Tuesday, August 03, 2010

Couple this with the IRS's stance that they can not legally notify the victims, and you have a generation who won't know their credit needs repair until they actually try to use it.

http://www.databreaches.net/?p=12933

New ID theft targets kids’ SS numbers

August 2, 2010 by admin

Bill Draper of the Associated Press reports:

…. Hundreds of online businesses are using computers to find dormant Social Security numbers — usually those assigned to children who don’t use them — then selling those numbers under another name to help people establish phony credit and run up huge debts they will never pay off.

Authorities say the scheme could pose a new threat to the nation’s credit system. Because the numbers exist in a legal gray area, federal investigators have not figured out a way to prosecute the people involved.

Read more on WRAL.

[From the article:

The scheme works like this:

Online companies use computers and publicly available information to find random Social Security numbers. The numbers are run through public databases to determine whether anyone is using them to obtain credit. If not, they are offered for sale for a few hundred to several thousand dollars.

Because the numbers often come from young children who have no money of their own, they carry no spending history and offer a chance to open a new, unblemished line of credit. People who buy the numbers can then quickly build their credit rating in a process called “piggybacking,” which involves linking to someone else’s credit file.

Many of the business selling the numbers promise to raise customers’ credit scores to 700 or 800 within six months.

If they default on their payments, and the credit is withdrawn, the same people can simply buy another number and start the process again, causing a steep spiral of debt that could conceivably go on for years before creditors discover the fraud.

… “Lenders don’t understand that when they pay money to go through a service, they may be receiving false information,” Jensen said. “They think when they order the information from credit bureaus, it must be true.”



Not much detail. Perhaps this doesn't seem to rise to the level of taking pictures in your daughters bedroom (nothing recent on the Lower Merion case, perhaps they are waiting for summer vacation to end) it does suggest that schools take even the potential for violence more seriously than they did once upon a time.

http://www.pogowasright.org/?p=12556

Father demands $7.5 Million because school officials read daughter’s text message

August 3, 2010 by Dissent

Duarte Geraldino reports on a case in Irving, Texas where a family is suing the school district for searching their teenage daughter’s cell phone for text messages.

The incident occurred when school officials:

got wind of a potentially threatening situation at the school involving a gun and keyed cars. They believed Madelyn was somehow involved and had evidence on her phone.

The student seems to have consented to the search but claims intimidation:

“I knew they could not do it but I was kind of scared to ask for it back because you know I was like ‘there were three principals and a police officer,” she said.

What’s raising some eyebrows on this one is the father’s motivation in filing a suit, as it does not come across as just some solely noble attempt to protect constitutional rights.

The Beaird family wants everyone involved in the search to be disciplined and fired, including the school administrator and resource officer. They are also demanding $7.5 M in damages.

Where did that figure come from?

“I remember back when hot coffee was spilled in the McDonald’s law suit. They were awarded $4.5 M. I said you know, I guess a constitutional right is worth at least $4 M today,” said Madelyn’s father. He went on to explain “It is worth at least a cup of coffee.”

Read more on 33 News.

If you have children, this might be a good case to discuss at your family’s dinner table tonight as it gives you an opportunity to teach your children their rights in school. The ACLU used to publish a booklet for students about their rights, but I don’t see any such current publication on their web site. That’s a shame, as it would be nice to have something to give kids and teens that explains their First Amendment and Fourth Amendment rights in schools. If anyone knows of a good resource like that, perhaps you could drop me a note or post a comment.

[From the article:

Though it denied the Beairds' claim, Irving ISD agreed to reimburse the teen for the cost of her phone. It has not been returned. [Does this suggest there was evidence on the phone? If not, why keep it? Bob]



Toward ubiquitous surveillance. Imagine the volume if you got a percentage of the fine!

http://www.pogowasright.org/?p=12552

All the Traffic Cop’s Spies

August 3, 2010 by Dissent

Danielle Citron writes:

According to The New York Times, New Delhi’s traffic police have waded into Government 2.0 territory, adopting Facebook to garner public participation. Its Facebook page began much like domestic Government 2.0 sites in asking the public for its views and suggestions. But people didn’t just comment on policy. Instead, they provided real-time information on drivers who violated traffic laws. In just two months’ time, the site attracted over 17,000 dutiful fans who have posted nearly 3,000 photographs and dozens of videos of traffic infractions. Fans posted pictures of people on motorcycles without helmets, drivers talking on cellphones or taking illegal turns, and improperly parked vehicles. With the license plate numbers captured on pictures and videos, police have been able to issue 665 tickets. New Delhi’s Joint Commissioner of Traffic, Satyendra Garg, explained that the city’s Facebook profile never asked people to report traffic infractions.

Read more on Concurring Opinions.



Tools & Techniques. For my Ethical Hackers (and stalkers)

http://it.slashdot.org/story/10/08/03/0117215/Using-XSS-amp-Google-To-Find-Physical-Location?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Using XSS & Google To Find Physical Location

Posted by kdawson on Tuesday August 03, @02:24AM

wiredmikey sends along a brief (and quite poorly written) report from Security Week on Samy Kamkar's talk at Black Hat last week. In the video, which is amusing, he demonstrates how to obtain location information (within 30 feet, in the example he shows) of a user who does no more than visit a malicious website. The technique involves sniffing out the local router, breaking into it to obtain its MAC accress, and sending that to Google to extract the router's location from Google's Street View database.


(Related) Another experiment to replicate in the computer lab.

http://www.pogowasright.org/?p=12564

RFID chips snooped from 66 metres

August 3, 2010 by Dissent

Bill Ray reports:

RFID tags can be read at a surprising range, a researcher has found.

When he’s not listening in to GSM phone calls, Chris Paget has been busy seeing at what distance an RFID tag can be read, managing a respectable 217 feet.

Paget also reckons the US military could read an EPC Gen2 tag from 80 miles off, though the connection would likely time out before any data was retrieved. Which is a shame as his calculations put the theoretical maximum read range at 317 miles, if you’ve got a big enough dish. [Can you say “AWACS?” Bob]

Read more in The Register.



It's one thing to add a game console as a team building exercise, it's quite another to think attaching it to the corporate network makes sense.

http://games.slashdot.org/story/10/08/03/0657251/Attacking-Game-Consoles-On-Corporate-Networks?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Attacking Game Consoles On Corporate Networks

Posted by Soulskill on Tuesday August 03, @06:48AM

A pair of security researchers speaking at DefCon demonstrated how video game consoles, which are becoming increasingly common break room or team-building toys, can open vulnerabilities in corporate networks.

"[They] found that many companies install Nintendo Wii devices in their work places, even though they don’t let you walk into the company with smartphones or laptops. (Factories and other sensitive work locations don’t allow any devices with cameras). By poisoning the Wii, they could spread a virus over the corporate network. People have a false sense of security about the safety of these game devices, but they can log into computer networks like most other computer devices now. In the demos, the researchers showed they could take compromised code and inject it into the main game file that runs on either a DS or a game console. They could take over the network and pretty much spread malware across it and thereby compromise an entire corporation. The researchers said they can do this with just about any embedded device, from iPhones to internet TVs."



“to dream the impossible dream...”

http://www.pogowasright.org/?p=12550

Lawyers Seek Order Forcing U.S. to Destroy NSA Wiretapping Data

August 2, 2010 by Dissent

Maria Dinzeo reports:

The Center for Constitutional Rights has asked a federal judge to order the government to destroy or quarantine all surveillance records from the National Security Agency’s warrantless wiretapping program. “It requires little imagination to see the continued risk of harm posed by the profoundly intrusive surveillance the NSA carried out with abandon for at least five years,” the center claims.

