https://www.theregister.com/2021/10/25/john_gilmore_removed_from_eff_board/ [user] [user] Sign in The Register(r) -- Biting the hand that feeds IT [magn] [burg] [burg] Topics Security Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem All On-PremServersStorageNetworksHPCPersonal Tech (X) Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Vendor Voice All Vendor VoiceAdobeAmazon Web Services (AWS)Amazon Web Services (AWS) MigrationGoogle CloudGoogle Cloud's ApigeeGoogle Workspace LenovoNutanixRapid7Red hatSophosVeeamVirtru (X) Resources * Whitepapers * Webinars * Newsletters Situation Publishing * The Next Platform * Devclass * Blocks and Files Get our Weekly newsletter [legal] Legal Electronic Frontier Foundation ousts co-founder John Gilmore from its board He's free of governance duties now, but still an emeritus member Simon Sharwood, APAC Editor Mon 25 Oct 2021 // 05:58 UTC 13 comment bubble on white --------------------------------------------------------------------- 13 comment bubble on white # reddit Twitter Facebook linkedin WhatsApp email [https://www.theregis] Copy Electronic Frontier Foundation (EFF) co-founder John Gilmore has been removed from any active role on the digital rights organisation's board but will continue to serve as emeritus member. "Since he helped found EFF 31 years ago, John Gilmore has provided leadership and guidance on many of the most important digital rights issues we advocate for today," wrote EFF executive director Cindy Cohn. If your instincts tell you that's the kind of prose that presages a "but", your instincts were correct. [legal] "But in recent years, we have not seen eye-to-eye on how to best communicate and work together, and we have been unable to agree on a way forward with Gilmore in a governance role. That is why the EFF Board of Directors has recently made the difficult decision to vote to remove Gilmore from the Board." [legal] [legal] The EFF announcement adds that the board is "deeply grateful for the many years Gilmore gave to EFF as a leader and advocate, and ... has elected him to the role of Board Member Emeritus moving forward". Cohn's post doesn't outline the nature or particulars of the dispute that led to Gilmore's departure. The EFF appears not to publish board minutes, nor to have posted its constitution or charter to its site (but does advocate for transparency), making it hard to ascertain why Gilmore was removed or the powers that made it possible to do so. * FSF doubles down on Richard Stallman's return: Sure, he is 'troubling for some' but we need him, says org * Who in America is standing up to privacy-bothering facial-recognition tech? Maine is right now leading the pack * Open-source projects glibc and gnulib look to sever copyright ties with Free Software Foundation The EFF's announcement about Gilmore's change of status was published on Friday. The Register has requested further information about the reasons for his changed status. The statement includes a quote from the man himself. [legal] "I am so proud of the impact that EFF has had in retaining and expanding individual rights and freedoms as the world has adapted to major technological changes," Gilmore is quoted as saying. "My departure will leave a strong board and an even stronger staff who care deeply about these issues." In recent years, we have not seen eye-to-eye on how to best communicate and work together Gilmore co-founded the EFF in 1990 - just one standout on a CV that includes being hired as employee number five at Sun Microsystems, helping to disprove the security of the Data Encryption Standard (DES), and creating Usenet's "alt." newsgroups. He's widely credited as the source of the famous aphorism "The Net interprets censorship as damage and routes around it." Gilmore's EFF profile states "He's trying to get people to think more about the society they are building." As an emeritus board member, he'll have the chance to keep doing that - but without a vote. (r) Get our Tech Resources #Share reddit Twitter Facebook linkedin WhatsApp email [https://www.theregis] Copy 13 Comments Corrections Send us news --------------------------------------------------------------------- [legal] Other stories you might like * If you're using this hijacked NPM library anywhere in your software stack, read this US govt issues alert over JS package downloaded 8m times a week - plus more news from world of infosec Iain Thomson in San Francisco Mon 25 Oct 2021 // 22:13 UTC comment bubble on black In brief The US government's Cybersecurity and Infrastructure Security Agency (CISA) has warned developers that a version of the ua-parser-js JavaScript library, available via NPM, was infected with data-stealing and cryptocurrency-mining malware. The package, which is fetched nearly eight million times a week, is used by software to extract information about users' browsers, operating systems, and host hardware from their