Thursday, May 22, 2008

Another ratio question. Does Tennessee represent only 1/200ths of their business?

http://www.phiprivacy.net/?p=418

HealthSpring says laptop with personal data stolen

Wendy Lee reports: May-22-2008

Nashville-based managed care company HealthSpring Inc. said Wednesday a laptop computer containing personal information of about 450 state residents was stolen in March.

The laptop, believed to contain names, dates of birth and social security numbers of about 9,000 individuals, was stolen from a HealthSpring employee’s locked car on March 30 in Houston, the company said.

[...]The stolen laptop was password protected but not encrypted….

Full story - The Tennessean



Interesting only for the Colorado connection

http://www.pogowasright.org/article.php?story=20080522054254263

NJ: ID thieves hit Elmer auto dealer employees

Thursday, May 22 2008 @ 05:42 AM EDT Contributed by: PrivacyNews News Section: Breaches

Several employees at Country Ford in Elmer, including owner Brent Lilliston, were apparently victims of identity thieves, the auto dealer said Wednesday.

As many as 11 service technicians were affected by an information breach that stretches back at least six months, one of the victims said.

Service technician Colt Gibson, 24, of Crest Avenue in Millville, reported the incident to police Tuesday. He indicated it occurred several months ago and this week he was notified that someone used his name to apply for a Kohl's credit card but was turned down because Gibson had put a lock on his credit report.

In a telephone interview Wednesday afternoon, Gibson said names, addresses, Social Security numbers and home phone numbers of the 11 technicians "somehow ended up in Colorado."

Source - The Daily Journal

[From the article:

"We have no idea how it happened," Gibson said.

... "It looks like the information was taken from years ago and in the last six months things started to pop," Nelson said.

... When he filed the police report, Gibson told investigators the dealership assured its employees the security breach had been eliminated. [Even though “we have no idea how it happened?” Bob



Why would this device be more secure than any other?

http://www.pogowasright.org/article.php?story=20080521070204808

iPhone forensics toolkit raises questions about privacy

Wednesday, May 21 2008 @ 07:02 AM EDT Contributed by: PrivacyNews News Section: Other Privacy News

You may have reason to worry about your personal data resurfacing if you've returned an iPhone back to the Apple Store or sold it on eBay. It appears one developer discovered a serious privacy issue with refurbished iPhones after creating a forensics toolkit that allowed him to recover deleted email, contact information, and other personal data previously stored on his iPhone.

On his website, Jonathan Zdziarski describes how this is possible.

Source - Yahoo! Tech

[From the article:

This means that while the average Joe may not have the know-how to recover deleted files yet, someone who does can easily have access to any data you've ever stored on the phone.


Now this is NOT new, so what's their excuse? (and wouldn't they still need to disclose the “breach?”)

http://www.pogowasright.org/article.php?story=20080521083712396

OKC buyer finds sensitive information on server

Wednesday, May 21 2008 @ 08:37 AM EDT Contributed by: PrivacyNews News Section: Breaches

The Oklahoma Corporation Commission is removing hard drives from all surplus computer equipment after a server containing the names and Social Security numbers of thousands of residents was sold at an auction recently.

Oklahoma City resident Joe Sills discovered more than 5,000 Social Security numbers after purchasing the server and other surplus state computer equipment at an auction last month.

Source - Tulsa World



When AG's start making noises like this, it could mean 1) they are running for re-election, 2) they want to make a “name” as 'tough on corporations' in preparation for a run for Governor or 3) their name was on that tape.

http://www.pogowasright.org/article.php?story=20080521142150916

People's customers' data lost (update1)

Wednesday, May 21 2008 @ 02:21 PM EDT Contributed by: PrivacyNews News Section: Breaches

Connecticut Attorney General Richard Blumenthal warned today that thousands of state residents' Social Security numbers and bank account information may have been lost when unencrypted computer back-up tapes disappeared in February.

According to Blumenthal, account holders and share owners of People's United Bank are among the 4.5 million consumers whose personal data was on the tapes.

Blumenthal demanded more information about the incident in a letter to Steven Dalmatch, general counsel of The Bank of New York Mellon Shareowner Services. A spokesman for People's United could not be immediately reached for comment.

Source - Connecticut Post

Related - Statement of Connecticut Attorney General: Data breach at New York bank possibly affecting hundreds of thousands of CT consumers
Related - AP: Bank of N.Y. works with attorney general on security breach
Related - The Day: Bank data breach exposes information on 4.5 million accounts
Related - WTNH: Security breach exposes Social Security, bank account numbers
Previous coverage on PogoWasRight.org: here and here



So where do I go for a refund? A case of “undue reliance?” How do you differentiate between stupidity and criminal intent? (The comments are very interesting...)

http://it.slashdot.org/article.pl?sid=08/05/21/2045247&from=rss

Coding Flaws Caused Moody's Debt Rating Errors

Posted by timothy on Wednesday May 21, @05:31PM from the uh-oh-spaghettios dept. Bug Programming The Almighty Buck News

An anonymous reader writes

"The Financial Times has the story that billions in incorrect AAA ratings given out by Moody's were the result of a coding error in its computer models. 'Internal Moody's documents seen by the FT show that some senior staff within the credit agency knew early in 2007 that products rated the previous year had received top-notch triple A ratings and that, after a computer coding error was corrected, their ratings should have been up to four notches lower.'"



Google's spin on the issue...

http://googlepublicpolicy.blogspot.com/2008/05/google-health-privacy-and-hipaa.html

Google Health, privacy, and HIPAA

Monday, May 19, 2008 at 6:32 PM Posted by Mike Yang, Senior Product Counsel

... Unlike a doctor or health plan, Google Health is not regulated by HIPAA because Google does not provide health care services.



Interesting. By the same logic, would you go to jail if I claimed YOU had child porn? (Is one free speech and the other crying “Fire” in a crowded theater?)

http://techdirt.com/articles/20080520/1749381182.shtml

Supreme Court Says Telling People You Have Child Porn Is Illegal... Even If You Don't Have It

from the something-doesn't-seem-right-there dept

I certainly have absolutely no problem with the government going after folks involved in child pornography. [Amen! Bob] However, they shouldn't stretch the laws so far as to make it ridiculous. Unfortunately, however, it looks like the Supreme Court is allowing them to do so. In a recent decision, the Supreme Court okayed a law that makes it illegal to simply try to convince someone else that child pornography is available -- even if it is not. That is, merely telling someone that there is child pornography at a certain link could be considered illegal. Two justices dissented, but seven said the law was fine. The lower court seemed to have it right, noting how problematic it was that this law would apply to "any promoter -- be they a braggart, exaggerator, or outright liar -- who claims to have illegal pornography." However, the justices, led by Justice Scalia, seem to say that the law would only be used in cases where it made sense. Of course, given how often we see laws twisted beyond their original purpose, this seems difficult to believe.



