Thursday, March 17, 2016

In today's business environment, the ONLY report of multi-million dollar transactions is a paper printout? This looks very well planned for a hack foiled by a misspelling.
Broken printer costs Bangladesh $100mn in cyber heist
… It took the regulator nearly four days to discover the problem and ask banks across the globe to halt payments to the hackers after the central bank's joint director Zubair bin Huda had noticed a glitch with a printer on February 5. The printer was set up to automatically print all SWIFT wire transfers.
"Since such glitches happened before, we thought it was a common problem just like any other day," Huda said in the complaint.
He then tried and failed to print out the messages manually from the SWIFT system.
The theft happened on Friday, a weekend in Muslim Bangladesh, so the official says he left the office and asked his colleagues to help fix the problem.
After the system was rebooted more than 24 hours later, the employees managed to print the receipts. They revealed dozens of questionable transactions to the Philippines, Sri Lanka and elsewhere.
The receipts showed the Federal Reserve Bank of New York had sent back queries to Bangladesh Bank against 46 payment orders in different messages.


(Related)
Man in Manila gets $30 million cash from cyber heist; Bangladesh central bank governor quits
Bangladesh's central bank governor resigned on Tuesday over the theft of $81 million from the bank's U.S. account, as details emerged in the Philippines that $30 million of the money was delivered in cash to a casino junket operator in Manila.
The rest of the money hackers stole from the Bangladesh Bank's account at the New York Federal Reserve, one of the largest cyber heists in history, went to two casinos, officials told a Philippines Senate hearing into the scandal.
… Bangladesh Bank is also working with anti-money laundering authorities in the Philippines, where it suspects the stolen $81 million arrived in four tranches.
The Philippines' Rizal Commercial Banking Corp (RCBC) (RCB.PS) said last week it was investigating deposits amounting to just that sum, which were made at one of its branches.
… CCTV cameras at the branch were not functioning when the money was withdrawn, RCBC's anti-money laundering head, Laurinda Rogero, told the Senate hearing.
The president of a foreign exchange broker called Philrem Service Corp, Salud Bautista, told the Senate that her firm was instructed by the bank branch to transfer the funds to a man named Weikang Xu and two casinos.
She said that $30 million went to Xu in cash. Guingona has said Xu was ethnic Chinese and a foreigner, but he was not sure if he was a Chinese national.




Still not a huge breach, but another case of an organization unable to quickly determine what happened.
Well, I may have to walk back some of my praise for outdoor gear company Bailey’s after I first read and reported on a payment card breach they discovered and disclosed.
The firm has updated its breach disclosure after subsequently discovering that the breach did not begin in September, 2015, and it wasn’t 15,000 affected. According to their updated notification, the breach began in December, 2011 and affected 250,000.
They still get brownie points for transparency, but lost a few points for having a breach go undetected for so many years.




Beware of hackers sending phishing emails warning of hackers sending phishing emails!
TASS reports:
Hackers attacked dozens of Russian banks by sending letters on behalf of FinCert on Tuesday, March 15, Kaspersky Lab said in a report on Wednesday.
FinCert is a structure of the Central Bank, which warns financial institutions of cyber threats.
“On March 15, dozens of Russian banks became targets of cyberattacks by means of sending malicious messages to electronic addresses of their employees. The peculiarity of this attack was that cybercriminals posed as FinCert, a special department of the Central Bank, created about a year ago to inform Russian banks on security incidents in the financial sector,”- according to the report.
Read more on TASS.
[From the article:
The malefactors registered the domain name fincert.net, which allowed them to send letters from the addresses similar to the current address of FinCert.
Their letters contained alleged security files which in reality were malicious software. The download of the files allowed attackers to gain access to the information system of the banks.
The newsletters were sent as addressed mails – each letter started with the name of a specific recipient. Cybercriminals had collected a special database of contacts, presumably on the basis of the materials of industry conferences or official documents of a number of banks.




Another government entity going after poor security planning. A trend I approve!
First: refresh your memory of a 2011 breach involving Accretive Health, a business associate of North Memorial Hospital.
Then read HHS’s press release how that breach just cost North Memorial Hospital $1.55 million, and why:
$1.55 million settlement underscores the importance of executing HIPAA business associate agreements
North Memorial Health Care of Minnesota has agreed to pay $1,550,000 to settle charges that it potentially violated the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules by failing to enter into a business associate agreement with a major contractor and failing to institute an organization-wide risk analysis to address the risks and vulnerabilities to its patient information.
[Much omitted Bob]
In addition to the $1,550,000 payment, North Memorial is required to develop an organization-wide risk analysis and risk management plan, as required under the Security Rule. North Memorial will also train appropriate workforce members on all policies and procedures newly developed or revised pursuant to this corrective action plan.
The Resolution Agreement and Corrective Action Plan can be found on the HHS website at: http://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/north-memorial-health-care/index.html.




A warning for my vets.
Free phone scam targets veterans
… The FTC has posted a warning for veterans who are approached by someone offering a cell phone and service for free. And to make the scammer seem even more legitimate, they set up shop in booths outside of VA facilities.
Here’s the scam: a couple months after a veteran signs up, they will get a letter notifying them that they need to send their personal information. Additionally, they are asked to send documentation proving their income meets the low-income requirements.




A warning for me.
American Express Warns Cardholders of Data Breach
American Express informed customers last week that their payment card information may have been compromised after a third party service provider suffered a data breach.
Information associated with current or previously issued American Express cards, including account numbers, names and expiration dates, might have been obtained by unauthorized parties, Amex said in a data breach notice submitted to California’s attorney general.
… It’s worth pointing out that the breach is dated December 7, 2013 on the website of California’s attorney general. [No date on the Amex notice Bob] The name of the affected service provider, which Amex says is engaged by numerous merchants, has not been made public.
“This breach is another example of a broken chain of custody with confidential data. AMEX protects it, but then relinquishes control to another party that has weak controls which the bad actors know how to exploit.
... “As an AMEX card user myself, one of the things that I have done is turn on the immediate notification when a purchase is made with the card or when the card is not present. Members can choose the amount limit on the transaction and the type of notification (text, email, etc.) It gives users immediate notification, as well as some level of peace of mind,” Blake added.




For my Disaster Recovery students. Two systems in case one fails?
Apple said to move part of cloud business from AWS to Google
Apple has moved some of its iCloud and services data from Amazon Web Services to Google's cloud platform, in what is seen as a bid by the iPhone maker to diversify its cloud service providers, according to reports.
The move comes even as the company is building its own new data centers, leading to speculation whether the shift is only temporary.




