Tuesday, October 12, 2010

Darn, darn, darn!

http://www.philly.com/inquirer/front_page/20101012_Lower_Merion_district_s_laptop_saga_ends_with__610_000_settlement.html

Lower Merion district's laptop saga ends with $610,000 settlement

The Lower Merion School District will pay $610,000 to settle lawsuits over its tracking of student laptop computers, ending an eight-month saga that thrust the elite district into a global spotlight and stirred questions about technology and privacy in schools.

School board members voted unanimously Monday night to pay $185,000 to the two students who claimed the district spied on them by secretly activating the webcams on their laptops.

The bulk of the money, $175,000, will be put in trust for Blake Robbins, the Harriton High School junior whose family brought the issue to light in February. Jalil Hasan, who filed his lawsuit this summer after graduating from Lower Merion High School, will receive $10,000.

The district will also pay $425,000 in legal fees to their attorney, Mark S. Haltzman.

… School Board President David Ebby said the board decided to settle after the district's insurance company agreed to cover $1.2 million of the costs. That insurer, Graphic Arts Mutual Insurance, initially refused to pay any claims because it said privacy-invasion claims were not covered under the district's multimillion-dollar liability policy.

… "Although we would have valued the opportunity to finally share an important, untold story in the courtroom, we recognize that in this case, a lengthy, costly trial would benefit no one," he said. [Sure they would... Bob]

Still unresolved is how much the district will pay out of pocket. A team of lawyers and computer specialists it hired has submitted more than $1 million in bills. And the attorney for at least one other student has notified the district that he was contemplating a lawsuit.

[The school board's statement is here: http://www.lmsd.org/sections/news/default.php?m=0&t=today&p=lmsd_anno&id=1456


(Related)

http://www.pogowasright.org/?p=15807

Lower Merion School District and Blake Robbins Reach a Settlement in Spycamgate

October 12, 2010 by Dissent

Over on Forbes, Kashmir Hill discusses the settlement in the Lower Merion webcam civil suits that have been discussed on this site previously. As reported last night, the two civil suits settled for $610k, with the lawyer getting the bulk of the settlement, presumably to cover all his time in court seeking an injunction, payment for forensics and consultants, etc.

The case has had a number of repercussions. First, it made other schools and parents more aware of the capability of school-issued laptops to surveill students – with or without their knowledge. Second, it served as a useful call-to-arms to protect and preserve student and youth privacy. Whether Blake Robbins, the student at the heart of the civil suit, actually has experienced any lasting psychological injury or harm as a result of his experiences is unknown to me, as people may try to make light of a traumatic experience to help reduce their anxiety. I hope that if he has suffered adverse emotional consequences, he’s able to get help and put some of this behind him. Sadly, once trust is violated, it’s very difficult to rebuild it or ever be so trusting again. Discovering that your school is taking pictures of you while you were in your bedroom would be very disturbing for most of us, I suspect, and might leave us with a sense of unease in dealing with the school.

Hill suggests one take-home message from the case:

A lesson for others from all this: One of the biggest problems for Lower Merion was that school administrators did not disclose from the beginning to students and their parents that the school could remotely activate the laptop cameras and take photos. If they had, they likely would not have gotten into so much legal trouble of the civil variety. (They were fine on the criminal front — prosecutors declined to pursue a case against the district.)

Transparency pays off. Lower Merion’s lack of transparency now means it has to pay off.

While I agree with her completely that transparency would have helped, I don’t think that makes it okay to be taking pictures of students in their home. The school district’s right and need to track possibly stolen equipment can be accomplished in other ways that do not risk invading students’ or families’ privacy in their homes. And maybe the take-home message we want people to get is that students still do have some privacy rights.



It's one of them lawyer things: Storing email electronically does not make them “electronic storage”

http://www.pogowasright.org/?p=15798

Emails on laptop not protected by the Stored Communications Act

October 12, 2010 by Dissent

Evan Brown comments on Thompson v. Ross, 2010 WL 3896533 (W.D. Pa. September 30, 2010):

Messages from Yahoo and AOL email accounts saved on laptop computer were not in “electronic storage” as defined by Stored Communications Act.

Plaintiff’s ex-girlfriend kept his laptop computer after the two of them broke up. The ex-girlfriend let two of her co-workers access some email messages stored on the computer. Plaintiff filed suit under the Stored Communications Act. Defendants moved to dismiss. The court granted the motion.

Read more on Internet Cases.



Is this the best indication that “you have no privacy?”

http://www.pogowasright.org/?p=15767

The Slow Demise of Defamation and the Privacy Torts

October 11, 2010 by Dissent

Daniel Solove writes:

The ABA Journal reports that the number of libel suits has been steadily dropping in the United States

[...]

Why is this happening? Is it because there’s much less defamation or invasion of privacy today? I strongly doubt that’s the reason. Instead, I can think of several reasons for the decline in defamation and privacy trials.

Read Dan’s commentary on Concurring Opinions. As always, he provides a lot of food for thought.


(Related) ...but maybe not in Canada.

http://www.pogowasright.org/?p=15787

Mirror, mirror on the web

October 12, 2010 by Dissent

donalee Moulton discusses online reputation:

… The study, Digital Footprints: Online Identity Management and Search in the Age of Transparency, also discovered that fully 60 per cent of Internet users surveyed said they are not worried about how much information is available about them online. Similarly, the majority of online adults (61 per cent) do not feel compelled to limit the amount of information that can be found about them online. Just 38 per cent said they have taken steps to limit information available about them.

Caution is required, however. And action is a viable option. “You have to be careful what is being said. There is recourse,” noted Giles Crouch, chief executive officer of MediaBadger, a social media research and consulting firm in Halifax.

Indeed, said Fraser, “you have at least a measure of control. If it’s defamation, you can take legal action.”

That action was apparent in Nova Scotia in a recent court case that highlighted the extent to which individuals — and the courts — will go to protect their reputation. In Mosher v. Coast Publishing Ltd., 2010 NSSC 153, the Supreme Court of Nova Scotia determined that information about individuals who posted online comments following a story in The Coast newspaper alleging racism in the Halifax Regional Municipality fire department and, in particular, against two senior officials, should be provided.

Read more on The Lawyers Weekly.



Behavioral Advertising

http://www.pogowasright.org/?p=15757

Markey and Barton release web site operators’ responses to consumer tracking inquiry

October 11, 2010 by Dissent

Related to the recent WSJ article about responses to a congressional inquiry on consumer tracking, two Representatives have now released the responses of the major web site operators. From the press release:

Representatives Edward J. Markey (D-Mass.) and Joe Barton (R-Texas), Co-Chairman of the House Bi-Partisan Privacy Caucus, today released responses to the letters they had sent to companies identified in a Wall Street Journal investigation as reportedly installing intrusive consumer-tracking technologies to track and/or target consumers visiting these company Web sites.

