Thursday, October 08, 2015

: BITAG Publishes Report: Differentiated Treatment of Internet Traffic

Denver, CO (October 8, 2015):  Today, the Broadband Internet Technical Advisory Group (“BITAG”) announced the publication of its technical report on the subject of Differentiated Treatment of Internet Traffic. The executive summary of the report can be found further below – including the full set of observations and recommendations – and the report itself can be found at:http://www.bitag.org/documents/BITAG_-_Differentiated_Treatment_of_Internet_Traffic.pdf.
Differentiated treatment of Internet Access Service traffic has been a subject of debate and regulatory scrutiny. In February 2015, the Federal Communications Commission (FCC) adopted Open Internet rules that address paid prioritization as well as other topics. This report touches on a broad range of questions associated with differentiation, but is not intended to address or analyze the economic, legal, regulatory, or public policy issues that the differentiated treatment of Internet access service traffic may raise, focusing instead on the technical issues.
The data transmitted across the networks that make up the Internet is formatted as packets, which contain information payloads encapsulated within one or more headers. These headers provide the information needed to deliver the packets to their destinations. As these packets travel across networks, they contend with other packets for network resources. The simplest way to handle this contention would be on a first come, first served basis (also known as First In First Out, or FIFO). In practice, however, network operators make many exceptions to FIFO, using the packet header information to classify packets into flows and treating those flows differently, for example rearranging the order or the timing with which packets are sent, or sending them along different network paths. This is done for various reasons, including meeting service level agreement (SLA) guarantees and selecting paths for traffic from different applications, among other things. Differentiated treatment of traffic can also contribute both to the efficiency of a network and to the predictability of the manner in which network resources are shared. The ability to treat traffic differentially has been built into Internet protocols from the beginning but has not been deployed end-to-end due to a number of issues.
Observations. From the analysis made in the report and the combined experience of its members when it comes to the differentiated treatment of Internet traffic, the BITAG Technical Working Group makes the following observations (See Executive Summary below or full report for the complete explanation of each):
·      TCP causes recurring momentary congestion.
·      A nominal level of packet discard is normal.
·      The absence of differentiation does not imply comparable behavior among applications.
·      Differentiated treatment can produce a net improvement in Quality of Experience (QoE).
·      Access technologies differ in their capabilities and characteristics.
·      Security of traffic has at times been downgraded to facilitate differentiation techniques.
Recommendations. The BITAG Technical Working Group also has the following recommendations (See Executive Summary below or full report for the complete explanation of each):
·      Network operators should disclose information on differential treatment of traffic.
·      Network operators and ASPs should be encouraged to implement efficient and adaptive network resource management practices.
·      Quality of Service metrics should be interpreted in the context of Quality of Experience.
·      Network operators should not downgrade, interfere with, or block user-selected security in order to apply differentiated treatment.
Ken Ko, Senior Staff Scientist at ADTRAN, and Fred Baker, a Fellow at Cisco, served as the lead editors of the report. Douglas Sicker, Executive Director of BITAG, Chair of BITAG’s Technical Working Group, Department Head of Engineering and Public Policy and a professor of Computer Science at Carnegie Mellon University, chaired the review itself.

About BITAG. BITAG is a non-profit, multi-stakeholder organization focused on bringing together engineers and technologists in a Technical Working Group (TWG) to develop consensus on broadband network management practices and other related technical issues that can affect users’ Internet experience, including the impact to and from applications, content and devices that utilize the Internet.
This is BITAG’s eighth report.  BITAG’s previous reports have focused on: Internet interconnection; VoIP impairment, failure, and restrictions; Real-time network management of Internet congestion; Port blocking; SNMP DDoS attack mitigation; Large scale network address translation; and IPv6 whitelisting. Copies of these technical reports can be found on the BITAG website at www.bitag.org.
Questions or Comments? BITAG welcomes any questions, comments or suggestions.  Please contact our Executive Director, Douglas Sicker, at dsicker@bitag.org or our Deputy Director, Kaleb Sieh, at ksieh@bitag.org.



