Monday, August 17, 2009

Gibberish is as gibberish does. “Allow me to explain, when we deezle the frum, kassele is a natural result.” It's just so technical!

http://www.databreaches.net/?p=6724

MP’s password accidentally leaked

August 17, 2009 by admin Filed under Breach Incidents, Exposure, Government Sector, Non-U.S.

Dizzy of the Dizzy Thinks blog was searching on Google for information on an article by Gisela Stuart MP for Birmingham Edgebaston and found a lot more than he expected. The results returned a link to an entry on the MP’s own web site which included her user name and password for managing the sites CMS.

According to the web design company responsible, the messages were the result of a data migration from a previous system resulting in the creation of twenty five rogue entries.

Read more on The H. Thanks to Brian Honan for this link.

[From the article:

The company says that the passwords were not valid on the new system, but that they had instituted an immediate security review to ensure such credential leaks do not occur again.

[From the Blog:

I called Gisela Stuart's Parliamentary office, then her constituency office, then handily I spotted the web design company was linked on the site so called them, The Social Media Partnership.

They took the matter seriously and have fixed it and changed the login credentials in less than half an hour - good work. [If they were invalid, why change them? Why not just delete them? Bob]



Ubiquitous Surveillance Everyone hates/fears/distrusts sex offenders, so they make a perfect test population. GPS monitoring is also used for “house arrest” and others not kept locked up. (and for cell phones, passports, drivers licenses, and the fillings in your teeth.)

http://www.pogowasright.org/?p=2864

Determining anchor points for sex offenders using GPS

August 17, 2009 by Dissent Filed under Govt, Surveillance

The California Department of Corrections and Rehabilitation (CDCR) has begun tracking more than 6,000 sex offender parolees by using global positioning system (GPS) anklets. Sex offender parolees are allowed to travel only through certain areas and must keep away from other people. The GPS device lets parole agents know when parolees are somewhere they should not be by logging GPS coordinates every minute and sending coordinates to a central server every 10 minutes. This information about parolee location is compared to law enforcement incident data through crime-scene correlation reports. Regular e-mail reports keep analysts notified of any incidents that are close to an offender’s tracks in time and space. The features are accessible through an online mapping application, and analysts can review a parolee’s GPS data for up to 4 hours at a time, or view data in real time (with a 15- minute delay). [No doubt to protect their “Privacy” Bob]

Read more on Corrections.com

[From the article:

Parolees must charge the anklet twice a day, [Batteries? Bob] and parole agents must respond to notifications if the parolee enters or leaves an inclusion zone during the prescribed times. Furthermore, the parole agent must keep track of a parolee’s location in relation to new crimes and discuss any possible infractions with the parolee. This keeps the parolee notified that his or her movements are being watched.



A simple example of the Dossier Problem. If our personal information is scattered in many databases on many sites, our perception is that no one would bother to make the effort to find it. Collect all that information in one place and you're a terrorist.

http://yro.slashdot.org/story/09/08/16/1146242/Woman-With-Police-Monitoring-Blog-Arrested?from=rss

Woman With Police-Monitoring Blog Arrested

Posted by Soulskill on Sunday August 16, @09:29AM from the there-are-better-hobbies dept.

Kris Thalamus writes

"The Washington Post reports that a Virginia woman is being held in custody by police who allege that information she posted on her blog puts members of the Jefferson area drug enforcement task force at risk. 'In a nearly year-long barrage of blog posts, she published snapshots she took in public of many or most of the task force's officers; detailed their comings and goings by following them in her car; mused about their habits and looks; hinted that she may have had a personal relationship with one of them; and, in one instance, reported that she had tipped off a local newspaper about their movements. Predictably, this annoyed law enforcement officials, who, it's fair to guess, comprised much of her readership before her arrest. But what seems to have sent them over the edge — and skewed their judgment — is Ms. Strom's decision to post the name and address of one of the officers with a street-view photo of his house. All this information was publicly available, including the photograph, which Ms. Strom gleaned from municipal records.'"



Suspicions confirmed! Not a tech problem, but the requirement to allow third party audit seems to be a deal breaker...

http://it.slashdot.org/story/09/08/17/0438207/Amazon-Confirms-EC2S3-Not-PCI-Level-1-Compliant?from=rss

Amazon Confirms EC2/S3 Not PCI Level 1 Compliant

Posted by timothy on Monday August 17, @02:31AM from the division-of-resources dept.

Jason writes

"After months of digging though speculation and polar opposite opinions from PCI experts, I finally sent a direct request to Amazon's AWS sales team asking if they are in fact PCI compliant and will provide documentation attesting that they are as is required by PCI guidlines. I fully expecting them to dodge the question and refer me to a QSA, but to my relief, they replied with a refreshingly honest and absolute confirmation that it is currently impossible to meet PCI level 1 compliance using AWS services for card data storage. They also very strong suggest that cardnumbers never be stored on EC2 or S3 as those services are inherently noncompliant. For now at least, the official verdict is if you need to process credit cards, the Amazon cloud platform is off the table."



Marketing Department Law. Any hacker knows, the trick is to use a neighbor's unsecured wireless connection to download anything likely to be traced by “those who sue”

http://www.pogowasright.org/?p=2855

UK Gov to prosecute parents of file sharers

August 17, 2009 by Dissent Filed under Featured Headlines, Internet, Legislation, Non-U.S.

The UK’s Peter Mandelson says that parents and other internet account holders must pay for illegal downloads of copyright material. But, in a move typical of the Labour party’s pandering to vested interests and potentially large supporters, the rights will be enforced in favour of the film and music industries. Independent producers of other copyright materials will be left out in the cold.

The move has dubious legality in any case: in principle, it is the same as the owner of a car being held liable for actions taken by a driver who uses it with the owner’s consent but the owners is not present.

Under Mandelson’s scheme, internet account holders will be liable if a user downloads covered copyright material.

Read more on The Chief Officers’ Network



Law West of the Pecos... Building alternate realities for jurors is a viable strategy, but you have to be a bit more subtle...

http://yro.slashdot.org/story/09/08/17/0449250/Microsoft-Trial-Misconduct-Cost-40-Million?from=rss

Microsoft Trial Misconduct Cost $40 Million

Posted by timothy on Monday August 17, @08:12AM from the at-least-he-wasn't-feeling-vindictive dept.

SpuriousLogic writes

"The judge who banned Microsoft from selling its Word document program in the US due to a patent violation tacked an additional $40 million onto a jury's $200 million verdict because the software maker's lawyers engaged in trial misconduct, court records reveal. In a written ruling, Judge Leonard Davis, of US District Court for Eastern Texas, chastised Microsoft's attorneys for repeatedly misrepresenting the law in presentations to jurors. 'Throughout the course of trial Microsoft's trial counsel persisted in arguing that it was somehow improper for a non-practicing patent owner to sue for money damages,' Davis wrote. The judge cited a particular incident in which a Microsoft lawyer compared plaintiff i4i, Inc. to banks that sought bailout money from the federal government under the Troubled Asset Relief Program. 'He further persisted in improperly trying to equate i4i's infringement case with the current national banking crisis implying that i4i was a banker seeking a "bailout,"' Davis said."



