Tuesday, February 05, 2013

...but if you read it, you become a target.
EXCLUSIVE: Justice Department memo reveals legal case for drone strikes on Americans
A confidential Justice Department memo concludes that the U.S. government can order the killing of American citizens if they are believed to be “senior operational leaders” of al-Qaida or “an associated force” -- even if there is no intelligence indicating they are engaged in an active plot to attack the U.S.
The 16-page memo, a copy of which was obtained by NBC News, provides new details about the legal reasoning behind one of the Obama administration’s most secretive and controversial polices: its dramatically increased use of drone strikes against al-Qaida suspects, including those aimed at American citizens, such as the September 2011 strike in Yemen that killed alleged al-Qaida operatives Anwar al-Awlaki and Samir Khan. Both were U.S. citizens who had never been indicted by the U.S. government nor charged with any crimes.
… But the confidential Justice Department “white paper” introduces a more expansive definition of self-defense or imminent attack than described by Brennan or Holder in their public speeches. It refers, for example, to what it calls a “broader concept of imminence” than actual intelligence about any ongoing plot against the U.S. homeland.


Just in time for a thoughtful discussion of Mobil App Privacy... (Works with your browser too)
… When thinking of privacy, the first thing that comes to mind is usually Facebook, with its ever changing privacy settings, but have you ever considered what information your mobile apps can collect about you?
Although iOS’s privacy settings are much improved in iOS 6, there’s still no clear way to find out exactly what each app knows about you, what information it can collect, and how these things can affect you. A new service by BitDefender called Clueful tries to bring some order into this area, with detailed analyses of what each iOS app knows, uses and does when it comes to your private data.
… Clueful is a simple Web app that gives you access to BitDefender’s analysis of many popular iOS apps.


Are we ready to make billions with our “Free is Good!” business plan? How big a game changer is this? (How likely is it to get past the lobbyists?)
"Internet access is an essential need on par with education access, but at what point do regulators recognize that? When will government officials acknowledge that widespread, guaranteed access is essential to fostering growth in the country? Somewhat surprisingly, that time is now, as the FCC is now calling for nationwide free wi-fi networks to be opened up to the public. The FCC proposes buying back spectrum from TV stations that would allow for what the Washington Post is dubbing 'super wi-fi,' as the commission wants to cover the country with wide-ranging, highly-penetrative networks. Essentially, you can imagine the proposal as covering a majority of the country with open-access data networks, similar to cell networks now, that your car, tablet, or even phone could connect to. That means no one is ever disconnected, and some folks – especially light users and the poor – could likely ditch regular Internet and cell plans altogether."


Keeping up on the tools of war
Palm-Sized Nano-Copter Is the Afghanistan War’s Latest Spy Drone
British troops in Afghanistan are flying a drone that’s shrunk down to its essentials: a micro-machine that spies, built for a solitary user.
This is the Black Hornet. Its Norwegian manufacturer, Prox Dynamics, bills it as the world’s smallest military-grade spy drone, with a weight of 16 grams and a length of 4 inches. Propelled by two helicopter blades, the Black Hornet carries little more than a steerable camera that records still and video imagery. (That is: It’s unarmed.) Now British soldiers have brought it to Afghanistan, as it fits in the palms of their hands. It’s supposed to be a drone for an Army of One.


Something for my Criminal Justice majors...
February 04, 2013
United States Courts - Access to Court Opinions Expands
"A pilot project giving the public free, text-searchable, online-access to court opinions now is available to all federal appellate, district and bankruptcy courts. The Judicial Conference, the policy-making body of the Federal court system, approved national implementation of the project with the Government Printing Office, Federal Digital System (FDsys), which provides free access to publications from all three branches of federal government via the Internet. The pilot project pulls opinions nightly from courts’ Case Management/Electronic Case Files (CM/ECF) systems and sends them to the GPO, where they are processed and posted on the FDsys website. The functionality to transfer opinions to FDsys is included in the latest release of CM/ECF which is now available to all courts. Twenty-nine courts participated in the original pilot, and now, all courts may opt to participate in the program. Access to judicial opinions through FDsys allows the Judiciary to make its work more easily available to the public. Collections are divided into appellate, district or bankruptcy court opinions and are text-searchable across opinions and across courts. FDsys also permits embedded animation and audio. Presently, more than 600,000 opinions dating back to 2004 are available. Opinions from the pilot are already one of the most heavily used collections on FDsys, with millions of retrievals each month."

Monday, February 04, 2013

In a multi-platform world, we need multi-platform malware.
Terrifying Android Malware Hacks Your PC and then Eavesdrops On You With Its Microphone
It's one thing when malware attacks your phone, but it's another when that same malware hops over to your PC and then uses it to listen in on all your conversations on top of just messing with your phone. A newly discovered Android app—one that's in the Google Play store—can do just that. Beware.
The sketchy app, which masquerades as a "cleaner" app called DroidCleaner, was discovered by Kaspersky, and if it infects you, its tendrils will wrap themselves around a seriously impressive number of things.


Was there an assumption that everyone used their phones as a phone?
Cell Phone Activities 2012

(Related)
Just Call Someone Already
You won't believe this. There's a technological marvel that, instead of forcing you to communicate with others in writing, actually allows you to hear other people's voices and words — you can even hear the tone and volume of their voices! And wonder of wonders, they can hear you! Across any distance! It's incredible! Not many people use the device today, but it's truly in a class by itself for productive communication.
Please pardon the sarcasm, but the way people shun the telephone these days is getting ridiculous.
You used to be able to just call people. You didn't have to be on someone's calendar to have a phone conversation.


