Thursday, October 16, 2014

For my Computer Security students. (Report available from HP)
Cost of Cyber Attacks Jumps for US Firms: Study
A survey of 59 US firms by the Ponemon Institute with Hewlett-Packard found the average annual cost of responding to cyber attacks was $12.7 million, up 96 percent over the previous five years.
The organizations saw a 176 percent increase in the number of cyber attacks, with an average of 138 successful attacks per week, compared to 50 attacks per week when the study was initially conducted in 2010.
The average time to detect an attack was 170 days, and it took on average 45 days to resolve a cyber incident, costing an average of $1.6 million, according to the researchers.


Teens: “We have the technology, let's use it!” Old Geezer (Bob): “I have the technology. I can't think of a reason to use it.”
Google study shows that we use Voice Search for a lot of embarrassing things
… A study commissioned by Google on how people use voice search was released today, and from it we've learned more than we ever wanted to know about how people use voice search.
… Apparently, 22 percent of teens have for some reason admitted to using voice search while in the bathroom. When you're in the age group that uses voice search most often, you're not going to let a quick pit stop to the restroom stop you from talking to your smartphone. The study found that 55 percent of teens ages 13 to 18 use hands-free search every day, compared to 41 percent of adults.
… In response to the question, "pick one thing you wish you could ask your phone to do for you," 45 percent of teens chose "send me a pizza." Boring adults chose the boring answer "tell me where my keys are" to the tune of 44 percent, but 36 percent of adults showed that they still have some fun in them by also saying they would like voice search to send them pizzas.


Could be useful. I'll add this to my Disaster Recovery class. Facebook will probably map “disasters” worldwide and become the “website of doom.”
Facebook's 'Safety Check' lets friends know you're safe
During a major disaster, Facebook users can let their friends and family know they are safe by using the new Safety Check tool.
When the tool is activated and Facebook determines that a user may be in an area where a natural disaster occurred, the social network will send a notification asking if the user is safe. If the response “I’m Safe” is selected, Facebook will create a post and share it on the user’s news feed, telling friends they are out of peril. Friends too have the possibility to mark someone as safe.
Facebook determines a user’s location by looking at the city listed in their profile, their last location if they’ve opted in to the Nearby Friends service, and the city where they are using the Internet, presumably derived from their IP address. If the location is wrong the user can tell Safety Check they are not in the affected area.

(Related) Sometimes it's good that your “Things” know where you are and can tell anyone(?) who asks! (Is something seriously wrong with OnStar?)
'Find My iPhone' App Helps Locate Missing Motorist
A California woman who drove her car into a 500-foot ravine was rescued this week after her family and one clever police officer were able to determine her location via her iPhone, the San Jose Mercury News reported.
The unnamed, 28-year-old resident of Campbell, Calif. veered off Mount Hamilton Road in a 2012 Chevy Cruze on Monday and wound up spending 18 hours at the bottom of the ravine before being airlifted out by a Coast Guard helicopter on Tuesday morning, the newspaper reported.
Though her vehicle was outfitted with General Motors's OnStar system, which determines a vehicle's location by means of a roof-mounted GPS antenna, the company was not able to pinpoint where the car was, according to the Mercury News.
… An OnStar spokesperson also told the Mercury News that GM's system "only keeps track of users locations at discreet moments in time, such as when an accident happens or when they call in to get driving directions from a particular place."
By contrast, when location tracking and location-based apps are enabled on an iPhone, the device and Apple's tracking system attempt to maintain an ongoing connection to pinpoint the location of the smartphone.


Revolt of the Content Providers?
HBO Launching Standalone Service In 2015
HBO has announced plans to offer a standalone subscription service starting sometime in 2015. HBO is currently only available to U.S. residents who also pay for a raft of other channels. But HBO CEO Richard Plepler has promised to go “beyond the wall” and launch a “stand-alone, over the top” version next year.
Details are thin on the ground, so it isn’t yet known how HBO will deliver such a service to customers, or what it’ll charge for the privilege. Regardless, this puts HBO on a collision course with streaming services, and Netflix in particular. But with an increasing number of people refusing to pay a small fortune for channels they don’t want to watch, HBO had to act, and fast.


Expanding the earlier survey.
A World of Beloved Books (According to Facebook)
What books have stayed with you?
… Back in September, Facebook tallied up the results of that status game worldwide. Its findings? The Harry Potter series, To Kill a Mockingbird, The Lord of the Rings, and Pride and Prejudice led the way. They were followed by none other than the Bible.
Since then, the game has gotten bigger, spreading to other countries and languages. In a new blog post, Facebook has unveiled which books are beloved in nations that have had 20,000 or more responses—that is, France, India, Italy, Mexico, Brazil, and the Philippines.
What did they find? In those six nations—as in the U.S. and U.K.-dominated first tally—the Boy Who Lives dominates.


