Google cleared in YouTube copyright case in Spain

 
News.cnet.com. Google has been cleared in a YouTube copyright-infringement case filed by a Spanish broadcaster.

In its lawsuit against the search giant, Spanish broadcaster Telecinco claimed that YouTube should be held responsible for people who upload videos that infringe on Telecinco's copyrights.

But a federal court in Madrid rejected those claims today, ruling that it is the responsibility of copyright holders to identify such content and inform YouTube if it infringes on their copyrights.

In reaching its decision, the court also noted that YouTube offers content owners tools to remove any material that infringes on their copyrights, further putting the onus on them, rather than on YouTube, to take action against copyright-infringing content.
 
In a blog post today, Google hailed the ruling and called it a "clear victory for the Internet and the rules that govern it." The company said the decision reaffirms European law, which finds that content owners are the ones best suited to determine whether something infringes on a copyright and that YouTube has a responsibility to remove such content only when notified by the owner.

Specifically, Google pointed to its Content ID technology, which gives content owners the ability to notify YouTube of any material that infringes on a copyright. The owner can then tell YouTube whether to block the content, put an ad next to it in order generate revenue, or simply keep track of the number of views. The company said that Content ID is being used by more than 1,000 media providers across Europe.
Google also noted the challenges that it and other online companies would face if they were held responsible for identifying copyrighted content.

"More than 24 hours of video are loaded onto YouTube every minute," according to the blog. "If Internet sites had to screen all videos, photos, and text before allowing them on a website, many popular sites--not just YouTube, but Facebook, Twitter, MySpace and others--would grind to a halt."
Google has squared off against other media outlets over the question of who should be held accountable for copyrighted material uploaded to YouTube.

Earlier this month, a German court ruled against the search giant, finding that YouTube was liable after users uploaded several copyrighted videos of singer Sarah Brightman.

But in June, the company won a decision in a longstanding, $1 billion lawsuit filed by Viacom, which accused Google of encouraging its users to violate copyright. Like the court in Madrid, the judge in that case found that the burden is on the content owners to identify copyrighted material and that only then does YouTube have a responsibility to remove that content.

Is your PC a sitting duck for hackers?

How confident are you that your computer is safe from an online attack?
Chances are you rely on vendors like Microsoft and Apple to let you know when a security update is ready to be installed. (Google updates systems automatically.)


But until a patch is released, that hole--known as a zero-day vulnerability--in effect makes your computer a sitting duck for anyone who writes an exploit for it and bothers to distribute it via e-mails and drive-by downloads on Web sites.

EEye Digital Security launched a Web site yesterday that lists current zero-day vulnerabilities and offers an archive on ones that have been patched. The Zero Day Tracker compiles information on publicly disclosed security holes and provides details on them including what software they affect, how severe they are, the potential impact and suggestions for workarounds and other protection techniques.


Marc Maiffret, co-founder and chief technology officer of eEye, describes the free site as a "one-stop shop" for zero-day information.
"For the longest time the only company that would notify you about zero-days was Microsoft, and recently Adobe has started doing that," he said. "But there are still many other companies that have zero-day vulnerabilities that go unreported."

The most widely used database of software vulnerabilities is the National Vulnerability Database sponsored by the Department of Homeland Security's National Cyber Security Division/US-CERT and run by the National Institute of Standards and Technology. There is also the Open Source Vulnerability Database, the US-CERT Vulnerability Notes Database and one run by SecurityFocus. But you have to do some digging on the sites to find the vulnerabilities that are unpatched.

Zero Day Tracker lists the outstanding unpatched holes with the most recent at the top. There are 21 current zero-days, all of them from 2010 except for one from 2006 and one from 2005. The oldest extant unpatched hole was first disclosed in November 2005 and affects Windows 2000. Patched zero-days are archived by year and date back to 2005.

"Microsoft, as some might expect, has the largest amount of unpatched zero day vulnerabilities in 2010," Maiffret said. Microsoft also dominates previous years too, not surprisingly, with increasing numbers for Adobe Systems as the years progress and only a few for Apple among them.

Those statistics are cursory and likely to change as eEye works to populate the archives.
Meanwhile, asked to comment on the dearth of Apple listings, Maiffret said that reflects on Apple's market being much smaller than Windows and does not mean that Macintosh software is more secure.

