By now, you’ve probably read or heard about Wired staff writer Mat Honan’s journey through digital hell, in which hackers social-engineered Apple into giving them the keys to his digital life, allowing them to scrub his laptop, iPhone and iPad, hijack his and Gizmodo’s Twitter accounts and delete eight-years-worth of email from his Gmail account.
Honan admits to making a number of mistakes — such as failing to enable two-factor authentication and not backing up his data — that allowed the hack to escalate to the point from which there was no return.
In the hope of preventing you from experiencing a similar fate, we’ve listed a number of steps you can take to protect your data and your identity online. While nothing is foolproof — if hackers install a keystroke logging Trojan horse on your computer, all bets are off — these steps will help protect you from the tactics that Honan’s hackers used, and other ones out there.
1. Use Two-Factor Authentication with Gmail and Other Accounts
Gmail and other services offer two-factor authentication that help secure your account even if your password is stolen or cracked.
When you set up two-factor authentication, you get verification codes delivered to your phone, which you then enter, in addition to your username and password, when you sign into Gmail. Google also offers an application you can download to your phone to generate the codes locally. See the video above for an explanation.
Amazon web services and Rackspace cloud service, and other sites and services have adopted Google’s two-factor authentication as an option (there’s even a WordPress plug-in), allowing you to use a Google application on your smartphone to generate verification codes to access your accounts with their services as well.
While two-factor and the associated application-specific passwords can be a minor hassle, they mean that even if a hacker gets your password, they’ll have another layer to break through. If you find it annoying to enter the secure code every time you use your computer, you can choose to have Google remember your computer for 30 days or forever, but this means you have to be very sure your computer won’t fall into the wrong hands.
2. Use SSL or a VPN with Public Wifi
When logging into accounts from public WiFis, make sure to use SSL login pages (https). The Electronic Frontier Foundation’s HTTPS Everywhere tool can helpfully do this for you. Even better, use a virtual private network (VPN) to protect your data so that your login credentials can’t be sniffed by someone on the network. Basic VPN costs start at $5 a month, and for light usage on a Mac try TunnelBear.
3. Use Unique Passwords
Don’t use the same password for multiple accounts. Pick unique passwords for personal e-mail, work e-mail, banking, social networking sites and shopping. If one site gets hacked and your username and password are exposed – as occurred in multiple hacks over the past year – hackers will attempt to use the exposed password with multiple accounts you might have. Don’t help them do one-stop shopping for all your credentials.
4. Use Complex Passwords for Important Accounts
Honan’s accounts weren’t hacked due to weak passwords – so consider strong passwords to be only one part of good online security habits. But nonetheless, we’ve said it before – and so has everyone else – passwords should be longer than eight characters and include letters, numbers and characters – Pn3L!x8@H. And yet, every time another major hack exposes passwords, the top passwords used turn out to be “password” and “abc1234.”
With so many tools available these days to help you generate solid passwords and remember them, there’s no excuse to use poor password hygiene. Wired staff use both LastPass and 1Password. And the old paper-in-wallet trick, loved by security expert Bruce Schneier, works as well. Unique passphrases are also handy – EveryFineBoyDoesGood — but should be used with other characters to avoid easy cracking — Every!Fine@Boy%Does8Good.
Ideally, this kind of complexity isn’t necessary for websites as long as you don’t use a dumb password (e.g., your anniversary, birthdate, “password” or “1234″) that is easily guessed, since sites should be set up to lock out a user after multiple password tries to prevent password crackers from bruteforcing a password. But, since we know that websites don’t always do what they should do, be warned.
5. Don’t Link Accounts
The hackers who hijacked Honan’s Twitter account, were also able to take control of Gizmodo’s Twitter account because Honan, who used to work for Gizmodo, had linked the two accounts so that he could automatically sign into Gizmodo’s account with his personal Twitter account credentials. Keep log-ins separate for different accounts.
6. Get Creative With Security Questions
Skip the standard security questions like “What’s your mother’s maiden name?” or “Where did you go to high school?” since that kind of information is easy to glean about you with a simple Google search (Hello, Sarah Palin!). Or you can answer those common questions in creative, unexpected ways by swapping answers to various questions. “What was the model of your first car?” How about using your first girlfriend’s name for the answer instead, and the name of your first car for your girlfriend’s name? Or simply add characters to the name of the car – Ch!evy Ca27maro.
Feel free to create unique answers for each site that requires a security question and keep them stored in your password manager.
7. Back Up Your System
Honan’s pain was increased tenfold when he discovered the hackers had erased all of the photos from his daughter’s first year of life. Storage is so cheap these days and automated backups are so easy to set up that there’s no excuse not to keep copies of your important data.
8. Encrypt and Password-Protect Devices
To prevent someone from accessing your data and the password storage tool you have on your devices, encrypt the data on your devices and password-protect them.
9. Use Single-Use Credit Cards
One of the ways the hackers got access to Honan’s Apple data was by providing the last four digits of a credit card number he had used at Amazon. Apple had the same card number on file for him. Aside from the fact that Apple should never use the last four digits of a credit card number to authenticate users in the first place, Honan might have protected himself by using a single-use, or disposable, credit card number for his online shopping at Amazon, thus reducing the number of services that stored his real credit card number. Citibank, Bank of America and Discover all offer disposable card numbers that are tied to your real card number, but prevent that number from being exposed if a site is hacked.
Always use a credit card, rather than your debit card, when shopping online. While you can get reimbursement for fraud on either card, there’s no buffer between you and the money linked to your debit card, allowing hackers to drain accounts that are linked to it. With a credit card, you can dispute the charge before you pay it.