How many strikes should social networks get?
Less than a week after social network Path settled with the US Federal Trade Commission for collecting childrens’ private information to the tune of $800,000 it has once again been caught publishing users’ private information.
The social network and photo sharing mobile app has been automatically geotagging users’ photos even when they have completely disabled location services. [“We look to see if you have 'Opted Out,' then we do it anyway...” Bob]
The bug was discovered by security researcher and hacker Jeffrey Paul who found that Path had geotagged a photo he published from his phone even though his location services had been disabled.
Read more on news.com.au. Path claimed initial ignorance of the issue and replied to Paul that they were addressing it. Now what, if anything, will the FTC do?


A reversal on this one may force us to “Open Source Only” resources. Fortunately, that's not a big deal.
February 03, 2013
Electronic Course Reserves Copuright Infringement Case Moves to Appeal
Chronicle of Higher Education, Jennifer Howard: "Fair use and electronic course reserves are back in court. A keenly watched copyright case that pitted three academic publishers against Georgia State University has entered the appeals phase, with a flurry of filings and motions this week and more expected soon. One surprise motion came from the U.S. Department of Justice, which requested more time to consider filing an amicus brief either in support of the publishers or in support of neither party...he case in question is Cambridge U. Press et al. v. Mark P. Becker et al. In 2008, Cambridge, Oxford University Press, and SAGE Publishers sued Georgia State, asserting it had committed widespread copyright violations when it allowed some of their content to be used, unlicensed, in e-reserves. The Association of American Publishers and the Copyright Clearance Center, which specializes in licensing content to universities, bankrolled the legal action."

(Related) Idiots can be found at all levels in all organizations.
"A proposal by the Prince George's County Board of Education to copyright work created by staff and students for school could mean that a picture drawn by a first-grader, a lesson plan developed by a teacher or an app created by a teen would belong to the school system, not the individual. It's not unusual for a company to hold the rights to an employee's work, copyright policy experts said. But the Prince George's policy goes a step further by saying that work created for the school by employees during their own time and using their own materials is the school system's property."


Think this is true? Could we run Geeks for Congress? (Interesting read)
Geeks are the New Guardians of Our Civil Liberties


Add to my library request list. Published only as an eBook?
February 03, 2013
MIT - The New Initiative on the Digital Economy
"The Initiative for the Digital Economy (IDE) is a major effort addressing the impact of digital technology on businesses, the economy, and society. Drawing upon MIT Sloan’s strengths in technology and innovation, its internationally recognized faculty, and over a decade of research and partnership with MIT Sloan’s Center for Digital Business, the new Initiative will analyze the broad sociological changes brought about by digital technology. Many of the key issues are described in a recent book by Professor Erik Brynjolfsson and Dr. Andrew McAfee, Race Against the Machine - How the Digital Revolution is Accelerating Innovation, Driving Productivity, and Irreversibly Transforming Employment and the Economy. In the book, they outline the relevant issues the new initiative will address..."


For all my students
These days, school careers advisors are more likely to be asked about careers in programming, IT, web and software developing, and anything else which involves a monitor and a keyboard. That is the subject of today’s infographic, courtesy of Schools.com.
So forget law school and medicine school – try programming school instead. Brush up on your database skills. And instead of learning Spanish, learn another language such as Python or Ruby. That will lead to the jobs with big bucks, especially when Skynet takes over the world and they need people human slaves to keep the computers upgraded.


I'm thinking, Math-Mag: Adventures in Addition. What do you think?
If you are looking to publish your content online in a way that is quite similar to traditional magazines, check out Zeen, an online content platform that lets users create and view elegant-looking web magazines.
Similar Tools: Appgreen, Themeefy, and Grisker.


A re-cap of Commercial Fest 2013
Super Bowl 2013 Commercials

Sunday, February 03, 2013

“We're the Feds. We can do anything we want, laws or no laws.” And they are probably doing whatever they want in states that do not have similar laws.
By Dissent, February 2, 2013 5:15 pm
Ooh. I missed this important post by Nathan Freed Wessler of the ACLU last week:
The Drug Enforcement Administration is trying to access private prescription records of patients in Oregon without a warrant, despite a state law forbidding it from doing so. The ACLU and its Oregon affiliate are challenging this practice in a new case that raises the question of whether the Fourth Amendment allows federal law enforcement agents to obtain confidential prescription records without a judge’s prior approval. It should not.
Read more on the ACLU’s site.
[From the article:
In 2009, the Oregon legislature created the Oregon Prescription Drug Monitoring Program (PDMP), which tracks prescriptions for certain drugs dispensed by Oregon pharmacies, including all of the medications listed above. The program was intended to help physicians prevent drug overdoses by their patients and more easily recognize signs of drug abuse. Because the medical information revealed by these prescription records is highly sensitive, the legislature created robust privacy and security protections for the PDMP, including a requirement that law enforcement must obtain a warrant before requesting records for use in an investigation. But despite those protections, the DEA has been requesting prescription records from the PDMP using administrative subpoenas which, unlike warrants, do not involve demonstrating probable cause to a neutral judge.


