April 2014

EU votes network neutrality into law, abolishes mobile roaming charges

Blocking and throttling Internet traffic will become illegal in the European Union following a parliamentary vote on April 3.

Members of the European Parliament voted to close loopholes in a proposed law that some believed would have created a two-tier Internet. The so-called Telecoms Package originally described "specialized services," which would have allowed Internet service providers to charge more for more data-intensive content services such as voice over IP and streaming video. The package also abolishes roaming charges for mobile phone use in the EU. The law is expected to be ratified by member states by the end of the year.

Yahoo now encrypting traffic from its data centers, and plans to encrypt Messenger too

Yahoo is one of the many technology companies demanding reforms on US surveillance laws, and now says it has taken additional security measures to protect data it handles. The company announced that it has begun encrypting traffic from its data centers, and plans to add encryption to additional services like Yahoo Messenger.

That's on top of existing measures that let web users access secured versions of its various properties like Yahoo News, Sports, and Finance. "Hundreds of Yahoos have been working around the clock to provide a more secure experience for our users and we want to do even more moving forward," wrote Alex Stamos, Yahoo's chief information security officer. "Our goal is to encrypt our entire platform for all users at all time, by default." While Stamos did not specifically call out the National Security Agency by name, he made it clear that revelations about NSA spying led directly to Yahoo's move toward more encryption. "The impetus for the huge push is obviously government revelations," Stamos told reporters. "The side effect is that the protections we're putting in place protect in a lot of different scenarios."

State and Local Government Cybersecurity

Although much of the attention around the development and implementation of the Framework, and the implementation of President Barack Obama’s Executive Order on Improving Critical Infrastructure Cybersecurity (E.O. 13636) has focused on the private sector, our state, local, tribal, and territorial government stakeholders are critical partners in our overall drive to improve cybersecurity protections for the nation’s critical infrastructure.

These government entities operate critical infrastructure where cybersecurity protections can be increased, and they house considerable amounts of information about residents -- everything from driver’s licenses to school records that must be protected. These entities are also the first line of response when something goes wrong for our people -- individuals and local businesses that are the victims of cyber crime or malicious incidents in cyberspace are likely to reach out to their local law enforcement and related government agencies first for help. At the same time, these local governments present a complex landscape for cybersecurity: they vary widely in governance structure, technical connectivity, and resources available for securing systems and information. Navigate this complex yet important landscape requires a team effort. Recognizing that, the White House in March 2014 convened a broad array of stakeholders including government representatives, local-government-focused associations, private sector technology companies, and partners from multiple federal agencies at the Framework Kickoff Event, hosted at the National Cybersecurity Center of Excellence (NCCoE), a partnership among the National Institute of Standards and Technology (NIST), the State of Maryland, and Montgomery County. This event is part of the White House’s ongoing coordination and outreach in support of implementing the Cybersecurity Framework to discuss ways to help this community implement the Framework as a tool for improving cybersecurity. Over 100 cybersecurity and technology leaders attended the event in person, and nearly as many participated virtually via a webinar, representing entities from Hawaii to Michigan.

[Daniel is the White House Cybersecurity Coordinator]

The Autocrat-and-Mouse Censorship Game

[Commentary] The message to autocrats is clear: You can't block communications, or at least not for long. Technology moves too fast.

While censorship grows, the US is becoming less serious about ensuring a free Internet. The United Nations of Internet sounds like a really dumb idea. Autocrats will find it easier to limit access to politically undesirable content and make it harder, though not impossible, for citizens to bypass the censorship. Why would the US want to start another cat-and-mouse game? Private, parallel networks that are immune to censorship are being created out of a mesh of cheap Wi-Fi technology. These nodes, with about $100 of equipment, can be set up on rooftops around a city using solar power. Call it Wi-Fi without Borders. Or Packets of America. Whatever. Maybe practice on North Korea, and then Cuba. Show autocrats that the network is mightier than the sword.

[Kessler is a former hedge-fund manager]

Underscoring Commitment to Free and Open Internet, Subcommittee Continues Robust Oversight of Latest Administration Proposal

The House Subcommittee on Communications and Technology, chaired by Rep Greg Walden (R-OR), held a hearing on “Ensuring the Security, Stability, Resilience, and Freedom of the Global Internet.” Members sought answers regarding the Obama administration’s proposal instructing the International Corporation for Assigned Names and Numbers (ICANN) to explore ways to remove the United States from its oversight role of the Domain Name System and replace it with a different multistakeholder governance model.

