Thursday, 10 September 2015

SumRando Speaks: 5 Questions with SumRando’s CEO

Today marks the inauguration of SumRando Speaks, an interview series geared towards introducing readers to the background, insights and expertise of cybersecurity, digital privacy and net neutrality professionals around the globe.

Our first installment features a conversation with SumRando Cybersecurity's Founder and CEO, who offers a rare glimpse into SumRando's history as well as a uniquely global perspective on the current state of digital privacy. Read on, surf secure and stay Rando!

Why SumRando Cybersecurity?
SumRando Cybersecurity grew from a desire to motivate everyday Internet users to employ better practices when online. The public and private sectors are shuffling and scuffling to create a cooperative framework to serve the public, but with very little to show for it. Every year new and larger threats mount, leaving the average Internet user ill-equipped to deal with hacks, surveillance and the like. I wanted to provide a service that would meet the needs of users in countries dealing with unsecured Wi-Fi and data collection as well as in countries where censorship and persecution for civil disobedience are rife. SumRando’s suite of privacy tools gives users everywhere the ability to proactively manage something they were never taught to protect: their data.
What is SumRando Cybersecurity’s greatest success to date? 
It was exciting to see usership spike in Iran in 2011 and Turkey in 2013 in response to government suppression and to know that we were virtually on the ground, helping the average citizen exercise his basic civil rights. Our greatest success, however, has been the universal adoption of SumRando. The fact that we have users all over the globe is a testament to my team’s ability to serve a diverse community with diverse needs and demonstrates our capacity to be anywhere we are needed in the future.
SumRando Cybersecurity is based in Africa, but has servers and users all over the globe. From your perspective, is there a singular debate regarding digital privacy and net neutrality, or does the conversation differ from region to region? 
There is an overarching theme, for sure. While technology bounds ahead and rewards are reaped across borders and classes, a conversation has begun about how to regulate these advances effectively, fairly and legally. Intuitively, we all perceive that the problems a businesswoman in Uganda has searching the internet are qualitatively different than those of a businesswoman in London. This contrast is reflected in the shifting priorities throughout the world regarding cybersecurity: in Africa, we’re wrapped up in a conversation about internet access that sometimes overlooks net neutrality and digital privacy; in the Middle East, Asia and Latin America, we focus on censorship and infringement of freedom of expression rather than data collection and data breaches; and in North America, we fear hackers and advertisers, and believe that censorship and access are issues for another time and place. Nonetheless, it’s an oversimplification to think that one country’s concerns and policies exist in isolation, especially when someone like Egypt’s al-Sisi cites increased government surveillance in the United States as reason to enact August’s oppressive “anti-terrorism” laws.
What individual, organization or law should be recognized for its work in support of (or against) digital privacy rights and net neutrality? 
I’ve seen a lot of positive momentum regarding network neutrality in 2015, but the regulations recently put in place still aren’t enough. The United States’ revised net neutrality rules were lauded as a step in the right direction and the European Commission self-labeled its regulations the “strongest and most comprehensive open Internet rules in the world.” Regardless, both sets of regulations leave far too much control in the hands of Internet Service Providers (ISPs). The deep packet inspection powers given to ISPs in the United States, for example, are so invasive that even the FCC recommends everyday users protect themselves with a VPN.
What's your #1 reason to use SumRando Cybersecurity's VPN? Web proxy? Secure messenger? 
At this point, it’s difficult to picture using the internet without our services, but there certainly are moments that stand out. Travel is an inherent part of my job, which means that I rely on our VPN to secure my internet connection in hotels, airports and cafes all over the world and also to keep up with news and sports back home. I frequently use our web proxy for a quick webpage look up on the run and our secure messenger to send notes to my team. 

SumRando Cybersecurity, SumRando CEO and Founder, SumRando Speaks, net neutrality, digital privacy, civil rights
www.sumrando.com

Wednesday, 9 September 2015

Public Comment Welcomed on South Africa’s Cybercrimes Bill


South Africa, Cybercrimes and Cybersecurity Bill, public comment, freedom of expression, legislation, Africa
South Africa's draft Cybercrimes and Cybersecurity Bill is open for debate.
“Cybercrime perpetrators no longer require complex skills or techniques." 


“The potential impact of a malware is limited only by the skills, resources and imagination of the programmer who creates it." 


“User interaction with computer devices produces a wealth of computer generated digital traces."


Bleak is the picture painted of the current state of South African cybersecurity by the discussion document accompanying a draft of the country’s 2015 Cybercrimes and Cybersecurity Bill. If length is any indication of necessity, then the 128-page bill and its accompanying 80-page discussion document are proof that such legislation is long overdue. 

