<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/surveillance"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Surveillance ]]></title>
                <link>https://www.itpro.com/uk/tag/surveillance</link>
        <description><![CDATA[ All the latest surveillance content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Thu, 26 May 2022 16:18:08 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Making the most of surveillance video storage ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-storage/367773/making-the-most-of-surveillance-video-storage</link>
                                                                            <description>
                            <![CDATA[ The questions IT decision makers need to ask themselves when rolling out or expanding video surveillance technology ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tKSR24PA6iwU7Y31jaAvrM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4ZtGxDpa74MosbgvqEk2ze-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 26 May 2022 16:18:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Storage]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                <cf:isSponsored>true</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4ZtGxDpa74MosbgvqEk2ze-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Four security cameras mounted on a pole]]></media:description>                                                            <media:text><![CDATA[Four security cameras mounted on a pole]]></media:text>
                                <media:title type="plain"><![CDATA[Four security cameras mounted on a pole]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4ZtGxDpa74MosbgvqEk2ze-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Monitoring and surveillance has come a long way from the days where everything was recorded onto tapes, and thanks to internet-connected cameras and AI-enabled video analysis, now falls squarely into the purview of IT decision makers.</p><p>Whether you’re using it for security or a <a href="https://www.itpro.com/cloud/cloud-storage/366617/why-video-surveillance-is-about-more-than-just-security" target="_blank" data-original-url="https://www.itpro.com/cloud/cloud-storage/366617/why-video-surveillance-is-about-more-than-just-security">host of other purposes</a>, there are various questions that ITDMs need to be asking when planning new or expanding existing video surveillance systems. A strong understanding of the uses to which you will put your footage is essential to making the right decisions.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/vRMILqXQjBY" allowfullscreen></iframe></div></div><p>A key consideration is the quality of your footage. Higher image quality and frame rates are of course more useful when it comes to analysing the footage you have captured, showing more details and preventing rapid movements from being lost. However, these factors must be balanced with the increased demands they place on storage, which can, if you aren’t careful, lead to rapidly spiralling costs.</p><p>ITDMs will need to strike a balance between not exceeding their budget and capturing footage that is fit for purpose. While it may be tempting to limit the frame rates and image quality of your surveillance system to keep costs down, it’s important to resist going too far and finding that, when you need it, your footage is unusable.</p><p>Decision makers will also need to set a retention policy that dictates how long footage needs to be retained before it is erased. In certain regions or industries there are legal requirements for how long surveillance footage must be kept, but even when there are no laws dictating how long your organisation needs to keep this data, a retention policy is essential for the proper management of your surveillance system.</p><p>Again, this will be heavily influenced by the purposes to which your surveillance footage is going to be put. If you have long-term requirements of the footage, it’s no good if the footage has been deleted before when you go to access it. But a longer retention period will naturally require more storage.</p><p>One approach is to set up a multi-tier retention policy to maximise the availability of your footage without having to repeatedly expand your disk capacity. Easily accessible ‘hot cloud’ storage is ideal for reducing on-prem storage requirements while extending retention policies, by offloading footage to the cloud for archiving after a certain period of time. An ideal cloud storage solution is Wasabi’s hot cloud service, a universal, one-size-fits-all object storage hub that serves as an “active” archive by delivering higher performance than the highest tiers of service from most traditional cloud storage providers, but at cold storage prices.</p><p>It’s important when deploying a video surveillance system to calculate your storage requirements. This can be a challenge, but there are various online calculators to assist you. A good rule of thumb is that one camera, recording in 1080p resolution at 30 frames per second, stored at medium quality and running for 24hrs a day, will generate roughly 700GB of data per day. Multiply this by the number of cameras you will be operating and that will give you some indication of your needs.</p><p>From here you can adjust footage quality and retention policies to match your storage requirements to your budget, finding a balance to ensure that you have the right surveillance footage available at the right quality, whenever you need it.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why video surveillance is about more than just security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-storage/366617/why-video-surveillance-is-about-more-than-just-security</link>
                                                                            <description>
                            <![CDATA[ How ‘hot’ cloud storage enables organisations to get the most out of video analytics ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uDDrUsw9UUxh2WAQ5zsV1i</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QPBFrcRAAYnQNKFrN6GKUm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Mar 2022 09:57:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Storage]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                <cf:isSponsored>true</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QPBFrcRAAYnQNKFrN6GKUm-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Video IP surveillance]]></media:description>                                                            <media:text><![CDATA[Video IP surveillance]]></media:text>
                                <media:title type="plain"><![CDATA[Video IP surveillance]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QPBFrcRAAYnQNKFrN6GKUm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Streaming services are brilliant examples of data storage, particularly for those of us that grew up having to record our favourite films onto VHS tapes. In the ‘80s, lots of households had shelf space or even whole cupboards filled with these legacy storage devices. Looking back now, it's amazing to think how much time was spent labelling, organising and simply finding things to watch.</p><p>Today we have services like Netflix giving us content at the touch of a button. Its library is also tailored to the end-user, with algorithms based on their preferences offering up suggestions to save time. These are the basic principles currently being applied to video surveillance, where companies like Wasabi use cloud storage and data analytics to give us the whole picture.</p><p>When talking about video surveillance it's easy to think of security and crime prevention, but there’s more to it than that. In 2019, the world’s video surveillance systems were generating more than 2,000 petabytes of data every day, according to MarketsandMarkets. Each frame captured can provide unique insights and valuable information. And this data can be collected and analysed with cloud computing services that enable all kinds of functions from facial recognition to traffic monitoring.</p><h3 class="article-body__section" id="section-what-can-we-do-with-video-surveillance-data"><span>What can we do with video surveillance data?</span></h3><p>Although CCTV cameras have been around for over 50-years, it’s only recently, with the adoption of cloud computing and IP video (video over internet protocol), that we’ve seen more use cases beyond security. By mixing the technologies together and adding analytical functions to camera software, organisations can find more insights, and ultimately more value, from the footage they capture.</p><p>Video analytics is about recognising temporal or spatial events in a video and we can do this with artificial intelligence software that’s been trained to identify and analyse images. Machine learning is used to tag objects, movements, patterns and so on to the point that it can flag changes or moments of interest. For example, traffic cameras have software that can identify road signs and also capture number plates, so if a car breaks the speed limit of the zone, the camera automatically registers the licence plate of the offender.</p><p>There are many different use cases for video analytics across a range of industries, such as retail environments, casinos, factories and even whole cities. For example, footfall monitoring systems are used to measure the flow of people to and from specific areas. These systems count people coming and going and also list the times they do with the aim of finding when traffic is at its peak. Similar systems are used by Transport for London to measure things like rush hour travel or if a platform is in danger of becoming overcrowded.</p><p>Other forms of spatial imagery include heat mapping, which is a visualisation of data with different colours denoting variations in temperature. There are many versions and use cases for heat maps, but they can also be applied to the monitoring of people. Some retail companies use heat maps to identify which parts of their stores are most popular with customers.</p><p>Facial recognition might be the most controversial use case, particularly given its impact on data privacy, but it is only one of a number of purposes to which law enforcement puts video surveillance. Of particular interest is the use of body cameras, which are now worn by most officers. These capture data for cloud-based evidence management systems and, as we’ll see, can lead to mounting costs that turn data storage into a burden for organisations.</p><h3 class="article-body__section" id="section-the-burden-of-video-surveillance-data-storage"><span>The burden of video surveillance data storage </span></h3><p>Like those days of recording on VHS tapes, there is only so much on-premises space in which a company can store its video surveillance data. The issue is compounded by the fact camera technology advances more and more each year. High-resolution images mean more data, because the better the camera the more detail it captures, which in turn can be more easily recognised by the software. This constant capture of data presents organisations with a choice: to either blow the budget and pay for more cloud storage or, like VHS tapes, simply delete stored data and record over it with new data.</p><p>However, immediate deletion is not always an option. Organisations strive for a particular retention period for surveillance footage – for instance, 30 days before deletion – and may find themselves pinched between these goals and mounting storage costs. In the case of law enforcement agencies, this retention is legally mandated and is likely to far exceed the periods that private companies aim at. Information collected from body cameras and surveillance footage can’t simply be deleted or discarded as it may become important later on, such as for evidence at trial or as an investigation unfolds.</p><p>Airport security teams are also burdened with similar guidelines that require video footage for events, such as thefts of passenger fights, to be stored for seven or more years. An incident at an airport can be captured on multiple cameras and played out over a prolonged period, and that is a significant amount of data to hold in an on-prem facility or a costly undertaking if you opt for a third-party cloud provider’s service.</p><p>A hybrid cloud environment, which mixes both on-premises and cloud storage, could be the solution. Organisations get more choice for where they keep their data, whether it's needed regularly, or instantly, or if it hasn’t got an immediate use. A good example of flexible cloud storage is Wasabi’s Hot Cloud service which is a universal, one-size-fits-all object storage hub. It takes away tiers and classifications and treats all data the same, allowing it to be readily accessible, whether it's “hot” or not. It costs less than traditional cold storage services – and doesn’t levy egress fees – but it’s also much faster than using frequent-access storage.</p><p>Not all data is created equally, according to Wasabi, but that doesn’t mean it shouldn’t be readily available and, more importantly, affordable. When it comes to surveillance, this can make all the difference.</p><p><a href="https://assets2.brandfolder.io/bf-boulder-prod/ccqhbf76wct5jt8s9xnmx6k/v/61699822/original/Wasabi%20Hybrid%20Cloud_Video%20Surv%20eGuide.pdf" rel="nofollow" target="_blank"><strong><em>Learn more about how Wasabi can help with your hybrid cloud video surveillance setup</em></strong></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US to ban surveillance software exports to authoritarian governments ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/361325/us-to-ban-surveillance-software-exports-to-authoritarian-governments</link>
                                                                            <description>
                            <![CDATA[ Commerce dept to prevent US companies from selling tools to hack people ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jpLp3NZajNMEVzef7oaNJB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QPBFrcRAAYnQNKFrN6GKUm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 21 Oct 2021 15:08:11 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QPBFrcRAAYnQNKFrN6GKUm-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Video IP surveillance]]></media:description>                                                            <media:text><![CDATA[Video IP surveillance]]></media:text>
                                <media:title type="plain"><![CDATA[Video IP surveillance]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QPBFrcRAAYnQNKFrN6GKUm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Department of Commerce has announced <a href="https://www.commerce.gov/news/press-releases/2021/10/commerce-tightens-export-controls-items-used-surveillance-private">an interim rule</a> that would place restrictions on exports of <a href="https://www.itpro.com/hardware" data-original-url="https://www.itpro.com/hardware">hardware</a> and software that could be used for malicious cyber activities. </p><p>The department’s Bureau of Industry and Security (BIS) made the rule, which will be active 90 days from today, and banned the export of “cyber security items.” The <a href="https://www.federalregister.gov/documents/2021/10/21/2021-22774/information-security-controls-cybersecurity-items">rule</a> mentions “National Security and Anti-terrorism” reasons as its basis. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/361191/is-australia-becoming-a-surveillance-state" data-original-url="/security/privacy/361191/is-australia-becoming-a-surveillance-state">Is Australia becoming a surveillance state?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/360756/ftc-bans-spyfone-and-orders-company-to-quit-surveillance-app" data-original-url="/business/policy-legislation/360756/ftc-bans-spyfone-and-orders-company-to-quit-surveillance-app">FTC bans SpyFone and orders company to quit surveillance app business</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/360627/more-than-90-privacy-orgs-urge-apple-to-abandon-csam" data-original-url="/security/privacy/360627/more-than-90-privacy-orgs-urge-apple-to-abandon-csam">More than 90 global privacy groups urge Apple to abandon CSAM surveillance</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/biometrics/360603/dangers-of-cctv-facial-recognition-impossible-to-regulate-warns-uks" data-original-url="/security/biometrics/360603/dangers-of-cctv-facial-recognition-impossible-to-regulate-warns-uks">UK's surveillance guidance shows tech is "impossible to regulate"</a></p></div></div><p>The law prohibits companies from selling cyber <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> software and tools to authoritarian regimes or countries the US deemed to have a history of human rights abuses, such as Russia or China. It also bars countries with weapons of mass destruction or under US arms embargoes.</p><p>There are some exceptions to the rule. For example, the Commerce Department may issue a license on request to sell <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> items to prohibited countries.</p><p>The rule said that cyber security items needed controls, as they could be used to carry out malicious cyber activities, such as surveillance or espionage.</p><p>"Today's rule is consistent with the result of BIS's negotiations in the Wassenaar Arrangement (W.A.) multilateral export control regime and with a review of comments from Congress, the private sector, academia, civil society, and other stakeholders on previously proposed BIS rulemaking in this area," the Commerce Department bureau said.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="njvRsL67rSgtpvunZuSnnj" name="njvRsL67rSgtpvunZuSnnj.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/njvRsL67rSgtpvunZuSnnj.png" mos="https://cdn.mos.cms.futurecdn.net/njvRsL67rSgtpvunZuSnnj.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>HP Wolf Security: Threat insights report</strong></p><p class="fancy-box__body-text">Equipping security teams with the knowledge to combat emerging threats</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/361005/hp-wolf-security-threat-insights-report" data-original-url="/security/ransomware/361005/hp-wolf-security-threat-insights-report">FREE DOWNLOAD</a></p></div></div><p>The US Secretary of Commerce Gina Raimondo said the country was committed to working with multilateral partners to “deter the spread of certain technologies that can be used for malicious activities that threaten cybersecurity and human rights.”</p><p>“The Commerce Department’s interim final rule imposing export controls on certain cybersecurity items is an appropriately tailored approach that protects America’s national security against malicious cyber actors while ensuring legitimate cybersecurity activities,” she added.</p><p>The department has invited public comments on the rule for the next 45 days. </p><p>The move follows European Union (EU) <a href="https://www.europarl.europa.eu/news/en/press-room/20201105IPR90915/dual-use-goods-parliament-and-eu-ministers-agree-on-new-eu-export-rules">efforts</a> last November to curb the exportation of cyber surveillance software and hardware to oppressive regimes. These rules covered “dual-use” products and services.</p><p>“Parliament negotiators, mandated by a <a href="https://www.europarl.europa.eu/doceo/document/TA-8-2018-0006_EN.html?redirect">2018</a> report, have succeeded in substantially strengthening human rights considerations among those new criteria to avoid that certain surveillance and intrusion technologies exported from the EU contribute to human rights abuses,” it announced last year.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AWS makes its Panorama Appliance generally available ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/amazon-web-services-aws/361323/aws-makes-aws-panorama-appliance-generally-available</link>
                                                                            <description>
                            <![CDATA[ The device helps increase quality control, optimize supply chains, and enhance consumer experiences ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kYiogNyCdyCy9JoyNqziuc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/P5mqDsicM9EpshXihUiAFn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 21 Oct 2021 14:06:18 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/P5mqDsicM9EpshXihUiAFn-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Amazon Web Services logo on a white background]]></media:description>                                                            <media:text><![CDATA[Amazon Web Services logo on a white background]]></media:text>
                                <media:title type="plain"><![CDATA[Amazon Web Services logo on a white background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/P5mqDsicM9EpshXihUiAFn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/amazon-web-services-aws/34126/amazon-web-services-review-aws-packs-in-more-features-than-any-other" data-original-url="https://www.itpro.com/amazon-web-services-aws/34126/amazon-web-services-review-aws-packs-in-more-features-than-any-other">Amazon Web Services (AWS)</a> has announced the general availability of its Panorama Appliance.</p><p>The device integrates computer vision into <a href="https://www.itpro.com/infrastructure/server-storage/356955/it-pro-live-why-on-premise-isnt-a-dirty-word" data-original-url="https://www.itpro.com/infrastructure/server-storage/356955/it-pro-live-why-on-premise-isnt-a-dirty-word">on-premises</a> internet protocol (IP) cameras, allowing fast and easy visual inspections of production lines, drive-thru queue management, layout optimizations of physical stores, and more.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/amazon-web-services-aws/361316/alkira-deepens-partnership-with-aws" data-original-url="/cloud/amazon-web-services-aws/361316/alkira-deepens-partnership-with-aws">Alkira deepens partnership with AWS</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/business-apps/361280/build-modern-applications-on-aws" data-original-url="/software/business-apps/361280/build-modern-applications-on-aws">Build modern applications on AWS</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/databases/361277/best-practices-for-running-microsoft-sql-server-on-aws" data-original-url="/data-insights/databases/361277/best-practices-for-running-microsoft-sql-server-on-aws">Best practices for running Microsoft SQL Server on AWS</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/amazon-web-services-aws/361073/aws-makes-amazon-managed-service-for-prometheus-generally" data-original-url="/cloud/amazon-web-services-aws/361073/aws-makes-amazon-managed-service-for-prometheus-generally">AWS makes Amazon Managed Service for Prometheus generally available</a></p></div></div><p>“While some smart cameras can provide real-time visual inspection, replacing existing cameras with new smart cameras can be cost prohibitive. Even then, smart cameras are often ineffective because they are limited to specific use cases and require additional effort to fine-tune,” explained AWS.</p><p>“Alternatively, some customers send video feeds from existing on-premises cameras to third-party servers, but often the required internet <a href="https://www.itpro.com/broadband/30274/what-is-bandwidth" data-original-url="https://www.itpro.com/broadband/30274/what-is-bandwidth">bandwidth</a> is costly or facilities are in remote locations where internet connectivity can be slow, all of which degrades the usefulness and practicality of the analysis.”</p><p>AWS’ Panorama device minimizes costs by enabling customers to pair the solution with existing on-premises cameras and monitor video streams locally through computer vision.</p><p>Customers can update their computer vision application in Amazon SageMaker and deploy the model to the AWS Panorama Appliance, thanks to the device's full integration with Amazon SageMaker.</p><p>Together, AWS Panorama Appliance, Amazon Monitron, Amazon Lookout for Equipment, and Amazon Lookout for Vision deliver the most comprehensive cloud-to-edge <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning" data-original-url="https://www.itpro.com/strategy/28071/what-is-machine-learning">machine learning</a> solution for industrial applications.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ejh4Z6whRy3FqzEUPsGXiK" name="ejh4Z6whRy3FqzEUPsGXiK.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ejh4Z6whRy3FqzEUPsGXiK.png" mos="https://cdn.mos.cms.futurecdn.net/ejh4Z6whRy3FqzEUPsGXiK.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The AI-powered supply chain</strong></p><p class="fancy-box__body-text">Better demand forecasting and operational excellence</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/361261/the-ai-powered-supply-chain" data-original-url="/technology/artificial-intelligence-ai/361261/the-ai-powered-supply-chain">FREE DOWNLOAD</a></p></div></div><p>AWS offers its Panorama Appliance in Virginia, Oregon, Canada, and Ireland. Support for additional regions will follow soon.</p><p>“CVG Airport is committed to providing a world-class traveler experience through continuous innovation and strategic cooperation,” said Brian Cobb, chief innovation officer at Cincinnati/Northern Kentucky International Airport.</p><p>Cobb added, “By using TaskWatch’s application on AWS Panorama, we are able to bring machine learning to our existing IP cameras and automatically monitor congestion over 70,000 square feet of airport traffic lanes. Once an issue is detected, such as a disabled vehicle, TaskWatch sends real-time alerts to airport staff so they can provide assistance, keep the traffic flowing, and reduce delays for our passengers.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Eagle Eye Networks announces new editions of Cloud VMS ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/361315/eagle-eye-networks-announces-new-editions-of-cloud-vms</link>
                                                                            <description>
                            <![CDATA[ The editions are suitable for small, medium, and large businesses ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">u7tGXhRAJ8tZLKTKV92rmx</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bXVncR7tN2tkZcLj5xtYaf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 20 Oct 2021 14:58:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bXVncR7tN2tkZcLj5xtYaf-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cameras on pole]]></media:description>                                                            <media:text><![CDATA[cameras on pole]]></media:text>
                                <media:title type="plain"><![CDATA[cameras on pole]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bXVncR7tN2tkZcLj5xtYaf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Eagle Eye Networks has announced several enhancements to its Cloud Video Management System (VMS). </p><p>Eagle Eye Cloud VMS, which combines <a href="https://www.itpro.com/strategy/28181/what-is-ai" data-original-url="https://www.itpro.com/strategy/28181/what-is-ai">artificial intelligence (AI)</a> and analytics for enhanced <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> and operational efficiency, now offers three editions: Enterprise, Professional, and Standard.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/360716/critical-flaw-in-iot-camera-system-could-lead-to-remote-takeover" data-original-url="/security/vulnerability/360716/critical-flaw-in-iot-camera-system-could-lead-to-remote-takeover">Critical flaw in IoT camera system could lead to remote takeover</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/video-conferencing/360038/1080p-webcams-smarten-up-your-video-calls-with-these-external" data-original-url="/software/video-conferencing/360038/1080p-webcams-smarten-up-your-video-calls-with-these-external">1080p webcams: Smarten up your video calls with these external cameras</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/359899/critical-supply-chain-flaw-exposes-iot-cameras-to-cyber-attack" data-original-url="/security/vulnerability/359899/critical-supply-chain-flaw-exposes-iot-cameras-to-cyber-attack">Critical supply chain flaw exposes IoT cameras to cyber attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/358783/sens-question-the-privacy-of-cameras-in-amazon-delivery-vans" data-original-url="/security/privacy/358783/sens-question-the-privacy-of-cameras-in-amazon-delivery-vans">Senators question the privacy of cameras in Amazon delivery vans</a></p></div></div><p>According to the company, the new editions will benefit small, medium, and large businesses alike.</p><p>“Our new Eagle Eye Cloud VMS Editions will propel customer and reseller success by delivering the right solution for each customer, while ensuring customers have the flexibility to scale,” said Dean Drako, founder and <a href="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do" data-original-url="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do">CEO</a> of Eagle Eye Networks.</p><p>The Standard Edition includes access to recorded and live video via a browser or mobile device. This edition is best suited for small businesses and franchisees with a modest number of locations. </p><p>The Professional Edition offers features to manage multiple locations, users, and cameras, ideal for midsize businesses with rapidly growing security operations.</p><p>The Enterprise Edition supports an unlimited number of users and offers sophisticated access control and video sharing capabilities. This edition is ideal for customers seeking flexible user identity and access management, advanced operational reporting, audit and regulatory <a href="https://www.itpro.com/policy-legislation/compliance/354495/testing-for-compliance-just-became-easier" data-original-url="https://www.itpro.com/policy-legislation/compliance/354495/testing-for-compliance-just-became-easier">compliance</a>, and more.</p><p>Additionally, all three editions come with Eagle Eye Cloud VMS’ core functionalities. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TDWPShop8idtg5y5PK4Eu4" name="TDWPShop8idtg5y5PK4Eu4.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TDWPShop8idtg5y5PK4Eu4.png" mos="https://cdn.mos.cms.futurecdn.net/TDWPShop8idtg5y5PK4Eu4.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Hybrid cloud for video surveillance</strong></p><p class="fancy-box__body-text">What it is and why you'll want one</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/360218/hybrid-cloud-for-video-surveillance" data-original-url="/cloud/360218/hybrid-cloud-for-video-surveillance">FREE DOWNLOAD</a></p></div></div><p>Using Eagle Eye Cloud-Premises Flex Storage, businesses can adjust the ratio of video surveillance stored in the <a href="https://www.itpro.com/cloud" data-original-url="https://www.itpro.com/tags/cloud">cloud</a> and <a href="https://www.itpro.com/infrastructure/server-storage/356955/it-pro-live-why-on-premise-isnt-a-dirty-word" data-original-url="https://www.itpro.com/infrastructure/server-storage/356955/it-pro-live-why-on-premise-isnt-a-dirty-word">on-premises</a>. With triple-redundant storage, the platform provides data security and reliability.</p><p>Eagle Eye Cloud VMS also supports camera resolutions as high as 20 megapixels per camera and up to 10 years of video retention. Unlimited integrations are made possible via Eagle Eye Video <a href="https://www.itpro.com/application-programming-interface-api/33557/the-api-economy-what-your-business-needs-to-know" data-original-url="https://www.itpro.com/application-programming-interface-api/33557/the-api-economy-what-your-business-needs-to-know">API</a>.</p><p>Customers can also choose to pair the solution with existing surveillance infrastructure, including analog cameras. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Synology DVA3221 review: Much more than a NAS ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/server-storage/network-attached-storage-nas/360331/synology-dva3221-review-much-more-than-a-nas</link>
                                                                            <description>
                            <![CDATA[ This surveillance solution is easy to deploy and packed with useful video analysis tools ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">63BDHqDLjVQxf53cCu76SE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tDQb4kDKGbLiupkJNiURZU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 22 Jul 2021 15:58:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Storage]]></category>
                                                    <category><![CDATA[Hardware]]></category>
                                                    <category><![CDATA[Desktops]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tDQb4kDKGbLiupkJNiURZU-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A photograph of the Synology DVA3221]]></media:description>                                                            <media:text><![CDATA[A photograph of the Synology DVA3221]]></media:text>
                                <media:title type="plain"><![CDATA[A photograph of the Synology DVA3221]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tDQb4kDKGbLiupkJNiURZU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>If you need to capture, store and manage large archives of security camera footage, the DVA3221 is for you. While it may look like a regular four-bay desktop NAS, it’s designed and configured as a one-stop surveillance hub, so you can simply plug in your IP cameras and go.</p><p>In terms of hardware, its key feature is a preinstalled Nvidia GeForce GTX 1650 graphics card. This provides the horsepower for deep video analytics tasks, allowing you to track people, employ live facial recognition and do plenty more across multiple video feeds.</p><p>The DVA3221 is also laughably easy to deploy. After slotting in four 14TB WD Red Pro NAS hard disks and firing up Synology’s web discovery portal, there was almost nothing left for us to do. The portal located the appliance, installed the latest DSM 6.2 software, set up <a href="https://www.itpro.com/server-storage/34537/raid-levels-explained" data-original-url="https://www.itpro.com/server-storage/34537/raid-levels-explained">a suitable RAID array</a>, loaded the Nvidia drivers, set up Synology’s own Surveillance Station app and created a shared video storage folder.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/server-storage/network-attached-storage-nas/360075/synology-diskstation-ds1821-review-hard-to-fault" data-original-url="/server-storage/network-attached-storage-nas/360075/synology-diskstation-ds1821-review-hard-to-fault">Synology DiskStation DS1821+ review: Hard to fault</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/nas/27920/best-nas-drives" data-original-url="/nas/27920/best-nas-drives">Best NAS drives 2023: Which network storage appliance is right for you?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/server-storage/network-attached-storage-nas/359864/western-digital-my-cloud-pro-series-pr4100" data-original-url="/server-storage/network-attached-storage-nas/359864/western-digital-my-cloud-pro-series-pr4100">Western Digital My Cloud Pro Series PR4100 review: A worthy out-of-the-box option</a></p></div></div><p>Connecting to your IP cameras is handled by the Surveillance Station software. This had no problems finding and identifying our motley mix of <a href="https://www.itpro.com/cctv/29446/axis-m1065-lw-review" data-original-url="https://www.itpro.com/cctv/29446/axis-m1065-lw-review">Axis</a>, <a href="https://www.itpro.com/cctv/29445/d-link-vigilance-dcs-4602ev-review" data-original-url="https://www.itpro.com/cctv/29445/d-link-vigilance-dcs-4602ev-review">D-Link</a> and <a href="https://www.itpro.com/cctv/29688/engenius-el-ews1025cam-review" data-original-url="https://www.itpro.com/cctv/29688/engenius-el-ews1025cam-review">EnGenius</a> cameras – the Synology software works with over 7,900 models. The price includes an eight-camera licence, but the appliance can work with up to 32 feeds. The standard live view scales to accommodate however many streams you have set up, but you’re free to switch to a different layout or create your own.</p><p>With our cameras connected, we started out by enabling the people-counting feature for a 2MP dome camera mounted on the ceiling by the lab door. It took us a few goes to successfully define the detection zone, but in around ten minutes the software was successfully logging all foot traffic. We could then pull up reports tracking daily, monthly and yearly footfall, and you can also use this feature for live crowd control, triggering an alert if the number of people who have entered exceeds those who’ve exited by more than a preset limit.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aa9X3N9wDXW7i5zTTaJyd3" name="" alt="A photograph of the rear of the Synology DVA3221" src="https://cdn.mos.cms.futurecdn.net/aa9X3N9wDXW7i5zTTaJyd3.jpg" mos="https://cdn.mos.cms.futurecdn.net/aa9X3N9wDXW7i5zTTaJyd3.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Facial recognition proved easier to set up. We began by importing photos of the people we wanted to track, then assigned each one to an account and configured a monitoring zone in the camera view. As soon as a subject entered that zone, the display zeroed in on their face and tagged the box with their name. Unrecognised individuals were flagged up as unknown, and we were invited to import them into the database; the only hitch, for now, is that we found the system had zero ability to identify anyone wearing a face mask. </p><p>Person and vehicle detection works by letting you define up to three polygonal zones on the preview screen, and warns you if anyone enters them. A customisable small object threshold stops birds and the like triggering an alert, while a minimum duration time in seconds tells the software to alert you only if someone lingers in a particular place.</p><p>Intrusion detection works in a similar way: for this, you draw a line in the preview window and an alert is triggered if anything crosses it. You can pick whether you’re only interested in people crossing to one side or want to track movement in both directions. </p><p>Since the footage you capture will almost inevitably contain personally identifiable information, the DVA3221 also includes some smart features to help you ensure GDPR compliance. The whole system can be isolated on a private network, video storage shares can be encrypted and access can be locked down with two-factor authentication, while Synology’s Evidence Integrity Authenticator app can digitally sign recordings to help prove that footage hasn’t been tampered with.</p><p>Yes, you could do all of this with a bog-standard NAS, given the right software and a graphics card – but the DVA3221 is a lot easier to deploy and it’s good value. Moreover, it can still double up as a general-purpose NAS, making it an almost irresistible proposition for SMBs wanting an in-house video surveillance solution without the hassle. </p><h2 id="synology-dva3221-specifications">Synology DVA3221 specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >Desktop chassis</td></tr><tr><td  ><strong>CPU</strong></td><td  >2.1GHz Intel Atom C3538</td></tr><tr><td  ><strong>GPU</strong></td><td  >Nvidia GeForce GTX 1650 with 4GB GDDR5 </td></tr><tr><td  ><strong>Memory</strong></td><td  >8GB DDR4 (max 32GB)</td></tr><tr><td  ><strong>Storage</strong></td><td  >4 x LFF hot-swap SATA drive bays</td></tr><tr><td  ><strong>Network</strong></td><td  >4 x Gigabit Ethernet</td></tr><tr><td  ><strong>Other ports</strong></td><td  >3 x USB 3, 2 x eSATA</td></tr><tr><td  ><strong>Dimensions (WDH)</strong></td><td  >250 x 237 x 166mm</td></tr><tr><td  ><strong>Warranty</strong></td><td  >3yr hardware warranty</td></tr><tr><td  ><strong>Options</strong></td><td  >8-camera licence included, additional 8-camera licence, £252 exc VAT</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Qnap QGD-3014-16PT review: A clever combo ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/server-storage/network-attached-storage-nas/359657/qnap-qgd-3014-16pt-review-a-clever-combo</link>
