Monday, November 06, 2006

Yet another viable method?

http://it.slashdot.org/article.pl?sid=06/11/05/2234252&from=rss

Verifiable Elections Via Cryptography

Posted by kdawson on Sunday November 05, @09:13PM from the but-suppose-they-don't-want-to-make-cheating-impossible? Dept. Security Politics

An anonymous reader writes, "Cryptographer David Chaum and his research team have invented a new voting protocol which allows voters to verify that their vote has been correctly cast and counted. This is enabled using a surprisingly low-tech technique of cryptographic secret sharing. The secret — your marked ballot — is split into two halves using a hole punch" You take half home and can verify later via a Web interface how your particular ballot was counted.




http://www.concurringopinions.com/archives/2006/11/neil_richards_o.html

Neil Richards on Information Privacy

posted by Daniel J. Solove November 05, 2006

Professor Neil Richards of Washington University Law School has posted on SSRN his recent essay, The Information Privacy Law Project, 94 Geo. L.J. 1087 (2006). He reviews my book, The Digital Person, and offers an interesting and insightful critique. Although he takes issue with some of my arguments and with the term "privacy," I find his review to be mostly a friendly amendment rather than an attack. Here's the abstract:



If the target of an interrogation can detect the “technique” being used, it isn't worth protecting in the first place... (Psych 101?)

http://www.cnn.com/2006/POLITICS/11/04/terrorism.detainees.ap/index.html?eref=rss_topstories

Bush administration: Ex-CIA prisoner shouldn't speak to attorney

POSTED: 12:17 p.m. EST, November 4, 2006

WASHINGTON (AP) -- A suspected terrorist who spent years in a secret CIA prison should not be allowed to speak to a civilian attorney, the Bush administration argues, because he could reveal the agency's closely guarded interrogation techniques.



If they're innocent they have nothing to hide?

http://www.gulfcoastgateway.com/apps/pbcs.dll/article?AID=/20061106/NEWS01/611060324/1006

Published - November, 6, 2006

Newspapers push for FEMA records

Speech, privacy rights advocates take sides on hurricane payouts

Jeff Cull jcull@news-press.com

A battle between open government and individual privacy resumes Tuesday in federal appeals court as three Gannett Inc. newspapers in Florida seek access to hurricane-relief records.

The newspapers want the government to disclose who got federal aid and how much after four hurricanes battered Florida in 2004. A federal judge denied the request in November. The case now will be heard in the 11th U.S. Circuit Court of Appeal in Atlanta. The three-judge court is expected to rule within the next six months.

"This is a real test of whether everything in government is a privacy issue," said Charles Davis, executive director of the Freedom of Information Center at the University of Missouri School of Journalism.

... "How can we know whether billions of taxpayer dollars are being spent appropriately without specific information on where the money went?" Marymont said. "This isn't a question of journalists' access to information but residents' access. People want to know if they were treated the same from house to house, neighborhood to neighborhood, storm to storm."

... In a separate suit filed by the Sun-Sentinel, a federal judge this year ordered FEMA to disclose the addresses, but not identities, of hurricane victims who received aid.



Interesting map of phishing sources...

http://www.f-secure.com/weblog/#00001012

New phishing statistics

Posted by Mikko @ 11:40 GMT

Phishtank, a service run by the good folks at OpenDNS, have published their first set of phishing statistics.

Interesting stuff, showing that Paypal and eBay continue to be the most targeted organizations in phishing attacks, but some German banks are climbing up the scales.



Isn't this a common argument? Don't you sign a traffic ticket so you can drive off rather than go to jail?

http://techdirt.com/articles/20061106/002555.shtml

Australian Firm Forced To Rehire Employee It Fired For Viewing Porn On Work Computers

from the so-now-it's-allowed? dept

Last year, NCR Australia fired a long-term (31 years) employee after it discovered 175 pornographic pictures stored on his work computer. That kind of story isn't all that uncommon these days -- but what is strange is that the Industrial Relations Commission has apparently told the company it needs to hire the guy back, saying that his dismissal was unfair, as well as "harsh, unreasonable and unjust." The man in question claimed that such content was routinely passed around at work, including from his supervisor. The review found that, even though having porn on the computer may have violated the signed policies of the company, since the signing of that form was done in a "mechanical, unthinking routine," it probably was meaningless. I would imagine this does not mean that Australians are free to surf porn at work whenever they feel like it, but they might at least make a reasonable defense as to why they shouldn't be fired for it.



We can, therefore we must? I suppose this will be another case of “some low level guy (we fired him) did this. We didn't know it was happening.”

http://americablog.blogspot.com/2006/11/republican-fake-phone-call-scandal.html

Republican "fake phone call" scandal spreads - now in Philly too

by John in DC - 11/05/2006 09:39:00 PM Sunday, November 05, 2006

This is turning into a big story. They're doing it across the country - Kansas, NH, and now PA. This is the Republican October Surprise, launched in November. It's to cheat, pretend that they are Democrats calling voters and then piss the voters off so much that they don't vote for the Democrats.

That's called lying and cheating in order to suppress the vote, and it's illegal. And the Republican party admits they're doing it.

States in which GOP fake calls are happening so far:



Techie stuff... Video, music, image and document formats.

http://www.zamzar.com/conversionTypes.php

Conversion Types

Zamzar supports conversion between a wide variety of different file formats. We're adding support for new formats all the time - if there's a format that you'd like us to support why not contact us and we'll do our best to add it.

Click on a category to see details of our conversion support:



Customer service?

http://www.ps3land.com/article-951.php

Bestbuy preorders deemed "a system glitch"

by Greg Bergen Posted 5 Nov 2006

Late last night, Bestbuy customers were able to fill out preorder forms for the PlayStation 3, online at www.bestbuy.com. The whole process seemed legit as customers believed they could obtain a PS3 without having to lineup or camp outside the store on launch day. However, the simple fact that Bestbuy gave customers preorders for a console should shock everyone, considering the fact that they never do preorders. There were reports that some people were actually able to fill out 12-15 preorders using different accounts. The whole system was hectic and fueled by the need for PlayStation 3.

