nexa
By thread
nexa@server-nexa.polito.it
By month
Messages by month
- ----- 2026 -----
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
December 2016
- 31 participants
- 71 messages
Sulla Rivista Il Mulino in edicola si parla di economie digitali
by J.C. DE MARTIN
C'è anche un articolo del Fellow Nexa Giovanni Arata :)
Buona domenica e buon voto referendario,
juan carlos
Dec. 4, 2016
Re: [nexa] Weapons of Math Destruction
by J.C. DE MARTIN
Grazie molte, Diego; l'ho comprato perché mi sembrava
interessante, ma non ho ancora trovato il tempo di leggerlo.
juan carlos
On 04/12/16 10:13, Diego Latella wrote:
> Probabilmente lo conoscete gia', ma non ricordo di averne visto
> traccia nella lista e quindi
>
> Segnalo "Weapons of Math Destruction"
> di Cathy O' Neil
> ALLEN LANE - Penguin - 2016
> https://weaponsofmathdestructionbook.com/
>
> del quale suggerisco la lettura.
>
> Sebbene, per motivi divulgativi, il linguaggio utilizzato sia spesso
> un po' troppo slang (per i miei gusti),
> specie nei primi capitoli, il libro racconta una serie di fatti
> documentati e descrive
> una serie di concetti che ritengo sia importante conoscere.
>
> In particolare, penso che la comunita' ICT dovrebbe riflettere
> sull'impatto sociale di alcuni
> suoi risultati, sull'opacita' di pratiche di sviluppo e utilizzo di
> strumenti software predittivi,
> e sulla necessita' di regolamentarle. Penso quindi che sia importante
> che la comunita'
> scientifica si mobiliti sempre di piu' e dia un suo contributo anche a
> livello normativo.
>
> Diego
Dec. 4, 2016
Weapons of Math Destruction
by Diego Latella
Probabilmente lo conoscete gia', ma non ricordo di averne visto
traccia nella lista e quindi
Segnalo "Weapons of Math Destruction"
di Cathy O' Neil
ALLEN LANE - Penguin - 2016
https://weaponsofmathdestructionbook.com/
del quale suggerisco la lettura.
Sebbene, per motivi divulgativi, il linguaggio utilizzato sia spesso
un po' troppo slang (per i miei gusti),
specie nei primi capitoli, il libro racconta una serie di fatti
documentati e descrive
una serie di concetti che ritengo sia importante conoscere.
In particolare, penso che la comunita' ICT dovrebbe riflettere
sull'impatto sociale di alcuni
suoi risultati, sull'opacita' di pratiche di sviluppo e utilizzo di
strumenti software predittivi,
e sulla necessita' di regolamentarle. Penso quindi che sia importante
che la comunita'
scientifica si mobiliti sempre di piu' e dia un suo contributo anche a
livello normativo.
Diego
--
Dott. Diego Latella - Senior Researcher -
CNR/ISTI, Via Moruzzi 1, 56124 Pisa, IT (http:www.isti.cnr.it)
FM&&T Laboratory (http://fmt.isti.cnr.it)
http://www.isti.cnr.it/People/D.Latella - phone: +39 0506212982 - mob:
+39 348 8283101 - fax +39 0506212040
===================
The quest for a war-free world has a basic purpose: survival. But if
in the process we learn how to achieve it by love rather than by
fear, by kindness rather than compulsion; if in the process we learn
how to combine the essential with the enjoyable, the expedient with
the benevolent, the practical with the beautiful, this will be an
extra incentive to embark on this great task.
Above all, remember your humanity.
-- Sir Joseph Rotblat
Dec. 4, 2016
Expanded Federal Hacking Authority Goes Into Effect Despite Last Minute Efforts in Senate
by Alberto Cammozzo
Mi pare nuovo lo scenario implicito di controllo delle botnet: per un
governo è più vantaggioso sfruttarle che chiuderle.
A quando la "botnet di Stato"?
<https://theintercept.com/2016/12/01/expanded-federal-hacking-authority-goes…>
As of December 1, it is considerably easier for the FBI to hack into
computers during investigations.
Thanks to a federal rule change, which passed through several judicial
panels before being approved by the U.S. Supreme Court in April, FBI
employees can now seek warrants from magistrate judges to remotely
access computers even when targets might be outside those judges’
districts, including when the targets’ location is disguised by
anonymity software like Tor. Additionally, FBI employees can now search
computers infected by malware that makes them part of a botnet — a
method used by criminals to disrupt internet service, distribute spam,
or spread viruses on a mass scale.
The argument over the modifications, while described by the Department
of Justice as simple amendments necessary to facilitate investigations
in the modern age, has been contentious.
