Tuesday, January 06, 2009

Another record year!

http://www.pogowasright.org/article.php?story=20090105175536874

2008 Data Breach Total Soars - ITRC Reports 47% Increase over 2007

Monday, January 05 2009 @ 05:55 PM EST Contributed by: PrivacyNews

The Identity Theft Resource Center (”ITRC”) issued its end of year press release today. Not surprisingly, the number of breaches reported in 2008 was up significantly from 2007, with their counter hitting 656 U.S. breaches for the year, an increase of 47% over last year’s total of 446 breaches in their database.

[...]

Whereas ITRC’s analysis might lead to the conclusion that the financial section is the most proactive sector because they represent less than 12% of all breaches, inspection of the raw frequency data suggests a somewhat different picture: reported breaches increased over 250% from 2007 to 2008. That trend indicates that security in the financial sector is not keeping pace with previous threats and new threats to data security.

In interpreting ITRC’s data, then, and in addition to all of the cautions and qualifiers they appropriately include, we also need to keep other factors in mind, not the least of which is that when Massachusetts analyzed its breach reports for the first 10 months after its law went into effect, 75% of the reported breaches were from the financial sector, a statistic that does not seem to “fit” with what ITRC found based on published media reports or those reports available on a few states attorney general web sites.

Source - Chronicles of Dissent (commentary and analysis)



If you are doing things that are illegal, immoral (fattening gets a pass) the anti-virus guys will attack you!

http://www.pogowasright.org/article.php?story=20090106073852215

Sophos versus police spyware in “legal hacking” debate

Tuesday, January 06 2009 @ 07:38 AM EST Contributed by: PrivacyNews

In a rather disturbing development it is being reported in the British press that police have been given the power to hack into computers without a court warrant.

[...]

One thing I can promise you though: If Sophos encounters any malware written by the police, we won’t turn a blind eye. We will add detection for it.

And if you think about it, we don’t have any other sensible choice.

For anti-virus vendors to know which spyware Trojan horse to ignore, the British police would need to provide us with a sample of their code. For security reasons, it seems unlikely that this would happen. As a result, how will we (and other security vendors) know which code is written by the cops and which originates from traditional hackers? After all, it’s not likely to say Copyright (c) New Scotland Yard is it?

In order to properly protect customers, Sophos continues to protect against all the malicious code that we see. ..... And if that puts us at loggerheads with our friends in the police, so be it.

Source - Sophos



Would anyone in congress receive/respond to a twit offering them a cabinet post? (Oh, wait! A twit is a message, not a person!)

http://www.databreaches.net/?p=251

Twitter Gets Hacked, Badly

January 5th, 2009 by admin

Michael Arrington reports:

Phishing attacks, which hit Twitter over the weekend, are a sign a service has arrived [My contention is that every new technology will be tested by evil-doers to see where the vulnerabilities are. It's inevitable! Bob] (Facebook has the same problem). But someone hacking into Twitter’s internal admin tools and compromising 33 high profile accounts, including President Elect Barack Obama, has Twitter users freaking out about what to do.

Here is Twitter’s official explanation: Read more on Washington Post



If you use these technologies, you'll never get a real job. If you don't, employers assume you can't/won't use technology! All that's left is (gasp) politics!

http://www.pogowasright.org/article.php?story=2009010510053137

MySpace Medical

Monday, January 05 2009 @ 10:05 AM EST Contributed by: PrivacyNews

For adults, browsing MySpace.com can be a secret window onto how teenagers sculpt their public personas. Teens, one of the most wired groups in America, use the social-networking site to create profiles where they share clips of their favorite songs, post pictures or vent about a bad day.

But MySpace, which now boasts 200 million profiles, is not all fun and games. Findings from a new pair of studies by Megan Moreno, a physician specializing in adolescent medicine, and her colleagues at Seattle Children's Hospital reveal that more than half of the 500 teen profiles they looked at during two and a half months in 2007, read more like cautionary tales, chock full of high-risk behaviors from sexual conquests to binge drinking and drug use. While the prevalence of racy MySpace pages created by teens may not be news, Moreno's studies are the first to systematically catalog the sexual and substance-abuse content of teens' profiles, and to look at the results of an online health intervention. Her results, on a small scale, support the idea that these profiles are an untapped resource for physicians and mental-health professionals. By harnessing this technology as a monitoring tool, physicians, parents and counselors may effectively tag along with teens for some of their social interactions and when appropriate, contact teens at risk.

Source - Newsweek



FUN! This reopens my debate (polite discussion) with Dead Dan Vigil. I still want my attorney to READ EVERYTHING. If the attorney then decides something should not be used, I will accept that judgment. But I can't accept a guess based on what you think might be in the document.

http://www.bespacific.com/mt/archives/020237.html

January 05, 2009

New on LLRX: Metadata - What Is It and What Are My Ethical Duties?

Metadata - What Is It and What Are My Ethical Duties?: Jim Calloway explains why every lawyer needs to understand a few basic things about metadata. He contends that the legal ethics implications of metadata “mining” are no longer just of interest to the lawyers processing electronic discovery, or the ethics mavens.



All laws should be like this, but only I should make the accusations. (No doubt, several lawmakers will find themselves accused...)

http://tech.slashdot.org/article.pl?sid=09%2F01%2F06%2F0351202&from=rss

NZ File-Sharers, Remixers Guilty Upon Accusation

Posted by kdawson on Tuesday January 06, @02:33AM from the how-laws-are-made dept. The Internet Government

An anonymous reader writes

"Next month, New Zealand is scheduled to implement Section 92 of the Copyright Amendment Act. The controversial act provides 'Guilt Upon Accusation,' which means that if a file-sharer is simply accused of copyright infringement he/she will be punished with summary Internet disconnection. Unlike most laws, this one has no appeal process and no punishment for false accusation, because they were removed after public consultation. The ISPs are up in arms and now artists are taking a stand for fair copyright."



Employees are scum. We should run our companies without them.

http://it.slashdot.org/article.pl?sid=09%2F01%2F05%2F2137202&from=rss

Employees the Next (Continuing) Big Security Risk?

Posted by ScuttleMonkey on Monday January 05, @05:30PM from the not-if-you-treat-them-right dept. Security IT

surely_you_cant_be_serious writes

"A nationwide survey finds that most companies consider their systems vulnerable to attack. Historically, crime rates increase during recessions — and some believe that cybercrime may well follow suit, especially given massive layoffs and the dim prospects many laid-off employees face in finding a new job. 'One thing companies can start doing is monitoring their networks on an ongoing basis so that they understand the normal pattern of data flow and usage, Brill said. [Failure to do this is equivalent to building a trans-continental railroad system and not know where your trains are or if other trains are using your rails! Bob] In many cases, companies may not have the internal capability to do this, but outsourcing options are available. Kroll Ontrack, for instance, will be rolling out a 24/7 monitoring service for its global clients manned from a US location by professionals in early 2009.'"



Youse don't take it all at once, youse first form a commission consisting of da heads of da five families!

http://it.slashdot.org/article.pl?sid=09%2F01%2F05%2F2038251&from=rss

A Hacker's Audacious Plan To Rule the Underground

Posted by ScuttleMonkey on Monday January 05, @04:47PM from the ambition-can-carry-you-just-so-far dept. Security The Internet

An anonymous reader writes

"Wired has the inside story of Max Butler, a former white hat hacker who joined the underground following a jail stint for hacking the Pentagon. His most ambitious hack was a hostile takeover of the major underground carding boards where stolen credit card and identity data are bought and sold. The attack made his own site, CardersMarket, the largest crime forum in the world, with 6,000 users. But it also made the feds determined to catch him, since one of the sites he hacked, DarkMarket.ws, was secretly a sting operation run by the FBI." [Technical term: Oops! Bob]



Movement toward my model for music (and other information) where you make it available and users buy by the drink?

http://tech.slashdot.org/article.pl?sid=09%2F01%2F06%2F0013245&from=rss

Amazon S3 Adds Option To Make Data Accessors Pay

Posted by kdawson on Monday January 05, @07:17PM from the by-the-byte dept. Software The Internet

CWmike writes

"Amazon.com has rolled out a new option for its Simple Storage Service (S3) that lets data owners shift the cost of accessing their information to users. Until now, individuals or businesses with information stored on S3 had to pay data-transfer costs to Amazon when others made use of the information. Amazon said the new Requester Pays option relieves data providers of that burden, leaving them to pay only the basic storage fees for the cloud computing service. The bigger question with the cloud is, who really pays? Mark Everett Hall argues that IT workers do."



Perhaps this is true wherever people congregate, explaining both soccer hooligans and congress!

http://science.slashdot.org/article.pl?sid=09%2F01%2F06%2F042202&from=rss

How the City Hurts Your Brain

Posted by kdawson on Tuesday January 06, @05:24AM from the but-not-paris dept. Science

Hugh Pickens writes

"The city has always been an engine of intellectual life and the 'concentration of social interactions' is largely responsible for urban creativity and innovation. But now scientists are finding that being in an urban environment impairs our basic mental processes. After spending a few minutes on a crowded city street, the brain is less able to hold things in memory and suffers from reduced self-control. 'The mind is a limited machine,' says psychologist Marc Berman. 'And we're beginning to understand the different ways that a city can exceed those limitations.' Consider everything your brain has to keep track of as you walk down a busy city street. A city is so overstuffed with stimuli that we need to redirect our attention constantly so that we aren't distracted by irrelevant things. This sort of controlled perception — we are telling the mind what to pay attention to — takes energy and effort. Natural settings don't require the same amount of cognitive effort. A study at the University of Michigan found memory performance and attention spans improved by 20 percent after people spent an hour interacting with nature. 'It's not an accident that Central Park is in the middle of Manhattan,' says Berman. 'They needed to put a park there.'"



Something for my Stat students

http://www.bespacific.com/mt/archives/020232.html

January 05, 2009

Statistical Abstract of the United States 2009

U.S. Census Bureau, Statistical Abstract of the United States: 2009 (128th Edition) - Washington, DC, 2008

  • "The Statistical Abstract of the United States is the standard summary of statistics on the social, political, and economic organization of the United States. It is also designed to serve as a guide to other statistical publications and sources. The latter function is served by the introductory text to each section, the source note appearing below each table, and Appendix I, which comprises the Guide to Sources of Statistics, the Guide to State Statistical Abstracts, and the Guide to Foreign Statistical Abstracts."



Something for my students

http://www.killerstartups.com/Web20/cramberry-net-studying-made-easy

Cramberry.net - Studying Made Easy

http://www.cramberry.net

A new web-based application, Cramberry is there to make life easier for students and those who have a memory like a sieve and always tend to neglect pivotal dates such as birthdays and the like.

Cramberry revolves around sets of flashcards that contain the information which the user intends to memorize or remember, and each card has a front and a back which will let you gauge your knowledge.

Once you have created a full set of cards, these will be randomly displayed, and your memory will be put to the test as you try and remember the back of each card that is displayed by clicking on the relevant button.

This process is actually a dynamic one, as Cramberry keeps track of the cards you know and helps you to overcome your shortcomings by learning the ones you have trouble with.

This solution is also wholly inexpensive, and if the abovementioned sounds good to you it is always possible to see if it delivers the goods or not by creating a free account and giving it a spin.

Monday, January 05, 2009

What a swell law! Let's get one in this country!

http://www.pogowasright.org/article.php?story=20090104153912115

UK: Police set to step up hacking of home PCs

Sunday, January 04 2009 @ 03:39 PM EST Contributed by: PrivacyNews

THE Home Office has quietly adopted a new plan to allow police across Britain routinely to hack into people’s personal computers without a warrant.

The move, which follows a decision by the European Union’s council of ministers in Brussels, has angered civil liberties groups and opposition MPs. They described it as a sinister extension of the surveillance state which drives “a coach and horses” through privacy laws.

Source - Times Online hat-tip, tech.blorge

[From the article:

Under the Brussels edict, police across the EU have been given the green light to expand the implementation of a rarely used power involving warrantless intrusive surveillance of private property. The strategy will allow French, German and other EU forces to ask British officers to hack into someone’s UK computer and pass over any material gleaned.

A remote search can be granted if a senior officer says he “believes” that it is “proportionate” and necessary to prevent or detect serious crime — defined as any offence attracting a jail sentence of more than three years.



Is this a good idea or is the Air Force asking for trouble? (Flowchart to determine if you should respond to Blog postings.

http://www.bespacific.com/mt/archives/020222.html

January 04, 2009

U.S. Air Force Leveraging Web 2.0 Apps - Twitter and Blogs

Via David Meerman Scott's blog WebInkNow, news about forward thinking and actionable PR and IT business process improvement from the U.S. Air Force: "David Faggard, Chief of Emerging Technology at the Air Force Public Affairs Agency in the Pentagon [in response to a direct message via Twitter], indicated that "the Air Force employs 330,000 communicators! Their mission is to use current and developing Web 2.0 applications as a way to actively engage conversations between Airmen and the general public. Yes, that’s right, the goal of the program is that every single Airman is an on-line communicator." Note, this post includes a very useful Air Force blog assessment flowchart.



You can't announce that you've fired your expert witness for incompetence.

http://yro.slashdot.org/article.pl?sid=09%2F01%2F05%2F0139216&from=rss

WSJ Confirms RIAA Fired MediaSentry

Posted by kdawson on Sunday January 04, @10:23PM from the meet-the-new-boss dept. Music

newtley writes

"Two days ago we discussed the earlier p2pnet report that the RIAA had fired MediaSentry (now called SafeNet). Now the Wall Street Journal is confirming this report. MediaSentry has been 'invading the privacy of people,' the WSJ quotes Ray Beckerman; 'They've been doing very sloppy work.' Beckerman cites MediaSentry's practice of 'looking for available songs in people's filesharing folders, uploading them, and using those uploads in court as evidence of copyright violations.' MediaSentry 'couldn't prove defendants had shared their files with anyone other than MediaSentry investigators.' The WSJ notes, 'In place of MediaSentry, the RIAA says it will use Copenhagen-based DtecNet Software ApS. The music industry had worked with DtecNet previously both in the US and overseas, and liked its technology...' "



Would that any modern technology would have as long a life!

http://tech.slashdot.org/article.pl?sid=09%2F01%2F05%2F0224202&from=rss

Player Piano Roll Production Ceases

Posted by kdawson on Monday January 05, @03:28AM from the day-the-music-died dept. Media Music Technology

boustrophedon writes

"The Buffalo News reports that QRS Music Technologies halted production of player piano rolls 108 years after the company was founded in Chicago. QRS continues to make digitized and computerized player-piano technology that runs on CDs. 'We're still doing what we always did, which is to provide software for pianos that play themselves. It's just the technology that has changed. But I would be lying to say [the halting of production] doesn't sadden me,' said Bob Berkman, the company's music director. Piano rolls can last for decades, but not forever. Volunteers at the International Association of Mechanical Music Preservationists build piano-roll scanners to scan rolls optically and convert them to MIDI files. The IAMMP archive and others contain thousands of scanned rolls."



