Wednesday, April 11, 2007

The Privacy Foundation strikes again!

http://www.privacyfoundation.org/

Ethics, Privacy, & New E-Discovery Rules

Morning/Lunch Seminar FRIDAY, April 20, 2007

Sturm College of Law at the University of Denver



What I like about this article is that it points out the problem with high-volume e-discovery (over one billion items per case) I've been saying that these huge volumes require a new approach and this paper seems to agree (is that an indication that they are wrong?)

http://ralphlosey.wordpress.com/2007/04/09/information-explosion-and-the-future-of-litigation/

Information Explosion and the Future of Litigation

A new law review article raises throught provoking questions about the impact of the information explosion on the practice of law, especially litigation: Information Inflation: Can the Legal System Adapt? 13 RICH. J.L. & TECH. 10 (2007). The article is available on-line at http://law.richmond.edu/jolt/index.asp.

... But we do know that, barring a major world disaster, an exponential increase of information is the most likely scenario for the rest of our lives, and so we had better learn to cope with this rapid change, and learn fast.

... For instance, in future suits involving actions by the current administration, the National Archives and Records Administration (”NARA”) estimates that by January 20, 2009, it will have custody of over one hundred million emails from the George W. Bush White House alone. Id. at pg. 12. The total number of emails in NARA custody will soon reach the one billion mark. To search through all of those emails would take a team of one hundred full time lawyers over fifty-four years. Id.at pg. 13. Assuming a very low billing rate of $100 per hour, the cost of review would be $ 2 billion. As the authors point out, email is just the beginning, new forms of writing and communication are developing that will continue the flood waves, such as instant messages, voice mail, web traffic, wikis and the like. Id.at pgs.14-15.



Overabundance of caution?

http://www.kktv.com/news/headlines/6943962.html

Water Bills Stolen

Reporter: Mindy Stone

Water Bills Stolen

Possibly hundreds of paid water bills Filled with private information. Checks and money orders could be in the hands of thieves. [A more immediate target that identity information... Bob] The Stratmoor Hills Water District was broken into sometime late Sunday night or early Monday morning. Besides the missing money, this could mean all these customers face having their identities stolen.

About 2000 water bills were mailed out to customers last week. But, Monday morning there were no envelopes in the front hallway of the building. Employees fear thieves may have stolen them if they were put in the drop slot of the front door over the weekend. And their customers may now be victims of identity theft.

Some customers use this drop slot to pay their water bills. But Monday morning there were no envelopes in the front hallway of the building. And when Ralph Ravenscroft showed up to work six of the windows were busted out of this office building. "It was very evident that they walked up to the building, right up to our windows," said Ralph Ravenscroft, Operations Manager. Ravenscroft says he could see footprints in the snow. But, the building doesn't have an alarm or cameras outside. He hopes surveillance video from the business next door will help authorities track down the thieves. "I'm afraid they might have gotten hold of some of our customers checks or money orders with personal information on them," said Ravenscroft. The water district doesn't know if anyone's bill was stolen. But they still want to get the word out. "Given it was a holiday maybe people didn't drop off their bills the way they normally do. But, it's a chance we don't want to take," said Ravenscroft.

If you dropped off your water bill payment over the weekend. Please call the Stratmoor Hills Water District to make sure they received it.



You can't outsource responsibility, but government agencies keep trying (and succeeding?)

http://news.yahoo.com/s/ap/20070410/ap_on_hi_te/lost_data

Disk with data on 2.9M Georgians lost

By SHANNON McCAFFREY, Associated Press Writer Tue Apr 10, 12:15 PM ET

A computer disk containing the names, birth dates and Social Security numbers of 2.9 million Medicaid and children's health care recipients is missing, Georgia health officials said Tuesday.

The state said the security breach was reported by Affiliated Computer Services, a private vendor with a contract to handle health care claims for the state.

The CD was lost while it was being shipped from Georgia to Maryland, ACS spokesman David Shapiro said. The company has been working with the carrier, which Shapiro would not identify, for several days to find the package, he said.

Shapiro said there was no indication anyone had tried to access any of the personal data.

"We are treating this as a missing package," he said.

Officials said the information, including addresses, covered the four-year period up to June 2006 and included some people who are no longer on the rolls.

The Georgia Department of Community Health said it was requiring the Dallas-based company to notify everyone affected and to offer free credit reports. [First time I've seen that requiement. Bob] The children's health care program involved in the data loss is called PeachCare.

PeachCare is the state's health insurance program for low-income children. Medicaid is a health insurance program for the poorest residents. Both programs are funded with a combination of state and federal dollars.

State officials notified the Centers for Medicare and Medicaid Services, the U.S. Department of Health and Human Services, the Governor's Office of Consumer Affairs and the state attorney general.

On The Net: Georgia Department of Community Health: http://dch.georgia.gov/

http://dch.georgia.gov/vgn/images/portal/cit_1210/19/38/80010015Public_Notice-Missing_Personal_Data.pdf


Why no one changes their behavior? (see next article)

http://techdirt.com/articles/20070410/105049.shtml

Firm's Personal Info Loss Just The Latest In A Proud Line Of Data Leaks

from the good-work dept

Another day, another data leak: a CD containing the personal information of 2.9 million Georgia residents has been lost by a contractor, potentially exposing them to identity theft. Even such a big leak is hardly notable these days, except for one factor -- the disk was lost by Affiliated Computer Services, a company that's been responsible for several other data leaks. An ACS computer got stolen in Denver last November, and on it was personal information of between 500,000 and 1.4 million people in Colorado. A few months earlier, a glitch on a student-loan web site run by ACS exposed the information of 21,000 students, while earlier in the year, credit-card data from seven years' worth of customers was stolen from a system run by ACS at the Denver airport. Rounding out the list -- or at least the list of ACS-related incidents that made it into the media -- is the theft of two of the company's laptops with data on tens of thousands of Motorola employees in May 2005. This company clearly has a problem with protecting personal information, but it doesn't appear that there are ever any repercussions to these losses. It just accepts whatever minimal fines, if any, it has to pay, and paying for some credit monitoring, as a cost of doing business. The fact that these problems keep happening to ACS reflect how seriously many companies take the threat of identity theft -- which is to say, not seriously at all. But perhaps more distressing is that with the company's track record, government officials don't seem to have any problem passing ACS personal information with little to no oversight.


