Tuesday, April 12, 2011

Smaller that Epsilon, but still clear that things are bigger in Texas!

http://www.databreaches.net/?p=17709

Texas comptroller’s office data breach exposes 3.5 million teachers’ and employees’ Social Security numbers and other personal information

April 11, 2011 by admin

Kelley Shannon reports:

Texas Comptroller Susan Combs revealed Monday that the personal information of 3.5 million people has been inadvertently disclosed by her agency, making Social Security numbers, dates of birth and other data accessible to the public.

The information was available on a publicly accessible computer server and included data transferred by the Teacher Retirement System of Texas, the Texas Workforce Commission and the Employees Retirement System of Texas.

Combs said that on Wednesday her office will begin sending letters to notify those affected by the data breach, which is thought to be the largest in Texas history.

Read more on Dallas News.

The Comptroller’s Office has issued a press release today:

The Texas Comptroller’s office is sending letters beginning Wednesday, April 13, to notify a large number of Texans whose personal information was inadvertently disclosed on an agency server that was accessible to the public. The records of about three and a half million people were erroneously placed on the server with personally identifying information.

There is no indication the personal information was misused. [A common, if meaningless statement in Breach Notices. Bob]

“I deeply regret the exposure of the personal information that occurred and am angry that it happened,” Texas Comptroller Susan Combs said. “I want to reassure people that the information was sealed off from any public access immediately after the mistake was discovered and was then moved to a secure location. We take information security very seriously and this type of exposure will not happen again.”

The records contained the names and mailing addresses of individuals. The records also included Social Security numbers, and to varying degrees also contained other information such as dates of birth or driver’s license numbers – all the numbers were embedded in a chain of numbers and not in separate fields. [In other words, a typical computer record. Bob]

The information was in data transferred by the Teacher Retirement System of Texas (TRS), the Texas Workforce Commission (TWC) and the Employees Retirement System of Texas (ERS).

The TRS data transferred in January 2010 had records of 1.2 million education employees and retirees. The TWC data transferred in April 2010 had records of about 2 million individuals in their system. And the ERS data transferred in May 2010 had records of approximately 281,000 state employees and retirees.

The data files transferred by those agencies were not encrypted as required by Texas administrative rules established for agencies. In addition to that, personnel in the Comptroller’s office incorrectly allowed exposure of that data. Several internal procedures were not followed, leading to the information being placed on a server accessible to the public, and then being left on the server for a long period of time without being purged as required by internal procedures. The mistake was discovered the afternoon of March 31, at which time the agency began to seal off public access to the files. The agency has also contacted the Attorney General’s office to conduct an investigation on the data exposure and is working with them.

The information was required to be transferred per statute by these agencies and used internally at the Comptroller’s office as part of the unclaimed property verification system.

The Comptroller views the protection of personal information as a serious issue. She will be working with the Legislature to advance legislation to enhance information security as outlined in the Protecting Texans’ Identities report she released in December. This would include the designation of Chief Privacy Officers at each agency as well as the creation of an Information Security Council in the state.

The agency has set up an informational website for individuals at www.TXsafeguard.org to provide additional details and recommended steps and resources for protecting identity information.



Could Spammers connect an email address to a phone number? Sure. Why would they leave “noise” rather than a sales pitch for Viagra?

http://www.databreaches.net/?p=17670

Readers question whether Epsilon breach was really names and email addresses only (updated to include response from Epsilon)

April 11, 2011 by admin

From comments under another blog entry, it seems clear that a lot of people are not believing Epsilon’s assurance that the breach involved names and email addresses only.

I received the following email, which I am reproducing except for redacting the name of the sender and the name of the Epsilon employee and their phone number, although that information was provided to me and to CERT:

I saw that you posted an article about the Epsilon breach and I am trying to make consumers aware of more information. Phone numbers were taken along with the email addresses. I am getting over 100 phone calls per day and nothing is being done about it. When contacting the phone company, they give me no other choice but to change my phone number. But I need my phone number for work and it would be very difficult to change it. I am sure there are hundreds of other people dealing with the same issue. At the least, people need to know that it was not just email addresses taken, phone numbers were taken and who knows what else. Epsilon lied to us.

———- Forwarded message ———-
From: [redacted]
Date: Sun, Apr 10, 2011 at 7:23 PM
Subject: Epsilon breach included phone numbers
To: phishing-report@us-cert.gov

Ever since I was notified that my information was compromised during the Epsilon breach, I have been getting phone calls every 4 minutes constantly for over a week. The calls will come from random computer-generated 11 digit numbers, blocked numbers, and unknown numbers. Even though the numbers are different, they always leave the same 29 second voicemail that sounds like frequencies when adjusting an old TV antenna. I called Epsilon and spoke to [redacted employee name] at [redacted phone number], and she confirmed that other customers were getting the same types of calls and it was widespread. However, they only reported that email addresses were taken and denied anything else. Clearly other information was taken and is still being abused.

I am blocking all calls that are not in my contact list. Here is a brief history of the calls that were blocked for 3 days.

Is anyone doing anything about this???

*********************************************
* Received and Blocked Calls
*********************************************

[A very very long list of timestamps and blocked calls was included in the email to CERT but is deleted here to save space]

In subsequent correspondence, the writer indicated that the phone calls started on March 31 around 2:00 pm ET and have been non-stop ever since. Note that the phone calls reportedly started after the breach occurred but the day before Epsilon issued its press release on the breach.

I asked which notifications s/he had received following the announcement of the breach, and s/he indicated New York & Company, Hilton Honors, and Capital One. The correspondent indicated some surprise that more notifications hadn’t been received because s/he has accounts with some of the other entities who were reportedly affected.

Epsilon did not respond to an email inquiry sent by DataBreaches.net by the time of this publication, but if I receive a response, I will update this post.

Update: An Epsilon spokesperson responds:

As stated in our releases, the ONLY information that was comprised was email address and/or customer name.

At this point, all I’m able to share are the statements on our website as we conduct an ongoing investigation.



No indication of numbers, yet. Data includes “sales leads” so apparently you don't need to be associated with the company to be a victim.

http://www.databreaches.net/?p=17713

Hacker breaks into Barracuda Networks database

April 12, 2011 by admin

Robert McMillan reports:

A hacker has broken into a Barracuda Networks database and obtained names and e-mail addresses of some of the security company’s employees, channel partners and sales leads.

The hacker, who called himself Fdf, posted proof of his attack to the Web on Monday, showing e-mail addresses of company employees and names, e-mail addresses, company affiliations and phone numbers of sales leads registered by the company’s channel partners.

Read more on Computerworld. Additional coverage on The Register. Barracuda’s response here.

[From the Register article:

Screenshots showed what was purported to be names, email addresses and phone numbers for Barracuda partners from organizations including Fitchburg State University in Massachusetts and the UK's Hartlepool College of Further Education.

… It was unclear if the hashed passwords were salted to prevent them from being cracked using various free tools available on the internet.

… SQL injection attacks exploit poorly written web applications that fail to scrutinize user-supplied data entered into search boxes and other fields included on the targeted website. By passing database commands to the site's backend server, attackers can harness the vulnerabilities to view and even modify the confidential contents.

