Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, February 02, 2011

No pressure! Note that it still requires you to click on a bogus link....

http://www.techeye.net/security/internet-explorer-bug-puts-900-million-users-at-risk

Internet Explorer bug puts 900 million users at risk

Microsoft has announced that all current versions of Internet Explorer are currently at risk of being hacked due to a flaw in the programme.

It is now known that the web browser, used by 900 million people across the globe, requires a software patch in order to defend against attack while Microsoft prepares a longer term fix, a massive security slip up by the firm.

A security advisory announcement was made on Friday highlighting scripting vulnerabilities affecting all versions of Windows.

It is not however thought that there has been any breaches of security so far: “The main impact of the vulnerability is unintended information disclosure,” said Angela Gunn, a Microsoft representative.

… The fault lies in the MHTML protocol handler, which is used by applications to render certain kinds of document.

According to the statement an attacker could, for example, construct an HTML link designed to trigger a malicious script and then persuade the targeted user to click on it.

Once this happens the script would then be able to run on the machine for the rest of that IE browser session, potentially collecting information from emails, sending the user to fake sites and generally interfering with the browser usage.



Ethical Hackers: Here's how you do it...

http://yro.slashdot.org/story/11/02/02/0217256/Egyptians-Turn-To-Tor-To-Organize-Dissent-Online?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Egyptians Turn To Tor To Organize Dissent Online

"Even as President Obama prepares to follow Mubarak with his own 'internet kill switch', Egyptians were turning to the Tor anonymiser to organise their protests online. The number of Egyptians connecting to the internet over Tor rose more than five-fold after protests broke out last week before crashing when the Government severed links to the global internet. Information security researcher, Tor coder and writer of the bridge that allowed Egypt's citizens to short-circuit government filters, Jacob Appelbaum, told SC Magazine Egyptians were 'concerned and some understand the risk of network traffic analysis.' Appelbaum has himself been the subject of attention from US security services who routinely snatch his electronics and search his belongings when he re-enters the country and who subpoenaed his private Twitter account last December."

Which helps explain why Appelbaum is helping to organize a small fundraiser to get more communications gear into Egypt.



(Related) “Yes, it gives the President Mubarak-like power, but its different! Or at least it will be on paper...”

http://news.cnet.com/8301-31921_3-20030332-281.html

Senators decry link between Egypt, 'kill switch' bill

Three U.S. senators who want to give the president emergency powers over the Internet are protesting comparisons with the "kill switch" highlighted by Egypt's Net disconnection.

In a statement yesterday, the politicians said their intent was to allow the president "to protect the U.S. from external cyber attacks," not to shut down the Internet, and announced that they would revise their legislation to explicitly prohibit that from happening.


(Related) “Hey, we're the government. You can trust us!”

http://www.bespacific.com/mt/archives/026401.html

February 01, 2011

EFF Releases Report Analyzing Surveillance of Americans During Intelligence Investigations Conducted Between 2001 and 2008

Patterns of Misconduct: FBI Intelligence Violations from 2001 - 2008, A Report Prepared by the Electronic Frontier Foundation, January 2011

  • "In a review of nearly 2,500 pages of documents released by the Federal Bureau of Investigation as a result of litigation under the Freedom of Information Act, EFF uncovered alarming trends in the Bureau’s intelligence investigation practices. The documents consist of reports made by the FBI to the Intelligence Oversight Board of violations committed during intelligence investigations from 2001 to 2008. The documents suggest that FBI intelligence investigations have compromised the civil liberties of American citizens far more frequently, and to a greater extent, than was previously assumed. In particular, EFF’s analysis provides new insight into the number of Violations Committed by the FBI..."



So much for net neutrality? Or have they just gone away from “unlimited Internet?”

http://www.cbc.ca/canada/nova-scotia/story/2011/02/02/ns-usage-based-billing.html

N.S. internet users mull over CRTC billing decision

The federal regulator gave Bell Canada the approval to implement so-called usage-based billing to wholesale customers — usually smaller internet service providers that rent portions of its network.

Customers of those service providers in Ontario and Quebec received notice this week that they would be able to stream or download only a fraction of the movies and data that they had previously been allowed under the same price plan.

"This is outrageous gouging," said Andrew Wright, who runs a non-profit internet provider in Halifax called Chebucto Community Net.

… "The sad point is that if people aren't careful of what they're doing online, they can rack up one serious bill and we've all heard stories about the cellular industry doing that," he said.



I wonder why no one in the US is doing this? We could easily “borrow” their criteria and evaluate state laws...

http://www.pogowasright.org/?p=20207

European Commission Finds Israeli Data Protection Law Provides Adequate Protection

February 1, 2011 by Dissent

Reporting from Israel, legal consultant Dr. Omer Tene writes:

On January 31, 2011, the European Commission formally approved Israel’s status as a country providing “adequate protection” for personal data under the European Data Protection Directive. The decision is restricted to automated international data transfers from the EU, as well as to non-automated data transfers that are subject to further automated processing in Israel. It will allow unrestricted transfers of personal data from the EU to Israel, for example between corporate affiliates or from European companies to data centers in Israel.

Israel joins a select group of countries, including Argentina, Canada, Switzerland, Andorra and several English Channel Islands, which have obtained similar status. A separate arrangement governs data transfers from the EU to the U.S. under the Safe Harbor framework.

Read more on Hunton & Williams Privacy and Information Security Law Blog.



“Hey, we got a good thing going here, why change?”

http://www.pogowasright.org/?p=20221

New Study Shows Persistence Of ‘Flash Cookies’

February 1, 2011 by Dissent

Joe Mullin reports:

The tracking uses of so-called “Flash cookies,” the data packets stored in the computers of users of Adobe (NSDQ: ADBE) Flash Player, started getting a lot more attention last year, when they were the focus of an article about online privacy in the Wall Street Journal, as well as severallawsuits. They were also mentioned as a privacy problem last month by the Federal Trade Commission.

The results from a new study suggest that “re-spawning,” one of the more troublesome practices around Flash cookies, is declining. But the same study showed that about 10 percent of the most-popular web sites may still be using Flash cookies to track users—and none of the companies that run those web sites would discuss what they’re using the cookies for.

Read more on PaidContent.org



1) after ignoring complaints for months, TSA announced earlier this month that they would be changing the machines. 2) no government hardware has ever been designed, tested and implemented in one month. 3) a minor software tweak, changing only how the data is displayed (but keeping the real images in storage somewhere) is a much more probable answer.

http://www.pogowasright.org/?p=20204

TSA debuts new full-body scanners

February 1, 2011 by Dissent

Ashley Halsey III reports:

New airport security scanners designed to be less intrusive than machines that captured near-naked images will debut at the Las Vegas airport Tuesday.

