Thursday, May 27, 2010

The restaurants would immediately notice if they weren't getting paid, but that bit about “secure transfer” isn't as important to them. Does the credit card industry certify any of these products?

http://www.databreaches.net/?p=11876

Restauranteurs threaten to sue POSitouch and NJ reseller

May 27, 2010 by admin

Yesterday’s press releases brought news of another potential lawsuit involving the restaurant industry and a POS vendor and reseller. I recognize the attorneys’ names as the same attorneys who filed suit on behalf of some Louisiana restauranteurs against another POS vendor, Radiant Systems, and their reseller, Computer World, last year. According to the press release, this potential lawsuit would be against Restaurant Data Concepts, Inc. of Warwick, Rhode Island, vendors of the POSitouch system, and CC Productions of Hoboken, New Jersey, the reseller.

At the core of the allegations in the developing lawsuit:

1) POSitouch’s POS system failure: The facts emanating from a forensic audit reveal that POSitouch sold a system that was non-compliant with PCI-DSS.

2) CC Productions’ mismanagement: This POSitouch reseller engaged in flagrant violations of PCI standards that gave rise to the security breaches. When companies such as CC Productions engage in the support and management of a merchants’ POS application system they need to ensure that they are not engaging in suspect actions that open up the ports so that hackers may penetrate the entire system through malware.

[...]

While the exact amount of the identify theft losses to banks, the financial losses to the restaurants, fines, investigatory costs, fines imposed by the credit card companies and other costs attributed to fixing the computer systems’ security breaches are still being tallied, the lawsuit is seeking compensation to repay the penalties levied by the credit card companies and the massive costs to track down and repair the POS system problems. According to the attorneys, damages “could run well into seven figures.”

I’ve sent out inquiries to the lead attorney and to Restaurant Data Concepts and will be following any developments in this case on this site. At this point, I’m not even sure whether we already knew about any of these incidents but the coverage didn’t mention the POS, or if most of the breaches alluded to flew under the media radar.



Is this a Class Action slam dunk or just another bandwagon for state AGs (and others) to leap on?

http://www.wired.com/threatlevel/2010/05/google-sued/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

Lawsuits Pour in Over Google’s Wi-Fi Data Collection

By Kim Zetter May 26, 2010 1:33 pm

At least three lawsuits have been filed against search engine giant Google for collecting Wi-Fi user data through its Street View cameras.

The lawsuits have been filed in California, Massachusetts and Oregon. They allege that Google violated federal and state privacy laws in collecting fragments of data from unencrypted wireless networks as its fleet of camera-equipped cars moseyed through neighborhoods snapping pictures.

The Massachusetts lawsuit, filed Tuesday by Galaxy Internet Services, is seeking class-action status for all Wi-FI users in the state who may have been affected, and is asking for $10 million in damages.

… Not everyone believes the plaintiffs in the lawsuits have a winning case. One attorney noted to The Recorder that the Electronic Communications Privacy Act contains a safe harbor for breaches that involve collections of data that is already publicly accessible.

The plaintiffs also may not have standing for a suit unless they can prove that their personal data specifically was among the information that was collected.



Another instance where the breach is not immediately reported in full, so the story will drag out as each client acknowledges the breach and drags Tower Watson's name back into the news.

http://www.databreaches.net/?p=11855

City of Charlotte joins list of Towers Watson data loss victims

May 26, 2010 by admin

The City of Charlotte becomes the third entity to reveal that their data were on two DVDs lost by Towers Watson.

In April, DataBreaches.net reported that Lorillard Tobacco was notifying employees that their names, addresses, dates of birth, and Social Security numbers were on two missing DVDs. General Agencies Welfare Benefits Program also reported that they had notified 1,874 employees, former employees, and family members that information provided to Towers Watson in 2001 were on the missing DVDs. The information included first and last names, health insurance plan numbers and/or the Social Security numbers of the covered employees. At the time, Towers Watson did not respond to a request from DataBreaches.net for a statement about the breach. And now we learn that the City of Charlotte was also impacted by the breach. DataBreaches.net has just sent Towers Watson another request, but so far, no response.

This is beginning to remind me of the Colt Express breach where a lot of old data were left unencrypted and a lot of entities were affected by what, in that case, was a burglary. If anyone knows of other entities affected by this Towers Watson incident, please let me know. In the meantime, Steve Lyttle reports on the City of Charlotte news:

Charlotte officials say personal data from about 5,200 current and former employees and elected officials has been lost.

[...]

The data loss affects those who were receiving health coverage from the city in early 2002, and the information was contained on two DVDs kept by Towers Watson, a company which handles the city’s payroll, health insurance and other human resources operations.

The DVDs contained Social Security numbers, health plan coverage numbers, and prescription information.

Read more in the Charlotte Observer.



Some evidence of how the Identity wholesalers clean up their data. They wouldn't want to get a bad reputation for selling sub-standard Identities.

http://www.databreaches.net/?p=11880

44 million stolen gaming credentials found in online warehouse

May 26, 2010 by admin

Ellen Messmer reports:

Symantec says it has unearthed a server hosting the credentials of 44 million stolen gaming accounts — and one of the most surprising aspects of it is that the accounts were being validated by a Trojan distributed to compromised computers.

The purpose of this Trojan-based validation is apparently to figure which credentials are valid and can be sold. Symantec is calling this the Trojan.Loginck, and as described in a blog post by Symantec researcher Eoin Ward, the database of stolen information includes about 210,000 stolen accounts for World of Warcraft, 60,000 for Aion, 2 million for PlayNC and 16 million for Wayi Entertainment, all of which were being sold online.

Read more on Network World.



I'm amused to see that other also see the Forest Gump Syndrome in action.

http://www.databreaches.net/?p=11866

Stupid is as stupid does: the Lake Ridge Middle School breach

May 26, 2010 by admin

As a follow-up to previous coverage about the stolen Lake Ridge Middle School stolen thumb drive here and here, Andrea McCarren of WUSA-9 provides some additional details that have infuriated parents (emphasis added by me):

The device was taken from a bag in an administrator’s unlocked car in her unlocked garage.

