Hadopi: A security flaw disrupts the graduated response
Assists Is there a pause of flexible response? The Hadopi decided to "suspend its Interconnection with Trident Media Guard (TMG), the company Nantes mandated by the rights holders to monitor P2P networks for the exchange to" flash "French Internet users currently downloading works monitored.
The decision comes after the computer security specialist Olivier Laurelli, better known on the Internet under the pseudonym bluetouff, revealed this weekend, several security holes on one of TMG servers. In the files have been found many IP addresses of French Internet users, "ID" of Internet-connected computers. However, these data should be secured.
"Precautionary Principle"
"We apply the precautionary principle," says the Hadopi Figaro.fr. "We do not know what is actually happening in servers TMG.But we do not want to risk an intrusion into our system and personal data it contains. "
Presently, TMG sends daily Hadopi records IP addresses of surfers caught in his nets. The High Authority then decides whether to send a warning email to the owner of the Internet line in question and is the first step in the graduated response. With Monday's decision by the highest authority, the transfer of information between TMG and Hadopi is now suspended indefinitely.
Customers can they download with impunity the time of the suspension? The Hadopi like to moderate the joy of some users. "TMG can retain data for some time.If we restore the interconnection sooner, then all records of addresses made since Monday will be considered by us. "
TMG minimizes the impact of the fault
According to a report of the CNIL, "the data collected [by TMG] are cleared during the night following the confirmation of receipt of referrals by Internet Piracy, usually 24 hours after the collection of this information." If data are not passed, it will "also destroyed 24 hours after collection.Therefore, if Hadopi decides to reestablish its connection with TMG Wednesday surfers flashed in the day on Monday not risk anything, since the data has been erased by TMG Tuesday at midnight.
TMG has defended his part in a press release stating that the flaw disclosed by bluetouff "comes from a test server of society" and that "the infrastructure used by GMT as part of its operations were not impacted. "Therefore," no confidential data and personal has been published on the Internet. "
The rights holders should expedite an expert report from TMG very quickly, according to Internet Piracy. "Everything must be put in clear," says one at the headquarters of the supreme authority.