Thursday, August 27, 2009

Most interesting reading. I expect the government to appeal immediately. They can't live with the limitations this court specifies. (Apparently the California financial crisis hasn't reduced the supply of “medical” marijuana available in the Ninth Circuit.)

http://www.wired.com/threatlevel/2009/08/privacyboost/

Court’s Steroid Ruling Pumps Up Computer Privacy

By David Kravets Email Author August 26, 2009 7:32 pm

A divided 11-judge federal appeals court panel has dramatically narrowed the government’s search-and-seizure powers in the digital age, ruling Wednesday that federal prosecutors went too far when seizing 104 professional baseball players’ drug results when they had a warrant for just 10. [As we all know, lawyers can't count. Bob]

The 9th U.S. Circuit Court of Appeals’ 9-2 decision offered Miranda-style guidelines to prosecutors and judges on how to protect Fourth Amendment privacy rights while conducting computer searches.

… Chief Judge Alex Kozinski, writing for the 9-2 majority, (.pdf) said the government “must maintain the privacy of materials that are intermingled with seizable materials, and … avoid turning a limited search for particular information into a general search of office file systems and computer databases.”

George Washington University law professor and former federal cybercrime prosecutor Orin Kerr called the decision “truly astonishing.”

“The majority opinion … announces a laundry list of brand-new rules, introduced with no citations to any authority, [I wonder if they read my blog? Bob] that henceforth the government must follow when executing warrants for digital information,” Kerr wrote in a post to the Volokh Conspiracy blog. “I can’t recall having read anything quite like it, although it does bring to mind Miranda v. Arizona.”

In dissent, Judges Consuelo Callahan and Sandra Ikuta wrote that the majority was sidestepping its own precedent in which the circuit court had denied the suppression of child pornography evidence found on a computer during a search for the production of false identification cards pursuant to a valid warrant.

There is no rule … that evidence turned up while officers are rightfully searching a location under properly issued warrant must be excluded simply because the evidence found may support charges for a related crime,” the dissenting judges wrote.

[The decision:

http://www.wired.com/images_blogs/threatlevel/2009/08/seizure.pdf



Repeated finding: The scope of any data breach expands dramatically after statements like, “Only a few records were compromised.” (The alternative would force us to the conclusion that politicians were lying to us!)

http://www.databreaches.net/?p=6883

Update: Home Office admits full extent of USB data loss

August 26, 2009 by admin Filed under Breach Incidents, Government Sector, Lost or Missing, Non-U.S., Subcontractor

The Home Office has had to dramatically revise its estimates of the amount of data contained on a memory stick lost by third-party contractor PA Consulting last year.

The department’s newly released Resource Accounts for 2008-09 (PDF) say that the USB device containing Police National Computer and prisoner data actually held 377,000 records, 250,000 more than originally reported.

Read more on V3

Earlier coverage of this breach can be found in the archive of PogoWasRight.org



A detailed (long) article illustrating another axiom of data breaches: If management doesn't understand what happened, they deny that anything happened.

http://www.databreaches.net/?p=6872

School district hiding behind a criminal investigation - parent

August 26, 2009 by admin

On the principle of “no good deed goes unpunished,” some of those who have discovered and reported breaches have been terminated or prosecuted for their actions...

Now a parent of a disabled student alleges that he is being investigated by the FBI because he discovered and reported a security breach that his child’s school district has not owned responsibility for.

… He claims that it wasn’t until four months later, however, when he went back to a publicly available document on Leander’s web site called “Welcome to the World of eSped” that he noticed that screen shots of the eSped system in that public document displayed logins and passwords to the system. [Probably created by “screen capture” of the logon process by someone with full access to the system. Bob] Short informs this site that he impulsively tested one of the logins on eSped’s site and found that it gave him access to Leander’s special education records.



Your tax data will never be used for any other purpose. Your health data will never be used for any other purpose.

http://www.pogowasright.org/?p=3202

Democratic health care bill divulges IRS tax data

August 27, 2009 by Dissent Filed under Featured Headlines, Govt, Legislation, U.S.

Over on Taking Liberties, Declan McCullagh has some commentary on provisions in the proposed health care bill, H.R. 3200, that relate to privacy. Some of the provisions in the massive bill include:

Section 431(a) of the bill says that the IRS must divulge taxpayer identity information, including the filing status, the modified adjusted gross income, [because if you're rich you get better coverage and you get to be on the Democrat's fund raising list. Bob] the number of dependents, and “other information as is prescribed by” regulation. That information will be provided to the new Health Choices Commissioner and state health programs and used to determine who qualifies for “affordability credits.”

Section 245(b)(2)(A) says the IRS must divulge tax return details — there’s no specified limit on what’s available or unavailable — to the Health Choices Commissioner. The purpose, again, is to verify “affordability credits.”

Section 1801(a) says that the Social Security Administration can obtain tax return data on anyone who may be eligible for a “low-income prescription drug subsidy” but has not applied for it.

Read more on CBS News.



Let me see if I get this right. They're bragging about catching this guy after failing to do so 9 times in a row. Yeah. Great software.

http://news.cnet.com/8301-17852_3-10318536-71.html?part=rss&subj=news&tag=2547-1_3-0-20

Man with 25 IDs nabbed by face-recognition tech

by Chris Matyszczyk August 26, 2009 12:14 PM PDT

… However, according to authorities in Indiana, his real name was George Helms and he assumed at least 10 different names in that state alone.

According to CBS2 Chicago, Helms walked into the Hobart, Ind., license branch to obtain an 11th ID. No one seems really sure why he would want an 11th license.

What Helms appears not to have known is that Indiana has invested in new facial recognition software.

Helms allegedly had all the correct paperwork and then posed for his photograph. However, in the evening after his application was approved, the photograph passed through the new facial recognition system, which spotted an allegedly remarkable similarity with 10 other licenses, according to the report.



