Tuesday, June 10, 2014

For my Computer Security students.
Free Python Script Detects MitM Vulnerability in OpenSSL
Tripwire has released a free Python script that’s designed to help organizations determine if their servers are affected by the recently patched Man-in-the Middle (MitM) vulnerability in OpenSSL.
… The OpenSSL CCS Inject Test Script is available for download on Tripwire’s website.


For anyone living under a rock.
For Sale: Practically All the Details of Your Personal Life
… The Federal Trade Commission (FTC) recently published the report Data Brokers: A Call for Transparency and Accountability. It’s an eye opener for anyone who thinks they lead a private life. Companies known as data brokers collect and sell just about every kind of data point about your life, and it goes far beyond what the NSA is doing with phone calls and emails.


Here's the report I blogged about yesterday.
Net Losses: Estimating the Global Cost of Cybercrime


At least someone is thinking about the future.
Preparing for the Internet of Things
What are you doing to prepare for the Internet of Things in your company? How are you going to handle connectivity of the new internet-enabled "things"? How will you handle the new bandwidth requirements from network-hungry devices? Are you prepared for the amount of storage required to maintain those devices? What about security concerns for new devices? And, how will you handle the significant amount of device and user management that's coming your way?
You might not know the answers to any of these questions, but fortunately, you have colleagues who at least have taken their best guesses at it. In a recent survey of 440 IT professionals in North America and EMEA, Spiceworks has compiled some surprising results.

1. Most IT pros agree that IoT will impact consumers in addition to the workplace. In fact, the vast majority believes the trend will pose significant security and privacy issues.
2. Even so, more than half say they aren’t doing anything specific to brace their infrastructure for the coming impact of IoT.
3. Despite the divide between belief and targeted action, it turns out the future is now. Our survey found that many IT pros are already doing things that’ll help support IoT – even if they aren’t thinking of them in that context. But chances are…they should be doing more.

(Related) Your car is several “Things.”
An editorial in the L. A. Times includes:
It’s easy to say that no one has a reasonable expectation of privacy when driving on the streets or parking in a public place. But changing technology — especially the digitizing of license plate photographs and an almost endless storage capacity — has dramatically widened the window through which police can track an individual’s comings and goings.
Like GPS technology, which allows police to track the movements of suspects through their cars and telephones, the proliferation of license plate scanners demonstrates the need to adapt traditional notions of privacy to new and invasive technologies. The American Civil Liberties Union has proposed several recommendations to protect privacy: Police must have reasonable suspicion that a crime has occurred before examining collected license plate data; citizens should be able to find out if data about their license plate are contained in a database; license plate data should be deleted after a short period to avoid fishing expeditions; and law enforcement shouldn’t share such data with third parties that don’t adhere to these protections.
Read more on L.A. Times.


Long article.
10 Powerful Facts About Big Data
Most companies estimate they're analyzing a mere 12% of the data they have, according to a recent study by Forrester Research.


For my students and not just the Trekies...
George Takei Explains Technology & The Internet In Takei’s Take [Stuff to Watch]
There are many reasons to admire George Takei: his much-loved role as Mr Sulu in Star Trek, his dedicated work as a gay rights activist and his efforts to improve Japanese-American relations. But now we have another reason: Takei’s Take on YouTube.
Produced in part by the AARP, George separates fact from fiction and explains some of the latest trends, buzz-words and technologies in short, easily consumable videos.
… Last week’s Stuff to Watch was all about 2014′s Webby winners – and George was one of them, for this very show.

Monday, June 09, 2014

Measuring the “harm” of a security breach.
PayTime Data Breach Hits Some Workers Hard
When we think about consequences of hacks or breaches, let’s not lose sight that people may lose their jobs simply because their data was caught up in an incident – even if there was no evidence that their information was misused. idRADAR.com has a good example of that in the aftermath of the PayTime hack. They previously reported other examples of how becoming a victim of hack can cost security clearance and/or jobs, with a follow-up on one such case.


I don't think I'd put it that way. Still, some interesting assertions.
Upsurge in hacking makes customer data a corporate time bomb
… The reality, cyber security experts say, is that however much they spend, even the largest companies are unlikely to be able to stop their systems being breached. The best defense may simply be either to reduce the data they hold or encrypt it so well that if stolen it will remain useless. [Or take most of it off-line? Bob]
… A report from cyber security think tank the Ponemon Institute showed the average cost of a data breach in the last year grew by 15 percent to $3.5 million. The likelihood of a company having a data breach involving 10,000 or more confidential records over a two-year period was 22 percent, it said.
… Still, a study of 102 UK financial institutions and 151 retail organizations conducted earlier this year by Tripwire showed 40 percent said they would need 2 to 3 days to detect a breach.


So, if I search for information on a company and Google indicates they have “something to hide,” I will expand my search by using search engines that do not comply with the EU rule. Or I may just not invest in that company. (Imagine the impact on politicians!)
Google may soon let you know when it’s required to hide something from you
A European Union court recently ruled that Google must respect the EU’s “right to be forgotten” and remove links to web pages that individuals find embarrassing.
Now, the Guardian reports, Google may soon add a note to its edited search results, indicating that something is missing.
Google already does this with pages from which it’s removed search results in response to DMCA takedown requests, usually as a result of alleged copyright violations.


