Je l'attendais avec impatience et la voici, la voilà... La R3 de Backtrack 5, la distrib linux spécialisé pour la sécurité informatique.
J'ai joué un peu il y a 1 semaine avec la version sortie spécialement pour la Black Hat (la conf aux US qui s'est déroulé juste avant la Defcon) mais maintenant, cette R3 est téléchargeable par tous.
Cette Backtrack voit l'apparition d'une nouvelle catégorie d'outils baptisée "Exploitation physique" qui propose des IDE et bibliothèques Arduino ou encore la collection de payload Kautilya pour hacker des devices.
vendredi 17 août 2012
#Patentfail: Tell Your Story
At the risk of repeating ourselves, the current patent system is broken. There's considerable evidence to support this claim, too—whether it's innovation-destroying patent trolls or certified "chaos" in legal battles among tech giants. More than 10,000 people have signed onto our Defend Innovation campaign, helpfully providing their thoughts on what works and what doesn't with the patent system, and what kinds of changes would really make things better.
These fixes can only come, however, with thorough evidence and analysis, which is why we have kicked off our Defend Innovation campaign. Another crucial ingredient is scholarship on the issue. Professor Colleen Chien of Santa Clara University School of Law is conducting a short Patent Demand Survey, and she's looking for your help in collecting relevant data. Professor Chien's research is an important step in understanding—and teaching others, including policy makers—the scope of the patent problem. It is crucial that those whose lives are affected by patents participate. We can't say it enough: we highly encourage those who have received patent demands to fill this confidential survey out.
We need entrepreneurs and engineers who have been affected by patents to tell their stories. Too often, startups are afraid (oftentimes for good reason) to publicly discuss the undesirable patent situations they find themselves in for fear of being targeted by trolls. And nearly all settlements with trolls require that alleged infringers sign nondisclosure agreements, meaning the world never finds out about the harm that has occurred.
We've been encouraged recently to see fixes to the system coming from within and without. For examples, private parties have developed tools to hack the system, making it work for engineers and companies who would rather not engage in the patent process. The Defensive Patent License (DPL) and Twitter's Innovator's Patent Agreement (IPA) are two prominent examples.
Two Congressmen also recently introduced the SHIELD Act, which creates a fee-shifting scheme for patent lawsuits: a plaintiff must have a good-faith believe that a defendant is infringing a valid patent, otherwise it must pay for the winning party's fees. Though we support this bill, it is an incremental change to a system that needs more sweeping reform. To that end, we've proposed our own additional suggestions on how to fix the system at https://defendinnovation.org.
It is exciting to see so many good ideas for revamping a broken patent system. Anecdotes serve to inspire, but thorough scholarly analysis is necessary too. If you or your business has been affected by patent demands, tell your story. When we are able to cite such scholarship in our legal briefs, our comments, and our blog posts, we make it that much harder for others to deny just how necessary it is to fix our broken patent system.
These fixes can only come, however, with thorough evidence and analysis, which is why we have kicked off our Defend Innovation campaign. Another crucial ingredient is scholarship on the issue. Professor Colleen Chien of Santa Clara University School of Law is conducting a short Patent Demand Survey, and she's looking for your help in collecting relevant data. Professor Chien's research is an important step in understanding—and teaching others, including policy makers—the scope of the patent problem. It is crucial that those whose lives are affected by patents participate. We can't say it enough: we highly encourage those who have received patent demands to fill this confidential survey out.
We need entrepreneurs and engineers who have been affected by patents to tell their stories. Too often, startups are afraid (oftentimes for good reason) to publicly discuss the undesirable patent situations they find themselves in for fear of being targeted by trolls. And nearly all settlements with trolls require that alleged infringers sign nondisclosure agreements, meaning the world never finds out about the harm that has occurred.
We've been encouraged recently to see fixes to the system coming from within and without. For examples, private parties have developed tools to hack the system, making it work for engineers and companies who would rather not engage in the patent process. The Defensive Patent License (DPL) and Twitter's Innovator's Patent Agreement (IPA) are two prominent examples.
Two Congressmen also recently introduced the SHIELD Act, which creates a fee-shifting scheme for patent lawsuits: a plaintiff must have a good-faith believe that a defendant is infringing a valid patent, otherwise it must pay for the winning party's fees. Though we support this bill, it is an incremental change to a system that needs more sweeping reform. To that end, we've proposed our own additional suggestions on how to fix the system at https://defendinnovation.org.
It is exciting to see so many good ideas for revamping a broken patent system. Anecdotes serve to inspire, but thorough scholarly analysis is necessary too. If you or your business has been affected by patent demands, tell your story. When we are able to cite such scholarship in our legal briefs, our comments, and our blog posts, we make it that much harder for others to deny just how necessary it is to fix our broken patent system.