They’ll look just like the controversial scanners that were introduced last fall, but instead of sending a revealing image to be examined in a private security booth, new software will project a non-gender-specific silhouette on a small screen attached to the booth.

If the passenger is carrying any contraband items a red box will appear on the screen. Otherwise it will flash a green okay.

Read more in the Washington Post.



Ethical Hackers: What's taking you so long?

http://www.theregister.co.uk/2011/02/01/ps3_hacked_again/

Newest PS3 firmware hacked in less than 24 hours

… Sony announced the release of Version 3.56 on Wednesday. That same day, game console hacker Youness Alaoui, aka KaKaRoToKS, tweeted that he had released the tools to unpack the files, allowing him to uncover the new version's signing keys.



Another resource discovered...

http://www.pogowasright.org/?p=20198

Ca: Management Ethics: Privacy issues

February 1, 2011 by Dissent

The Fall/Winter 2010 issue of Management Ethics (pdf) from www.ethicscentre.ca has a nice collection of articles:

  • Why Privacy Matters - Chris MacDonald, Ph.D.

  • Privacy by Design: Achieving Consumer Trust and Freedom in the Information Age - Ann Cavoukian, Ph.D.

  • Hiring in a Social Media Age - Avner Levin, SJD

  • Privacy Law: Questions and Answers - Christine Lonsdale



...and we should be able to identify new/modified data instantly...

http://www.bespacific.com/mt/archives/026407.html

February 01, 2011

Abandoning Law Reports for Official Digital Case Law

Abandoning Law Reports for Official Digital Case Law, Peter W. Martin, Cornell Law School, January 25, 2011, Cornell Legal Studies Research Paper No. 11-01

  • "In 2009, Arkansas ended publication of the Arkansas Reports. Since 1837 this series of volumes, joined in the late twentieth century by the Arkansas Appellate Reports covering the state's intermediate court of appeals, had served as the official record of Arkansas's case law. For all decisions handed down after February 12, 2009, not books but a database of electronic documents “created, authenticated, secured, and maintained by the Reporter of Decisions” constitute the “official report” of all Arkansas appellate decisions. The article examines what distinguishes this Arkansas reform from the widespread cessation of public law report publication that occurred during the twentieth century and this new official database from the opinion archives now hosted at the judicial websites of most U.S. appellate courts. It proceeds to explore the distinctive alignment of factors that both led and enabled the Arkansas judiciary to take a step that courts in other jurisdictions, state and federal, have so far resisted. Speculation about which other states have the capability and incentive to follow Arkansas’s lead follows. That, in turn, requires a comparison of the full set of measures the Arkansas Supreme Court and its reporter of decisions have implemented with similar, less comprehensive, initiatives that have taken place elsewhere. Finally, the article considers important issues that have confronted those responsible for building Arkansas’s new system of case law dissemination and the degree to which principal components of this one state’s reform can provide a useful template for other jurisdictions."



The “software tool” claims to identify copyrighted material in your browser (only?) but you have to pay for the “universal license” first. Clearly the “universal license” isn't universal as the software will explain how to “purchase the rights” in real time and then records information to summarize violations (and perhaps phone that information home?)

http://www.bespacific.com/mt/archives/026402.html

February 01, 2011

New on LLRX.com - The Risky Business of Information Sharing: Why You Need to Care About Copyright

The Risky Business of Information Sharing: Why You Need to Care About Copyright: Copyright is an essential tool in the spread of new ideas, and the workplace has become ground zero for infringement. Ask employees up and down the corporate hierarchy, and they'll tell you that whisking information electronically to co-workers is integral to their jobs. Their employers will emphatically agree. But unauthorized swaps of information also carry enormous potential risk: Ordinary office exchanges, so natural to the digital world, can easily violate the copyright rights of others and bring costly lawsuits or settlements. Now the same technology that has dramatically defined the Internet age is drawing a new roadmap to compliance, with software tools that simplify adherence to copyright requirements.



Ethical Hackers: Is this enough to automate forgery?

http://www.washingtonpost.com/wp-dyn/content/article/2011/02/01/AR2011020106442.html

National Treasures: Google Art Project unlocks riches of world's galleries

Google is bringing its "street view" technology indoors. With the announcement Tuesday in London of the Google Art Project, the Internet giant jumps into the online art arena with tools that will allow Web surfers to move through 17 of the most prominent art galleries in the world, with the option to look more closely at individual artworks, including some that will be digitized so exhaustively that individual paint strokes and hairline cracks in the surface will be visible.

http://www.googleartproject.com/


Friday, January 28, 2011

Isn't this the same control the US government wants?

http://yro.slashdot.org/story/11/01/28/0114217/Egypt-Shuts-Off-All-Internet-Access?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Egypt Shuts Off All Internet Access

"Several sources are reporting Egypt has shut off all Internet access. There is still no official confirmation. Blackberry, twitter and SMS seem confirmed off. So, if you were there, what would you do to get communications for everyone? Do you still have a POTS modem?"



Something for Privacy Day...

http://mashable.com/2011/01/27/the-real-reason-no-one-reads-privacy-policies-infographic/

The Real Reason No One Reads Privacy Policies [INFOGRAPHIC]



How many e-companies are dong this?

http://www.pogowasright.org/?p=20060

Monster.com Latest Site Trying to Beat Regulators to Privacy Punch

January 28, 2011 by Dissent

Katy Bachman reports:

Friday is Data Privacy Day and at least one company, job search giant, Monster.com, is using the occasion to announce additional privacy controls for the 68 million job seekers reached annually by behaviorally targeted ads through its Career Ad Network.

Monster is one of many Internet companies that’s recently been feeling the heat coming from probes by the Federal Trade Commission, the Commerce Department and Congress, and is taking privacy policy into its own hands before the regulators do.

“We want to make sure our users know what we’re doing with their information and that we maintain their trust. In light of what is going on, we don’t want consumers to be concerned about what we’re doing,” said Mary Cavanaugh, manager and counsel of global privacy for Monster. “We think we’re ahead of the game.”

All the recruitment ads Monster places for its company clients will now contain a hyperlink that allows consumers to either opt-out of behavioral targeted ads or provide more information for better results. Before this new just-in-time hyperlink notification, Monster provided an opt-out control through its privacy policy.

