Wednesday, April 06, 2011

Are we seeing only a small part of this breach?

http://news.cnet.com/8301-27080_3-20051038-245.html

Who is Epsilon and why does it have my data?

Epsilon is one of a growing number of companies that offer outsourced services for helping companies attract and keep customers. In addition to offering e-mail marketing services and managing customer e-mail databases for clients, Epsilon monitors social networking and other sites to see what people are saying about a company, advises on markets to target, helps develop and maintain customer loyalty programs, and offers Abacus, "the world's largest cooperative database with over 8.6 billion consumer transactions and 4.8 billion business transactions" used for creating lists of prospective customers. The different data Epsilon sells includes age, profession, residence, ethnic information and political affiliation, according to a list published on the site of security firm Magmatic.

"The e-mail component of Epsilon is a small part of the company," Dave Frankland, vice president and principal analyst at Forrester Research, told CNET. "They are in the business of managing customer data and helping companies integrate that data and communicate more effectively with customers. So they have a lot more information than just e-mail addresses and names."

… Breaches at third-party providers aren't new. After McDonald's and other companies' customers were informed of a breach at their e-mail database provider late last year, Silverpop acknowledged that it was one of "several technology providers targeted as part of a broader cyberattack."

… The Epsilon breach appears to be truly shaking the industry, said Frankland who is at the Forrester Marketing Forum this week and wrote this blog post on the incident.

"Epsilon, as well its competitors are here. They're all saying 'it could have been us,'" he said. "There is a lot of talk about legislation in the industry. This is going to increase the spotlight."

… Epsilon also has information and links for opting out of its e-mail and marketing services on its Web site here. [But, they will keep your information on the database, even if their clients no longer use their services... Bob]



No surprise. Data on the Internet is kept for geological time...

http://www.pogowasright.org/?p=22239

Why unsubscribing might not have protected you from the Epsilon breach

April 5, 2011 by Dissent

Back in December 2010, when Walgreens sent out its first breach notifications, one of the troubling aspects was that despite the fact that consumers had unsubscribed from their mailings, their data had been retained. The December 2010 notification email read, in part:

We realize you previously unsubscribed from promotional emails from Walgreens, and that will continue. As a company, we absolutely believe that all customer relationships must be built on trust. That is why we believe it is important to inform you of this incident. Online security experts have reported an increase in attacks on email systems, and therefore we have voluntarily contacted the appropriate authorities and are working with them regarding this incident.

So why did they retain his data when the customers had clearly unsubscribed? How does it inspire trust if you keep data that you are no longer supposed to use when hanging on to it increases the risk that it will be acquired by cybercriminals? How is that a relationship built on trust?

Fast forward and it appears that it has happened again. The latest round of Walgreens notifications reads, in part:

[...]

We realize you previously unsubscribed from promotional emails from Walgreens, and that will continue, but we feel an obligation to make you aware of this incident. We regret this has taken place and any inconvenience this may have caused you. If you have any questions regarding this issue, please contact us at 1-855-814-0010. We take your privacy very seriously, and we will continue to work diligently to protect your personal information.

Sincerely,

Walgreens Customer Service Team

So why were those data still on Epsilon’s servers? Was that a function of Walgreens’ policies about data retention even for unsubscribers? [Either a deliberate policy choice to keep the data, or a failure of management to consider it in their record retention policy Bob]

Shouldn’t “unsubscribe” mean “Pretend you never met me and I never gave you my email address. Delete it.” And do most customers believe that when they unsubscribe, their data are being deleted? [Probably, but your assumption is not my mandate. (Your wish is NOT my command) Bob]

Don’t tell me to read the privacy policies as we all know most people don’t really read them.

Why isn’t there a popup next to the “subscribe” button that tells you that your name and email address will be sent to a third party and will never be deleted even if you unsubscribe? How about:

By subscribing, your name and email address will go to a vendor that we trust, even if you don’t know who they are. And your data will remain with that vendor even after you die, barring any act of Congress or the FTC.

Wouldn’t that at least be more transparent if you’re not going to delete the data when the customer unsubscribes?

Walgreens has not (yet) responded to an inquiry I sent them about this issue earlier today.



What can you do with a mere email address?

http://news.cnet.com/8301-27080_3-20051071-245.html

Attack on RSA used zero-day Flash exploit in Excel

The breach at RSA that could compromise the effectiveness of the firm's two-factor authentication SecurID tokens was accomplished via phishing e-mails and an exploit for a previously unpatched Adobe Flash hole, RSA has revealed.



Small, but some interesting twists (and lots of common themes)

http://www.phiprivacy.net/?p=6389

CT: MidState Medical Center informs 93,500 patients of data breach

By Dissent, April 5, 2011

Greg Bordonaro reports:

MidState Medical Center has begun sending letters to 93,500 patients whose personal information may have been compromised following the accidental loss of a computer hard drive, [unencrypted, of course Bob] the hospital said in a letter to employees Tuesday.

The misplaced hard drive, which has not yet been recovered, contains patient’s names, addresses, birthdates, social security numbers and medical record numbers, hospital spokeswoman Pamela Cretella said.

The hospital learned of the misplaced hard drive, which was lost by a Hartford Hospital employee, Feb. 15, Cretella said. The hospital conducted an investigation into the matter and began notifying patients in a letter sent today.

Cretella said the hospital has no reason to believe that any personal information found on the lost hard drive has been misused. But MidState is offering those who have been affected two years of identity protection with Debix Identity Protection Network.

A statement on the medical center’s web site dated April 5 says:

Important Notice to Patients Regarding Misplaced Personal Information

By MidState Staff

MERIDEN – On February 15, 2011, we learned that a hard drive containing personal information of some patients of MidState Medical Center had been misplaced. The information contained on the device consisted of names, addresses, dates of birth, marital status, Social Security numbers and medical record numbers. Not all of the patients being notified of the incident had Social Security numbers on the missing hard drive. We promptly began an investigation of the incident and subsequently reported the event to law enforcement authorities.

… MidState Medical Center and other affiliates of Hartford HealthCare are in the process of reviewing their policies and are taking steps to help ensure that this type of incident does not happen in the future [Encryption? Bob]

A companion FAQ on the breach, also on the medical center’s web site, has some interesting details (emphasis added by me):

… We promptly began an investigation and subsequently reported the event to law enforcement authorities. The individual is no longer employed by our business associate, Hartford Hospital, or any other Hartford HealthCare affiliate.

