<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
>

<channel>
	<title>Voice on the Web &#187; Citizen Lab</title>
	<atom:link href="http://www.voiceontheweb.biz/tag/citizen-lab/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.voiceontheweb.biz</link>
	<description>Facilitating Personal and Business Conversations Across a Voice 2.0 World</description>
	<lastBuildDate>Wed, 08 Feb 2012 12:25:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<!-- podcast_generator="Blubrry PowerPress/2.0.4" -->
	<itunes:summary>Facilitating Personal and Business Conversations Across a Voice 2.0 World</itunes:summary>
	<itunes:author>Voice on the Web</itunes:author>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://www.voiceontheweb.biz/wp-content/plugins/powerpress/itunes_default.jpg" />
	<itunes:subtitle>Facilitating Personal and Business Conversations Across a Voice 2.0 World</itunes:subtitle>
	<image>
		<title>Voice on the Web &#187; Citizen Lab</title>
		<url>http://www.voiceontheweb.biz/wp-content/plugins/powerpress/rss_default.jpg</url>
		<link>http://www.voiceontheweb.biz</link>
	</image>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>TOM-Skype Breach: Nart&#8217;s Recommendations to Skype</title>
		<link>http://www.voiceontheweb.biz/skype-world/skype-ecosystem/tom-skype-breach-narts-recommendations-to-skype/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=tom-skype-breach-narts-recommendations-to-skype</link>
		<comments>http://www.voiceontheweb.biz/skype-world/skype-ecosystem/tom-skype-breach-narts-recommendations-to-skype/#comments</comments>
		<pubDate>Tue, 28 Oct 2008 23:53:11 +0000</pubDate>
		<dc:creator>Jim Courtney</dc:creator>
				<category><![CDATA[Skype Ecosystem]]></category>
		<category><![CDATA[Skype News]]></category>
		<category><![CDATA[Skype Operations]]></category>
		<category><![CDATA[Citizen Lab]]></category>
		<category><![CDATA[GigaOm]]></category>
		<category><![CDATA[Global Network Initiative]]></category>
		<category><![CDATA[Nart Villeneuve]]></category>
		<category><![CDATA[Regulation]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[TOMSkype Breach08]]></category>

		<guid isPermaLink="false">http://voiceontheweb.biz/?p=761</guid>
		<description><![CDATA[This is the fourth and final of four posts resulting from an interview with Nart Villeneuve, principle investigator of the Citizen Lab report &#8220;Breaching Trust&#8221;. Having discussed some background to Nart&#8217;s research, the activities of the Citizen Lab and answers to Phil&#8217;s questions, Nart had a couple of recommendations for Skype going forward. As background, [...]]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.voiceontheweb.biz/skype-world/skype-ecosystem/tom-skype-breach-narts-recommendations-to-skype/' addthis:title='TOM-Skype Breach: Nart&#8217;s Recommendations to Skype '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><p><em>This is the fourth and final of four posts resulting from an interview with Nart Villeneuve, principle investigator of the Citizen Lab report &#8220;Breaching Trust&#8221;.</em></p>
<p>Having discussed some <a title="Breaching Trust Background" href="http://voiceontheweb.biz/?p=755" target="_blank">background to Nart&#8217;s research</a>, <a title="Citizen Lab Overview" href="http://voiceontheweb.biz/?p=757" target="_blank">the activities of the Citizen Lab</a> and <a title="Answers to Phil's Questions" href="http://voiceontheweb.biz/?p=758" target="_blank">answers to Phil&#8217;s questions</a>, Nart had a couple of recommendations for Skype going forward. As background, the Citizen Lab is a affiliated with the BerkmanCenter for Internet &amp; Society&#8217;s <a href="http://cyber.law.harvard.edu/research/principles">&#8220;Principles on Free Expression and Privacy&#8221;</a> initiative <em>&#8220;<span class="long" style="display: block;">to protect and advance individuals&#8217; rights to free expression and privacy on the Internet through the creation of a set of principles and supporting mechanisms for ICT companies&#8221;.</span></em></p>
<p>The goal of this project is:</p>
<blockquote><p><span class="long" style="display: block;">Through the articulation of a broad set of common principles, the development of resources for implementation and a compliance structure, this collaborative effort is working to formulate an industry-wide response to guide businesses when they encounter laws and practices that may contravene international human rights standards or be at odds with law or culture in their home jurisdiction.</span></p></blockquote>
<p>Participants in this project include Microsoft, Google, Yahoo along with several human rights organizations. It is hoped that having a joint industry-activist initiative would help companies avoid situations similar to the one which Skype has encountered in its TOM-Skype relationship.</p>
<p>Update: as I was writing this post today, <a href="http://www.nytimes.com/2008/10/28/technology/internet/28privacy.html?_r=1&amp;adxnnl=1&amp;oref=slogin&amp;adxnnlx=1225224153-AtdfZAhFXgktlgMLcSR5Yg">a New York Times story</a> on this initiative, now called the Global Network Initiative, broke and has more details.</p>
<p>An initial draft document (update: final document to be released tomorrow) is under review amongst the participants but Nart brought out three recommendations for Skype that would be consistent with the guidelines in the draft document:</p>