Read more on AdWeek.



So, if the UK is doing a bad job, who is doing a good job (and what are they doing?)

http://www.pogowasright.org/?p=20042

Privacy study signals a worrying increase in surveillance across Europe

January 28, 2011 by Dissent

Yesterday I pointed readers to Privacy International’s newly revamped web site and their infographic on surveillance issues by country. On Data Privacy Day (Data Protection Day in Europe), it seems appropriate to also post their press release on the state of privacy protection in the EU:

A landmark EU-wide study of national privacy safeguards published today shows a decline in privacy protection across Europe and a steep increase in state surveillance over the lives of individuals.

The year-long study, funded by the European Commission and backed by a 600-page analysis of privacy in 31 countries, was co-authored by the London-based global watchdog Privacy International, the Electronic Privacy Information Center in Washington DC and the Center for Media and Communications Studies of the Central European University in Budapest.

The study includes a rating for EU member states and accession candidate countries. This rating pits Britain and Ireland fighting over the bottom of the privacy league.

Further information about the project will be found at http://www.privacyinternational.org/ephr

The EPHR project comprises three action areas: (1) Map European privacy laws and recent developments as well as summarise the trends in the light of the right to privacy; (2) disseminate information and publish it on multiple online and offline platforms; and (3) develop innovative awareness-raising campaigns to be launched at the European Data Protection Day on 28th January 2011. The country reports were also translated into native languages.

The EPHR project builds upon the EPIC and Privacy International publication “Privacy & Human Rights: An International Survey of Privacy Laws and Developments“, which is the most authoritative reference on privacy regulations and developments worldwide.

Read more on Privacy International



For my Ethical Hackers and Computer Security students...

http://www.pogowasright.org/?p=20068

Protecting your privacy from webcam threats

January 28, 2011 by Dissent

For Data Privacy Day, Cybrosys Technologies writes:

So you own a webcam? Good! Welcome to being watched then.

Cyber crime is a fascinating field: constantly evolving, and always innovating. Meet its most latest brain child: hacking webcams without even the owner knowing!

The idea is simple: they turn on your webcam and watch you. Oh no, you will not be asked to pose or say cheese. They simply capture away pictures and videos of yours or anything in the webcam’s field, when you go about doing stuff, blissfully unaware.

Switching off your cam is not going to help either. The webcam hacking spyware works with a Trojan backdoor software that will turn on the web cam on its own. This can be installed in your system when you download innocent-looking picture or video or music files.

Read more on Cybrosys. Although they mention “studies” about this problem, I see no studies mentioned – just some news reports describing cases where people didn’t know they were being monitored via their webcams, including the Lower Merion case. But the article may inspire some people to shield their webcam lens if they’re not really using it.


(Related)

http://www.makeuseof.com/tag/ispy-turns-computer-webcam-surveillance-equipment/

iSpy Turns Your Computer Webcam Into Surveillance Equipment [Windows]

iSpy … has the ability to record video, record audio, provide online access to video and more.

… iSpy is able to record multiple video streams at once, so this launch area is meant to provide the space needed to keep tabs on a large number of cameras.



For my Lawyer friends...

http://yro.slashdot.org/story/11/01/28/058256/Facebook-Posts-Mined-For-Courtroom-Evidence?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Facebook Posts Mined For Courtroom Evidence

"Defense lawyers are increasingly gaining permission from US courts to mine the private comments and postings on Facebook accounts to be used as evidence during trials. The first example — noted in Slashdot in September — has given way to an avalanche of new cases — and a worrying precedent that judges consider social networking content to be public data." [Isn't it? Bob]



The flip side of Facebook... and perhaps a new area for Lawyers?

http://www.nypost.com/f/print/news/local/staten_island/si_man_hits_facebook_with_suit_rMmqxdBwUg9UJpHI8WIDIK

SI man hits Facebook with $500G suit

A Staten Island man is poking Facebook with a $500,000 lawsuit for disabling his account.

Mustafa Fteja said his account was disabled without explanation this past September, cutting off his access to friends and family around the world, as well as to personal memories and photos.

… Fteja, 39, said he's pressed the company for months to find out what happened, but to no avail.

"You call, they don't answer the phone. You write, they don't reply," he said - leaving him no choice but to go to court to get what he considers his property back.

… He found out he'd been cut off from his outside world this past Sept. 24, when he tried to sign on to his account, but couldn't. After a few more attempts, the site told him his account had been "disabled."

He tried to find out why, but ony got a form e-mail back two weeks later telling him he'd somehow violated the terms of the Facebook agreement. The social network typically cuts off users if they've posted objectionable content, or are suspected of spamming. Fteja said he didn't post anything objectionable, and he's no spammer.

… "Did someobody hack my account? I don't know. If it's that someobody hacked my account, Facebook should help me. If you have a problem with your AOL login, AOL helps you. Not Facebook," he said.

Since the site didn't inform his "friends" that his account had been disabled, many assumed he'd defriended them.

...His suit seeks money damages - and the restoration of his account. "While the requested service is free, the plaintiff has spent timeless hours creating content and relationships [Facebook] benefitted from," the suit says.

Facebook did not respond to e-mails for comment.



Another look at what the police can get and how they get it...

http://www.pogowasright.org/?p=20032

When can cops gain access to my personal info on Facebook?

January 28, 2011 by Dissent

G.W. Schulz reports:

…. Digital rights advocates at the Electronic Frontier Foundation have been suing federal agencies for months under the Freedom of Information Act with help from the Samuelson Clinic at UC Berkeley’s School of Law. The goal was to force open policies that explain when social networking sites can be used for government surveillance, data collection and investigations.

Results made public so far by EFF are available below for more than a dozen sites in a chart built by the Center for Investigative Reporting. Old and new policies alike are posted next to the document year, so you can compare possible changes over time. EFF argues that the variety among them shows how “social networking sites have struggled to develop consistent, straightforward policies.”

The chart makes for an interesting read.

Schulz also notes:

Verizon testified to Congress four years ago that it faced tens of thousands of requests for customer data annually. Google’s “Transparency Report,” praised by observers as a leading example of openness, lists how many it receives from countries around the globe: nearly 4,300 in the United States alone during a six-month period last year.

Facebook recently told reporter Bob McMillan that it would be releasing some information in the future, but did not specify when or exactly how they would handle it. And just today we learned that Comcast had indicated in an affidavit that it had revealed information on 36,771 customers to law enforcement over the past four years.