“The responses raise a number of concerns, including whether consumers are able to effectively shield their personal Internet habits and private information from the prying eyes of online data gatherers,” Rep. Markey said. “Consumers may be unaware that the sites they visit, coordinating with a cadre of analytics firms, advertising networks and offline data companies, may be tracking their activities around the Internet. While the responses that Rep. Barton and I received cite privacy policies and opt-out choices to enable consumers to preserve their privacy, these policies can be complicated and laborious to navigate. For example, a single website may have business relationships with a dozen or more third-party data firms that display advertisements on its site. A consumer may have to visit each of these sites, consulting its privacy policy and clicking through to opt-out, if such an option is provided. In some cases, a list of all third party affiliates is not readily accessible, keeping consumers in the dark.”

Copies of the responses are available here:

Microsoft
AOL
CareerBuilder
Merriam Webster
Yahoo
Verizon
About Group
Comcast
AT&T
PhotoBucket
MySpace


(Related) Note that there is no response from Facebook in the previous article.

http://www.pogowasright.org/?p=15765

Deleted” Facebook photos still not deleted: a followup

October 11, 2010 by Dissent

Jacqui Cheng reports:

Facebook may be making strides in some areas of privacy, but the company is still struggling when it comes to deleting user photos—or not deleting them, as the case may be.

We wrote a piece more than a year ago examining whether photos really disappear from social network servers when you delete them, and found that Facebook was one of the worst offenders when it came to leaving “deleted” photos online. We decided to revisit the issue recently when readers continued to point out that our deleted photos from that article were still online more than 16 months later. Indeed, this old photo of meremains on Facebook’s content delivery network servers, despite being deleted on May 21, 2009.

Read more on Ars Technica. Does Facebook really expect us to believe that it’s acceptable that it has taken them so long to figure out how to truly delete photos that users want deleted?

Where’s Rep. Joe Wilson when you really want someone to stand up and yell, “You lie!” ?


(Related)

http://www.pogowasright.org/?p=15785

Escaping the ‘Scrapers’

October 12, 2010 by Dissent

The Internet has given rise to a dizzying array of people-search sites and data brokers that gather and compile public information and social-networking profiles. The sites gather information from public sources such as property records and telephone listings, and other information is harvested by “scraping” — or copying — websites where people post information about themselves.

Read more in the Wall Street Journal, where they also provide a guide to how to remove your information from some of the bigger data scrapers.

[Very slick infographic!!!

http://blogs.wsj.com/wtk/


(Related) Dilbert neatly sums up the Behavioral Advertising marketplace.

http://dilbert.com/strips/comic/2010-10-12/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+DilbertDailyStrip+%28Dilbert+Daily+Strip%29



The next contentious area of the law?

http://www.pogowasright.org/?p=15754

Cloud Computing Customers’ “Bill of Rights”

October 11, 2010 by Dissent

David Navetta writes:

Needless to say, due in part to our numerous writings on the legal ramifications of Cloud computing, the InfoLawGroup lawyers have been involved in much Cloud computing contract drafting and negotiations, on both the customer and service provider side. As a result, we have seen a lot in terms of negotiating tactics, difficult contract terms and parties taking a hard line on certain provisions.

During the course of our work, especially on the customer side, we have seen certain “roadblocks” consistently appear which make it very difficult for organizations to analyze and understand the legal risks associated with Cloud computing. In some instances this can result in a willing customer walking away from a deal. Talking through some of these issues, InfoLawGroup thought it would be a good idea to create a very basic “Bill of Rights” to serve as the foundation of a cloud relationship, allow for more transparency and enable a better understanding of potential legal risks associated with the cloud.

Just a pre-emptive comment: while we use the strong term “rights,” we know that cloud arrangements vary and that every transaction has its own issues and circumstances that impact the nature and scope of a negotiation. Moreover, as with the real Bill of Rights, we realize that none of these rights are absolute and may appropriately be subject to reasonable limitations in certain contexts. This document should be viewed less as a universal mandate, and more as a tool for cloud customers and providers to engage in spirited debate about the issues addressed in this Bill of Rights.

The Bill of Rights is set forth below with annotations. In addition, you can download an un-annotated version here, and we have even provided a pocket-sized version that can be easily accessed by those who are actively engaged in vetting cloud deals (however, you may need to keep a magnifying glass in your other pocket in order to read this version). [Proof that lawyers like fine print? Bob] This is a work in a progress and we invite you to submit your ideas on additional “rights” that we should include as well as any comments and criticisms on the current listing.

Read the Cloud Computing Customers’ Bill of Rights on InfoLawGroup.



You WILL be attacked. Manage it!

http://www.databreaches.net/?p=14581

Most large companies seeing more hack attacks, survey shows

October 11, 2010 by admin

Ellen Messmer reports:

Is this year turning out to be even worse for getting hacked than last year?

That’s what a survey of 350 IT and network professionals would indicate, with large companies in particular reporting this to be worse than last in terms of suffering at least one network intrusion of their user machines, office network or servers.

According to the Sixth Annual Enterprise IT Security Survey released Monday, 67% of large companies with 5,000 or more employees reported one successful intrusion or more this year, as opposed to 41% in 2009. Mid-size companies of 1,000 to 4,999 employees fared better with 59% reporting an intrusion, up slightly from 57% in 2009.

Read more on Network World.

[From the article:

For the first time, the survey, sponsored by VanDyke Software and undertaken by Amplitude Research in mid-September, delved into what the survey respondents believed primarily caused the network intrusion.

Fourteen percent of those surveyed attributed their intrusion problem to "hacker/network attack," 12% cited "lack of adequate security policies/measures," 10% said "employee Web usage," 9% pointed to "virus/malware/spyware," 8% faulted other employee carelessness, negligence," 6% said "unauthorized access by current/former employees," 5% blamed "weak passwords," 5% thought it was because of "lack of software updates," and 5% simply said "software security flaw/bug."

… About half of respondents said their organizations have a formal security audit by an outside organization at least once a year, up from 35% in 2009. Some 56% felt the audits helped identity "significant security problems."

Separately, 65% this year reported undergoing an internal security audit at least once a year, down slightly from 67% in 2009. Forty-seven percent felt internal audits helped identify security problems, but 30% said the audit didn't go far enough and 40% felt the audits should occur more frequently.


