FACEbook

Showing posts with label Internet. Show all posts
Showing posts with label Internet. Show all posts

Saturday, January 17, 2015

White House Goes Upworthy: Video of Obama Helping 'To Make Your Internet Faster'

    The White House branched out into yet another social media venue Tuesday. Upworthy, the popular you-won't-believe-what-happened-next site, was given an exclusive on a White House video of President Obama discussing the executive action he plans to take to improve internet speeds in US cities. In true White House fashion, the Upworthy video and article were promoted with re-tweets on Twitter Tuesday night, such as this one from a women who gushed, "I love how tech savvy POTUS is -- this video is awesome!"



    Similar to the free community college proposal from last week, the faster internet pitch is a preview of an item the president plans to include in his 2015 State of the Union address. In the video, the president discusses his upcoming trip to Cedar Rapids, Iowa, the city that the president intends to hold forth as a model of internet done right:


    The Upworthy article accompanying the video explains in true Upworthy fashion:
The reason why Cedar Falls has such crazy-fast Internet? 
They got together as a community and built their own public network. 
And they run it like a utility. So the same way that you pay the heating bill or the gas bill, you pay an Internet bill. And because the whole city pitched in, they're able to offer fiber-optic networks' blazing fast speeds. 
The article also takes a shot at current internet providers for being part of the problem:
The problem is that some companies — not saying who, not pointing fingers...  
 
...aren't too keen on the competition. So they've been throwing vast sums of money at politicians in cities around the U.S. to dissuade them from building their own networks. They've also been pressuring communities with pre-existing networks from expanding their services into suburban and rural areas where the cable companies are the only game in town. 
But what's the problem with a little competition? 
That's capitalism, yo.
    Incidentally, Open Secrets reports that the top two recipients of campaign donations from Comcast-related PACs and individuals in the 2012 election cycle were the DNC Services Corp. ($415,329) and Barack Obama ($328,128).
    That's politics, yo.



Note: A version of this post first appeared at The Weekly Standard.

Monday, October 13, 2014

Congress Members, LGBT Groups Urge FCC To Change Rules on Internet Filters at Libraries, Schools

    Congressman Mike Honda (D-CA), 13 fellow members of Congress and over 20 organizations sent a letter to the Federal Communications Commission (FCC) in late September urging officials to make sure that schools and libraries receiving federal funds do not block or limit access to websites with "important resources" for the LGBT community. Currently the FCC requires local libraries and schools to block sites that contain material that is "obscene; child pornography; or harmful to minors." Rep. Honda and the other signatories to the letter suggest that schools and libraries may be, intentionally or unintentionally, abusing the rules:
It has been reported to me that filtering software also can be used to block much more. Regrettably, Internet content filtering software can—intentionally or unintentionally—be used to block access to particular viewpoints in a discriminatory manner.
    Rep. Honda, who founded and chairs the Congressional Anti-Bullying Caucus, cites studies that suggest LGBT individuals rely on the internet more than the general public for social networking and anti-discrimination/anti-bullying resources. The letter to the FCC includes one example, a 2011 case in Missouri where a school district used a filter to block LGBT resources but not anti-LGBT material. That case was handled by the American Civil Liberties Union (ACLU), one of the co-signing organizations supporting Rep. Honda's letter to the FCC. Other groups include the Human Rights Campaign, the Santa Clara County (CA) School District, the LGBT Technology Partnership & Institute, and numerous LGBT groups, among others.
    The letter comes at a time when the FCC is considering "modernizing" the E-Rate program, which "helps schools and libraries to obtain affordable telecommunications services, broadband Internet access and internal network connections." The program costs about $2.3 billion per year and requires grant recipients to adhere to certain guidelines, including the content restrictions mentioned in Rep. Honda's letter. The letter does not suggest exactly how the rules prohibiting material that is "obscene; child pornography; or harmful to minors" should be revised, but simply that "LGBT educational content should not be filtered in a discriminatory manner." Asked for clarification, Rep. Honda's office replied:
The purpose of the letter is two-fold: (1) raise awareness of the issue to the FCC; and, (2) encourage the FCC to address the problem through regulation or guidance to the Universal Service Administrative Company, which oversees the E-rate program, or directly to public schools and libraries. The wording you referenced is the statute itself, which would require Congress to pass a law to modify. While the FCC considers its proposal to modernize the E-rate program, the Congressman believes a more practical solution is to ask the FCC to use its expertise--and its regulatory authority--to ensure our students and communities have access to critical LGBT resources at public schools and libraries.
    When asked to comment on Rep. Honda's letter and the internet filter issue, the Family Research Council (FRC), an organization promoting family values and a Christian worldview, responded with a statement from Chris Gacek, Senior Fellow for Regulatory Affairs at the FRC:
Essentially, Honda wants to reduce the restrictions of the neutral filtering software to allow LGBT sexual content to reach public school and public library viewing screens.   A portion of LGBT content is sexual in nature, and it is not surprising that some does not clear content filters.  That said, the filters are entirely appropriate.

