nexa
By thread
nexa@server-nexa.polito.it
By month
Messages by month
- ----- 2026 -----
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
March 2021
- 59 participants
- 385 messages
Re: [nexa] Reuters/ANSA: Millions of websites offline after fire at French cloud services firm
by Diego Giorio
Interessante, ma, chissà perchè, non sono sorpreso: in passato mi sono occupato della produzione di diodi di potenza, alcuni dei quali usati appunto negli UPS, e nel laboratorio di failure analysis ho visto diversi server distrutti proprio dall'UPS che doveva proteggerli. Fin quando si parla di un rack con uno - due macchine è un conto, quando c'è un intero datacenter è un altro, come si è visto. Mi sembra di ricordare un data center Microsoft, ma sono passati diversi anni e non ricordo se fosse operativo o solo un progetto, situato in un parco, dove quindi i container erano fisicamente sparpagliati sul territorio e la distruzione di un blocco non si sarebbe potuta estendere agli altri. Soluzione funzionale e apprezzata dalla popolazione, che può godere di un'area verde, ma certo costosa e non realizzabile ovunque. Inoltre allora i data center erano decisamente più piccoli.
Buona giornata e buon fine settimana a tutti.
D.
________________________________
From: nexa <nexa-bounces(a)server-nexa.polito.it> on behalf of Andrea Pellegrini <liste(a)andreapellegrini.net>
Sent: Thursday, March 11, 2021 9:58 PM
To: Nexa <nexa(a)server-nexa.polito.it>
Subject: Re: [nexa] Reuters/ANSA: Millions of websites offline after fire at French cloud services firm
Ciao a tutti,
Riporto qui alcuni dei passaggi del videomessaggio di Octave Klaba<https://www.ovh.com/fr/images/sbg/index-en.html> pubblicato nel pomeriggio:
Il sito colpito, SBG2 è stato costruito nel 2011, è stato progettato con un modello "a torre” che per il sistema di raffreddamento sfrutta la differenza di pressione dell’aria tra la parte alta e la parte bassa. OVH ha 4 datacenter di questa generazione, le strutture più recenti sono costruite in modo differente e probabilmente sono più sicure. Kalba porta l’esempio di SBG3 che pur essendo abbastanza vicino non è stato colpito in modo così rilevante dall’incendio.
Le cause dell’incendio, per quanto ancora in fase di studio, sono probabilmente da ricondurre a malfunzionamenti in alcuni UPS (gruppi di continuità). Le immagini rilevate dalle videocamere termiche dei vigili del fuoco, accorsi poco dopo l’allarme, hanno mostrato alte temperature in corrispondenza degli UPS 7 e 8. In queste ore verranno analizzate anche le immagini delle molte telecamere a circuito chiuso.
Il CEO di OVH fa notare che proprio l'UPS 7 abbia subito degli interventi di manutenzione la mattina del 9 marzo (martedì) e che il gruppo non ha mostrato problemi nel pomeriggio.
Circa a mezzanotte e mezza all’interno di SBG2 si è cominciato a diffondere molto fumo, in seguito a questo gli operatori presenti sul posto sono evacuati.
I datacenter non colpiti dall’incendio verranno ripristinati nelle prossime settimane e ai clienti direttamente colpiti verranno offerte nuove soluzioni in altri siti. Per soddisfare queste necessità nelle prossime settimane verrà triplicata la produzione di server, fino a 10000 macchine, in diverse configurazioni (anche se fa notare come probabilmente non saranno disponibili tutte le normali personalizzazioni).
Concludendo Kalba ammette che sarà necessario modificare la configurazione degli altri datacenter dello stesso tipo.
