Search This Blog

Showing posts with label site. Show all posts
Showing posts with label site. Show all posts

Tuesday, September 4, 2012

A Word from Our Sponsor



Adobe Dreamweaver

Wednesday, August 22, 2012

Web Sites Accused of Collecting Data on Children


The following is an excerpt from an article in



The New York Times
Wednesday, August 22, 2012

Web Sites Accused of Collecting Data on Children

By NATASHA SINGER

A coalition of nearly 20 children’s advocacy, health and public interest groups plans to file complaints with the Federal Trade Commission on Wednesday, asserting that some online marketing to children by McDonald’s and four other well-known companies violates a federal law protecting children’s privacy.

The law, the Children’s Online Privacy Protection Act, requires Web site operators to obtain verifiable consent from parents before collecting personal information about children under age 13. But, in complaints to the F.T.C., the coalition says six popular Web sites aimed at children have violated that law by encouraging children who play brand-related games or engage in other activities to provide friends’ e-mail addresses — without seeking prior parental consent.

For more, visit www.nytimes.com.

Wednesday, March 21, 2012

U.S. Stores Learn the Ropes of Shipping to Foreign Shoppers

Excerpt from an article in

The New York Times
Wednesday, March 21, 2012

U.S. Stores Learn the Ropes of Shipping to Foreign Shoppers

By STEPHANIE CLIFFORD

Macy’s has long marketed itself as a shopping destination for visitors to the United States. It offers a savings card with a 10 percent discount for foreign shoppers, custom programs for tour groups and travel agents, and a tourism Web site that lists shopping events and recommended hotels near Macy’s flagship stores.

But only last year did Macys.com — which shoppers worldwide can look at — offer overseas shipping.

“We were getting international traffic,” said Kent Anderson, president of Macys.com. “It was coming whether we were offering them, frankly, any realistic way to interact with the site or not.”

Macy’s is one of several retailers trying to extend its international presence to its Web operations by shipping overseas. In the last year, Williams-Sonoma, J. Crew, AĆ©ropostale, Crate and Barrel and Lane Bryant have added international shipping to their Web sites, while Ann Taylor and Neiman Marcus are working on it.

Some of the retailers are meeting existing or anticipated overseas demand, while others are testing the waters before opening stores in other countries. Either way, they are discovering that shipping beyond the United States is not a simple undertaking.

“Typically the guys we’re talking to start off thinking they can toss it in a box and give it to U.P.S. or FedEx and hope it gets there,” said Michael DeSimone, chief executive of FiftyOne, a technology company that helps retailers add international shipping capabilities.

But there are problems with ordering systems, customs and postal fees, he said.

For example, many retailers do not have software in their warehouse management systems that recognizes foreign postal codes, which — unlike those in the United States — do not always have five digits.

“It sounds like a really stupid reason not to sell internationally,” Mr. DeSimone said, “but I can’t tell you how many times I’ve heard this was the biggest roadblock.”

The appeal to reaching customers in other countries is based largely on the popularity of mobile phone sales overseas. Forrester Research expects online retail sales in the Western Europe, Asia Pacific and Latin America regions to increase 67 percent from 2011 to 2015, compared with 42 percent for the United States.

And traffic to American Web sites from international visitors is already high.