A book to request from my local library. (They let me request books they haven't purchased yet)
Google’s Schmidt: ‘Twitter Can No More Produce Analysis Than A Monkey Can Type Out A Work of Shakespeare’
Google Chairman Eric Schmidt’s upcoming book, The New Digital Age, isn’t pulling any punches. From the “irrelevance” of anonymity to some juicy thoughts on Twitter, the Wall Street Journal published some thought-provoking quotes from the book slated to be released in April.
...Twitter can no more produce analysis than a monkey can type out a work of Shakespeare.
...Within search results, information tied to verified online profiles will be ranked higher than content without such verification, which will result in most users naturally clicking on the top (verified) results. The true cost of remaining anonymous, then, might be irrelevance.
...“It’s fair to say we’re already living in an age of state-led cyber war, even if most of us aren’t aware of it.


May we conclude that liability exceeds revenue?
"U-T San Diego reports that the city has become 'the latest in a cadre of California cities turning their backs on red-light cameras — aloof intersection sentries that have prompted $490 tickets to be mailed to 20,000 motorists per year' there. 'Mayor Bob Filner announced his decision to take down the city's 21 cameras at a news conference set at the most prolific intersection for the tickets, North Harbor Drive and West Grape Street, near San Diego International Airport. A crew went to work immediately taking down "photo enforced" signs throughout the city. "Seems to me that such a program can only be justified if there are demonstrable facts that prove that they raise the safety awareness and decrease accidents in our city," Filner said of the cameras. "The data, in fact, does not really prove it."' I have to say I'm a bit surprised that my city is voluntarily shedding potentially $9.8M in revenue after objectively evaluating a program.


It is always thus. We grant monopolies to ensure services at reasonable prices with no real understanding of the price structure.
"After the school computer lab and public library close for the night in many communities, the local McDonald's is often the only place to turn for students without internet access at home. 'Cheap smartphones and tablets have put Web-ready technology into more hands than ever,' reports the WSJ's Anton Troianovski. 'But the price of Internet connectivity hasn't come down nearly as quickly. And in many rural areas, high-speed Internet through traditional phone lines simply isn't available at any price. The result is a divide between families that have broadband constantly available on their home computers and phones, and those that have to plan their days around visits to free sources of Internet access.' The FCC says it can make broadband available to all Americans by spending $45 billion over 10 years, but until then the U.S. will have to rely on Mickey D's, Starbucks, and others to help address its digital divide. Time to update that iconic McDonald's sign?"

(Related) Once you are a monopoly, you can do whatever you want...
"Joel Runyon recounts a tale that will be familiar to many people who have bought secondhand smartphones. After his old dumbphone died a few months ago, Runyon picked up a used iPhone. He just needed it for basic phone capabilities, and used it as such, turning data off. However, AT&T eventually figured out he was making calls from a smartphone, and they decided he needed a data plan, even if he wasn't going to use it. They went ahead and opted him into a plan that cost an extra $30 a month. Quoting: 'According to AT&T: They can opt me into a contract that I didn't agree to because I was using a phone that I didn't buy from them because it had the ability to use data that I wasn't using (and was turned off). To top it all off, they got the privilege of charging me for it because I bought a differently categorized device – even though the actual usage of their network did not change at all and I never reconstituted a new agreement with them.'"


For my students, because we are a “Technical” university...
10 Learnist Boards For The Tech-Savvy Teacher
.. There is a conversation ensuing between educators, policy makers, and industry leaders about the importance of teaching students coding and web design to prepare them for 21st century careers and entrepreneurship. Some are saying this is part of the Common Core Standards in technology, while others insist it’s actually another literacy, and should be treated as such.


For my students. I don't mind being Wile E. Coyote to your Road Runner, but if you cast me as Porky Pig, "Th-Th-Th-Th-Th-... That's an “F,” folks."
Animations are a fun way to convey your message to other people. If you are looking for a way to create animations online, then you will find a number of options to choose from. But few websites offer the speed and features offered by Miniclip’s Sketch Star.
Similar tool: SwarmSketch.

Saturday, February 02, 2013

If you haven't been hacked, China doesn't think you're important. (This Blog is safe.) On the other hand, Who has been hacked but has not (yet?) detected it?
Following on the heels of the New York Times, Bloomberg News, and the Wall Street Journal, sources have come forward to state that The Washington Post has also been hit by cyberattacks originating in China. The information was provided by individuals said to be familiar with the situation, including a former Post employee. The attacks were said to have occurred over the course of at least four years.


...and just for fun, we did it with 140 character programs!
"Earlier this week, hackers gained access to Twitter's internal systems and stole information, compromising 250,000 Twitter accounts before the breach was stopped. Reporting the incident on the company's official blog, Twitter's manager of network security did not specify the method by which hackers penetrated its system, but mentioned vulnerabilities related to Java in Safari and Firefox, and echoed Homeland Security's advisory that users disable Java in their browsers. Sure, blame everything on Larry Ellison. Looks like bad things do happen in threes — Twitter's report comes on the heels of disclosures of hacking attacks on the WSJ and NY Times."


What's the French word for “extortion?” Oh yeah, it's “extorsion.” Vive le France!
New submitter Flozzin writes with news of some resolution to the long-standing dispute that some French publishers have had with Google for republishing snippets of news reports without sharing revenue earned from the ads run alongside. Now, reports the BBC, "Google has agreed to create a 60m euro ($82m; £52m) fund to help French media organisations improve their internet operations. [Let's hope this does not mean “find more victims” Bob] It follows two months of negotiations after local news sites had demanded payment for the privilege of letting the search giant display their links. The French government had threatened to tax the revenue Google made from posting ads alongside the results."


