Selling flak jackets in the cyberwars

SAN FRANCISCO (Reuters) - When the Israeli army and Hamas trade virtual blows in cyberspace, or when hacker groups like Anonymous rise from the digital ether, or when WikiLeaks dumps a trove of classified documents, some see a lawless Internet.
But Matthew Prince, chief executive at CloudFlare, a little-known Internet start-up that serves some of the Web's most controversial characters, sees a business opportunity.
Founded in 2010, CloudFlare markets itself as an Internet intermediary that shields websites from distributed denial-of-service, or DDoS, attacks, the crude but effective weapon that hackers use to bludgeon websites until they go dark. The 40-person company claims to route up to 5 percent of all Internet traffic through its global network.
Prince calls his company the "Switzerland" of cyberspace - assiduously neutral and open to all comers. But just as companies like Twitter, YouTube and Facebook have faced profound questions about the balance between free speech and openness on the Internet and national security and law enforcement concerns, CloudFlare's business has posed another thorny question: what kinds of services, if any, should an American company be allowed to offer designated terrorists and cyber criminals?
CloudFlare's unusual position at the heart of this debate came to the fore last month, when the Israel Defense Forces sought help from CloudFlare after its website was struck by attackers based in Gaza. The IDF was turning to the same company that provides those services to Hamas and the al-Quds Brigades, according to publicly searchable domain information. Both Hamas and al-Quds, the military wing of the Palestinian Islamic Jihad, are designated by the United States as terrorist groups.
Under the USA Patriot Act, U.S. firms are forbidden from providing "material support" to groups deemed foreign terrorist organizations. But what constitutes material support - like many other facets of the law itself - has been subject to intense debate.
CloudFlare's dealings have attracted heated criticism in the blogosphere from both Israelis and Palestinians, but Prince defended his company as a champion of free speech.
"Both sides have an absolute right to tell their story," said Prince, a 38-year old former lawyer. "We're not providing material support for anybody. We're not sending money, or helping people arm themselves."
Prince noted that his company only provides defensive capabilities that enable websites to stay online.
"We can't be sitting in a role where we decide what is good or what is bad based on our own personal biases," he said. "That's a huge slippery slope."
Many U.S. agencies are customers, but so is WikiLeaks, the whistle-blowing organization. CloudFlare has consulted for many Wall Street institutions, yet also protects Anonymous, the "hacktivist" group associated with the Occupy movement.
Prince's stance could be tested at a time when some lawmakers in the United States and Europe, armed with evidence that militant groups rely on the Web for critical operations and recruitment purposes, have pressured Internet companies to censor content or cut off customers.
Last month, conservative political lobbies, as well as seven lawmakers led by Ted Poe, a Republican from Texas, urged the FBI to shut down the Hamas Twitter account. The account remains active; Twitter declined to comment.
MATERIAL SUPPORT
Although it has never prosecuted an Internet company under the Patriot Act, the government's use of the material support argument has steadily risen since 2006. Since September 11, 2001, more than 260 cases have been charged under the provision, according to Fordham Law School's Terrorism Trends database.
Catherine Lotrionte, the director of Georgetown University's Institute for Law, Science and Global Security and a former Central Intelligence Agency lawyer, argued that Internet companies should be more closely regulated.
"Material support includes web services," Lotrionte said. "Denying them services makes it more costly for the terrorists. You're cornering them."
But others have warned that an aggressive government approach would have a chilling effect on free speech.
"We're resurrecting the kind of broad-brush approaches we used in the McCarthy era," said David Cole, who represented the Humanitarian Law Project, a non-profit organization that was charged by the Justice Department for teaching law to the Kurdistan Workers' Party, which is designated by the United States as a terrorist group. The group took its case to the Supreme Court but lost in 2010.
The material support law is vague and ill-crafted, to the point where basic telecom providers, for instance, could be found guilty by association if a terrorist logs onto the Web to plot an attack, Cole said.
In that case, he asked, "Do we really think that AT&T or Google should be held accountable?"
CloudFlare said it has not been contacted about its services by the U.S. government. Spokespeople for Hamas and the Palestinian Islamic Jihad, told Reuters they contracted a cyber-security company in Gaza that out-sources work to foreign companies, but declined to comment further. The IDF confirmed it had hired CloudFlare, but declined to discuss "internal security" matters.
CloudFlare offers many of its services for free, but the company says websites seeking advanced protection and features can see their bill rise to more than $3,000 a month. Prince declined to discuss the business arrangements with specific customers.
While not yet profitable, CloudFlare has more than doubled its revenue in the past four months, according to Prince, and is picking up 3,000 new customers a day. The company has raked in more than $22 million from venture capital firms including New Enterprise Associates, Venrock and Pelion Venture Partners.
Prince, a Midwestern native with mussed brown hair who holds a law degree from the University of Chicago, said he has a track record of working on the right side of the law.
A decade ago, Prince provided free legal aid to Spamhaus, an international group that tracked email spammers and identity thieves. He went on to create Project Honey Pot, an open source spam-tracking endeavor that turned over findings to police.
Prince's latest company, CloudFlare, has been hailed by groups such as the Committee to Protect Journalists for protecting speech. Another client, the World Economic Forum, named CloudFlare among its 2012 "technology pioneers" for its work. But it also owes its profile to its most controversial customers.
CloudFlare has served 4Chan, the online messaging community that spawned Anonymous. LulzSec, the hacker group best known for targeting Sony Corp, is another customer. And since last May, the company has propped up WikiLeaks after a vigilante hacker group crashed the document repository.
Last year, members of the hacker collective UgNazi, whose exploits include pilfering user account information from eBay and crashing the CIA.gov website, broke into Prince's cell phone and email accounts.
"It was a personal affront," Prince said. "But we never kicked them off either."
Prince said CloudFlare would comply with a valid court order to remove a customer, but that the Federal Bureau of Investigation has never requested a takedown. The company has agreed to turn over information to authorities on "exceedingly rare" occasions, he acknowledged, declining to elaborate.
"Any company that doesn't do that won't be in business long," Prince said. But in an email, he added: "We have a deep and abiding respect for our users' privacy, disclose to our users whenever possible if we are ordered to turn over information and would fight an order that we believed was not proper."
Juliannne Sohn, an FBI spokeswoman, declined to comment.
Michael Sussmann, a former Justice Department lawyer who prosecuted computer crimes, said U.S. law enforcement agencies may in fact prefer that the Web's most wanted are parked behind CloudFlare rather than a foreign service over which they have no jurisdiction.
Federal investigators "want to gather information from as many sources as they can, and they're happy to get it," Sussmann said.
In an era of rampant cyber warfare, Prince acknowledged he is something of a war profiteer, but with a wrinkle.
Read More..

