Showing posts with label filesharing. Show all posts
Showing posts with label filesharing. Show all posts

Monday, March 2, 2009

P2P Filesharing Dangers: Marine 1 Blueprints?

Blueprints for Marine 1 were found by employees of Tiversa, a P2P monitoring company. The blueprints and avionics package were found in a file that appeared to have come from a defense contractor's network - the news article's spin sounds like a sales pitch for Tiversa's services, but the point remains useful.

Corporate IT knows the dangers that P2P programs can pose - many have default shares enabled, and some of them share a larger portion of the user's hard drive than might be expected. There are controls: extrusion prevention, local system lockdowns, and periodic software scans, but they require a strong set of corporate IT policies and security standards that are effectively enforced. For some systems, this is where access controls come into play - the system containing protected information shouldn't have had outbound Internet access in the first place!

Wednesday, August 13, 2008

H.R. 4137 - P2P and Higher Education


EDUCAUSE and the American Council on Education have released an advisory regarding H.R. 4137, a recently passed law waiting on the President's signature. The law requires higher education institutions to do three major things:

  1. To notify students that illegal distribution of copyrighted materials may subject them to civil and criminal penalties, and to describe the steps that the institution will take to detect and punish illegal distribution of copyrighted materials.
  2. The institutions will have to certify to the Secretary of Education that they have created plans to effectively combat unauthorized distribution of copyrighted materials. Institutions are required to consider the use of technology based deterrents such as bandwidth shaping and traffic monitoring. Notably, institutions are not required to adopt any specific technology, and the Secretary of Education is not required to collect, review, or to approve the plans.
  3. Institutions are required to offer alternatives to illegal file sharing "to the extent practicable".

These requirements are far less egregious than the might have been, and allow quite a bit of room for universities to operate within. That is, in large part because EDUCAUSE and other higher education organizations have been fighting this and similar requirements for some time. There is both good and bad news for institutions: the good is that as the EDUCAUSE memo notes, institutions operating in good faith and making reasonable efforts to comply should be in good shape. The bad news is that the negotiated rulemaking around the law must still occur, and that further restrictions and requirements can result.

Flickr Creative Commons image courtesy of MacGBeing.