Tuesday, July 07, 2009

For your Security Manager

http://m.apnews.com/ap/db_16036/contentdetail.htm?contentguid=RlgBwBQn

Microsoft warns of serious computer security hole

JORDAN ROBERTSON

SAN JOSE, Calif. (AP) - Microsoft Corp. has taken the rare step of warning about a serious computer security vulnerability it hasn't fixed yet.

The vulnerability disclosed Monday affects Internet Explorer users whose computers run the Windows XP or Windows Server 2003 operating software.

It can allow hackers to remotely take control of victims' machines. The victims don't need to do anything to get infected except visit a Web site that's been hacked.

Security experts say criminals have been attacking the vulnerability for nearly a week. Thousands of sites have been hacked to serve up malicious software that exploits the vulnerability. People are drawn to these sites by clicking a link in spam e-mail.

The so-called "zero day" vulnerability disclosed by Microsoft affects a part of its software used to play video. The problem arises from the way the software interacts with Internet Explorer, which opens a hole for hackers to tunnel into.

Microsoft urged vulnerable users to disable the problematic part of its software, which can be done from Microsoft's Web site, while the company works on a "patch" - or software fix - for the problem.



There is a lot of open source “health” stuff already out there, but there is always a niche to be filled. Should make an interesting baseline for debate though...

http://news.cnet.com/8301-13505_3-10280095-16.html?part=rss&subj=news&tag=2547-1_3-0-5

Former Red Hat execs aim to open-source health care

by Matt Asay July 6, 2009 10:35 AM PDT

It was bound to happen. With the U.S. government promising truckloads of cash to overhaul the U.S. health care system, while simultaneously making positive noises around open source, it was just a matter of time before someone connected the dots.

That someone appears to be Joanne Rohde, former executive vice president of worldwide operations at Red Hat, who has launched the Axial Project, a stealth-mode start-up that aims to "combin[e] the principles of Open Standards and Open Source...to connect all the parties in the Health ecosystem safely and securely.



We want our employees to be happy! (It is better to look happy than to be happy.)

http://tech.slashdot.org/story/09/07/06/1722225/Railway-Workers-Get-Daily-Smile-Scans?from=rss

Railway Workers Get Daily Smile Scans

Posted by samzenpus on Monday July 06, @02:15PM from the *_* dept.

More than 500 workers at Japan's, Keihin Electric Express Railway, must have their faces scanned each morning to determine their optimum smile. The "smile scan" analyzes a smile based on facial characteristics, from lip curves and eye movements to wrinkles. After the program scans you, it produces a smile rating that ranges from zero to 100 depending on the estimated potential of your biggest smile. If your number is sufficient, you can go about your day grinning like a maniac. If your smile number is too low the computer will give you a message such as, "lift up your mouth corners" or "you still look too serious." Every morning employees receive a printout of their daily smile which they are expected to keep with them throughout the day.



Well, there goes all that hacker fun! This is a hot topic on the security blogs.

http://www.databreaches.net/?p=6003

SSN Relatively Easy to Predict

July 6, 2009 by admin Filed under Commentaries and Analyses, ID Theft, Of Note, U.S.

Over on PogoWasRight.org, I’ve posted about a study released by researchers Alessandro Acquisti and Ralph Gross of Carnegie Mellon University. The study has significant implications for the use of SSN and for protecting against identity theft, even though a government spokesperson responded by seemingly downplaying the findings and their implications.

If you would like to read additional coverage of the study, there are already about 100 news stories that have appeared since the study was posted online at 5 pm, including articles in the New York Times and Associated Press , as well as Wired. The press release on the study can be found here.

[From the Press Release:

The study findings will appear this week in the online Early Edition of the Proceedings of the National Academy of Science, and will be presented on July 29 at the BlackHat 2009 information security conference in Las Vegas.

… Because many businesses use Social Security numbers as passwords or for other forms of authentication — a use not anticipated when Social Security was devised in the 1930s — the predictability of the numbers increases the risk of identity theft.

[I found it here: http://www.pnas.org/content/early/2009/07/02/0904891106.full.pdf+html



I suspect the RIAA realizes what will happen if hundreds of geeks listen to their “facts” and “theories” Think of it as having “human BS detectors” helping with the case for free...

http://yro.slashdot.org/story/09/07/06/2034213/RIAA-Seeks-Web-Removal-of-Courtroom-Audio?from=rss

RIAA Seeks Web Removal of Courtroom Audio

Posted by ScuttleMonkey on Monday July 06, @05:48PM from the afraid-people-might-see-what-they-are-up-to dept.

suraj.sun writes to tell us that the RIAA has asked a federal judge to order the removal of what they are calling "unauthorized and illegal recordings" by Harvard University's Charles Nesson of pretrial hearings and depositions in a file-sharing lawsuit.

"The case concerns former Boston University student Joel Tenenbaum, who Nesson is defending in an RIAA civil lawsuit accusing him of file-sharing copyrighted music. Jury selection is scheduled in three weeks, in what is shaping up to be the RIAA's second of about 30,000 cases against individuals to reach trial. The labels, represented by the RIAA, on Monday cited a series of examples in which they accuse Nesson of violating court orders and privacy laws by posting audio to his blog or to the Berkman site."



I find articles like this one amusing. Think of it as a guide to screwing up, big time.

http://ralphlosey.wordpress.com/2009/07/05/inside-the-head-of-a-digital-pirate/

Inside the Head of a Digital Pirate

What goes on in the head of a digital pirate who is hauled into court? A recent case in New York gives us a pretty good idea. Arista Records LLC v. Usenet.com, Inc., 2009 WL 1873589 (S.D.N.Y., June 30, 2009). All images of Johnny Depp aside, tis not a pretty sight.



Does this make sense? Or is it another “Here's a new way to do it the old way” kind of wasted effort? Should be interesting to see if they can compete with FREE.

http://news.slashdot.org/story/09/07/06/198237/Google-Will-Star-In-New-Dow-Jones-News-Model?from=rss

Google Will Star In New Dow Jones News Model

Posted by ScuttleMonkey on Monday July 06, @05:05PM from the free-will-find-a-way dept. media news

An anonymous reader writes

"Dow Jones is getting set to launch a new aggregator, akin to Google News, which will charge Web users for access to high-quality journalism. 'The Journal is one of the many newspapers you might buy in one place and with one payment [...] Watch for it,' said Dow Jones CEO Les Hinton. However, rather than posing a threat to Google News, Andrew Keen, author and entrepreneur, says the aggregator will use Google as a critical partner. The only people who should be worried about this new model, says Keen, 'are all those lucky consumers who, over the last 15 years, have been getting their news for free.'"



If the app is free (or almost so) what's wrong with it? The decision should be based on time/cost savings and benefits.

http://blogs.computerworld.com/should_local_governments_back_the_iphone

July 6, 2009 - 11:23 A.M.

Should local governments back the iPhone?