A potential guide for government Health Care systems?
Jack Doyle reports:
GPs are to be forced to hand over confidential records on all their patients’ drinking habits, waist sizes and illnesses.
The files will be stored in a giant information bank that privacy campaigners say represents the ‘biggest data grab in NHS history’.
They warned the move would end patient confidentiality and hand personal information to third parties.
The data includes weight, cholesterol levels, body mass index, pulse rate, family health history, alcohol consumption and smoking status.
Diagnosis of everything from cancer to heart disease to mental illness would be covered. Family doctors will have to pass on dates of birth, postcodes and NHS numbers.
Officials insisted the personal information would be made anonymous and deleted after analysis.
Read more on Daily Mail.
And if you’re looking for additional information on the Everyone Counts initiative, you might want to check out this NHS Commissioning Board web site. One of the documents on that site provides more details on the clinical data sets and the types of information GPs are required to submit.
It is understandable, and even commendable, that public health authorities want to get a handle on the state of the public’s health and available services to improve them. Our own CDC also compiles data that points to underserved groups of patients, etc. But requiring physicians to provide such extensive information on every patient in conjunction with the patient’s national NHS identifier when we know that the NHS has had numerous data security and privacy breaches is a breach waiting to happen. Under the scheme, GPs would be providing:
  • NHSNumber
  • Date of Birth
  • Gender
  • PostCode
  • EthnicityCode
  • Registration Status
  • RegistrationDate
  • DeRegistrationDate
  • Date of Death
And then there is all the medical/mental health information.
I think the NHS is overly and unduly confident of its ability to secure data. How many thousands of people will have access to the data that has been electronically inputted by physicians? And for how long will they store the data before it is analyzed and then deleted?
Overall, it appears that the NHS has taken the notion of public health to an extreme at the expense of patient confidence in the confidentiality of their visits to their doctors. How many patients will not seek care for fear of mental health or other problems being reported to a central authority?
Just as health care professionals in the U.S. need to resist some government plans to require us to provide data on our patients, so, too, do British health care organizations need to take a long hard look at confidentiality issues. The BMA has expressed some concerns, but confidentiality doesn’t appear to be among them. Hopefully they will address confidentiality and security issues in a further post.


On Marh 15th, The Privacy Foundation (http://privacyfoundation.org/ ) will host a seminar to correct all of the FTC's errors. Mark your calendar!
The FTC has released a new report: Mobile Privacy Disclosures: Building Trust Through Transparency. From the Executive Summary:
Based on the Commission’s prior work in this area, the panel discussions, and the written submissions, this report offers several suggestions for the major participants in the mobile ecosystem as they work to improve mobile privacy disclosures.
Platforms, or operating system providers offer app developers and others access to substantial amounts of user data from mobile devices (e.g., geolocation information, contact lists, calendar information, photos, etc.) through their application programming interfaces (APIs). In addition, the app stores they offer are the interface between users and hundreds of thousands of apps. As a result, platforms have an important role to play in conveying privacy information to consumers. While some platforms have already implemented some of the recommendations below, those that have not should:
  • Provide just-in-time disclosures to consumers and obtain their affirmative express consent before allowing apps to access sensitive content like geolocation;
  • Consider providing just-in-time disclosures and obtaining affirmative express consent for other content that consumers would find sensitive in many contexts, such as contacts, photos, calendar entries, or the recording of audio or video content;
  • Consider developing a one-stop “dashboard” approach to allow consumers to review the types of content accessed by the apps they have downloaded;
  • Consider developing icons to depict the transmission of user data;
  • Promote app developer best practices. For example, platforms can require developers to make privacy disclosures, reasonably enforce these requirements, and educate app developers;
  • Consider providing consumers with clear disclosures about the extent to which platforms review apps prior to making them available for download in the app stores and conduct compliance checks after the apps have been placed in the app stores;
  • Consider offering a Do Not Track (DNT) mechanism for smartphone users. A mobile DNT mechanism, which a majority of the Commission has endorsed, would allow consumers to choose to prevent tracking by ad networks or other third parties as they navigate among apps on their phones.
App developers should:
  • Have a privacy policy and make sure it is easily accessible through the app stores;
  • Provide just-in-time disclosures and obtain affirmative express consent before collecting and sharing sensitive information (to the extent the platforms have not already provided such disclosures and obtained such consent);
  • Improve coordination and communication with ad networks and other third parties, such as analytics companies, that provide services for apps so the app developers can provide accurate disclosures to consumers. For example, app developers often integrate third-party code to facilitate advertising or analytics within an app with little understanding of what information the third party is collecting and how it is being used. App developers need to better understand the software they are using through improved coordination and communication with ad networks and other third parties.
  • Consider participating in self-regulatory programs, trade associations, and industry organizations, which can provide guidance on how to make uniform, short-form privacy disclosures.
Advertising networks and other third parties should:
  • Communicate with app developers so that the developers can provide truthful disclosures to consumers;
  • Work with platforms to ensure effective implementation of DNT for mobile.
App developer trade associations, along with academics, usability experts and privacy researchers can:
  • Develop short form disclosures for app developers;
  • Promote standardized app developer privacy policies that will enable consumers to compare data practices across apps;
  • Educate app developers on privacy issues.
Download the full report here.


“We heard your protests and after review have decided to ignore them.”
"Facebook has brought back its photo Tag Suggestions feature to the U.S. after temporarily suspending it last year to make some technical improvements. Facebook says it has re-enabled it so that its users can use facial recognition 'to help them easily identify a friend in a photo and share that content with them.' Facebook first rolled out the face recognition feature across the U.S. in late 2010. The company eventually pushed photo Tag Suggestions to other countries in June 2011, but in the US there was quite a backlash. Yet Facebook doesn't appear to have made any privacy changes to the feature: it's still on by default."


