Wednesday, September 02, 2009

Happy Birthday! (Short video and transcript)

http://news.nationalgeographic.com/news/2009/08/090831-internet-40th-video-ap.html

Internet's 40th "Birthday" Marked



This is not a big deal relative to a TJX or Heartland, but perhaps it goes into the “US is falling behind” folder, since it seems these crimes are most often blamed on “Eastern Europe” or China or somewhere in Africa. Perhaps we should be recruiting from these countries?

http://www.databreaches.net/?p=6999

5 men named in racket that netted $4m in stolen card data

September 2, 2009 by admin Filed under Breach Incidents

The Register has more on a case reportedly here previously. It turns out that the “news” actually relates to a case that was originally filed in 2007. For the detailed version, read the prosecutor’s press release.

Prosecutors in Manhattan have named five additional men from Eastern Europe in an alleged scheme that pilfered $4m using more than 95,000 stolen credit cards.

Using handles such as “the Viver,” “Inexwor,” and “DoZ,” the men were part of an international conspiracy that reached half-way around the world to snatch the payment card credentials of people located in New York, according to prosecutors in Manhattan District Attorney’s office. They branded their highly profitable enterprise the Western Express Cybercrime Group.

Read more in The Register and PC World.



Keep this in mind the next time the DoJ (or FBI or DHS or 'fill in the blanks') says we need to modernize our legal system into match those of other countries.

http://www.pogowasright.org/?p=3448

Eavesdropping on Internet

September 2, 2009 by Dissent Filed under Internet, Non-U.S., Surveillance

Imagine an invisible person is behind you watching all you do on the Internet, like searching, chatting and file downloading. Horrible as it may sound, this was what the National Intelligence Service allegedly did to a pro-unification civic group leader.

As if that was not enough, the NIS agents wiretapped all communications in cyberspace, not just of the suspected violator of the anticommunist law but of his family members and coworkers who shared the same Internet lines with him, in what experts call “packet eavesdropping.” Could one brush it aside as just another shady aspect of “IT Korea”?

Even more astonishing was nobody knew about the Internet bugging until the prosecution presented wiretapped contents as evidence during a trial. [They learned this trick from Perry Mason! Bob] Most shocking of all, the top spy agency says its agents acted with court warrants and committed no legal violations, reaffirming the nation’s far too porous legal system to protect communication secrecy and other privacy.

Read more of this Op-Ed The Korea Times.


(Related) On the other hand, some laws (government initiatives?) are not worth emulating.

http://www.pogowasright.org/?p=3439

Scottish govt publishes plans to reduce personal data collection

September 2, 2009 by Dissent Filed under Featured Headlines, Govt, Non-U.S.

The Scottish Government plans to reduce the amount of information on citizens held by large public databases and curb the collection and use of personal data by public authorities.

A consultation on its plans has just begun. The Scottish Government, run by the Scottish National Party in a minority administration, has the backing of the UK Information Commissioner’s Office (ICO) for its plans.

It has proposed a set of Identity Management and Privacy Principles with which public bodies will have to comply. The principles move the Scottish Government away from the trend of building very large public databases of personal information.

Read more on Out-Law.com

According to a news release on the government’s web site, the draft principles include:

  • Proving identity or entitlement: people should only be asked for identity when necessary and they should be asked for as little information as possible

  • Governance and accountability: private and voluntary sectors which deliver public services should be contractually bound to adhere to the principles

  • Risk management: Privacy Impact Assessments should be carried out to ensure new initiatives identify and address privacy issues

  • Data and data sharing: Organisations should avoid creating large centralised databases of personal information and store personal and transactional data separately

  • Education and engagement: Public bodies must explain [To whom? Bob] why information is needed and where and why it is shared



This is becoming much more common. Are lawyers learning how to do it, or are organizations becoming more aggressive?

http://www.pogowasright.org/?p=3402

York University obtains court order for Bell and Rogers subscriber information

September 1, 2009 by Dissent Filed under Court, Internet, Non-U.S.

Michael Geist writes:

There has been considerable discussion in recent weeks regarding the prospect of court orders mandating ISPs or other intermediaries disclose identifying information about anonymous individuals (Google model case, Ottawa city hall blog). Overlook, however, is a recent order obtained by York University requiring Bell and Rogers to disclose subscriber information. Neither ISP opposed the order, which included some novel requirements in return for ordering the two companies to disclose the names of customers associated with particular IP addresses. First, York University was required to pay the ISPs to compensate them for providing the information - Rogers gets $600, while Bell gets $300. Second, the court added a condition that required notification of the customers identified by Bell and Rogers so that they could apply to the court to vary or vacate the order. Despite constituting only three paragraphs, the order raises some very interesting issues including the questions about why a university would seek this order, the compensation to the ISPs, and the attempt to factor in a response from the identified subscribers.

A copy of the order is embedded in the blog entry.



Another “first?” (I suspect more than the article suggests.

http://yro.slashdot.org/story/09/09/02/1152212/Web-Hosts-Hit-With-32-Million-Judgment-For-Content?from=rss

Web Hosts Hit With $32 Million Judgment For Content

Posted by Soulskill on Wednesday September 02, @08:40AM from the time-to-pay-the-piper dept.

mikesd81 tips news that a California jury has found two web hosting companies liable for "contributing to trademark and copyright infringement" after hosting web sites that sold counterfeit Louis Vuitton items. Both companies are owned by the same man, Steven Chen, and are being ordered to pay $32 million in fines. A similar judgment for $61 million went against eBay last year for facilitating the sale of counterfeit Louis Vuitton merchandise.

"The US District Court for the Northern District of California is expected to issue a permanent injunction banning the internet service providers from hosting Web sites that selling fake Louis Vuitton goods in the future, the company said. Attorneys for the luxury goods maker said in a statement that the case is the first successful application on the internet of the theory of contributory liability for trademark infringement. Under this theory, companies that know, or should know, that they are enabling illegal activities have an obligation to remedy the situation. Entities that fail to do so, as Louis Vuitton alleged in this case, can be held legally responsible for contributing to the illegal activities."



Follow-up Perhaps this topic is of interest to a wider audience that it used to be?

http://www.pogowasright.org/?p=3406

DHS: All your laptops are belong to us

September 1, 2009 by Dissent Filed under Featured Headlines, Govt, Surveillance, U.S.

As a follow-up to the position of the Department of Homeland Security on searching laptops at the border (reported here last week), Jaikumar Vijayan of Computerworld reports:

The Department of Homeland Security’s Privacy Office has approved the controversial searches, copying and retention of laptops, PDAs, and other digital devices without cause at U.S. borders.

Travelers could soon start seeing notices from the Privacy Office, which last week released a report supporting the right of customs agents to conduct such searches.

The 51-page Privacy Impact Assessment also supported the right of U.S. Immigration and Customs Enforcement agents to copy, download, retain or seize any content from these devices, or the devices themselves, without assigning any specific reason for doing so.

Read more on Computerworld.

Elsewhere, Jurist provides an interesting commentary on the legal underpinnings of DHS’s position :

John Wesley Hall, Jr. [Former President, National Association of Criminal Defense Lawyers]: “This fiscal year, through August 11, 2009, US Customs and Border Protection (CBP) tells us that there were about 1,000 laptop computer searches, only 46 of which were in-depth. This out of 221 million border crossings. It simply is not possible for CBP to widely search laptop computers at the border. Too many people are lined up coming in to search everybody intensively, let alone their computers and electronic media too.

CBP is searching laptop computers, a least in the litigated cases that I have seen, only for child pornography. [So they do have cause? Bob] And they at least appear to be limiting these searches to those whom they have reasonable suspicion to believe are potentially transporting child pornography into the country so as to target their resources. But what happens when these searches begin to occur based on political speech because one opposes a government position or happens to disagree with the opinion of the customs agent making the decision (“the discretion of the officer in the field”)?

All the case law to this point is clear that reasonable suspicion is not required for a laptop search. [Is that the same as saying you can search for unreasonable reasons? Bob] No case has held that it is, and I don’t think that any will. That should not be surprising considering the Supreme Court held in 2004 in United States v. Flores-Montano that the reasonable suspicion requirement is limited to searches of the person and not personal belongings, and in 1971 that pictures and motion pictures could be examined at customs in United States v. Thirty-Seven Photographs. Thirty-Seven Photographs predated the widespread use of truly portable laptop computers by more than a decade.

Read more on Jurist.

Updated: I contacted John Wesley Hall, Jr., an expert on Fourth Amendment law, to ask him about the Fourth Amendment basis for not just searching, but copying, the contents of devices, as there has been some talk among privacy advocates and attorneys about attorney-client privilege or other confidential materials that might be copied or put at risk of a breach. John’s response:

The right to search would presumably include the right to copy what is found for evidentiary use.