Boston will soon have an official iPhone app allowing residents to send photos of neighborhood nuisances to City Hall and request action, the Boston Globe reports this morning, "making the filing of complaints quicker and easier for iPhone users."

Cool, yes. But fair?

… Actually, the app was the idea of a city tech worker who uses a BlackBerry. But he told the Globe the city decided on an app for the iPhone "mostly because of its sex appeal -- because it's new and it's hot."



Interesting to look at the old home town...

http://www.bespacific.com/mt/archives/021745.html

July 06, 2009

Google Maps Launches Enhanced Features for Real Estate Search

Google LatLong Blog: "The web is becoming increasingly indispensable to people looking for a new home to buy...from today, if you enter a query like <<homes for sale in san francisco>> on Google Maps, you'll see that we make it easy for you to see all your results on a map with a one-box that will take you to real estate listings... We've added lots of markers that will show not only the ten most relevant listings with pins on the map, but also show a small circle on every other listing in that area using the search results layer, so you can get a really good idea of the distribution of properties for sale. You can click on each marker and each small circle to get more detailed information about the property."



Imagine a similar project that is NOT inside Microsoft... That must scare them, so they are attempting to preempt others...

http://news.cnet.com/8301-13860_3-10280270-56.html?part=rss&subj=news&tag=2547-1_3-0-5

Microsoft's Gazelle browser takes a radical path

by Ina Fried July 7, 2009 4:00 AM PDT

Many people think that the browser is starting to replace the operating system as the center of the personal computer.

Naturally, the view that Windows is on a path to irrelevance is not one generally espoused by Microsoft. That said, at least some inside Redmond's walls argue that the Web browser needs to start acting more like an operating system.

… Microsoft first outlined Gazelle earlier this year, but has only recently started to detail its thinking. Wang plans to present a paper on Gazelle at the Usenix security conference next month, and last week Microsoft posted an article on its Web site explaining more about Gazelle.

… Microsoft is also trying to be clear that Gazelle is not the immediate replacement for Internet Explorer, which has been losing share to rivals, including Mozilla's Firefox and Apple's Safari. The company has yet to commit to commercializing Gazelle in any way, meaning it remains just one of scores of projects incubating inside the company's research labs.

Many outside Redmond, though, see the browser finally starting to take on the preeminence that many had assumed it might back in the early days of Netscape. Google's decision to offer Chrome, some think, was more about having an engine for running its Web applications and it was offering an alternative means for serving up traditional Web pages.



Some light summer reading...

http://books.slashdot.org/story/09/07/06/137217/Beautiful-Security?from=rss

Beautiful Security

Posted by samzenpus on Monday July 06, @02:56PM from the read-all-about-it dept. security

brothke writes

"Books that collect chapters from numerous expert authors often fail to do more than be a collection of disjointed ideas. Simply combining expert essays does not always make for an interesting, cohesive read. Beautiful Security: Leading Security Experts Explain How They Think is an exception to that and is definitely worth a read. The book's 16 chapters provide an interesting overview to the current and future states of security, risk and privacy. Each chapter is written by an established expert in the field and each author brings their own unique insights and approach to information security."

Keep reading for the rest of Ben's review.



A project for my Computer Security class – portable security.

http://www.techradar.com/news/software/applications/secure-your-identity-and-data-on-every-pc-you-use-613834

Secure your identity and data on every PC you use

Protect yourself with this essential portable security toolkit

By Nick Peers

It's hard enough keeping your own PC secure without worrying about other computers.

But if you do need to access the web, email or an important document on another computer, you need to be sure you're not compromising yourself by doing so.

With a portable flash drive, you can build a collection of portable tools that will keep your data and identity secure, plus help you ascertain if that PC is safe to use.


(Related) Mobile Security

http://news.cnet.com/8301-1035_3-10280533-94.html?part=rss&subj=news&tag=2547-1_3-0-5

FAQ: How to vanquish mobile spam

by Elinor Mills July 7, 2009 4:00 AM PDT

… I called the four major U.S. wireless carriers to find out exactly what they suggest their customers do when they get SMS spam. Here is what they said, along with some other basic questions and answers people may have about mobile spam.

Monday, July 06, 2009

How big is this one? Too complex (or to scary) for network news?

http://developers.slashdot.org/story/09/07/06/0353217/Goldman-Sachs-Trading-Source-Code-In-the-Wild?from=rss

Goldman Sachs Trading Source Code In the Wild?

Posted by ScuttleMonkey on Monday July 06, @08:31AM from the bunny-ball-ball dept. business court

Hangtime writes

"The world's most valuable source code could be in the wild. According to a report by Reuters, a Russian immigrant and former Goldman Sachs developer named Sergey Aleynikov was picked up at Newark Airport on July 4th by the FBI on charges of industrial espionage. According to the complaint, Sergey prior to his early June exit from Goldman copied, encrypted, and uploaded source code inferred to be the code used by Goldman Sachs to process in real-time (micro-seconds) trades between multiple equity and commodity platforms. While trying to cover his tracks, the system backed up a series of bash commands so he was unable to erase his history that would later give him away to Goldman and the authorities. So the question, where are the 32MB of encrypted files that Sergey uploaded to a German server?

[From the ZeroHedge article:

This week's NYSE Program Trading report was very odd: not only because program trading hit 48.6% of all NYSE trading, a record high at least since the NYSE keep tabs of this data, and a data point which in itself was startling enough to cause some serious red flags as I jaunt from village to village in what little is left of Europe's bison country, but what was shocking was the disappearance of the #1 mainstay of complete trading domination (i.e., Goldman Sachs) from not just the aforementioned #1 spot, but the entire complete list. In other words: Goldman went from 1st to N/A in one week.

… Another major question: do Goldman and the NYSE not have a fiduciary responsibility to announce to both shareholders and any interested parties if there has been a major security breach in their trading operations? Certainly this seems like a material piece of information: given that program trading accounted for 49% of all NYSE trading last week, and Goldman as recently as one week ago represented about 60% of all principal program trading, will this be called an issue threatening the National Security of the United States. Shouldn't all market participants be aware that there is some rogue code in cyberspace that can be abused by the highest bidder, who very likely will not be interested in proving the efficient market hypothesis?

… The complete affidavit can be downloaded from this post here



Coming soon to a country near you.

http://www.pogowasright.org/?p=1338

New cellphone laws in Zambia

July 5, 2009 by Dissent Filed under Businesses, Govt, Legislation, Non-U.S.

Experts have lambasted new laws to collect information about prepaid cellphone users, citing their “severe” privacy implications.

One academic described existing rules that forced operators to retain personal call data for a minimum of three years as “excessive”.

And as of last Wednesday the government will collect more data. Operators now have to obtain the full name, address and identity number of customers buying SIM cards for prepaid services. MTN, Vodacom and Cell C have been given 18 months to get this information from customers.

Read more in the Pretoria News.

[From the article:

… Charles Goredema, the head of organised crime research at the Institute of Security Studies in Cape Town, said he failed to see "any link between (the legislation) and combating organised crime".

