Friday, March 06, 2009

Consequences! What a novel idea.

http://www.pogowasright.org/article.php?story=20090305153252110

Consumer Reporting Agency Settles FTC Charges: Sold Tenant Screening Reports to Identity Thieves

Thursday, March 05 2009 @ 03:32 PM EST Contributed by: PrivacyNews

A consumer reporting agency that failed to properly screen prospective customers and, as a result, sold at least 318 credit reports to identity thieves, has agreed to settle Federal Trade Commission charges that it violated federal law. Under the settlement, the company and its principal must ensure that they provide credit reports only to legitimate businesses for lawful purposes, use a comprehensive information security program, and obtain independent audits every other year for 20 years. The settlement also imposes a $500,000 penalty but suspends payment due to the defendants’ inability to pay.

.... The defendants are Rental Research Services, Inc. and Lee Mikkelson, both located in Eden Prairie, Minnesota. The Commission vote to authorize staff to refer the complaint and stipulated final order to the Department of Justice for filing was 4-0. The documents were filed in the U.S. District Court for the District of Minnesota.

Source - FTC Related FTC Files



Great little chart to illustrate the problem

http://www.atthebreach.com/blog/patch-availability-at-time-of-breach/

Patch Availability At Time of Breach

Recently Cybertrust released a data breach study . There is a lot of great information in it, but one thing I found particularly interesting was regarding breaches that were caused by vulnerability exploit. In those instances, how long had patches been available that if used would have prevented the breach from occuring. What they found from their in depth analysis of 500 data breach cases was the attached graphic. In 90% of cases, breaches had been available for more than 6 months. In no cases were there exploits of vulnerabilities that had patches available for 1 month or less. This emphasizes a blog post that talks about why hackers use old vulnerabilities to compromise networks. The answer is simply because they work!

Perhaps more emphasis should be placed on ensuring all systems are patched including all operating systems, and most importantly the 3rd party apps that we use rather than just how quickly we can patch.



Why do they really want to do this?

http://www.pogowasright.org/article.php?story=20090305181511636

Amex Demands Right to Call and SMS Any Phone You Call Them From

Thursday, March 05 2009 @ 06:15 PM EST Contributed by: PrivacyNews

American Express wants to keep in touch.

So much so that Amex is changing its fine print so that it or its robots can call or SMS card holders on any phone line a member ever uses to contact the company, and the card holder will get the bill.

That change in its U.S. card holders' terms of service agreement means travelers should be very wary about using hotel phones, pay phones, borrowed mobiles, or satelite phones to call Amex--- even in an emergency, according to travel guru Edward Hasbrouck who first brought attention to the change.

Source - Threat Level

[From the article:

But Amex's VP for Public Affairs Desiree Fish says users shouldn't worry about the change and that it doesn't mean what it plainly means. Amex will never divulge secret info over the phone or via SMS, Fish assures, and if people want to opt out of marketing phone calls, they can do so online.



Did someone actually hint they would consider writing a law?

http://www.pogowasright.org/article.php?story=20090305122329420

Major tech companies to drop support for comprehensive U.S. privacy law

Thursday, March 05 2009 @ 12:23 PM EST Contributed by: PrivacyNews

In the summer of 2006, a who's who of technology and Internet companies garnered headlines when they formed the Consumer Privacy Legislative Initiative. The group, which included Intel, Microsoft, eBay, Google, HP, Oracle, and Sun, was charged with promoting the adoption of a national privacy law in the U.S. (initial statement here). According to BNA's Electronic Commerce & Law Report (sub required), next week those same companies will announce a shift in name and emphasis.

Source - Straight.com

[From the article:

Microsoft Chief Privacy Strategist Peter Cullen tells BNA that "legislation is actually the wrong place to start. To provide effective privacy protection, it's going to potentially require good legislation. But more importantly, it will require good business processes and good accountability." The group is therefore morphing into the Business Forum for Consumer Privacy, which advisors say is working toward building a self-regulatory framework.



Wow You can get anything on Craig's List!

http://yro.slashdot.org/article.pl?sid=09/03/05/2225208&from=rss

Sheriff Sues Craiglist For Prostitution Ads

Posted by timothy on Thursday March 05, @05:50PM from the shameful-waste-of-tax-money dept. The Courts Privacy Politics

Amerika writes

"Craigslist is 'the single largest source of prostitution in the nation,' according to Cook County, Illinois Sheriff Thomas Dart. He has announced that he's filing a lawsuit against the popular classifieds site. Craigslist says it's determined to prevent criminal activity."

NewYorkCountryLawyer adds a link to the 28-page complaint (PDF), which "alleges that Craigslist maintains 21 classifications of sex-for-hire, coded as 'w4m,' 'm4m,' 'm4w,' etc." and that it has facilitated child prostitution and kidnapping and human trafficking.



Boy did they get roasted for this one. (Looks like the site crashed too.)

http://news.slashdot.org/article.pl?sid=09/03/05/215209&from=rss

State of Colorado Calls Firefox Insecure, IE6 Safe

Posted by timothy on Thursday March 05, @04:43PM from the sheeps'-bladders-may-be-used-to-prevent-earthquakes dept. Security Government Internet Explorer Mozilla IT

linuxkrn writes

"The State of Colorado's Office of Technology (OIT) has set up a work skills website. The problem is that the site says 'DO NOT use FIREFOX or other Browsers besides IE. It has been decided that Mozilla based, non-IE browsers pose a security risk.' (Original emphasis from site.) If the leading IT agency for the State is making these uneducated claims, should the people worry about their other decisions?"


Related Geeky stuff

http://tech.slashdot.org/article.pl?sid=09/03/06/029215&from=rss

9 Browsers Compared For Speed and Features

Posted by timothy on Thursday March 05, @10:57PM from the you-forgot-konqui-and-galeon dept. Software The Internet

notthatwillsmith writes

"Counting public betas and release candidates, there are a whopping nine different web browsers out today with enough market share to be considered mainstream. Maximum PC explains the differences between the browsers, future and present, so that you can make a more informed decision about the primary tool you use to browse the web. From the rendering engines used to the features that set the different browsers apart, this is a comprehensive, blow-by-blow battle between Safari 3, Internet Explorer 7, Firefox 3, Opera 9.6, Google Chrome, Firefox 3.1, IE 8, Safari 4, and Opera 10."



Useful resource

http://www.bespacific.com/mt/archives/020754.html

March 05, 2009

New on LLRX.com: Knowledge Discovery Resources 2009: An Internet MiniGuide Annotated Link Compilation

LLRX.com - Knowledge Discovery Resources 2009: An Internet MiniGuide Annotated Link Compilation - Marcus P. Zillman's compilation is dedicated to the latest and most reliable resources for knowledge discovery available through the Internet. This wide ranging selection of resources provides specialized tools, applications and sources relevant to researchers from many disciplines.



I looked. They don't have Java or C++

http://www.killerstartups.com/Web20/sanbit-com-learning-up-a-new-language

Sanbit.com - Learning Up A New Language

http://sanbit.com/

Sanbit is a new site that plays out a welcome role: letting you pick up a new language in a lively setting. The site makes for practicing every aspect of any foreign language that you might be interested in, and this includes not only reading texts and listening to audio files but also writing essays that are read by those who make up the community of native speakers.

