Tuesday, April 29, 2008

At first glance, I wondered why they even reported the loss of encrypted data. This is small potatoes, but an interesting twist on obfuscation...

http://www.pogowasright.org/article.php?story=20080428184852570

Concord Regional Visiting Nurse Association reports laptop stolen

Monday, April 28 2008 @ 06:48 PM EDT Contributed by: PrivacyNews News Section: Breaches

The Concord Regional Visiting Nurse Association reported [pdf] to the New Hampshire Department of Justice that a laptop was stolen from a staff member’s vehicle on April 16. The laptop contained birth date and social security numbers for 15 clients.

CRVNA believes that the risk of ID theft is low because of the three layers of security protection used, including encryption.

[The report actually states that the third password was stored in encrypted form – the file itself was unencrypted. Therefore there was no real protection for the data. Bob]



Sub-optimal security from a sub-prime mortgage company? Who'd-a thunk it?

http://www.pogowasright.org/article.php?story=20080428174713905

CO: Hundreds Of Mortgage Files Found In Dumpster

Monday, April 28 2008 @ 05:47 PM EDT Contributed by: PrivacyNews News Section: Breaches

The Arapahoe County District Attorney's Office is advising anyone who has used Cove Creek Mortgage to watch out for identity theft after hundreds of mortgage files were dumped in a public trash bin over the weekend.

Cove Creek's owner had abandoned his Englewood office in January and property managers had not been able to find him, investigators said. On Saturday, the property manager cleaned out his office and put all items from the office -- including complete mortgage files -- into two Dumpsters.

Source - The Denver Channel

[From the article:

David Peters who works in the same complex found the files Monday morning.

"I was taking some other trash out to the garbage can and opened the lid and on there was a couple of laptops," said Peters. "Directly underneath them were files with people's names on it and was like, well this is not right." [Like, well said, Dude! Bob]

... While there are civil laws against dumping such documentation, Chambers said it is not against the law. [Okay, I'm gonna need a lawyer to explain that statement. Bob]



Tools & Techniques

http://news10now.com/content/all_news/115046/police-investigate-multi-state-credit-card-scam/Default.aspx

Police investigate multi-state credit card scam

Updated: 04/28/2008 06:34 PM By: Iris St. Meran

HERKIMER, N.Y. -- Herkimer police have confiscated nearly 100 gift cards and debit cards as well as other items that were taken from Wal-Mart stores on April 8th.

"We were called to the Wal-Mart store regarding suspicious activity involving debit cards and or credit cards. The person was trying to swipe several different cards to obtain a gift cards," said Herkimer Police Investigator Robert Risi.

This resulted in the arrest of Alex Prime and Quincy Thompson both of Brooklyn, New York. Police say the credit and debit card information was taken from around the country and used in the Wal-Mart stores in Rome and Herkimer to buy mostly electronic products.

"During the course of our investigation we found that the back of the debit cards were altered with credit card information that was stolen. We don't know where from, they were stolen but that credit card information was placed on the back of the debit card magnet strip," said Risi.

In order to get a card holder's account information, a device called a skimmer is used. It's about the size of cell phone. A person can just swipe a credit card and have the personal information they need. [Can I get one on e-Bay? Bob]

"The information is then downloaded off the skimmer into a computer and they have the technology to take that information and put it on the magnetic strip of a gift card," said Herkimer Police Captain Scott Scherer.

Herkimer Police say this is the largest fraud investigation they have seen in the area and that Wal-Mart has reported nearly $900,000 lost in merchandise. [At these two stores? Bob] Wal-Mart declined comment during the investigation.

The FBI, Secret Service and U.S. Postal service as well as other police departments are assisting in this investigation.



Another risk of television? “Instead of pulse rate, we get re-runs of 'I Love Lucy'”

http://www.news.com/8301-10784_3-9930441-7.html?part=rss&subj=news&tag=2547-1_3-0-5

Hospital techies urge limits on 'white space' Wi-Fi

Posted by Anne Broache April 28, 2008 2:00 PM PDT

About a decade ago, wireless heart monitors hooked to patients at Baylor University Medical Center in Dallas went on the fritz, causing much scrambling among the building's engineering team.

The culprit, as it turned out, was interference from a nearby broadcast television station, which was testing its digital signal on the same channel where some of the medical devices operated, as detailed in the journal Biomedical Instrumentation & Technology a few years ago. The Federal Communications Commission ultimately cordoned off spectrum just for that purpose, although migrating there was largely voluntary.

Now, hospital administrators and medical device manufacturers fear similar problems could happen again if federal regulators don't place limits on requests by Google, Microsoft, and other high-tech companies to free up spectrum "white spaces" between television channels.



What happens when you just don't trust your government... No doubt encryption vendors will now claim their products offer a green alternative to flying...

http://yro.slashdot.org/article.pl?sid=08/04/29/003253&from=rss

Lawyers Would Rather Fly Than Download PGP

Posted by kdawson on Monday April 28, @08:19PM from the fly-once-to-exchange-keys dept. Privacy Encryption The Courts Politics

An anonymous reader writes

"The NYTimes is running a front-page story about lawyers for suspects in terrorism-related cases fearing government monitoring of privileged conversations. But instead of talking about the technological solutions, the lawyers fly halfway across the world to meet with their clients. In fact, nowhere in the article is encryption even mentioned. Is it possible that lawyers don't even know about PGP?"

The New Yorker has a detailed piece centering on the Oregon terrorism case discussed by the Times.



Interesting comments on this “military justice blog” and a good set of links...

http://www.pogowasright.org/article.php?story=20080428092427548

Government computers and expectation of privacy

Monday, April 28 2008 @ 09:24 AM EDT Contributed by: PrivacyNews News Section: In the Courts

In the first part of its opinion in United States v. Larson, __ M.J. ___, No. 07-0263/AF (C.A.A.F. Apr. 25, 2008), CAAF rather easily rules that an Air Force major had no expectation of privacy in his government computer, which he used to set up a rendez-vous with a civilian police detective who was posing on the computer as a 14-year-old girl and on which pornographic images were stored. The computer was located in a private office assigned to Major Larson and the office was capable of being locked. "[B]ut other Air Force personnel, including the fire department and the command's facility manager also had keys to his office." Id., slip op. at 5. The computer itself was government property that had been provided to Major Larson "to accomplish official business." Id. Major Larson "could secure the computer with a personal password, but a system administrator could still access the computer." Id. [There is a trend to have employees purchase and use their own computers. This could be interesting... Bob] When Major Larson "logged on to the computer, he was required to click a button accepting conditions listed in a banner, which stated that the computer was Department of Defense property, was for official use, and that he consented to monitoring." Id., slip op. at 5-6. "The military judge found that, while Appellant 'reasonably understood that he was allowed to send personal e-mail or visit the internet as long as it didn't interfere with [his] duties,' this did not change the fact that the government owned the computer and had a right to access it." Id., slip op. at 6.

