<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Non Spy RSS Feed]]></title><description><![CDATA[Technology, Law, Forensics]]></description><link>https://www.domingorivera.tech</link><generator>GatsbyJS</generator><lastBuildDate>Sat, 12 Dec 2020 19:58:43 GMT</lastBuildDate><item><title><![CDATA[WordPress Gets Overdue Security Features]]></title><description><![CDATA[Probably the biggest and the most important of today's new security features is WordPress' offline digital signatures system. Starting with WordPress 5.2, the WordPress team will digitally sign its update packages with the Ed25519 public-key signature system so that a local installation will be able to verify the update package's authenticity before applying it to a local site.]]></description><link>https://www.domingorivera.tech/gatsby-starter-developer-blog/wordpress-gets-overdue-security-features</link><guid isPermaLink="false">https://www.domingorivera.tech/wordpress-gets-overdue-security-featuresWordPress Gets Overdue Security Features</guid><dc:creator><![CDATA[domingo rivera]]></dc:creator><pubDate>Wed, 08 May 2019 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;For a Content Management System (CMS) that powers one third of the Internet, Wordpress leaves a lot to be desired in terms of security features.  A lot of it is not necessarily the fault of the Wordpress team.  Independent developers contribute &quot;plugins&quot; that are often full of vulnerabilities and junk code.  Also, some of these plugins are not frequently maintained resulting in sites loaded with vulnerabilities.&lt;/p&gt;
&lt;p&gt;WordPress is set to receive an assortment of new security features today that will finally add the protection level that many of its users have desired for years. &lt;/p&gt;
&lt;p&gt;&lt;em&gt;These features are expected to land with the official release of WordPress 5.2, expected for later today. Included are &lt;a href=&quot;https://www.zdnet.com/article/wordpress-finally-gets-the-security-features-a-third-of-the-internet-deserves/&quot;&gt;support for cryptographically-signed updates, support for a modern cryptography library&lt;/a&gt;, a Site Health section in the admin panel backend, and a feature that will act as a White-Screen-of-Death (WSOD) protection -- letting site admins access their backend in the case of catastrophic PHP errors. With WordPress being installed on around 33.8 percent of all internet sites, these features are set to put some fears at ease in regards to some attack vectors.&lt;/em&gt; &lt;/p&gt;
&lt;p&gt;Probably the biggest and the most important of today&apos;s new security features is WordPress&apos; offline digital signatures system. Starting with WordPress 5.2, the WordPress team will digitally sign its update packages with the Ed25519 public-key signature system so that a local installation will be able to verify the update package&apos;s authenticity before applying it to a local site.&lt;/p&gt;
&lt;p&gt;Better late than never, Wordpress...&lt;/p&gt;</content:encoded></item><item><title><![CDATA[Hacker Can Monitor Cars And Kill Their Engines]]></title><description><![CDATA[The hacker, who goes by the name L&M, told Motherboard he hacked into more than 7,000 iTrack accounts and more than 20,000 ProTrack accounts, two apps that companies use monitor and manage fleets of vehicles through GPS tracking devices. The hacker was able to track vehicles in a handful of countries around the world, including South Africa, Morocco, India, and the Philippines.]]></description><link>https://www.domingorivera.tech/gatsby-starter-developer-blog/hacker-can-monitor-cars-and-kill-their-engines</link><guid isPermaLink="false">https://www.domingorivera.tech/hacker-can-monitor-cars-and-kill-their-enginesHacker Can Monitor Cars And Kill Their Engines</guid><dc:creator><![CDATA[domingo rivera]]></dc:creator><pubDate>Thu, 25 Apr 2019 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;A hacker broke into thousands of accounts belonging to users of two GPS tracker apps, giving him the ability to monitor the locations of tens of thousands of vehicles and even turn off the engines for some of them while they were in motion, Motherboard has learned. The hacker, who goes by the name L&amp;#x26;M, told Motherboard he hacked into more than 7,000 iTrack accounts and more than 20,000 ProTrack accounts, two apps that companies use monitor and manage fleets of vehicles through GPS tracking devices. The hacker was able to track vehicles in a handful of countries around the world, including South Africa, Morocco, India, and the Philippines. On some cars, the software has the capability of remotely turning off the engines of vehicles that are stopped or are traveling 12 miles per hour or slower, according to the manufacturer of certain GPS tracking devices.&lt;/p&gt;
