Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, November 7, 2012

BlackBerry 10 gets important US security clearance ahead of launch

Research In Motion's upcoming BlackBerry 10 platform has received US security clearance that will allow it to be used by goverment agencies – provided they don't all desert the Canadian company before the new platform launches.

As Research In Motion (RIM) executives count down the days to the launch of its next-generation BlackBerry 10 platform (though one wonders if they really know precisely how many days are left), the company has been pushing out a number of positive press releases recently in an effort to create a silver lining on the gray cloud that has been hanging over the firm for some time.

Last week it announced that development of BB10 had passed what it described as a “critical milestone” with news that it had entered lab testing with more than 50 carriers worldwide.

And on Wednesday evening it issued a statement saying its new BB10 smartphones and its Enterprise Service 10 management console had both received important Federal Information Processing Standard (FIPS) 140-2 security certification from the National Institute of Standards and Technology. This is the first time BlackBerry products have been FIPS certified ahead of launch, the Ontario-based company said, and paves the way for US and Canadian government agencies to use the devices in their work.

Commenting on the news, Michael K. Brown, vice president of security product management and research at RIM, said, “Achieving FIPS 140-2 certification means that BlackBerry 10 is ready to meet the strict security requirements of government agencies and enterprises at launch.”

Talking up the security features of BB10, he added, “What differentiates BlackBerry is that it integrates end-to-end security, and includes certified encryption algorithms for data at rest and data in transit. No other mobile solution has achieved the level of security accreditation that the BlackBerry solution has.”

The certification is undoubtedly good news for the mobile company, though with several agencies in recent months announcing their intention to turn away from BlackBerry handsets in favor of iOS and Android-powered devices, RIM will have its work cut out to get them back on board. It must also work to hold on to those who have so far stuck with its devices.

Happily for RIM, last week the Pentagon said it would continue to support “large numbers” of BlackBerry smartphones even though it’ll also be allowing many of its employees to use the iPhone and other devices.

BlackBerry’s reputation for strong security was what until recently made RIM’s handsets stand out for those who required such features. But for many IT administrators working today, iOS and Android phones now offer more secure and manageable platforms.

RIM has been able to offer a few bits of positive news of late, but the real test will of course come when its new, long-awaited BB10 OS and handsets finally make an appearance.


Source : http://www.digitaltrends.com/mobile/blackberry-10-gets-important-us-security-clearance-ahead-of-launch/

Friday, October 12, 2012

UK government also probing Huawei, says it currently has no security concerns

Huawei Show Photograph: Reuters

Following the House of Representatives damaging report, the UK has revealed it has also been examining Huawei amid security concerns.

The story following the House of Representatives report that Huawei and ZTE pose a security threat to US national security continues, as international governments examine their involvement with the Chinese companies and look for their own evidence of security risks.

In the UK, it has been revealed that a parliamentary committee has also been examining Huawei’s presence in the country for a while, as it’s a major supplier of network equipment to British Telecom, Vodafone, O2 and most other network providers, plus it’s responsible for much of the infrastructure behind EE’s 4G network.

Should any discrepancies be identified, the continued rollout of both fiber and 4G broadband could be slowed or halted. Both projects, and the relationship with Huawei, are well established, and disruption would be costly. The report is due to be published at the end of the year.

Quite apart from the network disruptions, there’s a political aspect at work too, as Prime Minister David Cameron had a meeting with Huawei’s CEO Ren Zhengfei last month, where a £1.3 billion deal was reached. One of the first stages is for Huawei to move its UK workforce into a new 140,000 square foot office building in April next year.

A Cabinet Office spokesperson, Derek Smith, has been talking to the UK press about the government’s view on both Huawei and ZTE ahead of the final report, which is notably different to that of the US House of Representatives.

Cyber Security Evaluation Centre

Smith told TechRadar.com that “the Cabinet Office is confident that there are no security concerns,” and “comparisons with the US don’t hold up with what we’re doing here. We have a very strict evaluation process for products from any country, not just China, coming into the UK.”

He then referred to Huawei’s Cyber Security Evaluation Centre, which opened in 2010, where hardware and software are tested to, according to Huawei “ensure its ability to withstand growing cyber security threats.” The closest the blurb gets to admitting the centre is more about checking Huawei’s equipment is the admission that it’s there to “build mutual trust in the area of cyber security.”

A 2011 report covering the center’s opening from notorious scare-mongers The Daily Mail is far less subtle, starting with the headline “New cyber attack fears over the Chinese ‘Red Army Lab’ being used for BT tests.” The piece goes on to quote numerous security experts who warn against using Huawei’s services, plus it reveals that Huawei has an identical copy of BT’s computers and telecoms system back in its Shenzhen head office, so it can evaluate new hardware. Thankfully, the system isn’t connected to the UK network.

