February 2013

HTC America Settles FTC Charges It Failed to Secure Millions of Mobile Devices Shipped to Consumers

Mobile device manufacturer HTC America has agreed to settle Federal Trade Commission charges that the company failed to take reasonable steps to secure the software it developed for its smartphones and tablet computers, introducing security flaws that placed sensitive information about millions of consumers at risk.

The settlement requires HTC America to develop and release software patches to fix vulnerabilities found in millions of HTC devices. In addition, the settlement requires HTC America to establish a comprehensive security program designed to address security risks during the development of HTC devices and to undergo independent security assessments every other year for the next 20 years. The settlement not only requires the establishment of a comprehensive security program, but also prohibits HTC America from making any false or misleading statements about the security and privacy of consumers’ data on HTC devices. HTC America and its network operator partners are also in the process of deploying the security patches required by the settlement to consumers’ devices. Many consumers have already received the required security updates. The FTC encourages consumers to apply the updates as soon as possible.

Device Squad: The story behind the FTC's first case against a mobile device maker

Where did HTC go wrong? The company didn’t design its products with security in mind.

For example, HTC didn’t test the software on its mobile devices for potential security vulnerabilities, didn’t follow commonly accepted secure coding practices, and didn’t even respond when warned about flaws in its devices. As a result, in the process of customizing its products, HTC introduced numerous security vulnerabilities that malicious apps could exploit to gain access to sensitive data and compromise how the device worked.

Should Companies Tell Us When They Get Hacked?

The New York Times Company and others have come forward in recent weeks to say that they were hacked. Although hacking is common, it’s rare for companies to talk about it — even though doing so could warn customers about compromised data, or alert other businesses to a particular threat. Should companies be required to disclose security breaches?

European Decision on Google Antitrust Pushed to the End of Summer

Thought that whole Google antitrust brouhaha was over? It’s really not. The European Union is now saying in the vaguest of terms that August or later is “a possible deadline.”

“We can reach an agreement after the summer break. We can envisage this as a possible deadline,” European Commission head of competition Joaquin Almunia said. The slow turnaround comes as a bit of a surprise after Almunia had put pressure on Google to submit its proposed remedies to concerns about anticompetitive actions in search and advertising by the end of January — which the company did. But it’s really not that shocking after repeated lags in the European antitrust investigation of the company, which started way back in 2010.

New video games mirror debates about data privacy, hacking

A man shuffles down the street, phone in hand. He appears to be reading a message, but in fact he’s hacking into city computer systems and peering into the pockets of passersby — flicking through their bank accounts, government records and personal details. This kind of nightmare scenario is the feature of a new video game called ‘Watch Dogs,’ one of a number of new video game titles that put the player in the role of the passing hacker. Hacking and cyber warfare are not new themes for video game makers. But new titles that center on constant data threats and government surveillance are resonating now because they hit a little too close to home.

Thirst app creates your 'personal newspaper'

Most news apps known for aggregating stories require the user to plug in their sources and watch the content flow. The iOS app Thirst takes a different approach, using your Twitter feed to deliver stories and other content you want to read, all packaged in a sleek and elegant design.

Policymaking in a Time of Technology Transitions

Technological transitions do not change the values Congress codified in the Communications Act and the Federal Communications Commission remains committed to advancing a set of core principles rooted in those values:

  1. Competition. Over the last two decades, we've moved from monopoly toward competition in many areas of the communications market, a hugely positive trend. Take voice service: Today, most consumers and businesses have several options to choose from, including their local phone company, a cable company, multiple wireless providers, and Internet providers like Vonage and Skype. These choices exist because of massive private investment, and because of policies that created and maintain the conditions necessary for competition to flourish, including rules to ensure interconnection; consumer roaming across mobile carriers; number portability; and Internet openness, so broadband providers can't block competing voice apps and services. Still, competition challenges remain. For example, for robust residential broadband with no or high monthly usage limits, most consumers today have only one or two choices. Some have suggested that an all-Internet Protocol communications market will necessarily be robustly competitive -- "Deregulate for a competitive, all-IP world!" would be the bumper sticker -- eliminating the need for FCC policies to foster and protect competition. But basic economics and the facts on the ground show that's simply not true. Technological change brings great benefits, but it doesn't automatically bring vibrant competition, particularly in high-fixed-cost, network-effects-driven market segments. At the same time, it's also not true that all legacy regulations remain appropriate for promoting competition in today's marketplace. We must take a nuanced, data-driven approach to determining which policies to keep, which to eliminate, and which to add or modify.
  2. Universal service and consumer protection. The U.S. largely succeeded in connecting all Americans to the dominant communications platform of the 20th century -- the telephone network -- and used a number of policies to protect and empower telephone consumers. In the 21st century, universal service and consumer protection remain vital goals. But we will not meet these goals, no matter how fast technology transitions proceed, without modern policies like the 21st Century Communications and Video Accessibility Act of 2010, the Connect America Fund, and the Mobility Fund.
  3. Public safety. Ongoing technology transitions promise to substantially improve public safety. For instance, 4G LTE and next generation 911 can enable first responders to access data, video, and images in ways that will help them save lives. At the same time, technology transitions present new risks. Last year's major natural disasters highlighted the fact that, unlike copper, fiber networks do not have an independent source of power, which means consumers and businesses can lose access to 911 and other vital services during an emergency. And IP networks bring with them significant cybersecurity threats. Policies and industry standards need to evolve to ensure that the resiliency of our networks is not diminished as a result of technology transitions.

Rep Markey Leads in Race for Kerry Senate Seat

Former House Communications Subcommittee Chair Ed Markey (D-MA) is either slightly or comfortably ahead of his challenger for the Senate seat vacated by Secretary of State and former Senate Communications Subcommittee Chair John Kerry.

Rep Markey leads the primary race for Kerry's seat by seven percentage points, according to a new poll from noncommercial news station WBUR (FM) Boston, though that is still within the margin of error. That was according to a telephone survey conducted last week among 498 registered voters. It has a margin of error of 4.4 points.

Online Gambling Heats Up

The two big casino states, Nevada and New Jersey, are racing into online gambling as a way of protecting their turf.

They will in essence become laboratories for what is and is not feasible in Internet wagering. In the year since online poker became a theoretical possibility in Nevada, no company has yet offered it. One problem: It’s too small a market, especially in a state where it is not exactly hard to gamble the old-fashioned way. In a harbinger of the new age, gamblers at the Borgata casino in Atlantic City will, as USA Today put it, “be able to lose their shirts without wearing one.” Gamblers staying in one of the casino’s 2,000 rooms can now place their bets right there without venturing onto the casino floor. From there it is only a small step to just staying home and gambling from the hammock. Internet companies that make online games are watching all this with considerable interest.

What stays in Vegas: how Nevada’s online gambling law will — and won’t — change social gaming

Nevada became the first state in the country this week to allow online gambling with a new law that gives the green light to poker and other games. The new policy is significant in light of research that predicts online gambling will be worth $100 billion worldwide on mobile devices alone by 2017. This potential market has attracted the established casino industry as well as tech companies that are vying to make gambling games or process back-end betting operations. The law is intended to keep Nevada out in front of rival New Jersey but will not do much for social game makers like Zynga that are counting on gambling to change their fortunes. The Nevada only applies to internet users in the state. The law is also primarily intended not to help social gaming sites but to ensure that Vegas casinos have a first-mover advantage in providing operational support when — and if — other states follow suit.