Thursday, July 29, 2010

A challenge for my Ethical Hackers: Improve the efficiency and effectiveness of this code. Provide a simple User Interface so that even non-techies can use it.

http://www.pogowasright.org/?p=12405

100 million Facebook pages leaked on torrent site

July 28, 2010 by Dissent

The 2.8GB torrent was compiled by hacker Ron Bowes of Skull Security, who created a web crawler program that harvested data on users contained in Facebook’s open access directory, which lists all users who haven’t bothered to change their privacy settings to make their pages unavailable to search engines.

Bowes’ directory contains 171 million entries, relating to more than 100 million individual users – more than one in five of Facebook’s recently trumpeted half billion user base.

The file contains user account names and a URL for each user’s profile page, from which details such as addresses, dates of birth or phone numbers can be accessed. Accessing a user’s page from the list will also enable you to click through to friends’ profiles – even if those friends have made themselves non-searchable.

Read more on THINQ.

As of the time of this posting, Skull Security’s site is timing out, probably because the story was slashd0tted. The original post, available in Google’s cache, reads in part:

I wrote a quick Ruby script (which has since become a more involved Nmap Script that I haven’t used for harvesting yet) that I used to download the full directory. I should warn you that it isn’t exactly the most user friendly interface — I wrote it for myself, primarily, I’m only linking to it for reference. I don’t really suggest you try to recreate my spidering. It’s a waste of several hundred gigs of bandwidth.

The results were spectacular. 171 million names (100 million unique).

[...]

But it occurred to me that this is public information that Facebook puts out, I’m assuming for search engines or whatever, and that it wouldn’t be right for me to keep it private. Why waste Facebook’s bandwidth and make everybody scrape it, right?

So, I present you with: a torrent! If you haven’t download it, download it now! And seed it for as long as you can.

This torrent contains:

  • The URL of every searchable Facebook user’s profile

  • The name of every searchable Facebook user, both unique and by count (perfect for post-processing, datamining, etc)

  • Processed lists, including first names with count, last names with count, potential usernames with count, etc

  • The programs I used to generate everything



What? Just because it's free, you thought it wouldn't cost you?

http://www.pogowasright.org/?p=12413

What your phone app doesn’t say: It’s watching

July 28, 2010 by Dissent

Jordan Robertson of the Associated Press reports:

Your smart phone applications are watching you – much more closely than you might like.

Lookout Inc., a mobile-phone security firm, scanned nearly 300,000 free applications for Apple Inc.’s iPhone and phones built around Google Inc.’s Android software. It found that many of them secretly pull sensitive data off users’ phones and ship them off to third parties without notification.

Read more on Forbes.



Because government is better able to determine what's important than a bunch of silly old judges?

http://www.pogowasright.org/?p=12415

White House proposal would ease FBI access to records of Internet activity

July 29, 2010 by Dissent

Ellen Nakashima reports:

The Obama administration is seeking to make it easier for the FBI to compel companies to turn over records of an individual’s Internet activity without a court order if agents deem the information relevant to a terrorism or intelligence investigation.

The administration wants to add just four words — “electronic communication transactional records” — to a list of items that the law says the FBI may demand without a judge’s approval. Government lawyers say this category of information includes the addresses to which an Internet user sends e-mail; the times and dates e-mail was sent and received; and possibly a user’s browser history. It does not include, the lawyers hasten to point out, the “content” of e-mail or other Internet communication.

Read more in the Washington Post.

In related coverage, Pete Yost of the Associated Press reports on the FBI’s defense of its guidelines for domestic surveillance.

Earlier this week, the The American Civil Liberties Union on Tuesday asked FBI field offices in 29 states and Washington, D.C., to turn over records the FBI collected on race and ethnicity in various communities. The agency fears the FBI’s data gathering and mapping practices will invite racial profiling by law enforcement. Nick Divito covers the story on Courthouse News.



Perhaps Google was not (yet) evil? Will the US Attorneys General be as willing to drop their “investigation?”

http://www.pogowasright.org/?p=12424

UK: ICO Statement on Google WiFi data

July 29, 2010 by Dissent

A spokesperson for the Information Commissioner’s Office (ICO) said:

“The ICO has visited Google’s premises to assess samples of the ‘pay-load’ data it inadvertently collected. Whilst Google considered it unlikely that it had collected anything other than fragments of content, we wanted to make our own judgement as to the likelihood that significant personal data had been retained and, if so, the extent of any intrusion. The information we saw does not include meaningful personal details that could be linked to an identifiable person. As we have only seen samples of the records collected in the UK we recognise that other data protection authorities conducting a detailed analysis of all the payload data collected in their jurisdictions may nevertheless find samples of information which can be linked to identifiable individuals. However, on the basis of the samples we saw we are satisfied so far that it is unlikely that Google will have captured significant amounts of personal data. There is also no evidence as yet that the data captured by Google has caused or could cause any individual detriment. Nevertheless it was wrong to collect the information. We will be alerting Privacy International and others who have complained to us of our position. The Information Commissioner is taking a responsible and proportionate approach to this case. However, we remain vigilant and will be reviewing any relevant findings and evidence from our international counterparts’ investigations.”

Source: ICO


(Related) You ain't seen nothing yet! (Interesting picture: Who is that sitting next to Eric Schmidt?)

http://www.wired.com/dangerroom/2010/07/exclusive-google-cia/

Exclusive: Google, CIA Invest in ‘Future’ of Web Monitoring

The investment arms of the CIA and Google are both backing a company that monitors the web in real time — and says it uses that information to predict the future.

The company is called Recorded Future, and it scours tens of thousands of websites, blogs and Twitter accounts to find the relationships between people, organizations, actions and incidents — both present and still-to-come. In a white paper, the company says its temporal analytics engine “goes beyond search” by “looking at the ‘invisible links’ between documents that talk about the same, or related, entities and events.”

America’s spy services have become increasingly interested in mining “open source intelligence” — information that’s publicly available, but often hidden in the daily avalanche of TV shows, newspaper articles, blog posts, online videos and radio reports.

Secret information isn’t always the brass ring in our profession,” then CIA-director General Michael Hayden told a conference in 2008. “In fact, there’s a real satisfaction in solving a problem or answering a tough question with information that someone was dumb enough to leave out in the open.”



For my Ethical Hackers How to get the attention of your students....

http://news.cnet.com/8301-1009_3-20012019-83.html?part=rss&subj=news&tag=2547-1_3-0-20

Security researcher demonstrates ATM hacking

LAS VEGAS--Hacking into an ATM isn't impossible, a security researcher showed Wednesday. With the right software, it's actually pretty easy.

Barnaby Jack, director of security testing at Seattle-based IOActive, hauled two ATMs onto the Black Hat conference stage and demonstrated to a rapt audience the fond daydream of teenage hackers everywhere: pressing a button and having an automated teller machine spew out its cash until a pile of paper lay on the ground.


