Wednesday, May 02, 2007

I almost don't bother with these any more. They are small scale (usually less than a few thousand people) and not really an indication of a systemic failure. But the customer relations hit has got to hurt – especially when millions of Youtube viewers are watching...

http://wcbstv.com/watercooler/local_story_121055435.html

May 1, 2007 8:55 am US/Eastern

YouTube Shocker: Chase Bank Records Found In Trash

Video Exploits Security Lapses With Customer Info

Jay Dow Reporting

(CBS) NEW YORK A bank error that's certainly not in your favor has found its way onto the Internet, and now officials say very personal information of thousands of Chase Bank customers could find its way into the hands of identity thieves.

A new YouTube video flaunting the personal information of Chase Bank customers is getting a lot of attention. The video shows a person holding numerous confidential financial documents of bank customers, and pointing out information that is supposed to be protected by the bank.

"Social Security Numbers here as well as date of birth," one person could be heard saying on the video, pointing to one of the documents.

Bank statements, credit reports and other personal documents were seen being unearthed in the video.

Researchers for the Service Employees International Union, which is battling the banking giant over its use of non-union security employees, found the documents out in the open. [No bias here! Bob] They were found in trash bags that were left outside several New York City Chase branches.

[The video: http://www.youtube.com/watch?v=G_8xRnzQqME&eurl=http%3A%2F%2Fwww%2Efinextra%2Ecom%2Ffullstory%2Easp%3Fid%3D16872



If they can recognize your face, why not read your lips?

http://yro.slashdot.org/article.pl?sid=07/05/01/177254&from=rss

Lip-Reading Surveillance Cameras

Posted by kdawson on Tuesday May 01, @02:16PM from the open-the-pod-bay-doors dept.

mrogers sends us to Infowars for the following news from the UK, "which is fast becoming the front line of the war on privacy": "'Read my lips..."' used to be a figurative saying. Now the British government is considering taking it literally by adding lip reading technology to some of the four million or so surveillance cameras in order identify terrorists and criminals by watching what everyone says. Perhaps the lip-reading cameras and the shouting cameras will find something to talk about."


Related

http://www.washingtonpost.com/wp-dyn/content/article/2007/05/01/AR2007050100600_pf.html

British motorists face spy in sky monitoring

By Jeremy Lovell Reuters Tuesday, May 1, 2007; 9:25 AM

LONDON (Reuters) - Spies in the sky may track motorists in Britain within a decade if the government goes ahead with controversial plans to introduce road user charging schemes, scientists said on Tuesday.

The plans were unveiled in a report on future transport policy in November as a way of cutting congestion and prompted 1.8 million people to sign an electronic protest petition.

Monitoring would be via a combination of static cameras to capture license plate details, electronic tags in vehicles that would be read by roadside monitoring stations and global positioning system satellites to read on-board transponders.



Don't count this out yet. Even if criminals are unwilling to take the risk doesn't mean it isn't still a viable tool of cyberwar.

http://it.slashdot.org/article.pl?sid=07/05/01/2135212&from=rss

Death Knell For DDoS Extortion?

Posted by kdawson on Tuesday May 01, @07:17PM from the greener-pastures dept. Security The Internet IT

Ron writes "Symantec security researcher Yazan Gable has put forward an explanation as to why the number of denial of service attacks has been declining (coincident with the rise of spam). His theory is that DoS attacks are no longer profitable to attackers. While spam and phishing attacks directly generate profit, he argues that extortion techniques often used with DoS attacks are far more risky and often make an attacker no profit at all. Gable writes: 'So what happens if the target of the attack refuses to pay? The DoS extortionist is obligated to carry out a prolonged DoS attack against them to follow through on their threats. For a DoS extortionist, this is the worst scenario because they have to risk their bot network for nothing at all. Since the target has refused to pay, it is likely that they will never pay. As a consequence, the attacker has to spend time and resources on a lost cause.'"



Parents want to know but are afraid to ask their kids?

http://seattlepi.nwsource.com/local/6420AP_WA_Kissing_Protest.html

Last updated April 30, 2007 11:01 a.m. PT

Gig Harbor High School students protest kissing camera surveillance

THE ASSOCIATED PRESS

GIG HARBOR, Wash. -- A couple of dozen Gig Harbor High School students are demonstrating outside the school today to protest the use of a surveillance camera to catch two girls kissing.

One student reporting the demonstration for the school paper, Amber Critchley, says they are saying the school shouldn't have interfered and that sexual orientation shouldn't matter.

Principal Greg Schellenberg says the protest is a disruption but classes are continuing.

He says he congratulated the students on holding a peaceful demonstration. The students are wearing "free love" T-shirts and waving peace signs.

Schellenberg says the school was wrong to show surveillance video to the parents of one girl who was seen kissing another girl. He says the parents of one girl had asked the school to report anything unusual with her.

Schellenberg says she is no longer at the school, but the other girl remains a student.

He says the school does not target gay and lesbian students.



