Wednesday, June 02, 2010

As the Ski Season closes here in Colorado, the Class Action Season opens...

http://www.pogowasright.org/?p=10765

Aspen law firm, two attorneys take on Google

June 1, 2010 by Dissent

Rick Carroll reports:

An Aspen law firm has filed a class-action complaint on behalf of millions of Google e-mail users, alleging the Internet host violated their privacy.

Filed Thursday in the U.S. District Court of Denver, the lawsuit seeks to attain class-action status on behalf of users of Google’s free e-mail service, Gmail.

Aspen attorneys John Case and Lauren Maytin are the two plaintiffs who represent the users in the class-action suit, which was filed by the Aspen firm Thomas Genshaft PC. Neither Maytin nor Case are members of Thomas Genshaft PC.

The suit accuses California-based Google of violating three federal communications laws — the Electronic Communications Privacy Act, the Stored Communications Act and the Computer Fraud and Abuse Act — after it rolled out its Google Buzz social networking service Feb. 9. The suit also alleges violation of privacy under Colorado common law.

Read more on Vail Daily.


(Related) Apparently, Yahoo wants to emulate Google's success in the “Most sued” category.

http://www.washingtonpost.com/wp-dyn/content/article/2010/06/01/AR2010060100577.html

Yahoo to turn subscribers' e-mail contact lists into social networking base

By Cecilia Kang Washington Post Staff Writer Tuesday, June 1, 2010

Yahoo plans to announce Tuesday that it is jumping into social networking by using its massive population of e-mail subscribers as a base for sharing information on the Web.

Over the next few weeks, its 280 million e-mail users will be able to exchange comments, pictures and news articles with others in their address books. The program won't expose a user's contact list to the public, as was done by Google through its social networking application, Buzz. But unless a user proactively opts out of the program, those Yahoo e-mail subscribers will automatically be part of a sweeping rollout of features that will incorporate the kinds of sharing done on sites such as Facebook and MySpace.


...and of course, Facebook goes them all one better.

http://news.cnet.com/8301-13578_3-20006532-38.html?part=rss&subj=news&tag=2547-1_3-0-20

Facebook 'Like' button draws privacy scrutiny

by Declan McCullagh June 2, 2010 4:00 AM PDT

When Facebook Chief Executive Mark Zuckerberg recently announced a "Like" button that publishers could place on their Web pages, he predicted it would make the Web smarter and "more social."

What Zuckerberg didn't point out is that widespread use of the Like button allows Facebook to track people as they switch from CNN.com to Yelp.com to ESPN.com, all of which are sites that have said they will implement the feature.

Even if someone is not a Facebook user or is not logged in, Facebook's social plugins collect the address of the Web page being visited and the Internet address of the visitor as soon as the page is loaded--clicking on the Like button is not required. If enough sites participate, that permits Facebook to assemble a vast amount of data about Internet users' browsing habits.



Is it also possible to use Facebook or Twitter to establish an alibi? “Chillin' at home. Not visiting the mistress tonight.”

http://www.pogowasright.org/?p=10776

Divorce attorneys catching cheaters on Facebook

June 2, 2010 by Dissent

It’s a bit risky to post personal info and photos on social media, as you never know how it might come back to bite you in terms of employment — or divorce. It seems that matrimonial lawyers are really using Facebook as a primary investigative resource to find evidence on cheating spouses and the like. And when Facebook changed its privacy controls and made more info public than users knew or wanted, some divorce lawyers had a field day.

Stephanie Chen reports:

[...]

Facebook — where attorneys find most of the evidence and leads — has gradually relaxed privacy settings over the last year. Attorneys say that enabled some members’ personal details to be leaked without the user realizing it, attorneys say. On May 26th, Facebook founder Mark Zuckerberg acknowledged the problem and, in a blog, announced new tools making it easier for users to tighten privacy settings and block outside parties from seeing personal information.

“It’s becoming all but impossible to protect your information unless you spend hours and hours figuring it out,” said Lee Rosen, a divorce attorney in North Carolina, who added he reaped the benefits of the tricky privacy controls in a recent case.

Read more on CNN.



A brief (126 page) summary

http://www.databreaches.net/?p=12002

Educational Security Incidents Year in Review – 2009

June 1, 2010 by admin

After a hiatus, Adam Dodge’s ESI blog is back, and Adam has published his analysis of education sector breaches in 2009. From his summary:

The ESI Year in Review – 2009 examines all of the information security incidents occurring at colleges and universities around the world as reported in the news during 2009.

The information security incidents reported by institutions of higher education throughout 2009 were down significantly in both the number of incidents and the amount of information exposed. This downward trend in higher education incidents follows a broader downward trend in breaches across all industry sectors in 2009 . As such, 2009 saw fewer institutions reporting a smaller number of breaches. During 2009, institutions of higher education showed no Loss-type incidents, a significant change over the past three years. In addition, only one incident reported in the news affected multiple institutions, a substantially smaller number than 2008. In fact, many of the numbers in the Year in Review 2009 are close to those reported in 2006. However, the large number of institutions involved in this one multi-institution incident once against caused the number of institutions suffering from a breach to be greater than then number of breaches reported.

You can read the entire report here (pdf, 1.09 MB).



Are they suggesting that this is a manual procedure?

http://arstechnica.com/tech-policy/news/2010/06/time-warner-cable-a-good-isp-for-copyright-infringers.ars

Time Warner Cable "a good ISP for copyright infringers"

By Nate Anderson | Last updated a day ago

If you're wearing an eyepatch as you read this, pay attention: Time Warner Cable is the ISP for you. According to lawyers currently suing thousands of P2P users in federal court, TWC "is a good ISP for copyright infringers."

The outrageous behavior that provoked this claim? TWC's unwillingness to process in a timely manner hundreds or thousands of subscriber subpoenas sent from the law firm of Dunlap, Grubb, & Weaver.

… "Copyright cases involving third-party discovery of Internet service providers have typically related to a plaintiff's efforts to identify anonymous defendants whose numbers rank in the single or low double digits," the cable company told a federal judge earlier this month. "By contrast, plaintiff in this case alone seeks identifying information about 2,049 anonymous defendants, and seeks identifying information about 809 Internet Protocol addresses from TWC."

It continued: "If the Court compels TWC to answer all of these lookup requests given its current staffing, it would take TWC nearly three months of full-time work by TWC's Subpoena Compliance group, and TWC would not be able to respond to any other request, emergency or otherwise, from law enforcement during this period. TWC has a six-month retention period for its IP lookup logs, and by the time TWC could turn to law enforcement requests, many of these requests could not be answered."



Another Korea rant (sorry)

If your campaign platform is the same as North Korea’s, are you a fool or a tool?

http://www.buenosairesherald.com/BreakingNews/View/35160

South Korea probes war rumours ahead of elections

South Korean police are probing leaflets and Internet messages spreading rumours of imminent war and questioning an investigation into the sinking of a naval vessel which they say could affect Wednesday's local elections.