Samsung Smart TVs: The next frontier for data theft and hacking [video]

Smart TVs, particularly Samsung’s (005930) last few generations of flat screens, can be hacked to give attackers remote access according to a security startup called ReVuln. The company says it discovered a “zero-day exploit” that hackers could potentially use to perform malicious activities that range from stealing accounts linked through apps to using built-in webcams and microphones to spy on unsuspecting couch potatoes. Don’t panic just yet, though. In order for the exploit to be activated, a hacker needs to plug a USB drive loaded with malicious software into the actual TV to bypass the Linux-based OS/firmware on Samsung’s Smart TVs. But, if a hacker were to pull that off, every piece of data stored on a Smart TV could theoretically be retrieved.
[More from BGR: Has the iPhone peaked? Apple’s iPhone 4S seen outselling iPhone 5]
[More from BGR: Dell confirms it will exit smartphone business, drop Android]
As if the possibility of someone stealing your information and spying on you isn’t scary enough, according to ComputerWorld, “it is also possible to copy the configuration of a TV’s remote control, which would allow a hacker to copy the remote control’s settings, and remotely change the channel.”
ReVuln told The Register it hasn’t informed Samsung of the vulnerability and plans to sell the details of in hopes of “speeding up” development of a fix. A video of the exploit as proof from ReVuln follows below.
Read More..

92K Missourians affected by insurance data breach

JEFFERSON CITY, Mo. (AP) -- State officials say the personal information of more than 92,000 Missourians was accessed by potential identity thieves who hacked the computer systems of Nationwide Insurance, which also does business as Allied Insurance.
Missouri's insurance department said Friday the Oct. 3 data breach could affect more than 1.1 million people across the country who did business with Nationwide or Allied.
Missouri's insurance director says the breach affected the records of people who got quotes for auto insurance after August 2011. The department says Nationwide believes the hackers accessed names, Social Security numbers, driver's license numbers and birth dates, among other things.
Nationwide is offering free credit monitoring and identity theft protection to people affected by the data breach. The insurer says it's not aware that the information has been misused.
Read More..

18 million Android devices could get whacked with malware in 2013

One security firm on Thursday claimed that 2013 will be the year of mobile malware for Android users, however no specific numbers had been given. The team at Lookout Mobile Security has painted a similar picture for Google’s (GOOG) operating system. The firm notes that more than 1.2 billion mobile devices are expected to be purchased in 2013 and in the following year users are forecasted to download over 70 billion mobile apps. Due to Android’s popularity, it is estimated that 18 million devices running the operating system may encounter some form of mobile malware. The likelihood that users will encounter malware or spyware, however, is heavily dependent on geographical location and behavior. Research from the security firm reveals that users in the U.S. have a 0.40% chance of seeing malware, compared those in Russia with a 34.7% chance.
Read More..

