Wednesday, July 31, 2013

Portraying People with Disabilities in the Media - Easter Seals

Portraying People with Disabilities in the Media - Easter Seals
http://www.easterseals.com/site/PageServer?pagename=ntl_disability_media


Portraying People with Disabilities in the Media

Fear of the unknown. Inadequate experience. Incorrect or distorted information. Lack of knowledge. These shape some of the attitudinal barriers that people with disabilities face as they become involved in their communities.

People working in the media exert a powerful influence over the way people with disabilities are perceived.  It's important to the 54 million Americans with disabilities that they be portrayed realistically and that their disabilities are explained accurately.

Awareness is the first step toward change.

Interviewing People with Disabilities

Tips for Reporting on People with Disabilities

  • When referring to individuals with disabilities use "disability," not "handicapped." 
  • Emphasize the person, not the disability or condition. Use "people with disabilities" rather than "disabled persons," and "people with epilepsy" rather than "epileptics."
  • Omit mention of an individual's disability unless it is pertinent to the story.
  • Depict the typical achiever with a disability, not just the superachiever.
  • Choose words that are accurate descriptions and have non-judgemental connotations.
  • People with disabilities live everyday lives and should be portrayed as contributing members of the community. These portrayals should:

         - Depict people with disabilities experiencing the same pain/pleasure that others derive
         from everyday life, e.g., work, parenting, education, sports and community involvement.

         - Feature a variety of people with disabilities when possible, not just someone easily
         recognized by the general  public.

         - Depict employees/employers with disabilities working together.

  • Ask people with disabilities to provide correct information and assistance to avoid stereotypes in the media.

  • Portray people with disabilities as people, with both strengths and weaknesses.

Appropriate Words when Portraying People with Disabilities 

Never Use…

VICTIM – use: person who has/experienced/with.              
[THE] CRIPPLE[D] – use: person with a disability.
AFFLICTED BY/WITH – use: person has.
INVALID – use: a person with a disability.
NORMAL – most people, including people with disabilities, think they are. 
PATIENT – connotes sickness. Use person with a disability.

Avoid Using…

WHEELCHAIR BOUND/CONFINED – use: uses a wheelchair or wheelchair user.  
HOMEBOUND EMPLOYMENT – use: employed in the home.

Use with Care…

COURAGEOUS, BRAVE, INSPIRATIONAL and similar words routinely used to describe persons with disabilities. Adapting to a disability does not necessarily mean someone acquires these traits.


(via Instapaper)

Deeplinks | Electronic Frontier Foundation

Deeplinks | Electronic Frontier Foundation
https://www.eff.org/deeplinks


Defending your rights in the digital world

February 25, 2013 - 4:44pm | By Mark M. Jaycox and Kurt Opsahl

The privacy-invasive bill known as CISPA—the so-called "cybersecurity" bill—was reintroduced in February 2013. Just like last year, the bill has stirred a tremendous amount of grassroots activism because it carves a loophole in all known privacy laws and grants legal immunity for companies to share your private information. EFF has compiled an FAQ detailing how the bill's major provisions work and how they endanger all Internet users' privacy. Please join us in speaking out against CISPA by contacting Congress now.

February 25, 2013 - 4:24pm | By Daniel Nazer

EFF is pleased to see the Indiegogo campaign page of Internet startup CentUp has returned after the page was briefly taken down in response to a complaint by a patent troll. We hope this takedown is not the start of a trend of patent trolls sabotaging startups by complaining to online intermediaries. And we applaud Indiegogo, a crowdfunding platform crucial for financing many startups and projects, for doing the right thing and restoring the campaign.

February 25, 2013 - 11:15am | By Corynne McSherry

It's been a long time coming, but the copyright surveillance machine known as the Copyright Alert System (CAS) is finally launching.  CAS is an agreement between Big Content and large Internet Service Providers to monitor peer to peer networks for copyright infringement and target subscribers who are alleged to infringe—via everything from from "educational" alerts to throttling Internet speeds.

As part of the launch, the Center for Copyright Information, which administers the program, has revamped its website.  The website is supposed to help educate subscribers about the system and copyright.  Unfortunately, it's chock full of warning signs that this whole campaign is not going to go well.

For example, on the process for targeting subscribers, the site explains that:

February 22, 2013 - 2:08pm | By Adi Kamdar

Today, the White House released a memorandum (PDF) in support of a more robust policy for public access to research, making the results of billions of dollars of taxpayer-funded research freely available online. The memorandum gives government agencies six months to detail plans to ensure the public can read and analyze both research and data, without charge. Both open access and open data are key to promoting innovation, government transparency, and scientific progress.

As put by Dr. John Holdren, Director of the White House Office of Science and Technology Policy:

February 21, 2013 - 3:51pm | By Jennifer Lynch

The Los Angeles Times reported last week that the FAA has issued 1,428 permits to domestic drone operators since 2007 and noted this was "far more than were previously known."

This new number points out again how difficult it is to answer the most common questions EFF gets from reporters about drones — just how many agencies have applied for drone licenses? How many licenses has the FAA issued since it started issuing licenses (which was earlier than 2007)? And how much has domestic drone use increased over the years?

February 19, 2013 - 3:00pm | By Adi Kamdar

The domain name registrar Namecheap is running an awareness campaign against CISPA, the dangerous cybersecurity bill—and they're donating $1 to EFF for each tweet (#CISPAalert), Facebook share, and domain name bought using the code CISPAalert. Namecheap, a staunch opponent of SOPA last year, is now taking charge of spreading the word about CISPA's threats to your privacy.

February 15, 2013 - 3:30pm | By Parker Higgins

Yesterday the Alameda County Sheriff's Office presented a proposal for the purchase of a drone in a public hearing with the Board of Supervisors Public Protection Committee in Oakland, California. EFF joined the ACLU of Northern California and several other public interest groups in testifying against a drone purchase until the Sheriff's Office adopts a substantive, binding privacy policy—with no loopholes—that protects citizens from undue surveillance.

Pages

Subscribe to EFF Updates

Defending your rights in the digital world

February 15, 2013 - 3:11pm | By Adi Kamdar and Corynne McSherry

Internet users around the world got a Valentine's Day present yesterday in the form of new legislation that requires U.S. government agencies to improve public access to federally funded research.

The proposed mandate, called the Fair Access to Science & Technology Research Act, or FASTR (PDF), is simple. Agencies like the National Science Foundation, which invests millions of taxpayer dollars in scientific research every year, must design and implement a plan to facilitate public access to—and robust reuse of—the results of that investment. The contours of the plans are equally simple: researchers who receive funding from most federal agencies must submit a copy of any resulting journal articles to the funding agency, which will then make that research freely available to the world within six months.

February 15, 2013 - 11:46am | By Rebecca Jeschke

EFF is extraordinarily pleased to officially announce a new addition to our Board of Directors: entrepreneur and technologist Brian Behlendorf.  

We have long been a fan of Brian and his tireless work in the open source community – ranging from software development in the early days of the Web to open source advocacy at the highest levels of government.  

As the Web was in the midst of its first big growth spurt, Brian co-founded the Apache Group (later the Apache Software Foundation), helping to build and give away the popular Apache HTTP Server.  He also launched CollabNet, which brought the principles and tools used by the open source software community to large enterprises.

February 15, 2013 - 10:10am | By Parker Higgins

In a welcome turn of events, President Barack Obama spoke directly to the patent troll problem and the need for more comprehensive patent reform yesterday in a "Fireside Hangout" — a live question and answer session hosted in a Google+ hangout. The President was responding to a question by the prominent electrical engineer and entrepreneur Limor "Ladyada" Fried, who in 2009 won an EFF Pioneer Award for her work with free software and open-source hardware.

February 14, 2013 - 2:22pm | By Adi Kamdar

In a recent blog post, Jill Lesser, Executive Director of the Center for Copyright Information, responded to widespread concerns that the copyright surveillance machine known as the Copyright Alert System—or "Six Strikes"—would cripple libraries and cafes that provided open wireless networks. The title of said post: "CAS Will Not Harm Public Wi-Fi."

We disagree. 