One of those tools to eliminate lawyers?

http://techdirt.com/articles/20070426/010447.shtml

We'll Have To Wait For The Next Lawsuit To Find Out If A Web Crawler Can Enter Into A Contract

from the settled-away dept

Last month, news spread concerning a somewhat odd lawsuit involving the Internet Archive and the question as to whether or not a computer spider can enter into a contract just by indexing a website. The case involved a woman who ran a website and had put some text at the bottom claiming that just visiting the website was entering into a contract, and part of that contract included not copying or distributing the content. The Internet Archive's spider did what it does and archived the page, leading to the threat of a lawsuit. The Internet Archive preemptively went to court to have a judge say they were in the clear, at which point the woman countersued. Of course, she didn't just countersue for copyright infringement, but a range of charges including racketeering. Most of the discussion focused on whether or not a spider could enter into a contract, though an equally compelling question is whether or not you can automatically force someone to give up their fair use rights. Unfortunately, neither question is going to be decided in this case. WebProNews reports that the woman and the Internet Archive have settled the case out of court with both sides putting happy faces on the story. At the same time, however, WebProNews also reports that the woman in question is still going after some of her critics, including publishing all sorts of personal information about at least two of them, potentially violating some privacy laws (at least one of the critics she's revealing info on is a minor). So perhaps there will still be a lawsuit stemming from this situation after all.



This is a hot story. The “secret number” is all over the net!

http://techdirt.com/articles/20070501/202154.shtml

AACS Discovers The Streisand Effect: The More You Try To Suppress Something, The More Attention It Gets

from the let's-try-this-again dept

If you follow tech related sites, by now you've heard the story that the folks who control AACS, the copy protection used in next generation DVDs, have decided to send DMCA takedown notices to various sites that have posted the 128-bit integer that is needed, along with some software, to decrypt the video content on these new DVDs. This is odd for a few reasons. The key came out many months ago and has been available on the web for quite some time. There are, of course, the basic questions concerning whether or not this key alone really does violate the anti-circumvention clause of the DMCA -- but that's a separate issue. What's more intriguing here is trying to understand the thought process behind the decision to send out these takedown notices. As anyone who's been online for more than about two days knows, the more you try to suppress something online, the more attention you're going to call to it. Years back, we joking referred to this as the Streisand Effect -- after an incident where Barbara Streisand tried to remove some photos from the web, making them a lot more popular. The name has stuck, and it still amazes us that anyone doesn't recognize what will happen when they try to make such a move. While the group has forced some sites to pull pages here and there, every page they pull is just increasing the anger from a growing group of folks who are making sure the number shows up in many, many more places -- including directly in a URL. Digg, which was one of the sites accused of taking down pages about this, has been under a massive effort from folks to make sure that every story on the front page somehow points to the key in question (and it's interesting to see the anger of users turned against Digg for taking down some of these stories, even though they're pretty much required to thanks to the DMCA). As happened with DeCSS, it's only a matter of time until someone writes a song incorporating the key as well. Effectively, all that's been done here is to draw much, much more attention to the fact that the encryption on next generation DVDs is incredibly weak -- so that a lot more people now know about it. Most of us honestly couldn't have cared any less about the integer or the inner workings (or non-workings) of the encryption system -- and yet now we know a lot more. That can't be the intended consequence of these notices, but that's what's happened. Nice work, Hollywood.



It should have been obvious that they would do this (see next article for more obvious patents...)

http://techdirt.com/articles/20070501/203602.shtml

That Didn't Take Long: Vonage Asks Court To Review Verizon Patents Under New Supreme Court Rules

from the quick-response dept

Well, that certainly didn't take very long at all. Just a day after the Supreme Court smacked down the Federal Circuit for not properly reviewing patents for "obviousness," Vonage has used the case as an opportunity to ask the courts for a retrial in their VoIP patent lawsuit with Verizon. Vonage claims that, under the new obviousness test, Verizon's patents may be toast. When combined with recent discoveries of prior art that certainly may be true. This certainly is opportunistic of Vonage, but it will be interesting to see how the courts react to this request. One that that's definitely become clear is that courts at all levels are actually going to have to look more closely at obviousness, rather than brushing it off as they have for years. In the meantime, expect many more cases along these lines in the near future. It may clog the system for a bit, but if the end result is fewer bogus patents, it's worth it.


See! This is why patent attorneys get the big bucks!

Attention patent attorny types: I have a method for determining the page number even when the pages aren't numbered! I call it counting!

http://techdirt.com/articles/20070430/163631.shtml

Amazon Patents Counting Book Pages To Figure Out Unnumbered Page Numbers

from the doing-the-math dept

theodop writes "The USPTO has issued Amazon a brand spanking new patent for Determining Page Numbers of Page Images, a process which the e-tailer explains involves 'extracting all numbers that are exactly one different than a number found on an adjacent page'." Basically, they've figured out a way to look at pages in a book and see if some of the pages don't have numbers, and then use basic addition and subtraction to figure out what the actual number of those pages are. This isn't particularly complicated. Why should one company get a patent for it?



