Wednesday, August 30, 2006

Google is beta testing a new blogging tool. Among other features, there is the ability to: 1) Add authors so multiple people can post to your blog. 2) Choose who can view your blog just by adding their email address. This looks like a formula for creating project level blogs, and limiting access to the team – OR – allowing any partner in the firm to create a blog entry readable only by clients (and Google). NEAT!

http://www.blogger.com/migrate-login.g



Ia AT&T so dumb they release this information on a Tuesday? Or is there some reason to report “My security stinks” stories faster than “My employee was robbed” stories? OR 19,000 is too trivial a number to worry about?

http://news.com.com/2100-1029_3-6110765.html

AT&T hack exposes 19,000 identities

Hackers access personal data on thousands of customers who used the carrier's online store.

By Joris Evers Staff Writer, CNET News.com Published: August 29, 2006, 5:45 PM PDT

AT&T on Tuesday said hackers broke into one of its computer systems and accessed personal data on thousands of customers who used its online store.

The information that was illegally accessed includes credit card numbers, AT&T said in a statement. The cyberattack affects about 19,000 customers who purchased equipment for high-speed DSL Internet connections through AT&T's Web site, the company said.

"We deeply regret this incident," Priscilla Hill-Ardoin, chief privacy officer for AT&T, said in the statement. "We will work closely with law enforcement to bring these data thieves to account."

The break-in occurred over the weekend and was discovered within hours, after which the online store was shut down, AT&T said. The telecommunications company quickly notified credit card companies and is in the process of contacting the affected customers via e-mail, phone and letter, it said.


http://www.sfgate.com/cgi-bin/article.cgi?file=/chronicle/archive/2006/08/30/BUGTGKRI6B1.DTL&type=business

Hackers hit AT&T, steal users' info

Ryan Kim, Chronicle Staff Writer Wednesday, August 30, 2006

... AT&T officials said they are employing forensic teams to understand how the store was compromised. Walt Sharpe, a spokesman for the company, said the rest of the site remains secure. [“We don't know what happened, but were sure it can't happen elsewhere.” Right. Bob]



He may be selling his own product, but the concept is correct. Management must control not react.

http://www.computerworld.com.au/index.php/id%3b1622226737%3bfp%3b4%3bfpid%3b16

Spying on staff no solution to privacy protection: professor

Sandra Rossi 29/08/2006 12:27:40

Instead of spying on staff who snoop into private records while at work, organizations should adopt security measures that prevent staff breaching privacy laws, a Queensland University of Technology privacy expert said today.

His comments follow news last week that Centrelink is using keylogging software to monitor staff access to company records. The surveillance has led to the sacking of 19 staff. Similar steps are being taken at the Australian Tax Office (ATO) where 27 workers have been sacked.

Centrelink CEO Jeff Whalan dubbed the surveillance a "success" and said there would be no apologies for the tough stance the welfare agency has taken to protect public records.

Professor Peter Croll, from QUT's Faculty of Information and Technology, said the current approach to privacy regulation was to wait for workers to breach privacy laws and then take action. [Noactive or Sloactive rather than proactive? Bob]

"What's happening is that we have organizations snooping on their staff to see if their staff are snooping," he said. "This just isn't the answer."



You are doomed, DOOMED I tell you!

http://websearch.about.com/b/a/218295.htm

How to Remove Personal Information from Zabasearch

I often get emails asking me how to remove personal information from Zabasearch, a free people search engine. Learn how to opt-out of having your private information included in the Zabasearch database in my article titled How to Remove Personal Information from Zabasearch.

Tuesday August 29, 2006



Perhaps they should have included a lawyer on their marketing team – it probably would have been cheaper. Are there any firms that consult on issues like this?

http://www.bespacific.com/mt/archives/012293.html

August 29, 2006

EPIC Reports $50M Class Action Verdict Against Bank for Privacy Violation

EPIC: "A Florida bank was required to pay $50 million in a class-action settlement resulting from violations of federal privacy law. Fidelity Federal Bank & Trust purchased 656,600 names and addresses from the Florida DMV for use in direct marketing. The purchase violated the Drivers Privacy Protection Act, a 1993 law passed after it was shown that stalkers and other criminals had used motor vehicle records to locate their victims. EPIC filed a "friend of the court" brief in favor of the plaintiffs before the Eleventh Circuit, arguing that the penalties provided by the law create a necessary incentive for both states and private entities to preserve the privacy of drivers' personal information."



No conclusions? What works and doesn't work?

http://www.bespacific.com/mt/archives/012296.html

August 29, 2006

European Approaches to Homeland Security and Counter-Terrorism

CRS Report, European Approaches to Homeland Security and Counter-Terrorism, July 24, 2006. "This report examines homeland security and counterterrorist measures in six selected European countries: Belgium, France, Germany, Italy, Spain, and the United Kingdom. None of these European countries currently has a single ministry or department equivalent to the U.S. Department of Homeland Security. In most of these countries, responsibility for different aspects of homeland security and counterterrorism is scattered across several ministries or different levels of government."



Monte Python lives!

http://techdirt.com/articles/20060829/141702.shtml

UK Cabinet Office Dinged For Violating The Copyright Of The UK Cabinet Office

from the left-hand,-meet-right-hand dept

Last week, the UK's Cabinet Office got plenty of publicity for putting some videos on YouTube, suggesting that it was a good way to get certain messages out to the public. In fact, in that article, the reporter sounded surprised, noting that the UK government is considered somewhat "backwards on understanding tech issues." Well, perhaps people were a bit too quick to congratulate them on embracing the new technology. Today comes the news that the video has been pulled from YouTube for copyright violations. Whose copyright? Apparently the UK Cabinet Office's. Yes, it appears one group within the Office is accusing a different group of violating its own copyrights in putting its own video on YouTube without permission. So, perhaps they're not as backwards as people thought concerning new technologies, but they have a ways to go in understanding internal communications.