PUC approves writing rules for smart meter opt-out

EL PASO, Texas (AP) -- The Public Utility Commission has decided to develop a set of rules so consumers can opt out of the smart meters installed in millions of Texas homes and businesses.
Consumers have opposed the new meters, citing possible health hazards and privacy concerns. Some have installed steel cages around their analog meters to prevent utility workers from replacing them with the new digital units and one Houston woman held a gun to impede a utility worker from replacing her meter.
PUC spokesman Terry Hadley said Friday that an opt-out would leave already-installed smart meters in place but disable the devices' radio frequency capabilities.
A draft of the new rules will be written and submitted for public comment, Hadley said. After that, the PUC will vote again on whether to adopt them, which means there's still a chance the opt-out will fail. But, he said, "at this point the Commission is leaning toward an opt-out."
It will take several months until the new proposal is drafted and voted, Hadley said.
Smart meters allow for remote metering via radio frequency and are make the billing process cheaper since there is no need to send utility workers to read them. The meters also provide real-time information on energy consumption and help utilities prevent grid overloads during peak times. They also report to the utility when there is a power outage, making reconnection faster.
In websites and meetings organized by PUC, those against smart meters have spoken of possible government snooping and violations of the Fourth Amendment —unreasonable search and seizure — as well as the chance that hackers could access people's information from the meters.
On a petition template that's posted on www.bantexassmartmeters.com , meters are called "surveillance devices" because they record the household occupants' activities and can be used to "gain a highly invasive and detailed view" of their lives. Smart meters record consumption in 15-minute intervals.
Health hazards from the radio frequencies emitted by the meters have also been cited. The Public Utilities Commission says the meters have a lower impact than cellphones and microwave ovens and are well within Federal Communications Commission's standards for radio frequency devices.
It's likely that consumers who opt out will have to pay to have their meters read. As part of the rule-writing process, the Commission will gather information on how much it costs to send employees to read the meters and what disabling the radio frequency device would cost.
Users in California and Nevada pay between $75 and $107 to have the devices replaced along with monthly fees ranging from $8 to $10 to have the meters read. Meanwhile, Vermont legislators decided in May that utilities cannot charge users that opt out.
About 93 percent of the nearly 7 million smart meters in Texas' competitive markets for electricity, mainly in Houston and the Dallas-Fort Worth area, have been deployed, Hadley said.
Read More..

Cold weather kills 61 people in Poland since Oct.

WARSAW, Poland (AP) — Police in Poland have appealed to residents to dress warmly and look out for elderly and homeless people, after saying that 61 people have died of the cold weather since October.
Another 41 have been killed by carbon monoxide inhalation from coal or other ways of heating their homes since temperatures started falling.
The Interior Ministry said Friday the death toll from sub-freezing temperatures that set in in December was 49 people so far, compared to 19 in the whole of December last year. Another 15 people died of cold in October and five in November.
In most cases the victims are homeless people, or people under the influence of alcohol that fell asleep outside.
Sub-freezing temperatures and snow are usual winter conditions in Poland.
Read More..