(Related) AKA “Legacy Systems” and “Old stuff that still works” MBAs call this “sunk cost” and find it difficult to spend to upgrade when there is no clear need...

http://developers.slashdot.org/story/10/10/11/1331223/NSF-Wants-To-Know-How-Much-Software-Really-Costs?from=rss

NSF Wants To Know How Much Software Really Costs

Posted by CmdrTaco on Monday October 11, @09:31AM

"It's no secret that the actual cost of software is very complicated. Sure, the companies that write software are spending money on it, but when that software is released, it doesn't stop costing money. You can probably think of a number of relatively tiny things that add up — especially if you're a system administrator — like the man-hours spent patching software to avoid a nasty infection spreading quickly. The bigger debt is that old piece of software you paid a bunch of money for back in 1998 that you're critically dependent on, but it has no support and hasn't been updated in years due to any number of reasons. Well, the National Science Foundation paid Gartner almost half a million dollars to find out what it truly costs to bring an organization to a fully supported environment. According to Gartner, this hidden liability or 'IT debt' is at $500 billion worldwide right now, and in five years it will be at $1 trillion. Along similar lines, a company called Cast that makes software quality tools reported that your average business application comes with a million in IT debt (PDF). And if that's not misapplied enough for you, they estimate that the debt is $2.82 per line of code in the application and also that it's on average higher in the government sector."



Surveillance tools & techniques “Here is where you park at work, and here is where you park when visiting your mistress, and here...”

http://news.slashdot.org/story/10/10/12/020255/French-City-To-Use-CCTV-For-Parking-Fines?from=rss

French City To Use CCTV For Parking Fines

Posted by Soulskill on Tuesday October 12, @02:03AM

"The city of Nice, France is rolling out 626 CCTV cameras throughout town, giving it one of the highest levels of surveillance in the world (1.8 cameras per 1000 inhabitants). The usual rhetoric was given — that they will be used solely for reducing violent crime — but the city will now begin sending out parking tickets solely based on the CCTV video evidence."


(Related) Shades of The Conversation

http://hardware.slashdot.org/story/10/10/11/1838252/High-Tech-Microphone-Picks-Voices-From-a-Crowd?from=rss

High-Tech Microphone Picks Voices From a Crowd

Posted by Soulskill on Monday October 11, @03:12PM

JerryQ writes with news of an impressive audio detection system from a company called Squarehead that was demonstrated during a professional basketball game. According to Wired,

"325 microphones sit in a carbon-fiber disk above the stadium, and a wide-angle camera looks down on the scene from the center of this disk. All the operator has to do is pinpoint a spot on the court or field using the screen, and the Audioscope works out how far that spot is from each of the mics, corrects for delay and then synchronizes the audio from all 315 of them. The result is a microphone that can pick out the pop of a bubblegum bubble in the middle of a basketball game..."


(Related) If you do nothing else, grab the images that accompany the article...

http://www.networkworld.com/community/blog/police-state-wiretapping-web-who-do-they-want

Police State of Wiretapping the Web: Who Do THEY Want to Watch?



For my Ethical Hackers.

http://apple.slashdot.org/story/10/10/11/1420211/The-Hackintosh-Guide?from=rss

The Hackintosh Guide

Posted by CmdrTaco on Monday October 11, @10:21AM

"A 'Hackintosh' is a computer that runs Apple's OS X operating system on non-Apple hardware. This has been possible since Apple's switch from IBM's PowerPC processors to Intel processors a few years ago. Until recently, building a PC-based Mac was something done only by hard-core hackers and technophiles, but in the last few months, building a Hackintosh PC has become much easier. Benchmark Reviews looks at what it's possible to do with PC hardware and the Mac Snow Leopard OS today, and the pros and cons of building a Hackintosh computer system over purchasing a supported Apple Mac Pro."



For my Computer Security students (By the time you learn the rules, the technology is obsolete.)

http://www.wired.com/dangerroom/2010/10/read-em-all-pentagons-193-mind-numbing-cyber-security-regs/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

Read 'Em All: Pentagon’s 193 Mind-Numbing Cybersecurity Regs



For my website students

http://www.smashingapps.com/2010/10/11/ten-best-web-services-to-create-free-slideshows-online.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+SmashingApps+%28Smashing+Apps%29

Ten Best Web Services to Create Free Slideshows Online

Monday, October 11, 2010

In the rush for “Free phone calls” are we forgetting to secure the systems?

http://it.slashdot.org/story/10/10/10/2313255/In-Australia-Rising-VoIP-Attacks-Mean-Huge-Bills-For-Victims?from=rss

In Australia, Rising VoIP Attacks Mean Huge Bills For Victims

Posted by timothy on Sunday October 10, @07:12PM

"Australian network companies have told of clients receiving phone bills including $100,000 worth of unauthorised calls placed over compromised VoIP servers. Smaller attacks have netted criminals tens of thousands of dollars worth of calls. A Perth business was hit with a $120,000 bill after hackers exploited its VoIP server to place some 11,000 calls over 46 hours last year. ... Local network providers and the SANs Institute have reported recent spikes in Session Initiation Protocol (SIP) scanning — a process to identify poorly configured VoIP systems — and brute-force attacks against publicly-accessible SIP systems, notably on UDP port 5060."



Update: But it still seems like a personal (or at least ill-considered) reaction. Otherwise, I suspect you could make this argument at all levels of the organization.

http://www.databreaches.net/?p=14547

NC: Researcher Yankaskas appeals pay cut, demotion

October 10, 2010 by admin

More details are emerging about why the breach involving the UNC-Chapel Hill Carolina Mammography Registry led to consequences for the researcher.

C. Ryan Barber reports:

[...]

School of Medicine Office of Information Systems officials first alerted the University to the breach in July 2009 after uncovering a virus and potential security breach on the Carolina Mammography Registry’s FTP server.

As the registry’s principal investigator, Yankaskas has been blamed for the breach, which also compromised about 114,000 Social Security numbers. She has since claimed that the University is using her as a scapegoat for systemic data security weaknesses.

On Oct. 27, Yankaskas received an intention to discharge letter from Executive Vice Chancellor and Provost Bruce Carney, who said Yankaskas exhibited “deliberate neglect” in her oversight of the project’s data security.

“I was appalled,” said Carney, who held his current position on an interim basis in July 2009. “The first question you have to ask is, ‘How does this happen?’”

In the intention to discharge notice, Carney wrote that Yankaskas was negligent in assigning security duties without granting additional training to Melinda Boyd, whom he deemed to be underqualified. Carney later became aware that his wife’s Social Security number was exposed and said his personal connection to the breach has not clouded his judgment.

“At the time, Ms. Boyd had no certification or experience as a server administrator,” Carney wrote. “She has stated that she requested that you provide additional training for her in server administration but that you declined to do so.”