Better than nothing. I wonder how they prioritize?

http://www.pogowasright.org/article.php?story=20080522060742733

Feds encrypt 800,000 laptops; 1.2 million to go

Thursday, May 22 2008 @ 06:07 AM EDT Contributed by: PrivacyNews News Section: Fed. Govt.

In the last year, agencies have purchased 800,000 licenses for encryption software through the federal Data at Rest (DAR) Encryption program, which is run jointly by the General Services Administration and the U.S. Department of Defense.

... While sales on the DAR Encryption program are stronger than anticipated, federal officials admit they haven’t secured all of their laptops, handhelds and removable drives yet.

``It was originally thought that there would be about 1 million laptops in DoD and one million in civilian agencies. We roughly came up with the number of 2 million laptops. However that number is informal. It’s constantly being expanded and contracted,’’ says David Hollis, program manager for the Defense Department’s Data at Rest Tiger Team.

Source - NetworkWorld


If the UK's National Health Service alone has 700,000 devices, the the US Government-wide estimate of 2,000,000 suspect?

http://www.pogowasright.org/article.php?story=2008052206123147

UK: NHS to encrypt 700,000 devices

Thursday, May 22 2008 @ 06:12 AM EDT Contributed by: PrivacyNews News Section: Non-U.S. News

Connecting for Health, the NHS agency behind the troubled National Programme for IT, is to purchase 700,000 encryption licences for its desktop PCs, laptops and smartphones.

The encryption software, which will be provided by McAfee, should help limit the impact of any further data loss.

Source - SC Magazine Thanks to Brian Honan for this link.



The saga continues...

http://tech.slashdot.org/article.pl?sid=08/05/21/2211201&from=rss

Feds Now Allowed to Use Internet

Posted by samzenpus on Wednesday May 21, @07:35PM from the welcome-to-the-web dept. The Internet It's funny. Laugh. Security

fast66 writes

"Nextgov reports that a new court order allows the Department of the Interior to connect to the Internet, six years after the federal agency was ordered to disconnect. District Judge James Robertson said, "I find that the consent order is of no further use and must be vacated," Robertson wrote in his ruling. "The . . . disconnected offices and bureaus may be connected." He added that his ruling was based not on evidence but "on a legal conclusion that it is not my role to weigh IT security risks."

[Robertson's ruling:

http://www.usdoj.gov/civil/cases/cobell/docs/pdf/05142008_order.pdf



It isn't always wise to be on the cutting (bleeding?) edge.

http://www.law.wisc.edu/blogs/wisblawg/2008/05/twitter_and_the_legal_professi.html

Twitter and the Legal Profession

There has been a lot of discussion lately about Twitter and its applications for the legal profession. Twitter is a free micro-blog service in which people answer the question "What are you doing?" in 140 characters or less.

Although many have questioned whether such a tool could have any practical application at all, for better or worse, some enterprising individuals have indeed applied it in legal settings. Here's a sample of some of the ways in which Twitter is being used:

  • Live Coverage from the Courtroom - From journalists:
    From the ABA Journal:



Way to go, Judge! (No one else is teaching cell phone etiquette ...)

http://www.news.com.au/story/0,23599,23735155-421,00.html

Teenage boy jailed for taking call in court

By Phoebe Stewart May 21, 2008 02:53pm

A MAGISTRATE has jailed a teen for answering his mobile phone in court.



How I grade my students.

http://www.phdcomics.com/comics/archive/phd051608s.gif

Wednesday, May 21, 2008

I think this is a new low... They not only lost the disc, but it was their ONLY COPY?

http://www.phiprivacy.net/?p=412

May-20-2008

NHS disc containing sensitive data lost

Caroline Gammell reports in the Telegraph:

A computer disc containing the medical records of more than 38,000 NHS patients went missing when it was sent to a software company to be backed up - in case the records got lost.

The information, which dates back 10 years, was mislaid somewhere between London and Sandown Health Centre on the Isle of Wight.

It was given to courier company City Link in March, but the health centre only spotted it was missing in May.

Full story - Telegraph Related - The Press Association



Increasingly common?

http://www.pogowasright.org/article.php?story=20080520184358499

LendingTree LLC Sued Over Customer Information Data Breach

Tuesday, May 20 2008 @ 06:43 PM EDT Contributed by: PrivacyNews News Section: Breaches

LendingTree LLC, the online mortgage unit of IAC/ InteractiveCorp. (IACI), has been sued over a security breach in which some employees allegedly allowed mortgage lenders to gain access to confidential customer information.

The lawsuit, filed in U.S. District Court in Manhattan on Friday, alleges that the Charlotte mortgage referral company failed to adequately safeguard confidential customer information contained in its customer loan request forms and that data was accessed and stolen by several LendingTree employees.

"As a result of defendant's actions, millions of its customers have had their personal confidential information compromised, have had their privacy rights violated, have been exposed to the risk of fraud and have otherwise suffered damages," the lawsuit said.

Source - CNN Money



How bad was it? Would it scale up to have a similar impact on the US?

http://news.cnet.com/8301-10789_3-9948720-57.html?part=rss&subj=news&tag=2547-1_3-0-5

The Estonia cyberwar: One year later

Posted by Robert Vamosi May 20, 2008 2:34 PM PDT

One year ago, the Estonian government moved a war memorial honoring Russian-Estonians who died fighting the Nazis, a move that may have triggered what some believe is the first instance of a sustained, international cyberwar.

Now, Gadi Evron, a security evangelist for Beyond Security who was in Estonia at the time of the attacks, has revisited the events with an article in the Georgetown Journal of International Affairs and reprinted here online (PDF).



