Wednesday, November 04, 2009

We'll start hearing (a bit) more from Europe.

http://www.pogowasright.org/?p=4994

EU: Telcos’ data breach notification amendment is passed

November 3, 2009 by Dissent Filed under Breaches, Featured Headlines, Non-U.S.

From Out-Law.com:

The European Council has approved a data breach notification rule for Europe’s telecoms firms. The amendment to an EU Directive will force telcos to tell customers if they lose their data.

The European Parliament and Commission have already approved the amendments, which will become law after it has been published in the EU’s Official Journal and signed by the President of the Council and President of the European Parliament.

The amendments, though, do not extend data breach notification duties to non-telecoms firms, despite the Parliament’s earlier demands that it include providers of ‘information society services’ such as online banks or health services providers.

“The Council adopted a directive amending legislation in force on universal service, ePrivacy and consumer protection,” said a Council statement on its meeting last week. “The directive adapts the regulatory framework by strengthening and improving consumer protection and user rights in the electronic communications sector, facilitating access to and use of ecommunications for disabled users and enhancing the protection of individuals’ privacy and personal data.”

Read more on Out-Law.com



Next time, I'm going...

http://www.pogowasright.org/?p=5009

Experts meet to hash out web privacy rules: The Madrid Declaration

November 4, 2009 by Dissent Filed under Featured Headlines, Other

Hundreds of privacy experts from around the world met in Madrid on Wednesday for a three-day conference which aims to arrive at a global standard for the protection of personal data.

US Homeland Security Secretary Janet Napolitano as well representatives from data protection agencies from 50 nations and top managers from key Internet firms like Google and Facebook are taking part in the event, billed as the world’s largest forum dedicated to privacy.

Artemi Rallo Lombarte, the director of the Spanish Data Protection Agency, an independent control authority which is organising the 31st International Conference of Data Protection and Privacy, said laws regulating privacy vary greatly around the world.

Read more in the Sydney Morning Herald.

EPIC.org writes:

In a crisply worded declaration, over 100 civil society organizations and privacy experts from more than 40 countries have set out an expansive statement on the future of privacy. The Madrid Declaration affirms that privacy is a fundamental human right and reminds “all countries of their obligations to safeguard the civil rights of their citizens and residents.” The Madrid Declaration warns that “privacy law and privacy institutions have failed to take full account of new surveillance practices.” The Declaration urges countries “that have not yet established a comprehensive framework for privacy protection and an independent data protection authority to do so as expeditiously as possible.” The civil society groups and experts recommend a “moratorium on the development or implementation of new systems of mass surveillance.” Finally, the Declaration calls for the “establishment of a new international framework for privacy protection, with the full participation of civil society, that is based on the rule of law, respect for fundamental human rights, and support for democratic institutions.” The Madrid Declaration was released at the Public Voice conference in Madrid on Global Privacy Standards. Multiple translations of the Declaration are available.

The full text of the declaration in English can be found here, courtesy of The Public Voice.


(Related) Perhaps we'll see more articles like this one. NOTE: Read this carefully!

http://www.hlswatch.com/2009/10/15/%E2%80%9Cdo-i-have-the-right-to-refuse-this-search%E2%80%9D/

Do I have the right to refuse this search?”

Filed under: General Homeland Security — by Christopher Bellavita on October 15, 2009



So easy, a caveman could do it!

http://www.pogowasright.org/?p=5004

Protecting your virtual privacy

November 3, 2009 by Dissent Filed under Other

The details of your personal life, such as grocery purchases and pizza topping preferences, are collected every day ― online and by club and discount cards from the gym, department store and supermarket. Though this data seems innocent enough, when it’s put together it can tell a whole lot about your health, finances and behavior. That information, a Tel Aviv University researcher reminds us, could eventually be used against you.

Dr. Michael Birnhack of TAU’s Faculty of Law and Prof. Niva Elkin-Koren from the University of Haifa recently completed a comprehensive study on information privacy laws in Israel and found compelling reasons for lawmakers everywhere to take notice. “Our research from Israel can serve as a case study of the shortcomings of a comprehensive data protection program,” says Dr. Birnhack.

“It’s not just sites like Facebook and Twitter that should cause concern,” he continues. “It’s all the trivial things that are collected about us that we’re not protected against.”

Read more on PhysOrg.

[From the article:

Federal legislation in the U.S. regulates for some 15 different kinds of specific data sets, such as health data and credit histories, but not for information collected by club and discount cards or by commercial Web sites. And it's more difficult to write a law to secure confidentiality in those areas, says Dr. Birnhack.

… paper available at http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1456968.


(Related) Just the reverse? Think there's a market for auto-surveillance?

http://www.techcrunch.com/2009/11/03/nebul-us-a-new-way-to-visualize-and-share-how-youre-spending-your-time-online/

Share How You’re Spending Your Time Online

by Jason Kincaid on November 3, 2009

Many of us spend hours a day on our browsers surfing the web both at home and from the office, but we don’t really do much with our web history, which could really serve as a goldmine of information. Nebul.us, a startup launching today in private beta, is looking to tap into this data, leveraging it to offer a cloud-based web history, a productivity tool for monitoring how you’re spending your time online, and a social link sharing service.



See? It really is simple to do – so why don't politicians like it?

http://www.technologyreview.com/web/23836/

First Test for Election Cryptography

Novel voting technology will be used in a local government election.

By Erica Naone Monday, November 02, 2009

… After votes are cast, Scantegrity lets voters check online to make sure that their ballots were counted correctly. Officials and independent auditors can also check to make sure ballots were tallied properly--without seeing how any individual voted.



Cyber War (The opposite of Homeland Security?)

http://www.bespacific.com/mt/archives/022722.html

November 03, 2009

Technology, Policy, Law, and Ethics Regarding U.S. Acquisition and Use of Cyberattack Capabilities

"The United States is increasingly dependent on information and information technology for both civilian and military purposes, as are many other nations. Although there is a substantial literature on the potential impact of a cyberattack on the societal infrastructure of the United States, little has been written about the use of cyberattack as an instrument of U.S. Policy. Cyberattacks--actions intended to damage adversary computer systems or networks--can be used for a variety of military purposes. But they also have application to certain missions of the intelligence community, such as covert action. They may be useful for certain domestic law enforcement purposes, and some analysts believe that they might be useful for certain private sector entities who are themselves under cyberattack. This report considers all of these applications from an integrated perspective that ties together technology, policy, legal, and ethical issues. Focusing on the use of cyberattack as an instrument of U.S. national policy, Technology, Policy, Law and Ethics Regarding U.S. Acquisition and Use of Cyberattack Capabilities explores important characteristics of cyberattack. It describes the current international and domestic legal structure as it might apply to cyberattack, and considers analogies to other domains of conflict to develop relevant insights. Of special interest to the military, intelligence, law enforcement, and homeland security communities, this report is also an essential point of departure for nongovernmental researchers interested in this rarely discussed topic."