Hey! My Blog is for sale, make me an offer!

http://news.slashdot.org/story/09/08/16/1915219/Comcast-Seeking-Control-of-Both-Pipes-and-Content?from=rss

Comcast Seeking Control of Both Pipes and Content?

Posted by timothy on Sunday August 16, @03:32PM from the some-of-each-perhaps dept.

techmuse writes

"Reuters reports that Comcast may be attempting to use its huge cash reserves to purchase a large media content provider, such as Disney, Viacom, or Time Warner. This would result in Comcast controlling both the delivery mechanism for content, and the content itself. Potentially, it could limit access to content it owns to subscribers to its own services, thus shutting out competing services (where they still exist at all)."



September 19th is “Talk like a pirate” day. Anyone want to announce a Pirate Party in Colorado?

http://www.pogowasright.org/?p=2869

New UK Pirate Party “overwhelmed” by file sharing response

August 17, 2009 by Dissent Filed under Govt, Internet, Non-U.S.

New political party the Pirate Party UK said today it has been overwhelmed by the response to its formation, as the public gets behind its pro-file sharing agenda.

The organisation was registered as an official political party on 11 August by the Electoral Commission and has three core policies: the reform of copyright and patent law; the end of excessive surveillance by government and business; and to ensure freedom of speech.

Reports from various quarters have suggested that around 100 new members are signing up every hour to the party, but Eric Priezkalns, party treasurer, said he still needed to validate the figures about memberships received to date.

Read more on v3. Thanks to Brian Honan for this link.

Sunday, August 16, 2009

This is unlikely to be addressed. (We gotta DO something. It's for the children!) Unfortunately, I doubt this is the only area being trampled in the rush.

http://www.pogowasright.org/?p=2815

The FISMA challenge

August 15, 2009 by Dissent Filed under Featured Headlines, Legislation, U.S.

Carolyn Duffy Marsan has an informative piece on Government Health IT about the different requirements of different pieces of federal legislation and how they impact sharing federally held health data with the private sector. She writes, in part:

FISMA has 171 information security controls that are mandated for federal agencies. In contrast, the U.S. healthcare industry must meet the Health Insurance Portability and Accountability Act (HIPAA), which has only 101 of the FISMA controls.

“There is a gap of approximately 70 controls between FISMA and HIPAA,” Sankaran said. The challenge in healthcare information exchange is that data will be flowing from a more-secure FISMA- compliant federal system to a less-secure HIPAA-compliant private sector system.

“How do you make sure the information remains secure as it flows through two different domains of security controls?” Sankaran asked.

Among the questions that needs an answer from OMB is whether data that moves from a federal computer system to a private sector system is still considered federal data, and whether the recipient of that data needs to comply with FISMA. [Silly me, I thought it was MY data. Bob] “This requires clear guidance from OMB to the agencies’ Designated Approving Authorities (DAAs) about moving data between federal and private sector systems,” Sankaran said.

Read more on Government Health IT.



Perhaps we could take their advise?

http://www.pogowasright.org/?p=2818

NSWLRC recommends privacy cause of action

August 15, 2009 by Dissent Filed under Legislation, Non-U.S.

The NSW Law Reform Commission in a report released [Thursday] ( but dated April) recommends the state adopt a civil action for breach of privacy, but only as part of national law reform, so privacy law would be uniform throughout Australia. The report clarifies when an individual should be able to claim compensation and places limitations on the action. The Chairperson of the Commission, the Hon James Wood AO QC, said “the action is only applicable where an individual has a reasonable expectation of privacy that is not overridden by public interests such as freedom of speech. We advocate a common sense approach, whereby privacy interests are weighted against other important concerns such as the public’s ‘right to know’ and the protection of national security”. Despite this watch out for media types jumping from tall buildings.

Read more in Open and Shut.



Opening a can of worms wrapped in a fur ball while jumping into a rat's nest? Apparently they believe that changing the password locks everyone else out. WRONG The comments suggest the Sheriff is somewhat controversial. Might be nothing, might be amusing.

http://yro.slashdot.org/story/09/08/15/212254/Arizona-Judge-Tells-Sheriff-Reveal-Password-Or-Face-Contempt?from=rss

Arizona Judge Tells Sheriff "Reveal Password Or Face Contempt"

Posted by timothy on Saturday August 15, @05:33PM from the life-in-these-united-states dept.

An anonymous reader writes

"Four days ago, deputies from the Maricopa County Sheriff's Office in Arizona conducted a raid against the county government building hosting computers for a law enforcement database. After threatening to arrest county employees who would stop them, the officers proceeded to secure the room and promptly changed passwords on many of the servers. [I doubt this serves any legal purpose. Bob] In a hearing on Friday, a Superior Court judge threatened to hold members of the Sheriff's Office in contempt if they did not reveal the passwords by next Wednesday. Following this, the Sheriff's Office claimed to be conducting an investigation against other Superior Court judges. Courts have asked for passwords before, but never under conditions like this."



There are a number of Web2.0 guides for various professions. Nothing terribly new other than who is asking. (This is better done as a series of “Here's how it works” seminars, allowing individuals to innovate freely.)

http://www.bespacific.com/mt/archives/022061.html

August 15, 2009

DoD Web 2.0 Guidance Forum

DoD Web 2.0 Guidance Forum - Value of Web 2.0 Capabilities: "In examining how the Department of Defense should take maximal advantage of Web 2.0 capabilities (including social networking services, social media, wikis, blogs, RSS feeds, etc.), we are looking at how Web 2.0 capabilities can be used to improve current and future Department operations. Operations in this sense include both broad business and warfighting processes. Specifically, we are looking for insight from various Defense interest groups and think tanks, including Veterans groups, industry groups and individuals who have insights they can share regarding how Web 2.0 capabilities can be used to transform how the Defense Department operates."

Saturday, August 15, 2009

Local doesn't mean small...

http://www.bizjournals.com/denver/stories/2009/08/10/daily87.html

Arrests made in bank fraud probe

Friday, August 14, 2009, 1:32pm MDT Modified: Friday, August 14, 2009, 4:13pm

Denver Business Journal - by Renee McGaw

Federal authorities arrested four people and searched more than a dozen locations in the Denver metro area Friday morning as part of an investigation into a criminal fraud ring that may have cost multiple banks more than $80 million.

… In a complaint filed Friday in U.S. District Court, the FBI listed 16 people in the Denver metro area that it said it had probable cause to arrest, including Vishnevskaya and Nikitina.

But the investigation appeared to be much larger than that.

“To date, this investigation has identified approximately 700 straw buyers recruited by the criminal enterprise and financial losses are estimated to exceed $80 million,” according to the complaint filed in Vishnevskaya’s case

According to the complaint, the arrests stem from an FBI investigation that began in 2007 into alleged criminal rings in the United States.



No doubt Congress will want the US to “Catch up with the rest of the world”

http://www.pogowasright.org/?p=2796

Overseeing Surveillance - Lessons from the UK Experience?

August 15, 2009 by Dissent Filed under Non-U.S., Surveillance

In a previous post I pointed out the remarkable lack of transparency in the oversight of surveillance in Ireland. This has become all the more worrying since July when the remit of this oversight system was extended (by the Criminal Justice (Surveillance) Act 2009) beyond telephone tapping and data retention to include also the planting of covert audio bugs, video cameras and gps trackers. In effect, the Designated Judge has now been given (by ad hoc extensions of his role) oversight of most forms of surveillance - with public accountability in respect of this oversight remaining limited to a single page annual report. [That says: “Looks Okay to me!” Bob]

Two recently published documents from the UK illustrate a better model of oversight.