Perhaps they need to be taught a lesson?

http://www.chicagotribune.com/technology/chi-0704090519apr10,1,545902.story?coll=chi-technology-hed&ctrack=1&cset=true

Teachers say fire Duncan

Union rips schools CEO after breach

By Tracy Dell'Angela Tribune staff reporter April 10, 2007

Chicago Teachers Union President Marilyn Stewart called Monday for the ouster of schools chief Arne Duncan, saying he should be held accountable for the theft of two laptops that contained the names and Social Security numbers of 40,000 teachers.

Stewart compared the security breach to the police brutality scandal that triggered the resignation of Chicago Police Supt. Philip Cline, who announced his early retirement after an off-duty officer was videotaped pummeling a bartender at a North Side bar.

... If Arne Duncan cannot guarantee our protection, he should not have that job," said Stewart, adding that the breach came just months after the district accidentally mailed out the Social Security numbers and names of 1,740 retirees.

... The district offered to pay for credit and identity-theft protection for any affected employee who requests the service. Depending on the number of requests, the service could cost the district as much as $500,000, an expense school officials are looking to share with the accounting firm. "It wasn't our computer. It wasn't our negligence," said district spokesman Michael Vaughn.


Offering to pay for credit monitor is not a costly as you might think...

http://www.networkworld.com/news/2007/041007-choicepoint-victim-offers.html

Victims of ChoicePoint data breach didn’t take advantage of free offers

Panel of industry, government leaders discuss finding better ways to protect personal data and notify consumers

By Jon Brodkin, Network World, 04/10/07

When ChoicePoint became one of the first companies to admit to a high-profile data breach involving sensitive consumer information, the company offered 163,000 affected individuals free credit monitoring, credit reports and identity-theft insurance.

Barely anyone took the company up on its offer.

“We put out a 1-800 number, all this free stuff that people pay a lot of money to get . . . and fewer than 10% of the people we sent notices to ever called us, ever asked us for any of the free services,” Robert Kamerschen, ChoicePoint’s vice president of law and public policy, said Monday during a panel discussion on cybersecurity and consumer data in Boston. “People debated why this is, and I’m not sure I know what the answer is.”



We'll continue to do it (our way/the easy way/the way we've always done it) until someone notices.

http://www.firefightingnews.com/article-US.cfm?articleID=28822

Accident Information Released: Federal, State Privacy Laws Weighed In Decision

April 10, 2007

Wisconsin - As the state attorney general's office continues its review of the Waukesha Fire Department's practice of keeping ambulance reports secret, the department has reversed itself and released information regarding its response to an allegedly drunken postal worker who crashed a government vehicle.

The department had said the reports could not be released because of restrictions in the federal Health Insurance Portability and Accountability Act, but the department now acknowledges in a letter to the Journal Sentinel that the federal HIPAA law does not supersede state laws on open records.



Another fun e-Discovery fact. How reliable is your ISP?

http://techdirt.com/articles/20070410/135035.shtml

Maybe You Should Back Up Your Own Email; Google, AOL, Yahoo All Losing Emails

from the whoops dept

Web-based email has made quite the comeback in the past few years thanks to massive increases in email storage offerings, as well as revamped user interfaces. However, it appears that all of the big players have run into some problems actually keeping email systems online. This past week there have been stories of both AOL and Yahoo losing a ton of email (thousands of emails for AOL, millions for Yahoo Japan). This comes just a few months after Google had some problems with mass email deletions in Gmail. While the convenience these services provide is fantastic, all of these stories of lost emails should act as a reminder that you probably shouldn't trust any of these providers alone to care for your email. It's almost surprising that we haven't seen more of an effort by these or other providers to position email backup services as well, promising to keep you running, should your main account get knocked out or deleted.



Practice hacking the operating system soon to be used by millions of school children.

http://digg.com/linux_unix/OLPC_one_laptop_per_child_Linux_based_OS_ready_for_download

OLPC (one laptop per child) Linux based OS ready for download

Apparently, the Linux-based Sugar OS from the One Laptop Per Child project is now available via a bootable LiveCD ISO, and according to user reports, works quite well.

http://www.engadget.com/2007/04/10/olpcs-linux-based-operating-system-available-for-download/



How RealID will be used?

http://www.postchronicle.com/news/breakingnews/article_21274077.shtml

Scanners Raise Privacy Concerns

By Staff Apr 10, 2007

The sheriff's office in Cincinnati, Ohio, is testing a hand-held scanner that can tell police whether a person is on one of 140 watch lists.

"This is the future of crime fighting, Clermont County, Ohio, Sheriff A.J. Rodenberg told USA Today of the Mobilisa Defense ID system.

The device scans driver's licenses, passports and other ID cards and can tell authorities whether the holder is a fugitive, a convicted sex offender or other information.


Perhaps this is the true future of crime fighting – dealing with advocacy groups.

http://www.bespacific.com/mt/archives/014513.html

April 10, 2007

EFF Sues Justice Department for Immediate Release of NSL

Follow up to postings on investigations into FBI use of National Security Letters, this press release: "The Electronic Frontier Foundation (EFF) has asked a judge to issue an emergency order requiring the FBI to immediately release agency records about its abuse of National Security Letters (NSLs) to collect Americans' personal information. The Department of Justice has already agreed that the records should be disclosed quickly due to the exceptional media attention and the questions the NSL report has raised about the government's integrity. However, despite this recognition, the Bureau has failed to meet the 20-day time limit that Congress set for requests that do not merit fast processing...EFF's FOIA request asks for all FBI records discussing or reporting violations of current law, guidelines, or policies, as well as any communications discussing various potential interpretations of current federal investigative power. EFF also demands copies of the contracts between the FBI and three telephone companies, which were intended to allow the FBI to get rapid access to telephone records."