&lt;p&gt;By reverse engineering ProTrack and iTrack&apos;s Android apps, L&amp;#x26;M said he realized that all customers are given a default password of 123456 when they sign up. At that point, the hacker said he brute-forced &apos;millions of usernames&apos; via the apps&apos; API. Then, he said he wrote a script to attempt to login using those usernames and the default password. This allowed him to automatically break into thousands of accounts that were using the default password and extract data from them.&lt;/p&gt;</content:encoded></item><item><title><![CDATA[CIA Accuses Huawei Of Being Funded By Chinese Intelligence]]></title><description><![CDATA[The accusation comes at a time of trade tensions between Washington and Beijing and amid concerns in the United States that Huawei equipment could be used for espionage. The company has said the concerns are unfounded]]></description><link>https://www.domingorivera.tech/gatsby-starter-developer-blog/cia-accuses-huawei-of-being-funded-by-chinese</link><guid isPermaLink="false">https://www.domingorivera.tech/cia-accuses-huawei-of-being-funded-by-chineseCIA Accuses Huawei Of Being Funded By Chinese Intelligence</guid><dc:creator><![CDATA[domingo rivera]]></dc:creator><pubDate>Sun, 21 Apr 2019 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;U.S. intelligence has accused Huawei Technologies of being funded by Chinese state security, The Times said on Saturday.   The CIA &lt;a href=&quot;https://www.reuters.com/article/us-usa-trade-china-huawei/u-s-intelligence-says-huawei-funded-by-chinese-state-security-report-idUSKCN1RW03D&quot;&gt;accused Huawei of receiving funding from China&apos;s National Security Commission&lt;/a&gt;, the People&apos;s Liberation Army and a third branch of the Chinese state intelligence network, the British newspaper reported, citing a source. Earlier this year, U.S. intelligence shared its claims with other members of the Five Eyes intelligence-sharing group, which includes Britain, Australia, Canada and New Zealand, according to the report...&lt;/p&gt;
&lt;p&gt;The accusation comes at a time of trade tensions between Washington and Beijing and amid concerns in the United States that Huawei&apos;s equipment could be used for espionage. The company has said the concerns are unfounded... top educational institutions in the West have recently severed ties with Huawei to avoid losing federal funding.&lt;/p&gt;</content:encoded></item><item><title><![CDATA[The Boeing 737 Max Disaster Through The Eyes of a Software Developer]]></title><description><![CDATA[So Boeing produced a dynamically unstable airframe, the 737 Max. That is big strike No. 1. Boeing then tried to mask the 737 dynamic instability with a software system. Big strike No. 2. Finally, the software relied on systems known for their propensity to fail angle-of-attack indicators and did not appear to include even rudimentary provisions to cross-check the outputs of the angle-of-attack sensor against other sensors.]]></description><link>https://www.domingorivera.tech/gatsby-starter-developer-blog/the-boeing-737-max-disaster</link><guid isPermaLink="false">https://www.domingorivera.tech/the-boeing-737-max-disasterThe Boeing 737 Max Disaster Through The Eyes of a Software Developer</guid><dc:creator><![CDATA[domingo rivera]]></dc:creator><pubDate>Sun, 21 Apr 2019 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;IEEE&apos;s  Spectrum published the article &quot;How the Boeing 737 Max Disaster Looks to a Software Developer.&quot;  In the article, pilot (and software executive) Gregory Travis argues Boeing tried to avoid costly hardware changes  to their 737s with a flawed software fix -- specifically, the Maneuvering Characteristics Augmentation System (or MCAS): It is astounding that no one who wrote the MCAS software for the 737 Max seems even to have raised the possibility of using multiple inputs, including the opposite angle-of-attack sensor, in the computer&apos;s determination of an impending stall. As a lifetime member of the software development fraternity, I don&apos;t know what &lt;a href=&quot;https://spectrum.ieee.org/aerospace/aviation/how-the-boeing-737-max-disaster-looks-to-a-software-developer&quot;&gt;toxic combination of inexperience, hubris, or lack of cultural understanding&lt;/a&gt; led to this mistake. But I do know that it&apos;s indicative of a much deeper problem. The people who wrote the code for the original MCAS system were obviously terribly far out of their league and did not know it.&lt;/p&gt;
&lt;p&gt;So Boeing produced a dynamically unstable airframe, the 737 Max. That is big strike No. 1. Boeing then tried to mask the 737&apos;s dynamic instability with a software system. Big strike No. 2. Finally, the software relied on systems known for their propensity to fail (angle-of-attack indicators) and did not appear to include even rudimentary provisions to cross-check the outputs of the angle-of-attack sensor against other sensors, or even the other angle-of-attack sensor. Big strike No. 3... None of the above should have passed muster. None of the above should have passed the &quot;OK&quot; pencil of the most junior engineering staff... That&apos;s not a big strike. That&apos;s a political, social, economic, and technical sin...  &lt;/p&gt;
&lt;p&gt;The 737 Max saga teaches us not only about the limits of technology and the risks of complexity, it teaches us about our real priorities. Today, safety doesn&apos;t come first -- money comes first, and safety&apos;s only utility in that regard is in helping to keep the money coming. The problem is getting worse because our devices are increasingly dominated by something that&apos;s all too easy to manipulate: software.... I believe the relative ease -- not to mention the lack of tangible cost -- of software updates has created a cultural laziness within the software engineering community. Moreover, because more and more of the hardware that we create is monitored and controlled by software, that cultural laziness is now creeping into hardware engineering -- like building airliners. Less thought is now given to getting a design correct and simple up front because it&apos;s so easy to fix what you didn&apos;t get right later.&lt;/i&gt;
The article also points out that &quot;not letting the pilot regain control by pulling back on the column was an explicit design decision. Because if the pilots could pull up the nose when MCAS said it should go down, why have MCAS at all?  &lt;/p&gt;