If it was copied or taken and never used in a criminal prosecution, it would be subject to return under F.R.Crim.P. 41(g) if it was noncontraband. [Is there a simple procedure for this? Bob]

What about attorney-client privileged information? There has been some list serv traffic about this risk, which is a theoretical risk at best. CBP just does not have the time to search except for contraband. 221 M border crossings between 10/1/08 and 08/11/09 means it is impossible for them to do anything but a search that is likely to bear fruit; hence a virtual self-imposed reasonable suspicion standard, although the law does not require one. [Interesting argument. Still wouldn't address the “why me” question. Bob]



Apparently some people in the UK are finally waking up. This is not news, but the realization of what the government is doing seems to be growing.

http://yro.slashdot.org/story/09/09/02/0535218/UK-Plans-To-Link-Criminal-Records-To-ID-Cards?from=rss

UK Plans To Link Criminal Records To ID Cards

Posted by timothy on Wednesday September 02, @04:41AM from the oh-sure-blame-the-children-again dept.

Death Metal writes with this excerpt from ComputerWeekly.com about the UK's national ID card scheme:

"Privacy advocates have reacted angrily to reports that the government plans to link national identity records to criminal records for background checks on people who work with children and vulnerable people. Up to 11 million such workers could be affected immediately if the plan goes ahead. Phil Booth, national co-ordinator of privacy advocates NO2ID, said the move was consistent with the various forms of coercion strategy to create so-called volunteers for national ID cards. 'Biometrics are part of the search for clean, unique identifiers,' Phil Booth said. He said the idea was patently ridiculous when the Home Office was planning to allow high street shops and the Post Office to take fingerprints for the ID card. [Anyone else think there is an opportunity for hanky-panky here? Bob]



What a fun area for hackers! “Oh look, the patient just died! No, he's alive again, but his body temperature has dropped to -18 degrees. Ah, now he's pregnant with octuplets!”

http://news.cnet.com/8301-27083_3-10323325-247.html?part=rss&subj=news&tag=2547-1_3-0-20

Coming to a bedside near you: Body sensor networks

by Elizabeth Armstrong Moore September 1, 2009 5:01 PM PDT

GE Healthcare is developing a Body Sensor Network (BSN) that consists of sensor devices that collect patient-specific data, from body temperature and pulse-oximetry to blood glucose levels and respiratory function. The real-time information will be transmitted to doctors, nurses, caregivers, etc., to enable far more efficient body monitoring from any location, which in turn provides the most current patient information and treatment option evaluations.



This is sure to catch on. Perhaps there is an opportunity for a “Bill me through this email account” service that would check your bills for you? Probably not.

http://redtape.msnbc.com/2009/09/rob-connor-of-charleston-sc-watches-his-bills-carefully-so-hes-pretty-steamed-that-soon-hes-going-to-have-to-pay-for-th.html

T-Mobile users to be billed for bills

Posted: Tuesday, September 1 2009 at 05:00 am CT by Bob Sullivan

Rob Connor of Charleston, S.C., watches his bills carefully. So he's pretty "steamed" that soon he's going to have to pay for the right to do so.

Connor is caught in a debate that could pit environmentalists against consumer rights advocates over the basic monthly task of paying the bills.

Connor's mobile phone provider, T-Mobile, recently sent him a note saying it will now charge customers $1.50 per month to receive paper bills mailed to their homes, or $3.50 per month for detailed bills. E-mailed bills are free, but Connor says that won't help him. He doesn't have Internet access at home.

T-Mobile says it's making the change, which takes effect in September, in part to help the environment, but Connor doesn't buy that.

"This thing of having to pay so I can pay is just a little too much," he said. "And I'm certainly not interested in some bogus argument about me contributing to global warming by NOT signing on to making it cheaper for T-Mobile to send me a bill."

Is T-Mobile stiffing consumers like Connor or helping the environment? Many companies are strongly encouraging consumers to forgo paper bills in favor of electronic versions. Sprint offers a $5 credit to consumers to enroll in online billing. Verizon recently offered consumers who make the switch a chance to win a Toyota Prius.

But T-Mobile's fee for even summary paper bills marks one of the most aggressive steps by companies trying to push consumers into the paperless world.

… The firm is not the first wireless company to charge for paper bills. Verizon Wireless and AT&T charge $2 monthly fees for consumers who want to receive detailed bill statements via U.S. Mail. Basic summary bills are still free, however.

But Connor thinks he has a right to the paper bills for free, and he's not alone. T-Mobile customers have taken their displeasure with the new policy to the Internet, registering complaints on dozens of Web sites.T-Mobile’s own consumer message boards are full of angry notes.

It really pisses me off when companies hide behind the environmental wackos for a reason why not to include services anymore,” reads one.

Harvey Rosenfeld, founder of Consumer Watchdog and lead attorney in several lawsuits against the mobile industry, says Conner and other complainers may have legal grounds for their objection. He recently settled a lawsuit against Nextel Corp. for requiring consumers to pay for detailed billing statements back in 2003. As part of the settlement, Nextel agreed to refund customers. He says consumers are entitled to bills and invoices that itemize costs.

"There's a lot of policy language in state and federal law that says consumers need to be able to determine the validity of a bill," he said. "You need to know if you're being overcharged, if you've received a promotional discount. You can't figure anything out from a bill if all they give you is a single unitemized bill."

Rosenfeld says he's seen hospital bills where the consumer was charged $2.50 to obtain a copy of the bill.

"To bill you for the price of billing you is an outrage" he said. "It's the cost of doing business."

… Meanwhile, many T-Mobile consumers are wondering if the new paper bill fee constitutes a change in contract terms which would allow customers to break their contracts without paying an early termination fee.

T-Mobile says no.

"It doesn't qualify for opt out in the contract because customers were given 30 days notices as part of terms and conditions. They have the option to opt out. And they have access to bills for free online," said a company spokesman, speaking on condition he not be identified.

But Rosenfeld said the firm has clearly changed the cost to consumers – a $50 plan now costs $50 plus at least $1.50 to get a paper bill – so consumers should have the right to cancel.

"If a company starts charging for a service that they previously did for free ... that’s a material change for sure," he said. "I think consumers can get out of their contracts."



More interesting that I expected...

http://www.bespacific.com/mt/archives/022208.html

September 01, 2009

National Library of Medicine Offers Disaster Information Resources on Wildfires

Newsletter for the NN/LM Pacific Southwest Region: "An extensive list of resources related to wildfires is now available from the Specialized Information Services division at NLM. Learn how to prepare and protect yourself from wildfires, and get information on how the smoke and particulate matter may affect your health." [Dan Mitchel]



Is Kindle doomed? This may at least break the “proprietary” barriers

http://www.techcrunch.com/2009/09/02/google-widens-attack-on-amazon-kindle-partners-with-coolerbooks/

Google Broadens Attack On Amazon Kindle, Partners With COOLERBOOKS

by Robin Wauters on September 2, 2009

… First, the company teamed up with Sony, adding about 1 million public domain books to the technology giant’s eBook Store.

Now Mountain View has sealed a deal with British Interead, bringing the same amount of ebooks to an online store outside the U.S. for the first time (where close to half a million of them are available for free).

Reading-based Interead is the company behind ebook store COOLERBOOKS. The company also manufactures COOL-ER eReaders, small, elegant ebook readers that kinda look like giant iPods and cost $249 in the United States.



Oo! Oo! Can I “soundmark” such phrases as “I didn't know there was a test today!” or “Yeah, I know I missed eight of the last nine tests, but I've gotta pass this class!”

http://idle.slashdot.org/story/09/09/01/1654216/Tour-Companies-Battle-Over-Trademarked-Duck-Noises?from=rss

Tour Companies Battle Over Trademarked Duck Noises

Posted by samzenpus on Tuesday September 01, @01:15PM from the totally-quackers dept.

Tour company Ride the Ducks is suing rival tour company Bay Quackers, alleging that it holds trademark rights to the sound made by tourists using duck call devices, while on amphibious vehicle tours. San Francisco-based Ride the Ducks holds a 'sound mark' on the noise. Very few companies hold sound marks, but some of the more famous include: the NBC chimes and the MGM lion. The company holds US Trademark No. 2,484,276, which protects a mark consisting of 'a quacking noise made by tour guides and tour participants by use of duck call devices throughout various portions of [guided amphibious vehicle] tours.' Reading this makes my think that there is a room full of litigious monks somewhere, just waiting for someone to try clapping with one hand.



