Archive for category Internet

ZNC Private Message logging module

I have recently switched from using dircproxy as an IRC bouncer to ZNC and it is turning out to be a better piece of software. (Not least of which is decent SSL support and a handy web interface that allows easy reconfiguration) However, it suffers from the same problem as many other bouncers – it doesn’t log Private Messages when you’re online. This is annoying because I may have left some machine somewhere connected that I might not return to for a day or two, or I might be on a mobile device that’s prone to losing it’s connection due to train tunnels etc. (Which results in ZNC thinking the device is still connected until it times out and messages are lost completely)

So, for anyone who uses ZNC who finds this similarly problematic, you can download a copy of the logging module I’ve worked on here. It compiles cleanly against the Debian version of ZNC 0.202 cleanly using just “znc-buildmod pmlog.cpp”, and you can install it simply by coping the resulting pmlog.so file to ~/.znc/modules and enabling it from the web interface.

There are no configuration options yet so it’s rather rough and basic and should be regarded as Beta-quality code at best, but time permitting I should add more soon. When you connect, it will simply play back inbound/outbound private messages sent since you loaded the module.

No Comments

Free software users “illegal downloaders” according to OfCom report

A recently released report prepared for OfCom – remember, they’re the folks who are going to be responsible for setting the rules on policing content on the internet – classes anyone downloading free content as someone they “deduce” to be involved in illegal file sharing. Here’s the culprit question:

Q4: Which of these have you used in the last three months in order to download or share files through the internet? Multi-code, Do not rotate
1. Peer-to-peer such as BitTorrent, Gnutella, eDonkey, Limewire and Ares
2. Commercial websites such as iTunes, Blinkbox, Amazon, Lovefilm, Movieflix, Napster, Play, or Spotify
3. Social Networking sites such as Facebook, Myspace, or Bebo
4. File sharing websites such as Rapidshare, Yousendit, or Easyshare
5. Messaging programs such as Windows Messenger or Skype
6. FTP
7. Email
8. Other (please specify)
9. Can’t remember

Apparently an answer other than 2 (Commercial websites) marks you as an illegal downloader. They do note the following:

Of course, those responding to Q4 (methods used to share or download files) may have had things other than the categories in Q3 in mind when talking about file sharing (e.g. photos they had taken) and the question will clearly need tightening in the tracking survey – even when filtering on those downloading or file sharing one of the six categories. This reinforces the recommendation (Recommendation 3 in Section 3) that Q4 be asked for each category of download.

However, even that does not help fully. For example, I tend to download software such as Debian or Ubuntu quite legally (They’re free software) via Bittorrent. It’s not unheard of in the commercial sector either as I have a legitimate copy of DCS: A-10C, a game/simulator that is distributed by the software house themselves over Bittorrent. (Requires a key to activate)

But it’s not just limited to software. Here is the list of categories that the report uses, with examples of legal content I personally have from sources other than “commercial web sites”.

  • Software or applications – Ubuntu, Debian, Thunderbird, many other items.
  • Video games – DCS: A-10C.
  • Films – Sintel
  • TV programmes – None. (I’m currently using NetFlix. I’ll give them the benefit of the doubt and let them refer to BBC iPlayer as “commercial”)
  • Books – Anything from Project Gutenburg.
  • Podcasts – The Pod Delusion.

Unsurprisingly, they deduce a higher number of “illegal downloaders” in the report than people actually admit to.

5 Comments

Newzbin2 blocking court order pointless

The court-ordered block on Newzbin2 for BT customers was a while ago, but implementation was delayed due to discussion on the exact wording of the order. Yesterday, it was back in court and the precise details were set.

Reading the full judgement this morning is interesting, as it appears ineffective. The court is ordering BT to use Cleanfeed (Paragraphs 6 and 9) in order to block the site, but Cleanfeed does not work on HTTPS (Which is encrypted) as it is unable to examine the request to determine exactly what has been issued. Cleanfeed was only designed to stop “casual” access to child porn.

I notice that Newzbin2 already has HTTPS access.

Oops.

No Comments

Smut Filter: The answers

From multiple reports this morning, it seems the Big 4 ISPs are not too happy with Camerons announcement of his anti-porn initiative, and he’s made out it’s far more wide-reaching than it is really. But we do have a few answers, courtesy of Slightly Right of Centre (Who first reported on the ISP response), the Telegraph, the Guardian and of course El Reg.

