Wednesday, April 18, 2007

So long, and thanks for all the phish!

http://techdirt.com/articles/20070417/092918.shtml

Undisclosed Data Breach Helped Enable Phishing Scam At University

from the how-the-data-gets-used dept

Officials at Indiana University have concluded that a 2006 phishing attack against university members was made possible by an earlier breach of one of the university's main servers. This all came to light when one recipient of a phishing email -- a cybersecurity Ph.D. student -- wondered how an attacker could get his university email address, since he had never given it out to anyone. After requesting documents under the Indiana Public Records Act, the student discovered that the university had previously suffered an undisclosed breach, which is how the attacker obtained his information. This simple story underlines some important points. It shows that breaches aren't harmless; even if the stolen data isn't immediately used for direct fraud, it's likely to be used in other ways down the road. If stolen data can help a phisher do a better job of personalizing an email to make it look more legitimate, then that stolen data has value. The case also demonstrates the importance of disclosure. People whose data is lost need to be aware of it so that they can be on guard for fraud. When we hear about massive losses of data, such as the incidents at the Veterans Administration or TJ Maxx, it's easy to get lost in the staggering numbers and think of it all as an abstraction. But this incident shows, along with others before it, that breaches do have real consequences for the victims.



What liability? The taxpayer is responsible...

http://digg.com/business_finance/MASSIVE_Failure_of_TurboTax_Servers

MASSIVE Failure of TurboTax Servers

Beginning last night and stretching into this evening it is nigh impossible to e-file your taxes using TurboTax 2006. Here are some posting by some irate consumers -- including myself.

http://forums.turbotax.com/intuit/board?board.id=ef06



Do we automatically assume that any computer use involves the Internet? OR, we just think all strangers are up to no good...

http://news.bbc.co.uk/1/hi/england/hereford/worcs/6565079.stm

Two cautioned over wi-fi 'theft'

Two people have been cautioned for using people's wi-fi broadband internet connections without permission.

Neighbours in Redditch, Worcestershire, contacted police on Saturday after seeing a man inside a car using a laptop while parked outside a house. [I would have been more concerned if they had parked inside the house... Bob]

He was arrested and cautioned. A woman was arrested in similar circumstances in the town earlier this month.

... In the earlier incident, a woman was arrested after attracting the attention of neighbours in the early morning.

She had put up cardboard around her car windows but the light from her computer could be seen through the back window.



Perhaps they can learn!

http://slashdot.org/article.pl?sid=07/04/17/2337255&from=rss

Sony Fixes Problems With New DVDs

Posted by kdawson on Wednesday April 18, @04:43AM from the DRM-again dept. Sony Media Movies Entertainment

An anonymous reader writes "Following up on reports that DVDs for some Sony titles were causing problems, Video Business is reporting that Sony has fixed the copy-protection problem on recent DVD releases, and will provide replacement discs to customers. The problem was with the ARccOS DRM system. The company issued the following statement: 'Recently, an update that was installed on approximately 20 titles was found to cause an incompatibility issue with a very small number of DVD players (Sony has received complaints on less than one thousandth of one percent of affected discs shipped)... Since then, the ARccOS system has once again been updated, and there are no longer any playability problems.' Customers can call 800-860-2878 to inquire about replacement discs."



Look for bots that randomly claim content...

http://money.cnn.com/2007/04/17/technology/bc.google.viacom.reut/index.htm?section=money_technology

Google's copyright-protection tool unveiled

World's largest Web search services provider finds a way to protect itself from recent piracy claims from Viacom as well as future allegations.

April 17 2007: 4:53 PM EDT

SAN FRANCISCO (Reuters) -- Google is ready to introduce a copyright protection tool that helps media owners to automatically report acts of piracy on its YouTube video site, Chief Executive Eric Schmidt said Tuesday.

Schmidt said the new tool, known as "Claim Your Content," could resolve accusations that the world's largest provider of Web search services is tolerating piracy by consumers to share video on its YouTube site.

That complaint is featured in a high profile lawsuit filed last month by media conglomerate Viacom that seeks more than $1 billion in damages from Google for alleged violations of the Digital Millennium Copyright Act (DMCA).

"As that product rolls out, the issue becomes moot," Schmidt said in response to questions from an interviewer's question about how the tool might affect the suit. "We are automating that process to claim that content."



Your employees may elect to use this without consulting you – after all, the features they want to use don't include security.

http://www.infoworld.com/article/07/04/17/HNgooglecalendardata_1.html?source=rss&url=http://www.infoworld.com/article/07/04/17/HNgooglecalendardata_1.html

Corporate data slips out via Google calendar

The search function of the Web-based app can be used to find sensitive business data that has not been properly made private [Opt-in security Bob]

By Robert McMillan, IDG News Service April 17, 2007

It's not clear what gets discussed during McKinsey & Co.'s weekly internal communication meeting, but the dial-in number and passcode for the event can be easily found by searching with Google.

... Google Calendar gives users the choice of keeping calendar entries private or publishing them for the world to see, but some Google Calendar users appear to be sharing their calendar information without realizing it.

... Further searching revealed that quite a few corporate calendars can be found on Google Calendar, yielding such tidbits as the date and time of vendor meetings and names of projects in the works. Dial-in information could also be seen Tuesday on other calendars for calls on topics like "Deloitte's V2 Status Meeting- Updated" and "Compliance Overview."

... "This is pretty much exactly the kind of recon necessary to start doing industrial espionage," wrote Robert Hansen, the CEO of Sectheory.com, when he first blogged about this issue on Tuesday. "Weekly meetings that discuss key internal information? Not looking good. Sometimes you see major leaks in the least likely places."

This kind of data leakage is a growing problem for corporations, whose employees are adopting a new generation of Web-based productivity tools without necessarily understanding the security implications, said Marv Goldschmitt, vice president of business development with data auditing appliance vendor Tizor Systems.



Hey, they're my employees. I should be able to use any tool to protect them!

http://www.technewsworld.com/rsstory/56945.html

The Mushrooming Menace of Keyloggers

By Andrew K. Burger TechNewsWorld 04/18/07 4:00 AM PT

"Most modern keyloggers are considered to be legitimate software or hardware and are sold on the open market. However, there is an ethical boundary between justified monitoring and monitoring for the purpose of stealing confidential user information -- a boundary marked by a very fine line," said Nikolay Grebennikov, deputy director of Kaspersky Lab's R&D department.