He said the new law "contravened the right to privacy" and that the idea was to widen the amount of information accessible to police with no specific end other than to hoard as much data as possible.

… He also pointed out the confusion that would be caused if users swopped SIM cards en masse. "The system would then have no idea who it is actually tracking. It is, after all, ultimately tracking a SIM, not a person."

… Hosein views the three to five-year period as excessive.

"All the studies have shown that a minimum period of three months tends to be sufficient, with nine months at the maximum, three years is excessive. In fact, any retention period is excessive. Canada, the US, Australia, New Zealand, and a host of other countries have no retention period at all.

"And they all face the same challenges, so why the difference?" [None, but we will eventually point to their laws as justification for similar laws here. Bob]


(Related) We want a law like this one too, don't we?

http://www.livemint.com/2009/07/05204206/Data-protection-amendments-se.html?h=B

Data protection: amendments set the ball rolling on liability

Two of the major sectors of the Indian economy, IT and BPO, have access have access to personal data, yet there is no express legislation in place to deal with data protection

… Section 43A states that if a “body corporate” possessing, dealing or handling any “sensitive personal data or information” in a computer resource which it owns, controls or operates is negligent in implementing and maintaining “reasonable security practices and procedures”, and thereby causes wrongful loss or wrongful gain to any person, this body corporate will become liable to pay damages as compensation to the affected person.

The term “body corporate” is wide enough to include a company, a firm, sole proprietorship or other association of individuals engaged in professional or commercial activities. Then there is the question of what constitutes “reasonable security practices and procedures”.

… This essentially means that contracting parties could incorporate in their contract the level and extent of the security procedures, practices and protection that the disclosing party desires to put in place in order to protect its sensitive personal information. A breach of such provisions, if falling within the purview of section 43A, could make the receiving party liable to pay damages.


(Related) Takes a bit of reading to understand, but in short, the law is like swiss cheese...

http://www.databreaches.net/?p=5991

NV’s New Encryption Law Made Moot?

July 6, 2009 by admin Filed under Breach Laws, Commentaries and Analyses, Legislation, State/Local

Rebecca Herold of IT Compliance has a commentary on Nevada’s new encryption law and whether the state’s data breach law makes the encryption law moot. It begins:

On May 30, 2009, Nevada enacted a new law, SB 227, which will basically replace NRS 597.970 in January 2010.

In many ways the new law is an improvement over the much more vague, and brief, NRS 597.970. I want to focus here on an improvement, but something that still leaves much to interpretation; that is, what is meant by “encryption”?

According to NRS 205.4742,

“‘Encryption’ means the use of any protective or disruptive measure, including, without limitation, cryptography, enciphering, encoding or a computer contaminant, to: 1. Prevent, impede, delay or disrupt access to any data, information, image, program, signal or sound; 2. Cause or make any data, information, image, program, signal or sound unintelligible or unusable; or 3. Prevent, impede, delay or disrupt the normal operation or use of any component, device, equipment, system or network.”

Read more on IT Compliance.

[From the article:

So, what's the motivation for oranizations to actually use strong encryption if the breach law will not require the organizations to report a breach of PII that is simply scrambled? As the laws are written, an organization with a breach of simply scrambled PII would be liable for damages under SB 227, but according to SB 347 they wouldn't need to report such a breach, so who would know?



Can a technology as simple to use as Facebook seriously compromise security? Sure. But everybody is doing it. The wife shouldn't know anything too sensitive. Better most of this comes from them than just show up in the tabloids. Pick your favorite excuse...

http://www.pogowasright.org/?p=1319

Spy chief’s family details on Facebook

July 5, 2009 by Dissent Filed under Featured Headlines, Internet, Non-U.S.

The Daily Mail reports that personal and family details of Sir John Sawers, the new head of MI6, were exposed after his wife published intimate photographs and family details on her Facebook page. According to the paper, “Amazingly, she had put virtually no privacy protection on her account, making it visible to any of the site’s 200 million users who chose to be in the open-access ‘London’ network - regardless of where in the world they actually were.” The paper reproduced the photos in their paper after notifying the Foreign Office, who in turn, contacted Facebook to remove the family’s details. The exposed details reportedly included the location of his London residence and the whereabouts of his grown children.

Not everyone thinks this is a big deal in terms of a security breach, though. While The Times calls it a “major security breach,” and The BBC reports that some British politicians are calling the details a security lapse that leaves the incoming MI6 chief vulnerable to blackmail and criticism, others see the incident as no more than mildly embarrassing. The Guardian quotes Foreign Secretary David Miliband as reacting, “It’s not a state secret that he wears Speedo swimming trunks.” “Let’s grow up.”



We love our employees, we just don't trust them.

http://www.pogowasright.org/?p=1342

DSS takes employee monitoring to new level

July 5, 2009 by Dissent Filed under Non-U.S., Surveillance, Workplace

DSS Co Ltd, a Japanese firm that edits and processes digital maps based on survey data, started a service of recording the actions of factory workers for long hours and visualize them.

The tools used for collecting the data are (1) the “ankle sensor” to be attached to the leg of a worker for recording his or her movement, (2) the “milestone,” which will be installed in various places in the plant to know how long workers stay there and (3) the “small video camera” to be put in the chest pocket of the worker to record his or her action.

Read more and see photos of the devices on Tech-On!. Engadget’s Vladislav Savov comments:

Sure, you might find out Bob in accounting takes a really long lunch, but do you really need to spend $20,000 and piss off your entire workforce to prove that? Just stalk his Tweets and Facebook status updates like a good old-fashioned employer would do.


(Related) Maybe HP snooping at board member and reporter phone records wasn't so far outside the norm?

http://www.pogowasright.org/?p=1361

Deutsche Bank spied on employees

July 5, 2009 by Dissent Filed under Businesses, Non-U.S., Surveillance, Workplace

Germany’s biggest bank, Deutsche Bank, hired detectives to spy on its employees including a member of its supervisory board, managers and a shareholder, German magazine Der Spiegel reported.

The bank launched an internal inquiry at the end of May into potential breaches of data privacy law in connection with the affair, Spiegel said in its latest edition to be published Monday.

Chief executive Josef Ackermann promised a “zero tolerance” approach over the affair at an annual general meeting of the bank.

Detectives “kept an eye on the movements of these people, and made inquiries as to who they were meeting and when”, said Spiegel, which had seen a report by a law firm on the matter.

Read more in The Local (de)



Is this even possible?

http://www.pogowasright.org/?p=1384

Barring Internet access for criminals

July 6, 2009 by Dissent Filed under Court, Internet, Legislation, U.S.

Defendants in criminal proceedings are imposed conditions or restrictions when granted supervised release. Now with Internet crimes on the rise, United States (U.S.) courts are imposing the prohibition from accessing the Internet as condition of supervised release. The prohibition from accessing the Internet may be imposed as initial condition or may be added as modification of supervised release conditions. But, is this prohibition legal? and how does it fit federal sentencing guidelines? All those questions were answered by the IBLS INTERNET LAW specialists at ibls.com.