Is it opt-in or opt-out? “Active choice” has been touted – customers will need to answer one way or another, without any default. However, reading between the lines it seems ISPs are (unsurprisingly) leaning towards a more opt-in model and it will not be switched on be default for existing customers.

Who decides what will be blocked? Will the block list be public? How do you appeal? Who can appeal? It’s wide ranging, which is worrying, as we’re told “as well as pornography, parents will be able to block access to gambling and other adult websites.” “Other adult websites” likely includes “things parents might or might not disagree with morally, such as sites to help LGBT youth”. It’s entirely possible that this initiative conflicts with Cameron’s recent focus on forced marriage. If web blocking becomes more widespread, with many options on what can be blocked and no central regulation, those who need help may well be unable to get it as easily.

But every ISP will apparently be using different technology, so it’s possible that there will not be any central block list but the possibility of some sites being blocked on one ISP and not on another with no clear route to resolve issues. With blocks on mobile devices, it is already very hard, if not impossible, to get an inaccurately listed site allowed as there is simply nobody to get in contact with about it. “ParentPort” (Which is a non-government collaboration between various media regulators) is repeatedly mentioned, but that may just be a clearing house for reports.

Who pays? No answer on this one, but it’s sounding like it’ll be the ISPs are going to be funding it – which means a slight increase in Broadband cost for everyone.

How is it going to work technically? According to the Telegraph, Cameron has been accused of “misunderstanding what is technically possible“. So it’s quite possible this hasn’t been figured out yet – more than likely, with secure sites and proxies, the blocks will only stop casual access. This is at least slightly mitigates other problems as anyone that needs help on a topic may be able to get around the filters.

No Comments

Smut filter: The unanswered questions

“Confusion reigns” over the new proposal to filter internet access, because it has not been properly announced yet. Or, more likely, because it’s not been properly thought out. What we do know is that we know very little, but that’s OK because that well known technical expert, David Cameron, will be telling us all about it “later today”.

Is it opt-in or opt-out? Opt-out, i.e. switched on by default, is clearly a bad thing. The big four ISPs involved in this seem not to know themselves, but commercial pressures will tend towards it being opt-in only. Filtering costs money, and there are very small margins in the retail ISP industry.

Who decides what will be blocked? Someone has to make some policy decisions on what is acceptable – is what going to be the government or ISPs? Do we block just hard-core porn? What about page 3 images? Sites linked to terrorism? Sexual health sites? Sites accused of providing access to copyrighted material? Sites for dealing with LGBT issues, domestic violence, forced marriage… the list goes on. This is a big issue, because of the danger of further marginalising certain groups. What is acceptable content to one group is not acceptable to another.

Who pays? If it’s free, then you are effectively paying a tax on your unfiltered broadband service in order to subsidise those who do want filtering. Or will there be government money for this?

Will the block list be public? If a site ends up on the list without intending to, because of one image, will they be notified? This happened to Wikipedia with the IWF kiddy porn list, because of differences of opinion in what constituted child pornography, but the IWF list is not public.

How do you appeal? Who can appeal? Another messy area. Your site ends up on the block list, what now? Is there a presumption of removal until it’s shown it’s definitely infringing? For commercial sites, being blocked for even a few days could send them out of business. What if it’s a foreign site, does the site owner need to appeal or can anyone do it?

How is it going to work technically? We already have the IWF child porn block on many ISPs, but that is only intended to stop accidental, casual access. It’s trivial to bypass. If a site switches to secure connections (HTTPS) what then? Or connections on ports other than the default web port? Will whole sites be blocked or just the specific image or page that’s a problem? What about proxy sites? I’d expect well-advertised proxy sites and software to spring up the moment any filtering system goes live. “No dear, I’m not looking at porn online. How can I, we have a filtered connection!

I don’t expect these to get answered today of course, because from the reactions of the big four ISPs it appears that this hasn’t been thought through.

2 Comments

Hi-tech policing during the riots

In an age where the police have powers to force telecommunications companies to hand over data and install interception equipment in their networks… where we spend vast amounts of money maintaining listening posts… on an operation where apparently even MI5 were involved…

Just how did the police crack the various BlackBerry Messenger groups used to coordinate the riots?

