Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×
Electronic Frontier Foundation

Submission + - Warrantless wiretapping cases at the 9th Circuit (eff.org)

sunbird writes: The Electronic Frontier Foundation argued several critical cases yesterday before the Ninth Circuit Court of Appeals. Both Hepting v. AT&T and Jewel v. National Security Agency raise important questions regarding whether the NSA's warrantless wiretapping program (pdf summary of evidence) disclosed by whistleblower Mark Klein and implemented by AT&T and other telecoms, violates the Fourth Amendment to the U.S. Constitution. The full text of the Klein declaration and redacted exhibits are publicly available (pdf). This issue has been previously discussed here (1 2 3 4). The Klein evidence establishes that AT&T cut into the fiber optic cables in San Francisco to route a complete copy of internet and phone traffic to the "SG3" secure room operated by the NSA. The trial court dismissed the Hepting lawsuit (pdf order) based on the 2008 Congressional grant of immunity to telecoms. Similarly, the trial court in Jewel dismissed (pdf order) the lawsuit against the government agencies and officials based on the state secrets privilege. Both cases were argued together before the same panel of judges. The audio of the oral argument will be available after 12noon PT today.

Submission + - Man Faces 75 Year Sentence For Recording Police (youtube.com) 3

esocid writes: 42-year-old Michael Allison of Illinois could spend the rest of his life in prison for recording police in public. He faces five counts of eavesdropping, a class one felony. The Illinois Assistant Attorney General has joined the case and told the judge that citizens do not have the constitutional right to record police.

Comment Re:no more shopping in pakistan for me (Score 1) 351

Not so fast. Recall that India has implemented a similar regulation. Remember the whole dispute with RIM a while back? From the linked article:

the ISP license also bans internet providers from deploying 'bulk encryption' and further restricts the level of encryption for individuals, groups or organisations to a key length of only 40 bits in symmetric key algorithms or equivalents. Such weak encryption is easily broken, highly insecure and not suitable for e-commerce or any other sensitive applications. For the use of encryption equipment stronger than 40 bits, individuals, groups or organisations are required to obtain prior written permission and to deposit the decryption key, split into two parts, with the Department of Telecommunications.

Comment Re:Pakistan is NOT benning encryption (Score 2) 351

IANANE, but the regulation does not appear to be as limited as you suggest. Part II, Section 4, Clause 5 states:

All landing station and infrastructure licensee(s) shall establish a Monitoring System with its interface to the Authority . . . for the purpose of monitoring of telecommunications traffic (voice and data) within one hundred and twenty (120) days . . . .

And later on in clause (6) it requires each system to have "the following features:"

Capability to monitor, control, measure and record traffic in real-time

The clause you are referring to (and the only reference to encryption) occurs on the next page:

The Licensee(s) and Access Provider shall ensure that signaling information is uncompressed, unencrypted, and not formatted in a manner which the installed monitoring system is unable to decipher using installed capabilities.

But the limitation of this clause to signaling information seems to conflict with the earlier statement that the monitoring system must be capable of recording voice and data traffic in real time. I suppose you could argue that turning over the encrypted stream is sufficient, but I wouldn't want to hang my hat on that.

It'll be interesting to see how this is enforced. My guess will be that if they take the position that it applies to VPNs, it will not be enforced against the foreign visitor. There are many internet cafes in Pakistan and many hotels with internet service so there would be a huge logistical problem to enforce it. Sadly, Pakistanis and long-term ex-pats who use a VPN from their home or office could be targeted, especially if they are government opponents or dissidents.

Comment Re:This is unacceptable (Score 5, Informative) 840

I've always considered Egypt to be on of the more progressive muslim states

Whaaaaat? Egypt is ruled by a dictator that tolerates no dissent. There has been a state of emergency there for 44 years! Let's see, where to start. In 2009, the U.S. Department of State Human Rights report had this to say:

Police, security personnel, and prison guards often tortured and abused prisoners and detainees, sometimes in cases of detentions under the Emergency Law, which authorizes incommunicado detention indefinitely, subject to a judge's ruling.

and

Police and the SSIS reportedly employed torture methods such as stripping and blindfolding victims; suspending victims by the wrists and ankles in contorted positions or from a ceiling or door frame with feet just touching the floor; beating victims with fists, whips, metal rods, or other objects; using electric shocks; dousing victims with cold water; sleep deprivation; and sexual abuse, including sodomy. There was evidence that security officials sexually assaulted some victims or threatened to rape them or their family members. Human rights groups reported that the lack of legally required written police records often effectively blocked investigations.