Tuesday, March 20, 2012

AT&T Invests > $600 M in Kentucky

AT&T Invests More Than $600 Million in Kentucky from 2009 through 2011 to Improve Local Networks
Company Builds New Cell Sites, Boosts Capacity and Adds Fiber Optics to Enhance Networks
Louisville, Kentucky, March 20, 2012
AT&T* invested more than $600 million in its Kentucky wireless and wireline networks from 2009 through 2011 with a focus on improving the company’s mobile Internet coverage and overall performance of its networks.
During 2011, AT&T made more than 900 wireless network upgrades in four key categories in Kentucky.
These enhancements include:
·         Activating nearly 45 new cell sites or towers to improve network coverage.
·         Deploying faster fiber-optic connections to more than 275 cell sites. Combined with HSPA+ technology, these deployments enable 4G speeds**.
·         Adding capacity or an extra layer of frequency to cell sites – like adding lanes to a highway – with the addition of more than 425 of these layers, or “carriers.”
·         Upgrading nearly 150 cell sites to provide fast mobile Internet speeds.
“More developed wireless networks help drive economic growth and stimulate jobs by equipping Kentucky businesses to meet the customer demands of today and tomorrow,” said Mike Mangeot, president and CEO of the Kentucky Association for Economic Development. “By providing Kentuckians with faster speeds, greater reliability and better coverage, we improve not only the quality of life, but we better enable the innovation that will be required for Kentucky to compete in a global economy.”
AT&T has invested more than $95 billion nationwide in its wireless and wireline networks over the past five years, and invested $20 billion in 2011 to improve and expand its networks.
“The jobs of the future will require access to a robust wireless infrastructure in both rural and urban areas and this investment is a significant step towards making that happen,” said Kentucky Chamber of Commerce President Dave Adkisson.  “As the number of Kentuckians who rely on wireless devices continues to grow, our Commonwealth must do all it can to enable access to the new technologies needed for future innovation and job growth.” 
“Thanks to the vision and business-friendly approach of the General Assembly, Kentucky has a strong regulatory environment for telecom infrastructure investment,” said AT&T Kentucky President Mary Pat Regan. “As our legislators seek to move Kentucky forward in 2012, we hope they will build upon their past success and update our telecom laws to encourage even more capital investment across the Commonwealth.”
Regan said her company’s local investment creates many advantages for the people of Kentucky. “Arecent study by the NDN think tank found that innovation has driven continued investments to upgrade the mobile Internet infrastructure in America, including transitions from 2G to 3G and now from 3G to 4G,” said Regan. “The world is going wireless, and this technology is enabling, empowering, enriching and enhancing lives at work, at play and everywhere in between. This investment has spurred significant new job creation and growth across all sectors of the economy and has fostered employment for U.S. workers.”
“Our goal is to deliver a network experience that mobilizes everything for customers. The ongoing investment we’re making in Kentucky is designed to increase coverage, reliability and to provide advanced services to our customers,” said Chris Percy, vice president and general manager, AT&T Mobility and Consumer Markets for Kentucky and Tennessee.
CNN Money recently recognized AT&T for enhancing its wireless network. Last year, AT&T completed 150,000 network enhancements across the country, more than triple the year before, giving customers more capacity and faster speeds, as well as improving 3G dropped-call performance by 25 percent.
 AT&T plans to support the build or upgrade of thousands of cell sites nationwide to increase network speed, coverage and reliability for both mobile voice and Internet services. In addition, AT&T plans to install additional radio “carriers” at thousands of cell sites nationally, enabling new layers of spectrum capacity to carry larger volumes of mobile Internet traffic. Additional capacity helps support rising mobile data traffic volumes, which continue to increase at a rapid pace.
AT&T operates the nation’s largest Wi-Fi network*** with nearly 30,000 hotspots in the U.S. and provides access to nearly 190,000 hotspots globally through roaming agreements. Most AT&T smartphone customers get access to our entire national Wi-Fi network at no additional cost, and Wi-Fi usage doesn’t count against customers’ monthly wireless data plans.
For more information about AT&T’s coverage in Kentucky or anywhere in the United States, consumers can visit the AT&T Coverage Viewer. Using the online tool, AT&T customers can measure coverage quality of coverage from a street address, intersection, ZIP code or even a landmark. 

For updates on the AT&T wireless network, please visit the
 AT&T network news page.
*AT&T products and services are provided or offered by subsidiaries and affiliates of AT&T Inc. under the AT&T brand and not by AT&T Inc.
**4G speeds delivered by HSPA+ with enhanced backhaul. Available in limited areas. Availability increasing with ongoing backhaul deployment. 4G device required. Learn more at att.com/network.
*** Largest based on company branded and operated hotspots. Access includes AT&T Wi-Fi Basic.  A Wi-Fi enabled device required. Other restrictions apply. See www.attwifi.com for details and locations.

