Tuesday, June 21, 2016

An interesting article.  My concern, as a Computer Security manager would be that their hackers have found a less detectable method of hacking into my systems.  But that does not stop everyone involved (or not) from claiming success!
Chinese Curb Cyberattacks on U.S. Interests, Report Finds
Nine months after President Obama and President Xi Jinping of China agreed to a broad crackdown on cyberespionage aimed at curbing the theft of intellectual property, the first detailed study of Chinese hacking has found a sharp drop-off in almost daily raids on Silicon Valley firms, military contractors and other commercial targets.
But the study, conducted by the iSight intelligence unit of FireEye, a company that manages large network breaches, also concluded that the drop-off began a year before Mr. Obama and Mr. Xi announced their accord in the White House Rose Garden.  In a conclusion that is largely echoed by American intelligence officials, the study said the change is part of Mr. Xi’s broad effort to bring the Chinese military, which is considered one of the main sponsors of the attacks, further under his control.


Another “must have” surveillance App?  Do the people who buy these know what they are doing? 
The AI Dashcam App That Wants to Rate Every Driver in the World
If you’ve been out on the streets of Silicon Valley or New York City in the past nine months, there’s a good chance that your bad driving habits have already been profiled by Nexar.  This U.S.-Israeli startup is aiming to build what it calls “an air traffic control system” for driving, and has just raised an extra $10.5 million in venture capital financing.
Since Nexar launched its dashcam app last year, smartphones running it have captured, analyzed, and recorded over 5 million miles of driving in San Francisco, New York, and Tel Aviv.  The company’s algorithms have now automatically profiled the driving behavior of over 7 million cars, including more than 45 percent of all registered vehicles in the Bay Area, and over 30 percent of those in Manhattan.
Using the smartphone’s camera, machine vision, and AI algorithms, Nexar recognizes the license plates of the vehicles around it, and tracks their location, velocity, and trajectory.  If a car speeds past or performs an illegal maneuver like running a red light, that information is added to a profile in Nexar’s online database.  When another Nexar user’s phone later detects the same vehicle, it can flash up a warning to give it a wide berth.  (This feature will go live later this year.)
   Nexar estimates that if 1 percent of drivers use the app daily, it would take just one month to profile 99 percent of a city’s vehicles.  “We think that it’s a service to the community to know if you’re a crazy driver or not,” says Shir.
That community includes insurance companies, who Nexar suggests could save billions by cherry-picking only the best drivers to cover.


Security(?) at the cost of your privacy?  Was the Privacy Policy language deliberate?  What would you do with videos of someone’s home?  
From the not-exactly-a-glowing-review dept., SLC Security writes:
 Look familiar?  Well this device started showing up in all the big box retailers last year so we decided to give one a try.  Hooking the device up to a EVDO hotspot on Verizon was interesting at best.  During our testing we discovered that the device streams continuously back to Guardzilla (even if you don’t subscribe to their monitoring) all the time.  So this “security” device has some serious “privacy” issues.
[…]
Here’s the problem. Even when you don’t subscribe to the recording and playback features offered by Guardzilla the devices still stream to Guardzilla and we assume that the video is being stored otherwise why would you send it?  What tipped us off was the fact that the device uses nearly 1GB of bandwidth per day even when your not viewing the camera.  So basically your allowing Guardzilla to see into your protected space and to hear everything that goes on in this space because these devices are constantly streaming even when you are not using them. 
Read more on SLC Security.  In an update, they state that Guardzilla confirmed that that’s how the device operates.
I wonder what the FTC would say about all this.
[From the article:
The Guardzilla Privacy Policy:
Practecol takes reasonable efforts to ensure that your personal information is protected while you use the Services. [Not while you don’t?  Bob]
Oh and theres this line:
Also, video, audio, and other information received or recorded by your Guardzilla device may be stored on our servers or the servers of third parties.


Another surveillance technique?  (Beware of perverts/stalkers bearing gifts?)
Caleb Chen writes:
Over the weekend, the security community heard rumors about a potential issue with the NETGEAR Internet of Things wireless security camera.  A user reported to the privacy subreddit that after returning the device and not uninstalling the app or deleting an account, the user was still able to see camera footage from the new owner’s camera – a clear privacy breach.  The user accuses NETGEAR of having poorly planned out processes for change of ownership scenarios.  The reaction from the tech community lacked disbelief and sympathy.  Many others reported similar issues with brands other than NETGEAR.  In fact, there are websites that list all the world’s internet of things (IoT) cameras that are plugged in but not configured to keep the world out.
Read more on Privacy Online News.