For my spreadsheet students.
How To Use An Excel Pivot Table For Data Analysis


For my Computer Security students, past & present.
Looking for a job? Cyber Aces is hosting another National Cybersecurity Career Fair in November
Last spring I wrote about Cyber Aces hosting its first National Cybersecurity Career Fair (NCCF). (See National Cybersecurity Career Fair in June Will Connect Employers to Entry Level Cybersecurity Workers.)
… The group held its first ever career fair this past June and the event was so successful that it has decided to make the career fair a semi-annual event. The next NCCF is scheduled for November 20 and 21, 2014. Now is the time to register and create your personal profile if you want to meet with prospective employers.


For my Android toting students. Probably a similar one for the iPhone.
– is an Android app that welcomes you into the world of data by showing you the output of all sensors of your Android device. Check the temperature, humidity, air pressure, gravity, light, acceleration and a lot more. Most sensors also display a chart with the output of the sensor so you can better watch the changes during the time.

Wednesday, October 15, 2014

For my Ethical Hackers. I repeat, technically sophisticated hacks are fun, but the real money is in the huge volume of simple, low skill hacks that are available. (Note that management should be a bit concerned with their Security manager if they hear things like this.)
Byron Acohido reports;
Ethical hacker Bryan Seely of Seattle-based Seely Security showed how MBIA has long been exposing details of municipal bond and investment management accounts in a way that made it easy for criminals to transfer funds from existing accounts into newly created ones they control. There’s no evidence any theft took place, only because the bad guys appear to have overlooked this freebie.
[...]
Seely says he has identified more than 8,000 other servers that are similarly misconfigured and likewise exposing sensitive accounts on the open Internet. These are accounts that should be kept under lock and key.
Seely has been on a one-man campaign to notify organizations, and a few have listened to him.
Read more on Credit.com
[From the article:
“In the case of MBIA, it was not at risk because of a flaw in Oracle,” Seely says. “This was simply because the customer did not configure the server correctly when they deployed it, and it caused private banking records to be exposed to the Internet.”

(Related) Not hearing about security weaknesses is even worse. (Not to mention, pretending to not hear)
A former Maricopa County Community College District employee alleges executive leadership closed their eyes to a report on their database security conducted after their massive data breach in 2013 so they would have plausible deniability in any litigation. As a result, the employee alleges, the findings were never shared with those tasked with securing MCCCD’s data assets.
In November 2013, Maricopa County Community College District (MCCCD) disclosed that they had been informed by the FBI that 14 databases with personal information had been found up for sale on the Internet. The potential compromise of 2.5 million students’, employees’ and vendors’ personal and financial information currently stands as the largest breach ever in the education sector.
As part of its continuing investigation into that breach, DataBreaches.net recently disclosed parts of a report issued by Stach & Liu in 2011 after an earlier hacking incident. Failure to properly remediate that breach had been cited as a factor in the 2013 breach. Of special relevance now, MCCCD’s external counsel had asserted that MCCCD administration at the highest levels never even knew of the report’s existence until after the 2013 breach. [Apparently they don't read the local newspaper or watch local TV news. Bob] Their claim was disputed by former employee Earl Monsour, who stated he had delivered the report to the Vice Chancellor for ITS.
[I suggest you read the full article! Bob]


Is this because they have crazy people just across the boarder?
Cho Mu-hyun reports:
The shocking figure of over 106 million privacy breaches was unveiled by a report of data leaks between 2010 to 2014 filed by the Korea Communication Commission (KCC) to the National Assembly during the yearly government audit of ministries.
The figure means that each person has, on average, had his or her personal information leaked 2.1 times during the past four years in a country with a population of 50 million.
Read more on ZDNet.


For my Computer Security students. Should I add this to my “Stalker's Toolbox?”
How Anyone Can Find Your Personal Details Via Twitter With Tinfoleak
… There’s a free script called Tinfoleak which can pull an alarming amount of information about any Twitter user based simply on their profile and their tweets. Let me show you how it works.


Take that, Steve Jobs! (Could I follow this business model here in the US?)
Xiaomi, Not Apple, Is Changing the Smartphone Industry
… Xiaomi, the four-year-old Chinese smartphone manufacturer, has found just such a sweet spot, and as a result is taking the smartphone industry by a storm. Pundits claim that Xiaomi is just a Chinese copycat of Apple, and not without some reason. Some point to Xiaomi’s product introductions, which are eerily just like Apple’s. Others point out the strong similarities between Xiaomi’s operating system (named MIUI) and Apple’s iOS. What’s more, Xiaomi’s products rank among the best in the industry in terms of performance. All these cues might lead us to believe that it is competing head to head with the leading smartphone manufacturers.
However, looking at the full extent of Xiaomi’s business model reveals just how different – and how disruptive — it is. For starters, unlike Apple, Xiaomi is not targeting premium customers; it’s mostly teens buying those high-quality phones, and hardly at a premium, since Xiaomi’s prices are at least 60% lower. A neat trick. How does Xiaomi pull that off?