– ATTACHMENT –
Executive Summary of BITAG Report on Differentiated Treatment of Internet Traffic

The Internet is composed of interconnected networks, each having its own architecture and technical characteristics. The data transmitted across these networks is formatted as packets containing information payloads encapsulated within one or more headers, which in turn provide the information needed by networks to deliver the packets to their destinations. As these packets travel across networks, they contend with other packets for network resources. Contention can occur at any point where two or more packets can compete for a resource at the same time. The simplest way to handle such requests would be on a first come, first served basis (also known as First In First Out, or FIFO). In practice, however, network operators make many exceptions to FIFO, using the packet header information to classify packets into flows and treating those flows differently, for example rearranging the order or the timing with which packets are sent, or sending them along different network paths.
Differentiated treatment of Internet Access Service traffic has been a subject of debate and regulatory scrutiny. In February 2015, the Federal Communications Commission (FCC) adopted Open Internet rules that address paid prioritization as well as other topics [1]. This report touches on a broad range of questions associated with differentiation, but is not intended to address or analyze the economic, legal, regulatory, or public policy issues that the differentiated treatment of Internet access service traffic may raise, focusing instead on the technical issues.
The ability to treat traffic differentially has been built into Internet protocols from the beginning. The specifications for both IPv4 and IPv6 have included fields to support traffic differentiation since their inception (initially IPv4’s Type of Service or ToS field) to indicate to routers the quality of service desired, in terms of queuing precedence and routing parameters around delay, rate, and reliability. This was changed to more generic service descriptions with the definition of the Differentiated Services Field, and implemented in IPv4 and IPv6. Notably, traffic differentiation in this sense has not been implemented in multi-provider environments, although it is extensively used within specific networks. End to end deployment would require the harmonization and cooperation of a large number, if not all, of the relevant network operators. 
In its broadest sense, traffic differentiation includes any technique that classifies and applies potentially different treatment to two or more traffic flows contending for resources on a network (a flow being a group of packets that share a common set of properties). Differentiated treatment of network traffic is a two-part process: (1) traffic is classified into traffic streams, and (2) a prescribed set of actions is applied to each stream. This treatment may determine the order in which routers and switches send packets from different flows across the link, the rate of transmission of a given flow, or even whether certain packets are sent at all.
While the techniques used for traffic differentiation overlap with those used to manage congestion, differentiation has a broader purpose that includes meeting service level agreement (SLA) guarantees and selecting paths for traffic from different applications, among other things. Differentiated treatment of traffic can also contribute both to the efficiency of a network and to the predictability of the manner in which network resources are shared.
Differentiation can be complex, and a common vocabulary is key. This report uses the terms “differentiated treatment” or “differentiation,” as opposed to “prioritization” when referring to the full range of treatments that may be applied to traffic flows. The technical definition of “prioritization” is narrow and generally applies only to certain scheduling, dropping, and marking techniques. This report uses “differentiation” in a much broader sense, including most of the ways in which packets may be treated differently from each other while en route to their respective destinations across one or more networks. The scope of differentiation in this report encompasses the classic techniques of scheduling, shaping and queue management by which packets are processed at a network node, and also includes the techniques by which traffic flows are segregated or forwarded onto different physical or logical network paths where they may encounter greater or lesser propagation delays or contention for resources.
This report addresses differentiation applied to traffic on Internet access services, as well as the impacts to Internet access services when differentiation is applied to other traffic carried over the same network. Traffic for mass-market Internet access services is often carried over a common infrastructure with traffic associated with other IP services, as well as the network management traffic used to control devices and report status from them. Since differential treatment of other network traffic has the potential to affect the performance of Internet access services, it is considered here.
The subjective experience perceived by the user of a networked application is known as Quality of Experience, or QoE, and the factors that contribute to QoE vary significantly from one application to the next. In contrast, Quality of Service, or QoS, describes the performance of a network service using objective metrics such as throughput, delay, delay variation, and loss. The relationship between QoS and QoE is highly dependent on the type of application, but variations in QoS have been mapped to corresponding variations in QoE for a number of applications. It is possible to use knowledge about the relationships between network performance parameters and their effects on QoE to attempt to optimize the performance of network flows for their intended applications. Differentiation is often also used to address impairments to QoS.
Broadband networks use different network architectures and access technologies. Several of these network architectures have developed to take advantage of existing access infrastructure that was originally deployed for other services – for example, telephone service over twisted copper pairs or video over coaxial cable. Other networks were developed to meet specific needs, such as for mobility or for access in remote rural areas. In many cases, differences in network design can be traced to the different characteristics of the access technology used. Access technologies can require different approaches to differentiation of traffic.