Read more on Ecommerce Journal.

[From the article:

The prohibition from accessing the Internet fits well the federal sentence guideline’s factors enumerated in 18 U.S.C. § 3553(a), when the underline crime was committed through the use of the Internet.



Everyone should understand this by now – but they don't

http://www.wired.com/techbiz/it/magazine/17-07/mf_freer

Tech Is Too Cheap to Meter: It's Time to Manage for Abundance, Not Scarcity

By Chris Anderson 06.22.09

… All this was possible because Alan Kay, an engineer at Xerox's Palo Alto Research Center in the 1970s, understood what Moore's law was doing to the cost of computing. He decided to do what writer George Gilder calls "wasting transistors." Rather than reserve computing power for core information processing, Kay used outrageous amounts of it for frivolous stuff like drawing cartoons on the screen. Those cartoons—icons, windows, pointers, and animations—became the graphical user interface and eventually the Mac. By 1970s IT standards, Kay had "wasted" computing power. But in doing so he made computers simple enough for all of us to use. And then we changed the world by finding applications for them that the technologists had never dreamed of.

Scarcity vs. Abundance Management

Scarcity Abundance

Rules Everything is forbidden unless it is permitted. Everything is permitted unless it is forbidden.

Social model Paternalism ("We know what's best") Egalitarianism ("You know what's best")


Profit plan Business model We'll figure it out

Decision

process Top-down Bottom-up

Organizational

structure Command and control Out of control

Free: The Future of a Radical Price Download the audiobook » (285 MB .zip)

(Related)

http://www.wired.com/techbiz/it/magazine/16-03/ff_free

Free! Why $0.00 Is the Future of Business


(Related) But I bet he won't invest in my anti-gravity research...

http://news.cnet.com/8301-19882_3-10279763-250.html?part=rss&subj=news&tag=2547-1_3-0-5

Steve Jurvetson: Only investing in the unknown

by Rafe Needleman July 6, 2009 3:59 AM PDT

Since I started covering start-ups for Red Herring back in 1998, no venture capitalist has entertained me as much, or made me as envious, as Steve Jurvetson of Draper Fisher Jurvetson. He's of the few real dilettantes in the field, and he actually makes money from a studied lack of focus.

In comparison, most tech VCs, including titans like Vinod Khosla (at Kleiner Perkins) and Marc Andreessen, who just launched a new fund, focus on industry segments or coherent visions for certain markets. Khosla, for example, is a modern industrialist currently investing in companies attached to renewable energy or green products. Andreessen is all about Web start-ups.

Jurvetson? If other people are investing in it, he thinks it's passe.



An interesting business model for my students to explore...

http://news.slashdot.org/story/09/07/05/1546214/We-Rent-Movies-So-Why-Not-Textbooks?from=rss

We Rent Movies, So Why Not Textbooks?

Posted by Soulskill on Sunday July 05, @12:26PM from the or-food dept. education

Hugh Pickens writes

"Using Netflix as a business model, Osman Rashid and Aayush Phumbhra founded Chegg, shorthand for 'chicken and egg,' to gather books from sellers at the end of a semester and renting — or sometimes selling — them to other students at the start of a new one. Chegg began renting books in 2007, before it owned any, so when an order came in, its employees would surf the Web to find a cheap copy. They would buy the book using Rashid's American Express card and have it shipped to the student. Eventually, Chegg automated the system. 'People thought we were crazy,' Rashid said. Now, as Chegg prepares for its third academic year in the textbook rental business, the business is growing rapidly. Jim Safka, a former chief executive of Match.com and Ask.com who was recently recruited to run Chegg, said the company's revenue in 2008 was more than $10 million, and this year, Chegg surpassed that in January alone."



A simple suggestion for my hacking students. Take control of remote computers for fun a profit! (Find the answers to the hacking final on my computer and guarantee yourself an “A”)

http://www.labnol.org/software/control-computer-with-email-or-sms/9229/

July 3, 2009

How to Remote Control your Windows PC with Email or SMS

… You first install the free TweetMyPC utility on any Windows PC and associate your Twitter account. The app will silently monitor your Twitter stream every minute for any desktop commands and if it finds one, will act upon it immediately. The initial version of TweetMyPC was limited to basic shutdown and restart commands, however the current v2 has a far more robust set of commands, enabling a far more useful way of getting your PC to carry out certain tasks especially when you’re AFK (Away From Keyboard).

Sunday, July 05, 2009

Another day when very little news gets reported – too busy with beer and hot dogs.


Polluters must face the Green Party and the RIAA get the Pirate Party...

http://news.slashdot.org/story/09/07/05/0714203/Pirate-Party-Coming-To-Canada?from=rss

Pirate Party Coming To Canada

Posted by timothy on Sunday July 05, @05:08AM from the but-the-vikings-hit-canada-hundreds-of-years-ago dept. media politics

An anonymous reader writes

"After scoring a surprise electoral win in Sweden and getting high-profile support in Germany, The Pirate Party is coming to Canada. The party's goals are fairly simple. People should have the right to share and copy music, movies and virtually any material, as long as it is for personal use, not for profit. It opposes government and corporate monitoring of Internet activities, unless as part of a criminal investigation. It also wants to phase out patents."


(Related) “Oh what a tangled web we weave, When first we practice to deceive” You know there will be a reaction, you know it probably will not be organized and the odds of it changing the laws are similar to winning the lottery five times in a row...

http://yro.slashdot.org/story/09/07/04/1638223/Study-Deconstructs-Canadian-Copyright-Lobby-Deception?from=rss

Study Deconstructs Canadian Copyright Lobby Deception

Posted by Soulskill on Saturday July 04, @02:19PM from the anatomy-of-a-slow-con dept. internet

An anonymous reader writes

"A new Canadian study deconstructs how copyright lobby groups manipulate public opinion by laundering proposals through seemingly independent groups. The study started after the Conference Board of Canada was shown to have plagiarized several of its IP reports and now shows the connections that all lead through the MPAA and RIAA. Michael Geist writes, 'It is not just that these reports all receive financial support from the same organizations and say largely the same thing. It is also that the reports each build on one another, creating the false impression of growing momentum and consensus on the state of Canadian law and the need for specific reforms.'"



Everyone look up!

http://science.slashdot.org/story/09/07/04/2230220/Space-Station-Marathon-Starting-This-Weekend?from=rss

Space Station Marathon Starting This Weekend

Posted by timothy on Saturday July 04, @11:02PM from the this-calls-for-a-twitter-mashup dept. space nasa usa science

RobGoldsmith writes with this snippet from Space Fellowship:

"If you've never seen a spaceship with your own eyes, now's your chance. The International Space Station (ISS) is about to make a remarkable series of flybys over the United States. Beginning this 4th of July weekend, the station will appear once, twice, and sometimes three times a day for many days in a row. No matter where you live, you should have at least a few opportunities to see the biggest spaceship ever built."

