International law experts are on track to publish a manual amending the current Geneva convention for cyberwar in late 2016. The Tallin Manual 2.0 – an update of the original Tallinn Manual on the International Law Applicable to Cyber Warfare—is backed by a NATO-run military think tank based in Estonia.

Military strategists deem cyberspace the fifth dimension of warfare, the others being land, air, sea and space. An example of an “armed attack” in cyberspace is the Stuxnet worm, an Israeli-U.S. programmed computer virus that caused severe disruptions to Iran’s nuclear plants. By the original manual, similar attacks in the future would legally validate proportional retaliation, considered in this case to be self-defense.

The Tallinn Manual 2.0 will discuss peacetime international law, including human rights law in regards to cyberspace. The current question begin argued is whether international human rights norms apply to different widely practiced cyber activities, such as the collection of metadata by national governments.

“If the answer is yes, we then have to examine whether the state has actually violated the individual’s rights. For instance, assuming the collection of metadata implicates human rights norms, under what circumstances is a state authorized to engage in such activities?” asks Liis Vihul, managing editor of the Tallinn Manual and legal researcher at the NATO Cooperative Cyber Defence Centre of Excellence.

Additionally, the updated manual will include sections on diplomatic law, the responsibilities of international organizations, global telecommunications law, and peace operations.

Article via The Register, October 12, 2015

Photo: Satsop Nuclear Plant via Michael B. [Creative Commons Attribution-NonCommercial-NoDerivs]

The US Senate voted this past Tuesday to pass the Cybersecurity Information Sharing Act (CISA), which allows companies to share evidence of cyberattacks with the US government, even if that data includes the personal information of individuals.

Those in favor of the bill argue that CISA will help the government protect companies. Most big tech companies comprise the opposition, and say that the new act is another loophole that allows the US government to snoop on citizens. President Obama supports CISA.

Al Franken, a senator from Minnesota and one of 21 who voted against the bill, said in a statement following CISA’s passing, “There is a pressing need for meaningful, effective cybersecurity legislation that balances privacy and security. This bill doesn’t do that.”

Companies are supposed to remove personal information about customers—such as emails and text messages—before sending data to the government. Currently, however, no accountability system exists to ensure that personal identifiers are in fact deleted before reaching government databases.

CISA was most likely passed in response to recent high-profile hackings, such as those committed against Sony Pictures, Ashley Madison, and United Airlines.

“With security breaches like T-Mobile, Target, and [the US government’s Office of Personnel Management] becoming the norm, Congress knows it needs to do something about cybersecurity,” said Mark Jaycox, Legislative Analyst of the Electronic Frontier Foundation. “It chose to do the wrong thing.”

Article via CNET, October 27, 2015

Photo: The Capitol, in Washington, D.C. US Senate and The House of Representatives via DeusXFlorida [Creative Commons Attribution-NonCommercial-NoDerivs]

A recent study released by the organization Freedom House found that Internet freedom is declining globally due to a variety of reasons, among them surveillance and online censorship. Of the 65 countries surveyed, 29 percent are deemed “not free,” while 27 percent are considered “free.” This is the first year that more countries are considered to have restricted Internet than free Internet. Last year, 15 countries were “not free” and 19 countries were “free.”

After the terrorist attacks on Charlie Hebdo’s newspaper staff, France’s digital free speech rights were restricted and government surveillance was increased. This led to a dramatic drop in the country’s Internet freedom score—four points—which Freedom House considers “problematic.”

Cuba, in contrast, saw an increase of eight points as a result of recovering relations with the United Sates and a recent decision by state telecom operators to half the price of Internet in the country.

Europe and the United States have recently experienced controversies with encrypted Internet traffic, leading to decreases in digital freedom scores. Freedom House uses several factors to calculate scores, including quantity of Internet access within the country, how much Web content is restricted, and whether or not Internet users can be punished.

Article via The Washington Post, 28 October 2015

Photo: Internet Yami-Ichi via Ars Electronica [Creative Commons Attribution-NonCommercial-NoDerivs]

Tech giant Apple is under scrutiny for factory conditions overseas. Despite the company’s efforts to regulate its manufacturers, a recent report by China Labor Watch indicated that many improvements are still to be made.

