Blog Archive
-
2016
(1336)
-
April(1335)
- Samsung Galaxy S7: 2016's Finest Android Phones
- Samsung Galaxy S7, Galaxy S5, Galaxy Note Edge Wit...
- Apple updates MacBook, upgrades MacBook Air
- Apple iPad Air 2 review: Still a great tablet
- Apple iPad Air review
- Microsoft Surface Pro 4 review: A fantastic Window...
- Google.com is “partially dangerous”, says Google
- LG G5 review: Modular expansion and twin cameras s...
- Best hybrid cars 2016: The six best hybrid cars fo...
- Best smartphones of 2016: The best mobile phones i...
- iPhone 7 rumours, specs and features: 8 things to ...
- EU Google antitrust case: Everything you need to know
- LeEco Le 2, Le 2 Pro and Le Max 2: No headphone so...
- Samsung Galaxy TabPro S review: Super screen, but ...
- How to get American Netflix on all your devices in...
- Apple Car rumours and leaks: Former Tesla Vice Pre...
- How to install Exodus on Kodi: Get one of XBMC’s b...
- Recover all your forgotten passwords
- How to cancel Netflix: Stop your Netflix subscript...
- HTC 10 review: A great smartphone return to form b...
- President Barack Obama's UK visit shakes up the Lo...
- Should I upgrade to Windows 10?
- Microsoft, seagulls and magic: An interview with M...
- Opera just added a free VPN as a bonus feature for...
- HP Chromebook 14 review: Solid, reliable and depen...
- How to remove a device from Netflix: Here’s how to...
- Amazon Fire review: Now available with 16GB storage
- Xplova X5 (hands on) review: This cycling computer...
- Acer Chromebook 14 review (hands on): A Chromebook...
- Now there's an app to crowdfund your honeymoon
- Shell’s Concept Car uses petrol to save the planet
- Tesla Autopilot review: We test Elon Musk’s autono...
- iOS 10: Rumours, speculation, mock-ups, and what w...
- This AI is guessing who’s going to die next in Gam...
- Microsoft's Windows Phone results: Not pretty, but...
- Android N review (first look): Now available for t...
- Volvo wants to sell one million hybrid and electri...
- How GCHQ has been accessing YOUR personal data
- Nissan Leaf (2016) review: We drive the UK's most ...
- Raspberry Pi 3 vs Raspberry Pi 2 vs Raspberry Pi B...
- Best electric cars 2016: The four best electric ve...
- Tesla Model S (2016) review: Still the ultimate el...
- Amazon blocks sale of Fifa 16, GTA 5 and many othe...
- UK government wants to punish online pirates with ...
- Opera VPN: Can the privacy-enhanced browser really...
- Mobile game revenues set to overtake that of PC in...
- Ads trick and force Germans to listen to plight of...
- What became of the cartoon video game mascot?
- Google I/O 2016: What key announcements to expect ...
- Microsoft profits fall by 25% due to drop in Windo...
- Galaxy Note 6 rumoured to sport 5.8in curved scree...
- Mexican voter database containing 93.4 million rec...
- Bangladesh bank cyberheist was a hacker's dream af...
- China wants to visit Mars by 2020 and beat Nasa to...
- BTCC Bitcoin mining pool launches rapid connection...
- BLOCKCHAIN REVOLUTION by Don Tapscott and Alex Tap...
- Apple's Find My iPad tool leads Thai police to not...
- US agency steps up Twitter campaign against textin...
- Samsung Galaxy S7 Edge: Android security update fo...
- Blizzard offering 13 free Whispers Of The Old Gods...
- Apple iTunes Movies and iBooks go dark in China, c...
- Blizzard releases first free Overwatch comic featu...
- Google and Microsoft drop all regulatory complaint...
- Blizzard's Jeff Kaplan reveals how MMO Titan's 'de...
- Moto G4: Release date, specs and pricing expected ...
- Shakespeare's 400th Anniversary: Ian McKellen unve...
- Cortana on Windows 10: Tips and tricks for Microso...
- How to Turn Your Surface Pro 4 Into A Desktop PC
- Samsung Galaxy Note 6 Release: 6 Things to Know Ri...
- How to Change the LG G5 Lockscreen & Wallpaper
- Eclipse Black Ops 3 DLC Tips
- Best Samsung Galaxy S7 Deals
- 14 Best Samsung Galaxy S7 Cases
- HTC Vive Hands On: Three Things You Should Know
- 7 Apple Pencil Holders to Keep Your’s Safe
- Is Microsoft OneDrive Worth Buying?
