Thursday, July 10, 2014

Germany orders US intelligence chief out of country (Irish Times)

Chancellor Angela Merkel says spying on allies is ‘a waste of energy’ given other issues 

German chancellor Angela Merkel and finance minister Wolfgang Schaeuble have been speaking about claims of US spying on German interests after the arrest of a man on suspicion of working for a foreign intelligence agency. Mr Schaeuble said the story was so stupid that one can only cry at the foolishness of it. Photograph: Tobias Schwarz/Reuters.
German chancellor Angela Merkel and finance minister Wolfgang Schaeuble have been speaking about claims of US spying on German interests after the arrest of a man on suspicion of working for a foreign intelligence agency. Mr Schaeuble said the story was so stupid that one can only cry at the foolishness of it. Photograph: Tobias Schwarz/Reuters.

Germany’s federal government has ordered the US intelligence station chief at the Berlin embassy to leave the country - before he is expelled - after a second double agent was uncovered inside the German government.

Investigators in Berlin have interviewed a man working for the defence ministry on suspicion of co-operation with US intelligence - a week after an officer in the BND foreign intelligence service said he had sold classified files to the CIA.

German officials have now upped the ante in the spy affair to demonstrate their frustration at perceived stone-walling by Washington. A year after the first revelations by NSA whistleblower Edward Snowden, German officials say they are still no wiser as to how the US spies on Germany -- or why.

“The representative of the US intelligence services in the Embassy of the United States was ordered to leave Germany,” Steffen Seibert, government spokesman, said in a statement.
“The request was made in light of the ongoing investigation by the chief federal prosecutor and questions that have been raised for months about the activities of US intelligence services in Germany.”

The US embassy has declined to respond to the announcement, just as it has not commented on the most recent double agent claims.

The first alleged agent, a 31 year-old living and working with the foreign intelligence service (BND) in Munich, reportedly contacted the US embassy in Berlin via email with an offer to sell documents. He was arrested after making a similar offer to the Russians, telling German investigators last Wednesday that his contact person was a CIA official posing as a diplomat in the US embassy.

The BND official said he met the American agent several times in Vienna, receiving €25,000 for handing over 218 classified files.

Reports of a second double agent emerged yesterday when Germany investigators confirmed they had questioned an employee of the defence ministry “under suspicion of secret agent activity” and seized computers and storage devices in a search of his home.

Earlier today, German chancellor Angela Merkel said she viewed spying on allies as a “waste of energy”.

“We have so many problems, we should focus on the important things,” said Dr Merkel, her most outspoken remarks to date on the unfolding scandal.

Senior Berlin sources said the German leader was “not amused by the revelations and frustrated by the political fall-out.

The parliamentary committee that oversees the work of Germany’s intelligence agencies met yesterday to hear details of the two reported spy cases.

Germany has said it doesn’t spy on its allies and considers it unacceptable for its allies to spy on German government officials and institutions.

After a week airing their frustrations with the US in private, senior German politicians are now moving into the public.

Finance minister Wolfgang Schäuble, a two-times interior minister, criticised the practice of recruiting German officials for creating political tension disproportionate to the intelligence gain.

Mr Schäuble told a television discussion on Wednesday night that the US double agent claims, if true, were “so stupid that one can only weep at the foolishness of it all”.

Wednesday, July 9, 2014

Microsoft fixes 29 Windows vulnerabilities (ZDNet)

Summary: UPDATED. This Patch Tuesday brings six updates but the first, a Cumulative Update for Internet Explorer, fixes 24 of the vulnerabilities.
By  for Zero Day |
Microsoft today released six security bulletins and updates to address the vulnerabilities disclosed in them. The updates address a total of 29 vulnerabilities.
Update at 2:20 pm ET: This story is updated below to clarify the exploitability of MS14-042.
  • MS14-037: Cumulative Security Update for Internet Explorer (2975687) — This update fixes 24 vulnerabilities, all of them memory corruption vulnerabilities, in every supported version of Internet Explorer. Ironically, the only IE version for which there are no critical vulnerabilities in this update is IE6 on Windows Server 2003. None of the vulnerabilities had been publicly disclosed or exploited.

  • MS14-038: Vulnerability in Windows Journal Could Allow Remote Code Execution (2975689) — A user who opens a specially-crafted Journal file can be exploited in their user context. All versions of Windows since Vista are affected and the vulnerability is critical on all of them. Running as a standard user limits the potential damage.