….. On the stolen thumb drive: personal information on more 1,200 students-their names, phone numbers and sensitive information, including whether they have a medical condition.

Dollars to donuts says they don’t report this to HHS even though it has names and medical conditions, because these things are considered education records. There is a huge gap in protection and notification laws here, folks…..


(Related) If true, this is much more serious than a relatively small entity failing to secure data. Did no one learn from TJX and Heartland?

http://thenextweb.com/us/2010/05/25/american-express-has-abysmal-online-security/

American Express Might Not Be Encrypting Your Credit Card Number Online

… Unix man Joe Damato has recently uncovered what appears to be a flagrant abdication of even the most basic rules of security online by American Express.



Are we moving toward a “You have no right to privacy” law?

http://www.pogowasright.org/?p=10555

U.S. lawmakers target pre-paid cellphone anonymity

May 26, 2010 by Dissent

AFP reports:

U.S. lawmakers unveiled a bill Wednesday to enable law enforcement to identify users of pre-paid cell phones, charging that anonymity makes the devices attractive to terrorists, drug kingpins and gangs.

The legislation would require buyers of pre-paid cell phones to show identification when they purchase them and mandate that telephone companies keep the information on file as they do with subscription cell phones.

Read more in the Vancouver Sun.

Michael McAuliff of the NY Daily News also covers the story, commenting:

We suspect most people will like this measure, but the phone companies, libertarians, and immigrant groups may not be pleased. [Note that libertarians and immigrants are not people. Bob]

Oh goody, here we go again with trading a leeetle bit — just a smidgeon — of privacy for security…. or so they’d have us believe.


(Related) The EU seems to be going the other way... Are these the basic right we should see in all Privacy Law?

http://www.pogowasright.org/?p=10581

European Commission adopts draft mandate for EU-US data sharing deal

May 26, 2010 by Dissent

From the European Commission:

The European Commission today adopted a draft mandate to negotiate a personal data protection agreement between the European Union and the United States when cooperating to fight terrorism or crime. The aim is to ensure a high level of protection of personal information like passenger data or financial information that is transferred as part of transatlantic cooperation in criminal matters.

[...]

Under the Commission’s proposal:

- The transfer or processing of personal data by EU or US authorities would only be permitted for specified, explicit and legitimate purposes in the framework of fighting crime and terrorism;

- There would be a right to access one’s personal data and this would be enforceable in courts;

- There would be a right to have one’s personal data corrected or erased if it is found to be inaccurate.

- There would be an individual right of administrative and judicial redress regardless of nationality or place of residence.

Read more on Finextra.


(Related) Further basic rights?

http://www.pogowasright.org/?p=10586

Google, Yahoo and Microsoft Data Retention Practices Run Afoul Of EU Authorities

May 26, 2010 by Dissent

Wendy Davis reports:

European authorities told the three major search engines on Wednesday that their data retention practices violate a rule requiring the deletion of users’ personal information after six months.

The Article 29 Working Party alleged in letters to Google, Yahoo and Microsoft that they don’t adequately anonymize information about search users. “Therefore,” the letters state, “WP29 cannot conclude your company complies with the European data protection directive.”

Read more on MediaPost.


(Related) A solution or window dressing?

http://www.technewsworld.com/story/Facebooks-New-New-Privacy-Settings-Same-Old-70080.html?wlc=1274909278&wlc=1274966179

Facebook's New, New Privacy Settings: Same Old?

… "Facebook made some positive changes today, but only because of political pressure from policymakers and privacy advocates on both sides of the Atlantic," Jeffrey Chester, executive director of the Center of Digital Democracy, told TechNewsWorld.

"Unfortunately, Facebook still refuses to give its users control over the data it collects for its targeted advertising products," Chester pointed out. "The defaults should also be initially set for non-sharing, with the minimization of data collection at the core of Facebook's approach to privacy."

… Jeremy Mishkin, chair of the litigation department of legal firm Montgomery, McCracken, Walker & Rhoads, told TechNewsWorld.

… "I guess Facebook will try to play up what good citizens they are by making controls simpler and hope that people don't realize they're being sold to advertisers," he said.



I see this as smart lawyering. It definitely cuts down the time and expense of evidence gathering and probably gives them a slam dunk in court!

http://torrentfreak.com/law-firm-asks-alleged-file-sharers-to-incriminate-themselves-100526/

Law Firm Asks Alleged File-Sharers To Incriminate Themselves

… Davenport Lyons (DL), the law firm which pioneered the “pay-up-or-else” scheme in the UK, are facing disciplinary proceedings by the Solicitors Regulation Authority on allegations of misconduct. Knowing full well that they cannot make the same mistakes as DL, ACS:Law are trying to be a little more careful in the way they try to force money out of letter recipients.

According to ACS:Law owner Andrew Crossley, his company does not state that the people they send their letters to are guilty of anything, only that their connection has been used to infringe. He also goes on to say that his letters are merely an offer to settle any potential legal case in the future and people aren’t obliged to pay anything.

… Yesterday consumer magazine Which? reported on the questionnaires being sent out by ACS:Law. The law firm sends these out once people have written to them denying they did anything wrong. All they are designed to do is to enable the letter recipient to incriminate themselves or, in some cases, other people.

The advice from Deborah Prince, Which?’s head of legal affairs, is that people are under no obligation to fill in these questionnaires. These bits of paper simply amount to a fishing trip by a law firm clutching at straws in the face of a recipient who won’t be bullied and won’t pay up.



Good news. Bad news. Being number one is good in some ways...

http://www.wired.com/epicenter/2010/05/apple-passes-microsoft/

Apple Passes Microsoft as World’s Largest Tech Company


(Related) But it also triggers the “If they're big, they must be evil” response.

http://www.electronista.com/articles/10/05/25/apple.said.abusing.itunes.lead.to.hurt.amazon/

DoJ investigating Apple for antitrust abuses in music



Death to the RIAA??? Are we seeing “Music Label 2.0” at last? Anyone interested in finding and signing the next 12 year old sensation?

http://media.venturebeat.com/2010/05/26/lady-gaga-and-justin-biebers-managers-myspace-is-dead-we-make-music-videos-for-youtube/

Gaga and Bieber’s managers: MySpace is dead, we make music videos for YouTube

May 26, 2010 Devindra Hardawar

In one of the more intriguing panels to come out of the TechCrunch Disrupt conference, this morning Troy Carter (Lady Gaga’s manager, and Founder & CEO of Coalition Media Group) and Scooter Braun (Justin Bieber’s manager, and Founder & Chair of SB Projects) discussed how the Web was impacting the music industry.

Specifically, they focused on the importance of YouTube, Twitter, and the management of an artist’s online identity.

Carter went as far to say that he and Lady Gaga now develop music videos with YouTube in mind. Traditionally, the music industry aimed for MTV and foreign markets with videos. Now pop stars like Gaga are following in the footsteps of smaller web music video pioneers like OK Go. Braun also reminded the audience of how Bieber started out on YouTube, where his videos hit 55 million views before he signed his record deal.

After Braun discovered Bieber on YouTube, he came up with a strategy of creating more online content to promote the singer. This flew in the face of what the record labels were used to — they believed young singers needed a Disney or Nickelodeon show to become a viable act.

Carter mentioned that Gaga started out on MySpace about four years ago, but Braun was quick to point out that “nobody does MySpace anymore.” Carter is currently eying YouTube star Grayson Chance.

Both managers agreed that Twitter is an important tool, especially for artists that started out on the web. It’s a way to remove the layers between the fans and artist, and Carter believes that the younger generation today wants that unfiltered communication. They don’t want to hear the label speaking on behalf of the artist.

You can find a selective transcript of the chat over at TechCrunch.


(Related) Or is this just a fad? Does Oprah have one?

http://www.nytimes.com/2010/05/27/arts/television/27arts-RECORDCOMPAN_BRF.html

New Role for Degeneres: Record Company Mogul

By BEN SISARIO; Compiled by DAVE ITZKOFF

Published: May 27, 2010

A month after David Letterman said he had started a record company, Ellen DeGeneres has followed him with an announcement that she has created her own label.


(Related) Is this the other extreme? The opposite of “as visible as possible?” Will Rupert make this work, or kill his empire trying?

http://news.slashdot.org/story/10/05/27/0315243/UK-Newspaper-Web-Sites-To-Become-Nearly-Invisible?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

UK Newspaper Websites To Become Nearly Invisible

Posted by samzenpus on Thursday May 27, @04:52AM

"Various websites have tried to make readers pay for access to select parts of their sites. Now, in a bid to counter what he claims is theft of his material, Rupert Murdoch's Times and Sunday Times sites will become essentially invisible to web users. Except for their home pages, no stories will show up on Google. Starting in late June, Google and other search engines will be prevented from indexing and linking to stories. Registered users will still get free access until the cut off date."



Just to show my Math students that there are jobs waiting for them if they can get past their fear of fractions...

http://science.slashdot.org/story/10/05/27/0258245/Sudden-Demand-For-Logicians-On-Wall-Street?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Sudden Demand For Logicians On Wall Street

Posted by samzenpus on Thursday May 27, @01:46AM

"In an unexpected development for the depressed market for mathematical logicians, Wall Street has begun quietly and aggressively recruiting proof theorists and recursion theorists for their expertise in applying ordinal notations and ordinal collapsing functions to high-frequency algorithmic trading. [See! Simple! Bob] Ordinal notations, which specify sequences of ordinal numbers of ever increasing complexity, are being used by elite trading operations to parameterize families of trading strategies of breathtaking sophistication. The monetary advantage of the current strategy is rapidly exhausted after a lifetime of approximately four seconds — an eternity for a machine, but barely enough time for a human to begin to comprehend what happened. The algorithm then switches to another trading strategy of higher ordinal rank, and uses this for a few seconds on one or more electronic exchanges, and so on, while opponent algorithms attempt the same maneuvers, risking billions of dollars in the process." [Don't forget, I want a percentage! Bob]



This is for my Criminal Justice students – kind of like a “build a picture of your suspect” kit. WARNING: Be real careful of caricatures of your favorite professor, at least until I turn in your grades!

http://www.makeuseof.com/dir/caricaturemaker-caricature-faces

CaricatureMaker: Create Funny Caricatures Faces Online

www.digibody.com/avatar-maker/index.php

Similar sites: MrPicassoHead, PimpTheFace, PsykoPaint and FlashPaint.



Some inspiration for my Small Business Management students?

http://www.entrepreneur.com/magazine/entrepreneur/2010/june/206722.html

Entrepreneur's Annual 100 Brilliant Ideas



Bob's rant on North Korea – How will the US respond? It depends on who does the reporting, I guess.

http://theweek.com/article/index/203359/how-to-avert-a-new-korean-war-4-suggestions

4 strategies to avert a new Korean War

Kim Jong Il is telling his troops to prepare for battle as tensions escalate over the sinking of a South Korean warship. What now?

posted on May 26, 2010, at 12:42 PM

Keep up the pressure and hope for a coup: The population in the North is starving and the military is likely on the edge of revolt, says Ed Morrissey in Hot Air. Kim Jong Il is hoping that the U.S. "will come riding to rescue" with food aid to ease the desperate situation. It's tricky balance and at some point Obama will probably have to do just that — but if he can steel his resolve and hold out long enough, the North Korean military "may just decide that [Kim's] not worth the trouble any longer" and get rid of him. Here's hoping... [But, Kim Joun Un is only in his 20s. Will the Military support him or use him? Bob]

"North Korea severs ties, communications with South"

Launch a preemptive strike: The worst-case scenario is that the North will lob artillery shells into Seoul with guns positioned near the border, says Richard Halloran in RealClearPolitics. The U.S. and South Korea should take them out in a three-pronged "surprise attack" using B-1 bombers, sea-launched guided missiles, and artillery shelling. That will remove the biggest threat, and "shock the poorly trained North Korean Army into standing down."

"War of words with North Korea"

Make sure Kim knows the score: If there's one thing that Kim Jong Il needs to be aware of, it's that the South will answer military action in kind next time, says Bill Powell in Time. Knowing this ought to go a long way toward keeping him in line, since a "hot war" would certainly mean the end of his regime. Unfortunately, the North has been cutting off even the meager lines of communication that exist between the countries, so it's hard to be sure he actually knows it. The solution? China needs step up and forcefully convey the message to him.

"War in the Korean Peninsula: Thinking the unthinkable"

Let them get away with it, as usual: "The only government with the power to squeeze North Korea where it hurts is China," its biggest trading partner, says Richard Lloyd Parry in the London Times. But China doesn't seem interested in doing much squeezing. The only other viable option is to get behind a United Nations Security Council resolution condemning North Korea, and trumpet the sternness and significance" of the rebuke. Sure, it's only theater — but hopefully it will provide some cover for the West's "impotence" in this situation.

"Analysis: North Korea will get away with this outrage — again"


(Related) The AP is for peace (Option 4?)

http://www.arkansasonline.com/news/2010/may/26/clinton-offers-olive-branch-north-korea-expels-sou/

Clinton offers olive branch as North Korea expels South Koreans

By The Associated Press

“There is an opportunity here for the North Koreans to see that their behavior is unacceptable,” Clinton said in Seoul on Wednesday after meeting with Foreign Minister Yu Myung-hwan. “They need to look internally to see what they could do to improve the standing of their own people and provide a different future.”


(Related) The US seems to be hoping for Option 1. I think that can only lead to chaos…

http://www.kwtx.com/nationalnews/headlines/94933709.html

Clinton: World Must Act On Sinking Of South Korean Ship

U.S. State Department Website

SEOUL, South Korea (May 26 2010)--U.S. Secretary of State Hillary Rodham Clinton says the world has a duty to respond to sinking of a South Korean warship blamed on North Korea.

Wednesday, May 26, 2010

Interesting. If several students analyzed their laptops and discovered that someone had hacked them and was snapping pictures, would the school have any liability?

http://www.wired.com/threatlevel/2010/05/lanrev-security-holes/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

Spyware Installed on Student Laptops Has More Security Problems

By Kim Zetter May 25, 2010 1:52 pm

A remote administration program installed on student laptops by a Pennsylvania school district and used by numerous companies to manage their computers is even more vulnerable than previously reported.

The LANrev program can be exploited from anywhere on the internet, not just from an attacker on the same local area network as a victim’s computer, according to researchers who say that a second key used by the system is just as insecure as one that was previously disclosed.



Unlike the taxpayers who must make do when revenues decline, governments simply take more – never to return to lower tax levels.

http://www.pogowasright.org/?p=10541

Colorado’s Big Brother E-Commerce Law

May 26, 2010 by Dissent

Stephen P. Kranz reports:

Record-breaking budget shortfalls have caused states to search for new revenue using tools that arguably are unconstitutional and, at a minimum, violate the consumer privacy that online shoppers have come to expect. A new twist to increasing taxes is an effort — adopted by Colorado and under consideration in California and Tennessee — to force online retailers to reveal their customers and their customers’ purchases. The Colorado law will be challenged as unconstitutional. Meantime, Colorado consumers should be concerned that their state government is busy collecting data about their purchases that will be used to send them a tax bill.

Read more on InformationWeek.



It's like the holes in security are built in... If strong security isn't designed in, you have allowed the previous (lack of) design to rule.

http://www.phiprivacy.net/?p=2796

Yet another Veterans Administration breach

By Dissent, May 25, 2010 7:46 pm

What on earth is going on with all these Veterans Administration data breaches?

OCR just added another VA breach to its web site, again out of Texas. The description doesn’t match the breaches that Representative Buyer recently talked about in Congress, which were also from facilities in Texas:

VA North Texas Health Care System

State: Texas

Approx. # of Individuals Affected: 4,083

Date of Breach: 5/04/10

Type of Breach: Improper Disposal

Location of Breached Information: Paper Records



Should your bank be allowed to “discover” public information in order to make better evaluations of risk, or should they just guess?

http://www.pogowasright.org/?p=10538

Fake ANZ Facebook profile may breach laws

May 26, 2010 by Dissent

Sarah Gerathy reports:

Consumer rights advocates say ANZ bank employees may have breached privacy laws and the Trade Practices Act when they allegedly used Facebook to gather customers’ information.

It is alleged that someone in the bank’s debt collection team secretly set up a fake Facebook profile.

Using this false identity, they then befriended ANZ customers with bad credit in order to track down their current contact details.

The fake Facebook profile was set up under the name of Max Bourke, but did not mention ANZ in any way.

Read more on ABC (AU). There’s an interesting discussion of how this type of deception, frequently used offline, translates into online and what the regulatory bodies might think about it.



Who should you send this to?

http://www.phiprivacy.net/?p=2791

Webinar: Ready for Data Breaches under the HITECH Act?

By Dissent, May 25, 2010 2:18 pm

Webinar: Ready for Data Breaches under the HITECH Act?

Thursday, May 27, 2010

10:00 a.m. – 11:00 a.m. PST

Carrying Out Security Breach Incident Risk Assessments Mandated for Covered Entities

The HITECH Act requires HIPAA covered entities to carry out a careful risk assessment, including an evaluation of potential harm, for every potential data breach incident.

Kirk Nahra, CIPP & Partner at Wiley Rein, a premier healthcare law firm, and Rick Kam, President and Founder of ID Experts, will cover:

  • HITECH Act data breach notification provisions

  • HHS mandated data security incident risk assessment requirements

  • HHS rules for carrying out a compliant risk assessment

  • Evolving best practices to accommodate HITECH data breaches

  • Implications on data breach notification plans for HIPAA covered entities

Registration:

(https://www2.gotomeeting.com/register/666004955)

  • Learn about how to comply with HITECH/HHS data breach risk assessment rules.



My suggestion: A simple Cash Flow analysis. Where do government revenues come from and where do they go – with a history showing all those “temporary taxes” that never go away...

http://it.slashdot.org/story/10/05/26/1226201/Recrafting-Government-As-an-Open-Platform?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Recrafting Government As an Open Platform

Posted by CmdrTaco on Wednesday May 26, @09:47AM

"How effective are the world's governments at using technology to become more responsive? Technology has revolutionised the way that we do business, but the public sector has traditionally moved more cautiously than the private one. Now, a report from the Centre for Technology Policy Research in the UK has made some recommendations for the use of technology as an enabling mechanism for government."

I have one simple requirement: all laws must be written in a Wiki with full history.



Not sure about the smart part, but I'm definitely paranoid!

http://www.computerworld.com/s/article/9176406/The_smart_paranoid_s_guide_to_using_Google

The smart paranoid's guide to using Google

Here are down-and-dirty details on how to maintain your privacy while using Google's myriad services.

By Logan Kugler May 25, 2010 06:00 AM ET

… By taking some basic -- and not-so-basic -- precautions, you can minimize your exposure to bad guys, wherever and whoever they are. Read on to learn about things you can do to minimize the security risks involved in using Google, whether for search or for one of its myriad other online services.

For good measure, we've included two levels of advice on how you can protect yourself:

  • "Defcon 2" (good security) tips are things you can do with the tools already at your disposal to keep yourself safe against typical attacks -- but not against a determined attacker.

  • "Defcon 1" (best security) tips -- a.k.a. "the celebrity solution" (steps to take if you have, or intend to have, a highly visible public profile) -- offer far more security but are far less practical and often require using third-party tools.


(Related) Did you know what happens when you “Google?”

http://www.techi.com/2010/05/a-matter-of-trust-10-places-google-collects-user-data-from/

A Matter of Trust: 10 Places Google Collects User Data From

So where, exactly, is Google’s data collected from? Here’s a rundown of 10 of Google’s most valuable sources of data.


(Related) “But hey, we're tossing lots of money around!”

http://news.cnet.com/8301-30684_3-20005948-265.html?part=rss&subj=news&tag=2547-1_3-0-20

Google's primer on how it helps the economy

… In an effort to shine a brighter light on its economic contributions, Google held a series of press conferences around the country Tuesday highlighting the impact that AdWords, AdSense, and Google nonprofit grants have on the small business community. The events accompanied the release of a report claiming that Google advertisers generated $54 billion in U.S. economic activity during 2009, and that doesn't even count the taxes that co-founders Sergey Brin and Larry Page will inject into state and federal coffers over the next five years as they sell off stock.



“All your IP belong to us!”

http://gawker.com/5547420/twitter-gets-greedy-with-your-tweets

Twitter Gets Greedy With Your Tweets

… Here's how the Twitter business now works: Millions of people, including elected officials, Hollywood celebrities, you name it, supply the San Francisco startup with a huge quantity of free content. Twitter publishes this content, gets the right to sell ads against it and—here's the new part—gets a cut of any ads sold against the content when republished elsewhere, according to new terms of service noted by Peter Kafka of All Things D:

In cases where Twitter content is the basis (in whole or in part) of the advertising sale, we require you to compensate us (recoupable against any fees payable to Twitter for data licensing).



Would this suggest more rapid (seasonal?) changes of 'fashionable' books and movies? Or do we do that now?

http://news.slashdot.org/story/10/05/25/2222207/The-Fashion-Industry-As-a-Model-For-IP-Reform?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

The Fashion Industry As a Model For IP Reform

Posted by kdawson on Wednesday May 26, @04:12AM

"In this 15-minute TED talk, Johanna Blakley addresses a subject alien to most here — fashion — but in a way sure to grab our attention. The lesson is about how the fashion industry's lack of copyright protection can teach other industries about what copyright means to innovation. And yes, she mentions open source software. There is one killer slide at 12:20 comparing the gross sales of low-IP-protection industries with those of films and books and music. If you want to know more, or if you prefer text, the Ready To Share project website should give you all the data you crave on the subject."



Ah, to be getting speeds as great as those in Latvia or the Republic of Moldova!

http://tech.slashdot.org/story/10/05/25/1924235/Global-Last-Mile-Performance-Stats-Going-Public?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Global "Last Mile" Performance Stats Going Public

Posted by kdawson on Tuesday May 25, @05:28PM

Ookla, the company behind Speedtest.net, Pingtest.net, and the bandwidth testing apps deployed at many ISPs, has gone public with Net performance stats from 1.5 billion users (and counting). Their Net Index page displays download speed, upload speed, and connection "quality" from the EU and the G8, to countries, worldwide cities, and US states. Beginning today, the company is also making detailed (anonymized) data available to academics.

"Ookla will also start surveying users about how much they pay for broadband and how much bandwidth they were promised by their ISPs. The results of those questions will go into building a Value Index, which will show how much people around the world pay per megabit-per-second for Internet access. In addition, by collecting postal codes from Speedtest users, Ookla hopes to map broadband service to local economic conditions, Apgar said. The Speedtest data could give the US government far more information to work with in setting priorities for its National Broadband Plan..."

Tuesday, May 25, 2010

Best Practice: Get the Auditors involved in the design of computer systems.

http://www.phiprivacy.net/?p=2783

AU: Patient data under threat, say auditors

By Dissent, May 24, 2010 5:55 pm

Mark Metherell reports:

Federal government auditors have overruled Medicare, calling on the agency to improve security of patient details held by pharmacists.

Patient information on the 200 million prescriptions pharmacists dispense each year are largely electronically held, which the Auditor-General, Ian McPhee, says ”continues to be an area of growing threats”.

In an audit report on the administration of the Pharmaceutical Benefits Scheme released yesterday, Mr McPhee revealed a long-running turf war among three health agencies over responsibility for the PBS.

Read more in the Sydney Morning Herald.

[From the article:

On security, Mr McPhee said both Medicare and the Department of Health had argued that existing security at pharmacies was either not their responsibility or were satisfactory.



Use this to check (and fix?) your own privacy leaks, then use it to suck all the useful data from whomever you are stalking?

http://www.makeuseof.com/dir/zesty-facebook-privacy-checker

Zesty Facebook Privacy Checker: See How Exposed Your Facebook Profile Is

It is remarkably simple website which shows us our Facebook information which regular internet users can view.