(Related) Ditto

http://news.cnet.com/8301-27080_3-20012027-245.html?part=rss&subj=news&tag=2547-1_3-0-20

Expert: Critical system flaws a 'ticking time bomb'

"SCADA (supervisory control and data acquisition) systems are a lot less secure than IT (information technology) systems," Jonathan Pollet, founder of Red Tiger Security, said in his session, titled "Electricity for Free? The Dirty Underbelly of SCADA and Smart Meters."

… Recent modernization efforts have brought connectivity to the Internet back to the control environment and use of Windows, opening up new paths for threats, he said. Plus, there are known flaws in smart meters being installed in homes and linked back to critical systems, he added.

"We've had customers download a Windows patch and that patch actually broke the SCADA system," he said.

… Pollet said that during his consulting at utilities and other SCADA sites he has found all sorts of unnecessary software running on computers connected to important systems that can cause security problems, such as BitTorrent clients for peer-to-peer file sharing, chat clients, adult video directory scripts, and even botnet code and malware.

… Meanwhile, many power plant companies are trying to jump through loopholes in the regulations to reduce their "audit footprint," and controls are being bypassed, he said. Critical infrastructure companies are attempting to limit their responsibility and are not prepared to deal with the kinds of online attacks and espionage that keep chief information officers up at night, he said.



Another perspective

http://www.pogowasright.org/?p=12430

Mexico’s New Data Protection Law

July 29, 2010 by Dissent

W. Scott Blackmer writes:

Mexico has joined the ranks of more than 50 countries that have enacted omnibus data privacy laws covering the private sector. The new Federal Law on the Protection of Personal Data Held by Private Parties (Ley federal de protección de datos personales en posesión de los particulares) (the “Law”) was published on July 5, 2010 and took effect on July 6. IAPP has released an unofficial English translation. The Law will have an impact on the many US-based companies that operate or advertise in Mexico, as well as those that use Spanish-language call centers and other support services located in Mexico.

Read more on Information Law Group.



This might explain why red light cameras are so popular... And changing the law just make collecting fines easier.

http://yro.slashdot.org/story/10/07/28/1947231/Tennessee-Town-Releases-Red-Light-Camera-Stats?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Tennessee Town Releases Red Light Camera Stats

Posted by timothy on Wednesday July 28, @04:58PM

SonicSpike links to what he calls "a transparent look at some statistics released by a small town's red-light camera program," writing

"Specifically, in the last fiscal quarter, 7,213 incidents were recorded, 2,673 incidents were rejected by the reviewing officer, and 662 incidents were not processed due to technical issues or lack of information. All in all 3,878 citations were issued between April I — June 30 in a town of 17,000 residents. Interestingly enough there are two nearby cities claiming that individuals 'have no presumption of innocence' when accused by the red light cameras."

Fines for no-harm-no-foul rolling stops bug me, and remind me of Gary Lauder's suggestion to merge stop signs and yield signs.


(Related) Another “interpretation” of the law I find questionable.

http://games.slashdot.org/story/10/07/28/1954247/UK-Courts-Rule-Nintendo-DS-R4-Cards-Illegal?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

UK Courts Rule Nintendo DS R4 Cards Illegal

Posted by Soulskill on Wednesday July 28, @05:40PM

"A UK high court ruled today that R4 cards for the Nintendo DS are illegal, finding two vendors guilty of selling 'game copiers.' The ruling by Justice Floyd is quoted as saying, 'The economic effect on Nintendo of the trade in these devices is substantial as each accused device can store and play copies of many Nintendo DS games [...] The mere fact that the device can be used for a non-infringing purpose is not a defence.' No word in the article as to what law in particular they were found to have broken, nor of the penalty the vendors are facing, but this looks like bad news for all kinds of hardware mod, on any platform, that would enable homebrew users to bypass vendor locks."

Nintendo won a related lawsuit in the Netherlands recently, in addition to the one in Australia earlier this year.



How to reinforce your bias!

http://searchengineland.com/blekko-a-new-search-engine-that-lets-you-spin-the-web-47215

Blekko: New Search Engine Lets You “Spin” The Web

New challenger Blekko is stepping into the fray, opening to limited beta testing today. It offers a compelling way to “slash the web” and put a particular spin on your search results.

… Blekko’s “slashtags” are a unique feature that may draw you in on occasions when you want to see how search results look when they’re skewed to a particular viewpoint.

… What would rank number one for “honey” if you asked bakers versus beekeepers? Blekko can give you the spin from both groups. Want your search results with a liberal slant? You can do that at Blekko, or slash your results the opposite way for a conservative view.

This is all done using slashtags, special keywords that you place after what your searching for, in order to indicate the viewpoint you want used to spin your results.

… This is also known as a vertical search, where instead of searching across the entire “horizontal” spectrum of all web sites, you’re searching “vertically” through just one slice.



Facebook just past 500 million users. Imagine how many users Facebook would have if the users actually liked it!

http://www.bespacific.com/mt/archives/024823.html

July 28, 2010

American Customer Satisfaction Index: Internet news & information; Internet portals & search engines, Internet social media

The American Customer Satisfaction Index (ACSI) Report on E-Business: Internet Portals & Search Engines, News & Information, and Social Media Websites, July 20, 2010. Commentary by Professor Claes Fornell: Google Dips Sharply but Holds Off Bing; FOXNews.com Leads All E-Business Websites; Facebook and MySpace Fail to Satisfy



Interesting tool. Makes you wonder why a home grown system like Glenwood Springs is 8 times faster than Qwest. Of course they've had fiber since 2002. Just another example of my “let the city own it and sell it to everyone” model.

http://www.wired.com/epicenter/2010/07/fastest-best-isps/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

What’s the Fastest and Best ISP in Your City? Look It Up Here



For my website students, 'cause I don't want no sub-standard code!

http://www.webmonkey.com/2010/07/w3cs-unicorn-validator-checks-multiple-standards-at-once/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

W3C’s Unicorn Validator Checks Multiple Standards at Once

he web’s governing body has launched a new validation tool called Unicorn that checks the quality of your website’s code against multiple web standards at the same time.

You can find the new Unicorn “all-in-one validator” on the Worldwide Web Consortium (W3C) website at validator.w3.org/unicorn/.

The W3C maintains a number of free web-based tools for checking whether your web code is valid, and Unicorn makes several of these tools available under a single interface.



For my Math students. They won't be able to resist the “Easier” button.

http://www.freetech4teachers.com/2010/07/knotebooks-create-multimedia-math.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+freetech4teachers%2FcGEY+%28Free+Technology+for+Teachers%29

Wednesday, July 28, 2010

Knotebooks - Create Multimedia Math & Science Articles

Knotebooks is a neat service that allows users to create, customize, and share lessons composed of videos, images, and texts from all over the Internet.

