Google Search

Showing posts with label ordered. Show all posts
Showing posts with label ordered. Show all posts

Thursday, March 21, 2013

Twitter ordered to unmask hate speakers

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Twitter logoMonths after hate speech was taken down from Twitter, a French court has ordered the company to hand over details of users who posted anti-Semitic content.

The court, in Paris, issued the order on Thursday in response to a request from the French Jewish students' union (UEJF) and others.

According to Le Monde, Twitter has 15 days following service of the order to unmask users.

If it fails to do so, it will be subject to fines of €1,000 (£850/$1,346) per day.

Twitter has refrained from commenting beyond telling news outlets that it's studying the decision.

Le Monde in October published this collection of anti-semitic jokes on Twitter, after the tag #UnBonJuif (a good Jew) started to make waves.

Other Twitter tags associated with hate speech that have been making the rounds in France include #SiMonFilsEstGay (if my son is gay) and #SiMaFilleRamèneUnNoir (if my daughter brings home a black guy).

Twitter deactivated the accounts in question in October.

In the US, hate speech is protected by the First Amendment unless it incites violence.

In countries such as France and Germany, however, laws ban hate speech.

As IT Pro Portal describes, that conundrum led Twitter to announce, a year ago, that it would block tweets whose content was restricted by certain countries.

Twitter first blocked content in October, suspending access to an account run by a neo-Nazi group in Germany.

Hooded person, courtesy of ShutterstockTwitter in general has resisted handing over users' details, but courts have forced its hand: once when New York authorities got a court order for data about a user who threatened to kill people at a Manhattan theater, and again in September, when it turned over the tweets of an Occupy Wall Street protester.

As IT Pro Portal reports, a lawyer for Twitter earlier this month pointed to the company's US location as being a sticking point in forcing it to hand over data. Since the data is collected in the US, the French order should be authorised by a US judge, the lawyer said.

The French court disagreed, responding that the US's First Amendment protection doesn't apply in France.

Twitter will likely be brought to its knees again in this case, forced to take away the anonymity that's cloaked people who publish pretty vile content.

It's a good reminder that that invisibility cloak is illusory. It can be shredded by court dictate.

That invisibility cloak can also be stripped by the content platform itself.

Take Google as an example: In June 2012, it started to nudge users toward real-name usage on YouTube.

What's now merely a polite request could well blossom into a requirement as Google attempts to drain what is now a racist, ignorant, creepy, underage, psychotic, incoherent and/or homophobic swamp.

Therefore, it only makes sense to spout hatred if you truly believe that it's worth saying so publicly, and if you believe in such statements so sincerely, that law-ordered punishments aren't enough to dissuade you.

Are these demands for transparency an erosion of individuals' online privacy?

Sure. But that's the trade-off for not having cowards protected by cloaks of anonymity behind which they can safely hurl trash.

Follow @LisaVaas
Follow @NakedSecurity

Hooded person image courtesy of Shutterstock


View the original article here

Monday, September 24, 2012

Android SMS malware firm fined £50,000 and ordered to refund victims

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Mobile phone money. Image from ShutterstockBack in February, a SophosLabs researcher Vanja Svajcer discussed how he had discovered a malicious link on Facebook that led to malware being downloaded onto his Android smartphone.

Svajcer analysed the malware, adding detection for it as Andr/Opfake-C, and discovered that while posing as a conduit to popular games, it was coded to send an SMS message which subscribed the phone to an expensive premium rate service.

He even made a very short video of the malware automatically downloading to his Android phone.

(Enjoy this video? Check out more on the SophosLabs YouTube channel.)

Normally, the story stops there. We find malware, we stop malware. The end.

But this time, there's more to report.

Spurred by Naked Security's report of the malware, and complaints from the public, PhonepayPlus - the regulatory body for all premium rate phone-paid services in the United Kingdom - investigated who was hiding behind the phone numbers.

PhonepayPlus also confirmed the app's behaviour:

The Service, which was accessed via downloading an app (the "App"), enabled users to access popular games. Before installation of the App, consumers were presented with a screen titled "Downloader" (Appendix A). On selecting "install" the consumer was presented with a screen which stated, "Do you agree with the rules of downloading" and had two buttons, one marked “OK” and a second marked "Rules" (Appendix B).

Where a consumer selected "OK", a text message was sent to shortcode 80079, which prompted the Service to charge the user £10 by automatically sending a message from shortcode 79555 to the handset. Where a consumer selected "Rules", s/he was presented with eight pages of terms and conditions (Appendix C). Pricing information for UK users was located on the sixth page.

Consumers were given the opportunity to select buttons marked "Agree" or "Disagree". Where "Agree" was selected, a text message was sent to shortcode 80079, which prompted the Service to charge the user £10 by automatically sending a message from shortcode 79555 to the handset. The Executive took the view that consumers were not notified in advance of the charges.

After being charged, the consumer was redirected to the 7mobi.net "GamePortal", where s/he could play popular games.

Android app

PhonepayPlus discovered that the premium rate numbers used by the malware belonged to Moscow-based firm ??? ???????? (translated as Connect Ltd trading as SMSBill), and adjudicated that the company had made "very serious" breaches of the PhonepayPlus Code of Practice.

For one thing, the app's small print (hidden away on the 6th page of the terms and conditions) claimed that charges of "about 5 GBP" were applicable. And yet, the true charge was £10.

Anyone who did go to the effort of reading the T&Cs would not only be told that the fee was less than it actually was, but would also be assured that they would be notified before incurring any charges (they weren't).

PhonepayPlus said that the service provided by the Android app "had the sole purpose of generating high revenue and did so through recklessly misleading promotion and design."

Connect Ltd was also criticised for appearing "to have no regard to the Code and/or Guidance", and failure to co-operate with the investigation in a prompt or adequate manner.

In total, consumers are said to have spent some £100,000 - £250,000 on the service, although it is unclear how much revenue Connect Ltd themselves made.

Old phonePhonepayPlus has ordered Connect Ltd to pay a fine of £50,000 and refund - within three months - all consumers who used the service, whether or not they have claimed a refund.

Additionally, for the next two years Connect Ltd will have to receive prior permission from PhonepayPlus for any premium rate services it attempts to offer in the UK.

Some might wonder if Moscow-based Connect Ltd might be tempted to ignore the penalties imposed on it from the UK, but PhonepayPlus spokesman James McLarin was bullish.

McLarin told Naked Security that PhonepayPlus expects the fines to be paid and that the refund will take place:

"If our sanctions are not met we do have the power to bring a breach of sanction case, where the tribunal can impose tough penalties."

The sending of expensive SMS messages is one of the most common ways in which smartphone malware attempts to earn revenue from its victims.

Always be careful about what apps you install, and - in the case of Android apps - be sure to check that you are happy with the permissions the app requests at installation.

If you haven't already done so, you may consider installing Sophos's free anti-virus for Android to detect Opfake-C and other Android malware.

Follow @gcluley

Phone with money image from Shutterstock.


View the original article here