The ship sinking has become the top campaign issue, with the liberal opposition accusing President Lee Myung-bak of provoking tension after a decade of warming ties with reclusive and impoverished North Korea.

But polls showed Lee's uncompromising stand against the North has helped keep support ratings for him near the 50 percent mark in recent weeks.

… The crackdown on Internet rumor mongering is likely to resurrect a frequent opposition complaint that the government is trampling on democracy and free speech.

… An officer at Seoul police HQ said investigators were looking for the source of leaflets that said the results of the probe on the navy ship sinking had been fabricated.

Some leaflets say the government has been taking pictures of its troops as preparations for their funerals in anticipation of war with North Korea, he said.


(Related) Cyber-harassment? Cyber-propaganda? “…the continuation of politics by other means?”

http://www.etaiwannews.com/etn/news_content.php?id=1274260&lang=eng_news

SKorea accuses NKorea of identity thefts

By SANGWON YOON Associated Press 2010-06-01 09:08 PM

North Korea is stealing ordinary South Korean citizens' identities to open Internet accounts and post messages denying Pyongyang's involvement in the recent sinking of a South Korean warship, Seoul's top spy agency said Tuesday.

.. North Koreans have been registering with South Korean identification numbers to post material claiming the ship sinking as an event staged by Seoul, a National Intelligence Service official said Tuesday. In South Korea, people need to provide their ID numbers when they open a Web account.

The posts called the sinking of the 1,200-ton patrol ship "a staged fabrication" and questioned the veracity of the multinational investigation findings, South Korea's Yonhap news agency reported, citing an unnamed government source.

These cyberattacks are an advanced form of North Korea's psychological warfare against the South, designed to cause social panic, distrust, and instability, according to Yonhap.

Seoul resumed psychological warfare operations last month, which include radio broadcasts into the North and placing loudspeakers at the border to blast out propaganda, as a part of its punitive measures for Pyongyang.

North Korea _ which flatly denies involvement in the sinking of the Cheonan _ responded by threatening to cut ties with South Korea, wage "all-out counterattacks" against psychological warfare operations and bar South Korean ships and airliners from its waters and airspace.

Last year, North Korea was suspected in cyberattacks that paralyzed the sites of South Korean government agencies, banks and Internet sites.



Why would this surprise anyone? Think of it as another share of the market AT&T chooses not to contest.

http://techcrunch.com/2010/06/02/att-announces-new-data-plans-unlimited-data-nowhere-to-be-seen/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

AT&T Announces New Data Plans, Unlimited Data Nowhere To Be Seen



For my Computer Forensics students. First, you need the database...

http://www.theregister.co.uk/2010/06/01/enf_met_police/

Met lab claims 'biggest breakthrough since Watergate'

Power lines act as police informers

By Chris Williams Posted in Policing, 1st June 2010 11:16 GMT

Police scientists have hailed a new technique that recently played a pivotal role in securing a murder conviction as the most significant development in audio forensics since Watergate.

The capability, called "electrical network frequency analysis" (ENF), is now attracting interest from the FBI and is considered the exciting new frontier in digital forensics, with power lines acting as silent witnesses to crime.

… ENF relies on frequency variations in the electricity supplied by the National Grid. Digital devices such as CCTV recorders, telephone recorders and camcorders that are plugged in to or located near the mains pick up these deviations in the power supply, which are caused by peaks and troughs in demand.

… At the Metropolitan Police's digital forensics lab in Penge, south London, scientists have created a database that has recorded these deviations once every one and a half seconds for the last five years. Over a short period they form a unique signature of the electrical frequency at that time, which research has shown is the same in London as it is in Glasgow.

On receipt of recordings made by the police or public, the scientists are able to detect the variations in mains electricity occuring at the time the recording was made. This signature is extracted and automatically matched against their ENF database, which indicates when it was made.



An example of a ethical hacking tool. (They have a simple way to ensure that you own the website)

http://www.killerstartups.com/Web-App-Tools/zerodayscan-com-scan-how-secure-your-site-is

ZeroDayScan.com - Scan How Secure Your Site Is

http://www.zerodayscan.com/

ZeroDayScan is an online security scanner that can be used by webmasters that want to learn how secure their sites are both directly and cost-effectively. That is, having a site analyzed entails little more than providing the URL in question, and the whole process is free from start to finish.



For my Hackers...

http://www.makeuseof.com/tag/how-to-install-mac-os-x-on-a-pc-without-using-a-mac/

How to Install Mac OS X on a PC (Without Using a Mac)



In fact, I use some of these. They are quite useful.

http://www.maximumpc.com/article/features/expand_your_browser_universe

32 Incredible Bookmarklets for Chrome, Firefox, Safari and Internet Explorer



Just because I'm a Muppet fan.

http://technologizer.com/2010/05/31/ibm-muppets/

The IBM Muppet Show

Before Sesame Street and The Muppet Show, Jim Henson made short films for Big Blue. The tech may be archaic, but the entertainment is timeless.



A tool for research papers?

http://www.makeuseof.com/dir/scribtex-online-latex-editor

ScribTex: Free LaTex Editor Online

LaTex is a markup language and a document preparation system, widely used by academics and other fields. ScribTex is an online editor that lets you create, edit and share LaTex documents on the web. You can not only share documents with your friends but also give them persmission to edit the documents while keeping track of each revision.

If you don’t like a change you or somebody else has made, just undo it. ScribTex also lets you add images and other media to your LaTex documents. Once you are done, simply compile your document as a PDF file and share it anyway you want.

www.scribtex.com

Similar sites: MonkeyTex and Verbosus.

Tuesday, June 01, 2010

Another source of Privacy ideas...

http://www.pogowasright.org/?p=10742

Privacy Law Scholar’s Conference to be held this week

May 31, 2010 by Dissent

“Get back.
Get back.
Get back to where you once belonged.”

That Beatles’ tune kept running through my head yesterday as I read through some of the draft papers for the upcoming Privacy Law Scholar’s Conference to be held this week in Washington, D.C. While many of the papers are forward-looking, some take us back or urge a return to earlier approaches to privacy:

Peter Winn, an Assistant U.S. Attorney for the DOJ and law lecturer at the University of Washington Law School, will be presenting an absolutely fascinating paper on the “History of the Law of Privacy in the 16th & 17th Century.” His article really left me with a better understanding of the English roots of our legal system’s approach to privacy and with new appreciation that the “right to be let alone” was not judicial activism but was more firmly rooted in English law than some current jurists and members of Congress seem to realize.

Also read to the tune of “Get Back:” Paul Ohm, an Associate Professor at the University of Colorado Law School, has a paper, “The Benefits of the Old Privacy: Restoring the Focus to Traditional Harm,” while Lior Strahilevitz, Deputy Dean, Professor of Law & Walter Mander Teaching Scholar, University of Chicago, is presenting his paper, “Reunifying Privacy Law,” and Carol M. Bast and Cynthia A. Brown of the University of Central Florida are presenting their paper, “A Contagion of Fear: Post-9/11 Alarm Expands Executive Branch Authority and Sanctions Prosecutorial Exploitation of America’s Privacy.”

