Tuesday, January 08, 2008

When it is your business, you'd think you'd have a workable procedure... No indication the tape was encrypted. (People still use tapes?)

http://www.pogowasright.org/article.php?story=20080107105125443

Iron Mountain loses backup tape with GE Money-Americas clients' info

Monday, January 07 2008 @ 10:51 AM EST Contributed by: PrivacyNews News Section: Breaches

GE Money-Americas has notified the state of New Hampshire that its vendor, Iron Mountain, lost a backup tape containing active account numbers and some Social Security numbers. O ver 1800 NH residents had account numbers on the missing tape, and less than 20 appear to have SSN on the tape. There was no indication of total numbers nationwide.

Summary prepared by PogoWasRight.org based on Notification to NJ DOJ [pdf]



Not much of a manifesto... Not even a complete outline for a student paper – but it's a start!

http://www.pogowasright.org/article.php?story=20080108073905268

A Privacy Manifesto for the Web 2.0 Era

Tuesday, January 08 2008 @ 07:39 AM EST Contributed by: PrivacyNews News Section: Internet & Computers

Written by Alec Saunders, co-founder and CEO of iotum, creators of the first conference calling service for Facebook. Alec’s personal blog is about VoIP and web products, technologies and businesses.

[...]... Let’s start by defining what we mean by personal information. Personal information includes any factual or subjective information, recorded or not, in any form, about an individual. For example: name, address, telephone number, gender, identification numbers, income, blood type, credit records, loan records, existence of a dispute between a consumer and a merchant — even intentions to acquire particular goods or services. And let’s not forget health, medical history, political opinions, religious beliefs, trade union membership, financial information and sexual preferences!

Now, what rights should you have? Here are four principles that form a Privacy Manifesto for the Web 2.0 Era.

Source - gigacom



Warm & Fuzzy #1

http://it.slashdot.org/article.pl?sid=08/01/08/0154227&from=rss

Boot Record Rootkit Threatens Vista, XP, NT

Posted by kdawson on Monday January 07, @09:41PM from the writing-to-zero dept.

Paul sends us word on a new exploit seen in the wild that attacks Windows systems completely outside of the control of the OS. "Unfortunately, all the Windows NT family (including Vista) still have the same security flaw — MBR [Master Boot Record] can be modified from usermode. Nevertheless, MS blocked write-access to disk sectors from userland code on VISTA after the pagefile attack, however, the first sectors of disk are still unprotected... At the end of 2007 stealth MBR rootkit was discovered by MR Team members (thanks to Tammy & MJ) and it looks like this way of affecting NT systems could be more common in near future if MBR stays unprotected."



Warm & Fuzzy #2

http://www.pogowasright.org/article.php?story=20080107203646560

Hackers turn Cleveland into malware server

Monday, January 07 2008 @ 08:36 PM EST Contributed by: PrivacyNews News Section: Breaches

Tens of thousands of websites belonging to Fortune 500 corporations, state government agencies and schools have been infected with malicious code that attempts to engage in click fraud and steal online game credentials from people who visit the destinations, security researches say.

At time of writing, more than 94,000 URLs had been infected by the fast-moving exploit, which redirects users to the uc8010-dot-com domain, according to this search. Security company Computer Associates was infected at one point, as were sites belonging to the state of Virginia, the city of Cleveland and Boston University.

Source - The Register

[From the article:

He said the uc8010-dot-com domain (we don't recommend readers visit the site) was registered in late December using a Chinese-based registrar, indicating the attackers were fluent in Chinese.



An interesting interpretation. In the US, gathering (and organizing) the data should be enough for at least a Copyright... Right?

http://www.pogowasright.org/article.php?story=20080108071833645

UK: Database right infringed when staff took customer lists, rules court

Tuesday, January 08 2008 @ 07:18 AM EST Contributed by: PrivacyNews News Section: Breaches

Employees who left a company to start up a rival breached that firm's database rights when they took information with them, the High Court has ruled. The firm failed to prove, though, that the actions breached the company's confidentiality.

[...]Rider and Simpson did not dispute that they had taken a list of Crowson's customers and information about sales to them as well as email addresses from the company.

Crowson claimed that the pair broke an implied duty [Not worth the paper it's written on... Bob] not to remove confidential business information from it, but the High Court ruled that the information they had taken did not qualify as confidential.

For information to be confidential there needs to be an obligation of confidence, [We need that phrase! Bob] and the information must be confidential in nature. Judge Peter Smith said that material did not become confidential just because an employer deemed it so.

Smith said that the information was not confidential, that it was either in the public domain, as in the case of addresses and phone numbers, or it counted as the skills and expertise that an employee would naturally build up, and was therefore not able to be restricted by the employer.

Source - Out-Law.com



This must be at epidemic proportions to get the bank's attention.

http://www.pogowasright.org/article.php?story=20080107182643581

Citibank limits ATM withdrawals in New York City

Monday, January 07 2008 @ 06:26 PM EST Contributed by: PrivacyNews News Section: Breaches

In response to a series of ATM robberies over the holidays, Citibank has drastically reduced the daily amounts its customers may withdrawal from ATMs. In some cases, customers of Citibank could once withdrawal as much as $2000 per day, depending upon the account. The new limits are around $500 per day for most customers.

Citibank attributes the action to reports of "skimming," the process of copying someone's ATM card and passcode or PIN, over the holidays.

Source - C|net


Another hack....

http://www.pogowasright.org/article.php?story=20080108072330179

Dutch public transport card hacked

Tuesday, January 08 2008 @ 07:23 AM EST Contributed by: PrivacyNews News Section: Non-U.S. News

The security of the Dutch OV (public transport) card is at issue following the cracking of its secret code by German computer hackers.

The card, which is intended to replace the 'strippenkart', was due to be introduced throughout the country this year. It is likely that the launch will now be postponed. Because the card's code has been hacked, it would be possible for travellers to journey for free and for their private data to be made public.

