Wednesday, August 08, 2007

Fortunately, they can call on an old graduate to nuke the thieves...

http://www.pogowasright.org/article.php?story=20070808062016103

Computers containing 10,000 SSNs are stolen

Wednesday, August 08 2007 @ 06:20 AM CDT Contributed by: PrivacyNews News Section: Breaches

Social Security numbers for over 10,000 current and former students, faculty and staff were compromised last month following the theft of two University computers, officials said Tuesday.

The computers were stolen from the Yale College Dean’s Office on July 17, in only the latest in a series of data security breaches that have plagued universities nationwide. The computers were password-protected, and were probably stolen to be sold rather than for the data stored on them, University officials said. Yale has sent letters to the individuals whose personal information may now be at risk.

A review of back-up tapes after the theft found files on the two computers that included names and Social Security numbers for approximately 10,000 current and former students and about 200 current and former faculty and staff members, but no financial account information.

Source - Yale Daily News



Walk it poor, walk out richer?

http://www.pogowasright.org/article.php?story=20070807131504331

Merrill Lynch reports computer theft

Tuesday, August 07 2007 @ 01:21 PM CDT Contributed by: PrivacyNews News Section: Breaches

Merrill Lynch & Co. Inc. said on Tuesday a computer with personal information on some employees had been stolen from one of its offices.

Merrill Lynch, the world's largest brokerage, said the theft did not involve client information.

It did not give other details and declined to say how many employees records were on the computer.

Source - Reuters

Related - CNBC's Charlie Gasparino is reporting that "According to sources, the device contained sensitive personal information, including Social Security numbers, about some 33,000 employees of the financial firm."

Related - Merrill Lynch had another incident of a stolen laptop affecting client information in February 2007. Not reported in the media, it was reported to New Hampshire under their mandatory disclosure law. They also reported other incidents involving stolen laptops to New York State in February [pdf] of 2006 and April [pdf] of 2006; those incidents were not reported in the media, either, and we would not know about them but for mandatory disclosure laws -- and Chris Walsh, who takes the time and expense to obtain the reports under FOIA.



It's all perception...

http://www.pogowasright.org/article.php?story=20070807112601700

IBM Lost His Data... A Follow Up Story

Tuesday, August 07 2007 @ 11:26 AM CDT Contributed by: PrivacyNews News Section: Breaches

... Enter George -- who is not revealing his last name. George received notification from IBM in May about the data breach, which was a surprise for George because he said he never worked for IBM. He looked into the offer but figured that it may not be worth it to him since he already pays for credit monitoring.

George e-mailed me to say he recently had a 75-minute detailed conversation with IBM about their data breach. "IBM insists on calling it "lost" data tapes," he said. Of course George said he had several questions about the investigation status and IBM's records retention policy. He had heard very little about whether someone found the tapes and what authorities were doing about it.

But George's bigger beef is that "there are problems with the way IBM is handling their data breach."

Source - InformationWeek

Related - "I've Been Mugged... One person's experience with identity theft and corporate responsibility" blog



Just look for the new Disease Center?

http://www.eweek.com/article2/0,1759,2167936,00.asp?kc=EWRSS03119TX1K0000594

$22M Worth of CDC Equipment Disappears

August 7, 2007 By Lisa Vaas

The Centers for Disease Control and Prevention reports it cannot account for $22 million worth of computers and other equipment, according to a July 12 story from the Atlanta Journal-Constitution.

Thievery is suspected [What? No alien abductions? Bob] behind some of the missing gear. According to news reports, the Inspector General's office of the U.S. Department of Health and Human Services will investigate the loss and will look into procedures and allegations of theft, at the request of a congressional oversight committee that reported "troubling" findings in June.



Listen on your iPod!

http://www.bespacific.com/mt/archives/015658.html

August 07, 2007

Two Courts Offer Digital Audio Recordings Online

Press release: "Two federal courts today became the vanguard of a pilot project to make digital audio recordings of courtroom proceedings publicly available online. The U.S. District Court in Nebraska and the U.S. Bankruptcy Court for the Eastern District of North Carolina have integrated their recording and Case Management/Electronic Case Files (CM/ECF) systems to make some audio files available the same way written files have long been available on the Internet."



Not that I've told you so...

http://techdirt.com/articles/20070807/071003.shtml

R.I.P TimesSelect?

from the good-riddance dept

The New York Times' plan to lock up its premium content known as TimesSelect was a terrible idea to begin with, and every piece of data that came out about it merely confirmed that the program was unpopular. Sure, the company drew a modest amount of revenue from it, but in exchange it severely limited the exposure of its top columnists, not to mention all of the foregone advertising revenue from the lower traffic. Now comes word that the paper is set to pull the plug on the offering (via Romenesko). At this point, it's still just a rumor, but either way, the company has to arrive at this conclusion eventually. Newspaper publishers cling to the dream that one day all of their content will be safely behind paywalls and that readers will suddenly wake up with an allergy to money and favor this model. But the trend is only moving one direction, as there's even talk about the Wall Street Journal, the one paper that's had a moderate amount of success charging for access, making its content free.



Perhaps the intimidation strategy has run its course? (Or maybe one lawyer smells blood?)

http://yro.slashdot.org/article.pl?sid=07/08/07/2316248&from=rss

Oklahoma Security Expert Attacks RIAA Claims

Posted by kdawson on Tuesday August 07, @08:50PM from the resting-on-shifting-sands dept. The Courts Music

NewYorkCountryLawyer writes "A group of Oklahoma University students has made a motion to vacate the ex parte order the RIAA had obtained compelling the university to turn over their names and addresses. In support of their motion was the expert witness declaration (PDF) of a computer security and forensics expert who essentially attacked the entire premise of the RIAA's lawsuit, characterizing the declaration upon which the RIAA based its motion as 'factually erroneous' and 'misleading.' Among other things he pointed out that 'An individual cannot be uniquely identified by an IP address,' and that 'Many computers can be connected to the Internet with identical IP addresses as long as they remain behind control points.' The students are represented by the same Oklahoma lawyer who recently obtained a award for $68,000-plus in attorneys fees against the RIAA in Capitol v. Foster."