The Bill addresses previous cybercrime loopholes with measures such as clause 13, which reverses the notion that immovable property cannot be stolen. It also establishes much-needed critical infrastructure: a Cyber Security Centre (clause 52), a Government Security Incident Response Team (clause 53), a Cyberwarfare Strategy (clause 55), a Cybersecurity Hub (clause 56) and a National Critical Information Infrastructure Fund (clause 59). 

Regardless, several clauses of the Bill extend well beyond cybercrime protection and into an ambiguity that invites infringement upon freedom of expression and the right to privacy. Our main concerns include:

According to the Bill, possessors of software and hardware tools that could be used to commit cybercrimes are guilty unless proven innocent:

Clause 6(3): Any person who is found in possession of a software or hardware tool in regard to which there is a reasonable suspicion that such software or hardware tool is possessed for the purposes of contravening [certain provisions], and who is unable to give a satisfactory exculpatory account of such possession, is guilty of an offense.

The Bill broadly defines terrorism and consequently limits free speech for internet users. The discussion document acknowledges that South Africa’s Constitution prohibits the freedom of expression that many nations enjoy:

Clause 15(5): For purposes of this section, “computer related terrorist activity” means…that which is intended, or by its nature and context, can reasonably be regarded as being intended, in whole or in part, directly or indirectly, to— (i) threaten the unity and territorial integrity of the Republic; (ii) intimidate, or to induce or cause feelings of insecurity among members of the public, or a segment of the public, with regard to its security, including its economic security, or to induce, cause or spread feelings of terror, fear or panic in a civilian population; or (iii) unduly compel, intimidate, force, coerce, induce or cause a person, a government, the general public or a segment of the public, or a domestic or an international organisation or body or intergovernmental organisation or body, to do or to abstain or refrain from doing any act, or to adopt or abandon a particular standpoint, or to act in accordance with certain principles.

Clause 17(1-3): Any person who unlawfully and intentionally— (a) makes available, broadcasts or distributes; (b) causes to be made available, broadcast or distributed; or (c) assists in making available, broadcasts or distributes, through a computer network or an electronic communications network, to a specific person or the general public, a data message which advocates, promotes or incites hate, discrimination or violence against a person or a group of persons, is guilty of an offence. (3) For purposes of this section “data message which advocates, promotes or incites hate, discrimination or violence” means any data message representing ideas or theories, which advocate, promote or incite hatred, discrimination or violence, against a person or a group of persons, based on— (a) national or social origin; (b) race; (c) colour; (d) ethnicity; (e) religious beliefs; (f) gender; (g) gender identity; (h) sexual orientation; (i) caste; or (j) mental or physical disability.

The Bill sets in place a mechanism to search for, access and seize articles without a warrant:

Clause 30(1): An application referred to in section 29(1)(a), or an application for the amendment of a warrant issued in terms of section 29(1)(a), may be made orally by a specifically designated member of a law enforcement agency, if it is not reasonably practicable, having regard to the urgency of the case or the existence of exceptional circumstances, to make a written application. 

Clause 32(1): (1) On the arrest of any person on suspicion that he or she has committed— (a) an offence under this Act; or (b) any other offence, a member of a law enforcement agency may search the arrested person and seize any article referred to in section 28 which is in the possession of, in the custody of or under the direct control of, the arrested person.

The Bill calls for Internet Service Providers to preserve data traffic and stored information when requested. The discussion document acknowledges this and similar measures as attempts “to bring the law of the day in line with the international position regarding the investigation of cybercrime,” a position that frequently finds itself under attack:

Clause 40(3): An expedited preservation of data direction must direct the person or electronic communications service provider affected thereby, from the time of service of the direction, and for a period of 120 days— (a) to preserve the current status of; (b) not to deal in any manner with; or (c) to deal in a certain manner with, the data referred to in the direction in order to preserve the availability and integrity of the data.

Public comment on the Bill is welcome until November 30 via mail, email, fax or in person; further information is available at http://www.justice.gov.za/legislation/invitations/invites.htm.

Exercise your rights, surf secure and stay Rando!

Friday, 4 September 2015

For Many, Internet Access Is the Issue

Recently, we’ve highlighted the insecurity and censorship faced by internet users in Venezuela, Indonesia, Egypt, Bangladesh and Nigeria. What we haven’t mentioned is what makes these users quite fortunate: the fact that they have access to the internet at all.

A Pew Research Center study of 32 emerging and developing nations clarifies just how inaccessible the internet is for much of the world’s population.

Internet access, emerging markets, developing world,
[Source: Pew Research Center]
Of note:

  • Only 11% of Bangladesh’s population accesses the internet occasionally or owns a smartphone.
  • 91% of Egyptian adults own cell phones, but only 25% of those are smartphones. 
  • Only 3% of Uganda’s adult population has a working computer at home.

In spite of and because of such low rates of internet penetration, growth in regions such as Africa, Asia, Latin America and the Middle East has far outpaced that in Europe, North America or Australia in the last 15 years and is on track to continue. As such, governments, corporations and NGOs—including those in the developed world—are anxiously and entrepreneurially looking to get the ‘next billion’ online.

