Posts

Unsolicited Electronic Messages Bill

Image
Hong Kong after months of public consultations is proposing an Unsolicited Electronic Messages Bill. This proposed bill has the following major features: 1. Enforce Opt-out (One needs to check before sending) 2. Technology Neutral (cover SMS, FAX and Email) 3. Prohibit address harvesting Generally, HK Government's effort is appreciated and the bill is comprehensive. There is not loophole the drafted bill does not quite get it. Under this bill, government propose to empower the Telecommunications Authority (TA) to set up "do-not-call registers", "which would be to facilitate recipients to opt out from receiving further commercial electronic messages from all electronic marketers and for senders of commercial electronic messages to ascertain the electronic addresses to which they should not send further commercial electronic messages unless they have specific consents. "This kind of register is very likely to be abused by malicious person to validate email address...

National firewall weakness

A member from PISA posted an article on how the China Firewall works and how to circumvent it. Basically, there is one weakness of China national firewall that the web hosting company could exploit. This is another example of "Technology wants to be free". ================================================ Abstract. The so-called "Great Firewall of China" operates, in part,by inspecting TCP packets for keywords that are to be blocked. If thekeyword is present, TCP reset packets (viz: with the RST ag set) aresent to both endpoints of the connection, which then close. However,because the original packets are passed through the rewall unscathed,if the endpoints completely ignore the rewall's resets, then theconnection will proceed unhindered. http://www.cl.cam.ac.uk/~rnc1/ignoring.pdf

Another War in the technology standard

IEEE was and is affecting everyone by defining how bit and bytes transmit. Without a standard, no two machines could talk to each other. In the past, US company were pioneer of technology standard and they were the only voice in standard setting committees. Now China wants to play the game and proposed WAPI standard. However, “In March, delegates representing standard bodies from 25 countries voted in favor of the IEEE's version over WAPI.China appealed the ISO decision and demanded an apology from the IEEE which it accused of "dirty tricks" in lobbying for its standard, Xinhua said.” I am glad to see China government is actively protecting national manufacturers (although most of them are still state-owned) by going to international forum like IEEE. If IEEE does not adopt China-backed WAPI, I believe China will not step down. There will be two standards for wireless transmission. Just like Japan has their PHS mobile phone system.

A blackhole in Cyber Law Enforcement

Image
Local Police is not investigating the reported ransomware case as it MAY fall in the remit of the National High Tech Crime Unit (NHTCU), which was amalgamated into the Serious and Organised Crime Agency (Soca) in April. After reading this news article, I have no clue when or who will investigate this case. It seems in UK the law enforcement have not keep up with cyber crime. The local police said it is international crime and they do not have resources to investigate. The Soca seems only investigate large and organized crimes. So when a crime involves international transactions and not organized, citizen in UK does not have any protection from their government even they report it to police. I believe what happens in UK is similar to elsewhere in the world. Police forces are not ready or willing to surf the wave of cybercrime. The resource to investigate is huge. There may be some wrongly reported cases. The legislation and prosecution is difficult. All are the reaso...

Anti-Ransomware

A counter-action of last blog : The password for unlocking hijacked-files by Ransomware are widely available online now. One nature of encryption is that there is a one-to-one match of general used encryption softwares/tools. When a hacker distribute his ransomware to the victim, there is one key for encrypting files. There is also one key to unlock these files. Each release of ransomware will share the same unlocking key and this is the weakness of ransomware. When the password is publicly available, the ransomware is useless. However, there maybe multiple releases with different keys. In such case, the hacker will need to keep track of which key corresponding which release. The logistics maybe overwhleming. One direction of development is there is a pattern of generating keys (like using a master key and the username, ip address or computer service patch number). Then the variant of keys of each releases will be multiplied.

Another case of computer crime

From BBC A woman from Greater Manchester has become a victim of an internet scam in which hackers hijack computer files and blackmail owners to get them back. Do anyone have a glue on how to translate ransomware in Chinese ?