Remember, “We locked the barn door!” should only happen after, “We put the horse in the barn.”

http://www.bespacific.com/mt/archives/022165.html

August 26, 2009

DHS and Information Technology Sector Coordinating Council Release Information Technology Sector Baseline Risk Assessment

News release: "The Department of Homeland Security (DHS) and the Information Technology Sector Coordinating Council (IT SCC) today released the IT Sector Baseline Risk Assessment (ITSRA) to identify and prioritize national-level risks to critical sector-wide IT functions while outlining strategies to mitigate those risks and enhance national and economic security... The ITSRA validates the resiliency of key elements of IT sector infrastructure while providing a process by which public and private sector owners and operators can continually update their risk management programs. The assessment links security measures to concrete data to provide a basis for meaningful infrastructure protection metrics." [This control.....Didn't work. Bob]


(Related) In the US, wouldn't we (taxpayers) already own the code? Could we send the NSA a FOIA request? (The Swiss like their cheese and your network with holes.)

http://it.slashdot.org/story/09/08/26/144249/Coder-of-Swiss-Wiretapping-Trojan-Speaks-Out?from=rss

Coder of Swiss Wiretapping Trojan Speaks Out

Posted by Soulskill on Wednesday August 26, @10:41AM from the is-swiss-software-full-of-security-holes dept.

Lars Sobiraj writes

"Ruben Unteregger has worked for a long time as a software-engineer for the Swiss company ERA IT Solutions. His job there was to code malware that would invade PCs of private users, and allow the wiretapping of VoIP calls — in particular, calls made through Skype. In the German-speaking areas of the country, the Trojans were called 'Bundestrojaner' because the Swiss government was involved with their development and use. Unfortunately, Unteregger has to remain silent about the customers of the company. Last night, he published the source code of his Skype-Trojan under the GPL."



This is always one of the options on the negotiation table, so they can't complain.

http://www.hollywoodreporter.com/hr/content_display/news/e3i34ed7d659fd02963e279d2dc2ecf9406

TiVo sues AT&T and Verizon

DVR firm claims patent infringement

By Paul Bond Aug 26, 2009, 08:36 PM ET

Unable to strike a deal with either of the major phone companies that offer TV services, TiVo on Wednesday sued them both.

TiVo filed its DVR patent infringement lawsuits against AT&T and Verizon in the U.S. District Court in the Eastern District of Texas, where it has been battling -- mostly successfully -- Dish Network for five years.

TiVo has already taken Dish for more than $200 million and a judge has slapped a permanent injunction, now being appealed, against Dish. If all goes TiVo's way, Dish will have to shut off millions of its customers' DVRs or strike a licensing deal with TiVo.

Now, the company that introduced DVRs to the world is hoping for a similar outcome against the two phone companies.



Do they mean, “If it ain't work related, don't do it on government owned equipment or during work hours?”

http://yro.slashdot.org/story/09/08/26/1956201/US-Fed-Gov-Says-All-Music-Downloads-Are-Theft?from=rss

US Fed Gov. Says All Music Downloads Are Theft

Posted by timothy on Wednesday August 26, @04:29PM from the bit-of-a-broad-brush-there dept.

BenEnglishAtHome writes

"Nearly all US government employees and contractors are subject to mandatory annual information security briefings. [This is a good thing. Bob] This year the official briefing flatly states that all downloaded music is stolen. The occasionally breathless tone of the briefing and the various minor errors contained therein are funny but the real eye-opener is a 'secure the building' exercise where employees stumble across security problems and resolve them. According to the material, the correct response to an employee who is downloading music is to shout 'That's stealing!' No mention is made of more-free licenses, public domain works, or any other legitimate download. If this were a single agency or department that had made a mistake in their training material it might not be so shocking. But this is a government-wide training package that's being absorbed by hundreds of thousands of federal employees, both civilian and military. If you see a co-worker downloading music, they're stealing. Period. Who woulda thunk it? Somebody should mirror this. Who wants to bet that copies will become hard to find if clued-in technogeeks take notice and start making noise?"

Warning: this site gives a whole new meaning to "Flash heavy."



Dear Government Guys, Thank you for putting all of your utility communications eggs is one easily accessed basket. Sincerely, The League of Extraordinary Hackers

http://arstechnica.com/tech-policy/news/2009/08/utilities-may-get-dedicated-chunk-of-spectrum-for-smart-grid.ars

Utilities may get dedicated chunk of spectrum for smart grid

As part of its broadband hearings, the FCC looked at whether it should follow Canada's lead and allocate a chunk of spectrum to give utilities wireless broadband for smart grid devices.

By John Timmer Last updated August 26, 2009 2:41 PM CT



Remember the IBM commercials that suggested you would be able to listen to “Every song ever recorded?” This is how that will happen. No need for local storage, since you can access anything from anywhere.

http://www.wired.com/entertainment/music/magazine/17-09/pl_music

5 Apps Tap the Internet's Infinite Playlist

By Eliot Van Buskirk Email 08.24.09

It used to be you needed a ginormous hard drive to build and store your digital music collection. But now that most songs exist somewhere in the cloud—on YouTube, one-stop streaming sites like imeem, or blog aggregators like Hype Machine—services have emerged that help you squeeze the Internet for any track you need. Wherever music lives, you can now play, collect, and share it without downloading any audio files. None of these sites is pitch-perfect, and their fidelity isn't as high as your meticulously encoded lossless library. But in these lean times, free jams are sounding better by the minute.



For my Disaster/Recovery students. Creating an “excuse free” contingency plan.

http://www.pcworld.com/article/170688/7_backup_strategies_for_your_data_multimedia_and_system_files.html

7 Backup Strategies for Your Data, Multimedia, and System Files

Nobody likes backing up, but one day, it’ll save your bacon. Here are the most efficient methods of protecting your stuff, no matter what your situation.

Lincoln Spector, PC World Aug 25, 2009 7:00 pm



Tools & Techniques This could be very handy. I could create a new web page for each of my lectures, with all the links and images. Also useful in the website class...

http://www.makeuseof.com/tag/create-a-free-rinky-dink-disposable-web-page-with-dinky-page/

Create a Free Disposable Web Page with DinkyPage

Aug. 27th, 2009 By Karl L. Gechlik

Have you ever had the need to create a free web page quickly to share information with a group of people or even a team member? You have to fire up your editor, make the page and then upload the page to the site, find the URL and pass it around.