Observations. From the analysis made in this report and the combined experience of its members when it comes to the differentiated treatment of Internet traffic, the BITAG Technical Working Group makes the following observations:
·       TCP causes recurring momentary congestion
When TCP transfers a large file, such as video content or a large web page, it practically guarantees that it will create recurring momentary congestion at some point in its network path. This effect exists by design, and it cannot necessarily be eliminated by increasing capacity.  Given the same traffic load, however, the severity of the momentary congestion should decrease with increased capacity.
·       A nominal level of packet discard is normal
Packet discard occurs by design in the Internet. Protocols such as TCP use packet discard as a means of detecting congestion, responding by reducing the amount of data outstanding and with it self-induced congestion on the transmission path. Rather than being an impairment, packet discard serves as an important signaling mechanism that keeps congestion in check.
·       The absence of differentiation does not imply comparable behavior among applications
In the absence of differentiation, the underlying protocols used on the Internet do not necessarily give each application comparable bandwidth. For example:
-  TCP tends to share available capacity (although not necessarily equally) between competing connections. However, some applications use many connections at once while other applications only use one connection.
-  Some applications using RTP/UDP or other transport protocols balance transmission rate against experienced loss and latency, reducing the capacity available to competing applications.
·       Differentiated treatment can produce a net improvement in Quality of Experience (QoE)
When differentiated treatment is applied with an awareness of the requirements for different types of traffic, it becomes possible to create a benefit without an offsetting loss. For example, some differentiation techniques improve the performance or quality of experience (QoE) for particular applications or classes of applications without negatively impacting the QoE for other applications or classes of applications. The use and development of these techniques has value.
·       Access technologies differ in their capabilities and characteristics
Specific architectures and access technologies have unique characteristics which are addressed using different techniques for differentiated treatment.
·       Security of traffic has at times been downgraded to facilitate differentiation techniques
Encrypted traffic is on the rise and it has implications for current differentiation techniques. In response to this increase, some satellite and in-flight network operators have deployed differentiation mechanisms that downgrade security properties of some connections to accomplish differentiation. The resulting risks to the security and privacy of end users can be significant, and differentiation via observable information such as ports and traffic heuristics is more compatible with security.
Recommendations. The BITAG Technical Working Group also has the following recommendations:
·       Network operators should disclose information on differential treatment of traffic.
In previous reports, BITAG has recommended transparency with respect to a number of aspects of network management.  BITAG continues to recommend transparency when it comes to the practices used to implement the differential treatment of Internet traffic.
Specifically with respect to consumer-facing services such as mass-market Internet access, network operators should disclose the use of traffic differentiation practices that impact an end user’s Internet access service. The disclosure should be readily accessible to the public (e.g. via a webpage) and describe the practice with its impact to end users and expected benefits in terms meaningful to end users. The disclosure should include any differentiation amongst Internet traffic and should disclose the extent and manner in which other services offered over the same end user access facilities (for example video services) may affect the performance of the Internet access service.
·       Network operators and ASPs should be encouraged to implement efficient and adaptive network resource management practices
In a previous report BITAG recommended that ASPs and CDNs implement efficient and adaptive network resource management practices; we reiterate that recommendation here, extending it to network operators. Examples of such practices might target the minimization of latency and variation in latency induced in network equipment, ensuring sufficient bandwidth for expected traffic loads, and the use of queue management techniques to manage resource contention issues.
·       Quality of Service metrics should be interpreted in the context of Quality of Experience
Common Quality of Service metrics, often included in commercial service level agreements, include capacity, delay, delay variation, and loss rate, among other things. From the viewpoint of the end user application, these metrics trade off against each other and must be considered in the context of Quality of Experience. For example, since TCP Congestion Control and adaptive codecs depend on loss to infer network behavior, actively trying to reduce loss to zero leads to unintended consequences. On the other hand, non-negligible loss rates often directly reduce the user's Quality of Experience. Hence, such metrics should be interpreted in the context of improving user experience.
·       Network operators should not downgrade, interfere with, or block user-selected security in order to apply differentiated treatment.
Network operators should refrain from preventing users from applying over-the-top encryption or other security mechanisms without user knowledge and consent. Networks should not interfere with, modify, or drop security parameters requested by an endpoint to apply differentiated treatment. Given the potential for possible exposure of sensitive, confidential, and proprietary information, prior notice should be given to end users of traffic differentiation features that affect security properties transmitted by endpoints.


