Tech

  • Spelling error clue to tax refund phishing scam

    Without exception, everyone likes to get money back off the taxman.

    That being so, how would you react if you found the email below in one of your mailboxes?

    screenshot of phishing email offering tax refund
    Genuine email from HMRC or a fake – can you tell?

    With the subject line “Error in the calculation of your tax“, all the right colours used by HMRC and genuine links to HMRC website pages on both the left and right of the main message, it definitely has the appearance of a genuine email from the taxman.

    Would your reaction be one of joy that HMRC is prepared to refund you £1,400 of your hard-earned cash? Would that then lead you to click on the link below that figure in green text – the one enticingly indicating My Refvund?

    Running my mouse over that link revealed that it did not go to the HMRC website at all, but a phishing page on a website that seems to be hosted in Bangkok, which is not somewhere I suspect that hosts many .gov.uk domains.

    In addition to the dodgy spelling of the link, another clue is the incorrect use of capitalisation in the final paragraph.

    In case readers were unaware of the HMRC’s procedures, the taxman never sends notifications of a tax rebate by email or asks taxpayers to disclose personal or payment information by email.

    HMRC’s advice to anyone who has received a HMRC-related phishing/bogus email it to forward it to phishing@hmrc.gsi.gov.uk and then delete it.

    HMRC’s website has comprehensive advice on phishing and bogus emails.

    Stay safe!

  • Euro election hustings: a view from the chair

    ORG logoOn Friday evening the Open Rights Group organised one of a series of nationwide European Digital Rights hustings at St Werburgh’s Community Centre in Bristol. This was a chance for local people to quiz MEP candidates from the South West about their views on digital rights and ask them to sign up to the 10 point Charter of Digital Rights.

    Green European Parliament candidate Audaye Elesedy signs the Charter of Digital Rights at St Werburgh's Community Centre
    Green European Parliament candidate Audaye Elesedy signs the Charter of Digital Rights at St Werburgh’s Community Centre. Picture credit: Brent Longborough

    As Chair of St Werburgh’s and having a keen interest in digital rights, I volunteered my services and was surprised to be asked to chair the event.

    When I arrived, Ed Paton-Williams from the ORG had already shown up and there was little to organise in the room apart from setting up the wifi, a couple of notices with the wifi details and the last minute provision of water for the top table.

    In alphabetical order, the candidates who attended were:

    We were supposed to have been joined by Julia Reed from UKIP, but she pulled out at the last moment. Could this have had something to do with a little Twitter bother?

    After a brief introduction from Ed Paton-Williams and a warm welcome to all to the Centre from me, we were off with candidates’ opening statements. All stuck fairly well to the 2 minutes limit for speaking (and many thanks to Hadleigh for the use of his phone with the stopwatch app! Ed.).

    As chair I got to ask the first question: has the EU done enough to allow open source software to compete with proprietary products such as Microsoft Office?

    Some interesting answers followed: Hadleigh and Jay both raised the cost of licensing for small businesses; Audaye raised the use of open standards such as Open Document Format.

    The meeting was then thrown open to questions from the floor. The first concerned data protection and the UK’s government’s desire to make money from selling data provided by citizens. Once again there were some fascinating answers of which I’m reminded of two points in particular: Jay believed people should be compensated financially for the use of their data, whilst Hadleigh stated that companies shouldn’t be buying people’s data. A point made from the floor was that people are very mistrustful of the way the government uses – and loses – data.

    The next question from the floor raised the matter of TTIP. Some candidates, particularly those with links to business, favoured TTIP’s implementation; Georgina said it should be given a chance. Other, more wary candidates feared the consequences of TTIP’s proposals to allow corporations to take governments to court for changes to the competitive commercial landscape. TTIP was also seen as a big threat to personal control of data. Snowden’s revelation of US spying on the EU during TTIP negotiations were mentioned by Audaye.

    This led neatly into the next matter: surveillance. Georgina thought there was too much scaremongering going on about data collection. It’s there to protect us from paedophiles and terrorism, adding: “States knew perfectly well that surveillance happening… on the internet there’s no such thing as privacy.” Jay responded that we’re struggling with oversight in the UK and that access to communications data shouldn’t be a habitual thing. Hadleigh remarked that the public have to be given a guarantee that they won’t be spied on unless they’ve committed crime. Audaye stressed that Germany has gained a competitive advantage in digital sector because its far stronger privacy culture compared with the UK.