… We also retained a private investigator to search for the hard drive, but it has not been found. [What prompted this? Bob]



More of the same, with a few new tricks...

http://www.bespacific.com/mt/archives/026931.html

April 05, 2011

Symantec Internet Security Threat Report: Trends for 2010

Symantec Internet Security Threat Report Trends for 2010, Volume 16, Published April 2011

  • "Spam and phishing data is captured through a variety of sources, including the Symantec Probe Network, a system of more than 5 million decoy accounts; MessageLabs™ Intelligence, a respected source of data and analysis for messaging security issues, trends and statistics; as well as other Symantec technologies. Data is collected in more than 86 countries from around the globe. Over 8 billion email messages, as well as over 1 billion Web requests are processed per day across 16 data centers. Symantec also gathers phishing information through an extensive antifraud community of enterprises, security vendors, and more than 50 million consumers. These resources give Symantec’s analysts unparalleled sources of data with which to identify, analyze, and provide informed commentary on emerging trends in attacks, malicious code activity, phishing, and spam. The result is the Symantec Internet Security Threat Report, which gives enterprises and consumers the essential information to secure their systems effectively now and into the future."

  • "Symantec recorded over 3 billion malware attacks in 2010 and yet one stands out more than the rest - Stuxnet. This attack captured the attention of many and led to wild speculation on the target of the attacks and who was behind them...."

[From the report:

The ability to research a target online has enabled hackers to create powerful social engineering attacks that easily fool even sophisticated users.

… All these types of attacks are moving to mobile devices, limited only by attackers getting a return on their investment.

… Polymorphism and new delivery mechanisms such as Web-attack toolkits continued to drive up the number of malware variants in common circulation. In 2010, Symantec encountered more than 286 million unique variants of malware. [Security can not be done “manually.” Bob]



Italy again. Are they now the leading edge of “Luddite legislation?”

http://search.slashdot.org/story/11/04/05/2238227/Google-Loses-Autocomplete-Defamation-Case?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Google Loses Autocomplete Defamation Case

"Google has been found liable in an Italian court for defamatory comments made against an anonymous plaintiff — the complainant's name, when googled, elicited autocomplete suggestions that translate as 'con man' and 'fraud.' Google was found not to qualify for EU 'safe harbour' protection because the autocomplete suggestions were deemed to be Google's own creation, and not something merely passing through its systems."


(Related) Not to be left out of the “Luddite Legion”...

http://www.thetechherald.com/article.php/201114/7018/Street-View-slapped-by-Swiss-court-on-privacy-issue

Street View slapped by Swiss court on privacy issue

According to the Federal Administrative Court’s ruling of March 30, Google is not currently utilising sufficient protective processes to fully safeguard the identities of people (and the number plates of vehicles) inadvertently snapped by the fleet of Street View camera cars.

… As things stand, Google uses special algorithms to apply pixel blurring to the faces of any people (and vehicle number plates) caught by the multi-directional lenses of its Street View cameras. According to Google, its automatic blurring system is successful 99 percent of the time.

It’s also worth noting that any Swiss citizen that finds their face has slipped through the Street View security net can always have blurring applied upon request.

However, that clearly isn’t good enough for the Swiss court, which wants Google to manually seek out and blur the identifying features of anyone and everyone photographed by Street View—placing particular focus around “sensitive” locations such as courts, hospitals, prisons, retirement homes, schools and women’s shelters.



I may be only ¼ Dutch, but I can understand why they gave this the finger... After all, a leak is a leak.

http://www.phiprivacy.net/?p=6380

Dutch Senate rejects electronic patients’ records

By Dissent, April 5, 2011

Radio Netherlands Worldwide reports:

The Dutch Senate has unanimously rejected Health Minister Edith Schippers’ plan to introduce the Electronic Patient Dossier (EPD) nationwide.

Under the scheme, people’s medical records would have been available to doctors and other health professionals throughout the country. However, the senators decided that the planned system’s security was not good enough and that patients’ privacy and rights were not adequately safeguarded.

The EPD has been planned by successive governments over the last 14 years and has so far cost 300 million euros. [You would think that in 14 years, someone would have considered Security? Bob] Official figures show nearly 60 percent of healthcare professionals such as family doctors and pharmacies have voluntarily joined the scheme, which already holds the medical records of nearly 8.5 million Dutch residents.

So what’s the security like on those 8.5 million residents’ records? I wonder if people will be concerned enough by the Senate’s action to ask that their files not be part of the scheme any more.



Interesting, but I want to see it work.

http://www.pogowasright.org/?p=22245

Digital Agenda: new guidelines to address privacy concerns over use of smart tags

April 6, 2011 by Dissent

Today the European Commission has signed a voluntary agreement with industry, civil society, ENISA (European Network and Information Security Agency) and privacy and data protection watchdogs in Europe to establish guidelines for all companies in Europe to address the data protection implications of smart tags (Radio Frequency Identification Devices – RFID) prior to placing them on the market. The use of such smart tags is expanding enormously (around 1 billion in Europe in 2011) [so this is not really “ahead of the curve” Bob] but there are widespread concerns about their privacy implications. RFIDs can be found in many objects from bus passes to smart cards that pay motorway tolls. Microelectronic devices can process data automatically from RFID tags when brought close to ‘readers’ that activate them, pick up their radio signal and exchange data with them. Today’s agreement forms part of the implementation of a Commission Recommendation adopted in 2009 (see IP/09/740) that inter alia indicates that when consumers buy products with smart tags, they should be deactivated automatically, immediately and free-of-charge unless the consumer agrees explicitly that they are not.

Neelie Kroes, European Commission Vice-President for the Digital Agenda said “I warmly welcome today’s milestone agreement to put consumers’ privacy at the centre of smart tag technology and to make sure privacy concerns are addressed before products are placed on the market. I’m pleased that industry is working with consumers, privacy watchdogs and others to address legitimate concerns over data privacy and security related to the use of these smart tags. This sets a good example for other industries and technologies to address privacy concerns in Europe in a practical way.”

