<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ICMPECHO &#187; privacy</title>
	<atom:link href="http://www.icmpecho.com/category/privacy/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.icmpecho.com</link>
	<description>more than your usual type 8&#039;s</description>
	<lastBuildDate>Sat, 04 Feb 2012 19:00:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>UK Big Brother running out of funds</title>
		<link>http://www.icmpecho.com/2008/12/30/uk-big-brother-running-out-of-funds/</link>
		<comments>http://www.icmpecho.com/2008/12/30/uk-big-brother-running-out-of-funds/#comments</comments>
		<pubDate>Tue, 30 Dec 2008 09:43:39 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
				<category><![CDATA[democracy]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[big brother]]></category>
		<category><![CDATA[cctv]]></category>
		<category><![CDATA[economy]]></category>
		<category><![CDATA[funds]]></category>
		<category><![CDATA[united kingdom]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/?p=1600</guid>
		<description><![CDATA[Photo: Improbulus on Flickr. CC BY-NC-SA. UK has one CCTV camera per fourteen citizens according to a research paper released in 2002 and in the harsh financial climate now facing the world the local councils in Britain has started slashing the funding used to actually monitor the cameras. From Daily Mail (via Schneier): &#8220;Once, Britain [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.icmpecho.com/images/cctvwayla.jpg" alt="Improbulus on Flickr - http://flickr.com/photos/improbulus/" border=1/><br />
<em>Photo: <a href="http://flickr.com/photos/improbulus/">Improbulus</a> on<a href="http://flickr.com/"> Flickr</a>. <a href="http://creativecommons.org/licenses/by-nc-sa/2.0/deed.en">CC BY-NC-SA</a>.</em></p>
<p>UK has one CCTV camera per fourteen citizens according to a <a href="http://en.wikipedia.org/wiki/Closed-circuit_television">research paper released in 2002</a> and in the harsh financial climate now facing the world the local councils in Britain has started slashing the funding used to actually monitor the cameras.</p>
<p>From <a href="http://www.dailymail.co.uk/news/article-1095609/Big-brother-NOT-watching-Cash-strapped-towns-leave-CCTV-cameras-unmonitored.html?ITO=1490">Daily Mail</a> (via <a href="http://www.schneier.com/blog/archives/2008/12/cctv_cameras_go.html">Schneier</a>):</p>
<blockquote><p><em><font color="black">&#8220;Once, Britain was the most watched nation in the world, with more than 4 million CCTV cameras monitoring our every move.</p>
<p>But now in these difficult economic times, it seems that Big Brother isn&#8217;t actually watching, in fact no one is.</p>
<p>As cash-strapped police forces and councils around the UK are forced to tighten their belts in the recession, CCTV cameras around town centres are being left unmanned as they can&#8217;t afford to pay anyone to watch out for crime as it happens.</p>
<p>Instead, entire networks of surveillance cameras are being effectively put on auto-pilot, with police reviewing tapes only after a reported incident.&#8221;</font></em></p></blockquote>
<p>Does it take a recession to make people realize that an annual expense of ~£50 million on CCTV is excessive? That it never was useful? That the cost is too high in relation to what you might gain (if any)? This just verifies that the presented image of CCTV as a tool for crime prevention is false.</p>
<p>An another citation from the same article as above:</p>
<blockquote><p><em><font color="black">While in Dorset, police resorted to advertising for unpaid civilian volunteers to monitor CCTV footage after claiming that it was not cost effective to pay trained professionals.</p>
<p>In June Dorset Police appealed for members of the public to watch live images from street security cameras in Wimborne, Blandford, Shaftesbury and Gillingham to help spot crimes and anti-social behaviour.</font></em></p></blockquote>
<p>Civilian volunteers? Spot &#8220;anti-social behaviour&#8221;? Since when does an untrained civilian make an educated decision on when someone is acting anti-social? That&#8217;s like asking for false positives&#8230; deluxe version&#8230;<br />
<strong><br />
Read the <a href="http://www.dailymail.co.uk/news/article-1095609/Big-brother-NOT-watching-Cash-strapped-towns-leave-CCTV-cameras-unmonitored.html?ITO=1490">full article</a>&#8230;</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2008/12/30/uk-big-brother-running-out-of-funds/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Extracting metadata from Office 2007 docs</title>
		<link>http://www.icmpecho.com/2008/12/23/extracting-metadata-from-office-2007-docs/</link>
		<comments>http://www.icmpecho.com/2008/12/23/extracting-metadata-from-office-2007-docs/#comments</comments>
		<pubDate>Mon, 22 Dec 2008 23:46:08 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
				<category><![CDATA[microsoft]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[metadata]]></category>
		<category><![CDATA[office 2007]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/?p=1569</guid>
		<description><![CDATA[Found a short and interesting webcast on how to gather metadata such as usernames from documents created with Office 2007 over at PaulDotCom: Hack Naked TV &#8211; Episode 2 &#8211; Office 2007 Metadata from PaulDotCom on Vimeo. &#160; As you might know, the new MS Office format (.docx etc.) is based on a zipped structure [...]]]></description>
			<content:encoded><![CDATA[<p>Found a short and interesting webcast on how to gather metadata such as usernames from documents created with Office 2007 <a href="http://pauldotcom.com/2008/12/hack-naked-tv-episode-2-office.html">over at PaulDotCom</a>:</p>
