×
Businesses

NordVPN and Surfshark Are Merging, Continuing VPN Consolidation Trend (cnet.com) 22

An anonymous reader quotes a report from CNET: NordVPN and Surfshark have finalized a merger agreement between the two VPN providers, the companies announced Wednesday. Though the specifics of the transaction aren't being released, the finalized merger agreement follows months of negotiations between the two companies that began in mid-2021, according to a joint press release issued by Surfshark and Nord Security, NordVPN's parent company. Surfshark and NordVPN had been rivals in the ultra-competitive market for VPNs (virtual private networks) prior to the merger, but are now joining forces to "solidify both companies' offerings in different market segments and diversify the geographical reach," according to the press release. More consumers have turned to VPNs in recent years to counter increasingly invasive digital tracking from search engines, ISPs and advertisers, as well as to circumvent local content restrictions and censorship.

But the merger of two of the industry's top names -- both of which have long been among CNET's top VPN picks -- highlights the continued trend of consolidation in the VPN industry, which finds more brands under the umbrella of just three big companies -- Kape Technologies, Tesonet and Ziff Davis -- making it more important than ever to understand which entities are ultimately controlling the data sharing and privacy policies that underpin VPNs. The merger announcement follows the news just days ago that Surfshark was developed with the help of Tesonet, the same Lithuanian business incubator that helped NordVPN in its early days. While the Tesonet-NordVPN relationship was already known, the ties between Tesonet and Surfshark had been previously undisclosed. That changed last week after a report at Lithuanian news site Verslo zinios.

Music

Spotify Support Buckles Under Complaints From Angry Neil Young Fans (arstechnica.com) 599

On Monday, famed singer-songwriter Neil Young had his music removed from Spotify as a protest against the platform's distribution of Joe Rogan, who's been widely criticized for spreading misinformation about COVID-19 vaccines on his Spotify-exclusive podcast. Now, Neil's fans are taking their frustrations out on Spotify. Ars Technica reports: Though the loss of Young's music likely represents a small percentage of overall streams on Spotify, Young pointed out that "Spotify represents 60% of the streaming of my music to listeners around the world." For Young and his fans, the hit was palpable, and his fans are apparently taking their frustrations out on Spotify. The hashtag #SpotifyDeleted trended on Twitter yesterday, and fans seem to have inundated customer support with so many messages that Spotify has had to take it offline at times. "We're currently getting a lot of contacts so may be slow to respond," a large red banner has read on the support page. Options to message the company, which have previously included live chat with a customer support agent or a chat bot, are now limited to an email address link.

"When I left Spotify, I felt better," Young wrote on his website today. "I support free speech. I have never been in favor of censorship. Private companies have the right to choose what they profit from, just as I can choose not to have my music support a platform that disseminates harmful information. I am happy and proud to stand in solidarity with the front line health care workers who risk their lives every day to help others." The artist, who has long criticized audio quality on streaming services, and on Spotify in particular, closed with one last dig. "As an unexpected bonus, I sound better everywhere else," he wrote.

China

China Gives 'Fight Club' New Ending Where Authorities Win (bangkokpost.com) 156

The first rule of Fight Club in China? Don't mention the original ending. The second rule of Fight Club in China? Change it so the police win. From a report: China has some of the world's most restrictive censorship rules with authorities only approving a handful of foreign films for release each year -- sometimes with major cuts. Among the latest movies to undergo such treatment is David Fincher's 1999 cult classic "Fight Club" starring Brad Pitt and Edward Norton. Film fans in China noticed over the weekend that a version of the movie newly available on streaming platform Tencent Video was given a makeover that transforms the anarchist, anti-capitalist message that made the film a global hit.

In the closing scenes of the original, Norton's character The Narrator, kills off his imaginary alter ego Tyler Durden -- played by Pitt -- and then watches multiple buildings explode, suggesting his character's plan to bring down modern civilisation is underway. But the new version in China has a very different take. The Narrator still proceeds with killing off Durden, but the exploding building scene is replaced with a black screen and a coda: "The police rapidly figured out the whole plan and arrested all criminals, successfully preventing the bomb from exploding". It then adds that Tyler -- a figment of The Narrator's imagination -- was sent to a "lunatic asylum" for psychological treatment and was later discharged. The new ending in which the state triumphs sparked head scratching and outrage among many Chinese viewers -- many of whom would likely have seen pirated versions of the unadulterated version film.

