Tuesday, August 29, 2006

If your defense is “Hey, I'm just a kid!” then a punishment like “Go to your room!” seems appropriate. If you can read “sensitive” Secret Service information, your room should be at Guantanamo.

http://hosted.ap.org/dynamic/stories/C/CELLULAR_HACKER?SITE=VALYD&SECTION=HOME&TEMPLATE=DEFAULT

Aug 28, 11:14 PM EDT

T-Mobile Hacker Gets Home Detention

LOS ANGELES (AP) -- A hacker who infiltrated the network of T-Mobile USA Inc. and accessed personal information of hundreds of customers, including a Secret Service agent, was sentenced Monday to one year of home detention.

Nicholas Lee Jacobsen, 23, must also pay $10,000 in restitution to T-Mobile to cover losses caused by his acts, which took place in 2004.

The former Santa Ana resident who now lives in Oregon said he lacked "comprehension and maturity" when he targeted the network of Bellevue, Wash.-based T-Mobile USA, uncovering the names and Social Security numbers of 400 customers.

"I did some very stupid things," Jacobsen told U.S. District Judge George King at his sentencing Monday in Los Angeles.

Jacobsen was able to read some sensitive information that Special Agent Peter Cavicchia could access through his wireless T-Mobile Sidekick device. No investigations were compromised, the Secret Service said.

"What you've done is very dangerous to others. Maybe you didn't fully appreciate that, perhaps because of your youth," King told Jacobsen Monday.

Jacobsen could have faced a maximum sentence of five years in prison and a fine of up to $250,000 for the crime, accessing a protected computer.


On the other hand...

http://seattlepi.nwsource.com/local/282674_botnet26.html

Hacker sentenced to 37 months in prison

Victims in global attack included U.S. military

By PAUL SHUKOVSKY P-I REPORTER Saturday, August 26, 2006

Sending a message to malicious computer hackers "squirreled away in their basements," U.S. District Judge Marsha Pechman on Friday sentenced a 21-year-old man to 37 months in federal prison for a global robot virus attack in 2004 and 2005.

Christopher Maxwell launched the attack from the comfort of his Vacaville, Calif., home in order to collect commissions by installing adware onto the computers of unwitting victims.

To achieve his aim, he essentially took remote control of huge numbers of computers around the world, causing them to spread the infection and increase his profits. The Seattle FBI's cybersquad believes the scheme netted Maxwell and two unnamed teenage accomplices more than $100,000.

Among the countless victims, the virus wreaked havoc with the Defense Department, [Oh? Bob] Seattle's Northwest Hospital and a school district in California. Disaster preparations by the military and the hospital prevented significant damage, but the Colton Unified School District was not so fortunate.

"It took the district to its knees," said Gary Stine, the district's former director of information technology.

"We don't plan for calamities like this. The real impact was to our teachers and our students" who lost crucial instructional time on PCs used to teach such topics as English as a second language. The repairs cost the district more than $50,000.

At Northwest Hospital, digital systems used for transmitting results from medical labs and the radiology department directly to physicians crashed, said Vice President Robert Steigmeyer.

The hospital switched to its well-drilled disaster plan, which involves the use of runners to move medical records and lab test results. Elective medical procedures, however, had to be rescheduled.

No patients were harmed as a result of the attack, and Maxwell made no attempt to steal confidential patient information.

Army Maj. Keithon Corpening, who runs the Defense Department's computer incident response team, told Pechman that a full-scale investigation was launched after the military saw 407 of its computers taken over by an unknown assailant they dubbed "Don't Trip." Eight investigators were assigned to the case.

"Planes still flew, tanks were still operating, soldiers were getting their supplies," Corpening said. But "the potential for damage to our systems" was significant.

No military information was stolen, he said.

Assistant U.S. Attorney Kathryn Warma, in arguing for a six-year sentence, told Pechman: "The importance of deterrence in this case is profound. There is a hacker community. They will know immediately what sentence you impose."

Maxwell, holding back tears, pleaded for probation in lieu of prison time.

"I am a 21-year-old boy with a good heart and I made a mistake," he told the judge. "I never realized how dangerous a computer could be. I thank God no one was hurt."

Pechman rejected attempts by Maxwell and his attorney to portray him as being shocked by the consequences of his actions. "It is obvious that anyone who would launch this kind of computer attack would know" that there would be a multitude of victims, she said. [Well reasoned! Or is it obvious? Bob]

And while Pechman took Maxwell's age and lack of criminal record into account, she said the prison term was necessary to provide a deterrent to other hackers.

The robot virus program, or "botnet" software, used by Maxwell was sent over the Web, where it sought out computers with exploitable security flaws. [...which it found 407 times on Defense Department computers? Bob] He pleaded guilty in May to a felony charge of conspiracy to intentionally cause damage to a protected computer.



Why are so many media firms rushing to use technology that is a favorite target for hackers?

http://www.engadget.com/2006/08/25/fairuse4wm-strips-windows-media-drm/

FairUse4WM strips Windows Media DRM!

Posted Aug 25th 2006 11:48AM by Ryan Block Filed under: Portable Audio



Towards ubiquitous surveillance: “You have nothing to worry about if you're not guilty.” (Is this proof that the 'no fly list' isn't working?)

http://www.washingtonpost.com/wp-dyn/content/article/2006/08/28/AR2006082800849.html?nav=rss_opinions/columnsandblogs

A Tool We Need to Stop the Next Airliner Plot

By Michael Chertoff Tuesday, August 29, 2006; Page A15

Imagine that our troops in Afghanistan raided an al-Qaeda safe house and captured a computer containing the cellphone numbers of operatives in Europe. Wouldn't it be important to know whether one of those cellphone numbers was used to book a transatlantic flight? Unfortunately, today our ability to make that connection remains limited: Information that terrorists readily share with travel agents cannot easily be shared throughout the United States government. That needs to change.



Global warming update

http://www.technewsworld.com/rsstory/52663.html

Almanac Forecasts Frigid Winter

By David Sharp AP 08/28/06 8:00 PM PT

According to the Farmers' Almanac, the coming winter should be colder than normal from coast to coast. It'll be especially snowy across the nation's midsection, much of the Pacific Northwest, the mountains of the Southwest and parts of eastern New England, the almanac predicts.



I'll bet there would be a market for a “Legal guide to municipal WiFi”

http://www.technewsworld.com/rsstory/52561.html

Municipal WiFi Networks Popping Up All Over

By Paul Korzeniowski TechNewsWorld 08/29/06 4:00 AM PT

A large number of uncertainties are associated with municipal WiFi at this stage, so municipalities are starting slowly. "Most of the cities are starting small and seeing what the true implementation hurdles are before rolling out the services completely," said Christopher Baum, research vice president at Gartner.



At last!

http://www.eweek.com/article2/0,1759,2009403,00.asp?kc=EWRSS03119TX1K0000594

Unpatched Flaws to Be Published

By Ryan Naraine August 28, 2006

A security company that pays hackers for information on software exploits and flaws plans to release a list of 29 unpatched flaws in products sold by a host of big-name vendors, including Microsoft, IBM, Apple Computer and Novell.

The Aug. 28 disclosure from TippingPoint's ZDI (Zero Day Initiative) flaw bounty program is a significant change to the way the 3Com-owned company has handled the disclosure of vulnerability data it buys from external researchers.

Instead of waiting for software makers to issue patches, TippingPoint will announce the flaw purchase in bare-bones advisories at the time the issue is reported to the vendor.

... "We're not identifying the software or product versions. [Isn't that wimping out? Bob] We're simply naming the vendor, the date the issue was reported and the severity of the vulnerability," Endler said.