    Thangam Debonnaire, Labour’s candidate for the Bristol West parliamentary constituency and a former musician, asked about how the EU should make sure copyright law helps creators protect their income. There was general agreement in the responses that Digital Rights/Restrictions Management (DRM) hadn’t really done anything to stop so-called ‘piracy’, (better known to some of us by its correct definition of ‘copyright infringement’. Ed.). Furthermore, artists deserve better compensation from the likes of iTunes and Spotify. The general impression is that this area still needs attention as the music and film industries are still struggling to come to terms with the internet after a couple of decades.

    In one of the final questions, the power of the UK in the EU was raised from the floor. Candidates pointed out that the UK hadn’t really lost any power, but had lost influence due to its attitude. As regards attitude, the behaviour of UKIP in the European Parliament was criticised severely by the candidates. Proceedings in the Parliament were described as generally civilised and polite. However, UKIP’s MEPs were criticised for being rude to their fellow parliamentarians and failing to do any work on the committees on which they are supposed serve.

    The hustings concluded with closing statements from all candidates and a vote of thanks to them from the chair.

    For me it was a baptism of fire, never having chaired a hustings event before. But the candidates were – apart from a minor bit of mudslinging – models of politeness and made my job in the chair a pleasure. There was none of the two speakers talking at once that I witnessed the previous week at Radio 4’s broadcast from Bristol of Any Questions?

    The tenor of the meeting is perhaps summarised by this tweet from local councillor Rob Telford.

    This was echoed by others who said very similar things to me afterwards.

    There are still a few more ORG Digital Rights hustings to come. Details here.

  • Brussels increases investment in open data

    After launching its open data site opendata.bruxelles.be in February 2012, the Belgian capital has acquired an open data platform, according to Le Monde Informatique.

    As a pioneer of open data in Belgium, the city of Brussels launched its open data site in February 2012, making public datasets available in CSV et HTM formats. Wanting to comply better with the 2012-2018 legislative period which foresees the “systematic posting online of the city’s public data in a digital format in the spirit of open data“, the Belgian capital sought a means of boosting the supply of the council’s data and more especially it use. The data’s storage and downloading in various formats needed to be facilitated. The city of Brussels turned towards an open data platform created by the French start-up OpenDataSoft.

    Screenshot of Brussels Open Data website
    Screenshot of Brussels Open Data website

    An open data platform managed by IT consultants GIAL

    The platform was quickly deployed and is currently managed by Belgian IT consultants GIAL. The tool enables a better visualisation of data via systems of table, maps or graphics. Furthermore, these can also be embedded in other sites, particularly blogs. The data is now arranged into 70 different sets which can easily be found using the site’s internal search facility which offers different types of search – keywords, theme, data producer, etc. The majority of the datasets are produced by the local authority itself, but others produced by federal or regional public sector organisations are also available. On account of this new platform, the city of Brussels is strengthening its role as an open data pioneer in Belgium alongside the local authorities of Ghent, Antwerp and Kortrijk.

  • Paris adds open data clause to public contracts

    The City of Paris has added an open data clause to its public contracts Le Monde Informatique reports.

    The City of Paris is continuing its open data process which was launched in 2011 and made a reality by the launch of the opendata.paris.fr website. It has recently launched a series of meetings between its departments and the re-users of data, to whom it is now offering data challenges.

    Since 17th April, the city council’s public contracts have included a clause asking suppliers responding to invitations to tender to “release the data” produced within the scope of fulfilling the contract. This is one of the council’s latest open data initiatives, a field in which it has been active for more than 3 years. Via Open Data France, the City of Paris wants to share these items with other local authorities who would like to include this type of clause in their invitations to tender.

    Paris has also just started a series of meetings it is planning to organise regularly between council departments and open data users. Under the name “Open Data Paris meetups”, these meetings are open to developers, sponsors, students and more broadly all who are interested in the city’s open data project. The first of these meetings was held at the Hôtel de Ville on 28th April. This meeting featured the launch of the city’s data challenges.