Today, I came across a story where a writer, Mat Honan, lost all his lifetime’s digital files, thanks to a hacking. Someone hacked his google account, got hold of Twitter and Gmail accounts. Even though the hacking appears merely for the purpose of trolling his Twitter followers, it could have been much worse if it had led into his banking systems or to some of his contacts as a journalist. Maybe this incident shows that cloud services that are being pressed upon users need different security measures -- a password system doesn’t cut it anymore. Read the account of Honan here and see what best you can do to save yourself from being hacked: In the space of one hour, my entire digital life was destroyed. First my Google account was taken over, then deleted. Next my Twitter account was compromised, and used as a platform to broadcast racist and homophobic messages. And worst of all, my AppleID account was broken into, and my hackers used it to remotely erase all of the data on my iPhone, iPad, and MacBook. In many ways, this was all my fault. My accounts were daisy-chained together. Getting into Amazon let my hackers get into my Apple ID account, which helped them get into Gmail, which gave them access to Twitter. Had I used two-factor authentication for my Google account, it’s possible that none of this would have happened, because their ultimate goal was always to take over my Twitter account and wreak havoc.
Had I been regularly backing up the data on my MacBook, I wouldn’t have had to worry about losing more than a year’s worth of photos, covering the entire lifespan of my daughter, or documents and e-mails that I had stored in no other location. Those security lapses are my fault, and I deeply, deeply regret them. But what happened to me exposes vital security flaws in several customer service systems, most notably Apple’s and Amazon’s. Apple tech support gave the hackers access to my iCloud account. Amazon tech support gave them the ability to see a piece of information — a partial credit card number — that Apple used to release information. In short, the very four digits that Amazon considers unimportant enough to display in the clear on the web are precisely the same ones that Apple considers secure enough to perform identity verification. The disconnect exposes flaws in data management policies endemic to the entire technology industry, and points to a looming nightmare as we enter the era of cloud computing and connected devices.
This isn’t just my problem. Since Friday, Aug. 3, when hackers broke into my accounts, I’ve heard from other users who were compromised in the same way, at least one of whom was targeted by the same group. The very four digits that Amazon considers unimportant enough to display in the clear on the Web are precisely the same ones that Apple considers secure enough to perform identity verification. Moreover, if your computers aren’t already cloud-connected devices, they will be soon. Apple is working hard to get all of its customers to use iCloud. Google’s entire operating system is cloud-based. And Windows 8, the most cloud-centric operating system yet, will hit desktops by the tens of millions in the coming year. My experience leads me to believe that cloud-based systems need fundamentally different security measures. Password-based security mechanisms — which can be cracked, reset, and socially engineered — no longer suffice in the era of cloud computing.
I realized something was wrong at about 5 p.m. on Friday. I was playing with my daughter when my iPhone suddenly powered down. I was expecting a call, so I went to plug it back in. It then rebooted to the setup screen. This was irritating, but I wasn’t concerned. I assumed it was a software glitch. And, my phone automatically backs up every night. I just assumed it would be a pain in the ass, and nothing more. I entered my iCloud login to restore, and it wasn’t accepted. Again, I was irritated, but not alarmed.
I went to connect the iPhone to my computer and restore from that backup — which I had just happened to do the other day. When I opened my laptop, an iCal message popped up telling me that my Gmail account information was wrong. Then the screen went gray, and asked for a four-digit PIN.
I didn’t have a four-digit PIN.
By now, I knew something was very, very wrong. For the first time it occurred to me that I was being hacked. Unsure of exactly what was happening, I unplugged my router and cable modem, turned off the Mac Mini we use as an entertainment center, grabbed my wife’s phone, and called AppleCare, the company’s tech support service, and spoke with a rep for the next hour and a half. It wasn’t the first call they had had that day about my account. In fact, I later found out that a call had been placed just a little more than a half an hour before my own. But the Apple rep didn’t bother to tell me about the first call concerning my account, despite the 90 minutes I spent on the phone with tech support. Nor would Apple tech support ever tell me about the first call voluntarily — it only shared this information after I asked about it. And I only knew about the first call because a hacker told me he had made the call himself.At 4:33 p.m., according to Apple’s tech support records, someone called AppleCare claiming to be me. Apple says the caller reported that he couldn’t get into his .Me e-mail — which, of course was my .Me e-mail. In response, Apple issued a temporary password. It did this despite the caller’s inability to answer security questions I had set up. And it did this after the hacker supplied only two pieces of information that anyone with an internet connection and a phone can discover. At 4:50 p.m., a password reset confirmation arrived in my inbox. I don’t really use my .Me e-mail, and rarely check it. But even if I did, I might not have noticed the message because the hackers immediately sent it to the trash. They then were able to follow the link in that e-mail to permanently reset my AppleID password.
At 4:52 p.m., a Gmail password recovery e-mail arrived in my .Me mailbox. Two minutes later, another e-mail arrived notifying me that my Google account password had changed. At 5:02 p.m., they reset my Twitter password. At 5:00 they used iCloud’s “Find My” tool to remotely wipe my iPhone. At 5:01 they remotely wiped my iPad. At 5:05 they remotely wiped my MacBook. Around this same time, they deleted my Google account. At 5:10, I placed the call to AppleCare. At 5:12 the attackers posted a message to my account on Twitter taking credit for the hack. By wiping my MacBook and deleting my Google account, they now not only had the ability to control my account, but were able to prevent me from regaining access. And crazily, in ways that I don’t and never will understand, those deletions were just collateral damage. My MacBook data — including those irreplaceable pictures of my family, of my child’s first year and relatives who have now passed from this life — weren’t the target. Nor were the eight years of messages in my Gmail account. The target was always Twitter. My MacBook data was torched simply to prevent me from getting back in. I spent an hour and a half talking to AppleCare. One of the reasons it took me so long to get anything resolved with Apple during my initial phone call was because I couldn’t answer the security questions it had on file for me. It turned out there’s a good reason for that. Perhaps an hour or so into the call, the Apple representative on the line said “Mr. Herman, I….” “Wait. What did you call me?”