<p><center><object width="400" height="302"><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=2467697&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=&amp;fullscreen=1" /><embed src="http://vimeo.com/moogaloop.swf?clip_id=2467697&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=&amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="400" height="302"></embed></object><br /><a href="http://vimeo.com/2467697">Hack Naked TV &#8211; Episode 2 &#8211; Office 2007 Metadata</a> from <a href="http://vimeo.com/pauldotcom">PaulDotCom</a> on <a href="http://vimeo.com">Vimeo</a>.</center><br />
&nbsp;<br />
As you might know, the new MS Office format (.docx etc.) is based on a zipped structure of XML files. These XML files contain everything from the structure of the document, the data in it and of course the metadata of the document. Previous versions of MS Office has been known to divulge a bit too much information, and this webcast focuses on digging out user data that might be used in remote pen-testing.<br />
&nbsp;<br />
The webcast only illustrates digging for usernames, but as we all know, more information <a href="http://www.moredata.com/home/word-metadata-and-electronic-evidence.html">might be hidden</a> (even though it looks cleaner) <img src='http://www.icmpecho.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /><br />
&nbsp;<br />
Anyways, if you&#8217;re on windows and want investigate your own files you can just use WinZip, WinRAR or any other archiver to extract the files inside your .docx/.xlsx/etc-x files. XML files can be manually interpreted using notepad++, Internet Explorer or other more specialized tools.<br />
&nbsp;<br />
Cheers,</p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2008/12/23/extracting-metadata-from-office-2007-docs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More CCTV means more security for you!</title>
		<link>http://www.icmpecho.com/2008/12/17/more-cctv-means-more-security-for-you/</link>
		<comments>http://www.icmpecho.com/2008/12/17/more-cctv-means-more-security-for-you/#comments</comments>
		<pubDate>Tue, 16 Dec 2008 23:23:26 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
				<category><![CDATA[democracy]]></category>
		<category><![CDATA[personal]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[cctv]]></category>
		<category><![CDATA[surveillance]]></category>
		<category><![CDATA[uk]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/?p=1536</guid>
		<description><![CDATA[There&#8217;s been discussions here in Sweden on non-english blogs and forums in regards to just when a citizen should stand up and say &#8220;Stop this madness!&#8221;, instead of being caught in a machinery where you can&#8217;t protest, as you&#8217;ll be shot or jailed when doing so. My guess is that the United Kingdom is not [...]]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s been discussions here in Sweden on non-english blogs and forums in regards to just when a citizen should stand up and say &#8220;Stop this madness!&#8221;, instead of being caught in a machinery where you can&#8217;t protest, as you&#8217;ll be shot or jailed when doing so.</p>
<p>My guess is that the United Kingdom is not that very far from that point and now would be the time to stand up against the madness going on on their island. Caught this little poster via <a href="http://www.boingboing.net/2008/12/16/creepy-cctv-posters.html">BoingBoing</a> (with creds to <a href="http://www.shardcore.org/">Shardcore</a>):</p>
<p><img src="http://www.icmpecho.com/images/morecctv.jpg" alt="More CCTV means more security for you - via BoingBoing.net" border=1/></p>
<p>*shrug*</p>
<p>I mean please. This single statement is an outright lie <a href="http://gritsforbreakfast.blogspot.com/2005/03/britain-surveillance-cameras-do-not.html">as</a> <a href="http://electronics.howstuffworks.com/police-camera-crime1.htm">it</a> <a href="http://www.scotcrim.u-net.com/researchc2.htm">has</a> <a href="http://news.bbc.co.uk/1/hi/uk/2192911.stm">been</a> <a href="http://www.homeoffice.gov.uk/rds/pdfs05/hors292.pdf">broken</a> <a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2007/08/14/MNIPRHRPE.DTL">several</a> <a href="http://www.temple.edu/cj/misc/PhilaCCTV.pdf">times</a>. They <u>might</u> provide a marginal level of increased security around the specific streets where they are, but in some cases just move the crimes to other streets in the vicinity. Not even this has been fully established though. Even <a href="http://www.guardian.co.uk/uk/2008/may/06/ukcrime1">Scotland Yard says CCTV monitoring do not prevent crime</a> for crying out loud!</p>
<p>It feels like they&#8217;re trying to say it like a Japanese manga character or something, like <em>&#8220;More CCTV!!! *big eyes* Means More Security For You!!!! *freakishly large smile* *happy* *happy*&#8221;</em>&#8230; Maybe it&#8217;s just in my brain <img src='http://www.icmpecho.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Another thing I react to as a person working with security is that there can&#8217;t be a sound risk assessment in the bottom of the decisions to put up more camera&#8217;s and set up more monitoring stations. The risk of a crime does not motivate the cost of the &#8220;protection&#8221; so to speak. This is something that Bruce Schneier mentions<a href="http://www.schneier.com/blog/archives/2008/06/cctv_cameras.html"> in his article from which I stole all the links above</a>.</p>