For now, it seems Huawei’s operations in the UK are safe, but things will take a turn for the serious — not to mention politically embarrassing — should the forthcoming report not back up the Cabinet Office’s statements, as Huawei is already sitting at the table with its slippers on in the UK, instead of only knocking on the door in the US.


Source : http://www.digitaltrends.com/mobile/uk-government-examining-huawei-amid-security-concerns/

Thursday, October 11, 2012

Cisco, US tech firms reportedly urged Congress to investigate Huawei, ZTE

Cisco, US tech firms reportedly urged Congress to investigate Huawei, ZTE
Other US tech companies are reportedly suspicious of Huawei, ZTE

Cisco Systems, among others, may have nudged Congress into investigating Chinese companies Huawei and ZTE for security concerns, according to a new report from the Washington Post.

China's two largest telecommunications companies have taken a beating from U.S. Congressmen as they tried to enter the States' technology market.

Politicians are concerned the tech giants will use their systems to help expand the Chinese government's spying networks into the US.

Earlier this week, the US Intelligence Committee said the duo shouldn't be allowed to operate in the U.S. But the only proof of those claims are held secret in classified reports.

Cisco in the captain's chair

Cisco and other U.S. tech companies urged Congress to investigate Huawei and ZTE, according to an unnamed senior Hill staffer.

The staffer said politicians were already concerned about the two companies, and major players in the U.S. tech industry just fanned the flames of their suspension.

"What happens is you get competitors who are able to gin up lawmakers who are already wound up about China," the anonymous staffer said to the Post. "What they do is pull the string and see where the top spins."

The Post even found a seven-page sales presentation called "Huawei's & National Security," which is meant to give ammo to Cisco representatives on why clients should avoid Chinese competitors and go with American companies.

"Fear of Huawei spreads globally," according to the presentation. "Despite denials, Huawei has struggled to de-link itself from China's People's Liberation Army and the Chinese government."

The vitriol is no surprise in the cutthroat world of telecommunications. Cisco CEO, John Chambers, has repeatedly criticized Huawei for "not playing by the rules" and declared the company a "long-term threat."

The new McCarthyism

Huawei has been repeatedly denied entry into the U.S. tech game by the Treasury Department's Committee on Foreign Investments for years. All based on security concerns.

The two Chinese companies and their government have all denied the allegations of spying.

Last month, Huawei published a 81-page document when its top brass was being grilled by the House Intelligence Committee.

The report made the case for the benefits of Huawei entering the U.S. tech market, but said the investigation was "allegations based on allegations" and likened its treatment to McCarthyism.

Even though the barriers to entering the U.S. market seem pretty high, Huawei and ZTE still seems pretty determined to take a slice of that American telecom pie.


Source : http://www.techradar.com/news/phone-and-communications/mobile-phones/cisco-us-tech-firms-reportedly-urged-congress-to-investigate-huawei-zte-1103864

Sunday, September 23, 2012

Terms & Conditions: Evernote puts you in charge

Terms & Conditions evernote privacy

Evernote uses its terms of service and privacy policy to put users in charge of their data and information security.

Check out the full Terms & Conditions archive.

Launched in 2008, Evernote started as a “productivity tool.” But it has since grown into something much more — a virtual extension of your brain. For those of you not yet in the know, Evernote allows you to store nearly anything you want to remember — photos, receipts, Web pages, recipes, voice recordings, you-name-it — and access those “memories” through a mobile app or on the Web. You can also share “notebooks” with whomever you like. It’s quite handy, especially if you live a busy, active life, with plenty of stuff you want to remember.

But using a service that literally mimics your memory means putting a lot of trust in Evernote not to misuse or abuse the vast amounts of inherently personal data users upload to its servers. And to do that properly, you’re going to need to understand Evernote’s sweeping terms of service and privacy policy. Let’s boil things down to the most important bits.

Terms of Service

Evernote has already done the job of summarizing its terms of service into three main bullet points, which is extremely helpful. These points are:

  • Your Data is Yours
  • Your Data is Protected
  • Your Data is Portable

To learn more about what exactly Evernote means about all this, you can read this extremely explicit, clear, and downright encouraging blog post from Evernote CEO Phil Libin.

While helpful, these points don’t quite tell the whole story. Here’s the rest of what you should know about Evernote’s ToS.

Intruder alert!

Evernote kicks off its ToS with a “Use of Service” section, a dense paragraph that basically says that if you discover any “unauthorized use” of your account, you have to tell Evernote about it. And if you don’t, the company is not responsible if someone steals or deletes your data.

Legal shmeagle

One curious portion of the “Use” section is that you must be “of legal age to form a binding contract” to use Evernote, which in the U.S. means you technically have to be 18-years-old to sign up. Google also has this provision in its terms, meaning anyone under 18 can’t use any Google products. In reality, of course, no company pays much attention to this rule. And Evernote later explains that you can use the service if you’re over 13-years-old. So don’t fret, teens. You may be breaking the law by using Evernote, but nobody cares.