Source - Radio Netherlands Worldwide


Another hack... (What happens when you attract bright people...)

http://www.pogowasright.org/article.php?story=2008010807254840

Harvard uncovers ID scam that may involve debit cards

Tuesday, January 08 2008 @ 07:25 AM EST Contributed by: PrivacyNews News Section: Breaches

Harvard University police and the Middlesex district attorney's office are investigating a security breach at the school after an undergraduate allegedly manufactured phony driver's licenses and university identification cards that can be used as debit cards and to enter residence halls, the university announced yesterday.

Source - Boston Globe


Perhaps a bunch of hacks?

http://www.news.com/8301-10789_3-9843574-57.html?part=rss&subj=news&tag=2547-1_3-0-5

Digital gifts that keep on giving

Posted by Robert Vamosi January 7, 2008 1:43 PM PST

Care should be taken when plugging holiday gift gadgets into your personal computer and laptop, said security researchers at Sans.org, Microsoft, and Kaspersky in recent blog posts. Reports of strange files being found on USB storage devices increased over the holiday season. Reporting Monday on the SANS' Internet Storm Center blog, director Marcus Sachs said, "In years past this would have been limited to iPods and USB memory sticks, but now it includes digital photo frames, GPS devices, external hard drives, and of course digital cameras."



Going forward... (Anyone who quotes Machiavelli is worth reading...)

http://www.bespacific.com/mt/archives/017072.html

January 07, 2008

UK Report: National Security for the Twenty-First Century

Current notions of defence, foreign affairs, intelligence and development are redundant in the new security environment... National Security for the Twenty-first Century, Charlie Edwards, DEMOS: "The government remains structured around functions and services with separate budgets for defence, foreign affairs, intelligence and development. Whitehall departments, intelligence agencies and the police forces that make up the security architecture have changed very little in the past two decades, despite the end of the Cold War and the attack on the World Trade Centre in 2001. Based on a 12 month research project, this pamphlet sets out an approach to national security drawing on reforms and innovations from governments elsewhere in Europe and the United States and suggests some new ideas designed to shape the future of the national security architecture."



“Hey, we gotta blame somebody!”

http://www.pogowasright.org/article.php?story=2008010718113116

(follow-up) Guard: Metro laptops were stolen before Christmas Eve

Monday, January 07 2008 @ 06:11 PM EST Contributed by: PrivacyNews News Section: Breaches

... Murphy insists that the break-in that may have compromised hundreds of thousands of Metro voters’ Social Security numbers didn’t occur on his watch. In fact, it didn’t occur on anyone’s watch, because no one was assigned to watch, he said.

“I would swear on a stack of Bibles, that window was broken out Saturday,” Murphy said, referring to Dec. 22.

Source - Tennessean.com



For my web site class...

http://www.killerstartups.com/Video-Music-Photo/VideoSpincom---Quick-and-Fast-Movie-Editing/

VideoSpin.com - Quick and Fast Movie Editing

In order to produce stunning videos, no matter how amateur, you’ll need a good video editor. Of the many that are out there, VideoSpin stands out for its streamlined yet powerful interface. It’s light weighing in at only 2.25MB. There are two main functions—editing and publishing. The former section is used for adding music and transitions, putting in texts and making snips here and there. The publishing section connects to the web and allows users to add their videos to video sites like Yahoo or Youtube. If you’re lacking inspiration, VideoSpin gives you expert tips along the way. The download is free.

http://www.videospin.com/



Wait till the Porn Industry see this!

http://slashdot.org/article.pl?sid=08/01/07/2112205&from=rss

Making 3D Models from Video Clips

Posted by ScuttleMonkey on Monday January 07, @05:24PM from the fun-toys dept.

BoingBoing is covering an interesting piece of software called VideoTrace that allows you to easily create 3D models from the images in video clips. "The user interacts with VideoTrace by tracing the shape of the object to be modeled over one or more frames of the video. By interpreting the sketch drawn by the user in light of 3D information obtained from computer vision techniques, a small number of simple 2D interactions can be used to generate a realistic 3D model."



Chaos indeed. Perhaps the Colorado election commission can learn a lesson? Nah...

http://yro.slashdot.org/article.pl?sid=08/01/08/0218259&from=rss

Group Sues To Stop German E-Voting

Posted by kdawson on Monday January 07, @11:18PM from the we-don't-trust-them-either dept. The Courts Politics

kRemit writes "The German hacker group Chaos Computer Club today sued the German State of Hessen to prevent the use of electronic voting machines (Google translation) in the upcoming elections on January 27. This comes as a follow-up to the Dutch initiative 'We don't trust voting machines,' which succeeded in banning the same type of voting machines in the Netherlands."



I'll have to read this closely to see what I did...

http://www.bespacific.com/mt/archives/017065.html

January 07, 2008

Spartans in Darkness: American SIGINT and the Indochina War

Via Secrecy News, "this 2002 study was released in response to a Mandatory Declassification Review request filed by Michael Ravnitzky": Spartans in Darkness: American SIGINT and the Indochina War, 1945-1975 by Robert J. Hanyok, Center for Cryptologic History, National Security Agency, 2002.



Ancient history, modern technology?

http://www.reuters.com/article/technologyNews/idUSPAR75722620080107

Thousands follow soldier's fate in WW1 "blog"

Mon Jan 7, 2008 11:31am EST By Mike Collett-White

LONDON (Reuters) - Thousands of people have been following the fate of a British soldier fighting in the trenches of World War One on a Web site publishing his letters home exactly 90 years after they were written.



How to look smart...

http://digg.com/educational/How_To_Solve_a_Rubik_s_Cube_13

How To Solve a Rubik's Cube

howtodothings.com — Great beginners guide to solving the Rubik's Cube. Has step by step instruction with animation and images. Now you can solve any old cube laying around and impress your friends.

http://www.howtodothings.com/hobbies/how-to-solve-a-rubiks-cube

Monday, January 07, 2008

A dare is a dare – hacker love dares...

http://www.pogowasright.org/article.php?story=20080107044131596

UK: Clarkson U-turn over identity theft

Monday, January 07 2008 @ 06:21 AM EST Contributed by: PrivacyNews News Section: Breaches

Jeremy Clarkson has admitted he was wrong to brand the scandal of lost CDs containing the personal data of millions of Britons as a "storm in a teacup" - after himself falling victim to a scam.