February 14, 2013 - 10:45am | By Julie Samuels

There is much wrong with software patents. But one of their worst side effects has to be the advent of the patent troll: one who makes nothing, sells nothing, and capitalizes on legal loopholes to extort money in the guise of "licenses," oftentimes from parties who don't even arguably infringe the patent at issue. Lately, patent trolls have behaving even worse than usual, targeting downstream users, consumers, and others who lack the resources to fight back.

February 13, 2013 - 11:13pm | By Mark M. Jaycox

It's official: The Cyber Intelligence Sharing and Protection Act was reintroduced in the House of Representatives yesterday. CISPA is the contentious bill civil liberties advocates fought last year, which would provide a poorly-defined "cybersecurity" exception to existing privacy law. CISPA offers broad immunities to companies who choose to share data with government agencies (including the private communications of users) in the name of cybersecurity. It also creates avenues for companies to share data with any federal agencies, including military intelligence agencies like the National Security Agency (NSA).

EFF is adamantly opposed to CISPA. Will you join us in calling on Congress to stop this and any other privacy-invasive cybersecurity legislation?

February 13, 2013 - 10:05pm | By Trevor Timm

A few months ago, in EFF's backyard, the Alameda County Sheriff's Office tried to sneak approval for surveillance drone funding at the county's board of supervisors without a public hearing.  Worse, they told the board of supervisors it only wanted to use the drone for emergency purposes. Yet in internal documents obtained by EFF and MuckRock as part of our 2012 drone census showed the Sheriff's Office said it wanted to use the drone for activities like spying on "suspicious persons" and "large crowd control disturbances."

February 13, 2013 - 12:13pm | By Eva Galperin

This weekend, the Cairo Administrative Court issued a 30-day ban order on YouTube and all other websites that host or link to content from the anti-Islam film "The Innocence of Muslims," which was protested worldwide after footage from the trailer was shown on Egyptian television. The court's ruling may force the hand of the National Telecom Regulation Authority (NTRA) and the Ministry of Communications and Information Technology (MCIT), which have refrained from pursuing such a ban themselves.

Pages

Subscribe to EFF Updates

Score one for the space marines. 

Last month, a UK game developer, Games Workshop, complained to Amazon.com that an ebook, Spots the Space Marine, infringed its trademarks in the term "space marine."  Turns out Games Workshop sells a popular game, Warhammer 40,000: Space Marine, and has registered marks in the term "space marine" in connection with games. But Games Workshop lost all sense of proportion and decided that it also had trademark rights to the term in books. And thus a trademark bully was born.  

After it received the complaint, Amazon promptly removed the book from its virtual shelves.  When the author, M.C.A Hogarth, protested, Amazon initially refused to reinstate the book and instead politely suggested she resolve the dispute directly with Games Workshop.  

Defending your rights in the digital world

February 6, 2013 - 5:24pm | By Kurt Opsahl

Copyright troll Righthaven LLC just doesn't know when to stay down. Faced with six district court judges determining it didn't have the right to sue people over copyrights it didn't own, it turned to a higher power: the Ninth Circuit Court of Appeals. Yesterday, EFF appeared before that court to argue (audio) against Righthaven on behalf of Tad DiBiase, a criminal justice blogger who provides resources for difficult-to-prosecute "no body" murder cases and was one of Righthaven's victims.

February 6, 2013 - 12:43pm | By Jillian C. York and Maira Sutton

Following the events of the 'Arab Spring,' numerous countries throughout the Middle East and North Africa have begun assessing—or reassessing—their regulation of the Internet. Last April, we criticized Iraq's attempt at legislation: a heavy-handed bill that, if passed, would impose life imprisonment for vaguely-worded "crimes" such as promoting "ideas which are disruptive to public order" and lesser sentences for a range of other offenses.

February 6, 2013 - 10:52am | By Nate Cardozo

You might be surprised to learn that the vast majority of new cars sold in the United States contain a device that continuously monitors the driver's behavior and vehicle performance. This so-called "black box" or Event Data Recorder (EDR) records at least the last several seconds of vehicle and driver data before a crash, ostensibly for use by crash investigators. Last month, the National Highway Traffic Safety Administration (NHTSA) proposed rules that would mandate EDRs in all new cars and light trucks.

While we agree that EDRs can serve a valuable forensic function, we are concerned that the NHTSA's proposed rules fail to address driver and car-owner privacy in a meaningful way.

February 6, 2013 - 10:49am | By Hanni Fakhoury

The next time you allow a guest into your home for dinner, should you be worried they're secretly video recording every detail of your home for the government? In a new amicus brief filed in the Ninth Circuit Court of Appeals, we've asked the court to reconsider a decision finding that allowing someone into your home means you're also placing yourself at the risk of warrantless home video surveillance. 

February 6, 2013 - 9:43am | By Daniel Nazer

Patent trolls — companies that assert patents as a business model instead of creating products — have been in the news lately. This is hardly surprising, given that troll lawsuits now make up the majority of new patent cases. And the litigation is only the tip of the iceberg: patent trolls send out hundreds of demand letters for each suit filed in court. At EFF, we have been following this issue closely and are working hard to bring reform to fix the patent mess.

February 5, 2013 - 5:44pm | By Adi Kamdar and Peter Eckersley

The Washington Post boldly led a front-page story last weekend with the claim: "The federal government wants to create super WiFi networks across the nation, so powerful and broad in reach that consumers could use them to make calls or surf the Internet without paying a cellphone bill every month."

Let's get one thing straight: the government is not creating its own "super WiFi network", but its plans will indeed make awesome new WiFi networks possible. Technically, what the FCC is actually trying to do is increase the amount of open spectrum that is available for WiFi networks of all sorts—and for other "unlicensed" uses. This is a very good idea. Increasing the amount of unlicensed spectrum will lead to better functioning routers, tablets, laptops, and smartphones—and to a host of other new products in the marketplace. It will enhance the quality and supply of extremely useful open wireless networks, but it will also increase the quality of (somewhat less efficient) password-locked WiFi networks as well.

February 5, 2013 - 1:18pm | By Julie Samuels

Another day, another patent troll. Or so it seems. The threat of the patent troll is not new—we've written about it time and again. But the troubling trend of suing downstream users and content providers really makes us mad. First it was the app developers, then those who scan documents to email. Now, the latest outrage: podcasters. Yes, really. And EFF wants to help organize those facing the threat so that we can gauge the size of the problem and hopefully help people find counsel and a way to work together in response. 

Pages

Subscribe to EFF Updates

Defending your rights in the digital world

February 4, 2013 - 6:42pm | By Corynne McSherry

Can Congress embrace and enact sensible copyright policy? Four years ago, for a brief shining moment, it seemed the answer might be yes, as various interested stakeholders rallied around long-overdue legislation that would have helped to fix the orphan works problem.  Orphan works are those whose owner cannot be located. Consequently, those who would like to use and share these works may hesitate to do so out of fear that they could later be found liable for copyright infringement because they didn't get permission.  In 2008, a variety of interested parties managed to come up with a way to limit that liability.  It wasn't perfect, but it represented real progress.

February 4, 2013 - 10:56am | By Marcia Hofmann and Rainey Reitman

In the wake of social justice activist Aaron Swartz's tragic death, Internet users around the country are taking a hard look at the Computer Fraud and Abuse Act (CFAA), the federal anti-hacking law.  As we've noted, the CFAA has lots of problems. In this three-part series, we'll explain these problems in detail and why they need to be fixed. For more details about our proposal for CFAA reform, see part 2 and part 3.

February 1, 2013 - 11:05am | By Adi Kamdar

The open access movement is a long-standing campaign in the world of research to make scholarly works freely available and reusable. One of its fundamental premises is that the progress of knowledge and culture happens scholarly works of all kinds are widely shared, not hidden in ivory towers built with paywalls and shorn by harsh legal regimes.

January 31, 2013 - 12:09pm | By Mark M. Jaycox

Last year, we saw more battles in Congress over Internet freedom than we have in many years as user protests stopped two dangerous bills, the censorship-oriented SOPA, and the privacy-invasive Cybersecurity Act of 2012. But Congress ended the year by ramming through a domestic spying bill and weakening the Video Privacy Protection Act.

