Friday, May 10, 2013

The logistics clearly make this an “organized crime” operation. Note that the seven arrested took only a small fraction ($2.8 million) of the total.
This will be one for the books… and Hollywoood spinoffs. Jessica Dye and Jim Finkle of Reuters report:
The government charged eight people with using data obtained by hacking into two credit card processors in a worldwide scheme that netted some $45 million within hours, a crime prosecutors described as one of the biggest bank heists in history.
The individuals formed the New York-based cell of a global cybercriminal organization that stole MasterCard debit card data from two Middle Eastern banks, the Justice Department said. The information was used to make more than 40,500 withdrawals at automated teller machines in 27 countries, prosecutors said.
Read more on CNBC. Here’s the press release from the U.S. Attorney’s Office, Eastern District New York.
[From the CNBC article:
Prosecutors said the attacks, known as "unlimited operations," occurred in two separate incidents, in December 2012 and February 2013.
… In the New York area, the ring withdrew nearly $400,000 in less than three hours at more than 140 ATMs, the prosecutors said. On another occasion, about $2.4 million was collected in nearly 3,000 ATM withdrawals over 10 hours, they said.
[From the US Attorney's press release:
Over the course of approximately 10 hours, casher cells in 24 countries executed approximately 36,000 transactions worldwide and withdrew about $40 million from ATMs. From 3 p.m. on February 19 through 1:26 a.m. on February 20, the defendants and their co-conspirators withdrew approximately $2.4 million in nearly 3,000 ATM withdrawals in the New York City area.


Interesting (if small) breach. Looks like they ignored almost every “Best Practice” They didn't detect the breach and once told about it, it sounds like a very poor response.
Rachel La Corte reports:
The Washington state Administrative Office of the Courts was hacked in February, and up to 160,000 Social Security numbers and 1 million driver license numbers may have been accessed during the data breach of its public website.
Officials with the courts announced Thursday that so far, it has been confirmed that 94 Social Security numbers were obtained. Initially, authorities didn’t think confidential information was taken, but following an investigation by the Multi-State Information Sharing and Analysis Center, the broader breach was confirmed in April, said courts spokeswoman Wendy Ferrell.
Read more on KOMO News. Somewhat surprisingly (to me, anyway):
Ferrell said that there is no active law enforcement investigation at this time, but people who believe they are at risk should take precautions to monitor credit.
Why is there no active law enforcement investigation of a hack involving the state?

(Related) How they did it.
Rachel La Corte has more on the hack reported earlier today on this blog:
The breach happened due to vulnerability in an Adobe Systems Inc. software program, ColdFusion, that has since been patched, court officials said. The hack happened sometime after September but wasn’t caught until February, they said.
[...]
Mike Keeling, the courts’ information technology operations and maintenance manager, said officials were alerted to the breach by a business on the East Coast that had a similar intrusion.
They recognized our information in their breach log,” Keeling said, which led them to install the patch provided by Adobe and start an investigation.
[...]
Keeling acknowledged that confidential information should have been kept in a different area, “and now they are.”
“I can say nothing more than it was an oversight on our part,” he said.
Read more on Yakima Herald.


Perhaps my Ethical Hackers would do this faster? (For a modest fee, of course)
Apple deluged by police demands to decrypt iPhones
Apple receives so many police demands to decrypt seized iPhones that it has created a "waiting list" to handle the deluge of requests, CNET has learned.
Court documents show that federal agents were so stymied by the encrypted iPhone 4S of a Kentucky man accused of distributing crack cocaine that they turned to Apple for decryption help last year.
An agent at the ATF, the federal Bureau of Alcohol, Tobacco, Firearms and Explosives, "contacted Apple to obtain assistance in unlocking the device," U.S. District Judge Karen Caldwell wrote in a recent opinion. But, she wrote, the ATF was "placed on a waiting list by the company."
A search warrant affidavit prepared by ATF agent Rob Maynard says that, for nearly three months last summer, he "attempted to locate a local, state, or federal law enforcement agency with the forensic capabilities to unlock" an iPhone 4S. But after each police agency responded by saying they "did not have the forensic capability," Maynard resorted to asking Cupertino.
Because the waiting list had grown so long, there would be at least a 7-week delay, Maynard says he was told by Joann Chang, a legal specialist in Apple's litigation group. It's unclear how long the process took, but it appears to have been at least four months.
… It's not clear whether that means Apple has created a backdoor for police -- which has been the topic of speculation in the past -- whether the company has custom hardware that's faster at decryption, or whether it simply is more skilled at using the same procedures available to the government. Apple declined to discuss its law enforcement policies when contacted this week by CNET.


“We are determined to give our secret police the ability to create complete dossiers on every citizen. How else can we control them?”
David Kravets reports:
The immigration reform measure the Senate began debating yesterday would create a national biometric database of virtually every adult in the U.S., in what privacy groups fear could be the first step to a ubiquitous national identification system.
Buried in the more than 800 pages of the bipartisan legislation (.pdf) is language mandating the creation of the innocuously-named “photo tool,” a massive federal database administered by the Department of Homeland Security and containing names, ages, Social Security numbers and photographs of everyone in the country with a driver’s license or other state-issued photo ID.
Read more on Threat Level.
[From the article:
Employers would be obliged to look up every new hire in the database to verify that they match their photo. [After all, job applicants are guilty until proven innocent, right? Bob]
… “It’s like a national ID system without the card.”


Interesting. Is that a “We'll never make that mistake again” or a “Let's let the anger die down for a while?” Or perhaps they have a better way? In-store drones?
Angela Martin of CBS-DFW follows up on a story mentioned previously on this blog:
Nordstrom is no longer collecting information from the smart phones of its customers.
Since September, sensors staged throughout the stores were able to track signals from smart phones as they attempted to connect to Wi-Fi service. The company said it was using the data to measure foot traffic within different departments of its stores at different times of the day.
Nordstrom spokesperson Tara Darrow confirmed the company stopped using sensors the day after CBS 11 aired a story about the practice. [Yep. A definate “We didn't think we'd get caught!” Bob] After the story, customers contacted the company to ask questions and share feedback, according to Darrow.
Read more on CBSDFW.
Shining the light on surveillance practices – by government or businesses – sometimes help. In this case, it seems to have brought the “experiment” to a quicker halt and gave the business some feedback from customers who were unhappy with what the store was doing.