The Top Gear presenter and self-proclaimed voice of reason printed his own bank details in a newspaper to hammer home the point that his money was still safe and the spectre of identity theft a sham. He also gave instructions on how to find his address on the electoral roll and details about the car he drives.

However, in a rare moment of humility, Clarkson has now revealed he has lost at least £500 - after an unidentified reader copied his details to set up a £500 direct debit payable from his account to the British Diabetic Association. The charity is one of many organisations which does not need a signature to set up a direct debit. [Kinda makes it easy, don't it. Bob]

Source - Sunderland Echo



http://www.pogowasright.org/article.php?story=20080107033351151

The Major Verdict in a Recent Identify Theft Case: How It Underlines the Risk for Financial Reporting Companies

Monday, January 07 2008 @ 06:24 AM EST
Contributed by: PrivacyNews
News Section: In the Courts

The U.S. Court of Appeals for the Fourth Circuit recently upheld a sizable verdict against a credit agency for failing to promptly and efficiently aid a victim of identity theft. The decision in Sloane v. Equifax Information Services does not break new doctrinal ground. It does, however, underscore how identity theft could become a headache not only for individual consumers, but large financial reporting companies. The case also highlights the difficulty of determining non-economic damages in cases involving consumer activities.

Source - FindLaw's Writ



http://www.pogowasright.org/article.php?story=20080106015228107

ANNOUNCE: Health-related privacy breaches analysis update

Sunday, January 06 2008 @ 12:22 PM EST Contributed by: PrivacyNews News Section: Breaches

The on-site Medical Privacy Project analysis of health- or patient-related breaches has been updated to incorporate incidents reported in the media during 2007. Some of the major findings include:

  • The number of patient-related or health-related incidents reported in the media increased in 2007

  • Of the 354 incidents analyzed for this report, 55 (16%) resulted in fraud or ID theft

  • 80% of incidents that resulted in misuse of the data were attributable to employees who stole or improperly accessed patient or health-related information

Source - Medical Privacy at Risk: Privacy and Security Breaches [pdf] Updated January 2008.



...because.

http://www.pogowasright.org/article.php?story=20080107020425258

Data “Dysprotection:” breaches reported last week

Monday, January 07 2008 @ 06:20 AM EST Contributed by: PrivacyNews News Section: Breaches

A recap of incidents or privacy breaches reported last week for those who enjoy shaking their head and muttering to themselves with their morning coffee.

Source - Chronicles of Dissent



The dangers of technology?

http://techdirt.com/articles/20080103/012656.shtml

National Motorists Association Challenges Cities To Prove Red-Light Cameras Are Safer

from the put-up-or-shut-up dept

Over the years, we've had a number of posts about studies showing that red-light cameras tend to increase the number of accidents, even as cities that install them claim that they're doing so for safety reasons. The problem appears to be that red-light cameras cause more people to slam on the brakes at the last second, leading to more rear-ender collisions. Plenty of studies have shown that if you really want safer intersections, the solution is rather simple: increase the length of time for yellow lights and include a pause after a light turns red before the cross-traffic signal turns green. Some cities already do this, but many do not. A big part of the problem is that red-light cameras are big money makers for municipalities, who share the revenue with the makers of the cameras -- who have every incentive in the world to set the traffic lights to encourage more violations, rather than fewer. To give proof to the lie that municipalities are installing red-light cameras for safety reasons, the National Motorists Association is now offering $10,000 to cities (found via The Agitator) if it can't reduce by 50% the number of red-light violations using regular traffic engineering. They're only looking to do this at camera-enforced intersections that still have high numbers of violations. Of course, if the NMA can show such a reduction, the city would then be required to remove its red-light camera systems. What are the chances any city takes the NMA up on this challenge?



Online is good, but nothing feels like a good comic book...

http://slashdot.org/article.pl?sid=08/01/07/016217&from=rss

Online Cartoonist Finds Financial Success Offline

Posted by Zonk on Sunday January 06, @10:32PM from the that's-a-lot-of-comic dept. Books The Almighty Buck The Internet

destinyland writes "The first collection of Perry Bible Fellowship comics has racked up pre-sales of $300,000 due to its huge online following. Within seven weeks the volume required a third printing. Ironically, the 25-year-old cartoonist speculates people would rather read his arty comics in a book than on a computer screen, and warns that 'There's something wonderful, and soon-to-be mythic, about the printed page...' He also explains the strange anti-censorship crusade in high school that earned him an FBI record!"

Sunday, January 06, 2008

This didn't take long!

http://www.pogowasright.org/article.php?story=2008010523553669

Class Action Suit Alleges Sears Privacy Failures

Saturday, January 05 2008 @ 11:55 PM EST Contributed by: PrivacyNews News Section: Breaches

Class-action lawyers are circling around retailer Sears, Roebuck & Co., just days after privacy activists revealed that the company's Web site exposed the details of customer purchases going back more than a decade.

In a complaint filed Friday in Cook County, Illinois -- where Sears is headquartered -- the plaintiffs allege that the lack of privacy protections at Sears's managemyhome.com site violated its own privacy promises to consumers, and in so doing ran afoul of the Illinois Consumer Fraud Act, which prohibits "unfair and deceptive practices."

Source - Security Fix

Related - Complaint [pdf]



The device was encrypted, Good! The device was not locked up, Bad.

http://www.pogowasright.org/article.php?story=20080105085127516

Identity info stolen from NMSU, but personnel data on laptop hard drive is inaccessible, university says

Saturday, January 05 2008 @ 08:51 AM EST Contributed by: PrivacyNews News Section: Breaches

LAS CRUCES — A computer hard drive containing the names and Social Security numbers of current and former NMSU employees is missing from the Pan American Center, just the latest in a series of thefts from the facility since November 2006, according to police reports.

... The external hard drive was stolen sometime between Dec. 30 and Jan. 2 from an office at the NMSU Special Events Department, housed at the Pan Am. It contained the names and Social Security numbers of every employee hired by the department since 1999, according to a university police report. The hard drive was used as a backup to an employee's computer.