In all, 22 databases with names including new_barracuda, information_schema and Marketing were exposed, according to the post, which was published on Tuesday.

[From barracuda:

The Barracuda Web Application Firewall in front of the Barracuda Networks Web site was unintentionally placed in passive monitoring mode and was offline through a maintenance window that started Friday night (April 8 ) after close of business Pacific time.

… After approximately two hours of nonstop attempts, [Which no one noticed because they had turned off the firewall? Bob] the script discovered a SQL injection vulnerability in a simple PHP script that serves up customer reference case studies by vertical market.

… We have logs of all the attack activity, and we believe we now fully understand the scope of the attack.



Building a Hacker Target... Your data is secure, except that “almost everyone at the university?” will have access.

http://www.pogowasright.org/?p=22330

UK: Student database raises privacy concerns

April 11, 2011 by Dissent

Alice Kinder reports:

Oxford University’s decision to add students to the University’s Development and Alumni Relations System database has provoked mixed reactions.

An email was sent out to students on Thursday stating that the University will be adding information on all students to the new database “in order to facilitate better communication and engagement for the entire Oxford community.”

However, students wishing to opt out of having their information migrated are given the opportunity to do so before the 4th May.

This data includes name, contact details, date of birth, gender, marital status, nationality, supervisor, college advisor, programme of study and educational history. Academic results will not be transferred.

Read more on Cherwell.

I imagine hackers are licking their lips already over this one. I thought Oxford was supposed to have some smart people, but look at this self-contradictory explanation:

It is said that details in DARS are held securely, and the data can then be used for networking purposes so that those who have left university can “connect with other, like-minded alumni”.

The email sent to students also states that the data may be used by colleges, faculties, departments, administrative units, international offices, recognised alumni societies, and sports and other entities associated with the University.

Hopefully, the students at Oxford are smarter or more savvy than the folks who came up with this plan and they will opt out immediately.



Now those Privacy Policies no one reads are even more important. Absent a Policy, you have no Privacy?

http://www.pogowasright.org/?p=22339

Judge rules emails in Hamilton’s case admissible

April 12, 2011 by Dissent

Frank Green reports:

A federal judge in Richmond has ruled that the government may use emails between former Del. Phillip A. Hamilton and his wife in his upcoming bribery and extortion trial.

[...]

Hamilton’s lawyers said the emails are not admissible because of his Fourth Amendment right to privacy and the privilege of protecting confidential marital communications.

But, wrote U.S. District Judge Henry E. Hudson in an eight-page ruling Monday, “Neither affords him the protection he seeks.”

The emails were stored on Hamilton’s work computer with the Newport News school system. At the time they were written, the school system had no policy on privacy expectations.

Read more in the Richmond Times-Dispatch. Related coverage from Associated Press can be found on PilotOnline.com



Should be amusing to watch...

http://www.pogowasright.org/?p=22343

Draft PRC Guidelines on Personal Data Protection

April 12, 2011 by Dissent

Gabriela Kennedy writes:

While personal data privacy law has been developing in many jurisdictions with the increasing prevalence of internet usage, the People’s Republic of China (“PRC”) has not yet enacted comprehensive laws or regulations governing the collection, use and transfer of personal data. However, this may change soon, as indicated by the recent issuance of the draft Information Security Technology — Guide of Personal Information Protection (the “Guidelines”, issued jointly by the General Administration of Quality Supervision Inspection and Quarantine and the Standardization Administration of the PRC on 30 January 2011). The draft Guidelines were developed in consultation with the Ministry of Industry and Information Technology, the government agency charged with regulating the telecoms and internet industries, and would create broadly applicable rules and principles for handling and transferring personal information. Although the draft Guidelines could be revised before implementation and have not yet been enacted, upon entering into force they could significantly impact business practices relating to storage, processing and transfer of information.

Read more of their description of the draft guidelines on Hogan Lovells Chronicle of Data Protection.



E-Discovery Changing technology, large data volumes, and the Joy of Computer Forensics...

http://www.bespacific.com/mt/archives/026978.html

April 11, 2011

Sedona Conference® Database Principles - Addressing the Preservation & Production of Databases & Database Information in Civil Litigation

The Sedona Conference® Database Principles - Addressing the Preservation & Production of Databases & Database Information in Civil Litigation. A Project of The Sedona Conference®Working Group on Electronic Document Retention & Production (WG1), March 2011 Public Comment Verson, by the The Sedona Conference®. Editor-in-Chief: Conrad J. Jacoby

  • "Disputes over the discovery of information stored in databases are increasingly common in civil litigation. Part of the reason is that more and more enterprise-level information is being stored in searchable data repositories, rather than in discrete electronic files. Another factor is that the diverse and complicated ways in which database information can be stored has made it difficult to develop universal “best-practice” approaches to requesting and producing information stored in databases. The procedures that work well for simple systems may not make sense when applied to larger server-based systems. Similarly, retention guidelines that make sense for archival databases—that is, databases that add new information without deleting past records—rapidly break down when applied to transactional databases where much of the system’s data may be retained for only thirty days—or even thirty seconds."


(Related) Not everyone tries to hide evidence, but here's what happens when you get caught.

http://e-discoveryteam.com/2011/04/10/judge-refers-defendant%E2%80%99s-e-discovery-abuse-to-u-s-attorney-for-criminal-prosecution-of-the-company-and-four-of-its-top-officers/

Judge Refers Defendant’s e-Discovery Abuse to U.S. Attorney for Criminal Prosecution of the Company and Four of Its Top Officers



Not the typical knee-jerk reaction...

http://games.slashdot.org/story/11/04/11/2353248/DRM-Drives-Gamers-To-Piracy-Says-Good-Old-Games?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

DRM Drives Gamers To Piracy, Says Good Old Games

"Independent retro games retailer Good Old Games has spoken out about digital rights management, saying that it can actually drive gamers to piracy, rather than acting as a deterrent. In an interview, a spokesperson for Good Old Games said that the effectiveness of DRM as a piracy-deterrent was 'None, or close to none.' 'What I will say isn't popular in the gaming industry,' says Kukawski, 'but in my opinion DRM drives people to pirate games rather than prevent them from doing that. Would you rather spend $50 on a game that requires installing malware on your system, or to stay online all the time and crashes every time the connection goes down, or would you rather download a cracked version without all that hassle?'"



Interesting idea for an application. First, find a big market (dieters) then sell them something they can use... (Now we'll have people texting and snapping photos at the table next to us when we want a quiet dinner.)

http://news.yahoo.com/s/nm/us_technology_app_meals;_ylt=A0LEapEVAqNNt.QAmxis0NUE;_ylu=X3oDMTNzc2Fha3RmBGFzc2V0A25tLzIwMTEwNDExL3VzX3RlY2hub2xvZ3lfYXBwX21lYWxzBGNjb2RlA21vc3Rwb3B1bGFyBGNwb3MDMTAEcG9zAzcEcHQDaG9tZV9jb2tlBHNlYwN5bl9oZWFkbGluZV9saXN0BHNsawNuZXdhcHBjYWxjdWw-

New app calculates calories through photos of food

Worried about how many calories you are going to consume in that slice of pizza, chocolate cake or bag of fries? A new iPhone application may help.

