Tuesday, March 29, 2011


Once more, Gary Alexander points me to a really interesting page...

http://www.computerworld-digital.com/computerworld/op_cloud2011?sub_id=IY74RprF2aNm#pg1

Your Strategic Guide to Operationalizing Cloud



One thing about being late to the party is that you can see how others have screw up...

http://www.pogowasright.org/?p=22054

Information Privacy Law Set to be Enacted in South Korea in September

March 29, 2011 by Dissent

Song reports:

Korea’s Ministry of Public Affairs and Security announced a new set of laws on Tuesday in a move to protect private information.

According to the new law, set to go in effect in September, will require some 3-and-a-half million businesses and public institutions to publish their policy for processing private information and prohibit them from using resident registration numbers at their own discretion.

All service providers must now get separate permission to use private information for commercial purposes and report information leaks immediately.

A presidential committee will be set up as well to deliberate on private information laws.

Source: Arirang

So South Korea is imposing opt-in requirements and mandating data breach notification and …. we still don’t.



It seems to me we are finding more areas to dispute...

http://www.pogowasright.org/?p=22043

Europe and U.S. converging on Internet privacy

March 28, 2011 by Dissent

Eva Dou of Reuters reports:

Few topics are more sensitive for Web users, or more likely to raise concerns in the corridors of Facebook or Google, than how to regulate privacy.

For years the United States and Europe, with around 700 million Internet users between them, have diverged in their approach to policing the Web.

But the two sides are converging in their Web privacy positions, partly through intensive meetings in recent months between regulators from Washington and Brussels.

There are still many specifics to be worked out — final legislative proposals are not expected from the European Union until later this year and the United States in June or July — but officials are confident about steadily narrowing the gap.

Read more on Reuters.



For my Ethical Hackers. “Disabling” suggests you are hiding something. Might I suggest “locating” yourself in the office of a Computer Law Professor at your local Law School? I've been sharing an office for years...

http://www.makeuseof.com/tag/disable-fake-location-firefox-internet-explorer-chrome/

How To Disable Or Fake Your Location In Firefox, Internet Explorer & Chrome



For my Data Mining/Data Analysis students.

http://www.pogowasright.org/?p=22037

Privacy: reidentification a growing risk

March 28, 2011 by Dissent

Melanie D.G. Kaplan interviewed Paul Ohm on the re-identification of supposed-to-be de-identified records. Here’s a snippet of the interview, which you can read in its entirety on SmartPlanet:

Earlier this month the Commerce Department released a green paper that proposes a privacy bill of rights. What are your thoughts on this?

I think it’s great in principle. The devil’s in the details. It depends on what is going into this so-called bill of rights. From the things I’ve seen, I’m not sure they’re sufficiently incorporating the trends I and others are seeing in technology.

We have 100 years of regulating privacy by focusing on the information a particular person has. But real privacy harm will come not from the information they have but the inferences they can draw from the data they have. No law I have ever seen regulates inferences. So maybe in the future we may regulate inferences in a really different way; it seems strange to say you can have all this data but you can’t take this next step. But I think that‘s what the law has to do.

What would you like to see from the regulation?

What I’m starting to do now is think about how I’d make more concrete recommendations. One I’ve been tiptoeing around: Quantity is an interesting thing to me. Reidentification is much easier if you have a lot of data, yet I don’t know of many laws that treat you differently once you have more data; our privacy laws are very qualitative, not quantitative. So if you don’t have sensitive information, you can have as much information as you want. For instance, you’re not regulated if you know 10 things about me, but if you know 25 things about me, that might be enough to put you under a stricter form of regulation.



The first of a number of articles today that assume the potential for “evil” uses of technology trumps any legitimate use.

http://games.slashdot.org/story/11/03/29/027209/ISPs-War-On-BitTorrent-Hits-emWorld-of-Warcraftem?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

ISP's War On BitTorrent Hits World of Warcraft

"Canadian Internet users have the prospect of a metered Internet looming over their head, and now World of Warcraft players who use Rogers Communications as their ISP are encountering serious throttling. The culprit seems to be Rogers' determination to go after BitTorrent. WoW uses BitTorrent as a utility to update game files — something most users probably aren't even aware of."



Technology users are clearly a problem. A ban seems like a simple solution. But isn't it a bit extreme?

http://yro.slashdot.org/story/11/03/28/2235218/Should-Smartphones-Be-Allowed-In-Court?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Should Smartphones Be Allowed In Court?

"Federal courts have been debating how much freedom users of smartphones and portable wireless devices in general should have in a federal courthouse. Some say they should be banned outright, while others say they should be allowed, but their use curtailed (PDF). Unregulated use of smartphones has resulted in mistrials, exclusion of jurors and fines in some case."


(Related) Another reading of the memo...

http://www.wired.com/threatlevel/2011/03/court-smartphone/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

Federal Courts Worry Your Smartphone Might Be a Bomb

Smartphones could offer journalists and the public an easy and cost-effective method to provide online updates of court proceedings — which is why it’s always been frustrating that many federal jurisdictions don’t allow the devices into courthouses. Now, thanks to a newly issued document, we know why.

Terrorism.

An 8-page memo issued last week by the Administrative Office of the Courts describes the primary reason to ban smartphones from court buildings. “These common devices present security issues because some can be and have been converted for use as weapons, including explosives.”



For my Ethical Hackers. Does the Times not understand the technology or do they understand it and have a non-public strategy? I suspect the latter...

http://tech.slashdot.org/story/11/03/28/214234/New-York-Times-Paywall-Goes-Live-Loopholes-Abound?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

New York Times Paywall Goes Live, Loopholes Abound

"As the New York Times' new paywall went live this afternoon at 2 p.m., discussion of the move has made the natural transition to methods of bypassing it. As expected, a number of loopholes and hacks have appeared. One of the more notorious methods appeared almost instantly. Using a Twitter account named @FreeNYT, an anonymous user aggregated every article the newspaper posted to Twitter. The site caught The Times' notice and before long, The Times requested that Twitter suspend the account, arguing that it violated its trademark. Another loophole uses four lines of CSS and JavaScript. Canadian developer David Hayes managed to strip the Times' website of any mention of digital subscriptions in addition to getting past the paywall. The hack was released in the form of NYTClean, a bookmarklet easily added to web browsers."