[Get specific times here: http://spaceflight1.nasa.gov/realdata/sightings/



Now that I have your attention...

http://news.yahoo.com/s/ap/20090703/ap_on_fe_st/as_odd_new_zealand_flying_nude

New Zealand airline issues nude safety video

By RAY LILLEY, Associated Press – Fri Jul 3, 7:37 am ET

WELLINGTON, New Zealand – New Zealand's national airline has adopted a cheeky way to encourage passengers to watch its in-flight safety video: The cabin crew's uniforms are nothing but body paint.

http://www.youtube.com/watch?v7-Mq9HAE62Y&featureresponse(underscore)watch



Amusement

http://www.makeuseof.com/tech-fun/web-site-story-hilarious-internet-musical/

http://www.makeuseof.com/tech-fun/microsoft%E2%80%99s-vision-of-the-future-parody/

Saturday, July 04, 2009

Very slow news day. You'd think it was a holiday.


Next time someone tells you Apple is hacker-proof, laugh.

http://www.databreaches.net/?p=5972

Apple Learning Initiative security breach

July 3, 2009 by admin Filed under Breach Incidents, Business Sector, Hack, U.S.

The mothership is alerting members of this online program and forums that their account credentials, login and password, have been compromised. Although such events are common enough elsewhere on the interwebs, it’s quite unusual for one to affect Apple.

The email sent to members was included in the post:

Dear Apple Learning Interchange member,

We recently learned that the security of Apple Learning Interchange (ALI) members’ names and passwords may have been compromised. These accounts are limited to accessing the ALI discussion board and do not contain sensitive information such as credit card or social security numbers.

If you use this name and password combination on other websites and services, you may risk vulnerability on those sites. We strongly recommend that you change your password on any site that might have the same name and password combination.

We apologize for the inconvenience, and thank you for your continued participation in ALI.

Sincerely,
The Apple Learning Interchange Team

Read more on Blorge. The the Apple Learning Initiative website is still offline at the time of this posting.



Is it because the lawyers rely on Wikipedia themselves? Perhaps I should write “How to win as a prosecutor” and correct this chink in the armor of justice!

http://news.slashdot.org/story/09/07/04/0038243/UK-Police-Told-To-Use-Wikipedia-When-Preparing-For-Court?from=rss

UK Police Told To Use Wikipedia When Preparing For Court

Posted by Soulskill on Saturday July 04, @12:06AM from the citation-needed dept.

Half-pint HAL tips news of UK prosecution lawyers who are instructing police to study information on Wikipedia when preparing to give expert testimony in court.

"Mike Finn, a weaponry specialist and expert witness in more than 100 cases, told industry magazine Police Review: 'There was one case in a Midlands force where police officers asked me to write a report about a martial art weapon. The material they gave me had been printed out from Wikipedia. The officer in charge told me he was advised by the CPS to use the website to find out about the weapon and he was about to present it in court. I looked at the information and some of it had substance and some of it was completely made up.' Mr. Finn, a former Metropolitan Police and City of London officer and Home Office adviser, added that he has heard of at least three other cases where officers from around the country have been advised by the CPS to look up evidence on Wikipedia."



Now you can RTFM online!

http://www.makeuseof.com/dir/manualsonline-free-downloadable-manuals/

ManualsOnline: Lists Over 300,000 Free Downloadable Manuals

… You can browse manuals by product type, by brand or search with keywords. Simply enter the manufacturer/product name and model (ex: Apple iPhone 3G S) into the search field, click “Search” and download the relevant manual with one click without registration.

Sign up for an account to store and organize manuals online, upload your own manuals to the site and get help from site members with manual search and your product problems

www.manualsonline.com Similar sites: The Manuals and SafeManuals.



If it works in PowerPoint, it will work for my website students.

http://www.makeuseof.com/tag/10-websites-with-free-cool-media-clips-for-powerpoint/

10 Places To Get Cool Media Clips For PowerPoint Presentations

Jul. 3rd, 2009 By Saikat Basu

… There is a formulaic method behind creating a really great presentation, but it is an art too.

Slideshare is a good place to see some really cool works of PowerPoint ‘art’. Check under your favorite category and you will feel genuinely inspired to do things with the graphics, fonts, bullets, sounds and audio/video clips on the canvas of a PowerPoint slide.

… So here’s looking at 10 websites for free supplies of media clips for PowerPoint.

Friday, July 03, 2009

Today marks three years of (http://centennial-man.blogspot.com/) Blogging. That's 3 X 365 = 1095 days, averaging 10 articles per day that's 10,950 pithy comments.



A bit of analysis of the TJX settlement.

http://infoseccompliance.com/2009/07/02/tjx-settles-with-state-attorneys-general-for-975-million/

TJX Settles with State Attorneys General for $9.75 Million

Posted on July 2nd, 2009 by David Navetta

The TJX breach saga came a little closer to an end (excluding of course the still-pending case being pursued by a couple of issuing banks) with the announcement of a settlement with 41 State attorneys general that brought actions under their State’s respective consumer fraud and deceptive practices laws (a copy of the settlement document can be found: HERE). This is a summary of the TJX settlement.

… In addition to monetary payments, the settlement also requires TJX to “implement and maintain a comprehensive Information Security Program reasonably designed to protect the security, confidentiality and integrity of Personal Information.” The general description of the mandated program essentially matches the information security program required pursuant to TJX’s consent order with the FTC.

However, this settlement goes beyond the general requirements of the FTC’s consent order and mandates specific information security controls and actions, including:

  • Replacement of all WEP based wireless systems with WPA wireless systems (or equivalent)

  • No storage of sensitive authentication information related to payment cards (e.g. magnetic stripe track data, PIN numbers/PIN Blocks, and CVC2/CVV2/CID numbers)

  • Segmentation of TJX networks storing, processing or transmitting Personal Information (including Cardholder Information) from the rest of TJX’s network

  • “Security password management” for the portions of the TJX computer system that store, process or transmit Personal Information

  • Implementation of a security patching protocol for the portions of the TJX computer system that store, process or transmit Personal Information

  • Use of Virtual Private Networks/encryption for transmitting Personal Information

… As a condition of the settlement, TJX essentially has to advocate for improvements in the security of the payment card system. In particular, TJX must contact Visa and Mastercard and its acquiring bank and volunteer to participate in pilot programs for testing new security-related payment card technology (such as chip-and-PIN technology). TJX also must take steps encourage the payment card industry to achieve “end-to-end” encryption of cardholder data (all the way through the bank authorization process). TJX must take such steps within 180 days and must submit a report to the Attorneys General indicating TJX’s progress.



Stephen Rynerson sent me this article. (Looks like he reads the Physics blogs in his spare time.) This could be “the next big thing!” allowing true secure communications, until the little green hackers from Alpha Centauri arrive.

http://www.eurekalert.org/pub_releases/2009-07/iop-rut062909.php

Researchers unite to distribute quantum keys

Researchers from across Europe have united to build the largest quantum key distribution network ever built. The efforts of 41 research and industrial organisations were realised as secure, quantum encrypted information was sent over an eight node, mesh network.