Strategy includes more that one of the marketing department's talking points. In fact, there is no reason to “sell” this point at all. Customers looking for staff (cost) reductions will find Cloud Computing on their own.

http://www.networkworld.com/community/node/47039

Tone-deaf Unisys official on why cloud computing rocks

Or what shouldn't get lost in all the puffery over cloud technology

By Paul McNamara on Tue, 11/03/09 - 5:53am.

Here's Richard Marcello of Unisys extolling one of what he sees as the virtues of cloud computing yesterday at the Cloud Computing Conference and Expo in Santa Clara:

"We were able to eliminate a whole bunch of actually U.S.-based jobs and kind of replace them with two folks out of India."

Those actually U.S.-based jobs presumably were held by actual Americans trying to feed actual U.S.-based families.



Not only could this become a billion dollar industry, but my lawyers will want access to prove it was your dog that pooped on my lawn! (Ain't technology wonderful?)

http://tech.slashdot.org/story/09/11/03http://tech.slashdot.org/story/09/11/03/1659215/Could-GPS-Keep-Tabs-On-Your-Pets?from=rss/1659215/Could-GPS-Keep-Tabs-On-Your-Pets?from=rss

Could GPS Keep Tabs On Your Pets?

Posted by samzenpus on Wednesday November 04, @01:41AM from the lassie-tracking dept.

An anonymous reader writes

"Google Latitude has already made headlines for allowing phone users to locate their friends, and there are countless other iPhone and Android phone apps already designed to transmit your location — but could pets be the next big thing in GPS tracking? A number of device manufacturers are marketing GPS technology as a futuristic tool for tracking your cat or dog, and even discovering exactly where they've been. These devices are sold under a number of names and brands, including Sportdog, LoCATor, RoamEO, Petcell, Zoombak and Pettrack."



Is this a cleverly hidden hack? Perhaps the North Korea's cyber war division plans to snarl traffic in a clever bid to bring down the economy? (Comments suggest similar problems) Interesting 'find the bug' case for my forensic class.

http://tech.slashdot.org/story/09/11/04/0053215/Toyotas-Suddenly-Accelerate-Owners-Up-In-Arms?from=rss

Toyotas Suddenly Accelerate; Owners Up In Arms

Posted by kdawson on Tuesday November 03, @11:31PM from the off-to-a-bad-start dept.

cyclocommuter writes

"Some Toyota owners are up in arms as they suspect that accidents have been caused by some kind of glitch in the electronic computer system used in Toyotas that controls the throttle. Refusing to accept the explanation of Toyota and the federal government (it involves the driver's-side floor mat), hundreds of Toyota owners are in rebellion after a series of accidents caused by what they call 'runaway cars.' Four people have died."

The article notes: "The National Highway Traffic Safety Administration has done six separate investigations of such acceleration surges in Toyotas since 2003 and found no defect in Toyota's electronics."



Copyright, not counterfeiting.

http://yro.slashdot.org/article.pl?sid=09/11/03/1943237

Anti-Counterfeiting Deal Aims For Global DMCA

Posted by kdawson on Tuesday November 03, @02:45PM from the by-whose-authority dept.

An anonymous reader writes

"Negotiations on the Anti-Counterfeiting Trade Agreement continue on Wednesday as the US, Europe, Japan, Korea, Canada, Australia, and a handful of other countries secretly negotiate a copyright treaty that includes statutory damages, new search and seizure power, and anti-camcording rules. Now the substance of the Internet chapter has leaked, with information that the proposed chapter would create a 'Global DMCA' with anti-circumvention rules, liability for ISPs, and the possibility of three-strikes and you're out requirements."

[From the article:

Update: Further coverage from IDG and Numerama.

Update II: InternetNZ issues a press release expressing alarm, while EFF says the leaks "confirm everything that we feared about the secret ACTA negotiations." Electronic Frontiers Australia provides an Australian perspective on the ACTA dangers.



Something for my Disaster Recovery students. Could a hacker bring down the entire system?

http://www.bespacific.com/mt/archives/022726.html

November 03, 2009

DOT OIG: Review of FAA’s Progress in Enhancing Air Traffic Control Systems Security

DOT OIG Audit - Review of FAA’s Progress in Enhancing Air Traffic Control Systems Security, November 02, 2009, Project ID: FI-2010-006

  • "On November 2, we issued our final report on FAA’s Progress in Enhancing Air Traffic Control Systems Security. The audit objectives were to determine FAA’s progress in correcting security weaknesses previously identified in the air traffic control (ATC) system by assessing (1) the status of Business Continuity Plan implementation and (2) the enhanced methodology used in the certification and accreditation of air traffic control systems security at operational sites. The FAA made good progress in preparing the Technical Center to serve as the recovery site; yet several unresolved technical challenges, staffing issues, and funding requirements could delay recovery site readiness. Further, while FAA has enhanced the process of reviewing ATC systems security, the reviews were not properly carried out to ensure security protection of operational ATC systems."



I'm sure my students can come up with even more diabolical uses for this...

http://mobile.slashdot.org/story/09/11/03/1649246/Unfinished-Windows-7-Hotspot-Feature-Exploited?from=rss

Unfinished Windows 7 Hotspot Feature Exploited

Posted by timothy on Tuesday November 03, @11:54AM from the vestigial-tail dept.

An anonymous reader writes with this excerpt from Engadget:

"It wasn't all that long ago that Microsoft was talking up the Virtual WiFi feature developed by Microsoft Research and set for inclusion in Windows 7, but something got lost along the road to release day, and the functionality never officially made it into the OS. As you might expect with anything as big and complicated as an operating system though, some of that code did make it into the final release, and there was apparently enough of it for the folks at Nomadio to exploit into a full fledged feature. That's now become Connectify, a free application from the company that effectively turns any Windows 7 computer into a virtual WiFi hotspot — letting you, for instance, wirelessly tether a number of devices to your laptop at location where only an Ethernet jack is available, or even tether a number of laptops together at a coffee shop that charges for WiFi."



For my math students...

http://teachingcollegemath.com/?p=1753

How to Study for a Math Test

… All of the projects can be found on their website: How to Study for a Math Test.


(Related) Whatever works.

http://www.makeuseof.com/tag/3-great-online-tools-to-improve-study-skills-and-get-better-grades/

3 Great Online Tools to Improve Study Skills and Get Better Grades

Nov. 3rd, 2009 By Simon Slangen



For the Swiss Army folder (until everyone goes paperless)

http://www.walletpop.com/blog/2009/11/02/if-george-costanza-had-an-iphone-hed-use-this-app/

If George Costanza had an iPhone, he'd use this app

Aaron Crowe Nov 2nd 2009 at 11:00AM

… The Shoeboxed app allows users to take photos of receipts with their iPhone. The image is then automatically sent to Shoeboxed to be digitally archived and and categorized for expense tracking, reimbursements and deduction claims. A computer, backed by human verification, takes down the date, vendor name, amount, payment type and IRS tax category before filing away the electronic copies of the receipts.



