Thursday, July 23, 2009

Perhaps not the best target for identity theft?

http://www.pogowasright.org/?p=2113

Jackson death certificate improperly accessed

July 23, 2009 by Dissent Filed under Breaches, U.S.

Los Angeles County coroner’s officials said Wednesday that they have discovered security breaches involving the investigation into Michael Jackson’s death, including hundreds of improper views of the pop star’s death certificate and the discovery of weaknesses in two other computer systems in which more sensitive records are stored.

At least half a dozen staff members inappropriately accessed Jackson’s death certificate, officials said. Within two weeks of his death June 25, the certificate had been viewed more than 300 times. The document was not released publicly until July 7.

Read more on the Los Angeles Times.

[From the article:

In some cases, coroner's staff appear to have printed copies before it became public. [Perhaps we could blow it up to poster size and sell framed copies on e-Bay? Bob] This month, coroner's officials warned employees to cease in an e-mail reviewed by The Times.

… Death records in the can be accessed by anyone with a state-issued password, including employees at coroner's offices, funeral homes, hospitals and the county and the state registrar's office.

… Coroner's officials in L.A. said they also grappled with security concerns about two other password-protected computer systems that hold the active investigation files on Jackson's death.

Typically, such reports can be called up by investigators and other employees with system passwords. In Jackson's case, however, access was supposed to have been restricted from the start to a small number of high-ranking administrators. [Different rules for “important” people. Bob] Harvey said the hard copy of the investigation file was stored under lock and key.



Perhaps “Burden” isn't the right concern...

http://www.pogowasright.org/?p=2107

ABA plans for litigation over Red Flags rule

July 23, 2009 by Dissent Filed under Breaches, Businesses, Legislation, U.S.

The president of the American Bar Association said Wednesday the group may file a suit by the end of next week if it cannot persuade the Federal Trade Commission to exempt lawyers from new regulations set to take effect Aug. 1. The ABA has been lobbying for months to have lawyers kept out of the regulations, which require businesses and organizations that act as “creditors” to establish a program for preventing identity theft. The FTC and the ABA differ on how much of a burden the regulations would put on businesses.

Read more on Law.com.


...perhaps the word is “Waste” as it “If it doesn't work, why bother?”

http://www.pogowasright.org/?p=2105

Witnesses: E-Verify system can’t detect ID theft

July 23, 2009 by Dissent Filed under Govt, Surveillance, U.S.

The Homeland Security Department’s E-Verify employment verification system cannot detect identity theft and fraudulent applications, according to testimony before a Senate Judiciary Committee subcommittee.

The Internet-based E-Verify system allows employers to check Social Security numbers for their employees and prospective employees to determine whether the numbers are valid and the employees are therefore eligible to work. However, it is not designed to detect borrowed or stolen Social Security numbers.

[...]

E-Verify is a voluntary system used by about 134,000 employers, though it is mandatory to some degree in 12 states. Under an executive order from the Bush administration, federal contractors were supposed to begin mandatory use of E-Verify in January. However, that deadline has been pushed back to Sept. 8 due to a lawsuit. Homeland Security Secretary Janet Napolitano recently said the Sept. 8 deadline would be firm. [Even if it doesn't work, we want everyone tp use it... Bob]

The E-Verify system has been controversial due to alleged high error rates in the databases used. USCIS acknowledges a 3.1 percent rate of initial non-matches in the system.

Read more on FederalComputerWeek.


(Related?)

http://www.pogowasright.org/?p=2109

Hustinx issues warning over transport monitoring

July 23, 2009 by Dissent Filed under Govt, Non-U.S., Surveillance, Workplace

The European Commission plans to create a framework within which it will be easier for governments and transport operators to set up EU-wide tracking and monitoring systems for transport.

European Data Protection Supervisor Peter Hustinx, who is responsible for regulating EU bodies’ privacy practices, said that he had concerns about the proposals.

Though the systems are aimed at making transport more environmentally friendly and less time consuming, Hustinx said that they could be used to monitor individuals’ movements across the continent.

“The deployment of ITS will support the development of applications for ‘tracking and tracing’ of goods and will allow for the deployment of location-based commercial and public services,” said a formal opinion produced by Hustinx. “The use of location technologies is particularly intrusive from a privacy viewpoint as it allows for the tracking of drivers and for the collection of a wide variety of data relating to their driving habits.”

Read more on Out-Law.com.



Interesting that one of the most popular software applications in the US doesn't pass even the basic Privacy tests in other countries. Perhaps there will eventually be a Universal Standard with which applications can determine which countries will ban/warn against them?

http://www.pogowasright.org/?p=2099

Facebook: Australia piles on

July 22, 2009 by Dissent Filed under Businesses, Internet, Non-U.S.

Australian authorities are looking into whether Facebook is in breach of local privacy laws in the way it handles user data.

A report released by Canadian Privacy Commissioner Jennifer Stoddart last week found “serious” flaws in some of the social networking site’s practises.

[...]

Australian Privacy Commissioner Kartin Curtis this week said her office was investigating the findings of the report and whether they breached local law.

“My office is examining the report of the Canadian Privacy Commissioner’s year-long investigation into a complaint it had received against Facebook,” said Ms Curtis.

“A number of the privacy issues raised… could arise under the Australian Privacy Act.

Read more on news.com.au



What “old book” (or document?) would you like an exact copy of?

http://news.digitaltrends.com/news-article/20471/amazon-signs-a-deal-to-reprint-rarities

Amazon Signs A Deal To Reprint Rarities

July 23, 2009 by Christopher Nickson

Amazon has inked a deal with the University of Michigan to reprint and sell 400,000 rare books.

The rare books in the University of Michigan’s library are in 200 different languages, and include such collectibles as an 1898 volume on nursing by Florence Nightingale. They’re all out of print and out of copyright, but soon they’ll be available to buy again, since the university signed a deal with Amazon.

The books will be available from Amazon’s Book Surge in soft cover, with prices ranging from $10 to $45, according to the BBC.



Statistics It still comes as a shock when I find students with almost zero computer skills.

http://news.cnet.com/8301-1035_3-10293283-94.html?part=rss&subj=news&tag=2547-1_3-0-5

Americans are going wireless Internet big time, report says

by Dong Ngo July 22, 2009 3:30 PM PDT

A few days ago, the Pew Research Center released a report that Americans are looking online to fight the recession. On Tuesday it added that most of us are doing that via wireless Internet.

The results of the center's Internet & American Life Project survey show that 56 percent of adult Americans have accessed the Internet via wireless means, such as a Wi-Fi laptop, a mobile device, a game console, or an MP3 player. The most popular way people get online wirelessly is with a laptop computer, numbering 39 percent of some 2,200 survey participants.

The report also revealed the rising levels of Americans using the Internet on a mobile handset. Almost one-third (32 percent) have used a cell phone or a smartphone to access the Internet for e-mailing, instant messaging, or reading news.

