Tuesday, April 28, 2009

Digital Death Penalty and the future of civil rights

There's quite some shakeup happening in the european lawmaking. A massive attack on civil rights is being pushed through by copyright enforcement entities. Trials such against the Pirate-Bay are showing that the fine line of hosting content or having a link to a content is not understood by low level judges. This would mean google could be sued for anything illegal you could find over it. And there's always something to be found. So google should be banned. Would that make sense to you? To me it doesn't but exactly those rules where used against the Pirate Bay.

But there's more changes happening. The Cybercrime convention as I wrote in my last blog entry is a time bomb which will go off at some point if not acted upon as well.

And the french are trying to run the 3 strikes rule for file sharer. This means if you get cought 3 times doing illegal filesharing, you will be disconnected from the internet. No questions asked.

Now at first this makes some sense. Remove the person the ability to do something illegal. Similar to take someone's weapon away so he can not do harm with it. But there is one thing which is getting forgotten. The internet for a "filesharer" is not just a tool to do filesharing. It has become a necessity of life. You can not send/receive emails without internet. You can in some cases not follow your public rights. In some cases its used for governmental use. So someone who can no longer access the internet is basically loosing a lot of civil rights. Think 20 years down the road. We might vote for presidents over the internet. Someone who had done something stupid in his childhood will still be banned from the net and can not participate. Even today, electronic banking rules everywhere. I predict in 2 years time you might no longer be able to pay your bills over the counter, or at least not without big problems and/or costs.

Now think about the 3 strikes rule again. This filesharer who has violated copyright 3 times when he was maybe 18 years old is now 40. He can not pay any bills electronically, he can not vote, he can not learn. This is what some people call the "Digital Death Penalty".

Is this penalty really the correct way to handle this?

Now to make the case a bit worse, the french president Sarcosy thinks it's ok to block access to "unlawful" internet content without a prior ruling by the judicial authorities. (see http://www.laquadrature.net/wiki/Campaign-Save_amendment_138_and_Internet_Freedom_from_Council_of_EU).

Now think again. I open a book publishing company tomorrow. And because I hate my neighbor, I will just blindly accusing him, he is sharing copies of my books. No judge needed, he gets blocked. I do this 3 times and he would be punished for life.

Even though this sounds like a far away example, you can imagine what powerful companies like the IFPI would do just because they think you have done something bad to them by pointing a URL to a file hosted by someone else. They could basically make you dissapear from the digital life. In my personal case, this would mean loosing my job 100%, loosing all my income with no ability to ever work inside the business.

Can this be right?

And a last thing is threatening Europe. Privacy in the internet is being melting down. Politicians in germany are using the "child pornography theme" to show that there is a major issue in the internet and that we need mechanisms to ban websites. They believe every ISP must install devices which support blocking websites. While everyone agrees that child pornography is bad and should be punished, some politicians think that blocking the access to the websites solves the problem. But its not. A list of blocked sites from Australia have shown that the sites they have blocked there have been still alive for months. A german newspaper has tried to fix this and has called the ISP in USA to find out what's the status. The site dissapeared within hours. So if its so easy to bring down childporn websites (and believe me the US police will prosecute such cases quickly), why to install all those devices to block access to sites which then can be so easy get around? Just to push to sell the boxes can not be the reason. The real reason is somewhere else. It gives the government the ability to block anything they dont want anyone to see. It gives them a tool to bypass juristical procedures. The example from Australia also has shown that one dentists website was on the blocking list. Why? because someone has hacked his computer. This problem was fixed long ago but he still resided on the blocking list. Why? Because no one told him he was on this list. So he got punished twice. He had to reformat his computer and reinstall everything and then no one could look at his website without him knowing that's the case. And he had no way of appealing to any decision.

What does this say to us? There are industries who do heavyweight lobbying to establish laws which allow to block any content someone likes without even a judge looking at it. Laws to bring down filesharers without a judge looking into it and to permanently ban them. Laws to enforce blocking devices, laws to make sure privacy is no longer existing in the internet so the potentially bad guys can be punished in advance.

In other words, the old fashioned music industry who is loosing its business is trying to convince us that its correct to leave child porn websites alone and instead use censorship to control our universe. They apparently have the money to pay expensive attorneys, to pay politicians and even french presidents to vote in their sense.

Just because they have the wrong business model we should pay this bill?

No. Stand up and make your voice heard.

To remind you what is at stake:

Fundamental Rights of the European Union, Art. 11

the right to “receive and impart information and ideas without interference by public authority".

Thursday, April 16, 2009

Cybercrime Convention

Switzerland has signed the cybercrime convention. Now its time to put it into applicable law. But this seems to be very tricky. Several IT and ISP's and telecommunications companies are objecting those changes for a good reason.

The issue is the new rule about hacking tools (see previous posts).

I have uploaded our detailed answer (in german) on to
http://www.bebbicell.ch/cyber-crime-convention-response.pdf

Wednesday, March 18, 2009

Apple's view of the world

Here's Apple's view of the world. They are so proud that they have 80 countries offering the iPhone that they painted the world red. The map above however is missing Greenland and Iceland. It simply doesn't look that nice to have two big white spots in the middle of USA and Europe showing that Apple doesn't have world domination yet.

Tuesday, March 17, 2009

CyberCrime and the wrong way to bring it down

The swiss federal adminsitration wants to change the law about cyber crime.

See also:

http://www.admin.ch/ch/d/gg/pc/pendent.html#EJPD
(or especially Genehmigung und Umsetzung des Übereinkommens des Europarates über die Cyberkriminalität )

I think this new proposed law includes some dynamite in the details

First of all: I think its time for the government to face the fact that there are many open ends (like the discussion we had with the order from Canton de Vaud). My biggest issue with facing CyberCrime is however that not the law is the issue but the ability of the police force to enforce the law. Mainly due to lack of knowledge and probably financial resources. CyberCrime is happening every day and is happening Quick. The processes on police work where maybe accurate 1960 but lack the needed speed of todays events. I had two incidents in my own company where it has clearly shown that the police has not the slightest clue what's happening on the internet, besides how to fix the issue. Costed me a hell of a lot of money at the end even it was a crystal clear case for me (as a techie...). But I must admit its not the fault of the law, its the fault of the execution of the law and the financial resources needed to follow those cases. That's the real problem. If it takes 6 months to get police help from another country, it will take 6 months to stop the spammer. Well the spammer is changing its servers daily. So what does that help? Anyway...

The law above however has a section which I think is dangerous and could affect our work:

Das materielle Strafrecht mit seinen am 1. Januar 1995 in Kraft getretenen Bestim-
mungen im Bereich "Computerstrafrecht" vermag den Erfordernissen der Konventi-
on über weite Strecken zu genügen. Anpassungsbedarf ergibt sich bezüglich des
Straftatbestandes des unbefugten Eindringens in ein Datenverarbeitungssystem (Art.
143bis des Strafgesetzbuches, sog. "Hacking"-Tatbestand). Hier wird vorgeschlagen,
eine Vorverlagerung der Strafbarkeit vorzunehmen: Strafbar soll sich auch machen,
wer Programme oder Daten zugänglich macht im Wissen, dass diese für das illegale
Eindringen in ein Computersystem verwendet werden sollen. Daneben wird, ausser-
halb der Erfordernisse gemäss Konvention, vorgeschlagen, das durch die Lehre
verbreitet kritisierte Merkmal der fehlenden Bereicherungsabsicht in Artikel 143bis
StGB zu streichen.

Now what does that mean? It is basically what the germans have done under the term "Hackerparagraph". It disallows software which could potentially be used for hacking to be distributed. The result of this was for example that in germany the WiFi tools to verify your WiFi security dissapeared. Why? because someone could use it for hacking. If you think this a bit further, you could use a C compiler to write a hacker tool, so the compiler could be considered a tool to do hacking and we all very well know know someone can write hacking tools in C. So to bring this ad absurdum, it could theoretically forbid us to distribute a C compiler. Or think about Linux with all the built in tools.

Of course this is a bit far reached but there are many gray zones in between. For example I use Wireshark, a great open source packet analyzer for my daily work because I develop network protocols. So I use it to verify my own written network protocols for accuracy or use it for troubleshooting on other networks. Of course someone could use this for hacking to listen to passwords in cleartext (for example from old POP3 accounts). So if the new law passes and we publish a wireshark version on our server, we become criminal?

The result will be that security tools to verify your security will be forbidden. You will not be able to verify if your machine is crackable or not. The real bad boys out there (and I'm not saying a hacker is a bad boy by definition because most are honest and more in the area of security researcher than anything else) will not give a dam if they are allowed to distribute this hacking software (they just use it anyway) because they per definition want to commit crime. So they will get hold of that software and just use it. And because no one was able to verify if POP3 cleartext passwords are floating on your LAN, they will find it out for you but they will not help you to make your computer network a more secure world, they will simply abuse it to send spam, to take money from your bank account or whatever they want.

So the normal end user is getting tools removed to help fight crime. This is helping the bad boys instead of keeping them out. Its like saying, you are not allowed to encrypt to protect your privacy simply because some bad boys encrypt to protect their evil plans.


The report from the EJPD was clearly written by lawyers, people who do not understand the technological impact of such laws. And thats why I think its pretty dangerous.

I think we should respond to this proposal to keep above paragraph out of the law. Otherwise we wouldn't even be able to help the police if they are investigating because the tools to do this are also used by hackers sometimes.

Here is what I got first from EJPD.

----------- snip ----------
Ihre Kommentare sind willkommen. Sie finden die Unterlagen unter http://www.admin.ch/ch/d/gg/pc/pendent.html#EJPD (Geschäfte EJPD: Cybercrime). Das Verfahren läuft bis 30. Juni 2009.

----------- snip ----------

There's also contact details on that URL there.


So feel free to make your voice heard or remain silent forever.

Saturday, January 10, 2009

Exclusive fonts...


Printing twice in a Windows app revealed above error message. It apparently has exclusive rights about the font somehow. Is it trying to modify it on the fly maybe?

Monday, January 5, 2009

Virtually inexistant support



Edit: this problem has been fixed in VMWare 2.0.2. Now even 10.6 beta boots.

I own VMWare fusion 2.0.1. I use it on a MacOS X Server (XServe) to sometimes run Windows XP if I have to. But I also use it to try new stuff out in a "protected" environment. So I have a MacOS X Server instance running inside a VMWare Fusion virtual instance. I recently updated VMWare to 2.0.1 and MacOS X to 10.5.6. VMWare tells me that I should update VMWare tools inside the virtual machine for optimal performance. So I did. This is a BAD IDEA. MacOS X Server guest operating system didn't boot anymore after that.

So I reinstalled MacOS X Server 10.5.1 from CD, updated all the Apple updates to 10.5.6 again and VMWare tools again. Same problem. Locked up totally.

Clearly an issue for VMWare's support as its smells like a BIG FAT BUG.

So go to the website, click on support, you end up searching a database of similar cases. MacOS X Server is not found anywhere in there. So continue to register a support case. But oh-oh, you only get free support for 30 days. Well, ok I got to spend a few bucks. But no I can't. You try to log into the store and you get PAGE NOT FOUND. Sending a "comment" to the website triggers an email back after 30 minutes with the correct URL. Great now I'm able to waste my money in the shop and get a serial number for support. What now?

The confirming mail says you should register your product. So you click on it and what you get? Product registered. That's it. Now you log into support again and you get:



Well after quitting and restarting the webbrowser or force reload you can get past this. Now then you see I have an expired license. No mentioning of my registered pay per incident item. so what now? Well there is a item saying in emergency cases call this number. As this is my very last option, I call long distance across the atlantic.

"Welcome to VMware blabla, for VMWare Fusion, press #". I press #. "For VMWare Fusion issues please go to www.vmware.com .....". Great. Infinite loop.

Calling in again with NO OPTIONS selected. I end up on a human. GREAT. He can find my support license number but it says the license number I bought TODAY is already expired. He can not open a case due to that and wants to pass me on to the Licensing department to fix this. I get transferred and the call gets dropped.

I call again, "Welcome to VMware blabla, for VMWare Fusion, press #"... for Licensing issues and other stuff press 1. So I end up on another person. "Ah Fusion, please wait"... "Welcome to VMware blabla, for VMWare Fusion, press #". but now there's no option to wait. After 30 seconds "Please make a selection NOW"... and then "Welcome to VMware blabla, for VMWare Fusion, press #".

I call again and I end up on the same techie. He now figured out how to file my one time to support number and directs me through the website (including "not found" and all the issues again) I end up on a page to now file my support issues in a webform. He can not help me by phone. Its web / email support only (so why pay the bucks for commercial support if you dont even get phone support, but that's another story). So I successfully filed a request. HURRAY.

He also suggested to use VMWare Community. And there's an option from the support request page to go there so I do. I have to register AGAIN, now for the VMWare community (others call it forum but what the heck). Of course my usual username is taken and the webform only says that it can not register and brabbles some ununderstandable error. After picking another username I ended up on the forum. So I want to do a new post. Then I get this:




Going to the main page and go on to the community tab reveals this:



So I click on LOGIN (top left or the big fat button in the middle). This brings you to this page:



Fun, isn't it.

Getting nowhere, I decided to add those screenshoots to the support incident. But what do I get there:



and I also realized my phone number has changed:



To recap:
I spent about 1 hour of work, 29$ in wasted incident support, 3 international calls on a simple issue I'm sure the right techie could answer or fix in 1 minute.
The community can't help because you are not able to log in, the stuff is so carefully hidden in the website that no one can find it.

And after all this: my problem is still not fixed.

Well what options do we have? Unfortunately the competitor Parallels is worse. My Parallels Server actually freezes and after 2 months waiting, I have given up on them.

Conclusion: don't try to run virtualisation whatsoever on MacOS X on a server. Just don't even try. Boot camp is the only way (now I could start writing about 2h on how many countless hours it took me to get Vista running properly on my MacBook pro but I save this for another time).

Thursday, January 1, 2009

Windows Alert



What kind of question is this?? Yes I want to copy or Yes I want to move?
I have choice A or B but my options are yes or no...

Happened under Windows XP when moving a file from a ZIP to the desktop