×
Encryption

VPN, Tor Use Increases in Iran After Internet 'Curfews' (cnbc.com) 22

Iran's government is trying to limit internet access, reports CNBC — while Iranians are trying a variety of technologies to bypass the blocks: Outages first started hitting Iran's telecommunications networks on September 19, according to data from internet monitoring companies Cloudflare and NetBlocks, and have been ongoing for the last two and a half weeks. Internet monitoring groups and digital rights activists say they're seeing "curfew-style" network disruptions every day, with access being throttled from around 4 p.m. local time until well into the night. Tehran blocked access to WhatsApp and Instagram, two of the last remaining uncensored social media services in Iran. Twitter, Facebook, YouTube and several other platforms have been banned for years.

As a result, Iranians have flocked to VPNs, services that encrypt and reroute their traffic to a remote server elsewhere in the world to conceal their online activity. This has allowed them to restore connections to restricted websites and apps. On September 22, a day after WhatsApp and Instagram were banned, demand for VPN services skyrocketed 2,164% compared to the 28 days prior, according to figures from Top10VPN, a VPN reviews and research site. By September 26, demand peaked at 3,082% above average, and it has continued to remain high since, at 1,991% above normal levels, Top10VPN said....

Mahsa Alimardani, a researcher at free speech campaign group Article 19, said a contact she's been communicating with in Iran showed his network failing to connect to Google, despite having installed a VPN. "This is new refined deep packet inspection technology that they've developed to make the network extremely unreliable," she said. Such technology allows internet service providers and governments to monitor and block data on a network. Authorities are being much more aggressive in seeking to thwart new VPN connections, she added....

VPNs aren't the only techniques citizens can use to circumvent internet censorship. Volunteers are setting up so-called Snowflake proxy servers, or "proxies," on their browsers to allow Iranians access to Tor — software that routes traffic through a "relay" network around the world to obfuscate their activity.

Crime

How 'MythBusters' Helped a Wrongly Convicted Man Prove His Innocence (innocenceproject.org) 127

"John Galvan was arrested at 18 and spent 35 years in prison for a crime he didn't commit," writes the Innocence Project, a nonprofit specializing in legal exoneration.

"In 2007, John Galvan was about 21 years into a life sentence for a crime he didn't commit when he saw something on the prison television he thought might finally help him prove his innocence and secure his freedom: A re-run of an episode of the Discovery Channel's MythBusters."

At the time of his arrest, they write, Galvan had been handcuffed to a wall for hours, physically beaten, and ultimately "agreed to give a confession that was completely fabricated by the detectives to end the abuse" — that Galvan had started a fire in an apartment building "by throwing a bottle filled with gasoline at the building and then tossing a cigarette into the pool of gasoline on the porch to ignite it." And then 21 years later... In his cell, a 39-year-old John watched as the hosts of MythBusters struggled repeatedly to ignite a pool of gasoline with a lit cigarette, despite fervent attempts. Based on the ignition temperature of gasoline and the temperature range of a lit cigarette, the show's hosts had initially hypothesized that a lit cigarette might be able to ignite spilled gasoline as they had seen on TV and in movies. But after several failed attempts to start a fire, including rolling a lit cigarette directly into a pool of gasoline, the team determined it was highly unlikely that dropping a cigarette into gasoline could cause a fire....

The show's findings were confirmed in 2007, by experiments conducted by the U.S. Bureau of Alcohol, Tobacco, Firearms, and Explosives (ATF), which made more than 2,000 attempts to ignite gasoline with a cigarette under various conditions. The bureau's experiments even included a vacuum that increased the cigarette's temperature to the level it would typically reach when being sucked and spraying a mist of gasoline directly onto the lit cigarette. All of the attempts failed. "Despite what you see in action movies, dropping a lit cigarette on to a trail of gasoline won't ignite it, assuming normal oxygen levels and no unusual circumstances," said Richard Tontarski, a forensic scientist and then chief of the ATF's fire research laboratory.

In 2017, when John finally had his evidentiary hearing on his post-conviction claims, [his attorney Tara] Thompson and his legal team presented multiple alibi witnesses, in addition to seven witnesses who testified to being tortured by the same officers who had coerced his confession, documents showing that police had fabricated probable cause to arrest him, and an arson expert who testified that John's false confession was scientifically impossible.... In 2019, the appellate court granted John post-conviction relief on the grounds of actual innocence — a rarity in Illinois — largely based on the abuse used to coerce a false confession from John.