For my Ethical Hackers. Think of the fun possible by driving through a neighborhood, unlocking doors as you go!
August Smart Lock Gets Key Exposure in Apple Stores
The August Smart Lock will become available for purchase at Apple retail stores in the United States starting this week, the company announced on Tuesday.
Priced at US$249.99, the smart device uses Bluetooth and a mobile app to create a virtual key.
The August Smart Lock replaces the interior portion of users' existing deadbolt locks but does not require users to change their exterior door hardware; their physical, metal keys will work with the deadbolt as well.
The device is powered by four AA batteries [Why you need to keep the key Bob] and can be installed in about 10 minutes, August said.
Once in place, the smart lock allows users to control access to their home via smartphone. They can provide temporary or ongoing access to select others at will, including creating invited guest lists from their contacts for a party or event, for example.
Log records show who has entered and exited.


It's sad to think we need to buy hardware, install special software, or go to any extra effort at all to secure our communications. The amount of “over-subscription” ($7,500 asked, $500,000+ pledged) suggests we do want security and recognize the need to pay for it.
Cassandra Khaw reports:
On the internet, everyone is susceptible to invasions of privacy. But, a group of developers is hoping to change this by kickstarting a one-stop solution for anyone looking to peruse the internet without having their personal information harvested.
Anonabox hinges on open source software known as Tor, which encrypts user activities on the World Wide Web. While some amount of technical knowledge is usually needed to implement Tor, Anonabox will purportedly offer plug-and-play usability.
Read more on The Verge.


Clearly I'm pleased to see that Harvard clearly wants to clearly clarify the clutter surrounding the Internet of Things. Definitely worth a read!
The Internet of Things Is More than Just a Bunch of Refrigerators
The Internet of Things is definitely becoming a Thing, in the same way that big data’s a Thing or the sharing economy’s a Thing. And the thing about a thing that becomes a Thing is, it’s easy to lose sight of the things that made it a thing before everyone declared it the Next Big Thing that will change everything.
Got it? Good. We’ll start there. With the hype over the Internet of Things behind us. Because whether or not it’s a Thing, the internet of things is already a lot of things.
… But before you read anything else, I suggest you check out Michael Porter’s new opus of an article on the Internet of Things and strategy.
It’s quite a thing.

(Related) Also mentioned in the previous article.
Search engine for the Internet of Things
“Thingful® is a search engine for the Internet of Things, providing a unique geographical index of connected objects around the world, including energy, radiation, weather, and air quality devices as well as seismographs, iBeacons, ships, aircraft and even animal trackers. Thingful’s powerful search capabilities enable people to find devices, datasets and realtime data sources by geolocation across many popular Internet of Things networks, and presents them using a proprietary patent-pending geospatial device data search ranking methodology, ThingRank®. If you are concerned about asthma, find out about any air quality monitors in your neighbourhood; somebody working with a Raspberry Pi can find others round the corner using the same computing platform; if you notice a ship moored nearby, discover more about it by tracking it on Thingful, or get notified of its movements; a citizen concerned about flooding in a new neighbourhood can look up nearby flood monitors or find others that have been measuring radiation. You might even watch the weekly movements of a shark as it explores the oceans. The possibilities are unbounded! Thingful also enables people and companies to claim and verify ownership of their things using a provenance mechanism, thereby giving them a single web page that aggregates information from all their connected devices no matter what network they’re on, in categories that include health, environment, home, transport, energy and flora & fauna. Users can also add objects to a Watchlist in order to keep track of them, monitor their realtime status and get notifications when they change.”


They talk statistics, I'm looking for immediate (hardware or software) feedback.
Training Students to Extract Value from Big Data
“As the availability of high-throughput data-collection technologies, such as information-sensing mobile devices, remote sensing, internet log records, and wireless sensor networks has grown, science, engineering, and business have rapidly transitioned from striving to develop information from scant data to a situation in which the challenge is now that the amount of information exceeds a human’s ability to examine, let alone absorb, it. Data sets are increasingly complex, and this potentially increases the problems associated with such concerns as missing information and other quality concerns, data heterogeneity, and differing data formats. The nation’s ability to make use of data depends heavily on the availability of a workforce that is properly trained and ready to tackle high-need areas. Training students to be capable in exploiting big data requires experience with statistical analysis, machine learning, and computational infrastructure that permits the real problems associated with massive data to be revealed and, ultimately, [I'm gunning for “immediately” Bob] addressed. Analysis of big data requires cross-disciplinary skills, including the ability to make modeling decisions while balancing trade-offs between optimization and approximation, all while being attentive to useful metrics and system robustness. To develop those skills in students, it is important to identify whom to teach, that is, the educational background, experience, and characteristics of a prospective data-science student; what to teach, that is, the technical and practical content that should be taught to the student; and how to teach, that is, the structure and organization of a data-science program. Training Students to Extract Value from Big Data summarizes a workshop convened in April 2014 by the National Research Council’s Committee on Applied and Theoretical Statistics to explore how best to train students to use big data. The workshop explored the need for training and curricula and coursework that should be included. One impetus for the workshop was the current fragmented view of what is meant by analysis of big data, data analytics, or data science. New graduate programs are introduced regularly, and they have their own notions of what is meant by those terms and, most important, of what students need to know to be proficient in data-intensive work. This report provides a variety of perspectives about those elements and about their integration into courses and curricula.”