“Strategy is as strategy does.” F. Gump

http://techdirt.com/articles/20060829/190813.shtml

Ma Bell's About Face On Muni-WiFi

from the is-that-about-face,-or-just-two-faced? dept

Remember the good old days of... well, last year, when telcos were telcos and they absolutely hated muni-WiFi? It was such a huge threat to their business that they gave Congress people plenty of money to make it illegal. Of course, that was before they actually bothered looking at many of the muni-WiFi proposals, and recognized they weren't really "government-run" at all, but were really no different than traditional telco deals. The government was simply giving away rights of way for placing equipment in return for promises of service. The providers could still be commercial providers with real business models. Suddenly, the industry opposition quieted down. Industry associations claimed that muni-WiFi was great... and AT&T (whose former employee introduced the bill to ban muni-WiFi) was seen providing the very same "free, tax-supported" WiFi they had screamed about just months before. Well, congrats to AT&T for all that hard work trying to stop muni-WiFi. You've just won another muni-WiFi deal (this one without taxpayer funding). Of course, for those of you who thought that muni-WiFi would give consumers an alternate provider, offering real competition to the incumbent telco... well, that doesn't really work so well when that alternate provider is the telco itself.



In case you missed it... Also, there is a viable solution in the comments (but politicians can't read)

http://www.huffingtonpost.com/marty-kaplan/how-to-hack-a-diebold-vot_b_26301.html?p=8#comments

How to Hack a Diebold Voting Machine

08.01.2006



http://news.bbc.co.uk/2/hi/americas/5294690.stm

Last Updated: Tuesday, 29 August 2006, 11:22 GMT 12:22 UK

Canada university in campaign row

The university says it will not retract its campaign

A small Canadian university has sparked controversy with its recruitment drive by using posters and a website mocking US President George W Bush.

Lakehead University in northern Ontario set up www.yaleshmale.com in a bid to attract potential new students.



Would that writing your congressman was this easy...

http://www.techcrunch.com/2006/08/29/12-million-flickr-photos-geotagged-in-24-hours/

1.2 million Flickr Photos Geotagged in 24 Hours

Michael Arrington August 29 2006

Look for a post on the Flickr Blog later today announcing that 1,234,384 photos were geotagged in the first 24 hours after the new feature launched yesterday (159 of those were mine).



Clearly we need more studies like this one!

http://www.menshealth.com/cda/article.do?site=MensHealth&channel=nutrition&conitem=7a5d8e208b4e9010VgnVCM100000cfe793cd____

Genius Junk Food

6 formerly forbidden snacks that are actually good for you

Photographs by: Philip Habib, By: Jeff Volek, Ph.D., R.D.



Gifts for my niece who actually likes to read! I'll bind them with her name on the cover. (So where can I find one of those “Print & Bind” Xeroxes?)

http://www.businessweek.com/ap/financialnews/D8JQDN900.htm?sub=apn_news_down&chan=db

Google to allow free downloads of books

AUG. 29 8:28 P.M. ET Google Inc. on Wednesday plans to begin letting consumers download and print free of charge classic novels and many other, more obscure books that are in the public domain.

Using Google's Book Search service, Web surfers hunting titles like Dante's "Inferno" and Aesop's "Fables" will be able to download PDF files [easily converted to any other format you like Bob] of the books for later reading, to run keyword searches or to print them on paper. Up to now, the service only allowed people to read the out-of-copyright books online.

... Google's Book Search service is the product of its Books Library Project, which is digitizing books from major libraries around the world in order to make them searchable online.



Okay, it's not up to David Letterman quality... Maybe Animal House?

http://www.bbspot.com/News/2006/08/top-11-things-to-do-if-your-laptop-battery-explodes.html

Things to Do if Your Laptop Battery Explodes



Dilbert gets it right, again!

http://www.unitedmedia.com/comics/dilbert/

Tuesday, August 29, 2006

If your defense is “Hey, I'm just a kid!” then a punishment like “Go to your room!” seems appropriate. If you can read “sensitive” Secret Service information, your room should be at Guantanamo.

http://hosted.ap.org/dynamic/stories/C/CELLULAR_HACKER?SITE=VALYD&SECTION=HOME&TEMPLATE=DEFAULT

Aug 28, 11:14 PM EDT

T-Mobile Hacker Gets Home Detention

LOS ANGELES (AP) -- A hacker who infiltrated the network of T-Mobile USA Inc. and accessed personal information of hundreds of customers, including a Secret Service agent, was sentenced Monday to one year of home detention.

Nicholas Lee Jacobsen, 23, must also pay $10,000 in restitution to T-Mobile to cover losses caused by his acts, which took place in 2004.

The former Santa Ana resident who now lives in Oregon said he lacked "comprehension and maturity" when he targeted the network of Bellevue, Wash.-based T-Mobile USA, uncovering the names and Social Security numbers of 400 customers.

"I did some very stupid things," Jacobsen told U.S. District Judge George King at his sentencing Monday in Los Angeles.

Jacobsen was able to read some sensitive information that Special Agent Peter Cavicchia could access through his wireless T-Mobile Sidekick device. No investigations were compromised, the Secret Service said.

"What you've done is very dangerous to others. Maybe you didn't fully appreciate that, perhaps because of your youth," King told Jacobsen Monday.

