Showing posts with label internet. Show all posts
Showing posts with label internet. Show all posts

Wednesday, June 3, 2009

Has Microsoft Sneaked Malware Into Your Computer?

Routine Windows security update invisibly creates security holes in Firefox browser

Millions of computer users may be at risk

Should Microsoft’s hackers be jailed?

The 800-pound gorillas at Microsoft, notorious for releasing perhaps the most poorly tested, security-deficient commercial software in the known universe, have taken it upon themselves to shoot holes in the security of third-party software as well.

In February 2009, the bumbling twits at Microsoft released a—I actually hesitate to use the term, for reasons which will become apparent—“Security Update” for the Microsoft .Net Framework, specifically, “Microsoft .NET Framework 3.5 Service Pack 1.”

Outrageously, this update also installs the Microsoft .NET Framework Assistant 1.0 extension (add-on) into Firefox without asking the user’s permission.

Yeah? So What?

image

Well, if you use the Mozilla Firefox browser, you will now find, (actually, you may not—until it’s too late), that websites can now—without your knowledge or consent—download, install and run software on your computer! That’s right, the default settings of this add-on permit websites to install software without notifying you.

WHAT?

Yep! That’s what it does. Microsoft has seen to it that the users of third-party browsers can now have the same sort of security problems which plague users of Microsoft’s—much reviled—Internet Explorer!

But wait, there’s more! The add-on reports the .NET version installed on your computer to every website you visit in the User-Agent string.

The add-on makes use of “ClickOnce” technology, which is expressly designed to allow the installation and execution of software, simply by clicking a link on a webpage—whether or not the link legitimately indicates it is pointing to a software package.

Well, Wikipedia says ClickOnce is a secure technology. So, why shouldn’t I trust it?

Considering the fact that Wikipedia is the world’s largest repository of laughably erroneous data, and that said data is often provided by parties with a vested interest in skewing the information, lets look instead at a quote from InformIT.com’s page on ClickOnce security:

“The problem with the default security model for an enterprise [business] environment is that it puts the trust decision of whether to elevate permissions or not into the users' hands. If an application needs elevated permissions, it prompts the users, and if they click the Install button, the application can elevate its permissions all the way to full trust if it wants to, effectively removing the runtime protections that ClickOnce is capable of providing… Many users do not have the experience to discern a true high-risk scenario from one that is acceptable.”

Indeed, given Microsoft’s abysmal security track-record over the years, (they permitted one XP security hole to remain unpatched for seven years—though they knew about it all along), are you willing to bet that there isn’t a malicious hacker out there who can defeat whatever ClickOnce really has for security and take a peek at your credit card numbers or your financial data? Or watch over your shoulder as you do online banking?

If you have “Automatic Updates” enabled, and you are a Firefox user, you may have the .NET Framework Assistant installed on your computer.

image

To add insult to maliciousness, should you, while perusing your Firefox add-ons, run across the Microsoft .NET Framework Assistant extension in the list and wonder, “what the hell is that and how did it get into my Firefox?” I’m sure you will be equally bemused to find that the “Uninstall” button is disabled.

So, what is Microsoft .Net Framework? To simplify somewhat, .Net Framework, (yes, that .dot is supposed to be there), is a collection of software which can be used by Windows and third-party programs to perform various functions which would otherwise have to be coded into each application: It helps programmers by cutting down on their code-work and helps you by reducing the overall size of programs which require such routines.

So, this Firefox add-on thing is necessary to the functioning of my software then, Right?

Not in the slightest.

The average Windows user will likely never install software that requires the .Net Framework. Even if a user does have applications that require it, the “ClickOnce” add-on to Firefox is completely unnecessary, representing more of a security risk than it creates a convenience for the user.

Indeed, Annoyances.org, a website which relies on user input to find and fix problems related to Microsoft applications and operating systems, has this to say about the .NET Framework Assistant add-on:

“This update adds to Firefox one of the most dangerous vulnerabilities present in all versions of Internet Explorer: the ability for websites to easily and quietly install software on your PC. Since this design flaw is one of the reasons you may've originally [chosen] to abandon IE in favor of a safer browser like Firefox, you may wish to remove this extension with all due haste.”