The court concluded that without John's false confession, which he did not give voluntarily, "the State's case was nonexistent."

Thanks to long-time Slashdot reader Sleeping Kirby for sharing the story!
Earth

Are Single-Use Plastics Also Contributing to Climate Change? (cnn.com) 143

Made from fossil fuels refined with "extreme temperatures and significant amount of water and energy," plastics are also a climate problem, warns CNN. So "by the time we start talking about recycling, the damage is already done."

One former regional administrator for America's Environmental Protection Agency is now even calling plastics "the new coal." The process of making plastic is so energy intensive that if the plastics industry were a country, it would be the fifth largest emitter of greenhouse gases in the world, according to a 2021 report from Beyond Plastics.... The plastic industry is responsible for at least 232 million tons of planet-warming emissions each year, according to the Beyond Plastics report. That's the same amount as the average emissions released by 116 coal-fired power plants in 2020, according to the report's authors. It's also the same annual emissions as around 50 million cars, according to the EPA. And more plastic-making facilities continue to come online....

[P]lastic recycling doesn't work, Enck said, because most of what we think we're recycling just ends up in the landfill. It also doesn't address the planet-warming emissions that comes from making it in the first place....

Ultimately, the world needs large-scale change to address the climate impact of the fossil fuel and plastics industries, said Jacqueline Savitz [chief policy officer for the conservation non-profit Oceana]. Oceana, for example, is working with local volunteers from cities and counties around the country to help pass new laws to reduce single-use plastics, in hopes of sparking change at the national level. "We think that if we could start to reduce single-use plastics at the local level with local ordinances, that can start to become more of the norm," she said. "Then we can start taking it to higher levels of government, even getting to the point of getting national policies that will drive reductions in plastic use."

Ultimately, Savitz said consumers need to continue urging major corporations to provide plastic-free solutions and help support refill and reuse programs to encourage society to shy away from plastic use and stave off the worst impacts of the climate crisis. "Our country is burning and flooding and hurricanes are coming earlier and earlier," she told CNN. "I really think it's shocking that one of the things that's really leading to that is plastics, and it's hurting us in other ways, too. So if we could find a way to reduce our production of plastics as a country and as a global society, we'd be taking a bite out of climate change."

CNN suggests ways you can reduce your own plastic consumption, including:
  • Saying no to bottled water. "Get a couple of canteens and cut a major source of plastic out of your life."
  • Going beyond just reusable grocery bags. "You can easily go a step further by not using the plastic produce bags the store provides for your apples and broccoli..."
  • And when shopping, try to choose products packaged in paper over those packaged in plastic.

EU

French Court Slashes Apple Antitrust Fine in Blow to European Regulators (reuters.com) 28

"Apple won a massive reduction in a 1.1 billion euro ($1.1 billion) antitrust fine from French competition regulators," reports CNBC, "in a blow to the ambitions of European authorities to crack down on the dominance of Big Tech companies." The Paris appeals court on Thursday lowered the fine to 371.6 million euros, roughly a third of the value of the original penalty and a reduction of 728.4 million euros, an Apple spokesperson confirmed.According to Reuters, the amount was slashed because the court decided to drop one of the charges related to price fixing, and lower the rate originally used to calculate the fine....

In 2020, the French competition watchdog fined Apple 1.1 billion euros for allegedly pressuring premium resellers into fixing prices of non-iPhone products, such as its Mac and iPad computers, and abusing the economic dependence of its outside resellers. Tech Data and Ingram Micro, two global electronics wholesalers, were also fined 76.1 million euros and 62.9 million euros, respectively. The regulator accused Apple, Tech Data and Ingram Micro of agreeing not to compete and preventing independent resellers from competing with each other, "thereby sterilizing the wholesale market for Apple products."

Apple response, according to Reuters: "While the court correctly reversed part of the French Competition Authority's decision, we believe it should be overturned in full and plan to appeal.

"The decision relates to practices from more than a decade ago that even the (French authority) recognised are no longer in use."
Earth

Why Hurricane Ian Killed So Many People (cnn.com) 174

It was Florida's deadliest hurricane in 87 years, tied for the fifth-strongest hurricane to make landfall in the continental U.S. and killing more than 100 people after veering south into unexpected areas.

But a Rutgers University health psychologist suggests other factors might've made Hurricane Ian more deadly: Ian also underwent rapid intensification, perhaps influenced by climate change, which meant that its wind speeds increased dramatically as it passed over the warm waters of the Gulf of Mexico before landfall.