The agreement signed today, “Privacy and Data Protection Impact Assessment (PIA) Framework for RFID Applications”, aims to ensure consumers’ privacy before RFID tags are introduced on a massive scale (see IP/09/952). Around 2.8 billion smart tags are predicted to be sold in 2011, with about one third of these in Europe. But industry estimates that there could be up to 50 billion connected electronic devices by 2020.

RFID tags in devices such as mobile phones, computers, fridges, e-books and cars bring many potential advantages for businesses, public services and consumer products. Examples include improving product reliability, energy efficiency and recycling processes, paying road tolls without having to stop at toll booths, cutting time spent waiting for luggage at the airport and lowering the environmental footprint of products and services.

However RFID tags also raise potential privacy, security and data protection risks. This includes the possibility of a third party accessing your personal data (e.g. concerning your location) without your permission.

For example, many drivers pay tolls electronically to use roads, airport and car parks based on data collected through RFID tags on their car windscreens. Unless preventative action is taken, RFID readers found outside those specific locations could unwittingly lead to privacy leaks revealing the location of the vehicle. Many hospitals use RFID tags to track inventory and identify patients. While this technology can improve the overall quality of healthcare, the benefits must be balanced with privacy and security concerns.

Comprehensive assessment of privacy risks

Under the agreement, companies will carry out a comprehensive assessment of privacy risks [sure they will Bob] and take measures to address the risks identified before a new smart tag application is introduced onto the market. This will include the potential impact on privacy of links between the data collected and transmitted and other data. This is particularly important in the case of sensitive personal data such as biometric, health or identity data.

The PIA Framework establishes for the first time in Europe a clear methodology to assess and mitigate the privacy risks of smart tags that can be applied by all industry sectors that use smart tags (for example, transport, logistics, the retail trade, ticketing, security and health care).

In particular, the PIA framework will not only give companies legal certainty that the use of their tags is compatible with European privacy legislation but also offer better protection for European citizens and consumers.

Background

In May 2009 all interested stakeholders from industry, standardisation bodies, consumers’ organisations, civil society groups, and trade unions, agreed to respect a Recommendation from the European Commission laying out principles for privacy and data protection in the use of smart tags (see IP/09/740). Today’s PIA Framework is part of the implementation of the 2009 Recommendation. Information gathered during the PIA framework drafting process will also make a valuable contribution to discussions on the revision of EU rules on Data Protection (see IP/10/1462 and MEMO/10/542) and on how to address the new challenges for personal data protection brought by technological developments.

For more information:

SPEECH/11/236 Link to the PIA framework Digital Agenda website: http://ec.europa.eu/information_society/digital-agenda/index_en.htm

Neelie Kroes’ website: http://ec.europa.eu/commission_2010-2014/kroes/

Source: Press Release from Europa.eu



So, delegate already!

http://politics.slashdot.org/story/11/04/05/2140251/House-Votes-To-Overturn-FCC-On-Net-Neutrality?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

House Votes To Overturn FCC On Net Neutrality

"House Republicans voted unanimously today to block controversial Net neutrality regulations from taking effect, a move that is likely to invite a confrontation with President Obama. By a vote of 241 to 178, the House of Representatives adopted a one-page resolution that says, simply, the regulations adopted by the Federal Communications Commission on December 21 'shall have no force or effect.' 'Congress did not authorize the FCC to regulate in this area,' Rep. Rob Woodall (R-Ga.), said during this morning's floor debate. 'We must reject any rules that it promulgates in this area... It is Congress' responsibility to delegate that authority.'"



This is nothing new, surely?

http://yro.slashdot.org/story/11/04/05/2129250/Key-Music-Industry-Lawyer-Named-EU-Copyright-Chief?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Key Music Industry Lawyer Named EU Copyright Chief

"The European Union's new point person on copyright policy won't take up her post until mid-April, but she's already stirring up controversy. That's because Maria Martin-Prat spent years directing 'global legal policy' for IFPI, the global recording industry's London-based trade group, before moving back into government. The appointment raises new questions about the past private-sector work of government officials, especially those crafting policy or issuing legal judgments on the same issues they once lobbied for."



This fits with our increasing “work from home” (online and hybrid classes) at the university.

http://ask.slashdot.org/story/11/04/05/2015200/Ask-Slashdot-Would-You-Take-a-Pay-Cut-To-Telecommute?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Ask Slashdot: Would You Take a Pay Cut To Telecommute?

"IT pros want to telecommute — so much so that more than one-third of those surveyed by Dice.com said they would take a pay cut for the chance to work full time from home. In a survey conducted by the careers site, 35% of technology professionals said they would sacrifice up to 10% of their salaries for full-time telecommuting. The average tech pro was paid $79,384 last year, according to Dice's annual salary survey, which means a 10% pay cut is equivalent to $7,900 on average."



It's a geek thing, we're not really going to carry our PC around to make phone calls...

http://techcrunch.com/2011/04/05/want-to-run-android-apps-on-your-windows-pc-you-can-with-bluestacks/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

Want To Run Android Apps On Your Windows PC? You Can With BlueStacks.

There’s nothing new about virtualization software, per se, but BlueStacks might be worth checking out. It brings the Android operating system to Windows-based computers via a virtualization layer, much like how you can run Windows “inside” your Mac using Parallels. Why, exactly, you’d want to run Android “inside” your Windows PC, I’m not exactly sure, but there’s nothing inherently wrong with giving it a go.


Tuesday, April 05, 2011

Another third party breach...

http://www.databreaches.net/?p=17406

Breach of S&D Coffee web site results in notifications to customers

April 4, 2011 by admin

S&D Coffee recently notified the New Hampshire Attorney General’s Office that a security breach involving its online e-commerce site resulted in the compromise of customers’ names, addresses, email addresses, and credit card numbers.

The site is hosted by E-Dreamz, who discovered the breach on February 7 and notified S&D Coffee.

The coffee retailed indicated that it would be sending notifications to affected customers by March 25.



“Breach disclosure” laws do not ensure you will know how often (or even IF) your information was compromised.

http://news.cnet.com/8301-31021_3-20050555-260.html

Were you affected by Epsilon data breach?

The company said Monday that 2 percent of the companies it counts as clients are affected by the security breach. There is no official list of affected companies that's available, and a company spokesperson said Epsilon cannot release the names of its clients. Epsilon is in the midst of conducting an investigation of what led to the security breach.