“Hey!  We gotta do something!”  Don’t think, act! 
Invoking Orlando, Senate Republicans set up vote to expand FBI spying
U.S. Senate Majority Leader Mitch McConnell set up a vote late on Monday to expand the Federal Bureau of Investigation's authority to use a secretive surveillance order without a warrant to include email metadata and some browsing history information.
   Privacy advocates denounced the effort, saying it seeks to exploit a mass shooting in order to expand the government’s digital spying powers.
   The amendment would broaden the FBI’s authority to use so-called National Security Letters to include electronic communications transaction records such as time stamps of emails and the emails' senders and recipients.
The Obama administration for years has lobbied for a change to how NSLs can be used, after a 2008 legal memo from the Justice Department said the law limits them largely to phone billing records.  FBI Director James Comey has said the change essentially corrects a typo and is a top legislative priority for his agency.
   The amendment filed Monday would also make permanent a provision of the USA Patriot Act that allows the intelligence community to conduct surveillance on “lone wolf” suspects who do not have confirmed ties to a foreign terrorist group.  That provision, which the Justice Department said last year had never been used, is currently set to expire in December 2019.

(Related)  “They’re not letting us do what we want to do!” (say it with a whiney voice)  Or perhaps, “They’re child pornographers, they don’t have any rights!” 
Tim Cushing writes:
Another court handling an FBI Playpen case has handed down its decision on a motion to suppress.  Like other courts fielding prosecutions resulting from this massive investigation, it has found [PDF] that the FBI’s NIT (Network Investigative Technique) is invasive enough to be called a “search.” (via FourthAmendment.com)
The FBI must have felt its NIT deployment would be considered a search.  That’s why it obtained a warrant in the first place.  But it’s been frantically peddling “not a search” theories as court after court has declared its warrant invalid because the searches were performed outside of the issuing magistrate’s jurisdiction.
Read more on TechDirt.


This will be handy when (if) I start teaching the “Care and Feeding of the Social Media Beast”
Paper – Social Clicks: What and Who Gets Read on Twitter?
by Sabrina I. Pacifici on
Maksym Gabielkov, Arthi Ramachandran, Augustin Chaintreau, Arnaud Legout.  Social Clicks: What and Who Gets Read on Twitter?.  ACM SIGMETRICS / IFIP Performance 2016, Jun 2016, Antibes Juan-les-Pins, France. 2016. https://hal.inria.fr/hal-01281190  Submitted on 13 Apr 2016.
“Online news domains increasingly rely on social media to drive traffic to their websites.  Yet we know surprisingly little about how a social media conversation mentioning an online article actually generates clicks.  Sharing behaviors, in contrast, have been fully or partially available and scrutinized over the years.  While this has led to multiple assumptions on the diffusion of information, each assumption was designed or validated while ignoring actual clicks.  We present a large scale, unbiased study of social clicks – that is also the first data of its kind – gathering a month of web visits to online resources that are located in 5 leading news domains and that are mentioned in the third largest social media by web referral (Twitter).  Our dataset amounts to 2.8 million shares, together responsible for 75 billion potential views on this social media, and 9.6 million actual clicks to 59,088 unique resources.  We design a reproducible methodology and carefully correct its biases.  As we prove, properties of clicks impact multiple aspects of information diffusion, all previously unknown.
(i) Secondary resources, that are not promoted through headlines and are responsible for the long tail of content popularity, generate more clicks both in absolute and relative terms.
(ii) Social media attention is actually long-lived, in contrast with temporal evolution estimated from shares or receptions.
(iii) The actual influence of an intermediary or a resource is poorly predicted by their share count, but we show how that prediction can be made more precise.”


At what point does Google cross the line into practicing medicine without a license?  Will these be linked to the nearest medical specialist along with a coupon that says, “Google sent me?”
Google Sharpens Search Results for ‘Skin Rash,’ ‘Tummy Ache’ and Other Symptoms
Google has a health problem. Its search results for medical symptoms aren’t very useful at best, and in many cases are alarmingly off base, frustrating patients and doctors alike.
The Alphabet Inc. -owned search giant says it has developed a cure.  On Monday, it rolled out a new feature called symptom search.
The next time you use the Google search app for iPhone and Android to look up something like “my tummy hurts,” “skin rash,” or “headache on one side,” you’ll see about a half-dozen digital cards you can swipe through right below the search box.  Each of these cards briefly describes a common health problem related to your search term.


Perspective.  Is this now a nation of crooks?
Google is being overloaded with DMCA takedown requests.  The company has seen the number of takedown notices from rightsholders quadruple over the past two years.  In 2016 alone, Google is projected to process over a billion reported pirate links, most of which will be scrubbed from its search index.
   Google now handles around three million “pirate” links every day.


Perspective.  Also, some tips on how to do business in India?
Amazon's Bold Indian Strategy
Amazon CEO Jeff Bezos recently announced an expansion of the company's investment in India to the tune of US$3 billion -- that was in addition to the $2 billion in investments it announced in 2014.
   "It appears that Amazon is seeking to build an infrastructure just for the India market, which is good strategy given the regulatory challenges of being a foreign entity and the different e-commerce environment," said Jim McGregor, principal analyst at Tirias Research.
   One of the world's fastest-growing e-commerce markets, India currently is dominated by firms like Flipkart, Snapdeal and Alibaba.
"India represents a rapidly expanding market with a growing middle class," Stratecast/Frost & Sullivan Program Manager Mike Jude told the E-Commerce Times.
Overall, the online retail market in India is only 2 percent of total retail sales in that country, according to Forrester Research.  However, growth in e-tailing is exploding, with the market expected to rise at a compound annual growth rate of 44 percent, starting last year, to reach $75 billion by 2020.


It’s good to be on the New York Times bestseller list!
E-Book Buyers to Start Receiving Credits on Tuesday as Part of Apple Price Fixing Settlement
Starting on Tuesday, June 21, U.S. customers who purchased e-books from Apple and other retailers like Amazon and Barnes & Noble will begin receiving payouts from the $450 million settlement Apple agreed to pay after being found guilty of conspiring to fix the prices of e-books.
Customers will be receiving a $6.93 credit for each book that was a New York Times bestseller, and a $1.57 credit for other e-books.  Customers eligible for credits include those who purchased e-books between April 1, 2010 and May 21, 2012.


“If’n them thar good ole boys kin do it, I reckon us’ns can do it too!”
Chattanooga mayor: Gigabit speed internet helped revive city
When Chattanooga Mayor Andy Berke describes his city's economic renewal, he points to the city’s fiber network as a significant source of its new vibrancy.
   A pioneer in municipal broadband, Chattanooga developed its fiber network in 2010 with $330 million, paid for with $105 million in federal funds and the rest from bonds.  The high-speed access led to direct and indirect economic gains and has been profitable.
   “Our fiber goes to each and every home,” Berke said.  “We can’t have digital gated communities.  If we do that we and only allow fiber to go to some parts of the city, some parts of the state, we will see technology widen the gulf between people as opposed to bridging it.


This is all the Harvard B School could come up with?
The 8 Digital Productivity Tools Everyone Should Adopt
I’m a super adopter.  I love trying out hundreds of new applications, social networks and devices every year.  But not everybody wants to live the thousand-app lifestyle.  For most people, the goal is to adopt the smallest number of tools necessary to work efficiently.  That’s why my friends and colleagues often ask me which technologies I regard as must-haves: the tools and tactics that will make a big impact on their productivity without spending a lot of time or money getting up and running.

Monday, June 20, 2016

I would call this “stopping a major security risk,” but then what do I know. 
Wells Fargo Cites New API as Screen Scraping Countermeasure
   Wells Fargo recently announced that it has created an API to make business bank account data available in accounting software Xero.  According to a recent article by Penny Crosman for American Banker, the turnaround comes in response to the continued use of screen scraping to access bank data.
   These security concerns are largely founded on the fact that consumers are giving out their online banking username and password to third parties to access accounts and perform the scraping.  Several prominent banks are currently attempting to reduce the risk of financial data aggregation through the use of OAuth, as Wells Fargo is doing with Xero to leverage its commitment to the API concept.

(Related)
The practice is commonplace.  And the end-users are cooperating!
Fintech Firm Plaid Raises $44 Million
Plaid Technologies Inc., whose software allows a variety of financial-technology startups to access their customers’ bank account information, has raised $44 million in a new round led by a fund at Goldman Sachs Group Inc.
   Many upstart financial-services providers such as online financial adviser Betterment Inc. use Plaid’s software to access or check customers’ account data when providing mobile and web services like budgeting, investing or lending.