[...]

Read more on Daily Tar Heel.



Any technology can be used for evil as easily as for good. This is an old debate. I suggest we apply the old solutions.

http://www.pogowasright.org/?p=15721

Next Version of Web Design May Increase Privacy Threats

October 10, 2010 by Dissent

Tanzina Vega reports:

Worries over Internet privacy have spurred lawsuits, conspiracy theories and consumer anxiety as marketers and others invent new ways to track computer users on the Internet. But the alarmists have not seen anything yet.

Over the next few years, a powerful new suite of capabilities will become available to Web developers that could give marketers and advertisers access to many more details about computer users’ online activities. [Easier collection of data for Behavioral Advertising. Bob] Nearly everyone who surfs the Internet will face the privacy risks that come with those capabilities, which are an integral part of the Web language that will soon power the Internet: HTML 5

Read more in the New York Times.

Via @PrivacyMemes.


(Related) Is Google looking to automate the collection of data for “Street View” or will we be seeing auto-driving like the Sci-Fi novels have predicted for years? (With ads for the businesses you pass by?)

http://www.bespacific.com/mt/archives/025434.html

October 10, 2010

Google announces development of technology for cars that can drive themselves

Official Google Blog: Our automated cars, manned by trained operators, just drove from our Mountain View campus to our Santa Monica office and on to Hollywood Boulevard. They’ve driven down Lombard Street, crossed the Golden Gate bridge, navigated the Pacific Coast Highway, and even made it all the way around Lake Tahoe. All in all, our self-driving cars have logged over 140,000 miles. We think this is a first in robotics research. Our automated cars use video cameras, radar sensors and a laser range finder to “see” other traffic, as well as detailed maps (which we collect using manually driven vehicles) to navigate the road ahead. This is all made possible by Google’s data centers, [Your chauffeur in the Cloud? Bob] which can process the enormous amounts of information gathered by our cars when mapping their terrain. To develop this technology, we gathered some of the very best engineers from the DARPA Challenges, a series of autonomous vehicle races organized by the U.S. Government. Chris Urmson was the technical team leader of the CMU team that won the 2007 Urban Challenge. Mike Montemerlo was the software lead for the Stanford team that won the 2005 Grand Challenge. Also on the team is Anthony Levandowski, who built the world’s first autonomous motorcycle that participated in a DARPA Grand Challenge, and who also built a modified Prius that delivered pizza without a person inside. The work of these and other engineers on the team is on display in the National Museum of American History."


(Related) Is this because existing Operating Systems can't be secured, or because they can't be compromised by the government? (e.g. India's request to tap BlackBerry encryption.)

http://tech.slashdot.org/story/10/10/11/0214249/Indian-Military-Organization-To-Develop-Its-Own-OS?from=rss

Indian Military Organization To Develop Its Own OS

Posted by timothy on Sunday October 10, @10:20PM

"Several newspapers have reported that DRDO (the defence R&D organization of the Indian military) is planning to create an OS. The need for this arose due to the cyber security concerns facing India and that all [conventional] operating systems are made outside India. About 50 professionals in Bangalore and New Delhi are expected to start work on this operating system."

At least one of the linked articles says the new OS, though home-grown, would run Windows software.



It's rare for Pogo to include an editorial cartoon, but this one from the Denver Post is is likely to make it into my Computer Security handouts.

http://www.pogowasright.org/?p=15694

Government surveillance plans



Aren't we doing this already?

http://www.bespacific.com/mt/archives/025433.html

October 09, 2010

Can We Create a National Digital Library?

New York Review of Books: Can We Create a National Digital Library? Robert Darnton - "The following talk was given at the opening of a conference at Harvard on October 1 to discuss the possibility of creating a National Digital Library."

  • "Despite the complexities, the fundamental idea of a National Digital Library (or NDL) is, at its core, straightforward. The NDL would make the cultural patrimony of this country freely available to all of its citizens. It would be the digital equivalent of the Library of Congress, but instead of being confined to Capitol Hill, it would exist everywhere, bringing millions of books and other digitized material within clicking distance of public libraries, high schools, junior colleges, universities, retirement communities, and any person with access to the Internet." See also:



For my students

http://www.makeuseof.com/tag/retail-software-free-student/

Get The Best Retail Software For FREE As A Student

Sunday, October 10, 2010

Not much of an update on web-cam-gate. (Sounds like they have picked a scapegoat.)

http://mainlinemedianews.com/articles/2010/10/07/main_line_times/news/doc4cac9d9eae731517978686.txt

LMSD officials address residents' concerns at community meeting in Ardmore church

In an Ardmore meeting Tuesday referred to as a community conversation with Lower Merion School District Supt. Chris McGinley, the subject of the district’s webcam controversy came up but McGinley did not go into specifics.

There are some actions that have been taken that amount to personnel actions,” McGinley told a number of residents attending the meeting. His comments answered one of them, who asked if anyone has been held accountable for wrongly using the webcams.



Humor: Facebook, by Mom for Moms...

http://www.youtube.com/watch?v=yu4zMvE6FH4&feature=player_embedded

Today Now!: Facebook, Twitter Revolutionizing How Parents Stalk Their College-Aged Kids



How can you discriminate against an ethnic group if you don't know who they are?

http://www.pogowasright.org/?p=15641

French cops claimed to hold secret, illegal gypsy database

October 9, 2010 by Dissent

Last month, I blogged about concerns raised by EDRI that France was compiling a biometric database of Roma that could lead to significant humanitarian concerns. Now more evidence has emerged that is raising concerns. Jane Fae Ozimek reports in The Register:

The French national police force – la Gendarmerie – yesterday stood accused of operating a secret and illegal database of Roma and other travelling minorities.

The existence of this database was reported in great detail in yesterday’s Le Monde. It came to light by chance, when a 48-page powerpoint presentation, prepared by a Commandant in the Central Bureau for prevention of Traveller Crime (OCLDI), and presented to a meeting of Transport Businesses in November 2004, turned up on the internet.

Read more in The Register.



An exercise for my Ethical Hackers: Embed a program on your target's laptop and have it report the laptop's location via Twitter and e-mail.

http://www.pogowasright.org/?p=15664

How sites can pinpoint you without the need for a GPS

October 10, 2010 by Dissent

Ben Grubb reports:

If you thought websites planting tracking “cookies” on your computer was a cause for privacy concerns, what’s known as “location-aware browsing” is able to pinpoint your physical location – and fairly accurately.

Electronic Frontiers Australia chairman Colin Jacobs said this could mean that various websites would have in their databases a history of “where you have been and when”.