<ol>
<li>Include in Skype and/or the TOM-Skype client, as appropriate, an ability to provide notification to all participants in a conversation that a contact is participating in the conversation via the TOM-Skype client. In effect, this could be included in a more general identification of the version of Skype that other participants in a conversation are using. The reasoning for the providing version information was to let other participants know, via the version number, which feature set a participant can use in their Skype client installation.</li>
<li>When a user types a message that is diverted via the TOM-Skype filter, a message, indicating that the recipient is missing content due to government regulations, comes back to the initiating party. For example: &#8220;To comply with local laws, this message has not been displayed to your contact.&#8221; Often Nart found conversations where someone would type a message repeatedly when it was apparent the receiving party was not understanding the message being sent, yet the sender did not realize that the message was being filtered.</li>
<li>Become a participant in the Global Network Initiative and its dialogue.</li>
</ol>
<p>The hope is that, through an industry-wide initiative, foreign companies entering the Chinese market would have more negotiating power and a protocol for addressing issues that are raised in the process of establishing a business relationship in countries where the climate for free expression and human rights is restrictive. In an Opinion piece today, <a href="http://gigaom.com/2008/10/28/opinion-corporate-morality-is-not-a-group-effort/#more-26948">Om has other thoughts on the morality of this approach</a>.</p>
<p><small>Tags: <a rel="tag" href="http://technorati.com/tag/TOM-Skype">TOM-Skype</a>, <a rel="tag" href="http://technorati.com/tag/Skype">Skype</a>, <a rel="tag" href="http://technorati.com/tag/Nart+Villeneuve">Nart Villeneuve</a>, <a rel="tag" href="http://technorati.com/tag/Citizen+Lab">Citizen Lab</a>, <a rel="tag" href="http://technorati.com/tag/Global+Network+Initiative">Global Network Initiative</a></small></p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.voiceontheweb.biz/skype-world/skype-ecosystem/tom-skype-breach-narts-recommendations-to-skype/' addthis:title='TOM-Skype Breach: Nart&#8217;s Recommendations to Skype '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.voiceontheweb.biz/skype-world/skype-ecosystem/tom-skype-breach-narts-recommendations-to-skype/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>TOM-Skype Breach: Answers to Phil&#8217;s Questions from 2006 SJ Post</title>
		<link>http://www.voiceontheweb.biz/skype-world/skype-ecosystem/skype-partner-solutions/tom-skype-breach-answers-to-phils-questions-from-2006-sj-post/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=tom-skype-breach-answers-to-phils-questions-from-2006-sj-post</link>
		<comments>http://www.voiceontheweb.biz/skype-world/skype-ecosystem/skype-partner-solutions/tom-skype-breach-answers-to-phils-questions-from-2006-sj-post/#comments</comments>
		<pubDate>Tue, 21 Oct 2008 10:11:45 +0000</pubDate>
		<dc:creator>Jim Courtney</dc:creator>
				<category><![CDATA[Communications News]]></category>
		<category><![CDATA[Service Providers]]></category>
		<category><![CDATA[Skype News]]></category>
		<category><![CDATA[Skype Operations]]></category>
		<category><![CDATA[Skype Partner Solutions]]></category>
		<category><![CDATA[Using Skype]]></category>
		<category><![CDATA[Citizen Lab]]></category>
		<category><![CDATA[Nart Villeneuve]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Regulation]]></category>
		<category><![CDATA[screening]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[TOM Online]]></category>
		<category><![CDATA[TOMSkype Breach08]]></category>

		<guid isPermaLink="false">http://voiceontheweb.biz/?p=758</guid>
		<description><![CDATA[This is the third of four posts resulting from an interview with Nart Villeneuve, principle investigator of the Citizen Lab report &#8220;Breaching Trust&#8221;. Two weeks ago Phil republished an April 2006 Skype Journal post with about sixteen questions related to the TOM-Skype security breach discovered by Nart. My interview provided answers to several of these [...]]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.voiceontheweb.biz/skype-world/skype-ecosystem/skype-partner-solutions/tom-skype-breach-answers-to-phils-questions-from-2006-sj-post/' addthis:title='TOM-Skype Breach: Answers to Phil&#8217;s Questions from 2006 SJ Post '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><p><a href="http://voiceontheweb.biz/wp-content/uploads/2008/11/citizenlablogo.jpg" rel="shadowbox[sbpost-758];player=img;" title="citizenlablogo"><img class="alignright size-medium wp-image-776" title="citizenlablogo" src="http://voiceontheweb.biz/wp-content/uploads/2008/11/citizenlablogo.jpg" alt="citizenlablogo TOM Skype Breach: Answers to Phils Questions from 2006 SJ Post" width="200" height="61" /></a><em>This is the third of four posts resulting from an interview with Nart Villeneuve, principle investigator of the Citizen Lab report &#8220;Breaching Trust&#8221;.</em></p>
