Tuesday, August 28, 2007

Does this seem high to you?

http://www.theage.com.au/news/web/onein10-aussies-victims-of-id-theft/2007/08/28/1188067100796.html

One-in-10 Aussies victims of ID theft: report

Asher Moses August 28, 2007 – 4:40PM

Almost 2 million Australians have had their personal details stolen and used fraudulently by a third party, according to a report released today by the Office of the Privacy Commissioner, which highlights the internet as a growing privacy pain point.

The report found only 17 per cent of Australians trusted online businesses to handle their personal information responsibly, compared with 37 per cent for regular retailers, 73 per cent for government departments and 91 per cent for health service providers.

... Another survey released this month by Newspoll, which questioned 1202 people, found Australians were more concerned about the misuse of their personal information than national security in relation to war or terrorism.

... Half of the respondents were more concerned about giving personal information over the internet than they were two years ago, while 45 per cent believed ID theft was likely to occur as a result of using the internet.

... She said the laws got the balance right as her office received only 1100 privacy-related complaints a year, but acknowledged Australia's privacy laws were based on guidelines that were more than 30 years old - the International Covenant of Civil and Political Rights and the OECD Privacy Guidelines.

... She said the Australian Law Reform Commission would release its draft report discussion paper containing recommendations on changes to privacy laws in the middle of next month, which she expected would be 1200 pages long.

Among the report's other findings were that 65 per cent of Australians were more concerned about providing details online than in hard copy format and 25 per cent said they gave false information in online forms as a way of protecting their privacy.

[Reporsts are available here: http://www.privacy.gov.au/business/research/index.html ]



Interesting reaction... (Also the burden of e-Discovery just got bigger)

http://news.com.com/8301-10784_3-9767300-7.html?part=rss&subj=news&tag=2547-1_3-0-5

Court decides RAM is stored information in TorrentSpy case

Posted by Greg Sandoval August 28, 2007 2:59 AM PDT

A federal judge issued a decision on Monday that would have required TorrentSpy, a BitTorrent search engine, to hand over information about its users had the company not ceased operating in the U.S. a day earlier.

TorrentSpy, accused of encouraging movie piracy in a lawsuit filed by the film industry last year, was ordered in June to provide the studios with user information found in the company's computer RAM. The site, which can help people find bootleg films, had long promised to protect the anonymity of visitors.

TorrentSpy filed an appeal and argued that data in a computer's RAM was too temporary to be considered "stored information," and that it was impractical for companies to produce such material as part of a civil suit. According to court documents, the judge on Monday denied TorrentSpy's appeal.

"The court holds that data stored in RAM, however temporarily, is electronically stored information," wrote U.S. District Judge Florence-Marie Cooper in her 18-page decision.

Ira Rothken, TorrentSpy's attorney, said that as far as the court order goes, if the company isn't doing business in the U.S. there isn't any U.S. records to turn over. Nonetheless, Rothken said TorrentSpy plans to continue the court fight by filing a new appeal with the 9th Circuit.

... While the court's decision may have little impact on TorrentSpy--now that the company has ceased doing business in the U.S.--it could mean a great deal to scores of other companies, according to some experts.

Ken Withers, a legal scholar with the think tank, Sedona Conference, said shortly after TorrentSpy was ordered to turn over user information in June that he feared court's were creating "weapons of mass discovery" and expanding the scope of discovery too far.



An interesting variation on the 'social networking' sites...

http://www.gigalaw.com/news/2007/08/men-arrested-in-japan-after-using-crime.html

Men Arrested in Japan After Using "Crime Mates" Site

Three men who met on an Internet site that matches up criminals were arrested after battering a woman to death and abandoning her body in a forest, police and Japanese media said. The three arrested men swapped details on a "crime mates" site through their mobile phones, Kyodo news agency reported, and agreed to kidnap a 31-year-old office worker as she walked home.

http://www.reuters.com/article/internetNews/idUST28582520070827



well... we gotta blame someone!

http://news.zdnet.com/2100-1009_22-6204295.html

Discover security breach, blame the co-workers?

By Tim Ferguson, Silicon.com Published on ZDNet News: Aug 24, 2007 5:37:00 AM

IT managers in small and midsize businesses blame their fellow workers for online security breaches--despite the fact many small enterprises still don't enforce Web usage policies.

More than a fourth of European IT managers in small businesses said they believe that company employees are responsible for security problems, according to research commissioned by security software company Websense.

The most frustrating problem for IT managers is employee behavior (cited by nearly a third of managers), followed by security not being high enough on the corporate agenda and then budget constraints.

The survey found that nearly a third of employees said they need to access sites known to present a high security risk, such as peer-to-peer services and free software-downloading sites.

... The survey also reveals that 23 percent of small to midsize companies have Web security policies but don't enforce them among their employees. Another 16 percent of smaller enterprises have no Web usage policy at all, preferring to trust employees to not put them at risk.



