Posts

Anti-Online Game Addiction System implemeted in China (country-wide)

I am not in the online game industry and not sure about the statistics about online game addiction. But China government is serious about stopping online game to become a social problem. According the Chinese article below, a country-wide anti online game addiction system will go live in Jan 2007. The system will monitor user activity in RPG games. When a user spend more than 3 hours per day playing games, their gaming-scores will reduced to 50%. All online game company will need to modify their system to enable the monitoring. China is not leak of innovation when it comes to online monitoring and controls. http://www.ce.cn/cysc/tech/yw/200701/18/t20070118_10130593.shtml

Internet Blackout Seminar @ PISA

2 weeks after the earthquake strike Taiwan, Hong Kong is still suffering slow internet surfing, although 70% of website is not accessible. To understand the impact of this event to our society, PISA organized a seminar and invite industry experts. Panel Discussion: Internet Blackout - Lesson Learned from Large Scale Network Disruption Date 20-Jan-2007 (Sat) Time 2:00pm - 5:00pm

Undersea cable damage bring an issue of operantion risk in Basel

The earthquake stoke southern Taiwan on 26 Dec caused a major disruption of network communication in Hong Kong . It is believed that several cable connecting Taiwan, Japan and US were damaged and the restoration will take days. As banks and stocker brokers rely heavily on electronic settlement and straight though system, their operation are affected. Especially cross country trading, i.e. accepting oversea order to be executed in Hong Kong Exchange and at the same time, placing order to the US market. One of my broker in HK informed me that they will not be able to accept buy order until the network is restored (sell order is possible since they will execute instruction with telephone). The real issue is with STP system, there is a timeout value for each data transmissions and the timeout value is usually set to a reasonable time under normal network connections. The system may retry after timeout but the number of retry will only create more traffic on an already congested network. Th...

Latest developments in digital media distribution

These two days a bunch of news related to the digital media distribution appears across the globe. These news seems unrelated and did not go to the frontpage but their total effect will shape our future and the economy. Companies are committed to protect and capitalize their intellectual properties. An regulations is one of the way. Sony BMG settles suit over CDs BBC moves to file-sharing sites The HKSAR Government CITB announced yesterday the following consultation paper which discussed a lot of Internet related copyright issues.

UK banned DOS

I wrote an article in PISA Journal about UK proposed legislation in banning Denial of Services (DOS). Last week UK enacted a law of similarnature, you can read the comments and full legislation below. UK enacted Police And Justice Act 2006 The definition of a criminal offence is broad and includes "hinder access" ! "(a) to impair the operation of any computer, (b) to prevent or hinder access to any program or data held in any computer, or (c) to impair the operation of any such program or the reliability ofany such data,"

US Release guidance data discovery in civil litigation.

There are many discussions/articles on the web about the US Federal Rules of Civil Procedure (FRCP) Rule 26, 33, or 34. Below is a good summary. The rule set a 90 days period for lawyers of both parties to agree what needs to be prepared for the court. After this 90-days period, any data discovery request will likely be rejected by US court. New E-discovery Rules

Cybersecurity Workshop at Singapore

Image
I attended a Cybersecurity on 31 Oct and 1 Nov and the presentations are available online now. http://www.itsc.org.sg/downloa ds/presentations.html . The presentation from Koji on Monitoring Cyber Attacks showed many 3D visualization of attack patterns.

A New Blog

I have been quiet in the Blogsphere since I was busy with ISO SC27 activities and also PISA. PISA has a new blog created for discussion of local IT security matters. Take a look at http://pisa-security.blogspot .com/

Spammers manipulate stock markets

A news appear in BBC technology section and it is another trend that changed the unguarded world. Some people still believe email is an authenticated way of communication and trust the message it carries. But most email we received today are sent by machines! E-mails typically promote penny shares in the hope of convincing people to buy into a company to raise its price. People who respond to the "pump and dump" scam can lose 8% of their investment in two days.

US Senate approval of Council of Europe Cybercrime

I have been following the news about US Senate approval of Council of Europe Cybercrime Treaty. It is a milestone in both Internet law enforcement and Internet Governance. The most comprehensive article about this development was by ZDnet Asia There are a lot of Bloggers discussing how Americans is affected by this Cybercrime Treaty. From this blogs, I found most negative comments are worries out of ignorance. Their comments do not quote or make reference to the Treaty, most of the time are just suspicions. Treaty Article 19 – Search and seizure of stored computer data , US government may establish new provisions to seize individual data. But there are already lots of other American laws giving US government the right to do so. The Treaty only specifies the principles and each country is required to implement their own procedures. Below are some comments from the Blogsphere : entirely symbolic expand Big Government powers American ISPs would be obliged to obey other jurisdictions' ...

Unsolicited Electronic Messages Bill

Image
Hong Kong after months of public consultations is proposing an Unsolicited Electronic Messages Bill. This proposed bill has the following major features: 1. Enforce Opt-out (One needs to check before sending) 2. Technology Neutral (cover SMS, FAX and Email) 3. Prohibit address harvesting Generally, HK Government's effort is appreciated and the bill is comprehensive. There is not loophole the drafted bill does not quite get it. Under this bill, government propose to empower the Telecommunications Authority (TA) to set up "do-not-call registers", "which would be to facilitate recipients to opt out from receiving further commercial electronic messages from all electronic marketers and for senders of commercial electronic messages to ascertain the electronic addresses to which they should not send further commercial electronic messages unless they have specific consents. "This kind of register is very likely to be abused by malicious person to validate email address...