Tools & Techniques. It takes some thought to figure this stuff out...

http://www.f-secure.com/weblog/archives/00001440.html

Phishing Piers on Legitimate Sites

Posted by Sean @ 10:52 GMT Wednesday, May 21, 2008

... However, even obscure URLs can be taken offline quickly as they have no legitimate functions. Sending a message to the host providers with a request that the entire bogus site be taken offline does the trick.

So what next?

Instead of setting up their own sites, we're seeing more and more evidence of phishing from hacked sites; legitimate sites that are unknowingly hosting phishing. And then the site cannot simply be pulled offline without collateral damage to the legitimate business. So the website's administrator must be contacted to repair the damage.

Sites such as bbcsales.com, a 15 year old business with a long-standing Web presence.



Tools & Techniques These “how to” videos are useful...

http://digg.com/gadgets/How_To_Eavesdrop_on_Bluetooth_Conversations

How To Eavesdrop on Bluetooth Conversations watch!

5min.com — A demo on how to attack and capture audio on a Bluetooth headset using a handheld Nokia.

http://www.5min.com/Video/How-To-Eavesdrop-on-Bluetooth-Conversations-925061



Coming soon to a server near you?

http://hardware.slashdot.org/article.pl?sid=08/05/20/1248231&from=rss

New 'Phlashing' Attack Sabotages Hardware

Posted by timothy on Tuesday May 20, @09:29AM from the not-so-nice dept. Security Hardware IT

yahoi writes

"A new type of denial-of-service attack, called permanent denial-of-service (PDOS), damages a system so badly that it requires replacement or reinstallation of hardware. A researcher has discovered how to abuse firmware update mechanisms with what he calls 'phlashing' — a type of remote PDOS attack."



The data is there, why not use it? Information overload?

http://www.cnet.com/8301-13880_1-9949185-68.html?part=rss&tag=feed&subj=Workers'Edge

Get the low-down on the sites you visit with CallingID

Posted by Dennis O'Reilly May 21, 2008 12:01 AM PDT

I used to think the last thing I needed was another browser toolbar. But now I gladly sacrifice a little screen real estate to find out who owns the sites I visit, where they're located, and whether they pass muster with the security checkers.

That's what you get with CallingID, an add-on for Internet Explorer and Firefox that adds a mult-hued toolbar to the browsers. Along with use of green, yellow, and red to signify the site's safety, the toolbar shows the owner and location of the site.



We love our customers... When Microsoft pushes (forces) the update to SP3, your browser will die?

http://www.informationweek.com/news/windows/operatingsystems/showArticle.jhtml?articleID=207801330

Windows XP SP3 Chokes On ISP Versions Of Internet Explorer 7

Specifically, XP3 runs a version of an essential dynamic-link library file called XMLLite.dll that's not compatible with versions of IE7 released prior to October.

By Paul McDougall InformationWeek May 20, 2008 02:09 PM

Private label versions of Microsoft's Internet Explorer 7 browser, including those provided to customers by Internet Service Providers Comcast and Qwest, are prone to crash during installation on computers running Windows XP SP3 because they tend to be outdated, Microsoft is warning.



We love our customers... “We are actually blocking the only indication that you are being monitored, but we'll keep selling your information to our advertisers and charging them as if you were still looking at the ads!”

http://www.pogowasright.org/article.php?story=2008052018482763

UPDATE: Charter Will Track Your Internet Activity Regardless Of Whether You Opt Out

Tuesday, May 20 2008 @ 06:48 PM EDT Contributed by: PrivacyNews News Section: Businesses & Privacy

Last week, we wrote about Charter's decision to begin tracking its users internet activity and inserting targeted ads. One of our readers wrote in to let us know he discovered that Charter's insecure opt-out solution—downloading a cookie that must be downloaded for each user and browser, and downloading it again whenever the cache is cleared—only blocks the ads from showing up; it doesn't block Charter from monitoring users' searches and web activity.

Source - The Consumerist


Related. Maybe we can get versions for any company that tracks us on the Internet... (No doubt this will escalate into an all out arms race...)

http://www.pogowasright.org/article.php?story=20080520070402684

Privacy group launches Phorm spoiler

Tuesday, May 20 2008 @ 10:04 AM EDT Contributed by: PrivacyNews News Section: Internet & Computers

A privacy group has launched a new piece of software that it claims will make the data collected by the Phorm advertising service "absolutely worthless".

The AntiPhorm group - which describes itself as "a loose conglomeration of concerned individuals comprised of artists, programmers and designers" - says it wants to prevent ISPs from profiting from their customers' personal surfing habits.

Source - PC Pro



A simple way to show off the new puppy?

http://www.killerstartups.com/Comm/Ekkotv---Flash-Based-Video-Chat/

Ekko.tv - Flash Based Video Chat

ekkoTV is a new flashed based video chat service. It pulls your contacts from AIM, Yahoo, Google, and/or MSN to create buddy lists. Clicking on the name of your friend will send out an invite; once they’ve received the invitation, a webpage for your chat is opened. Users can chat with up to two other people. The platform can be embedded on blogs and personal websites to create interesting dialogues. Users will of course need a webcam and a decent internet connection to take advantage of ekkoTV. Using the video chat app is absolutely free. Sign up is required.

http://www.ekko.tv/



Could be useful...

http://www.killerstartups.com/Web20/Vocabulixcom----Learn-Spanish-and-German-the-Easy-Way/

Vocabulix.com - Learn Spanish and German the Easy Way

To avoid mistakes like the infamous Kennedy flub, “Ich bin ein Berliner” (roughly, ‘I’m a jelly donut’), you may want to brush up on those language skills. And why not try something free, something web-based, and something multilingual like Vocabulix. Granted, Vocabulix focuses on a trio of languages—English, Spanish, and German—but the spread is comprehensive. You can build vocabulary with a series of customizable (level, topic, type) practices. Or, you can focus on your verb skills with Vocabulix’s verb drills. Even those tricky conjugations are available for practice. Of course, there’s the requisite networking touch as well. You can find and connect with language buddies for extra practice, or create group lessons. You can find language schools, buy cds and books and post questions if you need extra help. And you don’t even have to leave your house.

http://www.vocabulix.com/

Tuesday, May 20, 2008

Today does not look like a good day for the new Privacy Officer.

http://www.pogowasright.org/article.php?story=20080519123314347

LPL Financial hacked in 2007 for "pump and dump" stock scheme; over 10,000 customer accounts exposed

Monday, May 19 2008 @ 01:12 PM EDT Contributed by: PrivacyNews News Section: Breaches

Almost a year after becoming aware that hackers had compromised the login passwords of 14 financial advisors and four financial assistants in 9 states over the course of several months, LPL Financial has notified [pdf] the Maryland Attorney General's office of the incident.