More perspective?

http://www.eff.org/deeplinks/archives/005394.php

Op-Eds in the Aftermath of Warrantless Spying Legislation

August 07, 2007

Op-ed pages and blogs around the country are bleeding with palpable outrage, as the country wakes up to exactly what happened when Congress radically expanded surveillance powers. Most are asking the same question: faced with this atrocious legislation, how could its many opponents shrink from the moment and let it pass?

Dan Froomkin at the Washington Post has an excellent round-up of editorials and news reporting since the weekend. Here are a few choice bits from opinion pieces around the Web:

  • The NY Times Editorial Page: "[T]he problem with Congress last week was that Democrats were afraid to explain to Americans why the White House bill was so bad and so unnecessary — despite what the White House was claiming.... While serving little purpose, the new law has real dangers. It would allow the government to intercept, without a warrant, every communication into or out of any country, including the United States. Instead of explaining all this to American voters — the minimal benefits and the enormous risks — the Democrats have allowed Mr. Bush and his fear-mongering to dominate all discussions on terrorism and national security."

  • The Washington Post Editorial Page: "To call this legislation ill-considered is to give it too much credit: It was scarcely considered at all. Instead, it was strong-armed through both chambers by an administration that seized the opportunity to write its warrantless wiretapping program into law -- or, more precisely, to write it out from under any real legal restrictions."

  • The LA Times Editorial Page:"That this flawed legislation was approved by a Democratic Congress is a reminder that many in the party are still fearful that they will be labeled 'soft on terror' if they don't give this administration what it wants when it wants it. But the party may be equally injured by the perception that it won't stand up for what it believes."

  • Professor Jack Balkin:"Do not be mistaken: We are not hurtling toward the Gulag or anything that we have seen before. It will be nothing so dramatic as that. Rather, we are slowly inching, through each act of fear mongering and fecklessness, pandering and political compromise, toward a world in which Americans have increasingly little say over how they are actually governed, and increasingly little control over how the government collects information on them to regulate and control them. Slowly, secretly and imperceptibly, the mechanisms of government surveillance are being freed from methods of political control and accountability; and the liberties of ordinary citizens are being surgically removed under a potent anesthesia concocted from propaganda, fear, ignorance and apathy."

  • Salon's Glenn Greenwald: "Those who fail to defend [the Constitutional] framework, or worse, those who are passively or actively complicit in its further erosion, are all equally culpable. With each day that passes, the radicalism and extremism originally spawned in secret by the Bush presidency becomes less and less his fault and more and more the fault of those who -- having discovered what they have been doing and having been given the power to stop it -- instead acquiesce to it and, worse, enable and endorse it."

  • Meteor Blades at DailyKos, speaking directly to Democratic leadership: "Weak is bad enough. Must you be simpletons as well? How many times has he [The President] marketed this crap? How many times have you bought it? Do you also fall for those late-night $19.95 television deals for a double-set of knives that never need sharpening?"



E-Discovery Doesn't this suggest that governments can use “not government business” “excuse” to eliminate e-mails, but businesses have to keep to the “you own the computer, therefore it's your e-mail?”

http://ralphlosey.wordpress.com/2007/08/05/are-government-employee-emails-always-a-public-record/

Are Government Employee Emails Always a Public Record?

Are all emails stored on government computers automatically “public records” subject to disclosure under state and federal Freedom of Information Acts (”FOIA”)? In a sharply divided opinion the Arkansas Supreme Court recently said no. Pulaski County v. Arkansas Democrat-Gazette, Inc., No.07-669 (Ark., July 20, 2007). The majority held that it all depends upon the content of the email, not its location in a government computer. Some emails written and received by government employees are personal in nature, and have no “substantial nexus” with government activities. For that reason they are not considered “public records” and thus are not subject to disclosure under FOIA.

In this case a newspaper requested all emails from a management employee of the county who had recently been arrested and accused of embezzling $42,000. [Clearly these e-mails would relate.. Bob] Before his arrest, and the FOIA request, the employee deleted many of his emails. Deleted, but not fully erased, and certainly not gone. A computer tech for the county was able to restore them. The county then produced most of his emails, but withheld others that were “of a highly personal and private nature.” They were emails to and from a woman with whom the accused manager was having an extramarital affair. This “other woman” also happened to work for a company who was a vendor of the county.

The newspaper naturally wanted to see this emails, and argued they must be presumed to be public records because they were written by a government employee during working hours on government computers, and were located and maintained on government computers. The trial court agreed and held that:

Because the emails at issue are maintained in a public office and are maintained by public employees within the scope of their employment, they are presumed to be public records according to the Freedom of Information Act.

Based on the facts before this Court, the emails at issue are public records because they involve a business relationship of the County and are a record of the performance or lack of performance of official functions by Ron Quillin during the times when he was an employee of Pulaski County.

The county, and the girlfriend, who intervened in the suit as “Jane Doe”, asked the court to look at the withheld emails in camera. They wanted the Judge to determine whether the emails in fact pertained to County business, as he presumed, or were instead just “monkey business” with no relevance to any kind of county activities, legal or illegal. The judge declined to do so, and entered an injunction giving the county 24 hours to turn over the emails to the newspaper. The county and Jane Doe immediately appealed.

