Wednesday, September 21, 2011


Interesting that this is treated as a breach. Do older X-rays include personal data 'burned' on the film?
By Dissent, September 20, 2011
Not the first time we’ve seen a breach like this and likely, it won’t be the last:
Barrels of X-ray film set to be destroyed were stolen from Good Samaritan Hospital in Baltimore by a man posing as a vendor employee, police said.
According to a Baltimore City police report, officers were called to the hospital Friday morning to investigate the theft of as many as two barrels of old X-ray film. Hospital officials said the films were “more than 5 years old” and the films “had been put aside to be either destroyed or recycled.”
“It appears he did this by misrepresenting himself as the vendor responsible for the disposing and/or the recycling of those items,” Baltimore police spokesman Kevin Brown said.
[...]
A statement released by Good Samaritan Hospital suggests the assailant’s motive may have been to extract and sell the silver contained in the films: “There is no clinical impact to patient care as medical reports associated with those films remain with the patient records. We are working diligently to determine the specific patients impacted by this occurrence so direct notification can be made to assist them.”
Read more on WBAL.


Is this the electronic equivalent of asking your neighbors about your biases?
Lawyers in Murray trial using Facebook, Twitter to screen jurors
After approximately a week of poring over 145 jury questionnaires, lawyers in the trial of Michael Jackson's doctor are due in court Wednesday to discuss removing jurors whose answers they believe should disqualify them from hearing the case.
But legal experts say prosecutors and defense attorneys in the Conrad Murray trial will be doing more than simply screening jurors based on their answers to the more than 100 questions filled out on September 8 and 9. They'll also be scrutinizing what prospective jurors may have said outside the courthouse and online about events surrounding the June 2009 death of pop star Michael Jackson.
… But Gabriel added that it is rare for a legal team to have time to do such vetting of prospective jurors, because jury selection is completed within hours in a vast majority of trials, [Sounds like a business opportunity: Instant social media search Bob] not over several weeks as in the Anthony case (and most likely Murray's as well).


Interesting but not unexpected statistics.
TalkTalk ISP Study Claims Half of Internet Connected Homes Suffer Cyber Attacks
A new TalkTalk commissioned YouGov study into the broadband habits of 19,828 UK adults ('Life Online') has claimed that almost half (45%) of all internet connected homes have suffered some form of cyber-attack, although this apparently included being "bombarded with unwanted 'pop-up' advertising".
The ISP estimates that more than 700,000 attempts at identity theft were also mounted on Britain’s homes during the first quarter of 2011 and that 89% of emails sent last year were SPAM (unwanted or malicious junk). The single most prominent form of cyber-attack was Adware (35%) related, which uses various methods (e.g. keyloggers) to collect sensitive private information from your computer.
The vast majority of respondents to the survey agreed that it was important to protect their internet connections, yet 10% of broadband ISP customers said they relied "solely on their own vigilance" instead of using security software. Personal vigilance alone is not enough to spot all threats, many of which can creep in silently.
Elsewhere 23% of parents claimed to have seen their children (those aged 6-17) accidentally download a virus on to the home computer and 5% witnessed them giving out personal information online; some 73% of parents sight this as being their "biggest concern".

(Related) Still, one out of three is better than 45%...
Data breaches affect 2m in Mass.
September 21, 2011 by admin
Hiawatha Bray reports:
Personal information from nearly one out of three Massachusetts residents, from names and addresses to medical histories, has been compromised through data theft or loss since the beginning of 2010, according to statistics released yesterday by the office of Attorney General Martha Coakley.
[...]
The attorney general’s office has received 1,166 data breach notices since January 2010, including 480 between January and August of 2011. About 2.1 million residents were affected by the various incidents, though it’s unknown whether any of them were actually defrauded as a result of the data leaks.
Of the reported incidents, 25 percent involved deliberate hacking of computer systems containing sensitive data. Another 23 percent involved accidental sharing of information with unauthorized people, such as sending faxes or e-mails with personal information to the wrong recipient. In 15 percent of cases, retailers reported the theft of customer credit card numbers. Data was also lost through thefts or accidental losses of laptop computers and paper documents, or in cases in which workers deliberately gained unauthorized access to client files.
Read more on Boston Globe.


I wonder if there will be a backlash if the cops start mailing out tickets based on this “evidence”
OnStar Begins Spying On Customers’ GPS Location For Profit
September 20, 2011 by Dissent
Jonathan Zdziarski writes:
I canceled the OnStar subscription on my new GMC vehicle today after receiving an email from the company about their new terms and conditions. While most people, I imagine, would hit the delete button when receiving something as exciting as new terms and conditions, being the nerd sort, I decided to have a personal drooling session and read it instead. I’m glad I did. OnStar’s latest T&C has some very unsettling updates to it, which include selling your personal GPS location information, speed, safety belt usage, and other information to third parties, including law enforcement. [Are the cops fishing for violators? Bob] To add insult to a slap in the face, the company insists they will continue collecting and selling this personal information even after you cancel your service, unless you specifically shut down the data connection to the vehicle after canceling.


Gary Alexander sends an interesting article... It is far easier to say “NO!!!” to everything than to actually read the laws and regulations and make an informed determination. Lots of lawyers (managers too) think there job is to say no. I think their job is to help me accomplish my job. And don't get me started on sending things by FAX (first patented before the Civil War) which requires someone to print out data, fax it, then someone else gets to type it back into a computer.
HIPAA on phones, faxes and e-mail
My wife Deborah Black (light of my life) is a neuropsychiatrist who works at two different clinics. Sometimes patients are referred from one clinic to the other, and the question arises of how to transmit the details of their medical record from one team to the other.
Anything concerning the privacy of medical data in the USA is governed by the Health Insurance Portability and Accountability Act (HIPAA) passed in 1996. The legislation is complex, and the U.S. Department of Health & Human Services (HHS) has set up an extensive Web site with detailed information and instructions about HIPAA.
One of the questions I’ve been asked by my wife’s staff is whether it is acceptable to send medical information by fax or e-mail; some of the security and information technology staff at her clinics have flatly forbidden such transmission, asserting baldly that HIPAA forbids such transmission. Unfortunately, their medical records systems are incompatible, so the data cannot be sent automatically from one clinic to the another with appropriate encryption and other safeguards.
However, the IT/security staff are wrong in their absolute interdiction of faxes and e-mail for medical records.
In the document entitled, “Does the HIPAA Privacy Rule permit a doctor, laboratory, or other health care provider to share patient health information for treatment purposes by fax, e-mail, or over the phone?”, the HHS writes (quoting in full),
Yes. The Privacy Rule allows covered health care providers to share protected health information for treatment purposes without patient authorization, as long as they use reasonable safeguards when doing so. These treatment communications may occur orally or in writing, by phone, fax, e-mail, or otherwise.