Demographics and Big Data. Summarizing by Zip Code.
Big Data Can Guess Who You Are Based on Your Zip Code
In the era of Big Data, your zip code is a window into what you can afford to buy, but it also reveals how you spend time—and, in essence, who you are.
That's according to software company Esri, which mapped zip codes across the United States and linked them to one of 67 profiles of American market segments.
… The level of detail is striking and—from what I could tell based on cross-referencing some of my own last several zip codes of residence—pretty accurate, too. Anyone can plug a zip code into Esri's database, which makes for an addicting game of "guess my identity."
… In the United States, where there are virtually no regulations on data collection, someone trying to profile you can fairly easily learn how much money you make, your education level, whether you own a home, who you voted for, how many kids you have, how much credit card debt you're carrying, even what you thought of the series finale of How I Met Your Mother.


Dilbert nails it again. This is exactly what happens when I assign Group Projects.

Tuesday, October 14, 2014

My Computer Security students need to understand this common follow-on to security breaches.
David Allison provides a litigation update here.
The next question is how many of them will be dismissed because of lack of standing.

(Related) Another reality of security breaches – they just keep on giving you headaches. In this case it seems to have triggered other investigations...
Wow. I suspected Aaron’s problems over spyware in rent-to-own computers weren’t over, but they just agreed to pay $28.4 million to settle California’s charges against them that included privacy violations:
… The complaint alleges that Aaron’s violated California’s Karnette Rental-Purchase Act, which is the strongest rent-to-own law in the country, by charging improper late fees, overcharging customers who paid off contracts early, and omitting important contract disclosures.
In addition, the complaint alleges that Aaron’s violated California state privacy laws by permitting its franchised stores to install spyware on laptop computers rented to its customers. A feature in the spyware program called ‘Detective Mode’, which was installed without consumers’ consent or knowledge, allowed the Aaron’s franchisees to remotely monitor keystrokes, capture screenshots, track the physical location of consumers and even activate the rented computer’s webcam.
… Copies of the complaint and stipulated judgment are attached to the online version of this release at www.oag.ca.gov/news.


Surely Buffy, Muffin, and Chaz would not stoop to such things?
Well, this is tacky, at best. It appears some members of the Sausalito Yacht Club gained access to the membership roster. From the notification letter of October 4:
We are writing to you because of an incident at the Sausalito Yacht Club on or about October 1, 2014,wherein several members gained unauthorized access to our member roster, which includes information linking your name to your private Sausalito Yacht Club member number, the combination of which allows you to charge beverages, goods, services and meals at the club, such amounts being charged at the time and accumulated for inclusion on your next bill.
The data to which unauthorized access occurred also included your personal contact information, and in certain cases, sensitive financial account information, including accounts receivable that were overdue by sixty days or more. As best we can tell, no bank account information or credit card information was involved in this breach.
… We are also undertaking steps to strengthen access [Strange wording Bob] to sensitive financial and membership sites with new passwords required for access by authorized users.
So, will they throw the intrusive and thoughtless privacy invaders out of the Yacht Club or will money triumph?
That was rhetorical.


This seems a bit too generic for me. “Oh look, someone is hacking.”
Russian Hackers Used Bug in Microsoft Windows for Spying, Report Says
Russian hackers used a bug in Microsoft Windows to spy on several Western governments, NATO and the Ukrainian government, according to a report released Tuesday by iSight Partners, a computer security firm in Dallas.
The targets also included European energy and telecommunications companies and an undisclosed academic organization in the United States, the cybersecurity report said.
… While the vulnerability affected many versions of Windows, iSight said the Russian hackers appeared to be the only group to use the bug. The company added, however, that other companies and organizations may also have been affected by the attacks.


Sometimes you get much more than you expected.
Snapchat Hackers Could Be Prosecuted for Child Porn Offenses
Private videos and pictures shared between tens of thousands of Snapchat users -- possibly as many as 200,000 -- were posted online by hackers over the weekend in an episode dubbed the "Snappening." Much of the content is sexual, including many nude photos -- some possibly of minors.
The hackers appear to have gone for maximum embarrassment and humiliation with this particular breach: A document also published online reportedly links many of the hacked images to user names.


One of the most well known downsides of any large database. They become large targets for hackers.
AP reports:
After an avalanche of data breaches, South Korea’s national identity card system has been raided so thoroughly by thieves that the government says it might have to issue new ID numbers to every citizen over 17 at a possible cost of billions of dollars.
The admission is an embarrassment for a society that prides itself on its high-tech skills and has some of the fastest Internet access.
Read more on CBC.