There are many more papers being presented this week (you can see the program here) and the only dilemma is how to decide which sessions to attend when everything sounds fascinating. As but one example of the many thoughtful and critical analyses being presented, Susan Freiwald, Professor of Law at the University of San Francisco School of Law, has a wonderful paper on “Fourth Amendment Protection for Stored Cell Site Location Information” that should also stimulate a lot of discussion.

Indeed, my fervent wish to get some of these people to guest blog on PogoWasRight.org to present their work for a public audience in a way that more people can understand the threats we face today to our privacy. I really doubt that most of the public truly understands how much information their cell phone carriers retain and can generate about them, the privacy risks we face when such data are handed over to law enforcement or combined with other databases, and why the public should care about the government’s argument that it doesn’t need a warrant to obtain location data.

Great thanks to law professors Dan Solove of George Washington University Law School and Chris Hoofnagle of the Berkeley Center for Law & Technology for organizing the conference and for inviting me, and to the sponsors who are making the conference possible as a free event for attendees: The Future of Privacy Forum, Doug Curling, AT&T, Google, The Privacy Projects, Intel, and Technology | Academics | Policy (TAP).

The conference will be on Thursday and Friday, and I’ll try to blog more about it each day.



A guide for Class Action lawyers?

http://news.cnet.com/8301-30684_3-20006342-265.html?part=rss&subj=news&tag=2547-1_3-0-20

Deciphering Google's Wi-Fi headache (FAQ)

by Tom Krazit June 1, 2010 4:00 AM PDT

How did Google's Wi-Fi spying debacle get to this point?

As Google prepares to defend itself against allegations of Wi-Fi spying, it has said very little about exactly what kind of personal data it gathered as part of its Street View project. Last week, Google also declined to provide executives willing to speak on the record about how one of the most monumental oversights in its history occurred: the inadvertent gathering of "payload" data by Wi-Fi sniffers mapping hotspots while recording street scenes for Google Street View.

But Google finally did confirm a few additional details about the type of scanning procedure it used as well as the nature of the code first written by Google engineers back in 2006. It first took responsibility for the gaffe--which only came to light after detailed inquiries from German authorities--in a blog post on May 14, and ever since then, Google critics have delighted at the opportunity the incident has provided, with lawsuits and Congressional inquiries pending.

Let's take a look at what Google has said and some of the technology issues in question to get some more perspective on Google's Wi-Fi scanning problem.

What data does Google have?

Google admitted on May 14 that it had been "mistakenly collecting samples of payload data from open (i.e. non-password-protected) Wi-Fi networks" for three years. Payload data is distinct from a "header," which contains mostly benign information about the network itself: The payload is the actual data that is being transmitted over the network.

… However, Google's store of personal data might not be quite the treasure trove it may seem. Data sent back and forth between encrypted Web sites (password logins, online banking, credit-card transactions, or anything with https:// in the URL) would not be collected. Mobile workers signed into VPNs would also not be affected.

In addition, it's not totally clear how much data Google would be able to capture with a Street View car moving at about 25 miles per hour along the streets of cities and towns around the world. Google said the data was "fragmented," implying that piecing together any coherent image from that data would be difficult.



Does government have it backwards? Do they cut taxes in good times? I don't think so...

http://www.bespacific.com/mt/archives/024380.html

Pew Report: Recession Brings Another Round of Higher Taxes and New Fees to Big Cities


(Related)

http://www.docuticker.com/?p=35947

New Law Increases Paperwork for Self-Employed Over A Thousand Percent



Twitter as a guide to “What's Hot!”

http://www.makeuseof.com/dir/zoofs-watch-videos-shared-discussed-twitter

Zoofs: Watch Most Shared Videos on Twitter

www.zoofs.com

Similar tools: TwitVid and Mov.io.


(Related) Some statistics

http://www.babybacon.com/index.php/random-pictures/misc/the-amazing-stats-of-twitter/

The Amazing Stats Of Twitter



“There's an app for that!”

http://news.slashdot.org/story/10/05/31/2228201/Study-Claims-Cellphones-Implicated-In-Bee-Loss?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Study Claims Cellphones Implicated In Bee Loss

Posted by kdawson on Monday May 31, @07:56PM

krou passes along word from Telegraph.co.uk that researchers from Chandigarh's Punjab University claim that they have proven mobile phones could explain Colony Collapse Disorder.

"They set up a controlled experiment in Punjab earlier this year comparing the behavior and productivity of bees in two hives — one fitted with two mobile telephones which were powered on for two 15-minute sessions per day for three months. The other had dummy models installed. After three months the researchers recorded a dramatic decline in the size of the hive fitted with the mobile phone, a significant reduction in the number of eggs laid by the queen bee. The bees also stopped producing honey. The queen bee in the 'mobile' hive produced fewer than half of those created by her counterpart in the normal hive. They also found a dramatic decline in the number of worker bees returning to the hive after collecting pollen."

We've talked about the honeybee problem before. Today's article quotes a British bee specialist who dismisses talk of cellphone radiation having anything to do with the problem.



Tools for Geeks

http://www.makeuseof.com/tag/sleek-easy-administer-ubuntu-ubuntu-control-center/

A Sleek & Easy Way To Administer Ubuntu – Ubuntu Control Center



These are definitely not the tools I would have expected.

http://www.makeuseof.com/tag/top-10-downloaded-student-tools-movers-shakers/

Top 10 Most Downloaded Student Tools

It’s time once again for our featured Movers and Shakers post. Each week, we take one software category and list the top ten most downloaded free apps.



'cause I only steal from the best!

http://www.freetech4teachers.com/2010/05/einztein-locate-online-courses-and.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+freetech4teachers%2FcGEY+%28Free+Technology+for+Teachers%29

Monday, May 31, 2010

Einztein - Locate Online Courses and Course Materials

Einztein is a new service for locating online collegiate level courses and corresponding materials. Einztein isn't your standard search engine as all courses listed by Einztein are reviewed by a PhD level editorial team. Each course listed by Einztein comes with a listing of the types of materials available for each course. Some courses have audio, video, and documents while other course may only have one or two of those elements. Visitors to Einztein can search for course by keyword or simply browse courses by subject area.

Monday, May 31, 2010

Interesting (if simple) tool for filling in the blanks in a boilerplate policy. I could easily see this extended into an advertising tool for lawyers specializing in a variety of areas, since it could raise the kind of questions you would need a lawyer's help to answer.

http://www.makeuseof.com/dir/policytool-social-media-policy/

PolicyTool: Create A Social Media Policy For Your Company

With social networks becoming an integral part of everybody’s life, it is important for companies to have a clear and concise policy about the use of social media by its employees. However, not every company can afford a team of legal experts to do that. For those who want a quick solution, PolicyTool is a great help.