Thursday, October 01, 2015

:: NTIA BroadbandUSA: Guide to Federal Funding of Broadband Projects

BroadbandUSA: Guide to Federal Funding of Broadband Projects

September 28, 2015
NTIA’s BroadbandUSA initiative presents this guide to key federal programs that offer funding for broadband-related projects.  NTIA intends this guide to answer questions from communities on how to access federal funding to support broadband planning, public access, digital literacy, adoption, and deployment.

Tuesday, September 01, 2015

:: Senate Hearing “Confronting the Challenge of Cybersecurity" Sept 3

Hearings

Dakota State University to Host U.S. Senate Cybersecurity Field Hearing

Sep 03 2015 3:30 PM

Dakota State University, Madison, S.D. - South Dakota Tunheim Classroom Building, Room 203


WASHINGTON, D.C. – U.S. Senator John Thune (R-S.D.), chairman of the Senate Commerce, Science, and Transportation Committee, will convene and chair a full committee field hearing entitled “Confronting the Challenge of Cybersecurity" on Thursday, September 3, 2015, at 2:30 p.m. CT (3:30 p.m. ET) at Dakota State University. 

Dakota State University's Cyber Operations Program is nationally recognized by the National Security Agency and the Department of Homeland Security as a National Center of Academic Excellence, holding education, research and cyber operations designations. It is one of the first universities in the country to hold all three prestigious designations. Approximately 20 percent of students at DSU are involved in its cybersecurity programs.

Witnesses:

·         Dr. Josh Pauli, Professor of Cyber Security and NSF SFS CyberCorps Program Director, Dakota State University (DSU)
·         Dr. Kevin Streff, Department Chair, Cyber Operations and Security, Dakota State University; Founder and Managing Partner, Secure Banking Solutions, LLC 
·         Mr. Mark Shlanta, CEO, SDN Communications
·         Mr. Eric Pulse, Director of Risk Advisory Services, Eide Bailly 
·         Mr. Jeremy Epstein, Lead Program Director, Secure and Trustworthy Cyberspace (SaTC) program, National Science Foundation (NSF)
·         Mr. Kevin Stine, Manager, Security Outreach and Integration Group, Information Technology Laboratory, National Institute of Standards and Technology (NIST)

Hearing Details: 

Thursday, September 3, 2015

2:30 p.m. CT/3:30 p.m. ET

Full Committee field hearing at Dakota State University
Madison, South Dakota
Tunheim Classroom Building, Room 203

The hearing will be webcast through www.commerce.senate.gov. Witness testimony, opening statements, and a live video of the hearing will be available on this page.

:: FTC Announces PrivacyCon :: RFP

PrivacyCon

PrivacyCon, Federal Trade Commission, DC, January 14, 2016
CONSTITUTION CENTER400 7th St SW, Washington, DC 20024 | Directions & Nearby