… Using Knotebooks you can organize information to create a reference article for yourself or to share with others. You can also browse the articles published by others, add them to your account for later reference, and or alter the articles that others have written to suit your needs.

… Creating Knotebooks could be a great way for mathematics and science students to build multimedia reference libraries for themselves and for their classmates.



Annotate your videos.

http://www.freetech4teachers.com/2010/07/video-ant-discuss-and-annotate-videos.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+freetech4teachers%2FcGEY+%28Free+Technology+for+Teachers%29

Wednesday, July 28, 2010

Video ANT - Discuss and Annotate Videos

Video ANT is a free tool developed by Brad Hosack at the University of Minnesota for the purpose of providing a platform on which students and teachers view and annotate videos. Video ANT plays your specified video and while watching you and your students can and marks along a timeline and write comments alongside the video. Annotations are archived and emailed to you when you've completed the annotation process. Video ANT works with YouTube videos as well as with some video files that you can upload to the site. Click here to watch a screencast created by Brad Hosack of Video ANT in action.

Wednesday, July 28, 2010

First new development in a while. Raises all kinds of “Who was in charge” questions.

http://www.philly.com/inquirer/front_page/20100728_Second_suit_over_Lower_Merion_webcam_snooping.html

Second suit over Lower Merion webcam snooping

The letter from Lower Merion school administrators delivered the news three weeks ago [If the school district is just now notifying the students it “spied on,” we can expect more of these. Bob]- her son had been secretly monitored by the webcam on his school-issued laptop. But only when Fatima Hasan saw the evidence did the scope of the spying on her son Jalil become apparent.

There were more than 1,000 images surreptitiously captured by the computer - 469 webcam photographs and 543 screen shots.

… The cases are similar in their broad outlines. The electronic monitoring began after school-issued computers were reported missing. In both cases, the system was simply left on long after the laptops were recovered. Hundreds of photos and screen shots were captured on a predetermined schedule.

The photos from Hasan's computer included shots of him in his bedroom and of other family members and friends

… According to the suit, Hasan forgot his computer in cooking class on Dec. 18, a Friday. A teacher turned it in to the technology department that day. On Dec. 21, Hasan retrieved his computer from the technology office.

At some point that day, school officials activated the security system. The system kept capturing images for nearly two months and was only deactivated after the first lawsuit was filed.

… The district did not respond to the allegations in the suit, but in a statement said "continued litigation is clearly not the right way to proceed." It noted that new policies governing the use of technology had been drafted.

"While the results of that investigation reveal that mistakes were made, there is no evidence that any students were individually targeted," the statement said. [But surveillance was initiated on specific computers (specific students). Perhaps they believe studentsa aren't individuals? Bob]

[Court documents here: http://www.wired.com/images_blogs/threatlevel/2010/07/hasan.pdf



A minor variation on “Because that's where the money is.” And a serious failure of Disclosure?

http://www.databreaches.net/?p=12730

Hackers add new twist to check counterfeiting

July 28, 2010 by admin

Jordan Robertson of the Associated Press reports:

Think of it as one more reason not to write checks.

Hackers believed to be operating out of Russia have figured out a high-tech way to carry out the decidedly low-tech crime of check fraud, a computer security company says — writing at least $9 million in fakes against more than 1,200 legitimate accounts.

But these hackers got the account information in an unusual way: They broke into three websites that specialize in a little-known type of business — archiving check images online.

[...]

Stewart uncovered the scam while investigating malicious software that steals banking passwords. In eavesdropping on one criminal group’s communications, which he was able to do by infecting his own computer with the malicious program the group was using, he noticed they were doing something unexpected: collecting massive amounts of images of checks.

He found a file logging all of their transactions, which revealed that 3,285 checks were written against 1,280 accounts since June 2009. Most checks were written for less than $3,000 to evade banks’ anti-fraud measures. [See? They have lawyers too. Bob] Overall, he saw about 200,000 stolen check images — suggesting the criminals have exploited only a fraction of the accounts on which they have information.

SecureWorks isn’t identifying the hacked sites. [“We want customers to continue to believe they are trustworthy.” Bob]

Read more in the Portland Press Herald.



Incompetent security managers? Inadequate testing?

http://news.cnet.com/8301-27080_3-20011871-245.html?part=rss&subj=news&tag=2547-1_3-0-20

Report: Most data breaches tied to organized crime

Organized criminals were responsible for 85 percent of all stolen data last year and of the unauthorized access incidents, 38 percent of the data breaches took advantage of stolen login credentials, according to the 2010 Verizon Data Breach Investigations report to be released on Wednesday.

While external agents were behind 70 percent of the breaches, nearly 50 percent were caused by insiders and only 11 percent were attributed to business partners, concluded the report, which focused on data breaches that took place in 2009.

… Most of the externally originated breaches came from Eastern Europe, North America, and East Asia, the data shows.

Nearly 50 percent of breaches involved misuse of user privileges, while 40 percent resulted from hacking, 38 percent used malware, 28 percent used social engineering tactics, and about 15 percent were physical attacks.

There was not one single confirmed intrusion that exploited a patchable vulnerability, reflecting that fact that many of the most common hacking methods--SQL injection, stolen credentials, and backdoors--exploit problems that can't be readily patched.

"Attackers really do seem to be not so much concerned with finding software vulnerabilities as much as finding types of misconfigurations that let them in the door," Wade Baker, director of risk intelligence for Verizon Business, told CNET on Tuesday.

[The correct link to the report:

http://www.verizonbusiness.com/resources/reports/rp_2010-data-breach-report_en_xg.pdf



Are these users in the 5% of users who respond (fall victim) to SPAM? If so, they are even more ignorant that I assumed.

http://it.slashdot.org/story/10/07/27/217210/Rogue-Anti-Virus-Victims-Rarely-Fight-Back?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Rogue Anti-Virus Victims Rarely Fight Back

Posted by kdawson on Tuesday July 27, @07:04PM

"One big reason why rogue anti-virus continues to make major bucks for scam artists: relatively few victims ever ask their credit card company or bank to reverse the charges for the phony security software — even when the victims don't even receive the worthless software they were promised. I recently found several caches of data for affiliates of a rogue anti-virus distribution program, and the data showed that in one set of attacks only 367 out of more than 2,000 scammed disputed the charge. A second rogue anti-virus campaign scammed more than 1,600 people, and yet fewer than 10 percent fought the charges."



A Privacy Infographic...

http://www.wordstream.com/articles/google-privacy-internet-privacy

Do You Know Who's Watching You?