The Arkansas Supreme Court reversed and remanded the case back for the judge to read the letters in camera. The appeals court noted that since the trial court had declined to review the emails, they were not in the record, and so it was impossible to “discern whether some emails at issue were purely business emails while other emails were purely personal in nature.” The Arkansas supreme court held that:

[I]n this particular case, it is necessary to conduct an in camera review of the e-mails to discern whether these e-mails relate solely to personal matters or whether they reflect a substantial nexus with Pulaski County’s activities, thereby classifying them as public records. See Griffis, supra . Both parties agree that the definition of “public records” is content-driven. The only way to determine the content of the e-mails is to examine them. In this case, no court has reviewed the e-mails at issue. Absent such a review, we have no record on which we can determine the nature and content of the requested documents.



Why go to school when you can hack yourself a degree?

http://www.articlexplosion.com/articledetail.php?artid=19701&catid=260

Why Go to School, When You Can Be Online Learning Law?

By : Trevor Mulholland Submitted 2007-08-08 01:01:56

Now that the Internet has made higher education more accessible, why would anyone still think it was advisable to go to school to become a lawyer? If you can go online learning law, you'd be saved transportation fees, as well as the time it takes to commute from your residence to campus. Time is, in fact, one of the biggest factors that drive people to consider online schooling: some people, notably family people and working professionals, find it hard to afford the time to participate in classroom activities.

... Author Resource:- Bestwebschool.com provides you with info on Online learning education, law enforcement training onlineand much more, come take a look at http://www.bestwebschool.com/



Could be useful for all those English teachers. I wonder if they have plays about hacking>

http://www.killerstartups.com/Video-Music-Photo/thewirelesstheatrecompany--Plays-for-Your-iPod/

TheWirelessTheatreCompany.co.uk - Plays for Your iPod

posted 8 Hours 35 Minutes ago by Siri | Visit http://www.thewirelesstheatrecompany.co.uk

The Wireless Theatre Company intends to catapult theatre back into the limelight of popular conscious by offering free downloads to your iPod. They’ve recorded thoroughly modern, new plays, comedies and short stories with the latest up and coming talents. Preview Wireless’ repertoire and pick the contents you’d like to download to your computer/MP3 device. Or give it a shot yourself. If you’ve a play you’d like to get on the air, or if you’re an actor looking to gain experience, join the ranks of the Wireless Theatre Company, and get heard. Content is updated every two weeks, so make sure you come back to check out what’s new. Enjoy listening to something different.

Tuesday, August 07, 2007

Laptop theft is so common he expected to get away with it? Unfortunately, video surveillance is also common.

http://www.pogowasright.org/article.php?story=20070807070938872

(follow-up) University of Toledo professor accused in theft of hard drive

Tuesday, August 07 2007 @ 07:09 AM CDT Contributed by: PrivacyNews News Section: Breaches

A University of Toledo professor who reported his computer stolen, leading to concerns that personal information could be at risk, was charged yesterday by UT police with taking the hard drive.

Thomas Tatchell, 33, an associate professor of health education, was charged in arrest warrants filed yesterday in Toledo Municipal Court with receiving stolen property, tampering with evidence, unauthorized use of property, obstructing official business, and filing a false report.

Source - Toledo Blade

[From the article:

... He told UT police he hadn’t been in his office since May 2

... Surveillance video from the office reviewed by UT police shows Mr. Tatchell taking the computer about 9 p.m. June 8, UT spokesman Matt Lockwood said.



Isolated incident or fun new way to embarrass your competition?

http://www.pogowasright.org/article.php?story=2007080707133379

IL: Personal Information at the Center of Insurance Companies' Fight

Tuesday, August 07 2007 @ 07:13 AM CDT Contributed by: PrivacyNews News Section: Breaches

Hundreds of documents, including social security and credit card numbers are supposedly found in an insurance company's dumpster. 13 News brought you the exclusive story Monday.

Ally Insurance Agency in Rockford says its competitor, Insurance King stole client information from Ally's office. But an Insurance King representative who did not want to be named, says he found loads of unshredded papers in the trash behind the office building. He tells 13 News, "You should keep this stuff. What if a claim were to come up and they don't have any proof?" Ally Insurance Vice President Bill Kerschner says, "This is something that does not go to the bank. This stays in our office. So if he's got a copy of that, my question to him is how did he get a copy of it? Did he have somebody come in our office illegally?"

Source - 13NBC

[Should be simple enough to prove – If he has a copy, show us the original... Bob]



Do you suppose the Class Action lawyers data mine these lists?

http://www.pogowasright.org/article.php?story=20070806064415323

Data “Dysprotection:” breaches reported last week

Monday, August 06 2007 @ 06:44 AM CDT Contributed by: PrivacyNews News Section: Breaches

A recap of incidents or privacy breaches reported last week for those who enjoy shaking their head and muttering to themselves with their morning coffee. Source - Chronicles of Dissent



http://www.bespacific.com/mt/archives/015643.html

August 06, 2007

Questions and Answers on the Protect America Act of 2007

Follow-up to August 5, 2007 posting - Bill to Amend Foreign Intelligence Surveillance Act Ready for President's Signature - today's FAQ: How far does the new wiretap law go? by Declan McCullagh - "Over strong objections from civil liberties groups and many Democrats, legislators voted over the weekend to temporarily rewrite a 1978 wiretapping law that the Bush administration claimed was hindering antiterrorism investigations."

Related government documents:



Some interesting statistics

http://www.bespacific.com/mt/archives/015650.html

August 06, 2007

Consumer Report's 2007 State of the Net

"The risk associated with using the Internet remains high. Our State of the Net assesses the likelihood and impact of four leading online hazards, listed in order of incidence, based on the survey by the Consumer Reports National Research Center and our follow-up investigation."