Does this indicate they now grasp the obvious? Is this an indication that their next operating system release will not be a “must have” for their largest customers? Is this just one more sign Microsoft is becoming just another software company? Or D: all of the above.

http://www.eweek.com/article2/0,1759,2009479,00.asp?kc=EWRSS03119TX1K0000594

Microsoft Offers Broader Support for Legacy Products

By Peter Galli August 28, 2006

Microsoft seems to have finally cottoned onto the fact that it can drive revenue from the use of legacy software by some of its largest customers, announcing on Aug. 28 a new Custom Support Agreement program.



http://news.com.com/2100-1041_3-6110277.html?part=rss&tag=6110277&subj=news

Digital cameras focus on revised reality

Consumers are embracing camera features that make them look thinner and more youthful. But what about society's trust in photography?

Photos: Camera makeovers By Candace Lombardi Staff Writer, CNET News.com Published: August 29, 2006, 4:00 AM PDT

Want to look thinner? Taller? Tanner? Don't worry, there's a camera for all that.

Today's cameras will let you do more than adjust the flash; they'll let you adjust reality. Photo-adjusting features that once required a PC and special know-how are now allowing consumers to alter a photo as soon as it's snapped.

Some new Hewlett-Packard cameras include a feature that makes subjects look thinner, while another mode makes facial lines and pores virtually disappear. A "skin tone" feature on some Olympus models can give consumers a leisure-class tan. Other manufacturers offer modes to make the colors of the world richer as you capture them. Using these new in-camera tools, consumers can even crop out ex-boyfriends, or put a virtual frame around a new one. [Let's hope they don't mean that in the evidentiary sense... Bob]



You mean Amazon is not alone?

http://www.bespacific.com/mt/archives/012282.html

August 28, 2006

Comparison and Evaluation of 10 Major Internet Bookshops

Hirwade, Mangala and Hirwade, Anil and Bherwani, Mohini (2006) Evaluative study of major Internet bookshops. ILA Bulletin XLII(1):pp. 32-43.

  • "Internet Bookshops are the online bookshops that allow the user to search the items of his interest, navigate, make a query, communicate, place an order, bargain and negotiate. At its simplest the Internet Bookshop or online bookshop list the products for sale or the services offered and invite the customer to phone, fax or e-mail their order. The present paper evaluates major ten Internet bookshops by using the evaluation criteria like Authority, variety of collection, help menu, shopping procedures, payment acceptance, special facilities for online purchase, user search support, product details, navigation facilities and discounts on the products. A 100 marks scoring system has been adopted to assign the scores to each Internet bookshop under study. Based on the marks obtained these bookshops are graded into five categories viz. Excellent, Very Good, Good, Average and Poor. Amazon.com, USA and Amazom, UK fall uder excellent category while the Internet bookshops from India viz D.K.Agencies and Khemraj fall under good and average category respectively."



God will get you for this!” Book of Bob, Chapter one Verse one

http://www.bespacific.com/mt/archives/012278.html

August 28, 2006

Pew Research Center for the People and the Press Report on Religion and Politics

Many Americans Uneasy with Mix of Religion and Politics - 69% Say Liberals Too Secular, 49% Say Conservatives Too Assertive, Released August 24, 2006.



Think of it as using the legal department as just another strategic tool. Any barrier to entry keeps the competition at bay. Should you NOT use every resource available? (What is needed is a “regulated ticket exchange” modeled on the Options market. Why shouldn't tickets be priced at “market?”)

http://techdirt.com/articles/20060828/152541.shtml

Apparently Ticketmaster Doesn't Like Having Competition

from the and-so-it-goes dept

Remember back in the day when Ticketmaster was the absolute monopoly in ticket sales for various venues and events? You simply couldn't avoid Ticketmaster and their ridiculous fees upon fees. A dozen years ago, Pearl Jam took on Ticketmaster, claiming that the company had a monopoly on ticket sales and were able to keep ticket price artificially high. Well, it appears that Ticketmaster doesn't like the idea that the internet has brought in new competition. Three years ago, we noted that, due to competition from online resale sites, Ticketmaster was launching a new service to auction off tickets itself. However, sites like Stubhub, eBay and Craigslist appear to have much better traffic for such things -- perhaps due to the public's general dislike of Ticketmaster for years and years of ridiculous fees. Of course, when you have a monopoly that is being attacked by competitors, what do you do? You go to the government to get new legislation passed to help you hold onto your monopoly. Ticketmaster is trying to get laws passed that would make it illegal to sell tickets above face value... unless you have an arrangement with the venue and they share in some of the profits. Ticketmaster, of course, already has many such deals in place. They spin this as "protecting" ticket buyers from fake scalped tickets, but the other sites in the space note that bogus tickets aren't a very big problem, and there are often other ways to deal with it. Instead, this looks like Ticketmaster is running to the government to help it keep its supposed monopoly in the face of competition.



One law to rule them... Oh, wait, that was a fantasy.

http://techdirt.com/articles/20060828/165835.shtml

Why Should EchoStar Wait For Patent Review When TiVo Doesn't Have To?

from the fairness? dept

In the ongoing battle over patents concerning DVR technology, both EchoStar and TiVo are suing each other, claiming the other company infringes on its patents. As was all over the news recently, TiVo won the first round, convincing a judge to tell EchoStar it needed to turn off its DVRs (a decision since stayed by the appeals court). However, a judge looking at the patent suit in the other direction has now told EchoStar it needs to wait until the Patent Office has reviewed the patent in question. This actually makes a lot of sense, and we all know at least one company that would still have over $600 million it was forced to give away if other judges followed similar rules. However, it seems a bit unfair that TiVo's case continued to move forward without USPTO review, while EchoStar needs to wait. It only seems fair to treat both cases the same. As it stands now, TiVo is in a much better bargaining position -- it's won its first case, and EchoStar has to wait before its own case will be reviewed. While it makes sense to allow USPTO review, shouldn't the courts follow the same rules in dealing with these types of cases?



Brilliant! This should drive up readership like nothing they've tried in years!

http://techdirt.com/articles/20060829/020547.shtml

New York Times Tells Brits They Can't Read Article On UK Terror Case

from the jurisdictional-silliness dept

Questions of legal jurisdiction over online content are nothing new at all. Over the years, we've pointed to plenty of legal cases that raised issues about online publications, and whether the content was liable under local laws in countries outside of where the publisher (or its servers) were based. Unfortunately, there still isn't a general agreement on what laws apply, and that makes things risky. Apparently, the NY Times didn't want to risk any such lawsuit in the UK, so when it published an article yesterday about the British terror case, it used some of its geographic ad targeting technology to also block out visitors from the UK from reading the content. This is to stay on the right side of British laws that "prohibits publication of prejudicial information about the defendants prior to trial." Of course, the Times then went on to publish an article proudly stating how they blocked the content from UK readers, which makes you wonder how effective the ban really is. By calling attention to it, it seems pretty likely that plenty of folks in the UK will be able to read the same (or similar) content from plenty of other sources. This isn't to call out the Times for the practice, but to question whether such laws are actually still possible in a world with a global internet.



What makes you think you're immune?

http://www.techzonez.com/comments.php?shownews=19104

Nine in 10 PCs infected with spyware

Posted by Reverend on 28 Aug 2006 - 19:27 GMT

Techzonez Nine out of ten PCs are infected with spyware, new research has found.