Too lazy to visit the library?

http://www.bespacific.com/mt/archives/014504.html

April 10, 2007

AALL Maintained List of Law Library Document Suppliers

The AALL Document Delivery Caucus maintains a list of law library document delivery suppliers.



Who's in your wallet? (BugMeNot works fine...)

http://publications.mediapost.com/index.cfm?fuseaction=Articles.showArticle&art_aid=58532&art_type=5

Just An Online Minute... Utah, Land Of Dumb Internet Laws?

by Wendy Davis, Tuesday, Apr 10, 2007 1:30 PM ET


Same idea, dumb regulation...

http://techdirt.com/articles/20070410/135928.shtml

FTC Wants Time In The Clink For Spyware Distributors

from the and-throw-away-the-key dept

Despite its best intentions, the FTC has been notably impotent in its efforts at stamping out spyware. Even after they've paid fines, many spyware distributors continue to operate and thumb their nose at the the government. Since it doesn't look like fines are working, the FTC is now endorsing the idea of jail time for spyware distributors, as it hopes that the key to solving the problem is in stiffer punishments. Anyone who has had their computer overrun by spyware or had their identity stolen could be forgiven if they wanted the people behind spyware thrown in jail, but it's not clear that it's the best solution. For one thing, there's no good definition of spyware, nor is it clear what aspect of it is illegal. Most people, to use an old line, know what spyware is when they see it, but such subjective definitions don't cut it when you're talking about imprisonment. Furthermore, the FTC doesn't have a good way of tracking down spyware distributors, particularly when it comes to its most pernicious forms (aimed primarily at stealing confidential information), much of which originates outside of US borders. As is the case with spam, it's unlikely that government actions will accomplish too much in this battle. The FTC probably realizes this, and in the absence of anything effective that it can do, it at least wants to sound tough.



Interesting. I wonder what's going on?

http://blog.photobucket.com/blog/2007/04/breaking_news_p.html

April 10, 2007

Breaking news: Posting from Photobucket to MySpace

A Message to our Customers

Today MySpace made the decision to prevent Photobucket users from posting their videos and remixes to their MySpace pages.



Probably not how the RIAA whants to define Copyright...

http://yro.slashdot.org/article.pl?sid=07/04/10/216206&from=rss

EFF Jumps in Against RIAA for Copyright Misuse

Posted by Zonk on Tuesday April 10, @05:20PM from the big-guns-call-for-bigger-guns dept. Music The Courts

NewYorkCountryLawyer writes "Arguing that the RIAA and big record labels may be misusing their copyrights, the Electronic Frontier Foundation has jumped in on the defendant's side in a White Plains, New York, court conflict. The case is Lava v. Amurao, and the EFF will be defending Mr. Amurao's right to counterclaim for copyright misuse. EFF argued that the RIAA, by deliberately bringing meritless cases against innocent people based on theories of 'secondary liability', are abusing their copyrights. In its amicus brief, EFF also decried (just as when it joined the ACLU, Public Citizen, and others on the side of Debbie Foster in Capitol v. Foster) the RIAA's 'driftnet' litigation strategy. They argue that the declaratory judgment remedy must also be made available to defendants, in view of the RIAA's habit of dropping the meritless cases it started but can't finish."



Worth the price?

http://www.technewsworld.com/rsstory/56785.html

Free Antivirus Download Roots Out Rootkits

By Jack M. Germain TechNewsWorld 04/10/07 5:00 AM PT

Rootkits have become a severe threat in comparison to traditional malware because they are often overlooked by conventional antivirus systems. They execute by embedding applications within the operating system, so it is important to correctly distinguish between malicious rootkits and legitimately hidden processes.

http://www.grisoft.com/doc/download-free-anti-rootkit/us/crp/0

Tuesday, April 10, 2007

What duty to check your potential employees? (Don't editors even read these stories? They left out “is missing and believed stolen.”)

http://cbs4.com/topstories/local_story_099223111.html

Apr 9, 2007 10:39 pm US/Eastern

Sensitive Info Is Stolen From Adoption Agency

(CBS4) FT. LAUDERDALE The highly confidential information on children and their adoptive parents is at stake in a criminal case being investigated by Ft. Lauderdale Police.

Detectives went to the Childnet office located at 1400 Commercial Blvd. on Friday, when they discovered that a sensitive database containing the information of 12,000 adoptive parents and the placement of adoptive children...... Police do not believe the suspects were after the information to harm children, but rather to commit id theft and fraud.

Two employees who work for security at the company have been suspended as they are the center of the investigation. Ironically these suspects have criminal records that span from manslaughter to burglary.

Chief Operating Officer Barbara Moss says she has not comment.

Childnet is a non-profit contractor that works for the Department of Children and families, helping abused, neglected and abandoned children. A spokesperson for the Department of Children and Family says that they are working with Childnet and law enforcement to help solve the case.



Oops

http://www.wrcbtv.com/news/index.cfm?sid=7473

Turbo Tax Error

Play video

A Nebraska woman recently discovered a shocking flaw with a website thousands of people use to prepare their taxes. Instead of taking advantage of this potential gold mine for identity thieves, she is calling attention to it to protect other taxpayers.

In her laptop, Jennifer discovered a key to the backdoor of some tax returns filed on line through Turbo Tax.

A Turbo Tax customer herself, Jennifer attempted to access some past filings and the route she took online opened returns for several others with the same last name, but different first initials.

For security reasons we're not revealing the common last name or how Jennifer inadvertently gained access to three other Turbo Tax accounts.

She was able to access tax returns for three Turbo Tax customers she never met in different parts of the country.

There on her screen, everything needed for electronic filing from bank account to routing digits and of course social security numbers.

An Omaha based official with the Turbo Tax parent company says the inadvertent access to some tax files came as a shock.

"We think it was a quirk, an individual circumstance as far as we know. [Must be an interesting program if it has “individual quirks” Bob] So what we did is we took that link down in the product for now until we can fully investigate to make sure the issue won't happen again to anybody else," says Gordon Whitten.