Ciao Ciao
Andrea Pellegrini
346 705 0039<tel:+393467050039>
Via Superga, 5
Pino Torinese (TO) Italy
pelle(a)andreapellegrini.net<mailto:pelle@andreapellegrini.net>
andreapellegrini.net<https://andreapellegrini.net>
On 11 Mar 2021, at 13:20, D. Davide Lamanna <davide.lamanna(a)binarioetico.it<mailto:davide.lamanna@binarioetico.it>> wrote:
On 11/03/21 12:38, Roberto Reale wrote:
Buongiorno a tutti,
una mia breve nota sul
tema: https://medium.com/reale/lincendio-al-datacenter-ovh-perche-ci-riguarda-b86…
<https://medium.com/reale/lincendio-al-datacenter-ovh-perche-ci-riguarda-b86…>.
+1
Sintetica e dritta al punto, grazie mille!
Aggiungo un commento veloce. Ho sempre avuto una buona reputazione di
OVH, per come lavorano e per i prezzi che fanno. Ecco i prezzi: secondo
me sono un po' troppo bassi. E' vero che hanno come target le piccole
realtà per cui ti devi tenere basso, però in casi come questi pensi
quanto ne valga la pena...
Ciao,
D.
_______________________________________________
nexa mailing list
nexa(a)server-nexa.polito.it<mailto:nexa@server-nexa.polito.it>
https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
March 12, 2021
Re: [nexa] Reuters/ANSA: Millions of websites offline after fire at French cloud services firm
by Andrea Pellegrini
Ciao a tutti,
Riporto qui alcuni dei passaggi del videomessaggio di Octave Klaba <https://www.ovh.com/fr/images/sbg/index-en.html> pubblicato nel pomeriggio:
Il sito colpito, SBG2 è stato costruito nel 2011, è stato progettato con un modello "a torre” che per il sistema di raffreddamento sfrutta la differenza di pressione dell’aria tra la parte alta e la parte bassa. OVH ha 4 datacenter di questa generazione, le strutture più recenti sono costruite in modo differente e probabilmente sono più sicure. Kalba porta l’esempio di SBG3 che pur essendo abbastanza vicino non è stato colpito in modo così rilevante dall’incendio.
Le cause dell’incendio, per quanto ancora in fase di studio, sono probabilmente da ricondurre a malfunzionamenti in alcuni UPS (gruppi di continuità). Le immagini rilevate dalle videocamere termiche dei vigili del fuoco, accorsi poco dopo l’allarme, hanno mostrato alte temperature in corrispondenza degli UPS 7 e 8. In queste ore verranno analizzate anche le immagini delle molte telecamere a circuito chiuso.
Il CEO di OVH fa notare che proprio l'UPS 7 abbia subito degli interventi di manutenzione la mattina del 9 marzo (martedì) e che il gruppo non ha mostrato problemi nel pomeriggio.
Circa a mezzanotte e mezza all’interno di SBG2 si è cominciato a diffondere molto fumo, in seguito a questo gli operatori presenti sul posto sono evacuati.
I datacenter non colpiti dall’incendio verranno ripristinati nelle prossime settimane e ai clienti direttamente colpiti verranno offerte nuove soluzioni in altri siti. Per soddisfare queste necessità nelle prossime settimane verrà triplicata la produzione di server, fino a 10000 macchine, in diverse configurazioni (anche se fa notare come probabilmente non saranno disponibili tutte le normali personalizzazioni).
Concludendo Kalba ammette che sarà necessario modificare la configurazione degli altri datacenter dello stesso tipo.
Ciao Ciao
Andrea Pellegrini
346 705 0039 <tel:+393467050039>
Via Superga, 5
Pino Torinese (TO) Italy
pelle(a)andreapellegrini.net <mailto:pelle@andreapellegrini.net>
andreapellegrini.net <https://andreapellegrini.net/>
> On 11 Mar 2021, at 13:20, D. Davide Lamanna <davide.lamanna(a)binarioetico.it> wrote:
>
> On 11/03/21 12:38, Roberto Reale wrote:
>> Buongiorno a tutti,
>>
>> una mia breve nota sul
>> tema: https://medium.com/reale/lincendio-al-datacenter-ovh-perche-ci-riguarda-b86…
>> <https://medium.com/reale/lincendio-al-datacenter-ovh-perche-ci-riguarda-b86…>.