    95 datasets on opendataparis.fr

    screenshot of Paris Open Data website
    Screenshot of licensing page of Paris Open Data website

    Paris set up its open data website in January 2011. It is now on version 2 and currently offers 95 datasets and an API enabling visitors to use them. Amongst the most recently added or amended data are the results of the 2014 local elections, the list of works contracts awarded by the Département de Paris and by the city from 2009 to 2013, as well as, for example, the geographical data for the city’s parks and gardens or a list of outlets in Paris selling coffees for €1.00.

  • FSFE sends open letter to the EU Commission

    FSFE logoThe Free Software Foundation Europe (FSFE) has written an open letter to the EU Commission today – the international “Day against DRM” – asking the EU to prevent Digital Rights Management (or Digital Restrictions Management as termed by the FSFE. Ed.) technology from being closely integrated into the HTML5 standard.

    The FSFE is concerned about efforts currently in progress at the World Wide Web Consortium (W3C), to encourage the integration of DRM technology into web browsers. The W3C oversees many of the key standards on which the World Wide Web is based.

    The full text of the letter is reproduced below.

    To: Commissioner Cecilia Malmstroem (Home Affairs)

    cc: Antonio Tajani (Enterprise)
    Viviane Reding (Justice)
    Joaquin Almunia (Competition)
    Michel Barnier (Internal Market)
    Neelie Kroes (Digital Agenda)

    Dear Commissioner Malmstroem,

    we are writing to you on the occasion of the international Day Against Digital Restrictions Management, which today is being celebrated around the world. We are very concerned about the security of European citizens, and we ask you to take action to protect them.

    The Free Software Foundation Europe (FSFE) is an independent charitable non-profit dedicated to promoting Free Software and freedom in the information society. Today we would like to direct your attention to a very specific threat to the freedom and security of computer users everywhere.

    Both at work and in our personal lives, we conduct a large part of our activity through Web browsers. Ever more of our work and life migrates into the digital domain, and many people use a growing number of web services to work, create, socialise, and express themselves. Businesses and public sector organisations similarly rely on web browsers as crucial tools to perform their everyday tasks.

    Recently, the importance of the Web browser was highlighted when numerous state agencies and IT security companies warned about a long-standing critical security problem in the widely used Microsoft Internet Explorer browser, soon followed by warnings of a vulnerability in the also widely used Adobe Flash Player.

    These incidents were only the most recent ones to highlight the importance of ensuring that such a crucial piece of software as the Web browser is fully under the control of its user. The German Federal Office of Information Security (BSI) issued a list of recommendations for secure Web browsers and their components for use in companies and public bodies on April 14. The BSI notes that due to the way they are used, “Web browsers are exposed to especially high risk from malware”. In the list of recommendations for a secure Web browser, the BSI includes the demand that Web browsers and their components should be completely auditable (Point 1.6).

    Web browsers like Mozilla Firefox or the Chromium browser have succeeded in this regard, providing the public with web browsers that are not only fully auditable, but which can also be freely shared and improved. This is in line with the Open Standards approach which has made it possible for the Internet and the World Wide Web to thrive and grow into its current role as a vital platform for economic activity, social interaction without borders, and unchained creativity.

    The protocols on which the Internet is built, such as the TCP/IP stack and the HTML standard, are fully open and implemented in myriad Free Software products. Free Software powers the vast majority of Web servers, smartphones, embedded devices, and many other applications of technology. The rise of today’s leading Web companies, such as Google, Facebook, and Amazon, would not have been possible without Free Software, and they could not operate without it today. Whatever European companies step up to challenge them are inevitably going to rely on Free Software and Open Standards as well. Free Software and Open Standards are both the foundation of our digital world, and the condicio sine qua non for its future.

    HTML5 is the latest revision of the HTML standard. It is hard to think of a standard that is more crucial for the World Wide Web. HTML5 will deliver a number of important improvements, and is set to be the basis of the World Wide Web for the coming years, and to allow for the kind of rich, responsive interactivity that will allow browsers to replace “apps” as controllers for everything from thermostats to automobiles.

    This is why we are very concerned about efforts currently in progress at the World Wide Web Consortium, which oversees many of the key standards on which the Internet and the World Wide Web are based, to encourage use of the Content Decryption Module (CDM) which cannot be audited. The CDM, though not specified in the HTML5 standard itself, is required by the so-called “Encrypted Media Extension” (EME), developed by a W3C working group. This extension’s primary purpose is to satisfy the desire of a limited number of content providers with traditional business models to generate revenue through restrictive distribution practices. With EME, the W3C would be building a bridge to let content providers take control of users’ computers, letting them impose restrictions far in excess of what consumers’ rights and copyright allow.