PolicyTool generates a social media policy for your company by making you answer a few quick questions. Once you have answered these questions about general rules for using social media and information about your company, a comprehensive social media policy is generated that can be used for commercial purposes free of charge.

www.policytool.net



I suspect this is less about censorship and more about access to the Apple platform.

http://yro.slashdot.org/story/10/05/30/1823223/German-Publishers-Want-Censorship-Talks-With-Apple?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

German Publishers Want Censorship Talks With Apple

Posted by kdawson on Sunday May 30, @04:24PM

"The association of German magazine publishers has sent a letter to Steve Jobs (Google translation; German original here) demanding talks about censorship by Apple. The move draws attention to growing concerns about freedom of the press when a single unelected commercial entity has worldwide control over what gets published for iPhone and, especially, iPad."

While the magazine publishers may rightly be concerned about private control of a platform that many of them are counting on for their long-term salvation, the German state is at the very least ambivalent about the subject of censorship. This is the country that has banned Wikileaks, sought a ban on violent games, and voted to censor child porn (only to have the president kill the ban as unconstituitonal).



No doubt she got the idea while reading the National Enquirer...

http://www.pcworld.com/article/197618/Google_Maps_Error.html?tk=rss_news

Woman Sues Google for Bad Directions



Let's just skip to 99G and same time...

http://www.google.com/hostednews/ap/article/ALeqM5g-9J1V_QON7EkHyfAv96mxHNuPAgD9G19JI00

4G wireless: It's fast, but outstripped by hype

By PETER SVENSSON (AP) – 20 hours ago

NEW YORK — Cell phone companies are about to barrage consumers with advertising for the next advance in wireless network technology: "4G" access. The companies are promising faster speeds and the thrill of being the first on the block to use a new acronym.

But there's less to 4G than meets the eye, and there's little reason for people to scramble for it, at least for the next few years.

… Broadly speaking, it's a new way to use the airwaves, designed from the start for the transmission of data rather than phone calls.



Continuing my “Wow, that's a lot of data!” theme

http://www.readwriteweb.com/archives/the_coming_data_explosion.php

The Coming Data Explosion

Written by Richard MacManus / May 31, 2010 3:34 AM

One of the key aspects of the emerging Internet of Things - where real-world objects are connected to the Internet - is the massive amount of new data on the Web that will result. As more and more 'things' in the world are connected to the Internet, it follows that more data will be uploaded to and downloaded from the cloud.

… Mayer went on to say that there were 5 exabytes of data online in 2002, which had risen to 281 exabytes in 2009. That's a growth rate of 56x over 7 years. Partly, she said, this has been the result of people uploading more data. Mayer said that the average person uploads 15 times more data today (in 2009) than they did just 3 years ago.

… HP's Parthasarathy Ranganathan used the term "ubiquitous nanosensors," which can have multiple dimensions per sensor:

  • Vibration

  • Tilt

  • Rotation

  • Navigation

  • Sound

  • Air flow

  • Light

  • Temperature

  • Biological

  • Chemical

  • Humidity

  • Pressure

  • Location

Ranganathan noted that there will soon be millions of sensors working in real-time, with data sampled every second.

Sunday, May 30, 2010

Strange they can get a patent for something my students have been doing for years – mapping (secure and open) Wifi sites.

http://yro.slashdot.org/story/10/05/29/0818219/Google-Describes-Wi-Fi-Sniffing-In-Pending-Patent?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Google Describes Wi-Fi Sniffing In Pending Patent

Posted by timothy on Saturday May 29, @08:12AM

"After mistakenly saying that it did not collect Wi-Fi payload data, Google had to reverse itself, saying, 'it's now clear that we have been mistakenly collecting samples of payload data from open (i.e. non-password-protected) Wi-Fi networks.' OK, mistakes happen. But, as Seinfeld might ask, then what's the deal with the pending Google patent that describes capturing wireless data packets by operating a device — which 'may be placed in a vehicle' — in a 'sniffer' or 'monitor' mode and analyzing them on a server? Guess belated kudos are owed to the savvy Slashdot commenter who speculated back in January that the patent-pending technology might be useful inside a Google Street View vehicle. Google faces inquiries into its Wi-Fi packet sniffing practices by German and US authorities."



This is probably better at noticing anomalies, but there is no indication (yet) that it could prevent an attack (or any other crime)

http://www.popularmechanics.com/technology/how-to/computer-security/future-of-surveillance-cameras?click=pp

The Future of Surveillance? When Automated Brains Keep Watch 24/7

Unblinking camera eyes need brains to look for real-time threats — but what if those brains are automated?

By David Hambling May 26, 2010 10:30 AM

Surveillance technology provides a vital shield against terrorism, and cheap modern electronics make it easy to fill the city streets with closed-circuit television (CCTV) cameras. New York City mayor Michael Bloomberg recently toured London's ring of cameras, seeking information on how to bring it to the Big Apple to thwart terrorist attacks. But unless the feeds from those cameras are constantly monitored, they only provide an illusion of security. Finding enough eyeballs to watch thousands of screens simply isn't practical, yet modern automated systems can fill the gap with a surprising degree of intelligence.

… Let's look at how this type of system would deal with an event like the failed car-bomb attack in Times Square: The vehicle involved was parked in a No Parking area, the emergency warning flashers were going, and smoke was pouring out of it. All of these were potential warning signs. If the system issued an alert every time a car was parked illegally, there would be a lot of false alarms. But AWARE can cross-check all illegally parked cars without human intervention.

"Should a vehicle be detected parked illegally, AWARE would aim a local camera at the license plate, and License Plate Recognition software would interpret the number," says Robert Allen of AbeoTS. "AWARE would submit the data to the appropriate DMV and the result would be analyzed for threat potential. In the Times Square incident, this would have triggered a threat as the license plate did not match the vehicle."



The end of free? Still cheaper, and possibly a continuous connection.

http://www.wired.com/epicenter/2010/05/skype-over-3g-comes-to-the-iphone-its-not-all-good-news/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

Skype Over 3G Comes to the iPhone. It’s Not All Good News

By John C Abell May 29, 2010 8:56 pm

Skype on Saturday released an upgrade to its iPhone app that allows calls to be made and received under AT&T’s 3G network, but there’s a catch — they won’t be free for very long, even for Skype-to-Skype calls or for people who have all-you-can-eat calling plans with the internet telephony company.

No specific pricing or even timeline was announced, but the release notes of version 2.0.0 (to the right) say this feature will be free only “until at least the end of August 2010, after which there will be a small monthly fee.”

All of this became possible only after Apple changed its iPhone SDK in anticipation of the iPad.

Skype pronouced on Feb 3 that 3G calling would happen “soon.” But the additional cost was not trumpeted and does comes as a surprise, though perhaps not a terribly big one given the revenue possibilities and the additional strain on AT&T’s already-vilified 3G network.