One of the best features on offer is the ability to find language partners that will let you practice what you have learned so far with all the inherent advantages that the contact with others bring.



TRY THIS! Very interesting. Pick a location and then monitor the twitter traffic...

http://monitter.com/

monitter? what is it?

Simple. It's a twitter monitor, it lets you "monitter" the twitter world for a set of keywords and watch what people are saying. Cool huh?



Geek history with images!

http://hardware.slashdot.org/article.pl?sid=09/03/05/190242&from=rss

A History of Storage, From Punch Cards To Blu-ray

Posted by timothy on Thursday March 05, @02:38PM from the isn't-that-right-joey dept. Data Storage Media

notthatwillsmith writes

"Maximum PC just posted a comprehensive visual retrospective about data storage, starting with the once state of the art punch card and moving through the popular formats of yesteryear, including everything from magtape to Blu-ray discs. It's amazing how much data you could pack on a few hundred feet of half-inch magnetic tape!"

[From the article:

A single reel of the oxide coated half-inch tape could store as much information as 10,000 punch cards



Geeky stuff

http://www.killerstartups.com/Web-App-Tools/screenfix-net-making-the-web-crisp-once-again

ScreenFix.net - Making The Web Crisp Once Again

http://www.screenfix.net/

ScreenFix compiles together a set of five different tools that can be used by anybody in order to have a crisp image on his monitor. These applications are three different checkers (“Gamma Checker”, “Phasing Checker” and “Brightness Checker”) and two fixers (“Dead Pixel Fixer” and “Flickr Fixer”). Moreover, the site includes a tool for checking TN monitors, and that tool goes by the corresponding denomination.

These tools go by self-explanatory names, and they are all provided at no cost. They are all hosted on the server, too, so that you won’t have to incur into software downloads of any kind, nor worry about updating anything.

Thursday, March 05, 2009

Security processes without monitoring is worthless. This would seem to refute those “no one could use the tapes” press releases.

http://www.databreaches.net/?p=1969

NYPD civilian worker busted in mass cop-ID Theft

March 4, 2009 by admin

Reuven Blau reports:

A civilian official of the NYPD’s pension fund has been charged with taking computer data that could be used to steal the identities of 80,000 current and retired cops, sources said.

Anthony Bonelli allegedly got into a secret backup-data warehouse on Staten Island last month and walked out with eight tapes packed with Social Security numbers, direct-deposit information for bank accounts, and other sensitive material.

Read more on NY Post

[From the article:

Sources said he managed to get past a guard on Feb. 21, unplugged video cameras, and left with the stolen tapes.

Bonelli raised suspicion with comments he made at work last week.

The NYPD sent technology specialists to the site, where they discovered that the cameras had been disabled and the tapes were missing. [No one noticed? Bob] The tapes were found at Bonelli's home when he was arrested Saturday, police said



Another step toward Big Brother-ness?

http://www.pogowasright.org/article.php?story=20090304072735895

AU: Latest police weapon: a secret search

Wednesday, March 04 2009 @ 07:27 AM EST Contributed by: PrivacyNews

New powers to secretly search homes and computers of people suspected of crimes ranging from murder to organised theft are wider than those now used against suspected terrorists.

The new covert search warrants would give police up to three years to delay informing targets they had carried out a raid on their property.

Source - Sydney Morning Herald

[From the article:

The proposed covert laws became necessary after the Supreme Court found in 2007 that three covert searches on a children's author suspected of drug offences had been unlawful. [When you want to keep doing something that is illegal, you simply change the law. Bob]

… But the Premier, Nathan Rees, said: "If you are a serious criminal [Translation: not a cop Bob] you should be very anxious. We now will have the power to enter your home without you knowing and collect evidence for subsequent prosecutions."


Related

http://www.pogowasright.org/article.php?story=20090304170722247

EXCLUSIVE: Google Takes a Stand for Location Privacy, Along with Loopt

Wednesday, March 04 2009 @ 05:07 PM EST Contributed by: PrivacyNews

Thanks in part to feedback from EFF, Google has chosen to take a strong and public stand on what legal privacy protections should apply if the government comes calling for the location data collected by Latitude, Google’s new cell phone-based friend-finding service. Google has decided to match the policy for dealing with law enforcement demands first adopted by its friend-finding competitor Loopt after consultation with EFF, a policy which relies on the strongest possible legal arguments for protecting users’ location privacy. The gist of the Latitude and Loopt policies? “Come back with a warrant.”

Source - EFF



There is a law journal article here!

http://news.cnet.com/8301-1023_3-10188981-93.html?part=rss&subj=news&tag=2547-1_3-0-5

Google Health lets users share their online records

by Steven Musil March 4, 2009 9:45 PM PST

Google Health has introduced a new feature that lets users share their online health records with designated doctors, friends, and family members.

Google said the move was in response to users' concerns that care-givers and loved ones might not be up to date on all the details of a patient's health situation, especially in the event of an emergency.

… Recognizing the sensitive nature of sharing health records, Google said it has built in several security measures to preserve privacy. Users choose who can view their histories [Hard to do when you are unconscious. Bob] and the link to the patient's profile will work only in connection with those people's e-mail addresses ['cause no one knows my email address... Bob]--meaning the link won't work if it is forwarded to a third party. Users can also decide what information they want to share, and those allowed to view the profile will not have the ability to edit the information. [Can they add to it? Bob] Users will also be able to see exactly who has reviewed the profile.

However, one security measure that is a bit baffling is a feature that restricts the usability lifespan of the e-mailed link to only 30 days. Unless the user is diligent about regularly sending links to loved ones, this protection could negate the feature's value in the event of an emergency.

Google also announced a feature that allows users to print wallet- and letter-size hard copies of a their profile, including medications, allergies, conditions, and treatments. But again, the value of these printouts may be questionable if they are not updated and replaced regularly.

Google Health, which is dedicated to the digitization of health records, launched in May 2007. Microsoft has also planned a medical records service called HealthVault. President Obama, meanwhile, has made it clear that he plans to make digital health records part of his health care reform agenda.



Watch the Justices Rap!

“Damn dem lawyers,

damn their eyes,

we'll hit 'em in the puss,

with custard pies!”

http://www.iht.com/articles/2009/03/03/america/03bar.php

The U.S. Supreme Court enters the YouTube era

By Adam Liptak Published: March 3, 2009

WASHINGTON: The first citation in a petition filed with the court last month, for instance, was not to an affidavit or a legal precedent but rather to a YouTube video link. The video shows what is either appalling police brutality or a measured response to an arrested man's intransigence — you be the judge.

Such evidence vérité has the potential to unsettle the way appellate judges do their work, according to a new study in The Harvard Law Review. If Supreme Court justices can see for themselves what happened in a case, the study suggests, they may be less inclined to defer to the factual findings of jurors and to the conclusions of lower-court judges.

… Three law professors accepted that invitation and made it the basis of an interesting study published in January in The Harvard Law Review. They showed the video to 1,350 people, who mostly saw things as the justices did. Three-quarters of them thought the use of potentially deadly force by the police was justified by the risk Harris's driving posed.