Full story: vnunet



http://www.infoworld.com/article/06/08/29/HNgoglelibraryscan_1.html?source=rss&url=http://www.infoworld.com/article/06/08/29/HNgoglelibraryscan_1.html

Google, UC disclose library scan agreement

Google contracts to digitize millions of books from the university's libraries

By Juan Carlos Perez, IDG News Service August 29, 2006

The University of California has released a copy of its contract with Google to have the search engine giant digitize millions of books from the university's libraries.

The document shines a light on the type of agreement Google is reaching with some of the world's largest academic libraries as part of its controversial project to scan portions of their collections.

The University of California decided to post the contract publicly to satisfy a "general interest" in the document, a university official said via e-mail. The disclosure follows a formal request to obtain a copy of the document filed by IDG News Service in mid-August with the university. The contract can be viewed here.



The more the merrier!

http://www.researchbuzz.org/wp/2006/08/28/worldcat-launches-with-10000-libraries-worldwide-searchable/

August 28, 2006

WorldCat Launches With 10,000 Libraries Worldwide Searchable

Filed under: Reference

Why yes, I am still catching up. I’m ALWAYS catching up. Anything else? Anyway, WorldCat.org has officially launched: http://www.worldcat.org . It’s in beta. Over 10,000 libraries in the OCLC cooperative are searchable from this one little box. How groovy is that? (And if you’re having a hard time wrapping your head around this, or the fact that there are over 70 million entries for items in this database, check out http://www.oclc.org/worldcat/grow.htm, which’ll give you a window to watch stuff being added into the database in real-time. I found this fascinating. I am a nerd.)



http://www.dottocomu.com/b/archives/003177.html

August 28, 2006

Japanese government prepares online lie-detector

Japan's Ministry of Internal Affairs and Communications is, for reasons best known to it, earmarking Y300 mn in its 2007 budget to produce what the Asahi Shimbun terms a lie-detector for online information.

The reality appears to be not so much that as an automated fact-checker that draws on related information to spot how likely something is to be a load of old balls. [Is that a l;iteral translation of the Japanese or a British-ism? Bob] The Ministry envisages it being able to give you search results in order of their reliability, or tell you that a piece of info is 95% crap and ask if you'd still like to display it. Example questions they see it being able to answer include "is this company analysis on the mark?", "is this a natural-sounding description of the political situation within Lebanon?", or "are the functions of this overseas electrical appliance described accurately in this auction listing?".

They note that key hurdles will be whether they can find reliable internet-based sources of information related to a search, and develop technologies that can accurately assess meaning and provide high-level machine translation, amongst other things.

It's unclear how they plan to establish the reliability of information, beyond taking the route of building an engine that tells you how in- or out-of-consensus a particular document is based on word frequencies or some other measure. And we somehow doubt that the AI Holy Grail of software that understands the meaning of natural language and can translate it accurately is about to be reached by some government researchers with $3 mn in funding. But still, nice of them to try.



Think you might have a skill? Here is one way to find out.

http://www.nytimes.com/2006/08/27/arts/television/27heff.html?ei=5090&en=b993c2e50a7b705d&ex=1314331200&partner=rssuserland&emc=rss&pagewanted=all

Web Guitar Wizard Revealed at Last

EIGHT months ago a mysterious image showed up on YouTube, the video-sharing site that now shows more than 100 million videos a day. A sinewy figure in a swimming-pool-blue T-shirt, his eyes obscured by a beige baseball cap, was playing electric guitar. Sun poured through the window behind him; he played in a yellow haze. The video was called simply “guitar.” A black-and-white title card gave the performer’s name as funtwo.

[Jump right to the video: http://www.youtube.com/watch?v=QjA5faZF1A8 ]



http://www.informationweek.com/news/showArticle.jhtml?articleID=192300841

Most Damaging Attacks Rely On Stolen Log-ins

Security safeguards need to identify, not just the user, but also the machine logging into the network.

By Gregg Keizer TechWeb Aug 28, 2006 03:15 PM

More than 8 out of every 10 computer attacks against businesses could be stopped if enterprises checked the identity of not only the user, but also the machine logging onto its network, a report released Monday claimed.

The study, conducted by a California research firm and paid for by BIOS maker Phoenix Technologies, used data from cases prosecuted by federal authorities between 1999 and 2006 to reach its conclusions.

"We wanted to get an honest viewpoint that wasn't opinion- or survey-based," said Dirck Schou, the senior director of security solutions at Phoenix. The problem with acquiring data on computer attacks, including the amount of damage done, is that companies are often hesitant to admit to a breach. "That's the beauty of this [data]," said Schou. "It's only looking at those who have actually suffered an attack."

According to the report, attacks based on logging in with stolen or hijacked credentials cost businesses far more, on average, than the typical worm or virus assault. When a privileged account is penetrated by an unauthorized user, the average damage runs to $1.5 million, the report said. The average cost from a single virus attack was much smaller: under $2,400.

"Cyber criminals who accessed privileged accounts obtained IDs and passwords through many means," the report said. "Network sniffing, use of password cracking programs, and collusion with insiders. It was also common for employees to share their IDs and passwords with coworkers who later left the organization and used that knowledge to gain access."

To bolster that outsider-as-attacker claim, the study also said that nearly 6 in 10 attackers had no relationship with the victim. (Just over a third (36 percent) were current and former employees.) Although the report's data contradicts other surveys that have pegged company insiders as the root of most attacks, the idea that credentials are good for ill-gotten gains isn't new. Earlier this year, for example, IBM predicted that attackers would increase their attacks against employees rather than networks.

"Viruses equal vandalism, but unauthorized log-ons lead to theft," said Schou. However, he acknowledged that the latter can come from the former, with worms and Trojan horses increasingly after information such as usernames and passwords rather than hoping to injure or bring down a network.

Overall, unsanctioned computers -- not among the systems actually expected to access the network -- were used in 84 percent of the attacks. The bulk of the attacks -- 78 percent -- came from at-home personal computers.

Naturally, Phoenix made much of that conclusion. It claimed that 84 percent of the attacks in the survey could have been prevented had the victim been protected by device authentication schemes. Such security identifies not only the user by checking ID and password, but can tell if the hardware has been authorized to connect to the network. Phoenix, for instance, sells a solution dubbed TrustConnector 2, that creates a unique identity for every authorized PC.

"What surprised us was the intensity and preponderance in unauthorized access attacks," said Schou. "We think device authentication is in the right time, right place.

"There are a lot of companies that aren't securing the device."



..but it's still organic, right?

http://www.latimes.com/features/health/la-he-closer28aug28,0,3552892.story?coll=la-home-health

Latest food additive: Viruses

The FDA-approved bacteria eaters work on deli meats and other ready-to-eat foods.

By Hilary E. MacGregor, Times Staff Writer August 28, 2006

If you want to get rid of a pest, why not use a littler pest to plague it? That's the tack OKd last week by the Food and Drug Administration, which has for the first time approved the use of bacteria-eating viruses as an additive to foods.

From now on, these viruses — known as bacteriophage or phage — can be sprayed on ready-to-eat cold cuts and luncheon meats by manufacturers to prevent listeriosis, the most deadly of all food-borne illnesses in this country.

... The viruses are grown in a broth of the listeria they are bred to kill — which was, Zajac said, a concern.

Monday, August 28, 2006

The “new AOL” is certainly making a reputation for itself!

http://www.infoworld.com/article/06/08/28/HNaolbadware_1.html?source=rss&url=http://www.infoworld.com/article/06/08/28/HNaolbadware_1.html

AOL 9.0 accused of 'badware behavior'

StopBadware.org advisers users to steer clear of the software

By Robert McMillan, IDG News Service August 28, 2006

AOL's free Internet client software has earned the company a slap on the wrist from StopBadware.org, a consortium set up to combat malicious software. In a report set to be released Monday, the group advises users to steer clear of the software because of its "badware behavior."