Read Schulz’s full report on the Center for Investigative Reporting. At the very least, consumers should be able to get clearer statements from some companies as to what their policies are about turning over information to law enforcement. Otherwise, how can consumers make an informed decision as to whether they want to use a service or trust a company with their data?



Tools for my Ethical Hackers. As I read this, I could install the software on your computer and have it quietly copy everything to my “backup” account in the Netherlands.

http://www.killerstartups.com/Web-App-Tools/safeberg-com-back-up-all-your-data?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+killerstartups%2FBkQV+%28KillerStartups.com%29

Safeberg.com - Back Up All Your Data

As the title of the review puts it, this is a new alternative for those who have decided it is time to back all their data. In this particular case, the storage process is made possible by installing and then launching a small application. This will take care of uploading all your data to the cloud, where you will be able to access it later on, at any time you want.

And (as it is only suitable) Safeberg takes care of backing up your data automatically. Once installed, it will do the job for you without you even noticing. And it is very important to mention that Safeberg can actually take care of backing up files that are open - its continuous backup capabilities make that possible.

The free version of Safeberg will let you store up to 2 GB of data...

https://www.safeberg.com/en


(Related) I wonder if I can make Hillary Clinton sound like Elmer Fudd?

http://www.screamingbee.com/product/MorphVOXJunior.aspx

MorphVOX Junior 2.7.5

MorphVOX® Junior is free voice changer software that will modify your voice to match your personality. You can sound like a man, woman, or little folk. Built-in voices and sound effects make this voice changer so convenient to use.



Closing the barn door? Can they stop distribution of changes he made to his own PS3?

http://yro.slashdot.org/story/11/01/27/2157211/Sony-Wins-Restraining-Order-Against-Geohot?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Sony Wins Restraining Order Against Geohot

"The courts have just issued a temporary restraining order against George Hotz (Geohot). Sony filed this lawsuit because they were unhappy that Geohot had released the Playstation 3 decryption keys so other people could play unsigned games on it. [Geohot is prohibited from] 'offering to the public, creating, posting online, marketing, advertising, promoting, installing, distributing, providing, or otherwise trafficking' in any software or methods for circumventing the PS3's protection methods. No longer can he 'provide links from any website to any other website' relating to such matters, or publish any information obtained by hacking the PS3. And more to the point, he can no longer 'engage in acts of circumvention of TPMS in the PS3 System to access, obtain, remove, or traffic in copyrighted works.' Pretty much he can't talk or think about the PS3 for some time."



As threatened promised...

http://tech.slashdot.org/story/11/01/28/0452216/Netflix-Compares-ISP-Streaming-Performance?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Netflix Compares ISP Streaming Performance

"The Netflix blog compared streaming performance among 20 top ISPs for the past three months. A Netflix HD stream can provide up to 4800 kbps, but the fastest American ISP, Charter, could sustain only 2667 kbps on average. Most Canadian ISPs beat that, with champ Rogers providing an average of 3020 kbps. Clearwire, Frontier, and CenturyTel were in the doghouse with under 1600 kbps."



It looks like Scott Adams has been through TSA security recently...

http://dilbert.com/strips/comic/2011-01-28/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+dilbert%2Fdaily_strip+%28Dilbert+Daily+Strip+-+UU%29



Best summary of Social Networks I have seen yet...

Twitter = I need to pee.

Facebook = I peed!

Foursquare = I'm peeing here.

Youtube = Watch this pee!

LinkedIn = I pee well.


Tuesday, January 25, 2011

Other questions to ask: Why would an employee be transporting a “backup device?” Is this a violation of policy?

http://www.phiprivacy.net/?p=5687

Grays Harbor Pediatrics notifies patients after backup device stolen from employee’s car

By Dissent, January 24, 2011

Great thanks to Grays Harbor Pediatrics for getting back to me with answers to some questions I sent them about their substitute notice concerning a stolen backup device.

According to their emailed statement to this site, the backup device was stolen from the employee’s car. In response to my question as to whether the data were supposed to have been encrypted under their policies, a spokesperson answered that “The backup device was password protected,” which was a somewhat non-responsive answer.

The statement also indicates that police were notified of the theft and that 12,009 patient records were affected.

All patients have been notified of the incident.

[From the earlier report:

Grays Harbor Pediatrics has secured all current software applications by changing passwords, implementing new encryption software and updating security protocols to ensure that no patient information may be compromised.



So, what does this suggest for Apple's future? (Are my Software Engineering students going to be much more valuable soon?)

http://apple.slashdot.org/story/11/01/25/0015216/Ex-NSA-Analyst-To-Be-Global-Security-Head-At-Apple?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Ex-NSA Analyst To Be Global Security Head At Apple

"Cnet.com reports that Apple has tapped security expert and author David Rice to be its director of global security. Rice is a 1994 graduate of the US Naval Academy and has a master's degree in Information Warfare and Systems Engineering from the Naval Postgraduate School. He served as a Global Network Vulnerability analyst (Forbes used cryptographer) for the National Security Agency and as a Special Duty Cryptologic officer for the Navy. He is executive director of the Monterey Group, a cybersecurity consulting firm. He's also on the faculty of IANS, an information security research company and works with the US Cyber Consequences Unit. In a 2008 interview with Forbes, 'A Tax On Buggy Software,' Rice talks of a 'tax on software based on the number and severity of its security bugs. Even if that means passing those costs to consumers. ... Back in the '70s, the US had a huge problem with sulfur dioxide emissions. Now we tax those emissions, and coal power plants have responded by using better filters. Software vulnerabilities, like pollution, are inevitable — producing perfect software is impossible. So instead of saying all software must be secure, we tax insecurity and allow the market to determine the price it's willing to pay for vulnerability in software. Those who are the worst "emitters" of vulnerabilities end up paying the most, and it creates an economic incentive to manufacture more secure software.'"



Another step toward ubiquitous surveillance...

http://www.allcartech.com/blog/1054140_nanny-cams-prove-popular-for-parents-of-teen-drivers

Nanny Cams Prove Popular For Parents Of Teen Drivers

… Apps and services like T-Mobile's DriveSmart encourage teens to be smarter about texting and driving. Ford's ingenious MyKey technology lets parents limit a driver's speed and the volume of the stereo. Monitors like the Progressive Snapshot work like the black boxes on airplanes, keeping track of major events. And, of course, real black box devices may be required on all cars in the U.S. in another two years.