Source - Las Cruces Sun-News

[From the article:

A former acting director of special events at the Pan Am called campus police on Aug. 3 about a series of thefts that began in the fall of 2006. [Not very timely... Bob] The incidents included two thefts of cash totaling $5,000, plasma televisions, watches, 200 feet of electrical cable, a floor buffer and a digital camera. [Must be a great neighborhood. Bob]



Tools & Techniques for Hackers: Don't you love those Flight Simulator games?

http://www.wired.com/politics/security/news/2008/01/dreamliner_security

FAA: Boeing's New 787 May Be Vulnerable to Hacker Attack

By Kim Zetter Email 01.04.08 | 7:30 PM

... The computer network in the Dreamliner's passenger compartment, designed to give passengers in-flight internet access, is connected to the plane's control, navigation and communication systems, an FAA report reveals.


Related

http://www.bespacific.com/mt/archives/017051.html

January 06, 2008

FAA Issues Special New Security Regs for Boeing Model 787-8



How rude...

http://www.pogowasright.org/article.php?story=20080105084547272

EU Commission insists on enforcing data retention

Saturday, January 05 2008 @ 08:45 AM EST Contributed by: PrivacyNews News Section: Non-U.S. News

The EU commission has officially put 19 member states on notice for failing to pass national laws implementing controversial EU regulations governing retention of telephone and Internet data. According to the dpa, the commission announced today that only eight of the 27 EU countries had passed such laws and reported back to Brussels.

Source - Heise Online



How employees burn corporate resources. (And we should probably take advantage of it.)

http://slashdot.org/article.pl?sid=08/01/06/0356213&from=rss

'Video Snacking' New Frontier For Media Creators

Posted by Zonk on Saturday January 05, @10:56PM from the digital-doritos dept.

News.com has up a piece from the NYT about the concept of 'video snacking', a new focus for media companies as they gain a certain savvy about the internet. They're increasingly targeting the 'lunch market' for office workers, creating short to-the-point videos that can be consumed over a sandwich. "The midday spike in Web traffic is not a new phenomenon, but media companies have started responding in a meaningful way over the last year. They are creating new shows, timing the posts to coincide with hunger pangs. And they are rejiggering the way they sell advertising online, recognizing that noontime programs can command a premium. In 2007, a growing number of local television stations, including WNCN in Raleigh, N.C., and WCMH in Columbus, Ohio, began producing noon programming exclusively for the Web."



Me to neighbor's kid: “Hey Ralphy! How would you like to trade in that drum set you got for Christmas for a really cool guitar! ...and $50 bucks?”

http://www.killerstartups.com/Video-Music-Photo/Video-tabscom---The-new-way-to-learn-guitar/

Video-tabs.com - The new way to learn guitar

Video-tabs.com is a site that aggregates videos from different sites (mainly YouTube) that teach how to play guitar of all types, styles and level of ability. The site includes a comprehensive database of tabs (music sheets) which are easy to print out and read in order to play the music you are learning. The site can be browsed in different ways: Skills Lessons, Video Song Lessons, Cool Guitar Videos and Chord Lessons. Also, take a look at the most popular videos to check out where other users have been learning their stuff from. The site also permits RSS feeds subscription.

http://video-tabs.com/



Very cool.

http://digg.com/gadgets/DVD_Laser_Labeling_System_2

DVD Laser Labeling System watch!

metacafe.com — Now you can use this New and Great Technology to burn cool tittles and pictures on the label side of your DVD disks.

http://www.metacafe.com/watch/911046/dvd_laser_labeling_system/



Just a shameless plug for Colorado Tech...

FORENSIC INVESTIGATION OPEN HOUSE

Saturday, January 12, 2007

10:00 AM - 2:00 PM, both campuses

Hosted in conjunction with the Lakewood Police Department and Aurora Police Department to promote the new Forensic Investigation concentration degree!

Saturday, January 05, 2008

You must involve someone outside the Marketing Department...

http://www.benedelman.org/news/010408-1.html

Sears Exposes Customer Purchase History in Violation of Its Privacy Policy

January 4, 2008

Want to know what a given customer has purchased from Sears? It's surprisingly easy to find out. Here's the procedure:

1) Go to the Sears "Manage My Home" site, www.managemyhome.com . Create an account and sign in. Screenshot.

2) On the Home menu, choose Home Profile. In the Search Purchase History section, choose Find Your Products. Screenshot.

3) Enter the name, phone number, and street address of the customer whose purchases you wish to view. Press Find Products. Screenshot.

Sears then displays all purchases its database associates with the specific customer -- typically major appliances and other large purchases. See examples from Washington, DC, Brookline, Massachusetts, and Lincoln, Massachusetts.



Stirring up some interesting comments. Likely some certification will be required...

http://it.slashdot.org/article.pl?sid=08/01/04/2244227&from=rss

PI License May Soon Be Required for Computer Forensics

Posted by ScuttleMonkey on Friday January 04, @08:22PM from the geeks-licensed-to-buy-cool-surveillance-gear dept. Security IT

buzzardsbay writes "The good folks over at Baseline Magazine have an intriguing — and worrisome — report on a movement to limit computer forensics work to those who have a Private Investigator license or those who work for licensed PI agencies. According to the story, pending legislation would limit the specialized task of probing deep into computer hard drives, network and server logs for telltale signs of hacking and data theft to the same people who advertise in the Yellow Pages for surveillance on cheating spouses, workers' compensation fraud and missing persons. Those caught practicing computer forensics without a license could face criminal prosecution."



For the IP crowd

http://www.eff.org/deeplinks/2008/01/new-study-copyright-and-creativity-center-social-media

New Study on Copyright and Creativity from the Center for Social Media

Posted by Hugh Dandrade January 3rd, 2008

Free video hosting sites like YouTube, Yahoo! Video, and Daily Motion are enabling creators to share video instantly with millions of viewers around the world. A new report from the Center for Social Media takes a close look at these user generated sites, and finds that there is much more at stake than the SNL and Daily Show clips often referenced in the usual Viacom v. YouTube debates on copyright infringement.

... (EFF has published a “best practices” guide that would protect fair uses from being caught in DMCA takedown dragnets.)


