Posts tagged ‘Censorship’

Krebs on Security: Chinese VPN Service as Attack Platform?

This post was syndicated from: Krebs on Security and was written by: BrianKrebs. Original post: at Krebs on Security

Hardly a week goes by without a news story about state-sponsored Chinese cyberspies breaking into Fortune 500 companies to steal intellectual property, personal data and other invaluable assets. Now, researchers say they’ve unearthed evidence that some of the same Chinese hackers also have been selling access to compromised computers within those companies to help perpetuate future breaches.

The so-called “Great Firewall of China” is an effort by the Chinese government to block citizens from accessing specific content and Web sites that the government has deemed objectionable. Consequently, many Chinese seek to evade such censorship by turning to virtual private network or “VPN” services that allow users to tunnel their Internet connections to locations beyond the control of the Great Firewall.

terracottavpn

Security experts at RSA Research say they’ve identified an archipelago of Chinese-language virtual private network (VPN) services marketed to Chinese online gamers and those wishing to evade censorship, but which also appear to be used as an active platform for launching attacks on non-Chinese corporations while obscuring the origins of the attackers.

Dubbed by RSA as “Terracotta VPN” (a reference to the Chinese Terracotta Army), this satellite array of VPN services “may represent the first exposure of a PRC-based VPN operation that maliciously, efficiently and rapidly enlists vulnerable servers around the world,” the company said in a report released today.

The hacker group thought to be using Terracotta to launch and hide attacks is known by a number of code names, including the “Shell_Crew” and “Deep Panda.” Security experts have tied this Chinese espionage gang to some of the largest data breaches in U.S. history, including the recent attack on the U.S. Office of Personnel Management, as well as the breaches at U.S. healthcare insurers Anthem and Premera.

According to RSA, Terracotta VPN has more than 1,500 nodes around the world where users can pop up on the Internet. Many of those locations appear to be little more than servers at Internet service providers in the United States, Korea, Japan and elsewhere that offer cheap virtual private servers.

But RSA researchers said they discovered that many of Terracotta’s exit nodes were compromised Windows servers that were “harvested” without the victims’ knowledge or permission, including systems at a Fortune 500 hotel chain; a hi-tech manufacturer; a law firm; a doctor’s office; and a county government of a U.S. state.

The report steps through a forensics analysis that RSA conducted on one of the compromised VPN systems, tracking each step the intruders took to break into the server and ultimately enlist the system as part of the Terracotta VPN network.

“All of the compromised systems, confirmed through victim-communication by RSA Research, are Windows servers,” the company wrote. “RSA Research suspects that Terracotta is targeting vulnerable Windows servers because this platform includes VPN services that can be configured quickly (in a matter of seconds).”

RSA says suspected nation-state actors have leveraged at least 52 Terracotta VPN nodes to exploit sensitive targets among Western government and commercial organizations. The company said it received a specific report from a large defense contractor concerning 27 different Terracotta VPN node Internet addresses that were used to send phishing emails targeting users in their organization.

“Out of the thirteen different IP addresses used during this campaign against this one (APT) target, eleven (85%) were associated with Terracotta VPN nodes,” RSA wrote of one cyber espionage campaign it investigated. “Perhaps one of the benefits of using Terracotta for Advanced Threat Actors is that their espionage related network traffic can blend-in with ‘otherwise-legitimate’ VPN traffic.”

DIGGING DEEPER

RSA’s report includes a single screen shot of software used by one of the commercial VPN services marketed on Chinese sites and tied to the Terracotta network, but for me this was just a tease: I wanted a closer look at this network, yet RSA (or more likely, the company’s lawyers) carefully omitted any information in its report that would make it easy to locate the sites selling or offering the Terracotta VPN.

RSA said the Web sites advertising the VPN services are marketed on Chinese-language Web sites that are for the most part linked by common domain name registrant email addresses and are often hosted on the same infrastructure with the same basic Web content. Along those lines, the company did include one very useful tidbit in its report: A section designed to help companies detect servers that may be compromised warned that any Web servers seen phoning home to 8800free[dot]info should be considered hacked.

A lookup at Domaintools.com for the historic registration records on 8800free[dot]info show it was originally registered in 2010 to someone using the email address “xnt50@163.com.” Among the nine other domains registered to xnt50@163.com is 517jiasu[dot]cn, an archived version of which is available here.

Domaintools shows that in 2013 the registration record for 8800free[dot]info was changed to include the email address “jzbb@foxmail.com.” Helpfully, that email was used to register at least 39 other sites, including quite a few that are or were at one time advertising similar-looking VPN services.

Pivoting off the historic registration records for many of those sites turns up a long list of VPN sites registered to other interesting email addresses, including “adsyb@163.com,” “asdfyb@hotmail.com” and “itjsq@qq.com” (click the email addresses for a list of domains registered to each).

Armed with lists of dozens of VPN sites, it wasn’t hard to find several sites offering different VPN clients for download. I installed each on a carefully isolated virtual machine (don’t try this at home, kids!). Here’s one of those sites:

One of the sites offering the VPN software and service that RSA has dubbed "Terracotta."

A Google-translated version of one of the sites offering the VPN software and service that RSA has dubbed “Terracotta.”

All told, I managed to download, install and use at least three VPN clients from VPN service domains tied to the above-mentioned email addresses. The Chinese-language clients were remarkably similar in overall appearance and function, and listed exit nodes via tabs for several countries, including the Canada, Japan, South Korea and the United States, among others. Here is one of the VPN clients I played with in researching this story:

517vpnconnected

This one was far more difficult to use, and crashed repeatedly when I first tried to take it for a test drive:

us-vpn2

None of the VPN clients I tried would list the Internet addresses of the individual nodes. However, each node in the network can be discovered simply by running some type of network traffic monitoring tool in the background (I used Wireshark), and logging the address that is pinged when one clicks on a new connection.

RSA said it found more than 500 Terracotta servers that were U.S. based, but I must have gotten in on the fun after the company started notifying victim organizations because I found only a few dozen U.S.-based hosts in any of the VPN clients I checked. And most of the ones I did find that were based in the United States appeared to be virtual private servers at a handful of hosting companies.

The one exception I found was a VPN node tied to a dedicated Windows server for the Web site of a company in Michigan that manufactures custom-made chairs for offices, lounges and meeting rooms. That company did not return calls seeking comment.

In addition to the U.S.-based hosts, I managed to step through a huge number of systems based in South Korea. I didn’t have time to look through each record to see whether any of the Korean exit nodes were interesting, but here’s the list I came up with in case anyone is interested. I simply haven’t had time to look at and look up the rest of the clients in what RSA is calling the Terracotta network. Here’s a more simplified list of just the organizational names attached to each record.

Assuming RSA’s research is accurate (and I have no reason to doubt that it is) the idea of hackers selling access to hacked PCs for anonymity and stealth online is hardly a new one. In Sept. 2011, I wrote about how the Russian cybercriminals responsible for building the infamous TDSS botnet were selling access to computers sickened with the malware via a proxy service called AWMProxy, even allowing customers to pay for the access with PayPal, Visa and MasterCard.

It is, after all, incredibly common for malicious hackers to use systems they’ve hacked to help perpetrate future cybercrimes – particularly espionage attacks. A classified map of the United States obtained by NBC last week showing the victims of Chinese cyber espionage over the past five years lights up like so many exit nodes in a VPN network.

Source: NBC

Source: NBC

TorrentFreak: Anti-Web Blocking Site More Popular in the UK than Spotify & Skype

This post was syndicated from: TorrentFreak and was written by: Andy. Original post: at TorrentFreak

FCT tyFor citizens of the UK, web blocking is becoming a hot topic. Aside from the large and growing list of torrent, streaming and other downloading sites currently blocked by ISPs, netizens are now facing the specter of government enforced porn barriers.

That’s according to Prime Minister David Cameron, who this week fired off a broadside against adult content providers who he says are failing to control what other people’s children are viewing online.

“Our one nation government is working hard to make the internet a safer place for children, the next step in this campaign is to curb access to harmful pornographic content which is currently far too widely available,” the Prime Minister said. “I want to see age restrictions put into place or these websites will face being shut down.”

According to the government the UK’s top 10 adult sites account for over half (52%) of all site views so this is no trivial matter. The site’s aren’t mentioned by name so TF decided to look them up.

The most popular within the UK’s top 200 most-visited sites according to Alexa are Pornhub (#41), XHamster (#44), Xvideos (#47), RedTube (#92), TubeCup (#105) and YouPorn (#122). To give an idea of scale, PornHub is more popular than Netflix and YouPorn is more visited than Vimeo.

However, while compiling this list we stumbled across something else that’s both surprising on one hand and utterly predictable on the other. Occupying the position of the UK’s 192nd most-visited site is Unblocked.pw, a service entirely dedicated to unblocking blocked websites.

Breaking the top 200 is no mean feat for any site, especially when one considers the competition at that level. Nevertheless, after existing for much less than a year, Unblocked.pw is already more popular in the UK than both Spotify (#194) and Skype (#195).

unblocked

While the skill of the site’s operator is no doubt a factor in its success, the huge popularity of Unblocked.pw is almost entirely down to restrictions being put in place by UK Internet service providers. Every time a blockade is put in place, Unblocked.pw provides a solution to the problem. It currently unblocks most major torrent and streaming sites plus the specialist ebook archives targeted in May.

“Fighting censorship has been the primary motivation behind running Unblocked,” the site’s operator informs TorrentFreak.