The list of Epsilon clients whose customer e-mail addresses were stolen is not complete, and is likely to grow. But so far Target, Kroger, TiVo, US Bank, JPMorgan Chase, Capital One, Citi, Home Shopping Network, Ameriprise Financial, LL Bean Visa Card, McKinsey & Company, Ritz-Carlton Rewards, Marriott Rewards, New York & Company, Brookstone, Walgreens, The College Board, Disney Destinations, and Best Buy have notified their own customers about the breach. Hilton Hotels and Ethan Allen are also said to be affected.

… You can forward suspected phishing e-mails to reportphishing@antiphishing.org and spam@uce.gov.



Spear Phishing for whales. Another way outsourcing (third parties) make you vulnerable. Strange they didn't have a procedure in place to confirm changes to vendor payment addresses.

http://www.wired.com/threatlevel/2011/04/condenast-hooked-by-spear-phisher/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

Condé Nast Got Hooked in $8 Million Spear-Phishing Scam

A spear phisher managed to reel in a prize catch last year with a single hook when media giant Condé Nast took the bait and wired $8 million to his bank account after he posed as a legitimate business, according to a news account.

The alleged swindler failed to withdraw any funds before federal authorities intervened and froze the money, but the case highlights how little effort a scammer needs to invest in order to get a big payday.

… Information about the scam appeared in a forfeiture lawsuit filed March 30 in Manhattan by the U.S. Attorney’s office for the Southern District of New York in an attempt to retrieve the money for Condé Nast. It was first reported by Forbes.

The filing seeks the funds for forfeiture on grounds that they are allegedly proceeds from wire fraud and money laundering crimes.

According to the court document, last November Condé Nast’s accounts payable department received an e-mail (.pdf) that purported to come from Quad/Graphics, the company that prints Condé Nast magazines.

The e-mail instructed Condé Nast to send payments for its Quad/Graphics account to a bank account number provided in the e-mail, and included an electronic payments authorization form. The e-mail indicated the account was for Quad Graph, a name similar to the real printer’s name.

Someone at Condé Nast apparently signed the form and sent it back to a fax number listed in the e-mail, then began making electronic transfer payments to the bank account specified by the scammer.

Between Nov. 17 and Dec. 30, the company wired $8 million to the Quad Graph account before a query around Dec. 30 from the real printer, Quad/Graphics, asking about outstanding bills, prompted Condé Nast to investigate the matter. The company was apparently able to reverse at least one transfer of about $36,000 back to its JPMorgan Chase account, though the court document doesn’t indicate when that occurred.



For my Computer Security students. I hope this is just bad reporting, but taking the story at face value, Army computer security sucks! I can't install software on my classroom computers without involving someone from tech support. I guess the Army doesn't bother with security on their computers...

http://www.wired.com/threatlevel/2011/04/manning-data-mining/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

Army: Manning Snuck ‘Data-Mining’ Software Onto Secret Network

Accused WikiLeaks source Pfc. Bradley Manning installed and used unauthorized “data-mining software” on his SIPRnet workstation during the time he allegedly siphoned hundreds of thousands of documents off that classified network, the Army said Friday in response to inquiries from Threat Level.

Manning’s use of unauthorized software was the basis of two allegations filed against him this year in his pending court martial, but the charge sheet listing those allegations was silent on the nature of that software.

On Friday, an Army spokeswoman clarified the charges. “The allegations … refer to data-mining software,” spokeswoman Shaunteh Kelly wrote in an e-mail. “Identifying at this point the specific software program used may potentially compromise the ongoing criminal investigation.” [I just renamed my “Steal_Stuff” program to “Mandatory_Security” That should fool them. Bob]

… Manning allegedly installed the software twice

… the first time between Feb. 11, 2010 and April 3, 2010. [Either the Army's computer logs don't have dates or they don't bother to log program installations and they are just guessing. Bob] The second time was around May 4, the day he was demoted from Specialist to Private First Class and given a new job assignment following an altercation with another soldier.

… Christie said that prosecutors wouldn’t have to show definitive evidence that the software was used to obtain or sort the purloined documents; just the fact that it was installed on Manning’s computer during the time the documents were taken would allow prosecutors to draw reasonable inferences that it was used to commit the crime. [Would they also have to prove that Manning installed it? Bob]



A step toward globalization?

http://www.pogowasright.org/?p=22219

European Privacy Law Comes to America Via FTC’s Google Order

April 4, 2011 by Dissent

Nathan Newman writes:

This probably will give the Tea Party types a heart attack but European privacy law has come to America via the FTC order last week.

One key part of the order imposed on Google was the FTC’s press statement that:

this is the first time the FTC has alleged violations of the substantive privacy requirements of the U.S.-EU Safe Harbor Framework, which provides a method for U.S. companies to transfer personal data lawfully from the European Union to the United States.

What makes this significant is that for Internet companies operating globally, including in Europe — and that means almost all the major companies — the FTC has established the precedent of applying European Union principles on privacy via the U.S.-EU Safe Harbor Framework.

Read more on Huffington Post.



I suspect they believe hackers will not stop at the public information on a Facebook page, but will eventually hack into the private stuff and reveal some embarrassing information about the candidates or the party. Or maybe they are just looking for nude pictures of the candidates...

http://www.pogowasright.org/?p=22232

Log-in demand crosses line

April 5, 2011 by Dissent

David Canton writes:

It [sic] not unusual for employers to conduct Google searches on prospective employees or check their public social media feeds. But prospective employer’s requests for job applicants’ social media log-in IDs and passwords crosses the line.

Unfortunately, some people have felt no choice but to comply given the unequal bargaining power between the parties and their need to obtain or keep a job.

The British Columbia New Democratic Party has required candidates to reveal their social media IDs and passwords so the party can search for potentially embarrassing material. So far, all the candidates have apparently complied, except for one.

Read more on Canoe.



