Wednesday, June 04, 2014

How do I surveil thee?
Let me count the ways...
Nathan Freed Wessler writes:
A Florida judge has sided with the ACLU to order release of information about police use of “stingrays,” which are invasive surveillance devices that send out powerful signals to trick cell phones into transmitting their locations and identifying information. The Tallahassee judge’s pro-transparency decision stands in contrast to extreme secrecy surrounding stingray records in another Florida court, which is at the center of an emergency motion filed by the ACLU today.
Read more on ACLU.
[From the article:
Late yesterday, the judge ordered unsealing of the entire transcript. The portion that the government had sought to keep secret is here.
… Stingrays can track cell phones whenever the phones are turned on, not just when they are making or receiving calls.
… In this case, police used two versions of the stingray — one mounted on a police vehicle, and the other carried by hand. Police drove through the area using the vehicle-based device until they found the apartment complex in which the target phone was located, and then they walked around with the handheld device and stood “at every door and every window in that complex” until they figured out which apartment the phone was located in.


“Users who take appropriate security measures protect their own privacy.” (Otherwise we read their email to send them appropriate ads.) Or does Google know how to read Google encrypted emails?
Google goads users to use encryption
As much as 50% of e-mail traffic sent from or to Gmail users isn't really private, and Google thinks it should be.
To nudge e-mail providers to make use of already existing encryption, Google on Tuesday published a page telling users which e-mail services support encryption and which do not, based on what it can see of e-mails sent by Gmail's 425 million active users worldwide.
The statistics were posted on Google's Transparency Report. There, users can search by region to see whether their e-mail provider has encryption turned on.


“Information” increases faster than “data?” Is there a point beyond which anyone can learn anything (everything?) about anyone because of the volume of data available on the Internet?
Can computer science and “mosaic theory”– the idea that a large enough collection of data is vastly more revealing than the individual points– help reinterpret Fourth Amendment search and seizure and surveillance protocols?
The answer is yes, according to University of Maryland Francis King Carey School of Law Professor Renee Hutchins, co-author of a new paper that examines how advances in machine learning technology may change the way courts treat searches, warrants, and privacy issues.
Read more on Newswise.
Related Article:
When Enough is Enough: Location Tracking, Mosaic Theory, and Machine Learning (pdf) by Steve Bellovin, Renee M. Hutchins, Tony Jebara, and Sebastian Zimmeck.


Perspective.
Microsoft Examines Relationship Between Cybersecurity and Socio-Economic Conditions
In the report, “Cyberspace 2025: Today’s Decisions, Tomorrow’s Terrain”, Microsoft predicts that by the year 2025, over 91% of people in developed countries and 69% in emerging countries will be using the Internet, and dependence on the Web will become a reality.
… Earlier this year, a report released by the World Economic Forum during its famous annual meeting, outlined different scenarios for how things could look in 2020 based on the “conceivable value created from innovations in technology” that could be affected by global organizations’ ability to defend against cyber attacks.
According to statistics cited by the World Economic Forum (WEF) in its report, technology trends such as cloud computing and big data have the potential to create between $9.6 trillion and $21.6 trillion in value for the global economy. However, the reports notes, if attacker tactics outpace the capabilities of defenders, more destructive attacks will result and spark a wave of new regulations and corporate policies that could slow innovation with a massive economic impact.


A heads-up for my Ethical Hackers.
Your car is a giant computer - and it can be hacked
Most people aren't aware their cars are already high-tech computers. And now we're networking them by giving them wireless connectivity. Yet there's a danger to turning your car into a smartphone on wheels: It makes them a powerful target for hackers.
Interviews with automakers, suppliers and security advisers reveal a major problem with the new wave of "connected" cars: The inside of your car has ancient technology that presents a security risk.
… Cars' computers were built safely enough back in the 1990s, when the car was a closed box. But their architecture won't hold up as we hook them up to the Internet.


Tools & Techniques. Isn't this too broad an interpretation of copyright law? If so, you might want to grab a copy now, before the injunctions start flying. NOTE: Not free and not cheap!
Save Videos From Any Site – Even Netflix – With Applian’s Replay Capture Suite
If you can watch or listen to something, you can record it. All you need is the right tool.
… One Applian program, called Replay Media Catcher, is a video downloader that grabs videos from unencrypted sites like YouTube and Vimeo – but not sites like Hulu and Netflix, which encrypt their files.
Another program, Replay Video Capture, isn’t a downloader at all: it actually records what’s happening on your screen, meaning you can save a copy of any online media – even Netflix or Hulu – without the need to break any encryption.
… “Copyright laws are pretty clear that you’re allowed to record for your own personal use,” says Bill Dettering, CEO of Applian Technologies. This means that if you record something, but don’t share it with others or attempt to sell it, you’re within your rights.