But African-Americans, liberals, Democrats, people who do not make much money and those who live in the Northeast were, the study found, "much more likely to see the police, rather than Harris, as the source of the danger posed by the flight and to find the deliberate ramming of Harris's vehicle unnecessary to avert risk to the public."



I'm sure there must be “nothing but games” stores out there somewhere, but most serious gamers wouldn't spend time to drive to and from the store when they could spend it playing their games.

http://games.slashdot.org/article.pl?sid=09/03/05/0655225&from=rss

How Much Longer Will Physical Game Distribution Survive?

Posted by Soulskill on Thursday March 05, @05:18AM from the shortly-after-blizzard-conquers-the-earth dept.

GamesIndustry is running an interview with Theodore Bergquist, CEO of GamersGate, in which he forecasts the death of physical game distribution in favor of digital methods, perhaps in only a few years. He says, "Look at the music industry, look at 2006 when iTunes went from not being in the top six of sellers — in the same year in December it was top three, and the following year number one. I think digital distribution is absolutely the biggest threat [traditional retailers] can ever have." Rock, Paper, Shotgun spoke with Capcom's Christian Svensson, who insists that developing digital distribution is one of their top priorities, saying Capcom will already "probably do as much digital selling as retail in the current climate." How many of the games you acquire come on physical media these days? At what point will the ease of immediate downloads outweigh a manual and a box to stick on your shelf (if it doesn't already)?



One of those articles than stops me in my tracks. Why? Probably lots of reasons, but most are logistical. Now if they replace Windows with Linux, they've really got something.

http://tech.slashdot.org/article.pl?sid=09/03/04/2234259&from=rss

Microsoft Windows, On a Mainframe

Posted by timothy on Wednesday March 04, @05:47PM from the operating-systems-plural dept. Windows Microsoft Operating Systems

coondoggie writes with an excerpt from Network World:

"Software that for the first time lets users run native copies of the Windows operating systems on a mainframe will be introduced Friday by data center automation vendor Mantissa. The company's z/VOS software is a CMS application that runs on IBM's z/VM and creates a foundation for Intel-based operating systems. Users only need a desktop appliance running Microsoft's Remote Desktop Connection (RDC) client, which is the same technology used to attach to Windows running on Terminal Server or Citrix-based servers. Users will be able to connect to their virtual and fully functional Windows environments without any knowledge that the operating system and the applications are executing on the mainframe and not the desktop."

[From the article:

According to the company's Web site, users will be able to create a PC in 15 seconds, have it operational in 15 minutes and use it once or have it permanently without worrying about depreciation of hardware.

… The z/VM hypervisor already natively supports the ability to run hundreds to thousands of Linux servers on a single mainframe.

… "The product has been a bear for the development group but the thought of being able to run 3,000 copies of Windows [Compare: Windows license fee X 3000 v. Free X100,000 Which give you bang for the buck? Bob] on one System z so fascinated the team that we needed very little additional incentive," Mantissa CEO and founder Gary Dennis said on the IBMVM list serve site last summer when he introduced the z/VOS concept.



E-Discovery A case for adding Data Mining/Data Analysis to the various Computer curriculums. Also some great examples for my Forensics classes.

http://ralphlosey.wordpress.com/

Jason Baron on Search - How Do You Find Anything When You Have a Billion Emails?

March 4, 2009



Geek stuff and the potential to create an ad hoc network with your friends/collaborators.

http://tech.slashdot.org/article.pl?sid=09/03/05/0415249&from=rss

LimeWire Brings Darknets To All

Posted by samzenpus on Thursday March 05, @07:57AM from the yes-have-some dept. Social Networks Technology

An anonymous reader writes

"LimeWire's new version lets people create private darknets with contacts on any Jabber server (like GMail or LiveJournal). It's different than the recent p2p darknet announcement because it doesn't use onion routing. Sharing with a friend connects directly to that friend. If you're worried about exposing personal information, LW5 doesn't share documents with the p2p network by default."



This is interesting. Return articles, images and videos related to the search! Definitely worth a look.

http://www.killerstartups.com/Search/daymix-com-news-of-the-world

Daymix.com - News Of The World

http://daymix.com/

A visit to this portal seems a good idea if you are looking for a fresh way to access all the news appertaining to you the most. In general terms, Daymix aims to show its users the latest information on any topic. This includes not only news that have been reported by major online agencies and channels but also blog posts and the buzz surrounding these topics as of late. Of course, the site also includes media contents, and photographs and videos top the list.



Very simple. I think I have several uses for this one!

http://www.killerstartups.com/Web-App-Tools/online-stopwatch-chronme-com-time-yourself

Online-Stopwatch.Chronme.com - Time Yourself

http://www.online-stopwatch.chronme.com/

This new solution is nothing more and nothing less than an online stopwatch that you can employ to see how you are managing your time. Essentially, it will let you record daily activities and then save reports to your computer in a very straightforward way indeed.

In order to use this system, you simply press the “Start” button and get down to what has to be done. Once you are finished, simply click on the “Stop” button and then proceed to add a label that describes the activity. You repeat the process as many times as you desire, and once you have compiled the full list you can download it to your desktop, or open it using Excel.



Evil business model: We build a site like this and then we assign realllly hard homework problems!

http://news.yahoo.com/s/nm/20090304/od_nm/us_france_homework_odd_1

You do the math. Or pay a website to do it..

Wed Mar 4, 1:21 pm ET

PARIS (Reuters) – "You can't do it? We're here to help," says the homepage of a new French website where children can pay for older students to do homework for them.

On faismesdevoirs.com (domyhomework.com), children will be able to buy answers to simple maths problems for 5 euros ($6), while a full end-of-year presentation complete with slides and speaking notes will cost 80 euros ($100).

… Schoolteachers reacted with outrage. [Because they didn't get a cut? Bob]

Wednesday, March 04, 2009

Perhaps they will steal all those bad loans and the banks will suddenly be solvent!

http://it.slashdot.org/article.pl?sid=09/03/03/1951222&from=rss

Tigger.A Trojan Quietly Steals Stock Traders' Data

Posted by kdawson on Tuesday March 03, @04:37PM from the where-the-money-is dept.

**$tarDu$t** recommends a Washington Post Security Fix blog post dissecting the Tigger.A trojan, which has been keeping a low profile while exploiting the MS08-66 vulnerability to steal data quietly from online stock brokerages and their customers. An estimated quarter million victims have been infected. The trojan uses a key code to extract its rootkit on host systems that is almost identical to the key used by the Srizbi botnet. The rootkit loads even in Safe Mode.

"Among the unusually short list of institutions specifically targeted by Tigger are E-Trade, ING Direct ShareBuilder, Vanguard, Options XPress, TD Ameritrade, and Scottrade. ... Tigger removes a long list of other malicious software titles, including the malware most commonly associated with Antivirus 2009 and other rogue security software titles... this is most likely done because the in-your-face 'hey, your-computer-is-infected-go-buy-our-software!' type alerts generated by such programs just might... lead to all invaders getting booted from the host PC."