Geeks of the world, unite! You have nothing to lose but a few stupid laws!

http://techdirt.com/articles/20070430/011612.shtml

The Growth Of The Pirate Bay As A Political Movement

from the good-or-bad? dept

Tim Lee points us to an LA Times article on the growing success of The Pirate Bay's political movement, noting that its membership is growing in Sweden and is nearly equal to that of the country's Green Party. This is ironic for a few reasons -- most of all being that the entertainment industry was so proud over the raids on the Pirate Bay's servers last year, insisting that it had killed off the site. Instead, the site was back up in days, and the attention propelled what had been a fairly minor search engine for BitTorrent trackers into the limelight -- helping to get it many more users and to get the political movement some traction. In fact, we've now seen other political parties take on some of the Pirate Bay's platform. To be honest, I have mixed feelings about this. I don't support the Pirate Bay's position that unauthorized downloads are defensible. Instead, I think that copyright holders need to come to the realization that they're actually better off by letting people download content -- not that it needs to be forced upon them by users taking matters into their own hands. That said, by taking such an extreme position (and having it get some attention), perhaps it's more likely that content holders will come to this realization. They'll simply be forced to adapt and will start coming up with more successful business models that actually benefit from free downloads rather than trying to block them and sue their best customers.



Better than pins in a wall map?

http://www.bespacific.com/mt/archives/014730.html

May 01, 2007

Global Incident Map Displays Terrorist Acts, Suspicious Activity, General Terrorism News

GlobalIncidentMap.com: "This free public service website was created to give the public, law enforcement, military, and government individuals a new way to visualize, and become instantly aware of terrorism and security incidents across the world...While this website employs much automation, the news gathering itself is not automated - news items are located, reviewed, and manually entered into the database...Immediately below the map there is a scrolling list of the most recently added incidents - click an item of interest to get to the full incident description and links to related news items, as well as a more precise satellite/map image...This page automatically reloads every 420 seconds." Users may search by type of incident, country, date/time and city.



It's always nice to see how the other half lives...

http://www.bespacific.com/mt/archives/014724.html

April 30, 2007

WSJ Posts CEO Compensation Scorecard

WSJ free article - CEO Compensation Scorecard: "...starting with this year's proxies, the SEC has changed how companies report pay. For companies whose fiscal year ended after Dec. 15, 2006, the SEC now mandates a table that includes salary, bonus, the accounting cost of stock and stock-option awards, incentive-plan payments, change in pension value and deferred-compensation earnings, and all other compensation -- typically perquisites. It also includes, for the first time, a "total compensation" column, which attempts to make pay across companies more comparable."



Background

http://www.bespacific.com/mt/archives/014723.html

April 30, 2007

The Broadband Factbook Sent to Congress

Press release: "This week, the Internet Innovation Alliance (IIA) delivered the Broadband Fact Book to Congress on the heels of an OECD report and hearings in both houses of Congress on broadband deployment. The Factbook, available in hard copy and online is part of an IIA initiative, and according to the group, its purpose is "to prepare for the impending explosive growth in video applications and downloads that is triggering the deluge of data, and to inform why it portends both a tremendous opportunity and an important challenge." The Factbook is a resource for policy makers and all Americans that are learning about high-speed broadband -- how we use it, who benefits, the future demands on the Internet and what the United States must do to bring faster, affordable and more reliable broadband to every American."



Not getting enough politics in the newspapers and on TV?

http://www.bespacific.com/mt/archives/014734.html

May 01, 2007

washingtonpost.com Launches Presidential Campaign Tracker

Via Adrian Holovaty, see the "washingtonpost.com's Presidential Campaign Tracker uses information from campaigns, media reports and other sources to compile a listing of events involving presidential candidates and their spouses. The tracker covers events since January 2007. It does not include every event -- particularly fundraisers, which often are unannounced. Some events will be added retroactively as more details become available.

  • You can browse by date on a color-coded calendar, and, of course, each day has its own permalink (e.g., April 13, 2007). Each state gets its own page, too, so you can keep an eye on past and future candidate visits to Illinois, for example.



Perhaps my math students would be interested? Nahhhh...

http://science.slashdot.org/article.pl?sid=07/05/01/1827259&from=rss

Mathematica 6 Launched

Posted by kdawson on Tuesday May 01, @08:41PM from the simulate-this dept. Math Software Upgrades

Ed Pegg writes "Wolfram Research has just released Mathematica 6. That link, in addition to the usual 'dramatic breakthrough' material, has an amazing flash banner that simultaneously shows a thousand mathematical demonstrations all at once. The animations came from the Wolfram Demonstrations Project, a free service with 1200+ dynamically interactive examples of math, science, and physics, all with code. For the product itself, much is new or improved, with built-in math databases, improved visualizations, and more."

Tuesday, May 01, 2007

No notification required in Australia. Here's what happens...

http://www.techworld.nl/idgns/3056/hsbc-acts-to-stem-the-fallout-of-security-breach.html

HSBC acts to stem the fallout of security breach

Door: Sandra Rossi Computerworld Australia dinsdag 1 mei 2007

At long last, after weeks of stony silence and apparent mute indifference, the HSBC Bank finally acts!

Amid complaints by outraged account holders, the bank has taken action to deal with the fallout created when a serious security breach exposed records of more than a 100 of its customers.

... As reported in Computerworld, these confidential documents were found on a peak hour train in Sydney, left there by an HSBC employee.

But what made the situation worse was the bank's decision not to notify a single customer after the incident. Put simply the bank failed to act.

... Customers suspect the reason they weren't notified of the security breach has more to do with reputation protection (the bank's that is), than privacy protection.

If you think the customers are a tad cynical, then think again. When the bank finally did reach its painfully, slow, drawn out decision to act, what did it do?