...and an interesting business model.

http://techdirt.com/articles/20080102/100856.shtml

Content Industry Could Learn From eBay Seller Turning A Profit With Public Domain Content

from the competing-with-free dept

Last year, Mike made the point that saying you can't compete with free is saying you can't compete, period. Every business makes a profit by adding value so that customers will be willing to pay above marginal cost for its products. The fact that the marginal cost of content (once it's been created) is zero doesn't change that principle. You can add value to free content just like you can add value to any other product. The New York Times Bits blog nicely illustrates this with a post about the market for public domain content on eBay. Apparently, there are a number of people who make a living by finding obscure, copyright-free content on the Internet, burning it on a DVD or other convenient format, and selling it on eBay. Despite the fact that every one of those customers could have tracked down the video for themselves and watched it on their computers, a lot of people are apparently willing to pay for a DVD version.

This business model actually illustrates two good ways to add value to free content. First is convenience. A lot of people don't have a high-speed Internet connection, don't like watching videos on their computer monitors, or want to be able to take their content with them in a compact format. For those users, a DVD is a much nicer format than a file on their computer's hard drive. DVDs are also a much more convenient format for giving gifts: you can wrap a DVD and put it under the Christmas tree, something that's harder to do with a video on YouTube. Second is filtering and organization. There's way more content out there than any one person could possibly watch. So there's a lot of value in helping people separate the wheat from the chaff. That's a big part of the value we provide here at Techdirt: a lot of the information you'll find on our blog comes from other sites, but we try to highlight only the best and most relevant information, helping our readers to keep up with news in the technology world more easily. By the same token, people who sell public domain content on the Internet create value by filtering and organizing the information so it's easier for others to quickly and easily find what they're looking for.

I won't belabor the implications for traditional content industries. Like it or not, their content is available for free on peer-to-peer sites, and if they want to make a profit they're going to have to find ways to make their content more valuable than what you can get with BitTorrent. Two important principles for doing that are: use formats that convenient and versatile and make sure content is organized in a way that makes it easy for users to find what they're looking for. That means, for example, that you probably shouldn't cripple your products with DRM or sue companies that help people find your content.



For my Web Site class...

http://www.killerstartups.com/Web-App-Tools/WhatsItsColorcom---The-Complementary-Color-Finder/

WhatsItsColor.com - The Complementary Color Finder

If you’re the type of person who thinks red and green are a good color combination outside of Christmas, or find yellow and pink appealing, then you might want to consider Whats Its Color, a free web app that finds complementary colors for any image you provide. Just upload an image or find one on the web. What Its Color will process and break down the colors in the image you’ve selected, and then evaluate the image’s primary and complementary colors. It’ll also give you the image’s top ten unique colors. With the color palette provided, you can create a killer web design, or spruce up that power point presentation.

http://whatsitscolor.com/

Friday, January 04, 2008

These are not the words of a reasonably competent manager...

http://www.pogowasright.org/article.php?story=20080104063400680

Day-care workers face risk of ID theft, DCF says

Friday, January 04 2008 @ 06:34 AM EST Contributed by: PrivacyNews News Section: Breaches

Thousands of Central Florida day-care-center workers could be at risk of identity theft after burglars stole state computers containing personal information.

Although the theft occurred two months ago, the Florida Department of Children and Families is just now notifying about 1,200 day-care providers that their employees, as well as center operations, may be at risk.

Social Security numbers, birth dates and other information about day-care workers in Orange, Seminole and Osceola counties were among the data on five laptop computers that were stolen from the DCF office near Orlando Fashion Square mall in Orlando on Nov. 7-8.

Source - OrlandoSentinel.com

[From the article:

Officials said they don't know how many day-care employees' records were on the stolen computers.



Why would this program be any different?

http://www.bespacific.com/mt/archives/017015.html

January 03, 2008

DHS OIG Audit of the State of Colorado Homeland Security Grant Program

OIG-08-16 - Audit of the State of Colorado Homeland Security Grant Program (PDF, 35 pages) - New 01/03/2008

  • "...Colorado has not complied with critical Homeland Security Grant Program requirements, as the state has not assured adequate oversight of program activities and compliance with its homeland security strategy. In addition, the state’s internal controls for managing homeland security grant programs, and ensuring sub-grantee compliance and program readiness were ineffective."



Interesting, but would we care if the “Security Ignorati” get crashed?

http://www.infoworld.com/article/08/01/04/Wi-Fi-virus-outbreak-possible-researchers-say_1.html?source=rss&url=http://www.infoworld.com/article/08/01/04/Wi-Fi-virus-outbreak-possible-researchers-say_1.html

Wi-Fi virus outbreak is possible, researchers say

By targeting unsecured wireless routers, criminals could create an attack that could piggyback across thousands of Wi-Fi networks in urban areas

By Robert McMillan, IDG News Service January 04, 2008

If criminals were to target unsecured wireless routers, they could create an attack that could piggyback across thousands of Wi-Fi networks in urban areas like Chicago or New York City, according to researchers at Indiana University.



Ask your techies to make one for you! Beside the e-discovery implications, this is quite useful for those of us who teach at several locations – we can take our “teaching computer” with us.

http://www.baselinemag.com/article2/0,1397,2243255,00.asp?kc=BARSS02129TX1K0000533

Virtual PCs Add New Layer of Security

January 3, 2008

BOSTON (Reuters) - Worried about people accessing your private information whenever you use a public computer?

There is a way to protect yourself: Devices as small as a keychain allow you to use any computer without leaving a trail of evidence.

A new computer program known as MojoPac can turn most flash memory sticks, hard drives or iPods into "virtual" PCs that can run most programs that work on Windows XP.

... The device cannot be bought. You have to make it by downloading free software onto a computer drive such as the thumb-sized USB flash memory drives that were so popular as gifts this Christmas. It also works with iPods, many other digital music players and regular external hard drives.

Once the MojoPac shell is created, users need to install their own software -- just as they would do on a regular PC running Windows XP.

... Other companies are working on similar technology, but there's nothing available with free software that is as easy to set up as MojoPac, according to Enderle.

... MojoPac is available for free on the company's Web site, www.MojoPac.com.

For now it only works with Windows XP, but the company plans to launch a version this summer that allows users to switch between machines running XP and Vista.