Many Sites Chart a New Course as Google Expands Fees

Excerpt from an article in

The New York Times
Tuesday, March 20, 2012

Many Sites Chart a New Course as Google Expands Fees

By QUENTIN HARDY

SAN FRANCISCO — When it comes to offering online maps to their users, some companies have been leaving Google Maps and setting out for less familiar territory.

In the seven years since it was introduced, Google’s offering of street maps, satellite photos and street-level views has become the dominant player in the world of online mapping, displacing earlier entrants like AOL’s MapQuest. According to comScore, 71 percent of the 91.7 million people in the United States who looked at maps online in February used Google Maps.

There are signs, however, that Google’s dominance is under assault — and the company’s own moves may have something to do with this.

Many sites incorporate Google Maps into their own pages, whether to pinpoint real estate listings or pothole problems. Google was already charging the biggest users of the service fees that could run into six figures a year. But last October it announced that it would start charging smaller Web sites when their users started generating an average of 25,000 map views a day over a quarter. Many independent Web developers, upon whom Google relies to make its products popular, rebelled at the change.

“If you are a site just looking to put a pizzeria on a map, it’s no big deal, but if you are trying to put a brand around your mapping, it’s a big deal,” said James Fee, chief evangelist at WeoGeo, which provides location data. “Google says it will affect a very small number of users, but I have heard it will touch 30 or 40 percent of people who really depend on maps for their business. It could cost you tens of thousands of dollars a month.”

In late February, Foursquare, the social media location service, said that on its Web site it would move from Google Maps to data from OpenStreetMap, a user-contributed map service that is created and managed much like Wikipedia. In a blog post, Foursquare said Google’s price increases had prompted the change.

Apple’s new version of its iPhoto application for the iPhone and the iPad also uses data from OpenStreetMap, though Apple uses many mapping sources, particularly Google, in its other products. Nestoria, a real estate search engine, also said it was leaving Google for OpenStreetMap because of the prices.

According to comScore, OpenStreetMap itself still has a minuscule amount of Web traffic. Google Maps had 65 million users in February, a 16 percent increase from a year earlier. MapQuest had 35 million, a 13 percent drop. Microsoft’s Bing Maps came in third with nine million users, an 18 percent gain.

Tuesday, March 6, 2012

Six Hackers Charged

Six Hackers in the United States and Abroad Charged for Crimes Affecting Over One Million Victims 
Four Principal Members of “Anonymous” and “LulzSec” Charged with Computer Hacking and Fifth Member Pleads Guilty; “AntiSec” Member also Charged with Stealing Confidential Information from Approximately 860,000 Clients and Subscribers of Stratfor