Maybe this is what my students are doing when they should be studying?
Make Money Gaming: 5 Games You Can Get Paid To Play


Because I have students who want to learn stuff we don't teach, yet.
– Education is changing, with great educators from around the world increasingly putting their amazing courses online. SlideRule believes that we all are in the early days of a revolution that will not only increase access to great education, but also transform the way people learn. SlideRule will help you discover the world’s best online courses in every subject.

Tuesday, June 03, 2014

What does your phone know? (How does your phone know all this?)
Don’t Miss The Next Big Thing — iBeacons
In Apple’s WWDC this year, one of the seemingly minor announcements has many industries abuzz with anticipation — iBeacons. While Apple did not highlight this new technology as prominently as others, mobile app developers and physical retail executives see huge potential in this nascent technology.
… Think of it this way: You’re walking through an airport, and your phone knows you normally buy a cup of coffee around 8am. So, it sends you a prompt letting you know that a Starbucks is 50 feet away on your left. Or, you’re in a clothing store. Based on your buying history, your phone knows your size and what styles you prefer, so it sends you a prompt telling you where to go in the store to look for those types of items. Maybe you’re in a grocery store buying a bottle of wine? Your phone knows you like Merlot and there’s a sale on one of your favorite bottles one row over… Your phone could send you a push notification alerting you to that sale.


Am I reading this correctly? This is not a development project? Who had this software ready to sell?
Secret Service seeks software to monitor current and historical social media data
by Sabrina I. Pacifici on June 2, 2014
Via NextGov: “The Secret Service is purchasing software to watch users of social networks in real time, according to contract documents. In a work order posted on Monday, the agency details information the tool will collect — ranging from emotions of Internet users to old Twitter messages. Its capabilities will include “sentiment analysis,” “influencer identification,” “access to historical Twitter data,” “ability to detect sarcasm,” and “heat maps” or graphics showing user trends by color intensity, agency officials said. The automated technology will “synthesize large sets of social media data” and “identify statistical pattern analysis” among other objectives, officials said.”


Is this how we move toward global government? (at least, global laws?) Or will some banks lie to the IRS and keep my accounts hidden?
IRS Nets Offshore Data From 77,000 Banks, 70 Countries In FATCA Push
An astounding 77,000 banks and financial institutions—even some in Russia—have registered under FATCA—the Foreign Account Tax Compliance Act. America’s global tax law requires foreign banks to reveal American accounts holding over $50,000. Non-compliant institutions could be frozen out of U.S. markets, so everyone is complying. The fact that 77,000 banks have registered and some 70 countries are providing government help to the IRS means almost no foreign account is secret.


My students will appreciate this.
How To Make Money Online
… You can earn a decent living just by blogging. If you’re a skilled writer or transcriber, there’s a job opportunity waiting for you.
If you’re still curious about making money on the Internet after reading through this flowchart, you might want to check out the extensive infograph on 200 ways to make money online.

Monday, June 02, 2014

Hit them were they ain't looking.
Windows PowerShell Increasingly Abused by Attackers
Windows PowerShell is a task-based command line shell and scripting language that enables IT teams to control and automate the administration of the operating system and applications. Built on the .NET Framework, the tool is available for all current versions of Windows, and it has been included by default starting with Windows 7.
Experts believe cybercriminals are increasingly relying on PowerShell because this is not a common technique and IT administrators who are usually on the lookout for malicious binaries might overlook threats that abuse the scripting tool.


Perspective, and a warning.
Business Adapts to a New Style of Computer
by Sabrina I. Pacifici on June 1, 2014
“The Internet of Things is especially important for companies that sell network equipment, like Cisco Systems. Cisco has been enthusiastically predicting that 50 billion “things” could be connected to communications networks within six years, up from around 10 billion mobile phones and PCs today (see “Silicon Valley to Get a Cellular Network, Just for Things”). Another beneficiary is the $300 billion semiconductor industry. As Blaauw notes, “Every time there has been a new class of computing, the total revenue for that class was larger than the previous ones. If that trend holds, it means the Internet of things will be bigger yet again.” But every shift promises pain, too. Large companies like Intel are already reeling from the rapid emergence of smartphones. Intel, with its powerful, power-hungry chips, was shut out of phones. So was Microsoft. Now both these companies, and many others, are groping to find the winning combination of software, interfaces, and processors for whatever comes next.”
The Economics of the Internet of Things