Skype calls are generally free or at least much less expensive than those made on minute-counting calling plans. But wireless minutes have become largely commoditized and, from most wireless carriers, available in unlimited plans that eliminate the traditional profit center that used to be overages.

Skype’s migration from the desktop on to mobile devices has created the potential for a dramatic shift in calling behavior. We aren’t quite there yet. But when you can receive calls from an VoIP provider like Skype on a portable device in either an WiFi or 3G network it almost completely blurs the line between an interesting alternative to a telephone and the very definition of a telephone.

Taking that one small step further: In a world with ubiquitous broadband, internet telephony with push notifications and location awareness could make traditional telco and wireless services irrelevant, even for the equivalent of enhanced 911, where the automatically operator knows where you are.

There are still some pieces missing to this puzzle, but the availability of VoIP under 3G — also true of Fring and for international calls on some Android-powered handsets provided by Verizon — is a big step forward.

And, one last thing: iPhone OS 4, expected in weeks, will enable non-core apps like Skype to operate in the background. Which means that you could be online with the internet telephony service all the time on any 3G enabled device like the iPhone and some models of the iPad.



“Amateur experts” Watching TV without a TV. Newspapers without paper.

http://www.pewinternet.org/Presentations/2010/May/Google.aspx

The Rise of Networked Individuals: The Millennial Tide

by Lee Rainie May 11, 2010 at Google

… The conversation covers questions such as: How have the internet and smart phones enabled modern citizens to create information and media that help them influence others, navigate their options and create new kinds of communities? Are new tools of social media - like blogs, social network sites and texting - reshaping the very environment of media and information itself?



Something to impress the students. Petabyte sized databases are common...

http://en.digitalkamera.com/how-big-is-a-yottabyte-infograph/

How Big is a Yottabyte? [Infograph]

Saturday, May 29, 2010

Our favorite school district learns another lesson: It's expensive to screw up.

http://www.philly.com/philly/news/pennsylvania/20100529_L__Merion__insurance_firm_spar_over_webcam_costs.html

L. Merion, insurance firm spar over webcam costs

By John P. Martin Inquirer Staff Writer Posted on Sat, May. 29, 2010

The Lower Merion School District argued Friday that the district's insurer should pay what could be a million-dollar tab to resolve a lawsuit over its now-disabled laptop tracking program.

… As the district launched an investigation and prepared to defend the lawsuit, it asked its insurer to cover the bills and any settlement or award.

But Graphic Arts balked, contending that its policy covered only personal injury or bodily harm, not the kind of damage that Robbins and his family alleged.

… How high the school district's bills will go is unclear. In the six weeks after Robbins and his parents filed their suit in February, the Ballard Spahr law firm and L3, a computer forensics company, submitted more than $550,000 in invoices for their services to Lower Merion.

District spokesman Doug Young said this week that those bills had been paid, but that the district was waiting for new bills from the firms for their work since then. It was not clear whether the district or insurer had paid those bills.

School board president David Ebby said last month that he expected at least $200,000 more in invoices before the case was over.


(Related) Might be an interesting read...

http://mrzine.monthlyreview.org/2010/scribner280510.html

Someone Is Watching: The Peril and Promise of School Surveillance

by Campbell Scribner

Torin Monahan, Rodolfo D. Torres, eds. Schools under Surveillance: Cultures of Control in Public Education. Critical Issues in Crime and Society Series. New Brunswick: Rutgers University Press, 2010. vi + 264 pp. $72.00 (cloth), ISBN 978-0-8135-4679-7; $24.95 (paper), ISBN 978-0-8135-4680-3.

… Read in light of the Lower Merion incident, what is most shocking is the public's lingering capacity for shock. The surreptitious use of laptop cameras was already underway in a Canadian classroom fifteen years ago, and in the decade after the Columbine shooting and the terrorist attacks of September 11, 2001, school administrators have cast an ever-widening net of observation and control over their pupils, raising important questions about safety, privacy, and student rights



I think we're all getting a little disgusted seeing the same failures over and over and over...

http://www.databreaches.net/?p=11958

Missing records on stolen laptop from Cincinnati Children’s Hospital

May 28, 2010 by admin

Unencrypted.

Employee’s car.

Pardon me while I spit.

Peggy O’Farrell reports (emphasis added by me):

Cincinnati Children’s Hospital Medical Center is beefing up its computer security after a laptop computer containing more than 61,000 patient records was stolen.

The laptop was stolen from a hospital employee’s personal vehicle while it was parked outside the employee’s home in late March. Cincinnati police were notified of the theft.

The missing records were password-word protected, but not encrypted.

An investigation found that the records on the computer contained some personal information about patients, including names, medical records numbers and services provided, said hospital spokesman Jim Feuer.

Feuer stressed, though, that the records did not contain Social Security numbers, credit card numbers or telephone numbers.

Read more on Cincinnati.com.

The hospital issued a statement today, linked from its homepage.

[From the Hospital statement:

The theft occurred from an employee’s vehicle parked at his residence sometime between March 27 and 29, 2010. [So it seems the employee wasn't working on the data at home Also amazing is the data of May 28 on the statement!!! Bob]

… Since this event, Cincinnati Children's has strengthened its encryption practices to ensure no PC laptop computers are issued unless the encryption process is initiated. Additionally, it has improved its process for tracking the encryption of these laptops. [That's a lot to accomplish in no time at all Perhaps Steven Hawking is consulting? Bob]



This answers at least part of the “Why are there so many breaches” question

http://www.databreaches.net/?p=11950

Poll: Canadian businesses unconcerned about privacy breach risk

May 28, 2010 by admin

Most Canadian companies aren’t concerned about data breaches involving their customers’ personal information — even though these same companies report they are collecting and holding more personal information than ever before, according to the results of a poll released today.

The poll conducted by EKOS for the Office of the Privacy Commissioner of Canada found that 42 per cent of businesses surveyed are not concerned about security breaches.

Read the entire press release from the Office of the Privacy Commissioner, or read the final report.



Are we reaching a consensus on patient rights?

http://www.phiprivacy.net/?p=2829

WPF comments on possible changes to HIPAA privacy rule; requests more patient access to audit logs

By Dissent, May 29, 2010 6:02 am

Oops — I missed this announcement last week from the World Privacy Forum:

The World Privacy Forum filed comments with the US Department of Health and Human Services today in response to its Request for Information about possible changes to the HIPAA health privacy rule. WPF strongly supported patients’ current right to request a history of disclosures of their medical files, and requested an expansion of this right. WPF noted in its comments to HHS that “An individual cannot fully protect his/her privacy interest in a health record (and most other records) unless he/she has a right of access to the record, the right to propose a correction, and the right to see who has used the record and to whom it has been disclosed. Each of these elements is essential.”

Read the full WPF comments



If organizations discover new ways to use your personal data, should they tell you about it? Perhaps the proper way to evaluate the risks to your data is to assume that everything will be gathered together and made available to people whose job it is to make your life miserable...

http://www.pogowasright.org/?p=10684

Mobile Data: A Gold Mine for Telcos

May 28, 2010 by Dissent

Tom Simonite reports:

Cell phone companies are finding that they’re sitting on a gold mine–in the form of the call records of their subscribers.