Not exactly an App, but an interesting “big data” tool...
IBM Security Tool Can Flag ‘Disgruntled Employees’
… The new tool, called IBM Security Intelligence with Big Data, is designed to crunch decades worth of emails, financial transactions and website traffic, to detect patterns of security threats and fraud. Beyond its more conventional threat prevention applications, the new platform, based on Hadoop, a framework that processes data-intensive queries across clusters of computers, will allow CIOs to conduct sentiment analysis on employee emails to determine which employees are likely to leak company data, Mr. Bird said. That capability will look at the difference between how an employee talks about work with a colleague and how that employee discusses work on public social media platforms, flagging workers who may be nursing grudges and are more likely to divulge company information. “By analyzing email you can say this guy is a disgruntled employee and the chance that he would be leaking data would be greater,” Mr. Bird said of IBM’s new tool.


For my Geeks...


For anyone who has to be out and about during “Commercial Fest” (More sources in the article)
… If you head over to the CBS Sports home page and click on over to their /SuperBowl/ portal, you’ll be able to see the whole game live.
… If you’re a Verizon user and you’ve subscribed to NFL Mobile, you’re in luck – the whole game will be streamed through your smartphone.


The future of education?
Friday, February 1, 2013
200+ MOOCs and Free Online Certificate Programs
… To help you find a MOOC that interests you and or your students Open Culture has created a list of more than 200 MOOCs and free certificate programs.
Stephen Downes also has a nice MOOC listing going on his MOOC.ca page. 


My weekly amusement...
… TorrentFreak reports that the University of Illinois is disconnecting the Internet of students who are accused of piracy after their first warning. “When copyright holders send a DMCA notice informing the university about unauthorized BitTorrent downloads, the student’s dorm room is immediately cut off from the Internet.”
… The patent system in the U.S. is broken. Case in point, the awarding this week of a patent to the University of Phoenix for its Academic Activity Stream, an educational news feed. There’s lots of prior art here, including Facebook’s patent on the news feed itself. Phil Hill offers more thoughts on e-Literate. Will ed-tech soon see round 2 of the great LMS patent wars (Blackboard v Desire2Learn) with the University of Phoenix going after those who use news feeds in their software (namely Instructure, Edmodo, Schoology, Pearson’s OpenClass…)?


Dilbert shows one downside (upside?) of Behavioral Advertising...

Friday, February 01, 2013

It's just the Chairman, checking his US investments...
"The Wall Street Journal said Thursday its computers were hit by Chinese hackers, the latest U.S. media organization citing an effort to spy on its journalists covering China. The Journal made the announcement a day after The New York Times said hackers, possibly connected to China's military, had infiltrated its computers [Interesting phrase from journalists who write accurately... Bob] in response to its expose of the vast wealth amassed by a top leader's family. The Journal said in a news article that the attacks were 'for the apparent purpose of monitoring the newspaper's China coverage' and suggest that Chinese spying on U.S. media 'has become a widespread phenomenon.'"

(Related) Can we wage war without drones? (Is this what all the “digital Pearl Harbor” posturing was about?)
U.S. weighs retaliation to alleged Chinese cyberattacks
The Obama administration is considering further action after the failure of high-level talks with Chinese officials over cyberattacks against America, according to the Associated Press.
The AP reports that two former U.S. officials say the administration is currently preparing a new National Intelligence Estimate -- a governmental assessment of concerns relating to security -- in order to better understand and analyze the persistence of cyberattacks that come from China.
Once this is complete, it will apparently be possible to better address the security threat, as well as justify actions to defend both the general public and national security.


At least they weren't Chinese...
"Amazon.com, the multi-billion online retail website, experienced an outage of unknown proportions on Thursday afternoon. Rumblings of an Amazon.com outage began popping up on Twitter at about 2:40 PM ET. Multiple attempts to access the site around 3:15 PM ET on Thursday were met with the message: 'Http/1.1 Service Unavailable.' By 3:30 PM ET the site appeared to be back online for at least some users. How big of a deal is an hour-long Amazon outage? Amazon.com's latest earnings report showed that the company makes about $10.8 billion per quarter, or about $118 million per day and $4.9 million per hour."
Update: 01/31 22:25 GMT by T : "Hackers claim credit."
[From the update:
The group went on detail how it knocked the front door down (only Amazon.com's front page was offline), with a large "botnet" or network of thousands of computers working together.
… Amazon.com averages $100,000 per minute in sales according to the Seattle Times.
“The gateway page of Amazon.com was offline to some customers for approximately 49 minutes,"


Your Computer Security managers should be able to explain each of these...
Security threats have increasingly come from new directions and that isn’t looking set to change in 2013. There are new risks you should be aware of, exploits of popular applications, increasingly sophisticated phishing attacks, malware, and scams targeting our love of social networks and photo sharing, and threats associated with viewing online videos.


Honest, this is not my Ethical Hackers retaliating for the New York Times hack. I know the lawyers at the Sturm College of Law (University of Denver) are looking at Mobile Apps for a March 15th seminar, perhaps we can get them to include a few malware Apps like this one...
"A new discovered malware is potentially one of the most costly viruses yet discovered. Uncovered by NQ Mobile, the 'Bill Shocker' (a.expense.Extension.a) virus has already impacted 620,000 users in China and poses a threat to unprotected Android devices worldwide. Bill Shocker downloads in the background, without arousing the mobile device owner's suspicion. The infection can then take remote control of the device, including the contact list, Internet connections and dialing and texting functions. Once the malware has turned the phone into a "zombie," the infection uses the device to send text message to the profit of advertisers. In many cases, the threat will overrun the user's bundling quota, which subjects the user to additional charges."

