Friday, May 06, 2016

Surely no bank is still using Windows XP? 
New Trojan Targets Banks in US, Mexico
…   The Trojan, written in .NET apparently by Spanish-speaking developers, caught the attention of researchers because it relies on popular tools such as Fiddler, an HTTP debugging proxy server application, and Json.NET, a high-performance JSON framework for .NET.
The malware is delivered using an installer named “curp.pdf.exe” that is served on several compromised websites.  Once executed, the installer downloads three files to the Windows system directory: the main payload (syswow.exe), a Fiddler DLL file (FiddlerCore3dot5.dll), and a Json.Net DLL file (Newtonsoft.Json.dll).  The main payload is then executed and the installer terminates itself.
..   If the infected machine is running Windows XP or Windows Server 2003, the malware creates a registry entry for persistence, downloads a configuration file, and launches the Fiddler proxy engine.  For other Windows versions, the threat doesn’t create a registry entry, and it starts the proxy engine only after installing a Fiddler-generated root certificate.
Once it’s installed on a device, the malware collects system information and sends it back to its command and control (C&C) server, which responds with a configuration file containing different C&C locations and other instructions.  Json.NET is used to parse the server’s response and save it in an XML file.  This file contains the list of domains targeted by the malware — when users visit these domains, they are redirected to phishing websites designed to trick them into handing over their information.


A small local problem?
Kieran Nicholson reports:
State investigators are looking into a database breach at the Colorado Department of Transportation which could lead to identity thefts.
The breach of the Disadvantaged Business Enterprise program with CDOT was discovered recently and has been reported to the Colorado Bureau of Investigation, said Amy Ford, a CDOT spokeswoman.
[…]
“A probationary employee, who worked at CDOT from January 2016 to April 2016 and had access to confidential tax returns of DBE…firms, had been using personal information for improper purposes,” the notification letter, sent Wednesday, said.
Read more on Denver Post.


One way to control your music library? 
Apple Stole My Music. No, Seriously
“The software is functioning as intended,” said Amber.
“Wait,” I asked, “so it’s supposed to delete my personal files from my internal hard drive without asking my permission?”
“Yes,” she replied
…   What Amber explained was exactly what I’d feared: through the Apple Music subscription, which I had, Apple now deletes files from its users’ computers.  When I signed up for Apple Music, iTunes evaluated my massive collection of Mp3s and WAV files, scanned Apple’s database for what it considered matches, then removed the original files from my internal hard drive.  REMOVED them.  Deleted.  If Apple Music saw a file it didn’t recognize—which came up often, since I’m a freelance composer and have many music files that I created myself—it would then download it to Apple’s database, delete it from my hard drive, and serve it back to me when I wanted to listen, just like it would with my other music files it had deleted.

(Related) I will have to warn my students.
Apple Music’s new student membership option discounts the service by 50%
Amid news that Apple Music is getting a makeover come this summer, Apple today launched a new plan to boost subscribers to its streaming music service and competitor to Spotify, SoundCloud, Tidal and others.  It’s introducing an Apple Music student plan which will discount the service by 50 percent for those who are enrolled in an eligible college or university.
…   The student membership is rolling out now in the available markets.


Think about those little secondary issues?
Cheryl Clark reports:
When Sharp Grossmont Hospital officials realized anesthesia drugs were disappearing from surgery carts, they turned to video surveillance to catch those responsible.  In the process, they also captured many images of women undergoing surgery.
The video surveillance has raised questions about patient privacy and how well the hospital managed its storage of dangerous drugs.
Read more on KPBS.


Useful backgrounder?  Something our App students could build? 
How Shops Track You Using Your Smartphone


Coming soon to a law firm near you?
Gabe Friedman reports:
The privacy focused class-action law firm Edelson P.C. announced it has filed a federal class-action under seal that targets a Chicago-based regional law firm for data security holes.
On Thursday morning, name partner Jay Edelson tweeted that he had filed a motion to unseal the complaint against the unnamed firm.
[…]
In an interview with Big Law Business in March, Edelson explained that his firm had conducted a year-long investigation and identified 15 major law firms with inadequate cybersecurity.  He said his firm planned to file a series of lawsuits that target data security vulnerabilities at law firms on behalf of firm clients who have concerns about how their data is being protected.
Read more on Bloomberg BNA.
I’m hard-pressed to see how any such civil suit could prevail if there’s been no actual hack or data compromise of the defendants’ systems, but the FTC could sure as hell investigate or take action if infosecurity is that bad.
Either way, this will be one to watch.  If nothing else, if the lawsuit is unsealed, this could become a name and shame situation to get law firms off the dime to bring their A game on security.


Will this impact our student portal?  Possibly.
Joey Bunch reports:
A bill to protect students’ online privacy while they are doing their school work is on its way to the governor’s desk to be signed into law.
The Colorado House gave it final passage Thursday with a 65-0 vote.  House Bill 1423 would prevent educational software and app makers from collecting any data that can be linked directly back to an individual student.
Read more on Denver Post.

(Related)  Same question.  Different state.
Rep. Cristin McCarthy Vahey (D-Fairfield) praised passage of legislation that would protect student privacy by imposing certain restrictions on the use and sharing of student data.  HB 5469, AN ACT CONCERNING STUDENT DATA PRIVACY, was passed by the Senate Wednesday evening.  The bill now goes to the Governor’s desk.
The legislation would restrict how student information may be used by contractors, consultants, and operators of websites, online services, and mobile applications for schools.  Companies would be required to specify how they will secure student data and would be prohibited from using student data for advertising unless authorized by the contract.
Read more on Fairfield Sun.


Lacking demonstrable intelligence themselves (real or artificial) it amazes me that politicians are addressing these issues.  Were they frightened by the Terminator movie? 
White House worries about bad A.I. coding
…   President Barack Obama's administration released a report this week that examines the problem associated with poorly designed systems that, increasingly, are being used in automated decision making.
…   A second effort looks at our algorithmic future through a series of four workshops held across the U.S. to examine A.I.'s impact on society.
…   The U.S. will produce an A.I. report after it holds workshops beginning May 24 in Seattle.  That will be followed by meetings in Washington, Pittsburgh and New York City in July.


For some old school types. 
How to Get RSS Feed Updates Straight to Your Email Inbox
Maybe it’d be better to receive those RSS updates as emails.
Fortunately, this is possible!  You’ll need to know how to use IFTTT, which is a lovely web service that can perform all kinds of actions based on certain triggers.  In our case, whenever our RSS feed updates, we want IFTTT to send it to us as email.


Good news for the employability of my Computer Security students?
After ISIS, Americans Fear Cyberattacks Most


Perfect timing.  Today’s Computer Security lecture is on Networks.
Interop: 12 killer (and free) tools for network engineers
Visibility is key to troubleshooting network woes, but getting such access can be expensive.  To help out, a veteran networking pro shared with attendees of the Interop conference in Las Vegas his list of a dozen mostly free “killer” tools.


A real concern.  Likely to have a serious negative impact no matter who wins. 
Americans’ Distaste For Both Trump And Clinton Is Record-Breaking


I can predict which if my students will become this employee!

Thursday, May 05, 2016

Are we trying to get into the Guinness Book of World Records?  
Millions of stolen email credentials shared online by Russian hacker
Tens of millions of stolen credentials for Gmail, Microsoft and Yahoo email accounts are being shared online by a young Russian hacker known as "the Collector" as part of a supposed larger trove of 1.17 billion records.
That's according to Hold Security, which says it has looked at more than 272 million unique credentials so far, including 42.5 million it had never seen before.  A majority of the accounts reportedly were stolen from users of Mail.ru, Russia's most popular email service, but credentials for other services apparently were also included.
…   Some 40 million of the credentials came from Yahoo Mail, 33 million were from Microsoft Hotmail, roughly 24 million were from Gmail, and nearly 57 million were from Mail.ru, according to Reuters.  Thousands of others came from employees of large U.S. companies in banking, manufacturing and retail, and hundreds of thousands more reportedly were from accounts at German and Chinese email providers.


Now this is interesting.  Would you believe that LAPD would keep this from the FBI? 
LAPD hacked into iPhone of slain wife of 'Shield' actor, documents show
…   LAPD detectives found an alternative way to bypass the security features on the white iPhone 5S belonging to April Jace, whom the actor is accused of killing at their South L.A. home in 2014, according to a search warrant filed in Los Angeles County Superior Court.
The bypass occurred earlier this year, during the same period that the FBI was demanding that Apple unlock the iPhone 5C of San Bernardino shooter Syed Rizwan Farook.  The FBI eventually said it found another method for unlocking the phone without using Apple.
LAPD Det. Connie Zych wrote that on March 18, the department found a "forensic cellphone expert" who could "override the locked iPhone function," according to the search warrant.
The search warrant did not detail the method used by the LAPD to open the phone, nor did police reveal the identity of the cellphone expert.  It's also unclear what operating system April Jace's phone had.


The latest “warm and fuzzy” report. 
FROM 2013 to 2015, the NSA and CIA doubled the number of warrantless searches they conducted for Americans’ data in a massive NSA database ostensibly collected for foreign intelligence purposes, according to a new intelligence community transparency report.
The estimated number of search terms “concerning a known U.S. person” to get contents of communications within what is known as the 702 database was 4,672 — more than double the 2013 figure.
And that doesn’t even include the number of FBI searches on that database.  A recently released Foreign Intelligence Surveillance Court ruling confirmed that the FBI is allowed to run any number of searches it wants on that database, not only for national security probes but also to hunt for evidence of traditional crimes.  No estimates have ever been released of how often that happens.


A couple of interesting hypotheticals to kick around in my Computer Security class.
Susan Hennessey writes:
During the recent panel event at the Hoover Institution on using data to protect privacy, I had an interesting exchange with Laura Donohue of Georgetown Law, which I’ve been mulling over ever since.
I had made the argument that, in discussing information sharing and privacy, it is important to differentiate between different types of data.  There are a number of areas in which privacy and security are mutually reinforcing, as a genuine operational matter and not just as a linguistic framing.  In particular, I argued, where we can automate collection and processing of data, technology can increasingly promote both privacy and security. [I agree and extend this to Military Intelligence generally.  Bob]
Donohue disagreed, and she had a pretty good line in response:
Read more on Lawfare.

(Related)  Nothing specific.  In fact, it sounds like what yearbook photographers used to do with those old fashioned camera thingies.
Katie Banks reports:
Police are investigating following teenage girls’ claims they were caught on camera without their knowledge or permission.
Shawnee police are now investigating one of their male classmates at Mill Valley High School in the De Soto School District for a possible privacy breach.
Students at the high school and their parents agree that the news of a teenage boy taking cell phone technology too far has caused some concern.
Families received an email on Tuesday from Mill Valley High’s principal.  It says a student, using a cell phone, took photos and videos of female students in public places while at school.
Read more on Fox4KC.


My guess is that Donald Trump will not pick this as one issue to use against Hillary.  I suspect he would be uncomfortable discussing technology.  Okay, “uncomfortable” is not the right word.  Nothing seems to make him uncomfortable. 
Romanian hacker Guccifer: I breached Clinton server, 'it was easy'
…   Guccifer’s potential role in the Clinton email investigation was first reported by Fox News last month.  The hacker subsequently claimed he was able to access the server – and provided extensive details about how he did it and what he found – over the course of a half-hour jailhouse interview and a series of recorded phone calls with Fox News.
Fox News could not independently confirm Lazar’s claims.
In response to Lazar’s claims, the Clinton campaign issued a statement  Wednesday night saying, "There is absolutely no basis to believe the claims made by this criminal from his prison cell.  In addition to the fact he offers no proof to support his claims, his descriptions of Secretary Clinton's server are inaccurate.  It is unfathomable that he would have gained access to her emails and not leaked them the way he did to his other victims.”
The former secretary of state’s server held nearly 2,200 emails containing information now deemed classified, and another 22 at the “Top Secret” level.

(Related)
Federal judge opens the door to Clinton deposition in email case
…   Judge Emmet Sullivan of the U.S. District Court for the District of Columbia laid out the ground rules for interviewing multiple State Department officials about the emails, with an eye toward finishing the depositions in the weeks before the party nominating conventions.
Clinton herself may be forced to answer questions under oath, Sullivan said, though she is not yet being forced to take that step.
“Based on information learned during discovery, the deposition of Mrs. Clinton may be necessary,” Sullivan said in an order on Wednesday.


Architecting the perfect automobile platform?  What should your car do for you?
Ford Invests in Pivotal to Soup Up Its Software
Ford Motor Co. , like the rest of the auto industry, has a software problem: Elon Musk’s Tesla Motors.
Tesla has set the standard in the auto industry as the equivalent of an iPad on wheels, offering major software updates to improve vehicles.
On Thursday, Ford said it will invest $182.2 million in Pivotal Software Inc., a San Francisco-based software company expected to help Ford stay competitive as software and cars become one.
,,,   FordPass includes a smartphone app that helps users with parking, car sharing, remote access to vehicles and other services.  Ford ownership isn’t required to use the app, and Ford says that FordPass “aims to do for car owners what iTunes did for music fans.”


Is this the virtual assistant we’ve been waiting for?  (Or merely a better pizza ordering App?) 
Siri’s creators say they’ve made something better that will take care of everything for you
…   The engineers erupted in cheers as the pizzas arrived.  They had ordered pizza, from start to finish, without placing a single phone call and without doing a Google search — without any typing at all, actually.  Moreover, they did it without downloading an app from Domino’s or Grubhub.
…   The goal is not just to build great artificial intelligence. Companies see in this effort the opportunity to become the ultimate intermediary between businesses and their customers.


The best “new tool” ever! 
Google aims to kill 'Death by PowerPoint' with new Slides
…   The new features -- currently rolling out on Android, iOS and the Web app -- aim to make slide presentations more interactive.  Audience members can ask questions and vote for which questions should get answered.
…   Education is obviously one key market for Google.  Mary Jo Madda got to interview Bose—Survey Says:
Bose believes that the Q&A feature [has] implications for teaching practices. [And] for students who may be afraid to ask for help.
“As a student myself, I've definitely been lost and confused in class. [Q&A] takes away the fear of asking questions. ...  Other students who have up-voted your question are [undoubtedly] also confused.”

(Related)
How to Use the New Q&A and Laser Pointer Features of Google Slides @googledocs


This could be amusing!
Feds make it easier for students to use drones
The Federal Aviation Administration (FAA) on Wednesday announced new guidelines meant to make it easier for students to use drones for academic purposes.
Students at accredited educational institutions will not need to get authorization from the FAA, according to the guidelines, or apply for an exemption from existing rules.  Faculty members will also be able to use a drone without additional authorization, assuming they are assisting a student.


Some of my students have too much time on their hands.  They might be perfect for this.
Did You Know You Can Earn Money Testing Mobile & Web Apps?


Those who do not study history are doomed to repeat it, but have we lost so much so quickly?
Police Called After Student Tries To Buy Lunch With $2 Bill
An eighth-grade student found herself in hot water for buying chicken nuggets for lunch last week – using a $2 bill.
Danesiah Neal, an eighth grader at Fort Bend Independent School District’s Christa McAuliffe Middle School outside of Houston, Texas, attempted to pay for lunch with a $2 bill given to her by her grandmother, Sharon Kay Joseph.  However, cafeteria workers at the school didn’t believe that it was real – they never see $2 bills, apparently – and called the police.  According to Neal, the police officer told her that she could be in “big trouble” for using the bill which they believed to be counterfeit.
…   Some semblance of sanity eventually took over and school officials called Joseph, who confirmed that she had given the bill to her granddaughter to pay for lunch.  In the meantime, the police (who apparently didn’t have much else to do that day) went to the convenience store where Joseph was given the bill.  They also took the bill to a local bank where it was eventually determined to be real.  Phony crisis averted.

Wednesday, May 04, 2016

So they can still generate electricity, but they can’t bill for it?  Or pay their employees?  Or their vendors? 
Richard Chirgwin reports:
A water and electricity authority in the US State of Michigan has needed a week to recover from a ransomware attack that fortunately only hit its enterprise systems.
Lansing’s BWL – Board of Water & Light – first noticed the successful phishing attack on its corporate systems on April 25, and has had to keep systems including phone servers locked down since then.
The company says customer data has not been stolen (only, as is the case in ransomware attacks, encrypted).
Read more on The Register.
Last week, the FBI posted an alert highlighting what we already knew: ransomware is on the rise.  And not only is it hitting all sectors, it’s hitting personal home computers.
What some may not know, and from the FBI’s alert:
And in newly identified instances of ransomware, some cyber criminals aren’t using e-mails at all.  According to FBI Cyber Division Assistant Director James Trainor, “These criminals have evolved over time and now bypass the need for an individual to click on a link.  They do this by seeding legitimate websites with malicious code, taking advantage of unpatched software on end-user computers.”
If you think you or your organization have been the victim of ransomware, contact your local FBI field office and report the incident to the Bureau’s Internet Crime Complaint Center.


Screwing up by the numbers?
Aha. I see Brian Krebs got some answers before I did concerning a breach involving ADP.  On April 30, I had reported that Allegheny College suspected that employee reports of W-2 data comprise were linked to a breach involving ADP’s iPay.  In an email to this site earlier today, Rick Holmgren, the college’s vice-president of Information Services and Assessment said he still had no idea how unauthorized third parties were able to register accounts on iPay.  ADP, contacted several times by DataBreaches.net yet, has yet to provide the requested explanation.
Enter Brian Krebs to the rescue.  Brian reports that the criminals were able to steal wage and tax data from ADP by registering accounts in the names of employees at “more than a dozen customer firms.”
ADP says the incidents occurred because the victim companies all mistakenly published sensitive ADP account information online that made those firms easy targets for tax fraudsters.
Last week, U.S. Bancorp(U.S. Bank) — the nation’s fifth-largest commercial bank — warned some of its employees that their W-2 data had been stolen thanks to a weakness in ADP’s customer portal.
…. A reader who works at the financial institution shared a letter received from Jennie Carlson, U.S. Bank’s executive vice president of human resources.
“Since April 19, 2016, we have been actively investigating a security incident with our W-2 provider, ADP,” Carlson wrote.  “During the course of that investigation we have learned that an external W-2 portal, maintained by ADP, may have been utilized by unauthorized individuals to access your W-2, which they may have used to file a fraudulent income tax return under your name.”
The letter continued:
“The incident originated because ADP offered an external online portal that has been exploited.  For individuals who had never used the external portal, a registration had never been established.  Criminals were able to take advantage of that situation to use confidential personal information from other sources to establish a registration in your name at ADP.  Once the fraudulent registration was established, they were able to view or download your W-2.”
[….]
According to ADP, new users need to be in possession of two other things (in addition to the victim’s personal data) at a minimum in order to create an account: A custom, company-specific link provided by ADP, and a static code assigned to the customer by ADP.
The problem, Cloutier said, seems to stem from ADP customers that both deferred that signup process for some or all of their employees and at the same time inadvertently published online the link and the company code.  As a result, for users who never registered, criminals were able to register as them with fairly basic personal info, and access W-2 data on those individuals.
Read more on KrebsOnSecurity.com.
The problem being described appears different than the problem being reported in connection with Greenshades clients.  As I’ve reported previously on this site, Greenshades claims their clients’ employees had their W-2 data compromised because they used their DOB and SSN as their login credentials, [Aargh!  Bob] and criminals who obtained that information elsewhere were then able to login as the employees and download their W-2 data.  Other clients’ employees, they claim, likely fell for a phishing scheme directing them to a fake Greenshades domain.
ADP and Greenshades are not the only payroll or W-2 vendors whose clients have been reporting problems.  As also noted previously on this site, Innovak customers in Mississippi and Alabama have reported problems, and Stanford University and its vendor, W-2 Express, are still investigating how over 700 Stanford employees had their W-2 data stolen.
How many other vendors have experienced compromises remains unknown, as some entities reporting breaches of their employees’ W-2 data are not naming their vendors.
Might this be a good time for all vendors to review and strengthen their authentication procedures?


Or screwing up wholesale.  (We don’t need no stinking encryption!) 
EqualizeRCM Services  is a vendor providing billing and collection services to healthcare providers.  In compliance with HIPAA, it has Business Associate contracts with its clients, who provide it with the information needed to fulfill its functions.  The firm has headquarters in Austin, Texas, and offices in Houston and Washington, D.C.
On February 29, EqualizeRCM learned that a laptop had been stolen from an employee on February 25 or 26.  A notification letter, signed by Janine Anthony Bowen of LeClairRyan to the New Hampshire Attorney General’s Office, does not indicate whether the laptop was stolen from the employee’s home, a car, or some other location.
[ … ]
In a statement posted on their web site on April 28, EqualizeRCM explained that
the information potentially exposed may have included patient name, address, phone number, date of birth, gender, insurance provider and policy number, health care provider information, billing and diagnosis codes, medical record number, internal reference number, date and type of service, the name of the treating facility, and other administrative information.
Financial account information and Social Security numbers were not impacted, and as of April 28, neither EqualizeRCM nor its clients were aware of any misuse of the information.  As a precaution, however, EqualizeRCM is offering affected patients services through AllClear ID.
[…]
In addition to offering remediation services, EqualizeRCM is also reviewing its policies and procedures, implementing additional safeguards to ensure information in its control is appropriately protected, and “retraining employees on existing policies for the proper handling of sensitive information.”