EVENT DESCRIPTION

"The Federal Trade Commission will hold a conference on January 14, 2016 to bring together a diverse group of stakeholders, including whitehat researchers, academics, industry representatives, consumer advocates, academics, and a range of government regulators, to discuss the latest research and trends related to consumer privacy and data security. The FTC is calling for research to be presented at the conference. 
"Due to the unique role that whitehat researchers, academics, and information security specialists have played in raising awareness about privacy and data security issues, the FTC is particularly interested in enlisting their participation in this effort. For the past several years, their work to strengthen privacy and security protections in this country has greatly benefitted the FTC and the public. For example, the FTC’s reports on the privacy implications of facial recognition technology and the Internet of Things have referred to important academic research. And the FTC has opened numerous law enforcement investigations in response to security vulnerabilities that whitehat researchers have brought to our attention. 
"PrivacyCon seeks to continue and expand collaboration among whitehat researchers, academics, industry representatives, consumer advocates, and regulators to address the privacy and security implications of emerging technologies. PrivacyCon will include brief privacy and security research presentations, along with expert panel discussions on the latest privacy and security challenges facing consumers. Whitehat researchers and academics will discuss the latest security vulnerabilities, explain how they can be exploited to harm consumers, and highlight research affecting consumer privacy and data security. During panel discussions, participants will discuss the research presentations and the latest policy initiatives to address consumer privacy and security, develop suggestions for further collaboration between researchers and policymakers, and highlight steps that companies and consumers can and should take to protect themselves and their data. 
"Call for Presentations: The FTC is seeking presentations on consumer privacy and security issues in the commercial sector. In particular, we are interested in hearing about research on topics such as:
  • Connected health and fitness devices or applications
  • Devices or services that incorporate voice-activation technology
  • Smarthomes
  • De-identification
  • Connected vehicles
  • Drones
  • Edu-tech
  • Big data and algorithms
  • Consumers’ attitudes toward, and valuation of, privacy
  • Costs and benefits of privacy-protective technology or behavior
  • Economics of privacy and security
  • Security by design techniques
We will provide more detail on the submission process by September 10th.
Please note that the FTC does not offer compensation of any kind to presenters or participants. Because we only have a very limited number of presentation slots, if there is enough interest, we may have an exhibit hall, where selected submitters can display posters and other information about their research. 
This event, including all presentations, will be available to the public via a live-stream and on our website in archived video and transcript form. 
Email questions to privacycon@ftc.gov(link sends e-mail).   

:: NTIA Multistakeholder Process: Cybersecurity Vulnerabilities

Date: August 28, 2015
"This web page provides details on the NTIA-convened multistakeholder process concerning collaboration between security researchers and software and system developers and owners to address security vulnerability disclosure.
"The first meeting will be on September 29, 2015 at the University of California, Berkeley, School of Law.  This meeting will be open to all interested parties. The meeting will be webcast, and NTIA will provide a dial-in conference bridge.  Pleasepre-register here to help NTIA plan logistics. Pre-registration is not required, but will assist NTIA in planning, and in determining space and webcast technology requirements.
Background:
"On March 19, 2015, the National Telecommunications and Information Administration, working with the Department of Commerce’s Internet Policy Task Force (IPTF), issued a Request for Comment to “identify substantive cybersecurity issues that affect the digital ecosystem and digital economic growth where broad consensus, coordinated action, and the development of best practices could substantially improve security for organizations and consumers.” Individuals and entities from across the commercial, academic, and civil society sectors filed comments. After reviewing these comments, NTIA announced that the first topic to be addressed would be collaboration on vulnerability research disclosure.
"The goal of this process will be to develop a broad, shared understanding of the overlapping interests between security researchers and the vendors and owners of products discovered to be vulnerable, and to establish a consensus about voluntary principles to promote better collaboration.  The question of how vulnerabilities can and should be disclosed will be a critical part of the discussion, as will how vendors receive and respond to this information. However, disclosure is only one aspect of successful collaboration.
Upcoming meetings:
September 29, 2015
Booth Auditorium at the University of California, Berkeley, School of Law, Boalt Hall, Bancroft Way and Piedmont Avenue, Berkeley, CA.
9am-3pm PDT
Dial-in information: to be announced.