The nonprofit legal advocacy group says its lawyers “have every right to believe that attorney-client communications have been intercepted by the program,” and its staffers have had to forego or delay communicating with certain clients to evade government eavesdropping.

Read more on Courthouse News.

Related: Plaintiffs’ Memorandum in Support of Motion for Summary Judgment and in Opposition to Defendants’ Motion to Dismiss (pdf)



Scam? Possibly not -MakeUseOf is a reputable site.

http://www.makeuseof.com/tag/instantly-find-credit-score-free-charge-credit-karma/

Instantly Find Out Your Credit Score Free Of Charge With Credit Karma

At first I was a bit skeptical about another site offering free credit scores and reports. Credit Karma was recommended to me via Reddit a few months ago, and several users had indicated that it was a good website with helpful information and that they took your privacy seriously. Armed with the Gmail + tip in hand (to detect if they sold my email address to outside companies), I signed up for the service.

After you sign up with Credit Karma the first thing that they request is your Social Security number (SSN). I almost never give this out online, but because of their reputation and the fact that they only use it once and do not store it, I felt more comfortable handing it over. They promise to use your SSN once and then they say they do not use it or store it in their databases at all.

… One of the features I like the best about Credit Karma is that it keeps track of your credit score over time. [How do they track your credit without your SSAN? Bob] It also analyzes the core components of your score and makes suggestions on how to improve your score.

… If you want your full free credit score, you may obtain them once a year from AnnualCreditReport.



This might actually find a market!

http://www.killerstartups.com/Mobile/getizup-com-make-your-phone-keep-quiet-as-you-drive

GetiZUP.com - Make Your Phone Keep Quiet As You Drive

http://www.getizup.com/what_is_izup/overview

We all know that we should keep our hands on the wheel when we are driving, but the demands of modern life often mean that our phone will ring right there and then, and that we will be forced to take the call. There is nothing that we can do about that… or is it? iZUP is a new mobile solution that does something quite ingenious: it holds your calls and messages while you are driving, so that you won’t become distracted. This is achieved by using the phone’s GPS in order to determine if the vehicle is moving or not. If iZUP thinks that the car is indeed moving, then it will proceed to limit its capabilities. It is as simple as that. Your messages and calls will be held until it is safe to read them

can tell one from the other.

[From the site:

always allows unlimited access to 911 and a list of authorized phone numbers.



Ownership of digital products does not an intellectual giant make. Rather than think of a way to make money from this, they simply say “don't do that”

http://games.slashdot.org/story/10/08/02/219233/NAMCO-Takes-Down-Student-emPac-manem-Project?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

NAMCO Takes Down Student Pac-man Project

Posted by Soulskill on Monday August 02, @06:30PM

"The core of how people first learn to do stuff — programming, music, writing, etc. — is to imitate others. It's one of the best ways to learn. Apparently a bunch of students using MIT's educational Scratch programming language understand this. But not everyone else does. NAMCO Bandai sent a takedown notice to MIT because some kids had recreated Pac-man with Scratch. The NAMCO letter is pretty condescending as well, noting that it understands the educational purpose of Scratch, but 'part of their education should include concern for the intellectual property of others.'"



I'll go a step farther. What they teach in high school Calculus is identical to what we teach in College. Okay, we toss in a bunch more and it comes at you faster, but why not build one great big “Everything you ever wanted to know about Math but were afraid to ask” database, and call it a day?

http://news.slashdot.org/story/10/08/02/222200/Sun-Founders-Push-For-Open-Source-Education?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Sun Founders' Push For Open Source Education

Posted by kdawson on Monday August 02, @06:54PM

"Unfortunately for textbook publishers, Scott McNealy has some extra time on his hands since Oracle acquired Sun and put him out of a job. The Sun co-founder has turned his attention to the problem of math textbooks, the price of which keeps rising while the core information inside of them stays the same. 'Ten plus 10 has been 20 for a long time,' McNealy quips. 'We are spending $8 billion to $15 billion per year on textbooks' in the US, he adds. 'It seems to me we could put that all online for free.' McNealy's Curriki is an online hub for free textbooks and other course material. Others hoping to bring elements of the Open Source model to the school textbook world include Vinod Khosla (who co-founded Sun with McNealy), whose wife Neeru heads up the CK-12 Foundation, which has already developed nine of the core textbooks for high school."



Explaining correlation to my Statistics students – and why that is not the same as cause and effect...

http://games.slashdot.org/story/10/08/03/0645218/Tracking-the-Harm-Games-Do?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Tracking the Harm Games Do

Posted by Soulskill on Tuesday August 03, @03:35AM

Every so often, video games are accused of causing all sorts of negative behavior in children, teens, and adults. These accusations are typically predicated on statistics that sound much more damning than they actually are. In that vein, gaming website Rock, Paper, Shotgun did their own tongue-in-cheek statistical analysis, complete with pretty charts and graphs. [Which I will happily copy Bob] Quoting:

"As part of my research I thought to compare the sales of each GTA game with what the divorce rate must have been when each came out. As you can see each new GTA game has been directly correlated with an increase in divorces. ... An often ignored statistic (and you have to ask why it’s being ignored by the games media, don’t you?) is the sheer volume of PC games being released. We’ve all noticed the British population is abandoning the church, turning instead toward shopping, DVDs and knife crime. But few have thought to check for a connection between PC sales and the numbers of people attending their local Church Of England church on a Sunday. When you look at the data there’s little doubt left that as the publishers continue to release more and more PC games each year, our nation’s faith is being increasingly eroded. And at what cost? If only a graph could tell us that."



Dilbert explains bureaucracies in three panels... and the last two are irrelevant.

http://dilbert.com/strips/comic/2010-08-03/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+DilbertDailyStrip+%28Dilbert+Daily+Strip%29

Monday, August 02, 2010

A Mid-term question for my Ethical Hackers. Write an App that erases this data in 25 lines of code or less.

http://www.pogowasright.org/?p=12509

“When you hit the delete button, it’s never really deleted:” Why cops love iPhone

August 1, 2010 by Dissent

Amber Hunt reports:

[...]

And if you’re doing something criminal, something about it is probably going to go through that phone:

• Every time an iPhone user closes out of the built-in mapping application, the phone snaps a screenshot and stores it. Savvy law-enforcement agents armed with search warrants can use those snapshots to see if a suspect is lying about whereabouts during a crime.

• iPhone photos are embedded with GEO tags and identifying information, meaning that photos posted online might not only include GPS coordinates of where the picture was taken, but also the serial number of the phone that took it.

• Even more information is stored by the applications themselves, including the user’s browser history. That data is meant in part to direct custom-tailored advertisements to the user, but experts said some of it could be useful to police.

Clearing out user histories isn’t enough to clean the device of that data, said John B. Minor, a member of the International Society of Forensic Computer Examiners.

Read more in the Chicago Sun-Times.


(Related)

http://www.pogowasright.org/?p=12512

New Minnesota law gives police warrantless access to cellphone location data

August 1, 2010 by Dissent

A new law went into effect in Minnesota today. As reported by Mark Sommerhauser:

A new law requires cell-phone companies to reveal call-location information if asked by law enforcement to do so in an emergency. The law came from the Kelsey Smith Act, named for a missing Kansas teen whose body was found after a phone company voluntarily provided the location of her cell phone. Such locations can be tracked by cell towers, according to a release from House Public Information Services.

