Thursday, September 27, 2012

Because this has the potential to impact US infrastructure, shouldn't this be investigated as a potential act of war? At least preparation for a terrorist attack. (Or just to avoid me telling the world, “I told you so!”)
Maker of Smart-Grid Control Software Hacked
The maker of an industrial control system designed to be used with so-called smart grid networks disclosed to customers last week that hackers had breached its network and accessed project files related to a control system used in portions of the electrical grid.
Telvent, which is owned by Schneider Electric, told customers in a letter that on Sept. 10 it learned of the breach into its network. The attackers installed malicious software on the network and also accessed project files for its OASyS SCADA system, according to KrebsOnSecurity, which first reported the breach.
According to Telvent, its OASyS DNA system is designed to integrate a utility’s corporate network with the network of control systems that manage the distribution of electricity and to allow legacy systems and applications to communicate with new smart grid technologies. [And vice versa? Bob]
… The breach raises concerns that hackers could embed malware in project files to infect the machines of program developers or other key people involved in a project. One of the ways that Stuxnet spread — the worm that was designed to target Iran’s uranium enrichment program — was to infect project files in an industrial control system made by Siemens, with the aim of passing the malware to the computers of developers.
Peterson says this would also be a good way to infect customers, since vendors pass project files to customers and have full rights to modify anything in a customer’s system through the project files.

(Related) I think...
September 26, 2012
US: CFIUS Review
US: CFIUS Review - Robert Schlossberg and Christine Laciak, Freshfields Bruckhaus Deringer US LLP
  • "The national security review process in the United States – often referred to as the Exon–Florio or CFIUS review process, after the relevant authorising statute and enforcement agency, respectively – has existed for decades. It originally focused, at least in practice, on the acquisition by foreign companies of US businesses directly or indirectly supplying the US Department of Defense, but especially after the 9/11 terrorist attacks, the concept of national security – and therefore the types of transactions subject to review under the regime – was broadened by statute and in practice. Today, the national security review process can be an important part of many transactions, even though it remains voluntary. Examples of industries in which notifications have been made include computers, network security, cyber systems, energy (development and transport), semiconductors, aerospace, telecommunications, optics, robotics, mining and natural resources, plastics and rubber, automotive, financial services, coatings and adhesives, chemicals, and steel."


Because everyone needs a “Personal Surveillance Tool” I think a helicopter would be most useful, since I could mount a shotgun for hunting and then swoop down to retrieve my kill. Duck soup anyone?
Everyone Who Wants a Drone Will Have One Soon
… Drones are not like the atomic bomb. There won't be a day when suddenly we realize that a horrible new weapon has changed the world forever. Instead, one day we'll wake up and there'll have been a terrorist attack by a swarm of drones launched by hand from a park across the Potomac from Washington, DC, and no one will know where they came from or who sent them. We'll wake up one day to a drone peering in our window as preparation for a common burglary.
The price of these unmanned aerial vehicles is plummeting from two sides. On the one hand, you've got the toys like the $70 iHelicopter you control with an iPhone. This little guy even has two plastic missiles you can fire!
There are already pretty good surveillance drones, too. Like this $300 Parrot AR.Drone.2.0, which can shoot HD video. You control it with an iPad.


Does this automatically make him a drone target?
"The U.S. military has designated Julian Assange and WikiLeaks as enemies of the United States — the same legal category as the al-Qaeda terrorist network and the Taliban insurgency. Declassified US Air Force counter-intelligence documents, released under US freedom-of-information laws, reveal that military personnel who contact WikiLeaks or WikiLeaks supporters may be at risk of being charged with 'communicating with the enemy.'"


How they do it?
September 26, 2012
EFF: Facebook and Datalogix - What's Actually Getting Shared and How You Can Opt Out
EFF: "We’ve been seeing a range of reports about Facebook partnering up with marketing company Datalogix to assess whether users go to stores in the physical world and buy the products they saw in Facebook advertisements. A lot of the reports aren’t getting into the nitty gritty of what data is actually shared between Facebook and Datalogix, so the goal of this blog post is to dive into the details. We’re glad to see that Facebook is taking a number of steps to avoid sharing sensitive data with Datalogix, but users who are uncomfortable with the program should opt out (directions). Hopefully, reporting on this issue will make more people aware of how our shopping data is being used for a lot more than offering us discounts on tomato soup. Datalogix is an advertising metrics company that describes its data set as including “almost every U.S. household and more than $1 trillion in consumer transactions.” It specifically relies on loyalty card data – cards anyone can get by filling out a form at a participating grocery store."


“Oops, we're sorry (for getting caught).”
"In the latest installment of the megaupload saga, an official study has determined that New Zealand's Government Communications and Security Bureau broke NZ law by spying on Megaupload founder Kim Dotcom. NZ Prime Minister John Key has apologised to Dotcom and all New Zealanders for this, saying they were entitled to be protected by the law but it had failed them. Link is to writeup in The Guardian."
Lots of outlets are reporting this, based on TorrentFreak's report.
[From the article:
The illegal surveillance may deal another blow to the US extradition case after a New Zealand court ruled in June that search warrants used in the raid on Dotcom's home were illegal.
… Dotcom maintains that the Megaupload site was merely an online storage facility, and has accused Hollywood of lobbying the US government to prosecute him.
American authorities are appealing against a New Zealand court decision that Dotcom should be allowed to see the evidence on which the extradition hearing will be based.


This is what happens when entry-level employees are in charge...
Microsoft is facing the unpleasant end of the European Commission antitrust blunderbuss, with the company now in line for a potentially huge fine over browser choice missteps. The EC confirmed it was investigating the software firm back in July, after an agreed-upon browser choice page failed to be shown to 28m PC users; now, Reuters reports, the EC will open a formal proceeding that will decide the extent of the penalty.


