Wednesday, April 25, 2007

Another source of details? Do they already have the full story?

http://www.forbes.com/feeds/ap/2007/04/24/ap3647951.html

Banks to Sue TJX Cos. Over Data Theft

By MARK JEWELL 04.24.07, 6:31 PM ET

Bank associations in Massachusetts, Connecticut and Maine said Tuesday they will sue TJX Cos. over a data theft that exposed at least 45 million credit and debit cards to potential fraud.

Banks have been saddled with costs to replace cards and cover fraudulent charges tied to the theft from TJX, the owner of nearly 2,500 discount stores including T.J. Maxx and Marshalls. Since it disclosed the data theft three months ago, Framingham-based TJX has been hit with several lawsuits filed in the U.S. and Canada by consumers, financial institutions and investors.

The Massachusetts Bankers Association said the Connecticut Bankers Association, Maine Association of Community Banks and at least three individuals banks are joining in a lawsuit to be filed Wednesday in U.S. District Court in Boston. The associations represent nearly 300 banks.

Dan Forte, president and chief executive of the Massachusetts Bankers Association, said his organization will contact other state bank groups nationwide to see if they're interested in joining the lawsuit, which seeks class-action status.

The complaint will make an unfair trade practices claim under Massachusetts law alleging that TJX failed to adequately protect sensitive customer data, and misrepresented how it handled data.

TJX spokeswoman Sherry Lang said the company does not comment on pending litigation, but also said, "TJX will defend itself vigorously."

The Massachusetts Bankers Association said in January its members had been contacted by credit and debit card companies of fraudulent purchases tied to the TJX breach that had been made in Florida, Georgia, and Louisiana, and overseas in Hong Kong and Sweden. Reports continue to come in from "around the world," bankers association spokesman Bruce Spitzer said.

Spitzer said the banks will try to recover "tens of millions of dollars," although the damages the banks ultimately will seek depends on future expenses from replacing cards and covering fraudulent purchases.

On Jan. 17, TJX disclosed a breach of its computer systems by an unknown hacker or hackers who accessed card data from transactions as long ago as late 2002. On March 28, TJX said at least 45.7 million of its shoppers' cards had been compromised. Independent organizations that track data thefts say the TJX case is believed to be the largest in the U.S. based on the number of customer records compromised.

TJX says about three-quarters of the 45.7 million cards had either expired by the time of the theft, or the stolen information didn't include security code data from the cards' magnetic stripes. However, TJX also has said the intruders could have tapped the unencrypted flow of information to card issuers as customers checked out with their credit cards.

The company and the U.S. Secret Service are investigating. The only arrests so far have come in Florida, where 10 people who aren't believed to be the TJX hackers are accused of using stolen TJX customer data to buy Wal-Mart (nyse: WMT - news - people ) gift cards.



See, it's not just me.

http://www.ebizq.net/podcasts/153.html

ebizQ Podcast: Systems Under Siege -

Steps a CSO Should Take Today: A Talk With Mike Rothman

Listen to or download the entire 10:03 podcast below: Download file

... Would you discuss the recent breach with TJX, and how incident response and crisis communications would have made a difference?
I always point back to the issue that Johnson & Johnson had with Tylenol. That was years ago and I was just a kid and there was bedlam and everybody was terrified and they were tossing their Tylenol out of their windows because they were scared. The CEO got on TV and accepted responsibility and said this is what my plan is going to be to both restore your trust in my company as well as the product and this is what we're doing to make sure it never happens again. That started the whole thing with sealing the drugs and making sure you?ve got tamper proof packaging. It really was a watershed moment in crises communications.

You look at how TJX handled their data breach which was, well, we didn't tell you for a couple of months. Sorry. You could tell they didn't even mean it and we're not going to give you any credit monitoring all 45 million customers that have been transgressed because, you know, at the end of the day I don't legally have to and my margins are like 2% so there is no way I can stay in business and do that. It just felt that every step of the process they were stonewalling the public, they were treating their customers shabbily. I think that comes back and bites you.

A brand is a very hard thing to build and is a very significant thing to waste. You do one stupid thing and years of good karma go by the wayside. I think by handling the situation a lot more effectively, TJX could have made this much less of an issue. But they stonewalled, they didn't admit a problem, they tried to blame other people, and they wouldn't do the right thing for customers. So at the end of the day, I believe customers won't do the right thing by them.



Probably after the computers...

http://www.cnbc.com/id/18294461

Thieves Nab Info on 160,000 Neiman Marcus Workers

24 Apr 2007 | 06:13 PM

A computer stolen from a Neiman Marcus consultant contained personal information on nearly 160,000 current and former employees, the luxury retailer said Tuesday.

The company said there was no indication yet that the thieves had tapped into the personal information, which included individuals' names, addresses, Social Security numbers, birth dates and salaries.

The stolen notebook computer belonged to a pension-benefits consulting firm hired by Neiman Marcus. It was taken April 5 from a technician hired by the consultant, according to a Neiman Marcus spokeswoman.

Ginger Reeder, the spokeswoman, said Neiman Marcus was told about the theft April 10 but was asked by police not to release information about it until this week while the case was investigated. She declined to say where or how the theft occurred, other than that it didn't occur in Dallas, where the retailer is based.

Reeder said other items were taken, leading the company to believe that the thieves weren't after information about the Neiman Marcus employees.

The consultant's policies called for computer files to be encrypted, but Neiman Marcus doesn't know whether that was done and is cautiously acting as if the data on the stolen machine wasn't protected, Reeder said.

... 'This is probably one of the most significant breaches of employee records by an American company,' said Mark Rotenberg, executive director of the Electronic Privacy Information Center, a consumer advocacy group. 'For a single company to lose its entire employee history is serious.'