I wish the government would stop providing my Computer Security students with such excellent “Bad Examples!”
Jack Moore reports:
After a wildfire tears through your community, the last thing you may be worried about is having your identity stolen or your personal information breached.
But maybe you should be.
A new inspector general report finds the Federal Emergency Management Agency still struggles to properly handle the safeguarding of personally identifiable information, or PII, at its disaster recovery centers.
Read more on NextGov.

(Related).  Proof that Liberals are Airheads?
Yet another security incident linked to failure to change default passwords.
CJAD in Canada reports that the Quebec Liberals’ failure to change the default password on their videoconferencing system allowed anyone to gain access to strategy meetings.
The user who found the flaw showed off the unlimited access to the Journal de Montreal. Published screenshots show archived videos of various meetings.
No need to hack opposition research, when you can just wait for the security clueless to leak their own data.


The competition continues.  The term “government malware” is not yet in common use.
Joshua Kopstein writes:
The FBI has had a fair amount of success de-anonymizing Tor users over the past few years.  Despite the encryption software’s well-earned reputation as one of the best tools for online privacy, recent court cases have shown that government malware has compromised Tor users by exploiting bugs in the underlying Firefox browser—one of which was controversially provided to the FBI in 2015 by academic researchers at Carnegie Mellon University.
But according to a new paper, security researchers are now working closely with the Tor Project to create a “hardened” version of the Tor Browser, implementing new anti-hacking techniques which could dramatically improve the anonymity of users and further frustrate the efforts of law enforcement.
Read more on Motherboard.


Inspiration for our Ethical Hacking students?
How to Use an Undocumented Facebook API to Identify Friends in Photos
   Tagging friends in photos is nothing new, but the more recent Facebook feature that pops up asking ‘Do you want to tag X?’ when hovering over an image got developer Narendra Rajput wondering how Facebook identifies who the person is.  In this recent post, Rajput explained how he figured out the undocumented API. 


No matter who is right, this provides insight.  Do all Facebook users know this is what happens?  
Facebook litigating $15B user internet track case
by Sabrina I. Pacifici on
Facebook Accused Of Tracking Users’ Internet Activity By Consuella Pachico – “Facebook is facing multidistrict litigation over allegations that the social media site tracked users’ internet activity after they logged off.  Facebook is insisting that users cannot sue because they were not harmed by the site’s tracking activities.  In response to users’ claim that their privacy rights were violated by post-logoff tracking, Facebook states that nothing in the amended complaint identifies “how the alleged violations caused plaintiffs to suffer real, actually existing injuries that are not abstract, conjectural, or hypothetical.”
·         In re: Facebook Internet Tracking Litigation, case number 5:12-md-02314, in the U.S. District Court for the Northern District of California.


Something for Contract Law students to debate?  If I use your program to do what you program was designed to do, have I done anything wrong? 
You may feel like you’re entering the Twilight Zone after reading this report from Russell Brandom:
One day after $53 million abruptly disappeared from an experimental cryptocurrency project, a note claiming to be from the attacker has surfaced on PasteBin, claiming that the money drained from the system is now legally his.  The attacker withdrew the money by exploiting a contract bug in the code of the DAO (or Decentralized Autonomous Organization), a collective investment fund that uses the Ethereum cryptocurrency.  The DAO had raised well over $100 million from Ethereum users at the time of the attack.
“I have carefully examined the code of The DAO and decided to participate after finding the feature where splitting is rewarded with additional ether,” the note reads.  “I… have rightfully claimed 3,641,694 ether, and would like to thank the DAO for this reward,” the note reads.  “I am disappointed by those who are characterizing the use of this intentional feature as ‘theft.’”  The note also threatens legal action against any who attempt to reclaim the money through technical means.
Read more on The Verge.
The note from the “attacker” is very well written, suggesting a certain level of education.  But the gist of the note is that the individual thinks s/he’s found a loophole or clause in the contract that can be legally exploited and seems to be bragging about it.
This will be interesting to follow.


Pick one:
There are some things man was not meant to know.
The American people are too delicate to hear such things!
His words would convince millions to join ISIS.
He is right, we is wrong.
Have we become so afraid of terrorists that we can’t let people decide for themselves how crazy this guy was? 
Lynch: "Partial Transcript" Of Orlando 911 Calls Will Have References To Islamic Terrorism Removed
In an interview with NBC's Chuck Todd, Attorney General Loretta Lynch says that on Monday, the FBI will release edited transcripts of the 911 calls made by the Orlando nightclub shooter to the police during his rampage.
"What we're not going to do is further proclaim this man's pledges of allegiance to terrorist groups, and further his propaganda," Lynch said.  "We are not going to hear him make his assertions of allegiance [to the Islamic State]."


A little “one-upmanship?”  I thought all US chips were already made in China – or is that only smartphones? 
China builds world’s fastest supercomputer without U.S. chips
China on Monday revealed its latest supercomputer, a monolithic system with 10.65 million compute cores built entirely with Chinese microprocessors.  This follows a U.S. government decision last year to deny China access to Intel's fastest microprocessors.
There is no U.S.-made system that comes close to the performance of China's new system, the Sunway TaihuLight.  Its theoretical peak performance is 124.5 petaflops, according to the latest biannual release today of the world's Top500 supercomputers.  It is the first system to exceed 100 petaflops.  A petaflop equals one thousand trillion (one quadrillion) sustained floating-point operations per second.


Perspective.  Is this real competition or is everyone not Uber or Lyft just another small player?  It’s hard to keep track of them all!
Uber Finds Passage to India Blocked by 30-Year-Old Ola Founder

(Related)
Black cab app Gett is launching a billboard campaign that mocks Uber for being expensive

(Related)
Americans and the new digital economy: 8 key findings
by Sabrina I. Pacifici on
“Digital technology has ushered in a slew of new shared, collaborative and on-demand online services ranging from virtual marketplaces to home sharing.  These services have potentially far-reaching implications for consumers and regulators and for the future of work in this country. To examine the scope and impact of these new services, Pew Research Center conducted its first survey devoted to the broader issues of the new digital economy. Here are eight findings from the report…”


Reading with your ears is not really reading, but it beats not reading at all.
This Site Has Thousands of Free Public Domain Audiobooks
   If you want to experience a few audiobooks yourself without shelling out so much cash, consider heading over to Librivox.  It’s home to thousands of public domain audiobooks.  No price tags.
The key is that these audiobooks are read by volunteers from around the world, mainly those who are training to be voiceover artists.  Also, you won’t find newly released books, but you’ll find a lot of classics and hidden gems.

Sunday, June 19, 2016

Simple.  Elegant.  Predictable?
Ethereum/TheDAO hack simplified
   Bitcoin is just a public ledger (the "blockchain"), of all transaction there ever was.  This ledger is huge (80-gigabytes) and growing, but Moore's Law says computers grow even faster, so that shouldn't be a problem.
Each entry in the ledger says to move the coins received in these previous entries, and give them to this recipient. In other words:
move these coins I received there, to this guy here
   How did The DAO get hacked?
When a member exits the investment scheme, they call the function name splitDAO().  There are two issues.
The first is that the member will supply some of their own code with the transaction.  Among the things that code will do is tell the DAO code how to transfer Ethereum coin.  It's a necessary feature, part of Bitcoin as well.
The second issue is that Ethereum code is recursive.  That means when a function is running, it may call itself a second time.
The bug is that when splitDAO() is called, it will then call the recipients code to transfer Ethereum coin, after which the recipients code will call splitDAO() again before finishing.  This causes the process to repeat itself, transferring more Ethereum coin, then calling splitDAO() again, which calls the hacker's code, which calls splitDAO(), which calls the hacker's code, and so on.  The process will continue endlessly, until it drains all of TheDAO's coin.


A little something for our Ethical Hacking students. 
Department of Defense expanding Hack the Pentagon program
The department announced today that it is expanding its Hack the Pentagon program to include more DoD systems and networks.  Hack the Pentagon pays hackers to find and report vulnerabilities in exchange for cash, and so far it’s proved effective — the first bug was reported 13 minutes after the program launched.
   “Although the pilot was a success, it only tested the crowdsourced security concept against public-facing websites.  We believe the concept will be successful when applied to many or all of DoD’s other security challenges,” a DoD spokesperson said in a statement.
Hack the Pentagon was administered by the bug bounty platform HackerOne, which reports that the pilot generated 138 unique bug reports and a total of $71,200 in bounties paid to hackers.


Not much guidance out there.
Lisa M. Thomas of Winston & Strawn writes:
The Office of the Australian Information Commissioner (OAIC) recently published a draft “Guide to big data and the Australian Privacy Principles” (Guide), and asked industry participants for comments.  The guide is intended to help companies understand how the Australian Privacy Principles (under the Australian Privacy Act 1988) apply to big data that contains information about “an identified individual, or an individual who is reasonably identifiable.”  Often, there is a question whether or not information contained in big data is really personally identifiable, or is “de-identified,” (Guide, p. 3) which to OAIC, is information that is sufficiently de-identified that “the information is no longer about an identified individual or an individual who is reasonably identifiable.” (Guide, p. 3).  When sufficiently de-identified, the Guide indicates, the privacy principles would not apply.
Read more on Winston & Strawn.