- Minecraft Realms for iPhone, Android & More: What ...
- Another Android Smartphone with 6GB RAM Spotted in...
- LinkedIn Launches Android/iOS Application to Help ...
- Sony Expands Marshmallow to Xperia Z2/Z3 Variants,...
- ZUK Z2 Pro Official Image Teased Ahead of April 21...
- Nubia Z11 Mini Goes Official with Snapdragon 617 C...
- Samsung Galaxy C7 Specs Leak in Benchmark: Snapdra...
- Motorola Moto G (4th Gen) Caught on Video Ahead of...
- VLC for Windows 10 Mobile Public Beta Launching Ne...
- Opera Mini Won't Receive Any Major Updates for Win...
- Samsung Plans to Build Powerful 18-24MP Camera wit...
- Motorola Moto G4 Plus First Press Render Leaks Online
- Huawei Honor V8 with Dual-Camera Setup Coming on M...
- World’s Smallest Android Smartphone Comes with 2.4...
- LeEco Le Max2 with 5.7-Inch Quad HD Display and 6G...
- Facebook Messenger for Android and iOS Updated wit...
- ZUK Z2 Pro Goes Official as Another Smartphone wit...
- Huawei P9 Lite Announced with 5.2-Inch Display, 13...
- Acer Liquid Zest Plus Launched with Massive 5,000 ...
- Samsung Galaxy S7 Clone Looks Shockingly Real - Video
- LG G5 SE Goes Official with 5.3-Inch Quad HD Displ...
- Fallout Shelter for Android/iOS Updated with Scrap...
- Sony Xperia Z3 Is the First Non-Nexus Device to Re...
- Huawei and Leica Release Statement on P9 and P9 Pl...
- Samsung Galaxy Note 6 Could Pack 4,000 mAh Battery...
- Xiaomi Mi Max Phablet Gets a Teaser Ahead of Offic...
- Qualcomm Addresses Concerns Over Quick Charge 3.0 ...
- Alcatel Pop 7 LTE Tablet Arrives at T-Mobile, Cost...
- Subway Surfers Developer Launches Frisbee Forever ...
- Intel-Powered 2-in-1 Tablet with Windows 10 and 10...
- Sony Xperia X Coming to the UK in May, Xperia XA A...
- Best smartphones of 2016: The best mobile phones i...
- AT&T reveals price and release details for the Sam...
- Samsung Galaxy Phones Prone to Hacking via USB Cab...
- Galaxy S7 and Galaxy S7 Edge dubbed world’s best p...
- Samsung Galaxy A7 (2016) review: External beauty i...
- Boost Mobile adds Samsung Galaxy J7, LG and Kyocer...
- Xiaomi Mi 5 review: Extraordinary value Android ph...
- HTC phone hopes to rival iPhone, Galaxy
- Samsung Galaxy S8: what we want to see
- Galaxy S7 New 'Top Rated Phone', consumer Reports...
- One month with the Samsung Galaxy S7 Edge: Can the...
- Researchers develop a mobile app that lets visuall...
- Facebook usage over Tor surpasses one million mont...
- India to become second largest smartphone market b...
- Free Wi-Fi content on trains and buses; this is ho...
- China ban on Apple services is a challenge for key...
- Android N Developer Preview moves beyond Nexus dev...
- Apple may be exempted from local sourcing norms fo...
- Acer Liquid Zest Plus announced with massive 5,000...
- US Justice Department withdraws NY iPhone unlockin...
- Microsoft, Google agree to withdraw regulatory com...
- February(1)
-
April(1335)
Sumsung Galaxy User Guide
Android Tutorials
Labels
Recent Posts
Blog Archive
-
Apple Watch 2 fans have a happy news here: At last, the brand has opened the box and confirmed its launch date which will be during the Worl...
-
Apple has lowered the prices of all iPhones sold officially in Japan by 10%. There is no official statement on the reason for the price cut,...
-
By now you've likely heard that the latest Tesla vehicle, the Model 3 , has been in high demand almost immediately since its debut early...
-
In an effort to further improve its service, Facebook has yet again updated it News Feed ranking algorithm. The social networking company sa...
-
Everyone likes free apps, but sometimes the best ones are a bit expensive. Now and then, developers put paid apps on sale for a limited time...
-
By now you've likely heard that the latest Tesla vehicle, the Model 3 , has been in high demand almost immediately since its debut early...
-
Apple has announced its update of the MacBook with better specs and a new color. In a press release two days ago, Apple said it installed ...