Jennifer wouldn't want an internet stranger peeking into her tax filings so she'll delete any information that opened the back door to others with the same last name.

This does not involve the Turbo Tax software, only the website that allows taxpayers to create an account and do their taxes there.

Company officials say the inadvertent window of opportunity for potential thieves has been closed. Turbo Tax has not received any reports of customer accounts being accessed by identity thieves, and says it is grateful the Nebraska customer brought it to the company's attention.



Perhaps we could start a business that specializes in closing barn doors. We could advertise “Call us right after your horses run off!”

http://www.infoworld.com/article/07/04/10/HNirslaptopsencrypted_1.html?source=rss&url=http://www.infoworld.com/article/07/04/10/HNirslaptopsencrypted_1.html

IRS head: All laptops to be encrypted within weeks

Commissioner says serious problems in the agency's handling of sensitive data are being corrected

By Robert McMillan, IDG News Service April 10, 2007

After an auditor found serious security problems in the way it handled sensitive data on laptops, the U.S. Internal Revenue Service said it will have all laptops encrypted within the next few weeks. [...and I'll win the lottery! Bob]

Speaking in an interview with National Public Radio over the weekend, Internal Revenue Service Commissioner Mark Everson said his organization was making the effort following a recently released audit that found unencrypted data on a large percentage of IRS laptop computers.

"What the report showed, which was correct, was that we weren't taking the proper steps to protect some laptops," Everson said. "We've worked to encrypt all of the laptops and that's just about done. We've got a couple dozen more we've got to finish up in the next few weeks."

Auditors tested 100 laptop computers used by IRS employees and found that 44 of them contained "unencrypted sensitive data, including taxpayer data and employee personnel data."

... A 2003 audit found similar problems within the IRS.



That'll teach you to do your legal research on the web...

http://www.bespacific.com/mt/archives/014500.html

April 09, 2007

AALL State-by-State Report on Authentication of Online

Press release: "How trustworthy are state-level primary legal resources on the Web? The American Association of Law Libraries (AALL) is pleased to announce the publication of the State-by-State Report on Authentication of Online Legal Resources that answers this very important and timely question. The comprehensive report examines the results of a state survey that investigated whether government-hosted legal resources on the Web are official and capable of being considered authentic."

State-by-State Report on Authentication of Online Legal Resources Report (254 pages, PDF)



The question is: Who have they tapped that hasn't detected them?

http://news.com.com/2100-1043_3-6174704.html?part=rss&tag=2547-1_3-0-5&subj=news

No end in sight to hacking of 'WoW' accounts

By Daniel Terdiman Story last modified Tue Apr 10 04:00:02 PDT 2007

If you're a World of Warcraft player using Windows, beware.

For months, hackers--most likely in China and Russia, according to security watchers--have been surreptitiously installing keylogging software on WoW players' Windows computers, hijacking their accounts and selling off their often valuable in-game assets.

And the problem doesn't show any signs of going away.

The gangs perpetrating the hacking are "incredibly active, and it's a good exploit," said Roger Thompson, CTO of security software developer LinkScanner. "It's probably a conservative estimate to say that there's tens of thousands of victims."

... For its part, Blizzard said it's addressing the problem by informing players that they should ensure their computers are safe against malware.

... There are more than 8 million WoW players, so even if tens of thousands are finding their accounts compromised, that's still a very small percentage of the total.

But for the hackers, the rewards can be substantial. That's because many players hoard gold, weapons, spells or armor worth a lot of money on the open market. Even though Blizzard doesn't officially allow players to buy or sell those goods, there is a thriving market for them (and that's in spite of the fact that eBay, one of the most popular venues for such transactions, recently decided to ban them).



Isn't it nice that our kids are getting involved in politics at an early age?

http://hosted.ap.org/dynamic/stories/M/MYSPACE_FREE_SPEECH?SITE=VALYD&SECTION=HOME&TEMPLATE=DEFAULT

Court: MySpace Postings Are Free Speech

By CHARLES WILSON Associated Press Writer Apr 10, 12:47 AM EDT

INDIANAPOLIS (AP) -- A judge violated a juvenile's free-speech rights when he placed her on probation for posting an expletive-laden entry on MySpace criticizing a school principal, the Indiana Court of Appeals ruled.

The three-judge panel on Monday ordered the Putnam Circuit Court to set aside its penalty against the girl, referred to only as A.B. in court records.

"While we have little regard for A.B.'s use of vulgar epithets, we conclude that her overall message constitutes political speech," Judge Patricia Riley wrote in the 10-page opinion.

In February 2006, Greencastle Middle School Principal Shawn Gobert discovered a Web page on MySpace purportedly created by him. A.B., who did not create the page, made derogatory postings on it concerning the school's policy on body piercings.

The state filed a delinquency petition in March alleging that A.B.'s acts would have been harassment, identity deception and identity theft if committed by an adult. The juvenile court dropped most of the charges but in June found A.B. to be a delinquent child and placed her on nine months of probation. The judge ruled the comments were obscene.

A.B. appealed, arguing that her comments were protected political speech under both the state and federal constitutions because they dealt with school policy.

The Court of Appeals found that the comments were protected and that the juvenile court had unconstitutionally restricted her right of free expression.



Attention copyright lawyers! A whole industry needs your help! (Non-digital rights management?)

http://techdirt.com/articles/20070405/194853.shtml

More Research Shows How The Fashion Industry Is Helped By The Lack Of Intellectual Property Rights

from the keep-it-coming dept

Back in 2003, we mentioned an article that compared the entertainment industry to the fashion industry, noting that even though there was no intellectual property protections over clothing design and copying was rampant, the fashion industry was thriving. This shouldn't come as a surprise, really. After all, without the artificial protectionism, the fashion designers are forced to continually compete by continually innovating and always trying to come out with the latest and greatest design. Even though others copy, there's tremendous value in being the first, or being the "big name" in the industry. The article included this fantastic quote: "Ideas arise, evolve through collaboration, gain currency through exposure, mutate in new directions, and diffuse through imitation. The constant borrowing, repurposing, and transformation of prior work are as integral to creativity in music and film as they are to fashion." In 2005, the NY Times wrote a similar article, but warned that the fashion industry was moving in the wrong direction, as lazy designers who didn't want to compete and wanted to rest on their laurels had started pushing for new intellectual property over their designs. Late last year, the calls for such protectionism grew even stronger -- though, the reasoning doesn't make any sense. The entire point of intellectual property protections is to create incentives for a market. If that market is already thriving, why do you need to add new incentives? The real reason is that it's not to provide incentives. It's a way for successful players to keep making money without continuing to innovate -- which is simply bad for society.