Jacobsen could have faced a maximum sentence of five years in prison and a fine of up to $250,000 for the crime, accessing a protected computer.


On the other hand...

http://seattlepi.nwsource.com/local/282674_botnet26.html

Hacker sentenced to 37 months in prison

Victims in global attack included U.S. military

By PAUL SHUKOVSKY P-I REPORTER Saturday, August 26, 2006

Sending a message to malicious computer hackers "squirreled away in their basements," U.S. District Judge Marsha Pechman on Friday sentenced a 21-year-old man to 37 months in federal prison for a global robot virus attack in 2004 and 2005.

Christopher Maxwell launched the attack from the comfort of his Vacaville, Calif., home in order to collect commissions by installing adware onto the computers of unwitting victims.

To achieve his aim, he essentially took remote control of huge numbers of computers around the world, causing them to spread the infection and increase his profits. The Seattle FBI's cybersquad believes the scheme netted Maxwell and two unnamed teenage accomplices more than $100,000.

Among the countless victims, the virus wreaked havoc with the Defense Department, [Oh? Bob] Seattle's Northwest Hospital and a school district in California. Disaster preparations by the military and the hospital prevented significant damage, but the Colton Unified School District was not so fortunate.

"It took the district to its knees," said Gary Stine, the district's former director of information technology.

"We don't plan for calamities like this. The real impact was to our teachers and our students" who lost crucial instructional time on PCs used to teach such topics as English as a second language. The repairs cost the district more than $50,000.

At Northwest Hospital, digital systems used for transmitting results from medical labs and the radiology department directly to physicians crashed, said Vice President Robert Steigmeyer.

The hospital switched to its well-drilled disaster plan, which involves the use of runners to move medical records and lab test results. Elective medical procedures, however, had to be rescheduled.

No patients were harmed as a result of the attack, and Maxwell made no attempt to steal confidential patient information.

Army Maj. Keithon Corpening, who runs the Defense Department's computer incident response team, told Pechman that a full-scale investigation was launched after the military saw 407 of its computers taken over by an unknown assailant they dubbed "Don't Trip." Eight investigators were assigned to the case.

"Planes still flew, tanks were still operating, soldiers were getting their supplies," Corpening said. But "the potential for damage to our systems" was significant.

No military information was stolen, he said.

Assistant U.S. Attorney Kathryn Warma, in arguing for a six-year sentence, told Pechman: "The importance of deterrence in this case is profound. There is a hacker community. They will know immediately what sentence you impose."

Maxwell, holding back tears, pleaded for probation in lieu of prison time.

"I am a 21-year-old boy with a good heart and I made a mistake," he told the judge. "I never realized how dangerous a computer could be. I thank God no one was hurt."

Pechman rejected attempts by Maxwell and his attorney to portray him as being shocked by the consequences of his actions. "It is obvious that anyone who would launch this kind of computer attack would know" that there would be a multitude of victims, she said. [Well reasoned! Or is it obvious? Bob]

And while Pechman took Maxwell's age and lack of criminal record into account, she said the prison term was necessary to provide a deterrent to other hackers.

The robot virus program, or "botnet" software, used by Maxwell was sent over the Web, where it sought out computers with exploitable security flaws. [...which it found 407 times on Defense Department computers? Bob] He pleaded guilty in May to a felony charge of conspiracy to intentionally cause damage to a protected computer.



Why are so many media firms rushing to use technology that is a favorite target for hackers?

http://www.engadget.com/2006/08/25/fairuse4wm-strips-windows-media-drm/

FairUse4WM strips Windows Media DRM!

Posted Aug 25th 2006 11:48AM by Ryan Block Filed under: Portable Audio



Towards ubiquitous surveillance: “You have nothing to worry about if you're not guilty.” (Is this proof that the 'no fly list' isn't working?)

http://www.washingtonpost.com/wp-dyn/content/article/2006/08/28/AR2006082800849.html?nav=rss_opinions/columnsandblogs

A Tool We Need to Stop the Next Airliner Plot

By Michael Chertoff Tuesday, August 29, 2006; Page A15

Imagine that our troops in Afghanistan raided an al-Qaeda safe house and captured a computer containing the cellphone numbers of operatives in Europe. Wouldn't it be important to know whether one of those cellphone numbers was used to book a transatlantic flight? Unfortunately, today our ability to make that connection remains limited: Information that terrorists readily share with travel agents cannot easily be shared throughout the United States government. That needs to change.



Global warming update

http://www.technewsworld.com/rsstory/52663.html

Almanac Forecasts Frigid Winter

By David Sharp AP 08/28/06 8:00 PM PT

According to the Farmers' Almanac, the coming winter should be colder than normal from coast to coast. It'll be especially snowy across the nation's midsection, much of the Pacific Northwest, the mountains of the Southwest and parts of eastern New England, the almanac predicts.



I'll bet there would be a market for a “Legal guide to municipal WiFi”

http://www.technewsworld.com/rsstory/52561.html

Municipal WiFi Networks Popping Up All Over

By Paul Korzeniowski TechNewsWorld 08/29/06 4:00 AM PT

A large number of uncertainties are associated with municipal WiFi at this stage, so municipalities are starting slowly. "Most of the cities are starting small and seeing what the true implementation hurdles are before rolling out the services completely," said Christopher Baum, research vice president at Gartner.



At last!

http://www.eweek.com/article2/0,1759,2009403,00.asp?kc=EWRSS03119TX1K0000594

Unpatched Flaws to Be Published

By Ryan Naraine August 28, 2006

A security company that pays hackers for information on software exploits and flaws plans to release a list of 29 unpatched flaws in products sold by a host of big-name vendors, including Microsoft, IBM, Apple Computer and Novell.