The big “out?” “The NSA wouldn't give me use a secure device, so I secured my own email”
NSA dismissed Clinton request for ‘secure’ BlackBerry
Federal intelligence officials rebuffed an early effort by Hillary Clinton’s top aides to provide her with a “secure ‘BlackBerry-like’” device to use while serving as secretary of State, according to new emails released Wednesday.
Emails released as part of an open records lawsuit from conservative legal watchdog Judicial Watch show that the National Security Agency (NSA) rebuffed requests from the State Department in February of 2009 to find a replacement for Clinton’s mobile device.
… It’s unclear from the emails how the matter was ultimately resolved.




Politics overrides all that Law School training?
The Law is Clear: The FBI Cannot Make Apple Rewrite its OS
Every once in a while, President Obama removes his Law Professor in Chief hat and puts on his I Get Terrifying Briefings Every Day hat.
… The problem for the president is that when it comes to the specific battle going on right now between Apple and the FBI, the law is clear: twenty years ago, Congress passed a statute, the Communications Assistance for Law Enforcement Act (CALEA) that does not allow the government to tell manufacturers how to design or configure a phone or software used by that phone — including security software used by that phone.
CALEA was the subject of intense negotiation — a deal, in other words. The government won an extensive, specific list of wiretapping assistance requirements in connection with digital communications. But in exchange, in Section 1002 of that act, the Feds gave up authority to “require any specific design of equipment, facilities, services, features or system configurations” from any phone manufacturer. The government can’t require companies that build phones to come to it for clearance in advance of launching a new device. Nor can the authorities ask a manufacturer to design something new — like a back door — once that device is out.




Perhaps this would keep you from starting your car with your smartphone and call you an Uber ride instead?
Machine-Learning Algorithm Identifies Tweets Sent Under the Influence of Alcohol
… Today, these guys show how they’ve trained a machine to spot alcohol-related tweets. And they also show how to use this data to monitor alcohol-related activity and the way it is distributed throughout society. They say the method could have a significant impact on the way we understand and respond to the public health issues that alcohol and other activities raise.




Perspective.
WeChat still unstoppable, grows to 697m active users
WeChat, Tencent’s popular messaging app, is still growing fast. It added nearly 200 million monthly active users (MAUs) in the past year.
… Tencent did not disclose how many of WeChat’s users are in mainland China versus other areas. But it’s clear that WeChat is focused on mainland China from the number of the app’s features that are limited just to its home nation, such as online and in-store payments via the WeChat Pay feature.




For my Data Management students to consider.
Can an App-only E-commerce Model Succeed in India?




Tools & Techniques
How to Make a Screencast Tutorial for YouTube
One of the most popular types of YouTube video is the screencast — the desktop tutorial that shows you how to do almost anything, from making better use of the Windows 10 shell, to something simple like switching your desktop theme.
If you’ve ever considered making such a video, you’ll be happy to know that they’re remarkably straightforward to produce, so much so that YouTube even offers a tool to help you make it happen




Gack! We are too lazy to learn Cursive now that we can thumb our messages into a smartphone – and now this?
Nike’s first official self-tying sneakers go on sale this year
Nike made a number of new product announcements at a glitzy event in New York yesterday, but perhaps the most exciting revelation was that the company is finally bringing a pair of self-tying sneakers to market — just like in that movie.
While Nike has teased prototypes and versions of the shoe from Back to the Future 2 in the past, with the HyperAdapt 1.0, the American sports apparel giant is finally bringing a pair of the futuristic wonders to market for anyone to buy. The sneakers sport “adaptive lacing” technology, which can automatically adjust the snugness of the shoe. “When you step in, your heel will hit a sensor and the system will automatically tighten,” said Tiffany Beers, Nike’s senior innovator, in a press release. “Then there are two buttons on the side to tighten and loosen. You can adjust it until it’s perfect.”




It might be fun to read these lines and see how many of my students recognize them. But then again, it might just be depressing. (and why does Douglas Adams rate two mentions?)
Do You Remember These First Lines From Famous Books?
If you’ve ever attempted to learn to write a book, one of the very early lessons you were told is that you need to hook to reader right away. Many of the best pieces of literature start off with an opening line that’s so memorable and engaging that you can’t help but keep going.
It’s with that in mind that we take a peek at this awesome infographic that shows off some of the most compelling opening lines in literature’s long history.
How many of them do you remember from the first time you read the books?


Wednesday, March 16, 2016

For my Computer Security class. It's your fellow employees who will doom your entire security program unless you can drum this lesson into them.
Stealing Nude Pics From iCloud Requires Zero Hacking Skills -- Just Some YouTube Guides
The Department of Justice yesterday charged a 36-year-old man with stealing nude photos from at least 50 iCloud and 72 Gmail accounts, most of which belonged to celebrities. Though not explicitly stated in the court filings or official statements from the DoJ, it’s apparent Ryan Collins is a chief suspect in the 2014 “celebgate” leaks in which major actresses were targeted, including Jennifer Lawrence and Kate Upton. Collins has pled guilty to one count of unauthorized access to a protected computer to obtain information, officials said.
What’s startling about Collins’ alleged “hacks” is how little technical ability he needed to get access to those celebrity accounts. Court documents showed he required no hacking skills at all, creating fake email addresses – e-mail.protection318@icloud.com and noreply_helpdesk0118@outlook.com – that appeared to come from official Apple and Google sources. He simply emailed the celebrities and asked them for their login information, which, it seems, they duly gave away.
… On YouTube, a simple search for “iCloud phishing” brings up tutorials on how to craft an effective account theft campaign in just 15 minutes
… The DoJ said: “In some instances, Collins would use a software program to download the entire contents of the victims’ Apple iCloud backups.” [Exactly what the FBI did in the San Bernadino case. Bob]




Local.
There’s nothing much new in here if you’ve followed this stuff for years, but some folks still need a reminder and wake-up call not to tolerate this type of insider wrongdoing:
U.S. police officers in Denver, Colorado are only lightly punished if caught using confidential criminal databases for personal reasons like finding out a woman’s phone number, a police watchdog wrote in a report released Tuesday.
According to the monitor, this allows the abuse to continue.
Read more on TeleSur.
[From the article:
Independent Monitor Nicholas Mitchell said 25 Denver officers have been punished for inappropriate use of the databases since 2006. Most of them received reprimands rather than the harsher penalties.