U.S. Attorney’s OfficeMarch 06, 2012
  • Southern District of New York(212) 637-2600
Five computer hackers in the United States and abroad were charged today, and a sixth pled guilty, for computer hacking and other crimes. The six hackers identified themselves as aligned with the group Anonymous, which is a loose confederation of computer hackers and others, and/or offshoot groups related to Anonymous, including “Internet Feds,” “LulzSec,” and “AntiSec.”
RYAN ACKROYD, a/k/a “kayla,” a/k/a “lol,” a/k/a “lolspoon”; JAKE DAVIS, a/k/a “topiary,” a/k/a “atopiary”; DARREN MARTYN, a/k/a “pwnsauce,” a/k/a “raepsauce,” a/k/a “networkkitten”; and DONNCHA O’CEARRBHAIL, a/k/a “palladium,” who identified themselves as members of Anonymous, Internet Feds, and/or LulzSec, were charged in an indictment unsealed today in Manhattan federal court with computer hacking conspiracy involving the hacks of Fox Broadcasting Company, Sony Pictures Entertainment, and the Public Broadcasting Service (“PBS”). O’CEARRBHAIL is also charged in a separate criminal complaint with intentionally disclosing an unlawfully intercepted wire communication.
HECTOR XAVIER MONSEGUR, a/k/a “Sabu,” a/k/a “Xavier DeLeon,” a/k/a “Leon,” who also identified himself as a member of Anonymous, Internet Feds, and LulzSec, pled guilty on August 15, 2011 in U.S. District Court to a 12-count information charging him with computer hacking conspiracies and other crimes. MONSEGUR’S information and guilty plea were unsealed today. The crimes to which MONSEGUR pled guilty include computer hacking conspiracy charges initially filed in the Southern District of New York. He also pled guilty to the following charges: a substantive hacking charge initially filed by the U.S. Attorney’s Office in the Eastern District of California related to the hacks of HBGary, Inc. and HBGary Federal LLC; a substantive hacking charge initially filed by the U.S. Attorney’s Office in the Central District of California related to the hack of Sony Pictures Entertainment and Fox Broadcasting Company; a substantive hacking charge initially filed by the U.S. Attorney’s Office in the Northern District of Georgia related to the hack of Infragard Members Alliance; and a substantive hacking charge initially filed by the U.S. Attorney’s Office in the Eastern District of Virginia related to the hack of PBS, all of which were transferred to the Southern District of New York, pursuant to Rule 20 of the Federal Rules of Criminal Procedure, in coordination with the Computer Crime and Intellectual Property Section (“CCIPS”) in the Justice Department’s Criminal Division.
Late yesterday, JEREMY HAMMOND, a/k/a “Anarchaos,” a/k/a “sup_g,” a/k/a “burn,” a/k/a “yohoho,” a/k/a “POW,” a/k/a “tylerknowsthis,” a/k/a “crediblethreat,” who identified himself as a member of AntiSec, was arrested in Chicago, Illinois and charged in a criminal complaint with crimes relating to the December 2011 hack of Strategic Forecasting, Inc. (“Stratfor”), a global intelligence firm in Austin, Texas, which may have affected approximately 860,000 victims. In publicizing the Stratfor hack, members of AntiSec reaffirmed their connection to Anonymous and other related groups, including LulzSec. For example, AntiSec members published a document with links to the stolen Stratfor data titled, “Anonymous Lulzxmas rooting you proud” on a file sharing website.
The following allegations are based on the indictment, the information, the complaints, and statements made at MONSEGUR’s guilty plea:
Hacks by Anonymous, Internet Feds, and LulzSec
Since at least 2008, Anonymous has been a loose confederation of computer hackers and others. MONSEGUR and other members of Anonymous took responsibility for a number of cyber attacks between December 2010 and June 2011, including denial of service (“DoS”) attacks against the websites of Visa, MasterCard, and PayPal, as retaliation for the refusal of these companies to process donations to Wikileaks, as well as hacks or DoS attacks on foreign government computer systems.
Between December 2010 and May 2011, members of Internet Feds similarly waged a deliberate campaign of online destruction, intimidation, and criminality. Members of Internet Feds engaged in a series of cyber attacks that included breaking into computer systems, stealing confidential information, publicly disclosing stolen confidential information, hijacking victims’ e-mail and Twitter accounts, and defacing victims’ Internet websites. Specifically, ACKROYD, DAVIS, MARTYN, O’CEARRBHAIL, and MONSEGUR, as members of InternetFeds, conspired to commit computer hacks including: the hack of the website of Fine Gael, a political party in Ireland; the hack of computer systems used by security firms HBGary, Inc. and its affiliate HBGary Federal, LLC, from which Internet Feds stole confidential data pertaining to 80,000 user accounts; and the hack of computer systems used by Fox Broadcasting Company, from which Internet Feds stole confidential data relating to more than 70,000 potential contestants on “X-Factor,” a Fox television show.