Interesting...

http://www.bespacific.com/mt/archives/014580.html

April 16, 2007

Law Review Article on First Amendment as Criminal Procedure

Solove, Daniel J., The First Amendment as Criminal Procedure. New York University Law Review, Vol. 82, p. 112, 2007.

  • "This Article explores the relationship between the First Amendment and criminal procedure. These two domains of constitutional law have long existed as separate worlds, rarely interacting with each other despite the fact that many instances of government information gathering can implicate First Amendment freedoms of speech, association, and religion. The Fourth and Fifth Amendments used to provide considerable protection for First Amendment interests, as in the famous 1886 case Boyd v. United States, in which the Supreme Court held that the government was prohibited from seizing a person's private papers. Over time, however, Fourth and Fifth Amendment protection has shifted, and countless searches and seizures involving people's private papers, the books they read, the websites they surf, and the pen names they use when writing anonymously now fall completely outside the protection of constitutional criminal procedure. Professor Solove argues that the First Amendment should protect against government information gathering that implicates First Amendment interests. He contends that there are doctrinal, historical, and normative justifications for developing what he calls "First Amendment criminal procedure." Solove sets forth an approach for determining when certain instances of government information gathering fall within the regulatory domain of the First Amendment and what level of protection the First Amendment should provide."



One or two look useful.

http://www.bespacific.com/mt/archives/014584.html

April 17, 2007

Gadgets Presentation from 2007 Computers in Libraries Conference

On April 16, 2007 Barbara Fullerton, Manager, Librarian Relations, 10-K Wizard, Sabrina Pacifici, Editor & Publisher, LLRX.com and beSpacific.com and Aaron Schmidt, Director, North Plains Public Library, presented their always popular round-robin Gadgets presentation at Computers in Libraries 2007.



Not sure I get it. Must be a legal thing.

http://www.law.com/jsp/article.jsp?id=1176455064218

'Dear Abby' Law Firm Blogs a No-No, Insurance Carrier Says

Lisa Brennan New Jersey Law Journal April 17, 2007

One of the largest carriers of lawyers' professional liability insurance has set out guidelines for law firms that want to get into the business of blogging, without hurting their insurability.

In brief, it's fine to post bulletins on Web logs but not to answer questions that could be construed as seeking advice, the Chubb Group of Insurance Companies said in an April 4 statement.

... The company said that informational blogs -- which are essentially news -- "pose a minimal level of risk from Chubb's underwriting perspective," but that advisory blogs -- such as those in question-and-answer format -- potentially establish attorney-client relationships that can lead to malpractice suits.

Tuesday, April 17, 2007

Close to home...

http://www.ncua.gov/news/press_releases/2007/MR07-0411.htm

New Horizons Community CU Takes Action

After Potential Data Breach; Members Informed of Protections

April 11, 2007, Alexandria VA—New Horizons Community Credit Union (NHCCU), a state chartered federally insured credit union located in Denver, Colo., and operating under conservatorship of the National Credit Union Administration, is notifying members of a potential breach of confidential member loan information. The potential breach results from the theft of a laptop computer from Protiviti, a consultant employed by Bellco Credit Union conducting due diligence to prepare a possible acquisition bid.

... On April 3, the NCUA Region V Office and the Colorado Division of Financial Services were alerted of a potential data security breach involving the loan account information of approximately 9,000 of NHCCU’s 19,500 members. The stolen computer contains information pertaining only to members who had loans with the credit union.



Employee monitoring?

http://www.alamogordonews.com/news/ci_5682295

DA investigates possible data security breach

Alamogordo Daily News Daily News Report Article Launched: 04/17/2007 12:00:00 AM MDT

District Attorney Scot Key says his office is undertaking a "complex" ongoing investigation into data found on an employee's laptop at Gerald Champion Regional Medical Center, saying that criminal charges are not being filed at this time.

He declined to comment on the scope of the investigation or any potential targets.

"We are not anticipating any criminal charges at this time," he said.

According to a press release issued by the hospital, the laptop contained "confidential employee information, including Social Security numbers and bank account numbers."

The employee was not authorized to have possession of such information and has been suspended from work.

The data was found during a routine virus scan of computers at the hospital, [Sounds like more than a “virus scan” Bob] according to the news release. The scan picked up an anomaly, and the hospital called in technical support to investigate further.

Sue Johnson-Phillipe, chief executive officer at GCRMC, said "a good portion" of the employees on the list, which dates to 2001, no longer work at the hospital. She said all affected individuals have been notified.



As laptop thefts become more common, the news items get smaller...

http://www.latimes.com/technology/la-me-briefs17.3apr17,1,5461366.story?coll=la-headlines-technology&ctrack=4&cset=true

Stolen laptop contained Social Security numbers

From Times Staff Reports April 17, 2007

A county laptop computer that contained individuals' Social Security numbers was stolen last month, according to a county report.

The password-protected computer assigned to a county auditor-controller employee held the names and Social Security numbers of 28 people enrolled in the Department of Social Services' Refugee Employment Program.

The auditor-controller's office is sending letters to the affected individuals advising them to protect themselves against identity theft.

The department is also obtaining encryption software and warning employees not to store sensitive data on laptops.



Shouldn't OSU have learned from OU?

http://www.cantonrep.com/index.php?ID=348872&Category=13&subCategoryID=

Personal information stolen from Ohio State University computer

Tuesday, April 17, 2007

COLUMBUS, Ohio (AP) — Someone hacked into an Ohio State University computer and stole the personal information of more than 14,000 current and former faculty and staff members, the school said.

The hacker breached a computer firewall the weekend of March 31 and accessed records from an Office of Research database, university spokesman Jim Lynch said Monday.

The records of 7,160 former and 6,934 current faculty and staff members contained names, Social Security numbers, employee ID numbers and birth dates, the university said.

The breach was discovered by the Office of Research on April 2 during a routine review of daily activity logs, and steps were taken to block access to the data, the university said.

This was a malicious attack,” Lynch said.