Always some good stuff...

http://www.bespacific.com/mt/archives/015830.html

August 27, 2007

New on LLRX.com for August 2007



This is very interesting. I wonder if we could hold them to these principles? (Yeah, silly question. It uses 'hold' and 'politician' in the same sentence.)

http://www.fcw.com/article103603-08-27-07-Web

OMB, CIO Council issue architecture principles

BY Jason Miller Published on Aug. 27, 2007

The Office of Management and Budget and the CIO Council released today a new framework that underpins many of the Bush administration’s core management tenets.

... The principles include:

The federal government focuses on people.

The federal government is a single unified enterprise.

Federal agencies collaborate with other governments and people.

The federal architecture is mission-driven.

Security, privacy and protecting information are core government needs.

Information is a national asset.

The federal architecture simplifies government operations.



Consolidation or the transfer of technology leadership?

http://politics.slashdot.org/article.pl?sid=07/08/27/2156231&from=rss

Lenovo Looking to Buy Seagate, May Raise Political Concerns

Posted by Zonk on Monday August 27, @07:22PM from the this-is-what-we're-worried-about dept. Businesses Data Storage Politics Hardware

andy1307 writes "According to an article in the New York Times, Lenovo has expressed an interest in buying Seagate. This has raised concerns among American government officials about the risks to national security in transferring high technology to China. From the article: 'In recent years, modern disk drives, used to store vast quantities of digital information securely, have become complex computing systems, complete with hundreds of thousands of lines of software that are used to ensure the integrity of data and to offer data encryption.'"


...or perhaps Taiwan just wants to stifle the mainland?

http://www.infoworld.com/article/07/08/27/Lenovo-plan-for-Packard-Bell-hit-by-Acer-Gateway-deal_1.html

Lenovo's plan for Packard Bell hit by Acer-Gateway deal

Acer just might end up owning both Gateway and Packard Bell

By Sumner Lemon and Dan Nystedt, IDG News Service August 27, 2007

Acer's agreement to acquire Gateway has foiled Lenovo Group's plans to buy PC vendor Packard Bell, and could leave Acer owning both Gateway and Packard Bell.

On August 7, Lenovo revealed it was in discussions with Packard Bell over a possible acquisition. At the time, it looked like Lenovo had beaten Acer, which was also interested in acquiring the company.

However, Acer's plan to buy Gateway for $710 million, announced Monday, trumps anything Lenovo brings to the table in its negotiations with Packard Bell.

In 2006, Gateway signed an agreement with John Hui, Packard Bell's largest shareholder, that gives Gateway the right of first refusal if he decides to sells PB Holding Co. SARL, the parent company of Packard Bell.

What that means is that if Packard Bell wants to enter into a final agreement to be purchased, the company has to ask Gateway first, said Y.T. Du, of Citigroup Global Markets, which represented Acer in the negotiations. Gateway can refuse the deal if it wants and enter into purchase talks with Packard Bell, he said.

That is exactly what Gateway has done, announcing plans to exercise its right of first refusal at the same time the Acer deal was unveiled.

The agreement between Hui and Gateway is rooted in Gateway's 2004 acquisition of eMachines, a PC vendor that Hui founded. When Hui acquired his stake in PB Holding, he granted the right of first refusal to Gateway in exchange for the company waving parts of the noncompete agreement that Hui signed when eMachines was sold.

Now that Gateway has entered into talks to acquire PB Holding from Hui, Acer could end up owning both Gateway and Packard Bell. While a Packard Bell acquisition would increase Acer's market share in Europe, a deal also means Acer will face having to integrate two companies with its existing operations instead of only one.

"Acer is still really strong in Europe," said Bryan Ma, director of personal systems research at IDC Asia-Pacific. Ma worried that Acer's desire to acquire Packard Bell is driven more by a desire to slow Lenovo's growth in Europe, rather than a pressing need to strengthen its own position there.

A Lenovo spokeswoman was not immediately available to comment.



Opinions vary... See next article.

http://www.infoworld.com/article/07/08/27/Unlocking-iPhone-could-invite-DMCA-suit_1.html?source=rss&url=http://www.infoworld.com/article/07/08/27/Unlocking-iPhone-could-invite-DMCA-suit_1.html

Unlocking the iPhone could invite DMCA suit

Intellectual property lawyers split over consequences for users who unlock their iPhones, but agree that trying to sell those secrets likely to lead to legal troubles

By Grant Gross, IDG News Service August 27, 2007

Hackers who unlock Apple's iPhone from the AT&T network and share the method with 10 million of their closest Internet friends are inviting a lawsuit from the two companies, several intellectual property (IP) lawyers said Monday.


