Monday, July 05, 2010

Identity Theft from the bottom up.

http://www.bespacific.com/mt/archives/024640.html

July 04, 2010

BJS - Identity Theft Reported by Households, 2007

Identity Theft Reported by Households, 2007 - Statistical Tables: "Presents data on identity theft victimization reported by households from the National Crime Victimization Survey (NCVS). These statistical tables provide 2007 data on rates and types of identity theft, as well as demographic characteristics of victimized households and their monetary losses. Tables compare rates of identity theft victimization in 2005 to 2007. Estimates from the last half of 2008 are also presented and compared to estimates from the same 6-month period in 2007."

[From the report:

In 2007, 7.9 million households, or about 6.6% of all households in the United States, discovered that at least one member had been a victim of one or more types of identity theft.

… In 2007, 32% of households victimized by identity theft reported a financial loss of $500 or more

… Among households experiencing the misuse of personal information, those with a financial loss reported an average household loss of $5,650



I think we need to translate Clausewitz into Internet. Anyone want to help with “On E-War”

http://news.slashdot.org/story/10/07/04/1247241/Behind-Cyberwar-FUD?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Behind Cyberwar FUD

Posted by Soulskill on Sunday July 04, @09:47AM

"The inevitable occurred this week as The Economist broached the topic of cyberwar with a couple of articles in its July 3rd issue. The first article concludes that 'countries should agree on more modest accords, or even just informal "rules of the road" that would raise the political cost of cyber-attacks.' It also makes vague references to 'greater co-operation between governments and the private sector.' When attribution is a lost cause (and it is), international treaties are meaningless because there's no way to determine if a participant has broken them. The second recommendation is even more alarming because it's using a loaded phrase that, in the past couple of years, has been wielded by those who advocate Orwellian solutions. The other article is a morass of conflicting messages. It presumes to focus on cyberwar, yet the bulk of the material deals with cybercrime and run-of-the-mill espionage. Then there's also the standard ploy of hypothetical scenarios: depicting how we might be attacked and what the potential outcome of these attacks could be. The author concludes with the ominous warning that terrorists 'prefer the gory theatre of suicide-bombings to the anonymity of computer sabotage — for now.' What's truly disturbing is that The Economist never goes beyond a superficial analysis of the topic to examine what's driving all of the fear, uncertainty, and doubt (PDF), a subject dealt with in this Lockdown 2010 white paper."



For the “Messing with the Mighty” file. Even the big boys can screw up.

http://news.slashdot.org/story/10/07/04/1530234/YouTube-Hit-By-HTML-Injection-Vulnerability?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

YouTube Hit By HTML Injection Vulnerability

Posted by Soulskill on Sunday July 04, @12:35PM

"Several hours ago, someone found an HTML injection vulnerability in YouTube's comment system, and since then sites such as 4chan have had a field day with popular videos. The bug is triggered by placing a SCRIPT tag at the beginning of a post. The tag itself is escaped, but everything following it is cheerfully placed in the page as is. Blacked out pages with giant red text scrolling across them, shock site redirects, and all sorts of other fun things have been spotted. YouTube has currently blocked such comments from being posted and set the comments section to be hidden by default, and appears to be in the process of removing some of these comments, but the underlying bug does not seem to have been fixed yet."



Another reason for me to avoid PowerPoint presentations – at least in the Ethical Hacking class.

http://hardware.slashdot.org/story/10/07/04/130217/Wireless-Presenters-Attacked-Using-an-Arduino?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Wireless Presenters Attacked Using an Arduino

Posted by Soulskill on Sunday July 04, @11:14AM

"This week Dutch security researcher Niels Teusink described a method of attacking wireless presenter devices at an Amsterdam security conference. He had a demo showing how it is possible to use an Arduino and Metasploit to get remote code execution by sending arbitrary keystrokes to the presenter dongle. He has now released the code and made a blog post explaining how it all works. Better watch out the next time you're giving a presentation using one of these devices!"



Have you ever been frustrated by a poorly designed website? Here's your chance to get even!

http://www.makeuseof.com/dir/destroy-the-web-destroying-websites

Destroy The Web: Have Fun Destroying Websites (Firefox Addon)

Destroy the Web is a free game that comes as an addon for Mozilla Firefox. The addon places a new icon to the left of the URL box. When you visit a webpage and click on this icon, the website’s interface transforms into an arcade game.

The objective of the game is to eliminate all page elements by clicking on them. Your clicking virtually destroys that element – you can even see a small virtual explosion on screen. Meanwhile exciting music is played in the background to keep up with the game’s fast pace. A score is kept of your performance and can be uploaded on Destroy the Web’s leaderboards.

Destroy The Web Addon For Firefox



I'll have to look into this one. It looks like you can add your own “course.” Perhaps you could use this to train employees on various policies.

http://www.makeuseof.com/dir/smartfm-online-learn-quickly

Smart.fm: Helps To Learn Stuff Quickly & Remember Longer

Smart.fm is a fun website that combines education with social networks. The web app serves as an online academic assistant that offers courses to anyone who wants to learn about any topic.

http://smart.fm



I usually ignore these, but Copland is a favorite

http://www.makeuseof.com/tag/10-free-mp3-albums-download-sound-sunday/

10 Free MP3 Albums To Download [Sound Sunday]

Aaron Copland – Copland Fanfare For The Common Man, Billy The Kid, El Salón México

In celebration of US Independence Day on July 4th, Classical.com features a free download from Aaron Copland. Copland, an American pianist and composer of concert and film music, was born in 1900 and lived to become 90 years old. Quite refreshingly, he maintains a MySpace profile with an unknown last login date.

Download the album from Classical.com. Login required.