The report, released this Thursday, detailed criticisms of an iPhone factory in Shanghai. The organization urged Apple to raise staff wages, which currently amount to $1.85 an hour. Employees work shifts of 9 hours a day, in addition to a minimum of 20 hours overtime each week during the busy September season—when Apple prepares to release the iPhone 6S and iPhone 6S Plus—in order to cover living expenses. Including overtime, workers generally earn $753 a month. China Labor Watch also noted cramped living dorms and a lack of adequate safety training.

Apple does make an effort to monitor its manufacturers, however. The company audits the companies in its supply chain on a regular basis and releases the reports independently. Apple also sets the guideline of a 60-hour maximum workweek, which 92 percent of factory staff were compliant with for the majority of 2014. That number fell to 75 percent September of last year, when Apple primed to release the iPhone 6. In the Shanghai factory featured in the recent report, only 42 percent of employees worked 60 hours or less a week.

Apple also is advocating clean energy usage by its manufacturers, and announced new solar power and energy efficiency projects in China this Thursday. Apple’s CEO Tim Cook commented, “Our culture is to leave the world better than we found it.”

Article via CNET, 22 October 2015

Photo: RT @ BGR via Humans Developer [Creative Commons Attribution-NonCommercial-NoDerivs]

A Citizen Lab report released Thursday revealed that 33 countries are likely using FinFisher, a prominent spyware program. Many of these countries—including Ethiopia, Bangladesh, and Egypt—have suspect human rights standards.

FinFisher enables an organization or government to capture the keystrokes of a computer, as well as use the device’s microphone and camera to surreptitiously eavesdrop on a target. This type of surveillance tool was once only used by advanced governments, but is now available to anyone willing to invest in the service. In the U.S., journalists and dissidents are especially targeted.

Hackings in the past two years have informed researchers about the mechanics of spyware companies. FinFisher was hacked last year, revealing confidential company logistics, and its competitor Hacking Team was hacked this past year, exposing vital emails and files. Errors in spyware servers help Citizen Lab researchers figure out which governments are using the services of companies like FinFisher or Hacking Team.

Spyware servers used by governments often infect and control target computers with malware disguised behind proxies. Researchers found that 135 servers matched the “technical fingerprint” of shady spyware after scanning the Internet, yet they were always directed to a decoy page after typing the server’s Internet address into a Web browser. The decoy pages were most often www.google.com or www.yahoo.com.

However, the decoy sites showed local search results of the server’s origin, and not of the location that the researchers were in when they used the site. One proxy server seemed to be from the United States, then returned an IP address from Indonesia, indicating that the country’s government may be using FinFisher’s services.

Article via The Washington Post, 16 October 2015

Photo: Patrons use computers in an internet cafe via World Bank Photo Collection [Creative Commons Attribution-NonCommercial-NoDerivs]

Street harassment affects women all over the U.S., but its prevalence varies greatly between cities, as well as street-to-street within those cities. The new Hollaback! mobile app enables women to map incidents of street harassment as a useful reference to others who seek safe and peaceful routes. The app is offered on both iPhone and Android.

Emily May, Co-founder and Executive Producer of Hollaback! comments on the rise of conversation about sexual harassment. “We know that movements start because people tell their stories,” she said. “In the last five years, we’ve seen the public conversation on street harassment change drastically as people stand up and share their experiences.”

People are also encouraged to post their experiences with sexual harassment under the hashtag #iHollaback. The organization has also partnered with retailer ModCloth to campaign against the notion that the way a woman dresses invites sexual harassment.

The app opens a map of the phone’s surrounding location, with different colored dots representing incidences of different types of street harassment. The goal of Hollaback! is that women can use this data to avoid streets that are generally felt to be unsafe. Additionally, the app has a “take action” page that lets users indicate whether they have witnessed sexual harassment in a certain location.

Article via Bustle, 11 September 2015

Photo: Done Shopping via John Fraissinet [Creative Commons Attribution-NonCommercial-NoDerivs]