(Related) Do you know who keeps your deleted messages? For my Forensics students.

http://www.pogowasright.org/?p=12374

Rape charges dropped after deleted messages recovered from iPhone

July 28, 2010 by Dissent

There was a case in Australia that may be of interest to readers, as a defendant in a rape case was able to get the charges dismissed after his attorney retained a forensics expert who was able to recover messages the victim/accuser had sent to his iPhone, even though the messages had been deleted:

Apple has sold more than 50 million iPhones since 2007 but few users know how much information they collect. The keyboard logging cache means an expert can retrieve anything typed on it for up to 12 months. Its internal mapping and ”geotags” attached to photos indicate where a user has been.

An iPhone has up to 32 gigabytes of data that can be ”imaged” or decoded with the right equipment, Mr Coulthart said, even if it has been deleted.

Read more of the story by Joel Gibson in the Sydney Morning Herald.



They may not have it figured out, but they are trying...

http://www.hhs.gov/news/press/2010pres/07/20100708c.html

HHS Strengthens Health Information Privacy and Security through New Rules

The proposed rule announced today would strengthen and expand enforcement of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security, and Enforcement Rules by:

  • expanding individuals’ rights to access their information and to restrict certain types of disclosures of protected health information to health plans.

  • requiring business associates of HIPAA-covered entities to be under most of the same rules as the covered entities;

  • setting new limitations on the use and disclosure of protected health information for marketing and fundraising; and

  • prohibiting the sale of protected health information without patient authorization.

HHS also launched today a privacy website at http://www.hhs.gov/healthprivacy/index.html to help visitors easily access information about existing HHS privacy efforts and the policies supporting them.



There seems to be a lot of articles related to “Behavioral Advertising” today.

Now you don't even need to “Click!” What relationship do you need with Google? Do you have to be on Google.com, or will it work on any site you visit after the search?

http://tech.slashdot.org/story/10/07/27/1624251/Google-Nabs-Patent-To-Monitor-Your-Cursor-Movement?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Google Nabs Patent To Monitor Your Cursor Movement

Posted by CmdrTaco on Tuesday July 27, @01:14PM

"Google has been awarded a patent for displaying search results based on how you move your mouse cursor on the screen... Google's plans are to monitor the movements of the cursor, such as when a user hovers over a certain ad or link to read a tooltip, and then provide relevant search results, and ads, based on that behaviour. It means that it does not require users to actually click a link to know that they were interested in it, opening a world of opportunity for even more focused ads."

[From the article:

The patent, entitled System and Method for Modulating Search Relevancy Using Pointer Activity Monitoring and numbered 7756887, was filed on February 16 2005, but it was only this month that it was published and released to the public. It is also a continuation of a previous patent filed in December 2004.

To monitor the cursor would require potential invasion of privacy by stepping off the web itself and into the user's browser.


(Related) Facebook has all this personal data users provide, why not exploit it?

http://gigaom.com/2010/07/27/amazon-connects-with-facebook-but-doesnt-kiss-and-tell/

Amazon Connects With Facebook, but Doesn’t Kiss and Tell

Amazon has launched a new feature that connects users to their Facebook profiles, and then makes product suggestions based on their “likes” and other activity on the social network — but the online retailer also stresses that it will not share any of the data it has about its users or their purchasing behavior with Facebook.


(Related) How would you prove the data you have on an individual was collected from sources not flagged as do-not-track?

http://www.pogowasright.org/?p=12382

FTC Considers Do-Not-Track List

July 28, 2010 by Dissent

Wendy Davis reports:

The Federal Trade Commission is considering proposing a do-not-track mechanism that would allow consumers to easily opt out of all behavioral targeting, chairman Jon Leibowitz told lawmakers on Tuesday.

Testifying at a hearing about online privacy, Leibowitz said the FTC is exploring the feasibility of a browser plug-in that would store users’ targeting preferences. He added that either the FTC or a private group could run the system.

Leibowitz said that while Web users on a no-tracking list would still receive online ads, those ads wouldn’t be targeted based on sites that users had visited in the past.

Read more on MediaPost.



Lots of questions: How often does it “ping?” What information is sent to Google? Is it legal to by-pass this as it is a dongle?

http://techcrunch.com/2010/07/27/android-takes-a-new-approach-to-fighting-piracy-with-licensing-service/

Android Takes A New Approach To Fighting Piracy With Licensing Service

Pirates looking to illegally copy Android applications are about to face a new challenge: today, Google’s Android team announced that it is releasing a new application Licensing Service for Android. The service, which is meant to help developers secure their applications from piracy, forces apps to ping Google’s home server at regular intervals to verify that they were legitimately purchased. Fail that check, and the app can lock you out.

According to the Dev Guide, developers are free to decide how they want to deal with an application that is deemed to be pirated (a developer could disable the app entirely, or perhaps they could activate a trial mode prompting the user to purchase the real thing).



How to use Copyrighted works

http://www.bespacific.com/mt/archives/024813.html

July 27, 2010

Rulemaking on Exemptions from Prohibition on Circumvention of Technological Measures that Control Access to Copyrighted Works


(Related) Lawyers don't find humor funny?

http://arstechnica.com/tech-policy/news/2010/07/did-you-hear-the-joke-about-the-comedian-and-copyright-law.ars

Did you hear the joke about the comedian and copyright law?

The notoriously litigious music industry often resorts to the legal system to protect itself from pirates and samplers. But comedians don't. So why hasn't the joke well gone dry?

That's the question asked by a forthcoming book chapter from the University of Chicago Press called "Intellectual Property Norms in Stand-Up Comedy." Written by two professors from the University of Virginia School of Law, the chapter offers a case study in the axiom that more IP rights aren't always better IP rights.



Interesting specs...

http://www.electronista.com/articles/10/07/27/augen.gentouch78.takes.on.apple.through.price/

iPad gets odd rival in $150 Android tablet at Kmart

The online edition of a Kmart flyer has revealed plans for what could be an unusual entry into competition against Apple in the still young tablet market. The Augen Gentouch78 should run Android 2.1 on a seven-inch screen and will keep simple with just 2GB of internal storage and Wi-Fi alone for Internet access. At $150, though, it would cost less than a third the price of an iPad while offering many more features than a similarly priced Nook Wi-Fi.



More things you can do with WolframAlpha

http://www.makeuseof.com/tag/10-search-terms-put-wolfram-alpha-good-everyday/

10 Search Terms To Put Wolfram Alpha To Good Use Everyday



Sort of a MindMap for navigating the Internet? Maybe linked bookmarks would be a better description.

http://www.makeuseof.com/dir/pearltrees-organize-store-online-content/

PearlTrees: Store, Share & Organize Web Content Visually

Pearltrees is a browser addon for Mozilla Firefox. The developers of the addon provide users with a great new way of storing and connecting the web content they want to save.

Basically you can create different map-like structures out of nodes; each node can be connected to one another. These nodes are shortcuts to websites. You can create more than one map and add as many nodes as possible. Nodes can be rearranged as you like.

www.addons.mozilla.org/en-US/firefox/addon/11255

Similar tools: BagTheWeb, DropVine, Shareaholic, Linkli.st, NiceSharing, ShareTabs and MinMu.