Government by magic? Regulating without regulations?
A number of people were hopeful that the FTC would disclose more information about its data security standards in testimony to be provided by Daniel Kaufman, Deputy Director of the FTC’s Bureau of Consumer Protection, in FTC v. LabMD.
If you were expecting new insights, however, you will likely be disappointed. Rather than having Kaufman testify last week during the heading before Administrative Law Judge Chappell, both LabMD and the FTC agreed to simply enter Kaufman’s deposition into the record.
So what was in his deposition? Here’s a sample exchange.
… The short version: for pretty much every aspect of the complaint in paragraph 10, Kaufman testified that the FTC had communicated that standard via its speeches, business guidance documents, testimony to Congress, and previous settlements, but he would not go so far as to say whether LabMD could have violated any of those standards and still be found to have complied with “reasonableness” under Section 5.
So where does that leave entities? It seems that we all must follow all of the FTC’s speeches, blog entries, and testimony to Congress, in addition to reading all of their settlements and closing letters if we want to deduce what all the standards are that we must comply with to stay on the safe side of the FTC.
… I’ve uploaded the second day of Kaufman’s deposition here (pdf), if you’d like to read it in its entirety.


Perhaps we could build one like this for the FTC?
New on LLRX – World leading online privacy law library gets big increase in capacity
by Sabrina I. Pacifici on June 1, 2014
The International Privacy Law Library on WorldLII has been expanded. The Library’s 32 databases include about 3,600 decisions of 13 privacy and data protection authorities, from New Zealand, Ireland, the United Kingdom, Hong Kong, Australia, Korea, Macau, Mauritius, the United States and the European Union.


This could get really messy.
Google's 'Right To Forget' Approach Should Not Be Leveraged By The Music Industry
Following the EU ruling on the principle of a ‘right to be forgotten’ by a search engine, Google has put in place their “initial effort” to comply with the ruling. Critics of Google in the music industry are looking at the reaction to the ruling, and are hoping to use it to bolster their arguments that the Mountain View based company should do more to police their search engine results.
… In a sense a link to something that could damage an individual is now beginning to be treated in the same way as a link to something that could damage the value of a copyrighted piece of media.
This has not stopped the music industry pointing out the ‘right to forget’ process to strengthen their argument that Google should be determining the legality of content not held on Google’s servers. Geoff Taylor is the Chief Executive of the BPI, the UK’s trade body for the music industry. Quoted in The Guardian, he makes the case that Google should be more proactive in dealing with outbound links from the search engine.
“It’s ‘Don’t be Evil’ 101,” says Geoff Taylor, chief executive of the music industry’s trade body, the BPI. “The principle at stake here is when you know someone is acting illegally, you shouldn’t continue helping them by sending them business.”
For me, the key part of the quote here is “when you know someone is acting illegally”. Computers must follow hard and fast rules they are not very good at judgement calls. Google cannot yet automatically decide with certainty if something it is linking to is ‘fair use’, ‘parody’, or ‘breaking copyright’.
The music industry and Google have a long antagonistic relationship with each other around linking to potentially copyrighted material. The EU ruling around the ’right to be forgotten’ is an important social issue that generates differing viewpoints on either side of the Atlantic that needs to be addressed. It should not be used in the continued debate around linking to material that may or may not be breaking copyright.


Question: How does political fund raising impact regulation? Also note that “creating” a channel to politicians does not ensure that it will be used, by either end of the “conversation.”
Social Media #FTW!: The Influence of Social Media on American Politics
by Sabrina I. Pacifici on June 1, 2014
Via LLRX - Thesis submitted to Johns Hopkins University in conformity with the requirements for the degree of Master of Arts in Government by Kenneth Scott Ames
Social Media #FTW!: The Influence of Social Media on American Politics – Abstract: “Social media has transformed politics in America. Its effect has impacted the way candidates campaign for the presidency, Members of Congress operate their offices, and advocacy organizations communicate with policymakers and supporters. Social media allows politicians and organizations a method to connect directly and without filters with people across the country, assemble a constituency, and solicit their support at a reduced cost and greater reach than traditional media. Social media is not simply the next in a line of communications technologies: it has changed everyday activities and connected people in a manner never before possible. The rise of smartphone technology has enabled this trend since people can access the Internet almost anywhere making a mobile device a potential organizing and fundraising tool. Social media has transformed politics in America because it creates an instantaneous multi-directional public dialogue that offers the ability to rapidly analyze the data and learn from the findings on an unprecedented scope.”