What you can say vs. what you can text?

http://www.bespacific.com/mt/archives/026913.html

April 04, 2011

"Regardless of Frontiers:" The International Right to Freedom of Expression in the Digital Age

Via CDT, "Regardless of Frontiers:" The International Right to Freedom of Expression in the Digital Age: "The purpose of this report is to explore how the internationally recognized right to freedom of expression should apply to the Internet. This report is intended to spark further research, discussion, and action. The Internet offers individuals around the world the potential to seek, receive, and impart information and ideas in unprecedented ways. Like no medium before it, the Internet can empower citizens to communicate instantaneously with others in their own communities and worldwide, at low cost relative to traditional forms of media. The Internetʼs unique attributes create new opportunities to collaborate, exchange ideas, and promote scientific, cultural, and economic progress. Producers of traditional forms of media also can use the Internet to greatly expand their audiences at nominal cost. Like no other technology, the Internet can transcend national borders and eliminate barriers to the free flow of information. These unique features of the Internet, if properly supported, can foster innovation, economic growth, democratic participation, and human development."



Technology redefining the law?

http://www.bespacific.com/mt/archives/026919.html

April 04, 2011

Article: Disclosure’s Effects: Wikileaks and Transparency

Disclosure’s Effects: Wikileaks and Transparency, Mark Fenster University of Florida - Fredric G. Levin College of Law

  • "Constitutional, criminal, and administrative laws regulating government transparency, and the theories that support them, rest on the assumption that the disclosure of information has transformative effects: disclosure can inform, enlighten, and energize the public, or it can create great harm or stymie government operations. To resolve disputes over difficult cases, transparency laws and theories typically balance disclosure’s beneficial effects against its harmful ones. WikiLeaks and its vigilante approach to massive document leaks challenge the underlying assumption about disclosure’s effects in two ways. First, WikiLeaks’s ability to receive and distribute leaked information cheaply, quickly, and seemingly unstoppably enables it to bypass the legal framework that would otherwise allow courts and officials to consider and balance disclosures’ effects. For this reason, WikiLeaks threatens to make transparency’s balance irrelevant. Second, its recent massive disclosures of U.S. military and diplomatic documents allow us to reconsider and test the assumption that disclosure produces effects that can serve as the basis for judicial and administrative prediction, calculation, and balancing. For this reason, WikiLeaks threatens transparency’s balance by disproving its assumption that disclosure necessarily has predictable, identifiable consequences that can be estimated ex ante or even ex post. This article studies WikiLeaks in order to question and evaluate prevailing laws and theories of transparency that build on the assumption that disclosure’s effects are predictable, calculable, and capable of serving as the basis for adjudicating difficult cases. Tracing WikiLeaks’s development, operations, theories, and effects, it demonstrates the incoherence and conceptual poverty of an effects model for evaluating and understanding transparency."


(Related) Technology redefining Economics?

http://www.bespacific.com/mt/archives/026914.html

April 04, 2011

Transcript: “Buying & Selling EContent'

Interview with Jim Jansen, Senior Fellow, Pew Internet & American Life Project, Recorded at “Buying & Selling EContent” Conference, For podcast release Tuesday, April 5, 2011

  • "..the ability to buy digital content online is critically important to a lot of people, a lot of businesses, a lot of artists, photographers, a whole gamut of people. So we were very interested in that aspect of this technology and whether consumers were willing to put out their money to buy this stuff... Certainly, the most common products purchased are music and software. However, games and information from articles and stuff are also purchased quite frequently. The average spend was about $47 in a given month, although the typical user spent $10 to $15."



Perhaps they should arrest FBI agents who break the law?

http://www.pogowasright.org/?p=22213

Watchdogs say Oakland, SF police should shun FBI

April 4, 2011 by Dissent

Civil rights watchdog groups say police in Oakland, San Francisco and other cities should stop working with the FBI on terrorism investigations so long as doing so means they can violate local privacy policies.

“Under the state constitution and local policies, Californians are protected against government intelligence gathering unless there is a factual basis to suspect them of wrongdoing,” Alan Schlosser, the American Civil Liberties Union of Northern California’s legal director, said in a news release today. “It is now clear that the FBI has been authorized to conduct thousands of investigations that are just fishing expeditions and run contrary to California law. It is an outrage that San Francisco and Oakland police officials are not being forthcoming about whether their JTTF (Joint Terrorism Task Force) officers are complying with state and local law.”

Read more on InsideBayArea.com



Should be amusing to see how this works...

http://search.slashdot.org/story/11/04/05/0349235/Yahoo-Liable-In-Italy-For-Searchable-Content?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Yahoo! Liable In Italy For Searchable Content

"A recent decision of an Italian court could spark considerable discussion over the liability of a search engines. The court actually ordered Yahoo! to remove any link to any site containing unlawful copies of a movie. Under EU Directives 2003/31, liability of search engines is not regulated (save for caching activities). In the case brought to court regarding the film About Elly, it was not the caching activities of Yahoo! that were questioned (or any content hosted on Yahoo!'s servers), but the mere fact that searching for the film made it possible to reach websites allowing the streaming or downloading of the movie (actually, illegal sites got a better ranking then the official one)."



Law vs. Economics

http://yro.slashdot.org/story/11/04/04/1851235/Piracy-Is-a-Market-Failure-mdash-Not-a-Legal-One?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Piracy Is a Market Failure — Not a Legal One

"Michael Geist, Canada's copyright law guru and law prof at the University of Ottawa, posted an interesting observation about the copyright issue of piracy. Canada's International Development Research Centre came to a conclusion that 'piracy is chiefly a product of a market failure, not a legal one' after a multi-year study of six relevant economies. 'Even in those jurisdictions where there are legal distribution channels, pricing renders many products unaffordable for the vast majority of the population. Foreign rights holders are often more concerned with preserving high prices in developed countries, rather than actively trying to engage the local population with reasonably-priced access. These strategies may maximize profits globally, but they also serve to facilitate pirate markets in many developed countries.'"



For my technology geeks, a most interesting video.

http://www.wired.com/gadgetlab/2011/04/predator-smart-camera-locks-on-tracks-anything-mercilessly/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

‘Predator’ Smart Camera Locks Onto, Tracks Anything … Mercilessly

Zdenek Kalal’s Predator object-tracking software is almost uncanny. Show anything to its all-seeing camera eye, and it will quickly learn to recognize it and then track it, whether it fades into the distance, hides amongst other similar objects or — in the case of faces turns sideways.