It's likely that the paywall is deliberately porous; as paywalls go, it's a relatively unrestrictive one. Readers referred from search or other sites are unlikely to notice a difference. Workarounds at least keep readers on their site.



Reliance on a shrinkwrap license that was never opened?

http://news.cnet.com/8301-17938_105-20048057-1.html

PS3 hacker's lawyers fire back at Sony

Things are getting even more interesting in one of the biggest jailbreaking cases currently in the courts. Stewart Kellar and his team of attorneys for George Hotz (aka GeoHot), on Friday filed a motion (PDF from Grocklaw) to dismiss Sony Computer Entertainment of America's suit against their client--for a few reasons:

… They argue that there's no evidence that Hotz ever logged into PSN with a jailbroken PS3, which would be a violation of the End User Licensing Agreement (EULA). In fact, they argue, there's no evidence Hotz ever accepted the PSN EULA at all--in fact, the EULA is part of the manuals that come with the PS3, and Hotz's were still sealed. If he didn't accept the agreement, his team says, then he couldn't possibly be in violation of it.


Monday, March 28, 2011

Well here's a surprise...

http://www.databreaches.net/?p=17235

McAfee and SAIC survey: Companies pick and choose which data breaches to report

March 28, 2011 by admin

Ellen Messmer reports:

One in 7 information technology companies have not reported data breaches or losses to outside government agencies, authorities or stockholders.

In addition, only 3 out of 10 said they report all data breaches and losses suffered related to intellectual property, while 1 in 10 organizations will only report data breaches and losses that they are legally obliged to report, and no more. Six in 10 said they currently “pick and choose” the breaches and losses of sensitive data they decide to report, “depending on how they feel about them.”

Those were some of the key findings from a McAfee and Science Applications International Corp. (SAIC) survey that queried 1,000 technology managers in the U.S., United Kingdom, Japan, China, India, Brazil and the Middle East on questions about intellectual property and security.

Read more on Network World.

Figure 3 of the report is interesting, as it shows that for U.S. respondents, 60% say that they report all breaches unless they’re small or insignificant, while 40% say that they report all breaches. In a way, that’s better than what I expected to see, although there aren’t details on how many people were approached for the survey and what percent responded, etc. The contrast between the U.S. responses and the U.K. responses is readily apparent: over a third of UK respondents note that they do not report breaches unless legally obligated to do so or they feel obligated to do so. Japan reported the greatest notification/disclosure rate, exceeding the U.S. for reporting all breaches, regardless of size.

Related: McAfee and SAIC’s press release on the study.

Related: Download the study, “Underground Economies: Intellectual Capital and Sensitive Corporate Data Now the Latest Cybercrime Currency,” at McAfee.



Why a big report on the Privacy implications of what is essentially a broadcast notification system? So they can repeatedly state that they do not request or record PII. Because apparently when they go “into the Cloud” they no longer control the information gathering.

http://www.bespacific.com/mt/archives/026847.html

March 27, 2011

Privacy Impact Assessment for the Use of Unidirectional Social Media Applications Communications and Outreach

Privacy Impact Assessment for the Use of Unidirectional Social Media Applications Communications and Outreach, March 8, 2011. Kathleen McShea Director of New Media and Web Communications, Office of Public Affairs, Department of Homeland Security

  • "Unidirectional social media applications encompass a range of applications, often referred to as applets or widgets, that allow users to view relevant, real-time content from predetermined sources. The Department of Homeland Security (DHS or Department) intends to use unidirectional social media tools including desktop widgets, mobile apps, podcasts, audio and video streams, Short Message Service (SMS) texting, and Really Simple Syndication (RSS) feeds, among others, for external relations (communications and outreach) and to disseminate timely content to the public about DHS initiatives, public safety, and other official activities and one-way notifications. These dynamic communication tools broaden the Department’s ability to disseminate content and provide the public multiple channels to receive and view content. The public will continue to have the option of obtaining comparable content and services through the Department’s official websites and other official means. This Privacy Impact Assessment (PIA) analyzes the Department’s use of unidirectional social media applications."

[From the report:

Risk: There is a risk that public users will not understand that the unidirectional social media tools may be third party owned and that the privacy policies belong to the third party.



One goal is to make the records available for research (e.g. any health impact from new drugs)

http://www.bespacific.com/mt/archives/026843.html

March 27, 2011

Federal Health Information Technology Strategic Plan 2011 – 2015

Office of the National Coordinator for Health Information Technology (ONC), Federal Health Information Technology Strategic Plan 2011 – 2015

  • "It has been a momentous time for health care. With two major pieces of legislation – first the Health Information Technology for Economic and Clinical Health (HITECH) Act passed as part of the American Recovery and Reinvestment Act (ARRA), and then the Patient Protection and Affordable Care Act as amended by the Health Care and Education Reconciliation Act of 2010 (referred to collectively as the Affordable Care Act) – Congress has given the country an unprecedented opportunity to modernize the way care is delivered, [Actually, it seems to have nothing to do with “care,” just improving record keeping. Bob] and improve the health of all Americans."



An Infographic for my students.

http://mediacaffeine.com/network/television-makes-us-miss-opportunities/

Television Makes Us Miss Opportunities


Sunday, March 27, 2011

Careful! Changing your information could invalidate your cookies or even block access to certain sites or files. And who would you spoof?

http://www.pogowasright.org/?p=21995

Privacy Blocker app for Android spoofs your personal data

March 26, 2011 by Dissent

Cory Doctorow relays some comments by Brook Jordan on Privacy Blocker app for Android:

Basically what the app does is scans all the applications you have installed. It identifies what data the apps are requesting about your phone and sending. It then will “fix” the privacy issue by replacing that data inside the app with hard coded (bogus) data. So if an app is sending your phone number back to a server, Privacy Blocker will hard code your number as “55544433333″. You also have the option to override the default values and make it anything you want. [Like the phone number of your local Congressman? Bob]

Read more on BoingBoing.