PCs that have been locked by administrators so users cannot install files on them won't work with MojoPac unless the administrator first installs a small piece of software that is available on the company's Web site. [Alert your Security Team! Bob]

... While most programs work with MojoPac, one good source for the devices is www.PortableApps.com, a site that specializes in offering programs customized for thumb drives.

It lists more than three dozen programs, including software for fighting viruses, backing up data, surfing the Web and viewing documents. There are also programs for word processing, photo editing, spreadsheets and instant messaging.



Unfortunately, this must be part of Disaster Planning.

http://www.technewsworld.com/rsstory/61040.html

Keeping Tabs on Employees When Disaster Strikes

By Pam Baker TechNewsWorld 01/04/08 4:00 AM PT

"If your key individuals are not at their primary locations to respond to the emergency, a robust, scalable, and reliable mobile solution is critical to get the word out quickly to those tasked with responding to the situation and ensure timely recovery of key business processes," said Frank Mahdavi, chief strategy officer for the emergency notification firm MIR3.

Change may no longer be the only constant; danger is proving omnipresent and therefore a constant variable in enterprise IT planning.

"In today's world where a shooter can walk in the front door of a church and open fire, there is really no place that is safe," Henry Dewing, analyst at Forrester Research told TechNewsWorld. "Companies must take steps to act as responsible guardians of their employee body."



Want to tweek someone?

http://www.bespacific.com/mt/archives/017017.html

January 03, 2008

The National Academy of Sciences: Science, Evolution, and Creationism

"The National Academy of Sciences (NAS) and Institute of Medicine (IOM) today released Science, Evolution, and Creationism, a book designed to give the public a comprehensive and up-to-date picture of the current scientific understanding of evolution and its importance in the science classroom. Recent advances in science and medicine, along with an abundance of observations and experiments over the past 150 years, have reinforced evolution's role as the central organizing principle of modern biology, said the committee that wrote the book."

Click here to download the free PDF of the Science, Evolution, and Creationism summary brochure.



Geek stuff... Note that the Digg Effect has crashed the website. Alternate links are available in the comments...

http://digg.com/linux_unix/68_Linux_Related_Free_E_books_2

68 Linux Related Free E-books

linuxhaxor.net — A comprehensive list of Free Linux related e-books.



Business Model: I've been thinking about a hobby based model ever since I saw “Endless Summer.” Unfortunately, I can't surf, but the concept still intrigues...

http://www.killerstartups.com/User-Gen-Content/MountainReviewscom---Time-to-Hit-the-Slopes/

MountainReviews.com - Time to Hit the Slopes

It’s winter in the northern hemisphere, so besides providing for the perfect excuse for curling up to a warm mug of hot cocoa, some of you will want to hit the slopes. For those of you who love alpine sports, there’s MountainReviews. Here you can find reviews and descriptions of the best places to ski and snowboard in the country. Find the most difficult slopes or search for terrain that’s easy enough for newbies. Additionally, you can search for ski areas in your own region, find photos and videos, and check out the latest snowboarding and skiing news. All reviews come with six different criteria for rating: difficulty, beginner’s rating, intermediate, expert, park, and overall rating. Find a slope that you just adore or hate? Add your own review.

http://www.mountainreviews.com/

Thursday, January 03, 2008

Isn't it amazing that procedures are revised days (hours?) after an incident.

http://www.pogowasright.org/article.php?story=20080102170749849

Robotic Industries Association site hacked; credit card details accessed

Wednesday, January 02 2008 @ 05:07 PM EST Contributed by: PrivacyNews News Section: Breaches

Robotics Industries Association reported that a hacker accessed their administration site for Robotics Online on or about December 10th, gaining access to individual orders that contained credit card information. Seven residents of NH were affected, but national totals were not indicated.

Following the intrusion, the company deleted all credit card information from their site, and temporarily ceased accepting credit card orders

Source - Robotics Industries Association Notification to NH DOJ [pdf]



Ha! The excuse I predicted! (Again, procedures changes immediately.)

http://www.pogowasright.org/article.php?story=20080103070058929

ID info at risk in laptop theft

Thursday, January 03 2008 @ 07:02 AM EST Contributed by: PrivacyNews News Section: Breaches

Officials with one of Utah's largest insurance companies are searching for a stolen laptop containing Social Security numbers and other personal information for about 2,800 people and 1,400 companies.

The computer was taken from a car parked in the home garage of an auditor for the Workers Compensation Fund (WCF) on Dec. 9. But WCF said it chose not to issue a public statement at that time out of fear of alerting anyone that the laptop contained information that could be used for identity thefts.

Source - The Salt Lake Tribune

[From the article:

"As soon as this was discovered, every auditor brought in their laptops so that all information was removed," she said. "And, we've added additional levels of password protection."

The stolen laptop was password protected, she said. But as an additional precaution, auditors are now not allowed to store personal information, such as Social Security numbers, in their laptops and the computer information will be better encrypted.



Here's a legal opinion that won't be imported to the US.

http://www.pogowasright.org/article.php?story=20080102091718346

De: Zypries: Retained data cannot be used in civil cases

Wednesday, January 02 2008 @ 09:17 AM EST Contributed by: PrivacyNews News Section: Non-U.S. News

Retained telephone and Internet data may be used only by the police and the public prosecutor's office, says German Justice Minister Brigitte Zypries. "Connection information can assist in the prosecution of terrorists and organized criminals but cannot be used to help the music industry pursue its rights under civil law," said the SPD party politician in an interview with Focus, the German news magazine.

Source - Heise

[From the article:

"Any government that tries to broaden its scope will lose all credibility."

... The music industry, backed by a number of political figures, had demanded access to this data to help pursue its claims for compensation against pirates.


Ditto

http://www.pogowasright.org/article.php?story=20080102191923269

UK: 'Prosecute officials who lose public's details'

Wednesday, January 02 2008 @ 07:19 PM EST Contributed by: PrivacyNews News Section: Breaches

WORKERS in the public and private sectors should face criminal charges if they put the security of personal data at risk through carelessness or impropriety, an influential group of MPs will say today.

Managers should also be obliged to report losses of data and other breaches to the government's information watchdog.

