Tuesday, September 11, 2007

Screwing up by the numbers... No doubt this will hurt in those Class Action suits...

http://techdirt.com/articles/20070910/012931.shtml

Did TJX Know About Massive Security Breach Long Before It Revealed It?

from the dates-not-adding-up dept

We've already seen that, as with just about every other data leak, the massive data leak from clothing retailer TJX was a lot worse than originally reported. However, some are now asking whether the company also hasn't come entirely clean about when the breach occurred and when the company knew about it. The official statements from TJX suggest that the company became aware that its own horrible security was breached on December 18th, 2006, and informed the FBI by December 22nd. However, as the article above notes, there's evidence suggesting that TJX was familiar with the breach well before that. Remember that a bunch of folks had been arrested in Florida for using the TJX data in scams. The police in that case have filed some reports, noting that TJX had alerted them to a breach back in March of 2006 -- and, in fact, the Florida investigators filed reports on their investigation in November 2006... well before TJX even claims that it knew of the breach. It certainly raises some questions about when TJX really became aware of the breach, and when the company finally alerted people that their data may have been compromised.


Another slam at TJX...

http://www.infoworld.com/article/07/09/11/dos-and-donts-for-dealing-with-data-breaches_1.html?source=rss&url=http://www.infoworld.com/article/07/09/11/dos-and-donts-for-dealing-with-data-breaches_1.html

Expert do's and don'ts for dealing with data breaches

A data breach victim shares his advice for addressing leakage incidents, while another expert highlights the missteps taken by TJX in dealing with its information theft

By Matt Hines September 11, 2007

Organizations that experience data breaches must move quickly to assuage the fears of their constituents and go beyond expectations to address the situations effectively, according to those most familiar with the incidents.

Speaking at the ongoing Security Standard Conference in Chicago, a pair of experts offered advice for handling situations where sensitive user or customer data is lost or stolen, and examined the missteps taken by retailer TJX Companies in handling its now-notorious credit card information theft.

... Less than two weeks after BC discovered the breach, the school had assembled a comprehensive incident response plan [I teach my students to have this plan in place BEFORE things go bad... Bob] and had mailed out 100,000 warning letters to anyone whose data may have been stored in the system.

... At the same time, it was crucial to establish separation of duties early in the game, Escalante said.

"It's good to keep your upper management separate from your response team because they can get in the way. You want management involved, but you don't want them focusing on every little issue," said Escalante.

... In addition to seeking legal help from its attorneys, the school was able to communicate effectively with law enforcement officials investigating the incident since BC had already familiarized itself with those people before the breach.

... Handling sensitive data in such a careless way was the first mistake TJX made, and it had plenty of warning that such attacks could be carried out on point-of-sale systems, the expert contends.

Among the additional mistakes made by TJX was not reporting the incident for months, or even years, after it first discovered the hack, he said, as well as failing to address the situation in public and apologize sufficiently to its customers.

TJX has also refused to share information about the attack publicly to help other companies avoid such incidents, Stiennon said.

"There's been a significant lack of core with TJX's response. They didn't overreact as they probably should have, unlike BC," Stiennon said. "As a result they've become the poster child for data breaches and how not to communicate risk to the rest of the security industry."



I told you we weren't done with this one.

http://www.pogowasright.org/article.php?story=20070910163034605

(follow-up) OH: Almost 67,000 more names on stolen tape

Monday, September 10 2007 @ 04:30 PM CDT Contributed by: PrivacyNews News Section: Breaches

The names and Social Security numbers of more than 66,600 more individuals, including former state workers, were on a computer backup tape stolen from a state intern's car in June, officials said today.

The revelation brings to more than 1.3 million the number of individuals, businesses and other entities whose sensitive information is on the tape. The new names evidently were missed in an extensive state review of a duplicate of the missing device. [Oh, that inspires confidence... Bob]

Source - Columbus Dispatch



At first glance, they seem to be handling this fairly well...

http://www.pogowasright.org/article.php?story=20070910172425646

Gander Mountain Announces Possible Theft of Pennsylvania Store Computer; Customers of the PA Store Could Be Affected

Monday, September 10 2007 @ 05:24 PM CDT Contributed by: PrivacyNews News Section: Breaches

Gander Mountain Company today announced that computer equipment, containing certain customer transaction information relating to a single store in Pennsylvania, is missing and may have been stolen. The transaction data relates only to customers who conducted business with the Gander Mountain store located in Greensburg, PA, during the period from July 2002 through June 2007.

The stored transaction information may have included:
-- Approximately 112,000 credit card numbers with expiration date but without any other associated information.
-- Approximately 10,000 transaction records may have included the credit card number, expiration date and customer name.
-- For the approximately 5,100 credit card customers who returned merchandise or did a lay-away purchase at the store during this period, the information also may have included an address.
-- For the approximately 650 customers who purchased by check and returned merchandise without a receipt or put merchandise on lay-away by check payment, the information may have contained a name, address, driver's license number and date of birth.

Source - CNN


...and they aren't

http://www.pogowasright.org/article.php?story=20070910183646754

Hewlett-Packard exec loses laptop, puts former Mercury Interactive employees at risk of ID theft

Monday, September 10 2007 @ 06:44 PM CDT Contributed by: PrivacyNews News Section: Breaches

While on a business trip to Atlanta, a Hewlett-Packard executive lost a laptop containing the names, addresses, dates of birth, Social Security numbers, compensation information and citizenship information of 1,425 former Mercury Interactive employees.

The loss occurred at the end of July, and HP notified those affected by letter on August 17th.

The laptop's security consisted of user/pass login. (Note from Dissent: do you folks realize how difficult it is to type that with a straight face?)

Source - Notification to New Hampshire and Letter to Former Employees (pdf)



No encryption? Fire that manager immediately!

http://www.pogowasright.org/article.php?story=20070910232822658

TennCare provider offers loses patient information on thousands

Tuesday, September 11 2007 @ 12:38 AM CDT Contributed by: PrivacyNews News Section: Breaches

A TennCare provider is offering free identity protection after a courier service lost the personal information of nearly 70,000 enrollees.

According to TennCare officials Americhoice Inc. hired a courier to transport a CD from Nashville to Knoxville.

The CD contained identifying information of 67,000 TennCare enrollees.

Source - WATE


Ditto

http://www.pogowasright.org/article.php?story=20070910234619571

PA: Computers stolen from welfare office

Tuesday, September 11 2007 @ 12:39 AM CDT Contributed by: PrivacyNews News Section: Breaches

Two computers containing the mental health histories of more than 300,000 medical-assistance recipients were stolen from a state Public Welfare Department office last month, a spokesman for Gov. Ed Rendell confirmed Monday.

The computer work stations were taken Aug. 22 during an overnight break-in at an office in the former Harrisburg State Hospital, said Rendell spokesman Chuck Ardo.

The mental health information on the computers identified people by codes and not by name... but full names and Social Security numbers of nearly 2,000 people were also on the computers.

Source - PennLive



A good source of bad examples...

http://www.pogowasright.org/article.php?story=20070910080243795

Hard times on the HIPAA front

Monday, September 10 2007 @ 08:02 AM CDT Contributed by: PrivacyNews News Section: Medical Privacy

It's been a week of bad news for lazy or sloppy health care organizations. An employee fired after a security breach of protected health information filed a wrongful termination suit against his former employer, and it may have merit because of poor policies. A community health care provider hacked by a disgruntled employee may be dragged into a compliance quagmire because it's not clear that the organization took basic steps to revoke his access. And to top it off, the U.S. Department of Health and Human Services (HHS) is starting to swing the enforcement rule -- a dowdy part of the Health Insurance Portability and Accountability Act (HIPAA) that few people read -- like a scythe in a field of weedy policies and overgrown practices.

Source - Computerworld



Nutty as a fruitcake?

http://www.wired.com/politics/law/news/2007/09/mcbride

Inside the Mind of the Man Who Tried to Milk Linux

By David Kravets Email 09.10.07 | 2:00 AM

Darl McBride has the unenviable reputation as the man who tried to milk Linux.

As CEO and president of SCO Group, McBride has spent the last few years trying to collect billions in licensing fees from companies using the Linux operating system, earning the wrath of the world's open-source geeks. For scores of programmers, here was a lawyered-up copyright troll trying to shake down Linux -- the free, open-source operating system built by idealistic hackers working for the common good.

But McBride insists he's just misunderstood.



Not only are they early adopters, they tend to actually solve tech problems! Look for great things!

http://torrentfreak.com/porn-industry-to-take-on-bittorrent-sites-070910/

Porn Industry to Take on BitTorrent Sites

Written by Ernesto on September 10, 2007

Porn industry representatives gathered at an anti-piracy conference last week to discuss solutions to the ever growing amount of pirated porn that’s traded on BitTorrent sites and other P2P-networks.



RIAA has bad lawyers? I'm shocked!

http://techdirt.com/articles/20070910/015200.shtml

Judge Tosses Out RIAA Suit For Being Based On Nothing More Than Speculation

from the here-in-the-court-system,-we-rely-on-these-things-called-facts dept

Recently, we've seen the courts getting less and less willing to accept the RIAA's flimsy evidence as being enough to convict someone of breaking the law with file sharing applications. The latest such case is along those lines, as a judge dismissed a case noting that it was just a "boilerplate listing," lacking enough substance to make a case. Specifically, the judge found that: "Plaintiffs have presented no facts that would indicate that this allegation is anything more than speculation. The complaint is simply a boilerplate listing of the elements of copyright infringement without any facts pertaining specifically to the instant Defendant." It's about time that courts realized that the RIAA shouldn't be able to run around accusing all sorts of people without any real evidence.



I'll have ti think about this one... Should I trust someone else with my Identity?

http://www.killerstartups.com/Web-App-Tools/spyshakers--Keep-Your-Info-Safe/

SpyShakers.com - Keep Your Info Safe

Security is on everyone’s mind; if you want to keep your info safe, take a look at SpyShakers. SpyShakers is an Identity Management System (IMS), which lets you access your favorites and passwords securely from any computer. All your personal info—bookmarks, passwords, log-ins, favorites, etc. can be stored safely in your SpyShakers account. For extra protection users can set up a Shaker List which contains the names of websites which that must be selected in order to gain full access; it also protects against keyloggers and phishing. Passwords and log-in ID’s can be dragged and dropped directly into sites, for increased use and safety. SpyShakers is free for everyone.

http://www.spyshakers.com/joomla/



Lady Bird lives!

http://www.researchbuzz.org/wp/2007/09/10/database-of-native-plants-from-ut-austin/

Database of Native Plants from UT-Austin

10th September 2007

The Lady Bird Johnson Wildflower Center, at the University of Texas at Austin, has a database of native plants with some really nice searching options. It’s available at http://www.wildflower.org/plants/.



Free is good! (Think this kind of promotion will catch on?)

http://www.wral.com/business/blogpost/1799397/

Walgreens Doing Free Ink Cartridge Refills Wednesday

Posted: Sep. 10 7:43 p.m.

Drug store chain Walgreens has announced that on Wednesday (Sept 12), over 3,000 of its locations will be offering free inkjet printer cartridge refills for free. Customers can bring one empty b&w or color cartridge to the Walgreens photo counter and get it filled for free.

Note there are MANY Walgreens offering this service, but not ALL Walgreens. You can search for Walgreens near you that offer ink cart refills at http://www.walgreens.com/storelocator/find.jsp. Be sure to tick the box that reads "Printer cartridge refills".

Monday, September 10, 2007

The problem is, they never RTFM (Read the F***ing Manual) The Questions are: 1) Why no encryption? 2) Why would an Embassy use Tor?

http://www.pogowasright.org/article.php?story=20070910061510649

Tor at heart of embassy passwords leak

Monday, September 10 2007 @ 06:22 AM CDT Contributed by: PrivacyNews News Section: Internet & Computers

Tor advertises itself as a means for people and groups to improve their privacy. And when used properly, the distributed, anonymous network does just that. But a Swedish security consultant has used the very same system to gain access to login credentials for a thousand or so individual email addresses, including those of at least 100 accounts belonging to foreign embassies.

Dan Egerstad, who made waves last week posting the login details to embassies belonging to Iran, India, Japan and Russia, among others, has finally identified how he got access to the information.

Source - The Register

[From the article:

Tor has taken pains to warn its users that people running so-called exit nodes - which are the last Tor servers to touch a packet before sending it on its way - "can read the bytes that come in and out there." They go on to say: "This is why you should always use end-to-end encryption such as SSL for sensitive Internet connections."

... The posting of 100 official embassy passwords has made Egerstad a pariah in many circles. Publishing information that allows any old criminal to infiltrate sensitive government networks [But only because criminals RTFM! Bob] is a touchy thing, and many, including several Reg readers, have denounced it.



As usual there are a number of incidents that I didn't bother blogging about.

http://www.pogowasright.org/article.php?story=20070910060649165

Data “Dysprotection:” breaches reported last week

Monday, September 10 2007 @ 06:20 AM CDT Contributed by: PrivacyNews News Section: Breaches

A recap of incidents or privacy breaches reported last week for those who enjoy shaking their head and muttering to themselves with their morning coffee.

