Monday, November 13, 2006

A long, but decent summary. Send this to any manger who doesn't “get” the need for information security...

http://www.nytimes.com/2006/11/12/business/yourmoney/12choice.html?ex=1320987600&en=14581a8cba5edab7&ei=5090&partner=rssuserland&emc=rss

Keeping Your Enemies Close

By GARY RIVLIN Alpharetta, Ga. November 12, 2006

IF you found yourself running a company suddenly branded one of the most reviled in the country — if, for example, you noticed that visitors to Consumerist.com, a heavily visited consumer Web site, voted yours as the second “worst company in America” and you had just been awarded the 2005 “Lifetime Menace Award” by the human rights group Privacy International — you might feel obliged to take extraordinary steps. You might even want to reach out to your most vocal critics and ask them, “What are we doing wrong?”

... “These guys were more sophisticated than anyone thought,” Mr. Lee said, echoing the sentiment of many inside the company.

But the F.T.C. seemed to reach the opposite conclusion in a 33-page report it released earlier this year, after it completed an investigation of ChoicePoint. The commission found that ChoicePoint ignored “obvious red flags” because the company “did not have reasonable procedures to screen prospective subscribers.” The report cast ChoicePoint’s criminal interlopers as sloppy and amateurish — but ultimately successful because their prey, a major company in the business of handling sensitive information, was alarmingly lax in its protection of its data repositories.

Signs that it was amateur hour inside ChoicePoint abounded, according to the F.T.C. report. The fraudsters faxed applications to ChoicePoint from a neighborhood Kinko’s, listed post office boxes as primary business addresses and offered cellphone numbers as sole telephone contacts — which no one at ChoicePoint ever bothered to call anyway to establish the numbers’ legitimacy. In at least one case, an approved applicant failed even to provide a last name, the F.T.C. found.

... It also took a state law. The data thieves who conned their way into ChoicePoint’s system downloaded information about at least 166,000 individuals. In years past, the company would alert law enforcement officials when it suffered a data breach, according to Mr. Lee, and leave it at that. But under a California disclosure law passed in 2003, the company was required to notify every Californian whose personal details might have fallen into criminal hands.

No one knows for sure, and no one can say, how many breaches occurred before California,” Mr. Hoofnagle said. “This is an ‘known unknown,’ as Donald Rumsfeld would say.”



Not the most un-biased web site?

http://www.homelandstupidity.us/2006/11/12/big-brother-big-business/

Big Brother, Big Business

By Michael Hampton Posted: November 12, 2006 1:12 pm

The Privacy Act of 1974, as amended, places a few restrictions on how the federal government can compile dossiers on Americans. It was passed in response to multiple scandals in which, for instance, former Federal Bureau of Investigation director J. Edgar Hoover would spy on Americans for his own purposes.

But does it go far enough? When the government can’t get the information on you that it wants because of the Privacy Act, it can always turn to a commercial data broker. And they know more about virtually everyone than anyone else, including the government itself.

On November 2, the cable network CNBC aired a two-hour special called “Big Brother, Big Business” which explored the issues of privacy and technology which can be used to track people.

I don’t want to ruin the ending, so I’ll just say that the Liberty Coalition put a copy of the special up on Google Video, and invite you to watch for yourself and make up your own mind. See what the commercial data brokers have to say for themselves.



http://slashdot.org/article.pl?sid=06/11/13/0732249&from=rss

Google Envisions Free Cell Phones For All

Posted by Zonk on Monday November 13, @04:20AM from the i-have-no-friends-you-insensitive-clod dept. Google Communications Businesses The Almighty Buck

Salvance writes "Google's CEO Eric Schmidt envisions a day when all cell phones are free if the user agrees to watch targeted ads. While he provides no specific plans for Google to give away phones, the implication is that he expects such moves in the future given Google's current pilot successes with delivering text ads on phones."

From the article: "Schmidt also said his company was working on how to allow users to maintain basic control of their personal data. Currently, Google stores consumer data on hundreds of thousands of its own computers in order to provide additional services to individual users. The company is looking to allow consumers to export their Web search history or e-mail archives and move them to other sites, if they so choose." [Where you can modify them to “prove” your innocence... Bob]



http://blogs.zdnet.com/Google/?p=387

Google Earth in 4D

Posted by Garett Rogers @ 9:55 am

Google skipped right past the third dimension and landed directly in the fourth (time) by offering historical maps on Google Earth. Now you can travel back in time — for example, I am looking at the globe of 1790. Don't expect detailed high resolution photography from days gone by, but it's still interesting to see old maps overlaid on the satellite imagery of today.



Just remember how simple this is...

http://majorgeeks.com/Wiretap_Professional_d5329.html

Wiretap Professional 6.0.1.4

Wiretap Professional is the premiere application for monitoring and capturing all important PC activity. Employing state-of-the-art packet sniffing techniques, Wiretap Professional can capture all Internet activity.

This means it can monitor and record Email, Chat Messages, and Web Sites Visited. In addition, powerful OS Monitors allow for the monitoring and recording of keystrokes, passwords entered, and all documents, pictures and folders viewed.

Sunday, November 12, 2006

Think of it as Rodney King, but with Open Source video rather than sale to the highest network bidder...

http://news.yahoo.com/s/ap/20061111/ap_on_re_us/videotaped_arrest

YouTube.com video prompts probe of LAPD

By ALEX VEIGA, Associated Press Writer Sat Nov 11, 7:08 AM ET

LOS ANGELES - An

FBI investigation prompted by video footage of a man being punched repeatedly in the face by police has demonstrated anew the power of the Internet sensation of the year, YouTube.com.

... The Los Angeles Times reported Friday that a Superior Court commissioner viewed the video nearly two months ago, heard the officers' testimony, and concluded that their conduct was "more than reasonable" because Cardenas was resisting.

... Legal observers said the public has become somewhat desensitized to questionable police tactics caught on tape because such videos have become more prevalent since the King beating. In many cases, officers have been exonerated.

"The first reaction by people is one of outrage," said Eugene O'Donnell, a professor of police studies at the John Jay College of Criminal Justice in New York City. "But the more you see police officers using force on tape, the more you get used to it."



...and they seem familiar with a few Open Source products!

http://news.com.com/2061-10796_3-6134573.html

Open source earns legal victory

November 10, 2006 2:26 PM PST

The open source software operations of IBM, Red Hat and Novell need not fear prosecution under antitrust laws, a federal appeals court has ruled.

Plaintiff Daniel Wallace had sued the open source giants, contending that they had conspired with the Free Software Foundation and others to offer their wares at an "unbeatable" price (read: free), thereby squeezing competing alternatives from enterprising software writers like Wallace out of the market. (Wallace, according to court documents, wanted to compete with Linux, "either by offering a derivative work or by writing an operating system from scratch.")

A three-judge panel at the U.S. Court of Appeals for the Seventh Circuit disagreed, upholding an earlier decision by a lower court.

"People willingly pay for quality software even when they can get free (but imperfect) substitutes," the judges wrote in a six-page opinion (click for PDF).

They named Open Office, a suite of word processor, spreadsheet and presentation software designed as an alternative to Microsoft Office, and Gimp, an open-source alternative to Adobe Photoshop, as examples of instances in which proprietary software manufacturers have had no trouble hanging onto the "lion's share" of the market.