Related Issues:
mardi 14 août 2012
Internet : l’ami des dictateurs ?
Ceci est une réaction au papier du Monde intitulé « L’information en ligne, l’autre conflit syrien« , écrit par Shahzad Abdul. Elle est écrite par n4rim, que vous pouvez croiser sur IRC.Honnêtement, commencer un article sur la Syrie avec une citation de Evgeny Morozov, « Internet sera le meilleur ami des tyrans », c’est assez gonflé. En tout cas, moi, ça me choque. Alors c’est probablement parce que je passe trop de temps sur IRC, trop de temps derrière un écran mais, non, définitivement, j’ai du mal à penser que l’on puisse commencer un article avec un « Internet saimal ».
Je m’explique.
[Important] TrapWire : un réseau d'espionnage dans les mains d'une entité privée
Wikileaks assure que les attaques DDOS qui le rendent indisponible depuis 10 jours sont liés à ses révélations sur l'ampleur de TrapWire, un programme qui centralise et croise les systèmes de surveillance de nombreux clients publics et privés aux USA et en Grande-Bretagne.

Depuis 10 jours, Wikileaks subit une attaque DDOS sans précédent contre ses serveurs, tellement surchargés de connexions qu'ils n'arrivent plus à rester en ligne pour répondre aux demandes légitimes de lecture de ses pages. Jamais le site n'avait connu une offensive d'une telle violence. Or pour Wikileaks, il faut faire un lien direct entre ces attaques et la divulgation de nouveaux e-mails issus de la fuite de Stratfor.
Ces e-mails montrent en effet l'existence d'un réseau de surveillance d'ampleur mis en place aux Etats-Unis et en Grande-Bretagne, sous le contrôle d'une société privée baptisée TrapWire, fondée en 2007 (elle s'appelait alors Abraxas Applications, avant de changer de nom suite à la vente de la maison-mère Abraxas Corporation).
TrapWire est dirigé par d'anciens haut fonctionnaires de la CIA, trois de ses quatre directeurs étant issus de l'agence américaine, en plus du fondateur de la société. Les fuites de Wikileaks n'ont pas révélé l'existence de TrapWire, qui était déjà connue, mais plutôt l'ampleur du programme qu'il gère pour assurer la sécurité de ses clients, aussi bien publics que privés.
La firme vend un logiciel qui collecte des informations de surveillance, y compris à partir d'un réseau de caméras (500 seraient installées dans le seul métro new-yorkais), et partage les alertes avec les départements de police, le ministère de l'intérieur, le FBI et même parfois des société privées. TrapWire compte de nombreux clients dans les transports publics, l'armée, la police (Washington, Las Vegas, New York, Los Angeles...), les casinos, et aurait même des clients en Grande-Bretagne (la Bourse de Londres, le 10 Downing Street où réside le premier ministre, Scotland Yard).... Par ailleurs, des e-mails montrent que des sociétés comme Google ou Salesforce auraient été démarchées, sans que l'on sache si elles ont répondu favorablement.
Concrètement, TrapWire installe des caméras de surveillance sur les "lieux sensibles" de ses clients, pour analyser les images collectées et détecter des "schémas comportementaux" qui peuvent faire craindre une action terroriste. En cas de besoin, il photographie les suspects et garde des preuves en vidéo. Le système est aussi relié à des plateformes d'alertes par lesquelles les citoyens sont invités à signaler les comportements suspects qu'ils remarquent, notamment à Washington et à Los Angeles. Tous les appels sont enregistrés et analysés, avant d'être éventuellement transmis aux centres concernés.
En principe, les surveillances des différents lieux sont isolées les unes des autres. Mais les e-mails révèlent que TrapWire centralise l'ensemble des données et les croise pour perfectionner ses alertes, mélangeant ainsi les données privées ou publiques. C'est tout un réseau de surveillance qui est mis en place, et confié à une société privée, avec l'approbation des pouvoirs publics américains et britanniques.
Le mélange public-privé et la surveillance prédictive de la population sont une tendance très lourde dans les programmes de sécurité américains ou européens, à l'image du programme INDECT financé par la Commission Européenne. La semaine dernière, nous rapportions que Microsoft s'est associé à la police de New York pour déployer un immense système de surveillance dans la ville, et qu'il reverserait 30 % de commission à chaque fois qu'il vendrait le même système ailleurs dans le monde.
MPAA / RIAA Want U.S. to Help Quash The Pirate Bay
The U.S. Government is constantly evaluating and updating its copyright enforcement policies. To this end, Copyright Czar Victoria Espinel recently asked “the public” to come up with recommendations for the future strategy.The call resulted in dozens of submissions from individuals, entrepreneurs, digital rights groups and copyright holders. The RIAA and MPAA did not miss out on the opportunity either – they filed a joint recommendation last Friday.