… Clicking on each subfield in the directory shows us the information in that directory which internet users can view. For instance clicking on the family members might bring up our Facebook family connections, in case we have not set the privacy preference to hide them.

hzesty.ca/facebook



Even rants contain some truth...

http://yro.slashdot.org/story/10/05/24/195208/Why-Online-Privacy-Is-Broken?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Why Online Privacy Is Broken

Posted by Soulskill on Monday May 24, @03:54PM

"One of the more trite and oft-repeated maxims in the software industry goes something like this: We're not focusing on security because our customers aren't asking for it. They want features and functionality. When they ask for security, then we'll worry about it. Not only is this philosophy doomed to failure, it's now being repeated in the realm of privacy, with potentially disastrous effects. A quick search of recent news on the privacy front reveals that just about all of it is bad. Facebook is exposing users' live chat sessions and other data to third parties. Google is caught recording not only MAC address and SSID information from public Wi-Fi hotspots, but storing data from the networks as well. But the prevailing attitude among corporate executives in these cases seems to be summed up by Google CEO Eric Schmidt, who famously said this not too long ago: 'If you have something that you don't want anyone to know, maybe you shouldn't be doing it in the first place.' If you look beyond the patent absurdity of Schmidt's statement for a minute, you'll find another old maxim hiding underneath: Blame the user. You want privacy? Don't use our search engine/photo software/email application/maps. That's our data now, thank you very much. Oh, you don't want your private chats exposed to the world? Sorry, you never told us that."


(Related)

http://www.docuticker.com/?p=35705

2010 International Piracy Watch List (PDF)


(Related) Everything you ever said online, stays online... Forever.

http://yro.slashdot.org/story/10/05/25/006201/Emergency-Dispatcher-Fired-For-Facebook-Drug-Joke?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Emergency Dispatcher Fired For Facebook Drug Joke

Posted by kdawson on Tuesday May 25, @02:43AM

"Dana Kuchler, a 21-year veteran of the West Allis' Dispatch Department, was fired from her job for making jokes on her Facebook page about taking drugs. She appealed to an arbitrator, claiming the Facebook post was a jok,e pointing out she had written 'ha' in it, and urine and hair samples tested negative for drugs. The arbitrator said she should be entitled to go back to work after a 30-day suspension, but the City of West Allis complained that was not appropriate. Is posting bad jokes on Facebook a justifiable reason to give someone the boot?"



“Oh, the poor, vulnerable newspaper industry... Let's kill it!”

http://techcrunch.com/2010/05/24/publish2-disrupt/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

Publish2 Wants To Disrupt The Associated Press With An Online News Exchange

Publish2 is taking a swing at the newswire mammoth – they un-lovingly call it an inefficient monopoly – by launching a platform that allows newspaper publishers and other media organizations tap the vast amount of quality content already available for free on the Web



Did anyone think the government would get it right the first time?

http://www.docuticker.com/?p=35709

PFF Report Says FCC’s Regulatory Leap Backwards Wrong for Internet



For my Security Students.

http://www.pcworld.com/article/196898/poisoned_pdfs_heres_your_antidote.html

Poisoned PDFs? Here's Your Antidote

Erik Larkin, PC World May 23, 2010 7:00 pm

… Here's the kicker: This embedded-file threat makes creative use of functionality built into the PDF standard. As such, it works not only on Adobe Reader but on other PDF readers, too, even if they're up-to-date. The makers of the Zeus Trojan horse are already using this new technique to spread their evil software.

How to Fight the New Threat

Changing a program setting in the current version of Adobe Reader can help. Head to Preferences, Trust Manager, and deselect Allow opening of non-PDF file attachments with external applications. See the Adobe Reader Blog for more details.

The latest 3.3 update for the Foxit PDF reader also has a new Safe Reading setting--enabled by default under a new Trust Manager section in the preferences--that likewise blocks embedded programs from running.

… Finally, a good antivirus program may stop a malicious PDF before it can launch an attack. And VirusTotal.com is excellent for scanning any downloaded or e-mailed file with a multitude of antivirus engines.

Monday, May 24, 2010

How about an application that copies this database to your friends in Romania?

http://www.pogowasright.org/?p=10493

Contest Unlocks 3.1B Personal Records to Developers

May 24, 2010 by Dissent

From a press release:

At the height of the online privacy debate, DataRockit, a leader in data services technology, is opening up its 3.1B criminal, consumer, sex offender and real estate records for an application development contest. Launching today, with TechCrunch Disrupt, the contest challenges developers to construct an application that utilizes the database records in DataRockit’s comprehensive infrastructure to help look after the communities where we live. The Disruptive contest will run through June 7, 2010, the kickoff of New York Internet Week

Does anyone else have any concerns that they could just be handing huge data sets to potential ID thieves?



Only true citizens (and those who work for them) have rights. Us second class citizens only think we do.

http://www.pogowasright.org/?p=10498

MD: Debate Sparks Over Video Recording Of Arrests

May 24, 2010 by Dissent

This issue has been covered on PogoWasRight.org in the past, but nothing has yet changed. WJZ reports:

Several Marylanders face felony charges for recording their arrests on camera, and others have been intimidated to shut their cameras off. That’s touched off a legal controversy.

[...]

Video of another arrest at the Preakness quickly made its way online, despite an officer issuing this warning to the person who shot it, “Do me a favor and turn that off. It’s illegal to videotape anybody’s voice or anything else, against the law in the state of Maryland.”

But is he right? Can police stop you from recording their actions, like a beating at the University of Maryland College Park?

The American Civil Liberties Union says no.

Read more on WJZ.

[From the article:

Under Maryland law, conversations in private cannot be recorded without the consent of both people involved.

But can that be applied to incidents, such as one caught on tape three years ago where a Baltimore officer arrested a teenager at the Inner Harbor?

"When you tell me to turn it off because it's against the law, you've proven to me that I'm not secretly taping you," said law professor Byron Warnken. "He doesn't have the right to say, if you don't stop recording me, I'm going to arrest you."

The last official interpretation of Maryland's law came from the previous attorney general saying it was legal for officers to record video on dashcams.