(Related)
Nordstrom may no longer be using Euclid to track smartphones, but other retailers are. And Ryan Grenoble reports that opting out may not be easy for some shoppers:
On its privacy page, Euclid assures skeptics it does not collect sensitive data, such as “who you are, whom you call or the websites you visit.” The anonymous data on individual shoppers that the company does collect is bundled with data from other individuals, resulting in an aggregate report of anonymous information.
Euclid has an opt-out option for shoppers who would rather not be tracked as they wander the aisles of participating retailers, though the process requires the user to look up his smartphone’s MAC address, a unique code that identifies the device to a network. (However, the MAC address is usually buried deep in the phone’s settings, and digging it out may be a daunting task for some users.) After a shopper opts out, his information is wiped from Euclid’s database along with Euclid’s record of the phone’s MAC address.
Read more on Huffington Post.


I think I'll forget this article...
May 09, 2013
On The "Right to Be Forgotten": Challenges and Suggested Changes to the Data Protection Regulation
  • "Since January 2012, the European Union institutions have been debating draft legislation to reform European rules on data protection (commonly referred to as the Data Protection Regulation (DPR)). Article 17 of the proposed DPR presents the concept of a "Right to Be Forgotten". Article 17 would allow a user to request that an online service provider delete all data – including data that has been made public – it has about that user. While CDT is sympathetic to the concerns that underlie Article 17, we have recommended that it be redrafted and narrowed substantially. As laid out in the Commissionʼs proposal it would significantly limit usersʼ free expression rights and impose unreasonable burdens on online platforms and ISPs, likely leading to fewer platforms for user speech. Private companies are ill-equipped to take responsibility for decisions that balance the right to privacy with the right to free expression. [Are they being asked to make a decision? Bob] Such questions are ultimately for courts to decide, interpreting carefully drawn legislative mandates in light of relevant human rights jurisprudence. Moreover, we believe that the measures to protect journalistic and artistic expression – namely, those granted by Article 80 of the DPR – are too narrowly drafted and do not satisfy international human rights obligations regarding free expression."


As goes California? I imagine the social networks will fight to avoid loss of their most easily influenced age group.
Philip Janquart reports:
A bill intended to give parents the right to pull their children’s’ personal information off social networking sites has passed the California Senate.
After a 23-10 vote, SB501, or the Social Networking Privacy Act, now moves to the Assembly, the lower house of the California Legislature.
Read more on Courthouse News.
“It’s for the children” arguments are often problematic. Should a parent really be allowed to demand removal of a 17 year-old’s information? What if the 17 year-old is politically advocating for changes in law and gives out his/her details because s/he wants to be contacted by others with similar views?


Think of this as a “Get out of jail, free” card.
Karen Gullo reports:
Delta Air Lines Inc. won dismissal of claims it violated California’s Internet privacy law because its mobile-phone application didn’t notify users that personal information, such as their locations, was being collected.
California Attorney General Kamala Harris sued Atlanta-based Delta in December alleging its “Fly Delta” app didn’t have a clearly posted privacy policy. Judge Marla Miller in state court in San Francisco agreed today with the airline that the federal Airline Deregulation Act bars states from imposing regulations on airlines related to price, routes or services.
Read more on Bloomberg News.


“It's a bird! It's a plane! It's SuperDrone!” Except where prohibited by law...
Jackie Johnson reports:
Photos, video and audio recordings captured without permission on private property with the use of a drone would be against the law under legislation being introduced at the state Capitol.
Lawmakers from both sides of the political aisle in Wisconsin want to ensure remote-controlled [How about autonomous drones? Bob] flying devices do not threaten individual privacy rights.

(Related) Is the era of the drone already at an end? (reads more like a hypothetical case to me)
Scott Bomboy writes:
A United Nations report about “killer robots” is a new spin on the rising concern about drones—and the legal problems caused by self-guided machines could be closer than you think.
The U.N. Human Rights Commission plans to address part of the issue later this month in Geneva. Christof Heyns, a South African professor of human rights law, released an extensive U.N. report on the topic in April that has ominous overtones.
[...]
Like many military technologies, these robots are also making their way into the civilian world. FEMA’s website lists government-approved robots including the SNEAKY, a small surveillance robot that literally sneaks around gathering evidence. SNEAKY can do border inspections, gather audio and video evidence, sniff bags, and issue voice instructions.
Read more on Constitution Daily.


This could be very interesting, if it ever actually happens.
May 09, 2013
Executive Order -- Making Open and Machine Readable the New Default for Government Information
"To promote continued job growth, Government efficiency, and the social good that can be gained from opening Government data to the public, the default state of new and modernized Government information resources shall be open and machine readable. Government information shall be managed as an asset throughout its life cycle to promote interoperability and openness, and, wherever possible and legally permissible, to ensure that data are released to the public in ways that make the data easy to find, accessible, and usable. In making this the new default state, executive departments and agencies (agencies) shall ensure that they safeguard individual privacy, confidentiality, and national security."


We knew this was coming...
Google announced on Thursday the launch of a pilot program designed to offer paid channels on YouTube with subscription fees starting at $0.99 per month. The program kicked off with a small group of partners including the producers of Sesame Street, Big Star Movies, DHX Kids TV, National Geographic Kids, Primezone Sports, and TYTPlus.
According to Google, there are over 1 million channels generating quality professional content and revenue on YouTube, making paid channels a natural way for content producers to increase their revenue beyond advertising sponsorship.
The paid channels work similarly to any online subscription service.