:: NIST Cyber Supply Chain Risk Management Workshop, October 1-2, 2015

NIST Invites Industry to Cyber Supply Chain Risk Management Workshop, October 1-2, 2015

From NIST Tech Beat: September 1, 2015Contact: Evelyn Brown 
301-975-5661
"The National Institute of Standards and Technology (NIST) will host a workshop on industry best practices in cyber supply chain risk management at its Gaithersburg, Md., campus, October 1-2, 2015.
continents connected by chains
Credit: ©freshidea-Fotolia_com
View hi-resolution image
"The two-day event will feature panels of industry professionals. Topics will include how cyber supply chain risk can affect organizations, proven strategies for managing those risks, existing standards and best practices, and practical guidance for enterprise risk governance.
"The Cyber Supply Chain Risk Management workshop is designed for a broad audience, including senior executives and those involved in enterprise risk management, supply chain management, acquisition or cybersecurity.
The goals of the workshop are to:
• share current research findings,
• validate the current findings and receive additional input from stakeholders, and
• gather input to inform future versions of the Framework for Improving Critical Infrastructure Cybersecurity and other cybersecurity and supply chain risk management initiatives.
NIST developed the framework, commonly referred to as the Cybersecurity Framework, as directed in Executive Order 13636 to assist critical infrastructure organizations to better manage and reduce their cybersecurity risks. NIST also released a companion document, Roadmap for Improving Critical Infrastructure Cybersecurity, which identifies supply chain risk management as a key focus area.
NIST has a Supply Chain Risk Management Program focused on securing the information and communications technology supply chain.
Registration information and the agenda are available here.

Saturday, August 22, 2015

:: NIST Hosts 2015 Cybersecurity Innovation Forum, Sept. 9-11 in D.C.

NIST Hosts 2015 Cybersecurity Innovation Forum, Sept. 9-11 in D.C.

From NIST Tech Beat: August 17, 2015


Contact: Evelyn Brown 
301-975-5661
"The National Institute of Standards and Technology (NIST) will host the 2015 Cybersecurity Innovation Forum on Sept. 9 to 11, 2015, at the Walter E. Washington Convention Center in Washington, D.C.
hacker
Credit: © ra2 studio/Fotolia.com
"At this annual meeting, government, industry and university representatives come together to focus on current, emerging and future challenges in areas such as trusted computing, security automation and information sharing. Leading cybersecurity researchers and executives from the cybersecurity industry will participate in the event.
"The forum’s four tracks—security automation, trusted computing, information sharing and cybersecurity research—will be interspersed with general sessions. Session topics include federal research and privacy, risk management and liability. The event will conclude with a review of the challenges and gaps discussed during the forum and next steps in collaborative efforts to resolve them.
"Presentations will cover Windows 10 security, cryptography, derived PIV credentials proof of concept, public safety cybersecurity, security and the Internet of Things, the NIST Privacy Risk Management Framework and augmenting Federal Information Security Management Act (FISMA) practices with the Cybersecurity Framework.
"The forum also will feature demonstrations and an industry expo on Sept. 9 and 10.
"The agenda is available online. Register for the 2015 Cybersecurity Innovation Forum at: https://www.fbcinc.com/e/cif/attendeereg.aspx.

:: NTIA / IANA Contract One Year Extension

August 17, 2015 by Assistant Secretary for Communications and Information and NTIA Administrator Lawrence E. Strickling
Assistant Secretary for Communications and Information and NTIA Administrator Lawrence E. Strickling
"The Internet’s global multistakeholder community has made tremendous progress in its work to develop a proposal to transition the historic stewardship role NTIA has played related to Internet’s domain name system (DNS).
"When we announced our intent in March 2014 to complete the privatization of the DNS, we noted that the base period of our contract with ICANN to perform technical functions related to the DNS, known as the IANA functions, expired on September 30, 2015. However, it has become increasingly apparent over the last few months that the community needs time to complete its work, have the plan reviewed by the U.S. Government and then implement it if it is approved.
"Accordingly, in May we asked the groups developing the transition documents how long it would take to finish and implement their proposals.  After factoring in time for public comment, U.S. Government evaluation and implementation of the proposals, the community estimated it could take until at least September 2016 to complete this process. In response to their feedback, we informed Congress on Friday that we plan to extend our IANA contract with ICANN for one year to September 30, 2016. Beyond 2016, we have options to extend the contract for up to three additional years if needed.
"This one-year extension will provide the community with the time it needs to finish its work. The groups are already far along in planning the IANA transition and are currently taking comments on their IANA transition proposals. As we indicated in a recent Federal Register notice, we encourage all interested stakeholders to engage and weigh in on the proposals.
"In preparation for the implementation phase of the IANA stewardship transition, NTIA also asked Verisign and ICANN to submit a proposal detailing how best to remove NTIA’s administrative role associated with root zone management, which the groups working on the transition were not asked to address. We asked Verisign and ICANN to submit a proposal detailing how best to do this in a manner that maintains the security, stability and resiliency of the DNS. Under the current root zone management system, Verisign edits and distributes the root zone file after it has received authorization to do so from NTIA. Verisign and ICANN have developed a proposal that outlines a technical plan and testing regime for phasing out the largely clerical role NTIA currently plays in this process. The testing will occur in a parallel environment that will not disrupt the current operation of the root zone management system.
"These developments will help ensure that the IANA transition will be done in a manner that preserves the security and stability of the DNS.

