Thursday, October 01, 2009

“We seem to have underestimated the breach. It wasn't a few hundred, it was a few hundred thousand...”

http://www.databreaches.net/?p=7553

700,000 Express Scripts members notified of extortion demands (update 2)

September 30, 2009 by admin Filed under Breach Incidents, Healthcare Sector, Of Note, U.S.

As previously reported here Express Scripts recently updated their breach report on the incident from 2008 involving an extortion demand. Now Dina Wisenberg Brin of Dow Jones Newswires provides some additional details, including the statistic that Express Scripts has now sent out approximately 700,000 individual notification letters, total. The company has not revealed how many of the 700,000 notifications are due to its recently becoming aware that even more data had been acquired than they had realized. [Almost always the case. No idea why that is so. Bob]

Express Scripts spokeswoman Maria Palumbo told Dow Jones Newswires that the person who illegally obtained member records recently sent a data file to a law firm, [Hacktivism? Bob] which forwarded it to the FBI. Palumbo wouldn’t identify the law firm, other than to say it was one that had filed a lawsuit against the company.

As it has in the past, Express Scripts made a statement that it is “unaware at this time of any actual misuse of members’ information, but we understand the concern that this situation has caused our members.”

That statement strikes me as somewhat preposterous because the company is already aware of actual misuse of the information — the extortion demand itself represents actual misuse of the information, in my opinion.

This report was crossposted from PHIprivacy.net

Update: Robert McMillan of IDG News Service also reports on the latest developments in this breach, and notes that:

In May, Washington, D.C., law firm Finkelstein Thompson brought a class-action suit against Express Scripts on behalf of members whose data was stolen. Attorneys at the firm did not return messages seeking comment for this story.

The report also includes statements I made to the reporter about this breach.

Update 2: Dina Wisenberg Brin has updated her story to include a few more details. Express Scripts indicates that most of the 700,000 notifications are due to the recently revealed data as only a few hundred members were notified last year. Additionally, the company notes that the data appear to be consistent with how their data looked in 2006.


(Related) “We didn't know where our records were either...” I teach my Statistics students that they should know how many people are involved in their studies. The math doesn't work well otherwise...

http://www.databreaches.net/?p=7563

UNC security breach less severe than feared

September 30, 2009 by admin Filed under Breach Incidents, Education Sector, Hack, U.S.

As an update to a previously reported breach:

A hacker who wormed into a UNC Chapel Hill computer server may not have gotten access to as much information as officials originally feared.

UNC School of Medicine officials said last week that a security breach had left data related to as many as 236,000 women enrolled in a mammography study exposed, including 163,000 social security numbers.

But now school officials say the number of exposed files is actually about 160,000 total, including about 114,000 social security numbers, said Stephanie Crayton, a UNC Health Care spokeswoman.

Source: NewsObserver.com

This week, UNC was also informed by DataBreaches.net that the UNC School of Journalism and Mass Communication server appeared to have been infected and was serving up spam. In that case, the compromise appeared to be due to a known WordPress vulnerability affecting older versions of WordPress.



A little encryption would have made this whole kerfuffle go away.

http://www.wired.com/threatlevel/2009/10/probe-targets-archives-handling-of-data-on-70-million-vets/

Probe Targets Archives’ Handling of Data on 70 Million Vets

By Ryan Singel October 1, 2009 8:05 am

The inspector general of the National Archives and Records Administration is investigating a potential data breach of tens of million of records about U.S. military veterans, after the agency sent a defective hard drive back to its vendor for repair and recycling without first destroying the data. [It's hard to 'erase' data if the drive won't let you talk to it. Bob]



As I mentioned yesterday, e-crooks are becoming more sophisticated. (not to be confused with smarter)

http://www.databreaches.net/?p=7575

Hackers Breach Payroll Giant, Target Customers

October 1, 2009 by admin Filed under Breach Incidents, Financial Sector, Hack, Malware, U.S.

Brian Krebs reports:

Hackers last week apparently used stolen account information from a New Jersey company that provides online payroll services to target the firm’s customers in a scheme to steal passwords and other information.

[...]

Unlike typical so-called “phishing” scams — which are sent indiscriminately to large numbers of people in the hopes that some percentage of recipients are customers of the targeted institution — this attack addressed PayChoice customers by name in the body of the message. The missives also included reference to each recipient’s onlineemployer.com user name and a portion of his or her password for the site.

In a statement e-mailed to Security Fix, PayChoice said the company discovered on Sept 23 that its online systems had been breached. The company said it immediately shut down the onlineemployer.com site and instituted fresh security measures to protect client information, such as requiring users to change their passwords.

Read more on Security Fix

[From Security Fix:

Last Wednesday, a number of PayChoice customers received an e-mail warning them that they needed to download a Web browser plug-in in order to maintain uninterrupted access to onlineemployer.com, the portal for PayChoice's online payroll service. The supposed plug-in was instead malicious software designed to steal the victim's user names and passwords.



Wow! Things are bad in Australia

http://www.databreaches.net/?p=7577

AU: One in five fall victim to ID theft

October 1, 2009 by admin Filed under Commentaries and Analyses, ID Theft, Non-U.S.

Nick Gardner reports:

The identity crimes report, which was commissioned by credit company Veda Advantage and conducted by Galaxy Research, found more than 1.5 million people’s credit cards had been skimmed and 1.2 million people’s bank accounts were illegally accessed.

Many more people’s mail containing PINs and other information that can be used to create a false identity was stolen.

ID fraud in Australia is up at least 23per cent this year compared with a year ago and experts believe it is because Australia has been slow in deploying anti-fraud technology.

Read more in Australian IT.

[From the article:

Police, meanwhile, rarely investigate incidents of ID theft because it is regarded as a "low priority'' crime.



Interesting. I would imagine corporations could more easily prove damages that individuals could. Perhaps I should become legal?

http://www.pogowasright.org/?p=4247

Since when does a legal entity have “privacy” rights?

September 30, 2009 by Dissent Filed under Businesses, Court

Kristen J. Mathews writes:

Since when does a legal entity have “privacy” rights?

Since the Third Circuit said so, in its September 22, 2009 decision in AT&T v. Federal Communications Commission (No. 084024).

Most privacy practitioners would not consider a legal entity to have privacy rights. Rather, a legal entity may have trade secrets or contractual confidentiality protections. However, in its novel holding, the Third Circuit found that a corporation (AT&T) was protected by an exemption in the Freedom of Information Act (FOIA) that applies to “unwarranted invasions of personal privacy.”

Read more on Proskauer Rose Privacy Law Blog



Advertising through intimidation? I don't remember this as a “Japanese thing” (Interesting too that she never contacted the police...)

http://www.pogowasright.org/?p=4251

Those unwanted terrifying emails were from…. Toyota?