If you’re on a computer with Wi-Fi – which most have these days (especially laptops) – then it’s likely you can be pinpointed using the Google Location Service.

Read more in The Age and follow the link to try the Firefox demo. When I tried it, Google was able to pinpoint my location exactly.

[From the article:

Using Firefox? Try out a demo of location-aware browsing



I would have thought this was obvious. But then, I'm not a lawyer.

http://www.pogowasright.org/?p=15661

Meta-data subject to public records law

October 9, 2010 by Dissent

Gene Johnson of The Associated Press reports:

Metadata associated with electronic documents — such as the “to” and “from” fields in e-mails — is a public record subject to disclosure, Washington’s Supreme Court ruled yesterday.

The 5-4 ruling concerned a Shoreline resident’s request under the Public Records Act for an e-mail that had been sent to the city’s deputy mayor. The resident received a copy of the e-mail without the metadata and subsequently filed a request for the information.

“Metadata may contain information that relates to the conduct of government and is important for the public to know,” Justice Susan Owens wrote in O’Neill v. City Of Shoreline.

Read more on The Olympian. Although this is not the first time a court has ruled this way, I think we all need to remain cognizant than when we e-mail public officials, if anyone requests their email under public records, our email address, name, etc. would be revealed.



An interesting if flawed argument. Poverty is not the issue. Political power is. The fact that the two are often linked causes confusion.

http://www.pogowasright.org/?p=15633

Article: A Fourth Amendment for the Poor Alone: Subconstitutional Status and the Myth of the Inviolate Home

October 9, 2010 by Dissent

Jordan C. Budd of the University of New Hampshire School of Law has an article in the Indiana Law Journal (Vol. 85, No. 2, 2010). Here’s the abstract:

For much of our nation’s history, the poor have faced pervasive discrimination in the exercise of fundamental rights. Nowhere has the impairment been more severe than in the area of privacy. This Article considers the enduring legacy of this tradition with respect to the Fourth Amendment right to domestic privacy. Far from a matter of receding historical interest, the diminution of the poor’s right to privacy has accelerated in recent years and now represents a powerful theme within the jurisprudence of poverty. Triggering this development has been a series of challenges to aggressive administrative practices adopted by localities in the wake of federal welfare-reform legislation. As a precondition to public assistance, some jurisdictions now require that all applicants submit to a suspicionless home search by law-enforcement investigators seeking evidence of welfare fraud. In turning back challenges to these intrusions, contemporary courts have significantly curtailed the protections of the Fourth Amendment as applied to the poor.

While the courts that sanction these practices disclaim any sort of poverty-based classification underlying their analysis, no other rationale withstands scrutiny. Neither precedent nor the principled extension of existing doctrine justifies recent outcomes or explains why the holdings should not be applied to authorize a vast – and, thus, unacceptable – expansion of suspicionless search practices directed at the homes of the less destitute. The developing jurisprudence accordingly represents an implicit concession that the poor constitute a subconstitutional class for purposes of the Fourth Amendment. Framed most charitably, the decisions understand poverty as a condition of moral culpability and thus accept it as a surrogate for the individualized suspicion that otherwise would be required to justify the intrusions at issue. The premise of the dissolute poor, tracing back centuries, remains alive and well in American law, and we have a bifurcated Fourth Amendment to prove its enduring vitality.

You can download the working paper from SSRN. (Hat-tip, Legal Theory Blog via @normative).

Although not specifically cited in the working paper, Budd’s article articulates nicely with a point made by Chief Judge Alex Kozinski in his dissent from the panel’s decision not to rehear the Pineda-Moreno ruling en banc:

There’s been much talk about diversity on the bench, but there’s one kind of diversity that doesn’t exist: No truly poor people are appointed as federal judges, or as state judges for that matter. Judges, regardless of race, ethnicity or sex, are selected from the class of people who don’t live in trailers or urban ghettos. The everyday problems of people who live in poverty are not close to our hearts and minds because that’s not how we and our friends live. Yet poor people are entitled to privacy, even if they can’t afford all the gadgets of the wealthy for ensuring it. Whatever else one may say about Pineda-Moreno, it’s perfectly clear that he did not expect– and certainly did not consent–to have strangers prowl his property in the middle of the night and attach electronic tracking devices to the underside of his car. [*10] No one does.

When you glide your BMW into your underground garage or behind an electric gate, you don’t need to worry that somebody might attach a tracking device to it while you sleep. But the Constitution doesn’t prefer the rich over the poor; the man who parks his car next to his trailer is entitled to the same privacy and peace of mind as the man whose urban fortress is guarded by the Bel Air Patrol. The panel’s breezy opinion is troubling on a number of grounds, not least among them its unselfconscious cultural elitism.

Saturday, October 09, 2010

A little advanced notice: Next week, our friends at the Privacy Foundation (http://privacyfoundation.org/) will be announcing a seminar on the “Legal Implications of Internet Advertising” to be held Friday, November 5th. You can contact Diane Bales at the Sturm College of Law at the University of Denver, 303.871.6580 or dbales@law.du.edu for more information.

http://yro.slashdot.org/story/10/10/08/1233236/New-Class-of-Malware-Will-Steal-Behavior-Patterns?from=rss

New Class of Malware Will Steal Behavior Patterns

Posted by Soulskill on Friday October 08, @09:32AM

"The information within huge, supposedly anonymized data sets can be used to build a detailed picture of an individual's lifestyle and relationships. This data is hugely valuable, which is why many companies already mine the pattern of links in their data to help them build things like recommender systems. Now a group of computer scientists say it is inevitable that a new class of malware will emerge for stealing this behavioral pattern data from social networks. They've analyzed the types of strategies this malware will use to collect information from a real mobile phone database of 800,000 links between 200,000 phones. They point out that the theft of behavioral data can be much more serious than the theft of other personal information. If somebody steals your credit card or computer password, for example, you can just get another card or change your password, thereby limiting the damage. That can't be done with behavioral data, they say. Who would be willing or able to change their real world pattern of person-to-person relationships, friendships and family ties?"



More on targeting Muslim communities for extra surveillance “to prevent crime.”

http://www.pogowasright.org/?p=15588

UK: The Independent View: surveillance lessons from Birmingham

October 8, 2010 by Dissent

James Elsdon-Baker, an activist with the NO2ID campaign, has a good commentary on the recent review of a poorly conceived, poorly communicated, and even more poorly implemented surveillance plan in Birmingham.

What U.S. readers will find particularly interesting are some of the statistics that he includes. Somewhat mind-boggling, to say the least.