The Aug. 28 disclosure from TippingPoint's ZDI (Zero Day Initiative) flaw bounty program is a significant change to the way the 3Com-owned company has handled the disclosure of vulnerability data it buys from external researchers.

Instead of waiting for software makers to issue patches, TippingPoint will announce the flaw purchase in bare-bones advisories at the time the issue is reported to the vendor.

... "We're not identifying the software or product versions. [Isn't that wimping out? Bob] We're simply naming the vendor, the date the issue was reported and the severity of the vulnerability," Endler said.



Does this indicate they now grasp the obvious? Is this an indication that their next operating system release will not be a “must have” for their largest customers? Is this just one more sign Microsoft is becoming just another software company? Or D: all of the above.

http://www.eweek.com/article2/0,1759,2009479,00.asp?kc=EWRSS03119TX1K0000594

Microsoft Offers Broader Support for Legacy Products

By Peter Galli August 28, 2006

Microsoft seems to have finally cottoned onto the fact that it can drive revenue from the use of legacy software by some of its largest customers, announcing on Aug. 28 a new Custom Support Agreement program.



http://news.com.com/2100-1041_3-6110277.html?part=rss&tag=6110277&subj=news

Digital cameras focus on revised reality

Consumers are embracing camera features that make them look thinner and more youthful. But what about society's trust in photography?

Photos: Camera makeovers By Candace Lombardi Staff Writer, CNET News.com Published: August 29, 2006, 4:00 AM PDT

Want to look thinner? Taller? Tanner? Don't worry, there's a camera for all that.

Today's cameras will let you do more than adjust the flash; they'll let you adjust reality. Photo-adjusting features that once required a PC and special know-how are now allowing consumers to alter a photo as soon as it's snapped.

Some new Hewlett-Packard cameras include a feature that makes subjects look thinner, while another mode makes facial lines and pores virtually disappear. A "skin tone" feature on some Olympus models can give consumers a leisure-class tan. Other manufacturers offer modes to make the colors of the world richer as you capture them. Using these new in-camera tools, consumers can even crop out ex-boyfriends, or put a virtual frame around a new one. [Let's hope they don't mean that in the evidentiary sense... Bob]



You mean Amazon is not alone?

http://www.bespacific.com/mt/archives/012282.html

August 28, 2006

Comparison and Evaluation of 10 Major Internet Bookshops

Hirwade, Mangala and Hirwade, Anil and Bherwani, Mohini (2006) Evaluative study of major Internet bookshops. ILA Bulletin XLII(1):pp. 32-43.

  • "Internet Bookshops are the online bookshops that allow the user to search the items of his interest, navigate, make a query, communicate, place an order, bargain and negotiate. At its simplest the Internet Bookshop or online bookshop list the products for sale or the services offered and invite the customer to phone, fax or e-mail their order. The present paper evaluates major ten Internet bookshops by using the evaluation criteria like Authority, variety of collection, help menu, shopping procedures, payment acceptance, special facilities for online purchase, user search support, product details, navigation facilities and discounts on the products. A 100 marks scoring system has been adopted to assign the scores to each Internet bookshop under study. Based on the marks obtained these bookshops are graded into five categories viz. Excellent, Very Good, Good, Average and Poor. Amazon.com, USA and Amazom, UK fall uder excellent category while the Internet bookshops from India viz D.K.Agencies and Khemraj fall under good and average category respectively."



“God will get you for this!” Book of Bob, Chapter one Verse one

http://www.bespacific.com/mt/archives/012278.html

August 28, 2006

Pew Research Center for the People and the Press Report on Religion and Politics

Many Americans Uneasy with Mix of Religion and Politics - 69% Say Liberals Too Secular, 49% Say Conservatives Too Assertive, Released August 24, 2006.



Think of it as using the legal department as just another strategic tool. Any barrier to entry keeps the competition at bay. Should you NOT use every resource available? (What is needed is a “regulated ticket exchange” modeled on the Options market. Why shouldn't tickets be priced at “market?”)

http://techdirt.com/articles/20060828/152541.shtml

Apparently Ticketmaster Doesn't Like Having Competition

from the and-so-it-goes dept

Remember back in the day when Ticketmaster was the absolute monopoly in ticket sales for various venues and events? You simply couldn't avoid Ticketmaster and their ridiculous fees upon fees. A dozen years ago, Pearl Jam took on Ticketmaster, claiming that the company had a monopoly on ticket sales and were able to keep ticket price artificially high. Well, it appears that Ticketmaster doesn't like the idea that the internet has brought in new competition. Three years ago, we noted that, due to competition from online resale sites, Ticketmaster was launching a new service to auction off tickets itself. However, sites like Stubhub, eBay and Craigslist appear to have much better traffic for such things -- perhaps due to the public's general dislike of Ticketmaster for years and years of ridiculous fees. Of course, when you have a monopoly that is being attacked by competitors, what do you do? You go to the government to get new legislation passed to help you hold onto your monopoly. Ticketmaster is trying to get laws passed that would make it illegal to sell tickets above face value... unless you have an arrangement with the venue and they share in some of the profits. Ticketmaster, of course, already has many such deals in place. They spin this as "protecting" ticket buyers from fake scalped tickets, but the other sites in the space note that bogus tickets aren't a very big problem, and there are often other ways to deal with it. Instead, this looks like Ticketmaster is running to the government to help it keep its supposed monopoly in the face of competition.



One law to rule them... Oh, wait, that was a fantasy.

http://techdirt.com/articles/20060828/165835.shtml

Why Should EchoStar Wait For Patent Review When TiVo Doesn't Have To?

from the fairness? dept

In the ongoing battle over patents concerning DVR technology, both EchoStar and TiVo are suing each other, claiming the other company infringes on its patents. As was all over the news recently, TiVo won the first round, convincing a judge to tell EchoStar it needed to turn off its DVRs (a decision since stayed by the appeals court). However, a judge looking at the patent suit in the other direction has now told EchoStar it needs to wait until the Patent Office has reviewed the patent in question. This actually makes a lot of sense, and we all know at least one company that would still have over $600 million it was forced to give away if other judges followed similar rules. However, it seems a bit unfair that TiVo's case continued to move forward without USPTO review, while EchoStar needs to wait. It only seems fair to treat both cases the same. As it stands now, TiVo is in a much better bargaining position -- it's won its first case, and EchoStar has to wait before its own case will be reviewed. While it makes sense to allow USPTO review, shouldn't the courts follow the same rules in dealing with these types of cases?



Brilliant! This should drive up readership like nothing they've tried in years!

http://techdirt.com/articles/20060829/020547.shtml

New York Times Tells Brits They Can't Read Article On UK Terror Case

from the jurisdictional-silliness dept

Questions of legal jurisdiction over online content are nothing new at all. Over the years, we've pointed to plenty of legal cases that raised issues about online publications, and whether the content was liable under local laws in countries outside of where the publisher (or its servers) were based. Unfortunately, there still isn't a general agreement on what laws apply, and that makes things risky. Apparently, the NY Times didn't want to risk any such lawsuit in the UK, so when it published an article yesterday about the British terror case, it used some of its geographic ad targeting technology to also block out visitors from the UK from reading the content. This is to stay on the right side of British laws that "prohibits publication of prejudicial information about the defendants prior to trial." Of course, the Times then went on to publish an article proudly stating how they blocked the content from UK readers, which makes you wonder how effective the ban really is. By calling attention to it, it seems pretty likely that plenty of folks in the UK will be able to read the same (or similar) content from plenty of other sources. This isn't to call out the Times for the practice, but to question whether such laws are actually still possible in a world with a global internet.



What makes you think you're immune?

http://www.techzonez.com/comments.php?shownews=19104

Nine in 10 PCs infected with spyware

Posted by Reverend on 28 Aug 2006 - 19:27 GMT

Techzonez Nine out of ten PCs are infected with spyware, new research has found.

Full story: vnunet



http://www.infoworld.com/article/06/08/29/HNgoglelibraryscan_1.html?source=rss&url=http://www.infoworld.com/article/06/08/29/HNgoglelibraryscan_1.html

Google, UC disclose library scan agreement

Google contracts to digitize millions of books from the university's libraries

By Juan Carlos Perez, IDG News Service August 29, 2006

The University of California has released a copy of its contract with Google to have the search engine giant digitize millions of books from the university's libraries.

The document shines a light on the type of agreement Google is reaching with some of the world's largest academic libraries as part of its controversial project to scan portions of their collections.

The University of California decided to post the contract publicly to satisfy a "general interest" in the document, a university official said via e-mail. The disclosure follows a formal request to obtain a copy of the document filed by IDG News Service in mid-August with the university. The contract can be viewed here.



The more the merrier!

http://www.researchbuzz.org/wp/2006/08/28/worldcat-launches-with-10000-libraries-worldwide-searchable/

August 28, 2006

WorldCat Launches With 10,000 Libraries Worldwide Searchable

Filed under: Reference

Why yes, I am still catching up. I’m ALWAYS catching up. Anything else? Anyway, WorldCat.org has officially launched: http://www.worldcat.org . It’s in beta. Over 10,000 libraries in the OCLC cooperative are searchable from this one little box. How groovy is that? (And if you’re having a hard time wrapping your head around this, or the fact that there are over 70 million entries for items in this database, check out http://www.oclc.org/worldcat/grow.htm, which’ll give you a window to watch stuff being added into the database in real-time. I found this fascinating. I am a nerd.)



http://www.dottocomu.com/b/archives/003177.html

August 28, 2006

Japanese government prepares online lie-detector

Japan's Ministry of Internal Affairs and Communications is, for reasons best known to it, earmarking Y300 mn in its 2007 budget to produce what the Asahi Shimbun terms a lie-detector for online information.

The reality appears to be not so much that as an automated fact-checker that draws on related information to spot how likely something is to be a load of old balls. [Is that a l;iteral translation of the Japanese or a British-ism? Bob] The Ministry envisages it being able to give you search results in order of their reliability, or tell you that a piece of info is 95% crap and ask if you'd still like to display it. Example questions they see it being able to answer include "is this company analysis on the mark?", "is this a natural-sounding description of the political situation within Lebanon?", or "are the functions of this overseas electrical appliance described accurately in this auction listing?".

They note that key hurdles will be whether they can find reliable internet-based sources of information related to a search, and develop technologies that can accurately assess meaning and provide high-level machine translation, amongst other things.

It's unclear how they plan to establish the reliability of information, beyond taking the route of building an engine that tells you how in- or out-of-consensus a particular document is based on word frequencies or some other measure. And we somehow doubt that the AI Holy Grail of software that understands the meaning of natural language and can translate it accurately is about to be reached by some government researchers with $3 mn in funding. But still, nice of them to try.



Think you might have a skill? Here is one way to find out.

http://www.nytimes.com/2006/08/27/arts/television/27heff.html?ei=5090&en=b993c2e50a7b705d&ex=1314331200&partner=rssuserland&emc=rss&pagewanted=all

Web Guitar Wizard Revealed at Last

EIGHT months ago a mysterious image showed up on YouTube, the video-sharing site that now shows more than 100 million videos a day. A sinewy figure in a swimming-pool-blue T-shirt, his eyes obscured by a beige baseball cap, was playing electric guitar. Sun poured through the window behind him; he played in a yellow haze. The video was called simply “guitar.” A black-and-white title card gave the performer’s name as funtwo.

