Tuesday, May 10, 2011

You shouldn't read this if you've got nothing to hide...

http://www.pogowasright.org/?p=22784

Chapter 1 of Nothing to Hide available online

May 10, 2011 by Dissent

Daniel Solove writes:

I’ve posted Chapter 1 of my new book, NOTHING TO HIDE: THE FALSE TRADEOFF BETWEEN PRIVACY AND SECURITY (Yale University Press, May 2011) on SSRN. The book is about some of the common arguments made in the debate between privacy and security. Chapter 1 is here



Do they? I hadn't noticed.

http://www.pogowasright.org/?p=22769

How Teens Understand Privacy

May 9, 2011 by Dissent

Danah Boyd writes:

In the fall, Alice Marwick and I went into the field to understand teens’ privacy attitudes and practices. We’ve blogged some of our thinking since then but we’re currently working on turning our thinking into a full-length article. We are lucky enough to be able to workshop our ideas at an upcoming scholarly meeting (PLSC), but we also wanted to share our work-in-progress with the public since we both know that there are all sorts of folks out there who have a lot of knowledge about this domain but with whom we don’t have the privilege of regularly interacting.

“Social Privacy in Networked Publics: Teens’ Attitudes, Practices, and Strategies”

by danah boyd and Alice Marwick

[...]


(Related)

http://yro.slashdot.org/story/11/05/10/0039249/Who-Owns-Your-Social-Identity?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Who Owns Your Social Identity?

"Who actually owns your username on a website? What rights do you have to use it? An IEEE Spectrum podcast reports: 'What happens if Facebook or Twitter or, say, your blog hosting service, makes you take a different user name? Sound impossible? It's happened. Last week, a software researcher named Danah Boyd woke up to find her entire blog had disappeared, and in fact, had been renamed, because her hosting service had given her blog's name to someone else.' And as important as they are, what protects our accounts are the terms of service agreements. If you read them — and who does? — you'd learn, probably to no surprise, that they protect the provider a lot more than they protect you." [After all, they paid the lawyers who wrote them... Bob]



Can you remain anonymous in a world of ubiquitous surveillance?

http://www.wired.com/gadgetlab/2011/05/iphone-udid/

Anonymous IDs on iPhones, iPads Can Reveal Your Identity

The unique string of numbers and letters assigned to your iPhone can potentially expose your real-life identity.

Security researcher Aldo Cortesi last week published his discovery of a flaw in the unique device identifier (UDID) stored on each iPhone, iPad and iPod Touch.

While this device identifier is well-known, it’s not supposed to be connected to a person’s actual identity. But Cortesi discovered that some apps can link the identifier to the phone owner’s Facebook profile, which effectively puts a face behind that string of numbers and letters.

“It’s like a permanent, unalterable tracking cookie that can’t be changed and that the user is not aware of,” Cortesi told Wired.com. “The UDID idea has got such deep flaws because it literally identifies the device.”



It's not confusion, it's obfuscation! (We can charge more for that...)

http://yro.slashdot.org/story/11/05/10/0155218/Confusion-Surrounds-UK-Cookie-Guidelines?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Confusion Surrounds UK Cookie Guidelines

"The Information Commissioner's Office has, with just over two weeks to go, given its interpretation on what websites must do to comply with new EU regulations concerning the use of cookies. The law, which will come into force on 26 May 2011, comes from an amendment to the EU's Privacy and Electronic Communications Directive. It requires UK businesses and organizations running websites in the UK to get informed consent from visitors to their websites in order to store and retrieve information on users' computers. The most controversial area, third-party cookies, remains problematic. If a website owner allows another party to set cookies via their site (and it is a very common practice for internet advertisers) then the waters are still muddy. And embarrassingly for the Commission — it's current site would not be compliant with its new guidelines as it simply states what they do and does not seek users' consent."



No need to go to court, just pay us our Greenmail (closest word I could find) and we'll drop the suit.

http://tech.slashdot.org/story/11/05/10/0048246/23000-File-Sharers-Targeted-In-Latest-Lawsuit?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

23,000 File Sharers Targeted In Latest Lawsuit

"Subpoenas are expected to go out to ISPs this week in what could be the biggest BitTorrent downloading case in US history. At least 23,000 file sharers are being targeted by the US Copyright Group for downloading The Expendables. The Copyright Group appears to have adopted Righthaven's strategy in blanket-suing large numbers of defendants and offering an option to quickly settle online for a moderate payment. The IP addresses of defendants have allegedly been collected by paid snoops capturing lists of all peers who were downloading or seeding Sylvester Stallone's flick last year. I am curious to see how this will tie into the BitTorrent case ruling made earlier this month indicating that an IP address does not uniquely identify the person behind it."


(Related) Competition is good... usually.

http://www.wired.com/threatlevel/2011/05/nude-nuns-brouhaha/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

Two Firms Battle for Right to Sue Nude Nuns Downloaders


(Related)

http://news.cnet.com/8301-31001_3-20061280-261.html

Unlicensed Google Music arrives Tuesday



I'm just trying to understand the “social world”

http://www.cbsnews.com/stories/2011/05/09/ap/tech/main20061100.shtml

Facebook sharing sending readers to big news sites

Facebook is playing a role in what news gets read online as people use the Internet's most popular hangout to share and recommend content.

That's according to a study released Monday by the Pew Research Center's Project for Excellence in Journalism.

Facebook funneled an average of 3 percent of traffic to 21 major news sites that allowed the data to be tracked. The report is based on an analysis of Internet traffic data compiled by the research firm Nielsen Co. during the first nine months of last year.

That's still small compared with Google Inc.'s media clout. Pew says Google's dominant search engine supplies about 30 percent of traffic to the top news site.

[Pew study: http://www.journalism.org/analysis_report/navigating_news_online


(Related) Are you ready to have your life reviewed by your peers everyone?

http://www.technologyreview.com/computing/37531/page1/

Facebook Could Be Planning a Visual Dashboard of Your Life

Ever wondered just how much coffee you drank last year, or which movies you saw, and when? New Web and mobile apps make it possible to track, and visualize, this personal information graphically, and the trend could be set to expand dramatically.

This is because Facebook recently acquired one of the leading personal-data-tracking mobile apps and hired its creators. The social-networking giant could be gearing up to offer users ways to chart the minutiae of their lives with personalized infographics.

Nick Felton and Ryan Case, two New York-based designers, have pioneered turning the mundane contours of an everyday life into a kind of visual narrative. Each year, Felton publishes an "annual report" on his own life: an infographic that charts out his habits and lifestyle in great detail.


(Related) “Our 'Terms of Service' say we can ignore our 'Terms of Service' if we want to...”

http://news.cnet.com/8301-19518_3-20061298-238.html

Survey: 7.5M Facebook users below minimum age

A survey published in the June issue of Consumer Reports (available now) found that "of the 20 million minors who actively use Facebook," 7.5 million were younger than 13 and more than five million were younger than 10. Facebook's terms of service require that users be at least 13.

The report tracks with other studies including a 2010 study by McAfee that found 37 percent of 10 to 12 year olds are on Facebook and a study (PDF) released in April from the London School of Economics EU Kids Online project that found that 38 percent of 9- to 12-year-old European children used social-networking sites, with one in five using Facebook, "rising to over 4 in 10 in some countries."


(Related)

http://techcrunch.com/2011/05/09/attention-dear-sophie-inspired-parents-you-cant-actually-create-a-google-account-for-your-kid/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

Attention ‘Dear Sophie’-Inspired Parents, You Can’t Actually Create A Google Account For Your Kid



Now Microsoft can be a Phone Company and a major Social Network provider. (No need to Text while driving if you can talk instead?)

http://www.readwriteweb.com/archives/skype_acquired_by_microsoft_3_fears_3_hopes.php

Skype Acquired by Microsoft: 3 Fears & 3 Hopes

In a shocking late-night turn of events it was revealed Monday that Microsoft has acquired Skype for more than $8 billion. (Confirmed by Microsoft this morning here.) It's a bold move that raises a lot of issues. ReadWriteWeb's Founding Editor Richard MacManus argued that the companies together could make big waves in two key parts of the future: mobile and the connected home.



I tell you, it's growing! We can't stop it from growing! And the worst part? It's hungry!

http://hardware.slashdot.org/story/11/05/09/1959213/Worlds-Servers-Process-957ZB-of-Data-a-Year?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

World's Servers Process 9.57ZB of Data a Year

"Three years ago, the world's 27 million business servers processed 9.57 zettabytes, or 9,570,000,000,000,000,000,000 bytes of information. Researchers at the School of International Relations and Pacific Studies and the San Diego Supercomputer Center estimate that the total is equivalent to a 5.6-billion-mile-high stack of books stretching from Earth to Neptune and back to Earth, repeated about 20 times. By 2024, business servers worldwide will annually process the digital equivalent of a stack of books extending more than 4.37 light-years to Alpha Centauri, the scientists say. The report, titled 'How Much Information?: 2010 Report on Enterprise Server Information,' (PDF) was released at the SNW conference last month."


Monday, May 09, 2011

They are even considering a reward for ratting out the hackers. Might be fun to see how many thousands of bad leads that generates.

http://www.metro.co.uk/tech/games/862731-sony-playstation-network-may-not-be-back-online-before-may-31

Sony PlayStation Network may not be back online before May 31

Last week, Sony were strongly suggesting that services could be restored within a week - they said in a statement that they were in 'the final stages of internal testing of the new system' - but over the weekend they announced that the return of the PSN had been delayed.

And now that date looks to have slipped even further, with a Sony spokesman telling Bloomberg that they were uncertain of when the networks would be back, with May 31 the only firm date they would give for the complete restart of services.



