Thursday, 11 February 2010

British Police Officer Accused of Using Records Management System to Stalk Women

ARMA's Information Overload Blog writes that PC Robert Campbell allegedly conducted unauthorized searches of Hampshire Constabulary's electronic Records Management System to try to forge relationships with three women between July 2006 and April 2009,” British newspaper The News reported. Supposedly, Campbell, a 42-year-old from Portsmouth, also used the Records Management System to find information to single parent, who had previously been a victim of domestic violence. Campbell, who is still serving as a police officer, denied the four counts of misconduct in a public office brought against him.

Visit Information Overload here

Yes to SWIFT unlikely as vote in limbo

Euractiv.com reports today that a debate in the European Parliament last night cast a cloud of uncertainty over a vote scheduled today (11 February) on an agreement between the EU and the US on the transfer of citizens' financial data to prevent terrorist attacks.

MEPs close to the negotiations told EurActiv that after a tense debate with the European Council and the European Commission, the Council began trying to hash out a compromise in the small hours of 10 February to satisfy MEPs' concerns on bulk data transfers and legal redress.

On Wednesday, the Council also issued a statement saying it would try to meet MEPs' concerns ahead of today's plenary vote.

Read more here

Thursday, 21 January 2010

Microsoft woos EU privacy watchdogs

Euractiv.com reports that Microsoft's Bing search engine will retain private Internet search data for a maximum period of six months, the ICT giant announced yesterday (19 January) as EU antitrust regulators started to scrutinise the company's alliance with Yahoo.

Microsoft offered to reduce from 18 to six months the period it retains the IP addresses of Internet users making queries through its Bing search engine, the company said. The change will be implemented over the next 12 to 18 months, it added.

Read the article here: http://www.euractiv.com/en/infosociety/microsoft-woos-eu-privacy-watchdogs/article-189063

Monday, 18 January 2010

EU Parliament threatens to derail EU-US bank data deal

EUObserver.com reports that the European Parliament is threatening to derail an interim agreement allowing US authorities to track European bank transactions in terrorism investigations unless certain concessions are made.

The president of the European Parliament Jerzy Buzek at the end of last week sent a second letter to the Spanish EU presidency asking for more information on the so-called Swift agreement.

A plenary debate on the matter is scheduled for Wednesday in Strasbourg, during which the Spanish presidency is expected to give more answers on the technicalities of the deal.
The agreement would allow US prosecutors and investigators to tap into intra-European bank transactions as part of anti-terrorist enquiries - something EU lawmakers say raises privacy concerns.

Read the article here: http://euobserver.com/9/29284/?rk=1

Monday, 11 January 2010

Brussels pledges antitrust overhaul

Euractiv.com reports that the EU executive is promising to make its complex antitrust procedures more transparent in a move designed to make competition cases more predictable for businesses.

The European Commission's competition arm has published a series of documents detailing how antitrust decisions are reached and pledging to help companies engage with the process.

The EU has sweeping antitrust powers and has conducted major inquiries into corporate giants including Intel, Microsoft and a host of energy firms. It has also launched high-profile investigations into competition in the pharmaceutical sector and has the power to block mergers and acquisitions.

Companies under investigation often find the process to be complex and opaque, something the Commission is keen to address.

Read the article here: http://www.euractiv.com/en/enterprise-jobs/brussels-pledges-antitrust-overhaul/article-188641

Wednesday, 6 January 2010

New ENISA publications available

In implementing its annual Work Programme, ENISA in December 2009 published a number of studies, reports, and a survey covering issues of resilience of communication networks, anti-spam measures by providers, and CERT/CSIRT material.

*Resilience: Tracking standardisation activities in NIS* ENISA published a study on "Gaps in standardisation related to resilience of communication networks". The study provides five recommendations for future standardisation activities. It can be downloaded from the ENISA website at: http://www.enisa.europa.eu/act/it/library/deliverables/gapsstd

*Third ENISA Survey on anti-spam measures implemented by European providers* The survey aims to determine how e-mail service providers are combating spam on their networks. It helps identifying the state of the fight against spam and helps service providers to learn from their peers throughout Europe. The survey report is available from the ENISA website at: http://www.enisa.europa.eu/act/res/other-areas/anti-spam-measures

*New CERT material*ENISA launched new Computer Emergency Response Teams (CERT or CSIRT) material including a field report on two CSIRT exercise pilots, a draft baseline capabilities definition for national/governmental CERTs, and three DVD images to support the exercise material.
The field report on the exercise pilots which is a hands-on report on logistics, preparation and experiences during the event can be obtained from the ENISA website at: http://www.enisa.europa.eu/act/cert/support/exercise
The draft document defines baseline capabilities for CERTs with national responsibility in the areas of service provision, mandate, cooperation and operation. This document which is a snapshot of an ongoing activity to enhance cross-border cooperation of national/governmental CERTs can be obtained from http://www.enisa.europa.eu/act/cert/support/baseline-capabilities
Three DVD images for teachers and students aim at enabling an easy application of the CSIRT exercise material. The material which is not only useful for CERTs but can also be applied in any kind of training for security professionals is available at http://www.enisa.europa.eu/act/cert/support/exercise

Wednesday, 2 December 2009

ENISA A new ENISA Position Paper on "Privacy and Security Risks when Authenticating on the Internet with European eID Cards"

A new ENISA Position Paper on "Privacy and Security Risks when Authenticating on the Internet with European eID Cards" has been published.

The paper is focusing on authentication risks with European eID Cards. It analyses seven vulnerabilities, identifies 15 threats and gives security recommendations.

Whenever we use internet services, the first steps we take are usually identification (we insert our names) and authentication (we prove that it is us). How we actually identify and authenticate ourselves depends on the security level of the application. The means used can vary from a simple combination of username and password, through a secret PIN, to a PIN generated by some external device or a smart card using cryptography. Smart cards are being used increasingly for authentication purposes. Many European identity cards now contain a smart-card chip, equipped with functionalities for online authentication. They are usually called 'electronic identity cards' (eID cards). The paper focuses on authentication using smart cards and compares this approach with other common means of authentication.

Press release:http://www.enisa.europa.eu/media/press-releases/position-paper-security-risks-online-banking-and-eid-cards

Full report:http://www.enisa.europa.eu/act/it/eid/eid-online-banking