Perspective Remember, the US is around #39 on the list of Internet connection speeds. It's going to be hard to compete if we don't jump ahead a few generations of technology.
"Sorry, everybody: terabit Ethernet looks like it will have to wait a while longer. The IEEE 802.3 Industry Connections Higher Speed Ethernet Consensus group met this week in Geneva, Switzerland, with attendees concluding—almost to a man—that 400 Gbits/s should be the next step in the evolution of Ethernet. A straw poll at its conclusion found that 61 of the 62 attendees that voted supported 400 Gbits/s as the basis for the near term 'call for interest,' or CFI. The bandwidth call to arms was sounded by a July report by the IEEE, which concluded that, if current trends continue, networks will need to support capacity requirements of 1 terabit per second in 2015 and 10 terabits per second by 2020. In 2015 there will be nearly 15 billion fixed and mobile-networked devices and machine-to-machine connections."

(Related) Virtual networks for virtual servers. Tools for the Cloud...
Ex-Amazon Genius Joins Battle for the Future of Networking
Giuseppe de Candia is the first name listed on a document that remade the internet. And now he wants to remake it all over again.
Known as “Pino” among friends and colleagues, de Candia was part of a small team of computer scientists at Amazon.com who created Dynamo, a means of storing vast amounts of data across a sea of computer servers. The team originally built Dynamo to power the Amazon shopping cart, but after publishing a research paper describing the technology in 2007, they helped spawn a new breed of database that was soon running many of the net’s largest sites, including Facebook, Twitter, Netflix, and Reddit.
Together with a handful of engineers at Google — who published a paper on an equally massive database called BigTable — de Candia is one of the founding fathers of the NoSQL movement, whose influence now extends well beyond the big-name websites, stretching into the data center that underpin all sorts of businesses.
“If you look at every NoSQL solution out there, everyone goes back to the Amazon Dynamo paper or the Google BigTable paper,” says Jason Hoffman, the chief technology officer at the San Francisco-based cloud computing outfit Joyent. “What would the world be like if no one at Google or Amazon ever wrote an academic paper?”


A tool is just a tool. I have no further comment (I'm too busy with extensive testing)
"The company behind the .xxx top-level domain plans to launch a search engine in an effort to drive more traffic to .xxx websites and give pornography fans a more satisfying search experience. ICM Registry, which operates the 9-month-old .xxx TLD, is scheduled to launch Search.xxx this week, said Stuart Lawley, ICM's CEO. The new search engine will give users a more streamlined searching process, help protect them from viruses and malware and help guard their privacy, he said. The search engine has cataloged 21 million webpages from .xxx sites, he said. ' It's porn, only porn, all porn,' he said. 'There's as much porn there as anyone would need, I'd imagine.'"


A 'heads up!' for your Help Desk... LibreOffice is free
"Google today announced a huge change for Google Apps, including its Business, Education, and Government editions. As of October 1, users will no longer have the ability to download documents, spreadsheets, and presentations in old Microsoft Office formats (.doc, .xls, .ppt)."
The perils of cloud computing; LibreOffice will probably be the best conversion utility at that point. Apropos: Reader akumpf writes with an essay about the dangers of letting our data and our tools be hosted by the same provider.


Perspective Perhaps driving is not stimulating enough without Texting? My Math classes need to be augmented with “Angry Birds” and “Bad Piggies?”
"Doug Gross writes that thanks to technology, there's been a recent sea change in how people today kill time. 'Those dog-eared magazines in your doctor's office are going unread. Your fellow customers in line at the deli counter are being ignored. And simply gazing around at one's surroundings? Forget about it.' With their games, music, videos, social media and texting, smartphones 'superstimulate,' a desire humans have to play when things get dull, says anthropologist Christopher Lynn and he believes that modern society may be making that desire even stronger. 'When you're habituated to constant stimulation, when you lack it, you sort of don't know what to do with yourself ...,' says Lynn. 'When we aren't used to having down time, it results in anxiety. Oh my god, I should be doing something.' And we reach for the smartphone. It's our omnipresent relief from that.' Researchers say this all makes sense. Fiddling with our phones, they say, addresses a basic human need to cure boredom by any means necessary. But they also fear that by filling almost every second of down time by peering at our phones we are missing out on the creative and potentially rewarding ways we've dealt with boredom in days past. 'Informational overload from all quarters means that there can often be very little time for personal thought, reflection, or even just 'zoning out,'" researchers write. 'With a mobile (phone) that is constantly switched on and a plethora of entertainments available to distract the naked eye, it is understandable that some people find it difficult to actually get bored in that particular fidgety, introspective kind of way.'"

(Related)
Bad Piggies Is A Hit, Taking Just 3 Hours To Hit The Top Spot In The U.S. App Store

(Related)


For my Geeks...
… By heading to the Try Office Preview website you can download the software to your computer.
… After clicking Try and selecting your country, you’ll be prompted to sign in. I nstallation will require you to have a Microsoft account – namely, one ending in @msn.com, @live.com or @hotmail.com (local variants such as .co.uk are also included). If you don’t have a Microsoft account, click the Sign up button and follow the steps to set one up.
… Microsoft Office 2013 Preview is a good upgrade to the previous releases, ideal for use on either a Windows 7 or a Windows 8 computer. The installation procedure is frustratingly streamlined, however, resulting in an inability to specify your preferred installation location. Similarly, removing the software relies on an Internet connection to deactivate. Given that Windows 8 also features an online activation and heavy use of the cloud, it is likely that this arrangement is here to stay.

Wednesday, September 26, 2012

You don't have to do anything to be a target. And there is nothing you can do to avoid being a target.
Wells Fargo is latest bank to be hit by cyberattacks
Wells Fargo is the most recent mega-bank to be hit by a distributed denial-of-service attack. According to the Wall Street Journal, roughly 220 customers filed complaints of outages on its Web site today saying they had problems logging on.
"The amount of bandwidth that is flooding the websites is very large, much larger than in other attacks, and in a sense unprecedented," chief executive of private security firm CrowdStrike Dmitri Alperovitch told the Wall Street Journal.
Last week, similar attacks happened on J.P. Morgan Chase and Bank of America's Web sites.