Interesting idea. Automate the Privacy Policy review. (Maybe I see it as an Audit tool because of 35 years of auditing?)
Bootstrapping Privacy Compliance in Big Data Systems
by Sabrina I. Pacifici on June 8, 2014
“In this paper, we demonstrate a collection of techniques to transition to automated privacy compliance compliance checking in big data systems. To this end we designed the LEGALEASE language, instantiated for stating privacy policies as a form of restrictions on information flows, and the GROK data inventory that maps low level data types in code to highlevel policy concepts. We show that LEGALEASE is usable by non-technical privacy champions through a user study. We show that LEGALEASE is expressive enough to capture real-world privacy policies with purpose, role, and storage restrictions with some limited temporal properties, in particular that of Bing and Google. To build the GROK data flow grap we leveraged past work in program analysis and data flow analysis. We demonstrate how to bootstrap labeling the graph with LEGALEASE policy datatypes at massive scale. We note that the structure of the graph allows a small number of annotations to cover a large fraction of the graph. We report on our experiences and learnings from operating the system for over a year in Bing. — Shayak Sen (Carnegie Mellon University), Saikat Guha (Microsoft Research, India), Anupam Datta (Carnegie Mellon University), Sriram Rajamani (Microsoft Research, India), Janice Tsai (Microsoft Research, Redmond), and Jeannette Wing (Microsoft Research), Bootstrapping Privacy Compliance in Big Data Systems, IEEE Security and Privacy Symposium 2014, Best Student Paper (1 of 2) – See more at: https://www.cylab.cmu.edu/news_events/news/2014/ieee-sp-2014.html#sthash.eM6ZYdS3.dpuf”


Another programming inspired paper?
Location Tracking, Mosaic Theory, and Machine Learning
by Sabrina I. Pacifici on June 8, 2014
Enough is Enough - Location Tracking, Mosaic Theory, and Machine Learning - Steven M. Bellovin, Renée M. Hutchins, Tony Jebara, Sebastian Zimmeck. New York University Journal of Law & Liberty, vol 8:555, 2014.
“Since 1967, when it decided Katz v. United States, the Supreme Court has tied the right to be free of unwanted government scrutiny to the concept of reasonable expectations of privacy. An evaluation of reasonable expectations depends, among other factors, upon an assessment of the intrusiveness of government action. When making such assessment historically the Court has considered police conduct with clear temporal, geographic, or substantive limits. However, in an era where new technologies permit the storage and compilation of vast amounts of personal data, things are becoming more complicated. A school of thought known as “mosaic theory” has stepped into the void, ringing the alarm that our old tools for assessing the intrusiveness of government conduct potentially undervalue privacy rights. Mosaic theorists advocate a cumulative approach to the evaluation of data collection. Under the theory, searches are “analyzed as a collective sequence of steps rather than as individual steps.” The approach is based on the recognition that comprehensive aggregation of even seemingly innocuous data reveals greater insight than consideration of each piece of information in isolation. Over time, discrete units of surveillance data can be processed to create a mosaic of habits, relationships, and much more. Consequently, a Fourth Amendment analysis that focuses only on the government’s collection of discrete units of trivial data fails to appreciate the true harm of long-term surveillance — the composite. In the context of location tracking, the Court has previously suggested that the Fourth Amendment may (at some theoretical threshold) be concerned with the accumulated information revealed by surveillance. Similarly, in the Court’s recent decision in United States v. Jones, a majority of concurring justices indicated willingness to explore such an approach. However, in general, the Court has rejected any notion that technological enhancement matters to the constitutional treatment of location tracking. Rather, it has found that such surveillance in public spaces, which does not require physical trespass, is equivalent to a human tail and thus not regulated by the Fourth Amendment. In this way, the Court has avoided quantitative analysis of the amendment’s protections. The Court’s reticence is built on the enticingly direct assertion that objectivity under the mosaic theory is impossible. This is true in large part because there has been no rationale yet offered to objectively distinguish relatively short-term monitoring from its counterpart of greater duration. As Justice Scalia recently observed in Jones: “it remains unexplained why a 4-week investigation is ‘surely’ too long.” This article suggests that by combining the lessons of machine learning with the mosaic theory and applying the pairing to the Fourth Amendment we can see the contours of a response. Machine learning makes clear that mosaics can be created. Moreover, there are also important lessons to be learned on when that is the case… In five parts, this article advances the conclusion that the duration of investigations is relevant to their substantive Fourth Amendment treatment because duration affects the accuracy of the predictions. Though it was previously difficult to explain why an investigation of four weeks was substantively different from an investigation of four hours, we now have a better understanding of the value of aggregated data when viewed through a machine learning lens. In some situations, predictions of startling accuracy can be generated with remarkably few data points.”
See also a rebuttal of interpretations of this paper by Orin Kerr – No, machine learning doesn’t resolve how the mosaic theory applies

