Pages

Showing posts with label USA. Show all posts
Showing posts with label USA. Show all posts

Saturday, 31 January 2015

Delhi victim sues Uber in the US over alleged assault

Uber has been sued in the US over alleged rape.Uber
A woman who says she was assaulted and raped by an Uber driver in New Delhi last month has sued the car-sharing service in the US.
The woman, who remains unidentified, is suing Uber for unspecified damages, saying that the alleged assault stemmed from the company failing to implement basic security features that might have kept her safe, according to Reuters, which obtained a copy of the lawsuit. The woman, who resides in Delhi, also asked for Uber to update its security protocols, arguing that a 24-hour customer support hotline and in-car cameras could prevent attacks from occurring.
"Our deepest sympathies remain with the victim of this horrific crime," an Uber spokeswoman said in a statement. "We are cooperating fully with the authorities to ensure the perpetrator is brought to justice."
Last month, the 26-year-old woman hailed a car from Uber in Delhi after attending a social event. Soon after, the driver allegedly attacked and sexually assaulted her. A few days later, the driver, Shiv Kumar Yadav, 32, was arrested in his hometown 100 miles outside of Delhi.
The arrest called into question Uber's safety protocols. Uber, based in San Francisco, performs background checks on drivers, but the company's drivers have faced a string of allegations over the last several months, including dozens of claims of sexual assaultgropingkidnapping, and physical assault, according to media outlets.
Just days after the woman in Delhi was allegedly assaulted, an Uber driver in Boston, Alejandro Done, was arraigned on charges of rape, assault to rape, kidnapping, and two counts of assault and battery after allegedly attacking a young woman in his Uber car. Done allegedly took the woman to a secluded area and attacked her, the district attorney's office for Massachusetts' Middlesex County said last month.
The alleged attack was the fourth time an Uber customer in the Boston area had reported an assault or inappropriate touching within one month, according to the Boston Globe. Three women had previously reported incidents with car-sharing services, and at least two had used Uber.
Uber has acknowledged that it needs to improve its approach to security. Last month, the company's head of global safety, Phillip Cardenas, said in a blog post that Uber has "more work to do" in safety, adding that his company "is committed to developing new technology tools that improve safety, strengthen and increase the number of cities and countries where background checks are conducted and improve communication with local officials and law enforcement."
Cardenas' comments came a month after Uber started a safety review to identify new technologies, such as biometrics and voice verification, to enhance driver screenings and background checks. Uber also said it is working to make it easier for riders to communicate with the company and is building "Safety Incident Response teams" to provide support to customers during emergencies. Uber did not say when its new programs would roll out.
After the alleged incident in Delhi, Uber's service was banned from the Indian capital territory over claims that it was operating illegally. Last week, Uber announced that it had applied for a radio taxi license and was now operating again in Delhi. The license effectively makes Uber a taxi provider and requires more availability, including a 24/7 on-call center.
In its statement announcing its return to Delhi, Uber said that it has instituted new safety protocols, including reverifying drivers and "implementing independent background checks on all driver partners, plus vehicle documentation reviews."
"Our teams have worked tirelessly to develop new safety features (including an in-app emergency button) nationwide, establish a dedicated incident response team and reverify the full credentials of every driver-partner on the Uber platform in Delhi," Uber wrote in a statement.

Thursday, 9 October 2014

US spying scandal will 'break the Internet,' says Google's Schmidt


20141008-sen-ron-wyden-palo-alto-2.jpg
Sen. Ron Wyden moderated a discussion between top tech firm leaders on the impact of the US spying scandal on the Internet economy. Prognosis: It's going to get worse before it gets better.Seth Rosenblatt/CNET
PALO ALTO, Calif. -- The impact of US government surveillance on tech firms and the economy is going to get worse before it gets better, leaders at some of the biggest tech firms warned US Sen. Ron Wyden on Wednesday during a roundtable on the impact of US government surveillance on the digital economy.
The senior Democratic senator from Oregon took the floor at the Palo Alto High School gymnasium -- where he played high school basketball well enough to earn a college scholarship for his court-side abilities more than 50 years ago -- to discuss the economic impact and future risks of US government surveillance on technology firms.
Google Executive Chairman Eric Schmidt, who has been outspoken on the topic, pulled no punches with his assessment of how the spying scandal has and will continue to impact Google and other tech companies.
The impact is "severe and is getting worse," Schmidt said. "We're going to wind up breaking the Internet."
Also on the panel with Schmidt was Microsoft General Counsel Brad Smith, another critic who became more outspoken of government surveillance after Edward Snowden leaked National Security Agency documents in 2013 that showed a much wider federal spying apparatus than previously believed.
"Just as people won't put their money in a bank they won't trust, people won't use an Internet they won't trust," Smith said.
Panelist Ramsey Homsany, general counsel for online storage company Dropbox, said the trust between customers and businesses that is at the core of the Internet's economic engine has begun to "rot it from the inside out."
"The trust element is extremely insidious," Homsany said. "It's about personal emails, it's about photos, it's about plans, it's about medical records."
The documents leaked by Snowden indicate that the US government has been collecting a record of most calls made within the US, including the initiating and receiving phone numbers, and the length of the call; emails, Facebook posts and instant messages of an unspecified number of people; and the vast majority of unencrypted Internet traffic including searches and social media posts. Documents from Snowden show that the British equivalent of the NSA, the Government Communications Headquarters (GCHQ), has a similar program.