Now we have discovered a service that does ALL the hard work for you! It’s called DinkyPage and can be found here.

Wednesday, August 26, 2009

Now do you understand, Mr. Chairman?

http://www.pogowasright.org/?p=3136

Bernanke Victimized by Identity Fraud Ring

August 25, 2009 by Dissent Filed under Breaches, U.S.

If ever there were living proof that identity theft can strike the mighty and powerful as well as hapless consumers, look no further than the nation’s chief banker: Ben Bernanke. The Federal Reserve Board chairman was one of hundreds of victims of an elaborate identity-fraud ring, headed by a convicted scam artist known as “Big Head,” that stole more than $2.1 million from unsuspecting consumers and at least 10 financial institutions around the country, according to recently filed court records reviewed by NEWSWEEK.

Read more in Newsweek



Small businesses have little leverage with the banks. Perhaps a Class Action to require the banks to extend the same level of security the give to individuals?

http://it.slashdot.org/story/09/08/25/2033206/Banks-Urge-Businesses-To-Lock-Down-Online-Banking?from=rss

Banks Urge Businesses To Lock Down Online Banking

Posted by kdawson on Tuesday August 25, @08:14PM from the no-social-no-engineering dept.

tsu doh nimh writes

"Organized cyber-gangs in Eastern Europe are increasingly preying on small and mid-size companies in the US, setting off a multimillion-dollar online crime wave that has begun to worry the nation's largest financial institutions, The Washington Post's Security Fix blog reports: '"In the past six months, financial institutions, security companies, the media and law enforcement agencies are all reporting a significant increase in funds transfer fraud involving the exploitation of valid banking credentials belonging to small and medium sized businesses," reads a confidential alert issued by the Financial Services Information Sharing and Analysis Center, an industry group created to share data about critical threats to the financial sector.' The banking group is urging that commercial bank customers 'carry out all online banking activity from a standalone, hardened, and locked-down computer from which e-mail and Web browsing is not possible.' The story includes interviews with several victim businesses, and explains that in each case, the fraudsters — thought to reside in Eastern Europe — are using "'money mules,' unwitting or willing accomplices in the US hired via Internet job boards. The blog has more stories and details about these crimes."

[From the first article:

According to the latest estimates by anti-virus maker Trend Micro, at least 253 million systems were infected with malware last year, the majority of which were the result of software lying in wait on hacked or malicious Web sites.

[From the second article:

"All of the people who have called us are very angry with their respective banks," Slack said. "Most have retained attorneys and I think they are afraid of publicity."

[From a related story at: http://www.washingtonpost.com/wp-dyn/content/article/2009/08/24/AR2009082402272.html

In many cases, the advisory warned, the scammers infiltrate companies in a similar fashion: They send a targeted e-mail to the company's controller or treasurer, a message that contains either a virus-laden attachment or a link that -- when opened -- surreptitiously installs malicious software designed to steal passwords. Armed with those credentials, the crooks then initiate a series of wire transfers, usually in increments of less than $10,000 to avoid banks' anti-money-laundering reporting requirements.

… Businesses do not enjoy the same legal protections as consumers when banking online. Consumers typically have up to 60 days from the receipt of a monthly statement to dispute any unauthorized charges.

In contrast, companies that bank online are regulated under the Uniform Commercial Code, which holds that commercial banking customers have roughly two business days to spot and dispute unauthorized activity if they want to hold out any hope of recovering unauthorized transfers from their accounts.

Avivah Litan, a fraud analyst with Gartner Inc., said few commercial banks have invested in back-end technologies that can detect fraudulent or unusual transaction patterns for businesses.

"The banks spend a lot of money on protecting consumer customers because they owe money if the consumer loses money," Litan said. "But the banks don't spend the same resources on the corporate accounts because they don't have to refund the corporate losses."



Something wrong when violations of citizen privacy is punished by taking citizen tax moneys and ignoring the bad actors.

http://www.pogowasright.org/?p=3134

Tentative settlement between govt and FL on sale of DMV records

August 25, 2009 by Dissent Filed under Breaches, Govt, U.S.

The Associated Press is reporting that Florida Governor Charlie Crist and the Florida Cabinet have agreed to pay the federal government $1.5 million to settle charges that the state violated motorists’ privacy by selling their personal information in motor vehicle records to businesses during the period June 1, 2000 to September 30, 2004. The legislature still has to approve the deal.



Tools & Techniques Privacy enabling tool?

http://www.techcrunch.com/2009/08/25/use-twitter-anonymously-this-will-not-end-well/

Use Twitter Anonymously. This Will Not End Well.

by MG Siegler on August 25, 2009

… a new service (which is really two new services) wants to make anonymous tweeting easy: Tweet From Above and Tweet From Below.

As their names imply, one of these services is meant to be used for good, while the other is meant for evil. Both allow you to use a third-party Twitter account to send out messages. While you might think that’s pointless, if you use it to @reply someone, they will obviously see the tweet, without knowing exactly who it is from.



This could be huge! (If they define neutrality the way geeks do)

http://tech.slashdot.org/story/09/08/25/2044233/FCC-Declares-Intention-To-Enforce-Net-Neutrality?from=rss

FCC Declares Intention To Enforce Net Neutrality

Posted by kdawson on Tuesday August 25, @05:38PM from the play-nice-now dept.

Unequivocal writes

"The FCC chairman, Julius Genachowski, told Congress today that the 'Federal Communications Commission plans to keep the Internet free of increased user fees based on heavy Web traffic and slow downloads. ...Genachowski... told The Hill that his agency will support "net neutrality" and go after anyone who violates its tenets. "One thing I would say so that there is no confusion out there is that this FCC will support net neutrality and will enforce any violation of net neutrality principles," Genachowski said when asked what he could do in his position to keep the Internet fair, free and open to all Americans. The statement by Genachowski comes as the commission remains locked in litigation with Comcast. The cable provider is appealing a court decision by challenging the FCC's authority to penalize the company for limiting Web traffic to its consumers.' It looks like the good guys are winning, unless the appeals court rules against the FCC."