For my Ethical Hackers. Hack one, hack them all.
Google to launch 180 satellites in $1bn plan to cover the unwired
Google will spend north of $1bn to launch a fleet of 180 satellites to blanket unwired parts of earth with internet access, according to the Wall Street Journal.
While details of the project are subject to change, people familiar with Google's satellite plans told the paper the project will start with 180 small, high-capacity satellites that orbit lower than typical satellites.


Perspective. I never would have guessed... (Very strange headline)
This Is The Most Commonly Spoken Language Spoken In Your State
The handy map below takes a look at the most common languages spoken at home, other than Spanish or English.


Amusing and potentially very scary.
– is a site that offers human-sized photos. They are called Engineer Prints because the prints are made on industrial printers typically used for architectural and engineering work. Your photo will be printed in halftone black and white ink on extra-light 20lb bond at a whopping 4 feet wide. Once it’s done it ships free, rolled nice and neat for just $40.


My students think “Free is Good!” I hardly had to train them at all. I list the ones I like.
6 Ways You Can Use Microsoft Office Without Paying For It
Microsoft Office remains the gold standard in office applications. Sure, Office alternatives exist, but Microsoft’s file formats dominate. People with access to Office tend to have an easier time than those who lack it, because while alternatives like LibreOffice can export to .doc or .xls, the formatting isn’t 100% compatible.
Microsoft itself offers a collection of free Office utilities formerly known as Office Web Apps and now called Office Online. They are essentially browser-based versions of the latest Office suite. You can use Word, Excel, and PowerPoint without paying a dime.
Ask Your School Or Employer
Many companies offer a low-cost or no-cost version of Office for a fairly obvious reason; the people working or studying there need it. Academic institutions often participate in Microsoft’s DreamSpark program (formerly MSDNAA), allowing them to offer professional software to their students and employees for free.

Sunday, June 01, 2014

Apparently nothing happened today.


A perfect article for my Statistics students as we study correlation.
Prove Anything With Statistics Using Spurious Correlations [Weird & Wonderful Web]
Mark Twain once said, “There are lies, damned lies, and statistics.” The point being that statistics can be used to prove anything, whether they’re made up on the spot or generated by real data.
You don’t have to take my word for it either, as a website called Spurious Correlations perfectly demonstrates how statistics can be bent and shaped to suit a particular bias.
… Spurious Correlations is the brainchild of Tyler Vigen, a criminology student at Harvard Law School. Vigen is fascinated by empirical research, so he created a simple website dedicated to comparing variables, and how closely they correlate with each other.
There is a new one of these Spurious Correlations posted to the site every day, with over 24,000 posted to date. As well as those generated automatically, visitors can discover their own by selecting two different datasets to compare with one another.
The money spent on pets in the U.S. correlates with the number of lawyers in California.
The divorce rate in Maine correlates with the per capita consumption of margarine in the U.S.

Saturday, May 31, 2014

Looks like the ATMs don't edit the data from the card. Really bad programming?
Thieves Planted Malware to Hack ATMs
A recent ATM skimming attack in which thieves used a specialized device to physically insert malicious software into a cash machine may be a harbinger of more sophisticated scams to come.
Authorities in Macau — a Chinese territory approximately 40 miles west of Hong Kong — this week announced the arrest of two Ukrainian men accused of participating in a skimming ring that stole approximately $100,000 from at least seven ATMs.
Local police said the men used a device that was connected to a small laptop, and inserted the device into the card acceptance slot on the ATMs. Armed with this toolset, the authorities said, the men were able to install malware capable of siphoning the customer’s card data and PINs.
… The Macau government alleges that the accused would return a few days after infecting the ATMs to collect the stolen card numbers and PINs. To do this, the thieves would reinsert the specialized chip card to retrieve the purloined data, and then a separate chip card to destroy evidence of the malware.


