Wednesday, March 2, 2016

Kiddle search engine for children causes controversy

Kiddle search engine for children causes controversy


Pamela Anderson search resultsImage copyrightKiddle
A search engine aimed at children, which blocks many common search terms including the words menstruation and balls, has gone viral.
Kiddle was registered in 2014 and is powered by Google safe search but has no connection with the tech giant.
Other words blocked by the site include lesbian and gay, a decision which has angered the campaign group Stonewall.
Kiddle says search results are "handpicked and checked" by its editors.
Other apparent search anomalies include the blocking of the term circumcision but not of FGM (female genital mutilation), suicide but not self-harm, the actress Pamela Anderson but not Fifty Shades of Grey.
A form on the site invites users to submit suggested additional key words for blocking.
search for lesbianImage copyrightkiddl
Image captionThe LGBT group Stonewall expressed disappointment that terms like lesbian and gay are also blocked
Lesbian, gay, bisexual and transgender terms also yield no results because the site "cannot guarantee the safety" of such searches.
"Young people regularly use the internet to find information on LGBT issues," a Stonewall spokesperson said.
"Attempting to stop young people finding safe and age-appropriate content of this nature will force many young lesbian, gay, bi and trans people to seek it elsewhere. This can take individuals down inappropriate avenues which might put them at risk.
"Kiddle should rethink its approach to blocking valuable LGBT advice and information."
Kiddle told the BBC it had received complaints "from parents and teachers" before the terms were blocked during early tests.
"Most LGBT sites have forums and user generated content. Even one picture of a half naked man posted as an avatar on such sites (after the site has been vetted) is enough to turn away most parents," the firm said.
It added that it had blocked the term "sex education" because of the illustrations contained within many sites hosting such material.
"What is OK for a child of 12 may not be OK for a child of five," it said.
"Since Kiddle results are either handpicked and checked by our editors or filtered by Google safe search, you know you get kid-oriented results without any explicit content. In case some bad words are present in a search query, our guard robot will block the search," Kiddle states on its website.
The site adds that its server logs are deleted every 24 hours and no user data is stored.

Apple v FBI: US debates a world without privacy

Apple v FBI: US debates a world without privacy

FBI director James ComeyImage copyrightGetty Images
Image captionFirst up at the hearing was FBI director James Comey
Is there such a thing as security so good it's a danger to society?
That's the bigger picture at hand as Apple continues to fight an order to unlock a terrorist's iPhone.
That fight made its way to Capitol Hill on Tuesday for a hearing in front of the House Judiciary Committee, the government body that covers matters relating to how law and order is enforced in the US.
Over the course of four meandering hours, representatives dived headfirst into the complexities of the case FBI director James Comey said is the most difficult issue he has ever had to deal with.
He told the committee that his organisation was seriously concerned by the growth of what law enforcement describe as "warrant-proof spaces" - the term given for methods of communication or storage that, even with the correct permission from the court, can't be accessed. Not by police and not by technology companies.
Pro-Apple protest outside storeImage copyrightGetty Images
Image captionApple has strong support among its users - and from the technology industry
"If we're going to move to a place where it's not possible to overcome that," Mr Comey warned, "that's a world we've never lived in before in the United States."


His demand that Apple assists his agency in weakening the iPhone's security was met with this from California Congresswoman Zoe Lofgren.
"The alternative [to strong encryption] is a world where nothing is private.
"Once you have holes in encryption, the rule is not a question of if, but when those holes will be exploited and everything you thought was protected will be revealed."

Physical intrusion

Apple was represented in this hearing by its lead counsel, Bruce Sewell.
Aside from customer letters, and a somewhat stage-managed interview with ABC, it's the first time the computing giant has been put under scrutiny over its refusal to comply with the FBI order.
Bruce SewellImage copyrightGetty Images
Image captionApple's lead counsel Bruce Sewell said breaking into the iPhone would be dangerous
Mr Sewell put in a strong performance thanks, largely, to the testimony of cryptology expert Prof Susan Landau  - whose pivotal input I'll discuss later.
Mr Sewell endured fierce exchanges with South Carolina Congressman Trey Gowdy, who was angry at what he deemed a lack of cooperation in this controversial case.
How is it possible, the Congressman offered, to live in a world where the FBI has the authority to stick a finger up someone's rear in search of drugs, but not the power to look at the locked iPhone of that same suspect?
There's no simple answer to that, of course, though Apple might contest that law enforcement's capability to carry out such physically intrusive actions doesn't increase the general public's risk of exposure to an unruly finger or two.