                                                                            <description>
                            <![CDATA[ A smart partnership of NAS appliance and PoE switch well suited to surveillance duties ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">af84Q4Tc7PaPx1iLMzUVXs</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HDrCd8zwDfosshq3JHmXKG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 May 2021 09:37:55 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Storage]]></category>
                                                    <category><![CDATA[Hardware]]></category>
                                                    <category><![CDATA[Desktops]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HDrCd8zwDfosshq3JHmXKG-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The front and rear of the Qnap QGD-3014-16PT]]></media:description>                                                            <media:text><![CDATA[The front and rear of the Qnap QGD-3014-16PT]]></media:text>
                                <media:title type="plain"><![CDATA[The front and rear of the Qnap QGD-3014-16PT]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HDrCd8zwDfosshq3JHmXKG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Qnap's Guardian series offers an innovative solution that combines <a href="https://www.itpro.com/nas/27920/best-nas-drives" data-original-url="https://www.itpro.com/nas/27920/best-nas-drives">a fully-functional NAS appliance</a> with a 16 port, PoE-enabled, fully managed Gigabit switch in a single unit. They're versatile, space-saving solutions designed to provide a wide range of storage and virtualized security services with a sharp focus on video surveillance.</p><p>When we reviewed <a href="https://www.itpro.com/server-storage/network-attached-storage-nas/354985/qnap-guardian-qgd-1600p-review-an-ideal-all-in" data-original-url="https://www.itpro.com/server-storage/network-attached-storage-nas/354985/qnap-guardian-qgd-1600p-review-an-ideal-all-in">the QGD-1600P 1U rack model</a>, we observed that its minimal internal storage was a potential limitation for video surveillance, but the QGD-3014-16PT resolves this with a big boost in capacity. This makes it more appealing as a high-volume video recording vault and Qnap's range of QVR Pro applications provide a wealth of monitoring services. </p><h2 id="qnap-qgd-3014-16pt-review-hardware-features">Qnap QGD-3014-16PT review: Hardware features</h2><p>The QGD-3014-16PT is powered by a 2GHz quad-core Intel Celeron J4125 CPU and 8GB of DDR4 memory. The motherboard has two SO-DIMM slots both populated with 4GB modules, which is the maximum the CPU can support – a shame, as this may present some limitations.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/server-storage/network-attached-storage-nas/359573/qnap-ts-h2490fu-quts-hero-edition-review-smash" data-original-url="/server-storage/network-attached-storage-nas/359573/qnap-ts-h2490fu-quts-hero-edition-review-smash">Qnap TS-h2490FU QuTS hero edition review: Smash hit flash</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/server-storage/network-attached-storage-nas/359623/synology-rackstation-rs1221rp-review-short-and" data-original-url="/server-storage/network-attached-storage-nas/359623/synology-rackstation-rs1221rp-review-short-and">Synology RackStation RS1221RP+ review: Short and sweet</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/server-storage/network-attached-storage-nas/358466/qsan-xcubenxt-xn8024d-review-nice-try-but-no" data-original-url="/server-storage/network-attached-storage-nas/358466/qsan-xcubenxt-xn8024d-review-nice-try-but-no">Qsan XCubeNXT XN8024D review: Nice try, but no cigar</a></p></div></div><p>At the back, you'll find sixteen Gigabit ports which support 802.3at PoE+ and can each provide up to 30W. The last two copper ports are dual personality and share their backplane links with the two non-PoE Gigabit SFP fibre ports alongside.</p><p>NAS storage is handled by four hot-swap LFF drive bays behind the removable plastic cover at the front. Caching is a possibility thanks to the two internal <a href="https://www.itpro.com/solid-state-storage-ssd/33908/best-ssds-the-top-nvme-and-sata-drives-around" data-original-url="https://www.itpro.com/solid-state-storage-ssd/33908/best-ssds-the-top-nvme-and-sata-drives-around">M.2 SATA SSD</a> slots but 10GbE is off the menu as, unlike the QGD-1600P, it doesn't have any expansion slots.</p><p>The NAS appliance and switch components are powered independently, which is a smart feature meaning that when a QTS software update requires a reboot, it won't affect devices connected to the switch and drawing power from it. Multi-Gig also comes into the equation, as the appliance has two separate 2.5GbE ports which can be used for management or connecting high performance hosts.</p><h2 id="qnap-qgd-3014-16pt-review-nas-and-switch-management">Qnap QGD-3014-16PT review: NAS and switch management</h2><p>Run Qnap's QFinder discovery app and it'll come back with two devices, each with their own IP address. One is for general NAS management using the QTS web console and other is for the switch's QSS Management web interface, which allows it to be independently monitored and controlled.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LhKv4cJ9pxP4jiuiQTmDsL" name="" alt="Screenshots of the Qnap QGD-3014-16PT management software" src="https://cdn.mos.cms.futurecdn.net/LhKv4cJ9pxP4jiuiQTmDsL.jpg" mos="https://cdn.mos.cms.futurecdn.net/LhKv4cJ9pxP4jiuiQTmDsL.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The switch can also be managed from within QTS using the QuNetSwitch app which presents an identical console to QSS Management. The home page offers a complete status overview; the ports have colour-coded icons showing their connection speed while those providing power get an orange lightning bolt overlay. </p><p>Graphs to the side reveal switch CPU utilisation and temperature, with another below showing overall PoE consumption along with total used and available power. The switch has a comparatively modest power budget of 140W but you can apply one of three power priorities to each port so if the total draw reaches this threshold, those with the lowest priority will be automatically switched off first. </p><p>A handy feature is the option to apply PoE schedules to single or multiple ports that define the days they are active and when power is to be supplied. The switch also supports all the Layer 2 features you'd expect to see including VLANs, ACLs (access control lists), port and VLAN QoS (quality of service) and link aggregation.</p><h2 id="qnap-qgd-3014-16pt-review-2-5gbe-performance">Qnap QGD-3014-16PT review: 2.5GbE performance</h2><p>For NAS performance testing, we configured four 10TB Seagate IronWolf NAS drives in a RAID5 array and used the appliance's 2.5GbE ports to hook it up to a Netgear MS510TX multi-Gig switch. We called up the lab's <a href="https://www.itpro.com/server-storage/31749/dell-emc-poweredge-t640-review-a-data-centre-in-a-box" data-original-url="https://www.itpro.com/server-storage/31749/dell-emc-poweredge-t640-review-a-data-centre-in-a-box">Dell EMC PowerEdge T640 Xeon Scalable tower server</a> running Windows Server 2019 for host duties and connected it to the switch's 10GbE port.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="hqTEXWUrfn4NsAH9yos5sT" name="hqTEXWUrfn4NsAH9yos5sT.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/hqTEXWUrfn4NsAH9yos5sT.png" mos="https://cdn.mos.cms.futurecdn.net/hqTEXWUrfn4NsAH9yos5sT.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The smart buyer’s guide to flash</strong></p><p class="fancy-box__body-text">Find out whether flash storage is right for your business</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/server-storage/flash-storage/359391/the-smart-buyers-guide-to-flash" data-original-url="/server-storage/flash-storage/359391/the-smart-buyers-guide-to-flash">FREE DOWNLOAD</a></p></div></div><p>With a NAS share mapped to the server, we saw Iometer report solid sequential read and write rates both of 2.3Gbits/sec. These translated to top real world speeds, with our 25GB drag and drop file copies also returning the same averages. </p><p>Backup performance was reasonable - a 22.4GB folder and 10,500 small files were secured to the share at 1Gbits/sec. The Celeron's integral AES-NI engine is very efficient, and copying our 25GB test file to an encrypted share returned a respectable 1.8Gbits/sec with CPU utilization hovering around the 60% mark.</p><p>IP SAN performance is equally good with a 500GB target returning Iometer read and write rates of 2.3Gbits/sec and 2.2Gbits/sec. With a dual 2.5GbE MPIO iSCSI link to the target, we saw read and write performance increase to 4.5Gbits/sec and 3.8Gbits/sec.</p><h2 id="qnap-qgd-3014-16pt-review-surveillance-apps">Qnap QGD-3014-16PT review: Surveillance apps</h2><p>Qnap provides plenty of surveillance apps. The free version of QVR Pro includes an eight-channel license, and supports 14 days of video playback. You can purchase extension licenses up to a maximum of 128 channels, with the QVR Pro Gold license costing £307 and providing eight extra channels and unlimited playback.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="skUYmd4CxpvbakrboodXu8" name="" alt="Screenshots of the Qnap QGD-3014-16PT management software" src="https://cdn.mos.cms.futurecdn.net/skUYmd4CxpvbakrboodXu8.jpg" mos="https://cdn.mos.cms.futurecdn.net/skUYmd4CxpvbakrboodXu8.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The free version offers plenty of features and its auto-discover feature found our IP cameras without any problems. You can create dedicated recording vaults on the appliance, set up rules to manage motion detection events and use the QVR Pro Windows client to view live feeds on your desktop.</p><p>The appliance's HDMI 2.0 ports add extra dimensions as you can connect a mouse, keyboard plus HD TV, directly access the HybridDesk Station app and use its QVR Pro Client app to display all camera feeds locally. Its interface is identical to the Windows client where you select cameras to view in the main pane, create a video wall with multiple cameras, remotely control PTZ functions and play back recordings from your vault.</p><p>Video analytics come into the picture with the QVR Face Tiger app, which is available on a monthly subscription with one analytics task and 10 face profiles costing around £2 per month. It's easy enough to use, but we did find that running this alongside all the other QVR Pro apps pushed average CPU utilization as high as 50% and swallowed 40% of available memory.</p><h2 id="qnap-qgd-3014-16pt-review-verdict">Qnap QGD-3014-16PT review: Verdict</h2><p>The QGD-3014-16PT delivers a versatile combination of fully-featured NAS appliance and 16-port PoE+ Gigabit switch that's a lot cheaper than buying separate components. It's an ideal choice as an all-in-one video surveillance solution for remote offices and SMBs - although the maximum 8GB of memory may limit its ability to run extra apps alongside these services.</p><h2 id="qnap-qgd-3014-16pt-specifications">Qnap QGD-3014-16PT specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >Desktop</td></tr><tr><td  ><strong>CPU</strong></td><td  >2GHz quad-core Intel Celeron J4125</td></tr><tr><td  ><strong>Memory</strong></td><td  >8GB SO-DIMM DDR4 (max 8GB) </td></tr><tr><td  ><strong>Storage bays</strong></td><td  >4 x hot-swap SATA LFF, 2 x M.2 2230 SATA SSD slots</td></tr><tr><td  ><strong>RAID</strong></td><td  >RAID0, 1, 5, 6, 10, JBOD, Single</td></tr><tr><td  ><strong>Network (NAS)</strong></td><td  >2 x 2.5GbE Multi-Gig</td></tr><tr><td  ><strong>Other ports</strong></td><td  >3 x USB 3.2 Gen 1, 2 x HDMI 2.0</td></tr><tr><td  ><strong>Switch</strong></td><td  >16 x Gigabit with PoE/PoE+</td></tr><tr><td  ><strong>Power</strong></td><td  >Internal 250W PSU</td></tr><tr><td  ><strong>Management</strong></td><td  >Web browser (NAS and switch)</td></tr><tr><td  ><strong>Warranty</strong></td><td  >2yrs standard hardware</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The IT Pro Podcast: Should companies spy on their employees? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/359444/the-it-pro-podcast-should-companies-spy-on-their-employees</link>
                                                                            <description>
                            <![CDATA[ Where’s the line between security and surveillance? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4zgNh5HRcbog6YaJXyNW36</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bZ4W5U5Azx679gPhJ457w7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 May 2021 17:24:24 +0000</pubDate>                                                                                                                                <updated>Fri, 07 May 2021 06:30:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Digital Transformation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bZ4W5U5Azx679gPhJ457w7-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast: Should companies spy on their employees?]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast: Should companies spy on their employees?]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast: Should companies spy on their employees?]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bZ4W5U5Azx679gPhJ457w7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>More and more employees now use their own personal devices for work, and 2020 saw a particular spike in this behaviour. But what many people don't know is that your employer is legally entitled to monitor your activity on any device that you use to do your job.</p><p>This raises a number of thorny issues, such as where the line is between security and surveillance, and whether it's a violation of employee's privacy to keep tabs on what they're doing with their phone or PC. In this week's episode, we speak to Kevin Curran, senior IEEE member and professor of cybersecurity at Ulster University, to get his take on these issues, as well as just how much safety this approach offers.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="high" data-lazy-src="https://widget.spreaker.com/player?episode_id=44665057&theme=light&playlist=false&playlist-continuous=false&autoplay=false&live-autoplay=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe><h2 id="footnotes">Footnotes</h2><ul><li><a href="https://www.itpro.com/security/privacy/355457/how-to-improve-zoom-video-chat-privacy-and-security" data-original-url="https://www.itpro.com/security/privacy/355457/how-to-improve-zoom-video-chat-privacy-and-security">How to improve Zoom video chat privacy and security</a></li><li><a href="https://www.itpro.com/security/malware/359049/dangerous-android-spyware-disguising-itself-as-system-update-app" data-original-url="https://www.itpro.com/security/malware/359049/dangerous-android-spyware-disguising-itself-as-system-update-app">Android spyware disguised as 'system update' app discovered</a></li><li><a href="https://www.itpro.com/mobile/byod/354978/achieving-byod-confidence" data-original-url="https://www.itpro.com/mobile/byod/354978/achieving-byod-confidence">Achieving BYOD confidence</a></li><li><a href="https://www.itpro.com/business/business-strategy/358405/what-is-the-personalisation-of-it" data-original-url="https://www.itpro.com/business/business-strategy/358405/what-is-the-personalisation-of-it">What is the 'personalisation of IT'?</a></li><li><a href="https://www.itpro.com/security/357447/managing-employee-security-risks-during-lockdown" data-original-url="https://www.itpro.com/security/357447/managing-employee-security-risks-during-lockdown">Managing employee security risks during lockdown</a></li><li><a href="https://www.itpro.com/business-strategy/flexible-working/358420/what-are-employers-responsibilities-when-we-use-personal" data-original-url="https://www.itpro.com/business-strategy/flexible-working/358420/what-are-employers-responsibilities-when-we-use-personal">What are employers' responsibilities when we use personal tech to work from home?</a></li><li><a href="https://www.itpro.com/business/business-strategy/358982/10-learnings-to-consider-when-it-comes-to-enterprise-mobility" data-original-url="https://www.itpro.com/business/business-strategy/358982/10-learnings-to-consider-when-it-comes-to-enterprise-mobility">10 learnings to consider when it comes to enterprise mobility</a></li><li><a href="https://www.itpro.com/policy-legislation/data-protection/358362/90-of-second-hand-storage-media-devices-hold-data-from" data-original-url="https://www.itpro.com/policy-legislation/data-protection/358362/90-of-second-hand-storage-media-devices-hold-data-from">90% of second-hand storage contains personal and business data</a></li><li><a href="https://www.itpro.com/security/26770/mark-zuckerberg-isnt-paranoid-hes-sensible-about-security" data-original-url="https://www.itpro.com/security/26770/mark-zuckerberg-isnt-paranoid-hes-sensible-about-security">Mark Zuckerberg isn't paranoid - he's sensible about security</a></li><li><a href="https://www.itpro.com/security/358927/security-professionals-need-to-become-wellness-experts" data-original-url="https://www.itpro.com/security/358927/security-professionals-need-to-become-wellness-experts">Security professionals need to become wellness experts</a></li><li><a href="https://www.itpro.com/security/cyber-security/359036/businesses-took-fewer-security-precautions-in-2020-despite-growing" data-original-url="https://www.itpro.com/security/cyber-security/359036/businesses-took-fewer-security-precautions-in-2020-despite-growing">Half of UK businesses had no security policies in place in 2020</a></li><li><a href="https://www.itpro.com/security/357935/top-security-tips-for-employees-working-from-home" data-original-url="https://www.itpro.com/security/357935/top-security-tips-for-employees-working-from-home">Top security tips for employees working from home</a></li><li><a href="https://xkcd.com/538">xkcd: Security</a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3><ul><li><a href="https://podcasts.apple.com/gb/podcast/the-itpro-podcast/id1483810154">Subscribe to The IT Pro Podcast on Apple Podcasts</a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M">Subscribe to The IT Pro Podcast on Google Podcasts</a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ">Subscribe to The IT Pro Podcast on Spotify</a></li><li><a href="https://www.itpro.com/newsletter-signup" data-original-url="https://www.itpro.com/newsletter-signup">Subscribe to the IT Pro newsletter</a></li><li><a href="https://www.itpro.com/business/business-strategy/358742/it-pro-2020-keeping-the-lights-on" data-original-url="https://www.itpro.com/business/business-strategy/358742/it-pro-2020-keeping-the-lights-on">Subscribe to IT Pro 20/20</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Synology DVA3219 review: An ideal CCTV system ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/server-storage/network-attached-storage-nas/354221/synology-dva3219-review-an-ideal-cctv-system</link>
                                                                            <description>
                            <![CDATA[ A smart surveillance solution with clever video analytics tools ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hH6EfD2sMwYUdm8PA4Yf7K</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GC4uFEjoYo9TpJjVEVzU75-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 28 Nov 2019 11:00:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Storage]]></category>
                                                    <category><![CDATA[Hardware]]></category>
                                                    <category><![CDATA[Desktops]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GC4uFEjoYo9TpJjVEVzU75-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GC4uFEjoYo9TpJjVEVzU75-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>If you want to implement professional video surveillance as an SMB, you could be faced with a big shopping list: you’ll need to acquire a suitable VMS (video management software) product and factor in the cost of a host system, an OS and associated hardware. If that doesn’t sound appealing, however, you could always just cut out the middle men and use Synology’s DVA3219, which offers a complete surveillance platform out of the box.</p><p>The DVA3219 takes full advantage of Synology’s Surveillance Station app, which comes as standard on all its appliances. Crucial differences are the DVA3219 includes a pack of eight additional IP camera licenses (to bolster the single license included with Surveillance Station by default), as well as an Nvidia GeForce GTX 1050 Ti <a href="https://www.itpro.com/hardware/30399/what-is-a-gpu" target="_blank" data-original-url="https://www.itpro.com/hardware/30399/what-is-a-gpu">GPU</a> card. It’s also the only model that includes Synology’s Deep Video Analytics (DVA).</p><p>DVA offers four features that need GPU power to process: people counting, enhanced intrusion detection, no-idle zones and deep motion detection. People counting requires a ceiling mounted IP camera to conduct head counts of people passing underneath while enhanced intrusion detection allows you to draw a perimeter line anywhere in a camera view so anything that crosses it will trigger an event.</p><p>No-idle zones trigger events if objects remain in a predefined zone for too long or leave it when they shouldn’t. Deep motion detection tasks monitor selected areas and filter out movements such as rain or swaying trees to stop them constantly triggering alerts.</p><h2 id="synology-dva3219-review-hardware-and-deployment">Synology DVA3219 review: Hardware and deployment</h2><p>Costing nearly £1,300, the DV3219 looks good value when stacked up against the completion. The Axis S1116 MT surveillance appliance, for example, comes with a single 8TB HDD and 16 camera licenses included but costs nearly £3,000. </p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="afRKxMuBVWGMivdn93kSp7" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/afRKxMuBVWGMivdn93kSp7.png" mos="https://cdn.mos.cms.futurecdn.net/afRKxMuBVWGMivdn93kSp7.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The appliance is well built and very quiet, making it suitable for small offices. At the rear, you have four Gigabit, dual USB 3 and two eSATA storage expansion ports but the HDMI, DisplayPort and DVI outputs on the Nvidia card are hidden behind a blanking plate.</p><p>Deployment is swift: we fitted three 14TB Seagate IronWolf NAS drives, used Synology’s discovery web portal to install the DSM software and created <a href="https://www.itpro.com/server-storage/34537/raid-levels-explained" target="_blank" data-original-url="https://www.itpro.com/server-storage/34537/raid-levels-explained">a RAID5 storage pool</a> from the Storage Manager app. You’ll need to install the Surveillance Station 8.2 app from the Package Center but this is easily done and the camera license pack is automatically applied. </p><p>The DVA3219 has extra levels of versatility as it runs the standard DSM software so every Synology app is available. If your surveillance needs are modest, it can also act as a NAS, IP SAN and backup server.</p><h2 id="synology-dva3219-review-deep-video-analytics">Synology DVA3219 review: Deep Video Analytics</h2><p>The DVA app is ready and waiting in the Surveillance Station web console and to test people counting, we used a D-Link 2MP dome camera mounted over the lab entrance. It requires a steady mouse hand as you create a detection zone in the DVA task preview screen, shape and position it and then define a head size. </p><p>Initially, it would only count people entering the lab but after a few adjustments, we had had it logging all entries and exits and could view graphs of daily, monthly and yearly footfall. A heat-map feature would have increased its value in retail environments; rivals with this capability provide a coloured map overlay showing customer dwelling habits, allowing shops to see how different areas of their store are performing.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/server-storage/network-attached-storage-nas/354213/qsan-xcubenas-xn5012re-review-powerful-data" data-original-url="/server-storage/network-attached-storage-nas/354213/qsan-xcubenas-xn5012re-review-powerful-data">Qsan XCubeNAS XN5012RE review: Powerful data protection</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/nas/27920/best-nas-drives" data-original-url="/nas/27920/best-nas-drives">Best NAS drives 2023: Which network storage appliance is right for you?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-attached-storage-nas/34313/synology-sa3400-review-a-big-nas-for-big-businesses" data-original-url="/network-attached-storage-nas/34313/synology-sa3400-review-a-big-nas-for-big-businesses">Synology SA3400 review: A big NAS for big businesses</a></p></div></div><p>For deep motion detection tasks, you’ll need to define up to two polygonal detection zones, each with individual sensitivity settings. Using a D-Link external bullet camera, we deliberately set the zone to include some trees and found that even in windy conditions, their leafy waves didn’t trigger motion detection.</p><p>It gets even easier with intrusion detection; just draw a line in the task preview window to denote a digital barrier, and anything crossing it will trigger alerts. Likewise with no-idle tasks: create a zone, choose a dwell time in seconds and decide whether a trigger is activated if something enters or leaves it. </p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="e9AfAHehpDoemjmnAyb357" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/e9AfAHehpDoemjmnAyb357.png" mos="https://cdn.mos.cms.futurecdn.net/e9AfAHehpDoemjmnAyb357.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Another useful feature is crowd control where a people counting task can trigger an alert if entries minus exits exceeds a specific number. These all make the appliance very versatile although it’s annoying that Synology limits the number of DVA tasks to four.</p><h2 id="synology-dva3219-review-standard-surveillance-features">Synology DVA3219 review: Standard surveillance features</h2><p>The DVA3219 supports up to 32 IP camera feeds and apart from DVA, offers all the same surveillance features as those found on other Synology appliances. Recording options are outstanding as you can set selected cameras to record to a daily schedule, when motion detection events have been triggered, or to just record continuously. </p><p>If your cameras support multiple video streams, you can apply different recording settings to each one and use the dynamic option to automatically change the recording stream if motion detection as triggered. It’s easy to manage your video vault too. For each camera, you choose which volume to send its recordings to, set the number of days they should be retained for and control the size of their archive.</p><p>A good surveillance solution is also measured by its search facilities and the TimeLine app provides a wealth of features so you don’t have to wade through recordings. Choose to view events such as motion detection for a selected camera and its calendar view will highlight those days when they were triggered, with a slider bar alongside for moving to a specific time.</p><p>The Smart Search feature in Synology’s Windows desktop client goes further still, allowing you to look for motion, missing or foreign object, no-idle zone and camera tampering events. You can fine-tune searches by drawing a detection zone within the camera view and only look for events that occurred within this space.</p><h2 id="synology-dva3219-review-verdict">Synology DVA3219 review: Verdict</h2><p>The DVA3219 makes sense if you want the additional deep video <a href="https://www.itpro.com/business-intelligence/28220/what-is-data-analytics" target="_blank" data-original-url="https://www.itpro.com/business-intelligence/28220/what-is-data-analytics">analytics features</a> in the Surveillance Station app but if not, you’re better off with one of Synology’s cheaper, non-GPU-equipped model. It is comparatively good value though, so if you want a brainy surveillance solution that can be easily deployed, the DVA3219 is hard to beat.</p><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >Desktop 4-bay</td></tr><tr><td  ><strong>CPU</strong></td><td  >2.1GHz quad-core Intel Atom C3538</td></tr><tr><td  ><strong>Memory</strong></td><td  >4GB DDR4 (max 32GB)</td></tr><tr><td  ><strong>GPU</strong></td><td  >Nvidia GeForce GTX 1050 Ti PCIe with 4GB GDDR5</td></tr><tr><td  ><strong>Storage</strong></td><td  >4 x SATA LFF/SFF hot-swap bays</td></tr><tr><td  ><strong>PSU</strong></td><td  >Inbuilt</td></tr><tr><td  ><strong>RAID support</strong></td><td  >RAID0, 1, 10, 5, 6, SHR</td></tr><tr><td  ><strong>Network</strong></td><td  >4 x Gigabit</td></tr><tr><td  ><strong>Other ports</strong></td><td  >3 x USB 3, 2 x eSATA expansion ports</td></tr><tr><td  ><strong>Management</strong></td><td  >Web browser, Windows desktop client</td></tr><tr><td  ><strong>Warranty</strong></td><td  >3 years limited</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cambridge Analytica: US Congress probes data firm set up by ex-Cambridge Analytica employee ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-protection/30792/cambridge-analytica-facebook-scandal</link>
                                                                            <description>
                            <![CDATA[ Congress wants to know whether it's collecting data from apps or using data brokers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sURu6oN48phepxGQ5DKm2v</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/h9yjRSnwZovokWdfr2Dfhe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 02 Jul 2018 06:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/h9yjRSnwZovokWdfr2Dfhe-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/h9yjRSnwZovokWdfr2Dfhe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>US Congress has requested that ex-Cambridge Analytica employee Matt Oczkowski answer questions regarding the use of data by his new company Data Propria.</p><p>Oczkowski has been asked to explain whether the data being used by Data Propria was supplied by researcher Aleksandr Kogan, who collected data from millions of Facebook users in 2016, according to a letter sent by Democrats on the House Energy and Commerce Committee last week.</p><p>"Given news reports indicating that Data Propria is being led by former Cambridge Analytica employees, including yourself, we believe the American people must be assured that Data Propria is not using consumer data wrongfully obtained by Cambridge Analytica or engaging in other inappropriate practices," the letter said.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-mining/31053/cambridge-analytica-closes-but-ico-investigation-rolls-on" data-original-url="/data-mining/31053/cambridge-analytica-closes-but-ico-investigation-rolls-on">Cambridge Analytica closes but ICO investigation rolls on</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/30795/cambridge-analytica-and-facebook-what-happened-and-has-it-impacted-any-votes" data-original-url="/data-insights/30795/cambridge-analytica-and-facebook-what-happened-and-has-it-impacted-any-votes">Cambridge Analytica and Facebook: What happened and has it impacted any votes?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/28683/ico-investigating-use-of-data-in-political-campaigns" data-original-url="/strategy/28683/ico-investigating-use-of-data-in-political-campaigns">ICO investigating use of data in political campaigns</a></p></div></div><p>Not only does Congress want Oczkowski to spill the beans on whether the data it's using as collected via Facebook, Democrats including Frank Pallone, Jr., Mike Doyle and Jan Schakowsky want to understand exactly how Data Propria is getting its data from Facebook, data brokers or other means.</p><p>It also requested that Data Propria advise Congress on whether or not it's telling consumers how their data is being used and if it's using the data for consulting purposes. For companies in the US, there's no legal requirement to disclose this information if customers request it, unlike the stringent rules imposed on those in the EU by <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a>. </p><p>"You have acknowledged in interviews with press that the work of Data Propria will be very similar to Cambridge Analytica," the group continued in their letter. "The admitted overlap between the personnel and work of Cambridge Analytica and Data Propria raises serious concerns about Data Propria's practices regarding the collection and use of Americans' personal information."</p><p><strong>05/06/2018: SCL Elections ignores watchdog order to hand over user's data</strong></p><p>Cambridge Analytica has refused to comply with a deadline to hand over the data it holds on a US citizen, throwing a regulatory battle between itself and the Information Commissioner's Office (ICO) into "uncharted waters".</p><p>The ICO had given the now-defunct political consultancy firm until Monday to comply with a legal notice after Professor David Carroll filed a Subject Access Request (SAR) under the Data Protection Act 1998 to discover what information the company held on him.</p><p>But the organisation's data controller, SCL Elections, failed to respond to the ICO's enforcement order - with the UK data regulator now considering prosecution.</p><p>"We are looking at the apparent failure to comply with our Enforcement Notice by SCL Elections Limited and its directors," an ICO spokesperson told <em>IT Pro</em>. "A decision on options for next steps, including any decision on prosecution, will now be taken in line with the prosecutors code."</p><p>Despite being a US citizen, Professor Carroll launched a landmark test case in 2017 under UK data protection law, after learning that Cambridge Analytica had processed his personal data in the UK as part of its alleged profiling of US voters for work on the Trump presidential election campaign. His case, separately filed with the High Court, was backed by the ICO, with its outcome bearing implications for millions of Americans whose data had also been harvested by the company.</p><p>However, Cambridge Analytica did not recognise his right to submit a SAR as a non-UK citizen, and refused to provide the full extent of the data it held. Consequently the ICO last month issued a <a href="https://ico.org.uk/media/action-weve-taken/enforcement-notices/2258812/en-scl-elections-20180504.pdf" target="_blank">legal notice</a> for SCL Elections to comply in full - or face prosecution.</p><p>"My story is a peculiar example of how the typically American deference to the tech companies and a reluctance to consider comprehensive privacy rules contrasts with strong data protection regimes, enforced by a muscular regulator equipped with the necessary tools," said Carroll, giving evidence before the European Union's (EU) Civil Liberties, Justice and Home Affairs (LIBE) committee yesterday.</p><p>He revealed that Cambridge Analytica administrators had not yet provided the ICO with the login credentials to recover his data from its servers, which the regulator seized earlier this year as it investigates the use of data in political campaigns.</p><p>He later <a href="https://twitter.com/profcarroll/status/1003709748515082246" target="_blank">tweeted</a>: "The company did not respond to the @ICOnews Enforcement Order due today. We are now in uncharted waters."</p><p>Information commissioner Elizabeth Denham, also giving evidence before the LIBE committee, outlined the scale of the ICO's probe into the misuse of data in political campaigning, branding it the "largest investigation ever undertaken by a data protection authority".</p><p>Involving 40 full-time ICO staff as well as a further 20 external legal and forensic IT recovery experts, the enquiry is examining more than 30 separate organisations, and the actions of around a dozen individuals.</p><p>"We are investigating social media platforms, data brokers, analytics firms, political parties and campaign groups and academic institutions," <a href="https://ico.org.uk/media/about-the-ico/documents/2259093/ico-opening-remarks-ep-libe-facebook-cambridge-analytica-20180604.pdf" target="_blank">she told the committee</a>, adding: "We are looking at both regulatory and criminal breaches. We are working with other regulators, EU Data protection authorities and law enforcement in the UK and abroad."</p><p>Denham added the ICO has seized dozens of servers containing hundreds of terabytes of data from several searches, and has conducted dozens of interviews.</p><p>"We are looking at the complete range of sanctions at our disposal at this time including our new powers under the new UK Data Protection Act for no-notice inspections, quicker warrants, to compel delivery of evidence and to seal digital evidence where it cannot be immediately recovered," she continued.</p><p>Cambridge Analytica, which specialised in data analysis and strategic communication, shut down in early May, blaming "a siege of media coverage" that drove away its customers and suppliers, as it commenced parallel bankruptcy proceedings in the US.</p><p>"Over the past several months, Cambridge Analytica has been the subject of numerous unfounded accusations," the company said at the time, adding that despite trying to "correct the record" it has has been "vilified for activities that are not only legal, but also widely accepted as a standard component of online advertising in both the political and commercial arenas".