In May 2011, following the publicity that they had generated as a result of their hacks, including those of Fine Gael and HBGary, ACKROYD, DAVIS, MARTYN, and MONSEGUR formed and became the principal members of a new hacking group called “Lulz Security” or “LulzSec.” Like Internet Feds, LulzSec undertook a campaign of malicious cyber assaults on the websites and computer systems of various business and governmental entities in the United States and throughout the world. Specifically, ACKROYD, DAVIS, MARTYN, and MONSEGUR, as members of LulzSec, conspired to commit computer hacks including the hacks of computer systems used by the PBS, in retaliation for what LulzSec perceived to be unfavorable news coverage in an episode of the news program “Frontline”; Sony Pictures Entertainment, in which LulzSec stole confidential data concerning approximately 100,000 users of Sony’s website; and Bethesda Softworks, a video game company based in Maryland, in which LulzSec stole confidential information for approximately 200,000 users of Bethesda’s website.
The Stratfor Hack
In December 2011, HAMMOND conspired to hack into computer systems used by Stratfor, a private firm that provides governments and others with independent geopolitical analysis. HAMMOND and his co-conspirators, as members of AntiSec, stole confidential information from those computer systems, including Stratfor employees’ e-mails as well as account information for approximately 860,000 Stratfor subscribers or clients. HAMMOND and his co-conspirators stole credit card information for approximately 60,000 credit card users and used some of the stolen data to make unauthorized charges exceeding $700,000. HAMMOND and his co-conspirators also publicly disclosed some of the confidential information they had stolen.
The Hack of International Law Enforcement
In January 2012, O’CEARRBHAIL hacked into the personal e-mail account of an officer with Ireland’s national police service, the An Garda Siochana (the “Garda”). Because the Garda officer had forwarded work e-mails to a personal account, O’CEARRBHAIL learned information about how to access a conference call that the Garda, the FBI, and other law enforcement agencies were planning to hold on January 17, 2012 regarding international investigations of Anonymous and other hacking groups. O’CEARRBHAIL then accessed and secretly recorded the January 17 international law enforcement conference call, and then disseminated the illegally-obtained recording to others.
***
MONSEGUR, 28, of New York, New York, pled guilty to three counts of computer hacking conspiracy, five counts of computer hacking, one count of computer hacking in furtherance of fraud, one count of conspiracy to commit access device fraud, one count of conspiracy to commit bank fraud, and one count of aggravated identity theft. He faces a maximum sentence of 124 years and six months in prison.
ACKROYD, 23, of Doncaster, United Kingdom; DAVIS, 29, of Lerwick, Shetland Islands, United Kingdom; and MARTYN, 25, of Galway, Ireland, each are charged with two counts of computer hacking conspiracy. Each conspiracy count carries a maximum sentence of 10 years in prison.
O’CEARRBHAIL, 19, of Birr, Ireland, is charged in the indictment with one count of computer hacking conspiracy, for which he faces 10 years in prison. He is also charged in the complaint with one count of intentionally disclosing an unlawfully intercepted wire communication, for which he faces a maximum sentence of five years in prison.
HAMMOND, 27, of Chicago, Illinois, is charged with one count of computer hacking conspiracy, one count of computer hacking, and one count of conspiracy to commit access device fraud. Each count carries a maximum sentence of 10 years in prison.
DAVIS is separately facing criminal charges in the United Kingdom, which remain pending, and ACKROYD is being interviewed today by the Police Central e-crime Unit in the United Kingdom. O’CEARRBHAIL was arrested today by the Garda.
The case is being prosecuted by the U.S. Attorney’s Office for the Southern District of New York. The investigation was initiated and led by the FBI, and its New York Cyber Crime Task Force, which is a federal, state, and local law enforcement task force combating cybercrime, with assistance from the PCeU; a unit of New Scotland Yard’s Specialist Crime Directorate, SCD6; the Garda; the Criminal Division’s CCIPS; and the U.S. Attorneys’ Offices for the Eastern District of California, the Central District of California, the Northern District of Georgia, and the Eastern District of Virginia; as well as the Criminal Division’s Office of International Affairs.
The charges contained in the indictment and complaints are merely accusations, and the defendants are presumed innocent unless and until proven guilty.

