Wednesday, April 18, 2007

IDentiWall could stop this thief

Georgia man pleads guilty in peer-to-peer crackdown

Grant Gross

April 16, 2007 (IDG News Service) A man from Columbus, Ga., has pleaded guilty to two felonies related to distribution of copyrighted materials over a peer-to-peer network, the Department of Justice announced Monday.

The plea of Sam Kuonen, 24, is the fifth in a series of convictions arising from the DOJ's Operation D-Elite, an ongoing crackdown against the distribution of movies, software, games and music over peer-to-peer networks using the BitTorrent file-sharing technology.

Kuonen was charged with conspiracy to commit criminal copyright infringement and criminal copyright infringement. He faces up to five years in prison and a $250,000 fine, the DOJ said. He faces sentencing July 16 in the U.S. District Court for the District of Kansas.

Operation D-Elite has targeted leading members of a peer-to-peer network known as Elite Torrents, the DOJ said in a news release. In its prime, Elite Torrents attracted more than 133,000 members and facilitated the illegal distribution of more than 17,800 titles, which were downloaded over 2 million times, the DOJ said.

The Elite Torrents network often included illegal copies of copyright works before they were available in retail stores or movie theaters. Kuonen was an "uploader" to the Elite Torrents network, responsible for supplying the network with the first copy of a particular movie or other title that was then made available to the entire network for downloading, the DOJ said.

On May 25, 2005, federal agents shut down the Elite Torrents network by taking control of its main server. Authorities replaced the existing Web page with a law enforcement message announcing that "This Site Has Been Permanently Shut Down by the Federal Bureau of Investigation (FBI) and U.S. Immigration and Customs Enforcement (ICE)." Within only one week, the law enforcement message was viewed over half million times.

The Motion Picture Association of America provided "substantial" assistance to the investigation, the DOJ said.

Labels: ,

Thursday, February 8, 2007

RSA: Microsoft pledges support for OpenID

Dynamic Security could help integrate this authentication system into your present security programs and policies.

RSA: Microsoft pledges support for OpenID

Robert McMillan

February 06, 2007 (Computerworld Hong Kong) Microsoft Corp. has thrown its weight behind OpenID, an emerging Web authentication standard.

The announcement was made today at the RSA Conference in San Francisco during a joint keynote by Microsoft Chairman Bill Gates and Chief Research and Strategy Officer Craig Mundie that was long on vision and short on specifics.

Microsoft pledged to work to integrate OpenID with its CardSpace identity management software, which is now available in conjunction with Windows Vista. "The marriage of CardSpace and OpenID 2.0 is actually a giant step forward," Mundie said.

By integrating these two technologies, Microsoft expects to "eliminate the issue of the man-in-the-middle-attack," Mundie said. In these attacks, which are increasingly being used by phishers, a thief steals sensitive information by setting up a fake Web site that passes information back and forth between the victim and the legitimate Web site.

OpenID is an emerging open-source standard that simplifies the task of logging on to many different Web sites.

Gates and Mundie spent much of their keynote discussing how their company plans to simplify security and make the process of managing digital identities easier.

IT professionals could achieve both ends by getting rid of log-in passwords and replacing them with strong, certificate-based authentication techniques like smart cards, Gates said. "Passwords are not only weak. Passwords have a huge problem. If you get more and more of them, the worse it is," he said.

"We see smart cards ... [and] certificates in general as the way these things should go. You'll be presenting certificates as opposed to weak passwords," he said.

Microsoft hopes to drive the adoption of smart cards, with the launch of its Identity Lifecycle Manager 2007, introduced at RSA. Expected to ship on May 1, this software integrates technology from Microsoft's 2005 acquisition of Alacris with the company's Identity Integration Server. The software will make it easier for users to integrate strong authentication technologies like smart cards into Microsoft networks.

Mundie suggested that in order for security to work, technology companies will need to turn their thinking upside down, to a certain extent. "Security was really a blocking thing," Mundie said. "How do you invert this ... so these security mechanisms become a thing that makes it simpler for anyone to be granted permission to get [network] access."

Microsoft plans to achieve this by switching the focus using technologies like IPsec (Internet Protocol security) and IPv6 (IP version 6), Mundie said. The company has already been using these technologies for the past two and a half years in an internal access control system that is better about granting employees and contractors access to the data and applications that they need, but keeping them away from the rest of the network, he said.

With breaches being reported every week -- often after the loss of a laptop computer -- companies need to think beyond locking down the perimeter of their networks, Mundie added. "The threat model is changing in fundamental ways. We could continue to invest in this fortress mentality of protecting everything, but I don't think that would be sufficient," he said. "Our castle is fairly porous because a lot of our assets leave the castle."

Microsoft's broad vision did not impress one attendee.

"This was the most content-free presentation I've seen at RSA in years," said Bruce Schneier, chief technology officer with BT Group PLC's Counterpane unit. "My guess is that most people in the room could have given that talk because it's where we all want to go."

The keynote, in which Gates and his successor sat side-by-side and, at times, finished each others thoughts, appeared to be a symbolic handing over of power, Schneier said.

Gates will be stepping down from his day-to-day duties in July 2008, at which point Mundie will take over Microsoft's research efforts.

But Schneier doesn't expect Gates to appear at next year's conference. "The take-away is Craig's coming back next year, but Bill isn't," he said.

Labels: , , ,

Made4biz Security Translating real-world security knowhow into state of the art security systems.
Made4biz Security

Turn on Sound for Demos:
Bill Gates Demo (Location-based)
Elvis Demo (Location/Context-based)
Clint Eastwood Demo (Temporal-based)

Powered by Blogger

Subscribe to
Posts [Atom]

Technorati Profile

RSS Syndication

Made4Biz Security Inc