Ditch the Firefox add-on, ditch it now.

Removal instructions may be found at Annoyances.org and Microsoft Support. WARNING! Microsoft has seen to it that there is no easy way to remove this malware! The removal instructions require registry editing which—if done incorrectly—may result in software malfunctions or Windows refusing to start altogether! Follow the instructions precisely.

If you are unwilling or unable to remove the offender according to instructions, open Add-ons in Firefox, right-click “Microsoft .NET Framework Assistant” select “disable” and restart Firefox. Hopefully, it will stay disabled.

Don’t think you are safe with the Microsoft malware enabled in Firefox so long as you don’t visit “questionable” websites: Here is a short sample of the many, many legitimate websites which have been hacked in the recent past:

Al Gore's climate crisis website hacked by Viagra sellers (Had to put Chicken Little at the top of this list)

Obama Website Hacked: Users Redirected To Clinton Campaign

Cybercrooks plant phishing scam on crime reduction website

Cern Website Hacked

Computer security Firm Kaspersky's website hacked

Security Software CA's website hacked to point users to Chinese malware

Another police website hacked

Security firm Trend Micro website hacked

Sony website hacked

Thousands hit in broad Web hack

Half-Million Sites Mostly Running PHPBB Forum Software Hacked In Latest Attack

So just what the hell did Microsoft think they were doing? According to Brad Abrams at this site they claim they were doing you a favor:

“A couple of years ago we heard clear feedback from folks that they wanted to enable a very clean experience with launching a ClickOnce app from FireFox. [I wasn’t one of them, Brad, nor, I’ll just bet, were the vast majority of Firefox users] James Dobson published FFClickOnce and got very good reviews, but we had many customers that wanted ClickOnce support for Firefox built into the framework… so in .NET Framework 3.5 SP1 we added ClickOnce support for Firefox! This made ClickOnce apps much more accessible to a wide range of customers.

We added this support at the machine level in order to enable the feature for all users on the machine. Seems reasonable right? Well, turns out [translation: ‘We knew it couldn’t be uninstalled and did it anyway’] that enabling this functionality at the machine level, rather than at the user level means that the "Uninstall" button is grayed out in the Firefox Add-ons menu because standard users are not permitted to uninstall machine-level components.”

Makes you wonder what the hell else these bozos have sneaked into your computer without your knowledge, doesn’t it?

Are Microsoft programmers like many journalists? Do they have to flunk an intelligence test before they are hired?

Brad, Microsoft, no. It sure as hell isn’t reasonable in any way, shape or form, to hack someone’s computer without their knowledge or consent. If there is some fool out there who wants to give websites the ability to silently run their software in his computer, he should manually install it from the Mozilla add-ons site—where Microsoft should have posted this disgrace in the first place. Microsoft has no business hiding this in an otherwise legitimate “security” update.

I work with clients whose companies are locked into Windows; consequently, I have to have at least one computer for my business which runs Windows so I can follow along with those clients—remotely—as I try to solve a problem they just discovered.

I go to a very great deal of trouble, indeed, to make certain that malicious software never takes a foothold on that computer—including the use of the more secure Firefox browser. The very last thing I need is for Microsoft—or other software companies—to waste my time, make my life more difficult and make my computer less secure by introducing yet more potential security holes while hacking my third-party applications!

Fortunately, said precautions prevented Microsoft from tinkering with my Firefox. Yours may be another matter. (And no—please don’t even think of asking what my security precautions and procedures are.)

Lets take a for instance, (I just love “for instances,” don’t you? They’re so warm and cuddly): You own a car, a Chevy, say, and you’ve paid it off—you own it free and clear. You take your car to your Chevy dealer for a 3,000-mile oil change and Chevy’s mechanic disables the third-party security device you had installed—without your knowledge or consent.