September 30, 2009 by Dissent Filed under Businesses, Court

Over on Courthouse News, Tim Hull reports that an advertising firm and Toyota are being sued because an advertising campaign terrorized an email recipient:

A woman says a “terror marketing” campaign that Saatchi & Saatchi created for Toyota made her believe a drunken English soccer hooligan with a pit bull would show up at her home expecting to crash on her couch. She says the defendants sent her a series of anonymous emails in which a fictional man claimed he knew her address and planned to “lay low at your place for a bit. Till it all blows over. Bringing Trigger.”

Amber Duik says she was terrorized by the “nontraditional promotion” called “The Other You.” In her Superior Court complaint, Duik says the anonymous series of emails left her “constantly in tears and shaking and sobbing in emotional distress” during the entire month of April 2008.

[...]

Eventually an actor in the “movie” revealed that the entire ordeal was a hoax, and that Duik had been “punked” by Toyota as part of a marketing campaign for its Matrix automobile.

Duik says she was so terrified by the emails that her boyfriend began sleeping with a club and Mace. She says she was convinced that “a violent criminal on the run from the police both in England and the United States” was making his way down the California coast to her home.

Duik seeks $10 million in punitive damages for fraud, negligent misrepresentation, deceptive advertising, emotional distress, consumer law violations and other charges.

[From Courthouse News:

The "terror marketing campaign" consisted of a series of emails that purported to come from Sebastian Bowler, a fictional 25-year-old man, created by Saatchi & Saatchi, who loves soccer, drinking, and getting into trouble (www.myspace.com/bowlerbowler).



All it costs you is some privacy...

http://it.slashdot.org/story/09/09/30/1916249/Auto-Detecting-Malware-Its-Possible?from=rss

Auto-Detecting Malware? It's Possible

Posted by timothy on Wednesday September 30, @03:18PM from the would-love-to-see-the-install-prompt-for-this dept.

itwbennett writes

"If antivirus protectors could collect data from machines and users, including geographic location, social networking information, type of operating system, installed programs and configurations, 'it would enable them to quickly identify new malware strains without even looking at the code,' says Dr. Markus Jakobsson. In a recent article, he outlines some examples of how this could work. The bottom line is this: 'Let's ignore what the malware does on a machine, and instead look at how it moves between machines. That is much easier to assess. And the moment malware gives up what allows us to detect it, it also stops being a threat.'"



Speaking of Big Brother tools... An easy “It's for the children” sell, but some real risk of “thought police”

http://www.wired.com/wiredscience/2009/09/domestic-abuse-prediction/

Data-Mining Medical Records Could Predict Domestic Violence

By Frederik Joelving September 30, 2009 3:58 pm

… Now, a group of researchers at Harvard University has created the first computer model to automatically detect the risk that a patient is being abused at home. The results were published Sept. 29 in the British Medical Journal.

“It’s a great concept,” said Debra Houry, an emergency physician at Emory University, who was not involved in the research. Although around one in four women experience domestic violence at some point in their lives, she says, the problem often goes unnoticed at a doctor’s visit. “It’s one of those hidden epidemics where they don’t come up to you and disclose the issue.”

… Using the new system, the researchers were able to predict abuse an average of two years before the doctor made the diagnosis. Presumably, the computer is picking up signs of ongoing maltreatment the patient hasn’t yet revealed.

The researchers also speculate that, in principle, some subtle signal could precede direct abuse. [“You are under arrest citizen for contemplating abusing your spouse.” Bob]



Redefining “Large Datacenter” Also some tips for my Business Continuity class.

http://news.cnet.com/8301-13860_3-10364746-56.html?part=rss&subj=news&tag=2547-1_3-0-20

Microsoft opens Windy City data center

by Ina Fried September 30, 2009 3:38 PM PDT

… But on Wednesday, the company allowed a group of reporters, customers, and partners to tour the 700,000 square foot facility.

… But, for all its strategic import, the ground floor of the Chicago plant looks more like a truck parking lot than a traditional data center. In each parking spot, though, Microsoft can drop off a container packed with up to 2,000 servers.



Improving the stalker toolkit!

http://news.slashdot.org/story/09/09/30/2052258/Google-Wants-to-Map-Indoors-Too?from=rss

Google Wants to Map Indoors, Too

Posted by timothy on Wednesday September 30, @04:55PM from the where's-the-good-silverware dept.

An anonymous reader writes

"Google maps are getting extended indoors next month with a new app called Micello that takes over where conventional navigators leave off — mapping your route inside of buildings, malls, convention centers and other points of interest. You don't get a 'you are here' blinking dot yet — but they do promise to add one next year using WiFi triangulation. At the introduction next month, Micello will only work in California, but they plan to expand to other major US cities during 2010."


(Related) Ain't technology wonderful?

http://yro.slashdot.org/story/09/10/01/1321212/Wireless-Network-Modded-To-See-Through-Walls?from=rss

Wireless Network Modded To See Through Walls

Posted by CmdrTaco on Thursday October 01, @09:30AM from the still-can't-see-through-pants dept.

KentuckyFC writes

"The way radio signals vary in a wireless network can reveal the movement of people behind closed doors, say researchers who have developed a technique called variance-based radio tomographic imaging which processes wireless signals to peer through walls. They've tested the idea with a 34-node wireless network using the IEEE 802.15.4 wireless protocol (the personal area network protocol employed by home automation services such as ZigBee). The researchers say that such a network could be easily distributed by the police or military wanting to determine what's going on inside a building. But such a network, which uses cheap off-the-shelf components, might also be easily deployed by your neighbor or anybody else wanting to monitor movements in your home."



Links to many more resources. Mostly for genealogy...

http://www.bespacific.com/mt/archives/022448.html

September 30, 2009

National Archives and Footnote.com Announce New Digital Holocaust Collection

News release: "The National Archives and Records Administration and Footnote.com announced the release of the internet’s largest Interactive Holocaust Collection. For the first time ever, over one million Holocaust-related records – including millions of names and 26,000 photos from the National Archives – will be available online. The collection can be viewed at: http://www.footnote.com/holocaust...The collection also includes nearly 600 interactive personal accounts of those who survived or perished in the Holocaust provided by the U.S. Holocaust Memorial Museum. The project incorporates social networking tools that enable visitors to search for names and add photos, comments and stories, share their insights, and create pages to highlight their discoveries. There will be no charge to access and contribute to these personal pages."



Global Warming! Global Warming! I knew it wasn't just Al Gore's hot air!

http://science.slashdot.org/story/09/09/30/2225245/Cosmic-Ray-Intensity-Reaches-Highest-Levels-In-50-years?from=rss

Cosmic Ray Intensity Reaches Highest Levels In 50 years

Posted by samzenpus on Wednesday September 30, @10:13PM from the start-the-mutations dept.