UPDATE (2/6/2022): After a widespread outcry and coverage around the globe, Fight Club's original ending has been restored for streamers in China.
Australia

Australia PM Morrison Loses Control of WeChat Chinese Account as Election Looms (reuters.com) 27

A little-known Chinese technology company that took over a WeChat social media account set up for Australia's Prime Minister Scott Morrison said on Monday it wanted to buy an account with a large fanbase in Australia, and was unaware it was his. From a report: Australian politicians said Morrison's office lost access to the account on the platform, owned by Chinese tech giant Tencent Holdings, several months ago. The politicians claimed the move represented censorship amid growing diplomatic tensions between Canberra and Beijing with a national election to be held in Australia by May. The account, which bore Morrison's photograph and posted information on his policies in Mandarin targeted at Australian voters of Chinese ethnic origin, had 76,000 followers.

The account was renamed 'Australia China New Life' in January by its new Chinese owner, Fuzhou 985 Technology, based in Fujian province, which notified followers the account would instead promote Chinese life in Australia. An employee from Fuzhou 985 Technology, who only gave his surname as Huang, told Reuters by telephone was not aware the account was previously connected to Morrison. He said the transfer of ownership was conducted with a Chinese male national living in Fuzhou, whose identity he declined to disclose. "We thought this account had a large fanbase, so we decided to buy it," said Huang, adding that the company was looking for an account whose target audience was the Chinese community in Australia. He declined to say how much his company had paid to take over the account.

China

Security Flaws Seen In China's Mandatory Olympics App For Athletes (nytimes.com) 29

schwit1 writes: The mandatory smartphone app that athletes will use to report health and travel data when they are in China for the Olympics next month has serious encryption flaws, according to a new report, raising security questions about the systems that Beijing plans to use to track Covid-19 outbreaks.

Portions of the app that will transmit coronavirus test results, travel information and other personal data failed to verify the signature used in encrypted transfers, or didn't encrypt the data at all, according to the report by Citizen Lab, a University of Toronto cybersecurity watchdog. The group also found that the app includes a series of political terms marked for censorship in its code, though it does not appear to actively use the list to filter communications.

And Olympic Athletes will be punished if they engage In Wrong Speak.

Privacy

Winter Olympics: Athletes Advised To Use Burner Phones In Beijing (bbc.com) 54

New submitter sperm shares a report from the BBC: The Beijing Winter Olympics app that all Games attendees must use contains security weaknesses that leave users exposed to data breaches, analysts say. The My2022 app will be used by athletes, audience members and media for daily Covid monitoring. The app will also offer voice chats, file transfers and Olympic news.

But cybersecurity group Citizen Lab says the app fails to provide encryption on many of its files. China has dismissed the concerns. Questions about the app come amid a rise in warnings about visitors' tech security ahead of the Games, which begin on 4 February. People attending the Beijing Olympics should bring burner phones and create email accounts for their time in China, cyber security firm Internet 2.0 said on Tuesday. Several countries have also reportedly told athletes to leave their main devices at home.
The report also says that it's found a "censorship keywords" list built into the app, and a feature that allows people to flag other "politically sensitive" expressions.
Censorship

Germany's Security Watchdog Finds No Evidence of Censorship In Xiaomi Phones (reuters.com) 28

Germany's federal cybersecurity watchdog, the BSI, did not find any evidence of censorship functions in mobile phones manufactured by China's Xiaomi, a spokesperson said on Thursday. Reuters reports: Lithuania's state cybersecurity body had said in September that Xiaomi phones had a built-in ability to detect and censor terms such as "Free Tibet," "Long live Taiwan independence" or "democracy movement." The BSI started an examination following these accusations, which lasted several months. "As a result, the BSI was unable to identify any anomalies that would require further investigation or other measures," the BSI spokesperson said.
Electronic Frontier Foundation

Are Social Media Companies Censoring Us? Is It Ever Justified? (msn.com) 398

The Washington Post asks what may be the ultimate question of our times. "Whether the largest social media companies have become so critical to public debate that being banned or blacklisted by them — whether you're an elected official, a dissident, or even just a private citizen who runs afoul of their content policies — amounts to a form of modern-day censorship."