Privacy advocates like Sen. Ron Wyden, D-Ore., called the impending rule
change “one of the biggest mistakes in surveillance policy in years” as
he fought on the Senate floor the day before it was scheduled to take
effect, joined by colleagues Sens. Chris Coons, D-Del., and Steve
Daines, R-Mont. “Law-abiding Americans are going to ask ‘What were you
guys thinking?’ when the FBI starts hacking victims of a botnet hack. Or
when a mass hack goes awry and breaks their device, or an entire
hospital system and puts lives at risk,” he said in a statement.
[...]
Dec. 3, 2016
Internet Archive Successfully Fends Off Secret FBI Order
by Alberto Cammozzo
Seconda vittoria dell'Internet Archive contro una National Security
letter dell FBI
<https://theintercept.com/2016/12/01/internet-archive-fends-off-secret-fbi-o…>
A decade ago, the FBI sent Brewster Kahle, founder of the Internet
Archive, a now-infamous type of subpoena known as a National Security
Letter, demanding the name, address and activity record of a registered
Internet Archive user. The letter came with an everlasting gag order,
barring Kahle from discussing the order with anyone but his attorney —
not even his wife could know.
But Kahle did eventually talk about it, calling the order “horrendous,”
after challenging its constitutionality in a joint legal effort with the
Electronic Frontier Foundation and the American Civil Liberties Union.
As a result of their fight, the FBI folded, rescinding the NSL and
unsealing associated court records rather than risk a ruling that their
surveillance orders were illegal. “This is an unqualified success that
will help other recipients understand that you can push back on these,”
Kahle told reporters once the gag order was lifted.
The bureau continued to issue tens of thousands of NSLs in subsequent
years, but few recipients followed in Kahle’s footsteps. Those who did
achieved limited but important transparency gains; as a result of one
challenge, a California District Court ruled in 2013 that the
everlasting gag orders accompanying NSLs are unconstitutional, and last
year Congress passed a law forcing the FBI to commit to periodically
reviewing such orders and rescinding them when a gag is no longer
necessary to a case.
Now, Kahle and the archive are notching another victory, one that
underlines the progress their original fight helped set in motion. The
archive, a nonprofit online library, has disclosed that it received
another NSL in August, its first since the one it received and fought in
2007. Once again it pushed back, but this time events unfolded
differently: The archive was able to challenge the NSL and gag order
directly in a letter to the FBI, rather than through a secretive
lawsuit. In November, the bureau again backed down and, without a
protracted battle, has now allowed the archive to publish the NSL in
redacted form.
[]
Dec. 3, 2016
Re: [nexa] Responsabilità dei software vendor in merito alle falle di sicurezza
by Andrea Glorioso
Sempre sullo stesso argomento, un recente evento dell'Atlantic Council
(basato a Washington, DC):
+++
http://www.csmonitor.com/World/Passcode/2016/1202/Should-companies-be-held-…
Should companies be held liable for software flaws?
December 2, 2016
—With more cars and medical devices connecting to the internet, what
happens if automakers and health care companies don't start prioritizing
digital security?
Many cybersecurity experts worry that faulty code in the so-called Internet
of Things (IoT) won't just cause systems to malfunction and freeze.
Instead, they say, flaws inside connected cars or pacemakers could lead to
serious injury or death.
As a result, leading digital security experts are calling on US
policymakers to hold manufacturers liable for software vulnerabilities in
their products in an effort to prevent the bugs commonly found in
smartphones and desktops from pervading the emerging IoT space.
But can that strategy work? Or will more government regulation stifle
innovation?
Those were the big questions at an event Wednesday at the Atlantic Council
in Washington. Passcode was a media partner of the event. Here are a few
things we learned:
About video ads
1. Everything is a computer. Act like it
To lay the legal foundation for the Digital Age, policymakers need to start
wrapping their minds around the idea that we're living in an era of
technology, where everything we depend on is a computer that may be
connected to the internet, says cryptographer Bruce Schneier, a fellow at
Harvard Law School's Berkman Klein Center for Internet and Society.
"The way to think about the world is that we’re creating technology where
everything is a computer," he said. "Your smartphone is a computer that
makes calls. Your car is a 100-computer network with an engine. That’s the
Internet of Things."
Though the US government hasn't adopted regulations for the burgeoning
space, the Obama administration last month released guidelines for IoT
devices that called on engineers to build secure features into the design
of connected products. That followed a similar strategy from the Department
of Homeland Security that said manufacturers should prioritize security
features for the most harmful functions that could be breached.