Sunday, June 08, 2014

Politicians, lawyers and marketing executives study semantics so they can do this well. (P. T. Barnum once sold a load of white fleshed salmon by advertising that they were guaranteed not to turn pink.)
I posted something about this previously, but Tim Cushing’s article is still worth reading:
James Clapper’s defense of leaked NSA programs have fallen into the “strictly legal + oversight” framework so often it’s become a cliche that can be ably wielded by lower level staffers. Occasionally, Clapper fires off something longer, like his defense of the NSA’s collection of French phone metadata. During this longer “debunking,” Clapper denied accusations that were never made by attacking a lousy translation of the original French article. This provided for some plausible deniability (“NSA does not collect recordings”), even if the underlying claims — correctly translated — pointed to something the agency was actually doing (bulk phone metadata collection).
The new head of the NSA, Michael Rogers, is doing the same thing.
Read more on TechDirt.
[From the article:
… no one suggested in the article that the NSA targeted US citizens. In fact, one of the biggest complaints about the NSA's programs is the fact that they're clearly untargeted. The NSA doesn't select a person and start the surveillance from that point. The surveillance is pervasive and ongoing and any selection tends to occur long after tons of data/communications have been collected. It's the after-the-fact nature of the programs that makes them so dangerous.


"Those who do not learn history are doomed to repeat it." (probably) George Santayana
From Washington’s Blog:
Spying has been around since the dawn of civilization.
Keith Laidler – a PhD anthropologist, Fellow of the Royal Geographical Society and a past member of the Scientific Exploration Society – explains:
Spying and surveillance are at least as old as civilization itself.
University of Tennessee history professor Vejas Gabriel Liulevicius agrees:
Espionage and intelligence have been around since human beings first began organizing themselves into distinct societies, cities, states, nations, and civilizations.
Unfortunately, spying hasn’t been limited to defense against external enemies. As documented below, tyrants have long spied on their own people in order to maintain power and control … and crush dissent.
Read more on Washington’s Blog.


About time someone revisited this...
Via Public Citizen: Chris Jay Hoofnagle and Jennifer M. Urban, both of Berkeley, have written Alan Westin’s Privacy Homo Economicus, 49 Wake Forest Law Review 261 (2014). Here’s the abstract:
Homo economicus reliably makes an appearance in regulatory debates concerning information privacy. Under the still-dominant U.S. “notice and choice” approach to consumer information privacy, the rational consumer is expected to negotiate for privacy protection by reading privacy policies and selecting services consistent with her preferences. A longstanding model for predicting these preferences is Professor Alan Westin’s well-known segmentation of consumers into “privacy pragmatists,” “privacy fundamentalists,” and “privacy unconcerned.”
… This Article contributes to the ongoing debate about notice and choice in two main ways. First, we consider the legacy Westin’s privacy segmentation model itself, which as greatly influenced the development of the notice-and-choice regime. Second, we report on original survey research, collected over four years, exploring Americans’ knowledge, preferences, and attitudes about a wide variety of data practices in online and mobile markets. Using these methods, we engage in considered textual analysis, empirical testing, and critique of Westin’s segmentation model.


Interesting. Is there much demand for lawyers in positions like this?
Last month, a report based on documents obtained by Edward Snowden uncovered an elaborate National Security Agency surveillance program that monitors every call made in the Bahamas. The island nation appears to have responded to those charges by retaining attorneys to work on “surveillance and privacy” issues.
According to disclosure documents obtained by The Hill, the government of the Bahamas has hired American law firm Hogan Lovells to represent it in a variety of cases. While the Bahamas has worked with the firm before, it added new responsibilities to their agreement. The firm will represent the nation on issues “that may affect or relate to [its] activities and interests … including but not limited to surveillance and privacy matters.”
Read more on Breitbart.com.


Another interesting concept. Could the owners of “private” systems charge for this access? Retain copyright? Have any rights at all?
Stacy Lange reports:
Authorities in Scranton are looking to increase surveillance all over the city. Not by adding more cameras, but by adding more eyes looking at the cameras already in place.
Scranton City Council announced this week that it is applying for a grant that would create community-wide surveillance for Scranton Police.
But the grant money wouldn’t pay for any cameras. It would pay for software that would allow Scranton Police to tap into private surveillance systems.
Read more on WNEP.


For my Computer Forensics students.
WSJ – In a Single Tweet, as Many Pieces of Metadata as There Are Characters
by Sabrina I. Pacifici on June 7, 2014
Elizabeth Dwoskin - “To understand big data, look no further than a single tweet. At 140 characters a tweet seems tiny, but it can yield a wealth of information. According to Elasticsearch, a startup that builds software to help companies mine data from social media, there are 150 separate points of so-called metadata in an individual tweet. Metadata loosely refers to information that can be gleaned about a piece of content. For example, in legal terms, the body of an email is considered content, while the time stamp, the sender and the receiver are considered metadata. For a tweet, metadata includes a unique numerical ID attached to each tweet, as well as IDs for all the replies, favorites and retweets that it gets. It also includes a timestamp, a location stamp, the language, the date the account was created, the URL of the author if a website is referenced, the number of followers, and many other technical specifications that engineers can analyze. (A Twitter employee created a map of metadata with explanations in 2010 that you can look at here.)”


It's one more “Thing” for the Internet of Things.
LG LifeBand Touch soon to be available in India
The era of 'smartness' has gripped the world. Begining with the 'smart' phones then to 'smart' TV then to 'smart' eyewear and now 'smart' wristbands have creeped in the market.
LG started selling the Lifeband in the US market last month for USD 150. And it is likely to be available in parts of Asia and Europe in the coming weeks.
Just like a life companion LG LifeBand Touch keeps a track on your workouts and calories burned and syncs it on your devices through an app-LG Fitness app. The figures collected by the band can be sycn on an iPhone, iPad or any Android device.

(Related) How many “Things” are being added to the Internet of Things?
Apple to make 3-5 million iWatch units per month, sales begin October: Nikkei
Apple is preparing to sell its first wearable device this October, aiming to produce 3 million to 5 million smartwatches a month in its initial run, the Nikkei reported on Friday, citing an unidentified parts supplier and sources familiar with the matter.
Specifications are still being finalized for the watch that many believe will be called iWatch, but the devices are likely to sport curved OLED (organic light-emitting diode) displays and sensors that collect health data from blood glucose and calorie consumption to sleep activity, the Japanese news service cited industry sources as saying.


Anyone want to start a car (truck/plane/motorcycle) company?
… Earlier this week, Mr Musk told Tesla shareholders that in order to speed up the pace of adoption of electric cars, Tesla was "playing with doing something fairly significant on this front which would be kind of controversial with respect to Tesla's patents".


Billion is the new million... Is this an indication of a bubble? (Are valuations like these real?)
Uber’s New Eye-popping Valuation
And to think $3.5 billion sounded like a lot.
Uber Inc, the startup known for its fast-growing on-demand car service, said it has raised $1.2 billion in additional capital, driving the company’s new valuation to an eye-popping $18.2 billion.
… Uber’s new net worth is $6.2 billion higher than it was just a month ago, when the company raised money at a roughly $12 billion level. Ten months ago the company was valued at $3.5 billion.
… At $18.2 billion, Uber is worth more than public companies including car-rental services Hertz Global Holdings, Inc. and Avis Budget Group Inc.


Bad move? High risk at best. Is one terabyte enough of a bribe to keep their users? Stay tuned!
Flickr closes doors for Facebook, Google logins
… Yahoo on Thursday announced that logging into Flickr using Facebook and Google accounts will not be possible after June 30. Instead, users will have to login with their Yahoo account or create a Flickr account to continue using the service.
… Flickr gained significance as the most used photo sharing service since it was acquired by Yahoo in 2005 but faded away into the background after the entry of Instagram. However, it started emerging as one of the prominent services last year after Yahoo announced a free storage of 1 TB and unlimited free accounts.


Perspective.
Google Chrome now most popular web browser in the U.S.
Popular internet browser Google Chrome is more popular than most people even realized. According to recently released figures, Google’s search engine has overtaken Microsoft’s Internet Explorer as the most popular internet browser in the United States.
Currently, 31.8 percent of internet users are running Google Chrome which according to a report published by the Adobe Digital Index is up 6 percent on the previous year. Oppositely, Internet Explorer was down 6 percent from the previous year. Despite this drop, Internet Explorer is only narrowly trailing Chrome with a market share of 30.9 percent.
These figures combine both traffic from desktop and mobile devices. This explains why both Chrome and Apple’s very own Safari have grown dramatically over the last few years. With more web browsing occurring on mobile devices through both iOS and Android, it’s no surprise that both web browsers have seen such growth.


For my Website Development students.
Face Your Fears, Become A True SEO Master
… SEO can either make or break a website. We do what we can to teach you, our readers about good SEO practices. However, I’ve always believed that SEO should come secondary to good content. But nevermind me, you should really pay attention to what the industry experts have to say about SEO. Here are 21 tips to help you through the sticky maze that is SEO, face your fears, and become a true SEO master.

Saturday, June 07, 2014

Heads-up Ethical hackers, they're talking about another of our tools.
Oh great: Is this new OpenSSL flaw worse than Heartbleed?
The Heartbleed flaw discovered in OpenSSL was one of the worst web vulnerabilities in history, but believe it or not it may have already been dethroned.
Even more incredible is the fact that once again, OpenSSL may be to blame.
The "CCS Injection Vulnerability" was discovered by Tatsuya Hayashi, who said it "may be more dangerous than Heartbleed," according to The Guardian.
Attackers can reportedly use this weakness to intercept and even alter data passing between computer and websites in a classic man-in-the-middle maneuver as long as they're on the same network, like a public Wi-Fi hub.


Isn't that what I've been saying?
Snowden Damage Apparently Less Than Feared: Report
Edward Snowden does not appear to have taken as much as originally thought from NSA files, The Washington Post reported late Thursday.
… "We're still investigating, [I doubt that. They should have finished an investigation like this in hours. Bob] but we think that a lot of what he looked at, he couldn't pull down," [Bologna! CNTL-A, CNTL-C, CNTL-V Any questions? Bob] Clapper said. "Some things we thought he got he apparently didn't," the director was quoted as saying.


Privacy in Canada.
Daniel Tencer reports:
Rogers Communications and internet service sartup TekSavvy have released the first-ever transparency reports from Canadian telecom companies, and what they have to say won’t lessen the concerns of privacy activists.
Rogers reported that it got 174,917 government requests for information about subscribers last year, or about 480 requests per day. That’s nearly one request for government data per 11 Rogers internet subscribers.
Read more on Huffington Post (Canada). In another post this morning, I note that Vodafone and Deutsche Telekom are also being more transparent now.
These are all great developments, and it’s appropriate that they are happening on or around the one-year anniversary of Edward Snowden’s revelations.


Privacy in the USA. This is strange.
Joe Wolverton, II writes:
Federal law enforcement officers recently seized the records of a local police force’s use of a controversial surveillance system known as “Stingray” just before the information was scheduled to be released to the public.
The U.S. Marshals Service “stunned” the American Civil Liberties Union (ACLU), which was waiting on the imminent release of the documents pursuant to a public records request the group filed earlier this year with the Sarasota, Florida, police department. The petition sought to shed light on the scope of the department’s use of the Stingray device.
According to the ACLU, its representatives were scheduled to be given access to the documents last Tuesday, but federal marshals showed up first and took possession of the entire cache, claiming they were the property of the U.S. Marshals Service. The feds forbade the local police from releasing the documents as planned.
Read more on New Amerian.


Some things are classified Top Secret when disclosure would cause "exceptionally grave damage." Other things are classified Top Secret when people think those things are very important. Yet others when the people choosing the classification think they are important.
EPIC v. NSA: EPIC Obtains Presidential Directive for Cybersecurity
by Sabrina I. Pacifici on June 6, 2014
EPIC - After almost five years, EPIC has obtained National Security Presidential Directive 54. The previously classified Presidential Directive contains the full text of the Comprehensive National Cybersecurity Initiative and “establishes United States policy, strategy, guidelines, and implementation actions to secure cyberspace.” This Directive, which is the foundational legal document for all cybersecurity policies in the United States, evidences government efforts to enlist private sector companies, more broadly monitor Internet activity, and develop offensive cybersecurity capability. EPIC first sought public release of NSPD-54 with a Freedom of Information Act request, submitted to NSA in June 2009. After the agency failed to disclose the document, EPIC filed suit. When a federal district court ruled in 2013 that the Presidential Directive was not subject to the Freedom of Information Act, EPIC then filed an appeal with the DC Circuit Court of Appeals. The document has now been disclosed to EPIC. The case is EPIC v. NSA, a Freedom of Information Act lawsuit in D.C. Circuit Court. EPIC has several related FOIA cases with the NSA pending in federal court. For more information see EPIC – EPIC v. NSA (Cybersecurity Authority).


This has potential, but I haven't found a link to check it out, yet.
Sam Evans-Brown reports:
There’s a database in New Hampshire, nestled in hard-drives in the Department of Education, with all sorts of information about student test scores, graduation rates, and achievement. It shows how poor kids do on tests compared to rich kids, and how minorities do compared to whites, and whether schools are improving on those tests.
Whenever the data in it is accessed, it’s totally anonymous; only a handful of employees at the DOE can match these test-scores with student names.
That makes New Hampshire already ahead of the curve, and that was the case before lawmakers passed a new student data privacy law.
National Privacy advocates are praising New Hampshire’s new measure, which Governor Maggie Hassan signed into law last week to basically no fanfare. They are saying it provides clarity in an area that in many states is largely unregulated.
Read more on NHPR


One part of the Net Neutrality debate?
Verizon tells Netflix to stop blaming it for streaming issues
… In a cease-and-desist letter sent to Netflix, Verizon said Netflix is making "false accusations" that have the "potential to harm the Verizon brand" and is engaging in "deceptive behavior."
At issue is a notice Netflix started running in Verizon homes earlier this week when buffering issues arose that said, "the Verizon Network is crowded right now."
"There is no basis for Netflix to assert that issues with respect to playback of any particular video session are attributable solely to the Verizon Network," Verizon General Counsel Randal Milch said in his Thursday letter to Netflix General Counsel David Hyman.
He went on to say that much of the problems consumers may be having are the fault of Netflix and the companies it uses to get its content to Verizon's pipes.
"Netflix has been aware for some time that a few Internet middlemen have congestion issues with some IP Networks and nonetheless, Netflix has chosen to continue sending its traffic over those congested routes," Milch said.


When does “tough business negotiations” tip over to monopolistic practices?
Amazon spat with publishers set to escalate
… The world's largest online retailer is already feuding with Hachette Book Group and Bonnier Media. Simon & Schuster and News Corp's HarperCollins will soon come up for renegotiation, say sources familiar with the matter, which means best-selling authors such as HarperCollins' Veronica Roth, writer of the Divergent trilogy, and Simon & Schuster's Michael Lewis could be entangled in the controversy.
Hachette's tussle will determine whether publishers can gain leverage against Amazon, the biggest seller of e-books, at a time when demand for digital tomes is surging and physical books are losing ground. Amazon is seeking a bigger cut of the retail price of a title so it can continue discounting e-books and boost margins, the sources said. To ratchet up the pressure on Hachette, Amazon started blocking some book pre-orders and delaying shipments - affecting titles such as The Silkworm, J.K. Rowling's new novel written under a pseudonym.
… Amazon commands 60 per cent of the e-books market, according to Forrester Research.
… ''Negotiating for acceptable terms is an essential business practice that is critical to keeping service and value high for customers in the medium and long term,'' Amazon said in an online post last week.
The tactics have hurt Hachette, the publisher of mass-market powerhouses like James Patterson and literary heavyweights like Donna Tartt. A few weeks into Amazon's campaign, Hachette relinquished its No.1 spot on the Digital Book World bestseller list, a sign of Amazon's dominance in the publishing industry.


Would “a personal representative of a deceased person’s estate” include a spouse or other heirs?
Access to Digital Accounts After Death Varies State to State
by Sabrina I. Pacifici on June 6, 2014
“The Uniform Law Commission, a body of lawyers who produce uniform legislation for states to adopt, recently drafted the “Fiduciary Access to Digital Assets Act (FADA).” It would grant fiduciaries (a catch-all term for the various types of people who can be legally appointed to hold assets) broad authority to access and control digital assets and accounts. FADA is considered by many attorneys to be an improvement over existing law because it would clarify and expand who can access a deceased person’s online accounts. The proposal would create four categories of fiduciaries who would be able to take over these accounts in the event of a death:
a personal representative of a deceased person’s estate;
someone carrying out a power-of-attorney;
a trustee of a trust; or
someone appointed by a court to act on behalf of a protected person.
Existing laws typically only apply to personal representatives. The Commission will vote on the proposed law in July. But two issues still remain. The first revolves around “media neutrality,” the idea that the treatment of assets should be the same regardless of whether they are digital or physical. The proposal would require certain fiduciaries to obtain access to digital assets, while it would be automatic for others.”


For my students.
More new jobs went to the college educated
US employers loaded up on college-educated workers in May.
A hefty 332,000 new jobs last month went to those who finished college, the Labor Department said Friday. That caused the jobless rate for college graduates to dip to 3.2 percent from 3.3 percent in April.
It was further evidence that businesses increasingly value educated workers, even when an advertised job doesn’t call for such a degree. The most recent estimate from the Federal Reserve Bank of New York found that, on average, one-third of college graduates work jobs for which their degrees aren’t necessary.


Does this signal an opportunity for Professional Employee Organizations? Security contractors.
Two-thirds of IT Employees Are Ready to Walk Out the Door: Survey
IT professionals are noticing a significant change in how they are regarded within their organizations, according to the latest research report from Wisegate, a private practitioner-based IT research services group. Instead of being treated as a nuisance or necessary evil, IT is increasingly being integrated into and respected by the business, according to the respondents—senior IT practitioners across a variety of industry sectors—who participated in the Wisegate survey.
But there is a gap somewhere, as many of the 362 IT professionals surveyed were looking for opportunities outside their organizations. Almost half of the respondents felt their organizations did not offer the opportunities they needed to advance in their careers. Two-thirds of the respondents said they expected to move on to another organization within the next two years. Respondents weren't just anticipating events beyond their control, as nearly half said they wanted to move within the year.
The full report is available online (PDF) from Wisegate.


I'll share this with my Statistics students, but I doubt they are old enough to appreciate it.
– Do you think time is catching up with you? Perhaps it’s already overtaken you and left you in the dust. Do the years seem to be going ridiculously quickly now? There’s a reason for it. You’re getting old. The site will provide you a report full of interesting stuff. Find out just how bad it’s got. Enter your date of birth.


For my students and fellow professors. Looks like we will get into Big Data (Data Mining and Data Analysis) in a much bigger way. Getting SAS for free is huge!
SAS® University Edition
By 2018, demand for workers skilled in analytics could outpace supply by 60 percent – or 1.5 million jobs – according to a McKinsey Global Institute study. Translation? Anyone with analytic prowess will be in high demand from employers around the world. What's more, a recent Monster.com article, "Job Skills That Lead to Bigger Paychecks," named SAS as the skill that nets the biggest paycheck. Bottom line, if you’re a student, learning SAS is a great way to prepare for – and secure – your future. If you’re a teacher or professor, teaching SAS is a great way to attract top students and to equip tomorrow's workers with the skills they'll need to succeed.

(Related) The “Why” of Big Data education.
What Big Data Needs to Do to Grow Up
We are in an Information Revolution — and have been for a while now. But it is entering a new stage. The arrival of the Internet of Things or the Industrial Internet is generating previously unimaginable quantities of data to measure, analyze and act on. These new data sources promise to transform our lives as much in the 21st century as the early stages of the Information Revolution reshaped the latter part of the 20th century. But for that to happen, we need to get much better at handling all that data we’re producing and collecting.
Consider the more than $44 billion projected by Gartner to be spent on big data in 2014. The vast majority of it — $37.4 billion — is going to IT services. Enterprise software only accounts for about a tenth.


Because it amuses me.
… Connecticut governor Dannel Malloy (D) signed a bill “to create and maintain a state platform for the distribution of electronic books (e-books) to public library patrons.”
… Onarbor is a new site, “intended as a publishing and funding platform for academics, kind of like a Kickstarter for scholarly work.” More via The Chronicle of Higher Education.
… Politico reports that Facebook has applied for a patent for “letting children create accounts with parental supervision”

Friday, June 06, 2014

This has been going on too long and involves too many “rebels” in uniforms with too many weapons to be a spontaneous bunch of protesters. Or am I wrong?
Pro-Russian rebels take control of 3 government bases in eastern Ukraine
Pro-Russian insurgents dislodged government troops from three bases in eastern Ukraine, a new blow to beleaguered armed forces as its president-elect vowed new initiatives to help end the regional mutiny.
… The move follows nearly two months of fighting in the region


If I block your device, I'm a privacy advocate. If you block my device, you're denying my First Amendment rights! Is there any law covering this?
For the privacy-conscious: An app that can jam Google Glass' WiFi
Here's something for the privacy-conscious who are wary of Google Glass' secret recording capabilities - an app to jam the wearable computing device's WiFi access.
Berlin-based artist Julian Oliver created the program "Glasshole.sh" to detect any Glass device and block it from accessing a WiFi network, a report on Wired.com said."
When it detects Glass, it uses the program Aircrack-NG to impersonate the network and send a 'deauthorization' command, cutting the headset’s Wi-Fi connection. It can also emit a beep to signal the Glass-wearer’s presence to anyone nearby," Wired.com reported.


Robots, like any “Thing” connected to the “Internet of Things” will know everything the Internet knows. What will they be programmed to do with it?
Robots: Can we trust them with our privacy?
Joss Wright is training a robot to freak people out.
Wright, a computer scientist, is plotting an experiment with a humanoid robot called Nao. He and his colleagues plan to introduce this cute bot to people on the street and elsewhere – where it will deliberately invade their privacy. Upon meeting strangers, for example, Nao may use face-recognition software to dig up some detailed information online about them. Or, it may tap into their mobile phone's location tracking history, learn where they ate lunch yesterday, and ask what they thought of the soup.


Can I use one to conduct academic research? I want before and after pictures of certain politician's homes.
Hollywood to feds: Let us use drones
It's almost entirely illegal to use drones for money-making purposes in the United States. But a little Hollywood magic could change that.
… Currently, there's only one exemption to the Federal Aviation Administration's nationwide ban on commercial drones, called unmanned aircraft systems or UAS. That's a spot off Alaska's coast where drones are used by an oil company.


For my students (and my lawyer friends)
E-Mail Self Defense
by Sabrina I. Pacifici on June 5, 2014
“Bulk surveillance violates our fundamental rights and makes free speech risky. This guide will teach you a basic surveillance self-defense skill: email encryption. Once you’ve finished, you’ll be able to send and receive emails that are coded to make sure that a surveillance agent or thief can’t intercept your email and read it. Even if you have nothing to hide, using encryption helps protect the privacy of people you communicate with, and makes life difficult for bulk surveillance systems. If you do have something important to hide, you’re in good company; these are the same tools that Edward Snowden used to share his famous secrets about the NSA. This guide relies on software which is freely licensed; it’s completely transparent and anyone can copy it or make their own version. This makes it safer from surveillance than proprietary software (like Windows). Learn more about free software at fsf.org. Email Self-Defense is a project of the Free Software Foundation. We fight for computer user’s rights, and promote the development of free (as in freedom) software like GnuPG, which is used in this guide. We have big plans to get this guide in the hands of people under bulk surveillance all over the world, and to make more tools like it.”


“Hey, we got him down, let's stomp on him!”
“Hey, he stole all that money, why should we let him use it to defend himself?”
Record companies want Kim Dotcom's assets frozen
Dotcom's assets had been frozen since January 2012 when his home was raided and Megaupload service was shut down. In April this year, a New Zealand court refused to extend the freeze on Dotcom's assets, which include a garage full of luxury cars, millions in cash, and other items taken from the raid of his mansion.
The court's decision has since been appealed by the Crown with a hearing due on July 30, and six major Hollywood studios also want Dotcom's assets to remain frozen while the case against him proceeds.
They are now joined by four record companies - reportedly Warner Music, UMG Recordings, Sony Music and Capitol Records - with papers served on Tuesday seeking to have Dotcom's assets frozen.


Learning how the (Brave new) world works.
Cloud Services For Dummies


For my student Mac users.
The Swift Programming Language
This book is available for download with iBooks on your Mac or iOS device, and with iTunes on your computer. Books can be read with iBooks on your Mac or iOS device.