If you’re using Android, you should probably check this app out to see if it will help protect your privacy. There are a number of forums where it is being discussed, and you can also read a review on DroidLife.



How else can you create a good “enemies list?” But seriously, isn't that what an Open Records law is for? Does a potential political impact negate the law? (Would someone suggesting a certain 'slant' send emails that were subject to this law rather than to a 'personal' account?)

http://politics.slashdot.org/story/11/03/27/0154213/Using-the-Open-Records-Law-To-Intimidate-Critics?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Using the Open Records Law To Intimidate Critics

"On March 15, Professor Bill Cronon posted his first blog. The subject was the role of the American Legislative Exchange Council in influencing recent legislation in Wisconsin and across the country. Less than two days later, his university received a communication formally requesting under the state's Open Records Law copies of all emails he sent or received pertaining to matters raised in the blog. Remarkably, the request was sent to the university's legal office by Stephan Thompson of the Republican Party of Wisconsin, with no effort to obscure the political motivations behind it. In a recent editorial, the New York Times notes that demanding copies of e-mails and other documents is the latest technique used politically to silence critics."



Ignorance of the technology is no defense.

http://www.pogowasright.org/?p=22010

Illinois Identity Theft Statute Partially Invalidated–People v. Madrigal

March 26, 2011 by Dissent

Eric Goldman writes:

People v. Madrigal, 2011 WL 1074427 (Ill. March 24, 2011)

Many state anti-identity theft laws are written very broadly. This loose drafting creates the possibility that they unintentionally restrict innocent–and indeed socially desirable–activity. Today’s case is a good example of sloppy statutory drafting. Fortunately, a vigilant Illinois Supreme Court fixed the legislative error.

The Illinois statute at issue said: “A person commits the offense of identity theft when he or she knowingly…(7) uses any personal identification information or personal identification document of another for the purpose of gaining access to any record of the actions taken, communications made or received, or other activities or transactions of that person, without the prior express permission of that person.”

Read more on EricGoldman.org.

[From Eric Goldman:

As one example, the court says:

doing a computer search through Google or some other search engine or through a social networking site such as Facebook or MySpace, by entering someone's name, could uncover numerous records of actions taken, communications made or received, or other activities or transactions of that person. Thus, the statute as it currently reads would criminalize such innocuous conduct as someone using the internet to look up how their neighbor did in the Chicago Marathon.



We have never stored scanned images and we won't release our stored images.

http://www.pogowasright.org/?p=21985

EPIC Urges Court to Order Release of 2,000 Airport Body Scanner Images

March 26, 2011 by Dissent

From EPIC:

EPIC asked a federal court in Washington, DC to reconsider its earlier decision allowing the Department of Homeland Security to keep secret 2,000 airport body scanner images in EPIC’s Freedom of Information Act lawsuit. The Court relied on a legal theory in its decision, “Exemption High b(2),” that was recently struck down by the Supreme Court in Navy v. Milner. In Milner, the Court held that FOIA exemption 2 only applies to records concerning employee relations and human resources issues. Milner overturns previous lower court decisions that applied the exemption to broader categories of records, allowing federal agencies to block disclosure of documents to the public. EPIC argues in its motion that the Department of Homeland Security is unlawfully withholding information about the airport scanners from the public. For more information, see EPIC-Milner v. Dept. of Navy and EPIC v. DHS – Body Scanners.



This could be an interesting debate...

http://www.phiprivacy.net/?p=6302

A Nuanced Understanding of Privacy

By Dissent, March 26, 2011

Brock N. Meeks of CDT writes:

A case pending before the U.S. Supreme Court has serious implications for how privacy protections are interpreted. But understanding the various risks posed in this case requires some careful unpacking of the ways in which “privacy” is—and is not—at issue here. CDT’s Health Privacy Project team has taken a look those risks and published an in-depth memo about its findings.

In this memo CDT focuses on two aspects of the case: First, an explanation of why it is important to recognize the valid distinctions between personally identifiable data and “de-identified” data. The paper explains that privacy could actually be harmed if the Court were to accept the claims, made in some briefs in the case, that there is no difference between identified and de-identified data.

The second aspect of the case the paper examines is the claim that doctors have a “privacy” right in their drug prescribing practices. CDT disagrees and explains here that, while the patient-doctor relationship is based on confidentiality and the trust it generates, it is not useful – and would undermine other health care goals – to speak of doctors as having a “privacy” right in their drug prescribing practices.

Note that I’m posting this without comment as I have not read through it yet and posting does not indicate any endorsement. Indeed, I suspect I will have more to say once I’ve read through it.



A quick “back of an envelope” (Okay, I used a spreadsheet) calculation shows that 35000 location records in 180 days equals 194 times a day or 8 times an hour. The argument is that this helps the telecoms identify locations where their cell phone towers need to be sited. Because, if they don't already have a tower there, they would get no signal... Did they really keep this data for 6 months?

http://www.pogowasright.org/?p=21989

Privacy backers balk at firms tracking people via cellphone

March 26, 2011 by Dissent

Noam Cohen of the New York Times reports:

A favorite pastime of Internet users is to share their location: Services like Google Latitude can inform friends when you are nearby; another, Foursquare, has turned reporting these updates into a game.

But as a German Green party politician, Malte Spitz, recently learned, we are already continually being tracked whether we volunteer to be or not. Cellphone companies do not typically divulge how much information they collect so Spitz went to court to find out exactly what his cellphone company, Deutsche Telekom, knew about his whereabouts.

The results were astounding. In a six-month period — from Aug 31, 2009, to Feb. 28, 2010 — Deutsche Telekom had recorded and saved his longitude and latitude coordinates more than 35,000 times. It traced him from a train on the way to Erlangen at the start through to that last night, when he was home in Berlin.

Spitz has provided a rare glimpse — an unprecedented one, privacy experts say — of what is being collected as we walk around with our phones. Unlike many online services and websites that must send “cookies” to a user’s computer to try to link its traffic to a specific person, cellphone companies simply have to sit back and hit “record.”