(Related) ...and while we're on the subject... You can zoom the map to County and Zip Code level. Also contains a “Test your speed” widget.

http://www.speedmatters.org/content/2009report/

2009 Report on Internet Speeds in All 50 States

[Or just Colorado:

http://files.cwa-union.org/speedmatters/State_Reports_2009/CWA_Report_on_Internet_Speeds_2009_Colorado.pdf



Business opportunity

http://www.wired.com/epicenter/2009/08/the-craigslist-credo-bad-advice-for-newspapers

The Craigslist Credo: Bad Advice for Newspapers

By Gary Wolf Email Author August 25, 2009 3:30 pm

Here is a question I took away from my reporting on craigslist: Why, given the site’s notorious shortcomings, has nobody ever succeeded in taking business away from it?


The business we should have started in the DotCom era?

http://www.techcrunch.com/2009/08/25/betfair-growing-30-easing-over-the-pond-and-hiring-50-valley-engineers/

Betfair Growing 30%, Easing over the Pond, and Hiring 50 Valley Engineers

by Sarah Lacy on August 25, 2009

Most Web sites started in the late 1990s have either gone public, been acquired or are defunct. Wired has a rather harsh cover story on one of the most famous ones that isn’t, Craigslist. But there’s another one that could rile up even more attorneys generals and socially conservative figureheads: Betfair.

The London-based online gambling company is seldom written about or mentioned in the U.S. despite its gargantuan size. It employs 1,800 people around the world, generates more than $500 million in annual revenues and is profitable. Oh, and those revenues have grown nearly 30% in the last year. What world-wide recession?

… The company is well aware that legislation is making the rounds that could legalize online poker, and while it doesn’t want to be one of those lobbying for changes, be sure the company will be ready to throw a ton of money at the U.S. should the laws change.



Something for the Forensic toolkit

http://www.bespacific.com/mt/archives/022148.html

August 25, 2009

NIST Guidelines recommends best practices for next generation of portable biometric acquisition devices

"A new publication that recommends best practices for the next generation of portable biometric acquisition devices—Mobile ID—has been published by Commerce’s National Institute of Standards and Technology (NIST). Devices that gather, process and transmit an individual’s biometric data—fingerprints, facial and iris images—for identification are proliferating. Previous work on standards for these biometric devices has focused primarily on getting different stationary and desktop systems with hard-wired processing pathways to work together in an interoperable manner. But a new generation of small, portable and versatile biometric devices are raising new issues for interoperability."



Tools & Techniques For when you don't want to re-type a document.

http://www.makeuseof.com/tag/top-5-free-ocr-software-tools-to-convert-your-images-into-text-nb/

Top 5 Free OCR Software Tools To Convert Images Into Text

Aug. 25th, 2009 By Saikat Basu

… Ah, modern technology is wonderful; take a scanned image (or take a snap using a mobile camera/Digicam) and presto – OCR software extracts all the information from the image into easily editable text format.



Tools & Techniques For the multi-tasker

http://www.makeuseof.com/tag/use-officetab-to-give-microsoft-office-applications-firefox-like-tabs/

Use OfficeTab To Give Microsoft Office Firefox-Like Tabs

Aug. 26th, 2009 By Karl L. Gechlik

I got a hot tip today on a piece of Chinese software that will make my life MUCH easier by adding Microsoft Office tabs to your installed MS applications. Have you heard of OfficeTab?

… Feel free to download OfficeTab from this link. BUT WAIT – the catch is that the site is NOT in English.

So the direct download link lives here which, if you scroll down to the bottom of the product page, is the only link there. So no need for Google Translations today. The actual application IS multilingual so there are no issues there.



Global Warming! Global Warming! Will this make Al Gore a monkey?

http://science.slashdot.org/story/09/08/26/0117230/Global-Warming-To-Be-Put-On-Trial?from=rss

Global Warming To Be Put On Trial?

Posted by ScuttleMonkey on Wednesday August 26, @08:23AM from the break-out-the-popcorn dept.

Mr_Blank writes to mention that the United States' largest business lobby is pushing for a public trial to examine the evidence of global warming and have a judge make a ruling on whether human beings are warming the planet to dangerous effect.

"The goal of the chamber, which represents 3 million large and small businesses, is to fend off potential emissions regulations by undercutting the scientific consensus over climate change. If the EPA denies the request, as expected, the chamber plans to take the fight to federal court. The EPA is having none of it, calling a hearing a 'waste of time' and saying that a threatened lawsuit by the chamber would be 'frivolous.' [...] Environmentalists say the chamber's strategy is an attempt to sow political discord by challenging settled science — and note that in the famed 1925 Scopes trial, which pitted lawyers Clarence Darrow and William Jennings Bryan in a courtroom battle over a Tennessee science teacher accused of teaching evolution illegally, the scientists won in the end."



A couple for my fellow teachers...

http://teachingcollegemath.com/?p=1254

Teaching and Learning in the Digital Age


http://teachingcollegemath.com/?p=1248

Mindmaps for Learning

Tuesday, August 25, 2009

Intelligence agencies fell into the same trap when they put all their marbles into satellites rather than human intelligence. Never confuse broad (global in the case of satellites) coverage with deep or useful coverage. What do you bet they buy lots more cameras?

http://yro.slashdot.org/story/09/08/24/2031258/One-Crime-Solved-Per-1000-London-CCTV-Cameras?from=rss

One Crime Solved Per 1,000 London CCTV Cameras

Posted by kdawson on Monday August 24, @07:09PM from the ready-for-my-closeup-mister-demille dept.