"And, if so, are there circumstances under which such censorship is justified?"

The first person cited is Jillian York, director for international freedom of expression at the nonprofit Electronic Frontier Foundation. Fighting over whether a given speech restriction is or isn't censorship, she adds, is often an excuse to avoid harder, more nuanced discussions as to exactly which types of speech ought to be restricted, and by whom, and on what authority. "There are a lot of people in the U.S. who will claim to be [free speech] absolutists but then basically be fine with censoring sexuality," she says. In contrast, expressions of sexuality are widely accepted in Germany, where York now lives, but there's broad consensus that censorship of Holocaust denial is warranted. In New Zealand, she adds, the democratically elected government has a Chief Censor who reviews the content of films and literature. "I'm very wary of censorship," York says. "But the reason is, who do you trust to do it? It's not that all speech is totally equal and valid." In other words, the problem York sees isn't social platforms banning a powerful figure such as Trump. It's their lack of legitimacy as arbiters of speech, especially when they're censoring people who lack the stature to speak out through other means.

David Kaye, a law professor at University of California-Irvine and the former U.N. Special Rapporteur on freedom of expression, agrees that we should be wary of tech giants' power over discourse — especially in countries that lack a robust free press. But he balks at applying the term "censorship" to content moderation decisions taken by the likes of Facebook, Twitter or YouTube in the United States... We're better off, Kaye believes, reserving the term "censorship" for the many instances around the world in which speech restrictions are backed by the power of the state. That can include cases in which "the state puts demands on social media to take down content, or criminalizes individuals who tweet," as has happened in China, the United Arab Emirates, Myanmar and elsewhere...

"If we start to dilute the idea of censorship as a state-driven tool by equating it with what platforms are doing, we start to misunderstand what platforms are actually doing, and why they're doing it," Kaye said.

The Post ultimately cites three experts who agree on one point: that it's worth scrutinizing the decisions of social media platforms because of their growing influence — whether or not you end up calling it censorship. But they also cite a follow-up observation from Chinmayi Arun, a resident fellow of Yale Law School's Information Society Project.

Too often overlooked in the debates over what social networks take down is that they aren't just passive conduits of information: Their recommendation algorithms and design decisions actively shape what speech gets heard, and by how many, and how it is framed — often fueling the kind of divisive content that they later face pressure to remove.

Facebook, Twitter and YouTube may or may not have censored Trump a year ago. But there's no doubt that for years prior, they amplified and enabled him.

Encryption

NBC: 'You Probably Don't Need to Rely on a VPN Anymore' (nbcnews.com) 166

NBC News writes: VPNs, or virtual private networks, continue to be used by millions of people as a way of masking their internet activity by encrypting their location and web traffic. But on the modern internet, most people can safely ditch them, thanks to the widespread use of encryption that has made public internet connections far less of a security threat, cybersecurity experts say. "Most commercial VPNs are snake oil from a security standpoint," said Nicholas Weaver, a cybersecurity lecturer at the University of California, Berkeley. "They don't improve your security at all...."

Most browsers have quietly implemented an added layer of security in recent years that automatically encrypts internet traffic at most sites with a technology called HTTPS. Indicated by a tiny padlock by the URL, the presence of HTTPS means that worrisome scenario, in which a scammer or a hacker squats on a public Wi-Fi connection in order to watch people's internet habits, isn't feasible. It's not clear that the threat of a hacker at your coffee shop was ever that real to begin with, but it is certainly not a major danger now, Weaver said. "Remember, someone attacking you at the coffee shop needs to be basically at the coffee shop," he said. "I don't know of them ever being used outside of pranks. And those are all irrelevant now with most sites using HTTPS," he said in a text message.

There are still valid uses for VPNs. They're an invaluable tool for getting around certain types of censorship, though other options also exist, such as the Tor Browser, a free web browser that automatically reroutes users' traffic and is widely praised by cybersecurity experts. VPNs are also vital for businesses that need their employees to log in remotely to their internal network. And they're a popular and effective way to watch television shows and movies that are restricted to particular countries on streaming services. But like with antivirus software, the paid VPN industry is a booming global market despite its core mission no longer being necessary for many people.