<p>Two weeks ago Phil republished <a href="http://skypejournal.com/2008/10/tom-skype-breach-questions-from-2006.html">an April 2006 Skype Journal post with about sixteen questions</a> related to the TOM-Skype security breach discovered by Nart. My interview provided answers to several of these questions but I ran them by Nart for more completeness, where an answer or response was feasible.</p>
<p>1. Is TOM only filtering chats where at least one of the callers&#8217; accounts were signed up by TOM Online?</p>
<p>A: One party must have the TOM-Skpe client installed. For example, if you (a normal skype user) sign in via a friends Tom_Skype client you&#8217;ll be filtered. If you (tom user) sign in on a normal Skype client, you won&#8217;t be filtered.</p>
<p>2. Will TOM filter chats if both parties are Chinese nationals but outside the PRC, say traveling in the US?</p>
<p>A: It is all dependent on which client software is installed. If you are using TOM-Skype you&#8217;ll be filtered no matter where you are (although the degree to which you are filtered may be dependent on your IP address). TOM-Skype would definitely have the Call Detail Record associated with the call.</p>
<p>3. Is TOM only filtering conversations where at least one of the parties are using the custom [TOM-Skype] version of the Skype client written for the joint venture?</p>
<p>A: Yes</p>
<p>4. Will TOM filter conversations using the TOM client being used by non-PRC nationals who are outside of China?</p>
<p>A: Since you have a TOM-Skype client here, Yes.</p>
<p>5. Does TOM&#8217;s contract with Skype provide for disclosure to Skype and Skype users when their information is provided to a government official? Not at this time.</p>
<p>A: I don&#8217;t know. It would be nice to have a Chinese speaker read the EULA you agree to on the install.</p>
<p>6. Are records of what the filter does kept? If so, by whom? Does Skype have or keep copies of those records?</p>
<p>A: Yes: TOM-Skype’s servers: unknown.</p>
<p>7. Does the filtering mechanism use a list of keywords? If so, is the list public? May I have a copy? Who has the list? How often does it change?</p>
<p>A: There is an encrypted keyfile that the TOM-Skype client downloads that I believe contains the keywords. There are also a few entries from the keyfile hardcoded in skype.exe (TOM-Skype version)</p>
<p>8. Are the keywords only in Simplified Chinese or are they in other languages too?</p>
<p>A: All languages but 60% English and 40% Chinese for the majority of conversations. English appears to be swear words, Chinese appears to be political.</p>
<p>9. Is China the only country where Skype and Skype&#8217;s partner have set up filtering? Have you done any testing for any other countries?</p>
<p>A: I haven&#8217;t tested any others.</p>
<p>10. Do all Skype chats have the potential for a hidden participant, whether human or a robot? ??</p>
<p>A: I don&#8217;t know.</p>
<p>11. Are filenames for transfer subject to filtering?</p>
<p>A: There are logged messages that are essentially the &#8220;this file was shared with participants of this conversation&#8221; message.</p>
<p>12. Are people&#8217;s names among the keywords?</p>
<p>A: Possibly SkypeID&#8217;s (but not real names), but also names of Chinese political people e.g. Hu Jintao</p>
<p>13. Are the content of files transferred via Skype also subject to filtering?</p>
<p>A: Unknown.</p>
<p>14.. Does Skype encrypt end-to-end the IMs that are subject to filtering? ??</p>
<p>A: Yes. TOM added an addition layer to the client that uploads the messages.</p>
<p>15. In a multiparty, multinational chat, can I as an American citizen have my text to a British subject filtered if someone from Shanghai is in that chat too?</p>
<p>A: I am not sure about it being filtered (such as not to be displayed in the recipient&#8217;s chat window) but it can be logged.</p>
<p class="MsoPlainText">16. Are audio conversations, where at least one party is in China, being listened to, filtered or recorded?</p>
<p>A: Only the Call Detail Record, there appears to be no interception of the voice stream.</p>
<p>17. Are all calls filtered, or only if users meet certain criteria, or are conversations selected for filtering randomly?</p>
<p>A: Other than the call detail record I don&#8217;t have evidence that suggests the content of voice calls were being filtered or monitored, but I wouldn&#8217;t rule it out as a possibility.</p>
<p>Bottom Line: If your chat conversation includes someone using TOM-Skype, you can assume there may be filtering of chat messages and/or logging of Call Detail Records. Conversations where all participants are using the normal Skype client cannot be filtered or logged.</p>
<p>Next post: <a title="Nart's Recommendations to Skype" href="http://voiceontheweb.biz/2008/10/tom-skype-breach-narts-recommendations-to-skype/" target="_blank">Nart&#8217;s recommendations to Skype</a>.</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.voiceontheweb.biz/skype-world/skype-ecosystem/skype-partner-solutions/tom-skype-breach-answers-to-phils-questions-from-2006-sj-post/' addthis:title='TOM-Skype Breach: Answers to Phil&#8217;s Questions from 2006 SJ Post '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.voiceontheweb.biz/skype-world/skype-ecosystem/skype-partner-solutions/tom-skype-breach-answers-to-phils-questions-from-2006-sj-post/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TOM-Skype Breach: The Citizen Lab</title>