Ohio State also reported Monday that two laptops stolen from the home of a professor in February contained the Social Security numbers and grades of about 3,500 chemistry students over the past decade.

... Allan Silverman, chairman of the Faculty Council that represents Ohio State faculty members, said he would ask the university why the Office of Research, which works to obtain research grants, possessed the database of about 190,000 current and former university employees.



Look at the evidence, then THINK!

http://techdirt.com/articles/20070416/103859.shtml

Early Time Change Costs Kid 12 Days In Jail

from the daylight-stupid-time dept

The early start on daylight savings time passed last month with little impact, both in terms of the predicted aclockalypse as well as the energy savings it was supposed to generate. However, the shift did have some severe consequences for one Pennsylvania 15-year-old: 12 days in the slammer. The kid made a call in to his school's recorded information line in the early hours of March 11, just a few minutes before the hot line supposedly received a bomb threat. School officials, in their haste to find the caller, matched his cell phone number to a list of callers to the hotline that morning, and immediately pointed the finger at him. His phone correctly recorded the call time as 3:12 am, which was apparently close enough for them to the 3:17 am entry in the system's call logs for the bomb threat. However, the officials hadn't set the clock in their call system properly, meaning the bomb threat came in more than an hour after the kid's innocent call, and it took nearly two weeks of the kid sitting in juvenile detention for somebody to figure it out. The real culprit here is somebody's stupidity -- because even if the time change hadn't occurred, the call times still didn't match up by five minutes.



Free is good!

http://www.nytimes.com/2007/04/16/technology/16ecom.html?ex=1334376000&en=6bf4d69c54bea5c9&ei=5088&partner=rssnyt&emc=rss

Giving Away Information, but Increasing Revenue

By BOB TEDESCHI April 16, 2007 E-Commerce Report

THOSE who don’t have $6,000 or enough prominent connections to get into a TED conference can take heart. The price of admission just went to zero, provided you can settle for a more remote experience.

The TED organization (TED stands for Technology, Entertainment and Design) runs an invitation-only conference in Monterey, Calif., every year for movers and shakers in business and nonprofit circles.

Yesterday, TED introduced a Web site that offers about 100 of its TED Talks, the polished 20-minute presentations for which the conference is renowned.

The new site will generate more advertising revenue for TED, but more important, conference leaders said, it will expose TED’s content to millions of people who would otherwise never attend the event.

In so doing, TED is at the vanguard of a trend in the conference industry, where organizers have begun to exploit assets that in years past evaporated as soon as speakers left the stage.

... Ms. Cohen said TED’s organizers began posting last June a handful of free videos from past conferences on TED.com, with “fairly aggressive goals for how I thought they’d do. But we blew past those pretty quickly.” By January, the number of TED Talks on the site had grown to 44, and they had been viewed more than three million times.

... From a business standpoint, Ms. Cohen said that giving away the conference’s content in such a highly polished manner has “completely transformed” the organization.

Conventional business logic would tell you that in a community like TED you have to keep your commodity scarce and expensive to retain brand value,” she said. “But the same year we started releasing most of our content for free we raised our conference price by nearly 50 percent and still sold out in 12 days.”

http://www.ted.com/



Would Dilbert get it wrong?

http://techdirt.com/articles/20070412/183135.shtml

Scott Adams' Pointy Haired Views On Copyright

from the whose-cognitive-dissonance-was-that? dept

I've been quite busy lately and haven't had a chance to get much work done on the latest post about economics in the absence of scarcity, but it seems like Dilbert creator Scott Adams has picked up on a piece of the topic. dcm writes in to let us know: "Sounds like Adams has been reading your blog. He mentions a few reoccurring themes from your many entries, but comes to the opposite conclusions. Being a copyright owner, he sees it from a different perspective. I don't think I suffer from cognitive dissonance as he says, but that maybe that is the cognitive dissonance speaking. What do you think?"

It's an interesting read, and his description of the position statement of those who don't believe copyright infringement is the equivalent of stealing is almost word for word along the lines of what we generally say. However, where Adams gets confused is when he gets down into analogy land. He uses an argument about borrowing someone's underwear, cleaning it and putting it back -- but that's a bad example and not at all analogous. Also, the use of underwear and the idea of wearing someone else's is designed to make people react emotionally, not logically. The problem is that the analogy isn't at all valid, since the underwear is a scarce good -- and even if someone else takes it and cleans it, wearing it has a real "cost" to the original owner. The underwear is worn down slightly, the owner cannot wear it at the same time if he wanted to and there is, of course, that emotional cost of knowing someone else is wearing your underwear. However, a much more analogous situation is that someone learns that you wear one kind of underwear and makes a similar pair for themselves. In fact, to make it even more analogous, say that someone has created a special replicating machine that allows you to replicate the style of anyone's underwear that you like. That's what's happening. Suddenly, it doesn't seem nearly as bad.

The bigger problem with Adams' essay, however, is that he seems confused about how markets work. He complains that the "loss" created by infringement is the creator's right to control how a work is marketed. Unfortunately, there is no such right. If I build a chair and someone buys it, then they can then market it however they want. The creator doesn't retain control. Or, if you want to get even more specific, if I build a chair and someone else likes it and builds their own similar chair, again they can market it however they want. In fact, as we were just discussing, this is pretty much how the fashion industry works -- and it's working out quite well there, creating all sorts of incentives for continual growth, creativity and innovation. Once a product is out in the market, the original creator no longer gets to keep control over it.

Finally, it's quite weak of Adams to then pick some very poorly thought out defenses of copyright infringement and use that as evidence that everyone who disagrees with copyright policy has cognitive dissonance on the issue. It's a blanket way of brushing off all criticism without addressing the actual points. All in all, Scott Adams is an intelligent and thoughtful guy -- so it's too bad that his argument on this particular topic wasn't more compelling.



Logic? We don't need no stinking logic!

http://www.bespacific.com/mt/archives/014568.html

April 16, 2007

Fact Sheet: Proposed FISA Modernization Legislation

Office of the Director of National Intelligence, April 13, 2007, Fact Sheet: Proposed FISA (Foreign Intelligence Surveillance Act)Modernization Legislation

"Key Provisions of this Bill Are:

  • Updating the definition of electronic surveillance to account for the sweeping changes in telecommunications technology that have taken place. The proposed legislation is technology neutral. In contrast to the 1978 statute, which contains central provisions that are tied to specific communications technologies, this proposal is not tied to specific technology we have today. That way, as telecommunications technology develops over time - - which it surely will do - - FISA will not run the risk of becoming out of date.