“It’s to show that whatever regulators do to censor things online, there will always be a way around it. The initial motivation came from when The Pirate Bay was blocked in the Netherlands. We set up Proxybay.co to maintain a list of Pirate Bay proxy sites and show people how to create their own.”

In respect of porn sites, Cameron’s office suggests that users could be required to validate their ages with a credit card, but the operators of overseas ‘tube’ sites will be extremely reluctant to introduce such measures since they will mess with their business models by reducing traffic and ad revenue.

That will leave web-blocking as Cameron’s only other option but as highlighted by the Open Rights Group, that won’t work.

“While the government can shut down UK-based sites, these are few in number and represent a tiny proportion of the global porn industry. Cameron needs to clarify how he wishes to achieve his goals, given that most porn sites are hosted abroad,” says ORG’s Jim Killock.

“To block them, the government would have to introduce a national firewall, which would censor sites for everyone, and would likely be widely circumvented.”

While there are currently no dedicated adult sites in Unblocked.pw’s repertoire (since none are currently blocked in the UK), there can be little doubt that if the UK government decides to order blockades, Unblocked and similar sites will quickly offer wordarounds.

If that does indeed transpire, expect a successful service to break the top 50 most-visited sites in the country while jockeying for rankings with the likes of Apple and WordPress. It’s a battle the government simply can’t win, but that won’t stop them from trying.

In the meantime the Internet continues to interpret censorship as damage, and routes around it.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and the best VPN services.

TorrentFreak: MPAA Emails Expose Dirty Media Attack Against Google

This post was syndicated from: TorrentFreak and was written by: Ernesto. Original post: at TorrentFreak

google-bayLate last year leaked documents revealed that the MPAA helped Mississippi Attorney General (AG) Jim Hood to revive SOPA-like censorship efforts in the United States.

In a retaliatory move Google sued the Attorney General, hoping to find out more about the secret plan. The company also demanded copies of internal communications from the MPAA which are now revealing how far the anti-Google camp planned to go.

Emails between the MPAA and two of AG Hood’s top lawyers include a proposal that outlines how the parties could attack Google. In particular, they aim to smear Google through an advanced PR campaign involving high-profile news outlets such as The Today Show and The Wall Street Journal.

With help from Comcast and News Corp, they planned to hire a PR firm to “attack” Google and others who resisted the planned anti-piracy efforts. To hide links to the MPAA and the AG’s office, this firm should be hired through a seemingly unaffiliated nonprofit organization, the emails suggest.

“This PR firm can be funded through a nonprofit dedicated to IP issues. The ‘live buys’ should be available for the media to see, followed by a segment the next day on the Today Show (David green can help with this),” the plan reads (pdf).

The Today Show feature would be followed up by a statement from a large Google investor calling on the company to do more to tackle the piracy problem.

“After the Today Show segment, you want to have a large investor of Google (George can help us determine that) come forward and say that Google needs to change its behavior/demand reform.”

In addition, a planted piece in the Wall Street Journal should suggest that Google’s stock would lose value if the company doesn’t give in to the demands.

“Next, you want NewsCorp to develop and place an editorial in the WSJ emphasizing that Google’s stock will lose value in the face of a sustained attack by AGs and noting some of the possible causes of action we have developed,” the plan notes.

mpaasmear

Previously, the MPAA accused Google of waging an “ongoing public relations war,” but the above shows that the Hollywood group is no different.

On top of the PR-campaign the plan also reveals details on how the parties would taint Google before the National Association of Attorneys General.

Through a series of live taped segments they would show how easy it is for minors to pirate R-rated movies, buy heroin and order an assault weapon with the help of Google’s search engine.

Finally, the plan includes a “final step” where Attorney General Hood would issue a civil investigatory demand to Google.

In its court filing (pdf) Google uses the information above to argue that the AG’s civil investigatory demand was not the basis of a legitimate investigation. Instead, it was another tool pressuring the company to implement more stringent anti-piracy measures.

Given this new information, Google hopes that the court will compel Fox, NBC and Viacom to hand over relevant internal documents, as they were “plainly privy” to the secretive campaign.

It’s now up to the judge to decide how to proceed, but based on the emails above, the MPAA and the AG’s office have some explaining to do.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and the best VPN services.

TorrentFreak: WordPress Rejects 43% Of All ‘Piracy’ Takedown Notices

This post was syndicated from: TorrentFreak and was written by: Ernesto. Original post: at TorrentFreak

wordpressAutomattic, the company behind the popular WordPress blogging platform, has seen a steady increase in DMCA takedown notices in recent years.

Some of these are legitimate, aimed at disabling access to copyright-infringing material. However, there are also many overbroad and abusive takedown notices which take up a lot of the company’s time and resources.

To give the public insight into the effort it takes to process the requests WordPress regularly publishes a transparency report. In the report WordPress outlines the number of DMCA takedown notices, but also how many were rejected due to inaccuracies or abuse.

“We work hard to make our DMCA process as fair, transparent, and balanced as possible, so we stringently review all notices we receive to quickly process valid infringement claims and push back on those that we see as abusive,” WordPress explains.

The latest update covering the past half year shows that 4,679 piracy takedown requests were received during this period. What stands out is that content was removed in barely half of the cases reported.

In total, 43% of all notices were rejected, either because they were incomplete or due to abuse. February and April were particularly bad months, as more than half of all notices were rejected.

According to WordPress’ figures more than 10% of the notices were abusive, and the company highlights some examples in its “Hall of Shame.”

WordPress’ most recent takedown statistics
wordpresstrans

For the first time WordPress has also released information on the organizations that submit the most complaints. Web Sheriff is listed on top here, followed by Audiolock and InternetSecurities.

Commenting on the new data Stephen Blythe, Community Guardian at Automattic, informs TF that they have seen a significant bump in rejections over the past months. This increase has two main causes.

“The first is that we rejected a large number of abusive takedown notifications from Web Sheriff that related to a single site. The second is that we are constantly refining our processes to ensure that we catch and push back on as many of these misuses as possible,” Blythe says.

WordPress currently doesn’t publish the takedown notices in full, but the company plans to highlight more abuse cases on its website in the coming months.

“We see numerous instances of abuse of the DMCA takedown process, on a regular basis. We plan to publish these via our transparency blog in future,” Blythe notes.

While the number of takedown requests WordPress receives pales in comparison to larger Internet services, it’s good to see that the company carefully reviews all notices to prevent unwarranted censorship. It will be interesting to see how the volume of request changes over time and whether copyright holders will improve their accuracy.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and the best VPN services.

TorrentFreak: Universal Asks Google to Censor “Furious 7″ IMDb Page, and More

This post was syndicated from: TorrentFreak and was written by: Ernesto. Original post: at TorrentFreak

face-palmIn an effort to make piracy less visible, copyright holders send dozens of millions of takedown notices to Google every month.

Unfortunately not all of these requests are as accurate as they should be.

Due to the high volume of often automated notices and the fact that copyright holders don’t check the validity of all requests, there are many questionable requests are made.

This week we spotted a dubious takedown notice from Universal Pictures, targeting several perfectly legitimate URLs. The movie studio’s tracking company apparently failed to properly screen the request as it lists the official IMDb page of the blockbuster Furious 7.

The Internet Movie Database is widely regarded as one of the top sources to find information on movies and having the page de-listed from Google certainly doesn’t help to prevent piracy.

Universal Pictures takedown request
fastimdb

Aside from Furious 7, the same notice targets “copyright infringing” links to the movie Hacker. Here, the movie studio also made an unfortunate mistake asking Google to remove a news article from Techdirt, covering the Hacking Team leak.

And while we’re on the topic of self censorship, it’s worth noting that Universal Pictures also asked Google, in a separate notice, to remove http://127.0.0.1 from the search results.

The mistakes were made by the French branch of the movie studio, which only recently began sending takedown notices to Google. The company has reported less than 200 URLs thus far including the mistakes above.

While Universal is the rightsholder, it’s worth noting the notices are sent by Trident Media Guard (TMG), the private company which also carried out file-sharing network monitoring for the French Government’s Hadopi scheme.

The good news is that Google hasn’t removed any of the inaccurately reported URLs just yet. The search engine is still validating the validity of the claims and will probably reject the requests.

In the meantime, Universal Pictures and TMG should reconsider their takedown campaign, or at least improve their monitoring tools.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and the best VPN services.

TorrentFreak: CloudFlare Forced to Censor Anti-Censorship Site

This post was syndicated from: TorrentFreak and was written by: Ernesto. Original post: at TorrentFreak

notresolvedLast May, Grooveshark shut down after settling with the RIAA. However, within days a new site was launched aiming to take its place.

The RIAA wasn’t happy with this development and quickly obtained an injunction, preventing various Internet service providers from offering their services to the site.

Through the lawsuit the companies hope to prevent further copyright infringements, but there is more at stake. Much more.

The case is also the first major test of how receptive the courts are to the notion of injunctions against hosting companies, domain name services, ISPs and search engines.

Fearing that these attempts may become commonplace several tech companies protested the injunction, including CloudFlare. The court order requires the CDN-service to ban all domain names that use the term “Grooveshark,” which the company believes is too broad.

This week CloudFlare informed the court that the order limits free-speech, impacting legitimate customers who use it for perfectly legitimate websites.

“CloudFlare has already been compelled by the injunction to deny service to at least one website that is plainly non-infringing, and to others that are arguably non-infringing and have no discernible connection with the Defendants in this case,” they write (pdf).

“This harm to CloudFlare’s business and potentially to customer’s businesses, and to the free speech rights of its customers, will continue without a modification of the Preliminary Injunction.”