SpuriousLogic writes

"Only one crime was solved for each 1,000 CCTV cameras in London last year, a report into the city's surveillance network has claimed. The internal police report found the million-plus cameras in London rarely help catch criminals. In one month CCTV helped capture just eight out of 269 suspected robbers. David Davis MP, the former shadow home secretary, said: 'It should provoke a long overdue rethink on where the crime prevention budget is being spent.' He added: 'CCTV leads to massive expense and minimum effectiveness. It creates a huge intrusion on privacy, yet provides little or no improvement in security. The Metropolitan Police has been extraordinarily slow to act to deal with the ineffectiveness of CCTV.'"


(Related) I see they have incorporated one of my cliches...

http://www.pogowasright.org/?p=3132

Personal spy gear: Is it ethical? Is it legal?

August 25, 2009 by Dissent Filed under Surveillance

… while it’s easy to find and buy surveillance devices, is it legal and/or ethical to use them? Is it okay if you use them to watch over strangers? Is it reasonable to use them to watch and hear family members and loved ones?

The answers can sometimes be murky.

“There are definitely legalities to consider,” said Lee Tien, a senior staff attorney for the San Francisco-based non-profit privacy group Electronic Frontier Foundation. “Just because you can do something doesn’t mean you should do it.” [We can, therefore we must! Bob]

[...]

Behnam Dayanim, an attorney with Los Angeles-based Paul, Hastings, Janofsky & Walker LLP, said the legal lines on the use of such devices can be blurry.

“The acceptability or permissibility of these techniques depends on several factors, including where they were activated, who is undertaking the activity and what notice is provided to the subject of the activation,” Dayanim said. “There are different degrees of privacy interests. The greatest privacy interest is in your own home.”

Read more on Computerworld.

[From the article:

http://www.theprotectionpros.com/

http://spygear4u.com/

http://www.spytek-detroit.com/

A sampling of security gear

There's an ocean of high-tech personal security devices out there. These are only a few:

Hidden cameras

GPS trackers

Audio recorders (with automatic voice activation)



What make you think you need cameras to monitor you citizens?

http://www.time.com/time/magazine/article/0,9171,1916302,00.html

Seoul: World's Most Wired Megacity Gets More So

By Stephen Kim and Bill Powell Monday, Aug. 24, 2009

In the sprawling, densely populated capital city of South Korea, Lee Hye-young and her husband Kim Soon-kyo are nothing if not typical citizens. Which is to say, even the most mundane, everyday aspects of their lives are carried out at technology's leading edge.

Consider their respective commutes to work early one recent morning. Lee clambers onto a city bus, headed to her office job in the southern part of the city. She pays using her radio-frequency-identification (RFID) card — it has a computer chip in it — part of a transit program conceived and implemented by the city government. The card is smart enough to calculate the distance she travels on any form of public transit, which determines the fare. She can then use the same card to pay for the taxi she hails to finish her journey to work. Sometimes her husband, the deputy marketing manager at a small chemical company, drives her to work. But not today. A few months ago, he applied online to join a program offered by the city that promises insurance discounts, reduced-cost parking and a tax break if he leaves his car home one business day a week. The city sent him an RFID tag, which he attaches to the windshield so the city can monitor compliance. It took him just minutes to fill out the application on his home computer, and now, he says, he saves the equivalent of $50 a month.

Seoul has even greater e-ambitions. It has begun to implement a project called Ubiquitous Seoul [Where have I heard that word before? Bob] — or U-city — which will extend the city's technological reach.


(Related) How citizens monitor themselves...

http://www.pogowasright.org/?p=3114

Social networks leak personal information

August 24, 2009 by Dissent Filed under Internet

Online social networking sites leak personal information, a new study has found, raising the possibility that users of such sites can be tracked everywhere they go online.

The study, “On the Leakage of Personally Identifiable Information Via Online Social Networks,” was co-authored by Balachander Krishnamurthy, a researcher at AT&T Labs and Craig E. Wills, a professor of computer science at the Worcester Polytechnic Institute in Massachusetts, and presented last week at the Second ACM SIGCOMM Workshop on Online Social Networks in Barcelona, Spain.

Read more on InformationWeek


(Related) How to document your cheating...

http://www.techcrunch.com/2009/08/25/facebook-conversations-used-as-evidence-in-exam-cheating-case/

Facebook Conversations Used As Evidence In Exam Cheating Case

by Robin Wauters on August 25, 2009

… But then a couple of threads on Facebook held prior to and after the exams surfaced, proving that the cheating had been going on for quite a while and showing that the students were pretty proud of the fact they hadn’t been caught to date.



Be sure to mention this to your politician of choice – it could cause apoplexy! (De-porkification?)

http://news.cnet.com/8301-13505_3-10316621-16.html?part=rss&subj=news&tag=2547-1_3-0-20

Open source, not $19 billion, may be best health care stimulus

by Matt Asay August 24, 2009 3:52 PM PDT

The federal economic stimulus package provides $19 billion to upgrade the U.S. health care system to digital records. It's a nice gesture, but the U.S. federal government has already developed a robust medical ERP system that could significantly improve U.S. health care. It's called VistA. It's open source.



For my hacker students...

http://news.cnet.com/8301-27080_3-10316812-245.html?part=rss&subj=news&tag=2547-1_3-0-20

Cracking GSM phone crypto via distributed computing

by Elinor Mills

If you are using a GSM phone (AT&T or T-Mobile in the U.S.), you likely have a few more months before it will be easy for practically anyone to spy on your communications.

Security researcher Karsten Nohl is launching an open-source, distributed computing project designed to crack the encryption used on GSM phones and compile it into a code book that can be used to decode conversations and any data that gets sent to and from the phone.

… This weakness in the encryption used on the phones, A5/1, has been known about for years. There are at least four commercial tools that allow for decrypting GSM communications that range in price from $100,000 to $250,000 depending on how fast you want the software to work, said Nohl, who previously has publicized weaknesses with wireless smart card chips used in transit systems.