[Jump right to the video: http://www.youtube.com/watch?v=QjA5faZF1A8 ]



http://www.informationweek.com/news/showArticle.jhtml?articleID=192300841

Most Damaging Attacks Rely On Stolen Log-ins

Security safeguards need to identify, not just the user, but also the machine logging into the network.

By Gregg Keizer TechWeb Aug 28, 2006 03:15 PM

More than 8 out of every 10 computer attacks against businesses could be stopped if enterprises checked the identity of not only the user, but also the machine logging onto its network, a report released Monday claimed.

The study, conducted by a California research firm and paid for by BIOS maker Phoenix Technologies, used data from cases prosecuted by federal authorities between 1999 and 2006 to reach its conclusions.

"We wanted to get an honest viewpoint that wasn't opinion- or survey-based," said Dirck Schou, the senior director of security solutions at Phoenix. The problem with acquiring data on computer attacks, including the amount of damage done, is that companies are often hesitant to admit to a breach. "That's the beauty of this [data]," said Schou. "It's only looking at those who have actually suffered an attack."

According to the report, attacks based on logging in with stolen or hijacked credentials cost businesses far more, on average, than the typical worm or virus assault. When a privileged account is penetrated by an unauthorized user, the average damage runs to $1.5 million, the report said. The average cost from a single virus attack was much smaller: under $2,400.

"Cyber criminals who accessed privileged accounts obtained IDs and passwords through many means," the report said. "Network sniffing, use of password cracking programs, and collusion with insiders. It was also common for employees to share their IDs and passwords with coworkers who later left the organization and used that knowledge to gain access."

To bolster that outsider-as-attacker claim, the study also said that nearly 6 in 10 attackers had no relationship with the victim. (Just over a third (36 percent) were current and former employees.) Although the report's data contradicts other surveys that have pegged company insiders as the root of most attacks, the idea that credentials are good for ill-gotten gains isn't new. Earlier this year, for example, IBM predicted that attackers would increase their attacks against employees rather than networks.

"Viruses equal vandalism, but unauthorized log-ons lead to theft," said Schou. However, he acknowledged that the latter can come from the former, with worms and Trojan horses increasingly after information such as usernames and passwords rather than hoping to injure or bring down a network.

Overall, unsanctioned computers -- not among the systems actually expected to access the network -- were used in 84 percent of the attacks. The bulk of the attacks -- 78 percent -- came from at-home personal computers.

Naturally, Phoenix made much of that conclusion. It claimed that 84 percent of the attacks in the survey could have been prevented had the victim been protected by device authentication schemes. Such security identifies not only the user by checking ID and password, but can tell if the hardware has been authorized to connect to the network. Phoenix, for instance, sells a solution dubbed TrustConnector 2, that creates a unique identity for every authorized PC.

"What surprised us was the intensity and preponderance in unauthorized access attacks," said Schou. "We think device authentication is in the right time, right place.

"There are a lot of companies that aren't securing the device."



..but it's still organic, right?

http://www.latimes.com/features/health/la-he-closer28aug28,0,3552892.story?coll=la-home-health

Latest food additive: Viruses

The FDA-approved bacteria eaters work on deli meats and other ready-to-eat foods.

By Hilary E. MacGregor, Times Staff Writer August 28, 2006

If you want to get rid of a pest, why not use a littler pest to plague it? That's the tack OKd last week by the Food and Drug Administration, which has for the first time approved the use of bacteria-eating viruses as an additive to foods.

From now on, these viruses — known as bacteriophage or phage — can be sprayed on ready-to-eat cold cuts and luncheon meats by manufacturers to prevent listeriosis, the most deadly of all food-borne illnesses in this country.

... The viruses are grown in a broth of the listeria they are bred to kill — which was, Zajac said, a concern.

Monday, August 28, 2006

The “new AOL” is certainly making a reputation for itself!

http://www.infoworld.com/article/06/08/28/HNaolbadware_1.html?source=rss&url=http://www.infoworld.com/article/06/08/28/HNaolbadware_1.html

AOL 9.0 accused of 'badware behavior'

StopBadware.org advisers users to steer clear of the software

By Robert McMillan, IDG News Service August 28, 2006

AOL's free Internet client software has earned the company a slap on the wrist from StopBadware.org, a consortium set up to combat malicious software. In a report set to be released Monday, the group advises users to steer clear of the software because of its "badware behavior."

The report blasts the free version of AOL 9.0 because it "interferes with computer use," and because of the way it meddles with components such as the Internet Explorer browser and the Windows taskbar. The suite is also criticized for engaging in "deceptive installation" and faulted because some components fail to uninstall.

The main problem is that AOL simply doesn't properly inform users of what its software will do to their PCs, said John Palfrey, StopBadware.org's co-director. "We don't think that the disclosure is adequate and there are certain mistakes in the way the software is architected in terms of leaving some programs behind," he said. "When there are large programs, some of which stay around after you've thought you've uninstalled them, they need to be disclosed to the user."

Because AOL has taken steps to address StopBadware.org's concerns, the group has held off on officially rating AOL 9.0 as badware, Palfrey said.

... StopBadware.org bills itself as a "Neighborhood Watch" of the Internet. It is run out of two well-respected university departments: Harvard University's Berkman Center for Internet & Society in Cambridge, Massachusetts, and University of Oxford's Internet Institute in the U.K.