As an example, CloudFlare says it had to terminate the account of “groovesharkcensorship.cf,” a site which protested the broad injunction as the screenshot below shows.

Groovesharkcensorship.cf, before CloudFlare took it offline
censorcomplaint

Under the injunction CloudFlare had no other option than to disable its services for the domain, rendering it inaccessible.

In an email, the company informed the affected user about its actions explaining that it’s not allowed to provide any services that use the Grooveshark trademark in a domain name.

CloudFlare’s email
censormail

According to CloudFlare many other legitimate sites may be at risk of being censored if the broad injunction is upheld.

Despite these protests, the record labels maintain the position that the measures are “entirely appropriate.” They argue that it’s up to CloudFlare to determine whether a domain name is infringing, and consult the record labels if there’s any doubt.

For its part, CloudFlare wants the court to modify the injunction so that they only have to target domain names which the record labels point out to them, instead of banning the word Grooveshark altogether.

Shortly before publishing this article the court ruled (pdf) on the dispute, largely in favor of CloudFlare.

In a ruling issued a few hours ago District Court Judge Alison Nathan clarifies that CloudFlare is no longer required to ban all Grooveshark-related domains. Instead, the record labels must alert the company to possibly infringing sites.

However, Judge Nathan adds that if CloudFlare has knowledge of an infringing domain name it is required to take action on its own.

So, in the end it appears that the censored anti-censorship site has served its purpose. At the time of writing it still remains offline, but this may change during the coming hours.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and the best VPN services.

TorrentFreak: Censoring Pirate Sites is Counterproductive, Research Finds

This post was syndicated from: TorrentFreak and was written by: Ernesto. Original post: at TorrentFreak

stop-blockedRather than taking operators to court, copyright holders are increasingly relying on Internet providers to block ‘pirate’ domains.

Courts all around the world have ordered Internet providers to block subscriber access to various pirate sites, and in Italy this process is formalized through telecoms regulator AGCOM.

The idea behind these blockades is that they help to decrease online piracy. However, research increasingly suggests that this aim is not being fulfilled. In fact, a new study shows that blocking attempts may actually be counterproductive.

To find out whether blocking efforts are effective, University of Padua professor Giorgio Clemente decided to run a comprehensive analysis, comparing traffic data before and after the measures were implemented.

The research uses the same methodology as an earlier MPAA-commissioned study by Incopro which examined UK blockades. However, instead of merely looking at the blocked domains, Professor Clemente also took domain name changes into account because site operators commonly switch domains to bypass censorship efforts.

The results are quite revealing and show that Government-sanctioned blockades actually increase traffic to the targeted sites.

“The blocking efforts of the Italian ISPs are all being thwarted,” Professor Celemente writes.

“The analyzed data shows that after a year the overall effects can be summarized as a significant increase in Italian search engine traffic to the targeted sites and a consequent increase in piracy rather than a decline,” he adds.

In many cases the websites simply switched to a new domain name to evade the blocking efforts. Cineblog01.net, for example, moved to a .li domain name and as a result of the attention the site received from the blocking efforts, search engine traffic spiked more than 1000%.

“AGCOM’s blocking measures have actually increased the site’s popularity, which went from 106,000 Italian search engine visitors in March 201 to 2,294,000 users a year later,” the report reads, adding that this caused a spike in piracy activity.

The same pattern was observed for other sites. Limetorrents, for example, saw Italian search engine traffic increase from 9,000 to 162,000 a few months later after, as shown below.

Limetorrents traffic increase
limeagcom

The measures also helped to promote previously unknown sites. TorrentDownloads had no Italian visits before the blocking measures but started to see traffic coming in after AGCOM put the site on its blocklist.

The full report lists a total of 27 sites which nearly all increased their visitor numbers. This leads to the overall conclusion that the time and money invested in the measures is wasted.

“The resources and energy which Internet providers put into the blocking efforts are completely unjustified, and so are the copyright protection activities of AGCOM, given the obvious ineffectiveness of the measures,” the report reads.

Professor Clemente notes that his research confirms a recent study by the European Commission’s Joint Research Centre, which reached a similar conclusion regarding the shutdown of the popular movie streaming portal Kino.to

Italian lawyer Fulvio Sarzana, who represented the owners of several blocked websites, says the report confirms what many people already expected.

“The research by the University of Padua shows what everyone already knows: administrative copyright enforcement by blocking access to websites is an unnecessary and harmful waste time,” he tells TF.

The controversial AGCOM measures are up for a review at the Italian Constitutional Court later this year which will look at whether they limit people’s right to free expression. If the court rules the measures unlawful, Sarzana says that the affected sites may be entitled to a substantial damage claim for being unfairly blocked.

However, taking the results of Professor Clemente into consideration there’s little damage to complain about.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and the best VPN services.

TorrentFreak: Israeli Court Lifts Ineffective Popcorn Time Ban

This post was syndicated from: TorrentFreak and was written by: Ernesto. Original post: at TorrentFreak

popcorntBranded a “Netflix for Pirates,” the Popcorn Time app quickly gathered a user base of millions of people over the past year.

The application has some of the major media giants shaking in their boots, including Netflix which sees the pirate app as a serious competitor.

In Israel, local anti-piracy group ZIRA took several Internet providers to court this year, with the goal to have several prominent Popcorn Time sites blocked. This effort resulted in an initial success when a preliminary injunction was granted in May.

However, after a careful review the Tel Aviv court has now reversed this decision. One of the arguments of the court is that blocking Popcorn Time domain names is relatively ineffective.

The court concluded that since the developers of the software can’t be tracked down, there’s nothing that prohibits them from launching new websites to render the blockade useless.

“Therefore, blockage or shutting down Popcorn Time sites does not guarantee that the application can no longer be downloaded,” the judgment reads.

In addition, the court points out that Popcorn Time applications that have been downloaded already will continue to work, even if the sites are blocked.

“This shows that the benefit of the requested measures is minimal, if any,” the verdict notes.

The Internet providers who protested the blocking requests further argued that the blockades would require a lot of resources and hurt their image, which the court largely agreed with.

“The cost of making ISPs some kind of censorship authority is at least equivalent, if not higher, than the cost of copyright infringement,” the verdict reads, mentioning that free competition and freedom of speech may be at risk.

Finally, the court gave ZIRA a slap on the wrist by pointing out that the requested blockade wasn’t as urgent as the copyright holders claimed, since Popcorn Time has been around for a long time.

“These sites, which presumably were visible to everyone, have been online for a long time. Given that, it seems that the applicant delayed the submission of the application which contradicts their urgency claim on the requested preliminary measures”, the judgment reads.

The outcome is a blow for ZIRA and the copyright holders they represent.

In addition to the negative outcome, the court also ordered the anti-piracy group to pay $1,060 to cover the legal fees of one ISP. The other ISPs settled the fees in question out of court.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and the best VPN services.

TorrentFreak: Police Let Seized ‘Pirate’ Domains Expire, Some Up For Sale

This post was syndicated from: TorrentFreak and was written by: Andy. Original post: at TorrentFreak

cityoflondonpoliceFor the past several years the Police Intellectual Property Crime Unit (PIPCU) has been at the forefront of Internet-focused anti-piracy activity in the UK. The government-funded unit has been responsible for several high-profile operations and has been praised by a broad range of entertainment industry companies.

After carrying out raids against the operators of dozens of sites, PIPCU likes to take control of their domains. They do this for two key reasons – one, so that the sites can no longer operate as they did before and two, so they can be used to ‘educate’ former users of the downed sites.

That ‘education’ takes place when visitors to the now-seized ‘pirate’ domains are confronted not with a torrent, proxy, streaming or links site, but a banner published by PIPCU themselves. It’s aim is to send a message that sites offering copyrighted content will be dealt with under the law and to suggest that their visitors have been noted.

Earlier comments by PIPCU suggest that its banner has been seen millions of times by people who tried to access a ‘pirate’ site but subsequently discovered that it no longer exists. Last month in an announcement on Twitter, the unit revealed that since Jul 2015 it has diverted more than 11m ‘pirate’ site visits.


While the hits continue to mount for many domains PIPCU has seized (or gained control over by forcing site operators or registrars into compliance), it’s now likely that the group’s educational efforts will reach a smaller audience. Tests carried out by TorrentFreak reveal that PIPCU has somehow lost influence over several previously controlled domains.

Instead of the now-familiar PIPCU ‘busted’ banner, visitors to a range of defunct sites are now greeted with expired, advert-laden or ‘for sale’ domains.

MP3lemon.org, for example, currently displays ads/affiliate links. The same goes for Boxingguru.tv, a domain that was linked to a high-profile PIPCU raid in 2014. Former proxies Katunblock.com and Fenopyreverse.info, plus former streaming links site Potlocker.re complete the batch.

boxing-guru

Other domains don’t carry ads but are instead listed for sale. They include former anti-censorship tool site Torrenticity.com, proxy index PirateReverse.info and H33T proxy h33tunblock.info.

The fate of the final set of domains is much less glamorous. Movie2KProxy.com, Movie4KProxy.com, EZTVProxy.net, Metricity.org, YIFYProxy.net and TorrentProxies.com all appear to have simply expired.

Whether these domains will be snapped up at the first opportunity or left to die will largely hinge on whether people believe they can make a profit from them. Some have already changed hands and are now being touted for a couple of thousand dollars each but others are lying in limbo.

In any event, none of these domains seem destined to display PIPCU’s banner in the future. Whether or not the unit cares right now is up for debate, but if any of the domains spring back into life with a ‘pirate’ mission, that could soon change.