The extreme end of this monitoring trend is the onboard video recorder. DriveCam -- arguably the most popular of such devices -- stores footage in a cache that's regularly cleared, but when it senses "erratic vehicle movements, such as extreme braking, acceleration, cornering or a collision, the device provides a video clip of what occurred the 10 seconds before and after the event." The camera then wirelessly sends that clip to DriveCam servers so that it can be shared with parents, [Might be an interesting server to hack into... Just saying... Bob] helping them coach their teens on safe driving behavior.



For my Computer Security students. To help, or not to help? Who should make this call?

http://it.slashdot.org/story/11/01/24/2017242/How-Facebook-Responded-To-Tunisian-Hacks?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

How Facebook Responded To Tunisian Hacks

"Facebook's security team opens up, shedding light on a revolution that could become a parable for Internet activism. Quoting: 'After more than ten days of intensive investigation and study, Facebook's security team realized something very, very bad was going on. The country's Internet service providers were running a malicious piece of code that was recording users' login information when they went to sites like Facebook. By January 5, it was clear that an entire country's worth of passwords were in the process of being stolen right in the midst of the greatest political upheaval in two decades. Sullivan and his team decided they needed a country-level solution — and fast. Though Sullivan said Facebook has encountered a wide variety of security problems and been involved in various political situations, they'd never seen anything like what was happening in Tunisia.'"

[From the article:

At Facebook, Sullivan's team decided to take an apolitical approach to the problem. This was simply a hack that required a technical response. "At its core, from our standpoint, it's a security issue around passwords and making sure that we protect the integrity of passwords and accounts," he said. "It was very much a black and white security issue and less of a political issue." [Oh? Bob]

The software was basically a country-level keystroke logger, with the passwords presumably being fed from the ISPs to the Ben Ali regime. As a user, you just logged into some part of the cloud, Facebook or your email, say, and it snatched up that information. If you stayed persistently logged in, you were safe. It was those who logged out and came back that were open to the attack.

Sullivan's team rapidly coded a two-step response to the problem. First, all Tunisian requests for Facebook were routed to an https server. [Note that if you were not in Tunisia, you didn't get a secure connection. Bob] The Https protocol encrypts the information you send across it, so it's not susceptible to the keylogging strategy employed by the Tunisian ISPs.

The second technical solution they implemented was a "roadblock" for anyone who had logged out and then back in during the time when the malicious code was running. Like Facebook's version of a "mother's maiden name" question to get access to your old password, it asks you to identify your friends in photos to complete an account login. [Wouldn't Big Brother love that information! Bob]



Here we go again...

http://news.cnet.com/8301-31921_3-20029423-281.html

Justice Department seeks mandatory data retention

Criminal investigations "are being frustrated" because no law currently exists to force Internet providers to keep track of what their customers are doing, the U.S. Department of Justice will announce tomorrow.

CNET obtained a copy of the department's position on mandatory data retention--saying Congress should strike a "more appropriate balance" between privacy and police concerns--that will be announced at a House of Representatives hearing tomorrow.



An inevitable reaction to Behavioral Advertising...

http://www.bespacific.com/mt/archives/026340.html

January 24, 2011

Do-Not-Track" Option Now on IE, Firefox and Chrome

National Journal: Google and Mozilla both announced that they will be adding "do-not-track" options to their Internet browsers, allowing users to prevent websites from gathering personal information and selling it to advertisers. Mozilla announced its plan Sunday with Google following suit Monday. According to a company statement, Google's "Keep My Op-Outs" feature will be available as an extension for download on its Chrome browser Monday. "We made available, for all major browsers, a downloadable browser plugin that enables you to permanently opt out of Google's advertising cookie, even if you deleted all your browser's cookies," according to the statement." Mozilla's Firefox version will be an HTTP header that will tell websites that a user wants to opt-out what's called "online behavioral advertising." "The advantages to the header technique are that it is less complex and simple to locate and use, it is more persistent than cookie-based solutions, and it doesn't rely on user's finding and loading lists of ad networks and advertisers to work," said Mozilla technology and privacy officer Alex Fowler wrote in a blog post Sunday. Microsoft announced a similar feature for its Internet Explorer in December."



“There's absolutely positively nothing wrong with our scanners-- but we're going to replace them.” I wonder if more detailed images will be captured but not displayed?

http://www.pogowasright.org/?p=19834

TSA Chief: Less intrusive scanners to be introduced

January 24, 2011 by Dissent

Ken Kaye of the Sun Sentinel reports on an interview he had with John Pistole of the TSA.

Interestingly, in a matter of days or hours, Pistole seems to have gone from saying that TSA will investigate other scanners and might introduce an alternative to the current “nudatrons” to more of a commitment that they will introduce less invasive scanners:

While detecting explosives at U.S. airports remains top priority, the TSA is also ready to ease passenger privacy concerns from body imaging scanners at checkpoints, said Pistole, 54, who spent 26 years with the FBI.

[...]

He said the TSA plans to introduce a new version of its controversial body imaging scanners. Instead of generating a fuzzy view of a passenger’s entire body, the new ones will create a generic image that highlights any suspicious items with a rectangle.

Then, both the passenger and transportation officers will be able to view that image at the same time, he said. The new machines might be used experimentally as early as this year, he added.

Read more in the Chicago Tribune.


(Related)

http://www.pogowasright.org/?p=19841

Ex-Minn. governor sues over body scans, pat-downs

January 24, 2011 by Dissent

Amy Forliti of Associated Press reports:

Former Minnesota Gov. Jesse Ventura sued the Department of Homeland Security and the Transportation Security Administration on Monday, alleging full-body scans and pat-downs at airport checkpoints violate his right to be free from unreasonable searches and seizures.

Ventura is asking a federal judge in Minnesota to issue an injunction ordering officials to stop subjecting him to “warrantless and suspicionless” scans and body searches.

Read more on Star-Tribune



A question for Economists: Are they creating a bank or their own currency? (Which is more profitable?)

http://games.slashdot.org/story/11/01/25/0547222/Facebook-To-Make-Facebook-Credits-Mandatory-For-Games?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Facebook To Make Facebook Credits Mandatory For Games

"Facebook has confirmed that it is indeed making Facebook Credits mandatory for Games, with the rule going into effect on July 1 2011. Facebook says that Credits will be the exclusive way for users to get their 'real money' into a game, but developers are still allowed to keep their own in-game currencies (FarmBucks, FishPoints, whatever). For example, Zynga can charge you 90 Facebook Credits for 75 CityCash in CityVille. ... The company acknowledges that some developers may not be pleased with the news, explaining this is why it is announcing the news five months in advance, so it can 'have an open conversation with developers.' The rule only applies to Canvas games (games that use Facebook Connect aren't affected), and while it's games only at this part, Facebook says that it eventually would like to see all apps using Facebook Credits. It's a move that's been a long time coming — there has been speculation that Facebook would do this for a year now, spurring plenty of angst in the developer community."