Monday, March 5, 2012

The Bright Side of Being Hacked

Excerpt from an article in

The New York Times
Monday, March 05, 2012

The Bright Side of Being Hacked

By SOMINI SENGUPTA and NICOLE PERLROTH

SAN FRANCISCO — Hackers operating under the banner Anonymous have been poking a finger in the eye of one private company after another for two years now.

They steal files from inside corporate computer systems and occasionally, as in the case of Stratfor last week, dump company e-mail online for all to see.

The Stratfor hack, in which Anonymous claimed to have joined forces with WikiLeaks, drove home a clear lesson about the era of ubiquitous “hactivism,” or hacking as a form of protest.

Despite the arrests of dozens of suspected members of Anonymous and its offshoots worldwide, it is far from diminished. Nor have most of its corporate targets been irreparably damaged by the attacks.

Rather, what Anonymous has done, experts said at the big RSA computer security conference here last week, is raise the alarm about the unguarded state of corporate computer systems.

By and large, the Anonymous break-ins take advantage of gaping computer holes and gullible human beings. The hackers ferret out weak passwords and take advantage of unencrypted e-mail stashes. They persuade company employees — one is all it takes — to click on rogue Web sites or divulge a confidential piece of information, in an exercise known as social engineering.

“Anonymous is a wake-up call,” said Roger Cressey, senior vice president of Booz Allen Hamilton, a defense and intelligence contractor that was attacked by the group last summer. “Any company that is patting themselves on the back and saying that they’re not a target or not susceptible to attack is in complete and utter denial.”

More to the point, a company that is a target of Anonymous may also be the target of a far more potent adversary. The social engineering tactics that Anonymous members have repeatedly used are often similar to those used by criminal hackers and state-sponsored actors who penetrate company systems in order to steal valuable secrets, whether for monetary gain or competitive edge.

Sunday, February 26, 2012

Wearable Electronics

Excerpt from an article in The New York Times
Sunday, February 26, 2012

Wearable Electronics Are Making a Statement - Novelties

By ANNE EISENBERG

RHINESTONES, sequins and gold lamƩ can still add traditional glitter to evening wear. But if you really want to shine at your next dinner party, consider the sparkle that a jacket with light-emitting diodes or a corsage with fiber optics could provide.

Wearable electronics are starting to dress up gowns, handbags and even tuxedos, and not just in one-of-a-kind costumes worn by the likes of Fergie, Katy Perry, Lady Gaga or other divas.

For the rest of us, designers and others are starting to offer such merchandise online — giving it bling by way of conductive thread, sensors, batteries and small microprocessors. And daytime computerized wearables are on the way, like T-shirts and coats that can show full-length videos or use GPS to point you to your destination.

Moon Berlin, a German fashion label of the company Franken & Bruns, recently opened an online shop that sells chiffon dresses with white LEDs beneath the sheer fabric. The LEDs twinkle softly at first, then shine more intensely as the wearer moves, says Christian Bruns, co-owner of Franken & Bruns. (The batteries are good for 8 or more hours. You can always turn them off if want to save power.)

Already popular on the Web site are accessories like fiber-optic brooches and LED-illuminated clutch pocketbooks. And men’s dinner jackets with a touch of LED glitter are on the way, Mr. Bruns says.

If you want to try your own hand at creating a computerized, electronic glow, Adafruit Industries, a New York company that makes and sells kits and components, will soon introduce a small, wearable microprocessor called Flora to control LEDs or other electronic adornments. Becky Stern, who leads the company’s wearable electronics group, will develop projects and kits based on it for crafters.

Friday, February 17, 2012

New Web Site for Business

From USA.gov:


Today President Obama announced the launch of BusinessUSA, a virtual one-stop-shop that makes it easier for America's businesses to access the services and information they need to help them grow, hire, and export.

Get help starting, growing, and financing a business, or learn more about expanding your market and becoming more globally competitive through exporting.

Thursday, February 16, 2012

Pinterest, the Newest Social Media Site

Excerpt from an article in The New York Times
Thursday, February 16, 2012

Reviewing Pinterest, the Newest Social Media Site 

By DAVID POGUE

“OMG! Did you see Brad Pitt’s post on Digglr last night?”

“No, I was too busy cruising Cr.us.ta.ce.an. What did he say?”

“OMG, it was all over Regurgtatr!”

Have you ever had the sinking feeling that the online world is moving so fast that you’ll never catch up?

Every year, there’s another hot new online service, another drain into which to pour your time. Question: Once you’re on Facebook and Twitter and Foursquare and Google Plus and Tumblr and LinkedIn and Instagram and Reddit and Path — when, exactly, do you have time left over for a life?