After taking a picture of the meal with the phone, the app gives a calorie read-out almost instantly.

The app, called MealSnap, was developed by DailyBurn, a fitness social network that has created several other fitness and diet-related iPhone applications.

Within minutes of taking a picture of a meal and matching it to a database of some 500,000 food items, the app sends users an alert with a range of calories for the meal that was photographed.



Might be interesting to add to your business cards as a pointer to an “always up-to-date” resume... Or the current price list... Or your Blog... Or ??? ...

http://www.makeuseof.com/dir/uqr-share-websites-qr-codes/

Uqr: Share Websites & Other Various Things Through QR Codes

uQR is a simple and free to use web service that lets you share anything on the web using QR codes. Basically the website gives you a public profile that has two parts: a URL and a QR code pointing to this URL. When people scan the code, they are taken to your uQR sharing page where you can share almost anything: specially formatted text, your vCard, a YouTube video, or any other URL of your choosing. Things you share on the profile can be changed anytime.

You can print out the QR code and paste it anywhere in public. This way you will be sharing material with everybody who has the ability to scan the code and reach your uQR profile ““ an interesting idea indeed.

www.uqr.me

Similar tools: QRVCards, QRcore and LocationBookmark.



For my fellow Sci-Fi fans. I always wanted to build one in my garage...

http://www.wired.com/wiredscience/2011/04/shuttle-manual-excerpt/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

Book Excerpt: Space Shuttle Owners’ Workshop Manual


Monday, April 11, 2011

Luddites or Privacy Champions?

http://www.thetechherald.com/article.php/201115/7038/Google-announces-Street-View-retreat-in-Germany

Google announces Street View retreat in Germany

by Steven Mostyn - Apr 11 2011, 12:28

Having only last week seen its contentious Street View service slapped down in Switzerland, search titan Google has now decided to abandon the German version of the interactive mapping tool.

That’s according to online blog Search Engine Land, which reports that Germany’s existing Street View content will remain accessible to users but will receive no further updates as Google’s iconic camera cars depart the country.

Google’s decision to yank its vehicles may be viewed as somewhat odd, not least because the Berlin State Supreme Court recently ruled in favor of the search giant after a German woman challenged Street View for invading her privacy and that of her family.

However, the Germans have been fairly resistant to the appearance of Street View’s camera cars, with almost 250,000 residents and businesses having taken advantage of an opt-out clause presented by Google—which results in entire locations being blurred from view via the online service.



...including Kindergartners!

http://news.cnet.com/8301-17852_3-20052512-71.html

Schools supe: iPad more important than a book

The iPad has enjoyed more than its fair share of hyperbole since its launch.

However, perhaps the praise heaped upon it by a school superintendent from Auburn, Maine, might represent the pinnacle (thus far, at least).

CNN and WGME reported that every elementary public school student in Auburn, Maine, will be getting a new iPad 2.

The iPad will become a permanent tool of learning for these children.

But perhaps those who haven't quite kept up with technology's pace will be perturbed at one comment made by Auburn schools Superintendent Tom Morrill. For he declared that the iPad is "even more important than a book."



The difference between vision and hallucination?

http://www.youtube.com/watch?v=xx2Slxp0TkM

The Essay


Sunday, April 10, 2011

A relatively small breach, but with some typical statements that illustrate points of security failure for my students.

http://www.databreaches.net/?p=17642

Ie: Firm possibly lost 50,000 clients’ data

April 9, 2011 by admin

Una McCaffrey reports:

Phoenix Ireland, a life and pensions company, has admitted it may have lost the personal details of about 50,000 current and former customers. [Keeping old records mixed in with current records Bob] The possible data loss also affects a small number of people who contacted the company, formerly Scottish Provident Ireland, but did not take out a policy. [Includes data on people who talked to their agents but never purchased their insurance? Will they even consider themselves at risk if they read about this but don't receive a letter? Bob]

In letters sent this week, Phoenix told the affected individuals that a “tape” containing their personal data held on its systems had been misplaced.

It is understood that in most cases, this data, which was not encrypted, included customers’ names, addresses and bank account details.

Read more on Irish Times.

[From the article:

A spokesman for Phoenix said yesterday that it viewed this risk as “low-level”, in part because hacking experts had concluded it would be extremely difficult to distil information from the tape, which was not labelled “Phoenix”. [That provides no security Bob]

In its advice to those contacted, the company said: “We believe it would require an experienced IT specialist to be able to understand the data.”

The spokesman also said the company is not convinced the tape was ever actually created; [Failure to keep records (logs) of computer activity, so they have no idea what is happening in their systems? Bob] it simply knows it did not arrive when it should have been sent from one office to another.



Some governments are pushing toward Privacy, others (China) are pushing in the other direction. Where does the pendulum stop?

http://www.pogowasright.org/?p=22315

AU: Government must justify web snooping: senate report

April 9, 2011 by Dissent

Nicky Phillips reports:

The federal government should justify why mandatory collection and retention of personal data is necessary for law enforcement, a senate report into online privacy has found.

An analysis of the costs, benefits and risks should be conducted before the government pursues its proposed data retention scheme, the report stated.

”We have sent a rocket back to the Attorney-General’s office saying don’t proceed any further until you’ve done your basic homework,” said the Greens Senator Scott Ludlum, a member of the senate committee.

Read more in The Age. It sounds like these legislators are looking at – and asking – some of the same questions that American privacy advocates are raising.



YouTube is facing government regulation and lawsuits for failure to “censor” uploaded videos in a timely manner (i.e. instantly). This would seem to really increase the difficulty of finding and blocking “unapproved” videos.

http://www.hollywoodreporter.com/news/youtube-launches-live-streaming-page-176535

YouTube Launches Live Streaming Page

YouTube, the video site owned by Google, on Friday unveiled a page highlighting live programming and said users have asked for more live streams.

"With over 2 billion views a day, it's easy to think about YouTube as a place to watch videos recorded in the past," it said in a blog post. "But you’ve told us you want more - and that includes events taking place right now. In response, we’ve live streamed a number of popular concerts, sporting events, and interviews, but primarily on a one-off basis."

The initial rollout of YouTube Live will "integrate live streaming capabilities and discovery tools directly into the YouTube platform for the first time," the video site said.

… Users can subscribe to their favorite YouTube live-streaming partners to be notified of upcoming live streams.