<p>Anyways, I think that the UK is setting a bad example for Europe and the risk for the rest of the countries in the region is that our governments point at them saying &#8220;It works over there!&#8221; even though it doesn&#8217;t and then we&#8217;re back were we are with the <a href="http://www.icmpecho.com/2008/11/06/qp-on-my-way-to-falun/">FRA-law</a>, <a href="http://www.icmpecho.com/2008/12/08/market-liberals-of-sweden-saving-dying-business-models/">EU IPRED1</a> and the <a href="http://www.icmpecho.com/2008/12/16/eu-data-retention-directive-again/">EU Data Retention</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2008/12/17/more-cctv-means-more-security-for-you/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sony goes spec-ops, hunting for Pirates</title>
		<link>http://www.icmpecho.com/2008/11/05/sony-goes-spec-ops-hunting-for-pirates/</link>
		<comments>http://www.icmpecho.com/2008/11/05/sony-goes-spec-ops-hunting-for-pirates/#comments</comments>
		<pubDate>Wed, 05 Nov 2008 18:36:53 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
				<category><![CDATA[personal]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[bond]]></category>
		<category><![CDATA[cinema]]></category>
		<category><![CDATA[citizens]]></category>
		<category><![CDATA[movie]]></category>
		<category><![CDATA[night vision]]></category>
		<category><![CDATA[piracy]]></category>
		<category><![CDATA[sony]]></category>
		<category><![CDATA[spying]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/?p=1263</guid>
		<description><![CDATA[Photo: labanex on Flickr. Apparently the suggested surveillance and &#8220;corporate police&#8221; laws weren&#8217;t enough for Sony. From TheLocal.se: &#8220;Sony Pictures in Sweden has employed methods worthy of James Bond in an attempt to protect against the pirating of Quantum of Solace. The film company is using special night vision goggles to keep an eye on [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.icmpecho.com/images/nightvision.jpg" alt="labanex on Flickr - http://flickr.com/photos/labanex/" border=1/><br />
<em>Photo: <a href="http://flickr.com/photos/labanex/">labanex</a> on <a href="http://flickr.com">Flickr</a>.</em></p>
<p>Apparently the suggested <a href="http://www.icmpecho.com/2008/09/25/fra-law-swedens-liberal-party-put-the-last-nail-in-the-coffin/">surveillance</a> and &#8220;<a href="http://www.icmpecho.com/2008/10/27/ipred1-based-law-gets-the-go-ahead/">corporate police</a>&#8221; laws weren&#8217;t enough for Sony.</p>
<p>From <a href="http://www.thelocal.se/15478/20081105/">TheLocal.se</a>:</p>
<blockquote><p><em><font color="black">&#8220;Sony Pictures in Sweden has employed methods worthy of James Bond in an attempt to protect against the pirating of Quantum of Solace.</p>
<p>The film company is using special night vision goggles to keep an eye on moviegoers attending showings of the latest Bond film at 149 cinemas around Sweden, reports entertainment news agency TT-Spektra.&#8221;</font></em></p></blockquote>
<p>Oh &#8211; my &#8211; god. That&#8217;s the words that best describes my immediate reaction.</p>
<p>If I were to be informed that someone would be lokoing at me with night vision goggles while I was enjoying a movie I had paid good money to see, I would probably sue them. Possibly just file a complaint with the police as that easily qualifies as harrasment (or is it OK to look at Sony employees in the dark with night vision goggles?).</p>
<p><strong>Sick.</strong></p>
<p>More <a href="http://news.sky.com/skynews/Home/Showbiz-News/James-Bond-Quantum-Of-Solace-Movie-Shown-To-Critics/Article/200810315123521?lpos=Showbiz_News_Article_Body_Copy_Region_0&#038;lid=ARTICLE_15123521_James_Bond%3A_Quantum_Of_Solace_Movie_Shown_To_Critics">here</a>, <a href="http://www.thisisbath.co.uk/news/Bath-gala-screening-new-Bond-film/article-439689-detail/article.html">here</a>, <a href="http://debcarrs-daydreams.blogspot.com/2008/10/id-like-to-wish-my-good-friend-andrea.html">here</a> and <a href="http://konsumenter.se/blogg/?p=1819">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2008/11/05/sony-goes-spec-ops-hunting-for-pirates/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>IPRED1 based law gets the &#8220;Go ahead&#8221;</title>
		<link>http://www.icmpecho.com/2008/10/27/ipred1-based-law-gets-the-go-ahead/</link>
		<comments>http://www.icmpecho.com/2008/10/27/ipred1-based-law-gets-the-go-ahead/#comments</comments>
		<pubDate>Sun, 26 Oct 2008 23:59:01 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
				<category><![CDATA[democracy]]></category>
		<category><![CDATA[personal]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[ipred1]]></category>
		<category><![CDATA[piratjägarlagen]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/?p=1040</guid>
		<description><![CDATA[Photo: peasap on Flickr. Apparently the swedish interpretion of IPRED1 has got the &#8220;Go ahead&#8221; from Lagrådet (those that check that everything is compatible with other legislation etc.). Next step is that the Government gives the law to the parliament for voting. And if they vote yes, well, then we have the harshest IPRED1 implementation [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.icmpecho.com/images/pirategirl.jpg" alt="Pirate girl from peasap on Flickr - http://flickr.com/photos/peasap/" border=1/><br />
<em>Photo: <a href="http://flickr.com/photos/peasap/">peasap</a> on <a href="http://flickr.com/">Flickr</a>.</em></p>
<p>Apparently the swedish interpretion of IPRED1 has got the &#8220;Go ahead&#8221; from Lagrådet (those that check that everything is compatible with other legislation etc.).</p>
<p>Next step is that the Government gives the law to the parliament for voting. And if they vote yes, well, then we have the harshest IPRED1 implementation cemented in law here in Sweden.</p>
<p>So? One might ask. Well, the biggest problem is that we are giving private, commercially motivated organizations more power than our regular police. Second, we&#8217;ll be stepping into a world of hurt as all previous implementations have made those countries hellish.</p>