-
[unable to retrieve full-text content] SIM only deals On this page you'll find links to the best SIM only deals currently available in t...
-
Privacy is always one of the biggest priorities in this time when everything can be searched with just a click of a button. Mobile messaging...
Like US On Facebook
Followers
Total Pageviews
In 2000, the Secure Digital Music Initiative held a contest to test out a new watermarking method for digital audio. Among the participants was a team led by Edward Felten, a graduate of Caltech and the University of Washington who had acted as a witness for the government in the 1998 case of the United States vs. Microsoft.
Within three weeks, Felten and his team had managed to remove the watermark from the stipulated audio sample, satisfying the automated judging system implemented by the SDMI. This could have earned them a cash prize, had they not waived their right to the reward in order to dodge a binding confidentiality agreement.
Upon presenting their work to SDMI officials, the research team was informed that their entry was invalid, referring to a contest rule stipulating that sound quality couldn’t take a hit. This was a setback, but not an out-and-out defeat — happy with their work, the team set about developing the research into a scientific paper to be presented at the 2001 Information Hiding Workshop.
Related: Apple just fixed an iMessage bug that researchers called easily exploitable
Weeks before the event, Felten received a letter from SDMI Foundation Secretary Matthew Oppenheim, which stated that sharing the team’s findings could “subject your research team to enforcement actions under the DMCA.” Yes — simply revealing the existence of an exploit can result in fines.
But what influence does copyright law have over a research paper on audio watermarks? As Felten and many other academics have found out, a lot more than it should.
DMCA Takedown
Jason Hong is an associate professor in the school of computer science at Carnegie Mellon University. While he’s never fallen foul of copyright law in his own research, he’s well-versed in the problems some of his colleagues have faced. “There have been other researchers who have had far worse experiences than me,” he told us, before illustrating his point with the aforementioned case of Edward Felten.
It’s worth noting at this point that Felten wasn’t and isn’t some maverick computer science researcher liable to go rogue with his findings. By all accounts, he’s rather trustworthy. The White House named him Deputy U.S. Chief Technology Officer last year.
Even if you put in the most trivial protection method, it’s a copyright violation to circumvent that.
Despite being developed as a means of helping content owners protect their libraries in the Internet age, the DMCA affects security researchers because their work commonly focuses on reverse-engineering protection systems that they did not create. That’s something the DMCA explicitly prohibits.
“There’s a provision that says if there’s any kind of technological protection method, security researchers can’t bypass that,” Jason told us. “Even if you put in the most trivial protection method, it’s a copyright violation to circumvent that, unless you get permission beforehand from the copyright owner.”
Sometimes, that permission is relatively easy to come by — just another annoyance on the road to a research project. In other situations,companies have good reason to keep technology shrouded in secrecy. But some organizations abuse the legislation, using it a shield to keep researchers silent.
Related: VTech waves off security responsiblity after major 2015 breach
“Remember the whole case with Volkswagen?” Jason asked. “How they had changed their software? Previously, it would have been very difficult for people to do that kind of research, because you had to have permission from the car manufacturer to inspect all their software. In all likelihood, those kind of behaviors could have been found earlier if people had access to it.”
Indeed, a round of exemptions proposed a month after the Volkswagen emissions scandal hit headlines did set in motion a plan to give researchers better ability to study in-car technology. However, the way the exemption process plays out is yet more evidence that the DMCA can’t cater to the ever-increasing needs of security.
Let’s Make a Deal
The cars on our roads are mobile computers, and that means they’re vulnerable to new exploits. The exemption proposed in 2015 is set to go into effect later this year, and will allow security researchers straightforward access to the software that needs to be inspected.
“Almost all the car manufacturers were against this,” Jason told us. “And to some extent, the statements they were making do make sense.”
Auto makers are concerned loosening the restrictions too much might encourage someone to make changes to the software that’s running in their vehicle. That could be as innocuous as removing a volume limiter on their stereo, but it could also put the driver, or the people around him, in harm’s way.
“You don’t want people just making arbitrary changes to the software in a car,” Jason continued. “But at the same time, [restrictions] also make it harder for security researchers to do their job, and to ensure people’s safety.” It’s a question of whether secrecy is a good enough substitute for extensive security research.
Deirdre Mulligan is an associate professor in the school of information at Berkeley, a co-founder of the Center for Democracy & Technology, and the first director of the Samuelson Law, Technology & Public Policy Clinic. Simply put, she’s no stranger to the areas where technology, law and the public interest collide.