HSBC chose to shoot the messenger.

That's right -- blame Computerworld for its predicament and take steps to gag this reporter. Surely that is the best way for HSBC to throw its support behind customers, right?

What a brilliant idea, try to bind the reporter in legal red tape and hollow threats so there are no more stories detailing security breaches at the bank. Problem solved! Not.

HSBC fired the first shot on Monday, April 23 sending a letter to Computerworld from its General Counsel.

HSBC had the audacity to write a letter expressing concern that this reporter had breached the Privacy Act by sighting the missing documents first hand.

Concerned that I am in possession of copies of the documents, HSBC was quick to demand their return by 5pm the very same day, or the bank "will not hesitate to take further action."

If only the bank had shown this level of concern for its customers, writing a brief letter notifying them when the incident first occurred.

But that incident didn't warrant any correspondence, yet HSBC seems to have fallen into a letter writing frenzy when it comes to Computerworld. I am reading my third letter in as many days. It seems I have become their favorite penpal.

Even more remarkable is letter number two which threatens to "seek damages" if I dare to contact any of their customers, especially those that had their financial details exposed in the security breach.

This is extraordinary because the only party in this debacle that has any right to seek damages is the customer who became a victim of HSBC's carelessness.



Nice of these folks to load the data into an easy to carry container...

http://content.hamptonroads.com/story.cfm?story=123820&ran=180020

Personal data stolen from Virginia agency

By CHRISTINA NUCKOLS, The Virginian-Pilot © May 1, 2007

RICHMOND - The names, addresses and Social Security numbers of 40,000 people were stolen last month from a state agency that serves elderly Virginians.

... Burcham said a computer and other equipment were stolen April 18 from the Richmond headquarters of the agency. She said a police investigation is pending and declined to give more details about the theft.

Notices were mailed to people in the database on April 26, eight days after the theft.

... Department officials said the client data is double-password-protected, but privacy advocates said that is not sufficient to safeguard personal information.



Minimum standards?

http://www.pogowasright.org/article.php?story=20070430172434317

GAO report targets data breach guidelines

Monday, April 30 2007 @ 05:24 PM CDT - Contributed by: PrivacyNews - Fed. Govt.

A U.S. Government Accountability Office (GAO) report issued Monday in response to a May 2006 data breach at the Department of Veterans Affairs says federal agencies should have uniform guidelines governing when to offer credit monitoring to individuals whose personal information is exposed.

Source - Network World

Related - GAO-07-657 {Full Report, PDF]
Related - GAO-07-657 [GAO Report Abstract]
Related - [GAO Report Highlights-PDF]



Originals are secured, copies are not!

http://pressherald.mainetoday.com/news/state/070501records.html

Data in Dumpster called 'disturbing'

Associated Press © Copyright 2007 Associated Press. Tuesday, May 1, 2007

AUGUSTA - A state official acknowledged Monday that a breakdown in security procedures caused personal information, including names and Social Security numbers, to be discarded in a Dumpster, where the records were uncovered by a television reporter. [New journalistic skill – dumpster diving! Bob]

The papers were found by WGME-TV, Portland, near the State Archives Records Center in Hallowell as part of an investigation about how state government handles personal information.

"What was discovered in the trash is certainly disturbing," said Secretary of State Matthew Dunlap, "but even though no laws were broken and the information uncovered could also be found in a variety of public records readily accessible to anyone who cares to look at them, this incident highlights a need -- for better tools for state employees and the implementation of additional policies and procedures to safeguard the personal information of Maine citizens."


More...

http://www.sunjournal.com/story/210197-3/MaineNews/Dumpster_discovery_raises_flag_on_ID_theft/

Dumpster discovery raises flag on ID theft

By Gregg Lagerquist and Judith Meyer , WGME 13 News Staff Sun Journal Managing editor/days Tuesday, May 1, 2007

HALLOWELL - In a parking lot Dumpster beside the state's Lottery Commission on Water Street there were enough discarded state records, including Social Security numbers, names and birth dates, to provide everything a would-be thief would need to steal dozens of identities.

... The News 13 investigation was launched after Maine's Health and Human Services Department issued an apology for unintentionally giving a half-dozen client records to a woman who had nothing to do with those cases.

... In a test of whether the state followed through on its pledge to better protect personal information, Lagerquist rifled through the contents of a Dumpster last week to see what kinds of records had been tossed there.

... He pulled all of the documents out of the Dumpster within two minutes and wasn't stopped by anyone from nearby state offices. In many cases, the documents were stamped "confidential" on their covers.

... Lagerquist shared what he found with Secretary of State Matt Dunlap.

"It's bad stuff," Dunlap said.

Dunlap, who supervises the state's record-keeping, acknowledged confidential documents "should be either in a locked Dumpster or shredded or somehow destroyed."

Maine law, according to the secretary of state's own rules for disposing local government records, requires that (unless otherwise specified by statute or rule), confidential records "may be destroyed by shredding, pulping, burning, burial or other effective means. The removal and destruction process shall be supervised by the official in whose custody the records are held in order to prevent the inadvertent removal and destruction of records of continuing value."

... The records Lagerquist found in the Dumpster were not original documents, but copies of documents forwarded through so-called inter-agency "transfer requests."