Unlike Megaupload’s old domains they don’t appear linked to obvious scams, so that’s probably the main thing.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and the best VPN services.

TorrentFreak: Popcorn Time Blamed For Movie Streaming Piracy Explosion

This post was syndicated from: TorrentFreak and was written by: Andy. Original post: at TorrentFreak

Up until last year, downloading content using BitTorrent was an activity that needed a reasonable level of technical competence. In addition to choosing the correct software and setting everything up, users needed to make themselves familiar with any number torrent indexes and platforms.

Then along came Popcorn Time and simplified the process to the point that almost anyone can now download the software and access a wide range of (mostly) infringing content within minutes. Needless to say, the various forks of the software have been a thorn in the side of the movie and TV show industry ever since.

With complaints being made against the software in most western countries, it’s now Norway’s turn to make some noise. While the country has expressed concerns about the software in the past, a report published in June by consultancy firm Mediavision is adding fuel to the fire.

According to the company, which analyzes consumer behavior within the sphere of digital media, around 750,000 Norwegians from a five million population are now obtaining video from illegal sources, up 17% on the previous year. However, it is the manner in which they are doing it that’s causing additional concern. According to the researchers, illegal consumption of streaming content has doubled in the past year. And no prizes for guessing who anti-piracy groups are blaming.

“The reason for the increase in piracy is Popcorn Time,” says Rights Alliance Norway chief Willy Johansen.

“It is unfortunately an incredibly easy way to watch movies. But one should be aware that this is a criminal offense. We are now collecting the IP addresses of Norwegian users of Popcorn Time.”

While users will be disappointed to hear that they are being tracked by a Hollywood-backed anti-piracy outfit, the big question is what Rights Alliance will choose to do with that data. The group says their hand may be forced.

“We have hoped for the longest time that we do not have to take on the end-user. But it is clear that if this does not stop, we will have no choice. Most people are now aware that they are doing something illegal, but many continue because ‘everyone else is doing it’,” Johansen says.

Also on the horizon are lawsuits against local ISPs. Rights Alliance hopes that by obtaining a blocking injunction against Popcorn Time-affiliated sites and services, the problem might be brought under control. However, things aren’t straightforward.

“It takes time in the Norwegian legal system, so there is a protracted process,” Johansen notes.

“There is nothing that can be sent to the court today. But we’re working on it together with our attorneys to look into the possibility of getting this stopped through a lawsuit against broadband providers.”

After changes in the law two years ago, these kinds of injunctions were supposed to be easy for groups like Rights Alliance to obtain, but it appears there are still significant hurdles to overcome. Not only are there very stringent requirements in order to obtain an injunction, all expenses incurred must be paid by the plaintiff.

“No independent licensees in Norway have the opportunity [to get injunctions], because they do not have the finances to do so. If we are to stop something, it must be an overall industry behind the lawsuit. It requires a very detailed presentation of evidence, says Johansen.

Interestingly, however, the group has been working on getting an injunction against another site, most probably The Pirate Bay. The results should become evident in a few weeks.

“The case we’re working on already started before Popcorn Time existed. The problem is that evidence is so extensive that the whole Popcorn Time phenomenon arose during the time we spent gathering evidence from the previous service,” the Rights Alliance chief adds.

As usual, however, the industry isn’t getting much help from ISPs including Telenor, Norway’s largest provider.

“We wish to contribute by relating to parliamentary procedure adopted in such cases,” says Telenor director Tormod Sandstø.

“So the court must make decisions in individual cases, also we will of course abide by those decisions. As an Internet provider we will not be a censorship body.”

The news that Norway may target end users is disappointing. The country has all but eliminated music piracy yet still prefers anti-piracy aggression over business model changes in the video sector.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and the best VPN services.

TorrentFreak: VPN Providers Respond To Allegations of Data Leakage

This post was syndicated from: TorrentFreak and was written by: Andy. Original post: at TorrentFreak

vpn4lifeAs Internet users seek to bypass censorship, boost privacy and achieve a level of anonymity, VPN services have stepped in with commercial solutions to assist with these aims. The uptake among consumers has been impressive.

Reviews of VPN services are commonplace and usually base their ratings on price and speed. At TorrentFreak we examine many services annually, but with a focus on privacy issues instead.

Now a team of researchers from universities in London and Rome have published a paper titled A Glance through the VPN Looking Glass: IPv6 Leakage and DNS Hijacking in Commercial VPN clients. (pdf) after investigating 14 popular services on the market today.

“Our findings confirm the criticality of the current situation: many of these providers leak all, or a critical part of the user traffic in mildly adversarial environments. The reasons for these failings are diverse, not least the poorly defined, poorly explored nature of VPN usage, requirements and threat models,” the researchers write.

While noting that all providers are able to successfully send data through an encrypted tunnel, the paper claims that problems arise during the second stage of the VPN client’s operation: traffic redirection.

“The problem stems from the fact that routing tables are a resource that is concurrently managed by the operating system, which is unaware of the security requirements of the VPN client,” the researchers write.

This means that changes to the routing table (whether they are malicious or accidental) could result in traffic circumventing the VPN tunnel and leaking to other interfaces.

IPv6 VPN Traffic Leakage

“The vulnerability is driven by the fact that, whereas all VPN clients manipulate the IPv4 routing table, they tend to ignore the IPv6 routing table. No rules are added to redirect IPv6 traffic into the tunnel. This can result in all IPv6 traffic bypassing the VPN’s virtual interface,” the researchers explain.

vpn-1

As illustrated by the chart above, the paper claims that all desktop clients (except for those provided by Private Internet Access, Mullvad and VyprVPN) leaked “the entirety” of IPv6 traffic, while all providers except Astrill were vulnerable to IPv6 DNS hijacking attacks.

The paper was covered yesterday by The Register with the scary-sounding title “VPNs are so insecure you might as well wear a KICK ME sign” but without any input from the providers in question. We decided to contact a few of them for their take on the paper.

PureVPN told TF that they “take the security of our customers very seriously and thus, a dedicated team has been assigned to look into the matter.” Other providers had already received advanced notice of the paper.

“At least for AirVPN the paper is outdated,” AirVPN told TorrentFreak.

“We think that the researchers, who kindly sent the paper to us many months in advance and were warned about that, had no time to fix [the paper] before publication. There is nothing to worry about for AirVPN.”

“Current topology allows us to have the same IP address for VPN DNS server and VPN gateway, solving the vulnerability at its roots, months before the publication of the paper.”

TorGuard also knew of the whitepaper and have been working to address the issues it raises. The company adds that while The Register’s “the sky is falling” coverage of yesterday is “deceptive”, the study does illustrate the need for providers to stay vigilant. Specifically, TorGuard says that it has launched a new IPv6 leak prevention feature on Windows, Mac and Linux.

“Today we have released a new feature that will address this issue by giving users the option of capturing ALL IPv6 traffic and forcing it through the OpenVPN tunnel. During our testing this method proved highly effective in blocking potential IPv6 leaks, even in circumstances when these services were active or in use on the client’s machine,” the company reports.

On the DNS hijacking issue, TorGuard provides the following detail.

“It is important to note that the potential for this exploit only exists (in theory) if you are connected to a compromised WiFi network in which the attacker has gained full control of the router. If that is the case, DNS hijacking is only the beginning of one’s worries,” TorGuard notes.

“During our own testing of TorGuard’s OpenVPN app, we were unable to reproduce this when using private DNS servers because any DNS queries can only be accessed from within the tunnel itself.”

Noting that they released IPv6 Leak Protection in October 2013, leading VPN provider Private Internet Access told TorrentFreak that they feel the paper is lacking.

“While the article purported to be an unbiased and intricate look into the security offered by consumer VPN services, it was greatly flawed since the inputs or observations made by the researchers were inaccurate,” PIA said.

“While a scientific theory or scientific test can be proven by a logical formula or algorithm, if the observed or collected data is incorrect, the conclusion will be in error as well.”

PIA criticizes the report on a number of fronts, including incorrect claims about its DNS resolver.

“Contrary to the report, we have our own private DNS daemon running on the Choopa network. Additionally, the DNS server that is reported, while it is a real DNS resolver, is not the actual DNS that your system will use when connected to the VPN,” the company explains.

“Your DNS requests are handled by a local DNS resolver running on the VPN gateway you are connected to. This can be easily verified through a site like ipleak.net. Additionally… we do not allow our DNS servers to report IPv6 (AAAA records) results. We’re very serious about security and privacy.”

Finally, in a comprehensive response (now published here) in which it notes that its Windows client is safe, PIA commends the researchers for documenting the DNS hijacking method but criticizes how it was presented to the VPN community.

“The DNS Hijacking that the author describes [..] is something that has recently been brought to light by these researchers and we commend them on their discovery. Proper reporting routines would have been great, however. Shamefully, this is improper security disclosure,” PIA adds.

While non-IPv6 users have nothing to fear, all users looking for a simply fix can disable IPv6 by following instructions for Windows, Linux and Mac.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and the best VPN services.

TorrentFreak: Google Scolds MPAA’s “Cozy” Anti-Piracy Lobby in Court

This post was syndicated from: TorrentFreak and was written by: Ernesto. Original post: at TorrentFreak

googlepopLate last year leaked documents from the Sony hack revealed that the MPAA helped Mississippi Attorney General Jim Hood to revive SOPA-like censorship efforts in the United States.

In a retaliatory move Google sued the Attorney General, hoping to find out more about the secret plan. The company also demanded internal communication from the MPAA and its lawfirm Jenner & Block.