It really lives up to its name, reminding us of the Predator’s HUD-enhanced vision in the movie of the same name.

Kalal is a Ph.D. student at the University of Surrey in England, researching projects that make computers see. His Predator algorithm is both fast and powerful.



Interesting business model, wouldn't you say? Ad supported Electronic Health Records and Doctors keep the $44,000 stimulus payment

http://techcrunch.com/2011/04/05/free-electronic-medical-records-service-practice-fusion-raises-23-million/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

Free Electronic Medical Records Service Practice Fusion Raises $23 Million

Launched in 2007, Practice Fusion allows doctors across the country to chart patient visits, review records, schedule appointments, prescribe medications electronically, order and receive lab tests, and connect patients to their health data — all in realtime. Unlike legacy electronic medical records systems that charged doctors exorbitant fees, Practice Fusion’s web-based system is free to health care providers and lives in the cloud.

Offering a free digital system is fairly unprecedented and, at first blush, would seem financially unsound, but Practice Fusion was initially able to stay in the black through rapid product development, word-of-mouth buzz among doctors, and the $44,000 economic stimulus incentive program rolled out by the Obama Administration in 2009. Since then, it has been able to rely on venture capital and has brought more than 70,000 health care providers into its community, allowing for triple-digit annual growth among its users, according to communications director Helen Phung.

As many are aware, the state of American healthcare systems remains atrocious, and the medical industry has struggled to incorporate technology into the management of the healthcare process. Sure, we may have cutting-edge devices in our ERs, but when it comes to IT and medical records, the U.S. healthcare industry might as well be in the Stone Age.

… For more on Practice Fusion, check out the video http://www.youtube.com/watch?v=pVYdPcqlSf8&feature=player_embedded#at=86



I like lists. (Someone else digging out the details so I don't have to) But this one isn't easy to use, sorry. Maybe there will be more detail after the judging...

http://eu.techcrunch.com/2011/04/05/techcrunch-europe-and-the-telegraph-release-the-startup100/

TechCrunch Europe and The Telegraph release the Startup100

Last December we agreed to link up with the London Telegraph newspaper, which planned to put some time and resources into a ranking of promising technology companies in Europe. The Telegraph Tech Start-Up 100 lists 100 top European tech companies.



As I get older, my friends send me this kind of stuff more and more (too) often...

"SENIORS TEXTING CODE"

ATD = ..At The Doctors.

BFF = ..Best Friend Fell.

BTW = ..Bring the Wheelchair.

BYOT = ..Bring Your Own Teeth.

FWIW = ..Forgot Where I Was.

GGPBL = ..Gotta Go, Pacemaker Battery Low.

GHA = ..Got Heartburn Again.

IMHO = ..Is My Hearing-Aid On.

LMDO = ..Laughing My Dentures Out.

OMMR = ..On My Massage Recliner.

OMSG = ..Oh My! Sorry, Gas.

ROFLACGU = ....Rolling On Floor Laughing And Can't Get Up.

TTYL = ..Talk To You Louder."


Monday, April 04, 2011

This may become the largest breach ever, measured by the number of individuals impacted...

http://www.databreaches.net/?p=17374

And the hits just keep on coming for Epsilon

April 3, 2011 by admin

I think I’ll just use this blog entry to add further updates/entities to the Epsilon breach, so check back if you want to see what else has been reported. Here’s the current list, below. Links to documentation are in previous blog posts if not provided here:

Kroger
JPMorgan Chase
Capital One
Citi
New York & Company
US Bank
Barclays Bank of Delaware (and Barclay’s L.L. Bean Visa card)
Brookstone
McKinsey Quarterly
TiVo
College Board
Walgreens
Ameriprise
Marriott Rewards
Ritz-Carlton Rewards
Disney Destinations (The Walt Disney Travel Company)
Benefit Cosmetics (see below)
Home Shoppers Network (HSN)
AbeBook

Best Buy
Best Buy Canada Reward Zone

Benefit Cosmetics. What’s significant about their report is that they appear to be former of Epsilon, raising the question of why their data were on the compromised server. Did the clients breach occur while they were still clients or did Epsilon not remove their data from their server after they stopped using their service?

An email sent to DataLossDB who shared it with this site, read:

While we wish this was about lipstick, we have important news regarding your email address.

We were just informed by a former email vendor that the database with our customers’ names and email addresses has been compromised by an unauthorized person. The only information at risk is your name and email address.

The vendor has assured us that “a rigorous assessment determined that no other personal identifiable information associated with those names was at risk. A full investigation is currently underway.” This data breach has also affected several other companies that work with this vendor.


(Related)

http://www.databreaches.net/?p=17261

A Rash of Third-Party Data Breaches Takes a Toll on Businesses and Customers

April 3, 2011 by admin

Last month I reported that both Play.com and Maine’s Dept. of Conservation had been hit by breaches at their third-party vendors. Game Show Network (GSN) customers were also notified of a breach at a third-party vendor, but I didn’t report it at the time because I was trying to get confirmation from the company whether the breach was due to a compromise involving ExactTarget – the same vendor that may have been involved in a TripAdvisor.com breach that was also reported recently. Although original media reports suggested that the TripAdvisor.com breach might have been due to an SQL injection, some other reports suggest otherwise.

A GSN spokesperson tells DataBreaches.net:

Yes, unauthorized access occurred to our email lists that led to fraudulent emails being sent to many of our players. We’re taking this matter very seriously and we are working with law enforcement to investigate the matter. We have identified the source and scope of the compromise and have been in touch with our players who clicked on the link in the fraudulent email. It’s important to note that no email lists were stolen, nor was any of our players’ personal information (credit card information, addresses, passwords, etc.) accessed or stolen. While opening the email message will not damage a recipient’s computer, we advised those players that if they entered personal information, made a purchase, or downloaded a file, they should contact their credit card company and run a virus scan as a safety precaution.

The spokesperson would not say whether the breach was at ExactTarget and they declined to indicate how many of their customers were affected. Other evidence, however, in the form of email headers sent to DataBreaches.net and posted to online forums suggest that the GSN breach was due to a breach at ExactTarget.

ExactTarget did not respond to requests for a statement. Nor did ProFlowers.com, another client of theirs who had at least one customer receive a phishing attempt sent to a unique email address he only used for their mailing list. If ExactTarget was breached, it is somewhat surprising that we have not seen a lot of press releases from their clients who needed to notify customers.