SCO is dead when Pamela Jones says it is dead.

http://slashdot.org/story/11/04/09/2315208/Groklaw-Declares-Victory-No-More-Articles?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Groklaw Declares Victory, No More Articles

"Pamela Jones announced that as of May 16th, she will no longer be updating groklaw

"I have decided that Groklaw will stop publishing new articles on our anniversary, May 16: "I know a lot of you will be unhappy to hear it, so let me briefly explain, because my decision is made and it's firm. In a simple sentence, the reason is this: the crisis SCO initiated over Linux is over, and Linux won. SCO as we knew it is no more. "



For my Computer Security students

http://linux.slashdot.org/story/11/04/09/2018231/Five-of-the-Best-Free-Linux-Disk-Encryption-Tools?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Five of the Best Free Linux Disk Encryption Tools

"Disk encryption uses software to encrypt the entire hard disk. The onus is therefore not on the user to determine what data should be encrypted, or to remember to manually encrypt files. By encrypting the entire disk, temporary files, which may reveal important confidential data, are also protected. Security is enhanced further when disk encryption is combined with filesystem-level encryption. To provide an insight into the open source software that is available, we have compiled a list of five notable disk encryption tools. Hopefully, there will be something of interest here for anyone who wants easy-to-use data encryption and security."


For my Ethical Hackers and Computer Security students. Great illustration of the data that accompanies a 140 character Tweet.

http://www.pogowasright.org/?p=22324

This is What a Tweet Looks Like

April 9, 2011 by Dissent

Sarah Perez writes:

Think a tweet is just 140 characters of text? Think again. To developers building tools on top of the Twitter platform, they know tweets contain far more information than just whatever brief, passing thought you felt the urge to share with your friends via the microblogging network. A tweet is filled with metadata – information about when it was sent, by who, using what Twitter application and so on.

Now, thanks to Raffi Krikorian, a developer on Twitter’s API/Platform team, you can see what a tweet looks like, in all its data-rich detail.

Read more on ReadWriteWeb.

[From the Article:

This image is all the more interesting when you consider how much richer a tweet's data map will soon become. At last week's first-ever official Twitter developers' conference, Chirp, Twitter announced that it will implement a new feature called "annotations" next quarter. This was possibly one of the most significant announcements made, second-only (if even) to the launch of Twitter's advertising initiatives, the long-anticipated answer as to how Twitter plans to make money.

With annotations, third-party Twitter developers can add any additional metadata to a Twitter post. That's right, any data. And a tweet can have more than one annotation attached to it. This extra data will initially start off small - Twitter developer Marcel Molina said it will "probably" be around 512 bytes. But over time, it will gradually grow larger as Twitter rolls out the feature and scales up in order to support it. The company hopes to have it end up "around 2K," says Molina. How developers use that extra space is entirely up to them - there can be one giant piece of extra data attached to a tweet or a thousand tiny ones.


Saturday, April 09, 2011

“We don't need no stinking regulation!”

http://www.databreaches.net/?p=17610

The Epsilon Hack Attack: Time For “SOX For Consumers”?

April 8, 2011 by admin

Matt Pauker of Voltage Security discusses the Epsilon breach and where we go from here. He writes, in part:

What about requiring every third-party service provider to protect personal customer data through encryption, tokenization or another advanced security technology, through clauses written into and enforced as part of standard service level agreements? This is something that companies can initiate today, without waiting for federal, state or industry regulation.

Or, has the time come for “SOX for consumers”: a consumer-focused plan calling for new rules that force companies to certify that they have adequate data protection in place to protect data even in the event of a breach?

Read more on Forbes.



Are Social Networks at risk? Perhaps, if the legislative pendulum swings too far...

http://www.pogowasright.org/?p=22308

Internet firms wake up to federal privacy scrutiny

April 8, 2011 by Dissent

Cecilia Kang reports:

As LinkedIn prepares to sell its stock to the public, the social network for professionals is warning of a potential threat to its business: Internet privacy laws.

In a filing to the Securities and Exchange Commission this month, the startup said a push by federal regulators to create first-time privacy rules “could deter or prevent us from providing our current products and solutions to our members and customers, thereby harming our business.”

Read more in The Washington Post.


(Related)

http://www.pogowasright.org/?p=22311

DOJ filing would create dangerous precedent on privacy policies

April 8, 2011 by Dissent

Declan McCullagh reports:

The U.S. Justice Department today dismissed as “absurd” any privacy and free speech concerns about its request for access to the Twitter accounts of WikiLeaks volunteers.

In a 32-page brief filed in federal court in Virginia, prosecutors characterized their request for a court order as a “routine compelled disclosure” that raises no constitutional issues.

Read more on cnet.

In related coverage, Andy Greenberg of Forbes focuses on the DOJ’s argument that the presence of a privacy policy on Twitter obliterates any reasonable expectation of privacy, even if the user never looks at it:

In their brief, the U.S. attorneys attack an argument from Appelbaum, Jonsdottir and Gonggrjip’s team that they shouldn’t be held to Twitter’s privacy policy–which allows authorities to lift data like users’ IP addresses–because it’s unreasonable to assume that users have read it or any other of the dense policies they face on commonly used sites.

“The existence of the Privacy Policy, even if unread by the Subscribers, undermines the legitimacy of any expectation of privacy the Subscribers may have had in the IP addresses they conveyed to Twitter,” reads the brief. “Although individual users might be ignorant of the terms of Twitter’s Privacy Policy, society is not prepared to recognize as reasonable an expectation of privacy that is directly contradicted by policy statements available to all who wish to read them.”

Read more on Forbes.



For my Computer Security students

http://www.makeuseof.com/tag/put-passwords-crack-test-password-strength-tools/

Put Your Passwords Through The Crack Test With These Five Password Strength Tools

How Secure Is My Password

The Password Meter

Test Your Password

Strength Test

Microsoft Safety And Security Center


Friday, April 08, 2011

This is going to take a shelf full of books to document...

http://www.databreaches.net/?p=17374

And the hits just keep on coming for Epsilon

April 3, 2011 by admin

Note: CBS reports that the Secret Service is investigating the Epsilon breach. If you receive a phishing attempt that you want to report to the Secret Service, email phishing-report@us.cert.gov. You can also file a report at http://www.ic3.gov/default.aspx. I’ll add businesses to the list of affected customers as I become aware of them, so check back if you want to see what else has been reported. See Brian Krebs’ commentary on the fears about spear phishing as a result of this breach.

  1. 1-800-FLOWERS

  2. AbeBooks

  3. AIR MILES Reward Program (Canada)

  4. Ameriprise

  5. Barclays Bank of Delaware (BJ’s Visa, L.L. Bean Visa)

  6. Beachbody

  7. bebe

  8. Best Buy

  9. Best Buy Canada Reward Zone

  10. Benefit Cosmetics (see below)

  11. Brookstone

  12. Capital One

  13. Charter Communications

  14. Citi (ExxonMobil, Card,Home Depot Card, NTB Card, The Place)

  15. City Market

  16. College Board

  17. Crucial

  18. Dell Australia

  19. Dillons

  20. Disney Destinations (The Walt Disney Travel Company)

  21. Eddie Bauer Friends

  22. Eileen Fisher (doesn’t name Epsilon but same template letter)

  23. Ethan Allen

  24. Eurosport Soccer (Soccer.com)

  25. Food 4 Less

  26. Fred Meyer

  27. Fry’s

  28. Hilton Honors

  29. Home Shopping Network (HSN)

  30. Jay C

  31. JPMorgan Chase

  32. King Soopers

  33. Kroger

  34. Lacoste (and as per TG Daily)

  35. Marriott Rewards (FAQ on site)

  36. Marks & Spencer

  37. McKinsey Quarterly

  38. MoneyGram

  39. New York & Company

  40. QFC

  41. Ralphs

  42. Red Roof Inn

  43. Ritz-Carlton (FAQ)

  44. Robert Half International

  45. Scottrade

  46. Smith Brands

  47. Stonebridge Life Insurance

  48. Target

  49. Tastefully Simple

  50. TD Ameritrade

  51. TIAA-CREF

  52. TiVo

  53. US Bank

  54. Verizon

  55. Viking River Cruises

  56. Walgreens

  57. World Financial Network National Bank (Ann Taylor, Catherine’s, Chadwick’s, Dressbarn, Express card, Fashion Bug, Giant Eagle fuelperks!, J Crew, Lane Bryant, Maurice’s, PotteryBarn/Kids/Teens, RadioShack, Sears, Smile Generation Financial, The Limited, United Retail Group (Avenue, Jessica London, OneStopPlus), Value City Furniture, Victoria’s Secret)