After the Hollywood group and its lawyers refused to provide all information Google asked for, a separate legal battle began with both sides using rather strong language to state their case.

The MPAA accused Google of facilitating piracy and objected to a request to transfer the case to Mississippi, where the underlying case was started. According to the movie industry group and its lawyers they are merely bystanders who want to resolve the matter in a Washington court.

This week Google responded to the MPAA opposition with a scathing reply, which outs the cozy relationship between the MPAA and the Attorney General’s office.

“Their rhetoric does not match reality,” Google responds (pdf) to the request not to transfer the case. “The MPAA and Jenner are no strangers to Mississippi.”

“The Subpoenaed Parties sought out Mississippi when they co-opted the state’s Attorney General for their anti-Google campaign. Documents withheld by the MPAA until last week reveal a stunning level of involvement in Mississippi’s affairs.”

According to Google it’s clear that the MPAA and its law firm were in “intimate contact” with the Attorney General, offered monetary donations, hosted fundraisers and also helped him to draft legal paperwork.

“According to the Subpoenaed Parties, they are strangers to Mississippi. But documents produced last week by the MPAA tell a very different story. The Subpoenaed Parties and their representatives made repeated visits to AG Hood’s office in Mississippi to guide his anti-Google work.”

“Even when they weren’t physically at AG Hood’s office, they may as well have been, getting together with him in Denver and Santa Monica and holding a fundraising dinner for him in New Orleans.”

And there is more. The emails the MPAA recently produced also reveal “remarkably cozy and constant communications” between the MPAA and the Attorney General’s office.

In one email the MPAA’s Brian Cohen greeted one of Hood’s staffers with “Hello my favorite” offering to share pictures of his vacation in New Zealand via Dropbox. In another email discussing a meeting with the AG’s staff, MPAA’s Cohen writes “OMG we spent 3 hours.”

favorite

According to Google the examples above clearly show that there’s a rather close relationship between the MPAA’s lobbyists and the Attorney General.

“This pattern of sustained, intimate contact is hardly the mark of a party that merely ‘communicated with Attorney General Hood’ ‘previously,’ as the MPAA characterizes itself.”

Throwing in a movie reference, Google further notes that transferring the case would be in line with Rule 45, which ties the subpoena to the Mississippi case.

“But it is not merely the Subpoenaed Parties’ starring role in the underlying events that warrants transfer of Google’s Motions to Compel to Judge Wingate in Mississippi; all of the Rule 45 factors support it as well,” Google notes.

The reply continues adding more support and arguments to transfer the case, using more strong language, and the sarcastic-aggressive tone continues throughout.

If we hadn’t seen enough evidence already, the filing makes it clear that the MPAA and Google are not on speaking terms, to say the least. And with the Attorney General case just getting started, things may get even worse.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and the best VPN services.

TorrentFreak: Surprise! VPN Provider Expects Victory in Site-Block Arms Race

This post was syndicated from: TorrentFreak and was written by: Andy. Original post: at TorrentFreak

networkAfter years of pressure but mere months of deliberations, yesterday the Australian government imposed a new copyright law on its citizens.

As soon as it receives the formality of royal assent, the Copyright Amendment (Online Infringement) Bill 2015 will enter into force and soon after it’s expected that rightsholders will make their first moves to have a site blocked.

After the passing of the law yesterday a lot of furious people took to the web, many decrying the censorship and filtering efforts of the Australian government. But despite the outcry there are others who are not only relaxed about the upcoming efforts but also stand to profit handsomely from them.

They are of course VPN providers, services setup to cut through web-blockades and similar efforts like a hot knife through butter. They’re already extremely popular in Australia due to their geo-unblocking abilities and will now do even more business as a result of the country’s new law.

However, there are still those that remain concerned over the future of VPNs and their status as site-blocking kryptonite. Might the government eventually run out of patience and do a U-turn on assurances they won’t tackle the technology by blocking? Would it matter, practically, if they did?

Robert Knapp, chief executive at CyberGhost, one of the more popular VPN providers, doesn’t think so. He is calm, taking developments completely in his stride, and foresees no threat to his business.

“We see in general the same that you see in nature if somebody tries to block a river floating – the water finds his way,” Knapp says.

Despite attempts by the Australian Greens to have VPNs exempted from the new law, it is unlikely that services who play by the rules (i.e do not promote their products for infringing purposes) will be blocked. However, if the authorities want to test the waters, companies like CyberGhost will be up for the challenge.

“They should also then realize with whom they play in the same league,” Knapp says.

“Maybe they do it [blocking], maybe they don’t do it, it’s kind of a technical race. So it’s our daily business. They might do it, we will find a way to keep our servers running.”

While most people understand that blocking a determined service provider could descend into an endless arms-race, rightsholders are also keenly aware of the political fallout from attacking legitimate technologies.

“We didn’t intend this law to be used specifically against VPN because there are many legitimate uses of VPN and the intention of the law is not to stop people using the internet for legitimate purposes,” a Foxtel spokesperson told Mumbrella this morning.

And herein lies the problem. By driving traffic underground, into the encrypted tunnels of VPNs, rightsholders now have even less of an idea of who is pirating what and from where. VPNs are a legitimate but “dual use” technology, one that can be used for privacy or indeed piracy purposes. It’s a giant loophole that will be difficult to close. Nevertheless, companies like Foxtel say they will keep an developments.

“We would obviously be concerned if it meant there was a hole in the law,” the spokesman said. “We will be monitoring how things go and see if there is a serious issue in the future.”

So what next for Australia’s blocking regime?

If history from the UK repeats itself (and there’s every reason to believe that it will), rightsholders will first take on a site that is guaranteed to tick every ‘pirate’ box. That forerunner is almost certain to be The Pirate Bay, a site that is not only located overseas as the legislation requires, but one that also has no respect for copyright. The fact that it has been blocked in plenty of other regions already will be the icing on the cake.

Once the case against The Pirate Bay is complete then other “structurally similar” sites will be tackled with relative ease and since none of their operators will be appearing in court to defend themselves, expect the process to be streamlined in favor of copyright holders.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and the best VPN services.

Lauren Weinstein's Blog: Why Google Must Stand Firm: Putin Pushes the Dangerous “Right To Be Forgotten” Further Into Lunatic Land

This post was syndicated from: Lauren Weinstein's Blog and was written by: Lauren. Original post: at Lauren Weinstein's Blog

A week ago, in my latest discussion of the nightmarish EU “Right To Be Forgotten” (RTBF), titled Just Say “NON!” – France Demands Right of Global Google Censorship, I once again emphasized the “camel’s nose under the tent” aspect of RTBF, and how we should have every expectation that Russia, China, and other repressive regimes would make similar demands and…

TorrentFreak: MPAA: Google Assists and Profits from Piracy

This post was syndicated from: TorrentFreak and was written by: Ernesto. Original post: at TorrentFreak

google-bayLate last year leaked documents from the Sony hack revealed that the MPAA helped Mississippi State Attorney General Hood to revive SOPA-esque censorship efforts in the United States.

In a retaliatory move Google sued the Attorney General, hoping to find out more about the secret effort. As part of these proceedings Google also demanded internal communication from the MPAA, but the Hollywood group has been hesitant to share these details.

After several subpoenas remained largely unanswered Google took the MPAA to court earlier this month. The search giant asked a Columbia federal court to ensure that the MPAA and its law firm Jenner & Block hands over the requested documents.

The MPAA and its law firm responded to the complaint this week, stressing that Google’s demands are overbroad. They reject the argument that internal discussions or communications with its members and law firm will reveal Attorney General Hood’s intent, not least due to the Attorney General not being part of these conversations himself.

According to the Hollywood group, Google’s broad demands are part of a public relations war against the MPAA, one in which Google inaccurately positions itself as the victim.

“Google portrays itself as the innocent victim of malicious efforts to abridge its First Amendment rights. In reality, Google is far from innocent,” the MPAA informs the federal court (pdf).

The MPAA notes that Google is knowingly facilitating and profiting from distributing “illegal” content, including pirated material.

“Google facilitates, and profits from, the distribution of third-party content that even Google concedes is ‘objectionable.’ ‘Objectionable’ is Google’s euphemism for ‘illegal’,” the MPAA writes.

The opposition brief states that for a variety of reasons the subpoenaed documents are irrelevant to the original lawsuit and are far too broad in scope. The MPAA’s initial searches revealed that 100,000 documents would likely require review, many of which it believes are protected by attorney-client privilege.

The MPAA says that Google is trying to leverage the information revealed in the Sony hack to expose the MPAA’s broader anti-piracy strategies in public, and that this is all part of an ongoing PR war.

“The purpose of these Subpoenas is to gather information — beyond the information that was already stolen via the Sony hack on which it relies — on the MPAA’s strategies to protect its members’ copyrighted material and address violations of law on the Internet affecting its members’ copyrights and the rights of others,” they write.

“Moreover, Google openly admits that it opposes any order to keep these discovery materials in confidence, revealing its goal to disseminate these documents publicly as part of its ongoing public relations war.”

Positioning itself as the victim, the MPAA goes on to slam Google for going after anyone who “dares” to expose the search engine’s alleged facilitation of piracy and other unlawful acts.

“…the most fundamental purpose of these Subpoenas is to send a message to anyone who dares to seek government redress for Google’s facilitation of unlawful conduct: If you and your attorneys exercise their First Amendment right to seek redress from a government official, Google will come after you.”

In conclusion, the MPAA and its law firm ask the court to reject Google’s broad demands and stop the “abuse” of the litigation process.