For my Computer Security students (all of whom use flash drives)
7 Best Antivirus To Save Your PC From Infected USB Flash Drives


For my Ethical Hackers.
Smart meters reveal TV viewing habits
September 21, 2011 by Dissent
Researchers at the Münster University of Applied Sciences have discovered that it is possible to use electricity usage data from smart electricity meters to determine which programmes consumers are watching on a standard TV set. The experiments were carried out as part of the state-funded DaPriM (data privacy management) project. By analysing electricity consumption patterns, it is, in principle, also possible to identify films played from a DVD or other source.
Read more on H-Online.
[From the article:
Until now, the general assumption has been that it would be possible to use typical electricity consumption data from the smart meter for different appliances to determine whether a customer had prepared his or her dinner in the microwave, on the hob or in the oven, but nothing more. That possibility had already spurred data protection officials in the USA, where smart meters are already widely used, into action – they demanded precise regulations on how electricity meters deal with and protect collected data.
Second by second data transfer makes it possible to carry out much finer analysis. In the opinion of the Münster-based research team, this calls for a tightening of data protection regulations. One solution might be to increase the polling interval or simply to transfer a statistical summary to the electricity generator or provider. This would make the high resolution consumption data required for close analysis unavailable. Either way, the consumer is reliant on the provider taking the appropriate measures.


Ditto Use the printer to make a skimmer that fits over the card slot on an ATM.
"An ATM skimmer gang stole more than $400,000 using skimming devices built with the help of high-tech 3D printers, federal prosecutors say. ... Apparently, word is spreading in the cybercrime underworld that 3D printers produce flawless skimmer devices with exacting precision. Last year, i-materialize blogged about receiving a client's order for building a card skimmer. In June, a federal court indicted four men from South Texas whom authorities say had reinvested the profits from skimming scams to purchase a 3D printer."

Tuesday, September 20, 2011


“etc.” is a weasel word that makes me (and the victims?) suspect much more was taken.
By Dissent, September 19, 2011
Yanez Dental Corporation in California recently reported a data breach to HHS.
In a notice on their web site dated June 15, they write, in part:
Our dental office was burglarized (5/22/2011). We have reported this incident to the police for investigation. The vandals stole three of our computers among other things. Personal information stored in these computers included names, birthdate, address, Social Security Number, telephone number, etc. It is important to mention that we are not aware that any personal information has been accessed or used inappropriately. For the purpose of security, each of the three computers has four level of passwords protection. However, we feel it is important for us to inform you of any potential situation, and explain steps you can to prevent or reduce any potential risk of identity theft or fraud loss.
[...]
According to HHS’s breach tool, 10,190 patients had information on the stolen computers.
I’m not quite sure I understand what the practice means by the “etc.” in types of information. Does “etc” include insurance account numbers, any financial information, etc.? It would have been helpful for them to be more inclusive in their description.


When will the default be “Encrypt sensitive data?” Demanding that one of their “Business Associates” improve their security isn't sufficient. All of their associates should be required to follow reasonable security practices.
By Dissent, September 19, 2011
On August 8, the Saint Barnabas Health Care System in New Jersey publicly disclosed a breach involving a Business Associate, MedAssets:
MedAssets, Inc., an independent revenue management and supply chain company that provides certain administrative and business services to the Saint Barnabas Health Care System, informed us on July 1, 2011 that an unencrypted external computer hard drive was stolen on June 24, 2011, from a MedAssets employee’s car, parked in a restaurant parking lot. The hard drive contained personal information used to determine eligibility for governmental benefits for certain patients of our six acute care hospitals.
The data contained patient names and for each such patient, information from one or more of the following categories: Medical Center account number, medical record number, date of birth, Medical Center charges incurred, amounts paid to the Medical Center, information on health insurance, eligibility for applicable governmental benefit programs and/or Medical Center admission and discharge dates. Social security numbers were included for about seven percent of the affected patients. The hard drive did not include any patient addresses, other financial information, or any clinical information regarding the patient’s care.
… MedAssets has provided written confirmation that it is implementing improved privacy safeguards to avoid similar incidents in the future, including eliminating the use of all unencrypted hard drives used for data back-up by its employees and strengthening the enforcement of its existing policy prohibiting their use.
… This is not the first time that Saint Barnabas has reported a breach involving a business associate. In September 2010, they disclosed a breach involving KPMG. Also last year, Newark Beth Israel Medical Center disclosed a web exposure breach involving Professional Transcription Company.
Saint Barnabas wasn’t the only hospital system affected by the MedAssets breach, however. Patients at the Cook County Health and Hospitals System in Chicago, Illinois was also affected.
… An unencrypted drive left in a car in a restaurant parking lost. Heads should have rolled for that one. What did this breach cost in terms of investigation and notifications? Those costs will ultimately drive up the cost of our health care. I find this type of breach inexcusable in this day and age and wish HHS/OCR would hand out a hefty fine or two to send the word that entities had damned well make compliance with good security practices more of a priority.


Think of it as an automated sideshow barker...
Inspired By ‘Minority Report,’ Immersive Labs Raises $810K For Digital Display Recognition
Immersive Labs is working on futuristic advertising displays like those in the well known book and film Minority Report, which tailor advertising to the individual viewer. Immersive Labs’ digital signs use cameras and facial recognition technology to determine viewer characteristics like gender, age, distance and time spent viewing the ad in order to then serve up the advertising that would be most relevant (see the demo video below).
The targeting technology has shown an over 60% increase in viewer attention time during pilot tests, according to CEO Jason Sosa.


What is the cost of a security breach? I'm sure it was a “separate” company to firewall the liabilities, but there must have been some assets...
twoheadedboy writes
"DigiNotar, the Dutch certificate authority which was recently at the centre of a significant hacking case, has been declared bankrupt. The CA discovered it was compromised on 19 July, leading to 531 rogue certificates being issued. It was only in August that the attacks became public knowledge. Now the company has gone bankrupt, parent firm VASCO said today. VASCO admitted the financial losses associated with the demise of DigiNotar would be 'significant.' It all goes to show how quickly a data breach can bring down a company."
Adds reader Orome1:
"This is unsurprising, since a report issued by security audit firm Fox-IT, who has been hired to investigate the now notorious DigiNotar breach, revealed that things were far worse than we were led to believe."


What is a violation of Privacy worth?
News Corp. Paying Phone Hack Victim’s Family $4.7 Million
September 19, 2011 by Dissent
Damon Poeter reports:
News International will reportedly pay the family of a British murder victim about £3 million ($4.7 million) in a settlement to close a phone-hacking case that led to the closure of the News of the World tabloid and rocked Rupert Murdoch’s News Corporation media empire to its core.
The settlement includes a £2 million payment to Milly Dowler’s family and the donation of an additional £1 million to charity, Reuters reported Monday, citing “sources close to the case.”
Read more on PC Magazine.

(Related) Hacking a phone is so easy, even a caveman could do it...
Il: Police Arrest 22 in Phone Tapping Case
September 19, 2011 by Dissent
Gavriel Queenann reports:
Israel’s Hebrew-language Maariv reported Monday that Israel Police arrested 22 ‘private investigators’ for installing spyware on mobile phones allowing access to private conversations and text messages.
Documents filed in a Rishon Letzion court revealed the Israel Police Lahav 433 unit and Computer Crimes unit conducted a covert protracted investigation into 11 detective agencies allegedly using software previously reserved for the security services.
Read more on Arutz Sheva.
[From the article:
The software allows mobile phones to be remotely accessed without leaving a trace or revealing to the owner they are being surveilled. All calls, text messages, and e-mail messages are transmitted to and from the infected phone can be received and recorded in real time.
A spokesman for the Israel Police said investigators believe hundreds of people across the country are using similar software to spy on competing businesses, family, or romantic partners.
[Try it yourself!
Tap A Cell Phone To Track Your Spouse Or Significant Other
How To Tap A Cell Phone | Can You Really Tap A Cell Phone?
Is Your Cell Phone Bugged?


I'm not sure I'd be bragging about this just yet. However, it does look like “location tracking” is getting some Privacy consideration.
Location based social network Foursquare has quietly released a new feature that allows places user categorize as their homes to be included in the system but not expose their exact addresses. Venues categorized as homes will now show up as a general area on a map, instead of a pin and street number, as restaurants and stores are displayed. The move was first reported by the independent blog AboutFoursquare.
It's a great little change that will enable users to check in at home without exposing too much information. This new feature will also allow people whose homes were listed on Foursquare against their wishes to easily obscure their addresses. [How does one learn if their home address is listed on Foursquare? Bob] Respecting home/away privacy is a key part of making people feel safe enough to expose their location at all, anywhere. Foursquare's approach is reminiscent of the new private location geofences Flickr launched earlier this month.
[From the AaboutFoursquare blog:
It appears foursquare has gone through and properly categorized lots of venues that appear to be homes, either by name or by checkin pattern (i.e., only one person has checked in). The number of venues named “home” but without a category has declined drastically over the past few days.
Venues that didn’t get caught by foursquare won’t receive any of the privacy protections, so it’s important for users to take the time to make sure their homes are properly categorized. If you have friends who’ve abandoned foursquare but left their miscategorized home venues in place, it might be worth a nudge to get them to come back to foursquare to get their home updated properly, too.
This is a great enhancement to user privacy on foursquare. Thousands of users have added their homes without realizing the privacy implications of posting that information on the internet, so it’s nice that foursquare has taken these proactive steps to help increase the security of their homes.
[In the same article, but completely(?) unrelated:
Below, a video about Flusquare - an interesting mash-up between Foursquare and CDC flu reports. Foursquare integration lets the app determine where you went when you were contagious! This little app hints at the potential of consumer geolocation technologies for the future.


The data is public and as far as I know legal to aggregate. So, aside from self-promotion, what;s the fuss about? (Or do the Senators have something they want to hide?)
"Social Intelligence Corp's online employment screening service, which preserves users' social media profiles and other data for use by potential employers, infringes on consumers' privacy and could be a violation of the law according to Senators Richard Blumenthal (D-CT) and Al Franken (D-MN). The Senators wrote to Social Intelligence Corp on Monday demanding answers to a host of questions about the service and how it collects data."
[From the article:
The firm says it looks for publicly posted content that is racially insensitive, sexually explicit, or demonstrates clearly illegal activity. Flagrant displays of weaponry are also flagged. Content limited only to users' friends is not included in the searches.
… The letter also suggests that Social Intelligence's practice of taking screenshots of social media profiles and pictures may violate the sites' terms of service.
"More troubling than the apparent disregard of these websites’ terms of service are what appear to be significant violations of users’ intellectual property rights to control the use of the content that your company collects and sells," the letter states, noting that pictures taken from sites like Flickr and Picasa are often licensed by the owner for a narrow set of uses.


Politicians without paper?
"The British government is examining whether it could save money by getting rid of its printers and giving civil servants free iPads instead. The head of the UK government skunkworks told silicon.com that if he got rid of all of a major government department's printers and gave staff iPads, the savings on printing costs would pay for the tablets in less than 18 months. The UK parliament has already let tablets into the debating chamber, with politicians already starting to choose to use tablets rather than bundles of papers in debates."