</p><p>The ICO has made clear that companies shutting themselves down must still comply with subject access requests like Professor Carroll's. The regulator will publish a report outlining the wider implications of its ongoing investigations before the end of June, which will include a series of recommendations on regulatory gaps in areas such as data protection.</p><p><em>Picture: Shutterstock</em></p><p><strong>08/05/2018: ICO orders firm to hand over data to US citizen</strong></p><p>The UK's data protection watchdog has served a <a href="https://ico.org.uk/media/action-weve-taken/enforcement-notices/2258812/en-scl-elections-20180504.pdf">legal notice</a> to Cambridge Analytica, ordering it to give a US academic all of the personal data it holds on him.</p><p>Professor David Carroll, who is based at the Parson School of Design in New York, had filed a Subject Access Request (SAR) under the terms of the <a href="https://www.itpro.com/data-protection/28085/what-is-the-data-protection-act-1998" target="_blank" data-original-url="https://www.itpro.com/data-protection/28085/what-is-the-data-protection-act-1998">Data Protection Act 1998</a> to Cambridge Analytica after the scandal broke that the data modelling company <a href="https://www.itpro.com/data-protection/30792/cambridge-analytica-facebook-scandal" target="_blank" data-original-url="https://www.itpro.com/data-protection/30792/cambridge-analytica-facebook-scandal">had allegedly amassed 240 million Americans' Facebook profile data</a>.</p><p>However, he only received information that showed how the company had scored him on certain political categories, such as gun control and national security, leading him he to believe the information was incomplete and launch legal action.</p><p>Cambridge Analytica's data controller is UK-based company SCL Elections, and Professor Carroll took his case to England's High Court, and also filed a complaint with the UK Information Commissioner's Office (ICO).</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-mining/31053/cambridge-analytica-closes-but-ico-investigation-rolls-on" data-original-url="/data-mining/31053/cambridge-analytica-closes-but-ico-investigation-rolls-on">Cambridge Analytica closes but ICO investigation rolls on</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/30795/cambridge-analytica-and-facebook-what-happened-and-has-it-impacted-any-votes" data-original-url="/data-insights/30795/cambridge-analytica-and-facebook-what-happened-and-has-it-impacted-any-votes">Cambridge Analytica and Facebook: What happened and has it impacted any votes?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/28683/ico-investigating-use-of-data-in-political-campaigns" data-original-url="/strategy/28683/ico-investigating-use-of-data-in-political-campaigns">ICO investigating use of data in political campaigns</a></p></div></div><p>The ICO said that not only does it believe Cambridge Analytica held back information, but pointed out that the firm did not offer an adequate explanation of where it had obtained Professor Carroll's data, or how it would be used.</p><p>However, <a href="https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/05/ico-serves-enforcement-notice-on-scl-elections-ltd">in a statement</a>, information commissioner Elizabeth Denham, said that SCL Elections was unwilling to cooperate with its investigation over Professor Carroll's personal data.</p><p>"The company has consistently refused to cooperate with our investigation into this case and has refused to answer our specific enquiries in relation to the complainant's personal data - what they had, where they got it from and on what legal basis they held it," she said.</p><p>"The right to request personal data that an organisation holds about you is a cornerstone right in data protection law and it is important that Professor Carroll, and other members of the public, understand what personal data Cambridge Analytica held and how they analysed it."</p><p>The regulator's decision means potentially millions of US Facebook users whose data was harvested by Cambridge Analytica could make similar demands of the organisation.</p><p>Both Cambridge Analytica and SCL Elections have filed for insolvency after the Facebook data harvesting scandal and have questioned the ICO's jurisdiction given the data in question belongs to an American citizen, but the ICO doesn't agree and has warned the companies could face criminal charges for withholding the information.</p><p>"We are aware of recent media reports concerning Cambridge Analytica's future but whether or not the people behind the company decide to fold their operation, a continued refusal to engage with the ICO will potentially breach an Enforcement Notice and that then becomes a criminal matter," Denham added.</p><p>While Cambridge Analytica is closing, some of the people involved in the firm <a href="https://www.itpro.com/data-mining/31053/cambridge-analytica-closes-but-ico-investigation-rolls-on" target="_blank" data-original-url="https://www.itpro.com/data-mining/31053/cambridge-analytica-closes-but-ico-investigation-rolls-on">have started another venture called Emerdata</a>.</p><p><em>Picture: Shutterstock</em></p><p><strong>19/04/2018: Alexander Nix may face formal summons to Parliament</strong></p><p>Alexander Nix, the suspended CEO of Cambridge Analytica, may face an official summons to appear before the Digital, Cultural, Media and Sport Committee after refusing to attend voluntarily.</p><p>The committee wanted him to address inconsistencies in testimony he gave in February stating that Cambridge Analytica did not have or work with Facebook users' data. Shortly afterwards, <em>The Observer</em> revealed that Cambridge Analytica allegedly had access to tens of millions of Facebook profiles.</p><p>Nix's lawyers said on Tuesday, however, that Nix was "not able to give evidence tomorrow as a consequence of him having been served with an information notice and being subject of a criminal investigation by the Information Commissioner's Office".</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-mining/31053/cambridge-analytica-closes-but-ico-investigation-rolls-on" data-original-url="/data-mining/31053/cambridge-analytica-closes-but-ico-investigation-rolls-on">Cambridge Analytica closes but ICO investigation rolls on</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/30795/cambridge-analytica-and-facebook-what-happened-and-has-it-impacted-any-votes" data-original-url="/data-insights/30795/cambridge-analytica-and-facebook-what-happened-and-has-it-impacted-any-votes">Cambridge Analytica and Facebook: What happened and has it impacted any votes?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/28683/ico-investigating-use-of-data-in-political-campaigns" data-original-url="/strategy/28683/ico-investigating-use-of-data-in-political-campaigns">ICO investigating use of data in political campaigns</a></p></div></div><p>In response, committee chairman Damian Collins said he may order Nix to give more evidence to the committee.</p><p>"It is certainly the intention of the committee to take this further and consider issuing a summons for Mr. Nix to appear on a named day at some point in the near future," said Collins, who <a href="https://www.theguardian.com/uk-news/2018/apr/17/cambridge-analytica-chief-alexander-nix-refuses-to-appear-before-fake-news-inquiry" target="_blank">warned Nix last month</a> on the severity of giving false statements to a select committee.</p><p>Though Nix did not appear, Cambridge Analytica whistleblower Brittainy Kaiser delivered written testimony and documents to the committee on Tuesday.</p><p>Kaiser wrote that Arron Banks of Leave.EU collected the personal data of people he sold car insurance to through his company GoSkippy, and that this data may have been used to target possible Brexit supporters.</p><p>"I do not believe Banks's written evidence to this inquiry is a full account of what happened," said Kaiser, submitting proposals for projects under Banks, along with supporting emails.</p><p>Cambridge Analytica also used quizzes to mine data on users, including a "sex compass" quiz, according to <a href="https://www.parliament.uk/documents/commons-committees/culture-media-and-sport/Brittany%20Kaiser%20Parliamentary%20testimony%20FINAL.pdf" target="_blank">Kaiser's testimony</a>.</p><p>"I do not know the specifics of these surveys or how the data was acquired or processed," said Kaiser.</p><p>She started the #OwnYourData campaign to push Mark Zuckerberg to change Facebook's terms of service so users get more rights over their own data. The campaign, which has 147,000 signatures, asks Zuckerberg to respond by the end of April. Facebook <a href="https://www.itpro.com/data-protection/28029/latest-gdpr-news-uk" target="_blank" data-original-url="https://www.itpro.com/data-protection/28029/latest-gdpr-news-uk">today introduced changes to its terms and conditions</a> that bring them in line with the EU's impending GDPR data protection legislation.</p><p><strong>12/04/2018: Zuckerberg claims ignorance about 'shadow profiles'</strong></p><p>Facebook founder Mark Zuckerberg was grilled by members of a US congressional committee over the social network's use of so-called "Shadow Profiles".</p><p>Shadow Profiles are said to be data collected by Facebook about non-users of the network, such as email addresses, names tagged in photos, or details in a smartphone contact list. This data is hidden from users but used to recommend friends and new connections as well as social data analysis. This data is not normally disclosed to account owners but is used in Facebook's "People You May Know" feature.</p><p>The existence of shadow profiles came to light in 2013 when a bug in Facebook showed not just contact details of a user's friend's in a download file but also their friend's shadow contact information.</p><p>At the hearing, of the US House Energy and Commerce Committee, New Mexico Representative Ben Lujan asked Zuckerberg about these profiles.</p><p>Zuckerberg replied that "in general we collect data on people who have not signed up for Facebook for security purposes to prevent the kind of scraping you were just referring to."</p><p>Zuckerberg denied he was familiar with the term "Shadow Profile". Lujan then asked how many data points on average Facebook collects on its users. Zuckerberg replied that he did not know.</p><p>Lujan then asked how many data points Facebook collected on non-users. Again, Zuckerberg said he did not know. Lujan then asked how someone who does not have a Facebook account opt out of Facebook's involuntary data collection?</p><p>The Facebook CEO responded that "anyone e can turn off and opt out of any data collection for ads, whether they use our services or not." He then suggested that Facebook still needed to collect non-user data for security reasons.</p><p>"In order to prevent people from scraping public information [...] we need to know when someone is repeatedly trying to access our services," he told the committee.</p><p>Lujan pointed out to Zuckerberg that non-users wanting to request what data it has on them need to go a Facebook page and sign up for an account to access their data.</p><p><strong>11/04/2018: Zuckerberg deflects US regulations in first Senate hearing</strong></p><p>Facebook CEO Mark Zuckerberg emerged relatively unscathed from the first of two US Senate hearings, managing to deflect attempts to enforce tougher regulations on the social media platform.</p><p>During a grilling by a joint committee of 44 US Senators, the 33-year-old internet mogul took full responsibility company failings that led to the improper sharing of data on approximately 87 million Facebook users, however, made no commitments to supporting any specific reactionary legislation drawn up by Congress.</p><p>Zuckerberg began with an opening speech that was released ahead of schedule, followed by a series of questions aimed at probing Facebook's business model and the events leading to the exploitation of the platform by Cambridge Analytica.</p><p>He admitted that the company had failed to audit the agreement drawn up with Cambridge Analytica, and said that it had become apparent that the firm had misled Facebook to exploit its algorithms.</p><p>He also conceded that following the discovery of the data breach in 2015, failing to notify both the Federal Trade Commission and the public immediately was a mistake, though he believed the case to be "closed" after dealing with the issue internally.</p><p>On the question of whether Zuckerberg would support the introduction of legislation Zuckerberg said:</p><p>"I'll have my team follow up with you so that way we can have this discussion across the different categories where I think this discussion needs to happen."</p><p>Shares in the company fell sharply on the news of the Cambridge Analytica scandal, however, investors were clearly happy with Zuckerberg's performance on Tuesday, as shares saw the single biggest daily jump in almost two years, up by 4.5%.</p><p>It could be argued that some Senators' questions failed to probe enough into the failings behind the scandal, as many were targeted at Facebook's business model or the way it currently manages data on the platform.</p><p>At one point, it appeared Zuckerberg was answering basic questions on how an internet company operates. Senator Orrin Hatch asked: "How do you sustain a business model in which users don't pay for your service?"</p><p>"Senator, we run ads," said Zuckerberg.</p><p>This was shortly followed by a question by Senator John Kennedy on whether the company would work on providing better ways for users to delete their data, only for Zuckerberg to highlight that such functions already exist.</p><p>It wasn't all smooth sailing for the CEO however. At around 2 hours into the hearing, Senator Lindsey Graham from South Carolina launched a barrage of questions on the subject of market monopolies and customer choice, frequently interrupting Zuckerberg before he could finish answering.</p><p>On the question of what competitors Facebook has, Zuckerberg attempted to offer up rival tech companies such as Google, Apple and Twitter, only for the Senator to dismiss them as he believes Facebook offers a unique service.</p><p>Graham: "I'm talking about is there real competition you face. Because car companies face a lot of competition. If they make a defective car, it gets out in the world, people stop buying that car, they buy another one. Is there an alternative to Facebook in the private sector?"</p><p>Zuckerberg: "Yes Senator, the average American uses 8 different apps...to communicate with their friends and stay in touch with people, ranging from text to email."</p><p>Graham: "OK, which is the same service that you provide."</p><p>Zuckerberg: "Well, we provide a number of different services."</p><p>Graham: "Is Twitter the same as what you do?"</p><p>Zuckerberg: "It overlaps with a portion of what we do."</p><p>Graham: "You don't think you have a monopoly?"</p><p>Zuckerberg responded with a pause, before adding that "it certainly doesn't feel like that to me!", prompting laughter from the chamber.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/983843066019753984"></a></p></blockquote><div class="see-more__filter"></div></div><p>While this moment was perhaps the toughest for Zuckerberg, other Senators were clearly displeased with his answers.</p><p>Writing on Twitter after the hearing, Senator Kamala Harris said: "Mark Zuckerberg's failure to answer several critical questions during his appearance before the Senate today leaves me concerned about how much Facebook values trust and transparency."</p><p>Tuesday's hearing was the first of two for Zuckerberg, who is also due to appear before the House Energy and Commerce Committee on Wednesday.</p><p>Speaking on Tuesday, Senator John Thune said a separate hearing would be held specifically on Cambridge Analytica, and other companies that may have been involved with the improper sharing of data on Facebook.</p><p><strong>10/04/2018: Zuckerberg apologises for data scandal ahead of Congress hearing</strong></p><p>Facebook CEO Mark Zuckerberg has apologised for failings in his company's data protection policies that led to 87 million users having their information improperly shared to third-parties, according to documents released yesterday ahead of his Congressional hearing on Tuesday.</p><p>Zuckerberg, who is due to appear before Congress to answer questions relating to improper data sharing deals on the social media site, also took responsibility for failing to stop the spread of fake news to influence public opinion.</p><p>"Facebook is an idealistic and optimistic company," said Zuckerberg, in a transcript compiled by <em><a href="https://www.cnbc.com/2018/04/09/congress-released-mark-zuckerbergs-prepared-testimony-ahead-of-wednesdays-hearing.html">CNBC</a></em>. "For most of our existence, we focused on all the good that connecting people can bring.</p><p>"But it's clear now that we didn't do enough to prevent these tools from being used for harm as well. That goes for fake news, foreign interference in elections, and hate speech, as well as developers and data privacy."</p><p>"We didn't take a broad enough view of our responsibility, and that was a big mistake," he added. "It was my mistake, and I'm sorry. I started Facebook, I run it, and I'm responsible for what happens here."</p><p>In the documents released ahead of Tuesday's hearing, Zuckerberg said the company was committed to making changes to policy that would "significantly impact our profitability", but these would take some time to implement.</p><p>The scandal surrounding Facebook and its data policies show no sign of abating. Recent reports from New Zealand suggest that as many as 63,714 users could have had their information exposed to Cambridge Analytica's data harvesting, after only 10 people took part in an online personality quiz.</p><p>John Edwards, New Zealand's data protection commissioner, said he was urgently reviewing the case and would seek answers from Facebook on how the data was being used by Cambridge Analytica, according to the <a href="https://www.theguardian.com/technology/2018/apr/10/facebook-data-breach-hits-63714-new-zealanders-after-10-people-download-quiz"><em>Guardian</em></a>.</p><p>Edwards reportedly deleted his Facebook account upon hearing news of the incident and has said that New Zealanders should consider doing the same.</p><p>Apple's co-founder, Steve Wozniak, told <em><a href="https://www.usatoday.com/story/tech/2018/04/08/apple-co-founder-steve-wozniak-says-hes-leaving-facebook/497392002">USA Today</a></em> that he would also be deleting his Facebook account over concerns that the social media site was becoming increasingly careless with user data.</p><p>"Users provide every detail of their life to Facebook and ... Facebook makes a lot of advertising money off this," he said to the newspaper. "The profits are all based on the user's info, but the users get none of the profits back."</p><p>Zuckerberg will appear before a joint hearing of the US Senate Judiciary and Commerce committee on Tuesday 10 April at 2:15 pm ET (7.15pm BST), and again before the US House Energy and Commerce Committee on Wednesday at 10 am ET (3 am BST). Details on how to watch Tuesday's hearing <a href="https://www.itpro.com/data-protection/30907/mark-zuckerberg-at-congress-why-when-and-where-to-watch" data-original-url="https://www.itpro.com/data-protection/30907/mark-zuckerberg-at-congress-why-when-and-where-to-watch">can be found here</a>.</p><p><strong>06/04/2018: Sheryl Sandberg admits 'mistakes'</strong></p><p>Weeks after the Cambridge Analytica scandal first started making headlines, Facebook's chief operating officer (COO), Sheryl Sandberg, has finally broken her silence on the matter.</p><p>Speaking to the <em>Financial Times</em>, Sandberg admitted the company had underinvested in safety and security but added that this attitude was changing. Indeed, there has been a flurry of announcements this week from senior figures detailing changes that have been made to the way the company shares data and giving users more granular control over what data Facebook holds on them (read on below).</p><p>"We made mistakes and I own them and they are on me," <a href="https://www.ft.com/content/9e973ba4-3903-11e8-8eee-e06bde01c544">Sandberg told <em>the FT</em></a>, adding: "There are operational things that we need to change in this company and we are changing them ... We have to learn from our mistakes and we need to take action."</p><p>Although Facebook admitted earlier this week that around 87 million of its 2.2 billion users are thought to have had their data scraped by Cambridge Analytica, Sandberg said the company is in the dark as to what exactly was taken, because it can't undertake an internal probe until the one being conducted by the Information Commissioner's Office (ICO) in the UK is completed.</p><p>Sandberg also acknowledged that she and CEO Mark Zuckerberg should have spoken out on the matter sooner, but added that they "wanted to make sure [they] knew exactly what happened" before making any public statements.</p><p>She also claimed that Russian meddling in the US election in 2016 through disinformation and incendiary posts took the social platform's top executives by surprise.</p><p>"Things happened in 2016 which we were too slow to understand. Now we are following and investigating very thoroughly," she said.</p><p>Her comments come after Zuckerberg held a press Q&A in which he admitted the company hadn't done enough to ensure third-party apps were using people's data responsibly and in line with Facebook's terms and conditions.</p><p>"In retrospect, I think we clearly should have been doing more all along," he said.</p><p>Facebook yesterday revealed new measures <a href="https://www.itpro.com/data-protection/28029/latest-gdpr-news-uk" data-original-url="https://www.itpro.com/data-protection/28029/latest-gdpr-news-uk">to bring Facebook's data protection policies in line with the EU's tougher rules</a> coming into force next month, including making the policy easier to understand, and explaining how and why Facebook uses people's information.</p><p><strong>05/04/2018: Facebook admits it 'could have done more' to scrutinise third-party apps</strong></p><p>Mark Zuckerberg has admitted that Facebook "should have been doing more" to ensure third-party companies were using the social network's data responsibly, as revised figures suggest as many as 87 million users may have been affected by the Cambridge Analytica scandal.</p><p>The admission came as Facebook's chief faced a grilling from the press over the company's data protection practices and how much it scrutinised those services accessing social media data.</p><p>"In retrospect, I think we clearly should have been doing more all along," said Zuckerberg, speaking at the conference on Wednesday. "I'm not trying to defend this now: I think our view in a number of aspects of our relationship with people is that our job is to give them tools, and that it was largely people's responsibility how they chose to use them.</p><p>"I think it was wrong in retrospect to have that limited of a view," he added. "I think we need to take a broader view of our responsibility."</p><p>Facebook now believes as many as 87 million users may have had their data improperly shared with Cambridge Analytica as a result of past policies, some 37 million more than previously thought.</p><p>"We wanted to take a broad view that is a conservative estimate," said Zuckerberg. "I am quite confident that given our analysis that it is not more than 87 million. It very well could be less, but we wanted to put out the maximum we felt that it could be as that analysis says."</p><p>In response to concerns about its data protection policies, Facebook has said it now intends to roll out <a href="https://www.itpro.com/data-protection/28029/latest-gdpr-news-uk" data-original-url="https://www.itpro.com/data-protection/28029/latest-gdpr-news-uk">EU General Data Protection Regulations worldwide</a>, dismissing <a href="https://www.theguardian.com/technology/2018/apr/04/facebook-gdpr-stronger-privacy-protections-eu-data-protection-law-mark-zuckerberg">earlier reports</a> that the measures would be diluted for US users.</p><p>Facebook also announced a string of updates to its API that aim to restrict the access third-parties have to user data. This includes a new App Controls link at the top of a user's news feed that gives an overview of the data they're sharing with third-party applications. As part of this addition, Facebook will also be telling users if their data had been improperly shared with Cambridge Analytica.</p><p>From now on, if a user allows an app to access data on the events they're attending, that app will no longer have free reign to scrape information from the list of users also interested in the event.</p><p>Apps will also no longer be able to use the Pages API to access posts or comments on any page by default, and instead only those "providing useful services to our community" will be able to petition Facebook for approval.</p><p>The ways in which Facebook groups work are also changing. Instead of a single member being able to give permission for an app to access group content, any third-parties using the API will need to be approved by Facebook first.</p><p>The ability to search for a person using their phone number or email address has also been scrapped, after it was found that the feature was being abused to harvest profile data, and any application seeking to access a user's feed, including likes, posts and photos, will need to first ask Facebook.</p><p>Last week it was revealed that Facebook had been storing user call and text histories as part of an opt-in feature on the Android version of Facebook. Although it appears the company will still maintain this practice, Facebook has said it will review the data it collects to ensure no message content is stored, and that it will delete all logs older than one year. Broader data, such as the time of calls, will now no longer be collected.</p><p>Zuckerberg revealed that his company had opened an investigation into the data Cambridge Analytica data agreement, as it still doesn't know exactly what information the firm held on its systems. However, this has since been put on hold while the UK's Information Commissioner's Office conducts its own investigation, which includes the examination of files taken during a raid on Cambridge Analytica's London headquarters in March.</p><p>Zuckerberg is <a href="https://www.itpro.com/data-protection/30842/facebook-data-privacy-scandal" data-original-url="https://www.itpro.com/data-protection/30842/facebook-data-privacy-scandal">due to appear before Congress next week</a> to defend company policies, having already refused to testify before a UK parliamentary committee.</p><p><strong>26/03/2018: Cambridge Analytica: Watchdog examines 'evidence' after London office raid</strong></p><p>The UK's data watchdog raided Cambridge Analytica's London headquarters on Friday evening after finally getting a search warrant approved by a High Court judge.</p><p>Twenty officials from the Information Commissioner's Office entered the Oxford Street address at 8pm to look for evidence relating to allegations the analytics firm harvested data from 50 million Facebook users without their consent.</p><p>The property search lasted seven hours, and an undisclosed volume of evidence was taken from the property, the ICO said.</p><p>"We will now need to assess and consider the evidence before deciding the next steps and coming to any conclusions," an ICO spokesperson <a href="https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/03/ico-statement-investigation-into-data-analytics-for-political-purposes">said in a statement</a>. "This is one part of <a href="https://www.itpro.com/strategy/28683/ico-investigating-use-of-data-in-political-campaigns" data-original-url="https://www.itpro.com/strategy/28683/ico-investigating-use-of-data-in-political-campaigns">a larger investigation by the ICO</a> into the use of personal data and analytics by political campaigns, parties, social media companies and other commercial actors."</p><p>The ICO announced it was investigating the allegations against Cambridge Analytica on 17 March, and issued a Demand for Access to records two days later. However, the judge adjourned the case from last Wednesday to last Friday, meaning a warrant wasn't granted until late that evening. Media reports showed pictures of boxes being carried out of Cambridge Analytica's shared offices prior to the warrant hearings.</p><p>The search forms part of wider public scrutiny into whether Facebook did enough to secure the data it held on its users, as well as whether data was abused to influence elections.</p><p>A former Cambridge Analytica director told the <a href="https://www.theguardian.com/news/2018/mar/23/cambridge-analytica-misled-mps-over-work-for-leave-eu-says-ex-director-brittany-kaiser"><em>Guardian</em></a> on Friday that the firm's management deliberately misled the British public about its involvement with a pro-Brexit group, Leave.EU, during the referendum campaign period.</p><p>In an attempt to mitigate fallout, Facebook took out full-page adverts in both UK and US newspapers over the weekend, in which CEO Mark Zuckerberg said the incident was a "breach of trust" and said he was "sorry we didn't do more at the time".</p><p>His comments were later echoed by COO Sheryl Sandberg, who told <em>CNBC</em> on Friday that the case "was a critical moment for our company". "We are going to do everything we can," added Sandberg. "I would definitely have had Mark and myself out speaking earlier, but we were trying to get to the bottom of this."</p><p>Friday's raid kicked off a turbulent weekend for the social media company, which saw scathing opinion polls and fresh revelations of data misuse.</p><p>A <em><a href="https://www.reuters.com/article/us-facebook-cambridge-analytica-apology/americans-less-likely-to-trust-facebook-than-rivals-on-personal-data-idUSKBN1H10AF">Reuters</a></em> poll in the US found that less than half of Americans now trust Facebook to adhere to US privacy laws, while 60% of users in Germany believe social networks are negatively impacting the democratic process, according to national newspaper <em>Bild am Sonntag</em>.</p><p>There were also multiple reports of users downloading their account files stored on Facebook's website, only to discover that call data from mobile phones was also being logged, including who they called and for how long, seemingly without their knowledge.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/977325434030428160"></a></p></blockquote><div class="see-more__filter"></div></div><p>Facebook has <a href="https://newsroom.fb.com/news/2018/03/fact-check-your-call-and-sms-history">since refuted the claim</a> that this was done secretly, pointing to a usage agreement as part of its Messenger platform that allows users to opt-in to call and text history logging.</p><p>Zuckerberg has now been called to appear before a UK parliamentary committee to give evidence on the Cambridge Analytica's use of personal data. The committee has demanded a response by the end of today.</p><p><strong>22/03/2018: ICO must wait for warrant</strong></p><p>UK data watchdog the Information Commissioner's Office (ICO) will not get access to Cambridge Analytica's London offices until Friday at the earliest, after its demand for a warrant to search the premises was adjourned.</p><p>In a statement today, an ICO spokesperson said: "A High Court judge has adjourned the ICO's application for a warrant relating to Cambridge Analytica until Friday. The ICO will be in court to continue to pursue the warrant to obtain access to data and information to take forward our investigation."</p><p>While <em>IT Pro</em> asked the regulator why it was adjourned, a spokesperson declined to comment further. However, <em>Guardian</em> journalist Carole Cadwalladr reported that the judge granted an extension because Cambridge Analytica's legal counsel was unavailable.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/976811145792237568"></a></p></blockquote><div class="see-more__filter"></div></div><p>It means the ICO's planned raid of Cambridge Analytica's offices is further delayed, despite reports earlier this week claiming <a href="https://www.theguardian.com/uk-news/2018/mar/22/cambridge-analytica-warrant-high-court-adjourns-hearing-information-commissioner">boxes were being removed from the firm's shared premises on Tuesday</a>.</p><p>Meanwhile, Facebook CEO Mark Zuckerberg has finally broken his silence over allegations that Cambridge Analytica accessed the data of 50 million Facebook users without their consent, seeking to reassure users that a similar abuse of people's information could never happen again.</p><p>The scandal, which broke earlier this week, surrounds the use of a quiz developed for data mining and an analytics firm that harvested the data not just of those who used the app (thisisyourdigitallife), but also of all their Facebook friends.</p><p>Several days after the story first broke, Zuckerberg finally issued an official response through Facebook, which includes a timeline of events and an explanation of how an app could have accessed data from individuals who didn't have any direct contact with it.</p><p>The Facebook CEO said: "The good news is that the most important actions to prevent this from happening again today we have already taken years ago.</p><p>"In 2014, to prevent abusive apps, we announced that we were changing the entire platform to dramatically limit the data apps could access. Most importantly, apps like [thisisyourdigitallife] could no longer ask for data about a person's friends unless their friends had also authorized the app.</p><p>"We also required developers to get approval from us before they could request any sensitive data from people. These actions would prevent any app ... from being able to access so much data today."</p><p>However, he added that the company is taking further steps to tighten up how it guards user data, including revoking apps' access where users haven't used them for three months, and reducing the data first given to apps on sign in to just the user's name, profile picture and email address.</p><p>This is particularly significant as part of the broad range of data collected by Cambridge Analytica included very sensitive data such as sexuality, location, religion and political leanings, and apps could access this data indefinitely.</p><p>Zuckerberg also claimed that Cambridge Analytica has once again affirmed that it has deleted all the data linked to this case something it previously said it had done in 2015, but which an Observer article subsequently contradicted with the account of former employee and whistleblower Christopher Wylie.</p><p>Cambridge Analytica has voluntarily agreed to a full forensic audit to ensure this is the case, Zuckerberg added.</p><p>Meanwhile, Wylie, the ex-director of research at Cambridge Analytica who blew the whistle on this scandal, took to Twitter to confirm he would be accepting invitations to testify in front of several legislative bodies in the US and UK.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/976594279425630209"></a></p></blockquote><div class="see-more__filter"></div></div><p><strong>20/03/2018: ICO seeks warrant to raid London offices</strong></p><p>The UK's data privacy watchdog is seeking a warrant to raid Cambridge Analytica's London headquarters in order to investigate allegations that the company illegally harvested the information of 50 million Facebook profiles.</p><p>The Information Commissioner's Office (ICO) confirmed to <em>IT Pro</em> this morning that it is seeking an urgent warrant following the company's failure to comply with its request on 7 March for access to its databases and records.</p><p>"Cambridge Analytica has not responded to the commissioner by the deadline provided; therefore, the information commissioner is seeking a warrant to obtain information and access to systems and evidence related to her investigation," an ICO spokesman said.</p><p>The news follows an expos by <em><a href="https://www.theguardian.com/news/2018/mar/17/cambridge-analytica-facebook-influence-us-election">the Observer</a> </em>that claimed Cambridge Analytica had used the Facebook data of more than 50 million people in order to build a powerful predictive analytics algorithm that could accurately predict political preferences, sexuality and other personal traits.</p><p>It has also emerged that Facebook was in the process of conducting its own internal investigation into Cambridge Analytica's actions separately to the ICO, which it ceased yesterday at the regulator's behest. Damian Collins, chair of the culture select committee, expressed doubt as to Facebook's motives in conducting its own investigation, telling the <em>BBC</em> that "This is a matter for the authorities".</p><p>"The concern would have been, were they removing information or evidence which could have been vital to the investigation? It's right they stood down but it's astonishing they were there in the first place."</p><p>Facebook is planning an open meeting today, to let staff grill the company's management on the unfolding incident. According to <a href="https://www.theverge.com/2018/3/20/17142074/facebook-employee-meeting-cambridge-analytica"><em>the Verge</em></a>, the meeting will be led by Facebook deputy general counsel Paul Grewal, who will give staff background information on the case and field questions from staff.</p><p>It will mark the first time that staff have had an official opportunity to ask questions of the company's leadership since the scope of Cambridge Analytica's use of Facebook data was publicly revealed - although Facebook has admitted it was aware of the issue in 2015, a year after it happened.</p><p>The meeting is planned to last just half an hour, and an employee told the <em>Verge</em> that the move felt like a temporary solution to buy time until Friday's all-hands meeting where founder and CEO Mark Zuckerberg - who has thus far been silent on the issue - is expected to address employees. Collins has called on Zuckerberg or a senior Facebook executive to give evidence to his Parliamentary committee on the scandal.</p><p><strong><em>To understand what the Cambridge Analytica and Facebook scandal is all about, read <a href="https://www.itpro.com/data-insights/30795/cambridge-analytica-and-facebook-what-happened-and-has-it-impacted-any-votes" data-original-url="https://www.itpro.com/data-insights/30795/cambridge-analytica-and-facebook-what-happened-and-has-it-impacted-any-votes">our explainer</a>.</em></strong></p><p>Facebook maintains that this is not a data breach in the traditional sense, and is instead a misuse of legitimately-obtained data. Security expert Graham Cluley agreed with the assessment, but said it shows fundamental issues with Facebook's design. "From Facebook's point of view, it's not a traditional data breach," he told <em>IT Pro</em>. "That's because this is how Facebook was designed, and many apps over the years have scooped up users' information and (privacy settings permitting) those of their friends as well."