For comparison, only 24 percent of Americans had done this by December 2007. Now, in a typical day, nearly one-fifth (19 percent) of Americans use the Internet on a mobile device, up substantially from the 11 percent level recorded in December 2007.



Attention Blog readers! It could be much worse – you could be listening to me ramble on... But this might also work for Seminars, or even my classes.

http://www.makeuseof.com/tag/how-to-start-your-own-internet-shoutcast-radio-station/

How To Start Your Own Internet Radio Station With Shoutcast

Jul. 22nd, 2009 By Jason K

Internet radio is, quite possibly, one of the more interesting methods of listening to music. As of this writing, there are approximately 30,000 broadcasting SHOUTcast radio stations – all broadcasting a unique playlist of songs or other content.

We’re going to show you how to start your own Internet radio station with SHOUTcast – and help you set up a player on your website.

Wednesday, July 22, 2009

How much should a security breach cost an organization?

http://www.databreaches.net/?p=6353

HSBC fined for personal data loss

July 22, 2009 by admin Filed under Breach Incidents, Lost or Missing, Non-U.S., Of Note

Three HSBC firms have been fined more than £3m for failing to adequately protect customers’ confidential details from being lost or stolen.

The Financial Services Authority (FSA) said customer data had been lost in the post on two occasions.

The firms concerned are HSBC Life UK, HSBC Actuaries and Consultants, and HSBC Insurance Brokers.
[...]

The FSA identified two instances where unencrypted data had been lost in the post.

In April 2007, HSBC Actuaries lost a floppy disk containing the personal information of 1,917 pension scheme members, including addresses, dates of birth and national insurance numbers.

And in February 2008, HSBC Life lost a CD containing the details of 180,000 policyholders.

“All three firms failed their customers by being careless with personal details which could have ended up in the hands of criminals,” said Margaret Cole, director of enforcement at the FSA.

Read more on BBC. Related - FSA Press Release



See how common “not knowing” is? Here's an idea. If you can't prove your laptop was “PII Free” then you must assume it contained data on every customer. (It'll never fly, but it would open some eyes.)

http://www.databreaches.net/?p=6349

Stolen laptop “may have” held customer data

July 21, 2009 by admin Filed under Breach Incidents, Business Sector, Theft

On July 8, a laptop that may have contained some customer information such as names and credit card numbers was stolen from an employee of Henry Schein, Inc. Although the laptop was password protected, the data were not encrypted.

By letter dated July 16 to the New Hampshire Attorney General’s Office, Kristen J. Mathews of Proskauer Rose indicated that the HSI, which distributes medical, dental, and veterinary supplies, was not even sure any customer data were on the laptop, writing “At this time HSI has no reason to believe that any personal information (if any was actually contained on the laptop) has been or will be accessed or misused. ”

So how do you notify customers when you’re not even sure any customer data were on a stolen device? Is this a “if there were data, then it would have to be _________’s data” thing?

Whenever I read such reports, I always wonder why there was no backup that could tell them definitively whether there were PII on a stolen device and if so, whose. I also wonder why any customer data would be on the device since it seems logical (to me, anyway) that the employee wasn’t working with the data or at the very least, hadn’t worked with it for long enough time that s/he could not longer remember or be sure what was on the laptop. So far, I haven’t come up with any good answers, but maybe there is a scenario that I haven’t considered. [Rampant stupidity? Bob]


(Related) If you don't have expertise in a niche area, ask the Internet. The first Comment provides a (free) answer. See how easy “knowing” can be?

http://tech.slashdot.org/story/09/07/21/218206/Best-Tools-For-Network-Inventory-Management?from=rss

Best Tools For Network Inventory Management?

Posted by kdawson on Tuesday July 21, @05:51PM from the IPs-and-users-and-boxes-oh-my dept. networking

jra writes

"Once every month or so, people ask here about backups, network management, and so on, but one topic I don't see come up too often is network inventory management — machines, serial numbers, license keys, user assignments, IP addresses, and the like. This level of tracking is starting to get out of hand in my facility as we approach 100 workstations and 40 servers, and I'm looking for something to automate it.



Hope for the “Privacy/Security Challenged?” (It is possible some of my students are already sending me their research papers using this tool...

http://it.slashdot.org/story/09/07/21/1522255/Vanish-Makes-Sensitive-Data-Self-Destruct?from=rss

'Vanish' Makes Sensitive Data Self-Destruct

Posted by Soulskill on Tuesday July 21, @12:14PM from the also-doesn't-appear-to-be-a-fire-hazard dept. security encryption

Hugh Pickens writes

"The NY Times reports on new software called 'Vanish,' developed by computer scientists at the University of Washington, which makes sensitive electronic messages 'self destruct' after a certain period of time. The researchers say they have struck upon a unique approach that relies on 'shattering' an encryption key that is held by neither party in an e-mail exchange, but is widely scattered across a peer-to-peer file sharing system. 'Our goal was really to come up with a system where, through a property of nature, the message, or the data, disappears,' says Amit Levy, who helped create Vanish. It has been released as a free, open-source tool that works with Firefox. To use Vanish, both the sender and the recipient must have installed the tool. The sender then highlights any sensitive text entered into the browser and presses the 'Vanish' button. The tool encrypts the information with a key unknown even to the sender. That text can be read, for a limited time only, when the recipient highlights the text and presses the 'Vanish' button to unscramble it. After eight hours, the message will be impossible to unscramble and will remain gibberish forever. Tadayoshi Kohno says Vanish makes it possible to control the 'lifetime' of any type of data stored in the cloud, including information on Facebook, Google documents or blogs."



Interesting approach. If the same information is available for the other state laws, we have the basis for a quick (and useful?) article.

http://www.databreaches.net/?p=6335

FAQ on Nevada’s Security of Personal Information Law (NRS 603A)

July 21, 2009 by admin Filed under Breach Laws, Legislation, State/Local

InfoSecCompliance (”ISC”) was recently asked by a prospective client to provide a summary of Nevada’s Security of Personal Information law (NRS 603A) and a recent amendment to the Security Law that incorporated the Payment Card Industry Data Security Standard (”PCI”). ISC decided to try something new and create a Frequently Asked Questions document around the PCI requirements contained in the Security Law. For better or worse (after sinking in 15 - 20 hours) ISC ended up doing FAQs for the entire Nevada Security Law. This turned out to be a much bigger work than originally anticipated, so ISC is going to do a five-part blog post series breaking down the Nevada Security Law into (hopefully) digestible parts.

This FAQ is broken down into six sections that will be posted over five posts over the next week or so. The postings will be broken down as follows:

Post One: The Basics of Nevada’s Security Law and Destruction of Records

Post Two: Security Breach Notice

Post Three: Required Security Measures

Post Four: Encryption and PCI Compliance

Post Five: Remedies, Penalties and Enforcement

Check the site for updates when the posts become available. Post One is available now.