The judges went on to knock down--and arguably mock--Wallace's arguments that people who release their software under the GNU General Public License are "conspirators" engaged in "price fixing."

"A 'quick look'," wrote the judges, "is all that's needed to reject Wallace's claim."



You don't often see articles like this in the traditional (non-techie) media... Some good quotes.

http://www.indystar.com/apps/pbcs.dll/article?AID=/20061112/BUSINESS/611120399

Security puzzle

Employers and clients at risk when vital data is carried around in laptops

By Dana Knight dana.knight@indystar.com November 12, 2006

So, you have been granted the privilege of a company laptop.

Here's a piece of advice: Treat that little black notebook like it's a pile of cold green cash.

... "Literally, pretend you are carrying around millions of dollars and protect it as such," said Amie Peele Carter, a partner with law firm Baker & Daniels who specializes in intellectual property.

... Some companies are instituting stringent policies, encrypting data and requiring 128-character pass codes. Others are counting on employees to use common sense.

More than 600,000 laptops are stolen annually and just 3 percent of those are recovered, according to the FBI.

... For some, the phenomenon hit home last month when an outside contractor working with Mishawaka-based Sisters of St. Francis Health Services inadvertently left compact discs containing confidential patient billing information in a laptop bag she purchased and then returned to a store.

The CDs contained names and Social Security numbers for about 260,000 patients and 6,200 employees, including some in Indianapolis.

St. Francis has a policy requiring such data be encrypted, or electronically scrambled, to keep unauthorized users from accessing it, according to spokeswoman Kay Johnson. The information on the misplaced CDs was not encrypted, however. A lawsuit has been filed by one of the patients affected and is awaiting class-action status approval.

... At JPMorgan Chase, encryption is also used.

"Even if it is stolen, you can't log on," said Nancy Norris, spokeswoman for the bank. "We take laptop security very seriously."

The company, for example, does not store confidential information on the hard drive, but only on the secure network, which is tough to access. Even in the office, a laptop must be secured with a locking cable and then locked in a cabinet at night, Norris said.



What is data security worth?

http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2006/11/10/BUGO4M8LB148.DTL&feed=rss.business

Another reason for data laws

David Lazarus Friday, November 10, 2006

As rental-car giant Hertz prepares to go public next week, the company seems to be having an unusually difficult time keeping confidential info under wraps.

In a regulatory filing on Wednesday, Hertz Global Holdings said it had dropped Deutsche Bank from its underwriting team after "several e-mails" discussing the $1.5 billion initial public offering were inadvertently sent by the bank to about 175 institutional clients.

Meanwhile, the names and Social Security numbers of an undisclosed number of Hertz workers were found last month on the home computer of a former employee of the company.

... In Hertz's case, the company is being reticent about the loss of its data. Broome declined to discuss details of the case or the number of workers affected.

"All we know is that our employee information is out there," he said. "We don't know how it got out there."

According to Hertz's letter to workers, dated Oct. 27, the data were found by the FBI "on the home computer of a former training department employee in Oklahoma City."

"We believe that the former employee obtained this information in the course of his employment in the training department and kept a copy when his employment ended, in violation of Hertz's policies," the letter says.

The letter says the computer is now in the possession of the FBI but offers no explanation for why federal agents are involved in the case, or how law enforcement became aware of the missing data. It says there's no evidence any of the data have been misused.

Broome told me that the missing info dates back to December 2002 and that Hertz previously used people's Social Security numbers as their employee I.D. numbers. He said this is no longer the case.

Broome said the company's training department keeps files on which employees had taken which in-house courses, and it would thus have been natural for the former staffer, who has not been identified, to have access to people's names and Social Security numbers.

"At one point in this person's career, it would have been appropriate for this employee to have had the data," he said.

Broome declined to describe the circumstances by which the data came to be in the former employee's home or for how long the data had been in this person's possession.

He said he didn't know whether the former worker had stored the data on a company laptop and then failed to return the computer, or whether the former worker had smuggled the data out by disc and uploaded it into his or her own computer.

... In any case, it's clear that Hertz's security policies were inadequate when it came to keeping track of the info. And the company isn't alone.



Isn't this similar to allowing Spanish speaking, (or in my case) Chech or Twi speaking) students to use their native language to answer questions?

http://slashdot.org/article.pl?sid=06/11/11/1356212&from=rss

New Zealand To Allow 'Text-Speak' On Exams

Posted by CowboyNeal on Saturday November 11, @10:19AM from the beginning-of-the-end dept. Education Communications

ScentCone writes "New Zealand's Qualification Authority (which sets testing standards for the public schools) is confident that those grading papers will understand the meaning of students' responses, even if they use phone/IM-style text-speak. From the article: 'credit will be given if the answer "clearly shows the required understanding," even if it contains text-speak.' Many teachers are not amused, and critics say that the move will devalue NZ's equivalent of a high school diploma."

Not to mention that graders will need to be restrained so they don't gouge their own eyes out. While in the medium of text messages, some shorthand might be in order, but I didn't realize that world paper, pencil, and ink shortages were so severe so that text-speak is necessary everywhere.



Virtual Law

http://www2.ljworld.com/news/2006/nov/12/virtualreality_crimes_present_literal_challenge_re/

Virtual-reality crimes present literal challenge for real-life police

‘We’re in an information economy’

By Eric Weslander Sunday, November 12, 2006

Earlier this year, Lawrence resident Carissa Hill called the police.

She had been swindled out of money by an online scam artist who had assumed someone else’s identity. But the money that Hill lost wasn’t in U.S. dollars. They were Linden dollars, the currency used in an online, computerized world called “Second Life.”

... Think Hill’s crime report sounds frivolous? Consider that the virtual money she lost could have been traded on an online currency exchange for $180 in cold cash. Hill’s computerized alter ego, “Leia Lulu,” is a real estate developer who earns real-life money for renting and selling land that exists only in pixels and in people’s imaginations.

... “Second Life,” launched in 2003, is the brainchild of Linden Lab, a San Francisco-based team of developers with expertise in physics, 3-D graphics and networking. It’s described on the company’s Web site as “a 3D online digital world imagined, created and owned by its residents.”

Much of the buzz surrounding the company comes from the fact that participants can own what they create inside the world, and can benefit from it by selling it or trading it with others. Linden dollars can be bought and exchanged for U.S. dollars using a credit card.

Through their online personae, known as “avatars,” residents design and buy clothing. They build shopping malls where they charge rent for a storefront. They build night clubs, where they put out tip jars and offer virtual-money prizes for dance contests.

It also can be a venue for promoting a real-world business or idea. Reuters news service, for example, last month opened a virtual “news bureau” there. A staff reporter regularly holds “office hours” via his online persona, and the company posts real-life news feeds on billboards. Wired magazine also has built a headquarters there.

... The equivalent of more than $1 million in U.S. dollars changes hands there each day, and last month, a congressional committee said it was looking at whether those transactions should be taxed.

Is this absurd?

Nancy Baym, an associate professor of communication studies at Kansas University, said that despite the hype, “Second Life” isn’t that different from other forms of online communication that are far more prevalent, such as e-mail or instant messaging.