The report blasts the free version of AOL 9.0 because it "interferes with computer use," and because of the way it meddles with components such as the Internet Explorer browser and the Windows taskbar. The suite is also criticized for engaging in "deceptive installation" and faulted because some components fail to uninstall.

The main problem is that AOL simply doesn't properly inform users of what its software will do to their PCs, said John Palfrey, StopBadware.org's co-director. "We don't think that the disclosure is adequate and there are certain mistakes in the way the software is architected in terms of leaving some programs behind," he said. "When there are large programs, some of which stay around after you've thought you've uninstalled them, they need to be disclosed to the user."

Because AOL has taken steps to address StopBadware.org's concerns, the group has held off on officially rating AOL 9.0 as badware, Palfrey said.

... StopBadware.org bills itself as a "Neighborhood Watch" of the Internet. It is run out of two well-respected university departments: Harvard University's Berkman Center for Internet & Society in Cambridge, Massachusetts, and University of Oxford's Internet Institute in the U.K.

... AOL has also come under fire for licensing its free antivirus software, called Active Virus Shield, with what anti-adware advocates view as excessive advertising and data gathering provisions.

... StopBadware.org makes its reports available on this Web page.



Soon, every recorded conversation will be transcribed this way... Maybe.

http://www.researchbuzz.org/wp/2006/08/27/some-new-features-at-podzinger/

Some New Features at PodZinger

Filed under: Multimedia-Video, Multimedia-Audio

Last February I reviewed a site called PodZinger. PodZinger, if you don’t remember, does machine transcription of podcasts and then makes the material searchable, which is just lovely. (And as far as I know they have that arena pretty much to themselves, which boggles the mind.) PodZinger’s at http://www.podzinger.com/ .



And IT managers are not normally trained for this... Remember to keep those budget meeting transcripts where the CEO said the organization couldn't afford the spend money on security.

http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9002748&source=rss_topic84

IT execs on firing line over security breaches

The most recent incident involved AOL's CIO

Jaikumar Vijayan August 25, 2006 (Computerworld) --

The cost of data breaches may be getting a lot higher for IT professionals who are deemed to be responsible for failing to properly secure corporate information.

For example, AOL LLC's chief technology officer abruptly resigned this week in the aftermath of a disclosure that the company had publicly released data on searches done by about 650,000 of its online subscribers. AOL also fired two workers in its research division, which was responsible for the data release and had been overseen by now-former CTO Maureen Govern.

It was the second time this month that high-level technology managers lost their jobs because of data breaches. On Aug. 3, Ohio University announced that it had sacked two top IT managers for what it saw as their failure to prevent a series of breaches that were discovered at the Athens-based school during the spring

... IT managers should expect firings and other harsh disciplinary actions to become more common as organizations face increasing public pressure to address data breaches that they suffer, said Robert Scott, managing partner at Dallas-based law firm Scott & Scott LLP.

"In order for companies to have a credible position in the marketplace, they're going to have to explain in a public way what they have done to address the issue," Scott said. "The risks that companies face from a liability and a reputation perspective are such that when breaches occur, people will not only need to be held accountable, but heads will have to roll." [“It is better to look proactive than to be proactive.” Fernando Bob]

... Tim O'Pry, CTO at The Henssler Financial Group in Kennesaw, Ga., said accountability is necessary, and it's reasonable to expect that people will lose their jobs where negligence has occurred.

The problem is that many times, the workers responsible for a security breach are only following what until then had been accepted practices within their companies, O'Pry said. And they may not have had the responsibility or authority to change the practices, he noted.

... Forging closer ties with IT audit teams is a key to survival in the new environment, Hession advised. "If you think you have an issue, go to audit and tell them about it," he said. If the audit group concurs that a security problem exists, it should be easier to get the resources needed to fix it, Hession added. And if the auditors agree that there's an issue "and nobody does anything about it, you probably don't need to be falling on your sword" if a data breach does occur, he said.

Companywide outreach and communication also are key, according to Scott. Managers who are responsible for IT security "need to do a better job of articulating a business case [that] suggests that ignoring data security and shuffling it to the bottom of the priority list is a recipe for disaster," he said.

In addition to the incidents at AOL and Ohio University, the massive security breach disclosed by the U.S. Department of Veterans Affairs in May resulted in a wide-ranging shake-up that included the resignation of the agency's chief information security officer. But the CISO's departure is thought to have been driven by his frustration over organizational issues within the VA, which traditionally has split most IT and security responsibilities among its three main operating divisions.



http://techdirt.com/articles/20060828/004204.shtml

Can We Set Up An Online Learning Class About Our Screwed Up Patent System?

from the might-help dept

There's been a lot of buzz in the last few weeks over the patent awarded to the provider of online courseware, Blackboard. The patent seems ridiculously broad and basically seems to cover the entire concept of e-learning software. So, of course, what else would Blackboard do, but sue another company for patent infringement? Blackboard claims that people are overreacting, but as people go through and breakdown the specific claims in the patent, it just looks worse and worse. There is simply no reason that this patent ever should have been issued. There is nothing in the patent that is remotely new or non-obvious -- and it's difficult to make even the slightest case that the issuance of this patent has any societal benefit. Instead, you could make a pretty good case that it's done plenty of harm. In the meantime, plenty of people are saying that the blame should fall entirely on the patent system and not Blackboard, but they are defending their decision to sue another provider. Hopefully, the growing backlash (especially from academia) against Blackboard for resorting to a lawsuit means that more universities decide to go with other software providers.



Virtual Law

http://techdirt.com/articles/20060828/025121.shtml

Who Do You Blame When Your Virtual Bank Fails?

from the should-have-thought-about-that-earlier dept

It's not like there haven't been warnings about the blurring boundary between online games and the real world when it comes to the legal system. In all of these online worlds, especially when real money gets involved, people just aren't clear as to whether or not in game actions have real world legal implications. On the one hand, you have people who will say that if something of real value is "stolen" in the game, that's a crime. Something of value has been lost. However, this gets tricky when you realize that some online games have theft or other crimes as a part of the gameplay on purpose. If stealing goods from other players is a part of the game, how can it be illegal outside of the game? So, even if it's not a major part of the game -- or if it's a programming flaw that allows it -- how can it be fair to say it's "illegal"? So, now, take that same issue to a larger scale. What if someone sets up an in-game bank? Then, it turns out the bank is actually a scam, and the owner simply takes all the money people gave him and runs? That's apparently exactly what happened recently. It may be tempting to say the guy committed real fraud -- but, again, the game let him do this. There was no guarantee within the game that the bank was legit. There was no FDIC "backing" the bank. There was a very real risk in putting money into that bank, but people did so by choice, as part of the game. The real issue is that too many online worlds are really just punting on the issue of an in-game legal system or conflict resolution system. They're forgetting that they've basically built a world -- and that world needs some sort of legal system as well. [Sounds like a call for articles to me... Bob] If there's a problem, then let the in-game mechanisms sort out the results or punishment. Because, if there isn't an official law enforcement/judicial process, you'll get the next best thing: an online mafia who will run the online world for you. Either way, that's still better than cluttering up the real world courts over these types of disputes.