Got DSL? Test it! (Simple but cute)

http://www.killerstartups.com/Web-App-Tools/speed-io-check-your-true-internet-speed

Speed.io – Check Your True Internet Speed

http://www.speed.io

It’s hard to know if you’re getting the speed you pay for. I mean, unless you’re some sort of tech geek/god/hacker, you’re not going to really figure out if you’re getting what you paid for. If you’re having your doubts, then you should check out Speed.io. With this easy to use service, you’ll be able to check you download and upload speeds. It also checks connections and pings, making it for a very complete connection test.

... It even figures out who your internet provider is, your IP address, and the browser you’re using.

Sunday, January 04, 2009

Adding a second country to the complications of a Data Breach.

http://www.databreaches.net/?p=105

Stolen CreditTek laptop contained data on 68,857 DJO patients

January 3rd, 2009 by admin

When a Creditek, LLC employee went on vacation to the Bahamas, he took his work laptop with him. The laptop, which contained personal and medical information on 68,857 patients of orthopedic products supplier DJO, LLC, was stolen from the home in which the employee was staying.

According to a notification sent to New Hampshire’s Attorney General on December 12th, Creditek is a Pennsylvania firm that provides billing services for DJO. The laptop, which was stolen on November 14th:

… contained numerous files including some of our billing data regarding certain OJO patients such as: names, addresses, social security numbers, dates of birth, gender, dates of services rendered by OJO, diagnostic codes (and, in some cases, a brief description of the diagnosis), summary charges (reflecting the total retail value of services rendered), patient balances, insurance ID numbers, current payors, and, if the payor was an insurance company, the insurance plan identification numbers.

There was no mention in the notification as to whether there was any security on the laptop, and no copy of any notification letter to individuals was enclosed with the report. Affected patients are from across the U.S. and Puerto Rico.



Update: We heard of this one before?

http://www.databreaches.net/?p=226

Wyndham Hotel Group hacked

January 3rd, 2009 by admin

If you stayed at a Wyndham hotel, check your mail, because you may be getting a letter from the chain telling you of a hack that occurred months ago.

In a letter to the New Hampshire Attorney General dated December 23, Wyndham Hotels and Resorts updated a notification sent to states attorney general back in early October about a breach involving their data center in Phoenix. The date of the breach and date of discovery were not indicated in the follow-up letter and the original notification to states attorney general is not currently available online.

In a letter to affected individuals, the chain writes:

As a result of unauthorized access to Wyndham systems, Wyndham has determined that your credit or debit card number, expiration date and possibly your name were compromised. Wyndham has taken numerous steps to protect your information since the discovery of this incident. In addition to terminating the unauthorized access, we revalidated our information security infrastructure to confirm that we maintain industry standard protections for customer data. In addition, we promptly notified law enforcement and each of the major payment card networks (American Express, Visa, MasterCard, and Discover). We also provided each of the payment card companies with the actual credit and debit card numbers that had been involved in the incident so that the payment card companies could take such action as they deemed appropriate to monitor the cards. We also notified the affected managed and franchised hotels so that they could take the appropriate action to ensure that their systems are properly investigated and secured.

In their notification to the states, Wyndham notes that “due to the nature of the breach, the names and addresses of the consumers were not readily available. Consequently, Wyndham contracted with a third party, Equifax, to provide a matching service for all current credit card numbers which we believe may have been compromised.”

Notification to those affected began on December 15, but because the matching process was not completed as of December 23, the company anticipated that it would still be sending out notifications “early in 2009.”

Wyndham did not indicate in its notification which hotels were affected or how many customers were affected. In its response to an inquiry, a spokesperson reported:

We are taking every step to ensure our guests’ information is protected and at the same time give them notice to watch their accounts. This affected a small number of guests at a small number of hotels.

Claiming confidentiality, the spokesperson declined to answer any further questions. A reliable source informs us that Wyndham has also tried to prevent its breach disclosure from being made publicly available on the web in at least one state’s breach list.

The chain is offering those affected one year of Equifax Credit Watch 3-in-1 Alerts and:

In addition, for a limited time we are offering a Preferred Customer Rate discount program for our customers who may have been impacted by this incident. You will receive a 20% discount on the room rate for any hotel stays with a Wyndham brand hotel when you make your reservations on or before March 31, 2009.



Is it possible to request that breach notices not be put online? Wyndham tried (see article above) but Merrill has more clout?

http://www.databreaches.net/?p=212

Five recent Merrill Lynch security breaches you probably didn’t know about

January 3rd, 2009 by admin

As if the financial sector wasn’t in enough of tailspin recently, Merrill Lynch reported at least five security breaches during the last quarter of 2008. Reports filed by the firm with several states attorney general reveal that:

  • On September 3, the company reported a lost laptop containing personally identifiable information to New York State. That report is not currently available online.

  • On September 15, the company reported a stolen laptop to New York State. That report is also not currently available online.

  • On September 18, the company reported a stolen laptop to Maryland that contained names, addresses, dates of birth, and social security numbers. The report is not available online, and Merrill Lynch has not responded to two inquiries as to whether this was the same laptop reported to NYS or a separate incident.

  • On October 9, the company notified Maryland that an external hard drive was lost or stolen during transport to a facility. Information on the drive included clients’ names, social security numbers or tax ID numbers, dates of birth, addresses, phone numbers, email addresses, passport numbers, [foreign nationals? Bob] drivers license numbers, Merrill Lynch account numbers, loan information, insurance policy information, other financial account information, and online user credentials.

  • On December 16, the company notified New Hampshire of a stolen laptop containing personal information. The laptop, which was stolen from the firm’s Tacoma office on November 26, contained client information including name, Social Security number, address, telephone number and email address.

  • On December 29, the company notified New Hampshire that another laptop was stolen, this one from the home of a third-party contractor’s employee. The theft occurred early in December, and the laptop contained names and social security numbers of “a population of current and former Merrill Lynch Financial Advisors and some applicants for employment.” The laptop did not contain any additional personal or financial information, nor any client data.

The number of employees or clients affected by these breaches was not revealed, and Merrill Lynch has not responded to several requests for additional information.