In 2013, Congress will tackle several bills—both good and bad—that could shape Internet privacy for the next decade. Some were introduced last year, and some will be completely new. For now, here's what's ahead in the upcoming Congress:

Reforming Draconian Computer Crime Law

January 31, 2013 - 8:59am | By Rainey Reitman

Recentemente, EFF está trabalhando com TOS;DR para hospedar uma hackathon na Campus Party Brasil, no Centro de Convenções do Parque Anhembi em São Paulo, Brasil. Novidades sobre o conteúdo, inscrição e agenda estão disponíveis no site oficial do evento. Abaixo algumas fotos do evento. 

Você está na Campus Party Brasil? Então mande um e-mail para o Pedro Markun pedro@markun.com.br para participar de nossa hackathon.

January 30, 2013 - 5:09pm | By Rebecca Jeschke

EFF is pleased to welcome our newest staff attorney, Daniel Nazer.  He joins our intellectual property team thanks to a generous donation from Mark Cuban, and will focus on an area of increasing importance in our digital world: patent reform.

Pages

Subscribe to EFF Updates

Defending your rights in the digital world

January 29, 2013 - 9:42pm | By Eva Galperin

When you use the Internet, you entrust your thoughts, experiences, photos, and location data to intermediaries — companies like AT&T, Google, and Facebook. But when the government requests that data, users are usually left in the dark. In the United States, companies are not required by law to alert their users when they receive a government request for their data. In some circumstances, they are explicitly prohibited from doing so. As part of our ongoing Who Has Your Back campaign, EFF has called on companies to be transparent by publishing their law enforcement guidelines and statistics on government requests for user data.

January 29, 2013 - 3:45pm | By Adi Kamdar

Facebook's Graph Search has certainly caused quite a stir since it was first announced two weeks ago. We wrote earlier about how Graph Search, still in beta, presents new privacy problems by making shared information discoverable when previously it was hard—if not impossible—to find at a large scale. We also put out a call to action—and even created a handy how-to guide—urging people to reassess their privacy settings.  

January 29, 2013 - 10:30am | By Jillian C. York

An article in this week's Economist describes a scenario in which—following the destruction of a mall's kiddie dinosaur display by the country's morality police—Saudi Arabia's Twitter users quick make a hashtag go viral, building off one another's jokes and mocking some of the country's most archaic laws.  As the article notes, many of the jokes mocked the morality police themselves, such as one in which a Twitter user quipped: "They worried that people would find the dinosaurs more highly evolved than themselves."

January 29, 2013 - 9:23am | By Katitza Rodriguez

January 28 marks International Privacy Day. Different countries are celebrating this day calling attention to their own events and campaigns. This year, EFF is honoring the day by sharing some advocacy strategies utilized by human rights advocates and activists from Argentina, the UK, Canada, and the United States, that have helped to defeat overreaching surveillance proposals that threaten civil liberties.

January 29, 2013 - 8:17am | By Parker Higgins

In the wake of social justice activist Aaron Swartz's tragic death, Internet users around the country are taking a hard look at the Computer Fraud and Abuse Act (CFAA), the federal anti-hacking law.  In addition to the below overview, we have a three part series explaining these problems in detail and why they need to be fixed. For more details about our proposal for CFAA reform, see part 1, part 2, and part 3.

January 28, 2013 - 2:35pm | By Mitch Stoltz

Legal protection for people who unlock their mobile phones to use them on other networks expired last weekend.  According to the claims of major U.S. wireless carriers, unlocking a phone bought after January 26 without your carrier's permission violates the Digital Millennium Copyright Act ("DMCA") whether the phone is under contract or not. In a way, this is not as bad as it sounds. In other ways, it's even worse.

Pages

Subscribe to EFF Updates

Defending your rights in the digital world

January 28, 2013 - 2:12pm | By Adi Kamdar

Continuing our series of posts about the importance of Section 230 of the Communications Decency Act (CDA 230), we spoke with John Swapceinski, co-founder of the Ratingz Network, which runs over a dozen review sites. Swapceinski got his start in the rating business when he founded RateMyProfessors.com in 1999, a site for college students to review their teachers (which he sold in 2005). In 2004, he started RateMDs to let people review doctors, and in 2005 he co-founded LawyerRatingz, RealEstateRatingz, VetRatingz, and more as part of the Ratingz Network.

January 28, 2013 - 12:46pm | By Corynne McSherry

After years of litigation, it appears Stephanie Lenz may have a chance to tell her story to a jury. Back in 2007, you'll remember, she posted a video to YouTube of her children dancing and running around in her kitchen with Prince's "Let's Go Crazy" playing in the background. A few months later, Universal Music Corp. used the Digital Millennium Copyright Act's rapid-fire takedown process to get the video removed from YouTube, claiming that it infringed copyright law. With help from EFF and Keker & Van Nest, Lenz fought back. She filed a lawsuit asking a federal court to hold Universal accountable for misrepresenting that her fair use video violated copyright law. Late last week, Judge Jeremy Fogel issued a ruling in the case that sent contradictory signals on the future of fair use under the DMCA.

January 28, 2013 - 12:00pm | By Katitza Rodriguez

This is the second in a series of posts mapping global surveillance challenges discussed at EFF's Surveillance Camp in Rio de Janeiro, Brazil.

In December 2012, EFF organized a Surveillance and Human Rights Camp in Brazil that brought together the expertise of a diverse group of people concerned about state electronic surveillance in Latin American and other countries. Among other concerns, participants spotlighted the many ways in which the private sector is increasingly playing a role in state surveillance. Here are a few examples:

January 28, 2013 - 2:16am | By Rainey Reitman

This is a re-posting of a guide by TOSBack developer Jimm Stout

TOSBack is an open-source project that aims to assist users around the world by tracking the changes to Terms of Service (TOS) and other policies on the web, but we need some help to bring it back to life! We are hosting a hackathon at Campus Party Brazil later this week to give the project a healthy revamp. The project uses Rails and we'd love people to contribute code. But if you aren't a Rails developer, you can still contribute by submitting rules and letting us know which policies are important to you. This is a developers' guide for submitting new policies for TOSBack to crawl. If you want to get started as quickly as possible, you can scroll down to the "Putting it all together" section below.

January 24, 2013 - 2:51pm | By Rainey Reitman

EFF, TOS;DR and Campus Party Brazil are Teaming Up for a Liberty-Enhancing Hackathon

UPDATE (2/1/13): For the last three days, hackers and activists in Sao Paulo attending Campus Party have been working with EFF and TOS;DR to improve the free software tool TOSBack. TOSBack is a software project spearheaded by EFF to track the changes to Terms of Service over time. It was in dire need of a revamp, and we're happy to say that hackers at Campus Party rose to the effort.

While there's still a lot to be done, we began the process of relaunching TOSBack over the 3 day hackathon.  Here's what we've done so far:

January 23, 2013 - 1:47pm | By Cindy Cohn and Marcia Hofmann

In our first post, we presented some initial thinking about how to fix the Computer Fraud and Abuse Act (CFAA) and wire fraud law in light of the tragic prosecution of Aaron Swartz. 

Now we present part two: suggestions to address the CFAA's penalty structure.  The CFAA, which is the primary federal computer crime law, allows for harsh punishments and makes too many offenses felonies. The statute is also structured so that the same behavior can violate multiple provisions of the law, which prosecutors often combine to beef up the potential penalties. 

Pages

Subscribe to EFF Updates

Defending your rights in the digital world

January 22, 2013 - 1:26pm | By Marcia Hofmann

アーロン・シュワルツが26歳の若さで自殺したとの報道以来、インターネット内には彼に対する悲しみの気持ちとインターネット規制の変化の要求を表す言葉が次から次へ洪水のようにあふれ出している。

 アーロンは、この電子フロンティア財団の優秀なメンバーの一人で、短い人生ながらとても偉大なことを成し遂げた。彼はコード書きで、政治活動家、起業家、RSSのような有名な技術開発の協力者、そして常にインターネットの自由を愛するロックスターだった。ワイヤードが言及しているように、世界は今後数十年、アーロンの人生がこれほど短命に終わっていなければ彼が果たしたであろう数々の素晴らしいことを手に入れる機会を失うことになるだろう。

  ここ2年以上、アーロンはマサチューセッツ州の司法省の検事たちから告発され、不正に重罪の容疑がかけられた執拗な訴訟を闘うためにエネルギーと財産を費やすことを余儀なくされていた。彼にかけられた容疑は、MITのコンピュータネットワークの利用や、オンラインのアーカイブJSTORからの何百万もの学術記事のダウンロードを、「権限なく」行ったことだという。そのため彼は13ものハッキングと有線通信不正行為という重罪に問われることとなった。これが認められれば、何十年も刑務所に入れられたり罰金を科せられかねない。彼の裁判は今年4月に結審することになっていた。

January 19, 2013 - 4:25pm | By Maira Sutton

We asked leading digital rights activists who have been involved in Trans-Pacific Partnership (TPP) negotiations to discuss copyright law and their advocacy work in the countries where they are based.