  • Protecting civil liberties and privacy interests and improving our intelligence capabilities by focusing FISA on people located in the United States. [Huh? Bob]

  • Improving the way the United States does business with communications providers. The country’s communications providers are important partners in the ability of the United States Government to protect our national security. The proposed legislation includes needed authority both to protect those carriers when they do comply with lawful requests under FISA, and to enable providers to cooperate with authorized intelligence activities.

  • Streamlining the FISA process. Numerous Congressional and Executive Branch reviews of the FISA process have recommended that the FISA process be made more efficient, and the Department of Justice has made major strides in recent years in improving its practices and procedures. The proposal would make several changes to improve further the efficiency of the FISA process, including extending the period of authorization for non-United States persons, which will allow the Department and the FISA Court to concentrate more scarce resources to the cases that concern United States persons.

  • Reflecting today’s national security threats. The Bill seeks to update FISA to reflect today’s national security threats. One of those threats is the proliferation of weapons of mass destruction. This legislation will allow the Intelligence Community to obtain FISA authority to better protect the nation against proliferators.

  • Adding an additional definition of an agent of a foreign power for non-U.S. persons whom the Government believes possess significant intelligence information, but whose relationship to a foreign power is unclear." [So the new definition would be “undefined?” Bob]

  • Via FAS, the text of the proposed legislative changes to FISA, including a section by section analysis (66 pages, PDF).

  • April 16, 2007 press release: "Senators Dianne Feinstein (D-Calif.) and Arlen Specter (R-PA) today re-introduced legislation reaffirming that the federal government must follow the requirements of the Foreign Intelligence Surveillance Act of 1978 (FISA) when conducting electronic surveillance of American citizens in the United States for foreign intelligence purposes. The Feinstein-Specter bill also would prevent delays in intelligence agency anti-terrorist surveillance, while ensuring that these activities do not violate the civil liberties guaranteed by the U.S. Constitution and federal law."



Congress has been in the dark before...

http://www.eff.org/deeplinks/archives/005205.php

Sen. Specter: Telcos' Role in NSA Spying Program Must Be Exposed

April 16, 2007

Tomorrow, the Bush Administration will go before the Senate Intelligence Committee to push a dangerous new spying bill [PDF]. Among other things, the bill could threaten cases like EFF's against AT&T by giving blanket immunity to companies for illegally assisting the NSA spying program.

We're glad to hear that Senators are already pushing back against this proposal. As the NY Times reports:

"[Senator Arlen] Specter said he opposed the proposed immunity for telecommunications companies because the White House had never provided Congress with enough information about the role of the companies in the program.

"'That provision is a pig in the poke,' Mr. Specter said. 'There has never been a statement from the administration as to what these companies have done. That's been an intolerable situation.'"

The rest of Congress should heed those words. It would be highly irresponsible of Congress to legislate in the dark, before the past and present abuse of surveillance powers has been thoroughly investigated.



Perhaps the RIAA would like to explain why?

http://hardware.slashdot.org/article.pl?sid=07/04/16/2239256&from=rss

Return of the Vinyl Album

Posted by kdawson on Monday April 16, @08:34PM from the vinylly dept. Music Data Storage Hardware

bulled writes "NPR ran a story this morning about the comeback of vinyl. It seems that sales of new vinyl records are up about 10%; sales will approach a million this year (as against half a billion for CDs). NPR mentioned the popularity of a turntable with a USB interface — they didn't specify the brand; could be this one, or this — and speculated on other possible reasons for the resurgence. They mentioned sound quality and lack of DRM as possible causes. Sound quality can and will be debated, but DRM rates a resounding 'Duh.'"



Perhaps the RIAA should sue for unfair competition?

http://www.bespacific.com/mt/archives/014566.html

April 15, 2007

BBC Plans to Offer Entire Broadcasting Archive Free

Guardian Unlimited reports: "The BBC wants to put nearly one million hours of material on the internet for viewers to watch, listen to and download and has already begun the long process of retrieving and transferring programmes. A trial involving 20,000 users will begin next month, and the service could be available nationally in a year's time."



Perhaps this story will get more interesting? It sure isn't dying! Would this have been appropriate “employee monitoring?”

http://www.thetimesonline.com/articles/2007/04/17/news/top_news/docba7b54a93d9181d1862572c0000470eb.txt

Ex-principal in sex tape apologizes, but says privacy invaded

Tuesday, April 17, 2007 12:28 AM CDT BY JOAN CARREON Times Correspondent

As students and staff returned to Sandridge Elementary School from spring break Monday, the school's former principal publicly apologized to his wife of 30 years and said the "persons who invaded my privacy need to be held accountable."

The words were Leroy Coleman's first about the explicit DVD that began to circulate last week and showed the former Sandridge Elementary District 172 administrator and a former science teacher having sex in a school office.

The recording showed Coleman, a 56-year-old Flossmoor resident, and science teacher Janet Lofton, a 41-year-old resident of Lynwood, engaged in sexual activity at various times and dates in what appeared to be December and January.

Another woman, identified as teacher's aide and substitute teacher Anjayla Reed, also appears in the recording on a separate occasion being hugged and touched by Coleman.

All three educators resigned their positions last week.

With Cook County Sheriff's Department police on hand, students arrived at Sandridge Elementary School as about 25 disgruntled parents staged a demonstration directly across the street and shouted sentiments such as "Fire Leroy Coleman!" at cars and trucks passing by.

Authorities kept parents and the media from school grounds, and some parents kept their children home from school.

One parent, Bonita Stack, said half of the children at Sandridge don't understand what has happened and now are wondering why their principal is not at school.

Sue Dykstra, whose first- and third-graders are in public school for the first time at Sandridge, said she thinks Coleman, Lofton and Reed should have been fired and not been allowed to resign.

"What if one of the kids would have walked in on them (at school)?" she asked.