But creating a legal regime that determines who's responsible for security
flaws in those computers or software, Mr. Schneier says, will require the
country to enact consumer protection laws that can more effectively respond
to rapid changes in technology. More safety regulation is needed, he added,
because consumers still might buy harmful products if they tend to work
well, regardless of the potential dangers to their safety.
"The market can’t fix this because neither the buyer and the seller care,"
he said. "Until now, we've given programmers the right to code the world
that they saw fit. We need to figure out the policy."
2. Data rules everything around you
In the era of big data, companies can measure many digital security
metrics, from the cost of cyberattacks to the susceptibility of employees
to phishing and other hacking tricks. But there's still not enough data on
IoT breaches, because its spread is so new, says John Soughan, who heads up
business in the cyberinsurance division at Zurich North America, a
Switzerland-based insurance company.
"Right now, there’s not enough data around what are the causes of these
breaches, all of the liabilities in there. That’s problematic for insurance
companies, because that’s part of the market," he said. "That’s why we're
supportive of efforts to collect breach data to make sure we know what the
cost of that risk is."
The lack of information on data breaches is also problematic as courts
begin to determine how to settle cases where consumers are harmed by
internet-connected products. Since there's been few efforts to
categorically track the harmful impact of faulty internet-connected
products, legal cases against manufacturers are often based on ambiguous
threats, which may not be enough to get a ruling – let alone create a
precedent for future cases.
What's more, added Wendy Knox Everette, a legal fellow at the
technology-focused law firm ZwillGen, "the amorphous threat of some future
non-physical harm is not enough for a court to address right now."
3. Learn to live with risk
Even if there is a legal framework for IoT that's designed to protect
consumers, people still may need to accept some risk with these types of
devices, the experts said.
"We don’t want perfectly unbreakable door locks because they’d be too
expensive. We choose to bear that risk," said Eli Dourado, director of the
Technology Policy Program at George Mason University's Mercatus Center.
"You never get rid of externalities. We’re trying to get to the most
efficient result – the least harm."
So to strike a balance between keeping consumers secure and enabling
technology to advance, experts say, policymakers would do well to find ways
to get the riskiest products off the market.
"The IoT makes people think about software liability," said Ms. Everette.
"Instead of being locked inside desktop computers, [software] is now inside
physical devices that can now interact with us and possibly harm us... .
You can buy knives, but we no longer have lawn darts on the market. That’s
a really good way to see how product liability helps you determine your
risk."
Sent from my iPad
On Wed, Nov 30, 2016 at 19:32 Andrea Glorioso <andrea(a)digitalpolicy.it>
wrote:
> Personalmente, e avendoci lavorato per un po' (ma diversi anni fa) ritengo
> che a fronte di tecnologie oggettivamente complesse (ma non necessariamente
> più complesse di un'automobile moderna) vi siano svariate soluzioni
> possibili, dell'assunzione di responsabilità di un "principal" (e.g.
> azienda che produce distribuzioni GNU/Linux), agli strumenti assicurativi
> (che anni fa non erano possibili perché le compagnie assicurative, pur
> essendo interessate al potenziale mercato, non avevano a disposizione i
> dati attuariali necessari, poiché le aziende ICT si rifiutavano di fornire
> il benché minimo numero in materia di bug / falle eccetera), all'esenzione
> di responsabilità per chi produce software senza scopo di lucro.
>
> Ma ci vogliono la visione e la volontà, che all'epoca mancavano, almeno da
> parte dell'industria. Poi mi hanno messo a fare altro, quindi non so bene
> cosa sia successo di recente. :)
>
> Sul rischio sistemico, la recente Direttiva NIS (Network and Information
> Security) introduce già obblighi di e.g. breach notification per le aziende
> (incluse quelle IT) il malfunzionamento dei cui prodotti o servizi possa
> avere un impatto significativo a livello nazionale o europeo.
>
> Naturalmente, durante le negoziazioni di quella Direttiva (e altre) si è
> assistito al fenomeno del "Lobbista di Schrödinger", ovvero il lobbista che
> sostiene al tempo stesso che l'azienda X è troppo importante per l'economia
> nazionale / europea perché gli stupidi legislatori possano pensare di
> regolamentarla in qualsivoglia modo, ma è anche così poco importante che le
> sue azioni non possono in alcun caso avere un impatto negativo sulle
> suddette economie. Ho sentito dire che Giacobbo ci sta preparando uno
> speciale di Voyager.
>
> Ciao,
>
> Andrea
>
> On Wed, Nov 30, 2016 at 13:21 mutek(a)riseup.net <mutek(a)riseup.net> wrote:
>
> On 30/11/2016 16:00, Fabio Pietrosanti (naif) - lists wrote:
>
> >
> > On 11/29/16 12:26 PM, Andrea Glorioso wrote:
> >> "Perché non si può uccidere l'innovazione."