According to Dunlap, Maine treats original documents very carefully but secondary documents, like those in the Hallowell Dumpster, are not so carefully secured. He assured News 13 that the state would make changes to upgrade security for these secondary documents, changes that he started putting in place as soon as he learned of the security lapse.



The miracle continues!

http://www.bespacific.com/mt/archives/014715.html

April 30, 2007

Wiretaps Up Slightly in 2006

Federal Judiciary News Release: "A total of 1,839 orders were issued by federal and state courts in 2006 authorizing or approving the interception of wire, oral or electronic communications, also known as wiretaps. This is a 4 percent increase over the 1,773 orders issued in 2005, according to The 2006 Wiretap Report. The complete report contains information on interceptions concluded between January 1, 2006 and December 31, 2006. A summary of the authorized intercepts reported for calendar years 1996-2006 is availabe in Table 7."

[From the report: Public Law 106-197 amended 18 U.S.C. 2519(2)(b) to require that reporting should reflect the number of wiretap applications granted for which encryption was encountered and whether such encryption prevented law enforcement officials from obtaining the plain text of communications intercepted pursuant to the court orders. In 2006, no instances were reported of encryption encountered during any federal or state wiretap.



They won't...

http://slashdot.org/article.pl?sid=07/04/30/1816247&from=rss

How Will Governments Keep Up With Technology?

Posted by ScuttleMonkey on Monday April 30, @03:58PM from the just-like-a-large-poorly-managed-corporation dept. The Internet Technology

Andy Updegrove writes "Governments are beginning to realize that perhaps the Internet really has changed everything, at least for them, and that they are going to have to deal with new responsibilities in this area. How will they deal with financial and medical data breaches? What can they do to ensure that first responders will be able to communicate the next time that terrorists strike in the Homeland, and how will the refugees of the next Katrina be able to access their electronic medical records? And what must governments do to ensure that public records will be available in fifty years, if they no longer maintain paper archives? Whether government should incline towards leading, following or simply getting out of the way [My personal choice... Bob] is a matter upon which there are likely to be strongly held differences of opinion. It's also likely, though, that government will not have the luxury of opting for the third choice in some of the areas just mentioned. How well government chooses among those roles, and how well it executes when it chooses to lead, will likely have a profound impact on our lives in the years ahead."



Worth reading the entire comedy...

http://ralphlosey.wordpress.com/2007/04/29/no-spoliation-sanctions-for-%e2%80%9cmissing%e2%80%9d-porn-on-police-computers/

No Spoliation Sanctions for “Missing” Porn on Police Computers

April 29th, 2007

Just a few weeks before trial the District Court in Orlando considered an “Emergency Motion” for spoliation sanctions against the defendant, City of Orlando, for alleged destruction of pornographic emails on police department computers. Floeter v. City of Orlando,2007 WL 486633 (M.D. F. Feb. 9. 2007). This is a sexual harassment and retaliation case where the plaintiff, a male undercover drug agent for the Orlando Police Department, complained about his female supervisor’s sexual advances, including viewing of x-rated emails on police department computers. Plaintiff complained, and was then, in his words, “disciplined and stripped of his job responsibilities.”

... The Administrator reported, however, that key hard drives could not be searched for various reasons, including an alleged hard drive crash and a re-imaging of another key hard drive after an upgrade to a new laptop. The re-imaging of the old drive made it forensically impossible to search for deleted or slack files. The re-imaging was standard procedure for a new computer replacement. The Magistrate who heard the testimony concerning these facts found the timing of the request for a new computer, resulting as it did in the complete destruction of all deleted data on the old computer, to be “certainly suspicious.”

The backup tapes the Administrator searched were also porn free as to these individuals. However, by the time of the search these tapes only went back to October 2005, seven months after suit was filed. This is because the City recycles its tapes every three months. Remarkably, the Court reports that:

There is no evidence that in-house nor outside counsel for the City ever issued a directive requiring that information which might be relevant to the issues in the case be preserved.



In a related story...

http://www.mcall.com/news/local/allentown/all-b1_5heller-r.5826818may01,0,2076526.story?coll=all-newslocalallentown-hed

Trooper posted explicit photos of ex

Pleads guilty to harassment for placing images on sex site. He will quit the state police.

By Debbie Garlicki Of The Morning Call May 1, 2007

A state trooper who posted photographs of his former wife nude on a bondage and sadomasochistic Web site pleaded guilty Monday to harassment, a misdemeanor.

As part of the plea agreement, Luke J. Heller, 37, will resign from the state police on or before his sentencing date, June 18.

Heller, who worked for the state police for 14 years, was suspended without pay after authorities accused him of putting his ex-wife's photographs, occupation and date of birth on the site. It also contained a solicitation for people to contact her to engage in violent sexual acts.

... In January, Steinberg dismissed two felony charges -- unlawful use of a computer and criminal use of a communication facility -- after ruling that the statutes on those charges didn't apply to the evidence in the case.