Source - Chronicles of Dissent



Tools and Techniques: Announcements of data spills claim the data was protected by passwords in probably 8 of 10 instances. Here is one example why that isn't enough...

http://www.codinghorror.com/blog/archives/000949.html

September 08, 2007

Rainbow Hash Cracking

The multi-platform password cracker Ophcrack is incredibly fast. How fast? It can crack the password "Fgpyyih804423" in 160 seconds. Most people would consider that password fairly secure. The Microsoft password strength checker rates it "strong". The Geekwisdom password strength meter rates it "mediocre".



Late to market...

http://googlesystem.blogspot.com/2007/09/microsoft-launches-translation-service.html

Sunday, September 09, 2007

Microsoft Launches Translation Service

Microsoft launched a service for automatic translation called Windows Live Translator. The site lets you translate a text limited to 500 words or a web page from English to German, Dutch, French, Spanish, Portuguese, Italian, Korean, Chinese, Japanese, Russian.

... Google also has a translation service powered by Systran. The translations are identical to the ones returned by Babel Fish, but they're different from Windows Live's translations, so Microsoft might use an updated version of Systran's software.

Google developed a machine translation system that's available to the public for only three languages: Arabic, Chinese and Russian. [Gee, I wonder what government agency would be interested in those languages... Bob]



This works in other areas as well. Expect virtual elections – perhaps a delegation from the great state of Second Life

http://www.technewsworld.com/rsstory/59238.html

Virtual Worlds: An Economist's Sandbox

By Peter Svensson AP 09/09/07 4:00 AM PT

Second Life is just one example of how economists and virtual worlds are teaming up, to mutual benefit. Outside Second Life, a game company just hired its first full-time economist. Another economist, coming from the academic side, believes that just as virtual economies need economists, so economists need virtual economies -- to experiment with.



One of my former students sent this... Think she rigged the test?

http://www.elks590.org/main/cooltest.htm

COOL PERSON TEST

Sunday, September 09, 2007

Another attempt to introduce astrology to the justice system?

http://yro.slashdot.org/article.pl?sid=07/09/08/1210219&from=rss

Ohio Court Admits Lie Detector Tests As Evidence

Posted by CowboyNeal on Saturday September 08, @10:37AM from the good-enough-for-maury dept. The Courts Security Technology

An anonymous reader writes "Last month, an Ohio court set a new precedent by allowing polygraph test results to be entered as evidence in a criminal trial. Do lie detectors really belong in the court room? AntiPolygraph.org critiques the polygraph evidence from the this precedential case (Ohio v. Sharma)."



Non-lawyer question. At what point does the Judge get to slap these guys?

http://yro.slashdot.org/article.pl?sid=07/09/08/1124219&from=rss

Judge Kimball Strikes SCO's Jury Trial Demand

Posted by CowboyNeal on Saturday September 08, @08:48AM from the down-on-their-luck dept. The Courts Caldera

watchingeyes writes "In a ruling on various pre-trial motions in limine and other, similar motions in the SCO vs Novell case, Judge Kimball today issued a ruling striking SCO's demand for a jury trial, ruling that Novell's claims seek equitable, and not legal relief. In addition, he denied SCO's request for entry of judgment that would allow them to appeal his ruling on the UNIX copyrights and Novell's waiver rights, ruling that if SCO wants to appeal any of his rulings, it can do them all at once after trial. He also granted Novell's request to voluntarily dismiss its own breach of contract claim, denied SCO's motion to exclude press coverage and evidence from the IBM case, granted Novell's motion in limine preventing SCO from contesting his summary judgment ruling at trial, granted Novell's second motion in limine preventing SCO from arguing that SCOsource licenses that license SVRx only incidentally aren't SVRx licenses, denied another SCO motion in limine which improperly asked the Judge to issue rulings on contractual issues and denied Novell's final motion in limine which sought to prevent SCO from contesting Novell's apportionment of royalties analysis. Looks like SCO will be facing a trial in-front of a judge which has already ruled against them numerous times."



Cyberwar? What are we being primed for? Perhaps a new government agency to counter hackers (and take over all the Internet data collection?

http://technology.timesonline.co.uk/tol/news/tech_and_web/the_web/article2409865.ece

China’s cyber army is preparing to march on America, says Pentagon

Tim Reid in Washington September 8, 2007

Chinese military hackers have prepared a detailed plan to disable America’s aircraft battle carrier fleet with a devastating cyber attack, according to a Pentagon report obtained by The Times.

The blueprint for such an assault, drawn up by two hackers working for the People’s Liberation Army (PLA), is part of an aggressive push by Beijing to achieve “electronic dominance” over each of its global rivals by 2050, particularly the US, Britain, Russia and South Korea.

China’s ambitions extend to crippling an enemy’s financial, military and communications capabilities early in a conflict, according to military documents and generals’ speeches that are being analysed by US intelligence officials. Describing what is in effect a new arms race, a Pentagon assessment states that China’s military regards offensive computer operations as “critical to seize the initiative” in the first stage of a war.

... Cyber attacks by China have become so frequent and aggressive that President Bush, without referring directly to Beijing, said this week that “a lot of our systems are vulnerable to attack” [Somehow i doubt that. Bob] He indicated that he would raise the subject with Hu Jintao, the Chinese President, when they met in Sydney at the Apec summit. Mr Hu denied that China was responsible for the attack on Robert Gates, the US Defence Secretary.


Larry M. Wortzel, the author of the US Army War College report, [I couldn't locate it on their site Bob] said: “The thing that should give us pause is that in many Chinese military manuals they identify the US as the country they are most likely to go to war with. They are moving very rapidly to master this new form of warfare.” The two PLA hackers produced a “virtual guidebook for electronic warfare and jamming” after studying dozens of US and Nato manuals on military tactics, according to the document.

The Pentagon logged more than 79,000 attempted intrusions in 2005. About 1,300 were successful, including the penetration of computers linked to the Army’s 101st and 82nd Airborne Divisions and the 4th Infantry Division. In August and September of that year Chinese hackers penetrated US State Department computers in several parts of the world. Hundreds of computers had to be replaced or taken offline for months. Chinese hackers also disrupted the US Naval War College’s network in November, forcing the college to shut down its computer systems for several weeks. The Pentagon uses more than 5 million computers on 100,000 networks in 65 countries.



If true, this is fairly significant. I recently imaged an 80GB laptop drive and it took me 90 minutes plus setup time – this promises twice the speed.

http://it.slashdot.org/article.pl?sid=07/09/08/1956226&from=rss

Forensic Computer Targets Digital Crime

Posted by kdawson on Sunday September 09, @12:07AM from the taking-a-byte-out-of-it dept. Security IT

coondoggie writes "A European consortium has come up with a high-speed digital forensic computer dedicated to the task of quickly offloading and analyzing computer records. The TreCorder is a rugged forensic PC able to copy or clone up to three hard disks simultaneously, at a speed of up to 2 Gb/min., far faster than alternative equipment. The PC not only provides a complete mirror image of the hard disk and system memory — including deleted and reformatted data — but also eliminates any possibility of falsification in the process, meaning that the evidence it collects will stand up in court."



Now wouldn't this make an interesting project for my security students...

http://www.dmnews.com/cms/dm-news/legal-privacy/42323.html

Looking out for data surveillance predictions for 2020

By Robert Gellman, Consultant September 7th, 2007

What will surveillance and tracking look like in 2020? It’s only 13 years away. Here are some fanciful predictions.

Auto tracking. Every car will be required to have a transponder, and automated highway readers will record all trips. The transponders will allow agencies to monitor driving habits and to issue electronic tickets for violations. The system will collect fees for using congested roads, replace parking meters and prevent undesirable people from driving in certain areas. For example, pedophiles will not be permitted to drive near schools. Driving with a malfunctioning transponder will be illegal. A black market will emerge in cars registered to “clean” or dead individuals.

Very personalized PC. Every computer will have a static IP address. No one will be able to operate a computer without registering through a token, fingerprint or other identification device. All e-mail will be stored permanently, and records of other network activity, including searching and transactions, will also be retained. Stolen computers will be a hot black market item for criminals who will use them to avoid accountability for online actions.

MySpace is mandatory. Every individual will be required to maintain a personal Web page with basic contact information accessible by the government and the public. People with out-of-date pages will be fined. An individual will be allowed to post minimal information for public use, but the government will demand more. Everyone will be required by law to have an active e-mail address. Official government notices will be sent by e-mail rather than by post.

Society caught on tape. Surveillance cameras will be even more universal than they are today. You will not be able to walk down a street, enter a store, park in a garage, ride the subway, sit at your desk at work, open your front door or do anything else outside your home without being recorded.

Penniless marketplace. Currency will disappear and all money will be electronic. Every transaction will be permanently tracked. Private money systems will develop using tokens, gold and other forms of intrinsic value. Paying in private money will work for some things, but prices for non-tracked activities will be double to cover the risks involved.

Dog tags go digital. Identification chips implanted in the human body will be banned after some people are maimed or killed to obtain their chips. However, governments will promote the wearing of personal transponders so that scanners can identity each person within range. Personal transponders will first be touted as a safety program for children and then as a protection against terrorists. If your transponder does not work, you will be subject to arrest in any public space. Trafficking in transponders will be illegal, but widespread.

Fast food goes under the table. The health and insurance industries will try to control costs by monitoring food purchases. They will begin by offering discounts to individuals who allow monitoring of their eating habits, but monitoring will eventually become mandatory. Separate checks will be universal in restaurants. Restaurants will prosper by putting fish on the menu, but will tell customers that the halibut is actually a hamburger. Eventually, insurers will audit restaurant food purchases to try to keep the reporting system honest. There will be a black market in unregistered junk food.

Healthy living is a must. Government and private insurers will mandate that individuals agree to health treatments as a cost-saving measure. Computerized health records will be centrally reviewed to monitor compliance. If you don’t get a required treatment, your insurance will cost more or be cancelled, you will lose your job, your tax return will be audited and you will be labeled as unpatriotic. Digital health records will permit precise scoring of individual and family health risks. Each insured person and family will be individually rated and priced, even under employer-provided health insurance policies. An underground system of healthcare will develop for people who don’t want their insurer to know about some medical conditions. People will pay privately for care to avoid higher rates, uninsurability or monitoring.

Direct marketing activities will be positively affected by the availability of more personal information. However, public aversion to spam, telephone calls and postal mail will make it harder to exploit the information by traditional means. Many free Internet services will remain free only to those who do not block ads.

These predictions come with the usual guarantee. Will there also be new and improved privacy protections by 2020? Maybe, but that’s a subject for another day.

Robert Gellman is a Washington-based privacy and information policy consultant and former chief counsel to the House subcommittee on information, justice, transportation and agriculture. His e-mail address is bob@bobgellman.com



Mandatory SiFi reading

http://slashdot.org/article.pl?sid=07/09/08/1146218&from=rss

2007 Hugo Award Winners Announced

Posted by CowboyNeal on Saturday September 08, @09:39AM from the come-on-down dept. Sci-Fi Entertainment

jX writes "This year's Hugo Award Winners have been announced at the recently launched Hugo Award official website. Some winners that should be familiar to any well read/watched geek are Vernor Vinge for Best Novel, Doctor Who for Best Dramatic Presentation, Short Form), and last years hit movie Pan's Labyrinth for Best Dramatic Presentation, Long Form. Of course, a complete list of this year's nominees and winners is also available."



You know I like lists...

http://www.teknobites.com/2007/09/08/40-free-windows-apps-for-you/

40+ Free Windows Apps For You

Published at September 8, 2007 in Tools and Software. Tags: Software, Tools.

This post is the part 2 of my earlier post 20 Open Source Windows Apps For You, i got lot of feedback for that post and my readers suggested some excellent programs to be included in that list. So here i am listing all those programs which i have missed in my earlier post. Do check the earlier post for the complete software list.



A list of lists! Neat!

http://mashable.com/2007/09/08/5000-resources-to-do-just-about-anything-online/

5000+ Resources to Do Just About Anything Online

September 8, 2007 — 07:45 AM PDT — by Sean P. Aune

Saturday, September 08, 2007

A little slow to disclose?

http://www.pogowasright.org/article.php?story=20070907162347602

McKesson: Stolen Computers Contain Patient Information

Friday, September 07 2007 @ 04:23 PM CDT Contributed by: PrivacyNews News Section: Breaches

Health-care services company, McKesson, is alerting thousands of its patients that their personal information is at risk after two of its computers were stolen from an office.

The company, which helps pharmaceutical manufacturers set up assistance programs for patients in need, sent out a letter alerting patients that the computers were stolen on July 18. The names of the people being alerted were on one of the two PCs, but it's not known how much of their accompanying identifying information was also contained on the machines.

Source - InformationWeek

[From the article:

The company representative said it's not clear if the data on the machines was encrypted. [“We don't know what the hell we're doing...” Bob]



Clueless in Canada?

http://www.pogowasright.org/article.php?story=20070908064133439

Ca: CHR patient data stolen

Saturday, September 08 2007 @ 06:41 AM CDT Contributed by: PrivacyNews News Section: Breaches

Patient information has been compromised after Calgary Health Region computers were stolen in a sophisticated break-and-enter early yesterday, officials said.

