Friday, September 06, 2013

I suspect more lawsuits based on failure to follow regulations and/or Best Practices. Clearly organizations are not learning from the failures of others.
Mitch Smith reports:
Advocate Medical Group, already under federal and state investigation after the theft of computers containing personal information on millions of people, is now facing a class-action lawsuit from patients who say the Downers Grove-based physician group didn’t do enough to protect their private data.
The suit, filed in Cook County Circuit Court, says the health care nonprofit violated privacy regulations by failing to use encryption and other security measures on the four computers that were stolen from its Park Ridge offices in July. The computers contained information on more than 4 million patients.
Read more on Chicago Tribune.


This should be interesting.
In a major victory in one of EFF’s Freedom of Information Act (FOIA) lawsuits, the Justice Department conceded yesterday that it will release hundreds of documents, including FISA court opinions, related to the government’s secret interpretation of Section 215 of the Patriot Act, the law the NSA has relied upon for years to mass collect the phone records of millions of innocent Americans.
In a court filing, the Justice Department, responding to a judge’s order, said that they would make public a host of material that will “total hundreds of pages” by next week, including:
[O]rders and opinions of the FISC issued from January 1, 2004, to June 6, 2011, that contain a significant legal interpretation of the government’s authority or use of its authority under Section 215; and responsive “significant documents, procedures, or legal analyses incorporated into FISC opinions or orders and treated as binding by the Department of Justice or the National Security Agency.”
Read more on EFF.

(Related) Dilbert explains the upside of NSA spying.


This shouldn't be so shocking.
This Russian Software Is Taking Over the Internet
… At a time when the world’s best-known web servers are losing marketshare, Nginx — pronounced “Engine X” — is growing, fueled by a no-frills philosophy and its knack for handling myriad web connections at the same time. Apache is still the king of all web servers, but use of Nginx has nearly doubled over the past two years, according to internet research outfit Netcraft.
It now runs about 15 percent of all websites, including everyone from startups such as CloudFlare and Parse (bought by Facebook earlier this year) to web giants such as Automattic and Netflix. “We use it for everything,” says Automattic’s Abrahamson. “We run as much of our software stack as possible on top of Nginx.”


A tool for stalkers.
– A geosocial footprint is the combined bits of location information that a user divulges through social media, which ultimately forms the users location “footprint”. For Twitter.com users, this footprint is created from GPS enabled tweets, social check-ins, natural language location searching, and profile harvesting. This website provides twitter users with an opportunity to view their geosocial footprint.

(Related) Another stalking tool.
– This app shows how people could use your social-media posts to find you in the physical world. It uses GPS data attached to Twitter and Instagram posts to create a map of where someone’s been posting from recently. Try to find yourself, your friends, or your favorite celebrity! Where are you most likely to be at 2:00 on a Tuesday? Then follow the links and find out.


Nothing ever dies on the Internet. This might become a valuable research tool.
Search For Tweets Since The Beginning Of Twitter With Topsy
… Topsy, the social analytics company gives you the ability to use it to search all tweets since the beginning of Twitter time. The ability to sift and search through an index of 540 billion tweets is an exceptional tool because Twitter’s real time conversation has become a huge storehouse of knowledge.


If you buy the book-book, (book2?) we'll give you (or heavily discount) the eBook too.
Amazon Soon To Offer Free & Discounted Ebooks Of Hard Copies Purchased Through Its Site


Something for that eGarage sale.
How To Be An Online Entrepreneur With Thrift Store Shopping On eBay
… With eBay, you can turn yourself into an online entrepreneur by flipping items you can find nearly anywhere — online or offline. Best of all, it’s pretty darn easy to do, and this means you can turn your weekend thrift store outings into a profitable hobby.


For my Math students: Targeted to K-12, but still potentially useful.
– presents math instruction and practice in a clear, manageable format that is complete with helpful hints, video lessons, and interventions. When a student doesn’t do well on a topic, TenMarks provides immediate and targeted intervention. The program analyzes precisely the areas in which the student is struggling, and assigns an “Amplifier” which diagnoses the root cause of the issue.


I try to use Wikis in my Security classes because students need to keep track of so much information. This might help my fellow teachers do the same.
Wikispaces Offers a Helpful Back to School Kit
Wikispaces, the popular and free wiki platform, has just released a new back to school kit for teachers. The kit includes a series of Google Slides presentations that offer step-by-step directions for every aspect of creating a classroom wiki through Wikispaces. The Wikispaces back to school kit also includes printable directions to distribute to students.


Keep learning. (NOTE: Not all of these are free)
9 Places To Find High-Quality Online Professional Development
Intel Teach Elements offers online continuing education courses for teachers that focus specifically on technology in 21st century classroom topics.
Modern Lessons is a free online learning platform designed for teachers and students looking to bolster their existing technology skills
PBS Teacherline offers a wide variety of online courses for teachers, many of which can earn you credit depending on how you choose to enroll in the class.
Annenberg Learner offers a wide variety of online courses and workshops that can count for continuing education credit, or in some cases, graduate credit
ScholasticU is the online PD for teachers arm of education giant Scholastic.
The Library of Congress offers its ‘Teacher Modules’ for free online. The courses are geared towards helping teachers learn how to use the huge collection of resources available from the Library.
ASCD offers over a hundred online courses in professional development for educators
Teachers First offers free courses in two formats – live sessions and pre-recorded sessions – on a variety of educational topics.