Are there billboards near potential target? 
Joe Cadillic isn’t buying any protestations that the data are “anonymous.”
He writes:
Clear Channel Outdoor (CCO) has 675,000 billboards worldwide most of which are tracking everyone’s smartphones and tablets.  CCO’s ad program is a partnership between AT&T and other companies that collect location data from smartphones, company officials said.
CCO’s smartphone electronic surveillance system is called “RADAR” which they insist, anonymizes everyone’s data. But it does much more than that, it tracks consumer’s real-world travel patterns and behaviors.
Read more on MassPrivateI.


Those who do not study technology are doomed to misunderstand it?  Frustrated (or technically ignorant) judges will certainly repeat rulings like this one. 
WhatsApp Goes Through Judicial Revolving Door in Brazil
A Brazilian court on Tuesday overturned a different court's Monday order that blocked WhatsApp, the messaging site owned by Facebook, amid a criminal investigation into drug trafficking in the state of Sergipe.
The earlier judicial demand that WhatsApp provide data considered critical to the investigation came soon after a ramp-up in the level of encryption built into the app.  Five major Internet service providers faced hefty fines of about US$142,000 daily if they failed to comply with the order.
…   The decision to block WhatsApp was clumsy and disproportionate, said Katitza Rodriguez, international rights director at the Electronic Frontier Foundation.
…   The order surprised activists in Brazil, who considered the move out of step with the spirit of the law, noted Javier Pallero, policy analyst at Access Now.
…   Brazilian lawmakers on Tuesday held hearings to consider a series of laws that could lead to a severe crackdown on open technology and privacy, as part of Brazil's Parliamentary Inquiry on Cybercrime.
Officials on Wednesday are expected to vote on seven pieces of legislation that would give police warrantless access to IP addresses, allow judges to block sites used for criminal purposes, and require monitoring of content on sites and apps deemed offensive, according to EFF.


Just to be clear…
Law Affords More Protection to PINs Than Prints
…   Although the Fifth Amendment to the U.S. Constitution protects citizens from self-incrimination, that protection doesn't extend to opening mobile phones with a fingerprint, according to Paul Rosenzweig, a George Washington University professorial lecturer in law.
"None of your physical characteristics are subject to Fifth Amendment protection," he told TechNewsWorld.
"You don't have a right to refuse to stand in a lineup," Rosenzweig said.  "You don't have a right to refuse an order to give your fingerprint to be compared to fingerprints at a crime scene."
The Fifth Amendment protects only things that are testimonial in nature.


Sometimes being the dominant player in a market can get expensive.  Would any insurance cover this?  If not, will they be able to replace all these airbags before bankruptcy?
Takata's fight for survival gets even harder as airbag recall widens
…   “This is just another step in the long decline of Takata,” said Jochen Siebert, managing director of JSC (Shanghai) Automotive Consulting Co.  “I just can’t see how Takata can survive this disaster.”
An expanded safety campaign will deal a further blow to President Shigehisa Takada, who has so far failed to contain a spiraling crisis that’s wiped out 75 percent of his family company’s market value in the past year.  Last May, the airbag supplier set the record for the largest automotive recall in U.S. history by agreeing to almost double the number of vehicles called back to about 34 million.


Something for my Spreadsheet students to play “what if” games with.
Traditional and Roth Individual Retirement Accounts (IRAs): A Primer
by Sabrina I. Pacifici on
CRS report via FAS – Traditional and Roth Individual Retirement Accounts (IRAs): A Primer, John J. Topoleski, Analyst in Income Security. April 27, 2016.
“In response to concerns over the adequacy of retirement savings, Congress has created incentives to encourage individuals to save more for retirement through a variety of retirement plans.  Some retirement plans are employer-sponsored, such as 401(k) plans, and others are established by individual employees, such as Individual Retirement Accounts (IRAs).  This report describes the primary features of two common retirement savings accounts that are available to individuals.  Although the accounts have many features in common, they differ in some important aspects.  Both traditional and Roth IRAs offer tax incentives to encourage individuals to save for retirement.  Contributions to traditional IRAs may be tax-deductible for taxpayers who (1) are not covered by a retirement plan at their place of employment or (2) have income below specified limits.  Contributions to Roth IRAs are not tax-deductible and eligibility is limited to those with incomes under specified limits…”


For my geeks!
IBM Is Now Letting Anyone Play With Its Quantum Computer
Quantum computing is computing at its most esoteric.  It’s an experimental, enormously complex, sometimes downright confusing technology that’s typically the domain of hardcore academics and organizations like Google and NASA.  But that might be changing.
Today, IBM unveiled an online service that lets anyone use the five-qubit quantum computer its researchers have erected at a research lab in Yorktown Heights, New York.  You can access the machine over the Internet via a simple software interface—or at least it’s simple if you understand the basics of quantum computing.


For my Students!  “Study hard.”  “Come to class on time.” 
How to Add Subliminal Messages to Windows
Whether you want to train your unconscious mind while you work, perform a study on whether these messages have an effect, or just play a few pranks on your friends’ computers, here’s how you can add some subliminal message text to Windows.


A recording studio on your phone?
Moog’s New App Is a Spot-on Recreation of a Classic Synth
Five years ago, Moog Music proved you could use the iPad as a real musical instrument when it released Animoog, a polyphonic synthesizer app that made full use of the tablet’s touchscreen.
…   The Moog Model 15 Synthesizer app is an iOS-powered recreation of the iconic Model 15 modular synth from 1973.  You can download it now for $30.  If you find that steep, consider two things.  One, this is a pro-grade instrument that plays and sounds like the business.  And two, a real Model 15 is the size of a suitcase and tops $10,000; the iPad version delivers 90 percent of the goods in something easily carried in your backpack.

(Related)  I wonder if any of my students have talent? 
BandLab - Collaboratively Create Music Online
BandLab is a free service that enables you to create music in your web browser or through free Android and iOS apps.  In BandLab's you can create soundtracks using any of the virtual instruments that are provided.  You can also speak or sing to record a track.  Within the BandLab editor you can mix your tracks together to create a song.  If you have existing audio files on your computer, you can upload those to incorporate into your BandLab creations.
BandLab is designed to allow you to collaborate with others. To collaborate you first have to create a band in your BandLab profile then invite other users to join your band.

Tuesday, May 03, 2016

Now a database of people who were breached has been breached. 
Brian Krebs reports:
Last week, I learned about a vulnerability that exposed all 866 million account credentials harvested by pwnedlist.com, a service designed to help companies track public password breaches that may create security problems for their users.  The vulnerability has since been fixed, but this simple security flaw may have inadvertently exacerbated countless breaches by preserving the data lost in them and then providing free access to one of the Internet’s largest collections of compromised credentials.
Read more on KrebsOnSecurity.


Is this just one judge who doesn’t get it, or are they really going crazy in Brazil?
WhatsApp Blocked in Brazil as Judge Seeks Data
Judge Marcel Maia Montalvão ordered telecom companies operating in Brazil to suspend WhatsApp nationwide for 72 hours.  As of just after midday Monday, Brazilians said they could not use the popular messaging service.
The shutdown is the latest twist in a case that has embroiled WhatsApp in legal trouble.  The case, which is under seal, involves an organized crime and drug trafficking investigation in the court in Lagarto, in the northeastern state of Sergipe.  The court has been seeking data from WhatsApp to aid in the investigation.  Diego Dzodan, a Facebook executive, was briefly taken into custody in March for refusing to comply with orders to turn over WhatsApp information in the case.
The judge who ordered WhatsApp’s shutdown on Monday is the same one who ordered Mr. Dzodan’s arrest.  Mr. Dzodan was released after one night when a higher court judge said the arrest was “an extreme measure.”
…   Concern is growing in Brazil that its Congress may pass laws that would weaken digital privacy.  One measure calls for Internet companies to remove content deemed critical of politicians within 48 hours, while another calls for imprisonment for violating an Internet’s site’s terms of use.  The proposals worry many Internet privacy advocates, including the authors of Brazil’s widely respected Internet bill of rights or Marco Civil.


An interesting approach.  Will the victim be able to identify the culprit?  At least, he may be able to correct some of the damage caused.
Glyn Moody reports:
The Italian data protection authority has ordered Facebook to provide an Italian user with all of their data, including the personal information, photos, and posts of a separate fake account set up in that person’s name by somebody else.
In addition, the US social network must provide details of how the personal data was used, including whom it was sent to or who might have obtained knowledge about it.
Read more on Ars Technica.


I suspect that no one in Congress needs to go through security at airports. 
From EPIC.org:
EPIC has filed a lawsuit challenging the Transportation Security Administration’s regulation for airport body scanners.  The TSA announcement came nearly five years after a federal appeals court ordered the agency to “promptly” solicit public comments on the controversial screening procedure.  Public comments overwhelmingly favored less invasive security screenings.  But the TSA decided it may now mandate body scanners at US airports.  In 2011, EPIC challenged the intrusive and ineffective TSA screening procedure.  EPIC’s new lawsuit challenges the regulation because it “denies passengers the right to opt out” of body scanner screening.  EPIC also challenged the effectiveness of airport body scanners and the TSA’s failure to recommend less invasive security screening.


Unless logic has changed in the decades since I worked in the Intelligence field, I can see no reason why “2,647” give away significantly (or even trivially) more information than “somewhere between 1 and 5,000.”  
Judge dismisses Twitter’s lawsuit against government
A federal judge dismissed Twitter’s attempt to publish the exact number of secret orders it receives from the government to turn over its customers' information. 
Judge Yvonne Gonzalez Rogers in California ruled that the information Twitter wants to publish is classified.  Because of that, the judge dismissed Twitter’s claim that the gag order violates the social media company’s First Amendment right, which does not apply to classified information.
“Again, Twitter has conceded that the aggregate data is classified,” the judge wrote.  “In the absence of a challenge to the decisions classifying that information, Twitter’s Constitutional challenges simply do not allege viable claims.”
The judge did give Twitter the option to amendment its lawsuit.  If the company wants to, it can challenge the classification of the information it wants to make public.