“Mr. Herman?”
“My name is Honan.”
Apple had been looking at the wrong account all along. Because of that, I couldn’t answer my security questions. And because of that, it asked me an alternate set of questions that it said would let tech support let me into my .Me account: a billing address and the last four digits of my credit card. (Of course, when I gave them those, it was no use, because tech support had misheard my last name.)
It turns out, a billing address and the last four digits of a credit card number are the only two pieces of information anyone needs to get into your iCloud account. Once supplied, Apple will issue a temporary password, and that password grants access to iCloud. Apple tech support confirmed to me twice over the weekend that all you need to access someone’s AppleID is the associated e-mail address, a credit card number, the billing address, and the last four digits of a credit card on file. I was very clear about this. During my second tech support call to AppleCare, the representative confirmed this to me. “That’s really all you have to have to verify something with us,” he said. We talked to Apple directly about its security policy, and company spokesperson Natalie Kerris told Wired, “Apple takes customer privacy seriously and requires multiple forms of verification before resetting an Apple ID password. In this particular case, the customer’s data was compromised by a person who had acquired personal information about the customer. In addition, we found that our own internal policies were not followed completely. We are reviewing all of our processes for resetting account passwords to ensure our customers’ data is protected.”
On Monday, Wired tried to verify the hackers’ access technique by performing it on a different account. We were successful. This means, ultimately, all you need in addition to someone’s e-mail address are those two easily acquired pieces of information: a billing address and the last four digits of a credit card on file. Here’s the story of how the hackers got them. On the night of the hack, I tried to make sense of the ruin that was my digital life. My Google account was nuked, my Twitter account was suspended, my phone was in a useless state of restore, and (for obvious reasons) I was highly paranoid about using my .Me account for communication.
I decided to set up a new Twitter account until my old one could be restored, just to let people know what was happening. I logged into Tumblr and posted an account of how I thought the takedown occurred. At this point, I was assuming that my seven-digit alphanumeric AppleID password had been hacked by brute force. In the comments (and, oh, the comments) others guessed that hackers had used some sort of keystroke logger. At the end of the post, I linked to my new Twitter account.
And then, one of my hackers @ messaged me. He would later identify himself as Phobia. I followed him. He followed me back. We started a dialogue via Twitter direct messaging that later continued via e-mail and AIM. Phobia was able to reveal enough detail about the hack and my compromised accounts that it became clear he was, at the very least, a party to how it went down. I agreed not to press charges, and in return he laid out exactly how the hack worked. But first, he wanted to clear something up: “didnt guess ur password or use bruteforce. i have my own guide on how to secure emails.”I asked him why. Was I targeted specifically? Was this just to get to Gizmodo’s Twitter account? No, Phobia said they hadn’t even been aware that my account was linked to Gizmodo’s, that the Gizmodo linkage was just gravy. He said the hack was simply a grab for my three-character Twitter handle. That’s all they wanted. They just wanted to take it, and fuck shit up, and watch it burn. It wasn’t personal. “I honestly didn’t have any heat towards you before this. i just liked your username like I said before” he told me via Twitter Direct Message. After coming across my account, the hackers did some background research. My Twitter account linked to my personal website, where they found my Gmail address. Guessing that this was also the e-mail address I used for Twitter, Phobia went to Google’s account recovery page. He didn’t even have to actually attempt a recovery. This was just a recon mission. Because I didn’t have Google’s two-factor authentication turned on, when Phobia entered my Gmail address, he could view the alternate e-mail I had set up for account recovery. Google partially obscures that information, starring out many characters, but there were enough characters available, m••••n@me.com. Jackpot. This was how the hack progressed. If I had some other account aside from an Apple e-mail address, or had used two-factor authentication for Gmail, everything would have stopped here. But using the .Me e-mail account as a backup meant told the hacker I had an AppleID account, which meant I was vulnerable to being hacked. “You honestly can get into any email associated with apple,” Phobia claimed in an e-mail. And while it’s work, that seems to be largely true. Since he already had the e-mail, all he needed was my billing address and the last four digits of my credit card number to have Apple’s tech support issue him the keys to my account. So how did he get this vital information? He began with the easy one. He got the billing address by doing a whois search on my personal web domain. If someone doesn’t have a domain, you can also look up his or her information on Spokeo, WhitePages, and PeopleSmart. Getting a credit card number is tricker, but it also relies on taking advantage of a company’s back-end systems. Phobia says that a partner performed this part of the hack, but described the technique to us, which we were able to verify via our own tech support phone calls. It’s remarkably easy — so easy that Wired was able to duplicate the exploit twice in minutes. First you call Amazon and tell them you are the account holder, and want to add a credit card number to the account. All you need is the name on the account, an associated e-mail address, and the billing address. Amazon then allows you to input a new credit card. (Wired used a bogus credit card number from a website that generates fake card numbers that conform with the industry’s published self-check algorithm.) Then you hang up.
Next you call back, and tell Amazon that you’ve lost access to your account. Upon providing a name, billing address, and the new credit card number you gave the company on the prior call, Amazon will allow you to add a new e-mail address to the account. From here, you go to the Amazon website, and send a password reset to the new e-mail account. This allows you to see all the credit cards on file for the account — not the complete numbers, just the last four digits. But, as we know, Apple only needs those last four digits. We asked Amazon to comment on its security policy, but didn’t have anything to share by press time.
And it’s also worth noting that one wouldn’t have to call Amazon to pull this off. Your pizza guy could do the same thing, for example. If you have an AppleID, every time you call Pizza Hut, you’ve giving the 16-year-old on the other end of the line all he needs to take over your entire digital life.
