Showing posts with label Officials. Show all posts
Showing posts with label Officials. Show all posts

Thursday, June 20, 2013

Bits Blog: Privacy Officials Worldwide Press Google About Glass

An attendee tries Google Glass during the Google I/O developer conference in San Francisco.Justin Sullivan/Getty Images An attendee tries Google Glass during the Google I/O developer conference in San Francisco.

Ten government privacy and data protection officials from seven countries have asked Google to address privacy concerns related to its wearable computing device, Glass.

The letter was sent to Larry Page, Google’s chief executive, by 10 commissioners from Canada, the Netherlands, Australia, New Zealand, Mexico, Israel and Switzerland. It comes after a letter sent by eight members of Congress in May raising similar questions about Glass and privacy.

“We would be very interested in hearing about the privacy implications of this new product and the steps you are taking to ensure that, as you move forward with Google Glass, individuals’ privacy rights are respected around the world,” the officials wrote.

Glass, which is not yet available to the public, tethers to a user’s cellphone and has much of the same functionality, like text messaging and phone calls. It can also take photos and record video hands-free, and apps from news organizations, social networks, Google Maps and others send alerts and updates to a screen above the user’s right eye.

The officials raised fears of “ubiquitous surveillance” and asked about Google’s privacy safeguards, what it plans to do with the data the devices collect and how it is addressing “the broader social and ethical issues” raised by Glass. They lamented that Google has not yet reached out to data protection authorities to discuss the privacy implications of Glass.

Mr. Page addressed similar questions at Google’s shareholders meeting this month, where he made his first public comments about the issue. He said that many people already carried cellphone cameras everywhere they go, and that Glass was no different.

“People worry about a lot of things that, when we use the products, don’t turn out to be an actual concern,” Mr. Page said.

Many people at Google wear Glass, he said. “When you go into the bathroom, you don’t collapse in terror that people might be wearing these in the bathroom, just like you don’t collapse in terror that someone will hold up a cellphone in the bathroom.”

“I would encourage you not to create fear and concern about technological change until it’s out there and we understand the issues,” Mr. Page said.

Susan Molinari, Google’s vice president for public policy, responded this month to the members of Congress. She wrote that Glass would not include facial recognition, users would be able to wipe data from the device if it was misplaced or stolen and that Google was relying on early users currently testing the device to help the company shape the discussion about it.

In the letter, the privacy commissioners said they wanted a demo of the as-yet-unavailable product.

“Would Google be willing to demonstrate the device to our offices and allow any interested data protection authorities to test it?” they asked.

Sunday, May 26, 2013

New Computer Attacks Come From Iran, Officials Say

The targets have included several American oil, gas and electricity companies, which government officials have refused to identify. The goal is not espionage, they say, but sabotage. Government officials describe the attacks as probes looking for ways to seize control of critical processing systems.

Investigators began looking at the attacks several months ago, and when the Department of Homeland Security issued a vaguely worded warning this month, a government official told The New York Times that “most everything we have seen is coming from the Middle East.”

Government officials and outside experts on Friday confirmed a report in The Wall Street Journal that the source of the attacks had been narrowed to Iran. They said the evidence was not specific enough to conclude with confidence that the attacks were state-sponsored, but control over the Internet is so centralized in Iran that they said it was hard to imagine the attacks being done without government knowledge.

While the attackers have been unsuccessful to date, they have made enough progress to prompt the Homeland Security warning, which compared the latest threat to the computer virus that hit Saudi Aramco, the world’s largest oil producer, last year. After investigations, American officials concluded that the Aramco attack, and a subsequent one at RasGas, the Qatari energy company, were the work of Iran.

Taken together, officials say, the attacks suggest that Iran’s hacking skills have improved over the past 18 months. The Obama administration has been focused on Iran because the attacks have given the Iranian government a way to retaliate for tightened economic sanctions against it, and for the American and Israeli program that aimed similar attacks, using a virus known as Stuxnet, on the Natanz nuclear enrichment plant.

That effort, code-named Olympic Games, slowed Iran’s progress for months, but also prompted it to create what Iran’s Islamic Revolutionary Guards Corps calls a cyber corps to defend the country.

This week Iran denied being the source of any attacks, and said it had been a victim of American sabotage. In a letter to the editor of The Times, responding to a May 12 article that reported on the new attacks’ similarity to the Saudi Aramco episode, Alireza Miryousefi, the head of the press office of the Iranian mission to the United Nations, wrote that Iran “never engaged in such attacks against its Persian Gulf neighbors, with which Iran has maintained good neighborly relations.”

