Thursday, July 16, 2009

California: Home to the most easily bribed bureaucrats in the world?

http://www.pogowasright.org/?p=1867

Pay as you drive “black boxes” threaten privacy

July 15, 2009 by Dissent Filed under Businesses, Legislation, U.S.

The California Department of Insurance (DOI) is considering regulations that would enable insurance prices to depend on the precise number of miles a car is driven in a given billing period. But in implementing these “Pay As You Drive” regulations, the DOI appears poised to empower insurance companies to require customers’ cars to be outfitted with “black-box” devices that could transmit back to the insurance companies all sorts of data about car motion (acceleration, braking, and so forth) as well as driver behavior (steering and seat-belt wearing).

Although DOI has retreated from its prior position that these devices should track your location – a definite improvement – it’s still true that every car already has a reliable, tamper-resistant device that verifies actual mileage: an odometer.

Read more on the Electronic Frontier Foundation.



New law.

http://www.pogowasright.org/?p=1880

ID theft law enacted in CT

July 16, 2009 by Dissent Filed under Breaches, Legislation, U.S.

Criminals who target senior citizens while committing identity theft will face tougher penalties this year under a law that passed with bipartisan support.

The law also empowers the state to seize cash and property obtained through identity theft and use it to reimburse victims.

[...]

The new bill bars businesses from printing their customers’ Social Security numbers on ID or access cards, or requiring customers to transmit Social Security numbers over the Internet unless the connection is secure.

Employers also are required to shred job applications so identity information on them is not revealed inadvertently.

Read more in The Hartford Courant.



One billion Indians can't be wrong! But what if they don't get a choice?

http://www.pogowasright.org/?p=1860

India to issue biometric ID cards to 1.2 billion

July 15, 2009 by Dissent Filed under Govt, Non-U.S., Surveillance

The Indian government has announced that it is to issue all of its 1.2 billion citizens with biometric identity cards.

The operation will be run by the Unique Identification Authority, a new government department created specifically for the task of assigning every living Indian an exclusive number and gathering and electronically storing their personal details.

Read more on The Telegraph.

Thanks to the The Jeff Farias Show.com for sending me this lead.

[From the article:

It is hoped that the operation, which is expected to cost at least £3 billion, [Approx $5 per card. I bet it costs a lot more. Bob] will fight corruption but it could also be used to identify illegal immigrants and tackle terrorism.

… At present Indian citizens can be issued with up to 20 proofs of identity, including birth certificates, driving licences and ration cards, although none is accepted universally.

A computer chip in each card will contain personal data and proof of identity, such as fingerprint or iris scans. Criminal records and credit histories may also be included. [Think they will be targets for hackers? Bob]

Mr Nilekani, who left Infosys, the outsourcing giant that he co-founded, to take up his new job, wants the cards to be linked to a “ubiquitous online database” accessible from anywhere.



How retro! Would anyone younger than 30 recognize the ring?

http://www.makeuseof.com/tag/free-ringtones-that-sound-like-real-phones/

Free Ringtones That Sound Like Real Phones

Jul. 15th, 2009 By Guy McDowell

Universal Phone Ring -

This one should sound familiar to almost everyone as it is the phone ring used most often in old movies and TV shows. Thanks to Hollywood Lost and Found for this one.

Black Rotary Phone Ring -

Sounds just like the one that your dad might have had in his office, doesn’t it? Those were the days.

Candlestick Phone Ring -

Ever seen those old phones where the earpiece hung on the main phone that looked like a candlestick? This is the ring from one of those.

French Rotary Phone -

Looking for that certain je ne sais quoi? This one is the ticket. C’est bon!

Classic British Phone -

I like the distinctive double-ring of the UK phones. Reminds me of old episodes of Coronation Street.

Higher Tone UK Phone -

Here’s the same kind of UK ring, but with a little higher pitch.

Now for some famous classic phone rings…

Maxwell Smart’s Shoe Phone Tone -

This is the ring that Agent 86’s shoe phone made. Yes, there was a TV show of Get Smart before the not-so-good movie.

Our Man Flint/Austin Powers Phone Ring

This one is my favourite! It seems not many people under 40 know that the phone ring from Austin Powers was taken from the Our Man Flint movie, starring James Coburn. It was also a sort of spy-spoof movie.

Counter Terrorist Unit on 24 Phone Ring -

Apparently this is the ring tone from Jack Bauer’s CTU unit on 24. Honestly, I’ve never made it through a full episode of this show, but the ringtone is pretty cool.

If what we have here doesn’t fill your boots, there is one other really good source for classic real phone ringtones that I found over at BeepZoid’s Vintage Phone Ringtones. With over 60 different ringtones in MIDI, MP3 and iPhone formats, there’s a good chance you’ll find what your looking for.

Wednesday, July 15, 2009

Follow-up They don't say it wasn't a mainframe, but unless they had cameras every few yards throughout Texas, they wouldn't need one. Interesting that the computer belonged to “Security”

http://www.databreaches.net/?p=6168

CORRECTS and REPLACES: Mainframe computer stolen from local TVCC campus

July 14, 2009 by admin Filed under Breach Incidents

Yesterday this site posted a story from and link to The Palestine Herald about a breach at Trinity Valley Community College. I just received this email, however, that the original source was in error:

Good Afternoon,

It has been brought to my attention that your website has posted as Associated Press news item regarding a potential security breach at Trinity Valley Community College in Palestine, Texas. That article contained completely erroneous information. The computer that was stolen was used exclusively for security surveillance. No personal, confidential or student information was stored on that computer. TVCC has had no breach of security at all.

If you have any questions, please feel free to contact me at the number below or on my cell phone at [redacted].

Thank you,

Jennifer Hannigan
Public Information Officer
Trinity Valley Community College



One of the primary justifications for buying laptops for employees is that they can take them with them when they leave the office. Why were all these left in the office?

http://www.databreaches.net/?p=6177

Laptops stolen from Springfield (OH) schools

July 14, 2009 by admin Filed under Breach Incidents, Education Sector, Theft, U.S.

Ten laptop computers stolen from Keifer Alternative School June 30 contained information about students with disabilities, but not social security numbers, Springfield City Schools Interim Superintendent Don Thompson said.