Well, never mind. Incredibly, yet another free site has become white-hot popular, because it’s found yet another purpose not quite served by anyone else. It’s Pinterest.com, which recently laid claim to being the fastest Web site in history to break the 10-million-visitors-a-month threshold. It’s suddenly cropping up in conversation, online and off, with surprising frequency.

Pinterest is a pinboard for online photos. Multiple pinboards, actually, each an individual page in your Pinterest account. You can make one for Cool Craft Ideas, another for Kitchen Redo Concepts, a third for Places to See Before I Die. Or maybe Books I’ve Read, Ideas for the Wedding, Best Web Comics. The sky’s the limit.

(Unlike most start-up Web site names, “Pinterest” actually makes sense. You pin things based on your interests.)

There are several keys to Pinterest’s success, but one of them is the simplicity and pleasure of adding a photo to one of your boards. As you surf the Web each day, whenever you see something that looks interesting or inspiring or funny, you click the Pin It button on your bookmarks bar.

Wednesday, February 15, 2012

Researchers Find Flaw in Online Encryption Method

Excerpt from an article in The New York Times
Wednesday, February 15, 2012

Researchers Find Flaw in an Online Encryption Method 

By JOHN MARKOFF

SAN FRANCISCO — A team of European and American mathematicians and cryptographers have discovered an unexpected weakness in the encryption system widely used worldwide for online shopping, banking, e-mail and other Internet services intended to remain private and secure.

The flaw — which involves a small but measurable number of cases — has to do with the way the system generates random numbers, which are used to make it practically impossible for an attacker to unscramble digital messages. While it can affect the transactions of individual Internet users, there is nothing an individual can do about it. The operators of large Web sites will need to make changes to ensure the security of their systems, the researchers said.

The potential danger of the flaw is that even though the number of users affected by the flaw may be small, confidence in the security of Web transactions is reduced, the authors said.

The system requires that a user first create and publish the product of two large prime numbers, in addition to another number, to generate a public “key.” The original numbers are kept secret. To encrypt a message, a second person employs a formula that contains the public number. In practice, only someone with knowledge of the original prime numbers can decode that message.

For the system to provide security, however, it is essential that the secret prime numbers be generated randomly. The researchers discovered that in a small but significant number of cases, the random number generation system failed to work correctly.

The importance in ensuring that encryption systems do not have undetected flaws cannot be overstated. The modern world’s online commerce system rests entirely on the secrecy afforded by the public key cryptographic infrastructure.

The researchers described their work in a paper that the authors have submitted for publication at a cryptography conference to be held in Santa Barbara, Calif., in August. They made their findings public Tuesday because they believe the issue is of immediate concern to the operators of Web servers that rely on the public key cryptography system.

Monday, February 6, 2012

Austrian Law Student Faces Down Facebook

Excerpt from an article in The New York Times
Monday, February 06, 2012

Austrian Law Student Faces Down Facebook

By KEVIN J. O'BRIEN

BERLIN — As Wall Street prepares for a record, multibillion-dollar initial stock sale from Facebook, the social networking site, a meeting with the potential to shape the economics of the deal was set to take place Monday in Vienna.

Richard Allan, a former member of Parliament in Britain who is the European director of policy for Facebook, and another executive from Facebook’s headquarters in Menlo Park, California, will meet with Max Schrems, a 24-year-old college student.

Mr. Schrems, a law student at the University of Vienna and a user of Facebook since 2008, has led a vocal campaign in Europe against what he maintains are Facebook’s illegal practices of collecting and marketing users’ personal data, often without consent.

In less than a year, Mr. Schrems’s one-person operation has morphed into a Web site, Europe Versus Facebook, and a grass-roots movement that has persuaded 40,000 people to contact Facebook in Ireland, where its European headquarters are located, to demand a summary of all the personal data the U.S. company is holding on them.

Mr. Schrems and his crusade have become a cause célèbre in parts of Europe, attracting the attention of lawmakers in Brussels as the Continent begins a lengthy debate over tough new proposed restrictions on personal data, which could affect Web businesses like Facebook.

Last month, the author of a proposed European data protection law, which would update a 1995 statute to reflect the realities of the digital age, cited Mr. Schrems’s case as an example of why European lawmakers should adopt tightened controls over Web businesses.

==========