March 2015

Senate Commerce Commission
Wednesday, March 11, 2015
10 am
http://www.commerce.senate.gov/public/index.cfm?p=PressReleases&ContentR...

The hearing will examine the progress of FirstNet's nationwide wireless broadband network for emergency responders. Witnesses will discuss progress and challenges in building the network, as well as FirstNet’s future as a self-funding entity as required by the Act.

Witnesses:

- The Honorable Bruce Andrews, Deputy Secretary, U.S. Department of Commerce
- Mr. Mark Goldstein, Director (Physical Infrastructure), Government Accountability Office (GAO)
- Ms. Susan Swenson, Chairwoman, First Responder Network Authority (FirstNet)
- The Honorable Todd Zinser, Inspector General, U.S. Department of Commerce



“FREAK” flaw undermines security for Apple and Google users, researchers discover

Technology companies are scrambling to fix a major security flaw that for more than a decade left users of Apple and Google devices vulnerable to hacking when they visited hundreds of thousands of supposedly secure Web sites, including Whitehouse.gov, NSA.gov and FBI.gov. The flaw resulted from a former US government policy that once forbid the export of strong encryption and required that weaker “export-grade” products be shipped to customers in other countries, say the researchers who discovered the problem. These restrictions were lifted in the late 1990s, but the weaker encryption got baked into widely used software that proliferated around the world and back into the United States, apparently unnoticed until 2015.

Researchers discovered in recent weeks that they could force browsers to use the old export-grade encryption then crack it over the course of just a few hours. Once cracked, hackers could steal passwords and other personal information and potentially launch a broader attack on the Web sites themselves by taking over elements on a page, such as a Facebook “Like” button. The existence of the problem with export-grade encryption amazed the researchers, who have dubbed the flaw “FREAK” for Factoring attack on RSA-EXPORT Keys. The keys used in the export-grade encryption had 512 bits, a standard that was considered fairly strong in the 1990s but has been thought unacceptably weak for more than a decade now.

City-run Internet services still in limbo after FCC vote

After the nation’s top Internet regulator moved to allow two cities to offer broadband service to their residents, don’t expect a lot of other cities to follow. Expect lawsuits. About 18 other states have laws that restrict cities from building or expanding government operated local broadband networks. The laws are a result of heavy lobbying and spending over the years by large telecommunications companies such as AT&T, Comcast and Time Warner Cable. The Federal Communications Commission’s favorable ruling may be viewed as opening the door to towns in those states to file similar petitions of Chattanooga (TN). But that’s not likely to happen soon, said city officials overseeing networks and broadband experts.

First, cities are waiting for the FCC to release their final ruling, probably later in March, on preempting the Tennessee and North Carolina laws. The details may affect how other towns view their chances of getting a favorable FCC decision.Second, it is likely the FCC’s ruling will be challenged in court, and cities want to wait for the judges to weigh in before paying lawyers to petition the FCC. Any suit will have a chilling effect on cities.

Public Safety and Homeland Security Bureau Announces Update to PSAP Text-to-911 Readiness and Certification Registry

The Public Safety and Homeland Security Bureau of the Federal Communications Commission announces that it is updating the FCC’s Public Safety Answering Point (PSAP) Text-to-911 Readiness and Certification Registry (Text-to-911 Registry) listing PSAPs that are ready to receive text-to-911 messages.

This Public Notice provides notice to Commercial Mobile Radio Service providers and other providers of interconnected text messaging services of the effective readiness date of those PSAPs for which the Bureau has received the updated information. Pursuant to the Commission’s text-to-911 rules, covered text providers must begin routing 911 text messages to requesting PSAPs within six months of this notice date.

Major Pay-TV Providers Lost About 125,000 Subscribers in 2014

Leichtman Research Group found that the thirteen largest pay-TV providers in the US -- representing about 95 percent of the market -- lost about 125,000 net video subscribers in 2014. Annual net pay-TV losses in 2014 were comparable to 2013, when the same top pay-TV providers lost about 95,000 subscribers.
Other key findings include:

  • The top nine cable companies lost about 1,195,000 video subscribers in 2014 -- compared to a loss of about 1,695,000 subscribers in 2013
  • Cable video losses in 2014 were the fewest since 2008
  • The top telephone providers added 1,050,000 video subscribers in 2014 -- compared to 1,430,000 net additions in 2013
  • Satellite TV providers added 20,000 video subscribers in 2014 -- compared to 170,000 net additions in 2013

Consumer Privacy Bill of Rights doesn't go far enough, critics say

The White House published a draft of the Consumer Privacy Bill of Rights Act three years in the making late February, but not all privacy advocacy groups are satisfied. In a letter to President Barack Obama, representatives from US privacy and technology groups Center for Democracy and Technology, Consumer Watchdog, Electronic Frontier Foundation, Public Knowledge and others expressed concern that the draft bill doesn’t go far enough to protect consumers.

The groups criticized the draft bill for not adequately defining “what constitutes sensitive information,” not being clear about whether it protects large categories of information like geolocation data, allowing companies to retain user data indefinitely for criminal investigations without placing clear limits on data retention for that purpose, and not offering heightened protection for information about children and teens. In addition, the organizations take issue with being left out of consultations.

Dispatch from the Mobile World Congress: Mobile Is the New Frontier for Privacy

2015's Mobile World Congress is noteworthy because for the first time ever, it featured a panel session on privacy. With the title "Ensuring User-Centred Privacy in a Connected World," this session -- which was cleverly masterminded by GSMA's Director of Privacy, Pat Walshe -- was a unique platform to bring up the issue of privacy among an audience busy with developing and selling cool products, devices and services.

From the start, the discussion focused on trust. This is by far the best way to introduce the importance of privacy to an otherwise sceptical audience. Talk about privacy in legal and compliance terms and you will get nowhere beyond a few yawns. Raise the issue of trust and you will get people's attention. Mobile is definitely the new frontier for privacy.

[Eduardo Ustaran, CIPP/E, is a partner in the global Privacy and Information Management practice of Hogan Lovells]

A New Era Begins at the EDPS

On Monday, March 2, the new European Data Protection Supervisor (EDPS) Giovanni Buttarelli and Assistant Supervisor Wojciech Wiewiórowski presented their strategic plan for the next five years. Entitled “The EDPS Strategy 2015-2019: Leading by Example,” the document represents a key moment in the work of the EU’s leading data protection regulator.

In the 11 years since Peter Hustinx originally established it, the EDPS has come to enjoy a worldwide reputation both for policy work and for its supervision of data protection in EU institutions. The fact that there is a “changing of the guard” in its leadership has led to great interest in the EDPS’ new strategic plan. The new EDPS strategy paper follows a vision “for the EU to lead by example as a beacon of respect for data protection and privacy and to speak with single, credible and informed voice on fundamental rights in the digital world”. It identifies three major strategic objectives (namely “data protection goes digital,“ “forging global partnerships,” and “opening a new chapter for EU data protection”) and 10 action items.

[Christopher Kuner is Senior Privacy Counsel in the Brussels office of Wilson Sonsini Goodrich & Rosati]

First Responders Network Authority Board

National Telecommunications and Information Administration
Department of Commerce
March 9, 2015
10am -- 11am
http://www.gpo.gov/fdsys/pkg/FR-2015-03-03/pdf/2015-04413.pdf

The teleconference for the Special Meeting is open to the public. On the date and time of the Special Meeting, members of the public may call toll-free 1–888–997–9859 and use passcode 1849005 to listen to the meeting.