(Related)

http://www.databreaches.net/?p=6358

Nevada’s Security of Personal Information Law Post Two: The Breach Notice Requirements

July 22, 2009 by admin Filed under Breach Laws, State/Local

From the FAQ provided by InfoSecCompliance:

What triggers the security breach notice obligations under the Security Law?

In order for the breach notice requirements to be triggered under the Security Law two general events must occur (with some sub-requirements discussed further below). First, there must have been a “breach of the security of the system data” discovered by a data collector or notified to a data collector. Second, “personal information” must have actually been acquired by an unauthorized person, or was “reasonably believed to have been acquired” by an unauthorized person.

Read more.


(Related) Perhaps not as detailed as the previous articles, but with some new ideas. Perhaps we need a website that analyzes new and modified laws to see how they are evolving. Provide a similar analysis of the breaches (what are the crooks doing) and it might allow legislatures to understand the issues. (Not that most politicians can actually read.)

http://www.databreaches.net/?p=6325

Missouri data breach notification law goes into effect soon

July 21, 2009 by admin Filed under Breach Laws, Legislation, State/Local

Perkins Coie has provided a short synopsis of key requirements of Missouri’s new data breach notification law, which goes into effect on August 28, 2009.

….. In addition to the more common elements of first name or initial and last name in combination with unencrypted Social Security Number, driver’s license number, financial account number, or credit or debit card number, the statute also includes in the definition of personal information first name or initial and last name in combination with an unencrypted:

  • Unique electronic identifier or routing code, in combination with any required security code, access code, or password that would permit access to an individual’s financial account;

  • Medical information, which includes any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; and

  • Health insurance information, which includes an individual’s health insurance policy number or subscriber identification number, any unique identifier used by a health insurer to identify the individual.

Other provisions of interest:

  • If an entity must notify more than 1000 residents, it must notify the Missouri Attorney General’s office and the nationwide consumer reporting agencies of the breach.

  • Civil penalties for violating the statute may reach up to $150,000 per breach of the security of the system.

The full text of the bill can be found at: http://www.house.mo.gov/billtracking/bills091/biltxt/truly/HB0062T.HTM.

Perkins Coie’s chart summarizing all of the states’ data breach notification laws can be found at: http://www.perkinscoie.com/statebreachchart/.

Source: Perkins Coie blog, Digestible Law.



Interesting that Iran only needs 3 months of data, but the US and the EU want several years.

http://www.pogowasright.org/?p=2052

Iran implements Internet data retention law

July 21, 2009 by Dissent Filed under Govt, Internet, Legislation, Non-U.S., Surveillance

Iranian President Mahmoud Ahmadinejad has implemented a law requiring the country’s Internet service providers to retain records of users’ incoming and outgoing data for at least three months, according to a Monday report by the state-run PressTV news agency. The government said the law is designed to help catch those who illegally steal others’ personal information from the Internet, and that the data would only be monitored under court order or in the interest of national security. [Riiight... Bob] Critics argue that the law will enable the government to monitor and censor the internet use [Al Jazeera report] of reporters and political dissidents, whose blogging and use of social networking websites have thus far been able to evade press restrictions.

Read more on JURIST.



Strategy: First start with someone who does not evoke sympathy. Then you have precedent to extend your program to everyone. “We've been doing this for years!”

http://www.pogowasright.org/?p=2055

Porn actress says state intruded on privacy

July 21, 2009 by Dissent Filed under Breaches, Court, Featured Headlines, Govt, U.S.

A porn film actress whose positive HIV test made news in June claims [pdf] state health officials violated her rights by demanding her medical records. Filing her complaint under the name “Patient Zero,” the woman sued California OSHA and the Adult Industry Medical Healthcare Foundation.

Zero claims that after she tested positive for HIV, the California Division of Occupational Safety and Health subpoenaed her health care provider for her records and personal information, in violation of her right to privacy.

She says that in June the Adult Industry Medical Healthcare Foundation (AIM), which provides health care to sex workers, told her she had preliminarily tested positive for HIV. She says the Foundation quarantined her and everyone known to have had sexual contact with her, and reported her case to the Los Angeles County Department of Public Health.

Cal/OSHA then conducted a surprise inspection of AIM and demanded the medical records of HIV patients, including Patient Zero, but AIM staff refused, she says.

After the inspection, she says, her attorney learned that Cal/OSHA was meeting with the medical facility’s staff to try to get the records of patients with HIV.

Read more on Courthouse News.



Does this mean I'll have to defend my Patent on “A device to measure thermodynamic changes in body temperature as a diagnostic tool? And won't be able to sue anyone who uses a thermometer?

http://yro.slashdot.org/story/09/07/21/1646216/Doctors-Fight-Patent-On-Medical-Knowledge?from=rss

Doctors Fight Patent On Medical Knowledge

Posted by kdawson on Tuesday July 21, @02:20PM from the no-not-patent-medicine dept. patents medicine

I Don't Believe in Imaginary Property writes

"Doctor's groups, including the AMA and too many others to list, are supporting the Mayo Clinic in the case Prometheus v. Mayo. The Mayo Clinic alleges that the patents in question merely recite a natural phenomenon: the simple fact that the level of metabolites of a drug in a person's body can tell you how a patient is responding to that drug. The particular metabolites in this case are those of thiopurine drugs and the tests are covered by Prometheus Lab's 6,355,623 and 6,680,302 patents. But these aren't the only 'observational' patents in medicine — they're part of a trend where patents are sought to cover any test using the fact that gene XYZ is an indicator for some disease, or that certain chemicals in a blood sample indicate something about a patient's condition. There are even allegations that certain labs have gone so far as to send blood samples to a university lab, order testing for patented indicators, then sue that university for infringement. Naturally, Prometheus Labs sees this whole story differently, arguing that the Mayo Clinic will profit from treating patients with knowledge patented by them.

They have their own supporters, too, such as the American Intellectual Property Law Association." Prometheus doesn't seem to be a classic patent troll; they actually perform the tests for which they have obtained patents.



Could they do this for other professions? Law, Medicine, Hacking?

http://www.wired.com/wiredscience/2009/07/wikipedia-training-scientists-on-wiki-culture/

Wikipedia Teaches NIH Scientists Wiki Culture

By Alexis Madrigal Email Author * July 21, 2009 | 1:03 pm



Adopt/Expand/Extend the business model

http://tech.slashdot.org/story/09/07/21/2026200/Applying-a-Music-Business-Model-To-a-Blog?from=rss

Applying a Music Business Model To a Blog

Posted by kdawson on Tuesday July 21, @05:07PM from the try-anything dept. internet business

An anonymous reader writes

"Many of you may be familiar with Mike Masnick, from the site Techdirt. Beyond just chronicling tech stories for years, he's also been following various music and media industry business models as well. While he's usually among the first (like Slashdot) to express dismay at silly activities from the recording industry, lately he's been cataloging numerous success stories, like business models from Trent Reznor, Amanda Palmer, and Josh Freese. Mike and Techdirt are now taking things a step further, and wondering what would happen if they took the lessons from those success stories and applied it to a media publication: their own Techdirt. The result is 'Connect with Fans + Reason to Buy.' Check out the very special offer for the RIAA."