This has potential! Watch the video. Look at the “Featured Binders” Make students do all the work?

http://www.killerstartups.com/Web-App-Tools/livebinders-com-store-everything-you-want-online

LiveBinders.com - Store Everything You Want Online

http://livebinders.com/

A site that defines itself as “the knowledge sharing place”, LiveBinders.com will let you create a binder in which you can organize all your resources and access them far more easily than ever before.

These binders can be created for free, and they can contain pretty much anything you like - images, videos, Word documents, PDFs… the choice is entirely yours, and it will depend on which uses you intend to put this application to - personal and professional uses are entirely compatible with the way in which Live Binders has been devised.

Of course, you can actually share the content that you have stored on your binder. In that way, LiveBinders.com stands as a great tool for collaboration.

And note that paid Binders are also going to be implemented soon. The free version of the service is limited to 100 MB per account, and 5 MB per file. These limitations will be automatically lifted the moment that you go for a paid account. Premium services will also come with better overall management features, such as the ability to monitor file uploads.

Tuesday, July 27, 2010

Interesting language. Makes it sound like they have their Computer Security act together! How novel.

http://www.databreaches.net/?p=12695

Hacked investment firm says hack intended as a launch pad

July 26, 2010 by admin

Attorneys for Resnick Investment Advisors in South Carolina have notified the New Hampshire Attorney General’s Office that in June 2010, the investment firm’s network was breached. The breach was discovered on June 22, and the means of attack identified and reported to the FBI.

An investigation into the incident reportedly indicated that the breach did not result in any client files being accessed or downloaded, and the firm notes that its security measures prevent downloading of any files. Based on an investigation by their IT service provider, the firm believes that the motive was not to access, alter, or acquire any client records but to use Resnick’s corporate identity to launch a malicious attack on another entity.

The firm began sending out notifications to its clients last week and offered them free credit monitoring services for a year.



Not sure how to interpret this. It would seem to fly in the face of the “government knows best” assumptions of “true believer” Democrats, but then that's only a label these days.

http://www.databreaches.net/?p=12704

North Carolina To Privatize IT Operations, Jobs

July 27, 2010 by admin

Paul McDougall reports:

Faced with a looming, $3 billion budget deficit, North Carolina is eyeing a major shakeup of its tech operations that could see the state outsource the bulk of its IT work to the private sector while consolidating other operations internally.

The state has launched a search for an outside consulting firm to help guide the reorganization, according to a memo Democratic governor Bev Perdue sent to state cabinet secretaries and agency heads. “The Office of Information Technology Services (ITS) issued a Request for Information to seek input and ideas from the vendor community for improving the delivery of IT in state government,” Perdue said in the memo, dated July 21st.

Read more on InformationWeek.


(Related) Here is (I suspect) one bidder... And come to think of it, didn't they back Obama in the last election?

http://techcrunch.com/2010/07/26/google-city-of-los-angeles-apps-delay-is-overblown/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

Google: City Of Los Angeles Apps Delay Is Overblown



Allow me to point out that computer programs do not spontaneously spring into being. You must deliberately program them. You must also deliberately remove them when you determine they are no longer desirable.

http://www.pogowasright.org/?p=12353

Citi plugs privacy hole in iPhone banking app

July 26, 2010 by Dissent

Elinor Mills reports:

Citibank has fixed a flaw in its iPhone app that was inadvertently storing customer account data on the mobile devices, the company said on Monday.

“During a recent review, we discovered that our U.S. Citi Mobile iPhone banking app was accidentally saving information related to customer accounts in a hidden file on their iPhones,” the company said in a statement. “This information may also have been saved on their computer if they had been synchronizing their iPhone with their computer via iTunes.”

Read more on cnet. Spencer E. Ante has more on the background of the problem in the Wall Street Journal.



Wow!. Think of this as taking the Lower Merion School District's “how to spy on our students in their bedrooms” privacy model and expanding it globally under the the banner of “It's for the children” This is also using the Facebook model: First, become popular. Then introduce privacy violations.

http://yro.slashdot.org/story/10/07/27/1244258/Chatroulette-To-Log-IP-Addresses-Take-Screenshots?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Chatroulette To Log IP Addresses, Take Screenshots

Posted by CmdrTaco on Tuesday July 27, @09:44AM

"Chatroulette, the strangely addictive online game in which users are connected via webcam and microphone to random strangers at the click of a button, has had enough of users exposing themselves to the unsuspecting public, among other disgraces. The founder of Chatroulette has announced the company has hired developers to collect IP addresses and take screenshots of those users breaking the rules."



Unlikely to be of any interest to the iPhone users I know long ago ignored their contracts.

http://gigaom.com/2010/07/26/what-the-new-dmca-ruling-on-copyright-actually-says/

What the New DMCA Ruling on Jailbreaking Actually Says

The U.S. Copyright Office today clarified how it plans to enforce the Digital Millennium Copyright Act, making new exemptions for things like jailbreaking iPhones and ripping DVDs.

It might be exciting to think that it’s now legal to jailbreak iPhones for the purpose of installing software not approved by Apple or switching wireless carriers. But “jailbreaking is legal” is not what the ruling said. It simply said that jailbreaking is not a violation of copyright law.



Why I believe research that is public has a better chance of being “honest.” When you have the world world looking at your data and methods, little flaws and assumptions tend to pop out.

http://yro.slashdot.org/story/10/07/26/1857224/Major-Flaws-Found-In-Recent-BitTorrent-Study?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Major Flaws Found In Recent BitTorrent Study

Posted by Soulskill on Monday July 26, @03:51PM

Caledfwlch writes with a followup to news we discussed a couple days ago about a study that found only 0.3% of torrents to be legal. (A further 11% was described as "ambiguous.") TorrentFreak looked more deeply into the study and found a number of flaws, suggesting that the researchers' data may have been pulled from a bogus tracker. Quoting:

"Here's where the researchers make total fools out of themselves. In their answer to the question they refer to a table of the top 10 most seeded torrents. ... the most seeded file was uploaded nearly two years ago (The Incredible Hulk) and has a massive 1,112,628 seeders. The torrent in 10th place is not doing bad either with 277,043 seeds. All false data. We're not sure where these numbers originate from but the best seeded torrent at the moment only has 13,739 seeders; that's 1% of what the study reports. Also, the fact that the release is nearly two years old should have sounded some alarm bells. It appears that the researchers have pulled data from a bogus tracker, and it wouldn't be a big surprise if all the torrents in their top 10 are actually fake."

They also take a cursory look at isoHunt, finding that 1.5% of torrent files come from Jamendo alone, "a site that publishes only Creative Commons licensed music."