Thanks to all those who have copied and pasted in the emails you have received. If you have something you think I’m missing, please check the list first to see if I already have the name of the company and a linked copy of the notice (bank cards are under the name of the issuing bank), and if not, post away!

Benefit Cosmetics. What’s significant about their report is that they appear to be former clients of Epsilon, raising the question of why their data were on the compromised server. Did the breach occur while they were still clients or did Epsilon not remove their data from their server after they stopped using their service?

An email sent to DataLossDB who shared it with this site, read:

While we wish this was about lipstick, we have important news regarding your email address.

We were just informed by a former email vendor that the database with our customers’ names and email addresses has been compromised by an unauthorized person. The only information at risk is your name and email address.

The vendor has assured us that “a rigorous assessment determined that no other personal identifiable information associated with those names was at risk. A full investigation is currently underway.” This data breach has also affected several other companies that work with this vendor.


(Related) If the “breachee” is responsible for notifying the customers of their customers, what are the implications for Cloud Computing?

http://www.databreaches.net/?p=17572

Who should be notifying consumers about the Epsilon breach?

April 7, 2011 by admin

Senator Richard Blumenthal, a staunch consumer privacy advocate, has said that Epsilon should be notifying every consumer whose data were involved in the recent humongous breach. You can read his entire letter to Attorney General Eric Holder requesting an investigation on his web site, but here’s part of what he wrote:

I believe that immediate notification to all customers is vital to protect them – and enable them to protect themselves – from identity theft.

[...]

I believe that affected individuals should be notified and provided with financial data security services, including free access to credit reporting services, for two years, the costs of which should be borne by Epsilon or its affected clients. I believe it is also necessary to provide every affected individual with sufficient insurance to protect them against possible financial consequences of identity theft.

Who Should Send Us the Notifications?

Should Epsilon be sending us the notifications – as Senator Blumenthal’s letter would seem to suggest – or should the company who gave our data to them be sending us the notifications?

[How about “Fourth Party” actors? Bob] If you have an account with a store and got a branded credit card through World Financial Network National Bank (WFNNB), WFNNB sent you the notification and apology email. They told you that their email was about [name of store where you have an account], but it was their email to you – not the store’s.

So you got the important information to be alert to phishing attempts, but you probably didn’t hear from the store. Are you okay with that? It was WFNNB who had the contract with Epsilon (or so it seems from their notification email text), but whom do you feel you have the relationship with – the store or WFNNB?

Who owes you the apology as well as the information?

And who should be accountable for this? The store or WFNNB – or both?

You trusted the store. They trusted WFNNB. WFNNB trusted Epsilon. But it all started with consumer trust in the store. And I think we need to hold the stores (or hotels or financial institutions) accountable if they want to keep our trust and our business. For that reason, I’ve been including all of their names in the running list of affected entities even though most other sites keeping tabs have not taken this approach and might just list WFNNB.

I’d also point out that on practical and safety levels, even if we had gotten an email from Epsilon (as the Senator urges), would most of us have even opened it, much less believed it – or would we have just looked at the subject line and deleted it as probably spam or a phishing attempt?

What do you think? You can sound off in the Comments section.



Here's one we haven't heard from in some time. I'm certain this will get all the attention it deserves.

http://news.cnet.com/8301-27080_3-20051941-245.html

T.J.Maxx hacker says feds gave him the OK

Albert Gonzalez, the hacker who pleaded guilty to leading one of the largest cases of credit card theft in the U.S., is asking a judge to toss out the pleas, arguing that they were part of his assignments as a paid government informant.

"I still believe that I was acting on behalf of the United States Secret Service and that I was authorized and directed to engage in the conduct I committed as part of my assignment to gather intelligence and seek out international cybercriminals," Gonzalez wrote in a 25-page petition filed March 24 with the U.S. District Court in Massachusetts and published on the Threat Level blog. "I now know and understand that I have been used as a scapegoat to cover someone's mistakes."



“Hey, our degrees are in education. They never trained us to count!”

http://www.databreaches.net/?p=17588

(update) More Student SSNs Were At Risk, TEA Says

April 7, 2011 by admin

Morgan Smith reports that a breach involving the Texas Education Agency was much worse than originally reported. An unencrypted disk containing data on almost 25,000 Laredo Independent School Districtast month, the TEA reported that an students had gone missing. But when the Texas Tribune obtained records about the breach, they discovered that there were data on 164,406 students who graduated from eight Texas school districts over the past two decades that had been sent via unencrypted disks.

The data were for students who graduated between 1992 and 2010 in the top 10% of their classes in the Crowley, Harlingen, Round Rock, Killeen, Richardson, Irving, Mansfield, and Grand Prairie school districts.

Between August (2010) and January (2011), the districts mailed unencrypted CDs loaded with students’ Social Security Numbers, dates of birth and ethnicity — data requested by the University of Texas at Dallas ’ Education Research Center — to the TEA, with the expectation that the TEA would deidentify the records and pass them along to UT-Dallas.

[...]

A TEA spokeswoman told the Tribune today that Laredo ISD’s data set is the only one believed to be missing. [“Of course, we didn't know about the other 140,000 students either” Bob] The January memo says the agency has since destroyed the CDs from the eight districts whose information it did receive.

Read more in the Texas Tribune.



I would expect any judge to do this, but I have one of those “I'm not a lawyer” questions. Shouldn't someone from the Patent Office be explaining this to the Judge? If they explained it the way Oracle said it should work wouldn't that end the case? What did the Patent Office think they were granting a Patent for?

http://developers.slashdot.org/story/11/04/08/0324236/Judge-In-Oracle-Google-Case-Given-Crash-Course-in-Java?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Judge In Oracle-Google Case Given Crash Course in Java

"Lawyers for Oracle and Google gave Judge William Alsup of the U.S. District Court in San Francisco an overview of Java and why it was invented, and an explanation of terms such as bytecode, compiler, class library and machine-readable code. The tutorial was to prepare him for a claim construction conference in two weeks, where he'll have to sort out disputes between the two sides about how language in Oracle's Java patents should be interpreted. At one point an attorney for Google, Scott Weingaertner, described how a typical computer is made up of applications, an OS and the hardware underneath. 'I understand that much,' Alsup said, asking him to move on. But he had to ask several questions to grasp some aspects of Java, including the concept of Java class libraries. 'Coming into today's hearing, I couldn't understand what was meant by a class,' he admitted."