Tools & Techniques. A bit of a rambling article, but shows a simple way to customize your “file open dialogue box” (The explorer-like window that opens when you want to Open a file.)

http://www.makeuseof.com/tag/use-the-places-utility-to-customize-your-open-file-locations-in-windows/

Use The Places Utility To Customize Your Open File Locations In Windows

Sep. 2nd, 2009 By Karl L. Gechlik

… Some programs like Outlook open the file box to a suitable folder – so why don’t they all? But what if I want to replace the links on the left with my most common folders?

Yeah there is a piece of software for that. Let’s help you make use of it. You can download the small 623kb file from here. It is compatible with Windows 2000 upwards, so that means XP, Vista and Seven friendly!



Not that I have a lot of wino friends... This is for my Small Business Management students. I tell them to start businesses that involve things they love.

http://www.techcrunch.com/2009/09/02/panorama-capital-pours-45-million-into-online-wine-outlet-vinfolio/

Panorama Capital Pours $4.5 Million Into Online Wine Outlet Vinfolio

by Robin Wauters on September 2, 2009

Online wine store and community site Vinfolio has raised $4.5 million in a Series A funding round led by Panorama Capital after receiving an undisclosed amount of angel investment earlier.

… There’s no shortage of wine-related websites and services out there. From the top of my head: review sites Snooth and Corkd, Vinogusto, good old Wine.com and wine ‘discovery’ service Adegga, although I’m sure there are many more.



Both a sign of Microsoft lack of dominance and a great premise for the next “I'm a PC...” ad. (Bill Gates will be rolling over in his retirement.)

http://mobile.slashdot.org/story/09/09/01/1941202/iPhone-App-Wins-Microsoft-Campus-Programming-Contest?from=rss

iPhone App Wins Microsoft-Campus Programming Contest

Posted by timothy on Tuesday September 01, @03:43PM from the cross-platform dept.

imamac writes

"Startup Weekend was a 54-hour coding marathon held on Microsoft's campus last weekend. It was designed to encourage the use of MS programming technologies. However, the winner of the contest was an iPhone app: ' "Awkward," whispered Startup Weekend organizer Clint Nelsen into the microphone upon announcing the top vote getter.'"

Tuesday, September 01, 2009

Privacy (and security?) in the Cloud.

http://www.pogowasright.org/?p=3366

Email Snooping Can Be Intrusion Upon Seclusion

August 31, 2009 by Dissent Filed under Court, Internet, Workplace

Attorney Evan D. Brown discusses a case that sheds some light on how courts may view a privacy invasion claim of “intrusion on seclusion” when a firm’s employee email is hosted in the cloud:

Local elected official Steinbach had an email account that was issued by the municipality. Third party Hostway provided the technology for the account. Steinbach logged in to her Hostway webmail account and noticed eleven messages from constituents had been forwarded by someone else to her political rival.

Steinbach sued the municipality, her political rival and an IT professional employed by the municipality. She brought numerous claims, including violation of the Federal Wiretap Act, the Stored Communications Act, and the Computer Fraud and Abuse Act. She also brought a claim under Illinois common law for intrusion upon seclusion, and the court’s treatment of this claim is of particular interest.

[...]

Finally, the defendant argued that the intrusion was authorized, looking to language in the Federal Wiretap Act and the Stored Communications Act that states there is no violation when the provider of an electronic communication services intercepts or accesses the information. The court rejected this argument, finding that even though the municipality provided the email address to Steinbach, Hostway was the actual provider. The alleged invasion, therefore, was not authorized by statute.

The court’s analysis on this third point could have broader implications as more companies turn to cloud computing services rather than hosting those services in-house. [Outsourcing in general? Bob] In situations where an employer with an in-house provided system has no policy getting the employee’s consent to employer access to electronic communications on the system, the employer—as provider of the system—could plausibly argue that such access would be authorized nonetheless. But with the job of providing the services being delegated to a third party, as in the case of a cloud-hosted technology, the scope of this exclusion from liability is narrowed.

Read more on CircleID

The case is Steinbach v. Village of Forest Park, No. 06-4215, 2009 WL 2605283 (N.D. Ill. Aug. 25, 2009)

[From the article:

The court looked to the case of Busse v. Motorola, Inc., 813 N.E.2d 1013 (Ill.App. 1st. Dist. 2004) for the elements of the tort of intrusion upon seclusion. These elements are:

  • defendant committed an unauthorized prying into the plaintiff's seclusion;

  • the intrusion would be highly offensive to the reasonable person;

  • the matter intruded upon was private; and

  • the intrusion caused the plaintiff to suffer.



Technology presents new challenges to governments. (Of course, this could also be used to “leak” positions on pending legislation and see what the feedback is...)

http://www.spiegel.de/international/germany/0,1518,646016,00.html

Illegal Election Updates Strike Again in Germany

Ninety minutes before the polling stations closed, the first results in the weekend's German state elections were already being made public. Twitter had struck again. At around 4:30 p.m. two Twitter users had published messages indicating the outcomes for Thuringia, Saarland and Saxony. These messages then made their way around the Internet.

In Germany, it is a crime to publish data gleaned from the exit polls -- a poll of voters taken immediately after they have exited the polling stations -- before the polling stations have closed.

… One of the Twitter accounts belonged to Patrick Rudolph, the head of the Christian Democrats (CDU) in the city of Radebeul in Saxony. "I don' know who wrote it," Rudolph told SPIEGEL ONLINE. It was not him, he says, and he deactivated the account because of this. [One of the problems with relying on your secretary (teenage children?) to handle the technology for you... Bob]



Users got rights?

http://www.pogowasright.org/?p=3348

German Court: Google must change its terms

August 31, 2009 by Dissent Filed under Court, Internet, Non-U.S.

Patrick McGroarty of the Associated Press reports that a German court has ruled that Google must eliminate 10 clauses from its terms of service. The Federation of German Consumer Organizations had argued that the clauses could be interpreted to compromise users’ rights to their own data

Google said in a statement that it removed the clauses, which it described “unfortunately framed,” more than a year ago.

Google spokesman Stefan Keuchel said the terms had already been changed when the court released its decision to clarify that users agree to allow data they upload to be viewed and manipulated only by other users they have explicitly authorized — for instance, through a shared Google document.

Read more on AJC.


Students got no rights!

http://www.pogowasright.org/?p=3382

Court backs plagiarism detector

September 1, 2009 by Dissent Filed under Court, Youth

David Canton had an article on Canoe yesterday about the use of the plagiarism detector service, Turnitin.com. For those who weren’t aware of the case at the time, several students sued Turnitin.com last year, claiming that the service violated their copyright and was making a profit off their work. The court sided with Turnitin.com, in part, because when students submit their work to the service, they are consenting to having it stored.

I personally disagreed with the court’s opinion, because students are often given no choice about submitting their work — their professors make it a condition of passing the assignment or course. Many educators, in my opinion, have been essentially coercing students into creating a digital record of their thoughts and opinions — records that might come back to haunt them in the future. Of course, someone might reasonably point out that the gripe would be with the educators and not the service, but to the extent that Turnitin.com was storing records that the student authors did not want stored but had no real choice about consenting to, I viewed it as a privacy invasion.

Now Canton reports that the issue is not totally dead. He writes:

However, this may not signal the end of the controversy surrounding turnitin. Legal action is being contemplated by other student groups unhappy with the policies of Turnitin. Some institutions have discussed eliminating the use of the service or letting professors decide if it should be used on a class-by-class basis.

It is not the concept of Turnitin that is being objected to by students, it is the manner in which the service is being operated.

It will be interesting to see what develops. The court felt that the benefits of turnitin.com outweighed the concerns of the students who filed the first lawsuit. But in this day and age, is creating a non-optional digital record of a student’s thoughts and opinions really a small thing that is outweighed by the convenience or tool it provides educators who want to rule out plagiarism? What do you think?



Stalking Congress

http://www.bespacific.com/mt/archives/022194.html

August 31, 2009

New on LLRX.com - The Government Domain: Tracking Congress 2.0

The Government Domain: Tracking Congress 2.0 - With the 111th Congress of the United States reconvening on September 8th, e-gov expert Peggy Garvin highlights new tools and sources that enhance and expand your ability to track and monitor the action.