Emergency managers typically need at least 48 hours to successfully evacuate areas of southwest Florida. However, voluntary evacuation orders for Lee County were issued less than 48 hours prior to landfall, and for some areas were made mandatory just 24 hours before the storm came ashore. This was less than the amount of time outlined in Lee County's own emergency management plan.

While the lack of sufficient time to evacuate was cited by some as a reason why they stayed behind, there are other factors that may also have suppressed evacuations in some of the hardest hit areas. In order to correctly follow evacuation orders, people need to first know their evacuation zone. Research from other areas of the country indicates that many people don't. That's why the evacuation zone locator websites in the affected counties were crucial. However, so many people were checking their zones that some of these websites crashed in the days before the storm.

The article asks whether the early voluntary evacuation order "lulled some residents into being less concerned" and ultimately compounded problems. "In areas where evacuation orders were issued later, people who weren't expecting to evacuate needed to find and understand this evacuation zone information quickly...."

"People need to know that they are in an area being asked to evacuate — and waiting until the storm is on its way to find out their zone may be too late. Emergency managers need to educate people in advance of imminent storms while also developing more robust websites to handle the queries in the days before the storm."
The Courts

Papa John's Sued For 'Wiretap' Spying on Website Mouse Clicks, Keystrokes (theregister.com) 60

Papa John's is being sued by a customer -- not for its pizza but for allegedly breaking the US Wiretap Act by snooping on the way he browsed the pie-slinger's website. From a report: The titan of greasy wheels is accused of falling foul of wiretapping rules by using so-called session replay software on its website. This software records and phones home everything a user does on the site, beyond what fetching pages and placing an order would submit, we're told. For instance, it tells Papa John's where the mouse is moved and clicked, and what's typed into the page, it's claimed [PDF]. This info can be used to figure out where users get stuck, bail out of a sale, get lost, and so on. Session replay tools have been a privacy concern due to their indiscriminate capturing of data, sometimes poor security, and failures to get user consent to track and store this data, not to mention having analysts going over your every move to see how they can optimize their webpages and boost sales. On the other hand, you may not see it as that much of a concern given all the other material data a website might have on you -- such as name, email and home address, date of birth, orders placed, payment details, etc etc.
Facebook

Facebook Warns 1 Million Users Whose Logins Were Stolen By Scam Mobile Apps (theverge.com) 15

Meta is warning Facebook users about hundreds of apps on Apple and Google's app stores that were specifically designed to steal login credentials to the social network app. From a report: The company says it's identified over 400 malicious apps disguised as games, photo editors, and other utilities and that it's notifying users who "may have unknowingly self-compromised their accounts by downloading these apps and sharing their credentials." According to Bloomberg, a million users were potentially affected. In its post, Meta says that the apps tricked people into downloading them with fake reviews and promises of useful functionality (both common tactics for other scam apps that are trying to take your money rather than your login info). But upon opening some of the apps, users were prompted to log in with Facebook before they could actually do anything -- if they did, the developers were able to steal their credentials.
The Internet

Biden Order Brings New Transatlantic Data Pact Ever Closer (bloomberg.com) 22

The European Union and U.S. moved a step closer to securing the privacy of transatlantic data flows as President Joe Biden moved to end years of uncertainty and allow thousands of companies to legally move customer data across the Atlantic. From a report: Biden signed an executive order Friday that'll create an independent court system in the US for EU citizens who think their data was unlawfully accessed or used by intelligence agencies. Decisions by the Data Protection Review Court will be binding and force the likes of the CIA to limit data collection to the "pursuit of defined national security objectives," according to a White House fact sheet.

The EU Court of Justice in 2020 toppled the so-called Privacy Shield over concerns that user data wasn't safe from prying eyes once on US soil. The ruling meant thousands of businesses that ship commercial data to the U.S. had to figure out an alternative and EU-U.S. negotiators were forced back to the drawing table. The prospect of no accord led Meta Platforms to say it would may have no choice but to pull its Facebook and Instagram services from the EU. The order is designed to address concerns about the ability of American spies to access EU data, which led to two previous data transfer accords being struck down by the bloc's top court. The EU and US have been working on a new deal for months and in March reached a breakthrough with an agreement in principle. The order gives the European Commission a tool to "restore an important, accessible, and affordable" data transfer mechanism while also providing greater legal certainty for companies shipping data across the Atlantic, the White House said.