An anonymous reader writes

"A NASA probe found that cosmic ray intensities in 2009 had increased by almost 20 percent beyond anything seen in the past 50 years. Such cosmic rays arise from distant supernova explosions and consist mostly of protons and heavier subatomic particles — just one cosmic ray could disable unlucky satellites or even put a mission to Mars in jeopardy."


(Related) Maybe Osama invented Global Warming. I thought it was Al Gore!

http://www.bespacific.com/mt/archives/022451.html

September 30, 2009

CIA Opens Center on Climate Change and National Security

News release: "The Central Intelligence Agency is launching The Center on Climate Change and National Security as the focal point for its work on the subject. The Center is a small unit led by senior specialists from the Directorate of Intelligence and the Directorate of Science and Technology. Its charter is not the science of climate change, but the national security impact of phenomena such as desertification, rising sea levels, population shifts, and heightened competition for natural resources. The Center will provide support to American policymakers as they negotiate, implement, and verify international agreements on environmental issues. That is something the CIA has done for years."


(Related) Global Warming results in more snow (or at least, more snow jobs), so this is important.

http://news.slashdot.org/story/09/09/30/188228/GPS-Receiver-Noise-Can-Be-Used-To-Detect-Snow-Depth?from=rss

GPS Receiver Noise Can Be Used To Detect Snow Depth

Posted by timothy on Wednesday September 30, @02:12PM from the for-the-journal-of-sensors-and-transducers dept.

cremeglace writes

"Scientists at the University of Colorado at Boulder have found a use for GPS besides finding restaurants or the occasional road-that-doesn't-exist: it can be used to measure snow depth. The new technique, which takes advantage of distortions of the GPS signal after it reflects off the snowpack, may potentially improve weather forecasts by allowing meteorologists to track snowfall patterns. ScienceNOW has the story, which one geophysicist describes as 'a classical case of one person's noise becoming another person's signal.'"



All I want for Christmas...

http://www.techcrunch.com/2009/09/30/bumptop-goes-multi-touch-um-awesome/

BumpTop Goes Multi-Touch. Um, Awesome.

by MG Siegler on September 30, 2009

… BumpTop is adding multi-touch support. And the result is awesome.

… This graphic below shows a list of the gestures BumpTop offers that competitors don’t, including the ones that they apparently have patents on (labeled as “BT”).



How could I resist passing this on to my students. (Any of you lawyers want me to pass on your cards?)

http://www.makeuseof.com/tag/top-5-websites-to-learn-how-to-hack-like-a-pro/

Top 5 Websites To Learn How To Hack Like A Pro

Oct. 1st, 2009 By Ryan Dube

Wednesday, September 30, 2009

Update: The effect was zero risk. As to the cause, I wonder if they expended any effort at all to prevent a reoccurrence?

http://news.cnet.com/8301-27080_3-10363663-245.html?part=rss&subj=news&tag=2547-1_3-0-20

Misfired e-mail was never viewed by Gmail user

by Elinor Mills September 29, 2009 3:01 PM PDT

A sensitive e-mail mistakenly sent by a bank to a Gmail address that prompted a court to order Google to deactivate the account was not viewed by the recipient and has been deleted, the bank said on Tuesday.

… The bank sent another e-mail asking that the data be destroyed and went to court to get Google to intervene on its behalf. Last week, a judge in U.S. District Court in San Jose, Calif., ordered Google to deactivate the Gmail account and Google complied. Google and the bank quickly resolved the matter and the court granted their motion to dismiss the case and allowed Google to reactivate the Gmail account.

"Rocky Mountain Bank, working with Google (through court order), confirmed on Thursday of last week that the e-mail containing client information was never opened and has now been permanently destroyed by Google's system," Tina Martinez, general counsel for Rocky Mountain Capital, wrote in an e-mail response to questions.

"As a result, no customer data of any sort has been viewed or used by any inappropriate user during this data lapse," Martinez wrote. [That statement is a bit broader than the facts suggest. Bob]

… The case poses some interesting questions. For instance, should the person who registered the e-mail address lose access to the account or have items deleted without his or her permission, particularly through no fault of their own?

And what recourse would the bank have if the data had been sent via regular mail to the wrong address? The U.S. Postal Office certainly doesn't have the ability to see the envelope sitting on the recipient's desk and vaporize it.



There has to be a “provable damage” requirement before the fund pays anything. I'll have to research this a bit.

http://www.pogowasright.org/?p=4233

CT: Governor Rell announces ID theft law

September 30, 2009 by Dissent Filed under Breaches, Legislation, U.S.

Governor M. Jodi Rell announced a new law [An Act Concerning Consumer Privacy and Identity Theft] which increases criminal penalties for identity theft and establishes a fund from forfeited assets to help individuals whose identity has been stolen will become effective on October 1st.

[...]

The legislation makes numerous changes in existing laws relating to identity theft, misuse of Social Security Numbers or other personal identifying information. The law also includes tougher penalties for those convicted of victimizing senior citizens. [Was AARP lobbying for this? Bob] A suspect now faces first-degree identity theft charges – a class B felony – for victimizing anyone older than 60 and stealing assets and valuables over $5,000. The law lowers the theft threshold for a first-degree offense from $10,000.

The legislation broadens the definition of identity theft, increases penalties for criminal impersonation and creates the crime of unlawful possession of personal access devices, such as card readers or scanners, account numbers, personal identification numbers or PIN number and telecommunications service.

Read more on News8



The amounts are small, the technology difficult to explain to a jury – no wonder these cases are not high on the prosecutor's list. Perhaps we could interest them in a nice old-fashioned lawsuit?

http://www.pogowasright.org/?p=4204

B.C. identity theft victims say they can’t get justice

September 29, 2009 by Dissent Filed under Breaches, Non-U.S.

Kathy Tomlinson reports:

Two B.C. people who are victims of identity theft are speaking out in frustration with the justice system.

Mark Gorst and Shannon Werry have ample evidence indicating who the thief is, but even so, RCMP have told them charges won’t be laid.

“It’s frustrating … and there is a lot of anger,” said Werry. “Because you know who it is — and you have the proof that you need — and nothing happens.”

“I didn’t know most of the money was stolen — until two years afterward,” said Gorst. “We’ve been told — because it’s been such a time delay — the statute of limitations on certain crimes means I am on the hook for everything.”

Read the full story on CBC.ca

[From the article:

"[Identity theft and fraud] is a level of crime that you don't know about until you know about it [Sounds very “Yogi Berra-like” Bob] — which is sometimes too late for legal boundaries," explained Cpl. Lea-Anne Dunlop of the Chilliwack RCMP.