It just goes on and on. And, keep in mind, the U.S. DOS reports tend to be very conservative, so when this stuff ends up in a DOS report, things on the ground are much, much worse.

Comment Not necessarily (Score 4, Interesting) 487

Well, how about we move away from certificate authorities. Impossible, you say? Not so.

Enter the Monkeysphere, a project that leverages the GPG web of trust to build trust paths for secure browsing (among other uses). From the site:

When you direct the browser to an https site using the Monkeysphere plugin and validation agent, if the certificate presented by the site does not pass the default browser validation (using standard, hierarchical X.509), the certificate and site URL are passed to the validation agent. The agent then checks the public keyservers for keys with UIDs matching the site url (e.g. https://zimmermann.mayfirst.org./ If there is a trust path to that key, according to your own OpenPGP trust designations, the certificate is considered valid, and a browser 'security exception' is put in place to allow connections to the site.

XBox (Games)

Anatomy of an Achievement 157

Whether they annoy you or fulfill your nerdy collection habit, achievements have spread across the gaming landscape and are here to stay. The Xbox Engineering blog recently posted a glimpse into the creation of the Xbox 360 achievement system, discussing how achievements work at a software level, and even showing a brief snippet of code. They also mention some of the decisions they struggled with while creating them: "We are proud of the consistency you find across all games. You have one friends list, every game supports voice chat, etc. But we also like to give game designers room to come up with new and interesting ways to entertain. That trade-off was at the heart of the original decision we made to not give any indication that a new achievement had been awarded. Some people argued that gamers wouldn't want toast popping up in the heat of battle and that game designers would want to use their own visual style to present achievements. Others argued for consistency and for reducing the work required of game developers. In the end we added the notification popup and its happy beep, which turned out to be the right decision, but for a long time it was anything but obvious."
Yahoo!

Submission + - Law enforcement guidebooks leaked

sunbird writes: "Buried in comments to a blogger's post about his research regarding Sprint's release of GPS records to law enforcement are the law enforcement guidance manuals issued by yahoo (pdf), facebook (pdf), and myspace. (pdf) Each provides helpful hints for law enforcement regarding the specific data available (some of which may be obtained with a mere subpoena and without any judicial scrutiny), and even sample request language to use in different circumstances. According to the manual, facebook retains IP information about its users for 30 days and has an application called "Neoprint" to deliver a handy packet of information about subscribers, including profile contact information, mini-feed, friend listing (with friend's facebook ID), group listing and messages. There is little oversight of this practice in the U.S. because the Department of Justice does not report the number of pen registers issued, notwithstanding a 1999 law requiring reports, and there is no reporting requirement for court orders issued under the Stored Communications Act."

Comment Oh, right because gun license = law abiding (Score 1) 629

I care deeply about personal privacy for the same reason I care deeply about gun rights - chances are that I will never carry a weapon in my life, but our society as a whole is made safer and more resilient by the fact that law-abiding citizens can own and use them in self defense.

Ummm, yeah, the shooter who killed 14 in NY state "had a permit for two handguns and wore body armor, indicating he was prepared for a confrontation with police."
source.

Media

Submission + - Technology and resistance in Pakistan (rabble.ca)

sunbird writes: "I'm living in Pakistan right now working at the Human Rights Commission of Pakistan, an NGO, and despite what you might think from media coverage in the west, there is still significant resistance to Musharraf's second coup. One author is describing the critical role played by technology and media in organizing efforts here, especially among newly-politicized students. Organizers here are using SMSs, blogs, and flash protests (1 | 2) to confound and evade the police. Some of the most current information about events here is often found on blogs (See 1 | 2 | 3 | 4 | 5 | 6); although the Pakistani English-language press (1 | 2 | 3 | 4) has done a decent job covering the crisis too, notwithstanding draconian media restrictions that forbid publication of anything that "brings into ridicule or disrepute" the president."

Slashdot Top Deals

Get hold of portable property. -- Charles Dickens, "Great Expectations"

Working...