New Internet consumer protection tool--SiteAdvisor.com

I’ve been using the Firefox plugin from SiteAdvisor.com for a few days, and I think it’s a great idea. They’ve searched the web, downloaded content, and submitted unique email addresses on signup forms everywhere they find them, to see what happens. They then rate each site for malicious content and the extent to which it generates spam in response to a signup. This database is then used by their browser plugin to display icons next to Google and Yahoo search results indicating whether that site is green, yellow, or red regarding the type of content downloaded, the amount of email you can expect to receive from signing up at the site, and whether it links to other sites that are problematic. Their privacy policy is good–they don’t keep a record of who goes to what site. One feature I’d like to see them add is the ability to not make queries for certain domains (such as Intranet web pages–their current design allows them to map out internal corporate web structures which they should not be able to get). Their advisory board includes Avi Rubin, a well-known security researcher at Johns Hopkins University (and formerly at AT&T) who has done significant work on e-voting security, and Ben Edelman, formerly of Harvard Law School’s Berkman Center for Internet & Society, who is well-known for his research on Internet subjects such as domain name usage and China’s web filtering, as well as his lawsuit against web filtering company N2H2 to defend his right to research its blocking list. SiteAdvisor has a blog, too (though as of this moment it doesn’t have a valid RSS feed, according to Thunderbird). ...

January 26, 2006 · 2 min

Arizona Sen. Jon Kyl is a spammer

As readers of this blog know, I’m no supporter of George W. Bush. I’ve never contributed funds or worked to support the campaign of a Republican. Yet I received this spam email from Jon Kyl, who is apparently concerned about competition from Arizona Democratic Party chairman Jim Pederson in the next election. It’s also interesting that Kyl’s jonkyl.com website is hosted in Canada, and his campaign webservers are hosted in New Jersey. Way to support your home state, Senator. From: “Senator Jon Kyl” [email protected] Date: Thu, 19 Jan 2006 23:57:14 -0500 Subject: I invite you to join my team… Today I am writing you for two reasons. One is to say thank you for your past support of President Bush and a second is to ask for your help. I am not asking for money. I am simply asking for your time and energy in helping my reelection campaign. First, thank you for your help in the 2004 election. Because of your hard work, we had a huge victory in Arizona. One of the key elements of victory was the organized force of Bush Volunteers who registered voters, made phone calls, walked neighborhoods, placed signs and bumper stickers, and helped get out the vote. It was a record setting year, and you were part of that team. Second, I want to ask for your help. As you may know, I am running for reelection to the U.S. Senate. My opponent is the former Chairman of the Arizona Democrat Party, Jim Pederson. He has personally bankrolled the Democrats’ efforts, including against President Bush, to date he has spent over $5 million on Democrats and their causes. He is a supporter of Howard Dean and Ted Kennedy and was a leader in John Kerry’s failed presidential campaign. Not surprisingly, John Kerry now is Pederson’s biggest contributor. That is why I need your help. Television and radio alone will not win this election. In order to be successful, we will need to replicate the Bush Volunteer program to run our grass roots campaign. We are currently recruiting volunteers from across Arizona to join our campaign as Kyl Captains. As a Kyl Captain you will be integral in our network of individuals who are willing to help on the campaign. Whether you prefer registering voters, working the phones, or just talking with your friends and neighbors, you will be a critical component of my campaign. Because Jim Pederson will spend what it takes on television, it is very important to have a strong and active Arizona Team on the ground, registering and getting voters to the polls. I am convinced it is the key to victory in November 2006. Please take a moment and visit www.jonkyl.com and sign up as a Kyl Captain. Your personal commitment to this campaign will make all the difference. It has been the greatest honor of my life to represent the people of Arizona in the United States Senate. With your help I hope to continue that public service. Again, thank you for your past work on behalf of the President and I look forward to working together in the future. Sincerely, Jon Kyl U.S. Senator P.S. If you have any questions, please feel free to call my office at (602) 840-0306 or visit: www.jonkyl.com P.O. Box 10246 :: Phoenix, AZ 85064 :: [email protected] Paid for by Jon Kyl for U.S. Senate/[email protected] ...

January 20, 2006 · 4 min

Wind-powered walking machines

The Animaris Rhinoceros Transport is a type of animal with a steel skeleton and a polyester skin. It looks as if there is a thick layer of sand coating the animal. It weighes 2. tons, but can be set into motion by one person. It stands 4.70 meters tall. Because of its height it catches enough wind to start moving. MPEG video here. (From Jamie Zawinski’s blog.)