Researchers in academia, and increasingly within the mobile industry, are working with large databases showing where and when calls and texts are made and received to reveal commuting habits, how far people travel for public events, and even significant social trends.

[...]

The data set is a collection of call detail records, or CDRs–the standard feedstock of cell phone data mining. A CDR is generated for every voice or SMS connection. Among other things, it shows the origin and destination number, the type and duration of connection, and, most crucially, the unique ID of the cell tower a handset was connected to when a connection was made. [The network illustration also breaks the data into the language being spoken. How would they know that without listening in? Bob]

[...]

Research in this area is typically focused on aggregate information and not individuals, but questions remain about how to protect user privacy, Blondel says. It is standard to remove the names and numbers from a CDR, but correlating locations and call timings with other databases could help identify individuals, he says. In the MIT study, for example, the team could infer the approximate home location of users by assuming it to be where a handset was most located between 10 p.m. and 7a.m., although they also lumped people together into groups by zip code.

Read more in the MIT Technology Review.



A push toward small, pirate/hacker-oriented ISPs?

http://news.slashdot.org/story/10/05/29/0615230/Ofcom-Unveils-Anti-Piracy-Policy-For-UK-ISPs?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Ofcom Unveils Anti-Piracy Policy For UK ISPs

Posted by timothy on Saturday May 29, @05:01AM

"Under plans drawn up by Ofcom, UK ISPs are going to draw up a list of those who infringe copyright, logging names and the number of times infringement took place. Music and film companies will then be allowed access to the list, and be able to decide whether or not to take legal action. '"It is imperative that a system that accuses people of illegal online activity is fair and clear," said Anna Bradley, chair of the Communications Consumer Panel.' The Panel, in partnership with Consumer Focus, Which, Citizens Advice and the advocacy body the Open Rights Group, has released a set of principles it believes should govern the code of practice. The principles say sound evidence is needed before any action is taken, consumers must have the right to defend themselves, and the appeals process must be free to pursue. The code shall come into practice by 2011, and only initially applies to ISPs with 400,000 customers or more."



No doubt this will requier prosecutors to check if you have ever accessed Google Maps...

http://yro.slashdot.org/story/10/05/28/1821200/High-Tech-Burglars-May-Get-Longer-Sentences-In-Louisiana?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

High-Tech Burglars May Get Longer Sentences In Louisiana

Posted by Soulskill on Friday May 28, @03:08PM

"Burglars and terrorists should be careful not to use Google Maps if they plan on committing crimes in the state of Louisiana. Nola reports that a bill approved 89-0 by the Louisiana House will require that judges impose an additional minimum sentence of at least 10 years on terrorist acts if the crime is committed with the aid of an Internet-generated 'virtual map.' The bill, already approved by the Louisiana Senate, defines a 'virtual street-level map' as one that is available on the Internet and can generate the location or picture of a home or building by entering the address of the structure or an individual's name on a website. If the map is used in the commission of a crime like burglary, the bill calls for the addition of at least one year in jail (PDF) to be added to the burglary sentence. The House measure is now being sent back to the Senate for approval of clarifying amendments made by a House committee."



Statistics

http://mashable.com/2010/05/27/non-google-site-stats/

Facebook Leads in the Top 1,000 Sites

According to Google’s AdPlanner stats, Facebook is the number one most-visited destination on the web. Weighing in at an unfathomably heavy 570 billion page views [That's a 'per month' figure Bob] and 540 million users, the ubiquitous social network outranks every other non-Google site, taking more than 35% of all web traffic measured.

… When it comes to non-Facebook social media properties, Twitter ranks 18th with 5.4 billion page views, Flickr (Flickr) is 31st with 1.8 billion views and LinkedIn (LinkedIn) sits in 56th place at 1.7 billion views.

… Bank of America and PayPal also made the list, coming in at 93rd and 39th, respectively. And in the news category we find the BBC, which was ranked 43rd with 2.5 billion hits, followed by The New York Times’s website, which ranked 83rd with 600 million views.



Another confirmation of the “My opinion is better than your facts” syndrome. Note that this also explains politicians who wish to pass legislation making Pi equal to 3.

http://news.slashdot.org/story/10/05/28/1740208/The-Scientific-Impotence-Excuse?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

The "Scientific Impotence" Excuse

Posted by Soulskill on Friday May 28, @02:25PM

"I've had the feeling for a long time that people refuse to listen to scientists. The following is from an article on Ars Technica: 'It's hardly a secret that large segments of the population choose not to accept scientific data because it conflicts with their predefined beliefs: economic, political, religious, or otherwise. But many studies have indicated that these same people aren't happy with viewing themselves as anti-science, which can create a state of cognitive dissonance. That has left psychologists pondering the methods that these people use to rationalize the conflict. A study published in the Journal of Applied Social Psychology [abstract here] takes a look at one of these methods, which the authors term "scientific impotence" — the decision that science can't actually address the issue at hand properly.' The study found that 'regardless of whether the information presented confirmed or contradicted [the subjects'] existing beliefs, all of them came away from the reading with their beliefs strengthened."



Another attempt to eliminate lawyers? Not according to the site.

http://agree2.com/

Agree2

The easiest way to make agreements online



An interesting talk (video) on how business find value in the tech world.

http://techcrunch.com/2010/05/28/video-evernote-ceo-phil-libin-shares-revenue-stats-and-how-to-make-freemium-work/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

Video: Evernote CEO Phil Libin Shares Revenue Stats (And How To Make Freemium Work)

by Jason Kincaid on May 28, 2010

Last week at the Founder Showcase, a quarterly event put on by Adeo Ressi’s TheFunded, Evernote CEO Phil Libin gave a presentation discussing some of the startup’s key revenue numbers and strategy. During his talk, Libin outlined some of the ingredients in making the freemium model work, and how long-term users actually become more valuable over time.

# Users have grown more valuable over time. New users convert to premium at a rate of .5%. But of the users that signed up two years ago and are still active, 20% have become paid customers.

# Evernote’s cost per user is around 9 cents per active user per month. It makes around 25 cents per user per month. The site reached break even a year and a half ago.



Make an effort now, save time forever.

http://www.makeuseof.com/tag/set-email-filters-gmail-hotmail-yahoo/

How To Set Up Email Filters In Gmail, Hotmail and Yahoo

Friday, May 28, 2010

What did they learn from their breach? That there is a market for security!

http://www.thetechherald.com/article.php/201021/5663/Heartland-offers-end-to-end-encryption-to-customers

Heartland offers end-to-end encryption to customers

by Steve Ragan - May 27 2010, 19:40

The E3 card terminal that Heartland announced this week will offer end-to-end encryption of the card data. Merchants that use it will have peace of mind that the data is useless to criminals if captured, the company said. However, E3 isn’t a free offer to any of their 250,000 plus customers, or those who might want in on the action down the line.