Rotenberg said it was particularly alarming that the loss involved Social Security numbers and dates of birth -- the currency used by identity thieves.

... Neiman Marcus Group has close to 17,000 current employees. [High turnover... Bob]

... 'It's absolutely unacceptable for any company to be carrying around information that includes people's Social Security numbers without it being encrypted, but unfortunately we see quite a few instances of it,' he said.



Small time...

http://www.jconline.com/apps/pbcs.dll/article?AID=/20070424/NEWS0901/70424010

Purdue reports potential for ID theft for 175 students

STAFF REPORTS April 24, 2007

A Purdue University computer gaffe put the names and Social Security numbers of 175 students on the Internet, according to a release from the university this morning.

It is unclear how long the site was available.

The site had the names and Social Security numbers of students enrolled in a freshman engineering honors course in fall 2001. The site could be found through search engines, but has been taken down now. It is not known if any of the information has been used in identity theft or fraud by anyone who has seen it.

Letters to the students, many of whom have graduated or now left the university, have been sent. Since the addresses of the students are several years old, anyone who thinks they might be on the list should call (866) 307-8513. More information is available at www.purdue.edu/news/coe0704.html.



Another laptop stolen...

http://wjz.com/local/local_story_114155042.html

Apr 24, 2007 3:48 pm US/Eastern

Baltimore Co. Laptop Stolen With Personal Info

(AP) TOWSON, Md. A laptop containing the personal information of about 6,000 people was stolen from a Baltimore County health center, a health department spokeswoman said Tuesday.

The computer did not contain medical informationm but did have names, date of birth, social security numbers, telephone numbers and emergency contact information. The personal information was from patients who were seen at the clinic between Jan. 1, 2004 and April 12.

Letters have been sent out to the 6,000, advising them of the availability of free credit checks provided by the three major credit reporting agencies and saying the risk of identity theft was low because the file containing the information was protected by passwords and other security safeguards.

Monique Lyle, a spokeswoman for the county health department, said the computer, which was stolen April 16, has not been recovered, but no one has reported any identity theft or other problems related to the theft.



Likely the IT department doesn't even know this is happening...

http://www.technewsworld.com/rsstory/57058.html

Are Data Leaks Bleeding Your Company Dry?

By Jack M. Germain TechNewsWorld 04/25/07 4:00 AM PT

Businesses are starting to respond to the rising threat levels posed by data leakage from pocket-sized storage devices. The push to react is not coming from the fear of lost data as much as it is fear of losing money. Negative publicity became a primary driver last year in influencing

The data drip is here. Computer security experts are worried that corporate data leaking from networks onto small mobile storage devices will worsen into a flood of stolen customer and company information.

Over half of all information leaks travel to personal data storage devices such as USB drives, MP3 players and PDAs, according to recent industry surveys. These surveys suggest that portable storage devices are contributing to a staggering rise in ID theft and loss of sensitive data on the corporate level.

Every 79 seconds, someone in the United States becomes a victim of such thefts. Even a single incident of data loss can cost a company millions of dollars in lost revenue, lost opportunity, lost competitive advantage and costly penalties for regulatory non-compliance, warn security experts.

"The cost of remediating lost data can be (US)$100 per record, so it makes economic sense to invest in data loss prevention technology," Chip Hay, vice president of marketing Email Marketing Software - Free Demo for security firm Code Green Networks, told TechNewsWorld.



Another report/statistic/guess

http://www.eweek.com/article2/0,1759,2121597,00.asp?kc=EWRSS03119TX1K0000594

New Report Chronicles the Cost of Data Leaks

April 24, 2007 By Brian Prince

Researchers at Datamonitor can give corporations 1.8 million reasons to protect themselves against data breaches.

According to the research group's new report, "Datagate: The Next Inevitable Corporate Disaster?", the average cost of a data leak incident is $1.82 million. That figure is based on accounts of 23 percent of respondents—the others were unable to track and audit losses after a breach.

The report surveyed 1,400 IT decision makers across the globe. All totaled, 60 percent of those surveyed said they experienced a data leak last year, and only six percent could state with certainty that they had no data leakage problems in the past two years.



The court will be so pleased... (But note that they still don't have the emails)

http://news.com.com/8301-10784_3-9712220-7.html?part=rss&subj=news&tag=2547-1_3-0-5

April 24, 2007 4:57 PM PDT

Intel outlines plans to find missing e-mail

Posted by Tom Krazit

Intel filed a report late Monday night outlining how it plans to recover e-mail that it failed to preserve following the filing of Advanced Micro Devices' antitrust lawsuit against the company.

Last month, Intel said that a number of employees had failed to properly preserve e-mail related to AMD's allegations after some people forgot to save "sent" e-mail or assumed IT was backing up their folders. The report doesn't have much in the way of details beyond what Intel has already said, that despite the breakdown in its document retention policies it thinks it can cobble together the rest of the e-mail messages from backup tapes, e-mail preserved by those who properly followed retention procedures, and by looking at other employees within the same department or management team.

The mess goes all the way to the top: court transcripts indicated that CEO Paul Otellini was one of the individuals who thought IT was backing up his e-mail. But Intel noted that it did take a snapshot of every file on its network the day after AMD filed its lawsuit, which are the files that might have the evidence AMD seeks.



Take all you want, but eat all you take.

http://www.belleville.com/198/story/18298.html

Posted on Tue, Apr. 24, 2007

DNA left on cinnamon bun nabs car thief

The Associated Press

EASTPOINTE, Mich. --Norman O. Wheeler probably wishes he had finished that cinnamon bun. DNA evidence from the partly eaten pastry led to Wheeler's arrest in a 2004 car theft.