		<link>http://www.voiceontheweb.biz/skype-world/skype-ecosystem/skype-partner-solutions/tom-skype-breach-the-citizen-lab/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=tom-skype-breach-the-citizen-lab</link>
		<comments>http://www.voiceontheweb.biz/skype-world/skype-ecosystem/skype-partner-solutions/tom-skype-breach-the-citizen-lab/#comments</comments>
		<pubDate>Thu, 16 Oct 2008 12:35:37 +0000</pubDate>
		<dc:creator>Jim Courtney</dc:creator>
				<category><![CDATA[Communications News]]></category>
		<category><![CDATA[Service Providers]]></category>
		<category><![CDATA[Skype News]]></category>
		<category><![CDATA[Skype Operations]]></category>
		<category><![CDATA[Skype Partner Solutions]]></category>
		<category><![CDATA[Using Skype]]></category>
		<category><![CDATA[Citizen Lab]]></category>
		<category><![CDATA[Nart Villeneuve]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Regulation]]></category>
		<category><![CDATA[screening]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[TOMSkype Breach08]]></category>

		<guid isPermaLink="false">http://voiceontheweb.biz/?p=757</guid>
		<description><![CDATA[This is the second of four posts resulting from an interview with Nart Villeneuve, principle investigator of the Citizen Lab report &#8220;Breaching Trust&#8221;. After discussing the report itself and some of the follow up activity, we went on to talk about The Citizen Lab, its mission and its activities. From their own website they are [...]]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.voiceontheweb.biz/skype-world/skype-ecosystem/skype-partner-solutions/tom-skype-breach-the-citizen-lab/' addthis:title='TOM-Skype Breach: The Citizen Lab '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><p><em>This is the second of four posts resulting from an interview with Nart Villeneuve, principle investigator of the Citizen Lab report &#8220;Breaching Trust&#8221;.</em></p>
<p><img class="alignright" style="float: right;" src="http://voiceontheweb.biz/wp-content/uploads/2008/11/protectthenet240px.jpg" alt="protectthenet240px TOM Skype Breach: The Citizen Lab" width="240" height="400" title="TOM Skype Breach: The Citizen Lab" />After <a href="http://voiceontheweb.biz/2008/10/tom-skype-breach-meeting-the-primary-investigator/">discussing the report itself and some of the follow up activity</a>, we went on to talk about <a href="http://www.citizenlab.org/">The Citizen Lab</a>, its mission and its activities. From their own website they are <em>&#8220;focusing on advanced research and development at the intersection of digital media and world civic politics&#8221;</em>. Nart described their activity as research on the politics of technology.</p>
<p>Under the leadership of Professor <a href="http://deibert.citizenlab.org/">Ronald Diebert</a>, their activities are carried out by graduate students with an undergraduate degree in either computer science or political science who join the lab to build up expertise in the other discipline while carrying out their research. They explore issues using their strong understanding of technology to &#8220;lift the hood&#8221; behind various politically and/or economically motivated intervention of web-based information exchange by governments and other agencies.</p>
<p>Assisted by a worldwide network of volunteers and a check list of relevant websites, they can develop a sense of the content that governments are censoring. According to Nart, all governments do some form of surveillance but definitely not to equal levels of resulting actions. At one extreme one finds outright blocking of content but the UAE has economic motivation to block Skype to protect a local communications monopoly. Apparently the Saudis are most interested in blocking porn. China obviously allows &#8220;uncensored&#8221; content to pass through but we are aware that Skype Journal is often blocked.</p>
<p>They will look at filtering techniques used by various countries, the type of content being blocked and try to determine the &#8220;local&#8221; government&#8217;s policy environment in which filtering is taking place. At this point in time most filtering addresses websites but gradually some countries are moving into screening applications (as we have seen with TOM-Skype). There is also &#8220;social filtering&#8221; censorship activity that involves blocking of porn, drugs and gambling.</p>
<p>At this point companies, such as Google, Microsoft and Yahoo, are modifying their products to address various &#8220;local&#8221; issues. For instance, Google has modified their process for enquiries from designated countries to &#8220;pre-filter&#8221; results delivered from their own servers in the U.S.. But then they put out a notification for &#8220;filtered&#8221; results with the wording for some search results: &#8220;to comply with local law, some results are not displayed&#8221;. On the other hand Google will not offer GMail accounts with a &#8220;.cn&#8221; domain name and does not make Blogger available in China.</p>
<p>The Citizen Lab also participates in a broader effort to develop guidelines for Internet companies operating in China. But, given that has much broader implications, it will be the subject of another post.</p>
<p>Next post: <a title="Answers to Phil's Questions" href="http://voiceontheweb.biz/2008/10/tom-skype-breach-answers-to-phils-questions-from-2006-sj-post/" target="_blank">Answers to Phil&#8217;s Questions</a></p>