Security

Game Firm 2K Says Users Info Stolen (arstechnica.com) 2

Game company 2K has warned users to remain on the lookout for suspicious activity across their accounts following a breach last month that allowed a threat actor to obtain email addresses, names, and other sensitive information provided to 2K's support team. From a report: The breach occurred on September 19, when the threat actor illegally obtained system credentials belonging to a vendor 2K uses to run its help desk platform. 2K warned users a day later that the threat actor used unauthorized access to send some users emails that contained malicious links. The company warned users not to open any emails sent by its online support address or click on any links in them. If users already clicked on links, 2K urged them to change all passwords stored in their browsers. On Thursday, after an outside party completed a forensic investigation, 2K sent an unknown number of users an email warning them that the threat actor was able to obtain some of the personal information they supplied to help desk personnel.
China

China Upgrades Great Firewall To Defeat Censor-Beating TLS Tools (theregister.com) 20

Great Firewall Report (GFW), an organization that monitors and reports on China's censorship efforts, has this week posted a pair of assessments indicating a crackdown on TLS encryption-based tools used to evade the Firewall. The Register reports: The group's latest post opens with the observation that starting on October 3, "more than 100 users reported that at least one of their TLS-based censorship circumvention servers had been blocked. The TLS-based circumvention protocols that are reportedly blocked include trojan, Xray, V2Ray TLS+Websocket, VLESS, and gRPC." Trojan is a tool that promises it can leap over the Great Firewall using TLS encryption. Xray, V2ray and VLESS are VPN-like internet tunneling and privacy tools. It's unclear what the reference to gRPC describes -- but it is probably a reference to using the gRPC Remote Procedure Call (RPC) framework to authenticate client connections to VPN servers.

GFW's analysis of this incident is that "blocking is done by blocking the specific port that the circumvention services listen on. When the user changes the blocked port to a non-blocked port and keep using the circumvention tools, the entire IP addresses may get blocked." Interestingly, domain names used with these tools are not added to the Great Firewall's DNS or SNI blacklists, and blocking seems to be automatic and dynamic. "Based on the information collected above, we suspect, without empirical measurement yet, that the blocking is possibly related to the TLS fingerprints of those circumvention tools," the organization asserts. An alternative circumvention tool, naiveproxy, appears not to be impacted by these changes.
"It's not hard to guess why China might have chosen this moment to upgrade the Great Firewall: the 20th National Congress of the Chinese Communist Party kicks off next week," notes the Register. "The event is a five-yearly set piece at which Xi Jinping is set to be granted an unprecedented third five-year term as president of China."
Movies

Court Blocks 13,445 'Pirate' Sites Proactively To Protect One Movie (torrentfreak.com) 30

An anonymous reader quotes a report from TorrentFreak: A court in India has granted what appears to be the most aggressive site-blocking injunction in the history of copyright law. In advance of the movie 'Vikram Vedha' premiering in cinemas last Friday, a judge handed down an injunction that ordered 40 internet service providers to proactively and immediately block an unprecedented 13,445 sites. [...] India began blocking pirate sites in 2011 but the public had no idea it was coming. In an early case, movie company Reliance Entertainment went to court to protect the movie 'Singham' and came away with an order that compelled ISPs to temporarily block sites including Megaupload, Megavideo, Rapidshare, Putlocker, Hotfile and Fileserve. Having obtained one injunction, to the surprise of no one Reliance Entertainment immediately sought and obtained another. From there, the site-blocking train gathered steam and hasn't looked back. [...]

After obtaining certification for its new movie 'Vikram Vedha' last Monday, Reliance Entertainment filed an injunction application the next day. The goal was to protect the movie from online piracy following its premiere last Friday. Given that courts in other countries can take months over a decision, the Madras High Court needed to act quickly. On September 30, the day of the movie's release, the Court published its orders, noting that substantial sums had been invested in 'Vikram Vedha' and the movie was expected to screen in 3,000 cinemas worldwide. With words such as "imminent" and "threat" featured early on, it was already clear which way the judge was leaning. How far he was prepared to go still came as a surprise. After reading through the Reliance application, the judge declared that Reliance had made its case and that an injunction was appropriate. The judge said that if an interim injunction wasn't immediately granted, it would "result in alleged piracy being completed in all and every aspect of the matter." That would in turn lead to an "irreversible situation" and "irreparable legal injury incapable of compensation."