... AOL has also come under fire for licensing its free antivirus software, called Active Virus Shield, with what anti-adware advocates view as excessive advertising and data gathering provisions.

... StopBadware.org makes its reports available on this Web page.



Soon, every recorded conversation will be transcribed this way... Maybe.

http://www.researchbuzz.org/wp/2006/08/27/some-new-features-at-podzinger/

Some New Features at PodZinger

Filed under: Multimedia-Video, Multimedia-Audio

Last February I reviewed a site called PodZinger. PodZinger, if you don’t remember, does machine transcription of podcasts and then makes the material searchable, which is just lovely. (And as far as I know they have that arena pretty much to themselves, which boggles the mind.) PodZinger’s at http://www.podzinger.com/ .



And IT managers are not normally trained for this... Remember to keep those budget meeting transcripts where the CEO said the organization couldn't afford the spend money on security.

http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9002748&source=rss_topic84

IT execs on firing line over security breaches

The most recent incident involved AOL's CIO

Jaikumar Vijayan August 25, 2006 (Computerworld) --

The cost of data breaches may be getting a lot higher for IT professionals who are deemed to be responsible for failing to properly secure corporate information.

For example, AOL LLC's chief technology officer abruptly resigned this week in the aftermath of a disclosure that the company had publicly released data on searches done by about 650,000 of its online subscribers. AOL also fired two workers in its research division, which was responsible for the data release and had been overseen by now-former CTO Maureen Govern.

It was the second time this month that high-level technology managers lost their jobs because of data breaches. On Aug. 3, Ohio University announced that it had sacked two top IT managers for what it saw as their failure to prevent a series of breaches that were discovered at the Athens-based school during the spring

... IT managers should expect firings and other harsh disciplinary actions to become more common as organizations face increasing public pressure to address data breaches that they suffer, said Robert Scott, managing partner at Dallas-based law firm Scott & Scott LLP.

"In order for companies to have a credible position in the marketplace, they're going to have to explain in a public way what they have done to address the issue," Scott said. "The risks that companies face from a liability and a reputation perspective are such that when breaches occur, people will not only need to be held accountable, but heads will have to roll." [“It is better to look proactive than to be proactive.” Fernando Bob]

... Tim O'Pry, CTO at The Henssler Financial Group in Kennesaw, Ga., said accountability is necessary, and it's reasonable to expect that people will lose their jobs where negligence has occurred.

The problem is that many times, the workers responsible for a security breach are only following what until then had been accepted practices within their companies, O'Pry said. And they may not have had the responsibility or authority to change the practices, he noted.

... Forging closer ties with IT audit teams is a key to survival in the new environment, Hession advised. "If you think you have an issue, go to audit and tell them about it," he said. If the audit group concurs that a security problem exists, it should be easier to get the resources needed to fix it, Hession added. And if the auditors agree that there's an issue "and nobody does anything about it, you probably don't need to be falling on your sword" if a data breach does occur, he said.

Companywide outreach and communication also are key, according to Scott. Managers who are responsible for IT security "need to do a better job of articulating a business case [that] suggests that ignoring data security and shuffling it to the bottom of the priority list is a recipe for disaster," he said.

In addition to the incidents at AOL and Ohio University, the massive security breach disclosed by the U.S. Department of Veterans Affairs in May resulted in a wide-ranging shake-up that included the resignation of the agency's chief information security officer. But the CISO's departure is thought to have been driven by his frustration over organizational issues within the VA, which traditionally has split most IT and security responsibilities among its three main operating divisions.



http://techdirt.com/articles/20060828/004204.shtml

Can We Set Up An Online Learning Class About Our Screwed Up Patent System?

from the might-help dept

There's been a lot of buzz in the last few weeks over the patent awarded to the provider of online courseware, Blackboard. The patent seems ridiculously broad and basically seems to cover the entire concept of e-learning software. So, of course, what else would Blackboard do, but sue another company for patent infringement? Blackboard claims that people are overreacting, but as people go through and breakdown the specific claims in the patent, it just looks worse and worse. There is simply no reason that this patent ever should have been issued. There is nothing in the patent that is remotely new or non-obvious -- and it's difficult to make even the slightest case that the issuance of this patent has any societal benefit. Instead, you could make a pretty good case that it's done plenty of harm. In the meantime, plenty of people are saying that the blame should fall entirely on the patent system and not Blackboard, but they are defending their decision to sue another provider. Hopefully, the growing backlash (especially from academia) against Blackboard for resorting to a lawsuit means that more universities decide to go with other software providers.



Virtual Law

http://techdirt.com/articles/20060828/025121.shtml

Who Do You Blame When Your Virtual Bank Fails?

from the should-have-thought-about-that-earlier dept

It's not like there haven't been warnings about the blurring boundary between online games and the real world when it comes to the legal system. In all of these online worlds, especially when real money gets involved, people just aren't clear as to whether or not in game actions have real world legal implications. On the one hand, you have people who will say that if something of real value is "stolen" in the game, that's a crime. Something of value has been lost. However, this gets tricky when you realize that some online games have theft or other crimes as a part of the gameplay on purpose. If stealing goods from other players is a part of the game, how can it be illegal outside of the game? So, even if it's not a major part of the game -- or if it's a programming flaw that allows it -- how can it be fair to say it's "illegal"? So, now, take that same issue to a larger scale. What if someone sets up an in-game bank? Then, it turns out the bank is actually a scam, and the owner simply takes all the money people gave him and runs? That's apparently exactly what happened recently. It may be tempting to say the guy committed real fraud -- but, again, the game let him do this. There was no guarantee within the game that the bank was legit. There was no FDIC "backing" the bank. There was a very real risk in putting money into that bank, but people did so by choice, as part of the game. The real issue is that too many online worlds are really just punting on the issue of an in-game legal system or conflict resolution system. They're forgetting that they've basically built a world -- and that world needs some sort of legal system as well. [Sounds like a call for articles to me... Bob] If there's a problem, then let the in-game mechanisms sort out the results or punishment. Because, if there isn't an official law enforcement/judicial process, you'll get the next best thing: an online mafia who will run the online world for you. Either way, that's still better than cluttering up the real world courts over these types of disputes.