“Senator, your STD test results are back...”

http://www.phiprivacy.net/?p=6407

Doctor visit text reminders violate patient privacy: Swedish health board

By Dissent, April 8, 2011

The Swedish health authorities have made a privacy-protective ruling about text messaging patients:

Text message reminders for appointments with doctors or dentists may soon be a thing of the past in Sweden.

The National Board of Health and Welfare (Socialstyrelsen) have found them to be in breach of their rules on patient confidentiality.

“It is against our rules. The texts contain patient information and must therefore be handled securely,” Anders Printz of the National Board of Health and Welfare said to daily Dagens Nyheter (DN).

Today, many health care providers in Sweden use text messages to remind patients of looming appointments. But now this will have to cease. At least for the time being.

The rules apply to both dentists’ and doctors’ appointments and it makes no difference if the patient has agreed to be contacted by text message.

Read more in The Local (Se)

I admit I’ve never even thought about this issue as I don’t text anyone, period, but in light of this news story, I wonder how many U.S. health care professionals use text messages to communicate with patients. I hope none, but I wouldn’t be surprised to hear that it goes on.

[From the article:

The National Board of Health and Welfare argue that because the traffic is not encrypted there is no way of making sure that the texts reach the right person.

… The Swedish Public Dental Service (FolktandvÃ¥rden) is one health care provider that has made good use of text message reminders. They think that the reasoning around text messages is surprising.

“It seems strange that it wouldn’t be allowed to send text messages to those patients that have agreed to it. If they give us their phone number we are allowed to phone them,” Irene Smedberg of the Public Dental Service said to DN.


(Related) “Citizens! Give us your personal information so we can protect it! If you don't voluntarily surrender this information, we'll assume you have something to hide...”

http://news.cnet.com/8301-13578_3-20051953-38.html

Report: U.S. to issue terror alerts via Facebook, Twitter

The Department of Homeland Security plans to replace its color-coded, five-level system of terrorism alerts with a new two-tiered approach later this month and will issue some public alerts via Facebook and Twitter, according to a report.

The Associated Press said it had obtained a confidential, departmental document outlining the plan, which, though not yet finalized, should go into effect by April 27.

According to the AP, the new plan will ditch the notoriously perplexing, green-to-red, low risk–to–severe risk system put in place in 2002 with a two-level system that labels threats as either "elevated" or "imminent." [Do you know if those “levels” connect with any specific regulatory power? If it was possible to have a “Nothing To Worry About” level, would there be a cut in funding? Bob]



“We've gotta DO something!”

http://www.gao.gov/new.items/d11461t.pdf

TSA Is Taking Steps to Validate the Science Underlying Its Passenger Behavior Detection Program, but Efforts May Not Be Comprehensive

As GAO reported in May 2010, TSA deployed its behavior detection program nationwide before first determining whether there was a scientifically valid basis for the program. According to TSA, the program was deployed before a scientific validation of the program was completed in response to the need to address potential security threats. However, a scientific consensus does not exist on whether behavior detection principles can be reliably used for counterterrorism purposes, according to a 2008 report of the National Research Council of the National Academy of Sciences.



For my Ethical Hackers

http://yro.slashdot.org/story/11/04/08/1245244/Involuntary-Geolocation-To-Within-One-Kilometer?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Schneier's blog tips an article about research into geolocation that can track down a computer's location from its IP address to within 690 meters on average without voluntary disclosure from the target. Quoting:

"The first stage measures the time it takes to send a data packet to the target and converts it into a distance – a common geolocation technique that narrows the target's possible location to a radius of around 200 kilometers. Wang and colleagues then send data packets to the known Google Maps landmark servers in this large area to find which routers they pass through. When a landmark machine and the target computer have shared a router, the researchers can compare how long a packet takes to reach each machine from the router; converted into an estimate of distance, this time difference narrows the search down further. 'We shrink the size of the area where the target potentially is,' explains Wang. Finally, they repeat the landmark search at this more fine-grained level: comparing delay times once more, they establish which landmark server is closest to the target."



No doubt this will confuse those in the Academic community who refuse to allow their students to use Wikipedia...

http://news.slashdot.org/story/11/04/08/0245241/Editing-Wikipedia-Helps-Professor-Attain-Tenure?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Editing Wikipedia Helps Professor Attain Tenure

"Lianna Davis writes in Watching the Watchers that Michel Aaij has won tenure in the Department of English and Philosophy at Auburn University Montgomery in Alabama in part because of the more than 60,000 edits ... he's written for Wikipedia. ... Aaij felt that his contributions to Wikipedia merited mention in his tenure portfolio and a few weeks before the portfolio was due two of his colleagues suggested, after they had heard him talk once or twice about the peer-review process for a Good Article, that he should include it under 'research' as well as well as 'service.'"


Thursday, April 07, 2011

Looks like a day of questions. The first is the classic, what did they know and when did they know it?

http://www.databreaches.net/?p=17540

Epsilon breach used four-month-old attack

April 7, 2011 by admin

Brett Winterford writes:

… Today iTnews can reveal that Epsilon has been aware of the vulnerability behind this attack for some months.

In late November, Epsilon partner ReturnPath – which provides monitoring and authentication services to email service providers – warned customers about a series of coordinated phishing and hacking attacks levelled at the mailing list industry.

Neil Schwartzman, senior director of security strategy at Return Path’s ‘Email Intelligence Group’ warned its partners of “an organized, deliberate, and destructive attack clearly intent on gaining access to industry-grade email deployment systems”.

He said that the phishing attacks were targeted specifically at employees at email service providers that had specific access to email operations.

Read more on iTnews. I note that Epsilon has not actually stated or confirmed the cause of the breach. That said, I suspect Neal’s right and I’m definitely not surprised to read this.

As a reminder, a Walgreens spokesperson had told DataBreaches.net that after the December breach that led to its notifying customers:

After the incident last year, Walgreens requested that Epsilon put a number additional security measures in place. Apparently, that expectation was not fully met.

Phishing attacks on ESPs like Epsilon are not new. There were breaches, and the threat was made publicly known. What did Epsilon do since they were made known? It seems evident that whatever they may have done, it wasn’t sufficient – assuming that this breach was of the same type as what we saw last year.

In 2008, we saw a rash of breaches in the hospitality sector when cybercriminals learned that many restaurants were using default configurations on their POS systems for customers’ credit or debit card payments. The industry spread the word – or tried to – about the need to disable remote desktop access unless absolutely necessary and to change their passwords and to limit access. There are still some breaches of this kind, but they have declined dramatically.

Now we have a rash of breaches involving ESPs. Will the Epsilon fiasco be the wakeup call for this industry? One would hope so, but before that happens, I fear we’re going to hear about more breaches – including some breaches that may have already occurred but not have been fully disclosed.