… Ahmad told us that the top three benefits for Heartland customers using E3 include the fact that no cardholder data is present in the merchant’s systems. In addition, there are minimal, if any disruptions to the merchant during day-to-day operations. Finally, there is the warranty from Heartland, which pays the merchant the amount of compliance fines, fees, or assessments in the event of a breach that can be linked to a direct failure of E3.



Things that make you say, “Oops!”

http://www.databreaches.net/?p=11917

UK: 1000 data breaches reported to the ICO

May 28, 2010 by admin

The Information Commissioner’s Office issued a press release and summary analysis of breaches:

With the number of breaches involving people’s personal information reported to the Information Commissioner’s Office (ICO) reaching 1000, the privacy watchdog is urging organisations to minimise the risk of mistakes. Staff need simple procedures on how to handle personal information with appropriate training to ensure the importance of personal information is fully understood.

The entire press release can be found here.

The government’s analysis of the 1007 breaches indicates that stolen data or stolen hardware accounted for the most common cause of breaches, with 307 breaches of this kind. Of those 307 thefts, 116 were reported by the NHS. The second most common source of reported breaches was disclosure errors (254), followed closely by lost data or lost hardware (233).

Comparing sectors, NHS (their public healthcare sector) accounted for 305 breaches, followed closely by the private sector (288 breaches).

ICO_BreachTable



I thought this might get messy. How dare Google actually look at publicly available, broadcast data! That's as rude as looking at the front of my house! The scum!

http://www.pogowasright.org/?p=10643

Oregon Judge Slaps Google With Restraining Order Over Private Wifi Data

May 27, 2010 by Dissent

Nick Saint reports:

An Oregon judge has issued a restraining order forbidding Google from destroying data the company accidentally recorded from private wifi networks with its Street View cars.

Google had announced its intention to consult with privacy advocates and governments about the best way to dispose of the data. Residents of Oregon and Washington filed a class action suit over privacy violations, and requested a restraining order to ensure the data could be used as evidence.

Read more on Business Insider and expect updates on this one.



Would P.T. Barnum's “This way to the egress” be considered adequate labeling?

http://www.pogowasright.org/?p=10640

UK: Viewing a website is a ‘transactional decision’, says OFT’s behavioural ad study

May 27, 2010 by Dissent

Struan Robertson writes:

OPINION: The OFT has endorsed the UK ad industry’s self-regulation of behavioural advertising. But its conclusion was based in part on a curious reading of consumer protection regulations, coupled with research that departs from similar studies.

The Office of Fair Trading is the Government’s consumer and competition authority. That it sees no need for Government regulation in behavioural advertising is great news for online publishers and advertisers. In my view, that is good for consumers too, because it helps to keep content free.

The biggest change demanded in the report is that ads selected according to someone’s browsing behaviour should be labelled. That’s a sensible step, and one that UK trade body the Internet Advertising Bureau (IAB) was taking already.

What surprised me more was another, less significant feature of the report: the OFT says that viewing a website is a transactional decision for the purposes of the Consumer Protection (Unfair Trading) Regulations, known as the CPRs.

Read more on Out-Law.com

[From Out-Law:

The report says:

"The OFT interprets transactional decision widely and believes it encompasses, for example, the decision to view a website. So not informing a consumer about the collection of information about their browsing behaviour could breach the CPRs if that knowledge would have altered their behaviour, perhaps by dissuading them from visiting that website."

The OFT is not just saying that its worried about information or a lack of information influencing a decision to buy something on a website; it's talking about it influencing a decision just to visit a site, whether the site sells things or not.



Who'd a thunk it!

http://news.yahoo.com/s/ap/20100527/ap_on_hi_te/us_tec_online_reputation;_ylt=AoqatztyPnbiRKWbdbBlDteyBhIF;_ylu=X3oDMTJwc3ZkcXBjBGFzc2V0A2FwLzIwMTAwNTI3L3VzX3RlY19vbmxpbmVfcmVwdXRhdGlvbgRjcG9zAzEEcG9zAzIEc2VjA3luX3RvcF9zdG9yeQRzbGsDaW1hZ2UtY29uc2Np

Image-conscious youth rein in social networking

By MARTHA IRVINE, AP National Writer – Thu May 27, 3:49 am ET

CHICAGO – What's that? A young college grad lecturing her elders about online privacy?

It might go against conventional wisdom, but a new report from the Pew Internet & American Life Project is adding fuel to the argument that young people are fast becoming the gurus of online reputation management, especially when it comes to social networking sites.

Among other things, the study found that they are most likely to limit personal information online — and the least likely to trust free online services ranging from Facebook to LinkedIn and MySpace.

… In this instance, adults over the age of 30 might do well to listen. The Pew study and a mounting body of new research is showing that the very generation accused of sharing too much information online is actually leading the pack in online privacy.

The Pew study found, for instance, that social networkers ages 18 to 29 were the most likely to change the privacy settings on their profiles to limit what they share with others online. The percentage who did so was 71 percent, compared with just 55 percent of the 50- to 64-year-old bracket. Meanwhile, about two-thirds of all social networkers who were surveyed said they've tightened security settings.

… Consider also that the study found that a quarter of online adults said their employers now have policies about how they portray themselves online. [That's new, isn't it? Bob]

[The report: http://www.pewinternet.org/Reports/2010/Reputation-Management.aspx?r=1



Where do threats come from and what are their targets? If you have a detection tool anywhere along the path that connects these points (not only at the corporate end-point) you can detect and respond to an attack. Why do you want to be in my network?

http://www.wired.com/threatlevel/2010/05/einstein-on-private-networks/

Pentagon: Let Us Secure Your Network or Face the ‘Wild Wild West’ Internet Alone

By Kim Zetter May 27, 2010 1:50 pm

Companies that operate critical infrastructures and do not voluntarily allow the federal government to install monitoring software on their networks to detect possible cyberattacks would face the “wild” internet on their own and place us all at risk, a top Pentagon official seemed to say Wednesday.

… The Einstein programs are intrusion-detection and response systems developed by the National Security Agency. The government is in the process of deploying Einstein 2 to federal networks to inspect traffic for malicious threats, but there has been talk of deploying it to private-sector networks as well. Intrusion-detection systems are already a standard tool in the defense arsenal of private-sector businesses, and the government has been unclear about how its system surpasses those already available to companies.