&lt;p&gt;&quot;MCAS is implemented in the flight management computer, even at times when the autopilot is turned off, when the pilots think they are flying the plane.&quot;&lt;/p&gt;</content:encoded></item><item><title><![CDATA[NYC Subway Denies Using Real-Time Face Recognition Screens in Times Square]]></title><description><![CDATA[Young says that the recordings arent being monitored to identify individuals in the footage, though. There is absolutely no facial recognition component to these cameras, no facial recognition software, or anything else that could be used to automatically identify people in any way.]]></description><link>https://www.domingorivera.tech/gatsby-starter-developer-blog/nyc-subway-denies-using-face-recognition</link><guid isPermaLink="false">https://www.domingorivera.tech/nyc-subway-denies-using-face-recognitionNYC Subway Denies Using Real-Time Face Recognition Screens in Times Square</guid><dc:creator><![CDATA[domingo rivera]]></dc:creator><pubDate>Fri, 19 Apr 2019 05:25:44 GMT</pubDate><content:encoded>&lt;p&gt;The New York Metropolitan Transportation Authority has denied suggestions that it&apos;s putting facial recognition cameras in the subway, saying that a trick designed to scare fare-dodgers was misinterpreted. From a report:
&quot;There is no capability to recognize or identify individuals and absolutely no plan&quot; to do so with NYC subway cameras, says MTA spokesperson Maxwell Young. Young was responding to a photo taken in the Times Square subway station by New York Times analyst Alice Fung, which shows a prominently placed monitor with the words &quot;RECORDING IN PROGRESS&quot; and &quot;Please Pay Your Fare&quot; superimposed on a video feed. &quot;Hey @MTA, who are you sharing the recordings with?&quot; Fung asked. The monitor featured the name Wisenet, a security company that prominently advertises facial recognition capabilities, and the video feed traced squares around subjects&apos; faces. &lt;/p&gt;
&lt;p&gt;Young says that the recordings aren&apos;t being monitored to identify individuals in the footage, though. &quot;There is absolutely no facial recognition component to these cameras, no facial recognition software, or anything else that could be used to automatically identify people in any way, and we have no plans to add facial recognition software to these cameras in the future,&quot; he tells The Verge. &quot;These cameras are purely for the purpose of deterring fare evasion -- if you see yourself on a monitor, you&apos;re less likely to evade the fare.&quot;&lt;/p&gt;</content:encoded></item><item><title><![CDATA[FTC May Hold Zuckerberg Personally Responsible For Facebook Privacy Failures]]></title><description><![CDATA[According to NBC, FTC officials are discussing whether and how to hold Facebook Chief Executive Mark Zuckerberg personally accountable for the company's history of mismanaging users private data. However, NBC said its sources wouldn't elaborate on what measures are specifically under consideration.]]></description><link>https://www.domingorivera.tech/gatsby-starter-developer-blog/ftc-may-hold-zuckerberg-responsible</link><guid isPermaLink="false">https://www.domingorivera.tech/ftc-may-hold-zuckerberg-responsibleFTC May Hold Zuckerberg Personally Responsible For Facebook Privacy Failures</guid><dc:creator><![CDATA[domingo rivera]]></dc:creator><pubDate>Thu, 18 Apr 2019 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Federal Trade Commission officials are &lt;a href=&quot;https://arstechnica.com/tech-policy/2019/04/ftc-may-hold-zuckerberg-personally-responsible-for-facebook-privacy-failures/&quot;&gt;discussing whether to hold Facebook CEO Mark Zuckerberg personally accountable for Facebook&apos;s privacy failures&lt;/a&gt;, according to reports by &lt;a href=&quot;https://www.washingtonpost.com/technology/2019/04/19/federal-investigation-facebook-could-hold-mark-zuckerberg-accountable-privacy-sources-say/&quot;&gt;The Washington Post&lt;/a&gt; and &lt;a href=&quot;https://www.nbcnews.com/tech/tech-news/u-s-looking-ways-hold-zuckerberg-accountable-facebook-s-problems-n996231&quot;&gt;NBC News&lt;/a&gt;. Facebook has been trying to protect Zuckerberg from that possibility in negotiations with the FTC, the Post wrote. Federal regulators investigating Facebook are &quot;exploring his past statements on privacy and weighing whether to seek new, heightened oversight of his leadership,&quot; the Post reported, citing anonymous sources who are familiar with the FTC discussions. &quot;The discussions about how to hold Zuckerberg accountable for Facebook&apos;s data lapses have come in the context of wide-ranging talks between the Federal Trade Commission and Facebook that could settle the government&apos;s more than year-old probe,&quot; the Post wrote. &lt;/p&gt;