> >>
> >> (Cose sentite da una decina d'anni a questa parte, quando appunto su a
> >> Bruxelles si cercava di ragionare su come assicurarsi che l'industria
> >> delle TIC fosse sostenibile. All'epoca, alcuni avevano già previsto ciò
> >> che oggi Bruce Schneier e altri vanno a dire al Congresso degli Stati
> >> Uniti, ovvero che Internet non è più solo foto di gattini, e per inciso
> >> non lo era nemmeno dieci anni fa quando Schneier & co dicevano cose un
> >> po' diverse di oggi.)
> >>
> >> Comunque io ero e resto convinto che (1) le responsabilità civili e
> >> penali, specialmente per dolo o colpa grave e/o per attività in cui è
> >> richiesta più della cura del "pater familias" (se è ancora questa la
> >> terminologia usata) non sono automaticamente obliterate da EULA
> >> fantasiose, e che (2) chi richiede software (che sia embedded o meno)
> >> per attività tipo gestire le turbine di una centrale nucleare, ha i
> >> soldi e le leve politiche per richiedere eccome al "vendor" l'assunzione
> >> di responsabilità precise in caso di malfunzionamento. Bisogna vedere se
> >> ne ha l'intelligenza e la volontà.
> > Ci vorrei aggiungere una riflessione che parte da questo tuo spunto.
> >
> > C'è software e software, ovvero ci sono software a rischio sistemico
> > (es: Internet Explorer, Chrome, Acrobat Reader, Mac OS X, etc) e
> > software che no (Impara a Cucinare 3.2, DisegnareGiardini 2.0) .
> >
> > Per il mondo delle banche la regolamentazione è stata differenziata fra
> > quelle a rischio sistemico (es: Unicredit) e quelle che no (es: Cassa
> > rurale di Cantù).
> >
> > Secondo questa riflessione, penso che debbano esserci delle
> > responsabilità ben definite, aldilà delle EULA, per i software vendor
> > che producono e distribuiscono software a rischio sistemico.
> >
> > Per rischio sistemico intendo una definizione, che può essere più o meno
> > articolata, di software diffusi su più dell'x% dei dispositivi in mano a
> > cittadini ed aziende (es: =>5% dei dispositivi?) .
> >
> > Per un software che è così ampiamente diffuso, avrebbe senso introdurre
> > dei criteri di responsabilità civile laddove vi siano delle falle di
> > sicurezza e come sia possibile risolvere queste falle (vedi:
> > impossibilità di aggiornare iPhone4 per il risolvere problemi di
> > sicurezza ad esempio).
> >
> > Ma questo lo dovrebbe fare "il legislatore"(c).
> >
> > Che ne dis?
> >
>
> se il kernel GNU/Linux fosse a rischio sistemico, sarebbe giusto
> rinegoziare tutto?(ed anche praticabile?)
> abbiamo bisogno di freak controllare la responsabilita di gnu.org per il
> middle layer GNU?
> Se un appliance FreeNAS ci distrugge i dati per i soliti motivi
> entropici con chi ce la prendiamo con iXsystems o con la FreeBSD
> foundation o con Oracle (per lo ZFS)?
> Forse uno spartiacque del tipo: mission critical vs tutto il resto
> dove il distributore è chiamato in causa a garante della catena e
> risponde in solido
> buone pensate
> salut
> _______________________________________________
> nexa mailing list
> nexa(a)server-nexa.polito.it
> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
>
>
Dec. 2, 2016
3 Books to be Presented at IGF
by Luca Belli
Buongiorno a tutti,
Per chi fosse interessato e/o per chi fosse all'IGF la settimana prossima:
Dear all, (apologies for crossposting)
The UN Internet Governance Forum is starting next week and CTS/FGV will be promoting 3 books that might be of your interest:
* Terms of Service and Human Rights. The book has been developed in partnership with the Council of Europe. It analyses the compatibility of the terms of service of 50 of the most popular online platforms with international human rights standards. It also includes the Recommendations on Terms of Service and Human Rights,<http://www.intgovforum.org/cms/documents/igf-meeting/igf-2016/830-dcpr-2015…> one of the IGF 2015 outcomes, developed by the IGF Dynamic Coalition on Platform Responsibility<https://igf2016.sched.org/event/8huv/dc-on-platform-responsibility>, last year.