This week, Jeremy Malcolm of Consumers International explains recent changes to Malaysia's copyright law, and his current work in pushing for positive global standards that would protect the rights of users against abusive copyright policies. Jeremy is the Project Coordinator for Intellectual Property and Communications. He is based in Kuala Lumpur, Malaysia.

~

January 18, 2013 - 1:27pm | By Rainey Reitman

We created some digital shwag to celebrate Internet Freedom Day — the one year anniversary of the Internet-wide blackout protests that killed the censorship bills SOPA and PIPA. Below are two images designed to be used as Twitter headers. Download the images and try them on your Twitter profile today. Everyone who sees your profile will instantly recognize you as a proud member of the larger EFF community and the movement that helped defeat SOPA.

Make sure to click each image to get the full-size version for download. We'll have more Twitter header options available in the future, so keep an eye here on the EFF blog for updates.

January 18, 2013 - 11:24am | By Adi Kamdar

Earlier this week, Facebook launched a new feature—Graph Search—that raised some privacy concerns with us. Graph Search allows users to make structured searches to filter through friends, friends of friends, and strangers. This feature relies on your profile information being made widely or publicly available, yet there are some Likes, photos, or other pieces of information that you might not want out there.

Since Facebook removed the ability to remove yourself from search results altogether, we've put together a quick how-to guide to help you take control over what is featured on your Facebook profile and on Graph Search results. (Facebook also has a new video explaining how to control what shows up in Graph Search.)

January 18, 2013 - 11:23am | By Adi Kamdar

The famed technology writer Steven Levy starts his long-form history of Facebook's newest product—Graph Search—by describing it as a feature that "promises to transform its user experience, threaten its competitors, and torment privacy activists." Though it takes quite a lot to torment us these days, Graph Search does raise a few eyebrows.

January 18, 2013 - 7:44am | By Trevor Timm

One year ago today, Internet users of all ages, races, and political stripes participated in the largest protest in Internet history, flooding Congress with millions of emails and phone calls to demand they drop the Stop Online Piracy Act (SOPA)—a dangerous bill that would have allowed corporations and the govenrment to censor larger parts of the Web.

But the price of freedom is eternal vigilance, and the fight for Internet freedom continues.  Here's a look at the top five issues SOPA activists should focus on next:

January 17, 2013 - 4:40pm | By Parker Higgins and Trevor Timm

The FBI had to rewrite the book on its domestic surveillance activities in the wake of last January's landmark Supreme Court decision in United States v. Jones. In Jones, a unanimous court held that federal agents must get a warrant to attach a GPS device to a car to track a suspect for long periods of time. But if you want to see the two memos describing how the FBI has reacted to Jones — and the new surveillance techniques the FBI is using beyond GPS trackers — you're out of luck. The FBI says that information is "private and confidential."

Pages

Subscribe to EFF Updates

Defending your rights in the digital world

January 17, 2013 - 1:41pm | By Cindy Cohn and Mark M. Jaycox and Marcia Hofmann

The death of our friend Aaron Swartz has resulted in an unprecedented outpouring of grief, along with a strong commitment to use this tragedy to make some of the change Aaron wanted to see in the world.

At EFF, Aaron's death created two imperatives on issues that are close to our hearts. The first is to continue his work to open up closed and entrenched systems that prevent ordinary people from having access to the world's knowledge, especially the knowledge created with our tax dollars. More on that soon.  

January 12, 2013 - 11:29am | By Peter Eckersley

Yesterday Aaron Swartz, a close friend and collaborator of ours, committed suicide. This is a tragic end to a brief and extraordinary life.

Aaron did more than almost anyone to make the Internet a thriving ecosystem for open knowledge, and to keep it that way. His contributions were numerous, and some of them were indispensable. When we asked him in late 2010 for help in stopping COICA, the predecessor to the SOPA and PIPA Internet blacklist bills, he founded an organization called Demand Progress, which mobilized over a million online activists and proved to be an invaluable ally in winning that campaign.

January 11, 2013 - 6:03pm | By Hanni Fakhoury

Late Friday, a federal judge granted a preliminary injunction in the lawsuit EFF filed with the ACLU of Northern California (ACLU-NC) that challenges the unconstitutional provisions in Proposition 35, a ballot measure passed by California voters in November that restricts the legal and constitutionally protected speech of all registered sex offenders in California.

January 11, 2013 - 10:25am | By Maira Sutton

Expanding copyright to allow rent seeking for linking would break the fabric of the Internet. Links and citations to articles do not infringe copyright, as links do not copy, distribute, or perform any copyrighted work. Despite some desperate assertions of the contrary, copyright protection of links is not enshrined in law. Newspapers, however, are pushing for legislation to support this dangerous claim, regardless of the implications it would have for free speech.

January 10, 2013 - 3:36pm | By Parker Higgins

Today the California Attorney General released "Privacy on the Go," [pdf] a report of privacy recommendations for players in the smartphone ecosystem focused on mobile app developers. These guidelines continue a push from the Attorney General to extend privacy protections from the online world onto the smaller screens of our mobile devices, kicked off by an agreement last year to incorporate app privacy policies into the six largest mobile "app stores." 

January 10, 2013 - 12:04pm | By Parker Higgins

Update: On January 10, YouTube informed Jonathan McIntosh that his video had been reinstated. The copyright "strike" appears to be removed from his account. YouTube did not wait for the DMCA's 10 to 14 day waiting period to expire, choosing to stand up for its user and putting a stake in this disappointing abuse of the takedown process.

Pages

Subscribe to EFF Updates

Defending your rights in the digital world

January 9, 2013 - 5:36pm | By Trevor Timm

The 113th Congress was sworn into office last week and will start regular business later this month. They'll have a huge, and perhaps unprecedented, slate of Internet related legislation in the next year, including potentially taking up a dangerous new Internet surveillance bill—which we will detail in the coming days and weeks.

But before they do, they should take a lesson from the 112th Congress on how not to conduct business. In their final official week of existence—and the cover of holidays—the 112th Congress used underhanded and undemocratic tactics to pass two bills that have terrible effects on your online privacy.

January 9, 2013 - 3:49pm | By Adi Kamdar

Free speech has very strong protections in the United States. Not only do we have laws like CDA 230 that allow review sites like Yelp to exist, but we also have very strong defenses ingrained both in our Constitution and in our statutes. Unfortunately, there are aspects of the legal system that are easily abused; people too often use lawsuits to intimidate others and stifle their speech.

January 9, 2013 - 3:08am | By Eva Galperin

In the last two days, Kuwaiti courts have issued back-to-back 2-year jail sentences to Twitter users for allegedly insulting Emir Sheikh Sabah al-Ahmad Al Sabah. The first verdict was issued on Sunday against 26-year old Rashid Saleh al-Anzi over a Tweet he made to his 5,700 followers in October, that the court said, "stabbed the rights and powers" of the Emir. Al-Anzi has been sentenced to two years in prison and is expected to appeal.

January 7, 2013 - 9:36pm | By Parker Higgins and Rainey Reitman

On December 28, 2012, Senator Ron Wyden (D-OR) spoke out eloquently against the warrantless wiretapping program instituted by the Bush Administration and continued by the Obama Administration. In his testimony before the Senate, Wyden explained how the original FISA Act worked - and how, after September 11th, the Bush Administration exceeded its legal authority and instituted a warrantless surveillance program.

