Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
2 Million Fake Net Neutrality Comments Stole American Identities
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
Joe Stanganelli,
User Rank: Ninja
12/18/2017 | 7:09:16 PM
Addresses of commenters
WTH?

I'm really concerned how much of these comments are a matter of public record. People's names and addresses are often enough to commit identity theft.

Of course, the same goes for most voting records.

It's a shame, really.
REISEN1955
REISEN1955,
User Rank: Ninja
12/15/2017 | 3:41:25 PM
Re: Ratio of "pro" to "con" fake posts could suggest unseen economic or political motives
As a past resident of NY State, I have many reasons to hate ALBANY and all that goes on there.  BUT ONE WORD OF GREAT ADVICE ----- IF you have or had relatives in the state, checked UNCLAIMED FUNDS ---- We came away with a substantial chunk of unknown change in the XX,XXX.xx number range. 
gruntsters
gruntsters,
User Rank: Strategist
12/15/2017 | 11:35:21 AM
Re: Ratio of "pro" to "con" fake posts could suggest unseen economic or political motives
I agree. Which way did the 2 million accounts lean? Why hasn't the NY AG listed this information?
SchemaCzar
SchemaCzar,
User Rank: Strategist
12/15/2017 | 9:17:28 AM
Ratio of "pro" to "con" fake posts could suggest unseen economic or political motives
Schneiderman's office did a valuable service.  Now this is definitely one of the more useless ways of gauging public opinion - no real authenticated identity to canvass citizens?  

However, the question I have is what is the ratio pro/con of fake comments?  If we see one side or the other exerting money and effort to swing the decision, it may lead us to hidden consequences of rescinding or preserving net neutrality that would give us further information in this important debate.

It's sort of disappointing that Schneiderman did not reveal this ratio.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Machine Learning, AI & Deep Learning Improve Cybersecurity
Machine intelligence is influencing all aspects of cybersecurity. Organizations are implementing AI-based security to analyze event data using ML models that identify attack patterns and increase automation. Before security teams can take advantage of AI and ML tools, they need to know what is possible. This report covers: -How to assess the vendor's AI/ML claims -Defining success criteria for AI/ML implementations -Challenges when implementing AI
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-39252
PUBLISHED: 2022-09-29
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to version 0.6, when a user requests a room key from their devices, the software correctly remembers the request. When the user receives a forwarded room key,...
CVE-2022-39254
PUBLISHED: 2022-09-29
matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from their devices, the software correctly remember the request. Once they receive a forwarded room key, they accept it without checking who the room key c...
CVE-2022-38732
PUBLISHED: 2022-09-29
SnapCenter versions prior to 4.7 shipped without Content Security Policy (CSP) implemented which could allow certain types of attacks that otherwise would be prevented.
CVE-2022-40407
PUBLISHED: 2022-09-29
A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file.
CVE-2022-40408
PUBLISHED: 2022-09-29
FeehiCMS v2.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into the Comment box under the Single Page module.