>
>
> +1
>
> Sintetica e dritta al punto, grazie mille!
>
> Aggiungo un commento veloce. Ho sempre avuto una buona reputazione di
> OVH, per come lavorano e per i prezzi che fanno. Ecco i prezzi: secondo
> me sono un po' troppo bassi. E' vero che hanno come target le piccole
> realtà per cui ti devi tenere basso, però in casi come questi pensi
> quanto ne valga la pena...
>
>
> Ciao,
> D.
> _______________________________________________
> nexa mailing list
> nexa(a)server-nexa.polito.it
> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
March 11, 2021
EU-Brazil Conference on Digital Economy and Innovation
by Luca Belli
Condivido l'invito qui di seguito nel caso potesse interessare
L'evento incomincerà domani alle 14 ora italiana
Buona serata
________________________________
De : Luca Belli <luca.belli(a)fgv.br>
Envoyé : jeudi 11 mars 2021 22:40
À : Luca Belli <lucabelli(a)hotmail.it>
Objet : EU-Brazil Conference on Digital Economy and Innovation
Dear colleagues,
This Friday, 12 March, FGV, the EU Delegation to Brazil, the Portuguese Presidency of the Council of the EU, and EUBrasil will host the First EU-Brazil Conference on Digital Economy and Innovation https://portal.fgv.br/eventos/webinar-first-eu-brazil-conference-digital-ec…<https://emea01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fportal.f…>
Below you can find the agenda and the event’s flyer, and here is the link to register https://evento.fgv.br/digitaeconomyandinnovation/<https://emea01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fevento.f…>
I hope this message will be useful. Please feel free to share this email through your networks!
All the best
Luca
First EU-Brazil Conference on Digital Economy and Innovation
New Perspectives on Emerging Technologies, Trade and Regulation
12 March 2021, from 10:00 to 12:30 (Brasilia, GMT-3) / 14:00 to 16:30 (Brussels, GMT+1)
At the time of the Portuguese Presidency of the Council of the EU, this webinar aims at identifying areas for cooperation between the EU and Brazil, regarding digital economy and emerging technologies. Participants will explore key issues such as new digital infrastructures, 5G, cybersecurity, personal data protection, data-driven technologies, the Internet of Things and its applications, and Artificial Intelligence. Speakers and participants will offer their perspectives on these issues and will explore areas where trade and cooperation can be strengthened in the short and medium term.
Welcome and Introductory Remarks
Goret Pereira Paulo, Directress, FGV Office of Research and Innovation
Thibaut Kleiner, Director of Strategy and Outreach, DG Connect, European Commission
Luigi Gambardella, President EUBrasil
Luca Belli, Professor FGV Law School
A new agenda for innovation and digital cooperation between Europe and Brazil
Patrícia Ellen, Secretária de Desenvolvimento Econômico, Ciência e Tecnologia do Estado de São Paulo
Marcos Galvão, Ambassador of Brazil to the EU
Ignacio Ybanez, Ambassador of the EU to Brazil
Ricardo Castanheira, Digital & Technology Counselor, Permanent Representation of Portugal to the EU
Moderator: Luigi Gambardella, President EUBrasil
EU-Brazil: A Dialogue on Digital Trade, Emerging Technologies and Regulation
Carlos Oliveira, Minister Counselor for Digital Market, Delegation of the European Union to Brazil
José Manuel Fernandes, President EU Brazil Delegation of the European Parliament
Jorge Arbache, Vice President for Private Sector at the Development Bank of Latin America
Tais Maldonado Niffinegger, Directress of International Affairs, ANATEL
Andrea Renda, Senior Research Fellow and Head of Global Governance, Regulation, Innovation and the Digital Economy, CEPS
Luiz Moncau,Public Policy Manager, NuBank
Emily Rees, Senior Fellow, ECIPE & Director, Trade Strategies
Moderator: Luca Belli, Professor FGV Law School
Wrap-up and takeaways
Renato Flores, Director of FGV International Intelligence Unit and Professor at FGV Graduate School of Economics
[cid:604a89595f1ca]
[cid:a14b1d22-0b31-4da5-b2b9-2dd374766a22]
Luca Belli, PhD
Professor of Internet Governance and Regulation
[cid:37f50eb7-55c1-43fa-8cba-aa12906e05f4]+55 21 3799 5763 t@1lucabelli<https://emea01.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftwitter.…>