Clearly something to point my “Intro to Computer Security” class to...

http://www.pogowasright.org/article.php?story=20090303094330706

EFF Releases How-To Guide to Fight Government Spying

Tuesday, March 03 2009 @ 09:43 AM EST Contributed by: PrivacyNews

The Electronic Frontier Foundation (EFF) launched its Surveillance Self-Defense project today -- an online how-to guide for protecting your private data against government spying. You can find the project at http://ssd.eff.org.

EFF created the Surveillance Self-Defense site to educate Americans about the law and technology of communications surveillance and computer searches and seizures, and to provide the information and tools necessary to keep their private data out of the government's hands. The guide includes tips on assessing the security risks to your personal computer files and communications, strategies for interacting with law enforcement, and articles on specific defensive technologies such as encryption that can help protect the privacy of your data.

Source - EFF Press Release



Would you steal if you had a 99% chance of getting away with it?

http://news.cnet.com/8301-1009_3-10186176-83.html?part=rss&subj=news&tag=2547-1_3-0-5

Gartner: Financial fraud hits 7.5 percent of U.S. adults

by Elinor Mills March 3, 2009 9:01 PM PST

About 7.5 percent of U.S. adults lost money as a result of financial fraud last year, mostly due to data breaches, according to a new Gartner study to be released on Tuesday night.

In the survey of nearly 5,000 consumers, 70 percent said they had never been a victim of identity theft fraud. Meanwhile 14 percent said they had had their credit card information used to charge purchases or get money, 7 percent said their debit card was used, 6 percent said a new account had been opened in their name, 5 percent had money transferred out of their account, and 4 percent had had checks forged.

… "The chances of a criminal getting arrested and convicted for identity theft-related fraud are much less than a half of 1 percent," the study said.



Analyzing and interpreting the data is going to be important. What liability would an employer or provider assume? i.e. Will they recognize a terrorist website when their employees connect to one?

http://www.pogowasright.org/article.php?story=20090304064506644

Fi: Parliament Passes "Lex Nokia" BIll

Wednesday, March 04 2009 @ 06:45 AM EST Contributed by: PrivacyNews

Parliament has passed the controversial reforms to the data protection law, the so-called "Lex Nokia" bill. The vote was 96 for, 56 against. [and 47 abstentions! Bob]

... The law allows employers and other organisations that provide users with Internet service and e-mail to monitor IP traffic data. In practice, this means that employers can see who workers are e-mailing, when the message was sent, and the size of the e-mails and attachments. It will not allow them to read the contents of e-mails.

Source - YLE.fi


Related “All that is not forbidden is mandatory!” The Once and Future King

http://yro.slashdot.org/article.pl?sid=09/03/04/0028227&from=rss

Should Job Seekers Tell Employers To Quit Snooping?

Posted by kdawson on Wednesday March 04, @01:14AM from the easy-for-you-to-say-you-have-a-job dept.

onehitwonder writes in with a CIO opinion piece arguing that potential employees need to stand up to employers who snoop the Web for insights into their after-work activities, often disqualifying them as a result.

"Employers are increasingly trolling the web for information about prospective employees that they can use in their hiring decisions. Consequently, career experts advise job seekers to not post any photos, opinions or information on blogs and social networking websites (like Slashdot) that a potential employer might find remotely off-putting. Instead of cautioning job seekers to censor their activity online, we job seekers and defenders of our civil liberties should tell employers to stop snooping and to stop judging our behavior outside of work, writes CIO.com Senior Online Editor Meridith Levinson. By basing professional hiring decisions on candidates' personal lives and beliefs, employers are effectively legislating people's behavior, and they're creating an online environment where people can't express their true beliefs, state their unvarnished opinions, be themselves, and that runs contrary to the free, communal ethos of the Web. Employers that exploit the Web to snoop into and judge people's personal lives infringe on everyone's privacy, and their actions verge on discrimination."



Similar to above? Is this becoming too common to resist? (It ain't the weather, we can do something about it! Can't we?)

http://www.pogowasright.org/article.php?story=20090304065408817

Behavioral Targeting: Not That Bad?! TRUSTe Survey Shows Decline in Concern for Behavioral Targeting

Wednesday, March 04 2009 @ 06:54 AM EST Contributed by: PrivacyNews

Consumers are more conscious of behavioral targeting than ever before, according to a recent survey conducted by TNS for TRUSTe, the leading internet privacy trustmark: two out of three consumers are aware that their browsing information may be collected by a third party for advertising purposes.

Additionally, consumer discomfort with behavioral advertising declined year over year (from 57 percent in 2008 to 51 percent in 2009), suggesting that although consumers worry about protecting their private information online, they are growing more accustomed to behavioral targeting, with some even preferring to be served targeted advertisements from brands they know and trust over irrelevant, intrusive advertisements. In fact, 72 percent of those surveyed said they found online advertising intrusive and annoying when the products and services being advertised were not relevant to their wants and needs.

Source - TRUSTe Press Release via MarketWire



Perhaps the certification testing isn't everything we were led to believe.

http://news.slashdot.org/article.pl?sid=09/03/03/182230&from=rss

Diebold Election Audit Logs Defective

Posted by kdawson on Tuesday March 03, @01:28PM from the worse-than-we-thought dept. Government Politics

mtrachtenberg writes

"Premier Election Solutions' (formerly Diebold) GEMS 1.18.19 election software audit logs don't record the deletion of ballots, don't always record correct dates, and can be deleted by the operator, either accidentally or intentionally. The California Secretary of State's office has just released a report about the situation (PDF) in the November 2008 election in Humboldt County, California (which we discussed at the time). Here's the California Secretary of State's links page on Diebold. The conclusion of the 13-page report reads: 'GEMS version 1.18.19 contains a serious software error that caused the omission of 197 ballots from the official results (which was subsequently corrected) in the November 4, 2008, General Election in Humboldt County. The potential for this error to corrupt election results is confined to jurisdictions that tally ballots using the GEMS Central Count Server. Key audit trail logs in GEMS version 1.18.19 do not record important operator interventions such as deletion of decks of ballots, assign inaccurate date and time stamps to events that are recorded, and can be deleted by the operator. The number of votes erroneously deleted from the election results reported by GEMS in this case greatly exceeds the maximum allowable error rate [There's an acceptable error rate? Bob] established by HAVA. In addition, each of the foregoing defects appears to violate the 1990 Voting System Standards to an extent that would have warranted failure of the GEMS version 1.18.19 system had they been detected and reported by the Independent Testing Authority that tested the system.'"



Isn't this what the xenophobes wanted? We scream that immigrants are coming to the US to steal our jobs, now we want them to stay?

http://news.slashdot.org/article.pl?sid=09/03/03/2219256&from=rss

Smart Immigrants Going Home

Posted by kdawson on Tuesday March 03, @07:04PM from the no-longer-the-only-land-of-opportunity dept. Education United States Politics

olddotter writes

"A 24-page paper on a reverse brain drain from the US back to home countries (PDF) is getting news coverage. Quoting: 'Our new paper, "America's Loss Is the World's Gain," finds that the vast majority of these returnees were relatively young. The average age was 30 for Indian returnees, and 33 for Chinese. They were highly educated, with degrees in management, technology, or science. Fifty-one percent of the Chinese held master's degrees and 41% had PhDs. Sixty-six percent of the Indians held a master's and 12.1% had PhDs. They were at very top of the educational distribution for these highly educated immigrant groups — precisely the kind of people who make the greatest contribution to the US economy and to business and job growth."