The NY Times is taking another look at this issue, this time in a piece written by well-known economist Hal Varian, who points to a recent study that doesn't just note that the fashion industry has thrived without intellectual property protection, but notes that a big part of the reason it has thrived is because of the lack of IP. In other words, if those pushing for those new IP rights get them, the end result will likely be harmful to the overall fashion industry. Again, this shouldn't be surprising, as removing protectionist policies tends to increase competition and the size of the addressable market, but it's certainly a good example to point to when people insist that things like the music industry wouldn't exist without copyright protection.



Don't tell Al Gore, he's happy in his fantasy world. (Then again, perhaps sunspots are herds of SUVs?)

http://science.slashdot.org/article.pl?sid=07/04/10/0058248&from=rss

Sunspots Reach 1000-Year Peak

Posted by CowboyNeal on Monday April 09, @11:16PM from the radio-signals-cringing dept. Space Science

rlp writes "Researchers at the Institute for Astronomy in Zurich are reporting that solar sunspot activity is at a 1000-year peak. Records of sunspots have been kept since 1610. The period between 1645 and 1715 (known as the Maunder Minimum) was a period of very few sunspots.[AKA: The “little ice age” Bob] Researchers extended the record by measuring isotopes of beryllium (created by cosmic rays) in Greenland ice cores. Based on both observations and ice core records, we are now at a sunspot peak exceeding solar activity for any time in the past thousand years."



Just consider it another way to find companies you never heard of...

http://valleywag.com/tech/the-chart/hottest-startups-250874.php

Hottest Startups

In two threads -- one on Linked In, the other on Venture Beat -- commenters are nominating the hottest startups of Silicon Valley. We totted up the mentions on both threads. Facebook, the college social network, scores highest; with Admob, the mobile ad network, following up.



Sometimes, technology just goes too far...

http://news.com.com/2061-10802_3-6174659.html?part=rss&tag=2547-1_3-0-5&subj=news

Picture perfect emoticons

April 9, 2007 4:18 PM PDT

A former University of Pittsburgh doctoral student and professor have devised a way to turn photos of people's faces into emoticons for use in e-mails, mobile text messages and other communications. Basically, they take a single expressionless photo, slice it into pieces and alter the slices to create separate images of the six basic facial expressions representing happiness, sadness, anger, surprise, disgust and fear, according to an article in Physorg.com. The program, called FaceAlive, was developed by Xin Li, who now works at Google, and his computer science adviser, Shi-Kuo Chang. No word on when they'll be creating the popular "wink" or "hug" emoticons.



The next big thing?

http://www.educause.edu/Browse/645?PARENT_ID=822

ESI and E-Discovery

20 Resources In This Topic - Last Updated: 4/6/2007

Monday, April 09, 2007

Lawyers go to school to learn how to keep two opposite and irreconcilable arguments in their heads at the same time...

http://www.insidehighered.com/news/2007/04/09/heckenkamp

April 9

Defining Privacy — and Its Limits

A student in a public university dormitory room had a “reasonable expectation of privacy” for his personal computer and its hard drive, a federal appeals court ruled on Thursday. The decision also found that despite that right to privacy, an administrator in the case under review had the right to conduct a remote search of the computer — without a warrant — because of the circumstances involved.

The decision — by the U.S. Court of Appeals for the Ninth Circuit — is among the highest level court rulings to date on a set of legal questions pitting privacy vs. security that are increasingly present in academe. While experts cautioned that the decision involved a specific set of facts, several also said it provided guidance for students on their privacy rights and for administrators at public colleges and universities on setting computer policies that give them the flexibility they feel they need to prevent security breaches.

The ruling dates back to an incident in 1999, and the actions of administrators at the University of Wisconsin at Madison, when they were notified by Qualcomm Corporation, a San Diego company that produces wireless computing devices, that someone on Madison’s network was hacking into the company’s network. Ultimately, a then-student at Madison whose computer was found to be used in the hacking entered into an agreement with prosecutors in which he agreed to admit guilt, received a sentence of time served on federal charges arising from the hacking, and was released after eight months in prison. But Jerome T. Heckenkamp, the then-student, also won the right to appeal the case in the hope of clearing his name, and his appeal focused on information gathered by Madison officials.

Jeffrey Savoy, a computer security official at Wisconsin, was the person who received Qualcomm’s complaint. When he confirmed that someone on the Madison network was hacking the company, he also found that this same person appeared to have gained unauthorized access to portions of the university’s network as well. Of particular concern to Savoy was that this hacker had gained access to the server used by the university to house 60,000 e-mail accounts and to deliver about 250,000 e-mail messages each day.

Savoy was able to link the intrusions to a computer from a specific dormitory room and eventually was able to identify the room and the computer accounts being used as belonging to Heckenkamp. The decision by the appeals court then details the dual tracks taken by Qualcomm and Madison. The company decided to seek a warrant for a search of Heckenkamp’s room, but Savoy continued to monitor the situation in the meantime. He found that Heckenkamp had lost a job in the university’s computer help desk two years before and so had extensive knowledge of the university networks — enough to do real damage.

As the investigation continued, Savoy saw that the computer in question was being used, and that the hacker might well have been able to see that his actions were being detected. So Savoy, with university police officers, went to Heckenkamp’s room, entered it when the door was ajar and nobody was there, and disconnected the cord attaching it to the network.

Using Heckenkamp’s password, [probably from a keylogger, passwords are stored encrypted on most systems. Bob] which he had provided to a police officer, Savoy also conducted some tests on the computer to be certain that he had been successful in blocking its access to the university network. When Heckencamp was indicted in California, evidence in the case was a mix of materials obtained with a warrant the day after Savoy was in the room, but also information Savoy had obtained remotely.

