges.
This wasn't the first time that Colbert has expressed a lack of support for Snowden, but it was his most vocal expression of anti-Snowden sentiment to date.
At the end, Colbert said that the "greatest threat to our security" was not knowing where political money came from, and not voting. But when it comes to doing the right thing for your country, as Snowden has stated was his reason for leaking the NSA documents, Colbert said that you must face the consequences of the law.

It's not often that Colbert stops being satirical, but when he does, he does it to express a closely held value. Unfortunately for his fans, this is one value that they all might not agree with.
Read more ...

Exclusive: Secret contract tied NSA and security industry pioneer



Documents leaked by former NSA contractor Edward Snowden show that the NSA created and promulgated a flawed formula for generating random numbers to create a "back door" in encryption products, the New York Times reported in September. Reuters later reported that RSA became the most important distributor of that formula by rolling it into a software tool called Bsafe that is used to enhance security in personal computers and many other products.

Undisclosed until now was that RSA received $10 million in a deal that set the NSA formula as the preferred, or default, method for number generation in the BSafe software, according to two sources familiar with the contract. Although that sum might seem paltry, it represented more than a third of the revenue that the relevant division at RSA had taken in during the entire previous year, securities filings show.

 
Secret contract tied NSA and security industry pioneer 

The earlier disclosures of RSA's entanglement with the NSA already had shocked some in the close-knit world of computer security experts. The company had a long history of championing privacy and security, and it played a leading role in blocking a 1990s effort by the NSA to require a special chip to enable spying on a wide range of computer and communications products.
RSA, now a subsidiary of computer storage giant EMC Corp, urged customers to stop using the NSA formula after the Snowden disclosures revealed its weakness.
RSA and EMC declined to answer questions for this story, but RSA said in a statement: "RSA always acts in the best interest of its customers and under no circumstances does RSA design or enable any back doors in our products. Decisions about the features and functionality of RSA products are our own."
The NSA declined to comment.
The RSA deal shows one way the NSA carried out what Snowden's documents describe as a key strategy for enhancing surveillance: the systematic erosion of security tools. NSA documents released in recent months called for using "commercial relationships" to advance that goal, but did not name any security companies as collaborators.
The NSA came under attack this week in a landmark report from a White House panel appointed to review U.S. surveillance policy. The panel noted that "encryption is an essential basis for trust on the Internet," and called for a halt to any NSA efforts to undermine it.
Most of the dozen current and former RSA employees interviewed said that the company erred in agreeing to such a contract, and many cited RSA's corporate evolution away from pure cryptography products as one of the reasons it occurred.
But several said that RSA also was misled by government officials, who portrayed the formula as a secure technological advance.
"They did not show their true hand," one person briefed on the deal said of the NSA, asserting that government officials did not let on that they knew how to break the encryption.
STORIED HISTORY
Started by MIT professors in the 1970s and led for years by ex-Marine Jim Bidzos, RSA and its core algorithm were both named for the last initials of the three founders, who revolutionized cryptography. Little known to the public, RSA's encryption tools have been licensed by most large technology companies, which in turn use them to protect computersused by hundreds of millions of people.
At the core of RSA's products was a technology known as public key cryptography. Instead of using the same key for encoding and then decoding a message, there are two keys related to each other mathematically. The first, publicly available key is used to encode a message for someone, who then uses a second, private key to reveal it.
From RSA's earliest days, the U.S. intelligence establishment worried it would not be able to crack well-engineered public key cryptography. Martin Hellman, a former Stanford researcher who led the team that first invented the technique, said NSA experts tried to talk him and others into believing that the keys did not have to be as large as they planned.
The stakes rose when more technology companies adopted RSA's methods and Internet use began to soar. The Clinton administration embraced the Clipper Chip, envisioned as a mandatory component in phones and computers to enable officials to overcome encryption with a warrant.
RSA led a fierce public campaign against the effort, distributing posters with a foundering sailing ship and the words "Sink Clipper!"
A key argument against the chip was that overseas buyers would shun U.S. technology products if they were ready-made for spying. Some companies say that is just what has happened in the wake of the Snowden disclosures.
The White House abandoned the Clipper Chip and instead relied on export controls to prevent the best cryptography from crossing U.S. borders. RSA once again rallied the industry, and it set up an Australian division that could ship what it wanted.
"We became the tip of the spear, so to speak, in this fight against government efforts," Bidzos recalled in an oral history.
RSA EVOLVES
RSA and others claimed victory when export restrictions relaxed.
But the NSA was determined to read what it wanted, and the quest gained urgency after the September 11, 2001 attacks.
RSA, meanwhile, was changing. Bidzos stepped down as CEO in 1999 to concentrate on VeriSign, a security certificate company that had been spun out of RSA. The elite lab Bidzos had founded in Silicon Valley moved east to Massachusetts, and many top engineers left the company, several former employees said.
And the BSafe toolkit was becoming a much smaller part of the company. By 2005, BSafe and other tools for developers brought in just $27.5 million of RSA's revenue, less than 9% of the $310 million total.
"When I joined there were 10 people in the labs, and we were fighting the NSA," said Victor Chan, who rose to lead engineering and the Australian operation before he left in 2005. "It became a very different company later on."
By the first half of 2006, RSA was among the many technology companies seeing the U.S. government as a partner against overseas hackers.
New RSA Chief Executive Art Coviello and his team still wanted to be seen as part of the technological vanguard, former employees say, and the NSA had just the right pitch. Coviello declined an interview request.
An algorithm called Dual Elliptic Curve, developed inside the agency, was on the road to approval by the National Institutes of Standards and Technology as one of four acceptable methods for generating random numbers. NIST's blessing is required for many products sold to the government and often sets a broader de facto standard.
RSA adopted the algorithm even before NIST approved it. The NSA then cited the early use of Dual Elliptic Curve inside the government to argue successfully for NIST approval, according to an official familiar with the proceedings.
RSA's contract made Dual Elliptic Curve the default option for producing random numbers in the RSA toolkit. No alarms were raised, former employees said, because the deal was handled by business leaders rather than pure technologists.
"The labs group had played a very intricate role at BSafe, and they were basically gone," said labs veteran Michael Wenocur, who left in 1999.
Within a year, major questions were raised about Dual Elliptic Curve. Cryptography authority Bruce Schneier wrote that the weaknesses in the formula "can only be described as a back door."
After reports of the back door in September, RSA urged its customers to stop using the Dual Elliptic Curve number generator.
But unlike the Clipper Chip fight two decades ago, the company is saying little in public, and it declined to discuss how the NSA entanglements have affected its relationships with customers.