[From the article:

Facebook’s argument is that Credits are good for users and developers alike. There’s a higher barrier to entry if a user has to pull out their wallet to buy a different currency every time they play a new game — using the same currency lowers this bar. It also means there’s less of a lock-in factor, and Facebook can do its part to educate and promote the use of Credits to get everyone used to paying real money for virtual goods.

Of course, Facebook gets something out of it: they take an industry-standard 30% cut whenever users purchase anything with Facebook Credits. That can add up to a lot of money — we’ve heard elsewhere that Zynga is paying Facebook around $30 million a month for its Credits tax.



For my Computer Security students. How will their rules differ from police in the US?

http://yro.slashdot.org/story/11/01/25/0239250/Iran-Launches-Cyber-Police-Units?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Iran Launches Cyber-Police Units

"Iran is implementing a cyber police force to combat social networks and similar sources of 'espionage and riots.' This will likely result in more control over internet access than efforts that might hinder attacks like Stuxnet. 'Ahmadi Moghaddam said that Iran's cyber police will take on the "anti-revolutionary" dissident groups that used online social networks to organize protests against President Mahmoud Ahmadinejad following disputed elections held in 2009. "Through these very social networks in our country, anti-revolutionary groups and dissidents found each other and contacted foreign countries and triggered riots," said Ahmadi Moghaddam, referring to the protests that took place at the time.'"

[From the Inquirer:

It all sounds fairly reasonable until you read that the cyber police unit's remit includes subverting social networks that police chief Esmaeil Ahmadi Moghaddam said promote "espionage and riots".


(Related)

http://www.bespacific.com/mt/archives/026331.html

January 24, 2011

China: Student Informant System to Expand, Limiting School Autonomy, Free Expression

Via FAS: China: Student Informant System to Expand, Limiting School Autonomy, Free Expression (U//FOUO - "Unclassified // For Official Use Only")- 23 November 2010, CIA-DI-10-05021 [This report was prepared by the Open Source Works, which was charged by the Director for Intelligence with drawing on language trained analysts to mine open-source information for new or alternative insights on intelligence issues.]

  • Chinese educators and Communist Party officials are expanding the student informant system (SIS) to a growing number of Chinese universities, colleges, vocational institutes, and lower level schools. Students designated as student-informants, who report to an academic affairs department, engage in political spying on both professors and fellow students and denounce professors and students for politically subversive or unconventional views. (U//FOUO) The principal objective of the SIS is to ensure campus stability and to control the debate and discussion of politically sensitive issues. Students have had their scholarships revoked and their academic records penalized because of information provided by student informants that is sometimes highly subjective, such as facial expressions. Since 2002, the SIS has added a separate, secret system of student informants who report to university security departments. (U//FOUO) Despite some teacher and student resistance, the government appears determined to continue to use the SIS as a tool to ensure political stability on Chinese campuses, as evidenced by government studies touting its utility and effectiveness for improving education. The limited public debate on the SIS focuses on its impact on freedom of speech, the risk of spreading a culture of denunciation, and the harm the system does to cultivating talented students. (U//FOUO)"


(Related) “We can, therefore we must” can quickly get out of hand... No threat implied, of course...

http://www.pogowasright.org/?p=19873

UK: Schools’ secret reports on how parents look as they build database to fight truancy: Education chiefs keep database on hair, height and build

January 25, 2011 by Dissent

James Slack reports:

Town hall bosses are compiling secret ‘Big Brother’ databases on the appearance of school children’s parents.

Education officials say they are keeping the sensitive information in case they ever want to identify a parent for legal action.

Forms are being given to staff asking them to comment on height, hair, and build, which involves assumptions on whether a parent should be considered overweight or untidy.

Read more in the Daily Mail.



If we can keep this up, we may eventually rise to “second rate!”

http://tech.slashdot.org/story/11/01/25/0442227/Two-Thirds-of-US-Internet-Users-Lack-Fast-Broadband?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Two-Thirds of US Internet Users Lack Fast Broadband

"Two-thirds of US Internet connections are slower than 5 Mbps, putting the United States well behind speed leaders like South Korea, where penetration of so-called 'high broadband connectivity' is double the rate experienced in the United States. The United States places ninth in the world in access to high broadband connectivity, at 34% of users, including 27% of connections reaching 5 Mbps to 10 Mbps and 7% reaching above 10 Mbps, Akamai says in its latest State of the Internet Report. That's an improvement since a year ago, when the United States was in 12th place with only 24% of users accessing fast connections. But the United States is still dwarfed by South Korea, where 72% of Internet connections are greater than 5 Mbps, and Japan, which is at 60%. The numbers illustrate the gap between expectation and reality for US broadband users, which has fueled the creation of a government initiative to improve access. The US government broadband initiative says 100 million Americans lack any broadband access, and that faster Internet access is needed in the medical industry, schools, energy grid and public safety networks."



Interesting statistics...

http://www.bespacific.com/mt/archives/026332.html

January 24, 2011

OCLC - Perceptions of Libraries, 2010: Context and Community

"OCLC's newest membership report, Perceptions of Libraries, 2010, a sequel to the 2005 Perceptions of Libraries and Information Resources, is now available. The new report provides updated information and new insights into information consumers and their online habits, preferences, and perceptions. Particular attention was paid to how the current economic downturn has affected the information-seeking behaviors and how those changes are reflected in the use and perception of libraries."



Attention Al Gore!

http://idle.slashdot.org/story/11/01/24/1640224/Genghis-Khan-Historys-Greenest-Conqueror?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Genghis Khan, History's Greenest Conqueror

New research suggests that in addition to being one of history's cruelest conquerors, Genghis Khan may have been the greenest. It is estimated that the Mongol leader's invasions unintentionally scrubbed almost 700 million tons of carbon from the atmosphere. From the article: "Over the course of the century and a half run of the Mongol Empire, about 22 percent of the world's total land area had been conquered and an estimated 40 million people were slaughtered by the horse-driven, bow-wielding hordes. Depopulation over such a large swathe of land meant that countless numbers of cultivated fields eventually returned to forests. In other words, one effect of Genghis Khan's unrelenting invasion was widespread reforestation, and the re-growth of those forests meant that more carbon could be absorbed from the atmosphere." I guess everyone has their good points.