Due to the urgency, the respondents in the case – including 40 internet service providers -- weren't notified of the legal action. Nevertheless, the injunction was handed down via two separate orders, which together prohibit anyone from copying, recording, camcording, making available, uploading, downloading, exhibiting or playing the movie without a license. After specifically prohibiting copying to CD, DVD, pen drives, hard drives or tapes, the orders move on to the issue of ISP blocking. It appears that Reliance asked for a lot and the judge gave them everything. According to one of the orders, the websites put forward for blocking are all "non-compliant" operations, in that they have no reporting and take down mechanisms in place, at least according to Reliance. Interestingly, Reliance also informed the court that all of the websites were infringing its copyrights in respect of the movie 'Vikram Vedha', even though it was yet to be released and when the application was filed, no copies were available online. This means that Reliance couldn't have provided any infringing URLs even if it wanted to. Nevertheless, the judge did consider more limited blocking.

Ultimately, the judge granted an interim injunction and ordered all of the ISPs (list below) to immediately and proactively block a grand total of 13,445 websites. While the names of the websites were made available to the court, the court did not make the schedule available on the docket. As a result we have no way of confirming which domains are on the list. The ISPs weren't informed about the injunction application either, so presumably they're also in the dark. The idea that the judge tested all 13,445 domains seems wishful thinking at best. That leaves Reliance Entertainment as the sole entity with any knowledge of the submitted domains, all of which have been labeled in court as infringing the movie's copyright, even though no copy was available when the application was made.

Crime

Former Uber Exec Joe Sullivan Found Guilty of Concealing 2016 Data Breach (nytimes.com) 10

According to the New York Times, former chief security officer of Uber, Joe Sullivan, has been found guilty of hiding a 2016 data breach from authorities and obstructing an investigation by the FTC into the company's security practices. The breach affected more than 57 million Uber riders and drivers. From the report: Mr. Sullivan was deposed by the F.T.C. as it investigated a 2014 breach of Uber's online systems. Ten days after the deposition, he received an email from a hacker who claimed to have found another security vulnerability in its systems. Mr. Sullivan learned that the hacker and an accomplice had downloaded the personal data of about 600,000 Uber drivers and additional personal information associated with 57 million riders and drivers, according to court testimony and documents. The hackers pressured Uber to pay them at least $100,000. Mr. Sullivan's team referred them to Uber's bug bounty program, a way of paying "white hat" researchers to report security vulnerabilities. The program capped payouts at $10,000, according to court testimony and documents. Mr. Sullivan and his team paid the hackers $100,000 and had them sign a nondisclosure agreement.

During his testimony, one of the hackers, Vasile Mereacre, said he was trying to extort money from Uber. Uber did not publicly disclose the incident or inform the F.T.C. until a new chief executive, Dara Khosrowshahi, joined in the company in 2017. The two hackers pleaded guilty to the hack in October 2019. States typically require companies to disclose breaches if hackers download personal data and a certain number of users are affected. There is no federal law requiring companies or executives to reveal breaches to regulators. Federal prosecutors argued that Mr. Sullivan knew that revealing the new hack would extend the F.T.C. investigation and hurt his reputation and that he concealed the hack from the F.T.C. Mr. Sullivan did not reveal the 2016 hack to Uber's general counsel, according to court testimonies and documents. He did discuss the breach with another Uber lawyer, Craig Clark.

Mr. Sullivan did not reveal the 2016 hack to Uber's general counsel, according to court testimonies and documents. He did discuss the breach with another Uber lawyer, Craig Clark. Like Mr. Sullivan, Mr. Clark was fired by Mr. Khosrowshahi after the new Uber chief executive learned about the details of the breach. Mr. Clark was given immunity by federal prosecutors in exchange for testifying against Mr. Sullivan. Mr. Clark testified that Mr. Sullivan told the Uber security team that they needed to keep the breach secret and that Mr. Sullivan changed the nondisclosure agreement signed by the hackers to make it falsely seem that the hack was white-hat research. Mr. Sullivan said he would discuss the breach with Uber's "A Team" of top executives, according to Mr. Clark's testimony. He shared the matter with only one member of the A Team: then chief executive Travis Kalanick. Mr. Kalanick approved the $100,000 payment to the hackers, according to court documents.
The case is "believed to be the first time a company executive faced criminal prosecution over a hack," notes the report.