Source - Scotsman.com

Related - Guardian: MPs say losing computer data should be made a crime



Mortgage the house?

http://www.techcrunch.com/2008/01/02/jpmorgan-predicts-2008-will-be-nothing-but-net/

JPMorgan Predicts 2008 Will Be “Nothing But Net”

Erick Schonfeld January 2 2008

JPMorgan’s Internet analyst Imran Khan and his team released a massive 312-page report this morning titled Nothing But Net that paints a bullish picture for the major Internet stocks (Google, Amazon, Yahoo, eBay, Expedia, Salesforce.com, Ominiture, ValueClick, Monster.com, Orbitz, Priceline, CNET, etc.). Some key takeaways:

—Noting that, in 2007, Internet stocks delivered a 14 percent return versus 5 percent for the S&P 500, JPMorgan expects 34 percent earnings growth in 2008 for the Internet stocks it covers versus 8 percent earnings growth for the S&P 500.



Could it be this simple?

http://digg.com/software/Sixty_One_A_Digg_Like_Site_For_Music

Sixty One, A Digg Like Site For Music

thesixtyone.com — If Guitar Hero™ is about shredding, Then Sixty One is about scouting. Musicians upload music and listeners decide which songs go on the homepage.

http://www.thesixtyone.com/hot/



A whale of a deal for my Wise old Owls, Loon-y, Legal Eagle – even “Ash-breasted Tit-tyrant” (honest!) friends...

http://hosted.ap.org/dynamic/stories/E/ENVIRONMENTAL_RINGTONES?SITE=VALYD&SECTION=HOME&TEMPLATE=DEFAULT

Wildlife Ringtones Reach Milestone

By SUSAN MONTOYA BRYAN

Associated Press Writer Jan 3, 5:09 AM EST

ALBUQUERQUE, N.M. (AP) -- With the new year comes a new Web site and new ringtones featuring the growls, bugles and chirps of dozens of rare and endangered species from around the globe.

Center for Biological Diversity: http://www.biologicaldiversity.org

Endangered Species Ringtones: http://www.rareearthtones.org

Wednesday, January 02, 2008

This is interesting in that the principal is assuming the worst instead of trying to minimize the incident.

http://www.todayonline.com/articles/230068.asp

Laptops, student data missing after school break-in

Teo Xuanwei xuanwei@mediacorp.com.sg Singapore News // Wednesday, January 2, 2008

The culprits of a break-in on Monday could have taken far more than just the three laptops they stole from Camford Business School.

But the ones they took contained the data of the school's students.

In an email sent to Today, Mr Indra, the school's principal, said he wanted to raise the alarm on the theft.

"The culprit was not interested in any of our assets except for our students' data.

"The computers that contained our student data were missing. Others were all left untouched," he said.



http://www.pogowasright.org/article.php?story=2008010206495223

UK: Stores accused over CCTV records

Wednesday, January 02 2008 @ 06:49 AM EST Contributed by: PrivacyNews News Section: Non-U.S. News

Thousands of innocent people could be unwittingly branded as “thieves and drug addicts” by shops.

Detailed files on customers, which include pictures taken from CCTV footage, are being held by some supermarkets purely on the basis that a person may be acting suspiciously, [Somewhat subjective? Bob] regardless of whether they have been caught committing a crime.

Source - EDP24

[From the article:

One victim, schoolboy Steven Hawkes, 13, found out he was on file at Tesco in Dereham, after several employees of the store told him and his family he had been blacklisted.

... “When I went to the store and tried to find out what was going on they said they only kept files on 'shoplifters and drug addicts' so I had to ask which one they thought my son was in. Eventually they admitted he hadn't done anything but looked suspicious.



At last, some push-back?

http://www.telegraph.co.uk/opinion/main.jhtml;jsessionid=FWNUFJIWHJMXJQFIQMFSFFOAVCBQ0IV0?xml=/opinion/2008/01/01/do0101.xml

We have everything to fear from ID cards

By Andrew O'Hagan Last Updated: 12:01am GMT 01/01/2008

We start the year in Britain with a challenge to our essential nature, for 2008 might turn out to be the year when we decide to rip up the Magna Carta.

Among the basic civil rights in this country, there has always been, at least in theory, an inclination towards liberal democracy, which includes a tolerance of an individual's right to privacy.

... Britain is already the most self-watching country in the world, with the largest network of security cameras; a new study suggests we are now every bit as poor at protecting privacy as Russia, China and America.

But surveillance cameras and lost data will prove minuscule problems next to ID cards, which will obliterate the fundamental right to walk around in society as an unknown.


Related... Will inability to read your license be probable cause for a traffic stop?

http://www.pogowasright.org/article.php?story=20080101192101421

Goverment Making It Easier To Steal Your Identity

Tuesday, January 01 2008 @ 07:21 PM EST Contributed by: PrivacyNews News Section: REAL ID

Electronic monitoring of motorists will soon expand dramatically as states including Arizona, Michigan, Vermont and Washington as they begin to use radio frequency identification (RFID) chips in drivers' licenses. These electronic chips broadcast the identity of any card holder to any chip-reading sensor within a minimum of thirty feet. The US Department of Homeland Security is promoting the tracking projects as part of its Western Hemisphere Travel Initiative.

Source - Gather



Perhaps you should convert those 5.25 floppies? (Comments are convinced this is just another way Microsoft is forcing users to buy an upgrade...)

http://it.slashdot.org/article.pl?sid=08/01/01/137257&from=rss

Office 2003 Service Pack Disables Older File Formats

Posted by Zonk on Wednesday January 02, @12:29AM from the always-so-helpful dept. Microsoft Software IT

time961 writes "In Service Pack 3 for Office 2003, Microsoft disabled support for many older file formats. If you have old Word, Excel, 1-2-3, Quattro, or Corel Draw documents, watch out! They did this because the old formats are 'less secure', which actually makes some sense, but only if you got the files from some untrustworthy source. Naturally, they did this by default, and then documented a mind-bogglingly complex workaround (KB 938810) rather than providing a user interface for adjusting it, or even a set of awkward 'Do you really want to do this?' dialog boxes to click through. And of course because these are, after all, old file formats ... many users will encounter the problem only months or years after the software change, while groping around in dusty and now-inaccessible archives."