January 15, 2006 · 1 min

Los Angeles traffic at night-time

Grass Collective makes “moving art” which includes a DVD of Los Angeles traffic at nighttime. It’s pretty hypnotic. (Hat tip to BLDGBLOG.) Historical Comments Einzige (2006-12-09): Would that Google Earth looked that cool!:)

January 11, 2006 · 1 min

Cell phone call records available online

America’s Blog has brought up a story that was published in the mainstream media last year (in the Washington Post) and a few days ago (in the Chicago Sun-Times) but which for some reason hasn’t resulted in an uproar. The story is that there are sites on the Internet from which you can purchase copies of calling records for cell phones and land lines, such as Locatecell.com. John in DC, who runs America’s Blog, purchased his own cell phone records, and indeed got a list of all the numbers he had called. Cingular thinks this is an “infinitesimally small problem” for them. How are sites such as Locatecell getting their information? They could be purchasing it from insiders, they are no doubt using “pretexting” (social engineering) to persuade customer support representatives to give them the information, or gaining access to customer account information via the web (Verizon Wireless had another major security hole in their online billing system last year, similar to one in 2001 which they took two weeks to act upon). Whichever mechanisms are used, it is clear that privacy is being violated and likely that laws are being broken, yet there seems to be little visible interest on the part of the telephone companies in going after the criminals–perhaps because doing so might expose how poorly they are securing the information. The Electronic Privacy Information Center (EPIC) has a good collection of material on this issue here. (Updated January 9: They filed a case against Bestpeoplesearch.com, which admits to using “pretexting” as their method to obtain the information.) (Thanks to cowmix for bringing this to my attention.) ...

January 8, 2006 · 2 min

Bush's warrantless interception program

In a New York Times followup about the Bush-approved program to engage in interception of email and voice calls to international destinations without warrants approved by the FISA Court, it is stated that The National Security Agency has traced and analyzed large volumes of telephone and Internet communications flowing into and out of the United States as part of the eavesdropping program that President Bush approved after the Sept. 11, 2001, attacks to hunt for evidence of terrorist activity, according to current and former government officials. The volume of information harvested from telecommunication data and voice networks, without court-approved warrants, is much larger than the White House has acknowledged, the officials said. It was collected by tapping directly into some of the American telecommunication system’s main arteries, they said. ...

January 4, 2006 · 3 min

Religious spammer in Scottsdale files lawsuit

Charles E. “Chuck” Carlson (not to be confused with convicted Watergate conspirator turned evangelical prison ministry mogul Chuck Colson) runs something called “Strait Gate Ministries” and assorted websites (including one called “Al-Jazeerah”) which seem to focus on arguing that the U.S. should not be supporting Israel. He has a history of advertising these websites by sending unsolicited bulk email, also known as “spam." He has clashed with a number of anti-spammers, which has led to multiple terminations of online services that he’s used–his DSL connection as well as web hosting. He has characterized this as mugging and assault as well as censorship. (Here is a list of some of Carlson’s domains blocked by rhyolite.com for sending spam.) In August, he filed a lawsuit (PDF) in Arizona Superior Court (CV2005-052008) against Robert Poortinga, his own providers who had terminated service, and Missouri Freenet Corporation. In his complaint, he argues that Poortinga and others have defamed him by calling him a “spammer” and accusing him of sending “spam,” on the grounds that his emails do not meet the criteria in the CAN-SPAM Act. “Missouri Freenet Corporation,” named as a defendant in Carlson’s suit, doesn’t actually exist–the person he’s intending to sue is Alif Terranson (on whose site the above lawsuit complaint PDF is hosted), who is a well-known anti-spammer and formerly ran the abuse team at Savvis. Terranson has supplied Carlson with information about how to properly name and serve him. Carlson’s complaint appears to me to be without merit. His argument based on CAN-SPAM fails because that act does not define the term “spam,” which is a well-known term of art in the Internet world, not a legal term. “Spam” originally meant bulk postings to Usenet newsgroups (an action associated with a couple of immigration attorneys also based in Scottsdale, Arizona), but quickly came to mean unsolicited bulk email (UBE)–email that is both (a) not explicitly requested by the recipients and (b) sent to multiple recipients. Although the most common form of UBE is unsolicited commercial email (which is what CAN-SPAM regulates), UBE and “spam” are broader than UCE and can include religious spam, insane spam, etc. Internet RFC 2505 endorses this broader notion of “spam,” as does this definition from Spamhaus. Although there are no legal penalties for spam that falls outside of what is regulated by federal and state laws (or laws in other countries), most online providers have stricter guidelines than what the law requires as part of their Acceptable Use Policies (AUPs). Customers of online providers are contractually bound by those AUPs, and can find their service terminated for violations even if they haven’t violated the law. This has been the case since long before CAN-SPAM went into effect. Another form of social penalty for spam is having one’s email blocked by those who operate mail servers on the Internet–companies, organizations, and individuals have a variety of tools which can be used to block the vast quantities of unwanted email being spewed out daily by compromised machines as well as by those operating in a more aboveboard manner. Included in those tools are the ability to block by domain name or using IP-address-based blocking lists. What Carlson calls censorship is really just the owners of private mail servers setting rules by which their property may be used by others. (The issue is a bit more complicated in the case of an ISP, but so long as the ISP accurately informs its customers of what they’ve signed up for, they can apply filters consistent with their service. In general, ISPs want their customers to receive what the customers want to receive, as blocking wanted email leads to complaints.) I’ll keep tabs on this suit as it progresses (if it does). ...