"There are significantly fewer zero-day vulnerabilities for Apple compared to Microsoft and Microsoft-related applications, but it's definitely not about Mac not having vulnerabilities," he said. Attackers prefer to spend their time and energy targeting the 90 or so percent of computers on the Internet running Windows, he added. (For more on the Mac-PC comparison, see "In their words: Experts weigh in on Mac vs. PC security.")

Recently, Adobe rushed out a patch for a zero-day vulnerability in Flash Player, and Microsoft released an emergency patch for one that exploited a Windows hole to spread the Stuxnet worm, which targets industrial control and critical infrastructure systems. Stuxnet exploited three other Windows vulnerabilities, one of which Microsoft patched last week and two others that are pending.

The Zero Day Tracker site also will include information on unpatched mobile software, which is a growing field. "One of the last iPhone jailbreak hacks out there was actually leveraging a vulnerability within PDF (portable document format) processing on the iPhone," Maiffret said. "That's an example of a zero-day vulnerability on the mobile platform."

In addition to offering a handy resource for people looking for zero-day information, Maiffret hopes that publicizing vulnerabilities on the Zero Day Tracker site will motivate vendors to patch them more quickly. "We want to put pressure on software vendors," he said.

The company is gathering its information from vendors, security e-mail lists, and by monitoring underground and overseas forums where malicious hackers brag about finding or exploiting holes in popular programs. "One (tip) we got was based on conversations on a Chinese message board," Maiffret said.

Often, when announcing a security hole vendors will attempt to assuage customer fears by announcing that attacks targeting the vulnerability have not yet been seen in the wild. But it's usually only a matter of time before an exploit surfaces, particularly if the software is something popular like Windows, Adobe Reader or Internet Explorer, according to Maiffret. "Often it's within the same day," he said.

For instance, Microsoft on Friday warned of a serious hole in its ASP.NET framework used to create Web sites and said it was not aware of any attacks using it. On Monday, the company updated its security advisory on the vulnerability to say that it was aware of "limited, active attacks" using the hole.

Exploits can go undetected for months, or even longer. For example, it's unclear how long the Operation Aurora attack that targeted Google and dozens of other companies via an unknown hole in Internet Explorer was going on. Google disclosed it in January 2010 and said it uncovered it the previous month. But one analysis said it was first tested in the wild five months before then, although it might not have been targeting the same companies at that time. Several days after Google announced the attacks, Microsoft confirmed the IE hole and a week later patched it.
"The vulnerability was being used before the industry knew about it," Maiffret said. "There are a huge number of attacks we don't know about and we typically learn about accidentally."


Read more: http://news.cnet.com/security/?tag=hdr;snav#ixzz10g3UShml

Going corporate: Chrome getting admin-friendly

Chrome, like Android, got its start as a technology geared for individuals, not companies. And just as Google updated Android with features such as Microsoft Exchange support, Chrome is being refashioned for a broader world of corporate use.
 

News.cnet.com. The results of the work can be seen at Google's Chrome administrative information site. The site includes quick-start guides for administrators, policy templates for setting group permissions, and a list of tweakable settings that can be enforced through policies.

For example, administrators can use the settings to prohibit use of particular plug-ins, set the home page, disable synchronization services, and set the interval for checking Chrome's automated update service. That includes halting automatic updates altogether.

Chrome has caught on among early adopters and has tens of millions of users. Getting corporate buy-in could help the browser's prospects, and with it Google's ambition to make the Web a more powerful foundation for applications rather than just Web pages to visit.

It took years for Firefox to attain some legitimacy among corporations, but Chrome in some ways could have an easier time. With Firefox, Mozilla helped fight for the idea that Web pages should be built to conform to various Web standards rather than to just work on the dominant browser, Microsoft's Internet Explorer.

That message caught on, with the upcoming IE9 aggressively embracing many of those standards. For Google, it means it's easier for a new browser to catch on since compatibility issues are less troublesome.
Even with easier compatibility, though, corporate IT personnel are not known for their enthusiasm for embracing new software. They're often naturally conservative, since change can break internal applications, confuse users, and bring other complications. Letting administrators set Chrome behavior will, though, make it more palatable.

originally posted by : Deep Tech