Read more on IT Law in Ireland.



For all you “Ubiquitous Surveillers” Now you can run a UAV inside your own home! Check on Grandpa! Make sure the kids are studying! See what the wife's making for dinner!

http://news.cnet.com/8301-17938_105-10309811-1.html?part=rss&subj=news&tag=2547-1_3-0-20

Robo-copter can navigate inside your home

by Tim Hornyak August 14, 2009 1:20 PM PDT

Just when you were getting used to the idea of unmanned aerial vehicles patrolling the skies over your city, they're beginning to enter buildings.

This flying robot designed by a U.S.-German team recently won a contest in which the goal was to autonomously navigate inside a simulated nuclear power plant and find and image a control panel without the aid of a GPS.



Disclaimer! I am not recommending this hack! I merely point out that certain individuals (some of them my students) would find it quite amusing to hijack a politician's home computer (or one belonging to their children), download this collection, and then rat them out to the RIAA.

http://mediamemo.allthingsd.com/20090814/the-pirate-bay-still-hasnt-gone-legit-still-enjoys-poking-big-media-in-the-eye-how-to-get-a-675000-mixtape-for-free/

The Pirate Bay Still Hasn’t Gone Legit, Still Enjoys Poking Big Media in the Eye: The “$675,000 Mixtape”

by Peter Kafka Posted on August 14, 2009 at 6:00 AM PT

Remember how the rascals at file-sharing site The Pirate Bay, chastened by the Swedish courts, were going to straighten up and go legit? Going to have to keep waiting on that one.

A reminder of the site’s outlaw status is splashed up on the site’s front page right now, in the form of a feature promoting “DJ Joel’s $675,000 Mixtape,” which is supposedly “Approved by the RIAA,” the U.S. lobbying/litigating arm of the big music labels.

It’s not approved by the RIAA, of course. Instead, the feature steers visitors to a page that where they can illegally download 30 songs that just cost grad student Joel Tenenbaum $675,000. That’s the amount a federal jury decided he owed the RIAA after being found guilty of copyright violations for sharing the tunes via a filesharing network.



I should have seen this coming. We could have started a “Build you own Broadband” franchise, and sold do-it-yourself kits to anyone stuck in areas monopolized by 'do nothing' providers...

http://tech.slashdot.org/story/09/08/14/2233221/Major-Carriers-Shun-Broadband-Stimulus?from=rss

Major Carriers Shun Broadband Stimulus

Posted by Soulskill on Friday August 14, @07:10PM from the why-risk-their-monopolies dept.

jmcharry sends word that as the deadline looms for requesting broadband grants from the $4.7 billion available in stimulus funding, Comcast, Verizon, and AT&T are conspicuously absent from the list of applicants. Quoting the Washington Post: "Their reasons are varied. All three say they are flush with cash, enough to upgrade and expand their broadband networks on their own. Some say taking money could draw unwanted scrutiny of business practices and compensation, as seen with automakers and banks that have taken government bailouts. And privately, some companies are griping about conditions attached to the money, including a net-neutrality rule that they say would prevent them from managing traffic on their networks in the way they want. ... Yet those firms might be the best positioned to achieve the goal of spreading Internet access to underserved areas, some experts say." Reader Michael_Curator notes that while the major carriers may be holding back, there were still enough applications to slow government servers to a crawl, resulting in a deadline extension.



You know a technology has arrives when... I like it! The Old Sargents I knew were always saying “Here's how it really works...”

http://tech.slashdot.org/story/09/08/14/2258244/Army-Asks-Its-Personnel-to-Wikify-Field-Manuals?from=rss

Army Asks Its Personnel to Wikify Field Manuals

Posted by Soulskill on Friday August 14, @08:06PM from the now-adding-wikify-to-the-spellchecker-and-sighing dept.

Hugh Pickens writes

"The NY Times reports that the Army began encouraging its personnel — from the privates to the generals — to go online and collaboratively rewrite seven of the field manuals that give instructions on all aspects of Army life, using the same software behind Wikipedia. The goal, say the officers behind the effort, is to tap more experience and advice from battle-tested soldiers rather than relying on the specialists within the Army's array of colleges and research centers, who have traditionally written the manuals. 'For a couple hundred years, the Army has been writing doctrine in a particular way, and for a couple months, we have been doing it online in this wiki,' said Col. Charles J. Burnett, the director of the Army's Battle Command Knowledge System. 'The only ones who could write doctrine were the select few. Now, imagine the challenge in accepting that anybody can go on the wiki and make a change — that is a big challenge, culturally.' Under the three-month pilot program, the current version of each guide can be edited by anyone around the world who has been issued an ID card that allows access to the Army Internet system. Reaction so far from the rank and file has been tepid, but the brass is optimistic; even in an open-source world, soldiers still know how to take an order."



What's in it for them?

http://www.time.com/time/business/article/0,8599,1915112,00.html?iid=digg_share

Google and Microsoft: The Battle Over College E-Mail

By Jeremy Caplan Friday, Aug. 14, 2009

… Google now manages e-mail for more than 2,000 colleges and universities, enabling students to transform accounts capped at 100 mb into Google-managed inboxes that allow for 70 times as much mail. Microsoft also provides free Web-based mail for thousands of schools, including colleges in 86 countries.



Studying Twits

http://news.cnet.com/8301-13577_3-10310191-36.html?part=rss&subj=news&tag=2547-1_3-0-20

Study: Twitter is 40 percent 'pointless babble'

by Caroline McCarthy August 14, 2009 12:54 PM PDT

Surprise! A full 40.5 percent of posts on Twitter--or tweets, as they're called--can be classified as "pointless babble," according to a new study from Pear Analytics. Coming in second was "conversational," which the company says makes up 37.55 of all tweets.

There's some interesting stuff in there. Despite some Twitter critics' insistence that the microblogging service is loaded with self-promoters, Pear Analytics only classified 5.85 percent of tweets as "self promotion."

The other categories were "news" (3.6 percent), "spam" (also lower than I'd expect, at 3.75 percent), and "pass-along value" (8.7 percent).

[The White Paper: http://www.pearanalytics.com/wp-content/uploads/2009/08/Twitter-Study-August-2009.pdf



The persistence of viral videos. (Business Model: Offer a “sponsored” upload option for amateur videos so that IF your video goes viral, it is already “wrapped” in an advertising package. Give creators 90% of the profits and everyone will upload through you.)

http://adage.com/mediaworks/article?article_id=138472

YouTube's Back-Catalog Amateur Content KILLS Pro Content

Dumenco's Trendrr Chart of the Week

by Simon Dumenco Published: August 14, 2009

… What's it all mean? Funny toddlers and dorky dancing couples in all their non-monetizable glory will live forever -- draining money (for server costs) from YouTube/Google's coffers until the end of time. Because people will never, ever tire of them. Ever!