... "Apart from other electronics, seven laptops were stolen, two of which contained patient information."

How sensitive the information in the stolen machines is and how much there is isn't yet known, [“We have no idea what our employees do, and they have no idea what data they do it with...” Bob] said Rougeau.

Source - Calgary Sun



This is interesting...

http://www.pogowasright.org/article.php?story=20070907170545688

ID Theft Research Group to Come Out of the Shadows

Friday, September 07 2007 @ 05:05 PM CDT Contributed by: PrivacyNews News Section: Breaches

The Center for Identity Management and Information Protection (CIMIP) has kept a low profile since its inception over a year ago, but that's about to change: The public-private partnership that includes IBM, the U.S. Secret Service, and the FBI, has just broken ground on a new multi-million dollar secured facility, and next month will release some surprising findings about the bad guys behind identity theft.

Source - Dark Reading


So is this (some of the same folks as in the previous story)

http://www.utica.edu/academic/institutes/ecii/ijde/index.cfm

International Journal of Digital Evidence



The major drawback is that US “broadband” is much slower that broadband in third world countries. That will need to change.

http://www.eweek.com/article2/0,1759,2180379,00.asp?kc=EWRSS03119TX1K0000594

Analysts Predict Death of Traditional Network Security

By Brian Prince September 7, 2007

As the number of mobile workers grow, businesses will be forced to opt for desktop virtualization, Forrester analysts say.

Robert Whiteley and Natalie Lambert have seen the future—and in it, traditional network security is dead. At least that is the message the two Forrester Research analysts delivered to a crowd at the Forrester Security Forum in Atlanta Sept. 6.

According to them, in the next five years the Internet will be the primary connectivity method for businesses, replacing their private network infrastructure as the number of mobile workers, contractors and other third-party users continues to grow. In this new world, which Whiteley and Lambert called "Internet Everywhere," corporations will have to redefine network security and focus on data encryption, managing risk at the endpoint and having strict data access controls, they said.

Some corporations, such as the energy giant BP, have already taken big steps towards deperimeterization—a term created by the Jericho Forum to describe a strategy that focuses on protecting data with tactics such as encryption rather than traditional efforts aimed at fending off attacks from intruders at the network's boundary. BP has taken some 18,000 of its 85,000 laptops off its LAN and allowed them to connect directly to the Internet, the two said.

... Desktop virtualization allows a PC's operating system and applications to execute in a secure area separate from the underlying hardware and software platform. Its security advantages have become a major selling point, as all a virtualized terminal can do is display information; if it is lost or stolen, no corporate data would likely be compromised since it wouldn't be stored on the local hard drive.



This wouldn't be interesting except for the “We didn't know... “ aspect. Is this a one-in-a-billion situation? (see next article)

http://news.com.com/8301-13578_3-9774295-38.html?part=rss&subj=news&tag=2547-1_3-0-5

National Intelligence Web site no longer invisible to search engines

Posted by Declan McCullagh September 7, 2007 4:30 PM PDT

Until a few hours ago, the Web site of National Intelligence Director Mike McConnell had been invisible in Google, MSN and Yahoo searches. That's because dni.gov's robots.txt file told search engines to stay away. [This is not a default, it requires action by someone. Bob]

Now it's been fixed. DNI spokesman Ross Feinstein told me, apologetically, a moment ago: "When we saw your story posted, I asked our developers to look into it... We certainly appreciate you bringing it to our attention. It's a public Web site. We want it to be indexed. We're not even sure how (the robots.txt file) got there." [The Tooth Fairy strikes again! Bob]


Typically, updates to a database are fed back to the updater, allowing them to confirm that ALL the updates were made. This is Programming 101.

http://www.technewsworld.com/rsstory/59227.html

Database Glitch Trips Up Terrorist Screening

By Lara Jakes Jordan AP 09/07/07 8:25 AM PT

A database mistake on the part of the FBI resulted in the records of 20 terror suspects not being available to front-line screeners, an audit found. The problem is that records for two systems that feed to and from the central terror watch list database don't match. The FBI says it is working on the problem and should have it fixed within six months.

... The audit by Justice Department Inspector General Glenn A. Fine gave the FBI mixed reviews for its efforts over the last two years to clean up its terror watch list database.


I wonder what this cost the taxpayers...

http://www.chicagotribune.com/news/local/southsouthwest/chi-lunch_07sep07,1,6329782.story?ctrack=1&cset=true

High technology off menu

After 1 day, Wilmette district's use of pupils' fingerprints to pay for lunches is put on hold because of privacy and legal concerns

By Lisa Black Tribune staff reporter September 7, 2007

Shortly after rolling out a new lunch program that allows pupils to pay for hot meals with a scan of their fingerprint, Wilmette school officials put the system on hold after learning that a new Illinois law limits the use of biometric information to protect children's privacy.

That, and the system didn't work, perhaps because of grubby fingers or a computer glitch, said officials from Wilmette Elementary School District 39.

"The jury is still out. We tried it just one day, and it was unsuccessful," said interim Supt. Ray Lechner. [Translation: “We're not done being stupid yet!” Bob]


The US isn't the only clueless government.

http://www.eweek.com/article2/0,1759,2180443,00.asp?kc=EWRSS03119TX1K0000594

No-Defense Department

September 7, 2007 By Lisa Vaas

On July 18, Sunbelt Software came across a SQL command passed as a query within a URL belonging to an arm of a European country's military. With that, any visitor can pass queries in the URL straight to the back-end database and squeeze out any data, no password required.

At the time, the URL displayed what Sunbelt President Alex Eckelberry calls an "infantile" security screw-up: Namely, putting production code and a back-end database into the hands of anybody who wanders by. It was, in other words, a serious security vulnerability that even the most basic security policy should have forbidden, never mind the security policy of a major defense agency.

Sunbelt, of Clearwater, Fla., alerted security researchers from the country in question. They in turn assured Sunbelt that they would notify the defense agency.

End of story? Unfortunately not. Six weeks later, Sunbelt checked the site and found it was still a sitting duck, serving up military base information to any visitor who knows how to frame a SQL query, telling potential attackers exactly which database it was running and what operating system it was using, thereby painting a day-glow arrow toward the exact class of known vulnerabilities and exploits that could bring it to its knees.

Sunbelt alerted security researchers from the country in question. Again. They in turn assured Sunbelt that they would notify the defense agency. Again.

This is far from an anomaly. As evidenced by the recent attack on a portion of the Pentagon's network—allegedly perpetrated by the Chinese People's Liberation Army—continued vulnerability in defense establishments is leaving governments exposed and populaces at risk. What's worse, much of it is due to sheer sloppiness: Poor security policies, unpatched systems, you name it—nothing glamorous, nothing cutting-edge, just run-of-the-mill slacker lack of attention.