New legal term: “Screwed up”

http://techdirt.com/articles/20070806/163525.shtml

Judge Says Jury Screwed Up In Awarding Alcatel-Lucent $1.5 Billion From Microsoft For MP3 Patents

from the so-sorry-about-that dept

Back in February, a jury told Microsoft to pay Alcatel-Lucent $1.5 billion for supposedly violating some patents Alcatel-Lucent held on MP3 technology. The case helped highlight the patent thicket around MP3 technologies, as Microsoft had licensed the technology from the creator of the MP3 technology, Fraunhofer. Back in May, as the judge was considering what to do about the jury's award, Alcatel-Lucent actually claimed that $1.5 billion wasn't enough. It appears the judge not only didn't buy that story, but didn't buy the jury's reasoning either. Today he threw out the jury's ruling, noting that Microsoft doesn't even infringe on one of the patents in question, and the other one is jointly owned by Fraunhofer, and therefore Microsoft has a legitimate license to it already. As the judge said, "The jury's verdict was against the clear weight of the evidence." As you might imagine, Alcatel-Lucent is not happy about this, calling the ruling "shocking and disturbing." So, there is likely going to be a long appeals process. However, this is the second time in recent weeks that we're seeing courts take a more reasonable approach on patents. Hopefully, it's the start of a trend.



This closely parallels what happens in organizations when the computer is unavailable. No other work gets done either.

http://techdirt.com/articles/20070803/191959.shtml

Congressional Computer Crashes: Congressional Reps Too Confused To Vote

from the oh-no! dept

It's no secret that many members of Congress seem to not understand technology issues, but they sure don't seem to like it when their own technology malfunctions. The Raw Feed points us to the news that the Congressional computer that shows vote tallies in the House of Representatives went on the fritz Friday afternoon, leaving those poor Congressional Representatives with no large monitor to tell them how their colleagues were voting. Apparently, without having this information being prominently displayed, some were concerned that they wouldn't know if their votes were being accurately counted (they were), and therefore began debating whether voting should cease until the computer was fixed. Rep. Joe Barton pointed out that each side had their own computers with tallies, and if those tallies matched up, it seemed silly to delay the voting, but eventually the Representatives decided it was just too difficult and recessed while the machines were fixed. What ever did they do before computers?



Tools & Techniques: (Take that IE users!)

http://immike.net/blog/2007/08/06/single-line-of-html-crashes-ie-6/

Single line of HTML crashes IE 6

Microsoft, Web Development August 6th, 2007

A Japanese blogger who goes by the name Hamachiya2 has discovered a single line of HTML and CSS that crashes IE 6. The line is:

If you’re brave, you can click here to try it out. The code is rendered correctly in Firefox, Safari and Opera (didn’t get a chance to try any other browsers, but presumably they work too). But in IE 6 it raises a fatal error in mshtml.dll.



Blog globally, sue locally?

http://www.law.com/jsp/article.jsp?id=1186132001827

Californian Can Be Sued in N.J. for Alleged Libel on Internet

Henry Gottlieb New Jersey Law Journal August 6, 2007

New Jersey's long-arm jurisdiction over Internet disputes just got a little longer.

A state appeals court ruled Thursday that a California resident accused of making libelous statements in a Web-based forum can be sued in New Jersey because the material was "targeted" toward a New Jersey audience. [“We could tell, 'cause they was lots a spelling errors!” Bob]

Many state courts have ruled that posting libelous material in open forums that can be seen everywhere does not vest jurisdiction in the victim's state. Where the libeler posts the comments is what counts.

But in Goldhaber v. Kohlenberg, A-5114-05, the allegedly libelous material was not only directed at a New Jersey resident; it included disparaging or insulting references to a town, a police department and the New Jersey resident's neighbors.

Given such targeting, the defendant had reason to foresee he would be hauled into court in New Jersey, [by that logic, the NJ Judges should expect to be hauled before the California courts for harassing their citizens. Bob] Judge Dorothea Wefing said, joined by Judges Lorraine Parker and Joseph Yannotti.

... Kohlenberg declined to submit to personal jurisdiction in New Jersey and the Goldhabers obtained a default judgment for $2,644 in compensatory damages and $1 million in punitive damages. Thursday's appellate decision vacated the default judgment, giving Kohlenberg an opportunity to defend himself against the libel charge, but he will have to do it in New Jersey.

... Courts in Minnesota, Connecticut, Nevada, Pennsylvania and North Carolina, to name a few, have ruled that the mere posting of messages on an open forum by a resident of one state read in a second state was not sufficient to confer jurisdiction on the latter.

In a print media case, though, the U.S. Supreme Court adopted what is known as an "effects" test. The Court granted jurisdiction in California to the libel claims of Hollywood actress Shirley Jones against the Florida-published, but internationally circulated, National Enquirer in Calder v. Jones, 465 U.S. 783 (1984).

The New Jersey court found Calder applicable in an Internet setting and went a step farther and used a so-called targeting-based analysis. It found that the posted comments not only circulated widely in New Jersey; they appeared to be targeted to a New Jersey forum.



Ubiquitous surveillance: Did you think there were exceptions?

http://www.pogowasright.org/article.php?story=20070807071118853

UK: Cameras in toilets 'a breach of privacy'

Tuesday, August 07 2007 @ 07:11 AM CDT Contributed by: PrivacyNews News Section: Non-U.S. News

MORE than 1,000 workers could take part in industrial action after CCTV cameras were installed in a factory's toilet blocks, The Northern Echo can reveal.

The move by ThyssenKrupp Automotive (TKA) Tallent Chassis, in Newton Aycliffe, County Durham, has been branded a "horrendous breach of employee privacy".

Source - The Northern Echo



Ubiquitous surveillance: Did you think there were inviolate legal protections?

http://www.fema.gov/news/newsrelease.fema?id=38452

FEMA To Contact Up To 2.2 Million Applicants Affected By Court Order Directing Release Of Personal Information

Release Date: August 6, 2007 Release Number: HQ-07-155

WASHINGTON, D.C. -- The Federal Emergency Management Agency (FEMA) is launching an effort to contact up to 2.2 million applicants for federal disaster assistance to inform them that a federal appellate court ruling requires FEMA to release certain personally identifiable information. This information would normally be protected [Except when someone wants it... Bob] under the Privacy Act and the exemption for personal privacy under the Freedom of Information Act (FOIA).