For my Ethical Hackers...
How To Change The Apple ID On Your iPod Touch/iPhone


For my Math students
Desmos, a free online graphing calculator that I reviewed in June, recently added a handful of new options that should be appealing to mathematics instructors and students. The new features enable better handling of strict inequalities, polar inequalities, internalization, slider bars, and graph tracing. The video below provides an overview of the Desmos graphing calculator.


“I know it's here somewhere...”
Figure Out Folder Contents With Better Directory Analyzer
Better Directory Analyzer, which I will from now on call BDA, is a simple freeware program that scans through the contents of any selected folder and spits out more information about it than you thought was possible. All scanned files can be sorted in a handful of different ways, which helps you quickly find certain files that you may be looking for. So how is this helpful compared to Windows Search?
Although Windows XP‘s version of Windows Search actually packed more of a punch, Windows 7‘s version only lets you search by filename, file size, and date modified (without using hidden operators). Windows 7 users can find benefit the most by using BDA as there are many different parameters to search and select files.


Worth a look?
3 Light & Simple Ways To Take Screenshots In A Snap


A word to the wise...
Transfer Your Delicious.com Bookmarks By September 23 Or Lose Them [News]

Monday, September 19, 2011


This could be serious both in potential information loss but also in reputation.
Missile maker sees network hacked
The Reuters news agency said Japanese newspaper Yomiuri reported that information from Mitsubishi's computer system was stolen in the attack. A representative of the company confirmed the attack, Reuters reported, but said the company was still looking into whether any data had been taken.
The Yomiuri report said about 80 infected computers were found at Mitsubishi headquarters in Tokyo and various facilities in other areas of Japan, according to Reuters.


Increasing SPAM results in increased numbers of compromised systems. The question is: What will they be used for?
The unknown explosion of malicious email attachments
Commtouch, the original equipment manufacturer (OEM) for many security vendors dealing with anti-Spam and anti-Malware protections, discovered a massive jump in malicious email attachments last month. Beyond concerns regarding extra volume, the problem is no one seems to know why there was a sudden spike.
Since August, someone unknown - perhaps a group - has been targeting millions of systems worldwide with email containing malicious attachments. However, this isn’t the typical type of Spam, this is direct malware distribution on a mass scale resulting in abnormally high levels of malicious messages.
The pattern has been seen before: Fake messages with malicious attachments alleged to contain details on UPS and FedEx deliveries, credit card charge errors, and so on. Since the fall of the Rustock botnet, Spam levels across the globe have fallen, but, despite that, the volume of malicious email attachments has skyrocketed.
In August, Commtouch’s monitoring points noticed an average of a few hundred million to two billion malicious messages per day. On August 8, that number exploded to 25 billion Malware-laced emails.
“A review of several end-user forums reveals that the email campaigns have been successful – with many users having opened the malware attachments. The infection rate is generally linear – the more malware is emailed, the greater the final number of infections.


“Them pesky illegal immigrants are a problem. Let's make everyone who is not illegal prove it!”
E-Verify: De Facto national ID and the end of privacy
September 19, 2011 by Dissent
John Whitehead has this editorial in Desoto Times Tribune:
As technology grows more sophisticated and the American government and its corporate allies further refine their methods of keeping tabs on citizens, those of us who treasure privacy increasingly find ourselves engaged in a struggle to maintain our freedoms in the midst of the modern surveillance state.
The latest attack on our right to anonymity and privacy comes stealthily packaged in the form of so-called job protection legislation. Introduced by House Judiciary Committee Chairman Lamar Smith (R-Texas) in June 2011, H.R. 2885 (formerly H.R. 2164), the “Legal Workforce Act,” is being marketed as a way to fight illegal immigration and “open up millions of jobs for unemployed Americans and legal immigrants.” [Sure. Bob] However, this proposed federal law is really little more than a Trojan horse, a backdoor attempt by the powers-that-be to inflict a de facto National ID card on the American people.
Read more on Desoto Times Tribune.

(Related) Another way to identify individuals in the herd?
Massive Biometric Project Gives Millions of Indians an ID
Kiran has never touched or even seen a real computer, let alone an iris scanner. She thinks she’s 32, but she’s not sure exactly when she was born. Kiran has no birth certificate, or ID of any kind for that matter—no driver’s license, no voting card, nothing at all to document her existence.
… Now, for the first time, her government is taking note of her. Kiran and her children are having their personal information recorded in an official database—not just any official database, but one of the biggest the world has ever seen. They are the latest among millions of enrollees in India’s Unique Identification project, also known as Aadhaar, which means “the foundation” in several Indian languages. Its goal is to issue identification numbers linked to the fingerprints and iris scans of every single person in India.


This will be important for Windows 8, which assumes touchscreens are everywhere...
"Open up a cardboard tube, roll out a transparent film just millimeters thick, apply it on a flat object and *tada* you've got an interactive touch surface. Cambridge-based Visual Planet just launched its new massive-sized multitouch thin film drivers so you can create touchscreens from 30 to 167 inches in size! Their touchfoil is a transparent nanowire embedded polymer capable of sensing the touch of a finger, or even pressure from wind and translating that to a computer interface. It works on glass, wood, and other non-conductive surfaces."


Interesting, but not enough to drag us out of the recession...
Study: Facebook ‘App Economy’ Adds Over 200K Jobs, Contributes More Than $15B To The U.S. Economy
Although the U.S. employment and jobs economic outlook is bleak, a new study released today reports that Facebook is creating a thriving economy around its social network. According to new research from University of Maryland, the Facebook App Economy has added at least 182,000 new jobs and contributed more than $12.19 billion in wages and benefits to the U.S. economy this year. Using more aggressive estimates, the Facebook App Economy created a total of 235,644 jobs, adding a value of $15.71 billion to the U.S. economy in 2011.
… As we’ve written in the past, 2.5 million websites have integrated with Facebook, and Facebook users install 20 million apps every day. Every month, more than 250 million people engage with Facebook on external websites. Especially with the viral growth of gaming apps, as well as the use of the ‘Like’ button used by brands, more and more developers are building off the Facebook platform to tap into the network’s 700 million-plus userbase.

Sunday, September 18, 2011


Wouldn't it be simpler and safer to “presume guilt?” This will definitely go bad at some point (HIV Positive “suspect,” needles, thrashing around)
WY: Police take first forced blood draw
September 17, 2011 by Dissent
Lindsey Erin Kroskob reports:
Cheyenne police are believed to be the first in the state to forcibly take a person’s blood via court order under the state’s new DUI law.
Statutes changed July 1, allowing officers to obtain a search warrant to take a suspected intoxicated driver’s blood if he or she refuses to willingly provide a sample.
Prior to the change, warrants were only obtained for individuals involved in crashes with serious injury or fatality.
“Usually, once we have the warrant they go ahead and cooperate with the blood draw,” Chief Brian Kozak said. “This is the first individual who refused to cooperate and had to be restrained.”
Read more on Wyoming Tribune Eagle.

(Related) Blood isn't just alcohol levels...
By Dissent, September 17, 2011
@Bainesy1969 has a thought-provoking blog entry on the retention of DNA samples vs. DNA profiles in the UK and what EU law requires. He begins:
On 26 July 2011 The Telegraph reported that “Innocent people’s DNA profiles won’t be deleted after all, minister admits”. It said that
“police will retain DNA profiles in anonymised form, leaving open the possibility of connecting them up with people’s names, ministers have admitted”.
In S and Marper v United Kingdom [2008] ECHR 1581 the European Court of Human Rights held that indefinite retention by the police of fingerprints and DNA samples of two people who had been arrested but not convicted of criminal offences was a breach of their rights under Article 8 of the European Convention on Human Rights (overturning a decision upheld at each instance in the English courts).
The Protection of Freedoms Bill proposes, accordingly, to amend the Police and Criminal Evidence Act 1984 (“PACE”) so that – broadly - a lawfully taken DNA sample (and fingerprints) must be destroyed after three (or in some cases five) years if the suspect has not been convicted of an offence to which the sample relates


I have seen many similar articles, but still have no idea what the tactical objective is. How will the computer be used to improve what subject area(s)? How will they measure the results? Will they train the teachers or just say, “Make this work!” (By the way: $200,000 / 250 students = $800 per student. Minus the $475 for the iPad that leaves $375 for the case. Must be some case!)
"'An Auburn, ME school district spent more than $200,000 to outfit every one of its 250 kindergartners with [iPads], along with sturdy cases to protect them. School officials say they are the first public school district in the country to give every kindergartner an iPad. Mrs. McCarthy says the tools give her 19 students more immediate feedback and individual attention than she ever could.' [Feedback at what level? I doubt they will even be able to Google (unless Maine kids read and write better than average). Bob] Will this improve low test scores, or be another case where spending more money does not produce a better educational outcome?"


Geeky tools...
NetbootCD: Install Ubuntu, Fedora, Debian & More From One CD [Linux]
Tired of burning a new CD every time a new version of your favourite Linux distro comes out? Then stop. Use NetbootCD to download and install your choice of Ubuntu, Debian, Fedora, openSUSE, Mandriva, CentOS or Slackware from a single disk. This handy disk downloads and runs the net installation tools for several distros, and is always capable of finding the latest version of your Linux operating system. Burn this tool once and you’ll never need to burn a Linux distro to CD again.
Using NetbootCD isn’t necessarily easy. You’ll need to learn to use text-based installers instead of the GUI versions found on live CDs. To me though, this is a small price to pay to contain my steadily-growing pile of Linux CDs.
First things first, you’ll need to download NetbootCD and burn the ISO to CD.
… If you like not to waste CDs but still use GUI installation tools, I suggest you check out Unetbootin or Linux Live USB Creator. Both of these tools make it possible to boot Linux from a USB drive or an SD card.

Saturday, September 17, 2011


Sony takes another step to ensure “Security.”
Use Sony's PlayStation Network, Waive Rights to Class-Action Suit?
… As first discovered by The Examiner, Sony updated its PlayStation Network terms of service on September 15 to ban class-action lawsuits against the company.
"Any dispute resolution proceedings, whether in arbitration or court, will be conducted only on an individual basis and not in a class or representative action or as a named or unnamed member in a class, consolidated, representative, or private attorney general action unless you and [Sony] agree to do so in writing," according to the updated terms.


It is possible to allow trading freedom while still monitoring risk. When would UBS managers want to be informed about unusual trade volumes or risk levels? Apparently, never.
"With the benefit of hindsight, IT experts are claiming that technical countermeasures at Swiss bank UBS could have stopped rogue trader Kweku Adoboli running up a $2 billion loss."
If American Express and Visa can mine transaction data and put a stop order on credit cards when you unexpectedly buy gas out of state, it seems like there could be patterns to watch for when the amounts are in the billions, too.


Should anyone quote an intelligence source by name?
Ethiopian Journalist Flees Country Over Exposure in WikiLeaks Cable


Something for my students to grab...
Students Can Now Create Wi-Fi Hotspots For Free With Connectify [News]
Connectify is offering free accounts until October 15th to students with .edu addresses, allowing them to set up free Wi-Fi hotspots for their devices. Students can sign up for the service for free and receive their Connectify Pro license here by using their .edu email address.

