Wednesday, October 29, 2008

For my Security students...

http://www.pogowasright.org/article.php?story=20081029055841317

Finjan unveils how cybercriminals steal corporate data and store it on remote crimeservers

Wednesday, October 29 2008 @ 05:58 AM EDT Contributed by: PrivacyNews

Finjan Inc., has announced that its Malicious Code Research Center (MCRC) has documented step-by-step how corporate data is being stolen and stored on remote servers owned by criminals. In its October 2008 Malicious Page of the Month report, Finjan describes how a corporate user, while browsing the web for his regular business needs, got infected with a Trojan.

Source - bjhcim.co.uk

[Finjan Page of the Mainth: http://www.finjan.com/Content.aspx?id=1367



Winning hearts and minds... (Does this only happen in China?)

http://tech.yahoo.com/news/ap/20081028/ap_on_hi_te/china_microsoft_blacked_out

Microsoft goes black, making Chinese see red (AP)

Posted on Tue Oct 28, 2008 12:40PM EDT

SHANGHAI, China - An anti-piracy tactic by Microsoft Corp. that turns some computer users' screens black has set off a wave of indignation among Chinese consumers, posing renewed problems for the software maker in the huge China market.

... "It's a crime," said Beijing lawyer Dong Zhengwei, who filed a complaint against Microsoft with the Public Security Ministry. The ministry hasn't responded. "The black-screen plan implies that Microsoft can hack all its users, not just the pirates," Dong said. "That's not fair."

At issue is Windows Genuine Advantage, a tool Microsoft uses to assess, over the Internet, whether a PC has one of the pirated copies of Windows that flourish in developing countries. The tool was developed after Windows XP was released, but has since been added to updated copies of the operating system. The technology was built into Vista, the latest edition of Windows, from the start.

As the tool scans for pirated copies of Windows, it logs certain information about computers, notifies users if it detects illegal copies or counterfeits — and urges them to get a legitimate copy.

Windows Genuine Advantage has been in use worldwide for several years. The update that started to affect Chinese PC users last week did exactly what it was intended to do: get people's attention.

Now when the tool detects a fake copy of Windows, it turns the PC's desktop black, replacing the user's background image. Though the user can override the blackout, it reappears every 60 minutes.

In all other ways, the blacked-out computer still works, thanks in part to an outcry last year. In Microsoft's first attempt to step up notifications for pirated software, Windows Genuine Advantage crippled Vista's snappy user interface and disabled other features. Microsoft backed down and settled on the blacked-out desktop as a compromise.



If you comply, can you still say, “I didn't know?”

http://www.bespacific.com/mt/archives/019669.html

October 28, 2008

Information Technology Risks and Controls and Fair Credit Reporting Act

OTS 08-051 - OTS Issues New Examination Procedures on Identity Theft Red Flags and Address Discrepancies: "This Regulatory Bulletin transmits revised Examination Handbook Section 341, Information Technology Risks and Controls, and revised Examination Handbook Section 1300, Fair Credit Reporting Act (FCRA). The revised Handbook Sections contain new guid-ance and examination procedures for the final rules on Identity Theft Red Flags and Address Discrepancies, which implement Sections 114 and 315 of the Fair and Accurate Credit Trans-actions Act (FACT Act) of 2003. This bulletin rescinds RB 37-15 dated April 20, 2006."



Google does evil? Isn't a compromise with the “old school” evil?

http://www.bespacific.com/mt/archives/019664.html

October 28, 2008

Authors, Publishers, and Google Reach Landmark Settlement

News release: "The Authors Guild, the Association of American Publishers (AAP), and Google today announced a groundbreaking settlement agreement on behalf of a broad class of authors and publishers worldwide that would expand online access to millions of in-copyright books and other written materials in the U.S. from the collections of a number of major U.S. libraries participating in Google Book Search... Under the agreement, Google will make payments totaling $125 million. The money will be used to establish the Book Rights Registry, to resolve existing claims by authors and publishers and to cover legal fees. The settlement agreement resolves Authors Guild v. Google, a class-action suit filed on September 20, 2005 by the Authors Guild and certain authors, and a suit filed on October 19, 2005 by five major publisher-members of the Association of American Publishers: The McGraw-Hill Companies, Inc.; Pearson Education, Inc. and Penguin Group (USA) Inc., both part of Pearson; John Wiley & Sons, Inc.; and Simon & Schuster, Inc. part of CBS Corporation. These lawsuits challenged Google’s plan to digitize, search and show snippets of in-copyright books and to share digital copies with libraries without the explicit permission of the copyright owner."