Source - CAAFlog

[From the article:

The actual practices of the network administrator may either support or refute a reasonable expectation of privacy. See Larson, slip op. at 10. [This is scary. Your prosecution or defense could rest on the understanding of entry level employee... Bob]



How could I resist an article with this title?

http://www.technewsworld.com/rsstory/62779.html?welcome=1209472608

The Art of Cyber Warfare, Part 1: The Digital Battlefield

By Jack M. Germain TechNewsWorld 04/29/08 4:00 AM PT

Computer network attacks are often perpetrated by gangs of criminal hackers attempting to break into a system for financial gain. However, cyber attacks for political purposes could just as easily be -- and sometimes are -- perpetrated. A country's national security could be severely threatened should a team of hackers successfully crack certain computer systems.

... FBI reports from last year show that 108 countries have dedicated cyber attack capabilities, he added. Kellerman also serves on the Commission on Cyber Security for the 44th Presidency and is a former senior data risk management specialist for the World Bank Treasury Security Team.

... Beginning April 27, 2007, about 1 million computers worldwide were reportedly used to conduct denial-of-service attacks on Estonian government and corporate Web sites. Over a three-week period, the attacks swamped Estonia's computer network with so much traffic that the government there was forced to shut them down. [Imagine a similar outcome with the attack limited to Wall Street... Bob]


Related?

http://www.bespacific.com/mt/archives/018206.html

April 28, 2008

Law Enforcement Strategy to Combat International Organized Crime

News release: "Attorney General Michael B. Mukasey announced a new strategy in the fight against international organized crime that will address this growing threat to U.S. security and stability. The Law Enforcement Strategy to Combat International Organized Crime (the strategy) was developed following an October 2007 International Organized Crime Threat Assessment (IOC Threat Assessment) and will address the demand for a strategic, targeted and concerted U.S. response to combat the identified threats. This strategy builds on the broad foundation the Administration has developed in recent years to enhance information sharing, and to secure U.S. borders and financial systems from a variety of transnational threats."



I thought SCO was dead months age.

http://yro.slashdot.org/article.pl?sid=08/04/29/1141231&from=rss

SCO v. Novell Goes to Trial Today In Utah

Posted by timothy on Tuesday April 29, @08:41AM from the smell-of-napalm-in-the-morning dept.

I Don't Believe in Imaginary Property writes "The day many have been waiting for has finally arrived, the day SCO gets torn apart in court by Novell. Each side gets 10 hours, and Novell managed to get them to agree to a stipulation (PDF) that should make things go a lot faster. With any luck, we will soon have an official ruling that SCO does not own much of anything and then we just have to wait for SCO to exhaust its appeals. This would've been over a long time ago, but SCO filed for bankruptcy on the eve of trial, stopping the clock. One can only wonder what trick they will try to pull this time."



Backgrounder... Why social networks are important.

http://www.techcrunch.com/2008/04/28/morgan-stanleys-march-internet-trends-report-social/

Morgan Stanley’s March Internet Trends Report: Social Applications Dominating

Michael Arrington April 28 2008

[From the Key takeaways:

  • YouTube + Facebook page views > Google or Yahoo page views (and may be bigger than both combined)

  • 6/10 top internet sites are social (youtube, live.com, facebook, hi5, wikipedia, orkut); none were on the list in 2005

  • >50% of Facebook users log in daily, 95% of Facebook users have used at least one third party application

  • 14 million photos uploaded daily on Facebook [Still hard to find the truly incriminating ones... Bob]

  • Google + Yahoo = 61% of U.S. Online Ad Revenue



Most interesting because of their first “do not use” recommendation – Adobe Reader. That;s not the only pakage you might be using...

http://lifehacker.com/384545/superior-alternatives-to-crappy-windows-software

Superior Alternatives to Crappy Windows Software

... it's time to replace stinky Windows software with its superior (but lesser-known) alternative.



Interesting that the author views this as a genealogy source...

http://www.researchbuzz.org/wp/2008/04/28/what-happened-at-the-old-bailey/

What Happened At the Old Bailey?

28th April 2008, 10:40 pm

If you have English ancestry, an interest in your family’s history, and some patience, do I have a site for you. It’s a Web site aggregating the proceeding of the trials at the Old Bailey (the Central Criminal Court in England) from 1674-1913. This site covers almost 200,000 trials.

http://www.oldbaileyonline.org/index.jsp



Perhaps they don't teach “the logic of the Internet” in Law School?

http://techdirt.com/articles/20080428/194905972.shtml

RIAA Now Decides That Not Enough People Have Heard Of Project Playlist

from the reverse-attention-whores dept

There they go again. The RIAA and MPAA keep picking totally random, mostly unknown, startups and suing them -- giving them all sorts of free publicity. They did it years ago with Napster and more recently with The Pirate Bay. And yet... they keep doing it. In the latest example, the RIAA is suing a company called Project Playlist, which offers apps for MySpace and Facebook that let you play music found elsewhere online. There are a bunch of similar offerings out there (some of which I think are even more well known). If this case goes forward, it could be quite interesting, as again it's hard to see how Project Playlist is the liable party. It just lets users point its player to mp3 files that are found on other sites. Those files may be infringing, but Project Playlist is just the player. It would be like suing Sony for making a Walkman on the assumption that most tapes used in Walkmen include infringing copies of songs.



There are worse things than driving while talking on a cell phone...

http://news.yahoo.com/s/afp/20080428/od_afp/francetransportroadoffbeat_080428160657;_ylt=AsuwTTk49y11A7uxfiyPwH.s0NUE

French police stop video-watching man driving at 200 km an hour

Mon Apr 28, 12:06 PM ET

French police said Monday they had caught a man driving on a motorway at 200 kilometres (125 miles) an hour while watching a video.

The 21-year-old was watching the video on a mobile viewer placed on the dashboard of his vehicle when police stopped him Sunday on the highway near the western city of Tours, police said.

... Police impounded his car and confiscated his licence while he awaits a court appearance.

Monday, April 28, 2008

1) If you only improve your security, have you shifted the liability to others? 2) Is that a reasonable strategy or should “protecting our customers” be in there somewhere?

http://www.pogowasright.org/article.php?story=20080428071107198

(follow-up) Paying breach bill may not buy Hannaford full data protection

Monday, April 28 2008 @ 07:11 AM EDT Contributed by: PrivacyNews News Section: Breaches

Hannaford Bros. Co. said last week that it expects to spend "millions" of dollars on IT security upgrades in response to the the recent theft of up to 4.2 million credit and debit card numbers from its systems.

Some of the new measures that the grocer outlined go beyond the controls mandated by the Payment Card Industry Data Security Standard, or PCI. But it isn't clear whether they actually will address the issues that led to the data breach.

Source - Computerworld

[From the article:

Huguelet said that the planned end-to-end encryption of card data also sounds good — on paper. But to make the data hacker-proof, he added, it would have to be encrypted from the PIN entry devices in stores to the systems of the payment-processing firm that authorizes card transactions.