It’s now up to the judge to decide how to proceed, but based on the language used, the stakes at hand and the parties involved, this dispute isn’t going to blow over anytime soon. It’s more likely to blow up instead.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and anonymous VPN services.

Lauren Weinstein's Blog: Just Say “NON!” – France Demands Right of Global Google Censorship

This post was syndicated from: Lauren Weinstein's Blog and was written by: Lauren. Original post: at Lauren Weinstein's Blog

I’ve been waiting for this, much the way one waits for a violent case of food poisoning. France is now officially demanding that Google expand the hideous EU “Right To Be Forgotten” (RTBF) to Google.com worldwide, instead of just applying it to the appropriate localized (e.g. France) version of Google. And here’s my official response as a concerned individual: To…

TorrentFreak: Aussie ‘Pirate’ Site-Blocking Bill Given the Green Light

This post was syndicated from: TorrentFreak and was written by: Andy. Original post: at TorrentFreak

ausLate 2014, Attorney-General George Brandis and Communications Minister Malcolm Turnbull asked the Australian Cabinet to approve the development of a new system which would allow rightsholders to obtain site-blocking injunctions against ISPs. In March a draft of that legislation was introduced to parliament.

Since then the Copyright Amendment (Online Infringement) Bill 2015 has been under investigation by the Legal and Constitutional Affairs Legislation Committee. After examining the framework which allows rightsholders to apply for blocks against ‘pirate’ sites located overseas, this morning the Committee published a report that notes four recommendations but otherwise gives the legislation a green light.

Recommendations

When an application is made by a rightsholder for a blocking injunction, the Bill in its current form requires the Court to consider at least eight factors when determining whether an application should be granted. These include whether a site shows a general disregard for copyright, whether it has been blocked already in another jurisdiction, and the ‘flagrancy’ of any infringement.

Responding to rightsholder complaints that the bar had been set too high, alongside a belief that the thresholds for proving infringement had been narrowly established elsewhere in the Bill, the Committee advised an amendment from “is to take the following matters into account” to the watered down “may take the following matters into account”.

The recommendations also address VPNs, noting that “the Bill does not explicitly
contemplate the introduction of injunctions against VPNs”, adding that “VPNs are unlikely to meet the ‘primary purpose test’ [designed for infringing uses].” The Committee noted, however, that it would be “reassured” if the government clarified the status of such tools.

In respect of the “reasonable steps” ISPs will be expected to take in order to “disable access to an online location”, the Committee advised that these may include the posting of a landing page, similar to those currently used in the UK, which advise visitors that the site in question has been blocked alongside details of the order.

In another recommendation the Committee calls upon the government to provide greater clarity and guidance on the issue of costs and liability for ISPs after they comply with a court order to block a site.

“The committee urges the government to clarify its position regarding the
attribution of costs of compliance with orders where injunctive relief is granted,” the report reads.

“The committee notes the persuasive evidence of service providers to the effect that as [an ISP] bears no fault or liability for the infringement of copyright by its subscribers, [the ISP] should not be required to contribute to the cost of the remedy. The committee is of the view that more clarity is required to reassure [ISPs] that the costs associated with site-blocking will primarily be borne by those parties who are seeking the remedy.”

In other words, if rightsholders want to benefit from a site block, they should be the ones to pay for its implementation.

Finally, the Committee advises that the new legislation should be given an initial 24 months to do its work. At this point it should be re-examined to assess its performance.

“The committee recommends that the government conduct a formal review
of the effectiveness of the Copyright Amendment (Online Infringement) Bill2015, to be completed two years after its enactment,” the Committee concludes.

Dissenting Report – Australian Greens

In a second report published alongside the Committee’s this morning, Senator Scott Ludlam of the Australian Greens slams the Bill as the “latest in a long line of misguided attempts by the government to monitor, control and censor the Internet.”

Noting that the Bill hands “significant” new censorship powers to the court, Ludlam says that the evidence shows that it will be relatively easy to bypass the Bill’s provisions. Furthermore, the Bill lacks safeguards to ensure that legitimate online sources aren’t subjected to overblocking.

“Most importantly, there is also a significant weight of evidence showing that
the Bill will not meet its aims, as it does not address the underlying cause of online copyright infringement: The continual refusal of offshore rights holders to make their content available in a timely, convenient and affordable manner to Australians,” Ludlam concludes.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and anonymous VPN services.

TorrentFreak: Kim Dotcom’s MegaNet Preps Jan 2016 Crowdfunding Campaign

This post was syndicated from: TorrentFreak and was written by: Andy. Original post: at TorrentFreak

dotcom-laptopFor many years Kim Dotcom was associated with a crazy lifestyle but these days he prefers to be seen more as a family man.

Regularly posting pictures of his children on Twitter and playing down his wild past, Dotcom seems unlikely to entertain a recent request from Pirate Bay founder Peter Sunde to join him on the Gumball Rally.

But while yachts and fast cars might be a thing of the past, Dotcom has certainly not lost the fire in his belly when it comes to his current predicament. As he fights off a ravenous U.S. government determined to bring him to justice by any means possible, spying included, the Megaupload founder has positioned himself as a champion of Internet privacy.

On January 19, 2013, Dotcom marked the anniversary of the raid on his empire by launching the privacy-focused cloud-storage service Mega.co.nz. Next year on the same date, the tenacious German says he will deliver again.

Thus far, details are thin on the ground, but what we do know is that Dotcom is planning a new anti-censorship network he calls MegaNet.

“How would you like a new Internet that can’t be controlled, censored or destroyed by Governments or Corporations?” Dotcom teased in February.

MegaNet’s precise mechanism is yet to be revealed, but Dotcom has already stated that the network will be non-IP address based and that blockchain technology will play an important role.

What we also know is that users’ mobile phones will play a crucial role, although at launch other devices will participate in the network.

“All your mobile phones become an encrypted network,” Dotcom notes. “You’d be surprised how much idle storage & bandwidth capacity mobile phones have. MegaNet will turn that idle capacity into a new network.”

At this stage it appears that Dotcom envisions a totally decentralized system, an essential quality if he is to deliver on his claims of absolute privacy.

With the earlier promise that participants in MegaNet “become the MegaNet”, Dotcom’s announcement this morning that the project will seek monetary contributions from the masses seems entirely fitting.

“MegaNet details will be revealed and equity will be available via crowd funding on 20 Jan 2016, the fourth anniversary of the raid [on Dotcom and Megupload],” Dotcom confirmed.

And for now, that is all. Dotcom has become somewhat of an expert at dripping small details to the masses as and when he sees fit while allowing the media to fill in the blanks. It’s a somewhat effective strategy which provides millions in free advertising for close to zero marketing outlay.

The big question now is how much equity MegaNet will need to get off the ground and how many of Dotcom’s supporters will believe that privacy is a commodity worth supporting with their wallets. People were happy to support Peter Sunde’s Heml.is on the same premise, but as recently revealed the amount of cash required to compete can be considerable.

However, Dotcom probably won’t attempt this entirely on his own. Given his history there’s a significant chance that the entrepreneur will pull in heavyweights such as Julian Assange and Glenn Greenwald to support the campaign. That will definitely help to boost the coffers.

Update: Kim Dotcom has sent TorrentFreak additional details on how MegaNet will operate.

“MegaNet has a unique file crystallization and recreation protocol utilizing the blockchain. You can load entire websites with this new technology and it makes them immune to almost all hacker attacks and ddos,” Dotcom informs TF.

“In the beginning MegaNet will still utilize the current Internet as a dumb pipe but in 10 years it will run exclusively on smartphones with hopefully over 500 million users carrying the network.

“A network by the people for the people. Not controlled by any government or corporations. MegaNet will be a powerful tool to guard our privacy and freedoms and it will also be my legacy,” Dotcom concludes.

On the finance front, MegaNet will partner with Bnktothefuture.com and Max Keiser to raise capital.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and anonymous VPN services.

TorrentFreak: Google Takes MPAA to Court Over Secret Censorship Plans

This post was syndicated from: TorrentFreak and was written by: Ernesto. Original post: at TorrentFreak

googlepopHelped by the MPAA, Mississippi State Attorney General Jim Hood launched a secret campaign to revive SOPA-like censorship efforts in the United States.

The MPAA and Hood want Internet services to bring website blocking and search engine filtering back to the table after the controversial law failed to pass.

In response to the looming threat Google filed a complaint against Hood last December, asking the court to prevent Hood from enforcing a subpoena that addresses Google’s failure to take down or block access to illegal content, including pirate sites.

This resulted in a victory for Google with District Court Judge Henry Wingate putting the subpoena on hold. At the same time Google requested additional details from the Attorney General and various other parties involved in the scheme, including the MPAA.

Thus far, however, these requests haven’t proven fruitful. In a motion to compel directed at the MPAA (pdf), Google explains that the movie industry group and other petitioned parties have yet to hand over the requested information.

“To date, the subpoenaed parties have produced nothing,” Google’s lawyers inform the court.

“They have inexplicably delayed producing the few documents they agreed to turn over, and have objected that many of their documents, including internal notes or summaries of meetings with AG Hood, are irrelevant or protected by some unsubstantiated privilege.”

In addition to the MPAA, Google has also filed similar motions against the MPAA’s law firm Jenner & Block, Digital Citizens Alliance, 21st Century Fox, NBC Universal and Viacom.

All parties thus far have refused to hand over the requested information, which includes communication with and prepared for the Attorney General, as well as emails referencing Google.

According to the MPAA this information is “irrelevant” or privileged, but Google disagrees.

“The relevance objections are meritless. As Judge Wingate has already held, there is substantial evidence that the Attorney General’s actions against Google were undertaken in bad faith and for a retaliatory purpose,” the motion reads.