(Related) These questions seem to confirm my suspicions that the Epsilon breach is big enough to be a potential game changer.

http://www.databreaches.net/?p=17532

House Lawmakers Want Info About Data Breach – So Do I!

April 6, 2011 by admin

Earlier today, I noted that Senator Blumenthal had asked Attorney General Holder to open an investigation into the Epsilon breach.

Also today, some members of the House decided that they wanted some answers, too. Juliana Gruenwald reports:

In a letter Wednesday to Epsilon’s parent company, Alliance Data Systems, the leaders of the Subcommittee on Commerce, Manufacturing and Trade voiced concern that even access to limited data such as a name and e-mail address can lead to identity theft.

“In the simplest fashion, a criminal can easily create a phishing e-mail that could lead an unwitting consumer into financial disaster,” subcommittee Chairwoman Mary Bono Mack, R-Calif., and ranking member G.K. Butterfield, D-N.C., wrote. “With a reported 40 billion marketing e-mails sent a year, the Epsilon breach could potentially impact a historic number of consumers.”

In response, the lawmakers asked for more details by April 18 on the breach and how it might affect consumers.

Some of the information they are seeking include: when Epsilon learned of the breach; when it notified authorities and its corporate customers about the breach; how many companies and consumers were affected; which companies were affected; what information was taken; how did the breach occur; and what steps the company is taking to prevent future intrusions.

Oh please, please, please, add a P.S. to that list of questions to include:

  • Was that Epsilon’s first breach, its second, third…?

And if there was a previous breach (as seems to be a reasonable hypothesis in light of Walgreens’ previous notice to customers):

  • Was this breach via the same means as the previous breach circa November 2010?

  • How many clients – and specifically which clients – did they notify of the 2010 breach?

  • What additional security steps did they take in response to Walgreens’ reported request in December 2010 that they add security protections to prevent a breach like the one Walgreens reported to its customers in December 2010?

  • Epsilon detected the breach on March 30, but when did it actually occur?

  • What other kinds of personal information were on the same server(s) that were compromised?

Read more on National Journal.

You can read the Representatives’ letter to Alliance here.


(Related) Many of Epsilon's clients have a global customer base...

http://www.databreaches.net/?p=17549

AU: Privacy czar to investigate Epsilon email breach


(Related) France makes it much more difficult to protect users (much more attractive for hackers looking for passwords) Question: If you have access to all the data in a user's account, why do you need the password?

http://yro.slashdot.org/story/11/04/07/0212222/France-Outlaws-Hashed-Passwords?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

France Outlaws Hashed Passwords

"Storing passwords as hashes instead of plain text is now illegal in France, according to a draconian new data retention law. According to the BBC, '[t]he law obliges a range of e-commerce sites, video and music services and webmail providers to keep a host of data on customers. This includes users' full names, postal addresses, telephone numbers and passwords. The data must be handed over to the authorities if demanded.' If the law survives a pending legal challenge by Google, Ebay and others, it may well keep some major services out of the country entirely."



Questions for the Cloud Computing industry?

http://www.pogowasright.org/?p=22265

Does Government Own Your Remotely Backed Up Computer Files, Your Emails, or Your Cell Phone GPS Info?

April 6, 2011 by Dissent

Warner Todd Huston writes:

Did you know that there are no laws to prevent government agencies from raiding your computer’s remotely hosted back up files, your third party emails, your cloud computing files, or your cell phone GPS location records? Well, there aren’t. As the law stands today government can go into your private computer files or trace your cell phone location without a warrant.

As a result of this lapse in protection form unlawful search and seizure a new group of concerned parties intends to change the law with the Digital Fourth Amendment campaign.

Read more on Publius Forum


(Related) I can see their interest in published writing (your Facebook page) but does the unpublished (background) stuff have any bearing on job performance?

http://www.pogowasright.org/?p=22268

ACLU Responds To Maryland Division Of Corrections’ Revision Of Invasive Social Media Policy

April 6, 2011 by Dissent

Today, the Maryland Department of Corrections released a letter describing a revised social media policy, in response to a complaint from the American Civil Liberties Union of Maryland asking DOC to rescind their blanket policy demanding personal social media passwords from corrections officers and applicants as part of the employment certification process.

The ACLU’s January 25 letter to Public Safety Secretary Gary Maynard details the experience of Officer Robert Collins, who was ordered to supply his Facebook login information during a recertification jnterview – giving the DOC access to his private electronic communications, and leaving his friends vulnerable to governmental cyber-snooping.

There was a public outcry when the case was reported in the media in February, and within days after the case was publicized, the department suspended the practice. Of concern, however, the state’s Attorney General held that the practice could be appropriate and legal under some circumstances. The Department of Corrections has not yet provided the written policy itself, although the ACLU has requested a copy.

Deborah Jeon, Legal Director for the ACLU of Maryland, said:

“The government should not ask people to “volunteer” access to their private, personal communications. If the term “chilling effect” describes anything, it describes this. Few job applicants, eager to please a prospective employer, are going to feel genuinely free to decline to give up their information. Under the DOC’s reasoning, it would be equally permissible (and logical) for them to ask that job applicants volunteer to have the DOC monitor all of their calls, read all of their e-mail, look at all of their letters, and search their houses on demand. The fact that no employer in country would think of “asking” that strongly indicates how improper it is, and how improper this is.

According to a statement released by the ACLU, although the government promises not to refuse to hire someone because the applicant does not turn over their password, it will be virtually impossible for an applicant who suspects the government is not living up to its word to prove that. Moreover, if the policy is truly voluntary, and if it is true that no negative inferences will be drawn, then it serves no useful purpose. [I doubt they'll buy the “logic” of this argument. Bob]

Equally significant, the revised policy does not address the privacy rights of the Facebook “friends” of those who apply for positions and agree to grant the government access to their social media sites, whose privacy rights are invaded by the government without their consent.

In a separate press statement regarding the policy change, the Department of Correction claims that, according to their own figures, 94 percent of those hired by the DOC during the past year shared their social media information. Because most people would not want to share their social network posts with a future employer, the staggeringly high rate of “volunteering to share” suggests that this was not really perceived as voluntary if one wants to get a job. The DOC statement is ambiguous as to whether anyone actually refused, saying only that five of those hired “chose not to, or were unable to” supply their login information.

Of significant interest is the omission from the DOC press statement of any statement as to how many of those who were not hired declined to provide the DOC with social media information.


(Related) Change is frightening. When you have a process that works and everyone understands it is very difficult to unlearn that process and learn a new one. Likewise, it is easier to oppose change that to support it.

http://www.pogowasright.org/?p=22274

Justice Department opposes digital privacy reforms

April 6, 2011 by Dissent

Declan McCullagh reports:

The U.S. Justice Department today offered what amounts to a frontal attack on proposals to amend federal law to better protect Americans’ privacy.

James Baker, the associate deputy attorney general, warned that rewriting a 1986 privacy law to grant cloud computing users more privacy protections and to require court approval before tracking Americans’ cell phones would hinder police investigations.