If more than a year has passed since the initial crime, she said, the bar to get charges approved by the Crown is higher.



How Big Brother does it...

http://www.eff.org/deeplinks/2009/09/prompted-eff-lawsuit-fbi-partially-releases-domest

Prompted by EFF Lawsuit, FBI (Partially) Releases Domestic Surveillance Guidelines

News Update by David L. Sobel September 29th, 2009

The Federal Bureau of Investigation has released a heavily censored version of its controversial Domestic Investigations and Operations Guidelines (DIOG), which became effective on December 1, 2008.

… The 258-page document implements the Attorney General’s Guidelines for Domestic FBI Operations, the most recent version of which was issued late last year by former Attorney General Michael B. Mukasey.

… The Mukasey guidelines, among other things, gave the FBI the authority to open investigative “assessments” of any American without any factual predicate or suspicion. Such “assessments” allow the use of intrusive techniques to surreptitiously collect information on people suspected of no wrongdoing and no connection with any foreign entity. These inquiries may include the collection of information from online sources and commercial databases, and the use of grand jury subpoenas to obtain telephone and email subscriber information.



A trend or just 'those weirdos in Massachusetts?'

http://www.pogowasright.org/?p=4215

Cops Can’t Convert Car Into Tracking Device Without Court’s OK

September 30, 2009 by Dissent Filed under Court, Surveillance, U.S.

Jennifer Granick of EFF has a commentary on a recent decision out of Massachusetts discussed here previously.

The Supreme Court of Massachusetts recently held that officers may not place GPS tracking devices on cars without first getting a warrant. The case, Commonwealth v. Connolly, was decided under the state corollary to the Fourth Amendment, and its reasoning may influence pending GPS tracking cases, including United States v. Jones, where EFF is an amicus.

Read more on EFF.

[From the EFF article:

EFF has urged a U.S. appeals court to reject government claims that federal agents have an unfettered right to install Global Positioning System (GPS) location-tracking devices on anyone's car without a warrant.



What would be better than a mandatory security law that banks would find plenty of loopholes in? This has got to be terrifying!

http://www.databreaches.net/?p=7541

Banks oppose computer crime law proposal

September 29, 2009 by admin Filed under Breach Laws, Legislation, Non-U.S.

Computer criminals could wind up costing Danish banks billions if a law requiring them to compensate small businesses on an equal footing with private account holders is passed.

The Commerce Ministry has asked the Financial Supervisory Authority to look into whether companies with less than 10 employees and annual turnover of less than 15 million kroner should be issued a guarantee that they will be compensated if their accounts are hacked into.

Currently, banks are required to compensate private account holders everything but a 1200 kroner deduction if their accounts are hacked. The new law would issue the same guarantee to small businesses and would encompass 90 percent of the country’s companies.

Read the full story in the Copenhagen Post.



One would expect crime to grow and mature slightly behind the growth curve of the industry itself. It was unlikely that thieves would steal the first (first thousand) automobiles, but eventually the volume made it easier and safer – eventually joining prostitution and gambling as a “business unit” of organized crime.

http://it.slashdot.org/story/09/09/29/2129243/IT-Security-Breaches-Soar-In-2009?from=rss

IT Security Breaches Soar In 2009

Posted by kdawson on Tuesday September 29, @07:24PM from the inside-jobs dept.

slak11 quotes from a Globe and Mail article on the jump in corporate and government security breaches year-over-year. (The reporting is from Canada but the picture is probably much the same in the US.)

"This does not seem to be all that newsworthy these days, since stories like this are appearing on a regular basis. The one detail I did like — that seems to break from the traditional 'hackers cause all the bad stuff' reporting — is the mention that everyday employees are a major cause of breaches. The recent Rocky Mountain Bank/Google story is a perfect example. As stated in the article: 'But lower security budgets aren't the only reason breaches tend to soar during tough economic times — employees themselves can often be the cause of such problems.' I figure this will be an ongoing problem until company management and employees accept their role in keeping company information safe. And IT people need to understand that regular employees are not propeller-heads like Slashdot readers, and to begin to implement technology and processes that average people can understand and use."


(Related) Coming soon to a bank near you! We should expect malware to be more sophisticated than early versions of VisiCalc, after all that was written more than 25 years ago. This looks like an automated stock trading program (also decades old) that initiates transactions based on readily available data.

http://news.cnet.com/8301-27080_3-10363836-245.html?part=rss&subj=news&tag=2547-1_3-0-20

Banking Trojan steals money from under your nose

by Elinor Mills September 29, 2009 5:51 PM PDT

Researchers at security firm Finjan have discovered details of a new type of banking Trojan horse that doesn't just steal your bank log in credentials but actually steals money from your account while you are logged in and displays a fake balance.

The bank Trojan, dubbed URLZone, has features designed to thwart fraud detection systems which are triggered by unusual transactions, Yuval Ben-Itzhak, chief technology officer at Finjan, said in an interview on Tuesday. For instance, the software is programmed to calculate on-the-fly how much money to steal from an account based on how much money is available.

It exploits a hole in Firefox, Internet Exlorer 6, IE7, IE8 and Opera, and it is different from previous reported banking Trojans, said Ben-Itzhak. The Trojan runs an executable only on Windows systems, he said. The executable can come via a number of avenues, including a malicious Javascript or Adobe PDF, he added.

The specific Trojan Finjan researchers analyzed targets customers of unnamed German banks, according to the latest Finjan report. It was linked back to a command-and-control server in Ukraine that was used to send instructions to the trojan software sitting infected PCs.


(Related) The growth bit...

http://news.cnet.com/8301-1009_3-10363373-83.html

Malware worldwide grows 15 percent in September

by Lance Whitney September 29, 2009 11:51 AM PDT

A rise in malware has caused the number of infected PCs worldwide to increase 15 percent just from August to September, says a report released Tuesday from antivirus vendor Panda Security.

Across the globe, the average number of PCs hit by malware now stands around 59 percent, an all-time high for the year. Among 29 countries tracked, the U.S. ranked ninth with slightly more than 58 percent of its PCs infected. Taiwan hit first place with an infection ratio of 69 percent, while Norway came in lowest with only 39 percent of its PCs attacked by malware.



Free software from Microsoft?

http://tech.slashdot.org/story/09/09/29/2250228/Microsoft-Security-Essentials-Released-Rivals-Mock-It?from=rss

Microsoft Security Essentials Released; Rivals Mock It

Posted by kdawson on Tuesday September 29, @11:11PM from the free-but-is-it-worth-it dept.