Adding to the brain drain is a problem with slow US visa processing, since last November or so, that has been driving desirable students and scientists out of the country.



Viable business model? Looks like it to me.

http://news.cnet.com/8301-1023_3-10187655-93.html?part=rss&subj=news&tag=2547-1_3-0-5

Start-up offers alternative to subscription TV

by Marguerite Reardon March 4, 2009 6:00 AM PST

… The plan is to offer streaming movies and TV shows directly to TVs using a broadband connection.

… Users will choose one of three options for viewing the content. They can either pay a small rental fee for the movie or episode they want to view without commercials; they can "buy to own" the content, or they can view the video for free by watching targeted advertising.

Tuesday, March 03, 2009

Are they saying the PCI standards are inadequate?

http://www.americanbanker.com/btn_article.html?id=20090224Y62W5L2P

Heartland's Lonely Quest For Reform

Bank Technology News | March 2009 By Rebecca Sausner

Heartland Payment Systems CEO Robert Carr has likened his company's massive data breach to the Tylenol moment when product contamination led to an overhaul in packaging safety. It's likely Carr has had a few Tylenol moments himself in the past couple of months as he dealt with perhaps the largest data breach ever, though the actual number of cards compromised is undisclosed.

Now Carr is using his standing in the industry - he founded Heartland and enjoys healthy respect among processors - to call for industry-wide reform of payments technology and information sharing about exploits to prevent criminals from successfully deploying the same hack on multiple targets. Lots of industry players agree with his stance, but there's been scant input thus far from the industry's most influential parties: including titans such as MasterCard, Discover and Visa, which are mostly mum on the subject.

… The creation of an exploit clearinghouse that would make specific, but perhaps confidential information about security breaches available to the industry has legal and inertia challenges. It was only a day or two after the Heartland breach was announced before the first class action lawsuit was announced; if done in a totally transparent way, coming clean with exactly how they were compromised in a timely fashion could be detrimental to the company's legal defense.

But offering the insight in an anonymous fashion to a confidential clearinghouse organization could get around many of the legal issues, if only someone would step up to lead the initiative, and pay for it.



Guidelines! Perhaps they will help.

http://www.pogowasright.org/article.php?story=20090302142522694

MD: Appeals court refuses to unmask anonymous donut shop critics

Monday, March 02 2009 @ 02:25 PM EST Contributed by: PrivacyNews

A Maryland Appeals Court has overturned a lower ruling that would have unveiled the identity of three anonymous Internet commenters due to a technicality in the discovery process. Still, the judges offer advice on how trial courts should handle the situation in the future by respecting the First Amendment rights of the posters in question.

Source - Ars Technica

[From the article:

In the future, lower courts should require plaintiffs to notify anonymous posters that they are the subject of a subpoena; a posting on the message board should suffice for that. The plaintiff should not only give the posters time to file and serve opposition to whatever action is being taken, he or she should also be required to provide evidence of exact statements made by each poster. "[I]f all else is satisfied, balance the anonymous poster’s First Amendment right of free speech against the strength of the prima facie case of defamation presented by the plaintiff," reads the order.



How scared were we? (and was it real fear or political fear?) No doubt this will be well chewed over...

http://www.pogowasright.org/article.php?story=20090303051011393

Obama unseals Bush-era wiretap memos

Tuesday, March 03 2009 @ 05:10 AM EST Contributed by: PrivacyNews

The Bush administration secretly concluded after the September 11, 2001, terrorist attacks that it had the authority to wiretap the Internet and telephone calls with virtually no limitations, restrict free speech, and use the U.S. military domestically against suspected terrorists.

Those legal opinions came in a series of memorandums written by U.S. Department of Justice lawyers, including deputy assistant attorney general John Yoo, which were disclosed by the Obama administration on Monday.

Source - Cnet



“Hello, We're your elected twits. We like this technology because 1) It's cool, 2) It gets our name in the news for being technologically sophisticated (and cool), 3) We can employ our children to actually use the technology since we don't know how.”

http://www.bespacific.com/mt/archives/020728.html

March 02, 2009

House Committees Take the Lead on Using Social Media to Ensure Transparency

News release: "House Committees on Science and Technology, Education and Labor, Transportation and Infrastructure, and the Select Committee on Energy Independence and Global Warming are the first four Congressional Committees to join Twitter. These Committees use Twitter as a new tool to reach their audience and ensure transparency between the government and the public."



Shouldn't we be able to take this and create a computer program to do our estimation for us? If we make it open source, it would be a powerful “Congressman, you are lying again.” type of tool. (or would that be redundant?)

http://www.bespacific.com/mt/archives/020725.html

March 02, 2009

GAO Issues First-of-Its-Kind Cost Estimating Guide

“How Much Will This Program Really Cost?” GAO Issues First-of-Its-Kind Cost Estimating Guide to Answer Such Questions, March 2, 2009

  • "Developed with input from industry experts as well as federal officials, the 436-page Cost Estimating and Assessment Guide lays out a multi-step process for developing high-quality, trustworthy cost estimates; explains how to manage program costs once a contract has been awarded; and presents 48 case studies, drawn from GAO published audits, that illustrate typical pitfalls and successes in cost estimating. The guide stresses both sound cost estimating and earned value management (EVM), a project management tool that compares completed work to expected outcomes, in setting realistic program baselines and managing risk. In future audits, GAO plans to use the Cost Estimating and Assessment Guide to assess the accuracy of agencies’ cost estimates and determine whether programs are on schedule. The guide can be found here."



It looks like someone is capturing all the RIAA cases. Lots of links to documents. Too much to read at one go, so I'll have to defer judgment. But, this seems to excite the technorati so I'll probably take a long look... (Clearly, if this became common practice it could get expensive quick!)

http://news.slashdot.org/article.pl?sid=09/03/03/0110242&from=rss

Judge Orders Record Company Execs To Duluth

Posted by kdawson on Monday March 02, @11:42PM from the get-your-butts-up-here dept. The Courts

NewYorkCountryLawyer writes

"Lest there be any doubt that District Judge Michael J. Davis, presiding over the Duluth, Minnesota, case, Capitol Records v. Thomas, really does 'get it' about the toxic effect the RIAA, its lead henchman Matthew Oppenheim, and their lawyers have had on the judicial process, all such doubt should be removed by the order he just entered (PDF). It removes control of the decision-making process from the RIAA, Oppenheim, and the lawyers. In the order Judge Davis spells out, in the clearest possible terms so that there can be no misunderstanding, that at the extraordinary 2-day settlement conference he has scheduled for later this month, each record company plaintiff is ordered to produce an 'officer' of the corporation, or a 'managing agent' of the corporation, who has corporate, decision-making, 'power.' The judge makes it clear that no one who has 'settlement authority' with any limits or range attached to it will be acceptable. This means that 'RIAA hitman' Matthew Oppenheim will not be able to control the settlement process as he has been permitted by the Courts to do in the past."



A research aggregator? Might be a fun challenge to my students!

http://news.cnet.com/8301-17939_109-10186187-2.html?part=rss&subj=news&tag=2547-1_3-0-5

Ensembli demos simple, useful RSS aggregator

by Rafe Needleman March 2, 2009 6:44 PM PST

The RSS reader Ensembli is not a product for me, says CEO Michael Wheatley. It's certainly not a product for RSS junkies like Robert Scoble. People who use RSS feeds professionally, to stay on top of news and spot emerging issues they may not have been aware of, need feed readers that show them everything that happens in the news sources they know about. (Personally, I use Netvibes as a dashboard.) What Ensembli does is track the topics you tell it you're interested in. It then watches what you click on and fetches stories based both on those implied interests and what you've said you want to see.


Related Another type of aggregator.

http://www.killerstartups.com/Web-App-Tools/feedweaver-net-rss-feeds-made-elastic

Feedweaver.net - RSS Feeds Made Elastic

http://feedweaver.net/

Feedweaver is a web-based tool that performs a simple yet interesting operation: combining multiple RSS feeds into one, and letting you save time that can be employed elsewhere. For example, you can combine feeds from music review sites (such as Wilson & Alroy’s Record Reviews) and official band sites in order to get the scoop on what is being released, and access some reviews in the same place.

This customization process can take into consideration different keyword filters, and in the abovementioned case you could filter out genres that you don’t like, and prioritize the ones that mean the most to you.

In addition to that, you can easily share your feeds with your friends by giving them the URL of the combined feeds. They don’t even need to login either – the feeds are available to every person who knows the actual address.

By way of conclusion, Feedweaver is a practical service that will enable anybody to have better control over his preferred web-based content. It is a wholly-free service, too, and that is always a nice thing.



For my website class

http://developers.slashdot.org/article.pl?sid=09/03/03/0152241&from=rss

Open Source Usability — Joomla! Vs. WordPress

Posted by kdawson on Tuesday March 03, @05:20AM from the apples-and-orange-trees dept. Programming Technology

An anonymous reader writes

"PlayingWithWire profiles two open source tools for Web development, comparing Joomla! and WordPress through the lens of usability. The article has apparently upset a few people at the Joomla! forum, but it does bring up a good point. Many open source projects are developed by engineers for engineers — should they focus more on usability? PlayingWithWire makes a bold analogy: 'If Joomla! is Linux, then WordPress is Mac OS X. WordPress might offer only 90% of the features of Joomla!, but in most cases WordPress is both easier to use and faster to get up and running.'"

The article repeatedly stresses that blogging platform WordPress and CMS harness Joomla! occupy different levels of the content hierarchy. How fair is it to twit Joomla! on usability?



Perhaps I could list my favorite Math tutorial videos here?

http://www.killerstartups.com/Video-Music-Photo/youtubereloaded-com-embedding-youtube-videos

YouTubeReloaded.com - Embedding YouTube Videos

http://www.youtubereloaded.com/

A free YouTube playlist generator that goes by the name of YouTubeReloader is available for those who are looking into a concise way to spruce up their sites and/or blogs. You can access it by following the link provided below, and use it without the need of registering beforehand or disclosing information of any kind.

There are three playlist types on offer: “Search based”, “Predefined feeds”, and a “Custom playlist”. The playlist itself can be modified in a plethora of ways. For example, you can choose from three different skins as well as choosing the size of the player itself and stretching the video as you see fit.

For its part, you can set down play options such as autostart and shuffle, and once everything is in place you can preview the results and have the code generated instantly. You can then paste it at will all over your sites, and see if your traffic figures go up accordingly or whether you will have to dream up something else in order to stand out from the throng.



Potentially interesting tool.

http://www.killerstartups.com/Video-Music-Photo/nibipedia-com-learning-together-through-the-web

Nibipedia.com - Learning Together Through The Web

http://www.nibipedia.com/

Nibipedia is an online community that revolves around educational videos that cover different topics. These videos can be readily searched and accessed from the main page, and they are also grouped under categories and tags such as “World Civics”, “Science” and “Internet & Computers”.

When you watch any of the featured videos, you are also provided with the full Wikipedia article as regards that topic, and further links that will take you to related videos and articles.

Nibipedeia is still being put together, but you can already access the featured videos from the main page and have a good idea of the dynamics of the site. Very soon Nibipedia will allow visitors to create profiles and interact with each other. In practice, this would mean that people will be able to connect with those interested in the very same topics. Still, the site is quite interesting as it stands, and if you are either an educator or someone who is looking for some enlightenment a visit to Nibipedia is a good start.

Monday, March 02, 2009

This is trivial (in TJX or HPS terms) but illustrates one of the fundamentals: Know where you store data!

http://www.databreaches.net/?p=1901

OK: City loses disk of account info

March 1, 2009 by admin

Keith Purtell reports:

Officials at the city of Muskogee recently discovered that a computer “zip” disk containing personal information has been in public circulation since 2000.

The citizen who found the disk noticed the official city label and returned it.

Late Friday afternoon, the city issued a press release saying they had discovered a “possible breach [What would it take to make it “definite?” Bob] of utility billing information” on about 4,500 utility accounts that were closed prior to August 2000.

[...]

Although the disk contained Social Security numbers for some of the account holders, the press release said officials don’t believe the information has been used to harm anyone.

Read more in Muskogee Phoenix



Nigeria started to migrate from the mag-stripe (the US still uses) to a “smart chip” back in 2003. Will TJX and HPS sized breaches encourage the US to do the same?

http://www.pogowasright.org/article.php?story=20090301181357673

Ng: CBN orders banks to stop issuing magnetic stripe payment cards

Sunday, March 01 2009 @ 06:13 PM EST Contributed by: PrivacyNews

The Central Bank of Nigeria (CBN) has ordered banks to Stop issuing magnetic stripe payment cards by April 1st 2009. A magnetic stripe payment card is a type of card capable of storing data by modifying the magnetism of tiny iron-based magnetic particles on a band of magnetic material on the card. The magnetic stripe, sometimes called a magstripe, is read by physical contact and swiping past a reading head.

Source - Vanguard



I'm conflicted on this. One reason to carry concealed is for protection. Knowing that you might be armed should add to the deterrent factor.

http://www.pogowasright.org/article.php?story=2009030204195432

Gun Database Ignites Debate in Tennessee

Monday, March 02 2009 @ 04:19 AM EST Contributed by: PrivacyNews

A Memphis newspaper has posted a searchable database of Tennesseans with permits to carry concealed handguns, upsetting firearm owners and igniting a debate on whether such information should be publicly available.

Source - NY Times

[From the article:

The database allows people to search for those who have a permit to carry a concealed weapon by name, ZIP code or city. Mr. Peck said it is the most viewed item on the newspaper’s Web site, with more than 65,000 page views per day.

Tennessee is one of 19 states that allow the public to have access to gun permit information, according to the Reporters Committee for Freedom of the Press. At least 21 states keep such information confidential.

A bill before the Arkansas Legislature would close to public view that state’s list of concealed weapon license holders.



Perhaps relying on your campaign supporters without considering the issues isn't the wisest of moves?

http://news.cnet.com/8301-13739_3-10184578-46.html?part=rss&subj=news&tag=2547-1_3-0-5

White House ditches YouTube after privacy complaints

by Chris Soghoian March 2, 2009 6:00 AM PST

Responding to complaints by privacy activists, the White House has quietly abandoned YouTube as the provider of the embedded videos on the President's official home page. With the release of the most recent weekly video address, the White House has shifted to a Flash-based video solution using Akamai's content delivery network.

The White House's decision to move away from the Google-owned video sharing site will likely be met with praise by privacy activists, and could mark the beginning of a real backlash in response to Google's insatiable thirst for detailed data on the browsing habits of web surfers.

Ironically, the decision by the White House comes days after YouTube began to roll out new policies to better protect the privacy of visitors who view videos embedded into Federal government Web sites. The move by YouTube may prove to be too little, too late.



“They're our customers, we can abuse them if we want to!” Attention Class Action lawyers?

http://slashdot.org/article.pl?sid=09/03/01/2120224&from=rss

Uproar Over Netflix's New Instant Viewer

Posted by kdawson on Sunday March 01, @08:14PM from the one-way-beta dept. Movies Television

almechist writes

"Many Netflix customers are up in arms over the new instant-watch player powered by Microsoft's Silverlight. The official Netflix blog is full of complaints from users who decry not only the new player's quality but also the way it's being distributed, with many claiming they were deceived into downloading it. Once you opt for the new player, the old Windows Media based player won't function, not on any computer associated with the account. The new player is supposedly still beta, but NF members are strongly encouraged (some say tricked) by NF into the so-called 'upgrade,' which is permanent — there is no way to opt out. The marked decrease in video quality seen by those who have switched is perhaps not surprising, since the old player could utilize bit streams up to twice as fast as the new one, but this information is nowhere given out by NF. So far NF has been answering all complaints with variations on 'tough luck pal, you're stuck with it,' but many customers are so disgusted they're ready to cancel their NF membership. [and replace it with what? Lock-in is a bitch, ain't it. Bob] This could be a public relations disaster in the making for Netflix."




Couldn't happen to a nicer bunch?

http://news.slashdot.org/article.pl?sid=09/03/01/174249&from=rss

RIAA Sued For Fraud, Abuse, & "Sham Litigation"

Posted by Soulskill on Sunday March 01, @01:27PM from the chickens-coming-home-to-roost dept. The Courts

NewYorkCountryLawyer writes

"It's been a rough week for the RIAA as massive layoffs are about to cost many employees their job. On top of that, the anti-piracy outfit is being sued in North Carolina for abusing the legal system in its war on piracy, particularly for civil conspiracy, deceptive trade practices, trespassing and computer fraud in SONY BMG Music Entertainment v. Moursy. Named along with the record companies as defendants on the counterclaims are Safenet (formerly known as MediaSentry) and the RIAA. This case first started out as 'LaFace Records v. Does 1-38' until the court required the RIAA to break it up into 38 separate cases, at which point it morphed into 'SONY BMG Music Entertainment v. Doe.' Only after the RIAA finally got its 'expedited' discovery did it become SONY v. Moursy. And from the looks of things, it has a long, long way to go. The RIAA hasn't even filed its answer to the counterclaims yet, but is making a motion to dismiss them on the grounds of legal insufficiency. Sound like a good investment of record company resources, anyone?"


Related? Is Microsoft's suit another example of “sham litigation” and does it rise to new anti-competitive heights when a “monopoly” does it?

http://yro.slashdot.org/article.pl?sid=09/03/01/2055239&from=rss

Analyzing Microsoft's Linux Lawsuit

Posted by kdawson on Sunday March 01, @06:05PM from the does-this-suit-make-my-filesystem-look-fat dept. Patents Microsoft The Courts

jammag writes

"Open source advocate Bruce Perens takes a close look at Microsoft's lawsuit against TomTom (discussed here last week), which involves an implementation of the Linux kernel, and calls it essentially a paper tiger. He notes: 'the technologies claimed in the 8 patents involved are so old and obvious that it's fair to say they have a high "Duh!" factor. There's an anti-trust angle to this suit that could blow up in Microsoft's face. And there's a high probability that some or all of the patents involved are invalid, due to recent court decisions.' Although the legal expense for TomTom to defend itself in court could be astronomical — meaning they may be forced to settle — in Perens' view Microsoft is aware its case is weak, yet hopes for a PR victory at limited cost."

And reader nerdyH adds speculation from Open Innovation Network CEO Keith Bergelt that Redmond's action could be retaliation for TomTom's spurning a Microsoft acquisition bid in 2006.



Free (ad supported) phone calls. No doubt this signals the death of the telephone industry... (I'm pretty sure I've seen this before, but perhaps a competitor?) Bad for privacy, unless you use someone else's phone...

http://www.killerstartups.com/Web-App-Tools/freevoiceline-com-the-free-call-revolution

FreeVoiceLine.com - The Free Call Revolution

http://www.freevoiceline.com/dialer.php

Freevoiceline.com makes calling someone a completely free process. The site itself is truly simple and straightforward, nothing complicated and no registration process. When you land on the site one of the first things you see are two fields where you must input your phone number for caller-id purposes and the number you wish to call. When you have done that, you simply press call.

There is, however, one small issue that deserves some special consideration. Every time you use this service you are giving them your telephone number, and by doing so you are also giving them a very qualified lead for several selling purposes. Everyone hates unsolicited marketing calls, however by using this service you are practically begging for them. You might be asking yourself why? And the answer is simple, their terms of service you agree to give them “free to use or disseminate such content on an unrestricted basis for any purpose” of the information you submit to the site. As well as this, you will have to listen to some advertising every time you start a call before it is actually connected.

Nothing’s really free in this world and this site is another example of it, but if you are willing to pay for your calls with advertising you receive, then this site is the place to go!

Sunday, March 01, 2009

I can't identify any new ideas here. “But now we really mean it!”

http://www.internetnews.com/government/article.php/3807401/Experts+Push+Guidelines+to+Halt+Data+Breaches.htm

Experts Push Guidelines to Halt Data Breaches

After a series of high-profile attacks and security lapses, government and private sector experts pull together a list of recommendations.

February 26, 2009 By Richard Adhikari

Amid increasing scrutiny over U.S. cybersecurity, experts from both the private and public sectors are pushing a set of recommendations they say are sorely needed to help shore up the nation's defenses against data breaches.

The resulting Consensus Audit Guidelines (CAG) map out requirements for security controls needed to protect IT installations in government and the private sector.

… Aiming to shut the door on such attacks, the new CAG recommendations (available here) call for organizations to adopt 20 key security controls to safeguard themselves against current and future threats.

Recommendations include inventorying hardware and software, [You can't secure it if you don't know it exists! Bob] maintaining and analyzing security audit logs, setting up boundary defense measures and implementing secure configurations for hardware, software and network devices. [Perhaps encrypting laptops? Bob]

… One key recommendation ensures that security efforts can pass a real-world litmus test, project participants said.

"The best item in the list is the shortest -- how do you test whether or not what you put together is effective?" Alan Paller, director of research at the SANS Institute, a security training group that brought together many of the CAG's participants, told InternetNews.com. "If you don't have a way to test, how do you know when you're done?"


Related An interesting philosophy.

http://securitywatch.eweek.com/identity_theft/pci_chiefs_defend_standards_plans.html

February 26, 2009 11:31 PM

PCI Chiefs Defend Standard(s), Plans

It's a gross oversimplification of an utterly staggering technical and social challenge, and he knows it as well as anyone, but it's hard to argue with PCI Security Standards Council General Manager Bob Russo's assertion that when it comes to improving electronic data security and related matters of individual privacy, "something is much better than nothing."



Unfortunately, disclosure to third parties is limited only when it is for “marketing purposes.” This still allows third parties to hold (and breach) the data in other contexts.

http://www.pogowasright.org/article.php?story=2009022811355380

Judgment For Disclosing PII To Business Partners: Explicit Opt-In Is Required

Saturday, February 28 2009 @ 11:35 AM EST Contributed by: PrivacyNews

Rebecca Herold offers some commentary on a court case:

Basically the District of Columbia Circuit upheld a Federal Communications Commission rule requiring phone carriers to obtain prior opt-in consent from customers before disclosing their PII to partners or independent contractors for marketing purposes

Source - IT Compliance

Related - National Cable & Telecommunications Association, Petitioner, v. Federal Communications Commission and United States of America, Respondents, Qwest Communications International iInc. and Verizon, Intervenors (pdf)



Statistics and quotes. Probably accurate even if the supporting numbers are missing.

http://www.contactcenterworld.com/view/contact-center-news/IT-experts-say-card-fraud-will-spike-in-2009-affecting-one-in-three.asp

IT experts say card fraud will spike in 2009 affecting one in three

United Kingdom - 25th February 2009 - Based on its observations in the e-crime marketplace - and reports in recent months from a wide number of third-party organisations - Fortify Software is predicting that one in three adults in the UK will be affected by card fraud in the coming year – last year the card fraud affected 1 in 4.

… Further, Fortify's VP says that, whilst card fraud identikits - which typically include a card number, start/expiry dates, three digit CVVs plus other relevant data extracted from the magnetic strip of the payment card - were selling for around $15.00 each 18 months ago, that figure had fallen to around $2.00 by last October.

"And, as card identikits are shared between cybercriminals, this form of card data is increasingly being sold by the thousand, meaning that kit prices are dropping to just a dollar a pop, when sold in volume," Kirk explained.

… What is driving the cost of identikits? The economic recession.

"Just as the average person in the street is having to tighten their belt, so is the average card criminal. They are having to increase their sales volumes by reducing the cost of each card indentikit, and so compete with the growing number of people in possession of this data," he explained.

… "We are reaching the stage where the card fraud market is becoming commoditised, and the card indentikit price being dictated by what is effectively a glut in the market," he said.



Security compromised because someone just had to listen to their tunes on a computer containing classified data? (If the helicopter pictured is the one compromised it's probably no big deal. If memory serves they are at least 20 years old.)

http://news.cnet.com/8301-1009_3-10184558-83.html?part=rss&subj=news&tag=2547-1_3-0-5

Data on Obama's helicopter breached via P2P?

by Charles Cooper February 28, 2009 4:06 PM PST

An Internet security company claims that Iran has taken advantage of a computer security breach to obtain engineering and communications information about Marine One, President Barack Obama's helicopter, according to a report by WPXI, NBC's affiliate in Pittsburgh.



Not all technology is useful in all areas. Then again, should we blame the tool or the tool user?

http://news.cnet.com/8301-13846_3-10184580-62.html?part=rss&subj=news&tag=2547-1_3-0-5

The case against enterprise micro-blogging

by Dave Rosenberg February 28, 2009 5:41 PM PST

As a consistent Twitter user, I've the found the service to be a valuable marketing tool as well as an entertaining pastime for my friends and I to shoot one-liners at each other.

… The lack of threaded messages amongst the users and the challenging interfaces of most micro-blogging services also affect communication styles by enforcing a shortened message. That sounds like a good idea until you are forced to spend more time trying to figure out what someone meant in 140 characters. The reality is that most people are poor communicators and they are even worse when it comes to their writing and editing skills.

When it comes to business, you don't want to read between the lines as you do in your personal Twitter-verse. Even with enterprise email overload, and a never ending-supply of documents flying back and forth, at least you have the ability to state and substantiate a point.


Related. Politicians believe in secrets only so they can be 'leaked' whenever a political advantage can be realized. Sounding “in the know” is sufficient advantage, as is “mocking the opposition,” “disrupting sensitive negotiations,” and “Monday morning quarterbacking.”

http://news.cnet.com/8301-10787_3-10184568-60.html?part=rss&subj=news&tag=2547-1_3-0-5

Suddenly, Twitter's the rage with D.C. politicos

by Charles Cooper February 28, 2009 4:21 PM PST

Did Missouri's U.S. senator, Claire McCaskill, just use Twitter to blab the timing of President Barack Obama's choice to run the Department of Health and Human Services?

… Besides, McCaskill has carved out a reputation as one of the most avid Twitter users in the Senate. When she noticed that Supreme Court Justice Ruth Bader Ginsberg showed up for President Obama's speech to Congress Tuesday night, following an operation related to her pancreatic cancer, McCaskill posted the following: "I did big wooohoo for Justice Ginsberg (sic). She looks good." [This fits none of my categories, so I'll create a new one: “Twit!” Bob]

Last week, much was written after several members of Congress were found to have twittered during the president's nationally televised speech.




Very interesting collection of forensic resources.

http://www.bespacific.com/mt/archives/020705.html

February 28, 2009

New on LLRX.com - Criminal Law Resources: Social Networking Online and Criminal Justice

Criminal Law Resources: Social Networking Online and Criminal Justice - The activities of users and the information being posted on social networking sites are having wide ranging effects on the administration of justice, law enforcement investigation, prosecution and defense. Ken Strutin's guide provides a snapshot of many of the novel and varied uses of social networking evidence in the field of criminal justice.



Is this the best business model they could come up with? How does it compete with “free” content? Does it suggest they are abandoning the advertising model? (Clearly I don't get it.)

http://news.cnet.com/8301-1023_3-10174003-93.html

Hearst developing e-reader, charging for e-news

by Dong Ngo and Zoë Slocum February 27, 2009 12:48 PM PST

Hearst, one of the largest media conglomerates in the world, announced on Friday that it has developed an electronic reader for newspapers and magazines, the way Amazon.com's new Kindle does for books. The publisher is also planning to put at least some of its online content behind a pay wall, according to a report in The Wall Street Journal.



Geeky stuff

http://news.cnet.com/8301-13846_3-10184539-62.html?part=rss&subj=news&tag=2547-1_3-0-5

Mozilla Bespin: Cloud code editing via browser

by Dave Rosenberg February 28, 2009 1:34 PM PST

Bespin is a Mozilla Labs experiment that "proposes an open, extensible Web-based framework for code editing that aims to increase developer productivity, enable compelling user experiences, and promote the use of open standards."

… There are a number of browser-based editors already, but check out the video, and you'll see why Bespin is interesting.