Sunday, July 04, 2010

Preparing to take over Health Care Records.

http://tech.slashdot.org/story/10/07/03/1432250/Microsofts-Health-y-Patent-Appetite?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Microsoft's Health-y Patent Appetite

Posted by Soulskill on Saturday July 03, @11:27AM

"This week's USPTO patent application disclosures included a trifecta of scary health-related 'inventions' from Microsoft. For starters, Microsoft envisions seeing Kids' Personal Health Records Fed Into Video Games, where they can be used to 'regulate and/or prescribe an individual's behavior while playing electronic games.' Next up is Centralized Healthcare Data Management, which describes how employees' health habits can be 'monitored, tracked or otherwise discovered' so employers can 'incentivize a user for an act or penalize for an omission to act.' Finally, there's Wearing Health on Your Sleeve, which describes a sort of high-tech Scarlet Letter designed to tip off 'doctors, potential dates, etc.' about your unhealthy behavior by converting information — 'number of visits to the gym, workout activities, frequency of workouts, heart rate readings, blood pressure statistics, food consumption, vitamin intake, etc.' — into a visual form so that others can see the data 'on mechanisms such as a mood ring, watch, badge, on a website etc.'"



It's obscure papers like these that allow my Ethical Hackers to flourish!

http://social.venturebeat.com/2010/07/02/facial-recognition-camouflage/

How to camouflage yourself from facial recognition technology

The day when you’ll be able to hold up your phone and identify a stranger through a viewfinder is getting closer.

Google’s Goggles, a mobile app for visual search, has a facial recognition version unreleased to the public, while Israeli startup Face.com’s technology can tag people’s faces in Facebook photos. Facebook even released a basic version of face detection last night, although it doesn’t have recognition.

So in a world where technology chips away at our ability to remain anonymous, how does one reclaim some semblance of control?

It turns out there’s actually a pretty simple way around the facial recognition technology available in the market today, according to Adam Harvey, a graduate student at NYU’s ITP (the same program that produced Foursquare chief executive Dennis Crowley and that Twitter’s location guru Raffi Krikorian taught at).

If you change the contrast in certain parts of your face — either through a watermark or by wearing a strategically-placed sticker or facepaint, recognition technology can’t identify that your face is a human face.

… Harvey said he got his idea from studying camouflage methods use during World War I and World War II. His project, CV Dazzle, is based on the original dazzle camouflage used by the military to hide ships in the 1940s.



Our next President?

http://www.wired.com/epicenter/2010/07/sign-of-the-apocaplypse-lady-gaga-heads-for-10-million-facebook-fan-record/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

Sign of the Apocaplypse: Lady Gaga Heads for 10 Million Facebook Fan Record

Glam pop singer Lady Gaga is on the brink of becoming the first living person to have 10 million fans on a single social networking site, having already overtaken President Obama on Facebook, a British group that measures online popularity said on Friday.



Simple is better than nothing.

http://www.makeuseof.com/tag/youtube-video-editor/

How to Use the New YouTube Video Editor

YouTube has had ways to editor your video for some time now, but it would probably be a stretch to call those features an actual video editor. They were more of a supplement, making it possible to add annotation and other notes to your video. If you needed to cut or change your video you had to use your own video editor, such as iMovie or Windows Movie Maker.

Now, that has changed. YouTube has released the first version of the YouTube Video Editor. This editor honestly doesn’t have a huge amount of functionality, but it does let you accomplish a few things which you couldn’t previously accomplish on YouTube.



A way to move beyond the Biblical Typing Method (seek and ye shall find)

http://www.makeuseof.com/dir/senselang-online-typing-tutor

Sense-Lang: Online Typing Tutor With Multi Language Support

Today many jobs require typing with the computer’s keyboard. Being able to type fast and accurately can save a lot of time on the job. While there are many typing tutor programs out there, tools that are absolutely free and cover multiple languages are rare. Sense-Lang is one of these rare tools.

www.sense-lang.org

Saturday, July 03, 2010

Many unusual aspects... It sounds like the are blaming the credit card processing companies – could it be another Heartland? It also looks like they have no idea what is happening, and therefore can't stop it.

http://www.databreaches.net/?p=12372

IN: Card breach linked to national company

July 2, 2010 by admin

Kristin Maiorano reports:

A local security breach with credit and debit cards has been linked to a national company.

Lafayette Police detective B.T. Brown said the security issue affected the Camilles Sidewalk Cafe restaurants in the area. But Brown said the breach was strictly through Camilles’ parent company, Beautiful Brands International.

“They [local Camilles franchises] had no knowledge of the breach until they were contacted by their corporate office,” he said. “These people were affected from California clear across the United States to New York.”

The people affected were customers at Camilles Sidewalk Cafe restaurants, including some in Tippecanoe County. But Brown said it’s a national issue that’s out of the hands of local law enforcement.

“The information that is sent to the financial institutions is being forwarded to the Secret Service,” he said.

We are working with Visa and Mastercard and the United States Secret Service to stop that breach and prosecute the people responsible,” said Robert Sartin, the attorney for Beautiful Brands International.

Sartin said the credit and debit card breach has likely affected fewer than 20 stores across the country. He said the issue has not been linked to any employees or owners of Camilles restaurants, or any employees at Beautiful Brands.

We believe, based on the evidence we’ve seen so far, that computer hackers have infiltrated the credit card processing system,” Sartin said. “And we believe that we’ll be able to stop that in the future.”

Read more on WLFI.

Interestingly, I had been tipped that Beautiful Brands had been breached almost two months ago, but when I contacted Beautiful Brands, they never returned my phone calls, and their PR representative, despite promising to respond, never got back to me after numerous attempts and reminders. So now they are saying that they believe they’ll be able to stop the infiltration of the POS “in the future?” When exactly did they secure the system this time around? For how long was their system compromised without their knowledge?

[From the article:

Sartin said the company hopes to contain the problem nationally within a couple of weeks. He said the investigation into who's behind the crimes will be complete shortly after that happens.