<p>In Denmark, for example, the citizens has been harassed and there has been one suicide because of the extortion attempts by these organizations. Seems harsh but <a href="http://opassande.se/index.php/2008/10/24/en-historik-over-de-danska-antipiratlagarna/">I got the facts to back it up</a> (sorry, just Swedish and Danish, <a href="http://translate.google.com/translate?u=http%3A%2F%2Fopassande.se%2Findex.php%2F2008%2F10%2F24%2Fen-historik-over-de-danska-antipiratlagarna%2F&#038;hl=en&#038;ie=UTF-8&#038;sl=sv&#038;tl=en">try the translator</a>.).</p>
<p>Anyways,<strong> I hope that our politicians see the absurd legislative situation as it is and do not grant anyone except our police the rights needed to fight real, commercially motived, piracy.</strong></p>
<p>But as usual, we&#8217;ll see what happens&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2008/10/27/ipred1-based-law-gets-the-go-ahead/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Second day of Internetdagarna ‘08</title>
		<link>http://www.icmpecho.com/2008/10/27/second-day-of-internetdagarna-%e2%80%9808/</link>
		<comments>http://www.icmpecho.com/2008/10/27/second-day-of-internetdagarna-%e2%80%9808/#comments</comments>
		<pubDate>Sun, 26 Oct 2008 23:43:52 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
				<category><![CDATA[personal]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[work]]></category>
		<category><![CDATA[integrity]]></category>
		<category><![CDATA[internetdagarna]]></category>
		<category><![CDATA[lavasoft]]></category>
		<category><![CDATA[software reputation]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spyware]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/?p=1020</guid>
		<description><![CDATA[The second day of Internetdagarna (22/10-08) was spent in the Security track as well, except for the last seminar where I switched to the society track. The first seminar was &#8220;Pålitlig e-post / Anti-spam&#8221; which translates to &#8220;Reliable e-mail / Anti-spam&#8221;. The moderator for this seminar was Jörgen Eriksson from .SE. First speaker out was [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.icmpecho.com/images/internetdagarna_cutout.jpg" alt="ID08" border=1/></p>
<p>The second day of Internetdagarna (22/10-08) was spent in the Security track as well, except for the last seminar where I switched to the society track.</p>
<p>The first seminar was &#8220;<strong>Pålitlig e-post / Anti-spam</strong>&#8221; which translates to &#8220;Reliable e-mail / Anti-spam&#8221;. The moderator for this seminar was Jörgen Eriksson from <a href="http://www.iis.se/lang/?id=en">.SE</a>.</p>
<p>First speaker out was Amar Andersson from <a href="http://www.teliasonera.com">TeliaSonera</a> and he spoke about &#8220;Spam-protection that undermine their own goals&#8221;. I can honestly say that I did not follow this good enough as I was very tired this first seminar and I kind of regret it now. However, the main problem presented by him was the lack of coordination and standards in anti-spam prevention methods. He mentioned blacklisting in general and the DUL-blacklist in particular, hostname &#8220;naming&#8221; (reverse lookups which results in a name conatining either &#8220;static&#8221; or &#8220;dynamic&#8221;) and how to make sure your e-mails got delivered in this day and age where the requirements for delivery can vary quite much from server to server (correct HELO/EHLO messages, correct reverse lookups, SPF and other DNS related issues).</p>
<p>Next speaker up was Bengt Carlsson from <a href="http://www.bth.se/eng/">Blekinge Tekniska Högskola</a> that just announced a new project between .SE and BTH. The project name was &#8220;säker e-post hantering bland illsinnad programvara&#8221; which translates to &#8220;Secure e-mail management amongst bad software&#8221;.</p>
<p>After this Rickard Bondesson from <a href="http://www.liu.se/en/">Linköpings Universitet</a> took the stage to present his research on DKIM, DKIM-milter and DNSSEC implementations. This was a quite long and very informative presentation which stepped through his research in a comprehensive way under the following bullets; Forged e-mail, Prevention of forged e-mail, DKIM, Reliability within DNS, Implementation, Tests, Statistics, Experiences.</p>
<p>After this there was a small moderated panel debate on the topic of Reliable e-mail.</p>
<p>The next seminar was &#8220;<strong>Parasitekonomin på Internet</strong>&#8221; which (roughly) translates to &#8220;The parasitic economy on the internet&#8221;. Stefan Görling from <a href="http://www.kth.se/?l=en_UK">KTH</a> moderated and had one presentation, and the other speakers were two representatives from <a href="http://www.lavasoft.com">Lavasoft</a> (you know, the guys behind Ad-Aware) and Martin Boldt (IT-security researcher from BTH).</p>
<p>Görling started out by picking at affiliate systems and the easy of exploiting these services for profit and he worked out from a site that supposedly uses this format in a legit way. He did not go into the malware point-of-view very much but he touched the subject when talking about &#8220;mis-spelled domain names default pages&#8221; which contain only affiliate links.</p>
<p>The guys (they were two) from <a href="http://www.lavasoft.com">Lavasoft</a> then held their presentation which more or less detailed the different types of spyware they had included during the year, and also gave a strange remark saying the TeliaSonera was gaining money from the malware circulating on the internet (as they&#8217;re an ISP, they supposedly make profit when having their bandwidth used&#8230; hrrm&#8230;). This little remark came back to bite them in the ass when a (quite upset) TeliaSonera security employee demanded that they would take that statement back during the Q &#038; A at the end of the session.</p>