  • MS14-039: Vulnerability in On-Screen Keyboard Could Allow Elevation of Privilege (2975685) — When the on-screen keyboard is triggered by a malicious low-integrity process, that process could load and execute programs with the privileges of the current user. This vulnerability is rated important.

  • MS14-040: Vulnerability in Ancillary Function Driver (AFD) Could Allow Elevation of Privilege (2975684) — An attacker who has rights to log on locally could run a malicious program that would elevate privileges to kernel mode. This vulnerability is rated important.

  • MS14-041: Vulnerability in DirectShow Could Allow Elevation of Privilege (2975681) — A user could elevate privilege by running a malicious program from a low-integrity process. Running IE in immersive mode with Enhanced Protected Mode helps to mitigate this problem. This vulnerability is rated important.

  • MS14-042: Vulnerability in Microsoft Service Bus Could Allow Denial of Service (2972621) — A remote authenticated attacker could create and run a program that sends a sequence of specially crafted Advanced Message Queuing Protocol (AMQP) messages to the target system, triggering a denial of service. This vulnerability is rated moderate.
The Microsoft Exploitability Index this month's updates says that successful exploit code for 28 of the 29 vulnerabilities is "likely." The 29th is rated Moderate and therefore not rated as to exploitability. 
As is usually the case, Microsoft will also release a new version of the Windows Malicious Software Removal Tool and a large collection of non-security updates to various Windows versions.
Larry Seltzer has long been a recognized expert in technology, with a focus on mobile technology and security in recent years

Tuesday, July 8, 2014

France lacks the moral authority to depose the dollar (FT)

By Barry Eichengreen             July 8, 2014 
Opinion
Paris failed to detect BNP Paribas’ violation of international norms, writes Barry Eichengreen
U.S. Currency Production At The Bureau of Engraving and Printing

Michel Sapin is not the first French finance minister to complain about the dollar’s singular position in the international financial system. It is almost 50 years since Valéry Giscard d’Estaing coined the phrase “exorbitant privilege” to denote the dominant role of the greenback in global monetary affairs....

Nor is the BNP Paribas affair that irked Mr Sapin – the French bank has been fined $9bn for breaking US sanctions on Sudan and Cuba – the first time America has thrown around its financial weight to advance its political agenda. In 1956 it used Britain’s dependence on dollar credit to force London and Paris to roll back their invasion of Suez.


BNP Paribas fell foul of US law because the credit it provided to governments subject to American sanctions was denominated in dollars, which is what exporters in other countries customarily require. Once the dollars sourced by BNP’s New York branch passed through the US financial system – through Fedwire or another US-based network for clearing and settlement since there is no other convenient, low-cost way of making dollar payments – they came under US law.


In fact this is only the second recent effort by US authorities to use the dollar’s position to extend their legal reach. Last month the Supreme Court ordered Buenos Aires to compensate in full “holdout” creditors who rejected the debt restructuring after Argentina’s 2002 default, setting the international bankruptcy regime on its ear. The judges’ leverage was that payments to holders of Argentina’s dollar bonds were routed through the Bank of New York Mellon and again, therefore, through the US payments system.

They may not like it, but it is not clear what France and other critics can do to alter the status quo. They might try to set up dollar clearing offshore, an echo of the eurodollar market that sprang up in Europe in the 1970s in response to US controls on international transactions.

But low-cost clearing requires liquidity. The Federal Reserve provides the necessary liquidity to financial institutions that transact in dollars in the US, including subsidiaries of foreign banks. In theory, the Fed might provide dollar liquidity for offshore transactions, as during the global financial crisis, but it would not be inclined to provide liquidity to an offshore market established expressly to circumvent US sanctions.

The only feasible alternative, then, is to induce non-US exporters to take euros and renminbi in payment for goods and services. When Mr Sapin called for a “rebalancing” against the dollar using “the big currencies of the emerging countries”, there is no doubt which big emerging country he had in mind.

But for the euro and renminbi to be attractive to European and Asian companies exporting, say, pharmaceuticals to Cuba, markets in those currencies will need to be deep and liquid. Market participants will have to be able to buy and sell those currencies at a cost as low and predictable as they can for dollars.