[cid:ce234a97-4255-4e6e-ab43-2f17664c9fce]Praia de Botafogo, 190 13º andar
Botafogo - Rio de Janeiro, RJ - CEP: 22250-900
[cid:4f5ca9a9-8f6c-4fa5-a5be-828b81c22b4b]luca.belli@fgv.br<mailto:luca.belli@fgv.br>
[cid:dc8d115e-71e6-4cfc-a1cb-b74ee422eb70]www.cyberBRICS.info<https://emea01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.cyber…> | www.CPDP.lat<https://emea01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.cpdp.…>
CONFIDENTIALITY NOTICE
This message, as well as any attached document, may contain personal data and information that is confidential and privileged and is intended only for the use of the addressee named above. If you are not the intended recipient, you are hereby notified that any disclosure, copying or distribution of this email or attached documents, or taking any action in reliance on the contents of this message or its attachments is strictly prohibited and may be unlawful. Please contact the sender if you believe you have received this email by mistake.
March 11, 2021
Verkada Workers Had Extensive Access to Private Customer Cameras
by Giacomo Tesio
Verkada was breached on Monday, when hackers gained access to what’s
known as a “Super Admin” account that allowed them to see all of the
live feeds and archived videos of Verkada’s customers, Bloomberg
reported. With access to 150,000 cameras, the hackers were able to see
inside Tesla Inc., as well as watch police interviews and witness
hospital employees tackling a patient.
The use of Super Admin accounts within Verkada was so widespread that
it extended even to sales staff and interns, two of the employees said.
“We literally had 20-year-old interns that had access to over 100,000
cameras and could view all of their feeds globally,” said one former
senior-level employee, who asked not to be identified discussing
private information. [...]
This week’s breach of the company was carried out by an international
hacker collective based in Europe. Tillie Kottmann, one of the hackers
who claimed credit for the incident, said they wanted to show the
pervasiveness of video surveillance and the ease with which those
systems could expose users’ confidential spaces. [...]
“Nobody cared about checking the logs,” the person said. “You could put
whatever you wanted in that note; you could even just enter a single
space.”
Verkada also offers a “privacy mode” to customers, allowing cameras to
be hidden from Verkada employees, according to a former employee. But
Super Admin accounts would allow employees to turn off that feature,
allowing them to see the camera footage, the former employee said.
https://www.bloomberg.com/news/articles/2021-03-11/verkada-workers-had-exte…
Domande per i giuristi in lista: immaginiamo un'azienda, un comune o
una scuola italiana che sia cliente di Verkada:
- Come risponde, il responsabile del trattamento (proprietario, sindaco,
preside...), del data breach?
- I data subject hanno diritto ad un risarcimento danni?
Giacomo
March 11, 2021
Europe’s Intelligence Services Aim to Avoid the EU’s Highest Court
by Giovanni Biscuolo
Buongiorno,
Schrems II ciao ciao!?!
https://www.lawfareblog.com/how-europes-intelligence-services-aim-avoid-eus…
--8<---------------cut here---------------start------------->8---
How Europe’s Intelligence Services Aim to Avoid the EU’s Highest
Court—and What It Means for the United States By Theodore Christakis,
Kenneth Propp Monday, March 8, 2021, 3:01 PM
[...] In the fall of 2020, the court softened that bitter pill when, for
the first time, it also imposed limits on EU member states’ intelligence
services’ own data collection and retention activities. But now the
member state governments have struck back against the Luxembourg-based
court, quietly slipping into their version of the EU’s ePrivacy
legislative reform proposal a provision that would put these contested
national security activities beyond the court’s reach. The
U.S. government is already [on record] as objecting to what it perceives
as a laxer data protection standard being applied by European courts to
their own national intelligence services. This latest move in Brussels
has only accentuated the sense of a disparity in treatment.