Later that afternoon, Coleman read from a prepared statement in front of media at his home, and later in the office of his Matteson attorney, Raymond G. Wigell. In the statement, Coleman accepted full responsibility for "my inappropriate acts with a consenting adult."

"Without denigrating my wrongdoing and my acceptance of responsibility, the persons who invaded my privacy need to be held accountable," Coleman said. "It is not for me to comment on the motivation of the persons who knew or should have known of the placement of the video camera on District 172 property. While my actions have hurt my wife, their actions have hurt my family, friends and a lifetime of educating children."

Coleman said he will continue to cooperate with the Sheriff's Department's investigation.



“I know nothing!” Sgt. Schultz

http://www.bespacific.com/mt/archives/014576.html

April 16, 2007

Pew Research Survey - What Americans Know: 1989-2007

Public Knowledge of Current Affairs Little Changed by News and Information Revolutions - What Americans Know: 1989-2007. Released April 15, 2007.

  • "Since the late 1980s, the emergence of 24-hour cable news as a dominant news source and the explosive growth of the internet have led to major changes in the American public's news habits. But a new nationwide survey finds that the coaxial and digital revolutions and attendant changes in news audience behaviors have had little impact on how much Americans know about national and international affairs.
    On average, today's citizens are about as able to name their leaders, and are about as aware of major news events, as was the public nearly 20 years ago."

Monday, April 16, 2007

I told you it was systemic... Good quote at the end of the article.

http://www.post-gazette.com/pg/07105/778182-85.stm

Second set of UPMC data found on Internet

Sunday, April 15, 2007 By Steve Twedt, Pittsburgh Post-Gazette

A second set of UPMC patient names, Social Security numbers, X-rays and other personal medical information has surfaced on a Web site maintained by a California archival company.

The data and related medical scans came from a PowerPoint presentation by Dr. Paul J. Chang to the Radiological Society of North America in 2002.

In December 2003, the California company, The Internet Archive, retrieved the presentation from the UPMC radiology department's Web site and posted it on its own Web site. That made it available to anyone searching the Archive site.

At some point, the presentation was deleted from the UPMC Web site, but it remained on The Internet Archive site until Friday.

On Thursday, the Pittsburgh Post-Gazette reported that another old PowerPoint presentation by Dr. Chang containing UPMC patient data was still accessible on the UPMC site, with identifying personal information for nearly 80 patients.

UPMC removed the item from its Web site Wednesday, but a copy was still available from The Internet Archive through Friday morning.

The latest presentation contains information on eight additional patients, including X-ray scans. At least two of the patients have since died. But other slides clearly show valid Social Security numbers for still-living patients.

Both sites were taken down Friday afternoon after the Post-Gazette inquired about them, and Internet Archive access to UPMC radiology sites now has been blocked.

... "I can guarantee this will never happen at UPMC again, but something else will. It's more than the Internet. It's being digital. If I burn a piece of paper, it's gone. If I shred a record, it's gone. But if I have an electronic version, it doesn't ever go away."



Someone at Sony needs a good talking to...

http://slashdot.org/article.pl?sid=07/04/15/1914248&from=rss

New Sony DVDs Not Working In Some Players

Posted by kdawson on Sunday April 15, @05:33PM from the DRMed-out dept. Sony Media Movies Entertainment

An anonymous reader writes "It seems that the most recent DVDs released by Sony — specifically Stranger Than Fiction, Casino Royale, and The Pursuit of Happyness — have some kind of 'feature' that makes them unplayable on many DVD players. This doesn't appear to be covered by the major media yet, but this link to a discussion over at Amazon gives a flavor of the problems people are experiencing. A blogger called Sony and was told the problem is with the new copy protection scheme, and they do not intend to fix it. Sony says it's up to the manufacturers to update their hardware."



e-Discovery resource?

http://searchstorage.bitpipe.com/detail/RES/1176144651_457.html?asrc=RSS_BP_KABPMANAGEIT

ON DEMAND WEBCAST!

Email Archiving Regulations and Legal Discovery for Exchange - Expert Webcast

by Sherpa Software


Will every company need a tool like this? Can users make this call?

http://www.infoworld.com/article/07/04/16/HNemcediscovery_1.html?source=rss&url=http://www.infoworld.com/article/07/04/16/HNemcediscovery_1.html

EMC taps users to expedite e-discovery

User input and full-text indexing fuel upgrades to company’s archiving governance initiative

By Jason Snyder April 16, 2007

... Slated for availability May 21, EmailXtender 4.8 allows administrators to push out archiving folders with predefined retention periods to users of Microsoft Exchange and Lotus Domino. Users can drag and drop messages they deem business-critical to these folders. The messages will appear in their inbox and can be shared among multiple users according to project needs.

“In the past, the form of archiving was automation,” Ferguson said. “What we’re adding is the ability for users to determine, based on their intimate knowledge of the content, what is a business record and, therefore, should be archived.”



...for a mere $3500

http://www.bespacific.com/mt/archives/014554.html

April 13, 2007

Worldwide Email Usage 2007–2011 Forecast

Press release, Worldwide Email Usage 2007–2011 Forecast: Resurgence of Spam Takes Its Toll, March 2007: "This IDC study examines how email is being used and will be used for business and personal purposes. In its eighth year, this annual study of email usage provides email solution providers and their customers with insights on how email usage is changing based on a 10+ year perspective (2000–2010)... "Spam volumes will continue to grow faster than expected [“Illogical” Spock Bob] due to the success of image-based spam in bypassing antispam filters and of email sender identity spoofing in getting higher response rates. Instant messaging, joined by free and low-cost VoIP calling, will result in slower email growth, especially among teens and young adults," [Interesting to us “business modelers” Bob] said Mark Levitt, program VP, Collaborative Computing and the Enterprise Workplace, IDC."



Shouldn't all this be free? Why all the limitations?

http://www.bespacific.com/mt/archives/014555.html

April 13, 2007

Nebraska Now Offers Online Access to 7.1 million State Court Case Records

Press release: "Nebraska's Court Case One Time Search service provides online access to court case records in all 93 county courts and 92 of the state's 93 district courts (excluding the district court in Douglas County). The service was launched through a collaborative effort between the Nebraska Office of the State Court Administrator and Nebraska.gov.