Sometime you have to let your inner intellectual take over...

http://beeradvocate.com/news/stories_read/673

Beer: The Midwife of Civilization

Horst Dornbusch on Beer and Civilization #10

[I want a T-shirt that says: “Bibo cerevisiam, ergo sum” Bob]

Sunday, August 27, 2006

A friend dropped one of these CDs on me yesterday. I plan to make copies for my students and thought you might find them useful yourselves. The will make great stocking-stuffers come Christmas!

http://www.ttcsweb.org/osswin-cd/index.htm

TTCS OSSWIN CD

Version 1.45 available July 28th, 2006. Changelog | Download.

What is the TTCS OSSWIN CD?

The TTCS OSSWIN CD is a collection of over 100 Free/Open Source software for home and business users using the Microsoft Windows 98SE/Me/2000 and XP operating systems.



Help me understand why anyone would rely on evidence obtained by this guy? No chance he planted it? Is illegally obtained information admissible?

http://yro.slashdot.org/article.pl?sid=06/08/26/1946232&from=rss

The Story of the Pedophile-catching Hacker

Posted by Zonk on Saturday August 26, @04:45PM from the small-world dept. Privacy The Courts The Internet

missing30 writes "A Turkish hacker seeding usenet groups with trojan horses has made it a habit to hunt down pedophiles trolling the groups. The cases go back to 2000, with the mysterious good samaritan responsible for several arrests. The man now has tacit approval from the FBI for his actions." [Since we can't catch him... Bob]

From the article: "At the urging of Montgomery Police Capt. Kevin Murphy, '1069' eventually turned over more and more information that led back to a computer owned by Bradley Joseph Steiger, who had worked as an emergency room physician in Alabama. The hacker's finds included information from Steiger's AT&T WorldNet account, records from his checking account, and a list of directories on his computer's hard drive where sexually explicit photographs were stored."



Isn't this sad? We should help them with this problem. I'll take a few million if you will.

http://www.technewsworld.com/rsstory/52638.html

Google Seeks SEC Exemption on Investing

By Miles Weiss Bloomberg News 08/26/06 4:00 AM PT

Google's $10 billion would make it a midsize mutual fund.



http://www.lessig.org/blog/archives/003499.shtml

“Steal This Film”

OpenBusiness.cc has a blog entry about a film about “piracy” and its politics in Sweden, including a bit about the Swedish Pirate Party. Appropriately enough, you can download it for free.



http://www.financialexpress.com/fe_full_story.php?content_id=138464

Kerala logs Microsoft out

M SARITA VARMA Posted online: Saturday, August 26, 2006 at 0025 hours IST

THIRUVANANTHAPRUAM, AUG 25: After the cola ban, it is now the turn of Microsoft to log out of Kerala. Children in 12,500 high schools in the state, India’s most literate, will not be taught Windows. Instead, instructors are lining up Linux for them. This is because Kerala has chalked out a plan for migrating its high school students to free software platforms in three years.

Although Linux was already blipping on the Kerala IT@School project radar, and the plans of VS Achuthanandan’s government to develop the state as a Foss (free and open software systems) destination has expedited the open software plans.

Free software guru Richard Stallman’s visit last week had nudged the schools to discard the proprietary software altogether,” state education minister MA Baby told FE. “Stallman has inspired Kerala’s transition to free software on the lines of an exciting model of a Spanish province, which did the same,” the minister said.

... There are other reasons as well. A sting operation by Microsoft in October 2005 had not endeared the proprietary software to PC and peripherals dealers. Often PC vendors are caught between customers’ demand for free pirated software along with hardware, and the fine print of law. Some dealers in Kerala even see the Foss market as a narrow, but a safe corridor out of this mess.



Learn mashups from IBM. Who'd a thunk it?

http://www-128.ibm.com/developerworks/edu/x-dw-x-ultimashup1.html?S_TACT=105AGX59&S_CMP=GR&ca=dgr-lnxw02aWebMashupsPart1

The ultimate mashup -- Web services and the semantic Web, Part 1: Use and combine Web services

Explore mashup concepts and build a simple mashup

developerWorks Level: Intermediate Nicholas Chase (ibmquestions@nicholaschase.com), Freelance writer, Backstop Media 22 Aug 2006

... The purpose of this tutorial series is to create a mashup application so smart that users can literally add and remove services at will, and the system will know what to do with them. The series progresses as follows:



http://digg.com/playable_web_games/Play_Simcity_for_free

Play Simcity for free

rcvictory submitted by rcvictory 13 hours 28 minutes ago (via http://simcity.ea.com/play/simcity_classic.php )

Play original simcity online at no cost



The Future?

http://www.washingtonpost.com/wp-dyn/content/article/2006/08/25/AR2006082501659.html

Brazilian Drug Users Won't Face Jail

The Associated Press Friday, August 25, 2006; 11:22 PM

RIO DE JANEIRO, Brazil -- Drug users who don't engage in dealing will no longer be sent to prison under a new drug law now in effect across Brazil, officials said Friday.

Saturday, August 26, 2006

Oh dear, yesterday must have been Friday... Apparently this bank has not learned from previous incidents.

http://www.miami.com/mld/miamiherald/15365554.htm

Posted on Fri, Aug. 25, 2006

Bank warns customers personal data may have been breached

Associated Press NEW BEDFORD, Mass.

Sovereign Bank is warning thousands of customers that their personal data may have been stolen along with three managers' laptops taken earlier this month in Massachusetts.

Bank officials said fewer than 1 percent of customers [Trivialize, trivialize, trivialize... Bob] in the New England and Mid-Atlantic area may have been affected, the Standard-Times of New Bedford reported.

"There's no information any of the accounts have been compromised," bank spokesman Carl Brown told the newspaper. He would not say how many letters were sent to customers Aug. 21, but said it was in the thousands.

"We do consider this as a serious matter; we want to do everything we can," Brown said. "Police are investigating, and we're conducting our own internal investigation."

Brown said the laptop computers used by branch managers and other managerial staff included unspecified personal information but not account information.

The letter sent to customers indicated bank officials "strongly believe" the personal files were deleted before the thefts. It says the bank has programmed a flag into its systems that will notify employees if the personal information of a particular customer may have been affected. [Horses**t! Bob]

Brown said the computers, taken from vehicles at two locations [Someone should mention to employees that leaving a laptop visible in your car increases the odd it will be broken into... Bob] in Massachusetts he declined to identify, have not been recovered and there are no leads in the case. He said extra precautions have been taken regarding laptops since the thefts.

A New Bedford customer who received a letter said he wasn't concerned.

"I'm just mad, really," David Brenneke said. "The personal information shouldn't be on laptop computers. It's kind of ridiculous." [When customers know more about how security should work than you do, you have problems! Bob]

Philadelphia-based Sovereign Bank serves primarily the Mid-Atlantic region and New England. It has approximately 800 branches.


Yep, yesterday was “Let's tell our customers we screwed up by whispering where they won't hear us” day... (You lawyers can think of it as the PR version of fine print.)

http://news.com.com/2100-1029_3-6109883.html?part=rss&tag=6109883&subj=news

Verizon gaffe lets customer details slip

By Joris Evers Story last modified Fri Aug 25 17:56:28 PDT 2006

Verizon Wireless this week accidentally distributed a file with limited details on more than 5,000 customers outside the company, potentially giving identity thieves a toehold.

The Microsoft Excel spreadsheet file was e-mailed on Monday and includes names, e-mail addresses, cell phone numbers and cell phone models of 5,210 Verizon Wireless customers, going by a copy of the file obtained by CNET News.com. [So did Verizon give them a copy or did they get it from an emailee Bob] All of the customers have Motorola Razr phones, according to the spreadsheet.