This is largely a poor job of reporting obvious security problems. But it raises an old concern. If organizations don't adequately secure their systems, should we continue to hold them blameless when security breaches are detected? Insurance companies set their rates based (partly) on how complete the security is. Should we insist the level of security be published as guide for consumers?

http://it.slashdot.org/story/10/07/26/2224232/How-Cyber-Spies-Infiltrate-Business-Systems?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

How Cyber Spies Infiltrate Business Systems

Posted by kdawson on Monday July 26, @06:52PM

"InfoWorld's Bob Violino reports on the quiet threat to today's business: cyber spies on network systems. According to observers, 75 percent of companies have been infected with undetected, [and 96% of “observers” have undetected brains. By definition, it's undetected until you detect it, but that doesn't mean it exists. If it's undetected, how do you count it? Bob] targeted attacks — ones that typically exploit multiple weaknesses with the ultimate goal of compromising a specific account. Such attacks often begin by correlating publicly available information to access a single system. From there, the entire environment can be gradually traversed enabling attackers to place monitoring software in out-of-the-way systems, such as log servers, where IT often doesn't look for intrusions. ' They collect the data and send it out, such as via FTP, in small amounts over time, so they don't rise over the noise of normal traffic and call attention to themselves,' Violino writes. 'There's probably no way you can completely protect your organization against the increasingly sophisticated attacks by foreign and domestic spies. That's especially true if the attacks are coming from foreign governments, because nations have resources that most companies do not possess.'"


(Related) Social engineering at the corporate level? Give us all your customer information and we give you some graphs back that you can use to justify pretty much anything you want to do.

http://yro.slashdot.org/story/10/07/27/0016216/UK-ISP-TalkTalk-Caught-Monitoring-Its-Customers?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

UK ISP TalkTalk Caught Monitoring Its Customers

Posted by kdawson on Tuesday July 27, @05:21AM

"The UK ISP TalkTalk has been caught using a form of Deep Packet Inspection technology to monitor and record the websites that its customers visit, without getting their explicit consent. The system, which is not yet fully in place, ultimately aims to help block malware websites by comparing the URL that a person visits against a list of good and bad sites. Bad sites will then be restricted. TalkTalk claims that its method is totally anonymous and that the only people with visibility of the URL database itself are Chinese firm Huawei, which will no doubt help everybody to feel a lot better (apply sarc mark here) about potentially having their privacy invaded."



Individuals often mistake their rights as equivalent to real citizens, like the police, rich folks and politicians.

http://yro.slashdot.org/story/10/07/27/0212232/Facing-16-Years-In-Prison-For-Videotaping-Police?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Facing 16 Years In Prison For Videotaping Police

Posted by kdawson on Tuesday July 27, @02:26AM

"The ACLU of Maryland is defending Anthony Graber, who faces as much as sixteen years in prison if found guilty of violating state wiretap laws because he recorded video of an officer drawing a gun during a traffic stop. ... Once [the Maryland State Police] learned of the video on YouTube, Graber's parents' house was raided, searched, and four of his computers were confiscated. Graber was arrested, booked, and jailed. Their actions are a calculated method of intimidation. Another person has since been similarly charged under the same statute. The wiretap law being used to charge Anthony Graber is intended to protect private communication between two parties. According to David Rocah, the ACLU attorney handling Mr. Graber's case, 'To charge Graber with violating the law, you would have to conclude that a police officer on a public road, wearing a badge and a uniform, performing his official duty, pulling someone over, somehow has a right to privacy when it comes to the conversation he has with the motorist.'"

Here are a factsheet (PDF) on the case from the ACLU of Maryland, and the video at issue.



An interesting conclusion.... Apparently you can talk about the Emperor's new clothes...

http://www.pogowasright.org/?p=12346

Appeals Court Protects Free Speech for Privacy Advocate

July 26, 2010 by Dissent

From EPIC.org:

Privacy Advocate Betty Ostergren has won in federal appeals court in her challenge to a state law designed to prosecute her for drawing attention to the state’s online publication of SSNs. In Ostergren v. Cuccinelli, the court ruled that the Commonwealth of Virginia may not prosecute Ostergren for publishing the SSNs of state officials available in public land records until the Commonwealth itself stops making these unredacted documents available. EPIC filed a “friend of the court” brief in support of Ostergen, urging the court to hold that the First Amendment protects Ostergren’s speech. For more information, see EPIC Ostergren v. McDonnell, EPIC Social Security Numbers, and EPIC Identity Theft.

Woo hoo! Congratulations, Betty!



Interesting. Does it explain the reluctance of the newspaper industry (or RIAA) to innovate?

http://www.bespacific.com/mt/archives/024800.html

July 26, 2010

The Effect of Market Leadership in Business Process Innovation: The Case(s) of E-Business Adoption

The Effect of Market Leadership in Business Process Innovation: The Case(s) of E-Business Adoption, Kristina Steffenson McElheran, Working Paper 10-104, Harvard Business School

  • "This paper empirically investigates how market leadership influences firm propensity to adopt new business process innovations. Using a unique data set spanning roughly 35,000 plants in 86 U.S. manufacturing industries, I study the adoption of frontier e-business practices during the early diffusion of the commercial internet. Theory predicts that firms with greater market share will be more likely to adopt innovations that build on their existing strengths, while they will resist more radical technological advances. While prior work primarily focuses on product innovation, I extend the logic into the business process setting to find that leaders were far more likely to adopt the incremental innovation of internet based e-buying. However, they were commensurately less likely to adopt the more strategically sensitive and complex practice of e-selling. This pattern is remarkably robust, holding across a wide range of industries and controlling for factors such as productivity and related technological capabilities. The results are explicated by a framework I develop for understanding the drivers of this behavior and making it possible to classify business process innovations as radical or not. While greater market share promotes adoption of all types of business process innovations, this effect is outweighed by additional co-invention and coordination costs whenever a technological advance address strategically sensitive and complex business processes that must also span the firm boundary."


(Related) Why the mud is sticky... A short article.

http://www.economist.com/node/16646290

Media's analogue holdouts

Digitisation and its discontents

Why some media outfits still refuse to go online

Jul 22nd 2010



Interesting application of the “move it into” part of “move it into the Cloud.” This could easily expand into a shared backup (even shared processing) application..

http://techcrunch.com/2010/07/27/zumocast-is-like-cloud-storage-without-the-cloud-or-the-cost/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

ZumoCast Is Like Cloud Storage Without The Cloud, Or The Cost

ZumoCast is a new cloud storage service, sorta, minus the cloud. The application streams files directly from your home desktop computer to another Internet connected device.



This will (eventually) be very interesting. Anything you have a “Top Ten” list of get aggregated with everyone's lists to give you an Average ranking. Value will depend on how cleverly you define your list.

http://techcrunch.com/2010/07/27/listiki-offers-a-smart-way-of-gathering-opinion-through-crowdsourced-lists/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

Listiki Offers A Smart Way Of Gathering Opinion Through Crowdsourced Lists

Listiki (a portmanteau of the words “list” and “wiki”) lets you crowdsource lists of, well, anything. This could be something as trivial as a list of the ‘top ten horror movies’ or something more self-serving like, I don’t know, ’5 must-read tech bloggers’. Lists can be as short or as long as you like and each item may also include a URL.