  • Justice Court Case One Time Search. This system is designed to allow easy access to information about court cases throughout Nebraska. For a $15.00 per search fee, a user can search for a party involved in a case in Nebraska. The results of the search can provide information on up to 30 cases. The search and corresponding results can be viewed over a three day time frame... The full listing of cases is updated nightly, so there is a 24 hour lag time between when data is entered into the system, and when it appears on the search."



For my web site class

http://digg.com/software/Turn_Any_Picture_Into_3D_Image

Turn Any Picture Into 3D Image

Fotowoosh, a new service from Maryland-based startup Freewebs, will turn any image into a 3D model. In a week or so, the company says, users will be able to upload a picture and have an animated 3D image returned to them in an embeddable Flash widget.

http://www.techcrunch.com/2007/04/15/fotowoosh-will-turn-any-picture-into-3d-image/



Granny's no fool. ...and you thought this industry had died in the 1960s...

http://techdirt.com/articles/20070413/110343.shtml

Open Source... Sewing?

from the stitch-it-up dept

Apparently this is the month for the fashion industry to teach some lessons to other industries that you don't need to focus on protecting your intellectual property when, instead, you can use it to promote products to sell. First there was the research showing how a lack of intellectual property protection on fashion designs helped grow the industry by making it faster to change and faster to innovate. Now, Portia writes in with an example of a company that sells high-end sewing patterns that has decided to adopt an "open source" attitude. Basically, the company has recognized that obscurity or disinterest is a much bigger risk its business than "piracy." So, with that in mind, it's removed the copyright on its designs, asked people to feel free to improve on them -- and even encourages people to make money selling the improved designs. The only thing the company asks for is attribution of where the design originated from. What gave Hubert Burda, the chairman of the company, the idea? "He said we should not make the same mistakes as record companies did with copy restrictions."



ATTENTION CLASS_ACTION LAWYERS!

http://news.bbc.co.uk/1/hi/uk/6554755.stm

Titanic passenger lists go online

The original passenger lists from the Titanic are being made available online for the first time, 95 years after the ocean liner sank on its maiden voyage.

The lists could previously be seen only at the National Archives in Kew, south-west London.

They will be free to view on the findmypast.com website for a week - after which a fee will be charged.

... The Titanic lists are part of a larger project - with 1.5m ship passenger lists dating back to 1890 being put online. [Some of which actually made it! Bob]

Sunday, April 15, 2007

We saw this a few weeks ago in Connecticut(?) Apparently there is a do-it-yourself kit out there...

http://www.insidebayarea.com/oaklandtribune/ci_5659098

Card fraud linked to supermarket

By Alejandro Alfonso, STAFF WRITER Article Last Updated: 04/13/2007 08:45:39 AM PDT

SAN LORENZO — Using their credit or debit cards in the checkout line at the supermarket is how more than 60 people had their identity stolen and bank accounts raided by tech-savvy thieves, Alameda County Sheriff's Sgt. Tom Madigan said.

A credit card skimmer, a device used to capture the account and PIN numbers associated with a credit or debit card when it is swiped through the machine, was placed on a checkstand in Albertsons [How can they do this without out anyone noticing? Bob] at 15840 Hesperian Blvd., Madigan said.

"By installing that device, they captured PIN and account numbers," he said. "We believe the device was installed for a period of time and then removed." [Two opportunities to catch these guys... Bob]

The Sheriff's Office saw a spike in reported cases of identity theft in the past week — at least 60 so far — and Madigan expects more as people continue to check their bank statments, he said. The Sheriff's Office usually averages about 20 calls of identity theft a month.

"Some people might not even know they are victims," he said.

In this case, the thieves are making clone cards with the information and using them to take money through ATMs, predominantly in Southern California, Madigan said.

"Clearly, this is a sophisticated person or group of organized individuals," he said.

The estimated total loss from all the accounts is about $50,000 as of Thursday, Madigan said. The minimum taken from any single account has been $500, he added.

In some cases, the thieves made phony deposits through the ATM with an empty envelope and then made withdrawals.

"Banks take the brunt of these losses," Madigan said. "They are getting hammered because they have to replace the money."

Most people only report the fraud to their banks, he said. "On average, about 25 percent report these things to us," Madigan added, implying the loss could be much larger.

"We are trying to sort out which ones are coming from the Albertsons and which are separate," he said.



Why would you think this is limited to Texas?

http://www.pogowasright.org/article.php?story=200704140756026

TX: Lawmakers concerned about governor's database, who has oversight

Saturday, April 14 2007 @ 07:56 AM CDT - Contributed by: PrivacyNews - State/Local Govt.

Concerns about a criminal database amassed by Gov. Rick Perry's homeland security office dominated a public hearing on a border security bill late Friday, with Democratic lawmakers pointedly questioning who controls the information, what safeguards are in place to ensure its integrity and whether it could be used for political purposes or to infringe on civil liberties.

Earlier, Rep. Richard Raymond, D-Laredo, filed legislation Friday that would move the database out of the governor's office to the Texas Department of Public Safety.

Source - Statesman.com

Related - KHOU: Perry aide has huge database with info on more than 1M Texans



We can, therefore we must!

http://www.pogowasright.org/article.php?story=20070414124549252

UK: Hundreds hit in drive for roadside fingerprints

Saturday, April 14 2007 @ 12:45 PM CDT - Contributed by: PrivacyNews - Non-U.S. News

HUNDREDS of motorists have had their fingerprints checked at the roadside in a controversial pilot scheme that has raised fears of a growing Big Brother culture. Drivers and passengers are among the 4,200 people who just in the past four months have been asked to use a hand-held fingerprint reader.

The device checks their identity against 6.5 million recorded prints of convicts and crime suspects.

Source - Yorkshire Post



If you know they are “breaking the rules” shouldn't there be more severe consequences?

http://www.sun-sentinel.com/news/nationworld/sfl-aloans15apr15,0,2245764.story

Lenders break rules searching students' data

System may be shut down

By Amit R. Paley The Washington Post April 15, 2007

WASHINGTON · Some lending companies with access to a national database that contains confidential information on 60 million student borrowers have repeatedly searched it in ways that violate federal rules, raising alarms about data mining and abuse of privacy, government and university officials said.