The spreadsheet was inadvertently sent to about 1,800 people, all Verizon Wireless subscribers, according to a follow-up e-mail apologizing for the gaffe that the mobile carrier sent on Thursday. The Excel file was attached to an ad for a Bluetooth wireless headset, instead of the electronic order form that was supposed to be sent.

... It said that it has already implemented additional quality control procedures and process improvements to prevent a re-occurrence. [If they have already been implemented they are trivial, if they are trivial why weren't they in place long ago? Bob]

A Verizon Wireless representative confirmed the incident, but could not immediately provide specific details when reached Friday afternoon.

The information in the document is limited and does not immediately expose those listed to fraud, the company said in its apology. Yet it recommends that people affected review their bills more carefully and add a password to their account [This ship is unsinkable, but you might want to get into your lifejacket and stand close to the lifeboats... Bob] by calling 1-866-861-5096.

While the privacy breach in no way makes identity theft automatic, [Wow, what a very “PR” phrase. Bob] it helps put a clever fraudster in the starting blocks, said James Van Dyke, the principal analyst at Javelin Strategy & Research in Pleasanton, Calif., which tracks identity fraud.

"To commit ID fraud, you must do several things well. This just makes the job slightly easier," he said. For example, with this list in hand, a fraudster could call the listed numbers, pretend to be a Verizon Wireless representative and ask the subscriber for information to update the account.

One Verizon Wireless customer whose details were included in the file said he was upset about the flap. "Someone just got incredibly careless sending out a sales e-mail," said Frank Donley of Fresno, Calif. "With all the privacy incidents you read about recently, I should feel relieved that my credit card number, Social Security number or some other secure info wasn't released." [When customers know more about how security should work than you do, you have problems! Bob]



Here is another attempt to convince us that they can definitely tell when data has been accessed. If they want to convince me, let them guarantee to reimburse everyone (me, the retailers, and the credit card companies) if my identity is stolen.

http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9002708&source=rss_topic84

It's back: Stolen Beaumont Hospitals laptop recovered

Linda Rosencrance August 24, 2006 (Computerworld)

Beaumont Hospitals today announced the recovery of a laptop missing since Aug. 5, when a home care nurse's car was stolen in Detroit.

The computer's hard drive was examined by an independent forensic computer expert, who determined that patient information on the computer was not accessed during the time it was missing, according to the hospital.

"We are so relieved to recover the laptop so that we can put our patients' minds at rest," Chris Hengstebeck, director of security at Beaumont Hospital in Troy Mich., said in the statement. "And we are relieved that no one's personal or medical information was accessed."

A resident of the area where the laptop was stolen called Hengstebeck after hearing news reports on Tuesday about the theft. The information led to the laptop's recovery, and Beaumont is giving the anonymous resident a $2,500 reward.

The computer, which contains personal and health information of 28,000 home care patients served during the three years leading up to Aug. 5, 2006, was in the nurse's bag in the back seat of her car when the auto was stolen.

The laptop does not contain information on inpatients or other outpatients of the Michigan hospitals, and the centralized registration and medical records of Beaumont were never at risk from this theft, according to Beaumont. The computer contains only information related to home care patients, including patients' names, addresses, birth dates, medical insurance information, Social Security numbers and personal health information related to their home care services, the hospital said.

Home care laptop computers are encrypted and password protected. In this instance, the nurse was a new employee in orientation, and her ID access code and password were taped to the computer when it was taken, [Please don't try to convince me passwords provide protection... Bob] according to the statement.

Hengstebeck said the home care nurse and her direct supervisors are no longer working at the facility because of the incident. [They should get lawyers. Were the disciplined because the car was stolen? Booo Bob] In addition, home care laptops have been inspected and computer security and password procedures are being reiterated with all Beaumont staff.



No privacy issues here! (These aren't the droids you want...)

http://www.eweek.com/article2/0,1759,2008340,00.asp?kc=EWRSS03119TX1K0000594

VeriChip Sells First Baby Protection System, in Talks with Military

By Renee Boucher Ferguson August 25, 2006

Updated: The maker of human-implantable RFID chips makes its first sale of its infant protection, wander prevention and staff duress system to a Canadian hospital and is discussing testing its implantable chips in two military branches.

VeriChip, the company that makes human-implantable RFID chips, is looking to span its equipment from newborns to the military's enlisted. [Willing to wait 18 years? Bob]

The company announced Aug. 24 that it has made the first sale of its infant protection, wander prevention and staff duress system to the Brampton Civic Hospital in Brampton, Ontario.



This could make life interesting... Suppose they just start issuing frequent (daily?) updates – to which you must subscribe, and then refuse to support anyone who had a problem but wasn't current on the updates.

http://slashdot.org/article.pl?sid=06/08/26/0741239&from=rss

Vista the Last of Its Kind

Posted by Zonk on Saturday August 26, @07:19AM from the vanishing-breed dept.

An anonymous reader wrote to mention a TechWorld story about Windows Vista. According to the Gartner Group, Windows Vista is likely to be the last of its kind. "The problem is that the operating system's increasing complexity is making it ever more difficult for enterprises to implement migrations, and impossible for Microsoft to release regular updates. This, in turn, stands in the way of Microsoft's efforts to push companies to subscription licensing. The answer, according to Gartner, is virtualization, which is built into newer chips from Intel and AMD, and has become mainstream for x86 servers through the efforts of VMware." Speaking of Vista, C|Net reports that a new release candidate is on the way. The average tester should expect it by the end of September.



Not exactly personal information, but the techniques are the same.

http://www.informationweek.com/news/showArticle.jhtml?articleID=192300409

Microsoft Unhappy With Release Of Lighthearted Training Video

The 37-minute video was only for internal use, but somehow got released on the Web.

By Antone Gonsalves TechWeb Aug 25, 2006 03:26 PM

Microsoft on Friday was unhappy with the online release of a training video that was made to look like an episode of the popular British comedy "The Office," and featured the show's star and creator Ricky Gervais.

Microsoft in the United Kingdom made the 2004 video as a fun way to instruct people on how not to act at work. The 37-minute video was only for internal use, but somehow got released on the Web.

... "These videos were produced for internal use and were never intended to be viewed by the public."

Microsoft was trying to determine how the video was released, the spokesperson said.



Remember, it's the spam that's illegal not the touting of stocks...

http://it.slashdot.org/article.pl?sid=06/08/25/1821256&from=rss

Buy Low, Spam High

Posted by Zonk on Friday August 25, @03:24PM from the anything-for-a-buck dept.

An anonymous reader writes "A recent study on spam has revealed that spammers see a return between 4.9% and 6% [Not bad if you can do it every month... Bob] when selling stocks they have bought low and spammed the world with." From the article: "The researchers say that approximately 730 million spam e-mails are sent every week, 15% of which tout stocks. Other estimates of spam volumes are far higher. The study, by Professor Laura Frieder of Purdue University in the US and Professor Jonathan Zittrain from Oxford University's Internet Institute in the UK, analysed more than 75,000 unsolicited e-mails. All of the messages touting stocks and shares were sent between January 2004 and July 2005."