To clear up this mess, we at PS3Land were able to get a hold of a Bestbuy sales representative via their public number 888-BESTBUY. The man assured us that the whole preorder process was a system glitch. Informed us that Bestbuy does not do preorders and that everyone who was able to obtain a preorder on their site will not be receiving one and will be given a full refund.



Killing trees.

http://www.businessweek.com/technology/content/nov2006/tc20061105_572061.htm

Google's New Frontier: Print Ads

With a slew of big-city newspapers on its side, Google sets out to reproduce the success of its online ad programs—offline

by Jon Fine November 6, 2006, 10:0PM EST

... Google Print Ads is notable for both the number of newspapers that have signed on, as well as the participants it's attracting. Among the participating papers are some of the nation's largest and most renowned: The New York Times, The Washington Post, The Boston Globe, the Chicago Tribune, The Philadelphia Inquirer, and The Denver Post. More than 100 advertisers will take part as well.

Sunday, November 05, 2006

Must read: Sunday Dilbert explains the world...

http://www.unitedmedia.com/comics/dilbert/



It is easy to “ban” it is hard to “teach”

http://news.yahoo.com/s/csm/20061103/cm_csm/yjohnson;_ylt=Ag7YlvMLy2ATusXEz2PjMl7MWM0F;_ylu=X3oDMTA3YWFzYnA2BHNlYwM3NDI-

Schools are banning tag. What's next: musical chairs?

By Dean P. Johnson Fri Nov 3, 3:00 AM ET

PITMAN, N.J. - More and more elementary schools are banning the game of tag from playgrounds. Why? To prevent accidents (read: lawsuits) and to keep kids' self-esteem intact. But if physical harm and psychological harassment can be hidden in a simple game of tag, surely educational experts must be on alert for other forms of abusive playground games.


Of course, it could be worse...

http://news.yahoo.com/s/ap/20061105/ap_on_re_us/fingerprinting_students;_ylt=AvxZFbn2hQI7H35E45sUtF_MWM0F;_ylu=X3oDMTA3MjBwMWtkBHNlYwM3MTg-

3 Calif. schools to fingerprint students

Sun Nov 5, 4:59 AM ET

SANTA BARBARA, Calif. - A plan to fingerprint elementary school students when they buy lunch has some parents worrying that Big Brother has come to the cafeteria.



How to identify vulnerable infrastructure targets? Read the news!

http://news.yahoo.com/s/ap/20061105/ap_on_bi_ge/europe_blackouts;_ylt=Am4jSRkQwR7DWJLBqPFE8AbMWM0F;_ylu=X3oDMTA3b2NibDltBHNlYwM3MTY-

Power shortage leaves Europe in the dark

By STEPHEN GRAHAM, Associated Press Writer 20 minutes ago

BERLIN - A power shortage in Germany triggered a cascade of blackouts across Europe, a German electricity said Sunday, halting trains, trapping people in elevators and plunging millions of homes into darkness.

... A private Germany company, E.On AG, said the problems began in northwestern Germany, where its network became overloaded, possibly because it shut down a high-voltage transmission line over the Ems River to let a ship pass safely.



As long as the nuclear facilities are open to inspection, this isn't a problem, is it? Is this a possible wedge in the “Arab countries united against the west” issue?

http://science.slashdot.org/article.pl?sid=06/11/04/1753211&from=rss

Nuclear Tech Race Is On In Middle East

Posted by Zonk on Saturday November 04, @03:41PM from the winner-could-also-be-the-loser dept. Power Science Technology Politics

CaroKann writes "The TimesOnline is reporting that six Middle Eastern nations have announced interest in developing nuclear technology. The nations involved are Algeria, Egypt, Morocco, Tunisia, the UAE and Saudi Arabia, according to the International Atomic Energy Agency. The Middle East Economic Digest states that most of these nations are interested in developing nuclear technology for the purpose of powering desalination plants. However, the International Institute for Strategic Studies, suggests that the sudden interest in nuclear technology is driven by the desire of the six nations to create a 'security hedge' in response to Iran's recent nuclear development program."



Win a court case, call the media. Okay, standard practice.

Win a court case, call the media, hand out the records? Someone needs an ethics class...

http://www.topix.net/content/ap/0505304264110959360316908889494233647849

O'Reilly Has Details of Kansas Abortions

The Associated Press By JOHN HANNA November 04, 2006

An abortion doctor plans to ask for an investigation of the state attorney general and Bill O'Reilly over comments by the Fox television host that he got information from Kansas abortion records, the doctor's attorneys said Saturday.

Saturday, November 04, 2006

Another story released on “hide the news day” (Friday) Obviously coffee does not keep you alert. (This story comes from the Privacy Foundation)

http://www.forbes.com/business/businesstech/feeds/ap/2006/11/03/ap3144984.html

Starbucks Loses Laptops With Worker Data

Associated Press 11.03.06, 5:46 PM ET

Starbucks Corp. said Friday it had lost track of four laptop computers, two of which had private information on about 60,000 current and former U.S. employees and fewer than 80 Canadian workers and contractors.

The data, which includes names, addresses and Social Security numbers, is about three years old, dating prior to December 2003, said Valerie O'Neil, a spokeswoman for the Seattle-based coffee retailer.

... O'Neil said Starbucks was in the process of notifying those affected, including an estimated 8 percent of its current work force, which numbers about 135,000 worldwide.

Starbucks has been looking for the laptops since early September after discovering they were missing from a closet in the corporate support center at its south Seattle headquarters, O'Neil said.


Another Friday story...

http://www.sltrib.com/ci_4599005

IHC laptop donated to thrift store contained employee information

By Linda Fantin The Salt Lake Tribune Article Last Updated:11/03/2006 04:35:01 PM MST

Posted: 4:23 PM- Intermountain Healthcare will destroy the hard drives of all recycled computers after an old laptop containing the names, job titles, social security and telephone numbers of 6,200 employees was donated to second-hand store and sold for $20.