This post explores the ongoing struggle within the European Union to
delimit the national security exception in its data protection law for
the activities of member state intelligence services, and the
corresponding impact this Brussels debate could have on the ongoing
transatlantic negotiations to restore a secure basis for commercial data
transfers from the European Union to the United States.
[...] Conclusion
The Council of the European Union’s action in the ePrivacy saga has
revealed that many EU member states were so deeply uncomfortable with
the evolution of CJEU jurisprudence on surveillance, that they decided
to do something radical about it. They acted to interpose a broad
national security exception in the ePrivacy regulation because they saw
it as the only way to preserve freedom of action in the areas of data
collection and retention for their intelligence agencies.
France also recently has taken a unilateral [additional action] in order
to escape the data retention case law of the CJEU: It asked the
country’s highest administrative court—the Council of State—to ignore
the CJEU ruling in the LQDN case. French government lawyers contend that
the CJEU acted outside its scope (ultra vires) by usurping for the EU an
important “sovereign” competence—national security and protection of
public order—that member states had never transferred to it. In effect,
the French government’s concern about the CJEU’s intrusion into its
intelligence and law enforcement activities is so great that it has
asked its highest court to choose between an EU member state’s duty to
respect, as a matter of principle, the jurisprudence of the CJEU and its
own interpretation of its core constitutional prerogatives.
The United States, by contrast, can make no comparable Houdini-like
escape from the Schrems II judgment. EU law provides no national
security exemption that may be invoked on behalf of third-state
intelligence services. The United States, as well as other third
countries, will remain under the close scrutiny of the CJEU in
Schrems-like cases addressing their “adequacy” and “essential
equivalence.” Similarly, while national data protection authorities in
Europe have no basis in EU law to sanction a company responding to an EU
member state request for data on national security grounds, they will be
able to heavily fine companies transferring data to the United States,
on the basis that U.S. national security laws do not meet the Schrems II
and the European Data Protection Board’s restrictive surveillance
standards.
There can be little doubt that the NSA’s counterparts in European
capitals sympathize with its uncomfortable position. After all, these
European agencies richly benefit from U.S. intelligence in combating
terrorism and other national security threats, and would be loath to
lose such a valuable source. One also can presume that Washington is
encouraging EU member state governments to bring the same level of
appreciation of surveillance interests to the international negotiations
for a successor to the Privacy Shield that they brought to their own
Brussels deliberations on the ePrivacy regulation.
In both contexts, governments are weighing traditional national security
surveillance prerogatives against an increasing and insistent
“judicialization” of the fundamental right to data protection in all
settings. The situation is in flux both within the European Union and in
transatlantic relations. If there is an eventual balance that excludes
from the scrutiny of the CJEU the data retention laws and practices of
European national security services, but not those of their
U.S. counterpart, it might well be unstable. Whether and how U.S. and
European diplomats can deliver their governments from this unsustainable
situation remains to be seen.
[on record]
<https://www.privacyshield.gov/servlet/servlet.FileDownload?file=015t0000000…>
[additional action]
<https://www.politico.eu/article/france-data-retention-bypass-eu-top-court/>
--8<---------------cut here---------------end--------------->8---
Saluti, Giovanni
--
Giovanni Biscuolo
March 11, 2021
CISPE Code of Conduct Certification vs GDPR
by Giovanni Biscuolo
Buongiorno,
non mi pare di aver trovato notizie del CISPE in lista.
--8<---------------cut here---------------start------------->8---
CISPE (Cloud Infrastructure Services Providers in Europe) is a
non-profit trade association for infrastructure as a service (IaaS)
cloud providers in Europe. It was started to aid IaaS providers in
explaining their business model to policymakers.