Trouble abroad

In prepared remarks to open the roundtable, Wyden noted that he warned back in 2011 that people were going to be stunned and angry when they found out how the US government had been "secretly applying its surveillance authority" to its citizens. What he wasn't counting on was the international backlash.
Some of the international pushback is in response to data collection by tech companies, not the US government. Europe's new and controversial "right to be forgotten" law, which says European citizens have a right to ask search engines to remove any results that might infringe on their privacy, is causing headaches for Google. Critics contend that Google policies placed data collection over privacy.
The cost of building data centers in each country that a tech firm wants to do business in could wind up destroying US tech firms, Schmidt and Smith warned.The tech execs on the panel were most upset and scared about international efforts to impose "data localization," as Microsoft's Smith put it, referring to a burgeoning efforts by countries to force companies to build data centers based within their borders.
Schmidt called data localization a "national emergency." Tech titans have yet to go in-depth as to the actual financial impact data localization has had on them, but in addition to the costs of having to build at least one separate data center for each country that demanded it, data localization could also subject the data to local laws in a way that tech firms worry would erode user trust -- and their ability to trade on that trust -- even further.
Smith noted that 96 percent of the world does not live in the US, and that the American tech economy depends on convincing them that American tech services are trustworthy. "Foreign data centers would compromise American [economic] growth" and leadership, he said.
Abroad, efforts are already underway to force international tech companies to be more respectful of their own national interests -- efforts that could erode consumer trust further, said Wyden. German Chancellor Angela Merkel has said publicly that Germany is looking at European email service providers so that their messages "don't have to go across the Atlantic." The government of Brazil's President Dilma Rousseff is considering forcing US tech firms to build data centers in Brazil, if they want to do business with Brazil.
The biggest indication of the decline of America's ability to guide the Internet, according to Wyden, is that Chinese officials told the senator earlier this summer that they considered the Chinese theft of US tech trade secrets no different than US government surveillance of foreign governments and firms.

Rebuilding trust

Part of reclaiming leadership in the digital economy since the Snowden document leaks has been efforts by tech companies to encrypt user data to protect it. Facebook has used its leverage to help convince tech companies to implement tougher webmail encryption standards, while Google and Yahoo are seeking to push the envelope of how encryption can safeguard webmail.
Panelist Colin Stretch, general counsel for Facebook, called efforts to encrypt user data "a key business objective of all of us."
"I'd be fundamentally surprised if anybody takes the foot off the pedal of building encryption into their products," he said.
Wyden reiterated his stance that he is not opposed to all government surveillance: He supports Section 702 of the Foreign Intelligence Surveillance Act Amendments from 2008, which allows the director of National Intelligence and the US attorney general to team up to target non-US citizens located outside the US.
While Wyden and the panelists discussed the need to revise American laws as the first step to regain the trust of American citizens and international governments, they didn't talk about what to do with the data that's already been collected.
Wyden told CNET after the panel that he had no plans at the moment to address the data that the government has currently collected.
"I have to reflect on that," he said, but added, "The cat's out of the bag. I want to get policies right for the future."
"There's no question that Washington, DC, does overreach well," quipped the senator.
Wyden concluded with a promise to make Congress take action to preserve the digital economy.
"The message here today is that there is a clear and present danger to the Internet economy," he said. "The reality is that we can pass a good bipartisan bill by the end of the year."