In the clip below, Wyden explains that he was never briefed on the warrantless wiretapping program when it was created- even though he was a member of the Senate Select Committee on Intelligence:

Like you, I have been on the Intelligence Committee and I have been a member for 12 years. But the first time I heard about the warrantless wiretapping program - the first time I heard about it - was when I read about it in the newspaper. It was in the New York Times before I - as a member of the Senate Select Committee on Intelligence - knew about it.

January 7, 2013 - 8:08pm | By Eva Galperin

UPDATE 1/10/13: After a two-day trial, a court in the city of Vinh convicted all 14 of the defendants that appeared in court. Thirteen of the activists and bloggers were sentenced to serve prison terms ranging individually from 3 to 13 years. One [Nguyen Dang Vinh Phuc] was given a three-year conditionally suspended sentence, making him easily vulnerable to re-arrest. EFF condemns these harsh sentences and calls for the immediate release of the imprisoned activists.

January 7, 2013 - 3:46pm | By Seth Schoen

We're really happy that Yahoo! is starting 2013 right by letting Yahoo! Mail users use HTTPS to access their e-mail accounts securely. (That means that, just a few days into 2013, we got one of the items on our holiday wishlist!)

January 6, 2013 - 7:05pm | By Jennifer Lynch

In the amount of time it takes to get lunch, the government can now collect your DNA and extract a profile that identifies you and your family members.

Rapid DNA Analyzers—machines with the ability to process DNA in 90 minutes or less—are an operational reality and are being marketed to the federal government and state and local law enforcement agencies around the country. These machines, each about the size of a laser printer, are designed to be used in the field by non-scientists, and—if you believe the hype from manufacturers like IntegenX and NetBio—will soon "revolutionize the use of DNA by making it a routine identification and investigational tool."

Pages

Subscribe to EFF Updates


(via Instapaper)



Just me,

e 📧
@ELyssaD™


^ed 

Thousands of Amazon S3 buckets left open exposing private data

Thousands of Amazon S3 buckets left open exposing private data
http://www.net-security.org/secworld.php?id=14669&utm_source=dlvr.it&utm_medium=twitter


Cloud hosting and cloud storage is all the rage, but there are still some common pitfalls that many organizations overlook. In this article I will walk through an issue that seems to be coming up a lot - exposed Amazon S3 buckets. Amazon Simple Storage Service (S3) provides the ability to store and serve static content from Amazon's cloud.

image

Businesses use S3 to store server backups, company documents, web logs, and publicly visible content such as web site images and PDF documents. Files within S3 are organized into "buckets", which are named logical containers accessible at a predictable URL. Access controls can be applied to both the bucket itself and to individual objects (files and directories) stored within that bucket.

A bucket is typically considered "public" if any user can list the contents of the bucket, and "private" if the bucket's contents can only be listed or written by certain S3 users. This is important to understand and emphasize. A public bucket will list all of its files and directories to an any user that asks.

Checking if a bucket is public or private is easy. All buckets have a predictable and publicly accessible URL. By default this URL will be either of the following:

http://s3.amazonaws.com/[bucket_name]/
http://[bucket_name].s3.amazonaws.com/

To test the openness of the bucket a user can just enter the URL in their web browser. A private bucket will respond with "Access Denied". A public bucket will list the first 1,000 objects that have been stored.

The security risk from a public bucket is simple. A list of files and the files themselves - if available for download - can reveal sensitive information. The worst case scenario is that a bucket has been marked as "public", exposes a list of sensitive files, and no access controls have been placed on those files. In situations where the bucket is public, but the files are locked down, sensitive information can still be exposed through the file names themselves, such as the names of customers or how frequently a particular application is backed up.

It should be emphasized that a public bucket is not a risk created by Amazon but rather a misconfiguration caused by the owner of the bucket. And although a file might be listed in a bucket it does not necessarily mean that it can be downloaded. Buckets and objects have their own access control lists (ACLs). Furthermore, Amazon helps their users by publishing a best practices document. The default configuration of an S3 bucket is private.

The research

My role at Rapid7 is providing penetration testing services for organizations that want to test the effectiveness of their security practices and identify potential areas of risk, as well as the likely impact of attacks in those areas. Having found public buckets on a number of assessments, and used them as part of my attack strategy, I was curious how common this issue of public buckets is, and what sorts of data we would find in exposed buckets.

Later on in the research process I discovered that someone else had already discussed the dangers of public buckets. Robin Wood previously blogged on the issue and published a tool to check the openness of buckets. Robin's work is excellent as usual and we tried to take it a bit further focusing on enterprises and buckets identified in web crawling results.

The results

We discovered 12,328 unique buckets with the following breakdown:

  • Public: 1,951
  • Private: 10,377
Approximately 1 in 6 buckets are left open for the perusal of anyone that's interested.

From the 1,951 public buckets we gathered a list of over 126 billion files. The sheer number of files made it unrealistic to test the permissions of every single object, so a random sampling was taken instead. All told, we reviewed over 40,000 publicly visible files, many of which contained sensitive data.

Some specific examples of the data found are listed below:

  • Personal photos from a medium-sized social media service
  • Sales records and account information for a large car dealership
  • Affiliate tracking data, click-through rates, and account information for an ad company's clients
  • Employee personal information and member lists across various spreadsheets
  • Unprotected database backups containing site data and encrypted passwords
  • Video game source code and development tools for a mobile gaming firm
  • PHP source code including configuration files, which contain usernames and passwords
  • Sales "battlecards" for a large software vendor.
Much of the data could be used to stage a network attack, compromise users accounts, or to sell on the black market. Although more subtle, one of the other concerns was the number of publicly available log files.

The majority of the file listings were images (~60%). Although most images were fine there were a few different social media sites exposing many of their users pictures and videos.

Finally, there was a considerable number of text documents (over 5 million), including a surprising amount that contained credentials. Much of the documentation we spot checked was marked up "Confidential" or "Private."

Data gathering techniques

In the first step we gathered a list of valid bucket names. A valid or invalid bucket can be determined by browsing to the bucket's URL; an invalid bucket will return an error of "NoSuchBucket." We used the following combination of sources to gather lists of valid bucket names:

1. Guessing names through a few different dictionaries:

  • List of Fortune1000 company names with permutations on .com, -backup, -media. For example, walmart becomes walmart, walmart.com, walmart-backup, walmart-media.
  • List of the top Alexa 100,000 sites with permutations on the TLD and www. For example, walmart.com becomes www.walmart.com, www.walmart.net, walmart.com, and walmart.
2. Extracting S3 links from the HTTP responses identified by the Critical.IO project. This enabled us to identify s3.amazonaws.com and cloudfront.net addresses "in the wild". It is very common for a cloudfront.net address to point to an S3 bucket.

3. The Bing Search API was queried to gather a list of potentials.

We then used custom tools to check the openness of the buckets. A file listing was pulled from all open buckets using the s3cmd tool. Finally, we analyzed the results and began to selectively download files. A majority of the available buckets were identified using Critical.IO scan data.

Penetration testing pro-tip

Although many buckets are now private, that doesn't mean they were always private. The s3.amazonaws.com site is regularly indexed by Google (unless the bucket itself includes a robots.txt) so Google dorks still apply. For example, the following Google query can identify Excel spreadsheets containing the word "password":

site:s3.amazonaws.com filetype:xls password

Also, the WayBackMachine is a great resource to identify previously open buckets. Using a modified version of @mubix's Metasploit module, I also quickly identified a few hundred buckets that are currently private that previously weren't.

Recommendations

This is pretty straightforward: check if you own one of the open buckets and if so, think about what you're keeping in that buckets and whether you really want it exposed to the internet and anyone curious to take a look. If you don't, remediation is quite simple for this one, and Amazon has made it even easier by helpfully walking through the options for you. We highly recommend you get on it now!

Acknowledgements

Robin Wood - for getting the ball rolling on S3 public bucket exposure.

HD Moore - when I said "we" above, this is typically who I was talking about.

The Amazon AWS security team - these folks have been extremely responsive, warned their users about the risk, and are currently putting measures in place to proactively identify misconfigured files and buckets moving forward. If only all service providers had a team this capable.

image

Author: Will Vandevanter, Security Researcher at Rapid7.