The 40-year-old Detroit resident already was serving time for another auto theft when authorities made the DNA match. Wheeler pleaded guilty earlier this month, and he now faces sentencing May 22.

Eastpointe Officer Ed Lulko was investigating the car-theft report when a witness described seeing a man arrive in one car and then break out the windows of the other car and steal it, according to police in the Detroit suburb.

"Officer Lulko found the partially eaten pastry in the car and sent it to the Michigan State Police crime laboratory with hopes that the DNA left on the roll could lead to the identity of the perpetrator," Detective Eric Keiser told The Macomb Daily of Mount Clemens. As a convict, Wheeler's DNA was on file, leading to the match and arrest.



I've gotta figure out how I can use this. Looks nteresting!

http://www.bespacific.com/mt/archives/014657.html

April 24, 2007

LC Global Legal Monitor, March 2007 Issue Now Available

LC Global Legal Monitor, March 2007 Issue Now Available



Amusing, but expected. Would a true businessman fire these lawyers?

http://techdirt.com/articles/20070424/154747.shtml

RIAA Seriously Smacked Down (Again) By Judge

from the worth-reading dept

The RIAA's track record in court hasn't been so great lately. After being forced to drop various lawsuits once it was pointed out to the RIAA that the suits were targeted incorrectly, the RIAA has tried (and failed) to get out of paying the legal fees of those they incorrectly sued. The latest ruling comes from a judge who already told the RIAA it needed to pay fees. Now he's reaffirmed the decision and explained it quite clearly to the RIAA. The quotes are absolutely worth reading at that link, as the judge highlights the fact that copyright isn't solely for the benefit of the content creator/owner, but for enriching the public domain, and that gives anyone accused of infringement strong defenses to their use of the content.

The judge also challenges a bunch of questionable or misleading claims by the RIAA, basically suggesting that the RIAA was assuming he wouldn't actually look into any of its claims. For example, the RIAA filing claimed that there were no "reported" cases where attorney fees were awarded without using a specific test, but the judge looked around and quickly found that there were many unreported cases, including ones against the exact same plaintiff. So the claim my be truthful that there were no "reported" cases, but ultimately misleading. Trying to trick a judge that way doesn't tend to end well. Also, rewriting history doesn't work well, as the judge points out the RIAA tried to do in claiming that it had offered the defendant a way to settle without paying anything. As the judge says: "Of course, that is not true. By the time the plaintiffs offered to dismiss their claims against the defendant, she had made a considerable litigation investment, and would have been required to pay those expenses already incurred. Furthermore, the plaintiffs offered merely to dismiss their claims without prejudice, thus leaving the defendant exposed to continued litigation in the matter." There's a lot more like that in the decision, including the judge pretty much slapping the RIAA down for suggesting that it may have won the case anyway... It's nice to see judges are recognizing the real issues in these cases.



Good news, bad news. If it works, don't worry about the perception. If it doesn't work, why even bring up perceptions – are you asking to take it covert?

http://www.abcnews.go.com/Politics/wireStory?id=3071482

Pentagon intel chief seeks end to TALON database

Apr 24, 2007 — WASHINGTON (Reuters) - The Pentagon's new intelligence chief has asked U.S. Defense Secretary Robert Gates to terminate the controversial military database known as TALON that tracks suspicious activity around U.S. bases, according to a memo obtained by Reuters on Tuesday.

James Clapper, U.S. undersecretary of defense for intelligence, said in an April 18 memo the program should end due in part to its image in Congress and the media.

"I have assessed results of the TALON program during the last year and I do not believe they merit continuing the program as currently constituted particularly in light of its image in the Congress and the media," Clapper said in a memo to Gates.

TALON is a database of raw reports of possible threats to U.S. military bases. It contains thousands of records of suspicious activities around bases that could involve terrorist threats, including information about some U.S. citizens.

After press reports in 2005, the Pentagon said the database included reports on peaceful civilian protests and anti-war demonstrations that should have been deleted from the collection. The Pentagon said the reports were added inadvertently and it later changed procedures and added safeguards to keep reports on U.S. civilians out of the system.



Just a note on the passing of the paper report.

http://www.bespacific.com/mt/archives/014661.html

April 24, 2007

FERC Announces No More Printed Copies of the Federal Energy Guidelines

"The Federal Energy Regulatory Commission (FERC) has informed GPO that they are discontinuing printed copies of the Federal Energy Guidelines, including FERC Reports and FERC Statutes and Regulations on April 30, 2007. The Commission's official issuances and decisions will be made available to the public and the FDLP through eLibrary, the Commission's Electronic records Management system - available on the Commission's Website. The affected classes and item numbers are: E 2.17: FERC Reports; 0438-C and E 2.18: FERC Statutes & Regulations; 0438-C-01." [via GPO Access]



Free is good!

http://digg.com/software/Best_of_the_Best_Free_and_Open_Source_Software_Collection_OS_X_and_Windows

Best of the Best Free and Open Source Software Collection: OS X and Windows

this site literally has everything

http://www.digitaldarknet.net/thelist/index.php?page=windows

Tuesday, April 24, 2007

Ahhh, say it ain't so!

http://www.poughkeepsiejournal.com/apps/pbcs.dll/article?AID=/20070423/BUSINESS/704230333

IBM: Tapes with personal data lost

By Craig Wolf Poughkeepsie Journal April 23, 2007

Data tapes containing the names and Social Security numbers of former IBM Corp. employes have been lost, the company confirmed today.

How many, the company officials aren't saying, but they have advised all affected people by letter and assured them that the data tapes were lost rather than stolen and that there has been no indication that any of the data has been used by anyone improperly.

The incident occurred Feb. 23 when a vendor transporting data lost them in Westchester County, spokesman Fred McNeese said. The names are of former IBMers and some who came back later to work at IBM.