It used to be that the aristocracy had servants who were so well trained they could do this without us noticing. Perhaps we want to return to that era – sans people.

http://yro.slashdot.org/article.pl?sid=07/04/30/2018232&from=rss

Buildings Could Save Energy By Spying On Workers

Posted by ScuttleMonkey on Monday April 30, @06:07PM from the tracking-everyone-driving-down-that-particular-sidewalk dept. Privacy Science

Galactic_grub writes "In the future, your place of work (or apartment) may very well spy on you. But that doesn't mean it'll be able to name and shame you for all your nasty habits. Researchers at Mitsubishi Electric Research Laboratory (MERL) have devised a 'dumb' surveillance system that monitors the movements of workers without identifying them individually. The idea is to have a computer system automatically configure the air-conditioning to save money, or illuminate the most appropriate escape signs in an emergency."



e-Discovery statistics...

http://www.eweek.com/article2/0,1759,2123982,00.asp?kc=EWRSS03119TX1K0000594

Report: E-Mail Archiving Becoming a Must

April 30, 2007 By Chris Preimesberger

Only about 14 percent of all corporate e-mail accounts are currently being backed up and archived for future access, but that number is going to shoot up to nearly 70 percent by the year 2011, according to a new storage industry study.

... People are sending and receiving more—and digitally heavier—e-mails now as opposed to past years, the study says. According to Radicati's research, in 2007 a typical corporate account generates about 18MB of mail and attachments per business day, or about 4.3GB of electronic data per user/per year.

This number is expected to grow to over 28MB per day (or 6.7GB per year) by 2011, Radicati said.

"Without an archiving record of all relevant messages, regulated companies can be heavily penalized," said Sara Radicati, president and CEO of The Radicati Group.

"Today, there is no good alternative to an interactive archiving solution to help companies properly store electronic messages."

This has been borne out in recent weeks in the ongoing Intel-AMD antitrust lawsuit, in which Intel was unable to come up with some 1,000 e-mails judged to be in evidence by the federal court.

... "Instant messaging is especially popular in the banking and securities industries," Radicati told eWEEK. "It's standard now to make trading deals via instant message. And companies certainly want to keep all those communications."

... The study, "E-Mail Archiving Market, 2007-2011," provides market size, four-year forecasts and regional breakouts. It also discusses legislative and technology issues of the archiving market and provides an analysis of the leading archiving vendors and service providers, Radicati said.

To order a copy of the study, visit the Radicati Web site here.




Die, DRM die?

http://apple.slashdot.org/article.pl?sid=07/04/30/2225246&from=rss

Apple To Grant All Labels DRM-Free Distribution

Posted by kdawson on Monday April 30, @07:06PM from the you-asked-for-it dept. Music Encryption Media (Apple) Apple

SexCaptain writes "MacRumors.com reveals a letter circulated by Apple to all producers of content for the iTunes Store, announcing that from May onward they can sell their music at higher quality and free of DRM. Hopefully this opens the doors for labels like Netwerk. This is a big step in the right direction, although it's unclear exactly what Apple means by 'higher quality,' and there is no mention of price changes. (Apple charges $0.30 more per song for DRM-free content from EMI and encodes it at 256K.) Quoting from the letter: 'Many of you have reached out to iTunes to find out how you can make your songs available higher quality and DRM-free," Apple wrote in the communication. "Starting next month, iTunes will begin offering higher-quality, DRM-free music and DRM-free music videos to all customers."



Checking for clients or companies you deal with might be a good idea! (sic the Class Action lawyers on them?)

http://it.slashdot.org/article.pl?sid=07/04/30/2340255&from=rss

Exposing Bots In Big Companies

Posted by kdawson on Monday April 30, @10:24PM from the pwned dept.

CalicoPenny let us know about yet another "30 days" effort, this one to name the names of major companies infected with spam-spewing bots. Support Intelligence began the effort on March 28, out of frustration at not being able to attract the attention of anyone who could fix the problems at these companies. While they haven't named 30 companies over the ensuing month, they did name some prominent ones, such as Thompson Financial, Bank of America, and AIG. The scary part is that if a bot can spam it can capture keystrokes or troll for interesting documents.



Strategy? More like Panic.

http://yro.slashdot.org/article.pl?sid=07/05/01/0246241&from=rss

SCO Wanted To Gag Torvalds, Moglen

Posted by kdawson on Tuesday May 01, @02:14AM from the can't-say-that dept.

An anonymous reader passes on word of court documents filed by IBM on Friday. The documents contain a copy of a letter, dated 2004, from SCO to IBM's lawyers stating that they tried to keep Linus Torvalds from making disparaging public statements about SCO, speculating erroneously that IBM was the principal funder of OSDL, where Torvalds worked at the time. Quoting: "The company also tried to silence Eben Moglen, the Columbia University professor who, until this month, was a director of the Free Software Foundation, and Eric Raymond, a controversial open-source advocate, saying they claimed to be IBM consultants."

Monday, April 30, 2007

Again data is lost by a contractor. I wonder what remedy is in the contract.

http://www.koat.com/news/13217242/detail.html

UNM Employee Information Stolen

Laptop Taken In California

POSTED: 6:49 pm MDT April 28, 2007 UPDATED: 6:56 pm MDT April 28, 2007

University of New Mexico officials said personal information for 3,000 employees may have been stored on a laptop computer that was stolen.

The university notified the employees by e-mail that some personal information may have been on a laptop taken Wednesday from a San Francisco office.

University officials learned of the theft Friday from an outside consultant working on UNM's human resource and payroll systems.