French leader honors troops home from Afghanistan

PARIS (AP) — President Francois Hollande on Friday declared "mission accomplished" for French combat troops in Afghanistan, hailing their 11-year military commitment even as the fight goes on for France's NATO allies.
After his election in May, Hollande announced a fast-track pullout of French combat troops from NATO's mission in Afghanistan by year-end — a goal now achieved. Increasingly, France has turned its focus to helping rebuild civilian sector institutions and foster diplomatic initiatives, including hosting a secretive meeting of rival Afghan factions north of Paris as the president spoke.
The Socialist leader has argued that France has done its part in Afghanistan and achieved its goals, and reiterated that theme as he hosted at the presidential palace dozens of soldiers who recently returned home.
"I say to you all: 'mission accomplished.' I also say to you: 'exemplary action'. I say to you: 'congratulations,'" he told them.
U.S. President George W. Bush infamously used the term "mission accomplished" in 2003 after U.S.-led forces toppled Saddam Hussein in Iraq, though some of the worst bloodshed in that war was yet to come and U.S. troops remained in Iraq for 8 1/2 more years.
While Hollande was speaking to French troops, NATO forces overall are still very much engaged in combat against the Taliban and other insurgents fighting Afghanistan's government.
France, which has lost 88 soldiers in Afghanistan, still has 1,500 troops there who are repatriating equipment or working in roles like providing medical care or helping operate Kabul's airport. Hollande said the numbers will decline to 500 by mid-2013. France had a peak deployment of some 4,000 troops in Afghanistan under former President Nicolas Sarkozy.
"There are no more French combat troops in Afghanistan — this is an important moment for you, for our country, and for Afghanistan," Hollande said. "We have now a part to play, but a different one." He said France's financial contribution will reach €300 million ($396 million), to help Afghanistan transition from war to peace in the coming years.
Meanwhile, in the town of Chantilly about 50 kilometers (30 miles) north of Paris, representatives of Afghan President Hamid Karzai's government, the Taliban and Hezb-e-Islami Islamic militant groups, as well as the political opposition, were meeting for a second straight day. They are discussing their country's long-term future — well beyond 2014, when the majority of NATO forces, including those of the United States, are set to leave.
Hosted by a French think tank in the presence of some French officials, the 20-odd delegates have been discussing since Thursday three topics to better understand each other's positions: The political balance in Afghanistan into 2020, the nature of Afghan sovereignty and the necessary parameters for long-lasting peace, according to Mahmoud Saikal, a high-level member of opposition leader Abdullah Abdullah's party.
"I doubt there will be a definite resolution of any kind emerging from this gathering," Saikal said. "It will definitely help building up confidence between the armed opposition forces of this country and the political opposition groups."
"The sheer fact that we do have a couple representatives of the Taliban is an achievement," he said.
Among the most significant delegates was Shahabudin Delwar, who served as Afghanistan's ambassador to Saudi Arabia and Pakistan under the Taliban regime that was ousted by the U.S.-led invasion in 2001. French hosts declined to specify the guest list, or provide access to the participants to journalists during the closed-door meeting. Police blocked off access to the luxury hotel where the Afghans were meeting.
Read More..

Russian parliament passes anti-US adoption measure

MOSCOW (AP) — The lower house of the Russian parliament on Friday overwhelmingly passed a bill that would ban adoption of Russian children by Americans, sending the controversial legislation a step closer to President Vladimir Putin's desk.
Putin hasn't said whether he will sign the measure into law if it passes its next stage of being approved by the upper house.
Some top government officials including the foreign minister and the education minister have spoken flatly against the bill, one part of a larger measure by angry lawmakers retaliating against a recently signed U.S. law that calls for sanctions against Russians deemed to be human rights violators.
It nonetheless received strong approval in Friday's third reading in the State Duma, passing by a vote of 420-7-1. The upper house, the Federation Council, is likely to consider the measure on Wednesday, vice-speaker Alexander Torshin was quoted as saying by the Interfax news agency.
Torshin said there is "serious basis for supposing the draft bill will be supported by the Federation Council."
Originally the bill was more or less a tit-for-tat response, providing for travel sanctions and the seizure of financial assets in Russia of Americans determined to have violated the rights of Russians.
But it was expanded to include the adoption measure and call for the banning of any organizations that are engaged in political activities if they receive funding from U.S. citizens or are determined to be a threat to Russia's interests. In addition, it calls for anyone with dual Russian-U.S. citizenship to be banned as members of political organizations.
The U.S. said the adoption law would needlessly stop hundreds of Russian children from finding families.
"The welfare of children is simply too important to be linked to other issues in our bilateral relationship," U.S. Ambassador Michael McFaul said in a statement.
The bill is a dramatic demonstration of two strains of animosity toward the United States. The Russian political establishment resents the United States for allegedly meddling in the country's internal affairs; Putin has charged that opposition protests over the past year were the work of U.S.-funded troublemakers. Many Russians are angered by cases of adopted children abused in America and by the alleged lenience of courts in these cases.
The Duma bill is named in honor of Dima Yakovlev, a Russian toddler who was adopted by Americans and then died in 2008 after his father left him in a car in broiling heat for hours. The father was found not guilty of involuntary manslaughter.
Anger over abuse peaked in 2010 when an American woman sent her 7-year-old adopted Russian son back to Moscow on a plane alone, saying he had emotional problems and she could no longer care for him.
Despite abuse cases, Russian critics of the bill say it would ultimately victimize orphans by depriving them of an opportunity to escape often-dismal Russian orphanages. There are about 740,000 children without parental custody in Russia, according to UNICEF. Russians historically have been less inclined to adopt children than in many other cultures.
More than 60,000 Russian children have been adopted in the United States in the past 20 years, McFaul said.
But Russia's children's ombudsman Pavel Astakhov, one of the strongest critics of U.S. abuse cases, says the solution is for Russia to adopt a national program to improve orphans' prospects.
"It's necessary to strictly hold to the principle of priority for Russian adopters," he told Interfax after the Duma vote.
Read More..