God Bless Open Source! Business model: Put together all the hardware in a kit, sell grain & hops, sponsor contests and annual conventions, drink lots of free beer!

http://www.wired.com/beyond_the_beyond/2009/07/open-source-arduino-robot-beer-brewery/

Open-Source Arduino Robot Beer Brewery

By Bruce Sterling Email Author July 21, 2009 4:37 am |

You may have noticed that I’m something of a skeptic about small-scale urban agriculture interventions. But this one? This is different. ‘Cause it’s beer! Small-scale stills and illicit breweries have a history that is literally as long as the invention of alcohol, tobacco and firearms laws! A revenuer-unfriendly gizmo like this has got proven legs!

So the basic scheme of this device is: you read the instructions, get the hardware, wire it together, plug it in, dump in some grain, walk away and there’s beer later. Who can’t like that? It’s like having your own cool radio-controlled surveillance blimp, except you’re drunk!



Students: If you are going to steal (we call it plagiarism) be sure you can get past these five. (and the ones we don't tell you about)

http://www.makeuseof.com/tag/article-checkers-5-free-websites-to-catch-the-copycats/

Plagiarism Checkers: 5 Free Websites To Catch The Copycats

Jul. 21st, 2009 By Saikat Basu



1) Find a teacher you don't like. 2) Send all of his/her students a link to this site with the suggestion they form an orchestra. 3) Stand outside the computer lab and enjoy the fun!

http://www.makeuseof.com/dir/virtualkeyboard-play-virtual-instruments-online/

VirtualKeyboard: Play Virtual Instruments Online

VirtualKeyboard is another fun web application for the times when you bored. It provides you with virtual keyboard to play 9 different instruments online.

Simply choose your instrument from Piano, Organ, Saxophone, Flute, Pan Pipes, Strings, Guitar, Steel Drums or Double Bass, and start playing. All the keys are labeled so it is easier for beginners to learn. If you are not a big fan of clicking each key with the mouse, you can use keyboard instead.

www.bgfl.org

Tuesday, July 21, 2009

“Interesting,” Anonymous

http://www.pogowasright.org/?p=2021

Judge OKs anon comments, some bloggers don’t

July 20, 2009 by Dissent Filed under Court, Internet, U.S.

There are a couple of interesting new posts around the blogosphere concerning anonymous online commenters. The first, over at Volokh, discusses a recent case out of Tennessee, State v. Cobbins, where a judge denied defendants’ motion to require a media outlet to disable a portion of its Web site enabling Web users to post comments (mostly anonymous) about the pending case. Defendants argued that the site comments could prejudice jurors. The judge denied the motion for a variety of reasons, noting the importance of the First Amendment rights at stake:

The right to speak anonymously extends to speech via the Internet. Internet anonymity facilitates the rich, diverse, and far ranging exchange of ideas. The “ability to speak one’s mind” on the Internet “without the burden of the other party knowing all the facts about one’s identity can foster open communication and robust debate.” People who have committed no wrongdoing should be free to participate in online forums without fear that their identity will be exposed under the authority of the court.

Read more on Legal Blog Watch. The blog entry goes on to discuss the recent trend on some legal blogs to require commenters to provide their real name and email address. [Perhaps we need an “Anonymous Lawyer” blog? Bob]



Too good to be true? Probably.

http://www.techradar.com/news/internet/google-promises-the-end-of-viruses--617790

Google promises 'the end of viruses'

Engineering director claims Chrome OS will finally defeat malware

By Adam Hartley Monday at 11:30 BST

Google's Engineering Director has promised that its forthcoming Chrome OS will see 'the end of malware'.

Google is promising what the latest issue of New Scientist magazine refers to as "a carefree antivirus nirvana" with its forthcoming Google Chrome OS.

… Via New Scientist



Of course, this was before the iPhone (June 2007)

http://www.bespacific.com/mt/archives/021863.html

July 20, 2009

NYT Posts Unreleased Government Report on Dangers of Using Cell Phones While Driving

"The following body of research, conducted by the Department of Transportation and completed in 2003, has not been made public until now. The documents pertain to the safety of using wireless communication devices while driving. The New York Times obtained the research from the Center for Auto Safety and Public Citizen, two consumer advocacy groups that earlier this year acquired more than 250 pages of undisclosed material through a Freedom of Information Act lawsuit." See also Related Article.

[From the report:

The experimental data indicates that, with the exception of the consequences of manipulating a

wireless communications device, there are negligible differences in safety relevant behavior and

performance between using hand-held and hands-free communications devices while driving from

the standpoint of cognitive distraction.



This all started with the evil conspiracy to eliminate the buggy whip industry. No doubt Congress will take action to “Keep American in the Forefront of 19th Century Technology!”

http://www.bespacific.com/mt/archives/021859.html

July 20, 2009

Will There Be a Fight To Save American Manufacturing?

New York Times: "The United States ranks behind every industrial nation except France in the percentage of overall economic activity devoted to manufacturing — 13.9 percent, the World Bank reports, down a percentage point or so in a decade. The 19-month-old recession has contributed to this decline. Industrial production has fallen 17.3 percent, the sharpest drop during a recession since the 1930s... Manufacturing has long been viewed as an essential pillar of a powerful economy. It generates millions of well-paid jobs for those with only a high school education, a huge segment of the population. No other sector contributes more to the nation’s overall productivity, economists say. [Didn't they say that about farming? Bob] And as manufacturing weakens, the country becomes ever more dependent on imports of merchandise, computers, machinery and the like — running up a trade deficit that in time could undermine the dollar and the nation’s capacity to sustain so many imports."



Once again I will be able to argue with the Antitrust lawyers that it is simpler to wait a full “Internet century” (about 10 years) for the “next big thing” to supersede Google, or for Google to follow Microsoft's example and shoot itself in the foot once too often.

http://www.wired.com/techbiz/it/magazine/17-08/mf_googlopoly

Why Is Obama's Top Antitrust Cop Gunning for Google?

By Fred Vogelstein

"I think you are going to see a repeat of Microsoft."

Christine Varney's blunt assessment sent a buzz through the audience at the National Press Club in Washington, DC. Varney, a partner at Hogan & Hartson and one of the country's foremost experts in online law, was speaking at the ninth annual conference of the American Antitrust Institute, a gathering of top monopoly attorneys and economists.