"The way responsibilities are divided up is going to be impacted by this. What's documented is going to be impacted by this The way bug bounty programs are designed is going to be impacted by this," said Chinmayi Sharma, a scholar in residence at the Robert Strauss Center for International Security and Law and a lecturer at the University of Texas at Austin School of Law.
The Almighty Buck

Fraud, Scam Cases Increasing on P2P Payment Service Zelle, Senate Report Finds (apnews.com) 54

Incidents of fraud and scams are occurring more often on the popular peer-to-peer payment service Zelle, according to a report issued Monday by the office of Sen. Elizabeth Warren, giving the public its first glimpse into the growing problems at Zelle. From a report: The report also found that the large banks that partly own Zelle have been reluctant to compensate customers who have been victims of fraud or scams. For instance, less than half of the money customers reported being sent via Zelle without authorization was being reimbursed. Warren, D-Massachusetts, a long-time critic of the big banks, requested data on fraud and scams on Zelle from seven banks starting in April. The report cites data from four banks that tallied 192,878 cases worth collectively $213.8 million in 2021 and the first half of 2022 where a customer claimed they had been fraudulently tricked into making a payment. In only roughly 3,500 cases did those banks reimburse the customer, the report found.

Further, in the cases where it's clear funds had been taken out of customers' accounts without authorization, only 47% of those dollars were ever reimbursed. Since being launched in June 2017, Zelle has become a popular way for bank customers to send money to friends and family. Almost $500 billion in funds were sent via Zelle in 2021, according to Early Warning Services, the company that operates Zelle. Zelle is the banking industry's answer to the growing popularity of peer-to-peer payment services like PayPal, Venmo and the Cash App. The service allows a bank customer to instantaneously send money to a person via their email or phone number, and it will go from one bank account to another. More than 1,700 banks and credit unions offer the service. But the service has also grown more popular with scammers and criminals. Once money is sent via Zelle, it requires a bank's intervention to attempt to get that money back.

Google

Google To Pay $85 Million To End Arizona Consumer-Privacy Suit (bloomberg.com) 8

An anonymous reader quotes a report from Bloomberg: Alphabet's Google will pay $85 million to resolve a consumer privacy suit by Arizona claiming the technology giant surreptitiously collects data on users' whereabouts for targeted advertising. The settlement comes as Google is facing similar complaints by a group of state attorneys general, including Texas, Indiana and Washington D.C., in their respective state courts, over user location data. Arizona accused Google in a May 2020 complaint of violating the state's Consumer Fraud Act by gathering location data even after users opt out of a feature that records location history through other settings such as "Web & App Activity." Google, in its defense, had argued that the state consumer protection law requires that alleged fraud is connected to a sale or advertisement. In January, an Arizona state judge denied Google's request to dismiss the case. The settlement represents the largest amount per individual user Google has paid in "a privacy and consumer-fraud lawsuit of this kind," Attorney General Mark Brnovich's office said in a statement on Tuesday. "I am proud of this historic settlement that proves no entity, not even big tech companies, is above the law."

Meanwhile, a Google spokesperson said Arizona's suit was based on old product policies that the company changed years ago. "We provide straightforward controls and auto delete options for location data, and are always working to minimize the data we collect," they said. "We are pleased to have this matter resolved and will continue to focus our attention on providing useful products for our users."
Google

Rightsholders Asked Google To Remove Six Billion 'Pirate' Links (torrentfreak.com) 48

An anonymous reader quotes a report from TorrentFreak: Over the past decade, rightsholders have asked [Google] to remove six billion links to alleged copyright-infringing content. The majority of these requests were indeed removed or put on a preemptive blacklist. The six billion links were reported by 326,575 copyright holders who identified 4,041,845 separate domain names. These domains also include many false positives, including websites of The White House, the FBI, Disney, Netflix, the New York Times, and even TorrentFreak. Overall, we can say that a relatively small number of rightsholders are responsible for a disproportionate number of takedown requests. The ten most active senders reported nearly 2.5 billion URLs, more than 40% of the total. Similarly, as we previously highlighted, most of the removed URLs belong to a small group of websites. Just 400 domains are responsible for 41% of all links removed by Google over the years.

Google continues to remove more than a million URLs per day but the trend started to change a few years ago. The frequency at which new links were reported started to decline. At the same time, Google started to cooperate more with rightsholders. For example, Google began to accept takedown notices for links that are not indexed by the search engine yet. These links, which are also counted in the six billion figure, are put on a preemptive blocklist. That prevents the links from being added to search results in the future. Google also actively demotes pirate sites in its search results when it receives an unusually high number of takedown requests for a domain. In addition, the search engine chose to voluntarily comply with third-party site-blocking orders by removing entire domain names from its index. These proactive anti-piracy measures have started to improve the relationship between Google and rightsholders. And it wouldn't be a surprise to see this trend continue going forward.