Classes I should learn to teach?
Six Classes Your Employer Wishes You Could Take
School is back amid growing controversy and cynicism. The quality, validity and economic value of college degrees and MBAs have rarely been under such sustained assault. Employability of graduates has never been so dismal. Machines are clearly getting smarter at many of the things people traditionally do on the job. That means people need to become non-traditionally smarter at things machines are not quite yet ready to think about or do. And that means educators worldwide must revisit how they want to make their most important product — their students — more valuable.
Multimedia Editing. Increasingly, knowledge workers won't simply be creating or generating information but assembling, reorganizing and prioritizing information from others. In other words, they'll be editing.
Scenarios. In addition to knowing how to create a compelling narrative out of reams of data, there will be a premium paid to those who can paint vivid pictures of possible tomorrows.
Fantasy Sports Competition. Understanding probabilities, statistics and analytics is increasingly vital to identifying and effectively managing high performing talent.
Reverse Engineering. This class looks at what makes experiments, inventions and artifacts tick and then takes them apart and rebuilds them. In other words, this is a hands-on class where students gain knowledge and skill by seeking to replicate and recreate things that work.
Comparative Coding. Another blog on this site asks, "Should MBAs Learn to Code?" Alas, that's exactly the wrong question. The better question is: What aspects of coding should MBAs (and university students) learn?
Cooking Science & Technology. Another hands-on course integrating fundamental scientific principles with real-world knowledge challenges students to transform their understanding of food.

Thursday, September 05, 2013

What stopped them? A sudden outbreak of logic? I doubt it was the privacy complaints they received.
David Kravets reports:
Following complaints from privacy groups, California lawmakers on Friday suspended legislation to embed radio-frequency identification chips, or RFIDs, in its driver’s licenses and state identification cards.
The legislation, S.B. 397, was put on hold by the state Assembly Appropriations Committee, despite it having been approved by the California Senate, where it likely will be re-introduced in the coming months.
Read more on Threat Level.
[From the article:
Michigan, New York, Vermont and Washington have already begun embedding drivers licenses with the tiny transceivers, and linking them to a national database — complete with head shots — controlled by the Department of Homeland Security. The enhanced cards can be used to re-enter the U.S. at a land border without a passport.


Is this the first “NSA's search is unconstitutional” defense?
AP reports:
A federal judge in a Chicago terrorism case has undone a key ruling saying the government needn’t divulge whether its investigation relied on expanded phone and Internet surveillance programs.
Adel Daoud denies trying to ignite what he thought was a bomb in Chicago. But if agents used the programs, he says they violated protections against unreasonable searches.
Read more on Chicago Sun-Times.
[From the article:
Prosecutors argued they won’t use evidence derived directly from expanded surveillance at the 19-year-old’s trial, so aren’t required to disclose if they relied on the programs.
Judge Sharon Johnson Coleman sided with prosecutors last week. But this weekend, she took the rare step of vacating her ruling when the defense complained it was premature.
By doing so, she reopens the matter to further debate.

(Related) At least, grab the manuals...
Web Resource Documents Latest Firestorm over NSA
“Recent press disclosures about National Security Agency (NSA) electronic surveillance activities — relying on documents provided by Edward Snowden — have sparked one of the most significant controversies in the history of the U.S. Intelligence Community. Today, the nongovernmental National Security Archive at The George Washington University posts a compilation of over 125 documents — a Web resource — to provide context and specifics about the episode. The Snowden leaks have generated broad public debate over issues of security, privacy, and legality inherent in the NSA’s surveillance of communications by American citizens. Furthermore, news coverage has explored the story on many levels, from the previously unknown scope of the NSA’s programs, to public and congressional reactions, to Snowden’s personal saga, including his attempts to evade U.S. authorities and avoid extradition to the United States. Today’s posting covers the full range of these topics, featuring documents from the White House, the Office of the Director of National Intelligence (ODNI), and the NSA itself, among other sources. The records include:
  • White House and ODNI efforts to explain, justify, and defend the programs
  • Correspondence between outside critics and executive branch officials
  • Fact sheets and white papers distributed (and sometimes later withdrawn) by the government
  • Key laws and court decisions (both Supreme Court and Foreign Intelligence Surveillance Court)
  • Documents on the Total Information Awareness (later Terrorist Information Awareness, or TIA) program, an earlier proposal for massive data collection
  • Manuals on how to exploit the Internet for intelligence.


Nothing really new.
Kashmir Hill has a disturbing follow-up to a report she did about how someone easily hacked into a baby monitor and said lewd things that the baby and homeowner could hear.
Shodan crawls the Internet looking for devices, many of which are programmed to answer. It has found cars, fetal heart monitors, office building heating-control systems, water treatment facilities, power plant controls, traffic lights and glucose meters. A search for the type of baby monitor used by the Gilberts reveals that more than 40,000 other people are using the IP cam–and may be sitting ducks for creepy hackers.
“Google crawls for websites. I crawl for devices,” says John Matherly, the tall, goateed 29-year-old who released Shodan in 2009. He named it after the villainous sentient computer in the videogame System Shock. “It’s a reference other hackers and nerds will understand.”
Read more on Forbes.
And yes, Shodan actually has a privacy policy. But only, it seems, for those using their search engine. Not for those whose devices might be exposed as sitting targets.

(Related) No massive fine, but they promise to be good in the future.


This translates into a request to stop making money on user information.
Vindu Goel reports:
A coalition of six major consumer privacy groups has asked the Federal Trade Commission to block coming changes to Facebook’s privacy policies that they say would make it easier for the social network to use personal data about its users, including children under 18, in advertising on the site.
In a letter sent to the agency late Wednesday, the coalition said Facebook’s changes, scheduled to go into effect later this week, violate a 2011 order and settlement with the F.T.C. over user privacy.
“Facebook users who reasonably believed that their images and content would not be used for commercial purposes without their consent will now find their pictures showing up on the pages of their friends endorsing the products of Facebook’s advertisers,” the letter says. “Remarkably, their images could even be used by Facebook to endorse products that the user does not like or even use.”
Read more on NY Times.

(Related) Dilbert explains why you need to be careful online...


Pew says, Many believe Privacy is impossible?
Anonymity, Privacy, and Security Online
A new survey finds that most internet users would like to be anonymous online, but many think it is not possible to be completely anonymous online.
Read Full Report


Once again, Stanford Law follows the lead of the Privacy Foundation.
The Stanford Law Review Online has just published a Symposium of articles entitled Privacy and Big Data. Here are the contents:
via Concurring Opinions


A scholarly Blog post. Just like all of mine...
Ari Waldman is guest-blogging on Concurring Opinions. By way of introduction, he writes:
… My research is on the law and sociology of privacy and the Internet, but I am particularly concerned with the injustices and inequalities that arise in unregulated digital spaces. This was the animator of my previous work on bullying and cyberharassment of LGBT youth. This month, I would like to speak more broadly about how sociologists (I am completely my Ph.D. in sociology at Columbia U) talk about privacy and, by the end of the month, persuasively argue that we — lawyers, legal scholars, sociologists, psychologists, economists, philosophers and other social scientists and theories — are, for the most part, thinking about privacy too narrowly, too one-dimensionally, too pre-Internet to adequately protect private interests, whatever they may be.
Read more on Concurring Opinions.


If I had gone for a PhD, my dissertation would have addressed “change.” It's a topic that truly fascinates me.
The More Things Change, the More Our Objections to Change Stay the Same
One of the very first articles in the very first issue of Fast Company, a magazine I started 20 years ago with Alan Webber, is a smart and entertaining list compiled by E.F. Borisch, product manager at a long-established outfit called Milwaukee Gear Company. Borisch's article was titled, "50 Reasons Why We Cannot Change," and it offered a clever and entertaining collection of objections to and worries about the hard work of making real progress. Reason #1: "We've never done it before." Reason #4: "We tried it before." Reason #13: "Our competitors are not doing it." Reason #17: "Sales says it can't be done." Reason #18: "The service department won't like it." Reason #45: "We're doing all right as it is." Reason #50: "It's impossible."
Now here's the punch line: E.F. Borisch compiled his list back in 1959, and published it in an obscure journal called Product Engineering. What we found so amazing about the list when we reprinted it in 1993 — and what remains just as amazing 20 years later — is that most leaders in most organizations face precisely the same set of worries and pushbacks today.


Eventually, for all of my students. This is where we are headed. (and this is an OLD idea)
Should Higher Education Be Free?
… How long can a business model succeed that forces students to accumulate $200,000 or more in debt and cannot guarantee jobs — even years after graduation? We need transformational innovations to stop this train wreck.
… According to Rafael Reif, MIT's president, who spoke at the Davos conference this past January, there are three major buckets that make up the total annual expense (about $50,000) of attending a top-notch university such as MIT: student life, classroom instruction, and projects and lab activities.
There is a significant opportunity to help reduce the lecture portion of expenses using technology innovations.
According to the American Institute of Physics (PDF), as of 2010, there are about 9,400 physics teachers teaching undergraduates every September in the United States. Are all of these great teachers? No. If we had 10 of the very best teach physics online and employed the other 9,390 as mentors, would most students get a better quality of education? Wouldn't that lead to lower per unit cost per class?


For my creative students
– is the perfect online video tool, that allows you to easily make animation videos for your product demo, presentations, teaching lessons, or just to have some fun. It has never been so intuitive to create an online video. With Wideo anyone can make cool videos. Personalize your Wideo by using your own images, logos, pictures and sounds. Publish or unpublish your wideos to make them public or private.

(Related) In case that got your creative juices flowing... (and it's free)
Start Creating Games In No Time With Unity3D Free
… There are plenty of free game development tools out there and many of them are super easy to use. However, for the longest time, game development tools suffered from one huge problem: limitations. When you code a game from scratch, you have absolute freedom to do whatever you want. When you use a creation tool, you’re limited to what that tool can do. That issue, however, is quickly becoming a moot point thanks to Unity3D.
… But Unity3D is more than just a codebase – it’s a full-featured environment complete with hundreds of tools that aid in rapid game development.
Lots of Tutorials. Because Unity3D is so popular, there are plenty of resources out there for helping you get started. The official website has a few basic guides. After that, you can explore user-created tutorial series such as Unity Cookie, UnityScript Basics, GamerToGameDeveloper, and more.


For the rest of my students... If this ever includes source code it could be very useful.
– Download abandonwares (games which have been abandoned by its developer), from 1980 to 2002. Find the sensations of your elders, Nostalgia, Discovery, Emotion, Curiosity, you’re a player or a collector, all the old history of video games will be at your fingertips. On My abandonware you can download all the old video games from 1980 to 2002 for free.


Infographic and translation guide.
All The Text Message Acronyms You Ever Wanted To Know


Resources as well as grants.
4 Resources For Finding STEM Grants For Your School


This is cute.
NFL 2013-2014 season salaries by team and position – interactive

Wednesday, September 04, 2013

Strange as it may seem, this is part of “We listen to everything.”
I can almost hear Bob Dylan singing, “Everybody must get surveilled.” Well, not really, but you know what I mean.
The US National Security Agency spied on emails, phone calls and text messages of the presidents of Brazil and Mexico, a Brazilian news programme has reported.
The report by Globo’s news programme Fantastico was based on documents that Guardian journalist Glenn Greenwald obtained from former NSA contractor Edward Snowden.
Read more on RTÉ.


For my Ethical Hackers: Told ya!
How the US Could Cyber Attack Syria, Too
Over the weekend, President Obama announced that he would seek Congressional approval for a strike on Syria, and immediately began a "lobbying blitz" to bolster public and political support for intervention. But Obama needs no such approval from Congress for a cyber strike. [Why do they think that is so? Bob] And according to both Foreign Policy magazine and The Washington Free Beacon, some form of cyber attack on Syria will accompany a missile strike, if it isn’t happening already.
The relatively new US Cyber Command will be testing out new cyberwar capabilities, military sources told the Free Beacon, with Syrian targets including the “electronic command and control systems used by the Syrian military forces, air defense computers, and other military communications networks.”


I think I'm seeing a general trend to view poor security as negligence. Interesting.
It seems it isn’t all over for a lawsuit by nine financial institutions against Heartland Payment Systems following a mammoth breach disclosed in January 2009. The Fifth Circuit Court of Appeals reversed the district court’s dismissal of negligence claims and remanded. Here’s part of the opinion, issued yesterday:
Turning to the case sub judice, we hold the economic loss doctrine under New Jersey law does not preclude the Issuer Banks’ negligence claim against Heartland at the motion to dismiss stage. First, the Issuer Banks constitute an “identifiable class” as contemplated by People Express. 495 A.2d at 116. Heartland had reason to foresee the Issuer Banks would be the entities to suffer economic losses were Heartland negligent. See id. The identities, nature, and number of the victims are easily foreseeable, as the Issuer Banks are the very entities to which Heartland sends payment card information. See id. Furthermore, Heartland would not be exposed to “boundless liability,” but rather to the reasonable amount of loss from a limited number of entities. Id. Accordingly, even absent physical harm, Heartland may owe the Issuer Banks a duty of care and may be liable for their purely economic losses. See id.; Carter Lincoln-Mercury, Inc., Leasing Div. v. EMAR Grp., Inc., 638 A.2d 1288, 1294 (N.J. 1994) (holding economic loss doctrine no bar to tort claim regardless of physical harm “if the plaintiff was a member of an identifiable class that the defendant should have reasonably foreseen was likely to be injured by the defendant’s conduct” (citing People Express, 495 A.2d at 116)).
Second, viewing the pleadings in the light most favorable to the Issuer Banks, in the absence of a tort remedy, the Issuer Banks would be left with no remedy for Heartland’s alleged negligence, defying “notions of fairness, common sense and morality.”
The court declined Heartland’s urging to uphold the district court’s dismissal on any one of four grounds, sending the case back to the district court to consider:
Heartland asserts that even if it owes the Issuer Banks a duty of care under People Express and the economic loss doctrine does not bar the Issuer Banks’ negligence claim at this stage of the litigation, we should affirm the district court on any of four grounds: (1) the Issuer Banks are bound by the allegation in their complaint that Heartland has contracts with Visa and MasterCard, so they should be limited to the contractual remedies available through the Visa and MasterCard networks; (2) Texas law, not New Jersey law, is controlling; (3) the Issuer Banks fail to state a claim under Federal Rule of Civil Procedure 8(a); and (4) some of the Issuer Banks are collaterally estopped from pursuing this negligence claim because the district court’s disposition of their separate claim against the Acquirer Banks involved the same issue. Though “[w]e are free to uphold the district court’s judgment on any basis that is supported by the record,” Zuspann v. Brown, 60 F.3d 1156, 1160 (5th Cir. 1995), we decline to decide these complex issues as they are better addressed by the district court in the first instance. See U.S. ex rel. Branch Consultants v. Allstate Ins. Co., 560 F.3d 371, 381 (5th Cir. 2009) (remanding so district court can consider issues in first instance) (citing Breaux v. Dilsaver, 254 F.3d 533, 538 (5th Cir. 2001) (“Although this court may decide a case on any ground that was presented to the trial court, we are not required to do so.”)).
You can access the full opinion here (pdf, 10 pp.).


The latest episode. It may further complicate extradition if he is elected.
Kim Dotcom exits Mega post to follow other pursuits
Kim Dotcom is resigning from data storage provider Mega in order to focus on his extradition case and political aspirations.
The New Zealand Herald reports that the flamboyant director of Mega resigned August 29 and was replaced by Hong Kong-based Bonnie Lam the same day, according to Companies Office filings.
… Earlier this month, Dotcom told his Twitter following that he planned to follow political aspirations and launch a political party in New Zealand. The 39-year-old plans to contest in next year's elections, campaigning to improve the country's IT infrastructure and push for "fair Internet pricing and no more data caps."
… Federal agencies seized and shut down the file-sharing service at the beginning of 2012, which caused outrage after leaving millions of users stranded without access to their files, some of which were legitimately stored on the service.
Kumar says that the Mega service currently accounts for over 4 million users, a few thousand of whom are paid customers.
… Mega is built around security and fully encrypted file sharing rather than storing and sharing IP infringing material, Kumar said. To this end, the "privacy company" is developing secure e-mail services to run on its entirely non-U.S.-based server network in order to replace Lavabit, a secure email service which has recently closed down.
The Mega founder is currently battling a case brought forward by US authorities to extradite him. DotCom may have to wait until next year for the hearing, which will decide whether Dotcom will be extradited to the United States, where he is wanted on charges of copyright infringement and money laundering through the Megaupload service.
The original hearing date was scheduled for last August, but complications and confusion around legal arguments have continually delayed the case.
The high-profile case resulted in an overhaul of New Zealand's Government Communications Security Bureau (GCSB). The agency was found to have unlawfully spied on Dotcom's activities as he had been granted residency. Recently, New Zealand police said that they will not charge anyone in the agency for illegally spying, because there was "a lack of criminal intent."


Now all I need to do is convince the wife.
FREE MANUAL: Cut That Cord! How To Ditch Cable
We’ll show you all of your best alternative options, including equipment and services to sign up for. Pretty soon, you will be rid of that cable TV bill and enjoying just as much great content as before.
You’ll learn about:
  • Why cutting the cord is a good idea
  • The free alternatives to cable TV
  • The nearly-free alternatives to cable TV
  • Alternatives to cable TV which cost a small amount
  • Devices and services to help you get great content
No password required. Web, PDF, EPUB and Amazon versions available.


For all my students
Get Paragon Drive Copy 12 Compact (PC) for free
… as with any storage upgrade, half the challenge lies in moving everything from old drive to new. Not many drives come with the software to aid in such a move.
Thankfully, there are third-party options, and for a very limited time, you can snag one gratis: Today only, BitsDuJour is offering Paragon Drive Copy 12 Compact (PC) for free. It normally sells for $29.95.
Update (9/4/13): Looks like the deal has been extended for a second day to accommodate users who weren't able to connect yesterday.


Also for all my students
The 70 Best Apps For Teachers And Students


We just purchased a pair of these for our students. Perhaps we should join this group?
… – So you bought an awesome 3D printer, but it’s sitting idly most of the time? Put it to good use by sharing it with those around you and make some extra cash along the way. 3d Hubs is an online community of 835 3D printers which are available if you want to print something. Just upload your design, choose a 3D printer, then go to collect your product.

Tuesday, September 03, 2013

Is this merely a continuation of the Ballmer era strategy or will we see “Skype phones?”
Microsoft to Buy Nokia’s Device Business in Deal Worth $7.17 Billion
Microsoft announced late Monday that it is buying the majority of Nokia’s cellphone unit for 3.79 billion Euros ($5 billion), and spending another 1.65 billion Euros ($2.18 billion) to license Nokia’s patent portfolio, for a total of 5.44 billion Euros ($7.17 billion).
… The move is a clear sign that Microsoft believes it can and must succeed in the phone business, and that it cannot afford to leave the success in the hands of a partner – even one like Nokia, that had bet its future on Microsoft’s phone software.

(Related)
How can they be so good?”: The strange story of Skype

(Related) Just for perspective, 7 Billion is cheap.
Verizon to pay Vodafone $130B for stake in Verizon Wireless
… The deal is the third largest corporate acquisition ever, behind Vodafone's $183 billion deal for Mannesmann AG in 1999 and AOL's $164 billion deal for Time Warner the next year. Under the terms of the deal announced Sunday, Verizon will pay $60.2 billion in stock and $58.9 billion in cash for Vodafone's 45 percent share.