(via Instapaper)

Policing the Internet

Policing the Internet
http://mybroadband.co.za/news/internet/71406-policing-the-internet-2.html


It reads like a bad spy novel: a secret unit of China's People's Liberation Army (PLA) is accused of spending the last seven years covertly infiltrating – or hacking – over a hundred large US corporations and stealing terabytes of sensitive data from their computer systems.

Unit 61398 of the PLA – nicknamed Comment Crew or Shanghai Group – was conclusively linked to thehacking of 141 US corporations by Mandiant, an internet security firm. The firm, which has spent nearly a decade tracking attacks on large firms, recently published a report called "Advanced Persistent Threat 1″ (APT1) on the group .

When Mandiant first revealed the existence of APT1 in 2010, the firm was careful not to imply complicity by the Chinese government. Now it is completely convinced "that the groups conducting these activities are based primarily in China and that the Chinese government is aware of them".

Naturally China's government vehemently denies the accusations, calling them "scientifically flawed", "irresponsible" and "unprofessional". But officials rathergive the game away with their second point: " … there is still no internationally clear, unified definition of what consists of a 'hacking attack'. There is no legal evidence behind the report subjectively inducing that the everyday gathering of online [information] is online spying."

Kevin Mandia, founder and chief executive of Mandiant, is unequivocal on the subject. In an interview with theNew York Times he said that "either [the attacks] are coming from inside Unit 61398, or the people who run the most-controlled, most-monitored internet networks in the world are clueless about thousands of people generating attacks from this one neighbourhood."

The neighbourhood Mandia is referring to is on the outskirts of Shanghai. Almost all of APT1′s activities can be traced back to a single building, which also happens to be the headquarters of PLA Unit 61398.

Of course the New York Times itself has a bone to pick with the Chinese. In January the media company revealed that it had been subject to months of cyberattacks, all of them originating in China – though not from APT1. The motive for the attacks seems to be a report in October about relatives of China's Prime Minister Wen Jiabao, who had earned billions of dollars through shady business deals.

The New York Times was not the only media company to attract the wrath of the Chinese. The Wall Street Journal, Washington Post and Bloomberg News were all recently attacked and it is alleged all of the attacks could be traced back to China.

Should we be concerned that Chinese technology seems so much better than the US's? That's the thing: none of these hacks used particularly technologically advanced methods. Like all gifted hackers, the Chinese infiltrators focused on the weakest link in the security chain – the human beings.

We have all received one of those emails from "ABBSA" or "Standerd Bank", telling us we need to "verify our details" – even though we have been lifelong customers of FNB. These blatant attempts to steal valuable data are called "phishing" because the hackers are simply casting out thousands of baited virtual hooks and hoping to catch a granny who does not know better.

The Chinese hackers used a clever variation on this method called "spear phishing". Instead of sending hundreds of anonymous emails that any wary professional would quickly reject, they crafted emails to look like internal office communications.

So you might receive an email that appeared to be from your HR department, addressing you by name, and asking you to complete the attached form. If you clicked on the attachment – which is really a piece of "spyware" designed to turn your computer into a gateway – the hackers would immediately have a foothold in your network.

This is almost certainly how the New York Times was hacked, as well as hundreds of other companies. The Mandiat report calls spear phishing APT1′s "most commonly used technique". This tells us that it is not our computer systems we need to beef up so much as our staff.

That said, when hackers can successfully fool the smartest technical staff of Twitter, Facebook and Appleall in the space of a few weeks, then there is little hope for us mere mortals. Both Facebook and Apple were hacked using an ingenious and almost undetectable method: infecting a forum popular with software developers with a piece of spyware. As soon as anyone visited the forum, their computers would be compromised. Bingo.

Hacking of this kind is obviously a scourge. It wastes resources, breaches confidentiality and hurts customer confidence. But there are two less obvious dangers.

The first is that hacking may be used as a pretext for a cyberwar with China. Such a war might seem exciting but it would be terrible for diplomatic and trade relations and an unwanted distraction from the very real problems both nations face.

And, despite all its clumsy dissembling, there is a danger of turning China into the new "reds under the bed". There is no evidence that China had anything to do with the hacks on Facebook or Apple, for instance, but hawks are already lumping them in with the "Chinese attacks". As outgoing US Secretary of State Hillary Rodham Clinton said: "The Chinese are not the only people who are hacking us."

The second hidden danger is that politicians on both sides of the divide may use hacking as an excuse to regulate the internet more closely. US President Barack Obama already signed an executive order to "give our government a greater capacity to secure our networks and deter attacks". That is not necessarily sinister but it is worrying.

There is no mistaking the Chinese position. A secret US state department cable revealed the chilling details of a report by China's state council information office to its Communist Party leadership.

The state department's contact told the New York Times: "In the past, a lot of officials worried that the web could not be controlled. But through the Google incident and other increased controls and surveillance, like real-name registration, they reached a conclusion: the web is fundamentally controllable."

The "Google incident" above refers to Google pulling out of mainland China in March 2010 after suffering from sustained hacking attacks, probably originating from the PLA.

The irony is that we would not have any of this information if it were not for WikiLeaks exposing secret cables between US government departments. Openness is a double-edged sword – if we clamp down in the name of security, we also stifle its ability to expose wrongdoing.

The US should not imitate China under any circumstances. However much openness might cost it, it is one of the things that made America great. Let us hope their lawmakers agree.

Source: Mail & Guardian

More Internet articles

Internet providers begin warning of illegal downloads

EU lawmakers seek to limit use of data by internet firms

P2P file-sharers buy more music than non-users

Landmark copyright infringement cases


(via Instapaper)

Amazon S3, Cloud Computing Storage for Files, Images, Videos

Amazon S3, Cloud Computing Storage for Files, Images, Videos
http://aws.amazon.com/s3/


Amazon S3 is storage for the Internet. It is designed to make web-scale computing easier for developers.

Amazon S3 provides a simple web services interface that can be used to store and retrieve any amount of data, at any time, from anywhere on the web. It gives any developer access to the same highly scalable, reliable, secure, fast, inexpensive infrastructure that Amazon uses to run its own global network of web sites. The service aims to maximize benefits of scale and to pass those benefits on to developers.

 


This page contains the following categories of information. Click to jump down:


Amazon S3 is intentionally built with a minimal feature set.

  • Write, read, and delete objects containing from 1 byte to 5 terabytes of data each. The number of objects you can store is unlimited.
  • Each object is stored in a bucket and retrieved via a unique, developer-assigned key.
  • A bucket can be stored in one of several Regions. You can choose a Region to optimize for latency, minimize costs, or address regulatory requirements. Amazon S3 is currently available in the US Standard, US West (Oregon), US West (Northern California), EU (Ireland), Asia Pacific (Singapore), Asia Pacific (Tokyo), Asia Pacific (Sydney), South America (Sao Paulo), and GovCloud (US) Regions. The US Standard Region automatically routes requests to facilities in Northern Virginia or the Pacific Northwest using network maps.
  • Objects stored in a Region never leave the Region unless you transfer them out. For example, objects stored in the EU (Ireland) Region never leave the EU.
  • Authentication mechanisms are provided to ensure that data is kept secure from unauthorized access. Objects can be made private or public, and rights can be granted to specific users.
  • Options for secure data upload/download and encryption of data at rest are provided for additional data protection.
  • Uses standards-based REST and SOAP interfaces designed to work with any Internet-development toolkit.
  • Built to be flexible so that protocol or functional layers can easily be added. The default download protocol is HTTP. A BitTorrent™ protocol interface is provided to lower costs for high-scale distribution.
  • Provides functionality to simplify manageability of data through its lifetime. Includes options for segregating data by buckets, monitoring and controlling spend, and automatically archiving data to even lower cost storage options. These options can be easily administered from the Amazon S3 Management Console.
  • Reliability backed with the Amazon S3 Service Level Agreement.