What’s the difference between our little for instance and Microsoft frivolously altering your third-party software? Save that Microsoft’s criminal tampering with private property was done via the internet—precisely, none.

If a basement-dwelling hacker did the same thing to your computer—altered your software to make it less secure—when caught, he would be arrested and charged with, at the very least, illegally accessing a computer. There is nothing in the EULA—the Microsoft End-User License Agreement—which gives Microsoft the right to tamper with your third-party software. Such tampering is illegal in the U.S. and many other countries.

"Breaking into other people's property is a crime—it makes no difference if it's a computer or a house that you're burgling."

—Graham Cluley, senior technology consultant for Sophos Anti-Virus

So, perhaps the twits at Microsoft who decided to hack your third-party software should spend a little time in the slammer, (I might recommend hard labor; smashing Microsoft Vista CDs).

“Now wait a minute,” I hear you bellow. “That’s ridiculous! You’re blowing this way out of proportion!”

Really?

Many people have their whole lives in their computers. Consider what may be found on a typical user’s system:

  • Financial records
  • Passwords to bank accounts
  • Mortgage data
  • Codes to disarm the security alarms for the house and the office
  • Medical information
  • Credit card numbers
  • Sensitive emails
  • Family photos—including pictures of the kids and the exterior and interior of the house
  • School records
  • Information which might allow someone to determine the whereabouts of children at a given time
  • Code words to be given to said children in case of emergency
  • The babysitter’s name and the dates and times she watches the kids
  • Data on what medication, money or firearms may be in the house
  • Safe combinations

Rightly or wrongly, wisely so or not, all that and more may be on someone’s computer, (which the users have reason to believe* to be as secure as possible), when Microsoft tampers with their system, allowing Jimmy-The-Crook’s website to download and run unknown software.

Given the above, maybe you’re not taking this seriously enough!

*Note: Do not infer from my statements that I consider Firefox or any other web browser to be 100% secure—that just ain’t so, folks.

Some internet sites speculate that Microsoft’s little Firefox hack job may have been a deliberate attempt to sabotage it’s competitor’s product. If this is, in fact, the case, it wouldn’t be the first time: Microsoft was brought to trial by the U.S. Department of Justice in 1998 for similar offenses.

If you find that your Microsoft security update has hacked your copy of Firefox, or if any other software company has similarly hacked your third-party software, and you reasonably believe that this activity is illegal, I strongly urge you to report the crime to:

The FBI Internet Crime Complaint Center

FYI, Microsoft isn’t the only upstart company to resort to such practices:

  • Apple’s QuickTime and ITunes updates previously installed MobileMe and Safari (63 MB and security-plagued)—without user notification or permission—and pushed Apple Mobile Device Support, Apple Software Update and Bonjour.
  • The RealAudio media player's default installation includes both Google Toolbar and Google Desktop Search.
  • Sometime ago, Java's default installation included a game called "Puzzle Pirates"—then Java decided they wanted to install Sun Open Office (takes up 250 MB on your hard drive) and Yahoo Toolbar during Java updates.
  • Adobe Acrobat Reader's default installation includes the Google Toolbar.
  • The RealAudio media player's default installation includes both Google Toolbar and Google Desktop Search.

None of the extras the software providers push in these installations and updates are necessary. In truth, many of these installs and updates do give you the option of disallowing the installation of some of the software, but if you have no bloody idea what “Open Office” or “Bonjour” is, do you allow it or disallow it and hope that the software you do install will run without it?

When in doubt, take a cue from Nancy Reagan and “just say, NO!”

If you research the Google or Yahoo toolbars and decide you want one of them added to your browser, go to their sites and download them—don’t trust anything you are asked to install second-hand.

Monday, March 23, 2009

Draconian Internet Copyright Law Dead, Or Is It?

New Zealand Parliament relents after public outrage

Section 92A scrapped, to be re-written

New Zealand Commerce Minister Simon Power announced today that Section 92A of New Zealand's copyright law will not come into force on 27 March as previously planned.