FEMA will send letters and make phone calls to notify people that the addresses of their disaster-damaged dwellings are included in the order, and must be released to certain media organizations. Information on the applicant notification timetable, distribution of information to the requesters; a state-by-state breakdown of disaster events, counties and disasters numbers may be found at www.fema.gov/individual/privacy.



Ubiquitous surveillance: Did you think it didn't apply to you?

http://www.news.com.au/story/0,23599,22203308-23109,00.html

Everyone in the world to be on website

By Helene Labriet-Gross in San Francisco August 07, 2007 12:39pm Article from: Agence France-Presse

A US web firm is preparing to launch an ambitious internet search engine it hopes will eventually track down the names of the world's six billion people.

Spock.com says it has already indexed 100 million people and is adding a million names per day on the invitation-only, beta version of its website, which will be made available to the public in mid-August.



Business model I like this one on many levels!

http://money.cnn.com/news/newsfeeds/articles/prnewswire/NYM01106082007-1.htm

AmieStreet.com Announces Series A Financing Led By Amazon.com

PR Newswire August 06, 2007: 12:01 AM EST

NEW YORK, Aug. 6 /PRNewswire/ -- AmieStreet.com, a fast-growing digital music store with a unique demand-based pricing system, announced today the completion of its Series A financing led by Amazon.com, Inc. . The amount of Amazon's investment and the terms are not disclosed.

... AmieStreet.com is the first digital music store propelled by social networking, where members of the community drive the discovery, promotion and pricing of music. All songs on AmieStreet.com start at a price of zero cents. As more people download a song the price rises, capping at $0.98.



Interesting claim. Will anyone believe it?

http://www.bespacific.com/mt/archives/015647.html

August 06, 2007

DHS Privacy Act System of Records Notice for the Automated Targeting System

Press release: "The Department of Homeland Security has posted on its web site, and will publish on Aug. 6, 2007, in the Federal Register, four Privacy Act records involving the Automated Targeting System (ATS). The records are an updated System of Records Notice (SORN), the Discussion of Public Comments Received on the SORN, a Notice of Proposed Rulemaking for Privacy Act Exemptions, and a Privacy Impact Assessment (PIA). In doing so, the department has strengthened privacy protections for all individuals traveling in to and out of the United States."



Reducing the candidates to a spreadsheet... “No nuance here!”

http://digg.com/politics/Chart_of_presidential_candidate_s_positions

Chart of presidential candidate's positions

Chart of 18 Democratic and Republican presidential candidates and their positions on 25 issues ranging from Iraq, immigration, universal heathcare, stem cell research, and same-sex marriage.

http://flickr.com/photo_zoom.gne?id=868063604&size=o



Swap early and often!

http://news.com.com/8301-10784_3-9755958-7.html?part=rss&subj=news&tag=2547-1_3-0-5

Vote-swapping Web sites are legal, appeals court (finally) says

Posted by Declan McCullagh August 6, 2007 7:08 PM PDT

It took seven years, but a federal appeals court has finally vindicated the creators of vote-swapping Web sites that let Al Gore and Ralph Nader fans support their chosen candidates in the 2000 presidential election.

The purpose of the sites, which included the now-defunct voteswap2000.com and votexchange2000.com, was to let a Nader supporter in a state where George Bush might win "swap" his vote with a Gore supporter in a state like Texas where Republican victory was practically assured.

There was no actual way to enforce the swap. But the killjoys who inhabit government bureaucracies were nevertheless unamused and came up with the bizarre claim that operating a vote-swap site was a criminal act. California Secretary of State Bill Jones even threatened to prosecute voteswap2000.com and votexchange2000.com (which immediately shut their virtual doors in response).

Fortunately, the site operators--Alan Porter, Patrick Kerr, Steven Lewis, and William Cody--had the means to force the issue and take the state of California to court. They met with little luck before a federal district judge.

But on Monday, the 9th U.S. Circuit Court of Appeals ruled (PDF) that "the websites' vote-swapping mechanisms as well as the communication and vote swaps they enabled were constitutionally protected" and California's spurious threats violated the First Amendment. The 9th Circuit also said the threats violated the U.S. Constitution's Commerce Clause.

Here's the key graf: "Both the websites' vote-swapping mechanisms and the communication and vote swaps that they enabled were...constitutionally protected. At their core, they amounted to efforts by politically engaged people to support their preferred candidates and to avoid election results that they feared would contravene the preferences of a majority of voters in closely contested states. Whether or not one agrees with these voters' tactics, such efforts, when conducted honestly and without money changing hands, are at the heart of the liberty safeguarded by the First Amendment."



Won't RIAA have a kitten?

http://www.killerstartups.com/Video-Music-Photo/anywhere--Enjoy-Your-iTunes-Library-From-Anywhere/

Anywhere.FM - Enjoy Your iTunes Library From Anywhere

posted 6 Hours 32 Minutes ago by rakohn | Visit http://www.anywhere.fm view profile

Wish you could listen to your iPod library while at work or some other place you haven’t brought your iPod or its connectors to? With Anywhere.FM you can upload your entire iTunes library with their handy uploading tool and save it for easy access from anywhere with internet. This is great if you have a song you want to play for someone or don’t have your iPod accessible, making it easy to reach the music you love from anywhere. You listen to songs via playlists, and you can listen to other members’ playlists as well. This is great for discovering new music if you like the music tastes of particular users. The site lets you know how similar your music tastes are based on your music libraries so that you have a better idea without even looking of whose playlists you might enjoy more.