The improper searching has grown so pervasive that officials said the Education Department is considering a temporary shutdown of the government-run database to review access policies and tighten security.

... The department has blocked thousands of users that it deemed unqualified for access after security reviews, McLane said, and it has blocked 246 users from the student loan industry for inappropriately accessing the data.

... The department has been "vigilant in its monitoring for unauthorized uses" of the database, McLane said. [Sure enough, we see lots of “unauthorized uses,” we just don't do much...” Bob]

The database, known as the National Student Loan Data System, was created in 1993 to help determine whether students are eligible for student aid and assist in collecting loan payments. About 29,000 university financial aid administrators and 7,500 loan company employees have access to it.



As long as we're talking about unpunished sins... (This is not a new incident, just a followup.)

http://www.pittsburghlive.com/x/pittsburghtrib/news/cityregion/s_502469.html

UPMC admits privacy violation

By Mark Houser TRIBUNE-REVIEW Friday, April 13, 2007

If the government fines UPMC for revealing the private records of 80 patients, it will be the first such fine in the country.

... Federal law prohibits the unauthorized release of private medical information.

... The U.S. Department of Health and Human Services enforces [Not the word I would use... Bob] medical records privacy through its Office of Civil Rights, which can issue fines of up to $25,000 a year for each violation.

The office has received about 26,000 complaints of medical privacy breaches since new privacy rules went into effect in 2003, according to a senior adviser there who spoke on background.

Of those, about 4,100 have been determined to be actual violations of federal rules, the official said. But the office has worked with health care agencies to correct problems and has not yet issued a fine, the official said.

... Some critics say the lack of fines gives the impression the government isn't serious about protecting privacy.

"The current policy is to give hospitals one free violation. That sends the wrong message," said Peter Swire, an Ohio State University law professor who oversaw the creation of the medical records law under the Clinton administration.

"Compliance people in hospitals have complained that they are not getting budget and support due to this no-enforcement strategy," Swire said.

A 2006 national survey of health care providers and insurers by the Healthcare Information and Management Systems Society found that 22 percent of care providers were not in compliance with privacy regulations.

In addition, the survey said about half of reportedly compliant hospitals reported breaches in medical privacy.



What does $3 Billion buy you?

http://blogs.zdnet.com/micro-markets/?p=1219

Google to tag users across Web: Privacy Boomerang?

Posted by Donna Bogatin @ 1:04 am April 14th, 2007

Why is Google acquiring DoubleClick?

To give users “better privacy protection,” among other things asserted by Google.

REALLY? Google has actually taken a $3.1 billion step closer to realizing its objective of organizing all the world’s information, the world’s personal information that is.

In acquiring DoubleClick, Google will operate the firm’s “Boomerang for Advertisers, Marketers and Agencies” to leverage behavioral targeting, “the most effective form of targeting available, according to DoubleClick.

How DoubleClick's Boomerang works:

1) User visits client Website looking for a product and browses, but does not make a decision. The user is “now tagged” as an interested prospect in a Boomerang List.

2) User continues Web browsing, visiting a site where the client has an ad campaign already running. Dart for Advertisers recognizes the visitor (thanks to the Dart cookie ID), and serves a targeted ad offering free shipping.

3) Qualified prospect clicks on Boomerang-targeted ad and is taken back to client Website to take advantage of free shipping offer.

Google has famously not accepted third party ad tags under the guise that “we don’t do anything to compromise the user experience on Google properties or across our AdSense network.”

In its Google Speak FAQ on its DoubleClick transaction, however, Google says:

We did not accept third party tags because we could not guarantee the quality of the ad or that it would comply with our format policies. (BUT) working with DoubleClick we will increase the relevance of ads online so that we maintain a positive user experience while providing targeted ad opportunities for advertisers and increased monetization for publishers.

What are some of the ways Google might “increase the relevance of ads online” by working with DoubleClick?

The ability to correlate information about third-party sites collected using DoubleClick technology, particularly cookies, with search history and other information gathered by Google would be extremely powerful, and potentially very attractive as a marketing tool (and) would significantly increase the amount of data that could be aggregated about any given individual, Lauren Weinstein, California Initiative for Internet Privacy, is cited by CIO Today.

Google acquires a DoubleClick “sketchy reputation,” according to Weinstein:

From the start DoubleClick has been the poster boy for third-party cookies, and when they started pulling information from widely ranging sources and compiling in it in a central database, they helped drive the opposition to cookies. There are entire Web sites devoted just to blocking DoubleClick ads.

When DoubleClick ads become Google ads will there be a privacy Boomerang?

ALSO: Google DoubleClick merger: Who wins, who loses and Google DoubleClick marriage (can be) risky business and Google hurts Yahoo with DoubleClick deal and Google: $3.1 billion cash for Web monopoly! and Microsoft vs. Google: Will MSN, Windows Live compete?



Finding potential collaborators or potential victims... (see next article)

http://radar.oreilly.com/archives/2007/04/why_im_so_excit.html

Why I'm so excited about Spock

Sat 04.14.07 Tim O'Reilly

Note: Spock is among the companies launching at the Web 2.0 Expo on Monday.

Michael Arrington wrote the other day about spock, the new people search engine, but I have to say that I don't think he did it justice. Spock is really cool, and performs a unique function that is well outside the range of capabilities of current search engines. What's more, it's got a fabulous interface for harvesting user contribution to improve its results.

You can search for a specific person -- but you can do that on Google. More importantly, you can search for a class of person, say politicians, or people associated with a topic -- say Ruby on Rails. The spock robot automatically creates tags for any person it finds (and it gathers information on people from Wikipedia, social networking sites like LinkedIn and Facebook), but it also lets users add tags of their own, and vote existing tags up or down to strengthen the associations between people and topics. Users can also identify relationships between people (friend, co-worker, etc.), upload pictures, and provide other types of information. This is definitely a site that will get better as more people use it -- one of my key tests for Web 2.0. It also illustrates the heart of a new development paradigm: using programs to populate a database, and people to improve it.