In its analysis of the case, the appeals court said there can be “no doubt” that Heckenkamp’s expectation of privacy on his computer was “legitimate and objectively reasonable.” Further, the court said that this privacy expectation did not go away when Heckenkamp attached his computer to the university’s network. In language that would be relevant to many colleges, the court said that “the mere fact of accessing a network does not in itself extinguish privacy expectations.”

While that part of the decision establishes the norm for a public university student’s computers to be assumed private (thus requiring a warrant for searches), the court went on to say that Savoy’s actions were protected because of the way the university had established and communicated its policies, and because of his intent.

The relevant part of the university policy, quoted by the judges, says the following: “[A]ll computer and electronic files should be free from access by any but the authorized users of those files. Exceptions to this basic principle shall be kept to a minimum and made only where essential to ... protect the integrity of the university and the rights and property of the state.”

It was legitimate for the university to act as it did, the judges found, because it was acting out of concern about its own e-mail network, not to help with the law enforcement investigation set off by Qualcomm, and it acted in ways that were consistent with the university’s policies that Heckenkamp had agreed to follow. Savoy “needed to act immediately to protect the system,” the court found. In this situation, Savoy acted with legitimate “special needs” that justified not waiting for a warrant, the court found. The ruling was about the remote search of the computer, not the in-room search.

Benjamin Coleman, a San Diego lawyer who represented Heckenkamp in the case, said that he was disappointed that the evidence was not thrown out, and said that an appeal to the U.S. Supreme Court is possible. But Coleman said that the ruling gave students a key victory because it rejected that there was no basis for Heckenkamp to presume the privacy of his computer. Even though the court defined some narrow limits to that right, Coleman said, “this is the first decision at this level that says college students have an expectation to privacy on their computers, so this is very good for students’ privacy rights.”

... On the basis of this case one could say, ‘just because something is technologically possible, i.e. remote inspection of a hard drive, does not necessarily make it legal.’”

The case also provides a clear lesson for colleges, Mitrano said: “Write good policy.”



This will tell us if the NFL's legal team is aware of the backlash...

http://wendy.seltzer.org/blog/archives/2007/04/05/nfl_second_down_and_goal.html

April 05, 2007

NFL: Second Down and Goal?

Today, 12 business days after I re-sent my DMCA counter-notification, YouTube sent notice that they had restored my Super Bowl excerpt. Catch it while you can, because I'm not holding my breath that it will stay online this time either.

The chronology so far:

By my count, that's 17 days up, 38 days down, not counting "technical problems" that prevented access to the video on some days when it was not sidelined by a notification.

In the first takedown first DMCA takedown NFL sent YouTube in February, shortly after the Super Bowl, my video of the copyright warning was among 162 URLs listed. After YouTube re-posted my video, NFL's second DMCA notice singled out just one video, the one for which I had counter-notified on fair use grounds. If there was any excuse that the first claim was just a bot's overactive pattern-matching -- an excuse the NFL doesn't rely on in its response on the Wall Street Journal's Law Blog -- that excuse evaporated by the time I counter-notified.

Rather, NFL Spokesman Brian McCarthy argues,

We are entitled to disagree, in good faith, with her asserted defense, absent a court decision.
(3) We have valid grounds to disagree with the professor’s fair use argument. Had she simply used the clip in her classroom, before students, she might have had a stronger argument that the context was educational and entitled to fair use deference. But it was posted without any of this context, and in a manner available for anyone in the world to see, not just her students.

I think their fair use analysis is wrong as a matter of law, and therefore it was “knowingly materially misrepresenting” to claim that the clip infringed after getting notification of the clip’s content. I’m entitled to share this type of educational fair use with more than the students in my classroom. (I’m not trying to rely on the TEACH Act with its crabbed DRM requirements.) I post my syllabus and teaching slides online for anyone to see, and wanted to post this discussion similarly.

On the fair use factors, I think I’m in good shape: My use is for nonprofit educational purposes; the copyright in the telecast is thin; the portion of football that follows the copyright warning is a minute portion of the whole, with no significant action or commentary, useful to show people what it was the NFL claimed its copyright covered; and the effect on the market for or value of the work is non-existent.

Too bad the U.S.'s WTO non-compliant gambling law prevents us from wagering on what will happen next...

Posted by Wendy at April 05, 2007 08:24 AM |



There is more than one way to teach...

http://techdirt.com/articles/20070406/132716.shtml

High School Principal Sues Students For Phony MySpace Profiles

from the please,-make-fun-of-me dept

Not all MySpace-related lawsuits involve the same predictable factors like underage users and sexual assault. A high school principal in Pennsylvania has sued four students after they created parody MySpace profiles for him that listed interests such as smoking pot and watching pornography. He claims that the profile has damaged his future earnings potential and so he wants monetary compensation. It's not clear whether the students' actions qualify as first amendment-protected parody or whether they'd be seen as defamation of a private citizen. Either way, the most likely outcome here is more copycat attempts as he's just put a target on himself inviting other students to attack him. Instead of suing, it seems like a better course of action would have been to simply contact MySpace and request that the profiles be taken down. Now, for better or worse, he'll always be known as the principal that sued his students over fake MySpace profiles, to anyone who searches for his name. To his credit (or maybe his lawyer's) he's suing the students and not the site itself, which is the proper legal course. Then again, it's hard to imagine that he'll be able to get much in damages from a few high school students.



For your e-bookshelf...

http://www.bespacific.com/mt/archives/014496.html

April 06, 2007

March 2007 Freedom of Information Act Guide Now Available

USDOJ: "The Office of Information and Privacy has completed the latest revision of the Freedom of Information Act Guide, a comprehensive reference volume covering all aspects of the Freedom of Information Act (FOIA). The March 2007 edition of the FOIA Guide contains a newly updated and revised discussion of the procedural requirements of the FOIA, the contours of the FOIA's nine exemptions and three exclusions, as well as the considerations applicable to FOIA litigation. This latest edition of the FOIA Guide also contains an overview of Executive Order 13,392, entitled "Improving Agency Disclosure of Information." This Executive Order was signed by the President on December 14, 2005, and calls upon all agencies to improve their FOIA operations by ensuring that they are "both results-oriented and produce results."