For my Computer Security class.

http://techcrunch.com/2010/05/24/evil-app-displays-cell-numbers-of-unwitting-facebook-users/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

“Evil” App Displays Cell Numbers Of Unwitting Facebook Users


(Related) Showing my students that there is money to be made by collecting all that “public” data and using it to fill the gaps others leave (or charge too much for)

http://news.cnet.com/8301-27076_3-20005690-248.html?part=rss&subj=news&tag=2547-1_3-0-20

PhoneTell taps the Web for proper mobile caller ID

by Josh Lowensohn May 24, 2010 4:00 AM PDT

… Though its one hang-up (no pun intended) is that its directory of phone numbers, which is attached to names and readily available for landline phones, has not been carried over to mobile phones. Instead, mobile-phone users get numbers only.

One company that's helping to change that is PhoneTell, which is launching at Monday's TechCrunch Disrupt conference in New York. Formerly CallSpark (which debuted at last year's DemoFall) PhoneTell aims to help you figure out who's calling your phone, even if they're not in your own personal phone book.

To accomplish such a feat, PhoneTell maintains its own directory of 200 million contacts from sources including the yellow pages and white pages, Yelp, OpenTable, and Zagat. The company also has a graylist that's made up of known telemarketers. More importantly though, its system can tap into various services you're a part of, like Gmail, LinkedIn, and Salesforce, to grab contacts behind a log in.



This is the kind of app I expect my Statistics students to create. With even a small percentage of users tech-literate, this type of app is likely to become common – measuring the performance of products and services against the promises of the Marketing Dept.

http://techcrunch.com/2010/05/23/complain-about-your-dropped-iphone-calls-with-science/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

Complain About Your Dropped iPhone Calls… With Science

by John Biggs on May 23, 2010

We just saw a great product at the TC Disrupt Hack Day. It’s basically a class action lawsuit generator against AT&T that uses your actual call drop data to tabulate how many times your phone crashed and how many times you’ve been generally hosed by AT&T.

The site is worstphoneever.com and it searches for baseband crashes on your desktop, uploads them, and saves them to a database. The results are tabulated and added to the total, eventually leading to a detailed class-action lawsuit.

Do you have an iPhone? Then you know it’s the best portable computer ever made, while at the same time being the worst phone. ever. because it drops calls all the time!

Here’s what you can do: upload log files of dropped calls for your phone, see how many calls you dropped, where, and when, and then see how they compare with your friends!

Then, when we have enough data, we’re going to file a class action lawsuit on behalf of all our users, run Apple and AT&T through the ringer, and you can get a slice of the action! Don’t get mad, get even!



Law 2.0 Kind of defeats the spirit of the GPL, which is intended to allow consumers to modify their software to suit their needs.

http://yro.slashdot.org/story/10/05/23/2018220/Do-Build-Environments-Give-Companies-an-End-Run-Around-the-GPL?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Do Build Environments Give Companies an End Run Around the GPL?

Posted by timothy on Sunday May 23, @05:34PM

"I have two devices, from two different companies (who shall remain nameless, but both are very large and well known), which run Linux-based firmware. The companies release all their source code to comply with the GPL, however neither of them include a build environment or firmware utilities with the code. This means that if you want to alter the free software on the device, you can't — there is no way to build a firmware image or install it on the devices in question, effectively rendering the source code useless. I have approached the companies directly and while one of them acknowledges that they are not fully GPL compliant, due to other license restrictions they cannot make their build environment public, and they do not have the resources to rewrite it. I have approached the FSF but their limited resources are tied up pursuing more blatant violations (where no code at all is being released.) Meanwhile I am stuck with two devices that only work with Internet Explorer, and although I have the skills to rewrite each web interface, I have no way of getting my code running on the devices themselves. Have these companies found a convenient way to use GPL code, whilst preventing their customers from doing the same?"

Sunday, May 23, 2010

Someone must have taught them to do this? Besides, if you don't have power off-premises, you can't spy on your students with those nifty little cameras in the laptops you gave them.

http://www.pogowasright.org/?p=10484

Does imposing school codes of conduct 24/7 go too far? Yes

May 23, 2010 by Dissent

Maureen Castriotta and Chris Rogers, members of the Roxbury Township Board of Education, write:

Every day, “We the People” lose a few more of our liberties at every level of government. Case in point is the disturbing trend of the adoption of Student Code of Conduct policies in our public schools throughout the state [New Jersey] requiring students to be on their best behavior the entire calendar year — even when school is out of session — or face disciplinary action from school authorities.

This begs the question: Just how much power are we willing to give our schools over our children?

In Roxbury Township, where we serve as school board members, a revised high school Student Code of Conduct was approved by a 7-3 vote last June, giving school administration the ability to prevent students from engaging in interscholastic athletics and student activities for inappropriate conduct on or off school grounds all year round.

Read more of their commentary on APP.com



Law in the Age of Web 2,0

http://www.computerworld.com/s/article/9177138/When_trade_secrets_meet_Facebook

When trade secrets meet Facebook

Is a customer list a trade secret once it's been recreated as a LinkedIn or Facebook account?

By Richard C. Darwin and Erin Welsh May 22, 2010 07:30 AM ET

Computerworld - Social networking sites are changing the way people interact, socially and professionally. Sites like Facebook and LinkedIn let people establish relationships and store information on their contacts.

… But the use of these social networking sites by employees to manage their business contacts can also have implications when those employees leave to join a competitor. Client lists and customer databases are frequently alleged to be trade secrets. If an employee has used a client list to build a network of links and/or contacts on Facebook or LinkedIn, does that list lose its trade secret status?


(Related) Big = Evil? Has antitrust addressed global revenue streams in comparison to non-global companies?

http://www.bespacific.com/mt/archives/024311.html

May 22, 2010

NYT: "Federal government is examining Google's acquisitions and actions as never before"

Regulators are Watching Google Over Antitrust Concerns: "When it comes to government scrutiny, the company’s executives challenge the premise that Google is a monopoly, even as the company’s share of the search market inexorably rises, arguing that Google is still a minor player in the overall advertising market, which totals $800 billion a year... [Google's revenue was less than $24 Billions Bob] “They are not just on the radar screen. They are the at the center of it,” said Tim Wu, a professor at Columbia University and the author of a forthcoming book on technology monopolies, “The Master Switch: The Rise and Fall of Information Empires.” “If you are in the federal government and are interested in antitrust, you are looking at Google.”