Would your local cops even understand the crime?

http://www.msnbc.msn.com/id/18101672/

WP: Stalkers track victims in cyberspace

Little more than cursory skills needed to track exes' online, phone activity

By Chris L. Jenkins The Washington Post Updated: 12:13 a.m. MT April 14, 2007

The case had the makings of an eerie cyber-mystery: A young Alexandria woman told local police she suspected that her ex-boyfriend was tapping into her e-mail inbox from thousands of miles away, reading messages before she could and harassing the senders.

She was right to be suspicious. Her ex had hacked into her e-mail account, either guessing her password or using spyware -- software that can secretly read e-mails and survey cyber-traffic, law enforcement officials said. For months, apparently, he had followed her every online move, part of a pattern of abuse city police are still investigating.

Law enforcement officials and safety groups have focused on the Internet as an arena for such types of harassment as false impersonation and character assassination as more people voluntarily place their private lives on public display through Web sites such as Facebook.com and MySpace.com.

But a little-discussed and more threatening phenomenon is also happening to the unwitting online and in the high-tech world: cyber-stalking, the illegal monitoring of private information and communication of ex-lovers and spouses as a form of domestic violence. The spurned often use global positioning systems, invasive computer programs, cellphone monitoring chips and tiny cameras to follow the whereabouts, goings-on and personal communications of unsuspecting victims.

... It's not hard to figure out. Do-it-yourself manuals are widely available online. Some sites advertise otherwise legitimate programs for stalking uses. For instance, spyware was developed commercially to help parents keep tabs on their children's Web use and to provide information for advertisers. Now it is commonly advertised on Web sites as a way to snoop on a spouse. "Monitor any PC from anywhere!" one ad promises. "Spy stealthily so that the user won't know such monitoring exists," another says.

... In addition, the Bureau of Justice Statistics has started to track technological methods used in stalking and domestic violence.



If Al Gore didn't invent it, I won't believe it! (Should this have been published on April 1st?

http://news.independent.co.uk/environment/wildlife/article2449968.ece

Are mobile phones wiping out our bees?

Scientists claim radiation from handsets are to blame for mysterious 'colony collapse' of bees

By Geoffrey Lean and Harriet Shawcross Published: 15 April 2007

It seems like the plot of a particularly far-fetched horror film. But some scientists suggest that our love of the mobile phone could cause massive food shortages, as the world's harvests fail.

They are putting forward the theory that radiation given off by mobile phones and other hi-tech gadgets is a possible answer to one of the more bizarre mysteries ever to happen in the natural world - the abrupt disappearance of the bees that pollinate crops. Late last week, some bee-keepers claimed that the phenomenon - which started in the US, then spread to continental Europe - was beginning to hit Britain as well.

The theory is that radiation from mobile phones interferes with bees' navigation systems, preventing the famously homeloving species from finding their way back to their hives. Improbable as it may seem, there is now evidence to back this up.



Lightweight paper. But it might start a useful debate.

http://politics.slashdot.org/article.pl?sid=07/04/14/1718241&from=rss

New Laws of Robotics Proposed for US Kill-Bots

Posted by Zonk on Saturday April 14, @04:43PM from the maybe-calling-them-kill-bots-is-a-bad-first-step dept. Sci-Fi Robotics Politics Technology

jakosc writes "The Register has a short commentary about a proposed new set of laws of robotics for war robots by John S Canning of the Naval Surface Warfare Centre. Unlike Asimov's three laws of robotics Canning proposes (pdf) that we should 'Let machines target other machines and let men target men.' Although this sounds OK in principle, 'a robot could decide under Mr Canning's rules, to target a weapon system such as an AK47 for destruction on its own initiative, requiring no permission from a human. If the person holding it was thereby killed, that would be collateral damage and the killer droid would be in the clear.'"



Some snippets to suggest that reading these articles may be important to both the e-Discovery team and IT in general...

http://www.securityfocus.com/infocus/1890?ref=rss

Notes On Vista Forensics, Part Two

Jamie Morris 2007-04-13

... Another interesting change is that Vista is configured by default to not update the last access time on files, a decision made to increase file system performance.

... In fact, situations where a user's data may no longer be stored on the local machine should come as no surprise to forensic examiners.

... As most computer users will know, there often comes a time when our machines slow to a crawl due to too many applications making demands on available memory. The most straightforward solution to this problem (other than running fewer programs at the same time, of course) is to add extra RAM but this can still be a daunting task for those with little technical knowledge. Vista offers a solution to this problem in the shape of ReadyBoost [ref 8], a new feature which allows attached flash memory devices to be used as extra memory.

... Metadata can be described as data about data. In the world of computer forensics, metadata is usually discussed in terms of information held about a file, a well known example of which is the information associated with a Word document which can include various details such as the author's name, comments and revision history (in fact, this particular example is so well known that Microsoft was forced to create a tool to help users remove the data in question!) Metadata on Windows systems becomes even more interesting when you examine multiple file streams, a concept first introduced in NT 3.51, which allow you to associate extra information with a file on an NTFS filesystem. Although the information held in these streams may appear invisible to the typical user, it can be a rich source of information to the examiner. This potential repository for data could also be used to hide information and so it has become an essential area to cover during an investigation.

... Returning to the user experience once again, another important develoment as far as metadata is concerned is that Microsoft is now encouraging users to add such data to their own files though the use of "tags" or "metatags". Primarily seen as a way to help users rate, organize and search through their content, user-generated tags may prove to be a useful source of information during certain types of investigation. However, the flip side of this potential benefit is that Vista also makes it relatively easy (through a file's Properties tab) for users to remove metadata.

... Scott A. Moulton of Forensic Strategy Services, LLC. [ref 11] explains: "I still have major problems mounting large drives under Vista. I use many 1 terabyte or 2 terabyte drives and Vista is absolutely worthless on these drives - I'm lucky if Vista does not actually mess the drive up. Deleting files is a nightmare and sometimes takes days.



Interesting debate? We can be open and not safe, or closed and still not safe.

http://www.networkworld.com/columnists/2007/041607backspin.html

Prepared for the worst

Backspin By Mark Gibbs, Network World, 04/13/07

Several readers wrote in after last week's column to ask whether it was a good idea to tell the bad guys about One Wilshire -- the carrier hotel inhabited by a bunch of Tier 1 service providers -- and how to find it.