The university says the laptop is believed to have names, e-mail and home addresses, UNM ID numbers and net pay for a pay period for staff, faculty and a few graduate students.

University officials said they don't believe there's any significant risk of identity theft. Officials with the school said that without passwords, ID numbers can't be used to access university systems.



Purchasing the tool isn't quite as useful as actually using the tool... However it does suggest you knew what you should have been doing!

http://computerworld.co.nz/news.nsf/news/4F82B863EF709A05CC2572C90081FFCC

IRD laptops were not encrypted

Spokeswoman says that the department is "considering implementing this improved encryption capability", indicating it has not already done so

By Randal Jackson, Auckland | Monday, 30 April, 2007

Inland Revenue laptops, some of which are expected to be among 106 computers that could not be accounted for in a department asset check, are not encrypted to protect any data they might contain.

An Inland Revenue spokeswoman says Hewlett-Packard provides the department’s laptops and these contain TPM (Trusted Platform Module) functionality. However, she adds the department is “currently considering implementing this improved encryption capability”, indicating it has not already done so. [Are they also considering such advanced features as email and word processing? Bob]

TPM is a specification for storing secured information, including the secure generation of cryptographic keys.

The spokeswoman says Inland Revenue does have levels of security around its notebook computers.

This includes power-on BIOS password and layers of authentication to protect access to sensitive information,” she says. “Our policy is not to store taxpayer information on local drives.”



Anyone like to co-author “The Decline and Fall of e-British e-Empire?

http://news.independent.co.uk/uk/this_britain/article2494230.ece

Britain becoming a Big Brother society, says data watchdog

By Sophie Goodchild Published: 29 April 2007

Britain is in danger of "committing slow social suicide" as such Big Brother techniques as surveillance cameras and recording equipment spread into every aspect of our lives, the nation's information watchdog will warn this week.

A new report from Richard Thomas, the information commissioner, will say that the public needs to be made more aware of the "creeping encroachment" on civil liberties created by email monitoring, CCTV and computer tracking of our buying habits.

... He will also call for greater regulation of companies that supply surveillance technology which provides "convenience or safety for the more affluent majority", but not for the vulnerable such as children, immigrants and the elderly. [England for the upper-class! Bob]]



Progress?

http://www.mondaq.com/article.asp?articleid=47798&searchresults=1

New Zealand: The Tort Of Privacy

29 April 2007 Article by Grant Slevin

In this article, Grant Slevin, a solicitor with Wynn Williams & Co, advises that the New Zealand Court of Appeal has recently indicated that it is now possible to sue publishers in tort for breaches of privacy.

In past years there have been sporadic instances in which orders have been made to prevent the publication of private...



Always something useful

http://www.bespacific.com/mt/archives/014708.html

April 29, 2007

New on LLRX.com for April 2007



Imagine that – the facts are not as important as making people feel good?

http://techdirt.com/articles/20070427/022155.shtml

Gowers Admits That Evidence Suggests UK Should Shorten Copyright Length, Not Extend It

from the could-have-mentioned-that-earlier dept

Late last year in the UK the infamous "Gowers Report" on intellectual property was issued, while it recommended not extending copyright terms on performances, some of us felt that the report was too balanced for its own good. Gowers seemed to go out of his way to make sure the report gave a little to everyone -- and therefore basically gave nothing to anyone. Rather than looking at the fundamental issues, it just tried to give a little bit here to one side and a little bit there to another. Of course, the copyright term extension got the most attention -- with supporters of term extension mistakenly thinking that copyright is a welfare system to perpetually support musicians rather than an incentive system for the creation of new content. Now that the report is all published and done with, apparently Andrew Gowers is willing to admit that when they did their actual research and investigation, they found that the economic evidence supported making copyright terms even shorter than the existing 50 years. However, recognizing that decreasing the length would have created howls of outrage from the industry that still thought it had a chance for extending the term, he simply recommended leaving it alone. Of course, it should come as no surprise to those of us around here that the economic evidence would suggest society is better off with shorter copyright terms -- but it's disappointing that Gowers had to wait until well after the report was released to even make that basic point. At least it's one more hole in the myth that longer copyrights must be good for society. The entire interview makes for an interesting read, though (as fits with his report) Gowers keeps focusing on the importance of "balance" between two opposing extremes, as if they're competing. At some point it would be nice for people to realize that there are solutions where everyone can benefit.



What do you men, “La la la le la” isn't a lyric?

http://lyricwiki.org/Main_Page

LyricWiki.org

LyricWiki is a free site which is a source where anyone can go to get reliable lyrics for any song from any artist without being hammered by invasive ads.

Sunday, April 29, 2007

What has to happen before people get the word? It also seems that no one wants to find anything criminal in this.

http://www.journal-advocate.com/articles/2007/04/27/news/local_news/local1.txt

Dr. admits dumping medical files

By AJ Vicens Journal-Advocate Staff Writer Friday, April 27, 2007 2:51 PM MDT

STERLING — In 1998, June Davis, of Boulder, visited an area chiropractor for some routine work. She only saw him a few times, and said she probably couldn’t even remember his name any more.