… One of the first practical applications to emerge from advances in the sometimes baffling study of quantum mechanics, quantum cryptography has become a soon-to-be reached benchmark in secure communications.

… The researchers write, "In our paper we have put forward, for the first time, a systematic design that allows unrestricted scalability and interoperability of QKD technologies."


(Related) Why we might need unbreakable cryptography?

http://www.pogowasright.org/?p=1194

Cybersecurity plan to involve NSA, Ttelecoms

July 3, 2009 by Dissent Filed under Featured Headlines, Govt, Internet, Surveillance, U.S.

Since The Washington Post first broke the news that the Obama administration is moving ahead with Einstein, a Bush-era plan to use National Security Agency assistance in screening government computer traffic on private-sector networks, the drum beat from privacy advocates has been growing.

Today, Siobham Gorman of The Wall Street Journal reports that the latest complete version of the system won’t be fully installed for 18 months, and even when it is, the system won’t protect networks from attack but will only trigger an alarm after one has happened:

A more capable version has sparked privacy alarms, which could delay its rollout. Since the National Security Agency acknowledged eavesdropping on phone and Internet traffic without warrants in 2005, security programs have been dogged by privacy concerns. In the case of Einstein, AT&T Corp., which would test the system, has sought written approval from the Justice Department before it would agree to participate, people familiar with the matter say.

A side bar describes the three phases of Einstein:

  • Einstein 1: Monitors Internet traffic flowing in and out of federal civilian networks. Detects abnormalities that might be cyber attacks. [or the spike in traffic when Michael jackson died Bob] Is unable to block attacks.

    * Einstein 2: In addition to looking for abnormalities, detects viruses and other indicators of attacks based on signatures of known incidents, and alerts analysts immediately. Also can’t block attacks.

    * Einstein 3: Under development. Based on technology developed for a National Security Agency program called Tutelage, it detects and deflects security breaches. Its filtering technology can read the content of email and other communications.

The Associated Press notes that the planned deployment of the new Einstein 3 program was noted in the administration’s recently released cyber security review.



Win friends and influence people Do they think no one notices?

http://tech.slashdot.org/story/09/07/02/2255241/Microsoft-Changing-Users-Default-Search-Engine?from=rss

Microsoft Changing Users' Default Search Engine

Posted by timothy on Thursday July 02, @07:34PM from the now-what-did-we-say-about-playground-behavior? Dept. windows microsoft security

BabyDuckHat writes

"Cnet's Dennis O'Reilly caught 'Windows Search Helper' trying to change his default Firefox search from Google to Bing. T his isn't the first time the software company has been caught quietly changing user's preferences to benefit its own products."


(Related?)

http://blogs.computerworld.com/london_stock_exchange_to_abandon_failed_windows_platform

July 1, 2009 - 1:20 P.M.

London Stock Exchange to abandon failed Windows platform

Anyone who was ever fool enough to believe that Microsoft software was good enough to be used for a mission-critical operation had their face slapped this September when the LSE (London Stock Exchange)'s Windows-based TradElect system brought the market to a standstill for almost an entire day. While the LSE denied that the collapse was TradElect's fault, they also refused to explain what the problem really wa. Sources at the LSE tell me to this day that the problem was with TradElect.

Since then, the CEO that brought TradElect to the LSE, Clara Furse, has left without saying why she was leaving. Sources in the City-London's equivalent of New York City's Wall Street--tell me that TradElect's failure was the final straw for her tenure. The new CEO, Xavier Rolet, is reported to have immediately decided to put an end to TradElect.



The problem with using laws that almost apply?

http://news.cnet.com/8301-13577_3-10278483-36.html?part=rss&subj=news&tag=2547-1_3-0-5

Report: Guilty verdict overturned in MySpace suicide case

by Caroline McCarthy July 2, 2009 2:26 PM PDT

Lori Drew, the woman convicted of using a hoax MySpace profile to harass a teenage girl to the point of suicide, was acquitted by a Los Angeles judge on Thursday, Wired reported.

Judge George Wu overturned Drew's guilty verdict, which was issued in November, saying that if Drew had been convicted of a felony in the case, she would already have been sentenced. But because she was convicted of three misdemeanors--a significantly lighter offense than prosecutors originally sought--the constitutionality of the guilty verdict was less clear.



Interesting business model for a Venture Capital firm.

http://www.killerstartups.com/Web20/startupwiz-biz-a-laboratory-for-new-entrepreneurs

StartupWiz.biz - A Laboratory For New Entrepreneurs

http://www.startupwiz.biz/

StartupWiz introduces a new program of its own which prepares entrepreneurs and business owners to achieve a much greater level and probability of success. The program's series of 14 sequential modules goes well beyond the traditional MBA courses and startup ‘boot-camps' available. It takes the student from "Am I really prepared to be an entrepreneur?" to "I'm ready to pitch my compelling business case to sophisticated investors or bankers". Each module includes a downloadable offline training presentation and keyed workbook for the topic, followed by a fast-paced interactive "WebShop" online to explore and test their ideas. Students learn at their own pace and from the comfort of their homes, enabling family members and friends to participate in the entrepreneurial process with them. They can even postpone their next module until they've done more ground work, and then pick up where they left off.

The program begins with students exploring their underlying motivations and expectations of the startup process and their desired outcome. Next they examine the entire set of success criteria for doing business in today's tough economy. Students then build a comprehensive and compelling business model. Under the guidance of seasoned entrepreneurs students are continuously challenged to think critically about their plans and assumptions throughout the process. Those who complete the program get the opportunity to present their tested plan online to qualified investors world-wide. Students come away with a test presentation, executive summary, a ‘PlayBook' covering their whole business case, and a much stronger confidence in the viability of their business model and their ability to execute it.

"You wouldn't start laying bricks or putting up framing for a custom home before you architected it, so why build your business before you design it?" said Rudi Wiedemann, founder and CEO of StartupWiz. "Thinking at a strategic level about your new business model before you bet your job and savings on it is the smart move. Unfortunately, this is difficult work and few entrepreneurs have the patience to do it. But the savings in time, money, grief and reputation can be enormous."

Investors looking for a source of better quality fundable deals will appreciate business models and management teams that have been ‘shaken out' more thoroughly before approaching them for money. Experienced business executives have a new avenue to participate in hot new startups. Professional service providers can contribute to startups and potentially gain new clients. Business educators have a new place to send those graduates ready to take the entrepreneurial plunge.

Registration to StartupWiz is free and provides members valuable resources including PodCasts, downloads, links, templates and other tools which are constantly being updated and expanded.



For DaVinci Code fans? Something to add to the search tool folder

http://www.makeuseof.com/dir/symbols-look-up-symbols/

Symbols: Look Up Symbol Meanings

If you come across a symbol or sign and don’t know what it means, head straight to Symbols.com. It is a web resource where you can easily look up symbols and read their meanings. The site currently lists around 2500 western (modern and ancient) symbols organized in 54 categories.