UK doctor stripped of license over death of Iraqi

LONDON (AP) — A British doctor was stripped of his medical license Friday for misconduct and dishonesty over the death of an Iraqi man who was beaten and killed while in the custody of British troops.
The latest fallout from Britain's troubled occupation of Iraq came as defense officials confirmed they have paid 14 million pounds ($23 million) to settle claims of abuse from more than 200 Iraqis.
Dr. Derek Keilloh treated Baha Mousa, a hotel clerk who died at a British base after being detained in Basra in September 2003 during a sweep for insurgents. Keilloh, then a 28-year-old captain in the Queen's Lancashire Regiment, tried unsuccessfully to revive Mousa, but denied knowledge of the scale of the man's injuries.
A public inquiry found that Mousa had sustained 93 injuries, including fractured ribs and a broken nose, in an "appalling episode of serious gratuitous violence" by British troops.
Dr. Jim Rodger of the Medical and Dental Defense Union of Scotland — which supported Keilloh — said the doctor was "extremely disappointed" by the ruling and was considering what to do next. He has 28 days to submit an appeal.
Last week, the Medical Practitioners Tribunal Service ruled that Keilloh knew of the injuries and failed to adequately examine Mousa's body. It said he also failed to inform senior officers of what was going on and protect other detainees from further mistreatment.
The tribunal also ruled that Keilloh engaged in "misleading and dishonest conduct" by maintaining under oath that he had seen no injuries to Mousa's body.
On Friday, the tribunal said that even though Keilloh had not harmed Mousa — and had tried his best to save him in a "highly charged, chaotic, tense and stressful" situation — the doctor should be barred from practicing medicine for at least five years.
"The panel has identified serious breaches of good medical practice and, given the gravity and nature of the extent and context of your dishonesty, it considers that your misconduct is fundamentally incompatible with continued registration," said Dr. Brian Alderman, a member of the tribunal.
Baha Mousa's father, Daoud Mousa, said he wished the doctor had been banned for life.
"He did not have humanity in his heart when he was supposed to be caring for my son," Daoud Mousa said. "He did not do his job properly."
The death of Mousa and mistreatment of other detainees blighted Britain's six-year deployment in southern Iraq, which ended in 2009.
Britain's defense authorities eventually apologized for the mistreatment of Mousa and nine other Iraqis and paid a 3-million-pound ($4.9-million) settlement. Six soldiers were cleared of wrongdoing at a court martial, while another pleaded guilty and served a year in jail.
The defense ministry said Friday that Britain has paid 14 million pounds to settle 205 damages claims since 2008, including 162 this year. A further 196 claims are being negotiated.
It said most of the 120,000 British troops who served in Iraq "conducted themselves with the highest standards of integrity and professionalism."
Read More..

NATO: Syria using Scud-type rockets again

BRUSSELS (AP) — The Syrian military has continued to fire Scud-type missiles, NATO's top official said Friday, describing the move as an act of desperation of a regime nearing its end.
Although none of the Syrian rockets hit Turkish territory, Secretary-General Anders Fogh Rasmusen said the use of the medium-range ballistic rockets showed that NATO was justified in deploying six batteries of Patriot anti-missile systems in neighboring Turkey.
The United States, Germany and the Netherlands will each provide two batteries of the U.S.-built air defense systems to Turkey. More than 1,000 American, German and Dutch troops will man the batteries, likely from sites well inland in Turkey.
Syria's use of missiles are "acts of a desperate regime approaching collapse," Fogh Rasmussen told reporters at NATO headquarters in Brussels.
A week ago, U.S. and NATO officials said the Syrians had used the ground-to-ground rockets for the first time in the nearly two-year conflict. Damascus immediately denied the claims.
Syria is reported to have an array of artillery rockets, as well as medium-range missiles — some capable of carrying chemical warheads. These include Soviet-built SS-21 Scarabs and Scud-B missiles, originally designed to deliver nuclear warheads.
On Thursday, NATO's supreme commander U.S. Adm. James Stavridis said the Patriot batteries will be shipped to Turkey within the next few days. He said he expected them to achieve initial operational capability next month.
Stavridis said the chain of command starts with himself as the operational commander, through NATO's air component command in Ramstein, Germany, and down to the commanders of the Patriot batteries at their locations in southern Turkey.
The operation will be closely coordinated with the Turkish air defense system, he said.
Read More..