    The discussion about EME at W3C is largely driven by a few large US-based companies, and except the BBC takes place without significant European involvement. Given these circumstances, the discussion will likely result in a solution that fails to take the needs of European citizens, businesses and governments fully into account.

    Auditing the Content Decryption Module will be difficult, because the source code of this functionality will be a closely held secret of the company which provides it. Performing such an audit and reporting security flaws would also be illegal in the many countries which have adopted so-called “anti-circumvention” laws. Reporting a security problem in CDM would expose the reporter to the risk of prosecution for making a circumvention device.

    In consequence, individuals, companies and organisations (including the European Commission) would likely end up increasing the amount of software with unknowable security problems which it uses in a high-risk setting.

    Integrating DRM facilities into HTML5 is the antithesis of everything that has made the Internet and the World Wide Web successful. It is directly contrary to the interests of the vast majority of Internet users everywhere, and especially in Europe.

    Recommendations

    The discussions within W3C are now at a crucial juncture in this regard. It is still just about possible to prevent the W3C from making it too easy to effectively require the inclusion of such secret, inauditable software in Web browsers.

    • We urge the Commission to engage with the W3C and ensure that the organisation takes these concerns on board as it decides on the adoption of the Encrypted Media Extension (EME).
    • We further ask the Commission to underline its commitment to the security and freedom of Europe’s citizens by pledging not to make use of the Encrypted Media Extension in its own infrastructure, even if EME would be standardised by W3C.
    • At a minimum, the W3C should require covenants from EME participants through which they promise not to take action against entities who report and demonstrate vulnerabilities in EME and the CDM; and covenants to safeguard entities who reverse-engineer and publish details of EME and CDM implementations for the purpose of interoperability, including interoperability with Free Software.

    At FSFE, we look forward to supporting the Commission in taking the appropriate actions to safeguard the interests of Europe’s citizens and companies, and remain at the Commission’s service.

    Sincerely,
    Karsten Gerloff, President Free Software Foundation Europe

  • Bryan Lunduke says: “Linux sucks”

    I’m indebted to Linux.com for alerting me to the video below.

    Bryan Lunduke is social media marketing manager at SUSE (the first Linux distribution your correspondent used daily. Ed.), as well as a writer and commentator.

    The talk was delivered at LinuxFest Northwest in Bellingham, Washington on Saturday 26th April 2014.

    Lunduke takes a good-humoured critical aim at some of the things that make Linux annoying, the development process which is likened to ‘herding millions of cats’, the large amount of forking that goes on, the age of the X.Org display server and the insistence of some distributions, particularly Fedora and Ubuntu on developing their own alternatives – Wayland and Mir respectively – for what is essentially something old, trusted and reliable, like X.Org.

    Fedora and Ubuntu/Canonical come in for plenty of gentle ribbing from Lunduke.

    About halfway through, Lunduke then turns the criticism completely on its head by stating that all the annoyances are actually what make Linux great and why we users love it. Furthermore, he points out that we can criticise our operating system of choice – and have it criticised – without acrimony; at this point Lunduke mentions something about Mac users… 🙂

    Anyway, the video itself is 45 minutes long, but well worth it. I hope you watch it all the way through and enjoy it (you should do if you you’re more than just content with running Linux as an operating system. Ed.). I certainly did.

  • LibreOffice 4.3 bug hunting session announced

    The first bug hunting session for LibreOffice 4.3 will take place from 23rd to 25th May 2014, The Document Foundation blog announced yesterday. This will coincide with the availability of the first beta of the new major release.

    image of LibreOffice Mime type icons
    LibreOffice for all your office suite needs: word processing, spreadsheets, presentations, database, drawing and formulas

    Those wishing to contribute and participating in the bug hunting session can find details on The Document Foundation wiki./ The wiki also has a list of new features and improvements for LibreOffice 4.3 to check for bugs and regression.

    Participants will need to have a PC with Windows, MacOS or Linux and LibreOffice 4.3 Beta 1.