US data retention law (to be)

Image
U.S. Attorney General said Internet service providers should retain subscriber information and network data for two years. Previously, I blogged about China's legislation on keeping user Internet-activity by ISP. Now US is going the same direction. When I was skeptical about Chinese government uses of IP address log, US government is doing it in the name of child pornography . I am more concern about the possible uses of these IP address. In HK and Japan , cases has been brought by music companies to request ISPs to disclose IP address logs and their correspondents. These information was used for copyright infringements. Once the detail user activity is kept. The uses of it will be unlimited and it is scary. There is nothing wrong for music company to sue for infringements. But if music company could use these logs, what will stop someone to bring civil cases against you and request ISP to disclose your internet activity. Recently, the Hong Kong Examination Authority used web serve...

One source of poverty

A study focused on the effects of Wal-Mart stores on poverty rates found that an estimated 20,000 families nationwide have fallen below the official poverty line as a result of the chain's expansion. Although I have not read the whole report nor the article confirmed the research method is scientific, I agree with the author that "found that one of the greatest effects of a Wal-Mart opening is the closing of mom-and-pop-type operations."

Promoting Chinese using Internet

BBC posted a new on China government is promoting Chinese using the Internet . Chinese is getting more attentions now. This brings me to think the process I learn English. Reading storybooks was the major part of it. Animal Farm , The Tale of Two Cities and Sophia were those I read. Those books were written not for learning English as a second language but they are interesting even after centuries. Chinese has some great storybooks too and I hope these books will enable people to understand Chinese culture. I am interested in knowing which books or stories will China government uses to educate Chinese to the world.

IP address logging has many faces

A council question on whether IP should be treated as Personal Data as defined in Section 2 of Personal Data (Privacy) Ordiance was asked by CK Sin . This issue was raised because Yahoo Hong Kong gave Internet usage information to China official and resulted in some arrestments in China. In reading the reply from government, I notice that government official referred to EU Directives but not China’s Law despite the fact that both EU and China adopt civil law legal system and HK is common law. I believe it is the intuitive reaction for HK government official to look for guidance from EU on privacy matters and it is this intuitive distinguish HK from other China cities. How will HK change to more like China cities or China cities changes to more like HK? I am not totally sure. Back to the real issue. I always think absolute anonymity is a fake concept in the Internet since each and every bytes transferred can be recorded with little incremental cost. ISPs have both the ability and capa...

Ransom, the 21th centrury story

Image
Two ransomware cases were reported recently, both involved a Trojan control access to computer. The trend of cybersecurity is going from phishing to ransomware and it is alarming as these ransomware will cause real damages. 16 March PCworld 27 April Yahoo News As I am working in a bank, I notice that both cases relied on money transfer company(Western Uinion & e-Gold) for their operations. The convenient e-payment infrastructure is one of the factors for this type security incidence. The Torjan instructed victims to deposit money via this money transfer company and their computer/file will be unlocked. If the criminals are able to open a large amount of money transfer account for large scale operation, it will be a real danger to the Internet.

China Internet Security Law and WTO!?

There is a new Law effective in China being 1 March 2006. A brief outline is here http://news.xinhuanet.com/it/2005-12/29/content_3986087.htm The full legislation is here 互联网安全保护技术措施规定 . There are some interesting observations from an IT security perspective: 1. This regulation is under the regime of China Police Force. 2. Article 7.1.2 requires ISPs to have disaster recovery ability for vital database and system equipments. 3. Most of the regulation requires ISP or who operate internet services (loosely defined at Article 18) to record and store users login time, IP address, user account information and system logs. 4. ISP has to maintain records if they find any illegal materials being distributed to the public. (“What means by illegal in the China ?” is a mystery). 5. China Police could punish entity if they fail to perform Article 7 to 14. But there is no indication of what kinds of punishment should be. First, as a security professional, I appreciate China go...

A war ! and who wins

I read story(case study) about Britannica transforming from books to CD and their need to change business model in Internet Age. Now the same company face another challenge : Wikipedia, which has been a phenomena now. BBC reported a study comparing their accuracy : Wikipedia study 'fatally flawed' It seems Britannica always face challenges from "new media" and this time they choose to begin a war!

