Thursday, October 28, 2010

Keeping it “small.” Now that the unknown “Henry Ford of skimmers” has commoditized (by mass producing) the card skimming tools, this fraud seems to offer a steady income with low risk.

http://www.databreaches.net/?p=14960

Credit card ‘flash attack’ steals up to $500,000 a month

October 28, 2010 by admin

Dan Goodin reports:

Credit card fraudsters may have pocketed as much as $500,000 over the past month by pursuing a new type of attack that exploits a major blind spot in payment processors’ defenses, an analyst said.

The “flash attacks” recruit hundreds of money mules who go to ATMs throughout the US and almost simultaneously withdraw relatively small sums of money from a single compromised account, according to Avivah Litan, vice president at market research firm Gartner, who follows the credit card industry. They then move on to a new account. At the end of the month, the heists can fetch as much as $500,000.

“The resulting cash transactions fly under the radar of existing fraud detection systems — they are typically small amounts that don’t raise any alarms,” Litan blogged on Tuesday.

Read more in The Register.

[From the Gertner blog:

The only successful fraud mitigation strategy I’ve seen that works in practice today, is that once the first round of fraud is discovered, an acquiring processor or a payment network tries to figure out the point-of-compromise for these cards. If that is determined, then all cards that were used at that point of compromise (i.e. breached entity site) are put on a blacklist and are rejected for future use at a point-of-sale or ATM machine. This is obviously a costly measure, since new cards and accounts generally have to be reissued to the customers – plus it can jeopardize customer relationships – but the alternative is far less attractive, i.e. risk having the customer account drained.



Another organization with security managed by “Sargent Schultz.” (I know nothing!) Apparently they don't bother to log activity, which matches nicely with their lack of access security.

http://www.databreaches.net/?p=14958

Hacker may have accessed database of Louisiana EMTs

October 28, 2010 by admin

Marsha Shuler reports:

Some 56,000 emergency medical technicians were advised this week that a hacker may have gained access to personal information about them contained in a state licensing database.

The state Department of Health and Hospitals sent letters to the emergency medical technicians, notifying them of the incident that occurred Sept. 17.

[...]

Department of Health and Hospitals spokeswoman Lisa Faust said Bureau of Emergency Medical Services personnel discovered the database breach. The unauthorized entry gave the hacker access to an individual’s name and personal information, including Social Security numbers.

What we don’t know is whether the hacker was able to access any information,” Faust said.

A computer screen displayed the message “You have been hacked,” Faust said. “Since we don’t know one way or the other we sent notices out to 56,000 people that there’s a potential that the information was compromised.”

Although we have no indication that information was actually released, we know that it was accessed,” Tony Keck, DHH’s deputy secretary, said Wednesday.

Both the East Baton Rouge Parish Sheriff’s Office and the Louisiana Attorney General’s Office are investigating, Keck said.

Read more in 2theAdvocate. I’m a tad confused by what seem to be their conflicting statements as to whether the database was actually accessed.

On an unusual note, the state said notification to EMTs was delayed because the agency had to find the money to cover the cost of printing the letters and stamps.



I guess it pays to be an Obama backer...

http://www.pogowasright.org/?p=16489

FTC to Google re Wi-Fi data capture: case closed

October 27, 2010 by Dissent

The FTC has closed its investigation into the Google Street View wi-fi mess without levying any fines or penalties. A copy of the FTC’s letter to Google can be found here. It apparently helped Google that they announced a new Privacy Director and other changes in response to other countries’ investigation into the situation.


(Related) You know you have big legal problems when...

http://www.fastcompany.com/1698322/google-street-view-privacy-on-google-maps

A Google Map of Google Maps' Legal Troubles

Italian officials today launched a probe into Google, which has been accused of collecting mounds of personal information through unsecured Wi-Fi networks with its Street View cars.

This is just the latest in a long line of governments looking into the matter, from Australia to Germany to South Korea. We've found it increasingly difficult to keep track of all Google's privacy snafus. So here's a handy way to track international investigations into Google Maps: A Google Map mashup. Click on the pins for news about investigations or allegations in each location.



You have no right to be drunk, therefore you have no other rights either?

http://www.pogowasright.org/?p=16509

Refuse breath test? Not in Lafourche

October 28, 2010 by Dissent

Raymond Legendre reports:

Lafourche has become the second Louisiana parish to enforce a DWI “no-refusal” policy at all times.

Sheriff Craig Webre announced the action Tuesday.

The Sheriff’s Office experimented with the program three times this year in its ongoing effort to reduce drunk-driving deaths and remove drunk drivers from the parish’s roadways.

Starting yesterday, suspected drunk drivers in Lafourche no longer have the right to refuse a Breathalyzer test. Previously, drivers could refuse taking such a test but would be charged with DWI and have their licenses suspended for a year.

[...]

“Where in the Fourth Amendment does it say you can stop people and take their blood?” said Marjorie Esman, executive director of the Louisiana-branch of the American Civil Liberties Union. She raised questions about how long and where the blood would be kept.

Read more on HoumaToday.com

[From the article:

Previously, drivers could refuse taking such a test but would be charged with DWI and have their licenses suspended for a year. [How did that work? Were they convicted of “looking really drunk” or “refusing to be tested?” Bob]

… Under the no-refusal program, deputies can use probable cause to receive a signed search warrant from a district judge, forcing drivers who refuse a Breathalyzer test to submit to a breath, blood or urine test. Those drivers, who submit after initially refusing test, are still subject to the same penalties as people who refused the test. [Even if they test “sober?” Bob]



Gosh, his thinking evolved? Who'd a thunk it?

http://www.pogowasright.org/?p=16502

Article: The Puzzle of Brandeis, Privacy, and Speech

October 28, 2010 by Dissent

Neil Richards has an article, “The Puzzle of Brandeis, Privacy, and Speech” in the Vanderbilt Law Review (2010). Here’s the abstract:

Most courts and scholarship assume that privacy and free speech are always in conflict, even though each of these traditions can be traced back to writings by Louis D. Brandeis—his 1890 Harvard Law Review article The Right to Privacy and his 1927 concurrence in Whitney v. California. How can modern notions of privacy and speech be so fundamentally opposed if Brandeis played a major role in crafting both? And how, if at all, did Brandeis recognize or address these tensions? These questions have been neglected by scholars of First Amendment law, privacy, and Brandeis. In this Article, I argue that the puzzle of Brandeis’s views on privacy and speech can be resolved in a surprising and useful way.

My basic claim is that Brandeis’s mature views on privacy and its relationships to free speech were more complex and interesting than the simplistic tort theory of privacy he expounded in The Right to Privacy. As a young lawyer, Brandeis envisioned privacy as a tort action remedying emotional injury caused by the revelation of embarrassing private facts by the press. But Brandeis’s ideas evolved over his life. He soon came to believe strongly in a contrary idea he called “the duty of publicity.” This is the notion that disclosure of most kinds of fraud and wrongdoing are in the public interest; that as he famously put it, “sunlight is the best disinfectant.” When Brandeis came to think through First Amendment issues after the First World War, tort privacy could no longer consistently fit into his influential theories of civil liberty.