&lt;p&gt;According to NBC, FTC officials are &quot;discussing whether and how to hold Facebook Chief Executive Mark Zuckerberg personally accountable for the company&apos;s history of mismanaging users&apos; private data.&quot; However, NBC said its sources &quot;wouldn&apos;t elaborate on what measures are specifically under consideration.&quot; According to the Post, one idea raised during the probe &quot;could require [Zuckerberg] or other executives to certify the company&apos;s privacy practices periodically to the board of directors.&quot; But it&apos;s not clear how likely the FTC is to target Zuckerberg in a final settlement, and &quot;Facebook has fought fiercely to shield Zuckerberg as part of the negotiations, one of the sources familiar with the probe said,&quot; the Post wrote.&lt;/p&gt;</content:encoded></item><item><title><![CDATA[Facebook Groups Reselling Fraud Services]]></title><description><![CDATA[The now-removed groups had more than 385,000 members in total and offered a variety of illegal services, from credit card information and identity theft to website hacking and email phishing, according to cybersecurity researchers at Talos, the threat intelligence division for the technology company Cisco.]]></description><link>https://www.domingorivera.tech/gatsby-starter-developer-blog/facebook-groups-reselling-fraud-services</link><guid isPermaLink="false">https://www.domingorivera.tech/facebook-groups-reselling-fraud-servicesFacebook Groups Reselling Fraud Services</guid><dc:creator><![CDATA[domingo rivera]]></dc:creator><pubDate>Fri, 05 Apr 2019 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Facebook connects old friends almost as well as it apparently connects cyber criminals.  According to researchers,  black markets are only a few keystrokes away in Facebook.  &lt;/p&gt;
&lt;p&gt;According to NBC News, researchers &lt;a href=&quot;https://www.nbcnews.com/tech/social-media/facebook-s-black-markets-just-keystrokes-away-researchers-say-n991121&quot;&gt;uncovered more than 70 Facebook groups openly selling black-market cyber fraud services,&lt;/a&gt; some of which they say had been running for up to eight years.  The now-removed groups had more than 385,000 members in total and offered a variety of illegal services, from credit card information and identity theft to website hacking and email phishing, according to cybersecurity researchers at Talos, the threat intelligence division for the technology company Cisco. &lt;/p&gt;
&lt;p&gt;By conducting searches for well-known fraud terms, the researchers exposed a sizable online black market hiding in plain sight on the world&apos;s most popular social media site. &quot;Selling CVV fresh $5&quot; read one post for stolen credit card numbers. &quot;100k mail list fresh&quot; touted another from the &quot;Professional Spammers and Hackers&quot; page. &lt;/p&gt;
&lt;p&gt;As has become customary, Facebook apologized for another instance of fraudulent activity involving it&apos;s network. &quot;These Groups violated our policies against spam and financial fraud and we removed them,&quot; a Facebook spokesperson said in an emailed statement. &quot;We know we need to be more vigilant and we&apos;re investing heavily to fight this type of activity.&quot;&lt;/p&gt;</content:encoded></item><item><title><![CDATA[Judge Orders Fairfax Police To Stop Collecting Data From License Plate Readers]]></title><description><![CDATA[The ruling followed a related finding by the Virginia Supreme Court last year, meaning the case could affect how long Virginia police can keep license plate data. The ruling by Fairfax Circuit Court Judge Robert J. Smith is a victory for privacy rights advocates who argued that the police could track a person's movements by compiling the times and exact locations of a car anytime its plate was captured by a license plate reader]]></description><link>https://www.domingorivera.tech/gatsby-starter-developer-blog/judge-orders-fairfax-police-to-stop-collecting-data-from-license-plate-readers</link><guid isPermaLink="false">https://www.domingorivera.tech/judge-orders-fairfax-police-to-stop-collecting-data-from-license-plate-readersJudge Orders Fairfax Police To Stop Collecting Data From License Plate Readers</guid><dc:creator><![CDATA[domingo rivera]]></dc:creator><pubDate>Wed, 03 Apr 2019 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;A Fairfax County judge on Monday ordered the Fairfax County police to stop maintaining a &lt;a href=&quot;https://www.washingtonpost.com/crime-law/2019/04/02/judge-orders-fairfax-police-stop-collecting-data-license-plate-readers/?utm_term=.c21dbebee346&quot;&gt;database of photos of vehicle license plates&lt;/a&gt;, with the time and location where they were snapped, ruling that &quot;passive use&quot; of data from automated license plate readers on the back of patrol cars violates Virginia privacy law. &lt;/p&gt;
&lt;p&gt;The ruling followed a related finding by the Virginia Supreme Court last year, meaning the case could affect how long -- if at all -- Virginia police can keep license plate data. The ruling by Fairfax Circuit Court Judge Robert J. Smith is a victory for privacy rights advocates who argued that the police could track a person&apos;s movements by compiling the times and exact locations of a car anytime its plate was captured by a license plate reader. Fairfax County Police Chief Edwin C. Roessler Jr. said Monday night that he would ask the county attorney to appeal the ruling. &lt;/p&gt;