Just going down their checklist of “things we haven't screw up yet”

http://www.washingtonpost.com/wp-dyn/content/article/2007/04/22/AR2007042201362_pf.html

FEMA's 'Unfortunate' Privacy Disaster

By Al Kamen Monday, April 23, 2007; A15

Sometimes when they are not busy dealing with natural disasters, FEMA folks just make up their own. We got this letter the other day from Glenn M. Cannon, assistant administrator in the Disaster Operations Directorate.

"Dear Disaster Generalist," he wrote to about 2,300 people on April 16, "an unfortunate administrative processing error at FEMA . . . has resulted in the printing of Social Security numbers on the outside address labels of Disaster Assistance Employee (DAE) . . . reappointment letters."

... Once it figured out what happened, FEMA sprang into action. Everyone affected will get "identity theft protection for one year free of charge," Cannon said.

But wait! That's not all! "Each affected [employee] will receive a personal telephone call to apologize and explain the actions FEMA will take to minimize the impact," he said. And from now on employees will be given personal identification numbers so the agency won't need to use Social Security numbers.



So we should increase the numbers when they tell us they notified nnnn people?

http://www.pogowasright.org/article.php?story=20070423100227921

Institutions only notify 62 percent of identity theft victims, Assistance Center reveals

Monday, April 23 2007 @ 10:02 AM CDT - Contributed by: PrivacyNews - Breaches

It came as a surprise to see that only 62 percent of identity theft victims are notified by financial institutions, according to the Identity Theft Assistance Center (ITAC) in Washington DC.

... In a survey conducted by the non-profit group, ITAC found that 38.4% of those poled (sic) who were victims of identity theft said they were notified by their financial services company. Another 23.3% said they were notified by another financial services company.

Source - Axcess News



I gotta take that “English as a second language” course...

http://business.guardian.co.uk/story/0,,2064181,00.html?gusrc=rss&feed=24

GM subsidiary paid conman for 'blagged' private data, court told

Rob Evans and David Leigh Tuesday April 24, 2007 The Guardian

Debt collectors linked to General Motors and private equity firm Cabot Square Capital were named yesterday in a court case over the black market in private information stolen from government databases.

A private investigator used by companies chasing vehicle hire purchase and bank debtors was convicted at Kingston magistrates court in south-west London. Nicholas Munroe, 32, of west London, conned civil servants into giving home addresses of more than 250 people over the phone. He was convicted of 44 offences of stealing and selling private data in a prosecution brought by Richard Thomas, the information commissioner, and fined £3,200 plus £5,000 costs.

GM subsidiary paid conman for 'blagged' private data, court told

The companies say they told the private investigator at the time not to break the law.

In a practice known as "blagging", conmen trick employees in banks, call centres and government departments into disclosing private details such as addresses or details of bank accounts, tax returns and mortgages. The blaggers often pretend to be from another section and use jargon and knowledge of computer systems to sound plausible. Prosecutions by Mr Thomas have shown that City law firms and national newspapers have used blaggers.

Mr Thomas has persuaded ministers that jail terms are needed to stamp out the trade and wants to prosecute companies that buy the information.


Ditto


http://www.smh.com.au/news/tv--radio/porn-and-privacy-big-brothers-big-bother/2007/04/23/1177180545710.html

Porn and privacy: Big Brother's big bother

David Braithwaite April 23, 2007 - 4:22PM

First it was porn, now it's privacy - a technical stuff-up on reality show Big Brother's website is said to have exposed the personal details of fans who signed up for its special features.

... Last Friday, Behind Big Brother revealed the official site was not using encryption technology on its credit card sign-up page, exposing users to having their details intercepted.

... Big Brother fans have to pay using a credit card to view the site's "premium content". However, the login and registration links on the official site have been disabled due to the security issues.

... Despite its tech staff being alerted to the privacy problem last night, Network Ten was still "looking into" it, a spokeswoman said.



Comments?

http://blogs.csoonline.com/personal_data_exposed_how_can_we_fix_this_mess

Personal data exposed! How can we fix this mess?

Submitted by Mintz Levin on Thu, 2007-04-19 21:55.

Part of the reason that business is interested in the implementation of a federal consumer data breach notification law is that there is currently a crazy quilt of state legislation -- 38 states and counting -- and compliance is difficult. Here are two perspectives on what “should” be included in a federal data breach notification law. What is your perspective? How would you define these elements at a federal level? Should a federal law be overly inclusive? Should encryption be a “safe harbor”?



Big day for reports

http://www.pogowasright.org/article.php?story=20070423163056550

Privacy and Civil Liberties Board Report Issued

Monday, April 23 2007 @ 04:55 PM CDT - Contributed by: PrivacyNews - Fed. Govt.

The Privacy and Civil Liberties Board has issued its First Annual Report to Congress:.

Privacy and Civil Liberties Oversight Board: First Annual Report to Congress March 2006 – March 2007 [PDF]

PogoWasRight.org Editor's note: In reading the report and their findings, note carefully this paragraph on p. 6 (footnotes omitted):

"As shown in the Board’s location, assigned roles, and authority, IRTPA did not create an independent watchdog entity in the nature of an inspector general. Rather, the statute created a Board that operates within the Executive Office of the President and ultimately reports to the President. The statute requires the Board to produce an annual report to Congress only “on [its] major activities” – not on all of its internal deliberations and recommendations. The statute expressly places the Board within the Executive Office of the President (EOP), an office whose sole purpose is to support the Executive. Consistent with that placement and with the goal of offering candid advice, the President has located the Board even more closely to him by placing it within the White House Office (WHO). As the statute explicitly acknowledges, all five Board Members (like other EOP and WHO employees) serve at the pleasure of the President."



Another report...

http://www.pogowasright.org/article.php?story=20070423124721515

CDT Unveils Draft Identity Principles

Monday, April 23 2007 @ 12:47 PM CDT - Contributed by: PrivacyNews - Other Privacy News

From CDT.org: As information-gathering technology improves and governments seek to bolster their capacity to identify individuals, questions surrounding how to manage individual identity have mounted. CDT today officially unveiled its draft Privacy Principles for Identity in the Digital Age, which seek to address those issues in a way that takes into account privacy, security, as well as the broader issues associated with identity. CDT Deputy Director Ari Schwartz discussed the principles at the Federal Trade Commission workshop "Proof Positive: New Directions for ID Authentication."

Privacy Principles for Identity in the Digital Age (Draft) [PDF]



The argument continues...

http://news.com.com/2100-1029_3-6178552.html?part=rss&tag=2547-1_3-0-5&subj=news

Canada, Mexico travel cards under privacy attack

By Anne Broache Story last modified Mon Apr 23 17:03:01 PDT 2007

WASHINGTON--A forthcoming travel identification card geared toward Americans who frequently cross U.S. borders into Mexico and Canada is drawing renewed criticism.

At a Monday workshop here, privacy advocates said they were puzzled that come summertime, the U.S. Department of State, in consultation with the Department of Homeland Security, still hopes to begin issuing so-called "passport cards" embedded with radio frequency identification (RFID) chips whose data can be skimmed by readers up to at least 20 feet away.

The technology, which is similar to the passes read by highway tollbooths, is already being used in other U.S. immigration documents and programs, but that doesn't make it any less troublesome, critics said at the first day of an identification workshop hosted by the Federal Trade Commission.

... In their most recent draft rules issued in October (PDF), government officials said they're leaning against using a chip that could be read from only a few inches away because it would require vehicles to slow down and hold out cards one at a time for scanning. It was unclear when the final rules would be released.



Surveillance is so easy and so readily accepted. Trust, but verify?

http://news.yahoo.com/s/nm/20070423/od_nm/divorces_uk_investigators_dc;_ylt=Ah6WKXyBQd_G8n_8Cc9vXbXMWM0F
Use of private sleuths rising in divorces?

By Elena Moya 1 hour, 52 minutes ago

LONDON (Reuters) - Almost half of Britain's divorcing couples used a private investigator last year to confirm, or deny, their suspicions about their spouse cheating on them, accountancy firm Grant Thornton said on Monday.



The counter-trend

http://news.yahoo.com/s/ap/20070423/ap_on_hi_te/fon_time_warner;_ylt=AvjTbJ71AiMKhp3Ydllkz0LMWM0F

Time Warner customers get Wi-Fi hotspots

By JESSICA MINTZ, AP Business Writer 2 hours, 38 minutes ago



Age discrimination?

http://hardware.slashdot.org/article.pl?sid=07/04/23/2348249&from=rss

French Voting Machines a "Catastrophe"

Posted by kdawson on Tuesday April 24, @02:18AM from the nous-ne-nous-tenons-pas-dans-les- lignes dept. Input Devices Politics Technology

eldavojohn writes "The electronic voting machine has soured another election. Some French voters have reportedly turned away in disgust after facing up to two hours in lines to use the machines. Further, the article reports, 'Researchers at Paul Verlaine University in Metz said that trials on two of the three machines used in France showed that four people out of every seven aged over 65 could not get their votes recorded.' This article concentrates primarily on usability and efficiency, but surprisingly mentions little (aside from user trust issues) about the security embodied in the machines or whether it was satisfactory. I think all three aspects are important to anyone aiming to produce voting machines. The manufacturer of these particular machines is France Élection."



Good summation for those who have been asleep for the last few years....

http://www.bespacific.com/mt/archives/014648.html

April 23, 2007

President’s Identity Theft Task Force Releases Comprehensive Strategic Plan to Combat Identity Theft

Press release: "Attorney General Alberto R. Gonzales and Federal Trade Commission Chairman Deborah Platt Majoras today announced the completion of the President’s Identity Theft Task Force strategic plan to combat identity theft. The strategic plan is the result of an unprecedented federal effort to formulate a comprehensive and fully coordinated plan to attack this widespread and destructive crime. The plan focuses on ways to improve the effectiveness of criminal prosecutions of identity theft; enhance data protection for sensitive consumer information maintained by the public sector, private sector, and consumers; provide more comprehensive and effective guidance for consumers and the business community; and improve recovery and assistance for consumers."

Related Documents:

Combating Identity Theft: A Strategic Plan, Final recommendations released April 23, 2007



Sound familiar?

http://techdirt.com/articles/20070423/002025.shtml

Wait, There Are Good Internet Laws?

from the just-kidding... dept

Law professor Eric Goldman has written up an article where he wanted to list out the best and worst internet-related laws out there. Coming up with "good" ones turned out to be a challenge, with just the law banning new internet access taxes and section 230 of the CDA making the list. Of course, you could argue that the safe harbor afforded by section 230 (protecting sites from the actions of their users) is based on so much common sense that there shouldn't need to be a law to back it up. Of course, when it comes to the "bad" list, there were way too many to choose from. The DMCA makes a couple of appearances (for different parts) and there are some other blasts from the past as well. It's pretty frustrating to read through the list, in part because so many of the "bad" laws aren't just bad, but were obviously bad from when they were proposed. Lots of people have pointed out why those laws would do more harm than good, but so far, politicians don't seem interested in correcting the mistakes they made with them. They passed the laws so they could claim they stopped some "bad" thing from happening online, even if the law did no such thing. It would be nice if politicians were actually held accountable for the unintended consequences of their bad laws -- especially when those laws do little to actually achieve what they were proposed to do.

Monday, April 23, 2007

Why does this read like a Monty Python script? “We are sure that no information was taken, because we do not actually use the computers for work.”

http://www.radionz.co.nz/news/latest/200704221140/assurances_tax_info_safe_despite_mislaid_computers

Assurances tax info safe despite mislaid computers

Posted at 11:42am on 22 Apr 2007

Revenue Minister Peter Dunne says taxpayers' personal information is not at risk despite more than 100 Inland Revenue computers going missing.

The Inland Revenue Department's 2006 asset audit shows the department does not know the whereabouts of 106 computers.

The National Party says the loss is a serious breach, and the IRD must do more to safeguard taxpayers' personal information. Its state services spokesperson, Gerry Brownlee, says the IRD has no idea where the computers are, or what is on them.

The department says the figure is only 1.2% of the total number of its computers. It says the computers could be laptops [we don't know that either... Bob] that were of the office at the time of the audit, obsolete computers that have been dumped, computers that are out of use and being stored out of sight, or out for repairs.

Mr Dunne says there are strict security controls regarding access to taxpayer information, and he is confident no personal data has gone missing.

The IRD says all taxpayer information is held on a central database and it has a policy that no sensitive data is to be stored on computer hard drives.

... IRD says it does expect the number of unaccounted-for computers to decrease in future audits [because it won't be long before they are all stolen... Bob] because it is bringing in systems to track assets electronically.



Tools & Techniques: How long before someone embarrasses a politician?

http://biz.yahoo.com/bw/070420/20070420005612.html?.v=1

Montana Launches Online Access to Driver Records and Vehicle Histories at www.mt.gov

Friday April 20, 3:43 pm ET

HELENA, Mont.--(BUSINESS WIRE)--Have you ever wondered how many speeding tickets are on your driver record? Or have you been curious to know the ownership history of a pre-owned car you want to purchase? Thanks to two new online services offered through Montana's official Web site (www.mt.gov), citizens can get instant access to individual driver and vehicle histories at any time of day or night.

With the Driver History Records Service, people can search information recorded with the MVD to get individual driver history record information, including:

All reported vehicle accidents, including the date and time of the accident and the number of reported injuries due to the accident;

Any driving restrictions placed on the driver license like corrective lenses or driving at night; and

Limited personal information, including legal name, date of birth, and type of driver license -- including commercial licenses.

"This online driver history search is much more convenient for Montanans," said Dean Roberts, Motor Vehicle Division Administrator. "Prior to offering public access to this service, the process of requesting and receiving an individual driver history often took several days."

The Vehicle Search Service allows users to research the history of a pre-owned vehicle and get immediate results before purchasing the vehicle. Citizens can verify the legal owner, title history, and registration information on each vehicle.

"This is a valuable service for buyers of used cars," said Roberts. "We believe it will result in a more informed consumer, and it may also protect buyers from scams such as unknowingly buying a stolen vehicle. Previously, this service was only available to authorized users such as vehicle dealerships, insurance companies and banks."

Both search services are secure and do not include sensitive information like a home address, Social Security number, or previous driver license number. Prior to starting an online search, users will be asked to certify that they have a valid reason to request the information.



Maybe this time?

http://slashdot.org/article.pl?sid=07/04/22/1330245&from=rss

Novell Bombards SCO with Summary Judgment Motions

Posted by CmdrTaco on Sunday April 22, @10:29AM from the ratatatatat dept. Caldera Novell

rm69990 writes "Novell has filed 4 motions for Summary Judgment against SCO, which essentially ask the court to toss the remainder of SCO's case that isn't already being arbitrated between SUSE and SCO. One seeks a ruling from the court that Novell transfered none of the copyrights in Unix to SCO, which is backed up by many exhibits and declarations from people who negotiated the deal. Another, along the same lines, asks the court to toss the portions of SCO's Unfair Competition and Breach of Contract claims pertaining to the Unix copyrights. The third asks the court to rule that Novell did not violate the Technology License Agreement between SCO and Novell, and last and also least, the fourth seeks to toss the Slander of Title for the additional reason that SCO has failed to prove any special damages. These motions follow 2 motions for summary judgment filed by Novell late last year on 2 of their counterclaims."



E-Democracy: Perhaps we can set the firewall to block them?

http://hosted.ap.org/dynamic/stories/O/ONLINE_DEBATES?SITE=VALYD&SECTION=HOME&TEMPLATE=DEFAULT

Presidential Debates Set for Cyberspace

By BETH FOUHY Associated Press Writer Apr 22, 7:36 PM EDT

NEW YORK (AP) -- The 2008 presidential contenders may soon be slugging it out in cyberspace, with pioneering online-only debates being planned for early next fall, a new media partnership says.

The political blog Huffington Post, online portal Yahoo and Slate Magazine will host the debates - one for Democratic candidates, one for Republicans - sometime after Labor Day, with PBS host Charlie Rose serving as moderator, the sponsors planned to announce Monday.

Voters will be invited to submit questions, and can blog in real time to share their opinions on the candidates' answers.

Sunday, April 22, 2007

I wonder if TJX will be doing this in all 50 states?

http://www.ct.gov/dmv/cwp/view.asp?Q=335996&A=807

Consumer Alert for those Affected by the Theft of Information from TJX Companies

April 20, 2007

The Department of Motor Vehicles has been notified by TJX Companies of an incident of unauthorized access to personal information of nearly 18,000 people with Connecticut addresses. The firm advised customers to contact their local DMV office because information taken included license and social security numbers. Please be assured that all Connecticut licenses and ID cards are assigned a unique identifying number. Unlike the practice in some other states, the Connecticut driver license number is not connected in any way with your social security number. You do not need a new driver’s license.