Data stored in Amazon S3 is secure by default; only bucket and object owners have access to the Amazon S3 resources they create. Amazon S3 supports multiple access control mechanisms, as well as encryption for both secure transit and secure storage on disk. With Amazon S3's data protection features, you can protect your data from both logical and physical failures, guarding against data loss from unintended user actions, application errors, and infrastructure failures. For customers who must comply with regulatory standards such as PCI and HIPAA, Amazon S3's data protection features can be used as part of an overall strategy to achieve compliance. The various data security and reliability features offered by Amazon S3 are described in detail below.

Data Security Details

Amazon S3 supports several mechanisms that give you flexibility to control who can access your data as well as how, when, and where they can access it. Amazon S3 provides four different access control mechanisms: Identity and Access Management (IAM) policies, Access Control Lists (ACLs), bucket policies, and query string authentication. IAM enables organizations with multiple employees to create and manage multiple users under a single AWS account. With IAM policies, you can grant IAM users fine-grained control to your Amazon S3 bucket or objects. You can use ACLs to selectively add (grant) certain permissions on individual objects. Amazon S3 Bucket Policies can be used to add or deny permissions across some or all of the objects within a single bucket. With Query string authentication, you have the ability to share Amazon S3 objects through URLs that are valid for a predefined expiration time.

You can securely upload/download your data to Amazon S3 via the SSL encrypted endpoints using the HTTPS protocol. Amazon S3 also provides multiple options for encryption of data at rest. If you prefer to manage your own encryption keys, you can use a client encryption library like the Amazon S3 Encryption Client to encrypt your data before uploading to Amazon S3. Alternatively, you can use Amazon S3 Server Side Encryption (SSE) if you prefer to have Amazon S3 manage encryption keys for you. With Amazon S3 SSE, you can encrypt data on upload simply by adding an additional request header when writing the object. Decryption happens automatically when data is retrieved.

Amazon S3 also supports logging of requests made against your Amazon S3 resources. You can configure your Amazon S3 bucket to create access log records for the requests made against it. These server access logs capture all requests made against a bucket or the objects in it and can be used for auditing purposes.

For more information on the security features available in Amazon S3, please refer to Access Control and Using Data Encryption topics in the Amazon S3 Developer Guide. For an overview on security on AWS, including Amazon S3, please refer to Amazon Web Services: Overview of Security Processes document.

Data Durability and Reliability

Amazon S3 provides a highly durable storage infrastructure designed for mission-critical and primary data storage. The service redundantly stores data in multiple facilities and on multiple devices within each facility. To increase durability, Amazon S3 synchronously stores your data across multiple facilities before returning SUCCESS. In addition, Amazon S3 calculates checksums on all network traffic to detect corruption of data packets when storing or retrieving data. Unlike traditional systems which can require laborious data verification and manual repair, Amazon S3 performs regular, systematic data integrity checks and is built to be automatically self-healing.

Amazon S3 provides further protection via Versioning. You can use Versioning to preserve, retrieve, and restore every version of every object stored in your Amazon S3 bucket. This allows you to easily recover from both unintended user actions and application failures. By default, requests will retrieve the most recently written version. Older versions of an object can be retrieved by specifying a version in the request. Storage rates apply for every version stored.

Amazon S3's standard storage is:

  • Backed with the Amazon S3 Service Level Agreement.
  • Designed for 99.999999999% durability and 99.99% availability of objects over a given year.
  • Designed to sustain the concurrent loss of data in two facilities.

Reduced Redundancy Storage (RRS) is a storage option within Amazon S3 that enables customers to reduce their costs by storing non-critical, reproducible data at lower levels of redundancy than Amazon S3's standard storage. It provides a cost-effective, highly available solution for distributing or sharing content that is durably stored elsewhere, or for storing thumbnails, transcoded media, or other processed data that can be easily reproduced. The RRS option stores objects on multiple devices across multiple facilities, providing 400 times the durability of a typical disk drive, but does not replicate objects as many times as standard Amazon S3 storage, and thus is even more cost effective. Reduced Redundancy Storage is:

  • Backed with the Amazon S3 Service Level Agreement.
  • Designed to provide 99.99% durability and 99.99% availability of objects over a given year. This durability level corresponds to an average annual expected loss of 0.01% of objects.
  • Designed to sustain the loss of data in a single facility.

Amazon Glacier

Amazon S3 enables you to utilize Amazon Glacier's extremely low-cost storage service as a storage option for data archival. Amazon Glacier stores data for as little as $0.01 per gigabyte per month, and is optimized for data that is infrequently accessed and for which retrieval times of several hours are suitable. Examples include digital media archives, financial and healthcare records, raw genomic sequence data, long-term database backups, and data that must be retained for regulatory compliance.

Like Amazon S3's other storage options (Standard or Reduced Redundancy Storage), objects stored in Amazon Glacier using Amazon S3's APIs or Management Console have an associated user-defined name. You can get a real-time list of all of your Amazon S3 object names, including those stored using the Amazon Glacier option, using the Amazon S3 LIST API. Objects stored directly in Amazon Glacier using Amazon Glacier's APIs cannot be listed in real-time, and have a system-generated identifier rather than a user-defined name. Because Amazon S3 maintains the mapping between your user-defined object name and the Amazon Glacier system-defined identifier, Amazon S3 objects that are stored using the Amazon Glacier option are only accessible through Amazon S3's APIs or the Amazon S3 Management Console. To restore Amazon S3 data that was stored in Amazon Glacier via the Amazon S3 APIs or Management Console, you first initiate a restore job using the Amazon S3 APIs or Management Console. Restore jobs typically complete in 3 to 5 hours. Once the job is complete, you can access your data through an Amazon S3 GET request.

The Amazon Glacier storage option is:

  • Backed with the Amazon S3 Service Level Agreement.
  • Designed for 99.999999999% durability and 99.99% availability of objects over a given year.
  • Designed to sustain the concurrent loss of data in two facilities.

Amazon S3 makes it easy to manage your data. With Amazon S3's data lifecycle management capabilities, you can automatically archive objects to even lower cost storage options or perform recurring deletions, enabling you to reduce your costs over an object's lifetime. Amazon S3 also allows you to monitor and control your costs across your different business functions. All of these management capabilities can be easily administered using the Amazon S3 APIs or Management Console. The various data management features offered by Amazon S3 are described in detail below.

Data Lifecycle Management

Lifecycle management of data refers to how your data is managed and stored from creation and initial storage to when it's no longer needed and deleted. Amazon S3 provides a number of capabilities to simplify the lifecycle management of your data, including management of capacity, automated archival to lower cost storage, and scheduled deletions.

When storing new data, Amazon S3 eliminates the need for capacity planning by enabling you to both scale on-demand and pay only for the capacity you use. With traditional storage systems, capacity planning can be an error-prone process, especially when storage growth is unpredictable, as it often is. Over provisioning capacity can result in under-utilization and higher costs, while under provisioning can trigger expensive hardware upgrades far earlier than planned.

As your data ages, Amazon S3 takes care of automatically and transparently migrating your data to new hardware as hardware fails or reaches its end of life. This eliminates the need for you to perform expensive, time-consuming, and risky hardware migrations. Amazon S3 also enables you to automatically archive your data to lower cost storage as your data ages. You can define rules to automatically archive sets of Amazon S3 objects to Amazon Glacier based on their lifetime. Data archival rules are supported for Amazon S3 objects in the US-Standard, US-West (N. California), US-West (Oregon), EU-West (Ireland), and Asia Pacific (Japan) Regions

When your data reaches its end of life, Amazon S3 provides programmatic options for recurring and high volume deletions. For recurring deletions, rules can be defined to remove sets of objects after a pre-defined time period. For efficient one-time deletions, up to 1,000 objects can be deleted with a single request. These rules can be applied to standard objects, RRS objects, or objects that have been archived to Amazon Glacier.

Cost Monitoring and Controls

Amazon S3 offers several features for managing and controlling your costs. You can use the AWS Management Console or the Amazon S3 APIs to apply tags to your Amazon S3 buckets, enabling you to allocate your costs across multiple business dimensions, including cost centers, application names, or owners. You can then view breakdowns of these costs using Amazon Web Services' Cost Allocation Reports, which show your usage and costs aggregated by your tags. For more information on Cost Allocation and tagging, please visit About AWS Account Billing. For more information on tagging your S3 buckets, please see the Bucket Tagging topic in the Amazon S3 Developer Guide.