&lt;p&gt;The issue represents another front in the ongoing conflict over the use of emerging technologies by law enforcement. Police say they can, and have, used license plate location data to find dangerous criminals and missing persons. Privacy advocates don&apos;t oppose the use of the technology during an active investigation, but they say that maintaining a database of license plate locations for months or years provides too much opportunity for abuse by the police. Last month, the ACLU disclosed that the federal Immigration and Customs Enforcement agency was tapping into a vast, national database of police and private license plate readers. Such private databases remain unregulated.&lt;/p&gt;</content:encoded></item><item><title><![CDATA[United States v. Favio Gasperini: The Click-fraud Botnet Case]]></title><description><![CDATA[The court rejected the challenge to the authentication of Internet Archive screenshots of websites registered to defendant for use in the click fraud scheme.]]></description><link>https://www.domingorivera.tech/gatsby-starter-developer-blog/united-states-v-favio-gasperini-the-click-fraud-botnet-case</link><guid isPermaLink="false">https://www.domingorivera.tech/united-states-v-favio-gasperini-the-click-fraud-botnet-caseUnited States v. Favio Gasperini: The Click-fraud Botnet Case</guid><dc:creator><![CDATA[domingo rivera]]></dc:creator><pubDate>Wed, 03 Apr 2019 00:00:00 GMT</pubDate><content:encoded>&lt;h2&gt;In this case, The court rejected defendant’s challenge to the authentication of screenshots of websites registered to defendant for use in the click fraud scheme, which were captured and stored by the Internet Archive, and maintained as business records of that entity. - Domingo J. Rivera&lt;/h2&gt;
&lt;p&gt;894 F.3d 482&lt;/p&gt;
&lt;p&gt;MUNITED STATES of America, Appellee, v. Fabio GASPERINI, Defendant-Appellant.&lt;/p&gt;
&lt;p&gt;Docket No. 17-2479-cr&lt;/p&gt;
&lt;p&gt;United States Court of Appeals, Second Circuit.&lt;/p&gt;
&lt;p&gt;Decided: July 2, 2018&lt;/p&gt;
&lt;p&gt;ORDER&lt;/p&gt;
&lt;p&gt;Fabio Gasperini was convicted by a jury in the United States District Court for the Eastern District of New York (Nicholas G. Garaufis, Judge ) of one count of misdemeanor computer intrusion in violation of 18 U.S.C. § 1030(a)(2)(C), a provision of the Computer Fraud and Abuse Act of 1986 (“CFAA”). Gasperini raises several challenges to his conviction. First, he contends that the statute that he was convicted of violating is unconstitutionally vague. Second, he asserts that the district court erroneously denied his motion to suppress evidence that was allegedly collected in violation of the Stored Communications Act. Third, he contends that the district court abused its discretion in allowing the government to introduce into evidence screenshots from the Internet Archive (also known as the “Wayback Machine”). Gasperini makes several other arguments, which are addressed in an accompanying summary order. Because we are not persuaded by any of Gasperini’s arguments, we AFFIRM the judgment of the district court.&lt;/p&gt;
&lt;p&gt;BACKGROUND&lt;/p&gt;
&lt;p&gt;The evidence discussed below is taken from the trial record. Insofar as it relates to the offense of conviction, the evidence is viewed in the light most favorable to the government, and we draw all reasonable inferences in its favor. United States v. Guadagna , 183 F.3d 122, 125 (2d Cir. 1999). As it relates to the sentencing issues discussed in the accompanying summary order, “we review the District Court’s factual findings relevant to a sentencing determination for clear error.” United States v. Johnson , 378 F.3d 230, 238 (2d Cir. 2004). In order to vacate such findings, “we must view the evidence in the light most favorable to the government and nevertheless find to be impermissible the factual determinations based upon that favorably-viewed evidence.” Id. In 2014, a virus began infecting QNAP-brand devices.1 Computer security experts who detected the virus determined that the attacker behind the virus was attempting to covertly infiltrate computers. The attacker targeted QNAP computers, which do not log external internet connections, and used an often-overlooked port to access the computers. The virus installed malware, which included several commands for the computer to execute, in hidden directories on the infected computers. Once a computer was infected, the attacker installed a “backdoor” account, which had the status of a “superprivileged user,” with unrestricted access to and control over the computer’s data. After creating the backdoor account, the attacker patched the initial vulnerability that had allowed him access, thereby locking out other hackers. The infected computer was then instructed to scan the internet for other computers with the same vulnerability and infect them. In this way, the attacker created what is known as a “botnet”—a network of infected computers under the attacker’s control. An analysis of one of the servers used in the scheme revealed that more than 155,000 computers were infected worldwide. Many of those computers were located in the United States. The virus’s commands accomplished different tasks. One command was designed to take certain username and password files from the infected computers and copy them onto a server. Another caused the infected computer to disguise itself as a human browsing the internet, and to click on certain banner advertisements. Yet another command prompted the botnet to launch coordinated attacks on certain websites, a practice known as distributed denial-of-service attacks.&lt;/p&gt;
&lt;p&gt;United States investigators identified Gasperini, an Italian citizen, as the creator of the virus and perpetrator of the various attacks because he leased and operated several servers around the world that were used to host the malware and communicate with the infected computers. A search of Gasperini’s email account also found a “test” copy of the computer virus that was initially used to infect QNAP computers, and emails from Gasperini expressly referencing several of the scripts installed on the infected computers. Evidence later adduced at trial also linked Gasperini to a related “click fraud” scheme, in which the botnet computers were commanded to click on certain advertisements. Business records showed that several websites implicated in the scheme were registered in Gasperini’s name. Additionally, Gasperini contracted with an Italian advertising company to earn money for each advertisement viewed on these websites. Finally, evidence at trial tended to show that Gasperini monitored the operation. This included emails from his servers reporting “clicks completed” and a photograph of his home computer commanding his botnet to click on an advertising banners. After his arrest in the Netherlands, Gasperini deleted the contents of his Google account, deactivated his Facebook account, and instructed someone to discard the hard drives in his home and erase others.&lt;/p&gt;