Is this evidence that ISPs are doing what they swear thay don't do?

http://tech.slashdot.org/story/09/09/01/0223225/Drop-in-P2P-Traffic-Attributed-To-Traffic-Shaping?from=rss

Drop in P2P Traffic Attributed To Traffic Shaping

Posted by ScuttleMonkey on Tuesday September 01, @03:27AM from the or-just-sneakier-options An anonymous reader writes

"A new report based on data from 100 US and European ISPs claims P2P traffic has dropped to around 20% of all Internet traffic. This is down from the 40% two years ago (also reported by the same company which sells subscriber traffic management equipment to ISPs). The report goes on to say the drop is likely due to continued, widespread ISP P2P shaping: 'In fact, the P2P daily trend is pretty much completely inverted from daily traffic. In other words, P2P reaches it low at 4pm when web and overall Internet traffic approaches its peak... trend is highly suggestive of either persistent congestion or, more likely, evidence of widespread provider manipulation of P2P traffic rates.'"



Arbitrary is as arbitrary does... or doesn't, depending...

http://yro.slashdot.org/story/09/08/31/1515239/Woman-Fired-For-Using-Uppercase-In-Email?from=rss

Woman Fired For Using Uppercase In Email

Posted by samzenpus on Monday August 31, @12:49PM from the don't-type-angry dept.

tomachi writes

"An accountant in NZ has been awarded $17,000 NZD for unfair dismissal after her boss fired her without warning for using uppercase letters in a single email to co-workers. The email, which advises her team how to fill out staff claim forms, specifies a time and date highlighted in bold red, and a sentence written in capitals and highlighted in bold blue. It reads: 'To ensure your staff claim is processed and paid, please do follow the below checklist.' Her boss deemed the capital letters too confrontational for her co-workers to read after they woke up from naptime."



Is Microsoft doomed? Can you name anything new from them in the last few years? (Windows7 seems like a major improvement, but addresses a declining market)

http://www.nytimes.com/2009/08/31/technology/business-computing/31virtual.html?_r=2&partner=rss&emc=rss

Challenging Microsoft With a New Technology

By STEVE LOHR Published: August 30, 2009

Microsoft’s No. 1 rival is a household name, Google. But a strong candidate for No. 2 is a company that is scarcely known outside the technology industry: VMware.


(Related) Lose in this market, and individuals have no reason to buy the same software for use at home.

http://uk.techcrunch.com/2009/09/01/british-small-biz-falls-out-of-love-with-microsoft-heads-to-the-clouds/

British small biz falls out of love with Microsoft, heads to the Clouds

by Mike Butcher on September 1, 2009

Remember all that Web 2.0 hype back in the day? Remember how some predicted an end to the monopoly of Microsoft in those basic applications like Word, Excel and others as these functions moved to the Cloud? Well it looks like that trend is well on its way now and especially in the UK.

According to a survey by Accredited Supplier, a B2B services marketplace, Microsoft is losing their grip on the UK small business market under increasing pressure from cloud computing and open source software.


(Related) Another “old guard” company that isn't moving (can't move?) quickly enough to create a service that customers want.

http://reviews.cnet.com/8301-19512_7-10322103-233.html

Is AT&T losing its grip on the iPhone?

by Marguerite Reardon August 31, 2009 11:09 AM PDT

Apple's exclusive deal with AT&T to offer the iPhone may end within the year, according to a prediction from financial analyst Gene Munster, a senior research analyst at Piper Jaffray.

If Munster is correct, opening up the iPhone to other carriers in the U.S. could be a boon for Apple, which would likely see iPhone sales go through the roof. On the flipside, if this prediction were to come true, it would likely mean very bad news for AT&T, which has relied heavily on the iPhone to boost its own wireless sales and revenue.



Interesting concept. The RIAA will no doubt be calling (Think they can read music?)

http://www.noteflight.com/login

Noteflight

Noteflight® is an online application that lets you display, edit, print and play back music notation with professional quality, right in your web browser. You can work on a musical score from any computer on the Internet, share it with other users, and embed it in your own pages. And it's free for individual use.



For my website students

http://www.makeuseof.com/tag/conduct-embed-online-interviews-with-wetoku-invites/

How To Conduct Video Interviews with Wetoku (Invites!)

Aug. 31st, 2009 By Tim Lenahan

… Wetoku offers a simple way to meet someone online, record the meeting (or interview) and then share it with others. You may use it for video chat, conduct online interviews, etc.

Our Makeuseof authors have touched on several video chat type offerings that can help with online interviews (Tokbox, Eyejot, and Gmail’s video chat features). Well, wetoku makes meeting face to face with someone far away even easier.

http://wetoku.com/

Monday, August 31, 2009

Is this bad reporting or good (but subtle) reporting. Can a professional storage company really screw up this bad?

http://www.databreaches.net/?p=6976

Vendor data on encrypted tapes falls off truck

August 30, 2009 by admin Filed under Breach Incidents, Government Sector, Lost or Missing, Subcontractor, U.S.

A box with encrypted tapes containing personal data fell off a truck…

Cuyahoga County officials are searching for a box that fell off a truck and contained personal information for 300 people.

The box was being moved Monday to a storage facility and held information, including Social Security numbers, for private vendors who provide services to the county. It did not contain personal information about county employees, officials said.

A driver for Iron Mountain, a company that stores and shreds documents, picked up two containers Monday from the county’s Information Services Center at East 13th Street and Chester Avenue. The driver left one box on a rear rack, and it fell off when the trucker pulled away, according to a police report. [What kind of truck does this bring to mind? A pick-up with no rear gate? Sounds as fishy to me as it does to the commenters. Bob]

Read more from The Plain Dealer.



Someone to explain Privacy to those charged with protecting it? What a concept!

http://www.pogowasright.org/?p=3316

Bell Canada ordered to inform customers about data gathering

August 30, 2009 by Dissent Filed under Businesses, Featured Headlines, Govt, Non-U.S.

Peter Nowak of CBC News reports:

Canada’s privacy commissioner, fresh off forcing Facebook to change how it handles users’ data, is ordering Bell Canada to change how it informs internet customers of its network-management practices.

In a report dated Aug. 13 and made public on Friday, assistant privacy commissioner Elizabeth Denham told the company it must change its service agreements and the Frequently Asked Questions section of its website to notify customers that it collects and retains their personal information through use of its deep-packet inspection technology.

[...]

The report was in response to a complaint by the Canadian Internet Policy and Public Interest Clinic, based at the University of Ottawa. The privacy commissioner rejected CIPPIC’s two other complaints about Bell’s DPI, that the company was collecting personal information about customers without their consent and that it is gathering more information than needed to manage its network.

Denham said the service agreements customers sign constitute their consent. She also said she had not found any evidence that Bell was using DPI to look at users’ internet traffic for purposes such as advertising or boosting its own services.

“I am unconvinced that, at date of issue of this report, Bell is collecting or using any personal information of individuals other than the IP addresses and subscriber IDs of Sympatico customers when it uses its DPI technology for the purpose of network traffic management,” she wrote.

Read more on CBC.ca

I wonder if all American privacy bloggers like me have Privacy Commissioner Envy. Maybe it should be a new diagnosis: “A disorder characterized by intense and persisting desire for a privacy commissioner to protect the citizens’ privacy.”



Maybe it is Nigerians. Or maybe it is Republicans pretending to be Nigerians. Or it could be Democrats pretending to be Republicans pretending to be Nigerians. (Ain't paranoia wonderful...)

http://politics.slashdot.org/story/09/08/30/126259/Spammers-Use-Holes-In-Democratsorg-Security?from=rss

Spammers Use Holes In Democrats.org Security

Posted by Soulskill on Sunday August 30, @09:17AM from the hello-sir-madam dept.

Attila Dimedici writes

"According to Cloudmark, 419 spammers are using the democrats.org website to relay email and bypass spam filters. 'The abuse, which dates back at least to the beginning of this month, helps evade filters that internet service providers employ to block the messages. ... The messages were sent courtesy of this page, which allows anyone with an internet connection to send emails. The PHP script employs no CAPTCHA [It does now. Bob] or other measure to help ensure there is a real human being behind each email that gets funneled through the service. The service allows messages to be sent to 10 addresses at a time and even provides a way for people to import contacts they have stored in their address book.'"



“We told you the old system wasn't adequate. Now we have to have National ID Cards.” Papers, Comrade Citizen!

http://www.theregister.co.uk/2009/08/27/crb_id/

CRB looks to ID cards to solve accuracy woes

One day, their prints may come

By Chris Williams Posted in Government, 27th August 2009 12:58 GMT

Millions could be asked to provide ID card and fingerprint data to get a job under new systems being developed by the Home Office following a collapse in the accuracy of background checks.

… In the 12 months to the end of March 2009, identity errors at the CRB more than doubled compared to the previous year. More than half of the 1,570 mistakes were made in just one month.

The CRB declined to offer a specific reason for its disastrously inaccurate month, saying it was reliant on the quality of data provided to it by police and employers. It added that plans to use ID card and biometric data were part of its policy response, however.

Phil Booth, national coordinator of the campaign group NO2ID, said that he was "not surprised by this."

He added: "This is entirely consistent with the various forms of coercion strategy they've been working on to create artificial 'volunteers' for ID cards.



When the facts don't support your position, try propaganda. After all, why else would the industry that supposedly represents musicians not want to hear what they think?

http://yro.slashdot.org/story/09/08/30/1332243/Musician-Lobby-Terms-Balanced-Copyright-Disgusting?from=rss

Musician Lobby Terms Balanced Copyright "Disgusting"

Posted by Soulskill on Sunday August 30, @10:35AM from the less-than-impressed dept.

An anonymous reader writes

"While most of the attention at Thursday's Canadian copyright town hall was on the recording industry's strategy to pack the room and exclude alternate voices, the most controversial activity took place outside the hall. It has now been revealed that security guards threatened students and a Member of Parliament for distributing leaflets, and the American Federation of Musicians termed the MP's leaflet, which called for balanced copyright, 'disgusting' and demanded a retraction and apology. At this point, such an admission seems unlikely."


(Related) A day for IP articles...

http://yro.slashdot.org/story/09/08/30/1948206/Cato-Institute-Critique-of-Software-Patents?from=rss

Cato Institute Critique of Software Patents

Posted by timothy on Sunday August 30, @04:16PM from the oprah-favre dept.

binarybits writes

"I've written an article for the free-market Cato Institute about how patents impede innovation in the software industry. It points out that people tend not to realize how vast the software industry is. It's not just Google and Microsoft; virtually every organization has an IT department producing potentially-infringing software. Organizations as diverse as J. Crew and the Green Bay Packers have been sued for patent infringement. It's crazy to expect all these organizations to worry about potential patent infringement. Hopefully the Supreme Court's Bilski decision will lead to new limits on software patents."



For my Disaster/Recovery students

http://www.bespacific.com/mt/archives/022192.html

August 30, 2009

FEMA Searchable Disaster Photo Library

Disaster Photo Library - FEMA: "The FEMA on line Photo Library contains more than 16,500 disaster related photographs made since 1989. The collection is composed almost entirely of declared disasters and there are also photographs from FEMA public events which have occurred in Washington, DC. The photographs are of Hurricanes, Tornadoes, Floods, Typhoons, Fires, Avalanches, Ice Storms, Blizzards, World Trade Center and Pentagon Terrorist Attacks, Earthquakes, and the Columbia Space Shuttle Disaster."



Tools & Techniques 'cause you never know when you'll need to be anonymous

http://www.makeuseof.com/tag/4-sites-that-give-you-a-free-updated-proxy-list/

4 Sites That Give You A Free Updated Proxy List

Aug. 30th, 2009 By Guy McDowell


Or, you can do it yourself!

http://www.makeuseof.com/tag/how-to-set-up-a-secure-free-proxy-server/

How To Set Up A Secure & Free Proxy Server

Aug. 31st, 2009 By Sharninder


...and if you can't protect your anonymity, you should be practicing...

http://www.reloadbench.com/pdf.html

The Reload Bench

Sunday, August 30, 2009

Again it seems that there is nothing happening on Sunday (at least nothing gets reported) I should probably have my Statistics class analyze the probability the newsworthy events only occur during the week, but I doubt the results would be newsworthy.



Interesting, but expected.

http://yro.slashdot.org/story/09/08/30/0448217/Lori-Drew-Cyberbullying-Case-Dismissed?from=rss

Lori Drew Cyberbullying Case Dismissed

Posted by timothy on Sunday August 30, @08:01AM from the neither-vindication-nor-absolution dept.

Trepidity writes

"About seven weeks after the judge tentatively overturned Lori Drew's guilty verdict for 'cyberbullying' following her online harassment of a teenager that was linked to the teenager's suicide, the case was finally officially dismissed. In a 32-page opinion [PDF], the court avoided a minefield of possible follow-on effects that civil-liberties groups had warned of by holding that merely violating a website's Terms of Service cannot constitute 'unauthorized access' for the purposes of the Computer Fraud and Abuse Act (18 U.S.C. 1030)."



Strategy: If it's stupid and it works, it ain't stupid! (I doubt this will work, even in bad economic times I can't see the UK selling the BBC to Murdoch.)

http://yro.slashdot.org/story/09/08/29/1750259/James-Murdoch-Criticizes-BBC-For-Providing-Free-News?from=rss

James Murdoch Criticizes BBC For Providing "Free News"

Posted by timothy on Saturday August 29, @02:30PM from the you-don't-trust-the-gov't-to-report-news-fairly? dept.

Hugh Pickens writes

"News Corporation's James Murdoch says that a 'dominant' BBC threatens independent journalism in the UK and that free news on the web provided by the BBC made it 'incredibly difficult' for private news organizations to ask people to pay for their news. 'It is essential for the future of independent digital journalism that a fair price can be charged for news to people who value it,' says Murdoch. 'The expansion of state-sponsored journalism is a threat to the plurality and independence of news provision.' In common with the public broadcasting organizations of many other European countries, the BBC is funded by a television license fee charged to all households owning a television capable of receiving broadcasts. Murdoch's News Corporation, one of the world's largest media conglomerates, owns the Times, the Sunday Times and Sun newspapers and pay TV provider BSkyB in the UK and the New York Post, Wall Street Journal, and Fox News TV in the US."

Note that James Murdoch is the son of Rupert Murdoch.


(Related) Free is good! If you had never looked closely at your customers (something any good manager would do) you would discourage P2P users. Worse, you might even sue them!

http://adage.com/digital/article?article_id=138587#=rss2534

Media Cos.' Best Customers: Those Who Steal Their Content

Mike Vorhaus on Digital Communications

by Mike Vorhaus Published: August 24, 2009

… We compared a random set of Vuze users with a national sample of internet users ages 18 to 44, and results revealed that users of P2P technology spend considerable money on traditional media and entertainment. They are, in fact, important and valued customers of the traditional media companies. Our survey shows that the P2P user attends 34% more movies in theaters, purchases 34% more DVDs and rents 24% more movies than the average internet user.



Ensuring that Colorado stays on the leading edge! (Also a business opportunity that locks in customers since pigeons are trained to return to YOUR coups!)

http://entertainment.slashdot.org/story/09/08/29/1934251/Pigeon-Protocol-Finds-a-Practical-Purpose?from=rss

Pigeon Protocol Finds a Practical Purpose

Posted by timothy on Saturday August 29, @03:37PM from the fly-away-little-one dept.

Selanit writes

"Since David Waitzman wrote his tongue-in-cheek Standard for the Transmission of IP Datagrams on Avian Carriers, there have been occasional attempts to actually transmit information via pigeon. One group back in 2001 successfully sent a PING command. But now there's a practical use for pigeon-based communications: photographers working for the white-water rafting company Rocky Mountain Adventures send memory sticks full of digital photos via homing pigeon so the photos will be ready when the rafters finish up. The company has details on how the pigeons are trained and equipped. It may not be a full implementation of the Pigeon Protocol, but it works in narrow canyons far off the beaten path — and just as David Waitzman presciently predicted, they occasionally suffer packet loss due to hawks and ospreys."



Don't tell my wife...

http://www.makeuseof.com/tag/top-10-sites-for-online-coupons-promotional-codes/

Top 10 Sites For Online Coupons & Promotional Codes

Aug. 30th, 2009 By John McClain

… Here’s some websites that may help you save a little bit of money the next time you shop online simply by typing in a code.

Saturday, August 29, 2009

TJX update. It seem the assets he is surrendering come to about one percent of the amount TJX spent to “resolve” the issue. I wonder how much it cost TJX customers?

http://www.databreaches.net/?p=6925

Gonzalez pleads guilty, sentenced to 15-25 years

August 28, 2009 by admin Filed under Breach Incidents, Business Sector, Hack, Of Note

The Associated Press has reported that Albert Gonzalez has agreed to plead guilty to conspiracy, wire fraud and aggravated identity theft charges.

Under a plea agreement with federal prosecutors filed in Boston on Friday, Albert Gonzalez would serve a sentence of 15 to 25 years after pleading guilty to a 19-count indictment. He would also forfeit some $2.8 million in cash, a Miami condo, a car and expensive jewelry.

Gonzalez, 28, is charged with swiping credit and debit card numbers of more than 170 million accounts.

Kim Zetter of Threat Level reports:

The agreement resolves the case against Gonzalez in Massachusetts — which charged him with hacking into TJX, Barnes & Noble and OfficeMax — as well as a case in the eastern district of New York that charged him with hacking into the Dave & Busters restaurant change.

Still outstanding are charges filed last week in New Jersey alleging that Gonzalez also hacked into Heartland Payment Systems, Hannaford Brothers, ATMs stationed in 7-11 stores, and two unnamed national retailers.

Yesterday, StorefrontBacktalk indicated that the two unnamed retailers are J.C. Penney and Target.

Update 1: The Associated Press has published more detail.



You might wonder why they bothered to notify the AG if the database was encrypted. It looks to me that is was not really encrypted, but might squeak by based on some vague legal definition of encryption. Much more likely the data was in some database format and not “encrypted” at all. But we'll never know since there is no requirement to report the impact of a breach.

http://www.databreaches.net/?p=6945

Normandeau Associates reports theft and recovery of stolen laptop

August 28, 2009 by admin Filed under Breach Incidents, Breach Types, Business Sector, Theft, U.S.

Normandeau Associates, an environmental consulting firm based in New Hampshire, notified the New Hampshire Attorney General of the theft of a laptop with an encrypted employee database. The theft occurred in 2008, and the laptop was recovered in February 2009, but Normandeau did not learn of the problem until June 2009, [How could that be? The manager responsible was in a coma? Bob] at which point they notified 277 employees in New Hampshire. As they explain (pdf):

In June, 2009, Normandeau learned that one of its laptop computers had been stolen from the home of a Normandeau employee in November, 2008, and later returned in February, 2009. The password protected laptop contained an encrypted employee database with personal information, including names, social security numbers, and bank account numbers of past and present Normandeau employees. The perpetrator required specific computer software to access the encrypted database in its existing format on the laptop, and it is unknown if access was actually made. [Are we to assume the employee did not have the software on his computer to access the database he downloaded? How stupid is this guy? Bob]

The local police were notified [Apparently not by the employee! Bob] about the theft and Normandeau conducted an internal investigation. Nonnandeau also consulted with a computer forensic analyst, but was unable to determine if unauthorized access to the database actually occurred. There is no evidence of misuse of the personal information. [This is a very safe statement to make. Worthless, but safe. Since employees didn't know about the theft, they were unlikely to notify the firm of any Identity Theft issues. Bob]

[...]

Normandeau has policies that prohibit personal information from being downloaded onto its laptop computers. In this instance, the database was temporarily stored on the laptop during restorative maintenance to the company’s network, and contrary to company policy, not thereafter removed. The company took action against the responsible person for unintentionally failing to remove the database containing the personal information as required by company policy. No further precautionary actions were required to prevent similar breaches. [Near gibberish. Translation: “We're not going to change anything.” Bob]


(Related) Lessons: Most organizations still don't encrypt. Laptops are still targets of thieves. Apparently, unlimited downloading of patient data (personal data) is still okay...

http://www.databreaches.net/?p=6972

Laptops containing medical details of Birmingham patients stolen

August 29, 2009 by admin Filed under Breach Incidents, Healthcare Sector, Non-U.S., Theft

In the U.K.:

Laptops containing the private and medical details of more than 7,000 Birmingham NHS patients, including sick children, have been stolen prompting a massive security alert.

Surgical firm Trulife used by four hospitals – Birmingham Children’s Hospital, City Hospital, in Winson Green, Sandwell Hospital, in West Bromwich, and Rowley Regis Hospital – has revealed that three computers have been taken.

One of them was taken after being left in a car by an employee, while another was snatched during a mugging.

None of the information on the missing laptops had been encrypted.

Between 3,000 and 3,500 Children’s Hospital patients are affected plus a further 3,633 patients from City, Sandwell and Rowley Regis.

[...]

The first laptop went missing at the premises of a Birmingham hospital in March 2006, a second was stolen in a mugging in March 2007 and the third was stolen after being left in a Trulife employee’s car in February last year.



Update your statistics.

http://www.databreaches.net/?p=6933

Biggest Breaches of 2009

August 28, 2009 by admin Filed under Breach Incidents, Commentaries and Analyses, Of Note

Linda McGlasson of BankInfoSecurity.com provides an analysis and commentary, based on ITRC’s statistics for this year.

There have been 356 data breaches so far in 2009, according to the Identity Theft Resource Center (ITRC). And 46 of those breaches have involved financial institutions - up from 34 at this same time last year.

In reviewing these 46 incidents (see interactive timeline w/details of each breach), one finds goods news and bad, according to ITRC executive director Linda Foley.

The good news, Foley says, is that, based on percentages, financial institutions consistently have lower percentages of data breaches than other organizations. “This means they’re doing a better job of controlling and protecting their data,” she says.

The bad news is when financial institutions - or their third-party service providers — are breached … it’s big.

Read more on BankInfoSecurity.com



Good news, bad news? “If you're innocent, you have nothing to worry about.”

http://www.pogowasright.org/?p=3299

Swedish police to publicly identify suspects

August 29, 2009 by Dissent Filed under Non-U.S., Surveillance

Police in Skåne in southern Sweden will shortly begin publishing pictures of criminal suspects on the police website, a practice that may soon be adopted all over the country.

The pictures will be taken from surveillance cameras and the police hope that the general public will help investigate and identify criminals.

[...]

Anne Ramberg, general secretary of the Swedish Bar Association (Advokatsamfundet), argues that innocent people may suffer anxiety as a result of this method. She writes publicly that the pictures are a further sign that more societal surveillance leads to “an insidious shifting of the boundaries”.

Read more on The Local (Sweden)



Worth a review

http://www.pogowasright.org/?p=3288

Privacy missing from Google Books settlement

August 29, 2009 by Dissent Filed under Internet, U.S.

If Google digitizes the world’s books, how will it keep track of what you read?

That’s one of the unanswered questions that librarians and privacy experts are grappling with as Google attempts to settle a long-running lawsuit by publishers and copyright holders and move ahead with its effort to digitize millions of books, known as the Google Books Library Project.

[...]

“Which way are we going to go?” said Michael Zimmer, a professor from the University of Wisconsin at Milwaukee. “ Is this service going to be an extension of the library, or an extension of Web searching?”

Zimmer spoke at a panel discussion at the University of California, Berkeley, on Friday. He was one of several panelists who called on Google to make a stronger privacy commitment as it develops the Google Books service.

Read more on PC World.

Michael Zimmer has posted a draft of the talk he gave as well as his slides on his blog, here.



Yes. Youse gotta problem wit dat?

http://science.slashdot.org/story/09/08/29/0449206/Is-Good-Enough-the-Future-of-Technology?from=rss

Is "Good Enough" the Future of Technology?

Posted by Soulskill on Saturday August 29, @02:08AM from the seems-to-work-for-the-movie-industry dept.

himitsu writes

"In an article titled 'The Good Enough Revolution: When Cheap and Simple Is Just Fine,' Wired claims that the future of technology, warfare and medicine will be filled with 'good enough' solutions; situations where feature-rich and expensive products are replaced with bare-bones infrastructures and solutions. 'We now favor flexibility over high fidelity, convenience over features, quick and dirty over slow and polished. Having it here and now is more important than having it perfect. These changes run so deep and wide, they're actually altering what we mean when we describe a product as "high-quality."'"


(Related) but rather simplistic...

http://news.cnet.com/8301-13505_3-10320382-16.html?part=rss&subj=news&tag=2547-1_3-0-20

What technology tells us about society

by Matt Asay August 28, 2009 8:10 AM PDT

Twitter has become an excellent way to quickly scan headlines. It's terrible at just about everything else. It's hard to have a coherent discussion in 140-character soundbites, and even harder when the architecture of Twitter is set to "broadcast" rather than "discourse." But maybe, just maybe, Twitter's not to blame. We are.

After all, Twitter is simply a creation of our society, and reflects our priorities.

Not all of society, of course. After all, as The New York Times reported, teenagers, usually technology's early adopters, hardly use Twitter at all, with only 11 percent of people aged 11 to 17 using the service. They are, however, heavily into Facebook, preferring to share with friends rather than talk at strangers.

A generational thing?

Perhaps. But I think the technology we build and use says a lot about society.



Oooo! I like it!

http://tech.slashdot.org/article.pl?sid=09/08/28/1952211

Crime Expert Backs Call For "License To Compute"

Posted by ScuttleMonkey on Friday August 28, @06:08PM from the natural-selection-working-just-fine dept.

The Cable Guy writes to mention that Russel Smith, one of Australia's principal criminologists, is pushing for first-time computer users to be required to earn a license to browse the web.

"The Australian Computer Society launched computer driver's licenses in 1999. It aimed to give users a basic level of competency before they started using PCs. But the growth in cybercrime has led to IT security experts such as Eugene Kaspersky to call for more formalized recognition of a user's identity so they can travel the net safely. Last week Dr. Smith sat in front of a Federal Government Inquiry into cybercrime and advised Australia's senior politicians on initiatives in train to fight cybercrime. He said that education was secondary to better technology solutions." [This is incredibly illogical... “Let's build a device but not teach people how to use it!” Bob]



Monopolies are good? Perhaps the rule should be “Subscribers get to choose their provider?”

http://yro.slashdot.org/story/09/08/28/2213208/Court-of-Appeals-Rejects-FCCs-Cable-Subscriber-Cap?from=rss

Court of Appeals Rejects FCC's Cable Subscriber Cap

Posted by Soulskill on Friday August 28, @06:59PM from the pack-'em-in dept.

olsmeister writes

"The US Court of Appeals Friday threw out the FCC's cap on the number of cable subscribers one operator can serve, saying the FCC was 'derelict' in not giving DBS its due as a legitimate competitor. 'We agree with Comcast that the 30% subscriber limit is arbitrary and capricious. We therefore grant the petition and vacate the Rule,' said the court, which concluded that there was ample evidence of an increasingly competitive communications marketplace and that cable did not have undue control on the programming pipeline. The FCC commissioner's statement (PDF) is available online."



Breaking News! I am not on this list!

http://www.bespacific.com/mt/archives/022174.html

August 28, 2009

Federal Reserve Board Must Release Bank Bailout Info to News Organizations

Reporters Committee for Freedom of the Press: "The string of FOIA lawsuits for release of records of the government's emergency lending programs finally saw its first victory Monday. The Federal Reserve Board must release to Bloomberg News records identifying the financial firms it loaned bailout funds to as well as the assets or amounts put up as collateral, the news agency reported. Chief Judge Loretta Preska in Manhattan federal court issued the first ruling requiring disclosure in a handful of suits in New York federal court brought separately by Bloomberg, Fox News and the New York Times. Bloomberg reported that she rejected the argument that the records were exempt from release under FOIA because they might harm the competitive advantage of the borrowers."



This is filed under Humor, but we know better!

http://www.divinecaroline.com/22087/81995-hilarious-new-iphone-commercial

Hilarious New iPhone Commercial

By: Dahlia Rideout



With one University going entirely to eBooks and another to “programed learning” site like this one should prove useful.

http://www.killerstartups.com/blogs/all-about-online-learning-theelearningcoach-com

All About Online Learning - TheeLearningCoach.com

http://theelearningcoach.com/

Online learning has gone from being a curiosity and even something regarded as unreliable to a form of education revered and respected both by teachers and students the world over. As such, it is only appropriate that there are resources which intend to guide people and show them which online providers of education are the best available, or the ones that will suit their specific needs more minutely and accurately.

The opening screen of the blog, then, showcases the most recent sites and products to have been reviewed, whereas the obligatory list of categories is available for you to focus your stay at the site even more.

Friday, August 28, 2009

Curious. HP suspects fraud. So would I if five laptops were paid for on a personal credit card (or were they shipped COD?)

http://www.pogowasright.org/?p=3241

FBI investigating laptops sent to US governors

August 27, 2009 by Dissent Filed under Breaches, Other

Robert McMillan of IDG News Service reports:

There may be a new type of Trojan Horse attack to worry about.

The U.S. Federal Bureau of Investigation is trying to figure out who sent five Hewlett-Packard laptop computers to West Virginia Governor Joe Mahchin a few weeks ago, with state officials worried that they may contain malicious software.

According to sources familiar with the investigation, other states have been targeted too, with HP laptops mysteriously ordered for officials in 10 states. Four of the orders were delivered, while the remaining six were intercepted, according to a source who spoke on condition of anonymity because of the ongoing investigation.

Read more on Network World.


(Related)

http://www.databreaches.net/?p=6923

Security test prompts federal fraud alert

August 28, 2009 by admin Filed under Financial Sector, U.S.

Robert McMillan of IDG News Service reports:

A sanctioned security test of a bank’s computer systems had some unexpected consequences this week, leading the federal agency that oversees U.S. credit unions to issue a fraud alert.

On Tuesday, the National Credit Union Administration (NCUA) warned all federally insured credit unions of a bogus letter that an unnamed credit union had received along with two CDs. The bogus letter claimed that the CDs contained NCUA anti-fraud training materials, but in its fraud alert, NCUA warned that running the CDs “could result in a possible security breach to your computer system, or have other adverse consequences.”

Only it turned out that the CDs were not sent by fraudsters. They were sent by employees of MicroSolved, a Columbus, Ohio, security testing company. “It was a part of some social engineering we were doing in a fully sanctioned penetration test,” said MicroSolved CEO Brent Huston in an e-mail message.

Read more on Computerworld

It’s interesting (to me, anyway), that this type of information was immediately and correctly shared throughout the system to prevent fraud, whereas details of actual compromises that might help other institutions prevent compromises of their own do not seem to be shared quickly or fully. [And apparently before checking the contents of the CDs Bob] To the contrary, they are often kept under tight wraps. Following the Heartland Payment Systems breach, Heartland indicated that it would share specifics with others and called for greater information sharing. Is that actually happening?



Hackers aren't the only problem you face with IT systems. Sometimes incompetence is even more deadly.

http://news.slashdot.org/story/09/08/27/2144223/Bug-Means-High-School-Students-Schedule-Errors-May-Last-Days?from=rss

Bug Means High School Students' Schedule Errors May Last Days

Posted by timothy on Thursday August 27, @05:53PM from the ok-computer-meeting-people-is-easy dept.

Hugh Pickens writes

"The Washington Post reports that thousands of high school students in Prince George's County missed a third day of classes Wednesday, and school officials said it could take more than a week to sort out the chaos caused by a computerized class-scheduling system as students were placed in gyms, auditoriums, cafeterias, libraries and classes they didn't want or need at high schools across the county and their parents' fury over the logistical nightmare rose. 'The school year comes up the same time every year,' said Carolyn Oliver, the mother of a 16-year-old senior who spent Wednesday in the senior lounge at Bowie High School. 'When I heard they didn't have schedules, I was like, "What have they been doing all summer?"' When school opened Monday, about 8,000 high school students had no class schedules and were sent to wait in holding spaces while administrators tried to sort things out." (More below.)

"By Tuesday evening, that number was down to 4,000. As of noon Wednesday, 3,400 of the school district's 41,000 high school students had no class schedules, officials said. Superintendent William R. Hite Jr. said that some schools didn't realize there was a problem with schedules until school started and that the trouble was exacerbated by difficulties with SchoolMax, a $4.1 million computer system introduced last school year. SchoolMax went online in Prince George's a year ago to help the county track students' grades, attendance and discipline data. Last year, the program crashed at least four times and was plagued by errors that led to botched schedules, an overcount of students and mistakes on report cards. Jessica Pinkney, a junior, said she was moved to the cafeteria Wednesday morning after two days in the gymnasium because the cafeteria had air conditioning. 'We just sit and do nothing,' says Pinkney. 'But I'm meeting new people, so it's getting more interesting.'"


(Related) And sometimes acting before thinking produces some nasty (if inevitable) results too.

http://www.pogowasright.org/?p=3210

White House sued over free speech violations in healthcare battle

August 27, 2009 by Dissent Filed under Court, Featured Headlines, Govt, U.S.

The Office of the President and other White House officials are defendants in a free speech lawsuit filed by a prominent physician group, and a non-profit advocate for inner-city poor, according to a new press release.

The White House has “unlawfully collected information on political speech,” [What makes it “unlawful?” Bob] thereby illegally using the power of the White House to chill opposition to its plans for health care reform, according to the complaint filed in District Court for the District of Columbia, by the Association of American Physicians and Surgeons (AAPS) and the Coalition for Urban Renewal and Education (CURE)

The lawsuit was prompted by the White House solicitation for the public to report any “fishy” comments to ‘flag@whitehouse.gov.’ Although the White House slightly revised its data collection procedure last week, the email address still exists, the illegal activity continues, and is part of an “unlawful pattern and practice to collect and maintain information” on the exercise of free speech, which “continues in violation of the Privacy Act and First Amendment even if the Defendants terminate a particular information-collection component due to negative publicity.”

The lawsuit outlines how the White House has employed a form of “bait-and-switch” tactic of accusing the Plaintiffs and other opponents of spreading misinformation about the Administration’s goals for health care reform, and thereby refusing to ‘come clean’ about its real agenda.

The lawsuit outlines that the White House knew that the data collection would chill free speech, and in fact, intended to do just that:

“43. As part of their effort to advance the White House healthcare
reform agenda, Defendants have accused opponents (including
Plaintiffs) of spreading misinformation on issues such as whether
(a) health reform would provide public funding for abortions, (b) put
“death panels” in place to deny care to the elderly or infirm,
(c) amount to a government takeover of healthcare, and (d) increase
healthcare costs..the Defendants and the administration have spread
misinformation, semantics, and disinformation on these topics…..

“45. By denying and continuing to deny that healthcare reform
legislation includes “death panels” that make individual life-or-death
decisions on the elderly or infirm, the Defendants and the current
administration have ignored and implicitly denied and continue to
ignore and implicitly to deny both that their healthcare reform agenda
involves rationing healthcare…”

“My hate mail started shortly after the White House issued the ‘fishy’ request,” said Kathryn Serkes, Director of Policy and Public Affairs for AAPS. “We were quite visible and vocal before then, so it doesn’t seem like a coincidence. Who did they share their data with? With whom might they share it?”

AAPS and CURE demand that the White House remove all information already collected, and further, be prohibited from collecting any personal data in the future.

NOTE: AAPS is a non-partisan professional association of physicians dedicated since 1943 to protection of the patient-physician relationship. CURE, founded by Star Parker, serves poor and inner-city communities through church, individual, and market-based solutions to poverty.

The case number is Civil Action No. 09-1621-EGS. The full text of the complaint is available on request .

SOURCE Association of American Physicians and Surgeons (AAPS)


(Related) If you can't get away with a “chilling effect” try something else.

http://news.cnet.com/8301-13578_3-10320096-38.html?part=rss&subj=news&tag=2547-1_3-0-20

Bill would give president emergency control of Internet

by Declan McCullagh August 28, 2009 12:34 AM PDT

Internet companies and civil liberties groups were alarmed this spring when a U.S. Senate bill proposed handing the White House the power to disconnect private-sector computers from the Internet.

They're not much happier about a revised version that aides to Sen. Jay Rockefeller, a West Virginia Democrat, have spent months drafting behind closed doors. CNET News has obtained a copy of the 55-page draft (excerpt), which still appears to permit the president to seize temporary control of private-sector networks during a so-called cybersecurity emergency.



What is secure today, is hacker fodder tomorrow.

http://hardware.slashdot.org/story/09/08/27/180249/WPA-Encryption-Cracked-In-60-Seconds?from=rss

WPA Encryption Cracked In 60 Seconds

Posted by timothy on Thursday August 27, @02:38PM from the nicholas-cage-has-an-alibi dept.

carusoj writes

"Computer scientists in Japan say they've developed a way to break the WPA encryption system used in wireless routers in about one minute. Last November, security researchers first showed how WPA could be broken, but the Japanese researchers have taken the attack to a new level. The earlier attack worked on a smaller range of WPA devices and took between 12 and 15 minutes to work. Both attacks work only on WPA systems that use the Temporal Key Integrity Protocol (TKIP) algorithm. They do not work on newer WPA 2 devices or on WPA systems that use the stronger Advanced Encryption Standard (AES) algorithm."



Eco-hacking?

http://www.wired.com/dangerroom/2009/08/china-all-your-rare-earth-metals-belong-to-us/

China: All Your Rare-Earth Metals Belong to Us

By Nathan Hodge Email Author August 26, 2009 11:57 am

Rare-earth metals are the key to 21st Century technology: Without them, we wouldn’t have smartphones, hybrid cars or precision weapons. And China, which mines most of the world’s rare-earth metals, may be starting to catch on to their strategic value.

According to this alarming story in Britain’s Telegraph, China’s Ministry of Industry and Information Technology is weighing a total ban on exports of terbium, dysprosium, yttrium, thulium, and lutetium — and may restrict foreign sales of other rare-earth metals. But don’t panic yet: U.S.-based Molycorp Minerals is preparing to resume mining of rare earth ore deposits at a California facility, pictured here.



I'm shocked! Shocked I tell you!

http://www.wired.com/threatlevel/2009/08/maplight/

Hollywood, Big Software and Coal Miners Pros at Timely Political Donations

By Ryan Singel August 26, 2009 7:38 pm

Money in politics is an old story. But armed with a new tool that shows just how closely timed votes and contributions are, Threat Level uncovered some interesting connections between high tech industries, lawmakers and legislation that became the law of the land.

MAPLight.org’s new Money Near Votes site works by noting which groups support a bill and which oppose it, and watching their campaign contributions over time. MAPLight launched the tool Wednesday with a dramatic chart showing that bank lobbyists paid nearly $300,000 to politicians before and after a vote on a credit card reform measure.



This is too soon after the 9th Circuit's decision to be a result of that decision, isn't it?

http://www.pogowasright.org/?p=3219

New directives on border searches of electronic media

August 27, 2009 by Dissent Filed under Govt, Surveillance, U.S.

Department of Homeland Security (DHS) Secretary Janet Napolitano today announced new directives to enhance and clarify oversight for searches of computers and other electronic media at U.S. ports of entry.

“Keeping Americans safe in an increasingly digital world depends on our ability to lawfully screen materials entering the United States,” said Secretary Napolitano. “The new directives announced today strike the balance between respecting the civil liberties and privacy of all travelers while ensuring DHS can take the lawful actions necessary to secure our borders.”

The new directives address the circumstances under which U.S. Customs and Border Protection (CBP) and U.S. Immigration and Customs Enforcement (ICE) can conduct border searches of electronic media—consistent with the Department’s Constitutional authority to search other sensitive non-electronic materials, such as briefcases, backpacks and notebooks, at U.S. borders.

The directives, available at DHS.gov, will enhance transparency, accountability and oversight of electronic media searches at U.S. ports of entry and includes new administrative procedures designed to reflect broad considerations of civil liberties and privacy protections—measures designed to ensure that officers and agents understand their responsibilities to protect individual private information and that individuals understand their rights.

The DHS Privacy Office also released today a Privacy Impact Assessment, available at www.dhs.gov/privacy, in connection with the new directives to enhance public understanding of the authorities, policies, procedures and controls employed by DHS during border searches of electronic data to protect individuals’ privacy. The DHS Office for Civil Rights and Civil Liberties (CRCL) will also conduct a Civil Liberties Impact Assessment within 120 days.

In conjunction with the Privacy Office and CRCL, CBP will ensure training materials and procedures promote fair and consistent enforcement of the law relating to electronic media searches. CBP will also provide travelers subject to electronic device searches with clear and concise material informing them of the reasons for the search, how their data may be used and detailed information about their constitutional and statutory rights.

DHS conducts border searches of computers and other electronic media on a small percentage of international travelers seeking to enter the United States—searches often as basic as asking a traveler te to o turn on a devicensure it is what it appears to be.

Between Oct. 1, 2008, and Aug. 11, 2009, CBP encountered more than 221 million travelers at U.S. ports of entry. Approximately 1,000 laptop searches were performed in these instances—of those, just 46 were in-depth. [Does that sound like an under estimation to you? Bob]

The new directives will also allow DHS to develop automated, comprehensive data collection and analytic tools to facilitate accurate, thorough reporting on electronic media searched at the border, the outcomes of those searches and the nature of the data searched—further enhancing transparency and accountability.

Related documents:

Source: Department of Homeland Security



Just a reminder that outsourcing isn't the ONLY way... Worth reading!

http://news.slashdot.org/story/09/08/27/1719234/US-Call-Center-Jobs-mdash-That-Pay-100K-a-Year?from=rss

US Call-Center Jobs — That Pay $100K a Year

Posted by timothy on Thursday August 27, @01:50PM from the payment-for-the-gift-of-gab dept.

bheer writes

"BusinessWeek profiles a call center company called iQor which has grown revenues 40% year-on-year by (shock) treating employees as critical assets. It's done this not by nickel-and-diming, but by expanding its US operations (13 centers across the US now), giving employees universal health insurance, and paying salaries and bonuses that are nearly 50% above industry norms. The article notes that outsourcing will continue and globalization will continue to change the world's economic landscape. 'But the US is hardly helpless. With smart processes and the proper incentives, US companies can keep jobs here in America, and do so in a way that is actually better for the company and its employees.' Now if only other companies get a clue as well."



An interesting graphic for my Intro to Computing class (and as a perspective on e-Discovery)

http://www.mozy.com/blog/misc/physical-storage-vs-digital-storage/

Physical Storage vs. Digital Storage

August 26th, 2009 by nate

Last time we did one of these, we wanted to show you how much data we create with our digital lives. Now we want to show you how data storage has changed over the years. It’s pretty mind-blowing. Enjoy!