And because almost no payment processors accept encrypted data at this point, Hannaford would likely need to convince the firm it works with to make system changes as well.

Similarly, Hannaford's decision to replace all of its existing PIN entry devices puts it ahead of the curve in meeting a PCI mandate that companies must start using models with built-in support for Triple DES by July 2010.

But in most cases, the Triple DES technology encrypts only a customer's PIN, according to Huguelet. So even if Hannaford was already using such devices, it's unlikely that they would have prevented the card numbers from being compromised, he said.

Litan views Hannaford's plan to bolster its network defenses via the use of intrusion-prevention systems as another step in the right direction. But she said there are indications that the breach may have been the handiwork of a rogue insider — in which case the intrusion-prevention tools probably wouldn't have helped stop the attack.



...because...

http://www.pogowasright.org/article.php?story=20080428065836714

Data “Dysprotection:” breaches reported last week

Monday, April 28 2008 @ 07:10 AM EDT Contributed by: PrivacyNews News Section: Breaches

A recap of incidents or privacy breaches reported last week for those who enjoy shaking their head and muttering to themselves with their morning coffee.

Source - Chronicles of Dissent



“Don't tell us what could go wrong, wait until the e-chad hang, then tell us what we could have done to prevent it...”

http://techdirt.com/articles/20080426/142226957.shtml

New Jersey Court Says Independent Investigators Can Review E-Voting Machines

from the protect-the-vote dept

Last month, e-voting firm Sequoia threatened both independent researchers and New Jersey election officials if those independent researcher were allowed to inspect Sequoia's e-voting machines. This seemed like a very odd threat for a variety of reasons. Why wouldn't Sequoia want its machines inspected? The very fact that it was threatening legal action seemed like grounds to simply never use Sequoia e-voting machines. Sequoia claimed that existing inspections were enough, despite a history of problems in those inspections. Furthermore, Sequoia's own explanations for the problems with its machines in the primary elections this year were wrong. Ed Felten found that Sequoia's explanations didn't actually explain many of the problems. Unfortunately, though, with the threat of legal action, New Jersey agreed not to have Felten test the machines.

However, a New Jersey state judge has now ruled that it's perfectly reasonable for independent inspectors to review the machines. Unfortunately, she pushed back the date for such inspections until September, meaning that it won't affect this year's presidential election -- which will still use machines that may have problems. So while Sequoia didn't succeed in stopping independent examination of its machines, it did stall the process long enough so that the existing machines will stay in use for this year's elections -- despite the long list of problems that have been discovered with them. Apparently, we're still in beta when it comes to democracy.



Do they “get it?”

http://www.nytimes.com/2008/04/28/technology/28ecom.html?_r=1&ex=1367035200&en=4b3a478845a3ea12&ei=5088&partner=rssnyt&emc=rss&oref=slogin

Users Demand Expertise at How-To Web Sites

Article Tools Sponsored By By BOB TEDESCHI Published: April 28, 2008

IF the Internet can make anyone a star, can it turn Barnes & Noble into one, too?

The bookseller has taken another step beyond its traditional business into the online publishing world, recently introducing Quamut.com, a site that teaches Web users things as diverse as the basics of football and how to build a Web site.

... Quamut differentiates itself from the long list of how-to sites like eHow, HowStuffWorks.com and, to a lesser degree, About.com (which is owned by The New York Times Company), with a somewhat novel twist: selling downloadable documents of its otherwise free content.


Some “expertise” isn't fully appreciated...

http://www.bespacific.com/mt/archives/018198.html

April 27, 2008

EU Backs Criminalizing Posting Bomb Making Instructions on Web

European Digital Rights: "The European Ministers of Justice and Internal Affairs have agreed to make publishing bomb-making instructions on the Internet a crime...Justice and interior ministers from the EU member states backed a proposal from Commissioner Frattini to harmonise the normative acts that will make the "public provocation to commit a terrorist offence, recruitment, and training for terrorism" a crime. According to the statements of the EU officials publishing these acts on the Internet completed the European legislation in this domain. They described the Internet as "a virtual training camp for militants, used to inspire and mobilise local groups." Gilles de Kerchove, the EU anti-terrorism co-ordinator, declared that there are approx. 5,000 websites that are used to radicalise young people."



Interesting talk at the Berkman Center

http://tech.slashdot.org/article.pl?sid=08/04/27/1422258&from=rss

Mining the Cognitive Surplus

Posted by kdawson on Sunday April 27, @02:28PM from the looking-for-the-mouse dept.

Clay Shirky has been giving talks on his book Here Comes Everybody — his "masterpiece," per Cory Doctorow — and BoingBoing picks up one of them, from the Web 2.0 conference. Shirky has come up with a quantification of the attention that TV has been absorbing for more than half a century. Shirky defines as a unit of attention "the Wikipedia": 100 million person-hours of thought. As a society we have been burning 2,000 Wikipedias per year watching mostly sitcoms. We're stopping now. Here's a video of another information-dense Shirky talk, this one at Harvard.



Another column on e-discovery, with some interesting links...

http://ralphlosey.wordpress.com/2008/04/26/e-discovery-at-the-harvard-club-in-new-york-city/

e-Discovery at the Harvard Club in New York City

[I had never heard of the Legal Electronic Document Institute for instance http://www.gulfltc.org/ Bob]



I wonder if anyuone in Congress has heard of these?

http://blog.lib.umn.edu/lawlib/lexlibris/2008/04/congressional_research_video_t.html

Congressional Research: Video Tutorials

The University of California at Berkeley has created several video tutorials that demonstrate how to do Congressional research in the following areas, each of which is highly useful for law students:

Finding bills and Congressional debates from 1989 forward on Thomas

Finding a Congressional report on LexisNexis Congressional

Finding debates from 1873 to the present in print in the Congressional Record.

Note that the video tutorials last from two to five minutes apiece, and that they require Macromedia’s Flash player to be installed on your computer.



Sometimes it's hard to tell the difference between good legal research and great legal research. Here is one or the other from Stephen Rynerson

http://www.bbspot.com/News/2008/04/top-11-privacy-policy.html

Lines You Don't Want to See in a Privacy Policy

11. No one will have access to your data, not even my brother-in-law in the Russian mafia.

10. We collect personal information including pages visited and time spent on pages. Also a man will be around tomorrow to collect your fingerprints, a vial of urine and a DNA sample.

