<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>TorrentFreak &#187; CNIL</title>
	<atom:link href="http://torrentfreak.com/tag/cnil/feed/" rel="self" type="application/rss+xml" />
	<link>http://torrentfreak.com</link>
	<description>Breaking File-sharing, Copyright and Privacy News</description>
	<lastBuildDate>Wed, 29 Oct 2014 13:30:09 +0000</lastBuildDate>
	<language>en-US</language>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.9.2</generator>
	<item>
		<title>Government Concludes Investigation Following  Anti-Piracy Data Breach</title>
		<link>http://torrentfreak.com/government-concludes-investigation-following-anti-piracy-data-breach-111024/</link>
		<comments>http://torrentfreak.com/government-concludes-investigation-following-anti-piracy-data-breach-111024/#comments</comments>
		<pubDate>Mon, 24 Oct 2011 19:16:39 +0000</pubDate>
		<dc:creator><![CDATA[enigmax]]></dc:creator>
				<category><![CDATA[All]]></category>
		<category><![CDATA[CNIL]]></category>
		<category><![CDATA[hadopi]]></category>
		<category><![CDATA[TMG]]></category>

		<guid isPermaLink="false">http://torrentfreak.com/?p=41678</guid>
		<description><![CDATA[The French authority responsible for ensuring that data privacy law is applied to the handling of personal data has concluded its investigation into anti-piracy company Trident Media Guard. Earlier this year vulnerabilities caused TMG's site to leak private data linked to the country's Hadopi "3 strikes" operations. But while the anti-piracy outfit has now been given a clean bill of health, the spotlight has now fallen on rightsholders.<p>Source: <a href="http://torrentfreak.com">TorrentFreak</a>, for the latest info on <a href="http://torrentfreak.com/category/copyright-issues/">copyright</a>, <a href="http://torrentfreak.com/category/pirate-talk/">file-sharing</a> and <a href="http://torrentfreak.com/which-vpn-services-take-your-anonymity-seriously-2014-edition-140315/">anonymous VPN services</a>.</p>
]]></description>
				<content:encoded><![CDATA[<p><img alt="" src="http://torrentfreak.com/images/tmg.jpg" class="alignright" width="198" height="90">In May 2011, French security researcher Olivier Laurelli, who is better known by his alias Bluetouff, told TorrentFreak that he had <a href="http://torrentfreak.com/french-hadopi-3-strikes-anti-piracy-company-hacked-110514/">discovered vulnerabilities</a> in the website of  anti-piracy company Trident Media Guard.</p>
<p>TMG have the contract to carry out the monitoring of file-sharers as part of the French government&#8217;s enforcement of its &#8216;Hadopi&#8217; 3-strikes regime. Given the politically sensitive nature of the work, the subsequent leak of information and software tools from TMG was all the more embarrassing.</p>
<p>In order to maintain confidence in the system, Commission Nationale de l’informatique et des Libertés (CNIL), the French authority responsible for ensuring that data privacy law is applied to the collection, handling, and use of personal data, were sent in to investigate the breach.</p>
<p>While CNIL investigated, TMG was forced to sever its online connections with the Hadopi agency. Instead, information on infringements was sent through the postal system on DVD. </p>
<p>According to <a href="http://www.numerama.com/magazine/20297-hadopi-tmg-peut-reprendre-une-activite-normale.html">Numerama</a>, CNIL had given TMG until September 16th to get their systems in order. That deadline having passed, today CNIL made an announcement.</p>
<p>&#8220;On July 29th and September 13th 2011, TMG detailed the procedures implemented to improve the security of its information system,&#8221; said CNIL in a statement.</p>
<p>CNIL noted that since the changes carried out by TMG were &#8220;satisfactory&#8221; and met legal requirements, their investigation into the anti-piracy company is now over. TMG and Hadopi will now link back up online in order to transfer infringement data between them.</p>
<p>Despite TMG&#8217;s obvious shortcomings, at this stage they appear to have avoided public admonishment. However, rightsholders may now have to share some of the responsibility for the embarrassment and failures at TMG.</p>
<p>&#8220;In France, before rights holders can collect IP addresses of infringing users, they have to ask and obtain an approval from the CNIL,&#8221; Numerama&#8217;s Guillaume Champeau  told TorrentFreak.</p>
<p>Guillaume says that in order to obtain this approval, the four rights holder organizations &#8211; SCPP, SPPF, ALPA, SACEM/SDRM &#8211; submitted an application in which they described the security measures TMG was forced to abide by.</p>
<p>&#8220;But it appears TMG did not abide by all of these requirements, and even the rights holders organizations did not. For instance, they said they would audit TMG every quarter, which they didn&#8217;t,&#8221; he adds.</p>
<p>&#8220;As these rights organizations are the ones who where directly in touch with the CNIL, as they are legally speaking &#8216;in charge of the collection&#8217; of the IP addresses, they are the ones who may be found in violation of their pre-approval promises.&#8221;</p>
<p>Source: <a href="http://torrentfreak.com">TorrentFreak</a>, for the latest info on <a href="http://torrentfreak.com/category/copyright-issues/">copyright</a>, <a href="http://torrentfreak.com/category/pirate-talk/">file-sharing</a> and <a href="http://torrentfreak.com/which-vpn-services-take-your-anonymity-seriously-2014-edition-140315/">anonymous VPN services</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://torrentfreak.com/government-concludes-investigation-following-anti-piracy-data-breach-111024/feed/</wfw:commentRss>
		<slash:comments>21</slash:comments>
		</item>