</p><p>"Hundreds of millions of times every day Facebook hones the content it displays to you based on what it has determined you are interested in, who you are, and what it thinks will be most effective. So, it's not that different from what Cambridge Analytica does with the same access to the data," he added.</p><p>"None of this is news. Facebook has been working this way for years. The only way to reduce your exposure is to refuse to play Facebook's game and not be a member of the site. If you can't bring yourself to leave, at the very least lock down your privacy settings and reduce the level of information that you share."</p><p>Cambridge Analytica's CEO, Alexander Nix, was also caught in an undercover sting by Channel 4, which recorded Nix seemingly bragging about using ex-intelligence operatives, micro-targeted propaganda and 'honeypot' traps to influence elections and other political proceedings.</p><p>"We're used to operating through different vehicles, in the shadows, and I look forward to building a very long-term and secretive relationship with you," Nix told undercover reporters posing as potential clients in an initial phone call.</p><p>"We have two projects at the moment, which involve doing deep, deep depth research on the opposition and providing... really damaging source material, that we can decide how to deploy in the course of the campaign," he said as part of a later meeting recorded by Channel 4.</p><p>Cambridge Analytica denied that it uses any of the methods alleged by the investigation, and stated that it was simply 'humouring' the potential client.</p><p><strong>19/03/2018: Millions of Facebook profiles 'mined illegally' by Cambridge Analytica</strong></p><p>The personal data of 50 million Facebook users was leaked to a data analytics firm and used to help Donald Trump win the 2016 US presidential election, it has been claimed.</p><p>Cambridge Analytica used this information to build sophisticated software models in 2014 to target US voters with political advertising, according to a whistleblower who said he helped collect the data.</p><p>Facebook, which denied the incident amounted to a data breach, confirmed it knew about it in 2015 but didn't inform affected individuals or data protection regulators.</p><p>Whistleblower Christopher Wylie said he worked with a Cambridge University academic to collect user data via a third-party Facebook app called thisisyourdigitallife.</p><p>Aleksandr Kogan created the app through his company Global Science Research (GSR) and worked with Cambridge Analytica to pay 270,000 Facebook users to take part in a personality test. They also agreed to have their data, such as their home city and Facebook 'likes', collected for academic use.</p><p>But then-Analytica employee Wylie told the <a href="https://www.theguardian.com/news/2018/mar/17/cambridge-analytica-facebook-influence-us-election"><em>Observer</em></a>, which broke the story, that the app also collected data belonging to Facebook friends of the users who signed up to the quiz, producing a pool of data of tens of millions of people.</p><p>"We exploited Facebook to harvest millions of people's profiles," Wylie told the newspaper. "And built models to exploit what we knew about them and target their inner demons. That was the basis the entire company was built on."</p><p>Cambridge Analytica claimed it had deleted all the data shared by GSR when it discovered this information was collected in breach of Facebook's terms of service and had no reason to believe the data was obtained illegally.</p><p>"In 2014, we contracted a company led by a seemingly reputable academic at an internationally-renowned institution to undertake a large scale research project in the United States," its statement read.</p><p>"No data from GSR was used by Cambridge Analytica as part of the services it provided to the Donald Trump 2016 presidential campaign."</p><p>On the eve of the story breaking, Facebook said it has banned Cambridge Analytica from its platform.</p><p>In explaining its decision, Facebook said that while Kogan obtained people's data legitimately, by then sharing that information with Cambridge Analytica he had "lied" to the company and broken platform rules about not sharing such information with third-parties. Kogan maintains he acted legally and had a "close working relationship" with Facebook, the <em>Guardian</em> reports.</p><p>Facebook learned of this violation in 2015 and subsequently removed the app from its platform. It also "demanded certifications" from Kogan, Wylie and Cambridge Analytica that they had deleted the data.</p><p>However, while Wylie said he received a letter from Facebook lawyers in August 2016 to this effect, he claimed they never followed up to verify the data was deleted.</p><p>"That to me was the most astonishing thing," he said. "They waited two years and did absolutely nothing to check that the data was deleted. All they asked me to do was tick a box on a form and post it back."</p><p>The social network also failed to report the leak of data to the affected users or to US state regulators, because it claimed the event was not a data breach.</p><p>Facebook said: "Several days ago, we received reports that, contrary to the certifications we were given, not all data was deleted. We are moving aggressively to determine the accuracy of these claims.</p><p>"If true, this is another unacceptable violation of trust and the commitments they made. We are suspending SCL/Cambridge Analytica, Wylie and Kogan from Facebook, pending further information."</p><p>UK data protection regulator the Information Commissioner's Office <a href="https://www.itpro.com/strategy/28683/ico-investigating-use-of-data-in-political-campaigns" data-original-url="https://www.itpro.com/strategy/28683/ico-investigating-use-of-data-in-political-campaigns">is already conducting an investigation into the use of personal data in political campaigns</a> and confirmed it's looking into this incident as part of the investigation.</p><p>"Our investigation into the use of personal data for political campaigns, includes the acquisition and use of Facebook data by SCL [Strategic Communication Laboratories, which is affiliated with Cambridge Analytica], Doctor Kogan and Cambridge Analytica," said information commissioner Elizabeth Denham.</p><p>"This is a complex and far-reaching investigation for my office and any criminal or civil enforcement actions arising from it will be pursued vigorously."</p><p>Damian Collins MP, chair of the Digital, Culture, Media and Sport Committee, accused Cambridge Analytica CEO Alexander Nix of misleading the committee when he told the committee while giving evidence last month that his firm had not received any data from GSR.</p><p>Collins said: "It seems clear that he has deliberately mislead (sic) the committee and Parliament by giving false statements. We will be contacting Alexander Nix next week asking him to explain his comments, and answer further questions relating to the links between GSR and Cambridge Analytica, and its associate companies."</p><p>The committee will also demand that Facebook CEO Mark Zuckerberg, or someone similarly senior, attends the committee to answer questions about the incident.</p><p><em>Main image credit: Shutterstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to build a Raspberry Pi security camera ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/hardware/31258/how-to-build-a-raspberry-pi-security-camera</link>
                                                                            <description>
                            <![CDATA[ Build your own cut-price surveillance equipment ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">biy4rpbS9nFf3CqrnqLPWZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y9Ra55ZAQ6uX39vgs3zZXV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 06 Jun 2018 13:33:00 +0000</pubDate>                                                                                                                                <updated>Fri, 14 Feb 2020 10:24:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Mark Mayne ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y9Ra55ZAQ6uX39vgs3zZXV-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[CCTV]]></media:description>                                                            <media:text><![CDATA[CCTV]]></media:text>
                                <media:title type="plain"><![CDATA[CCTV]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y9Ra55ZAQ6uX39vgs3zZXV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>One of the most endearing things about the Raspberry Pi is how it can be used as the computational brain for all most any tech project. Its open-source nature means it has been used to create tiny PCs to being used as a form of Hadoop data base cluster; there's a huge swathe of projects that have used the micro computer at their core. </p><p>For the security conscious, the Raspberry Pi can be used to power a fledgeling home security camera system, providing one is willing to get involved in a little bit of DIY coding.</p><h2 id="choosing-your-hardware">Choosing your hardware</h2><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/31187/how-to-put-alexa-on-raspberry-pi" data-original-url="/hardware/31187/how-to-put-alexa-on-raspberry-pi">How to put Alexa on Raspberry Pi</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/21862/raspberry-pi-top-projects-to-try-yourself" data-original-url="/mobile/21862/raspberry-pi-top-projects-to-try-yourself">Raspberry Pi: Top projects to try yourself</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/31138/how-to-build-a-raspberry-pi-weather-station" data-original-url="/hardware/31138/how-to-build-a-raspberry-pi-weather-station">How to build a Raspberry Pi weather station</a></p></div></div><p>With the Raspberry Pi you can create a basic security camera to tinker with, but there's also scope to create a more fully-fledged system should you so desire. </p><p>That means there's an element of choice in how you approach a security camera project; you'll not only need to decide which Raspberry Pi model to go for, which will dictate the size of the camera system, but you'll also need to consider how it will connect to your home network and what type of camera module you'll want to use. </p><p>For example, a USB webcam will work as a makeshift security camera when connected to a Raspberry Pi, but you can get the official camera board to get more out of the security setup, as well as avoid any incomparability issues than might pop up. </p><p>There are two official options for this: the Raspberry Pi Camera v2 and the Raspberry Pi NoIR Camera v2, the latter being specifically designed for low-light applications. They both feature an 8 megapixel Sony IMX219 image sensor, which supports 1080p video at 30fps, 720p at 60 and 640x480p at 90fps. They connect direct to the Pi via a dedicated ribbon socket, and are supported natively in Raspbian. In short, one of these is your best choice, depending on whether you're planning mostly daytime video, or a significant amount of night/twilight work.</p><p>If you're planning a security camera system with dedicated hardware, then the cheaper Pi Zero W paired with one of the many night-vision kit cameras is worth considering, as this option keeps hardware costs, size and unwanted additional components to a minimum. Note, though, that the Pi Camera v2 needs an additional adaptor to work with the Pi Zero range.</p><p>Aside from your choice of Pi and camera combo, you'll need the usual USB power supply, an 8GB minimum SD/Micro SD card with Raspbian installed and either a monitor/keyboard/mouse or remote access enabled. Although you'll be able to get this project up and running without a case, you'll need to buy or build a suitable item depending on where you plan to monitor - weatherproof options are usually a good idea unless they''ll be living exclusively indoors.</p><p>Also bear in mind that motion-based camera systems can generate large volumes of video, which will require large amounts of either local or network storage if you want to view it later. This project can accommodate either, depending on your needs.</p><p>Once you've connected everything up - and carefully clipped the camera board in place - you're ready for the software bit. There are two simple routes to go down here - either install <a href="https://github.com/Motion-Project/motion" target="_blank">Motion</a> and tweak it to suit, or go for an all-in-one option, like <a href="https://github.com/ccrisan/motioneyeos" target="_blank">MotionEye</a>, a Linux distribution that turns a single-board computer into a video surveillance system. The OS is based on <a href="http://buildroot.uclibc.org" target="_blank">BuildRoot</a> and uses <a href="https://motion-project.github.io" target="_blank">Motion</a> as a backend and <a href="https://github.com/ccrisan/motioneye" target="_blank">MotionEye</a> for the frontend.</p><p>We'll go with MotionEye here, as it rounds off some of the corners without adding much in terms of complexity.</p><h2 id="downloading-and-writing-motioneye-image-to-disk">Downloading and writing MotionEye image to disk</h2><p>First, download the latest version of <a href="https://github.com/ccrisan/motioneyeos/releases" target="_blank">MotionEye</a> for your device, extract the image file from the archive and write it to your SD card. You can use <a href="https://etcher.io" target="_blank">Etcher.io</a> on Windows, or in Linux there is a writeimage.sh script that will do everything for you.</p><p>Just run the script as follows (replacing the arguments with appropriate values):./writeimage.sh -d /dev/mmcblk0 -i "/path/to/motioneyeos.img"</p><p>Note that you'll need to specify the device path to the disk and not to some partition (for example /dev/mmcblk0 instead of /dev/mmcblk0p1).</p><p>You can preconfigure a wireless network connection - or a static IP if you'd rather not use DCHP - with the following command. Just use this command for Wi-Fi:./writeimage.sh -d /dev/mmcblk0 -i "/path/to/motioneyeos.img" -n 'yournet:yourkey'</p><p>...and this command for a static IP:./writeimage.sh -d /dev/mmcblk0 -i "/path/to/motioneyeos.img" -s "192.168.1.101/24:192.168.1.1:8.8.8.8"</p><h2 id="boot-and-setup">Boot and setup</h2><p>This complete, you're ready to boot the image. This will take a few minutes as the system auto-configures. Your motionEyeOS needs an IP address before you can communicate with it so you'll have to use the ethernet connection with DHCP enabled, unless you have preconfigured a static IP address.</p><p>As soon as your motionEyeOS setup is complete, it will listen on port 80 and present you with a web user interface - simply enter the IP address of your board in the address bar of your browser. Use your router to display devices on your home network, or use a network scanner to hunt for a device called "meye-".</p><p>Once found, you'll be able to click on the user icon on the upper-left side of the page to switch user to administrator. Use admin with no password when asked for credentials - the user setting is for remote monitoring, the admin for changing settings.</p><p>MotionEyeOS has a broad range of settings to play with, but the first thing you'll want to do is set up passwords for both admin and user, set the timezone and enable wireless. After that, choose the desired resolution, frame rate, and other details of your video feed, and configure file storage if you want your pictures and movies saved on a network or USB drive.</p><p>You'll be able to monitor your camera remotely (including on a smartphone) by visiting the relevant IP, inputting your 'user' login, and then using the web interface. The interface also allows you to browse, preview and download videos and images from each connected camera by using the media browser window which opens by clicking on the pictures or movies buttons.</p><p>This project gives you the beginning of a great security camera system which can scale up to monitor almost any situation, and is far more flexible than most comparable-price commercial systems. In addition, the Pi and Camera board can be the basis for a wide range of other projects too, including wildlife cameras or timelapse photography.</p><p><em>Thanks to Calin Crisan for his MotionEyeOS</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK oversight bodies 'were not aware' of spies' data-sharing ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/it-legislation/29749/uk-oversight-bodies-were-not-aware-of-spies-data-sharing</link>
                                                                            <description>
                            <![CDATA[ Privacy International finds documents alleging widespread GCHQ data-sharing occurred without safeguards ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5LF1Ytswvc77qJnYwK7b57</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/w3LpY94RhY5XWRsHmBDKbH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 18 Oct 2017 11:46:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GFZtdGsYoXrkh3Jhj4ZKTc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/w3LpY94RhY5XWRsHmBDKbH-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/w3LpY94RhY5XWRsHmBDKbH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Privacy International has raised concerns that oversight bodies were not aware that GCHQ or MI5 were allegedly sharing people's social media data with foreign intelligence and law enforcement agencies.</p><p>The charity <a href="https://privacyinternational.org/node/1532" target="_blank">claims</a> that GCHQ accessed this information by gaining access to private companies' databases. <em>IT Pro</em> understands that Facebook and Twitter do not provide governments with direct access to user data.</p><p>The Investigatory Powers Commissioner's Office (IPCO) now oversees the intelligence agencies' activities, after subsuming both the the Intelligence Services Commissioner's Office, and the Interception of Communications Commissioner. Both these latter bodies, the charity said, were unaware that UK intelligence agencies were sharing massive databases of people's information with foreign governments, law enforcement and industry - potentially for decades.</p><p>Inappropriate and uncontrollable sharing with industry third parties may still be ongoing without proper oversight, the privacy campaign group added, saying that there are contractors who have system access rights that could allow them to enter the intelligence agencies' systems, access and extract data and then cover their tracks.</p><p>The charity said it has since seen letters from the IPCO raising concerns about the role of private contractors who are given administrator access to the data. The body was worried that there were no systems in place to prevent the misuse of this data by the contractors.</p><p>A GCHQ spokesperson said to <em>IT Pro</em>: "We have always operated within the law, co-operated fully with oversight regimes, and all our activities are authorised, necessary and proportionate."</p><p>The information the agencies hold is stored in large databases but it remains unclear what data they have, with Privacy International's documents only revealing broad categories like "biographical details", "financial activities", "travel data" and "legally privileged communications".</p><p>The group revealed a tranche of documents detailing the data-sharing activities yesterday, and is in Southwark Crown Court until Thursday to uphold its challenge of the UK government's access to private company and/or organisation databases.</p><p>The case is a continuation of the charity's challenge to spy agencies' access to data, being heard by the Investigatory Powers Tribunal (IBT). The IBT previously made <a href="https://www.itpro.com/data-protection/27419/gchq-mi5-and-mi6-unlawfully-collected-data-for-over-a-decade" target="_blank" data-original-url="https://www.itpro.com/data-protection/27419/gchq-mi5-and-mi6-unlawfully-collected-data-for-over-a-decade">a landmark ruling that spy agencies had unlawfully collected communications data between 1998 and 2015</a> after Privacy International's challenge.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/29439/investigatory-powers-tribunal-escalates-lawsuit-to-the-eu" data-original-url="/data-protection/29439/investigatory-powers-tribunal-escalates-lawsuit-to-the-eu">Investigatory Powers Tribunal escalates lawsuit to the EU</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28251/liberty-launches-legal-challenge-against-investigatory-powers-act" data-original-url="/it-legislation/28251/liberty-launches-legal-challenge-against-investigatory-powers-act">Liberty launches legal challenge against Investigatory Powers Act</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/27419/gchq-mi5-and-mi6-unlawfully-collected-data-for-over-a-decade" data-original-url="/data-protection/27419/gchq-mi5-and-mi6-unlawfully-collected-data-for-over-a-decade">GCHQ, MI5 and MI6 "unlawfully" collected data for over a decade</a></p></div></div><p>The UK government claims that there are effective safeguards in place around data sharing, which Privacy International disputes. Furthermore, the charity will question the government's evidence after the IPCO flagged that part of the government's evidence includes <a href="https://privacyinternational.org/sites/default/files/5.%20Amended%20GCHQ%20WS%202017.07.07%20%28signed%202017.10.12%29%20.PDF" target="_blank">a misleading GCHQ witness statement.</a> The statement details that the former commissioners were briefed about the agencies' use of information on private company and/or organisation databases. The IPCO stated the commissioners were never made aware of this.</p><p>Millie Graham Wood, solicitor at Privacy International, said: "The intelligence agencies' practices in relation to bulk data were previously found to be unlawful. After three years of litigation, just before the court hearing, we learn not only are safeguards for sharing our sensitive data non-existent, but the government has databases with our social media information and is potentially sharing access to this information with foreign governments.</p><p>"The risks associated with these activities are painfully obvious. We are pleased the IPCO is keen to look at these activities as a matter of urgency and the report is publicly available in the near future."</p><p>The IBT <a href="https://www.itpro.com/data-protection/29439/investigatory-powers-tribunal-escalates-lawsuit-to-the-eu" target="_blank" data-original-url="https://www.itpro.com/data-protection/29439/investigatory-powers-tribunal-escalates-lawsuit-to-the-eu">ruled last month that a case brought against the UK's spy agencies last month over the legality of mass surveillance should be taken to the European Court of Justice (ECJ)</a>. This means the ECJ will have the final say on whether the UK's collection of bulk communications data, granted under the Investigatory Powers Act, is legal.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EnGenius EL-EWS1025CAM review ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cctv/29688/engenius-el-ews1025cam-review</link>
                                                                            <description>
                            <![CDATA[ A clever hybrid IP camera that combines video surveillance with a wireless AP and support for EnGenius’ Neutron WLAN meshing ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cDw2nPk821hR7CwrpfAn1Z</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GXkp4yX3NKQ75mpAYpAx4M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 09 Oct 2017 12:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GXkp4yX3NKQ75mpAYpAx4M-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GXkp4yX3NKQ75mpAYpAx4M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>EnGenius adds a new dimension to video surveillance as its EL-EWS1025CAM teams up a 2-megapixel IP camera with an integral dual-band 11n/ac wireless access point (AP). There's more, too: it can function as a standalone unit or integrate with EnGenius' Neutron WLAN management switches and join a wireless mesh network.</p><p>This ceiling-mounted camera has impressive credentials - along with a wide 120-degree diagonal FOV, the lens is encircled by 24 IR emitters for night-time operations. It has an integral mic, the Gigabit port is PoE-enabled and EnGenius also provides an external power adapter.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cctv/29457/hikvision-darkfighter-ds-2cd4b26fwd-izs-review" data-original-url="/cctv/29457/hikvision-darkfighter-ds-2cd4b26fwd-izs-review">Hikvision Darkfighter DS-2CD4B26FWD-IZS review</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cctv/29456/engenius-eds6255-review" data-original-url="/cctv/29456/engenius-eds6255-review">EnGenius EDS6255 review</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cctv/29445/d-link-vigilance-dcs-4602ev-review" data-original-url="/cctv/29445/d-link-vigilance-dcs-4602ev-review">D-Link Vigilance DCS-4602EV review</a></p></div></div><p>The kit includes a circular plastic mounting bracket and a set of clips for hanging it from the T-rails of a suspended ceiling. The lens position can be easily adjusted using its friction joints and behind the rubber cover on the side are a MicroSD card slot and reset button.</p><p>The camera is easy to deploy and on first contact, its tidy web interface sensibly advised us to change the default admin password. The Live View offers two streams using H.264 or MJPEG at up to 30fps. The first supports 1920 x 1080 while the second only goes up to 640 x 360 for mobile viewers.</p><p>The Live View image quality is excellent at the top resolution, with a sharp focus, good colour balance and smoothly conveyed motion via an H.264 feed. Microsoft Edge and Google Chrome had no problems showing the Live View, although we noted that the snapshot, full screen view, recording and audio mute buttons to the side only worked with IE11.</p><p>The camera uses a single web console for video and wireless management and provides eight SSIDs each for the 2.4GHz and 5GHz radios. All the expected security options are present and correct, plus you can assign one isolated guest network to each radio with its own DHCP server.</p><p>We used the scheduler to control availability of individual SSIDs, allowing us to turn them off outside normal working hours and on weekends. Monitoring options include lists of associated wireless clients and real-time graphs showing traffic for each radio plus system CPU load.</p><p>The EnGenius Video Management Software (VMS) provides a video wall for up to 16 IP camera feeds. The camera slotted in neatly with VMS allowing us to place it on an e-map, create recording schedules and motion detection events, store its feed on network storage and browse the recording vault.</p><p>To test the camera's efficacy with the Neutron solution we used an EnGenius EWS5912FP PoE WLAN management switch and threw in a couple of EWS360AP wireless APs for good measure. The switch has a dual-role web console providing access to the switch itself and the WLAN controller portion.</p><p>Adding the APs and camera was simple, and after they had been auto-detected by the switch, we assigned them to an AP Group containing all our wireless and security settings. We could enabled both radios, enforce security for all 16 SSIDs, broadcast them, enable or disable client isolation, create wireless VLANs and enforce upload and download traffic shaping limits.</p><p>With meshing in action, new APs don't need to be wired to the network as they'll link up wirelessly with the nearest AP and grab their settings from the switch. We tested roaming by unplugging an AP and watched connected clients transparently move over to the next available one.</p><p>The camera's video functions can still be accessed directly from its local web console so there's no change here. To simplify management further, we moved over to the VMS app loaded on a Windows 10 desktop and monitored and recorded its feed from here.</p><p>Priced right for SMBs, the EnGenius EL-EWS1025CAM is a great idea for adding surveillance and wireless access at the same location. As a standalone device it has a lot to offer but support for the EnGenius Neutron WLAN management solution probably makes it the most versatile IP camera we've seen.</p><p><em>This review originally appeared in PC Pro issue 276.</em></p><h2 id="verdict">Verdict</h2><p>Priced right for SMBs, the EnGenius EL-EWS1025CAM is a great idea for adding surveillance and wireless access at the same location. As a standalone device it has a lot to offer but support for the EnGenius Neutron WLAN management solution probably makes it the most versatile IP camera we've seen.</p><p>1/2.9in. Sony RGB CMOS</p><p>2.8mm/F2.0 lens</p><p>1080p max res</p><p>30fps</p><p>MJPEG/H.264</p><p>Gigabit</p><p>PoE</p><p>2.4/5GHz 11/n/ac wireless AP</p><p>24 x IR LEDs</p><p>Internal mic</p><p>MicroSD/SDXC card slot</p><p>External PSU</p><p>EnGenius Video Management software</p><p>134 x 134 x 97mm (WDH)</p><p>1yr standard warranty. Options: EWS5912FP 8-port Neutron switch, £273 ex VAT</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Gov accuses Whatsapp of creating security 'black hole' ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-protection/29536/gov-accuses-whatsapp-of-creating-security-black-hole</link>
                                                                            <description>
                            <![CDATA[ Gov ramps up pressure on app to hand over encrypted messages - report ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9Bkg6utf6uKHUUh3d2HB74</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2zVbrBxgGmCxdyJ5oujTLQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 22 Sep 2017 07:49:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2zVbrBxgGmCxdyJ5oujTLQ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2zVbrBxgGmCxdyJ5oujTLQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The government has reportedly accused WhatsApp of creating a "black hole" in security intelligence by refusing to give it access to people's encrypted messages.</p><p>This is according to <em><a href="http://news.sky.com/story/whatsapp-denies-government-access-to-encrypted-messages-11043069">Sky</a> <a href="http://news.sky.com/story/whatsapp-denies-government-access-to-encrypted-messages-11043069">News</a></em>, which quoted an anonymous security source, who claimed that terrorists are "frequent users" of encrypted apps because they know no one can read their messages.</p><p>"It is crucially important that we can access their communications - and when we can't, it can provide a black hole for investigators," the source added.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/public-sector/29288/whatsapp-amber-not-getting-the-message" data-original-url="/public-sector/29288/whatsapp-amber-not-getting-the-message">WhatsApp Amber? Not getting the message?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/26305/whatsapp-announces-end-to-end-encryption" data-original-url="/security/26305/whatsapp-announces-end-to-end-encryption">WhatsApp announces end-to-end encryption</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28251/liberty-launches-legal-challenge-against-investigatory-powers-act" data-original-url="/it-legislation/28251/liberty-launches-legal-challenge-against-investigatory-powers-act">Liberty launches legal challenge against Investigatory Powers Act</a></p></div></div><p>Other platforms such as iMessage and Telegram also protect messages using encryption and do not allow the government access to the information.</p><p>WhatsApp does, however, allow authorities to see other information such as an account name, when the account was created, the last know IP address used to access the service and the email address associated with each account.</p><p>However, WhatsApp made it clear it wants to protect its users, and this means messages must stay encrypted and hidden from authorities, just as they should remain protected from potential criminals.</p><p>"Naturally, people have asked what end-to-end encryption means for the work of law enforcement," the company explains on a statement on its website. "WhatsApp appreciates the work that law enforcement agencies do to keep people safe around the world.</p><p>"We carefully review, validate, and respond to law enforcement requests based on applicable law and policy, and we prioritise responses to emergency requests."</p><p>The news comes after Theresa May stressed the importance for technology companies to do more to help the government identify security threats following the Parsons Green tube station bomb attack last week.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Axis M1065-LW review ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cctv/29446/axis-m1065-lw-review</link>
                                                                            <description>
                            <![CDATA[ It’s pricey, but this little 1080p camera simply won’t be beaten for video quality and surveillance features ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bDhhKxNd1ESV8ahD1q683X</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9qczvuDr5uFQKyrmpjMwkW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 13 Sep 2017 08:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9qczvuDr5uFQKyrmpjMwkW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9qczvuDr5uFQKyrmpjMwkW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Axis M1065-LW is one of the smallest IP cameras on the market, making it an attractive option for offices seeking a discreet indoor surveillance solution. What's more, despite its miniscule dimensions, it comes with a list of features to match IP cameras twice its size.</p><p>That includes a maximum resolution of 1080p at 25fps, with support for both wired and wireless network connections. With an integrated infrared illuminator and a PIR motion sensor, it can detect movement and record video in the dark as well as the daytime.</p><p>There's also an internal microphone and speaker for two-way audio, and a micro-SD card slot, so you can store video locally as well as to network storage. It's a shame that there's no PoE support, but the included PSU has a decent 2.9m cable, so your positioning options aren't too limited.</p><p>We found the camera took less than a minute to set up over a wired connection, and its native web interface is very easy to use. From here, setting up a wireless connection is simplicity itself: you can choose your SSID from a list, or simply use the WPS button on the side of the camera.</p><p>The M1065-LW impressed us with its video quality. Its live view is pin-sharp, with excellent contrast and colour balance. You can choose from 10 resolutions and configure multiple stream profiles, so you can set up different image sizes, frame rates and compression levels to suit different destinations.</p><p>For night-time operation the IR illuminator has a range of 10 metres and switches on automatically when light levels drop. We found the PIR sensor also worked well, with movement within 6 metres triggering our alert actions.</p><p>The one concession you'll probably have to make is accessing the camera via Internet Explorer. Neither Microsoft Edge nor Chrome supports the Axis Media Control plug-in required for H.264 streaming - so if you want to watch your feed in one of these browsers you'll have to live with MJPEG. And while Firefox will stream H.264 through the QuickTime plug-in, there's an annoying three-second video delay. Internet Explorer has no such limitations: we were happily able to stream in either video format, with latency of less than one second.</p><p>When we enabled audio, the web interface also installed an AAC decoder plug-in. Audio transmission is half-duplex: to speak to someone, you click and hold the Talk button at the bottom of the live view page,and let go when you want to listen to them. Overall sound quality isn't great, but it was good enough for us to hold a conversation with someone next to the camera.</p><p>The camera can be set to respond to a wide range of events, including motion (detected by either the camera or the PIR sensor), audio noise or camera tampering. The camera comes preloaded with Axis' clever Motion Detection 3 app, which offers variable sensitivity, so you can ignore small movements such as birds landing on the windowsill.</p><p>You can set up rules to link triggers to actions, such as recording to the micro-SD card or to a network share, sending images to HTTP and FTP servers or emailing them and playing a warning sound clip stored on the camera. You can also set up schedules to apply different rules at different times of the day.</p><p>It's a system with scope to grow, too: Axis' free Camera Companion software supports multiple sites, each with up to 16 cameras and provides centralised recording and playback facilities. The interface provides live views of assigned cameras, along with facilities for browsing recordings and a slick investigation mode for frame-by-frame viewing.</p><p>We found it automatically discovered our Synology NAS appliance, listed available shares for selection and set up motion detection for us. We also had no problems linking the Axis iOS app to our MyAxis cloud account and viewing camera feeds remotely from our iPad.</p><p>For a small office or shop, the M1065-LW is comparatively expensive, but it delivers premium protection for your business. It's small enough to be unobtrusive, and offers top-notch image quality and a comprehensive set of surveillance features.</p><p><em>This review originally appeared in PC Pro 270</em></p><h2 id="verdict-2">Verdict</h2><p>For a small office or shop, the M1065-LW is comparatively expensive, but it delivers premium protection for your business. It's small enough to be unobtrusive, and offers top-notch image quality and a comprehensive set of surveillance features.</p><p>1/3in. RGB CMOS; 2.8mm, f/2.0 lens</p><p>1080p max res</p><p>25fps</p><p>MJPEG/H.264</p><p>10/100 Ethernet</p><p>802.11n wireless</p><p>PIR sensor</p><p>IR illuminator</p><p>Internal mic/speaker</p><p>Micro-SD card slot</p><p>External PSU</p><p>Axis Camera Companion and Camera Station (1 licence) software</p><p>61 x 37 x 106mm (WDH)</p><p>128g</p><p>Wall mount bracket and table-top stand</p><p>3yr RTB warranty</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ D-Link Vigilance DCS-4602EV review ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cctv/29445/d-link-vigilance-dcs-4602ev-review</link>
                                                                            <description>