What don't you like about your browser? Here's a guy who can see how to fix any shortcoming you can think of...

http://tech.slashdot.org/story/09/08/14/1835247/Netscape-Founder-Backs-New-Browser?from=rss

Netscape Founder Backs New Browser

Posted by ScuttleMonkey on Friday August 14, @05:27PM from the making-web-development-harder dept.

wirelessjb writes to share that after a resounding defeat at the hands of Microsoft in the first major browser war of the mid 1990s, Marc Andreessen is looking to have another go at the market by backing a new startup called "RockMelt."

"Mr. Andreessen suggested the new browser would be different, saying that most other browsers had not kept pace with the evolution of the Web, which had grown from an array of static Web pages into a network of complex Web sites and applications. 'There are all kinds of things that you would do differently if you are building a browser from scratch,' Mr. Andreessen said. RockMelt was co-founded by Eric Vishria and Tim Howes, both former executives at Opsware, a company that Mr. Andreessen co-founded and then sold to Hewlett-Packard in 2007 for about $1.6 billion. Mr. Howes also worked at Netscape with Mr. Andreessen."

[From the article:

After Microsoft defeated Netscape, it controlled more than 90 percent of the browser market. Interest in browsers among technology companies waned and innovation ground to a halt. But in the last 18 months, the Internet browser has become a battleground again with giants like Google, Apple and Microsoft fighting one another.

The renewed interest in browsers is partly a result of the success of Mozilla, a nonprofit. The speedier, safer and more innovative Mozilla Firefox browser, introduced in 2004, has grabbed 23 percent of the market, and Microsoft’s share has dropped to 68 percent.

… On the company’s Web site, the corporate name and the words “coming soon” are topped by a logo of the earth, with cracks exposing what seems to be molten lava from the planet’s core. A privacy policy on the site, which was removed after a reporter made inquiries to Mr. Vishria, indicates the browser is intended to be coupled somehow with Facebook. Mr. Andreessen serves as a director of Facebook.

… Another browser, Flock, based on Firefox, already incorporates feeds from social networking sites.



Just in time for my Advanced Algebra class! (Anything to amuse my students)

http://science.slashdot.org/story/09/08/15/0019258/A-Mathematical-Model-For-a-Spreading-Zombie-Infestation?from=rss

A Mathematical Model For a Spreading Zombie Infestation

Posted by Soulskill on Friday August 14, @10:04PM from the integrating-by-parts dept.

cloude-pottier writes

"What do you do when zombies attack? Turn to a mathematician to come up with a model for the spread of a zombie infestation, of course! Students at Carleton University and the University of Ottawa have published a paper in a book titled Infectious Disease Modelling Research Progress detailing how to model the spread of a zombie population and various complications in managing the spread of the infestation. They even give humans a fighting chance in some cases! The original paper (PDF) can be found at their professor's website."

[A comment points to an online zombie simulation: http://kevan.org/proce55ing/zombies/

Friday, August 14, 2009

Does this fall under Surveillance or Data Breach or Data Mining or I Told You So?

http://www.pogowasright.org/?p=2777

Anonymization FAIL! Privacy Law FAIL!

August 14, 2009 by Dissent Filed under Other

Paul Ohm writes that he has uploaded his latest draft article entitled, “Broken Promises of Privacy: Responding to the Surprising Failure of Anonymization” to SSRN, where you can download a free copy of the article.

The Abstract:

Computer scientists have recently undermined our faith in the privacy-protecting power of anonymization, the name for techniques for protecting the privacy of individuals in large databases by deleting information like names and social security numbers. These scientists have demonstrated they can often “reidentify” or “deanonymize” individuals hidden in anonymized data with astonishing ease. By understanding this research, we will realize we have made a mistake, labored beneath a fundamental misunderstanding, which has assured us much less privacy than we have assumed. This mistake pervades nearly every information privacy law, regulation, and debate, yet regulators and legal scholars have paid it scant attention. We must respond to the surprising failure of anonymization, and this Article provides the tools to do so.

The issue has significant implications for all of us, particularly when we consider arguments that health and medical information will be shared without our direct consent because it will be “de-identified.”



Big Brother moves down under? Who gets to define “appropriate?”

http://tech.slashdot.org/story/09/08/14/0346249/Australian-ISPs-Soon-To-Become-Copyright-Cops?from=rss

Australian ISPs Soon To Become Copyright Cops

Posted by timothy on Friday August 14, @02:11AM from the classic-multitasking dept.

srjh writes

"In the Australian Federal Government's latest assault on the internet, draft legislation has been released that allows network operators to intercept communications to ensure that their networks are being 'appropriately used.' Such legislation is particularly important given the interference of Communications Minister Stephen Conroy in a recent copyright lawsuit against iiNet, one of the largest ISPs in the country. Conroy called prominent filtering opponent iiNet's inaction over copyright infringement 'stunning,' whereas iiNet claimed that it would be illegal under current Australian law to intercept its users' downloads. While this latest legislation appears to be a concession of that point, the government is said to be watching the case closely and along with attempts to introduce a three-strikes law in Australia, it appears the law will be changed if the government dislikes the outcome of the case. The internet villain of the year just continues to earn his title."



For my Lawyer/Hacker friends. No Copyright, no foul?

http://news.slashdot.org/story/09/08/14/1158247/Firefox-Plugin-Liberates-Paywalled-Court-Records?from=rss

Firefox Plugin Liberates Paywalled Court Records

Posted by kdawson on Friday August 14, @09:01AM from the free-as-in-beer dept.

Timothy B. Lee writes

"If you want to access federal court records, you're often forced to use PACER, a cumbersome, paywalled Web site run by the federal judiciary. My colleagues and I at Princeton's Center for IT Policy have released a new Firefox extension called RECAP that allows users to automatically upload the documents they download from PACER into a public archive hosted by the Internet Archive. It also saves users money by automatically notifying them if a document they're searching for is available for free from the public archive. Over time, we hope to build a comprehensive, free repository of federal court records that's available to everyone."



Records retention. How permanent can records be?

http://news.cnet.com/8301-21546_3-10309283-10253464.html?part=rss&subj=news&tag=2547-1_3-0-20

How long is long-term storage?

by John Webster August 13, 2009 1:31 PM PDT

There is a big disconnect between how long people think they should be storing data and how long they actual can. One group of vendors and academics is trying to change that.

Two years ago, the Storage Networking Industry Association's Data Management Forum reported the results of a landmark study that looked at the state of long-term storage, i.e. preserving a digital object for more than 10 years. Some disturbing results jumped out.

… A whopping 80 percent of the 276 organizations included in the study reported a need to retain electronic records for more than 50 years, so let's start there.

… So there's a big gap here. A group of concerned vendors and academic advisers have formed the 100 Year Archive Task Force under the auspices of the Storage Networking Industry Association's Data Management Forum wants to start filling the gap. You can follow their progress or become involved yourself here.



I think I need a lawyer... The development I've done in “Simulate the World” has been stolen. The game host has sold the predictive model to the CIA and now they want me to turn over 'all source code, notes and documentation.'

http://yro.slashdot.org/story/09/08/13/1821203/Making-the-Case-That-Virtual-Property-Is-a-Bad-Idea?from=rss

Making the Case That Virtual Property Is a Bad Idea

Posted by timothy on Thursday August 13, @03:07PM from the contrarians-just-can't-get-along dept.

pacergh writes

"Many legal commentaries on virtual property argue that it should exist. Others argue why it can exist. None seem to explicitly spell out what virtual property will look like or how it will affect online worlds. Lost in the technology love-fest are the problems virtual property might bring. The Virtual Property Problem lays out a model for what virtual property might look like and then applies it to various scenarios. This highlights the problems of carving virtual property out of a game developer's rights in his creation. From the abstract: '"Virtual property" is a solution looking for a problem.' The article explains the 'failure of property rights to benefit the users, developers, and virtual resources of virtual worlds.'"