Web 2.0 & Democratization of Media

Image
When I go to class at HKU, two separate seminars bring a thinking threads to the current Web2.0 discussion. Professor Bebo White spoke of user empowerments at Web 2.0 and the Future of Social Networking and Online Communities . And this empowerment results in Democratization of Media . Web 2.0 is still in a developingstage but the decentralized publishing is really changing how the society works. My view is once the media is effectively decentralized and people being to information from the democratized media (like blog, wiki and off-line chat) for decision making, the result will be a collaborated decision making. The other think thread is the influence of each individual to the world will be greater since the voice will be heard (either collectively or individually). However, all this has to be based on a trustworthy web. P.S. take a look at www.yackpack.com a offline chat services

2006 Spring (open source and collaborations)

On cyber space, I was hibernated for last winter. In real world, lots of new ideas and works. During this time, I extend my horizon from IT security to a larger world ; open source and web 2.0. And now I am sure I can't handle all these new concepts coming in. Mostly the time were spent on understanding the open source world. It has been evolving at a pace, no one alone can understand the impact of it. In Chinese, bamboo after spring rain. Will have more thinking threads along these new lines.

MS 05-51 buggy patch

My computer did not show any network connection after I installed my computer with all 9 security patches. After some search, MS also noticed this problem and the update is below. http://support.microsoft.com/?kbid=909444 This experience prompt me for 2 issues (one technical , one management) 1. MS recommend one setting "Everyone group should have Bypass Traverse Checking permission". But this violated the default server built standard at some companies. The servers before put into production was hardened and this permission was changed to Domain User or Authenticated User. Should we ask ourselves "Are we doing too much security hardening?" or "Why Everyone is need this permission?" 2. While it took 5 days for malicious hacker to publish exploit code, MS took 4 days to resolve their buggy patch. How IT admin is going to manage their internet facing server if running MS IIS ? Patch too soon, we are at risk of MS bug. Patch too late, we are at risk of exploi...

Message from the court

BBC news reported two twenty-something were convinced for 3 and 6 months. What alter me is that the judge by putting them behind bars was sending message to other young people. “Young men, like you, have to be deterred from committing this kind of offence.” By Judge Beatrice Bolton http://news.bbc.co.uk/1/hi/england/4319942.stm

Behavior becomes mainstream

Reading of this weeks Economist on mandatory pension (page 63), quote below " Given the choice between $1000 in now and $1100 next year, an individual may well take the money at once ... ... Behavioral finance also shows the surprising extent to which people are swayed by the way that choices are framed. " Behavior economy is going mainstream. As a security professional, I usually encountered people (even myself) taking risks just because it is convenient! And security professional should make use of behavior to control IT related risks.

Windows Online Crash Analsysis (OCA) Security

Image
Today when I was using MS word to edit a document, I encountered an error which hangs my application. By forcing it to quit, Windows XP started Microsoft Online Crash Analsysis (OCA) and asked me to send an error report to Microsoft. OCA has been with us for sometimes and I usually clicked on “OK” with an urge to start working as soon as possible. However, today I looked into what was happening behind the simple click and found something unexpected. Opening 5MB file generated by OCA with a notepad, I was stunned to find my entire document appear in plain text (see the figure below). The error-reporting module actually transfers the document I am editing to Microsoft. Immediately, I checkout their privacy website to find out if is declared and it is (see the red circle). At this moment, a lot of questions pop up 1. Most importantly, are the document content necessary for the error investigations? 2. I believe with million of error reporting, Microsoft and their staff will not have the r...

Growing game indsutry ... ...

A highly contaminated network "About 6000 machines connected to the network... of these 1100 were infected...no less than 400 000 different species of your least favorite malware were identified! " A read of this Blog shows how immediate pleasure overshadowed the risk of virus infections. While firewall and patches will keep the computer safe, PC gamers who are afraid of speed deterioration let themselves open for real world attacks. The figure shows 18.3% of gaming PCs are vulnerable. With the ever-growing PC game industry, the family of Zombie machines is also growing. Again, IT security is more on human behavior than technology. My advice is to have the machine dual-boot, one for productive work and one for adventures. (A side question is do we need 2 OS licenses for a dual boot machine?)