[...] The association aims to advocate for an EU-wide cloud-first public
procurement policy and engage for a European Digital Single Market
including the promotion of high-level security and data protection
rules/standards as well as avoiding vendor lock-in.
In June 2020, the association became one the 22 founding members of
GAIA-X
--8<---------------cut here---------------end--------------->8---
CISPE promuove un registro pubblico https://cispe.cloud/publicregister/
di fornitori certificati (o autocertificati) con il loro... Codice di
Condotta... olè!
Guardando tra i fornitori **certificati** troviamo Amazon con diversi
servizi AWS dagli USA... e Tencent Cloud Computing dalla Cina.
Mumble mumble, ma davvero?!?
Nella pagina del codice di condotta https://cispe.cloud/code-of-conduct/
dicono:
--8<---------------cut here---------------start------------->8---
CISPE’s Code of Conduct for data protection anticipates the enforcement
of the European Union’s General Data Protection Regulation (GDPR). On
March 2017 the CISPE Code of Conduct was submitted for review and
approval by the European Data Protection Board (EDPB). This review is
currently underway by the EDPB.
--8<---------------cut here---------------end--------------->8---
Il Code of Conduct è del Marzo 2017, non riesco a trovare se EDPB ne
frattempo abbia commentato qualcosa.
Trovo però che CISPE sollecita EDPB:
--8<---------------cut here---------------start------------->8---
the adoption of a clear and simple approval procedure as well as greater
clarity over the timeline necessary to obtain such approval. CISPE
therefore asks the European Data Protection Board to facilitate
efficient coordination between Data Protection Authorities so that Codes
of Conduct will be approved under transparent and fixed timelines.
--8<---------------cut here---------------end--------------->8---
(tratto da
https://cispe.cloud/website_cispe/wp-content/uploads/2019/04/190402-CISPE-r…)
Io già intravedo l'implementazione del GDPR attraverso certificazioni a
fronte di Code of Conduct dove i fornitori se la cantano e se la suonano
:-O
Oppure il CISPE è un tentativo innocuo di annacquare il GDPR che non
trova sponde nella commissione e nel EDPB?
Saluti, Giovanni
--
Giovanni Biscuolo
March 11, 2021
Re: [nexa] Going from bad to worse: from Internet voting to blockchain voting
by Enrico Nardelli
Grazie Giacomo, è la versione su rivista di quanto anticipato a novembre scorso qua
https://www.csail.mit.edu/news/mit-experts-no-dont-use-blockchain-vote
Ciao, Enrico
Il 11/03/2021 15:37, Giacomo Tesio ha scritto:
> Voters are understandably concerned about election security.
> News reports of possible election interference by foreign powers, of
> unauthorized voting, of voter disenfranchisement, and of technological
> failures call into question the integrity of elections worldwide.
>
> This article examines the suggestions that “voting over the Internet” or
> “voting on the blockchain” would increase election security, and finds
> such claims to be wanting and misleading. While current election
> systems are far from perfect, Internet- and blockchain-based voting
> would greatly increase the risk of undetectable, nation-scale election
> failures. Online voting may seem appealing: voting from a computer or
> smartphone may seem convenient and accessible.
>
> However, studies have been inconclusive, showing that online voting may
> have little to no effect on turnout in practice, and it may even
> increase disenfranchisement. More importantly, given the current state
> of computer security, any turnout increase derived from Internet- or
> blockchain-based voting would come at the cost of losing meaningful
> assurance that votes have been counted as they were cast, and not
> undetectably altered or discarded. This state of affairs will continue
> as long as standard tactics such as malware, zero day, and
> denial-of-service attacks continue to be effective.
>
> This article analyzes and systematizes prior research on the security
> risks of online and electronic voting, and shows that not only do these
> risks persist in blockchain-based voting systems, but blockchains may
> introduce ‘additional’ problems for voting systems. Finally, we suggest
> questions for critically assessing security risks of new voting system
> proposals. [...]