Past Known Breaches

In 2007, Merrill Lynch reported two data losses to New Hampshire: a laptop stolen from a New York office that contained client information, and a storage device theft affecting 33,000 employees that was reported in the media. Two incidents reported to New York in 2006 were not reported in the media. One involved a laptop stolen from a third-party tax preparer that contained information on 300 individuals. The other involved a laptop stolen from an employee’s vehicle that contained client account data on 10,500 New York residents and 2,800 North Carolina residents; the total number of clients affected was not reported. Other breaches may have been reported to New York for 2007, but complete 2007 data from NYS have not yet been obtained.



Things go better with Coke? (PBG is in New York, so I suspect this could be a nation-wide breach)

http://www.databreaches.net/?p=131

Pepsi employee data on missing storage device

January 3rd, 2009 by admin

On December 23rd, Pepsi Bottling Group notified the New Hampshire Attorney General that:

During the week of December 8, the payroll department of The Pepsi Bottling Group (PBG) reported that it could not account for a portable data storage device, which contained unencrypted personal information, including the names and social security numbers of PBG employees in the US. Upon receiving the report of the missing device, the PBG security department conducted a thorough search for the device, but concluded it was lost.

Although the total number of affected employees was not provided in the report, 198 New Hampshire residents were affected. Information on the device also included the employees’ identification number and state of residence.

In an F.A.Q. sent to those affected, Pepsi indicated that a member of PBG’s payroll department had downloaded unencrypted personal information onto a portable data storage device in connection with an audit of payroll information. The F.A.Q. also indicated that although some of the files on the device were password protected, the employee information was in one or more files that were not password protected.

PBG has not responded to inquiries as to whether the situation violated any of its security policies.



The rise of the hacker as a tool of asymmetric cyber war? How do you counter attacks originating in cyber-cafes around the world?

http://news.cnet.com/8301-10787_3-10130633-60.html?part=rss&subj=news&tag=2547-1_3-0-5

Israeli news site down, blames cyber attack

Posted by Charles Cooper January 3, 2009 6:41 PM PST

First real war, now a cyber war? The Jerusalem-based Debkafile said it was temporarily put out of action Saturday evening by a cyber attack.

It's not clear whether this was a denial of service attack. Debka, which specializes in military and political analysis, sent out a note to subscribers that both its English and Hebrew sites had been under attack "since 19:00 local time." It did not get more specific and the site's publishers were not immediately available for comment.

The announcement took place in the shadow of the week-long conflict between Israel and Hamas. Earlier today, the Israel Defense Force sent its troops into Gaza in a move to smother missile fire.



Hey! It's free! (If you've been using a free service to interact with customers, you have some scrambling to do...)

http://tech.slashdot.org/article.pl?sid=09%2F01%2F03%2F203255&from=rss

Protection From Online Eviction?

Posted by kdawson on Saturday January 03, @05:01PM from the our-data-our-selves dept.

AOL has been shutting down its free Web services, in some cases with little or no notice to users, and they are not the only ones. This blog post on the coming "datapocalypse" makes the case that those who host Web content should be required to provide notice and access to data for a year, and be held strictly accountable the way landlords are before they can evict a tenant. Some commenters on the post argue that you get what you pay for with free Web services, and that users should be backing up their data anyway. What do you think, should there be required notice and access before online hosts take user data offline for good?



Does the contract make any guarantee that service quality will remain constant? (Sometimes you act like an evil monopoly even when you aren't, technically.) Comments make it seem most readers now expect this type of behavior from providers...

http://mobile.slashdot.org/article.pl?sid=09%2F01%2F03%2F1818206&from=rss

AT&T 3G Upgrades Degrade 2G Signal Strength

Posted by kdawson on Saturday January 03, @03:44PM from the cellphone-walks-into-a-bar dept. Cellphones Wireless Networking

Timothy R. Butler writes

"Much to the chagrin of owners of various 2G cell phones on AT&T Mobility's network, including the highly visible (and originally highly expensive) first-generation iPhone, we have discovered that AT&T has been quietly adjusting its network in ways that degrade 2G network performance as it has sought to build out its next-generation 3G network. Many of the phones affected, including BlackBerry devices, are still well within their two-year contract period."



Interesting idea. Not your normal search – looks at twits, blogs, etc. I found out that "privacy law in a nutshell" is available for the Kindle!

http://www.killerstartups.com/Web20/whostalking-com-see-who-s-saying-what

WhosTalking.com – See Who’s Saying What

http://www.whostalkin.com

Have you ever wanted to know what people are saying about you or your startup? If so, then you probably tried Twitter Search, Google, and other things of that nature. But, is there a tool that lets you quickly search through all that web chatter? Yes there is, and it’s called WhosTalkin.com. With this site, you’ll be able to keep track of what people are saying about any topic you can think of. The site uses 60 of the internet’s most popular sources of information to help you find that chatter about your startup you were looking for. I was impressed by how well thought out the site’s UI is. It’s easy to sort through all the information, as the menus slide up and down in order to reveal what information you’re looking for.

The selection of sources is top-notch, and should allow you to find everything people are saying about any topic, be it you, your startup, or even your favorite trumpet player.



Simple strategy: 1) attract really smart students. 2) exploit them.

http://yro.slashdot.org/article.pl?sid=09%2F01%2F03%2F2327255&from=rss

Universities Patenting More Student Ideas

Posted by kdawson on Sunday January 04, @04:23AM from the thanks-for-the-research dept. Patents Education

theodp writes

"Working as a NASA intern, grad student Erez Lieberman had a eureka moment, resulting in an algorithm that detects whether a person is standing correctly or is off balance. Unfortunately, MIT liked it so much they decided to patent it. Seeking permission to use his own idea for his iShoe startup, which develops products like insoles to address the problems of seniors, Lieberman was told no problem — as long as he promised a hefty royalty and forked over a $75,000 upfront payment. Whether or not students are aware of it, the NYTimes reports that most universities own inventions created by students that were developed using a 'significant' amount of schools resources. Colleges and universities once obtained fewer than 250 patents a year, but that was before the Bayh-Dole Act gave them ownership of inventions developed through federally financed research. Now they acquire about 3,000 a year, and in 2006 licensing fees and equity in spinoff companies totaled at least $45B — research powerhouses like Stanford and NYU pocketed $61M and $157M, respectively."



This has potential. For my website students!

http://www.killerstartups.com/Video-Music-Photo/mashface-com-put-your-face-anywhere

MashFace.com – Put Your Face Anywhere

http://www.mashface.com

It’s a well known fact: people like to put their face on others’ bodies. Whether it be a body builder, Amy Winehouse, or a dog, it’s funny to see your face on someone else’s body. If that is something that draws your attention (and I assume it does, you’re only human) then you have to check out MashFace.com. With the site, you’ll be able to quickly put your face on any type of body you can think of. All you have to do is follow the simple 4 step process to get your pictures “mashed”. The site takes advantage of your computer’s video camera, allowing you to record mouth and eye movement. This adds a whole new level of depth to any “mashed” face you create.

Saturday, January 03, 2009

At least proof read your notification letter!

http://www.databreaches.net/?p=199

Seibels Bruce Group hacked?

January 2nd, 2009 by admin From the your-guess-is-as-good-as-mine dept.

On December 22, Seibels Bruce Group notified the New Hampshire Attorney General of breach. I’m pretty sure they were describing a hack, but from their wording, I suppose it’s possible that someone wandered into their offices and just browsed through their file cabinets. See what you think when you read the description.

What’s really noteworthy is that within the space of a few paragraphs, they went from saying that individuals’ data may have been improperly accessed to saying that they had confirmed that the individuals’ data was accessed.

From the letter to those affected:

We are sending you this letter as a cautionary measure because we believe that certain information about you may have been improperly accessed.

What Happened:

The Seibels Bruce Group, Inc. and its subsidiaries (”Seibels Bruce”) provide various identity verification and related services to insurance companies who use our services during the process of granting and servicing insurance policies. In mid-December, we became aware that certain personal records that we use for these business purposes were accessed improperly by an unauthorized third party. We promptly detected the issue, and took a number of measures to secure our systems. We are sending you this letter because we confirmed that, during this brief period of time, your records (which may have contained your name, address, telephone number, Social Security number, and/or date of birth) were accessed by an unauthorized third party.

And that’s all they wrote by way of explanation. They did tell those affected that they could call them on a toll-free information helpline, and it was a nice touch to have the President of Seibels Bruce Group sign the letter, but if I was on the receiving end of this notification letter, I would not be happy with the contradictions in the notification. What do you think?



I wonder if anyone has actually thought through the contract requirements to secure data in third party hands?

http://www.databreaches.net/?p=181

Vonage customer data on Google Notebook

January 2nd, 2009 by admin

With all the advice we see these days about hardening security, this might be a good time to remember the importance of both having stringent security standards written into any contractor agreements and actually monitoring compliance with any contracts or policies. A recent breach reported by Vonage serves as a useful example.

On December 23, Vonage notified the New Hampshire Attorney General that it had recently discovered that an employee of an unnamed telesales contractor had violated Vonage’s policy of not recording sensitive customer data outside of its own computer system. The agent was recording contact data — including credit card number, CCV, or bank account number and routing information on Googe Notebook. [Expect more of this a Cloud Computing grows Bob]

Vonage got the information removed from Google Notebook, but in response to the incident:

Vonage has required that all of its third party vendors that handle credit card data provide Vonage with a description of their methodology for detecting data leaks. In addition, Vonage has required that third party vendors, with sales or support agents serving Vonage, block access to a number of web sites including Google Notebook.

That’s a good start, and kudos to Vonage for catching the breach and trying to address it in a proactive way, but of course, that is just one piece of a more comprehensive security approach. Hopefully, more entities will take a closer look at what they are requiring from vendors in the way of security and what they are requiring of the vendors and themselves in terms of monitoring.



“ all men are created equal” but sometimes that changes... Perhaps someone will invent a scoring system that measures privacy against 'the public's right to know' – perhaps.

http://www.pogowasright.org/article.php?story=20090103055854144

IA: Panel proposes expanded privacy in public records

Saturday, January 03 2009 @ 05:58 AM EST Contributed by: PrivacyNews

Iowa governments would have greater authority to black out personal information from public records under proposals recommended by a legislative committee.

Advocates say the proposals would protect citizens from identity theft.

But opponents say the unintended results could be alarming, particularly if the public is unable to differentiate between, for example, a convicted sex offender and another citizen with the same name.

Source - Des Moines Register



Perhaps a bit too British?

http://yro.slashdot.org/article.pl?sid=09%2F01%2F03%2F0246252&from=rss

India Sleepwalks Into a Surveillance Society

Posted by Soulskill on Saturday January 03, @02:11AM from the your-tech-support-calls-may-be-monitored dept. Privacy Government The Internet

An anonymous reader writes

"ZeroPaid has a fascinating roundup of news stories surrounding the latest surveillance laws passed in India, including a first-hand account of someone writing from inside India. The legislation in question is the Information Technology Act's amendment bill 2006, which was recently passed in the Indian parliament. Things you can't do with the new legislation include surfing for news in Bollywood and looking up porn on the internet. The legislation also allows all transmissions over the internet to be monitored for any form of lawbreaking and permits a sub-inspector to break into your house to make sure you aren't browsing porn on your computer."



If you make an exact copy of your data as it changes, you are protected when (not if) a hard drive fails – but you are not protected if you are writing corrupt data to the disk.

http://hardware.slashdot.org/article.pl?sid=09%2F01%2F02%2F1546214&from=rss

Why Mirroring Is Not a Backup Solution

Posted by kdawson on Friday January 02, @12:25PM from the pointed-lesson dept. Data Storage IT

Craig writes

"Journalspace.com has fallen and can't get up. The post on their site describes how their entire database was overwritten through either some inconceivable OS or application bug, or more likely a malicious act. Regardless of how the data was lost, their undoing appears to have been that they treated drive mirroring as a backup and have now paid the ultimate price for not having point-in-time backups of the data that was their business."

The site had been in business since 2002 and had an Alexa page rank of 106,881. Quantcast said they had 14,000 monthly visitors recently. No word on how many thousands of bloggers' entire output has evaporated.



Whatever you do, don't tell the taxpayers! Download the spreadsheet and try to keep it up to date? Naaah, too depressing.

http://www.bespacific.com/mt/archives/020213.html

January 02, 2009

Calculating the Acutal Cost of the Financial Bailout

Several sources are reporting the current price tag for the bailout of the financial system. According to the Washington Post's Binyamin Appelbaum, "...the Treasury Department has now spent or committed more money than Congress has allocated to its financial rescue program, effectively making more promises than it can afford to keep. The scorecard: Congress gave Treasury $350 billion; Treasury has allocated $354.4 billion." Another perspective, on total expenditures of $8.5 trillion, comes from Barry Ritholtz's blog posting, Calculating the Total Bailout Costs, inclusive of a handy spreadsheet.



Is Microsoft taking a page from the Free Software book? (While maintaining deniability?)

http://tech.slashdot.org/article.pl?sid=09%2F01%2F02%2F1936201&from=rss

Windows 7 Leaked To Pirates By Microsoft?

Posted by ScuttleMonkey on Friday January 02, @03:55PM from the viral-marketing-usually-comes-back-to-bite-you dept. Microsoft Windows

nandemoari writes

"The beta version of Windows 7 has been widely distributed through torrents and other file sharing systems. But now some commentators claim Microsoft deliberately allowed the package to get into the hands of pirates. ' I'm not being critical here, as some Microsoft Watch commenters will surely claim. It's rather smart marketing. Microsoft fills a big news void with something bloggers and journalists will write about. The suspense of stealth downloads from torrents and races to post the best screenshots first make the Windows 7 leak buzz all the more exciting. For other people, there is delight in seeing Microsoft squirm because Seven leaked early. Not that I see much squirming going on.'"