But here’s the clever bit: any list can, effectively, be cloned so that you can re-order items to your own taste (via drag ‘n’ drop) or even add, delete and/or replace them. Any changes made are interpreted in real time and ripple through to a ‘master’ list, aggregating the opinions of all contributors but without destroying your own version of the list. You can also, of course, view the original lists of other contributors to that subject. It’s pretty neat.



Mainly for teachers, but normal mortals can use it too.

http://www.freetech4teachers.com/2010/07/learn-it-in-5-tech-how-to-videos-for.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+freetech4teachers%2FcGEY+%28Free+Technology+for+Teachers%29

Monday, July 26, 2010

Learn It in 5 - Tech How-to Videos for Teachers

Learn It In 5 is a relatively new site that features short how-to videos for teachers. The videos are intended to help teachers quickly learn how to use some of the the web tools are essential to being a successful user of classroom technology. The videos cover tools like Skype, Diigo, VoiceThread, and more.



For illustrating differences...

http://www.freetech4teachers.com/2010/07/search-credible-26-search-engines-in.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+freetech4teachers%2FcGEY+%28Free+Technology+for+Teachers%29

Monday, July 26, 2010

Search Credible - 26 Search Engines in One

Search Credible is a search service that allows you to access 26 different search engines from one location. Included in the list of search engines Search Credible searches are Wolfram Alpha, EBSCO, ERIC, and the usual suspects such as Google, Bing, and Yahoo. To use Search Credible just enter your search term(s) then click on the search engine of your choice.



This could be HUGE! I can see developing tools for my Statistics class that are far easier to use than Excel...

http://www.freetech4teachers.com/2010/07/wolfram-alpha-launches-custom-widget.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+freetech4teachers%2FcGEY+%28Free+Technology+for+Teachers%29

Tuesday, July 27, 2010

Wolfram Alpha Launches a Custom Widget Builder

Computational search engine Wolfram Alpha has just launched a new widget building tool. The Wolfram Alpha widget builder will allow anyone to create a computational search widget. Once created the widgets can easily be embedded into Blogger, WordPress, iGoogle, and just about any other website or blog service. Published widgets appear in a gallery that is accessible to anyone that registers with Wolfram Alpha.

Creating a Wolfram Alpha Widget is a fairly straight-forward process. To get started, enter a search phrase such as "distance from Boston to New York in inches." In the second step you define the variables for your widget. This second step is the crucial step that I had to try a few times before I got it right. After completing step two the rest of the process is a simple matter of selecting the output format, widget theme, and writing a description of the widget.



A talk by one of my favorite bloggers. Don't let the word Math fool you, this is about teaching technology.

http://teachingcollegemath.com/2010/07/math-technology-to-engage-delight-and-excite-2/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+TeachingCollegeMath+%28Teaching+College+Math%29

Math Technology to Engage, Delight, and Excite

We’re in a recession and so is your department budget. Luckily for you, there are lots of great programs and web resources that you can use to teach math, and most of these are free. Use the resources in this presentation to tackle the technology problems that haunt you and capture the attention of your math classes with interactive demonstrations and relevant web content.

Here is the video, audio, and slides from my keynote talk “Math Technology to Engage, Delight, and Excite” from the MAA-Michigan meeting in May 2010. There is also an iPad/iPod-friendly version here.

Monday, July 26, 2010

Indication that banks have known about this of years and never told their customers? Apparently they haven't fixed it either. Not the best way to inspire confidence...

http://yro.slashdot.org/story/10/07/25/1954216/Online-Banking-Trojan-Stole-Money-From-Belgians?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Online Banking Trojan Stole Money From Belgians

Posted by kdawson on Monday July 26, @04:37AM

"Belgian authorities uncovered an international network of online banking fraud (Google translation; Dutch original), which has been going on since 2007. The fraud targeted customers of several major banks, which used supposedly secure two-factor systems that require the customer to generate authorization codes from transaction information (random code and amount or recipient's account number) that is manually keyed into a cryptographic device (Flash demo from one of the banks; manufacturer's website). Trojan horses that were planted onto the victims' computers would generate a fake error message and request that the victim re-enter the authorization code. This way, amounts up to €4,000 were transferred to money mules and thence to Eastern Europe. The worrying part is that many cases were never reported to the police, because the bank preferred to refund the money to the victim rather than risking its reputation. The extent of this type of fraud is unknown."

The article mentions in passing that similar crimes are occurring in Germany and Sweden.



Perhaps now that Big Brother will have to share all those video cameras with Eurasia, and Eastasia the average citizen will wake up?

http://www.pogowasright.org/?p=12337

Britons to be spied on by foreign police

July 26, 2010 by Dissent

Tom Whitehead and Andrew Porter report:

Britons face being spied on and pursued by foreign police officers even for the most minor offences in an European agreement the Home Office will sign up to tomorrow.

The power allows prosecutors from any EU country to demand details such as DNA or even bank and phone records on anyone they suspect of a crime.

Officers in the UK would be almost powerless to refuse the request even if they believed it was disproportionate to the alleged offence being investigated.

They could also be told to carry out investigations and live surveillance for their EU counterparts, despite already stretched resources.

Read more in the Telegraph.



As I read it, this means that as long as I have the right to use the software (my license is current) I can bypass (or remove?) all those irritating technological protections.

http://yro.slashdot.org/story/10/07/25/1646256/Court-Rules-That-Bypassing-Dongle-Is-Not-a-DMCA-Violation?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Court Rules That Bypassing Dongle Is Not a DMCA Violation

Posted by kdawson on Sunday July 25, @03:53PM

tcrown007 sends along an appeals court ruling that, for once, limits the reach of the Digital Millennium Copyright Act's anti-circumvention clause.

"MGE UPS makes UPS systems and software that are protected by hardware dongles. After the dongles expired, GE bypassed the dongles and continued to use the software. MGE sued, won, and has now lost on GE's appeal. Directly from the court's ruling (PDF): "Merely bypassing a technological protection that restricts a user from viewing or using a work is insufficient to trigger the DMCA's anti-circumvention provision... The owner's technological measure must protect the copyrighted material against an infringement of a right that the Copyright Act protects, not from mere use or viewing.' Say what? I think I just saw a pig fly by."



Five articles on risk. Two I think are generally useful.

http://www.deloitte.com/view/en_US/us/Insights/hot-topics/your-turn-risk/index.htm?id=USRSS&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+DeloitteUs+%28Deloitte+LLP+Top+Stories%29

Your Turn: Risk

Most business leaders today understand what risk management is and why it’s important — but they’re still wrestling with questions about how to make it work in real life. What does your organization need to do to manage risk effectively? Who should be responsible for what? What tools and technologies do they need?