“Second Life” just hit a million users. In the big picture, it’s pretty low, compared to, say, MySpace, which has about a 100 million users,” Baym said.

But isn’t it absurd to think that something created in “virtual reality” — for example, a poster to hang on the wall of a virtual apartment — could have a value in real life? Baym says, “No.”

We’re in an information economy, and it’s not that big of a step from telecommuting to work and never being physically present in the home office,” she said. “If you think that people are making a living trading stock via the Internet, it’s not that big of a leap to go into providing PR services via ‘Second Life’... Things like Web design and public relations and consulting and education, all of those things can go on in that kind of a forum.”



The new Rumsfeld

http://www.bespacific.com/mt/archives/012978.html

November 10, 2006

National Security Archive Posts The Robert Gates File

National Security Archive: "Bush administration nominee for Secretary of Defense Robert M. Gates had a long career in government which showed a notable combination of ambition and caution, according to a new book by Archive senior analyst John Prados [Safe for Democracy: The Secret Wars of the CIA (Chicago: Ivan R. Dee, 2006)] which deals with Gates among its much wider coverage of the agency since its inception...Excerpts from Safe for Democracy related to Mr. Gates are here posted by the Archive. They are accompanied by the full three volumes of the extraordinary confirmation hearings of Gates for CIA director which took place in 1991, and which at the time constituted the most detailed examination of U.S. intelligence practices carried out since the Church and Pike investigations of the 1970s. Also posted is the portion of the report by Iran-Contra special prosecutor Lawrence Walsh which concerns Mr. Gates, along with his response to those findings."



Interesting. What would you like to review?

http://publishing2.com/2006/11/11/reviewme-creates-a-currency-and-marketplace-for-buying-influence/

ReviewMe Creates a Currency and Marketplace for Buying Influence

SPONSORED BY REVIEWME

I’m being paid $125 to write about ReviewMe (half of what ReviewMe charges for a review on Publishing 2.0). I would have written about ReviewMe anyway, but it’s certainly nice to get paid. Will getting paid influence what I say? I’ll get paid regardless of what I say, but I’ll admit that I’m conscious as I write of this being a paid posting.

There has been much fear and loathing in the blogosphere about PayPerPost and its fostering of deceptive marketing practices. ReviewMe avoids many of PayPerPost’s mistakes, in particular by requiring disclosure and not requiring that reviews be positive.

... The real innovation of ReviewMe is that they’ve created a marketplace for buying influence. Unlike PayPerPost, which lists fixed-price review opportunities that any blogger can select, ReviewMe allows advertisers to select the blogs where they want to be reviewed — each blog can accept or reject the paid review opportunity.

It gets even more interesting when you look at how each blog is priced — based on a combination of Alexa ranking, Technorati ranking, and estimated RSS readers. This is the first real effort I’ve see to create a currency for influence. Is this the right formula? The market will ultimately have to decide, but it’s exactly the kind of metric that bloggers need to sell their true value — page views just ain’t going to cut it.



Geek stuff...

http://www.lifehacker.com/software/collaboration/geek-to-live-essential-tools-for-the-placeless-office-213641.php

Geek to Live: Essential tools for the placeless office

Us Lifehacker editors have never been in the same room at once, yet we work together every weekday from 5 different cities across 2 time zones. If your team is distributed across vast distances like we are, you need to set up shop not with Aeron chairs and cubicle walls but with the right collaboration tools. Thanks to the wonders of the internets and a growing crop of mature webapps, this kind of "placeless office" is now possible.

We've covered tons of web services that help long-distance co-workers collaborate, and you've got to choose what works best for your team. That said, today I've got a rundown of the web-based software that runs Lifehacker's virtual headquarters.



I'm just a student at heart...

http://www.productivity501.com/2006/11/free_academic_p.html

Free Academic Podcasts

About a year ago, I put together a listing 30 or 40 free podcasts of lectures from Universities. When I started putting together another list, I was amazed at how many more lectures are available. The 134 lectures in this list are all free and don't require any type of authentication--you don't have to be a student to download them. The links are to the rss feed of class lectures. If you copy the URL and in iTunes click on Advanced > Subscribe to Podcast it will automatically download the lectures and new ones as they become available.



...but is it community property?

http://www.newsoftheworld.co.uk/story_pages/showbiz/showbiz1.shtml

Oops, I vid it again

By Rav Singh

SUPERSTAR Britney Spears is facing a mega divorce payout because she did it again and again and again...on a HONEYMOON sex video.

Dumped husband Kevin Federline has been touting the four-hour tape for sale and has already been offered £26 MILLION.

A film company wants to make it available online to fans around the world.

... She is worried she will become infamous like Paris Hilton —whose home-made sex video, was put on the internet by her ex and became one of the world's most popular sites.

... Last week she filed for divorce after dumping him by text.



http://www.lifegoggles.com/?p=150

4 easy steps to getting your videos online

Posted on November 10th, 2006 in Internet, Web Apps, Movies by Joel

... so I thought it would be interesting to go through the process of uploading a video to each of the sites and measuring how easy it was and the resulting video quality.

Saturday, November 11, 2006

Hummm Yesterday this was between 8,000 and 10,000 votes. I wonder if it will continue to grow?

http://www.infoworld.com/article/06/11/10/HNfloridaevotingg_1.html?source=rss&url=http://www.infoworld.com/article/06/11/10/HNfloridaevotingg_1.html

Florida e-voting: 18,000 'missing' votes in close race

Government watchdog group has received many complaints about lost votes and missing candidate names on ballots

By Grant Gross, IDG News Service November 10, 2006

Government watchdog group Common Cause has called for an investigation of electronic voting machines used in Florida's 13th congressional district because of 18,000 missing votes.

About 18,000 people who cast votes in other races in Tuesday's election failed to record a vote for either candidate for the U.S. House of Representatives. At last count, Republican candidate Vern Buchanan led Democratic candidate Christine Jennings by less than 400 votes in the race to succeed Republican Katherine Harris, who ran unsuccessfully for U.S. Senate.

Nearly 13 percent of voters in Sarasota County picked candidates in other races but did not choose a candidate in the House race. More than 35 callers to Common Cause's voter hotline left messages Tuesday saying the e-voting machines appeared to leave off a vote for Jennings on their summary screens, [and no one said anything? Bob] said Ben Wilcox, executive director of Common Cause Florida. In neighboring Manatee County, just 2 percent of voters did not cast a ballot in the congressional race.

Some voters caught the omission and were able to go back and vote again for Jennings, but others may have missed the problem, Wilcox said.

"Sarasota County election officials must conduct a revote," [a recount being impossible... Bob] Wilcox said. "The machines should be impounded, audited and tested to determine if voters were unable to cast a ballot and why. Sarasota County voters deserve an explanation."

Undervoting for top-of-the-ballot races on e-voting machines is typically under 1 percent, according to a study released this year by the Brennan Center for Justice.

The county did not require the Elections System and Software (ES&S) e-voting machines to include paper printouts to back up the electronic vote.

"This is part of the reason we've been calling for a paper trail," Wilcox said.

Ironically, Sarasota County voters on Tuesday approved a ballot measure requiring paper trail ballots to be used as a backup to the e-voting machines.

Sarasota County voters cast about 16,000 more votes in the Florida governor's race and in the Senate race than were recorded in the House race. About 4,000 more people cast ballots for the county's Southern District Hospital Board than were recorded in the House race.

One of the major advantages of using e-voting machines is they are supposed to make it for difficult for voters to undervote, e-voting advocates have long said.

Sarasota County will begin a recount in the race Monday. County Supervisor of Elections Kathy Dent didn't immediately return a phone call seeking comment on the undervote. An ES&S spokesman also didn't not immediately return a phone call.



Noble words, without the evidence...

http://www.securityfocus.com/news/11423?ref=rss

E-voting worries focus on failures, not fraud

Robert Lemos, SecurityFocus 2006-11-10

Major electronic voting machine problems occurred in at least six U.S. states during the country's midterm elections, underscoring that system failure, not fraud, is the biggest issue facing future races, voting-rights activists and technologists said this week.

Machine problems delayed voting in many precincts in Colorado, Florida, Indiana, and Ohio, requiring election officials to keep the polls open late. Problems in Montana delayed the final tally of the results in that state, and in New Jersey, about 5 percent of machines had some sort of problem, though the issues were characterized as minor in news reports.



Okay guys, what's going on here? Is this an indication that a deal has been negotiated?

http://www.allheadlinenews.com/articles/7005473208

Ex-HP Ethics Chief Pleads Not Guilty In Boardroom Spying Probe Case

November 10, 2006 11:13 a.m. EST Jacob Cherian - All Headline News Staff Writer

San Francisco, CA (AHN) - Former Hewlett-Packard Co ethics chief, Kevin Hunsaker, has pleaded not guilty to four felony charges in a case accusing him of carrying out a spy investigation into the company's board members and journalists.

Spokesman for California Attorney General Bill Lockyer, Tom Dresslar, said Hunsaker was brought before the court in a hearing that was unannounced in Santa Clara County Superior Court. This comes weeks before his scheduled court date on December 6.

... According to the AP, the defendants are now facing four felony counts including, "use of false or fraudulent pretenses to obtain confidential information from a public utility; unauthorized access to computer data; identity theft; and conspiracy to commit each of those crimes."



A quiet Friday. (Not many computer theft reports...)

http://www.thisislancashire.co.uk/news/localnews/display.var.1017168.0.hospital_clamp_after_computer_thefts.php

Hospital clamp after computer thefts

By Jane Lavender

SECURITY is being reviewed at the Royal Bolton Hospital after thousands of pounds worth of computer equipment was stolen.

Thieves stole four computers thought to contain information on patients' pacemaker settings from the hospital's cardiology department [“Let's turn them up a bit and see what happens...” Bob] Police are working with the hospital in a bid to improve security following the thefts - which included laptop computers - over the weekend of October 7.

... She added: "A computer was stolen from pathology, one from the orthopaedic department, two from cardiology and two flat display screens from an outpatient waiting area.

"All the information on these computers was backed up elsewhere and therefore no information was lost.


I hope Bronco security is better!

http://www.thisisbradford.co.uk/news/tibnews/display.var.1015134.0.bulls_count_cost_of_computer_theft.php

Bulls count cost of computer theft

By Sunita Bhatti

Vital statistics and match performance details about Bradford Bulls' players have been stolen in a raid on the Super League team's offices.

Three computers on which exhaustive information about each of the club's players - from tries scored to conversions made and number-crunching statistics of their match prowess and fitness levels - were swiped by thieves early yesterday.

... Bulls media, PR and football manager Stuart Duffy said CCTV footage which had been passed on to the police showed the teenagers snooping around the club shop roof before breaking into the office. [Note to security guys: “Video recorders do not prevent theft.” Bob]

... "It's quite comprehensive information for us and it's not really of any use to anyone else," [Oh? Bob] said Mr Duffy.

... The laptop is used for administrative purposes and the information is not believed to be backed up so it would need collating again if it was not returned.


http://www.canada.com/victoriatimescolonist/news/story.html?id=d437f45b-1ec1-4ae4-9ac7-caef3dc4ae3d&k=80400

Stolen laptop has data on mental health of 1,000 kids

CanWest News Service; Calgary Herald Published: Friday, November 10, 2006

CALGARY - Alberta's privacy commissioner is investigating the theft of a laptop computer containing personal information on 1,000 children all mental health patients in Calgary.

Commissioner Frank Work announced Thursday he would examine security measures after the computer was stolen from a Calgary Health Region therapist's home [Why 1000 kids, is that a typical case load? Why was all that data at home? Bob] during a break and enter last month.

... But a three-step process for password authentication [Interesting. I haven't heard of a “3-step process” before, so I googled it and all I got was this article! Bob] on the laptop should protect the personal information on the laptop, according to CHR.



Can you say “Gullible?”

http://www.cambs-times.co.uk/content/cambstimes/news/story.aspx?brand=CATOnline&category=NewsCambs&tBrand=cambs24&tCategory=NewsCAT&itemid=WEED10%20Nov%202006%2011%3A45%3A00%3A847

Bad news for laptop thieves

10 November 2006 WEB EDITORIAL - webdesk@herts24.co.uk

A NEW tracking system which can trace stolen computers was launched this week at Kingsfield School in Chatteris, where 15 laptops were stolen in June.

Six months earlier 16 laptops were stolen in another burglary.

Education ICT Service, a business unit of Cambridgeshire County Council has joined forces with Dell in a bid to reduce laptop thefts from schools.

Computertrace is a theft protection service that tracks, locates and recovers stolen computers.

Councillor John Powley, Cambridgeshire County Council's cabinet member for corporate services, said: "This is an exciting and innovative initiative which will be bad news for computer thieves. The software is embedded, undetectable and non removable. [Who cares? Steal the computer, reformat the hard drive and load Linux... Bob]



How about this: AT LEAST have a policy!

http://www.privsecblog.com/archives/security-measures-confidential-information-should-be-encrypted-or-not-stored-on-laptops.html

Confidential Information Should Be Encrypted or Not Stored on Laptops

Posted by Randy Gainer

81% of U.S. businesses surveyed this year reported that, in the previous 12 months, at least one of their laptops or other portable electronic devices had been lost or stolen. U.S. Survey: Confidential Data at Risk, 5 Privacy & Security Law Report 1162 (2006). When a laptop is lost or stolen, unencrypted data on the computer can easily be accessed. Even if a user name and password are needed to sign on to the laptop, the hard drive can be removed in a few seconds and all data on the hard drive can be copied to another computer or to a storage device in minutes.

Despite the high risk sensitive data may be obtained from lost or stolen laptops, many businesses continue to allow employees to store such information on laptops and to take the laptops home, on business trips, and on vacations. Business managers should consider whether their current laptop security practices are sufficient. If a business’ trade secrets, attorney-client privileged information, customer lists, or financial information are obtained from a lost or stolen laptop, affected shareholders, employees, or business partners may argue that the business failed to take adequate steps to safeguard the data.