Do you ever talk about company strategy?
Who’s Watching Your WebEx?
KrebsOnSecurity spent a good part of the past week working with Cisco to alert more than four dozen companies — many of them household names — about regular corporate WebEx conference meetings that lack passwords and are thus open to anyone who wants to listen in.
… Many of the meetings that can be found by a cursory search within an organization’s “Events Center” listing on Webex.com seem to be intended for public viewing, such as product demonstrations and presentations for prospective customers and clients. However, from there it is often easy to discover a host of other, more proprietary WebEx meetings simply by clicking through the daily and weekly meetings listed in each organization’s “Meeting Center” section on the Webex.com site.
… Cisco began reaching out to each of these companies about a week ago, and today released an all-customer alert (PDF) pointing customers to a consolidated best-practices document written for Cisco WebEx site administrators and users.


No military, no economists, not even a politician – I think their perspective might be a bit skewed.
Electronic mass surveillance – including the mass trawling of both metadata and content by the US National Security Agency – fails drastically in striking the correct balance between security and privacy that American officials and other proponents of surveillance insist they are maintaining.
We arrived at this conclusion by subjecting a wide-range of surveillance technologies to three separate assessments by three parallel expert teams representing engineers, ethicists, and lawyers. Each team conducted assessments of surveillance technologies, looking at ethical issues they raise; the legal constraints on their use – or those that should exist – on the basis of privacy and other fundamental rights; and, finally, their technical usability and cost-efficiency.


“Comprehensive” is the word. Eventually, every “Thing” will bring its own resources – then we'll never find anything.
New on LLRX – Internet-of-Things (IOT) Resources
Via LLRX - Internet-of-Things (IOT) Resources – This is a comprehensive listing of Internet-of-Things (IOT) research resources and sites available on the Internet. Marcus P. Zillman developed this guide with the goal of highlighting the most current and actionable research resources available on this topic.


For all my students.
New on LLRX – Student Research Resources Library
Via LLRX.com – Student Research Resources Library – Marcus P. Zillman developed this Student Research Resources Library to provide researchers with a comprehensive listing of reliable topical resources and sites available on the Internet.

(Related) Here's how to get started.
Wiki Summarizer Can Help Students Start Their Research Projects
Wiki Summarizer is a site that allows you to search Wikipedia, have articles summarized by key points, and provides lists of articles that are related to your original search. Wiki Summarizer also offers expandable webs of related articles. For example, I searched for "Maine" and a web of related terms was created. Clicking on the "+" symbol next to each term opens a new element of the web. The final summary aspect of the Wiki Summarizer is the hyperlinked word clouds for every Wikipedia article. You can click on any word in the word clouds to jump to the corresponding Wikipedia article.
Wiki Summarizer could be a good tool for students who are just starting a research assignment and are not quite sure what terms to use or what topics to explore. By using the Wiki Summarizer web view or word cloud view students will be able to find some terms and topics that could help them alter and or direct their searches. In other words, Wiki Summarizer could help students who have a very broad research topic narrow down their searches.


Intended for Press Releases, but might apply to research, publications and resumes.
Get Your Pitch Noticed by a Major Publisher
… So, how should you approach a major publisher? The first thing you need to understand is a writer’s capacity. On average, 45% of writers only publish one story per day. In fact, 60% of writers publish two or fewer stories per day, and 40% said they publish only one story per week. Meanwhile, 40% of these writers get pitched a minimum of 20 times per day, while 11% get 50 pitches per day and 8.4% get more than 100 pitches per day. That’s 100, 250, or 500 pitches a week for only five story spots. When you take into account that only 11% of these writers “often” write a story based on content that was sent through a pitch, 45% “sometimes” do, and 39% “rarely” do, you see the pile of email waste rising well above a person’s threshold to tolerate it.
Here’s the good news: our survey found that 70% of publishers are open to getting pitched a set of ideas that fit their beat, and they prefer collaboration over getting pitched a finished asset without prior contact.
What story angles are these writers interested in collaborating on? 39% of writers said the perfect piece of content possesses exclusive research, 27% said breaking news, and 15% said emotional stories. 19% filled in “other” and stated that content relevant to their audience was most important. Other popular terms included: interesting data, actionable advice, trending/timely angles, and high arousal emotions.


...and 100% believe they are the 15%.
Teen Researchers Defend Media Multitasking – WSJ
“Some teens doing homework while listening to music and juggling tweets and texts may actually work better that way, according to an intriguing new study performed by two high-school seniors. The Portland, Ore., students were invited to the annual conference of the American Academy of Pediatrics in San Diego this past weekend to present a summary of their research, which analyzed more than 400 adolescents. The findings: Though most teens perform better when focusing on a single task, those who are “high media multitaskers”—about 15% of the study participants—performed better when working with the distractions of email and music than when focusing on a single activity. The results are a surprise. Previous research generally has found that people who think they are competent multitaskers actually perform worse than others who try to focus on one thing at a time. But the latest study looked only at teens and is one of the few multitasking-research projects focused on this age group. The student researchers suggest this may explain the different outcomes.”


