Section 201 -- Gives federal officials the authority to
intercept wire, spoken and electronic communications
relating to terrorism.
Section 202 -- Gives federal officials the authority to
intercept wire, spoken and electronic communications
relating to computer fraud and abuse offenses.
Subsection 203(b) -- Permits the sharing of grand jury
information that involves foreign intelligence or
counterintelligence with federal law enforcement,
intelligence, protective,immigration, national
defense or national security officials.
Subsection 203(d) -- Gives foreign intelligence or
counterintelligence officers the ability to share
foreign intelligence information obtained as part
of a criminal investigation with law enforcement.
Section 204 -- Makes clear that nothing in the law
regarding pen registers -- an electronic device
which records all numbers dialed from a particular
phone line -- stops the government's ability to
obtain foreign intelligence information.
Section 206 -- Allows federal officials to issue roving
"John Doe" wiretaps, which allow investigators to
listen in on any telephone and tap any computer they
think a suspected spy or terrorist might use.
Section 207 -- Increases the amount of time that federal
officials may watch people they suspect are spies or
terrorists.
Section 209 -- Permits the seizure of voicemail messages
under a warrant.
Section 212 -- Permits Internet service providers and
other electronic communication and remote computing
service providers to hand over records and e-mails
to federal officials in emergency situations.
Section 214 -- Allows use of a pen register or trap and
trace devices that record originating phone numbers
of all incoming calls in international terrorism or
spy investigations.
Section 215 -- Authorizes federal officials to obtain
"tangible items" like business records, including
those from libraries and bookstores,for foreign
intelligence and international terrorism
investigations.
Section 217 -- Makes it lawful to intercept the wire or
electronic communication of a computer hacker or
intruder in certain circumstances.
Section 218 -- Allows federal officials to wiretap or
watch suspects if foreign intelligence gathering is
a "significant purpose" for seeking a Federal
Intelligence Surveillance Act order. The pre-Patriot
Act standard said officials could ask for the
surveillance only if it was the sole or main purpose.
Section 220 -- Provides for nationwide service of search
warrants for electronic evidence.
Section 223 -- Amends the federal criminal code to provide
for administrative discipline of federal officers or
employees who violate prohibitions against unauthorized
disclosures of information gathered under this act.
Section 225 -- Amends FISA to prohibit lawsuits against
people or companies that provide information to federal
officials for a terrorism investigation.
Monday, February 15, 2010
Key Provisions of the USA Patriot Act
Monday, January 25, 2010
What is privacy protection and the Law?
In a consumer protection approach, in contrast, it is acknowledged that individuals may not have the time or knowledge to make informed choices, or may not have reasonable alternatives available. This approach advocates greater government definition and enforcement of privacy standards.
Privacy Law
Privacy law is the area of law concerning the protecting and preserving of privacy rights of individuals. While there is no universally acceptes privacy law among all countries, some organizations promote certain concepts be enforced by incividual countries. For example, the Universal Declaration of human Rights, article 12, states:
What is privacy?
Monday, January 11, 2010
Who are the computer criminals and what are their objectives?
OBJECTIVES:
Computer criminals have different objectives. An underground network of hackers helps pass along secrets of success; as with a jigsaw puzzle, a few isolated pieces joined together may produce a large effect. Others attack for curiosity, personal gain, or self-satisfaction. And still others enjoy causing chaos, loss, or harm. Criminals seldom change fields from arson, murder, or auto theft to computing; more often, criminals begin as computer professionals who engage in computer crime, finding the prospects and payoff good. Electronic spies and information brokers have begun to recognize that trading in companies' or individuals' secrets can be lucrative. A hacker wants a score, bragging rights. Organized crime wants a resource; they want to stay and extract profit from the system over time.
Zero-day attack
A zero day attack, also known as a zero hour attack, takes advantage of computer vulnerabilities that do not currently have a solution. Typically, a software company will discover a bug or problem with a piece of software after it has been released and will offer a patch — another piece of software meant to fix the original issue. A zero day attack will take advantage of that problem before a patch has been created. It is named zero day because it occurs before the first day the vulnerability is known.
For example, On November 09, 2006, there was a zero-day attack on a part of Windows called the XMLHTTP 4.0 ActiveX Control. When a web browser opened an infected web page in Internet Explorer (IE), it called the ActiveX control, which then helped the attacker to cause a buffer overflow. Attackers were then able to download spyware and steal data.
(www.mysecurecyberspace.com)