<p>Following this Martin Boldt from <a href="http://www.bth.se/eng/">BTH</a> that discussed reputation systems and automatic EULA analysis. He had researched these areas and they were at this moment involved in creating web browser plugins and applications to enable users to share their thoughts and score on specific applications (binary files). See their project website at <a href="http://www.softwareputation.com/">www.softwareputation.com</a> for more information. He also noted that this project is still in Alpha stage. The ideas they&#8217;re having kind of looks like Panda Security&#8217;s Collective Intelligence, except it is user generated not automatic.</p>
<p>When it came to EULA analyzing they&#8217;ve taken a harder route than SpywareGuide&#8217;s <a href="http://www.spywareguide.com/analyze/index.php">EULA analyzer</a> and they used many different bayesian and similar algorithms in order to define if an EULA is &#8220;good&#8221; or &#8220;bad&#8221; with a high level of success. Ideas for the future was to make this automatically integrated into system so that any EULA boxes could be automatically read and scored.</p>
<p>After this there was a Q&#038;A session and Lavasoft&#8217;s statements was quite heavily scrutinized both by the TeliaSonera employee and <a href="http://www.netnod.se/">Netnod</a>&#8216;s CEO Kurt-Erik Lindqvist (I think it was him but I only heard the voice, so don&#8217;t quote me on this). It seems like Lavasoft&#8217;s statement was just illustrating and that they based their assumptions on an US ISP that had misbehaved and in some ways had profited on bad software.</p>
<p>Here I switched room and joined the &#8220;Infrastructure and society&#8221;-line of seminars. The one I was interested in was &#8220;<strong>Integritet och övervakning</strong>&#8221; which translates to &#8220;Integrity and surveillance&#8221;.</p>
<p>This seminar was moderated by Johan Hallsenius (editor for Computer Sweden) and the debate panel was only populated by pro-Integrity people as none of the invited politicians and FRA-people had turned up even though they were invited. The panel members was <a href="http://swartz.typepad.com">Oscar Swartz</a> (debater, writer and blogger), Patrik Fältström (<a href="http://stupid.domain.name/">Cisco</a>), Fredrik von Essen (<a href="http://www.itotelekomforetagen.se/website1/1.0.1.0/22/2/index.php">Swedish IT and Telecom Industries</a>) and Daniel Westman (<a href="http://www.juridicum.su.se/jurweb/default.asp?lang=eng">Juridicum</a>, Stockholms University)</p>
<p>The focus of the debate was of course the FRA-law but also dangerous EU-directives and other laws that affect impede personal integrity. It was an interesting debate, but as &#8220;the other side&#8221; was missing no hard questions could be discussed. I talked briefly to Oscar Swartz before the seminar and he described it as a &#8220;non-debate&#8221;, as there was only one point of view from all participants (with small diversions). He <a href="http://swartz.typepad.com/texplorer/2008/10/chief-internet-evangelist.html">wrote a post on &#8220;Internetdagarna&#8221;</a> on his blog in which he breifly mentions this debate.</p>
<p>It was also to hear what Fredrik von Essen from the <a href="http://www.itotelekomforetagen.se/website1/1.0.1.0/22/2/index.php">Swedish IT and Telecom Industries</a> had to say on this issue.</p>
<p>Unfortunately I had to leave before the Q&#038;A session that followed, so I&#8217;m looking forward to the sound recording that are to be released <a href="http://www.internetdagarna.se/program">here</a>.</p>
<p>Some pictures from this day:</p>
<p><em>Integrity debate:</em><br />
<img src="http://www.icmpecho.com/images/id08_6.jpg" alt="ID08" border=1/><br />
<img src="http://www.icmpecho.com/images/id08_7.jpg" alt="ID08" border=1/><br />
<em>Martin Boldt (from <a href="http://www.bth.se/eng/">BTH</a>):</em><br />
<img src="http://www.icmpecho.com/images/id08_8.jpg" alt="ID08" border=1/></p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2008/10/27/second-day-of-internetdagarna-%e2%80%9808/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NSA today, FRA tomorrow.</title>
		<link>http://www.icmpecho.com/2008/10/15/nsa-today-fra-tomorrow/</link>
		<comments>http://www.icmpecho.com/2008/10/15/nsa-today-fra-tomorrow/#comments</comments>
		<pubDate>Wed, 15 Oct 2008 19:36:19 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
				<category><![CDATA[censorship]]></category>
		<category><![CDATA[democracy]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[fra]]></category>
		<category><![CDATA[fra-lagen]]></category>
		<category><![CDATA[massavlyssning]]></category>
		<category><![CDATA[nsa]]></category>
		<category><![CDATA[wiretap]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/?p=936</guid>
		<description><![CDATA[Photo: whurley on Flickr. Power without oversight equals abuse! From The NY Times &#8211; &#8220;Panel to Study Military Eavesdropping&#8221; (4-page article): WASHINGTON — The chairman of the Senate Intelligence Committee, Senator John D. Rockefeller IV, said Thursday that the committee would investigate claims by two military eavesdroppers that they routinely listened in on private calls [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.icmpecho.com/images/nagios_nsa.jpg" alt="Nagios - Only the NSA monitors more... From Whurley on Flickr - http://flickr.com/photos/whurley/" border=1/><br />
<em>Photo: <a href="http://flickr.com/photos/whurley/">whurley</a> on <a href="http://flickr.com">Flickr</a>.</em></p>
<p><strong>Power without oversight equals abuse!</strong></p>