The customer who bought the laptop from Deseret Industries discovered a single spreadsheet on a laptop whose memory was otherwise erased, [Something fishy here... Bob] said LDS Hospital spokesman Jess Gomez.

... The DI customer took the machine to television station KUTV [proof you can't hide these incidents? Bob] which alerted Intermountain and returned the computer about two weeks ago.

"Keep in mind this is a 14-year-old computer that sat in storage until last month when it donated to DI," Gomez said. "We feel very confident that no information was compromised in any way."


Lot's fishy here...

http://federaltimes.com/index.php?S=2331714

VA reports two more data security lapses

By RICK MAZE November 03, 2006

The Veterans Affairs Department is dealing with two new data security lapses affecting about 3,000 people.

About 1,600 veterans who received pulmonary tests at the VA hospital in Manhattan are being provided free credit counseling after the Sept. 8 theft of a laptop computer from a lab.

VA officials said the stolen laptop, which contained names and Social Security numbers of veterans who had received tests, had been triple-locked — in a locked corridor inside a locked room and secured by a cable to a cart, said VA spokeswoman Jo Schuda.

Some 80 percent of VA-owned computers are now encrypted, but data on this laptop was not because a decision had been made not to encrypt data being used for medical purposes. [“We call it our 'HIPPA be damned' policy” Bob]

... While that investigation was under way, VA officials learned of more missing data when computer disks containing the names and personal data on about 1,400 Oklahoma veterans were lost in the mail.

The disks contained information about veterans who had been treated at a McAlester, Okla., community-based outpatient clinic.

The disks included information on current and deceased patients at the clinic.

“It should not have been mailed, and they have promised to not mail anything like this again,” Schuda said.


Better customer service: “You don't have to steal our computers, we'll email the information directly to you!”

http://www.charlottesvillenewsplex.tv/news/headlines/4563112.html

UVa Emails Personal Information

Michael Gorsegner November 3, 2006

Imagine having your social security number emailed to a complete stranger. That is the reality for over 600 UVa students.

... After refusing an on camera interview, spokesperson Carol Wood said, "We trust all the students will quickly and honorably dispose of the information eliminating any chance of a problem."



I'll have to think about this...

http://www.lessig.org/blog/archives/003593.shtml

The Value of the Public Domain

I hadn’t seen this piece when it came out in July. The Value of the Public Domain by Rufus Pollock is an excellent analysis of how one might quantify the value of the public domain. It nicely introduces what otherwise strikes many as counter intuitive. Highly recommended.



If this had been a TV network, heads would roll and their stock would drop like a stone.

http://www.micropersuasion.com/2006/11/nba_pulls_vids_.html

Friday, November 03, 2006

NBA Pulls Vids from Google Video

The NBA and Google Video have terminated their landmark partnership, which was announced to much ballyhoo earlier this year. All games, which had been previously available for a fee, have been pulled down from Google. [Not worth keeping even as an extra marketing channel? Bob] This includes last year's NBA Finals. If you follow the links on this page, you will note that all of the games are gone.

In the meantime, the NHL and Google yesterday announced that hockey games are now available for free [When they are done with the court, we turn it into an ice rink... Bob]on Google Video. Even better, you can download them for your iPod. That's wonderful for consumers, but it points to Google's bigger problems when it comes to video.

My gut is that Google is having a lot of difficulty selling content on Google Video. If the NBA were making money with Google, you can bet they would have stayed there. In fact, they probably would have used it as a platform to promote their new League Pass Broadband service - but they didn't.

Now, enter YouTube. If Google can't sell video content on its own video property you can bet they will have the same challenge on the newest addition to their family. The only way they will make up their $1.6B is in advertising - provided the copyright issues don't kill YouTube first. Possible? For sure. But Google better hope that the Transient Web doesn't take over.



A long article with lots of quotes, but I'd rather see the original document.

http://www.bradblog.com/?p=3719

BLOGGED BY Rebecca Abrahams ON 11/2/2006 7:16PM

EXCLUSIVE: LEAKED 2003 REPORT ON MARYLAND'S DIEBOLD VOTING SYSTEMS REVEALS SERIOUS SECURITY CONCERNS WERE WITHHELD FROM ELECTION BOARD, GOVERNOR, PUBLIC!

Long-Sought Document Finally Surfaces Showing America's Largest Voting Machine Company, MD State Election Director, Hid Major Flaws From State, Country!

Original 200-Page Security Report — Said to be 'The Pentagon Papers of Electronic Voting' — Previously Released Only in 38-Page Highly Redacted Form…Until Now…



Is this what Arnold means when he says, “I'll be back?” (This is the computerized version of the old Chicago “machine”)

http://techdirt.com/articles/20061103/095309.shtml

California E-Voting Machines Let You Vote Early And Often

from the whoo-hoo dept

At what point do we wake up from this e-voting story nightmare and have someone reassure us it was only a dream? Every day, there's yet another story about how badly screwed up these machines are. Today, we've got a treat, as it's not actually about Diebold, but their competitor, Sequoia Voting Systems. It turns out that on the back of some of their machines used in California, there's a little yellow button. If you push it, you can vote multiple times by switching the machine to "manual" mode. In true geek fashion, Sequoia has responded with (I kid you not) their own version of "that's not a bug, that's a feature!" They claim it's "deliberate back-up feature to prevent the Edge from having a single point of failure." Hey, preventing single points of failure are great, but when they introduce a totally different point of failure, that's not so good. But, according to the company, this is the type of "flexibility" they've always provided. I didn't realize that "flexibility" was something desired in an e-voting system. Generally, you'd think people would prefer them to be pretty rigid, but to work right -- and not allow multiple votes. Sequoia claims that use of this feature emits a loud beeping noise, and they'll train poll workers to listen for that -- but that doesn't seem like the most reliable methods. We've heard so many stories of confused and technology illiterate voting officials that it's hard to believe they'll remember this or know what to do if it happens. The company says it will address the issue after next week's election -- but that any district using them can choose to simply turn off this "feature." So, if you're voting in California and you have an AVC Edge e-voting machine from Sequoia, and you have a bit of moral flexibility, apparently you can support your favorite candidate just that much more.



I don't normally report “pending” law or regulation since they rarely arrive in the form reported in the early articles, but this one interests me. Perhaps we should escape while we can? To where though...

http://sianews.com/modules.php?name=News&file=article&sid=3023

We're All Prisoners, Now: US Citizens to be Required ''Clearance'' to Leave USA

International Politics October 26, 2006

Forget no-fly lists. If Uncle Sam gets its way, beginning on Jan. 14, 2007, we'll all be on no-fly lists, unless the government gives us permission to leave-or re-enter-the United States.

The U.S. Department of Homeland Security (HSA) has proposed that all airlines, cruise lines-even fishing boats-be required to obtain clearance for each passenger they propose taking into or out of the United States.

... Why might the HSA deny you permission to leave-or enter-the United States? No one knows, because the entire clearance procedure would be an administrative determination made secretly, with no right of appeal. Naturally, the decision would be made without a warrant, without probable cause and without even any particular degree of suspicion. Basically, if the HSA decides it doesn't like you, you're a prisoner - either outside, or inside, the United States, whether or not you hold a U.S. passport.

The U.S. Supreme Court has long recognized there is a constitutional right to travel internationally. Indeed, it has declared that the right to travel is "a virtually unconditional personal right." The United States has also signed treaties guaranteeing "freedom of travel." So if these regulations do go into effect, you can expect a lengthy court battle, both nationally and internationally.

... For more information on this proposed regulation, see http://hasbrouck.org/IDP/IDP-APIS-comments.pdf.



It's that time of year again. (Black Friday is the day after Thanksgiving) Retailers pretend to be shocked that their deals leak out early – as if the extra publicity was bad.

http://digg.com/business_finance/OfficeMax_Black_Friday_Ad_For_2006_Posted

OfficeMax Black Friday Ad For 2006 Posted.

graphicsux submitted by graphicsux 1 day 6 hours ago (via http://www.blackfriday.info/ads/officemax-black-friday-ad.html )

Another ad leaked out. Some of the deals in the Office Max ad are a 20" Widescreen LCD Flat Panel Monitor for $199.99, an Averatec 2370 12" AMD Turion 64 X2 12" Laptop for $599.99, and a Sandisk Cruzer Micro 1GB Flash Drive for $13.

Friday, November 03, 2006

Oh man, I had this all figured out and now they confuse me with facts. Very interesting reading!

http://www.theregister.co.uk/2006/11/03/workplace_digital_privacy/

Employee privacy versus employer policy

By Mark Rasch, SecurityFocus Published Friday 3rd November 2006 11:17 GMT

Your organisation has a computer and internet use policy. Fine. It's been reviewed by corporate counsel, approved by senior management, and implemented over the years. The policy is comprehensive - it includes policies on expectations of privacy, employee monitoring, and the ownership of corporate electronic assets.

... However, there is a genuine divergence between what companies say and what they do. There is also a divergence between what employees regurgitate about their expectations of privacy (corporate mantra) and how they actually act. My own answer to the question, "do I have a reasonable expectation of privacy in the workplace?" – of course! What we really need to do is better define the scope of that reasonable expectation of privacy.

... The electronic workplace is no longer just the cubicle, desk or office. It now encompasses the coffee shop, the hotel room, the back of the taxi, the living room or bedroom.

... If nobody in the company has a privacy interest in electronic records, then how can the company resist a subpoena, search warrant, or even a warrantless search, since the courts only protect a reasonable interest in privacy?

... In effect, the court held that the actual policy of not monitoring content created, in the users, an expectation of privacy, which the court found to be reasonable.


Also consider...

http://www.internetworld.co.uk/0311.htm#6

Electronic snooping threatens US financial centres

It's official: the US leads the UK in compliance culture - but is it damaging New York as a financial centre?

Email monitoring? Tapped mobile calls? Switchboard snooping? It's all going on, according to a new survey which claims that New Yorkers are more aware of compliance breaches and monitored electronic communication - but they are also more likely to try to dodge communication controls.

The survey, conducted simultaneously in the financial districts of New York and London in October 2006, revealed a key difference in regulatory compliance culture: while Wall Street employees broadly support a firm's right to monitor their communication, they are also more likely to circumvent communication controls. A total of 300 people working in the Wall Street and City areas of New York and London, two of the world's busiest financial districts, were surveyed. The research discovered that:

- In New York more than 60% of respondents thought that it was right that their employer should monitor their e-mail. By contrast, in London less than half (38%) supported their firm's right to monitor e-mail.

- Employees in the New York finance sector are under heaviest scrutiny. In New York almost three quarters of respondents who worked in the finance sector thought their e-mail was already monitored (74%), compared to 62% of London finance workers. Only 28% of non-finance employees in New York believe their e-mail is monitored.

- New Yorkers are more likely to try to dodge e-mail monitoring:

- 60% admitted that they had sent something that they 'didn't want their employer to know about' using webmail. This compared to 42% of London respondents.

- More than seven out of ten New York-based finance workers admitted they had received an e-mail that broke corporate or regulatory policies, compared to just 36% of London City employees. Non-compliant communication is not just a problem in the finance sector; over half of non-finance workers in New York and London admitted to receiving e-mails that broke corporate policy (52% and 57% respectively).

Moreover, the survey confirmed that today's businesses rely heavily on e-mail as heir primary business communication channel.



Here's another one I thought had been resolved on the side of privacy...

http://www.newsday.com/news/nationworld/wire/sns-ap-kansas-attorney-general,0,1436618.story?coll=sns-ap-nationworld-headlines

Kansas AG Gets Abortion Clinic Records

By JOHN HANNA Associated Press Writer November 1, 2006, 12:31 AM EST

TOPEKA, Kan. -- The state attorney general said Tuesday night that his office has received the records of 90 patients from two abortion clinics and is reviewing them for possible crimes, the culmination of an effort that prompted concerns over patient privacy.

... Shawnee County District Judge Richard Anderson subpoenaed the records at Kline's request in September 2004, concluding there was probable cause to believe they contained evidence of crimes.

While Anderson didn't give Kline unfettered access to the records, the state Supreme Court imposed new guidelines for having them reviewed and edited before they were given to the district court. Under that process, neither Kline nor the judge saw the names of the patients.



Why else would we publish their addresses?

http://www.theolympian.com/101/story/48680.html

Attack on sex offender worries official

jeremy pawloski Published November 03, 2006

The beating of a registered offender by an alleged vigilante Tuesday night could spur calls to protect sex offenders' privacy, making it more difficult for law enforcement to track predators, an inspector with the Mason County Sheriff's Office fears.

... Dennis A. Clark, 51, remained at the Mason County Jail Thursday on suspicion of first-degree burglary [Not assault? Bob] and had his first court appearance Thursday.

... In Mason County, deputies also go out and give information about sex offenders to residents who live near them, Byrd said.

"We actually go to neighborhoods and knock on doors," he said.



RFID: Really Fast Identity-theft Device?

http://www.schneier.com/blog/archives/2006/11/dhs_privacy_com.html

November 01, 2006

DHS Privacy Committee Recommends Against RFID Cards

The Data Privacy and Integrity Advisory Committee of the Department of Homeland Security recommended against putting RFID chips in identity cards. It's only a draft report, but what it says is so controversial that a vote on the final report is being delayed.



http://www.cnn.com/2006/EDUCATION/11/02/villanova.stolen.laptop.ap/index.html

Stolen laptop had personal data on 1,200 college students and staff

PHILADELPHIA, Pennsylvania (AP) -- A laptop computer stolen from an insurance brokerage firm contained the names, birth dates and driver's license numbers of more than 1,200 Villanova University students and staff members, the school said Thursday.



http://www.bespacific.com/mt/archives/012904.html

November 02, 2006

UK Report Reviews Surveillance in 2006 With Projections Through 2016

The UK Information Commissioner, Richard Thomas, today issued a press release and a publication titled, A Surveillance Society (102 pages, PDF), a report commissioned for the International Conference of Data Protection and Privacy Commissioners, currently underway. The report "looks at surveillance in 2006 and projects forward ten years to 2016. It describes a surveillance society as one where technology is extensively and routinely used to track and record our activities and movements. This includes systematic tracking and recording of travel and use of public services, automated use of CCTV, analysis of buying habits and financial transactions, and the work-place monitoring of telephone calls, email and internet use. This can often be in ways which are invisible or not obvious to ordinary individuals as they are watched and monitored, and the report shows how pervasive surveillance looks set to accelerate in the years to come."



I'm certain others are doing this. Next they may want to knock on your door for an examination of your National ID and a scan of your sub-cutaneous RFID chip, a DNA sample... Imagine the lengths they would go to if you wanted access to something involving National Security!

http://www.siliconvalley.com/mld/siliconvalley/business/technology/15914032.htm

Posted on Thu, Nov. 02, 2006

Bud.TV site will check IDs at the door

ST. LOUIS (AP) -- Sorry kids. Bud.TV will be checking ID.

Anheuser-Busch Cos. is set to become the first major brewer to weed out underage visitors to its Web sites by hiring an outside firm to check their age.

... The screening process likely will ask visitors for a name, age and address, including zip code, Ponturo said. The data can be matched against public records such as driver's licenses and voter registration cards.

... Anheuser-Busch is walking a fine line between keeping minors off its Web sites without turning away too many people. [The more effort required to access a site, the larger the reward must be. Perhaps free beer? Bob] The company hopes to draw between 3 million and 5 million visitors to Bud.TV each month.

...On the Net: Anheuser-Busch: http://www.anheuser-busch.com Center on Alcohol Marketing and Youth: http://camy.org



Definitely a project to follow.

http://www.infoworld.com/article/06/11/02/HNmitweb_1.html?source=rss&url=http://www.infoworld.com/article/06/11/02/HNmitweb_1.html

MIT will train students to build a better Web

The Web Science Research Initiative plans interdisciplinary course addressing the growing amount of online information and the rules to moderate it

By Ben Ames, IDG News Service November 02, 2006

A group of professors has formed a research collaboration to train students how to design future versions of the World Wide Web.

One of their first lessons will be how to strike a balance between better access to data and stricter rules about its use, said researchers from the Massachusetts Institute of Technology (MIT) and England's University of Southampton at an MIT press conference Thursday.

The Web Science Research Initiative (WSRI) hopes to create a college degree program in "Web science" that combines disciplines including computer science, mathematics, neuroscience law and economics. It will also raise funding for doctorate students to study at MIT and the University of Southampton.



These guys are at Lackland (Texas). Perhaps they could attend a Privacy Foundation seminar an tell us what to watch out for in a CyberWar.

http://www.af.mil/news/story.asp?storyID=123030505

8th Air Force to become new cyber command

by Staff Sgt. C. Todd Lopez Air Force Print News

11/2/2006 - WASHINGTON (AFPN) -- During a media conference here Nov. 2, Secretary of the Air Force Michael W. Wynne said the 8th Air Force would become the new Air Force Cyberspace Command.

... Secretary Wynne said the 67th Network Warfare Wing, now under 8th Air Force, and other elements already within the 8th, would provide "the center of mass" for the nascent Cyberspace Command.



Ah the very symbol of prestige for executives...

http://www.f-secure.com/weblog/#00001011

Bluetooth cracking

Posted by Mikko @ 18:58 GMT Thursday, November 2, 2006

Last Friday Thierry Zoller and Kevin Finistere gave a presentation in the Hack.lu 2006 conference on Bluetooth issues. They also showed a demo of BTCrack, a Windows tool that can crack Bluetooth PIN and Linkkey in almost real-time (assuming it has sniffed the initial pairing).



I wonder what his Privacy Policy says...

http://techdirt.com/articles/20061102/091304.shtml

Would You Take Investment Advice From A Spyware Distributor?

from the your-customers-are-gonna-love-that dept

It turns out that record labels and movie studios aren't the only companies that treat their customers like criminals. So do writers of investment newsletters. The investment newsletter industry is basically what it sounds like. A company or an individual writes up a regular (often monthly) report filled with forecasts and picks and then send it to clients, for what is typically a rather high fee. But they know content like this is easily copied and passed around, so some of them, even in this day and age, are sent on physical paper by mail, in an attempt to make it just a little more difficult to re-distribute it than forwarding an email. The writer of one newsletter, who does distribute it electronically, is suing one of its corporate customers for copying it and passing it around. And how did he find this out? Because through his website, he installed spyware on the computers of all his clients that tracks what happens to the document. Even if he successfully sues the company, you really have to wonder about whether this was a good idea. Now all of his corporate clients, of which there are many, know him as a distributor of spyware, so either they'll stop doing business with the guy -- or maybe they'll get someone from IT to just disable it.



Note that even if the machines are secure (a BIG if) you could intercept the results at several steps along the way...

http://techdirt.com/articles/20061102/112448.shtml

Surprise! More Diebold Problems As They Expose Memory Cards To Viruses

from the didn't-see-that-coming dept

As if there haven't been enough problems with Diebold e-voting equipment (all of which they pretty much brush off or ignore). Ed Felten, who has been pointing out numerous security flaws with Diebold machines has found another one. It turns out that the memory cards that are used to store votes on some of the machines, the same memory cards that Felten showed was susceptible to viruses, are being placed into a variety of laptops that have not been checked to make sure they're free of spyware. Apparently, election workers are expected to put the memory cards into laptops in order to transfer the votes to CD-ROM (and, no I won't even start to get into why you should need to transfer votes to CD-ROM). The laptops in question, though, were either the election workers personal laptops or a bunch that were just "gathered from around the office." How many of those laptops (especially the personal ones) do you think are infected with spyware and viruses? Especially when you consider how many election workers are freaking out over the new machines because they're not at all technically savvy. What kind of e-voting company would think it's somehow "secure" to require people to transfer votes using their personal laptop? In the meantime, of course, we eagerly await Diebold's expected brushing off of this story, complete with insults directed at Felton (as per usual) and some sort of claim about how the whole thing isn't a problem at all due to some bogus "security" procedure they have in place.



Again the field of “virtual law” looks real.

http://techdirt.com/articles/20061102/112643.shtml

Australia To Tax Money From Second Life, But Can Money Spent On Your Avatar Be A Write-Off?

from the H&R-Block-Next-To-Set-Up-In-Second-Life dept

There continues to be a lot of discussion about the real world implications of activity inside virtual worlds. One of the issues is how to deal with taxation, and it appears that Australia has taken the lead, announcing that they plan to tax money made in virtual worlds, specifically citing Second Life Linden Dollars. A spokesperson for the country's tax office said that if you're getting monetary benefit from the site, then it should be taxed like any other income. What's not clear is when the money is taxed. Do they tax you when you've cashed in your Linden Dollars for Australian Dollars? If they did this, the policy would make sense, as it's basically like a capital gains tax, which is levied after someone sells their stock. Or, do they tax the player based on their Linden Dollars even if they don't cash out. This would be a ridiculous policy as it would basically be taxing people for playing a game. Assuming it's the former, the taxation occurs after withdrawing the money, it could be a real boon for Second Life, as it would discourage people from taking money out of the in-game economy.



The business model that will replace those used by media industries are becoming clearer every day.

http://techdirt.com/articles/20061103/001605.shtml

Writers, Directors, Actors Want Their Cut Of The Online Video Spoils

from the did-no-one-expect-this? dept

One of the important things in business is being able to be aware enough and flexible enough that you're rarely (if ever) caught by surprise. You can watch for trends and do scenario planning to help with these types of things -- but apparently some folks in the entertainment industry don't believe in that kind of planning ahead (if they'd only contacted us, we could have helped). So, now, it seems that they're running into all sorts of problems that were easily predictable five years ago. Take the TV industry, for example. Five years ago, they should have paid attention to the various disputes between musicians and the recording industry over digital rights. Contracts had been written in a time before the internet, and no one was exactly sure who got what cut in the royalties and whether or not it was really covered by existing contracts. That, of course, should have been the signal for those in the video business to start looking at their contracts and figuring it all out before it became a problem for them as well. And, of course, not very much happened. So, now, as we hear stories about Google negotiating to give entertainment companies a nice upfront lump of cash to allow their videos online, writers, directors and actors are suddenly wondering what it all means for them. They want to know what their cut will be. Considering that the industry execs have a long, long history of figuring out ways to take the money without paying the talent, they absolutely should be worried.

These are the type of legacy issues that should have been clear from years ago -- and which seem to have been ignored by the execs. Either that or they knew about them and figured they would have the leverage in the end anyway, so there was no reason to negotiate. Of course, these kinds of legacy issues don't just impact the content creation side of the business. Business Week is writing about the difficulties HBO is facing in designing its own online strategy -- since any such plan routes around the cable TV providers who pay good money (and make nice profits) being the only way to get HBO's sought after content. Again, this should have been clear years ago, but it sounds like everyone's just trying to figure out how to get around the legacy issues now.


...perhaps they should read this?

http://arstechnica.com/news.ars/post/20061102-8133.html

UK report: knowledge should be public good first, private right second

11/2/2006 9:36:09 AM, by Nate Anderson

The UK is awaiting the release of a report by the Gowers Review of Intellectual Property, a task force charged with suggesting changes to the country's intellectual property laws. The formation of the commission has inspired a flurry of private books and reports on IP designed to influence debate on the subject. While many of these are exactly as interesting as you'd expect, a new report from the Institute for Public Policy Research offers a fascinating look at the reasons behind intellectual property rights and suggests a new way forward for Britain: thinking about knowledge as a public resource first, and a private asset second. Is this idealistic, anti-business pinko blue-skying? The group says no.



Bogus arguments? I'm shocked!

http://www.boston.com/business/technology/articles/2006/11/02/fcc_rebukes_logan_says_continental_can_offer_wifi/

FCC rebukes Logan, says Continental can offer WiFi

By Peter J. Howe, Globe Staff | November 2, 2006

A two-year effort by Logan International Airport officials to shut down private alternatives to the airport's $8-a-day wireless Internet service was decisively rejected yesterday by federal regulators, who blasted airport officials for raising bogus legal and technological arguments.

Thursday, November 02, 2006

Once again the media has called on Prof. John Soma to put some perspective on the Privacy implications of a recent story about theft of a computer with personal identity information... I'd like to see the whole list of things that might (should?) happen to managers who allow this to happen.

http://www.9news.com/acm_news.aspx?OSGNAME=KUSA&IKOBJECTID=a201d668-0abe-421a-0086-5200cc35add2&TEMPLATEID=0c76dce6-ac1f-02d8-0047-c589c01ca7bf&GID=TguDwnGpVNB58v4lhA79duiZWJ8Bk4hHrQZn+E3T1Ng%3D

More than a million at risk for identity theft

written by: Anastasiya Bolton Reporter posted by: Jeffrey Wolf Web Producer Created: 10/31/2006 10:33 PM MST - Updated: 11/1/2006 6:55 PM MST

DENVER - A computer with sensitive information was stolen and now up to 1.4 million people across the country could be at risk of identity theft.



I'm sure there will be several jokes about who the bomber will be, but I suspect this site was protected better than your average airport. Could be interesting to follow...

http://www.valleywag.com/tech/ebay/ebay-building-bombed-exclusive-ims-from-an-ebayer-inside-the-building-211579.php

EBay building bombed: Exclusive IMs from an eBayer inside the building

Firefighters rushed to eBay's San Jose headquarters last night after an explosion in a four-story eBay building. First thought to be a transformer, the cause is now being reported as a bomb.

A live TV report from last night is available at KRON 4. If you have any information, photos, or first-hand accounts, e-mail tips@valleywag.com. A reader sends the following IM conversation they had with an eBay employee in the building.

My friend was working late at eBay tonight when there was a large explosion within the building.

Here's the breaking news story: Firefighters Respond to Explosions within eBay Building




You known, I like the way this guy thinks...

http://knowledge.wharton.upenn.edu/article.cfm?articleid=1594

Michael Porter Asks, and Answers: Why Do Good Managers Set Bad Strategies?

Published: November 01, 2006 in Knowledge@Wharton

Errors in corporate strategy are often self-inflicted, and a singular focus on shareholder value is the "Bermuda Triangle" of strategy, according to Michael E. Porter, director of Harvard's Institute for Strategy and Competitiveness.

... During his remarks, Porter stressed that managers get into trouble when they attempt to compete head-on with other companies. No one wins that kind of struggle, he said. Instead, managers need to develop a clear strategy around their company's unique place in the market.

... Managers who think there is one best company and one best set of processes set themselves up for destructive competition. "The worst error is to compete with your competition on the same things," Porter said. "That only leads to escalation, which leads to lower prices or higher costs unless the competitor is inept." Companies should strive to be unique, he added.

... Years ago, corporate strategy was considered a secret known only by top executives for fear competitors might use the information to their advantage, said Porter. Now it is important for everyone in the organization to understand the strategy and align everything they do with that strategy every day. Openness and clarity even help when coping with competition. "It's good for a competitor to know what the strategy is. The chances are better that the competitor will find something else to be unique at, instead of creating a zero-sum competition."



Is this how it's done?

http://yro.slashdot.org/article.pl?sid=06/11/01/2334226&from=rss

Groups Call for Investigation of MS Ad Service

Posted by samzenpus on Wednesday November 01, @07:05PM from the learning-all-about-you dept. Microsoft

narramissic writes "The Center for Digital Democracy (CDD) and the U.S. Public Interest Research Group (US PIRG) have filed a complaint with the FTC, asking for an investigation into Microsoft's use of customer data collection in its adCenter Web advertising service. The groups claim that 'Microsoft has embarked on a wide-ranging data collection and targeting scheme that is deceptive and unfair to millions of users.' Microsoft, for its part, says the groups 'have got it all wrong.'"



I wonder if a collection (or searchable database) of campaign ads would result in screams from the candidates (or perhaps a new law banning “politician stalking”)

http://www.technewsworld.com/rsstory/54018.html

An Alternative Guide to Election 2006

By Erika Morphy TechNewsWorld 11/01/06 8:00 AM PT

Politicians and their operatives are no dummies. YouTube might have started out as a site for ordinary people to post their own videos, but it is now well seeded with videos produced by candidates -- both focusing on themselves and on their opponents.

... Call it "Election 2.0." Call it the revenge of voters tired of watching the increasingly negative 30-second ads on network television. Whatever the reason, it is clear that voters are going outside mainstream media -- far outside -- to learn more about the candidates and the issues.

Consider YouTube, says Robb Hecht, an adjunct marketing professor at the City University of New York's Baruch College and social tech media strategist.

"Its role in this year's elections cannot be underestimated," he tells the E-Commerce Times. "While people need to tune into CNN, they also need to check out YouTube's vault of political videos and sites like WhereIStand.com to find out where [the politicians] stand on issues."



What aspects of his job can he remember?

http://www.infoworld.com/article/06/11/01/HNhphurdforgetful_1.html?source=rss&url=http://www.infoworld.com/article/06/11/01/HNhphurdforgetful_1.html

HP: Hurd can't recall probe meeting details

CEO says he wishes he could have been more "focused" during meetings with private investigators

By Robert Mullins, IDG News Service November 01, 2006

Hewlett-Packard Co. Chairman and Chief Executive Officer (CEO) Mark Hurd has an incomplete recollection of details of a crucial internal meeting on the HP board scandal, according to new information released Wednesday.