9. Sharing is caring. We care about your privacy.

8. We do not ask children under 13 for personal information, but we wouldn't mind if they sent us pictures.

7. Your credit card information will be securely stored using our patented ROT-26 encryption.

6. We reserve the right to use any pictures we may have obtained from your unsecured webcam.

5. We limit access to your personal information to anyone in our company with a computer and an Internet connection.

4. We will not sell your personal information unless offered money for it.

3. Just because we don't share your private information doesn't mean our spyware won't.

2. If an employee from our company shows up at your door with flowers, he certainly didn't get the information from us.

1. We're doing a heckuva job protecting your privacy.

Sunday, April 27, 2008

Is this another SunGard victim or a duplicate story. Hard to remember.

http://www.pogowasright.org/article.php?story=20080426160154124

MS: Stolen Laptop Could Expose Former Students to ID Theft (Sungard update)

Saturday, April 26 2008 @ 04:01 PM EDT Contributed by: PrivacyNews News Section: Breaches

A laptop containing personal information of former Meridian Community College students has been stolen.

The laptop was stolen on Mar. 13 in New York state from an employee of SunGard Higher Education, a software company that provides IT services for MCC and dozens of other colleges nationwide.

... Officials say they don't believe that identity theft was the reason for the incident, but they say among the information on the computer were the Social Security numbers of former students at the school.

Source - WTOK

[Fron SunGard's web site http://www.sungardhe.com/about/news/PressReleases/Article.aspx?id=3422

A laptop containing personally identifiable information was stolen from a SunGard Higher Education employee on March 13, 2008.

... “Upon notification of the theft, we commenced a series of diagnostic procedures to determine whether the laptop contained personally identifiable information. [We had no idea what was on that laptop... Bob]

We notified impacted customers of our findings commencing April 9, 2008 [It took us damn near a month to find out what customers were involved... Bob]

Our investigation continues and our security specialists remain focused on analyzing the files to determine if additional individuals or institutions have been affected. [There may be others, we can't tell,,, Bob]

[They also set up an “Incident Specific” web page: http://www.sungardhe.com/custom.aspx?id=1554

... the stolen laptop contained data from projects with a number of customers.

... The nature of that employee’s job included analysis of customer data as part of software implementation and upgrade projects. [“Before we can upgrade the software you have been using with your data, we'll need a copy of your data to see if it works with our software.” Isn't that what they are saying? Bob]



Oh, so that's okay then? What a great addition to management science!

http://news.yahoo.com/s/nm/20080425/tc_nm/wholefoods_sec_dc;_ylt=AuCwQTP7i1L1RAb4C7l3jyas0NUE

Whole Foods says SEC concludes message board probe

Fri Apr 25, 5:36 PM ET

Whole Foods Market (WFMI.O) said on Friday that Securities and Exchange Commission staffers have concluded a probe into its chief executive's anonymous Web chat room messages about then-rival Wild Oats Markets and recommended no action be taken.

Whole Foods said in July 2007 it had received an SEC inquiry related CEO John Mackey's anonymous postings on a Yahoo Inc chat forum. Mackey for years used an alias when he posted positive comments about Whole Foods and critical comments about rival Wild Oats, which his company later acquired.



Is this an indication that the story is going mainstream or is it just “one of those funny articles?”

http://news.slashdot.org/article.pl?sid=08/04/27/0030217&from=rss

Business Week Takes On the RIAA

Posted by kdawson on Sunday April 27, @08:05AM from the palpable-hit dept. The Courts The Media

NewYorkCountryLawyer writes

"Business Week magazine has gone medieval on the RIAA, recounting in grisly detail the cruel ordeal to which the RIAA has subjected a completely innocent defendant, Tanya Andersen of Oregon. Nobody can read the story and come to any other conclusion than that the RIAA and its lawyers are total jerks. Of course we've been reading about Atlantic v. Andersen on p2pnet.net and on my blog, and discussing it here, but there's something extra special about a mainstream publication like Business Week really letting them have it."



Another one of those “it's free, so it can't possibly succeed” type of sites?

http://www.flatworldknowledge.com/minisite/

Flat World Knowledge

Our books are free online. We offer convenient, low-cost choices for students – print, audio, by-the-chapter, and more. Our books are open for instructors to mix, mash, and make their own.

Site is info only. We're coming January 2009!



Simple game to test your motor skills

http://www.hurtwood.demon.co.uk/Fun/copter.swf

Saturday, April 26, 2008

Close to home

http://www.pogowasright.org/article.php?story=20080425172046118

CU-Boulder Alerting Students And Faculty In Wake Of Compromised Continuing Education Computers

Friday, April 25 2008 @ 05:20 PM EDT Contributed by: PrivacyNews News Section: Breaches

The University of Colorado at Boulder today announced that it discovered three computers in the Division of Continuing Education and Professional Studies were compromised and that one of the computers contains private data (i.e. names, Social Security numbers, addresses, grades) of approximately 9,000 students and approximately 500 instructors.

Although at this time there is no reason to believe that the data on the computer has been accessed, the university will be contacting the affected students and instructors to provide guidance about how to protect their identities.

An analysis of the data compromise is being conducted by a computer forensics firm hired by the university. While this analysis is still in progress, it is believed that this data compromise affects some students who were enrolled in Division of Continuing Education and Professional Studies courses between 1997 and 2003, as well as some instructors employed by the division. The university will mail letters to affected parties by the end of next week.

Source - University of Colorado - Boulder



First words form SunGard?

http://www.pogowasright.org/article.php?story=20080425174507145

Sungard still assessing the scope of breach (update)

Friday, April 25 2008 @ 07:08 PM EDT Contributed by: PrivacyNews News Section: Breaches

As of today, Sungard Higher Education was continuing to investigate and analyze the incident involving a laptop stolen from one of their employees. The total number of clients and individuals who had personal information on the laptop is not yet known. Some more new details did emerge today, however.

In contrast to many recents breaches where a laptop was stolen from an employee's vehicle or home, the Sungard laptop was stolen from an employee while the employee was working at a customer site. [That may complicate liability, but the solution is the same. Encryption. Bob] According to a spokesperson, the employee was not following company policies. In a statement provided to PogoWasRight.org, Laura Kvinge, Senior Director of Communication, wrote, "SunGard Higher Education has strict policies for data retention and the handling of sensitive customer information. In this case that policy was not followed."

In order to assist their customers, and in addition to the web site and FAQ they created quickly to respond to the situation, Sungard is offering one year of credit monitoring membership for all affected individuals. In an effort to alleviate the number of calls that the institutions would otherwise have to handle, Sungard has also created a help desk to personally answer calls and assist individuals.

According to Ms. Kvinge, Sungard also offered to assist with the entire notification process, including the production and mailing of notification letters as the institution deems appropriate.

"This incident is a serious matter for SunGard Higher Education. We realize that this challenges the relationship of trust we have built with our customers and we are going to have to work very hard to gain that back."



How to handle the fallout from a security breach? (Remember the “Streisand Effect”)

http://techdirt.com/articles/20080424/194340942.shtml

LendingTree Pressures Blogger To Remove Comments

from the section-230-anyone? dept

You may have heard the story earlier this week about how LendingTree had a security breach as employees were apparently handing out company passwords to mortgage firms, allowing them to access customer data directly. [Not in the articles I read... Bob] LendingTree is now suing the mortgage firms involved. However, LendingTree is apparently trying to crack down on some of the discussion about all of this. On one blog that wrote about the story, a commenter left a comment alleging that LendingTree doesn't actually "let banks compete" but has its own lending center -- which seems to be based on a class action lawsuit that was filed against LendingTree a couple years ago.