Perspective. Give it a few years and everyone will be hacked multiple times each year. So often, you won't know who to sue.
Report – Half of American Adults Data Hacked So far This Year
by Sabrina I. Pacifici on May 30, 2014
EPIC: “A new report finds that 432 million online accounts in the US have been hacked this year, concerning about 110 million Americans. In the last year, 70 million Target customers, 33 million Adobe users, 4.6 million Snapchat users, and potentially all 148 million eBay users had their personal information exposed by database breaches. Earlier this month, the President’s science advisors found little risk in the continued collection of personal data. However, the FTC’s recent report on data brokers warned that, “collecting and storing large amounts of data not only increases the risk of a data breach or other unauthorized access but also increases the potential harm that could be caused.” Earlier, EPIC urged the White House to promote Privacy Enhancing Techniques that minimize or eliminate the collection of personally identifiable information. For more information, see EPIC: Big Data and the Future of Privacy,EPIC: Identity Theft and EPIC: Choicepoint.”


Got any embarrassing photos you'd like removed? Send your request from a European address.
Google sets up 'right to be forgotten' form after EU ruling
Google has launched a service to allow Europeans to ask for personal data to be removed from online search results.
The move comes after a landmark European Union court ruling earlier this month, which gave people the "right to be forgotten".
Links to "irrelevant" and outdated data should be erased on request, it said.
Google said it would assess each request and balance "privacy rights of the individual with the public's right to know and distribute information".
"When evaluating your request, we will look at whether the results include outdated information about you, as well as whether there's a public interest in the information," Google says on the form which applicants must fill in.

(Related)
‘Right To Be Forgotten’ is a hit in Europe; 12,000 requests to Google on Day 1


Because the government needs to know if you can afford campaign contributions or are rich enough to have good lawyers (and therefore laws don't apply to you) or are failing to report cash (and therefore are a drug dealer)
New federal database will track Americans’ credit ratings, other financial information
by Sabrina I. Pacifici on May 30, 2014
Washington Examiner, Richard Pollock: “As many as 227 million Americans may be compelled to disclose intimate details of their families and financial lives — including their Social Security numbers — in a new national database being assembled by two federal agencies. The Federal Housing Finance Agency and the Consumer Financial Protection Bureau posted an April 16 Federal Register notice of an expansion of their joint National Mortgage Database Program to include personally identifiable information that reveals actual users, a reversal of previously stated policy… But under the April register notice, the database expansion means it will include a host of data points, including a mortgage owner’s name, address, Social Security number, all credit card and other loan information and account balances. The database will also encompass a mortgage holder’s entire credit history, including delinquent payments, late payments, minimum payments, high account balances and credit scores, according to the notice. The two agencies will also assemble “household demographic data,” including racial and ethnic data, gender, marital status, religion, education, employment history, military status, household composition, the number of wage earners and a family’s total wealth and assets.”


Does anyone believe this? Could the FTC articulate “Best Practices?” How about “Not too bad Practices?”
Companies should already know how to protect data, FTC argues
The Federal Trade Commission (FTC) has published enough information publicly for companies to know exactly what the agency considers reasonable security practices for protecting sensitive data, an FTC representative said in deposition entered this week in a closely watched case challenging its authority to enforce data security standards.
"The [FTC] has published a great deal of consumer and business education on the issue of what is reasonable data security," Daniel Kaufman, the deputy director for the FTC's Bureau of Consumer Protection, said in deposition before an FTC administrative court. "The Commission has testified on it on a number of occasions, and there's a lot of other publicly available information on what constitutes reasonable data security."
The deposition involves a dispute between the FTC and LabMD, an Atlanta-based medical laboratory that claims it was driven out of business by an FTC data breach investigation.
… The FTC last August filed a formal compliant against LabMD over data leaks dating back to 2008 that exposed personal information on close to 10,000 people. In its complaint, the FTC charged LabMD with unfair trade practices for not doing enough to protect data. [Enough? Or what we have published as “reasonable?” Bob]
Over the past few years, the agency has filed similar complaints against dozens of companies that suffered data breaches and has won settlements from almost all of them.
LabMD, however, challenged the FTC complaint and accused the agency of holding it to data security standards that do not exist officially at the federal level. The only other company to challenge the FTC so far is Wyndham Hotels, which has argued that the agency has no legal authority to enforce data security controls on companies.
Both cases are widely seen as a test of the FTC's authority to punish companies that suffer data breaches. Many have expressed concern that the FTC may be overstepping its authority in going after breached firms.
… In response to the LabMD motion, the FTC argued that it was not obligated to disclose the standards it uses to judge whether a company has adequate controls or not. However, in a setback for the agency, the FTC's chief administrative judge earlier this month held that the agency could indeed be compelled to disclose the standards.