Sunday, 15 June 2014

Apple, Cisco back Microsoft in fight over US warrant for data overseas

  • by 
  •  
    8-Microsoft_V2.jpg

    Microsoft is challenging a US search warrant for customer emails stored on a data center outside the country, and tech companies are lining up in support.
    Apple and Cisco are the latest to file a friend-of-the-court brief backing the software giant's position. The joint filing, made Friday, is in addition to ones earlier in the week by Verizon and AT&T showing their support.
    The Electronic Frontier Foundation also filed a friend-of-the-court brief Friday, saying US warrants don't apply to emails stored on an overseas server.
    "The Fourth Amendment protects from unreasonable search and seizure. You can't ignore the 'seizure' part just because the property is digital and not physical," said EFF Staff Attorney Hanni Fakhoury, according to a press release Friday. "Ignoring this basic point has dangerous implications -- it could open the door to unfounded law enforcement access to and collection of data stored around the world."
    Court papers made public Monday detail Microsoft's objections to comply with a December warrant for a customer's email data stored in Dublin, Ireland, that the US government is seeking in connection with a criminal investigation.
    "The government takes the extraordinary position," the filing reads, "that by merely serving such a warrant on any US-based email provider, it has the right to obtain the private emails of any subscriber, no matter where in the world the data may be located, and without the knowledge or consent of the subscriber or the relevant foreign government where the data is stored."
    The government, on the other hand, said in its own filing in April that Microsoft's position would lead to "absurd" and "arbitrary" results that would have "a devastating impact on the government's ability to conduct criminal investigations."

Thursday, 5 June 2014

Behind US-China cyberspy tensions: The view from Beijing

  • by 
  •  
    china.jpg
    Chinese paramilitary police officers in Tiananmen Square, Beijing, China.Getty Images
    An increasingly testy dispute between China and the United States over cyberespionage is about to drag out in Silicon Valley.
    Last month, the Justice Department unsealed an indictment charging five officers of China's People's Liberation Army of trying to steal US commercial trade secrets. The assumption is that the five belong to the shadowy specialist group, Unit 61398, which was described in a 2013 report by Mandiant as a government-run Shanghai computer spy group.
    China, which has never confirmed the group's existence and says that the government has never supported any hacker activities, this week issued a call "to punish severely the pawns" of the US government for monitoring China and stealing secrets.
    That fits with a familiar narrative. Ever since former contractor Edward Snowden one year ago disclosed the existence of extensive spying programs conducted by the National Security Agency, Chinese official media have suggested that American tech companies were in cahoots with Washington. (Coincidentally, Microsoft's top lawyer on Wednesdayurged the US to change its surveillance procedures immediately.)"US companies including Apple, Microsoft, Google, Facebook, etc. are all coordinating with the PRISM program to monitor China," the People's Daily said on its official microblog. (PRISMwas a government program set up to monitor foreign communications that cross US servers but which also gave theNSA access to the central servers of major tech companies.)
    China also warned that it would favor domestic technology suppliers over US companies.
    "To resist the naked Internet hegemony, we will draw up international regulations, and strengthen technology safeguards, but we will also severely punish the pawns of the villain. The priority is strengthening penalties and punishments, and for anyone who steals our information, even though they are far away, we shall punish them!" the statement said.
    If China makes good on that threat, it will cost US technology companies billions in dollars in lost contracts. But this increasingly fraught Sino-American relationship is likely not going to improve anytime soon, notes Shen Yi, who teaches in Fudan University's department of international politics in Shanghai. CNET spoke with Yi to get a perspective on how China views the latest ratcheting up in tensions and the potential fallout suffered by US tech companies.
    Q: Given Edward Snowden's revelations about the extent of NSA spy operations around the world, what's been the reaction to the US decision to indict five PLA officers?Shen Yi: That US decision triggered quite a lot of feedback from China's side. The decision to indict five PLA officers is a surprise to China, especially considering the revelations of the PRISM project by Snowden. According to Beijing's understanding, the US needs to apologize first for the abuse of its capabilities and should find a proper solution on all these issues involving China and the US via diplomatic negotiations.
    Obviously, many US technology companies do business in China. Is there likely to be a major impact on their ability to operate in China because of the latest dispute between Washington and Beijing?Shen Yi: Of course there will be an impact. For quite a long time, since the end of the 1970s, these companies enjoyed an overwhelming advantage in the mainland market. One of the most important reasons that Beijing trusted these companies was the belief that technology companies are politically free, meaning that the company is not the secret agent of a foreign government, and the import of the technology could be a benefit to China's own national interest.
    Does China believe that US tech companies are colluding with US espionage efforts?Shen Yi: It's very difficult for China to say no after Snowden released the evidence.
    The Chinese government says it plans to put in place new procedures to deal with what it says are potential security problems with Internet technology and services used by sectors "related to national security and the public interest." What might this mean in practice?Shen Yi: In 2010, the Chinese government decided to research Washington's new concept: supply chain security. The newly reported procedures are nothing but the Chinese version of supply chain security and national security review procedures. Lots of Chinese companies enjoyed the warm welcome of such kinds of procedures and (now) it's Beijing's turn. Generally speaking, Beijing would like to duplicate the procedures deployed by Washington and its friends in Europe.
    Is there a relationship between the PLA and Chinese state companies?Shen Yi: According to the report on the existence of a global system for the interception of private and commercial communications (the Echelon interception system), US companies like Boeing could directly collect commercial intelligence on the Airbus via the national intelligence infrastructure (offered by) Echelon. In my personal view, China should copy such kinds of cooperation to ensure that our companies could be assured of fair play in such an environment.
    The US argues that the PLA stole commercial information over the Internet in order to benefit Chinese firms. Is there persuasive evidence to back up that allegation? Is the government irritated because it views this as just another example of the US trying to hold back China?Shen Yi: The US Department of Justice provides no more evidence than that found inside the Mandiant report about one year ago. Until now, no companies have been mentioned that directly benefited from the so-called hacking operation. Such an indictment, very easily, would revive the Chinese government's memory of the Cox Report in 1998 which implies that the development of China heavily depended on the stealing of high tech from the US. From theft of high tech to manipulation of the RMB exchange rate and to theft via PLA hacking again, it seems that the US favors the development of different narratives to explain the vivid development of the economy of China, and has tried its best to hold back China.
    What's been the main takeaway for the Chinese government from the Snowden disclosures about cybersecurity? Were they caught unaware at the scale of the intelligence gathering being conducted over the Internet?Shen Yi: At least before Snowden, no information officially came from Washington telling Beijing that we are spying on you via the Internet. If the video upload by Mandiant is true and they could record the screens of the so-called Chinese hacker when he was "invading" some US companies, it seems that it would be difficult for Beijing to realize the existence of US intelligence gathering via the Internet.
    From a national security point of view, how does the Chinese military view the cybergathering of intelligence?Shen Yi: My opinion is that the cybergathering of intelligence is a new arena for great powers like the US and China. The US already has overwhelming advantages in cyberspace. It seems that Washington, just like (American political scientist) Kenneth Waltz has mentioned, doesn't want to produce any self-restraint of its power in cyberspace.
    Given the course that both countries are now on, how likely is it that we'll see a cyber conflict erupt between China and the US within the next 10 years? What will it take to prevent that from taking place?Shen Yi: Cyber conflict is not easy to define, but it would be difficult to say it will be 100 percent impossible. I think if both sides are not able to improve their strategic confidence in the cyberspace, it would be very dangerous.