Is the Judge asking the RIAA to have pity on their victims? I doubt they will change their strategy that easily! Costly litigation is a strategic tool.

http://news.slashdot.org/article.pl?sid=08/10/28/203218&from=rss

Judge Tells RIAA To Stop 'Bankrupting' Litigants

Posted by CmdrTaco on Tuesday October 28, @04:50PM from the also-bake-them-cookies dept. The Courts

NewYorkCountryLawyer writes

"The Boston judge who has consolidated all of the RIAA's Massachusetts cases into a single case over which she has been presiding for the past 5 years delivered something of a rebuke to the RIAA's lawyers, we have learned. At a conference this past June, the transcript of which (PDF) has just been released, Judge Nancy Gertner said to them that they 'have an ethical obligation to fully understand that they are fighting people without lawyers... to understand that the formalities of this are basically bankrupting people, and it's terribly critical that you stop it ...' She also acknowledged that 'there is a huge imbalance in these cases. The record companies are represented by large law firms with substantial resources,' while it is futile for self-represented defendants to resist. The judge did not seem to acknowledge any responsibility on her part, however, for having created the 'imbalance,' and also stated that the law is 'overwhelmingly on the side of the record companies,' even though she seems to recognize that for the past 5 years she has been hearing only one side of the legal story."



Interesting, but if IBM is creating what is essentially a standalone computer on a thumbdrive, why not build it into a handheld device (PDA or cellphone) and ignore the laptop entirely?

http://news.cnet.com/8301-1009_3-10077655-83.html?part=rss&subj=news&tag=2547-1_3-0-5

Banking security on a USB stick

Posted by Elinor Mills October 28, 2008 10:01 PM PDT

IBM was set to unveil on Wednesday a prototype USB device designed to protect people doing online banking from having their data stolen or compromised.

The device, which looks like a memory stick with an integrated display, creates a secure channel to a bank's online transaction server. The connection bypasses the user's PC, which could be infected with viruses and other malware that make sending financial information over the Internet unsafe.

The user can log on and validate transactions using the device's display and a smart card can be inserted into the device, providing an added layer of security to protect transmissions from man-in-the-middle interceptions, IBM said.



Might be useful, but it seems redundant. What would be useful is an interactive guide to Google Hacks, demonstrating how to use all the Google features. For instance, I use it frequently to identify acronyms (define: SAAS) and in my math classes as a calculator or table lookup (sine 28 degrees)

http://www.killerstartups.com/Web20/simply-google-com-roundup-of-google-services

Simply-Google.com - Roundup Of Google Services

http://www.simply-google.com

This web-service was created with the objective of encapsulating all the different products and services that Google offers into a single and self-contained page. The person behind this concept terms it “a roundup of every Google search and service out there on one convenient page”, and this is exactly what the site stands for.



Could be useful. I can spot the books/authors I want and get on the waiting list at my local library (maybe even earlier than #629!)

http://www.killerstartups.com/eCommerce/windowshop-com-amazon-window-shop

WindowShop.com - Amazon Window Shop

http://www.windowshop.com

Those who have a soft spot for online shopping and are hooked up on Amazon have arrived at the right place. The Amazon Window Shop is a new way of browsing through products which have been recently released, and have a taster of what each full product has to offer.

Basically, the site is updated every Tuesday. That day, samples from a new batch of products are uploaded to the site for you to delve upon. This approach dispenses with text-based advertising and lets you see trailers from the new movies that have added to the catalog, as well as listening to the most notable tracks from albums which have just hit the streets. There are also audio reviews of recommended books.



http://tech.slashdot.org/article.pl?sid=08/10/29/0516228&from=rss

MTV Launches Music Video Site

Posted by Soulskill on Wednesday October 29, @08:15AM from the guess-what's-top-rated-right-now dept. Music The Internet

An anonymous reader writes

"MTV Music has just launched a website where they offer over 16,000 music videos — like YouTube, but with fewer notices and DMCA takedowns. They've also set up development tools for third parties to incorporate the content into their own creations. Users creating accounts at the site face other challenges, however, such as the six separate agreements and privacy statements that must be accepted via a single checkbox. Thankfully, at the time of writing the MTV Music website was making this process easier on its Firefox 3 visitors by automatically checking the accept box whenever any agreement is viewed."

No comments: