Thursday, April 24, 2008

Extra care is indicated when you deviate from 'normal practice' – it is 'normal' for a reason.

http://www.pogowasright.org/article.php?story=20080423110831574

(follow-up) UK: The 'local bank' loses 370,000 customers' details

Wednesday, April 23 2008 @ 11:08 AM EDT Contributed by: PrivacyNews News Section: Breaches

PogoWasRight.org note: Apparently, HSBC has yet to send out notification letters.

The largest bank in the UK, HSBC, has admitted that it may never find the disk that contained thousands of its customers details on it.

The "world's local bank" sent 370,000 customers details in the post from HSBC's life offices in Southampton to Swiss Re in Folkestone in February.

The bank added that it is putting together customer communications and letters are going to be sent out shortly.

HSBC said that the disk, which was password protected but not encrypted, would "normally" be sent electronically, but was sent through the mail when it could not be sent using this method. [The Internet was closed that day? Bob]

HSBC apologised for the breach. Candice Durrett, HSBC's media relations executive, said: "The data disk lost by HSBC contains no address or bank account details for any customer and would therefore be of very limited, if any, use to criminals.

"The data, which was password-protected, includes names, life insurance cover levels, dates of birth and whether or not a customer smokes. There is nothing else that could in any way compromise a customer and there is no reason to suppose that the disk has fallen into the wrong hands. "

Source - FTAdviser

[From the article:

Norwich Union Life was handed the eighth largest fine in the history of the FSA following poor security checks at call centres. The breach allowed fraudsters to impersonate customers and cash in their policies, leaving customers with a £3.3m loss through identity fraud. The regulator fined Norwich Union £1.26m. [I didn't notice the “cash in their policies” bit. Must have come as a shock to find out they were dead. Bob]



Good news: Organizations are starting to review their systems. Bad news: They should have been doing this for years...

http://www.pogowasright.org/article.php?story=20080423143509287

CT: SCSU security breach

Wednesday, April 23 2008 @ 02:35 PM EDT Contributed by: PrivacyNews News Section: Breaches

About 11,000 current and former students at Southern Connecticut State University may be at risk for identity theft.

SCSU was reviewing their Web server when they realized that the names, addresses and Social Security numbers of students since 2002 were vulnerable to access by unauthorized individuals.

SCSU has been notifying the affected students and is offering free identity protection services for up to two years.

A help desk has been established to respond to questions at (203) 392-7216 or you can visit www.southernct.edu/creditmonitoring

Source - WTNH

[From the article:

The move comes after a website with student and alumni information was found to be easily accessible to hackers.

... SCSU says records of about 11,000 students and alumni may have been compromised by hackers.

[These two statements seem to conflict. Was the data unprotected, or was the University hacked? Bob]



Too common.

http://www.pogowasright.org/article.php?story=20080424062001528

Ca: Chrysler unit's missing tape contains sensitive personal information

Thursday, April 24 2008 @ 06:40 AM EDT Contributed by: PrivacyNews News Section: Breaches

Chrysler's lending arm has admitted a courier service may have lost a data tape with sensitive personal information of thousands of Canadian auto customers.

Chrysler Financial also acknowledged yesterday it didn't inform customers for five weeks or longer about the "destroyed or lost" tape because of an internal search and investigation. [Unlikely they were searching internally for a tape they sent out. Most likely they were trying to determine what was on the tape. Bob]

Chrysler has still not recovered the tape, but a company official emphasized that it would be extremely difficult to access the contents, which include names, addresses and social insurance numbers.

... Jelich said the data on the mainframe computer tape contains details from "thousands" of customers in several provinces, but Chrysler would not disclose the specific number. During the last week, customers received letters from Brian Chillman, general counsel for Chrysler Financial, that informed them of the incident.

Source - Toronto Star

[From the article:

Chrysler did not contact police, but Jelich said the company voluntarily informed federal and provincial privacy commissioners about the possible breach.

The company said it was in the process of changing the way it was sending the sensitive data when the breach occurred.

"We are now using a secure electronic transmission," Jelich noted.

... As Chrysler prepared to notify customers three weeks later about the missing tape, UPS indicated it had found one. Chrysler verified that it wasn't the tape in question [Perhaps another instance of lost data they hadn't noticed? Bob] and Chrysler proceeded again with the process of informing customers by letter, Jelich said.



Easy to do” does not equal “Smart”

http://gizmodo.com/382972/crooks-rig-atm-with-eee-pc-to-steal-credit-card-info

Crooks Rig ATM with Eee PC to Steal Credit Card Info

In yet another demonstration of the never-ending hacking possibilities of the ASUS Eee PC laptop, three criminals in Brazil rigged an ATM with the little low cost computer to grab credit card information and personal information numbers to clone cards. Smart, except that one of them was a total moron.

The three men were specialized in cloning credit cards at ATMs, always with the same method. As you can see in the video, the first opens one of the machines, then another one comes to help him with the installation of a black Eee PC. Then they always proceeded to disable the rest of the machines, so clients were forced to use the rigged ATM. All this while they were being recorded by bank security cameras, of course.

The bank manager noticed that the door was forced and all the ATMs were disabled except for one, so he checked the security video and discovered what happened the night before. He immediately alerted the police, who started to search among the usual suspects. It didn't last long: Idiotic Crook Number One went to a police station to denounce a car accident and the three of them—who had a previous criminal history for bank assault in other parts of the country—were aprehended shortly thereafter.



Comments suggest this is the start down a slippery slope.

http://tech.slashdot.org/article.pl?sid=08/04/24/138227&from=rss

Google Turns Over Data on Suspected Pedophiles In Brazil

Posted by timothy on Thursday April 24, @09:39AM from the when-others-are-evil dept. Google Privacy

Dionysius, God of Wine and Leaf, points to a Yahoo! story which begins

"Google on Wednesday handed over data stored by suspected pedophiles on its Orkut social networking site to Brazilian authorities, ceding to pressure to lift its confidentiality duty to its users, officials said."



Of course we will be able to set our own criteria: “Caution Bob, you are approaching an area heavily infected by Democrats!”

http://techdirt.com/articles/20080422/025145916.shtml

GPS Will Now Tell You You're In A 'Bad' Neighborhood

from the now-that's-a-point-of-interest dept

While various GPS systems are competing to provide better, more interesting or more detailed "points of interest," it appears that Honda is going even further. Its new GPS system will also warn drivers when they're in a "bad neighborhood" where there's a high crime rate, and where their cars may be more likely to be vandalized or stolen. Right now, the product is only targeted at the Japanese market, but it's likely to eventually make it to the US. What will be worth watching is how communities respond if they're listed in GPS systems as being bad neighborhoods. These days, such designations are usually made by random people -- but having it in a GPS system (especially given how slavishly some listen to what their GPS tells them) may make it seem more "official." While I can imagine some communities getting angry about the designation, some might try to improve their reputations, which could have a very positive end result. Of course, when talking about American communities, that's probably not the case. They'll probably just sue, claiming defamation.



Quotable stats?

http://www.reuters.com/article/technologyNews/idUSL2390434820080423

Web criminals fuel big rise in "trojans"

Wed Apr 23, 2008 2:49pm EDT

... In a report released in London, Microsoft said the number of trojans removed from computers around the world in the second half of 2007 rose by 300 percent from the first half.

[Find the report at: http://www.microsoft.com/security/portal/sir.aspx



Can application developers learn from a bad example?

http://www.news.com/8301-10784_3-9926997-7.html

FBI grilled again over computer upgrade woes

Posted by Anne Broache April 23, 2008 12:35 PM PDT

... Sensenbrenner accused Mueller of "continuously frustrating" his committee's attempts to find out how much money had been spent before the failed program was abandoned about three years ago. The FBI has since begun a new effort called Sentinel, whose first phase--a Web portal of sorts for investigators--went live in June last year.

... Mueller said the agency now has help from technology and business process experts that it didn't have when the Virtual Case File project began. He said the agency has also set "firm requirements" so that contractors have clearer guidance on what to build.

... Rep. Zoe Lofgren (D-Calif.) also urged Mueller to devote more attention to digitizing years of paper FBI records, arguing that if a company like Google can digitize university library volumes in a matter of months, the federal agency has no excuse for inaction. "I don't know if you've done a cost-benefit analysis," she said, "but it seems to me (it's) clear that if you move into the modern age, your agents are going to be optimized in terms of their performance."



..to keep those UFO pilots from leaving?

http://www.pogowasright.org/article.php?story=20080423085606568

US-VISIT Program: Collection of Alien Biometric Data upon Exit from the United States at Air and Sea Ports of Departure

Wednesday, April 23 2008 @ 08:56 AM EDT Contributed by: PrivacyNews News Section: Older News Stories

The Department of Homeland Security has uploaded, "United States Visitor and Immigrant Status Indicator Technology (US-VISIT) Program In conjunction with the Notice of Proposed Rulemaking on the Collection of Alien Biometric Data upon Exit from the United States at Air and Sea Ports of Departure", April 22, 2008, (PDF, 26 Pages - 851 KB).

The United States Visitor and Immigrant Status Technology (US-VISIT) Program is implementing the first phase of the Exit component of its integrated, automated biometric entry-exit system that records the arrival and departure of covered aliens; conducts certain terrorist, criminal, and immigration violation checks of covered aliens; and compares biometric identifiers to those collected on previous encounters to verify identity. The US-VISIT Program has been implemented in phases with each phase adding additional capabilities, locations of implementation, or subject populations. US-VISIT is publishing this Privacy Impact Assessment (PIA) in conjunction with the Notice of Proposed Rulemaking (NPRM) on Collection of Alien Biometric Data upon Exit from the United States at Air and Sea Ports of Departure. A revised PIA will be issued in conjunction with the Final Rule on Collection of Alien Biometric Data upon Exit from the United States at Air and Sea Ports of Departure. US-VISIT does not collect any information on United States citizens.



It is beginning to look like Comcast will get slammed. (The comments are interesting...)

http://tech.slashdot.org/article.pl?sid=08/04/23/2145214&from=rss

FCC Reports Comcast P2P Blocking Was More Widespread

Posted by Soulskill on Wednesday April 23, @06:12PM from the saw-that-coming dept.

bob charlton from 66 tips us to a ComputerWorld story about FCC Chairman Kevin Martin, who has testified that Comcast's P2P traffic management occurred even when network congestion wasn't an issue, contrary to the ISP's claims. After defending its actions and being investigated by the FCC over the past few months, Comcast has tried to repair its image by making nice with BitTorrent and working towards a P2P Bill of Rights. Quoting:

"'It does not appear that this technique was used only to occasionally delay traffic at particular nodes suffering from network congestion at that time,' Martin told the Senate Commerce, Science and Transportation Committee. 'Based on testimony we've received thus far, this equipment was typically deployed over a wider geographic area or system, and is not even capable of knowing when an individual ... segment of the network is congested.'



...and this seems to be an indication that the phone companies are going the way of the music industry. “We don't understand it, so we aren't making money with it, so we should sue the people who are.”

http://www.infoworld.com/article/08/04/23/Telecom-carriers-Phantom-voice-traffic-costing-billions_1.html?source=rss&url=http://www.infoworld.com/article/08/04/23/Telecom-carriers-Phantom-voice-traffic-costing-billions_1.html

Telecom carriers: 'Phantom' voice traffic costing billions

Some rural carriers are seeing up to 30 percent of their minutes eaten by voice calls lacking ID needed for carriers to charge access fees for use of their networks

By Grant Gross, IDG News Service April 23, 2008



I know there are people out there who hate PowerPoint – but honestly people... (Think of it as training for CyberWar)

http://www.techcrunch.com/2008/04/23/slideshare-slammed-with-ddos-attacks-from-china/

SlideShare Slammed with DDOS Attacks from China

Mark Hendrickson April 23 2008

SlideShare, a Mountain View-based startup that lets you upload and embed PowerPoint presentations on the web, appears to have stirred the red dragon last week.

About ten days ago the company began receiving anonymous requests to delete slideshows that were deemed “illegal” by the requesters. The SlideShare staff checked out these slideshows and discovered them to be quite innocent. While some described ways to fight corruption in China, none of them violated the company’s terms of service, and so SlideShow did nothing to fulfill the requests.

SlideShare soon began receiving a different type of request from the same people, who could now be identified by their email addresses. This time they were pretending to be users who had lost their passwords. Once again doing nothing, the company got a very demanding, and almost threatening, call to its Indian office on Wednesday, one that insisted that the company grant access to an account.

After these three failed attempts, SlideShare experienced a massive distributed denial of service attack starting at 10pm on Thursday, one day before the CNN website was attacked by Chinese instigators in apparent backlash to its coverage of the Tibetan protests. We’ve been told that the attack reached a peak of 2.5GB/sec and consisted entirely of packets sent from China.

Not long after the first attack subsided, SlideShare was hit a second time on Friday and the site went down again until Saturday morning. Since then there have been no more attacks, but the company continues to receive fake password recovery and illegitimate takedown requests at a rate of about 5-10 per day (it has accumulated about 50-60 total).

There’s a lot of speculation around just what has happened here since no one knows for sure who is behind the requests and attacks. However, it seems likely that they were from the same hacker groups - possibly linked to the Chinese government - that attacked the CNN site (and later called their attack off after getting too much publicity). Some of the slideshows with takedown requests have been viewed many times recently, so their popularity seems to have landed them on the Chinese government’s radar.

SlideShare insists that it will do everything it can to protect its users’ freedom of speech. As such, it has no plans to remove any of the content in question.

The Sports Network was also recently taken over by Chinese hackers who mistook it for CNN sports.

Update: Just as I finished writing this post, I received word from the company that a third attack had begun.


...and on the flip side...

http://www.infoworld.com/article/08/04/24/China-worries-hackers-will-strike-during-Beijing-Olympics_1.html?source=rss&url=http://www.infoworld.com/article/08/04/24/China-worries-hackers-will-strike-during-Beijing-Olympics_1.html

China worries hackers will strike during Beijing Olympics

Amid recent turmoil over Tibet, hackers view the Olympics as a challenge and a target; Chinese security officials say the network security situation is grim

By Sumner Lemon, IDG News Service April 24, 2008

... "Based on historical experience, many hackers seeking to make a name for themselves view the Olympic Games as a challenge and a target, and the Beijing Olympics may face attacks from individual hackers, groups, organizations, as well as other countries and those with all kinds of political motivations, therefore the network security situation is very grim," China's National Computer Network Emergency Response Technical Team (CNCERT) said in a report released earlier this month.



I think I've mentioned this before. Clear, simple, introductory guides...

http://www.wral.com/business/blogpost/2782327/

In Pictures Is Now Apparently All Free

Posted: Apr. 23 7:12 p.m.

... all the tutorials are freely available on the Web. Among the tutorials are several Office applications, open office, and some Web programming basics.

http://inpics.net/



For my web site students

http://www.killerstartups.com/Web-App-Tools/MashMakerIntelcom---Customize-Websites-on-the-Fly/

MashMaker.Intel.com - Customize Websites on the Fly

Intel Mash Maker lets you mash together bits and pieces of them web, as if it were your own personal canvas. The tool which comes from the chip making monolith, is currently offered as a free browser extension for Firefox and IE (with more features for the former). Once downloaded, users can modify web pages, combining info from a range of sources. All of this occurs on the client, so you’re not making a brand new web app per se. You are adding visualizations etc via widgets. So basically, the masher allows you to customize a page by creating or modifying widgets to different web pages. Customization is thus on offer to everyone, not simply tech nerds. There is a gallery where you can find popular widgets to customize for your own use.

http://mashmaker.intel.com/web/

Wednesday, April 23, 2008

Remember, you hire your worst security threat.

http://www.pogowasright.org/article.php?story=20080422112536737

LendingTree discloses insider data breach

Tuesday, April 22 2008 @ 11:25 AM EDT Contributed by: PrivacyNews News Section: Breaches

Web-based lending exchange LendingTree, which generates leads in the mortgage business by accepting online customer information, yesterday disclosed that it believes several former employees illicitly helped a handful of mortgage lenders gain access to customer data.

"Recently, LendingTree learned that several former employees may have helped a handful of mortgage lenders gain access to LendingTree's customer information by sharing confidential passwords with the lenders," LendingTree stated in a letter sent April 21 to its customers. "When we learned of this situation, we quickly contacted the authorities, and LendingTree is helping with the investigation. We promptly made several system-security changes. We also brought lawsuits against those involved." [Bravo Bob]

Source - Network World

Related - Charlotte.com: LendingTree tells clients of breach

[From the Network World article:

LendingTree believes the lenders gained illicit entry to its data systems to access LendingTree’s loan-request forms between October 2006 and early 2008. [Boo Bob]



Do you notify people or customers?

http://www.pogowasright.org/article.php?story=20080422153358504

Bank customers urged to take precautions because of security breach

Tuesday, April 22 2008 @ 03:33 PM EDT Contributed by: PrivacyNews News Section: Breaches

A Laguna Woods Village resident was informed by letter from his bank this week that his "non-public private account" [as opposed to his public private account Bob] information might be at risk.

The Villager is not the only customer getting such letters, nor was his bank the only financial institute impacted by a security breach that occurred in a banking systems provider last month.

In the letter sent to the Villager from First Federal Bank of California it states that "a large number of financial institutions [This could be huge Bob] including First Federal Bank of California, was accessed."

First Federal Bank of California Counsel Greg Josephson and Chief Operating Officer Jim Giraldin explained that the breach in security occurred Easter Saturday, March 22, in a "subsystem of a financial data processor," Fiserv, Inc. of Wisconsin.

Fiserv, a Fortune 500 company, is one of the largest providers of electronic information technology to financial institutions and insurance industries worldwide.

Source - OCRegister.com Thanks to Wilma Burt of the Identity Theft Resource Center for this link..

[From the article:

Fiserv Company Corporate Communications Vice President Melanie Tolley said... ...that it was "company policy" not to reveal any details about the breach including the number of banks involved, how many customers were impacted, the depth of information breached, how extensive the breach was geographically even which federal agencies were involved in the investigation.

She said releasing such information would hamper the investigation...

... She said ultimately the banks, not Fiserv, are responsible to their clients.



Looks like at least one news organization is beginning to see the obvious...

http://www.pogowasright.org/article.php?story=20080423003815333

(follow-up) BoI kept quiet about stolen client details since February

Wednesday, April 23 2008 @ 12:38 AM EDT Contributed by: PrivacyNews News Section: Breaches

Bank of Ireland managers knew in early February that thieves had stolen personal data on 10,000 customers, but decided not to tell the authorities.

And even after the security breach was uncovered internally, the bank took no steps -- until yesterday -- to begin encrypting its laptop computers.

Despite making a profit of €1.7bn last year, Bank of Ireland's failure to spend an estimated €200,000 on encryption technology to protect its customers' data has caused shock.

Source - Independent.ie

[From the article:

The technology is used by all of its major banking rivals but Bank of Ireland's lack of investment in such a key area of basic security is a source of deep concern, experts said.

... The bank said there was no evidence of fraud so far, but yesterday a clearly embarrassed governor Richard Burrows said he could not guarantee the data would not be used by the thieves.

The Irish Independent learned the thefts -- between June and October 2007 -- were reported to gardai within hours but senior managers at the bank were not told.

... The Data Protection Commissioner wants to know why medical data was being stored at all.



Confusion or cover-up?

http://www.pogowasright.org/article.php?story=20080422222032702

Hackers Breach System At UMass

Tuesday, April 22 2008 @ 10:20 PM EDT Contributed by: PrivacyNews News Section: Breaches

Hackers breached the computer system used by UMass Amherst's Health Services, potentially gaining access to thousands of medical records.

More than half of the student population at UMass Amherst are patients on record at the University Health Services.

Source - CBS

[From the article:

Officials believe outside hackers wanted to use the server as a host for illegal music and video downloads, one that would make the culprits untraceable.

... A fact that's even more unsettling for patients who were unaware of the breach more than a week after it occurred. The University did post a notice on the Health Services website, and say they are notifying patients when they enter the clinic.

... "If it's that easy for someone who just wanted to get music who knows what would happen for someone who was trying to get confidential information."

Campus officials say it will be weeks before they are completely sure what information, if any, was taken off the computers.



Save for college (because your credit history will be so screwed up you'll never get a loan!

http://www.pogowasright.org/article.php?story=20080422155529893

CollegeInvest loses hard drive, customers' personal data

Tuesday, April 22 2008 @ 03:55 PM EDT Contributed by: PrivacyNews News Section: Breaches

CollegeInvest this week is sending letters to roughly 200,000 customers who had personal information stored on a computer hard drive that disappeared during a recent move.

CollegeInvest believes there is little risk of customers’ personal information being compromised because the data is in a format that would be difficult to access and also was password protected.

Personal data from some but not all CollegeInvest customers was on the hard drive.

... CollegeInvest moved to a new office space recently using an international relocation firm that offered specialists in moving computer equipment. CollegeInvest discovered while unpacking at the new location that a hard drive was missing.

.... CollegeInvest is a not-for-profit division of the Colorado Department of Higher Education. CollegeInvest helps families break down the financial barriers to college by providing expert information, simple planning tools, scholarships, college savings plans, and low-cost student and parent loans.

Source - North Denver News



http://www.pogowasright.org/article.php?story=2008042307131558

Infosec: Reputation driving information security

Wednesday, April 23 2008 @ 07:13 AM EDT Contributed by: PrivacyNews News Section: Businesses & Privacy

Concerns over reputation and brand protection are key drivers of information security for nearly three-quarters of companies worldwide.

The findings come from the latest Global Information Security Workforce Study from ISC2 published at Infosec Europe 2008.

'Corporate image' topped the list of top priorities for motivating information security governance, but the privacy of customer data, identity theft and breach of laws and regulations are also key factors.

The fourth edition of the study was conducted by Frost & Sullivan and surveyed 7,548 information security professionals from companies and public sector organisations in more than 100 countries.

Source - IT Week

Global Information Security Workforce Study (PDF)



A step in the right direction? More likely: “The Scapegoat Minister has acknowledged his responsibility, and will immediately retire to his villa in the south of France.”

http://www.pogowasright.org/article.php?story=2008042211170366

UK: Top officials to be held to account for data losses

Tuesday, April 22 2008 @ 11:17 AM EDT Contributed by: PrivacyNews News Section: Breaches

Senior Whitehall figures are to be held personally responsible if their department loses or mishandles personal information, under a range of measures designed to increase data security.

Officials across the public sector, including permanent secretaries and chief executives of NHS trusts, are to be forced to take data protection "much more seriously" under proposals due to be laid out by Gus O'Donnell, the Cabinet Secretary.

In the coming weeks Mr O'Donnell is expected to present the findings of a report on data security.

Source - TimesOnline

[From the article:

...the heads of departments would be personally responsible in the event of serious data breaches.

"It has to be the likes of chief executives (of NHS trusts) and permanent secretaries who are held accountable when things go wrong," Mr Thomas told a security conference in London. "They can't simply make assumptions that everything is in the hands of the 'techies'".

... "There are going to be new requirements for Whitehall departments and new guidance for the public sector at large," Mr Thomas said. "It's not just about data security. We need to ask a whole range of questions, such as why so much information is being collected. Why is it being retained for so long? Why are laptops which hold the information not being encrypted? And why are such laptops being left in the backs of cars?" [Noble words. Let's check back in six months. Bob]


Mentioned in the article above...

http://www.pwc.co.uk/eng/publications/berr_information_security_breaches_survey_2008.html

BERR Information Security Breaches Survey 2008

April 2008


Another “We're gonna fix everything” promise.

http://www.pogowasright.org/article.php?story=20080422112017169

Hannaford details upgrades prompted by security breach

Tuesday, April 22 2008 @ 11:20 AM EDT Contributed by: PrivacyNews News Section: Breaches

Hannaford Bros. Co. says it's taking steps to enhance the security of its data network following a massive breach that compromised up to 4.2 million credit and debit card numbers.

Company officials announced Tuesday that the new measures include encryption of all card numbers during the entire time they are within the supermarket chain's data network. The company says it's also introducing a "24/7 monitoring system" to detect intrusions.

Source - WPRI

[From the article:

Hannaford President and CEO Ron Hodge apologized again Tuesday and said there has been no drop in sales since the breach was announced five weeks ago. [Maybe TJX was right, customers don't care. Bob]



...because cameras aren't enough? Will every prisoner get a Bluetooth device surgically implanted? (If not, won't they simply swap them randomly?)

http://yro.slashdot.org/article.pl?sid=08/04/22/1754242&from=rss

Bluetooth Surveillance Tested In the UK

Posted by kdawson on Tuesday April 22, @02:37PM from the turn-the-darn-thing-off dept. Privacy Wireless Networking

KentuckyFC writes

"If you live in the city of Bath in the UK and carry a Bluetooth-enabled device, your movements may have been secretly monitored in an experiment designed to test surveillance techniques in prisons. Researchers from Bath University recorded the movements of 10,000 Bluetooth-enabled devices during their 6-month trial. They say the experiment was a test of a technique for monitoring the interactions between prisoners in jail that could be used to work out which inmates have become closely associated. The work was prompted by revelations that the Madrid train bombers who devastated the city in 2004 first met in a Spanish prison (abstract)."

Tuesday, April 22, 2008

Another SunGard victim. It will be interesting to see how long they can hide the magnitude of this one... One of my students pointed me to the Univ of Miami

http://www.pogowasright.org/article.php?story=20080422071108916

Personal info at risk in laptop theft (Sungard Update)

Tuesday, April 22 2008 @ 07:11 AM EDT Contributed by: PrivacyNews News Section: Breaches

Another security breach — this time following the theft of a laptop owned by the company which implements the Banner system — has exposed the names and Social Security numbers of over 130 individuals related to Binghamton University.

This weekend the University notified 11 students and about 120 applicants that their names and Social Security numbers were saved on a laptop belonging to an employee of SunGard Higher Education, which was stolen on March 13.

Source - Pipe Dream

hat-tip, ESI

[One of my students pointed me to this article on the Univ of Miami Bob]

http://www.scmagazineus.com/University-of-Miami-admits-to-stolen-medical-records/article/109195/



Don't you love British sarcasm?

http://www.pogowasright.org/article.php?story=20080421162625306

UK: Someone's put their foot in it at Boots

Monday, April 21 2008 @ 04:26 PM EDT Contributed by: PrivacyNews News Section: Breaches

Boots is the latest company to be embarrassed by the loss of confidential information after a drug addict stole a back-up tape with details of customers to whom the company had sold dental insurance. Boots is blaming Medisure, the insurer, which is blaming the security firm that was transporting the tape. No one is saying much more, and the whereabouts of the tape, or indeed why it should have attracted the interest of an opportunistic thief, is unclear.

The thief was caught on CCTV. [It's the UK. CCTV is everywhere! Bob] The pharmacist and the insurer have written to an unspecified number of customers reassuring them that the data, including dates of birth and bank account details, are inaccessible without specialist machinery. [You need a tape drive, or one of those services that move the data to CDs for you. Bob] As The Register, the online IT magazine, points out acidly: “That's all right then, because surely there are no ties between thieves in this country and hackers in, for example, the former Soviet bloc?”

Source - Times Online



Perspective: If you don't have mandatory disclosure laws, there is little incentive to move quickly.

http://www.pogowasright.org/article.php?story=20080421161738759

Ie: Data probe after BoI laptops theft

Monday, April 21 2008 @ 04:17 PM EDT Contributed by: PrivacyNews News Section: Breaches

Sensitive information about 10,000 Bank of Ireland customers has been stolen.

[...] The records of 10,000 customers on the computers included credit history, some medical backgrounds for life insurance quotes, personal pension plan details, dates of birth, addresses and bank account details. All the material was contained on the four laptops stolen between June and October 2007.

The laptops were not encrypted, therefore whoever has them has full access to the customers' data. A spokesperson for the bank has confirmed to RTE that it is currently encrypting all its computer - up to 5,000 of the bank's laptops - a process that is likely to take two weeks.

Source - RTÉ.ie

[From the article:

RTE News understands that none of the customers has been informed, but the bank is intending to do so shortly.



I bet they have a reeeeallly strong policy that permits them to do this. “In an attempt to 'make the punishment fit the crime,' we have discarded these employees without thinking about it...”

http://www.pogowasright.org/article.php?story=20080421171505548

(follow-up) Two employees out of a job after discarding files incorrectly

Monday, April 21 2008 @ 05:15 PM EDT Contributed by: PrivacyNews News Section: Breaches

Two employees of an organization that serves homeless veterans are out of their jobs.

This after, a 24-Hour News 8 exclusive report over the weekend that discovered hundreds of files containing personal information about some of those veterans in a dumpster.

Source - WISH-TV

[From the article:

"One of our case managers erroneously labeled a box trash, actually three of them that came out of his office. The supervisor did not do what she should have done and check those. Neither one of them is with us any more,...



Makes you wonder: if this is more important than finding Osama? if it was a reciprocal agreement? If governments truly believe they can do anything to “mere citizens?”

http://www.pogowasright.org/article.php?story=20080421124605312

Secret pact allows the US to spy on UK motorists

Monday, April 21 2008 @ 12:46 PM EDT Contributed by: PrivacyNews News Section: Non-U.S. News

THE UK Home Secretary secretively signed a "special certificate" last year that gives foreign security agencies real-time access to traffic camera images and related data monitoring British motorists on highways throughout the UK.

Opposition politicians and civil liberties advocates yesterday accused Gordon Brown's government of attempting to hide from Parliament its covert plans to facilitate international surveillance of UK citizens in violation of privacy laws.

Source - The Inquirer

[From the article:

Opposition politicians and civil liberties advocates yesterday accused Gordon Brown's government of attempting to hide from Parliament its covert plans to facilitate international surveillance of UK citizens in violation of privacy laws. [Indicating it was reciprocal... Bob]



Some interesting questions and a proposal or two...

http://www.phiprivacy.net/?p=290

Apr-21-2008

Contractor or vendor woes (commentary)

A few recent breaches involving health information have gotten me thinking more about contractor or third party data losses. Is our reaction to such incidents the same as it would be if the hospital, insurance company, or other covered entities directly experienced the breach or loss themselves?


Related? Who 'repairs' your computer?

http://www.pogowasright.org/article.php?story=20080421175225860

CT: Hard Drive Containing Personal Info Sold To Student

Monday, April 21 2008 @ 05:52 PM EDT Contributed by: PrivacyNews News Section: Breaches

A student bought a computer hard drive and discovered that it contains personal information about people with ties to the University of Connecticut.

Ryan Green, a junior at UConn, bought the drive at the UConn Co-op for $200 and discovered it already contained information.

[...] Green found about 10,000 private pictures, 10,000 Microsoft Word documents and even some sensitive personal information like credit cards and driver's licenses. " It's multiple people's data, entire computers," Green said.

[...] Authorities said the information belongs to 10 people, all who have a connection to the university. Police said early indications suggest that all had their computers serviced at the co-op between November and March.

Source - WFSB



CyberWar? (I wonder if they created the PowerPoint on their Lenovo laptop?)

http://hardware.slashdot.org/article.pl?sid=08/04/22/1317212&from=rss

FBI Concerned About Implications of Counterfeit Cisco Gear

Posted by timothy on Tuesday April 22, @10:10AM from the now-watch-these-chickens-well dept. Security United States Hardware

SpicyBrownMustard writes

"An FBI PowerPoint presentation provides details about a criminal investigation into counterfeit CISCO hardware originating from China, and sold by Gold/Silver partners to numerous US government, military, and intelligence agencies. The concern of the article's author and the FBI is that the counterfeit equipment may be state-sponsored to aid in accessing otherwise secure systems (slides 46+47). Says the article author: 'The threat is real. Compromised hardware of potentially hostile foreign origin sits within secure networks of the US government, military, and intelligence services. And as you now see, the FBI has been concerned about it.'"

We've mentioned the seizure of some of this equipment before, but this presentation adds quite a bit of detail, and highlights the FBI's concern of Chinese government involvement.



Close to home...

http://www.pogowasright.org/article.php?story=20080422082903928

Boulder district OKs cell phone search limits

Tuesday, April 22 2008 @ 08:29 AM EDT Contributed by: PrivacyNews News Section: Minors & Students

The Boulder Valley School District won't search a student's cell phone without the permission of the student or parent under an agreement reached with the American Civil Liberties Union.

The only exception is an emergency in which there is an imminent threat to public safety, said district spokesman Briggs Gamblin.

The agreement came out of talks between the district and the American Civil Liberties Union, which sent a letter to the district in October objecting to the actions of officials at Monarch High School in Louisville.

Source - Rocky Mountain News



Hillary is a hacker!

http://news.netcraft.com/archives/2008/04/21/hacker_redirects_barack_obamas_site_to_hillaryclintoncom.html

Hacker Redirects Barack Obama's site to hillaryclinton.com

A security weakness in Barack Obama's website has been exploited to redirect visitors to Hillary Clinton's website. Visitors who viewed the Community Blogs section of the site were instead presented with Clinton's website as a result of a cross-site scripting vulnerability.



More fun election news! Can you say, “E-chad?” (Is this practice for November?)

http://arstechnica.com/news.ars/post/20080421-pa-primary-will-be-unauditable-gop-blocks-e-voting-reform.html

PA primary will be unauditable; GOP blocks e-voting reform

By Jon Stokes Published: April 21, 2008 - 02:30PM CT

On the eve of tomorrow's hotly contested and relatively close Democratic presidential primary in Pennsylvania, a number of voting activists are sounding the alarm one last time about the state's election systems. Over 85 percent of PA voters will vote on paperless touchscreen machines that are hackable, failure-prone, and fundamentally unauditable.

[During prohibition, Malt came in a package printed with the recipe for beer along with the warning that “accidentally” mixing the ingredients listed would make an illegal beverage. In that same vein, this from the article:

Sixteen counties will use the Diebold Accuvote TS touchscreen model. Regular Ars readers will recall that my 2006 article, "How to steal an election by hacking the vote," described in some detail how to steal an election using this machine. (I hope that nobody from PA decides that it would be a good idea to print copies of the free PDF of this how-to article to bring to the polls with them as a form of protest, because you would probably get in trouble. So don't do that.)



For my Computer Security (Forensics) class

http://www.bespacific.com/mt/archives/018157.html

April 21, 2008

Electronic Crime Scene Investigation: A Guide for First Responders, Second Edition

Electronic Crime Scene Investigation: A Guide for First Responders, Second Edition, April 2008: "Computers and other electronic devices are being used increasingly to commit, enable, or support crimes against persons, organizations, or property. This National Institute of Justice guide is intended for first responders to a variety of crime scenes who may have the responsibility of protecting, recognizing, collecting, and preserving electronic evidence at the scene." (NCJ 219941, 74 pages, PDF)



Amusing but too limited to be useful...

http://www.pogowasright.org/article.php?story=20080421172604770

NJ Supreme Court rules Internet user has right to privacy

Monday, April 21 2008 @ 05:26 PM EDT Contributed by: PrivacyNews News Section: In the Courts

The state Supreme Court ruled today that under the New Jersey Constitution an Internet user has the right to privacy in the subscriber information maintained by the individual's Internet service provider.

Ruling in the case of Shirley Reid, a Cape May County woman who was charged with hacking into her employer's computer system after police obtained her identity from Comcast by using a municipal court subpoena, the high court unanimously held law enforcement had the right to investigate her but should have, instead, used a grand jury subpoena.

The court upheld a state appeals court ruling that overturned the conviction for second-degree computer theft.

Source - NJ.com

[From the article:

Ruling in the case of Shirley Reid, a Cape May County woman who was charged with hacking into her employer's computer system after police obtained her identity from Comcast by using a municipal court subpoena, the high court unanimously held law enforcement had the right to investigate her but should have, instead, used a grand jury subpoena.



Summary of a warrantless wiretapping case, and a ethical dilemma for lawyers

http://www.pogowasright.org/article.php?story=20080422063733172

State Secrets: A government misstep in a wiretapping case.

Tuesday, April 22 2008 @ 06:37 AM EDT Contributed by: PrivacyNews News Section: Surveillance

One Friday afternoon in August, 2004, a Washington, D.C., attorney named Lynne Bernabei received a package from the Department of the Treasury. The government was investigating one of her clients, the American branch of a Saudi charity called the Al Haramain Islamic Foundation, which had been active in fifty countries. Al Haramain had come under scrutiny, as had many other Islamic charities, after the attacks of September 11, 2001, and Treasury Department investigators believed that Al Haramain’s American branch, which was based in Oregon, had connections to Al Qaeda. In response to a request from Bernabei for evidence against her client, the government had turned over two sets of documents, primarily media reports that referred to other branches of Al Haramain. None of the materials demonstrated a direct connection between the Oregon branch and Al Qaeda.

Source - Patrick Radden Keefe, in The New Yorker hat-tip, Cryptome

[From the article:

The attorneys representing Al Haramain had been dealing with a novel quandary of legal ethics. If they had a reasonable belief that any telephone conversation with Seda or Buthi might be monitored by the N.S.A., could they talk to their clients without violating attorney-client confidentiality?



For my Math students (I'm teaching linear algebra)

http://digg.com/software/25_000_000_000_Eigenvector_Linear_Algebra_Behind_Google

$25,000,000,000 Eigenvector: Linear Algebra Behind Google

rose-hulman.edu — The paper describing Google's $25 billion dollar equation.



Too strange to be true?

http://gizmodo.com/382026/a-cellphones-missing-dot-kills-two-people-puts-three-more-in-jail

A Cellphone's Missing Dot Kills Two People, Puts Three More in Jail

Monday, April 21, 2008

Do political campaigns have an exemption from notifying potential Identity Theft victims?

http://weblogs.baltimoresun.com/news/politics/blog/2008/04/obamas_allentowngate_laptops_m.html

Obama's Allentowngate? Laptops missing

Posted April 19, 2008 9:00 PM by Josh Drobnyk

Barack Obama's Allentown office was burglarized this week, and multiple laptops and cell phones were stolen, an Obama campaign aide said today. A police spokesman confirmed the incident, but couldn't provide details today because reports are kept in the department's records depository, which is closed weekends. [Sounds fishy to me... Bob]

An Obama aide, speaking on condition of anonymity, said "a couple" field laptops were taken out of the office at 1233 Linden St. The computers have demographic information that the campaign uses to target voters. [At minimum, voter registration information. Bob] "A couple" cell phones were also taken, the aide said.

Police spokesman Capt. James Stephens confirmed the break-in, but could not confirm details of what was taken because the records office is closed on weekends. When and how the break-in occurred also remained unclear. Stephens would only say that it happened "a couple days ago." The Obama campaign declined to comment officially on the incident.

Both campaigns have had their share of incidents at field offices during the race. Obama field offices in California and Iowa have also been broken into. And late last year, a man took campaign workers hostage at a Hillary Clinton field office in Rochester, N.H.


Is this merely Identity Theft, or a way to make CyberWar pay its own way?

http://www.pogowasright.org/article.php?story=20080420154901426

Kr: User Data Stolen From Top Auction Site and Sold (update)

Sunday, April 20 2008 @ 03:49 PM EDT Contributed by: PrivacyNews News Section: Breaches

User data leaked from Auction.co.kr has been put up for sale on Chinese Web sites, raising alarm over potential damage from voice phishing or spam e-mail.

The personal information of 10.81 million users was stolen from the popular online shopping site in Korea.

A posting titled, “Buy Naver, Auction IDs at a good price,” was found on the China-based Internet portal site O2SKY. The posting was put up April 11 before being deleted nine days later, offering the e-mail address and phone number of the seller.

Source - dongA.com



This is a slight twist on the replacement of card scanning devices in US supermarkets. (It might explain why no one seemed to notice.)

http://www.pogowasright.org/article.php?story=20080420182810757

UK: Police break £1m credit card fraud linked to terrorism

Sunday, April 20 2008 @ 06:28 PM EDT Contributed by: PrivacyNews News Section: Breaches

Police in Scotland have uncovered petrol station credit card frauds with a potential value of £1m, linked to international terrorism.

Banks, oil companies and police forces throughout the country are on alert after 5000 cards were copied and their details stolen at two Edinburgh filling stations. A further attempt on a filling station in Kilmarnock was discovered before card details were stolen.

Source - The Herald

[From the article:

The gang members approach petrol station employees, who often work alone on shift, and offer a large bribe to allow access to the station's card-reading terminal.

... A miniaturised interceptor inserted inside the terminal copies the information on the card's magnetic strip and picks up the pin.

... The Herald's investigations suggest that banks' early warning systems in place to protect customers do not work consistently - especially in Scotland.

One industry source said: "Some banks decide not to inform the customers until any attempts are made to actually use the compromised details."

While in England and Wales it is the banks' responsibility to notify the police of suspect locations, in Scotland the onus is on the customer to report a suspected fraud to the police.



...because...

http://www.pogowasright.org/article.php?story=20080421063954293

Data “Dysprotection:” breaches reported last week

Monday, April 21 2008 @ 06:39 AM EDT Contributed by: PrivacyNews News Section: Breaches

A recap of incidents or privacy breaches reported last week for those who enjoy shaking their head and muttering to themselves with their morning coffee.

Source - Chronicles of Dissent



Security as a commodity? (Remember, someone in the organization has to know what questions to ask the vendors.)

http://news.slashdot.org/article.pl?sid=08/04/20/1524246&from=rss

Information Security Is Becoming Infrastructure

Posted by Soulskill on Sunday April 20, @12:25PM from the time-to-pay-your-monthly-security-bill dept.

Bruce Schneier has a story at Wired about his observations from the recent RSA conference. He noticed that the 350+ vendors who attended the conference were having difficulties selling their products or even communicating with potential buyers. Schneier suggests that the complexity of the security industry is forcing it away from end-users and into the hands of companies who can bundle it with the products that need it. Quoting: "When something becomes infrastructure -- power, water, cleaning service, tax preparation -- customers care less about details and more about results. Technological innovations become something the infrastructure providers pay attention to, and they package it for their customers. No one wants to buy security. They want to buy something truly useful -- database management systems, Web 2.0 collaboration tools, a company-wide network -- and they want it to be secure. They don't want to have to become IT security experts. They don't want to have to go to the RSA Conference."



Inevitable

http://www.pogowasright.org/article.php?story=20080421063410632

From DNA of Family, a Tool to Make Arrests

Monday, April 21 2008 @ 06:34 AM EDT Contributed by: PrivacyNews News Section: Other Privacy News

He was a church-going father of two, and for more than 30 years Dennis Rader eluded police in the Wichita area, killing 10 people and signing taunting letters with a self-styled monogram: BTK, for Bind Torture Kill. In the end, it was a DNA sample that tied BTK to his crimes. Not his own DNA. But his daughter's.

Investigators obtained a court order without the daughter's knowledge for a Pap smear specimen she had given five years earlier at a university medical clinic in Kansas. A DNA profile of the specimen almost perfectly matched the DNA evidence taken from several BTK crime scenes, leading detectives to conclude she was the child of the killer. That allowed police to secure an arrest warrant in February 2005 and end BTK's murderous career.

The BTK case was an early use of an emerging tool in law enforcement: analyzing the DNA of a suspect's relatives. Source - Washington Post


Related?

http://science.slashdot.org/article.pl?sid=08/04/20/1640237&from=rss

Google Invests In Genetic Indexing

Posted by Soulskill on Sunday April 20, @01:24PM from the get-a-NDA-for-your-DNA dept.

Bibek Paudel point us to a BusinessWeek report on Google's interest in the cataloging and analyzing of people's DNA. Google has recently invested in DNA screening firms Navigenics and 23andMe, which test customers' DNA for characteristics such as ancestry and predisposition for certain diseases. The customers are then able to give the information to their doctors. This is not Google's first foray into the medical industry. "Google wants to plant an early stake in a potentially large new market around genetic data. 'We are interested in supporting companies and making investments in companies that [bolster] our mission statement, which is organizing the world's information and making it universally accessible and useful,' Google spokesman Andrew Pederson says. 'We felt it was important to get involved now, at the early stage, to better understand the information generated by this fast-moving field.'"



This works! I tested it on my favorite DU Law professor and found him (and some guy in St. Paul.)

http://www.bespacific.com/mt/archives/018148.html

April 20, 2008

Google News Adds New Quotes Feature

Google News Blog: "As part of Google's mission to organize the world's information, we've been hard at work making quotations in news articles easy to search and browse. You can now more easily keep track of what your favorite politician, actor or sports star is saying. You can even search within their quotes for specific topics. To access these new features, first search for a person's name on Google News. If we have a recent quote, we'll show it above the search results."



Pity the poor lawyers who must now un-learn all that stuff they paid big bucks to learn...

http://news.slashdot.org/article.pl?sid=08/04/20/2232220&from=rss

Court Finds Part of Copyright Act Unconstitutional

Posted by timothy on Sunday April 20, @09:14PM from the small-favors dept.

I Don't Believe in Imaginary Property writes

"A US District Court in the Southern District of California has found the Copyright Remedy Clarification Act to be unconstitutional. That act is what removes the sovereign immunity for infringement that state workers have in their official capacity, something many argued would jeopardize universities with liability for faculty infringement, not to mention other state agencies. In a rather dense legal ruling (PDF), the Court found that the Clarification Act was not a valid exercise of congressional power under the 14th Amendment. For those of you who have absolutely no idea what I just said, I recommend either being glad that a small piece of copyright law may soon bite the dust, or hoping that NYCL will explain this better."



This could be quite useful. (for my web site class)

http://www.killerstartups.com/Web-App-Tools/Feed2Mobilekaywacom---Making-Mobile-Feeds/

Feed2Mobile.kaywa.com - Making Mobile Feeds

... You can make your web content accessible on your mobile device by using Feed2Mobile’s converter to create a mobile feed. It is quite simple, copy and paste the URL of your RSS feed into the blank spot where stated and your mobile feed with be generated.

http://feed2mobile.kaywa.com/



A couple for the e-discovery wizards...

http://www.law.com/jsp/legaltechnology/pubArticleLT.jsp?id=1208169988197

Keeping Your Firm's E-Discovery In-House

There are arguments for managing e-discovery in-house instead of outsourcing it, but it takes a special breed of employee

By Dale Buss Corporate Counsel April 15, 2008


and this one.

http://www.strozllc.com/files/Publication/cb91edfe-09dd-495b-a475-038265b4b838/Presentation/PublicationAttachment/bbd40893-8e79-4f19-93d5-0d61c82756f1/NewElectronicDiscoveryTeamsRolesFunctions.pdf

NEW ELECTRONIC DISCOVERY TEAMS, ROLES, AND FUNCTIONS

Eric Friedberg



For my Statistics class

http://www.bespacific.com/mt/archives/018147.html

April 20, 2008

Households using the Internet in and outside the home, by selected characteristics

National Telecommunications and Information Administration (NTIA): Households using the Internet in and outside the home, by selected characteristics: Total, Urban, Rural, Principal City, October 2007


Ditto

http://www.bespacific.com/mt/archives/018141.html

April 20, 2008

Census Bureau - 2008 Elections

News release, 2008 Elections: "A look at the population, selected characteristics and 2004 voting percentage of each state as it approaches its 2008 primary or caucus."



I like lists (it's an addiction)

http://www.networkworld.com/community/node/27057

25 leading-edge IT research projects

Submitted by Alpha Doggs on Fri, 04/18/2008 – 4:51pm.



For my Computer Security students

http://cups.cs.cmu.edu/antiphishing_phil/

Anti-Phishing Phil

Sunday, April 20, 2008

Once upon a time, this strategy may have worked. In the pre-blog world, a story in the local paper stayed local. Today there is no local, so one wonders why a company doesn't bite the bullet and announce the total extent of the damage in one “swell foop.” (Perhaps they have not read 'The Prince?”)

http://www.pogowasright.org/article.php?story=20080419095610235

Student data compromised (Sungard update)

Saturday, April 19 2008 @ 09:56 AM EDT Contributed by: PrivacyNews News Section: Breaches

More colleges named as being affected by the stolen laptop

Personal data about students from at least three area colleges was compromised after a laptop computer was stolen, officials said Friday.

... About 1,500 people who included Brockport in their financial aid application process were affected. The school is still determining the number of enrolled Brockport students whose information was compromised. A letter will be mailed to these students, according to the statement.

Twenty MCC students had information on the stolen laptop, spokeswoman Cynthia Cooper said. Those students have been notified.

Source - Democrat & Chronicle

PogoWasRight.org editor's note: this was not the first time a laptop containing sensitive data was stolen from an employee of Sungard. The company reported the theft of a laptop from an employee's vehicle in February 2007; that laptop contained financial details. Sungard has not yet responded to questions concerning whether the most recent laptop theft occurred from an employee's vehicle or from some other location, and whether the employee was following corporate policies.


Have you noticed that the reports are moving east to west? Can Denver be far behind?

http://www.pogowasright.org/article.php?story=20080419212738616

Northwestern Michigan College reports data risk (Sungard update)

Saturday, April 19 2008 @ 09:27 PM EDT Contributed by: PrivacyNews News Section: Breaches

Northwestern Michigan College says a laptop computer that was stolen from a company that works with the school may have put the personal information of 1,600 students from 2003 at risk.

The school says Friday that the laptop belonged to a consultant at SunGard Higher Education, which provides NMC's core data management systems.

Source - mlive.com



Another self-serving announcement.

http://www.pogowasright.org/article.php?story=20080419103026287

NY: Retirees' information disappears

Saturday, April 19 2008 @ 10:30 AM EDT Contributed by: PrivacyNews News Section: Breaches

A portable storage device containing sensitive information about 600 Penfield Central School District retirees and retirees' spouses has disappeared from Monroe 1 BOCES.

The Monroe County Sheriff's Office is investigating the disappearance and the people affected have been notified and offered credit monitoring services.

The Penfield district contracts with Monroe 1 BOCES for certain record-keeping services and the missing storage device contains information about 360 retirees' health plans, including names, birthdates and Social Security numbers. Officials noticed that the device was missing on Thursday.

Source - Democrat & Chronicle

[From the article:

So far, BOCES has not heard of any complaints from retirees about their identities being stolen.

"To our knowledge, there has been no unauthorized use of the information," said Walker. [Apparently the PR flacks have no idea how ignorant this kind of statement makes them seem. Bob]



Oh boy, thanks Carnegie Mellon Research guys... (Automation takes all the fun out of hacking.)

http://www.cs.cmu.edu/~dbrumley/pubs/apeg.html

Automatic Patch-Based Exploit Generation

David Brumley, Pongsin Poosankam, Dawn Song, and Jiang Zheng

... What does this mean?

Attackers can simply wait for a patch to be released, use these techniques, and with reasonable chance, produce a working exploit within seconds. Coupled with a worm, all vulnerable hosts could be compromised before most are even aware a patch is available, let alone download it.



All terrorists breathe. You are breathing. You must be a terrorist!

http://blog.aclu.org/index.php?/archives/628-You,-With-the-Camera!-Stop-Acting-Suspicious!.html#comments

Friday, April 18, 2008

You, With the Camera! Stop Acting Suspicious!

Mike German, a former FBI agent who currently works as policy counsel for our Washington, D.C. office, wrote in our DailyKos Diary about how local law enforcement agencies across the country are gathering a curious kind of domestic intelligence on citizens, all in the name of, you guessed it, national security:

The Wall Street Journal and the Los Angeles Times both reported on the Los Angeles Police Department’s extensive list of "criminal and non-criminal" behaviors, which LAPD officers are instructed to report as "suspicious activities." The list includes such innocuous, clearly subjective and First Amendment protected activities as "taking pictures or video footage with no apparent esthetic value," "drawing diagrams and taking notes," "espousing extremist views," and "engaging in suspected coded conversations or transmissions."



That which is technically true is not always strategically wise.

http://www.pogowasright.org/article.php?story=20080419214504745

AU: Approval not needed for cancer data: Qld

Saturday, April 19 2008 @ 09:45 PM EDT Contributed by: PrivacyNews News Section: Non-U.S. News

Queensland's Health Minister Stephen Robertson says his department has found a way avoid a court battle [I wonder what odds they're giving in Vegas? Bob] with the cancer council over access to data.

Mr Robertson on Sunday said the Cancer Council Queensland would be able to get data from the state's cancer registry to researchers without the approval of the health authority and without breaching patient confidentiality.

The Cancer Council on Friday launched legal action in the Supreme Court against Queensland Health seeking routine access to cancer statistics from the registry.

Source - The Daily

[From the article:

Mr Robertson on Sunday said he was advised the council could share registry data with researchers with only minor changes to the current contract between the council and Queensland Health. [But no details were given Bob]



For my Computer Security students. The opposite of e-discovery?

http://www.bespacific.com/mt/archives/018137.html

April 18, 2008

Computerworld Guide to Removing Data From Your Hard Drive

"With stories surfacing on news channels regularly about lost or stolen data or the ability to recover data from discarded or resold computers and their hard drives, Computerworld decided to look at some cheap methods of removing that sensitive data from your hard drive permanently. And, what better place to look than YouTube?"



Using technology. Sounds good to me. (Has policy kept pace with this reality?)

http://yro.slashdot.org/article.pl?sid=08/04/19/2343210&from=rss

British Police Use Facebook to Gather Evidence

Posted by timothy on Sunday April 20, @03:39AM from the nothing-at-all-creepy-about-that dept. Privacy Social Networks

Amy Bennett writes

"Move over police scanner and most-wanted poster. The Greater Manchester Police force has created a Facebook application to collect leads for investigations. The application delivers a real-time feed of police news and appeals for information. A 'Submit Intelligence' link takes a Facebook user to the police Web site where they can anonymously submit tips. Another link leads to the videos on YouTube featuring information on the police force, ongoing investigations and other advisories."

As reader groschke writes, though,

"Their access to user data raises significant civil liberties problems. They may be able to see more of your data than your friends or network members can — and you also expose your friends' data when you add the application. All without needing a subpoena or warrant."



As goes computers, so goes DNA? (see next article)

http://www.pogowasright.org/article.php?story=20080419214912380

Computer searches as 21st Century general warrants

Saturday, April 19 2008 @ 09:49 PM EDT Contributed by: PrivacyNews News Section: Internet & Computers

I was reading a child porn computer search case today, posted elsewhere, that again made me think about how easy it is for police to put in a search warrant application that they want to search for a computer. So, let me go on a little about the need for computer searches just because there is a computer in the placed to be searched:

What is the "nexus" of the computer to the evidence to be sought, practically, realistically, and actually? Is it hypothetical or real? Even if it is hypothetical, is that enough to get over the good faith exception? The case law is not all that helpful. Basic search principles lead to one result, but computer searches almost seem to be in the process of subconsciously trying to divide off into their own little world so they become subject to different rules. If it happens, it is result oriented jurisprudence that fails to adhere to basic Fourth Amendment principles. If Kyllo’s thermal imaging is governed by basic Fourth Amendment rules applied to new technology, then why are not computer searched governed the same way? There is no way that they should not be. (The DOJ computer search manual is listed on the right margin.)

Source - FourthAmendment.com blog


Here comes a battle... Interesting article.

http://www.pogowasright.org/article.php?story=20080420062336881

DNA Tests Offer Deeper Examination Of Accused

Sunday, April 20 2008 @ 06:23 AM EDT Contributed by: PrivacyNews News Section: In the Courts

Twenty years after DNA fingerprints were first admitted by American courts as a way to link suspects to crime scenes, a new and very different class of genetic test is approaching the bench.

Rather than simply proving, for example, that the blood on a suspect's clothes does or does not match that of a murder victim, these "second generation" DNA tests seek to shed light on the biological traits and psychological states of the accused. In effect, they allow genes to "testify" in ways never before possible, in some cases resolving long-standing legal tangles but in others raising new ones.

Source - Washington Post

[From the article:

Already, chemical companies facing "toxic tort" claims have persuaded courts to order DNA tests on the people suing them, part of an attempt to show that the plaintiffs' own genes made them sick -- not the companies' products.

In other cases, defense attorneys are asking judges to admit test results suggesting that their clients have a genetic predisposition for violent or impulsive behavior, adding a potential "DNA defense" to a legal system that until now has held virtually everyone accountable for their actions except the insane or mentally retarded.

Some gene tests are even being touted for their capacity to help judges predict the likelihood that a convict, if released, will break the law again -- a measure of "future dangerousness" that raises questions about how far courts can go to abort crimes that have not yet been committed.



For the medicos

http://dsc.discovery.com/tv/human-body/explorer/explorer.html

Human Body Explorer



Well, it is a change. All change evokes resistance (fear)

http://entertainment.slashdot.org/article.pl?sid=08/04/19/1842208&from=rss

Dilbert Goes Flash, Readers Revolt

Posted by timothy on Saturday April 19, @04:06PM from the please-please-please-mr.-adams-pleeaaaase-no dept. It's funny. Laugh. The Internet The Media Entertainment

spagiola writes

"The Dilbert.com website just got an extreme makeover. Gone is the old, rather clunky but perfectly functional, website, replaced by a Flash-heavy website that only Mordac the Preventer of Information Services could love. Users have been pretty unanimous in condemning the changes. Among the politer comments: 'Congrats. Vista is no more lonely at the top in the Competition For The Worst Upgrade In Computing Industry, this web site upgrade being a serious contender.' You have to register to leave comments, but many seem to have registered for the express purpose of panning the new design."



I was once a Chemistry major so this caught my eye... Hope it is not too technical for you.

http://www.writeidea.org/2008/04/governmentium-described-as-element-on.html

Saturday, April 19, 2008

Governmentium - Described as an Element on Periodic Table

The element, Governmentium (Gv),

Research has led to the discovery of the heaviest element yet known to science. The new element, Governmentium (Gv), has one neutron, 25 assistant neutrons, 88 deputy neutrons, and 198 assistant deputy neutrons, giving it an atomic mass of 312.

These 312 particles are held together by forces called morons, which are surrounded by vast quantities of lepton-like particles called peons. Since Governmentium has no electrons, it is inert; however, it can be detected, because it impedes every reaction with which it comes into contact. A minute amount of Governmentium can cause a reaction that would normally take less than a second to take from four days to four years to complete.

Governmentium has a normal half-life of 2- 6 years; It does not decay, but instead undergoes a reorganization in which a portion of the assistant neutrons and deputy neutrons exchange places. In fact, Governmentium's mass will actually increase over time, since each reorganization will cause more morons to become neutrons, forming isodopes. This characteristic of moron promotion leads some scientists to believe that Governmentium is formed whenever morons reach a critical concentration. This hypothetical quantity is referred to as critical morass.

When catalyzed with money, Governmentium becomes Administratium, an element that radiates just as much energy as Governmentium since it has half as many peons but twice as many morons.