>
> # Critical questions
>
> This section provides a list of worthwhile questions that should be
> asked about any future online or blockchain-based election system
> proposal in order to better understand its security implications,
> before considering its adoption for high-stakes elections. Much of this
> list is inspired by previous examples of failures in Internet voting
> schemes [15, 20, 54, 56, 100], questions asked by experts involving
> past blockchain-based systems [7], as well as the survey of open
> problems E2E-V systems by Bernhard et al. [101].
>
> This list is not intended to be comprehensive, as a short article like
> this cannot provide a complete guide to all of the issues that might be
> raised about “voting on the blockchain,” or electronic-only voting as a
> whole.
>
> First, the questions raised here relate to voting system security,
> rather than other important aspects of voting systems (e.g.,
> usability, cost, accessibility, etc.).
>
> Second, security cannot be achieved simply by “passing a checklist” —
> even given good answers to all of the questions here, a system could
> still be insecure. However, a good set of questions illuminates gaps in
> reasoning, poor assumptions, and implementation problems.
> We believe that satisfactory answers to these questions are a
> worthwhile demand: a valuable starting point to evaluate voting system
> proposals, and a basic level of transparency to which the public is
> entitled.
>
>
> Continua, proponendo alcune OTTIME domande, su
> https://academic.oup.com/cybersecurity/article/7/1/tyaa025/6137886
>
>
> Giacomo
> _______________________________________________
> nexa mailing list
> nexa(a)server-nexa.polito.it
> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
>
-- EN
=====================================================================
Prof. Enrico Nardelli
Dipartimento di Matematica - Universita' di Roma "Tor Vergata"
Via della Ricerca Scientifica snc - 00133 Roma
tel: +39 06 7259.4204 fax: +39 06 7259.4699
mobile: +39 335 590.2331 e-mail: nardelli(a)mat.uniroma2.it
home page: http://www.mat.uniroma2.it/~nardelli
blog: http://www.ilfattoquotidiano.it/blog/enardelli/
http://link-and-think.blogspot.it/
=====================================================================
--
March 11, 2021
Federal Reserve interbank payment system suffers outage
by Giovanni Biscuolo
Buongiorno,
curioso che alcune notizie di "disservizi digitali" passino quasi
inosservate mentre altre facciano molto rumore (a volte per nulla).
https://www.datacenterdynamics.com/en/news/federal-reserve-interbank-paymen…
--8<---------------cut here---------------start------------->8---
Federal Reserve interbank payment system suffers outage, disrupting
crucial piece of US economy Delaying hundreds of billions of dollars in
transactions
February 25, 2021 By Sebastian Moss
"Our technical teams have determined that the cause is a Federal Reserve
operational error," the Fed said in a statement. "We acknowledge that
payment deadlines are impacted and will communicate remediation efforts
to our customers when available. Thank you for your patience while we
work to resolve the issue.”
The glitch is not thought to be due to a cyber attack.
"Let's work together to ensure we have a faster, more reliable way to
send payments," Senator Cynthia Lummis said [on Twitter].
Following the September 11 attacks, the Federal Reserve has taken a more
active interest in maintaining the uptime of the financial system.
In 2003, it created an undisclosed list of the biggest and most
influential financial institutions, which it told to beef up their data
center redundancy.
The companies and organizations were told to ensure that primary and
backup facilities were on different grid and water systems, and followed
numerous other resiliency best practices.
In 2019, with much of the financial sector moving to the cloud - and in
particular, moving to one cloud vendor - [the Federal Reserve conducted
a formal examination of an Amazon Web Services data center] in Virginia.
The examination focused on Amazon’s resiliency and backup systems, and
is thought to be the first of several visits to cloud facilities.
A single outage, caused by software or hardware issues, can still
cripple key parts of the US economy.
In 2019, [a fire at a Wells Fargo data center] meant that customers
could not access ATMs, or their online and mobile banking accounts.