Tools & Techniques
– lets you easily monitor the file access activities on your system. Have you ever wondered what’s going on with your disk system behind your watch? Why the disk is busy? What’s scratching your HDD? You may find them out using this simple program. There is an installable version and also a portable version.

Thursday, June 05, 2014

Soon, everything (on the Internet of Things) will know where you are. (Why would a flashlight need to know where you are?)
FTC Testifies on Geolocation Privacy
by Sabrina I. Pacifici on June 4, 2014
“The Federal Trade Commission testified before Congress on the Commission’s efforts to address the privacy concerns raised by the tracking of information about consumers’ location, as well as proposed legislation to protect the privacy of geolocation data. Delivering testimony before the Senate Judiciary Committee’s Subcommittee for Privacy, Technology and the Law, Jessica Rich, Director of the FTC Bureau of Consumer Protection, outlined the FTC’s ongoing efforts to protect the privacy of consumers’ geolocation information through enforcement, policymaking, and consumer and business education. Precise geolocation data is sensitive personal information increasingly used in consumer products and services, the testimony states. These products and services make consumers’ lives easier and more efficient, but the use of geolocation information can raise concerns because it can reveal a consumer’s movements in real time and provide a detailed record of a consumer’s movements over time. “Geolocation information can divulge intimately personal details about an individual. Did you visit an AIDS clinic last Tuesday? What place of worship do you attend? Were you at a psychiatrist’s office last week? Did you meet with a prospective business customer?” the testimony states. Geolocation information may be sold to companies to help build profiles about consumers without their knowledge or consent, or it could be accessed by cybercriminals, hackers or through surreptious means such as “stalking apps.” The FTC has used its enforcement authority under Section 5 of the FTC Act to take action against companies engaged in unfair or deceptive practices involving geolocation information. Last month, for example, the Commission entered into a settlement with the mobile messaging app Snapchat, resolving FTC allegations that Snapchat made multiple misrepresentations to consumers about the disappearing nature of messages sent through its service, as well its transmission of users’ geolocation information. The FTC has raised similar allegations involving undisclosed collection and transmission of location data as part of privacy complaints against a popular flashlight app, as well as a national rent-to-own retailer and one of its software vendors, the testimony states.”


So if the first thing out of my mouth was, “This involves National Security!” they have to turn off the recorders? OR if they think it involves National Security, I won't be able to prove what was said during the interrogation? Seems nuts to me, but then I'm not a lawyer.
In an important decision not widely reported, the Department of Justice last month adopted a policy requiring that interrogations of suspects arrested by the principal federal law enforcement agencies (including the FBI and the Drug Enforcement Administration) ordinarily must be recorded electronically. The new requirement is an unquestionably positive development, long overdue, but it expressly exempts interrogations in national security cases – an exception that is at best puzzling and, at worst, downright alarming. The new policy, set forth in a May 12 DoJ memo entitled “New Department Policy Concerning Electronic Recording of Statements” (full text), will go into effect on July 11, 2014.


For my Ethical Hackers. This is what happens to all those stolen cards...
Peek Inside a Professional Carding Shop
Over the past year, I’ve spent a great deal of time trolling a variety of underground stores that sell “dumps” — street slang for stolen credit card data that buyers can use to counterfeit new cards and go shopping in big-box stores for high-dollar merchandise that can be resold quickly for cash. By way of explaining this bizarro world, this post takes the reader on a tour of a rather exclusive and professional dumps shop that caters to professional thieves, high-volume buyers and organized crime gangs.


For my students with an Android phone.
New Ransomware Encrypts Android Files: ESET
Dubbed Simplocker, the malware scans the SD card for certain file types, encrypts them and then demands a ransom in exchange for decrypting the files. After launching the malware will display a message in Russian warning that the victim's phone has been locked while files are being encrypted in a separate thread in the background. The message demands payment in Ukrainian money, indicating that region of the world is likely the primary target.


For my Computer Security students. Scary, isn't it?
Keep Up With The Latest Data Leaks – Follow These 5 Services & Feeds
SC Magazine - The Data Breach Blog
Unfortunately, they are split between the US site and the UK site,


For my artsy-fartsy students.
30,000+ Images of Art and Artifacts to Download and Re-use for Free
The Museum of New Zealand recently released more than 30,000 images of art and artifacts to download and re-use for free. The images are a mix of public domain images and images labeled with a Creative Commons license. The museum makes it easy to determine how an image is licensed. To determine the licensing of an image simply click on the download button and the next page clearly shows the license for the image.
Finding images in the Museum of New Zealand's gallery isn't the most intuitive process. You can enter a keyword to search, but if you're too specific you might not find what you're looking for. For example, enter "fish" and scroll through the results rather than entering "salmon" or "trout" to find images of fish. The other way to search is to open the advanced search settings in which you can choose a collection to browse through.


For all my students. (Includes a “Free Doughnut Search Engine!”
National Doughnut Day Friday, June 6