Bimal writes

"After a short three-month beta program, Microsoft is officially releasing Microsoft Security Essentials, its free, real-time consumer anti-malware solution for fighting viruses, spyware, rootkits, and Trojans. MSE is available for Windows XP 32-bit, Windows Vista/7 32-bit, and Windows Vista/7 64-bit. 'Ars puts MSE through its paces and finds an unobtrusive app with a clean interface that protected us in the dark corners of the Internet.' The software received positive notes when in beta, including a nod from the independent testing group AV-Test."

But reader CWmike notes that Symantec is trash-talking Microsoft's free offering. Jens Meggers, Symantec's vice president of engineering, dismissed MSE as a "poor product" that will "never be up to snuff." Meggers added, "Microsoft has a really bad track record in security." The GM of Trend Micro's consumer division sniffed, "It's better to use something than to use nothing, but you get what you pay for."



“We'll only use DNA for identification, like fingerprints” “We're not prejudiced, but we ain't allowing no WOGs into the country!”

http://science.slashdot.org/story/09/09/29/1946232/Scientists-Decry-Horrifying-UK-Border-Test-Plan?from=rss

Scientists Decry "Horrifying" UK Border Test Plan

Posted by kdawson on Wednesday September 30, @03:27AM from the genetic-papers-please dept.

cremeglace writes

"Scientists are dismayed and outraged at a new project by the UK border agency to test DNA, hair, and nails to determine the nationality of asylum seekers and help decide if they can enter the UK. 'Horrifying,' 'naive,' and 'flawed' are among the words geneticists and isotope specialists have used to describe the 'Human Provenance pilot project.' The methods being used to determine ancestry include fingerprinting of mitochondrial DNA and isotope analysis of hair and nails. ScienceInsider blog notes that it is 'not clear who is conducting the DNA and isotope analyses [That would be the Klass Kategorizing KO-OP –ticker symbol KKK Bob] for the Border Agency,' and that the agency has not 'cited any scientific papers that validate its DNA and isotope methods.' There is also a followup post with more information on the tests that are being used, and some reactions from experts in genetic forensic analysis. This story was first reported in The Observer on Sunday."



Hackers! We need a free iPhone app that everyone will want/need to install. Viagra Marketers: Have we got a deal for you!

http://yro.slashdot.org/story/09/09/29/1933252/Retrievable-iPhone-Numbers-Raise-Privacy-Issue?from=rss

Retrievable iPhone Numbers Raise Privacy Issue

Posted by kdawson on Tuesday September 29, @04:58PM from the how-about-never-is-never-good-for-you dept.

TechnologyResource writes

"When a couple of voicemails didn't show up recently, I thought nothing of it until a friend asked me if I'd gotten his message — people just don't call me that often. But the iPhone is indeed a phone, as some users are reportedly being reminded when they get phone calls from the publishers of a free app they've downloaded from the App Store. The application in question, mogoRoad, is a real-time traffic monitoring application. As invasive and despicable as that sounds, it raises another question: how did the company get hold of the contact information for those users? Mogo claims the details were provided by Apple, but Apple doesn't disclose that information to App Store vendors. French site Mac 4 Ever did some digging (scroll down for the English version) and determined it was possible — even easy — for an app to retrieve the phone number of a unit on which it was installed."



Interpreting Fair Use (because no one can interpret Ulysses.)

http://yro.slashdot.org/story/09/09/29/1749240/Professor-Wins-240K-In-Fair-Use-Dispute?from=rss

Professor Wins $240K In Fair Use Dispute

Posted by kdawson on Tuesday September 29, @03:22PM from the happy-bloomsday dept.

pickens writes

"In a victory for Fair Use, Stanford Law School's Fair Use Project has announced that the estate of 20th century literary giant James Joyce, author of the landmark novel Ulysses, has agreed to pay $240,000 in attorneys' fees to Stanford University Consulting Professor Carol Shloss and her counsel in connection with Shloss's lawsuit to establish her right to use copyrighted material in her scholarship on the literary work of James Joyce. When Shloss used copyrighted materials in her biography of Joyce's daughter Lucia, titled Lucia Joyce: To Dance in the Wake, she had to excise a substantial amount of source material from the book in response to threats from the Joyce Estate. However following publication of the book, Shloss sued the Estate to establish her right to publish the excised material. The parties reached a settlement regarding the issue in 2007, permitting the publication of the copyrighted material in the US. Following the settlement, Shloss asked the Court to order the Estate to pay attorneys' fees of more than $400,000. She has now agreed to accept an immediate payment of $240,000 in return for the dismissal of the Estate's appeal. 'This case shows there are solutions to the problem Carol Shloss faced other than simple capitulation,' says Fair Use Project Executive Director Anthony Falzone, who led the litigation team."



Only lawyers understand copyright law, and they can't explain it to juries.

http://yro.slashdot.org/story/09/09/30/1152211/338M-Patent-Ruling-Against-Microsoft-Overturned?from=rss

$338M Patent Ruling Against Microsoft Overturned

Posted by Soulskill on Wednesday September 30, @08:50AM from the courts-just-like-making-work-for-themselves dept.

some_guy_88 writes

"The $338 million verdict against Microsoft for violating a patent held by Uniloc has now been overturned. 'Ric Richardson ... is the founder of Uniloc, which sued Microsoft in 2003 for violating its patent relating to technology designed to deter software piracy. The company alleged Microsoft earned billions of dollars by using the technology in its Windows XP and Office programs. In April, a Rhode Island jury found Microsoft had violated the patent and told Microsoft to pay the company $388 million, one of the largest patent jury awards in US history. But on Tuesday ... US District Judge William Smith "vacated" the jury's verdict and ruled in favor of Microsoft.' In his ruling, Smith said the jury 'lacked a grasp of the issues before it [perhaps there can't be a jury of peers in Copyright litigation? Bob] and reached a finding without a legally sufficient basis (PDF).'"



How to capture a market? (Or at least not get left behind...)

http://news.cnet.com/8301-27083_3-10363506-247.html?part=rss&subj=news&tag=2547-1_3-0-20

Microsoft and CVS expand pharmacy partnership

by Lance Whitney September 29, 2009 3:26 PM PDT

Microsoft HealthVault is a free service that lets consumers store and maintain their health information in one single electronic spot.

… Microsoft isn't CVS' only health care partner. In April, CVS expanded its joint venture with Google to let customers store their health records online through Google Health.

With the push toward health care reform, other tech companies have also gotten into the act.

In May, Intuit, Microsoft, Dell, Intel, and other firms formed the EHR Stimulus Alliance, designed to push doctors and hospitals toward digital record keeping.



Interesting because of the debate in the comments. Consensus: there is no good electronic means to store data for the long term. Solutions range from paper to constant copying.

http://ask.slashdot.org/article.pl?sid=09/09/29/1646251

Archiving Digital Artwork For Museum Purchase?