The White House, meanwhile, says it will consider this week's panel recommendation that any efforts to subvert cryptography be abandoned.
Read more ...

Christopher Burgess

Christopher Burgess

Christopher Burgess (@burgessct) is the CEO, President and Co-Founder of Prevendra. Prior to Prevendra, Burgess served as the Chief Security Officer, President Public Sector and Chief Operating Officer (2011-2013) of Atigeo. He also previously served as the Senior Security Advisor to the Chief Security Officer of Cisco, where he focused on intellectual property strategies. He served 30+ years within the CIA and co-authored the book, “Secrets Stolen, Fortunes Lost, Preventing Intellectual Property Theft and Economic Espionage in the 21st Century” (Syngress, March 2008). His CSO magazine contributions are highlighted by his study “Nation States’ Espionage and Counterespionage, Overview of the 2007 Global Economic Espionage Landscape.”
Read more ...

Security firm RSA took millions from NSA: report

The National Security Agency paid $10 million to the security firm RSA to implement intentionally flawed encryption, according to a new report.
An RSA SecurID key fob

What's an encryption backdoor cost? When you're the NSA, apparently the fee is $10 million.
Intentional flaws created by the National Security Agency in RSA's encryption tokens werediscovered in September, thanks to documents released by whistleblower Edward Snowden. It has now been revealed that RSA was paid $10 million by the NSA to implement those backdoors, according to a new report in Reuters.
Related stories:

In most-anticipated SXSW talk in years, Snowden fires up Austin
WikiLeaks' Julian Assange: NSA critics got lucky because agency had no PR strategy
Kill the Snowden interview, congressman tells SXSW
Edward Snowden to speak at South by Southwest
Klocwork: Our source code analyzer caught Apple's 'gotofail' bug

Two people familiar with RSA's BSafe software told Reuters that the company had received the money in exchange for making the NSA's cryptographic formula as the default for encrypted key generation in BSafe.
"Now we know that RSA was bribed," said security expert Bruce Schneier, who has been involved in the Snowden document analysis. "I sure as hell wouldn't trust them. And then they made the statement that they put customer security first," he said.
RSA, now owned by computer storage firm EMC Corp, has a long history of entanglement with the government. In the 1990s, the company was instrumental in stopping a government plan to include a chip in computers that would've allowed the government to spy on people.
It has also had its algorithms hacked before, as has RSA-connected VeriSign.
The new revelation is important, Schneier said, because it confirms more suspected tactics that the NSA employs.
"You think they only bribed one company in the history of their operations? What's at play here is that we don't know who's involved," he said.
Other companies that build widely-used encryption apparatus include Symantec, McAfee, and Microsoft. "You have no idea who else was bribed, so you don't know who else you can trust," Schneier said.
In a statement issued Sunday, RSA said it "categorically" denied recent reports.
"We have worked with the NSA, both as a vendor and an active member of the security community. We have never kept this relationship a secret and in fact have openly publicized it," the company said in a statement. "Our explicit goal has always been to strengthen commercial and government security."

The statement goes on to rebut a number of claims, including that the company knowingly introduced a flawed numbers generator into its encryption libraries.
Read more ...
THam khảo: Đầu thu DVB T2 | giàn phơi, lắp đặt giàn phơi quần áo hay giá giàn phơi thông minh tốt nhất cả nước