Friday, September 16, 2011


Local. I want to assure you that this has absolutely, positively nothing to do with our new campus in Aurora. (probably)
CO: Aurora City Council members become victims of ID fraud
September 16, 2011 by admin
Carlos Illescas reports:
At least five Aurora City Council members have had their identities stolen over the past few weeks, and police have opened an investigation to determine whether the cases are linked.
Someone — armed only with the council members’ basic personal information — opened accounts in their names at a billing service for PayPal and ordered items at retail online sites.
Read more on Denver Post.
Update: Make that at least seven known victims.
[From the Post article:
The bills came from a company called Bill Me Later, a service of PayPal, the online site where people can order items and send money securely.
A Bill Me Later account, which doesn't require a credit card, is easy to open. Basic personal information, such as name, phone number, date of birth and the last four digits of a Social Security number, is all that is needed. [Think of it as making ID Theft really, really simple! Bob]


It's nearly impossible to kill a government program/boondoggle. There's a story about a Hollywood mogul who kept tons of obsolete and useless paperwork. When asked if it could be tossed out, he replied, “Okay. But make a copy of it first.”
U.S. Representative John Mica (R-Florida), the sponsor of the original House bill that helped create the TSA, has become an outspoken opponent of the agency. In a recent interview, "Mica said screeners should be privatized and the agency dismantled." Mica seems to agree with other TSA critics that the agency 'failed to actually detect any threat in 10 years.' Mica is the House Transportation and Infrastructure Committee Chairman and receives classified briefings on TSA. Perhaps we should trust him more than most people on this topic.
In an older ABC news article (ignore the unrelated video) Mica describes how he deals with security checkpoints. "He won't go through a full body scanner at an airport because 'I don't want them circulating pictures of my beautiful body' all over. He said he opts for a pat-down, and just 'closes his eyes and imagines a beautiful female.'"

(Related) Fortunately, there is (at least seasonal) work for terminated TSA employees. Makes you wonder what risks they are addressing... Killer Calves? Aggressive Ankles? Note that they skip “Thunder Thighs” and all the “politically incorrect” search areas – could be difficult to retrain TSA agents.
NFL wants pat-downs from ankles up at all stadiums
September 16, 2011 by Dissent
Michael McCarthy reports:
The NFL wants all fans patted down from the ankles up this season to improve fan safety.
Under the new “enhanced” pat-down procedures, the NFL wants all 32 clubs to search fans from the ankles to the knees as well as the waist up. Previously, security guards only patted down fans from the waist up while looking for booze, weapons or other banned items.
Read more on USA Today.
[From the article:
The NFL suffered damage to its family-friendly image when a South Carolina man was arrested for using an illegal stun gun on other fans at a New York Jets-Dallas Cowboys game Sunday night. [Note that the new pat-down procedure was “recommended” well before this incident. Bob]


That didn't take long to undo. I wonder what got through to the law makers? Was there a Facebook Frenzy? A Twitter “Outing of Twits?” Nah, just a lawsuit.
"The Missouri State Teachers Association (MSTA) has managed to secure another win in its battle against a new law regarding social networking with students. A repeal of the recently passed law has unanimously passed the Missouri state Senate."


Not sure if were narrowing toward a common definition or
raising more issues to debate.
UK: Privacy watchdog publishes e-privacy laws compliance guidance
September 15, 2011 by Dissent
The UK’s data protection watchdog’s guidance includes amendments made to the Privacy and Electronic Communications Regulations (PECR) in May. The changes transposed an EU Directive into national law.
The amendments included changes to rules on email marketing and for gaining internet users’ consent to ‘cookies’ – small text files that websites store about users’ online activity. It also introduced a requirement for organisations to inform the Information Commissioner’s Office (ICO) about all personal data breaches.
Read more on Out-Law.com
[From Out-Law:
[About Cookies:


Interesting vision of the future. With the growth of Cloud computing, I suspect this is true. And we need to bring more Smartphones into our computing classes...
"The build-out of 3G networks in developing countries, plus ultra-low prices from the likes of Samsung, will make the smartphone the sole computer of millions of citizens worldwide. And by 2016, 97 percent of smartphones are expected to use touchscreens. Now, don't get me wrong — I carry an iPad and an iPod Touch in my backpack and love touchscreens — but I still like a phone that fits in my pocket. However, I'm going to be in the minority five years from now, when the majority of wireless communicators will be smartphones."


Geeky stuff...

(Related) Will we be able to run Smartphone Apps on our desktop PC?
Forget Apps, Carbyn Has Built A HTML5 OS

Thursday, September 15, 2011


Virtual geopolitical boundaries for Cloud Computing. Inevitable, I suppose.
Deutsche Telekom Wants ‘German Cloud’ to Shield Data From U.S.
September 14, 2011 by Dissent
Deutsche Telekom AG’s T-Systems information technology unit is pushing regulators to introduce a certificate for German or European cloud operators to help companies guard data from the U.S. government.
T-Systems plans to lure customers by emphasizing the security of its servers, over which it delivers its Internet- accessed computing services, Reinhard Clemens, the division’s chief executive officer, told reporters in Bonn on Sept. 12. This includes shielding clients from government access such as that allowed by the U.S. Patriot Act, he said.
Read more from Bloomberg.


Is this a case of “techno-paparazzi,” teenage testosterone, or orchestrated publicity? (I'm sure the obvious solution has never occurred to these ladies...)
Celebs Hacked: Which Hollywood Hottie Will Have Nude Pics Leaked Next?
It's probably not the biggest surprise that some of Hollywood's biggest stars also happen to be exhibitionists (see Vanessa Hudgens—and quite a lot of her, as it turns out).
But on the heels of news that no less an authority than the FBI met with the clothes-eschewing starlet to investigate her latest scandalous nude photo leak, several more names have emerged as possible targets of the hacking ring.
Fifty names, to be precise. All female. And all of whom are no doubt shaking in their Louboutins at the prospect of becoming the next viral (and let's face it, in all likelihood naked) victim.

(Related) Maybe the hacking is just part of wholesale emails for sale?
New emails found in News of the World hacking scandal
''MANY tens of thousands'' of documents and emails that might be evidence of phone hacking have been found by the publisher of the now-defunct News of the World, Britain's High Court has been told.
The lawyer for News Group Newspapers, which had been ordered to search its internal mail system for any evidence of hacking of a list of public figures, said: ''Two very large new caches of documents have been [found] which the current management were unaware of.'' [That would be the Management in place after the business was shut down and everyone was fired? Bob]


The cost of Data Breaches. OR “How not to win friends...”
Uni hackers spoil exam
HACKERS from within the University of Tasmania have breached online exam security, leaving 600 nursing students without vital test results.
Angry students will be forced to sit a longer end-of-year exam that will now be worth a greater share of their final mark.
The closed-book test will now be worth 60 per cent instead of 40 per cent of their final mark for the compulsory unit.