Here’s a snippet from his article:

ANPR [Automated Number Plate Recognition Bob] differs from CCTV in that the information captured by the cameras is processed and stored on a massive centralized database. Although these cameras in a Muslim area are currently not in use (as I write it’s unclear if they will be taken down), there will remain a national network of over 10,000 cameras. Together they have captured over 7,600,000,000 occasions on which the location of people’s vehicles have been automatically logged. This data is held for five years at the National ANPR Data Centre (NADC) that is operated by the National Police Improvement Agency and routinely shared with other countries.

Read more on Liberal Democrat Voice.



Part of a CIO's job is to monitor system capacities and avoid problems like this. What else will they fail to do? NOTE: The previous article mentions 7 Billion records in the UK database.

http://yro.slashdot.org/story/10/10/09/0150204/US-Monitoring-Database-Reaches-Limit-Quits-Tracking-Felons-and-Parolees?from=rss

US Monitoring Database Reaches Limit, Quits Tracking Felons and Parolees

Posted by timothy on Saturday October 09, @04:24AM

"Thousands of US sex offenders, prisoners on parole and other convicts were left unmonitored after an electronic tagging system shut down because of data overload. BI Incorporated, which runs the system, reached its data threshold — more than two billion records — on Tuesday. This left authorities across 49 states unaware of offenders' movement for about 12 hours."

As the astonished submitter asks, "2 billion records?"

[From the article:

Prisons and other corrections agencies were blocked from getting notifications on about 16,000 people...

… In Wisconsin, local police and probation agents held about 140 sex offenders at local jails until the GPS tracking system was restored. [Prevented their release or rounded them up? Neither seems likely. Bob]

The offenders - about 300 in the state, most of them sex offenders - were never aware they were not being tracked, state Department of Corrections spokeswoman Linda Eggert said.

… “In retrospect, we should have been able to catch this” Jock Waldo BI Incorporated spokesman [“Well, DUH! Bob]


(Related)

http://www.pogowasright.org/?p=15584

Privacy Defense Mounted

October 8, 2010 by Dissent

Julia Angwin and Scott Thurm report:

Eleven of the nation’s largest website operators defended their privacy practices to lawmakers, saying it is impossible for them to monitor all the tracking technologies their sites install on visitors’ computers. [What they actually said was: "It is technically impossible for Yahoo! to be aware of all software or files that may be installed on a user's computer when they visit our site" Bob]

The operators, including Microsoft Corp., Yahoo Inc. and AOL Inc., say they are improving disclosures about online tracking and offering users more ways to protect their privacy. But they say that eliminating tracking is technically difficult and economically impractical, [“Do you know how expensive it is to flip a switch!” Bob] because the targeted advertisements supported by tracking allow the operators to offer free content.

Read more: on WSJ (behind paywall, though)

If I were writing the headline for this, I wouldn’t have called it “Privacy Defense Mounted.” Maybe “Website Operators Claim They Really Have No Idea What They’re Doing.”



Coming soon to a National Health Records system near you!

http://www.phiprivacy.net/?p=4192

AU: iPads for Doctors

By Dissent, October 8, 2010

The Australian Privacy Foundation has written to the Victorian Department of Health over reports that 500 iPads are to be provided to graduate doctors and nurses. Noting the potential benefits of such technology, APF honed in on a few key privacy and security and issues.

In a letter signed by Roger Clarke, the group asks Andrew Howard, Chief CIO for the Department of Health, whether the pilot study reportedly being conducted was ever approved by an research ethics review board. It also asks whether there’s been a privacy impact assessment, and:

APF understands that many of the staff involved are academic-clinicians and are staff of both Alfred Health and Monash University. APF further understands that Monash uses Google as its email-provider.

What consideration has been given to the proprietary nature of both the Apple and Google services and data formats, and the data security aspects of the services, in the context of inter-operable information sharing


(Related) A video demoing some of the technology Kaiser Permanente is considering.

http://news.cnet.com/1606-2_3-50094204.html?part=rss&subj=news&tag=2547-1_3-0-20

Inside the hospital of the future



Think of this as notification that you are already too late.

http://yro.slashdot.org/story/10/10/08/190203/New-Tool-Suite-Helps-Track-Privacy-Policies?from=rss

New Tool Suite Helps Track Privacy Policies

Posted by Soulskill on Friday October 08, @03:10PM

"Forbes reports that The Internet Society announced this week the availability of the Identity Management Policy Audit System, a suite of tools designed to give Internet users a clearer understanding of the online usage policies of the websites they visit. Born out of a collaboration between The Internet Society, the University of Colorado, the Electronic Frontier Foundation, and the Center for Democracy and Technology, the system consists of a free, open-source Firefox plug-in that checks a library of scraped terms of service and privacy policies from several popular websites. If a site changes the fine print of one of its policies, the plug-in notifies the user when they visit the website next. According to Forbes, 'that functionality would help users spot controversial switcheroos in sites' legalese, such as Facebook's change last year that suddenly gave the site the right to use your photos and other content.'"



More on the Aldi skimmers.

http://www.databreaches.net/?p=14528

Skim Scam: Did Aldi Invite 11-State Coordinated Attacks?

October 8, 2010 by admin

Frank Hayes writes:

When a gang of thieves physically tampers with point-of-sale systems, the tampering is usually a local operation. But that may be changing. Discount grocer Aldi said Friday (Oct. 1) that it has found tampered payment-card readers in stores in 11 states, spread from the east coast to Illinois. The retailer said the tampering was only in a limited number of its 1,100 U.S. stores, and all those stores were clustered near 10 cities—but the stolen data is being cashed out thousands of miles away.

Read more on StorefrontBacktalk. Via @_Florindo_

Reading the full commentary, I started thinking that this sounds very much like we heard in the Hancock Fabrics breach. In that multi-state breach, the chain also seemingly used older pin pads.

Are older pin pads a thief’s best friend?

[From the article:

The retailer won’t say exactly how many stores got the tampered devices, but a spokesperson said that they were found in only a “limited number” of stores, and they were probably placed there during June, July and August. [and no one noticed! Bob]

… And because Aldi only accepts debit cards, not credit cards, at most stores, the card information collected by a skimmer (complete with PIN) would give direct access to a customer’s bank account.

These kind of physical attacks should be much less common than they are, and they would be that much less common if retailers were more meticulous about reviewing their network activity logs, [AMEN! Bob] said QSA-and StorefrontBacktalk PCI Columnist-Walter Conway. “There should be huge red flags in the logs if anyone disconnects a terminal.