But while Brandeis changed his mind about tort privacy, what he replaced it with is even more interesting. In his Olmstead dissent and free speech writings, Brandeis identified a second conception of privacy that I call “intellectual privacy.” Brandeis reminds us that the generation of new ideas requires a certain measure of privacy to succeed, and that in this way intellectual privacy and free speech are mutually supportive. I conclude by suggesting some modern implications of Brandeis’s ambivalence about tort privacy and his linkage of intellectual privacy with free speech.

You can download the full article here (pdf). Hat-tip, Concurring Opinions



Is using the RIAA model the way to save the newspaper industry? New term: “pay-wall by threat

http://news.slashdot.org/story/10/10/27/2134236/Pay-Or-Else-News-Site-Threatens?from=rss

Pay Or Else, News Site Threatens

Posted by samzenpus on Wednesday October 27, @06:47PM

"The North Country Gazette, a news blog, says users who read beyond a single page of an article must pay up or they will be tracked down. They don't have a pay wall. If you go beyond page 1, you owe them. From the article: 'A subscription is required at North Country Gazette. We allow only one free read per visitor. We are currently gathering IPs and computer info on persistent intruders who refuse to buy subscription and are engaging in a theft of services. We have engaged an attorney who will be doing a bulk subpoena demand on each ISP involved, particularly Verizon Droids, Frontier and Road Runner, and will then pursue individual legal actions.'"



Push-back was inevitable.

http://it.slashdot.org/story/10/10/27/2257223/British-Airways-Chief-Slams-US-Security-Requests?from=rss

British Airways Chief Slams US Security Requests

Posted by samzenpus on Wednesday October 27, @09:56PM

"Reflecting a growing frustration among airport and airline owners with the steady build-up of rules covering everything from footwear to liquids, Martin Broughton, chairman of British Airways, has launched a scathing attack on the 'completely redundant' airport checks requested by the TSA and urged the UK to stop 'kowtowing' to American demands for ever more security. Speaking at the annual conference of the UK Airport Operators Association, Broughton lambasted the TSA for demanding that foreign airports increase checks on U.S.-bound planes, while not applying those regulations to their own domestic services. 'America does not do internally a lot of the things they demand that we do,' says Broughton. 'We shouldn't stand for that. We should say, "We'll only do things which we consider to be essential and that you Americans also consider essential.''' For example, Broughton noted that cutting-edge technology recently installed at airports can scan laptops inside hand luggage for explosives but despite this breakthrough the British government still demands computers be examined separately. 'It's just completely ridiculous,' says Broughton."


(Related) Might be interesting to see if they can produce any data on the “effectiveness” of all this security in detecting terrorists. (i.e. is it more effective at deterring terrorists than it is at keeping monsters at bay?)

http://www.pogowasright.org/?p=16495

Memphis pilot files lawsuit over airport body-scans

October 27, 2010 by Dissent

Michael Roberts, the pilot who refused to go through a full body scanner, is suing the TSA. Jamel Major reports:

A Mid-South pilot who refused a full-body scan at Memphis International Airport is suing the TSA. Michael Roberts and attorneys at the Rutherford Institute are suing the federal government over air passenger screening procedures.

“We’re basically challenging the constitutionality of the new policies under the 4th Amendment,” Roberts said Tuesday.

A pilot with ExpressJet Airlines, Roberts was in full uniform and trying to commute to his job in Houston when he refused to submit to a full body scan and pat down at Memphis International Airport.

Read more on WMCTV.



For my Ethical Hackers. Another case of children bypassing “security?” Probably not. This is speculation by the reporters, although it is based on long established techniques.

http://it.slashdot.org/story/10/10/28/0124242/Aussie-Kids-Foil-Finger-Scanner-With-Gummi-Bears?from=rss

Aussie Kids Foil Finger Scanner With Gummi Bears

Posted by samzenpus on Thursday October 28, @02:10AM

"An Australian high school has installed "secure" fingerprint scanners for roll call for senior students, which savvy kids may be able to circumvent with sweets from their lunch box. The system replaces the school's traditional sign-in system with biometric readers that require senior students to have their fingerprints read to verify attendance. The school principal says the system is better than swipe cards because it stops truant kids getting their mates to sign-in for them. But using the Gummi Bear attack, students can make replicas of their own fingerprints from gelatine, the ingredient in Gummi Bears, to forge a replica finger. The attack worked against a bunch of scanners that detect electrical charges within the human body, since gelatine has virtually the same capacitance as a finger's skin."

[From the ABC article:

Deputy principal Bob Cox says the school is hoping it will simplify the attendance system, but that students will still have the choice to opt out if parents take issue with it. “We can save money by implementing two systems rather than one!” Bob]

"The machine, which is unique to the school, [Bad reporting or a case of being the first to try a new system? Bob] plots three lines from those points and works out the angles and the length of the lines and assigns that particular logarithm to one student," he said.



“We're not sure what Cloud Computing means, but we are going to manage it.”

http://blogs.wsj.com/digits/2010/10/27/intel-technology-buyers-talk-of-freedom-in-the-cloud/?mod=google_news_blog

Intel, Technology Buyers Talk of Freedom in the Cloud

It’s hard to find a technology vendor who isn’t vociferously supporting the craze known as cloud computing. But some customers seem to be worried about the pace of progress, judging by comments from Intel and a large group of technology buyers.

The Open Data Center Alliance, whose formation was announced at a news conference Wednesday in San Francisco, seems partly inspired by the fear known as vendor lock-in.

… Skaugen estimated that $100 billion of potential IT spending is stalled because of customer concerns about vendor lock-in and other issues.

The Open Data Center Alliance says it plans to define technical requirements and recommendations to head off a logjam. Besides Terremark, members include Lockheed Martin, BMW, China Life, Deutsche Bank, JPMorgan Chase, Marriott International, Inc., National Australia Bank and Shell.



Implications for business in the Cloud?

http://it.slashdot.org/story/10/10/27/2138238/Google-Now-Second-Largest-ISP?from=rss

Google Now Second-Largest ISP

Posted by samzenpus on Wednesday October 27, @07:35PM

"Google is now the second-largest carrier of Internet traffic, accounting for 6.4% of all web traffic, according to data released this week by Arbor Networks. But should IT execs care? Yes, says Craig Labovitz, Arbor's chief scientist, who argues that IT managers need to understand how macro Internet traffic trends will affect the design and management of their own network backbones. 'This will affect how enterprises plan their services... whether they host their own services or whether they use cloud vendors,' Labovitz says. ' The enterprise needs to shift its thinking in terms of [service level agreements] and the way it measures, monitors and secures its networks. That all used to be focused on connectivity, but now it needs to be focused on content.'"