I had never heard of Missoni, but apparently it is possible to generate as much excitement with fashion as with the latest teenage movie heroes or world series tickets going on sale.
Target’s Missoni launch: empty racks, crashed website, furious eBay bidding


“Security is as security does” F. Gump ...and it is much harder to retro-fit security than to design it in at the beginning.
Slow learning curve for DHS on infosec
September 14, 2011 by admin
Aliya Sternstein reports:
Security weaknesses in the computers that track money for the Homeland Security Department could lead to a substantial mistake in the agency’s financial statements, according to a federal audit.
KPMG analysts hired by the DHS inspector general to assess the department’s various financial systems for the fiscal year ending Sept. 30, 2010, found about 160 deficiencies, or inadequate controls, most of which — 65 percent — were repeats of the previous year’s problems. The IG office released a redacted version of the April 26 report on Monday.
Among the information technology inadequacies highlighted: ex-employees were still able to logon to their accounts and unauthorized outsiders successfully acquired user passwords from DHS personnel.
Read more on NextGov.


Privacy costs sales?
National Retail Federation opposes Sen. Leahy’s data breach notification bill
September 14, 2011 by admin
The National Retail Federation today voiced concern over data breach legislation set for consideration by a Senate committee, saying the bill is too broadly written and would lead to “notice fatigue” among consumers. [Assuming all retailers have lousy security? Bob]
[...]
French’s comments came in a letter sent today to members of the Senate Judiciary Committee. The panel is scheduled to consider S. 1151, the Personal Data Privacy and Security Act of 2011, sponsored by Chairman Patrick Leahy, D-Vt., Thursday morning.
The bill would require businesses to notify customers when “sensitive personally identifiable information” has been breached, such as in a number of recent data breach cases targeting retailers along with universities, government agencies, financial institutions and other businesses. But French said the bill’s definition of such information “is far reaching and covers common data items, the disclosure of which in most cases is inconsequential or does not lead directly to identity theft.” In one example, the breach of a customer’s name, address and date of birth would be deemed sensitive even though that combination of items alone “provides very little risk of leading to identity theft.”
What is there about “It’s not just about ID theft” that the NRF refuses to acknowledge?


Didn't take long for this brilliant idea to go south...
AU: Westfield Bondi caught in ‘find my car’ privacy flap
September 15, 2011 by Dissent
Less than one week after Ben Grubb reported privacy concerns or the potential for abuse of a new mobile app, he reports that there’s been a breach:
Westfield’s new mobile app has been caught leaking customers’ car number plate data on to the public internet, allowing for “anyone with the knowhow” to monitor when cars entered and exited its Bondi Junction shopping centre car park.
Sydney software architect Troy Hunt discovered the leak and posted about it on his blog yesterday, saying the hole could have potentially been used by stalkers, a suspicious husband tracking his wife, an aggrieved driver holding a grudge from a nearby road rage incident and a car thief with their eye on a particular vehicle.
Shortly after his blog was posted Westfield and the developer of the app’s technology, Park Assist, closed the hole.
Read more on The Age.


I don't think this is how it's supposed to work. But then, Texas is “a whole other country”
(Update) EPISD Lawyer: District Is Not Legally Liable For The Hacking
September 14, 2011 by admin
Gaby Loria reports:
El Paso Independent School District trustees heard from concerned employees and parents at a Tuesday evening board meeting regarding the hacking situation that put more than 70,000 students and employees at risk for identity theft.
[...]
The district alerted the community about the breach the day it found out about it and negotiated a deal with a credit monitoring company to offer a 50 percent discount on anti-identity-theft services.
[...]
The school board’s attorney, Anthony Safi, explained the district is not legally liable for the hacking and is therefore limited in the options it can offer the community. “The district does not have any liability for what occurred due to the doctrine of governmental immunity,” Safi said. “Because there is no liability, to pay (for services) could very well be considered a gift of public funds, which is prohibited.”
Read more on KVIA.
No liability? Did the Veterans Administration have no liability for the incident involving 26.5 millions’ veterans data or did they wind up having to compensate people for it in a huge settlement?
And if there is no liability under a theory of governmental immunity, then what recourse is there for individuals who now have incurred out-of-pocket expenses for something that they had no responsibility for?

(Related) I don't think government immunity even came up in this one...
Court: FERPA Doesn’t Shield Settlement Over Student Strip-Search Lawsuit
September 15, 2011 by Dissent
Matthew Heller writes:
After winning a public records lawsuit, On Point has learned that an Arizona school district paid a $250,000 settlement to a former student who was illegally strip-searched by school officials looking for prescription drugs.
An Arizona judge recently ordered the Safford Unified School District to produce the settlement agreement, finding that the privacy interest of the former student, Savana Redding, “is minimal when weighed against the greater public interest for transparency in the expenditure of public funds by the district.”
Read more on On Point.


I can remember a day when lawyers knew very little about technology... Oh wait, that day was today.
September 14, 2011
University of Victoria Law Student Technology Survey 2011
Via Rich McCue: UVic Law Student Technology Survey 2011 - "In addition to the technology questions we’ve been asking UVic Law students over the past nine years, we decided for the second year in a row to ask some extra questions about the mobile technology that students are arriving at Law School equipped with. This survey was completed by 139 incoming and transferring law students, which is a strong 90% plus response rate. Executive Summary:
  • 84% of incoming law students own “Smart Phones” that can browse the internet (up dramatically from 50% last year), with 42% of the total being iPhones, 13% Android and 27% Blackberry’s.
  • 19% of students own tablet devices or ebook readers.
  • 98% of students own laptops, and 16% own both a laptop and a desktop computer.
  • 50% of student laptops are Mac’s, up from 44% last year.
  • The average laptop price stayed basically the same as last year at $1,186, which is down from $1400 in 2007, and from $2,100 in 2004.
  • The students’ average typing speed was was 60 wpm. [Impressive, since I don't think they teach typing any more... Do they? Bob]
  • 72% of all students bring their laptops to school almost every day.
  • 55% of students use Gmail as their primary email account (up from 49% last year), 9% use UVic email and 22% Hotmail.
  • 60% of students identified MS Word as their favorite tool for collaborative document editing (down from 67%). 30% favor Google Docs (up from 27%) and 2% OpenOffice.
  • 58% of students report backing up their primary computer on a regular basis. 60% of those backing up do so to an external hard drive and 25% to a cloud storage solution.
  • 97% of students use Facebook (up from 91%) and 92% (up from 80%) would like to see law school events and activities published on Facebook as well as through the online faculty calendar