<p><small>Tags: <a rel="tag" href="http://technorati.com/tag/Citizen+Lab">Citizen Lab</a>, <a rel="tag" href="http://technorati.com/tag/censor">censor</a>, <a rel="tag" href="http://technorati.com/tag/filter">filter</a>, <a rel="tag" href="http://technorati.com/tag/Nart+Villeneuve">Nart Villeneuve</a>, <a rel="tag" href="http://technorati.com/tag/Ronald+Diebert">Ronald Diebert</a></small></p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.voiceontheweb.biz/skype-world/skype-ecosystem/skype-partner-solutions/tom-skype-breach-the-citizen-lab/' addthis:title='TOM-Skype Breach: The Citizen Lab '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.voiceontheweb.biz/skype-world/skype-ecosystem/skype-partner-solutions/tom-skype-breach-the-citizen-lab/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>TOM-Skype Breach: Meeting the Primary Investigator</title>
		<link>http://www.voiceontheweb.biz/skype-world/skype-ecosystem/skype-partner-solutions/tom-skype-breach-meeting-the-primary-investigator/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=tom-skype-breach-meeting-the-primary-investigator</link>
		<comments>http://www.voiceontheweb.biz/skype-world/skype-ecosystem/skype-partner-solutions/tom-skype-breach-meeting-the-primary-investigator/#comments</comments>
		<pubDate>Mon, 13 Oct 2008 01:54:29 +0000</pubDate>
		<dc:creator>Jim Courtney</dc:creator>
				<category><![CDATA[Communications News]]></category>
		<category><![CDATA[Service Providers]]></category>
		<category><![CDATA[Skype News]]></category>
		<category><![CDATA[Skype Operations]]></category>
		<category><![CDATA[Skype Partner Solutions]]></category>
		<category><![CDATA[Using Skype]]></category>
		<category><![CDATA[Citizen Lab]]></category>
		<category><![CDATA[Nart Villeneuve]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[screening]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[TOM Online]]></category>
		<category><![CDATA[TOMSkype Breach08]]></category>

		<guid isPermaLink="false">http://voiceontheweb.biz/?p=755</guid>
		<description><![CDATA[This is the first of four posts resulting from an interview with Nart Villeneuve, principle investigator of the Citizen Lab report &#8220;Breaching Trust&#8221;. Last Tuesday afternoon I returned to a University of Toronto building I had last visited in its role as an engineering students&#8217; residence in the mid-1960&#8242;s. Abandoned as a residence in the [...]]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.voiceontheweb.biz/skype-world/skype-ecosystem/skype-partner-solutions/tom-skype-breach-meeting-the-primary-investigator/' addthis:title='TOM-Skype Breach: Meeting the Primary Investigator '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><p><img class="alignright" style="float: right;" src="http://voiceontheweb.biz/wp-content/uploads/2008/11/southhousedevonshire250px.jpg" alt="southhousedevonshire250px TOM Skype Breach: Meeting the Primary Investigator"  title="TOM Skype Breach: Meeting the Primary Investigator" /><em>This is the first of four posts resulting from an interview with Nart Villeneuve, principle investigator of the Citizen Lab report &#8220;Breaching Trust&#8221;.</em></p>
<p>Last Tuesday afternoon I returned to a University of Toronto building I had last visited in its role as an engineering students&#8217; residence in the mid-1960&#8242;s. Abandoned as a residence in the 1980&#8242;s, the building was <a href="http://www.utoronto.ca/cis/history/history.htm">restored in the late 1990&#8242;s to house the Munk Centre for International Studies</a>, when the university&#8217;s Centre for International Studies was designated as a strategic priority for future growth. In the basement of the former Devonshire Place South House, I found the <a href="http://www.citizenlab.org/">Citizen Lab</a>, &#8220;an interdisciplinary laboratory focusing on advanced research and development at the intersection of digital media and world civic politics&#8221;.</p>
<p><img class="alignleft" style="float: left;" src="http://voiceontheweb.biz/wp-content/uploads/2008/11/nartvcitizenlab2008-10-07180px.jpg" alt="nartvcitizenlab2008 10 07180px TOM Skype Breach: Meeting the Primary Investigator" width="180" height="240" title="TOM Skype Breach: Meeting the Primary Investigator" />I spent 90 minutes with Nart Villeneuve, the PhD student and Psiphon Fellow, who was the principle investigator resulting in the Citizen Lab&#8217;s recently published <a href="http://www.infowar-monitor.net/breachingtrust.pdf">&#8220;Breaching Trust: An analysis of surveillance and security practices of China&#8217;s TOM-Skype platform&#8221;</a>. We covered a wide range of issues related to this report, from the initial contact with New York Times through to the follow up activities as a result of the report&#8217;s release. We also discussed the broader mission of the Citizen Lab and some recommendations for how Skype should address the challenge of participating in the China market while making all parties aware that their conversation activity may be tracked.</p>
<p>Key points about the report and the follow up activity:</p>
<ul>