… The technology industry, she said, was coming under the sway of a dominant behemoth, one that had the potential to stifle innovation and squash its competitors. The last time the government saw a threat like this—Microsoft in the 1990s—it launched an aggressive antitrust case. But by the time of this conference, mid-June 2008, a new offender had emerged. "For me, Microsoft is so last century," Varney said. "They are not the problem. I think we are going to continually see a problem, potentially, with Google."

… She acknowledged that her remarks might ruffle some feathers at Google headquarters in Mountain View, California. "If any of my colleagues or friends from Google are here," she said, "I invite you to jump up and scream and yell at me."

Nobody took her up on that offer. But it is safe to assume that plenty of Googlers were jumping and screaming six months later when President Obama appointed Varney head of the Justice Department's antitrust division, making her the government's most powerful antimonopoly prosecutor.

… "Part of what you have to do when you're going to try to bring a [Sherman Antitrust] Section Two case is you have to create the political climate," she said. [Because neither the B-school nor Google's customers believe you have a case. Bob]

… In and of itself, Google's size is not a legal problem.

… Because its search and advertising algorithms are secret, there is no way for competitors or partners to know whether Google tweaks results to direct traffic to its own properties over theirs.

… And even if Google is behaving honorably now, it is creating a system full of temptations should the company ever come under financial pressure.

… Some antitrust experts argue that the natural business cycle will take care of this problem without government intervention, but Varney's three top economists have all said that they favor a hands-on approach. [What did they say when the Republicans were in charge? Bob]



This is an interesting business model. Would it work for other professions?

http://www.killerstartups.com/Web20/pubmeddy-com-science-articles-resources

PubMeddy.com - Science Articles & Resources

http://pubmeddy.com/

Hundreds of articles are published in various fields of medical research ranging from obesity, stem cell, various human syndromes and so forth on a daily basis. The information is usually stored in various publicly available databases. Pubmeddy.com takes that information and automatically makes webpages that users can access to read the articles or research papers of their choice.

This means that now instead of conducting a search that goes “stem cell papers” or “obesity” users can resort to this site and find the latest articles that are published by the scientific community. The site is updated by the hour, which means if you are interested in various fields of biomedical research, you can just check out the website and see what is new at a glance. Websites such as this one (solely devoted to biomedical research) are not that commonplace, and as such it can gather a considerable following.



This is brilliant. Now I can point my students to tools they can try before downloading and installing (i.e. immediate feedback.)

http://www.killerstartups.com/Web20/click2try-com-try-open-source-software-at-no-cost

Click2Try.com - Try Open Source Software At No Cost

http://www.click2try.com/

Quite a well-focused community site, Click2Try will allow you to put open source software to the task without having to incur into downloads of any kind, and without having to worry about setting anything up. Basically, through the site you can gain access to software applications that are pre-configured and already functional, and that are installed on a virtual machine that is also private, and accessible from your desktop.

The advantages of such an approach are obvious: you eliminate long downloads and time-demanding installation procedures, whereas you also dispense with upgrades and integration issues of every kind. In short, a system like this one ensures that you will do without each and every software headache one knows that has to be faced when putting a new application into motion.

There are both standard and premium subscription plans, and there are also different evaluation packages so that if you want to see whether such an approach is what you need in order to have a less-stressful time with your computer this might be where it’s at.



Expect many pointers to presentations and videos...

http://en.oreilly.com/oscon2009

OSCON 2009

[I'm interested in:

Introduction to Forensics

http://en.oreilly.com/oscon2009/public/schedule/detail/8194

Cloud Computing - Why IT Matters

http://en.oreilly.com/oscon2009/public/schedule/detail/9210

Enabling Academic Research – Open Tools and Services on Microsoft Platforms

http://en.oreilly.com/oscon2009/public/schedule/detail/10209

Monday, July 20, 2009

It looks like all the identity Theft is providing a bit of motivation for better Monitoring at least.

http://www.bespacific.com/mt/archives/021851.html

July 18, 2009

Javelin: U.S. Credit Card Issuers Dramatically Improve Customer Fraud Detection

News release: Javelin Strategy & Research released its Fifth Annual Card Issuers’ Identity Safety Scorecard, which analyzes the top 25 U.S. card issuers’ capabilities for protecting customers from identity fraud. To compile the report, Javelin incorporated data from annual household, consumer, and issuer surveys using Javelin’s Prevention, Detection and Resolution™ criteria to accurately reflect customer demands and trends in how issuers protect against fraud. The Javelin scorecard is a structured assessment of each issuer’s fraud protection services. The scorecard ranks features that best empower two major victims of the nation’s $48B identity fraud problem—cardholders and issuers—showing how to turn the tables on a worrying method of crime."



Perhaps this is a pilot project for Google's expansion of Google Maps? Perhaps it is viewed as a way out of California's Budget Crisis? (Visit our town, pay a toll?) Perhaps they think crooks drive around in their own cars... (...a van with “Crooks R Us” painted on the side?)

http://www.pogowasright.org/?p=1995

Tiburon wants to photograph every car

July 19, 2009 by Dissent Filed under Govt, Surveillance, U.S.

Visitors should be prepared to have their pictures taken as they enter and leave this picturesque town of million-dollar views and homes along the San Francisco Bay.

Officials want to photograph every car and use the license plate information to solve crimes in the town of 9,000. Critics see the plan as an intrusion into the rights of visitors, but proponents say it is a sensible precaution that absolutely will not cross privacy lines.

Read more in the Sacramento Bee.



Perhaps lawyers are (at last) noticing the Cloud?

http://www.pogowasright.org/?p=2011

Lost in the Cloud

July 20, 2009 by Dissent Filed under Breaches, Internet, Other

Jonathan Zittrain, a law professor at Harvard and the author of “The Future of the Internet — And How to Stop It,” had an op-ed in The New York Times about the dangers of cloud computing. He writes, in part:

The cloud, however, comes with real dangers.

Some are in plain view. If you entrust your data to others, they can let you down or outright betray you. For example, if your favorite music is rented or authorized from an online subscription service rather than freely in your custody as a compact disc or an MP3 file on your hard drive, you can lose your music if you fall behind on your payments — or if the vendor goes bankrupt or loses interest in the service. Last week Amazon apparently conveyed a publisher’s change-of-heart to owners of its Kindle e-book reader: some purchasers of Orwell’s “1984” found it removed from their devices, with nothing to show for their purchase other than a refund. (Orwell would be amused.)

Worse, data stored online has less privacy protection both in practice and under the law. A hacker recently guessed the password to the personal e-mail account of a Twitter employee, and was thus able to extract the employee’s Google password. That in turn compromised a trove of Twitter’s corporate documents stored too conveniently in the cloud. Before, the bad guys usually needed to get their hands on people’s computers to see their secrets; in today’s cloud all you need is a password.