(Related) Some of these depend on users having Smartphones.
FTC’s $50,000 Robocall Challenge nets 744 ideas to shut down robocallers
The Federal Trade Commission today said the submission period for its Robocall Challenge had ended and it got 744 new ideas for ways to shut down the annoying automated callers.


Now there is an eye catching headline! (I can't yet confirm this, but I am dilligently viewing as many porn sites as possible...)
"The popular belief is that security risks increase as the user engages in riskier and shadier behavior online, but that apparently isn't the case, Cisco found in its 2013 Annual Security report. It can be more dangerous to click on an online advertisement than an adult content site these days, according to Cisco. For example, users clicking on online ads were 182 times more likely to wind up getting infected with malware than if they'd surfed over to an adult content site, Cisco said. The highest concentration of online security targets do not target pornography, pharmaceutical, or gambling sites as much as they affect legitimate sites such as search engines, online retailers, and social media. Users are 21 times more likely to get hit with malware from online shopping sites and 27 more times likely with a search engine than if they'd gone to a counterfeit software site, according to Cisco's report (PDF). There is an overwhelming perception that people get compromised for 'going to dumb sites,' Mary Landesman, senior security researcher at Cisco, told SecurityWeek."


I forget. Are we here in Oceania at war with Eastasia or Eurasia?
"Leading privacy expert Caspar Bowden, warned European citizens not to use cloud services hosted in the U.S. over spying fears. Bowden, former privacy adviser to Microsoft Europe, explained at a panel discussion hosted at the recent Computers, Privacy and Data Protection conference in Brussels, that a section in the Foreign Intelligence Surveillance Act Amendments Act 2008 (FISAAA) permits U.S. intelligence agencies to access data owned by non-U.S. citizens on cloud storage hosed by U.S. companies, if their activity is deemed to affect U.S. foreign policy. Bowden claimed the Act allows for purely political spying of activists, protesters and political groups. Bowden also pointed out that amendments to the EU's data protection regulation proposal, introduce specific loopholes that permit FISAAA surveillance. The president of Estonia, Toomas Hendrik Ilves (at a separate panel discussion) commented that, "If it is a US company it's the FBI's jurisdiction and if you are not a US citizen then they come and look at whatever you have if it is stored on a US company server". The European Data Protection Supervisor declined to comment but an insider indicated that the authority is looking into the matter."


Pop quiz material for my students!

Thursday, January 31, 2013

It's only the Times. God help them if they shut down the SuperBowl telecast!
Hackers in China Attacked The Times for Last 4 Months
For the last four months, Chinese hackers have persistently attacked The New York Times, infiltrating its computer systems and getting passwords for its reporters and other employees.
… The timing of the attacks coincided with the reporting for a Times investigation, published online on Oct. 25, that found that the relatives of Wen Jiabao, China’s prime minister, had accumulated a fortune worth several billion dollars through business dealings.
… The hackers tried to cloak the source of the attacks on The Times by first penetrating computers at United States universities and routing the attacks through them, said computer security experts at Mandiant, the company hired by The Times. This matches the subterfuge used in many other attacks that Mandiant has tracked to China.


Keeps my secret identity secret!
I’ve been checking Foursquare’s site occasionally today as they indicated that a change in their Terms of Service was forthcoming. Now it’s here, and it’s great.
As I blogged earlier today, Foursquare had implemented their new “full name” privacy policy, announced last month, even though it seemed to be in conflict with their media statements that suggested nyms could be used, and their Terms of Service that required “truthful” registration information.
Their new TOS, dated yesterday but uploaded today, states, in relevant part:
Registration and Eligibility.
You may browse the Site and view Content without registering, but as a condition to using certain aspects of the Service, you are required to register with Foursquare and represent, warrant and covenant that you provide Foursquare with accurate and complete registration information (including, but not limited to a user name (“User Name”), e-mail address and a password you will use to access the Service) and to keep your registration information accurate and up-to-date. Failure to do so shall constitute a breach of these Terms of Use, which may result in immediate termination of your Foursquare account. We recommend, but do not require, that you use your own name as your User Name so your friends can recognize you more easily. (emphasis added by me)
This is good news, indeed, and I think they made a great policy decision. Hopefully, they’ll allow users who registered using real names to change to usernames if they so desire.
Frankly, I have no idea if any of this was already under internal review before Jules Polonetsky, Greg Norcie, and I individually contacted them with our observations and questions, but either way, it’s a good outcome for user privacy.


I don't think the IRS has a sense of humor either...
"An employee of the Canada Revenue Agency lost his job after releasing a humorous game in which the player answers customer service calls for the Agency, usually leading to his termination. In an email National Revenue Minister Gail Shea said: 'The Minister considers this type of conduct offensive and completely unacceptable. The Minister has asked the Commissioner (of Revenue, Andrew Treusch) to investigate and take any and all necessary corrective action. The Minister has asked the CRA to investigate urgently to ensure no confidential taxpayer information was compromised.'"


Perhaps we should think about this in the US?
"As the UK prepares to shake up the way computer science is taught in schools, Redmond is warning that the UK risks falling behind other countries in the race to develop and nurture computing talent, if 'we don't ensure that all children learn about computer science in primary schools.' With 100,000 unfilled IT jobs but only 30,500 computer science graduates in the UK last year, MS believes: 'By formally introducing children to computer science basics at primary school, we stand a far greater chance of increasing the numbers taking the subject through to degree level and ultimately the world of work.'"


OMG! IMHO this is too much! (Don't they Google these requests?)
First time accepted submitter 3seas writes in about DMVs across the country learning textspeak in order to keep vulgar acronyms off the road.
"You can have txtspeak on your plate in Arizona, but only if you keep it clean. 'ROFLMAO' is a no-go. Arkansas, however, seems to be a little slower on the uptake. 'ROFLMAO' doesn't appear on the state's prohibited list. That doesn't necessarily mean the plate would pass DMV scrutiny should someone request it."


Everything is a joke today... Isn't it? I mean, would we ever see the “TRUE” sign?
The Washington Post has announced a prototype news application called "Truth Teller", that displays “TRUE" or “FALSE” in real time next to video of politicians as they speak. The Knight Foundation-funded program automatically transcribes speeches and checks the statements against a database of facts. From the article: "For now, the early beta prototype has to be manually hand-fed some facts, and thus only works on topics it has been specifically designed to recognize. Since Congress has yet to pass a budget, and financial discussions are prone to widespread lies and misstatements, Truth Teller is being piloted on the issue of tax policy."


Now all I need is a reason for everyone to give me money!
… I’d like to ... show you all of the different ways that you can actually accept payments from people.


Dilbert voices one of my long time concerns...

Wednesday, January 30, 2013

So would this automatically suggest negligence?
"Five years after the disclosure of a serious vulnerability in the Domain Name System dubbed the Kaminsky bug, only a handful of U.S. ISPs, financial institutions or e-commerce companies have deployed DNS Security Extensions (DNSSEC) to alleviate this threat. In 2008, security researcher Dan Kaminsky described a major DNS flaw that made it possible for hackers to launch cache poisoning attacks, where traffic is redirected from a legitimate website to a fake one without the website operator or end user knowing. While DNS software patches are available to help plug the Kaminsky hole, experts agree that the best long-term fix is DNSSEC, which uses digital signatures and public-key encryption to allow websites to verify their domain names and corresponding IP addresses and prevent man-in-the-middle attacks. Despite the promise of DNSSEC, the number of U.S. corporations that have deployed this added layer of security to their DNS server is minuscule."


The models for 'Best practices' or simply the 'Least Bad?' Most likely, neither...
From their Executive Summary:
Ponemon Institute’s Most Trusted Companies for Privacy Study is an objective study that asks consumers to name and rate organizations they believe are most committed to protecting the privacy of their personal information. This annual study tracks consumers’ rankings of organizations that collect and manage their personal information.
More than 100,000 adult-aged consumers were asked to name up to five companies they believe to be the most trusted for protecting the privacy of their personal information. Consumer responses were gathered over a 15-week period concluding in December 2012 and resulted in a final sample of 6,704 respondents who, on average, provided 5.4 discernible company ratings that represent 25 different industries.
Following are our most salient findings:
  • American Express (AMEX) continues to reign as the most trusted company for privacy among 217 organizations rated in our most trusted companies list.
  • New entrants to this year’s top 20 most trusted list includes: Microsoft (ranked 17), United Healthcare (ranked 18) and Mozilla (ranked 20).
  • Healthcare, consumer products, and banking are the industry segments considered by consumers to be the most trusted for privacy (among 25 industry categories). In contrast, Internet and social media, non-profits (charities) and toys are viewed as the least trusted for privacy.
  • Seventy-eight percent of respondents continue to perceive privacy and the protection of their personal information as very important or important to the overall trust equation. Further, the importance of privacy has steadily trended upward over seven years.
  • While most individuals say protecting the privacy of their personal information is very important, 63 percent of respondents admit to sharing their sensitive personal information with an organization they did not know or trust. Of those who admit to sharing, 60 percent say they did this solely for convenience such as when making a purchase.
  • Fifty-nine percent of respondents believe their privacy rights are diminished or undermined by disruptive technologies such as social media, smart mobile devices and geo-tracking tools. Fifty-five percent say their privacy has been diminished by virtue of perceived government intrusions.
  • Only 35 percent of respondents believe they have control over their personal information and this result has steadily trended downward over seven years.
  • Less than one-third (32 percent) of respondents admit they do not rely on privacy policies or trust seal programs when judging the privacy practices of organizations they deal with. When asked why, 60 percent believe these policies are too long or contain too much legalese.
  • Forty-nine percent of respondents recall receiving one or more data breach notifications in the past 24 months. Seventy percent of these individuals said this notification caused a loss of trust in the privacy practices of the organization reporting the incident.
  • Seventy-three percent of respondents believe the substantial security protections over their personal information is the most important privacy feature to advancing a trusted relationship with business or government organizations. Other important privacy features include: no data sharing without consent (59 percent), the ability to be forgotten (56 percent) and the option to revoke consent (55 percent).
  • The number one privacy-related concern expressed by 61 percent of respondents is identity, closely followed by an increase in government surveillance (56 percent).
Read the full report here.