    Filing bug reports will be extremely easy thanks to the help of experienced volunteers who will be available via the QA mailing list (libreoffice-qa@lists.freedesktop.org) and IRC channel (irc://irc.freenode.net/#libreoffice-qa).

    A second LibreOffice 4.3 bug hunting session will be organised immediately after the release of LibreOffice 4.3 Release Candidate 1 in mid-June.

  • ORG meet-up at St Werburghs

    ORG logoThe Open Rights Group (ORG), an organisation which exists to preserve and promote your rights in the digital age, is holding a meet-up at 8.00 pm on Thursday 24th April 2014 at St Werburgh’s Community Centre, Horley Road, Bristol, BS2 9TJ (map).

    Following the Snowden revelations on GCHQ’s role in Prism, Open Rights Group, Big Brother Watch, English PEN and Chaos Computer Club spokesperson Constanze Kurz are challenging the UK government at the European Court of Human Rights.

    The European Court has completed its preliminary examination of the case and has asked the British Government to justify how GCHQ’s practices and the current system of oversight comply with the right to privacy under Article 8 of the European Convention on Human Rights.

    The court has also given the case a rare priority designation. The British government now has until 2nd May to respond, after which the case will move into the final stages before judgement.

    Join ORG in Bristol to hear from Dan Carey, the solicitor for the application, as he explains what the challenge hopes to achieve and how it will progress from here.

    We’ll also be hearing about the Don’t Spy On Us campaign from ORG’s Policy Director, Javier Ruiz, as ORG asks the public to sign its 6 key principles on mass surveillance.

    The event will provide a fun and informal way to meet with other local ORG supporters, as well as an opportunity to learn about mass surveillance.

    Please join the meetup group if you’re interested in coming along.

  • OPW’s success partly to blame for GNOME expenditure freeze

    Gnome logoAccording to German IT news site Heise, the financial cushion of the Gnome Foundation -non-profit organisation that furthers the goals of the GNOME Project, helping it to create a free software computing platform for the general public that is designed to be elegant, efficient, and easy to use – has declined so sharply that the organisation has frozen part of its expenditure. The success of the Gnome Outreach Program for Women (OPW) is said to be partly to blame for this situation (posts passim).

    The situation was explained in an email to Foundation members over the weekend.

    Dear Foundation members,

    Due to a shortfall in the budget, the Foundation board voted on 2014-04-08 to freeze all expenditure which is not essential to the running of the Foundation. This freeze affects sponsorship expenses
    which are unpaid at this time, but it does not affect the funds which we hold for other organisations.

    By keeping our expenditures to a minimum while we regain some delayed revenue, we aim to have things back to normal within a few months. All Foundation members who expect to receive reimbursements within the next three months have already been informed of the issue and most have responded positively. The board will prioritise these pending reimbursements over other expenses.

    The issue has been caused by a number of factors. These include increased administrative overheads in the last few years due to the increased turnover which has been caused by to the Outreach Program
    for Women (OPW), and the associated payments going out while the associated income has been slow to come in.

    The board expects that you may have some questions or would like to know more details about the problem, please read https://wiki.gnome.org/FoundationBoard/CurrentBudgetFAQ and contact the board at board-list gnome org if you have any further questions.

  • LibreOffice 4.2.3 released

    The Document Foundation has announced on its blog the release of LibreOffice 4.2.3, the third minor release of the LibreOffice 4.2 family. Codenamed “Fresh”, LibreOffice 4.2.3 is the most feature rich version to date of this free and open source office suite. The release itself is described by The Document Foundation as being suited for early adopters. For enterprise use and more conservative users, The Document Foundation recommends the more mature LibreOffice 4.1.5 release.

    People interested in this release’s technical details and bug fixes can view the change logs as follows:

    In addition, the released version of LibreOffice 4.2.3 adds a security fix for the Heartbleed bug (CVE-2014-0160).

    screenshot of Calc spreadsheet program
    LibreOffice’s Calc spreadsheet program running on Ubuntu Linux

    Downloading LibreOffice

    LibreOffice 4.2.3 and LibreOffice 4.1.5 are both available for download from http://www.libreoffice.org/download/. Extensions and templates to increase the software’s functionality and add specific features are available at http://extensions.libreoffice.org/.

Posts navigation