Wednesday, September 14, 2011


A most intriguing topic...
Damages From Hannaford Bros. Data Breach Dominate 1st Circuit Debate
September 13, 2011 by admin
Sheri Qualters writes:
A debate about the damages available to some to 4.2 million customers of the Hannaford Brothers Co. supermarket company whose financial information was compromised during a data breach dominated an oral argument at the 1st U.S. Circuit Court of Appeals.
The Sept. 8 hearing in Anderson v. Hannaford Brothers Co. concerned the appeal of a May 2009 order by District of Maine Judge D. Brock Hornby that rejected most of the plaintiffs’ claims.
Read about some of the exchanges between the judge and attorneys during oral argument on Law.com.


“No good deed goes unpunished”
Two years later, Texas parent who reported a breach gets prosecutors off his back and his laptop returned
September 13, 2011 by admin
A Texas parent who reported a school district security breach involving sensitive student records spent the next two years facing federal charges and trying to get his laptop back
Back in August 2009, DataBreaches.net reported that a parent had his work and personal computers seized by the FBI after he reported a security breach to his child’s school district, Leander ISD, and the Texas Education Agency. The parent, Mark Short, had discovered a working login on the district’s web site for a vendor-maintained database of students’ educational records. Having not received all of his child’s records that he had requested under FERPA (the federal law that gives parents the right to inspect all of their children’s education records), Short explored the database enough to confirm that it contained additional records on his child as well as sensitive information on other students. Short then notified the district of their security lapse and filed a complaint with the state.
Rather than thanking him for alerting them to their security gaffe and FERPA noncompliance, the district reportedly referred the matter to law enforcement, who treated him as a criminal.
Short informed DataBreaches.net that his personal laptop was seized by FBI agents without a search warrant “under the guise of concluding the investigation.” Short claims that he was not informed that he could refuse, and that after the FBI hung on to the computer for one week and he started insisting on its return, the FBI first obtained and served him with a search warrant for the laptop they had already seized.
Short has kept DataBreaches.net apprised of the case over the past two years, and now reports:
Two years after the FBI seized my personal property and just two days before a scheduled hearing to force the return of my computer, the US District Attorney has decided to not prosecute and return my computer.
This is after I was offered plea agreements two or more times and refused. Then I would get threatened that I would face prosecution if I did not accept.
The entire situation has been costly for Short, who lost his job due to the FBI showing up his workplace and seizing his work computer. It also created significant family stress. Short tells DataBreaches.net:
This has been a huge “pain in the ass” in order to assert individual rights and force a return of personal property – potentially improperly obtained; however, the government has really exceeded their mandate in this case. For them to seize my computer, refuse to return it (even after two years) without even making a formal charge is insane.
I can see why some people would rather just give-in to the federal government and simply forfeit their personal property. However, I cannot do that and allow the continued erosion of individual constitutional rights and freedoms.
In the meantime, the school district that had failed to turn over all his child’s records and that had failed to adequately secure access to the outsourced records has incurred no penalty for noncompliance with FERPA’s requirement nor for the breach.
What’s wrong with this picture?


Do you suppose this will come to the US? How powerful is the advertising lobby?
Google Lets Wi-Fi Owners Opt Out of Registry
September 14, 2011 by Dissent
Kevin J. O’Brien reports:
Google defused a confrontation with European privacy regulators by announcing on Tuesday that it would give the owners of Wi-Fi routers worldwide the option of removing their devices from a registry Google uses to locate cellphone users.
The change was made less than four months after European regulators warned that the unauthorized use of data sent by Wi-Fi routers violated European law. Google and other companies use the signals from Wi-Fi routers as navigational beacons, helping them pinpoint the locations of nearby cellphone users.
Read more on the New York Times.


This has been a SciFi staple for years.
Your face — and the Web — can tell everything about you
September 13, 2011 by Dissent
Bob Sullivan has an absolutely chilling article on Red Tape that I wish were SciFi but isn’t:
Imagine being able to sit down in a bar, snap a few photos of people and quickly learn who they are, who their friends are, where they live, what kind of music they like … even predict their Social Security number.
Now, imagine you could visit one of those anonymous online dating sites and quickly identify nearly every person there, just from their photos, despite efforts to keep their online romance search a secret.
Such technology is so creepy that it was developed, and withheld, by Google — the one initiative that Google deemed too dangerous to release to the world, according to former CEO Eric Schmidt.
Too late, says Carnegie Mellon University researcher Alessandro Acquisti.
“That genie is already out of the bottle,” he said Thursday, shortly before a presentation at the annual Las Vegas Black Hat hackers’ convention that’s sure to trouble online daters, bar hoppers and anyone who ever walks down the street.
Using off-the-shelf facial recognition software and simple Internet data mining techniques, Acquisti says he’s proven that most people can now be identified simply through a photograph of their face — and anyone can do the sleuthing. In other words, our faces have become our identities, and there little hope of remaining anonymous in a world where billions of photographs are taken and posted online every month.
Read more on Red Tape.


We have a “Software Security Engineering” class, which is really an eye opener for our students. Changes the way they think about building applications.
"Perhaps no segment of the security industry has evolved more in the last decade than the discipline of software security. At the start of the 2000s, software security was a small, arcane field that often was confused with security software. But several things happened in the early part of the decade that set in motion a major shift in the way people built software ... To get some perspective on how far things have come, Threatpost spoke with Gary McGraw of Cigital about the evolution of software security since 2001."