However, LendingTree is now putting pressure on bloggers to remove such comments, mentioning that they're defamatory. Of course, thanks to section 230 of the CDA, a blogger is not responsible for defamatory content left by others (they are still responsible for their own defamatory content, of course). While it doesn't appear that LendingTree's legal notes have entirely reached the level of a cease & desist (more like a legalistic nudge), it does sound like they've convinced some other bloggers to remove content that need not be removed. And, of course, by claiming that the content is defamatory, it may scare some bloggers who don't understand their section 230 safe harbors to feel obligated to remove the content.



A mere amateur. The pros were intercepting the wireless signals from another building...

http://techdirt.com/articles/20080425/122243949.shtml

If Top Gov't Officials Need To Leave Blackberries Outside A Meeting, Shouldn't Someone Guard Them?

from the just-a-thought dept

Apparently a Mexican press attache at a meeting with White House officials in New Orleans saw an opportunity and swiped the Blackberries of a bunch of White House staffers. At many such meetings, it's required for attendees to leave their phones and mobile devices outside of the meeting room. You would think that with such high-powered government officials that someone would then be left to guard the devices, but apparently not. This guy grabbed a bunch of the devices and made a run for the airport, where he was caught by Secret Service officials, who promptly showed him the surveillance camera footage of him taking the devices. His response was that he thought the devices had been left behind, and he was merely picking them up to return them to their owners, which might be more believable if the folks weren't still in the meeting room when he grabbed all the devices. Who knows if it's true, but I'm still wondering why no one was guarding the Blackberries.



CyberWar For my Security students

http://news.bbc.co.uk/2/hi/technology/7366995.stm

Page last updated at 13:48 GMT, Friday, 25 April 2008 14:48 UK

Hackers warn high street chains

High street chains will be the next victims of cyber terrorism, some of the world's elite hackers have warned.

... "If someone wants to have a pop at the UK, they are unlikely to go for the government web servers. They will go for the lower hanging fruit - companies which are seen as good representatives of the country.



Moving into the 21st Century... Blogging done right!

http://techdirt.com/articles/20080425/020649944.shtml

Beer, Blogs And Bias

from the i'll-drink-to-that dept

The Wall Street Journal has an article focusing on a blog set up by Miller Brewing Company called Brew Blog. There are a few different, interesting points worth discussing here. First, the blog isn't used as a blog about what's going on at Miller Brewing. Instead, Miller hired an experienced reporter, and told him to just cover the beer industry as if he were a beat reporter. In other words, it's reporting news -- and even breaking stories on the competition. In fact, it revealed that main rival Anheuser-Busch was planning a new beer before A-B was able to make the announcement itself. This is certainly a recognition of how content is advertising. The blog clearly isn't "advertorial." It's full-on reporting about the industry, in a way that's interesting and relevant to those in the industry.

What may be even more interesting, though, is what the article says about journalism. In an age in which journalists are whining that their jobs are disappearing, here's yet another example of where suddenly there are new types of jobs for journalists appearing every day. But, even more interesting, is a quote at the end of the article highlighted by David Card. It's from Harry Schuhmacher, the editor and publisher of a fee-based trade publication on the beer industry:

"I tell Miller you're subsidizing a free publication, and it hurts the trade press," he says. "But they don't care."...Mr. Schuhmacher adds that he writes fewer positive pieces about Miller than he once did because he knows Brew Blog will always publish the same stories.

Think about this for a bit. People complain that when you have a company-sponsored publication it will inevitably be biased -- but the sponsorship of that site is totally open and in the clear. The site's content stands for itself. Yet, at the same time, a supposedly "objective" traditional journalist is admitting that he writes fewer stories about Miller because he's upset that it's competing with his own publication. From that, it would certainly seem like the Brew Blog is a lot more credible (it's biases are out in the open), while this fee-based trade pub admits that story choices are sometimes based on personal vendettas.



If I recall correctly, this is called “undue reliance” The computer is NOT always right, nor are procedures always adequate. (Besides, an “irate” judge often writes amusing opinions...)

http://techdirt.com/articles/20080424/175013938.shtml

Judge Slams Florida Authorities For Bogus Toll Fines

from the it's-all-about-the-money dept

It's not just with red light cameras that local authorities are squeezing extra money out of drivers, Consumerist points us to the news that a judge in Florida has tossed out thousands of bogus toll citations, slamming both the Orlando-Orange County Expressway Authority and Florida Turnpike Authority for failing to deal with the fines properly. It appears that some of the fines resulted from malfunctioning toll transponders. The judge noted that this should have been easy for the traffic authorities to correct, but instead they made it a bureaucratic nightmare for those unfairly and incorrectly accused of running tolls. The judge has even gone so far as to bar the two Authorities from issuing any new citations to drivers who have prepaid or credit-card accounts -- to the point that he's instructed the court clerks in both places to refuse to accept any new citations without affidavits swearing that the offenders have no money in their accounts.

[From the article:

"In this technology age, it is hard to believe it would take more than a few computer keystrokes to rectify the problem of matching alleged violators to account holder's vehicles," Galluzzo wrote.



Perhaps they could wire the attorney's chairs in order to deliver instant (1000 volt) sanctions?

http://www.bespacific.com/mt/archives/018186.html

April 25, 2008

Long Range Plan for Information Technology in the Federal Judiciary

"The fiscal year 2008 update to the Long Range Plan for Information Technology in the Federal Judiciary articulates five-year directions and objectives for the judiciary’s information technology program. The plan presents the program in terms of five fundamental areas: external participants, court operations, judges and chambers, probation and pretrial services, and information technology infrastructure. This represents a more aggressive effort to identify needs by various constituents. Future updates to the plan will build on this approach and incorporate additional elements."



What do you need to know and how will you find out?

http://www.pogowasright.org/article.php?story=20080425094129470

UK: Office snooping software attacked by privacy groups

Friday, April 25 2008 @ 09:41 AM EDT Contributed by: PrivacyNews News Section: Non-U.S. News

Companies are coming under fire from privacy campaigners for rolling out a computer program which enables them to track the communications and contacts of their staff.

... One of the more sophisticated programs, provided by a software company called Contact Networks, analyses the frequency of an employee's communications with their contacts, to distinguish, for instance, between someone contacted briefly in relation to one deal, say, and someone with whom a more long-standing relationship exists.

Source - Times Online

[From the article:

The software can be put to a range of uses, from a simple trawling of the entire company's Microsoft Outlook database to see if any employee knows someone at 'company X', through to a more intrusive approach, including monitoring the content of e-mails on a regular basis.



Perhaps we shouldn't follow their lead...

http://www.theregister.co.uk/2008/04/25/mass_web_attack_grows/

Department of Homeland Security website hacked!