Those few chiropractic visits came back to give Davis “goose bumps” nine years later when she found out that the complete record of her consultations with that chiropractor was one of hundreds thrown in a Dumpster near a Sterling 7-Eleven full of her private medical and personal identification information.

... The hundreds of medical records found in a Dumpster behind the 7-Eleven came from Healing Hands Chiropractic on West Third Avenue and, for now, there are no plans for criminal charges associated with the way the records were disposed of, according to the Sterling Police Department.

Sterling Sgt. Tyson Kerr said an investigation revealed that the records were dumped by Dr. John Sommers, who runs Healing Hands Chiropractic, “due to lack of office space.”

Sommers said in an interview Tuesday he did put the records — complete with patients’ social security numbers, birth dates, addresses and, in some cases, credit card information — in the Dumpster because all of his client’s records are electronic and he didn’t have space in the office for the old paper records that came with the purchase of the business.

You’re not supposed to do what I did,” Sommers said. “That’s for sure. I was trying to get away with dumping it in the Dumpster, and figured it would end up at a trash dump the next day and nobody could get it.”



What would an imminent civil war/genocide/angry mob/Russian invasion look like online? (f-secure points to many sites...)

http://www.f-secure.com/weblog/#00001181

Saturday, April 28, 2007

Unrest in Estonia

Posted by Mikko @ 13:51 GMT

For the past days, there's been unrest and rioting in Estonia.

Quoting CNN: "Police arrested 600 people and 96 were injured in a second night of clashes in Estonia's capital over the removal of a disputed World War Two Red Army monument ... Russia has reacted furiously to the moving of the monument ... Estonia has said the monument had become a public order menace as a focus for Estonian and Russian nationalists."

We're now seeing large attacks against websites run by Estonian goverment. Some of the sites are unreachable. Others are up, but do not allow any traffic from foreign IP addresses.



What would happen if you had thousands of computer experts on your legal team? Is this a strategy that could/should be used more broadly?

http://yro.slashdot.org/article.pl?sid=07/04/28/202206&from=rss

RIAA Security Expert's Quest For Reliability

Posted by Zonk on Saturday April 28, @06:46PM from the is-he-who-he-says-he-is dept.

NewYorkCountryLawyer writes "In the ongoing case of UMG v. Lindor, Ms. Lindor has now moved to exclude the trial testimony of the RIAA's 'expert' witness, Dr. Doug Jacobson. Jacobson is the CTO and co-founder of Palisade Systems, Inc, and a teacher of internet security at Iowa State, but in his February 23rd deposition testimony she argues he failed to meet the reliability standards prescribed by Daubert v. Merrell Dow Pharmaceuticals, Inc. and Federal Rule of Evidence 702. The Groklaw and Slashdot communities participated in both the preparation of the deposition questions, and the vetting of the witness's responses."



Strategically, one should try for every possible advantage.

http://yro.slashdot.org/article.pl?sid=07/04/27/1439245&from=rss

RIAA Secretly Tries to Get ISP Subscriber Info

Posted by Zonk on Friday April 27, @11:53AM from the always-with-the-plotting-and-planning-are-they dept. Privacy The Courts

NewYorkCountryLawyer writes "In an attempt to change the rules of the game, the RIAA secretly went to a federal district court in Denver with an ex parte application. The goal was to get the judge to rule that the federal Cable Communications Policy Act does not apply to the RIAA's attempts to get subscriber information (pdf) from cable companies. Just to clarify, ex parte means that the application was secret, no one else — neither the ISP nor the subscribers — were given notice that this was going on. They were, in effect, asking the Court to rule that the RIAA does not need to get a court order to be able to force an ISP to disclose confidential subscriber information. The Magistrate Judge declined to rule on the issue (pdf), but did give them the ex parte discovery order they were looking for."



What happens in Vegas, stays in Vegas. What happens online gets distributed world-wide forever... Raises interesting questions, doesn't it?

http://hosted.ap.org/dynamic/stories/B/BRF_MYSPACE_PHOTO_GRADUATION?SITE=VALYD&SECTION=HOME&TEMPLATE=DEFAULT

Apr 28, 5:45 PM EDT

School Sued Over MySpace Photo Response

MILLERSVILLE, Pa. (AP) -- A woman denied a teaching degree on the eve of graduation because of a MySpace photo has sued the university.

Millersville University instead granted Stacy Snyder a degree in English last year after learning of her Web-published picture, which bore the caption "Drunken Pirate."

"I dreamed about being a teacher for a long time," said Snyder, 27, who now works as a nanny.

The photo, taken at a 2005 Halloween party, shows Snyder wearing a pirate hat while drinking from a plastic "Mr. Goodbar" cup. It was posted on her own MySpace site.

Although Snyder apologized, she learned the day before graduation that she would not be awarded an education degree or teaching certificate.

Jane S. Bray, dean of the School of Education, accused Snyder of promoting underage drinking, the suit states.

The federal lawsuit seeks at least $75,000 in damages. Millersville spokeswoman Janet Kacskos referred questions to a state System of Higher Education spokesman, who declined comment.



Always informative

http://www.schneier.com/blog/archives/2007/04/schneier_talk_a.html

April 28, 2007

Schneier Talk at the British Computer Society

The MP3 of my March 21 talk at the British Computer Society -- on information security trends and economic considerations -- is on the Internet.