According to The Times: (£)

Scotland Yard said yesterday that it had picked up conversations on the BlackBerry Messenger (BBM) system after confiscating phones from arrested troublemakers. Police were then able to access the instant messaging network and respond to the more credible threats being circulated

Modern policing at it’s best. The best encryption available isn’t going to help if you have your collar felt by the old bill and they simply read what’s on your phone!

No Comments

Updated Google privacy data: UK now “only” 2nd most snooped on

A while ago, I produced a per-capita analysis of the Google privacy data showing that the UK, per citizen, is the most snooped on country – there were more requests per person in the UK to Google than any other country. More up to date data is now available, for July to December 2010, showing that the UK is no longer the most snooped on – we’ve dropped to second place. Singapore does not appear in the January to June data but no reason is indicated for this.

(Note: Previous positions in the table below are based on latest data from Google. Some countries did not have data available at the time the previous blog post was compiled, so those numbers do not match)


Population Previous position Requests per Million (Jan-Jun) Requests per Million (Jul-Dec)
1. Singapore 5,076,700 5th 20.9 23.2
2. United Kingdom 62,008,049 1st 40.5 18.7
3. France 65,447,374 3rd 28.5 15.6
4. Australia 22,469,943 6th 15.8 15.4
5. United States 310,314,000 4th 25.4 14.8
6. Italy 60,402,499 6th 19.9 13.9
7. Germany 81,802,257 13th 5.6 9.4
8. Brazil 193,549,000 2nd 31.5 9.3
9. Portugal 10,636,888 10th 6.9 8.6
10. Belgium 10,839,905 11th 6.5 7.8

And no real surprises in the removal requests category either as Lybia is still an order of magnitude ahead of every other country. The United States, home of free speech, drops out of the top 10 completely down to number 13 while the UK stays up at number six.


Population Previous position Removals per Million (Jan-Jun) Removals per Million (Jul-Dec)
1. Libya 6,546,000 1st 22.8 10.4
2. South Korea 49,773,145 5th 2.0 2.8
3. Germany 81,802,257 2nd 3.8 1.4
4. Brazil 193,549,000 3rd 3.6 1.4
5. Italy 60,402,499 4th 2.1 0.8
6. United Kingdom 62,008,049 6th 1.7 0.6
7. Argentina 40,518,951 8th 1.3 0.5
8. Switzerland 7,866,500 13th 0.6 0.5
9. France 65,447,374 3rd 0.5 0.4
10. Spain 46,072,834 9th 1.0 0.3

1 Comment

A refreshing change to copyright takedown notices

From time to time (OK, pretty much constantly – hundreds every month) we get copyright takedown notices from rights holders. We don’t do anything about them, we’re not their enforcement arm, but a handy little script automatically forwards them on to our customers via email. Most of them are of the form “WE’RE GOING TO SUE YOU UNLESS YOU STOP THIS RIGHT AWAY! Although, we may sue you anyway” wrapped up in some opaque legalese. So, it’s refreshing to have seen the following go past over the weekend:

Recently BayTSP detected an infringement of TV TOKYO Medianet Inc.’s copyright interests on your IP address. TV TOKYO Medianet Inc. appreciates that you enjoy their anime and hopes you can support them and the original creators directly by watching their programs at http://www.crunchyroll.com/watchbleach where they are making a strong effort to provide their content legally.

Supporting the content legally ensures that TV TOKYO Medianet can continue to broadcast more of the high quality anime which you crave. Crunchyroll.com gives anime fans access to the anime they want as soon as possible, allowing fans to watch episodes of their favorite series as they premiere in Japan. TV TOKYO Medianet urges you to show your support by going to the website below and watching content legally.

http://www.crunchyroll.com/watchbleach

TV TOKYO Medianet appreciates your interest in their anime and hopes you continue to be a fan.

Hopefully we’ll see more of the same in future, to my mind it’s a much more constructive approach than the usual one. (Oh, it then launches into the standard BayTSP WE’RE GOING TO SUE YOU UNTIL YOU BLEED legal language, but you can’t have everything. Most people probably don’t read that far down.)

No Comments

Travelodge web site hack update

There’s been a few developments related to my earlier post about the possible Travelodge compromise. Firstly, it’s been covered by The Register so is attracting some interest. Travelodge themselves have also confirmed via Twitter that they haven’t sold any data, which makes it pretty clear they’ve been broken in to.