Market liquidity requires a diverse clientele. Only if market participants include a wide variety of buyers and sellers who require a currency at different times will bid-ask spreads be low and stable – the hallmark of a liquid market. Building market liquidity therefore requires solving what economists call a “co-ordination problem”, inducing a diverse set of participants to enter the market at the same time. This, evidently, was what Mr Sapin was trying to orchestrate by exhorting companies in other countries to contemplate use of the euro and “big emerging currencies” in lieu of the dollar.

But France lacks the moral authority to orchestrate this process. Not only did one of its biggest banks egregiously violate international norms by doing business with Sudan and other unsavoury regimes. The government also failed to detect the violation or, worse, did not try.

Arbitrary and capricious use of US financial leverage would, in time, create widespread disaffection with the dollar. But steps by the US against BNP Paribas were hardly arbitrary and capricious. Such terms better describe Mr Sapin’s remarks.

The writer is professor of economics at the University of California, Berkeley






Monday, July 7, 2014

El éxito es dejar a un lado el temor a fracasar (Ricardo Tribin)

E    N      M    I      O    P    I    N    I    O    N
Esta célebre frase de Charles Agustin Sainte- Beuve nos recuerda que lamentablemente el temor es un insistente acompañante en la mente de las personas. Fracaso, a quien le gusta esto, que suena tan rudo? Prácticamente a nadie por supuesto, aunque una buena cantidad de gentes lo proyectan a diario en sus pensamientos.

No puedo? No soy capaz; me van a echar del trabajo; esto es muy difícil, son estos unos pocos de los pensamientos que llegan a la mente y los cuales, si no se contrarrestan, llevaran necesariamente al fracaso. Aprender a pensar bien y positivo  es quizás el modelo de cambio más aconsejable que ayuda a una persona a avanzar hacia adelante.

Pero, y que pasa si el fracaso llega? Pues tampoco es el fin del mundo y por ello es importante lidiar con el temor a fracasar puesto que no siempre, al emprender algo, se llega al avance y finalización con éxito. Y entonces esto que implica? Algo bien simple que aprendí en las laderas del nevado del Ruiz. “Aunque todo parezca nada siempre…. vuelve a empezar.

Miami, Julio 5 de 2014

Thursday, July 3, 2014

How big data may protect us from NSA spying (TechRepublic)


By  July 1, 2014, 

NSA surveillance
It's a truism in big data that you can never have enough data. With the cost of storage declining to unprecedented levels, the mantra now is to store everything... just in case it becomes useful data tomorrow or years from now.
The problem with this approach, however, is that it assumes that the only cost of storing more data is the associated storage cost. Lost in the calculation is the difficulty of making sense of signal amidst ever increasing data noise. The more data we store, the harder it becomes to separate meaningful signal from meaningless noise.
Just ask the NSA.

So much data... what's a spy to do?

Bill Binney recently resigned from the US National Security Agency (NSA), where he was a high-ranking official, mathematician, and codebreaker. After becoming disillusioned with the way the NSA was gathering and using intelligence, he quit.
While Binney is a severe critic of the NSA's spying on US citizens, one of his most potent critiques goes to the heart of big data:
"[T]he problem...[w]ith this bulk acquisition of data on everybody [is that the NSA has] inundated their analysts with data. Unless they do a very focused attack, they're buried in information, and that's why they can't succeed."
In other words, there's so much data noise that it's increasingly difficult to decipher any signal.
Noted statistician Nate Silver addresses this in his book The Signal and the Noise:
"If the quantity of information is increasing by 2.5 quintillion bytes per day, the amount of useful information almost certainly isn't. Most of it is just noise, and the noise is increasing faster than the signal. There are so many hypotheses to test, so many data sets to mine -- but a relatively constant amount of objective truth."
As both Binney and Silver highlight, the bigger the haystack, the harder it is to find the needle. We make this task ever more difficult for ourselves by using Hadoop and other modern data technologies to create "unsupervised digital landfills," as one Fortune 100 IT executive phrased it to me.

Nate Silver on signal and noise

Not only does it become ever harder to glean insight from mountains of data, but we can also seduce ourselves into believing that more data necessarily translates into more truth. In fact, all data is always processed by highly biased beings. Our prejudices aren't minimized by data.
If anything, they can be amplified by data, as Silver posits:
"[Big data] is sometimes seen as a cure-all, as computers were in the 1970s. Chris Anderson... wrote in 2008 that the sheer volume of data would obviate the need for theory, and even the scientific method....
"[T]hese views are badly mistaken. The numbers have no way of speaking for themselves. We speak for them. We imbue them with meaning.... [W]e may construe them in self-serving ways that are detached from their objective reality."
Ultimately, more data doesn't require less thinking, as some would suggest. We don't magically find correlations in mountains of data. We have to search for them, so we must ask the right questions of our data.