Avivah Litan, vice president and analyst at the Gartner Group, said in a recent interview: "Frankly, there is no excuse anymore not to encrypt data on laptops and mobile devices. . . . The cost for laptop encryption is $40 or less per laptop. . . . [T]here is no excuse today. It is really bordering on negligence." An Interview with Experts on the Cost of Ensuring Data Security, 6 Privacy Advisor 20, 23 (2006). Every company with sensitive data on mobile devices should consider whether the data should be encrypted.

Another issue must also be resolved by companies whose employees take laptops containing trade secret or privileged information across U.S. borders. Whether such information is encrypted or not, employees who travel across a U.S. border with company laptops should be prepared for U.S. Customs officers to ask to review files on the device. [What, exactly these dim-bulbs are looking for eludes me. Something that could not be emailed? Bob] Customs officers have apparently made several such requests. See Joe Sharkey, At U.S. Borders, Laptops Have No Privacy, N.Y. Times, October 24, 2006, at C 8. Both the Fourth and Ninth Circuit Courts of Appeal have held that Customs officers may conduct routine searches of laptops without a warrant, without probable cause, and without a reasonable suspicion of illegal conduct. [...to protect our rights? Bob] See United States v. Romm, 455 F.3d 990, 996-97 (9th Cir. 2006); United States v. Ickes, 393 F.3d 501, 503-07 (4th Cir. 2005). Although a trial court in the Ninth Circuit recently ruled that Customs officers may not search a laptop or other electronic files without at least a reasonable suspicion of wrongdoing, United States v. Arnold, 2006 WL 2861592 (C.D. Cal. October 2, 2006), appeal docketed, No. 06-50581 (9th Cir. October 23, 2006), it is unclear whether that decision will survive on appeal.

If Customs officers note that there are encrypted files on a laptop, they may ask travelers to decrypt the data or may retain the laptop to get a warrant to require that the decryption key be turned over to them. See Sharkey, at C 8; and this article from cybercrimelaw.org (via digg.com). To make sure that businesses are not temporarily denied access to important data, "some companies are considering telling travelers coming back into the country with sensitive information to encrypt it and email it to themselves, which at least protects access to the data, if not its privacy." Sharkey, at C 8. If a laptop with trade secrets or privileged information is retained for inspection by Customs, temporary lack of access to the data may not be the most serious problem on company officials’ minds.

A possible solution, both to the risk that data may be obtained by a thief or by someone who finds a lost laptop and to the potential disclosure of highly sensitive data during border searches, is to stop storing sensitive data on laptops. Such data can be stored on company servers and accessed via a VPN. Whether encrypting confidential data on laptops or never storing such data on laptops is chosen as the means to protect the information, company officials should make sure they are doing all they can to protect confidential data.




No subpoena, no foul?

http://techdirt.com/articles/20061109/162935.shtml

Convenient Timing: Politician's Computer 'Crashed' And Deleted Everything Just As Investigators Asked To See It

from the how-convenient dept

Don't you just love convenient timing? The Raw Feed points us to a corruption case involving a commissioner in Hollywood, Florida. He apparently helped a company win an $18 million "sludge-handling" contract. However, just as investigators went to search his computer it was conveniently "wiped clean". He claims it just crashed, even though that crash (conveniently, again) was so thorough that no data was recoverable from the drive even after being sent to various data recovery shops. Not surprisingly, this is raising a few eyebrows, though his lawyer insists that if the guy was really trying to hide info, he would have just "thrown out" the computer. [rather than just replacing the hard drive? Bob]



Fortunately, we in America can read all of these without being considered terrorists – just don't have any Democrat propaganda (until January)

http://yro.slashdot.org/article.pl?sid=06/11/10/1650256&from=rss

UK Woman Charged As Terrorist For Computer Files

Posted by Zonk on Friday November 10, @06:31PM from the more-you-know dept. The Internet Privacy

Terror Alert Brown writes "Reuters is reporting that a UK woman has been charged as a terrorist because of computer files on her hard drive. According to the article, these files included 'the Al Qaeda Manual, The Terrorists Handbook, The Mujahideen Poisons Handbook, a manual for a Dragunov sniper rifle, and The Firearms and RPG Handbook.' She was picked up in connection with the plot stopped in August to detonate explosives in airplanes flying out of Heathrow airport. Now might be a good time to delete any copies of the Anarchist's Cookbook you once read for amusement and still have floating around on your hard drive."




http://money.cnn.com/magazines/business2/business2_archive/2006/11/01/8392021/index.htm?postversion=2006111008

Dial S for Skype, P for profits

Sure, Skype can shave a few bucks off your phone bill. But now it's helping savvy entrepreneurs create brand-new business models.

Business 2.0 Magazine By Hillary Woolley, Business 2.0 Magazine November 10 2006: 8:40 AM EST

(Business 2.0 Magazine) -- Free Internet phone service was always likely to change the world - but until recently we had no idea how. A little more than a year after eBay bought Skype for $2.6 billion, the service has become a business tool on a surprising scale.

A million people worldwide, 300,000 of them in the United States, will rely on Skype as their primary means of business communication in 2007, according to telecom analyst Albert Lin at American Technology Research. And those are just the power users: Skype says nearly a third of its 113 million users now log on to make work-related calls.



Who says people in the porn industry aren't innovative? Smart may be in question, but not innovative.

http://techdirt.com/articles/20061110/123022.shtml

Phone Sex Company Hacks Competitors; Spams Their Customers

from the now-there's-a-business dept

While internet scams have changed and adapted over the years, from the beginning a popular target has always been folks who are viewing porn -- on the assumption that if they get scammed, they're less likely to then report it out of some sort of embarrassment. It appears that applies over in Korea as well, where the operators of a phone sex company hacked into their competitors' computers, accessed the personal information of over 8 million people, and started sending them "lascivious text messages." Specifically, they searched through the computer systems of over 60 different competitors, to figure out which were their "superior clients" (those who spent over an hour on the phone) and targeted those clients with more specific text messages. Even better, they did this by registering phones in the names of homeless people, so that they wouldn't have to pay the bills. Of course, it seems that they were found out and have now been arrested for the scam.



...for those thinking of converting to Linux

http://www.foogazi.com/2006/11/10/alternatives-to-windows-programs/

Alternatives to Windows Programs

Posted by: adam k on 10 November 2006

There are many alternatives to using Microsoft Windows and the applications that are made for it. One of the more popular alternatives is the Linux operating system. Just about everything you can do in Windows, you can do in Linux, sometimes even better and with more control. Linux has been around for quiet a long time, so its no surprise that there are a ton of applications out there that offer the same type of functionality that many of our favorite Windows applications have. This article takes a look at some of the most popular software applications used in Microsoft Windows and compares them with some alternatives that get the same job done.



Don't forget to read today's Dilbert on the reliability of corporate data.

http://www.unitedmedia.com/comics/dilbert/



Attention politicians! When you have nothing to say (i.e. When you are talking) you can at least amuse the crowd...

http://www.psconclave.com/wiki/Main_Page

Welcome to PSConclave - The Pen Spinning Wiki!

Welcome to the Pen Spinning Conclave at psconclave.com, a wiki dedicated to the art of pen spinning! Pen Spinning is a fast growing subdiscipline of contact juggling which uses only a pen or pencil, the fact it can be performed practically anywhere contributes to its rising popularity.