FRC opposes any effort to interfere with or lower the restrictions on sexual content reaching public schools and public libraries.  First, the standard given above -- “obscene; child pornography; or harmful to minors” – is too low as it is.  For example, a great deal of indecent or soft-core material might satisfy this standard.  Thus, if regulations are to be issue by the Commission, the restrictions on sexual content should be tighter.  Second, before issuing any regulations the Commission must include language that allows local communities to filter content up to the limit allowed by the federal statute.

    The full text of Rep. Honda's letter to the FCC can be found below:

Congressional Letter to the FCC regarding LGBT Content Filtering in Public Schools and Libraries by Mike Honda


Note: A version of this post first appeared at The Weekly Standard.

Friday, February 21, 2014

Widespread Vulnerability Found in Dozens of Government 'Open Data' Websites [Updated]

    At first glance, a page on the Health and Human Services (HHS) website seems to be giving that agency's official advice on the "The Health Benefits of Nootropics," a classification of purportedly memory-enhancing drugs.  The page is found on the website's subdomain of the Assistant Secretary for Planning and Evaluation (ASPE) as part of the Health System Measurement Project.  The page contains the official logo of HHS, the domain in the URL ends with the legitimate HHS address containing "hhs.gov", and the "https://" indicates the connection is even a secure one.  Further down the page, there is even a link to a website selling related products.  A partial screenshot of the profile page at HHS.gov appears as follows:



    Similar pages on the site offer information and counsel on shampoo, surgery, and health issues suffered by computer users.  However, in spite of all the apparently reassuring elements and features of these pages, Health and Human Services had nothing to do with their creation or content, and does not recommend or endorse either the information or the linked products.
    Nevertheless, while the pages are not official HHS information, neither are they technically cases of hacking.  Rather, the creators have exploited a weakness in the "open data" system used by dozens of government websites.  The platform was developed by a company called Socrata.  The system allows users to create profiles and then manipulate data tables that various governments (federal, state, local) host on their websites.  The results can be shared with others for statistical analysis, research, and other purposes, as some users have done. However, in cases like the ones above, a profile page itself can be used to promote a product or information in a way that gives viewers the impression that the host government entity approves or even endorses.  A legitimate looking link could even be included in an email to direct recipients to what they may easily perceive as government-provided information.
    THE WEEKLY STANDARD first reported this opening in January when some internet marketers had created profiles at data.healthcare.gov, the federal government's Obamacare website.  Within a day  after the story ran, Healthcare.gov disabled public access to profiles created for its data site.  At the time, David Kennedy, the CEO of TrustedSec, an information security firm, remarked that the opening could allow scammers to fool users with a "website that’s legitimate to make them believe its something else," and that "an attacker can basically create a functioning website and host any content they want there and under the umbrella of healthcare.gov."
    Use of the profiles can be especially effective since the profiles contain no disclaimers that the government entity does not endorse the content, and there are no warnings when clicking on links that "you are now leaving the website for an external site", a common warning on government sites.
    Health and Human Services is not the only government agency at risk.  The White House announced "Project Open Data" in May 2013 with dozens of federal agencies and sub-agencies taking part.  As recently as January 14, the White House released a Fact Sheet on the White House Safety Datapalooza,  an initiative to safeguard government data that is "part of the Administration’s larger commitment to unleash the power of open data."
    Other examples of profiles such as the one above are numerous, including other federal agencies, plus state, county and local governments.  The products and information being pushed range from private loans to debt consolidation to even "artificial turf":











