Comments for The Citizen Lab https://citizenlab.org University of Toronto Sat, 09 May 2015 02:43:05 +0000 hourly 1 http://wordpress.org/?v=4.2.4 Comment on Encryption, Anonymity and the Right to Science by S. Keeling https://citizenlab.org/2015/05/sarah-mckune-encryption-anonymity-and-the-right-to-science/#comment-181156 Sat, 09 May 2015 02:43:05 +0000 https://citizenlab.org/?p=25163#comment-181156 “Though we may not immediately recognize it, economic, social and cultural rights are fundamental to the contest surrounding the role of encryption and anonymity in the future of the Internet. That’s because these rights are inseparably tied to the “right to science,” which includes access to the benefits of the latest advances in digital security.”

It seems odd to me that this even needs to be stated. It’s the 21st Century. Science is a huge portion of our culture. It’s how we do things these days, and have for some time now.

]]>
Comment on China’s Great Cannon by David L https://citizenlab.org/2015/04/chinas-great-cannon/#comment-181101 Fri, 08 May 2015 21:00:35 +0000 https://citizenlab.org/?p=25079#comment-181101 Hi,and thanks for the great report.

I was wondering if you all could address the vulnerabilities of playstore apps by Chinese developers. I have confirmedd that ES File Explorer uses Baidu analytics and connects to server’s in Beijing China. The ip address is 202.108.23.85 The app was also pinging for updates,but I turned that off. The problem is,there are many apps like browsers,security apps,and other productivity apps such as file managers that have too many permissions in most cases,IMHO. Now with a multitude of vulnerabilities on older Android OS less than 5.0.x lollipop,I believe that it would not be hard to infec these devices,in light of your research. Recent research by Palo Alto network have discovered a way to hijack an app install and substitute another app,hide it,and be able to take control of a device. There are several JavaScript vulnerabilities too. I have written to many others,but no one seems interested in this issue. Thanks for your time. DL

]]>
Comment on We will miss you, Roger Hurwitz by W. Michael Guillot https://citizenlab.org/2015/04/we-will-miss-you-roger-hurwitz/#comment-179553 Tue, 05 May 2015 14:14:09 +0000 https://citizenlab.org/?p=25126#comment-179553 Ron,

I share your sentiments about Roger completely. Several years ago I met Roger and after hearing his views on cyber norms asked him to write for Strategic Studies Quarterly–which he did (see article Depleted Trust in the Cyber Commons, Fall 2012).
He also offered great mentoring to some of the cyber authors we have published (one in our current edition). Indeed he and I talked about that at ISA-New Orleans this year!
SSQ will surely miss his talent. I can still hear his voice debating cyber issues with panel members.
RIP Roger. Mike

]]>
Comment on China’s Great Cannon by Nate https://citizenlab.org/2015/04/chinas-great-cannon/#comment-170234 Mon, 13 Apr 2015 17:36:37 +0000 https://citizenlab.org/?p=25079#comment-170234 I am puzzled by the statement “We remain puzzled as to why the GC’s operator chose to first employ its capabilities in such a publicly visible fashion.” in the conclusion. I don’t think there is any way for an outsider to know that this is the GC’s first use. It is not only possible but likely that the GC has been used to target individuals and on smaller scale distributed attacks prior to the GreatFire DDoS and that these incidents were never detected and/or didn’t supply enough evidence to determine their origin. This is so likely that the only reasonable conclusion is to assume that the GC has been used before and we didn’t know it.

]]>
Comment on Malware Attack Targeting Syrian ISIS Critics by Dovydas Sankauskas https://citizenlab.org/2014/12/malware-attack-targeting-syrian-isis-critics/#comment-139222 Sun, 01 Feb 2015 22:28:13 +0000 https://citizenlab.org/?p=24386#comment-139222 Damien, this is the list of AntiVirus software that can recognize this malware:

https://www.virustotal.com/lt/file/c2ee598f0135f60ef2b303e198dfb5a377c8881333e29283d5f274ca396dbd49/analysis/

]]>
Comment on The Murky State of Canadian Telecommunications Surveillance by Derek Fairley https://citizenlab.org/2014/03/murky-state-canadian-telecommunications-surveillance/#comment-134209 Wed, 07 Jan 2015 04:24:56 +0000 https://citizenlab.org/?p=22617#comment-134209 At the end of this article (https://citizenlab.org/2014/03/murky-state-canadian-telecommunications-surveillance/) you appear to ask why telecommunications service providers might not be willing to disclose information related to state agency requests for subscriber data. I suspect you already the answer in part but if I am misreading the intent of the conclusion then I am commenting here to let you know that telecommunications service providers are directed to not disclose any requests for subscriber information as outlined in the Section 18 (Offence to disclose identity) of the Canadian Security Intelligence Service Act.

I look forward to reading the following up to this article.

Thanks
Derek

]]>
Comment on The Geopolitics of Cyberspace After Snowden by S. Keeling https://citizenlab.org/2015/01/geopolitics-cyberspace-snowden/#comment-134165 Tue, 06 Jan 2015 20:48:56 +0000 https://citizenlab.org/?p=24472#comment-134165 “What was originally designed as a small-scale but robust information-sharing network for advanced university research …”

I believe that’s incorrect. It was originally designed for the US’ DoD as a disruption resistant communications infrastructure for the military. Universities and academic researchers were brought in to help with, or to enhance, its development. See DARPANet, ARPANet, etc.

I’m feeling very pessimistic about the future of the Internet these days, what with NSA and its partners crowing about being able to crack IPSec and ssh (see der Spiegel). The US and its Five Eyes partners are undermining whole democracies and their protections for individual citizens’ freedoms, all in the name of safety. It’s often said these days Hitler and the Nazis lost WWII, but the fascists won.

Snowden and his fellow whistleblowers are to be commended, but I doubt they’ll be enough to save us from the burgeoning tyranny now running rampant in our midst. It appears there’s a full court press going on to return us to serfdom serving corporate special interests and Intellectual (Imaginary?) Property maximalists in the name of infinite length copyright terms.

Thanks for CLO. I’ve read of some interesting work going on here. Have fun!

]]>
Comment on Malware Attack Targeting Syrian ISIS Critics by Damien4166 https://citizenlab.org/2014/12/malware-attack-targeting-syrian-isis-critics/#comment-130907 Fri, 19 Dec 2014 17:29:06 +0000 https://citizenlab.org/?p=24386#comment-130907 wondering which antivirus/anti malware programs can detect and remove this?

]]>
Comment on Malware Attack Targeting Syrian ISIS Critics by Hemraj https://citizenlab.org/2014/12/malware-attack-targeting-syrian-isis-critics/#comment-130622 Thu, 18 Dec 2014 16:59:58 +0000 https://citizenlab.org/?p=24386#comment-130622 It’s Holyshit…
How to deal with such malware ?

]]>
Comment on Egypt, FinFisher Intrusion Tools and Ethics by Waffa https://citizenlab.org/2011/03/egypt-finfisher-intrusion-tools-and-ethics/#comment-119626 Thu, 16 Oct 2014 13:54:11 +0000 http://citizenlab.org/?p=8050#comment-119626 Gamma international and FinSpy before 2010..
Great price tag.

]]>