More than target practice. Did Syria even notice? There is provocation and then there is an announcement of capabilities...
Israel Just Fired Missiles into the Mediterranean
With the entire world on edge over (possible) impending airstrikes on Syria, it seems that Israel decided to freak everyone out and start launching ballistic missiles into the sea.
Around 6:00 a.m. ET on Tuesday morning, Russian news services began reporting that Russian-based radar systems detected two ballistic "objects" over the Eastern Mediterranean Sea. With multiple U.S. warships already in the region, and Barack Obama threatening an attack on Syria, officials naturally wondered if this was the planned assault they were worried about. When nothing fell out of the sky on Damascus, it soon became apparent that whatever was shot into the air had fallen harmlessly into the water.


Probably less than Citibank spends on paperclips.
Back in June 2011, I noted a breach involving Citibank (previous coverage here and here). There’s now a follow-up to that breach:
Citibank N.A. will pay $55,000 to the state of Connecticut and will obtain a third-party data security audit of its online credit card account system under a settlement filed in court today, Attorney General George Jepsen has announced.
The settlement comes after a joint investigation with the California Attorney General’s Office revealed that a known technical vulnerability in Citibank’s Account Online Web-based service permitted hackers to access multiple user accounts. Hackers accessed account information through Account Online by logging in with an account number and password, and then modifying a few characters in the resulting Universal Resource Locater (URL) bar in a browser in order to access additional accounts. This vulnerability was known to the company at the time of the breach and may have existed since 2008.
Citibank discovered that Account Online had been breached on May 10, 2011, but did not permanently fix the vulnerability until May 27, 2011, and did not begin notifying affected customers until June 3, 2011. Account information for more than 360,000 Citibank customers, including about 5,066 Connecticut residents, was accessed or obtained by hackers.
“Citibank represented to its customers that its online system was secured, but ultimately the techniques hackers used to obtain individual account information were relatively simple and unsophisticated,” Attorney General Jepsen. “This settlement not only ensures that Citibank will be responsive to its customers should this system experience a breach in the future, it also requires the company to review and audit its security protocols.”
… The settlement is not final until approved by the court.
Please click here to view the complaint and the settlement documents.
The settlement does not contain any admission of liability or guilt on Citibank’s part.
SOURCE: Attorney General Jepsen


My Math topic this week is Probability. What are the odds that this is the only company that ever did this? (Other than Big Brother in 1984)
Valerie Vlasenko reports:
TP Vision is a joint venture based in Amsterdam, the Netherlands, which develops, manufactures and markets Philips branded TV sets in Europe, Russia, the Middle East, Brazil, Argentina, Uruguay, Paraguay and selected countries in Asia-Pacific.
In 2012 TP Vision made statements about their monitoring the use of Philips branded smart TVs in the Netherlands, such as
“60% of our active users switch on their television more than 50 times a month”.
The Dutch Data Protection Authority started an investigation into TP Visions collection and handling of usage data.
Not surprisingly, they were found to be in violation:
TP Vision used cookies and logfiles in order to monitor the users behavior – the programs, which the users were watching, the websites they were visiting and the apps they used for that, and intended to offer personalized ads to its customers. However TP Visions did not ask their prior permission to these actions. Moreover the company did not inform their customers about such monitoring, providing them with insufficient information about processing their personal data.
Read more on Legal Artviser.


Would this be legal in the US? (If providers could charge for it, they would do it)
Juliette Garside reports:
Broadband providers are being asked to create a database of customers illegally downloading music, films and books, which could be used to disconnect or prosecute persistent offenders.
Measures to combat digital piracy will be among the topics discussed at a Downing Street breakfast on 12 September, when record-label bosses and their trade association, the BPI, have been invited to meet David Cameron.
BT, Virgin Media, BSkyB and TalkTalk are being asked by music and film companies to sign up to a voluntary code for policing illegal downloading.
Read more on The Guardian.
So BPI wants to make broadband providers their agents for purposes of identifying and stopping illegal downloads? I don’t see how they can do that under the Data Protection Act there, but I’m no lawyer. I only hope the providers do not agree to create such records or databases at the BPI’s behest.


Attention Ethical Hackers: I want one. Let's discuss extra credit...
Dan Goodin reports:
Recently leaked brochures advertising next generation spy devices give outsiders a glimpse into the high-tech world of government surveillance. And one of the most tantalizing of the must-have gizmos available from a company called GammaGroup is a body-worn device that surreptitiously captures the unique identifier used by cell phones.
“The unit is optimized for short range covert operation, designed to allow users to get close to Target(s) to maximize the changes of only catching the Target(s’) identities and minimal unwanted collateral,” one of the marketing pamphlets boasts. “The solution can be used as a standalone device or integrated into wider data-gathering and geo-tracking systems.”
Read more on Ars Technica.


