ie8 fix

EFF: Internet's security, privacy flaws need attention

By | March 24, 2010, 10:02am PDT

Summary: Internet technology engineers face legal concerns that are still not addressed according to many legal scholars that follow Internet services and applications.

The Electronic Frontier Foundation (EFF) held a 1 hour round table concerning internet architecture revealing what they believe are flawed design elements have never been designed with standards consumers can trust. Internet technology engineers face legal concerns that are still not addressed, according to many legal scholars that follow Internet services and applications.

The panel consisted of EFF Board of Directors David Farber, Ed Felton and Lorrie Faith Cranor; John Buckman, current Chairman of the Board of the EFF; and facilitated by Cindy Cohn, EFF’s staff Legal Director.

Security certificate trust - or more accurately, the lack of authority oversight of managing certificates when https protocol is used, was highlighted as an area of concern that needs to be reviewed. Certificate authorities should not be delegated to third parties unless publicly disclosed. Issuers of certificates are not controlled by any one organization or body of standards. There are over 500 different providers of certificates - which all browsers support. The EFF panel maintains that ‘man in the middle’ interception of https is still very rampant due to lack of oversight of certificate issuing policies and processes allowed. Mozilla.org has a list of certificate of issuers that it supports. There are others.

Transparency of user information on social media and commerce websites are very different. Distinction of what is viewed and how disclosure methods are implemented are often thought of as one and the same, which is not true. EFF’s panel suggested that commerce websites understand the ethical and security concerns required. Social websites should have the same mindset but don’t. One interesting suggestion is that users of social media websites should have the option of paying to maintain their privacy. Google was used as an example of where privacy was an afterthought in its design. Cindy Cohn  stated that during early discussions with Google about new library of books, the company was building the service and that consumer privacy concerns and requirements would be assessed and configured after initial development was completed.  Cohn argued that is a flawed development process.

Contracts do not correlate to Terms of Service, Intellectual property rights and how user patterns suggest that they often ignore copyright owners through intentional ignorance and not the lack of understanding. EFF’s panel argues that application architecture and designers of applications and websites do not build services from the ground up with these issues as cornerstones of their business.

Several attempts to correlate standards, security of applications and websites have tried in the past, all of which have failed. With the Internet now exploding across broadband wireline and wireless network capabilities, the security issues will have to be addressed. White House Cybersecurity Director Howard Schmidt will have to review these concerns. There’s no way to manage internet users outside of the United States. There is the possibility to monitor international sources of users and their habits. That may be one of the things the U.S. government will have to review as next steps in security and privacy exploitation of U.S. Internet users. One of the issues with this approach is legal implications - which the EFF did not address.

The FCC National Broadband Plan touches on some of the concerns addressed by the EFF but does not include a plan for enforcement or regulatory authority over such issues. The USITC and FTC will likely be the agencies burdened with what laws the U.S. Government will adhere to with security and intellectual property as ACTA negotiations come to a close. ICANN may also be an avenue that enables neutral network policy management with respects to certificate authorities and assurance of their validity.

The EFF has some valid points and concerns. The world of software programming, coding and engineering has never been concentric around consumer standards, law or privacy, except when it applies to software code. The EFF believes it is long overdue and they maybe right.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Disclosure

Doug Hanchard

http://government.zdnet.com/?page_id=5774

Biography

Doug Hanchard

Doug is the principal of Rapid Response Consulting, an advisory group that integrates ICT solutions. He has worked at some of the largest telecommunications firms in Canada, including Bell Canada, Telus and AT&T and is a guest lecturer for several universities and associations. He serves on several advisory boards in Canada and the United States.

Starting with a new national ISP in 1993 in sales, positioning internet access, web sites and network services began the path of telecommunications technologies from the early Bulletin Board Services (BBS) to the first web pages for commercial clients.

Became the National Data Network Service Manager for Frame Relay and Internet access for AccTel Enterprises which was acquired (after 3 mergers already) by AT&T Canada. Interested in how marketing could expand service availability, he moved to Telus to become the Frame Relay / ATM Product Manager and expanded the network across Canada. In 2002 he went to Bell Canada becoming a Solution Architect to get back to his passion for technology working with enterprise clients. In 2006, became the Director of R&D and Senior Solution Architect for Bell Canada Security Solutions Inc, developing I.P. based physical and logical security platforms and ICT services.

This position created new commercial concepts such as Crisis and Disaster technology solutions required for emergency use after an event occurred. He designed interoperable technologies and application combinations allowing any to any I.P. service through landline, broadband, satellite and wireless technologies to be deployed anywhere

1
Comments

Join the conversation!

0 Votes
+ -
Great!!! thanks for sharing this information to us!
seslisohbet seslichat

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix