Mar 01 2011

Schneier on Anonymous vs HBGary

Tag: (i)realidad,Informática Legal — Joaquim Anguas @ 9:27 am

Or was it ArsTechnica?
Anyway…


Feb 26 2011

The end of the saga?

Tag: Informática Legal — Joaquim Anguas @ 8:02 pm

Thousands of unnamed “John Does” in P2P file sharing lawsuits filed in California, Washington DC, Texas, and West Virginia have been severed, effectively dismissing over 40,000 defendants. The plaintiffs in these cases must now re-file against almost all of the Does individually rather than suing them en mass. These rulings may have a significant impact on the copyright trolls’ business model, which relies on being able to sue thousands of Does at once with a minimum of administrative expense. The cost of filing suit against each Doe may prove prohibitively expensive to plaintiffs’ attorneys who are primarily interested in extracting quick, low-hassle settlements.

See also:
On the menu for today: Motion to quash
Economies of scale
News on 873
Single action, multiple defendants and the power of self interest>

Vía:
EFF


Feb 24 2011

cloud based computer forensics pipeline

Tag: Informática Legal — Joaquim Anguas @ 9:55 am

In a scenario in which there’s a need for flexible computing power for certain companies offering services in the computer forensics arena, cloud computing appears to be a model ready to offer value.

Amazon offers a set of services that may support the needs for flexible computing power a full «ingest/digest» analysis pipeline may need.

Continue reading «cloud based computer forensics pipeline»


Feb 22 2011

Block Size Matters

Tag: Informática Legal — Joaquim Anguas @ 9:15 pm

There’s an ongoing debate regarding the role of the public “trust” when performing an HDD cloning action.

What does a notary or a judicial clerk add to the action? And regarding the tools, is it better to use a single purpose device as a cloning machine or a multi-purpose one as a laptop computer?

In my humble opinion both the cloning machine and the notary/judicial clerk don’t add much more in a technical sense, but in fact they create an scenario in which it is less likely that the part that suffers the action will attack it in court.

As the time that takes to complete the action may be important, performance may be a factor in the decision, and here’s where the tittle comes in.

For some time now I’ve been experimenting with different means to acquire forensically sound disk images. The cloning machine I use is an Intelligent Computer Solutions Image MASSter Solo-3 Forensics. It can deliver 2,5GBpm when hashing SHA1 on SATA 7.200 drives. This means close to 7 hours for a 1TB drive…

I prefer to use the cloning machine when I perform the cloning procedure in court or with the intervention of a notary. When cloning big disks, I try to get the room locked while the copy is being performed and get back the next day to see the result.

But in other cases you may consider the following performance results the next time you need to perform a disk image:

  • No hash 1.080GB/h
  • MD5 923GB/h
  • SHA1 923GB/h

So, what if instead of almost 7h you could perform a complete clone of a 1TB HDD in a bit more than 1h?

Enter the “poor’s man cloning machine”…

Continue reading «Block Size Matters»


Feb 17 2011

history repeating…

Tag: (i)realidad — Joaquim Anguas @ 5:34 pm

This looks familiar to me:

As with previous seizures, ICE convinced a District Court judge to sign a seizure warrant, and then contacted the domain registries to point the domains in question to a server that hosts the warning message. However, somewhere in this process a mistake was made and as a result the domain of a large DNS service provider was seized.

The domain in question is mooo.com, which belongs to the DNS provider FreeDNS. It is the most popular shared domain at afraid.org and as a result of the authorities’ actions a massive 84,000 subdomains were wrongfully seized as well. All sites were redirected to the banner below.

…

A noble initiative, but one that went wrong, badly. The above failure again shows that the seizure process is a flawed one, as has been shown several times before in earlier copyright infringement sweeps. If the Government would only allow for due process to take place, this and other mistakes wouldn’t have been made.

Via https://torrentfreak.com/u-s-government-shuts-down-84000-websites-by-mistake-110216/.

See also https://www.dhs.gov/ynews/releases/pr_1297804574965.shtm.


Feb 15 2011

Risky Business

Tag: (i)realidad — Joaquim Anguas @ 6:25 pm

Short
https://www.boingboing.net/2011/02/15/the-implosion-of-sec.html

Long

+

https://arstechnica.com/tech-policy/news/2011/02/the-ridiculous-plan-to-attack-wikileaks.ars

Longer

+

https://www.ft.com/cms/s/0/87dc140e-3099-11e0-9de3-00144feabdc0.html#axzz1E3621iOg (registration needed)
https://arstechnica.com/tech-policy/news/2011/02/how-one-security-firm-tracked-anonymousand-paid-a-heavy-price.ars
https://arstechnica.com/tech-policy/news/2011/02/virtually-face-to-face-when-aaron-barr-met-anonymous.ars
https://www.salon.com/news/opinion/glenn_greenwald/2011/02/11/campaigns/index.html
https://krebsonsecurity.com/2011/02/hbgary-federal-hacked-by-anonymous/

Uptade

https://arstechnica.com/tech-policy/news/2011/02/anonymous-vs-hbgary-the-aftermath.ars

https://www.hbgary.com/
https://www.bericotechnologies.com/
https://www.palantirtech.com/
https://www.hunton.com/


Dic 28 2010

the leaking society

Tag: (i)realidad,01 — Joaquim Anguas @ 1:33 pm

The general model behind Wikileaks comprises:

  • A system that allows someone (the leaker) to release information to an organization (receiving organization) leaving no traces that lead to him. As a variation, the possible traces may be in the only possession of the receiving organization. In this case the organization either guarantees to keep them secret or destroy them effectively. At last it is a matter of trust: if the leaker trusts the system behind the receiving organization, he will relase the information. Otherwise, he will not.
  • A receiving organization that receives the so called “leaks”, verifies and evaluates them and evacuates them to the public or to some other organizations for publishing (publishing organizations).
  • In case there are publishing organizations involved, they add some context to the leaks and publish them to the public.

Today there are entities working by this model other than Wikileaks which, at least by now, haven’t attracted (much) public attention to them.

All these organizations have had some permeability within their workforce, they share some of the procedures, general systems and tools they use to achieve their goals.

At this point of time most look at the actual scenario these entities draw. Fewer look forward to future scenarios. When they do, most of the attention goes towards the implications in the specific field where they are being used in: international relations and, laterally, journalism.

But once the systems are in place and have proved to be effective (in the case of Wikileaks, the person who is held responsible exposed himself, it was not because of a failure in the system), why should them be kept bound to secrets related to diplomacy?

Once they spread (and they will), why not use them to reveal administration’s misbehaviors?

And why not use them to report the (naughty) private life of famous people or VIPs?

Or to circulate the life of your neighbor, at least?

I bet there’s a market for that…

We’ll see…


Dic 24 2010

The emotional computer

Tag: (i)realidad,01 — Joaquim Anguas @ 3:07 pm

By analyzing faces, gestures, and tone of voice, it is hoped that machines could be made to be more helpful (hell, we’d settle for «less frustrating»).

From IEEE Spectrum via engadget.


Dic 23 2010

The year in 3D printing

Tag: (i)realidad — Joaquim Anguas @ 4:54 pm

3D Printing

Via boingboing.


Dic 21 2010

DDoS

Tag: (i)realidad,01 — Joaquim Anguas @ 11:19 am

Our research suggests that:

  • DDoS attacks against independent media and human rights sites have been common in the past year, even outside of elections, protests, and military operations. With recent highly publicized DDoS attacks on Wikileaks, and «Operation Payback» attacks by «Anonymous» on sites perceived to oppose Wikileaks, we expect these attacks to become more common.»

2010 Report on Distributed Denial of Service (DDoS) Attacks.

Via boingboing.


« Página anterior — Página siguiente »