Not the first “professional” organization with unprofessional levels of security.
IEEE leaks 100,000 members’ usernames and plain-text passwords (updated)
September 25, 2012 by admin
Seen on Slashdot, Radu Dragusin writes:
IEEE suffered a data breach which I discovered on September 18. For a few days I was uncertain what to do with the information and the data. Yesterday I let them know, and they fixed (at least partially) the problem. The usernames and passwords kept in plaintext were publicly available on their FTP server for at least one month prior to my discovery.
Radu provides additional details about the leak and his analyses of exposed data on IEEElog.
This is not IEEE’s first breach involving members’ information. A November 2010 hack affecting 828 members was disclosed in February 2011. And in April 2011, some members who signed up for life insurance underwritten by NY Life Insurance were notified that a mailing error by Marsh U.S. Consumer exposed some of their information to other members.
Update: Oh hell…. I won’t post links, but it has been pointed out that IEEE’s log files have been mirrored in a number of places on the Internet. If you’re an IEEE member, you may want to search to see what information about you has been exposed.


Strange: This seems to be a “first” although I can't think of a good (or even a bad) reason to do it. (and I'm not sure what “force” is required...)
fermion writes with news of Windows computers being forcefully liberated:
"The campaign headquarters of Michael Grimm, a U.S. House of Representatives member from New York, were vandalized. What has not been reported everywhere is that Linux was installed on one of his computers, erasing data in the process. Is this a new attack on democracy by the open source radicals, or it is just a random occurrence?"
From the article: "'In fact, one officer said to me today they see this as a crime against the government, because I am a sitting United States congressman and they take it very seriously. [Unlike crimes against us 'second class' citizens Bob] You know, especially in light of what happened with Gabby Giffords, we're not in the world today where we can shrug things off,' Grimm said. ... [GNU/]Linux, an open-source operating system, was installed on Grimm's computers, erasing the hard drive contents, which included polling and voter identification data. But staff had backed up the hard drive contents hours beforehand. Grimm and his staffers said the vandalism — cement blocks were thrown through the office's windows — is a cover-up for the attacks on the computers."


I think I've linked to this report earlier...
Drones Subject to GPS Spoofing, Privacy ‘Abuses,’ GAO Report Warns
The Government Accountability Office is warning Congress that its push for drones to become commonplace in U.S. airspace fails to take into account concerns surrounding privacy, security and even GPS jamming and spoofing.
The GAO, Congress’ research arm, was responding to the FAA Modernization and Reform Act of 2012, signed by President Barack Obama in February, which among other things requires the Federal Aviation Administration to accelerate drone flights in U.S. airspace.
… But there’s a concerted push to expand the commercial use of drones for pipeline, utility, and farm fence inspections; vehicular traffic monitoring; real-estate and construction-site photography; relaying telecommunication signals; fishery protection and monitoring; and crop dusting, according to the report (.pdf), which was distributed to lawmakers earlier this month.
… Among other things, the report urged the Transportation Security Administration [God help us! Bob] to come up with a plan to secure operation centers for unmanned drones, recommended the government formulate privacy protections to head off “abuses” and also pointed out safety concerns that need to be addressed regarding GPS spoofing and jamming.
In a GPS jamming scenario, the UAS could potentially lose its ability to determine its location, altitude, and the direction in which it is traveling. Low-cost devices that jam GPS signals are prevalent. This problem can be mitigated by having a second or redundant navigation system onboard the UAS that is not reliant on GPS, which is the case with larger UAS typically operated by DOD and DHS.
… “Once the authentic (original) GPS signal is overpowered, the UAS is under the control of the ‘spoofer.’ This type of scenario was recently demonstrated by researchers at the University of Texas at Austin at the behest of DHS.”
The report comes three months after it was revealed that there are 64 drone bases on U.S. soil, with several private companies cleared to operate them. As for legal protections for citizens, “there is very little in American privacy law that prohibits drone surveillance within our borders,” points out Ryan Calo, the director for Privacy and Robotics at the Stanford Center for Internet and Society.
… According to the EFF:
The Seattle Police Department’s drone comes with four separate cameras, offering thermal infrared video, low light ‘dusk-dawn’ video, and a 1080p HD video camera attachment. The Miami-Dade Police Department and Texas Department of Public Safety have employed drones capable of both daytime and nighttime video cameras, and according to the Texas Department of Public Safety’s Certificate of Authorization (COA) paperwork, their drone was to be employed in support of ‘critical law enforcement operations.’
The report noted that commercial and government drone expenditures could top $89 billion over the next decade.

(Related) I think this one is new...
"In 'Living Under Drones,' investigators from Stanford and NYU Law Schools report on interviews with 130 people in Pakistan about U.S.-led drone attacks there, including 69 survivors and family members of victims. The report affirms Bureau of Investigative Journalism numbers that count '474 to 884 civilian deaths since 2004, including 176 children' while 'only about 2% of drone casualties are top militant leaders.' It also argues that the attacks violate international law and are counterproductive, stating: 'Evidence suggests that US strikes have facilitated recruitment to violent non-state armed groups, and motivated further violent attacks One major study shows that 74% of Pakistanis now consider the U.S. an enemy.'"
[From the report:
In the United States, the dominant narrative about the use of drones in Pakistan is of a surgically precise and effective tool that makes the US safer by enabling “targeted killing” of terrorists, with minimal downsides or collateral impacts.[1]
This narrative is false.

(Related)
Appeals Court Caves to TSA Over Nude Body Scanners
A federal appeals court on Tuesday said it was giving the Transportation Security Administration until the end of March to comport with an already 14-month-old order to “promptly” hold public hearings and take public comment concerning the so-called nude body scanners installed in U.S. airport security checkpoints.
The public comments and the agency’s answers to them are reviewable by a court, which opens up a new avenue for a legal challenge to the agency’s decision to deploy the scanners. Critics maintain the scanners, which use radiation to peer through clothes, are threats to Americans’ privacy and health, which the TSA denies.