    Each of the pages above (and dozens of others discovered in the preparation of this story) contains a link to an external website that is obviously not an officially sanctioned site by the government host, but neither are there any disclaimers to warn potential viewers.  The pages appear to violate the Terms of Service of the Socrata platform since "[u]nsolicited promotions, political campaigning, advertising or solicitations" are prohibited.
    More malicious sites could be used for data harvesting or even identity theft since scammers are able to trade on the credibility conferred by the official government websites that host these profile pages.  THE WEEKLY STANDARD has no direct evidence that such activity has yet taken place via an "open data" website, but at this point, clearly the door is wide open to such abuse.  
   An email to an official at Data.gov seeking comment was referred to another official who has not yet responded.  An emailed request to Socrata for comment was initially returned Tuesday evening with a promise of a response, but so far, no additional response has been received.

UPDATE: By the end of the day on Thursday, public access to Socrata profiles had been disabled.  Clicking on links to the profiles now redirect users to a login page.  Neither the government nor Socrata ever acknowledged the vulnerability nor issued any statement regarding the issue despite earlier promises to respond.  Tim Cashman, a Senior Content Strategist at Socrata, initially responded to an email Tuesday night with a promise to "be in touch with a response shortly", and Steven Gottlieb, a Socrata PR contact, and Bill Glenn, VP of Marketing, were both cc'd on his reply.  Several followup emails to all three Socrata representatives, however, were ignored.


Note: A version of this post, before the update, first appeared at The Weekly Standard.

Wednesday, December 18, 2013

Obamacare Test Website is Publicly Accessible [Updated]

UPDATE: Shortly after a version of this post went up at The Weekly Standard, http://spa.healthcare.gov/ disappeared, apparently taken down by the website administrators.  However, a Google search still turns up hundreds of results, some with cached versions of pages from the "spa." site.

    The Healthcare.gov website has been plagued with bugs and other problems since the October 1 launch.  As web programmers often do, the designers of the federal government's flagship healthcare website have a test version of the site, test.healthcare.gov, to help work out the kinks before implementation on the public site.  Attempts to access this site are met with "Access Denied. You don't have permission to access 'http://test.healthcare.gov/' on this server."  However, another test version of the site, possibly set up in October after the launch, is readily accessible to the public: spa.healthcare.gov.
   When a user first attempts to access the "spa" site, a warning from the user's browser may be encountered. For example, the following warning appears to Chrome users:


    The "security certificate" for the site is registered to Akamai Technologies, which bills itself as the "leading cloud platform for helping enterprises provide secure, high-performing user experiences on any device, anywhere."  Akamai does not list Healthcare.gov or the Department of Health and Human Services (HHS) as a client, though Akamai has been identified as handling server and web traffic duties for the site.
    Some pages on the site simply mirror the main www.healthcare.gov site, such as the home page.  However, some pages on the main site (https://www.healthcare.gov/find-premium-estimates/) are met with a "Sorry, we can't find that page" message on the "spa" site (https://spa.healthcare.gov/find-premium-estimates/).  The login page on the "spa" site does not even open, but rather returns "An error occurred while processing your request" message.
    It is unclear why this "spa" site would be publicly accessible.  A web designer, who requested not to be named, asked about security concerns of the "spa" site wrote:
Well it does have the https (ssl) option, however the certificate that is installed is for the wrong domain so you will get a warning/have to accept etc. Certificate details below. It is common practive to create a "duplicate" site for testing and development. I do it all the time, however, common practice is to restrict access to the development/testing site. I always password protect etc the [non-production] site. To me it just seems like more sloppy work.
    Congressional testimony given on November 19 by internet security firm TrustedSec mentioned a security concern with the "spa" site:


    It is unclear if the security concern indicated by TrustedSec is still present currently on the site.


NOTE: A version of this article (before the update) first appeared at The Weekly Standard.