Read more in the Star Advertiser.



Interesting idea. Perhaps it could replace the TSA body scanner...

http://games.slashdot.org/story/11/03/26/2014234/Kinects-AI-Breakthrough-Explained?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Kinect's AI Breakthrough Explained

"Microsoft Research has just published a scientific paper (PDF) and a video showing how the Kinect body tracking algorithm works — it's almost as impressive as some of the uses the Kinect has been put to. This article summarizes how Kinect does it. Quoting: '... What the team did next was to train a type of classifier called a decision forest, i.e. a collection of decision trees. Each tree was trained on a set of features on depth images that were pre-labeled with the target body parts. That is, the decision trees were modified until they gave the correct classification for a particular body part across the test set of images. Training just three trees using 1 million test images took about a day using a 1000-core cluster.'"


Saturday, March 26, 2011

Truly an out of touch legislature. After ignoring warnings, they claim to be shocked that citizens actually read the bill and found it objectionable.

http://yro.slashdot.org/story/11/03/25/2321216/Utah-Repeals-Anti-Transparency-Law?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Utah Repeals Anti-Transparency Law

"After enduring two weeks of public fury, Utah lawmakers voted Friday to repeal a bill that would have restricted public access to government records. While Senate President Michael Waddoups accused the media of lobbying on the issue and others blamed the press for biased coverage that turned citizens against them, Sen. Steve Urquhart said bluntly: 'We messed up. It is nobody's fault but ours.'"



For my Risk Management students. Never test (or practice) on a live system.

http://news.slashdot.org/story/11/03/25/202235/Univ-of-Illinois-Goes-War-of-the-Worlds-On-Students?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Univ. of Illinois Goes War-of-the-Worlds On Students

"'Strange beings who landed in New Jersey tonight are the vanguard of an invading army from Mars.' (Orson Welles, 1938). 'Active shooter at BUILDING NAME/INTERSECTION. Escape area if safe to do so or shield/secure your location.' (Univ. of Illinois, 2011). An alert message sent out Thursday to 87,000 emails and cell phones warning recipients to escape from an 'active shooter' at the University of Illinois was an error, the Office of the Chief of Police confirmed. 'The alert sent today was caused by a person making a mistake,' explained an email. 'Rather than pushing the SAVE button to update the pre-scripted message, the person pushed the SUBMIT button. We are working with the provider of the Illini-Alert service to implement additional security features in the program to prevent this type of error.'"



I can see no obvious reason for MS to do this (unless they are signaling that governments have a backdoor into their “secure” communications?

http://politics.slashdot.org/story/11/03/26/0053203/MS-Removes-HTTPS-From-Hotmail-For-Troubled-Nations?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

MS Removes HTTPS From Hotmail For Troubled Nations

"Microsoft has removed HTTPS from Hotmail for many US-embargoed or otherwise troubled countries. The current list of countries for which they no longer enable HTTPS is known to include Bahrain, Morocco, Algeria, Syria, Sudan, Iran, Lebanon, Jordan, Congo, Myanmar, Nigeria, Kazakhstan, Uzbekistan, Turkmenistan, Tajikistan, and Kyrgyzstan. Journalists and others whose lives may be in danger due oppressive net monitoring in those countries may wish to use HTTPS everywhere and are also encouraged to migrate to non-Microsoft email providers, like Yahoo and Google."



Geeky stuff

http://download.cnet.com/8301-2007_4-20047349-12.html

Everything you need to know about Firefox 4



Interesting hack...

http://www.wired.com/gadgetlab/2011/03/kindlefish-turns-kindle-into-worldwide-universal-translator/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

Kindlefish Turns Kindle Into Worldwide Translator

Nicholas found that Google Translate is badly suited to the e-reader’s admittedly limited web browser. “Standard Google Translate doesn’t work for the Kindle,” he writes on his blog, “and the mobile Google Translate page returns text that is too small to be easily read, and a little clunky for use on the Kindle.”

To get around this, he wrote a new front-end called Kindlefish, a homage to the universally translating Babelfish from Douglas Adams’ five-part Hitchhiker’s trilogy. The interface is simple, letting you set three preferred languages for quick access, and one input language (English by default). You just type your phrase on the Kindle’s little keyboard and hit the “Translate” button.

… If you want to try it out, head over to the Kindlefish site on your Kindle. The site is on free hosting, but if it is swamped by traffic then Nicholas plans to move it to a more permanent home.



You never know what you'll find in lists like this one.

http://savedelete.com/best-free-windows-business-software.html

Top 10 Extremely Useful Free Windows Software For Your Small Business

4. Calibre Ebook Management : calibre is a free and open source e-book library management application developed by users of e-books for users of e-books. It has a cornucopia of features such as Library Management, E-book conversion, Syncing to e-book reader devices, Downloading news from the web and converting it into e-book form, Comprehensive e-book viewer, Content server for online access to your book collection.

If you too into reading books, here you can check our article on 30 sites to download free ebooks and best free Microsoft ebooks for business persons.


Friday, March 25, 2011

Perhaps we can educate the educators?

http://www.databreaches.net/?p=17208

Hackers Take Schools To School

March 24, 2011 by admin

Nice to see on data on this. Tim Wilson of Dark Reading writes:

Some 63 percent of K-12 schools say they have experienced at least two security breaches in the past year, according to a new study, and their IT administrators are struggling to find the resources they need to keep up with security tasks.

According to the “Panda Security Kindergarten-12 Education IT Security Study,” which was published today, many schools are struggling to find the time and resources they need to build out their security programs.

Read more on Dark Reading.



Reminds me of an Inverse Drake Equation – instead of calculating the number of planets hosting an Intelligent species, it calculates the number of clueless victims on the Internet.

http://www.wired.com/magazine/2011/02/st_equation_spamprofits/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

Equation: How Much Money Do Spammers Rake In?