* Net Neutrality Reloaded. Zero Rating, Specialised Services, Ad Bloking and Traffic Management. The book explores the most recent net neutrality trands. 7 out of 10 chapters are dedicated to the various aspects of zero rating practices, a very prominent issue, particularly in developing counties. The book is the annual outcome of the IGF Dynamic Coalition on Net Neutrality<https://igf2016.sched.org/event/8htg/dc-on-net-neutrality>.
* Community Connectivity. Building the Internet from Scratch. The book explores alternative models to expand connectivity in a sustainable fashion. The first part focus on community networks' governance while the second one analyses a series of case studies. Together with the Declaration on Community Connectivity<http://www.intgovforum.org/multilingual/index.php?q=filedepot_download/3737…>, the book is the annual outcome of the IGF Dynamic Coalition on Community Connectivity.<https://igf2016.sched.org/event/8htn/dc-on-community-connectivity>
Below, you can find the book contents. Free hard copies of the books will be distributed at the IGF. Here is CTS/FGV schedule<https://igf2016.sched.org/ctsfgv>, should you be interested in joining us and have your copy of the books.
The Open Access versions will be released right after the IGF, under Creative Commons Licenses.
I would like to thank all those who participated in the development of the books (notably those who are in this mailing list) for their great contributions.
Please do not hesitate to circulate this email to any interested person.
Best regards,
Luca
-----------------------------------------------------------------------------------------------
Luca Belli, PhD
Senior Researcher, Center for Technology & Society, FGV Rio de Janeiro
Chercheur Associé, Centre de Droit Public Comparé, Université Paris 2
Head of Internet Governance @ FGV
internet-governance.fgv.br<http://internet-governance.fgv.br>
-----------------------------------------------------------------------------------------------
[cid:bb7069cc-37ec-4b5f-9c69-ab960eb819c5]
[cid:70a6cdc0-c721-46f7-b07a-a0ce2a6e31cb]
[cid:81e7d89e-debc-4796-b791-1aac4a66fa34]
Dec. 2, 2016
Re: [nexa] Attacco hacker a Telekom, così la botnet Mirai colpisce l'Internet delle cose
by A Dicorinto
Hai ragione Enrico, forse dove speigarlo meglio che quello era il
suggerimento dato dalle case produttrici e dalla Telekom per il caso in
oggetto e funziona con alcuni apparati, però nella frase precedente dicevo:
"La soluzione? ''Sarebbe opportuno progettare i firmware in modo da poter
consentire agli utenti di aggiornare il proprio software in maniera
trasparente e senza richiedere specifiche conoscenze tecniche'', spiega
Paganini. ''E alla luce di quanto accaduto in Germania il nostro CERT, con
gli ISP ed i principali vendor di router, dovrebbero censire i dispositivi
sul mercato e preoccuparsi di produrre eventuali aggiornamenti utili per
proteggerli''.
Insomma, l’urgenza adesso è mettere al sicuro tutti i dispositivi IoT e nel
frattempo fare una cosa che spesso funziona con ogni apparato informatico:
spegnere e riaccendere. Questa procedura automatizza l’aggiornamento dei
software che comandano molti dei dispositivi che teniamo in casa."
Qui invece ho elencato tutte le cose da fare e sono linkate con molta
evidenza
dentro l'articolo di cui stiamo palando
http://www.repubblica.it/tecnologia/sicurezza/2016/11/21/news/dieci_cose_da…
un salutone e grazie
Il giorno 1 dicembre 2016 12:35, Cosmo Carabellese <
carabellese.cosmo(a)gmail.com> ha scritto:
> Buon giorno, scusate se mi inserisco pur non essendo un tecnico né un
> professore ma un semplice curioso al quale piace apprendere, nella mia,
> ormai lunga vita lavorativa, ho osservato che spesso spegnendo e
> riaccendendo, macchine anche assai poco sofisticate, sistema certi grovigli
> che si erano verificati durante il loro uso, per cui questo reset (non so
> se sia il termine appropriato) fa sparire il problema anche in assenza di
> un aggiornamento del software.
> Cordiali saluti.
> Cosmo Carabellese - Milano.
>
>
> Il giorno 29 novembre 2016 16:39, Enrico Nardelli <
> nardelli(a)mat.uniroma2.it> ha scritto:
>
>>
>> Arturo
>>
>> il pezzo è certamente ben scritto e ben documentato, complimenti.
>>
>> Ho qualche perplessità sull'affermazione proprio in chiusura
>> dell'articolo:
>>
>> "nel frattempo fare una cosa che spesso funziona con ogni apparato
>> informatico: spegnere e riaccendere. Questa procedura automatizza
>> l’aggiornamento dei software che comandano molti dei dispositivi che
>> teniamo in casa."