There are four ways you can search for symbols:

  1. Simple keyword search.

  2. Use graphic index tool that searches symbols based on symmetry, shape and crossing lines.

  3. Use word index to find a symbol with a certain meaning.

  4. Check out a random sign.

www.symbols.com



Is this the “e-version” of sports fans chatting at a bar?

http://howto.wired.com/wiki/Follow_The_Tour_De_France_Online

Follow The Tour De France Online

From Wired How-To Wiki

The 2009 edition of the Tour de France -- the premiere event on the pro cycling calendar and the oldest of the three grand tours -- kicks off Saturday, July 4 with a short time trial in Monaco.

… Here are our tips for getting your Tour fix online.

This page is a wiki. Got extra advice? Log in and add it!

Contents

Thursday, July 02, 2009

If they knew in February and there has been no fraud, why would they replace the cards now?

http://www.databreaches.net/?p=5900

Heartland Breach Affects OPFCU

July 1, 2009 by admin Filed under Financial Sector, Hack, ID Theft, Malware, U.S.

And the impact of the Heartland Payment Systems breach continues:

Having police officers around didn’t prevent this credit union from having to deal with a data breach.

The Omaha Police Federal Credit Union is replacing 1,167 of its customers’ debit cards after being notified that the card numbers were among those involved in the data breach at Heartland Payment Systems of Princeton, N.J.

Mary Johnson, credit union president, said her staff members have been monitoring card activity while the new cards are being issued and have found no instances of fraud or loss. Credit union members are receiving the new cards before the old ones are deactivated, she said.

Read more in The Omaha World-Herald.

Once again, though, a news report doesn’t tell us when the credit union was first made aware that those card numbers were involved in the breach. Were they notified in February and are first taking action now or were they just recently notified?



What level of cooperation is proper?

http://www.pogowasright.org/?p=1086

Warrantless searches: MySpace, Yahoo and ATT

July 1, 2009 by Dissent Filed under Govt, Internet, Surveillance

An email purporting to be from Mike Duffey, Special Agent, Florida Department of Law Enforcement Computer Crime Center, to the ICAC Task Force mailing list was posted on Wikileaks.org. The email is reportedly from June 2009. The full header is not provided:

From: Duffey, Mike
Sent: None
To: ICAC.Task.Force
Subject: RE: Att refuses legal process in exigent situation- UPDATE!! and concerns

Thank you to everyone who responded. Below is an update with some concerns that based on the responses we received some of you have had.

First let me layout the scenario: Wed night- June 24th we received information that an individual using a yahoo screen name had discussed in detail recently molesting his six year old daughter in an incest forum then chatting on yahoo instant messenger. We began attempting to identify this individual. We discovered a MySpace page associated with the email address. Also on the Myspace, which was public was a name and photos of a girl with the same name as the one who was being molested. Also on the Myspace page was the photo of an adult female who had been tagged, which linked us to her public MySpace page, and had a caption under the photo saying “girlfriend”. Also at this time we were able to discover who we believed the potential targets were but based on info we were receiving we were not able to determine where the suspect was living due to multiple addresses. Later we discovered that our suspect had moved two weeks ago to where we ultimately found him.

We contacted MySpace claiming “exigent circumstances” for subscriber info and log in information for both MySpace using the users at they both had photos of the child victim on there pages with references to her being their child. MySpace responded to our request within 20 minutes and 45 minutes later we had the IP log-in info. Which came back with at least 15 different IP’s over the last 30 days, all belonging to ATT.

Problem Number 1. –Yahoo
In the mean time we were still waiting on Yahoo to respond to our initial request. Approximately three hours later yahoo responded by denying our exigent request. We then called Yahoo back and explained the situation to yahoo who understood the request but claimed they would not be able to obtain the IP log-in info until 48 hours after the log-in occurred. In this case we had info the abuse had recently occurred and need that IP log in within that 48 hour window. When we couldn’t get that we were forced to push back for IP info after the 48 hour window. After 7-hours they gave us the IP’s that were over 48 hours old. These IP’s also were assigned to ATT.

My Comment here is that I find it very hard to believe Yahoo, which collects your IP at the time of log in can’t provide LEO’s with IP log-in information until 48 hours later. In today security conscious environment its not weather they can its that they don’t want to and im sure they will site costs. I say they are actually helping facilitate criminal activity and hindering LEO’s ability to conduct a real time investigation.

Problem Number-2- ATT
We then contacted ATT around 9:00 am. We talked with [employee's name redacted] at ATT and explained to her the situation at hand. [employee] told us “it did not meet there requirement” and we need a subpoena to get that information. We again attempted to explain the situation and were told “ due to ECPA and their interpretation ATT was not allowed to release this information as to where the user of the IP was physically located at. We than began the legal process of getting a subpoena issued as we here in FL don’t have Admin subpoena powers and the process could take anywhere from 4-5 hours or longer. Upon posting on the listserve we received many, many contact names for ATT other than [employee] who basically of no help and didn’t really seem to care. We then contacted [employee 2] with ATT who also toed the company line and refused to provided the information without a subpoena. [employee 2] explained that if it was an exigent situation we would not be giving him IP addresses that were over 48 hours old, hence where is the exigency? We then explained that the IP had to be like that because Yahoo couldn’t provide us with current IP’s. It was at this point that we went to the only current IP we had which were from the MySpace info which was connected to the yahoo email address. We were still forced to get a subpoena after which ATT confirmed the address and subscriber name at 4pm.

My comment is on ATT interpretation of ECPA and that they sighted a prior issue where they provided subscriber info to an LEO. The case went to trial and at the trial ATT had to explain why they provided customer info to LEO’s in a non-exigent situation, thus the defense claimed. ATT said the info they provided was throw out and caused a bad case. ATT explained that is one example as to why they don’t just give out customer on old IP’s, which I explained the fact of why this was occurring and that a child we believed was being sexually abused. In the end they didn’t offer much help either as we had already developed enough intelligence to connect the suspect with a residence.

At 6pm we hit the residence. In the interview with the suspect he admitted to sexually molesting the child over the last two day and while doing so streamed it on webcam to other users. The child was interviewed and divulged the occurrence. Actually the suspect was to arrive home about ten minutes after we arrived. We can only imagine what would have occurred that evening. Why would it have been different than any other night.

To those who assisted thank you !!

I can only hope that one day ATT realizes that there interpretation of ECPA potentially could have hindered us to a point that the abuse could have occurred again. They are not by themselves there Yahoo in their inability to provide LEO with real time IP is equally to blame. Especially when they both could have been of more help!! I realize that they receive a lot of requests but they also make a lot of money from the people who use their systems.