The Courts

'The Onion' Files a Supreme Court Brief (nytimes.com) 75

An anonymous reader quotes a report from the New York Times: A man who was arrested over a Facebook parody aimed at his local police department is trying to take his case to the Supreme Court. He has sought help from an unlikely source, which filed a friend-of-the-court brief on Monday. "Americans can be put in jail for poking fun at the government?" the brief asked. "This was a surprise to America's Finest News Source and an uncomfortable learning experience for its editorial team." The source is, of course, The Onion. Or, as the satirical website described itselfin the brief (PDF),"the single most powerful and influential organization in human history."

The Parma, Ohio, area man in question, Anthony Novak, spent four days in jail over a Facebook page he created in 2016 that mocked his local police department. He was charged with using a computer to disrupt police functions, but a jury found him not guilty. Mr. Novak says his civil rights were violated, and he is trying to sue the city for damages. A federal judge dismissed the lawsuit earlier this year, saying that the police had qualified immunity, and an appeals court upheld that decision. Now the high court is reviewing his request to take up the matter. One of Mr. Novak's lawyers, Patrick Jaicomo, said in an interview Monday that last month he contacted Jordan LaFlure, the managing editor of The Onion, which is based in Chicago, to make him aware of the case and see if he would be interested in helping raise attention. "They heard the story, and they were like, 'Oh my god, this is something that could really put all of our people in the crosshairs if we rub someone the wrong way with one of our stories,'" Mr. Jaicomo said. [...]

On Tuesday, a lawyer representing Parma, Richard Rezie, said that the courts had dismissed Mr. Novak's lawsuit as groundless and agreed that his rights had not been violated. The judges "did not base their opinions on parody, freedom of speech, or the need for a disclaimer," Mr. Rezie said, adding that Mr. Novak "went beyond mimicry" when he reproduced a police warning about his fake page, but claimed that the Parma site was the fake and his was the "official" page. "Falsely copying an official warning along with a claim to be the authentic Facebook page is not parody," Mr. Rezie said, adding that Mr. Novak also deleted comments from readers who realized his page was fake. In Mr. Jaicomo's view, The Onion's brief used parody itself to make the point that parody is important and protected speech.
"The Onion cannot stand idly by in the face of a ruling that threatens to disembowel a form of rhetoric that has existed for millennia, that is particularly potent in the realm of political debate, and that, purely incidentally, forms the basis of The Onion's writers' paychecks," the brief said. It pointed to The Onion's history of blatantly ridiculous headlines: "Fall Canceled After 3 Billion Seasons." "Children, Creepy Middle-Aged Weirdos Swept Up in Harry Potter Craze." "Kitten Thinks of Nothing but Murder All Day." A footnote reads "See Mar-a-Lago Assistant Manager Wondering if Anyone Coming to Collect Nuclear Briefcase from Lost and Found, The Onion, Mar. 27, 2017."

The brief also said that the case posed a threat to The Onion's business model. "This was only the latest occasion on which the absurdity of actual events managed to eclipse what The Onion's staff could make up," it said. "Much more of this, and the front page of The Onion would be indistinguishable from The New York Times."
Censorship

VLC-Developer VideoLAN Sends Legal Notice To Indian Ministries Over Ban (techcrunch.com) 12

VideoLAN, the developer and operator of popular media player VLC, has filed a legal notice to India's IT and Telecom ministries, alleging that the Indian bodies failed to notify the software developer prior to blocking the website and did not afford it a chance for an explanation. From a report: Indian telecom operators have been blocking VideoLAN's website, where it lists links to downloading VLC, since February of this year, VideoLan president and lead developer Jean-Baptiste Kempf told TechCrunch in an earlier interview. India is one of the largest markets for VLC. "Most major ISPs [internet service providers] are banning the site, with diverse techniques," he said of the blocking in India. The telecom operators began blocking the VideoLan website on February 13 of this year, when the site saw a drop of 80% in traffic from the South Asian market, he said. Now, VideoLAN, in assistance with local advocacy group Internet Freedom Foundation, is using legal means to get answers and redressal. It has sought a copy of the blocking order for banning VideoLAN website in India and an opportunity to defend the case through a virtual hearing. In the notice, VideoLAN argues that the way Indian ministries have enforced the ban on the website, they violate their own local laws.
The Courts

Apple Loses Second Bid To Challenge Qualcomm Patents At US Supreme Court (reuters.com) 22