In a detailed notification letter dated May 6th from Keith H. Fine, Senior Vice-President and Associate Counsel, the company described how after they first became aware of the hack on July 16, 2007, they notified law enforcement, FIRA, and affected individuals. The company estimates that personal information on 10,219 customers was exposed, including the unencrypted names, addresses, phone numbers, dates of birth, account numbers, and Social Security numbers of customers and non-customer beneficiaries.

Investigation of the incident determined that access to customer accounts was used to engage in a "pump and dump" scheme involving penny stocks, but all attempted transactions were reportedly either intercepted or reversed. No customer suffered any financial loss from the attempted transactions, and the company reports that there is no indication that customer information was used for any other purpose.

In August 2007, LPL retained Kroll Inc. to provide various services, including notification of affected individuals and free credit monitoring services for individuals. A series of communications was sent to affected individuals commencing on September 21, 2007, and most recently in May 2008.

Following this incident, LPL Financial reportedly initiated steps to improve its security on its advisor facing trading and operations systems. As part of enhancing security, they created a new position of Chief Security/Privacy Officer in March 2008, and other new security policies have been implemented this month. The company anticipates that their other security improvements will be completed in December 2008.


...and then after that one...

http://www.pogowasright.org/article.php?story=20080519131659904

Burglary of LPL Financial employee's home affects 1,397 employees

Monday, May 19 2008 @ 01:16 PM EDT Contributed by: PrivacyNews News Section: Breaches

While still dealing with the hacking incident that affected over 10,000 customer accounts, LPL Financial learned in September 12, 2007 that a laptop containing employee data had been stolen from an employee's home in San Diego.

The password-protected computer contained unencrypted names, addresses, fingerprints, and Social Security numbers of registered representatives and office employees, most of who were from Massachusetts.

Affected individuals were first notified on November 30, 2007 and were offered free credit monitoring and identity restoration services from Kroll, Inc.

And once again, the notification to individuals did not say that there was a theft, but talked about the incident as "unauthorized person(s) obtained access to the system...."


...and after that...

http://www.pogowasright.org/article.php?story=20080519130551172

Five computers stolen from LPL Financial office in December contained customer data

Monday, May 19 2008 @ 01:17 PM EDT Contributed by: PrivacyNews News Section: Breaches

LPL Financial has notified [pdf] the Maryland Attorney General's Office that on December 11, 2007, a burglary at one of their offices in Diamond Bar, California, resulted in the theft of 5 computers that contained personal information on 444 customers.

The stolen computers were password-protected, but contained unencrypted personal information: names, addresses, dates of birth, Social Security numbers, and account numbers. Affected individuals were first notified on February 11, 2008 and were offered free credit monitoring through Kroll.

Somewhat curiously, perhaps, although LPL reports this as a burglary, all of their appended notifications to individuals say "unauthorized person(s) obtained access to the system...." which sounds more like a hack than a burglary.


...and let's not forget this one...

http://www.pogowasright.org/article.php?story=20080519125724971

LPL Financial laptop stolen from employee's car had data on 2800 employees

Monday, May 19 2008 @ 01:14 PM EDT Contributed by: PrivacyNews News Section: Breaches

LPL Financial has notified the Maryland Attorney General's office that on April 10, 2008, a laptop containing data on 2800 employees of LPL or its affiliated companies was from an employee's car in North Carolina

The personal information on the laptop contained names, Social Security numbers, employee ID numbers, and other employee financial compensation information.

In describing its plans to improve data security and steps it had already taken, the company indicated that it "had begun" a project to encrypt data on laptops [Translation: Nothing has actually been encrypted yet... Bob] used by employees and representatives.

Once again, the company used Kroll to provide services to affected individuals, including free credit monitoring.



Questions: 1) Is it reasonable to extrapolate the total number of compromised customers by taking the ratio of Maryland's population to the total US population? 2) Why do so many employees have social security numbers on their laptops?

http://www.pogowasright.org/article.php?story=20080519121639862

Stolen laptop contained employee data from Bearing Point Management & Technology Consultants

Monday, May 19 2008 @ 01:08 PM EDT Contributed by: PrivacyNews News Section: Breaches

Bearing Point Management & Technology Consultants reports that a laptop stolen from an employee's vehicle on April 11 contained personal information on some of its employees, 26 of whom are Maryland residents.

Personal information on the laptop included first and last names and Social Security numbers.

According to the letter sent to employees by Joseph T. Van Thuyne, HR Director, Administration, Policies and Systems, the laptop required two passwords and two forms of authentication and at the time of the theft, was inside a case in the trunk of the employee's vehicle. [Translation: No encryption Bob]

The company has offered those affected 12 months of free credit monitoring.



So who (if anyone) would assert they are in control of (you know, actually managing) the users with the laptops? Another reason to encrypt EVERYTHING on EVERY laptop.

http://www.pogowasright.org/article.php?story=20080519122543129

Sodexo laptop stolen but company not sure whether employee data was on it or not

Monday, May 19 2008 @ 01:10 PM EDT Contributed by: PrivacyNews News Section: Breaches

Sodexo, Inc., a provider of integrated food and facilities management services, reports that a laptop stolen from an employee's vehicle in Montgomery County may have contained names and Social Security numbers on 919 residents of Maryland employed by the company.

In a letter [pdf] to the Maryland Attorney General's office dated May 9, Robert A. Stern, Senior Vice-President and General Counsel for Sodexo, writes that the company "has not been able to confirm definitively that the file was on the laptop."

The company set up a hot line for employees to call, but did not offer free credit monitoring.



The damage from the Hannaford breach continues...

http://www.pogowasright.org/article.php?story=20080520063131461

Bank: Breach affected accounts

Tuesday, May 20 2008 @ 06:31 AM EDT Contributed by: PrivacyNews News Section: Breaches

TD Banknorth said yesterday a group of New Hampshire customers was notified last week that their Visa debit or credit cards have been compromised, most likely because of the Hannaford Brothers Supermarkets security breach.