The Sports Book is open!  OR: Oh look, an application for Watson!
New York State Lawmakers Vote to Legalize Fantasy Sports
   The businesses’ legislative backers in New York have insisted that fantasy sports is not gambling — which is mostly barred by the state’s Constitution — but rather is “based upon the skill and knowledge of the participants.”  The widely advertised games, in which players create imaginary teams using real players and win or lose depending on the players’ statistics, would be classified as games of skill, not chance, a distinction under a 2006 federal law governing online wagering.


An illustration of the old adage, “Cheaters never prosper!”  (Unless they get away with it of course.) 
VW Said Ready With $10 Billion Diesel Plan, to Devise Fix Later
Volkswagen AG  will submit its $10 billion plan this month to fix a half-million emissions-cheating cars or get them off U.S. roads even though it’s awaiting regulators’ sign-off on how to retrofit the vehicles, a person familiar with the matter said.
About $6.5 billion will go to car owners and $3.5 billion to the U.S. government and California regulators, said the person, who asked not to be identified because the deal isn’t public yet.


Perspective.  Successful is not always profitable.  A lesson for my IT Architecture students.
Can Netflix survive in the new world it created?
   Netflix, since its streaming service debuted in 2007, has had its annual revenue grow sixfold, to $6.8 billion from $1.2 billion.  More than 81 million subscribers pay Netflix $8 to $12 a month, and slowly but unmistakably these consumers are giving up cable for internet television: Over the last five years, cable has lost 6.7 million subscribers; more than a quarter of millennials (70 percent of whom use streaming services) report having never subscribed to cable in their lives.  Those still paying for cable television were watching less of it.  In 2015, for instance, television viewing time was down 3 percent; and 50 percent of that drop was directly attributable to Netflix, according to a study by MoffettNathanson, an investment firm that tracks the media business.
All of this has made Netflix a Wall Street favorite, with a stock price that rose 134 percent last year.
   At the moment, Netflix has a negative cash flow of almost $1 billion; it regularly needs to go to the debt market to replenish its coffers.  Its $6.8 billion in revenue last year pales in comparison to the $28 billion or so at media giants like Time Warner and 21st Century Fox.  And for all the original shows Netflix has underwritten, it remains dependent on the very networks that fear its potential to destroy their longtime business model in the way that internet competitors undermined the newspaper and music industries.

(Related) Something else for my Architecture students.  (Who are all too young to remember.)
How Mobile Today Is Like TV Six Decades Ago
In the early 1950s, television was popular, but unsophisticated.  This was a common sentiment, even among the people who produced it—"a hybrid monstrosity derived from newspapers, radio news, and newsreels, which inherited none of the merits of its ancestors," as one CBS News anchor summed it up.  But either despite its gimmicky shortcomings or because of them, advertisers loved the little box.  Revenue from ads increased more than 60 percent a year for the first five years of the decade, so that by 1955, television accounted for nearly 20 percent of total U.S. media advertising.
This year, mobile media accounts for the exact same share, nearly 20 percent of total U.S. media spending.  So, in a very real way, mobile is today where television was exactly six decades ago.


In case you missed this yesterday…
Facebook Reveals How It Decides if a Research Project Is Ethical
   Now, after nearly two years of soul-searching, Facebook has revealed how it reviews and approves the experiments the company runs on users without them knowing about it.
In a new paper, called “Evolving the IRB: Building Robust Review for Industry Research,” company officials describe a process that loosely imitates the system used at universities, which convene institutional review boards, or IRBs, to evaluate research projects on their scientific and ethical merits.
At Facebook, which is constantly experimenting on its users, “expert” managers have to approve all research projects, according to the paper.


Many students use Chrome; not sure how many have a map-able mind.
Connected Mind - A Mind Mapping App in Chrome
Connected Mind is a free mind mapping tool that you can find in the Google Chrome Web Store. Using Connected Mind you can create free-form mind maps or use a template. A lot of mind mapping tools lock you into using straight lines between elements, but Connected Mind is not one of them. Connected Minds allows you to create mind maps in any configuration that you like. As it is a Chrome Web Store app, Connected Mind allows you to save your work online using your Google Account credentials. The video below offers a demonstration of Connected Minds (there is not any sound in the video).


This is not the future.  This is now!