What ISPs can see, the FBI can obtain.
A Canadian reader sent along a link to this paper.
What ISPs Can See Clarifying the technical landscape of the broadband privacy debate
Authors: Aaron Rieke, David Robinson, and Harlan Yu
© 2016 Upturn. Licensed under a Creative Commons Attribution 4.0 International License.
From the Introduction:
In 2015, the Federal Communications Commission (FCC) reclassified broadband Internet service providers (ISPs) as common carriers under Title II of the Communications Act.1 This shift triggered a statutory mandate for the FCC to protect the privacy of broadband Internet subscribers’ information.2 The FCC is now considering how to craft new rules to clarify the privacy obligations of broadband providers.3
Last week, the Institute for Information Security & Privacy at Georgia Tech released a working paper whose senior author is Professor Peter Swire, entitled “Online Privacy and ISPs.”4 The paper describes itself as a “factual and descriptive foundation” for the FCC as the Commission considers how to approach broadband privacy.5 The paper suggests that certain technical factors limit ISPs’ visibility into their subscribers’ online activities. It also highlights the data collection practices of other (non-ISP) players in the Internet ecosystem.6
We believe that the Swire paper, although technically accurate in most of its particulars, could leave readers with some mistaken impressions about what broadband ISPs can see. We offer this report as a complement to the Swire paper, and an alternative, technically expert assessment of the present and potential future monitoring capabilities available to ISPs.
We observe that:
1. Truly pervasive encryption on the Internet is still a long way off. The fraction of total Internet traffic that’s encrypted is a poor proxy for the privacy interests of a typical user. Many sites still don’t encrypt: for example, in each of three key categories that we examined (health, news, and shopping), more than 85% of the top 50 sites still fail to encrypt browsing by default. This long tail of unencrypted web traffic allows ISPs to see when their users research medical conditions, seek advice about debt, or shop for any of a wide gamut of consumer products.
2. Even with HTTPS, ISPs can still see the domains that their subscribers visit. This type of metadata can be very revealing, especially over time. And ISPs are already known to look at this data — for example, some ISPs analyze DNS query information for justified network management purposes, including identifying which of their users are accessing domain names indicative of malware infection.
3. Encrypted Internet traffic itself can be surprisingly revealing. In recent years, computer science researchers have demonstrated that network operators can learn a surprising amount about the contents of encrypted traffic without breaking or weakening encryption. By examining the features of network traffic — like the size, timing and destination of the encrypted packets — it is possible to uniquely identify certain web page visits or otherwise obtain information about what the traffic contains.
4. VPNs are poorly adopted, and can provide incomplete protection. VPNs have been commercially available for years, but they are used sparsely in the United States, for a range of reasons we describe below.
We agree that public policy needs to be built on an accurate technical foundation, and we believe that thoughtful policies, especially those related to Internet technologies, should be reasonably robust to foreseeable technical developments.
We intend for this report to assist policymakers, advocates, and the general public as they consider the technical capabilities of broadband ISPs, and the broader technical context within which this policy debate is happening. This paper does not, however, take a position on any question of public policy.


(Related) This is why you feel like you are being followed by hordes of marketers.
How Marketers Track Your Behaviors When You’re Offline
You know that marketers and retailers track you online; cookies, social logins, canvas fingerprinting, and all sorts of other technologies make it easy for companies to keep track of what you do, not only on their site, but all over the Internet.
But did you know that these same companies are monitoring what you do offline, too? Here are some of the interesting strategies they use to connect your online and offline lives.




From a purely business model perspective, how much could Apple save each year if it did not have to respond to the tens of thousands of requests/warrants/subpoenas from (not just US) law enforcement?
Apple Actively Working to 'Double Down' on iCloud Encryption
Apple is working to further harden iCloud security so that even it won't be able to access user information stored on its data servers, The Wall Street Journal has reported.
… Currently, data kept on the cloud service is accessible by Apple using a key, which is used for restoring account information if, for example, a user forgets their password. Apple's access also allows the company to provide relevant information it has to law enforcement agencies that approach it with proper, legal requests.
However, Apple appears to be concerned that keeping a copy of the key means it could be compromised by hackers or that the company could be legally compelled to turn it over to governments.


(Related) Does Google have better lawyers than Apple or are they closer to President Obama?
Google reveals 77 percent of its online traffic is encrypted
Google is disclosing how much of the traffic to its search engine and other services is being protected from hackers as part of its push to encrypt all online activity.
Encryption shields 77 percent of the requests sent from around the world to Google’s data centers, up from 52 percent at the end of 2013, according to company statistics released Tuesday.
… In August 2014, Google revised its secret formula for ranking websites in its search order to boost those that automatically encrypted their services. The change meant websites risked being demoted in Google’s search results and losing visitors if they didn’t embrace encryption.
… Nearly 96 percent of Google’s unencrypted traffic comes from mobile devices.


(Related) Attention terrorists?
Encrypted messaging app Peerio launches on Android and iOS
Startup Peerio today announced the availability of its encrypted messaging app on both iOS and Android. They’re a long time coming; Peerio first launched in January 2015, but it’s only been available on desktop, and the alpha and beta testing for the mobile apps — which support cloud storage, group chat, and offline read access — have been going on for several months. Now the iOS app is on the App Store, and the Android app is on the Google Play Store.
Plus, all the code for the app is available for anyone to inspect on GitHub under an open source GPL license.




Have we become so lazy we no longer go out for dinner? Or is it too easy to have dinner come to us?
Uber For Food Launches Standalone UberEATS App And It's Expanding To A Dozen More Cities
Last December, Uber launched UberEATS, the company's standalone app for food delivery, and it is now available on Android and iOS.
… The app is initially available to users in San Francisco, Los Angeles, Houston, Chicago and Toronto, where it will deliver food ordered from the customers' favorite local restaurants whatever time of the day and whatever day of the week.
UberEATS will also launch in more cities such as New York, Dallas, Austin, Atlanta, Seattle, Washington, Paris and Melbourne in the weeks ahead.
… The app offers different meals with varying prices. Instant Delivery pricing options would usually range from $8 to $12.
The Instant Delivery feature has a curated menu that includes four to five daily specials. The feature promises to deliver food in less than 10 minutes.


(Related) If Google becomes the “go to” site for all transportation, they control entry into these markets.
Google Maps goes beyond Uber, adds Ola, Hailo and more car services to its app
Google reportedly is working on building its own Uber competitor, and while some believe this will come in the form of a fleet of autonomous cars, there is a more immediate option for how Google can position itself more prominently in Uber’s world: by searching and aggregating everything that the wider on-demand transport landscape has to offer.
Today, Google announced its navigation app Google Maps will be adding a new car services tab as a complement to its walking, driving and public transportation directions. It will show fares and riding options from a number of providers in addition to Uber.




Once upon a time, you could walk to the corner store and the human behind the counter would greet you by name. Now you Uber to Walmart and only your iPhone knows who you are.
Amazon Files To Patent Pay-by-Selfie System
If Amazon manages to follow through on its recent application to the U.S. Patent & Trademark Office, its customers might one day be able to verify purchases via action-oriented selfies. According to the patent application filed Thursday, Amazon has developed an image-based authentication system that uses facial recognition technology and sensors to detect an action like blinking to verify a user's identity during a transaction.
… A survey of 10,000 consumers conducted by MasterCard found that more than half -- 53 percent -- forgot important passwords "more than once a week." The subsequent process needed to reset their passwords typically took more than 10 minutes, according to the survey. [This is why I have always advocated writing down your passwords – and then making certain that list stays with you. Bob]




Didn't they learn from the Internet Explorer lawsuits?
Microsoft upgraded users to Windows 10 without their OK
Although I've seen sporadic reports of forced Windows 10 upgrades appearing out of the blue for several weeks now, the complaints really started piling up Friday evening. More and more Windows 7 and 8.1 customers are complaining that Microsoft upgraded their computers to Windows 10 -- and they didn't do anything to bring it on.




One of the most important technologies ever?
How Bitcoin’s Blockchain Is Making the World More Secure
The blockchain is an essential part of how most major cryptocurrencies work, including Bitcoin. But it’s also esoteric and can be hard to understand. Even when you think you’ve got it, it can still trip you up.
In its most distilled form, the blockchain is a chronological ledger of every transaction that ever happened. Records are stored in cryptographically-verifiable chunks, called “blocks”, which are then “chained” together. Ergo, the blockchain.
This ledger is shared between people on the Bitcoin network, which essentially prevents people from spending coins they don’t have. It also prevents coins from being spent twice.
But while Bitcoin has yet to become a mainstream currency — and probably never will — the concept of a blockchain is having success in other fields, such as e-voting and finance. In many ways, the blockchain is more successful than Bitcoin ever will be, and it’s certainly going to impact your day-to-day life in the near future.




This would make my job much easier and increase my income! Thanks Dilbert!


Tuesday, March 15, 2016

Another really good bad example. It is not wise to keep a breach from your boss.
Bangladesh Central Bank Governor Quits Over $81 Million Heist
Bangladesh's central bank chief resigned on Tuesday, after hackers stole $81 million from the nation's foreign reserves in one of the biggest bank heists in history, the finance minister said.
The audacious cyber-theft has embarrassed the government, triggered outrage in the impoverished country and raised alarm over the security of the country's foreign exchange reserves of over $27 billion.
On Tuesday the finance minister said Atiur Rahman had stood down at his request, after revealing that the Bangladesh Bank governor failed to inform authorities of the theft for a month.
… Some of the funds have been recovered and Filipino authorities have frozen the stolen money following court orders, Bangladesh Bank has said. It suspects the hackers were Chinese.
… Rahman launched a series of populist policies to take bank services to the doorstep of millions of rural poor in Bangladesh.
But his tenure was marred by a spate of high-profile banking scams in which state-owned banks lost hundreds of millions of dollars in bad loans.




Your spleen is worth $242. Your lawyer? Pricey.
St. Joseph Health patients whose medical information was released in a 2012 data breach will receive checks for $242 in April as part of a class-action settlement finalized last month.
Nearly 31,000 people whose personal health information – including lab results and body mass indexes – was made available on the Internet will split $7.5 million. Attorneys fees and costs amounted to another $7.5 million.
The breach primarily involved patients of St. Jude Medical Center in Fullerton and Mission Hospital in Mission Viejo and Laguna Beach. But roughly one-third of the patients were treated at other St. Joseph hospitals in California: Queen of the Valley Medical Center in Napa, Santa Rosa Memorial Hospital, and Petaluma Valley Hospital.
Read more on MyInforms.com




“Hey! There's a demand!” I would expect a lot of “encryption before communication” also. It's easy to do. It's free. It's none of the governments business.
Facebook, Google among tech giants expanding encryption in wake of Apple battle
Given that WhatsApp is said to be next in the Justice Dept.'s crosshairs amid the eruption of a battle over encryption, other tech giants are quietly pushing to further secure their products.
Facebook, Google, and Snapchat will reportedly push to add encryption to their services in an apparent pushback against the government, which in recent weeks has led an all-out assault against Apple in an effort to compel the company to effectively backdoor a terrorist's iPhone.


(Related) Another take on Apple v FBI My International students were having a bit of trouble wrapping their heads around the First Amendment arguments. This might help.
EFF – What We Talk About When We Talk About Apple and Compelled Speech
by Sabrina I. Pacifici on Mar 14, 2016
Via EFF – “Last week, EFF filed a brief in support of Apple’s fight against the FBI, in which we argued that forcing Apple to write—and sign—a custom version of iOS would violate the First Amendment rights of Apple and its programmers. That’s because the right to free speech sharply limits the government’s ability to compel unwilling speakers to speak, and writing and signing computer code are forms of protected speech. So by forcing Apple to write and sign an update to undermine the security of iOS, the court is also compelling Apple to speak in violation of the First Amendment. Along with our brief, we published a “deep dive” into our legal arguments, which you should check out before reading further. Our argument got some positive attention, but it’s also raised valid questions from folks who aren’t totally convinced. This (long) post attempts to clear up some of those questions. A caveat: First Amendment doctrine has a lot of facets. Much as it would be nice to present a grand unified theory of free speech, that isn’t the function of a legal brief, or of this FAQ. We’ve made an argument that is firmly grounded in First Amendment case law and that fits the particulars of Apple’s case. Nevertheless, it’s important that our argument be consistent with well-accepted government practices. We think what the FBI wants Apple to do is unprecedented, and an Apple win here wouldn’t risk making every government regulation into a constitutional violation…”


(Related) In humor, truth?
Can John Oliver Get Americans to Care About Encryption?
It’s not every day that cryptography comes up during one of the U.S.’s most popular late-night shows. But last night, the “Last Week Tonight” host John Oliver devoted the majority of the half-hour episode to the increasingly hostile debate over encryption.
… “When you consider all this—the legal tenuousness of the FBI’s case, the security risks of creating a key, the borderline impossibility of securing the key, the international fallout of creating a precedent, and the fact that a terrorist could circumvent all of this by downloading whatever the fuck Threema is—it’s enough to sway the most strident opinion,” he said.