(Related) Big = Evil. And we've gotta handicap anyone that successful – the alternative is to admit they're smarter than us. (Who is John Galt?)

http://www.pogowasright.org/?p=10486

Swiss want new rules to regulate firms like Google

May 23, 2010 by Dissent

Switzerland’s data protection chief said Sunday that the country needs new rules to regulate Internet services such as Google which could pose a problem to individuals’ privacy.

“I believe that Internet services and applications that could endanger personal rights must be subject to a licensing procedure,” said Hanspeter Thuer, Swiss data protection commissioner, in an interview with newspaper Sonntag.

Asked if this meant that a sort of Google-law was required, Thuer said: “Yes. A change in legislation is needed not just for Google, but for all IT applications. Everyone that offers applications on the market that could harm personal rights must be certified.”

Read more from the AFP on Expatica.com

Let’s see: if Canada’s privacy commissioner takes on Facebook, and Europe takes on Google, then, gosh, we really don’t need any U.S. privacy czar or commissioner to protect our privacy and data. Which is just as well, since other than some admirable efforts by the FTC, what has our federal government done to protect our privacy?

This is America, right? Why are we still essentially outsourcing privacy protection?



I wonder what “loose” means in Russia?

http://www.databreaches.net/?p=11758

Russia Considers Improving its Data Protection Law

May 22, 2010 by admin

The Russian Federation is considering amending the country’s data protection law, according to BNA’s Privacy Law Watch. Businesses have long complained that the law contains restrictions on data processing that are extremely difficult to meet. For example, the law requires affirmative written consent for most types of data processing. In the online context, this provision has been interpreted to require a consumer’s digital signature. A check box, which is an acceptable mechanism for expressing consent in the EU, for example, is deemed unacceptable in Russia.

Read more on Hunton & Williams LLP, Privacy and Information Security Law Blog.



Interesting that citations of law are now global...

http://www.databreaches.net/?p=11761

FAQ on Alberta’s New Breach Notice Law

May 22, 2010 by admin

David Navetta writes:

Earlier this month (May 1, 2010), Alberta became the first Canadian province to pass a broad breach notice law (“Bill 54”) as part of their comprehensive data privacy statute, the Personal Information Protection Act (“the Act”; technically, Alberta is the second province to pass a breach notice law in Canada, Ontario previously passed a breach notice law that focuses on health information custodians).

It will be interesting to see whether the Alberta law ushers in the passage of additional provincial laws similar to way California’s SB 1386 lead to breach notice laws in over forty U.S. states. There appear to be several breach notice initiatives at the provincial and federal level in Canada, some of which may be on the verge of passing. If a wave of breach notice laws do pass throughout Canada, it will be interesting to see if it will have the same impact as in the United States (e.g. frequent reporting of breaches, lawsuits, etc.). It will also be interesting to see whether the Canadian approach differs from the U.S. approach.

This blog post breaks down Alberta’s breach notice provisions in a “Frequently Asked Questions” format, and includes commentary and comparisons to existing U.S. Law. Note that the Act also now includes obligations concerning collecting and transferring of personal information outside of Canada. That is also discussed briefly in this blog post.

Read the FAQ on InformationLawGroup.



“Security is as Security does.” F. Gump This only works if you don't bother to log and review changes to your website.

http://tech.slashdot.org/story/10/05/22/1546215/Malware-on-Hijacked-Subdomains-a-New-Trend?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Malware on Hijacked Subdomains, a New Trend?

Posted by Soulskill on Saturday May 22, @12:20PM

The Unmask Parasites blog discusses a technique attackers are using more and more often recently: modifying a compromised site's DNS settings to redirect various subdomains to different IPs that serve up malware, often leaving site administrators none the wiser. Quoting:

"It is clear that hackers have figured out that subdomains of legitimate websites are an almost infinite source of free domain names for their attack sites. With access to DNS settings, they can create arbitrary subdomains that point to their own servers. Such subdomains can hardly be noticed by domain owners who rarely check their DNS records after the initial domain configuration. And they cost nothing to hackers. I wonder if using hijacked subdomains of legitimate websites is a new trend in malware distribution or just a temporarily solution that won't be widely adopted by cybercriminals in the long run (like dynamic DNS domains last September)."



I suppose this was inevitable. Strange that a gestural language hasn't been developed by NY Taxi drivers...

http://mobile.slashdot.org/story/10/05/23/0614255/New-iConji-Language-For-the-Symbol-Minded-Texter?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

New iConji Language For the Symbol-Minded Texter

Posted by timothy on Sunday May 23, @06:00AM

"As texting evolves into its own language, a Northern Colorado Business Review article covers an ambitious project to develop a new symbol-based language called iConji for mobile texting and online chatting. 'iConji is a set of user-created 32x32-pixel symbols that represent words or ideas, not dissimilar from ancient Egyptian hieroglyphics or American Sign Language.' There is an instructional video for the iPhone app and it is also integrated into Facebook."

Behind this project is Kai Staats, formerly CEO of Terra Soft Solutions, the original developer of Yellow Dog Linux.



This must be useful to someone, right?

http://www.makeuseof.com/tag/find-content-matters-twitter-part-1/

9 Websites To Show You The Hottest Stuff on Twitter Now



Facebook has problems enough, now they are a gateway to Microsoft?

http://www.makeuseof.com/tag/microsoft-docs-supplement-replacement-ms-office/

Microsoft Docs – A Supplement To (Not A Replacement) MS Office

Microsoft Docs is technically in beta, but I received my login within minutes of signing up. Just head over to Docs.com and click the “Sign Up” button.

… You’ll notice right away that signing into Microsoft Docs requires not an MSN username and password but a Facebook one.



For my website class

http://www.cssreflex.com/2010/05/10-best-css-editors.html

10 Best of Breed CSS Editors