For all my students

http://news.slashdot.org/story/11/01/25/0515212/The-Rise-and-Rise-of-the-Cognitive-Elite?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

The Rise and Rise of the Cognitive Elite

"As technology advances, the rewards to cleverness increase. Computers have hugely increased the availability of information, raising the demand for those sharp enough to make sense of it. In 1991 the average wage for a male American worker with a bachelor's degree was 2.5 times that of a high-school drop-out; now the ratio is 3. Cognitive skills are at a premium, and they are unevenly distributed."



A drill-down search tool?

http://www.makeuseof.com/tag/search-search-content-linked-current-web-page/

Search Everywhere: Search The Content Linked From The Current Web Page

It is always fun to discover new great tools people can use to search. We have shared quite a few of them already, including tools that let you quickly jump to other search engines after you search Google, plugins that support search suggestions and Firefox addons that let you search faster than Google Instant.

… Search Everywhere is a great FireFox addon that allows you to search over the content linked from your web browser’s current page.



For my Lawyer friends...

http://news.yahoo.com/comics/uclickcomics/20110117/cx_crbc_uc/crbc20110117;_ylt=AiK2MQzU5GC4iDCNAdiacyfqcLQF;_ylu=X3oDMTE2MWRjdnZjBHBvcwMyBHNlYwN5bl9oaWdobGlnaHRfdmlld2VyBHNsawNwcmV2


Thursday, January 20, 2011

For my Computer Security students: “Segregation of duties” is far less likely in a small business.

http://it.slashdot.org/story/11/01/20/0228258/Hackers-Respond-To-Help-Wanted-Ads-With-Malware?from=rss

Hackers Respond To Help Wanted Ads With Malware

"The FBI issued a warning Wednesday about a new twist on a long-running computer fraud technique, known as Automated Clearing House fraud. With ACH fraud, criminals install malware on a small business' computer and use it to log into the company's online bank account. In this latest twist on the scam, the criminals are apparently looking for companies that are hiring online and then sending malicious software programs that are doctored to look like job applications. One unnamed company recently lost $150,000 in this way, according to the FBI's Internet Crime Complaint Center. 'The malware was embedded in an e-mail response to a job posting the business placed on an employment website,' the FBI said in a press release. The malware, a variant of the Bredolab Trojan, 'allowed the attacker to obtain the online banking credentials of the person who was authorized to conduct financial transactions within the company.'"



Is “suspected theft” a polite (i.e. politically correct) way to say “theft” or do they mean they could have lost the 7 million, but they think it was stolen? Easy way to find out. Ask Al Gore if he got his commission.

http://news.cnet.com/8301-11128_3-20028993-54.html

EU locks carbon market after security breach

LONDON/BRUSSELS--The European Union locked all accounts in its carbon market today, after a security breach, seeking to protect the battered reputation of the EU's main weapon against climate change.

… The European Commission suspended much of its Emissions Trading Scheme, the hub of a 92-billion-euro ($124 billion) global market, following the suspected theft of about 7 million euros of emissions permits from the Czech Republic's carbon registry.

This theft and a hacking attack on the Austrian registry on January 10 follows a raft of scandals to hit the market in the past two years, including VAT fraud, a phishing scam, and the resale of used carbon credits.



For my Computer Security students. What security was missing and what manager was responsible.

http://www.phiprivacy.net/?p=5645

Nurse Fired for Snooping in Tiger Woods’ Records Files Defamation Suit

By Dissent, January 20, 2011

David Rothenberg was the charge nurse on duty at Health Central Hospital in Ocoee on Nov. 27, 2009, as paramedics wheeled in Tiger Woods. The golfer had just crashed his Cadillac Escalade into a tree and fire hydrant outside his Isleworth home.

According to Rothenberg, within hours of Woods’s arrival, someone inside the hospital improperly gained access to the patient’s confidential medical records using the nurse’s computer login and password.

“They said it had something to do with Tiger Woods’ lab results and my name was on there,” said Rothenberg. “I’ll be honest with you, I was scared. And I said, ‘I have no idea what you’re talking about.’”

In a defamation lawsuit filed this week against Health Central, the nurse claims he signed on to the hospital computer system and then walked away to tend to some other business.

“I minimized my screen, a common practice at the hospital,” said Rothenberg.

Rothenberg claims someone else must have approached his terminal, and within 10 minutes typed in “Tiger Woods,” as well as “Ronald Williams” and “Ernest Smith,” which the nurse has been told are aliases for the golfer.

Read more on ClickOrlando.com (via @LawandLit)

This case is worth noting for several reasons:

1. The hospital detected – but did not prevent – unauthorized access to patient records.
2. An employee was disciplined for snooping in patient records.
3. The employee may not have snooped (if his story is true), but by taking shortcuts such as minimizing the window instead of logging out, may have contributed to his own grief.
4. There is no indication as to whether the hospital’s security controls automatically time users out after a certain amount of inactivity. If the nurse’s report is accurate, the system also does not automatically log people out when a window is minimized.



Oh for shame. You did something naughty, now you have to pay me... (Not a very well written article, but you get the idea...)

http://spokane.bbb.org/article/new-phone-scam-twist-reflects-2011-buzz-headliner-wikileaks-24851

NEW PHONE SCAM TWIST REFLECTS 2011 BUZZ HEADLINER, Wikileaks

… It has been brought to your regional BBB’s attention via the Central and Eastern KY BBB that there is a Wikileaks automated phone scam circulating.

… A caller reported she received an automated phone call telling her that her computer and IP address had been noted as having visited the Wikileaks site, and that there were grave consequences for this, including a $250,000 or $25,000 fine, perhaps imprisonment. It left an option for leaving a message as to how she was going to handle this and the fine payment. She figured it was a scam, and did nothing but hang up. It gave a number on caller ID of 852-604-4799. Reverse searches on the Internet don’t bring up anything but a couple subjective chat boards where people report similar calls.



Social Security numbers were never intended to be used as identification numbers, but “everyone does it.” Shouldn't someone have noticed long before now?

http://www.databreaches.net/?p=16429

Ingenix discovers it may have been exposing health service providers’ SSNs for up to 5 years

January 19, 2011 by admin

This is one of those breaches where I really don’t blame the company, which in this case is Minnesota-based Ingenix.