Read what DMV is doing to protect your identity on your license. [Most interesting. Read this! Bob] The DMV is making this announcement in advance of a letter that TJX plans to re-send the week April 23, 2007, to 10,000 [Not all? Bob] of the original number of customers to advise them of additional credit protection opportunities.

.. There are also other steps you can take to protect yourself and to understand more about identity theft.

  • DMV has prepared a letter for all those affected by this unauthorized disclosure. If you would like a copy, please request it through this link.

Content Last Modified on 4/20/2007 5:39:49 PM



Note that this has not been headline news, nor has the story been picked up by other news sources.. Probably because the jokes are too self evident... Possibly because of the number of politicians named?

http://www.homelandstupidity.us/2007/04/21/astroglide-data-breach-exposes-customer-information/

Astroglide data breach exposes customer information

Special to Homeland Stupidity By Michael Hampton Posted: April 21, 2007 9:41 am

... Astroglide suffered a data breach this week. People who ordered the company’s products from their Web site from 2003 to the present may have had their names and email and shipping addresses published on the Internet.

The breach exposed information for as many as tens of thousands of Astroglide customers. The data was broken down by product and date and much of it is still available in Google’s cache. It’s not known at this time how long the information, which consisted primarily of Microsoft Excel spreadsheets and CSV formatted text files, was published online.

... Biofilm, Inc., was notified of the breach on Wednesday, and the company pulled most of the data from their Web site and placed a robots.txt file to cause search engines to (eventually) remove their cached copies of the personal data.

The breach was discovered when a person who had ordered a free sample of Astroglide searched for his own name in Google and found the Astroglide record of his request.

... This is important because aside from the thousands of records remaining in Google’s cache, a spreadsheet containing 4,529 records of people who ordered the company’s Silken Secret vaginal moisturizer product remains on Astroglide’s web site, available for download by anyone. Out of these records, 4,055 were identified as female, 472 identified as male, and two had no gender listed.



Honest! How refreshing!

http://www.eveningnews24.co.uk/content/news/story.aspx?brand=ENOnline&category=News&tBrand=ENOnline&tCategory=news&itemid=NOED21%20Apr%202007%2009%3A21%3A15%3A820

Email blunder leaves Sportspark bosses red-faced

DAN GRIMMER 21 April 2007 09:19

Bosses at the University of East Anglia Sportspark were forced to apologise after a member of staff accidentally sent out every one of their customers' email addresses to more than a thousand people. [At least they didn't blame the computer! Bob]

People who use the sports venue were sent the Sportspark E-Zine previewing a forthcoming charity event, but opened it up to discover their email addresses had been shared with almost 1,200 other customers.

The person sending out the email had accidentally forgotten to hide the email addresses of all the recipients who were getting the message - so everyone sent the message could read them.

The Sportspark was accused of breaking the data protection act and one person who responded to the message said: “I am sure I will not be the only one who is upset that their email addresses can be simply given away to more than 1,100 people so cheaply.”

Upon realising the mistake, Keith Nicholls, director of physical education and sport at the Sportspark, sent out an apology.

It said: “This should not have happened and I regret any problems this may cause you. In future I have arranged that the email will be checked by a second member of staff before it is sent.”



Write the law, then gather some facts. What's wrong with this picture?

http://www.reuters.com/article/governmentFilingsNews/idUSN1933708420070419

House panel approves anti-spyware bill

Thu Apr 19, 2007 7:59PM EDT

WASHINGTON (Reuters) - Legislation that would help protect consumers from harmful spyware that can harvest personal data from a user's computer was approved on Thursday by a U.S. House Energy and Commerce subcommittee.

... The Energy and Commerce Committee's panel on commerce, trade and consumer protection approved the bill on a voice vote. It plans to hold a May hearing on computer data breaches at retailer TJX Cos. Inc., which recently reported information was stolen on more than 45 million credit and debit cards.



See the picture of the cute little hand-held card scanner! I want one!

http://www.gothamist.com/2007/04/21/credit_card_sca.php

April 21, 2007

Credit Card Scam at Restaurants

The Manhattan DA's office announced that thirteen people were indicted in a identity theft scam. Credit card information from diners in Chinatown and other areas (Brooklyn, Westchester, Long Island, Florida, New Hampshire, New Jersey, and Connecticut) would be stolen by wait staff, using handheld credit card skimmers. A list of restaurants where the scam took place was not released.

One defendant, JD Kenny, would pay $35-50 per skimmed card information, [Outrageous! They should only cost $12 per... Bob] and then use that information to create fake cards. Then, another group of people were enlisted to use the fake cards and buy "high-end electronics merchandise – such as laptop computers, Sony Play Stations, GPS navigation systems, high-end digital cameras and IPods." The DA's office says each "shopper" was expected to make $1,000 of purchases per card; another defendant, Li-Chieh Pao, would pay the shopper 15% of the items' retail values and then sold the goods to stores in Queens.

This is not the first time restaurant workers have been known to skim credit card information - this happened at Tenement in 2005 and at Les Halles last year.



I wonder if my blog could aspire to such greatness?

http://www.boingboing.net/2007/04/21/mayor_of_boston_bans.html

Saturday, April 21, 2007

Mayor of Boston bans Boing Boing

Jake tried to access Boing Boing from Boston's free WiFi network and got this notice -- topped by the seal of the Mayor of Boston no less! Banned in Boston -- first they came for the Mooninites, then they came for the Boingers.

Want to defeat censorware? Let freedom ring!

Update: Seth sez, "The phrase 'Banned combination phrase found' is a characteristic message of the censorware Dan's Guardian. It seems some combination of words has triggered the 'isItNaughty' flag (that's what they call it). It would be an interesting legal case to see if you had the right to file a Freedom Of Information Act for the settings and block logs to find out the exact reason you got censorware'd."