clients' user-agent strings. It's useful for web apps to predict or figure out the devices connecting to them. The NPM account hosting it was seemingly compromised by miscreants, who modified the package so that when installed, it would bring in various bits of malware on whatever system was running the code. Continue reading * Non-profit's IT manager accused of embezzling $400k by buying gear, services from his own fake companies Boss used org's credit card to buy stuff from Amazon, Square accounts he set up, say prosecutors Thomas Claburn in San Francisco Mon 25 Oct 2021 // 20:10 UTC 6 comment bubble on white An IT manager in the US was arrested on Friday for allegedly embezzling about $370,000 from an unidentified non-profit organization. Prosecutors said Kyriakos 'Rick' Kapiris, 35, of Northborough, Massachusetts, was indicted on two counts of wire fraud and one count of money laundering. Released on $10,000 bond to await the resolution of the charges, Kapiris is alleged to have used his Sturbridge-based organization's credit cards to purchase IT equipment and services from firms he supposedly created to fake sales and embezzle funds. Continue reading * The future: Windows streaming through notched Apple screens Choice is the word for Jamf's Dean Hager Richard Speed Mon 25 Oct 2021 // 18:45 UTC 1 comment bubble on white Interview As Apple's devices continue to find favour with enterprise users, the fortress that is Windows appears to be under attack in the corporate world. Speaking to The Register as the Jamf Nation User Conference wound down, the software firm's CEO, Dean Hager, is - unsurprisingly - ebullient when it comes to the prospects for Apple gear in the world of suits. Jamf specialises in device management and authentication, and has long been associated with managing Apple hardware in business and education environments. In recent years it has begun connecting its products with services such as Microsoft's Azure Active Directory as administrators face up to a hybrid working future. Continue reading * There's a wave of ransomware coming down the pipeline. What can you do about it? AI can help. Here's how... David Gordon Mon 25 Oct 2021 // 18:00 UTC Sponsored The Colonial Pipeline attack earlier this year showed just how devastating a ransomware attack is when it is targeted at critical infrastructure. It also illustrated how traditional security techniques are increasingly struggling to keep pace with determined cyber attackers, whether their aim is exfiltrating data, extorting organisations, or simply causing chaos. Or, indeed an unpleasant combination of all three. So, what are your options? More people looking for more flaws isn't going to be enough - there simply aren't enough skilled people, there are too many bugs, and there are way too many attackers. So, it's clear that smart cyber defenders need to be supplemented by even smarter technology incorporating AI. You can learn what this looks like by checking out this upcoming Regcast, "Securing Critical Infrastructure from Cyber-attack" on October 28 at 5pm. Continue reading * Ransomware criminals have feelings too: BlackMatter abuse caused crims to shut down negotiation portal Or so says infsec outfit Emsisoft Gareth Corfield Mon 25 Oct 2021 // 17:16 UTC 3 comment bubble on white Hurling online abuse at ransomware gangs may have contributed to a hardline policy of dumping victims' data online, according to counter-ransomware company Emsisoft. Earlier this month, the Conti ransomware gang declared it would publish victims' data and break off ransom negotiations if anyone other than "respected journalist and researcher personalities" [sic] dared publish snippets of ransomware negotiations, amid a general hardening of attitudes among ransomware gangs. Typically these conversation snippets make it into the public domain because curious people log into ransomware negotiation portals hosted by the criminals. The BlackMatter (aka DarkSide) gang's portal credentials (detailed in a ransom note) became exposed to the wider world, however, and the resulting wave of furious abuse hurled at the crims prompted them to pull up the virtual drawbridge. Continue reading * Windows XP@20: From the killer of ME to banging out patches for yet another vulnerability When NT and 9x became one Richard Speed Mon 25 Oct 2021 // 16:24 UTC 13 comment bubble on white Feature It was on this very day, 20 years ago, that Microsoft released Windows XP to General Availability. Regarded by some as the cockroach of the computing world, in part due to its refusal to die despite the best efforts of Microsoft, XP found its way into the hands of customers on 25 October 2001 and sought to undo the mess wrought upon the public by 2000's Windows Millennium Edition (ME). While ME used the Windows 9x kernel, XP was built on the Windows NT kernel, formerly aimed at the business market and a good deal more stable. It