… He said the security breach has affected about five local financial institutions to the scale of more than $100,000, but he hasn't seen a local debit or credit card complaint for several weeks. [So this has been going on for a LONG time! Bob]



Is this also related to a payment processor?

http://news.softpedia.com/news/Credit-Card-Breach-at-Destination-Hotels-Resorts-145843.shtml

Credit Card Breach at Destination Hotels & Resorts

PoS processing system affected

June 30th, 2010, 15:22 GMT

Unidentified hackers have managed to compromise the credit card processing system at Destination Hotels & Resorts. The company, which operates a chain of hotels in the United States, claims that only credit cards that were physically swiped were affected.

Destination is headquartered in Englewood, Colorado, but runs over thirty hotels and resorts nationwide, including in popular vacation spots like Aspen, Lake Tahoe or Maui. In a press release posted on its website, the company announced that it was the victim of a credit card fraud scheme, which involved malware being installed into its point-of-sale processing system. It appears that the attackers operated remotely.

… We know we are not the first hotel company to be victimized by this kind of attack... [We just assumed we didn't need security... Bob'



Another case of “Were the school, so we know best. Parents are ignorant, so we need to show them how to 'parent.'”

http://www.pogowasright.org/?p=11976

Big Brother row as ‘food police’ secretly photograph schoolchildren’s packed lunches

July 2, 2010 by Dissent

Sarah Harris:

Teachers have used ‘Big Brother’ tactics to secretly spy on children’s lunch boxes, it has been revealed.

They have covertly photographed pupils’ packed lunches over the last six months and analysed the contents.

Staff have awarded marks to the food and then revealed their findings to outraged parents, offering them advice on how to improve nutrition.

Education bosses have now put a stop to the scheme in Gloucestershire after discovering the extent of the surveillance.

Read more in the Daily Mail.



No skulking here! “We're going to listen to your phonecalls and read your email.” ...and you thought Facebook was bad.

http://yro.slashdot.org/story/10/07/02/2137207/Indian-Government-Threatens-RIM-Skype-With-Ban?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Indian Government Threatens RIM, Skype With Ban

Posted by Soulskill on Friday July 02, @06:16PM

"India's Department of Telecommunications has been asked by the government to serve a notice to Skype and Research In Motion to ensure that their email and other data services comply with formats that can be read by security and intelligence agencies, or face a ban in India if they do not comply within 15 days. A similar notice is also being sent to Google, asking it to provide access to content on Gmail in a readable format."



Colleges are moving everything online – classes, libraries and textbooks for example. This requires them to severely limit the capabilities of their networks. Could my Ethical Hacking class find a way around the controls? Should they have to?

http://yro.slashdot.org/story/10/07/02/2019213/Colleges-Risk-Losing-Federal-Funding-If-They-Dont-Fight-Piracy?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Colleges Risk Losing Federal Funding If They Don't Fight Piracy

Posted by Soulskill on Friday July 02, @04:50PM

"The US government is making colleges and universities join in the fight against digital piracy by threatening to pull federal funding. Beginning this month, a provision of the Higher Education Opportunity Act of 2008 requires colleges to have plans to combat unauthorized distribution of copyrighted materials on their networks. Colleges that don't do enough could lose their eligibility for federal student aid. 'Their options include taking steps to limit how much bandwidth can be consumed by peer-to-peer networking, monitoring traffic, using a commercial product to reduce or block illegal file sharing or "vigorously" responding to copyright infringement notices from copyright holders.'"



'cause it's the best or 'cause it's the best that's not Microsoft?

http://www.networkworld.com/community/node/63144

Firefox: The official web browser of IBM



An intresting TED talk to motivate my students?

http://www.bespacific.com/mt/archives/024635.html

July 03, 2010

Clay Shirky: How cognitive surplus will change the world

"Clay Shirky looks at "cognitive surplus" -- the shared, online work we do with our spare brain cycles. While we're busy editing Wikipedia, posting to Ushahidi (and yes, making LOLcats), we're building a better, more cooperative world."



This means I'd have to look at my students? (shudder)

http://www.freetech4teachers.com/2010/07/simple-guide-to-google-video-chat.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+freetech4teachers%2FcGEY+%28Free+Technology+for+Teachers%29

Friday, July 2, 2010

A Simple Guide to Google Video Chat

Google Video Chat is a nice alternative to Skype available to anyone using Gmail. Some folks aren't aware of how easy it is to video chat using Google Video Chat. Therefore, yesterday Google released a simple video guide and PDF guide about it.



Phoney email is okay? Perhaps they get “anonymous”

http://www.killerstartups.com/Web-App-Tools/wheatt-com-a-new-way-to-bookmark-content

Wheatt.com - A New Way To Bookmark Content

http://www.wheatt.com/

Terming Wheatt the result of fusing together a search engine and a read-it-later app is the best way there is to introduce it to you. By installing the provided bookmarklet you will be capable of finding specific information within any page that you are reading, and the ability to tag what you have found will let you access the information more naturally later on.

That is, when you are on a page that you find interesting you just use the bookmarklet to add these tags that you think will let you find the information more succinctly afterwards. You can work with dates, domains, words… it is all taken into account.

Installing Wheatt is a mere matter of dragging and dropping the bookmarklet that is provided into your browser’s toolbar, and signing up by submitting an email address and a password. It is interesting to note that you are not required to supply a working email at all - just make sure to remember the password. That will do the trick. No fees have to be paid for using this service, and no other kind of information is ever requested.

Friday, July 02, 2010

It might be useful to collect these and put together the questions management will need to answer after a breach – and I suspect they are questions that should also be asked/answered in normal day-today monitoring of security.

http://www.databreaches.net/?p=12358

And so it starts: Blumenthal Investigating Wellpoint Security Breach

July 2, 2010 by admin

From the CTWatchdog:

Connecticut Attorney General Richard Blumenthal is investigating a massive security breach that allegedly compromised private financial and health information on nearly a half million WellPoint consumers, including thousands in Connecticut.

In a letter to WellPoint Inc., Blumenthal has requested detailed information about how the breach occurred, what steps have been taken to protect the affected individuals, and what new procedures have been adopted to prevent future breaches.

Blumenthal is also calling on WellPoint to provide the same protection that other companies have done after similar breaches — at least two years of credit monitoring, at least $25,000 of identity theft insurance and expenses covered to impose and later lift any security freeze on consumers’ credit reports.

[...]

Blumenthal is seeking a response by July 9. The information he is seeking includes:

  • the name and address of the computer company who updated the online application process in October 2009; [“We'd also like to send a letter to ______________” Bob]

  • What security protections, hardware or software, were present or used on the online application system prior to the upgrade;

  • the categories of information contained on the online system and compromised by this breach;

  • the process by which someone would be able to “manipulated the URL address” in order to view other individuals’ information;

  • Prior measures to safeguard sensitive information;

  • how and when WellPoint first learned about the breach;

  • the circumstances under which the information was accessed or viewed by anyone without authorization;

  • what, if any, security protocols or procedures were in effect to prevent the exposure of private information to users or applicants using the online system;

  • the number of individuals affected by this incident and their state of residence;

  • all steps taken to determine what caused the flaw in the online application system and the time period in which private information was publicly available;

  • how WellPoint determined that the information was accessed by fewer than 10 unidentified computers — someone other than the health insurer’s employees and affiliates;

  • copies of all investigative reports or audits relative to this incident;

  • all steps taken or that will be taken to warn all affected persons that their private information may have been compromised, and copies of any notification letters already sent;

  • an outline of any plan to prevent a future breach and a timeline for implementing that plan; and

  • corporate policies regarding securing servers, databases, or other systems containing private information.



Here we go again...

http://www.thetechherald.com/article.php/201026/5818/Sony-forced-to-recall-534-000-VAIO-notebooks

Sony forced to recall 534,000 VAIO notebooks

… According to Sony, the recall covers certain models in the VAIO F and VAIO C series and has been issued in light of a temperature-control defect that can lead to the production of potentially dangerous levels of heat within the hardware.



How to build the ultimate facial recognition database?

http://gizmodo.com/5577986/facebook-will-now-recognize-you-in-that-shameful-party-photo

Facebook Will Find Your Face In That Shameful Party Photo

Facebook appears to have added a shutterbug's [and Intelligence agencies Bob] dream feature: Face detection technology. As soon as you upload a picture, the feature realizes that there are humans in it and preselects their faces. You just add the poor souls' names.



Something to amuse my Anti-Trust lawyer friends...

http://news.cnet.com/8301-30684_3-20009502-265.html?part=rss&subj=news&tag=2547-1_3-0-20

Regulators bound to stack up over Google-ITA

When will the U.S. government eventually decide to confront Google?

That's really the only question that needs to be debated in the wake of Google's announcement that it plans to acquire ITA Software, the leading provider of flight information from airlines to travel Web sites, for $700 million in cash. As it stands, the deal would marry the world's leading Internet search company with a crucial link in the online flight reservation process, making life for executives at online travel sites such as Orbitz, Kayak, and Expedia a whole lot more complicated.

… So from Google's perspective, this is a user-friendly deal that will simply allow it to offer a better service. It also doesn't hurt that if Google turns into the predominant online destination for travel search, revenue from ads placed next to those search results will add to Google's already lucrative search advertising business.

But there are dozens of other sites that already offer these services by licensing ITA's software, including Google archrival Microsoft's Bing search engine and travel-oriented sites like the ones described above. So why didn't Google simply license the software as well? CEO Eric Schmidt said Google considered that, but concluded it would be unable to do the "deep integration" with search results and innovation in travel search that it desired without merging Google's technology and ITA's.



For your Computer Security manager or anyone who would like to understand what can be done to secure your computers.

http://techcrunch.com/2010/07/01/ibm-acquires-enterprise-data-security-software-company-bigfix/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

IBM Acquires Enterprise Data Security Software Company BigFix

IBM is making another acquisition today, buying up computer security software company BigFix. Terms of the deal were not disclosed.

BigFix security software identifies all of a company’s PCs, laptops, server and then monitors and flags IT administrators when devices are not in compliance with corporate IT security standards. BigFix’s software promises to make security fixes across at least 500,000 machines in a matter of minutes.



Worth reading.

http://www.bespacific.com/mt/archives/024623.html

July 01, 2010

New GAO Reports: Implementing Cloud Computing,

  • Information Security: Governmentwide Guidance Needed to Assist Agencies in Implementing Cloud Computing, GAO-10-855T, July 01, 2010

  • Biosurveillance: Efforts to Develop a National Biosurveillance Capability Need a National Strategy and a Designated Leader, GAO-10-645, June 30, 2010

  • Information Security: Federal Guidance Needed to Address Control Issues with Implementing Cloud Computing, GAO-10-513, May 27, 2010



An interesting title. One would assume this incorporates responsibilities for protecting privacy and securing data... Will they be able to spend any money, since Obama is suspending many IT projects.

http://www.bespacific.com/mt/archives/024626.html

July 01, 2010

FCC Launches Data Innovation Initiative

News release: "The Federal Communications Commission today launched the Data Innovation Initiative, the agency’s latest action to modernize and streamline how it collects, uses, and disseminates data. With this launch, the FCC continues the changes that were made as part of a comprehensive reform effort that is improving the agency’s fact-based, data-driven decision-making. To lead the Data Innovation Initiative, FCC Chairman Julius Genachowski today established a new, cross-bureau data team, led by the agency’s first-ever Chief Data Officer... The launch of the Data Innovation Initiative, the appointment of the data team, and the release of the public notices follows other data innovations recently launched at the FCC, which include improving the search on ECFS, making more information machine-readable at www.reboot.fcc.gov/data, tools that allow consumers to test the performance of their broadband connections that can be found at www.broadband.gov, an interactive Spectrum Dashboard, and collaboration with the NTIA to produce a National Broadband Map."



definitely NSFW, but funny!

http://techcrunch.com/2010/07/01/best-buy-iphone-4-evo-4g/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

Best Buy Trying To Fire Employee Over Those Hilarious EVO Versus iPhone Videos



They will find I live in Lynchberg, Tennessee. (Do people still drink water?)

http://science.slashdot.org/story/10/07/01/1815204/Things-You-Drink-Can-Be-Used-To-Track-You?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Things You Drink Can Be Used To Track You

Posted by timothy on Thursday July 01, @02:40PM

sciencehabit writes with an intriguing story about the potential of figuring out where people have been by examining their hair:

"That's because water molecules differ slightly in their isotope ratios depending on the minerals at their source. Researchers found that water samples from 33 cities across the United State could be reliably traced back to their origin based on their isotope ratios. And because the human body breaks down water's constituent atoms of hydrogen and oxygen to construct the proteins that make hair cells, those cells can preserve the record of a person's travels. Such information could help prosecutors place a suspect at the scene of a crime, or prove the innocence of the accused."

Or frame someone by slipping them water from every country on the terrorist watchlist.



Links to Georgetown U. Interesting statistics!

http://www.docuticker.com/?p=36837

Help Wanted: Projections of Jobs and Education Requirements Through 2018

[Here's Colorado: http://www9.georgetown.edu/grad/gppi/hpi/cew/pdfs/colorado.pdf



Try the free version first! If it is all you need, STOP! If not, you have narrowed your search to the specific features you require.

http://www.makeuseof.com/tag/the-5-best-most-reliable-surces-to-download-freeware-programs/

The 5+ Best Sources To Download Freeware Programs

The good news is that there are thousands of software developed everyday that do most of what commercial software does, but for free!



Used with care, this can be powerful.

http://www.makeuseof.com/tag/how-to-make-a-visual-resume-with-powerpoint-in-3-steps-stand-out-from-the-crowd/

How to Make a Visual Resume with PowerPoint in 3 Steps & Stand Out from the Crowd



It's here so you better learn how to live with it...

http://www.makeuseof.com/tag/7-great-completelyfree-ebooks-social-media-read/

7 Great Completely Free eBooks on Social Media You Have to Read



Start your geeks young!

http://www.makeuseof.com/tag/5-computer-games-toddlers/

5 Best Computer Games for Toddlers



Once you find a new book, link to your local library and put it on hold. Simple!

http://www.freetech4teachers.com/2010/07/your-next-read-book-recommendations.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+freetech4teachers%2FcGEY+%28Free+Technology+for+Teachers%29

Your Next Read - Book Recommendations

Your Next Read is a neat little site that provides you with a web of book recommendations based on the authors and books you already like.

Thursday, July 01, 2010

You can trust the government to keep your personal information safe from the government

http://www.pogowasright.org/?p=11945

Opt-Out Privacy Policy for Govt Web Sites “Weird” – EPIC

July 1, 2010 by Dissent

From EPIC.org:

The White House has announced a new “Clear Notice and Personal Choice” policy for the use of Web Measurement and Customization Technologies for government web sites. The policy is remarkable in that there does not appear to be any legal basis to allow federal agencies to routinely disclose personal information of citizens to private companies. The policy is accompanied by new Guidance for Agency Use of Third-Party Websites and Applications. The White House also announced a National Strategy for Trusted Identities in Cyberspace. EPIC had urged the White House to uphold Privacy Act obligations in use of web 2.0 services. For more information, see EPIC – Privacy and Government Contracts with Social Media Companies.



If you haven't tried spokeo.com you should. Even the free preview illustrates what you can grab (no matter how inaccurately) from the Internet.

http://www.pogowasright.org/?p=11939

CDT Files FTC Complaint Against Spokeo

June 30, 2010 by Dissent

Sean Brooks of CDT writes:

Today we filed a complaint with the FTC and multiple state attorney generals’ offices against online data broker and aggregator Spokeo, Inc. We hope the FTC will view this complaint as an opportunity to tackle the growing issue of online — and offline — data aggregators offering unregulated consumer profiles.

Read more on CDT.

Complaint.

Grant Gross of IDG has more on this.



For my Ethical Hacker class. Also I wonder why there has been so much information released about these people? Is the FBI bragging or laying the foundation for a budget request?

http://www.networkworld.com/news/2010/063010-russian-spy-ring.html?hpg1=bn

Russian spy ring needed some serious IT help

The Russian ring charged this week with spying on the United States faced some of the common security problems that plague many companies -- misconfigured wireless networks, users writing passwords on slips of paper and laptop help desk issues that take months to resolve.

In addition, the alleged conspirators used a range of technologies to pass data among themselves and back to their handlers in Moscow including PC-to-PC open wireless networking and digital steganography to hide messages and retrieve them from images on Web sites.



So apparently this list isn't to ensure that extra attention is paid when these folks travel (run them through the nude image scanner, full cavity search, etc.) it's to allow discrimination based on religion? Or maybe it's based on ethnicity or national origin... Or maybe (and this is truly scary) there is “no particular reason”

http://www.wired.com/threatlevel/2010/06/no-fly/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

Too Scary to Fly, Not Scary Enough to Arrest

Ten U.S citizens and residents, three of whom are veterans, are stuck abroad or cannot fly within or out of the United States because they are wrongly on a no-fly list, according to a federal lawsuit lodged Wednesday.

The Oregon federal court case claims the plaintiffs, many with Middle Eastern names who have committed no legal wrongdoing, have asked the Department of Homeland Security and Transportation Security Administration for an explanation, to no avail.



If they are US citizens pirating US films, what are ICE and Homeland Security doing there?

http://news.cnet.com/8301-31001_3-20009348-261.html?part=rss&subj=news&tag=2547-1_3-0-20

Feds seize cash, Web sites of alleged film pirates

A week after U.S. Vice President Joe Biden warned that the government would start cracking down on illegal file sharing, the feds swooped in and seized assets belonging to operators of accused movie-pirating sites.

… Authorities are searching for operators of the sites as part of an ongoing criminal investigation, according to Virginia Kice, a spokeswoman for the U.S. Immigration and Customs Enforcement (ICE). The crimes that the operators are accused of committing weren't clear, but some of the sites are accused of distributing film copies prior to their theatrical release. [So these were foreign films? Bob]

As of 3 p.m. PDT, some of the sites were still operating, but government officials said they anticipated the sites would come under government control within hours. [I wonder how much of this is currently 'in the cloud' and how much will be driven there by these actions? Bob]

The investigation involved multiple law enforcement groups, including the U.S. District Court for the Southern District of New York and ICE, a unit of the Department of Homeland Security.

Last week, Biden and Victoria Espinel, the U.S. intellectual property enforcement coordinator, told reporters that they wanted to send a message to counterfeiters and pirates that this administration was intent on protecting the nation's intellectual property.


(Related) This could be a government attempting to control the information available to its citizens – or maybe they too have an active movie/music lobby.

http://torrentfreak.com/damaging-to-culture-online-library-smashed-by-police-100630/

Damaging To Culture”, Online Library Smashed By Police

There is outrage amongst sections of the online community as it is revealed that at the behest of copyright holders, a free online library has been raided by police. Chitanka carried user translated and submitted books, poems and other literature and as an “altruistic library” was thought to be legal under current legislation. Instead the site was raided and subjected to criminal procedures.



Mon Dieu! Have the French gone completely bonkers?

http://yro.slashdot.org/story/10/06/30/1836231/France-Says-D-Star-Ham-Radio-Mode-Is-Illegal?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

France Says D-Star Ham Radio Mode Is Illegal

Posted by timothy on Wednesday June 30, @03:15PM

"Citing 'national security concerns,' the French Autorité de Régulation des Communications Électroniques et des Postes (ARCEP, France's equivalent of the US's FCC) has ruled that D-Star, an amateur radio digital signal mode used world-wide, is illegal because it could allow operators to connect to the Internet. The ARCEP also cites alleged concerns regarding cryptography and national security as well as the use of a proprietary codec. While it's true that the D-Star codec is proprietary, its owner has openly licensed it (for a fee, of course) to any manufacturer who wants to build it into their equipment. Any licensed amateur radio operator who lives within the EU can sign an online petition protesting this decision."



Isn't this just polite behavior that all online services should provide? Corporate Security Managers should be checking employee login locations and flagging those that fall outside normal parameters. Think of banks that fail to check the IP address of customers who move money via electronic banking systems.

http://arstechnica.com/tech-policy/news/2010/06/suspicious-login-protection-extended-to-all-google-accounts.ars

Suspicious login protection extended to all Google accounts

When your credit card gets too much activity from random parts of the world, your bank usually shuts it off, or at least gives you a call to make sure all those charges are legit. Now, Google is implementing a similar strategy across all elements of your Google account: if the company detects what it considers to be suspicious logins for your Gmail, Google Calendar, Blogger, Buzz, or other Google accounts, it will flag your dashboard and let you decide how to proceed.



Just in time for my next Statistics class. Also, I'm noting this type of display more frequently – there must be tools that make this a much simpler process than it used to be.

http://www.bespacific.com/mt/archives/024614.html

June 30, 2010

BLS: New Data Access Tool Quarterly Census of Employment and Wages - State and county map application

"The Bureau of Labor Statistics (BLS) has developed an interactive state and county map application available at beta.bls.gov. The application displays geographic economic data through maps, charts, and tables, allowing users to explore employment and wage data of private industry at the National, State, and county level. Throughout this application, URLs are specific to the data displayed, so links can be bookmarked, reused, and shared. The application includes maps, charts, tables, and a link to standard BLS data tables and graphs."

http://beta.bls.gov/



Everything old is new again. I had hoped this would be more useful, but there are already many free password crackers out there.

http://it.slashdot.org/story/10/07/01/1239234/New-Tool-Reveals-Internet-Passwords?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

New Tool Reveals Internet Passwords

Posted by CmdrTaco on Thursday July 01, @09:18AM

"A new password cracking tool was released today that instantly reveals cached passwords to Web sites in Microsoft Internet Explorer, mailbox and identity passwords in all versions of Microsoft Outlook Express, Outlook, Windows Mail and Windows Live Mail."

[For example:

http://www.nirsoft.net/utils/#password_utils



For researchin' stuff. Searches in many search engines at the same time.

http://www.nginer.com/

Nginer



This looks interesting (besides, I couldn't ignore the Swiss Army knife bit)

http://www.killerstartups.com/Web-App-Tools/usekit-com-an-advanced-way-to-capture-information

UseKit.com - An Advanced Way To Capture Information

http://usekit.com/

While I was testing UseKit I found myself thinking, “Boy, this is a bit like a Swiss Army knife for the Internet”. And I wouldn’t be surprised if most people who test it out feel exactly like that at the end of the trial.

UseKit can not be termed “a tool”; it is “a collection of tools” that are not necessarily interconnected, but they do have one common denominator: they all make for increasing your productivity when it comes to accessing and processing information found online.

For starters, UseKit will let you capture information via a provided bookmarklet, and once you have retrieved it you can proceed to share it with whomever you want. Besides, you will be capable of using sticky notes and a virtual highlighter in order to further capture information without having to leave the page that you are viewing.

In order to give UseKit a try, all that you need to do is drag and drop the provided bookmarklet into position. Upon doing so, the UseKit toolbar will become visible. And note that you can actually personalize it in order to make it fully accommodate your needs.

[From the website:

No installation required. Register it's free.



Another multi-tool, including Bibliography creator! Includes a Teacher's Guide

http://www.freetech4teachers.com/2010/06/yolink-search-refinement-and.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+freetech4teachers%2FcGEY+%28Free+Technology+for+Teachers%29

Tuesday, June 29, 2010

YoLink - Search Refinement and Bookmarking

YoLink is a free service that helps students refine their web searches and easily bookmark their findings in Diigo and EasyBib. YoLink also integrates with Google Docs account so that users can quickly move the content you bookmark in YoLink into a document. YoLink is plug-in for Firefox and Chrome.



I've linked to several of these videos for my Math classes. Better than most Math videos!

http://www.makeuseof.com/dir/mathtv-com-math-problems-solved-online

MathTV.com: See Math Problems Solved & Explained Online

www.mathtv.com

Similar sites: Multiplication Tool, MathRun, Carrots Sticks, MathWay, and Sporcle.

Wednesday, June 30, 2010

It is increasingly difficult to believe that hospitals and their supporting contractors have never heard of encryption or security/privacy 'best practices.' I'd think by now that contractors would want to charge extra to handle unencrypted data – at least enough to insure against the cost of a breach.

http://www.phiprivacy.net/?p=2975

New York hospital loses data on 130,000 via FedEx

By Dissent, June 30, 2010 6:03 am

Robert McMillan reports:

New York’s Lincoln Medical and Mental Health Center is notifying patients that their personal information may have been compromised after seven CDs full of unencrypted data were FedExed by a hospital contractor and then lost in transit.

The CDs were sent by the hospital’s billing processor, Siemens Medical Solutions USA, around March 16, but never arrived at their intended destination. They included sensitive health and personal information including Social Security numbers, addresses, dates of birth, health plan numbers, driver’s license numbers and even descriptions of medical procedures, the hospital said on a note posted to its Web site.

Read more on Computerworld.



Can you say, “Ubiquitous?”

http://www.pogowasright.org/?p=11920

ACLU Study Highlights U.S. Surveillance Society

June 29, 2010 by Dissent

David Kravets reports:

Welcome to the surveillance society.

That’s what the American Civil Liberties Union concluded Tuesday with a report chronicling government spying and the detention of groups and individuals “for doing little more than peacefully exercising their First Amendment rights.”

The report, Policing Free Speech: Police Surveillance and Obstruction of First Amendment-Protected Activity (.pdf), surveys news accounts and studies of questionable snooping and arrests in 33 states and the District of Columbia the past decade.

Read more on Threat Level.



Sometimes we make surveillance too easy. Also, for my Ethical Hackers

http://www.wired.com/threatlevel/2010/06/foursquare-privacy/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

White Hat Uses Foursquare Privacy Hole to Capture 875K Check-Ins

If you have checked in with Foursquare in San Francisco in the last three weeks, Jesper Andersen probably knows where and when — even if you’ve set your check-ins to be published to friends only.

Andersen, a coder who recently built a service called Avoidr that helps you avoid social network “friends” you don’t really like, figured out that Foursquare had a privacy leak because of how it published user check-ins on web pages for each location.



“How dare you make it easy for our customers to leave!” (Implications for Cloud Computing)

http://techcrunch.com/2010/06/29/twitpic-posterous-lawyers/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

Twitpic Blocks Posterous’ Import Tool; Out Come The Lawyers

Well that didn’t take long. Halfway into their big 15 importers in 15 days campaign, Posterous has managed to make one of their competitors very angry. Twitpic is so angry, in fact, that they’re blocking the service and threatening legal action.

This morning, Posterous introduced their new “Rescue your photos from TwitPic” tool — a one-click way to import your photos from Twitpic over to your Posterous blog. This is the same type of importer Posterous has already made for Ning, Vox, Tumblr and a host of other services



...and us normal people too?

http://yro.slashdot.org/story/10/06/29/1724233/Why-Google-Bing-Yahoo-Should-Fear-ACTA?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Why Google, Bing, Yahoo Should Fear ACTA

Posted by kdawson on Tuesday June 29, @01:44PM

"US intellectual property law expert Jonathan Band has warned that Silicon Valley's search engines, hosting companies, and e-commerce giants have much to fear from the Anti-Counterfeiting Trade Agreement, negotiations for which continued in Switzerland today. The fear for search engines in particular is the erosion of 'fair use' protections and introduction of statutory damages, both of which could lead to more copyright claims from rights holders."

The article links a marked-up ACTA draft (PDF) that Band and a coalition of library organizations and rights groups believe is more balanced. Quoting Band: "Our high-level concern is that ACTA does not reflect the balance in US IP law, [which] contains strong protections and strong exceptions. ACTA exports only the strong protections, but not the strong exceptions."



Using the “Streisand effect,” deliberately or not. What would cause an “automatic” deletion?

http://techcrunch.com/2010/06/29/facebook-boycott-bp-page/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

Facebook Disabled The Massively Popular Boycott BP Page “In Error”

This morning, there was some ruckus on the Web when Facebook seemingly flat out deleted the Boycott BP page, which has amassed some 734,000 ‘fans’ on the social network so far.

… Following multiple reports on the Web about the mysterious apparent removal of the page and its return, we contacted Facebook to learn what happened exactly. Moments ago, the company provided us with an official statement on the matter, which remains quite vague but at least acknowledges there was no malicious intent involved, let alone a conscious decision by someone at Facebook to shut the page down:

“The admin profile of the Boycott BP Page was disabled by our automated systems therefore removing all the content that had been created by the profile. After a manual review we determined the profile was removed in error and it has now been restored along with the Page.”

Asked what triggered the automated systems to flag said profile in the first place, Facebook declined to go into detail because it fears people knowing about how their systems work will “weaken their effectiveness”.