Over reaction?

http://news.cnet.com/8301-19518_3-10309421-238.html?part=rss&subj=news&tag=2547-1_3-0-20

Social-networking ban for sex offenders: Bad call?

by Larry Magid August 13, 2009 3:12 PM PDT

The just-signed Illinois law banning sex offenders from social-networking sites might seem like a good idea to protect children, but it will have virtually no impact on their safety and could wind up making things worse.

… A January 2009 analysis of Pennsylvania cases by the Center for Safe and Responsible Internet Use found, during a four-year period, that "only eight incidents involved actual teen victims with whom the Internet was used to form a relationship," compared to 9,934 children who were sexually abused in a single year in that state.



Transparency is as transparency does “Hey, we're the government. We don't see this as unusual. Besides, Osama might try to use this site and we gotta be ready!”

http://news.slashdot.org/story/09/08/13/195235/18M-Contract-For-Transparency-Website-Released-mdash-But-Blacked-Out?from=rss

$18M Contract For Transparency Website Released — But Blacked Out

Posted by timothy on Thursday August 13, @03:59PM from the but-don't-worry-government-health-care-will-be-cheap dept.

zokuga writes

"The US government recently approved an $18 million contract for Smartronix to build a website where taxpayers could easily track billions in federal stimulus money, as part of President Obama's promise to make government more transparent through the Internet. However, the contract, which was released only through repeated Freedom of Information Act requests, is itself heavily blacked out. ProPublica reports: 'After weeks of prodding by ProPublica and other organizations, the Government Services Agency released copies of the contract and related documents that are so heavily blacked out they are virtually worthless. In all, 25 pages of a 59-page technical proposal — the main document in the package — were redacted completely. Of the remaining pages, 14 had half or more of their content blacked out.' Sections that were heavily or entirely redacted dealt with subjects such as site navigation, user experience, and everything in the pricing table. The entire contract, in all its blacked-out glory, is here."



Why secret? The Berkman Center at Harvard has been doing this openly for years. Certainly any geek would know what gets scanned and blocked and could list dozens of alternative communications methods.

http://yro.slashdot.org/story/09/08/14/0426247/US-Tests-System-To-Evade-Foreign-Web-Censorship?from=rss

US Tests System To Evade Foreign Web Censorship

Posted by timothy on Friday August 14, @08:12AM from the worthy-objective dept.

D1gital_Prob3 excerpts from a Reuters story that says

"The US government is covertly testing technology in China and Iran that lets residents break through screens set up by their governments to limit access to news on the Internet. The 'feed over email' (FOE) system delivers news, podcasts and data via technology that evades web-screening protocols of restrictive regimes, said Ken Berman, head of IT at the US government's Broadcasting Board of Governors, which is testing the system. The news feeds are sent through email accounts including those operated by Google, Microsoft's Hotmail, and Yahoo. 'We have people testing it in China and Iran,' said Berman, whose agency runs Voice of America. He provided few details on the new system, which is in the early stages of testing. He said some secrecy was important to avoid detection by the two governments."



Open Source is killing another golden goose? Where there appears to be enormous profit, there is enormous opportunity.

http://news.slashdot.org/story/09/08/13/1450220/Open-Textbooks-Win-Over-Publishers-In-CA?from=rss

Open Textbooks Win Over Publishers In CA

Posted by CmdrTaco on Thursday August 13, @12:18PM from the now-put-them-in-a-wiki dept.

Unequivocal writes

"Recently California's Governor announced a free digital textbook competition. The results of that competition were announced today. Many traditional publishers submitted textbooks in this digital textbook competition in CA as well as open publishers. An upstart nonprofit organization named CK-12 contributed a number of textbooks (all free and open source material). 'Of the 16 free digital textbooks for high school math and science reviewed, ten meet at least 90 percent of California's standards. Four meet 100 percent of standards.' Three of those recognized as 100% aligned to California standards were from CK-12 and one from H. Jerome Keisler. None of the publisher's submissions were so recognized. CK-12 has a very small staff, so this is a great proof of the power of open textbooks and open educational resources."



Data Mining/Data Analysis

http://radar.oreilly.com/2009/08/big-data-and-real-time-structured-data-analytics.html

Big Data and Real-time Structured Data Analytics

by Ben Lorica| @dliman

The emergence of sensors as sources of Big Data highlights the need for real-time analytic tools. Popular web apps like Twitter, Facebook, and blogs are also faced with having to analyze (mostly unstructured) data in near real-time. But as Truviso founder and UC Berkeley CS Professor Michael Franklin recently noted, there are mountains of structured data generated by web apps that lend themselves to real-time analysis:



Tools & Techniques Every now and then, a simple tool comes along that makes something else (Craigslist in this case) much more valuable.

http://www.killerstartups.com/Web-App-Tools/itsmysale-com-keep-an-eye-on-craiglist-all-the-time

ItsMySale.com - Keep An Eye On Craiglist All The Time

http://www.itsmysale.com/

We can define Its My Sale as a watching tool for Craiglist that serves many purposes, most notably an alert function that enables you to be the first to contact someone on Craigslist that is selling something that you have been actively looking for.

An account can be created for free through the main page of ItsMySale.com. From that point onwards, you can start using the CraigsWatch tool to be notified by e-mail when someone posts an ad on Craigslist that matches the keywords that you have specified beforehand.

… CraigWatch is a free tool

Thursday, August 13, 2009

There is a not so subtle difference between naive and gullible. Wouldn't you expect a CEO to know just how secure his data was?

http://www.databreaches.net/?p=6655

Heartland CEO on Data Breach: QSAs Let Us Down

August 12, 2009 by admin Filed under Breach Incidents, Commentaries and Analyses, Financial Sector

For Heartland Payment Systems Inc. CEO Robert Carr, the year did not start off well, to say the least.

In January, the Princeton, N.J.-based provider of credit and debit processing, payment and check management services was forced to acknowledge it had been the target of a data breach — in hindsight, possibly the largest to date with 100 million credit and debit cards exposed to fraud.

In the following Q&A, Carr opens up about his company’s data security breach. He explains how, in his opinion, PCI compliance auditors failed the company, how informing customers of the breach before the media had a chance to was the best response, and how other companies can avoid the pain Heartland has experienced.

Read more on Computerworld.

[From the article:

What have you learned in recent months regarding how exactly the burglars were able to get in? have investigators flagged in terms of the big security holes that were exploited?

Carr: "The audits done by our QSAs (Qualified Security Assessors) were of no value whatsoever. To the extent that they were telling us we were secure beforehand, that we were PCI compliant, was a major problem. The QSAs in our shop didn't even know this was a common attack vector being used against other companies. We learned that 300 other companies had been attacked by the same malware. I thought, 'You've got to be kidding me.' That people would know the exact attack vector and not tell major players in the industry is unthinkable to me. I still can't reconcile that."