And so, with my name, address, and the last four digits of my credit card number in hand, Phobia called AppleCare, and my digital life was laid waste. Yet still I was actually quite fortunate. They could have used my e-mail accounts to gain access to my online banking, or financial services. They could have used them to contact other people, and socially engineer them as well. As Ed Bott pointed out on TWiT.tv, my years as a technology journalist have put some very influential people in my address book. They could have been victimized too. Instead, the hackers just wanted to embarrass me, have some fun at my expense, and enrage my followers on Twitter by trolling. I had done some pretty stupid things. Things you shouldn’t do.
I should have been regularly backing up my MacBook. Because I wasn’t doing that, if all the photos from the first year and a half of my daughter’s life are ultimately lost, I will have only myself to blame. I shouldn’t have daisy-chained two such vital accounts — my Google and my iCloud account — together. I shouldn’t have used the same e-mail prefix across multiple accounts — mhonan@gmail.com, mhonan@me.com, and mhonan@wired.com. And I should have had a recovery address that’s only used for recovery without being tied to core services. But, mostly, I shouldn’t have used Find My Mac. Find My iPhone has been a brilliant Apple service. If you lose your iPhone, or have it stolen, the service lets you see where it is on a map. The New York Times’ David Pogue recovered his lost iPhone just last week thanks to the service. And so, when Apple introduced Find My Mac in the update to its Lion operating system last year, I added that to my iCloud options too. After all, as a reporter, often on the go, my laptop is my most important tool. But as a friend pointed out to me, while that service makes sense for phones (which are quite likely to be lost) it makes less sense for computers. You are almost certainly more likely to have your computer accessed remotely than physically. And even worse is the way Find My Mac is implemented.
When you perform a remote hard drive wipe on Find my Mac, the system asks you to create a four-digit PIN so that the process can be reversed. But here’s the thing: If someone else performs that wipe — someone who gained access to your iCloud account through malicious means — there’s no way for you to enter that PIN. A better way to have this set up would be to require a second method of authentication when Find My Mac is initially set up. If this were the case, someone who was able to get into an iCloud account wouldn’t be able to remotely wipe devices with malicious intent. It would also mean that you could potentially have a way to stop a remote wipe in progress. But that’s not how it works. And Apple would not comment as to whether stronger authentification is being considered.
As of Monday, both of these exploits used by the hackers were still functioning. Wired was able to duplicate them. Apple says its internal tech support processes weren’t followed, and this is how my account was compromised. However, this contradicts what AppleCare told me twice that weekend. If that is, in fact, the case — that I was the victim of Apple not following its own internal processes — then the problem is widespread. I asked Phobia why he did this to me. His answer wasn’t satisfying. He says he likes to publicize security exploits, so companies will fix them. He says it’s the same reason he told me how it was done. He claims his partner in the attack was the person who wiped my MacBook. Phobia expressed remorse for this, and says he would have stopped it had he known. “yea i really am a nice guy idk why i do some of the things i do,” he told me via AIM. “idk my goal is to get it out there to other people so eventually every1 can over come hackers”
I asked specifically about the photos of my little girl, which are, to me, the greatest tragedy in all this. Unless I can recover those photos via data recovery services, they are gone forever. On AIM, I asked him if he was sorry for doing that. Phobia replied, “even though i wasnt the one that did it i feel sorry about that. Thats alot of memories im only 19 but if my parents lost and the footage of me and pics i would be beyond sad and im sure they would be too.”
But let’s say he did know, and failed to stop it. Hell, for the sake of argument, let’s say he didit. Let’s say he pulled the trigger. The weird thing is, I’m not even especially angry at Phobia, or his partner in the attack. I’m mostly mad at myself. I’m mad as hell for not backing up my data. I’m sad, and shocked, and feel that I am ultimately to blame for that loss. But I’m also upset that this ecosystem that I’ve placed so much of my trust in has let me down so thoroughly. I’m angry that Amazon makes it so remarkably easy to allow someone into your account, which has obvious financial consequences. And then there’s Apple. I bought into the Apple account system originally to buy songs at 99 cents a pop, and over the years that same ID has evolved into a single point of entry that controls my phones, tablets, computers and data-driven life. With this AppleID, someone can make thousands of dollars of purchases in an instant, or do damage at a cost that you can’t put a price on. (Source: Wired)
A nighttime drive down Al Waab Street toward the harbor in Doha, Qatar, puts one literally in the spotlight of what some are calling "one of the biggest cases of public counterfeiting in the history of design." That's what officials at the Spanish industrial design firm Santa & Cole think, anyway. They're the firm that designed the streetlights shining down on drivers along this roughly 10-kilometer stretch of road. Problem is, the 920 streetlights lining that roadway are alleged copies.
It may not be the biggest case of counterfeiting in the history of design, but it's likely the biggest in the history of streetlights.
Towering up and leaning over the street like splayed chopsticks, the streetlights are almost exact replicas of Santa & Cole's "Latina" streetlights, designed by architect Beth GalĂ and installed on streetscapes from Spain to Italy to the Netherlands. Qatar could have been another official entry on that list. In late 2005, Santa & Cole were invited to present a lighting design for transforming Al Waab Street ahead of Doha's hosting of the 2006 Asian Games. Those designs were then allegedly taken by the State public works authority, Ashghal, and sent to another firm to more affordably replicate the lights Santa & Cole had proposed.
Santa & Cole and GalĂ are so upset about the breach of intellectual property that they've launched an online campaign about the alleged counterfeit, QatarFakes.com. An extensive and document-rich timeline of the entire process is detailed on the site.