  • "The March 2007 edition of the FOIA Guide is now available electronically on the Department of Justice's FOIA Web site at http://www.usdoj.gov/oip/foia_guide07.htm. This electronic version of the FOIA Guide can be easily searched by using key words. The FOIA Guide has also been sent to the Government Printing Office, which expects it to be ready for distribution in hard copy within the next few weeks."



Schools may go the way of record stores...

http://slashdot.org/article.pl?sid=07/04/08/1317213&from=rss

O'Reilly Opens Online Tech School

Posted by CmdrTaco on Sunday April 08, @09:56AM from the exams-are-today-and-you-didn't-study dept. Education

bl8n8r writes "The popular book author has started the O'Reilly School of Technology which offers online training and certification. "The O'Reilly School of Technology and the University of Illinois have partnered to offer Certificates of Professional Development in information technology and related skills." Among classes offered are Linux/Unix administration, Open Source coding, Java coding, C Programming and others."



Something my students can use...

http://slashdot.org/article.pl?sid=07/04/08/2212225&from=rss

Canadian University Students Taught To Protect IP

Posted by Zonk on Sunday April 08, @07:39PM from the they-have-a-few-rights-too dept. Education

innocent_white_lamb writes "Graduate students at Carleton University (Ottawa) are taking steps to protect their intellectual property, at the same time are insuring that they are being properly recognized for their work. This is in response to the increased commercialization of research done at universities, and high-profile cases of copyright infringement by professors at the University of Toronto and Indiana University. 'The initiative will include workshops and a handbook outlining what would constitute an infraction of students' intellectual property rights, Howlett said. Examples include a student not receiving authorship on written work, or having a professor take credit for their work. "This isn't an indictment of profs at all," said Howlett. "It's just to ensure that students' rights are protected in the case that it does happen."'"

Sunday, April 08, 2007

It has been so long since we had a good sized (tens of thousands) identity theft, I was beginning to think people were becoming honest! (Quick, smelling salts/CPR for all the lawyers!)

http://www.wbbm780.com/pages/342336.php?contentType=4&contentId=402122

Laptops Stolen From Chicago Public Schools HQ

Posted: Saturday, 07 April 2007 9:04AM

CHICAGO, Ill. (AP) -- Two laptop computers stolen from Chicago Public Schools headquarters Friday contain the names and Social Security numbers of about 40,000 current and former employees, officials said.

The theft occurred at the district’s downtown offices about noon, and a suspect's image was captured by surveillance video, CPS said in a statement. No one was in custody late Friday and a Chicago police spokesman said he had no information on the theft.

The computers belong to McGladrey and Pullen and its subcontractor — accounting firms that were reviewing the history of payments to the CPS Teacher Pension Fund, the release said. Therefore they contain the names and Social Security numbers of any current and former CPS employees who contributed to the system's Teacher Pension Fund from 2003 to 2006. That includes teachers, principals and assistant principals, the statement said. The laptops do not contain addresses or birth dates.

"We have no reason to believe the person knew what information is on there," [Fair statement. Bob] District spokesman Michael Vaughn told the Chicago Tribune. He said the files containing personal information are password-protected. [Wishful thinking Bob]

The school system, the nation's third-largest, is offering a $10,000 reward for information leading to an arrest or the recovery of the computers. [You don't often see that... Bob]

CPS planned to e-mail all current employees about the thefts and to post information for former employees on its Web site: www.cps.k12.il.us.

[Note that the story on the school web site is hidden in plain sight (bottom third of the page, follows a link to another story, no headline) Clever! Bob]



Too long a delay?

http://www.al.com/newsflash/regional/index.ssf?/base/news-28/117587754827260.xml&storylist=alabamanews

Tuscaloosa-based DCH loses personal data on employees

4/6/2007, 11:32 a.m. CDT The Associated Press

TUSCALOOSA, Ala. (AP) — Social Security numbers and other personal data on more than 6,000 employees and retirees of DCH Health System are missing after a consulting company lost a computer disk and documents containing the information.

The hospital system notified employees of the breach on Thursday. The loss could affect anyone on the payroll last year at DCH Regional Medical Center in Tuscaloosa, Northport Medical Center or Fayette Medical Center.

While the data has been missing since last month, DCH said it did not notify workers of the breach until it had in place a program to help protect against possible identity theft linked to the loss.

"We felt it was best if we could tell our employees of the issue and solution at the same time," said Brad Fisher, a DCH spokesman.

An encrypted disk and papers containing employees' personal identification information were lost in early March by Mercer Human Resources Consulting, the company that reviews DCH's pension plan to determine annual employer contribution requirements.

The pension documents had been mailed from Mercer's Birmingham offices on March 2, but disappeared after they reached their destination in Louisiana, where they had been sent to a Mercer employee.

However, Mercer did not notify DCH until March 22 that a package of documents containing retirement benefit information had disappeared. It was about a week before Mercer realized the package was missing, said Mercer spokesman Charles Salmans.

Tracking data indicated the package had been delivered properly, but the intended recipient never received it.

"It was sent without requiring the addressee to sign for it, which should not have happened," Salmans said. An investigation is still under way, he said.



Welcome to the neighborhood!

http://www.journal-news.net/news/articles.asp?articleID=8305

Workforce computer missing

By LAUREN HOUGH / Journal Staff Writer Saturday, April 07, 2007— Time:2:17:09 PMEST

MARTINSBURG — Additional security measures are being examined for the recently opened Workforce West Virginia Career Center after a laptop computer was taken from the facility during its first day of business.

... The missing laptop contained audit information pertaining to 107 employers in the five county region of Berkeley, Hampshire, Jefferson, Mineral and Morgan counties.

It contained limited information about some, but not all, of the employees who worked or had worked for those employers,” Harbour said.