Most VPNs market their products as a security tool. A Consumer Reports investigation published earlier this month found that 12 of the 16 biggest VPNs make hyperbolic claims or mislead customers about their security benefits. And many can make things worse, either by selling customers' browsing history to data brokers, or by having poor cybersecurity.

The article credits the Electronic Frontier Foundation for popularizing encryption through browser extensions and web site certificates starting in 2010. "In 2015, Google started prioritizing websites that enabled HTTPS in its search results. More and more websites started offering HTTPS connections, and now practically all sites that Google links to do so.

"Since late 2020, major browsers such as Brave, Chrome, Firefox, Safari and Edge all built HTTPS into their programs, making Electronic Frontier Foundation's browser extension no longer necessary for most people."
China

Buying Influence: How China Manipulates Facebook and Twitter (nytimes.com) 57

The New York Times: Flood global social media with fake accounts used to advance an authoritarian agenda. Make them look real and grow their numbers of followers. Seek out online critics of the state -- and find out who they are and where they live. China's government has unleashed a global online campaign to burnish its image and undercut accusations of human rights abuses. Much of the effort takes place in the shadows, behind the guise of bot networks that generate automatic posts and hard-to-trace online personas. Now, a new set of documents reviewed by The New York Times reveals in stark detail how Chinese officials tap private businesses to generate content on demand, draw followers, track critics and provide other services for information campaigns. That operation increasingly plays out on international platforms like Facebook and Twitter, which the Chinese government blocks at home. The documents, which were part of a request for bids from contractors, offer a rare glimpse into how China's vast bureaucracy works to spread propaganda and to sculpt opinion on global social media. They were taken offline after The Times contacted the Chinese government about them.

On May 21, a branch of the Shanghai police posted a notice online seeking bids from private contractors for what is known among Chinese officialdom as public opinion management. Officials have relied on tech contractors to help them keep up with domestic social media and actively shape public opinion via censorship and the dissemination of fake posts at home. Only recently have officials and the opinion management industry turned their attention beyond China. The Shanghai police are looking to create hundreds of fake accounts on Twitter, Facebook and other major social media platforms. The police department emphasizes that the task is time sensitive, suggesting that it wants to be ready to unleash the accounts quickly to steer discussion. Bot-like networks of accounts such as those that the Shanghai police want to buy have driven an online surge in pro-China traffic over the past two years. Sometimes the social media posts from those networks bolster official government accounts with likes or reposts. Other times they attack social media users who are critical of government policies.

Network

Tor Project Sees Decline in Server Numbers, Will Offer Rewards for New Bridge Operators (therecord.media) 33

The Tor Project said this week that it has seen a drop in the number of Tor relays and bridge servers and is now offering various rewards to users who help bring the number back up. From a report: Rewards include the likes of hoodies, t-shirts, and stickers and are meant to provide some sort of meaningful gift to those who help keep the Tor anonymity network alive and resilient to censorship. More specifically, the rewards will be provided to those who run "Tor bridges," which serve as entry points into the Tor network for users located in countries that block access to Tor servers. "We currently have approximately 1,200 bridges, 900 of which support the obfs4 obfuscation protocol," said Gustavo Gus, Community Team Lead for the Tor Project. "Unfortunately, these numbers have been decreasing since the beginning of this year. It's not enough to have many bridges: eventually, all of them could find themselves in block lists. We therefore need a constant trickle of new bridges that aren't blocked anywhere yet," the Tor Project member said.
Network

With Coercion and Black Boxes, Russia Installs a Digital Iron Curtain 52

Russia's boldest moves to censor the internet began in the most mundane of ways -- with a series of bureaucratic emails and forms. From a report: The messages, sent by Russia's powerful internet regulator, demanded technical details -- like traffic numbers, equipment specifications and connection speeds -- from companies that provide internet and telecommunications services across the country. Then the black boxes arrived. The telecom companies had no choice but to step aside as government-approved technicians installed the equipment alongside their own computer systems and servers. Sometimes caged behind lock and key, the new gear linked back to a command center in Moscow, giving authorities startling new powers to block, filter and slow down websites that they did not want the Russian public to see.