More has to be done to combat online piracy according to the two groups, and the U.S. Government should play an active role in these efforts.
Google sanctionne les sites accusés de piratage
Google va enfouir dans son moteur de recherche les sites qui font le plus souvent l'objet de demandes de retraits de contenus, faisant ainsi remonter mécaniquement les plateformes légales.
[Lire la suite]
New Tor Browser and Obfsproxy Bundles
The alpha Tor Browser Bundles have all been updated to the latest Tor 0.2.3.20-rc release candidate as well as being updated with some bugfixes. We're getting closer and closer to releasing the 0.2.3.x series as stable, so please give these bundles a lot of testing and help us shake out all of the remaining bugs! The regular bundles have also been updated.
https://www.torproject.org/download
The Tor Obfsproxy Browser Bundles have also been brought up to date with all of the same software as the regular alpha Tor Browser Bundles. These are still a work in progress, so please remember to report bugs! You can download them from the obfsproxy page.
Tor Browser Bundle (2.3.20-alpha-1)
- Update Tor to 0.2.3.20-rc
- Update NoScript to 2.5
- Change the urlbar search engine to Startpage (closes: #5925)
- Firefox patch updates:
- Fix the Tor Browser SIGFPE crash bug (closes: #6492)
- Add a redirect API for HTTPS-Everywhere (closes: #5477)
- Enable WebGL (as click-to-play only) (closes: #6370)
samedi 11 août 2012
Furieux et paranos, des auteurs font fermer un site légal de prêts de livres
Parce qu'ils étaient persuadés d'y voir une forme de piratage ou de vol, des auteurs ont envoyé par centaines des lettres de menaces à l'hébergeur d'un site qui proposait aux acheteurs de livres électroniques de prêter temporairement leur "exemplaire numérique"... comme l'autorisent de nombreux éditeurs. Le site, parfaitement légal, est fermé depuis 10 jours.
[Lire la suite]
[Lire la suite]
Google Starts Punishing “Pirate” Sites In Search Results
For years entertainment industry groups have lobbied search engines to penalize sites that link to a high number of copyrighted files, and today Google has given in to their demands.The search engine will soon take into consideration the number of DMCA takedown notices it receives against sites to determine the ranking of those websites in its search results.
“Starting next week, we will begin taking into account a new signal in our rankings: the number of valid copyright removal notices we receive for any given site. Sites with high numbers of removal notices may appear lower in our results,” Google’s Amit Singhal writes in a blog post.
Earlier this year Google decided to publish all takedown requests online as part of their transparency report, and they will now use this data as part of their search algorithm. This means that websites for which Google receives a high number of valid takedown requests will be penalized.
The top receivers of these notices over the past year were filestube.com, extratorrent.com, torrenthound.com, bitsnoop.com and isohunt.com. They can expect to appear lower in future search results and will therefore receive less traffic through Google searches. Whether Google will downgrade YouTube, where (tens of) thousands of videos are routinely disabled because of alleged infringements, is unknown at this point.
Google stresses that it doesn’t know whether content is authorized or not, so removal of pages from its search results will only take place following a valid DMCA takedown notice.
“Only copyright holders know if something is authorized, and only courts can decide if a copyright has been infringed; Google cannot determine whether a particular webpage does or does not violate copyright law,” Singhal writes.
“So while this new signal will influence the ranking of some search results, we won’t be removing any pages from search results unless we receive a valid copyright removal notice from the rights owner.”
One of the main problems with Google’s new ranking is that perfectly legitimate content on sites with a high number of takedown requests will be degraded as well. Taking YouTube as an example, millions of relevant and legal search results will be degraded simply because there are a high number of “unauthorized” videos posted to the site.
Adding the high number of bogus DMCA notices which Google sees as valid, many sites may also be punished for the faulty takedown requests that copyright holders send. That’s worrying to say the least.
For Hollywood and the major music labels Google’s announcement is a clear win. In fact, it was one of the three demands they handed out to Google, Bing and Yahoo last year during a behind-closed-doors meeting.
The other two demands were “prioritize websites that obtain certification as a licensed site under a recognized scheme” and “stop indexing websites that are subject to court orders while establishing suitable procedures to de-index substantially infringing sites.”
Whether Google will also adopt these suggestions remains to be seen.
Source: Google Starts Punishing “Pirate” Sites In Search Results
Une attaque DDOS empêche les dons à Wikileaks (MàJ : une plainte déposée)
Mise à jour : FDNN a décidé de porter plainte en France pour tenter de faire identifier et condamner l'auteur de l'attaque DDOS, qui se poursuit depuis au moins trois jours sans discontinuer.
[Lire la suite]
[Lire la suite]
Inscription à :
Articles (Atom)