Monday, August 06, 2007

Small, but local

http://cbs4denver.com/local/local_story_218072752.html

Company Leaves Boxes Of Personal Info Outside

Documents Found Outside Howard Johnson Hotel In Denver

Karlyn Tilley Reporting Aug 6, 2007 5:19 am US/Mountain

(CBS4) DENVER A hotel company left about 200 boxes of personal information about customers and employees behind the Howard Johnson along Interstate 70 near Federal Blvd. over the weekend. Workers eventually took the boxes back inside after a hotel guest called CBS4.

Denver police said they don't plan to file charges against the hotel company. It is against federal law to dump documents like the ones found outside the hotel. Officers did tell the hotel to take action after CBS4 also called police.

The documents included full credit card numbers, color copies of drivers' licenses and social security numbers.

... The company did not want to do an interview, but released a statement that said in part "these boxes were under observation at all times by motel staff and security staff. The boxes were not in the dumpster area and never were intended to be disposed."

It was apparent to CBS4 that they were not in a secure location on Sunday when viewed by reporters.



I'd be curious to here the employee's side of the story.

http://www.pogowasright.org/article.php?story=20070806062315384

(follow-up) VeriSign worker exits after laptop security breach

Monday, August 06 2007 @ 06:23 AM CDT Contributed by: PrivacyNews News Section: Breaches

VeriSign has warned workers of the theft of a laptop that contained their personal information.

The laptop was stolen from a car parked in the garage of a California worker sometime on the night of 12 July. The laptop contained personal information - name, Social Security number, date of birth, salary information, telephone numbers, and home addresses - of an unknown number of VeriSign employees

... Prompted by our follow-up questions, Verisign issued a statement explaining its response to the breach.

"VeriSign is taking the recent laptop theft very seriously. The Company initiated an investigation as soon as the theft was discovered. We have no reason to believe that the thief or thieves acted with the intent to extract and use this information. The local police have said the theft may be tied to a series of neighborhood burglaries. We disabled any access by the employee’s computer to the VeriSign network. The employee involved in this incident has since left VeriSign."

Source - The Register

Sunday, August 05, 2007

How many of these must occur before we can certify management as incompetent or negligent?

http://www.pogowasright.org/article.php?story=20070804170838215

Credit union: members' data stolen

Saturday, August 04 2007 @ 05:08 PM CDT Contributed by: PrivacyNews News Section: Breaches

A computer containing personal information on an undisclosed number of Kellogg Community Federal Credit Union members was stolen during a break-in sometime in the third week of July. In a letter dated July 25 sent to affected customers, the credit union said the computer was taken along with other items from "the offices of a vendor who has been providing services to the Credit Union."

A file containing some members' names, addresses, telephone numbers, birth dates, social security numbers and account numbers was on the computer's hard drive.

Source - Battle Creek Enquirer



...and should it be twice as easy to certify SECURITY VENDORS as incompetent and/or downright stupid!

http://www.pogowasright.org/article.php?story=20070805001052189

Laptop Theft Leaves VeriSign Employees Data Exposed

Sunday, August 05 2007 @ 12:10 AM CDT Contributed by: PrivacyNews News Section: Breaches

VeriSign, Inc., the company that operates the digital infrastructure that enables and protect billions of interactions across the world's voice and data networks every day, notified current and former employees this week that their employee data was lost in a recent laptop theft. The market leader in SSL certificates and secure web transactions left an unknown number of current and former employees' exposed to identity theft because the data on the stolen laptop was not encrypted. [Doesn't this suggest that the computer was not setup to encrypt by default? Why would a security company do that? Bob]

Source - WizBang (blog)

Related - Mandatory Disclosure to NH [PDF]



Hey, it could have been the prisoners!

http://www.pogowasright.org/article.php?story=20070804070551218

Computer breach gives prison staff access to employee information

Saturday, August 04 2007 @ 07:05 AM CDT Contributed by: PrivacyNews News Section: Breaches

Officials at a Wabash Valley prison confirmed Friday that an internal computer security breach allowed prison staff access to Social Security numbers and other identifying information of employees for an unknown period of time. [My dog ate my access logs. Bob]

Rich Larsen, public information officer for the Wabash Valley Correctional Facility in Carlisle, said a database containing Social Security numbers, dates of birth and names of people employed at the facility between 1997 and 2002 was unintentionally [but deliberately Bob] moved “from a secure private drive that was accessible only by the human resources department to a shared directory that could be accessed by other employees here.”

Source - Tribstar.com

[From the article:

Larsen said officials are not sure how long the database was accessible.

“We are estimating the length of the breach to be as short as a week to up to nine months,” he said.

So they don't know when the data was moved or who accessed it. They probably have no record of who moved it, either. Makes you wonder if they know where their prisoners are... Bob]



Training children to be second class citizens. (Some folks got more rights than others!) This is a good case to push the law -- no one will have much sympathy for a sex abuser.

http://www.pogowasright.org/article.php?story=2007080407462189

Court: Parents can record kids' calls

Saturday, August 04 2007 @ 07:46 AM CDT Contributed by: PrivacyNews News Section: Minors & Students

The Iowa Supreme Court ruled Friday that parents can wiretap their children's telephone conversations.

The court said conversations a Marshalltown man recorded between his daughter and the teacher he suspected of sexually abusing her will be admissible in court, stating that guardians may record their minor children's telephone conversations if it is necessary for the child's welfare.

Source - Des Moines Register

[The decision: http://www.judicial.state.ia.us/Supreme_Court/Recent_Opinions/20070803/06-0565.pdf



Interesting NPR comment: Would the Democrats like the President to call them back to pass an anti-terrorist bill?

http://www.reuters.com/article/newsOne/idUSN0328188520070804

Bush urges House to pass spy bill

Sat Aug 4, 2007 4:05PM EDT By Thomas Ferraro

WASHINGTON (Reuters) - U.S. President George W. Bush pushed for approval by Congress on Saturday of the temporary expansion of his power to conduct electronic surveillance without a court order.