As the potential for universal access to the internet becomes a reality, SumRando Cybersecurity asks users to be aware of what has come before and what will likely continue: laws that infringe upon basic privacy rights; access to some websites but not others; and an endless supply of email phishing, malware, stolen passwords and data breaches.

Be informed, surf secure and stay Rando!

Wednesday, 2 September 2015

It’s a Vulnerable World: late August 2015

The big names in our last roundup—Apple, Tor, Internet of Thingsseem to be reappearing a short two weeks later, but the bad news doesn’t end there. Security vulnerabilities revealed in late August include open source ransomware and Microsoft adopting Google-level data collection.
Preferring convenience to safety, investment management company Vanguard continues to allow users to login, even with misspelled security answers.

British Gas’s Hive Active Heating app was renamed a “burglar’s dream” when a study revealed that the Internet of Things technology does not encrypt user data. British Gas has since agreed to employ encryption.
Twitter, bot, Twitterbot, Mexico, Turkey, Egypt, Syria, activist
Twitter bots have the power to silence activists.
Pro-government Twitter bots prevented Mexican activists from sharing information and pushed #YaMeCanse out of the platform’s trending topics; such actions have been taken against Turkish, Egyptian and Syrian protesters in the past. 
A Trend Micro security researcher reported that stolen credit card information—such as that from the recent Ashley Madison data dump—is highly desirable to cybercriminals, as it is commonly used to pay for the ebullet proof hosting services (BPHS) used to spread malware. 

The newly released Windows 10 has made headlines for the degree to which it sends user data back to Microsoft. As InfoWorld wisely pointed out, like it or not, the data Microsoft is collecting is akin to what Google has been doing all along.

The United States’ NSA and the United Kingdom’s GCHQ have acknowledged that today’s encryption would be powerless against tomorrow’s quantum computing. Although not an immediate threat, such computers will exist in the next half century.

Turkish security researcher Utku Sen published open source ransomware on GitHub, along with the disclaimer: “While this may be helpful for some, there are significant risks. The Hidden Tear may only be used for Educational Purposes. Do not use it as a ransomware!”

Dark web drug market Agora suspects the current protection provided by Tor is insufficient to maintain its anonymity and has temporarily gone offline as it strengthens its security. Researcher Nicolas Christin reminds us, “Tor is not a magic box that provides you a cloak of invisibility, Harry Potter style.”

Vint Cerf, Father of the Internet, Heidelberg Laureate Forum, Turing Award, internet freedom, open internet
"Father of the Internet" Vint Cerf is worried.
Apple designed iOS 9 to default to rigorous security standards for app developers, but also published the code to disable such encryption. Google shortly thereafter further spread the word on the privacy workaround. 
At the Heidelberg Laureate Forum, Turing Award winner and “Father of the Internet” Vint Cerf spoke with knowledge, experience and perhaps foresight when he said, “I worry a lot about the potential loss of openness and freedom on the Internet.”
KeyRaider malware has stolen login credentials from 225,000 mostly-Chinese, jailbroken iPhones. The incident reminds us of what can go wrong when security features are removed in order to access otherwise-inaccessible apps. 
If we’ve missed any vulnerabilities, let us know in the comments below. Surf secure and stay Rando!

Monday, 31 August 2015

Venezuela Border Crisis: Your News or Ours?

When we heard that a recent border closing had motivated thousands of immigrants—many of whom were legal and naturalized—to flee Venezuela for their native Colombia, we decided to use SumRando Cybersecurity’s VPN to see if the story shifted based on who was doing the telling. The results are in:

On August 27, as Venezuela's pro-government, investment firm-owned El Universal reported: 
Venezuela llama a consultas a su embajador en Colombia 
Venezuela Recalls Embassador to Colombia for Consultation
El Universal, Venezuela, Colombia, border crisis, immigration, Maduro
[Source: El Universal]

and Venezuela’s independent news outlet TalCual reported:
Maduro también llama a consultas a embajador venezolano en Colombia
  Maduro Recalls Venezuelan Embassador to Colombia for Consultation
TalCual, Venezuela, Colombia, border crisis, immigration
[Source: TalCual]

from our New York node, the New York Times reported:
New York Times, Venezuela, Colombia, immigration, border crisis
[Source: The New York Times]

and from our Sweden node, Dagens Nyheter reported:
Undantagstillstånd vid gränsen mot Colombia
A State of Emergency on the Border with Colombia
Dagens Nyheter, Colombia, Venezuela, border crisis, immigration
[Source: Dagens Nyheter]

The news you receive depends on where your internet service provider believes your computer is. See for yourself with our nodes in Brazil, Hong Kong, Jordan, New York, Singapore, Sweden and Turkey. Find what's out there, surf secure and stay Rando!