Assuming this proves the concept at the state level, will other/all states do this?
The Texas Tribune and Oyez® to launch multimedia site for Texas high courts
by Sabrina I. Pacifici on May 30, 2014
IIT Chicago Kent College of Law - “Texas will soon benefit from an online archive for its two highest courts, launched through a partnership between The Texas Tribune and Oyez®, a free law project at IIT Chicago-Kent College of Law, with support from the John S. and James L. Knight Foundation. Amidst a scarcity of news coverage about law, the partnership between The Texas Tribune and Oyez will increase public access to the cases before the Supreme Court of Texas and Texas Court of Criminal Appeals. This offers more opportunities for in-depth reporting and research on the state’s judicial system… The site will go live in late summer 2014 and offer case summaries written for a non-legal audience. The multimedia resource will include opinions, transcript-synchronized videos of oral arguments, justice biographies and decision information. Fundraising is also underway to provide Spanish translations of case information… The partnership is part of a larger initiative to expand Oyez’s successful U.S. Supreme Court site to all federal appellate and state supreme courts. The Knight Foundation has funded Oyez’s efforts in Texas, as well as in California, New York, Florida and Illinois, covering one-third of the U.S. population.”


Perhaps my Criminal Justice students would find this useful.
– Search more than five million legal cases with precision, using natural language or Boolean. Ravel lets you focus on judges’ words and analysis, removing clutter so that you can read and scan quickly. Mining the connections that link millions of court documents, Ravel’s technology identifies cases’ key passages and shows how later cases have rephrased or interpreted them.


Tools for my Computer Security and Ethical Hacking students.
– is a collection of useful online tools for your computer. As the name of the site suggests, you can view DNS settings and DNS changes. But that is not all the site offers. It also offers various tools that you would normally have to surf to other sites to use. Here they all are on the same page for your convenience. This includes Is My Site Down, and an IP location finder.

(Related) The start of a series about analyzing the “Big Data” from security logs. Simple in concept, tedious to implement.
Finding Needles in the Haystack of Security Events
… Security devices generate volumes of raw data, usually in a proprietary manner. Parsing such unstructured data and making sense out of it is a tedious, if not an impossible task. If that’s not enough to make you cringe, when your organization is under a DDoS attack, your CIO is going to want not only a resolution but the answers to Who, What, Where, When, Why and How – fast. Security is time-sensitive; every minute counts and every second that ticks by negatively impacts your bottom line – brand degradation, unhappy customers and ultimately lost revenues.
… The goal of inspecting Internet traffic and establishing a baseline is to determine the normal activity level for your environment and establish any thresholds that would indicate a threat or security event in order to generate the proper alerts. Normal activity levels can vary by time of day or by the month of the year or by some other factors specific to your business.
… Once the baselines are established, SOCs monitor all activity (network activity, security events) and analyze those that exceed the pre-determined thresholds or indicate suspicious behavior. Monitoring involves tracking abnormal behavior, outside the range of normal activity levels established during the baseline, and is almost always done via the alerting procedures that notify SOC personnel via an e-mail, SMS, dashboard indicators, or a combination of these.


Continuing to automate the legal functions. Soon there will be nothing left for lawyers to do!
5 Apps & Online Tools To Help You Write a Will


Is it because too many people have too much money, or is it that I don't?
Did Steve Ballmer pay too much for the Los Angeles Clippers? The market says no.
At least on a surface level, the Los Angeles Clippers appeared to be a lousy investment for any potential buyer — a franchise with none of the championship history and Hollywood buzz of the rival Lakers and one still reeling from the racist comments made five weeks ago by now-deposed owner Donald Sterling.
But as the sports industry begins to process the staggering amount — $2 billion — for which Sterling’s wife agreed to sell the Clippers, it is clear, in this new Golden Age of sports television, there is no franchise too weak or too sullied to command a windfall at auction, especially in Hollywood.


I must be out of touch. I can't imagine what a good old fashioned spanking would result in. (Is Hawaii infested with pedophiles?)
Father Gets Probation For Making Son Walk Home From School
A Hawaii man has been sentenced to a year of probation after making his son walk a mile [Oh the horror! Bob] home from school.
Robert Demond was convicted of a misdemeanor charge of second-degree endangering the welfare of a minor.
Demond explained that his son had been involved in some sort of rule-breaking at school. When Demond picked him up, he asked about it, but his son refused to respond. Demond then stopped the car and told his son to walk to rest of the way home to think about what he had done, reports the Garden Island.
The judge, Kathleen Watanabe, ruled that the punishment was “old-fashioned” and inappropriate. She said that it is dangerous for children to walk alongside the road due to potential pedophiles. It was a form of punishment no longer supported by the community.

