Read Articles

Thursday, 28 April 2011

There’s anonymity on the Internet. Get over it.


In a recent interview prominent antivirus developer Eugene Kaspersky decried the role of anonymity in cybercrime. This is not a new claim – it is touched on in theCommission on Cybersecurity for the 44th Presidency Report and Cybersecurity Act of 2009, among others – but it misses the mark. Any Internet design would allow anonymity. What renders our Internet vulnerable is primarily weakness of software security and authentication, not anonymity.
Consider a hypothetical of three Internet users: Alice, Bob, and Charlie. If Alice wants to communicate anonymously with Charlie, she may relay her messages through Bob. While Charlie knows Bob is an intermediary, Charlie does not know with whom he is ultimately communicating. For even greater anonymity Alice can pass her messages through multiple Bobs, and by applying cryptography she can ensure no individual Bob can piece together that she is communicating with Charlie. This basic approach to anonymity is remarkable in its independence of the Internet’s design: it only requires that some Bob(s) can and do run intermediary software. Even on an Internet where users could verify each other’s identity this means of anonymity would remain viable.
The sad state of software security – the latest DHS weekly bulletin alone identified over 40 “high severity” vulnerabilities – is what enables malicious users to exploit the Internet’s indelible capacity for anonymity. Modifying the prior hypothetical, suppose Alice now wants to spam, phish, denial of service (DoS) attack, or hack Charlie. After compromising Bob’s computer with malicious software (malware), Alice can send emails, host websites, and launch DoS attacks from it; Charlie knows Bob is apparently misbehaving, but has no means of discovering Alice’s role. Nearly all spam, phishing, and DoS attacks are now perpetrated with networks of compromised computers like Bob’s (botnets). At the writing of a July 2009 private sector report, just five botnets sourced nearly 75% of spam. Worse yet, botnets are increasingly self-perpetuating: spam and phishing websites propagate malware that compromises new computers for the botnet.
Shortcomings in authentication, the means of proving one’s identity either when necessary or at all times, are a secondary contributor to the Internet’s ills. Most applications rely on passwords, which are easily guessed or divulged through deception – the very mechanisms of most phishing and account hijacking. There arepotential technical solutions that would enable a user to authenticate themselves without the risk of compromising accounts. But any approach will be undermined by weaknesses in underlying software security when a malicious party can trivially compromise a user’s computer.
The policy community is already trending towards acceptance of Internet anonymity and refocusing on software security and authentication; the recent White House Cyberspace Policy Review in particular emphasizes both issues. To the remaining unpersuaded, I can only offer at last a truism: There’s anonymity on the Internet. Get over it.

0 comments:

Post a Comment

Note: only a member of this blog may post a comment.

free counters

Categories

Blog File Sharing Troubleshooting all Computer Troubleshooting How to Operating System Internet Maintanance and Repair ERROR Solutions Help Support Help and Support Device Manager Error Computer Windows Device Applications Install Java Script Computer Repair Java Programe Photoshop Add HTML facebook on site Computer Management Facebook and Site Messenger and Chat Protect Your Computer XFBML and HTML Facebook BELAJAR PHOTOSHOP Shortcut Startup Programs TUTORIAL PHOTOSHOP Windows Administration Tools Create DVD Create DVD Maker Keyboard Network Set Up Security Security System Test DVD Test DVD Drive VGA Card VGA Conector VGA Informations CA-CLIPPER INTERNAL ERROR Crack Create PDF Create PDF using Smart PDF Creator Error windows explorer Hard Drive Partitioning Intall Windows 7 Ultimates Internet Browser Local Area Network Networking PDF EDITOR Protect CD from Copy Router Smart PDF Creator Tutorial Java USB REMOVE Word Password Remover Access Media Collection Adsense Animator Anomymity Computer Hang Computer Icon Computer Set Up D-Link D-Link Router DNS DVD Drive DVD compress Device Drive partitions Drive parts Earn Money Easy Gif Animator Elastomer Eror Solution External Hard Drive Facebook Free Internet Hack Password Hard Drive How to Download Inside Adsense Internet Explore JPEG JPG GIF PNG BMP Laptop Laptop vs PC MS Word to PDF Make DVD Make Money with blog Make Your Own Copy-Protected CD with Passive Protection Modem Ms Word Applications Online Shoping PC Desktop PDF Remover Partitions drive Picture Prevent Windows XP Print Printer Error Reboot Application Remove Pasword Excel Restore Windows Registry Search Engines Optimizer Social Networking Solving Probelm System Registry Upload File to blogger Upload Files Virtual Memory is to Low Viture Windows 7 Windows DVD Maker Wireless Wireless router Words error intall windows explorer cannot open words documents cannot open

Share

Twitter Delicious Facebook Digg Stumbleupon Favorites More