Despite a Cease and Desist letter [PDF], numerous attempts to negotiate, and an attempted arbitration through the World Intellectual Property Organization of the United Nations, the streetlights still stand in Doha.
Santa & Cole argues that the poorly built streetlights are not only a breach of intellectual property rights, but also create a negative impression of their design.
Officials in Qatar have declined to participate in any negotiations or arbitration related to the streetlights. With little recourse, GalĂ has filed a lawsuit against the State of Qatar with courts in Barcelona, which has the support of Santa & Cole, the Barcelona Center for Design and the Design For All Foundation. She calls the whole ordeal "a large-scale forgery case that is threatening the creativity of professionals and European companies." She's hoping the lawsuit will put an end to this years-long battle. For now, drivers in Doha will continue to navigate Al Waab Street under the glow of these controversial streetlights.
A few weeks ago, a senior Greek Orthodox clergyman in Israel attended a meeting at a government office in Jerusalem's Givat Shaul quarter. When he returned to his car, an elderly man wearing a skullcap came and knocked on the window. When the clergyman let the window down, the passerby spat in his face.
The clergyman prefered not to lodge a complaint with the police and told an acquaintance that he was used to being spat at by Jews. Many Jerusalem clergy have been subjected to abuse of this kind. For the most part, they ignore it but sometimes they cannot.
On Sunday, a fracas developed when a yeshiva student spat at the cross being carried by the Armenian Archbishop during a procession near the Holy Sepulchre in the Old City. The archbishop's 17th-century cross was broken during the brawl and he slapped the yeshiva student.
Both were questioned by police and the yeshiva student will be brought to trial. The Jerusalem District Court has meanwhile banned the student from approaching the Old City for 75 days.
But the Armenians are far from satisfied by the police action and say this sort of thing has been going on for years. Archbishop Nourhan Manougian says he expects the education minister to say something.
"When there is an attack against Jews anywhere in the world, the Israeli government is incensed, so why when our religion and pride are hurt, don't they take harsher measures?" he asks.
According to Daniel Rossing, former adviser to the Religious Affairs Ministry on Christian affairs and director of a Jerusalem center for Christian-Jewish dialogue, there has been an increase in the number of such incidents recently, "as part of a general atmosphere of lack of tolerance in the country."
Rossing says there are certain common characeristics from the point of view of time and location to the incidents. He points to the fact that there are more incidents in areas where Jews and Christians mingle, such as the Jewish and Armenian quarters of the Old City and the Jaffa Gate.
There are an increased number at certain times of year, such as during the Purim holiday."I know Christians who lock themselves indoors during the entire Purim holiday," he says.
Former adviser to the mayor on Christian affairs, Shmuel Evyatar, describes the situation as "a huge disgrace." He says most of the instigators are yeshiva students studying in the Old City who view the Christian religion with disdain.
"I'm sure the phenomenon would end as soon as rabbis and well-known educators denounce it. In practice, rabbis of yeshivas ignore or even encourage it," he says.
Evyatar says he himself was spat at while walking with a Serbian bishop in the Jewish quarter, near his home. "A group of yeshiva students spat at us and their teacher just stood by and watched."
Jerusalem municipal officials said they are aware of the problem but it has to be dealt with by the police. Shmuel Ben-Ruby, the police spokesman, said they had only two complaints from Christians in the past two years. He said that, in both cases, the culprits were caught and punished.
He said the police deploy an inordinately high number of patrols andspecial technology in the Old City and its surroundings in an attempt to keep order.
Historic and culturally important landmarks are being destroyed to make way for luxury hotels and malls, reports Jerome Taylor
Behind closed doors – in places where the religious police cannot listen in – residents of Mecca are beginning to refer to their city as Las Vegas, and the moniker is not a compliment.
Over the past 10 years the holiest site in Islam has undergone a huge transformation, one that has divided opinion among Muslims all over the world.
Once a dusty desert town struggling to cope with the ever-increasing number of pilgrims arriving for the annual Hajj, the city now soars above its surroundings with a glittering array of skyscrapers, shopping malls and luxury hotels.
To the al-Saud monarchy, Mecca is their vision of the future – a steel and concrete metropolis built on the proceeds of enormous oil wealth that showcases their national pride.
Yet growing numbers of citizens, particularly those living in the two holy cities of Mecca and Medina, have looked on aghast as the nation's archaeological heritage is trampled under a construction mania backed by hardline clerics who preach against the preservation of their own heritage. Mecca, once a place where the Prophet Mohamed insisted all Muslims would be equal, has become a playground for the rich, critics say, where naked capitalism has usurped spirituality as the city's raison d'ĂȘtre.
Few are willing to discuss their fears openly because of the risks associated with criticising official policy in the authoritarian kingdom. And, with the exceptions of Turkey and Iran, fellow Muslim nations have largely held their tongues for fear of of a diplomatic fallout and restrictions on their citizens' pilgrimage visas. Western archaeologists are silent out of fear that the few sites they are allowed access to will be closed to them.
But a number of prominent Saudi archaeologists and historians are speaking up in the belief that the opportunity to save Saudi Arabia's remaining historical sites is closing fast.
"No one has the balls to stand up and condemn this cultural vandalism," says Dr Irfan al-Alawi who, as executive director of the Islamic Heritage Research Foundation, has fought in vain to protect his country's historical sites. "We have already lost 400-500 sites. I just hope it's not too late to turn things around."
Sami Angawi, a renowned Saudi expert on the region's Islamic architecture, is equally concerned. "This is an absolute contradiction to the nature of Mecca and the sacredness of the house of God," he told the Reuters news agency earlier this year. "Both [Mecca and Medina] are historically almost finished. You do not find anything except skyscrapers."
Dr Alawi's most pressing concern is the planned £690m expansion of the Grand Mosque, the most sacred site in Islam which contains the Kaaba – the black stone cube built by Ibrahim (Abraham) that Muslims face when they pray.