Fun and games for my Ethical Hackers?
Gianna, 14, discovers iPad 2 heart risk
Gianna Chien is somewhat different from all the other researchers reporting on their work to more than 8000 doctors at the Heart Rhythm Society meeting in Denver, Colorado.
Chien is 14, and her study – which found that Apple's iPad 2 can, in some cases, interfere with life-saving heart devices because of the magnets inside – is based on a science-fair project that didn't even win her first place.
… If a person falls asleep with the iPad 2 on the chest, the magnets in the cover can "accidentally turn off" the heart device, said Chien, a high school freshman in Stockton, California, whose father is a doctor. "I definitely think people should be aware. That's why I'm presenting the study."
Defibrillators, as a safety precaution, are designed to be turned off by magnets. The iPad 2 uses 30 magnets to hold the iPad 2's cover in place, Chien said. While the iPad 2 magnets aren't powerful enough to cause problems when a person is holding the tablet out in front of the chest, it can be risky to rest it against the body, she found.

Thursday, May 09, 2013

So this could reveal who is in a 'battered women's shelter' or the location of foster children? Not good, but not talking about the risks is even worse!
This could be bad. WGN TV reports:
Chicago police are investigating a “significant theft” of computer equipment from the Dept of Family and Support Services.
Someone stole about $41,000 worth of computer equipment from a city office building on the West Side in a burglary, police said.
Police could not comment on what information may have been compromised.
A spokesperson for DFSS was also unable to comment saying “Because this matter is under investigation by Chicago Police, it would be inappropriate for us to comment on any of the details that could be a part of that investigation.”
The Chicago Tribune has a bit more on the burglary, including the fact that not all of the equipment stolen was new equipment.
If any unencrypted PII or PHI were on the stolen computers, the police would not want to tip the burglars to the presence of usable information. But by the same token, if there are PII or PHI on it, DFSS cannot afford to wait long to alert clients, who will need to protect themselves.

(Related) Statistically, this might be true, but potential victims would rather have the particulars for this case, not what happens “on average.”
A breach notification letter submitted this week to the Vermont Attorney General’s Office by WorldVentures Marketing had me grinding my teeth.
According to the notification to consumers, WorldVentures recently became aware of unauthorized access to their servers. The access may have occurred from October 23, 2012 through March 14, 2013. The server held customers’ credit card numbers with expiration dates. They do not indicate how they became aware of the unauthorized access.
The firm says that they do not have any evidence that the card data were extracted. Then again, do they have any firm proof it wasn’t extracted?
“We believe the risk of harm to you is low.”
If you don’t know for sure that data were not extracted, should you write that? No.
The firm did not offer affected customers any free credit monitoring services.


“It's for your own good!”
hypnosec tipped us to news that India is rolling out a new intrusive monitoring system, using the authority of a 2000 telecom law. Quoting The Times of India:
"However, Pavan Duggal, a Supreme Court advocate specialising in cyberlaw, said the government has given itself unprecedented powers to monitor private Internet records of citizens. 'This system is capable of abuse,' he said. The Central Monitoring System, being set up by the Centre for Development of Telematics, plugs into telecom gear and gives central and state investigative agencies a single point of access to call records, text messages, and emails as well as the geographical location of individuals."
Privacy advocates are worried about abuse, partially because India has no effective privacy legislation, and the "...Indian government under PM Manmohan Singh has taken an increasingly uncompromising stance when it comes to online freedoms, with the stated aim usually to preserve social order and national security or fight 'harmful' defamation."


Don't locate it next to a skeet range...
Colorado's Mark Udall, a privacy watchdog, stumps for domestic drones
Sen. Mark Udall … is spinning a sunnier side to unmanned machines that fly in the sky with cameras.
At a Washington speech Wednesday to entrepreneurs and business leaders in the unmanned aerial technology sector, Udall urged development of the technology, saying it will help people. [at least, Sen. Udall Bob]
"We need to integrate unmanned aerial systems into the American psyche in a way that isn't threatening or scary," [i.e. Sneak up on them? Bob] he said, in remarks at the National Press Club. "Many here today have likely recognized that I'm deliberately not using the word 'drone' because it carries a stigma.
… Udall, along with other Colorado officials, is urging the Federal Aviation Administration to make Colorado a test site for the unmanned aircraft systems.
… To keep the checks and balances intact, Udall plans proposed legislation that would prohibit individuals or private businesses from spying on another person using a privately operated drone.


It's a Jedi mind trick: “This is not the Fourth Amendment violation you are looking for...”
Additional perspective on today’s ruling in Rigmaiden from Linda Lye of the ACLU:
Today, a federal district judge in Arizona issued a very disappointing decision concerning the government’s obligations to be candid with courts about new technologies they are seeking a warrant to use.
The case involves Daniel Rigmaiden, who is being criminally prosecuted for an alleged electronic tax fraud scheme. The government used a surveillance device known as a stingray to locate Mr. Rigmaiden. A stingray operates by simulating a cell tower and tricking all wireless devices on the same network in the immediate vicinity to communicate with it, as though it were the carrier’s cell tower. In order to locate a suspect, a stingray scoops up information not only of the suspect, but all third parties on the same network in the area. This means that when the government uses a stingray to conduct a search, it is searching not only the suspect, but also tens or hundreds of third parties who have nothing to do with the matter. When the FBI sought court permission to use the device to locate Mr. Rigmaiden, it didn’t explain the full reach of stingrays to the court.
The ACLU and the Electronic Frontier Foundation filed an amicus brief arguing that when the government wants to use invasive surveillance technology, it has an obligation to explain to the court basic information about the technology, such as its impact on innocent third parties. This is necessary to ensure that courts can perform their constitutional function of ensuring that the search does not violate the Fourth Amendment. Unfortunately, today’s decision trivializes the intrusive nature of electronic searches and potentially opens the door to troubling government misuse of new technology.
In today’s decision denying the motion to suppress, the judge held that information about how the stingray operates – such as the fact that it scoops up third party data – was merely a “detail of execution which need not be specified.” We respectfully but strongly disagree.
Read more on ACLU’s blog.


If aggregating lots and lots of trivial data points could add up to a search, where would that leave the data brokers who collect all that behavioral advertising stuff?
Orin Kerr writes:
I haven’t blogged recently on judicial decisions considering the mosaic theory of the Fourth Amendment. As regular readers will recall, the “mosaic theory” is a term for the idea that long-term monitoring of a suspect can be a Fourth Amendment search even if short-term monitoring is not. Under this approach, which was suggested by the concurring opinions in United States v. Jones, surveillance and analysis of a suspect is outside the Fourth Amendment until it reaches some point when it has gone on for too long, has created a full picture of a person’s life (the mosaic), and therefore becomes a search that must be justified under the Fourth Amendment. I think the mosaic approach is a misstep for reasons I elaborated on in this article. And the handful of lower courts to have considered the theory since Jones mostly have not adopted it, either because they found it unpersuasive, because they distinguished Jones on the facts, or because they avoided the question under the good-faith exception to the exclusionary rule. See, e.g., United States v. Graham, 846 F.Supp.2d 384 (D.Md. 2012).
In the last week, two district courts have divided on the question: United States v. Ringmaiden (D. Ariz. May 8, 2013), and United States v. Powell, — F.Supp.2d –, 2013 WL 1876761 (E.D. Mich May 3, 2013) In this post, I want to discuss the two rulings, and then offer some critical commentary on Powell at the end.
Read more on The Volokh Conspiracy.

(Related) We can, therefore we must? (Remember, “To Serve Man” is a Twilight Zone cookbook) Note that the sensors can tell what department you are in (and that is no doubt logged with a time stamp), but can't follow from deparment to department (except by arranging the deparments in time sequence). Does no one ever read this stuff before publishing?
CBS in Dallas-Forth Worth reports:
Nordstrom says it wants to serve you better, so it’s tracking your movements through their stores. The CBS 11 I-Team has learned the retailer is using software to track how much time you spend in specific departments within the store. The technology is being used in 17 Nordstrom and Nordstrom Rack stores nationwide, including the NorthPark store in Dallas.
A company spokesperson says sensors within the store collect information from customer smart phones as they attempt to connect to Wi-Fi service. The sensors can monitor which departments you visit and how much time you spend there.
However, the sensors do not follow your phone from department to department, nor can they identify any personal information tied to the phone’s owner, says spokesperson Tara Darrow.
Read more on CBSDFW.
So if you want to shop and don’t want to contribute to their “aggregate” information, you have to shut off your phone? I guess they can get away with this, but should they be able to?

(Related) For my Ethical Hackers
"A researcher has found that Apple user locations can be potentially determined by tapping into Apple Maps and he has created a Python tool to make the process easier. iSniff GPS accesses Apple's database of wireless access points, which is collected by iPhones and iPads that have GPS and Wi-Fi location services enabled. Apple uses this crowd-sourced data to run its location services; however, the location database is not meant to be public. You can download the tool via Giuthub."


A clear explanation...
Why facial recognition tech failed in the Boston bombing manhunt
In the last decade, the US government has made a big investment in facial recognition technology. The Department of Homeland Security paid out hundreds of millions of dollars in grants to state and local governments to build facial recognition databases—pulling photos from drivers' licenses and other identification to create a massive library of residents, all in the name of anti-terrorism. In New York, the Port Authority is installing a "defense grade" computer-driven surveillance system around the World Trade Center site to automatically catch potential terrorists through a network of hundreds of digital eyes.
But then an act of terror happened in Boston on April 15. Alleged perpetrators Dzhokhar and Tamerlan Tsarnaev were both in the database. Despite having an array of photos of the suspects, the system couldn't come up with a match. Or at least it didn't come up with one before the Tsarnaev brothers had been identified by other means.
For people who understand how facial recognition works, this comes as no surprise. Despite advances in the technology, systems are only as good as the data they're given to work with. Real life isn't like anything you may have seen on NCIS or Hawaii Five-0. Simply put, facial recognition isn't an instantaneous, magical process. Video from a gas station surveillance camera or a police CCTV camera on some lamppost cannot suddenly be turned into a high-resolution image of a suspect's face that can then be thrown against a drivers' license photo database to spit out an instant match.


Nothing new to my Ethical Hackers, but it might amuse my Intro to IT students.
Use These Secret NSA Google Search Tips to Become Your Own Spy Agency
There’s so much data available on the internet that even government cyberspies need a little help now and then to sift through it all. So to assist them, the National Security Agency produced a book to help its spies uncover intelligence hiding on the web.
The 643-page tome, called Untangling the Web: A Guide to Internet Research (.pdf), was just released by the NSA following a FOIA request filed in April by MuckRock, a site that charges fees to process public records for activists and others.
The book was published by the Center for Digital Content of the National Security Agency, and is filled with advice for using search engines, the Internet Archive and other online tools. But the most interesting is the chapter titled “Google Hacking.”
… Lest you think that none of this is new, that Johnny Long has been talking about this for years at hacker conferences and in his book Google Hacking, you’d be right. In fact, the authors of the NSA book give a shoutout to Johnny, but with the caveat that Johnny’s tips are designed for cracking — breaking into websites and servers. “That is not something I encourage or advocate,” the author writes.

Wednesday, May 08, 2013

Is your bad programming automatically fraud on my part? If not, I'm moving to Reno.
Feds Drop Hacking Charges in Video-Poker Glitching Case
They know when to fold ‘em. Las Vegas prosecutors targeting two men who took advantage of a software bug to win a small fortune at video poker have dropped all hacking charges from the case, cashing out an 18-month legal battle over the applicability of the 1986 Computer Fraud and Abuse Act.
“The United States of America, by and through the undersigned attorneys, hereby moves this Court to dismiss Counts 2 and 3 of the Indictment,” wrote(.pdf) Assistant U.S. Attorney Michael Chu yesterday, in a terse motion immediately granted by U.S. District Judge Miranda Du.
Du had asked prosecutors to defend their use of the federal anti-hacking law by Wednesday, in light of a recent 9th Circuit ruling that reigned in the scope of the CFAA.
The dismissal leaves John Kane, 54, and Andre Nestor, 41, facing a single remaining charge of conspiracy to commit wire fraud — another federal law that generally criminalizes fraudulent schemes that use wire communications. Trial is set for August 20.
… Prosecutors had argued that the complex sequence of button presses needed to activate the bug made it a form of hacking. But defense lawyers argued that Kane and Nestor only played by the rules imposed by the machine.
“The case never should have been filed under the CFAA,” says Kane’s lawyer, Andrew Leavitt. “It should have been just a straight wire fraud case. And I’m not sure its even a wire fraud. I guess we’ll find out when we go to trial.”


Failure to verify your customers in this case means you could be selling to an Identity Thief. I wonder how the letters were worded? “Please stop breaking the law or we'll have to send you a much firmer warning...”
Grant Gross reports:
More than 20 percent of data brokers checked by the U.S. Federal Trade Commission allegedly violated a U.S. privacy law when sharing personal data with agency workers posing as companies wanting to purchase information.
This week, the FTC warned 10 data brokers, most with a significant online presence, that they may be violating the Fair Credit Reporting Act (FCRA).
The FCRA requires consumer reporting agencies to reasonably verify the identities of data customers and to ensure that these customers have a legitimate purpose for receiving the information.
Read more on Computerworld.


Is the data required or merely 'easily available?'
Robyn Greene writes:
Last week served as yet another reminder of the threats posed to Americans’ privacy by the post-Patriot Act surveillance state. According to the Department of Justice’s annual report, FISA applications to the secretive Foreign Intelligence Surveillance Court (FISC) in 2012 revealed a continued increase in the FBI’s surveillance of Americans. The report covers the Bureau’s requests for electronic and physical surveillance, secret court orders under Section 215 of the Patriot Act, and National Security Letters (NSLs).
Over the last four years, the government’s requests for electronic and physical surveillance have steadily increased after a brief decline in 2008 and 2009, with a total of 1,856 applications in 2012. However, the truly shocking number is how many times it applied for Section 215 orders, also known as business records requests, which as far as we know give the government extremely broad authority to access “any tangible thing,” including sensitive information such as financial records, medical records, and even library records.
Read more on ACLU’s Blog.

(Related) “Give us access to everthing and we'll probably find something.”
Charlie Savage reports:
The Obama administration, resolving years of internal debate, is on the verge of backing a Federal Bureau of Investigation plan for a sweeping overhaul of surveillance laws that would make it easier to wiretap people who communicate using the Internet rather than by traditional phone services, according to officials familiar with the deliberations.
Read more on the NY Times.
[From the article:
I think the F.B.I.’s proposal would render Internet communications less secure and more vulnerable to hackers and identity thieves,” said Gregory T. Nojeim of the Center for Democracy and Technology. “It would also mean that innovators who want to avoid new and expensive mandates will take their innovations abroad and develop them there, where there aren’t the same mandates.”


Can't tell the players without a scorecard...
May 07, 2013
EPIC - Senate Confirms Chairman of Privacy and Civil Liberties Oversight Board
EPIC: "Today the Senate voted to confirm David Medine as the Chairman of the Privacy and Civil Liberties Oversight Board (PCLOB), an agency established to review executive branch actions and to protect privacy and civil liberties after 9/11. EPIC urged the creation of an independent privacy agency after 9/11. At the first meeting of the agency in 2012, EPIC set out several priorities for PCLOB, including (1) suspension of the fusion center program, (2) limitations on CCTV surveillance, (3) removal of airport body scanners, (4) establishing privacy regulation for drones, (5) updating data disclosure standards, and (6) ensuring Privacy Act adherence. For more information, see EPIC: The 9/11 Commission Report and EPIC: The Sui Generis Privacy Agency."


For my Intro to IT class...
… today you an rest assured that anyone who wants to know anything about you has already typed your name in Google. But what did they find when they did that? Did they actually find information about you? Was it information you really wanted them to have? And who are those people who might be searching for your name on Google?


For my Statistics class. Can we determine why?
May 07, 2013
BJS - Firearm Violence, 1993-2011
Michael Planty, Ph.D., Jennifer L. Truman, Ph.D. May 7, 2013. NCJ 241730. "Presents trends on the number and rate of fatal and nonfatal firearm violence from 1993 to 2011. The report examines incident and victim demographic characteristics of firearm violence, including the type of firearm used; victim's race, age, and sex; and incident location. The report also examines changes over time in the percentages of nonfatal firearm crimes by injury, reporting to the police, and the use of firearms in self-defense. Information on homicide was obtained primarily from the Centers for Disease Control's (CDC) National Vital Statistics System. Nonfatal firearm violence data are from the National Crime Victimization Survey (NCVS), which collects information on nonfatal crimes reported and not reported to the police against persons age 12 or older from a nationally representative sample of U.S. Households. Highlights:
  • Firearm-related homicides declined 39%, from 18,253 in 1993 to 11,101 in 2011.
  • Nonfatal firearm crimes declined 69%, from 1.5 million victimizations in 1993 to 467,300 victimizations in 2011.
  • Firearm violence accounted for about 70% of all homicides and less than 10% of all nonfatal violent crime from 1993 to 2011.
  • From 1993 to 2011, about 70% to 80% of firearm homicides and 90% of nonfatal firearm victimizations were committed with a handgun.


Since I spend too much time working with students who aren't ready, this is interesting...
May 07, 2013
Report - What Does It Really Mean to Be College and Work Ready?
"Today the National Center on Education and the Economy (NCEE) released What Does It Really Mean to Be College and Work Ready?, a study of the English Literacy and Mathematics required for success in the first year of community college. During a day-long meeting with key education and policy leaders, NCEE will discuss the results of the study and its implications for community college reform, school reform, teacher education, the common core state standards, and vocational education and the workplace."
Helpful Links:


Have an idea for a MOOC?
George Veletsianos (an Associate Professor in the School of Education and Technology at Royal Roads University in Victoria, BC) and I have submitted an application for Iversity’s MOOC production fellowship program. If funded, we will co-teach a course titled “Foundations of Educational Technology.” (If not funded, we’ll figure something else out…)
… The recipients of the Iversity MOOC fellowship will be chosen through a combination of peer review and public voting, and George and I would love your support for the latter. To vote for our proposal, you do have to register on the platform (ugh) first. You can also read more about the class there.
George has more details on his blog too, including an awesome list of other friends, colleagues, professors, and grad students who’ve volunteered to help.

Tuesday, May 07, 2013

“Oh, you noticed that we broke into your home? Don't worry, we were just testing your security.”
Associated Press reports:
The Speaker of the Missouri House says an attempt to access a secure website listing Missouri’s concealed gun permit holders was part of an investigation into whether the state had appropriately shielded the information.
In an interview with The Associated Press, House Speaker Tim Jones, R-Eureka, declined Monday to identify the person who tried to access the information last Thursday. But Jones said it was an appropriate action.
Read more on KY3.
So wait… when researchers attempt to test the security of systems, they can get prosecuted criminally, but state legislators can grant themselves permission to attempt to hack a state database and that’s okay?
[From the article:
Those attempts were unauthorized because information on concealed gun permit holders can only be shared with law enforcement.


“What do they know and how long will they keep it?”
The Electronic Frontier Foundation (EFF) and the American Civil Liberties Union of Southern California (ACLU-SC) today jointly filed suit against two Los Angeles-area law-enforcement agencies over their failure to produce records related to the use of automatic license plate readers (ALPRs).
Mounted on squad cars and telephone poles, these sophisticated camera systems read license plates and record the time, date, and location a particular car was encountered. EFF and the ACLU-SC filed requests with the Los Angeles Police Department and the Los Angeles County Sheriff’s Department under the California Public Records Act seeking documents relating to policy and training on ALPRs, as well as a week’s worth of ALPR data collected by the agencies in 2012. While the sheriff and police departments produced some materials, they failed to provide documents related to sharing information with other agencies, and neither agency has produced the data collected during the one-week period.
“Location-based information like license plate data can be very revealing,” said EFF Staff Attorney Jennifer Lynch. “By matching your car to a particular time, date and location — and building a database of that information over time — law enforcement can learn where you work and live, what doctor you go to, which religious services you attend, and who your friends are. The public needs access to data the police actually have collected to be able to make informed decisions about how ALPR systems can and can’t be used.”
… While the police can use this technology to match license plates against databases to find stolen or wanted cars, the systems currently record and store information on every car, even where there’s no reason to think a car is connected to any crime.


Is this “playing nice?” Will China pass a law requiriing Texas to turn over data?
Karen Brooks Harper reports:
A minor dustup over the protection of private info hosted by ISPs flared up briefly on the floor, on a bill by Rep. John Frullo that would allow Texas judges to issue search warrants for companies based in other states – like Yahoo in California – to hand over online records that could help them investigate crimes relating to cases like child pornography and human trafficking.
Frullo briefly tried to fend off an amendment by Bedford GOP Rep. Jonathan Stickland that requires law enforcement to get a warrant before they can get emails from an ISP that are over 180 days old.
Read more on Dallas Morning News. And see Grits for Breakfast for comments on this development.


Finally someone will smack these lawyers?
Judge Asks IRS, Feds to Investigate Copyright-Trolling Attorneys
Using terms like “brazen conduct and relentless fraud,” a federal judge on Monday sanctioned attorneys running a BitTorrent copyright lawsuit factory, and recommended federal prosecutors investigate for potential criminal charges.
Los Angeles federal judge Otis D. Wright II said the Prenda Law attorneys’ “moral turpitude” is “unbecoming of an officer of the court.” (.pdf) The judge said the attorneys “fraudulently signed” documents about who owned the rights to sue thousands over the illegal downloading of pornographic films.
The attorneys, including John Steele, a Chicago barrister who has sued thousands for unlawfully downloading porn, were also labeled a racketeering outfit.
The judge often used Star Trek references as he blasted them.
“The federal agency eleven decks up is familiar with their prime directive and will gladly refit them for their next voyage. The Court will refer this matter to the United States Attorney for the Central District of California. The will also refer this matter to the Criminal Investigation Division of the Internal Revenue Service and will notify all judges before whom these attorneys have pending cases.”
Kurt Opsahl, an intellectual property attorney with the Electronic Frontier Foundation, said the judge’s opinion underscores “the ease of which you can file copyright lawsuits.”
… “Plaintiffs have outmaneuvered the legal system. They’ve discovered the nexus of antiquated copyright laws, paralyzing social stigma, and unaffordable defense costs,” the judge wrote.
Adding insult to injury, the lawyers were ordered to pay $40,000 in legal fees and the same in sanctions.


I thought this would be a 1 word report: “Nuts!”
May 06, 2013
Military and Security Developments Involving the Democratic People’s Republic of Korea 2012
DOD - Military and Security Developments Involving the Democratic People’s Republic of Korea 2012. A Report to Congress Pursuant to the National Defense Authorization Act for Fiscal Year 2012.
  • "Section 1236 of the National Defense Authorization Act for Fiscal Year 2012, Public Law 112-81, provides that the Secretary of Defense shall submit a report "in both classified and unclassified form, on the current and future military power of the Democratic People's Republic of Korea" (DPRK). The report shall address an assessment of the security situation on the Korean Peninsula, the goals and factors shaping North Korean security strategy and military strategy, trends in North Korean security, an assessment of North Korea's regional security objectives, including an assessment of the North Korean military's capabilities, developments in North Korean military doctrine and training, an assessment of North Korea's proliferation activities, and other military security developments." [Greta E. Marlatt]

(Related) Nothing new here...
U.S. says Chinese government behind cyberespionage
The Chinese government and military have engaged in widespread cyberespionage targeting U.S. government and business computer networks, the Pentagon said Monday.
China maintained a steady campaign of computer intrusions in 2012 that were designed to acquire information about the U.S. government's foreign policy and military plans, according to the Pentagon's annual report to Congress on China's military.
"China is using its computer network exploitation capability to support intelligence collection against the U.S. diplomatic, economic, and defense industrial base sectors that support U.S. national defense programs," according to the 83-page 2013 "Military and Security Developments Involving the People's Republic of China" (PDF).


For the Crypto class...
May 06, 2013
Revolutionary Secrets: Cryptology in the American Revolution
Revolutionary Secrets: Cryptology in the American Revolution, Jennifer Wilcox, Center for Cryptologic History, National Security Agency, 2012.


Another take on the “Freemium” model?
Google nears launch of paid YouTube subscriptions, report says
The information comes from a Financial Times report over the weekend that suggests the company could be rolling out paid subscriptions for over 50 different premium channel partners. The subscriptions will reportedly set you back about $2 per month, per channel.
We heard rumblings about paid YouTube subscriptions back in January, with the video service rumored to have been in discussions with several of its channel partners about a new subscription-based program. It was also said that those subscriptions would range between $1 and $5 per month, which is in line with the FT report.
Google is currently making plenty of money on YouTube videos, but the company realizes it’s hitting a brick wall when it comes to gaining the kind of content that people desire from other video services. The company has already spent upwards of $200 million to market and cultivate premium content through its channel partners, but so far it’s still not lucrative enough for those partners. The subscription would likely be another source of revenue both for Google and those content creators.

(Related) Resolving the “First Sale” question?
"According to CNET and various other sources, CS6 will be the last version of Adobe's Creative Suite that will be sold in the traditional manner. All future versions will be available by subscription only, through Adobe's so-called 'Creative Cloud' service. This means that before too long, anyone who wants an up-to-date version of Photoshop won't be able to buy it – they will have to pay $50 per month (minimum subscription term: one year). Can Adobe complete the switch to subscription-only, or will the backlash be too great? Will this finally spur the creation of a real competitor to Photoshop?"


For my phone and tablet packing students.
Office Suite Pro 7 (PDF &HD) Made by MobiSystems, OfficeSuite Pro allows you to view, create, edit, print and share Word, Excel and PowerPoint files on the go.

Monday, May 06, 2013

No mention of a computer, but still an interesting insider job.
Anthony Dowsley reports:
The lives of informers and police officers have been put at risk over the “gravest” of leaks from inside the force.
Police raids across Melbourne three weeks ago discovered volumes of confidential and sensitive police files dating back three years.
So far, a junior police officer from the northern metro region has been suspended without pay after sensitive police documents were found at three addresses.
Chief Commissioner Ken Lay today described the breach as “damaging and horrible”.
One of the locations raided had direct links to an outlaw motorcycle gang, and some of the files involved organised crime.
Those most at risk are believed to be criminals who have co-operated with police.
Read more on The Telegraph.


Lot's of ways this could have been 'leaked' to the defense. How would they determine the leak was based on the stolen information?
From the Daily Mail:
The psychologist who testified in the Jodi Arias murder trial had her laptop stolen in February, just weeks before she was slated to testify in the highly publicized murder trial, a new report has revealed.
Dr Janeen Demarte told police that the computer contained notes that pertained to the murder trial.
Read more on Daily Mail
The notes were not encrypted, nor even password-protected according to the report. Even more disturbingly, this sounds like it might have been a targeted theft, as jewelry and cash were not taken.


Art, pornography, terrorism. It's all in the eye of the beholder.
"A Methusen, Mass. high schooler, who goes by the rapper name 'Cammy Dee' has been arrested after posting lyrics that police felt were 'communicating terrorist threats.' This wouldn't be the first time rap lyrics were investigated, but if formally charged for 'communicating terrorist threats' this would a set a chilling low bar for terrorist investigations."
[From the article:
He faces up to 20 years in state prison if convicted on one count of making a bomb threat. [and he is being held without bail. Bob]


Everyone is curious. End of story.
Shirie Leng, M.D., writes:
I am affiliated with the institution where Dzhokhar Tsarnaev is currently hospitalized. I am friends with people who have treated him. I’m trying to stay away from those people; I would be unable to help asking them about him. They might be unable to help talking about him.
There has been a flurry of emails and red-letter warnings cautioning people here not to talk about Mr. Tsarnaev or look him up on the EMR (electronic medical record) system. Despite this, there have been leaks of information and photos from various sources. It is virtually impossible to keep people from asking about him and talking about him. Curiosity is human nature. When human nature comes up against morals and laws, human nature will win a good percentage of the time.
Read more on KevinMD.


Why we will never, ever be able to ban drones.
This August, drones will drop payloads all over South Africa's OppiKoppi music festival, and there's a good chance no one will mind. Probably because the payload is beer.
Customers thirsty for beer will order beer with their phones, then someone will attach a parachute to a beer, load that beer into an octorotor, and the octorotor will fly overhead, release the beer, and the beer parachutes to the person who ordered it (hopefully).
For test flights, the drone is remotely piloted, but the goal is to make the process far more autonomous, with drones flying themselves to coordinates on a GPS delivery grid.

(Related) No doubt we'll need a new law.
9-inch helicopter retrieved from Ohio statue
… After a week of back-and-forth about who was responsible for retrieving the device, how it could be done and how much it would cost, it took nothing more than a man hanging out of a window with a long pole to fetch the 2-pound, 9-inch device, which is equipped with a camera and cost $1,500.
The Columbus Dispatch reports that the device was recovered Saturday, a week after it flew into the Lady Justice statue on top of the courthouse, coming to rest on the hilt of her sword more than 100 feet off the ground.
… "Look," the sheriff told The Columbus Dispatch. "Let's put this in perspective. He ran a helicopter into county property. It's no different than if someone hit the courthouse with their car. We took a report. We're done."


The ultimate threat? I bug you daily with my blog, but the dose is small. Imagine a whole book of “Bob quotes” – perhaps in time to be a stocking stuffer at Christmas?
Sunday, May 5, 2013
Three Ways to Your Blog Into a Book
The end of the school year is quickly approaching. If your students have been blogging all year one way to show them, their parents, and others how much they've written is to turn the blog into a book. Here are a few methods for turning a blog into a book.
1. If you have a relatively small number of posts (25 or so) you could just copy and paste the text into a Word, Pages, or Google Drive document. Then you can export it as a PDF and or print it.
2. BlogBooker is a free service that allows you to turn your the contents of your Blogger blog into a PDF. Using BlogBooker is a fairly straight-forward process. BlogBooker walks you through each step of the process except for the very first step which might sound a little too "techy" for some Blogger users, but it's actually quite easy. The first step in using BlogBooker is to export the contents of your blog as an XML file. This is actually easy to do in Blogger. Step one is to open the "settings" menu of your Blogger blog. Step two is to select "export blog" under "basic" menu. Step three is to click "download." Don't worry, exporting the contents of your blog will not remove any content from your blog. After you've completed the export process, jump over to BlogBooker and follow their directions for completing the transition from XML file to PDF.
3. Anthologize is a free WordPress plug-in that allows you to take your posts and arrange them into an ebook. Anthologize features a drag and drop interface for arranging the layout of your ebook. Anthologize will only work for self-hosted blogs not on WordPress.com blogs.

Sunday, May 05, 2013

How would the FBI hide this? If it is never mentioned directly in court, is the defense unable to “discover” it? Would a direct question, (Did you do something like the Guardian article said you did?) be sufficient to open that can of worms?
Glenn Greenwald’s piece in The Guardian is your must-read for this weekend. Here’s a snippet:
On Wednesday night, Burnett interviewed Tim Clemente, a former FBI counterterrorism agent, about whether the FBI would be able to discover the contents of past telephone conversations between [Katherine Russell and her husband, deceased bombing suspect Tamerlan Tsarnaev]. He quite clearly insisted that they could:
BURNETT: Tim, is there any way, obviously, there is a voice mail they can try to get the phone companies to give that up at this point. It’s not a voice mail. It’s just a conversation. There’s no way they actually can find out what happened, right, unless she tells them?
CLEMENTE: “No, there is a way. We certainly have ways in national security investigations to find out exactly what was said in that conversation. It’s not necessarily something that the FBI is going to want to present in court, but it may help lead the investigation and/or lead to questioning of her. We certainly can find that out.
BURNETT: “So they can actually get that? People are saying, look, that is incredible.
CLEMENTE: “No, welcome to America. All of that stuff is being captured as we speak whether we know it or like it or not.”
Read more on The Guardian.


Bruce always demonstrates a grasp of the obvious that others seem to lack...
"Bruce Schneier, security expert (and rational voice in the wilderness), explains in an editorial on CNN why 'Connecting the Dots' is a 'Hindsight Bias.' In heeding calls to increase the amount of surveillance data gathered and shared, agencies like the FBI have impaired their ability to discover actual threats, while guaranteeing erosion of personal and civil freedom. 'Piling more data onto the mix makes it harder, not easier. The best way to think of it is a needle-in-a-haystack problem; the last thing you want to do is increase the amount of hay you have to search through. The television show Person of Interest is fiction, not fact.'"


Now this would be interesting if they had reported a few details...
"The CCTV cameras operated by the local government in the country town of Nowra, NSW (Australia) have been turned off following an order by the Administrative Decisions Tribunal. The local government is crying because it believes that it is losing an effective method in combating crime in public. Locals however are rejoicing that they are no longer being recorded whilst walking down the street."
[From the article:
After allegations made by a member of the public, only identified as SF, that the council had used its CCTV cameras to obtain personal information from him, the council was ordered to refrain from any conduct or action in contravention of the act.


Does this mean the US government will never make the same claim?
"U.S. officials have told the Indian Government that they will not be able to serve summons to the executives of companies like Google and Facebook because they are not convinced that the content hosted on these sites can cause violence and that these summons impact 'free speech principles.' The reply comes as a response to India's request to the US to help serve papers to 11 Internet companies accused of hosting content on their sites that was meant to fuel communal hatred and violence. The U.S. authorities said that there are limitations when it comes to protection on free speech — when the speech comprises a true threat or provokes imminent violence — but in this particular case there is not sufficient evidence of either of these."


Typical government long windedness...
May 04, 2013
FTC Issues Updated FAQs on Amended Children's Online Privacy Protection Rule
"The Federal Trade Commission has issued an updated set of frequently asked questions designed to help website operators, mobile application developers, plug-ins and advertising networks operating on child-directed websites and online services prepare for upcoming changes to the Children’s Online Privacy Protection Rule. The document, titled Complying With COPPA: Frequently Asked Questions contains information directed to websites and online services whose work online may involve the collection of personal information from children under age 13. The document provides guidance from the FTC staff that supplements the rule and other COPPA–related material previously published by the FTC."


For my Data Analysis class.
May 04, 2013
How lawyers are mining the information mother lode for pricing, practice tips and predictions
  • "Law firms are using big data to identify which cases will be easy slam dunks and those that are air balls. They’re relying on the technology to get a read on what other law firms are charging, so they can adjust their rates accordingly. And big data is also popping up in law firm human resources departments, where tech-savvy department heads are crunching data on potential new hires in the hopes of coming up with recruits who are truly a good fit."


For my Geek friends who find an App that does almost everything they want...


For my amusement (like all the other articles)
… Professors in the philosophy department at San Jose State University penned an open letter to Harvard professor Michael Sandel, famous for his class on “Justice.” “There is no pedagogical problem in our department that JusticeX [the edX version of the Justice class] solves, nor do we have a shortage of faculty capable of teaching our equivalent course,” they write. “Professors who care about public education should not produce products that will replace professors, dismantle departments and provide a diminished education for students in public universities.” [Perhaps they worry that they won't be selected as the “Best” teacher for that class? Bob]
… According to a Gallup poll of college presidents, only 3% surveyed believe that MOOCs will improve the learning of all students. 2% said they think MOOCs will solve universities’ financial troubles. More details via Inside Higher Ed, which worked with Gallup on the survey.
Washington State’s Open Course Library has released openly licensed course materials for 39 university courses (it released 42 others a year and a half ago). Along with the release of materials, the state’s student public interest research group says that it’s found that the “The Open Course Library has saved students $5.5 million in textbook costs to date, including $2.9 million during the 2012–2013 academic year alone.”
OpenStax College, a Rice University OER initiative, says it plans to double the number of fields that its open textbooks cover by 2015. More details via Inside Higher Ed.