The process, underway since 2019, represents the start of perhaps the world's most ambitious digital censorship effort outside of China. Under President Vladimir V. Putin, who once called the internet a "C.I.A. project" and views the web as a threat to his power, the Russian government is attempting to bring the countryâ(TM)s once open and freewheeling internet to heel. The gear has been tucked inside the equipment rooms of Russia's largest telecom and internet service providers, including Rostelecom, MTS, MegaFon and Vympelcom, a senior Russian lawmaker revealed this year. It affects the vast majority of the country's more than 120 million wireless and home internet users, according to researchers and activists. The world got its first glimpse of Russia's new tools in action when Twitter was slowed to a crawl in the country this spring. It was the first time the filtering system had been put to work, researchers and activists said. Other sites have since been blocked, including several linked to the jailed opposition leader Alexei A. Navalny.
Apple

Apple Takes Down Koran App in China (bbc.com) 78

Apple has taken down one of the world's most popular Koran apps in China, following a request from officials. From a report: Quran Majeed is available across the world on the App Store -- and has nearly 150,000 reviews. It is used by millions of Muslims. The BBC understands that the app was removed for hosting illegal religious texts. The Chinese government has not responded to the BBC's request for comment. The deletion of the app was first noticed by Apple Censorship -- a website that monitors apps on Apple's App Store globally. In a statement from the app's maker, PDMS, the company said: "According to Apple, our app Quran Majeed has been removed from the China App store because it includes content that requires additional documentation from Chinese authorities."

"We are trying to get in touch with the Cyberspace Administration of China and relevant Chinese authorities to get this issue resolved." The company said it had close to one million users in China. The Chinese Communist Party officially recognises Islam as a religion in the country. However, China has been accused of human rights violations, and even genocide, against the mostly Muslim Uyghur ethnic group in Xinjiang. Earlier this year the BBC reported that Uyghur imams had been targeted in China's Xinjiang crackdown. Apple declined to comment, but directed the BBC to its Human Rights Policy, which states: "We're required to comply with local laws, and at times there are complex issues about which we may disagree with governments."

Microsoft

Microsoft Shutting Down LinkedIn In China (wsj.com) 38

phalse phace writes: Facing a significantly more challenging operating environment and greater compliance requirements in China, Microsoft has decided to shut down LinkedIn in the country. The announcement follows the rebuke of LinkedIn executives by China's internet regulator in March for failing to control political content and gave them 30 days to do so. In recent months, LinkedIn notified several China-focused human-right activists, academics and journalists that their profiles were being blocked in China, saying they contained prohibited content. LinkedIn said it would replace its Chinese service, which restricts some content to comply with local government demands, with a job-board service lacking social-media features, such as the ability to share opinions and news stories.
Facebook

The Intercept Reveals Facebook's Secret Blacklist of 'Dangerous Individuals and Organizations' (theintercept.com) 71

Sam Biddle writes via The Intercept: To ward off accusations that it helps terrorists spread propaganda, Facebook has for many years barred users from speaking freely about people and groups it says promote violence. The restrictions appear to trace back to 2012, when in the face of growing alarm in Congress and the United Nations (PDF) about online terrorist recruiting, Facebook added to its Community Standards a ban on "organizations with a record of terrorist or violent criminal activity." This modest rule has since ballooned into what's known as the Dangerous Individuals and Organizations policy, a sweeping set of restrictions on what Facebook's nearly 3 billion users can say about an enormous and ever-growing roster of entities deemed beyond the pale. [...] The Intercept has reviewed a snapshot of the full DIO list and is today publishing a reproduction of the material in its entirety, with only minor redactions and edits to improve clarity. It is also publishing an associated policy document, created to help moderators decide what posts to delete and what users to punish.

The list and associated rules appear to be a clear embodiment of American anxieties, political concerns, and foreign policy values since 9/11, experts said, even though the DIO policy is meant to protect all Facebook users and applies to those who reside outside of the United States (the vast majority). Nearly everyone and everything on the list is considered a foe or threat by America or its allies: Over half of it consists of alleged foreign terrorists, free discussion of which is subject to Facebook's harshest censorship. The DIO policy and blacklist also place far looser prohibitions on commentary about predominately white anti-government militias than on groups and individuals listed as terrorists, who are predominately Middle Eastern, South Asian, and Muslim, or those said to be part of violent criminal enterprises, who are predominantly Black and Latino, the experts said.

