Showing posts with label USA. Show all posts
Showing posts with label USA. Show all posts

Friday, 6 July 2012

Snooping, sharing and shifting

Many offices around the world sent their employees an urgent message on 6 June: ‘Please change your LinkedIn password immediately’, as the news spread that millions of accounts of the professional networking website had been hacked. 

Nearly 6.5 million LinkedIn passwords ended up in the wrong hands and were posted on an online forum by cybercriminals. And it was not only LinkedIn that was a victim of a the latest data security breach; the online dating website eHarmoney also admitted that nearly 1.5 million of its passwords had been stolen and music website Last.fm also suffered a major password leak. 

Although the three companies invalidated the embezzled passwords and they were quick to send out instructions to their affected customers telling them how to reset their accounts, the damage had been done. Analysts say it is not unlikely that criminals have scrutinised and copied millions of accounts and will try the same passwords – in combination with the corresponding usernames, usually email addresses – on other popular websites, such as Gmail, Hotmail, Twitter and Facebook. After all, many people use the same email address and password for a range of websites.

Who is snooping?
Obviously, it was not LinkedIn’s best month since the company launched 10 years ago. And the password leak sent shudders through the industry: if this can happen to such a big and popular website, who says it won’t happen to smaller, less well-protected players?

Experts, meanwhile, are convinced the internet is increasingly becoming a dangerous data jungle. Data is being copied, transmitted and passed on to advertisers, credit card details are being sold, twitter, hotmail and gmail accounts used to send round viruses and spam, while login details are publicly available online. 

Without trying to scare away the average internet user, many fraud experts do admit protecting your login details and other sensitive data has become more difficult than ever before in the history of the internet. The number of cyberattacks, tens of thousands each single day, are quickly increasing and, worryingly, consumers are mostly not even aware an attack has taken place or data has been stolen or shared without their consent. Mass hackings like the users of LinkedIn and eHarmony experienced at the beginning of June are rare and do make headlines, but many industry experts warn about all those smaller attacks you never hear about. Who is snooping, sharing and shifting is increasingly becoming one big blur. Keeping the same password for months on end has become a convenience one cannot longer afford.


Michiel Willems © 2012 CP Publishing Ltd. Picture: IBNLive.in.com / Original Artist 


Saturday, 28 January 2012

US Court: domain registrar not liable if domains merely 'forward'

A District Court in California ruled on 10 January that a domain name registrar is not liable for 'cyber squatting' if it redirects web users from a squatted website to another site.

Two domain names, registered by Go Daddy (GD) and bearing the name of the oil company Petronas, redirected visitors to a pornographic website through GD's servers. The District Judge ruled that "the forwarding of the disputed domains does not amount to 'use' of the domain names".

Simon Bennett, Partner at Fox Williams, believes the "decision was the right one, since [GD] does not exercise editorial control over sites hosted under domain names for which it acts as registrar".

Gillian Anderson, an Associate at Pinsent Masons, also called the ruling "the correct decision", while referring to the 2011 case Microsoft Corp v Shah Civil Action. In that case a claim of 'contributory cyber squatting' was upheld. "In contrast, Petronas' claim failed because the court decided that the registrar had not directly contributed to the infringement", Anderson explains. "It remains to be seen how the Petronas decision will be applied in future cases given the opposing outcomes from Petronas and Microsoft."

Cyber squatting - the practice of registering a domain name with the intent to profit from the goodwill of a trademark belonging to someone else - is illegal under the Anti-cyber squatting Consumer Protection Act (ACPA) if it happens in bad faith and with the intent to profit.

Michiel Willems © 2012 ECLP January issue, CP Publishing Ltd. London, UK.

Friday, 27 January 2012

The UIGEA, at last?

It sent shock waves through the industry. On 7 December, a jury in the US District Court of Boston found Todd Lyons guilty of illegal gambling offences under the Unlawful Internet Gambling Enforcement Act (UIGEA).

The jury was convinced Lyons ran the illegal gambling business Sports Offshore together with a number of co-defendants. Although Sports Offshore is based in Antigua, it was not licensed there and the business actively targeted and recruited customers throughout the US. Since Lyons acted as an 'on-the-ground agent' ­ collecting losses from US sports betters and shipping the proceeds back to Antigua ­ he was found guilty of 'acceptance of financial instruments for unlawful internet gambling', specifically stated under terms set out in the UIGEA. He was also convicted for racketeering under the Racketeer Influenced and Corruption Organisations Act (RICO) as well as violations of the Wire Act. 

And so it was official. The first conviction under the UIGEA ever was a fact. A historic moment? For the industry it certainly was. The conviction was hailed as a huge victory for those who oppose online gambling and the US Attorney for Massachusetts, Carmen M. Ortiz, said in a statement that the conviction of Lyons 'should serve as a message to those involved in illegal gambling schemes'. Really? This is a strong message from a government that has never convicted someone before under the UIGEA, even though the law has been in effect for more than five years. 

Lawyers and industry experts wonder what to make of this UIGEA verdict, and where to go from here. Before Lyons conviction, the Wire Act and RICO were as good as the only legal tools available to prosecute and convict persons involved in illegal gambling. 

So does this case mean a change of course? The answer is most likely no. The UIGEA conviction was merely possible because Lyons was physically collecting gambling proceeds within the United States, while practically all gambling businesses that even dare to offer their services to US customers stay well away from such practices. Money is transferred out of the country and collected in offshore jurisdictions far away, such as Barbados or Panama. 

So can we expect another UIGEA conviction soon? Probably not. Although since Black Friday it is clear that cracking down on online gambling activities in the US has become a priority for the US Department of Justice, the UIGEA's own terms limit the possibilities for prosecutors to crack down on online gambling businesses that attempt to take advantage of America's millions of poker players. 

In all likelihood, this conviction should be seen as a one-off event and prosecutors ought to celebrate the existence of the Wire Act and RICO if they wish to continue cracking down on online gambling in 2012.

Michiel Willems in WOGLR, December issue © 2011 CPP Publishing Ltd