After deleting the 10,000th Viagra offer from your inbox, you might wonder, does anyone actually make money off this crap? Chris Kanich and his colleagues at UC San Diego and the International Computer Science Institute wondered too—so they hijacked a botnet to find out. Kanich’s team intentionally infected eight computers with a middleman virus, software they found in the wild that was relaying instructions between a botmaster computer and the network of computers it had secretly turned into spam-sending zombies. Then they changed the orders, effectively zombifying the botnet for their own research. Instead of sending hapless rubes to the botmaster’s website, spam ads would instead funnel them to a site built by Kanich’s team. It looked like an authentic Internet pharmacy, but instead of taking credit card numbers in return for a bottle of sugar pills (or worse), the site coughed up an error message and counted the clicks. Then the researchers calculated an estimate of how much money the spammer grossed per day: about $7,000.



Nothing is as much fun to read as two legal scholars jousting...

http://www.pogowasright.org/?p=21951

Hard drive search warrants: should there be any limits?

March 24, 2011 by Dissent

Matthew Lasar writes:

Here’s the latest hot debate among Fourth Amendment scholars: when magistrate judges issue search warrants on computers, should those warrants limit where in the machine’s directory system the police may look, or for how long they can scan the drive?

Professor Orin Kerr of George Washington Law School says no (PDF). Assistant Professor Paul Ohm of the University of Colorado Law School says yes (PDF).

Read more on Ars Technica.



Let's face it. Lawyers are in their own little world.

http://yro.slashdot.org/story/11/03/25/0434255/Federal-Prosecutors-Tempt-the-Streisand-Effect?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Federal Prosecutors Tempt the Streisand Effect

"As the case of NSA IT guru Thomas Andrews Drake nears trial, the fur has been flying between the defense and prosecution lawyers. Earlier this week the judge ordered the sealing of a defense motion because the government claimed it contained classified information. The problem? The document had been sitting on the Federation of American Scientists website for several days. Another problem: the document is marked 'Unclassified' in big bold letters at the top of the page."



Tweet globally, legislate locally.

http://www.pogowasright.org/?p=21950

EP demands personal data protection in US WikiLeaks investigation

March 24, 2011 by Dissent

On 23 March MEPs asked the Commission and the Council about the implications for EU citizens of a US court order obliging Twitter to hand over personal data, messages and communications of users considered to be related to WikiLeaks. What personal data protection rights do EU-based Twitter users have in such cases?

Read more on the European Parliament web site. Short answer: it sounds like everyone agreed to respect U.S. laws but to strengthen EU laws.

Dutch Liberal Sophie in ‘t Veld explained, “The US court argues that once you use Twitter, you no longer have a legitimate expectation of privacy, and that means that EU citizens no longer have any legal protection, because Twitter is US-based”. That is “a problem that must be addressed in the review of the data protection” directive, she said.

By all means, review it, but unless Twitter or another social network is actually a registered business in the EU or advertises to/pitches to EU citizens, how does the EU bring them under their directives? Or will we see court rulings out of the EU that are not enforceable here?

This is another opportunity to mention how much we need to get people together to see how we can better harmonize privacy laws and protections between the EU and US and how much we need to strengthen privacy protections here in the U.S.



I'm sure this is completely unrelated to the story above. It does make me think that Twitter can find twits anywhere... No doubt this will “prove” that the US is behind the technology curve and result in a multi-billion dollar program to catch up.

http://www.crunchgear.com/2011/03/24/rt-twitter-en-route-to-floor-of-uk-parliament/

RT: Twitter En Route To Floor Of UK Parliament

… A rules committee there has said that MPs should be be allowed to use the service from the floor provided it doesn’t “impair decorum.”

MPs will be allowed use devices no larger than a sheet of A4 paper. Laptops are still banned. [Apparently this is a space issue. Bob]

The idea is to allow MPs to bring in digital notes (on, say, their iPad) and maintain communications ties with their constituents from the floor.



Interesting. Should providers be required to prove the validity of their data before they can cut off/slow down/charge users of their (not really) unlimited plans?

http://www.crunchgear.com/2011/03/24/att-broadband-metering-is-shoddy-and-they-know-it/

AT&T Broadband Metering Is Shoddy And They Know It

… Readers over at Broadband Reports are noticing marked differences between AT&T’s measurements and their own. One user found differences of several orders of magnitude. Now, if AT&T (and of course Comcast and others) are unwilling to allow for wiggle room in their GB caps (fees start the byte over 250GB), why should we allow wiggle room in their measurement? After all, we don’t let grocers use poorly (or maliciously) calibrated scales.



Dude! Just because all these new words/terms/abbreviations appear in the OED does not mean it is appropriate to Tweet your research paper.

http://www.engadget.com/2011/03/24/omg-fyi-and-lol-enter-oxford-english-dictionary-foreshadow-th/

OMG, FYI, and LOL enter Oxford English Dictionary, foreshadow the apocalypse

In an acknowledgment of the internet's overwhelming influence on the triviality we sometimes refer to as "real life," the Oxford English Dictionary doyens have decided to add a few of the web's favorite pronouncements to their lexicon. Among them are the standouts OMG, LOL and FYI, joining their compatriots IMHO and BFF among the proud number of officially sanctioned initialisms (abbreviations contracted to the initials of their words) used in the English language. Shockingly enough, the expression OMG has had its history tracked all the way back to 1917, while LOL used to mean "little old lady" back in the '60s, and FYI first showed up in corporate lingo in 1941. Not only that, but the heart symbol -- not the emoticon, the actual graphic -- has also made it in. Just so long as Beliebers and fanpires are kept out, there's still hope for the future. A tiny, twinkling ember of a hope.



Thursday, March 24, 2011

Ebay (et al) as a tool for Identity Theft (is it theft if you purchase the phone “as is” from its owner?)

http://yro.slashdot.org/story/11/03/24/040255/Half-of-Used-Phones-Still-Contain-Personal-Info?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Half of Used Phones Still Contain Personal Info

"More than half of second-hand mobile phones still contain personal information of the previous owner, posing a risk of identity fraud. A study found 247 pieces of personal data stored on handsets and SIM cards purchased from eBay and second-hand electronics shops. The information ranged from credit card numbers to bank account details, photographs, email address and login details to social networking sites like Facebook and Twitter. According to data security firm CPP, 81 percent of previous owners claim they have wiped personal data from their mobile phones and SIM cards before selling them. However, deleting the information manually is 'a process that security experts acknowledge leaves the data intact and retrievable.'"