Bush hailed the Senate for passing the bill, denounced as excessive by civil liberties groups, which would allow eavesdropping on communications between U.S. residents and people abroad. He urged the House of Representatives to provide needed concurrence before lawmakers begin a monthlong recess.

But it was not immediately clear if the Democratic-led House would approve the Senate measure or try again to pass a bill rejected by Republicans on Friday. The Democratic bill would have expanded the electronic surveillance program, but also required greater court scrutiny.

"We're looking at our options," a Democratic aide said. Another said, "Likely we will pass it (the Senate bill)," but party leaders were planning their course of action as many lawmakers packed up to go home.



Do you suppose this author will get free books on Privacy next year?

http://www.concurringopinions.com/archives/2007/08/noteworthy_priv.html

Noteworthy Privacy Law Scholarship: 2006

posted by Daniel J. Solove August 02, 2007

As there are tons of new scholarly works in the privacy law field each year, I thought it might be useful to point out a few books and articles that I found particularly interesting and useful from the past year. This post will cover only those books and articles published in 2006.



Tools & Techniques There are thousands of articles like this on the Internet.

http://www.hackthissite.org/articles/read/649

Rooting

Published by: paranoiahax, on 2007-05-31 20:56:16

An article on gaining root to a remote system:

Too often have I seen articles that claim to teach how to hack into a server, but all they do is just show you how to scan open ports, and many many people have no idea what to do with an open port. So I am going to show you pretty much all the basics, to get you well on your way to your first ever successful hack of a server, giving you root privileges.



Arthur C. Clarke wrote (years ago) about third world countries bypassing the technology the US uses for the latest available... Here is another example – while cities dither about WiFi, technology has moved on.

http://news.yahoo.com/s/pcworld/20070804/tc_pcworld/135367

Public Wi-Fi: Past its Prime?

Tim Wilson, Network World Canada Sat Aug 4, 12:00 PM ET

For the average Internet user, wireless means Wi-Fi. Most routers used in offices and at hot-spots in local cafes and-libraries use Wi-Fi technology. However, the increasing development and use of the fledgling WiMAX technology has some questioning whether cities should invest in the older standard.



...from back in the days when government did something useful...

http://science.slashdot.org/article.pl?sid=07/08/04/125207&from=rss

Digitized Apollo Flight Films Available Online

Posted by CowboyNeal on Saturday August 04, @10:07AM from the earth-to-the-moon dept. NASA Space Science

Pooua writes "SpaceRef reports that NASA and Arizona State University have teamed up to offer all of NASA's Apollo lunar films online at no charge. The images are scanned from the original films at high resolution, then offered as 16-bit TIFF or 8-bit PNG or ISIS files. The project is expected to take 3 years, but some images are already available. The ASU-NASA website is located at the Arizona State University Apollo Image Archive."



Mostly for my Web Site class, but too much fun to ignore...

http://www.killerstartups.com/Blogging-Widgets/largeanimal--Create-game-widgets/

LargeAnimal.com Playwidgets - Create game widgets

posted 7 Hours 42 Minutes ago by rachsig | Visit http://www.largeanimal.com/playwidgets/

Jazz up your MySpace page or personal website with Playwidgets, brought to your by LargeAnimal, a gaming site.



Most successful students will already know about this site, the rest won't go there unless force is used.

http://www.killerstartups.com/Web20/cafescribe--E-Textbooks/

CafeScribe.com - E-Textbooks

posted 8 Hours 1 Minutes ago by rachsig | Visit http://www.cafescribe.com/

CafeScribe is a site that that lets you download electronic copies of your textbook, so you can have a copy on your home computer or laptop. It's handy because you don't have to lug around heavy books, like when you go to the library to study. Also it makes it easy to cite the texts with you are writing papers. you join for free, and then you purchase the books. They are offered at about half the price as you would find online or at a bookstore.

... You can also add friends to your CafeScribe network and publish your school notes so that they are shared.

How many of these must occur before we can certify management as incompetent or negligent?

http://www.pogowasright.org/article.php?story=20070804170838215

Credit union: members' data stolen

Saturday, August 04 2007 @ 05:08 PM CDT Contributed by: PrivacyNews News Section: Breaches

A computer containing personal information on an undisclosed number of Kellogg Community Federal Credit Union members was stolen during a break-in sometime in the third week of July. In a letter dated July 25 sent to affected customers, the credit union said the computer was taken along with other items from "the offices of a vendor who has been providing services to the Credit Union."

A file containing some members' names, addresses, telephone numbers, birth dates, social security numbers and account numbers was on the computer's hard drive.

Source - Battle Creek Enquirer



...and should it be twice as easy to certify SECURITY VENDORS as incompetent and/or downright stupid!

http://www.pogowasright.org/article.php?story=20070805001052189

Laptop Theft Leaves VeriSign Employees Data Exposed

Sunday, August 05 2007 @ 12:10 AM CDT Contributed by: PrivacyNews News Section: Breaches

VeriSign, Inc., the company that operates the digital infrastructure that enables and protect billions of interactions across the world's voice and data networks every day, notified current and former employees this week that their employee data was lost in a recent laptop theft. The market leader in SSL certificates and secure web transactions left an unknown number of current and former employees' exposed to identity theft because the data on the stolen laptop was not encrypted. [Doesn't this suggest that the computer was not setup to encrypt by default? Why would a security company do that? Bob]

Source - WizBang (blog)

Related - Mandatory Disclosure to NH [PDF]



Hey, it could have been the prisoners!

http://www.pogowasright.org/article.php?story=20070804070551218

Computer breach gives prison staff access to employee information

Saturday, August 04 2007 @ 07:05 AM CDT Contributed by: PrivacyNews News Section: Breaches

Officials at a Wabash Valley prison confirmed Friday that an internal computer security breach allowed prison staff access to Social Security numbers and other identifying information of employees for an unknown period of time. [My dog ate my access logs. Bob]

Rich Larsen, public information officer for the Wabash Valley Correctional Facility in Carlisle, said a database containing Social Security numbers, dates of birth and names of people employed at the facility between 1997 and 2002 was unintentionally [but deliberately Bob] moved “from a secure private drive that was accessible only by the human resources department to a shared directory that could be accessed by other employees here.”