Something for your Swiss Army Folder?

http://www.killerstartups.com/Mobile/cherple-com-im-to-sms-and-back

Cherple.com – IM To SMS And Back

http://www.cherple.com

The gap between the internet and mobile phones is growing ever smaller. Since the iPhone and other smart phones became mainstream, there’s little difference between an IM message and an SMS text message. Cherple.com is here to make that gap even smaller. Through the site, you’ll be able to send SMS text messages to any phone in the US, and get an answer, all in IM format. Why should you care? Well, it makes getting in touch with anyone with a US cell phone instant, without having to waste money sending a text message from your phone. Standard text message charge rates apply to the user on the cell phone end, but the online user doesn’t have to worry about it. [Know anyone who deserves the entire Library of Congress at 20 Cents a message? Bob]

It could get you out of a jam, say you lost your cell phone and you need to get in touch with someone quickly. It might sound like a novelty now, but it could grow into something truly interesting. Look for a desktop version coming soon, and might we suggest a mobile app?



Who says the FBI doesn't understand technology? Look at this exotic tool for tracking your Internet surfing!

http://users.chartertn.net/tonytemplin/FBI_eyes/

Friday, January 02, 2009

Important for those of us who follow breaches.

http://www.pogowasright.org/article.php?story=20090101074119872

ANNOUNCE: Breach news moving to DataBreaches.net

Thursday, January 01 2009 @ 07:41 AM EST Contributed by: PrivacyNews

Effective today, reports and news stories on specific breach incidents will no longer be posted to PogoWasRight.org , but will have their own web site at DataBreaches.net, the Office of Inadequate Security. The OIS news feed will now appear on PogoWasRight.org's homepage for those who prefer to continue visiting this site while finding out the latest headlines from OIS and PHIprivacy.net

The change will enable site visitors to comment on breaches and to help researchers more quickly locate specific types of breaches.

Some breach-related news will continue to be posted to PogoWasRight.org, but the bulk of breach news will be on the new site. The change also enables PogoWasRight.org to continue to provide global coverage of privacy issues without important news stories being lost amid the increasing number of breach stories. PHIprivacy.net will continue to cover healthcare-related privacy issues, but healthcare-related breaches are also moving to DataBreaches.net.

Hope to see you over there, and Happy New Year!


Related

http://www.databreaches.net/?p=27

Happy New Year and Welcome!

January 1st, 2009 by admin

Whether you’ve migrated over from PogoWasRight.org, PHIprivacy.net, or just stumbled across this site, welcome and Happy New Year!

This site is devoted to reported breaches involving PII or PHI. PogoWasRight.org and PHIprivacy.net will continue to cover discussions of privacy breaches as well as other aspects of privacy news, but if you are looking for reports on breach incidents, you will now find them on this site.

In addition to news coverage, you will also find information on legislation related to breaches as it is proposed in the 111th Congress.

This site permits comments on news stories and items. Simply register and login to post your comments. No longer do you need to just mutter to yourself as you read a news story — now you can mutter out loud. [So that's what I've been doing! Bob]



Individuals are not the only potential targets in a BIG data breach.

http://www.databreaches.net/?p=120

Express Scripts extortionist sends Toyota data on 188 employees

January 1st, 2009 by admin

On November 11, Express Scripts announced that some its clients had received extortion attempts, presumably from the same person or persons who had contacted them with the threat to expose personal information if Express Scripts did not meet their demands.

On November 21, Toyota Motor Sales notified the New Hampshire Attorney General that:

[...]

Early the following week, Toyota received a similar threat directly, apparently from the same extortionist. The extortionists identified 188 current and former Toyota associates’ name, social security number and date of birth held by Express Scripts. Additionally, they suggested that they possessed similar information for “most” other current and former Toyota associates and their covered dependents. The FBI is investigating the incident.

In its letter to affected associates and their dependents, Toyota described the communication they received, and added (boldface in original):

[...]

We believe that there is some risk, based on the threat contained in extortionists’ letter, that you or your dependents’ personal information could be misused. Therefore, we believe you should consider taking action to protect your identity even though, at this time, we have received no evidence that there has been any attempt to misuse your personal information or that of your covered dependents.

Express Scripts, through its vendor Kroll, Inc. is offering fraud prevention assistance in connection with this incident (please see enclosed information). The Fraud Prevention Steps You Can Take enclosed with this letter will also be available on ToyotaVision at http://tv/toyotavision/. You may also obtain information through the Express Scripts website at www.esisupports.com We recommend that you take action promptly.


Related Everyone is impacted by Identity Theft. Expect this to devolve to any “unusual” charge.

http://www.pogowasright.org/article.php?story=20090102065507903

UK: Tell us your holiday plans, banks insist

Friday, January 02 2009 @ 06:55 AM EST Contributed by: PrivacyNews

Credit and debit cardholders are being told by banks to notify them of their holiday destinations and foreign travel plans or face having their accounts frozen in moves to combat fraud.

Customers increasingly find that trying to make a transaction abroad triggers a shutdown of their account as card companies seek to curb the use of information stolen from British cards.

Source - Times Online



How to abuse your customers...

http://www.pogowasright.org/article.php?story=20090102060252289

Twply takes a spam-and-grab approach to violating your privacy

Friday, January 02 2009 @ 06:02 AM EST Contributed by: PrivacyNews

When's the last time you gave out your username and password for something crucial to a random web service? That's what a lot of people have been doing with Twply.com. The site asks you for your username and password, and then promises to send any @replies that you get on Twitter to your email account.

However, it'll also spam its own URL across your Twitter account - "Just started using http://twply.com/ to get my @replies via email. Neat stuff!". That means they've got a big database of Twitter usernames and passwords, ripe for spamming. I wonder what could happen if they got bought by someone without a conscience... Oh, wait.

Source - TechDigest



They win contracts based on their expertise?

http://www.databreaches.net/?p=113

Malware blamed in latest SAIC breach

January 1st, 2009 by admin

Science Applications International Corporation (”SAIC”), recipient of a number of large government contracts, notified the New Hampshire Attorney General on December 9th of a security breach involving malware. The specific malware was not named, but was described as “designed to provide backdoor access.”

The breach was detected on October 28th. In its letter to an unspecified number of affected individuals, SAIC wrote:

This letter is to notify you of a potential compromise of your personal information, including your name and social security number, date of birth, home address, home phone number and clearance level and possibly other personal information necessary to complete government security clearance questionnaires (e.g., SF-8SP or SF-86). We collected this information from you to provide it to the U.S. Government either to enable you to visit a government facility or to assist you in obtaining or updating your government clearance.

Our Security personnel routinely receive information regarding malicious software from industry partners. This process led to the recent discovery on October 28, 2008 of malicious software designed to provide backdoor access on a computer used to process your security clearance or visit request. [Why is anything online beyond a unique identifier and an approved or denied flag? Bob] Unfortunately, due to the nature of this malicious software, it avoided our standard cyber security precautions which include using industry-leading software for virus and spyware detection, intrusion detection systems, and firewalls. To help detect and prevent similar attacks, we keep pace with industry best practices and software, we continue to work with our industry partners and we are implementing Trusted Desktop, which removes elevated privileges from users. [Let's hope they don't mean this version of Trusted Desktop: http://downloads.zdnet.com/abstract.aspx?docid=720717 Bob]

We have communicated with Defense Security Information Exchange and the Federal Bureau of Investigation regarding this malicious software, and we have sought evidence regarding whether the malicious software was used to access your personal information. To date there is no indication that any of your personal data was accessed. As there is a potential that it could have been accessed, we recommend that you take precautionary measures, including the actions further detailed in Exhibit A attached to this letter,

If their description and explanation sounds familiar, it may be because SAIC had another breach almost a year ago where malware (a keylogger) also evaded their detection system. In that breach, it was mostly corporate account data at risk. The nature of the data in this most recent incident is of more concern due to its security implications.