Elsewhere, Fahmida Y. Rashid of eWeek reported:

Three recent data breaches at third-party Web service providers highlight the importance of organizations making sure customer data outside of the company is protected.

[...]

There have been other data breaches at third-party providers recently. Play.com, an online seller of CDs, DVDs, books and apparel, notified customers on March 23 that its third-party marketing company’s database had been breached. CEO John Perkins told customers via Play.com’s Facebook page that the email marketing company is Silverpop, which was attacked a few months ago.

[...]

The agency claims none of the Play.com email addresses was affected by that episode, according to Perkins. It is not clear at this time whether email addresses and names were stolen during that attack, or if attackers got into Silverpop again more recently.

With respect to that last point, Tom Espiner of ZDNet writes:

Silverpop told ZDNet UK on Tuesday that it had suffered a breach in the autumn of 2010, but did not believe that this was affecting Play.com customers.

“While we are reviewing all possibilities, it’s difficult for us to directly connect the 2010 incident with specific spam messages sent this year,” said Silverpop spokeswoman Stacy Kirk.

Rashid also reported:

Users on Game Show Network forums reported receiving similar fake Adobe Acrobat/Reader spam on March 20. An examination of the email headers revealed the messages were being sent from GSN’s marketing company, ExactTarget. TripAdvisor has been an ExactTarget client since 2008, according to the company’s previous announcements.

Brian Krebs originally broke the story about these spear phishing attacks back in November, and provided an update in December.

Are the recent rash of breaches the results of November attacks, or do they represent a newer rash of attacks as cybercriminals recognize how easy it may be to gain access to huge databases of email addresses?

And of course, now there’s the Epsilon breach.

With so many obvious compromises, isn’t it time for companies to be a bit more transparent about whether their customers’ email addresses have been acquired, and if so, who was the vendor involved?

At times like these, I’m really glad I use disposable or self-expiring email addresses when I sign up for some things.



About time! We're going to need Best Practices as Everyone starts using Social Media to communicate with customers and employees...

http://www.bespacific.com/mt/archives/026911.html

April 03, 2011

Best Practices Study of Social Media Records Policies

Best Practices Study of Social Media Records Policies, ACT-IAC Collaboration & Transformation (C&T) Shared Interest Group (SIG), March 2011

  • "Government agencies are increasingly incorporating Web 2.0 collaborative technologies, also known as social media, such as wikis and blogs, in conducting agency business. Federal recordkeeping requirements include developing and implementing policies for Federal records and cover records from social media.

  • The purpose of this study is to build a discussion around the use of social media to help government and its citizens connect more closely, collaboratively, and openly. The study involved interviews at 10 agencies regarding records management processes addressing the use of social media. The ACT-IAC Collaboration & Transformation Shared Interest Group (C&T SIG) sought to explore and identify government best practices of records policies for social media used to support agency missions. The team found that active use of social media tools has identified some challenges for recordkeeping, but also has allowed some best practices to surface which agencies are following or need to follow to address the challenges."


(Related) I must assume that all social network communications and probably all SMS (Short Message Service) texts would fall under CAN-SPAM as well.

http://www.pogowasright.org/?p=22203

CAN-SPAM Held to Apply to Social Media Messaging

April 3, 2011 by Dissent

Timothy Tobin writes:

On March 28, 2011, the U.S. District Court for the Northern District of California held, in Facebook, Inc. v. MAXBOUNTY, Inc., case no. CV-10-4712-JF, that messages sent by Facebook users to their Facebook friends’ walls, news feeds or home pages are “electronic mail messages” under the CAN-SPAM Act. The court, in denying the defendant MAXBOUNTY’s motion to dismiss, rejected that CAN-SPAM applies only to traditional e-mail as it is commonly understood. The ruling is the most expansive judicial interpretations to date of the types of messages falling within the purview of the CAN-SPAM Act. The court did not reach or otherwise address the underlying merits of the CAN-SPAM claims.

Read more on Hogan Lovells Chronicle of Data Protection.



A guide for the technically naive (ignorant)

http://www.pogowasright.org/?p=22198

States Attempt to Address Privacy Risks Associated with Digital Copiers and Electronic Waste

April 3, 2011 by Dissent

On April 1, 2011, a New York law went in effect requiring retailers of certain electronic equipment to institute electronic waste collection programs and to provide information to consumers on how to “destroy all data on any electronic waste, either through physical destruction of the hard drive or through data wiping.” Manufacturers of devices that have hard drives capable of storing personal information or other confidential data must include instructions describing how consumers can destroy such data before recycling or disposing of the devices, and businesses that sell products with hard drives must inform customers at the point of sale where the data destruction information can be located.

Read more on Hunton & Williams Privacy and Information Security Law Blog.



A “How to” guide for Google?

http://www.bespacific.com/mt/archives/026909.html

April 03, 2011

A Guide For the Perplexed Part IV: The Rejection of the Google Books Settlement

A Guide For the Perplexed Part IV: The Rejection of the Google Books Settlement, by Jonathan Band

  • "On March 22, 2011, Judge Denny Chin rejected the proposed settlement in copyright infringement litigation over the Google Library Project. Judge Chin found that the settlement was not “fair, reasonable, and adequate” as required by the Federal Rules of Civil Procedure. Judge Chin issued the decision over a year after the fairness hearing he conducted. His opinion agrees in large measure with the objections to the settlement asserted by the U.S. Department of Justice at the hearing and in its written submissions. This paper discusses the opinion and where it leaves Google Books Search."



I see this as the future of Scientific Journals. Other journals (e.g. Law) as well.

http://www.bespacific.com/mt/archives/026910.html

April 03, 2011

Open access, readership, citations: a randomized controlled trial of scientific journal publishing

Open access, readership, citations: a randomized controlled trial of scientific journal publishing, Philip M. Davis, Department of Communication, Cornell University, Ithaca, New York

  • "Does free access to journal articles result in greater diffusion of scientific knowledge? Using a randomized controlled trial of open access publishing, involving 36 participating journals in the sciences, social sciences, and humanities, we report on the effects of free access on article downloads and citations. Articles placed in the open access condition (n=712) received significantly more downloads and reached a broader audience within the first year, yet were cited no more frequently, nor earlier, than subscription-access control articles (n=2533) within 3 yr. These results may be explained by social stratification, a process that concentrates scientific authors at a small number of elite research universities with excellent access to the scientific literature. The real beneficiaries of open access publishing may not be the research community but communities of practice that consume, but rarely contribute to, the corpus of literature." FASEB J. 25, 000–000 (2011).