For my Data Analytics and Enterprise Architecture classes. 
Your Next Big Data Project? Operational Analytics
If Big Data has a killer application, it is operational analytics.
Companies using Big Data initially focused on the customer experience, with Capgemini/Sloan Management Review research finding that 40 percent of analytics initiatives in 2013 were aimed at the customer while 26 percent focused on operational improvements.  A lot has changed in three years, however.  In 2016, Capgemini surveyed 600 global executives and found 70 percent now emphasize operations rather than customer experience with their analytics projects.
That's because companies get the most bang for the buck with operational analytics, said Steve Jones, Global VP of Big Data for Capgemini.
…   The benefits of operational analytics are far easier to illustrate than those of customer analytics, Jones said.  A Capgemini report titled Going Big: Why Companies Need to Focus on Operational Analytics offers the example of an Asian steel manufacturer that used operational analytics to uncover root causes of quality issues and then attained a 50 percent reduction in lead time for production of some of its products and a 60 percent reduction in inventory.  In another example, the UK's Network Rail used operational analytics to make better decisions on preventive maintenance for its rail system infrastructure, realizing cost savings of 125 million euros (U.S. $141 million) over a five-year period.

(Related)
Inspirational Quotes From 100 Famous Business Leaders (Infographic)


Perspective.  Now American Express (and Visa and Master Card) have competition everywhere.
Alipay Users Can Now Use it to Hail Uber Cars World-Wide
Users of China’s most popular digital-payment service, Alipay, can now use the mobile app to hail a car anywhere in the world where Uber is available.
On Tuesday, Uber Technologies Inc. extended its partnership with Alibaba Group Holding Ltd.’s online-payment affiliate to let the 450 million customers of Alipay use the digital-payments app to request and pay for a ride in all 69 countries in which Uber operates.


For our programming students?
This App Teaches You Coding Basics in Minutes per Day
…   If you want to pick up the basics of a programming language on the go, SoloLearn has awesome free mobile apps that can help you understand several popular languages.  On their Google Play or App Store pages, you’ll find apps for learning C++, Java, Swift, JavaScript, HTML, Python, and more.
…   Every lesson gives you some information then asks you a question about it (usually multiple choice or typing your own code to complete a block) to be sure you understand it.
Any snippet of code you see in the apps can be run so you see its real output, and the apps also include a code playground where you can mess around and apply what you’ve learned to some real code.


‘cause Checkers is boring?  (I am so out of touch…)
6 Coolest Games You Can 3D Print at Home

Monday, May 02, 2016

For my Computer Security students.  See what you’re up against?
A Scary Look Back at History’s Worst Data Breaches


On one hand, identification.  On the other hand, access to search.  Would this authorize physical force to place a finger in the phone?  What would happen if the fingerprint triggered an erase of the phone? 
For the first time in a federal case, a suspect has been ordered to use her fingerprint to unlock her iPhone using Touch ID.  The LA Times reports that a federal judge signed a warrant allowing the FBI to compel a suspect in an identity theft case to unlock the phone just 45 minutes after her arrest.
Authorities obtained a search warrant compelling the girlfriend of an alleged Armenian gang member to press her finger against an iPhone that had been seized from a Glendale home […]
In the Glendale case, the FBI wanted the fingerprint of Paytsar Bkhchadzhyan, a 29-year-old woman from L.A. with a string of criminal convictions who pleaded no contest to a felony count of identity theft.
The warrant is consistent with a 2014 case where a Virginia District Court ruled that while passcodes are protected by the 5th Amendment right against self-incrimination, fingerprints are not. Legal experts, however, have differing views …
Fingerprints are currently viewed by the law as ‘real or physical evidence,’ meaning that law enforcement has a right to access to them without a warrant. However, some law professors say that this view is now outdated when a fingerprint can provide access to incriminating data.
“It isn’t about fingerprints and the biometric readers,” said Susan Brenner, a law professor at the University of Dayton who studies the nexus of digital technology and criminal law, but rather, “the contents of that phone, much of which will be about her, and a lot of that could be incriminating.”
Others, however, disagree.
Albert Gidari, the director of privacy at Stanford Law School’s Center for Internet and Society, said the action might not violate the 5th Amendment prohibition of self-incrimination. “Unlike disclosing passcodes, you are not compelled to speak or say what’s ‘in your mind’ to law enforcement,” Gidari said. “‘Put your finger here’ is not testimonial or self-incriminating.”
In this particular case, the argument will go no further: Bkhchadzhyan pleaded ‘no contest’ to a felony count of identity theft. There seems little doubt, however, that some future case will make it to the Supreme Court.

(Related) DNA is identification only, right?  What happens if we use it to secure our data? 
New on LLRX – Evolutions in DNA Forensics
by Sabrina I. Pacifici on
Via LLRX.com – Evolutions in DNA Forensics – Criminal law expert Ken Strutin’s new article is yet another research tour de force – a collection of recent and notable developments concerning DNA as forensic science, metric of guilt, herald of innocence, and its emerging place in the debate over privacy and surveillance.  The increasing use of DNA evidence to support assumptions of an individual’s guilt and less frequently as a tool to prove the innocence of prisoners wrongly convicted, reflects many facets of the changing fabric of the American criminal justice, the role of the Fourth Amendment and the increasing collection of a wide range of biological evidence from crime scenes whose metadata then is searchable within the national DNA database.


In a similar vein. 
FISA Court did not reject any warrant requests in 2015
by Sabrina I. Pacifici on
Via ZDNet: “A secret court that oversees the US government’s surveillance requests accepted every warrant that was submitted last year, according to new figures.  The Washington DC.-based Foreign Intelligence Surveillance Court received 1,457 requests from the National Security Agency and the Federal Bureau of Investigation to intercept phone calls and emails.  In long-standing fashion, the court did not reject a single warrant, entirely or in part…”


If Google gets to choose, I’d bet on “No!”  God only knows what the politicians might say.
As I suggested to a commenter in another thread, not all requests for removal from search engine results really fall under “Right to Be Forgotten.”  Here’s a case out of New Delhi that is really, at its core, a reputation management issue:
Does right to privacy include right to delink from the Internet the irrelevant information, the Delhi High Court has asked the Centre and Google.
Justice Manmohan sought the responses of the Ministry of Communication and Information Technology (MOC & IT), Google Inc., Google India Pvt Ltd and IKanoon Software Development Pvt Ltd on a plea of an NRI [non-resident Indian  Bob] seeking that he be “delinked” from information regarding a criminal case involving his wife in which he was not a party.
The petitioner has sought the relief saying it would affect his employment opportunities as companies often search about prospective employees on the internet and as the criminal case pops up on searching his name, it might give an impression that he was involved in it.
Read more on NDTV.
Is there an actual privacy issue here?


What does it really do for the CIA’s image?  Looks like politics again. 
CIA ‘live tweets’ Osama bin Laden raid and the internet wasn’t happy
To mark the fifth anniversary of the death of Osama bin Laden, the CIA Monday "live tweeted" the special forces raid on the al-Qaeda leader's compound in Pakistan in a move that was slammed on social media as "inappropriate" and "distasteful".
…   "Death of Usama Bin Ladin marked significant victory in US-led campaign to disrupt, dismantle, & defeat al-Qa`ida. #UBLRaid," the CIA wrote on Twitter before commencing a to-the-minute live-tweeting session of the mission.
…   A CIA spokesperson defended the live-tweeting.
"The takedown of bin Laden stands as one of the great intelligence successes of all time.  History has been a key element of CIA's social media efforts," CIA spokesman Ryan Trapani told ABC News.
"On the fifth anniversary, it is appropriate to remember the day and honor all those who had a hand in this achievement."
He added that the CIA has done a similar exercise to mark other events, including the Glomar operation, Argo, U-2 shootdown, and the evacuation of Saigon.

Sunday, May 01, 2016

If you think encrypting a laptop is too expensive, consider what it might cost to lose an unencrypted laptop.
Bill Mah reports that a lawsuit filed after a 2013 Medicentres breach has settled.  The incident involved a laptop with information on 620,000 Albertans being stolen from the clinic.  The laptop belonged to an employee of their IT consultant, AbleIT Inc.  The Privacy Commissioner would later rule that the clinic had failed to adequately protect their patients’ information.
According to Mah:
The settlement totals $725,000 to resolve credit damage, mental distress, increased risk of future identity theft and time and costs associated with preventing identity theft, according to a notice posted on the website of James H. Brown and Associates, an Edmonton law firm working with Calgary-based D’Arcy Deacon on the lawsuit.
The lawsuit originally sought $11 million.
Read more on Edmonton Journal.


Have you noticed that all of the FBI’s “secret” programs, tools and techniques seem to leak?  And sooner rather than later! 
Former Tor developer created malware for the FBI to hack Tor users
How does the U.S. government beat Tor, the anonymity software used by millions of people around the world? By hiring someone with experience on the inside.
A former Tor Project developer created malware for the Federal Bureau of Investigation that allowed agents to unmask users of the anonymity software.
Matt Edman is a cybersecurity expert who worked as a part-time employee at Tor Project, the nonprofit that builds Tor software and maintains the network, almost a decade ago.
Since then, he's developed potent malware used by law enforcement to unmask Tor users.  It's been wielded in multiple investigations by federal law-enforcement and U.S. intelligence agencies in several high-profile cases.
…   Tor is widely considered one of the most important and powerful Internet privacy tools ever made.  The project has received the majority of its funding from the U.S. government.
“This is the U.S. government that's hacking itself, at the end of the day,” ACLU technologist Chris Soghoian told the Daily Dot in a phone interview.  “One arm of the U.S. government is funding this thing, the other is tasked with hacking it.”
…   The malware targeted the Flash inside the Tor Browser.  The Tor Project has long warned against using Flash as unsafe but many people—including the dozens revealed in Operation Torpedo—often make security mistakes, just as they do with all types of software.


Interesting.  Not that they made the projection, but that anyone at this level remembered where they predicted encryption to be in seven (not five or ten) years.
THE DIRECTOR OF NATIONAL INTELLIGENCE on Monday blamed NSA whistleblower Edward Snowden for advancing the development of user-friendly, widely available strong encryption.
…   When pressed by The Intercept to explain his figure, Clapper said it came from the National Security Agency.  “The projected growth maturation and installation of commercially available encryption — what they had forecasted for seven years ahead, three years ago, was accelerated to now, because of the revelation of the leaks.”


Something for my Computer Security class. 
IBM Defines Security Standards For Running Blockchain In The Cloud
…   “We are enumerating a set of standards that we think are critical to running production watching networks, especially for companies that are regulated,” says Jerry Cuomo, IBM’s vice president of blockchain, adding that this will help several industries, including financial services, healthcare and government, deal with data security regulations.
…   The new standards provide companies experimenting on IBM’s cloud-based blockchain networks the ability to create comprehensive log data that can be used for audits and compliance.
…   Blockchain technology is shorthand for a ledger held on multiple computers that records all the transactions being tracked.  It obviates the need for a middleman, since cryptography makes the record immutable and tamper-proof, thereby increasing efficiency and lowering costs.  The technology also enables companies to offer new products and services that are too expensive or impossible with current systems.
[For more on Blockchain:  http://www.ibm.com/blockchain/


Dilbert on e-voting?