<p>From <a href="http://www.nytimes.com/2008/10/10/washington/10nsa.html">The NY Times &#8211; &#8220;Panel to Study Military Eavesdropping&#8221;</a> (4-page article):</p>
<blockquote><p><em><font color="black">WASHINGTON — The chairman of the Senate Intelligence Committee, Senator John D. Rockefeller IV, said Thursday that the committee would investigate claims by two military eavesdroppers that they routinely listened in on private calls home from American military officers, aid workers and journalists stationed in Iraq.</p>
<p>Former intelligence officers were interviewed by ABC News and by James Bamford, above, who has written a book about the National Security Agency due to be published next week.</p>
<p>Mr. Rockefeller, Democrat of West Virginia, called the accusations “extremely disturbing.”</p>
<p>“Any time there is an allegation regarding abuse of the privacy and civil liberties of Americans it is a very serious matter,” he said.</font></em></p></blockquote>
<p>More references:<br />
<strong>ABC News</strong> &#8211; <a href="http://abcnews.go.com/Blotter/Story?id=5987804&#038;page=1">Exclusive: Inside Account of U.S. Eavesdropping on Americans</a><br />
<strong>UPI.com</strong> &#8211; <a href="http://www.upi.com/Top_News/2008/10/10/Spy_agency_accused_of_improper_listening/UPI-99751223644874/">Spy agency accused of improper listening</a><br />
<strong>Reuters.com</strong> &#8211; <a href="http://www.reuters.com/article/domesticNews/idUSTRE4990CD20081010">U.S. probes claims officials eavesdropped on calls</a></p>
<p>Apparently the US&#8217;s multi-billion surveillance system is used to wiretap personal calls, and joking around about them. Will our system be used in the same way? For sure, <strong>power without oversight equals abuse</strong>. This is worth repeating.</p>
<p>Found this news first on <a href="http://www.schneier.com/blog/archives/2008/10/nsas_warrantles.html">Bruce Schneier</a>&#8216;s blog.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2008/10/15/nsa-today-fra-tomorrow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Democracy? Nooo, no need for that.</title>
		<link>http://www.icmpecho.com/2008/10/14/democracy-nooo-no-need-for-that/</link>
		<comments>http://www.icmpecho.com/2008/10/14/democracy-nooo-no-need-for-that/#comments</comments>
		<pubDate>Tue, 14 Oct 2008 21:45:59 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
				<category><![CDATA[censorship]]></category>
		<category><![CDATA[democracy]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[copyright]]></category>
		<category><![CDATA[eu]]></category>
		<category><![CDATA[telecoms package]]></category>
		<category><![CDATA[WORKING PARTY ON TELECOMMUNICATIONS AND INFORMATION SOCIETY]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/?p=908</guid>
		<description><![CDATA[What do you do if you&#8217;re a corrupted EU politician and wants the Telecoms Package to pass without the additional integrity protecting amendments? Well, just don&#8217;t add them. A-R-G-H-H-H. Swartz used this as an illustration. It&#8217;s right on. The situation is now like this; The parliament has voted on the Telecoms package. As familiar, amendment [...]]]></description>
			<content:encoded><![CDATA[<p><strong>What do you do if you&#8217;re a corrupted EU politician and wants the Telecoms Package to pass without the additional integrity protecting amendments?</strong></p>
<p>Well, just don&#8217;t add them.</p>
<p><strong>A-R-G-H-H-H.</strong></p>
<p><object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/VjdgXqKjHvY&#038;color1=0x5d1719&#038;color2=0xcd311b&#038;hl=en&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><embed src="http://www.youtube.com/v/VjdgXqKjHvY&#038;color1=0x5d1719&#038;color2=0xcd311b&#038;hl=en&#038;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="344"></embed></object><br />
<em><a href="http://swartz.typepad.com/texplorer/2008/10/eu-l%C3%A4cka-sverige-yxas-bort.html">Swartz</a> used this as an illustration. It&#8217;s right on.</em></p>
<p>The situation is now like this;</p>
<p><strong>The parliament has voted on the Telecoms package.</strong> As familiar, <strong>amendment 166 was voted into the package</strong> and thus providing european citizens with protection against arbitrary disconnection from the internet and privacy.</p>
<p><strong>So far all good</strong> and <a href="http://www.europarl.europa.eu/sides/getDoc.do?type=TA&#038;language=EN&#038;reference=P6-TA-2008-0452">here&#8217;s the voting results</a> from EU-parliament so you can read for yourselves.</p>
<p><strong>Now the matter moved on</strong> to the <em>&#8220;WORKING PARTY ON TELECOMMUNICATIONS AND INFORMATION SOCIETY&#8221;</em> whose job is to prepare the package for either a second hearing, or if everyone are still agreeing, for the ministers for OK&#8217;ing.</p>
<p><strong>HOWEVER</strong> (always seem to be a however in my posts), what they are now doing is <strong>more or less editing away the amendments that were added</strong> and making it as they (the french, primarily) want it. Yep, that&#8217;s right, <strong>they are actually editing the democratic decision by the parliament to fit the lobbying organizations needs</strong>. <strong><a href="http://www.piratpartiet.se/files/active/0/ROOM%20DOC%2071%20-%20Universal%20Service%20Directive.pdf">A leaked document shows us this progress</a></strong> and the evidently left out &#8220;<strong>Article 32a</strong>&#8221; which would be the one containing amendment 166&#8242;s content.</p>