                            <![CDATA[ A very affordable outdoor IP camera that’s built like a tank, though image quality is merely adequate ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4qJbtqTjtHzQvH5S2J6SHJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/f94RdYgZzcvt852uPnUVdE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 12 Sep 2017 08:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/f94RdYgZzcvt852uPnUVdE-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/f94RdYgZzcvt852uPnUVdE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A member of D-Link's Vigilance professional surveillance family, the DCS-4602EV is designed to go where other IP cameras fear to tread. Its IP66 rating makes it fully weather-proof against dust-storms and heavy jets of water, and its solid metal casing and polycarbonate dome have an IK10 external mechanical impact rating - the highest possible - meaning it can stand up to a physical battering too.</p><p>The DCS-4602EV is based on a 2MP CMOS with a top resolution of 1080p. It also features 15 infrared LED illuminators circling its lens, which D-Link claims will deliver night-vision at a range of up to 20 metres - something our tests bore out.</p><p>The camera supports wired connections only, and the expectation is that you'll be driving it via PoE - the 12V power supply is an optional extra. A short waterproof Ethernet cable protrudes from the camera's base, so that the RJ-45 connection doesn't become a chink in the DCS-4602EV's armour.</p><p>The tidy web interface makes light work of configuration, but as usual Microsoft Edge and Chrome don't support H.264 streams. We had no such problem with IE 11, in either format, and were also able to use Firefox via the QuickTime plugin for H.264 - although as with other cameras, this introduces an annoying three second latency for motion. D-Link tells us it's looking into these issues but is currently advising Windows 10 users to stick with IE 11.</p><p>Live view quality is reasonable, but the camera's focus is on the soft side, making the image appear very slightly blurry. Still, it's good enough for general surveillance of areas such as lobbies and corridors. The camera handles artificial lighting well, and when positioned outdoors it reacted quickly to changing light levels. We suggest you keep it out of direct sunlight, however: faced with our brightest scene, the camera turned down the exposure so far that the areas in shadow were too dark to be usable.</p><p>The web interface is standard across D-Link's range, so you'll find a PTZ control pad on the left side, even though the pan and tilt buttons do nothing on this camera. The zoom buttons do work for the DCS-4602EV, but since this is digital zoom it's only good for blowing up the image: you won't capture any more detail, and quality breaks down badly at the maximum 10X setting.</p><p>We defined two streams each with their own resolution, codec and frame rate for PC and mobile viewing, and saw quick links in the live view page, along with buttons for full-screen, taking snapshots and recording on demand.</p><p>Setting up motion detection is simple too: you can draw zones to mark where you want it be active, and set a global sensitivity level. A handy indicator in the live view shows when motion detection has been triggered, and this can be linked to a range of events. Up to five email, FTP and NAS servers are supported and we could decide whether to send snapshots, video clips or just system logs to them. You can also set events to be automatically triggered to a schedule, or to a camera reboot.</p><p>In addition to the camera's own web interface, you get D-Link's D-ViewCam software for accessing up to 32 cameras and managing recordings to multiple storage locations. The console looks dated but it works fine on Windows 10 and offers plenty of tools including a handy e-map facility. There's also an iOS app: we had no problems accessing the video server host on the LAN, but if you want to access it from outside your company network you'll need to manually set up port forwarding to allow it to get through your firewall.</p><p>The DCS-4602EV is a tough all-weather camera that's built to last and offers plenty of features. Image quality isn't the best, but if you're looking for an vandal-proof outdoor IP camera, the low price makes it an attractive choice.</p><p><em>This review originally appeared in PC Pro issue 270</em></p><h2 id="verdict-3">Verdict</h2><p>The DCS-4602EV is a tough all-weather camera that's built to last and offers plenty of features. Image quality isn't the best, but if you're looking for an vandal-proof outdoor IP camera, the low price makes it an attractive choice.</p><p>1/3in. 2MP RGB CMOS</p><p>2.8mm, f/1.8 lens</p><p>1080p max res</p><p>30/25fps (60/50Hz)</p><p>IP66/IK10 certified</p><p>MJPEG/H.264</p><p>10/100 Ethernet</p><p>PoE</p><p>15 x IR LEDs</p><p>10X digital zoom</p><p>D-Link D-ViewCam software</p><p>110 x 110 x 72mm (WDH)</p><p>2yr RTB warranty</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The government needs to abandon its war on WhatsApp ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/28381/the-government-needs-to-abandon-its-war-on-whatsapp</link>
                                                                            <description>
                            <![CDATA[ Encryption might seem like an easy target, but mess with it at your peril ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6ubZNTbj5JJZTopSZR1uEt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/digBJriZwFmkS9iu5cCXD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Mar 2017 16:41:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/digBJriZwFmkS9iu5cCXD-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/digBJriZwFmkS9iu5cCXD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It seems that encryption has been firmly established as the whipping boy <em>du jour</em> for pearl-clutching, public-safety panic merchants. Specifically, it's encrypted messaging services like WhatsApp and iMessage that have found themselves in the crosshairs.</p><p>Following last week's terror attack by the Houses of Parliament, it has emerged that the killer was communicating with someone via WhatsApp in the moments preceding his assault. It has been speculated although not confirmed that he may have been in contact with someone who conspired with him to plan the attack, although this afternoon the Met Police have said there's no evidence he was directed by Islamic State.</p><p>This has fuelled <a href="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages" target="_blank" data-original-url="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages">fresh calls to severely weaken</a> or outright ban the use of encryption by such services to secure their messages, echoing last year's fierce debate over <a href="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone" target="_blank" data-original-url="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone">whether or not Apple should hack the iPhone</a> of the San Bernardino killer. It's worth noting at this point that even though a third-party company did eventually hack into Syed Farook's phone, there is no indication that it offered any actionable intelligence.</p><p>Nevertheless, home secretary Amber Rudd and other Tory MPs are using this tragedy as an excuse to castigate and demonise encryption, with talk of coercing tech companies into installing backdoors into their code. It's not the first time the government has proposed this, either; it was <a href="https://www.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web&cd=2&cad=rja&uact=8&ved=0ahUKEwjI4bTDkvfSAhViD8AKHf7wAaQQFgghMAE&url=http%3A%2F%2Fwww.itpro.com%2Fsecurity%2F23840%2Fwhatsapp-imessage-face-uk-ban-on-anti-terrorism-grounds&usg=AFQjCNHAGYm0-jC2c91ZwBkAsT239KrU_g&sig2=Y1Gr3EnMau4ZnhnX0j7gBQ&bvm=bv.150729734,d.ZGg" target="_blank">included in early versions of the Snooper's Charter</a>, but was ultimately dropped from the bill.</p><p>Naturally, the idea of messing with encryption has got the tech sector up in arms. <a href="https://www.itpro.com/security/28380/deeply-misguided-tech-industry-rejects-rudd-s-attack-on-encryption" target="_blank" data-original-url="https://www.itpro.com/security/28380/deeply-misguided-tech-industry-rejects-rudd-s-attack-on-encryption">Critics have called it "deeply misguided"</a> and other (less printable) things. Supporters of the plan say that spies need to be able to read the messages of terror suspects, but experts are queuing up to tell Rudd and the rest of the anti-crypto club that technology simply doesn't work that way.</p><p>In an exchange that would be funny if it weren't so deeply depressing, Conservative MP Nadine Dorries made the case that WhatsApp should "develop a terrorist related exception" to encryption technology - presumably this is some kind of Java-based magic wand that would allow GCHQ to hack only the baddies'.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/846272022644711424"></a></p></blockquote><div class="see-more__filter"></div></div><p>This, along with Rudd's laughable quote that we need people who "understand the necessary hashtags", betrays a deep lack of technological knowledge throughout government. Of course, one would hope that the country's elected leaders have better things to do than immersing themselves in the finer points of C++ and Python, but on the other hand, having one of the country's top ministers saying things like "we don't want to go into the cloud" is embarrassing, especially when she clearly doesn't have the faintest idea what it means.</p><p>The experts are right, of course; if government spooks can read the WhatsApp messages of one terrorist, they can read the messages of everyone, from the 12-year-old at the bus stop all the way to the Pope. (This is assuming he doesn't use a rival app, of course - PopeChat, perhaps.)</p><p>This is troubling for a number of reasons, most notably from a privacy standpoint. Naturally, the public has been assured that they won't be covertly spied on by the intelligence services, who pinkie-promise that they'd only look at terrorists' communications. We're expected to take this on faith, but <a href="https://www.itpro.com/security/25398/gchq-can-control-your-smartphone-edward-snowden-says" target="_blank" data-original-url="https://www.itpro.com/security/25398/gchq-can-control-your-smartphone-edward-snowden-says">incidents like the Snowden leaks</a> suggest that perhaps the government's methods aren't always unimpeachable.</p><p>We've also got to consider what future governments could do with any anti-encryption laws. If an anti-democratic, fascistic party found itself in power, for example, these laws could be very easily used to identify and round up immigrants, LGBTQ people and other undesirables'. It's a lot easier to grant powers than it is take them away and this goes double when applied to governments.</p><p>Here's the thing, though: aside from the many legal, political and ethical issues with installing backdoors into services like WhatsApp, the biggest problem is practical. The fact is, there's simply no way to block the use of encryption on a technical level. Theresa May could force WhatsApp to stop encrypting its messages, but how long do you think it would take terrorists to simply switch to a different app?</p><p>Not only are there innumerable encrypted chat apps available for web and mobile devices, there's also plenty of free resources online to help you build your own, meaning that even an outright ban on encryption wouldn't work. If there's one thing you learn on the internet, it's that there's <em>always</em> a workaround.</p><p>Any steps to weaken the encryption of WhatsApp and other services would almost certainly do nothing to help fight terrorism. Instead, all it's likely to do is force terrorists to use even less visible means of communication, whilst simultaneously putting the safety and privacy of innocent people at risk.</p><p>Despite the repeated protestations of the security and technology communities, the government continues to revisit this stunningly ignorant and fundamentally flawed plan. Before it goes any further, you should know that Rudd and her cronies aren't just declaring war on WhatsApp - they're endangering your freedoms too.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages" data-original-url="/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages">Amber Rudd demands spy agency access to WhatsApp's encrypted messages</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28380/deeply-misguided-tech-industry-rejects-rudd-s-attack-on-encryption" data-original-url="/security/28380/deeply-misguided-tech-industry-rejects-rudd-s-attack-on-encryption">“Deeply misguided”: tech industry rejects Rudd’s attack on encryption</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet" data-original-url="/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet">The fight against the Investigatory Powers Bill isn't over yet</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Big Data surveillance 'risks public's privacy' ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/public-sector/28302/big-data-surveillance-risks-publics-privacy</link>
                                                                            <description>
                            <![CDATA[ Commissioner looks to limit use of CCTV ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jwZ6hzfbkDppSG2Upn2Eto</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bXVncR7tN2tkZcLj5xtYaf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Mar 2017 11:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bXVncR7tN2tkZcLj5xtYaf-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cameras on pole]]></media:description>                                                            <media:text><![CDATA[cameras on pole]]></media:text>
                                <media:title type="plain"><![CDATA[cameras on pole]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bXVncR7tN2tkZcLj5xtYaf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Public privacy is at risk of mass scale invasion as an increasing use of Big Data and a surge in the amount of overt CCTV has left regulators struggling to keep pace, according to the UK's surveillance commissioner.</p><p>Alongside the launch of a <a href="https://www.gov.uk/government/consultations/draft-national-surveillance-camera-strategy-for-england-and-wales" target="_blank">new three-year strategy</a> on Tuesday, surveillance camera commissioner Tony Porter told the <a href="https://www.theguardian.com/uk-news/2017/mar/14/public-faces-mass-invasion-of-privacy-as-big-data-and-surveillance-merge" target="_blank"><em>Guardian</em></a> that the UK government is falling behind the pace at which new CCTV technology is being implemented.</p><p>The 2017-2020 National Surveillance Camera Strategy for England and Wales, which was first proposed in October and has now passed through its consultation phase, aims to establish a code of practice for the use of CCTV equipment, including the use of body worn cameras and automatic number plate recognition.</p><p>Under the strategy, disparate groups and regulators would be brought together in an attempt to create a set of coherent rules, limiting the use of surveillance cameras to times when it was deemed proportionate and necessary. </p><p>However, Porter has expressed alarm that the increasing number of CCTV devices could lead to more invasive surveillance tactics than anticipated, as video footage is now being linked with data analysis tools like facial recognition or being cross referenced with other monitored personal data and activities.</p><p>"I'm worried about over surveillance becoming much more invasive because it is linked to everything else," Porter told the <em>Guardian</em>. "You might have a video photograph of somebody shopping in Tesco - now it is possible to link that person to their pre-movements, their mobile phone records, any sensor detectors within their house of locality."</p><p>"As smart cities move forward, these challenges are so much greater for people like myself, and members of the public need to decide whether they are still happy with this."</p><p>His comments come after <a href="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament">Parliament passed the Investigatory Powers Act</a>, allowing spy agencies to monitor people's web browsing habits and collect bulk personal datasets.</p><p><strong>"Fast and loose"</strong></p><p>Although there are an estimated four to six million CCTV cameras in the UK, new technology is changing the nature of surveillance, as we no longer rely on just cameras for spotting crimes. The use of <a href="https://www.itpro.com/strategy/27420/met-police-rolls-out-body-cameras" target="_blank" data-original-url="https://www.itpro.com/strategy/27420/met-police-rolls-out-body-cameras">body worn cameras</a> is becoming the norm for police forces across the country, and drone technology is regularly being deployed to help solve crimes or missing person reports.</p><p>However despite the benefits to policing, Porter argues that privacy is not always a priority when deciding to use the technology, adding that the Metropolitan police in particular were playing "fast and loose" with public privacy by <a href="https://talkaboutlocal.org.uk/anpr-met-police-explain-the-olympic-feed-and-data-retention" target="_blank">planning not to erase number plate records after a two-year period</a>.</p><p>Porter highlighted the case of the London Olympics in 2012, in which millions of vehicle registration plate records were obtained, but subsequently never deleted in the time since. Police forces are obligated to delete number plate records after two years, or they risk the possibility of legal challenges.</p><p>"The nightmare scenario is that there is a lack of understanding about how big and effective this can be," said Porter. "This technology is there to protect us, but there needs to be informed consent about what it is capable of doing. Body-worn video or facial recognition - that can identify people on databases who didn't know they were on databases."</p><p>Porter has urged authorities to adopt his code of practice set out in the three-year strategy, which would limit the use of surveillance cameras to only when there is a clear need to safeguard the public.</p><p><em>Picture: Bigstock</em></p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/27590/investigatory-powers-bill-passes-through-parliament" data-original-url="/it-legislation/27590/investigatory-powers-bill-passes-through-parliament">Investigatory Powers Bill passes through Parliament</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet" data-original-url="/security/27657/the-fight-against-the-investigatory-powers-bill-isnt-over-yet">The fight against the Investigatory Powers Bill isn't over yet</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/27420/met-police-rolls-out-body-cameras" data-original-url="/strategy/27420/met-police-rolls-out-body-cameras">Met Police rolls out body cameras</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WikiLeaks files expose alleged CIA hacking tools ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/28273/wikileaks-files-expose-alleged-cia-hacking-tools</link>
                                                                            <description>
                            <![CDATA[ CIA's tools can break into any kind of operating system, smart device or digital machine ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2WeSsTKjMeJVNZPv6Q8kt5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hFGqsnfx34S6pk3GEseu4W-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Mar 2017 09:47:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hFGqsnfx34S6pk3GEseu4W-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hFGqsnfx34S6pk3GEseu4W-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>WikiLeaks has claimed the CIA can pretty much hack into any device, even smart TVs, with its range of hacking tools, designed to read and lift data from electronic devices.</p><p>The information obtained is "the largest ever publication of confidential documents on the agency," according to a statement <a href="https://wikileaks.org/ciav7p1" target="_blank">released by WikiLeaks</a>.</p><p>The first batch to be leaked, dubbed 'Year Zero' is comprised of 8,761 documents and files that reportedly detail how authorities have discovered a way to bypass the encryption in highly secure messaging platforms such as WhatsApp, Telegram and Signal. This is done by accessing the data on devices before encryption is applied on Android and using other methods on the iPhone, Microsoft Windows and even Samsung smart TVs. However, <a href="https://www.itpro.com/security/28276/apple-ios-1021-protects-users-from-weeping-angel" target="_blank" data-original-url="https://www.itpro.com/security/28276/apple-ios-1021-protects-users-from-weeping-angel">privacy campaigners dispute this claim</a>.</p><p>The files were accessed via an internal network inside the CIA's Center for Cyber Intelligence in Langley, Virgina.</p><p>The engineering development group (EDG) is responsible for developing, testing and supporting the tools that the CIA uses for this type of surveillance. The EDG sits within the Center for Cyber Intelligence (CCI), which itself is a sub-department of the Directorate for Digital Innovation (DDI), one of the CIA's five major directorates. </p><p>One particular method of surveillance, dubbed "Weeping Angel", was developed by the CIA's embedded devices branch (EDB) and focused on turning Samsung smart TVs into covert microphones. When users think the TV is off, it's actually a 'fake-off' mode that records conversations and send them to a covert CIA server. It is believed that the CIA didn't act alone for this attack and worked in co-operation with MI5/BTSS (British Security Service). </p><p>WikiLeaks explained that the agency "lost control" of its hacking weapons, including malware, viruses, trojans, weaponised "zero day" exploits, malware remote control systems and associated documentation. Anyone finding the information could use it to launch a serious attack on anyone. However, the notes don't include the hacking files themselves, merely the information about how the CIA is believed to be using them.</p><p>The anonymous source who sent the materials to WikiLeaks is apparently hoping that the documents will trigger a conversation about "whether the CIA's hacking capabilities exceed its mandated powers and the problem of public oversight of the agency," WikiLeaks said. </p><p>"There is an extreme proliferation risk in the development of cyber 'weapons'," said Julian Assange, WikiLeaks editor. "Comparisons can be drawn between the uncontrolled proliferation of such 'weapons', which results from the inability to contain them combined with their high market value, and the global arms trade.</p><p>"But the significance of 'Year Zero' goes well beyond the choice between cyberwar and cyberpeace. The disclosure is also exceptional from a political, legal and forensic perspective."</p><p><a href="https://www.itpro.com/security/28276/apple-ios-1021-protects-users-from-weeping-angel" target="_blank" data-original-url="https://www.itpro.com/security/28276/apple-ios-1021-protects-users-from-weeping-angel"><strong><em>Read our analysis of the WikiLeaks revelations here.</em></strong></a></p><p><em>Picture: Bigstock</em></p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28276/apple-ios-1021-protects-users-from-weeping-angel" data-original-url="/security/28276/apple-ios-1021-protects-users-from-weeping-angel">Apple iOS 10.2.1 protects users from Weeping Angel</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/27125/was-an-insider-behind-the-nsa-hack" data-original-url="/hacking/27125/was-an-insider-behind-the-nsa-hack">Was an insider behind the NSA hack?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28251/liberty-launches-legal-challenge-against-investigatory-powers-act" data-original-url="/it-legislation/28251/liberty-launches-legal-challenge-against-investigatory-powers-act">Liberty launches legal challenge against Investigatory Powers Act</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Workplace monitoring: would you let your boss track your mood? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/staffing/surveillance/27912/workplace-monitoring-would-you-let-your-boss-track-your-mood</link>
                                                                            <description>
                            <![CDATA[ Tracking tools by Humanyze are in use at British firms, raising concerns about in-office surveillance ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">t9WddD9YTxqyDVNUtduA2V</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sqkH7VnQ4W42d45NsbkQZb-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 16 Jan 2017 15:48:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/sqkH7VnQ4W42d45NsbkQZb-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sqkH7VnQ4W42d45NsbkQZb-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>At least four British companies are using a tracking device that monitors employees' tone of voice, steps, and stress levels - but so far it's a choice, as 90% of the workers opted into the programme. </p><p>Technology from <a href="http://www.humanyze.com/products.html">Humanyze</a> is being trialed by Deloitte, a high-street bank, a retailer and some parts of the NHS, according to a report in the <em><a href="http://www.thetimes.co.uk/edition/news/bosses-track-you-night-and-day-with-wearable-gadgets-kdn8068ql">Times</a></em>. The tech on trial is a tracker worn on a lanyard around the neck, which gathers data via Bluetooth, accelerometer, GPS and a microphone to monitor employee location, body language, as well as assess stress levels via voice analysis of the tone of conversations. It does not record their content. </p><p>"It's looking at the amount of time you talk, who you talk to, your tone of voice, activity levels, dynamics like how often you interrupt," CEO Ben Waber told the newspaper. "By mining that data, you can actually get very detailed information on how people are communicating, how physiologically aroused people are, and can make predictions about how productive and happy they are at work."</p><p>That could include uncovering how well an employee sleeps, that they interrupt colleagues too often, don't take the stairs instead of the lift, or aren't "optimised" for morning meetings, the report revealed. </p><p>The scheme has naturally raised concerns about privacy, however.</p><p>"These devices are part of a broader shift to a surveillance culture in the workplace," Pam Cowburn, communications director at Open Rights Group, told <em>IT Pro</em>. "While some degree of monitoring may sometimes be necessary, pervasive and intrusive surveillance may actually be counter-productive to good management and training."</p><p>Chris Brauer, director of innovation at the Institute of Management Studies at Goldsmiths, disagreed - he's previously worked on in-office tracking for brain activity and posture. "Employees tend to be very enthusiastic about participating in workplace trials involving wearables," he told <em>IT Pro</em>. "Despite all the hysteria, the goals will be typically beneficial to both the organisation and its workforce: increasing communication channels, recognising innovation, designing a better workplace."</p><p><strong>Worker choice</strong></p><p>Workers in these trials did appear "enthusiastic". None of the employees were forced to wear the device, but the company claimed 90% opted to do so.</p><p>However, Cowburn warned: "Staff may feel [pressured] into consenting to wearing surveillance devices because they fear that they will be discriminated against if they don't."</p><p>Renate Samson, head of Big Brother Watch, said choice was key. "Certainly an individual should be given the right to opt out without any detriment in how their employer sees them," she told <em>IT Pro</em>, adding it's helpful if the tracking has a clear goal, rather than worn for generic, all-the-time data collection.</p><p>The Citizens Advice Bureau points out that companies have a legal right to monitor their staff in "many situations", while Samson noted that employers already have the right to read your work-supplied email and look at your in-office web browsing without first asking your permission. "Work email belongs to the company, and it and your boss can access it without permission," she said, advising staff to carefully read their work contract and employers to make it clear what monitoring they do. </p><p>While workplace monitoring tools would likely fall under similar regulations, Samson noted that "this is a whole new area that needs more conversation".</p><p>Arguably it's difficult to discuss such technologies without first testing them, and the use of Humanyze in particular remains a trial, though <a href="http://www.alphr.com/business/1002466/is-your-boss-spying-on-you">companies have long used other workplace-monitoring tools</a>, most of which focus on location for security purposes or for performance, rather than physiological data on their moods. "Wearables and sensors cover an increasingly wide domain of both technologies and enterprise applications. Gathering physiological data from workers is currently only a very small part of the market," said Brauer. </p><p><strong>Are we turning into robots?</strong></p><p>Indeed, such physiological analysis, or "people analytics" is different from most existing workplace monitoring tools, which tend to focus on optimising productivity, watching how much progress an employee makes, how often they leave their desk and so on. Examples include the <em>Telegraph</em>'s attempted use of OccupEye, a box that monitors how often staff stepped away from their desks, or telematics in lorries to ensure drivers buckle up and behave safely. </p><p>Products such as Humanyze instead measure "softer" data points, such as employee well-being and stress, with rival systems such as Plasticity Labs polling staff to ask how happy they are. Do such mood-analysing systems even work? "We are gathering data all the time about both the reliability (are the results repeatable) and the validity (is the wearable measuring what it is purporting to measure) of emerging technologies of all kinds and wearables are no different," Brauer said.</p><p>Brauer argues that the focus on well-being, health and similar aspects of work are more sympathetic to the human condition than merely tracking location or counting how many widgets a worker produced. </p><p>"There are countless advantages to these kinds of technologies in the workplace," he argued. "They help make visible analytics and data around people instead of just looking only at machines or process flows that can really tend to dehumanise a workforce. You can identify pockets of innovation that need support, clogs and limitations to communications, promote collaboration and teamwork, and design and orient physical space in the interest of a healthier and more productive work environment."</p><p>However, Samson questions whether gather such data on human workers risks managers treating us like robots. "We all fear the robot revolution. We're all worried about our jobs being lost to robots but one of the solutions is not to make humans into robots," she said. "Appreciating a workers unique qualities, abilities to converse in a variety of different ways, and have natural human one-to-one interaction is critical. Formulising your workforce may actually cause more harm than good." </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/27266/how-to-carry-out-workplace-email-surveillance" data-original-url="/security/27266/how-to-carry-out-workplace-email-surveillance">How to carry out workplace email surveillance</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ VoIP software can be used to eavesdrop ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/government-it-strategy/25907/gchq-voip-software-can-be-used-to-eavesdrop</link>
                                                                            <description>
                            <![CDATA[ The backdoor could allow agents, employers or third parties to listen in on conversations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qF9ubsACvE1wmrJrTBJbBV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nzUxpj7jRvPYD8sdFZdMbk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 22 Jan 2016 08:26:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nzUxpj7jRvPYD8sdFZdMbk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Snooping]]></media:description>                                                            <media:text><![CDATA[Snooping]]></media:text>
                                <media:title type="plain"><![CDATA[Snooping]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nzUxpj7jRvPYD8sdFZdMbk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The GCHQ has developed VoIP encryption tools with a built-in backdoor, allowing both authorities and third parties to listen in on conversations.</p><p>The backdoor is embedded into the MIKEY-SAKKE encryption protocol and has a 'key escrow' built in, allowing those with authority - whether an employer or government agency - to access it if a warrant or request is made.</p><p>The backdoor was uncovered by Dr Steven Murdoch, a security researcher from the University of London, who wrote a blog about the potential snooping tool.</p><p>He explained that MIKEY-SAKKE has a monopoly over other security protocols used by approved government voice communications, meaning almost all software used for communication is using the encryption, with the enbedded backdoor. GCHQ can also insists the technology is used in other products used by the public sector and companies "operating critical national infrastructure".</p><p>"Although the words are never used in the specification, MIKEY-SAKKE supports key escrow," Murdoch wrote. "That is, if the network provider is served with a warrant or is hacked into it is possible to recover responder private keys and so decrypt past calls without the legitimate communication partners being able to detect this happening."</p><p>He explained this is being marketed as a benefit to using MIKEY-SAKKE rather than a bug, with documentation issued by GCHQ advertising it means employers can listen into voice communications when investigating into misconduct trials.</p><p>"The Government should come to the realisation that the inclusion of backdoors in encryption isn't merely a legislative or privacy mandate, however, it is technically impossible to control the use of a backdoor in this way." Justin Harvey, chief security officer at Fidelis Cybersecurity said. </p><p>"I liken the pro-backdoor encryption movement to complaints about the weather; some people complain about rain, snow or sunshine and wish it were otherwise, but in the end, we can't do anything about it. The same is true for strong encryption."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Adaptive Mobile reveals hacker holes in mobile networks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/hacking/25446/adaptive-mobile-reveals-hacker-holes-in-mobile-networks</link>
                                                                            <description>
                            <![CDATA[ The flaws can be used by malicious actors maliciously and governments to carry out large-scale attacks and surveillance operations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qyPyN4tyEbdarPDArfHiX5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NYhtSnRYodjcHZnHiW5Lja-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Oct 2015 07:54:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NYhtSnRYodjcHZnHiW5Lja-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NYhtSnRYodjcHZnHiW5Lja-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Adaptive Mobile has uncovered a security flaw in mobile networks that could cause widespread fraud and large-scale surveillance attacks for mobile users.</p><p>The threat takes advantage of a hole in Signalling System 7 (SS7), which is used to connect mobile networks around the world.</p><p>According to Adaptive Mobile, almost every network around the world uses SS7 and most people use it everyday. In fact, the company's Cathal McDaid, head of Adaptive Mobile's threat intelligence unit, said more people use SS7 on a daily basis than the internet.</p><p>Cyber criminals are using the vulnerability to infiltrate mobile network billing systems and then trick them into giving the criminals lower-cost calling and roaming charges.</p><p>Governments are also said to be taking advantage and listening into confidential conversations. An example Adaptive Mobile gave was how conversations were monitored between MTC Ukraine network users and individuals on a Russian mobile phone network, although it hasn't been revealed who was behind the hack.</p><p>"The SS7 vulnerabilities are just another example of software-based systems that weren't built for the rich interconnectivity and threats of the modern mobile infrastructure," Chris Wysopal, CISO and CTO at Veracode said. "Development teams need to go into projects with the expectations that what they're creating will live in a hostile environment where attackers will look to exploit vulnerabilities. We've seen this across every industry and it's no surprise it's occurring in the telco industry."</p><p>A number of companies have investigated mobile network flaws, discovering it's a widespread problem caused, in many cases, by out-of-date technologies that haven't had significant updates since mobile phones became widespread ten or more years ago.</p><p>"A core protocol like SS7 provides governments and rogue actors wide access to the world's communications infrastructure making it an incredibly attractive system to break into," Wysopal added. "Until software developers change their approach and build security into their code from the start, we're going to continue to see these problems."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Gov denies Verify could be used to spy on you ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/government-it-strategy/24838/gov-denies-verify-could-be-used-to-spy-on-you</link>
                                                                            <description>
                            <![CDATA[ GDS issues rebuttal to paper claiming identity assurance scheme degrades your privacy ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bRKy2MXRAP8mRSxMq6ev1G</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SxL5K5kxee3QDGTtjHGFmn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Jun 2015 10:37:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SxL5K5kxee3QDGTtjHGFmn-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Government]]></media:description>                                                            <media:text><![CDATA[Government]]></media:text>