You can use Amazon CloudWatch to receive billing alerts that help you monitor the Amazon S3 charges on your bill. You can set up an alert to be notified automatically via e-mail when estimated charges reach a threshold that you choose. For additional information on billing alerts, you can visit the billing alerts page or see the Monitor Your Estimated Charges topic in the Amazon CloudWatch Developer Guide.


Pay only for what you use. There is no minimum fee. Estimate your monthly bill using the AWS Simple Monthly Calculator. We charge less where our costs are less, and prices are based on the location of your Amazon S3 bucket.

AWS Free Usage Tier*

As part of the AWS Free Usage Tier, you can get started with Amazon S3 for free. Upon sign-up, new AWS customers receive 5 GB of Amazon S3 standard storage, 20,000 Get Requests, 2,000 Put Requests, and 15GB of data transfer out each month for one year.

Storage Pricing

Request Pricing

Data Transfer Pricing

The pricing below is based on data transferred "in" to and "out" of Amazon S3.

Storage and bandwidth size includes all file overhead.

Rate tiers take into account your aggregate usage for Data Transfer Out to the Internet across Amazon EC2, Amazon S3, Amazon Glacier, Amazon RDS, Amazon SimpleDB, Amazon SQS, Amazon SNS, Amazon DynamoDB, and AWS Storage Gateway.

AWS GovCloud Region

AWS GovCloud is an AWS Region designed to allow U.S. government agencies and contractors to move more sensitive workloads into the cloud by addressing their specific regulatory and compliance requirements. For pricing and more information on the new AWS GovCloud Region, please visit the AWS GovCloud web page.

*

Your usage for the free tier is calculated each month across all regions except the AWS GovCloud Region and automatically applied to your bill – unused monthly usage will not roll over. Restrictions apply; See

offer terms

for more details.

(Amazon S3 is sold by Amazon Web Services, Inc..)


Using Amazon S3 is easy. To get started you:

  • Create a Bucket to store your data. You can choose a Region where your bucket and object(s) reside to optimize latency, minimize costs, or address regulatory requirements.
  • Upload Objects to your Bucket. Your data is durably stored and backed by the Amazon S3 Service Level Agreement.
  • Optionally, set access controls. You can grants others access to your data from anywhere in the world.

You can easily and securely create buckets, upload objects, and set access controls using the AWS Management Console. The console provides a point-and-click web-based interface for accessing and managing all of your Amazon S3 resources. The Amazon S3 Getting Started Guide shows you how to start using Amazon S3 from the console. Developers building applications can use the AWS SDK for .NET, the AWS SDK for Java, or a wide variety of 3rd party libraries for other platforms and languages.


AWS Import/Export accelerates moving large amounts of data into and out of AWS using portable storage devices for transport. AWS transfers your data directly onto and off of storage devices using Amazon's high-speed internal network and bypassing the Internet. For significant data sets, AWS Import/Export is often faster than Internet transfer and more cost effective than upgrading your connectivity. You can use AWS Import/Export for migrating data into the cloud, distributing content to your customers, sending backups to AWS, and disaster recovery.

You can also use AWS Direct Connect to transfer large amounts of data to Amazon S3. AWS Direct Connect makes it easy to establish a dedicated network connection from your premise to AWS. Using AWS Direct Connect, you can establish private connectivity between AWS and your datacenter, office, or colocation environment, which in many cases can reduce your network costs, increase bandwidth throughput, and provide a more consistent network experience than Internet-based connections.


Amazon S3 can be used to support a wide variety of use cases, for example:

Content Storage and Distribution

Amazon S3 provides a highly durable and available store for a variety of content, ranging from web applications to media files. It allows you to offload your entire storage infrastructure onto the cloud, where you can take advantage of Amazon S3's scalability and pay-as-you-go pricing to handle your growing storage needs. You can distribute your content directly from Amazon S3 or use Amazon S3 as an origin store for pushing content to your Amazon CloudFront edge locations.

For sharing content that is either easily reproduced or where you're storing an original copy elsewhere, Amazon S3's Reduced Redundancy Storage (RRS) feature provides a compelling solution. For example, if you're storing media content in-house but you need to provide accessibility to your customers, channel partners, or employees, RRS is a low-cost solution for storing and sharing this content.

Storage for Data Analysis

Whether you're storing pharmaceutical data for analysis, financial data for computation and pricing, or photo images for resizing, Amazon S3 is an ideal location to store your original content. You can then send this content to Amazon EC2 for computation, resizing, or other large scale analytics – without incurring any data transfer charges for moving the data between the services. You can then choose to store the resulting, reproducible content using Amazon S3's Reduced Redundancy Storage feature (or, of course, you can store it using Amazon S3's standard storage as well).

Backup, Archiving and Disaster Recovery

Amazon S3 offers a highly durable, scalable, and secure solution for backing up and archiving your critical data. You can use Amazon S3's Versioning capability to provide even further protection for your stored data. If you have data sets of significant size, you can use

AWS Import/Export

to move large amounts of data into and out of AWS with physical storage devices. This is ideal for moving large quantities of data for periodic backups, or quickly retrieving data for disaster recovery scenarios. You can also define rules to archive sets of Amazon S3 objects to Amazon Glacier's extremely low-cost storage service based on object lifetimes. As your data ages, these rules enable you to ensure that it's automatically stored on the storage option that is most cost-effective for your needs.

Static Website Hosting

You can host your entire static website on Amazon S3 for an inexpensive, highly available hosting solution that scales automatically to meet traffic demands. Self-hosting a highly available website that can handle peak traffic loads can be challenging and costly. With Amazon S3, you can reliably serve your traffic and handle unexpected peaks without worrying about scaling your infrastructure. Amazon S3 is designed for 99.99% availability and 99.999999999% durability, and it gives you access to the same highly scalable, reliable, and fast infrastructure that Amazon uses to run its own global network of web sites. You also benefit from pay-as-you-go pricing. You pay only for the capacity you use. Amazon S3's website hosting solution is ideal for websites with static content, including html files, images, videos, and client-side scripts such as JavaScript. (Amazon EC2 is recommended for websites with server-side scripting and database interaction).


Amazon S3 is based on the idea that quality Internet-based storage should be taken for granted. It helps free developers from worrying about how they will store their data, whether it will be safe and secure, or whether they will have enough storage available. It frees them from the upfront costs of setting up their own storage solution as well as the ongoing costs of maintaining and scaling their storage servers. The functionality of Amazon S3 is simple and robust: Store any amount of data inexpensively and securely, while ensuring that the data will always be available when you need it. Amazon S3 enables developers to focus on innovating with data, rather than figuring out how to store it.

Amazon S3 was built to fulfill the following design requirements:

  • Secure: Built to provide infrastructure that allows the customer to maintain full control over who has access to their data. Customers must also be able to easily secure their data in transit and at rest.
  • Reliable: Store data with up to 99.999999999% durability, with 99.99% availability. There can be no single points of failure. All failures must be tolerated or repaired by the system without any downtime.
  • Scalable: Amazon S3 can scale in terms of storage, request rate, and users to support an unlimited number of web-scale applications. It uses scale as an advantage: Adding nodes to the system increases, not decreases, its availability, speed, throughput, capacity, and robustness.
  • Fast: Amazon S3 must be fast enough to support high-performance applications. Server-side latency must be insignificant relative to Internet latency. Any performance bottlenecks can be fixed by simply adding nodes to the system.
  • Inexpensive: Amazon S3 is built from inexpensive commodity hardware components. All hardware will eventually fail and this must not affect the overall system. It must be hardware-agnostic, so that savings can be captured as Amazon continues to drive down infrastructure costs.
  • Simple: Building highly scalable, reliable, fast, and inexpensive storage is difficult. Doing so in a way that makes it easy to use for any application anywhere is more difficult. Amazon S3 must do both.

A forcing-function for the design was that a single Amazon S3 distributed system must support the needs of both internal Amazon applications and external developers of any application. This means that it must be fast and reliable enough to run Amazon.com's websites, while flexible enough that any developer can use it for any data storage need.


Your use of this service is subject to the Amazon Web Services Customer Agreement


(via Instapaper)