Good news / bad news? Perhaps I could index Centennial-Man and publish it as a work of fiction?

http://hosted.ap.org/dynamic/stories/B/BUSINESS_OF_LIFE?SITE=VALYD&SECTION=HOME&TEMPLATE=DEFAULT

Got a Manuscript? Publishing Now a Snap

By CANDICE CHOI Associated Press Writer Jan 2, 8:29 AM EST

NEW YORK (AP) -- Getting a book published isn't the rarefied literary feat it once was.

... On-demand publisher Lulu.com has churned out 236,000 paperbacks since it opened in 2002, and its volume of new paperbacks has risen each month this year, hitting 14,745 in November. Retail giant Amazon.com got into the game this summer, offering on-demand publishing through its CreateSpace, which was already letting filmmakers and musicians burn DVDs and CDs.

... Unlike vanity publishing, in which aspiring authors pay to have their books run on traditional presses, on-demand publishing doesn't have to cost writers a cent.

... The system also allows small businesses to print high-end brochures, screenwriters to shop their scripts around and others to assemble wedding and other special-event books for friends and family.

On the Net:

http://www.Lulu.com

http://www.Blurb.com

http://www.createspace.com



I can't say I see the importance of some of these, but then, that's why I read these lists....

http://www.smh.com.au/news/technology/ten-things-that-will-change-your-future/2007/12/31/1198949747758.html

Ten things that will change your future

January 1, 2008

So Google and Wikipedia took you by surprise? Nick Galvin looks into his crystal ball and explains what you need to know to survive the next decade.

Tuesday, January 01, 2008

Clearly the goal isn't security. Perhaps it isn't even the appearance of security. But clearly it allows tracking (inventorying) of the second class... Note: If this technology allows “reading” of the card without the traveler even taking it from his pocket (and it does) will the Boarder Guards feel any need to actually look at the document?

http://www.bespacific.com/mt/archives/016990.html

December 31, 2007

CDT: Passport Card Rule Will Weaken Border Security and Privacy

"Today, the Department of State released a final rule for the new "Passport Card," which is intended to be used by American citizens who frequently travel by land or sea to Canada, Mexico, the Caribbean, and Bermuda. The new rule calls for the use of "vicinity read" RFID technology without the use of encryption. This means the card will be able to be read remotely, at a long distance. CDT strongly objected to the use of this technology--developed for tracking inventory, not people--because it is inherently insecure and poses threats to personal privacy, including identity theft, location tracking by government and commercial entities outside the border control context, and other forms of mission creep."



Tools and techniques:

http://digg.com/security/Eavesdropping_on_Bluetooth_headsets_with_Linux

Eavesdropping on Bluetooth headsets with Linux

hackszine.com — Few users realize that Bluetooth headsets can be exploited granting a remote attacker the ability to record and inject audio through the headset while the device is not in an active call. SANS Institute author and senior instructor Joshua Wright demonstrates.

http://www.hackszine.com/blog/archive/2007/12/eavesdropping_on_bluetooth_hea.html



You don't have to understand a technology to misuse it.

http://it.slashdot.org/article.pl?sid=07/12/31/2041205&from=rss

The Rising Barcode Security Threat

Posted by ScuttleMonkey on Monday December 31, @06:23PM from the what's-in-a-number dept. Security Software

eldavojohn writes "As more and more businesses become dependent on barcodes, people are pointing out common problems involving the security of one- or two-dimensional barcode software. You might scoff at this as a highly unlikely hacking platform but from the article, 'FX tested the access system of an automatically operated DVD hire shop near his home. This actually demanded a biometric check as well, but he simply refused it. There remained a membership card with barcode, membership number and PIN. After studying the significance of the bar sequences and the linear digit combinations underneath, FX managed to obtain DVDs that other clients had already paid for, but had not yet taken away. Automated attacks on systems were also possible, he claimed. But you had to remember not to use your own membership number.' The article also points out that boarding passes work on this basis — with something like GNU Barcode software and a template of printed out tickets, one might be able to take some nice vacations."



Craftsman Rootkits require Craftsman Class Action lawyers!

http://www.infoworld.com/article/07/12/31/Researcher-says-Sears-downloads-spyware_1.html?source=rss&url=http://www.infoworld.com/article/07/12/31/Researcher-says-Sears-downloads-spyware_1.html

Researcher says Sears downloads spyware

Sears and Kmart customers who sign up for the My SHC marketing program could, in essence, be stuck with spyware without notification, a Harvard professor says

By Robert McMillan, IDG News Service December 31, 2007

Sears and Kmart customers who sign up for a new marketing program may be giving up more private information than they'd bargained for, a prominent anti-spyware researcher claims.

According to Harvard Business School Assistant Professor Ben Edelman, Sears Holdings' My SHC Community program falls short of U.S. Federal Trade Commission (FTC) standards [..and that's hard to do! Bob] by failing to notify users exactly what happens when they download the company's marketing software.

And given the invasive nature of the product, Sears has an obligation to make its behavior clearer to users. "The software is not something you'd want on your computer or the computer of anyone you care about," Edelman said in an interview. "It tracks every site you go to, every search you make, every product you buy, and every product you look at but don't buy. It's just spooky."

Edelman has written up an analysis of Sears's software, set to be made public on Tuesday.



Always something useful

http://www.bespacific.com/mt/archives/016986.html

December 31, 2007

New on LLRX.com

  • FOIA Facts: FOIA - The Year in Review, by Scott A. Hodes

  • CongressLine: The Committee Markup, Paul Jenks



Your tax dollars at work... No doubt the TV industry will be paid 'per coupon issued' rather than for the coupons used.

http://hosted.ap.org/dynamic/stories/D/DIGITAL_TV?SITE=VALYD&SECTION=HOME&TEMPLATE=DEFAULT

Feds Share Coupons to Help TV Transition

By JOHN DUNBAR Associated Press Writer Dec 31, 6:18 PM EST

WASHINGTON (AP) -- Millions of $40 government coupons become available Tuesday to help low-tech television owners buy special converter boxes for older TVs that might not work after the switch to digital broadcasting.

Beginning Feb. 18, 2009, anyone who does not own a digital set and still gets their programming via over-the-air antennas will no longer receive a picture.