No, no, no, no... Please do not resuscitate!

http://yro.slashdot.org/story/09/08/25/0021246/Appeals-Court-Overturns-2007-Unix-Copyright-Decision?from=rss

Appeals Court Overturns 2007 Unix Copyright Decision

Posted by kdawson on Tuesday August 25, @08:09AM from the long-dark-teatime dept.

snydeq writes

"A federal appeals court has overturned a 2007 decision that Novell owns the Unix code, clearing the way for SCO to pursue a $1 billion copyright infringement case against IBM. In a 54-page decision (PDF), the 10th Circuit Court of Appeals said it was reversing the 2007 summary judgment decision by Judge Dale Kimball of the US District Court for the District of Utah, which found that Novell was the owner of Unix and UnixWare copyrights. SCO CEO Darl McBride called the decision a 'huge validation for SCO.'"

The case over who owns Unix will now go to trial in Utah.



Strange choices some of them...

http://www.time.com/time/specials/packages/completelist/0,29569,1918031,00.html

50 Best Websites 2009

[A couple of sites to visit:

http://www.californiacoastline.org/ Pictures of Barbara Streisand's house gave us the term “Streisand Effect”

http://www.academicearth.org/ Full video courses from leading universities.



I'll suggest this to my students who will make a careful and detailed note and then never see it again...

http://www.makeuseof.com/tag/notely-helps-students-get-organized-online/

Notely Helps Students Get Organized Online

Aug. 24th, 2009 By Stefan Neagu

… Since the statistics say that more than 90% of college students own a computer with an Internet connection, why not take a look at a web application that helps students easily achieve GTD nirvana: Notely.

This is what Notely does; It takes all the tools that a student needs to be organized and get stuff done and brings it together in a shrink wrapped package for anyone to use.

Signing up for an account is completely free and takes just seconds – it will even work with an existing OpenID login. After that, you can start adding courses, to do’s, notes – all on a single website. While manually inputting 20 classes doesn’t look that enticing, it’s a one-time only thing and you’re not going to regret it.

It’s also got a Tools section, which contains a scientific calculator, a comprehensive unit converter and a dictionary that makes use of the Google Translate API.

You can sign up for Notely here, or view a live demo.



Personal forensics...

http://www.makeuseof.com/tag/use-licensecrawler-to-recover-your-lost-software-serial-numbers/

Use LicenseCrawler To Recover Your Lost Software Serial Numbers

Aug. 25th, 2009 By Karl L. Gechlik

Have you ever had a installation of something that you wanted to reinstall but you couldn’t? Have you ever lost a software serial number or key code? How about something that was pre-installed on your system – how do you reinstall that?

… It is a neat little piece of freeware called LicenseCrawler.

After downloading the application you simply run it and it will return all the keys from your computer.



I suspect this will be useful. There are tons of webinars...

http://www.killerstartups.com/Web20/webinarhero-com-finding-webinars-easily

WebinarHero.com - Finding Webinars Easily

http://www.webinarhero.com/

As you can figure out by looking at its name, this site is about webinars. What it does is to gather together information as regards such events, and present it to the user so that anybody can learn about any upcoming webinar that could appeal to him or her immediately.

Monday, August 24, 2009

More pieces are fitting into place.

http://www.databreaches.net/?p=6847

Hacking ring linked to theft at Citibank ATMs

August 23, 2009 by admin Filed under Breach Incidents, Business Sector, Financial Sector, ID Theft, Of Note, Skimmers, U.S.

The hacking ring allegedly at the centre of the world’s largest identity theft [Heartlan, TJX, et alia Bob] last week was also involved in cracking a network of Citibank-branded ATMs in 7-Eleven stores and operated by a third company, a law enforcement source claimed.

[...]

In the case of the Citibank-branded ATMs, the perpetrators penetrated a network linking 2,200 kiosks inside 7-Eleven stores from late 2007 until at least February 2008, the law enforcement sources said.

The ATMs displayed Citibank’s logo. The network and the machines were owned by Texas-based CardTronics, which took in monthly fees from Citi.

[...]

CardTronics said its machines were the ones affected. Its chief marketing officer, Brian Archer, told the Financial Times that the breach occurred on a back-end system that had been outsourced by 7-Eleven, the prior owner of the machines, and had not yet been brought onto CardTronics’ internal network.

Read more on Financial Times.



Not all hacks are attempts at Identity Theft. Some are auditions for jobs at National Lampoon or the Onion.

http://www.theregister.co.uk/2009/08/21/sears_baby_roaster/

Baby-roasting BBQ pulled from Sears site

Red-faced retailer apologizes

By Dan Goodin in San Francisco Posted in Enterprise Security, 21st August 2009 19:20 GMT

In a blunder that might top the Baby Shaker app on Apple's App Store, retailing giant Sears.com has been caught offering a Bar-B-Que grill specially designed to roast infants and other human morsels.

The ad, which was spotted earlier by celebrity news site TMZ, showed a Kenmore natural-gas grill with five burners. A caption above the photo read: "Human cooking > Grills to cook babies and more > Body part roaster."

Sears quickly labeled the cannibal-themed grill a prank that was carried out by someone visiting the company's website.

"We discovered earlier today that someone visiting our site had defaced a limited number of product pages," the company said in a written statement to FOXNews.com. "We've already taken steps to prevent this from happening again."



I think these are a bit older than the article suggests.

http://it.slashdot.org/story/09/08/23/2015208/Real-Time-Keyloggers?from=rss

Real-Time Keyloggers

Posted by kdawson on Sunday August 23, @05:18PM from the taking-a-leaf-from-twitter dept.

The NY Times has a story and a blog backgrounder focusing on a weapon now being wielded by bad guys (most likely in Eastern Europe, according to the Times): Trojan horse keyloggers that report back in real-time. The capability came to light in a court filing (PDF) by Project Honey Pot against "John Doe" thieves. The case was filed in order to compel the banks — which are almost as secretive as the cyber-crooks — to reveal information such as IP addresses that could lead back to the miscreants. Or at least allow victims to be notified. Real-time keyloggers were first discovered in the wild last year, but the court filing and the Times article should bring new attention to the threat. The technique menaces the 2-factor authentication that some banks have instituted:

"By going real time, hackers now can get around some of the roadblocks that companies have put in their way. Most significantly, they are now undeterred by systems that create temporary passwords, such as RSA's SecurID system, which involves a small gadget that displays a six-digit number that changes every minute based on a complex formula. If [your] computer is infected, the Trojan zaps your temporary password back to the waiting hacker who immediately uses it to log onto your account. Sometimes, the hacker logs on from his own computer, probably using tricks to hide its location. Other times, the Trojan allows the hacker to control your computer, opening a browser session that you can't see."