... But even without specifics from the horses' mouths, finding specific vulnerabilities on these sites isn't particularly difficult. Eckelberry directed eWEEK to simply Google "sex porn site:.gov." Out of the 10 top hits Sept. 6 at 4:13 EDT, eight were for pornography somehow tied in to Web servers hosted by the government of California.



Same questions I asked only better...

http://techdirt.com/articles/20070907/000225.shtml

Why Is The Justice Department Commenting On Net Neutrality?

from the not-really-their-area-of-interest dept

There's been a fair amount of chatter over the Justice Department's decision to comment to the FCC about network neutrality, but there's been almost no discussion as to why the Justice Department should be involved at all. It's true that the DOJ covers anti-trust issues, but this isn't about a merger or the potential to create a monopoly. While I'm not in favor of regulating network neutrality, there are a bunch of really questionable statements in the DOJ's filing that simply don't make much sense. Take, for example, the following statement: "Regulators should be careful not to impose regulations that could limit consumer choice and investment in broadband facilities." If the DOJ really feels that way, then shouldn't it have also come out against the FCC's decision to do-away with line sharing rules that actually did allow for competition? Does the DOJ not realize that the market for broadband is already heavily regulated, which is why most consumers here only have one or two choices -- compared to other countries that have created more open markets on top of the infrastructure, allowing for competition, faster speeds and increased innovation? Does the DOJ really not realize how many gov't subsidies and handouts have been given to the telcos so that they could build networks where no one else could enter the market in the same manner?

The DOJ also makes the bizarre argument that without breaking net neutrality, broadband providers will never make enough money to upgrade their networks. It's a dumb argument for the same reason that it's a dumb argument to claim that without network neutrality, it'll be too costly for certain sites to make enough money to offer cool services to users. Both arguments are ridiculous because they focus on the specific benefits to one private party and not how they impact the rest of the market -- and the DOJ shouldn't have any interest in focusing on the benefits of a single private party (and it's even worse for the DOJ to do so under the false guise of "free market" economics). Sure, without network neutrality telcos might be able to make more money in the short term. But you could just as easily argue that if network neutrality remains, it'll be easier (and cheaper) to create the next generation of killer apps that will make more bandwidth more valuable (allowing the telcos to profit handsomely). And, it's not even worth going into the DOJ's use of the thoroughly debunked claim comparing network neutrality to different delivery speeds at the post office. Basically, the DOJ brief (and, again, it's still not clear why they even have an opinion on this) repeats a bunch of the misleading half-truths that the telcos have spouted for months. Yet, it doesn't touch on the really key issue: there simply isn't real competition in the broadband market. Allowing the telcos to break network neutrality doesn't change that.



Free is good!

http://www.technewsworld.com/rsstory/59219.html

Taking the Open Road: University Libraries Explore Options

By Tracey Caldwell Information World Review 09/08/07 4:00 AM PT

The virtual learning environment could be where university libraries first encounter open source. An increasing number of content management and portal systems are also open source and many university libraries are involved in setting up open source repositories. As acceptance of open source grows, the next step will be to consider open source solutions for the core integrated library system.

... Open source learning management system (LMS) Moodle alone is now used in 56 percent of universities since its introduction three years ago, and the Open University has moved over to it wholesale. Supporters say open source LMS tend to be more modular and make it much easier for libraries to contribute content than is the case with commercial solutions.

Friday, September 07, 2007

We didn't know...”

http://www.pogowasright.org/article.php?story=20070906191236314

USC investigates student information found on the Web

Thursday, September 06 2007 @ 07:12 PM CDT Contributed by: PrivacyNews News Section: Breaches

The University of South Carolina is looking into what it called an "accidental disclosure" of private student information on the Internet, school spokesman Russ McKinney said Thursday.

The information wasn't on the Web long before the school realized what happened and took immediate steps to remove it, McKinney said.

The university is trying to determine exactly what type of information was released, the length of time it was on the Internet and who might have accessed it. McKinney said.

The breach involved 1,482 students, he said.

Source - Associated Press

[From the article:

The student files were found Aug. 31 by the Washington-D.C.-based nonprofit group Liberty Coalition, said Aaron Titus, director of information privacy for the group.

... It appears the person responsible [Isn't the CIO responsible for Information? Bob] for the breach may not have known enough about computers to realize the information could be accessed outside the university system, Titus said.

"But once that information gets out there, it's nearly impossible to tell how many copies of it might have been made," [This is what auditors refer to as a Big Fat Lie... Bob] Titus said.

The disclosure was first reported by The Daily Gamecock, the independent student newspaper at the university.



Another attempt to calm the victims by declaring that passwords are adequate to prevent Identity Theft. Just go to digg.com and enter a search for “password” -- they'll provide dozens of techniques for bypassing or cracking passwords. Most of the computer forensic companies will show you how to access data on a hard drive without ever being asked for a password. (sorry for the rant, but I worry that someone actually believes this nonsense!)

http://www.pogowasright.org/article.php?story=20070907061312281

Stolen laptop contained data on De Anza students

Friday, September 07 2007 @ 06:13 AM CDT Contributed by: PrivacyNews News Section: Breaches

De Anza College warned Thursday that a laptop swiped from a math teacher's home contained personal information - including many Social Security numbers - of about 4,375 students.

But the laptop and its personal information were password protected, according to a district spokeswoman, and there was no evidence that any of the information has been used.

Source - Mercury News



This article is worth reading...

http://seattletimes.nwsource.com/html/localnews/2003873008_mailfraud07m.html

Indictment here marks "new age" of ID theft

By David Bowermaster Seattle Times staff reporter

Like millions of computer users, Gregory Kopiloff used the file-sharing program known as LimeWire to swap digital content with people all over the world.

But federal prosecutors say Kopiloff, 35, was not only using LimeWire to download music, movies or video games.

The Seattle resident allegedly used the peer-to-peer network to infiltrate hundreds of people's hard drives and steal tax returns, student financial-aid forms and other sensitive personal data. According to a federal indictment, Kopiloff then used that information to create bogus credit-card and bank accounts and illegally purchased thousands of dollars in merchandise.

Authorities said they have identified at least 83 victims — most of whom have teenage children and did not know the file-sharing software was on their computer. But investigators also said they believe the number of people affected was in the hundreds.

... "We are entering a new age of identity theft," said Robert Boback, chief executive of Tiversa, a computer-security firm based in Pittsburgh that has conducted extensive research on peer-to-peer networks. "Tens of thousands of individuals make a living doing this."