'No no no'

But, crass comparison aside, Congressman Gowdy's heated questioning eventually arrived at this key point - if Apple won't comply with this order, he thinks the company must at least be forthcoming in sharing what it is actually prepared to do.
In a similar vein, the session's soundbite moment came from the mouth of Congressman Jim Sensenbrenner, who scolded Apple for having the audacity to demand Congress do something without offering any solution itself.
Trey GowdyImage copyrightGetty Images
Image captionCongressman Trey Gowdy was at times irate at Apple's position
"All you've been doing is saying 'no no no no'," the Congressman said.
"You're operating in a vacuum.
"You've told us what you don't like. You haven't told us one thing about what you do like. When are we going to hear about what you do like so Apple has a positive solution to what you are complaining about."
Congress could, he added, continue unassisted by Apple, "but I can guarantee you aren't going to like the result".

Mother's diary

That's because, judging by some of the questioning during the session, some members of Congress consider it unfathomable that police cannot reach the information kept in Apple devices.
It's a barrier hindering many, many cases. Mr Comey could not say exactly how many phones the FBI wanted to unlock nationwide, other than that it was "a lot".
Later in the hearing, we learned that there are 205 locked iPhones currently held by police in New York alone.
Prof Susan LandauImage copyrightGetty Images
Image captionProf Susan Landau offered her expert insight into the risks of breaking encryption
We were reminded about a case involving Brittany Mills, an expectant mother who was shot and killed on her doorstep in Louisiana last year. Her baby boy died soon after.
Ms Mills - whose family attended the hearing - kept a personal diary on her phone that could contain crucial information about the murderer. The phone is locked, rendered unreachable by Apple's encryption software.
"I think about the nine-year-old girl who asked 'why can't they open the phone so we can see who killed my mother'," said Louisiana Congressman Cedric Richmond.
Mr Sewell said Apple had done a lot to help with that investigation, but without creating the kind of tool demanded by the FBI in the San Bernardino case, it would be unable to assist further.

Making a smarter FBI

But maybe someone else could?
Republican Congressman Darrell Issa - a favourite among tech enthusiasts thanks to his opposition to several bills considered to be anti-internet - gave Mr Comey a hard time over the process leading up to asking for Apple's help.
Mr Issa said the FBI had not explored all the options for accessing the data and circumventing Apple's security.
He said the FBI should be investing in bringing in people with that expertise, not relying on companies like Apple to do the work for them.
Point being - if the FBI could crack the phone itself, Apple's opposition would be irrelevant.
This call was backed up by the thoughts of Prof Landau, an independent cryptology expert who argued, with some force, that there was no way the FBI's request in San Bernardino could be carried out safely.
Screengrab from IS Telegram channelImage copyrightTelegram
Image captionThe so-called Islamic State has used encrypted app Telegram to announce attacks
She said that while Apple could no doubt keep the code required to crack Syed Farook's phone a secret, the real issue is what will happen when Apple is subjected to possibly hundreds of requests to do the same thing on other devices.
She said the surge of orders would mean Apple would need to create a faster process to handle the task, one that would by its nature be vulnerable to exploitation through interception, or perhaps a rogue employee.
Prof Landau insisted the only real course of action was for the FBI to invest heavily in becoming smarter - rather than compelling Apple to make its products less secure.
Because a weakened iPhone would have one critical side effect, she said. Criminals would simply use other, more secure methods to talk to each other - apps created by countries outside the US, offering encryption mechanisms even more secure than those offered by Apple currently.
Should that happen, the wishes of Congress matter not a jot.
"What you're saying," Congressman Jerrold Nadler asked Prof Landau, "is that we're debating something that's… undoable
source bbcnews.com