Thanks in part to the Patriot Act, the federal government has been able to demand some details of your online activities from service providers — and not to tell you about it. There have been thousands of such requests lodged since the law was passed, and the F.B.I.’s own audits have shown that there can be plenty of overreach — perhaps wholly inadvertent — in requests like these.

The cloud can be even more dangerous abroad, as it makes it much easier for authoritarian regimes to spy on their citizens. The Chinese government has used the Chinese version of Skype instant messaging software to monitor text conversations and block undesirable words and phrases. It and other authoritarian regimes routinely monitor all Internet traffic — which, except for e-commerce and banking transactions, is rarely encrypted against prying eyes.

With a little effort and political will, we could solve these problems.

Read more in The New York Times.



Typical politician mis-understanding of technology or recognition that data in the Cloud is out of their control?

http://www.pogowasright.org/?p=1997

Web-based mail exempt from data retention

July 19, 2009 by Dissent Filed under Govt, Internet, Legislation, Non-U.S., Surveillance

Hotmail, Gmail and Yahoo Mail users will be exempt from the (Irish) government’s new telecoms surveillance bill, according to industry experts.

The Retention of Data Bill, published by the Minister for Justice to combat serious criminal offences, compels internet and telephone operators to retain customer data on calls, texts and e-mails for up to two years.

But a loophole will result in the majority of Irish email accounts falling outside its provisions - including the users of popular web-based services such as Hotmail, Gmail and Yahoo Mail. The bill’s provisions will also not affect communications on social networking sites such as Facebook, Bebo and Twitter.

Read more in ThePost.ie.


(Related) Everyone underestimates the Swiss.

http://www.pogowasright.org/?p=2006

Internet interception to start in Switzerland

July 20, 2009 by Dissent Filed under Internet, Non-U.S., Surveillance

Wikileaks.org has published confidential documents that “detail information on an official program for centralized, real-time, interception of Internet traffic in Switzerland. The interception will start on August 1, 2009.”

One of the documents in the file is draft version 0.2 of TR TS (Technical Requirements for Telecommunication Surveillance). It is dated May 2009 and “applies to every telecommunication provider operating in Switzerland or offering services to customers geographically based in Switzerland or abroad.”



What happens when “It's for the children” changes to “It's for your own good?”

http://www.pogowasright.org/?p=2004

Call for NZ website blacklist leak

July 20, 2009 by Dissent Filed under Govt, Internet, Non-U.S.

A euthanasia activist is questioning the Government’s motives behind blocking access to objectionable websites.

The new Digital Child Exploitation Filtering System , worth $150,000, will be provided free to Internet Service Providers (ISPs) in a couple of months.

The Government said 7000 objectionable sites [Is there a US government agency tasked with finding Child Porn sites? If so, which politicians provide constant/extensive/detailed/personal oversight? Bob] would be blocked to fight child sex abuse.

[...]

The software, called Whitebox, will reroute all site requests to government-owned servers.

It compares users’ site requests with a list of banned links. If a match is found, the request is denied.

It will not cover email, file sharing or borderline material.

Internal Affairs censorship compliance head Steve O’Brien said the blacklist would be personally reviewed by staff each month and would be restricted to paedophilic content only.

The scheme was voluntary for internet service providers, but Telecom, TelstraClear and Vodafone, which represented more than 93 percent of the market, had expressed interest in adopting it.

Read more from the New Zealand Press Association.



NOW do you see why I don't trust electronic voting that does not provide an Audit Trail? (Still leaves the question: Why do we (the State Department) want this guy back in power? Perhaps this was a trial run for “Hillary 2012?”)

http://news.slashdot.org/story/09/07/19/1646201/Computerized-Election-Results-With-No-Election?from=rss

Computerized Election Results With No Election

Posted by kdawson on Sunday July 19, @02:28PM from the why-bother-with-mere-tampering dept. government

_Sharp'r_ writes

"In Honduras, according to breaking Catalan newspaper reports (translations available, USA Today mention), authorities have seized 45 computers containing certified election results for a constitutional election that never happened. The election had been scheduled for June 28, but on that day the president, Manuel Zelaya, was ousted. The 'certified' and detailed electronic records of the non-existent election show Zelaya's side having won overwhelmingly."



Are we blazing trail through new areas of law or wading through a swamp of new technologies? When stolen data is “published” (even if only to a few Blogs) does it become “public knowledge?”

http://www.computerworld.com/s/article/9135606/Possible_Twitter_lawsuit_would_dive_into_murky_blog_waters

Possible Twitter lawsuit would dive into murky blog waters

Twitter may file suit against blogs, other Web sites that published hacked information

By Sharon Gaudin July 16, 2009 05:06 PM ET

Computerworld - If Twitter decides to sue Web sites and bloggers that published information pilfered from its systems by hackers, the company could be diving into murky and largely untested legal waters.

Biz Stone, co-founder of the microblogging site, confirmed in a blog post yesterday that a hacker gained access to the personal e-mail account of a Twitter employee and with that was able to lift private company documents. At that point, the hacker offered the information to various blogs and online publications.

Bloggers from multiple Web sites followed the Twitter hack story, but TechCrunch, a well-known blog covering the tech industry, went a step further and published a few of the stolen documents.

… In a blog post yesterday, Michael Arrington, founder and co-editor of TechCrunch, said [...]that any unethical or illegal activity weighs solely on the person who took the information and then distributed it. "On our end, it's simply news," wrote Arrington.

… And then another question pops up: Are bloggers considered to be journalists under the law? That issue, legal experts say, is still up in the air.

Earlier this month, a New Jersey Superior Court judge ruled that a blogger who posted comments about the pornography industry is not protected by journalistic shield laws and can be sued for defamation, according to a report on New Jersey On-Line LLC's NJ.com Web site. [Only in New Jersey can you defame a porn site Bob]


(Related) Background Includes an assertion that the password on (at least one of) Twitter's server was “password”

http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/?awesm=tcrn.ch_6B7

The Anatomy Of The Twitter Attack

by Nik Cubrilovic on July 19, 2009

The Twitter document leak fiasco started with a simple story that personal accounts of Twitter employees were hacked. Twitter CEO Evan Williams commented on that story, saying that Twitter itself was mostly unaffected. No personal accounts were compromised, and “most of the sensitive information was personal rather than company-related,” he said. The individual behind the attacks, known as Hacker Croll, wasn’t happy with that response. Lots of Twitter corporate information was compromised, and he wanted the world to know about it. So he sent us all of the documents that he obtained, some 310 of them, and the story developed from there.



This is huge! What tactic did the EU use to force Microsoft to change?

http://www.pcworld.com/article/168661/internet_explorer_modified_nudged_by_antitrust_charge.html

Internet Explorer Modified -- Nudged by Antitrust Charge?

Gregg Keizer, Computerworld Jul 18, 2009 2:22 pm

Microsoft last week bowed to critics [I doubt it Bob] involved in the company's European antitrust case who have accused it of silently changing users' default browsers, a move that may be aimed at Brussels-based regulators.