...so who is right?

http://techdirt.com/articles/20070827/111009.shtml

iPhone Supposedly Gets Unlocked, AT&T Apparently Freaks Out

from the on-what-grounds dept

There were several reports last week that the operator lock on the iPhone had been broken, meaning that people might be able to use the device with service from a company other than AT&T. The first to emerge was from a New Jersey teenager, who came up with a complex method involving soldering and software; then two separate companies later said they had software-only unlocking methods. To be sure, these unlocking methods and services will only ever appeal to a small number of users, as most general consumers won't really care, or won't want to go to the trouble. With that in mind, it really doesn't seem like AT&T has much at stake financially, but that apparently hasn't stopped its lawyers from threatening one of the software providers. The company claims it got a call from a law firm representing the company, tossing around things like copyright infringement and "illegal software dissemination" in what appears to be an attempt at intimidating the company to keep them from releasing the software (particularly since the DMCA doesn't cover phone unlocking). It's worth reiterating that these are supposedly AT&T's lawyers, not Apple's -- but it's not clear what standing AT&T would have to sue, making this look like little more than a SLAPP situation. Apple's remained quiet on the matter, but it wouldn't be surprising to see the company close the loophole or re-lock the phones with one of its software updates, [Would the customer then have a cause of action? Bob] since it has a financial stake in iPhone buyers activating and using their phones on AT&T thanks to its revenue-sharing deal with the operator. Of course, it could take the more enlightened view that it doesn't want to frustrate and annoy the customers who would go to the trouble of unlocking their iPhones -- but if it were going to do that, it wouldn't have locked the device to AT&T in the first place.


...or maybe they're all nuts.

http://www.businessweek.com/technology/content/aug2007/tc20070827_230698.htm

Why Apple Can't Stop iPhone Hackers

AT&T and Apple may face an uphill battle prosecuting hackers that untether the iPhone from the AT&T wireless network

by Olga Kharif August 28, 2007, 12:01AM EST

... Individual users are already allowed to unlock their own phones under an exemption to the Digital Millennium Copyright Act (DMCA) that the U.S. Copyright Office issued last November. The exemption, in force for three years, applies to "computer programs…that enable wireless telephone handsets to connect to a wireless telephone communication network, when circumvention is accomplished for the sole purpose of lawfully connecting to a wireless telephone communication network."

What's less clear is whether companies and hackers can legally unlock the phones and then sell them to others, or sell unlocking software.



Interesting thought...

http://gigaom.com/2007/08/27/google-phone-an-attempt-to-take-on-100-pc/

Google Phone An Attempt To Take On $100 PC?

Written by Om Malik Monday, August 27, 2007 at 10:53 AM PT

Google Phone has been a subject of many rumors lately. Mark Hopkins, a technology podcaster, says he got the confirmation of the Gphone after talking to an insider Google.

He said that the Google (applications) Suite is going to play a huge role in the usability of the GPhone, and the thought process behind it’s functionality is less about beating the iPhone and more about beating the $100 Laptop, which provides a huge clue behind what will be the pricing structure on this…regarding the two week timetable on it’s release, he said he could not confirm that part of the story.



Don't ya just love competition?

http://digg.com/gaming_news/Tera_Discs_To_Blow_Away_Blu_Ray_and_HD_DVD

Tera-Discs To Blow Away Blu-Ray and HD-DVD?

Tech UK is reporting a startling new disc storage technology that could end the HD war between HD- DVD and Blu-Ray: the Tera-Disc. How much data? On a 1TB disc, you could store 212 DVD-quality movies, 250,000 MP3 files or 1,000,000 large Word documents. Holy flarging snit!

http://www.gamestooge.com/2007/08/27/tera-discs-to-blow-away-blu-ray-and-hd-dvd/



New business model?

http://www.dvd-recordable.net/Article3448.phtml

Copyright Holders Hire Human YouTube Crawlers

Date Tuesday, August 14 @ 14:56:28

Google says it will implement an automated filtering system this autumn that will stop music videos and other copyrighted material from finding their way onto its YouTube site without permission. But for the work of identifying allegedly infringing material is done by humans.

The Wall Street Journal reports that a company called BayTSP has hired over 20 analysts, which it pays $11/hour and up to scour the site for its clients' material in the recently uploaded section of YouTube and a few other sites.

In some cases, they have a standing order to issue takedown notices for anything they find; in others, the analysts log allegedly infringing videos and then issue one big takedown notice consisting of hundreds of thousands of them.



Not as well handled as Tylenol, but still worth study?

http://hbswk.hbs.edu/item/5755.html

Mattel: Getting a Toy Recall Right

Published: August 27, 2007 Author: John Quelch

Executive Summary: Mattel has been criticized heavily for having to recall not once but twice in as many weeks 20 million toys manufactured in China. But Mattel also deserves praise for stepping up to its responsibilities as the leading brand in the toy industry. Harvard Business School professor John Quelch examines what Mattel did right. Key concepts include:

Mattel's recall of 20 million toys made in China was handled deftly: The CEO took personal charge of the problem.

Consumers are being empowered by Mattel's communications.

The recall Web site is a model of excellence. http://service.mattel.com/us/recall.asp

Mattel's compensation program to customers may not be sufficient.



Has potential...

http://www.researchbuzz.org/wp/2007/08/27/professor-cooks-up-news-metasearch-with-lots-of-muscle/

Professor Cooks Up News Metasearch With Lots of Muscle

27th August 2007

With two coconuts and some bamboo… sorry, wrong professor. THIS professor is Clement Yu from the University of Illinois at Chicago, and he’s come with a metasearch engine for news. What impressed me was its scope — it covers about 1800 news search engines across about 200 countries and territories. After all that it has the terribly pedantic name Allinonenews; you can try it at www.allinonenews.com.



