Showing posts with label Electronic Frontier Foundation. Show all posts
Showing posts with label Electronic Frontier Foundation. Show all posts

Friday, 27 November 2015

EFF Wants Stronger Encryption Against Terrorists And Criminals



If the government were to ask people to remove the good locks on their doors and windows and replacing them worse so that government employees can penetrate more easily in case someone is a terrorist, no one would accept this because bad locks make everyone vulnerable.

Yet this is exactly what governments and law enforcement agencies in the case of encryption will, according to the American civil rights movement EFF. Regularly advocate agencies like the FBI to add backdoors in encryption, ensuring encrypted communication can still be tapped. This is similar to prevent people from getting access to good locks and locksmiths can produce good locks.

In this last example, most people would understand that this is not a wise idea, says Cindy Cohn of the EFF. However, when it comes to Internet and technology, such as the operation of encoding, which for many people is less clear. Parties such as the FBI and politicians would also have known better, says Cohn. "The answer to insecure networks and digital technologies must be correct in order to make them safer."

But that is not what is happening, so she continues. Policymakers are therefore urged to take this into account. "Ensuring that everyone's door is unlocked, is not the answer to crime or terrorism. That is the development and support of better security," Cohn decision.

Sunday, 1 March 2015

EFF: Install New Computer Ever Again

EFF

If you buy a new computer that must first install all over again, because the software that comes standard is not to be trusted. That secures the American civil rights movement EFF. Following are programs like Superfish and PrivDog who intercepted the SSL traffic of users to inject ads and thus users exposed themselves to all kinds of risks.

This week it was announced that next Superfish, standard on some Lenovo notebooks shipped, other programs intercepting SSL traffic. One of these programs was PrivDog . A vulnerability in certain versions of PrivDog caused the software each certificate which replaced the Internet came and intercepted by a self-signed certificate. Even though it was about certificates that were not valid in the first place.

The Decentralized SSL Observatory of the EFF, which gathers information from the HTTPS Everywhere plugin for Firefox, has collected more than 17,000 different certificates PrivDog users. "Each of these licenses may be an attack. Unfortunately there is no way to know this for sure" says Joseph Bonneau of the Electronic Frontier Foundation (EFF).

"So what have we learned from this Lenovo / Superfish / Komodia / PrivDog debacle? For users, we have learned that the software is pre-installed on your computer can not be trusted, which means that reinstalling a clean operating system standard now procedure must be if someone has bought a new computer, " said Bonneau. The main lesson, he says, for software companies, which must stop intercepting SSL traffic of their users.

Monday, 9 February 2015

EFF Also Not Happy With YouTube Without Flash Player


In late January announced that Google's now standard HTML5 for video playback, so users do not have Adobe Flash Player need more, but according to the American civil rights movement EFF this is not a victory or improvement for Internet users.

The Electronic Frontier Foundation (EFF) is also not in favor of Adobe Flash Player, which it describes as a closed technology where regular vulnerabilities are found in exposing millions of users to attack. Switching to HTML5 seems at first sight, therefore an improvement, but it is anything but that, late science fiction writer, journalist and blogger Cory Doctorow know.

The problem is that to play Youtube videos without Flash Player Encrypted Media Extension (EME) is used. According Doctorow a controversial technology that Apple, Microsoft and Google, after consultation with Netflix agreed upon. In the spring of 2013 decided the World Wide Web Consortium (W3C) is behind to rally the extension. Last May, Mozilla joined here. According to the browser developer would be no support for Netflix users lose other browser vendors. To the annoyance of Doctorow, who likens it to "destroy the village to save it."

In the case of YouTube is it now means that users without Adobe Flash Player to view videos. "As long as your browser supports the W3C version of Adobe's proprietary software," says Doctorow. Firefox Users can view all the Youtube videos without Flash, but will in some cases require standardized by W3C Encrypted Media Extension. But who uses proprietary software from Adobe, including Mozilla announced last year. According Doctorow is therefore ultimately nothing changed.