Could she be this petty... uh... I withdraw the question.

http://blog.washingtonpost.com/securityfix/2006/08/paris_hilton_accused_of_phone.html

Paris Hilton Accused of Phone Phreakiness

... So says SpoofCard.com, a company that offers "spoofing" services that let people fake the number that appears in the recipient's caller ID display. The company's lawyer, Mark Del Bianco, says Hilton was among some 50 customers whose accounts were suspended for allegedly using Spoofcard's service to break into other peoples' voice mail accounts and listen to their private messages or alter their outgoing messages. Spoofcard said it discovered the violation "while reviewing its customer call records for evidence of fraud and other prohibited conduct."



http://www.technewsworld.com/rsstory/52633.html

The Battery Recalls: Frequently Asked Questions

By Michelle Kessler USA Today 08/25/06 8:42 AM PT

... Apple and Dell both announced large laptop battery recalls this month. Here are answers to some common customer questions:



Think of this an an electronic version of the sideshow barker (e-barker?)

http://www.technewsworld.com/rsstory/52649.html

CBS to Use Bluetooth to Beam TV Clips to Passersby

By Keith Regan www.EcommerceTimes.com Part of the ECT News Network 08/25/06 2:12 PM PT



Very impressive tour of a modern data center. You should see this video!

http://news.com.com/1606-2_3-6109900.html?part=rss&tag=6109900&subj=news

Video: See where the Internet lives

Take a tour of the data warehouse for the Web

Equinix is responsible for holding massive amounts of data, including storage for popular sites like MySpace.com. Take a tour of the facilities, and see how much energy it takes to keep the Web alive. CNET News.com's Neha Tiwari reports.



So how would a non-governmental entity (a private eye) be able to trace through a secure system where the FBI can't?

http://techdirt.com/articles/20060825/131234.shtml

Note To Fugitives: Stay Off Of Skype

from the man-on-the-run dept

We reported last week about Kobi Alexander, the ex-CEO of Comverse, who's gone on the lam to avoid charges relating to a stock-options scam. Now, he's apparently been tracked down in Sri Lanka -- by a private eye hired by a venture capital company, who was able to trace him to a fishing village by tracking a call he made to relatives over Skype. It's not clear it's done much good, as the FBI just says it's checking out the report, while rumors say Alexander's already ditched Sri Lanka, perhaps for some place where it's a little harder to get extradited. In any case, one of Skype's selling points is its "security" -- but as is pointed out on Bruce Schneier's site, there's a big difference between the encrypting of calls Skype does, and a system that offers anonymity, as Alexander has presumably discovered.



Gee willikers, you don't suppose they've done this before?

http://techdirt.com/articles/20060825/120054.shtml

FCC Acts Concerned About Telco Doublespeak

from the please-provide-more-doublespeak dept

We've discussed this week how both Verizon and BellSouth were adding on new "regulatory fees" or "supplier surcharges" that almost exactly matched the Universal Service Fund fees they were no longer required to collect for DSL service. In both cases, the companies tossed out a bunch of meaningless doublespeak about why those fees were legitimate, and weren't just a way to take the money that had previously gone to the useless USF and pocketing it themselves. It was especially egregious since the telcos had lobbied the FCC to get rid of those fees, claiming it would benefit consumers. With so much attention, it appears that the initial doublespeak is a little confusing to the FCC as well, and they've now asked for a bit more info from both telcos, suggesting that these new fees may violate "truth in advertising" laws. Of course, seeing as the telcos seem to have an extra special relationship with the FCC leadership these days, it's unlikely that this new investigation will result in anything.



This all hinges on the definition of “large sum” which I believe is best defined as “How much you got on you?”

http://hammeroftruth.com/2006/08/24/united-states-of-america-v-124700-in-us-currency/

U.S. v. $124,700 in U.S. Currency

No really, that’s the name of the case.

The Eighth Circuit Appeals Court recently ruled that police may seize cash from motorists, citing that “possession of a large sum of cash is ’strong evidence’ of a connection to drug activity.” [So can I sue my bank? Bob] The case, in which Emiliano Gomez Gonzolez — a man with a “lack of significant criminal history” — was caught with the “crime” of having too much cash on him, so they confiscated it, and apparently pressed charges against the money itself and took it to court.

Says Radley Balko:

Gonzolez was never even charged with a drug crime, much less convicted. Which means the prosecutors didn’t even have enough evidence to bring the case to trial. Yet the state still took the man’s $125,000, money he had a pretty respectable explanation for, complete with witnesses. That’s not even mentioning the fact that in a free society, a man never charged with a crime shouldn’t have to vouch for the legitimacy of the money he’s carrying, no matter how he happens to be carrying it.

Dead presidents have no rights.



They start training these terrorists early.

http://psp3d.xhardwarereviews.com/index2.php?page=Hacking%20Wireless%20Networks%20With%20The%20PSP

Hacking Wireless Networks With The PSP

Is the PSP spurring a new generation of safety concerns?

August 24th, 2006 By Robert A.

Friday, August 25, 2006

That Dell thing is now a Dell/Sony/Apple thing...

http://techdirt.com/articles/20060824/1140224.shtml

Apple Gets Burned By Sony Batteries, Too

from the feeling-hot-hot-hot dept

Apparently Apple noticed all the fun Dell was having with this whole battery recall thing, so it's decided to get in on the act by recalling 1.8 million batteries for three of its laptops -- batteries that, like the Dell ones, have cells made by Sony. Apple's suggesting affected users should remove the batteries from their machines and use them on AC power, while they wait 4 to 6 weeks for a replacement. In the meantime, perhaps Apple users can enjoy a vacation -- just don't fly Qantas.



http://www.infoworld.com/article/06/08/24/HNsonybatteryprob_1.html?source=rss&url=http://www.infoworld.com/article/06/08/24/HNsonybatteryprob_1.html

Sony puts price on battery problems

Multimillion dollar replacement costs may have effect on company's financials

By Martyn Williams, IDG News Service August 24, 2006

Sony Corp. has provided for the first time an estimate of what the recalls of its battery packs by PC makers could end up costing the Japanese company.

On Wednesday Apple Computer Inc. said it will join Dell Inc. in recalling the Sony-made battery packs in some of its products because of a risk that they will overheat and catch fire while being charged. Apple is recalling about 1.8 million batteries, while Dell is asking customers to return 4.1 million batteries.

Sony expects the Apple and Dell recalls to cost between ¥20 billion and ¥30 billion (US$172 million to $258 million). It said the figure represents the cost of replacement battery packs and any other related costs.

That could put a dent in Sony's full-year financial results. The company currently forecasts both its operating profit and its net profit to be ¥130 billion for the fiscal year ending March 31, 2007.

Sony said it anticipates "no further recalls of battery packs using these particular battery cells." [Clever use of a tautology. We've recalled them all therefore we don't think there are any more to recall. Bob]



Correcting the problems caused by top management?

http://blog.wired.com/cultofmac/#1545004

Thursday, 24 August 2006

Apple Looking to Hire a Business Ethicist

In the wake of sweatshop charges at iPod factories in China, Apple is advertising for a manager of a "Corporate Social Responsibility program."

Sometimes known as "business ethics," CSR often involves policing human rights at overseas suppliers or assembly plants.

In a job posting at Ethical Performance.com, Apple says the candidate will have a "strong desire to improve human rights and worker conditions."

The post calls for "experience in auditing practices and supplier management."



So much data, so little time...

http://www.researchbuzz.org/wp/2006/08/23/university-of-california-launches-calisphere-digital-library/

University of California Launches Calisphere Digital Library

Filed under: US-California

The University of California has announced Calisphere, a digital library containing more than 150,000 digitized primary source materials about California. Calisphere is available at http://www.calisphere.universityofcalifornia.edu.

... If you want to see all the topics and the entire index at once, there’s a huge page that’s great for browsing at http://www.calisphere.universityofcalifornia.edu/browse-a-z.html. Teachers shouldn’t miss the guide page at http://www.calisphere.universityofcalifornia.edu/for-teachers.html.

Lots of great material here, though I wish the details for the pictures weren’t buried under a couple of extra clicks. A real timesink.