"We do closely monitor those cards for suspicious activity, and it was because of our fraud-detection activity that we noticed the cases of fraud," spokesman bank Jennifer Carlson said yesterday,

Carlson declined to release the specific number of customers affected or their location, citing privacy policy.

Source - Union Leader



Looks like the Phishers missed one. Or did they?

http://it.slashdot.org/article.pl?sid=08/05/19/1325214&from=rss

Identity Theft Hits the Root Name Servers

Posted by CmdrTaco on Monday May 19, @10:00AM from the i-don't-think-i-am-who-you-think-i-am dept. Security The Internet IT

aos101 writes

"The Renesys blog has an interesting story about networks advertising the old address space of the L root name server after ICANN changed the IP address last November. These networks were also running root name servers on the old IP address of the L root name server up until last week, so any DNS servers still using the old IP address might have been getting their answers from these bogus name servers. A very cursory examination by Renesys of one of these bogus servers found that it appeared to be providing correct responses, which might be why no one noticed the problem. As Renesys points out, the volume of traffic to a root server is staggering, so the people running these bogus root servers must have had a reason. What did they get out of it?"



One to watch? At least until I find out how they can substitute their machine for the ATM card reader without anyone noticing!

http://www.pogowasright.org/article.php?story=20080519163803504

Secret Service joins Lunardi's ATM theft case; 234 victims now identified

Monday, May 19 2008 @ 04:38 PM EDT Contributed by: PrivacyNews News Section: Breaches

The Secret Service has joined the investigation into the Los Gatos Lunardi's Supermarket ATM identity theft case as the number of victims continues to climb.

Most recent figures show that 234 Lunardi's shoppers reported they are victims of the scam. Approximately $251,000 has been stolen since police discovered an ATM machine at the store had been tampered with to obtain customers' account information.

Source - Mercury News



Perhaps we'll get a better look at how these Phishing crimes work too?

http://www.pogowasright.org/article.php?story=20080519162213833

5 People Arrested in Connection with International Online Phishing Scheme (update 1)

Monday, May 19 2008 @ 04:22 PM EDT Contributed by: PrivacyNews News Section: Breaches

Five people were arrested Monday in Los Angeles and others were being sought in connection with an international online "phishing" scheme that defrauded thousands of victims and hundreds of financial institutions, federal authorities said.

A total of 33 people, U.S. citizens and foreign nationals alike, were named in a 65-count indictment charging them with participating in the Internet-based fraud, prosecutors said. The indictment, unsealed today, was returned by a federal grand jury in Los Angeles.

Source - Fox6News

Related - DOJ Press Release

Related - an article in InformationWeek lists affected institutions as:

Allegheny Federal Credit Union, American National Bank of Texas, Arizona Federal Credit Union, Banker's Bank & Trust, Bank of the West, Boeing Employees' Credit Union, Bowdoinham Federal Credit Union, Capital One Bank, Citibank, Downey Savings & Loan, Credit Union One, E-Trade, Desert Schools Federal Credit Union, Flagstar Bank, First Merit Bank, Iowa League Corporate Central Credit Union, Jeffco Schools Credit Union, Langley Federal Credit Union, Mountain America Credit Union, Orange County Teacher's Credit Union, Pointbank, NASA Federal Credit Union, North Island Credit Union, Premier Credit Union, PSCU Financial Services, Regions Bank, School Financial Credit Union, Southwest Corporate Federal Credit Union, Teacher's Credit Union, Telco Credit Union & Affiliates, Valley National Bank, VISA, Washington State Employees Credit Union, and Waterbury Teachers' Federal Credit Union.

Update 1: The Hartford Courant indicates that Bridgeport-based People's Bank, Brattleboro Savings and Loan Association in Vermont, Citibank, Capital One, JPMorgan Chase & Co., Comerica Bank, Wells Fargo & Co., eBay and PayPal were also targeted.



An ethical Catch 22 In theory, lawyers aren't supposed to look at this information. In theory, lawyers aren't supposed to claim the data is classified when it is not. So do you sanction both sides?

http://blog.wired.com/27bstroke6/2008/05/secret-data-in.html

Secret Data in FBI Wiretapping Audit Revealed With Ctrl+C

By Ryan Singel May 16, 2008 | 7:51:59 PM

Once again, supposedly sensitive information blacked out from a government report turns out to be visible by computer experts armed with the Ctrl+C keys -- and that information turns out to be not very sensitive after all.

This time around, University of Pennsylvania professor Matt Blaze discovered that the Justice Department's Inspector General's office had failed to adequately obfuscate data in a March report (.pdf) about FBI payments to telecoms to make their legacy phone switches comply with 1995 wiretapping rules. That report detailed how the FBI had finished spending its allotted $500 million to help telephone companies retrofit their old switches to make them compliant with the Communications Assistance to Law Enforcement Act or Calea-- even as federal wiretaps target cellphones more than 90 percent of the time.

This isn't the first time the Justice Department has made such an error.



“Screwing our customers, one sale at a time.” Hard to blame this one on an untrained new employee...

http://www.news.com/8301-10784_3-9947410-7.html?part=rss&subj=news&tag=2547-1_3-0-5

Best Buy challenges FCC over analog TV sales penalty

Posted by Erica Ogg May 19, 2008 3:43 PM PDT

The Federal Communications Commission says Best Buy and other retailers must pay more than $3 million in fines for selling analog TVs without labels that explain the sets won't work after the digital TV switchover next February.

In a 41-page legal document filed last week (and dug up by Ars Technica), Best Buy essentially says, "Oh yeah? Make us."



Won't the RIAA have fits over this service?

http://www.killerstartups.com/Web20/iRadeocom---Stream-Your-Music/

iRadeo.com - Stream Your Music

Want to share your music with others? iRadeo is a free streaming radio platform. Installing iRadeo on your website is easy. First download and unzip the iRadeo package. Open the file and update your settings and preferences. Upload files and folders to your server and place the given code where every you please on your website and you are done. You can start uploading your MP3/WAV files to your folder and iRadeo will stream the file.