(Related) What are we teaching/failing to teach our teachers?
The Sydney Morning Herald reports:
A Victorian mother is demanding answers after her teenage daughter’s armpits were shaved by her teacher as part of the school’s curriculum.
Melissa Woods, mother of 14-year-old Taylah, says her daughter was “extremely upset” when her armpits were shaved in front of two other girls in a classroom.
Read more on Sydney Morning Herald.


Something for my Statistics students to debate. No doubt Google and whichever auto makers lease their software will get sued a lot. Probably worth having insurance for anything that gets past their lawyers. (Will cars be subject to “grounding” like airplanes? One measly little wing falls off and the FAA gets all safety conscious.)
Car insurance would be a lot cheaper without drivers
… Driverless cars may shrink your insurance costs.
Human error accounts for more than 90% of car crashes, multiple studies have found. Cars that drive themselves are expected to dramatically reduce that statistic, particularly since Google’s version nixes the steering wheel and brakes. “They have sensors that remove blind spots, and they can detect objects out to a distance of more than two football fields in all directions, which is especially helpful on busy streets with lots of intersections,” Chris Urmson, director of Google’s self-driving car project, wrote in a blog post. Those factors could also largely absolve drivers from liability for accidents, experts say.

Friday, May 30, 2014

No doubt this will result in a push to legalize other drugs.
Denver Murder Rate Cut in Half After Marijuana Legalization. Coincidence?
According to statistics recently released by the government in Denver, the amount of robberies and violent crimes significantly decreased since marijuana legalization went into effect. It is important to mention that this strong correlation is not definitive proof that legalization is the cause of this drop in crime, but it does strongly suggest that this is the case.
These statistics are especially convincing considering the short amount of time that this drastic reduction in crime has taken place. In just one short year the number of homicides dropped by 52.9%. Sexual assaults were reduced by 13.6%. Robberies were down by 4.8% and assaults were down by 3.7%.
The statistics measured the first few months of the year for both 2013 and 2014, and then compared those numbers with one another to determine whether they were higher or lower after legalization went into effect.


Oops! Heads up!
TrueCrypt Encryption Software Shut Down, May Be Compromised
Independent encryption software TrueCrypt is apparently not as secure as many thought. Yesterday (May 28), the TrueCrypt homepage was suddenly replaced with a notification that read "WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues."
TrueCrypt is used by many security-minded people, including NSA whistleblower Edward Snowden, to turn a storage device, such as a flash drive or hard drive or a partition of such a device, into an encrypted volume, protecting the documents stored in that volume from prying eyes.
But TrueCrypt's creators never revealed their true identity, which caused others to be skeptical of its integrity.


Lawyers. No matter how often I tease them about this, they still insist that encryption is too complicated for their clients – even when their clients are the firms that create encryption Apps.
LexisNexis – Study tells a Story about Law Firm File Sharing
by Sabrina I. Pacifici on May 29, 2014
LexisNexis Survey of Law Firm File Sharing in 2014 – “This study found that file sharing is increasingly important in law firm collaboration and while those firms are keenly aware of the consequences of IT security risks, unencrypted email – reinforced with a statement of confidentiality – remains the primary mechanism for sharing files.
  • See also this related infographic - http://www.slideshare.net/BusinessofLaw/lexisnexis-2014-survey-of-lfile-sharing-survey-report-final


If it's not something you immediately recognize as part of the Internet of Things, we can “thingify” it for you! (We will know everything you do, everything you are, everything you think. Then we'll sell that information to people who want to sell you things to help you do more, be healthier and think Republican!)
Samsung wants to 'thingify' your BODY with Simband
… As Samsung says, it's a reference design for a platform, rather than yet-another-Fitbits-knockoff: “Devices based on the Simband platform will be able to gather vital diagnostic information - from your heart rate to your skin’s electrical conductivity, 24 hours a day, seven days a week.”


Would you call this “Self-Surveillance?” Perhaps “Auto-Surveillance?”
– is an easy way to keep a record of your things. Keep an always up-to-date record of what you own, with easy access to receipts, manuals and warranty information. After connecting with Gmail, Unioncy pulls information from Amazon receipts in your inbox to create a collection of your things. They then match manuals & warranty information with important information from manufacturers and other reliable sources.