“Governments don't do a good job, so we want to be your government?”
Australia – The Coalition’s Policy for E-Gov and Digital Economy
“One of the Coalition’s core principles is a preference for markets, because markets typically produce better outcomes than governments. But government can play a valuable leadership role in the economy, particularly in periods of structural change. If elected, a Coalition government intends to play such a leadership role in driving Australia’s transition to a digital economy and recognising the importance of prioritising investments in ICT. The centrality of ICT to productivity, innovation and growth is beyond dispute: it shows up in the data, in business and in our everyday lives. McKinsey Global Institute has calculated around a fifth of GDP growth in advanced economies over the past five years has arisen from the Internet and associated technologies – with 75 per cent of this growth occurring in sectors not traditionally seen as ‘technology’ industries.”


A major benefit (or downside) of Big Data?
New on LLRX – Will Data Analytics Allow Us to “Do Less Law?”
Ron Friedmann is an expert on the legal market, where hardly a day goes by without an article or blog post about alternative fee arrangements (AFA) or delivering more value. Yet both clients and law firms struggle to define value and adopt alternatives to the billable hour, so Ron proposes perhaps the time has come to re-think the question.


For my students who don't have time to read an article, but can sit and watch a video...
– Two of the top sites on the Internet today are YouTube and Wikipedia. Together, they provide lots of entertainment and information. But what if you could combine both sites, so that relevant YouTube videos appear on Wikipedia pages? Well, that’s what WikiTube does.

Monday, September 02, 2013

In the highly polarized Washington of today, asking Congress to take a stand is smart and sad at the same time. Smart because failure to support the President will require explaining why we should allow more gassing of civilians. Sad because apparently vacation time is more important than resolving the issue.
Congressional Authorizations of War: A Brief History
Via The Atlantic: All the Previous Declarations of War – Congress has formally declared war only 11 times in U.S. history, and authorized the use of military force 11 times. “As we head into a period of vigorous congressional debate over whether to authorize the use of force against Syria, it’s instructive to look back at America’s history of congressional war declarations. The Congressional Research Service put together a great mini-history in 2011, “Declarations of War and Authorizations for the Use of Military Force: Historical Background and Legal Implications,” by Jennifer Elsea and Richard Grimmett, which is worth a read at this juncture.”


I bet those NETWARCOM guys have been doing this for years.
Richard Chirgwin reports:
It’s easier to identify TOR users than they believe, according to research published by a group of researchers from Georgetown University and the US Naval Research Laboratory (USNRL).
Their paper, Users Get Routed: Traffic Correlation on Tor by Realistic Adversaries, is to be presented in November at November’s Conference on Computer and Communications Security (CCS) in Berlin. While it’s been published at the personal page of lead author Aaron Johnson of the NRL, it remained under the radar until someone posted a copy to Cryptome.
Read more on The Register.


For my Computer Security students.
Phishing Activity Trends Report
“The APWG Phishing Activity Trends Report [published July 23, 2013] analyzes phishing attacks reported to the APWG by its member companies, its Global Research Partners, through the organization’s website, and by e-mail submissions to reportphishing@antiphishing.org. APWG also measures the evolution, proliferation , and propagation of crimeware by drawing from the research of our member companies. The APWG also tracks the number of unique phishing websites. This is now determined by the unique base URLs of the phishing sites. (A single phishing site may be advertised as thousands of customized URLS, all leading to basically the same attack destination.) APWG additionally tracks crimeware instances (unique software applications as determined by MD5 hash of the crimeware sample), as well as unique sites that are distributing crimeware (typically via browser drive-by exploits). The APWG Phishing Activity Trends Report also includes statistics on rogue anti-virus software, desktop infection rates, and related topics.”


I doubt it is an error in translation. Facebook is all about your face!
Loek Essers reports:
A German privacy regulator is astonished that Facebook has added facial recognition to a proposed new privacy policy it published on Thursday.
“It is astonishing to find the facial recognition again in the new proposed privacy policy that Facebook published yesterday. We therefore have directly tried to contact officials from Facebook to find out if there is really a change in their data protection policy or if it is just a mistake of translation,” Hamburg Commissioner for Data Protection and Freedom of Information Johannes Caspar said in an email on Friday.
Read more on PC World.


We know that, but it never hurts to remind the clueless... (See Big Data below)
Devin Coldewey reports:
Everywhere you go, your phone is sending out signals that can be assembled to form a picture of your movements. You can’t turn them off, and companies have begun to pick them up, often without any indication that they’re doing so. As this trend develops, smartphones could spell the end of real-world privacy.
“It’ll get worse before it gets better,” mobile industry expert Chetan Sharma told NBC News. “Unless leaders step up and work on a framework that works for all consumers, it’s going keep getting worse and worse until it is unbearable.”
Read more on NBC News.

(Related) ...and your pulse rate, blood pressure, etc.
Twenty of the most popular health apps transmit information – usually without user knowledge – to a web of nearly 70 companies, according to research conducted by Evidon for Financial Times. Read more here (sub. required).