(Related) Perhaps extreme language and an argumentative stand isn't the best way to win friends and influence people?

http://entertainment.slashdot.org/story/10/06/30/1019224/ASCAP-War-On-Free-Culture-Escalates?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

ASCAP War On Free Culture Escalates

Posted by kdawson on Wednesday June 30, @08:13AM

"After ASCAP declared war on free culture and Creative Commons responded on the incident, the war of words is escalating. Drew Wilson of ZeroPaid has been following this story closely. The EFF responded to the ASCAP letter, saying 'we don't think that ASCAP characterized EFF and its work accurately. We believe that artists should be compensated for their work, and one proposal we have for that is Voluntary Collective Licensing.' The response from the EFF came with a study and a letter written by one irate ASCAP member who donated to the EFF and to Public Knowledge as a result of the ASCAP letter. Public Knowledge also responded to the letter, saying 'It's obvious that the characterization of Public Knowledge is false. Public Knowledge advocates for balanced copyright and an open Internet the empowers creators and the public. What we oppose are overreaching policies proposed by large corporate copyright holders that punish lawful users of technology and copyrighted works.' Now the National Music Publishers Association has weighed in to support ASCAP, saying that organizations like Public Knowledge and the EFF 'have an extremist radical anti-copyright agenda' according to a transcript of a speech posted on Billboard. Public Knowledge has dismissed those allegations, saying 'anybody who has spent more than 5 minutes on our website or talking to our staff knows that these things are not true.'"



I'm in my local library at least twice a week and probably on their website weekly too.

http://www.bespacific.com/mt/archives/024600.html

June 29, 2010

Association of College and Research Libraries - Futures Thinking for Academic Librarians: Higher Education in 2025

Futures Thinking for Academic Librarians: Higher Education in 2025 (June 2010)

  • "For academic librarians seeking to demonstrate the value of their libraries to their parent institutions, it is important to understand not only the current climate. We must also know what will be valued in the future so that we can begin to take appropriate action now. This document presents 26 possible scenarios based on an implications assessment of current trends, which may have an impact on all types of academic and research libraries over the next 15 years. The scenarios represent themes relating to academic culture, demographics, distance education, funding, globalization, infrastructure/facilities, libraries, political climate, publishing industry, societal values, students/learning, and technology."

[I particularly like these “Futures”:

2. Academic niche networking

5. Breaking the textbook monopoly



A visual summary of online video

http://www.tammycamp.com/2010/06/28/the-state-of-online-video.html

The State of Online Video



For my Ethical Hacking class. Ignorance of the technology is no excuse (but does make our job easier...) NOW will they consider “Security by Default?”

http://news.slashdot.org/story/10/06/29/1840241/Hack-ATampT-Voicemail-With-Android?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Hack AT&T Voicemail With Android

Posted by kdawson on Tuesday June 29, @09:15PM

"It is shockingly easy to gain access to an AT&T customer's voicemail using caller ID spoofing techniques. What's worse is that AT&T knows about it. On your Android phone, download one of the two caller ID spoofing programs. Input the number of your target as the destination number and then enter the same number as the spoofed caller ID. Then connect your call. If the target has not added a voicemail password (the default is no password), you will be dropped into a random menu of their voicemail and eventually can drill up or down to get what you want. You can change greetings, erase messages, send voicemails out of the target account, and much more. How many politicians up in arms about Google Wi-Fi sniffing will want to know more about this?"



One of the Statistical tests I think my students must master. Think of it as an “Is this Bull?” test.

http://politics.slashdot.org/story/10/06/29/1856248/Daily-Kos-Pollster-Made-Up-Numbers?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Daily Kos Pollster Made Up Numbers

Posted by kdawson on Tuesday June 29, @03:18PM

jamie found a story up on Daily Kos revealing that the polling firm they had contracted with for 18 months, Research 2000 or R2K, apparently made up or at least manually tweaked its polling results. The blog published a preliminary report by a team of statistics gurus (Mark Grebner, Michael Weissman, and Jonathan Weissman), and it is an exemplar of clarity and concision. The team reports, "We do not know exactly how the weekly R2K results were created, but we are confident they could not accurately describe random polls." Daily Kos will be filing a lawsuit against its former pollster.

"For the past year and a half, Daily Kos has been featuring weekly poll results from the Research 2000 (R2K) organization. These polls were often praised for their 'transparency,' since they included detailed cross-tabs on sub-populations and a clear description of the random dialing technique. However, on June 6, 2010, FiveThirtyEight.com rated R2K as among the least accurate pollsters in predicting election results. Daily Kos then terminated the relationship. One of us (MG) wondered if odd patterns he had noticed in R2K's reports might be connected with R2K's mediocre track record, prompting our investigation of whether the reports could represent proper random polling. ... This posting is a careful initial report of our findings, not intended to be a full formal analysis but rather to alert people not to rely on R2K's results."



For my students who don't like to read? Now they can listen to my blog on their cellphones while driving to class.

http://www.makeuseof.com/dir/blogradio-converts-rss-to-audio/

BlogRadio: Converts Rss To Audio

BlogRadio is a great tool that takes your RSS feeds and convert them to audio speech so you can listen to them instead of reading them.

You can choose between an almost natural male or female voice and even listen to the feeds on your smart phone. Moreover, everything is stored in the cloud so you get unlimited storage. This desktop tool works on Windows, Mac as well as Linux. You can control your audio files and even see pictures included in the RSS feeds. The desktop client is automatically updated every time you launch it.

www.podblogr.com

Similar tools: SpokenText



For my website students and my Ethical Hackers

http://www.makeuseof.com/tag/choose-browser-open-specific-link-firefox-extension/

How To Open Specific Links With Other Browsers While Using Firefox

… There are ... times where I need to open a link in a new browser window like in Internet Explorer, or if I need to test a website for usability, I might need to test a page in several different browsers.

In the past you would open a link in a new browser window by opening the browser and browsing to the page you need to test or you could fire up a tool like Browsershots that we have previously profiled. But what if you want an easy way to tell Firefox to open that link in a different browser? Well now you can with a Firefox extension called Open With.

You can find the extension here.