The U.S. Supreme Court on Monday again declined to hear Apple's bid to revive an effort to cancel three Qualcomm smartphone patents despite the settlement of the underlying dispute between the two tech giants. Reuters reports: The justices left in place a lower court's decision against Apple after similarly turning away in June the company's appeal of a lower court ruling in a closely related case challenging two other Qualcomm patents. Qualcomm sued Apple in San Diego federal court in 2017, arguing that its iPhones, iPads and Apple Watches infringed a variety of mobile-technology patents. That case was part of a broader global dispute between the tech giants. Apple challenged the validity of the patents at issue in this case at the U.S. Patent and Trademark Office's Patent Trial and Appeal Board.

The companies settled their underlying fight in 2019, signing an agreement worth billions of dollars that let Apple continue using Qualcomm chips in iPhones. The settlement included an Apple license to thousands of Qualcomm patents, but allowed the patent-board proceedings to continue. The board upheld the patents in 2020, and Apple appealed to the patent-specialist U.S. Court of Appeals for the Federal Circuit. Cupertino, California-based Apple argued it had proper legal standing to appeal because San Diego-based Qualcomm could sue again after the license expires, potentially as soon as 2025.

A Federal Circuit three-judge panel, in a 2-1 ruling, dismissed the case last year for a lack of standing, finding that Apple's risk of being sued again was speculative and the challenge would not affect its payment obligations under the settlement. Qualcomm has again argued that Apple has not shown a concrete injury to justify the appeal, just like in the "materially identical" case that the high court rejected.

AI

Bruce Willis Denies Selling Rights To His Face (bbc.com) 34

Last week, a number of outlets reported that Bruce Willis sold his face to a deepfake company called Deepcake, allowing a "digital twin" of himself to be created for use on screen. The only problem is that it's apparently not true. According to the BBC, the actor's agent said that he had "no partnership or agreement" with the company and a representative of Deepcake said only Willis had the rights to his face From the report: On 27 September, the Daily Mail reported that a deal had been struck between Willis and Deepcake. "Two-time Emmy winner Bruce Willis can still appear in movies after selling his image rights to Deepcake," the story reads. The story was picked up by the Telegraph and a series of other media outlets. "Bruce Willis has become the first Hollywood star to sell his rights to allow a 'digital twin' of himself to be created for use on screen." said the Telegraph. But that doesn't appear to be the case.

What is true is that a deepfake of Bruce Willis was used to create an advert for Megafon, a Russian telecoms company, last year. The tech used in the advert was created by Deepcake, which describes itself as an AI company specializing in deepfakes. Deepcake told the BBC it had worked closely with Willis' team on the advert. "What he definitely did is that he gave us his consent (and a lot of materials) to make his Digital Twin," they said. The company says it has a unique library of high-resolution celebrities, influencers and historical figures. On its website, Deepcake promotes its work with an apparent quote from Mr Willis: "I liked the precision of my character. It's a great opportunity for me to go back in time. "The neural network was trained on content of Die Hard and Fifth Element, so my character is similar to the images of that time."
A representative from Deepcake said in a statement: "The wording about rights is wrong... Bruce couldn't sell anyone any rights, they are his by default."
Spam

FCC Threatens To Block Calls From Carriers For Letting Robocalls Run Rampant (theverge.com) 78

The Federal Communications Commission is threatening to block calls from voice service providers that have yet to take meaningful action against illegal robocalls. The Verge reports: On Monday, the FCC announced that it was beginning the process to remove providers from the agency's Robocall Mitigation Database for failing to fully implement STIR/SHAKEN anti-robocall protocols into their networks. If the companies fail to meet these requirements over the next two weeks, compliant providers will be forced to block their calls. "This is a new era. If a provider doesn't meet its obligations under the law, it now faces expulsion from America's phone networks. Fines alone aren't enough," FCC Chairwoman Jessica Rosenworcel said in a statement on Monday. "Providers that don't follow our rules and make it easy to scam consumers will now face swift consequences."

The FCC's orders target seven carriers, including Akabis, Cloud4, Global UC, Horizon Technology Group, Morse Communications, Sharon Telephone Company, and SW Arkansas Telecommunications and Technology. "These providers have fallen woefully short and have now put at risk their continued participation in the U.S. communications system," Loyaan A. Egal, FCC acting chief of the enforcement standards, said in a Monday statement. "While we'll review their responses, we will not accept superficial gestures given the gravity of what is at stake."

Slashdot Top Deals