By Dan Goodin Published Friday 25th April 2008 18:57 GMT

The sophisticated mass infection that's injecting attack code into hundreds of thousands of reputable web pages is growing and even infiltrated the website of the Department of Homeland Security.

While so-called SQL injections are nothing new, this latest attack, which we we reported earlier, is notable for its ability to infect huge numbers of pages using only a single string of text. At time of writing, Google searches here, here and here showed almost 520,000 pages containing the infection string, though the exact number changes almost constantly. As the screenshot below shows, even the DHS, which is responsible for protecting US infrastructure against cyber attacks, wasn't immune.

... The script is also notable for its ability to slip past web application defenses. The SQL query is mostly made up of HEX code, allowing it to obscure itself, at least to apps that use Microsoft SQL. MySQL and PostgreSQL are less easily fooled, according to researcher Ronald van den Heetkamp.

Sites are getting pwned because they fail to sanitize user supplied data.



Got video? For my web site class

http://www.killerstartups.com/User-Gen-Content/StartYourTubecom---Create-the-Next-Big-Thing-Online/

StartYourTube.com - Create the Next Big Thing Online

Just as the name implies, Start Your Tube is a site that encourages users to start their own version of YouTube in hopes that it explodes. Start Your Tube allows users to create their own video sharing site within minutes for free, then invite friends to view the uploaded content. Users may customize their own Tube site with colors, text, and graphics, in addition to posted material. Tube creators can easily spread the word about their created site through the “Share” function. Other Tubes can be searched and viewed for inspiration and entertainment. Furthermore, users have the ability to make money from advertising on their Tubes.

http://www.startyourtube.com/



I bet they meant to do that – or perhaps none of them have minds like Bevis & Butthead?

http://www.telegraph.co.uk/news/main.jhtml?xml=/news/2008/04/24/nogc124.xml&reason=0

OGC unveils new logo to red faces

By Aislinn Simpson Last Updated: 3:58pm BST 25/04/2008

Friday, April 25, 2008

A small breach, but some interesting questions...

http://www.pogowasright.org/article.php?story=2008042410244081

'Significant security hole' found in Wisconsin database

Thursday, April 24 2008 @ 10:24 AM EDT Contributed by: PrivacyNews News Section: Breaches

A computer program housing personal information about Wisconsin seniors and disabled people had a "significant security hole," a state health official overseeing the program said in an e-mail obtained by The Associated Press. [AP hacked the email system? Bob]

In addition, a senior center volunteer in McFarland said he could see hundreds of files of people's private information from across the country in the system run by Virginia-based Harmony Information Systems.

Source - Forbes

[From the article:

Chuck Crawford, the deputy security manager at DHFS, said in an e-mail provided to the AP that Harmony would be asked whether it has a confidentiality agreement with the state [Shouldn't the state have a copy? Bob] and what procedures are in place to inform those in the database about how their information is being used.



Another 'consulting firm' with multiple customers' data on their laptops.

http://www.pogowasright.org/article.php?story=20080424111343160

Chipotle Mexican Grill, Inc. employee data on stolen USinternetworking laptop

Thursday, April 24 2008 @ 11:13 AM EDT Contributed by: PrivacyNews News Section: Breaches

Chipotle Mexican Grill, Inc. has become the third company to report [pdf] that their employees' personal information was on a laptop stolen from an employee of USinternetworking. The personal information for the unspecified number of current and former employees included name, address, Social Security number.

Source - Notification to employees [pdf]



“Let's randomly select a few potential victims! Won't that be fun!” (Tip of the hat to Gary at the Law Library!)

http://www.ibls.com/internet_law_news_portal_view.aspx?s=sa&id=1242

UNITED STATES: University Computer Breach Risks Data of Students Who Never Went There

Wednesday, April 23, 2008

A computer server at Antioch University containing more than a decade of sensitive information on 60,000 people, some entirely unconnected with the university, was breached three times last year.

The server contained data going back to 1996 on current and former students and employees, as well as on students who had been scouted by the university but never attended or even applied. The data contained ample material for identity theft—Social Security numbers, names, academic records, and payroll records—but university officials said they do not know of any theft connected to the breaches.

University officials noticed something wrong on February 13, 2008, when users who logged into the server received a "mildly profane" message sent by a virus, according to William H. Marshall, the university''s interim chief information officer. The server was taken offline, and an outside company''s forensic investigation of the server found that "an unauthorized intruder" breached the system on June 9, 2007, June 10, 2007, and October 11, 2007. Mr. Marshall declined to say if he knew if the breach came from an internal or external hacker, citing a continuing law-enforcement investigation.

The university, which has six campuses in four states, began sending out letters about two weeks ago notifying people whose information was compromised and giving them a toll-free number to call for more information. The institution has received about five or six calls a day since then. "The most common calls are from people wondering why Antioch would have had their information on the system in first place, probably rightfully so," said Mr. Marshall.

The university has used outside companies to identify prospective students. "I think it is fairly common for universities, particularly in the last few years, to be more proactive in identifying and tracking students they''re interested in," said J. Brice Bible, chief information officer at Ohio University, which endured high-profile security breaches several years ago. Antioch University officials [Non sequitur alert! Bob] "have obviously acquired information to be competitive, which had made it more challenging for them to maintain a secure environment," he said.

Privacy advocates said there was no excuse for colleges to fail that challenge. "We have a very simple recommendation for universities," says Marc Rotenberg, executive director of the Electronic Privacy Information Center. "If they can''t protect it, they shouldn''t collect it." [Where can I buy this bumper sticker? Bob]



Come for the swimsuit models phone number, leave with their social security numbers...

http://www.pogowasright.org/article.php?story=20080424105656150

SwimwearBoutique.com hacked; customer credit card info accessed

Thursday, April 24 2008 @ 05:32 PM EDT Contributed by: PrivacyNews News Section: Breaches

SwimwearBoutique.com (SWB), a Texas-based online retailer of men and women's swimwear, reports [pdf] that on March 28, it discovered that their databases had been accessed sometime between March 26- March 28. [suggesting that they do not keep logs, which record access to the second. Bob] An unspecified number of customers had their names, addresses, SWB account passwords, email addresses, and credit card information accessed.

In addition to accessing customer data, the intruders reportedly also corrupted existing data, rendering it unusable or unreadable. [Typically, only the loss of data is reported. Bob]

In his notification letter to the New Hampshire DOJ on behalf of SWB, Ronald I. Raether, Jr. of Faruki Ireland & Cox, P.L.L., wrote, "In addition, to any affected customer requesting assistance from us, SWB will offer a year's subscription to the LoudSiren Identity Protection NetworkTM. We are committed to helping our customers affected by these criminal acts."

SWB's notification letter to customers makes no mention of any SWB-subsidized services, [a clever strategy for reducing costs... Bob] suggesting that only customers who call SWB and specifically request assistance will actually be offered the free service. Calls to SWB to clarify this were referred to SWB's attorney, who did not return our call by the end of the day.