The materials show Facebook offers "an iron fist for some communities and more of a measured hand for others," said Angel Diaz, a lecturer at the UCLA School of Law who has researched and written on the impact of Facebook's moderation policies on marginalized communities. Facebook's policy director for counterterrorism and dangerous organizations, Brian Fishman, said in a written statement that the company keeps the list secret because "[t]his is an adversarial space, so we try to be as transparent as possible, while also prioritizing security, limiting legal risks and preventing opportunities for groups to get around our rules." He added, "We don't want terrorists, hate groups or criminal organizations on our platform, which is why we ban them and remove content that praises, represents or supports them. A team of more than 350 specialists at Facebook is focused on stopping these organizations and assessing emerging threats. We currently ban thousands of organizations, including over 250 white supremacist groups at the highest tiers of our policies, and we regularly update our policies and organizations who qualify to be banned."

The Almighty Buck

Credit-Card Firms Are Becoming Reluctant Regulators of the Web (economist.com) 97

An anonymous reader quotes a report from The Economist: Who should police the internet? For some time now the question has tied companies, regulators and campaigners in knots. Social networks spend billions moderating content posted on their platforms, but are still criticized either for not removing enough toxic material or for stifling free speech. They are not the only ones to grapple with the problem. Banks and credit-card companies too are finding themselves playing a bigger role in what is said and done in the public square -- to their, and their customers', discomfort. Now the boundary of censorship is being extended further, into the pornography business. From October 15th adult websites worldwide will have to verify the age and identity of anyone featured in a picture or video, as well as the ID of the person uploading it. They will need to operate a fast complaints process, and will have to review all content before publication. These requirements are being imposed not by regulators but by Mastercard, a credit-card giant. Websites can always choose not to work with Mastercard. But given that the company handles about 30% of all card payments made outside China, to do so would be costly. Visa, which manages a further 60% of payments, is also taking a firmer line on adult sites. And the trend goes beyond porn. In the shadier corners of the web, and in industries where the law is unclear or out of date, financial firms are finding themselves acting as de facto regulators.
[...]
Visa and Mastercard's near-duopoly on card payments makes their decisions more powerful -- and the firms prime targets for protesters. In 2019 SumOfUs, a left-wing pressure group, tabled a proposal at Mastercard's annual meeting meant to stop payments to far-right groups. (The proposal was defeated.) Thirty-four women are suing Visa along with the owners of Pornhub, an adult site which they say hosted unconsenting footage of them. Illegal-porn sites "care a lot more about their finances than they do about the law," says Laila Mickelwait, whose Justice Defense Fund helps sex-abuse victims litigate. And, she adds, when financial firms change their policies it applies globally. Last year Visa and Mastercard cut off Pornhub over its hosting of potentially unlawful material. Payment companies in particular face a philosophical dilemma. "On one hand they try to be very open, accepting, willing to facilitate payments for whomever. They're not taking any sort of political or moral stance," says Lisa Ellis of MoffettNathanson, a research firm. "But on the other hand, they also feel like they have a very strong responsibility in making sure that they're not aiding and abetting any sort of crime."

Visa and Mastercard both say that, as global companies, their guiding principle is local legality. (This can throw up some surprises: one executive recalls being informed by clients from a Scandinavian country that bestiality was legal there at the time.) Things are not always black and white. In 2017, after a far-right march in Charlottesville, Virginia, Mastercard shut down the use of its cards on websites that had made "specific threats or incite[d] violence," but kept dealing with other sites labelled hate-groups. "Our standard is whether a merchant's activity is lawful, even when we disagree with what they say or do," the company said at the time. In grey areas they have reason to err on the side of caution. Payment networks' risk of liability tends to be low, since they operate at one remove from the merchants. But being named in a sex-trafficking complaint or accused of helping Nazis does not look good. In working with a borderline adult site, for instance, there's "not a lot of upside and a lot of downside", says Ms Ellis. And in legally tricky areas it can be cheaper to issue a blanket ban than pick through every difficult case. Banks may steer clear of countries that are not embargoed but which have a lot of people on the banned list, "to minimize the burden of determining whether every transaction is compliant," says Jonathan Cross of Herbert Smith Freehills, a law firm. [...] For as long as legislation lags behind, financial institutions will be left in a difficult position: either accused of being the "moral police," as one executive puts it, or of enabling wrongdoing. As Richard Haythornthwaite, then Mastercard's chairman, told the protesters at the firm's annual meeting in 2019: "If it is lawful, then we need to respect that transaction. If it is something that is swimming against the tide of society, it's for the society to rise up and change the law."