Construction officially began earlier this month with the country's Justice Minister, Mohammed al-Eissa, exclaiming that the project would respect "the sacredness and glory of the location, which calls for the highest care and attention of the servants or Islam and Muslims".
The 400,000 square metre development is being built to accommodate an extra 1.2 million pilgrims each year and will turn the Grand Mosque into the largest religious structure in the world. But the Islamic Heritage Foundation has compiled a list of key historical sites that they believe are now at risk from the ongoing development of Mecca, including the old Ottoman and Abbasi sections of the Grand Mosque, the house where the Prophet Mohamed was born and the house where his paternal uncle Hamza grew up.
There is little argument that Mecca and Medina desperately need infrastructure development. Twelve million pilgrims visit the cities every year with the numbers expected to increase to 17 million by 2025.
But critics fear that the desire to expand the pilgrimage sites has allowed the authorities to ride roughshod over the area's cultural heritage. The Washington-based Gulf Institute estimates that 95 per cent of Mecca's millennium-old buildings have been demolished in the past two decades alone.
The destruction has been aided by Wahabism, the austere interpretation of Islam that has served as the kingdom's official religion ever since the al-Sauds rose to power across the Arabian Peninsula in the 19th century.
In the eyes of Wahabis, historical sites and shrines encourage "shirq" – the sin of idolatry or polytheism – and should be destroyed. When the al-Saud tribes swept through Mecca in the 1920s, the first thing they did was lay waste to cemeteries holding many of Islam's important figures. They have been destroying the country's heritage ever since. Of the three sites the Saudis have allowed the UN to designate World Heritage Sites, none are related to Islam.
Those circling the Kaaba only need to look skywards to see the latest example of the Saudi monarchy's insatiable appetite for architectural bling. At 1,972ft, the Royal Mecca Clock Tower, opened earlier this year, soars over the surrounding Grand Mosque, part of an enormous development of skyscrapers that will house five-star hotels for the minority of pilgrims rich enough to afford them.
To build the skyscraper city, the authorities dynamited an entire mountain and the Ottoman era Ajyad Fortress that lay on top of it. At the other end of the Grand Mosque complex, the house of the Prophet's first wife Khadijah has been turned into a toilet block. The fate of the house he was born in is uncertain. Also planned for demolition are the Grand Mosque's Ottoman columns which dare to contain the names of the Prophet's companions, something hardline Wahabis detest.
For ordinary Meccans living in the mainly Ottoman-era town houses that make up much of what remains of the old city, development often means the loss of their family home.
Non-Muslims cannot visit Mecca and Medina, but The Independent was able to interview a number of citizens who expressed discontent over the way their town was changing. One young woman whose father recently had his house bulldozed described how her family was still waiting for compensation. "There was very little warning; they just came and told him that the house had to be bulldozed," she said.
Another Meccan added: "If a prince of a member of the royal family wants to extend his palace he just does it. No one talks about it in public though. There's such a climate of fear."
Dr Alawi hopes the international community will finally begin to wake up to what is happening in the cradle of Islam. "We would never allow someone to destroy the Pyramids, so why are we letting Islam's history disappear?"
Under Threat
Bayt al-Mawlid
When the Wahabis took Mecca in the 1920s they destroyed the dome on top of the house where the Prophet Mohammed was born. It was thenused as a cattle market before being turned into a library after a campaign by Meccans. There are concerns that the expansion of the Grand Mosque will destroy it once more. The site has never been excavated by archaeologists.
Ottoman and Abasi columns of the Grand Mosque
Slated for demolition as part of the Grand Mosque expansion, these intricately carved columns date back to the 17th century and are the oldest surviving sections of Islam's holiest site. Much to the chagrin of Wahabis, they are inscribed with the names of the Prophet's companions. Ottomon Mecca is now rapidly disappearing
Al-Masjid al-Nawabi
For many years, hardline Wahabi clerics have had their sites set on the 15th century green dome that rests above the tomb holding the Prophet, Abu Bakr and Umar in Medina. The mosque is regarded as the second holiest site in Islam. Wahabis, however, believe marked graves are idolatrous. A pamphlet published in 2007 by the Saudi Ministry of Islamic Affairs, endorsed by Abdulaziz Al Sheikh, the Grand Mufti of Saudi Arabia, stated that "the green dome shall be demolished and the three graves flattened in the Prophet's Masjid".
Jabal al-Nour
A mountain outside Mecca where Mohammed received his first Koranic revelations. The Prophet used to spend long spells in a cave called Hira. The cave is particularly popular among South Asian pilgrims who have carved steps up to its entrance and adorned the walls with graffiti. Religious hardliners are keen to dissuade pilgrims from congregating there and have mooted the idea of removing the steps and even destroying the mountain altogether.
Honour killing is back on the headlines. I have come across several stories of honour killings, not just in the developing world, but one also in the UK! So here goes something on them. Mind you I’m giving details of very few incidents here, the ones which hit the headlines, god knows how many more have gone unreported. I don’t think that the actual figure of honour killing is available with anyone, neither is there any authority at the national or provincial level to monitor the act and collect the details in every country. The numbers are only collected from police and media reports. But what about the cases that go unreported?
Honour killing is a compoundable offence in which the parties -- accused and victim family -- can reach a compromise and settle the issue. As the accused of the honour killing is often a family member -- father, brother or husband -- of the victim, he easily earns pardon by the kin of the victim or the complainant. In such killings, parents should pursue the case, but as both the victim and accused were related, the killer gains an advantage.
Palestine Let me begin with Palestine. To the shock of all, the man killed slit the throat of his wife in the market, in front of all. Why? Just because she sought divorce from her abusive husband of 10 years!