[on Twitter] <https://twitter.com/SenLummis/status/1364665835558760453>
[the Federal Reserve conducted a formal examination of an Amazon Web
Services data center]
<https://www.datacenterdynamics.com/en/news/us-federal-reserve-conducted-for…>
[a fire at a Wells Fargo data center]
<https://www.datacenterdynamics.com/en/news/widespread-wells-fargo-outage-bl…>
--8<---------------cut here---------------end--------------->8---
Anche su:
https://arstechnica.com/tech-policy/2021/02/fed-outage-shuts-down-us-paymen…
--8<---------------cut here---------------start------------->8---
The Fed urged banks to double-check that any transactions they submitted
in recent hours had actually gone through.
--8<---------------cut here---------------end--------------->8---
Saluti, Giovanni
--
Giovanni Biscuolo
March 11, 2021
Re: [nexa] infrastrutture e data center, prima o poi un disastro arriva?
by Giacomo Tesio
Ciao Giovanni,
credo ti sia accidentalmente scappato un punto di domanda in più
nell'oggetto di questo thread. ;-)
On Thu, 11 Mar 2021 15:07:02 +0100 Giovanni Biscuolo wrote:
> Se conoscete altri siti specializzato o altre storie analoghe le
> condividete per favore?
Giusto 10 anni fa, in Italia...
http://web.archive.org/web/20110817185816/http://www.i-dome.com/articolo/17…
Giacomo
March 11, 2021
Going from bad to worse: from Internet voting to blockchain voting
by Giacomo Tesio
Voters are understandably concerned about election security.
News reports of possible election interference by foreign powers, of
unauthorized voting, of voter disenfranchisement, and of technological
failures call into question the integrity of elections worldwide.
This article examines the suggestions that “voting over the Internet” or
“voting on the blockchain” would increase election security, and finds
such claims to be wanting and misleading. While current election
systems are far from perfect, Internet- and blockchain-based voting
would greatly increase the risk of undetectable, nation-scale election
failures. Online voting may seem appealing: voting from a computer or
smartphone may seem convenient and accessible.
However, studies have been inconclusive, showing that online voting may
have little to no effect on turnout in practice, and it may even
increase disenfranchisement. More importantly, given the current state
of computer security, any turnout increase derived from Internet- or
blockchain-based voting would come at the cost of losing meaningful
assurance that votes have been counted as they were cast, and not
undetectably altered or discarded. This state of affairs will continue
as long as standard tactics such as malware, zero day, and
denial-of-service attacks continue to be effective.
This article analyzes and systematizes prior research on the security
risks of online and electronic voting, and shows that not only do these
risks persist in blockchain-based voting systems, but blockchains may
introduce ‘additional’ problems for voting systems. Finally, we suggest
questions for critically assessing security risks of new voting system
proposals. [...]
# Critical questions
This section provides a list of worthwhile questions that should be
asked about any future online or blockchain-based election system
proposal in order to better understand its security implications,
before considering its adoption for high-stakes elections. Much of this
list is inspired by previous examples of failures in Internet voting
schemes [15, 20, 54, 56, 100], questions asked by experts involving
past blockchain-based systems [7], as well as the survey of open
problems E2E-V systems by Bernhard et al. [101].
This list is not intended to be comprehensive, as a short article like
this cannot provide a complete guide to all of the issues that might be
raised about “voting on the blockchain,” or electronic-only voting as a
whole.
First, the questions raised here relate to voting system security,
rather than other important aspects of voting systems (e.g.,
usability, cost, accessibility, etc.).
Second, security cannot be achieved simply by “passing a checklist” —
even given good answers to all of the questions here, a system could
still be insecure. However, a good set of questions illuminates gaps in
reasoning, poor assumptions, and implementation problems.
We believe that satisfactory answers to these questions are a
worthwhile demand: a valuable starting point to evaluate voting system
proposals, and a basic level of transparency to which the public is
entitled.
Continua, proponendo alcune OTTIME domande, su
https://academic.oup.com/cybersecurity/article/7/1/tyaa025/6137886
Giacomo
March 11, 2021