Members expressed concern about any change that could leave the Internet vulnerable to power grabs from international governments and sought commitments that the administration would not permit any outcome that fails to protect the ideals of Internet freedom and openness. As part of their review, members also discussed H.R. 4342, the Domain Openness Through Continued Oversight Matters (DOTCOM) Act of 2014, legislation authored by Rep. John Shimkus (R-IL), which would direct the Government Accountability Office to study the proposed changes and present a non-partisan evaluation before NTIA is permitted to modify the current Domain Name System.

Rep Blackburn: President Obama hypocritical on Internet control

Rep Marsha Blackburn (R-TN) criticized the Obama Administration for praising a “multistakeholder” approach to Internet governance while pushing for rules that would place limits on Internet providers’ business models.

“We are not setting a good example,” Rep Blackburn, vice chairwoman of the House Commerce Committee, said during a hearing held by the House Commerce subcommittee on Technology. During the hearing, Rep Blackburn questioned how the Administration could push for Internet governance by global stakeholders through the Commerce Department while the Federal Communications Commission attempts to rewrite its network neutrality rules. Those rules kept Internet providers from slowing or blocking access to certain websites before they were struck down by a federal court in early 2014. The agency is in the process of rewriting those rules under a different legal justification.

ICANN chief: Russia, China will not hijack Internet oversight

Internet Corporation for Assigned Names and Numbers (ICANN) chief Fadi Chehadé defended the US government's move to cede oversight of the body, and downplayed concerns that Russia, China or other countries could exert control and restrict the web's openness. said the multi-stakeholder model -- with governments, the private sector and other interested parties reaching consensus with equal power -- will continue to restrain countries seeking to limiting the web's openness and freedom. "Everyone is focused on these three, four countries ... but in between we have 150 other countries that value the same values we do," Chehadé said in an interview after a congressional hearing. "Our commitment to the multi-stakeholder model is not so much for the few who do not believe in it, it should be to the great middle mass that would like to see us stand by it and they will stand with us. This is the bet we need to make."

Sens Thune, Rubio Demand Answers from Administration on Internet Transition

Sens John Thune (R-SD) and Marco Rubio (R-FL) and 33 of their Senate Republican colleagues sent a letter to Assistant Secretary of Commerce Larry Strickling, head of the National Telecommunications and Information Administration (NTIA), seeking clarification regarding the recent announcement that NTIA intends to relinquish responsibility of the Internet Assigned Numbers Authority (IANA) functions to the global multistakeholder community.

The letter expresses strong support for “the existing bottom-up, multistakeholder approach to the Internet governance,” and cautions: “We must not allow the IANA functions to fall under the control of repressive governments, America’s enemies, or unaccountable bureaucrats.”

The letter goes on to say: “The global community of Internet stakeholders should act deliberately and transparently as it formulates a possible proposal to transition the IANA functions to a nongovernmental entity. The multistakeholder model of Internet governance and the IANA functions are far too important for this process to be rushed or to be done behind closed doors.” Among other things, the letter asks the administration to “explain why it is in our national interest to transition the IANA functions,” and how NTIA will ensure “the IANA functions do not end up being controlled, directly or indirectly, by a government or inter-governmental entity.”

DHS Quietly Delivers Hacker Footprints To Industry

A little-known website sitting behind a firewall has been exchanging sensitive hack intelligence between companies and agencies at a rate of one new threat hallmark per hour, a top Homeland Security Department official said.

The Cybersecurity Information Sharing and Collaboration Program, launched in 2011, virtually convenes about 70 critical industry and analytics organizations – think energy companies -- as well as federal departments. The result is bulletins provided in formats that computers can "read" so they can apply the appropriate protections. And containment recommendations are pumped out in plain text that people can read.

"It enables us to identify those threats or organizations" that are a danger, said Roberta Stempfley, DHS acting assistant secretary of cybersecurity and communications. "We have shared through this program more than 26 unique indicators a day. You wouldn't think that that sounds like a large number. But it's unique indicators in a day. That's more than one an hour."

Google Fiber faces 'issues' as it seeks public rights of way

Google set politicians and netizens abuzz in February when it suggested it might bring that fiber to the Portland area, perhaps as soon as 2015.

But building a faster network could invite years of disruption as Google installs networking equipment around the city and buries fiber along suburban streets. The service could also necessitate new rules about what’s allowed in the public right of way -- and open the door to other companies installing their own gear on public property.

“There’s issues,” said Portland city commissioner Steve Novick, who runs the transportation bureau, which oversees rights of way. “But we’re very hopeful we can work out the issues.”