Law enforcement may request call-location information if a person is at risk of death or serious physical harm, the law says.

Source: St. Cloud Times.


(Related)

http://www.pogowasright.org/?p=12517

Atkinson to ask privacy commissioner not to cut access to Go Cards

August 1, 2010 by Dissent

Courtney Trenwith reports:

Queensland Police will appeal to the state’s privacy commissioner not to sever their access to Brisbane commuters’ movements recorded on Go Cards.

Police Commissioner Bob Atkinson said officers had used the information ‘‘lawfully and appropriately’’ and should be allowed to continue to do so.

brisbanetimes.com.au exclusively revealed last week police are tapping into commuters’ Go Card records to not only pinpoint the movements of criminal suspects but also potential witnesses.

Read more in the Brisbane Times.


(Related)

http://www.pogowasright.org/?p=12519

NZ: Growing concern over tracking devices lead to call for new legislation

August 1, 2010 by Dissent

Nicky Hager of Stuff reports, “Spies target animal rights campaigners:”

An Auckland private investigation firm has been caught out after it attached a sophisticated tracking device to a political campaigner’s car – but left the device visible from outside the vehicle. [Incompetent. Bob]

The GPS tracking device, which used a mobile phone connection to report the car’s position to private investigators, had been attached with magnets.

It is the third time in three years the Sunday Star-Times has caught Thompson & Clark Investigations doing covert surveillance on political groups for corporate clients.

Read more on Stuff.

From a Green Party press release:

Changes to a law already before Parliament could protect New Zealanders from spying by private companies, the Green Party said today.

“It’s silly that private investigators have more rights to use tracking devices than the Police,” said Green human rights spokesperson Keith Locke, “but we can extend the law to control companies and individuals as well as Government agencies.”

Read more on Scoop.

The Privacy Commissioner’s comments on tracking as it relates to the new counter-terrorism bill can be found at http://www.privacy.org.nz/counter-terrorism-bill/?highlight=tracking



A Final exam question?

http://www.networkworld.com/news/2010/073110-hacker-snoops-on-gsm-cell.html

Hacker snoops on GSM cell phones in demo

Despite concerns that federal authorities might fine or arrest him, hacker Chris Paget went ahead with a live demonstration of mobile phone interception at the Defcon hacking conference Saturday.

Using several thousand dollars worth of equipment, [$1500 according to most reports Bob] Paget was able to intercept mobile-phone data on the GSM (Global System for Mobile Communications) networks used by AT&T and T-Mobile. He did this using a home-made system he calls an IMSI (International Mobile Subscriber Identity) catcher.

Within minutes of activating his IMSI catcher in test mode, Paget had 30 phones connected to the system. Then, with a few keystrokes, he quickly configured the device to spoof an AT&T cell tower.

"As far as your cell phones are concerned I am now indistinguishable from AT&T," he said. He predicted that every AT&T device in the room would connect to his tower, within the next half hour.



So, could I request (via FOIA) a list of everyone using my SSAN? Would they refuse to tell a Senator?

http://www.databreaches.net/?p=12908

Petri bill would enlist IRS against identity theft

August 2, 2010 by admin

U.S. Rep. Tom Petri is introducing federal legislation to fix a loophole that the IRS claims prevents it from informing people if the IRS detects that their Social Security Number has been fraudulently used…

… One resident of Princeton, Wis., learned that he was a victim of the fraud as a result of a call from a debt collector, Petri said. The resident contacted the Internal Revenue Service to alert the agency that somebody was using his Social Security number illegally.

“To his surprise, he learned that the IRS already knew of the situation, had known for some time, and had chosen not to tell anybody,” said Tom Petri. “The IRS explained that it is legally required to protect the privacy of the person committing the fraud.”

[...]

Petri last week introduced legislation that, he said, would “require the IRS to fight on the side of the good guys.” Joining him in introducing the bill is Rep. Melissa Bean, D-Ill.

“Privacy laws are not intended to protect fraudsters or to enable illegal immigration,” Bean said. “If the IRS has information about identify theft, it should share that information immediately with law enforcement and affected parties.”

The Petri-Bean bill — known as the Social Security Identity Defense (SSIDA) Act — would require the IRS to inform a taxpayer when his or her Social Security number has been used fraudulently to gain employment; provide that the IRS share this information with the FBI and allow the FBI to make facts available to state and local law enforcement agencies; and prevent the appearance of a fraudulently used Social Security number on a W-2 statement.

Read more on fdlreporter.com



If you're innocent, you have nothing to fear. (If you can't afford an indoor pool, you deserve to be fined, you Second Class citizen, you.)

http://www.pogowasright.org/?p=12507

NY: High-tech crackdown on illegal pools raises privacy fears

August 1, 2010 by Dissent

Mitchell Freedman

If you live in Riverhead and have a backyard pool that doesn’t have a permit, beware: The town is using a new tool to find you without ever setting foot on your property.

In a move other Long Island towns may copy but privacy advocates say raises “Big Brother” concerns, Riverhead has used the satellite image service Google Earth in the last nine months to snag about 250 homeowners who have swimming pools but no required permits.

[...]

Lee Tien, an attorney with the San Francisco -based Electronic Frontier Foundation , a digital-rights advocacy group, said the town’s use of Google Earth is “probably” legal because the images aren’t “particularly revealing of intimate activities” and officials used them to answer a simple yes or no question: Pool or no pool?

Tien said just because a practice is legal, however, that doesn’t make it good policy. “It seems like there are less creepy ways of doing this type of thing,” Tien said.

Read more on Newsday.



Are we still stuck n the Industrial Age? The TJX hackers didn't bother with hardware at the retail level, they stole credit card data wholesale! Why make possession of each separate possible tool a crime, when you could make possession/use of the data a crime?

http://www.databreaches.net/?p=12896

Possession of a skimmer now a felony in Minnesota

August 1, 2010 by admin

A new law went into effect in Minnesota today. As reported by Mark Sommerhauser:

The Legislature moved to criminalize possession of “skimming” devices that can be used to steal someone’s identity. The new law makes it a felony to possess devices that allow unauthorized scanning and recording of personal information from the magnetic strip of a credit card.

Source: St. Cloud Times.



Gosh, does this means they no longer think we're perfect?

http://www.bespacific.com/mt/archives/024852.html

August 01, 2010

The Economist Targets American Criminal Justice System

Rough justice in America - Too many laws, too many prisoners- Never in the civilised world have so many been locked up for so little "Justice is harsher in America than in any other rich country. Between 2.3m and 2.4m Americans are behind bars, roughly one in every 100 adults. If those on parole or probation are included, one adult in 31 is under “correctional” supervision. As a proportion of its total population, America incarcerates five times more people than Britain, nine times more than Germany and 12 times more than Japan. Overcrowding is the norm. Federal prisons house 60% more inmates than they were designed for. State lock-ups are only slightly less stuffed. The system has three big flaws, say criminologists. First, it puts too many people away for too long. Second, it criminalises acts that need not be criminalised. Third, it is unpredictable. Many laws, especially federal ones, are so vaguely written that people cannot easily tell whether they have broken them."

Sunday, August 01, 2010

I wonder if this is another case of Hackers finding a poorly secured funds transfer system? One where the bank relies on a single password and never checks to see where the password is coming from? This should make their customers wary, but I doubt most of them will ever hear of this hack.

http://www.databreaches.net/?p=12835

NM: Computer Heist at Bank Nets $700K: Student Loan Foundation Account Victimized

July 31, 2010 by admin

John Fleck reports:

Someone accessed the bank account of the New Mexico Educational Assistance Foundation earlier this month, making off with as much as $700,000.

The nonprofit foundation manages federal student loans worth $1.3 billion for 94,000 New Mexicans, said the organization’s president, Elwood “Woody” Farber. Farber said only the foundation’s bank account, not any personal client data such as names or Social Security numbers, was accessed in the break-in.

Farber said the matter has been turned over to the FBI.

Read more from this Albuquerque Journal story on Trading Markets.

[From the article:

Experts say that, in cases like this, it is more likely that an account was accessed with a user password rather than by a breach of the bank's firewalls. [You would think the bank would insist that be mentioned if it was true here. Bob]



Someone is angry... I assume the lying is SOP...

http://news.cnet.com/8301-27080_3-20012253-245.html?part=rss&subj=news&tag=2547-1_3-0-20

Researcher detained at U.S. border, questioned about Wikileaks

A security researcher involved with the Wikileaks Web site was detained by U.S. agents at the border for three hours and questioned about the controversial whistleblower project as he entered the country on Thursday to attend a hacker conference, sources said on Saturday.

He was also approached by two FBI agents at the Defcon conference after his presentation on Saturday afternoon about the Tor Project.

Jacob Appelbaum, a Seattle-based programmer for the online privacy protection project called Tor, arrived at the Newark, New Jersey, airport from Holland flight Thursday morning when he was pulled aside by customs and border protection agents who told him he was randomly selected for a security search, according to the sources familiar with the matter who asked to remain anonymous.

Appelbaum, a U.S. citizen, was taken into a room, frisked and his bag was searched. Receipts from his bag were photocopied and his laptop was inspected but it's not clear in what manner, the sources said. Officials from the Immigration and Customs Enforcement and the U.S. Army then told him he was not under arrest but was being detained, the sources said. They asked questions about Wikileaks, [They peobably don't do that with truly random selectees. Bob] asked for his opinions about the wars in Iraq and Afghanistan and asked where Wikileaks founder Julian Assange is, but he declined to comment without a lawyer present, according to the sources. He was not permitted to make a phone call, they said.

After about three hours, Appelbaum was given his laptop back but the agents kept his three mobile phones, sources said.



But... They just want to be your friend!

http://yro.slashdot.org/story/10/07/31/137217/Who-Is-Downloading-the-Torrented-Facebook-Files?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Who Is Downloading the Torrented Facebook Files?

Posted by Soulskill on Saturday July 31, @09:20AM

"Gizmodo's got an interesting scoop on a list of IPs acquired from Peer Block revealing who is downloading the Facebook user data torrented this week: Apple, the Church of Scientology, Disney, Intel, IBM and several major government contractors just to name a few. The article notes that this doesn't mean it's sanctioned by these companies or even known to be happening, but the IP addresses of requests coming to one of the users' machines match to lists of IP blocks for each company."



Ubiquitous surveillance: It's from the children!

http://science.slashdot.org/story/10/07/31/220234/Ive-Fallen-and-I-Cant-Get-Up-v20?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

'I've Fallen and I Can't Get Up!' v2.0

Posted by timothy on Saturday July 31, @06:53PM

"Remember those old Lifecall commercials? Well, you've come a long way, Grandma! The NY Times reports on a raft of new technology that's making it possible for adult children to remotely monitor to a stunningly precise degree the daily movements and habits of their aging parents. The purpose is to provide enough supervision to allow elderly people to stay in their homes rather than move to an assisted-living facility or nursing home. Systems like GrandCare, BeClose, QuietCare, and MedMinder allow families to keep tabs on Mom and Dad's whereabouts, and make sure they take their meds. Perhaps Zynga can make a game out of all this — GeriatricVille?"



Statistics. I would like to see the final study results. What is the range & standard deviation for each vendor? Verizon's numbers suggests both are large.

http://mobile.slashdot.org/story/10/07/31/1447246/Average-Cellphone-Data-Usage-Is-1458-MB-Per-Month?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Average Cellphone Data Usage Is 145.8 MB Per Month

Posted by Soulskill on Saturday July 31, @11:26AM

"For the first time, the majority of cell phones are accessing data services — 53 percent, compared to only 42 percent last year, according to a new study by Validas. And each user downloads an average of 145.8 MB per month (the average was just 96.8 MB per month in 2009). The heaviest users are Verizon smartphone owners, averaging 428 MB per month (338 MB on average for iPhone users). In fact, Verizon users were twice as likely as iPhone users to exceed both 500 MB and 2 GB each month."

[From the article:

One potential note of caution is that Validas is a company which analyzes phone bills for customers and advises them if they have been billed incorrectly or if they could get a better deal elsewhere. The data used in the study comes from customer bills, which means it is based on customers who take a particularly keen interest in their spending. That may bias the results towards people who use more data than the general public (and thus have higher bills to query), though it shouldn’t favor or penalize any particular network.



What part of “early adopter” don't they understand?

http://www.digitaltrends.com/mobile/porn-industry-to-cash-in-on-iphone-4s-face-time-feature/

Porn Industry to Cash In on iPhone 4’s Face Time Feature

It’s a maxim of technology: Invent the newest gadget and the porn industry will find a way to cash in.

So when Apple Inc. launched the iPhone 4 and its FaceTime videoconference feature, it didn’t take long for adult-entertainment companies to develop video-sex chat services and start hiring workers through Craigslist.



How to be a criminal in Europe.

http://www.bespacific.com/mt/archives/024843.html

July 31, 2010

European e-Justice Portal is now online

The European e-Justice Portal: Includes links to primary documents in the following areas: EU law, Member State law, International law, Case law, Judicial systems, Legal professions and justice networks, Going to court, Mediation, Victims of crime, Tools for courts and practitioners, Registers, and more.



For all my students.

http://www.bespacific.com/mt/archives/024839.html

July 31, 2010

Google With Direct Dictionary Result

Via Google Blogscoped: "Perhaps bad news for the traffic of dictionary sites, which often don’t show the actual word definition in the search engine snippets: Google now has a onebox of their own immediately offering the definition(s) for certain words you’re searching for. Try enter e.g. pleasant into Google.com and the top will read: “pleas·ant/ˈplezÉ™nt/Adjective ... 1. Giving a sense of happy satisfaction or enjoyment. ... 2. (of a person or their manner) Friendly and considerate; likable.”

[From the article:

Note entering e.g. define:pleasant still works, too, and triggers a bit of a more extensive page.

Saturday, July 31, 2010

The backroom of Behavioral Advertising? “Hey, someone has to gather the data!” (Article includes a Glossary and video introduction to Cookies)

http://www.pogowasright.org/?p=12481

Sites Feed Personal Details To New Tracking Industry

July 30, 2010 by Dissent

Julia Angwin and Tom McGinty have a must-read story in the Wall Street Journal:

The largest U.S. websites are installing new and intrusive consumer-tracking technologies on the computers of people visiting their sites—in some cases, more than 100 tracking tools at a time—a Wall Street Journal investigation has found.

[...]

n an effort to quantify the reach and sophistication of the tracking industry, the Journal examined the 50 most popular websites in the U.S. to measure the quantity and capabilities of the “cookies,” “beacons” and other trackers installed on a visitor’s computer by each site. Together, the 50 sites account for roughly 40% of U.S. page-views.

The 50 sites installed a total of 3,180 tracking files on a test computer used to conduct the study. Only one site, the encyclopedia Wikipedia.org, installed none. Twelve sites, including IAC/InterActive Corp.’s Dictionary.com, Comcast Corp.’s Comcast.net and Microsoft Corp.’s MSN.com, installed more than 100 tracking tools apiece in the course of the Journal’s test.