Mike Duffey
Special Agent
Florida Department of Law Enforcement
Computer Crime Center



Perhaps we shouldn't give powerful tools like computers to people with no clue how to use them? By now you would think politicians would understand that emails are sensitive – and calling the police makes more sense than calling the IT department.

http://www.databreaches.net/?p=5933

PA Legislator’s Laptop Stolen from Car

July 1, 2009 by admin Filed under Breach Incidents, Government Sector, Theft, U.S.

A Pennsylvania state representative had his state-issued laptop stolen from his car over the past weekend. But State Rep. Frank Dermody may not be particularly concerned because, according to the Pittsburgh Tribune-Review, the legislator said no sensitive state data were on it.

Nothing “sensitive,” but an “undetermined number of e-mails from constituents” were on the stolen laptop? I wonder how his constituents feel about his lack of concern over their emails and any personal details they might have contained.

Dermody said that after the theft, he immediately contacted the legislature’s I.T. department, “which erased his password.” Horses and barn doors, anyone?



Better than a “National ID” program? “Papers, Citizen! We can't allow you to travel/enter a federal building/drive a car until we know you are healthy.”

http://www.pogowasright.org/?p=1096

Class Action Suit: Stimulus Act and health privacy

July 1, 2009 by Dissent Filed under Court, Legislation, U.S.

The Stimulus Act signed into law by President Obama jeopardizes the privacy rights of the 65 percent of Americans who aren’t on Medicaid or Medicare by requiring health-care providers to create an electronic health record of every person in the United States, a class action claims in Federal Court.

Because Title XIII of the Stimulus Act aims to have everyone’s medical histories in the system by 2014, their personal health information would be a “mouse click away from being accessible to an intruder,” according to lead plaintiff Beatrice M. Heghmann, a health-care professional who has never been covered by Medicare and Medicaid.

Heghmann sued Secretary of Health and Human Services Kathleen Sebelius, White House Office of Health Reform Director Nancy-Ann Deparle and Administrator of the Centers for Medicare and Medicaid Services Charlene Frizzera.

Read more in Courthouse News.

[From the article:

It also allows government officials to link a person's medical information with other forms of personal identification, such as a driver's license number or Social Security number, Heghmann says.

… She says the $22 billion earmarked for the electronic registry exists solely to obtain confidential health-care information.


(Related) Now that we know who you are, we need to know where you go... And we want you to pay us for tracking you!

http://tech.slashdot.org/story/09/07/01/1457243/GPS-Based-System-For-Driving-Tax-Being-Field-Tested?from=rss

GPS-Based System For Driving Tax Being Field Tested

Posted by Soulskill on Wednesday July 01, @11:37AM from the you-can-trust-us dept. transportation privacy

An anonymous reader writes

"Apparently, since gas consumption is going down and fuel efficient cars are becoming more popular, the government is looking into a new form of taxation to create revenue for transportation projects. This new system is a 'by-the-mile tax,' requiring GPS in cars so it can track the mileage. Once a month, the data gets uploaded to a billing center and you are conveniently charged for how much you drove. 'A federal commission, after a two-year study, concluded earlier this year that the road tax was the "best path forward" to keep revenues flowing to highway and transportation projects, and could be an important new tool to help manage traffic and relieve congestion. ... The commission pegged 2020 as the year for the federal fuel tax, currently 18.5 cents a gallon, to be phased out and replaced by a road tax. One estimate of a road tax that would cover the current federal and state fuel taxes is 1 to 2 cents per mile for cars and light trucks.'"



Move the workers someplace else, I need a bigger office. Actually a good move if you need to draw employees from an educated population or a population that speaks foreign languages (and English)

http://it.slashdot.org/story/09/07/02/0333202/NSA-To-Build-20-Acre-Data-Center-In-Utah?from=rss

NSA To Build 20 Acre Data Center In Utah

Posted by samzenpus on Thursday July 02, @07:57AM from the data-on-the-horizon dept. security database usa

Hugh Pickens writes

"The Salt Lake City Tribune reports that the National Security Agency will be building a one million square foot data center at Utah's Camp Williams. The NSA's heavily automated computerized operations have for years been based at Fort Meade, Maryland, but the agency began looking to decentralize its efforts following the terrorist attacks of Sept. 11, 2001 and accelerated their search after the Baltimore Sun reported that the NSA — Baltimore Gas & Electric's biggest customer — had maxed out the local grid and could not bring online several supercomputers it needed to expand its operations. The agency got a taste of the potential for trouble January 24, 2000, when an information overload, rather than a power shortage, caused the NSA's first-ever network crash taking the agency 3 1/2 days to resume operations. The new data center in Utah will require at least 65 megawatts of power — about the same amount used by every home in Salt Lake City so a separate power substation will have to be built at Camp Williams to sustain that demand. "They were looking at secure sites, where there could be a natural nexus between organizations and where space was available," says Col. Scott Olson, the Utah National Guard's legislative liaison. NSA officials, who have a long-standing relationship with Utah based on the state Guard's unique linguist units, approached state officials about finding land in the state on which to build an additional data center. "The stars just kind of came into alignment. We could provide them everything they need.""



This is rather depressing – the type of search I'd expect from devoted followers of supermarket tabloids...

http://www.killerstartups.com/Web-App-Tools/chromomulator-com-find-out-what-is-hot-on-the-www

Chromomulator.com - Find Out What Is Hot On The WWW

http://www.chromomulator.com/

There is so much happening on the Internet that it is a bit hard to stay on top of the hottest stories and media doing the rounds. That is where services such as Chromomulator step right in. They let you have access to only the crème of the crème as regards the stories and items featured on the Web. In the specific case of Chromomulator, it takes the top 100 Google searches at any given time by glancing at the Google Trends page, and complements it with information retrieved from Digg and Technorati. Using this information it produces a list of the hottest and most noteworthy online content around.



For my Computer Security class. Have fun with your neighbors!

http://lifehacker.com/5305094/how-to-crack-a-wi+fi-networks-wep-password-with-backtrack

How to Crack a Wi-Fi Network's WEP Password with BackTrack

By Gina Trapani, 9:30 AM on Wed Jul 1 2009

… Today we're going to run down, step-by-step, how to crack a Wi-Fi network with WEP security turned on.

… Dozens of tutorials on how to crack WEP are already all over the internet using this method. Seriously—Google it. This ain't what you'd call "news." But what is surprising is that someone like me, with minimal networking experience, can get this done with free software and a cheap Wi-Fi adapter.



I'm looking for a co-author (to do all the work)

http://gawker.com/5305024/exploiting-the-blog%2Bto%2Bbook-bubble-a-guide

Exploiting the Blog-to-Book Bubble: A Guide

By Alexia Tsotsis, 6:49 PM on Tue Jun 30 2009

Two blogs, [...] scored contracts at Penguin's Gotham Books imprint in the past week, the latest in an endless series of such deals. Shouldn't you get a piece of the action?

It's not like there's any shame in aiming for a book deal right when you start your blog. As the New York Observer puts it:

These days it seems more and more like people start goofy Web sites practically counting on seeing their stuff between two covers.