So all the contract language needs to change?
Helpful write-up by Dena Feldman on the final HITECH rule as it applies to business associates and subcontractors includes:
Direct Liability under the Security Rule. The final rule alters the regulations to expressly subject business associates to the administrative, physical, and technical safeguard requirements of the Security Rule. HHS commented that, because business associates previously had to agree in their business associate agreements with covered entities to appropriately protect and safeguard PHI, business associates and subcontractors “should already have in place” security practices that are compliant with the rule or need only “modest improvements.” HHS recognized, however, that many business associates will not have engaged in the “formal administrative safeguards” required by the rule.
Direct Liability under the Privacy Rule. The final regulations modify the Privacy Rule to extend direct liability for disclosures of PHI by business associates. However, the rule does not subject business associates to liability for all aspects of the Privacy Rule. Business associates are liable for:
  • uses or disclosures of PHI in a manner not in accord with the business associate agreement or the Privacy Rule;
  • failure to disclose PHI when required by HHS for an investigation and/or determination of the business associate’s compliance with HIPAA;
  • failure to disclose PHI to the covered entity, an individual (to whom the information pertains), or the individual’s designee with respect to an individual’s request for an electronic copy of the information;
  • failure to make reasonable efforts to limit PHI uses, disclosures, and requests to the minimum necessary amount; and
  • failure to enter into a business associate agreement with a subcontractor that creates or receives PHI on their behalf.
Read more on InsidePrivacy.


I have visions of teachers discovering communications with lawyers about abuse by school officials. Things could go south really quickly.
The Fourth Amendment question here is not about the seizure, but the search that came afterward.
A Berne parent grew outraged after a school principal confiscated his son’s phone earlier this week after being caught texting in class. It’s not the confiscation of the 14-year-old’s iPhone 5 that caused the ire, but rather the searching of it, which revealed inappropriate photos of his 14-year-old ex-girlfriend. The principal, Brian Corey, contacted the Albany County Sheriff’s Department.
Law enforcement and legal experts agree schools have a greater right to search students and their property than do police among the general public, where the Fourth Amendment protects against unreasonable searches and seizures. The question is the line where it becomes too invasive given the circumstances.
Read more on the Albany Times-Union.
Does your teen understand that their school administrator might not only confiscate, but scroll through their images and emails? I’m not saying administrators should – indeed, I think they generally shouldn’t unless there’s an imminent threat of danger to the student or others — but it could happen. And as in this case, inappropriate images could result in the police being called for child pornography.
Are you ready for that? Is your child?
Talk with your kids. Again and again and again.
But also ensure you understand your school district’s policies on this. If you’re not sure, ask under what conditions they might not only confiscate, but search your child’s mobile devices.
And then talk with your child again.
[From the article:
Technically, since the ex-girlfriend sent the images, both youths could face child pornography charges for the photos. The sheriff's department is in the process of obtaining a search warrant for the phone, but at this point it doesn't appear any charges, which would go to Family Court, will be filed.
"We've spoken to the district attorney's office," Sheriff Craig Apple said. "Right now, they don't want to go forward with the information they have.
… Apple … said, he believes students can't have an expectation of privacy on school grounds.

(Related) Another area where the constitution does not apply?
Brothel Patrons Have No Legal Expectation of Privacy, Judge Rules
Brothel patrons have no expectation of privacy, a Maine judge has ruled while dismissing 49 criminal counts against a man accused of secretly filming illicit sexual encounters at his Zumba studio that authorities claim was a bordello.
A local judge dropped the counts against Mark Strong, Sr., who was accused of breaching the privacy of those who paid to have sex with his female business partner at a Kennebunk, Maine dance studio he managed.
The 57-year-old defendant’s attorney, Dan Lilley, successfully argued that the state law protecting the privacy of people in dressing rooms, locker rooms and restrooms did not apply to those having illegal sex with a prostitute.
That law, Lilley argued, “does not apply to bordellos, whorehouses and the like.” He said “those places are to commit crime. There is no expectation to privacy.”


Dude, don't mess with the Mouse! It's clear from this letter that they carefully introduced the program – nothing happens haphazardly in the Magic Kingdom.
Dominic Patten reports:
Bob Iger today told a Massachusetts congressman that his privacy issue concerns about new technology being introduced at Disney theme parks are bunk. “We are offended by the ludicrous and utterly ill-informed assertion in your letter dated January 24, 2013, that we would in any way haphazardly or recklessly introduce a program that manipulates children, or wantonly puts their safety at risk,” the Disney chairman and CEO wrote in a letter (read it in full below) Monday to Ed Markey.
Read more on Deadline.com


New features equals new concerns for management.
"Microsoft's release of Office 2013 represents the latest in a series of makeover moves, this time aimed at shifting use of its bedrock productivity suite to the cloud. Early hands-on testing suggests Office 2013 is the 'best Office yet,' bringing excellent cloud features and pay-as-you-go pricing to Office. But Microsoft's new vision for remaining nimble in the cloud era comes with some questions, such as what happens when your subscription expires, not to mention some gray areas around inevitable employee use of Office 2013 Home Premium in business settings."
Zordak points to coverage of the new Office model at CNN Money, and says "More interesting than the article itself is the comments. The article closes by asking 'Will you [pay up]?' The consensus in the comments is a resounding 'NO,' with frequent mentions of the suitability of OpenOffice for home productivity." Also at SlashCloud.


For my literate friends who will no doubt say, “Bob you idiot, you forgot...”


Worth reading. Here are some bits...
Eight Brilliant Minds on the Future of Online Education
Why this disruption is happening:
Peter Thiel, partner, Founders Fund
"In the United States, students don't get their money's worth. There's a bubble in education as out of control as the housing bubble and the tech bubble in the 1990s.
Bill Gates, chairman of Microsoft
Our whole notion of 'credential', which means you went somewhere for a number of hours, needs to move to where you can prove you have the knowledge and the quality of these online courses need to improve.
Rafael Reif
"Can you hire MIT professors who know that they need to teach 150,000 people and not 150?