... Other listeners can easily embed your player on their sites by coping and pasting code. Sharing music with others couldn’t be easier than at iRadeo.com.

http://www.iradeo.com/



Interesting resource...

http://www.bespacific.com/mt/archives/018382.html

May 19, 2008

Online Tool Provides Victims' Rights Law Information

"VictimLaw has been designed as a comprehensive, user-friendly online database of victims’ rights statutes, tribal laws, constitutional amendments, court rules, administrative code provisions, and case summaries of related court decisions that meets the needs of a wide variety of users with different levels of substantive and technological expertise. VictimLaw also offers brief victims' rights and justice system overviews. Such ready access to information can advance the cause of crime victims’ rights by facilitating the exercise, implementation, and enforcement of those rights. This resource was developed by the National Center for Victims of Crime with funding from the Office for Victims of Crime (OVC), the Office of Justice Programs (OJP), and the U.S. Department of Justice (DOJ)."



More disciplines should do this. Who knows what is being lost...

http://www.bespacific.com/mt/archives/018392.html

May 19, 2008

Preserving Legal Information: The Chesapeake Project's First-Year Evaluation

"The Chesapeake Project began as a two-year (2007-2008) pilot digital preservation program established to preserve and ensure permanent access to vital legal information currently available in digital formats on the World Wide Web. The purpose of The Chesapeake Project is to successfully develop and implement a program to stabilize, preserve, and ensure permanent access to critical born-digital legal materials. The goal is to establish the beginnings of a strong regional digital archive collection of U.S. legal materials as well as a sound set of standards, policies, and best practices that have the potential to serve as a model for the future realization of a nationwide digital preservation program . See Legal Information Archive: The Chesapeake Project, First Year Evaluation." [via Sarah J. Rhodes]



and since we're discussing legal resources, I'll toss this one in too

http://www.bespacific.com/mt/archives/018383.html

May 19, 2008

New on LLRX.com

Keeping Up with Class Actions: Reports, Legal Sites and Blogs of Note - "Staying current on the latest cases and news in the area of class actions can be challenging, but Russell Scott's guide to reliable subscription based publications, free legal sites and blogs that offer timely news, analysis and selected copies of court filings, is a valuable resource. — Published May 19, 2008"



Another example of tools to make the transition from Windows to Linux easier. Start training your employees now, the death of Windows is inevitable!

http://tech.slashdot.org/article.pl?sid=08/05/19/2223258&from=rss

A Virtualized Linux System For Windows

Posted by kdawson on Monday May 19, @07:01PM from the bill-in-the-middle dept. Operating Systems Windows Linux

getupstandup1 writes

"Ulteo today unveiled their Virtual Desktop (screenshots, download) which is a free, full Linux desktop that runs seamlessly on Windows. It's interesting because it's not running under Xen or VMWare, but instead uses the coLinux patch, which they claim allows the system to achieve 'great performance, close to a native installation on the PC.' No need to reboot the system anymore to switch from Windows to Linux."

We discussed Ulteo when the Ubuntu-derived distro was announced a year back.

Monday, May 19, 2008

The bribes may explain why no one seems to detect the skimmers...

http://www.pogowasright.org/article.php?story=20080519062429708

Ie: 1 million euro stolen in bank card fraud

Monday, May 19 2008 @ 06:24 AM EDT Contributed by: PrivacyNews News Section: Breaches

Around one million euro has been stolen from 300 bank accounts in one of the largest incidents of bank card fraud ever in Ireland.

It is understood bank cards were cloned at points of sale in shops and restaurants around Dublin in the last few weeks.

Source - Independent.ie Thanks to Brian Honan for the link.

[From the article:

It is understood that criminal's paid shop and restaurant workers up to ten thousand euro to skim laser cards and find out their pin numbers by looking over their shoulder - a practice called "shoulder surfing".

... Most of the withdrawals took place at the end of April and in early May, and many of the customers contacted their bank themselves to notify them of the irregularities because the banks fraud detection systems failed to pick up on the activity. [Shouldn't that scare hell out of the banks? Bob]



...because Phishing takes too long?

http://www.pogowasright.org/article.php?story=20080518094324689

Chinese Red Cross Website Hacked to Steal Earthquake Relief Donations

Sunday, May 18 2008 @ 09:43 AM EDT Contributed by: PrivacyNews News Section: Breaches

Verified by the Ministry of Public Security, a section of the official Red Cross website has been illegally hacked. According to the report, criminal elements gained access to the section of the website that held the special accounts for earthquake disaster relief donations. [...and changed the site to point to their accout numbers. Bob]

An individual named Li Bujiu, had opened four fraudulent bank accounts to steal the funding.

Source - The Dark Visitor hat-tip, Fergie's Tech Blog


Related?

http://www.infoworld.com/article/08/05/19/Mass-SQL-injection-attack-targets-Chinese-Web-sites_1.html?source=rss&url=http://www.infoworld.com/article/08/05/19/Mass-SQL-injection-attack-targets-Chinese-Web-sites_1.html

Mass SQL injection attack targets Chinese Web sites

Attack has implanted malware in thousands of Web sites in China and Taiwan

By Sumner Lemon, IDG News Service May 19, 2008

Web sites across China and Taiwan are being hit by a mass SQL injection attack that has implanted malware in thousands of Web sites, according to a security company in Taiwan.

First detected on May 13, the attack is coming from a server farm inside China, which has made no effort to hide its IP (Internet Protocol) addresses, said Wayne Huang, chief executive officer of Armorize Technologies, in Taipei.

"The attack is ongoing, ... even if they can't successfully insert malware, they're killing lots of Web sites right now, because they're just brute-forcing every attack surface with SQL injection, and hence causing lots of permanent changes to the victim Web sites," Huang said.



...because..

http://www.pogowasright.org/article.php?story=20080519061401232

Data “Dysprotection:” breaches reported last week

Monday, May 19 2008 @ 06:20 AM EDT Contributed by: PrivacyNews News Section: Breaches

A recap of incidents or privacy breaches reported last week for those who enjoy shaking their head and muttering to themselves with their morning coffee.

Source - Chronicles of Dissent



Did anyone thing they were invulnerable?

http://www.news.com/8301-10784_3-9946716-7.html?part=rss&subj=news&tag=2547-1_3-0-5

Security hole found in software used by power plants

Posted by Elinor Mills 3 comments May 18, 2008 10:01 AM PDT

We can all live with outages at Yahoo Mail, Twitter, and CNN.com. But what about when there's an outage that affects our electrical power, heating systems, and gas supplies?

Boston-based security firm Core Security has discovered a serious hole in the Suitelink software that is used to automate operations at power stations, oil refineries and production lines, according to a report in New Scientist.