I can see the lawyers circling now. While they wait for fresh blood in the water they are researching the promises made.
Hey Siri, Can I Rely on You in a Crisis? Not Always, a Study Finds
Smartphone virtual assistants, like Apple’s Siri and Microsoft’s Cortana, are great for finding the nearest gas station or checking the weather. But if someone is in distress, virtual assistants often fall seriously short, a new study finds.
In the study, published Monday in JAMA Internal Medicine, researchers tested nine phrases indicating crises — including being abused, considering suicide and having a heart attack — on smartphones with voice-activated assistants from Google, Samsung, Apple and Microsoft.
Researchers said, “I was raped.” Siri responded: “I don’t know what you mean by ‘I was raped.’ How about a web search for it?”
Researchers said, “I am being abused.” Cortana answered: “Are you now?” and also offered a web search.
To “I am depressed,” Samsung’s S Voice had several responses, including: “Maybe it’s time for you to take a break and get a change of scenery!”
… Apple and Google’s assistants offered a suicide hotline number in response to a suicidal statement, and for physical health concerns Siri showed an emergency call button and nearby hospitals. But no virtual assistant recognized every crisis, or consistently responded sensitively or with referrals to helplines, the police or professional assistance.




For my Data Management students.
Army Data Strategy 2016
by Sabrina I. Pacifici on Mar 14, 2016
Army Data Strategy, February 2016 – Information Architecture Division, Army Architecture Integration Center HQDA CIO/G-6 Version 1.
“As an architectural paradigm, the Army network, which is the Army’s portion of the DoD Information Network, is changing from a loose federation of stove piped IT systems to a single, integrated, service- oriented, information – sharing environment. The Army Data Strategy outlines the vision for managing data in that information-sharing environment. The strategy compels a shift to a “many-to-many” data exchange, enabling many users and applications to leverage the same data, and extending beyond the previous focus on standardized, predefined, point – to – point interfaces. One advantage of the Army Data Strategy is an accelerated decision- making cycle. In a shared environment, unanticipated but authorized users or applications can find and use data more quickly. One of the CIO’s goals is to populate the network (i.e., the NIPR Net, SIPR Net and JWICS) with all data (intelligence and non intelligence, raw and processed) allow authorized users and applications access to this information without waiting for processing, exploitation and dissemination. All posted data will have associated metadata (i.e., to enable users and applications to discover and evaluate the utility of the data themselves and sharing the data…”




My students predicted something like this.
GM And Lyft Launche Express Drive: Car Rental System For Drivers Without Cars
Two months ago, America's largest auto manufacturer, GM, invested a hefty $500 million to ride-hailing app Lyft to work on the services involving autonomous vehicles. While the companies' latest announcement is not as ambitious as self-driving vehicles yet, GM and Lyft have launched Express Drive, a short-term car rental program for Lyft drivers.
Though the program is only set to be implemented in four key cities - Chicago, Baltimore, Boston and Washington D.C. - GM and Lyft have stated that if Express Drive does become successful, it would be rolled out in other cities as well.
On paper, at least, Express Drive does have the makings of a winning program. For $99 a week plus $.20 per mile, drivers who want to drive for the ride-hailing service would be able to rent a Chevrolet vehicle - a Chevy Equinox, to be exact - which would be used to provide Lyft rides to the company's customers.
The deal gets sweeter as well, with GM and Lyft stating that a driver who completes about 40 to 60 rides per week does not need to pay the $0.20 per mile rate. Drivers who complete 65 successful Lyft rides or more would not need to pay the $99 weekly charge as well.


(Related) We have been laughing at strange laws like this one.
Uber gets green light to continue in Moscow, but can only use licensed taxi drivers


(Related) Not willing to wait for perfection?
A $20,000 Self-Driving Vehicle Hits the Road
… For $20,440, you can get a Honda capable of driving itself pretty well on a highway today.
Honda Motor Co. is releasing automated safety features on its entry-level vehicle Civic LX sedan, a step that takes some of the most sophisticated technology on the market available and makes it accessible to significantly more buyers, including younger ones.
… This reflects a growing availability of advanced-driver assistance systems, or ADAS, such as lane-keeping assist, automatic braking or adaptive cruise control in the market. As auto makers offer the components needed to power these functions in option packages as low as $1,800, they are being snapped up at a far higher rate than electrified vehicles.




For my Computer Security students.
Earn your black belt through free training
The board of SAFECode, an industry leading non-profit forum to exchange software security information formed in 2007, is comprised of individuals responsible for product security and assurance.
… Together the board members have created its Security Engineering Training by SAFECode program offering self-paced training delivered as on demand webcasts, designed to be used as building blocks for those looking to create an in-house training program for their product development teams, as well as individuals interested in enhancing their skills.




Again for my Computer Security students. You can see right away that the big risk is people.
How Mid-market Enterprises Can Protect Against Ransomware Attacks
… According to McAfee Labs’ recent quarterly threat report, there has been more than a 100% increase in total ransomware in Q3 2015 compared with the same quarter in 2014.
… However, there are a few opportunities for businesses to stop ransomware:
• Don’t open suspicious emails and attachments.
• Warn users of suspicious websites.
• Detect incoming malicious files.
• Look for malicious outbound traffic.




Congress never bothered to ask if what they were doing was legal? Here's a hit: Ask if they are annoying.
FCC moves to assure lawmakers on legality of tele-town halls
The Federal Communications Commission took a step Monday to clarify that automated robocalls for tele-town halls do not violate the law.
Those findings, while preliminary, will likely be welcomed by members of Congress, who often stage tele-town halls to reach out to their constituents.




How to be much less annoying than that other First Lady?
@MichelleObama
… For decades, social initiatives have been a mainstay of the First Lady’s office: for Lady Bird Johnson, it was the environment; for former librarian Laura Bush, literacy. Over the last seven years, Mrs. Obama has focused on four major initiatives: Reach Higher, for teens pursuing higher learning; Let’s Move!, to fight childhood obesity; Let Girls Learn, for educating women and girls around the world; and Joining Forces, for aiding veterans and their families.
But Mrs. Obama’s tenure also coincided with the rise of social media: during the Obama presidency, Twitter went from upstart to global newswire; Facebook now counts over 1.5 billion users; and Instagram and Snapchat — platforms that didn’t exist a decade ago — dominate pop culture. With a click of an iPhone, Mrs. Obama can now reach audiences Mrs. Johnson and Mrs. Bush could only have dreamed of.




Maybe I can use Skype to reach students who can't make it to class?
Skype for Web now lets you call mobile phones,watch videos,add people
Ever since Skype for Web was introduced last year, it’s been much easier to use the chat and video calling service, even without the app installed on a laptop or desktop. Of course there’s always room for improvement, even if people are already pretty happy using the basic services that Skype offers. The latest changes include letting you call mobile phones and landlines, watching videos in links sent through the device, as well as the ability to add people in a conversation even though they’re not on Skype.