                                <media:title type="plain"><![CDATA[Government]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SxL5K5kxee3QDGTtjHGFmn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The government has denied its new identity assurance service, <a href="https://www.itpro.com/government-it-strategy/23951/govuk-verify-needs-more-data-sources-for-wider-adoption" target="_blank" data-original-url="https://www.itpro.com/government-it-strategy/23951/govuk-verify-needs-more-data-sources-for-wider-adoption">Gov.uk Verify</a>, could lead to mass surveillance of citizens, following claims made by a group of academics.</p><p>Verify reduces the privacy of citizens due to technical flaws in the system's architecture, wrote the three authors of a paper titled <a href="http://www0.cs.ucl.ac.uk/staff/G.Danezis/papers/popets15-brokid.pdf" target="_blank"><em>Toward Mending Two Nation-Scale Brokered Identification Systems</em></a>.</p><p>The Government Digital Service (GDS) designed Verify as a way for people to prove they are who they say they are when using government services online, and HMRC is already using it with allegedly mixed success.</p><p>Verify relies on a central hub to mediate interactions between the departments providing a service, <a href="https://www.itpro.com/public-sector/24297/govuk-verify-partner-scheme-adds-five-new-members" target="_blank" data-original-url="https://www.itpro.com/public-sector/24297/govuk-verify-partner-scheme-adds-five-new-members">companies performing the identity checks</a> and the citizens using Verify.</p><p>Users of Verify are passed to identity authentication providers, who ask questions and use official documentation to confirm citizens' IDs, the idea being to limit the amount of information the government or the providers have on people.</p><p>But the authors of the research, Lus Brando, Nicolas Christin, and George Danezis warned too much trust has been placed in the hub, through which all the information travels, as it has the power to read encrypted information coming from identity checks and users themselves.</p><p>"The excessive trust placed on the hub could be notably used to support undetected mass surveillance," the report read.</p><p>"Leaving the hub outside of the scope of privacy and security goals triggers serious problems. As currently inferred, [Gov.uk Verify] may actually degrade the privacy of citizens."</p><p>However, the GDS published a <a href="https://identityassurance.blog.gov.uk/2015/06/22/gov-uk-verify-hub-privacy-aspects" target="_blank">blog post</a> this morning denying Verify could be used to spy on people.</p><p>It read: "Gov.uk Verify does not allow for mass surveillance. It does not have any other connection with or ability to monitor people or their data.</p><p>"Only minimal data passes through the Gov.uk Verify hub. The person's name, address and date of birth [and gender] is sent through the hub to a government department the person is trying to access.</p><p>"No data about the person's interactions or activities within certified companies or government departments passes through the hub."</p><p>But the GDS did say the report's findings added to the pool of knowledge around digital identity assurance issues, and has welcomed Danezis as a member of the government's privacy and consumer advisory group.</p><p>Verify's use by HMRC came under scrutiny this month after thousands were understood to have missed out on a marriage tax break because they were asked to provide documents many people did not actually have.</p><p>In response, HMRC is introducing an alternative process for those who have been unable to use Verify to apply for the tax break.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Watchdog says “intolerable” terror laws must be scrapped ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/server/24786/watchdog-says-intolerable-terror-laws-must-be-scrapped</link>
                                                                            <description>
                            <![CDATA[ Adds that stronger reasons required to introduce Snoopers' Charter ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qsZZkr69Hinh9FdCZoHgJJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RPcs2bRtSKhiU8nJeEqSYN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Jun 2015 15:41:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RPcs2bRtSKhiU8nJeEqSYN-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[surveillance]]></media:description>                                                            <media:text><![CDATA[surveillance]]></media:text>
                                <media:title type="plain"><![CDATA[surveillance]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RPcs2bRtSKhiU8nJeEqSYN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK must redraft its "intolerable" terror laws from scratch, a watchdog recommended today.</p><p>Parts of RIPA, and DRIPA 2014, must be scrapped by the government as it returns to the drawing board, said David Anderson, Britain's independent reviewer of anti-terrorism laws, in his report published today.</p><p>The report <em>'A Question of Trust'</em> also said the government must outline the need for new surveillance powers such as the Snooper's Charter.</p><p>Writing in his report, Anderson said: "RIPA, obscure since its inception, has been patched up so many times as to make it incomprehensible to all but a tiny band of initiates. This state of affairs is undemocratic, unnecessary and in the long run intolerable.</p><p>"But trust requires verification. Each intrusive power must be shown to be necessary, clearly spelled out in law, limited in accordance with international human rights standards and subject to demanding and visible safeguards."</p><p>RIPA, which allows police and spies to intercept emails, phone calls and snoop on people's online movements, should be overseen by a law that bolsters safeguards to prevent abuses of power.</p><p>One measure the report recommended was to strip ministers' powers to approve surveillance warrants, giving these responsibilities to judges, instead.</p><p>A new law should be easy to understand, too, while any extra surveillance powers must be justified by strong cases for their introduction, Anderson added.</p><p>He called for a new easily understood, comprehensive law with improved safeguards, and judges, not ministers, approving warrants to allow access to the content of emails, phone calls and other communications.</p><p>It should also comply with human rights standards, despite the Conservatives' proposal to ditch the Human Rights Act</p><p>Any further powers, such as forcing service providers to keep details of all individuals' internet use, should only be allowed after a compelling case was made, he added.</p><p>Shami Chakrabarti, director of human rights organisation Liberty, said: "This thoughtful report is in sharp contrast with the defensive whitewash from the discredited Intelligence and Security Committee of the last Parliament. </p><p>"Whilst we don't agree with all his conclusions, Mr Anderson's intervention could be the beginning of re-building public trust in surveillance conducted with respect for privacy, democracy and the law. It is further vindication of Edward Snowden's courage."</p><p>The part Chakrabarti does not agree with is Anderson's support that mass surveillance should continue, if the right safeguards can be introduced.</p><p>He wrote: "The capability of the security and intelligence agencies to practise bulk collection of intercepted material and associated data should be retained ... but used only subject to strict additional safeguards."</p><p>These cover judicial authorisation and a tighter definition of the reasons it is required.</p><p>Reacting to the report, Home Secretary Theresa May suggested she would push the Snoopers' Charter through Parliament regardless of the report's advice.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Legal scholars plead with MPs over Snooper’s Charter ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-protection/24670/legal-scholars-plead-with-mps-over-snooper-s-charter</link>
                                                                            <description>
                            <![CDATA[ Academics sign open letter to stem government-sanctioned data collection ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pa1eqGMZaWQJzWWQ8qabmk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/a7VvP8PHKKNfqMksHrF8c3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 26 May 2015 11:06:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Alan Lu ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/a7VvP8PHKKNfqMksHrF8c3-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[government]]></media:description>                                                            <media:text><![CDATA[government]]></media:text>
                                <media:title type="plain"><![CDATA[government]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/a7VvP8PHKKNfqMksHrF8c3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A group of prominent UK legal academics is urging MPs to closely scrutinise the new Conservative government's attempts to give the security services greater internet surveillance powers.</p><p>The revived Communications Data Bill was blocked under the coalition government by the Liberal Democrats, but Home Secretary Theresa May hopes the so-called Snooper's Charter will be passed under the majority Tory Parliament.</p><p>If approved, British spy agencies would have legal access to citizens' data, with the bill forcing internet service providers to collect and store vast amounts of information on users, handing it over to the government on request.</p><p>The letter, signed by 38 law professors, lecturers and researchers, argues that proper Parliamentary oversight is needed as the previous Coalition Government tried to authorise dramatic new surveillance powers without proper debate in the House of Commons.</p><p>As an example, it cites a draft Code of Practice published in February 2015 that tried to give the intelligence services the authority to hack computers both in the UK and abroad.</p><p>The group of legal experts, which includes individuals both for and against increased surveillance powers, point out that this proposed authority was contained in a draft code rather than in a Bill.</p><p>MPs were therefore denied an opportunity to debate its effects even though, the academics argue, state-sponsored hacking "threatens the security of all internet services as the tools intelligence services use to hack can create or maintain security vulnerabilities that may be used by criminals to commit criminal acts and other governments to invade our privacy".</p><p>Signatory Andrew Murray, professor of law at the London School of Economics, told <em>IT Pro</em>: "We hope that MPs, especially those newly elected to the Commons, will take heed of our warning that surveillance powers must be subject to Parliamentary scrutiny and must be proportionate.</p><p>"By highlighting failings in the previous Parliament we hope MPs will be aware of the risks of failings in Parliamentary scrutiny and will take steps to educate themselves in this area."</p><p>Murray himself is highly critical of mass surveillance, arguing the balance between privacy and security has tipped too much in favour of security in recent years.</p><p>He added: "We need to ensure surveillance laws are proportionate and respect the rule of law. Full transparency and Parliamentary oversight is the minimum required for this. There is little evidence that mass surveillance is a proportionate response to the risks face [sic] by the country."</p><p>The open letter comes after <a href="https://www.itpro.com/data-protection/24581/tories-suffer-privacy-backlash-over-resurrected-snoopers-charter" target="_blank" data-original-url="https://www.itpro.com/data-protection/24581/tories-suffer-privacy-backlash-over-resurrected-snoopers-charter">privacy groups hit back at renewed proposals for the Snooper's Charter</a>, telling <em>IT Pro</em> the government is guilty of ignoring widespread public concern.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Wikimedia accuses NSA and US DoJ of stifling freedom of speech ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/24206/wikimedia-accuses-nsa-and-us-doj-of-stifling-freedom-of-speech</link>
                                                                            <description>
                            <![CDATA[ The Foundation is taking legal action against the NSA and the US Department of Justice ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">weuFWsA2QMUTWBewDSZeRT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4xj8ZPXCcEyoFNsXbKn6k9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 11 Mar 2015 09:34:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4xj8ZPXCcEyoFNsXbKn6k9-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[legal hammer]]></media:description>                                                            <media:text><![CDATA[legal hammer]]></media:text>
                                <media:title type="plain"><![CDATA[legal hammer]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4xj8ZPXCcEyoFNsXbKn6k9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Wikimedia Foundation is suing the NSA and US Department of Justice because it believes the spy agency's mass surveillance programmes violate freedom of speech laws.</p><p>Eight organisations have signed the documents, calling for the NSA to shut down its large-scale surveillance operation that tracks data flowing to and from the US to protect its 500 million monthly users.</p><p>Lila Tretikov, executive director of the Wikimedia Foundation, said in a blog post on the <a href="http://www.nytimes.com/2015/03/10/opinion/stop-spying-on-wikipedia-users.html?_r=0">New York Times</a>: "The NSA's mass surveillance of Internet traffic on American soil often called "upstream" surveillance violates the Fourth Amendment, which protects the right to privacy, as well as the First Amendment, which protects the freedoms of expression and association.</p><p>"We also argue that this agency activity exceeds the authority granted by the <a href="http://topics.nytimes.com/top/reference/timestopics/subjects/f/foreign_intelligence_surveillance_act_fisa/index.html?inline=nyt-classifier">Foreign Intelligence Surveillance Act</a> that Congress amended in 2008."</p><p>The blog post goes on to explain that Wikipedia's users have the right to browse and upload articles to Wikipedia anonymously and without prejudice. The NSA snooping on its users could break confidentiality, especially in countries where governments are repressive and this could lead Wikipedia's users not to post topical information to the website.</p><p>"By tapping the backbone of the internet, the NSA is straining the backbone of democracy. By violating our users' privacy, the NSA is threatening the intellectual freedom that is central to people's ability to create and understand knowledge," she continued.</p><p>"Privacy is an essential right. It makes freedom of expression possible, and sustains freedom of inquiry and association. It empowers us to read, write and communicate in confidence, without fear of persecution. Knowledge flourishes where privacy is protected."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK tribunal rules GCHQ's NSA data-sharing deal "unlawful" ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/24005/uk-tribunal-rules-gchqs-nsa-data-sharing-deal-unlawful</link>
                                                                            <description>
                            <![CDATA[ Civil liberty groups cheer court ruling, but claim there is more work to do ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2x4oWP8kCmFdzXmHJ2RmUz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Feb 2015 16:34:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Surveillance]]></media:description>                                                            <media:text><![CDATA[Surveillance]]></media:text>
                                <media:title type="plain"><![CDATA[Surveillance]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Investigatory Powers Tribunal (IPT) has declared British intelligence services acted unlawfully by accessing the personal communications data gathered by the US National Security Agency (NSA).</p><p>The IPT, set up 15 years ago to oversee the activities of GCHQ, MI5 and MI6, ruling follows a complaint made by several civil liberties organisations, including Amnesty International, Privacy International, Bytes for All and Liberty.</p><p>The Tribunal said the way intelligence was shared between GCHQ and the NSA's Prism surveillance programme was unlawful up until December 2014, because the rules governing the practice were kept secret.</p><p>Post-December 2014, this was no longer the case, as the details of it were made public through the work of the Tribunal.</p><p>The existence of Prism came to light in a series of disclosures by NSA whistleblower Edward Snowden during the summer of 2013.</p><p>Through the programme, it's alleged the NSA was able to access data used by the a wide range of tech giants, including Microsoft, Yahoo, Google and Facebook, and share it with GCHQ if needed.</p><p>As a result of today's outcome, Privacy International and Bytes for All have asked for further clarification from the court regarding the interception and collection of their communications data.</p><p>If it transpires that their data was unlawfully collected before December 2014, the parties are set to demand its immediate deletion.</p><p>They also want to challenge the assertion that GCHQ's activities after December 2014 were lawful, and have vowed to lodge an application with the European Court of Human Rights on this point.</p><p>Eric King, deputy director of Privacy International, said the ruling should put an end to security agencies acting like they can operate outside of the law.</p><p>"We must not allow agencies to continue justifying mass surveillance programs using secret interpretations of secret laws. The world owes Edward Snowden a great debt for blowing the whistle, and today's decision is a vindication of his actions," he said.</p><p>"But more work needs to be done. The only reason why the NSA-GCHQ sharing relationship is still legal today is because of a last-minute clean-up effort by Government to release previously secret arrangements'.</p><p>"That is plainly not enough to fix what remains a massive loophole in the law, and we hope that the European Court decides to rule in favour of privacy rather than unchecked State power."</p><p>James Welch, legal director for Liberty, added: "The Intelligence Services retain a largely unfettered power to rifle through millions of people's private communications and the Tribunal believes the limited safeguards revealed during last year's legal proceedings are an adequate protection of our privacy. We disagree, and will be taking our fight to the European Court of Human Rights."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Governments accused of using hacked data to spy on people ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/23998/governments-accused-of-using-hacked-data-to-spy-on-people</link>
                                                                            <description>
                            <![CDATA[ According to leaked documents, governmental organisations in the UK, US and Canada are making use of hacked intel ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nWpGZUHXYPhzHxoHihUytR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dpWWQo2P3DuoSFbihnmfPc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Feb 2015 09:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dpWWQo2P3DuoSFbihnmfPc-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hand casting a shadow over a keyboard]]></media:description>                                                            <media:text><![CDATA[Hand casting a shadow over a keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[Hand casting a shadow over a keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dpWWQo2P3DuoSFbihnmfPc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK, US and Canadian governments are using data gleaned from hackers to spy on people, a report has revealed.</p><p>Documents leaked to <em><a href="https://firstlook.org/theintercept/2015/02/04/demonize-prosecute-hackers-nsa-gchq-rely-intel-expertise">The Intercept</a></em> suggest the National Security Agency (NSA) is using data mined by hackers in their own snooping schemes in an initiative called Intolerant.</p><p>One leaked document explained the thinking behind the campaign, stating: "INTOLERANT traffic is very organised. Each event is labeled to identify and categorise victims. Cyber attacks commonly apply descriptors to each victim it helps herd victims and track which attacks succeed and which fail."</p><p>The documents went on to explain that hackers are stealing the emails of some of its targets and collecting their stolen data, meaning the investigating government agencies can get access to their targets' emails and gain other insights into who's being hacked.</p><p>They continued: "People who open attachments from unknown senders (gasp) or respond to 'Nigerian' money laundering emails aren't the only individuals on the internet being hacked.</p><p>"Some of our targets are also being targeted by outside forces, by state-sponsored and freelance hackers. Could your target's communications be the target of other countries or groups?"</p><p>The documents list a number of groups that have been spied upon using the techniques, including the Indian navy, Tibetan pro-democracy personalities and the Tibetan Government in Exile.</p><p>Other documents referred to a scheme named Lovely Horse that monitored security analyst and hacker Twitter accounts to gain insights into how to more effectively monitor targets.</p><p>"Analysts are potentially missing out on valuable open source information relating to cyber defence because of an inability to easily keep up to date with specific blogs and Twitter sources," the documents said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Government slammed for using Charlie Hebdo attack to revive Snoopers Charter ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/strategy/23851/government-slammed-for-using-charlie-hebdo-attack-to-revive-snoopers-charter</link>
                                                                            <description>
                            <![CDATA[ The ICO and ISPA hit out at Government's attempt to use Paris attacks to push for more surveillance powers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">94W7HVSCTP1JPzMB9o6uEv</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 14 Jan 2015 13:22:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Surveillance]]></media:description>                                                            <media:text><![CDATA[Surveillance]]></media:text>
                                <media:title type="plain"><![CDATA[Surveillance]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Government needs to keep a "cool head" about how much access the security services should have to people's private data, in the wake of last week's Paris shootings.</p><p>That's according to Christopher Graham, the UK's Information Commissioner, who warned the Government off making any rash decisions about curtailing the use of encrypted online services for surveillance purposes.</p><p>"We need cool heads to analyse carefully what information the security services had access to [in the run up to the shootings] and how they used it before necessarily concluding that we must give [the powers that be] access to more and more of our private information," he said during a speech marking the 125th Roscoe Lecture at Liverpool's John Moores University.</p><p>"We must avoid knee-jerk reactions. In particular, I am concerned about any compromising of effective encryption for consumers of online services."</p><p>His comments follows the news earlier this week about the Prime Minister's plans to stop people using encrypted messaging services, such as WhatsApp and iMessage, on anti-terrorism grounds.</p><p>As <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security/23840/whatsapp-imessage-face-uk-ban-on-anti-terrorism-grounds">reported by <em>IT Pro</em> yesterday</a>, David Cameron said he would not hesitate to legislate against the use of these services, should his party remain in power beyond the 2015 General Election.</p><p>Graham went on to say that offering encryption to users of online services is an essential step in the fight against cybercrime, but accepts these services could be exploited by people who use them to operate under the radar.</p><p>That's why a healthy balance must be struck between protecting the privacy of individuals, and the public interest in keeping tabs on people's online activities.</p><p>"In matters of security, we surely need an effective, American-style Privacy and Civil Liberties Oversight Board or the equivalent to find the right balance," he added.</p><p>The ICO isn't the only industry body concerned by the push to give the intelligence services greater online surveillance powers since the attack on offices and staff of French satirical magazine Charlie Hebdo.</p><p>In a statement, Nicholas Lansman, secretary general for the Internet Service Providers Association (ISPA), said doing so would be the "easy way out" for politicians.</p><p>Particularly those intent on using the attacks to make a renewed push to introduce the controversial Communications Data Bill, AKA The Snoopers Charter.</p><p>"Existing legislation already allows for suspects' communications to be intercepted via a warrant, and the retention of communications data, which is already being retained in the UK, would also have been available to the intelligence services and the police under the existing RIPA process," Lansman added.</p><p>"While the draft Communications Data Bill would have provided access to broader data set, it is questionable whether it would have helped to prevent the incidents in Paris and the industry and UK citizens should be provided with a clear justification for why the Bill is needed now."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[  Anti-terror measures: How tech helps fight the counter-terrorism war ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/23685/anti-terror-measures-how-tech-helps-fight-the-counter-terrorism-war</link>
                                                                            <description>
                            <![CDATA[ Davey Winder examines how technology can help and hinder in the fight against terrorism ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mwuhZ2Z1n6wmHewmaWeFeE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xPZqvJFthBNFwUWQeLDGCY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 09 Dec 2014 12:27:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xPZqvJFthBNFwUWQeLDGCY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xPZqvJFthBNFwUWQeLDGCY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Science is being used to counter "technically aware terrorists", as part of a wider technology push for countering international terror threats, according to the UK government's recent <em>Protecting the UK Against Terrorism </em><a href="https://www.gov.uk/government/policies/protecting-the-uk-against-terrorism/supporting-pages/using-science-and-technology-to-counter-the-threat-from-terrorists">policy document</a>.</p><p>Because of the nature of the counter-terrorism beast, exactly what technology is being used and how it is being implemented is not in the public domain. That doesn't mean, however, we are unaware that communication monitoring techniques are at the very heart of the surveillance and interception policy and have been for many years.</p><p>Indeed, the 1991 Intelligence Services Act and the 2000 Regulation of Investigatory Powers Act give law enforcement and security agencies fairly sweeping authority to intercept and monitor everything from mobile phone calls to email and social media usage.</p><div><blockquote><p>There's a very fine line between counter-terrorism and wholesale State monitoring of citizens. Which is why, post-Snowden, the big players have woken up to encryption and the newly-enlightened public's desire to embrace it.</p></blockquote></div><p>I'm not going to cover old ground, on the basis that everyone knows about the Edward Snowden <a href="https://www.itpro.com/security/22650/snowden-just-10-of-nsa-data-is-terrorism-related" data-original-url="https://www.itpro.com/security/22650/snowden-just-10-of-nsa-data-is-terrorism-related">revelations by now</a>. However, only a fool would think spies are going to stop spying; it's what they do, and when 'the threat' could be any one of us they will spy on all of us.</p><p>I don't like it and there's a very fine line between counter-terrorism and wholesale State monitoring of citizens. Which is why, post-Snowden, the big players have woken up to encryption and the newly-enlightened public's desire to embrace it.</p><p>It's also why Robert Hannigan, the UK spymaster general at GCHQ, has accused companies of enabling platforms that have become "the command and control networks of choice" for terrorist groups like ISIS.</p><p>Breaking encryption is, one would assume and if you'll excuse the pun, another key to counter-terrorism success. Which is why during a recent visit to Professor Andrew Blyth, director of the Information Security Research Group based at the University of South Wales, I wasn't surprised to learn government agencies have already expressed an interest in his lab's ability to break the device encryption employed by iOS 8.</p><p>Intercepting communications will be at the heart of every counter-terrorist investigation, just as it has always been, because as one intelligence officer so aptly put it "terrorists have to communicate." How they communicate, of course, is also part of the growing problem for the counter-terrorism guys.</p><p>Looking beyond the cloak and dagger, encoded messages and dark corner conversations, some terrorist communication is much more open. Use of the web, via YouTube videos and social media has become de rigueur when it comes to the distribution of extremist material, propaganda and misinformation alike.</p><p>All of which are powerful weapons in the terrorist arsenal, and which have been used with devastating effect recently by ISIS for both showcasing executions and recruiting new fighters for its cause. In an attempt to proactively defend against such tactics, the Metropolitan Police established a dedicated <a href="http://www.acpo.police.uk/ACPOBusinessAreas/PREVENT/TheCounterTerrorismInternetReferralUnit.aspx">Counter Terrorism Internet Referral Unit</a> (CTIRU) in 2010 that deals with public reports of online content "of a violent extremist or terrorist nature." Since it started, CTIRU has removed some 55,000 pieces of content and 34,000 of those have been in the last year alone.</p><p>More controversially, the UK government is putting pressure on Internet Service Providers to block 'extremist' content at source, so that customers would not be able to see it. This blocking would, if successful, take the form of optional filtering such as is already in place for pornographic content, for example.</p><p>Quite how effective this might be is one legitimate question being raised by both the ISPs themselves and internet rights groups, with opt-in filters not proving that popular with the public and methods of circumventing them being readily available for anyone who cares to Google for it.</p><p>Another legitimate question is who determines what content is extremist, and how is that determination reached? Whenever we talk of political censorship we have to be very careful to be transparent and open, otherwise it's a very slippery slope leading further down the road to state-controlled media.</p><p>I appreciate such a view will, no doubt, have some readers on the verge of an aneurysm but there has to be a method of knowing who is blocked and why, and an appeals mechanism for when the system inevitably screws up.</p><p>According to CTIRU, examples of what is currently considered extremist include speeches or essays calling for racial or religious violence, videos of violence with messages of glorification' or praise for terrorists, postings inciting people to commit acts of terrorism or violent extremism and messages intended to generate hatred against any religious or ethnic group.</p><p>Of course, even if such a method of filtering online material were to be agreed it would need to be implemented by every UK-based ISP to be effective. And there lies the next stumbling block, and one the likes of CTIRU has to deal with: most social media organisations are not based in the UK and are not obligated to remove content when asked to by UK law enforcers.</p><p>I'm not saying they won't or don't, but the process is an entirely voluntary one and that's why definitions of extremism and terrorism have to be front and centre of the counter-terrorism tech debate. The international element also raises another concern over counter-terrorism measures when they flow into the social media and online realm, namely who gets to participate in the takedown process? Free speech is a two-way street and with social media being a global game there are players whose politics and definitions of extremism and terrorism differ from ours.</p><p>Social media is no longer a two-horse race with just Facebook and Twitter to deal with, smaller players quickly gain traction with the young (who are the main targets of extremist propaganda, remember) and may be less amenable to kicking the freedom of speech ball out of play. Especially in a post-Snowden world where tech companies have seen the backlash when any hint of being in bed with the spymasters becomes public.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russian webcam hackers: Nothing to see here ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/23610/russian-webcam-hackers-nothing-to-see-here</link>
                                                                            <description>
                            <![CDATA[ Davey Winder explains why the Russsian webcam story isn't news at all... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iWG5FmExqpGFnx56bJJLL3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9hyhA8qN9gdwGyFYBvjrPW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Nov 2014 16:24:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9hyhA8qN9gdwGyFYBvjrPW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[CCTV cameras]]></media:description>                                                            <media:text><![CDATA[CCTV cameras]]></media:text>
                                <media:title type="plain"><![CDATA[CCTV cameras]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9hyhA8qN9gdwGyFYBvjrPW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The slightest hint of voyeurism and the news media is all over an IT security issue like an itchy rash.</p><p>I'm talking about last week's story about a Russian website that was found to be streaming the live feeds of thousands of unsecured webcams from around the world.</p><p>The site had been known about for a while before the BBC and others picked up on it, as word of it had already been widely circulated on social media sites long before.</p><p>This wasn't the only thing that made the story old news, because the so-called hacking of webcam feeds isn't a new phenomenon. I have been writing about the risk of unsecured network cams with IP addresses since they first hit the market more than a decade ago.</p><p>But why, I hear you ask, have I referred to it as "so-called hacking"? The reason for that is because there is precious little hacking involved. In actual fact, all that is happening here are people and organisations hooking their webcams and CCTV units up to the internet without bothering to change the default admin logins and passwords first. </p><p>Of course, the media interest has peaked because of two things: Firstly there's opportunity for a scare story about someone, somewhere watching us get down and dirty in the bedroom. Although why anyone would want a live streaming camera in the bedroom is beyond me, unless they wanted people to see their intimate moments.</p><p>Then there's the Internet of Things (IoT) connection. Just as with the cloud prefix, if a story can be associated with the IoT, it's worth running. The fact that IP cams pre-date the IoT by a decade is neither here nor there. A bit like the Russian site in question.</p><p>I went and looked at it when I first heard about it, hopeful that something more interesting than empty car parks, office hallways and dingy corners of warehouses might be on display. But no, that was pretty much it no matter which location I looked in, any time of day, anywhere on the map. This is, almost, a non-story then.</p><p>Except it does serve to remind us that we are responsible for our own actions and our own security. Simply blaming the 'bloody Russians' for putting this site up and 'hacking' into all those cameras is not good enough.</p><p>The buck stops with the user; if you have an IP connected camera and haven't bothered to change the defaults for remote access or secure the damn thing behind your perimeter defences. The larger the enterprise, the better the security posture and the more comprehensive the security policy so the less chance of this happening. That's what my experience of such things would suggest at least. The further down the enterprise size scale you slide, the greater the risk of inadvertent exposure becomes.</p><p>It also reminds us that vendors have a role to play here, and have known about the dangers these camera defaults pose for years yet have done naff all to rectify the matter and switch them off out of the box. Would it really be such a problem to Joe User that remote internet access had to be switched on if that was made clear on the packaging, on the device and in the instruction manual? Is Joe User really that thick? Don't answer that...</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Facebook outed as host of Lee Rigby murder chat ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/23599/facebook-outed-as-host-of-lee-rigby-murder-chat</link>
                                                                            <description>
                            <![CDATA[ Extremist had "online exchange" via Facebook claiming he wanted to kill a soldier, it has emerged ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">beqe2MiCtXXPKWPJSw3eyE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/efEsxopTc8zj7ctpbKUYVK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Nov 2014 12:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Social Media]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/efEsxopTc8zj7ctpbKUYVK-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Facebook]]></media:description>                                                            <media:text><![CDATA[Facebook]]></media:text>