The best data scientist is the one you already have

This is why Gartner analyst Svetlana Sicular is dead-on when she suggests that enterprises will find it easier to train employees on big data technologies like Hadoop and NoSQL rather than bring in a "mythical data scientist" who already knows such technologies but likely won't know your business.
The hard part is figuring out the right questions to ask of your data, not how to use the technologies.
Which brings us back to the NSA. While the NSA may know which questions to ask of its data to figure out what citizens are doing with our time, could it be that mass surveillance may actually help to make us less susceptible to the NSA's prying into our lives? Share your thoughts in the discussion thread below.
Matt Asay is a veteran technology columnist who has written for CNET, ReadWrite, and other tech media. In his day job, he is the vice president of business development and marketing at MongoDB. He was previously chief operating officer at Canonical, ...

Wednesday, July 2, 2014

Intel pushes industry to cut the cables (ZDNet)

Summary: WiFi is wonderful, but somehow we are still stuck with lots of cables. Now Intel and others are working to eliminate the rest and deliver true wireless computing.

By  for Laptops & Desktops |

Tuesday, July 1, 2014

Facebook Emotional Experiment Annoys Users (PCMagazine)

BY DAVID MURPHY JUNE 29, 2014

No matter how you describe it, the end result is the same: Attach the words "emotional manipulation" to a practice that a company does, and people are going to feel a little incensed. Perhaps used. Possibly even a bit angry.
Such is the fallout from recent revelations that a Facebook data scientist and two university researchers manipulated the content of around 600,000 Facebook users' news feeds. The goal? To see how people might respond on Facebook if they were given more negative or more positive posts to view for a solid week.
It's a digital recreation of the psychological concept of "emotional contagion," or the notion that the moods of those you interact with on a daily basis can affect your mood positively or negatively. Researchers wanted to see if the experience could be recreated in the virtual environment with digital contacts, so they purposefully removed a chunk of positive posts or negative posts from an experimental set of users to see if there was any effect on their moods.
"In these conditions, when a person loaded their News Feed, posts that contained emotional content of the relevant emotional valence, each emotional post had between a 10 percent and 90 percent chance (based on their User ID) of being omitted from their News Feed for that specific viewing," reads the accompanying paper, published in the Proceedings of the National Academy of Sciences.
"It is important to note that this content was always available by viewing a friend's content directly by going to that friend's 'wall' or 'timeline,' rather than via the News Feed. Further, the omitted content may have appeared on prior or subsequent views of the News Feed. Finally, the experiment did not affect any direct messages sent from one user to another."
The result? Reducing the number of positive expressions in a News Feed appeared to make a person less likely to post positive things him or herself and more likely to post negative things. The opposite appeared to hold true when the number of negative expressions were reduced.
"Although these data provide, to our knowledge, some of the first experimental evidence to support the controversial claims that emotions can spread throughout a network, the effect sizes from the manipulations are small (as small as d = 0.001). These effects nonetheless matter given that the manipulation of the independent variable (presence of emotion in the News Feed) was minimal whereas the dependent variable (people's emotional expressions) is difficult to influence given the range of daily experiences that influence mood," read the researchers' paper.
However, the effects of running an experiment on a subset of its users seems to have also produced an effect of its own: irritation, with reactions ranging from describing the company's manipulations as "creepy," to questions regarding Facebook's decision to not specifically ask for user consent to participate in the study, to calls for Facebook to inform the users it attempted to emotionally manipulate. Some are even calling for increased regulation regarding Facebook's ability to run experiments on its users.
Here's Facebook's response:
"This research was conducted for a single week in 2012 and none of the data used was associated with a specific person's Facebook account. We do research to improve our services and to make the content people see on Facebook as relevant and engaging as possible. A big part of this is understanding how people respond to different types of content, whether it's positive or negative in tone, news from friends, or information from pages they follow. We carefully consider what research we do and have a strong internal review process. There is no unnecessary collection of people's data in connection with these research initiatives and all data is stored securely," said a Facebook spokesperson, as reported by Forbes.
For more, watch PCMag Live in the video below, which discusses Facebook's shady experiment.