How did the QSAs respond when you expressed this view?

Carr: "In the post-Enron environment, the auditors have contracts with clients that essentially absolve them of gross negligence. The false reports we got for 6 years, we have no recourse. No grounds for litigation. That was a stunning thing to learn. In fairness to QSAs, their job is very difficult, but up until this point, we certainly didn't understand the limitations of PCI and the entire assessment process. PCI compliance doesn't mean secure. We and others were declared PCI compliant shortly before the intrusions."


(Related) On the other hand...

http://www.databreaches.net/?p=6670

Opinion: Heartland CEO Must Accept Responsibility

August 13, 2009 by admin Filed under Breach Incidents, Commentaries and Analyses, Financial Sector

I just read Bill Brenner’s interview with Heartland Payment Systems’ CEO Bob Carr [Heartland CEO on Data breach: QSAs Let Us Down] and truthfully, my blood is boiling.

Basically, he’s throwing his QSA under the bus for the massive data breach that happened under his watch. Basically, because the QSA didn’t find anything, therefore he should be off the hook.

I say that’s a load of crap. It’s about time organizations suffering from a data breach owned up to the fact that they made a mistake. You see, the fine folks at Johnson and Johnson didn’t throw the pharmacy under the bus when Tylenol got poisoned in 1982, did they? NO! They accepted responsibility (even though it wasn’t their fault) and re-established trust with their customers.

This kind of response from Mr. Carr basically proves that organization has learned NOTHING from the data breach, which means inevitably it will happen again.

Read more of Mike Rothman’s commentary on CSO.



(Related) In that UPS also began encrypting after a breach. I wonder if they do it in the US too?

http://www.databreaches.net/?p=6657

UPS encrypts laptops and smartphones after data breach

August 12, 2009 by admin Filed under Breach Incidents, Business Sector, Non-U.S., Theft

Parcel service UPS has encrypted all its UK laptops and smartphones, following a breach of the Data Protection Act last year.

The firm has also signed an undertaking to assure the Information Commissioner’s Office that personal information will be kept securely in future.

An unencrypted, password-protected laptop was stolen from a UPS employees while on business abroad in October 2008.

The laptop, which was never recovered, contained the payroll data of 9,150 UK based employees, including personal, salary and bank details.

Read more on computing.co.uk

[From the article:

Password-protected laptops are not secure. [Interesting that (post-breach) organizations are recognizing the obvious. Bob]



It could mean that companies have figured out how to manage their way through the minefield.

http://it.slashdot.org/story/09/08/12/1454253/How-Much-Does-a-Reputation-For-Security-Matter-Anymore?from=rss

How Much Does a Reputation For Security Matter Anymore?

Posted by Soulskill on Wednesday August 12, @11:49AM from the eh-i'm-sure-they'll-patch-it-soon dept.

dasButcher writes

"We often hear that businesses risk their corporate reputations if they don't have adequate security. It's been a common refrain among those selling security technologies: protect your data or suffer the reputational consequences. But, as Larry Walsh points out, the evidence is against this notion. Even companies that have suffered major security breaches — TJX, Hannaford, etc. — have suffered little lasting damage to their reputation. So, does this mean that reputational concerns are simply bunk?"



How much does a reputation for customer surveillance matter? Another target for the e-Discovery folks?

http://www.mobilecrunch.com/2009/08/12/oh-by-the-way-the-palm-pre-phones-home-with-your-location/

Oh, By the way: The Palm Pre phones home with your location [Updated]

by Greg Kumparak on August 12, 2009

… When Debian developer Joey Hess started tinkering with webOS, he noticed that it was sending something to Palm once a day. Surely, Palm wasn’t sending anything too potentially incriminating without making it blatantly obvious to the user, right? Wrong.

Joey tore apart the data the Pre was transmitting, and there it was, smack dab at the top of the page:

{ “errorCode”: 0, “timestamp”: 1249855555954.000000, “latitude”: 36.594108, “longitude”: -82.183260, “horizAccuracy”: 2523, “heading”: 0, “velocity”: 0, “altitude”: 0, “vertAccuracy”: 0 }

That was Joey’s position at the time the data was sent, accurate to the same degree that the Google Maps application was.

Also included was a list of every application Joey used, along with how long they were used for (as measured by “launch” and “close” parameters), along with crashlogs.



Peer-to-peer systems don't just share music

http://news.slashdot.org/story/09/08/12/1533248/Man-Jailed-After-Using-LimeWire-For-ID-Theft?from=rss

Man Jailed After Using LimeWire For ID Theft

Posted by Soulskill on Wednesday August 12, @12:31PM from the guess-his-making-available-defense-didn't-work-either dept.

angry tapir sends along this excerpt from PC World:

"A Seattle man has been sentenced to more than three years in prison for using the LimeWire file-sharing service to lift personal information from computers across the US. The man, Frederick Wood, typed words like 'tax return' and 'account' into the LimeWire search box. That allowed him to find and access computers on the LimeWire network with shared folders that contained tax returns and bank account information. ... He used the information to open accounts, create identification cards and make purchases. 'Many of the victims are parents who don't realize that LimeWire is on their home computer,' [said Kathryn Warma of the US Attorney's Office]."



...because there is absolutely, positively no way using technology is harmless.

http://yro.slashdot.org/story/09/08/12/1817232/Illinois-Bans-Social-Network-Use-By-Sex-Offenders?from=rss

Illinois Bans Social Network Use By Sex Offenders

Posted by timothy on Wednesday August 12, @02:52PM from the good-feel-measure-vs.-bad-feel-felons dept.

RobotsDinner writes

"Illinois Governor Pat Quinn has signed into law a bill that bans all registered sex offenders from using social networks. '"Obviously, the Internet has been more and more a mechanism for predators to reach out," said Sen. Bill Brady (R-Bloomington), a sponsor of the measure and a governor candidate. "The idea was, if the predator is supposed to be a registered sex offender, they should keep their Internet distance as well as their physical distance." [Whatever we do in the real world, we should also do in the virtual world? Bob]



Undue reliance? It's so if the computer says it's so. Now we know where TSA got the idea for the no-fly list!

http://it.slashdot.org/story/09/08/12/2055208/Database-Error-Costs-Social-Security-Victims-500M?from=rss

Database Error Costs Social Security Victims $500M

Posted by timothy on Wednesday August 12, @05:18PM from the drop-in-the-bucket dept.

Hugh Pickens writes

"The Washington Posts reports that the Social Security Administration has agreed to pay more than $500 million in back benefits to more than 80,000 recipients whose benefits were unfairly denied after they were flagged by a federal computer program designed to catch serious criminals. At issue is a 1996 law, which contained language later nicknamed the 'fleeing felon' provision, that said fugitives were ineligible to receive federal benefits. As part of its enforcement, the administration began searching computer databases to weed out people who were collecting benefits and had outstanding warrants. The searches captured dozens of criminals, including some wanted for homicide, but they also ensnared countless elderly and disabled people accused of relatively minor offenses such as shoplifting or writing bad checks and in some cases, the victims simply shared a name and a birth date with an offender."

(Read more, below.)