Internet Explorer 8 (IE8) will no longer replace a PC's default browser when a user selects the already-checked "Use express settings" option in the setup screen, Microsoft said. Both Opera Software and Mozilla had hammered Microsoft in May over the tactic, accusing the company of force feeding Internet Explorer 8 to users with Windows Update, and silently changing the default browser on PCs.



Strategy This happens when you fail to understand the business you are in. AT&T is still thinking “telephone company” while Apple sees them as a “Data Delivery Utility” (Perhaps Apple should buy AT&T to “save” it.)

http://www.appleinsider.com/articles/09/07/13/apples_iphone_wrecking_the_cell_industry.html

Apple's iPhone "wrecking" the cell industry

By Aidan Malley Published: 06:55 PM EST

Analyst Craig Moffett of Bernstein Research likens the relationship between Apple and AT&T as that between the former and music labels dating as far back as 2001, when Apple first had to ingratiate itself with labels as it incorporated music CD ripping into iTunes. Apple at first won important concessions and praise from its partners, only for them to regret it later as the iPod maker's popularity left these companies at the supposedly smaller company's mercy.

… As late as this spring, AT&T has continued to praise the iPhone as virtually saving the company from the US economy's fallout by driving customers to its network and encouraging them to spend more on data plans. But with the launch of the iPhone 3GS in June and the 3G congestion problems in the months leading up to the handset's debut, AT&T was increasingly cast as Apple's anchor -- keeping a good device locked to a carrier that doesn't enable features like MMS and tethering.


(Related) What happens when Apple customers (used to reliable computers) subscribe to AT&T systems that fail like they did in the 1930's? You get lot's of articles/blogs calling on Apple to dump AT&T.

http://www.techcrunch.com/2009/07/18/att-is-a-big-steaming-heap-of-failure/

AT&T Is A Big, Steaming Heap Of Failure

by MG Siegler on July 18, 2009



I too think they have it backwards. “Really Early Early-Adopters” like the Porn industry see profit in each new technology, but are unlikely to be the research funders.

http://news.cnet.com/8301-17852_3-10290322-71.html?part=rss&subj=news&tag=2547-1_3-0-5

So porn revolutionizes technology, right?

by Chris Matyszczyk July 19, 2009 11:30 AM PDT



Another source of videos for the classroom

http://www.makeuseof.com/dir/watchknow-educational-videos/

WatchKnow: Educational Video Resource

WatchKnow is a new educational video resource for students and teachers. It aggregates quality educational video content from all over the web, nicely organizes it, and presents on clean interface. You can search for videos by keywords and browse by category such as Mathematics, Science, History, Practical Skills, Pedagogy… etc.

www.watchknow.org

Similar websites: Lectr, AcademicEarth and MBAvid.



I use both Google and Wolfram Alpha, so I hope this site recovers from whatever clobbered it.

http://www.makeuseof.com/dir/goofram-search-google-and-wolfram-alpha-at-the-same-time/

Goofram: Search Google And Wolfram Alpha At The Same Time

Goofram lets you search Google and Wolfram Alpha at the same time and compare their search results side-by-side. While Google is a general purpose search engine, Wolfram Alpha bills itself as a “computational knowledge engine” due to its ability to understand and answer natural language queries (”capital of India”, “population growth in California” etc)

http://www.goofram.com/



Might find a use for this in my Stat class...

http://www.makeuseof.com/dir/cynergy-systems-map-us-census-data-online/

Cynergy Systems Map: View US Census Data Online

Cynergy Systems Map is an interesting Google Maps mash up that lets you view US census data online. Simply enter any zip code and the application will show corresponding census data sets such as age distribution, ethnic distribution, household statistics, population statistics, housing units and vacancy rates. For each data set it is possible to view the raw data and a chart view.

www.cynergysystems.com/blogs/blogs/andrew.trice/census



For my Forensics Class

http://www.makeuseof.com/tag/how-to-protect-sensitive-information-by-securely-delete-data-from-your-hard-disk/

How To Protect Sensitive Information by Erasing Your Hard Disk Completely

Jul. 20th, 2009 By Varun Kashyap



Why am I certain that many of my readers will find this interesting? Because I attend so many “Legal Seminars/Wine Tastings”

http://www.bespacific.com/mt/archives/021857.html

July 19, 2009

LLRX Book Review - The Little Red Book of Wine Law: A Case of Legal Issues

LLRX Book Review by Heather A. Phillips: The Little Red Book of Wine Law: A Case of Legal Issues - Heather A. Phillips recommends this slim volume as it provides an engaging and accessible introduction to American wine law and history that will broaden the reader's appreciation of the wine industry. Though short and non-technical, this book is suitable for a surprising number of library collections.


(Related) Proof the iPhone owners are winos?

http://www.killerstartups.com/Web-App-Tools/cellar-app-com-manage-your-wine-collection-on-the-go

Cellar-App.com - Manage Your Wine Collection On The Go

http://cellar-app.com/

In case you are interested in fine wines and you have a wine library, this is the right site for you to stop by. Here, you will start learning about a solution that will be very helpful for you to organize your wine collection. Cellar can be actually defined as a transportable showcase that was designed to let you store your favourite wine selections. This is going to be an interesting and fun way to effectively organize your wine collection.

One of the best things about the site is the fact that allows you to perform a quick data entry as well as to keep track of your wine library. This solution was created by Airsource Ltd and Glasshouse Apps and can be described as a collaborative iPhone app that works precisely when it comes to helping you be well organized in order to learn what to buy the next time you visit the liquor store.

[From their website:

What an amazing launch. To think that Cellar was only approved by Apple on Monday and 24 hours later it was the 15th top paid app in Lifestyle on the US App Store and another 24 hours after that it became the #1 top paid app in Lifestyle on the Australian App Store (even Barista only managed to reach #2).

Sunday, July 19, 2009

How long between the breach (taking the information) and conversion (turning that information into cash)

http://www.databreaches.net/?p=6291

Heartland breach felt in Bermuda

July 18, 2009 by admin Filed under Breach Incidents, Financial Sector, ID Theft

Hundreds of Bermudians may have been the victims of credit card fraud stemming from a US security breach in January.

Many people have had their cards cancelled due to suspicious activity as criminals are using credit cards cloned from information stolen from a credit card processing company in the US.

Capital G President and CEO John Kephart said that around five to six percent of all cardholders in Bermuda have experienced some degree of fraud.

“There’s a lag period of time, and then the copied cards appear,” said Mr. Kephart. “The general consensus is that this is the wave of cards coming out of the breach in January.

Read more in The Royal Gazette.