GNU is Not Unix

FSF Announces 'JShelter' Browser Privacy Extension to Block Fingerprinting, Tracking, and Malware (fsf.org) 40

This week the Free Software Foundation (FSF) announced JShelter, "an anti-malware Web browser extension to mitigate potential threats from JavaScript, including fingerprinting, tracking, and data collection."

The browser add-on — supported by NLnet Foundation's Next Generation Internet (NGI) Zero Privacy & Trust Enhancing Technologies fund — is currently "in development and the first release is available." This browser add-on will limit the potential for JavaScript programs to do harmful actions by restricting default behavior and adding a layer of control... Accessing cookies, performing fingerprinting to track users across multiple sites, revealing the local network address, or capturing the user's input before they submit a form are some examples of JavaScript's capabilities that can be used in harmful ways. JShelter adds a safety layer that allows the user to choose if a certain action should be forbidden on a site, or if it should be allowed with restrictions, such as reducing the accuracy of geolocation to the city area. This layer can also aid as a countermeasure against attacks targeting the browser, operating system, or hardware levels... [The extension] will ask — globally or per site — if specific native functions provided by the JavaScript engine and the Document Object Model (DOM) are allowed by the user. It will also link to an explanatory page for each function, to raise awareness of related threats. Depending on the function being addressed, the user will have the option to allow it, block it, or have it return a custom value...

"Our browsers have become perhaps the most critical of tools we depend on, and yet the browser environment is far from healthy," says Michiel Leenaars, director of strategy at NLnet Foundation and coordinator of NGI Zero. "Dominant corporate behavior from a small amount of actors has been aggressively reshaping the evolution of the Web, and that is starting to wreak havoc. Despite an enormous systemic dependency, we as users have very little control over what browsers allow and share — leading to significant risk as the most powerful tools in the shed are essentially left unprotected for every casual Web site to abuse. JShelter is a great initiative to help empower us all, to help us gain better understanding and to better safeguard ourselves from obvious and otherwise unavoidable harm."

The effort is part of a larger, multi-year campaign from FSF on JavaScript on the Web started in 2013, which among others includes the development of GNU LibreJS and outreach to users and developers about nonfree software inside the browser. The GNU LibreJS extension detects JavaScript web labels and assists users with running only JavaScript distributed under a free software license, according to their ethical convictions and individual preferences.

"JShelter will help protect users from critical threats now, and contribute significantly to progress on the necessary longer-term cultural shift of moving away from nonfree JavaScript," said Ruben Rodriguez, former FSF chief technology officer.

"This is a project I've been looking forward to for years, tired of dealing with all kinds of potential antifeatures in the browsers I use and distribute, and having to figure out some countermeasure for them with configuration changes, patches or extensions. Being able to wrap the JavaScript engine in a layer of protection is a game changer."
Facebook

'The Big Delete:' Inside Facebook's Crackdown in Germany (go.com) 78

"Days before Germany's federal elections, Facebook took what it called an unprecedented step: the removal of a series of accounts that worked together to spread COVID-19 misinformation and encourage violent responses to COVID restrictions," reports the Associated Press.

The crackdown, announced Sept. 16, was the first use of Facebook's new "coordinated social harm" policy aimed at stopping not state-sponsored disinformation campaigns but otherwise typical users who have mounted an increasingly sophisticated effort to sidestep rules on hate speech or misinformation. In the case of the German network, the nearly 150 accounts, pages and groups were linked to the so-called Querdenken movement, a loose coalition that has protested lockdown measures in Germany and includes vaccine and mask opponents, conspiracy theorists and some far-right extremists.