The district sent letters home to parents of students who were affected following the theft, said Thompson. The laptops belonged to employees of the district’s special education department, including psychologists, which relocated to Keifer as part of a plan to move all administrative offices out of the South High School building.

Read more on Springfield-Sun.



Isn't this the basis for all “data breach” cases? Either deliberately or through gross carelessness the custodian of the data leaked it.

http://www.pogowasright.org/?p=1830

Woman threatens suit against Tigo over info leak

July 14, 2009 by Dissent Filed under Breaches, Non-U.S.

Millicom Ghana, operators of Tigo could soon be in the dock for allegedly releasing confidential information about a subscriber.

A married woman, name withheld, accused the network operator of providing her ‘jealous’ husband with details of her call records.

[...]

She was however surprised when the husband produced a detailed account of all calls she had made, the duration of those calls and and text messages she sent.

Upon further investigation she found a white envelope with the inscription ‘Tigo’ containing all the details of the calls.

Read more on ModernGhana.com.



(Could have been worse, could have been a Western Diamondback.) I doubt the virus story. More likely, the Superintendent's userid and password were stolen (keylogger?) from his computer. But it does look like there was a weakness in the bank's controls...

http://www.databreaches.net/?p=6179

Western Beaver Sues ESB Bank

July 14, 2009 by admin Filed under Breach Incidents, Education Sector, Malware, Of Note, U.S.

Western Beaver School District has sued Ellwood City-based ESB Bank, saying the bank allowed someone to siphon more than $700,000 from two accounts while school administrators were off during the Christmas break in December and January.

The district says it’s still missing nearly $450,000.

According to the suit filed in Beaver County Court, someone infected Western Beaver’s computer system with a virus, which deceived the bank’s computer system into thinking that Superintendent Robert Postupac requested 74 electronic fund transfers totaling $704,610.35. Postupac was unaware of the transfers, the suit said.

Money was deposited from Dec. 29 through Jan. 5 into the bank accounts of 42 separate individuals from as far away as California and Puerto Rico. The suit did not identify the people who received the money, but noted that none of them had had any connection to Western Beaver.

Read more on iStockAnalyst.com.

[From the article:

In May, Pittsburgh's FBI office confirmed that it was investigating a computer crime within the school district. A phone call to the FBI on Friday was not returned.

… The suit alleges that ESB should have immediately realized that the transfers were fraudulent for the following reasons:

The bank's contract with Western Beaver stipulates that it can electronically transfer money only from the district's payroll account. The transfers in question came from the district's tax account and general fund account.

The contract stipulates that only certain board members and the district business manager -- not Postupac -- are permitted to authorize withdrawals from the tax and general fund accounts.

In the five months prior to the incident, Western Beaver had requested only 29 third-party fund transfers, and the unusual number of transfers should have raised a red flag.

The suit alleges that ESB eventually learned of the transfers on Jan. 2 only through a phone call from an unidentified out-of-state bank, which called after becoming suspicious when a large electronic deposit showed up in a customer's account.

At that point, the suit says, ESB had permitted 55 transfers.

It permitted about 19 more transfers after the call, the suit says.



For your Security Manager and my Excel class.

http://it.slashdot.org/article.pl?sid=09/07/14/1932234

Attacks Against Unpatched Microsoft Bug Multiply

Posted by kdawson on Tuesday July 14, @06:59PM from the how-not-to-excel dept. Security Microsoft

CWmike writes

"Attacks exploiting the latest Microsoft vulnerability are quickly ramping up in quantity and intensity, several security companies warned today as they rang alarms about the developing threat. Symantec, Sunbelt Software, and SANS' Internet Storm Center bumped up their warnings yesterday after Microsoft announced that attackers were exploiting a bug in an ActiveX control used by IE to display Excel spreadsheets. There is no patch for the vulnerability; Microsoft didn't release one in today's Patch Tuesday. A temporary fix that sets the 'kill bits' of the ActiveX control is available, but experts believe it's likely most users won't take advantage of the protection. Symantec raised its ThreatCon ranking to the second of four steps. "We're seeing it exploited, but currently on a limited scale," said Symantec's Ben Greenbaum. Sunbelt also bumped up its ranking, to high."

Firefox users can't be too complacent; Secunia is warning of a 0-day in version 3.5.



Updating (but not resolving) the issue.. Reminds me of “The Cuckoo's Egg” Let's hope the Military (somebody) has better tools! Or we could depend on the Vietnamese...

http://it.slashdot.org/story/09/07/14/1715252/UK-Not-North-Korea-Is-Source-of-DDoS-Attacks?from=rss

UK, Not North Korea, Is Source of DDoS Attacks

Posted by kdawson on Tuesday July 14, @02:16PM from the one-master-to-rule-them-all dept. security military

angry tapir writes

"The UK was the likely source of a series of attacks last week that took down popular Web sites in the US and South Korea, according to an analysis performed by a Vietnamese computer security researcher. The results contradict assertions made by some in the US and South Korean governments that North Korea was behind the attack. Security analysts had been skeptical of the claims, which were reportedly made in off-the-record briefings and for which proof was never delivered."

The Vietnamese security site's blog is linked from the article, but it is very slow even before Slashdotting. The researchers observed 166,908 zombies participating in the attacks — a number far larger than most earlier estimates.

Update: 07/14 21:24 GMT by KD : Wired is reporting that the UK owner of the IP address in question is pointing a finger at a server in Florida, which it says opened a VPN to the UK machine for the attacks. Once again, the attacker could be anywhere.



Ethics. We can, therefore we must (publish) What happened to the “fit to print” part?

http://www.pogowasright.org/?p=1839

TechCrunch reveals confidential Twitter docs

July 15, 2009 by Dissent Filed under Breaches, Businesses, Featured Headlines

Michael Arrington of TechCrunch discusses the dilemma they grappled with when they received a zip file from “Hacker Croll” containing hundreds of confidential corporate and personal documents of Twitter and Twitter employees.

There is clearly an ethical line here that we don’t want to cross, and the vast majority of these documents aren’t going to be published, at least by us. But a few of the documents have so much news value that we think it’s appropriate to publish them.

Marie Boran of Silicon Republic comments on the controversy about publishing the documents:

Plans to publish the stolen confidential corporate documents were met with some disapproval from Twitter users, some of whom labelled this action ‘going too far’, a ‘bad move’, and ‘wrong and unethical’.