Deirdre also referred to the case of Edward Felten, using it as an example of how legislators have attempted to demonstrate their awareness of the plight of researchers. “The Department of Justice wrote them a letter and said ‘we’re not going to shoot you; this is not the sort of thing that we would go after, this is academic research, this is a publication.”
In an ideal world, that would be enough to allow work to continue without researchers looking over their shoulders just to check there are no copyright lawyers lurking. In reality, there are forces that make the idea of “good faith” research seem naive.
Getting a PhD is Hard Enough
Between exemptions, the implication that cases made against legitimate research won’t be pursued, researchers should be able to pursue their work without worries of legal action against them based on DMCA legislation.
In reality, they’re working in a gray area of the law. Sure, they might be acting in the public interest — but what if their research leads them to tinker with a system that an unscrupulous corporation would rather keep closed? Depending on the product, a security firm or academic institution might find itself in a legal case they don’t have the funds to contest.
What Congress did was say, ‘OK, we don’t feel like taking the time to figure this all out now.
“There are so many areas that you could conduct research in that don’t raise any risk,” Deirdre explained. “If you’re advising your new PhD student or your new post-doc, if there’s an area where they might end up drawing a lot of ire and getting people in the department pissed off at them because, you know, some company’s now really angry at the university, or somebody files a lawsuit — getting a PhD is hard enough. You don’t want to create additional headaches for people.”
Jason added that individuals might find their decision-making process changed, purely because their end product might be inadmissible. “Because security researchers know that this law exists, there’s probably a lot of things that they wouldn’t do.” Work is of little use in academic circles if it can’t be published.
Related: After database debacle, MacKeeper hires the security researcher who outed vulnerability
From that perspective, it’s easy to understand the frustration felt by security researchers like Jason, and advocates like Deirdre. “What happens when you adopt a law that doesn’t take into account the multiple values that it might impact?” she asked. “The law might not be fit for purpose.”
“What Congress did instead was say, ‘OK, we don’t feel like taking the time to figure this all out now, and we realize that things may change and we may need different sorts of exceptions to the anti-circumvention rule over time —we’re going to create this triennial rule-making procedure, so that people can come and make their case.'”
“So, on the one hand, you can say that it was good that they did that. And, on the other hand, the process is one that makes it a little bit easier recently. But generally it’s a process that requires a pretty high burden of truth.”
Public Interest and the Public Interest
Researchers and advocates are well aware of the difficulties caused by the DMCA. Yet we don’t often see such topics make headlines. “It’s not something that’s on the average person’s radar,” said Jason.
Not all of us will dabble in security research, but we would all benefit from that work being done. More to the point, we’ll all suffer if we don’t enable institutions and individuals to carry out this type of study.
Deirdre reels off a list of federal agencies working to push for more people to enter the field of security research, and they’re being supported by efforts from private entities. “At Berkeley, where I work, we got a multi-million dollar grant from the Hewlett Foundation that’s trying to improve the state of cybersecurity by growing the discipline,” she added. “They’re trying to do field development because we need more activity in this area.”
As encouraging as it is to see time and energy being dedicated to kindling the next generation of security researchers, it seems at odds with the obstacles standing in the way of the work itself. Most people outside of the research community don’t have a reason to campaign against the way DMCA and other legislation is being implemented.
“I have worked on encryption policy since the mid 90s, and I can tell you it has not been a sexy hot topic among my friends and family,” Deirdre told us. “Today, I can walk into a room and they’re like, ‘oh! you probably know a lot about this Apple v FBI thing.'”
Related: YouTube changes its tune, will now defend select channels against DMCA takedowns
The Sony Pictures email hack, the dump of Ashley Madison member information, search engines that prey on unsecured webcams, the shocking video of a Jeep being ‘killed’ remotely — we’re inundated with evidence that security research should be a top priority. Yet laws like the DMCA force security researchers to work under constant legal threat.
“Researchers, many of whom are funded by the National Science Foundation, and who are doing work to make our nation more secure, shouldn’t be required to place them and their institutions at risk of a lawsuit — that’s just not reasonable,” said Deirdre. “My hope is that we can create, not just one-off exceptions that allow research under the DMCA for things that get a three-year exemption, but a broader set of limitations on existing laws.”
“I think on balance, most people would think that human safety, security, and privacy research is probably more important to protect,” Deirdre concluded. “But a more narrowly written law could allow us to have both.”
Source : http://www.digitaltrends.com
0 comments:
Post a Comment