There are many pen spinning tricks and combinations to learn, pen modifications to make, and history to reflect on. Visit the help pages or create an account to get started.

For Beginners, if you do not know which pen tricks to learn first, start with the 4 fundamentals of pen spinning, then continue from there. A guide for a learning order is always under contruction as new tricks are invented and added. However there is no set tricks to learn, if you see one you like, then go for it! Spend some time and read through the guide, then spend some more time perfecting it.



Dennis Dallas mentioned this yesterday and I had to research it to see if the source was Comedy Central.

http://www.eweek.com/article2/0,1759,2055821,00.asp?kc=EWRSS03119TX1K0000594

'BlackBerry Thumb' Sparks New Form of Hand Massage

November 10, 2006 By Martin Roberts, Reuters

TORONTO (Reuters)—Sore thumbs after spending hours on a hand-held e-mail device? Sounds like a case of "BlackBerry Thumb"—but help is at hand.

The Hyatt hotel chain found so many of their business travelers were complaining of hand and arm discomfort that they have introduced a special "BlackBerry Balm" hand massage at most of their North American spas.

... Hedge recommended preventive measures like holding the device comfortably in the hands and close to the body, and not typing for more than five minutes without a break.

"Don't type "War and Peace" with your thumbs! If you need to type long messages use and external keyboard for the device," Hedge said by e-mail.


Know someone who needs this?

http://www.kk.org/cooltools/archives/001476.php

Starfall.com

Free reading tutorials

Remember that greeting card company and famous-in-the-late-90s website Blue Mountain Arts? Well the extremely talented and philanthropic founders have started a learning-to-read website, totally free, called Starfall.com. My daughters, ages 6 and 7, have literally gotten more educational value out of this than their schools. And now their schools are using it in their classes once a week! Super site, makes the most out of flash and audio on a broadband connection, and really a treasure for young kids (aimed at first graders and below) who want to get going with reading (at no cost).

-- Jeff Blackburn

Starfall.com

Friday, November 10, 2006

There is no evidence of a voting problem.” (Clever, very clever.) I don't suppose there is any reliable statistic to show that this is normal or abnormal...

http://techdirt.com/articles/20061108/184456.shtml

No Major E-Voting Problems, Huh? Then Where Are Florida's Missing Votes?

from the just-asking dept

In one of the stories we spotted yesterday about e-voting glitches, it was amusing to see (at the very, very bottom) the idea that "no major problems" were reported for e-voting in Florida. Florida and Ohio, of course, are the two places where e-voting stories have raised the most questions, and there had already been a number of reports of e-voting problems in Florida voting last week when their early polls opened. So, it looks like ABC may need to revise that "no major problems" report, as the EFF points us to a report saying that 13% of the electronic responses in Sarasota County included no vote for Congressional Representative. That means that somewhere between 8,000 to 10,000 people [the margin of victory? Bob] who voted for other things, like governor, appear to have not voted for House Representative -- and no one seems to have a good explanation. It's certainly possible that all those people decided to go "none of the above," but it seems unlikely -- especially since similar undervoting was not seen in other counties covered by the same Congressional district. Also, there were complaints all day about the e-voting machines not properly recording votes in that county. So, while people are asking for a recount... there's nothing to recount since the machines did not record the votes. Amusingly, the EFF also notes that the very same county had a referendum on the ballot about the e-voting machines, and the people overwhelmingly voted to scrap the machines and bring back paper ballots. So what was it the press was just saying about no major glitches with e-voting?



So, how do I get a share?

http://techdirt.com/articles/20061109/114427.shtml

Rights Holders Start Lining Up To Get Money From Google/YouTube

from the oh,-look,-free-money dept

While it's still not clear who is suing Google over their video offering, it's clear that plenty of rights holders are looking for some sort of payout similar to what YouTube gave the record labels. However, as we noted with Microsoft's decision to pay out to Universal Music, once you start down this route, everyone is going to want a piece of you from all over the world representing all different groups of all different sizes. So, for example, it should come as no surprise to find out that the German Society for Musical Performing and Mechanical Reproduction Rights has now joined the handout line, demanding royalties from YouTube/Google. Of course, part of the problem is that YouTube made this possible by giving those few labels money in the first place, rather than sticking to the letter of the law which says they're not liable for content uploaded by users. They can still make that claim, and perhaps that's what they'll do if this goes to court, but in the meantime, they're going to be facing a ton of random players (small and large) who are all going to demand a cut.



As “full hard drive” encryption becomes easier, it might be useful to think of the downside. What happens if individuals encrypt the only copy of a “critical document?” Look for centralized control of all encryption keys, and look for hackers going for that file first.

http://slashdot.org/article.pl?sid=06/11/09/226205&from=rss

U.S. Government Prepares For Vista

Posted by Zonk on Thursday November 09, @06:02PM from the battening-down-the-hatches dept. Windows United States

IO ERROR writes "Patrick Svenburg, program manager for Windows Client Solutions in Microsoft Federal, answered questions from government IT managers today about the upcoming Windows Vista release. Many of the questions were about BitLocker, Microsoft's new drive encryption technology, as well as other security questions, upgrading from Windows XP, IPv6 deployment and more. Svenburg is a member of the Windows Vista Launch Team and is leading early adoption efforts for Windows Vista within the Federal community, according to Government Computer News."



Think this is “interesting but not consequential?” Read the next article.

http://hardware.slashdot.org/article.pl?sid=06/11/10/0358204&from=rss

The Information Factories are Here

Posted by CowboyNeal on Thursday November 09, @11:46PM from the brave-new-world dept. The Internet Data Storage

prostoalex writes "Wired magazine has coined a new term for the massive data centers built in Pacific Northwest by Google, Microsoft and Yahoo! Cloudware is, ironically, a return of the centralized data and bandwidth power houses caused by decentralized and distributed nature of the Internet. George Gilder thinks we're witnessing something monumental: 'According to Bell's law, every decade a new class of computer emerges from a hundredfold drop in the price of processing power. As we approach a billionth of a cent per byte of storage, and pennies per gigabit per second of bandwidth, what kind of machine labors to be born? How will we feed it? How will it be tamed? And how soon will it, in its inevitable turn, become a dinosaur?'"


This could be very useful. It could also be very mis-used.

http://www.infoworld.com/article/06/11/09/HNdatabaseinsky_1.html?source=rss&url=http://www.infoworld.com/article/06/11/09/HNdatabaseinsky_1.html

MySQL wants to build 'database in the sky'

Data repository would make structured data available to application developers and Internet entrepreneurs

By Juan Carlos Perez, IDG News Service November 09, 2006

MySQL AB wants to launch a global project to build a massive, distributed repository containing all of the world's data now stored in structured databases, the company's chief executive officer said Thursday.

While search engines like the one from Google Inc. aim to give people access to unstructured data on the Web, this "database in the sky" would make available structured data to application developers and Internet entrepreneurs, said Marten Mickos at the Web 2.0 Summit in San Francisco.

The data repository would be to database access what eBay Inc.'s Skype is to Internet telephony, and it would create the next-generation OLAP (online analytical processing) engine for data analysis and discovery, Mickos said.

The project seeks to apply the open-source model to data, so that developers worldwide could share and aggregate data, Mickos said. "Then the data would be the platform," Mickos said. He envisions, for example, being able to tap into all of the world's structured databases that have weather information.