                                <media:title type="plain"><![CDATA[Facebook]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/efEsxopTc8zj7ctpbKUYVK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Facebook has been outed as the unnamed internet company accused of failing to flag details of an online conversation between one of Fusilier Lee Rigby's killers and a fellow extremist where he outlined plans to kill a solider.</p><p>A report <a href="https://b1cba9b3-a-5e6631fd-s-sites.googlegroups.com/a/independent.gov.uk/isc/files/20141125_ISC_Woolwich_Report%28website%29.pdf?attachauth=ANoY7co8-06O2Fk8Kf9e_hXtQ2V5UlgStlYCFg1WSl7tcUO33wSx-ZHI_i1u3FVCdd8iHRCCF2dsMVSKPZ4Y7eivtXY7j_bML_EOBJHf4U4txraiSnDaG_JoVZdc3ygfJ8QYuEpcuc4pN-5-7fDNReZIeSbC4RDdZ1Z5b7Yf5JhWcKem7LgZ6CTLkXeJMy_gNK5DNts7bqqEkdgrNZB3uK4VTCkePZibXQcVeRX2BHi1Ekl0wlhgM6Zscat3YEMVQ7XSqMZNXqvB&attredirects=0">published</a> yesterday by the Intelligence and Security Committee (ISC) of Parliament into the circumstances that led to the murder of Lee Rigby in May 2013 said an "unnamed "internet company could have taken steps to prevent it, and the <a href="http://www.bbc.co.uk/news/technology-30199131">BBC has since confirmed</a> the company in question is social networking giant Facebook.</p><p>According to the ISC document, one of the perpetrators of the crime - Michael Adebowale had an online exchange with a fellow extremist where he detailed plans to murder a British soldier in December 2012.</p><p>Details of this exchange only emerged after the fatal attack against Rigby took place, but it could have been detected earlier, the report claims, if the social network had flagged it.</p><div><blockquote><p>To pass the blame to internet companies is to use Fusilier Rigby's murder to make cheap political points.</p></blockquote></div><p>The report claims the unnamed communications service provider automatically closed several accounts belonging to Adebowale for terrorism-related reasons without passing on details to the authorities about the nature of his discussions.</p><p>"They [the communications provider] had not been aware of the content of these accounts before as they did not routinely monitor content in this way," it was noted.</p><p>"GCHQ understands that Adebowale's accounts were disabled as a result of an automated process, where activity met the above descriptors, but that the company did not then manually review the content of these accounts, nor pass any information to the authorities," it adds.</p><p>The report goes on to claim that, had the company passed on details of Adebowale's online activities, his discussion with the extremist may have come to light sooner.</p><p>"We take the view that, when possible links to terrorism trigger accounts to be closed, the company concerned and other communications service providers should accept their responsibility to review these accounts immediately and, if such reviews provide evidence of specific intention to commit a terrorist act, they should pass this information to the appropriate authority," the report continues.</p><p>In a statement to <em>IT Pro</em>, a Facebook spokesperson said the company does take action to prevent terror-related content from being shared on the site. </p><p>"Like everyone else, we were horrified by the vicious murder of Fusilier Lee Rigby. We don't comment on individual cases but Facebook's policies are clear, we do not allow terrorist content on the site and take steps to prevent people from using our service for these purposes," the spokesperson said.</p><p>The report's conclusion has been criticised by Jim Killock, executive director of privacy organisation The Open Rights Group, who said the government is wrong to use Rigby's murder to build a case for keeping closer tabs on the online activities of UK citizens.</p><p>"To pass the blame to internet companies is to use Fusilier Rigby's murder to make cheap political points," he said.</p><p>"And it is quite extraordinary to demand that companies pro-actively monitor email content for suspicious material. Internet companies cannot and must not become an arm of the surveillance state."</p><p>He goes on to add that mass surveillance, rather than reassure citizens, actually makes them more distrustful of the authorities.</p><p>"The security services should focus their efforts on the targeted surveillance of individuals like Michael Adebolajo [Adebowale's accomplice] rather than continuing to monitor every citizen in the UK," Killock continues.</p><p>"Mass surveillance erodes the basic trust between citizen and state by treating us all as suspects. If the government keeps finding new ways to justify indiscriminate whole population trawls, it will be fair to say that we have lost our liberty and the terrorists have won."</p><p>The Internet Service Providers' Association (ISPA) has also hit back at the report's suggestion that online comms providers should do more to keep tabs on users, and that the internet as a whole has become a "safe haven for terrorists."</p><p>In a statement, the ISPA said: "It is for the intelligence agencies and not service providers to identify potential subjects, and when identified by the authorities CSPs (communication service providers) can and do assist in providing communications data under a clear legal process.</p><p>"The proposal that companies should monitor all communications online runs counter to the legal framework that underpins the internet, which forbids unwarranted monitoring of customers' communications. </p><p>ISPA and its members are in active discussions around communications data capabilities, including the current Anderson Review, and the ISC's report adds to the ongoing discussions," it concluded.</p><p><em><strong>This article was originally published on 25 November, before being updated with further comment from Facebook, the ISPA and others.</strong></em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Privacy groups unveil Detekt surveillance malware detection tool ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/23579/privacy-groups-unveil-detekt-surveillance-malware-detection-tool</link>
                                                                            <description>
                            <![CDATA[ New tool looks for state spyware on activist computers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cfmuq8HEcB8ygY4ZR3bsg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Nov 2014 15:33:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Surveillance]]></media:description>                                                            <media:text><![CDATA[Surveillance]]></media:text>
                                <media:title type="plain"><![CDATA[Surveillance]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Human rights and privacy campaigners have designed a tool to sniff out state-sponsored surveillance malware.</p><p>The software, dubbed Detekt, is geared towards helping activists find out if their PCs have been infected with government-backed surveillance malware.</p><p>The campaigners behind the software include Amnesty International, the Electronic Frontier Foundation (EFF), Privacy International and Germany's Digitale Gesellschaft. </p><p>Detekt was developed by security researcher Claudio Guarnieri, and is reportedly the first tool of its kind to be made publicly available that detects well-known surveillance spyware, some of which is used by government computers. </p><p>"Governments are increasingly using dangerous and sophisticated technology that allows them to read activists and journalists' private emails and remotely turn on their computer's camera or microphone to secretly record their activities," said Amnesty head of military, security and police Marek Marczynski.</p><p>"They use the technology in a cowardly attempt to prevent abuses from being exposed."</p><p>The privacy groups admitted the tool may not detect all spyware and - if any is found - it won't be removed, but the software be important in gathering evidence of surveillance taking place.</p><p>"It represents a strike back against governments who are using information obtained through surveillance to arbitrarily detain, illegally arrest and even torture human rights defenders and journalists," added Marczynski. </p><p>Some surveillance technology is widely available on the internet, while other more sophisticated alternatives are developed by private companies based in developed countries and sold to state law enforcement and intelligence agencies in countries that persistently commit human rights violations. </p><p>FinFisher, a German firm that used to be part of UK-based Gamma International, developed the FinSpy spyware which can be used to monitor Skype conversations, extract files from hard drives, record microphone use and emails, and even take screenshots and photos using a device's camera. </p><p>Finfisher was used to spy on prominent human rights lawyers and activists in Bahrain. </p><p>Marczynski said Detekt is "a great tool which can help activists stay safe but ultimately the only way to prevent these technologies from being used to violate or abuse human rights is to establish and enforce strict controls on their use and trade."</p><p>The tool can be downloaded from <a href="https://resistsurveillance.org">here</a>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Yahoo details government requests for data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/23197/yahoo-details-government-requests-for-data</link>
                                                                            <description>
                            <![CDATA[ Nearly 7,000 requests made by US government alone in six months ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nwmx6bZkCwkEkw59e7pL8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/64DtPhsPXuyF7SWZrukyye-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 29 Sep 2014 09:17:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/64DtPhsPXuyF7SWZrukyye-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[snooping]]></media:description>                                                            <media:text><![CDATA[snooping]]></media:text>
                                <media:title type="plain"><![CDATA[snooping]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/64DtPhsPXuyF7SWZrukyye-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US government made 6,791 requests for data to Yahoo in the first six months of the year, more than twice the number made by any other country.</p><p>According to <a href="https://transparency.yahoo.com/government-data-requests/index.htm">Yahoo's Government Data Requests report</a>, the firm received 2,872 requests for data by Germany (second only to the US), while the UK submitted 1,408 requests.</p><p>However, out of these 6,971 requests by US authorities, only 382 were rejected by Yahoo. The firm rejected 575 requests from the UK while Germany saw 1,529 of its requests (over half) fall on deaf ears at Yahoo.</p><p>In the report, Yahoo said that while it complied with lawful requests for data, it carefully scrutinised "each request to make sure that it complies with the law, and we push back on those requests that don't satisfy our rigorous standards."</p><p>In a <a href="http://yahoo.tumblr.com/post/98394296894/yahoo-transparency-report-update">blog post</a>, Yahoo general counsel Ron Bell, said the publication of the report was to continue "our efforts to provide as much information as we can about government requests for our users' data and government requests to remove content".</p><p>He said, despite handing over data to authorities, Yahoo's users would "always come first".</p><p>Bell added the firm would "narrowly" interpret government requests to minimise disclosure of user data, contest requests it believed may violate a user's human rights, including rights to privacy or free expression as well as publish its transparency report.</p><p>"An important example of how we put users first is <a href="http://yahoopolicy.tumblr.com/post/97238899258/shedding-light-on-the-foreign-intelligence-surveillance">our recent effort </a>to push the US Government to release 1,500 pages of once-secret documents detailing our 2007-08 challenge to the expansion of US surveillance laws," said Bell. "We are still pushing for the FISC to release additional materials from this case. </p><p>"Through the Reform Government Surveillance Group, we are advocating for reform to ensure that US surveillance laws are transparent, reasonable and subject to independent oversight," he added.</p><p>"On the international front, a number of countries seek to expand their surveillance authorities beyond their borders. We will continue our efforts to protect your information from unclear, improper, overbroad or unlawful government requests."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple denies NSA data-grabbing backdoors exist in iOS ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/22763/apple-denies-nsa-data-grabbing-backdoors-exist-in-ios</link>
                                                                            <description>
                            <![CDATA[ Claims made by forensic data scientist at hacking conference about iOS access flaws denied by Apple ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7M3eRvejs2LUpwnBoJHtcS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rspMKVvJ8Fgeo5q2ek64oa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Jul 2014 11:28:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[iOS]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Apple]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rspMKVvJ8Fgeo5q2ek64oa-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rspMKVvJ8Fgeo5q2ek64oa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple's iOS mobile operating system contains numerous backdoors that allow hackers to bypass its PIN and password controls to steal users' personal data, a data forensics scientist has claimed.</p><p>Speaking at the Hackers of Planet Earth (HOPE) conferences last week, Jonathan Zdziarski shared with delegates details about various backdoors he claims to have found in iOS-running devices that could potentially be exploited by government agencies, such as the NSA.</p><p>During his presentation he flagged several mobile OS features that could make the OS vulnerable to government snooping, although <a href="http://www.zdziarski.com/blog/?p=3441">he has since gone to great lengths to reiterate</a> that he has not accused Apple of working with the NSA.</p><div><blockquote><p>We have designed iOS so that its diagnostic functions do not compromise user privacy and security, but still provides needed information to enterprise IT departments.</p></blockquote></div><p>These include the "lockdownd", "Pcapd" and "mobile.file_relay", which it is claimed can side-step encrypted backups to plunder data on the behalf of third parties.</p><p>In a blog post, <a href="http://www.zdziarski.com/blog/?p=3441">published in the wake of his appearance at the conference</a>, he said Apple needs to explain to the 600 million people using iOS devices why this capability is included in the mobile operating system.</p><p>"At the same time, this is NOT a zero day and NOT some widespread security emergency. My paranoia level is tweaked, but not going crazy," he added.</p><p>"My hope is that Apple will correct the problem. Nothing less, nothing more. I want these services off my phone. They don't belong there."</p><p>The claims have been strenuously denied by Apple in <a href="http://www.imore.com/apple-reaffirms-never-worked-any-government-agency-backdoor-product-service">a statement to <em>iMore</em></a>, where it was also quick to stress that it has never worked with any government agency to install a backdoor in one of its products.</p><p>"We have designed iOS so that its diagnostic functions do not compromise user privacy and security, but still provides needed information to enterprise IT departments, developers and Apple for troubleshooting technical issues," the statement reads.</p><p>"A user must have unlocked their device and agreed to trust another computer before that computer is able to access this limited diagnostic data.</p><p>"The user must agree to share this information, and data is never transferred without consent," it added.</p><p>NSA whistleblower <a href="https://www.itpro.com/security/22734/snowden-calls-on-peers-to-develop-anti-surveillance-tech" data-original-url="https://www.itpro.com/security/22734/snowden-calls-on-peers-to-develop-anti-surveillance-tech">Edward Snowden also spoke</a>, via video link, at the conference this week, and urged attendees to use their skills and expertise to build anti-surveillance products. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Snowden calls on peers to develop anti-surveillance tech ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/22734/snowden-calls-on-peers-to-develop-anti-surveillance-tech</link>
                                                                            <description>
                            <![CDATA[ NSA whistleblower to focus on promoting anti-snooping tools ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eBagTVo7s4gMZqUsVXQ6SV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ULyMsNDRUY4EdibcUdr8KJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Jul 2014 09:08:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ULyMsNDRUY4EdibcUdr8KJ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Edward Snowden picture]]></media:description>                                                            <media:text><![CDATA[Edward Snowden picture]]></media:text>
                                <media:title type="plain"><![CDATA[Edward Snowden picture]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ULyMsNDRUY4EdibcUdr8KJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Edward Snowden wants the cybersecurity industry to channel its expertise into creating technologies that prevent governments from snooping on their citizens' online activities.</p><p>Snowden, who has become a torchbearer for the anti-surveillance movement after systematically leaking details about US efforts to keep tabs on its residents, was speaking at the Hackers On Planet Earth (HOPE) conference in New York over the weekend.</p><p>During his presentation, he called on the audience to pool their resources to create anti-tracking technologies that will encrypt messages and allow people to communicate anonymously online.</p><p>"You in this room, right now have both the means and the capability to improve the future by encoding our rights into programmes and protocols by which we rely every day," he said.</p><p>"This is what a lot of my future work is going to be involved in."</p><p>His conference presentation was broadcast via video link from Russia, where Snowden was granted asylum in June 2013 in the wake of revelations he made about the activities of the US National Security Agency (NSA).</p><p>It is understood he has since found work in the country as an IT contractor, but according to a report on <a href="http://www.reuters.com/article/2014/07/19/us-usa-snowden-hackers-idUSKBN0FO0ZB20140719">Reuters</a> his Russian visa is due to expire at the end of this month.</p><p>If the Russian authorities decide not to extend his rights to say in the country, he faces being sent back to the US where he faces criminal charges over his decision to leak classified information about the NSA's activities.</p><p>In his most recent round of revelations, published last week, Snowden claimed nude photos accrued by the NSA during its surveillance activities were "routinely" passed around by some members of staff.</p><p>The claim was made during a seven hour interview with <a href="http://www.theguardian.com/world/2014/jul/17/edward-snowden-professionals-encrypt-client-communications-nsa-spy">The Guardian newspaper</a>, where he also shed some considerable light on his life in Russia.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple denies Chinese government tracks iPhone location data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/22689/apple-denies-chinese-government-tracks-iphone-location-data</link>
                                                                            <description>
                            <![CDATA[ Apple has reassured Chinese iPhone users that the government can't use their location data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5XC4RSLvjdT1wEv3qVDmAS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5pLL7ZyLcCdsB54V95GfXk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Jul 2014 08:17:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[iPhone]]></category>
                                                    <category><![CDATA[Hardware]]></category>
                                                    <category><![CDATA[Mobile Phones]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5pLL7ZyLcCdsB54V95GfXk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5pLL7ZyLcCdsB54V95GfXk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple has released a statement to assure iPhone users the Chinese government can't track their data using the iPhone's location settings.</p><p>Last week, China's state-owned TV broadcaster China Central Television said the government could find out an individual's identity from data intercepted from iPhones.</p><p>The TV service quoted Ma Ding, head of the online security institute at People's Public Security University of China, saying governments could use the Frequent Locations feature, usually used to boost GPS signals in apps such as Maps and Weather, to find out the user's identity and track their movements.</p><p>The report said the data could reveal the country's economic situation and even state secrets. However, Apple argued the data in question is only stored on a user's phone, not on a server that could be hacked. The data is also heavily encrypted meaning even if someone was able to access the data, it would be very hard for them to understand it.</p><p>Apple released the statement on its Chinese website saying it takes privacy very seriously: "We appreciate CCTV's effort to help educate customers on a topic we think is very important. We want to make sure all of our customers in China are clear about what we do and we don't do when it comes to privacy and your personal data."</p><p>The statement continued: "Apple has never worked with any government agency from any country to create a backdoor in any of our products or services. We have also never allowed access to our servers. And we never will. It's something we feel very strongly about."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Angry Birds, Squeaky Dolphin, NoseySmurf: The NSA programs you never knew about ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/22640/angry-birds-squeaky-dolphin-noseysmurf-the-nsa-programs-you-never-knew-about</link>
                                                                            <description>
                            <![CDATA[ IT Pro takes you on a run down of some of the major NSA projects that may have passed you by over the last 12 months ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">k6wA47KBez4T4otymWJony</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Jul 2014 14:12:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Alex Hamilton ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Angry Birds in space]]></media:description>                                                            <media:text><![CDATA[Angry Birds in space]]></media:text>
                                <media:title type="plain"><![CDATA[Angry Birds in space]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The National Security Agency (NSA), set up to combat foreign and domestic intelligence threats to the US, has had its reputation turned upside down since whistleblower Edward Snowden began to leak details of its clandestine activities.</p><p>In the past year, Snowden's leaks have revealed more than 40 separate intelligence campaigns undertaken by the NSA or its UK allies at GCHQ.</p><p>Among the most infamous was the news the NSA had been infiltrating the data centres of US technology companies - including Facebook, Microsoft and Google - and snatching user data from the traffic.</p><p>Upstream and PRISM, the names of the surveillance operations that conducted those clandestine acts, caused outrage throughout the technology industry and the world. People began to wonder if their data was truly safe in the hands of the big companies and on the internet.</p><p>The ripples of that discovery can still be felt today, as companies attempt to <a href="http://www.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web&cd=4&cad=rja&uact=8&ved=0CEAQFjAD&url=http%3A%2F%2Fwww.itpro.com%2Fsecurity%2F20476%2Fnsa-paid-google-yahoo-and-microsoft-cover-prism-compliance-costs&ei=p5a2U5nEJeKR0QXYtoF4&usg=AFQjCNGzaX0iYIZ">side-step their involvement</a> or relocate their services to assuage worried customers.</p><p>Yet those two operations were only part of myriad of projects the NSA and GCHQ have undertaken. The details of many more have been released by Snowden over the past year, some of which you might never even have heard of.</p><h3 class="article-body__section" id="section-angry-birds"><span>Angry Birds</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KVDQadPyDpdDqyKYiVoDmC" name="" alt="Angry Birds in space" src="https://cdn.mos.cms.futurecdn.net/KVDQadPyDpdDqyKYiVoDmC.jpg" mos="https://cdn.mos.cms.futurecdn.net/KVDQadPyDpdDqyKYiVoDmC.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Nowhere is safe from the prying eyes of government agencies, it seems, not even much-loved mobile game Angry Birds.</p><p>As soon as a player opened up the game and began their bird-slinging adventures, algorithms within the game's code relayed their age, sex and other information to intelligence agents.</p><p>This is according to documents leaked from GCHQ, which revealed how it and the NSA had been working on ways to tap into mobiles and collect data through apps. Not just Angry Birds fell foul of the surveillance program: Google Maps, Facebook, Twitter and LinkedIn were also targeted.</p><p>"It effectively means that anyone using a smartphone is working in support of a GCHQ system," a secret 2008 report by the British agency said.</p><h3 class="article-body__section" id="section-noseysmurf"><span>NoseySmurf</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HT86y5RYWJyUcSbQZs6aK5" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/HT86y5RYWJyUcSbQZs6aK5.jpg" mos="https://cdn.mos.cms.futurecdn.net/HT86y5RYWJyUcSbQZs6aK5.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Also known by the names "TrackerSmurf" and "DreamySmurf", the NoseySmurf project tied into the Angry Birds scheme by tapping into mobile phones to scrape data from users.</p><p>The NSA spent over $1 billion (580 million) in its search to find more efficient tracking and piggybacking methods for infiltrating targeted devices. In one top-secret presentation, the agency describes a victim uploading an image to Facebook from their phone as a "Golden Nugget!!"</p><p>From the simple act of someone uploading a picture to a social media site, later slides say, agents could glean a victim's contacts, location, gender, age, income, ethnicity, education level and even number of children.</p><h3 class="article-body__section" id="section-happyfoot"><span>HappyFoot</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7sStEf86W6dUrez2CpsErb" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/7sStEf86W6dUrez2CpsErb.jpg" mos="https://cdn.mos.cms.futurecdn.net/7sStEf86W6dUrez2CpsErb.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>HappyFoot was the codename for an operation designed to track internet users' movements by piggybacking onto their cookies and location data.</p><p>When a consumer visits a site cookies are enabled on their computer, allowing the site's company to tailor advertisements to them, something government snoops were keen to exploit.</p><p>Slides released by Snowden and published by the <a href="http://www.washingtonpost.com/blogs/the-switch/wp/2013/12/10/nsa-uses-google-cookies-to-pinpoint-targets-for-hacking"><em>Washington Pos</em>t</a> revealed the NSA had been latching onto these cookies in order to identify possible targets for further hacking operations.</p><p>Using a <a href="http://www.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web&cd=1&cad=rja&uact=8&ved=0CCUQFjAA&url=http%3A%2F%2Fwww.itpro.com%2Fsecurity%2F21218%2Fnsa-and-gchq-tracked-google-cookies&ei=gJe2U6j6KoyY0AXhqIDwDA&usg=AFQjCNG4k16kB_vQZV576ZQaiF8N4duJEA&sig2=NB">unique cookie from Google</a> called PREF, intelligence agents could pick out one person from a sea of internet data in order to focus on them specifically. The NSA slides indicated that Google complied with this action entirely after being compelled to by the US government.</p><h3 class="article-body__section" id="section-squeaky-dolphin"><span>Squeaky Dolphin</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mYfA6XJ83wCzVQv9iuVdMS" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/mYfA6XJ83wCzVQv9iuVdMS.jpg" mos="https://cdn.mos.cms.futurecdn.net/mYfA6XJ83wCzVQv9iuVdMS.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>There's a prize for anyone who can understand the reasoning behind this codename. Squeaky Dolphin was an initiative thought up by the UK's GCHQ. It involved tapping into the cables carrying the world's web traffic in order to monitor what people are up to on social media.</p><p>Documents leaked to <a href="http://investigations.nbcnews.com/_news/2014/01/27/22469304-snowden-docs-reveal-british-spies-snooped-on-youtube-and-facebook?lite">NBC news</a> by Snowden revealed how British spies showed off their new invention to their US counterparts. GCHQ demonstrated how it could monitor YouTube in real time and collect addresses from the billions of videos watched every day.</p><p>Analysts demonstrated how, through a central information hub, they could determine which videos were popular in which cities and at what times, as well as what each demographic preferred to click on.</p><p>The UK spooks did mention to their allies that this program was for general trends only and not for spying on individuals, but there are as yet unconfirmed rumours GCHQ used the tech to target Twitter users with propaganda.</p><h3 class="article-body__section" id="section-gilgamesh"><span>Gilgamesh</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="uUVoc2pXzySqc54GT8JR2Q" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/uUVoc2pXzySqc54GT8JR2Q.jpg" mos="https://cdn.mos.cms.futurecdn.net/uUVoc2pXzySqc54GT8JR2Q.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Unfortunately, this operation has nothing to do with the fifth king of Uruk Mesopotamia.</p><p>According both to documents released by Snowden and the testimony of a former drone operator, the NSA used telecommunications devices as targets for drone strikes.</p><p>Rather than confirming with operatives on the ground, said the whistleblower, the NSA would identify a target based on the geolocation of their phone and order an assassination.</p><p>The drone operator was adamant the technology was aiding the War on Terror but that civilians were "absolutely" being killed en masse by the strikes.</p><p>Terrorists cottoned on to the NSA's idea, though, and began to mix up their SIM cards to avoid being tracked. Commanders would switch them with footsoldiers and footsoldiers with civilians.</p><p>The NSA often located targets based on their activity levels and not on the content of the calls, resulting in, according to the former pilot "death by unreliable data."</p><h3 class="article-body__section" id="section-egotisticalgoat"><span>EgotisticalGoat</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="eLmE65LLf74yLyexi7Wgnh" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/eLmE65LLf74yLyexi7Wgnh.jpg" mos="https://cdn.mos.cms.futurecdn.net/eLmE65LLf74yLyexi7Wgnh.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>EgotisticalGoat and its sister program, EgotisticalGiraffe, were designed to help facilitate attacks on people using the anonymous network Tor.</p><p>Techniques included targeting web browsers like Firefox and giving the NSA full control over a target's computer keystrokes, online activity and files.</p><p>The Tor network is relied upon by journalists, activists and campaigners around the world to maintain the secrecy of their communications and avoid reprisals from their respective governments.</p><p>The network, oddly enough, is provided with 60 per cent of its funding by the US government.</p><p>Agents operating EgotisticalGoat admitted the Tor network was too large for them to completely crack. In one top-secret presentation named "Tor Stinks" it stated "We will never be able to de-anonymize all Tor users all the time ... with manual analysis we can de-anonymize only a very small fraction of Tor users."</p><p>With more information to come from Snowden, who claims his leaks to date are just the tip of the iceberg, do we have more cause for concern over our data than ever before? Are all of these operations a gross misconduct or a necessary evil? Let us know what you think by emailing us at <a href="mailto://comments@itpro.co.uk" data-original-url="mailto:comments@itpro.co.uk?Subject=Snowden%leaks">comments@itpro.co.uk</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Facebook, Google & Twitter users at risk of mass surveillance in UK ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/22503/facebook-google-twitter-users-at-risk-of-mass-surveillance-in-uk</link>
                                                                            <description>
                            <![CDATA[ Counter terrorism director claims monitoring social media activity of UK citizens is permissible by law ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vq8P2nA25cqcBCYVyntTZA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 17 Jun 2014 15:59:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Social Media]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Surveillance]]></media:description>                                                            <media:text><![CDATA[Surveillance]]></media:text>
                                <media:title type="plain"><![CDATA[Surveillance]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A secret policy that gives the government permission to carry out mass surveillance of Facebook, Twitter, YouTube and Google users in the UK has been uncovered.</p><p>The legal loophole was uncovered in the wake a challenge by several privacy and civil liberties groups, which featured a witness statement by Charles Farr, the UK government's director general of office for security and counter terrorism.</p><p>The <a href="https://www.privacyinternational.org/sites/privacyinternational.org/files/downloads/press-releases/witness_st_of_charles_blandford_farr.pdf">50-page document featuring</a> Farr's statement claims UK residents could lawfully have their social networking site communications monitored because these are classed as "external communications" under the Regulation of Investigatory Powers Act (RIPA).</p><p>According to RIPA, external communications are defined are those that are sent and received outside of the British Isles, but do not include those sent and received within its borders.</p><p>"A person conduction a Google search for a particular search term in effect sends a message to Google asking [the company] to search its index of web pages. The message is a communication between the searcher's computer and a Google web server," Farr explained.</p><p>Because Google's largest European datacentres are not located within the British Isles, the likelihood is this correspondence between the Google web server and the user will be classed as an external communication.</p><p>And the same could apply to Facebook, YouTube and Twitter users, if the communications they have with those sites are facilitated by overseas datacentres and web servers.</p><p>"A user located in the British Islands posting a message on Twitter will communicate with a Twitter web server forming part of Twitter's datacentre infrastructure," Farr continued.</p><p>"That datacentre infrastructure is largely based in the United States; so the communications may well be external' for the purposes of RIPA." </p><p>The witness statement has been published by Privacy International and forms part of the government's defence case about the scope of its surveillance activities in the wake of the Edward Snowden revelations, which is being handled by the Investigatory Powers Tribunal.</p><p>In a statement on the <a href="https://www.privacyinternational.org/press-releases/uk-intelligence-forced-to-reveal-secret-policy-for-mass-surveillance-of-residents">Privacy International website</a>, the civil liberties group hit out at the definition of social media posts and Google searches as "external communications".</p><p>"By defining the use of platforms' [like this], British residents are being deprived of the essential safeguards that would otherwise be applied to their communications simply because they are using services that are based outside of the UK," the statement reads.</p><p>The revelation has prompted an outpouring of contempt from several other privacy groups, including Amnesty International.</p><p>Michael Bochenek, senior director of international law and policy at Amnesty, said: "British citizens will be alarmed to see their government justifying industrial-scale intrusion into their communications.</p><p>"The public should demand an end to this wholesale violation of their right to privacy." </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple, Google & Microsoft set to notify users of government data requests ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-protection/22171/apple-google-microsoft-set-to-notify-users-of-government-data-requests</link>
                                                                            <description>
                            <![CDATA[ Defying authorities, major companies mark their end of compliance with a bang ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">yPJCsAzxr8k8aqY6Treis</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/g8VujSxGTcNRnBJWyFcxV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 02 May 2014 11:12:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Alex Hamilton ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/g8VujSxGTcNRnBJWyFcxV-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data breach]]></media:description>                                                            <media:text><![CDATA[Data breach]]></media:text>