According to Google’s legal team the documents will shine a light on how the MPAA and others encouraged and helped the Attorney General to push for Internet censorship.

“Google expects the documents will show that the Attorney General, the Subpoenaed Parties, and their lobbyists understood that his actions invaded the exclusive province of federal law,” the motion reads.

“More fundamentally, the documents are likely to show that the Attorney General’s investigation was intended not to uncover supposed violations of Mississippi law, but instead to coerce Google into silencing speech that Viacom, Fox, and NBC do not like…”

District Court Judge James Boasberg has referred the case to a magistrate judge (pdf), who will discuss the matter in an upcoming hearing. Considering the stakes at hand, the players involved will leave no resource untapped to defend their positions.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and anonymous VPN services.

TorrentFreak: Russia Orders ISPs to Block The Pirate Bay

This post was syndicated from: TorrentFreak and was written by: Ernesto. Original post: at TorrentFreak

pirate bayAs the arch-rival of many copyright groups, The Pirate Bay has become one of the most censored websites on the Internet in recent years.

Courts all around the world have ordered Internet providers to block subscriber access to the torrent site and the list continues to expand.

This week Russia’s telecommunications watchdog Roskomnadzor issued an update to the country’s blocklist adding two Pirate Bay domain names.

Following a complaint from Mosfilm, one of the largest European movie studios, Russian ISPs are now required to block access to thepiratebay.se and thepiratebay.mn.

Interestingly, there is no separate court order against The Pirate Bay. Instead, the domains were added to an existing injunction targeting tushkan.net, which was offering a pirated copy of Mosfilm’s movie “The Road to Berlin.”

Under Russian law, copyright holders can add domain names to an injunction if their content appears on other sites as well. In addition to The Pirate Bay domains, a dozen other sites were added in the same update.

Technically, The Pirate Bay can request a removal from the blocklist after they remove all links to the film in question. But considering the site’s stance on taking down content, this is not going to happen.

Pirate Bay Blocked
russiablocked

While the order aims to deprive millions of Russians from visiting the popular torrent site, it will be rather ineffective for now. Two weeks ago The Pirate Bay added several new domain names and four of those remain readily accessible.

It is clear, however, that Russia is not averse to taking measures against websites that are accused of facilitating copyright infringement. Hundreds of websites have been blocked in recent years and there are calls to ban various circumvention tools including VPNs and TOR as well.

The first step in this direction was set last week when an anti-censorship website from a local human rights group was blocked, and similar crackdowns may follow in the near future.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and anonymous VPN services.

TorrentFreak: Court Orders VPN, TOR & Proxy Advice Site to be Blocked

This post was syndicated from: TorrentFreak and was written by: Andy. Original post: at TorrentFreak

stopstopWhile there is still much resistance to the practice in the United States, having websites blocked at the ISP level is becoming easier in many other countries around the world.

One country where the process is becoming ever more streamlined is Russia. The country blocks hundreds of websites on many grounds, from copyright infringement to the publication of extremist propaganda, suicide discussion and the promotion of drugs.

Keeping a close eye on Russia’s constantly expanding website blocklist is RosComSvoboda. The project advocates human rights and freedoms on the Internet, monitors and publishes data on blockades, and provides assistance to Internet users and website operators who are wrongfully subjected to restrictions.

Now, however, RosKomSvoboda will have to fight for its own freedoms after a local court ordered ISPs to block an advice portal operated by the group.

The site, RUBlacklist, is an information resource aimed at users who wish to learn about tools that can be used to circumvent censorship. It doesn’t host any tools itself but offers advice on VPNs, proxies, TOR and The Pirate Bay’s Pirate Browser.

Also detailed are various anonymizer services (which are presented via a linked Google search), Opera browser’s ‘turbo mode’ (which is often used in the UK to unblock torrent sites) and open source anonymous network I2P (soon to feature in a Popcorn Time fork).

Unfortunately, Russian authorities view this education as problematic. During an investigation carried out by the Anapa district’s prosecutor’s office it was determined that RosKomSvoboda’s advice undermines government blocks.

“Due to anonymizer sites, in particular http://rublacklist.net/bypass, users can have full access to all the banned sites anonymously and via spoofing. That is, with the help of this site, citizens can get unlimited anonymous access to banned content, including extremist material,” a ruling from the Anapa Court reads.

Describing the portal as an anonymization service, the Court ordered RosKomSvoboda’s advice center to be blocked at the ISP level.

Needless to say the operators of RosKomSvoboda are outraged that their anti-censorship efforts will now be censored. Group chief Artyom Kozlyuk slammed the decision, describing both the prosecutor’s lawsuit and the Court ruling as “absurd”.

“Law enforcement has demonstrated its complete incompetence in the basic knowledge of all the common technical aspects of the Internet, though even youngsters can understand it,” Kozlyuk says.

“Anonymizers, proxies and browsers are multitask instruments, helping to search for information on the Internet. If we follow the reasoning of the prosecutor and the court, then the following stuff should be prohibited as well: knives, as they can become a tool for murder; hammers, as they can be used as a tool of torture; planes, because if they fall they can lead to many deaths.

“To conclude, I would love to ask the prosecutor of Anapa to consider the possibility of prohibiting paper and ink, because with these tools one can draw a very melancholic picture of this ruling’s complete ignorance.”

RosKomSvoboda’s legal team say they intend to appeal the ruling which was the result of a legal procedure that took place without their knowledge.

“We can only guess why the project is considered to be an anonymizer. It’s likely that no one in Anapa city court understands what they are dealing with,” says RosKomSvoboda lawyer Sarkis Darbinian.

“We see that these kinds of rulings are being stamped on a legal conveyor belt. Moreover, we see the obvious violation of the fundamental principles of civil procedure – an adversarial system.”

The court ruling against RUBlacklist arrives at the same time as a report from the United Nations which urges member states to do everything they can to encourage encryption and anonymity online.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and anonymous VPN services.

TorrentFreak: Hola VPN Sells Users’ Bandwidth, Founder Confirms

This post was syndicated from: TorrentFreak and was written by: Andy. Original post: at TorrentFreak

hola-logoFaced with increasing local website censorship and Internet services that restrict access depending on where a user is based, more and more people are turning to specialist services designed to overcome such limitations.

With prices plummeting to just a few dollars a month in recent years, VPNs are now within the budgets of most people. However, there are always those who prefer to get such services for free, without giving much consideration to how that might be economically viable.

One of the most popular free VPN/geo-unblocking solutions on the planet is operated by Israel-based Hola. It can be added to most popular browsers in seconds and has an impressive seven million users on Chrome alone. Overall the company boasts 46 million users of its service.

Now, however, the company is facing accusations from 8chan message board operator Fredrick Brennan. He claims that Hola users’ computers were used to attack his website without their knowledge, and that was made possible by the way Hola is setup.

“When a user installs Hola, he becomes a VPN endpoint, and other users of the Hola network may exit through his internet connection and take on his IP. This is what makes it free: Hola does not pay for the bandwidth that its VPN uses at all, and there is no user opt out for this,” Brennan says.

This means that rather than having their IP addresses cloaked behind a private server, free Hola users are regularly exposing their IP addresses to the world but associated with other people’s traffic – no matter what that might contain.

hola-big

While this will come as a surprise to many, Hola says it has never tried to hide the methods it employs to offer a free service.

Speaking with TorrentFreak, Hola founder Ofer Vilenski says that his company offers two tiers of service – the free option (which sees traffic routed between Hola users) and a premium service, which operates like a traditional VPN.

However, Brennan says that Hola goes a step further, by selling Hola users’ bandwidth to another company.

“Hola has gotten greedy. They recently (late 2014) realized that they basically have a 9 million IP strong botnet on their hands, and they began selling access to this botnet (right now, for HTTP requests only) at https://luminati.io,” the 8chan owner says.

TorrentFreak asked Vilenski about Brennan’s claims. Again, there was no denial.

“We have always made it clear that Hola is built for the user and with the user in mind. We’ve explained the technical aspects of it in our FAQ and have always advertised in our FAQ the ability to pay for non-commercial use,” Vilenski says.

And this is how it works.

Hola generates revenue by selling a premium service to customers through its Luminati brand. The resources and bandwidth for the Luminati product are provided by Hola users’ computers when they are sitting idle. In basic terms, Hola users get their service for free as long as they’re prepared to let Hola hand their resources to Luminati for resale. Any users who don’t want this to happen can buy Hola for $5 per month.

Fair enough perhaps – but how does Luminati feature in Brennan’s problems? It appears his interest in the service was piqued after 8chan was hit by multiple denial of service attacks this week which originated from the Luminati / Hola network.

“An attacker used the Luminati network to send thousands of legitimate-looking POST requests to 8chan’s post.php in 30 seconds, representing a 100x spike over peak traffic and crashing PHP-FPM,” Brennan says.

Again, TorrentFreak asked Vilenski for his input. Again, there was no denial.

“8chan was hit with an attack from a hacker with the handle of BUI. This person then wrote about how he used the Luminati commercial VPN network to hack 8chan. He could have used any commercial VPN network, but chose to do so with ours,” Vilenski explains.

“If 8chan was harmed, then a reasonable course of action would be to obtain a court order for information and we can release the contact information of this user so that they can further pursue the damages with him.”

Vilenski says that Hola screens users of its “commercial network” (Luminati) prior to them being allowed to use it but in this case “BUI” slipped through the net. “Adjustments” have been made, Hola’s founder says.