It would probably be required to build "a DNS of SQL servers," address likely routing obstacles and make data definitions understandable and accessible to others, Mickos said. It would also be necessary for the data owners to have a willingness to make their database contents available.

But the most important ingredient will be to assemble a community of collaborators and volunteers willing to work on the project. The database wouldn't be monolithic but rather function on a peer-to-peer principle, he said.

Those interested in learning more can go here .



Curious. As I read this, Microsoft has purchased a company that secures its operating system rather than correct the problem internally. Does this mean they don't consider the effort worth their time or that they had no clue there was a problem, so they had no clue how to fix it?

http://www.pcworld.com/article/id,127804-pg,1-RSS,RSS/article.html

Microsoft Releases Sony Rootkit Hunter's Tools

New software will assist Windows users in detecting hidden system hacks and malware.

Robert McMillan, IDG News Service Thursday, November 09, 2006 01:00 PM PST

Nearly four months after hiring Sony rootkit whistleblower Mark Russinovich, Microsoft has moved his company's software to its Web site and has released a new Windows system tool that can help fight hackers.

The freeware products, now known as Windows Sysinternals were made available on Microsoft's Web site earlier this week. They are based on the code that Russinovich and Bryce Cogswell had been distributing on Sysinternals.com before Microsoft bought their company, Winternals Software, in July.

Original Tools Updated

"The tools are the same as what was on the original Sysinternal site with the exception of some updates and the release of Process Monitor," said Russinovich in an e-mail interview. Process Monitor is new software, based on code from two Sysinternals tools, which keeps track of activity on the Windows file system and registry and is designed to help Windows administrators with troubleshooting and malware detection.

Russinovich and Cogswell founded Winternals in 1996, and have since produced a number of widely used system-recovery and performance-tuning products.

Russinovich made international headlines last November after he discovered that copy protection software that Sony had been distributing with millions of CDs was cloaking itself using undetectable "rootkit" software. Sony was ultimately forced to recall the affected CDs after hackers began using the rootkit to hide malicious code.

Russinovich's popular blog, along with his original posting on the Sony rootkit have been moved to Microsoft's Technet Web site.

No Source Code

One aspect of the Sysinternals.com Web site that did not survive the transition to Microsoft is the free source code that Cogswell and Russinovich had made available for some of their tools.

These tools were not often downloaded, however, Russinovich said. That fact, "combined with the Microsoft requirement of having all published source scrubbed for security ... and compatibility issues, drove the decision not to move it forward," he said.



It's not our fault! We asked them not to violate their customers' privacy.”

http://news.yahoo.com/s/pcworld/20061109/tc_pcworld/127810

Intel Drafts Privacy License for Location-Aware Cell Phones

Ben Ames, IDG News Service Thu Nov 9, 6:00 PM ET

Intel has attached a privacy license to its new location-aware software product, intended to protect cell phone users' personal information as mobile devices increasingly rely on tracking technology to provide targeted services.

Installed on a smart phone or ultramobile PC, location-aware software can use GPS technology to produce tailored information like driving directions, nearby restaurants and movie schedules. The downside of that feature is that handsets can double as tracking devices if location data is not kept private. The abuse of such access could range from civil liberties violations to physical threats in the cases of vulnerable people like battered spouses, Intel fears.

So, Intel has added a privacy addendum to the Eclipse Public License it uses for the software application called Privacy Observant Location System (POLS), according to a posting on Intel's Web site by John Miller, the privacy and security policy manager of Intel's corporate technology group.

The addendum says that vendors must inform the end-user what information is recorded and how long it is stored, and it requires developers to include opt-out capability so users can change those settings, Miller said.

Compelling Ethics

POLS is a tool for mobile application developers that determines its location by triangulating between nearby radio beacons such as GSM cells or Wi-Fi access points. Most location-aware devices use different approaches, relying on the wireless provider to track every device, or on GPS chips, which can have poor reception in dense cities.

While Intel's ethics concerns are compelling, the market may be slow to react to this initiative because so few customers actually use location-based technology, analysts say.

Only 10 percent of the PDAs sold today are equipped with internal GPS antennas, and most of those are in Europe, where the more complex roads and diversity of languages have made street mapping a larger market, said Todd Kort, principal analyst for Gartner Dataquest.

In contrast, nearly 90 percent of CDMA phones from Sprint Nextel and Verizon offer assisted-GPS technology, which relies on Intel's type of cell tower navigation technique. But most users don't know it exists or have chosen not to use it, he said.

"It's great that it's there, and someday we'll appreciate it, but it is something that's in the back of Americans' minds and will not be a driving force for sales," Kort said.

Software Developers Have Control

In the meantime, Intel faces a continuing challenge as it must convince developers to abide by its privacy initiative. The new addendum is useless if software developers don't obey it, so the company has begun a campaign to build support in the open-source community.

"We believe that a bottoms-up effort to encourage the development of privacy-sensitive social norms is necessary, and in fact critical, for both privacy and public adoption of the technology," Miller said.


Not a trivial question. If Osama bin Laden owns his location, do we violate copyright by targeting a smart bomb?

http://techdirt.com/articles/20061109/103329.shtml

Who Owns Your Location Information?

from the where's-waldo? dept

Location-based services have long been a hot topic in wireless, even if they've largely failed to live up to the ridiculous level of hype thus far. However, even though relatively few handsets currently have the ability to pinpoint users' locations with the accuracy of GPS, operators do keep less detailed location information, such as the towers from which calls are made or messages sent. This information is used for different reasons, such as billing, and is more commonly being used by law enforcement as forensic evidence. One researcher who was called as an expert witness in a trial recently to help explain such evidence is now wondering just who owns that location information. Obviously in criminal cases, it must be subpoenaed from an operator, but the researcher says his operator won't even provide him with the location info they have regarding his own calls. It's also unclear what operators' policies are with this information. Some operators are already delivering aggregated location information to companies that use it to determine how road traffic is moving. While this is anonymous, general data, what if operators decided they could start a nice new revenue line by selling individual information to anybody who wanted it? As location-based services proliferate, these sorts of questions are bound to pop up more frequently. While the services do have the potential to be very useful, they'll also need to come with safeguards that allow people to control who can see their location data and how it can be used.



http://www.eweek.com/article2/0,1759,2055066,00.asp?kc=EWRSS03119TX1K0000594

Data Governance Rises to Top of Compliance Efforts

By Matt Hines November 9, 2006

News Analysis: Companies should look closely at how they manage their databases to make the compliance auditing process less painful and more cost-effective, analysts contend.

NEW YORK—Analysts in the field of regulatory compliance say enterprises should increasingly build their IT auditing processes around database governance efforts.

... Among the technologies utilized to help forward such efforts are software tools used for tracking the manner in which employees are looking at files, and how they behave while logged into databases.

In addition to increasing companies' security by providing a method of detecting an potential misuse of database information, the technologies provide the type of detailed paper trail that compliance auditors demand when inspecting enterprise operations, said Paul Proctor, analyst with Gartner, in Stamford, Conn.