As outlined in my 16 February 2009 article, Guilt On Accusation - Draconian Internet Copyright Law To Be Enacted, under this ill-conceived law, internet users’ accounts would have been terminated as a result of unproven accusations of piracy. Section 92A stated that if a copyright owner thinks an internet user guilty of repeatedly breaching copyright, the user’s ISP would have been forced the terminate the user's internet connections and websites.

In protest of this law and under encouragement from the Creative Freedom Coalition, thousands of New Zealanders blacked out their websites, Myspace pages, Facebook photos, and Twitter accounts.

In my 13 March follow-up to that article, Draconian New Zealand Copyright Law Foundering?, I noted that New Zealand's Telecommunications Carriers’ Forum (TCF) spent weeks trying to draft a Code of Practice dealing with the implementation of Section 92A, but TCF member TelstraClear stated they would veto that code.

New Zealand Prime Minister John Key said Monday:

"We have now asked the minister of commerce to start work on a replacement section [for 92A]... There is a need for legislation in this area. Some progress was made between copyright holders and the ISPs but not enough to agree a code of conduct... In our view there are a number of issues that made it difficult to complete that code of conduct without fixing the fundamental flaws in section 92a."

The bottom-line in all this: Which is ultimately most important? Ensuring above all else that an extra 30-cents go into the pocket of a—likely wealthy—copyright holder, or protecting the rights of all citizens to due process of law in the face of unproven accusations? Seems like a no-brainer to me.

Does the New Zealand Parliament—or the government of any nation—first and foremost represent and protect its citizens? Or does it despotically chuck the peoples' rights out the window in order to placate grumbling, paranoid, billion-dollar corporations whose sole reason for existence is to make money? Should the rights of such corporations be protected? Certainly! But NEVER at the expense of the basic civil rights of the people which a government is required to protect!

Such corporations are acting purely in self-interest: By pressuring politicians to enact this and similar draconian laws, they have shown that they have absolutely no interest in the rights of others. These corporations and their representatives, the RIAA, RIANZ and others, are NOT police forces, they don’t know how to be police forces, they cannot be trusted to behave responsibly as police forces, and they must not be given—by any nation—the power to act as police forces. If they have evidence of theft of their products, such evidence should be turned over to appropriate authorities for a proper and lawful investigation—as any other private entity is required to.

Lets hope—indeed, all New Zealanders should expect and require—that in re-drafting this despicable law, New Zealand's Parliament—civil servants, NOT civil masters—will, this time, do their damn jobs: Protecting and ensuring the rights of the people of New Zealand, rather than abrogating those rights—and Parliament's mandate—by giving entertainment guilds, for pity's sake, independent powers of judge and jury over all internet users in New Zealand.

What on Earth were they thinking?

New Zealanders should contact their MPs through instructions and links on this page and let the rascals know you expect them to ensure civil rights and due process of law.

Friday, March 13, 2009

Draconian New Zealand Copyright Law Foundering?

Major player TelstraClear withdraws its cooperation

Update! See follow-up article: Draconian Internet Copyright Law Dead, Or Is It? March 23, 2009

On 16 February 2009, I wrote about the New Zealand Copyright Act (Section 92A) in Guilt On Accusation - Draconian Internet Copyright Law To Be Enacted. This law would allow American and New Zealand film and music industries to pressure Internet Service Providers (ISPs) to terminate any individual or business users solely on their say so.

On 23 February, the New Zealand government suspended Section 92A which had been scheduled to become active on 28 February. For months, the ruthless law has been under fire from many quarters—not the least of which are some of the ISPs themselves.

Members of the Telecommunications Carriers’ Forum (TCF) a New Zealand organization which develops standards and codes of practice for the New Zealand telecommunications industry, have spent many weeks trying to draft a Code of Practice dealing with the implementation of Section 92A: That Code of Practice needs a unanimous vote to pass TCF's board.