I’ve also had a reply from the CEO of Travelodge. It’s a bit light on content:

Thank you for your email regarding spam e-mail you have received. I am sorry you have had the need to write to me, but appreciate you bringing this to our attention.

Please be assured we are taking this matter most seriously. I attached a copy of a letter to our customers, for your information.

It’s not clear who the letter has or is being sent to, but it was included as a PDF and the text reads:

Our main priority is to ensure the security of our customers’ data, which is why I wanted to make you aware, that a small number of you; may have received a spam email via the email address you have registered with us.

Please be assured, we have not sold any customer data and no financial information has been compromised.

All financial data (including credit card information) is compliant with current best practice standards and is audited to PCI (Payment Card Industry) requirements.

The safety and security of your personal information is of the upmost importance to us and as a result we are currently conducting a comprehensive investigation into this issue.

If you receive an email similar to the one detailed below, please delete it as spam.

They’ve included a copy of the original spam – I’ll not reproduce it here. The letter closes:

If you have any questions regarding this matter please email: andrea@tra…dge.co.uk. A
further update will be given, when we have completed our investigation.

At least they’ve responded quickly to this as companies can often take days or weeks. The lack of any detail is understandable, given that it’s still early days and they probably don’t know what happened themselves yet – but then, how can they give us assurances that financial data is safe if they do not know what happened…? The mention of PCI is a little superfluous, given that PCI-DSS is the baseline standard required by banks before you’re allowed to handle any credit card information. It’s no guarantee of security.

@PogoWasRight is on the right track, asking Travelodge: “Do you handle email marketing in-house or do you outsource to an email service provider? If the latter, who?”. We’ve seen cases of email marketing providers getting themselves broken into recently and Travelodge may be another in a long list.

4 Comments

Travelodge UK compromised?

Yesterday I received a spam email. Not unusual, but note the destination email address:

Subject: Zoe OConnell
Date: Wed, 22 Jun 2011 10:58:33 -0400
From: Lorraine Ackerson @lt;lorraineackersonas113@hotmail.com>
To: <zoe-travelodge@****.co.uk>

Greetings.
Don’t miss exciting business chance.
Reputable agency is looking for energetic worker in United Kingdom to help us expand our activity in the UK sector.

Necessity:
- 18+ United Kingdom resident
- Only operational knowledge of Internet & computer.
- Free access to personal e-mail box
- 2-3 free hours per day
- Fast replies on our written tasks
- Excellent organizational skills.

You can without problem combine our work with your primary work.
Great income potential. Free study possible.
Applicants must be honest and commerce motivated. Operate only few hours per day.
Everyone located in the United Kingdom can be our representative.
Our manager will e-mail you within few hours if you attracted.

—————-
Top News: taylor honored for boosting antelope island.

Note that it’s zoe-travelodge@… (You can guess what the full email is but I don’t want to make life too easy for spammers to harvest addresses) My mail system ignores anything after the dash and just puts it all in my mailbox, so that I can filter mail by source more easily and also spot who has been selling email addresses.

The spammers also knew my full name. And I’m not the only one in this position as several other users on twitter have complained of the same thing. I’ve just emailed the Chief Executive of Travelodge, Guy Parsons, (Hat tip to @benjymous for finding his details) to ask exactly what was stolen:

Dear Mr.Parsons,

Yesterday, I received spam email to an email address that has only ever been used to register on the Travelodge site. This was clearly not just someone making up random addresses as the email was specifically to zoe-travelodge@****.co.uk and the spammer knew my full name. I am not the only one to have experienced this as since last night at least half a dozen other people who also use unique addresses for registering on web sites have complained about exactly the same situation on Twitter.

It would appear likely, unless Travelodge are in the habit of selling on personal details to unsavoury third parties, that your site has been compromised. I would be grateful if you could confirm that this is the case and also what other details were stolen so that those affected can take appropriate action – was this just names and email addresses or were payment details and postal addresses compromised too?

I shall let people know if I get a reply.

Update at 1315: Travelodge UK, via twitter, have stated: “Sorry for the spam email you may have received. We have NOT sold any data. We’re currently investigating this issue and will update you ASAP”

7 Comments