Source - Tribstar.com

[From the article:

Larsen said officials are not sure how long the database was accessible.

“We are estimating the length of the breach to be as short as a week to up to nine months,” he said.

So they don't know when the data was moved or who accessed it. They probably have no record of who moved it, either. Makes you wonder if they know where their prisoners are... Bob]



Training children to be second class citizens. (Some folks got more rights than others!) This is a good case to push the law -- no one will have much sympathy for a sex abuser.

http://www.pogowasright.org/article.php?story=2007080407462189

Court: Parents can record kids' calls

Saturday, August 04 2007 @ 07:46 AM CDT Contributed by: PrivacyNews News Section: Minors & Students

The Iowa Supreme Court ruled Friday that parents can wiretap their children's telephone conversations.

The court said conversations a Marshalltown man recorded between his daughter and the teacher he suspected of sexually abusing her will be admissible in court, stating that guardians may record their minor children's telephone conversations if it is necessary for the child's welfare.

Source - Des Moines Register

[The decision: http://www.judicial.state.ia.us/Supreme_Court/Recent_Opinions/20070803/06-0565.pdf



Interesting NPR comment: Would the Democrats like the President to call them back to pass an anti-terrorist bill?

http://www.reuters.com/article/newsOne/idUSN0328188520070804

Bush urges House to pass spy bill

Sat Aug 4, 2007 4:05PM EDT By Thomas Ferraro

WASHINGTON (Reuters) - U.S. President George W. Bush pushed for approval by Congress on Saturday of the temporary expansion of his power to conduct electronic surveillance without a court order.

Bush hailed the Senate for passing the bill, denounced as excessive by civil liberties groups, which would allow eavesdropping on communications between U.S. residents and people abroad. He urged the House of Representatives to provide needed concurrence before lawmakers begin a monthlong recess.

But it was not immediately clear if the Democratic-led House would approve the Senate measure or try again to pass a bill rejected by Republicans on Friday. The Democratic bill would have expanded the electronic surveillance program, but also required greater court scrutiny.

"We're looking at our options," a Democratic aide said. Another said, "Likely we will pass it (the Senate bill)," but party leaders were planning their course of action as many lawmakers packed up to go home.



Do you suppose this author will get free books on Privacy next year?

http://www.concurringopinions.com/archives/2007/08/noteworthy_priv.html

Noteworthy Privacy Law Scholarship: 2006

posted by Daniel J. Solove August 02, 2007

As there are tons of new scholarly works in the privacy law field each year, I thought it might be useful to point out a few books and articles that I found particularly interesting and useful from the past year. This post will cover only those books and articles published in 2006.



Tools & Techniques There are thousands of articles like this on the Internet.

http://www.hackthissite.org/articles/read/649

Rooting

Published by: paranoiahax, on 2007-05-31 20:56:16

An article on gaining root to a remote system:

Too often have I seen articles that claim to teach how to hack into a server, but all they do is just show you how to scan open ports, and many many people have no idea what to do with an open port. So I am going to show you pretty much all the basics, to get you well on your way to your first ever successful hack of a server, giving you root privileges.



Arthur C. Clarke wrote (years ago) about third world countries bypassing the technology the US uses for the latest available... Here is another example – while cities dither about WiFi, technology has moved on.

http://news.yahoo.com/s/pcworld/20070804/tc_pcworld/135367

Public Wi-Fi: Past its Prime?

Tim Wilson, Network World Canada Sat Aug 4, 12:00 PM ET

For the average Internet user, wireless means Wi-Fi. Most routers used in offices and at hot-spots in local cafes and-libraries use Wi-Fi technology. However, the increasing development and use of the fledgling WiMAX technology has some questioning whether cities should invest in the older standard.



...from back in the days when government did something useful...

http://science.slashdot.org/article.pl?sid=07/08/04/125207&from=rss

Digitized Apollo Flight Films Available Online

Posted by CowboyNeal on Saturday August 04, @10:07AM from the earth-to-the-moon dept. NASA Space Science

Pooua writes "SpaceRef reports that NASA and Arizona State University have teamed up to offer all of NASA's Apollo lunar films online at no charge. The images are scanned from the original films at high resolution, then offered as 16-bit TIFF or 8-bit PNG or ISIS files. The project is expected to take 3 years, but some images are already available. The ASU-NASA website is located at the Arizona State University Apollo Image Archive."



Mostly for my Web Site class, but too much fun to ignore...

http://www.killerstartups.com/Blogging-Widgets/largeanimal--Create-game-widgets/

LargeAnimal.com Playwidgets - Create game widgets

posted 7 Hours 42 Minutes ago by rachsig | Visit http://www.largeanimal.com/playwidgets/

Jazz up your MySpace page or personal website with Playwidgets, brought to your by LargeAnimal, a gaming site.



Most successful students will already know about this site, the rest won't go there unless force is used.

http://www.killerstartups.com/Web20/cafescribe--E-Textbooks/

CafeScribe.com - E-Textbooks

posted 8 Hours 1 Minutes ago by rachsig | Visit http://www.cafescribe.com/

CafeScribe is a site that that lets you download electronic copies of your textbook, so you can have a copy on your home computer or laptop. It's handy because you don't have to lug around heavy books, like when you go to the library to study. Also it makes it easy to cite the texts with you are writing papers. you join for free, and then you purchase the books. They are offered at about half the price as you would find online or at a bookstore.

... You can also add friends to your CafeScribe network and publish your school notes so that they are shared.