I read these because I'm still trying to develop a “General Theory of Privacy,” (P=MC2) which has to include rules for disclosure...

http://www.bespacific.com/mt/archives/014620.html

April 20, 2007

Paper Addresses Consent for Disclosures of Health Records

Robert Gellman, Privacy and Information Policy Consultant: Consent for Disclosures of Health Records: Lessons from the Past (PDF), ver. 1.2, April 17, 2007. This paper addresses issues specific to the Maine health privacy law.



Yes it was the software. It wrote itself, then it failed to test itself. Fortunately it didn't blame the humans. Bad software!”

http://cbs2chicago.com/topstories/local_story_110224943.html

Software Blamed For Chicago Teachers' Checks Snafu

Flitches In New $19 Million Payroll Software Left Some Teachers Without Checks Friday

(CBS) CHICAGO The Chicago Teachers Union is giving the school system an "F" for payroll management.

Some teachers didn't get paid Friday and others got shortchanged.



Consider me paranoid, but doesn't this have e-Discovery implications?

http://it.slashdot.org/article.pl?sid=07/04/21/1257249&from=rss

Digital Media Archiving Challenges Hollywood

Posted by CowboyNeal on Saturday April 21, @09:14AM from the taping-over-m*a*s*h-reruns dept. Movies Data Storage IT

HarryCaul writes "Movies are moving to digital, but what about long-term archiving of the master source materials? Turns out it's harder for digital media than for contemporary analog. Data is being lost, and studios have to learn to cope. Phil Feiner of the AMPAS sci-tech division says when he worked on studio feature films he 'found missing frames or corrupted data on 40% of the data tapes that came in from digital intermediate houses' How to deal with it? Regular migration from old media to new media. Grover Crisp, says Sony has put in a program of migrating every two to three years. Other studios are following suit, but what about indie features? Will we lose films like we lost the originals of the 20s?"



Okay, perhaps security at nuclear reactors isn't all that it could be...

http://www.ncr-iran.org/content/view/3257/152/

Former Engineer Accused of Taking Nuclear Power Plant Codes to Iran

Saturday, 21 April 2007

AHN global news - Federal official are accusing a former U.S. engineer of taking security codes from the nation's largest nuclear power plant to Iran, reports say.

Mohammed Alavi, 49, is accused of downloading training materials and access codes from the Palos Verde Nuclear Generation Station to his computer while he was on a trip in Tehran, Iran.

According to published reports, Alavi was charged with violating a trade embargo law that forbids Americans from offering goods or services to Iran.

Alavi, a U.S. citizen, was reportedly visiting Iran to set up a new home and life for himself. He quit his job at Palos Verde in August after working 16 years, but still had access to some security codes. [Seems like that procedure isn't working. Bob]

The software Alavi allegedly used to download Palos Verde material allowed access to the power plant's layout and control rooms. Alavi reportedly used a Palos Verde user's identification to download the material.

It was reported that there was no security risk posed nor was the breach linked to the Iranian government. Federal officials feared that potential danger could arise if the access codes were placed in the wrong hands.

... Palos Verde employees learned of Alavi's arrest and charge on April 21, when security procedures were changed.



Talk about your “high value” targets!

http://www.webware.com/8301-1_109-9711121-2.html

BuyYourFriendADrink update: It works!

By Caroline McCarthy – April 20, 2007, 12:48 PM PDT



Perhaps the best idea is: take a floppy to Kinkos?

http://hardware.slashdot.org/article.pl?sid=07/04/21/1331248&from=rss

Is Your Printer Ripping You Off?

Posted by CowboyNeal on Saturday April 21, @11:16AM from the or-only-its-maker dept. Printers Hardware

An anonymous reader writes "Are original inkjet cartridges really worth the high cost? Do third party refill inks do as good a job? This article looks at printers from Epson, HP, Canon and Lexmark, with a combination of original inks and the top selling third-party options, using a whole host of different papers. A panel of printer users judged the output in a blind test — the printer manufacturers may not be happy with the results!"



I suspect there will be many sites like this, with extreme specialization. (Eye color in female Shad in the Delaware river, upstream of Trenton NJ during the full moon...)

http://www.researchbuzz.org/wp/2007/04/21/science-information-video-style/

Science Information, Video Style

Thanks to reader KM for pointing me toward VideoLectures.net ( http://videolectures.net/), a collection of over two thousand videos related to science. It’s currently in beta and looks like it covers a variety of topics, from Web technologies to translation tools to math to logic.

... Click on a video and you’ll get a page for the video and a brief description as well as a list of related videos (”The people who watched this video also watched…”) You’ll have the opportunity to leave comments as well. Click on the thumbnail to start the video. Some lectures are set up as a series of videos.

... These are lectures; all the videos I looked at were well at least an hour.



Fun! An Origami simulator?

http://jrc313.com/processing/cloth/index.html

Cloth Simulation

I happened across this rather nice spring physics library for Processing, so I thought I'd try making a simple cloth simulation to see what it was capable of. Turns out it's really easy to use and works exactly as advertised. I think it's time for a little more experimentation.



I'm not fluent, but is this correct?

http://www.bespacific.com/mt/archives/014628.html

April 20, 2007

Election Assistance Commission Provides Spanish Language Glossary of Election Terms

Press release: "The U.S. Election Assistance Commission (EAC) today voted to adopt a glossary that provides a translation of key election terms from English to Spanish and from Spanish to English. The glossary is available at www.eac.gov and EAC will distribute copies to jurisdictions throughout the nation."

Spanish Language Glossary of Election Terms

[Somehow, this seems wrong...

Democrat: demócrata

Republican: mal personificado

...Yes, it's a joke, Bob]