Read more in the Wall Street Journal.


(Related) You thought Cookies were bad? This pushes the Publishers Clearinghouse model to the breaking point. Imagine the calls to Brazil's 911: “Someone followed me home from the supermarket and now they're pounding on my door!”

http://www.pogowasright.org/?p=12486

Omo follows customers home with GPS-enabled products

July 30, 2010 by Dissent

Meghan Keane reports:

Privacy advocates may not be happy with brands tracking consumers online, but a Brazilian detergent brand is set to begin tracking customers in the real world. Starting next week, Omo is embedding 50 detergent boxes with GPS devices as part of a new video camera giveaway.

The campaign is sure to get Omo lots of attention, but the amount of privacy concessions necessary to make it all happen could prohibit GPS-enabled products from becoming a widely used marketing strategy.

Read more on Econsultancy.

[From the article:

"Fifty Omo boxes implanted with GPS devices have been scattered around Brazil, and Mr. Figueiredo has teams in 35 Brazilian cities ready to leap into action when a box is activated. The nearest team can reach the shopper's home 'within hours or days,' and if they're really close by, 'they may get to your house as soon as you do,' he said.

"Once there, the teams have portable equipment that lets them go floor by floor in apartment buildings until they find the correct unit, he said."

There are backup plans in place if things do not go smoothly with the unsuspecting customers. If the customer is hesitant to let the marketing team into his/her home, the group can "remotely activate a buzzer in the detergent box so that it starts beeping." And if something goes wrong with the search, or it takes too long, the boxes come equipped with a note explaining the promotion and prize offering (essentially the traditional approach to such things.)


(Related) Coming soon to a cubicle near you!

http://edition.cnn.com/2010/TECH/innovation/07/30/anybots.robots.office/index.html#fbid=_TZvT-Jj4iq

The robot that visits your cubicle

When Trevor Blackwell, CEO of a company called Anybots, wants to know what his employees are up to, he sends a robot to their cubicles.

… The 5-foot-6, 35-pound robot contains a video camera, a still camera and a microphone. From a laptop, Blackwell can see everything the robot sees. He hears what the robot hears. And, when he talks, the robot projects his voice.

… Watch the company's demo video, and this will all make more sense

Blackwell says that this is how the office of tomorrow will work. Within a year or so, he says, every office in Silicon Valley, California, will have about one telepresence robot for every 10 employees. [Want to bet? Bob]



Perhaps there is hope for the younger generations...

http://arstechnica.com/web/news/2010/07/students-finally-wake-up-to-facebook-privacy-issues.ars

Students finally wake up to Facebook privacy issues

Students care about Facebook privacy more than the world thinks, and their use of privacy controls has skyrocketed recently, according to two researchers. Eszter Hargittai, Associate Professor of Northwestern University, and Danah Boyd, Research Associate at Harvard’s Berkman Center for Internet & Society published their findings in the online peer-reviewed journal First Monday, noting that young people are very engaged with the privacy settings on Facebook, contrary to the popular belief that their age group is reckless with what they post publicly.

… The one thing the researchers were unsure of was why so many Facebook users started tweaking their privacy controls so much between 2009 and 2010. One theory was that there was an increase in public attention on Facebook privacy just before and during that time



Always a good place to start the debate – with a definition of the “problem” (Lots of links worth following...)

http://www.pogowasright.org/?p=12474

Did we pronounce privacy dead this week?

July 30, 2010 by Dissent

Caroline McCarthy reports:

Does privacy exist anymore? Do we even know what it is? A conversation between digital academics Jeff Jarvis and Danah Boyd on Friday morning at the Supernova conference capped off a week in which many peoples’ perceptions of the tension between public and private data online were shaken (and stirred).

“We have no definition of privacy,” said Boyd, a charismatic Microsoft researcher who says she has spent the past two months working on a data-intensive analysis of news stories pertaining to Facebook’s ongoing privacy controversy. The massive social network has been criticized by bloggers, advocates, and lawmakers for an allegedly cavalier attitude toward the privacy of its user base–but its astonishing growth has continued, and the social network propelled past 500 million members last week. “We don’t know what we’re talking about, the (members of the) press certainly don’t know what they’re talking about, (and) the spokespeople don’t know what they’re talking about.” [Does this speaker know what she is talking about? Bob]

Read more on cnet.



For my Ethical Hackers: How to be a Social Engineer

http://news.slashdot.org/story/10/07/30/2230224/DefCon-Contest-Rattles-FBIs-Nerves?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

DefCon Contest Rattles FBI's Nerves

Posted by Soulskill on Friday July 30, @07:34PM

"A DefCon contest that invites contestants to trick employees at 30 US corporations into revealing not-so-sensitive data has rattled nerves at the FBI. Chris Hadnagy, who is organizing the contest, also noted concerns from the financial industry, which fears hackers will target personal information. The contest will run for three days, with participants attempting to unearth data from an undisclosed list of about 30 US companies. [Is your company on the list? Bob] The contest will take place in a room in the Riviera hotel in Las Vegas furnished with a soundproof booth and a speaker, so an audience can hear the contestants call companies and try to weasel out what data they can get from unwitting employees."

The group organizing the contest has established a strict set of rules to ensure participants don't violate any laws.

Update: 07/31 04:45 GMT by S : PCWorld has coverage of one of the day's more successful attacks.



Geek tools. Speed your boot and secure your flash drive.

http://www.smashingapps.com/2010/07/29/the-5-really-cool-windows-tools-you-might-need.html

The 5 (Really) Cool Windows Tools You Might Need

Soluto

Identifies what applications start at boot time and allows you to remove or delay them.

Smart Defrag

Click on the partition you feel is responding slowly, and perform an analysis to see if any files require defragmentation.

USB Write Protect

If you could somehow temporarily disable the writing permissions on your drive, your flash drive would be more secure. At the same time, you will be unable to accidentally delete or modify the flash drive’s contents.

FontFrenzy

a font manager with some extra font cleaning features. When you load it up, the program shows all fonts installed on your computer.

Bvckup

Bvckup is a program currently in its beta that works with Windows operating systems. The program has a number of interface and functionality features which set it apart from applications that perform the same auto-syncing tasks.



For my spreadsheet students (well, two out of three anyway.)

http://www.makeuseof.com/tag/top-3-websites-download-free-excel-programs/

Top 3 Websites To Download Useful Free Excel Programs

Microsoft Office Templates

On the Microsoft Office website, you’ll find countless pre-built Excel templates. … most of them are clearly intended for business purposes.

Vertex42 Excel Templates / Financial Calculators

Vertex42 is a website dedicated to everything related to Excel – including templates and financial calculators.

A large part of these even work on Open Office as well!

Excel Games

This last website is complementary, and wouldn’t be considered ‘useful’ by all parties. [Would you believe, Excel Tetris? Bob]



Coming soon to Firefox. Keep tabs of your frequently used sites available all the time! (Interesting that a Microsoft ad precedes the video.)

http://download.cnet.com/8301-2007_4-20012241-12.html?part=rss&subj=news&tag=2547-1_3-0-20

How to use App Tabs in Firefox (video)

Friday, July 30, 2010

Asymmetric by policy only, not by capability.

http://news.cnet.com/8301-31921_3-20012121-281.html?part=rss&subj=news&tag=2547-1_3-0-20

U.S. military cyberwar: What's off-limits?