Another SunGard victim – no new information

http://www.pogowasright.org/article.php?story=2008042418051084

Stolen laptop contains personal data for 'nearly 2,000' current, prospective Fisher students (Sungard Update)

Thursday, April 24 2008 @ 06:05 PM EDT Contributed by: PrivacyNews News Section: Breaches

Personal information (name, Social Security number, and date of birth) for close to 2,000 current and prospective St. John Fisher students may have fallen into the wrong hands as part of a security breach that involves a number of area colleges.

Source - Cardinal Courier Online Related - St. John Fisher College FAQ



Identity theft immediately! A very bad strategy...

http://www.pogowasright.org/article.php?story=20080425065426750

NY: Credit card info stolen in Canton

Friday, April 25 2008 @ 06:54 AM EDT Contributed by: PrivacyNews News Section: Breaches

Police are investigating hundreds of reports of thefts of credit and debit card numbers belonging to customers who shopped at WiseBuys department store in December.

"We have had hundreds of victims and thousands of thefts. We have had amounts as high as $3,000 and as low as $10," said Sgt. Lori A. McDougal of the village police department. "I would say at this point they total upwards of $100,000."

Victims are all believed to have shopped at the Canton WiseBuys store between Dec. 5 and 20, Ms. McDougal said. Since then, stolen credit card numbers have been used to create fake cards in New York City.

... The Canton store was the only one in the WiseBuys and Hacketts chain that was affected by the number thefts. The stores use the credit card processing system used by nearly every True Value hardware store in the nation, Mr. Garrelts said.

WiseBuys changed its computer system in December and investigators are attempting to determine whether that was when the numbers were stolen, Ms. McDougal said. Village police have begun interviewing about 30 WiseBuys employees but so far have not identified any as suspects.

Source - Watertown Daily Times



Follow-up: A non-TJX reaction after all. PCI security isn't sufficient. ISO 27001 will take 18 months.

http://www.pogowasright.org/article.php?story=20080425072317695

Hannaford CIO: We Need To Spend Millions, Go Well Beyond PCI

Friday, April 25 2008 @ 07:23 AM EDT Contributed by: PrivacyNews News Section: Breaches

Hannaford CIO Bill Homa, overseeing a data breach probe that exposed some 4.2 million payment cards, said this week that his chain needs to go well beyond PCI to try and be secure, an effort he predicted would cost his department millions of dollars "but not tens of millions."

Homa called a news conference to detail some of those planned security improvements, including Triple DES PIN encryption ("customer card information is now encrypted from the PINpad at the store register and remains encrypted while it's in our own internal network"), host and network intrusion prevention systems ("to proactively prevent malware from being installed in our systems") and better payment segmentation.

Source - StorefrontBacktalk



Tools & Techniques for ubiquitous surveillance

http://www.opengpstracker.org/

The Open GPS Tracker is a small device which plugs into a $20 prepaid mobile phone to make a GPS tracker. The Tracker responds to text message commands, detects motion, and sends you its exact position, ready for Google Maps or your mapping software. The Tracker firmware is open source and user-customizable.



It's safe, therefore we can use it more...

http://www.intergovworld.com/article/81ae989f0a01040801dd6a6784e2fdd6/pg1.htm

More privacy-boosting technology begets more video surveillance

By: Rosie Lombardi, InterGovWorld.com (Apr 25, 2008 06:00:00)

... Developed by Karl Martin and Kostas Plataniotis, researchers at the faculty of engineering, their secure visual object coding application uses cryptography techniques to encrypt "objects of interest" within video frames -B faces or other features that may be used to identify a person - and store them separately. In order to view the original complete image, a decryption key is needed to restore the object of interest.



What was the real reason to go to electronic voting?

http://news.slashdot.org/article.pl?sid=08/04/25/0337219&from=rss

Diebold Admits ATMs Are More Robust Than Voting Machines

Posted by Soulskill on Friday April 25, @08:23AM from the votes-on-the-cheap dept.

An anonymous reader points out a story in the Huffington Post about the status of funding for election voting systems. It contains an interesting section in which Chris Riggall, a spokesman for Premier (formerly Diebold) acknowledged that less money is spent making an electronic voting machine than on a typical ATM. The ironically named Riggall also notes that security could indeed be improved, but at a higher price than most election administrators would care to pay. Also quoted in the article is Ed Felten, who has recently found some inconsistencies in New Jersey voting machines. From the Post:

"'An ATM is significantly a more expensive device than a voting terminal...' said Riggall. 'Were you to develop something that was as robust as an ATM, both in terms of the physical engineering of it and all aspects, clearly that would be something that the average jurisdiction cannot afford.' Perhaps cost has something to do with the fact that a couple of years ago, every single Diebold AccuVote TS could be opened with a standard key also used for some cabinets and mini-bars and available for purchase over the Internet."



Will he win if the data has been gathered legally? (e.g. From a state database that failed to remove the SSAN?)

http://www.govtech.com/gt/299913?topic=117671

Missouri AG Attempts to Stop Web Site from Selling Personal Information

Apr 24, 2008, News Report

Attorney General Jay Nixon is seeking to shut down a Web site that permits anyone with a credit card to purchase detailed personal information about Missouri consumers -- including Social Security numbers -- and have its operator fined a significant sum for each violation of state consumer protection laws.

... Anyone who provides this information to third parties is obligated under federal law to ensure that the third party's use of the information is for a legitimate purpose allowed under the law. Nixon says A1 Peoplesearch unethically failed to properly verify the use to which its subscribers put the data the defendant sold to them. [So add a screen that requires you to state the purpose (selected from a pull down menu of 'legitimate purposes') Bob]


Related?

http://yro.slashdot.org/article.pl?sid=08/04/25/1143236&from=rss

Companies To Be Liable For Deals With Online Criminals

Posted by kdawson on Friday April 25, @09:46AM from the sees-you-when-you're-sleeping dept.

Dionysius, God of Wine and Leaf, sends us to DarkReading for a backgrounder on new rules from the FTC, taking effect in November, that will require any business that handles private consumer data to check its customers and suppliers against databases of known online criminals. Companies that fail to do so may be liable for large fines or jail time. In practice, most companies will contract with specialist services to perform these checks. Yet another list you don't want to get on.

"The [FTC's] Red Flag program... requires enterprises to check their customers and suppliers against databases of known online criminals — much like what OFAC [the Treasury Department's Office of Foreign Asset Control] does with terrorists — and also carries potential fines and penalties for businesses that don't do their due diligence before making a major transaction."



I am noticing an increase in the number of articles where reporters are taking organizations to task for failure to secure the data, even doing some basic research to learn what the “normal” practices are.

http://www.pogowasright.org/article.php?story=20080425062120348

Ie: Potential for data leakage rife in Irish organisations

Friday, April 25 2008 @ 06:21 AM EDT Contributed by: PrivacyNews News Section: Non-U.S. News

The failure by Bank of Ireland and other financial institutions as well as some of the largest corporations and government bodies to sign up to an international security standard accredited by the Irish Government means that more embarrassing data leak scandals such as laptop theft will occur again.