Facebook investigated over market-power abuse claims

Facebook investigated over market-power abuse claims

FacebookImage copyrightGetty Images
Image captionThe formal investigation is the first to be held into Facebook
German authorities are investigating Facebook for suspected abuse of its dominant market position.
The country's federal cartel office suspects the social network's privacy terms violate data protection laws.
It is looking into whether Facebook's "dominance" means those terms also constituted an abuse of market power. The formal probe is the first of its kind the social network has faced.
Facebook said it was confident it complied with the law.
"Dominant companies are subject to special obligations," said Andreas Mundt, the president of the cartel office.
"These include the use of adequate terms of service as far as these are relevant to the market
FacebookImage copyrightGetty Images
Image captionFacebook said it complied with the law
"For advertising-financed internet services such as Facebook, user data are hugely important.
"For this reason, it is essential to also examine under the aspect of abuse of market power whether the consumers are sufficiently informed about the type and extent of data collected."
His investigation would focus on Facebook's US operation, as well as its German and Irish subsidiaries, the cartel office said in a statement released on Wednesday.
It said Facebook was dominant in the social media market and relied on advertising revenues generated on the basis of a "large amount of personal user data".
And users had to agree to this collection of data as a condition of their being able to use the network.
"It is difficult for users to understand and assess the scope of the agreement accepted by them," it said.
"There is considerable doubt as to the admissibility of this procedure, in particular under applicable national data protection law.
"If there is a connection between such an infringement and market dominance, this could also constitute an abusive practice under competition law."
Mark ZuckerbergImage copyrightGetty Images
Image captionFacebook co-founder Mark Zuckerberg recently visited Germany, where his company has come in for criticism
A Facebook representative said: "We are confident that we comply with the law, and we look forward to working with the Federal Cartel Office to answer their questions."
The German authorities are working in "close contact" with the European Commission, the competition authorities of the other EU member states and data and consumer protection officers.
European Commission spokesman Ricardo Cardoso said the EU executive shared the view of the German cartel office that the mere infringement of data protection rules by a dominant company did not automatically amount to a competition violation.
"However, it cannot be excluded that a behaviour that violates data protection rules could also be relevant when investigating a possible violation of EU competition rules," he added, while declining specific comment on the new case.
Speaking in Germany in January, the European commissioner for competition Margrethe Vestager said her agency was taking a harder look at whether the collection of vast amounts of consumer data by big internet companies violated competition rules.

Thousands of popular sites' at risk of Drown hack attacks

Https padlock
Websites have been warned they could be exposed to eavesdroppers, after researchers discovered a new way to disable their encryption protections.
The experts said about a third of all computer servers using the HTTPS protocol - often represented by a padlock in web browsers - were vulnerable to so-called Drown attacks.
They warn that passwords, credit card numbers, emails and sensitive documents could all be stolen as a consequence.
A fix has been issued.
But it will take some time for many of the website administrators to protect their systems.
The researchers have released a tool that identifies websites that appear to be vulnerable.
They said they had not released the code used to prove their theory because "there are still too many servers vulnerable to the attack".
As yet, there is no evidence hackers have worked out how to replicate their technique.
An independent expert said he had no doubt the problem was real.
"What is shocking about this is that they have found a way to use a very old fault that we have known about since 1998," said Prof Alan Woodward, from the University of Surrey.
"And all this was perfectly avoidable.
"It is a result of us having used deliberately weakened encryption, which people broke years ago, and it is now coming back to haunt us."
Drown Attack website
Image captionThe researchers have published background information to their discovery online

Call to action

The researchers, cybersecurity experts from universities in Israel, Germany and the US as well as a member of Google's security team, found a computer server could be vulnerable to attack just by supporting 1990s-era encryption protocol SSLv2 (Secure Sockets Layer version 2), even if in day-to-day use it employed more modern encryption standards to scramble communications.
In practice, older email servers would be more likely to have this problem than the newer computers typically used to power websites.
But many organisations reuse encryption certificates and keys between the two sets of servers.
The researchers dubbed the flaw Drown - an acronym for decrypting the Rivest-Shamir-Adleman (RSA) algorithm with obsolete and weakened encryption.
"Operators of vulnerable servers need to take action," they wrote.
"There is nothing practical that browsers or end-users can do on their own to protect against this attack."
Computer serverImage copyrightThinkstock
Image captionOlder email servers that still support SSLv2 could be used to attack more modern web servers

Export restrictions

The SSLv2 protocol was deliberately weakened because, at the time of its creation, the US government wanted to try to restrict the availability of tough encryption standards to other countries.
It has since eased its export limits, but the effects live on.
"The problem is that while clients - such as [web] browsers - have done away with SSLv2, many servers still support the protocol," blogged Prof Matthew Green, from Johns Hopkins University.
"In most cases this is the result of careless server configuration.
"In others, the blame lies with crummy and obsolete embedded devices that haven't seen a software update in years - and probably never will. "

Quick attack

To mount a successful attack on a website would still require a considerable amount of computational force.
But, the researchers said, under normal circumstance, hackers could rent the required capacity from Amazon's cloud compute division for as little as $440 (£314).
In addition, because many of the servers vulnerable to Drown were also affected by a separate bug, a successful attack could be carried out using a home computer.
"This form of the attack is fast enough to allow an online man-in-the-middle style of attack, where the attacker can impersonate a vulnerable server to the victim," the researchers wrote.
"We were able to execute this form of the attack in under a minute on a single PC."
The researchers said many popular sites - including ones belonging to Samsung, Yahoo and a leading Indian bank - appeared to be vulnerable.
Prof Woodward said the team's test had also indicated a problem with bbc.co.uk.
"The weakness is actually in the old Pop3 server," he said.
"Few people still use Pop3, but it means that things like your password reset server could theoretically be eavesdropped upon."
source bbc news

Saturday, February 13, 2016

MY FORUM