… In 2008, DHS’s Privacy Office published a Privacy Impact Assessment (.pdf) on early versions of Einstein 2, but has not published one on Einstein 3. The assessment left many questions unanswered, such as the extent of the NSA’s role in the programs and whether information obtained by the monitoring systems will be shared with law enforcement or other intelligence agencies. [Of course it will. Why else would you bother detecting the attack? Bob]


(Related) ...but a different perspective. Question: How do I distinguish an all out attack from the government trying to take control of my network to defend me? (I'm still haunted by, “In order to save the village, we had to destroy it.”)

http://www.wired.com/dangerroom/2010/05/cyber-command-we-dont-wanna-defend-the-internet-but-we-just-might-have-to/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

Cyber Command: We Don’t Wanna Defend the Internet (We Just Might Have To)

By Noah Shachtman May 28, 2010 9:44 am

OMAHA, Nebraska – Members of the military’s new Cyber Command insist that they’ve got no interest in taking over civilian Internet security – or even in becoming the Pentagon’s primary information protectors. But the push to intertwine military and civilian network defenses is gaining momentum, nevertheless. At a gathering this week of top cybersecurity officials and defense contractors, the Pentagon’s number two floated the idea that the Defense Department might start a protective program for civilian networks, based on a deeply controversial effort to keep hackers out of the government’s pipes.

U.S. Cyber Command (“CYBERCOM“) officially became operational this week, after years of preparation. But observers inside the military and out still aren’t quite sure what the command is supposed to do: protect the Pentagon’s networks, strike enemies with logic bombs, seal up civilian vulnerabilities, or some combination of all three.

… A 356-page classified plan outlining CYBERCOM’s rise is being put into action. A team of about 560 troops, headquartered at Ft. Meade, Maryland, will eventually grow to 1093. Each of the four armed services are assembling their own cyber units out of former communications specialists, system administrators, network defenders, and military hackers. Those units – Marine Forces Cyber Command, the 24th Air Force, the 10th Fleet, and Army Forces Cyber Command – are then supposed to supply some of their troops to CYBERCOM as needed. It’s similar to how the Army and Marines provide Central Command with combat forces to fight the wars in Afghanistan and Iraq. Inside the military, there’s a sense that CYBERCOM may take on a momentum of its own, its missions growing more and more diverse.


(Related) How would you define a data disaster? Loss of control of the Air Traffic system? Disclosure of IRS data? Shutdown of the phone systems./stock markets/airline reservation systems?

http://it.slashdot.org/story/10/05/27/2018201/Are-We-Ready-For-a-True-Data-Disaster?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Are We Ready For a True Data Disaster?

Posted by timothy on Thursday May 27, @05:32PM

"Fatal Exception's Neil McAllister questions how long we can go before a truly catastrophic data disaster strikes. 'The lure of potential profits in the information economy, combined with the apparent ease with which data can be gathered and a lack of regulation, creates a climate of recklessness in which a "data spill" of the scale of the Deepwater Horizon incident seems not just likely, but inevitable.' Witness Google mistakenly emailing potentially sensitive business data to customers of its Local Business Center service, or the 1.5 million Facebook accounts and passwords recently offered up on an underground hacking forum. 'These incidents seem relatively minor, but as companies gather ever more individually identifiable data and cross-reference these databases in new and more innovative ways, the potential for a major catastrophe grows.'"



For my Intro to Computing (and Statistics) students. Another reason for Backups! Note that even with some lasting millions of cycles, we don't yet know what the Mean and Standard Deviation are.

http://hardware.slashdot.org/story/10/05/27/1841242/Flash-Destroyer-Tests-Limit-of-Solid-State-Storage?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Flash Destroyer Tests Limit of Solid State Storage

Posted by timothy on Thursday May 27, @04:02PM

"We all know that flash and other types of solid state storage can only endure a limited number of write cycles. The open source Flash Destroyer prototype explores that limit by writing and verifying a solid state storage chip until it dies. The total write-verify cycle count is shown on a display — watch a live video feed and guess when the first chip will die. This project was inspired by the inevitable comments about flash longevity on every Slashdot SSD story. Design files and source are available at Google Code."



For my Computer Security students.

http://www.computerworld.com/s/article/9177398/How_to_foil_Web_browser_tabnapping_

How to foil Web browser 'tabnapping'

Patches may never come, but you can take steps to stymie tab kidnapping

By Gregg Keizer May 26, 2010 03:32 PM ET

Computerworld - A new, incredibly sneaky identity-theft tactic surfaced earlier this week when Mozilla's Aza Raskin, the creative lead of Firefox, unveiled what's become known as "tabnapping."

Stated simply, tabnapping -- from the combination of "tab" and "kidnapping" -- could be used by clever phishers to dupe users into giving up passwords by secretly changing already-open browser tabs. All of the major browsers on Windows and Mac OS X are vulnerable to the attack.



For my Computer Forensics students who don't have Windows 7 yet...

http://www.makeuseof.com/dir/findexif-extract-exif-data-online/

FindExif: Extract EXIF Data Online

All digital cameras add a bunch of information to each photo that they save. This information is called the EXIF data that is used to store information about the camera used to take the photo, the camera settings used, resolution of the image and other details that might help in classifying the image later on.

… FindExif is an online site that lets you extract exif data online and view it in an easy to understand format.

www.findexif.com

Similar sites: CameraSummary, Get-exif-info and Exifremover.



For my Computer Security (Process Engineering) students.

http://it.slashdot.org/story/10/05/28/009220/CERT-Releases-Basic-Fuzzing-Framework?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

CERT Releases Basic Fuzzing Framework

Posted by timothy on Thursday May 27, @08:53PM

"Carnegie Mellon University's Computer Emergency Response Team has released a new fuzzing framework to help identify and eliminate security vulnerabilities from software products. The Basic Fuzzing Framework (BFF) is described as a simplified version of automated dumb fuzzing. It includes a Linux virtual machine that has been optimized for fuzz testing and a set of scripts to implement a software test."

[From the article:

Fuzz testers, or fuzzers, are used by security researchers to find vulnerabilities by sending random input to an application. If the program contains a vulnerability that can leads to an exception, crash or server error, researchers can parse the results of the test to pinpoint the cause of the crash. [Note that this is the opposite of testing with real data. Your software must handle ANY input. Processing the good stuff and rejecting the bad. Bob]



For my Ethical Hacking students Why we use Linux (Ubuntu)

http://apple.slashdot.org/story/10/05/27/1826207/iPhones-PIN-Based-Security-Transparent-To-Ubuntu?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

iPhone's PIN-Based Security Transparent To Ubuntu

Posted by timothy on Thursday May 27, @03:19PM

"Security experts found that the iPhone 3GS has very little security, even with a PIN set up. They plugged one into Ubuntu 10.04, and it was automounted with almost all of the iPhone's data exposed. This has been reported to Apple, but the company seems to be having difficulty reproducing the problem."


(Related) Making Linux even more useful

http://www.makeuseof.com/tag/4-ways-linux-compatible-software/

4 Ways To Make Linux Compatible With Even More Software



Tools & Techniques

http://www.makeuseof.com/tag/3-fast-easy-online-screen-capture-tools/

3 Fast and Easy Online Screen Capture Tools



Tools & Techniques A number of simple videos explaining how things work.

http://www.commoncraft.com/

Common Craft

[Some Technology topics:

Blogs

Cloud Computing

RSS

Web Search Strategies

Wikis