Siliconrepublic.com has learned that an important data security management standard ISO 27001, which governs the prevention and handling of security breaches and is used worldwide by financial institutions and government bodies, is not in place in any Irish financial institution – save a Credit Union in Waterford.

The ISO 27001 standard sets out best practices for IT security techniques and management systems.

Source - Silicon Republic

[From the article:

In the UK, for example, all financial institutions have had to qualify for the standard, otherwise the payments association APACS won’t do business with them. [Compare to PCI standard “enforcement”... Bob]

... Asked if organisations are perhaps unaware of the ISO 27001 standard, Brophy said: “Three or four years ago that might have been the case. Anyone who works in IT would know that this standard is a basic minimum requirement and can be tailored to suit any organisation of any size. Waterford Credit Union achieved the standard in recent months. Why larger financial organisations haven’t seen the need to go for it is beyond me.”

On the subject of whether Irish government bodies are subscribing to the standard, Brophy said that despite healthy attendance by government bodies at ISO 27001 training courses, no government body has moved to get certified.



I expect a few amusing articles as this process 'works out the kinks”

http://www.pogowasright.org/article.php?story=20080425061643431

Face scans for air passengers to begin in UK this summer

Friday, April 25 2008 @ 06:16 AM EDT Contributed by: PrivacyNews News Section: Surveillance

Airline passengers are to be screened with facial recognition technology rather than checks by passport officers, in an attempt to improve security and ease congestion, the Guardian can reveal.

From summer, unmanned clearance gates will be phased in to scan passengers' faces and match the image to the record on the computer chip in their biometric passports.

Border security officials believe the machines can do a better job than humans of screening passports and preventing identity fraud. The pilot project will be open to UK and EU citizens holding new biometric passports.

Source - Guardian

[From the article:

Border security officials believe the machines can do a better job than humans [Translation: you can trust the machines Bob] of screening passports and preventing identity fraud. The pilot project will be open to UK and EU citizens holding new biometric passports.

But there is concern that passengers will react badly to being rejected by an automated gate. To ensure no one on a police watch list is incorrectly let through, the technology will err on the side of caution and is likely to generate a small number [see below Bob] of "false negatives" [Translation: you can't trust the machines. Bob] - innocent passengers rejected because the machines cannot match their appearance to the records. [Translation: We will deliberately tackle, handcuff and hood, strip and cavity search a few so called “innocents” just to demonstrate that we are serious about protecting innocents” Bob]

... Phil Booth of the No2Id Campaign said: "Someone is extremely optimistic. The technology is just not there. The last time I spoke to anyone in the facial recognition field they said the best systems were only operating at about a 40% success rate in a real time situation. I am flabbergasted they consider doing this at a time when there are so many measures making it difficult for passengers."



The latest French version of our regional TIA systems – they've been doing this since at laeast 1974...

http://www.pogowasright.org/article.php?story=20080424114601906

France 'suspends' Creation of Big-Brother Database

Thursday, April 24 2008 @ 11:46 AM EDT Contributed by: PrivacyNews News Section: Non-U.S. News

The French government will "suspend" the use of new software for recording the personal habits and affiliations of its citizens in a police database, following an outcry by civil rights groups.

Interior Minister Michèle Alliot-Marie took the decision Tuesday to suspend trials of the Ardoise software while officials consider how to reconcile privacy rights and operational needs, her spokesman confirmed Thursday.

Source - CIO

[From the article:

Campaigners say that Ardoise infringes civil liberties by allowing law enforcers to tag a person's file with annotations including "runaway child," "handicapped," "homeless," "trade unionist," "alcoholic," "narcotics user," "transvestite," "transgendered," "homosexual," "prostitute," "person who frequents prostitutes," "psychologically disturbed" or "member of a sect," simply by picking them from a list.

... The database also holds information about religion, sexual orientation and race, according to the Interior Ministry.

[What information do the police need? Bob]


Related. This is what happens when databases are matched...

http://www.pogowasright.org/article.php?story=20080424131800760

IN: Judge refuses to stop license revocations

Thursday, April 24 2008 @ 01:18 PM EDT Contributed by: PrivacyNews News Section: In the Courts

The Indiana Bureau of Motor Vehicles reports that it has revoked the driver’s licenses and ID cards of about 32,455 people this year because their personal information didn’t match Social Security records.

On Wednesday a Marion Superior Court judge denied an injunction that would have temporarily stopped the BMV from revoking the credentials, a new process that began last year.

The injunction was sought by the American Civil Liberties Union of Indiana. It was paired with a class-action lawsuit where the key plaintiff was South Bend attorney Lyn Leone.

Source - WSBT

[From the article:

The ACLU’s lawsuit claimed that it’s against state law and the U.S. Constitution to take away licenses because of mismatches between BMV and Social Security records.

A hearing was held April 11 before Judge Kenneth Johnson in Indianapolis.

In his 44-page ruling, Johnson wrote that the suit failed to show any harm or hardship [I'll have to read the ruling, but no license and the need to re-apply should be harm, right? Bob] to Leone by the BMV’s new screening process, which began last year.

... The BMV says it will reinstate a license — at no charge — if the customer can successfully show their personal information matches that of Social Security records. To date, the BMV says 835 credentials have been reinstated. [Doesn't this suggest that the matching process is flawed? Bob]



Talk on implementation of HIPAA rules.

http://www.phiprivacy.net/?p=313

Apr-25-2008

Pointer: Case Study: Five ways to energize your information security program

Jim Reiner’s presentation at the 15th National HIPAA Summit is now available online.



My friendly neighborhood Linux geek sent me this article. Looks very interesting...

http://www.itwire.com/content/view/17816/1141/1/0/

Ubuntu 8.04’s Wubi makes for universal desktop

by David M Williams Wednesday, 23 April 2008

... Today, I’d like to talk about something else which is new in this release: Wubi, the Windows based Ubuntu Installer.

Wubi offers a remarkable new way of trying out Ubuntu, making it even more of a risk-free proposition than ever before.

... Wubi’s goals are to assist a Windows user unacquainted with Linux in trying Ubuntu out without risking any loss of information, because although the hard disk will be written to there is no disk partitioning or formatting involved. The existing hard drive configurations, and Windows installation, are not affected in any way.

Wubi runs straight from within Windows and will install Ubuntu onto a disk image – that is, a single disk file which emulates a stand-alone hard drive. Using Wubi, Windows users can try Ubuntu out without any complex installation.

... At worst, if you don’t like it, uninstallation is a snap and your computer is left as it was.

... On rebooting I’m greeted with a boot loader menu asking which operating system I wish to use; choosing Ubuntu fires up the new operating system without hitch and with just a few more questions on the way.