Kopiloff was charged Thursday in U.S. District Court in Seattle with mail fraud, accessing a protected computer without authorization in order to further fraud, and two counts of aggravated identity theft.

... Also, early versions of LimeWire automatically exposed a user's entire hard drive to other users on the peer-to-peer network.

More recent versions create a "shared" folder where users can isolate music or video files they want to swap, but many viruses "effectively expand access to [other] areas of the disk drive," according to a search warrant.

To illustrate how criminals try to exploit such security holes, Boback conducted a demonstration during Thursday's news conference at the U.S. Attorney's Office in Seattle. Using his company's technology, he showed — in real time — searches being conducted on peer-to-peer networks. As the searches were entered, they scrolled rapidly along the screen of his laptop. Many clearly concerned music files and pornography, but interspersed were scores looking for files that contained terms such as "password" and "medical billing."



Follow-up

http://hosted.ap.org/dynamic/stories/C/COLLEGE_HACKING?SITE=VALYD&SECTION=HOME&TEMPLATE=DEFAULT

Alum Charged With Hacking Into Texas A&M

By MONICA RHOR Associated Press Writer Sep 7, 7:55 AM EDT

HOUSTON (AP) -- A recent graduate of Texas A&M University is charged with hacking into the school's computer system and illegally accessing information on 88,000 current and former students, faculty and staff members.

Luis Castillo must appear before a magistrate judge Wednesday.

Federal prosecutors said Castillo, who graduated in December with a computer science degree, accessed the system in February and caused more than $5,000 in losses to the university. The school had to hire extra staff to minimize damage.

Castillo was charged with felony reckless damage to a protected computer [I wonder if there is a tool (software) that helps you select the charge? Should be simple to program... Bob] and could face as many as five years in prison if convicted.

... Social Security numbers and bank account numbers were not accessed, and the breach did not allow entry into the school's financial system or payroll, officials said. No unauthorized changes to the records have been found.



Another follow-up..

http://www.pogowasright.org/article.php?story=20070906191359962

(follow-up) SAIC Second Quarter Profits Rise on Higher National Security Sales

Thursday, September 06 2007 @ 07:13 PM CDT Contributed by: PrivacyNews News Section: Breaches

Defense and national security contractor SAIC Inc. Thursday reported higher profit in the second quarter on sales of border patrol and port security technology and cost cutting measures. The San Diego-based company also said it spent $8 million in the quarter to deal with a security breach in July when it compromised personal information about more than half a million military personnel and their relatives when it transmitted information unencrypted.

Source - Associated Press Previous Coverage



Winning Customer loyalty?

http://slashdot.org/article.pl?sid=07/09/06/1935240&from=rss

1300 Unopened Fry's Rebate Forms Found In Dumpster

Posted by samzenpus on Thursday September 06, @05:22PM from the put-it-in-the-circular-file dept. Businesses It's funny. Laugh.

blackmonday writes "The Consumerist is reporting a find of 1,300 unopened rebate submissions in a dumpster belonging to Vastech, a rebate processor hired by Fry's Electronics. Vastech's management blames it on a bad employee."



Their PR Dept. deserves lots of credit for keeping their name in the news...

http://www.pogowasright.org/article.php?story=20070906134835120

Pfizer victim of spambots, says security company

Thursday, September 06 2007 @ 01:48 PM CDT Contributed by: PrivacyNews News Section: Businesses & Privacy

Home PCs aren't the only ones vulnerable to compromise. After all, the same people using machines at home are using them at work – and often lax security policies (or bad software) make it difficult or impossible to fully protect hundreds of workstations.

A humorous and glowing example of this is Pfizer, who has found themselves victim of spambots. The company, better known as the manufacturer of Viagra, has found their own inboxes flooded with spam for their own products. The reason is that machines on their internal network have become compromised by hackers on the outside and turned into spambots, churning out tons of email.

Source - TechSpot



About time! (Will it stick?)

http://www.bespacific.com/mt/archives/015896.html

September 06, 2007

Federal Court Strikes Down National Security Letter Provision of Patriot Act

ACLU press release: "A federal court today struck down the amended Patriot Act's National Security Letter (NSL) provision. The law has permitted the FBI to issue NSLs demanding private information about people within the United States without court approval, and to gag those who receive NSLs from discussing them. The court found that the gag power was unconstitutional and that because the statute prevented courts from engaging in meaningful judicial review of gags, it violated the First Amendment and the principle of separation of powers."



Another source for a Universal Guideline... Anyone want to do a paper or journal article?

http://www.bespacific.com/mt/archives/015906.html

September 06, 2007

DOT OIG Analysis of Loss of Control Over Sensitive Personally Identifiable Information

Analysis of Loss of Control Over Sensitive Personally Identifiable Information and Follow-up Actions to Strengthen its Protection, August 28, 2007. Correspondence (23 pages, PDF)

  • Summary: "On August, 28, 2007 we issued a memorandum on our analysis of the circumstances surrounding the July 27, 2006 theft of an OIG laptop from a government vehicle in Doral, Florida and a prior theft that had occurred on April 24, 2006 from a hotel conference room in Orlando, Florida. Both laptops contained Sensitive Personally Identifiable Information (SPII) information on 138,000 individuals that heightened their potential risk of identity theft. Following our notification of the July theft, Members of the Florida congressional delegation requested that we examine our procedures for handling and storing such information and identify steps we have taken to ensure that such a breach would not happen again...We identified three interrelated factors that contributed to the loss of our control over the sensitive personal information stored on the laptops:(1) measures taken to protect the physical security of the laptops were insufficient; (2) the data on the laptops had been decrypted to preserve the data during an upgrade to the OIG's information technology (IT) system; and (3) SPII databases were stored on laptop computers, which are inherently less secure than computers that operate in a centralized environment. The memorandum also sets forth the steps we have taken to improve the physical security of our laptops and improve how sensitive personal information is handled and stored."



It should be possible to structure your discovery request to be both reasonable and impossible to comply with...

http://www.bespacific.com/mt/archives/015894.html

September 06, 2007

Seek and Ye Shall Find? State CIOs Must Prepare Now for E-Discovery

NASCIO - Seek and Ye Shall Find? State CIOs Must Prepare Now for E-Discovery, September 2007: "In increasingly consolidated state technology environments, State CIOs may have heightened responsibility for the storage, preservation and retrieval of electronic information in response to e-discovery requests. Since government information is a knowledge asset, State CIOs must ensure the proper management of state information assets in addition to the technological infrastructure for locating and retrieving that information. This issue brief explains the impact for State CIOs of e-discovery requests and encourages State CIOs to pursue a holistic approach to enterprise records management as part of a team of state government stakeholders, including state legal counsel, archivists, records managers, and agency business leaders."



What would you expect them to say?

http://yro.slashdot.org/article.pl?sid=07/09/07/0047225&from=rss

Copyright Alliance Says Fair Use Not a Consumer Right

Posted by CowboyNeal on Thursday September 06, @11:12PM from the no-rights-make-a-wrong dept. Media Movies Music Television

KingSkippus writes "In response to a complaint to the FCC filed by the Computer and Communications Industry Association (CCIA) to change copyright warnings before movies and sporting events, Executive Director Patrick Ross of the Copyright Alliance tells us in an editorial that "fair use is not a consumer right." The Copyright Alliance is backed by such heavy-hitters as the MPAA, RIAA, Disney, Business Software Alliance, and perhaps most interestingly, Microsoft, who is also backing the CCIA's complaint."



What possible basis would Justice have for making these comments? Perhaps they could come back to this arguement when the US ranks in the top 100 countries for Internet speed?

http://www.washingtonpost.com/wp-dyn/content/article/2007/09/06/AR2007090601262.html

Feds OK Fee for Priority Web Traffic

The Associated Press Thursday, September 6, 2007; 12:22 PM

WASHINGTON -- The Justice Department on Thursday said Internet service providers should be allowed to charge a fee for priority Web traffic.

The agency told the Federal Communications Commission, which is reviewing high-speed Internet practices, that it is opposed to "Net neutrality," the principle that all Internet sites should be equally accessible to any Web user.

... The Justice Department said imposing a Net neutrality regulation could hamper development of the Internet and prevent service providers from upgrading or expanding their networks. It could also shift the "entire burden of implementing costly network expansions and improvements onto consumers," [Who pays for it now? The Tooth Fairy? Bob] the agency said in its filing.

... However, the agency said it will continue to monitor and enforce any anticompetitive conduct to ensure a competitive broadband marketplace.



Interesting, but I doubt I'd create such a fuss unless I was traveling with my lawyer... (I like their version of the DHS Security Levels. Perhaps we could make similar posters?)

http://www.cnet.com/8301-13739_1-9769089-46.html?part=rss&subj=news&tag=2547-1_3-0-5

Skip to the front of the airport security line

Posted by Chris Soghoian September 6, 2007 3:49 AM PDT Airport security

Attempts to assert your right to fly without ID can often be very frustrating, due to Transportation Security Administration and airport officials not knowing their own rules.



I'm teaching all of my classes at least partly (50%) online. What will life be like when these kids hit college?

http://hosted.ap.org/dynamic/stories/V/VIRTUAL_SCHOOLS?SITE=VALYD&SECTION=HOME&TEMPLATE=DEFAULT

Virtual Schooling Growing at K-12 Level

By BILL KACZOR Associated Press Writer Sep 7, 8:03 AM EDT

TALLAHASSEE, Fla. (AP) -- As a seventh-grader, Kelsey-Anne Hizer was getting mostly D's and F's and felt the teachers at her Ocala middle school were not giving her the help she needed. But after switching to a virtual school for eighth grade, Kelsey-Anne is receiving more individual attention and making A's and B's. She's also enthusiastic about learning, even though she has never been in the same room as her teachers.

Kelsey-Anne became part of a growing national trend when she transferred to Orlando-based Florida Virtual School. Students get their lessons online and communicate with their teachers and each other through chat rooms, e-mail, telephone and instant messaging.

"It's more one-on-one than regular school," Kelsey-Anne said.

... Virtual learning is becoming ubiquitous at colleges and universities but remains in its infancy at the elementary and secondary level, where skeptics have questioned its cost and effect on children's socialization.

However, virtual schools are growing fast - at an annual rate of about 25 percent. There are 25 statewide or state-led programs and more than 170 virtual charter schools across the nation, according to the North American Council for Online Learning.

Estimates of elementary and secondary students taking virtual classes range from 500,000 to 1 million nationally compared to total public school enrollment of about 50 million.

... Many policymakers approach virtual learning with dollar signs in their eyes, expecting big savings from schools that do not need buildings, buses and other traditional infrastructure.

"We should not, as stewards of public money, be automatically paying the same or even close to the same amount of money for a virtual school day as we pay for a conventional school day," said Florida Senate Education Committee Chairman Don Gaetz.

On the Net: Florida Virtual School: http://www.flvs.net

Education Sector: http://www.educationsector.org

North American Council for Online Learning: http://www.nacol.org



Geek stuff...

http://developers.slashdot.org/article.pl?sid=07/09/06/1527258&from=rss

Are Relational Databases Obsolete?

Posted by kdawson on Thursday September 06, @12:27PM from the long-in-the-tooth dept.

jpkunst sends us to Computerworld for a look at Michael Stonebraker's opinion that RDBMSs "should be considered legacy technology." Computerworld adds some background and analysis to Stonebraker's comments, which appear in a new blog, The Database Column. Stonebraker co-created the Ingres and Postgres technology while a researcher at UC Berkeley in the early 1970s. He predicts that "column stores will take over the [data] warehouse market over time, completely displacing row stores."



There are 44 vineyards and wineries in Colorado? Whod'a thunk it! I can see this type of site as a model for many “hobbies” or interests... (Bike trails, professional seminars, chili cook-offs, soccer games, even yard sales)

http://www.killerstartups.com/User-Gen-Content/winesandtimes--Find-A-Vineyard-Near-You/

WinesAndTimes.com - Find A Vineyard Near You

Planing on doing some wine tasting? Or are you curious to see if there are any vineyards in your area? Go to WinesAndTimes.com where you can search by state and see what type of wine events are going on in your area. WinesAndTimes.com uses the google map function to give you a visual image of where these wine events are. The map marks where; vineyards, wine festivals, wine associations and wine trails are located. Plan your trip and get directions from your home to the vineyards.

... Look through the calendar to see what events are happening this week. If you know of a vineyard that is not listed go to the feedback section and add it to the list. The information is updated regularly so you know when future events will take place. Search for vineyards and plan your trip with WinesAndTimes.com.

http://www.winesandtimes.com/wnt/index.php



Just because we can...

http://digg.com/videos/comedy/Video_Hundreds_of_Dogs_in_a_Public_Pool

Video - Hundreds of Dogs in a Public Pool! watch!

intheory.tv — Dogs take over the pool at the 4th annual Pooch Plunge held in Fort Collins, Colorado. City Park pool is open for the summer season and then closes for the rest of the season. Before the pool is drained our four-legged friends get to enjoy the pool. This August 19th - 20th, from 4pm to 5:30pm you could bring your pooch to the pool.

http://www.intheory.tv/?p=72