[From the article:

Increasingly, whether you’re a consumer or an enterprise, you care not about reaching thousands of different Web sites. You care about the 20 social networking, cloud vendor and partner sites that you do business with.”

The Arbor Networks’ data points to a future where Internet traffic consolidates on the networks of a handful of carriers and content providers – what Arbor calls “hyper giants.”

… The Arbor data shows that overall Internet volumes are increasing at a rate of 40% to 45% per year, and that Google is growing faster than that. Most of Google’s data is video from its popular YouTube site.


(Related) How content drives traffic? I wonder if she has made Google more money than her record label? Perhaps the RIAA should sue?

http://www.fastcompany.com/1698374/how-lady-gagas-billion-youtube-views-changes-the-music-industry

How Lady Gaga's One Billion YouTube Views Changes the Music Industry

metric more fully captures Lady Gaga's global superstardom: the 15 million albums she's sold to date, or the one billion views she reached this week on YouTube?

Though CDs are rapidly becoming a thing of the past, replaced by digital music, physical album sales still remain the gold standard for the industry. Isn't it time that metric is updated to include the wealth of ubiquitous digital platforms? "The notion of tracking sales and correlating that to success is a bit antiquated," says Vevo CEO Rio Caraeff. "There's no single indicator you can look at now--you must look at everything."



Perhaps we should ban them from political office until we find a cure? Or is that why they've been funding DNA databases?

http://science.slashdot.org/story/10/10/28/038252/Researchers-Find-a-Liberal-Gene?from=rss

Researchers Find a 'Liberal Gene'

Posted by samzenpus on Thursday October 28, @07:57AM

"Liberals may owe their political outlook partly to their genetic make-up, according to new research from the University of California, San Diego, and Harvard University. Ideology is affected not just by social factors, but also by a dopamine receptor gene called DRD4. The study's authors say this is the first research to identify a specific gene that predisposes people to certain political views."

Wednesday, October 27, 2010

This could be nothing. At least, they are not sure it is something. The servers were down over the weekend for “maintenance,” so this could be a problem introduced by those changes.

http://www.databreaches.net/?p=14937

TX: HISD investigating how its computers were hacked

October 27, 2010 by admin

Erika Mellon reports:

Houston school district officials suspect their computer system was hacked over the weekend, leaving employees and students without access to the Internet, online classes and e-mail for two days.

The electronic blackout ended late Tuesday afternoon, but the district’s police department was continuing to work with the FBI to investigate the suspected cyber-attack. HISD officials said they had found no evidence so far that hackers had tampered with personal information, such as payroll data or students’ grades.

As one of the largest employers in Houston, the school district has loads of electronic data on its 30,000 workers and 202,000 students that could have been compromised.

Read more in the Houston Chronicle.


(Related)

http://www.myfoxhouston.com/dpp/news/local/101026-fbi-investigates-alert-of-possible-hacking-attempt-into-hisd

FBI Investigates Alert of Possible Hacking Attempt into HISD

When the district was alerted to the possible hacking attempt, [They did not detect it themselves? Bob] the IT team shut down the computer system, according to a statement from HISD. Police and administrative staff were notified early Monday morning.



Interesting question. If they had not informed the victims, how would they learn of the breach? Should the laws be modified to allow the police to “fight fire with fire?”

http://www.databreaches.net/?p=14928

Did Dutch Police Break the Law Taking Down a Botnet?

October 26, 2010 by admin

Interesting article by Jeremy Kirk about how Dutch police may have broken the law in an attempt to get control of a botnet and to warn innocent users that their systems were infected:

Dutch police took unprecedented action in taking down a botnet on Monday: They uploaded their own program to infected computers around the world, a move that likely violated computer crime laws.

The program causes a computer’s Web browser to redirect to a special site set up by the Netherlands Police Agency, where users are informed their computer is infected with Bredolab, a password-stealing malicious software program.

Dutch police did that by taking command of 143 Web servers used to control computers infected with Bredolab. The servers belong to LeaseWeb, one of the top hosting providers in Europe, which was informed in August of the problem by police and other computer security experts, said Alex de Joode, LeaseWeb’s security officer.

Read more on PCWorld.

[From the ComputerWorld article:

The Armenian man had constructed a massive botnet, at one point infecting up to 29 million computers in countries including Italy, Spain, South Africa, the US and the UK.

"We wanted to take down the botnet," Prins said. "What we also wanted to do was make sure the botnet wouldn't switch over to other infrastructure under his control."

The Dutch police decided to use a tactic they have apparently used before, taking over the computers infected with Bredolab and directing them to servers not under the control of the Armenian. Fox IT helped with that by uploading a "good" bot developed by police [Are US computer cops also doing this? Bob] to those PCs, Prins said.

… So far, at least 100,000 computers have displayed the Web page, which also has a link where people can file a complaint about Bredolab. So far, 55 people have filled out the complaint form, according to the Dutch National Prosecutor's Office.

[From the PC World article:

The action by the Dutch police is likely a breach of the Computer Misuse Act, said Struan Robertson, a technology lawyer with Pinsent Masons. Since the territorial scope of the legislation is wide, in theory it could be used against somebody in the Netherlands hacking into a U.K. computer, he said.

"There is no defense in the Computer Misuse Act for unauthorized access to another computer being for noble purposes," Robertson said. " That said, I think it is important to note it is unthinkable that anyone would prosecute for this," Robertson said. "They were making the best of a bad situation."

But in an era where fake Web pages are rampant, it begs the question of whether people will believe that the warning is legitimate. Fraudsters could also simply copy the Web page, set up a new domain and create a site that actually infects people's computers with Bredolab or other malware.


(Related) The next botnet won't be as easily defeated.

http://www.securityweek.com/rise-small-botnet

The Rise of the Small Botnet

In September, law enforcement agencies in the US and Europe announced that they had cracked a major ZeuS botnet operation allegedly responsible for the theft of over $70 million.

Reports of such law enforcement crackdowns are increasingly common, but they represent merely the tip of the iceberg in addressing the real underlying problem. Botnets controlled by criminal enterprises all over the world continue to multiply at a steep rate, and it is now arguably the smaller, harder-to-trace operations that organizations should be the most worried about. Not only are smaller botnets cheaper and easier to build out and operate, but criminals have already realized that large-scale botnet activity attracts unwanted attention, and not just of law enforcement.



I vote “Hell Yes!”

http://www.phiprivacy.net/?p=4750

Should HHS fine entities who experience repeated avoidable security failures?

By Dissent, October 26, 2010

I’m working on a breach post for later today but started mulling over the question of whether HHS needs to start fining covered entities who have repeat breaches where the entity did not seem to adequately harden their security after the first breach or to really learn from experience.

This is 2010. The excuse “we were in the process of encrypting” or “now we’re going to encrypt” seems inadequate. HIPAA went into effect in 1996. Why are some of these easily avoidable breaches still occurring? HHS has adopted an educative and corrective approach, but how many times do some entities need to be educated before the government starts hitting them with fines in addition to the other costs of a breach?

Do you think that it would help if HHS started handing out fines to repeat offenders? If so, what scenarios would you think should lead to fines? I’d nominate inadequately secured PHI on a device stolen off-premises as my first nomination. As a close second, repeated theft of devices from hospital premises where the data at rest were not adequately protected.

Your thoughts?


(Related) Should this also go beyond lip service?

http://www.phiprivacy.net/?p=4741

Consent and privacy in HIT, redux

By Dissent, October 26, 2010

Julie Chang reported on a recent Texas Tribune interview with David Blumenthal, the national coordinator of Health Information Technology. Here’s the section dealing with privacy issues, and it follows on the heels of some great reporting by the Austin Bulldog, covered previously on this blog, that revealed how a lot of patient data is being sold for “research” purposes:

TT: The issue of privacy has been a hotbed of concern. There have been reports, even here in Texas, of patient electronic records being sold to research companies. How do you respond to concerns that electronic records will only increase the risk of violating patient privacy?

Blumenthal: Well, they shouldn’t be sold if people don’t give consent. We’re committed to having patients control the uses of their health data. Their consent is going to be vital.

Okay, stop right there. Isn’t that what some of us have been saying should be the requirement — consent — and not just “consent” but “informed consent?” And for our advocacy, we’ve been called privacy alarmists or just viewed as the enemy of progress.

TT: Whose responsibility is it to ensure that patient privacy is protected?

Blumenthal: It’s a collective responsibility. We, in the federal government, give our best judgment about what the preferred approach is to getting patient consent. I think we also need to enforce the existing laws that penalize people who don’t carefully guard patient information, and there are substantial penalties available. States have a responsibility because they have a lot of freedom to set local laws to make sure that they involve the public in creating those statutes and those regulations. Doctors and hospitals have to understand what patients want and need from them in the way of privacy in the electronic world.



Privacy is not his first strategic objective, but “Do no evil” is...

http://www.computerworld.com/s/article/9193178/5_comments_from_Google_s_CEO_on_privacy

5 comments from Google's CEO on privacy

On Monday, for instance, Schmidt raised the latest privacy hubbub by saying that if people don't like having their homes photographed for Google Street View for the world to see, they can "just move."

… The comment wasn't the first controversial remark Schmidt has made regarding privacy. Here are others:

  • "If you have something that you don't want anyone to know, maybe you shouldn't be doing it in the first place," Schmidt said during an interview on CNBC in December 2009.

  • "We know where you are... with your permission. We know where you've been with your permission. We can more or less guess what you're thinking about," he said earlier this month, speaking at the Washington Ideas Forum and cited by The Atlantic.

  • "There is what I call the creepy line. The Google policy on a lot of things is to get right up to the creepy line and not cross it," Schmidt is quoted as saying by The Hill Web site last month during an event at the Newseum in Washington.

  • "I actually think most people don't want Google to answer their questions," he said. "They want Google to tell them what they should be doing next," he said, adding that at some point young adults will change their names so they can hide from youthful hijinks stored on social networks. He made the comments during an August interview with the Wall Street Journal.

  • "In a world of asynchronous threats, it is too dangerous for there not to be some way to identify you. We need a [verified] name service for people. Governments will demand it," Schmidt said at the Techonomy conference in April, according to a ReadWriteWeb blog by Marshall Kirkpatrick.


(Related) Tip number one: ignore the boss?

http://www.makeuseof.com/dir/familysafetycenter-safe-internet-use-for-kids/

FamilySafetyCenter: Tips & resources on safe internet use for kids & family

FamilySafetyCenter is a portal put together by Google that contains lots of tips, answers, videos and articles to help provide a safe internet use for kids and family. In addition to a list of safety tools that are embedded in various Google services, the site has a detailed FAQ section on how Google handles various related issues.

www.google.com/familysafety



Humor A Venn diagram of Privacy and the Internet...

http://www.makeuseof.com/tech-fun/privacy-and-the-internet/



It's almost Halloween – think of this as sneaking up on your employees and yelling, “Boo!” (Assuming your employees have serious heart conditions...) Perhaps they learned about changing policies without notice from their favorite Internet sites?

http://www.pogowasright.org/?p=16466

Drug Testing Poses Quandary for Employers

October 27, 2010 by Dissent

Katie Zezima and Abby Goodnough report:

The news, delivered in a phone call, left Sue Bates aghast: she was losing her job of 22 years after testing positive for a legally prescribed drug.

Her employer, Dura Automotive Systems, had changed the policy at its sprawling plant here to test for certain prescription drugs as well as illicit ones. The medication that Mrs. Bates was taking for back pain — hydrocodone, a narcotic prescribed by her doctor — was among many that the company, which makes car parts, had suddenly deemed unsafe.

Read more in the New York Times. Hat-tip, Privacy Lives.



The future of Copyright Law? When do we implement ACTA? Would any US ISP resist government “recommendations?”

http://tech.slashdot.org/story/10/10/26/1926201/Korea-Kicking-People-Offline-With-One-Strike?from=rss

Korea Kicking People Offline With One Strike

Posted by CmdrTaco on Tuesday October 26, @04:15PM

"While there's lots of talk of 'three strikes' laws in places like France, it may be worth looking over at South Korea, which put in place a strict new copyright law, required by a 'free trade' agreement with the US (which was the basis for ACTA). It went into effect in the middle of 2009, and now there's some data about how the program is going. What's most troubling is that the Copyright Commission appears to be using its powers to 'recommend' ISPs suspend user accounts based on just one strike, with no notice and no warning. The system lets the Commission make recommendations, but in well over 99% of the cases, the ISPs follow the recommendations, and they've never refused to suspend a user's account."



Gee, it must be election time again. We always see reports of election machine flaws before the election and whoever win quickly suppresses any investigation that might reveal how he won...

http://news.slashdot.org/story/10/10/26/1428226/Voting-Machines-Selecting-Default-Candidates?from=rss

Voting Machines Selecting Default Candidates

Posted by CmdrTaco on Tuesday October 26, @10:47AM

"Some voters in Las Vegas have noticed that Democrat Harry Reid's name is checked by default on their electronic voting machines. By way of explanation, the Clark County Registrar says that when voters choose English instead of Spanish, Reid's Republican opponent, Sharron Angle, has her name checked by default."



Cable must move to the Internet or be replaced by Google?

http://www.wired.com/epicenter/2010/10/comcast-gives-tv-anywhere-another-nudge-in-the-right-direction/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

Comcast Gives ‘TV Anywhere’ Another Nudge in Right Direction

Fancast.com has programs from about 90 content partners, and Comcast customers also get access to the premium digital channels they pay. The array of programming is a smallish subset of 225 sources already available from Hulu, the web-based video service whose backers include NBC Universal, News Corp. (Fox) and Walt Disney (ABC), even though Hulu serves up much of the programming on Fancast. But unlike Hulu, Fancast includes programming from CBS.



Is this the business model that saves the publishing industry? Somehow, I doubt it.

http://news.slashdot.org/story/10/10/27/0048235/Free-E-Books-With-a-Catch-mdash-Advertising?from=rss

Free E-Books, With a Catch — Advertising

Posted by timothy on Tuesday October 26, @10:48PM

"Barnes & Noble may kick off a fresh price war today for digital book readers, with its new Nook news. But the real news in digital publishing is a novel approach to the e-books themselves: Free books — with advertising. The basic idea is to offer publishers another way to reach readers and to give readers the chance to try more books — books that perhaps they wouldn't normally peruse if they had to pay more for them. Initially, Wowio specialized in offering digital versions of comic books and graphic novels, usually formatted as Adobe PDFs. So it was a natural step for the company to offer graphic ads that are inserted in e-books. 'We think we're creating a broader audience for some of these titles,' Wowio's CEO Brian Altounian told me. 'I think folks are going to download more books because they're saving the costs' of having to drive to the store or pay more for them. Would ads stop you from reading?"

The new color Nook goes for $249, and comes with a browser, games, Quickoffice, streaming music via Pandora, and an SDK; reader itwbennett links to an analysis of how well it stacks up as a tablet.



Interesting. Nothing in the article to explain why a second device is required.

http://mobile.slashdot.org/story/10/10/27/015223/Some-Aussie-High-Schools-Moving-To-Two-Devices-Per-Child?from=rss

Some Aussie High Schools Moving To Two Devices Per Child

Posted by timothy on Wednesday October 27, @01:55AM

"One laptop per child is so last year. Private secondary schools in New South Wales, Australia are in discussions to upgrade their wireless networks so they can handle the strain of supporting a two-to-one ratio — a laptop and tablet for every student."

Tuesday, October 26, 2010

Not very encouraging...

http://www.databreaches.net/?p=14896

FinCEN report: Identity Theft Trends, Patterns, and Typologies Reported in Suspicious Activity Reports Filed by Depository Institutions January 1, 2003 – December 31, 2009

October 25, 2010 by admin

From the Financial Crimes Enforcement Network report, Identity Theft Trends, Patterns, and Typologies Reported in Suspicious Activity Reports Filed by Depository Institutions January 1, 2003 – December 31, 2009, the Executive Summary:

Identity theft was the sixth most frequently reported characterization of suspicious activity within the period of the study, behind structuring/money laundering, check fraud, mortgage loan fraud, credit card fraud, and counterfeit check fraud. Based upon analysis of the study sample, the number of identity theft-related depository institution SAR filings submitted during calendar year (CY) 2009 was 123 percent higher than the number reported in CY 2004. This compares with an 89 percent increase in the numbers of all depository institution SAR filings made in CY 2004 versus CY 2009.

… Victims reportedly discovered identity theft through review of their own account activity in about 28 percent of filings in the sample. Filers credited routine financial institution account monitoring with uncovering identity theft in nearly another 21 percent of sample filings, [So they missed it 79% of the time? Shame on them! Bob] and checks of commercial databases at account set-up in 14.5 percent of sample filings. Credit reports, law enforcement investigations, collection agencies, and credit monitoring services were responsible for revealing identity theft in a decreasing percentage of sample filings.



Keep an eye on this one...

http://www.pogowasright.org/?p=16376

White House Unveils Internet Privacy Committee

October 25, 2010 by Dissent

Elizabeth Montalbano reports:

The White House council on technology has formed a new subcommittee to develop principles that will attempt to balance the Internet’s economic opportunity with people’s right to privacy.

The National Science and Technology Council’s new Subcommittee on Privacy and Internet Policy also will aim to synchronize the practices of federal agencies with policy being considered and developed by lawmakers, according to a White House blog post unveiling the committee.

Read more on InformationWeek.



http://www.makeuseof.com/tag/download-unofficial-facebook-privacy-guide/

The (Very) Unofficial Facebook Privacy Guide [DOWNLOAD]

Like Facebook, but wish your information wasn’t so public? Time to lock your settings down. Facebook doesn’t make this easy, however; features are constantly added and the default for each new one seems to favor transparency instead of privacy.

The result: there are hundreds of little changes you need to make to truly control where your information goes.

Enter “The (Very) Unofficial Facebook Privacy Manual”. This handy guide outlines everything you could ever want to know about locking down your privacy on Facebook, and a few things you probably didn’t even know you wanted to know.

If you use Facebook you should read this guide, if only to understand how public most of your information is.

Download: The (Very) Unofficial Privacy Guide Or Read online at Scribd



Probably inevitable. They just haven't convinced a judge that “everyone is a terrorist” yet.

http://news.cnet.com/8301-31921_3-20020680-281.html?part=rss&subj=news&tag=2547-1_3-0-20

Amazon wins fight to keep customer records private

In a victory for the free speech and privacy rights of Amazon.com customers, a federal judge ruled today that the company would not have to turn over detailed records on nearly 50 million purchases to North Carolina tax collectors.

The state had demanded sensitive information including names and addresses of North Carolina customers--and information about exactly what they had purchased between 2003 and 2010.

U.S. District Judge Marsha Pechman in Washington state said that request went too far and "runs afoul of the First Amendment." She granted Amazon summary judgment.

The Tar Heel State's tax collectors have "no legitimate need" for details about the literary, music, and film habits of so many Amazon customers," Pechman wrote. "In spite of this, (North Carolina) refuses to give up the detailed information about Amazon's customers' purchases, while at the same time requesting the identities of the customers and, arguably, detailed records of their purchases, including the expressive content."

Amazon has provided the state tax collectors with anonymized information about which items were shipped to which ZIP codes. But North Carolina threatened to sue if the retailer did not agree to divulge the names and addresses linked to each order--in other words, by providing personally identifiable information that could be used to collect additional use taxes that might be owed by state residents.

Pechman's opinion did leave open the possibility of North Carolina tax collectors deleting the data they currently have and firing off a narrower request to the online retailer: "Issuing the declaratory relief as phrased does not prohibit (N.C. tax collectors) from issuing a new request for information as to only the names and addresses of Amazon's customers and general product information, assuming that (the state) destroys any detailed information that it currently possesses."



For my Ethical Hackers and Computer Forensic students

http://www.wired.com/threatlevel/2010/10/iphone-snoop/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

Secret Button Sequence Bypasses iPhone Security

A security flaw in the iPhone allows strangers to bypass the handset’s lock screen with a few button presses.

In the video below, a Brazilian iPhone customer demonstrates the quick method to circumvent an iPhone’s passcode-protected lock screen: tap the “Emergency call” button, then enter three pound signs, hit the green call button and immediately press the lock button. That simple procedure gives a snoop full access to the Phone app on the iPhone, which contains the address book, voicemail and call history.



Good surveillance?

http://www.technologyreview.com/communications/26524/

Improving Phones through Surveillance

A cell-phone application that logs everything the phone's user does--from sending e-mail to playing games--may not sound so desirable. But researchers are deploying the software to see if they can determine the best ways to improve the battery life of phones and uncover network dead spots.

… "By studying how people use [the phones], we can find ways to match devices and networks to people."



For my Computer Security students

http://developers.slashdot.org/story/10/10/25/2134247/New-Programming-Language-Weaves-Security-Into-Code?from=rss

New Programming Language Weaves Security Into Code

Posted by Soulskill on Monday October 25, @05:47PM

"Until now, computer security has been reactive. 'Our defenses improve only after they have been successfully penetrated,' says security expert Fred Schneider. But now Dr. Dobb's reports that researchers at Cornell are developing a programming platform called 'Fabric,' an extension to the Java language that builds security into a program as it is written. Fabric is designed to create secure systems for distributed computing, where many interconnected nodes — not all of them necessarily trustworthy — are involved, as in systems that move money around or maintain medical records. Everything in Fabric is an 'object' labeled with a set of policies on how and by whom data can be accessed and what operations can be performed on it. Even blocks of program code have built-in policies about when and where they can be run. The compiler enforces the security policies and will not allow the programmer to write insecure code (PDF). The initial release of Fabric is now available at the Cornell website."



One University in Denver has already done this. Student reaction is mixed. The next step would be to require students to find their own information on the Internet and ignore a structured textbook entirely.

http://news.slashdot.org/story/10/10/25/1838201/Colleges-May-Start-Forcing-Switch-To-eTextbooks?from=rss

Colleges May Start Forcing Switch To eTextbooks

Posted by Soulskill on Monday October 25, @03:41PM

"Here's the new approach under consideration by college leaders and textbook manufacturers: 'Colleges require students to pay a course-materials fee, which would be used to buy e-books for all of them (whatever text the professor recommends, just as in the old model).' That may be 'the best way to control skyrocketing costs and may actually save the textbook industry from digital piracy,' proponents claim."



For my Math students... One of my recommended sites just got easier to search.

http://www.freetech4teachers.com/2010/10/khan-instant-instant-search-for-khan.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+freetech4teachers%2FcGEY+%28Free+Technology+for+Teachers%29

Monday, October 25, 2010

Khan Instant - Instant Search for Khan Academy

Khan Academy is famous for the fantastic educational videos produced by Salman Khan. Khan's mathematics and science videos are available on YouTube, on iTunes, and on Khan Academy.org. This morning I discovered Khan Instant. Khan Instant is an instant search engine (like Google or YouTube instant) for Khan Academy videos. Just to clarify, Khan Instant was developed by Ben Jacobson not by Khan Academy.

Applications for Education

Khan Instant could be a good tool for quickly locating outstanding mathematics and science videos to supplement your classroom instructions. Searching with Khan Instant is much faster than trying to browse through the YouTube channel for the video that meets your needs.



For all my students.

http://www.makeuseof.com/tag/notes-annotate-pdfs-easy-jarnal-crossplatform/

Take Notes & Annotate PDFs The Easy Way With Jarnal [Cross-Platform]

I thought that college students get heavy discounts on commercial software but I just recently found out that students can get commercial software completely free (including Visual Studio, Expression Encoder, etc), which is a nice perk. However, the perks of being a student don’t end there as there are actually quite a few student-friendly applications, which may even be useful to wider audiences and not just students.

You can use Delicious to organize your student life, Evernote to help you reduce your paper clutter and more! Evernote, in particular, can definitely be considered a giant when it comes to the many platforms it has apps for and how versatile it is.

Jarnal is also a great note-taking application that can run in Windows, Mac and Linux and deserves a mention, without a doubt, for its extensive features.

Getting Jarnal

Jarnal is an open-source note-taking and sketching application that you can run without installing it [i.e. from your thumb drive Bob] (as the program is bundled in a zipped file), but there are also installable versions for Windows and Mac on the official wiki and SourceForge page.



A tool for serious researchers.

http://www.makeuseof.com/tag/touchgraph-visual-search-similar-results/

TouchGraph: Visual Search for “Similar” Results

We have already mentioned some tools and tricks to help you search without words: we have listed some Google search tricks that allow you to find something when you really don’t know what you are looking for. We have also seen some image search tools that search by color and / or similarity (instead of words).

Today we are looking at another alternative way to do a visual search – Touch Graph which is based on Google’s RELATED: search operator.

… How it really works is a mystery but the general (educated and proved by tests) theory is that it is based on two main factors:

  1. Co-citation: if two pages have similar backlinks, they are related. It means that if several pages all cite and link to pages A and B, the latter are considered to be “similar”.

  2. Thematic relevance: it seems like Google has also started to apply some thematic relevance when it comes to filtering pages with common backlinks.

Monday, October 25, 2010

As the bad guys adopt technology, what else would you expect?

http://web.docuticker.com/go/docubase/61422

Information Theft At Global Companies Surpasses All Other Forms of Fraud for First Time

Theft of information and electronic data at global companies has overtaken physical theft for the first time, according to the latest edition of the Kroll Annual Global Fraud Report. This year’s study shows that the amount lost by businesses to fraud rose from $1.4m to $1.7m per billion dollars of sales in the past 12 months – an increase of more than 20%. The findings are the result of a study commissioned by Kroll with the Economist Intelligence Unit of more than 800 senior executives worldwide.

… According to the 2010 survey, 88% of companies said they had been the victim of at least one type of fraud during the past year. Of the specific countries analyzed, China is the top market in which companies suffered fraud with 98% of businesses operating there affected. Colombia ranked second with a 94% incidence of fraud in 2010, followed by Brazil with 90%.

http://www.kroll.com/library/fraud/FraudReport_English-US_Oct10.pdf



Poor Google.

http://www.pogowasright.org/?p=16358

Google Target of Misdirected Privacy Backlash

October 24, 2010 by Dissent

Tony Bradley follows up on the ICO’s announcement that it will be looking into the Google Wi-Fi situation again by pointing out that Google is being blamed for the security and privacy failures of individuals and businesses who fail to use even minimal security on their systems:

Many of the privacy concerns, however, are not really a function of Google. Google is simply the high-profile messenger making communities and users aware of just how exposed they are. It is part of a common and growing privacy backlash trend that misdirects blame at third-party organizations rather than taking personal responsibility.

Did Google collect Wi-Fi data–including sensitive information like usernames and passwords? Yes. It has admitted as much. But, Google didn’t do anything wrong to get that data. It’s more like someone gave Google a $20 bill, then turned around and accused Google of theft.

[...]

The issue isn’t that Google invaded anyone’s privacy by gathering and retaining the Wi-Fi data. The issue is that many businesses and homes are like the man in the park with his zipper down–operating insecure wireless networks that are constantly transmitting these types of sensitive data for anyone to intercept.

Even if the woman taking the pictures truly is a perverted stalker and had intent to capture the inappropriate photos, prosecuting her won’t change the fact that the guy is still walking around the park with his zipper down.

Read more on PC World.



Why not treat people as idiots? It usually works. (If you argue with Big Brother, you may get your own dedicated camera...)

http://www.pogowasright.org/?p=16367

UK: ‘Spy’ camera police ‘treated people like idiots’

October 24, 2010 by Dissent

More on the surveillance controversy in Birmingham.

Caroline Gall reports:

West Midlands Police “treated people like idiots” over the way more than 200 surveillance cameras were installed in parts of Birmingham with large Muslim populations, an MP has said.

The cameras – covert and overt – were put up earlier this year and were paid for with £3m of government money put aside for tackling terrorism.

But the communities were in uproar after they were not consulted, prompting the force to apologise and instigate an independent review of what happened.

The findings were highly critical, saying the force paid little attention to “compliance with the legal or regulatory framework” and relations between the Muslim community and police had been set back 10 years.

[...]

Liberty has now threatened legal action against the force if it refuses to agree to remove all the cameras in the next two weeks.

West Midlands Police Chief Constable Chris Sims has said previously all the covert cameras have been removed and the remainder covered with bags until a final decision was made.

Read more on BBC. In related coverage, BBC reports that the West Midland police will be responding to the recent report at a meeting later.

[From the article:

"They made a conscious decision of 'we won't lie, we will put into the public domain what we want to and we will wait and see if people ask questions'."



I think I'll still have my Ethical Hackers write their own version...

http://techcrunch.com/2010/10/24/firesheep-in-wolves-clothing-app-lets-you-hack-into-twitter-facebook-accounts-easily/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

Firesheep In Wolves’ Clothing: Extension Lets You Hack Into Twitter, Facebook Accounts Easily

It seems like every time Facebook amends its privacy policy, the web is up in arms. The truth is, Facebook’s well publicized privacy fight is nothing compared to the vulnerability of all unsecured HTTP sites — that includes Facebook, Twitter and many of the web’s most popular destinations.

Developer Eric Butler has exposed the soft underbelly of the web with his new Firefox extension, Firesheep, which will let you essentially eavesdrop on any open Wi-Fi network and capture users’ cookies.

As Butler explains in his post, “As soon as anyone on the network visits an insecure website known to Firesheep, their name and photo will be displayed” in the window. All you have to do is double click on their name and open sesame, you will be able to log into that user’s site with their credentials.

… This is how it works. If a site is not secure, it keeps track of you through a cookie (more formally referenced as a session) which contains identifying information for that website. The tool effectively grabs these cookies and lets you masquerade as the user.

Apparently many social network sites are not secured, beyond the big two, Foursquare, Gowalla are also vulnerable. Moreover, to give you a sense of Firesheep’s scope, the extension is built to identify cookies from Amazon.com, Basecamp, bit.ly, Cisco, CNET, Dropbox, Enom, Evernote, Facebook, Flickr, Github, Google, HackerNews, Harvest, Windows Live, NY Times, Pivotal Tracker, Slicehost, tumblr, Twitter, WordPress, Yahoo, Yelp. And that’s just the default setting— anyone can write their own plugins, according to the post.


(Related) Didn't everyone already know this?

http://techcrunch.com/2010/10/25/firesheep/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

How To Protect Your Login Information From Firesheep

… Firesheep banks on the fact that most social sites default to the HTTP protocol because it’s quicker. The already existing Firefox extension Force-TLS attempts to circumvent this by forcing those sites to use the HTTPS protocol, therefore making user cookies invisible to Firesheep.

Like the alternative option HTTP Everywhere, the Force-TLS Firefox extension allows your browser to change HTTP to HTTPS on sites that you indicate in the Firefox Add On “Preferences” menu, protecting your login information and ensuring a secure connection when you access social sites.



For my students – PLEASE!

http://www.makeuseof.com/dir/read-able-readability-of-text/

Read-Able: Check Readability Of Text Online

The Readability Test Tool is a web based service that lets you quickly test the readability of an entire webpage, a part of it or a sample of text. You can conduct the test by entering the URL of the page, inputting text directly or by linking to the tool from your webpage. It scores the text on various readability indicators like Flesch Kincaid Reading Ease, Flesch Kincaid Grade Level, Gunning Fog Score, Coleman Liau Index and Automated Readability Index (ARI).

www.read-able.com

Check out related article: 8 Readability Web Tools to Test Your Writing Quality.



GE provides this nifty online drawing tool...

http://imaginationcubed.com/

Sunday, October 24, 2010

Strange that when they are the target, teachers sound remarkably like their students. I also hear, “Yes we know it's a public forum, but we still want privacy”

http://www.pogowasright.org/?p=16340

Manatee teachers union fights website rules

October 24, 2010 by Dissent

I tend to think that having clearly stated employee policies concerning social media use is a good thing. But can such policies go too far and step on privacy or free speech rights? A teachers’ association in Florida is claiming that that’s one such policy does. Christopher O’Donnell reports:

A local teachers union is taking on the Manatee School District over its plan to restrict how teachers use the Internet and social networking sites like Facebook in their personal time.

Manatee Education Association leaders this week filed a complaint with the state asking it to rule against the proposed policy.

They are also threatening to sue the district in civil court if the policy is enacted, arguing that the rules violate a teacher’s right to privacy and free speech.

The proposed policy prohibits teachers from communicating with students through sites like Facebook or with personal e-mail without parental permission, and from using the school district’s name in online forums.

Union leaders object to a section that prohibits teachers from posting pictures or comments that cast the district, teachers or students in a negative light even if done on their own computer in their own time.

Read more in the Herald Tribune.

[From the article:

The new policy comes in the wake of a pair of cases in which teachers got in trouble for their use of the Internet.

Earlier this year, a teacher received a five-day unpaid suspension for posting on Facebook that he hated his job and hated the students he taught.

On Monday, the School Board is scheduled to vote on whether to move forward with firing Braden River High School teacher Charles Willis for inappropriate communication with more than 100 students on Facebook.



Technology provides the means... “We can, therefore we must”

http://techcrunch.com/2010/10/23/privacy-scandal-social-feds-spying/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

The Real Privacy Scandal On Social Networks: The Feds Are Spying On Their “Friends”

All the hoopla over the Wall Street Journal’s so-called Facebook “privacy breach” article, it’s subsequent and curiously-timed MySpace followup, and also the New York Times’ take on the ability of Facebook advertisers to target ads for nursing schools to gay men is unwittingly creating cover for a social networking privacy issue that’s much bigger. It might be surprising to some, but it turns out that U.S. federal agents have been urged to “friend” people in order to spy on them.

The feds operate such social sting operations aided by the fact that there are very few individuals that actually know every single person in their “friend” list on Facebook. For instance, it is typical to connect to someone because one thinks they might have met them. Or, a connection might take place because two people share common interests and want to view each other’s news posts going forward. But that’s not how the government sees it.

In a memo obtained through the Freedom of Information Act, the Electronic Frontier Foundation (EFF) discovered that the Feds see Facebook as a psychological crutch for the needy. Here’s a direct quote from a U.S. Citizenship and Immigration Services (USCIS) memo: “Narcissistic tendencies in many people fuels a need to have a large group of “friends” link to their pages and many of these people accept cyber-friends that they don’t even know.” And it gets worse.

The memo explains that these “tendencies” provide “an excellent vantage point for FDNS to observe the daily life of beneficiaries and petitioners who are suspected of fraudulent activities.” Translation: spy on unsuspecting people on Facebook and MySpace in order to catch the bad guys.

Such tactics are decidedly creepy (how many completely innocent people are they spying on), but the argument could be made that if you have nothing to hide, then why worry? Here’s why: many people post items to their profiles that they forget to update or that are not necessarily true, and which they certainly wouldn’t be saying if they knew they were under investigation. Indeed, a recent study initiated by UK insurance company Direct Line concluded that “people are more likely to be dishonest when chatting using technology, such as Twitter, than they would be face to face.”


(Related) Just because a particular technology isn't part of your IT plan (or budget) does not stop Senior Managers (or Officials) from using it.

http://web.docuticker.com/go/docubase/61416

Friends, Followers, and Feeds: A National Survey of Social Media Use in State Government

The survey examined adoption trends, current applications and expectations of social media technologies, the extent to which implementation is governed by formal policies or individual agency initiative, and perceptions of risk associated with social media tool use.

[From the report:

Just as in that earlier time when many state IT departments suddenly found they had rogue servers put up by agencies independent of any oversight or standards, state CIOs may recently have found themselves unblocking YouTube to allow greetings from public officials or Flickr to mount photos of a bridge opening or to document some other important announcement. CIOs may not have been immediately convinced of the business value of these tools as they entered the workplace, but the fact is that this is how effective governments are communicating now, and this is not just a fad.

… The results of the social media survey reflect the following key points:

social media adoption rates are broad across state governments, whether controlled by CIO offices or not

two-thirds of survey respondents lack enterprise policies addressing social media

one-third of the states responding do have enterprise policy frameworks, guidance, and standards, and a sizable number of states are in the process of developing these – models do exist

business drivers have most commonly been communications, citizen engagement, and outreach, along with low-cost of entry – 98% of use is of free social media tools

social media pose challenges to states in the areas of

security

legal issues associated with terms of service

privacy

records management

acceptable use



The views of a lawyer on the inside...

http://www.pogowasright.org/?p=16324

Harvey Levin on media and privacy

October 23, 2010 by Dissent

I’ve occasionally blogged about celebrities, the media, and right to privacy. I came across an interesting talk that Harvey Levin of TMZ gave to students at the University of Chicago Law School this week on media and privacy. It’s a very human talk that deals with ethics of the media, the “yuck factor,” “zones of privacy,” and includes a number of cases the show’s been involved in and how they made particular decisions about what to reveal or not to reveal. He also talks about how in one case, a sheriff got warrants to search his cell phones after they revealed a report on Mel Gibson and how chilling that can be for journalists.

I’m not a regular viewer of TMZ at all, but found the talk both entertaining and also thought-provoking. See what you think:

[Or watch on YouTube:

http://www.youtube.com/watch?v=SKv52hnXXFQ&feature=player_embedded#!



So Saddam wasn't lying, just exaggerating?

http://www.wired.com/dangerroom/2010/10/wikileaks-show-wmd-hunt-continued-in-iraq-with-surprising-results/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

WikiLeaks Show WMD Hunt Continued in Iraq – With Surprising Results

By late 2003, even the Bush White House’s staunchest defenders were starting to give up on the idea that there were weapons of mass destruction in Iraq.

But for years afterward, WikiLeaks’ newly-released Iraq war documents reveal, U.S. troops continued to find chemical weapons labs, encounter insurgent specialists in toxins, and uncover weapons of mass destruction.

An initial glance at the WikiLeaks war logs doesn’t reveal evidence of some massive WMD program by the Saddam Hussein regime — the Bush administration’s most (in)famous rationale for invading Iraq. But chemical weapons, especially, did not vanish from the Iraqi battlefield. Remnants of Saddam’s toxic arsenal, largely destroyed after the Gulf War, remained. Jihadists, insurgents and foreign (possibly Iranian) agitators turned to these stockpiles during the Iraq conflict — and may have brewed up their own deadly agents.



Eventually, an online “Library of the Internet?”

http://www.killerstartups.com/Search/neotake-com-a-quick-way-to-find-ebooks

Neotake.com - A Quick Way To Find eBooks

Neotake is a search engine for eBooks. The site will let you look up books in any language, and in formats as different as PDF, Mobipocket, ePUB and Kindle. And once you have found what you are looking for, you will be able to get it right away.

One of the most solid aspects of the site is that users are not anonymous. Far from it - they make up a true community. Each user has got his own profile, complete with his own avatar. They can see what each other has searched, and they can even begin following each other and be notified about the latest activity of those who are always finding good (and unusual) titles.

In any case, the site includes a series of “Top 100 eBooks” that will let you know what has been in more demand in the last week, the last month and even the day before. Not knowing what to download is a situation you are not facing if you use this site, and that’s a fact.

http://www.neotake.com/



Collaboration tools

http://www.makeuseof.com/dir/livedocuments-free-office-suite-online/

Live-Documents: Free Office Suite Online

Live Documents is a free office suite online that provides online document editing collaboration features. After you have created an account on the site you can start creating presentations, spreadsheets, and text documents.

The interface for each type of document all loads up within the web browser. You will find that the most commonly used and most popular features are available in all the interfaces. The text document interface, for instance, includes languages, different fonts, formats and styles, text alignment, and paragraph properties. When you are done with your document you can save it and share it using the buttons located in the top right.

Sharing is possible either with specific Live Documents members or with everyone on the web by sharing the document’s URL. You can specify whether others will be able to edit the document or only view it.

Users of Live Documents get 100 MB of storage space and access to their documents in a wonderfully organized web interface that resembles an operating system.

www.live-documents.com

Related articles:

6 Free Office Suites That Are NOT Microsoft

Top 3 FREE web-based Office Suites (Word, Excel, PowerPoint, etc.)