Now TCF member and New Zealand Internet Service Provider giant TelstraClear have stated they will veto the code, saying:

"TelstraClear considers that there is a fundamental problem with the TCF being a party to any code of this nature, which is that the code would be based on flawed legislation… In TetstraClear’s view, any industry code would simply be an attempt to tidy up poorly drafted legislation. TelstraClear does not consider this to be the responsibility of the TCF. Indeed the best outcome would be if s92A was repealed. Failing that, it should be amended to address the above concerns."

InternetNZ, the group which oversees the Internet in New Zealand—including the management of the .nz domain name system—says implementation of Section 92A will be impossible without TelstraClear's participation:

...TelstraClear’s decision not to support the Telecommunications Carriers’ Forum Copyright Code of Practice means the Government should promptly repeal Section 92A of the Copyright Act.

“Executive Director Keith Davidson notes that the TelstraClear decision means the TCF cannot now implement the Code.”It is clear that the agreement that the Government sought will not now be reached between ISPs and rightsholders. To attempt to bring 92A into force now would invite disaster,” Davidson says.

“The problems with the Code have come to a head because the Government made the future of Section 92A dependent on agreement between a limited group of rights holders and a small number of ISPs.

“What about everyone else who is affected? Section 92A applies to any business that provides Internet services to its staff or hosts a website, and can be triggered by any rights holder or claimed rightsholder with a genuine complaint or a malicious axe to grind,” says Davidson.

The University of Auckland has expressed its concerns:

"The main problem is in Section 92A of the Copyright Act which we believe should be removed from the Act or, if it is to remain in some form, then substantially redrafted with input from stakeholders as would have happened during a select committee process."

"The activities of a university also make use of third party copyright materials. These activities could be seriously affected by copyright notices from rights owners demanding the termination of the accounts of a staff member or a student who has legitimately downloaded material under the fair dealing and education provisions of the Act or under the many licences [sic] the University holds to copy and use third party copyright materials. Universities largely have processes and penalties in place to deal with any copyright infringement by staff and students, but these may or may not incorporate the termination provisions. The requirement to terminate accounts or comply with a Code which cuts across those policies threatens institutional autonomy. A university may face unreasonable compliance costs and procedures if it adopts the Draft Code."

Judge David Harvey, former Chair of the New Zealand Copyright Tribunal and author of Internet.law.nz - Selected Issues
has this to say:

"[Section 92A] is poorly drafted and makes a number of unsupported assumptions, but in essence it suggests that an Internet service provider must develop a policy to cancel an existing contract as a result of copyright infringement.

"The reality of the matter is that the cancellation or termination of the contract arises at the behest, not of the Internet service provider, but of copyright owners. Without significant justification in normal circumstances this could amount to an interference with economic relations and raises significant issues about the sanctity of contract... section 92A is unnecessary and gives rise to a situation where a person may be deprived of rights under a contract without proper legal process."

Google voiced its objections in a 6 March 2009 document to TCF:

“Google has a number of concerns around the new section 92A and the impact the section 92A obligation is likely to have on the balance of interests served by copyright law:

"Section 92A undermines the incredible social and economic benefits of the open and universally accessible Internet, by providing for a remedy of account termination or disconnection that is disproportionate to the harm of copyright infringement online.

"Section 92A puts users’ procedural and fundamental rights at risk, by threatening to terminate users’ Internet access based on mere allegations and reverse the burden of proof onto a user to establish there was no infringement. In Google’s experience, there are serious issues regarding the improper use and inaccuracy of copyright notices by rights holders.

"Section 92A could impose significant burdens on ISPs, as it threatens to require enforcement of policies based simply on rights holders’ allegations of infringement."

There are those who maintain that the withdrawal of TelstraClear sounds the death knell for Section 92a, but the New Zealand parliament is still debating courses of action.

The bottom line in all this is that no one—anywhere—should be deprived of their civil rights, of due course of law, particularly when the accuser is a private party with an agenda but no clear evidence of an internet user’s wrongdoing.

The battle for New Zealanders’ civil rights continues.