The lawsuit is a strategic tool, which does not mean it is always used wisely.

http://yro.slashdot.org/story/09/08/24/1026205/Model-Drops-Lawsuit-After-Outing-Anonymous-Blogger?from=rss

Model Drops Lawsuit After Outing Anonymous Blogger

Posted by kdawson on Monday August 24, @08:09AM from the you-can-pull-your-pants-up-now dept.

JumperCable writes

"The NY Daily News is reporting that model Liskula Cohen, who was suing the 'Skanks of NYC' blogger for defamation, is dropping the lawsuit now that she has outed the anonymous blogger, who is a Fashion Institute of Technology student named Rosemary Port. This brings up the question of potential abuse of the legal system to 'out' anonymous authors even if there is no intention [probably not easy to prove. Bob] actually to pursue a case against an anonymous individual. Also, according to the article, the outed blogger intends to sue Google for $15 million because it 'breached its fiduciary duty to protect her expectation of anonymity.' Do Web hosting services even have a fiduciary duty to protect their clients, or is this all legal bluff and bluster?"

Should such anonymity-busting court rulings include a provision for penalties if the plaintiff does not follow through with legal action after outing their target?



If it's not important, outsource it. In business this means any task that is not critical to your competitive position. (ATMs, janitorial services, the legal department, etc.) In government, it means anything not currently popular with the voters. (The military)

http://science.slashdot.org/story/09/08/23/180257/NASA-May-Outsource?from=rss

NASA May Outsource

Posted by kdawson on Sunday August 23, @02:57PM from the let-a-thousand-rockets-bloom dept.

The Wall Street Journal is running a piece about the growing momentum behind the idea of NASA outsourcing to private companies everything from transporting astronauts to ferrying cargo into orbit. Quoting:

"Proposals gaining momentum in Washington call for contractors to build and run competing systems under commercial contracts, according to federal officials, aerospace-industry officials and others familiar with the discussions. While the Obama administration is still mulling options and hasn't made any final decisions, such a move would represent a major policy shift away from decades of government-run rocket and astronaut-transportation programs such as the current space-shuttle fleet. ... In the face of severe federal budget constraints and a burgeoning commercial-space industry eager to play a larger role in exploring the solar system and perhaps beyond, ...a consensus for the new approach seems to be building inside the White House as well as [NASA]. ... Under this scenario, a new breed of contractors would take over many of NASA's current responsibilities, freeing the agency to pursue longer-term, more ambitious goals such as new rocket-propulsion technology and manned missions to Mars. ...[T]hese contractors would take the lead in servicing the International Space Station from the shuttle's planned retirement around 2011 through at least the end of that decade."



For specific types of intelligence, it works. It is not going to solve all intelligence problems (answer every question and point to new ones)

http://news.cnet.com/8301-13639_3-10315748-42.html?part=rss&subj=news&tag=2547-1_3-0-20

Social networks--the new front in war on terror

by Mark Rutherford August 24, 2009 6:23 AM PDT

Unnamed intelligence agencies and certain academics have yet to give up on data mining to identify terrorists and predict attacks, despite a 352-page tome published last year pronouncing the practice a waste of time.



No comment. No! Seriously, no comment.

http://www.techcrunch.com/2009/08/23/twitt-sex-because-everything-popular-needs-a-sex-clone/

Twitt Sex: Because Everything Popular Needs A Sex Clone

by MG Siegler on August 23, 2009



Just in case someone (in Marketing) thought we weren't watching, here are ten ways to steal the market from existing companies... (Details omitted)

http://www.pcworld.com/article/170624/10_things_we_hate_about_wireless_carriers.html

10 Things We Hate About Wireless Carriers

The companies that provide cell phone voice and data make their billions by cheating. They must be stopped.

Mike Elgan, Computerworld Aug 21, 2009 2:32 pm

1. You overcharge for service

2. You're a global laggard in new technologies [My pet peeve Bob]

3. Handset discounts are a shell game, not a 'subsidy'

4. You seek new ways to get money for nothing

5. You want to lock me in

6. You aggressively oppose net neutrality

7. You want to lock out competition

8. Your solution to public opposition is more lobbying

9. You're growing too powerful

10. You've forgotten that we own the airwaves



I've been considering sites like these as tools to help students outline complex projects.

http://www.wisemapping.com/c/home.htm

WiseMapping

A mind map is a diagram used to represent words, ideas, tasks or other items linked to and arranged radially around a central key word or idea. It is used to generate, visualize, structure and classify ideas, and as an aid in study, organization, problem solving, and decision making.

It is an image-centered diagram that represents semantic or other connections between portions of information. By presenting these connections in a radial, non-linear graphical manner, it encourages a brainstorming approach to any given organizational task, eliminating the hurdle of initially establishing an intrinsically appropriate or relevant conceptual framework to work within.

[Related:

http://www.mindomo.com/

http://www.text2mindmap.com/



What my students are considering...

http://www.speedcine.com/default.aspx?l=numbers

SpeedCine [Speed-Sinny] makes it easy to find legal feature-length movies on your computer.



Tools & Techniques I can recommend a couple.

http://www.makeuseof.com/tag/20-must-have-bookmarklets-for-your-web-browser/

20 Must-Have Bookmarklets For Your Web Browser

Aug. 24th, 2009 By Ellie Harrison

To add a bookmarklet to your browser, click on the bookmarklet and drag and drop to your bookmarks toolbar. Want to save space? Organize your bookmarklets into a folder in your bookmarks toolbar.

