Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Tuesday, July 12, 2011

A Stronger Net Security System Is Deployed - New York Times

“It won’t matter where you are in the world or who you are in the world, you’re going to be able to authenticate everyone and everything,” said Dan Kaminsky, an independent network security researcher who is one of the engineers involved in the project.

The Singapore event included an elaborate technical ceremony to create and then securely store numerical keys that will be kept in three hardened data centers there, in Zurich and in San Jose, Calif. The keys and data centers are working parts of a technology known as Secure DNS, or DNSSEC. DNS refers to the Domain Name System, which is a directory that connects names to numerical Internet addresses. Preliminary work on the security system had been going on for more than a year, but this was the first time the system went into operation, even though it is not quite complete.

The three centers are fortresses made up of five layers of physical, electronic and cryptographic security, making it virtually impossible to tamper with the system. Four layers are active now. The fifth, a physical barrier, is being built inside the data center.

The technology is viewed by many computer security specialists as a ray of hope amid the recent cascade of data thefts, attacks, disruptions and scandals, including break-ins at Citibank, Sony, Lockheed Martin, RSA Security and elsewhere. It allows users to communicate via the Internet with high confidence that the identity of the person or organization they are communicating with is not being spoofed or forged.

Internet engineers like Mr. Kaminsky want to counteract three major deficiencies in today’s Internet. There is no mechanism for ensuring trust, the quality of software is uneven, and it is difficult to track down bad actors.

One reason for these flaws is that from the 1960s through the 1980s the engineers who designed the network’s underlying technology were concerned about reliable, rather than secure, communications. That is starting to change with the introduction of Secure DNS by governments and other organizations.

The event in Singapore capped a process that began more than a year ago and is expected to be complete after 300 so-called top-level domains have been digitally signed, around the end of the year. Before the Singapore event, 70 countries had adopted the technology, and 14 more were added as part of the event. While large countries are generally doing the technical work to include their own domains in the system, the consortium of Internet security specialists is helping smaller countries and organizations with the process.

The United States government was initially divided over the technology. The Department of Homeland Security included the .gov domain early in 2009, while the Department of Commerce initially resisted including the .us domain because some large Internet corporations opposed the deployment of the technology, which is incompatible with some older security protocols.

Internet security specialists said the new security protocol would initially affect Web traffic and e-mail. Most users should be mostly protected by the end of the year, but the effectiveness for a user depends on the participation of the government, Internet providers and organizations and businesses visited online. Eventually the system is expected to have a broad effect on all kinds of communications, including voice calls that travel over the Internet, known as voice-over-Internet protocol.

“In the very long term it will be voice-over-I.P. that will benefit the most,” said Bill Woodcock, research director at the Packet Clearing House, a group based in Berkeley, Calif., that is assisting Icann, the Internet governance organization, in deploying Secure DNS.

Secure DNS makes it possible to make phone calls over the Internet secure from eavesdropping and other kinds of snooping, he said.

Security specialists are hopeful that the new Secure DNS system will enable a global authentication scheme that will be more impenetrable and less expensive than an earlier system of commercial digital certificates that proved vulnerable in a series of prominent compromises.

The first notable case of a compromise of the digital certificates — electronic documents that establish a user’s credentials in business or other transactions on the Web — occurred a decade ago when VeriSign, a prominent vendor of the certificates, mistakenly issued two of them to a person who falsely claimed to represent Microsoft.

Last year, the authors of the Stuxnet computer worm that was used to attack the Iranian uranium processing facility at Natanz were able to steal authentic digital certificates from Taiwanese technology companies. The certificates were used to help the worm evade digital defenses intended to block malware.

In March, Comodo, a firm that markets digital certificates, said it had been attacked by a hacker based in Iran who was trying to use the stolen documents to masquerade as companies like Google, Microsoft, Skype and Yahoo.

“At some point the trust gets diluted, and it’s just not as good as it used to be,” said Rick Lamb, the manager of Icann’s Secure DNS program.

The deployment of Secure DNS will significantly lower the cost of adding a layer of security, making it more likely that services built on the technology will be widely available, according to computer network security specialists. It will also potentially serve as a foundation technology for an ambitious United States government effort begun this spring to create a system to ensure “trusted identities” in cyberspace.


