Scroogle.Org

Google may not yet be evil, but it is certainly moving further and further down toward that end of the continuum with its extremely poor privacy practices in combination with the almost absurd amount of user data it appears to be logging and storing.

With that in mind, I suspect more services like Scroogle will arise to route around Google’s blase attitude toward user privacy.  Scroogle is basically a Google search proxy. Enter your search into Scroogle and it passes it on to Google using one of a small number of IP addresses, so yours is never logged. Scroogle then intercepts the cookie that Google returns and then displays just the actual search results.

Unlike Google which stores user identifiable information about the search for 18 months, Scroogle promises that a) it doesn’t store search terms at all and b) it only maintains logs for a maximum of 48 hours.

I noticed Daniel Brandt, who I’ve criticized in the past for his conspiratorial ways, is listed as one of the directors of the Scroogle effort. It’s nice to see him turn his anti-Google obsession to positive solutions.

Blizzard Announces a Physical Token for World of Warcraft Account Authentication

Theft of World of Warcraft accounts is a huge problem. The perception is that gold farmers are finding it much more lucrative to simply hack people’s accounts by tricking them into to installing keyloggers rather than actually use in-game bots to farm resources. There is an entire class of trojans now aimed largely at WoW players.

So Blizzard recently announced a forthcoming Authenticator product which looks to be a rebranded RSA SecurID. The device will costs $6.50 and asks the user to link the serial number of the device to the WoW account. From then on, when you want to log in you enter your username and password, then press a button on the Authenticator which generates a number that has to be entered as well. The number is essentially a rolling one time pad, and that specific number is only good for 30-60 seconds. So someone who manages to grab all three pieces of data has a very small window in which to gain access to your account.

As some have noted on WoW-related sites, this sort of scheme is still vulnerable to man-in-the-middle attacks. Think of this being used to authenticate login to a bank website. I put my server in between you and the bank. You think your data is going to the bank, but its really going to my server, then I’m passing it on to the bank, and then passing the bank’s response on to you. You never even know you’ve been hacked until I log in with your password and ID later and clean out everything.

Assuming that the Authenticator is ever owned by a large percentage of users — and I’m skeptical it will be — it will be interesting to see if the hackers turn to man-in-the-middle style attacks or simply turn their attention to an easier target.

Silly Brits and Their Child Database

This Guardian article highlights the odd way that Great Britain treats personal data. On the one hand, laws that govern what private companies can do with personal data are rather draconian compared to, say, the United States. On the other hand, there seems to be almost no effective limit to what European governments can compile.

In this case, the UK is creating a single database to track every child in the country.  The database will give each child a unique identifying number and contain everything from the name and address of the child’s physician to info on parents, what schools the child has attended, etc. And only about 300,000 people nationwide will have access to the database.

The Guardian article is about a report examining the security procedures for access to the database — a report that the government refused to publish in full. Of course the best method would be to simply not create such a monstrosity in the first place. As a review of the database’s security noted, “there will always be a risk of data security incidents occurring.” And because of the overreaching nature of the database, a security breach threatens the exposure of sensitive data about literally every child in the UK. Oy.

How Long Should ISPs Preserve Customer Records?

In September, U.S. Attorney General Alberto Gonzales told lawmakers that ISPs should be legally required to preserve customer records for perhaps as long as two years. Currently there are no federal laws governing customer record retention for ISPs.

Gonzales says that the customer records must be preserved for that length of time to assist the government in cracking down on child pornography.

The problem with this, of course, is that the result is records are preserved on millions of completely innocent people in order to help prosecute a relatively small number of cases that involve child pornography (in 2000-2001, according to the National Center for Missing & Exploited Children, a little over 1,700 people were arrested on child pornography-related charges).

And once that data is collected and preserved, it will inevitably be subpoenaed far and wide for everything from terrorism prosecutions to copyright infringement to anything else under the Sun.

As I’ve said before, ISPs should not preserve any sort of customer traffic records for any longer than they need for technical purposes — no more than a few days, at most. More importantly, ISPs and web services need to be more upfront and make more accessible just how long they do preserve such customer data and under what circumstances they will provide said data to law enforcement and other entities.

Sources:

Statement Of Alberto R. Gonzales Attorney General Of The United States Before The Committee On Banking, Housing, And Urban Affairs United States Senate Concerning “Combating Child Pornography By Eliminating Pornographers’ Access To The Financial Payment System”. September 19, 2006.

Child pornography fact sheet. National Center for Missing & Exploited Children, Accessed: September 30, 2006.

Gonzales Calls for ISP Customer Data Retention Law. RedmondMag.Com, September 19, 2006.