“Unfortunately, wrongful acts such as authorizing the 2010 Stuxnet attack against Iran have set a bad, and dangerous, precedent in breach of certain principles of international law,” he wrote.

American officials have not offered any technical evidence to back up their assertions of Iranian authorship of the latest attacks, but they describe the recent campaign as different from most attacks against American companies — particularly those from China — which quietly siphon off intellectual property for competitive purposes.

The new attacks, officials say, were devised to destroy data and manipulate the machinery that operates critical control systems, like oil pipelines. One official described them as “probes that suggest someone is looking at how to take control of these systems.”

The White House would not confirm that Iran was the source, but Laura Lucas, a spokeswoman for the National Security Council, said that “mitigating threats in cyberspace, whether theft of intellectual property or intrusions against our critical infrastructure” was a governmentwide initiative and that the United States would consider “all of the measures at its disposal — from diplomatic to law enforcement to economic — when determining how to protect our nation, allies, partners, and interests in cyberspace.”

In the past, government officials have privately warned companies under threat. But Homeland Security was able to issue a broader warning because of an executive order, signed in February, promoting greater information sharing about such threats between the government and private companies that oversee the nation’s critical infrastructure.

An agency called ICS-Cert, which monitors attacks on computer systems that run industrial processes, issued the warning. It said the government was “highly concerned about hostility against critical infrastructure organizations,” and included a link to a previous warning about Shamoon, the virus used in the Saudi Aramco attack last year.

That attack prompted Leon E. Panetta, then defense secretary, to warn of a “cyber-Pearl Harbor” if the United States did not take the threat seriously.

Saudi Aramco and RasGas both said that the attackers had failed in their efforts to infiltrate their oil production systems.

Government officials also say Iran was the source of a separate continuing campaign of attacks on American financial institutions that began last September and has since taken dozens of American banks intermittently offline, costing millions of dollars. But that attack was a less sophisticated “denial of service” effort.

Jeff Moss, chief security officer at the Internet Corporation for Assigned Names and Numbers, the private body that oversees the basic design of the Internet, said: “For the last year, Iran has been focused on disrupting financial institutions’ Web sites. If they are going after energy, and opening a multiprong front, at what point does it cross from annoyance to a threshold?”

Sunday, November 4, 2012

In Crisis, Public Officials Embrace Social Media

It is usually Mr. Cuomo’s aides, not the governor, typing the messages. But he and his staff recognize that social media “is a highly effective method of communicating information in a time of crisis,” said Joshua Vlasto, Mr. Cuomo’s deputy communications director. The governor’s followers have increased to 50,000 from 20,000 last Friday

Although phone service has been spotty in some places across the Northeast, people with working signals have been reliant on texting and social networking to a degree not seen during previous disasters.

In turn, governors, mayors and emergency workers from North Carolina to Maine have fully embraced Twitter, Facebook and YouTube, knowing that constituents unable to watch television can still receive texts and Twitter messages.

Political leaders are still having “Voice of God” news conferences, of course, but aides now tend to post their words on Twitter at the same time, trying to spread accurate information and convey a sense of control amid the chaos and confusion.

“Twitter makes it possible for a public official to create a round-the-clock press conference, simultaneously informing their staff, the public and the press,” said Andrew Rasiej, the founder of the Personal Democracy Forum. Praising the effectiveness of the Web during the recovery from the storm, he said, “We can now separate public officials’ embrace of social media as either pre- or post-Sandy.”

Even before the storm, states showed newfound creativity in getting the word out. Maryland’s emergency management office promoted a Pinterest page with resources and photos of past floods to prod people to get ready. On the Outer Banks of North Carolina, a county manager posted videos to YouTube about preparations before the storm passed by, and videos of damage afterward.

Political campaigns big and small started realizing the effectiveness of these tools several years ago — and now the lessons learned are being applied by the winning candidates.

“Social media is an integral part of an emergency communication plan,” said J. Tucker Martin, the director of communications for Gov. Bob McDonnell of Virginia, who was elected in 2009. “I think a few years ago, it would have been considered a nicety, where it is now considered essential.”

Shortly after Connecticut’s governor, Dannel P. Malloy, was inaugurated in 2011, a couple of big snowstorms quickly showed how useful social media could be in delivering emergency information, said David Bednarz, a deputy communications manager who operates Mr. Malloy’s Twitter account.

Then came Hurricane Irene in August of last year, followed by a freakish October snowstorm. As more and more citizens lost power, the number of Mr. Malloy’s Twitter followers soared.

“Perhaps a sign of the times, we have found that many people do not own battery-operated radios anymore and can’t listen to the governor’s live news briefings,” Mr. Bednarz said. “Using their cellphones, Twitter was the last resource they had available to them to find out what was happening while they were stuck in their homes with no power.”