&lt;p&gt;A grand jury charged Gasperini with felony crimes of computer intrusion with intent to defraud, for financial gain, and in furtherance of criminal acts; wire fraud conspiracy; wire fraud; and money laundering. After a seven-day jury trial, he was acquitted of all felony charges, and was convicted only of misdemeanor computer intrusion in violation of 18 U.S.C. § 1030(a)(2)(C), a lesser-included crime within one of the computer intrusion felonies charged in the indictment.2 At sentencing, the trial judge found that the government had proven, by a preponderance of the evidence, that Gasperini had committed the felony offenses with which he was charged. Accordingly, those crimes were considered as relevant conduct in calculating the applicable Guidelines range, resulting in a range of 63 to 78 months’ incarceration, which was capped by the statutory maximum of imprisonment for one year. The district court sentenced Gasperini principally to that statutory maximum. He now appeals from that conviction.3&lt;/p&gt;
&lt;p&gt;DISCUSSION&lt;/p&gt;
&lt;p&gt;I. Vagueness The statute under which Gasperini stands convicted punishes anyone who “intentionally accesses a computer without authorization … and thereby obtains … information from any protected computer.” 18 U.S.C. § 1030(a)(2)(C). Gasperini argues that the statute is unconstitutionally vague because it does not define the terms “access,” “authorization,” and “information,” and because the definition of “protected computer” in § 1030(e)(2) is overbroad. [894 F.3d 487] Because Gasperini did not raise this challenge below, we review it for plain error. United States v. Boyland , 862 F.3d 279, 288 (2d Cir. 2017), cert. denied , ––– U.S. ––––, 138 S.Ct. 938, 200 L.Ed.2d 212 (2018). When reviewing for plain error under Federal Rule of Criminal Procedure 52(b), an appellate court has discretion to correct an error not raised at trial only where the appellant demonstrates that “(1) there is an error; (2) the error is clear or obvious …; (3) the error affected the appellant’s substantial rights …; and (4) the error seriously affects the fairness, integrity[,] or public reputation of judicial proceedings.” United States v. Marcus , 560 U.S. 258, 262, 130 S.Ct. 2159, 176 L.Ed.2d 1012 (2010) (internal quotation marks and brackets omitted). Gasperini cannot clear the hurdle set by the second of these requirements. “At a minimum, a court of appeals cannot correct an error pursuant to Rule 52(b) unless the error is clear under current law.” United States v. Olano , 507 U.S. 725, 734, 113 S.Ct. 1770, 123 L.Ed.2d 508 (1993) ; see also Rosales-Mireles v. United States , ––– U.S. ––––, 138 S.Ct. 1897, ––– L.Ed.2d –––– (2018). Gasperini cites no authority from any court—let alone one whose decisions are binding on us—holding, or even suggesting, that § 1030(a)(2)(C) is unconstitutionally vague. Accordingly, we cannot conclude that the district court plainly erred by not sua sponte dismissing the indictment on that ground. In any event, Gasperini has not identified a due process violation here. “A conviction fails to comport with due process if the statute under which it is obtained fails to provide a person of ordinary intelligence fair notice of what is prohibited, or is so standardless that it authorizes or encourages seriously discriminatory enforcement.” United States v. Williams , 553 U.S. 285, 304, 128 S.Ct. 1830, 170 L.Ed.2d 650 (2008). We apply this standard in the context of the facts at issue, because, outside of the First Amendment context, an individual “who engages in some conduct that is clearly proscribed cannot complain of the vagueness of the law as applied to the conduct of others.” Id . Even if we assume, arguendo , that the statute’s application may be unclear in some marginal cases (including some fanciful possibilities conjured in Gasperini’s appellate brief), Gasperini’s conduct falls squarely and unambiguously within the core prohibition of the statute. “Congress enacted the CFAA in 1984 to address ‘computer crime,’ which was then principally understood as ‘hacking’ or trespassing into computer systems or data.” United States v. Valle , 807 F.3d 508, 525 (2d Cir. 2015), citing H.R. Rep. No. 98-894, at 3691–92, 3695–97 (1984), and S. Rep. No. 99-432, at 2480 (1986). In this case, Gasperini was found by the jury to have hacked into thousands of computers without permission, thereby gaining access to all of the information stored on those computers. The jury further found Gasperini guilty of taking information, including usernames and passwords, from at least some of those computers. There is thus no doubt that all of these actions fall within the core meaning of the phrase “accesses a computer without authorization … and thereby obtains … information from [a] protected computer” as the italicized terms are used in § 1030(a)(2)(C).4 Accordingly, [894 F.3d 488]&lt;/p&gt;
&lt;p&gt;Gasperini’s challenge to the constitutionality of 18 U.S.C. § 1030(a)(2)(C) fails.&lt;/p&gt;
&lt;p&gt;II. Suppression&lt;/p&gt;