National firewall weakness

A member from PISA posted an article on how the China Firewall works and how to circumvent it. Basically, there is one weakness of China national firewall that the web hosting company could exploit. This is another example of "Technology wants to be free". ================================================ Abstract. The so-called "Great Firewall of China" operates, in part,by inspecting TCP packets for keywords that are to be blocked. If thekeyword is present, TCP reset packets (viz: with the RST ag set) aresent to both endpoints of the connection, which then close. However,because the original packets are passed through the rewall unscathed,if the endpoints completely ignore the rewall's resets, then theconnection will proceed unhindered. http://www.cl.cam.ac.uk/~rnc1/ignoring.pdf

Another War in the technology standard

IEEE was and is affecting everyone by defining how bit and bytes transmit. Without a standard, no two machines could talk to each other. In the past, US company were pioneer of technology standard and they were the only voice in standard setting committees. Now China wants to play the game and proposed WAPI standard. However, “In March, delegates representing standard bodies from 25 countries voted in favor of the IEEE's version over WAPI.China appealed the ISO decision and demanded an apology from the IEEE which it accused of "dirty tricks" in lobbying for its standard, Xinhua said.” I am glad to see China government is actively protecting national manufacturers (although most of them are still state-owned) by going to international forum like IEEE. If IEEE does not adopt China-backed WAPI, I believe China will not step down. There will be two standards for wireless transmission. Just like Japan has their PHS mobile phone system.

A blackhole in Cyber Law Enforcement

Image
Local Police is not investigating the reported ransomware case as it MAY fall in the remit of the National High Tech Crime Unit (NHTCU), which was amalgamated into the Serious and Organised Crime Agency (Soca) in April. After reading this news article, I have no clue when or who will investigate this case. It seems in UK the law enforcement have not keep up with cyber crime. The local police said it is international crime and they do not have resources to investigate. The Soca seems only investigate large and organized crimes. So when a crime involves international transactions and not organized, citizen in UK does not have any protection from their government even they report it to police. I believe what happens in UK is similar to elsewhere in the world. Police forces are not ready or willing to surf the wave of cybercrime. The resource to investigate is huge. There may be some wrongly reported cases. The legislation and prosecution is difficult. All are the reaso...

Anti-Ransomware

A counter-action of last blog : The password for unlocking hijacked-files by Ransomware are widely available online now. One nature of encryption is that there is a one-to-one match of general used encryption softwares/tools. When a hacker distribute his ransomware to the victim, there is one key for encrypting files. There is also one key to unlock these files. Each release of ransomware will share the same unlocking key and this is the weakness of ransomware. When the password is publicly available, the ransomware is useless. However, there maybe multiple releases with different keys. In such case, the hacker will need to keep track of which key corresponding which release. The logistics maybe overwhleming. One direction of development is there is a pattern of generating keys (like using a master key and the username, ip address or computer service patch number). Then the variant of keys of each releases will be multiplied.

Another case of computer crime

From BBC A woman from Greater Manchester has become a victim of an internet scam in which hackers hijack computer files and blackmail owners to get them back. Do anyone have a glue on how to translate ransomware in Chinese ?

US data retention law (to be)

Image
U.S. Attorney General said Internet service providers should retain subscriber information and network data for two years. Previously, I blogged about China's legislation on keeping user Internet-activity by ISP. Now US is going the same direction. When I was skeptical about Chinese government uses of IP address log, US government is doing it in the name of child pornography . I am more concern about the possible uses of these IP address. In HK and Japan , cases has been brought by music companies to request ISPs to disclose IP address logs and their correspondents. These information was used for copyright infringements. Once the detail user activity is kept. The uses of it will be unlimited and it is scary. There is nothing wrong for music company to sue for infringements. But if music company could use these logs, what will stop someone to bring civil cases against you and request ISP to disclose your internet activity. Recently, the Hong Kong Examination Authority used web serve...

One source of poverty

A study focused on the effects of Wal-Mart stores on poverty rates found that an estimated 20,000 families nationwide have fallen below the official poverty line as a result of the chain's expansion. Although I have not read the whole report nor the article confirmed the research method is scientific, I agree with the author that "found that one of the greatest effects of a Wal-Mart opening is the closing of mom-and-pop-type operations."

Promoting Chinese using Internet

BBC posted a new on China government is promoting Chinese using the Internet . Chinese is getting more attentions now. This brings me to think the process I learn English. Reading storybooks was the major part of it. Animal Farm , The Tale of Two Cities and Sophia were those I read. Those books were written not for learning English as a second language but they are interesting even after centuries. Chinese has some great storybooks too and I hope these books will enable people to understand Chinese culture. I am interested in knowing which books or stories will China government uses to educate Chinese to the world.

IP address logging has many faces

A council question on whether IP should be treated as Personal Data as defined in Section 2 of Personal Data (Privacy) Ordiance was asked by CK Sin . This issue was raised because Yahoo Hong Kong gave Internet usage information to China official and resulted in some arrestments in China. In reading the reply from government, I notice that government official referred to EU Directives but not China’s Law despite the fact that both EU and China adopt civil law legal system and HK is common law. I believe it is the intuitive reaction for HK government official to look for guidance from EU on privacy matters and it is this intuitive distinguish HK from other China cities. How will HK change to more like China cities or China cities changes to more like HK? I am not totally sure. Back to the real issue. I always think absolute anonymity is a fake concept in the Internet since each and every bytes transferred can be recorded with little incremental cost. ISPs have both the ability and capa...