Saturday, 15 March 2014

US government begins loosening decades-old grip on the Internet

ICANN CEO Fadi Chehade
ICANN CEO Fadi Chehade will get his wish: an opportunity to hand off control of the core of the Internet from the US government to a variety of involved stakeholders from across the world.
(Credit: ICANN)
After incubating the Internet and overseeing it for decades, the US government announced Friday it's releasing the last elements of control it has.
The Department of Commerce originally handled core parts of the Internet, but gradually backed away from those duties through a contract with a nonprofit organization called the Internet Corporation for Assigned Names and Numbers (ICANN). In a statement Friday, the Commerce Department tasked ICANN with convening involved parties to formalize a "multistakeholder" approach to Internet governance.
It's been a long time coming -- the privatization process began under President Bill Clinton in 1997 -- but now the timing is right for ICANN. In a January interview, ICANN Chief Executive Fadi Chehade told CNET, "US oversight is not sustainable any longer."The nuts and bolts of that work involves running the Internet's Domain Name System (DNS), which translates numeric Internet Protocol addresses into the more convenient human-readable domain names like cnet.com; managing the root servers that hold those DNS records for use by all other machines on the Internet; and overseeing the current explosive growth of new top-level domain names such as .berlin, .social, and .cleaning.
ICANN has matured, the Commerce Department had committed to handing off responsibility at some point, and the revelations from Edward Snowden of US government surveillance on the Net increased the need for the hand-off, Chehade said:
There is no question that Edward Snowden's revelations have stimulated the dialog. I attended a couple of sessions at the World Economic Forum about security risks. I saw leader after leader of major companies like GE sincerely worried about the trust factor on the Internet. And we have the Target situation. The trust in the ecosystem has been punctured a little bit.
Working toward the hand-off, ICANN already had set up a meeting on Internet governance in Brazil on April 23-24. The Commerce Department generally is on the same page, using the "multistakeholder" term Chehade also relies on.
Those stakeholders include the Internet Engineering Task Force (IETF), the Internet Architecture Board (IAB), the Internet Society (ISOC), and Regional Internet Registries that oversee the distribution of IP addresses to those registering new domain names.
Those organizations welcomed the Commerce Department's move. They and others said in astatement Friday:
Our organizations are committed to open and transparent multistakeholder processes...The Internet technical community is strong enough to continue its role while assuming the stewardship function as it transitions from the US government.
The Commerce Department's National Telecommunications and Information Administration (NTIA) wants ICANN not just to build its multistakeholder approach, but also to maintain the DNS security and resilience and to make sure the "openness of the Internet" is maintained.