&lt;p&gt;Gasperini next argues that the district court should have suppressed certain evidence introduced by the government at trial, including (1) evidence obtained pursuant to search warrants issued under the Stored Communications Act (“SCA”), 18 U.S.C. § 2701 et seq ., and (2) evidence obtained during searches of his home in Italy by Italian law enforcement officers pursuant to warrants issued by Italian courts. The district court did not err with respect to either category of evidence. Gasperini first argues that the SCA warrants were extraterritorial warrants not authorized by that Act. He relies on this Court’s decision in Matter of Warrant to Search a Certain E-Mail Account Controlled and Maintained by Microsoft Corp. , 829 F.3d 197 (2d Cir. 2016), vacated as moot sub nom. United States v. Microsoft Corp. , ––– U.S. ––––, 138 S.Ct. 1186, 200 L.Ed.2d 610 (2018), in which we held that the SCA does not apply extraterritorially, and does not authorize the seizure of electronic communications stored on servers located outside of the United States. Id. at 222.5 Even assuming that at least some of the warrants demanded and acquired electronic communications stored abroad,6 and that our ruling in Microsoft —which was vacated as moot by the Supreme Court—correctly states the law, suppression still would not be required, because suppression of evidence is not a remedy available for violation of the SCA. Congress provided a number of specific remedies for such violations; these do not include suppression of evidence in a criminal case. See 18 U.S.C. § 2707(b) (listing “appropriate relief” in a “civil action” as “equitable or declaratory relief,” “damages,” and “a reasonable attorney’s fee and other litigation costs reasonably incurred”); [894 F.3d 489]&lt;/p&gt;
&lt;p&gt;18 U.S.C. § 2707(d) (providing for “disciplinary action against the officer or employee” who violated the Act). Moreover, Congress expressly provided that the listed remedies are exclusive , stating in § 2708 that the “remedies and sanctions described in this chapter are the only judicial remedies and sanctions for nonconstitutional violations of this chapter.” (Emphasis added).7 Gasperini does not request any form of relief authorized under the SCA, nor does he argue that any of the purported statutory violations he identifies also violate the Constitution, and we find no basis for any such argument. Accordingly, the district court did not err in denying Gasperini’s motion to suppress the evidence collected pursuant to the SCA warrants.&lt;/p&gt;
&lt;p&gt;Gasperini’s challenge to the use of hard drives and documents obtained from Italian law enforcement officials who searched his home fares no better. The searches were conducted pursuant to an Italian warrant, and Gasperini makes no claim that the warrant was issued in violation of Italian law. He argues instead that the Italian officials acted at the behest of American law enforcement agents, thus making them subject to American constitutional requirements for searches. “In order to render foreign law enforcement officials virtual agents of the United States, American officials must play some role in controlling or directing the conduct of the foreign parallel investigation.” United States v. Getto , 729 F.3d 221, 230 (2d Cir. 2013). Beyond alleging that the search was conducted at the request of the U.S. government, however, Gasperini does not argue that Italian officials were controlled by American law enforcement agents. A mere request is not sufficient to show control. See, e.g., id . (“It is not enough that the foreign government undertook its investigation pursuant to an American [Mutual Law Enforcement Assistance Treaty] request.“) There is thus no basis for Gasperini’s efforts to apply to the Italian searches the constitutional standards that would apply to domestic searches conducted by United States officers.&lt;/p&gt;
&lt;p&gt;III. The Wayback Machine&lt;/p&gt;
&lt;p&gt;Finally, Gasperini challenges an evidentiary ruling made by the district court permitting the government to introduce screenshots of various websites taken by the Internet Archive, more commonly known as the “Wayback Machine.” “A district court judge is in the best position to evaluate the admissibility of offered evidence. For that reason, we will overturn a district court’s ruling on admissibility only if there is a clear showing that the court abused its discretion or acted arbitrarily or irrationally.” United States v. Valdez , 16 F.3d 1324, 1332 (2d Cir. 1994) (internal citation omitted). We detect no such abuse of discretion here. Gasperini challenges the authentication of screenshots of websites registered to Gasperini for use in the click fraud scheme, which were captured and stored by the Internet Archive, and maintained as business records of that entity. Federal Rule of Evidence 901(a) requires that before evidence is admitted, “the proponent must produce evidence sufficient to support a finding that the item is what the proponent claims it is.” That standard was amply met here. [894 F.3d 490]&lt;/p&gt;