:: FTC Start with Security Conference San Francisco

FTC Start with Security Conference San Francisco

UNIVERSITY OF CALIFORNIA HASTINGS COLLEGE OF THE LAWAlumni Reception Center, 200 McAllister St., San Francisco, CA 94102 | Directions & Nearby

EVENT DESCRIPTION

"The FTC's first “Start With Security” conference is scheduled for September 9, 2015, in San Francisco, and is co-sponsored by the University of California Hastings College of the Law. It is part of a business education initiative designed to provide companies with practical resources to help them implement effective data security strategies.
"Aimed at start-ups and developers, this event will bring together experts to provide information on security by design, common security vulnerabilities, strategies for secure development, and vulnerability response. "Start with Security" will run from 10:00 AM to 4:00 PM. The event is free and open to the public. No pre-registration is necessary. Lunch is provided. This event will be webcast. Check this page on the day of the event for details.
"The conference series is part of the agency’s longstanding efforts to provide businesses with guidance about how to put effective security in place.

♪ Whether Smart City engaged in prohibited Wi-Fi blocking

In re Smart City Holdings, Dkt. EB-SED-15-00018248, Order (Aug. 18, 2015)

"The Enforcement Bureau (Bureau) of the Federal Communications Commission has entered into a Consent Decree to resolve its investigation into whether Smart City Holdings, LLC, and its wholly-owned subsidiaries, Smart City Networks, LP, and Smart City Solutions LLC (collectively, Smart City) engaged in prohibited Wi-Fi blocking by interfering with and disabling Wi-Fi networks established by consumers at several conference facilities where Smart City operates or manages the facility’s Wi-Fi network. To settle this matter, Smart City (i) admits that it prevented certain Wi-Fi users at these locations from establishing or maintaining a Wi-Fi network independent of Smart City’s network, (ii) will implement a compliance plan under which it commits to not engage in Wi-Fi blocking, and (iii) agrees to pay a $750,000 civil penalty."

"On June 24, 2014, the Commission received an informal complaint from a company that provides equipment that enabled users to establish hotspots, marketing its use as an alternative to paying forWi-Fi service that may otherwise be available to consumers at a venue. The complaint charged that its customers could not connect to the Internet using the complainant’s equipment at several venues where Smart City operates or manages the Wi-Fi access.2 In response to the Bureau’s investigation, Smart City provided information revealing that it automatically blocked certain Wi-Fi users at several venues where it managed or operated the Wi-Fi access to prevent such these users from establishing or maintaining a Wi-Fi network independent of Smart City’s network. No evidence exists that the Wi-Fi blocking occurred in response to a specifically identified threat to the security of the Smart City network or the network’s users."

"After reviewing the terms of the Consent Decree and evaluating the facts before us, we find that the public interest would be served by adopting the Consent Decree and terminating the referenced investigation regarding Smart City’s compliance with Section 333 of the Communications Act of 1934, as amended (Act)."

SMART CITY HOLDINGS, LLC, AND ITS WHOLLY-OWNED SUBSIDIARIES, SMART CITY NETWORKS, LP, AND SMART CITY SOLUTIONS LLC. Adopted a Consent Decree and terminated the investigation. Action by: Chief, Enforcement Bureau. Adopted: 08/17/2015 by Order/Consent Decree. (DA No. 15-917). EB   DA-15-917A1.docx  DA-15-917A1.pdf  

IGF-USA 2015 - Keynote Conversation with Vint Cerf and Steve Crocker (Video)