In 2012, 12 women were killed by relatives, including three in "family honour" cases. Those include suspected adultery and similar cases. The new addition is a man killing his wife brutally in the market. Nancy Zaboun, a 27-year-old mother of three, was reportedly regularly beaten by her 32-year-old husband Shadi Abedallah, at times so severely that she had to be hospitalized. Even then, Abedallah was never arrested, police only made him sign pledges that he would stop beating his wife. And what’s even more surprising is the fact that Abedallah himself is a former police officer and he killed her after attending a hearing in her divorce case.
Women might have scored some breakthroughs in traditional Palestinian society in recent years, including gaining a greater role in public life, but tribal laws still remain strong, and violence against women is generally viewed by police as an internal family matter.
The case might have reverberated across Palestinian society because of the brutality of the attack, but violence against women is overlooked here, as in other parts of the Arab world, and women's rights activists say abusive husbands are rarely punished.
On July 18, the Palestinian Centre for Human Rights (PCHR) released a statement, which said a 19-year-old girl was murdered overnight in a refugee camp in Gaza City by her brother and father in an apparent "honour killing". “The body of the girl, identified only by the initials "WMQ," arrived at the city's Shifa Hospital at approximately 2:00 am (2300 GMT on Tuesday),” The Egyptian Gazettereported. "Palestinian police spokesman Major Ayman Batniji told PCHR that police opened an investigation immediately and arrested her father and her brother who both confessed to committing the crime in the context of 'family honour'," it said.
Honour killings, in which a family member murders a relative who is perceived to have ruined the family's reputation, occur periodically in the Palestinian territories.
Last year, following the murder of a woman in the southern West Bank city of Hebron, Palestinian President Mahmud Abbas pledged to amend a decades-old law under which those citing "honour" as a defence could expect to receive a jail sentence of no more than six months.
India: Honour killings are not new to India. They have been on the headlines very often. On July 14, a man was murdered for falling in love with an upper caste girl. Elango was murdered by a gang of men who opposed his falling in love with Selvalakshmi, 18, a dominant caste girl in Erode. Selvalakshmi’s brother Saravanan, who wanted to save the ‘honour’ of the family, arranged his friends to ‘finish off’ Elango, a dalit. His friends brought Elango to Muneerpallam secretly and killed him. Now Saravanan’s gang has been put behind bars. Selvalakshmi is depressed and sees no hope for her future. “This is not an isolated case. Many Elangos and Selvalakshmis are facing threat from their families for marrying out of their caste,” reportedThe Asian Age.
A local court of Badaun in Lucknow on July 30 awarded death penalty to seven members of a family for killing a couple in Fareedpur village in May 2006. The police, in its investigation, found that Deen Dayal and Aneeta, both in their early twenties, had been victims of ‘honour killing’. All those convicted belonged to the girl’s family and included her father Nathu.
A local court in Sonipat in Haryana on August 1 awarded life imprisonment to a woman and her two sons for killing her 12-year-old daughter and 14-year-old niece in the name of honour. Chanchal and her cousin Raj Kumari were killed after their grandmother caught them with their 16-year-old cousin around two years back. The judge also slapped Rs 10,000 fine each on the convicts -- Vidya Devi, Kumari's mother, Chand Varma and Suraj Varma, reportedThe Times of India. They would undergo an additional 10-month imprisonment if they fail to pay the fine. A police officer said the "affair'' infuriated Vidya and her two sons, who took the girls to a secluded place and strangled them to death. They then threw their bodies into a canal near Badwasni village in Sonipat on June 26, 2010.
Pakistan: Earlier in Pakistan, the honour killings were mostly isolated to northern Sindh, southern Punjab and some parts of Khyber Pakhtunkhwa and Balochistan in Pakistan, but now the capital police are registering cases regularly especially in its rural areas, reportedDawn. At least six incidents of honour killings were reported over the last two-and-a-half months in the country.
On July 3, a man was found dead from a nullah at G-11/2. The victim, Mohammad Bashir, and his cousin Ahsanullah, natives of district Kohat, persuaded two local girls to elope with them and did a court marriage a year back. A Jirga -- a tribal assembly of elders -- was called which barred the couple from entering the village. In response, the couple migrated to Islamabad and started living at Merabadi in Golra. On July 13, the victim received a call on his mobile from his in-laws and immediately left the house. Later, he was found strangled in the nullah.
On July 6, a man killed his wife and her alleged paramour in the area of Shahzad town. Later, the accused, who escaped from the spot after the killing, surrendered to the police. The accused told the police that when he returned home on July 6, he found his bedroom locked from the inside, but his wife was in the kitchen. Later, he found a man inside his bedroom and lost his temper and killed the duo. He further claimed that around a month ago, he had returned home and found his bedroom locked. Later, his wife opened it and he saw the man escaping from another door. He rebuked his wife over her illicit relation with the man and in response she left the house. A week later, she returned on his insistence, but did not abandon the illicit relationship.
On July 19, a man killed his sister ‘MB’, 19, on pretext of “honour” at his house in Kirpa. The victim’s family was trying to convince her to marry a man of their choice, but she repeatedly refused. When asked for the reason, she disclosed that she had married secretly. Over the disclosure, her brother killed her with a pistol and escaped. Later, the victim’s father lodged a complaint against his son and the police registered a murder case.
Afghanistan: An Afghan man killed his two teenage daughters when they returned home four days after running away with a man in a southern village, police said on July 19. The father, who shot the girls, has been detained on murder charges in Nad Ali district in the southern province of Helmand, a hotbed of the Taliban insurgency, provincial police spokesman Farid Ahmad Farhang told AFP. “He killed two of his daughters. His daughters had run away with a young man four days ago. When they returned home their father killed them,” Farhang said. Police have issued an arrest warrant for the young man, who is said to be working as an interpreter with NATO forces in the southern province, reportedThe Nation.