(Related) Legitimate uses for a used phone.

http://www.makeuseof.com/tag/5-interesting-spare-smartphone/

5 Interesting Uses For A Spare Old Smartphone



For my Computer Security students.

http://news.cnet.com/8301-31921_3-20046588-281.html

Hackers exploit chink in Web's armor

A long-known but little-discussed vulnerability in the modern Internet's design was highlighted yesterday by a report that hackers traced to Iran spoofed the encryption procedures used to secure connections to Google, Yahoo, Microsoft, and other major Web sites.

This design, pioneered by Netscape in the early and mid-1990s, allows the creation of encrypted channels to Web sites, an important security feature typically identified by a closed lock icon in a browser. The system relies on third parties to issue so-called certificates that prove that a Web site is legitimate when making an "https://" connection.

The problem, however, is that the list of certificate issuers has ballooned over the years to approximately 650 organizations, which may not always follow the strictest security procedures. And each one has a copy of the Web's master keys

… This has resulted in a bizarre situation in which companies like Etisalat, a wireless carrier in the United Arab Emirates that implanted spyware on customers' BlackBerry devices, possess the master keys that can be used to impersonate any Web site on the Internet, even the U.S. Treasury, BankofAmerica.com, and Google.com. So do more than 100 German universities, the U.S. Department of Homeland Security, and random organizations like the Gemini Observatory, which operates a pair of 8.1-meter diameter telescopes in Hawaii and Chile.

… The vulnerability of today's authentication infrastructure came to light after Comodo, a Jersey City, N.J.-based firm that issues SSL certificates, alerted Web browser makers that an unnamed European partner had its systems compromised. The attack originated from an Iranian Internet Protocol address, according to Comodo Chief Executive Melih Abdulhayoglu, who told CNET that the skill and sophistication suggested a government was behind the intrusion.

Spoofing those Web sites would allow the Iranian government to use what's known as a man-in-the-middle attack to impersonate the legitimate sites and grab passwords, read e-mail messages, and monitor any other activities its citizens performed, even if Web browsers show that the connections were securely protected with SSL encryption.



Also for my Computer Security students

http://blogs.computerworld.com/18019/microsoft_accepts_reality_offers_it_tool_for_iphones_ipads_and_android

Microsoft accepts reality, offers IT tool for iPhones, iPads, and Android

Not everyone at Microsoft is marching in lockstep to the idea that Windows Phone 7 will rule the enterprise. At the Microsoft Management Summit (MMS), the company announced that it has released a beta of a tool to let IT manage iPhones, iPads, Android devices, Symbian devices, and Windows Phone 7 devices in the enterprise. Up until now, the tool only worked for Windows Mobile.

The tool is called System Center Configuration Manager (SCCM), and it's designed to deploy and update servers, clients, and devices across an enterprise's entire computing and network infrastructure. The current version is SCCM 2007, and the only mobile devices it handles are Windows Mobile ones --- it won't even handle Windows Phone 7 right now.

At MMS today, though, Microsoft made available for download beta 2 of SCCM 2012.


(Related) Why you should care. Ignorance is bliss only until the bill comes...

http://www.bespacific.com/mt/archives/026824.html

March 23, 2011

AVG Study Reveals Alarming Complacency Among Users of Mobile Devices on Security

Smartphone Security - Survey of U.S. consumers, Ponemon Institute© Research Report, Sponsored by AVG Technologies, Independently conducted by Ponemon Institute LLC, Publication Date: March 2011

  • News release: "AVG Technologies, one of the leading providers of consumer security software, today revealed details of a sobering study uncovering new statistics about the data security risks involved in everyday smartphone use. Findings are the result of a recent study conducted by the Ponemon Institute in concert with AVG of 734 random US consumers over age 18 regarding their mobile communications behavior. The study confirmed AVG’s concerns focus on consumers indifference to the many serious security risks associated with the storage and transmission of sensitive personal data on iPhone, Blackberry and Android devices. Following are three of the most alarming:

  • 89 percent of respondents were unaware that smartphone applications can transmit confidential payment information such as credit card details without the user’s knowledge or consent.

  • 91 percent of respondents were unaware that financial applications for smartphones can be infected with specialized malware designed to steal credit card numbers and online banking credentials, yet nearly a third (29 percent) report already storing credit and debit card information on their devices and 35 percent report storing “confidential” work related documents as well.

  • 56 percent of respondents did not know that failing to properly log off from a social network app could allow an imposter to post malicious details or change personal settings without their knowledge. Of those aware, 37 percent were unsure whether or not their profiles had already been manipulated.



Toys make sense. Shoelaces don't. It also suggests who Apple uses to test their user interfaces...

http://www.bespacific.com/mt/archives/026823.html

March 23, 2011

"Preschoolers better at navigating iPad than tying their shoes"

Inside iPad: "Hand a two-year-old child a shoe and he will probably end up throwing it. Hand him an iPad, however, and he'll navigate through it to find his favorite app in no time. According to a new survey from security software maker AVG, kids can grasp new tech skills long before they even learn how to do normal kid things, such as swimming or tying their shoelaces. AVG surveyed 2,200 parents with children between the ages of two and five in the US, Canada, UK, France, Italy, Germany, Spain, Japan, Australia and New Zealand. Nineteen percent said their kids know how to access a smartphone application (and it's not just the older kids either—17 percent of 2- to 3-year-olds did as well). Another 58 percent can play a computer game, and a quarter of kids can open and operate a Web browser. By comparison, only nine percent of kids between 2 and 5 can tie their shoelaces, 20 percent can swim without help, and 43 percent can ride a bike."



No liability here! Another Vigilante product.

http://news.cnet.com/8301-17938_105-20046421-1.html

Burglar alarm marks territory with pepper spray

Burglar alarms usually work by scaring off criminals with loud noises and the threat of police action. The Burglar Blaster from Heracles Research Corporation takes the law into its own hands.

It comes loaded with 4 ounces of painful, burning pepper spray.

… The concept behind the Burglar Blaster is really pretty simple. You screw this little terror to the wall where you expect criminals to come busting in. An intruder triggers the passive infrared motion sensor and the Blaster commences spraying mace at the offender. It runs on batteries, so all you really need for installation is a screwdriver and some determination.



I think they still don't get it. Buying the DVD or downloading and burning one are effectively the same thing, aren't they?

http://news.cnet.com/8301-31001_3-20046430-261.html

Sony Pictures eyes cheaper film downloads

By and large, the big Hollywood film studios have clung to the idea that digital downloads should be priced the same as DVDs. Sony Pictures is trying to find out if there's a better way.

On Tuesday, Sony began selling downloads of two new releases for about 13 percent less than the $15 DVD price. At Amazon.com and iTunes, "The Tourist" and "How Do You Know" could be downloaded for $12.99. Elsewhere at Amazon, the disc sold for $15. Both movies were disappointments at the box office, so the reductions seem barely to quality as a toe dip into price cutting.

But according to two film industry sources, the studio is experimenting with pricing for download-to-own videos. Sony, which has tried similar tests before, is searching for a price that stimulates download sales but won't erode demand for DVDs. [A sale is a sale is a sale... Bob]


Wednesday, March 23, 2011

At some point you have to ask if those who run the education system have ever taken advantage of it.

http://www.databreaches.net/?p=17183

SSNs of All Laredo ISD Students Missing In Data Breach; Trustee says not “a big deal”

March 22, 2011 by admin

Morgan Smith reports:

A disk holding the Social Security numbers of every student in the Laredo Independent School District — a total of 24,903 — has gone missing, according to the Texas Education Agency.

TEA spokeswoman Suzanne Marchman said the agency first became aware of the situation in January, [See below Bob] when officials with the University of Texas at Dallas’ Education Research Center contacted the TEA looking for sensitive data they had requested from Laredo ISD — data that was supposed to be sent to the TEA first.

At that point, the TEA contacted Laredo ISD for the package tracking number, only to learn that the CD had been signed for at the William B. Travis Building in Austin, which houses five state government agencies, including the TEA. But the CD was never delivered to James Van Overschelde, the TEA’s former director of educational research and policy who was working with UTD on the project — and the agency doesn’t know who signed for it.

Read more in the Texas Tribune.

Okay, insert the entity’s usual disclaimers and outrageous finger-pointing here, because what is really stunning about this report is a stunningly stupid statement reportedly made by George Beckelhymer, president of Laredo ISD’s Board of Trustees:

[Beckelhymer] said he was also unaware that the information had gone missing.

“I am trying to be sure we are looking in the right spot if we are looking for blame on this,” he said. “Is it really LISD’s blame? Did UTD use an inappropriate method to request the [information] and then tricked us? Does the TEA have fault that they didn’t have the proper personnel to sign legitimately?”

Beckelhymer also added that, while he doesn’t like “sharing” Social Security numbers, he doesn’t think the fact that they’re missing is “a big deal.”

Un—-believable.

[From the artiocle:

Van Overschelde said he left the TEA in June [Which means that the data should have arrived prior to that, right? So they didn't notice for AT LEAST seven months? Bob]



Mom thinks it's cool?

http://www.ispyce.com/2011/03/facebook-bans-20000-kids-day.html

Facebook Bans 20,000 Kids a Day

Although Facebook requires all users to be 13 or older, the social network bans 20,000 underage users a day, a spokeswoman said. "There are people who lie. There are people who are under 13 [accessing Facebook]," Mozelle Thompson, Facebook's chief privacy adviser, told the The Telegraph (Sydney, Australia). "Facebook removes 20,000 people a day, people who are underage."

When asked by the Australian parliamentary online safety committee how Facebook can detect those lying on age forms, Thompson replied, "It's not perfect." In fact, it's relatively easy. A standard online form asks a user if he or she is 13 or over, and the user can tell the truth or not. ComScore estimates about 3.6 million of kids under 12 use Facebook in the United States. [So they should have them all kicked off in 180 days, assuming no new sign-ups. Bob] Last week, a story in the New York Times highlighted the number of those under 13 who skirt the age requirement often with parental consent. Many began using Facebook or other online community in elementary school and many parents see nothing wrong with it. “It’s not like there’s a legal age limit for being on the Internet," said a parent whose 11-year-old son uses Facebook. He told the social media site he was 15.

There are obvious reasons why there are federal age requirements for Internet use: [There are? Bob] sexual predators, cyberbullying, adult content and explicit language. Most very young children are not equipped to be dumped at the equivalent of an online adult cocktail party and fend for themselves. While many want most of the security to be created by tech companies, they are ignoring the reality that many parents don't see a problem with their underage children using a social network with 600 million users. The best online security is a connected parent who carefully monitors online usage -- including only allowing children to use computers in a central location, not a bedroom, easily accessed by a parent -- and one that doesn't allow their children to use Facebook if they are younger than 13.



I'll say it's disturbing. How could they fail to find the other 15%? Police mine every database they can access. Does that mean they don't appear in any government or commercial database? No birth certificate, school records, tax return, drivers license, credit card, phone, etc.?

http://www.pogowasright.org/?p=21877

85 percent of B.C. adults in police database ‘disturbing’

March 22, 2011 by Dissent

Neal Hall reports:

The B.C. Civil Liberties Association says it is disturbing that up to 85 per cent of B.C. adults have their names in a police computer database designed to track criminals.

The association has written a letter to B.C. Solicitor General Shirley Bond, asking her to investigate why the majority of B.C.’s law-abiding citizens are in the PRIME-BC database.

Even more troubling, said Robert Holmes, president of BCCLA, is that no information is available as to how long the information is kept on file.