&lt;p&gt;Gasperini relies on Novak v. Tucows, Inc. , 330 F.App’x 204 (2d Cir. 2009), in which we affirmed a district court decision excluding screenshots from the Archive for lack of authentication. In that non-precedential summary order, however, we held only that the district court did not abuse its discretion in excluding the evidence in a civil trial, where the proponent of the evidence offered no testimony explaining its provenance. Id. at 206, aff’g Novak v. Tucows, Inc. , No. 06-CV-1909, 2007 WL 922306 (E.D.N.Y. Mar. 26, 2007). Here, in contrast, the government presented testimony from the office manager of the Internet Archive, who explained how the Archive captures and preserves evidence of the contents of the internet at a given time. The witness also compared the screenshots sought to be admitted with true and accurate copies of the same websites maintained in the Internet Archive, and testified that the screenshots were authentic and accurate copies of the Archive’s records. Based on this testimony, the district court found that the screenshots had been sufficiently authenticated. The Third Circuit considered the admissibility of Internet Archive records on a similar record in United States v. Bansal , 663 F.3d 634, 667–68 (3d Cir. 2011). In that case, the court found that where a witness testified, from personal knowledge, “about how the Wayback Machine website works and how reliable its contents are,” there was sufficient evidence to authenticate screenshots taken from that website. Id. at 667. We agree with the holding of the court in Bansal , and hold that the testimony presented in this case by the government was “sufficient proof … that a reasonable juror could find in favor of authenticity or identification.” United States v. Tin Yat Chin , 371 F.3d 31, 38 (2d Cir. 2004). Gasperini was free to cross-examine the witness about the nature and reliability of the Archive’s procedures for capturing and cataloguing the contents of the internet at particular times, and the jury was thus enabled to make its own decision about the weight, if any, to be given to the records. Accordingly, a sufficient basis was laid to place the admission of the evidence well within the discretion of the district court, and Gasperini’s challenge therefore fails.&lt;/p&gt;
&lt;p&gt;CONCLUSION&lt;/p&gt;
&lt;p&gt;For the foregoing reasons, and those set forth in the accompanying summary order, we AFFIRM the judgment of the district court.&lt;/p&gt;
&lt;p&gt;Notes: 1 QNAP Incorporated is a company headquartered in Taiwan, with offices and warehouses in California, that manufactures and sells “network attached storages,” which are computers specifically designed for the storage of data. 2 The misdemeanor offense lacks the aggravating purpose element of the felony charged in the indictment. See 18 U.S.C. § 1030(c)(2) (establishing escalating penalties for violations of § 1030(a)(2) under various circumstances). 3 Gasperini has served his sentence and has been deported to Italy. 4 Gasperini’s questioning of the definition of “protected computer” is also meritless. The definition describes a wide range of computers, including ones “used in or affecting interstate or foreign commerce or communication.” 18 U.S.C. § 1030(e)(2)(B). That standard, a familiar limitation on the reach of any number of federal criminal statutes, has never been found void for vagueness. 5 As we explained in Microsoft , SCA “warrants,” although issued only when the constitutional standards governing conventional search warrants are met, do not authorize agents to enter premises and search for evidence, but rather are served on a third-party holder of electronic communications and demand that the third party turn over the information called for in the warrant. See 829 F.3d at 214 (describing the operation of SCA warrants). In that respect, SCA warrants function analogously to subpoenas. See id . at 226–29 (Lynch, J ., concurring in the judgment). 6 Gasperini asserts that because he lived in Italy, it is “obvious” that his emails and Google Drive files were stored in Google’s foreign servers. Appellant’s Br. at 36. That assertion is far from obvious, however. Prior to our decision in Microsoft , Google appears to have stored user data at locations that bore no relation to the location of the user. See, e.g. , In re Search of Content that is Stored at Premises Controlled By Google , No. 16-MC-80263-LB, 2017 WL 1398279, at *4 (N.D. Cal. Apr. 19, 2017) (“Unlike Microsoft , where storage of information was tethered to a user’s reported location, there is no storage decision here. The process of distributing information is automatic, via an algorithm, and in aid of network efficiency”) (internal citation omitted) (amended and superseded on other grounds by In re Search of Content that is Stored at Premises Controlled by Google, No. 16-MC-80263-LB, 2017 WL 1487625, at *1 (N.D. Cal. Apr. 25, 2017) ); In re Search Warrant No. 16-960-M-01 to Google , 232 F.Supp.3d 708, 712 (E.D. Pa. 2017) (“Google stores user data in various locations, some of which are in the United States and some of which are in countries outside the United States. Some user files may be broken into component parts, and different parts of a single file may be stored in different locations (and, accordingly, different countries) at the same time.“) (internal citations omitted). Gasperini musters no evidence to support his conclusory assertion that in his case, the emails and files obtained from Google had, in fact, been stored abroad. 7 Our reading of the SCA as not requiring or authorizing suppression of evidence for nonconstitutional violations of its provisions is consistent the rulings of our sister circuits that have considered the issue. See , e.g., United States v. Clenney , 631 F.3d 658, 667 (4th Cir. 2011) ; United States v. Guerrero , 768 F.3d 351, 358 (5th Cir. 2014) ; United States v. Smith , 155 F.3d 1051, 1056 (9th Cir. 1998) ; United States v. Perrine , 518 F.3d 1196, 1202 (10th Cir. 2008) ; United States v. Steiger , 318 F.3d 1039, 1049 (11th Cir. 2003).&lt;/p&gt;</content:encoded></item></channel></rss>