The United States should decide on rules for attacking other nations' networks in advance of an actual cyberwar, which could include an international agreement not to disable banks and electrical grids, the former head of the CIA and National Security Agency said Thursday.

… One option would be for the larger G8 or G20 nations to declare that "cyberpenetration of any (financial) grid is so harmful to the international financial system that this is like chemical weapons: none of us should use them," he said at the Black Hat computer security conference here.

Another option would be for those nations to declare that "outside of actual physical attacks in declared conflicts, denial of service attacks are never allowed and are absolutely forbidden and never excused," and a consensus would "stigmatize their use," said Hayden, who's now a principal at the Chertoff Group. Nations "do not do it and they do not allow it to happen from their sovereign space."



The perils of “Pushed” updates. First, give away really useful Apps that everyone “has to have!” Second, activate Big Brother mode. Third, analyze the data and identify targets. Forth, Boom!

http://mobile.slashdot.org/story/10/07/29/1545238/Android-Data-Stealing-App-Downloaded-By-Millions?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Android Data Stealing App Downloaded By Millions

Posted by CmdrTaco on Thursday July 29, @12:04PM

"A wallpaper utility (that presents purloined copyrighted material) 'quietly collects personal information such as SIM card numbers, text messages, subscriber identification, and voicemail passwords. The data is then sent to www.imnet.us, a site that hails from Shenzen, China.'"

[From the article:

“Even good apps can be modified to turn bad after a lot of people download it,” MaHaffey said. “Users absolutely have to pay attention to what they download. And developers have to be responsible about the data that they collect and how they use it.”

… The app has been downloaded anywhere from 1.1 million to 4.6 million times. The exact number isn’t known because the Android Market doesn’t offer precise data.



Securing you phone.

http://news.cnet.com/8301-27080_3-20012144-245.html?part=rss&subj=news&tag=2547-1_3-0-20

Can your calls be intercepted? This tool can tell

A researcher released software at the Black Hat conference on Thursday designed to let people test whether their calls on mobile phones can be eavesdropped on.

The public availability of the software, dubbed Airprobe, means that anyone with the right hardware can snoop on other peoples' calls, unless the target telecommunications provider has deployed a patch that was standardized about two years ago by the GSMA, the trade association representing GSM (Global System for Mobile Communications) providers, including AT&T and T-Mobile in the United States.

Most telecommunications providers have not patched their systems, cryptography expert Karsten Nohl said.

… Airprobe offers the ability to record and decode GSM calls. When combined with a set of cryptographic tools called Kraken, which were released last week, "even encrypted calls and text messages can be decoded," he said.



A humbling perspective, with an interesting graphic.

http://tech.slashdot.org/story/10/07/29/2345248/2-Chinese-ISPs-Serve-20-of-World-Broadband-Users?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

2 Chinese ISPs Serve 20% of World Broadband Users

Posted by timothy on Thursday July 29, @10:46PM

"If you need a reminder of just how big China is—and just how important the Internet has become there—consider this stat: between them, two Chinese ISPs serve 20 percent of all broadband subscribers in the entire world and both companies continue to grow, even as growth slows significantly in more developed markets. Every other ISP trails dramatically. Japan's NTT comes in third with 17 million subscribers, and all US providers are smaller still. 'The gap between the top two operators and the world's remaining broadband service providers will continue to grow rapidly,' said TeleGeography Research Director Tania Harvey. 'Aside from the two Chinese companies, all of the top ten broadband ISPs operate in mature markets, with high levels of broadband penetration and rapidly slowing subscriber growth.'"



Does this suggest the young are delusional?

http://www.bespacific.com/mt/archives/024831.html

July 29, 2010

Why and How the Millennial Generation Is the Most Pro-Government Generation and What This Means for Our Future

The Generation Gap on Government - Why and How the Millennial Generation Is the Most Pro-Government Generation and What This Means for Our Future, by Guy Molyneux and Ruy Teixeira, with John Whaley July 2010

  • "Young Americans today across the ideological spectrum share a far more favorable view of the federal government than do their elders. Importantly, this so-called Millennial Generation may hold the key to reversing historic declines in public confidence in government—the major finding from a new survey commissioned by the Center for American Progress... Young adults are particularly receptive to a reform agenda that would strip wasteful spending and focus on improvements in the delivery of government services. Millennials will reward politicians who adhere to these principles with their votes, young respondents say."



Confirming my suspicions.

http://www.readwriteweb.com/archives/so-called_digital_natives_not_media_savvy_new_study_shows.php

So-Called "Digital Natives" Not Media Savvy, New Study Shows

A new study coming out of Northwestern University, discovered that college students have a decided lack of Web savvy, especially when it comes to search engines and the ability to determine the credibility of search results. Apparently, the students favor search engine rankings above all other factors. The only thing that matters is that something is the top search result, not that it's legit.

… Another interesting finding from the study involved the use of Wikipedia. Perhaps because of teachers' insistence over the years that the user-generated encyclopedia is not a credible source of information, only a third of the students used Wikipedia to search for answers when given particular tasks. This is a drop from earlier studies (like Raine & Tancer, 2007) which showed Wikipedia use at 46% among students.

Other popular trusted sources included SparkNotes (a study guide site), WedMD, Planned Parenthood, CNN, BBC, Microsoft (specifically Encarta and Office-related resources) and those sites with a .gov or .edu extension. Some students even thought that .org domain name meant a site was inherently trustworthy - they weren't aware that the .org extension can be freely registered just like .com and is not for nonprofit use only, as may have originally been intended.



Info-graphic

http://www.intac.net/the-perils-of-the-internet/

The Perils of the Internet



For my Computer Security (and other) students

http://www.bespacific.com/mt/archives/024827.html

July 29, 2010

National Cyber Security Alliance launches Web portal for 2010 National Cyber Security Awareness Month

News release: "The National Cyber Security Alliance (NCSA), a public-private partnership focused on educating a digital citizenry to stay safe and secure online, today launched its National Cyber Security Awareness Month Web portal with information on events, activities, promotions and educational materials to be used in preparation for the online safety month to be held in October. Anyone – family, employers, consumers, teachers, and students – interested in online safety is encouraged to access the portal, and all materials are free to use."

[From the site:

Free materials to support your awareness efforts and valuable links to other organizations.

Safety tip sheets for a variety of online settings



Tools & Techniques Free app.

http://www.makeuseof.com/dir/anti-theft-mobile-recover-stolen-cell-phone/

Anti Theft For Mobile: Recover Lost/Stolen Cellphone & Protect Your Data

I have come across a number of phone apps that provide great security for iPhones and Android based smartphones. There are 3 basic features these security apps offer: the ability to know where your phone is when lost, the ability to remotely lock your phone and the ability to remotely wipe all of your phone’s data.

Finally a security application containing all these features has been made for Symbian OS, Windows and Android phones; this app is F-Secure Anti Theft for Mobile. [Did I mention, it's free? Bob]

Similar tools: WaveSecure and BuddyWay.



Tools & Techniques I should use this in my website classes, and probably lots of other classes.

http://www.makeuseof.com/dir/bounce-annotate-share-comments-website/

Bounce: Tool For Marking & Annotating Websites

On the site’s homepage, you will see a bar where you need to enter the URL of the site you want to comment on. After entering the URL and submitting it, Bounce captures a screenshot image of it and then opens the image in an editable panel.

From the controls in the panel, you can create a red box anywhere on the image and leave comments within the red box. You can do this as many times as you want, adding as many comments as you want.