Sometime you have to let your inner intellectual take over...

http://beeradvocate.com/news/stories_read/673

Beer: The Midwife of Civilization

Horst Dornbusch on Beer and Civilization #10

[I want a T-shirt that says: “Bibo cerevisiam, ergo sum” Bob]

Sunday, August 27, 2006

A friend dropped one of these CDs on me yesterday. I plan to make copies for my students and thought you might find them useful yourselves. The will make great stocking-stuffers come Christmas!

http://www.ttcsweb.org/osswin-cd/index.htm

TTCS OSSWIN CD

Version 1.45 available July 28th, 2006. Changelog | Download.

What is the TTCS OSSWIN CD?

The TTCS OSSWIN CD is a collection of over 100 Free/Open Source software for home and business users using the Microsoft Windows 98SE/Me/2000 and XP operating systems.



Help me understand why anyone would rely on evidence obtained by this guy? No chance he planted it? Is illegally obtained information admissible?

http://yro.slashdot.org/article.pl?sid=06/08/26/1946232&from=rss

The Story of the Pedophile-catching Hacker

Posted by Zonk on Saturday August 26, @04:45PM from the small-world dept. Privacy The Courts The Internet

missing30 writes "A Turkish hacker seeding usenet groups with trojan horses has made it a habit to hunt down pedophiles trolling the groups. The cases go back to 2000, with the mysterious good samaritan responsible for several arrests. The man now has tacit approval from the FBI for his actions." [Since we can't catch him... Bob]

From the article: "At the urging of Montgomery Police Capt. Kevin Murphy, '1069' eventually turned over more and more information that led back to a computer owned by Bradley Joseph Steiger, who had worked as an emergency room physician in Alabama. The hacker's finds included information from Steiger's AT&T WorldNet account, records from his checking account, and a list of directories on his computer's hard drive where sexually explicit photographs were stored."



Isn't this sad? We should help them with this problem. I'll take a few million if you will.

http://www.technewsworld.com/rsstory/52638.html

Google Seeks SEC Exemption on Investing

By Miles Weiss Bloomberg News 08/26/06 4:00 AM PT

Google's $10 billion would make it a midsize mutual fund.



http://www.lessig.org/blog/archives/003499.shtml

“Steal This Film”

OpenBusiness.cc has a blog entry about a film about “piracy” and its politics in Sweden, including a bit about the Swedish Pirate Party. Appropriately enough, you can download it for free.



http://www.financialexpress.com/fe_full_story.php?content_id=138464

Kerala logs Microsoft out

M SARITA VARMA Posted online: Saturday, August 26, 2006 at 0025 hours IST

THIRUVANANTHAPRUAM, AUG 25: After the cola ban, it is now the turn of Microsoft to log out of Kerala. Children in 12,500 high schools in the state, India’s most literate, will not be taught Windows. Instead, instructors are lining up Linux for them. This is because Kerala has chalked out a plan for migrating its high school students to free software platforms in three years.

Although Linux was already blipping on the Kerala IT@School project radar, and the plans of VS Achuthanandan’s government to develop the state as a Foss (free and open software systems) destination has expedited the open software plans.

“Free software guru Richard Stallman’s visit last week had nudged the schools to discard the proprietary software altogether,” state education minister MA Baby told FE. “Stallman has inspired Kerala’s transition to free software on the lines of an exciting model of a Spanish province, which did the same,” the minister said.

... There are other reasons as well. A sting operation by Microsoft in October 2005 had not endeared the proprietary software to PC and peripherals dealers. Often PC vendors are caught between customers’ demand for free pirated software along with hardware, and the fine print of law. Some dealers in Kerala even see the Foss market as a narrow, but a safe corridor out of this mess.



Learn mashups from IBM. Who'd a thunk it?

http://www-128.ibm.com/developerworks/edu/x-dw-x-ultimashup1.html?S_TACT=105AGX59&S_CMP=GR&ca=dgr-lnxw02aWebMashupsPart1

The ultimate mashup -- Web services and the semantic Web, Part 1: Use and combine Web services

Explore mashup concepts and build a simple mashup

developerWorks Level: Intermediate Nicholas Chase (ibmquestions@nicholaschase.com), Freelance writer, Backstop Media 22 Aug 2006

... The purpose of this tutorial series is to create a mashup application so smart that users can literally add and remove services at will, and the system will know what to do with them. The series progresses as follows:



http://digg.com/playable_web_games/Play_Simcity_for_free

Play Simcity for free

rcvictory submitted by rcvictory 13 hours 28 minutes ago (via http://simcity.ea.com/play/simcity_classic.php )

Play original simcity online at no cost



The Future?

http://www.washingtonpost.com/wp-dyn/content/article/2006/08/25/AR2006082501659.html

Brazilian Drug Users Won't Face Jail

The Associated Press Friday, August 25, 2006; 11:22 PM

RIO DE JANEIRO, Brazil -- Drug users who don't engage in dealing will no longer be sent to prison under a new drug law now in effect across Brazil, officials said Friday.