...documentation of the absolute minimum...

http://www.bespacific.com/mt/archives/012970.html

November 09, 2006

NIST Information Security Handbook: A Guide for Managers

November 7, 2006: "NIST is proud to announce the release of Special Publication 800-100, Information Security Handbook: A Guide for Managers. The purpose of this publication is to inform members of the information security management team [agency heads, chief information officers (CIO), senior agency information security officers (SAISO), and security managers] about various aspects of information security that they will be expected to implement and oversee in their respective organizations. (176 pages, PDF)



I've repeatedly mentioned how easy it is to get at this data. Now you don't have to pretend you've never seen it!

http://www.bespacific.com/mt/archives/012975.html

November 09, 2006

Lawyers Receiving Electronic Documents are Free to Examine 'Hidden' Metadata: ABA Ethics Opinion

Press release: "Lawyers who receive electronic documents are free to look for and use information hidden in metadata – information embedded in electronically produced documents – even if the documents were provided by an opposing lawyer, according to a new ethics opinion from the American Bar Association."



It's all about getting even. “This virus brought to you by ____[enter name of person you dislike here]_____ .”

http://www.f-secure.com/weblog/#00001017

Gromozon vs. Marco Giuliani

Posted by Paolo @ 14:28 GMT Thursday, November 9, 2006

... After being utterly frustrated by the inability to bypass Prevx's dedicated disinfection tool, Gromozon's authors decided to attack on another front. In the latest variants of Gromozon, whenever an analysis tool, such as our F-Secure BlackLight, or more generically a "banned" application is detected, the malware itself will present the user with a lovely message that leads him to believe that the source behind the malware are the guys from Prevx, and especially Marco Giuliani - one of the first security researchers to study Gromozon in depth and to provide a disinfection tool.



http://techdirt.com/articles/20061109/144849.shtml

So Now He Tells Us: Alan Greenspan Doesn't Like Sarbanes-Oxley

from the thanks-for-nothing dept

Despite the major financial scandals from a few years ago, embodied most famously by the collapse of Enron, there's good reason to think that the resulting Sarbanes-Oxley regulation was a poor response to the problem that ultimately had the effect of making the US a worse place to do business. Apparently, ex-Federal Reserve Chairman Alan Greenspan agrees, calling parts of the bill a "nightmare". He also said some interesting things about the nature of financial reporting, noting that it was something of an art form, which makes it hard to believe that we'll ever have real-time financial reporting. Greenspan added that he's optimistic that certain parts of the law will be changed, noting that some of the incoming Democratic leadership are open to the idea. It's good to hear him speaking up, but we wonder why he waited until he was out of office to let his opinions be known. Perhaps at the time he didn't feel it was his place to talk about it, or maybe it's just a matter of now having some hindight. Unfortunately, it's always easier to get things passed than to get them repealed.



Think of them as ring tones for your computer based phone system. When you lawyer calls, use the Jack Nicholson clip, and use Brando is you ever get a call from John Kerry?

http://news.com.com/2100-1026_3-6134027.html

Copyright eased for clips offered by Grouper

By Greg Sandoval Story last modified Thu Nov 09 09:40:58 PST 2006

Film clips featuring stars such as Jack Nicholson, Tom Cruise and Cameron Diaz can now be shared online without violating copyright law.

Grouper.com, acquired last August by Sony Pictures Entertainment, is offering snippets from 100 Sony films and TV shows for users to integrate into blogs and on social networking sites such as MySpace, the company said Thursday.

Fans can choose, for example, to have Nicholson appear barking "You can't handle the truth!" (in A Few Good Men) or Marlon Brando declaring "I could have been a contender" (in On the Waterfront).

... To avoid court battles, some video sites are trying to strike content-sharing deals with studios and music labels.

That's what Sony said it is after with Grouper's new "ScreenBites" channel. By offering famous scenes from hit films for free, Sony is hoping fans will be prompted to buy the full-length movie, the company said in a statement. [Sony thought of this all by themselves? Wow! Bob]

... Sony and Grouper plan to offer many more clips from Sony's library and eventually offer them for people to include in homemade videos.

"The challenge with that is making sure that we have the right commerce model," Felser said. "We want the copyright holder to feel good about it. Remember, a lot of this works because it's promotional. Sony is promoting the sale of their content in a way that's never been tried before."

Felser predicted that competitors may have trouble offering a similar service. He said that had Grouper not been part of Sony, the deal may not have ever gotten done.

Even as a unit of Sony, Grouper had to wait until it received the proper rights clearances, video from Sony's library was pulled, and contracts with actors and other creators were checked for clauses that may prevent such an offering.



http://digg.com/videos_comedy/NBC_Launches_New_Online_Comedy_Channel

NBC Launches New Online Comedy Channel

toprank submitted by toprank 18 hours 34 minutes ago (via http://www.dotcomedy.com/cs/Satellite?c=DC_P&childpagename=DotComedy%2FDCLayout&cid=1155067928952&channel=Home&channelid=1155067928952&pagename=DCWrapper )

Watch free comedy on-demand ranging from standup with Tenacious D to late night re-runs, sitcoms and viral videos. Users can vote, tag and submit their own videos as well.



One of those headline grabbing (but ultimately worthless?) statistics.

http://www.comscore.com/press/release.asp?press=1057

More than Half of Top 25 U.S. Web Properties Generate More Traffic from Outside the U.S. than from Within

Lion’s Share of Visitors to Top 5 U.S. Web Properties – Yahoo!, Time Warner, Microsoft, Google and eBay – Come from Outside the U.S.

London, UK, November 9, 2006 – comScore Networks, a leader in measuring the digital age, today released the results of a study showing that 14 of the top 25 U.S. Web properties attract more traffic from people outside the U.S. than from within. Among them are the Top 5 Web properties in the U.S. – Yahoo! Sites, Time Warner Network, Microsoft Sites, Google Sites and eBay.

As Internet usage outside the U.S. has grown rapidly from a small base, the U.S. share of the world’s online population has fallen from 65 percent to less than 25 percent in the last 10 years,” [that sort of explains it, doesn't it? Bob] said Bob Ivins, managing director of comScore Europe. “The fact that more than three-quarters of the traffic to Google, Yahoo!, and Microsoft is now coming from outside of the U.S. is indicative of what a truly global medium the Internet has become.”

... Some sites do not attract a substantial percentage of international visitors. Examples include U.S.-based, telecommunications/ cable companies such as Verizon and AT&T, media entities including Fox (owners of MySpace), New York Times Digital, and CBS, and major U.S. retailers, banks and airlines such as Target, Wal-Mart, Bank of America and United.



Is this headline an attempt to attract students to computer science programs?

http://oedb.org/library/financial-aid/hacking-financial-aid

Hacking Financial Aid: 33 Ways to Get Money for College

Published on Wednesday 18th of October, 2006

The cost of college is constantly on the rise. The average cost of attending a four-year public college has increased over 40% since 2000. And according to a report from the Campaign for America's Future (PDF link), just one year at a public university consumes 25% of the annual median household income in the United States, while one year at a private university consumes 57%. Considering how expensive it is becoming to attend college, it's no wonder that approximately $90 billion in financial aid money is awarded to United States college students each year. So you're about to go to college, or perhaps you're already in college. How can you get your hands on this money?