Somehow I think this is going to be difficult to follow.
UK Surveillance camera code of practice comes into force
“The code sets out guidelines for CCTV and Automatic Number Plate Recognition (ANPR) systems to ensure their use is open and proportionate and that they are able to capture quality images that give police a better chance to catch criminals and cut crime. It follows Andrew Rennison’s appointment as the first surveillance camera commissioner last year. The commissioner will encourage all operators to comply with the code and report back to parliament with any concerns. Crucial tools - The principle of surveillance by consent is at the heart of the new legislation – meaning the public can be confident cameras are not there to spy on them but to protect them.” August 12, 2013.


How to avoid controversy? Pass the buck!
Joseph Goedert reports:
The Centers for Medicare and Medicaid Services, in a final rule setting standards for health plans operating in state health insurance exchanges, has dropped a proposed requirement that privacy and security incidents be reported within one hour of discovery, while at the same time noting it is still required by other regulations.
Read more on HealthData Management.
[From the article:
CMS noted that many commenters to the proposed rule issued in June found the one-hour provision to be not practical or workable. But, while dropping the provision, what CMS decided to do in the final rule may not be much of a change. CMS apparently decided the provision wasn’t needed because it’s already in existing legal agreements.


Data is gathered on a “We can, therefore we must” basis, but there is still a “Now what can we do with it” question to be answered.
Accenture – Data Monetization in the Age of Big Data
Monetizing Big Data is on the mobile operators’ agenda. Mobile operators want to know how to harness the potential of Big Data. They are talking about when and how to sort, analyze and manipulate the data to put it to use. In today’s climate of convergence, in which new technologies and networks are blurring industry lines, the mobile phone has become the hub of insight into consumer behavior. The volume and richness of the data now uniquely accessible to mobile operators offers a veritable gold mine of insights and applications. And even as mobile phones have become the primary device through which consumers get their information; those very same devices have begun to facilitate new types of information, including extremely precise, real-time, geolocation information.”


Something for my multi-platform students.
Manage eBooks and webtexts in one place. Read ePubs and webtexts in one reader. Import RSS feeds. Collaborate, discover, and share. Share your highlights and comments. See what your friends are reading. Create an archive of your read knowledge. Organize and archive all your texts. Find your thoughts and favorite passages quickly.

Sunday, September 01, 2013

Roughly the same as one Ethical Hacking course. Are they bragging or complaining? How does this stack up to China or North Korea?
U.S. spy agencies mounted 231 offensive cyber-operations in 2011, documents show
U.S. intelligence services carried out 231 offensive cyber-operations in 2011, the leading edge of a clandestine campaign that embraces the Internet as a theater of spying, sabotage and war, according to top-secret documents obtained by The Washington Post.
That disclosure, in a classified intelligence budget provided by NSA leaker Edward Snowden, provides new evidence that the Obama administration’s growing ranks of cyberwarriors infiltrate and disrupt foreign computer networks.
Additionally, under an extensive effort code-named GENIE, U.S. computer specialists break into foreign networks so that they can be put under surreptitious U.S. control. Budget documents say the $652 million project has placed “covert implants,” sophisticated malware transmitted from far away, in computers, routers and firewalls on tens of thousands of machines every year, with plans to expand those numbers into the millions.

(Related) I'll repeat, what part of “We listen to everything” did you not understand? (Are you part of everything?)
Snowden Document: NSA Spied On Al Jazeera Communications


Business opportunities?
The Current YouTube Economy Is In Peril
… YouTube has massive potential to revolutionize the entertainment industry and redefine storytelling, but in order to do that, the industry has to first start making money. This can happen by either YouTube charging less money for its services and the arrival of a competitor, or big brands injecting capital.
If neither of these happens soon, much of "new Hollywood" could go out of business. And maybe that's not such a bad thing.


Brief but interesting. Can't wait to see how this works out.
What Does A Totally Technology-Centric School Look Like?


If you are a movie nut, this is too cool! If you're a regular nut, think what other industries or topics would benefit from collections like this...
– is a non-profit initiative dedicated to digitizing collections of classic media periodicals that belong in the public domain for full public access. The project is supported by owners of materials who loan them for scanning, and donors who contribute funds to cover the cost of scanning. They have currently scanned over 800,000 pages, and the number is growing.


For all my students, who need it almost as much as I do...
Grammarly – automated proofreader and personal grammar coach
Grammarly is an automated proofreader and your personal grammar coach. Correct up to 10 times more mistakes than popular word processors.” This is for use in addition to Microsoft® Word – it “scans your text for proper use of more than 250 advanced grammar rules, spanning everything from subject-verb agreement to article use to modifier placement.”


For my students with desktop, laptop, ipad, and smartphone. Simple backup tool!
– Want to share and sync files on the go? BitTorrent Sync lets you share files with family and friends, share files between mobile devices, and backup your phone and tablets. Sync files between mobile devices, collaborators, or your home and work PC. When you create a new folder secret, a QR code will be generated. Scan and share this QR code to easily sync files between mobile devices.