Facebook touted the move as an innovative response to potentially harmful content; far-right commenters condemned it as censorship. But a review of the content that was removed — as well as the many more Querdenken posts that are still available — reveals Facebook's action to be modest at best. At worst, critics say, it could have been a ploy to counter complaints that it doesn't do enough to stop harmful content. "This action appears rather to be motivated by Facebook's desire to demonstrate action to policymakers in the days before an election, not a comprehensive effort to serve the public," concluded researchers at Reset, a U.K.-based nonprofit that has criticized social media's role in democratic discourse....

Even with the new rule, a problem remains with the takedowns: they don't make it clear what harmful material remains up on Facebook, making it difficult to determine just what the social network is accomplishing. Case in point: the Querdenken network. Reset had already been
monitoring the accounts removed by Facebook and issued a report that concluded only a small portion of content relating to Querdenken was taken down while many similar posts were allowed to stay up... Facebook initially declined to provide examples of the Querdenken content it removed, but ultimately released four posts to the Associated Press that weren't dissimilar to content still available on Facebook...

Reset's analysis of comments removed by Facebook found that many were actually written by people trying to rebut Querdenken arguments, and did not include misinformation.

Censorship

Who Censored Marie Antoinette's Letters? X-Rays Reveal a Surprise (science.org) 26

sciencehabit shares a report from Science.org: In late 1791 and early 1792, on the eve of the French Revolutionary Wars, Queen Marie Antoinette engaged in a secret correspondence with her confidant and rumored lover, Swedish Count Axel von Fersen. Nearly 50 letters from that exchange survive at the French National Archives. But certain passages in 15 of the letters were unreadable, obscured by redactions made with swirls of dark ink. Now, researchers have revealed the words beneath 45 of these alterations using x-ray technology. They have also discovered the censor's identity: von Fersen, himself. The idea that von Fersen made the redactions is "a revelation," says Catriona Seth, a professor of French literature at the University of Oxford who was not involved with the work. Historians had thought the letters were censored in the second half of the 19th century -- most likely by von Fersen's great-nephew -- to protect the writers' reputations. Now, she says, scholars will need to rethink the cover-up -- and the reasons behind it.

The newly legible passages are largely sentimental, phrases like "made my heart happy," and "you that I love." Comments on politics and world events, meanwhile, remain uncensored. But even these seemingly intimate phrases don't definitively tell historians anything new about Marie Antoinette and von Fersen's relationship, Seth says. Scholars, she notes, already knew Marie Antoinette had "a very deep affection for him." Still, she adds, the letters offer "direct insight into the thoughts and feelings of Marie Antoinette." In the future, the techniques in this study could be used in combination with machine algorithms to automatically transcribe old texts, the researchers say, making it easier to understand these important documents -- and others like them.
The researchers published their findings in the journal Science Advances.
Microsoft

Rick Scott Probes LinkedIn, Microsoft on Censoring US Journalists in China (axios.com) 43

Sen. Rick Scott (R-Fla.) sent a letter to Microsoft and LinkedIn leadership on Thursday questioning why LinkedIn censored the profiles of U.S. journalists from the company's China-based platform this week, according to a letter obtained by Axios. From a report: LinkedIn -- which is owned by Microsoft -- notified several U.S. journalists this week, including Axios' Bethany Allen-Ebrahimian, that their accounts will no longer be viewable in China due to "prohibited content" on their profile. In addition to Allen-Ebrahimian, affected journalists include VICE News' Melissa Chan and freelance reporter Greg Bruno. All three have reported on human rights abuses in China.

"I am deeply concerned that an American company is actively censoring American journalists on behalf of the Chinese Communist Party," Scott said in the letter addressed to Microsoft CEO Satya Nadella and LinkedIn CEO Ryan Roslansky. "Members of the media report information that is critical to helping Americans, including members of Congress, understand the scope of Communist China's abuses, especially its abuses against and surveillance of Uyghurs in Xinjiang," the senator continued. "The censorship of these journalists raises serious questions about Microsoft's intentions and its commitment to standing up against Communist China's horrific human rights abuses and repeated attacks against democracy."

Slashdot Top Deals