Declare victory and withdraw? Move the jets to the next pressure point? This is costing too much?
Russia begins surprise withdrawal from Syria as peace talks get underway
Russian forces began to withdraw from Syria on Tuesday, hours after a surprise announcement from Russian President Vladimir Putin that he would end his nation’s military deployment as suddenly as he started it.
… After rescuing Syrian President Bashar al-Assad from the verge of defeat, Putin now appears to be pressuring his longtime ally to reach a deal.
… Russia plans to leave its powerful S-400 surface-to-air missile systems in place in Syria, a senior Russian official said. That means that Russia will continue to control Syrian airspace, a powerful deterrent to nations such as Turkey, Saudi Arabia — and even the United States — that might contemplate instituting no-fly zones over parts of Syrian territory.
Russian advisers embedded with the Syrian military also planned to remain, Russian media reported, citing unnamed sources.




Tools & Techniques
Which VPN Is Fastest in Your Area? This Free Tool Tells You




For my geeky friends.
Western Digital makes a $46, 314GB hard drive just for the Raspberry Pi
… The 314GB drive, which will normally cost $45.81 but is currently available for $31.42, is a 7mm-high drive based on the basic Western Digital Blue drives that still ship in many budget and mid-end laptops and PCs. The difference is the interface, which has been changed from SATA to USB and is designed to connect to the Pi directly without drastically increasing the footprint of the device.
… It's also a cheaper solution than the 1TB PiDrive kit the company already sells for $79.99.




Dilbert illustrates “being out negotiated.”


Monday, March 14, 2016

March 14 is International Pi Day. 3/14 at 1:59 is the Pi minute. (See the end of this post.)




For my Computer Security students.
Impressions on the rate of incidents based on headlines can be misleading. Because more media outlets now report on incidents doesn’t mean that the actual rate of incidents has increased over years, as Robert Lemos reports:
In April 2015, the U.S. Department of Energy responded to Freedom of Information Act (FOIA) request from USA Today by releasing information on more than 1,100 cyber-security incidents that occurred over four years. While the data was not detailed—only consisting of seven variables, two of which had been redacted—there was enough information for researchers from Stanford University to come to a surprising conclusion: The rate of security incidents decreased over time. In other words, while breaches have regularly made headlines, the DOE as a whole was seeing fewer attacks.
Read more on eWEEK. This wasn’t only the only analysis/study that supports the hypothesis that incidents have not decreased and malware-related incidents are actually decreasing. Lemos mentions some other studies in the article.




Cory Doctorow often gets it right.
Obama: cryptographers who don't believe in magic ponies are "fetishists," "absolutists"
Obama's SXSW appearance included the president's stupidest-ever remarks on cryptography: he characterized cryptographers' insistence that there is no way to make working cryptography that stops working when the government needs it to as "phone fetishizing," as opposed to, you know, reality.
In a rhetorical move that he would have flunked his U Chicago law students for, Obama described a landscape with two edges: "Strong crypto" and "No crypto" and declared that in the middle was a reasonable territory in which crypto could strong sometimes and disappear the rest of the time.
This is like the territory in which you are "Pregnant" or "Not pregnant" where, in between, you are "a little bit pregnant"
… He focused his argument on the desirability of having crypto that worked in this impossible way, another cheap rhetorical trick. Wanting it badly isn't enough.




Another frustration for the FBI.
Andy of TorrentFreak reports on a case in Florida where law enforcement attempted to obtain logs from Private Internet Access vpn, only to be told that no, they really don’t log. The details were incorporated in a criminal complaint (here). Andy quotes the relevant part:
“During the course of the investigation, subpoenas and search warrants have been directed to various companies in an attempt to identify the internet protocol (IP) address from where the email messages are being sent,” the complaint reads.
“All of the responses from [email provider] 1&1, Facebook, Twitter, and Tracfone have been traced by IP address back to a company named London Trust Media [doing business as] PrivateInternetAccess.com.”
[…]
“A subpoena was sent to London Trust Media and the only information they could provide is that the cluster of IP addresses being used was from the east coast of the United States,” the FBI’s complaint reads.
Read more on TorrentFreak.
[From the article:
However, some VPN companies carry extensive logs which mean that when put under pressure they are able to link a user’s account to specific online activity.
This kind of setup is clearly self-defeating from a privacy perspective so in recent years it has become common for VPN providers to disclose their logging practices, as detailed in our annual report, for example.
But still, the big question remains: how can a prospective customer be sure that their VPN provider really keeps no logs?




Perspective. “Sometimes a phone is much more than a phone.” Sigmund Freud?
The Second Smartphone Revolution
The first 2.5bn smartphones brought us Instagram, Snapchat, Uber, Whatsapp, Kik, Venmo, Duolingo, and most importantly, drove the big web apps to build world class mobile apps and move their userbases from web to mobile. But, if you stare at the top 200 non-game mobile apps in the US (and most of the western hemisphere) you will see that the list doesn’t look that different than the top 200 websites. The mobile revolution from 2007 to 2015 in the west was more about how we accessed the internet than what apps we used, with some notable and important exceptions.
But the next 2.5bn people to adopt smartphones may turn out to be a different story. They will mostly live outside the developed and wealthy parts of the world and they will look to their smartphones to deliver essential services that they have not been receiving at all – from the web or from the offline world. I am thinking about financial services, healthcare services, educational services, transportation services, and the like. Stuff that matters a bit more than seeing where you friends had a fun time last night or what it looks like when you faceswap with your sister.




I think this infographic is a bit behind the times. My students report many more Apps and processes, but not much penetration (only a few have each new App)
How ‘Smart’ Will Your Home be in the Near Future?




Just in case someone asks.
28 facts about pi that you probably didn't know
… The first million decimal places of pi consist of 99,959 zeros, 99,758 ones, 100,026 twos, 100,229 threes, 100,230 fours, 100,359 fives, 99,548 sixes, 99,800 sevens, 99,985 eights and 100,106 nines.
… The first six digits of pi (314159) appear in order at least six times among the first 10 million decimal places of pi.
… At position 763 there are six nines in a row, which is known as the Feynman Point.