<p><strong>We now need to make some noise!</strong> But not just the (crazy?) swedes, <strong>everyone!</strong> If you are from another European country please <a href="http://www.europarl.europa.eu/members/public/geoSearch.do?language=EN">send e-mails to your MEP&#8217;s and/or call them</a> and ask them to follow-up on and verify that their democratically voted decisions stands firm! <strong>Remind them that if this can be changed, so can their own main issues and that this should not go unnoticed through a democratic system!</strong></p>
<p>I&#8217;m getting seriously tired of writing about politicians and others tricking and removing citizens rights.</p>
<p><strong>Can&#8217;t any of them please break the trend so I can write something nice?</strong></p>
<p><em>Others writing (mostly in Swedish, use <a href="http://translate.google.com">the translator</a>): <a href="http://swartz.typepad.com/texplorer/2008/10/eu-l%C3%A4cka-sverige-yxas-bort.html">Oscar Swartz</a>, <a href="http://opassande.se/index.php/2008/10/14/mycket-snack-och-sma-verkstader/">Opassande</a>, <a href="http://bjandersson.blogspot.com/2008/10/telekompaketet-demokratiunderskott-i.html">Josef</a>, <a href="http://scabernestor.blogg.se/2008/october/folkpartiet-hamnas-pa-fra-kritikerna-nu-peta.html">scaber_nestor</a>, <a href="http://farmorgun.blogspot.com/2008/10/datainspektionen-och-vi-andra-granskar.html">farmorgun</a>, <a href="http://blogg.frihetfildelningfeminism.se/2008/10/i-vntan-p-debatten.html">Frihet-Fildelning&#038;Feminism</a>, <a href="http://satmaran.blogg.se/2008/october/piratjagarlagen-ar-inte-ok-inte-fra-lagen-he.html">satmaran</a>, <a href="http://www.odsvall.se/blog/2008/10/rattorna-i-bryssel-myglar-bort-amendment-166/">Jens. O</a>, <a href="http://henrikalexandersson.blogspot.com/2008/10/never-ending-story.html">HAX</a>.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2008/10/14/democracy-nooo-no-need-for-that/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why being lawful doesn&#8217;t pay off&#8230;</title>
		<link>http://www.icmpecho.com/2008/10/13/why-being-lawful-doesnt-pay-off/</link>
		<comments>http://www.icmpecho.com/2008/10/13/why-being-lawful-doesnt-pay-off/#comments</comments>
		<pubDate>Mon, 13 Oct 2008 22:30:37 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
				<category><![CDATA[censorship]]></category>
		<category><![CDATA[democracy]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[drm]]></category>
		<category><![CDATA[ipred1]]></category>
		<category><![CDATA[steal this comic]]></category>
		<category><![CDATA[xkcd]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/?p=880</guid>
		<description><![CDATA[XKCD Others posting this image to raise awareness of DRM-dangers (in Swedish) are Opassande, Dennis, Daniel. Probably a lot of others as well but these were the ones conveniently linked from Emma (Opassande) and I&#8217;m lazy today And another comment in english on the suggested swedish IPRED1 implementation from paf (also posted the XKCD image). [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.icmpecho.com/images/steal_this_comic.png" alt="Steal This Comic !" /><br />
<em><a href="http://xkcd.com/488/"><strong>XKCD</strong></a></em></p>
<p>Others posting this image to raise awareness of DRM-dangers (in Swedish) are <a href="http://opassande.se/index.php/2008/10/13/malande-beskrivningar-och-piratjagarlagen-som-inte-behovs/">Opassande</a>, <a href="http://www.katallaxi.se/2008/10/13/dagens-stold/">Dennis</a>, <a href="http://blogg.ricercar.se/basic/2008/10/13/xkcd-tar-strid-mot-drm/">Daniel</a>. Probably a lot of others as well but these were the ones conveniently linked from Emma (<a href="http://opassande.se">Opassande</a>) and I&#8217;m lazy today <img src='http://www.icmpecho.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>And another comment in <u>english</u> on the suggested swedish IPRED1 implementation from <a href="http://stupid.domain.name/node/715"><strong>paf</strong></a> (also posted the XKCD image).</p>
<p>Cheers,</p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2008/10/13/why-being-lawful-doesnt-pay-off/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>EU IPRED1 directive to be enforced in Sweden</title>
		<link>http://www.icmpecho.com/2008/10/13/eu-ipred1-directive-to-be-enforced-in-sweden/</link>
		<comments>http://www.icmpecho.com/2008/10/13/eu-ipred1-directive-to-be-enforced-in-sweden/#comments</comments>
		<pubDate>Mon, 13 Oct 2008 22:13:36 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
				<category><![CDATA[censorship]]></category>
		<category><![CDATA[democracy]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[corporate police]]></category>
		<category><![CDATA[eu]]></category>
		<category><![CDATA[fascism]]></category>
		<category><![CDATA[ipred1]]></category>
		<category><![CDATA[piratjägarlagen]]></category>
		<category><![CDATA[upphovsrätt]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/?p=856</guid>
		<description><![CDATA[Photo: rich115 on Flickr. Whole story behind image here. Even though it doesn&#8217;t need to be&#8230; Here we go again&#8230; Not really sure I&#8217;ve got the energy for this lunacy&#8230; First off, what&#8217;s the IPRED1 directive? Intellectual Property Rights Enforcement Directive 1 (IPRED1) is a directive created by lobbyists and pushed through the EU by [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.icmpecho.com/images/bootleg_haloed.jpg" alt="rich 115 on Flickr - http://flickr.com/photos/richardgiles/" border=1/><br />
<em>Photo: <a href="http://flickr.com/photos/richardgiles/">rich115</a> on <a href="http://flickr.com">Flickr</a>. Whole story behind image <a href="http://www.flickr.com/photos/richardgiles/18106723/">here</a>.</em></p>
<p>Even though it doesn&#8217;t need to be&#8230; Here we go again&#8230; Not really sure I&#8217;ve got the energy for this lunacy&#8230;<br />
<strong><br />
First off, what&#8217;s the IPRED1 directive?</strong></p>