For my web site class... Think about how this tool could manipulate image “evidence”

http://www.techcrunch.com/2007/08/27/i-want-this-in-photoshop-immediately/

I Want This In Photoshop Immediately

Michael Arrington August 27 2007

This image resizing and manipulation demonstration is sort of jaw dropping, particularly as the video goes on. The related paper, written by Dr. Ariel Shamir and Dr. Shai Avidan is available here.



Doesn't surprise me at all...

http://news.yahoo.com/s/ap/20070826/ap_on_fe_st/odd_counterfeit_bills;_ylt=Aig1Ye0gMLGbkLTnzRRwUVqs0NUE

Fake money doesn't fool Tenn. strippers

Sun Aug 26, 2:18 AM ET

SMYRNA, Tenn. - A man who authorities say used his computer to make fake $100 bills to buy lap dances at a strip club has pleaded guilty to counterfeiting charges, federal prosecutors said.



Dilbert on the consequences of bad contracts...

http://www.unitedmedia.com/comics/dilbert/archive/images/dilbert2045830070828.gif

Monday, August 27, 2007

Okay, Bioshock is clean but Sony rides again! Class Action lawyers take a number please!

http://www.f-secure.com/weblog/#00001263

Double Whammy! Another Sony Case (And it's Not BioShock)

Posted by Mika @ 10:58 GMT Monday, August 27, 2007

Hypothetical: Imagine that you visit your local mall and browse around for stuff to buy. And you decide to buy a new CD from your favorite artist and you also buy a brand new cool USB stick thingy on an impulse. You go home and stick the CD into your laptop's CD drive. It prompts you to install some software. You do so and while you are listening to the music, you open the USB stick package and start experimenting with your new toy. It has a fingerprint reader so you install the software for that as well. Guess what… you might have just installed, not one, but two different rootkit-like software on your laptop.

We received a report that our F-Secure DeepGuard HIPS system was warning about a USB stick software driver. The USB stick in question has a built-in fingerprint reader. The case seemed unusual so we ordered a couple of USB sticks with fingerprint authentication. We installed the software on a test machine and were quite surprised to see that after installation our F-Secure BlackLight rootkit detector was reporting hidden files on the system.

... This USB stick with rootkit-like behavior is closely related to the Sony BMG case. First of all, it is another case where rootkit-like cloaking is ill advisedly used in commercial software. Also, the USB sticks we ordered are products of the same company — Sony Corporation.

... Note that over the weekend there was news about a suspected rootkit in the PC version of the game Bioshock. This news proved not to be true, but since BioShock apparently uses copyright protection software made by Sony there was lots of initial commotion.



Unusual for attacks to have a geographic relationship

http://www.pogowasright.org/article.php?story=20070826084116741

Central Indiana has been hit by identity theft in recent months

Sunday, August 26 2007 @ 08:41 AM CDT Contributed by: PrivacyNews News Section: Breaches

This year, several Indiana universities, including Goshen College and Notre Dame and Purdue universities have suffered various kinds of security breaches.

Source - Reporter-Times



Because I'm too lazy to list them all...

http://www.pogowasright.org/article.php?story=20070826184434981

Data “Dysprotection:” breaches reported last week

Monday, August 27 2007 @ 05:30 AM CDT Contributed by: PrivacyNews News Section: Breaches

A recap of incidents or privacy breaches reported last week for those who enjoy shaking their head and muttering to themselves with their morning coffee.

Source - Chronicles of Dissent



Sure you've worked here for 29 years, but we don't know who you are!

http://www.pogowasright.org/article.php?story=20070827052711572

IE: Fury over roll-out of biometric testing for hotel staff

Monday, August 27 2007 @ 05:27 AM CDT Contributed by: PrivacyNews News Section: Non-U.S. News

THE national privacy watchdog has expressed concern at the growth in 'Big Brother'-style clock-in systems that read workers' physical data after another hi-tech attendance procedure was launched at a major hotel.

Ireland's Data Protection Commissioner Billy Hawkes issued his warning after it emerged that the Gresham Hotel in Dublin is the latest employer to introduce a 'biometric' system. Workers claim they were not consulted about the introduction of the system that reads handprints.

Source - Independent.ie



Interesting thought, but the banks would hate it...

http://www.pogowasright.org/article.php?story=20070826180822165

Hoofnagle: Identity Theft: Making the Known Unknowns Known

Sunday, August 26 2007 @ 06:08 PM CDT Contributed by: PrivacyNews News Section: Breaches

Abstract of article:

There is widespread agreement that identity theft causes financial damage to consumers, lending institutions, retail establishments, and the economy as a whole. Surprisingly, there is little good public information available about the scope of the crime and the actual damages it inflicts. The publicly available data on identity theft come mainly from survey research. Methodologically, these survey polls of the public suffer from being both under and over-inclusive in measuring the problem. As a result, low estimates attribute tens of billions of dollars in costs to the economy and consumers, the highest estimates place losses in the hundreds of billions.

To identify proper interventions and appropriately allocate resources we need comprehensive, hard data on the scope and effect of identity theft. One way to provide concrete data is to require lending institutions to publicly report figures on identity theft. Such public reporting will help identify the relative need for intervention and the likely efficacy of interventions. These disclosures are necessary to provide a sound baseline for investment by businesses and action by regulators. They are also warranted because the public pays the price of identity theft directly when they are the victim, and indirectly through higher fees, interest rates, and because the losses are tax subsidized.

The author hypothesizes that if lending institutions reported limited information about identity theft, it would reveal that identity theft is both more prevalent and economically damaging than currently acknowledged, in part because of the rise of synthetic identity theft, a form that cannot be measured by victim surveys because they are unaware of the crime. Furthermore, the disclosure requirement would birth an anti-identity theft market, and the prevalence and severity of the crime would decrease dramatically as institutions compete to offer the safest financial products to consumers.

Source - Download Full Article (free reg. req.)

(Props CL&P Blog)



It's an idea!

http://www.pogowasright.org/article.php?story=20070826175035673

NZ: Events & Materials for Privacy Awareness Week, 26 August-1 September 2007

Sunday, August 26 2007 @ 05:50 PM CDT Contributed by: PrivacyNews News Section: Non-U.S. News

Events planned are: Monday, 27 August - Computer Society, Auckland; Tuesday, 28 August - Privacy & Technology in the 21st Century Forum (registrations full, except for media); Wednesday, 29 August - Computer Society, Christchurch; Thursday, 30 August new case notes; National Community Law Centres' hui, Auckland; Friday, 1 September privacy officers' training requirements Check out our quiz.

Source - Privacy Commissioner's Site



Like Animal House – We're on “Double Secret Probation” “Unlimited bandwidth means what we say it means...”

http://yro.slashdot.org/article.pl?sid=07/08/27/0040220&from=rss

Comcast Cuts Off Users Who Exceed Secret Limit

Journal written by SEWilco (27983) and posted by kdawson on Monday August 27, @02:22AM

from the we-won't-tell-you-and-we-won't-tell-you-why dept.

ConsumerAffairs.com has an article up spotlighting Comcast's tendency to cuts off heavy Internet users without defining in their AUP exactly what the bandwidth limit is. Frank Carreiro of West Jordan, Utah, got cut off by the mystery limit and started a 'Comcast Broadband dispute' blog.



In case someone outside the US reasoned well?

http://www.bespacific.com/mt/archives/015818.html

August 26, 2007

FLARE: Foreign Law Research

Foreign Law Research: "FLARE is a collaboration between the major libraries collecting law in the United Kingdom: Institute of Advanced Legal Studies, Bodleian Law Library, Squire Law Library, British Library, and School of Oriental and African Studies. It is working to improve the coverage and accessibility of foreign legal materials at the national level and to raise expertise in their use."



Non-obvious strategy: Why would anyone want Gateway?

http://www.infoworld.com/article/07/08/27/Acer-buys-Gateway_1.html?source=rss&url=http://www.infoworld.com/article/07/08/27/Acer-buys-Gateway_1.html

Acer to acquire Gateway for $710 million

Deal puts Acer in third spot in PC market, blocks Lenovo's intention of scooping up Packard Bell

By Sumner Lemon and Dan Nystedt, IDG News Service August 27, 2007



Worth a look!

http://www.killerstartups.com/Web-App-Tools/feedmarklet--Feed-Aggregator--Bookmarklet/

FeedMarklet.com - Feed Aggregator + Bookmarklet

FeedMarklet’s a handy tool which creates instant RSS feeds. This bookmarklet feed aggregator mashup requires no registration.



Attention L3's! (So this is what the ABA does...)

http://www.bespacific.com/mt/archives/015821.html

August 26, 2007

U.S. Supreme Court Coloring and Activity Book

"About the Book - "Have fun and learn about the Supreme Court! It's a coloring book with a surprising educational twist. This 32-page coloring book features expertly rendered illustrations depicting significant Supreme Court Justices of the United States to color in--including all current sitting Justices. The U.S. Supreme Court Coloring and Activity Book is perfect for the children of lawyers and judges, or for teachers looking for a new resource for Law Day or Constitution Day."



How my math students learn the shortcuts! (Humor)

http://soapbox.msn.com/video.aspx?vid=777094f2-a127-46f2-af96-80c8d5233bfa

Sunday, August 26, 2007

First you weigh risk against reward...” My guess is: it's not “High Reward” but rather “Low Risk”

http://www.f-secure.com/weblog/#00001262

Targeted trojan attacks against German government

Posted by Mikko @ 11:07 GMT Sunday, August 26, 2007

Yesterday Der Spiegel magazine broke the story about targeted attacks against the German ministry of the interior.

As is typical in cases like this, the malware was sent to key employees via e-mail as booby-trapped DOC and PPT files, and the stolen data was sent out to unknown location via servers located in China.

We highlighted the risk of attacks like this in our video lecture last March. The video was recorded pretty much exactly at the time when these attacks were taking place.

We are aware of at least two other similar attacks against governments in Europe.



...we agree to disagree..

http://www.pogowasright.org/article.php?story=20070825085115910

Vendors, privacy activists speak out on report

Saturday, August 25 2007 @ 11:24 AM CDT Contributed by: PrivacyNews News Section: Medical Privacy

Part two of a two-part series: An HHS-funded study on how to use electronic health-record systems as fraud fighting tools was well-received by government information technology leaders (access part one here); the 151-page report with its 14 specific recommendations got a decidedly mixed reception from IT vendors and privacy advocates.

Source - Modern Healthcare Online



I'm not certain what is going on here. Do we have a repeat of the Sony rootkit problem? Or has the rootkit moved to the mainstream? (...at least for the gaming industry?) Should we alert the Class Action lawyers?

http://digg.com/pc_games/BioShock_Installs_Rootkit_Including_Demo

BioShock Installs Rootkit, Including Demo

BioShock installs a rootkit on your computer system, which is also included with the demo.

http://www.gamingbob.com/2007/08/23/bioshock-installs-rootkit-including-demo/



Free the schoolchildren!

http://www.thelocal.se/8289/20070825/

Pupils 'should not be forced to give fingerprints'

Published: 25th August 2007 12:53 CET

Forcing schoolchildren to give fingerprints in order to get their lunches should be forbidden, the Swedish Data Inspection Board (Datainspektionen) has said.

Children at schools in the town of Lerum have to prove that they have paid for school lunches by giving their fingerprints or handprints. Once their prints have been compared with a database, a machine releases their plates.



Tools for vigilantes?

http://www.techcrunch.com/2007/08/25/sex-offenders-in-your-neighborhood/

See All Sex Offenders In Your Neighborhood

Duncan Riley August 25 2007

Vision 20/20 offers a free web based mashup of sex offender data and Windows Live Maps.

Users simply add their address, city and/ or zip code to the Vision 20/20 site, and then the locations of sex offenders in the immediate vicinity are displayed over a map. Clicking on each sex offender leads to a profile which includes the name, address, and crimes of the sex offender, as well as a mug shot.



I'm shocked! If this had been in the US, the FBI would have spent at least $840 million, and the software would never have worked, and so would never have been released!

http://yro.slashdot.org/article.pl?sid=07/08/25/1258257&from=rss

Teen Hacks $84 Million Porn Filter in 30 Minutes

Posted by CowboyNeal on Saturday August 25, @11:13AM from the worth-every-penny dept. Censorship The Internet IT

An anonymous reader writes "Tom Wood, a Year 10 Australian student has cracked the federal government's $84-million Internet porn filter in just 30 minutes. He can deactivate the filter in several clicks in such a way that the software's icon is not deleted which will make his parents believe the filter is still working. Tom says it is a matter of time before some computer-savvy kid puts the bypass on the Internet for others to use."



What drives this, I wonder?

http://digg.com/general_sciences/50_drop_in_Americans_interest_in_science_and_tech_in_past_20_years

50% drop in Americans' interest in science and tech in past 20 years

Pew has released an extensive analysis of three decades of its news consumption data. Among the key findings, since the 1980s, the percentage of the public who say they follow news about science and technology "very closely" has dropped by half. Meanwhile, the percentage of Americans who say they follow personalities and entertainment has doubled.

http://pewresearch.org/pubs/574/two-decades-of-american-news-preferences



Towards the death of cable TV?

http://go2web2.blogspot.com/2007/08/watch-full-screen-on-demand-tv-on-your.html

Friday, August 24, 2007

Watch Full Screen, On-Demand TV on Your Web Browser

tubecast.tv (alpha mode), makes a successful attempt at merging traditional (passive viewing) television broadcasting with the active nature of the web.

Essentially, this means that you can sit back, relax, and enjoy whatever is showing next on the channel of your choice. The active nature comes into play with the 'opportunity' to rewind, fast forward, pause or skip the current show.



...because I love lists like this... Note that with the success of VMWare, they are starting to add alternative Operating Systems.

http://news.com.com/8301-10784_3-9766337-7.html?part=rss&subj=news&tag=2547-1_3-0-5

August 25, 2007 12:44 PM PDT

40 great free (and sometimes open source) applications

Posted by Matt Asay

This list of 40 great freeware applications is a bit skewed to the geeks (web development tools, etc.), but it also includes some gems in the end-user application category. The list isn't restricted to open-source applications, and it misses some exceptional projects like Handbrake, but it's a respectable list.



Free is good!

http://www.researchbuzz.org/wp/2007/08/25/questia-media-releases-free-online-classics-library/

August 25, 2007

Questia Media Releases Free Online Classics Library

Filed under: Reference, Culture-Fine Arts

Questia Media has released a library of over 5,000 books for free access on its Web site. You can get started browsing at http://www.questia.com/publicdomainindex

Saturday, August 25, 2007

Let's hope that the damage doesn't escalate like it does in most data spills.

http://www.pogowasright.org/article.php?story=20070824160540873

OK: Law enforcement system breached

Friday, August 24 2007 @ 04:05 PM CDT Contributed by: PrivacyNews News Section: Breaches

Private information may have been leaked inadvertently from a statewide law enforcement computer system at three Oklahoma law enforcement agencies.