We have an underutilized 3D printer. Perhaps we could work something out?
123D Catch Turns Pictures Into 3D Models
123D Catch is a free iPad and Android app. The app makes it possible to turn your pictures into a 3D model that you can manipulate on your iPad or on your Android tablet.
To create a model with 123D Catch select a physical object that you can photograph with your tablet or phone. Then take a series of pictures of that object as you either walk around it or rotate it slowly as you take pictures of it. Then select the best images from those that you took (20+ images works best) to let Autodesk process and turn into a 3D model for you. Your completed 3D models can be shared to the Autodesk community where others can view and use them.
123D Catch could be a great app for creating virtual manipulatives to use in a math or science lesson. The app could also be used to create 3D models of interesting landmarks that you visit during a vacation, but that your students would otherwise only see in 2D pictures. Finally, all of the models that you create with 123D Catch can be edited in Meshmixer and printed with a 3D printer.

Monday, October 13, 2014

Consider: The President was briefed on the JPMorgan hack and the potential for damage was explained.
Obama Said to Warn of Crippling Cyber Attack Potential
President Barack Obama believes cyber terrorism is one of the biggest threats to national security and says the White House is bracing for a possible doomsday scenario if hackers can successfully penetrate government and business computer systems, the FOX Business Network has learned.
… At the fundraisers, the president laid out what one person with first-hand knowledge of the fundraising meetings called a “doomsday” scenario if hackers can successfully gain entry into government systems or breach security walls at major banks.
“The president is worried that cyber criminals could literally wipe out the identities of millions of people through some breach of government systems and that could lead to massive chaos,” this person said.

(Related) The President is speaking hypothetically, DHS deals with actual events.
Critical Manufacturing Firm Hit by Sophisticated Threat Actors: DHS
Several sophisticated threat groups have breached the systems of a major critical manufacturing company, the Department of Homeland Security (DHS) revealed last week in a report.
According to the report, which summarizes the Industrial Control Systems Cyber Emergency Response Team's (ICS-CERT) activities in the second quarter of 2014, the attackers had access to the unnamed manufacturing organization's networks for several months.
… A study published this summer revealed that 70% of critical infrastructure organizations had suffered at least one security breach that either led to the disruption of operations or the loss of confidential information.
The DHS has been actively involved in the protection of critical infrastructure, but the agency has also made some mistakes that could have had serious consequences. In July, in response to a freedom of information act (FOIA) request, the DHS mistakenly released 840 pages of documents containing details on potentially vulnerable critical infrastructure points across the U.S.


For my Computer Security students. These are fun questions to ask your managers. Tell them it is for a project at school.
Is Your Company Ready for a Big Data Breach?
The Second Annual Study on Data Breach Preparedness – Ponemon Institute© Research Report – Sponsored by Experian® Data Breach Resolution – Independently conducted by Ponemon Institute LLC. Publication Date: September 2014.
“Data breaches are increasing in frequency. Forty-three percent of respondents say their companies had a data breach involving the loss or theft of more than 1,000 records, an increase of 10 percent from 2013. Sixty percent of respondents say their companies have had more than one breach. Last year, 52 percent of respondents said their company had more than one breach. Current data breach preparedness programs often fail to deal with all consequences of an incident. Despite the increased existence of data response teams and plans in organizations represented in this research, Figure 1 reveals 68 percent of respondents do not agree their company would know how to deal with negative public opinion, blog posts and media reports. Further, only 67 percent do not agree their organization understands what needs to be done following a material data breach to prevent the loss of customers’ and business partners’ trust and confidence.”


Apple is not a bank. But, could we someone steal as much from them? Looks like it.
Apple Pay Setup Process Revealed as Retail Employees and Partners Begin Training
Apple has begun preparing its retail employees and retail partners for the upcoming launch of its Apple Pay mobile payments service with a host of new training materials that show the feature in action, reports 9to5Mac.
Users will be able to set up Apple Pay in Passbook or through the Settings app, as up to eight credit or debit cards be connected with an iTunes account or by scanning one in with the iPhone's camera. Every card connected to the service will allow users to access a number of features, including the ability to see a simple transaction list, the ability to turn on push notifications, and an area that allows quick access to a bank's phone number and an accompanying app. Passbook will also be able to automatically update an expired card with a new expiration date without the need to re-enter information.

(Related)
PayPal Mobile API Flaw Allows Security Feature Bypass
For security reasons, PayPal accounts are temporarily blocked if someone enters incorrect passwords several times. In order to have the account unblocked, the user must answer a series of security questions.
While this security feature is enforced in the regular Web application, the mobile API doesn't check if the account is restricted before allowing the user to attempt to log in again, Benjamin Kunz Mejri, Vulnerability Lab founder and the one who identified the issue, revealed in an advisory published last week.