Ingenix provides web-based lookups so that patients can find providers in their area covered by their health plan. The provider data Ingenix uses is provided by the health plans or preferred provider plans themselves.

Ingenix recently discovered that in some cases, the health plans or preferred providers had used the providers’ Social Security Numbers as provider identification numbers. Thus, when someone looked up that provider through Ingenix’s search tool, the provider’s SSN was exposed, even though it was not identified as a Social Security Number and may not have been readily apparent as such. In some cases, providers’ SSN may have been available for five years.

Ingenix reported the issue to the New Hampshire Attorney General’s Office on January 6. Their notification letter indicates that they have offered 142 providers in New Hampshire free credit monitoring and credit restoration services. The total number of providers notified was not mentioned in the notification.

Providers can enroll for protection through a web site set up for them by ID Experts at www.cliniciannotification.com.



Interesting “business plan” If I didn't know better, I'd think the NSA was behind this company...

http://www.killerstartups.com/Web-App-Tools/recordableapp-com-record-phone-conversations?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+killerstartups%2FBkQV+%28KillerStartups.com%29

RecordableApp.com - Record Phone Conversations

As the title of the review puts it, this is a new application that will let you record phone conversations. This can be done without having to get any additional hardware, and the fact the whole application is web-based means that you are not required to download and install anything either.

All you have to do is to dial 877-395-3442 from your phone and follow the provided instructions for the next call that you make to be recorded. You will then be provided with a session code that you can use to retrieve the call.

This service is provided at no cost, and the basic functionality at play (that of recording phone conversations) will always remain like that. Some premium features might be implemented later on, but the recording of phone calls will remain unchanged.

And just in case you are wondering, all the recorded phone calls are stored on Twilio, IE a secure server. You should not worry about the safety and privacy of what you record being compromised at all. [I'm taking bet here... Bob]

http://recordableapp.com/



Sufficient? Has potential in any case...

http://www.pogowasright.org/?p=19640

Pennsylvania Court Specifies Test for Unmasking Anonymous Online Speakers

January 19, 2011 by Dissent

Ryan Mrazik writes:

Last week, the Superior Court of Pennsylvania vacated a trial court’s order directing the disclosure of the identities of six John Does who allegedly posted defamatory remarks on the internet and adopted a four-prong modified test for unmasking anonymous online speakers in the future. In Pilchesky v. Gatelli, 2001 Pa. Super. 3, Nos. 38 MDA 2009 and 39 MDA 2009 (Jan. 5. 2001), the appeals court reviewed the standards courts use to evaluate whether the identity of an anonymous online speaker should be disclosed, and concluded that “[t]here are four requirements which must be addressed [and which] are necessary to ensure the proper balance between a speaker’s right to remain anonymous and a defamation plaintiff’s right to seek redress.” These requirements, discussed further below, are

(1) notification of the John Doe defendants,

(2) sufficiency of evidence to establish a prima facie case for all elements of a defamation claim,

(3) an affidavit from the plaintiff asserting that the information is sought in good faith and is necessary to secure relief, and

(4) that the court has expressly balanced the defendant’s First Amendment rights against the strength of the plaintiff’s prima facie case.

Read more on Digestible Law.



Another opportunity lost.

http://www.pogowasright.org/?p=19630

Is There a Right of Informational Privacy? Supreme Court Avoids the Issue in NASA Opinion

January 19, 2011 by Dissent

Debra Cassens Weiss discusses today’s Supreme Court opinion in NASA v. Nelson with a focus on the court’s statements about whether there is a constitutional right to information privacy:

“We assume, without deciding, that the Constitution protects a privacy right of the sort” mentioned in two 1977 Supreme Court decisions, Alito wrote. “We hold, however, that the challenged portions of the government’s background check do not violate this right in the present case.”

The decision was 8-0, with a concurrence written by Justice Antonin Scalia and joined by Justice Clarence Thomas, SCOTUSblog reports. The concurrence argued there is no informational right to privacy.

“Like many other desirable things not included in the Constitution, ‘informational privacy’ seems like a good idea.” Scalia wrote. “But it is up to the people to enact those laws, to shape them, and, when they think it appropriate, to repeal them. A federal constitutional right to ‘informational privacy’ does not exist.”

Read more on ABAJournal.



Technology for my Criminal Justice students? Another tool to mount this on the dashboard of police cruisers (next to the license plate readers) and soon they will look like Google Earth cars...

http://www.pogowasright.org/?p=19635

Fingerprints Go the Distance – Are Our Laws Keeping Up?

January 19, 2011 by Dissent

Ian Geldard sent me a link to an article on Technology Review about a fingerprint technology that has the potential to become yet another part of public surveillance. Here are some snippets from the article so you can understand the potential for misuse:

Now a company has developed a prototype of a device that can scan fingerprints from up to two meters away, an approach that could prove especially useful at security checkpoints in places like Iraq and Afghanistan.

The device, called AIRprint, is being developed by Advanced Optical Systems (AOS). It detects fingerprints by shining polarized light onto a person’s hand and analyzing the reflection using two cameras configured to detect different polarizations.

Read the whole article on Technology Review.

As with most technology, this device clearly can be put to good use. But by now, I’ve come to look at technology and ask, “And how is this going to be misused, and with what consequences?”

So… if we have no reasonable expectation of privacy in public spaces, could these devices just record our fingerprints and match them against different databases or even add them to a database? Could law enforcement create a database on wanted criminals’ fingerprints and have these devices scan passersby to determine a match? Some might argue that that might not be a bad thing, but where is the line and our laws ready to deal with this type of possible use of surveillance technology in public spaces?



E-Mail v. Snail Mail

http://tech.slashdot.org/story/11/01/19/1814237/Mail-Service-Costs-Netflix-20x-More-Than-Streaming?from=rss

Mail Service Costs Netflix 20x More Than Streaming

"Netflix currently pays up to $1 per DVD mailed round trip, and the company mails about 2 million DVDs per day. By comparison, the company pays 5 cents to stream the same movie. In other words, the company pays 20 times more in postage per movie than it does in bandwidth. Doing some simple math, Netflix is spending some $700 million per year in physical disk postage. Rising content prices are offset by declining postage fees for the company, as more and more users choose the streaming-only option. Furthermore, subscriber revenues will continue to increase as Netflix increases the size of its streaming library."



I need to work this into my Business Classes...

http://www.mint.com/blog/goals/what-is-a-401k-01182011/?display=wide

In Graphics: What Is a 401(k) Plan?