The Department of Public Safety announced Friday it discovered the first-ever security breach in the Oklahoma Law Enforcement Telecommunication System, which could put some Oklahomans at risk for identity theft.

The breach affected only the Elk City and Eufaula Police Departments and Kiowa County Sheriff's Office, Capt. Chris West said. The agency is urging anyone who has had contact with those agencies to check their credit report as soon as possible to see whether their information has been compromised.

West initially would not say in what timeframe the breach occurred or how long security had been compromised at those locations.

Source - NewsOK

[From the article:

Eufaula Police Chief Don Murray said he first learned about the problem about 11 a.m. Friday. [Same day notice? Wow! Bob]

Murray said the state provided the computer his dispatchers use to access the telecommunications system and he didn't know it was capable of doing anything else. [Not unusual. The problem is managers don't specify that they should be limited in what they can do... Bob]



Somehow I don't trust this statement...

http://www.pogowasright.org/article.php?story=20070824083524755

MedicAlert says accessed info didn't hurt clients

Friday, August 24 2007 @ 11:20 AM CDT Contributed by: PrivacyNews News Section: Breaches

Information inappropriately e-mailed to her own account by a former MedicAlert alert employee did not compromise the financial records of the company's 4 million members, its chief executive said Thursday.

Investigators arrested Andrea Terry on Wednesday on suspicion of e-mailing information about 10,000 MedicAlert clients to an outside account she controlled.

MedicAlert CEO Paul Kortschak said those records did not include medical information, Social Security numbers or bank-related data. ... Stanislaus County Sheriff's Detective Lydell Wall said the information Terry accessed consisted of a list of member names and a corresponding client identification number.

Source - Modesto Bee

[From the article:

Aside from identity theft, Wall said, the information could be used to pick out vulnerable seniors, [See? No problem. Bob] or a competitor could take advantage of it.

Terry, 43, was booked at the Stanislaus County Jail on Wednesday on suspicion of using a computer without authorization. [Her own computer? Bob] She was released after posting a $10,000 bond, Wall said.

MedicAlert dismissed Terry on May 8 and hired her back as a consultant May 29, police said. As a consultant, she worked from home, police said. On Aug. 15, she was given notice that her contract would not be renewed.

Kortschak said the company worked closely with the Turlock Police Department to ensure that Terry did not have a chance to use the information she sent herself.[Huh? Bob] "We were able to cut it off very quickly," he said.

Wall said MedicAlert's information technology department tracked the e-mail Terry sent herself, prompting the company to contact law enforcement officers. [More likely, looked into the e-mail she (stupidly) sent via the companies mail server. Bob]



If I read this one right, clicking on SPAM that takes you to a child porn site is sufficient to convict under this reading of the law. (Nothing you can do will reverse that interpretation?) If the SPAM takes you to an Al Qaeda site, you could wind up in Guantanamo.

http://www.law.com/jsp/article.jsp?id=1187859734533

Pa. Court: Viewing Child Porn on Computer Enough for Possession

Gina Passarella The Legal Intelligencer 08-24-2007

The Pennsylvania Superior Court isn't buying the argument that a man who viewed child pornography on his computer, but didn't save the images, couldn't be charged with possession of child pornography.

A 7-2 en banc Superior Court panel in Commonwealth v. Diodoro reversed a prior three-judge panel that found there was not sufficient evidence to show Anthony Diodoro downloaded or saved the images of child pornography he viewed.

In the latest majority opinion, Judge Correale F. Stevens said §6312(d) of the Crimes and Offenses Code, which prohibits the possession of child pornography, clearly states that anyone who "possesses or controls" child pornography is guilty of a third-degree felony.

Diodoro, who freely admits that he viewed at least 30 images of child pornography, argued that he never possessed them.

"[Diodoro's] actions of operating the computer mouse, locating the Web sites, opening the sites, displaying the images on his computer screen, and then closing the sites were affirmative steps and corroborated his interest and intent to exercise influence over, and, thereby, control over the child pornography," Stevens said.

He added that while Diodoro was viewing the pornography, he had the ability [but never did? Bob] to download, print, copy or e-mail the images.

... Klein said the Legislature didn't include the word "viewing" in the statute, and the judges shouldn't write it in.

"If the Legislature fails to keep up with modern technology, it is not our responsibility to correct its oversight," he said.

... "If a person intentionally enters the Philadelphia Art Museum to view Cezanne's bathers, one would not say that that person 'possesses or controls' the painting," Klein wrote. "Why should it be different if a person visits the museum's Web site ... and clicks on the part of the site that shows images of the same Cezanne bathers?"

... The decision was a big win for Delaware County District Attorney G. Michael Green, who heads up the state's Internet Crimes Against Children Task Force out of his office.

He said the ruling has broader applications in an age when computer-based information is being used in cases involving drugs, homicide and domestic relations. Green said there really is no possession of data in the traditional sense in the virtual world, but people can control the data.



Ubiquitous surveillance.

http://digg.com/offbeat_news/13_Freaky_Hidden_Surveillance_Cameras_photos

13 Freaky Hidden Surveillance Cameras - [photos]

You never know who's watching. Or from where.

http://www.rotolactor.com/wireless_surveillance_camera_01.htm



Interesting variations.

http://ralphlosey.wordpress.com/2007/08/22/uniform-law-commission-approves-model-e-discovery-rules/

Uniform Law Commission Approves Model e-Discovery Rules

The Uniform Law Commissioners have now adopted model rules of e-discovery for use by state courts. Uniform Rules Relating To Discovery of Electronically Stored Information. The proposed uniform rules of civil procedure essentially clone the bigger federal rules.

... The Draft Text of the Rules included Prefatory and Reporters Notes, which, as always, were excluded from the final version approved as a model to be adopted by the states. The Notes are not intended to be authoritative, but still are interesting to understand the thinking behind the committee that prepared the rules. You might want to review the Draft Text for that reason.



A big deal?

http://www.bespacific.com/mt/archives/015803.html

August 24, 2007

Free, Full-text Searchable Database of Supreme Court and Federal Appellate Case Reports

AltLaw Beta: "The law is meant to belong to the people, but it can be surprisingly hard to find. Case reports, a major part of the laws of the United States, are hard to get at, and even when on the Internet, rarely searchable. To get full access you generally need either a library of law reports, or an expensive subscription to an online database, which can cost hundreds of dollars per hour. AltLaw is a small effort to change that—to make the common law a bit more common. AltLaw provides the first free, full-text searchable database of Supreme Court and Federal Appellate case reports. It is a resource for attorneys, legal scholars, and the general public."

  • "Coverage, for most Circuits, limited to about the last 10 to 15 years. West Reporter Citations...not yet available (work in progress). As of yet, no state law or district court cases.
    AltLaw is a joint project of Columbia Law School’s Program on Law and Technology, and the Silicon Flatirons Program at the University of Colorado Law School. AltLaw was written by Stuart Sierra and Paul Ohm, with help from Luis Villa, and produced by Tim Wu."


Even less of a big deal?

http://www.pogowasright.org/article.php?story=20070824135200344

Open Access to Law: Swiss Data Privacy Cases Now Online

Friday, August 24 2007 @ 01:52 PM CDT Contributed by: PrivacyNews News Section: Non-U.S. News

I’m delighted to announce that our Research Center for Information Law at the University of St. Gallen - usually focusing more on basic research rather than implementing project work - has just launched an online data privacy case law collection (in German and French) that features the entire collection of cases decided by the Swiss Commission for Data Privacy and Freedom of Information from 1993 - 2006.



Research tool for money launderers...

http://www.bespacific.com/mt/archives/015804.html

August 24, 2007

Agencies Release Revised Bank Secrecy Act/Anti-Money Laundering Examination Manual

Press release: "The Federal Financial Institutions Examination Council (FFIEC) today released the revised Bank Secrecy Act/Anti-Money Laundering (BSA/AML) Examination Manual (405 pages, PDF). The revised manual reflects the ongoing commitment of the federal and state banking agencies and the Financial Crimes Enforcement Network (FinCEN) to provide current and consistent guidance on risk-based policies, procedures, and processes for banking organizations to comply with the BSA and safeguard operations from money laundering and terrorist financing. The 2007 version further clarifies supervisory expectations since the July 28, 2006, update. The revisions again draw upon feedback from the banking industry and examination staff."



For your Security Manager...

http://it.slashdot.org/article.pl?sid=07/08/24/179247&from=rss

Forensics On a Cracked Linux Server

Journal written by Noryungi (70322) and posted by kdawson on Friday August 24, @01:33PM from the hmmm-ls-looks-funny dept.

This blog entry is the step-by-step process that one administrator followed to figure out what was going on with a cracked Linux server. It's quite interesting to me, since I have had the exact same problem (a misbehaving ls -h command) on a development server quite a while back. As it turns out, my server was cracked, maybe with the same tool, and this analysis is much more thorough than the one I was able to do at the time. If you've ever wondered how to diagnose a Linux server that has been hijacked, this short article is a good starting point.



When your day job gets boring...

http://www.cosic.esat.kuleuven.be/keeloq/

How To Steal Cars — A Practical Attack on KeeLoq

KeeLoq is a cipher used in several car anti-theft mechanisms distributed by Microchip Technology Inc. It may protect your car if you own a Chrysler, Daewoo, Fiat, General Motors, Honda, Toyota, Volvo, Volkswagen, or Jaguar. The cipher is included in the remote control device that opens and locks your car and that activates the anti-theft mechanisms.

Each device has a unique key that takes 18 billion billion values. With 100 computers, it would take several decades to find such a key. Therefore KeeLoq was widely believed to be secure. In our research we have found a method to identify the key in less than a day. The attack requires access for about 1 hour to the remote control (for example, while it is stored in your pocket). [I wonder if I could sit outside the Jaguar dealership and read all the keys – it is wireless after all... Bob] Once we have found the key, we can deactivate the alarm and drive away with your car.