Across Manhattan’s powerless areas this week, people with smartphones tended to huddle around the few remaining Wi-Fi hot spots rather than battery-operated televisions or radios.

Some agencies have also used the Web to correct news outlets that provided misleading information. On Wednesday, when The New York Post reported on its Web site that Mayor Michael R. Bloomberg planned to ban all passenger cars in Manhattan, the mayor’s press secretary posted a Twitter response in capital letters, “NOT CORRECT.”

The Post deleted the story, which overstated the car restrictions that were announced an hour later.

Social media styles vary. Power utilities tend to be matter-of-fact, keeping emotion to a minimum. Mr. Cuomo is data-driven; Mr. Vlasto said the staff treats his Twitter page “very much like a news operation.”

Gov. Chris Christie of New Jersey, on the other hand, is oftentimes personal. (“The rides I took my kids on this summer are in the Atlantic Ocean,” he wrote Tuesday night.)

Mayor Cory Booker of Newark, a pioneer of Twitter politicking, replies to more people than most public officials. When a woman who lives around the corner from Mr. Booker asked on Thursday morning, “Why don’t we have our power back?” he replied that he did not know.

But he added that anyone in the neighborhood “can come to my house” to warm up and charge their cellphones. A few hours later, the woman said on Twitter, she was at his home, charging her phone and watching the movie “Happy Feet.”

Thursday, October 25, 2012

E.U. Antitrust Officials Say Microsoft Violated Deal

BRUSSELS — European regulators on Wednesday charged Microsoft with an antitrust violation for failing to live up to a prior agreement to give users of its Windows software equal access to rival Internet browsers.

The decision by JoaquĆ­n Almunia, the European Union antitrust commissioner, opens Microsoft up to a substantial fine for defying the terms of a settlement reached in 2009.

The case also represents the first time a company facing antitrust penalties from Europe’s top enforcer has been sent a so-called Statement of Objections for neglecting to comply with the terms of a settlement, which allows companies to avoid fines.

“Companies should be deterred from any temptation to renege on their promises or even to neglect their duties,” Mr. Almunia said.

Mr. Almunia put Microsoft on notice that it must include adequate access to rival browsers in European versions of its next-generation operating system, Windows 8, which goes on sale at the end of the week.

Mr. Almunia said he warned Microsoft officials “at the highest level possible” of his concerns about Windows 8 and had made clear to them what “should be avoided if they don’t want to take the risk of new investigations.”

Microsoft apologized for the latest infringement when it came to light in July, calling it a technical problem it had learned of only recently.

On Wednesday, Microsoft said, “We take this matter very seriously and moved quickly to address this problem as soon as we became aware of it.”

“Although this was the result of a technical error, we take responsibility for what happened, and we are strengthening our internal procedures to help ensure something like this cannot happen again.”

The significance of Wednesday’s action could reach beyond Microsoft. It comes as Mr. Almunia’s office is negotiating with Google to try to settle the commission’s concerns about that company’s dominance of the Internet search and advertising markets.

Legal experts say that by cracking down on Microsoft, Mr. Almunia is also sending a warning to Google that settling its case may not be possible unless there are also effective monitoring mechanisms.

Mr. Almunia said that the case involving Google was different and that there was no direct link with his decision to charge Microsoft. But he underlined that the move against Microsoft was “a very serious message not to infringe the commitments that have been agreed and have that been given status as legally binding.”

Mr. Almunia can levy a fine totaling up to 10 percent of a company’s global annual revenue. In Microsoft’s case that could mean a penalty of $7 billion, but analysts say it is probably unlikely to reach that level.

The largest single fine ever levied by the European antitrust authorities was €1.1 billion, or $1.4 billion, in 2009 against Intel for abusing its dominance in the computer chip market. Intel is still appealing that ruling.

Microsoft has paid a long series of fines to European regulators over the past decade.

In 2008, Microsoft was fined nearly €900 million in so-called periodic penalties for defying a decision that regulators had imposed on the company.

In June, the General Court, the second-highest in the Union, handed a small victory to Microsoft by reducing the fine by €39 million to €860 million after finding that the commission had miscalculated the amount.

Microsoft also paid fines of €497 million and €281 million for separate but related offenses, bringing the total to €1.7 billion during its battle with European regulators.

The current dispute stems from the settlement of a case concerning Microsoft’s dominance in Internet browsers — a dominance that the company has relinquished to market forces in recent years.

In Microsoft’s 2009 settlement, the company did not pay a fine but instead committed to installing a system called Browser Choice Screen with Windows. It was intended to offer users alternatives like Google Chrome and Mozilla Firefox to counter the strength of Internet Explorer, Microsoft’s own browser product. The choice must be offered for five years, according to the agreement.

Millions of European users of the Windows 7 SP1 version of the software may not have been offered a choice of browsers between February 2011 and July 2012, Mr. Almunia said.

The company said it only learned of the error when the commission sent a notification about reports it had received indicating that alternative browsers were not being offered on some personal computers.

On Wednesday, Mr. Almunia saved his sharpest words when discussing Microsoft’s highly anticipated new Windows 8 operating system, one which the company has high hopes for.

In particular, Mr. Almunia said users of Windows 8 should be able to remove the icon for Microsoft’s browser, called Internet Explorer, from the start screens on their personal computers if they had chosen another browser as their default option.

Once users had made the choice of another browser, “there should not be unnecessary warning windows or confirmations by the user, and the Internet Explorer icon should also be unpinned from the Start screen,” said Mr. Almunia.

Mr. Almunia said it had examined another operating system by Microsoft called Windows RT for tablet computers but had decided not to take that investigation further — at least now.

“We will remain vigilant and we will continue to monitor all aspects of Microsoft’s compliance with its commitments in the future,” he said.

Sunday, September 30, 2012

U.S. Officials Opening Up on Cyberwarfare

But the reticence is giving way. The chorus of official voices speaking publicly about American cyberattack strategy and capabilities is steadily growing, and some experts say greater openness will allow the United States to stake out legal and ethical rules in the uncharted territory of computer combat. Others fear that talking too boldly about American plans could fuel a global computer arms race.

Next month the Pentagon’s research arm will host contractors who want to propose “revolutionary technologies for understanding, planning and managing cyberwarfare.” It is an ambitious program that the Defense Advanced Research Projects Agency, or Darpa, calls Plan X, and the public description talks about “understanding the cyber battlespace,” quantifying “battle damage” and working in Darpa’s “cyberwar laboratory.”

James A. Lewis, who studies cybersecurity at the Center for Strategic and International Studies in Washington, says he sees the Plan X public announcement as “a turning point” in a long debate over secrecy about cyberwarfare. He said it was timely, given that public documents suggest that at least 12 of the world’s 15 largest militaries are building cyberwarfare programs.

“I see Plan X as operationalizing and routinizing cyberattack capabilities,” Mr. Lewis said. “If we talk openly about offensive nuclear capabilities and every other kind, why not cyber?”

Yet like drone aircraft, which similarly can be used for both spying and combat, American cyberattack tools now are passing through a zone of semisecrecy, no longer denied but not fully discussed. President Obama has spoken publicly twice about drones; he has yet to speak publicly on American cyberattacks.

Last week, at a public Cyber Command legal conference, the State Department’s top lawyer, Harold H. Koh — who gave the Obama administration’s first public speech on targeted killing of terrorists in 2010 — stated the administration’s position that the law of war, including such principles as minimizing harm to civilians, applies to cyberattacks.

In August, the Air Force raised eyebrows with a bluntly worded solicitation for papers advising it on “cyberspace warfare attack capabilities,” including weapons “to destroy, deny, degrade, disrupt, deceive, corrupt or usurp” an enemy’s computer networks and other high-tech targets.

And a few weeks earlier, a top Marine commander recounted at a public conference how he had used “cyber operations against my adversary” in Afghanistan in 2010. “I was able to get inside his nets, infect his command-and-control, and in fact defend myself against his almost constant incursions to get inside my wire,” said Lt. Gen. Richard P. Mills, now deputy commandant of the Marine Corps.

Cyberwarfare was discussed quite openly in the 1990s, though technological capabilities and targets were far more limited than they are today, said Jason Healey, who heads the Cyber Statecraft Initiative at the Atlantic Council in Washington.

“Our current silence dates back 8 or 10 years, and N.S.A. is a big reason,” said Mr. Healey, who is working on a history of cyberwarfare.

The National Security Agency, which plays a central role in Cyber Command, traditionally breaks foreign codes and eavesdrops on foreign communications; it is among the most secretive agencies in government. Years ago it pioneered the field of cyberespionage: breaking into foreign computer systems in order to collect intelligence. The same skills and reflexive secrecy of spies carried over to cyberwarfare, Mr. Healey said. American officials have long preferred to talk cyberdefense, leaving the attack side in the shadows.

The increased candor recently about cyberoffense results not from a policy change, officials say, but from an inevitable acceptance of attacks on computer networks as a standard part of military and intelligence capabilities. The fact that dozens of Beltway contractors see cyberwarfare as one of the few parts of the defense budget that are likely to grow is also a factor.