>>
>> Non sono infatti proprio del tutto sicuro che questa procedura risolva i
>> problemi.
>>
>> Nella mia esperienza personale sui modem/router casalinghi, solo i
>> modelli più recenti (e configurati in questo modo) fanno questo
>> autoaggiornamento.
>>
>> Per gli smartphone (che sono comunque dispositivi molto sofisticati)
>> l'autoaggiornamento del software non mi pare sia di default.
>>
>> Per le "cose" a valore più basso e/o più vecchie potrebbe poi proprio non
>> esserci questa possibilità: che è una delle maggiori vulnerabilità
>> segnalate da Schneier nell'intervento circolato su questa lista qualche
>> tempo fa.
>>
>> Non è una critica, sia ben chiaro, perchè certamente la procedura
>> suggerita danni non ne fa.
>>
>> Non vorrei però che la procedura venisse letta dalla gente comune come
>> "LA" soluzione e si diffondesse quindi come una semplificazione che induce
>> le persone a pensare di essere sicure se la implementano.
>>
>> Ciao, Enrico
>>
>>
>>
>>
>> Il 29/11/2016 13:50, A Dicorinto ha scritto:
>>
>> Ciao-
>> ho ricostruito l'attacco ai 900mila router tedeschi. Alla fine del pezzo
>> c'è la proposta su come intervenire nell'immediato.
>> buona lettura
>>
>> http://www.repubblica.it/tecnologia/sicurezza/2016/11/29/
>> news/attacco_hacker_a_telekom_cosi_mirai_colpisce_l_internet
>> _delle_cose-153075288/
>>
>> --
>>
>> Arturo Di Corinto
>> www.dicorinto.it
>> --------------------------------->
>>
>> AVVERTENZE AI SENSI DEL D.Lgs. 196/2003 Le informazioni contenute in
>> questo messaggio di posta elettronica e/o nel/i file/s allegato/i sono da
>> considerarsi strettamente riservate. Il loro utilizzo è consentito
>> esclusivamente al destinatario del messaggio, per le finalità indicate nel
>> messaggio stesso. Qualora riceviate questo messaggio senza esserne il
>> destinatario, Vi preghiamo cortesemente di darcene notizia via e-mail e di
>> procedere alla distruzione del messaggio stesso, cancellandolo dal Vostro
>> sistema. Conservare il messaggio stesso, divulgarlo anche in parte,
>> distribuirlo ad altri soggetti, copiarlo, od utilizzarlo per finalità
>> diverse, costituisce comportamento contrario ai principi dettati dal D.Lgs.
>> 196/2003
>>
>>
>> _______________________________________________
>> nexa mailing listnexa@server-nexa.polito.ithttps://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
>>
>>
>> -- EN
>>
>> =====================================================================
>> Prof. Enrico Nardelli
>> Dipartimento di Matematica - Universita' di Roma "Tor Vergata"
>> Via della Ricerca Scientifica snc - 00133 Roma
>> tel: +39 06 7259.4204 <06%207259%204204> fax: +39 06 7259.4699 <06%207259%204699>
>> mobile: +39 335 590.2331 <335%20590%202331> e-mail: nardelli(a)mat.uniroma2.it
>> home page: http://www.mat.uniroma2.it/~nardelli
>> blog: http://www.ilfattoquotidiano.it/blog/enardelli/
>> =====================================================================
>> --
>>
>>
>> _______________________________________________
>> nexa mailing list
>> nexa(a)server-nexa.polito.it
>> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
>>
>>
>
--
Arturo Di Corinto
www.dicorinto.it
--------------------------------->
AVVERTENZE AI SENSI DEL D.Lgs. 196/2003 Le informazioni contenute in questo
messaggio di posta elettronica e/o nel/i file/s allegato/i sono da
considerarsi strettamente riservate. Il loro utilizzo è consentito
esclusivamente al destinatario del messaggio, per le finalità indicate nel
messaggio stesso. Qualora riceviate questo messaggio senza esserne il
destinatario, Vi preghiamo cortesemente di darcene notizia via e-mail e di
procedere alla distruzione del messaggio stesso, cancellandolo dal Vostro
sistema. Conservare il messaggio stesso, divulgarlo anche in parte,
distribuirlo ad altri soggetti, copiarlo, od utilizzarlo per finalità
diverse, costituisce comportamento contrario ai principi dettati dal D.Lgs.