Wednesday, March 11, 2009

Kremlin-backed Group Behind Estonia Cyber Attacks

Russian politician: 'My assistant started Estonian cyberwar'

image

At a 3 March 2009 panel discussion between Russian and American experts on information warfare in the 21st century, Sergei Markov, a State Duma deputy from Vladimir Putin's Unified Russia party, admitted his involvement in the 2007 attack that shutdown Estonia’s internet traffic.

"About the cyberattack on Estonia... don't worry, that attack was carried out by my assistant. I won't tell you his name, because then he might not be able to get visas," Markov said.

Estonian officials always claimed the attacks originated from Russia. The attacks, according to computer experts, were distributed denial-of-service, or DDoS, attacks; hundreds or thousands of "zombie" computers are enlisted to overwhelm the target network. They began after April 27, when Estonia removed a World War II Soviet memorial from its capital, Tallinn, provoking howls of protest from the Kremlin, (which seems to spend a very great deal of it’s time howling.) The internet attacks continued to mid-May.

Russia has consistently denied any involvement. On 10 March, however, Konstantin Goloskokov—Markov’s assistant—a commissar in the pro-Putin youth group Nashe, (Молодежное демократическое антифашистское движение «Наши»), which works for the Kremlin, admitted he and some associates had launched the attack—apparently the first time anyone has claimed direct responsibility.

Nashe—which means “Ours!”—is Russian Prime-Minister-For-Life Vladimir Putin's version of the Soviet Komsomol, (Коммунистический союз молодёжи), or Communist Union of Youth.

Putin-Navy-Fur-Cap

Vladimir Putin:
The buck stops with him

"I wouldn't have called it a cyber attack; it was cyber defense," Goloskokov said. "We taught the Estonian regime the lesson that if they act illegally, we will respond in an adequate way."

"We were attacked by 178 countries," quipped Katrin Pargmae, a spokeswoman for the Estonian Informatics Centre, which administers the state's information systems, including the internet.

It is believed to have been the first attack of its kind, directed against virtually the entire informational infra-structure of a NATO country.

And then:

August 2008: Russia's invasion of Georgia was accompanied by a wave of cyber attacks on Georgian government websites. The cyber attacks—which began well before Russian tanks rolled in—overwhelmed Georgian government websites with swarms of data: some websites were defaced by hackers.

There was no clear proof of Russian military involvement (investigators have reportedly traced some of the data to Russian servers tied to organized-crime groups), so the perpetrators may have been nationalists. Still, the timing suggests that even if the responsible parties weren't in uniform, they coordinated their moves with the Russian military.

November 2008: Russian hackers successfully penetrated Pentagon computer systems in the most severe cyber attacks ever on US military networks.

The attacks struck computers within the US Central Command, which oversees Iraq and Afghanistan, and involved malicious software—known as malware—which permeates a network. The attacks were so serious, Admiral Michael Mullen, the chairman of the joint chiefs of staff, briefed President  Bush and Defense Secretary Robert Gates.

I smile when they tell me the Cold War is over. I try not to guffaw out loud, though.

“Soviet Union foreign policy is a puzzle inside a riddle wrapped in an enigma, and the key is Russian nationalism.”

— Winston Churchill

Monday, February 16, 2009

Guilt On Accusation - Draconian Internet Copyright Law To Be Enacted

The New Zealand Parliament Wins Our 'Useless Git of the Week' Award

Three Strikes and You Are Terminated

Will It Happen In The US?

Update! See follow-up articles:
Draconian New Zealand Copyright Law Foundering? March 13, 2009
Draconian Internet Copyright Law Dead, Or Is It? March 23, 2009

NZ-BB

A new draconian law in New Zealand allows the American and New Zealand film and music industries to pressure Internet Service Providers (ISPs) to terminate any individual or business users solely on their say so. If an ISP resists, they may be sued for not complying with the new law--as has happened in Australia.