As in the previous incident, SAIC did not offer those affected by the recent breach any free services for credit monitoring or repair.


Related In case you thought I was kidding about the contracts...

http://news.cnet.com/8301-1009_3-10130225-83.html?part=rss&subj=news&tag=2547-1_3-0-5

Defense contractors eye cybersecurity bonanza

Posted by Jonathan Skillings January 1, 2009 6:46 PM PST

... Bloomberg has a year-end rundown on the efforts of the big defense contractors to tap into market that could swell to $11 billion by 2013.


Related?

http://yro.slashdot.org/article.pl?sid=09%2F01%2F02%2F0052201&from=rss

UK Government To Outsource Data Snooping and Storage

Posted by timothy on Friday January 02, @06:40AM from the avoid-conflict-of-interest dept. Privacy

bone_idol writes

"The Guardian is reporting that the private sector will be asked to manage and run a communications database that will keep track of everyone's calls, emails, texts and internet use under a key option contained in a consultation paper to be published next month by Jacqui Smith, the home secretary. Also covered on the BBC."



Oh gloom and doom!

http://www.pogowasright.org/article.php?story=20090102062518126

Data losses set to soar, predicts KPMG

Friday, January 02 2009 @ 06:25 AM EST Contributed by: PrivacyNews

KPMG’s Data Loss Barometer predicts that the number of people affected by data loss around the world could soar to 190 million in 2009, compared to 92 million in the previous year, as the credit crunch deepens.

In the three months to November 2008 the number of people affected by data loss incidents (47.8 million) was more than for the first eight months of the year combined – and 38 per cent higher than the same period in 2007 (34.5 million).

The Data Loss Barometer research concludes that the total number of reported incidents for 2008 will be 427, compared to 2007 (412) – the highest annual figure recorded by KPMG since the firm began collecting the data in 2005.

Source - SC Magazine

[From the article:

A few simple questions such as ‘Do you know where your data comes from?’, ‘Where it is stored and how it is used?’ and ‘Do you have a clear plan of what to do should you lose your data?’ are good starting points for all businesses – large and small.”



Attention Homeland Security! Isn't this the system you want to install?

http://www.pogowasright.org/article.php?story=2009010113151646

S. Korean woman 'tricked' airport fingerprint scan

Thursday, January 01 2009 @ 01:15 PM EST Contributed by: PrivacyNews

A South Korean woman entered Japan on a fake passport in April 2008 by slipping through a state-of-the-art biometric immigration control system using special tape on her fingers to alter her fingerprints, it was learned Wednesday.

Source - Daily Yomiuri

[From the article:

The sources said the fact that the woman was so easily able to beat the sophisticated computer system will force the government into a drastic review of its counterterrorist measures and the current screening immigration system.

The immigration bureau reported to the Justice Ministry that a considerable number of South Koreans might have entered Japan illegally using the same technique, as a South Korean broker is believed to have helped the woman enter Japan.



Wouldn't it be nice to connect a numbers of people, each interested in a narrow area of law, and produce high-level overviews like this one every week?

http://www.pogowasright.org/article.php?story=20090102062125484

Log retention initiatives

Friday, January 02 2009 @ 06:21 AM EST Contributed by: PrivacyNews

David Fraser of Canadian Privacy Law Blog presents a brief snapshot of some legal initiatives that affect internet log retention in a selection of countries.

Source - Slaw



Illustrating once again that there are many ways to skin a cat. But, is the DA just creating a larger petard?

http://www.pogowasright.org/article.php?story=20090101072011731

ID cases may go to grand jury

Thursday, January 01 2009 @ 07:20 AM EST Contributed by: PrivacyNews

Weld District Attorney Ken Buck has requested a grand jury be assembled to decide whether there’s enough evidence to arrest more than 1,000 people suspected of identity theft.

Buck asked for the jury Tuesday after he and Weld District Court Judge James Hartmann continued to disagree on whether the tax records of defendants in the identity theft sting Operation Number Games were confidential.

Source - Greeley Tribune

[From the article:

The Weld County Sheriff’s and District Attorney’s offices began the effort in November to apprehend 1,300 people suspected of identity theft or criminal impersonation in northern Colorado by seizing their federal income tax records from Amalia’s Tax Service in Greeley. The tax records were used as evidence of them using false or stolen Social Security numbers. [So you can see why he doesn't want then toss out. Bob]

... Buck has said he consulted with the Internal Revenue Service before filing the cases and firmly believes the information is not considered confidential. [Amplify! Are my records confidential? If not, why not? Bob]

... Convening a grand jury also would eliminate the need for preliminary hearings, which are held to determine if there’s enough evidence to take the matters to trial.

In a preliminary hearing Monday, Hartmann dismissed two criminal impersonation cases against one defendant involved in Operation Number Games because of a lack of evidence.



For my security classes and your security manager

http://www.bespacific.com/mt/archives/020211.html

January 01, 2009

Google Releases Browser Security Handbook

SecurityFocus: "Google posted...a handbook for Web developers that highlights the key security features and quirks of major Web browsers. The document, dubbed the Browser Security Handbook, has three parts that tackle the security features in browsers and browser-specific issues that could lead to security weaknesses."



Documenting the decline and fall of the Microsoft Empire

http://tech.slashdot.org/article.pl?sid=09%2F01%2F01%2F2322235&from=rss

IE Market Share Drops Below 70%

Posted by timothy on Thursday January 01, @07:06PM from the probably-too-late-to-open-source-ie dept. Internet Explorer Microsoft Software

Mike writes

"Microsoft's market share in the browser dropped below 70% for the first time in eight years, while Mozilla broke the 20% barrier for the first time in its history. It's too early to tell for sure, but if Net Applications' numbers are correct, then Microsoft's Internet Explorer will end 2008 with a historic market share loss in a software segment Microsoft believes is key to its business."



In contrast to the Microsoft article above... (Is this so different from a “feature want list?”)

http://tech.slashdot.org/article.pl?sid=09%2F01%2F02%2F0037254&from=rss

Google Wants You To Be Its Unpaid Muse

Posted by timothy on Friday January 02, @08:10AM from the voluntary-grindstone-for-nose-skinning dept. Google Businesses

theodp writes

"So where do you turn to for great ideas when tough times force you to abort your engineers' brainchildren? If you're Google, reports Nicholas Carlson, you simply outsource brainstorming to your users. Google's launched a new Google Product Ideas blog as well as a Product Ideas for Google Mobile site where users can submit feature and product ideas and vote on others. So what's in it for you if you come up with Google's next billion-dollar-idea? 'If you post an idea or suggestion and we put it into action, we may give you a shout out on our Product Ideas blog,' explains Google, 'but we won't be compensating users for their ideas.' Lucky thing don't-be-evil Googlers don't have to live up to the IEEE Code of Ethics, or they might have to credit properly the contributions of others."