196/2003
Dec. 2, 2016
Re: [nexa] WashPost: "Russian propaganda effort helped spread ‘fake news’ during election, experts say"
by J.C. DE MARTIN
Sempre sul criticatissimo articolo del WashPost che avevo postato
in lista.
juan carlos
*The 'Washington Post' 'Blacklist' Story Is Shameful and Disgusting*
/The capital's paper of record crashes legacy media on an iceberg/
By Matt Taibbi
Last week, a technology reporter for the Washington Post named Craig
Timberg ran an incredible story. It has no analog that I can think of in
modern times. Headlined "Russian propaganda effort helped spread 'fake
news' during election, experts say," the piece promotes the work of a
shadowy group that smears some 200 alternative news outlets as either
knowing or unwitting agents of a foreign power, including popular sites
like Truthdig and Naked Capitalism.
The thrust of Timberg's astonishingly lazy report is that a Russian
intelligence operation of some kind was behind the publication of a
"hurricane" of false news reports during the election season, in
particular stories harmful to Hillary Clinton. The piece referenced
those 200 websites as "routine peddlers of Russian propaganda."
The piece relied on what it claimed were "two teams of independent
researchers," but the citing of a report by the longtime anticommunist
Foreign Policy Research Institute was really window dressing.
The meat of the story relied on a report by unnamed analysts from a
single mysterious "organization" called PropOrNot – we don't know if
it's one person or, as it claims, over 30 – a "group" that seems to have
been in existence for just a few months.
[…]
Continua qui:
http://www.rollingstone.com/politics/features/washington-post-blacklist-sto…
On 25/11/16 15:18, J.C. DE MARTIN wrote:
> Dalla lista IP di David Farber.
>
> juan carlos
> *
> From: *Michael Robertson <mr(a)michaelrobertson.com
> <mailto:mr@michaelrobertson.com>>
> *Subject: **Re: [IP] Russian propaganda effort helped spread ‘fake
> news’ during election, experts say - The Washington Post*
> *Date: *November 25, 2016 at 8:55:36 AM EST
> *To: *David Farber <dave(a)farber.net <mailto:dave@farber.net>>
> *Cc: *ip <ip(a)listbox.com <mailto:ip@listbox.com>>
>
> The two examples they cite of fake news were actually not fake.
>
> 1) Hillary's health
> Due to citizen reporting we know that Hillary did have health issues.
> After public scrutiny, her campaign revised her condition first
> blaming allergies and layer pneumonia.
>
> 2) Paid anti Trump protesters
> We know from project veritas' undercover videos that operatives for
> the DNC paid mentally unstable people to disrupt Trump rallies and
> also people in Donald duck costumes.
> https://youtu.be/5IuJGHuIkzY
> https://youtu.be/EEQvsK5w-jY
> Parties in the videos either resigned or were fired after the videos
> were made public.
>
> It's entirely possible the Russians placed fake stories online to try
> and influence the election. However this article does not stand up to
> scrutiny. For the two instances references there's publicly available
> evidence that it's not fake.
>
>
>
> On 25/11/16 07:00, J.C. DE MARTIN wrote:
>> *Russian propaganda effort helped spread ‘fake news’ during election,
>> experts say*
>>
>> By Craig Timberg
>>
>> November 24 at 8:27 PM
>>
>> The flood of “fake news” this election season got support from a
>> sophisticated Russian propaganda campaign that created and spread
>> misleading articles online with the goal of punishing Democrat
>> Hillary Clinton, helping Republican Donald Trump and undermining
>> faith in American democracy, say independent researchers who tracked
>> the operation.
>>
>> Russia’s increasingly sophisticated propaganda machinery — including
>> thousands of botnets, teams of paid human “trolls,” and networks of
>> websites and social-media accounts — echoed and amplified right-wing
>> sites across the Internet as they portrayed Clinton as a criminal
>> hiding potentially fatal health problems and preparing to hand
>> control of the nation to a shadowy cabal of global financiers. The
>> effort also sought to heighten the appearance of international
>> tensions and promote fear of looming hostilities with nuclear-armed
>> Russia.
>>
>> Two teams of independent researchers found that the Russians
>> exploited American-made technology platforms to attack U.S. democracy
>> at a particularly vulnerable moment, as an insurgent candidate
>> harnessed a wide range of grievances to claim the White House. The
>> sophistication of the Russian tactics may complicate efforts by
>> Facebook and Google to crack down on “fake news,” as they have vowed
>> to do after widespread complaints about the problem.