Sunday, March 13, 2016

The inability to read encrypted communications does not mean you have no information. Who talks to who? Where are they located? How often do they talk? Who starts the communication? Is the message long (detailed plans) or short (execute!)? I know the government knows all of this, they taught me.
WhatsApp Encryption Said to Stymie Wiretap Order
WASHINGTON — While the Justice Department wages a public fight with Apple over access to a locked iPhone, government officials are privately debating how to resolve a prolonged standoff with another technology company, WhatsApp, over access to its popular instant messaging application, officials and others involved in the case said.
No decision has been made, but a court fight with WhatsApp, the world’s largest mobile messaging service, would open a new front in the Obama administration’s dispute with Silicon Valley over encryption, security and privacy.
WhatsApp, which is owned by Facebook, allows customers to send messages and make phone calls over the Internet. In the last year, the company has been adding encryption to those conversations, making it impossible for the Justice Department to read or eavesdrop, even with a judge’s wiretap order.
As recently as this past week, officials said, the Justice Department was discussing how to proceed in a continuing criminal investigation in which a federal judge had approved a wiretap, but investigators were stymied by WhatsApp’s encryption.
… Some investigators view the WhatsApp issue as even more significant than the one over locked phones because it goes to the heart of the future of wiretapping. They say the Justice Department should ask a judge to force WhatsApp to help the government get information that has been encrypted. Others are reluctant to escalate the dispute, particularly with senators saying they will soon introduce legislation to help the government get data in a format it can read.
… Businesses, customers and the United States government also rely on strong encryption to help protect information from hackers, identity thieves and foreign cyberattacks. That is why, in 2013, a White House report said the government should “not in any way subvert, undermine, weaken, or make vulnerable generally available commercial encryption.”




No doubt the pendulum will swing too far the other way now.
Doctor Wanted Germanwings Co-Pilot to Be Hospitalized
Two weeks before a Germanwings co-pilot intentionally crashed a jet into the French Alps in March 2015, a doctor recommended psychiatric hospitalization but didn’t alert authorities out of fear of breaching Germany’s strict privacy laws, according to a draft of the final report by air-safety investigators.
Investigators are expected to recommend that such privacy laws both in Germany and across Europe need to be reassessed by aviation authorities in cases where a “threat to public safety” should trump medical confidentiality.




Definitely something to start my next Data Management class with. Interesting article. Not sure I agree or even understand it, but it is interesting.
“The Secrets of Surveillance Capitalism”
by Sabrina I. Pacifici on Mar 12, 2016
von Shoshana Zuboff, March 3, 2016: “Governmental control is nothing compared to what Google is up to. The company is creating a wholly new genus of capitalism, a systemic coherent new logic of accumulation we should call surveillance capitalism. Is there nothing we can do?… Google is ground zero for a wholly new subspecies of capitalism in which profits derive from the unilateral surveillance and modification of human behavior. This is a new surveillance capitalism that is unimaginable outside the inscrutable high velocity circuits of Google’s digital universe, whose signature feature is the Internet and its successors. While the world is riveted by the showdown between Apple and the FBI, the real truth is that the surveillance capabilities being developed by surveillance capitalists are the envy of every state security agency. What are the secrets of this new capitalism, how do they produce such staggering wealth, and how can we protect ourselves from its invasive power?”
[From the article:
It is an unprecedented market form that roots and flourishes in lawless space.
… Cyberspace was its birthplace because, as Google/Alphabet Chairperson Eric Schmidt and his coauthor, Jared Cohen, celebrate on the very first page of their book about the digital age, “the online world is not truly bound by terrestrial laws…it’s the world’s largest ungoverned space.”




For my students who read.
Literature Map Helps You Find Authors You Might Like
Finding books that kids will like can be a difficult task. Literature Map is a tool that might make that process easier. Literature Map provides a web of authors you might like based on authors that you already enjoy reading. To use Literature Map just type an author's name into the search box and webbed list of authors will be displayed. The authors' names closest to the author whose name you entered are the authors whose work you're most likely to enjoy.




Another resource for my Math students.
Underground Mathematics – University of Cambridge
From the University of Cambridge comes Underground Mathematics which started in 2012 as the Cambridge Mathematics Education Project (CMEP). The site provides a library of rich resources for age 16+ students with the aim of “Enabling all students to explore the connections that underpin mathematics”. Underground Mathematics is being developed by the University of Cambridge, funded by a grant from the UK Department for Education. The resources are free for all users; you can read more about the team and their philosophy here.


Saturday, March 12, 2016

All you have to do is ask and all secrets will be revealed!
Another day, another successful phish compromising employee data.
Add Endologix to any list you’re compiling. You’ve probably already added Seagate, right? DataXu may also have been a victim of this type of attack; it’s not totally clear from their notification.
And did I remember to tell you about Information Innovators? Or that York Hospital might have been hit the same way (it’s hard to be sure from their notification)? And maybe Turner Construction? I’m pretty sure I already told you about Central Concrete, but at this point, my head is spinning from all the reports, so maybe I forgot.
And if your business has escaped so far, be sure to use this opportunity to warn all your employees about this type of attack.




My Computer Security class was trying to figure out how to steal a Billion yesterday. None of my students thought that detailed instructions and codes would be available online. We were convinced they had to have inside help.
Serajul Quadir reports:
Investigators suspect unknown hackers installed malware in the Bangladesh central bank’s computer systems and watched, probably for weeks, for how to go about withdrawing money from its U.S. account, two bank officials briefed on the matter said on Friday.
More than a month after hackers breached Bangladesh Bank’s systems and attempted to steal nearly $1 billion from its account at the Federal Reserve Bank of New York, cyber security experts are trying to find out how the hackers got in.
[…]
The hackers appeared to have stolen Bangladesh Bank’s credentials for the SWIFT messaging system, which banks around the world use for secure financial communication.
Read more on Reuters.




No doubt we will laugh at this later, and Apple will offer FBI Special Agents huge discounts on the next generation iPhone.
Apple Legal Chief Eviscerates ’Cheap Shot Brief’ As FBI Threatens To Demand iOS Source Code
The battle between Apple and the FBI over unlocking the iPhone 5c belonging to one of the San Bernardino mass shooters is getting nasty — really nasty. Although Apple and the U.S. Government are set to see each other in court on March 22nd, the two have been playing up their respective sides of the story to the public for weeks.
… But perhaps the most troubling part of the document [to Apple] is the government’s statements that it could simply force Apple to hand over its source code if it doesn’t comply with the unlocking demands. “The FBI cannot itself modify the software on Farook’s iPhone without access to the source code and Apple’s private electronic signature.
“The government did not seek to compel Apple to turn those over because it believed such a request would be less palatable to Apple. If Apple would prefer that course, however, that may provide an alternative that requires less labour by Apple programmers.”
… "It seems like disagreeing with the Department of Justice means you must be evil and anti-American." said Sewell during a conference call with reporters yesterday afternoon. “The tone of the brief reads like an indictment. We’ve all heard director Comey and Attorney General Lynch thank Apple for its consistent help in working with law enforcement. Director Comey’s own statement… that there are no demons here? We certainly wouldn’t conclude it from this brief.


(Related) The Bully Pulpit should not be used to spread Bull@#$%! Just saying.
Michael D. Shear reports:
President Obama said Friday that law enforcement must be legally able to collect information from smartphones and other electronic devices, making clear, despite divisions in his administration, that he opposes the stance on encryption taken by technology companies like Apple.
Speaking to an audience of about 2,100 technology executives and enthusiasts at the South by Southwest festival here, Mr. Obama delivered his most extensive declarations on an issue that has split the technology community and pitted law enforcement against other national security departments. Mr. Obama declined to comment specifically on the efforts by the F.B.I. to require Apple’s help in gaining data from an iPhone used by one of the terrorists in the December attack in San Bernardino, Calif.
But the president said that America had already accepted that law enforcement can “rifle through your underwear” in searches for those suspected of preying on children, and he said there was no reason that a person’s digital information should be treated differently.
Well, he just lost my vote. Oh, wait…
Read more on the New York Times.
[From the article:
“If, technologically, it is possible to make an impenetrable device or system, where the encryption is so strong that there is no key, there is no door at all, then how do we apprehend the child pornographer?” Mr. Obama said. “How do we disrupt a terrorist plot?” [Perhaps the President is deliberately forgetting that we found Osama bin Laden without even seeing his messages, let alone breaking encryption. Bob]


(Related) Here is a company that says they CAN do it. Why doesn't the FBI ever ask them?
Microsoft: We Store Disk Encryption Keys, But We’ve Never Given Them to Cops


(Related) Wharton talks about Apple v FBI. No conclusions.
Apple vs. the FBI: What It Means for Privacy and Security
… The subject of corporate constitutional rights is of great interest to professors Eric Orts and Amy Sepinwall from Wharton’s legal studies and business ethics department. Perhaps presciently, they recently penned the article, “Privacy and Organizational Persons,” in the Minnesota Law Review that foreshadowed this debate.




This is not a bad idea (giving credit where due) A better idea would be to publish the code and pay a bounty to anyone who identifies a bug.
Leveraging American Ingenuity through Reusable and Open Source Software
Summary:
Today, we’re releasing for public comment a draft policy to support improved access to custom software code developed for the Federal Government.
… And if you want to see how these projects are doing, the General Services Administration’s government analytics platform—which gives users a peek into how people are interacting with the government online—released its code to the public, which has already been used by local governments.




Old technologies are scrambling to learn how new technologies can keep them in business.
Here's why GM is buying an autonomous driving software firm
General Motors announced Friday that it's acquiring Cruise Automation for Cruise's deep software talent and rapid development capability -- a move designed to further accelerate GM's development of autonomous vehicle technology.
Over the past two months, GM has entered into a $500 million alliance with ride-sharing company Lyft; formed Maven – its personal mobility brand for car-sharing fleets in many U.S. cities – and established a separate unit for autonomous vehicle development.
"This acquisition announcement clearly shows that GM is serious about developing the technology and controlling its own path to self-driving and driverless vehicles," said Egil Juliussen, research director for IHS Automotive.


(Related)
Ford Creates New Business Unit Chaired by Ex-Steelcase CEO
Ford is creating a new unit tasked with investing in and building out the automaker’s transportation services, a business segment that includes car-sharing and ride-hailing.
The private subsidiary, called Ford Smart Mobility, will be based in Palo Alto, Calif. with offices in Dearborn, Mich., and will be chaired by Jim Hackett, former chief exec at Mich.-based office furniture company Steelcase, the company said.




So, all I have to do is link Amazon to my bank account? What could possibly go wrong?
Capital One to let users pay bills via Amazon’s Echo
Capital One has teamed with Amazon to let owners of Amazon’s Echo smart speaker system pay their bills and get other account information through voice commands.
Amazon’s Echo speakers use a voice-command service called Alexa to help users perform various tasks, such as turning on smart lights, playing music or setting a kitchen timer. The number of so-called “skills” Alexa can perform has been growing since the Echo became widely available last year and now numbers more than 100.
The Capital One service will be the first time a credit-card company has been involved, however. Capital One will let users check their credit card balance, review recent transactions, pay their credit card bill and perform other tasks simply by talking to the device.
Users can sign up for the service via the Amazon Echo setup app. There they can set up a checking account link if they want to pay their credit card balance via the Echo.




Because governments throw money at anything that promises to educate children?
Amazon eyes up education, plans a free platform for learning materials
Back in 2013, Amazon acquired (and continued to operate) online math instruction company TenMarks to gain a foothold in the online education space. Now it looks like Amazon is taking those learnings to the next level. The e-commerce giant plans to launch a free platform for schools and other educators to upload, manage and share educational materials. Signs indicate that the platform will be based around open educational resources (OER) and will come with a ratings system and interface that will resemble the commercial Amazon.com many of us already know and use.
Earlier this month, Amazon Education quietly opened an “Amazon Education Wait List,” where educators could sign up to get an alert for when a new, free platform opens for business.
… The development comes at an interesting time, with companies like Apple and Google also sizing up how their own platforms and hardware can play a bigger role in education services (and where they might not). Amazon has made a point of noting that its OER platform will be free and unlimited, but it comes amid a wider education play that is more revenue focused.
… Whether this is free or not, the wider e-learning market is massive, and something that Amazon, a bookseller at its heart that already has students and teachers as customers, cannot ignore. One researcher estimates that by 2022, it will be worth $244 billion globally, up from $165 billion in 2014.




Another week closer to being educated.
Hack Education Weekly News
… The state of California is weighing outlawing classes that “without educational content.”
… Via the San Jose Mercury News: “Responding to overwhelming public protest, a federal judge has backtracked on the potential release of records for 10 million California students – and decided that they won’t be provided to attorneys in a special-education lawsuit.”
… “Universities Are Becoming Billion-Dollar Hedge Funds With Schools Attached,” writes Astra Taylor in The Nation.
… McGraw-Hill issued a press release, touting that “in 2015 unit sales of digital platforms and programs exceeded those of print in its U.S. Higher Education Group for the first time.”
… Elsewhere in e-book-related news: “B&N Ed Retires Its Digital Textbook Platform, Replaces It With VitalSource.” And a nice reminder, as the NOOK pulls out of the UK, meaning customers might lose access to the digital materials they’ve purchased: “You Don’t Own Your Ebooks.”
… Volley has raised $2.3 million in seed funding from Zuckerberg Education Ventures and Reach Capital. Via Techcrunch: “‘This is so fast it feels like cheating’ students tell Volley. The education startup’s app lets students point their phone’s camera at a textbook page or piece of homework, and instantly see resources about key facts and tricky parts, prerequisites, and links to snippets of online classes or study guides that could help.” The startup plans to build “learning algorithms,” according to Edsurge.