For my “Advanced Hacking” Class. Includes some good history and background.

http://it.slashdot.org/story/09/07/18/2019228/Security-Threats-3-Levels-Beyond-Kernel-Rootkits?from=rss

Security Threats 3 Levels Beyond Kernel Rootkits

Posted by kdawson on Saturday July 18, @06:19PM from the close-to-the-machine dept. security

GhostX9 writes

"Tom's Hardware has a long interview with security expert Joanna Rutkowska (which is unfortunately split over 9 pages). Many think that kernel rootkits are the most dangerous attacks, but Joanna and her team have been studying exploits beyond Ring 0 for some years. Joanna is most well known for the BluePill virtualization attack (Ring -1) and in this interview she chats a little bit about Ring -2 and Ring -3 attacks that go beyond kernel rootkits. What's surprising is how robust the classic BluePill proof-of-concept is: 'Many people tried to prove that BluePill is "detectable" by writing various virtualization detectors (but not BluePill detectors). They simply assumed that if we detect a virtualization being used, this means that we are "under" BluePill. This assumption was made because there were no products using hardware virtualization a few years ago. Needless to say, if we followed this way of reasoning, we might similarly say that if an executable makes network connections, then it must surely be a botnet.'"

Rutkowska says that for her own security, "I don't use any A/V product on any of my machines (including all the virtual machines). I don't see how an A/V program could offer any increased security over the quite-reasonable-setup I already deployed with the help of virtualization." She runs three separate virtual machines, designated Red, Yellow, and Green, each running a separate browser and used for increasingly sensitive tasks.


(Ditto)

http://www.theregister.co.uk/2009/07/17/linux_kernel_exploit/

Clever attack exploits fully-patched Linux kernel

'NULL pointer' bug plagues even super max versions

By Dan Goodin in San Francisco Posted in Security, 17th July 2009 22:32 GMT


(Related) And we're not even able to handle the simple stuff...

http://www.databreaches.net/?p=6280

GAO report: persisting info sec weaknesses

July 18, 2009 by admin Filed under Breach Incidents, Commentaries and Analyses, Government Sector, Of Note, U.S.

From the Summary of GAO-09-546 July 17, 2009, Information Security: Agencies Continue to Report Progress, but Need to Mitigate Persistent Weaknesses :

Persistent weaknesses in information security policies and practices continue to threaten the confidentiality, integrity, and availability of critical information and information systems used to support the operations, assets, and personnel of most federal agencies. Recently reported incidents at federal agencies have placed sensitive data at risk, including the theft, loss, or improper disclosure of personally identifiable information of Americans, thereby exposing them to loss of privacy and identity theft. For fiscal year 2008, almost all 24 major federal agencies had weaknesses in information security controls. An underlying reason for these weaknesses is that agencies have not fully implemented their information security programs [i.e. We know how, we just haven't Bob]. As a result, agencies have limited assurance that controls are in place and operating as intended to protect their information resources, thereby leaving them vulnerable to attack or compromise. In prior reports, GAO has made hundreds of recommendations to agencies for actions necessary to resolve prior significant control deficiencies and information security program shortfalls. Federal agencies reported increased compliance in implementing key information security control activities for fiscal year 2008; however, inspectors general at several agencies noted shortcomings with agencies’ implementation of information security requirements. Agencies reported increased implementation of control activities, such as providing awareness training for employees and testing system contingency plans. However, agencies reported decreased levels of testing security controls and training for employees who have significant security responsibilities. In addition, inspectors general at several agencies disagreed with performance reported by their agencies and identified weaknesses in the processes used to implement these activities. Further, although OMB took steps to clarify its reporting instructions to agencies for preparing fiscal year 2008 reports, the instructions did not request inspectors general to report on agencies’ effectiveness of key activities and did not always provide clear guidance to inspectors general. As a result, the reporting may not adequately reflect agencies’ implementation of the required information security policies and procedures.

Highlights Page (PDF) Full Report (PDF, 66 pages) Recommendations (HTML)

A few statistics from the report:

When incidents occur, agencies are to notify the federal information security incident center—US-CERT. The number of incidents reported by federal agencies to US-CERT has risen dramatically over the past 3 years, increasing from 5,503 incidents reported in fiscal year 2006 to 16,843 incidents in fiscal year 2008 (slightly more than 200 percent). [p. 10]

The three most prevalent types of incidents reported to US-CERT during fiscal years 2006 through 2008 were unauthorized access (18%), improper usage (22%), and [We don't know what happened, so it's still under... Bob] investigation (34%). [pp. 11-12]



I'm not a visual person (in many ways) but these tools should keep my website students occupied.

http://www.makeuseof.com/tag/tools-to-do-10-cool-things-with-youtube-videos/

10 More Cool Things You Can Do With YouTube Videos

Jul. 18th, 2009 By Varun Kashyap

… Right now, allow us to present forth some of the most popular tools out there to go along with YouTube and the super cool stuff you can do with them.



What do you think about “My life as a Blogger?” OR “How to Mis-Manage IT like a Pro” OR “We don't need no stinking security!”

http://www.makeuseof.com/tag/publish-your-own-book-easily-with-some-help-from-publishamerica/

Publish Your Own Book For Free With Some Help From PublishAmerica

Jul. 18th, 2009 By Guy McDowell

… You write your book. You e-mail or mail it in to PublishAmerica. They review it for quality and grammar and see if it will garner some sort of market. If that’s all good, they’ll talk to you about a contract. You sign the contract. They design a cover for the book. They market the book on their website and to different booksellers such as Barnes and Noble, Ingram, Borders.com and others. They also give you some advice on promoting the book yourself.

Your book sells and they send you royalty payments.

PublishAmerica



(Related?) Build your own library catalog auto-magically and carry it on your thumb drive!

http://www.makeuseof.com/tag/track-your-reading-and-catalogue-your-books-with-booktomb-windows/

Track Your Reading and Catalogue Your Books with BookTomb [Windows]

Jul. 18th, 2009 By Karl L. Gechlik

… I stumbled upon this small portable application called BookTomb and it not only stores all your book loving data – it also has the ability to retrieve book covers, ISBN numbers, descriptions and a bunch more from Amazon, ISBNdb and BookThing.

… If you can’t decide on which book to read next, let Stefan help you out by showing you the 8 best book review sites.



Geeky stuff An interesting and educational poster (if you have a large format printer)

http://fc08.deviantart.com/fs49/i/2009/199/8/4/Computer_hardware_poster_1_7_by_Sonic840.png

Computer Hardware Chart



Forensic tool

http://www.computingunleashed.com/2009/07/protect-your-dvdcd-from-damages-must.html

How To Perfectly Protect Your DVD/CD from Future Damages – A Must Read Guide For Every DVD/CD Collectors

… dvdisaster can also be used to recover the contents of a damaged DVD/CD even when if you havent created the error correction (.ECC) file before / if no ECC file is available. Only problem is that the data recovery chances are less without the error correction (.ECC) file