Automated stalking?

http://news.com.com/2061-12572_3-6131727.html?part=rss&tag=6131727&subj=news

Looking for someone? Spock will track them down

November 1, 2006 3:49 PM PST

Spock, a start-up that wants to make it easier to find personal information about people on the web, has launched its private beta.

Type in a name, and Spock says it can serve up a picture, address, occupation, interests and other information. Conversely, you can type in an occupation and location ("Rodeo Clown, Lubbock") and it will spit up people that fit that category.

... Spock's public beta hasn't started, but the founders told VentureBeat that it will have 100 million profiles.

No word on whether Leonard Nimoy is filing suit against them yet. Oh, humans, you are so irrational.



Negotiating ploy? Perhaps they want to be treated like North Korea and have a Chinese pipeline supply them with fuel oil for those cold Seattle winters?

http://news.bbc.co.uk/2/hi/technology/6102180.stm

Microsoft considers China policy

By Darren Waters Technology editor, BBC News website, Athens

There is mounting pressure on tech firms for their dealings in China

A senior executive for Microsoft has said the firm could pull out of non-democratic countries such as China.



http://politics.slashdot.org/article.pl?sid=06/11/01/2344209&from=rss

E-voting State By State

Posted by samzenpus on Wednesday November 01, @09:31PM from the make-them-count dept. United States Politics Technology

jcatcw writes "One-third of Americans will use voting machines next week that have never before served in a general election. Computerworld.com provides an overview of e-voting in each of the 50 states and the District of Columbia — equipment, systems for voter registration, polling, significant legal challenges to the systems, previous media coverage, links to government watchdog sites, the vendors, technologies and laws that are important to the issue, and a review of 'Hacking Democracy.'"



We're number 30! We're number 30!

http://www.theglobeandmail.com/servlet/story/RTGAM.20061101.wpriv1101/BNStory/Front/?page=rss&id=RTGAM.20061101.wpriv1101

Canada #2 in maintaining personal privacy

KATIE FRETLAND Canadian Press and Associated Press

LONDON — Germany and Canada are the best defenders of privacy, and Malaysia and China the worst, an international rights group said in a report released Wednesday.

Britain was rated as an endemic surveillance society, at No. 33, just above Russia and Singapore on a ranking of 37 countries' privacy protections by London-based Privacy International.

The United States did only slightly better, at No. 30, ranked between Israel and Thailand, with few safeguards and widespread surveillance, the group said.



If your ass is uncovered, scream National Security!

http://www.wired.com/news/technology/0,72051-0.html?tw=rss.index

The Virus That Ate DHS

By Kevin Poulsen 02:00 AM Nov, 02, 2006

A Morocco-born computer virus that crashed the Department of Homeland Security's US-VISIT border screening system last year first passed though the backbone network of the Immigrations and Customs Enforcement bureau, according to newly released documents on the incident.

The documents were released by court order, following a yearlong battle by Wired News to obtain the pages under the Freedom of Information Act. They provide the first official acknowledgement that DHS erred by deliberately leaving more than 1,300 sensitive US-VISIT workstations vulnerable to attack, even as it mounted an all-out effort to patch routine desktop computers against the virulent Zotob worm.

... U.S. District Judge Susan Illston reviewed all the documents in chambers, and ordered an additional four documents to be released last month. The court also directed DHS to reveal much of what it had previously hidden beneath thick black pen strokes in the original five pages.

"Although defendant repeatedly asserts that this information would render the CBP computer system vulnerable, defendant has not articulated how this general information would do so," Illston wrote in her ruling (emphasis is lllston's).

A before-and-after comparison of those documents offers little to support CBP's security claims. Most of the now-revealed redactions document errors officials made handling the vulnerability, and the severity of the consequences, with no technical information about CBP's systems. (Decide for yourself with our interactive un-redaction tool.)



Must be simple if you can reduce it to a PowerPoint presentation...

http://www.bespacific.com/mt/archives/012895.html

November 01, 2006

Presentation on Deconstructing Information Warfare

K. A. Taipale, "Deconstructing Information Warfare," presented to the Committee on Policy Consequences and Legal/Ethical Implications of Offensive Information Warfare, The National Academies, Washington, DC (Oct. 30, 2006) [download presentation slides in PDF).



I like it! (Who says there are no innovators left in business...)

http://techdirt.com/articles/20061101/221144.shtml

Innovative Funding Strategy: Steal Employees' IDs, Apply For Loans And Credit Cards In Their Names

from the nothing-to-it dept

It's one thing to be the victim of identity theft where the crook uses your identity to get loans, lines of credit and credit cards, but it's taken to an entirely different level when it's the CEO of a well-known company, and the victims are his employees. That's apparently what happened with Compulinx. Apparently, the company needed some money, and rather than raising it the old-fashioned way, the CEO and his nephew are accused of taking the data they had on file of some of the company's 50 employees, and using them to get loans, lines of credit and credit cards. The employees were apparently totally unaware that their CEO was pretending to be them, and sometimes claiming (falsely) that they were officers of the company.



http://techdirt.com/articles/20061101/222131.shtml

Spam Scam Says You're Fired

from the well-that-sucks dept

In the last year or so, the concept of "spear phishing" has gained a lot of popularity. Rather than broadly phishing by sending out emails pretending to be from companies with huge numbers of users/customers such as eBay or Citibank, spear phishing is much more targeted, and sometimes much more devious. It is often sent directly to people at a certain organization, made to look like it comes from someone at that organization and designed to play on what that organization does. It seems that some phishing scammers went one step further last week, using a spear phishing attack on employees of the Dekalb Medical Center. The email itself appeared to come from the medical center and told the employees they were being laid off. It included a link to a website supposedly for "career-counseling information," but actually directing people to a website that automatically downloaded a keylogger program. Enough employees were freaked out enough by the notice that they didn't consider it might be a scam, and clicked on the link. Once again, it shows how the scammers continue to adjust and adapt, and how difficult it can be to spot some of these types of scams.