Sunday, April 03, 2011

A third party breach is similar to what we would expect from a Cloud Computing provider breach. I would expect lots of Phishing emails, if I gave my email address to these clients. I deal with several, but very few have anything but a disposable email address.

http://www.securityweek.com/massive-breach-epsilon-compromises-customer-lists-major-brands

Massive Breach at Epsilon Compromises Customer Lists of Major Brands

Due to the growing list of brands disclosing that they have been compromised as a result of this breach, I’m going to go ahead and tag this as a massive breach. And I only expect it to get bigger as more announcements come out from Epsilon customers.

… Epsilon sends over 40 billion emails annually and counts over 2,500 clients, including 7 of the Fortune 10 to build and host their customer databases.

SecurityWeek has been able to confirm that the customer names and email addresses, and in a few cases other pieces of information, were compromised at several major brands including the following:

• TiVo

• Marriott Rewards

• Ritz-Carlton Rewards

• US Bank

• JPMorgan Chase

• Capital One

• Citi

• McKinsey & Company

• New York & Company

• Brookstone

• Kroger

• Walgreens (Again!)

Some may dismiss the type of data harvested as a minor threat, but having access to customer lists opens the opportunity for targeted phishing attacks to customers who expect communications from these brands. Being able to send a targeted phishing message to a bank customer and personally address them by name will certainly result in a much higher “hit rate” than a typical “blind” spamming campaign would yield. So having access to this information will just help phishing attacks achieve a higher success rate.

… As the initial disclosure by Epsilon occurred late in the day on Friday, [Slow news day... Bob] I expect several more brands to be announcing that they’ve been affected by the breach as well. When asked to comment, Epsilon has refused to provide additional details on what other brands may have been affected.


(Related) Clearly not every client is on the list above...

http://www.databreaches.net/?p=17335

The College Board makes notifications after the Epsilon breach



I can see the Defender of Rights in a mask and cape...

http://www.pogowasright.org/?p=22184

French Data Protection Act Amended

April 2, 2011 by Dissent

A new French law containing several key amendments to the French Data Protection Act and creating a new public authority referred to as the “Defender of Rights” (Loi n°2011-334 du 29 mars 2011 relative au Défenseur des droits, or the “Law”) came into effect on March 30, 2011. The Defender of Rights, whose role is to defend civil rights and liberties, to promote children’s rights and to fight against discrimination, also will serve as a member of the CNIL’s plenary committee.

Read more on Hunton & Williams Privacy and Information Security Law Blog.



The music industry never liked the idea that you might create a backup copy of your music (rather than buy another copy) Have they have convinced someone independent or is this another “industry controlled” organization?

http://entertainment.slashdot.org/story/11/04/02/1625241/CD-Ripper-Incites-Law-Breaking-Says-British-Regulator?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

CD Ripper 'Incites Law Breaking,' Says British Regulator

"A British firm has been banned from advertising a CD ripping device because it 'incites law breaking.' The Brennan JB7 is 'a CD player with a hard disk that stores up to 5,000 CDs.' The adverts for the Brennan highlight the convenience of ripping your entire CD collection to the device – much like we've all been doing for years on our PCs, iPods and other MP3 players. The Advertising Standards Authority has banned the ads after concluding 'that the ad misleadingly implied it was acceptable to copy CDs, vinyl and cassettes without the permission of the copyright owner.'"



Justice goes Hollywood! Court TV now Court YouTube.

http://www.bespacific.com/mt/archives/026900.html

April 02, 2011

US Court of Appeals - 9th Circuit YouTube Channel

"This is the official YouTube Channel for the US Court of Appeals for the Ninth Circuit. In addition to these video recordings, you may find audio recordings of our hearings on our internet site at http://www.ca9.uscourts.gov."



How large a share of the market will it take to keep RIM from bankruptcy?

http://mobile.slashdot.org/story/11/04/02/2159217/Android-Passes-BlackBerry-In-US-Market-Share?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Android Passes BlackBerry In US Market Share

"69.5 million people in the US owned smartphones during the three months ending in February 2011, up 13 percent from the preceding three-month period. For the first time, more Americans are using phones running Google's Android operating system than Research In Motion's BlackBerry, according to comScore. Having passed the iPhone in the preceding three-month period, this now means that Android has been crowned king in the US."



For my Intro to IT students

http://graphic.is/videos/how-large-is-a-petabyte/

How Large Is a Petabyte

A Petabyte is equivalent to:

1024 Terabytes,

1,048,576 Gigabytes,

1,073,741,824 Megabytes,

1,099,511,627,776 Kilobytes,

1,125,899,906,842,624 Bytes,

9,007,199,254,740,992 Bits.

As a rough guide, you can fit 0.00002 Petabytes (or 25 Gigabytes) on a single-layer Blu-ray disc, 0.000048 Petabytes (or 50 Gigabytes) on a dual-layer Blu-ray disc, 0.000004 PetaBytes (or 4.7 Gigabytes) of information on a full size (12cm) DVD and 0.0000005 Petabytes (or 0.7 GigaBytes) of information on a standard (12cm) CD.

[Or, looked at from the other direction:

There are 8 Bits in a Byte, 1024 Bytes in a Kilobyte (KB), 1024 KiloBytes in a MegaByte (MB), 1024 MegaBytes in a GigaByte (GB), 1024 GigaBytes in a TeraByte (TB), 1024 TeraBytes in a PetaByte, 1024 PetaBytes in an ExaByte, 1024 ExaBytes in a ZettaByte and 1024 ZettaBytes in a YottaByte.



An interesting InfoGraphic for my Ethical Hackers...

http://www.smashingapps.com/2011/04/02/current-state-of-freedom-on-the-internet-infographic.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+SmashingApps+%28Smashing+Apps%29

Current State Of Freedom On The Internet (Infographic)