Kerfuffle is us? We're a University – why would we think before we open our mouth?

http://news.slashdot.org/story/09/08/13/137252/US-Colleges-Say-Hiring-US-Students-a-Bad-Deal?from=rss

U.S. Colleges Say Hiring U.S. Students a Bad Deal

Posted by CmdrTaco on Thursday August 13, @09:27AM from the talking-to-you-cliff dept.

theodp writes

"Many U.S. colleges and universities have notices posted on their websites informing U.S. companies that they're tax chumps if they hire students who are U.S. citizens. "In fact, a company may save money by hiring international students because the majority of them are exempt from Social Security (FICA) and Medicare tax requirements," advises the taxpayer-supported University of Pittsburgh (pdf) as it makes the case against hiring its own U.S. students. You'll find identical pitches made by the University of Delaware, the University of Cincinnati, Kansas State University, the University of Southern California, the University of Wisconsin, Iowa State University, and other public colleges and universities. The same messsage is also echoed by private schools, such as John Hopkins University, Brown University, Rollins College and Loyola University Chicago."



Basil says this is a service worth look at, so is it worth investing in too?

http://www.techcrunch.com/2009/08/12/full-details-on-mints-14-million-series-c-round/

Full Details On Mint’s $14 Million Series C Round

by Jason Kincaid on August 12, 2009

Mint, the popular personal finance site that won 2007’s TechCrunch40 conference, has closed a new $14 million Series C funding round. Silicon Alley Insider discovered the round in an SEC filing this morning, and we’ve just gotten off the phone with CEO Aaron Patzer, who confirmed the deal and filled us in on the details.



Increasingly important, even for individuals...

http://lifehacker.com/5335553/free-tools-to-back-up-your-online-accounts

Free Tools to Back Up Your Online Accounts

By Gina Trapani, 9:00 AM on Wed Aug 12 2009



Humor or fact? Watch and decide!

http://www.techcrunch.com/2009/08/12/google-privacy-opt-out-announced-via-the-onion/

Google Privacy Opt Out Announced Via The Onion

by Michael Arrington on August 12, 2009

The Onion strikes again, announcing Google Opt Out today, a product that lets people opt out of Google’s information gathering activities by having their home destroyed and moving to a covered villiage complex at an undisclosed location. As always, they nail it. Video is below.

Wednesday, August 12, 2009

One side of the debate. Will the OMB share their arguments?

http://www.pogowasright.org/?p=2720

EFF’s recommendations for federal web privacy policy

August 11, 2009 by Dissent Filed under Govt, Internet, U.S.

Today, EFF and the Center for Democracy and Technology submitted comments to the Office of Management and Budget in response to the agency’s review of the policies governing the federal government’s use of cookies and other web technologies.

The comments are an extension of recommendations we made in May, in which we suggested that the OMB permit cookie-based web analytics so long as the process was carefully overseen and met with specific strict safeguards. Today, we’ve expanded our recommendations to include the use of cookies for creating individualized web account logins and other common web practices that we understand government webmasters would like to be able to use. Overall, we continue to urge the government to limit the use of any data collected, to eliminate this data as soon as possible, and to seek third-party oversight.

Read more on EFF (The Electronic Frontier Foundation).

Related: EPIC submitted comments to the Office of Management and Budget recommending that the existing ban on the use of cookies at federal government websites be maintained.



Strategy is as Strategy does... Worth reading the article!

http://www.pogowasright.org/?p=2726

What unites advocates of speech controls & privacy regulation?

August 12, 2009 by Dissent Filed under Other

Anyone who has spent time following debates about speech and privacy regulation comes to recognize the striking parallels between these two policy arenas. In this paper we will highlight the common rhetoric, proposals, and tactics that unite these regulatory movements. Moreover, we will argue that, at root, what often animates calls for regulation of both speech and privacy are two remarkably elitist beliefs:

  1. People are too ignorant (or simply too busy) to be trusted to make wise decisions for themselves (or their children); and/or, [Governments aer smart, people are not. Bob]

  2. All or most people share essentially the same values or concerns and, therefore, “community standards” should trump household (or individual) standards. [Xenophobia. If you're not with us, you're against us. Bob]

While our use of the term “elitism” may unduly offend some understandably sensitive to populist demagoguery, our aim here is not to launch a broadside against elitism as Time magazine culture critic William H. Henry once defined it: “The willingness to assert unyieldingly that one idea, contribution or attainment is better than another.”[1] Rather, our aim here is to critique that elitism which rises to the level of political condescension and legal sanction. We attack not so much the beliefs of some leaders, activists, or intellectuals that they have a better idea of what it in the public’s best interest than the public itself does, but rather the imposition of those beliefs through coercive, top-down mandates.

Read more of this commentary by Adam Thierer & Berin Szoka in The Progress & Freedom Foundation, Progress on Point No. 16.19 on The Technology Liberation Front or access the pdf version of the article.

Making it harder for us to convict you is a crime. Making it impossible to convict you is a capital crime. The only thing worse is being innocent.

http://it.slashdot.org/story/09/08/11/2340221/In-UK-Two-Convicted-of-Refusing-To-Decrypt-Data?from=rss

In UK, Two Convicted of Refusing To Decrypt Data

Posted by kdawson on Wednesday August 12, @05:31AM from the no-pleading-the-fifth dept.

ACKyushu clues us to recent news out of the UK, where two people have been successfully prosecuted for refusing to provide authorities with their encryption keys, resulting in landmark convictions that may have carried jail sentences of up to five years. There is uncertainty in that the names of the people convicted were not released; [Secret trials? Bob] and without those names, the Crown Prosecution Service said it was unable to track down details of the cases.

"Failure to comply with a section 49 notice carries a sentence of up to two years jail plus fines. Failure to comply during a national security investigation carries up to five years jail. ... Of the 15 individuals served, 11 did not comply with the notices. Of the 11, seven were charged and two convicted. Sir Christopher [Rose, the government's Chief Surveillance Commissioner] did not report whether prosecutions failed or are pending against the five charged but not convicted in the period covered by his report."



Hey, who ya gonna believe? A bunch of guys with PhDs or our Marketing Department? We've been working on your politicians... I means, explaining the evidence to your politicians and they agree with us. (Lots of comments)

http://it.slashdot.org/story/09/08/11/1642231/Voting-Machine-Attacks-Proven-To-Be-Practical?from=rss

Voting Machine Attacks Proven To Be Practical

Posted by kdawson on Tuesday August 11, @01:51PM from the back-up-the-dumpster dept.

An anonymous reader writes

"Every time a bunch of academics show vulnerabilities in electronic voting machines, critics complain that the attacks aren't realistic, that attackers won't have access to source code, or design documents, or be able to manipulate the hardware, etc. So this time a bunch of computer scientists from UCSD, Michigan, and Princeton offered a rebuttal. They completely own the AVC Advantage using no access to source code or design documents (PDF), and deliver a complete working attack in a plug-in cartridge that could be used by anyone with a few private minutes with the machine. Moreover, they came up with some cool tricks to do this on a machine protected against traditional code injection attacks (the AVC processor will only execute instructions from ROM). The research was presented at this week's USENIX EVT."


(Related)

http://www.wired.com/threatlevel/2009/08/diebold-audit-logs/

Diebold Quietly Patches Security Flaw in Vote Counting Software

By Kim Zetter Email Author August 12, 2009 8:00 am

Premier Election Solutions, formerly Diebold, has patched a serious security weakness in its election tabulation software used in the majority of states, according to a lab that tested the new version and a federal commission that certified it.