...because we just love spending taxpayer money! (Why use the free software when we can pay Microsoft and then add in extra software we have to maintain?)

http://politics.slashdot.org/article.pl?sid=06/08/24/1831230&from=rss

Massachusetts to use ODF Through Microsoft Office

Posted by Zonk on Thursday August 24, @03:49PM from the they-have-a-cave-troll dept. Microsoft Software Politics

An anonymous reader writes "In a move sure to be unpopular with Sun and IBM, Mass. has decided to use the ODF plug-ins recently released for Microsoft Office rather than move to OpenOffice. Officials pointed to accessibility requirements as being one of the primary reasons for not moving away from Microsoft Office. Is this a victory or a defeat for the Open Document Format effort?"



This seems extremely dangerous to me. If I “disclose” that I have a solution for the problem I've been hired to work on, can they still get the patent? “Back in 1990 I had this idea for an online patent prior art search systems, I use it every day, but havent bothered to patent it yet...”

http://ask.slashdot.org/article.pl?sid=06/08/25/0212247&from=rss

Are NDA 'Prior Inventions' Clauses Safe to Sign?

Posted by Cliff on Friday August 25, @12:20AM from the contractual-time-bombs dept. Businesses Privacy

BenderMan asks: "I own a small consulting company. Today I was asked by yet another corporate customer to sign an NDA with the increasingly popular 'Prior Inventions' clause. The gist of it is they want you to provide a list of all your past and current inventions and/or ideas so they can define and protect the intellectual property that they have hired you to build. Like many of us that lay awake at night, whilst the hamster wheel spins new ideas, I've got a number of un-patented works in various stages of development. Given that mutual NDAs only provide one year of protection, I don't feel obligated, nor do I have sufficient time and energy, to fully and properly document my inventions for an NDA. While these clauses are written with good intentions, the reality is that these valuable ideas would be placed in the hands of people that could potentially profit with impunity (Have you priced patents lately?). Unfortunately many companies are not willing to strike this clause from their contracts. Does Slashdot agree that this is a concern, and how have you dealt with these situations?"



Apparently, it takes a long time to “appall” these guys... Did they think the Vietnamese were barbarians, too ignorant to understand the technology? Fortunately, this would never happen with US firms... Right? (See next article)

http://freeinternetpress.com/story.php?sid=8142

U.S., U.K. Firms Sold Wiretapping Equipment To Vietnam

2006-08-24 16:42:00 Posted By: Intellpuke

Reporters Without Borders has learned that a British company, Silver Bullet, and a U.S. company, Verint Systems (a subsidiary of Comverse Technology), sold equipment for intercepting mobile phone calls to the Vietnamese intelligence services. The source of this information, the U.K.-based Jane's Defence Weekly, said a subsidiary of Israel Aircraft Industries acted as intermediary in some of the sales.

"We are appalled to learn that our phone calls with Vietnamese cyber-dissidents have been monitored with equipment provided by European and U.S. companies," said the Paris-based press freedom organization. "Coming a year after it emerged that Yahoo! cooperates with the Chinese police, this new case reinforces our conviction that telecommunications companies must be forced to respect certain rules of ethical conduct. In particular, they should be banned from selling surveillance equipment to repressive governments."

The sales were revealed by Robert Karniol in an article headlined "Vietnamese army enhances mobile phone monitoring" in the October 31, 2005, issue of Jane's Defence Weekly (JDW). He said the London-based Silver Bullet had recently sold two P-GSM stations (portable mobile phone listening devices) to Vietnam for $250,000 each. Elta (a subsidiary of Israel Aircraft Industries) and Aikap Group, another Israeli company, acted as intermediaries in this transaction.


Them barbarians learns quick.

http://www.infoworld.com/article/06/08/25/HNvietnamintel_1.html?source=rss&url=http://www.infoworld.com/article/06/08/25/HNvietnamintel_1.html

Vietnam's Communist Party gets help from Intel

Intel will set up a lab in Vietnam for testing and developing open-source software

By Sumner Lemon, IDG News Service August 25, 2006

The Vietnamese Communist Party's decision to move its computer systems to open-source software got a boost on Friday from Intel, the world's largest chip maker.

Under terms of a memorandum of understanding signed on Friday, Intel will help the Communist Party's Central Committee for Science and Education (CCSE) set up a laboratory, called OpenLab, for testing and developing open-source software. Over the next three years, the lab will oversee the installation of open-source software on 27,000 PCs running Intel processors, the chip maker said.

The Communist Party's decision to use open-source software matches a wider Vietnamese government effort. In 2004, the government announced plans to promote the use of open-source software in a bid to reduce its IT costs and promote the development of the local software industry.

The Communist Party is counting on open-source software to improve office automation and efficiency across different party organizations. It also hopes to benefit from improved security and reliability, the chip maker said. An Intel spokeswoman in Vietnam was not immediately available to comment further on the deal.

Intel is investing heavily in Vietnam, which has emerged as a low-cost alternative to manufacturing in China. In February, Intel announced plans to build a $300 million test and assembly plant in Ho Chi Minh City. When completed, the Ho Chi Minh City site will be Intel's seventh test and assembly plant, joining the ranks of similar facilities in China, the Philippines, Malaysia, and Costa Rica.

The Ho Chi Minh City plant is expected to eventually employ 1,200 workers.



Tools & Techniques

http://www.searchengineguide.com/searchbrief/senews/008281.html

Protecting the Privacy of Search

Posted by Jennifer August 24, 2006

On the heels of AOLs blundering decision to share search histories of its users with the world, search engine privacy has become a fairly hot topic. After all, search queries often reveal the deepest secrets and fears of the searcher...things that many searchers would prefer not be shared with the general public. With that in mind, Search Engine Journal's Loren Baker has put together "Six Ways to Keep Your Search History Private."



Cause for action! I like it, therefore I'll sue!

http://today.reuters.com/news/articlenews.aspx?type=internetNews&storyID=2006-08-24T190801Z_01_N24448872_RTRUKOC_0_US-ADDICTS-LAWSUITS.xml

Unable to unplug, tech addicts may sue: academic

Thu Aug 24, 2006 3:08 PM ET By Wojtek Dabrowski

TORONTO (Reuters) - Keeping employees on electronic leashes such as laptops, BlackBerries and other devices that keep them constantly connected to the office could soon lead to lawsuits by those who grow addicted to the technology, a U.S. academic warns.



http://www.bespacific.com/mt/archives/012241.html

August 24, 2006

DOJ Criminal Law Enforcement Data on Criminal Prosecutions

Posting from David Burnham and Susan B. Long, co-directors
Transactional Records Access Clearinghouse: "Very timely criminal enforcement data from the Justice Department document that federal criminal prosecutions in May were up from the previous month in all of the following categories: white collar crime (up 8.5%), immigration (up 15.3%), illegal drugs (up 8.9%) and weapons (up 9.7%). However, only immigration is up from a year ago (up 4.8% from May 2005); the other enforcement areas all show declines in prosecutions from the previous year...the reports on the latest trends," are available online here.



Could be real useful...

http://digg.com/software/Open_Source_Designing_a_book_with_LyX

Open Source: Designing a book with LyX

3monkeys submitted by 3monkeys 17 hours 40 minutes ago (via http://software.newsforge.com/article.pl?sid=06/08/15/1859251&from=rss )

If you've ever considered writing a book, you may have looked at the layout capabilities of OpenOffice.org Writer, AbiWord, KWrite, or other word processing programs. While these tools can produce adequate results for many types of documents, it's also worth considering LyX, an open source (GPL) desktop publishing application.