<li>A major issue to address in dealing with the media has been the confusion resulting because there is a need to separate out the security breach that allowed Nart to gather the data he has gathered and the functionality of the TOM-Skype servers resulting in the capture and logging of chat conversations and Skype calling activity. (There was no evidence of capturing voice calls themselves).</li>
<li>As a result of reporting this breach prior to release of the document to New York Times, the security breach itself has been closed but there is no evidence that the actual information capture activity has ceased. Nart has been checking daily to confirm that the security breach remains closed.</li>
<li>There was a period of several hours between finally establishing contact with someone at Skype who could initiate action to address the security breach and the final close down of the breach. During this time Nart observed blocking of read access to the directories but since he knew the file names he was still able to follow a reconfiguration of the web servers, removal of sensitive files, such as an encryption key, and disappearance of the log files such that they were not accessible.</li>
<li>While they have captured a significant quantity of call log data going back a year, they are being careful not to expose any of the detailed information which comprised both chat message logs and what amounts to call detail records for voice calls; more details are in the report itself. Basically they don&#8217;t want to compromise anyone individually.</li>
<li>While the log files are still under analysis, they have been encrypted while he continues to mine them for any additional information they may expose. Eventually it is his intention to destroy even these files.</li>
<li>Messages were about 40% Chinese, 60% English with a small smattering of other languages.</li>
<li>While it would be very difficult to reconstruct an entire conversation thread, as only each individual message was logged with no ready reference to other messages within the thread, they could build social graphs of conversing parties.</li>
<li>There are at least two versions of the TOM-Skype client: a normal version and a second version with additional features such as a Baidu Toolbar; however the promote.dll module in this can trigger off anti-virus scanners such as Norton.</li>
<li>Other evidence that the servers had been compromised was the discovery that the servers were hosting &#8220;pirate&#8221; movies and had the appropriate software to support Bit Torrent transfers.</li>
</ul>
<p>Nart had three definite recommendations for Skype; we also covered the broader issue of global enterprises doing business in China. These will be covered in future posts.</p>
<p>Next post: <a title="Citizen Lab Overview" href="http://voiceontheweb.biz/2008/10/tom-skype-breach-the-citizen-lab/" target="_blank">The Citizen Lab: Its broader mission and findings</a>.</p>
<p><small>Tags: <a rel="tag" href="http://technorati.com/tag/Skype">Skype</a>, <a rel="tag" href="http://technorati.com/tag/Citizen+Lab">Citizen Lab</a>, <a rel="tag" href="http://technorati.com/tag/Breaching+Trust">Breaching Trust</a>, <a rel="tag" href="http://technorati.com/tag/TOM+Online">TOM Online</a>, <a rel="tag" href="http://technorati.com/tag/TOM-Skype">TOM-Skype</a>, <a rel="tag" href="http://technorati.com/tag/Nart+Villeneuve">Nart Villeneuve</a>, <a rel="tag" href="http://technorati.com/tag/Munk+Centre+for+International+Studies">Munk Centre for International Studies</a></small></p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.voiceontheweb.biz/skype-world/skype-ecosystem/skype-partner-solutions/tom-skype-breach-meeting-the-primary-investigator/' addthis:title='TOM-Skype Breach: Meeting the Primary Investigator '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.voiceontheweb.biz/skype-world/skype-ecosystem/skype-partner-solutions/tom-skype-breach-meeting-the-primary-investigator/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Nart Villeneuve&#8217;s Q&amp;A on TOM-Skype&#8217;s Firewall Breach</title>
		<link>http://www.voiceontheweb.biz/skype-world/skype-llc/skype-news-skype-llc-skype-world-2/nart-villeneuves-qa-on-tom-skypes-firewall-breach/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=nart-villeneuves-qa-on-tom-skypes-firewall-breach</link>
		<comments>http://www.voiceontheweb.biz/skype-world/skype-llc/skype-news-skype-llc-skype-world-2/nart-villeneuves-qa-on-tom-skypes-firewall-breach/#comments</comments>
		<pubDate>Sun, 05 Oct 2008 11:57:00 +0000</pubDate>
		<dc:creator>Jim Courtney</dc:creator>
				<category><![CDATA[Communications News]]></category>
		<category><![CDATA[Service Providers]]></category>
		<category><![CDATA[Skype News]]></category>
		<category><![CDATA[Skype Operations]]></category>
		<category><![CDATA[Using Skype]]></category>
		<category><![CDATA[Citizen Lab]]></category>
		<category><![CDATA[Skype]]></category>
		<category><![CDATA[Skype Vulnerability]]></category>
		<category><![CDATA[TOMSkype Breach08]]></category>

		<guid isPermaLink="false">http://voiceontheweb.biz/?p=752</guid>