Posted by timothy on Tuesday September 29, @01:09PM from the just-put-something-on-youtube dept.

An anonymous reader writes

"I am an artist working with 3d software to create animations and digital prints. For now my work just gets put on screening DVDs and BluRays and the original .mov and 3d files get backed up. But museums and big art collectors do want to purchase these animations. However as we all know archival DVDs are not really archival. So I want to ask the Slashdot readers, what can I give to the museum when they acquire my digital work for their collection so that it can last and be seen long after I am dead? No other artist or institution I know of have come up with any real solution to this issue yet, so I thought Slashdot readers may have an idea. These editions can be sold for a large amount of money, so it doesn't have to be a cheap solution."



'cause I'm gonna make my website students publish...

http://www.makeuseof.com/tag/top-7-easy-and-free-web-hosting-services/

Top 7 Easy and Free Web Hosting Services

Sep. 29th, 2009 By Jeffry Thurana

Tuesday, September 29, 2009

Introducing new avenues of attack before the old ones are secure?

http://news.slashdot.org/article.pl?sid=09/09/28/1646257

Banking Via Twitter?

Posted by ScuttleMonkey on Monday September 28, @03:16PM from the what-not-to-do dept.

In the latest example of how just because you can do something doesn't mean you should, one credit union has decided to offer a new feature, dubbed "tweetMyMoney," that allows members to interact with their accounts via Twitter. Can't wait for the next version, "tweetSomeoneElsesMoney."

"tweetMyMoney, available exclusively to Vantage members! With tweetMyMoney, you can monitor your account balance, deposits, withdrawals, holds and cleared checks with simple commands. And, you can even transfer funds within your account. It's all available on Twitter, 24/7!"



What is Apples definition of malware? My definition is “unauthorized/unwanted software” If I charge for testing/evaluating software on my system, can I bill Apple? If I'm running a system as part of my dissertation research and Apple screws thing up, can I sue? What is the threshold that must be crossed to make a Class Action likely?

http://apple.slashdot.org/story/09/09/28/2330229/Apple-Pushes-Unwanted-Software-To-PCs-Again?from=rss

Apple Pushes Unwanted Software To PCs, Again

Posted by kdawson on Monday September 28, @08:10PM from the just-updates-please dept.

itwbennett writes

"Blogger Steven J. Vaughan-Nichols wags his finger at Apple for indiscriminately pushing the iPhone Configuration Utility 2.1 update out to Windows users, since it is a tool for business system administrators to set up and administer corporate iPhones — the blogger himself (and practically every other iPhone user) not being of the corporate iPhone user persuasion. But more than just unnecessary, the update actually puts him and millions of other iPhone owners/Windows PC users at increased risk by installing 'not just a configuration program, but the Apache Web server as well,' says Vaughan-Nichols. 'A Web server like the one Apple [is] adding to your PC... [is] a gateway just asking to be hammered on by an attacker. Managed properly Apache is as safe a Web server as you'll ever find, but ordinary PC users shouldn't try to manage it, and even an expert can't do anything with it if they don't know it's there.'"

Reader CWMike notes that Apple pulled the iPhone Configuration Utility from the update list after a few hours.


(Related) A survey of the Blogs and a new term of art...

http://blogs.computerworld.com/14808/apple_shovelware_problems_again_iphone_configuration_utility

September 28, 2009 - 5:45 A.M.

Apple shovelware problems again (iPhone Configuration Utility 2.1)



A cautionary tale as my schools start into e-textbooks

http://news.slashdot.org/article.pl?sid=09/09/29/0133221

In Trial, Kindles Disappointing University Users

Posted by kdawson on Tuesday September 29, @12:11AM from the write-on dept.

Phurge writes

"When Princeton announced its Kindle e-reader pilot program last May, administrators seemed cautiously optimistic that the e-readers would both be sustainable and serve as a valuable academic tool. But less than two weeks after 50 students received the free Kindle DX e-readers, many of them said they were dissatisfied and uncomfortable with the devices. 'I hate to sound like a Luddite, but this technology is a poor excuse of an academic tool,' said Aaron Horvath, a student in Civil Society and Public Policy. 'It's clunky, slow and a real pain to operate.' 'Much of my learning comes from a physical interaction with the text: bookmarks, highlights, page-tearing, sticky notes and other marks representing the importance of certain passages — not to mention margin notes, where most of my paper ideas come from and interaction with the material occurs,' he explained. 'All these things have been lost, and if not lost they're too slow to keep up with my thinking, and the "features" have been rendered useless.'"



Worth a few minutes to browse?

http://www.bespacific.com/mt/archives/022426.html

September 28, 2009

Deloitte: Cloud computing - A collection of working paper

Deloitte: Cloud computing - A collection of working papers, released September 17, 2009 and published on July 31, 2009.

  • "Cloud Computing frequently is taken to be a term that simply renames common technologies and techniques that we have come to know in IT. It may be interpreted to mean data center hosting and then subsequently dismissed without catching the improvements to hosting called utility computing that permit near realtime, policy-based control of computing resources. Or it may be interpreted to mean only data center hosting rather than understood to be the significant shift in Internet application architecture that it is... Cloud computing represents a different way to architect and remotely manage computing resources. One has only to establish an account with Microsoft or Amazon or Google to begin building and deploying application systems into a cloud. These systems can be, but certainly are not restricted to being, simplistic. They can be web applications that require only http services. They might require a relational database. They might require web service infrastructure and message queues. There might be need to interoperate with CRM or e-commerce application services, necessitating construction of a custom technology stack to deploy into the cloud if these services are not already provided there."



Tools & Techniques What works

http://arstechnica.com/security/news/2009/09/av-comparatives-picks-seven-anti-malware-winners.ars

AV-Comparatives picks seven on-demand antimalware winners

AV-Comparatives' August 2009 report has been released and there are seven winners.

By Emil Protalinski Last updated September 28, 2009 11:59 AM CT

AV-Comparatives is known for the thorough tests it does on security software. Following its May 2009 retrospective/proactive report, the company has released its August 2009 on-demand comparative. Sixteen products, last updated on August 10, were set on the same highest detection settings (except for Sophos and F-Secure) and put to the test.



Tools & Techniques I wonder if they would allow me to search for vulnerabilities? (Would they know if I was?)

http://tech.slashdot.org/story/09/09/28/190259/Company-Offers-Customizable-Web-Spidering?from=rss

Company Offers Customizable Web Spidering

Posted by ScuttleMonkey on Monday September 28, @05:41PM from the my-legs-are-longer-than-yours dept.