Own it

Evernote has the fantastic policy that you own the rights to everything you upload to its service, and the company promises not to use your stuff to make money. Further, if you decided to ditch Evernote, you can take all of your data with you.

That said, you are on your own if you upload (and share) copyrighted content and get served with a lawsuit — Evernote will not help you in any way.

Contact at your own risk

If you contact Evernote with some ingenious way to improve the product, Evernote may (or may not) use the information you provide however it sees fit, be it for marketing material, or to tell the world about what dumb ideas you have. (Kidding!) It also automatically owns that idea. So if you come up with something brilliant, don’t just email it to the company willy nilly.

Avoid the following

Evernote lists a bunch of stuff you can’t do, but nothing that surprising. All of it simmers down to these forbidden activities. Don’t use Evernote to:

  • Make money
  • Scam people
  • Spam people
  • Abuse, stalk, or harass people
  • Share copyrighted content that you don’t own
  • Spread viruses
  • Do anything else that’s illegal
  • Spread naked pictures or porn (even homemade stuff) publicly, though you can upload whatever you want to your private notebooks

If you find anyone doing any of these activities listed above, you can rat them out to Evernote.

Nuts & bolts

Most of the second half of Evernote’s ToS include a bunch of basic explanations of things that don’t really need explaining. So let’s just sum up the potentially important bits:

  • Evernote uses some other third-party institutions to do business (like server providers, banks, etc), and your account information may be passed on for general business purposes.
  • Evernote may make changes to its services at anytime, so don’t freak out like a Facebook user if that happens.
  • Evernote may serve you ads sometimes. If you click them, any data you provide is between you and the advertiser.

Evernote might send you marketing material or other emails from time to time. If you want to opt-out of marketing emails, visit Evernote.com and click: Settings > Personal Settings > Contact Preferences, uncheck all the boxes, and click “Save Changes.”

Evernote marketing

Privacy policy

Privacy and security are of the utmost importance to Evernote, as is evidenced by their privacy policy and other corporate explanations of their practices. As such, there’s not much here you need to worry about, so I’ll keep this short and sweet.

Collect yo’self

Like all digital services, some personal information is collected by Evernote. But it’s really just the bare minimum to provide the service. Here’s what you can expect Evernote to know about you, either because you provided the information by signing up, or through cookies and tracking pixels:

  • Name
  • Email address
  • Billing information (if you pay for a premium account)
  • IP address
  • Demographic data (like occupation)
  • Location information
  • Device data (whether you’re using a mobile phone, Mac, PC, etc, to access Evernote)
  • What stuff you click on while visiting Evernote’s website
  • Whether or not you’ve opened an email from Evernote

Feeling used

Of course, the information above is collected for a reason. The company may use or share it in a number of ways, which include:

  • To contact you about offers (unless you opt-out)
  • To obey the law (e.g. if served a judicial subpoena for your data by a U.S. court)
  • To investigate possible illegal activity from your account
  • If you sign up for Evernote through the website of a third-party affiliate

Maximum security

Seeing as Evernote can be (and often is) used to store things like passwords, financial data, and credit card numbers, the company’s security practices are probably the most important part of the whole business. (After all, we wouldn’t use Evernote if we thought it be easy for our personal stuff to get into the hands of hackers.) Here’s what Evernote does to protect your info:

  • All passwords are encrypted, and are not directly stored on Evernote’s servers
  • All the stuff you upload is encrypted over SSL (the Internet’s standard)
  • Servers are physically protected, and only a select number of approved employees have access to those servers (a very important part of data security that many average Web users fail to take into consideration)
  • Your data is never observed by Evernote, or used for data mining, or to provide targeted advertising, which limits the possibility of a security breach
  • Evernote’s PC and Mac desktop clients allow you to further encrypt your extra-sensitive notebooks and protect them with a password that is never transmitted to Evernote (further limited the chance of a hacker snagging it)

Here’s a video about how that last bit works:

Conclusion

Overall, Evernote’s terms of service and privacy policy are straightforward, and provide little surprises. However, despite the helpful bullet points listed at the top, the terms of service is particularly long and dense. So I doubt many (read: any) users have actually read them. (I certainly wouldn’t if it weren’t my job.) As the company’s user base grows, however, I would love to see Evernote move in the direct of companies like Tumblr and Microsoft, both of which have made a serious effort to dumb-down their legalese for us non-attorney types.

I reached out to Evernote for comment on this story, but they were not able to get back to me straight away. I will update this space as soon as I hear back. 


Source : http://www.digitaltrends.com/mobile/terms-conditions-evernote/