		<description><![CDATA[Internet Censorship Explorer Nart Villeneuve has been getting lots of questions about his &#8220;Breaching Trust&#8221; report and issued a Q&#38;A that answers some common questions. Initially he describes how he determined that messages containing key words were being uploaded to a web server. (The technologically curious can get the answer through accessing the link.) He [...]]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.voiceontheweb.biz/skype-world/skype-llc/skype-news-skype-llc-skype-world-2/nart-villeneuves-qa-on-tom-skypes-firewall-breach/' addthis:title='Nart Villeneuve&#8217;s Q&amp;A on TOM-Skype&#8217;s Firewall Breach '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><p><img class="alignright" style="float: right;" src="http://voiceontheweb.biz/wp-content/uploads/2008/11/nartvcitizenlab2008-10-07180px.jpg" alt="nartvcitizenlab2008 10 07180px Nart Villeneuves Q&A on TOM Skypes Firewall Breach" width="180" height="240" title="Nart Villeneuves Q&A on TOM Skypes Firewall Breach" />Internet Censorship Explorer <a href="http://www.nartv.org/">Nart Villeneuve</a> has been getting lots of questions about his &#8220;Breaching Trust&#8221; report and <a href="http://www.nartv.org/2008/10/02/tom-skype-q-a/">issued a Q&amp;A</a> that answers some common questions. Initially he describes how he determined that messages containing key words were being uploaded to a web server. (The technologically curious can get the answer through accessing the link.) He then goes on to say:</p>
<blockquote><p><strong>Is “normal” Skype affected?</strong></p>
<p>No. The Skype software downloaded from skype.com is not affected by the behavior. The only time “normal” Skype users are affected is when they communicate with TOM-Skype users.</p>
<p><strong>What is TOM-Skype and what is the difference between it and Skype?</strong></p>
<p>If you go to www.skype.com from China, you are redirected to skype.tom.com — so that’s [the] version most Chinese people will use.</p>
<p>In 2004 Skype developed a relationship with TOM Online, a leading wireless provider in China, and announced a joint venture in 2005. Skype and TOM Online produced a special version of the Skype software, known as TOM-Skype, for use in China.</p>
<p><strong>What is Skype saying, have they said anything to you?</strong></p>
<p>I contacted Skype to have the security issue fixed before the report was released. So, they have configured the servers so that one can no longer view the logs and they have deleted sensitive files, such as the one containing the encryption key. Other than that contact, I’ve only seen the statements they’ve made to reporters.</p></blockquote>
<p>The irony here is that if I find someone using the &#8220;F&#8221; word inappropriately, at my discretion, they may be deleted from my Facebook friends or Twitter contacts. In one case I reported the use to the person&#8217;s parent; that person continues to be a Facebook friend but now posts without the expletives. The paranoid in me could ask &#8220;are the Chinese trying to clean up the expression of the English language?&#8221;</p>
<p>In closing, I would recall that <a href="http://webguide.net.nz/2007/tibet-protesters-combine-cellphones-skype-and-youtube/">Skype was involved as an element of the process</a> in getting out to the world the message when <a href="http://beijingwideopen.org/2007/08/07/free-tibet-on-the-great-wall/">some &#8220;Free Tibet&#8221; demonstrators put a banner up</a> on the Great Wall of China last spring.</p>
<p>Hat tip to <a href="http://rconversation.blogs.com/rconversation/2008/10/skype-messes-up.html?cid=133457251#comments">Rebecca MacKinnon</a> for pointing to this Q&amp;A. As mentioned in my comment to her post, for the first time in its five year history, we have seen <a title="Tom-Skype Breach: Josh Silverman Response" href="http://share.skype.com/sites/en/2008/10/skype_president_addresses_chin.html" target="_self">a timely response in a crisis situation directly from the top executive at Skype</a>; hopefully this reflects on the new directions and attitude Skype&#8217;s new management team is taking in becoming more transparent with the public. Of course, along with the reported dialogue between Nart and Skype personnel, it means all the technology speculators out there have no opportunity to exercise their minds by delving into the (non)-complexity of how this was detected and corrected. But the blogosphere will survive; other issues will be taken up.</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.voiceontheweb.biz/skype-world/skype-llc/skype-news-skype-llc-skype-world-2/nart-villeneuves-qa-on-tom-skypes-firewall-breach/' addthis:title='Nart Villeneuve&#8217;s Q&amp;A on TOM-Skype&#8217;s Firewall Breach '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.voiceontheweb.biz/skype-world/skype-llc/skype-news-skype-llc-skype-world-2/nart-villeneuves-qa-on-tom-skypes-firewall-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Story Behind the Story: How a Canadian cracked the Great Firewall of China</title>
		<link>http://www.voiceontheweb.biz/skype-world/skype-software/the-story-behind-the-story-how-a-canadian-cracked-the-great-firewall-of-china/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-story-behind-the-story-how-a-canadian-cracked-the-great-firewall-of-china</link>
		<comments>http://www.voiceontheweb.biz/skype-world/skype-software/the-story-behind-the-story-how-a-canadian-cracked-the-great-firewall-of-china/#comments</comments>
		<pubDate>Fri, 03 Oct 2008 12:54:31 +0000</pubDate>
		<dc:creator>Jim Courtney</dc:creator>
				<category><![CDATA[Communications News]]></category>
		<category><![CDATA[Service Providers]]></category>
		<category><![CDATA[Skype Software]]></category>