TechReviewAl writes

"A company called 80legs has come up with an interesting new web business model: customized, on-demand web spidering. The company sells access to its spidering system, charging $2 for every million pages crawled, plus a fee of three cents per hour of processing used. The idea is to offer Web startups a way to build their own web indexes without requiring huge server farms. 'Many startups struggle to find the funding needed to build large data centers, but that's not the approach 80legs took to construct its Web crawling infrastructure. The company instead runs its software on a distributed network of personal computers, much like the ones used for projects such as SETI@home. The distributed computing network is put together by Plura Processing, which rents it to 80legs. Plura gets computer users to supply unused processing power in exchange for access to games, donations to charities, and other rewards.'"



Something else for my students to be watching when they should be listening to my lectures...

http://www.makeuseof.com/tag/watch-free-tv-channels-on-the-go-with-kiteplayer/

Watch Free TV Channels On The Go With KitePlayer

Sep. 29th, 2009 By Karl L. Gechlik

Have you ever wanted to watch free TV on your laptop on the go? You say, sure there is Hulu (which we have covered extensively here) and other sites that let me do that.

But how about one site that aggregates all the others and lets you watch them via one program interface that you could run on say your media center station showing on your TV or your laptop on the bus?

… Kiteplayer software is free to download and you can always get the latest version by clicking here.



Interesting. I suspect the first one is congress asking “What are my colleges doing that I should be doing to look smart?”

http://www.bespacific.com/mt/archives/022430.html

September 28, 2009

Recent CRS Reports: Congress and Twitter, Wildfire Fuels, F-35 Joint Strike Fighter, Older Workers, Climate Change

Monday, September 28, 2009

Security has not risen to the level of 'competitive advantage' quite yet, but perhaps there are indications that it will.

http://news.slashdot.org/story/09/09/27/1636254/Cyber-Gangs-Raise-Profile-of-Commercial-Online-Bank-Security?from=rss

Cyber Gangs Raise Profile of Commercial Online Bank Security

Posted by Soulskill on Sunday September 27, @01:26PM from the only-you-can-prevent-identity-theft dept.

tsu doh nimh writes

"The Washington Post's Security Fix blog has published a rapid-fire succession of investigative stories on the theft of hundreds of thousands of dollars from companies, schools, and public institutions at the hands of organized cyber thieves and 'money mules,' willing or unwitting people recruited via online job scams. Some businesses are starting to challenge the financial industry's position that they are not responsible for online banking losses from things like keystroke logging malware that attacks customer PCs. Last week, a Maine firm sued its bank, saying the institution's lax approach to so-called multi-factor authentication failed after thieves stole $588,000 from the company, sending the money to dozens of money mules. The same group is thought to have taken $447,000 from a California wrecking company, whose bank also is playing hardball. Most recently, the Post's series outlined a sophisticated online system used by criminals to recruit, track and manage money mules."


(Related)

http://www.databreaches.net/?p=7531

FBI: Virus suspected in school thefts

September 28, 2009 by admin Filed under Breach Incidents, Education Sector, Malware, U.S.

Brett Rowland and Kate Schott report:

As much as $350,000 reported stolen from Crystal Lake District 47 bank accounts earlier this summer could be linked to cyberthefts at other suburban schools.

The FBI’s Chicago office is investigating the cases, at least one of which involves a hard-to-detect computer virus. No arrests have been made or charges filed, said Cynthia Yates, a spokeswoman for the Chicago office of the FBI. She said Crystal Lake School District 47 and Sycamore School District 427 were part of their investigation, but she declined to identify any other organizations involved in the case.

Read more on Northwest Herald. Thanks to Brian Honan for this link.



Why does this sound all too familiar? Why does Charlie Brown trust Lucy to hold the football? Thank god stupid isn't a capital offense.

http://www.databreaches.net/?p=7533

Jail chaos as lag hacker is left in charge of computer system

September 28, 2009 by admin Filed under Breach Incidents, Government Sector, Non-U.S., Of Note, Other

Justin Penrose reports:

A jailed hacker shut down a prison’s entire computer system – after bosses gave him the job of programming it.

Douglas Havard, 27, serving six years for stealing up to £6.5million using forged credit cards over the internet, was approached after governors wanted to create an internal TV station but needed a special computer program written.

He was left unguarded and hacked into the system’s hard drive at Ranby Prison, near Retford, Notts. Then he set up a series of passwords so no one else could get into the system.

Read more on Mirror. Thanks to Brian Honan for this link.

[From the article:

The blunder emerged a week after the Sunday Mirror revealed how an inmate at the same jail managed to get a key cut that opened every door.



What is it with governments passing laws restricting a very limited range of devices, and not addressing the problem they are trying to solve?

http://yro.slashdot.org/story/09/09/28/0252203/For-New-Zealanders-No-More-Phones-As-Sat-Nav-Devices?from=rss

For New Zealanders, No More Phones As Sat-Nav Devices

Posted by timothy on Monday September 28, @04:16AM from the fine-distinctions dept.

rixth writes

"From the 1st of November, it will be illegal to use cell phones while driving in New Zealand. Today, the Government clarified that you can't use your mobile phone as a navigational device, even if it is mounted on the dash board."

[From the article:

The restriction does not apply to navigation systems that do not have a mobile phone function, he says.



I was going to suggest that the 'unhackable' would be hacked quickly, but the comments report that these computers have already been hacked. That's what happens when you challenge hackers.

http://news.slashdot.org/story/09/09/27/0252235/AU-Government-To-Build-Unhackable-Netbooks?from=rss

AU Government To Build "Unhackable" Netbooks

Posted by kdawson on Sunday September 27, @08:09AM from the smells-like-a-challenge dept.

bennyboy64 writes

"In what may be one of the largest roll-outs yet of Microsoft's new Windows 7 Operating System, Australia's Federal Government decided to give 240,000 Lenovo IdeaPad S10e netbooks to Year 9-12 students. Officials are calling them 'unhackable.' iTnews reports that the laptops come armed with an enterprise version of the Windows 7 OS, Microsoft Office, the Adobe CS4 creative suite, Apple iTunes, and content geared specifically to students. New South Wales Department of Education CIO Stephen Wilson said that schools were 'the most hostile environment you can roll computers into.' While the netbooks are loaded with many hundreds of dollars worth of software, 2GB of RAM, and a 6-hour battery, the cost to the NSW Department of Education is under $435 (US) a unit. Wilson praised Windows' new OS: 'There was no way we could do any of this on XP,' he said. 'Windows 7 nailed it for us.' At the physical layer, each netbook is password-protected and embedded with tracking software that is embedded at the BIOS level of the machine. If a netbook were to be stolen or sold, the Department of Education is able to remotely disable the device over the network. Each netbook is also fitted with a passive RFID chip which will enable the netbooks to be identified 'even if they were dropped in a bathtub.' The Department of Education also uses the AppLocker functionality within Windows 7 to dictate which applications can be installed."