In light of the recent scandal in the UK involving phone tapping by the press, this action by TechCrunch continues to raise questions on what role the media plays in the violation of privacy laws. Is this publishing in and of itself a criminal act? Where are the police with a court injunction to stop one firm publishing the stolen, private documents of another?



We're lawyers, we don't need to know nothing! Discusses social media as 'advertising'

http://www.bespacific.com/mt/archives/021819.html

July 14, 2009

Five Things Lawyers Should Know About Social Media

Five Things Lawyers Should Know About Social Media: Lawyer, writer and blogger Nicole Black advises fellow professionals about important core techniques and goals to consider before jumping on the “social media” bandwagon.



Cyborg: part man , part machine. I don't think I'd want this on record anywhere. (I don't think their last paragraph has much basis in reality either.)

http://www.pogowasright.org/?p=1814

Anonymous web data can be personal data

July 14, 2009 by Dissent Filed under Featured Headlines, Internet, Non-U.S.

The Register has a story on a fascinating legal analysis by Chris Pounder of Amberhawk Training (report here, pdf) as to how identifying yourself as being the individual associated with a particular IP address might be used to force companies such as Google and Yahoo to treat your data as being under the UK Data Protection Act. According to the report:

This analysis is valid for countries where the national data protection legislation is based on the Data Protection Directive 95/45/EC or on the OECD Guidelines; Google’s privacy policy suggests that the analysis applies to it.

According to the report’s overview:

In outline, an individual user can, at any time, send an Internet service provider his name, address, time the service was used, and any relevant URL, reference number or IP address associated with that user session. If this information is sent, then the service provider possesses all the identifying information needed to link any related service data or profiling data derived from a user session to that individual. That individual has become unambiguously identifiable and any further processing of the personal data related to the user session will engage the usual data protection obligations.

As more and more users of a service send a service provider these details, there will become a threshold of user contact after which a service provider should assume that personal data are processed on ALL users of a service without the need for user identifying information to be sent. This is because the rate of user contact is such that a service provider can anticipate that he is likely to be sent the identifying information about an individual user.

Report: IP ADDRESSES, REFERENCE NUMBERS, URLs AND THE UK’s DATA PROTECTION ACT 1998



Failure to have a clear policy or failure to ensure employees understand the policy.

http://www.pogowasright.org/?p=1826

Employee sacked for smutty emails is reinstated

July 14, 2009 by Dissent Filed under Non-U.S., Workplace

A worker sacked for sending dozens of grubby emails has got his job back after successfully arguing that the correspondence was part of a wider work culture.

Philip Walker said a culture of sending emails “where the content was not likely to offend and was banter between colleagues” existed at his Safe Air workplace in Blenheim.

The Employment Relations Authority (ERA) found in Mr Walker’s favour, awarding him $1000 for “a loss of dignity and injury to his feelings’ and ordering Safe Air to reinstate him.

Read more in The New Zealand Herald. There is some commentary on the case and its implications by an employment lawyer here.

If I apply the logic described, it seems that if a company does not make its policies clear to employees about appropriate use of its computer network or databases, it may be difficult to fire an employee for misuse. Just another reminder on the importance of ensuring that employees know and acknowledge privacy and security policies.

[From the article:

Click here for infamous email incidents



“I've been studying for my Psych test” takes on a whole new meaning...

http://yro.slashdot.org/story/09/07/14/1829231/Wikipedia-Debates-Rorschach-Censorship?from=rss

Wikipedia Debates Rorschach Censorship

Posted by kdawson on Tuesday July 14, @04:38PM from the guy-drawing-the-dirty-pictures dept. censorship internet

GigsVT writes

"Editors on Wikipedia are engaged in an epic battle over a few piece of paper smeared with ink. The 10 inkblot images that form the classic Rorschach test have fallen into the public domain, and so including them on Wikipedia would seem to be a simple choice. However, some editors have cited the American Psychological Association's statement that exposure of the images to the public is an unethical act, since prior exposure to the images could render them ineffective as a psychological test. Is the censorship of material appropriate, when the public exposure to that material may render it useless?"



Tools & Techniques

http://www.makeuseof.com/tag/10-websites-for-free-mobile-phone-ringtones-other-mobile-downloads/

10 Websites For Free Mobile Phone Ringtones & Other Mobile Downloads

Jul. 14th, 2009 By Saikat Basu



Tools & Techniques Crowd sourcing with source code. Could be used for other things...

http://ushahidi.com/

Ushahidi

Welcome to Ushahidi, which means “testimony” in Swahili, where we are building a platform that crowdsources crisis information. Allowing anyone to submit crisis information through text messaging using a mobile phone, email or web form.

Tuesday, July 14, 2009

Florida strikes again!

http://www.databreaches.net/?p=6140

FL DOE loses loan promissory notes

July 13, 2009 by admin Filed under Breach Incidents, Education Sector, Financial Sector, Lost or Missing, U.S.

Bill Cotterell of the Tallahassee Democrat reports a breach involving the Florida Department of Education’s Office of Student Financial Assistance:

The agency is notifying 475 student-loan borrowers that their financial records have been exposed to identity theft because the OSFA managed to lose 1,186 “promissory notes” that they signed when they were going to school, and have now fallen behind on.

It’s not that the money is lost. There are copies of the promissory notes, so the loans can be collected.

But Jose Blas Lorenzo Jr., director of policy, regulatory compliance and institutional review for the OSFA, said the missing files bear Social Security numbers, names and addresses, birth dates, personal references and lots of other little tidbits that could come in handy for an identity thief.

“While your file was being processed for reassignment during the week of May 25, 2009, your promissory note(s) was lost,” he wrote in the official notice approved by the Federal Trade Commission and sent to borrowers. He added that the OSFA “cannot verify if the record of your promissory note(s) has been tampered with or if the confidentiality of your promissory note(s) was compromised.”

Cotterell reportedly filed a public records request on the incident and discovered that although OSFA’s director of policy, regulatory compliance and institutional review was informed of the breach on June 2, he did not notify the bureau chief until June 23.

The story doesn’t seem to report how the promissory notes were lost.



Lexis as “good citizen?” OR, did this occur before 2004 and Lexis is only learning about it because of the arrest?

http://www.databreaches.net/?p=6146

LexisNexis warns of breach after alleged mafia bust

July 13, 2009 by admin Filed under Business Sector, Insider, Of Note, U.S., Unauthorized Access

Information broker LexisNexis has warned more than 13,000 consumers, saying that a Florida man who is facing charges in an alleged mafia racketeering conspiracy may have accessed some of the same sensitive consumer databases that were once used to track terrorists.

Lee Klein, 39, of Boynton Beach, Florida, was charged by the U.S. Department of Justice in May following an undercover sting operation that netted 11 suspects from an alleged South Florida crew of the Bonanno crime family.

On Friday, the office of the New Hampshire Attorney General posted a letter that LexisNexis sent out to consumers last month, warning that Klein may have used his access to LexisNexis’ Seisint databases “in order to perpetrate certain crimes.”

Read more of Bob McMillan’s report on Network World.

[From the article:

On Friday, the office of the New Hampshire Attorney General posted a letter that LexisNexis sent out to consumers last month, warning that Klein may have used his access to LexisNexis' Seisint databases "in order to perpetrate certain crimes."

… In a statement, LexisNexis said Monday that "the former Seisint customer involved in this matter should have provided notice to potentially affected individuals. However, because the customer is no longer in business we provided the notice."

… Seisint is best known as the creator of the ill-fated MATRIX (Multi-State Anti-Terrorism Information Exchange) terrorist data-mining project, which was shut down in 2005 following privacy concerns. LexisNexis, a division of Reed Elsevier, acquired Seisint in 2004 for US$775 million. It sells two Seisint products: Accurint, which provides information on individuals and their assets, and Securint, a background screening tool.



It takes little effort to steal an ID

http://www.databreaches.net/?p=6150

OK: ID theft attributed to online public records

July 13, 2009 by admin Filed under Breach Incidents, Exposure, Government Sector, ID Theft

Some Pottawatomie County residents claim they are the victims of identity theft, and they believe it is the result of their Social Security numbers being visible online.

[...]

At issue are mortgage and lease documents posted to a publicly accessible Web site. The documents were posted with social security numbers in view.

Pottawatomie County clerk Nancy Bryce said there is no plan currently to remove them from the Web.

Read more on KOCO.com.



Bigger is not always better. (Nor as easily fenced.) Somehow I doubt this is actually a mainframe. Sounds more like a rack-mounted server.

http://www.databreaches.net/?p=6162

Mainframe computer stolen from local TVCC campus

July 14, 2009 by admin Filed under Breach Incidents, Education Sector, Theft, U.S.

A “mainframe computer” containing confidential student information was stolen over the weekend from the Palestine campus of Trinity Valley Community College, according to local authorities.

Source: The Palestine Herald

The number of students with information on the computer was not reported, and no notice appears on the college’s web site at the time of this posting.

In an unusual twist, although thieves stole a computer and some money, they reportedly left a glass container filled with urine in the office from which the money was stolen. [Thank you for the DNA sample! Bob]

[From the article:

“Of course, they cut a lot of wires (to take the mainframe computer),” the sheriff said. [Most computer 'wiring' (cable) unplugs at both ends. Bob]



I'm sure there's a perfectly logical explanation.

http://yro.slashdot.org/story/09/07/13/1727218/Wells-Fargo-Bank-Sues-Itself?from=rss

Wells Fargo Bank Sues Itself

Posted by samzenpus on Monday July 13, @01:37PM from the so-crazy-it-just-might-work dept.

Extreme economic problems require extreme solutions, and Wells Fargo Bank has come up with a good one. They have decided to sue themselves. Wells Fargo holds the first and second mortgages on a condominium that is going into foreclosure. As holder of the first, they are suing all other lien holders, including the holder of the second, which is Wells Fargo. It gets better. The company has hired a lawyer to defend itself against its own lawsuit. The defense lawyer even filed this answer to the complaint, "Defendant admits that it is the owner and holder of a mortgage encumbering the subject real property. All other allegations of the complaint are denied." On the website The Consumer Warning Network, Angie Moreschi wrote: "We've apparently reached the perfect storm for complete and utter idiocy by some banks trying to foreclose on homes."



Citizens in a Surveillance Society. Is this a business opportunity for GPS technology (minus the phone contract)

http://hardware.slashdot.org/story/09/07/13/2148232/Tracking-a-Move-Via-Find-My-iPhone?from=rss

Tracking a Move Via "Find My iPhone"

Posted by kdawson on Tuesday July 14, @02:45AM from the unintended-consequences dept. cellphones macbook

dmolnar writes

"I recently helped my girlfriend move her stuff from Chicago, IL to Oakland, CA. The movers were scheduled to arrive at 8AM on the 5th of July, and we were stressing the day before about all the things that could go wrong with a move. We realized that if we knew where her stuff was, it'd make us feel better. This is a story about using the $99 iPhone to track the move ... and about a somewhat surprising potential use of Find My iPhone to track your friends' iPhones without them noticing."



Privacy is never a 'one size fits all” absolute.

http://www.bespacific.com/mt/archives/021813.html

July 13, 2009

Report examines Privacy Implications of Data.Gov

"Center for Democracy and Technology (CDT) today released a Policy Post discussing privacy implications for the federal data clearinghouse known as data.gov and de-identification considerations for the Open Government Directive. While this initiative signifies a step in the right direction towards a more open and transparent federal government, it must be done in concert with protecting the privacy of individuals. The Policy Post recommends specialized review procedures for each data set on data.gov. In addition, it says that different levels of data protections should be implemented in different contexts and that de-identification guidelines should be adaptable over time. This is essential in addressing consumer privacy risks associated with handling large data sets, as is the case with data.gov."



A candidate article for “A brief history of Privacy”

http://blog.law.cornell.edu/voxpop/2009/07/08/peter_winn/

Bentham and the Privacy of the Grave

Published July 8, 2009

… Bentham famously believed that publicity was the key to truth. His ideal was a Panoptic universe, where all in the world would believe themselves to be constantly observed, listened to, and monitored.



Isn't it the third generation (the grandchildren) who have the most difficulty with inherited wealth?

http://news.yahoo.com/s/nm/us_korea_north

North Korea leader Kim has pancreatic cancer: report

By Jack Kim Jack Kim – Mon Jul 13, 10:54 am ET

SEOUL (Reuters) – North Korean leader Kim Jong-il has life-threatening pancreatic cancer, South Korean broadcaster YTN said on Monday, citing information gathered from Chinese and South Korean intelligence sources.

… Kim's health is one of the most closely guarded secrets in the reclusive state. There has never been official confirmation of him falling ill.

… South Korean officials said the military grandstanding was aimed at helping Kim build internal support as he prepares for succession, with his youngest son seen as the likely heir.



Very interesting, if a bit awkward.

http://radar.oreilly.com/2009/07/recovery-mapping-arra-spending.html

Recovery Mapping: ARRA Spending Across the US

by Brady Forrest

To really understand economic and government data you need a map. This is especially important to remember right now with the American Recovery and Reinvestment Act (ARRA) spending. There's a lot of data out there and it's when you see can see the relative concentration of funds within a state that the spending priorities begin to become clear.

A number of states have put their spending plans online in map form. ESRI, the GIS toolmaker, has compiled a list of states and federal agencies that use their technology to put recovery data online. (ESRI is the dominant GIS provider to governments around the world so this a pretty good list). I applaud states and agencies that have taken the time to put their data online, I just wish that they had invested more in the UI (see Colorado's use of nurse heads to represent relative Health spending across the state for an example).



What planet are these guys living on? Some journalists. They give us a list of singers, but not the text of the document they signed. It turns out to be vague and whiny.

http://www.bespacific.com/mt/archives/021807.html

July 13, 2009

International publishers demand new intellectual property rights protection to safeguard the future of journalism

News release, July 9, 2009: "On the day that Commissioner Viviane Reding unveils her strategy for a Digital Europe during the Lisbon Council, and as the European Commission's consultation on the Content Online Report draws to a close this week, senior members of the publishing world are presenting to Information Society Commissioner Viviane Reding and Internal Market Commissioner Charlie McCreevy, a landmark declaration adopted on intellectual property rights in the digital world in a bid to ensure that opportunities for a diverse, free press and quality journalism thrive online into the future."

[From the article:

Universal access to our services should be available, but going forward we no longer wish to be forced to give away property without having granted permission. [The current law addresses that. Perhaps they don't need new laws after all? Bob]

[The Hamberg Declaration:

http://www.axelspringer.de/downloads/153453/Hamburg_Declaration.pdf



How to be a non-typical newspaper? Could be a useful app at any seminar or large classroom.

http://www.guardian.co.uk/open-platform/blog/curating-conversations

Open Platform Blog

Curating conversations

Twitter is becoming an ever present backchannel at conferences and events. However sometimes it needs curating and moderating, especially if it's to be displayed large as a part of the event. Here we talk about an app built in a few hours and open sourced today which we used for this purpose for The Guardian's Activate Summit.

Twitter is becoming a very fertile backchannel at conferences and news stories. It provides a simple mechanism for those at conferences to discuss themes, to amplify topics of interest and to engage those unable to attend. We wanted to keep the immediacy of Twitter as a backchannel but also maintain some sense of respect for the speakers, who would often have the messages writ large above their head.

… An un-moderated or un-curated stream obviously gives you the purest view in terms of openness, but when displayed large, can actually give a poorer experience for the conference goers.

The two main problems as ever are unwelcome content (swearing, racist or homophobic content, links to pornography and other linkbombs) and automated spam aimed at trending topics.



Interesting. Monitoring all that data might provide some interesting intelligence too.

http://news.cnet.com/8301-1001_3-10285718-92.html?part=rss&subj=news&tag=2547-1_3-0-5

Ghost's operating system comes alive

by Dara Kerr July 13, 2009 5:35 PM PDT

In the middle of the desert between Israel and Palestine, Ghost's high-tech Virtual Computer is set to launch Tuesday. After three years of work, Ghost finished the development of its Web-based operating system that uses "cloud computing" to let users access their desktop and data from any computer worldwide.

Ghost, short for Global Hosted Operating System, was founded in 2006 by Zvi Schreiber, whose goal was to create the Virtual Computer that works with third-party Web applications like Google Docs, Zoho, and Flickr and joins them together into one online service and can be accessed from any computer with the Internet. Users can also access their personal desktop, files and applications.


(Related) Cloud computing is the next big thing?

http://news.cnet.com/8301-19413_3-10286028-240.html?part=rss&subj=news&tag=2547-1_3-0-5

Lawyers shine light on real cloud concerns

by James Urquhart July 14, 2009 5:00 AM PDT

Like moths to a porch light (or trial lawyers to ambulances), many lawyers are finding the uncertain legal and regulatory terrain of cloud computing fertile ground for new legal analysis--and new legal business.

… The gap between the cloud and the current state of legislation is serious. Check out these examples from past posts:

… For example, take CNET's recent coverage of a panel on the effects of cloud computing on cyber crime at Symantec's Norton Cyber Crime Day. Matthew Parrella, chief of the computer hacking and intellectual property unit at the U.S. Attorney's Office, noted that "hacking" PCs by inserting software into the system by various means is being replaced by a new threat:

"That model of importation of software is becoming obsolete because we're seeing on the horizon cloud computing where so many of these operations are pushed from a user's PC or a user's computer onto Google Docs or Salesforce.com," he said.

… Barry Reingold and Ryan Mrazik, members of the Privacy and Security practice group at law firm Perkins Coie, coauthored a very well written paper in Cyberspace Lawyer (a legal journal I hope I can afford). The paper, titled "Cloud Computing: The Intersection of Massive Scalability, Data Security and Privacy" (PDF), covers a wide swath of issues largely targeted at data and processing taking place in external clouds.

… Also of interest to me was a post by Daniel Schwartz of the Connecticut Employment Law Blog, titled "Cloud Computing and Employment Law: The Uncharted Sky". In this post, Schwartz asks some interesting questions regarding data stored in external clouds:

From an employment law perspective, I have not seen much, if anything on the subject. For example, Connecticut's wage and hour laws require employers to keep track of various records of the employee including hours worked, etc. The catch? Such records need to be kept at the employer's place of business for three years. Does storing the information in "the cloud" satisfy that?

… Of course, it could also lead to a whole new collection of cloud lawyer jokes...



Another resource for my Math students

http://www.makeuseof.com/tag/the-best-free-algebra-homework-help-websites/

The Best Free Algebra Homework Help Websites

Jul. 13th, 2009 By Ryan Dube

… As usual, help is available on the Internet, and the following list are some of the best free algebra homework help websites that can make the process of learning algebra a whole lot easier.

MyAlgebra – A Free Algebra Problem Solver

A very simple and useful resource is the MyAlgebra online problem solver application. While this isn’t the first place a student should go for help, because it simply provides the answer to the equation, it is an excellent website for students to check their work.

Illuminations – Cool Algebra Activities and Lessons

Nothing is quite as frustrating for many students as trying to understand abstract concepts, and learning to do so by reading drab and boring textbooks that make you want to go to sleep. Luckily, the National Council of Teachers of Mathematics in the U.S. understands this problem and created a website called Illuminations that brings the subject (including algebra) to life for students.

Algebra.com – Math Tutors Who Just Can’t Get Enough

Of course, the best place to get some free algebra tutoring is Algebra.com, an online community of mathematicians who are obsessed with the topic. You can turn their obsession into your child’s advantage by posting problems for the tutor community to answer. The website itself offers more lessons and information than probably any other algebra help website out there.

Math.com – Interactive Algebra Help

Another valuable site filled with step-by-step instructions and lessons for students to learn the most important algebra concepts is Math.com. This site covers both the basics as well as advanced concepts under categories like “The Language of Algebra”, “Equations and Inequalities” and “Graphing Equations and Inequalities.”

Drexel University – The Math Forum

The Math Forum is a valuable public service offered by Drexel University that offers both students and teachers dozens of resources. Many of the resources are buried within internal links, but the Algebra Section alone offers classroom materials for teachers, Internet projects, public forums and even links to algebra software throughout the net.



Can I make my students subscribe?

http://radar.oreilly.com/2009/07/citizen-engineer-open-source-h.html

Citizen Engineer: Open Source Hardware Hacking Zine

by Brady Forrest

Over at Adafruit, Limor Fried and Phil Torrone have put out the first issue of Citizen Engineer. It's a zine devoted to open-source hardware, electronics arts and hacking.

… The issue also contains info on how to modify old payphones. It reminds me of 2600, but pt and Limor provide the hardware for the hacks.


(Related) Perhaps more of the Surgical Technology students will take my hacking course?

http://radar.oreilly.com/2009/07/recovery-mapping-arra-spending.html

Hackers' Next Target — Your Brain?

Posted by ScuttleMonkey on Monday July 13, @04:27PM from the true-tongue-in-cheek dept.

security biotech

Hugh Pickens writes

"Wired reports that as neural devices become more complicated — and go wireless — some scientists say the risks of 'brain hacking' should be taken seriously. ' "Neural devices are innovating at an extremely rapid rate and hold tremendous promise for the future," said computer security expert Tadayoshi Kohno of the University of Washington. "But if we don't start paying attention to security, we're worried that we might find ourselves in five or 10 years saying we've made a big mistake."' For example, the next generation of implantable devices to control prosthetic limbs will likely include wireless controls that allow physicians to remotely adjust settings on the machine. If neural engineers don't build in security features such as encryption and access control, an attacker could hijack the device and take over the robotic limb."

Relatedly, several users have written to tell us that science may be closer to the science fiction "mind wipe" than previously thought. Put this all together and I welcome the next step in social networking; letting the cloud drive my limbs around town via a live webcam and then wiping the memory from my brain. Who has MyLimb.com parked and is willing to deal?



Humor? Maybe they are looking for someone to pretend to be a satisfied customer?

http://www.networkworld.com/community/node/43490

Best Buy calls Twitter a job qualification

Employment ad asks for "250 plus followers" on social networking site

By Paul McNamara on Mon, 07/13/09 - 10:46am.

Twitter skeptics -- and they remain legion -- will find the idea silly … but it's not, particularly not in this case.

From a Computerworld Canada story:

A recent job posting on Best Buy Co Inc.’s Web site for a Senior Manager – Emerging Media Marketing position based out of the company’s corporate headquarters in Richfield, Minn. listed two preferred job qualifications: a graduate degree and 250+ followers on Twitter.

(Update: Just stumbled across this item noting that Best Buy in general is big on Twitter and that company CEO Brian Dunn has an account, albeit one that just barely would qualify him for employment in his marketing department.)


(Related)

http://www.wired.com/gadgetlab/2009/07/girl-falls-into-manhole-while-texting-parents-sue/

Girl Falls Into Manhole While Texting, Parents Sue

By Charlie Sorrel Email Author * July 13, 2009 | * 9:06 am

It’s hard to decide who are the biggest morons in this story: parents or daughter. 15 year-old Alexa Longueira was walking along Victory Boulevard in Staten Island when she fell into an open manhole.

Why didn’t she see it? You’re ahead of me here. She was too intent on tapping out a text message to notice the gaping gap in the sidewalk and just dropped straight on in.



He who steals my flash drive, steals o more – ever! KaBoom!

http://hardware.slashdot.org/article.pl?sid=09/07/13/1836204

IronKey Unveils Self-Destructing USB Flash Drive

Posted by ScuttleMonkey on Monday July 13, @05:11PM from the better-than-having-to-eat-it dept.

fysdt writes to share that IronKey has released a USB flash drive with self-destruct capability. Specializing in "secure flash drives," IronKey has launched the S200 aimed at government and enterprise customers, "featuring hardened physical security, the latest Cryptochip technology, active anti-malware and enhanced management capabilities. It's the 'first and only USB storage device to achieve FIPS 140-2, Level 3 validation' and delivers advanced Cryptochip featuring AES-256, tamper-resistance and self-destruction circuitry."

Monday, July 13, 2009

We can, therefore we must!

http://www.pogowasright.org/?p=1788

Aussie ‘Big Brother’ hospital plan irks docs

July 12, 2009 by Dissent Filed under Non-U.S., Workplace

The State Government has a secret plan to track the movement of staff around the new Royal Children’s Hospital using radio tags, which has outraged unions and raised fears of setting a precedent in employee surveillance.

Doctors say the plan smacks of Big Brother, and they will refuse to wear the tags when the hospital opens in 2011.

Read more in The Age.



What happens when you are given a choice?

http://www.pogowasright.org/?p=1790

Opt-out requests crash mobile directory

July 12, 2009 by Dissent Filed under Businesses, Featured Headlines, Internet, Non-U.S.

Controversial new mobile phone directory service 118800.co.uk has crashed, after thousands of users flocked online to remove their numbers from the site, according to reports.

The site, which launched last month, now displays holding page which reads “service suspended while we make improvements”.

Read more on v3.co.uk. The service, which has generated a lot of consumer anger, was deemed not to be a threat to privacy by the Information Commissioner’s Office.

Update: A 118 800 spokesperson has responded to the news story and comments on this, below.



For my Privacy peeps

http://www.pogowasright.org/?p=1526

Summer reading

July 12, 2009 by Dissent

Looking to get caught up on recent articles on privacy over the summer? I’ve compiled a list of some recent articles that are available for free online that I’ve been meaning to get to, and I thought I’d post the list here. Many more privacy-related articles can also be found on SSRN.

If you know of a good privacy-related article that I’ve missed or that you want to recommend to others, please post it in the comments section. The links below will take you to the abstract for the article on SSRN where you will also find a download link for the full article:

  • Gidron T: Publication of private information: An examination of the right to privacy from a comparative perspective.http://ssrn.com/abstract=1422525

  • Hoofnagle CJ: Beyond Google and evil: How policy makers, journalists and consumers should talk differently about Google and privacy. First Monday, 14(No. 4-6), April 2009. http://ssrn.com/abstract=1380702

  • John LK , Acquisti A, & Loewenstein GF: The best of strangers: Context dependent willingness to divulge personal information. http://ssrn.com/abstract=1430482

  • Picker RC: Online advertising, identity and privacy. U of Chicago Law & Economics, Olin Working Paper No. 475. http://ssrn.com/abstract=1428065

  • Shackelford SJ: Fragile merchandise: A comparative analysis of the privacy rights for public figures. http://ssrn.com/abstract=1396378

  • Soghoian C: Caught in the Cloud: Privacy, encryption, and government back doors in the Web 2.0 era. http://ssrn.com/abstract=1421553

  • Sprague R, Ciocchetti C: Preserving identities: Protecting personal identifying information through enhanced privacy policies and laws. Albany Law Journal of Science and Technology, 19(1), 2009. http://ssrn.com/abstract=1417135

  • Winn PA: Katz and the origins of the ‘reasonable expectation of privacy’ test. McGeorge Law Review, forthcoming. http://ssrn.com/abstract=1291870



Sort of a wiki for books?

http://www.makeuseof.com/dir/openlibrary-book-cover-database/

OpenLibrary: Extensive Book Cover Database

OpenLibrary is a comprehensive book cover database that aims to profile every book ever published, including the translated versions. It already lists over 20 million published books in multiple languages, including full text for 1 million scanned books from public domain.

www.openlibrary.org



Might make an interesting writing tool for my students (with extensive analysis and proper citations, of course)

http://www.makeuseof.com/dir/openzine-create-online-magazine/

OpenZine: Create Online Magazines For Free

OpenZine lets you easily create online magazines without having any knowledge of web design or development. It is a WYSIWYG based service where you can create as well as publish a web magazine by inserting text, images and videos.

www.openzine.com


(Related) How to capture content for your 'zine (and because I love lists)

http://www.hongkiat.com/blog/screen-capture-tools-40-free-tools-and-techniques/

Screen Capture Tools: 40+ Free Tools and Techniques

Screen capture, or print screen is perhaps the most efficient way to share whatever appears on your desktop. They help tech users like us to share and communicate better with friends and peers. Major operating systems today comes with basic screen capture and print screen function, but if these can’t fulfill what you need from a screen capture then you are probably looking for a screen capturing tool.

Screen capturing tools do what the basic tool don’t. What these tools could do varies, including the ability to include sketches and text, instantly upload image online, audio capturing, dimension-specific capturing and more. Make your screen capture and sharing experience more interesting, here’s a showcase of 40+ Free Screen Capturing Tools and Related Techniques.

Sunday, July 12, 2009

Interesting. Fodder for the Class Action lawyers? Would submitting the Judge's information be a good move?

http://www.pogowasright.org/?p=1769

Ohio drivers sue over sale of their data

July 11, 2009 by Dissent Filed under Breaches, Court, Govt, U.S.

The Ohio Department of Public Safety and Bureau of Motor Vehicles has been hit with a potentially costly class action lawsuit alleging that two senior employees contravened federal privacy laws when they authorized the sale of information in the state’s databanks. “At this point we don’t know what motivated them to sell the data,” says Charles Lester, an attorney with the Eric Deters law firm in Cincinnati, who represents plaintiffs in the suit. “We just know that the information is out there on the Internet.”

According to documents filed with the US District Court in Ohio, the names, addresses and driver’s license numbers of hundreds of thousands of Ohio drivers were sold to a consumer information aggregating company called PublicData, which in turn sold the information to another company called Shadowsoft. “Anyone can go get that information, all you have to do is pay a fee – there is no vetting process that stops you,” says Lester. “If I wanted to get the information about the judge in the case I could go online and get it!”

The suit, which has yet to be certified, asks that the state of Ohio cease selling data and make an effort to recover the information released into the public domain. “We want the practice stopped and we want damages,” says Lester. “There is a statutory penalty of a minimum amount of $2500 that people are entitled to even if they cannot show any specific harm. The federal law makes it clear this information should not be freely available.”

Read more on LawyersandSettlements.com


(Related) Perhaps Andy Warhol was wrong. Today, even 15 milliseconds of fame leaves a permanent record on the Internet...

http://www.pogowasright.org/?p=1686

Privacy and the democratization of fame

July 11, 2009 by Dissent Filed under Other

Sarah Hinchliff Pearson has a commentary on differing notions of privacy for celebrities and ordinary people that seems quite timely in light of the media fascination with Michael Jackson. Pearson, a Stanford Center for Internet and Society Residential Fellow, writes, in part:

On one hand, we can tell ourselves that celebrities were asking for public scrutiny or at least should have expected it when they sought out fame. The problem is that this “bargain” is not always entered into knowingly (as in the case of those born into celebrity families) and even when it is, the precise terms of the bargain were probably not clear initially. When Britney Spears got her first record deal, could she reasonably have expected to be a favorite target of tabloids as she self-destructed years later? Of course not, just as the Dog Poop Girl could not have expected her entire country to learn of her rude behavior on the subway, despite the fact that she committed her conduct in public.

[...]

In my opinion, the double standard between the private lives of celebrities and average citizens is largely bogus. There is no compelling moral reason why private citizens used to be free from public scrutiny while the lives of celebrities were freely dissected. The only thing that has changed is how easy it is to spread information. With the Internet, celebrity status is being democratized, and with even fleeting fame, comes scrutiny.

Read more of Pearson’s blog entry here.

She raises some good points. There comes a time when no matter how famous someone is or how curious the public is, people should be left alone. Whether it’s a politician having an affair that does not break any law, or a prominent figure in the racing world acting out sadomasochistic sex fantasies with consenting adults, or a pop music star having mental health problems or family problems, being a public figure should not mean that there is no longer any right to privacy.

When did the public start believing that it was entitled to every shred of a person’s life? When did we lose our way?



Food for thought. Would the same arguments apply if they wrote articles for the New York Times? Yeah, they're Nazis, but wouldn't it be smarter to let them rant?

http://yro.slashdot.org/story/09/07/11/1746206/British-Men-Jailed-For-Online-Hate-Crimes?from=rss

British Men Jailed For Online Hate Crimes

Posted by timothy on Saturday July 11, @02:33PM from the don'tcha-just-hate-online-crime dept. censorship court

chrb writes

"Two British men have become the first to be jailed for inciting racial hatred online. The men believed that material they published on web servers based in the United States did not fall under the jurisdiction of UK law and was protected under the First Amendment. This argument was rejected by the British trial judge. After being found guilty, the men fled to Los Angeles, where they attempted to claim political asylum, again arguing that they were being persecuted by the British government for speech that was protected under the First Amendment. The asylum bid was rejected and the two were deported back to the UK after spending over a year in a US jail."



...so this is a non-rational reaction? Based on what? “We didn't think of it first?” “Maybe no one will come to see the original if they can see an image on their computer?” “Hey! We gotta do something!” (I probably would never have looked at the pictures without the “Streisand Effect”)

http://yro.slashdot.org/story/09/07/11/1239244/UKs-National-Portrait-Gallery-Threatens-To-Sue-Wikipedia-User?from=rss

UK's National Portrait Gallery Threatens To Sue Wikipedia User

Posted by Soulskill on Saturday July 11, @10:21AM from the pictures-of-pictures dept. censorship media court

jpatokal writes

"The National Portrait Gallery of London is threatening litigation against a Wikipedia user over his uploading of pictures of some 3,000 paintings, all 19th century or earlier and firmly in the public domain. Their claim? The photos are a 'product of a painstaking exercise on the part of the photographer,' and that downloading them off the NPG site is an 'unlawful circumvention of technical measures.' And remember, the NPG's taxpayer-funded mission is to 'promote the appreciation and understanding of portraiture in all media [...] to as wide a range of visitors as possible!'"



That last bit doesn't seem to be in sync with the rest. My guess? The people who approve the money (Democrats) are in power. (Just another way that funding influences science)

http://science.slashdot.org/story/09/07/11/1155220/Study-Highlights-Gap-Between-Views-of-Scientists-and-the-Public?from=rss

Study Highlights Gap Between Views of Scientists and the Public

Posted by Soulskill on Saturday July 11, @09:17AM from the i-blame-the-schools dept.

ZeroSerenity was one of many to write with news of a survey from the Pew Research Center which sought to find out how Americans feel about science and contrast that with the opinions of actual scientists. The study showed that "nearly 9 in 10 scientists accept the idea of evolution by natural selection, but just a third of the public does. And while 84% of scientists say the Earth is getting warmer because of human activity, less than half of the public agrees with that." 27% of the respondents said that the advances of the US in science are its greatest achievement, down from 44% ten years ago. The study is lengthy, and it contains many more interesting tidbits. For example: scientists decry the level of media coverage given to science, and they also think research funding has too much influence on study results. 32% of scientists identify themselves as Independent, while 55% say they're Democrats and 6% say they're Republicans.



For my Hacking 101 students. A little social engineering (“Would you mind if I plugged this 100 foot extension cord into your wall socket?) and you can tap anyone before the data is encrypted!

http://it.slashdot.org/story/09/07/12/0259246/Stealing-Data-Via-Electrical-Outlet?from=rss

Stealing Data Via Electrical Outlet

Posted by timothy on Sunday July 12, @04:57AM from the accidentally-forget-to-label-some-220v-outlets dept. security power

Ponca City, We love you writes

"NetworkWorld reports that security consultants Andrea Barisani and Daniele Bianco are preparing to unveil their methodology at the Black Hat USA conference for stealing information typed on a computer keyboard using nothing more than the power outlet to which the computer is connected. When you type on a standard computer keyboard, electrical signals run through the cable to the PC. Those cables aren't shielded, so the signal leaks via the ground wire in the cable and into the ground wire on the computer's power supply. The attacker connects a probe to a nearby power socket, detects the ground leakage, and converts the signal back into alphanumeric characters. So far, the attack has proven successful using outlets up to about 15 meters away. The cost of the equipment to carry out the power-line attack could be as little as $500 and while the researchers admit their hacking tools are rudimentary, they believe they could be improved upon with a little time, effort and backing. 'If our small research was able to accomplish acceptable results in a brief development time (approximately a week of work) and with cheap hardware,' they say, 'Consider what a dedicated team or government agency can accomplish with more expensive equipment and effort.'"



Useful for citations? It does archive the pages...

http://www.makeuseof.com/dir/roohit-web-page-highlighter/

RoohIt: Instant Online Web Page Highlighter

RoohIt is an instant web page highlighter which lets you quickly highlight, save and share content from webpages. And I mean really quick. Just type roohit.com/ before any web URL address and you can start highlighting. No registration required and no download needed. You can highlight stuff as you surf and it saves things automatically. Also access your micro-bookmarks easily and share them with others via email, Twitter, Facebook etc.

www.roohit.com

If you liked this tool you can also check iCyte, Ibrii, Markkit and AwesomeHightlighter.



Humor

http://www.makeuseof.com/tech-fun/rare-genetic-dissorder-duke-nukems-disease/

Rare Genetic Dissorder: Duke Nukem’s Disease