Biometric security.
Banks Are Harvesting Your 'Voiceprint' On The Phone To See If You're Lying
… Two major U.S. banks, JPMorgan Chase & Co. and Wells Fargo & Co., use voice screening, also known as voice biometric blacklists, according to three people familiar with the arrangements, all of whom spoke on condition of anonymity because the system was meant to remain secret.
… "It's in the background. It doesn't affect the call in any way," said Inscoe. "Nobody even knows it's happening."


Healthcare. Apparently the potential to make huge amounts of money is attracting everyone.
The doctor will see you now — through Google
… Developer Jason Houle noticed an interesting feature when he googled “knee pain” on an Android device recently: Google was offering him to “talk with a doctor now” through a video chat. He posted a screenshot to Reddit on Friday, and Engadget confirmed yesterday that Google was indeed testing the feature.
The extraordinary aspect of the feature is that it suggests Google does actually harbor major ambitions for its expert-chatting feature, Helpouts, specifically in the domain of health care.
… It’s HIPAA-compliant, ensuring doctors won’t need to worry about the security of patient information, as VentureBeat reported last year.


I hypothesize a zombie attack in my Disaster Recovery class, perhaps I could work robots into my Computer Security class? Will there be a market for drones (balloons?) I can fly to establish that I do use the air over my property and that drones could interfere with that use?
Self-Defense Against Robots
A. Michael Froomkin and Zak Colangelo on “Self-Defense Against Robots”
“Deployment of robots in the air, the home, the office, and the street inevitably means their interactions with both property and living things will become more common and more complex. This paper examines when, under U.S. law, humans may use force against robots to protect themselves, their property, and their privacy. In the real world where Asimov’s Laws of Robotics do not exist, robots can pose—or can appear to pose—a threat to life, property, and privacy. May a landowner legally shoot down a trespassing drone? [Make my day! Bob] Can she hold a trespassing autonomous car as security against damage done or further torts? Is the fear that a drone may be operated by a paparazzo or a peeping Tom sufficient grounds to disable or interfere with it? How hard may you shove if the office robot rolls over your foot? This paper addresses all those issues and one more: what rules and standards we could put into place to make the resolution of those questions fairer to all concerned. The default common-law legal rules governing each of these perceived threats are somewhat different, although reasonableness always plays an important role in defining legal rights and options. In certain cases—drone overflights, autonomous cars—national, state, and even local regulation may trump the common law. Because it is in most cases obvious that humans can use force to protect themselves against actual physical attack, the paper concentrates on the more interesting cases of
(1) robot (and especially drone) trespass,
(2) robot (and especially drone) spying, and
(3) responses to perceived threats by robots—perceptions which may not always be justified, but which sometimes may nonetheless be considered reasonable in law.
We argue that the scope of permissible self-help in defending one’s privacy should be quite broad. We also identify seven problems in current law relating to human-robot interaction, all of which involve some kind of uncertainty — usually about what a robot can or will do — and suggest ways of solving or at least ameliorating them, either by making robots less potentially dangerous (banning the arming of robots) or by requiring robots to give clearer notice of their capabilities. We conclude by looking at what the law on human self-defense against robots might tell us about a robot’s right to not be harmed by a human.”


Could this be how we get Russia to back off the Ukraine when “sanctions” don't work? Does Saudi Arabia owe us a favor this big?
Saudi Arabia's Oil Price 'Manipulation' Could Sink The Russian Economy
The vice-president of Russia's state-owned oil behemoth Rosneft has accused Saudi Arabia of manipulating the oil price for political reasons. Mikhail Leontyev was quoted in Russian media as saying:
Prices can be manipulative. First of all, Saudi Arabia has begun making big discounts on oil. This is political manipulation, and Saudi Arabia is being manipulated, which could end badly.
The news comes as Reuters reports Saudi officials have been privately admitting to oil market participants that they are comfortable with lower oil prices. According to the news service, the Organization of the Petroleum Exporting Countries (OPEC) is willing to accept prices as low as $80 a barrel for as much as the next two years.
Falling prices are of particular concern to Russia. Russia needs high oil prices to buoy its economy. The country has seen its economic performance slow under the weight of sanctions over Ukraine and weakening domestic demand.


One desktop per course. It reduces the clutter...
Don’t Wait for Windows 10: How to Use Virtual Desktops in Windows XP and Up
One of the big new features Microsoft is touting in Windows 10 is virtual desktops, something that OS X and Linux users have long enjoyed. But while virtual desktops might be getting some tweaks for its public debut in Windows 10, the core technology required for the feature has been available in Windows for years — it’s just been hidden.
Starting way back in Windows XP, Microsoft built a hidden Windows architecture called “desktop objects,” which let Windows launch separate Explorer processes to create up to four virtual desktops. The company now provides a free utility called Desktops that lets users access this hidden Windows feature with a clean and simple Taskbar-based user interface.