Asking the right questions and finding effective answers are at the heart of becoming what we call a Risk Intelligent EnterpriseTM. Explore our latest resources to get started.

Creating a Risk Intelligent Infrastructure

Explore our most current thinking on building effective risk management practices into the fabric of your organization.

E-Discovery: Mitigating Risk Through Better Communication

A survey of legal, risk, compliance and information technology (IT) functions identified three interrelated challenges.



Have the Chinese found another 'opiate of the people?”

http://politics.slashdot.org/story/10/07/25/1454255/Porn-Sites-Still-Exposed-In-China?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Porn Sites Still Exposed In China

Posted by Soulskill on Sunday July 25, @12:07PM

"Could it be that internet censorship in China has a pecking order? Politics and human rights are bad — but porn is okay? The porn sites that suddenly popped up in China two months ago are still accessible, leaving people wondering if it's a change in policy, a glitch, or maybe a test by the Chinese Internet police. The Chinese government isn't saying, but one Internet analyst speculates, 'Maybe they are thinking that if Internet users have some porn to look at, then they won't pay so much attention to political matters.'"



With my handwriting, this is also a one-way encryption tool!

http://www.makeuseof.com/dir/pilothandwriting-type-in-your-own-handwriting

PilotHandWriting: Type In Your Own Handwriting & Email

Here’s how it works – you sign up with them, start with the process and print out a template which is nothing but a sheet containing 26 squared blocks for all the alphabets. Now you type in the letters on those blocks using a pen, switch on the webcam through the site’s interface and then hold the paper right in front of it, so that the tool can capture the letters.

Once it’s done, you get an opportunity to edit the letters and make them more beautiful. Finally, you can type in a letter in the same interface using your keyboard. This time, the fonts would be what you always wanted – handwritten. Finally, send the email with the click of a button. Neat, isn’t it?

www.pilothandwriting.com/en

Similar tools: YourFonts, FontStruct as well as our recent article, Two Free Tools To Make Your Very Own Fonts.

Sunday, July 25, 2010

Unlikely to be a coincidence. Build your own scenario.

http://news.yahoo.com/s/pcworld/20100724/tc_pcworld/iranwasprimetargetofscadaworm

Iran Was Prime Target of SCADA Worm

Computers in Iran have been hardest hit by a dangerous computer worm that tries to steal information from industrial control systems.

According to data compiled by Symantec, nearly 60 percent of all systems infected by the worm are located in Iran.



I'd have a few more questions. Have any systems been added or updated in the past ten years? What is available and how is it used?

http://www.bespacific.com/mt/archives/024791.html

July 24, 2010

More Fallout from Failed Attempt to Modernize FBI Computer System

News release: "Senator Chuck Grassley is pressing the Director of the FBI for additional information about its latest attempt to modernize its antiquated computer system. Grassley sent a letter to Director Robert Mueller following reports that a stop work order had been placed on both phases 3 and 4 of the Sentinel contract with Lockheed Martin. “The FBI has been trying to get its computer system up to speed for a decade. It appears that the third iteration of a modern FBI computer system is about to fail. Hundreds of millions of dollars have been spent on a system that is little more than a fancy personnel management system. Taxpayers deserve an answer about the continued failure of the FBI and where the hundreds of millions of dollars went,” Grassley said. “I want to know exactly how much more taxpayer money the FBI intends to spend and when the system will be completed and in working order. The FBI needs a modern computing system, on time and on budget, for our intelligence community to stay ahead of the new and evolving threats facing our country...”



Interesting business model and about time someone did this...

https://www.entrustet.com/

Entrustet

Create a secure list of digital assets

Designate heirs and a Digital Executor

Decide which assets are transferred to heirs and which are deleted

Legally protect your digital assets



An interesting mind exercise for my Small Business students. Create a business model that does not depend on the Internet...

http://news.slashdot.org/story/10/07/24/1514210/Adapting-the-Post-Office-To-the-Digital-Age?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Adapting the Post Office To the Digital Age

Posted by Soulskill on Saturday July 24, @12:24PM

"Paul B. Carroll and Chunka Mui write in the Washington Post that with projected deficits through 2020 of $238 billion, the debate over potential changes at the US Postal Service is like a fight over the dessert bar on the Titanic: email has already supplanted letters, more people will send money via PayPal rather than mail checks, people will download their movies and books, check their bills online, and receive information about their investments electronically. Delivery volume for first-class mail fell 22 percent from 1998 through 2007, tumbled an additional 13 percent last year and was down 3 percent in the first half of this year despite heavy mailings from the Census Bureau. USPS's future lies in things that need to be delivered physically: shoes, computers and other objects, and the USPS has assets that could let it take on UPS and FedEx. 'USPS needs to start with the future and work backward to the present,' write Carroll and Mui. 'It needs to forecast volumes for all types of its business five, 10 and 15 years out and design a business model that will thrive under those scenarios. Only then can it figure out what radical changes need to be made now.'"



Tools & Techniques

http://www.freetech4teachers.com/2010/07/nine-survey-tools-for-teachers-and.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+freetech4teachers%2FcGEY+%28Free+Technology+for+Teachers%29

Saturday, July 24, 2010

Nine Survey Tools for Teachers and Students



Diagramming tool

http://live.gnome.org/Dia

Dia

Dia is a GTK+ based diagram creation program for GNU/Linux, Unix and Windows released under the GPL license.

Dia is roughly inspired by the commercial Windows program 'Visio', though more geared towards informal diagrams for casual use. It can be used to draw many different kinds of diagrams. It currently has special objects to help draw entity relationship diagrams, UML diagrams, flowcharts, network diagrams, and many other diagrams. It is also possible to add support for new shapes by writing simple XML files, using a subset of SVG to draw the shape.

[Some examples: http://live.gnome.org/Dia/Examples



Project Management tool.

http://www.serena.com/products/openproj/index.html

OpenProj

OpenProj is a open source project management desktop software by Serena Software. It is replacement of Microsoft Project . Speaking of Microsoft Project, OpenProj does everything that Project does. It also adds a few tricks Project hasn’t learned: it works on Windows, Mac, Unix and Linux. And it’s completely free.



More capable spreadsheet than Excel? Includes 154 functions not found in Excel

http://projects.gnome.org/gnumeric/

Gnumeric

Gnumeric will import your existing Microsoft Excel files.



An upgrade for OpenOffice? Or Oprah Winfrey software?

http://sourceforge.net/projects/ooop/

OxygenOffice Professional - Office Suite

OxygenOffice Professional(OOOP, O2OP)is an enhanced version of free OpenOffice.org what is a multi-platform office productivity suite. OxygenOffice Professional contains more extras like templates, clipart, samples, fonts and VBA support.