I'm thinking of creating a decal for my laptop with Linus Torvald's face and the words: “Build your own Operating System”

http://www.infectious.com/

Tuesday, November 03, 2009

There should be an MBA class on mitigating the cost of a security breach.

http://www.databreaches.net/?p=8083

Heartland Payment Systems Reports Third Quarter Financial Results

November 3, 2009 by admin Filed under Breach Incidents, Financial Sector

Heartland Payment Systems, Inc. announced a GAAP net loss of $13.6 million or ($0.36) per share for the three months ended September 30, 2009. Results for the quarter are after $35.6 million (pre-tax), or $0.59 per share, of various expenses, accruals and reserves, all of which are attributable to the processing system intrusion, including charges related to settlement offers made by the Company in attempts to resolve certain processing system intrusion related claims and settlements of certain claims deemed to be likely to be agreed upon in the near future based upon discussions between the Company and the claimants.

(emphasis added by me).

Read more on Business Wire.



Clearly this is malware that “escaped into the wild” or maybe that's what we're supposed to think?

http://www.databreaches.net/?p=8080

New Trojan encrypts files but leaves no ransom note

November 3, 2009 by admin Filed under Malware

Elinor Mills reports:

Symantec is warning about a new Trojan horse that encrypts files on compromised computers but offers no ransom note like other software designed to hold data hostage for a fee.

Instead, a Web search for terms related to the Trojan horse leads to a company offering a way to remove the malware. The company offering the product used to charge for it but now offers it for free.

Read more on Cnet.



Using Cloud Computing you can dramatically reduce time, but cost rises exponentially.

http://it.slashdot.org/story/09/11/03/0053230/Cracking-PGP-In-the-Cloud?from=rss

Cracking PGP In the Cloud

Posted by kdawson on Tuesday November 03, @05:17AM from the distant-thunder dept.

pariax writes

"So you wanna build your own massively distributed password cracking infrastructure? Electric Alchemy has published a writeup detailing their experiences cracking PGP ZIP archives using brute force computing power provided by Amazon EC2 and a distributed password cracker from Elcomsoft."

[From the article:

Unfortunately, on a fast dual core Windows7 box we were looking at something like 2100 days to brute force a reasonably long complex passphrase for these PGP ZIPs.

… Clearly each additional character of password length adds a significant amount of cost to the brute forcing effort. One might speculate that an average corporate adversary could quite easily come up with ~$50K USD to brute an 11 character simple password, but struggle to find the $1.5M USD to brute a 12 character simple password.



Lest you thought new technologies were more “hacker proof”

http://arstechnica.com/apple/news/2009/11/dutch-hacker-holds-jailbroken-iphones-hostage-for-5.ars

Dutch hacker holds jailbroken iPhones "hostage" for €5

One Dutch hacker managed to find and hack into jailbroken iPhones, though it seems the hacker was more interested in a few euros than malicious ends. However, the incident is another reminder that users of jailbroken iPhones need to be more vigilant about security.

By Chris Foresman Last updated November 2, 2009 4:27 PM CT

… The hacker relied on unchanged root passwords to hack into the phones [Users never learn (or read the manual) Bob]



Patent weirdness. I thought it might be because “humans” were prior art,

http://www.wired.com/threatlevel/2009/11/genes/

Judge OKs Challenge to Human-Gene Patents

By David Kravets November 2, 2009 8:11 pm

… The first-of-its-kind lawsuit by the American Civil Liberties Union and the Public Patent Foundation at the Benjamin Cardozo School of Law claims that the patents violate free speech by restricting research.



Think of all the things the government makes us buy now. Auto insurance, Drinking water (once they pollute ground water), etc. This is unique only in that it require everyone to purchase something.

http://www.pogowasright.org/?p=4940

Health insurance mandate alarms some

November 2, 2009 by Dissent Filed under Govt, Legislation, U.S.

David G. Savage reports:

Among some libertarians and conservatives, the most troubling aspect of the pending healthcare reform bills is the prospect of a federal requirement that Americans buy insurance.

“What next? Can Congress order you to buy spinach?” asked Roger Pilon, director of constitutional studies at the Cato Institute.

He and other defenders of limited federal power foresee a constitutional challenge to the mandate to buy insurance based on the claim that Congress’ power to regulate commerce does not extend to forcing citizens to buy a commercial product.

Read more in the L.A. Times.



When did anonymous become the equivalent of evil? Shouldn't the test be: Would this be actionable without the anonymity?

http://www.pogowasright.org/?p=4950

ACLU appeals ruling in Review-Journal subpoena case

November 2, 2009 by Dissent Filed under Court, Featured Headlines, Internet

Joan Whitely reports:

Litigation continues about the right to anonymously post disparaging comments online about a Las Vegas-based jury and prosecutor.

The American Civil Liberties Union of Nevada has filed an appeal of federal Judge Kent Dawson’s October decision to not examine the legality of subpoenas served last summer on the Las Vegas Review-Journal to identify who wrote the comments, which had appeared on the newspaper’s Web site.

The government “shouldn’t be permitted to go on a fishing expedition,” the ACLU’s Margaret McLetchie said today on behalf of four anonymous clients who had posted comments. “It took the bravery of the Review-Journal to let the four (John) Does know” that prosecutors were seeking personal information on them, she added. Rarely do subpoena recipients publicize such government efforts to extract information.

The civil rights organization is appealing to have a higher court declare that the two past subpoenas were unconstitutional, even though one was withdrawn and the other has already reaped a harvest of personal data for prosecutors to use in tracking the authors of two specific comments.

In October, Dawson dismissed the ACLU’s effort to intervene as “moot,” or no longer relevant. But the ACLU argues that prosecutors could still be forced by a court to return the data to the newspaper and cease any ongoing search to locate the authors.

Read more in the Las Vegas Review-Journal. More background can be found on the ACLU of Nevada’s web site.



There once was the promise of universal access to knowledge, but we're apparently not yet knowledgeable enough to pull it off.

http://www.time.com/time/business/article/0,8599,1933055,00.html

The Global Antitrust Battle Over Google's Library

By Theo Emery Saturday, Oct. 31, 2009

… The original settlement appeared to be a fait accompli until last summer, when a sleepy copyright case, Authors Guild et al. vs. Google Inc., erupted into an intercontinental brawl. Hundreds of authors and publishers from the Netherlands to New Zealand have written to U.S. District Court Judge Denny Chin, some expressing astonishment and outrage. France and Germany have protested; German Chancellor Angela Merkel singled out Google for criticism in a podcast this month.

… Last month the DOJ dropped perhaps the biggest bombshell. While saying that the settlement could breathe life into millions of unavailable works, the government also said the deal raised "significant legal concerns," and was the target of an antitrust probe.


(Related) I thought cutting off customers was bad. This article suggests you can lose your best content providers too. Apparently there is an audience for a well reasoned opinion. (Some very interesting comments)

http://news.slashdot.org/story/09/11/02/168232/Paywalls-To-Drive-Journalists-Away-In-Addition-To-Consumers?from=rss

Paywalls To Drive Journalists Away In Addition To Consumers?

Posted by ScuttleMonkey on Monday November 02, @12:31PM from the lose-lose-lose dept.

Hugh Pickens writes

"With news organizations struggling and newsroom jobs disappearing, each week brings new calls from writers and editors who believe their employers should save themselves by charging for Internet access. However, in an interesting turnabout, the NY Times reports that Saul Friedman, a journalist for more than 50 years and a columnist for Newsday since 1996, announced last week he was quitting after Newsday decided that non-subscribers to Newsday's print edition will have to pay $5 a week to see much of the site, making it one of the few newspapers in the country to take such a plunge. 'My column has been popular around the country, but now it was really going to be impossible for people outside Long Island to read it,' he says. Friedman, who is 80, said he would continue to write about older people for the site 'Time Goes By.' 'One of the reasons why the NY Times eventually did away with its old "paywall" was that its big name columnists started complaining that fewer and fewer people were reading them,' writes Mike Masnick at Techdirt. 'Newspapers who decide to put up a paywall may find that their best reporters decide to go elsewhere, knowing that locking up their own content isn't a good thing in terms of career advancement.'"


(Related) One would think anything that increased your audience was to be accepted. But then, you have to understand how these things work rather than assume the worst.

http://entertainment.slashdot.org/story/09/11/02/1653246/DVRs-Help-Some-TV-Shows-Improve-Ratings?from=rss

DVRs Help Some TV Shows Improve Ratings

Posted by Soulskill on Monday November 02, @01:55PM from the we've-only-been-telling-them-that-for-a-decade dept.

ubermiester writes

"After years of panicked lawsuits by content providers against TiVo and DVR technology in general, the NYTimes is reporting on yet another lesson for the content providers to learn and then immediately forget: [Great line! Bob] 'Against almost every expectation, nearly half of all people watching delayed shows are still slouching on their couches watching messages about movies, cars, and beer. According to Nielsen, 46 percent of viewers 18 to 49 years old for all four networks taken together are watching the commercials during playback, up slightly from last year.' The article also notes viewership increases 'in the range of 7 to 12 percent, with some shows having increases of more than 20 percent when DVR ratings are added. The four networks together are averaging a 10 percent increase."


(Related) Another unintended consequence.

http://tech.slashdot.org/story/09/11/02/1821232/Pirate-Bay-Closure-Sparked-P2P-Explosion?from=rss

Pirate Bay Closure Sparked P2P Explosion

Posted by ScuttleMonkey on Monday November 02, @03:22PM from the can't-stop-the-signal-mal dept.

Barence writes to share that the closure of The Pirate Bay seems to have done nothing to stem the flow of potentially copyrighted materials. In fact, there has been an estimated 300% increase in the number of sites providing access to copyright files, according to McAfee.

"In August, Swedish courts ordered that all traffic be blocked from Pirate Bay, but any hope of scotching the piracy of music, software and films over the web vanished as copycat sites sprung up and the content took on a life of its own. 'This was a true "cloud computing" effort,' the company said in its Threats Report for the third quarter. 'The masses stepped up to make this database of torrents available to others.'" [And as happens whenever “the masses” is mentioned, they got their own political party. Bob]



I'm not sure this is where the FTC wanted the discussion to go, but that's never stopped the RIAA or MPAA before.

http://arstechnica.com/telecom/news/2009/11/paramount-pictures-over-five-million-copies-of-star-trek-stolen.ars

5 million Star Trek pirates vs. 1 FCC broadband plan

Paramount Pictures says the widespread availability of a bootleg version of Star Trek means it needs to get tough on Internet users and websites, maybe even Google, Yahoo, and Bing. But what does this have to do with the FCC's national broadband plan? Everything, says Paramount.

By Matthew Lasar Last updated November 2, 2009 8:10 AM CT



You know, with the right tweaks to an AI program, we could make a bunch of money in the God business.

http://news.yahoo.com/s/ap/20091102/ap_on_re/us_rel_church_online;_ylt=AiZeyxs4vWTfDX6Vq.9D4q6s0NUE;_ylu=X3oDMTFoNnRzN2E4BHBvcwMxMzQEc2VjA2FjY29yZGlvbl90ZWNobm9sb2d5BHNsawNpbnRlcm5ldGJlbGk-

Internet believers: Pastors open online churches

… The World Wide Web has become the hottest place to build a church. A growing number of congregations are creating Internet offshoots that go far beyond streaming weekly services.

The sites are fully interactive, with a dedicated Internet pastor, live chat in an online "lobby," Bible study, one-on-one prayer through IM and communion.

Monday, November 02, 2009

Perhaps this should be factored in when considering damages?

http://www.databreaches.net/?p=8059

Report: Data Breaches Hike Fraud Risk 400%

November 2, 2009 by admin Filed under Commentaries and Analyses

By Doug Pollack, Chief Marketing Officer for ID Experts:

Because data breaches have become such commonplace incidents, there is concern that people have become desensitized to the potential harm they face upon receiving a notification letter from an organization informing them that sensitive information has been lost or misappropriated.

A recently published report from Javelin Strategies should be a wake up call to those people.

The Javelin report, Data Breach Notifications: Victims Face Four Times Higher Risk of Fraud, is based on multiple years of data and includes updates on 2009 data breaches, implications of changes to the legislative landscape and the technical means by which data breaches occur.

This report should also be heeded by those banks, healthcare organizations, government agencies, insurance companies and others that we entrust with our social security and checking account numbers, birthdates and mothers’ maiden names, and in some cases our personal health information.

Primary Questions

  • Is there a link between data breach notification letters and identity fraud?

  • Are data breach notification letters working?

  • In the face of escalating data breaches, what should financial institutions and other companies do to protect brands and customer loyalty?

  • How do victims respond to breach notification, and how does this impact their relationship with their financial institution?

  • Are paper or electronic records most vulnerable?

  • How are criminals obtaining data records?

There is now proof that data breach incidents put the affected individuals in harms way.

This report is mainly based on consumer data collected from Javelin’s annual Identity Fraud Survey. The survey is conducted each year using computer-assisted telephone interviewing (CATI) via random-digit dialing from 4,784 respondents in October 2008, 5,075 respondents in October 2007, and 5,000 respondents in October 2006. The surveys targeted respondents based on representative proportions of gender, age and income compared to the overall U.S. online population.

Some data also came from Dataloss.db.org, an open community research project that documents known and reported data loss incidents worldwide. Some data also came from the Identity Theft Resource Center, a non-profit organization that compiles information about public data breaches to help understand and prevent identity theft.

The responsibility for doing everything possible to help these people address this harm — from identifying identity fraud to cleaning up the fraud — should fall squarely on the laps of the entrusted organizations.

The Publisher gives permission to link, post, distribute, or reference this article for any lawful purpose, provided attribution is made to the author and to Information-Security-Resources.com



Strategy involves using whatever tools work. If the student was truly concerned about his anonymity, there were better ways of ensuring it. However, if the University takes ANY action, they had better have tons of documentation to justify it. So, other than the intimidation factor, are we at a stalemate?

http://www.pogowasright.org/?p=4936

Student Blogger Case Shows That Online Anonymity Isn’t Guaranteed

November 2, 2009 by Dissent Filed under Court, Internet, U.S., Youth

Butler University has dropped its libel lawsuit against a student that criticized university administration in an anonymous blog, but not before it was able to obtain the identity of the student. It will continue to pursue its own disciplinary proceedings against the student, junior Jess Zimmerman.

Dan Altman, Zimmerman’s lawyer, said that the university filed the lawsuit not because it believed that Zimmerman posted libelous information, but because it wanted to silence his criticism. He called the lawsuit an example of a strategic lawsuit against public participation (SLAPP), lawsuits that are designed to intimidate defendants that are critical of the plaintiff.

Read more on FindingDulcinea.com



If done properly, they should also record your conversation (with passengers and on the phone) as well as texting and listening to your GPS.

http://www.pogowasright.org/?p=4930

EU proposes black boxes for cars

November 1, 2009 by Dissent Filed under Non-U.S., Surveillance

David Millward reports:

Cars could be fitted with aircraft-style black boxes to help police allocate blame following a crash, under plans being considered in Brussels.

The European Commission has spent £2.4 million on Project Veronica, a study on how the boxes would work.

These boxes could be used to reconstruct what happened in the event of a commission which would make it easier for insurance companies to decide who was at fault and, where necessary, enable police to take action against the driver. [...]

These proposals are likely to trigger concern among civil liberties groups over the growth of the surveillance state. However such concerns have been dismissed in the Project Veronica report.

“Anonymised EDR data would be of very limited use in the judicial process and in that regard there is no obvious reason for which data privacy rights should supersede public order and crime investigation,” it notes. [Of course, it's not the anonymized data that concerns us. Can they tap the black boxes any time they choose, without warrants? Bob]

Read more in the Telegraph.


(Related) You would think someone had studied commuters. Is there a PhD dissertation waiting here?

http://tech.slashdot.org/story/09/11/01/2033242/Appeal-For-Commuter-GPS-Logs-To-Aid-Electric-Cars?from=rss

Appeal For Commuter GPS Logs To Aid Electric Cars

Posted by timothy on Sunday November 01, @03:42PM from the where-did-you-go-this-summer dept.

holy_calamity writes

"A team at Carnegie Mellon University has begun a project seeking to design a kit to cheaply convert secondhand cars into cheap, electric ones suitable for commuting, if little else. They hope to rely heavily on smart management software to extract as much efficiency as possible from regenerative braking, and knowledge of terrain from GPS tracking. But they are hampered by a lack of public data on how commuters actually drive. Their solution is to appeal to GPS users to upload .gpx log files of their commute to the team's site. The data is plugged into a simulator that reveals how much cheaper an electric car could do your journey, and an anonymized public dataset will be created. A programming contest will award a production electric car to the coder who designs the best management algorithm using it."



Hardly the best platform for reading, but I guess you use what you have in hand.

http://apple.slashdot.org/story/09/11/02/0853219/For-September-Book-Related-Apps-Overtook-Games-On-iPhone?from=rss

For September, Book-Related Apps Overtook Games On iPhone

Posted by timothy on Monday November 02, @05:00AM from the fall's-good-contemplative-reading-weather dept.

ruphus13 writes

"In a sign that ebooks are rising in popularity, a recent survey by mobile analytics company Flurry revealed that users may be using the iPhone for more intellectual pursuits, and not just the visual sizzle. The 'book-related' apps on the iPhone overtook games in terms of new apps released. [I'll be impressed when the number of books read exceeds... well, anything else. Bob] According to the post, 'Book-related apps saw an upsurge in launches in September ... So much so that book-related applications overtook games in the App Store as a percentage of all released apps. The trend isn't an aberration. In October, one out of every five new applications launching on the iPhone was a book ... from August 2008 to the same month in 2009, more apps were released in the 'games' category than any other and, as a result, the iPhone (and iPod touch) became a new handheld gaming platform, one that impacted the Nintendo DS. '"


(Related) Balderdash! But I found it amusing...

http://www.bespacific.com/mt/archives/022701.html

November 01, 2009

Commentary on the Future of Reading

As the book changes form, the library must champion its own power base—readers, By Tom Peters: "The future of reading is very much in doubt. In this century, reading could soar to new heights or crash and burn. Some educators and librarians fear that sustained reading for learning, for work, and for pleasure may be slowly dying out as a widespread social practice."

[From the article:

At the other extreme, some people have developed a practice of rapidly skimming through long lists of bibliographic citations, dipping into the abstracts, references, tables, citations, and full text as their interest is piqued. We could call this type of reading skimmy-dipping, which wasn't even possible a quarter century ago. The recent launch of Google Fast Flip (fastflip.googlelabs.com) may make skimmy-dipping even easier and more respectable.



Another phone app. Integrating Google and the Cloud and your phone and your car. How distracting can that be?

http://www.businessinsider.com/googles-latest-disruptor-free-turn-by-turn-gps-maps-2009-10

Google's Latest Disruptor: Free Turn-By-Turn GPS Maps (GOOG)

Dan Frommer Oct. 28, 2009, 10:15 AM

… This is potentially bad news for GPS companies such as TomTom and Navigon and telcos like AT&T, which charge up to around $100 per year for this sort of service.

Here's a video from Google:


(Related) Could you be executed for talking to (not on) your phone?

http://www.bespacific.com/mt/archives/022710.html

November 01, 2009

UK Definitive Sentencing Guideline – Causing death by driving

Follow up to postings on driving distractions and texting, see the UK Definitive Sentencing Guideline – Causing death by driving which includes the following: "Using a hand-held mobile phone when driving is, in itself, an unlawful act; the fact that an offender was avoidably distracted by using a hand-held mobile phone when a causing death by driving offence was committed will always make an offence more serious. Reading or composing text messages over a period of time will be a gross avoidable distraction and is likely to result in an offence of causing death by dangerous driving being in a higher level of seriousness."



How silly. (Does that make it more believable?) We want people to work at home so we're going to make it difficult or impossible for them to do so? Perhaps we shouldn't trust an article by someone who can't get the name of the government agency correct. (see gao.gov )

http://blogs.computerworld.com/15011/u_s_pandemic_options_include_crippling_home_modems

U.S. pandemic options include crippling home modems

October 30, 2009 - 11:32 A.M.

The U.S. has a dark box of options for keeping Internet traffic flowing during a pandemic, including restricting the bandwidth capability of home modems.

The feds have already shown their willingness to impose their power on carriers because of national security, something that happened after 9/11 with the Patriot Act. If a pandemic keeps large numbers of the workforce at home and causes network congestion, the U.S. government will likely act again.

Most businesses and government agencies have diverse routing and pay carriers handsomely for bandwidth rich connections. But if a pandemic keeps 30% or more of the population at home, the so-called low bandwidth "last mile" to homes will be critical but in trouble as legions of at-home employees attempt work along with those playing networked games and streaming video.

Voluntary appeals to reduce Internet use will likely be the first option for policy makers. But if that doesn't work, the U.S. General Accountability Office report this week on pandemic planning and networks, outlined some of the other possibilities.

One "technically feasible alternative," wrote the GAO, is to temporarily cripple home user modems:



Looks like an interesting project for my Computer Security class...

http://www.darkreading.com/database_security/security/app-security/showArticle.jhtml?articleID=221300001&cid=RSSfeed

New Honeypot Mimics The Web Vulnerabilities Attackers Want To Exploit

New open-source Honeynet Project tool toys with attackers by dynamically emulating apps with the types of bugs they're looking for

Oct 29, 2009 | 03:53 PM By Kelly Jackson Higgins DarkReading

A next-generation Web server honeypot project is under way that poses as Web servers with thousands of vulnerabilities in order to gather firsthand data from real attacks targeting Websites.

Unlike other Web honeypots, the new open-source Glastopf tool dynamically emulates vulnerabilities attackers are looking for, so it's more realistic and can gather more detailed attack information, according to its developers. "Many attackers are checking the vulnerability of the application before they inject malicious code. My project is the first Web application honeypot with a working vulnerability emulator able to respond properly to attacker requests," says Lukas Rist, who created Glastopf.

Rist, a student, built Glastopf through the Google Summer of Code (Gsoc) 2009 program, where student developers write code for open-source projects. His Web honeypot was one of the Honeynet Project's Gsoc projects.


(Related) Anyone want to be a phone company?

http://linuxcrunch.com/content/skype-will-be-open-source

Skype will be Open Source

By Zayed Sun, 11/01/2009 - 14:37



These are always useful

http://www.bespacific.com/mt/archives/022704.html

November 01, 2009

New on LLRX.com - The Government Domain: A Handful of Classics

The Government Domain: A Handful of Classics - Peggy Garvin has updated her directory of useful government information resources online, the e-Government and Web Directory: U.S. Federal Government Online. Her research has found that federal web sites do not change as rapidly as users believe. The content on these sites is dynamic, constantly being refreshed and redesigned. However, the sites themselves, the ones that represent so much of the work of the federal government and are selected for inclusion in the book, are fairly stable.



This may be useful as we push students online for books, class schedules, research, math and writing labs, forums, testing, even snow closing announcements.

http://www.makeuseof.com/tag/design-your-own-online-portal-website-for-free-with-zooloo/

Design Your Own Online Portal Website for Free with Zooloo

Nov. 1st, 2009 By Mahendra Palsule

Zooloo provides you one place to create, connect and control your online life, including your own website, dashboard, widgets, blog, news, social networks, photos, and videos. While this may sound ambitious, Zooloo is geared towards inexperienced users who want a simple way to design their own website for free and engage in their favorite online activities.

Sunday, November 01, 2009

Is there a clear procedure to accomplish everything that needs to be done when a laptop is stolen? Interesting question for IT and the legal department. NOTE: We have yet to study smaller devices (phones, PDAs, etc.) that would seem easier to lose.

http://www.bespacific.com/mt/archives/022700.html

October 31, 2009

Report: Lost Laptops: More Expensive than you Think

"New research quantifies the primary factors driving the cost of a lost or stolen laptop. Learn from Intel IT’s best practices."

[From the article:

A security expert, billing from around USD 50 to USD 160 per hour, typically spends a day reviewing backup files, e-mail trails, and other clues to the potential damage to the firm.

[From the White Paper:

Summing up these cost drivers, Ponemon estimated the average cost of a lost laptop to be a whopping USD 49,246.



Interesting question. Leads me to ask, do those shrink-wrap licenses work both ways? If a customer “opens and account” has he entered a contractual agreement?

http://news.cnet.com/8301-19413_3-10387879-240.html?part=rss&subj=news&tag=2547-1_3-0-20

Does cloud computing need malpractice safeguards?

by James Urquhart November 1, 2009 6:00 AM PST

Recent failures to protect consumer data stored on the Internet (aka "the cloud") point to an alarming gap between the value of that data and the care with which some vendors treat that data.

Microsoft subsidiary Danger failed to put in even adequate safeguards for its customers' data. Amazon Web Services failed to discover an obvious problem that kept a loyal customer down for 20 hours. Coghead's agreement to sell to SAP without any provisions to continue support for existing customers.



Here's an interesting question. If this speculation is true for music, would it also be true for other content? I already see students who appear to have broad and deep knowledge of games (both as players and programmers) could the same happen to video (tv and movies),books, newspapers, and other topics? (It used to be that you first needed to become an expert at information gathering...)

http://entertainment.slashdot.org/article.pl?sid=09/10/31/215209

The Golden Age of Infinite Music

Posted by kdawson on Sunday November 01, @03:03AM from the in-the-air dept.

Over at the BBC, music journalist John Harris speculates on what may become of the music business now that we have entered the golden age of infinite music.

"I've just poured the music-related contents of my brain into a book, and I would imagine that 30-ish years worth of knowledge about everyone from Funkadelic to The Smiths has probably cost me a five-figure sum, a stupid amount spent on music publications, and endless embarrassed moments spent trying to have a conversation with those arrogant blokes who tend to work in record shops. Last weekend, by contrast, I had a long chat about music with the 16-year-old son of a friend, and my mind boggled. At virtually no cost, in precious little time and with zero embarrassment, he had become an expert on all kinds of artists, from English singer-songwriters like Nick Drake and John Martyn to such American indie-rock titans as Pavement and Dinosaur Jr. Though only a sixth-former, he seemingly knew as much about most of these people as any music writer. Like any rock-oriented youth, his appetite for music is endless, and so is the opportunity..."



Interesting but probably not true. What really happened?

http://politics.slashdot.org/story/09/10/31/2058206/Blogger-Humiliates-Town-Counselors-Into-Resigning?from=rss

Blogger Humiliates Town Councillors Into Resigning

Posted by kdawson on Sunday November 01, @06:16AM from the speaking-truth-to-power dept.

Dr_Barnowl writes

"In an occurrence first postulated in sci-fi and later lampooned by stick figures, it seems that a blogger has actually been responsible for the mass resignation of elected officials — a British town council — largely by calling them 'jack***es' and Nazis. What's next? The deposition of a president with 'your mom' smacktalk?"

[Not how I read the blog http://muckandbrass.blogspot.com/ Bob]



Bad strategy. Software that throttles itself proves the ISP's point – networks need to be throttled! (No it's not logical, this is an argument for politicians, not rational people.) True problem is that many ISPs have what amounts to monopolistic power.

http://torrentfreak.com/utorrent-2-0-to-elimininate-the-need-for-isp-throttling-091031/

uTorrent 2.0 To Elimininate The Need For ISP Throttling

Written by Ernesto on October 31, 2009

ISPs have been throttling BitTorrent traffic for years already. Although the true reasons for this are not always clear, some ISPs have argued that a high number of BitTorrent connections are slowing down other applications and traffic.

In early 2007, when network neutrality was still a non-issue for most people, BitTorrent inventor Bram Cohen told us that ISPs should find a way to cope with BitTorrent.

“ISPs have to invest in making their networks better and faster rather than stifling applications which consumers use and love,” he said, while encouraging users to switch to non throttling ISPs if possible, or complain to their ISP’s customer services.



These articles still capture my attention

http://news.yahoo.com/s/ap/20091031/ap_on_bi_ge/us_health_care_public_plan;_ylt=Asr0WWrkNWizT1iUg64ceh.s0NUE;_ylu=X3oDMTJuMmhzbDYwBGFzc2V0A2FwLzIwMDkxMDMxL3VzX2hlYWx0aF9jYXJlX3B1YmxpY19wbGFuBHBvcwM1BHNlYwN5bl9tb3N0X3BvcHVsYXIEc2xrA2FmdGVyYWxsdGhlZg--

After all the fuss, govt health plan to cover few

By RICARDO ALONSO-ZALDIVAR, Associated Press Writer – Sat Oct 31, 5:17 pm ET

WASHINGTON – What's all the fuss about? After all the noise over Democrats' push for a government insurance plan to compete with private carriers, coverage numbers are finally in: Two percent.



Repeat, but really useful guides

http://www.makeuseof.com/tag/pdf-manuals-round-up/

15 Free Guides That Really Teach You USEFUL Stuff

Oct. 31st, 2009 By Simon Slangen



For the Forensics Wiki

http://www.makeuseof.com/tag/how-to-recover-deleted-emails-in-thunderbird/

How To Recover Deleted eMails in Thunderbird

Oct. 31st, 2009 By Tina

Saturday, October 31, 2009

If you let a little thing like a pre-Halloween blizzard keep you from joining us at the Privacy Foundation's seminar on HIPAA yesterday, shame on you. (And thank you, since I ate your share of an excellent lunch)

I've noticed several articles that seem to touch on topics we raised (and definitely did not resolve) yesterday. Here they are in no particular order...


This article hits several points (including the unstated: lots of money attracts lots of big players)

http://news.cnet.com/8301-27083_3-10387384-247.html?part=rss&subj=news&tag=2547-1_3-0-20

GE launches eHealth, hopes for early adopters

by Elizabeth Armstrong Moore October 30, 2009 12:26 PM PDT

The government's $19 billion incentive package to compel doctors and hospitals to digitize their inefficient paper record systems is nice and shiny. But until a platform exists to support the easy yet secure flow of highly sensitive personal information, that promise could also be empty.

Seeing a business opportunity, General Electric unveiled on Thursday its new unit, eHealth, a suite of solutions that aims to provide the necessary infrastructure. (GE reports that it is investing $90 million to launch eHealth.) It is a daunting task, but if it works, a digital record system that streamlines connectivity between clinicians and patients would eventually cost less, work faster, and reduce medical errors, some of which can be fatal.


(Related) This ties because so many of the players are not covered by HIPAA. (Okay, it's not a perfect match but read the first page of the paper and use your imagination.)

http://www.pogowasright.org/?p=4906

Article: From Privacy To Liberty: The Fourth Amendment After Lawrence

October 31, 2009 by Dissent Filed under Other, U.S.

Thomas P. Crocker has an article (pdf) in the current issue of UCLA Law Review. Here’s the abstract:

This Article explores a conflict between the protections afforded interpersonal relations in Lawrence v. Texas and the vulnerability experienced under the Fourth Amendment by individuals who share their lives with others. Under the Supreme Court’s third-party doctrine, we have no constitutionally protected expectation of privacy in what we reveal to other persons. The effect of this doctrine is to leave many aspects of ordinary life shared in the company of others constitutionally unprotected. In an increasingly socially networked world, the Fourth Amendment may fail to protect precisely those liberties—to live in the company of others free from state surveillance and intrusion—the Constitution should protect. Against the background of the third-party doctrine, we guarantee our privacy only by avoiding ordinary acts of interpersonal sharing. By contrast, the Court in Lawrence explains that intimate conduct occurring within protected personal relationships constitutes a private sphere wherein government may not intrude. Because the third-party doctrine views privacy narrowly, this Article develops a framework for revising Fourth Amendment jurisprudence in light of Lawrence’s protection for interpersonal liberty. By following the lessons of Lawrence, this Article proposes a way to reorient Fourth Amendment jurisprudence away from its focus on privacy in order to protect interpersonal liberty.

Hat-tip, Concurring Opinions.


(Related) After all, government has repeatedly demonstrated its command of Computer Technology.

http://www.pogowasright.org/?p=4911

In Congress, a call to review internal cybersecurity policies

October 31, 2009 by Dissent Filed under Breaches, Featured Headlines, Govt, U.S., Workplace

Ellen Nakashima and Carol D. Leonnig report:

House leaders on Friday called for an “immediate and comprehensive assessment” of congressional cybersecurity policies, a day after an embarrassing data breach that led to the disclosure of details of confidential ethics investigations.

Speaker Nancy Pelosi (D-Calif.) and Minority Leader John A. Boehner (R-Ohio) said they had asked the chief administrative officer of the House to report back to them on the policies and procedures for handling sensitive data as a result of the breach. The inadvertent disclosure of a House ethics committee document, obtained by The Washington Post, summarized the status of investigations into lawmakers’ activities on subjects such as influence peddling and defense lobbying. [...]

In the breach, the report was disclosed inadvertently by a junior committee staff member, who had apparently stored the file on a home computer with “peer-to-peer” software, congressional sources said. The popular software allows computer users to share music or other files and is easily available online. But it also allows anyone with the software on a computer to access documents of another user without permission, as long as the users are on a file-sharing network at the same time.

Read more in the Washington Post.



(Related) Another potential downside of huge government databases...

http://www.wired.com/threatlevel/2009/10/ncic

Woman Loses Job Due to Error in FBI Criminal Database

By Kim Zetter October 30, 2009 3:57 pm

A Maryland woman lost her accounting job after a background check performed through the FBI’s criminal database indicated, erroneously, that she was unsuitable for the job, according to the Baltimore Sun.



Would this be an issue if the targets had made a real effort to remain anonymous? The flip side is that the “defamation” would be taken far less seriously unless there was independent confirmation – i.e. it was true.

http://www.pogowasright.org/?p=4903

Swartz v. Does: American and Canadian approaches to anonymity in internet defamation cases

October 30, 2009 by Dissent Filed under Court, Internet

Matthew Nied, a law student at the University of Victoria, writes:

A recent case illustrates that American jurisprudence is increasingly coalescing around a uniform approach to determine whether a plaintiff may compel the disclosure of an anonymous defendant’s identity in internet defamation cases. As discussed below, the Canadian experience has been different.

In Swartz v. Does (“Swartz”) (see: judgment) a Tennessee state court held that plaintiffs were entitled to discover the identity of an anonymous blogger that published allegedly defamatory statements about them. The case arose when the plaintiffs subpoenaed Google, the parent company of the blogging service used by the anonymous defendants (see: news article). [...]

Swartz is yet another American case that has followed the increasingly prevalent Dendrite standard. Unfortunately, Canadian jurisprudence has yet to begin coalescing to the same extent. The scarce Canadian law on this issue, most of which comes from Ontario, indicates that plaintiffs have two ways to compel online service providers to reveal the identities of anonymous defendants….

Read more on Defamation Law Blog.

[From the blog:

The decision is notable for Justice Brothers’ survey of the various standards previously applied by American courts and his ultimate application of the standard most protective of internet anonymity. This



Cyber War I still suspect this is an example of the first stage of a binary cyber-weapon. Once the first stage is as close to ubiquitous as possible, the second stage delivers the payload. Of course, this is a very primitive example and was easily detected – if not so easily stopped.

http://it.slashdot.org/story/09/10/30/223238/After-1-Year-Conficker-Infects-7M-Computers?from=rss

After 1 Year, Conficker Infects 7M Computers

Posted by Soulskill on Friday October 30, @08:04PM from the happy-anniversary-now-run-an-antivirus dept.

alphadogg writes

"The Conficker worm has passed a dubious milestone. It has now infected more than 7 million computers, security experts estimate. On Thursday, researchers at the volunteer-run Shadowserver Foundation logged computers from more than 7 million unique IP addresses, all infected by the known variants of Conficker. They have been able to keep track of Conficker infections by cracking the algorithm the worm uses to look for instructions on the Internet and placing their own 'sinkhole' servers on the Internet domains it is programmed to visit. Conficker has several ways of receiving instructions, so the bad guys have still been able to control PCs, but the sinkhole servers give researchers a good idea how many machines are infected."


(Related) Could this be another attack on the Internet.

http://news.cnet.com/8301-17852_3-10387620-71.html?part=rss&subj=news&tag=2547-1_3-0-20

Miley Cyrus: Twitter should be banned

by Chris Matyszczyk October 30, 2009 3:51 PM PDT



I will be watching this one closely!

http://hardware.slashdot.org/story/09/10/31/0120223/Contest-To-Hack-Brazilian-Voting-Machines?from=rss

Contest To Hack Brazilian Voting Machines

Posted by Soulskill on Saturday October 31, @12:09AM from the hack-the-vote dept.

An anonymous reader writes

"Brazilian elections went electronic many years ago, with very fast results but a few complaints from losers, of course. Next month, 10 teams that accepted the challenge will have access to hardware and software (Google translation; original in Portuguese) for the amount of time they requested (from one hour to four days). Some will try to break the vote's secrecy and some will try to throw in malicious code to change the entered votes without leaving traces."



It's good to be an anti-spam lawyer, lots (and lots and lots) of evidence, predisposed (angry?) juries, and many useful precedents.

http://yro.slashdot.org/story/09/10/30/1713258/Facebook-Awarded-711-Million-In-Anti-Spam-Case?from=rss

Facebook Awarded $711 Million In Anti-Spam

Posted by Soulskill on Friday October 30, @01:46PM from the yet-another-spam-king-dethroned dept.

An anonymous reader writes

"Facebook is on a never-before-seen legal rampage against high profile internet spammers. Today Facebook was awarded yet another nine-figure settlement, this time for over $700 million. Facebook also has a criminal contempt case on Wallace, which means a high likelihood of prison, a big win for the internet and a milestone in cyber law. 'The record demonstrates that Wallace willfully violated the statutes in question with blatant disregard for the rights of Facebook and the thousands of Facebook users whose accounts were compromised by his conduct,' Jeremy Fogel wrote in his judgment order, which permanently prohibits Wallace from accessing the Facebook Web site or creating a Facebook account, among other restrictions."



Oh look, Congress noticed that Internet thingie... Let's hope someone (preferably someone born in the last 25 years) explains it to them. NOTE: It looks like these arguments could have come from the RIAA and ISP lobbyists.

http://arstechnica.com/tech-policy/news/2009/10/house-senate-get-separate-bills-to-kill-net-neutrality.ars

House, Senate get separate bills to kill net neutrality

With the FCC launching a rule-making proceeding on net neutrality, a pair of bills have been introduced to Congress that would bar the FCC from issuing "any regulations regarding the Internet."

By Nate Anderson Last updated October 30, 2009 12:50 PM CT

Real argument about "network neutrality" is fascinating stuff, provocative and well worth anyone's time if they care about the Internet. Unfortunately, Congress isn't great at having intelligent arguments, and net neutrality is rapidly on its way to becoming the latest victim of the Sound Bite Wars.

Sen. John McCain (R-AZ) and Rep. Marsha Blackburn (R-TN) have each introduced an anti-net neutrality bill into their respective chambers. McCain's is known as the "Internet Freedom Act of 2009," but Blackburn's is billed as (seriously) the "Real Stimulus Act of 2009" (PDF).

This "real stimulus" consists of a single line, which is identical in both bills: "The Federal Communications Commission shall not propose, promulgate, or issue any regulations regarding the Internet or IP-enabled services." While the bills target network neutrality, they appear to go much further by banning any sort of new rules on all IP services.


(Related) This video claims the economics of the Internet will break in 2015. Perhaps that is why Comcast (et.al.) want to limit volume/user.

http://www.youtube.com/watch?v=g9P3FNw7W-A


(Related) Interesting opinion piece on the UK's three strikes proposal.

http://www.timesonline.co.uk/tol/comment/columnists/guest_contributors/article6896049.ece

Denying physics won’t save the video stars

Technology is making file sharing easier and easier. It will take more than unfair laws and harsh punishments to stop it

From The Times October 30, 2009 Cory Doctorow


(Related?) The Cory Doctorow article mentioned he was talking at this “Festival” Looks like lots of interesting videos are available.

http://www.battleofideas.org.uk/index.php/2009/video_index



What happens when the Twitter world gets video? Ego-world become narcissist-world?

http://www.techcrunch.com/2009/10/30/stealth-startup-zkatter-to-launch-real-time-broadcasting-site-to-capture-live-moments/

Stealth Startup Zkatter To Launch Real-Time Broadcasting Site To Capture “Live Moments”

by Leena Rao on October 30, 2009



For the Hacker Folder, several ways around geographic blocks. Thank you Washington Post

http://www.washingtonpost.com/wp-dyn/content/article/2009/10/05/AR2009100500411.html?dyn=popular

On The Internet, Nobody Knows You're Not In The USA

Nik Cubrilovic TechCrunch.com Sunday, October 4, 2009; 11:25 PM

A large number of web services are geographically restricted, such as Hulu, Pandora and Spotify. The reasons are usually to do with content licensing restrictions, or because US visitors (or visitors from other advanced economies) are of a higher value from a monetization perspective. A web application can only guess at the location of a visitor based on an IP address and other information, such as browser language and regional settings.

… If you find yourself outside of the USA and wanting to watch Hulu, outside of the UK and wanting to checkout the BBC, or wanting to rig a web poll, here are some tips:



For the Hacker Folder

http://howto.wired.com/wiki/Traverse_Corporate_Firewalls

Traverse Corporate Firewalls

Censorship has never been popular with American citizens. Unfortunately, censorship is very popular with American corporations.

… Some of these techniques will require a reasonable degree of computer knowhow. They also could get you fired (or worse) so use caution. But for those undaunted, here's our guide to circumventing internet censorship.



Literature for geeks? Plagiarism reduced to cut & paste?

http://www.sparknotes.com/ SparkNotes

http://www.litcharts.com/ LitCharts