A case to follow. (Even if they're ALL douchebags.)

http://www.rep-am.com/News/438521.txt

Blogger to be back in court Former Mills High student's suit before U.S. appeals panel

BY JIM MOORE REPUBLICAN-AMERICAN

Avery Doninger will soon return to the 2nd U.S. Circuit Court of Appeals with the right of students across the country to speak their minds in blogs and text messages at stake.

… Her federal lawsuit against former Region 10 Superintendent Paula Schwartz and Lewis S. Mills High School Principal Karissa L. Niehoff, who disqualified Doninger from election as senior class secretary when the infamous blog post came to their attention, is expected to be heard, perhaps for the final time, later this year

… According to the argument presented by the Virginia-based Student Press Law Center in a "friend of the court" brief, Doninger's post — which urged readers to contact administrators in support of the endangered concert — is especially deserving of protection.

"The lower court's decision would send the wrong message to civics classes, for it unmistakably says that a student may not exercise her First Amendment rights to encourage others to challenge a governmental decision," wrote SPLC attorney Joseph P. Esposito.

… For the plaintiffs, and their legal supporters, the issue boils down to a comparatively simple question: whether school officials have the right to discipline students for off-campus speech.



Anti-Trust in the 21st Century! “If theys big, theys musts be evil!” “They're not out-competing, they must be cheating.” “It's not fair!”

http://news.cnet.com/8301-30684_3-10362108-265.html?part=rss&subj=news&tag=2547-1_3-0-20

Google adjusts to life with trustbusters

by Tom Krazit September 28, 2009 4:00 AM PDT

Google's greatest challenge as it heads into its second decade may very well be innovating without ticking off Uncle Sam.

The position taken by the Department of Justice two weeks ago on the Google Books search settlement marked the second time in about a year the U.S. government has taken an active step to rein in one of the tech industry's signature companies. Google now is in the process of renegotiating a deal it once called "a historic settlement," one that gave it sweeping and exclusive rights to digitize certain kinds of books that competitors and activists feared would allow Google to gain more control of access to digital information.

Unlike the famous technology antitrust cases of the last century [Boy, does that make me feel old... Bob]--IBM, AT&T, Intel, and Microsoft--Google has not drawn government scrutiny based on allegations of past conduct. Rather, the focus is on what the company might do or is about to do, which should be both comforting and troubling for Google executives.


(Related)

http://webanalytics.globalthoughtz.com/index.php/google-announce-two-new-search-features/

Google announce two new search features

On 09.27.09, In Basics, by rohit

Google has been facing stiff competition from Microsoft Bing, which has come out a slew of new search features. Though Google still dominates the search result but it needs to make things better, if it wants to remain at the top. And Google is doing just that, Google has now come out with two more features in its search result to help users search better.


(Related)

http://www.techcrunch.com/2009/09/27/with-google-places-concerns-rise-that-google-just-wants-to-link-to-its-own-content/

With Google Places, Concerns Rise That Google Just Wants To Link To Its Own Content

by Erick Schonfeld on September 27, 2009



Play time for geeks?

http://www.makeuseof.com/tag/how-to-try-out-the-microsoft-office-web-apps-technical-preview/

How To Try Out The Microsoft Office Web Apps Technical Preview

Sep. 27th, 2009 By Varun Kashyap

… Microsoft has been working on a free version of its popular Office franchise as well. The free version would be available via the cloud. Microsoft recently launched a tech preview. It is an invite-only preview, however you just need a Skydrive account and some URL tweaking to try out the Office Web Apps Preview. Here is how:



For my Business Continuity class, because noting disrupts your business operations like killing off your employees.

http://www.bespacific.com/mt/archives/022425.html

September 27, 2009

CDC Weekly Influenza Surveillance Report

"Each week CDC analyzes information about influenza disease activity in the United States and publishes findings of key flu indicators in a report called FluView. During the week of September 13-19, 2009, a review of the key indictors found that influenza activity continued to increase in the United States compared to the prior weeks."



Because I show (or at least point to) many videos in my classes, it's good to have some tools to control things.

http://www.safeshare.tv/

SafeShare

Not only does SafeShare.TV remove distracting and offensive elements around YouTube videos, but it also allows you to crop videos before sharing them.

Sunday, September 27, 2009

Who was it in “Dr. Strangelove” that was concerned with “our precious bodily fluids?”

http://www.pogowasright.org/?p=4169

Sweat Becomes Offenders’ New Snitch

September 26, 2009 by Dissent Filed under Featured Headlines, Surveillance

Fredrick Kunkle and Derek Kravitz report:

The government has buried its nose in Bari Lynne Williams’s personal business.

Almost literally.

Twenty-four hours a day, whether she’s jogging, sleeping or managing a pool hall, Williams wears a high-tech sensor on her ankle that can detect the faintest whiff of alcohol in her perspiration. If she sneaks a drink, the device will know it — and so will a judge, who could put her behind bars for violating a court order to avoid alcoholic beverages.

[...]

While law enforcement has been using satellite-based GPS to track offenders’ whereabouts for some time, privacy advocates say the alcohol-monitoring device — known as Secure Continuous Remote Alcohol Monitor, or SCRAM — has taken law enforcement into the realm of continuously and remotely monitoring people’s physical condition.

Read the full article on The Washington Post.


(Related) “It's for their own good!”

http://www.pogowasright.org/?p=4176

UK drugs test for claimants sparks row over unemployment benefits

September 27, 2009 by Dissent Filed under Govt, Non-U.S., Surveillance

Controversial government plans to allow Jobcentre staff to “order” benefit claimants to undergo tests for drug and alcohol dependency are in breach of European law and unlikely to work, according to leading addiction charities.

The proposals, outlined in the welfare reform bill, which is due before the House of Lords next month, are part of a major government drive to reform Britain’s benefits culture and save taxpayers hundreds of millions of pounds a year.

Read more on UTV

[From the article:

"Potentially, anyone could be required to answer questions about their drug or alcohol use as the bill includes no test or threshold which staff must first satisfy," he said. "Do we really want to see Jobcentres given the power to drug test, share information about claimants with the police and, for the first time, require vulnerable people to undergo medical treatment by waving the stick of benefit sanctions?"



What does the US have on Switzerland? First, access to banking records, now arresting an “artist”

http://www.cnn.com/2009/SHOWBIZ/Movies/09/27/zurich.roman.polanski.arrested/

Polanski arrested in connection with sex charge

... He was taken into custody trying to enter Switzerland on Saturday, Zurich police said.



'cause sometimes it helps to have a simple explanation you can point to.

http://www.makeuseof.com/tag/technology-explained-how-do-rfid-tags-work/

Technology Explained: How Do RFID Tags Work?

Sep. 26th, 2009 By Guy McDowell