Read more in the Vancouver Sun



Think of it as a way for manufacturers to trace each device sold.

http://www.pogowasright.org/?p=21862

UDID: The Next Privacy Frontier?

March 22, 2011 by Dissent

The Womble Carlyle Team writes:

Companies that make their money in the mobile computing space – application developers, device manufacturers, software adaptors – have a new worry. Many functions and applications used on iPhone devices currently rely on reporting that includes the UDID unique device identifier. Two new lawsuits against Apple for its use of UDID information may change the way that mobile functions and applications are built, managed and paid for.

The UDID for the iPhone is a 40 character identifier that is set by Apple and stays with the specific defined device forever. Its function is to uniquely identify any one iPhone, allowing the UDID to be connected with the name and behaviors of that iPhone’s user.

The Wall Street Journal may have started the snowball of lawsuits rolling in its ongoing series of articles about how the computer industry tracks people using the internet.

Read more on Womble Carlyle.



Okay, this would seem to throw a monkey into the wrench... Does it override “appropriate use” policies?

http://www.pogowasright.org/?p=21874

Ca: Personal files on work computers ruled private

March 22, 2011 by Dissent

Tracey Tyler reports:

The Ontario Court of Appeal has recognized a right to privacy in the personal information Canadians store on work-issued computers.

In a 3-0 ruling Tuesday, the court said a Sudbury high school teacher charged with having nude photos of a Grade 10 student on a laptop issued by the school board had a right to expect his personal files on the computer’s hard drive would remain private.

Read more in Toronto Star.



I wonder who tipped them off?

http://www.computerworld.com/s/article/9214928/Senators_to_Apple_Pull_iPhone_DUI_checkpoint_alert_apps

Senators to Apple: Pull iPhone DUI checkpoint alert apps

Four U.S. senators Tuesday called on Apple to yank iPhone and iPad apps that help drunken drivers evade police, saying the programs are "harmful to public safety."



Does this extend Copyright to Shakespeare’s descendants? Chaucer's Copyrighted Tales?

http://www.bespacific.com/mt/archives/026815.html

March 22, 2011

EPIC: Courts Rejects Google Books Settlement as Unfair

EPIC: "Judge Denny Chin struck down a proposed settlement between Google and copyright holders that would have imposed significant privacy risks on e-book consumers. Google's proposal would have entitled the company to collect each users' search queries as well as the titles and page numbers of the books they read. In a February 2010 hearing before the Court, EPIC President Marc Rotenberg explained EPIC Press Release: EPIC Urges Court To Reject Google Books Settlement; EPIC: Google Books Settlement and Privacy."



When you grown to the size of a medium country, people start asking why you haven't issued your own currency... And lot's of people think Google is printing money as it is.

What is the Dollar – Google exchange rate?

http://news.slashdot.org/story/11/03/23/0210207/Google-Engineer-Releases-Open-Source-Bitcoin-Client?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Google Engineer Releases Open Source Bitcoin Client

"A Google engineer has released an open source Java client for the Bitcoin peer-to-peer currency system, simply called BitcoinJ. Bitcoin is an Internet currency that uses a P2P architecture for processing transactions, avoiding the need for a central bank or payment system. Cio.com.au also has an interview with Gavin Andresen, the technical lead of the Bitcoin virtual currency system."



You don't have to understand technology to really screw up technology.

http://www.latimes.com/news/local/la-me-court-resignation-20110323,0,7040071.story

Top California courts administrator to step down

The top administrator for California's courts announced Tuesday that he would step down, a month after two state lawmakers urged that he be fired for his handling of a computer modernization project that has skyrocketed in cost from $260 million to $1.9 billion.

… Philip Carrizosa, a spokesman for the chief justice, said the retirement had nothing to do with the lawmakers' recent criticism.

Lowenthal said the departure "gives the chief justice a chance to set a whole new level of responsiveness and accountability." [What, he had Tenure or something on the Chief Justice? Bob]



For my Risk Management students

http://jps.anl.gov/Volume4_iss2/Paper3-RGJohnston.pdf

Being Vulnerable to the Threat of Confusing Threats with Vulnerabilities



Looking for that perfect word or phrase? Try entering “Looking for that * word or phrase?” (They did not return “perfect.”)

http://www.killerstartups.com/Web-App-Tools/phraseup-com-write-better-phrases?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+killerstartups%2FBkQV+%28KillerStartups.com%29

PhraseUp.com - Write Better Phrases

what Phrase Up does is to let you fill gaps in sentences. Using Phrase Up, you can write a half-baked sentence and have it automatically fleshed out.

… And all the suggestions produced by Phrase Up can be translated. Handy for those who are using the site because English is not their first language, and they are looking for the words they have not yet learned.

http://www.phraseup.com/



http://www.makeuseof.com/tag/5-podcast-directories-visit-subscribe-download-free-podcasts/

5 Podcast Directories You Can Visit To Subscribe & Download Free Podcasts

Here are five where you can download podcasts for free:

Podcast Alley

Podcast Alley usually comes up tops in a Google podcast search. It is a large podcast directory with nearly 90,000 podcasts and 6,000,000 episodes. Access genres with a dropdown which cover everything from arts to TV & Film. You can subscribe to podcasts directly from here or go to the individual websites. You can click to even listen to the podcasts online if you don’t want to clutter your podcatcher.

Podcast

Looking at the domain name, these guys probably had first dibs at setting up a directory and they have done a nice job of it with nearly 85,000 podcasts

Podiobooks

This is a cool collection of serialized audiobooks which you can subscribe to using RSS. You can choose to subscribe, listen online, or download the episodes. The site is completely free

Podfeed

Podfeed is a podcast directory with a relatively small collection of 16000+ podcasts and 2783515 episodes. With a sign-up, you can also submit your own podcasts.

The Education category for instance, is helpful if you want to learn a language like Spanish or even English. Another category that’s worth a look is that of Storytelling with its collection of nearly 500 podcasts.

Tech Podcasts

Tech Podcasts is all about technology and geeky topics with the help of free podcasts.



Mitchell's Law of Committees: Any simple problem can be made insoluble if enough meetings are held to discuss it.