This appears the first time that the Justice Department has publicly responded to a set of digital privacy proposals unveiled last year by a coalition of businesses and advocacy groups including AT&T, Google, Microsoft, eBay, the American Civil Liberties Union, and Americans for Tax Reform.

Read more on cnet.

[From the article:

The question at hand is rewriting the Electronic Communications Privacy Act, or ECPA, which was enacted in the pre-Internet era of telephone modems and is so notoriously convoluted, it's difficult even for judges to follow.

[An interesting graphic illustrating how email is protected (or not):

http://www.scribd.com/doc/51761318/Email-Privacy-Protection



This has further implications for Data Mining. If you have millions of records, can you determine who is a terrorist and who is a completely innocent Blogger? (I really need to know!)

http://www.pogowasright.org/?p=22251

Applying the Mosaic Theory of the Fourth Amendment to Disclosure of Stored Records

April 6, 2011 by Dissent

Orin Kerr writes:

I’ve blogged a few times about United States v. Maynard, the controversial D.C. Circuit case holding that over time, GPS surveillance begins to be a search that requires a warrant. Maynard introduced a novel mosaic theory of the Fourth Amendment: Although individual moments of surveillance were not searches, when you added up the surveillance over time, all the non-searches taken together amounted to a search. The obvious question is, just how much is enough to trigger a search? At what does point the Constitution require the police to get a warrant?

This issue recently came up in a court order application before Magistrate Judge James Orenstein in Brooklyn seeking historical cell-site location for two cell phones used by a particular suspect.

Read more on The Volokh Conspiracy.

Julian Sanchez responds to Orin’s commentary in, “Blurry Lines, Discrete Acts, and Government Searches.” Julian writes, in part:

Orin’s point about the seeming arbitrariness of these determinations—and the difficulties it presents to police officers who need a rule to rely on—is certainly well taken. The problem is, the government is always going to have substantial control over how any particular effort at information gathering is broken into “acts” that the courts are bound to view “discretely.” If technology makes it easy to synthesize distinct pieces of information, and Fourth Amendment scrutiny is concerned exclusively with whether each particular “act” of information acquisition constitutes a search, the government ends up with substantial ability to game the system by structuring its information gathering as a series of acquisitions, each individually below the threshold.



Behavioral Advertising may be too aggressive?

http://www.pogowasright.org/?p=22259

Do certain mobile apps violate the Computer Fraud and Abuse Act?

April 6, 2011 by Dissent

Caroline Belich writes:

According to the Wall Street Journal and other sources, federal prosecutors in New Jersey are investigating whether certain mobile applications for smartphones have illegally obtained or transmitted information about their users. Part of the criminal investigation is to determine whether these app makers made appropriate disclosures to users about how and why their personal information is being used. The app makers subpoenaed include the popular online music service Pandora.

Examples of information disclosed by these app makers may include a user’s age, gender, location, and also unique identifiers for the phone. The information may then passed on to third parties and advertising networks. The problem is that users may be unaware that their information is being accessed by a smartphone app because a maker failed to notify them.

As a result, this failure to notify may violate the Computer Fraud and Abuse Act (18 USC 1030).

Read more on Internet Cases.



A data breach as a labor negotiation tactic? Lots of unanswered questions here, and I'm too ignorant to see how this aids negotiations in any way.

http://www.databreaches.net/?p=17512

US Airways Pilots Express Outrage over Data Theft

April 6, 2011 by admin

A press release from the U.S. Airlines Pilots Association reminds us yet again how labor disputes may increase the risk of a privacy breach or data breach:

The pilots of US Airways, represented by the US Airline Pilots Association (USAPA), today expressed their outrage at the airline’s acknowledgement that its management personnel aided in unauthorized distribution of the highly confidential personal data of thousands of pilots. USAPA is currently cooperating with a criminal investigation into this matter.

US Airways recently admitted that a management pilot accessed and transferred a confidential database containing the personal information of thousands of US Airways pilots, including names, addresses and Social Security numbers. The transferred database may also have included pilot passport information. The data was given to a third party pilot group, which has acted to disrupt the ongoing negotiations between USAPA and US Airways currently under the auspices of the National Mediation Board and undermine USAPA’s bargaining objectives.

“US Airways pilots are infuriated at the data breach perpetuated by a management official of the company for which they work,” stated Mike Cleary, president of USAPA. “Thousands of us have been exposed to identity theft that could impact us for the rest of our lives. Further, as the Federal Bureau of Investigation has yet to determine the extent of the breach, we are concerned about the security of ALL information provided to US Airways – including our families’ personal information. US Airways collects personal information on US Airways employees’ family members and information from passengers, such as credit card data.”

USAPA has been working with the FBI since November 2010 in an attempt to determine the exact scope of the data breach. In his letter alerting the FBI, the Transportation Security Administration and the Federal Aviation Administration to USAPA’s concerns, President Cleary said,

“We believe the unauthorized access to this confidential information may pose a direct threat to national security, our represented pilots’ safety, and their professional standing.

“The exact scope of the breach is unknown, but unauthorized access to airline pilot passport numbers coupled with pilot residential addresses could potentially be used to forge U.S. commercial airline pilot passports, or identities, in order to gain access to international or domestic commercial aircraft or flights – thereby posing a direct threat to our nation’s security.”

“In light of this breach, USAPA has concluded that US Airways cannot be trusted with confidential or sensitive information,” President Cleary said today. “The union is also extremely disappointed by the Company’s lack of aggressive action to address this issue, first denying that a significant breach had even occurred, then equivocating concerning the extent of that breach, all the while taking no remedial action against the Company personnel involved in the breach. Significantly, the Company has also failed to take steps to provide lifelong protection to the pilots directly affected and adequately address the potential national security issues for all of our pilots and passengers.”

USAPA is committed to spending the time and resources necessary to protect its members, while it believes that US Airways sits on the sideline. US Airways management has informed USAPA that it is relying on the “assurances” of the very parties responsible for the data breach that the confidential information will not be misused.

“This is, of course, ludicrous,” President Cleary responded. “It’s analogous to a bank robber promising he will not spend the stolen loot. We are demanding swift and aggressive action as we simultaneously take significant steps to hold both US Airways and the specific responsible parties liable for the damage caused.



For my Disaster Recovery students. How easy would it be to disrupt the Internet in your neighborhood? The Internet was designed to re-route data around links taken out in a nuclear war – but you have to have more than one link for that to work.

http://tech.slashdot.org/story/11/04/07/0234214/Elderly-Georgian-Woman-Cuts-Armenian-Internet?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Elderly Georgian Woman Cuts Armenian Internet

"An elderly Georgian woman was scavenging for copper with a spade when she accidentally sliced through an underground cable and cut off internet services to nearly all of neighboring Armenia. The fibre-optic cable near Tiblisi, Georgia, supplies about 90% of Armenia's internet so the woman's unwitting sabotage had catastrophic consequences. Web users in the nation of 3.2 million people were left twiddling their thumbs for up to five hours. Large parts of Georgia and some areas of Azerbaijan were also affected. Dubbed 'the spade-hacker' by local media, the woman is being investigated on suspicion of damaging property. She faces up to three years in prison if charged and convicted."