  1. Share on Tumblr – A custom bookmarklet to clip pictures and quotes to a Tumblr tumblelog.

  2. MapThis – Highlight addresses and click on the bookmarklet to generate a Google map of the address.

  3. Bookmaplet – Similar to MapThis, highlight an address in your browser and click on the bookmarklet. It will automatically open a Google Map with the address.

  4. Share on Facebook – Quickly share websites, links and videos on Facebook.

  5. Spell Check – Activate Firefox’s built-in spell checker in any static website. Great for proofreading websites before they are published or double checking someone else’s work.

  6. twitthat! – Share websites, links and videos to your Twitter account.

  7. bit.ly – Shorten links and get great statistics on how many clicks they get with this handy URL shortener. (bit.ly is also the default URL shortener of Twitter.)

  8. Boxqueue – Add videos to your Boxee Queue for viewing later. You must have a Google account and Boxee account to make this bookmarklet work. Visit the My Feeds section in Boxee to watch your saved videos.

  9. Twitter Reactions – Read reactions on Twitter about the page you are currently viewing with this bookmarklet.

  10. Darken – Invert the colors on webpages with a simple click. Some people prefer dark backgrounds and light text, so this bookmarklet’s for you.

  11. BugMeNot – Stop registering for websites and use BugMeNot’s database of usernames and passwords to sign in to “registered users only” websites, like news sites.

  12. GmailThis! – Automatically share links via your Gmail account without having to copy/paste the link.

  13. getASIN – Make Amazon Affiliate links quickly. Just replace usernamehere with your affiliate ID.

  14. WordPress Comments – Fill in the comment form on WordPress powered sites. Change values to your name, email address and blog URL.

  15. Clip to Evernote – Save clips of websites to the popular notebook software Evernote.

  16. DiggThis! – Quickly add new sites to Digg.

  17. Remove Bloat – Remove bloat from websites such as music, background images and more.

  18. Subscribe in Google Reader – Subscribe to RSS feeds in Google Reader, skipping the “Google Reader or iGoogle” selection page.

  19. Google Bookmark – Bookmark websites to your Google Bookmarks account.

  20. Readability – Click on this bookmarklet to clean up websites and make them more readable. [Actually strips images and ads, leaving only the text! Bob]

Sunday, August 23, 2009

The translation clearly isn't top notch, but it touches on hacking, privacy, and porn? (sexting?) Is this a new class of evil-doer? The Hacker/Peeper?

http://www.databreaches.net/?p=6833

Two arrested in Alicante for hacking women’s files and stealing hundreds of sexual videos

August 22, 2009 by admin Filed under Breach Incidents, Hack, Non-U.S.

Agents of the National Police in Alicante have arrested an alleged ‘hacker’ and an accomplice who have on their computers more than 200 email accounts of women and more than 300 file folders with photographs and videos of a sexual nature and intimate pictures of other young people.

The two accused have allegedly invaded their privacy without the victims being aware and taken their images and personal data.

[...]

The officers conducted a house search in which they seized two laptops and a 4Gb USB stick, containing more than 200 email accounts of women and more than 300 file folders with photographs and videos of a sexual nature and intimate pictures of many other women. The detainees, who have no criminal record, are accused of crimes against honour, privacy and crimes of usurpation of civil status.

Read more in the Barcelona Reporter



Remember that axiom of science and geekdom: If you can't think of a way to misuse the technology, someone else certainly will. Consider: The technology already exists – they are merely giving YOU the ability to turn it on. Want to bet that NSA never knew you could do this?

http://tech.slashdot.org/story/09/08/22/1541208/Twitter-Developing-Location-Based-API?from=rss

Twitter Developing Location-Based API

Posted by Soulskill on Saturday August 22, @01:32PM from the for-up-to-the-minute-online-stalking dept.

adeelarshad82 writes

"Twitter developers are now working on a location-based API that will provide accurate information on your whereabouts. Developers will be able to add latitude and longitude to any tweet. The option will definitely be opt-in. Folks will need to activate this new feature by choice, and the exact location data won't be stored for an extended period of time."



Tools & Techniques Don't you hate having to register at a site to download an article, knowing you'll never be back? Use Login2 instead! They login to sites so you don't have to.

http://login2.me/

Login2



Very interesting graphic. Surprised to see how little time is spend using the computer.

http://www.bespacific.com/mt/archives/022136.html

August 22, 2009

American Time Use Survey

New York Times "Sunday Business analyzed new data from the American Time Use Survey to compare the 2008 weekday activities of the employed and unemployed. The comparison may seem obvious, but differences in time spent by these two groups can be striking."



Something for my website students

http://www.makeuseof.com/tag/build-a-free-website-that-makes-money-without-any-programming-nb/

Build a Free Website That Makes Money Without Any Programming

Aug. 22nd, 2009 By Guy McDowell

http://www.devhub.com/



Global Warming! Global Warming! I admit I don't understand this at all. Apparently the more sunspots (cooler areas on the sun) the more heat the sun delivers. If these guys are correct, we're in for a major cool down.

http://science.slashdot.org/story/09/08/22/2340202/Sunspots-May-Be-Different-During-This-Solar-Minimum?from=rss

Sunspots May Be Different During This Solar Minimum

Posted by kdawson on Sunday August 23, @04:43AM from the too-much-clearasil dept.

PhreakOfTime writes

"According to Bill Livingston and Matt Penn of the National Solar Observatory in Tucson, Arizona, sunspot magnetic fields are waning. The two respected solar astronomers have been measuring solar magnetism since 1992. Their technique is based on Zeeman splitting of infrared spectral lines in radiation emitted by iron atoms in the vicinity of sunspots. Extrapolating their data (PDF) into the future suggests that sunspots could completely disappear within decades."

To motivate their interest the researchers mention the Maunder Minimum, which occurred beginning in 1645 and coincided with the coldest part of the so-called "Little Ice Age." Sunspot counts during this period were as low as 1/1,000 of the numbers seen in modern times.