		<category><![CDATA[Using Skype]]></category>
		<category><![CDATA[Citizen Lab]]></category>
		<category><![CDATA[Instant Messaging]]></category>
		<category><![CDATA[Josh Silverman]]></category>
		<category><![CDATA[Nart Villeneuve]]></category>
		<category><![CDATA[politics]]></category>
		<category><![CDATA[Regulation]]></category>
		<category><![CDATA[Skype PR]]></category>
		<category><![CDATA[TOMSkype Breach08]]></category>
		<category><![CDATA[Yahoo]]></category>

		<guid isPermaLink="false">http://voiceontheweb.biz/?p=749</guid>
		<description><![CDATA[As a four time graduate of the University of Toronto, I am glad to see the atmosphere for investigative research is thriving at my alma mater. A researcher at their unique Citizen Lab, &#8220;focusing on advanced research and development at the intersection of digital media and world civic politics&#8221;, is responsible for uncovering the Tom-Skype [...]]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.voiceontheweb.biz/skype-world/skype-software/the-story-behind-the-story-how-a-canadian-cracked-the-great-firewall-of-china/' addthis:title='The Story Behind the Story: How a Canadian cracked the Great Firewall of China '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><p><img class="alignright size-medium wp-image-776" title="citizenlablogo" src="http://voiceontheweb.biz/wp-content/uploads/2008/11/citizenlablogo.jpg" alt="citizenlablogo The Story Behind the Story: How a Canadian cracked the Great Firewall of China" width="200" height="61" />As a four time graduate of the University of Toronto, I am glad to see the atmosphere for investigative research is thriving at my alma mater. A researcher at their unique <a href="http://www.citizenlab.org/">Citizen Lab</a>, &#8220;focusing on advanced research and development at the intersection of digital media and world civic politics&#8221;, is responsible for uncovering the Tom-Skype security breach that has widespread coverage.</p>
<p>Globe and Mail reporter Matt Hartley has obviously gone to the lab for an interview with researcher Nart Villeneuve for his article in today&#8217;s editions: <a href="http://www.theglobeandmail.com/servlet/story/RTGAM.20081003.wrskype03/BNStory/Technology/home">How a Canadian cracked the Great Firewall of China</a>. &#8230;. the irony of where &#8220;lost passwords&#8221; can lead you:</p>
<blockquote><p>When he couldn&#8217;t remember the password to his Chinese MySpace account he decided to take a look at Skype.</p>
<p>&#8230;Using a TOM-Skype account on one computer and a regular Skype account on a nearby laptop, Mr. Villeneuve would type a word into one computer and see if the other computer received the message, to see what information would be filtered out by the service&#8217;s censorship tools. When he typed in a common four-letter expletive and hit send, it didn&#8217;t show up on the other computer. But he noticed something else.</p></blockquote>
<p><a href="http://www.theglobeandmail.com/servlet/story/RTGAM.20081003.wrskype03/BNStory/Technology/home">Read on.</a> Further along Matt reports:</p>
<blockquote><p>After he contacted Skype on Wednesday to inform them of the breach, the company moved quickly to plug the holes in the TOM-Skype servers, Mr. Villeneuve said.</p></blockquote>
<p>And, as Phil has already reported, Skype President <a href="http://share.skype.com/sites/en/2008/10/skype_president_addresses_chin.html">Josh Silverman responds here</a>, including this comment:</p>
<blockquote><p>It&#8217;s important to remind everybody that the issues highlighted in yesterday&#8217;s <a href="http://www.nartv.org/mirror/breachingtrust.pdf">Information Warfare Monitor / ONI Asia report</a> refer only to communications in which one or more parties are using TOM software to conduct instant messaging. It does not affect communications where all parties are using standard Skype software. Skype-to-Skype communications are, and always have been, completely secure and private.</p></blockquote>
<p><a href="http://www.nytimes.com/2008/10/02/technology/internet/02skype.html?adxnnl=1&amp;ref=business&amp;pagewanted=print&amp;adxnnlx=1223036274-k68vxpA0L9A2yas9wI0v9g">New York Times, Oct. 2</a> (registration required)</p>
<p><a href="http://online.wsj.com/article/SB122291621892397279.html">Wall Street Journal</a> (may encounter a walled garden), noting that TOM-Skype has 69 million users, places this story in the perspective of other &#8220;Doing business in China&#8221; stories involving Microsoft, Google and Yahoo.</p>
<p style="color:#008;text-align:right;"><small><em>Powered by</em> <a href="http://www.qumana.com/">Qumana</a></small></p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.voiceontheweb.biz/skype-world/skype-software/the-story-behind-the-story-how-a-canadian-cracked-the-great-firewall-of-china/' addthis:title='The Story Behind the Story: How a Canadian cracked the Great Firewall of China '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.voiceontheweb.biz/skype-world/skype-software/the-story-behind-the-story-how-a-canadian-cracked-the-great-firewall-of-china/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: enhanced
Database Caching 1/33 queries in 0.028 seconds using disk: basic
Object Caching 1527/1606 objects using disk: basic

Served from: www.voiceontheweb.biz @ 2012-02-09 00:47:12 -->