Under a new provision in the New Zealand Copyright Act (Section 92A), which comes into force on 28 February, internet users’ accounts can be terminated as a result of unproven accusations of piracy. Section 92A states that if a copyright owner thinks that an internet user is guilty of repeatedly breaching copyright, then the user’s ISP will be forced the terminate their internet connections and websites.

In an internet version of the Salem Witch Hunts, the concept of “innocent until proven guilty” will be thrown out the window. Termination of Internet access will occur without any evidence, without a fair trial, without any right of appeal, and with no punishment for anyone making erroneous or malicious accusations of copyright infringement.

A "copyright holder" can get you kicked off an ISP without having to provide any evidence of an actual infringement. Having to [provide evidence] is apparently "impractical" and "ridiculous" in the words of RIANZ [Recording Industry Association of New Zealand] chief executive Campbell Smith. What happens when the "you" above is a public library, or a school? Or if the "copyright holder" makes a mistake or a malicious accusation?

--ComputerWorld Magazine (New Zealand)

Making mistakes can be an easy thing to do. 25% of computers are infected with viruses that download and distribute material without the owners knowledge, interaction or consent. What happens to computer users whose wireless internet connection is compromised? What if that user is a school or hospital?

Already, New Zealand Internet Service Provider giant TelstraClear's head of corporate services, Matthew Bolland, has stated that from 1 November 2008, TelstraClear is taking down websites upon a single accusation of copyright breach. "We don't check or verify," Bolland said "We take it down." ISPs like TelstraClear do not and cannot identify copyright infringement which is why this law forces them to take such actions.

Too bad if the IP has been spoofed, or the accusation is unfounded or even malicious--there is no right for contesting the claim. Too bad too, if the IP is being used by a school, library, university, hospital, business or even a government office!

Justin Graham of the New Zealand law firm Chapman Tripp confirms that the act fails to differentiate between individual accounts (home users) and internet accounts with multiple users such as businesses.

Rick Shera, a partner in law firm Lowndes Jordan, says ISPs have to decide whether material infringes copyright after receiving a complaint. If ISPs choose to leave the material up they have no protection from liability for secondary copyright infringement. The risk of not removing material is, therefore, greater than the risk of taking that material down, Shera says.

Effectively, a single person's bad behavior can bring down an institution, all because certain elements of the recording, videogame and movie industries can't solve their own piracy problems.

"Businesses support the need to protect intellectual property, and we are sympathetic to the significant problems the music, movie and gaming industries face. However, balance is the key. Protecting one person's interests at the expense of others is completely inappropriate," Telecommunications Carriers Forum chief executive Ralph Chivers said.

More sadly, it's symptomatic of a technologically uneducated group of political decision makers being taken for a ride by lobbyists putting their interests ahead of the nation.

--National Business Review (New Zealand)

"What it does is it forces internet service providers to cut off the internet of anyone who's accused of infringing copyright, not found guilty, just accused," said Bronwyn Holloway-Smith of New Zealand’s Creative Freedom Coalition.

Until August, Elliott Smith had over 100 videos on YouTube. Then, he made the mistake of uploading Olympics footage without permission and within 12 hours his account was suddenly deleted.

"I emailed YouTube and they didn't get back to me. So I ended up just setting up a new account. It's probably easier than going back but I didn't have any of my old videos or anything saved to my hard drive so it's a bit of a hassle," said Smith.

The new law forces New Zealand ISPs into the untenable position of being the police, judge, jury and executioners for the entertainment industry. “Three-strike” laws--as proposals to force ISPs to terminate internet users merely accused of illegally downloading copyright material have been called--are being pushed globally by “Big Content” representatives of the entertainment industries. Australia and France recently caved-in and agreed to enact such laws, though the Parliaments of the European Union and the UK have rejected them.

In protest, the Creative Freedom Coalition and others have organized an “internet blackout” February 16-23, during which they encourage internet users to: “Join thousands of New Zealanders already against this law by blacking out your Facebook photo, your websites, your Myspace pages, your Twitter account, in protest against this unjust new law that may come into effect on February 28.”

How long before it happens where you live?