View the original article here

StartSSL Suspends Certificate Services Following Security Breach - Web Host Industry Review


Web Host Industry Review

StartSSL Suspends Certificate Services Following Security Breach
Web Host Industry Review
(WEB HOST INDUSTRY REVIEW) -- Certificate authority StartSSL (www.startssl.com) experienced a security breach on June 15, the company said in an advisory posted on its website. Operated by Israel-based StartCom ...

and more »

View the original article here

Friday, July 8, 2011

Rojadirecta Sues US Government, Homeland Security & ICE Over Domain Seizure - Techdirt

Puerto 80 does not host any infringing material on the websites which operate under the subject domain names... In the same way a search engine or other site which aggregates links to existing material on the Internet, Rojadirecta provides an index of links to streams of sporting events that can already be found on the Internet through a search for those sites or simply by typing the URL for the site directly. Id. Such activity does not constitute direct copyright infringement, much less criminal infringement. See supra, at note 8. Indeed, United States Senator Ron Wyden (D-Or) made this point in a letter he wrote to ICE Director John Morton and Attorney General Holder expressing concern over the government?s seizure of the subject domain names....

Puerto 80?s operation of the Rojadirecta site does not constitute contributory infringement because the subject domain names are capable of?and are, in fact, used for? substantial non-infringing uses. Sony Corp. v. Universal City Studios, Inc., 464 U.S. 417, reh?g denied, 465 U.S. 1112 (1984); Arista Records LLC v. Lime Group LLC, 715 F. Supp. 2d 481, 517-18 (S.D.N.Y. 2010) (summary judgment inappropriate where material fact existed as to whether file-sharing program, which was ?used overwhelmingly for infringement,? is ?capable of substantial non-infringing uses.?).

Nor is Rojadirecta a site devoted simply to linking to such streams. In addition to providing a forum for discussion on sports, politics, and a variety of other topics, the Rojadirecta site enables users to post links to authorized sports broadcasts. For example, on Saturday, February 12, 2011, the Rojadirecta site (hosted on the rojadirecta.es domain name) provided a link to ?9:30am Hockey (NHL): Los Angeles ? Washington.?... Clicking on this link opened a new window for the Yahoo! sports website for the National Hockey League, and provided a live stream of the match between the Los Angeles Kings and Washington Capitals. Id.

Nor does Puerto 80?s operation of the Rojadirecta site constitute vicarious liability because it does not have ?a right and ability to supervise that coalesce[s] with an obvious and direct financial interest in the exploitation of copyrighted materials.? Softel, Inc. v. Dragon Med. & Sci. Commc?ns Inc., 118 F.3d 955, 971 (2d Cir. 1997) (quoting Shapiro, Bernstein & Co. v. H.L. Green Co., 316 F.2d 304, 307 (2d Cir. 1963) (emphasis added)). Puerto 80 does not receive any revenue that is derived from specific content hosted on, or streamed by, the sites to which it links.... In other words, Puerto 80 does not receive any revenue from any site to which a user can link from the subject domain names based upon the content of that site. Id. To the extent there is any site to which Rojadirecta links that contains infringing material, Puerto 80 receives no specific financial benefit from a user clicking through to that site and viewing such content.... Because Puerto 80?s revenues are not tied to whether or not infringing material is linked to or accessed, the government cannot show that Puerto 80 has a ?direct financial interest in the exploitation of copyrighted materials? which ?coalesce[s] with? any right or ability to supervise what is linked to on the site. See Artists Music, Inc. v. Reed Publ?g (USA), Inc., Nos. 93 civ. 3428(JFK), 73163, 1994 WL 191643, at *6 (S.D.N.Y. May 17, 1994) (direct financial benefit not established where defendant leased space at a trade show for a fixed fee to exhibitors who played infringing music, but defendant?s revenues were not dependant on whether exhibitors actually played music or what they played); Viacom Int?l Inc. v. YouTube, Inc., 718 F. Supp. 2d 514, 521 (S.D.N.Y. 2010) (in DMCA safe-harbor context, ?financial benefit directly attributable to the infringing activity? not established ?where the infringer makes the same kind of payment as non-infringing users of the provider?s service?) (quoting Senate Judiciary Committee Report and the House Committee on Commerce Report, H.R. Rep. No. 105-551, pt. 2 (1998)).


View the original article here