Clicking a ‘save’ button in the top right of the editing panel gives you the URL which you can share with people. Visiting the URL will take them to your annotated page.

www.bounceapp.com

Similar tools: A.nnotate, Asterpix, BubblePly, Co-ment, PicBite and MiddleSpot.

Also read related articles:

Top Web Annotation Tools: Annotate+Bookmark+Collaborate

Annotate Web pages you visit with Mystickies

The Commentor- A Visual Online Collaboration & Annotation Tool.

Thursday, July 29, 2010

A challenge for my Ethical Hackers: Improve the efficiency and effectiveness of this code. Provide a simple User Interface so that even non-techies can use it.

http://www.pogowasright.org/?p=12405

100 million Facebook pages leaked on torrent site

July 28, 2010 by Dissent

The 2.8GB torrent was compiled by hacker Ron Bowes of Skull Security, who created a web crawler program that harvested data on users contained in Facebook’s open access directory, which lists all users who haven’t bothered to change their privacy settings to make their pages unavailable to search engines.

Bowes’ directory contains 171 million entries, relating to more than 100 million individual users – more than one in five of Facebook’s recently trumpeted half billion user base.

The file contains user account names and a URL for each user’s profile page, from which details such as addresses, dates of birth or phone numbers can be accessed. Accessing a user’s page from the list will also enable you to click through to friends’ profiles – even if those friends have made themselves non-searchable.

Read more on THINQ.

As of the time of this posting, Skull Security’s site is timing out, probably because the story was slashd0tted. The original post, available in Google’s cache, reads in part:

I wrote a quick Ruby script (which has since become a more involved Nmap Script that I haven’t used for harvesting yet) that I used to download the full directory. I should warn you that it isn’t exactly the most user friendly interface — I wrote it for myself, primarily, I’m only linking to it for reference. I don’t really suggest you try to recreate my spidering. It’s a waste of several hundred gigs of bandwidth.

The results were spectacular. 171 million names (100 million unique).

[...]

But it occurred to me that this is public information that Facebook puts out, I’m assuming for search engines or whatever, and that it wouldn’t be right for me to keep it private. Why waste Facebook’s bandwidth and make everybody scrape it, right?

So, I present you with: a torrent! If you haven’t download it, download it now! And seed it for as long as you can.

This torrent contains:

  • The URL of every searchable Facebook user’s profile

  • The name of every searchable Facebook user, both unique and by count (perfect for post-processing, datamining, etc)

  • Processed lists, including first names with count, last names with count, potential usernames with count, etc

  • The programs I used to generate everything



What? Just because it's free, you thought it wouldn't cost you?

http://www.pogowasright.org/?p=12413

What your phone app doesn’t say: It’s watching

July 28, 2010 by Dissent

Jordan Robertson of the Associated Press reports:

Your smart phone applications are watching you – much more closely than you might like.

Lookout Inc., a mobile-phone security firm, scanned nearly 300,000 free applications for Apple Inc.’s iPhone and phones built around Google Inc.’s Android software. It found that many of them secretly pull sensitive data off users’ phones and ship them off to third parties without notification.

Read more on Forbes.



Because government is better able to determine what's important than a bunch of silly old judges?

http://www.pogowasright.org/?p=12415

White House proposal would ease FBI access to records of Internet activity

July 29, 2010 by Dissent

Ellen Nakashima reports:

The Obama administration is seeking to make it easier for the FBI to compel companies to turn over records of an individual’s Internet activity without a court order if agents deem the information relevant to a terrorism or intelligence investigation.

The administration wants to add just four words — “electronic communication transactional records” — to a list of items that the law says the FBI may demand without a judge’s approval. Government lawyers say this category of information includes the addresses to which an Internet user sends e-mail; the times and dates e-mail was sent and received; and possibly a user’s browser history. It does not include, the lawyers hasten to point out, the “content” of e-mail or other Internet communication.

Read more in the Washington Post.

In related coverage, Pete Yost of the Associated Press reports on the FBI’s defense of its guidelines for domestic surveillance.

Earlier this week, the The American Civil Liberties Union on Tuesday asked FBI field offices in 29 states and Washington, D.C., to turn over records the FBI collected on race and ethnicity in various communities. The agency fears the FBI’s data gathering and mapping practices will invite racial profiling by law enforcement. Nick Divito covers the story on Courthouse News.



Perhaps Google was not (yet) evil? Will the US Attorneys General be as willing to drop their “investigation?”

http://www.pogowasright.org/?p=12424

UK: ICO Statement on Google WiFi data

July 29, 2010 by Dissent

A spokesperson for the Information Commissioner’s Office (ICO) said:

“The ICO has visited Google’s premises to assess samples of the ‘pay-load’ data it inadvertently collected. Whilst Google considered it unlikely that it had collected anything other than fragments of content, we wanted to make our own judgement as to the likelihood that significant personal data had been retained and, if so, the extent of any intrusion. The information we saw does not include meaningful personal details that could be linked to an identifiable person. As we have only seen samples of the records collected in the UK we recognise that other data protection authorities conducting a detailed analysis of all the payload data collected in their jurisdictions may nevertheless find samples of information which can be linked to identifiable individuals. However, on the basis of the samples we saw we are satisfied so far that it is unlikely that Google will have captured significant amounts of personal data. There is also no evidence as yet that the data captured by Google has caused or could cause any individual detriment. Nevertheless it was wrong to collect the information. We will be alerting Privacy International and others who have complained to us of our position. The Information Commissioner is taking a responsible and proportionate approach to this case. However, we remain vigilant and will be reviewing any relevant findings and evidence from our international counterparts’ investigations.”

Source: ICO


(Related) You ain't seen nothing yet! (Interesting picture: Who is that sitting next to Eric Schmidt?)

http://www.wired.com/dangerroom/2010/07/exclusive-google-cia/

Exclusive: Google, CIA Invest in ‘Future’ of Web Monitoring

The investment arms of the CIA and Google are both backing a company that monitors the web in real time — and says it uses that information to predict the future.

The company is called Recorded Future, and it scours tens of thousands of websites, blogs and Twitter accounts to find the relationships between people, organizations, actions and incidents — both present and still-to-come. In a white paper, the company says its temporal analytics engine “goes beyond search” by “looking at the ‘invisible links’ between documents that talk about the same, or related, entities and events.”

… America’s spy services have become increasingly interested in mining “open source intelligence” — information that’s publicly available, but often hidden in the daily avalanche of TV shows, newspaper articles, blog posts, online videos and radio reports.

“Secret information isn’t always the brass ring in our profession,” then CIA-director General Michael Hayden told a conference in 2008. “In fact, there’s a real satisfaction in solving a problem or answering a tough question with information that someone was dumb enough to leave out in the open.”



For my Ethical Hackers How to get the attention of your students....

http://news.cnet.com/8301-1009_3-20012019-83.html?part=rss&subj=news&tag=2547-1_3-0-20

Security researcher demonstrates ATM hacking

LAS VEGAS--Hacking into an ATM isn't impossible, a security researcher showed Wednesday. With the right software, it's actually pretty easy.

Barnaby Jack, director of security testing at Seattle-based IOActive, hauled two ATMs onto the Black Hat conference stage and demonstrated to a rapt audience the fond daydream of teenage hackers everywhere: pressing a button and having an automated teller machine spew out its cash until a pile of paper lay on the ground.


(Related) Ditto

http://news.cnet.com/8301-27080_3-20012027-245.html?part=rss&subj=news&tag=2547-1_3-0-20

Expert: Critical system flaws a 'ticking time bomb'

"SCADA (supervisory control and data acquisition) systems are a lot less secure than IT (information technology) systems," Jonathan Pollet, founder of Red Tiger Security, said in his session, titled "Electricity for Free? The Dirty Underbelly of SCADA and Smart Meters."