So what's wrong with a shout out among consenting adults?

Thursday, January 01, 2009

More, shall we say “inventive” language in the press release. (and another suggestion for contracts with third parties: Delete the data when your task is done!)

http://www.pogowasright.org/article.php?story=20081231094603792

OH: OSU students told that private information was on Internet

Wednesday, December 31 2008 @ 09:46 AM EST Contributed by: PrivacyNews

Ohio State University has notified 18,000 current and former students that their names and Social Security numbers were mistakenly stored on a computer server exposed to the Internet.

A vendor doing work for Ohio State's student health insurance plan made the mistake. Only students enrolled in the school's insurance program from fall 2005 to summer 2006 are affected.

... The data included student names, Social Security numbers, addresses and coverage dates for those enrolled in the health insurance plan for three quarters in 2005-06.

Source - Columbus Dispatch - OSU web site on breach

[From the article:

Ohio State officials said the students' personal information has been deleted from Internet search engines [I doubt they know of half the search engines out there. What they actually mean is the archives some SEs make. Bob] and they haven't heard of any cases of identity theft related to the incident.

... OSU officials became concerned when a small number of students said they had found their personal data on the Internet in September.



Tip to crooks: Pick you targets carefully!

http://www.pogowasright.org/article.php?story=20081231104112259

IL: 8 arrested in ring targeting police credit unions

Wednesday, December 31 2008 @ 10:41 AM EST Contributed by: PrivacyNews

Police have arrested eight people in a two-month-long investigation of at least $150,000 in credit card fraud against members of two police credit unions, officials announced late Tuesday.

The fraud ring, which involved seven employees of Chicago-area retail stores, hit 140 accounts at Illinois State Police Credit Union and the Chicago Patrolmen's Credit Union, according to Illinois State Police.

... The ring involved seven employees of retail stores who either bought merchandise fraudulently or helped other people buy goods fraudulently. Investigators began their probe after people with accounts at the two credit unions found out someone was making fraudulent purchases on their cards, according to police.

Source - Chicago Breaking News

Related - Press Release from Illinois Attorney General, sent by Rob Douglas.



Every new technology (toy) needs software written from scratch. How else can we re-invent all the classic glitches of a bygone era?

http://it.slashdot.org/article.pl?sid=08%2F12%2F31%2F1428254&from=rss

Microsoft Zunes Committing Mass Suicide

Posted by CmdrTaco on Wednesday December 31, @10:04AM from the i-bet-a-bricked-zune-is-still-warm dept. Bug Media Microsoft Hardware

jddeluxe writes

"There are multiple reports springing up all over the internet of a mass suicide of Microsoft 30GB Zune players globally. Check Zune forums, Gizmodo, or other such sites; the reports are spreading rapidly, except apparently to the Microsoft official Zune site."


Related Fix or wishful thinking?

http://gizmodo.com/5121822/official-fix-for-the-zune-30-fail

Official Fix for the Zune 30 Fail

By Brian Lam, 5:29 PM on Wed Dec 31 2008

Microsoft's responded to the Zune 30GB failure, blaming a leap-year handling bug. And they've provided a fix. Which is to wait til New Years, when the bug will go away by itself. Huh.



Sour Grapes, corporate style. If you send customers to the Internet, will they ever return? (And if you thought that customers would meekly accept this, read the comments!)

http://news.slashdot.org/article.pl?sid=08%2F12%2F31%2F1827256&from=rss

Time Warner Recommends Internet For Some Shows

Posted by timothy on Wednesday December 31, @02:09PM from the how-to-keep-hulu-in-page-views dept. The Media Businesses Television

EdIII writes

"The dispute between Time Warner and Viacom over fees seems to be without any resolution this year. Time Warner faces the possibility of being without content for almost 20 channels. Alexander Dudley, a spokesperson for Time Warner, is fighting back: 'We will be telling our customers exactly where they can go to see these programs online,' Mr. Dudley said. 'We'll also be telling them how they can hook up their PCs to a television set.' Why pay for digital cable when many content providers are now providing it on demand via the Internet? Not to mention the widespread availability of TV shows in both standard and high definition on public and private torrent tracker sites. It is entirely possible to watch television with no commercials or advertising with only an Internet connection. So getting your content via the Internet is not exactly free, but it certainly isn't contributing to Time Warner or any other cable providers' revenue stream. The real question is why Time Warner would fight back by so clearly showing how increasingly obsolete they are becoming and that cable providers are losing their monopolistic grip on media delivery."

If no agreement is reached, those channels are supposed to be dropped just after midnight tonight.

[One interesting comment:

If you go to www.mtv.com or www.comedycentral.com (or any other Viacom property) and you're coming from a Time Warner-served IP, you'll get a nice pop up message that indicates your channels will be dropped on your (assumed) cable service.

It is also my understanding that after new years, should there be no deal, that Viacom will be pulling video access for a variety of their sites, if you're coming from the aforementioned ISP. Obviously its not that hard to do, if they already have that pop up working.


Related Did Viacom chicken out?

http://www.washingtonpost.com/wp-dyn/content/article/2009/01/01/AR2009010100621.html

Viacom and Time Warner reach deal to avoid blackout

Reuters Thursday, January 1, 2009; 7:38 AM


Related but opposite? Turmoil in the music space? Still searching for a business model!

http://news.slashdot.org/article.pl?sid=08%2F12%2F31%2F2149236&from=rss

Capitol Records Flooded Internet With MP3s, Says MP3Tunes CEO

Posted by timothy on Wednesday December 31, @05:29PM from the how-much-carrot-how-much-stick dept. The Courts

NewYorkCountryLawyer writes

"In court papers filed in New York in Capitol Records v. MP3Tunes, the CEO of MP3Tunes, Michael Robertson, has accused the plaintiffs EMI, Capitol Records, and other EMI record labels of flooding the internet with free MP3s of their songs for promotional purposes, 'free to everyone (except, apparently, MP3tunes).' His 10-page declaration (PDF) provides exact details of specific song files, including the URLs from which they are being distributed free of charge, both by paid content distributors, and by EMI itself from its own web sites."



FEMA: A whole 'nother country? Is it me, or are they speaking gibberish?

http://www.bespacific.com/mt/archives/020204.html

December 31, 2008

FEMA Launches DisasterAssistance.gov

"DisasterAssistance.gov is an easy to use website that consolidates disaster information in one place. Currently, 17 U.S. Government agencies, which sponsor more than 40 forms of disaster assistance, contribute to the website. You can apply for many forms of assistance with a single, online application. Your application information is shared only with those agencies that you identify and is protected by the highest levels of security. Ultimately, DisasterAssistance.gov will speed the application process and allow you to check the progress of your application online."

[Gibberish from the website:

Take Full Pre-Screening Questionnaire

Take an anonymous questionnaire to obtain and apply for the most accurate list of disaster forms of assistance for which you may be eligible.

[I clicked on the link but didn't answer ANY of the questions... Seems I'm still eligible for three forms of assistance! Bob]