Does anyone leave their laptop in their checked baggage?

http://hardware.slashdot.org/story/10/10/09/0023211/FAA-Reports-Heat-In-Cargo-Holds-Can-Ignite-Laptop-Batteries?from=rss

FAA Reports Heat In Cargo Holds Can Ignite Laptop Batteries

Posted by timothy on Saturday October 09, @01:23AM

"US aviation officials are warning air carriers that new research shows lithium batteries are sensitive to heat and can ignite in-flight if transported in cargo compartments that get too hot. The Federal Aviation Administration also acknowledged publicly for the first time Friday that a United Parcel Service 747-400 plane that crashed in Dubai last month killing both pilots was carrying a large quantity of lithium batteries. Since the early 1990s, there have been dozens of incidents of batteries igniting in flight. But it has not been known what triggered many of the fires. FAA now says recent research has identified heat as the trigger and is offering air carriers advice on how to reduce the risk of fire."



Are we missing something? The EU seems to think this is an early peak at “Weapons of Cyberwar”

http://news.cnet.com/8301-27080_3-20019124-245.html?part=rss&subj=news&tag=2547-1_3-0-20

EU calls Stuxnet 'paradigm shift' as U.S. responds more mildly

While official U.S. response has been comparatively mild, the European Union's cybersecurity agency says Stuxnet represents a "paradigm shift" in critical infrastructure threats and that current defense philosophies need to be reconsidered.



Again I suspect I'm missing something. The judge seems to be suggesting that everyone will be insured at the same rate and that rate won't cover the payouts. If that is true, then the “Insurance Industry” is already gone, isn't it?

http://www.scotusblog.com/2010/10/health-insurance-mandate-upheld/

Health insurance mandate upheld

A federal judge in Detroit, in a broad ruling upholding Congress’s power to require all Americans to buy health insurance or pay a penalty, decided Thursday that the mandate is necessary to prevent the “extinction” of the nation’s entire health care insurance market. U.S. District Judge George Caram Steeh said the requirement was well within Congress’s power to regulate commerce among the states. The decision is the first by a federal court to rule directly on the constitutionality of the buy-or-be-penalized provision of the sweeping new health care reform law.

The Obama Administration lost on two arguments it had made to Judge Steeh — that the challengers in the Michigan case had no legal right to sue to stop the insurance mandate, and that their lawsuit in any event was premature. But, after finding that the challengers were properly in court and that a decision was appropriate now, the judge went on to rule that the requirement satisfies the Constitution and dismissed the claims targeting that specific provision of the new law. Thus, the result was a major victory for the Administration.



This is too strange. But if it is a fake, it's a good one.

http://regretfulmorning.com/2010/10/woman-uploads-child-porn-police-raid-her-neighbors-house-then-it-really-gets-strange/

Woman Uploads Child Porn, Police Raid Her Neighbor’s House…then it Really Gets Strange



Tools & Techniques

http://www.killerstartups.com/Web-App-Tools/markup-io-a-tool-for-drawing-on-webpages

Markup.io - A Tool For Drawing On Webpages

Markup is a new collaboration tool that will let you draw on any webpage that you come across, and communicate your ideas to others in a more visual way. Certainly, being able to draw a pattern highlighting where different parts of a design you are should be is a much quicker way to let the rest of your team know what you mean than writing a long email that can be misinterpreted to no end.

Markup is a browser-hosted application. You (and your coworkers) won’t need to download anything on order to use it. All you will have to do is drag and drop the relevant bookmarklet into position. From that point onwards, Markup can be launched by merely clicking on the relevant button.

… And I didn’t mention it above, but you also have a tool for writing text on the page.

http://markup.io/



Tools & Techniques

http://www.makeuseof.com/tag/awesome-free-tools-infographics/

10 Awesome Free Tools To Make Infographics

Friday, October 08, 2010

Hey, it's the law!

http://yro.slashdot.org/story/10/10/08/0051245/French-ISP-Refuses-To-Send-Out-Infringement-Notices?from=rss

French ISP Refuses To Send Out Infringement Notices

Posted by timothy on Friday October 08, @02:19AM

"Last month it was clear that French ISPs were not at all happy about the whole three strikes Hadopi process in France. Now that the 'notice' process has started, with Hadopi sending out notices to 10,000 people per day, it's hit a bit of a stumbling block. The French ISP named 'Free' has apparently figured out a bit of a loophole that allows it to not send out notices and protect its subscribers. Specifically, the law requires ISPs to reveal user info to Hadopi, but it does not require them to alert their users. But, the law does say that only users who are alerted by their ISP can be taken to court to be disconnected. In other words, even if Free is handing over user info, so long as it doesn't alert its users (which the law does not mandate), then those users cannot be kicked off the internet via Hadopi."



In the UK they make speeches....

http://www.pogowasright.org/?p=15534

Speeches: “The English Law of Privacy: An Evolving Human Right” – Lord Walker

October 7, 2010 by Dissent

Hugh Tomlinson QC writes:

On 25 August 2010 Supreme Court Justice Lord Walker of Gestingthorpe gave a speech to Anglo-Australasian Lawyers Society at Owen Dixon Chambers, Melbourne on the subject of privacy. His title was “The English Law of Privacy: An Evolving Human Right“. The lecture contains an interesting an useful overview of the current law of privacy, particularly in relation to the media. Lord Walker suggests that, as the law of privacy develops “its origin in the law of confidence will become a historical curiosity” and that we have now reached the point where “invasion of personal privacy” is a separate tort.

Read more on UKSC Blog.

[From the article:

He emphasises the importance of “the discipline of analysing an issue correctly“, considering first the question of interference with Article 8 rights and second that of the justification for that interference.


(Related) In the US, we give “lip service”

http://www.pogowasright.org/?p=15531

White House lies says online investigations, privacy can coexist

October 7, 2010 by Dissent

Aliya Sternstein reports:

Civil liberties and national security are at the core of the White House’s cybersecurity agenda, a senior administration official said late Wednesday, amid concerns the FBI’s desire to wiretap the Internet conflicts with protecting personal information on the Internet.

“We don’t take the position that this is an either-or situation,” the official said during the first week of the 7th annual National Cybersecurity Awareness Month. “Hardening our cybersecurity defenses around critical infrastructure and protecting classified and sensitive information go hand in hand and are easy examples to point to.”

You can read more on NextGov. Personally, I can’t read any more of the government’s bullshit on this. If they’re serious about protecting personal information: WHY IS THE PRIVACY AND CIVIL LIBERTIES OVERSIGHT BOARD STILL SITTING EMPTY?