… Recent modernization efforts have brought connectivity to the Internet back to the control environment and use of Windows, opening up new paths for threats, he said. Plus, there are known flaws in smart meters being installed in homes and linked back to critical systems, he added.

"We've had customers download a Windows patch and that patch actually broke the SCADA system," he said.

… Pollet said that during his consulting at utilities and other SCADA sites he has found all sorts of unnecessary software running on computers connected to important systems that can cause security problems, such as BitTorrent clients for peer-to-peer file sharing, chat clients, adult video directory scripts, and even botnet code and malware.

… Meanwhile, many power plant companies are trying to jump through loopholes in the regulations to reduce their "audit footprint," and controls are being bypassed, he said. Critical infrastructure companies are attempting to limit their responsibility and are not prepared to deal with the kinds of online attacks and espionage that keep chief information officers up at night, he said.



Another perspective

http://www.pogowasright.org/?p=12430

Mexico’s New Data Protection Law

July 29, 2010 by Dissent

W. Scott Blackmer writes:

Mexico has joined the ranks of more than 50 countries that have enacted omnibus data privacy laws covering the private sector. The new Federal Law on the Protection of Personal Data Held by Private Parties (Ley federal de protección de datos personales en posesión de los particulares) (the “Law”) was published on July 5, 2010 and took effect on July 6. IAPP has released an unofficial English translation. The Law will have an impact on the many US-based companies that operate or advertise in Mexico, as well as those that use Spanish-language call centers and other support services located in Mexico.

Read more on Information Law Group.



This might explain why red light cameras are so popular... And changing the law just make collecting fines easier.

http://yro.slashdot.org/story/10/07/28/1947231/Tennessee-Town-Releases-Red-Light-Camera-Stats?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Tennessee Town Releases Red Light Camera Stats

Posted by timothy on Wednesday July 28, @04:58PM

SonicSpike links to what he calls "a transparent look at some statistics released by a small town's red-light camera program," writing

"Specifically, in the last fiscal quarter, 7,213 incidents were recorded, 2,673 incidents were rejected by the reviewing officer, and 662 incidents were not processed due to technical issues or lack of information. All in all 3,878 citations were issued between April I — June 30 in a town of 17,000 residents. Interestingly enough there are two nearby cities claiming that individuals 'have no presumption of innocence' when accused by the red light cameras."

Fines for no-harm-no-foul rolling stops bug me, and remind me of Gary Lauder's suggestion to merge stop signs and yield signs.


(Related) Another “interpretation” of the law I find questionable.

http://games.slashdot.org/story/10/07/28/1954247/UK-Courts-Rule-Nintendo-DS-R4-Cards-Illegal?from=rss&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

UK Courts Rule Nintendo DS R4 Cards Illegal

Posted by Soulskill on Wednesday July 28, @05:40PM

"A UK high court ruled today that R4 cards for the Nintendo DS are illegal, finding two vendors guilty of selling 'game copiers.' The ruling by Justice Floyd is quoted as saying, 'The economic effect on Nintendo of the trade in these devices is substantial as each accused device can store and play copies of many Nintendo DS games [...] The mere fact that the device can be used for a non-infringing purpose is not a defence.' No word in the article as to what law in particular they were found to have broken, nor of the penalty the vendors are facing, but this looks like bad news for all kinds of hardware mod, on any platform, that would enable homebrew users to bypass vendor locks."

Nintendo won a related lawsuit in the Netherlands recently, in addition to the one in Australia earlier this year.



How to reinforce your bias!

http://searchengineland.com/blekko-a-new-search-engine-that-lets-you-spin-the-web-47215

Blekko: New Search Engine Lets You “Spin” The Web

New challenger Blekko is stepping into the fray, opening to limited beta testing today. It offers a compelling way to “slash the web” and put a particular spin on your search results.

… Blekko’s “slashtags” are a unique feature that may draw you in on occasions when you want to see how search results look when they’re skewed to a particular viewpoint.

… What would rank number one for “honey” if you asked bakers versus beekeepers? Blekko can give you the spin from both groups. Want your search results with a liberal slant? You can do that at Blekko, or slash your results the opposite way for a conservative view.

This is all done using slashtags, special keywords that you place after what your searching for, in order to indicate the viewpoint you want used to spin your results.

… This is also known as a vertical search, where instead of searching across the entire “horizontal” spectrum of all web sites, you’re searching “vertically” through just one slice.



Facebook just past 500 million users. Imagine how many users Facebook would have if the users actually liked it!

http://www.bespacific.com/mt/archives/024823.html

July 28, 2010

American Customer Satisfaction Index: Internet news & information; Internet portals & search engines, Internet social media

The American Customer Satisfaction Index (ACSI) Report on E-Business: Internet Portals & Search Engines, News & Information, and Social Media Websites, July 20, 2010. Commentary by Professor Claes Fornell: Google Dips Sharply but Holds Off Bing; FOXNews.com Leads All E-Business Websites; Facebook and MySpace Fail to Satisfy



Interesting tool. Makes you wonder why a home grown system like Glenwood Springs is 8 times faster than Qwest. Of course they've had fiber since 2002. Just another example of my “let the city own it and sell it to everyone” model.

http://www.wired.com/epicenter/2010/07/fastest-best-isps/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

What’s the Fastest and Best ISP in Your City? Look It Up Here



For my website students, 'cause I don't want no sub-standard code!

http://www.webmonkey.com/2010/07/w3cs-unicorn-validator-checks-multiple-standards-at-once/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

W3C’s Unicorn Validator Checks Multiple Standards at Once

he web’s governing body has launched a new validation tool called Unicorn that checks the quality of your website’s code against multiple web standards at the same time.

You can find the new Unicorn “all-in-one validator” on the Worldwide Web Consortium (W3C) website at validator.w3.org/unicorn/.

The W3C maintains a number of free web-based tools for checking whether your web code is valid, and Unicorn makes several of these tools available under a single interface.



For my Math students. They won't be able to resist the “Easier” button.

http://www.freetech4teachers.com/2010/07/knotebooks-create-multimedia-math.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+freetech4teachers%2FcGEY+%28Free+Technology+for+Teachers%29

Wednesday, July 28, 2010

Knotebooks - Create Multimedia Math & Science Articles

Knotebooks is a neat service that allows users to create, customize, and share lessons composed of videos, images, and texts from all over the Internet.

… Using Knotebooks you can organize information to create a reference article for yourself or to share with others. You can also browse the articles published by others, add them to your account for later reference, and or alter the articles that others have written to suit your needs.

… Creating Knotebooks could be a great way for mathematics and science students to build multimedia reference libraries for themselves and for their classmates.



Annotate your videos.

http://www.freetech4teachers.com/2010/07/video-ant-discuss-and-annotate-videos.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+freetech4teachers%2FcGEY+%28Free+Technology+for+Teachers%29

Wednesday, July 28, 2010

Video ANT - Discuss and Annotate Videos

Video ANT is a free tool developed by Brad Hosack at the University of Minnesota for the purpose of providing a platform on which students and teachers view and annotate videos. Video ANT plays your specified video and while watching you and your students can and marks along a timeline and write comments alongside the video. Annotations are archived and emailed to you when you've completed the annotation process. Video ANT works with YouTube videos as well as with some video files that you can upload to the site. Click here to watch a screencast created by Brad Hosack of Video ANT in action.