<p>Intellectual Property Rights Enforcement Directive 1 (IPRED1) is a directive created by lobbyists and pushed through the EU by a woman married to a record company executive. The gist of the directive is to enable rightsholders to force counterfeiting middle-men to tell where they got the goods from. So in the beginning this was  but this was about physical counterfeiting. Along the way it got a bit manhandled by the IP-lobbyists and record companies and finally was voted through in the form of a law that would allow private companies to demand ISPs to hand over their client data for a specific client, so that the rightsholder could sue.</p>
<p><strong>However,</strong></p>
<p>The EU IPRED1 directive is not forced upon any member state in the European Union <a href="http://www.eff.org/deeplinks/2008/01/eu-law-does-not-require">as ruled by the European Court of Justice</a> (source <a href="http://www.eff.org/">EFF</a>). From the article:</p>
<blockquote><p><em>In a much-anticipated decision, the European Court of Justice ruled yesterday that European Community law does not require EU Member States to impose an obligation on ISPs to divulge customer data in response to a request from a copyright holder who alleges that copyright infringement has taken place. The decision in Promusicae v. Telefonica involved a request made by a Spanish music rightsholder association (Promusicae) to Spain&#8217;s leading ISP (Telefonica) for personal data about Telefonica subscribers using particular dynamic IP addresses, which Promusicae alleged were engaged in filesharing.</p>
<p>The European Court of Justice was asked to interpret a mesh of overlapping EU Community laws and answer the question: does European community law require EU Member States that are implementing this suite of EU directives to impose an obligation on ISPs to divulge their customers&#8217; personal data to rightsholders in a civil copyright lawsuit? The court ruled no, but with some qualifications. Thus, the Spanish law is valid and Telefonica will not be forced to divulge its customers&#8217; data. </em></p></blockquote>
<p><strong>And what does the Swedish government, with the help of record company lobbyists do now?</strong></p>
<p>They go ahead and suggest a Swedish implementation and law <strong>which would grant MORE power</strong> to the IP-holders, effectively creating a <strong>corporate police</strong> which can, without any real evidence, get the identity of the person owning a specific IP-adress.</p>
<p>The law that is now proposed actually <strong>grants these commercial interests more power than the Swedish police.</strong></p>
<p>Actually, it is so over-implemented so it actually breaches the directive&#8217;s own regulations which states:</p>
<blockquote><p>3. Paragraphs 1 and 2 shall apply without prejudice to other statutory provisions which:<br />
(a) grant the rightholder rights to receive fuller information;<br />
(b) govern the use in civil or criminal proceedings of the information communicated pursuant to<br />
this Article;<br />
(c) govern responsibility for misuse of the right of information; or<br />
(d) afford an opportunity for refusing to provide information which would force the person<br />
referred to in paragraph 1 to admit to his own participation or that of his close relatives in an<br />
infringement of an intellectual property right; or<br />
<strong>(e) govern the protection of confidentiality of information sources or the processing of personal<br />
data.</strong></p></blockquote>
<p>I mean come on.. If I, an uneducated IT-nerd with a taste for bodybuilding can find, read, and understand this, then why can&#8217;t the people preparing our laws do the same?</p>
<p>So, the question remains;</p>
<p><strong>WTF?</strong></p>
<p>Yep. That&#8217;s really the question. <em>What the f*ck?</em></p>
<p>This, <em>if voted through in parliament</em>, will create a situation like the one in the US where companies threaten with lawsuits that no one can afford to challenge, effectively forcing you to pay up even though you haven&#8217;t done anything wrong.</p>
<p>Next question is the use of IP-addresses as evidence. What value does an IP-address have in Sweden today where most ISPs ship unsecured wireless APs as the default router? Not much.</p>
<p>This also presents more questions, like &#8220;If downloading torrents in an internet café, is the café liable?&#8221; and &#8220;What are your rights if a neighbour uses your WLAN, willingly or without knowing it, and downloads pirated material? Are you liable?&#8221;.</p>
<p>And again, why does this law grant commercial interests powers that now even our police have? Where&#8217;s the logic? <strong>It&#8217;s so glaringly see-through, ordered and paid for, lobbyist crap</strong> that has been suggested as a law.</p>
<p>As I wrote in some of the first FRA-posts&#8230; <strong>Where will this end?</strong></p>
<hr/>
<p><em>Other writing about this in Swedish (plz use <a href="http://translate.google.com">Google translate</a>): <a href="http://rickfalkvinge.se/2008/10/13/piratjagarlagen-ipred1-del-i-bakgrund/">Rick Falkvinge (PP)</a>, <a href="http://opassande.se/index.php/2008/10/10/piraaater-piraaater-pirater/">Opassande</a>, <a href="http://henrikalexandersson.blogspot.com/2008/10/piratlagen-ljg-regeringen-medvetet.html">HAX</a>, <a href="http://elrubio.se/?p=2100">El Rubio</a>.</p>
<p>And <a href="http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2004:157:0045:0086:EN:PDF"><strong>here&#8217;s the whole crapfest</strong></a> that our swedish, newly suggested, law claims to be born out of.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2008/10/13/eu-ipred1-directive-to-be-enforced-in-sweden/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