Sure to be a feature of the Olympics?

http://yro.slashdot.org/article.pl?sid=08/05/18/1630208&from=rss

China's All-Seeing Eye

Posted by Soulskill on Sunday May 18, @01:22PM from the who-watches-the-watchers dept.

Greg Walton brings us a lengthy story from Rolling Stone which describes China's comprehensive surveillance project, dubbed Golden Shield. The 'Great Firewall of China,' which we've discussed in the past, is but one aspect of Golden Shield. It also includes national ID cards, CCTV networks, and face-recognition software. This investigation showcases just how massive an undertaking it truly is. When finished, it will dwarf London's surveillance system. Quoting:

"Over the past two years, some 200,000 surveillance cameras have been installed throughout the city. Many are in public spaces, disguised as lampposts. The closed-circuit TV cameras will soon be connected to a single, nationwide network, an all-seeing system that will be capable of tracking and identifying anyone who comes within its range -- a project driven in part by U.S. technology and investment. Over the next three years, Chinese security executives predict they will install as many as 2 million CCTVs in Shenzhen, which would make it the most watched city in the world. (Security-crazy London boasts only half a million surveillance cameras.) ... This is the most important element of all: linking all these tools together in a massive, searchable database of names, photos, residency information, work history and biometric data. When Golden Shield is finished, there will be a photo in those databases for every person in China: 1.3 billion faces."



Lawyer Losey make a couple of points I've been pushing for years. 1) You don't need to write a book in one sitting. Small 'compositions' on a regular basis add up quickly. 2) Collecting data makes you a resource. If you can apply some expertise, perhaps a valuable resource.

http://ralphlosey.wordpress.com/2008/05/17/online-reference-and-thirty-one-more-e-discovery-cases/

Online Reference and Thirty One More e-Discovery Cases

... I was surprised to notice that I have somehow written and posted over 100 essays in the past year and a half. They cover most of the important e-discovery cases and trends since I started this blog in the Fall of 2006.

... So I got to thinking what I might do to make this blog a more useful research tool for everyone? The answer was to post my collection of favorite e-discovery cases, most of which have not been previously included in the blog because they preceded it in time. So my blog for this week is my list of favorite cases, along with a brief summary of each case. I include this case digest in my CLE handouts anyway, so I thought it might be helpful to make them available in electronic, searchable form.



For the students in my Inter-Stellar Navigation class...

http://www.bespacific.com/mt/archives/018372.html

May 18, 2008

WorldWide Telescope Web 2.0 Visualization Software

"The WorldWide Telescope (WWT) is a Web 2.0 visualization software environment that enables your computer to function as a virtual telescope—bringing together imagery from the best ground and space-based telescopes in the world for a seamless exploration of the universe.

Choose from a growing number of guided tours of the sky by astronomers and educators from some of the most famous observatories and planetariums in the country. Feel free at any time to pause the tour, explore on your own (with multiple information sources for objects at your fingertips), and rejoin the tour where you left off. Join Harvard Astronomer Alyssa Goodman on a journey showing how dust in the Milky Way Galaxy condenses into stars and planets. Take a tour with University of Chicago Cosmologist Mike Gladders two billion years into the past to see a gravitational lens bending the light from galaxies allowing you to see billions more years into the past." [Microsoft Research]

Sunday, May 18, 2008

Apparently a number of 'failures' must occur for Identity Theft to happen... Let's sue them all! (How easy was it to get all this information?)

http://torontosun.com/News/TorontoAndGTA/2008/05/18/5603146-sun.html

Jason Young plays private eye after buying a new car and running smack into a bad case of identity theft

By MARK BONOKOSKI Sun, May 18, 2008

The car that Jason Young has never owned, a 2001 Audi A4, can be found today under lock-and-chain in an OPP compound north of Toronto, having been seized following its abandonment in a still unsolved hit-and-run.

... Jason Young, it appears, would make a fine private eye.

He paid $20 for a used vehicle information package on the car he never owned, and found out that it had its beginnings in Ottawa and was passed along to various car dealerships in southern Ontario -- ending up at the Woodbridge used car dealership that, at this writing, is under investigation by the York Regional Police fraud squad, and being sold to one "Jason Young," and with its odometre reading rolled back more than 30,000 klicks.

He discovered that the downpayment cheque, while it carried his name, was actually an account belonging to someone else which, due to Privacy Laws, will now be left to the police to sort out through a warrant.

He tracked down the financing documents, then with Travelers, and pointed out that not only was the signature on the document not his, but neither was the social insurance number or the attached T-4 document supposedly proving income.

It was all bogus.

Not only that, he was supposedly a plumber, and working for a legitimate plumbing company in Mississauga.

Whoever was doing the due diligence for Travelers, however, was asleep at the switch because "Jason Young" got a loan despite a handwritten notation at the bottom of the loan application which noted the plumbing company could not possibly have "Jason Young" on its payroll.

"Spoke to owner," reads the notation. "He said he doesn't have any employees!"

Nonetheless, the $20,517 loan to "Jason Young" was approved, at an almost unimaginable interest rate of 29.9%. [That explains why... Bob]

In fact, the only thing that appeared to have a credible connection to Jason Young was a ninth-generation photo copy of his driver's licence which, to this day, Jason Young has no idea how it got into circulation.



Another example of multiple failures?

http://www.baltimoresun.com/business/bal-bz.ml.consuming18may18,0,6711338.column?track=rss

Comcast slow to act on hijacked e-mail site

Dan Thanh Dang Consuming Interests May 18, 2008

Early this year, Gary Brawerman's e-mail account was hijacked. As much of a nightmare that was, it didn't compare to the lack of concern he found when he called his Internet service provider, Comcast Corp., for help.

Brawerman noticed trouble Jan. 21 when he went to log on to the e-mail account he'd used for four years but could not access it. The system couldn't even find his e-mail address.

"That's when I knew something was wrong," said Brawerman, owner of a local mattress store. "I called Comcast and they told me they needed 24 hours."

Brawerman called the next day. A Comcast rep told him they needed another 24 hours.

"When I still had not heard from anyone, I called Jan. 24 and was told by someone named Michael that I should have been told they needed 24 to 72 hours," Brawerman said. "Michael told me he was going on vacation the next day at midnight, but said he could call me late Friday. He didn't call. On Jan. 25, I called and was told 'Your problem has not reached upstairs yet.'"