Perspective
Tablet Slump Predicted as More People Buy Phablets
… "First, consumers are keeping their tablets, especially higher-cost models from major vendors, far longer than originally anticipated. And when they do buy a new one they are often passing their existing tablet off to another member of the family," Mainelli said in a statement. "Second, the rise of phablets — smartphones with 5.5-inch and larger screens — are causing many people to second-guess tablet purchases as the larger screens on these phones are often adequate for tasks once reserved for tablets."


Perspective. Is it just me or are “valuations” like this one a bit excessive?
Uber's new potential valuation? $17B
Uber’s plans to raise more venture capital could push its value up to $17 billion.
“This one could be record-breaking,” CEO Travis Kalanick said at Re/code's Code Conference Wednesday.
The San Francisco car-sharing company has raised more than $300 million thus far. Its service connects people needing a ride with drivers in 115 cities around the world and employs 900 people.


For my Computer Security students.
Google Launches Game to Teach XSS Bug Discovery Skills
Google has launched a new game to teach Web application developers how to spot cross-site scripting (XSS) bugs in their code.
XSS vulnerabilities are highly common in websites, but can be quite dangerous. In fact, Google pays up to $7,500 for XSS bugs discovered in important products.
The XSS Game, which requires a modern web browser with JavaScript and cookies enabled, is mainly addressed to Web application developers who don’t specialize in security. However, Google believes that while security experts might find the first levels easy, they could also learn a few things.
… “Cross-site attacks are dangerous because of what they do, but also because the three distinct types of each strike from different angles,” Chris Hinkley, a Senior Security Engineer at FireHost, explained in a late 2012 SecurityWeek column.
Cross-site scripting (CSS) can either be persistent or reflected, and cross-site request forgery (CSRF), where attackers use an authenticated session on one Website to perform unauthorized actions on another site, are also especially dangerous.

(Ditto)
Most Mobile Breaches Will be Tied to App Misconfiguration by 2017: Gartner
Analyst firm Gartner is predicting that by 2017, the focus of endpoint security breaches will shift to mobile devices such as tablets and smartphones.
With nearly 2.2 billion smartphones and tablets expected to be sold in 2014, Gartner believes attackers will continue to pay more attention to mobile devices. By 2017, 75 percent of mobile security breaches will be the result of mobile application misconfigurations, analysts said.


For my students.
The Condition of Education 2014
by Sabrina I. Pacifici on May 29, 2014
“The Congress has mandated that the National Center for Education Statistics (NCES) produce an annual Condition of Education report to help inform policymakers about the progress of education in the United States. This year’s report presents 42 indicators on important topics and trends in U.S. education. These indicators focus on population characteristics, participation in education, elementary and secondary education, and postsecondary education. This year’s Condition shows that about 90 percent of young adults ages 25 to 29 had a high school diploma or its equivalent in 2013, and that 34 percent had a bachelor’s or higher degree. As in previous years, in 2012, median earnings were higher for those with higher levels of education—for example, 25- to 34-year-olds with a bachelor’s degree earned more than twice as much as high school dropouts. Also, the unemployment rate was lower for bachelor’s degree holders in this age range than for their peers with lower levels of education.
… Postsecondary enrollment was at 21 million students in 2012, including 18 million undergraduate and 3 million graduate, or postbaccalaureate, students.


For my “You had better be researching” students. Watch the video.
Listango - A Quick and Easy Bookmarking Tool
The Internet is not lacking for bookmarking tools. Some are complex and robust while others are clean and simple. Listango falls into the clean and simple category. Bookmarking websites with Listango is a simple matter of clicking the Listango bookmarklet in your browser then choosing the list to which you want to add your bookmark.
To get started with Listango you register for an account then drag the Listango browser bookmarklet into your browser's bookmarks bar. With the Listango bookmarklet installed whenever you're viewing a site that you want to bookmark you can just click the Listango button to save the site to one of your bookmark lists. In your Listango account you can create as many categorized bookmarks lists as you like.


It's that time again. (Time for me to laugh)
… “Nevada education officials this month told a local man it would cost more than $10,000 to access the data the department has collected on his four children.” More via Education Week.
… COSN and the EducationSuperHighway organization estimate that it’ll cost $3.2 billion in E-rate subsidies to connect all the schools and libraries in the US at a level sufficient to support “1:1 digital learning.” Their full report is here. [I'll wager they spend 10 times that amount and never get close to 100% connections. Bob]