The flaw in the tabulation software was discovered by Wired.com earlier this year, and involved the program’s auditing logs. The logs failed to record significant events occurring on a computer running the software, including the act of someone deleting votes during or after an election. The logs also failed to record who performed an action on the system, and listed some events with the wrong date and timestamps.

… It’s not known if Premier will offer the more secure version to election officials who purchased previous software. The company did not respond to a call for comment Tuesday.



Another “the patent system is broken” article? Or perhaps a “Microsoft is evil” article? Or even a “Texas is a whole 'nother country” article.

http://news.slashdot.org/story/09/08/12/1129230/US-Court-Tells-Microsoft-To-Stop-Selling-Word?from=rss

US Court Tells Microsoft To Stop Selling Word

Posted by Soulskill on Wednesday August 12, @08:13AM from the somebody's-not-having-a-good-day dept.

oranghutan writes

"A judge in a Texas court has given Microsoft 60 days to comply with an order to stop selling Word products in their existing state as the result of a patent infringement suit filed by i4i. According to the injunction, Microsoft is forbidden from selling Word products that let people create XML documents, which both the 2003 and 2007 versions let you do. Michael Cherry, an analyst quoted in the article, said, 'It's going to take a long time for this kind of thing to get sorted out.' Few believe the injunction will actually stop Word from being sold because there are ways of working around it. [Sure to make the judge happy. Bob] In early 2009, a jury in the Texas court ordered Microsoft to pay i4i $200 million for infringing on the patent. ZDNet has a look at the patent itself, saying it 'sounds a bit generic.'"


(Related) If the software can copy an entire hard drive bit by bit (as e-Discovery tools do) would that tool now be illegal? Such copying does not “notice” what it is copying, does not “unprotect” a file, but can recreate the data exactly on another drive.

http://yro.slashdot.org/story/09/08/12/1220211/Judge-Rules-Against-RealDVD?from=rss

Judge Rules Against RealDVD

Posted by Soulskill on Wednesday August 12, @09:40AM from the another-one-bites-the-dust dept.

mattOzan writes

"Judge Marilyn Hall Patel was unswayed by RealNetworks' defense of their product under the Fair Use Doctrine, as she declared RealDVD illegal and barred its distribution. As she said in her ruling, 'So while it may well be fair use for an individual consumer to store a backup copy of a personally owned DVD on that individual's computer, a federal law has nonetheless made it illegal to manufacture or traffic in a device or tool that permits a consumer to make such copies.' She also said RealNetworks was aware of the conflict between their agreement and their plans for the software: 'Real did not elect to return (or destroy, with appropriate certification) the CSS General Specifications after it received them, as Real had a right to do under the agreement... This behavior indicates that Real understood it to be bound by the CSS General Specifications as well as the other technical specifications received after execution of the CSS License Agreement.'"

[The ruling: http://opinion.latimes.com/files/pi-order-081109.pdf

[From the ruling:

See Reimerdes, 111 F.Supp.2d at 324 (“The fact that Congress elected to leave technologically unsophisticated persons who wish to make fair use of encrypted copyrighted works without the technical means of doing so is a matter for Congress. . . .”).



Obvious? The opening for non-US firms seems obvious but aren't there some “protections” that prevent foreign telecommunications firms from jumping on the gravy train?

http://tech.slashdot.org/story/09/08/11/1610237/US-Cell-Phone-Plans-Among-Worlds-Most-Expensive?from=rss

US Cell Phone Plans Among World's Most Expensive

Posted by timothy on Tuesday August 11, @01:03PM from the yes-but-we-have-cheap-gasoline dept.

Albanach writes

"An OECD report published today has shown moderate cell phone users in the United States are paying some of the highest rates in the world . Average US plans cost $52.99 per month compared to an average of $10.95 in Finland. The full report is available only to subscribers, however Excel sheets of the raw data are available to download."

(You'll find those Excel sheets — which open just fine in OpenOffice — on the summary page linked above.)



Pandemic or Overreaction? Hard to tell without Al Gore...

http://www.bespacific.com/mt/archives/022030.html

August 11, 2009

Flu.gov Provides Tools and Data on Pandemic Influenza and Avian Influenza

"Flu.gov provides comprehensive government-wide information on pandemic influenza and avian influenza for the general public, health and emergency preparedness professionals, policy makers, government and business leaders, school systems, and local communities."



A business model I've been suggesting for years. Converting obsolete media to “current” media. As the pace of obsolescence grow ever faster, the market for this service should grow just as fast.

http://news.cnet.com/8301-19882_3-10308039-250.html?part=rss&subj=news&tag=2547-1_3-0-20

Pixorial collects your video, sells it back to you

by Rafe Needleman August 12, 2009 3:00 AM PDT

The family video site Pixorial opens up to the public Wednesday. It solves two problems most people will probably relate to. First, it's a nice little video editor for piecing together clips from digital cameras and the like. Second, if you send Pixorial your old analog media (VHS tapes, Super 8 film, other formats), the company will convert them to digital so you can edit them into new films.

Once your film is edited, you can then press it to DVD ($9.99) or just view it online in smallish window. If you want to download the full, high-resolution video, that's $1.99



Inevitable. But we're going to have a battle for a device that can do everything you can already do to your textbook. Underlines, highlights, fold the corner of the page, add sticky notes, etc.

http://www.wired.com/gadgetlab/2009/08/coursesmart-brings-7000-text-books-to-the-iphone/

CourseSmart Brings 7,000 Text Books to The iPhone

By Charlie Sorrel Email Author August 11, 2009 6:13 am



Tools & Techniques for the complete hacker

http://www.makeuseof.com/tag/how-to-trace-an-ip-address-how-to-find-your-own-nb/

How to Trace an IP Address to a PC & How to Find Your Own

Aug. 11th, 2009 By Saikat Basu

[See also:

http://www.makeuseof.com/tag/how-to-trace-your-emails-back-to-the-source/

How To Trace Your Emails Back To The Source

May. 28th, 2009 By Stefan Neagu



Business Model? After all, there is always something new...

http://www.techcrunch.com/2009/08/11/the-new-media-school-because-college-didnt-teach-you-a-thing-about-the-digital-economy/

The New Media School: Because College Didn’t Teach You A Thing About The Digital Economy

by Jason Kincaid on August 11, 2009

By now, most businesses and self-employed individuals know that they can use social media services like Twitter and Facebook to help themselves grow their customer base and (hopefully) make some money. But for most people, actually using these services presents a challenge. Granted, there is no shortage of social media ‘gurus’ who have blogged their tips, but when it comes to finding ongoing instruction from genuine experts, the pickings have been slim.

Nick O’Neill , founder of the The Social Times, is looking to help. O’Neill is launching an educational program called the New Media School, which is setting out to help both companies and individuals most effectively take advantage of the businesses opportunities afforded by the web.

The school’s first course is the Social Media Marketing Program, which entitles participants to a number of text guides as well as a series of video lectures led by a solid roster of industry veterans. Each lecture will be streamed live via Livestream, and students in the program will be able to submit questions live via an integrated chat box. The course will begin in about a week and a half.

The school is charging $147 per month, and plans to offer new content on a rolling basis.