December 31, 2005 · 4 min

FISA Court: Rubber Stamp?

In a New York Times op-ed defending the president’s warrantless wiretapping of international calls and emails, former Justice Department attorneys (under GHWB and Reagan) David Rivkin and Lee Casey write: Furthermore, the FISA court is not a rubber stamp and may well decline to issue warrants even when wartime necessity compels surveillance.It’s not? Let’s take a closer look (stats from EPIC by way of Talking Points Memo). The FISA court, established in 1978, had received 18,761 requests for warrants as of the end of 2004. How many were rejected? Four or five (sources disagree). Of the four which were definitely rejected (all from 2003), all four were partially approved upon reconsideration. And how many have been modified by the court from the original requests? 1978-1999: 0 (?) 2000: 1 2001: 2 2002: 2 (but the modifications were later reversed) 2003: 79 (of 1727 requests) 2004: 94 (of 1758 requests) It looks to me like the FISA court was a rubber stamp at least until 2003, and quite arguably still is. Rivkin and Casey go on to argue that Congress has no authority to regulate how the President exercises his wartime authority: The Constitution designates the president as commander in chief, and Congress can no more direct his exercise of that authority than he can direct Congress in the execution of its constitutional duties.Say what? Have they not read Article I, Section 8 of the U.S. Constitution, which explicitly gives Congress authority to regulate many aspects of military and wartime activity? I’ve italicized a key passage: Congress shall have the power … To declare war, grant letters of marque and reprisal, and make rules concerning captures on land and water; ...

December 28, 2005 · 4 min

Major flaw in Diebold voting machines

It is possible to preload a memory card with negative votes that are not recognized by the machine, but which affect the final outcome in an undetectible manner. In the test described in a Wired article, a mock vote was held on the question of whether Diebold machines could be hacked, with eight votes. The eight votes fed into the machines (via optically scanned paper ballots) were six “no” votes and two “yes” votes. The outcome recorded on the rigged card was one “no” and seven “yes”–the memory card was preloaded with -5 “no” votes and 5 “yes” votes. By balancing out the preloaded votes (with a sum of zero), the final record showed an accurate number of votes, but not an accurate record of what the votes were. Further flaws indicate that the Diebold machines execute code residing on the memory cards, without doing checks on the content of that code which are required by Federal Elections Commission standards. As a result of the hacking demonstrations by Finnish security expert Harri Hurst in Florida on December 13, Leon and Volusia counties in Florida have cancelled their contracts with Diebold. Much more at blackboxvoting.org.

December 23, 2005 · 1 min

Bush administration approved warrantless wiretaps on U.S. citizens

News is now out that the Bush administration, in 2002, authorized the National Security Agency to conduct eavesdropping (on international email or phone calls) against U.S. citizens without court oversight. The NSA’s domestic surveillance is supposed to be limited to foreign embassies and missions, and to require court approval. This is not a power granted to the president by the U.S. Constitution. This abuse of power has apparently been exercised against as many as 500 people in the U.S. at any given time. The NY Times reports that some NSA officials, to their credit, refused to participate due to their concerns about the legality of the program. Note that the standards which the Foreign Intelligence Surveillance Court uses to approve wiretaps are already incredibly low (their decision algorithm is pretty close to “say yes to everything”), but apparently that was considered too great a barrier and it had to be bypassed. Approval of torture, secret CIA prisons in Europe, kidnapping citizens of other countries and taking them to Afghanistan… apparently the Bush administration has no respect for the U.S. Constitution on the principles behind it. ...

December 16, 2005 · 2 min
Mastodon Verification