Gaming was not a large share of GDP 100 years ago. Now, one game can pull in $1 Billion.
League of Legends to Hit $1 Billion in Revenue
… Despite the fact that the game is free, revenue is made from the in-game purchases that users make in order to enhance the game. The company has now suggested that by the end of the year, they would have reached the $1 Billion mark.


For my students who insist on chattering in class! Android App.
– take over the entire production of your own podcast or radio show with Spreaker Studio. It transforms your device into a fully-equipped radio studio, allowing you to broadcast live or pre-record podcasts while adding tracks and sound effects. Start an active relationship with your listeners by interacting with them directly.

(Related)
How To Run Android Apps in Chrome on Mac / Linux / Windows
It’s now possible to run Android apps in the Chrome browser — it just takes a little bit of work.
Google has officially brought four Android apps to Chromebooks, so it would seem that it’s only a matter of time before more and more Android apps become officially available on the Chrome browser. If you can’t wait, however, let’s run through a few options for running Android apps in Chrome right now.


99 cent Apple App. Formats as well as lists.
– is an app plus an iOS 8 Safari extension that makes it easy to do one key web developer task: view the HTML, JavaScript and CSS source of any web page, with beautiful and customisable syntax highlighting. As an app, you can enter a URL and immediately see the source code behind it. As an extension, it’s even easier.

Sunday, October 12, 2014

We will add this to our Data Mining and Data Analytics course. Perhaps we can create some Open Source tools for smaller businesses. (And of course, my Ethical Hacker are interested!)
How GE generates $1 billion from data
The company can now offer predictive maintenance and optimization services for more than $1 trillion worth of Internet-connected industrial equipment, ranging from medical equipment to jet engines.
… For GE, this is the next phase of the “Industrial Internet,” its in-house phrase for what others call the Internet of Things—the ever-growing collection of connected devices “talking” to businesses with valuable data.
This phenomenon is worth an estimated $1 billion in incremental revenue for the company this year alone, mostly in the form of advanced asset performance management services, according to GE’s top executive.
… Using its Predix technology, GE already captures 50 million data points collected and communicated by 10 million sensors installed on $1 trillion worth of equipment ranging from medical imaging systems to locomotives to jet engines, Immelt said.
… By the end of 2014, there will be more than 40 applications and services based on GE’s platform but the company hopes to spur many others by making Predix available to businesses interested in developing industry-specific solutions.


This could be amusing.
UH Law Center debuts first database of Fortune 500 company codes of conduct
“The University of Houston Law Center today released a searchable database that contains the compliance codes for Fortune 500 companies. The project was led by Houston attorney Ryan McConnell, an adjunct professor at the University of Houston Law Center. McConnell worked with a team of recent graduates and current students to develop the database, which covers 42 different topics.
“The free database allows any company to conduct benchmarking on virtually every compliance area covered in a code of conduct and to spot compliance trends within their industry,” McConnell explained. “In addition to proactively building a program, when compliance failures occur, whether a foreign bribery violation or environmental issue, stakeholders – whether they are shareholders in a lawsuit or criminal investigators – frequently scrutinize the company’s compliance program. This database provides a powerful tool for anyone to evaluate the strength of a company’s compliance program, including subject matters addressed in the code and the organization’s core values.”
The Wall Street Journal has already dubbed the online tool as “catnip for compliance officers.”


Perhaps something my next Statistics class could tackle?
No One Knows How Teens Listen to Music
… After surveying a national group of 7,200 teens, analysts at the research arm of Piper Jaffray discovered that teens like listening to music the 2000-and-late way, through downloaded music onto iTunes libraries or MP3 players:
That's 42 percent of teens listening to music through MP3s, according to the bank. But what does that statistic mean? Piper Jaffray told us that the "42 percent" figure was compiled from four survey questions, but it hasn't revealed how. Nor has it indicated what that percentage indicates—whether it's 42 percent of teens preferring MP3s over other options, or if it's that, 42 percent of the time they listen to music, teens are using MP3s to do it.
… That's a 13 percent increase this year for MP3s. Given those stats, maybe Apple shouldn't have discontinued the iPod.


This game would be better if we could overwrite the face of the lawyer. (You can play these games on your PC.)
Free Android Game: Play A Scumbag Lawyer In RPG Devil’s Attorney
… Devil’s Attorney, a game set in the 1980s and starring a defense attorney dedicated to keeping criminals on the streets, is free until the end of next week as part of a Humble Mobile Bundle promotion. All the games offered are worth checking out, but even if you’re not interested in the bundle, there’s no reason to not pick up this gem.


For my Ethical Hackers (and six-year-olds everywhere).
– is a place for the world to share photo-driven disassembly guides. It is a place to see how to take apart everyday things, and to find things to do once inside. It will void the warranties of devices, but in the process, you may learn a lot about how a device works internally. It can be a simple Zippo lighter or a complicated MacBook Air.


Optimism. Sometimes it's really funny.