                                <media:title type="plain"><![CDATA[Data breach]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/g8VujSxGTcNRnBJWyFcxV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Privacy policy changes by Apple, Facebook, Google and Microsoft will see their users notified whenever a government agency requests their data.</p><p>All four tech giants are updating their privacy policies to include the types of disclosures they can make to their userbase. Now, whenever a government agency makes a request for a specific person's data, they will be warned in advance.</p><p>The technology industry is eager to demonstrate that it is world's apart from the NSA, which has operated surveillance operations on multiple online services. The change in regulations means millions of customers will be able to fight in court to prevent the disclosure of their information.</p><p>Google already notifies users of data requests but has updated its policy to include instances where they will be unable to do so, if there is risk to a potential victim, for example.</p><p>Apple, Facebook and Microsoft have been working on their own revisions, according to company officials, but have not released specific details.</p><p>"Later this month, Apple will update its policies so that in most cases when law enforcement requests personal information about a customer, the customer will receive a notification from Apple," company spokeswoman Kristin Huguet said.</p><p>Prosecutors have warned that tech companies will be undermining the course of justice, giving criminals time to destroy evidence or escape capture. Hitting back, the big four have said they will continue to notify users unless gagged by a judge or major legal body.</p><p>The policies do not affect key US data requests, like those from the Foreign Intelligence Surveillance Court, which are kept top secret by American law.</p><p>The new policies will force agencies to weigh up the risks of attempting to gain information digitally. If they push ahead then there is a risk of the target destroying data while going through the courts may land them with only a fixed time period.</p><p>Jason Weinstein, former assistant attorney general of the Justice Department, told the <em><a href="http://www.washingtonpost.com/business/technology/apple-facebook-others-defy-authorities-increasingly-notify-users-of-secret-data-demands-after-snowden-revelations/2014/05/01/b41539c6-cfd1-11e3-b812-0c92213941f4_story.html?hpid=z1">Washington Post</a></em>: "It's sort of a double whammy that makes law enforcement's job harder. It has the potential to significantly impair investigations."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ "Dark Wallet" bitcoin software aims to keep users anonymous ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/22165/dark-wallet-bitcoin-software-aims-to-keep-users-anonymous</link>
                                                                            <description>
                            <![CDATA[ App will keep transaction untraceable, no matter who you are ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gArkFCeUKtZWy2RqXghykW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jdhBNnd5skU9cyTsLyZwm4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 01 May 2014 16:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cryptocurrencies]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Alex Hamilton ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jdhBNnd5skU9cyTsLyZwm4-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jdhBNnd5skU9cyTsLyZwm4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A group of politically-charged coders have released a bitcoin application designed to protect its users from any form of surveillance.</p><p>The program, named Dark Wallet, will seek to subvert incoming legislation aimed at linking users to their bitcoin transactions. Brainchild of subversive group unSystem, the software raised 30,000 from an October 2013 crowdfunding campaign on Indiegogo.</p><p>An accompanying video for the campaign promised Dark Wallet would be "a line in the sand" for all bitcoin users wishing to remain anonymous.</p><p>All bitcoin transactions are stored within a ledger called the blockchain, which is copied to users' computer and checked to prevent fraud in the network. Although this prevents forgery, it also leaves bitcoiners vulnerable, as their spending record can easily be traced back to their IP address.</p><p>Dark Wallet aims to remedy this by combining any payments made with another already in progress nearby. In effect, this means that if law enforcement agencies attempt to backtrace spending records they would be unable to distinguish one from the other.</p><p>"This is a way of using bitcoin that mocks every attempt to sprinkle it with regulation," said founder Cody Wilson, speaking to <a href="http://www.wired.co.uk/news/archive/2014-04/30/dark-wallet">Wired</a>. "It's a way to say to the government You've set yourself up to regulate bitcoin. Regulate this."</p><p>The software also protects those receiving the coins. Using something known as a stealth address, any user can set Dark Wallet to publish an encrypted address online. When a buyer sends coins to that address, Dark Wallet reroutes them to a random encryption that matches the receiver's specific key.</p><p>The developers behind Dark Wallet admit that it has flaws, and that they will be ironed out in due time; integration with anonymity software Tor is also in the works.</p><p>Wilson said that he specifically intends for the software to be used in online black markets; he also doesn't deny that Dark Wallet might be used by terrorists, murderers-for-hire or paedophiles.</p><p>"Liberty is a dangerous thing," he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ accused of using fake LinkedIn pages to access company data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/strategy/21866/gchq-accused-of-using-fake-linkedin-pages-to-access-company-data</link>
                                                                            <description>
                            <![CDATA[ Latest Edward Snowden revelations suggest GCHQ used spoof LinkedIn pages to spy on telcos. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6nuuV3X65brDTy9jjpTv5t</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Mar 2014 10:11:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Surveillance]]></media:description>                                                            <media:text><![CDATA[Surveillance]]></media:text>
                                <media:title type="plain"><![CDATA[Surveillance]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>British intelligence and security organisation GCHQ hacked Belgian telecommunications company Belgacom via spoof employee LinkedIn profiles.</p><p>The top secret' project was leaked by NSA whistleblower Edward Snowden in a presentation and revealed the victim would not have known they were being watched because the malware was invisible to them.</p><p>Profiles would have displayed as normal despite being fake set-ups, not hosted on LinkedIn - but the malware allowed intelligence officers to access their computers.</p><p>The majority of those targeted worked in network maintenance and security for the company.</p><p>LinkedIn has denied having anything to do with the hack, saying it takes the privacy of its users very seriously and "does not sanction the creation or use of fake LinkedIn profiles or the exploitation of its platform for the purposes alleged in this report. To be clear, LinkedIn would not authorise such activity for any purpose,' and was not notified of the alleged activity."</p><p>When the GCHQ had managed to access the computers of engineers, they were able to access information about the company and its subsidiary BICS, which operates a GRX router system that allows people to make and receive calls or use data abroad.</p><p>This enabled the organisation to access data about the locations of targets and who they are communicating with.</p><p>Mobile networks expert Philippe Langlois told German website <em><a href="http://www.spiegel.de/international/world/ghcq-targets-engineers-with-fake-linkedin-pages-a-932821.html">Spiegel</a></em>: "This way, an intelligence service could read the entire Internet communications of the target and even track their location or implant spying software on their device."</p><p>He explained, since there are several hundred wireless companies, but only about two-dozen GRX providers worldwide, it is a much easier way to track the activities of targets.</p><p>The presentation revealed by Snowden (and reportedly seen by <em>Spiegel</em>) mentioned other telecommunications companies GCHQ was interested in, including Swiss company Comfone and Mach, which is now owned by Syniverse and Starhome Mach.</p><p>The document went into detail about a particular employee at Mach, listing all the devices he uses, identifying work devices and personal technology. GCHQ is said to have accessed cookies on his computer and lists his Skype name, Gmail user name and other social accounts he uses.</p><p>In January this year, GCHQ was accused of <a href="https://www.itpro.com/apps/21486/gchq-and-nsa-accused-of-using-angry-birds-and-google-maps-to-nab-user-data" data-original-url="https://www.itpro.com/apps/21486/gchq-and-nsa-accused-of-using-angry-birds-and-google-maps-to-nab-user-data">hacking mobile apps Angry Birds and Google Maps</a> to collect user data with the NSA.</p><p>It was another of the security leaks revealed by Snowden and it's said the organisations were trying to take advantage of "leaky apps" that inadvertently spill details about the age, sex and location of their users.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ and NSA accused of using Angry Birds and Google Maps to nab user data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/apps/21486/gchq-and-nsa-accused-of-using-angry-birds-and-google-maps-to-nab-user-data</link>
                                                                            <description>
                            <![CDATA[ Surveillance agencies have reportedly tried to collect personal information leaked from smartphone and tablet apps. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oB66kLmJPdtjcS2bzTVNTL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KVDQadPyDpdDqyKYiVoDmC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 28 Jan 2014 10:37:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business Apps]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KVDQadPyDpdDqyKYiVoDmC-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Angry Birds in space]]></media:description>                                                            <media:text><![CDATA[Angry Birds in space]]></media:text>
                                <media:title type="plain"><![CDATA[Angry Birds in space]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KVDQadPyDpdDqyKYiVoDmC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>US and British surveillance agencies have been accused of using Angry Birds and other popular smartphone apps to gather users' personal information.</p><p>That's according to the latest round of revelations from National Security Agency whistleblower Edward Snowden, which have been made public by the <a target="_blank" href="http://www.nytimes.com/2014/01/28/world/spy-agencies-scour-phone-apps-for-personal-data.html?_r=0"><em>New York Times</em></a> and <em>Guardian</em> newspaper.</p><p>It's claimed the NSA and its British counterpart GCHQ have colluded on how to take advantage of "leaky apps" that inadvertently spill details about the age, sex and location of their users.</p><p>These include mapping, gaming and social networking apps, although the amount of data that's been collected in this way is not yet clear, nor is the number of users likely to be affected.</p><p>The documents suggest GCHQ and the NSA have "traded methods" for collecting location data from Google Maps users, along with address book and phone log data when users post pictures to mobile versions of Facebook, Flickr, LinkedIn and Twitter.</p><p>The report claims the two surveillance agencies have been working on ways to collect and store these types of data since 2007.</p><p>Its work to-date has reportedly focused on collecting data from older apps, but newer ones including Angry Birds are being targeted too, the latest tranche of documents from Snowden suggest.</p><p>In particular, they set out how to obtain information from Angry Birds running on Android-based devices.</p><p>The latest revelations come hot on the heels of <a target="_blank" href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security/21428/president-obama-sets-out-us-surveillance-reforms">President Obama's pledge earlier this month to curb the surveillance activities of the NSA</a>.</p><p>In a statement to the <em>New York Times</em>, the NSA insisted it does not profile "everyday Americans" during its foreign intelligence missions.</p><p>"Because some data of US persons may at times be incidentally collected in NSA's lawful foreign intelligences mission, privacy protections for US persons exist across the entire process," the statement added.</p><p>GCHQ declined to comment, aside from saying its activities complied with British law.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Vodafone wants to blow whistle on surveillance requests ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/21427/vodafone-wants-to-blow-whistle-on-surveillance-requests</link>
                                                                            <description>
                            <![CDATA[ Mobile operator writes to 25 governments asking to publish surveillance requests. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8poX6iYYQzLrSJ5AaGnczU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GRkxsKPdQbP8BrcP8MMCQ9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jan 2014 16:19:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GRkxsKPdQbP8BrcP8MMCQ9-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GRkxsKPdQbP8BrcP8MMCQ9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Vodafone wants to publish transparency reports detailing the type and number of requests it receives from government bodies asking for data on its customers.</p><p>According to a report from <em>The <a href="http://www.theguardian.com/business/2014/jan/15/vodafone-aims-to-disclose-wiretap-demands">Guardian</a></em>, the operator has written to Home Secretary Theresa May and Justice Secretary Chris Grayling demanding they lift the lid on data requests. It has also approached government ministers in 24 other countries where it operates regarding the same matter.</p><p>At present UK law prevents Vodafone and other operators from disclosing even general information about interception of communications. The only information available about government requests comes through the Communications Commissioner, whose job it is to make sure such requests are issued lawfully.</p><p>The mobile phone giant is bidding to be allowed to publish details on how many requests it receives and what they are for, such as metadata containing names phone numbers and locations.</p><p>"We want all of our customers worldwide to feel they are at liberty to communicate with each other as they see fit. We want our networks to be big and busy with people who are confident they can communicate with each other freely; anything that inhibits that is very bad for any commercial operator," said Vodafone's privacy head, Stephen Deadman.</p><p>The firm is looking to detail surveillance requests in its annual sustainability report, slated for publication in June. Alongside the requests, Vodafone will include new provisions of its data that state it will "not allow access to customer data unless legally obliged to do so" and will "challenge requests in law where appropriate."</p><p>Last year, AT&T and Verizon announced plans to publish transparency reports following the whistle blowing revelations of Edward Snowden. Surveillance of phone communications was among the first exposed by him in the summer.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NSA accused of collecting 200 million text messages a day ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/21425/nsa-accused-of-collecting-200-million-text-messages-a-day</link>
                                                                            <description>
                            <![CDATA[ Latest twist in NSA surveillance scandal suggests its been snooping on millions of text messages every day. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9feVJCeNN2fNBtp8gy581s</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mwqWFkJsHHpmTgTuTbQgJ5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jan 2014 15:07:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mwqWFkJsHHpmTgTuTbQgJ5-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Text message on phone]]></media:description>                                                            <media:text><![CDATA[Text message on phone]]></media:text>
                                <media:title type="plain"><![CDATA[Text message on phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mwqWFkJsHHpmTgTuTbQgJ5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US National Security Agency (NSA) has been collecting up to 200 million SMS text messages every day, according to a report in <em>The Guardian</em>.</p><p>The revelations came through a joint investigation with Channel 4 News. The NSA managed to collect large volumes of text messages through its Dishfire surveillance programme. The agency then sifts through the messages and analyses them.</p><p>Documents leaked by whistleblower Edward Snowden revealed the NSA selects random targets and collects SMS messages from them regardless of who they are.</p><p>The NSA has also been colluding with GCHQ on the surveillance programme with the former sharing access to the SMS messages with the latter. According to <a href="https://www.documentcloud.org/documents/1006111-sms.html">slides</a> released by the newspaper, the operation has been running since 2008.</p><p>The programme managed to collect 1.6 million notifications when people roamed from one network to another and around 800,000 messages relating to financial transactions.</p><p>With such a large amount of data collected, the NSA had to create an automated scanning tool, dubbed Prefer, to extract key metadata from the messages to "enhance current analytics".</p><p>However, an NSA spokeswoman played down the reports and told <em>The Guardian</em> the tool was only used "against foreign intelligence targets".</p><p>Dishfire has also helped Britain's spies as it has collected a lot of information on UK citizens without needing to make formal requests under the Regulation of Investigatory Powers Act.</p><p>A GCHQ spokesman said the organisation would not comment on intelligence matters.</p><p>"All of GCHQ's work is carried out in accordance with a strict legal and policy framework which ensures that our activities are authorised, necessary and proportionate, and that there is rigorous oversight, including from the Secretary of State, the Interception and Intelligence Services Commissioners and the Parliamentary Intelligence and Security Committee," he told <em>The Guardian</em>.</p><p>In other NSA-related news, President Obama is set to outline changes later today he wants the surveillance organisation to make to the way it operates.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NSA accused of bugging 100,000 PCs across the globe ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/21401/nsa-accused-of-bugging-100000-pcs-across-the-globe</link>
                                                                            <description>
                            <![CDATA[ US surveillance agency has reportedly installed radio wave transmitters into thousands of overseas computers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qfAjycJcqJxNXgezozq8en</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/X9oPGA7KjDNvUQ64DTUhNf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jan 2014 11:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/X9oPGA7KjDNvUQ64DTUhNf-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spyglass]]></media:description>                                                            <media:text><![CDATA[Spyglass]]></media:text>
                                <media:title type="plain"><![CDATA[Spyglass]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/X9oPGA7KjDNvUQ64DTUhNf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US National Security Agency (NSA) has covertly installed surveillance tools on 100,000 PCs around the world, according to a <a target="_blank" href="http://www.nytimes.com/2014/01/15/us/nsa-effort-pries-open-computers-not-connected-to-internet.html?_r=0"><em>New York Times</em></a> (NYT) report.</p><p>The Agency has been accused of having small circuit boards and USB cards inserted into the affected machines, which broadcast a channel of radio waves back to NSA surveillance teams.</p><p>Code-named Quantum, the project allows the NSA to keep tabs on machines that are not connected to the internet, but does require a third party to insert the circuit board or USB to be successful.</p><p>It has reportedly been used by the NSA for surveillance purposes since 2008, and only to snoop on overseas targets.</p><p>These, according to the <em>NYT</em> report, include Russian military networks, systems used by Mexican police and drug cartels, and European Union trade institutions.</p><p>The claims are based on the accounts of US officials, computer experts and prolific NSA whistleblower Edward Snowden.</p><p>An NSA spokesperson told the paper that it only focuses on "valid foreign intelligence targets" based on the intelligence it receives.</p><p>"We do not use foreign intelligence capabilities to steal the trade secrets of foreign companies on behalf of or give intelligence we collect to US companies to enhance their international competitiveness or increase their bottom line," Vanee Vines, the NSA spokesperson told the <em>NYT</em>.</p><p>The report is the latest in a long line of disclosures about the NSA's activities, which have come under scrutiny since Snowden started leaking details about it in the summer of 2013.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NSA spies targeted World of Warcraft and Xbox Live ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/21196/nsa-spies-targeted-world-of-warcraft-and-xbox-live</link>
                                                                            <description>
                            <![CDATA[ Wizard plan saw spooks became elves and trolls to hunt for terrorists. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uVHgN9ishvzj2XCvcvnzjE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KDyqt2dLucEFziCrPXhToB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 10 Dec 2013 17:06:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KDyqt2dLucEFziCrPXhToB-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[World of Warcraft]]></media:description>                                                            <media:text><![CDATA[World of Warcraft]]></media:text>
                                <media:title type="plain"><![CDATA[World of Warcraft]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KDyqt2dLucEFziCrPXhToB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>GCHQ and the NSA both infiltrated games such as World of Warcraft and the Xbox Live platform as part of their Prism operations, it has emerged.</p><p>The <a href="http://www.theguardian.com/world/2013/dec/09/nsa-spies-online-games-world-warcraft-second-life"><em>Guardian</em> reported</a> the campaign of spying was leaked in a document from Edward Snowden.</p><p>The document, entitled Exploiting Terrorist Use of Games & Virtual Environments, was written in 2008 and claimed games were a "target rich communications network" and that agencies slurped up vast amounts of data.</p><p>The NSA said the games could allow surveillance targets to hide in plain sight.</p><p>"We know that terrorists use many feature-rich internet communications media for operational purposes such as email, VoIP, chat, proxies, and web forums and it is highly likely they will be making wide use of the many communications features offered by Games and Virtual Environments (GVE) by 2010," the document said.</p><p>"The SIGINT Enterprise needs to begin taking action now to plan for collection, processing, presentation, and analysis of these communications."</p><p>The document also show how spy agencies tried to recruit informants to help find terrorists using games as a cover.</p><p>However, so many spies infiltrated the games leading to spy agencies setting up a "de-confliction" group to make sure agents didn't erroneously spy on each other.</p><p>It is unclear if the action taken by spies to infiltrate games ever resulted in the foiling of a terrorist plot. The document said the "amount of GVEs in the world is growing but the specific ones that CT [counter-terrorism] needs to be methodically discovered and validated. Only then can we find evidence that GVEs are being used for operational uses."</p><p>In a statement, Blizzard Entertainment, the company behind World of Warcraft, said: "We are unaware of any surveillance taking place. If it was, it would have been done without our knowledge or permission."</p><p>Microsoft also made similar statements.</p><p>The news comes as a group of major tech companies have <a href="https://www.itpro.com/public-sector/21185/apple-microsoft-and-google-urge-governments-to-address-surveillance" data-original-url="https://www.itpro.com/public-sector/21185/apple-microsoft-and-google-urge-governments-to-address-surveillance">asked the US government to reform surveillance laws</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple, Microsoft and Google urge governments to address surveillance ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/public-sector/21185/apple-microsoft-and-google-urge-governments-to-address-surveillance</link>
                                                                            <description>
                            <![CDATA[ Internet-focused firms lobby Washington for reform. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m4748qotNazBFg2EdEioYi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9XhhSSSFeN75egJ99xgRVF-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 09 Dec 2013 13:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Social Media]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/9XhhSSSFeN75egJ99xgRVF-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9XhhSSSFeN75egJ99xgRVF-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Tech firms including Apple, Facebook and Google have co-authored and co-signed a letter to US President Barack Obama and the US Congress petitioning them to reform government surveillance practices across the globe.</p><div><blockquote><p>Reports about government surveillance have shown there is a real need for greater disclosure and new limits on how governments collect information.</p></blockquote></div><p>The action has been taken in light of continuing revelations from former NSA contractor Edward Snowden regarding the widespread use of interception techniques by the American National Security Agency (NSA) and its UK equivalent GCHQ to monitor internet traffic and electronic communications.</p><p>The letter, <a href="http://reformgovernmentsurveillance.com">which has been published on reformgovernmentsurveillance.com</a>, says: "We understand that governments have a duty to protect their citizens. But this summer's revelations highlighted the urgent need to reform government surveillance practices worldwide.</p><p>"The balance in many countries has tipped too far in favour of the state and away from the rights of the individual rights that are enshrined in our Constitution. This undermines the freedoms we all cherish. It's time for a change."</p><p>The companies, which include AOL, Apple, Facebook, Google, LinkedIn, Microsoft, Twitter and Yahoo, are urging the US to take the lead in carrying out this reform.</p><p>In an individual comment posted on the same website, Larry Page, Google's CEO, said: "The security of users' data is critical, which is why we've invested so much in encryption and fight for transparency around government requests for information.</p><p>"This is undermined by the apparent wholesale collection of data, in secret and without independent oversight."</p><p>Facebook CEO Mark Zuckerberg added: "Reports about government surveillance have shown there is a real need for greater disclosure and new limits on how governments collect information.</p><p>"The US government should take this opportunity to lead this reform effort and make things right."</p><p>However, Rafael Laguna, CEO of open source software firm Open-Xchange, criticised their arguments as "flawed".</p><p>"This very public display of unity is essentially an acknowledgement from these large internet companies the public has begun to lose trust in them, and as a result in the internet as a whole.</p><p>"However, a fundamental flaw in their argument is the double standard of condemning governments for data surveillance, while at the same time harbouring the unquantifiable amounts of data that governments wish to access in the first place."</p><p>He added: "Charity begins at home, and the first step to rebuilding trust in an open internet is to address their own data retention policies before pointing the finger elsewhere."</p><p>Further revelations from the Snowden Papers this week include <a href="http://www.theguardian.com/world/2013/dec/09/nsa-spies-online-games-world-warcraft-second-life?CMP=twt_gu">the infiltration of Massive Multiplayer Online (MMO) games</a>, such as World of Warcraft, and digital communities by the NSA and GCHQ in order to spy on and, in some cases attempt, to recruit users.</p><p>Separately, <a href="http://www.washingtonpost.com/business/technology/fbis-search-for-mo-suspect-in-bomb-threats-highlights-use-of-malware-for-surveillance/2013/12/06/352ba174-5397-11e3-9e2c-e1d01116fd98_story.html"><em>Washington Post</em> has allegedly uncovered the FBI's use of malware</a> in order to track down a suspect who made repeated bomb threats online.</p><p>The agency also requested to be allowed to activate the suspect's webcam remotely, but a judge ruled such an action would be excessively intrusive and could violate his fourth amendment right to protection from unreasonable searches and seizures.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ PRISM fallout could damage business, claim Google and Cisco ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/21022/prism-fallout-could-damage-business-claim-google-and-cisco</link>
                                                                            <description>
                            <![CDATA[ BRIC revenues decline following Snowden revelations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9pMbDfYaw7ZrHbD8GX23hU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/X9oPGA7KjDNvUQ64DTUhNf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 14 Nov 2013 14:51:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Google]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/X9oPGA7KjDNvUQ64DTUhNf-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spyglass]]></media:description>                                                            <media:text><![CDATA[Spyglass]]></media:text>
                                <media:title type="plain"><![CDATA[Spyglass]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/X9oPGA7KjDNvUQ64DTUhNf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google and Cisco claim the US National Security Agency's (NSA) PRISM programme has not only damaged trust but could also be harmful to American businesses.</p><p>Cisco made the claim as it warned its revenue would shrink by up to ten per cent this quarter, claiming demand in China had caused a backlash against American communications firms.</p><p>Indeed, rivals Oracle, IBM and EMC were reported to be facing an official investigation by the Chinese government in August following revelations that the NSA had been carrying out wide-scale monitoring of global electronic communications.</p><p>According to an earnings results call <a href="http://seekingalpha.com/article/1838052-ciscos-ceo-discusses-f1q-2014-results-earnings-call-transcript?page=9&p=qanda&l=last">transcribed by Seeking Alpha</a>, Rob Lloyd, president of development and sales at Cisco, said: "This issue has caused increasingly customers to pause and [it is] another issue for them to evaluate...it's certainly causing people to stop and then rethink decisions and that is I think reflected in our results."</p><p>Meanwhile, Google's law enforcement and information security director Richard Salgado became the first representative of a major technology company to testify before the US Congress following the PRISM revelations.</p><p>Salgado said: "The current lack of transparency about the nature of government surveillance in democratic countries undermines the freedom and the trust most citizens cherish, it also has a negative impact on our economic growth and security and on the promise of an internet as a platform for openness and free expression."</p><p>Echoing <a href="https://www.itpro.com/cloud-security/20982/monitoring-scandals-must-not-lead-balkanisation-cloud-says-box-ceo" data-original-url="https://www.itpro.com/cloud-security/20982/monitoring-scandals-must-not-lead-balkanisation-cloud-says-box-ceo">comments made by Box's CEO at a recent London conference</a>, Salgado warned the scandal could lead to the creation of a "splinter-net" by <a href="http://www.cloudpro.co.uk/cloud-security/3340/cloud-society-is-brazil-nuts-to-want-to-break-up-the-internet">putting up internet barriers</a>.</p><p>After the hearing, Salgado <a target="_blank" href="http://www.reuters.com/article/2013/11/13/us-usa-security-hearing-idUSBRE9AC0S720131113">told <em>Reuters</em></a>: "You can certainly look at the reaction, both inside the United States and outside of the United States to these disclosures, to see the potential of the closing of the markets <a href="http://www.cloudpro.co.uk/cloud-essentials/cloud-security/3437/european-cloud-strategists-should-live-in-real-world">through data location requirements</a>.</p><p>"This is a very real business issue, but it is also a very real issue for the people who are considering using the cloud and for those who currently use the cloud and may have their trust in it rocked by the disclosures."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Monitoring scandals must not lead to balkanisation of the cloud, says Box CEO ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud-security/20982/monitoring-scandals-must-not-lead-balkanisation-cloud-says-box-ceo</link>
                                                                            <description>
                            <![CDATA[ Box CEO Aaron Levie hits out at suggestions of country-specific clouds ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2GeeTAFyryqKeCULuodyZv</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9bjTgDSXnUx8ZwrZQnHWfK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 07 Nov 2013 12:32:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9bjTgDSXnUx8ZwrZQnHWfK-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Box CEO Aaron Levie on stage]]></media:description>                                                            <media:text><![CDATA[Box CEO Aaron Levie on stage]]></media:text>
                                <media:title type="plain"><![CDATA[Box CEO Aaron Levie on stage]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9bjTgDSXnUx8ZwrZQnHWfK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Prism government spying scandal, in which the US National Security Agency monitored electronic communications, must not be allowed to break up the cloud and restrict data flow.</p><p>This was the opinion expressed by the Aaron Levie, the CEO of Box, regarding <a href="http://www.cloudpro.co.uk/cloud-essentials/cloud-security/3437/european-cloud-strategists-should-live-in-real-world">propositions from the European Commission to alter data protection requirements</a> in a way that could require data to be kept either within the European Union or within the originating countries.</p><div><blockquote><p>We are optimistic that there will have to be more transparency, have to be more processes created for how this works. We don't think the internet could blossom and evolve in the appropriate ways if this fear [were to] remain.</p></blockquote></div><p>Similar proposals have also been put forward by <a href="http://www.cloudpro.co.uk/cloud-security/3340/cloud-society-is-brazil-nuts-to-want-to-break-up-the-internet">Brazil</a>.</p><p>Speaking to journalists yesterday at the organisation's Business Without Boundaries event in Central London, Levie said: "It is obviously incredibly bad and inappropriate what the NSA has been doing ... it's not only bad the actions they have taken but it's also the inaction of not actually creating any transparency or any visibility into what is actually happening."</p><p>However, Levie added: "On the [subject of] EU privacy and data [regulation], the biggest thing that we are worried about ... we want to avoid some of the noise about the balkanisation of the cloud, that would be a very bad outcome this idea of regionally specific or government specific or country specific clouds. Not only does it not make technological sense, it's also bad from an economy standpoint."</p><p>Most of Box's customers need to collaborate and share information cross international boundaries, Levie said. He added that the only way to do so effectively was with an open platform. </p><p>Levie also touched on the topic again during his keynote following a question from a delegate.</p><p>"We don't think the current [surveillance] situation is tenable ... and we are optimistic that there will have to be more transparency, have to be more processes created for how this works. We don't think the internet could blossom and evolve in the appropriate ways if this fear [were to] remain," he said.</p><p>"Fortunately, we are a little bit outside of the whole issue and distanced from it, because the biggest issue has been national security issues and those are generally ... consumer communication services on the internet. We tend not to fall into the space that is of interest, but we care a lot from a technology company standpoint. We have to have a world that allows us to securely communicate and work and share on a global basis, so that is obviously something that we care about and that we are pushing on," he concluded.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>