>>
>> […]
>>
>> Continua qui:
>> https://www.washingtonpost.com/business/economy/russian-propaganda-effort-h…
>>
>>
>>
>> _______________________________________________
>> nexa mailing list
>> nexa(a)server-nexa.polito.it
>> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
>
>
>
> _______________________________________________
> nexa mailing list
> nexa(a)server-nexa.polito.it
> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
Dec. 1, 2016
Re: [nexa] Attacco hacker a Telekom, così la botnet Mirai colpisce l'Internet delle cose
by Cosmo Carabellese
Buon giorno, scusate se mi inserisco pur non essendo un tecnico né un
professore ma un semplice curioso al quale piace apprendere, nella mia,
ormai lunga vita lavorativa, ho osservato che spesso spegnendo e
riaccendendo, macchine anche assai poco sofisticate, sistema certi grovigli
che si erano verificati durante il loro uso, per cui questo reset (non so
se sia il termine appropriato) fa sparire il problema anche in assenza di
un aggiornamento del software.
Cordiali saluti.
Cosmo Carabellese - Milano.
Il giorno 29 novembre 2016 16:39, Enrico Nardelli <nardelli(a)mat.uniroma2.it>
ha scritto:
>
> Arturo
>
> il pezzo è certamente ben scritto e ben documentato, complimenti.
>
> Ho qualche perplessità sull'affermazione proprio in chiusura dell'articolo:
>
> "nel frattempo fare una cosa che spesso funziona con ogni apparato
> informatico: spegnere e riaccendere. Questa procedura automatizza
> l’aggiornamento dei software che comandano molti dei dispositivi che
> teniamo in casa."
>
> Non sono infatti proprio del tutto sicuro che questa procedura risolva i
> problemi.
>
> Nella mia esperienza personale sui modem/router casalinghi, solo i modelli
> più recenti (e configurati in questo modo) fanno questo autoaggiornamento.
>
> Per gli smartphone (che sono comunque dispositivi molto sofisticati)
> l'autoaggiornamento del software non mi pare sia di default.
>
> Per le "cose" a valore più basso e/o più vecchie potrebbe poi proprio non
> esserci questa possibilità: che è una delle maggiori vulnerabilità
> segnalate da Schneier nell'intervento circolato su questa lista qualche
> tempo fa.
>
> Non è una critica, sia ben chiaro, perchè certamente la procedura
> suggerita danni non ne fa.
>
> Non vorrei però che la procedura venisse letta dalla gente comune come
> "LA" soluzione e si diffondesse quindi come una semplificazione che induce
> le persone a pensare di essere sicure se la implementano.
>
> Ciao, Enrico
>
>
>
>
> Il 29/11/2016 13:50, A Dicorinto ha scritto:
>
> Ciao-
> ho ricostruito l'attacco ai 900mila router tedeschi. Alla fine del pezzo
> c'è la proposta su come intervenire nell'immediato.
> buona lettura
>
> http://www.repubblica.it/tecnologia/sicurezza/2016/11/
> 29/news/attacco_hacker_a_telekom_cosi_mirai_colpisce_l_
> internet_delle_cose-153075288/
>
> --
>
> Arturo Di Corinto
> www.dicorinto.it
> --------------------------------->
>
> AVVERTENZE AI SENSI DEL D.Lgs. 196/2003 Le informazioni contenute in
> questo messaggio di posta elettronica e/o nel/i file/s allegato/i sono da
> considerarsi strettamente riservate. Il loro utilizzo è consentito
> esclusivamente al destinatario del messaggio, per le finalità indicate nel
> messaggio stesso. Qualora riceviate questo messaggio senza esserne il
> destinatario, Vi preghiamo cortesemente di darcene notizia via e-mail e di
> procedere alla distruzione del messaggio stesso, cancellandolo dal Vostro
> sistema. Conservare il messaggio stesso, divulgarlo anche in parte,
> distribuirlo ad altri soggetti, copiarlo, od utilizzarlo per finalità
> diverse, costituisce comportamento contrario ai principi dettati dal D.Lgs.
> 196/2003
>
>
> _______________________________________________
> nexa mailing listnexa@server-nexa.polito.ithttps://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
>
>
> -- EN
>
> =====================================================================
> Prof. Enrico Nardelli
> Dipartimento di Matematica - Universita' di Roma "Tor Vergata"
> Via della Ricerca Scientifica snc - 00133 Roma
> tel: +39 06 7259.4204 <06%207259%204204> fax: +39 06 7259.4699 <06%207259%204699>
> mobile: +39 335 590.2331 <335%20590%202331> e-mail: nardelli(a)mat.uniroma2.it
> home page: http://www.mat.uniroma2.it/~nardelli
> blog: http://www.ilfattoquotidiano.it/blog/enardelli/
> =====================================================================
> --
>
>
> _______________________________________________
> nexa mailing list
> nexa(a)server-nexa.polito.it
> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
>
>
Dec. 1, 2016