Three days later, someone named Byron from Comcast told him that "my e-mail was changed by another I.D. user, microsoft.team.206. I told him that's no one I know. Byron said, 'Uh-oh. Let me get back to you.' You guessed it, I never heard from him again."

Meanwhile, Brawerman was in full panic mode.

"I kept a lot of personal data in my e-mail account," Brawerman said. "Bank account numbers, credit card numbers, financial information, passwords, a list of phone numbers and birth dates. I had no idea if someone accessed that information or not."

... By May 5, when Brawerman contacted me, it had been 106 days since his initial call - and he still had not received any explanation of what happened to his e-mail address or what he should do.

He began getting some answers after I contacted Comcast May 7.

Spokesman Aimee Metrick said a spammer used Brawerman's e-mail account in January to set up numerous false e-mail addresses in a short amount of time. Metrick said Comcast's e-mail server was not compromised.

"In a very rare occurrence, it appears the spammer also used the customer's primary e-mail address to send spam and then dumped it, which sent it to our reservoir database of inactive accounts," Metrick said. "We do not believe there are any issues with identity theft, [Absent proof, do they have a duty to notify? Bob] as spammers are generally focused solely on the ability to use the account to set up additional e-mail addresses as a way to send spam."

... Comcast says the reason it took so long was because the problem was so rare. But wouldn't that alone have been enough reason to escalate the complaint? [Only if it was seen as a problem for Comcast. It was merely a 'customer service' issue, therefore safe to ignore. Bob] It doesn't jibe.

... Avi Rubin, Johns Hopkins computer science professor and founder of a computer security firm, said, "I know firsthand of several instances of people having their e-mail hijacked by spammers. It can't be that uncommon. … Why Comcast customer service couldn't give him back his account quickly is perplexing to me, too. They should have a mechanism to deal with emergencies. It should be instantaneous."

Since Comcast won't discuss what protocol it has in place to deal with security issues, it's hard to know if Comcast didn't have the technical know-how to deal with e-mail hijacking or if its employees dropped the ball. I'd like to believe the latter; the other scenario would not be too reassuring to its customers.

... Brawerman said Comcast offered him six months of free cable, but he declined. He wants a written apology and possibly money for what he spent for credit-monitoring services. In the meantime, Brawerman said he will never ever keep personal data in his e-mail account again. "I learned that the hard way," he said.



Everyone needs a hobby

http://www.usatoday.com/tech/news/computersecurity/hacking/2008-05-17-hackers-spain_N.htm

Five arrested in Spain for hacking government sites

By Daniel Woolls, Associated Press

MADRID, Spain — Spanish police have arrested five young computer hackers who allegedly disabled Internet pages run by government agencies in the U.S., Latin America and Asia, authorities said Saturday.

The National Police described the suspects as belonging to one of the most active hacker groups on the Internet and said two of the suspects are only 16 years old. The others are 19 or 20.

On the Internet, the group calls itself D.O.M Team, police said.

One of the group's techniques was to infiltrate websites and insert a page of its own, police said. A Google search turns up several hits with pages that fit this description.

The group attacked some 21,000 Web pages over the last two years, police said in a statement. The five were arrested this week in Barcelona, Burgos, Malaga and Valencia.

The statement did not identify which government websites the suspects are accused of tampering with.

The Spanish newspaper El Mundo reported in March that the group had infiltrated NASA's Web page, but a police official said Saturday she could not confirm this. The official spoke on condition of anonymity in line with department rules.

The group also hacked the Venezuelan national telephone company's page, and that of the Spanish telephone operator Jazztel, among others, the paper said.

El Mundo said it had contacted the group and it described itself not as a bunch of delinquents, but computer-lovers that raid websites to show system administrators the pages' vulnerabilities.

The Spanish investigation began in March after the Web page of a Spanish political party, Izquierda Unida, was disabled shortly after Spain's general election March 9.

The five suspects did not know each other personally, but rather just over the Internet. They were in contact with other members of the hacking group, mainly in Latin America, police said.



This could be an interesting approach to Network Neutrality: “Prove to us that your network is inadequate...”

http://tech.slashdot.org/article.pl?sid=08/05/17/2321231&from=rss

Canadian ISP Ordered to Prove Traffic-Shaping is Needed

Posted by timothy on Saturday May 17, @08:47PM from the offer-good-only-in-canada dept. The Internet Communications Government

Sepiraph writes

"In a letter sent to the Canadian Association of Internet Providers and Bell Canada on May 15, the Canadian Radio-television and Telecommunications Commission (CRTC) have ordered Bell Canada to provide tangible evidence that its broadband networks are congested to justify the company's Internet traffic-shaping policies. This is a response after Bell planned to tackle the issue of traffic shaping, also called throttling, on the company's broadband networks. It would be interesting to see Bell's response, as well as to see some real-world actual numbers and compare them to a previous study."



Apparently Global Warming has cooked his brain. (Other parts of the lawsuit are less crazy.)

http://blog.wired.com/27bstroke6/2008/04/prof-sues-note.html

Lawsuit Claim: Students' Lecture Notes Infringe on Professor's Copyright

By Ryan Singel April 04, 2008 | 1:48:14 PM

... Moulton and his e-textbook publisher are suing Thomas Bean, who runs a company that repackages and sells student notes, arguing that the business is illegal since notes taken during college lectures violate the professor's copyright.



Linux only (so far)

http://www.bespacific.com/mt/archives/018363.html

May 16, 2008

Secure web browsing with the OP web browser

Secure web browsing with the OP web browser, Chris Grier, Shuo Tang, and Samuel T. King, Department of Computer Science, University of Illinois at Urbana-Champaign

  • "Current web browsers are plagued with vulnerabilities, providing hackers with easy access to computer systems via browser-based attacks. Browser security efforts that retrofit existing browsers have had limited success because the design of modern browsers is fundamentally flawed. To enable more secure web browsing, we design and implement a new browser, called the OP web browser, that attempts to improve the state-of-the-art in browser security. Our overall design approach is to combine operating system design principles with formal methods to design a more secure web browser by drawing on the expertise of both communities. Our overall design philosophy is to partition the browser into smaller subsystems and make all communication between subsystems simple and explicit. At the core of our design is a small browser kernel that manages the browser subsystems and interposes on all communications between them to enforce our new browser security features."