“We have communicated directly with the founder of 8Chan to make sure that once we terminated BUI’s account they’ve had no further problems, and it seems that this is the case,” Vilenski says.

It is likely the majority of Hola’s users have no idea how the company’s business model operates, even though it is made fairly clear in its extensive FAQ/ToS. Installing a browser extension takes seconds and if it works as advertised, most people will be happy.

Whether this episode will affect Hola’s business moving forward is open to question but for those with a few dollars to spend there are plenty of options in the market. Until then, however, those looking for free options should read the small print before clicking install.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and anonymous VPN services.

Krebs on Security: China Censors Facebook.net, Blocks Sites With “Like” Buttons

This post was syndicated from: Krebs on Security and was written by: BrianKrebs. Original post: at Krebs on Security

Chinese government censors at the helm of the “Great Firewall of China” appear to have inadvertently blocked Chinese Web surfers from visiting pages that call out to connect.facebook.net, a resource used by Facebook’s “like” buttons. While the apparent screw-up was quickly fixed, the block was cached by many Chinese networks — effectively blocking millions of Chinese Web surfers from visiting a huge number of sites that are not normally censored.

fblikeunlike

Sometime in the last 24 hours, Web requests from within China for a large number of websites were being redirected to wpkg.org, an apparently innocuous site hosting an open-source, automated software deployment, upgrade and removal program for Windows.

One KrebsOnSecurity reader living in China who was inconvenienced by the glitch said he discovered the problem just by trying to access the regularly non-blocked UK newspapers online. He soon noticed a large swath of other sites were also being re-directed to the same page.

“It has the feel of a cyber attack rather than a new addition to the Great Firewall,” said the reader, who asked not to be identified by name. “I thought it might be malware on my laptop, but then I got an email from the IT services at my university saying the issue was nation-wide, which made me curious. It’s obviously very normal for sites to be blocked here in China, but the scale and the type of sites being blocked (and the fact that we’re being re-directed instead of the usual 404 result) suggests a problem with the Internet system itself. It doesn’t seem like the kind of thing the Chinese gov would do intentionally, which raises some interesting questions.”

Nicholas Weaver, a researcher who has delved deeply into Chinese censorship tools in his role at the International Computer Science Institute (ICSI) and the University of California, Berkeley, agrees that the blocking of connect.facebook.net by censors inside the country was likely a mistake.

“Any page that had a Facebook Connect element on it that twas unencrypted and visited from within China would instead get this thing which would reload the main page of wpkg.org,” Weaver said, nothing that while Facebook.com always encrypts users’ connections, sites that rely on Facebook “like” buttons and related resources draw those from connect.facebook.net. “That screw-up seems to have been fairly quickly corrected, but the effect of it has lingered because it got into peoples’ domain name system (DNS) caches.”

In short, a brief misstep in censorship can have lasting and far flung repercussions. But why should this be considered a screw-up by Chinese censors? For one thing, it was corrected quickly, Weaver said.

“Also, the Chinese censors don’t benefit from it, because this caused a huge amount of disruption to Chinese web surfers on pages that the government doesn’t want to censor,” he said.

Such screw-ups are not unprecedented. In January 2014, Chinese censors attempting to block Greatfire.org — a site that hosts tools and instructions for people to circumvent restrictions erected by the Great Firewall — inadvertently blocked all Chinese Web surfers from accessing most of the Internet.

Doing censorship right — without introducing the occasional routing calamities and unintended consequences — is hard, Weaver said. And China isn’t the only nation that’s struggled with censorship goofs. The United Kingdom filters its providers’ Internet traffic for requests to known child pornography material. In 2008, a filtering system run by the U.K-based Internet Watch Foundation flagged the cover art for the album Virgin Killers by the rock band Scorpions as potential child porn. As a result, the system placed several pages from Wikipedia on its Internet black list.

The British child porn filtering system checked for requests to images flagged as indecent by using a proxying the traffic through a specific system. So when U.K. residents tried to edit Wiki pages following the blacklisting, Wikipedia saw those requests as huge numbers of users all trying to edit Wiki pages from the same Internet addresses, and blocked the proxy address — effectively cutting off U.K. users from editing all Wiki pages for several days.

Suggested further reading:

Don’t Be Fodder for China’s ‘Great Cannon’

TorrentFreak: Pirate Bay Blockade Censors CloudFlare Customers

This post was syndicated from: TorrentFreak and was written by: Ernesto. Original post: at TorrentFreak

cloudflareLike any form of censorship web blockades can sometime lead to overblocking, targeting perfectly legitimate websites by mistake.

This is also happening in the UK where Sky’s blocking technology is inadvertently blocking sites that have nothing to do with piracy.

In addition to blocking domain names, Sky also blocks IP-addresses. This allows the site to stop https connections to The Pirate Bay and its proxies, but when IP-addresses are shared with random other sites they’re blocked too.

This is happening to various customers of the CDN service CloudFlare, which is used by many sites on the UK blocklist. Every now and then this causes legitimate sites to be blocked, such as CloudFlare customers who shared an IP-address with Pirate Bay proxy ilikerainbows.co.uk.

Although the domain is merely a redirect to ilikerainbows.co, it’s listed in Sky’s blocking system along with several CloudFlare IP-addresses. Recently, the CDN service received complaints from users about the issue and alerted the proxy owner.

“It has come to our attention that your website — ilikerainbows.co.uk — is causing CloudFlare IPs to be blocked by SkyB, an ISP located in the UK. This is impacting other CloudFlare customers,” CloudFlare wrote.

The CDN service asked the proxy site to resolve the matter with Sky, or else it would remove the site from the network after 24 hours.

“If this issue does not get resolved with SkyB though we will need to route your domain off CloudFlare’s network as it is currently impacting other CloudFlare customers due to these blocked IP addresses.”

cfemail

The operator of the “Rainbows” TPB proxy was surprised by Sky’s overbroad blocking techniques, but also by CloudFlare’s response. Would CloudFlare also kick out sites that are blocked in other countries where censorship is common?

“What do they do when Russia starts blocking sites under their system? Are they going to kick users off CloudFlare because there’s a Putin meme that the Russians don’t like?” Rainbows’ operator tells TF.

Instead of waiting for the domain to be switched off by CloudFlare he reverted it back to the domain registrar’s forwarding services. The main .co domain still uses CloudFlare’s services though, as does the official Pirate Bay site.

This is not the first time that CloudFlare customers have been blocked by mistake. Earlier this year the same thing happened to sites that shared an IP-address with The Pirate Bay. At the time we contacted Sky, who informed us that they do all they can to limit collateral damage.

“We have a process in place to monitor requested site blocks to limit the chances of inadvertently blocking sites, and in addition to this if we are advised by a site owner or Sky customer that a site is being inadvertently blocked we take the necessary steps to remove any unintended blocks,” a Sky spokeswoman said.

In addition to Sky we also contacted CloudFlare about the issue multiple times this year, but the company has yet to reply to our inquiries.

It’s clear though that despite cheers from copyright holders, website blocking is not all rainbows and unicorns. Without any significant change to Sky’s blocking setup, more of these inadvertent blocks are bound to happen in the future.

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and anonymous VPN services.

TorrentFreak: Court: Google Can See Emails About MPAA’s Secret ‘SOPA Revival’

This post was syndicated from: TorrentFreak and was written by: Ernesto. Original post: at TorrentFreak

mailgIn backroom meetings the MPAA and Mississippi State Attorney General Jim Hood discussed a plan to bring website blocking and search engine filtering back to the table after the controversial SOPA law failed to pass.

The plan, dubbed “Project Goliath,” became public through various emails that were released during the Sony Pictures leaks. In a response Google said that it was “deeply concerned” about the developments.

To counter the looming threat Google filed a complaint against Hood last December, asking the court to prevent Hood from enforcing a subpoena that addresses Google’s failure to take down or block access to illegal content, including pirate sites.

This resulted in a victory for Google with District Court Judge Henry Wingate putting the subpoena on hold. At the same time Google requested additional details from the Attorney General on his discussions with Hollywood.

During an oral hearing earlier this month Google requested various documents including an email conversation between MPAA’s Senior Vice President State Legislative Affairs Vans Stevenson and the Attorney General.

In addition, Google asked for copies of Word files titled Google can take action, Google must change its behavior, Google’s illegal conduct, CDA, and any documents gathered in response to a request previously submitted by Techdirt’s Mike Masnick .

After a careful review District Court Judge Henry Wingate sided with Google, ordering Attorney General Hood to hand over the requested information before the end of the month.

Judge Wingate’s order
hoodorder

The documents will help Google to get to the bottom of the censorship efforts and to determine what role the MPAA played and what its contributions were.

Various emails that leaked after the Sony hack already revealed that the MPAA’s long-standing law firm Jenner & Block had drafted a subpoena and other communication the Attorney General could use against Google.

Many of the “Project Goliath” emails and documents are readily available after Wikileaks released them late last week, but nearly all details had already been made public after the leaks first surfaced.

Interestingly, in one email the MPAA’s Vans Stevenson linked to a New York Times piece on how lobbyists court State Attorneys to advance their political agendas.

“FYI, first is a series of articles,” Stevenson wrote to several high level executives involved, not knowing that a follow-up would include “Project Goliath.”

Perhaps fittingly, New York Times’ journalist Eric Lipton won a Pulitzer prize for the series yesterday, for reporting “how the influence of lobbyists can sway congressional leaders and state attorneys general, slanting justice toward the wealthy and connected.”

Source: TorrentFreak, for the latest info on copyright, file-sharing, torrent sites and anonymous VPN services.