... He also noted that every person who walked through the front door was required to sign in, giving officials a list of names of those who would have had access to the computer. [A little wager anyone? Bob]



Searching for a data haven?

http://www.bespacific.com/mt/archives/014490.html

April 06, 2007

World Bank Developing Country-by-Country Database on Access Laws

Via Toby McIntosh, freedominfo.org: "The World Bank is well on its way to developing a country-by-country database "on various transparency and accountability institutions in developing countries...The new database, which may be posted online in a month or so, will summarize national laws on asset disclosure, conflict of interest, freedom of information, and immunity provisions. The Bank also has developed a set of "good practices" against which to measure country laws, according to information provided by Bank officials. The data-gathering effort now covers 78 countries, with an emphasis on developing countries. Of the 78, 53 are so-called IDA countries, a reference to the World Bank's International Development Association, the facility through which the Bank supports anti-poverty programs in the poorest developing countries with long-term, no interest loans."



...and the car's blackbox, and the GPS system, and that laptop in the back seat, and your PDA, and...

http://fourthamendment.com/blog/index.php?blog=1&title=d_kan_consent_to_search_car_extended_to_&more=1&c=1&tb=1&pb=1

Consent to search car extended to looking at call history on cellphone

04/07/07 Permalink 09:22:11 am, by fourth Email

Discovery of an apparent hidden [is that an oxymoron? Bob] compartment justified making defendant follow the officer to a garage in a nearby city. Defendant's consent to search the vehicle extended to looking at the call history on his cellphone. Defendant conceded that it otherwise was a lawful accessing of the number under the Electronic Communications Privacy Act. [Here there also was probable cause.] United States v. Espinoza, 2007 U.S. Dist. LEXIS 25263 (D. Kan. April 3, 2007):



Similar to looking for all cell phones within a mile of the crime?

http://www.latimes.com/news/opinion/commentary/la-oe-mnookin5apr05,1,4944312.story?ctrack=1&cset=true

The problem with expanding DNA searches

They could locate not just convicted criminals but also relatives -- violating privacy.

By Jennifer Mnookin, JENNIFER MNOOKIN is a professor at UCLA's School of Law. April 5, 2007

IF YOU'RE CONVICTED of a felony (or in some states a misdemeanor), your DNA goes into a database. That information primarily helps in the pursuit of repeat offenders. But some people want to extend the reach of that data to find people who are only a partial match. It's a particularly personal form of a law enforcement fishing expedition.

The technique is called "familial searching," and it targets not only the convicted but their relatives as well.

Sometimes, when an investigator tries to match a crime scene sample to the several million profiles in, say, the FBI's database, no exact match turns up. But there might be someone whose DNA profile is unusually similar. [Definition? Both are (fill in ethnic group) Bob] If the partial match is sufficiently close, or if some of the genetic markers in the sample are sufficiently rare, it could mean that the crime scene sample was left by a close genetic relative of the person who is included in the DNA database.

... Is this a lead that any investigator would be crazy to ignore, or is it an encroachment on civil liberties?

The difficulty is that it is both. While mining the DNA database for clues is certainly tempting, it is a temptation we should resist. Fairness and privacy concerns require it.

Although Britain has been using familial searches for several years, it's just arriving in the United States.

... Many prosecutors, including those in California, are lobbying hard to be able to use the technique, and a 2006 article in Science argued that the use of such kinship analysis could increase the number of cases that were solved by up to 40%.



Government should control everything. People can't be trusted.

http://www.stltoday.com/stltoday/news/stories.nsf/stlouiscitycounty/story/6373F4AA466B0DBF862572B400104D48?OpenDocument

Missouri bill calls for crackdown on sale of ... baking soda

By Derek Kravitz POST-DISPATCH JEFFERSON CITY BUREAU 04/05/2007

JEFFERSON CITY — First, the state said you must make a special trip to the pharmacy counter to buy certain cold medicines. That was to curb production of methamphetamine.

Now, a St. Louis legislator wants you to do the same thing to buy an even more common household item — baking soda — because it's used to make crack cocaine.



Want to experiment with a photo editor?

http://www.kk.org/cooltools/archives/001646.php

Picnik Photo Editor

Free, web-based photo editing

I've seen many quick and dirty photo editing programs via web browser, but this Flash-based editor definitely takes the cake. Hands down, the ease of use is the best part. As you work, little windows pop up with explanations, but I've never needed them because of the usability.

... Picnik also has a bunch of "creative tools" (essentially "filters" in Photoshop). What's great is the ability to adjust most of these effects. Most online programs allow you only to simply set a photo to B&W or Sepia tone. This program allows for adjustments so that you can gradually set a color hue, or go crazy.

... One of the biggest selling points is how it integrates Picasa and Flickr. You can search and download photos from any public Flickr account seamlessly, and Picnik also allows you to email photos to sites like Photobucket, TypePad and even Walmart (Walmart's own online photo editing software is nothing compared to Picnik). Moreover, close Picnik and come back the next day: your image is cached. Picnik sends a cookie to your browser, so when you return, you can pick up right where you left off.

... The main cons here are that it seems you can only upload one photo at a time (which may just be part of the beta), and there's no selection "lasso" tool (as in Photoshop).

Picnik Photo Editor Free! Available here Created by Picnik, Inc.



Free is good! (So good, the site was swamped...)

http://digg.com/offbeat_news/Top_10_Best_Places_to_Get_Free_Books

Top 10 Best Places to Get Free Books

In our fast paced world of email, and RSS feeds, sometimes it ’s best to just slow down and read a good book…but if you’re unwilling to shell out big bucks for the latest bestseller - try out these great resources, and read to your hearts content!

http://www.friedbeef.com/2007/04/02/top-10-best-places-to-get-free-books-part-1/

[...more freebies from the comments:

Here's a nice site for free audiobooks: http://librivox.org/newcatalog/

...books that are freely available under the creative commons license. http://wiki.creativecommons.org/Books

I get all my books at http://www.anonib.com/bookchan/ [Looks like “Copyright Violators Inc.” Bob]