also upped the hardware requirements on its preceding consumer OS. Where ME recommended 64MB of memory, XP wanted at least 128MB. And although masochists could run ME on a VGA screen, XP insisted on a minimum of SVGA. It all seems rather quaint now, but could be a painful jump back in the day. Continue reading * UK watchdog launches full probe of Motorola Solutions' cop-comms deals on Emergency Services Network Firm working on both old programme and its replacement - CMA checks potential 'incentive' to delay Paul Kunert Mon 25 Oct 2021 // 15:31 UTC 7 comment bubble on white Britain's competition watchdog is launching a full blown probe into whether Motorola Solutions is abusing its position as the sole provider of an emergency service network by holding up the replacement project. In early July, the Competition and Markets Authority (CMA) said it was consulting on whether to take a deeper dive into the TETRA mobile radio network, run by Airwave (itself owned by Motorola), which currently delivers comms to support police, ambulance and fire rescue services. The service, launched in 2000, was due to be replaced by the 4G-based Emergency Services Network in 2019 but that programme is running years late - and at last count in mid-2019, was PS3bn over budget and three years late. Continue reading * Intel hopes to burn newly open-sourced AI debug tech into chips Chipzilla dreams of planting ControlFlag in hardware Agam Shah Mon 25 Oct 2021 // 14:45 UTC 5 comment bubble on white Intel Labs has big plans for a software tool called ControlFlag that uses artificial intelligence to scan through code and pick out errors. One of those goals, perhaps way out in the future, is to bake it into chip packages as a last line of defense against faulty code. This could make the information flow on communications channels safer and efficient. But that's a big "if," and contingent to many things falling in place. Last week Intel open-sourced the tool - dubbed ControlFlag - to software developers. The software pores over lines of code and points out errors that developers can then fix. Continue reading * SolarWinds attacker on the move: Russia's Nobelium crew has trebled attacks targeting MSPs, cloud resellers, says Microsoft Phishing and password spraying on the up Gareth Corfield Mon 25 Oct 2021 // 13:16 UTC 7 comment bubble on white Russia's Nobelium group - fingered as being a Russian state actor by both the United States and Britain - has massively ramped up phishing and password spraying attempts against managed service providers (MSPs) and cloud resellers, Microsoft's security arm has warned. The Windows maker said the group's targeted attacks against "resellers and other technology service providers that customize, deploy and manage cloud services and other technologies on behalf of their customers" had trebled over the past three months. Nobelium has been linked by Microsoft and others as the organisation behind the infamous SolarWinds supply chain compromise, and linked to Russia's foreign intelligence (SVR). In infosec circles the SVR-backed group is also known as APT29. Continue reading * Tesla slams into reverse, pulls latest beta of Full Self-Driving software from participating car owners FSD rolled back to 10.2 after 'issues' found Richard Speed Mon 25 Oct 2021 // 12:31 UTC 21 comment bubble on white Tesla has yanked the latest beta, 10.3, of its Full Self-Driving (FSD) software from participating car owners after boss Elon Musk noted the company was "seeing some issues" with the code. Continue reading * HIV Scotland fined PS10,000 for BCC email blunder identifying names of virus-carriers' patient-advocates 'Serious deficiencies in tech and organisational measures' Paul Kunert Mon 25 Oct 2021 // 11:48 UTC 5 comment bubble on white The United Kingdom's data watchdog is calling on organisations to review their "bulk email practices" after a BCC blunder by HIV Scotland incurred a PS10,000 fine for breaking data protection regulations. The case pertains to an email that was sent to 105 individuals on the Community Advisory Network (CAN) list, which is made up of patient-advocates "from across Scotland to represent the full diversity of people living with HIV". In the offending chain, all of the email addresses were visible to all recipients and some 65 were people identified by name. Continue reading ABOUT US* * Who we are * Under the hood * Contact us * Advertise with us MORE CONTENT* * Latest News * Popular Stories * Forums * Whitepapers * Webinars SITUATION PUBLISHING* * The Next Platform * DevClass * Blocks and Files * Continuous Lifecycle London * M-cubed Situation Publishing The Register - Independent news and views for the tech community. Part of Situation Publishing SIGN UP TO OUR DAILY NEWSLETTER Subscribe Twitter Facebook LinkedIn feeds no-js Biting the hand that feeds IT (c) 1998-2021 Do not sell my personal information Cookies Privacy Ts&Cs