(Related) In any case, actions speak louder than words.

http://www.phiprivacy.net/?p=4173

Breach Notice: The Struggle for Medical Records Security Continues

By Dissent, October 7, 2010

William Pewen, who was involved in drafting the language in ARRA, has an excellent commentary on Health Affairs Blog:

On July 28 the Obama Administration surprised many in the health sector by withdrawing a pending Department of Health and Human Services (HHS) final “breach notification” rulegoverning when consumers must be informed of illicit access or use of their medical records. With this exceptional action, the Administration now has a critical opportunity to correct a rule which undermined congressional efforts to secure medical records. Contrary to the underlying statutory language – which I took the lead in drafting as the senior health advisor to Senator Olympia Snowe (R-ME) – the rule drafted by HHS to implement the statute would have allowed medical providers to bypass notification if they themselves decided that consumers had not been harmed by a breach.

Withdrawal of the rule is a positive step. However, efforts to weaken consumer privacy protections will resume. Industry will once again attempt to block efforts to promote transparency and data security, and support for health information technology (IT) will erode if Americans find Washington unresponsive in protecting their health information.

Read more of his thoughtful commentary on Health Affairs Blog.



Gary Alexander sent me this one. Should be interesting.

http://www.law.com/jsp/article.jsp?id=1202472987882&src=EMC-Email&et=editorial&bu=Law.com&pt=LAWCOM%20Newswire&cn=nw20101007&kw=Internet%20Privacy%20Suits%20Filed%20Against%20Yahoo%2C%20Others

Internet Privacy Suits Filed Against Yahoo, Others

A set of potential class actions filed recently in Fulton County, Ga., Superior Court against three Internet powerhouses raises interesting questions about how law enforcement agencies get information about Internet users without their knowledge.

While the suits address the government's ability to see what people do on the Web, their viability may turn on more process-oriented questions: how Georgia subpoenas and warrants are served and where they are valid.

The suits claim that Comcast, Yahoo and Windstream have violated federal wiretap and computer privacy laws by providing information in response to warrants or subpoenas issued by Georgia judges or magistrates, which are then faxed or otherwise relayed to the Internet companies' headquarters outside of Georgia.

"If these were federal warrants, there would be no cause of action," said one of the plaintiffs' attorneys, Joshua A. Millican. "But these are state warrants, and they have no force outside of the state of Georgia."

… The three suits, filed on behalf of two class representatives, charge "willful violations" of the U.S. Stored Communications Act [SCA] and the Wiretap Act by each company.

Each defendant "routinely and unlawfully accepts as valid legal process from law enforcement and other government entities" faxed subpoenas from state grand juries or trial judges, often with instructions not to notify the customer whose account will be searched, the suit said.

"Search warrants signed by state magistrates and other state judges have no force and effect outside of the state of issuance," the suits claim, "and when faxed or sent out of state, said search warrants are not deemed issued by a court of competent jurisdiction."

… In addition to violations of the SCA and Wiretap Act, the four-count complaints also accuse the companies of breach of contract and breach of implied duty of good faith and fair dealing.

… Millican said he has been unable to find any case law that raises the issues his complaints do.

"Both the Wiretap Act and the SCA have a good faith clause -- there's a case out there that says an unsigned warrant was fine -- but again, that's for a federal warrant. But that doesn't apply to a Georgia subpoena being served in California."

Millican said that it would be easy for a local law enforcement agency to comply with the law.

"In the Comcast case," he said, "all it would take is for the Cherokee County sheriff to call a judge in New Jersey and say, 'I've got this person down here I'm investigating, I need a warrant.' Then the marshal up there serves it."



Gee, maybe their strategy isn't to increase privacy... Maybe it's to facilitate Behavioral Advertising. In that context, this make sense.

http://www.pogowasright.org/?p=15529

Irony: Facebook’s New Groups Give Me Less Control, Not More

October 7, 2010 by Dissent

Danny Sullivan writes:

I missed Facebook’s press conference yesterday about the new Facebook Groups feature that promises that you can share comments, photos and other information more tightly among only people you trust. But I learned about the feature firsthand soon enough, when I found myself added to a group without being asked. And that was worrisome.

Robert Scoble had created the group, invited a number of people, and I was flattered to be included. But Facebook should have asked me first, not just let Robert Scoble or anyone put me into a group without permission.

In fact, I was pretty aghast this had happened. This company has time-and-time-again been accused of trying to push people into being less private, giving them less control. Here, yet again it rolls out a feature that suggests better privacy but gets things wrong. Share with only those you “care about the most” and “feel confident about who sees” what you post, the Facebook blog posts pitch us. But groups go wrong from the beginning, by failing to ask if you want to be included.

It gets worse. As best I can tell, once you’re in a group, you can add anyone else to it. I’m pretty sure the rest of the group members aren’t notified when you do this. The group I’m in started with no one, and now it’s up to over 500 people. I wasn’t told when new people were added, nor is there a notification option for this…

Read more on SearchEngineLand.



For my Ethical hackers. Should we create bogus certificates for our machines or would it be more amusing to change the “Master” to indicate that all machines (except ours) are infected?

http://it.slashdot.org/story/10/10/08/006240/Microsoft-Eyes-PC-Isolation-Ward-To-Thwart-Botnets?from=rss

Microsoft Eyes PC Isolation Ward To Thwart Botnets

Posted by timothy on Thursday October 07, @08:09PM

"In a paper published Wednesday (PDF), Scott Charney, who heads Microsoft's trustworthy computing group, spelled out a concept of 'collective defense' that he said was modeled after public health measures like vaccinations and quarantines. The aim: To block botnet-infected computers from connecting to the Internet. Under the proposal, PCs would be issued a 'health certificate' that showed whether the system was fully patched, that it was running security software and a firewall, and that it was malware-free. Machines with deficiencies would require patching or an antivirus update, while bot-infected PCs might be barred from the Internet."



Search the Internet like a librarian?

http://www.freetech4teachers.com/2010/10/dewey-digger-explore-knowledge.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+freetech4teachers%2FcGEY+%28Free+Technology+for+Teachers%29

Thursday, October 7, 2010

Dewey Digger - Explore Knowledge

Dewey Digger is an interesting attempt to catalog the web according to the Dewey Decimal System. To use Dewey Digger just click on a Dewey Decimal category. Then select a topic in that category. Once you've selected a topic Dewey Digger will present you with twenty-seven sources of information. Click any of those sources to see articles, videos, and images on your chosen topic.



Can I have your autograph?

http://www.makeuseof.com/tag/electronically-sign-pdf-documents-free-adobe-esignatures/

Electronically Sign Your PDF Documents For Free Using Adobe eSignatures

… you can now electronically sign documents, using your email address as verification of identity. Many similar online tools require payment for the service, but the Adobe eSignatures beta is completely free (at least for now).



Understandable statistics on child mortality.

http://www.ted.com/talks/hans_rosling_the_good_news_of_the_decade.html#9403263583125429969

Hans Rosling: The good news of the decade?