(Related) “First, you have to get the mule's attention...”
ACLU sues to get U.S. agencies' license plate tracking records
The American Civil Liberties Union today sued the U.S. government to get access to information about how authorities are using automated license plate readers to track people's movements and location.
The ACLU filed Freedom of Information Act requests on July 30 with the departments of Justice, Homeland Security, and Transportation to try to find out how much officials use the technology and how much it is paying to expand the program. Agencies are required by law to respond to FOIA requests within 20 working days, but more than a month later, only one DOJ office and a few DOT agencies have responded, according to the ACLU.


Surveillance down under...
"The Age reports on creeping Australian government surveillance, beginning with the first operation launched on a baseless rumor. Six decades later the still-unaware victim read five months of transcripts with deep distress. Two decades ago few Australians would have consented to carrying a government-accessible tracking device, but phone and tablet data accessible without a warrant includes historic and real-time location data. In 2010-2011 there were 250,000 warrantless accesses by Federal agencies including ASIO, AFP, the Tax Office, Defence, Immigration, Citizenship, Health, Ageing, and Medicare. This is 18 times the rate of similar requests in the U.S."


Do we get the Feds involved because there are no state laws making this illegal?
September 25, 2012
FTC Action Halts Computer Spying by Illinois Companies
News release: "Seven rent-to-own companies and a software design firm have agreed to settle Federal Trade Commission charges that they spied on consumers using computers that consumers rented from them, capturing screenshots of confidential and personal information, logging their computer keystrokes, and in some cases taking webcam pictures of people in their homes, all without notice to, or consent from, the consumers. The software design firm collected the data that enabled rent-to-own stores to track the location of rented computers without consumers’ knowledge according to the FTC complaint. The settlements bar the companies from any further illegal spying, from activating location-tracking software without the consent of computer renters and notice to computer users, and from deceptively collecting and disclosing information about consumers."


Interesting question.
"The Dutch Supreme Court has asked the European Court of Justice to decide whether downloading copyrighted material for personal use — even from illegal sources — is legal. At the heart of the debate is whether the European Copyright Directive requires that any new legal copy of material must have originated from a copy that is itself legal. The case tests the law in the Netherlands, where copyright holders are granted a levy on blank media in exchange for the legalization of private copying."
In the Netherlands, it is already legal to download from illegal sources. But EU law might conflict and trump that.


How to get the attention of a Global company?
"Judge Flavio Peren of Mato Grosso do Sul state in Brazil has ordered the arrest of the President of Google Brazil, as well as the 24-hour shutdown of Google and Youtube for not removing videos attacking a mayoral candidate. Google is appealing, but has recently also faced ordered fines of $500K/day in Parana and the ordered arrest of another executive in Paraiba in similar cases."
Early reports indicated that the judge also ordered the arrest of the Google Brazil President, but the story when this was written is that the police haven't received any such order (and an earlier such order was overuled recently). The video is in violation of their pre-election laws.


Sometimes laws make no sense to me...
"Microsoft's Quincy data center, physical home of Bing and Hotmail, was fined $210,000 last year because the data center used too little electricity. To avoid similar penalties for 'underconsumption of electricity' this year, the data center burned through $70,000 worth of electricity in three days."


Perspective Stay healthy people!
September 25, 2012
Kaiser - Visualizing Health Policy
"The latest infographic in the Visualizing Health Policy series examines health costs in the United States, including how costs have changed, how they compare to some other countries, and how they impact American families."


Since I'm surrounded by geeks...
It is an acronym that stands for Free Art and Technology and this is where Open Source and pop culture comes together.
This channel demonstrates the future of information and how it should be presented, because these days information is taking the visual route and statistics is no longer the dull science it used to be. [I beg your pardon? Bob]
There are loads of videos on animated infographics. If you are into visual design or image facilitation, this is inspiring stuff. I like the way the channel is described – Research findings in data visualization captured, streamed, animated… beautified!


Also a geek thing...
Binreader is designed for someone who wants a portable Usenet client that runs on anything. You can run it on Mac, Windows and Linux and it does not need any installation. It is incredibly easy to use and it uses almost no system resources.


This could be amusing. Perhaps I could have my students write a script for a commercial advertising their hacking skills (Hire me or else!)

(Related) ..and then they could make the video to complete the comemrcial...


Tuesday, September 25, 2012

A clever example of hacker misdirection or yet another example of “We don't need no stinking logs!”
Ah, less-than-sweet mysteries of life: when you can’t figure out if or how you were breached
September 24, 2012 by admin
How frustrating for everyone: St. Agnes Hospital in Baltimore learned that 40 of its physicians had become victims of ID theft. Hapless victims had their names and Social Security numbers used to create wireless telephone accounts that they knew nothing about until they started receiving overdue notices from creditors. [What? They sent the bills to some bogus address but the overdue notices to the doctors? Bob]
But despite its best efforts to identify any internal source of the breach, St. Agnes Hospital could not find any confirmation of a breach. [That's what happens when you don't log access Bob] In a letter to those affected, the text of which was submitted to the state last month, they write:
Once the reports were received, we reviewed all of the points of access and storage for this type of information in Saint Agnes systems. The only system that maintained the same information for all physicians making reports was the credentialing system. We conducted a careful access review and interviews and failed to detect unauthorized access, access after normal business hours, or any other suspicious activity in the system. We were unable to determine that there was a breach of any of our systems that allowed disclosure of the physicians’ personal data.
So what do you do when you suspect your organization has suffered a breach and you think you’ve narrowed it down to one part of your system, but you can’t find out how or when it happened? In this case, the hospital notified physicians that despite its inability to confirm any breach, given the seriousness of the problem, it intended to:
  • Review the list of users with access to sensitive personal data and minimize access where possible to only those who have a business need to access or review the information;
  • Refresh HIPAA privacy education in those departments routinely using physician information; and,
  • Investigate disguising or eliminating social security numbers in data systems where they are stored.
That’s nice, but shouldn’t they have been doing all of that already? [Yes! Bob] And how about running more extensive criminal background checks on employees who could be simply writing down names and SSNs as they access data for their routine job duties? We’ve seen too many insider breaches in hospitals. Usually it’s patient data being sold, but why not physicians, too? [Doctors have huge incomes, patients have huge debts – who do you think is the more attractive target? Bob]


“It's not a failure, it's a feature!” I can hear Dr. Evil laughing...
A single line of code can apparently trigger an unstoppable factory-reset of the Samsung Galaxy S III, security researchers have discovered, with the potential for malicious websites to wipe out users’ phones. The hack was detailed by Ravi Borgaonkar at the Ekoparty security conference, with a simple USSD code – that could be sent from a website, or pushed to the handset by NFC or triggered by a QR code – that can reset the Galaxy S III or indeed other Samsung handsets.



The sad part is, he probably didn't think it was creapy...
"Has Immigration Minister Jason Kenney been emailing you? Maybe it's because you're gay. The minister sent out an email on Sept 24 lauding the government's efforts to protect and promote queer rights abroad. It highlights the 'emphasis . . . on gay and lesbian refugee protection, which is without precedent in Canada's immigration history.' The Ottawa Citizen's Glen McGregor broke the story, complete with reaction over the 'creepy' letter. For many who received an email from Citizenship and Immigration Minister Jason Kenney about gay refugees on Friday, the message raised one important question: How did he know I'm gay? The Conservatives have targeted written messages at minority communities in the past, most notably using direct mail lists to send out greetings to Jewish voters on religious holidays. Some recipients were alarmed by the prospect of the government assembling lists based on ethnicity or religious beliefs. Surely creating such a list will become easier when your are forced to use your real identities on social sites."


It's not uncommon to make rediculous proposals with the assumption that they will be “corrected” before legislation is approved. History tells us otherwise...
Leak reveals EU surveillance of communications
September 24, 2012 by Dissent
Nerea Rial reports:
The CleanIT project was funded by the European Commission’s Home Affairs Directorate in order to reduce the impact of the terrorist use of internet, but a leaked document has shown that the initiative is not what it seems to be.
The main idea of the programme, in which participates among others the Dutch National Coordinator for Terrorism and Security, Spain, UK, Belgium and Europol, is to fight terrorism through voluntary self-regulatory measures under the law. However the document shows how they rapidly forgot about European democracy and legislation.
Read more on New Europe.
[From the article at http://www.edri.org/cleanIT
The proposals urge Internet companies to ban unwelcome activity through their terms of service, but advise that these “should not be very detailed”. This already widespread approach results, for example, in Microsoft (as a wholly typical example of current industry practice) having terms of service that would ban pictures of the always trouserless Donald Duck as potential pornography (“depicts nudity of any sort ... in non-human forms such as cartoons”).
… Moving still further into the realm of the absurd, the leaked document proposes the use of terms of service to remove content “which is fully legal”... although this is up to the “ethical or business” priorities of the company in question what they remove. In other words, if Donald Duck is displeasing to the police, they would welcome, but don't explicitly demand, ISPs banning his behaviour in their terms of service. Cooperative ISPs would then be rewarded by being prioritised in state-funded calls for tender.


“Sure you have rights. In most cases, we just choose to ignore them.”
Do Users of Wi-Fi Networks Have Fourth Amendment Rights Against Government Interception?
September 24, 2012 by Dissent
Orin Kerr writes:
My earlier post on how the Wiretap Act applies to wireless networks triggered a lot of comments on how the Fourth Amendment might apply, so I thought I would have a post specifically on the matter. Here’s the question: Does governmental interception and analysis of the contents of a person’s wi-fi traffic constitute a Fourth Amendment search? And does it depend on whether the traffic is encrypted or unencrypted?
The answer turns out to be surprisingly murky. Because the Wiretap Act has been thought to protect wireless networks, the Fourth Amendment issue has not come up: There’s a surprising lack of caselaw on it. Second, there are plausible arguments on either side of the debate both for encrypted and unencrypted transmissions. So I wanted to run through the arguments, starting with the case of unencrypted communications and then turning to encrypted communications, and then ask which side readers find more persuasive.
Read more on The Volokh Conspiracy.


Is an “Emergency” what I think it is or anything you say it is?
Maine likely to consider cell phone location law that mandates companies provide info in an emergency
September 24, 2012 by Dissent
Mal Leary reports:
A law that requires cellphone providers to give law enforcement agencies the location of a person’s cellhone in an emergency is expected to be considered in Maine next year.
Eight states have adopted a version of the law, known as Kelsey’s Law.
“I fully expect we will see some version of it introduced,” said Rep. Anne Haskell, D-Portland, the lead Democrat on the Legislature’s Criminal Justice Committee and a former-co-chair of the panel. “When we see other states passing a law, we usually see a Maine version introduced.”
Read more on the Portland Press Herald.


Boy, dat Facebook ting one great surveillance tool, aint' she?
Facebook Now Knows What You’re Buying at Drug Stores
September 24, 2012 by Dissent
Rebecca Greenfield writes:
In an attempt to give advertisers more information about the effectiveness of ads, Facebook has partnered with Datalogix, a company that “can track whether people who see ads on the social networking site end up buying those products in stores,” as The Financial Times‘s Emily Steel and April Dembosky explain. Advertisers have complained that Facebook doesn’t give them any way to see if ads lead to buying. This new partnership is their response, as it connects real-life buying with ads seen on the site. Specifically, the service links up the 70 million households worth of purchasing information that Datalogix has with these buyers’ Facebook profiles. Using that, they can compare the ads you see with the stuff you buy and tell advertisers whether their ads are working. Up until now, the social network has been limited to only tracking your Internet life (on and off Facebook.com) with its ubiquitous “like” buttons, but as promised, the future of Facebook is more focused on data, including tracking our offline habits.
Specifically, Datalogix gets its information from retailers like grocery stores and drug stores who keep careful records of what its customers who use its loyalty discount programs are buying. Datalogix’s site doesn’t list its partners, but from a Google search, it looks like the company has worked with CVS’s ExtraCare card program. Datalogix matches the email addresses and other identifying information in those databases to Facebook accounts.
Read more on The Atlantic Wire.
So… do you find that scary, helpful, or neither?

(Related)
FTC should examine Facebook-Datalogix partnership, privacy group says
September 25, 2012 by Dissent
Jeremy Kirk reports:
The U.S. Federal Trade Commission should analyze Facebook’s relationship with a data marketer to ensure it doesn’t violate the social networking site’s recently approved settlement, the Electronic Privacy Information Center said Monday.
Facebook is working with Datalogix, a company based in Colorado that specializes in collecting data from retailers using customer loyalty cards and linking those purchases to future advertising campaigns, The Financial Times reported. Datalogix links loyalty card holders to their Facebook accounts using shared information, such as email addresses, although the information is anonymized, the report said.
Facebook’s user guide say it only provides “data to our advertising partners or customers after we have removed your name or any other personally identifying information from it.”
Read more on CSO.


This confirms a lot of suspicions. Clearly the government is run by Twitts and apparently, not many people care what they Tweet. One person in 100 follows the Whit House and the readers of number 50's Tweets might not even include all the employees...
September 24, 2012
FCW - The 50 most-followed agencies on Twitter
Federal Computer Week: "Twitter has quickly evolved from social media novelty to critical communications channel. This list shows which federal agencies have built the biggest audiences, and where the growth has been fastest over the past year. The data [in this article] was compiled by OhMyGov, a media and technology firm that specializes in providing advanced media intelligence for government agencies, congressional offices, lobbyists, and businesses working with government. Please note that for many agencies, follower totals for multiple Twitter accounts were combined to provide a better sense of total reach. All counts are as of Aug. 31, 2012."


Stunning! Well done, India!
Over in India there’s an extremely cheap Android tablet being deployed by the government to families, schools and more. We’ve talked about the Aakash tablet more than a few times, but this new and improved Aakash 2 tablet for just $35 dollars is set to arrive throughout India starting next month.


For my Computer Forensics students?
"Today's handheld device is the mainframe of years past. An iPhone 5 with 64 GB of storage and the Apple A6 system-on-a-chip processor has more raw computing power entire data centers had some years ago. With billions of handheld devices in use worldwide, it is imperative that digital forensics investigators and others know how to ensure that the information contained in them, can be legally preserved if needed."
In Digital Forensics for Handheld Devices, author Eamon Doherty provides an invaluable resource on how one can obtain data, examine it and prepare it as evidence for court.
… Chapter 5 also has overviews of nearly 50 different forensic tools for every imaginable purpose.


I use LightShot to capture screen images both in the Firefox browser and on the destop. LightShot does not capture video. Here are a few others...
Monday, September 24, 2012
Here are some free tools that you can use to create screen capture videos and images.


Sometimes you just want to let your students watch the boob tube so you can take a nap...
Monday, September 24, 2012


At last! Something to do with all those cellphones I confiscate in class... (At least, that's what I'm going to tell my students)
You can visit the Recycle Through USPS page on the USPS.com website and follow the four easy steps to find out how much your old cell phone is worth and to see if your items qualify for instant cash. Even if your device does not qualify for a buyback, you can use the free mail-back recycling envelopes at the locations to ship and dispose of the waste electronics.


...and all in less than 10 pages!
September 24, 2012
The Debunking Handbook - free download
"The Debunking Handbook, a guide to debunking misinformation, is now freely available to download. Although there is a great deal of psychological research on misinformation, there's no summary of the literature that offers practical guidelines on the most effective ways of reducing the influence of myths. The Debunking Handbook boils the research down into a short, simple summary, intended as a guide for communicators in all areas (not just climate) who encounter misinformation."


Perhaps it's not just a “New Jersey thing” I have no doubt that my students also get very creative when I make them do endless hours of homework.

Monday, September 24, 2012

Just an observation. This is not why my Ethical Hackers study math...
September 23, 2012
Trend Micro Commentary on Global Hackers
Trend Micro Incorporated Opinion Piece, September 2012 - Peter the Great Versus Sun Tzu
  • "Due to the competitive nature of the environment, East European hackers create customized malware, often with all capabilities internally hard-coded with no external third-party tools. Trend Micro threat researchers noted that robust anti-debugging techniques and complex command and control (C&C) are hallmarks of East European design. East European malware are not always innovative but often incorporate several exploits designed by others in creative ways. An East European hacker is only as good as his last successful job. East European malware are so elegantly crafted, they have been dubbed the “Faberge Eggs” of the malware world. This is due in part to the long history of high-quality science and math education in the former Soviet Bloc. With the fall of communism and the free market chaos that ensued, East Europeans with strong math and science backgrounds turned to the skills developed to help fight the Cold War and started using them to put food on the table by selling them to the highest bidder. In addition, computer scientists in the former Soviet Bloc had to make do with simpler, less sophisticated computing resources, which instilled in them a discipline to make every line of code count. These were combined to yield a pool of expert craftsmen able to build high-impact, small-footprint malware. Probably the best recent example of this is in the new Tinba malware—a well-crafted piece of malware that is optimized for size and capability and used in Trojan banker attacks targeting Turkey."


Take that, Copyright lawyers!
September 23, 2012
New Study Affirms Less Copyright Restrictions Benefit the Economy
EFF: "A new study from Australia presents the latest evidence that loosening copyright restrictions not only enables free speech, but can improve an economy as well. The study, published by the Australian Digital Alliance, indicated that if Australia expanded copyright exceptions like fair use, along with strengthening safe harbor provisions, the country could potentially add an extra $600 million to their economy. In addition, the report details how vital copyright exceptions are to the Australian economy as a whole. As ADA’s executive officer and copyright advisor Ellen Broad told EFF, "Australia's sectors relying on copyright exceptions currently contribute 14% of our GDP, around $182 billion and they're growing rapidly. It's essential that Australia's copyright policy framework adequately support innovation and growth of these sectors in the digital environment.”

(Related) On the other hand, an interesting question for students of Copyright law?
"I've created some popular science videos showing how asteroid discoveries have happened over the last few decades. However I've run into a problem with a religious organization which borrowed my video and redubbed it to promote their religious message. Ultimately I filed a DMCA takedown request via YouTube's site, it's as easy as filling in a form and the video was removed. But this organization has since submitted a counterclaim claiming 'under penalty of perjury' that they do in fact have the rights to this work, and YouTube has reinstated the video. It looks like the only way I can pursue this further is to spend the money to take the organization to court and get an injunction, but even if I did so I'd have to pay court costs up front and since they're based in another country I'd have a difficult time actually collecting any money from the other party. It feels like this other group is simply gambling that I won't spend the time and resources to take further legal action, the DMCA is supposed to provide equal protection but the more lawyer you have the more 'equal' you are. So does anyone have any suggestions for how I should proceed here?"


At some point they will realize it would be easier to study the things they did right. (There must have been some...)
"Prime Minister John Key today announced he has requested an inquiry by the Inspector-General of Intelligence and Security into the circumstances of unlawful interception of communications of certain individuals by the Government Communications Security Bureau. Mr Key says the Crown has filed a memorandum in the High Court in the Megaupload case advising the Court and affected parties that the GCSB had acted unlawfully while assisting the Police to locate certain individuals subject to arrest warrants issued in the case. The Bureau had acquired communications in some instances without statutory authority."


Interesting I wonder if other advocacy groups would be willing to sponsor education software? Perhaps Google would sponsor Driver Training? GEICO could sponsor lizzard races?
PETA Foots The Bill For Virtual Frog Dissection Software In India
PETA, People for the Ethical Treatment of Animals, is offering to sponsor software that lets students poke around the innards of frogs — without actually, you know, poking around the innards of frogs. The offer is being made to schools and colleges in India that agree to give students a choice of cutting into real or virtual frog flesh — or indeed replacing traditional dissection with other “humane” alternatives.
The software in question — Frog Dissection — is made by Emantras, the company PETA is tying up with for the Indian initiative, and is priced at between $2.99 and $4.99 in the U.S. but will be offered free to classrooms in India that agree to offer non-animal dissection alternatives.


Perhaps a tool to collect the odds & ends I hand out to my students?
Readlists is a web app that creates eBooks from your chosen articles online. This effectively allows you to curate articles and turn them into your own collection that you can use with your Kindle or favorite e-book reader.
Similar Tools: Readability, and Wikipedia Book Creator

Sunday, September 23, 2012

“Continuing our quest to know everything about everyone, inside and out...”
FBI renews broad Internet surveillance push
The FBI is renewing its request for new Internet surveillance laws, saying technological advances hinder surveillance and warning that companies should be required to build in back doors for police.
"We must ensure that our ability to obtain communications pursuant to court order is not eroded," FBI director Robert Mueller told a U.S. Senate committee this week. Currently, he said, many communications providers "are not required to build or maintain intercept capabilities."
… It's not exactly clear how much of the FBI's problems in conducting surveillance arise from wireless communications, encryption, social networks, or VoIP; the bureau has not been eager to be specific. Microsoft's Skype service has worked with law enforcement to make online chats and other user information available to police, the Washington Post reported in July.

(Related)
Watch Your Tongue: Law Enforcement Speech Recognition System Stores Millions of Voices
September 22, 2012 by Dissent
Ryan Gallagher reports:
Intercepting thousands of phone calls is easy for government agencies. But quickly analyzing the calls and identifying the callers can prove a difficult task.
Now one company believes it has solved the problem—with a countrywide biometric database designed to store millions of people’s “voice-prints.”
Russia’s Speech Technology Center, which operates under the name SpeechPro in the United States, has invented what it calls “VoiceGrid Nation,” a system that uses advanced algorithms to match identities to voices. The idea is that it enables authorities to build up a huge database containing up to several million voices—of known criminals, persons of interest, or people on a watch list. Then, when authorities intercept a call and they’re not sure who is speaking, the recording is entered into the VoiceGrid and it comes up with a match. It takes just five seconds to scan through 10,000 voices, [That way too slow to be really useful Bob] and so long as the recording is decent quality and more than 15 seconds in length, the accuracy, SpeechPro claims, is at least 90 percent.
Read more on Slate.


Traing a generation of tattlers...
Is #Snitchgate much ado about nothing?
September 22, 2012 by Dissent
Back on July 5, Aliette de Bodard tweeted, “WTF, FB greets me with a picture of one of my friends and asks me “is this your friend’s real name”? Like I’m going to denounce them…” Her tweet was re-tweeted by only one person and got only one response. On July 6, however, Heise reported on Facebook’s attempt to get information on whether its users were really using their real names or pseudonyms. Apart from Heise, a handful of other sites also mentioned this latest development, but only one was in English, which may help explain why the story really didn’t get any traction.
Fast-forward a few months, and when “dǝǝɥƆ Deefy” tweeted, “Facebook wants to know if your friends’ names are real. Are you going to be the snitch? pic.twitter.com/CdqGoxvQ” it gets over 800 re-tweets and its own hashtag – #snitchgate.
So Facebook has been doing this since the beginning of July, but it seemingly flew under privacy advocates’ radar until September 19. In a statement to AllFacebook, Facebook explains:
We are always looking to gauge how people use Facebook and represent themselves to better design our product and systems. We are showing people information that their friends have made available to them, and we indicate to the person taking the survey that their response will be anonymous to ensure them that we are not sharing their data with anyone and only looking to understand the results in an aggregate sense. Additionally, it is important to understand that we will not be using this data for enforcement actions.
But there’s no way out of the survey pop-up except to click “I don’t want to answer:”
Of course, Facebook is a company and not the government, so they can decide that their Terms of Service requires real names – even if they don’t attempt to justify it by saying the real names policy is for safety purposes. And they can take steps to find out whether most users are complying with those terms. There’s nothing seemingly illegal or unethical about what Facebook is doing. It’s just plain creepy. And it may create distrust among users who fear they will be “outed.” How social is that?
But more than creepy, it also reminds us that while Facebook offers its users some privacy settings and controls, its business model is based on real names and making as much information about users as public as possible so that advertisers can target advertising. Using a pseudonym on Facebook still permits targeted advertising based on content, but how much richer would the data mining – and advertising revenues for Facebook – be if the Facebook account can be linked to Gmail or other accounts?
So what should a good friend do when confronted by the screen? Do you say “yes?” (even if it’s not the real name) or do you answer “I don’t want to answer?” Hopefully, you won’t answer “no.”
As for me, I’ll never encounter that survey, because I’ve never used Facebook and never understood why anyone who cares about their privacy would use it. But that’s just me. YMMV.


Local and depressing...
"A Colorado county put bar codes on printed ballots in a last minute effort to comply with a rule about eliminating identifying markings. Citizens sued, because the bar codes can still be traced back to individual voters. In a surprise ruling, Denver U.S. District Judge Christine Arguello said the U.S. Constitution did not contain a 'fundamental right' to secret ballots, and that the citizens could not show their voting rights had been violated, nor that they might suffer any specific injury from the bar codes.


Well of course it is.
"In Victoria (Australia), detailed information about electricity customers' power usage, which gives insights into when a house is occupied, is being shared with third parties including mail houses, debt collectors, data processing analysts and government agencies."


My Computer degree says: Solve the problem and give it to anyone who needs it. My MBA says: Would a nominal fee bee so bad?
"A Private User Agent W3C Community Group has been proposed to tackle the privacy of the web browser by developing technical solutions to close the leaks. Current Javascript APIs are capable of leaking a lot of information as we browse the Internet, such as details of our browser that can be used to identify and track our online presence, and the content on the page (including any private customizations and the effects of extensions), and can monitor and leak our usage on the page such a mouse movements and interactions on the page. This problem is compounded by the increased use of the web browser as a platform for delivering software. While the community ignores the issue, solutions are being developed commercially and patented — we run the risk of ending up unable to have privacy because the solutions are patented. The proposed W3C PUA CG proposes to address the problem with technical solutions at the web browser, such as restricting the back channels available to Javascript, and also by proposing HTML extensions to mitigate lost functionality. Note, this work cannot address the privacy of information that we overtly share, and there are other current W3C initiatives working on this, such as DNT."


Online music
Pandora Users: An Explanation Of The Radio Law You’re Asked To Support
Pandora listeners may notice their regularly scheduled commercial breaks of Ford products and tight jeans were interrupted by a call to support a bill called, “The Internet Radio Fairness Act.” The proposed bill would reduce the royalty fees paid by Internet music-streaming services to those paid by other digital and satellite radio stations (the so-called “801(b)” standard). The Hill reports that online radio services shell out more than 55% of their revenue to pay off royalty fees, while satellite and cable companies only pay somewhere between 7 and 16 percent, according to co-sponsor Rep Jason Chaffetz’s office. Like Google and Wikipedia blacking out their websites in opposition to the Stop Online Piracy Act, Pandora has a captive audience of 150+ million users to broadcast their campaign, once again revealing how web giants can transform into powerful media outlets.


A bit geeky. This is a SEO tool...
September 21, 2012
Google Keywords and search queries using metatags
Google News blog: "...today we’re excited to announce a news_keywords metatag. The goal is simple: empower news writers to express their stories freely while helping Google News to properly understand and classify that content so that it’s discoverable by our wide audience of users. Similar in spirit to the plain keywords metatag, the news_keywords metatag lets publishers specify a collection of terms that apply to a news article. These words don’t need to appear anywhere within the headline or body text. Taking the Variety example above, news keywords such as “stocks”, “stock market”, or “crash” would be helpful in allowing Google News to better understand the article content for ranking without forcing the editors to water down the creativity of a great headline. Because the metatag appears only as part of the HTML code of a page, visitors to a site won’t ever see the magic under the hood."


Perspective


For my students, while we are on break...


Handy for illustrating some Math concepts...
… Loopcam is an application for the iOS devices that allow people to make GIF using their iPhone and iOS device cameras.
Similar tools: Gifture and GifBoom.


Are you ignoring me? (Yet another way to freak out my students!)
BananaTag not only allows users to tag and track their emails but it also analyzes them and shows the whole summary using a graph.
This graph shows you a complete detail of the emails you sent, the number of people who clicked it and the ones who opened it. It also shows you how many of the people you sent the emails to be accessing them from their Desktop or Mobile. The location insight gives you an insight to the places where the emails were accessed from – the location of the people.
Honestly, this type of tool is not for the regular email user, but for business organizations and small businesses who communicate with their clients via e-mails. This is also great for people who advertise via e-mails (not SPAM), and would allow them to find how much audience they reach.
Using the BananaTag tool is pretty easy and simple. Just download the tool and have it integrated into your Outlook software or your Google or Google Apps account. There is also a non-integrated browser email tracking for all other email clients and mobile devices.
There is a FREE available version for a person that allows them to track 100 emails per day.
SImilar tool: Unbox,