		<item>
		<title>Anti-Piracy Outfit Will Not Sue Hadopi &#8216;Hacker&#8217;</title>
		<link>http://torrentfreak.com/anti-piracy-outfit-will-not-sue-hadopi-hacker-110521/</link>
		<comments>http://torrentfreak.com/anti-piracy-outfit-will-not-sue-hadopi-hacker-110521/#comments</comments>
		<pubDate>Sat, 21 May 2011 10:43:10 +0000</pubDate>
		<dc:creator><![CDATA[enigmax]]></dc:creator>
				<category><![CDATA[Hot Off The Press]]></category>
		<category><![CDATA[Bluetouff]]></category>
		<category><![CDATA[CNIL]]></category>
		<category><![CDATA[TMG]]></category>

		<guid isPermaLink="false">http://torrentfreak.com/?p=35413</guid>
		<description><![CDATA[Exactly a week ago, French anti-piracy company Trident Media Guard experienced a security breach after they failed to properly secure their servers. As reports begin to surface that TMG intend to sue the alleged 'hacker', the target of their intentions informs TorrentFreak that having backed themselves into a corner, the company will not take legal action against him.<p>Source: <a href="http://torrentfreak.com">TorrentFreak</a>, for the latest info on <a href="http://torrentfreak.com/category/copyright-issues/">copyright</a>, <a href="http://torrentfreak.com/category/pirate-talk/">file-sharing</a> and <a href="http://torrentfreak.com/which-vpn-services-take-your-anonymity-seriously-2014-edition-140315/">anonymous VPN services</a>.</p>
]]></description>
				<content:encoded><![CDATA[<p><img src="http://torrentfreak.com/images/tmg.jpg" align="right" alt="TMG">Last Saturday, we <a href="http://torrentfreak.com/french-hadopi-3-strikes-anti-piracy-company-hacked-110514/">began reporting</a> on a security breach at French anti-piracy company Trident Media Guard (TMG). The company had been entrusted by the French government to carry out monitoring of file-sharing networks in pursuit of their nationwide anti-piracy program.</p>
<p>Blogger and security researcher Olivier Laurelli, aka Bluetouff, told us that a TMG virtual machine had been leaking data, including security tools and, according to a later <a href="http://torrentfreak.com/french-3-strikes-suspended-due-to-anti-piracy-security-alert-110517/">report</a> by news resource Numerama, IP-addresses of French citizens.</p>
<p>Naturally the revelations generated controversy, with the Hadopi agency announcing that they had suspended electronic connections with TMG and had resorted to shifting file-sharing monitoring data around on DVD instead.</p>
<p>As the pressure mounted on TMG, in the middle of the week they called in Commission Nationale de l&#8217;informatique et des Libertés (CNIL) to investigate the security issue. CNIL is the French authority responsible for ensuring that data privacy law is applied to the collection, handling, and use of personal data, </p>
<p>Then yesterday, Telecom Paper <a href="http://www.telecompaper.com/news/tmg-sues-hacker-of-p2p-pirates-ip-addresses">reported</a> that TMG would sue the person responsible for finding the security flaw, but adding that it would be unusual for the French courts to prosecute people who expose lax security as doing so is deemed to be in the public interest.</p>
<p>TMG&#8217;s position, however, is slightly more awkward than that.</p>
<p>After first trying to play the situation up, using language such as &#8220;we have been the victim of data theft&#8221;, TMG followed up with claims that the exposed information was in fact nothing to do with their main systems. Furthermore, the server from which it came allegedly carried no live end-user data and was in fact a mere test machine. According to a source quoted by <a href="http://www.pcinpact.com">PCInpact</a>, this is why TMG left it unprotected.</p>
<p>So on what basis would TMG sue Bluetouff? TorrentFreak asked him.</p>
<p>&#8220;TMG first said to the press it was an unprotected test server with no confidential data, and that there was no hack. So I&#8217;m really wondering on what basis they could attack,&#8221; he explained.</p>
<p>&#8220;I guess they need to sue someone because of insurance stuff or just to avoid admitting their own fail. So just wait and see but I&#8217;m quite sure they won&#8217;t sue.&#8221;</p>
<p>Bluetouff then reminded us of the <a href="http://torrentfreak.com/isp-attempts-to-block-file-sharing-ends-results-in-epic-failure-100614/">security flaw</a> he discovered in software developed by ISP Orange, which inadvertently leaked users&#8217; IP addresses as it tried to block file-sharing.</p>
<p>&#8220;Orange had the same reaction, to send me lawyers first over their splendid &#8216;hadopiware&#8217;. Then they tried to understand what happened and who is guilty of what afterwards,&#8221; he explained.</p>
<p>Then within minutes we had another message from Bluetouff. &#8220;Wow, that was fast,&#8221; he said.</p>
<p>As predicted, TMG had announced that they won&#8217;t sue after all, unless they find evidence of &#8220;a formal intrusion&#8221;, something which presumably won&#8217;t be possible on a server they left deliberately open.</p>
<p>Time will tell what conclusions the CNIL data inspectors will draw from the episode. Their report is forthcoming.</p>
<p>Source: <a href="http://torrentfreak.com">TorrentFreak</a>, for the latest info on <a href="http://torrentfreak.com/category/copyright-issues/">copyright</a>, <a href="http://torrentfreak.com/category/pirate-talk/">file-sharing</a> and <a href="http://torrentfreak.com/which-vpn-services-take-your-anonymity-seriously-2014-edition-140315/">anonymous VPN services</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://torrentfreak.com/anti-piracy-outfit-will-not-sue-hadopi-hacker-110521/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
	</channel>
</rss>