So-called “honour killing” is a common practice in Afghanistan. The Taliban recently publicly executed a young woman in a village near Kabul after she was accused of adultery. The execution was widely condemned internationally after a shocking video of the killing surfaced in Afghan media. It showed a crowd cheering as a man shot the woman with a rifle.
The UK: It is not that only developing countries and Muslim-dominated countries are haunted by honour killings, it happens even in the developed countries, even in the West, even in the UK! A jury in the UK has begun considering its verdicts in the trial of a couple accused of murdering of their daughter because they believed she brought “shame on the family”, reportedThe Independent. Iftikhar Ahmed, 52, and his wife Farzana, 49, of Liverpool Road, Warrington, Cheshire, are alleged to have suffocated their 17-year-old daughter Shafilea with a plastic bag. The 10-week trial heard evidence from Shafilea's sister Alesha, who claimed that she and the rest of her siblings witnessed the murder at the family home. Taxi driver Ahmed denies murder, saying Shafilea ran away from home in the middle of the night and he never saw her again. Farzana also denies murder but told the told the jury she saw her husband beat her eldest child and she believes he killed her. Study on honour killings: Worldwide, most honour killings take place in Muslim countries -- Pakistan, in particular. But the northern parts of Hindu-majority India also are plagued by the phenomenon. Official estimates suggest at least 1,000 honour killings take place in each country every year. The actual numbers likely are many times that. As Phyllis Chesler and Nathan Bloom wrote in the Summer 2012 edition of the Middle East Quarterly, “honor killing is the premeditated murder of a relative (usually a young woman) who has allegedly impugned the honor of her family.”
In the case of Pakistani honour killings, the researchers found, three motives prevailed: punishment for “illicit relationships” (often involving a woman who elopes with a mate of her own choosing); “contamination by association” (in which family member are killed for the moral sins of their sister or daughter); and “immoral character,” in which the woman or girl (the average victim age is 22) is punished for going unveiled, or otherwise flouting the standards of dour piety expected of Muslim women in backwards societies.
In Indian honour killings, these factors sometimes are present. But the dominant motivation is something entirely different: caste. This difference in honour-killing motivation is tied to a difference in the murder-sanctioning decision-making process. In Pakistan, the killings are embarked upon as small-scale family conspiracies. In India, on the other hand, caste-based councils called khap panchatays explicitly order the killings -- despite the fact that inter-caste and intra-gotra marriage has been legal in India for over half a century.
The difference in Indian/Pakistani honour-killing motivations also leads to another striking statistical gap between the two nations: “In 40% of the cases, Indian Hindus murdered men, while Pakistani Muslims murdered men only 14% of the time in Pakistan,” the authors reported. “The higher percentage of male victims in India underscores the fact that Hindu honor killings are more often about caste purity than sexual purity. While sexual purity is traditionally a female responsibility, the religious mandate to maintain strict boundaries between castes is an obligation for all Hindus, both male and female.”
From a policy-making perspective, this analysis suggests that there is more hope in India than in Pakistan for eliminating the practice of honour killing.
India has unambiguously denounced honour killings and is keen to crack down on the khap panchayats’ stubborn grip on popular attitudes in northern India. In particular, a bill drafted in 2011 stipulates that: “It shall be unlawful for any group of persons to gather, assemble or congregate with the… intention to deliberate, declare on, or condemn any marriage or relationship such as marriage between two persons of majority age in the locality concerned on the basis that such conduct or relationship has dishonored the caste or community or religion of all or some of the persons forming part of the assembly or the family or the people of the locality concerned.” Unfortunately, the fate of the legislation remains uncertain -- because the khap panchayats still have political sway.
In Pakistan, the situation is worse, because national authorities don’t even control large swathes of their own country’s northern borderlands -- let alone the murderous intra-familial dynamics of the tribes that inhabit these areas.
Political Islam also is a complicating factor in Pakistan. Like the Hindu faith, Islam provides no explicit religious justification for honour killings. Yet the perceived imperative of “protecting” Muslim women from the “impurities” of the West has become wrapped up with the Islamist political project, and so has blurred into a quasi-religious justification for honour killings.
In 2009, the authors note, “Pakistan’s National Assembly passed the Domestic Violence (Prevention and Protection) Bill, which strengthened legal protections against domestic violence for women and children. However, the Council of Islamic Ideology, a constitutional body charged with assessing whether laws are consistent with Islamic injunctions, issued a statement saying the bill ‘would fan unending family feuds and push up divorce rates.’ After this, the bill was held up in the Pakistani senate and allowed to lapse.”
Moreover: “Under Sharia-based provisions of Pakistan’s judicial system, murderers can buy a pardon by paying blood money (dyad) to the victim’s family. Since the family of honor killing victims are nearly always sympathetic to the honor killer as well as complicit to some degree, getting a pardon is usually just a formality. Women’s rights organizations in Pakistan have pressed parliament to disallow the practice of blood money in honor killing cases, but conservative Islamist groups have blocked the needed legislation.”
From a strictly Western point of view, the most interesting conclusion from the Chesler/Bloom study is this: Pakistani immigrants to the West sometimes bring the seeds of a deadly honour culture with them, while Indian immigrants typically do not.
That is because the belief that a family’s honour lives and dies with the perceived chastity and obedience of its female members is deeply culturally ingrained in Pakistan, and often survives for decades, even on Western soil. On the other hand, Indians who emigrate to the West also leave behind the khap panchayats, and the codes of caste behaviour they enforce. (To my knowledge, certainly, there are no khap panchayat in Brampton or Mississauga -- at least, none that issue murder decrees.)