It will be interesting to see how they implement this... Can you say: “Shrink Wrapped Websites?”

http://www.pogowasright.org/?p=22756

UK: ICO advice on new EU cookies law published

May 9, 2011 by Dissent

Advice on how UK businesses and organisations can comply with a new EU law on the use of cookies technology has been published today by the Information Commissioner’s Office (ICO).

The law, which will come into force on 26 May 2011, comes from an amendment to the EU’s Privacy and Electronic Communications Directive.

The advice, which follows the publication of UK regulations by the Department for Culture, Media and Sport, will help people to consider what type of cookie or similar technology their website uses and for what purpose, how intrusive their use is, and offers advice on what solution for obtaining consent will suit them.

From the advice:

What do the new rules say?

The new requirement is essentially that cookies can only be placed on machines where the user or subscriber has given their consent.

6 (1) Subject to paragraph (4), a person shall not store or gain access to information stored, in the terminal equipment of a subscriber or user unless the requirements of paragraph (2) are met.

(2) The requirements are that the subscriber or user of that terminal equipment–

(a) is provided with clear and comprehensive information about the purposes of the storage of, or access to, that information; and
(b) has given his or her consent.

(3) Where an electronic communications network is used by the same person to store or access information in the terminal equipment of a subscriber or user on more than one occasion, it is sufficient for the purposes of this regulation that the requirements of paragraph (2) are met in respect of the initial use.

“(3A) For the purposes of paragraph (2), consent may be signified by a subscriber who amends or sets controls on the internet browser which the subscriber uses or by using another application or programme to signify consent.

(4) Paragraph (1) shall not apply to the technical storage of, or access to, information–

(a) for the sole purpose of carrying out the transmission of a communication over an electronic communications network; or
(b) where such storage or access is strictly necessary for the provision of an information society service requested by the subscriber or user.



As we suspected...

http://it.slashdot.org/story/11/05/08/2339252/File-hosting-Sites-Not-a-Safe-Haven-For-Private-Data?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

File-hosting Sites Not a Safe Haven For Private Data

"Academic researchers say they've uncovered weaknesses in dozens of the most popular file hosting sites that allow people to gain unauthorized access to data that's supposed to be available only to those selected by the user."



I can see this genre of phone apps expanding until it reproduces the classic “Stalking the Wild Asparagus”

http://techcrunch.com/2011/05/08/for-the-high-tech-naturalist-leafsnap-identifies-leaves-using-your-iphones-camera/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

For The High-Tech Naturalist: LeafSnap Identifies Leaves Using Your iPhone’s Camera

This is just plain fantastic. The LeafSnap app for iPhone identifies any leaf you take a picture of, as long as it’s in their library. Check out the video inside.



Download the free editions...

http://yro.slashdot.org/story/11/05/08/1346251/2-RMS-Books-Hit-Version-20?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

2 RMS Books Hit Version 2.0

"The Free Software Foundation (FSF) has just released in tandem the second edition of its president and founder Richard Stallman's selected essays, Free Software, Free Society, and his semi-autobiography, Free as in Freedom: Richard Stallman and the Free Software Revolution."

http://www.gnu.org/doc/fsfs-ii-2.pdf

http://static.fsf.org/nosvn/faif-2.0.pdf



Speaking of books... I am a fan of Science Fiction. Occasionally, a SciFi writer hits the “prediction” nail on the head. Deep State, by Walter Jon Williams seems to do just that. Published in February 2011, it documents an “Astroturfing” (synthetic 'grass roots') project that provokes peaceful demonstrations against a military dictatorship. Warning: It is not “great literature” or even really good science fiction, but the technology (cell phones) and the “flash mob” response provoked seem to match recent history all too well. Is it possible “Arab Spring” was a CIA plot? Naaah...

Timeline of “Arab Spring” http://www.guardian.co.uk/world/interactive/2011/mar/22/middle-east-protest-interactive-timeline


Sunday, May 08, 2011

Sony is still thrashing about (and finding data they should have removed years ago)

http://news.cnet.com/8301-31021_3-20060773-260.html

Sony: More testing needed before PlayStation relaunch

Sony's breached PlayStation Network may well be offline longer than the company had expected, according to a Sony executive.

In a post on Sony's PlayStation.Blog late yesterday, Patrick Seybold, senior director of corporate communications and social media for the company, said Sony was still performing security checks on the system and that it might not be back up and running in the originally announced timeframe. Part of the problem, Seybold said, has been the hitherto unknown size of a breach of the Sony Online Entertainment gaming network, discovered during Sony's investigation into the PlayStation intrusion.

Meanwhile, the company said today that on Thursday it removed 2,500 customer names and partial addresses that had been stolen by hackers and posted on a Sony Web site. The names belonged to mostly U.S. customers who had entered a contest in 2001. Sony said the Web site was "out of date and inactive" when discovered and that the company took the page down. CNET reported on Thursday that hackers were planning to break into an unspecified Sony Web site this weekend and post information gleaned from the attack somewhere online.


(Related)

http://linux.slashdot.org/story/11/05/07/1936221/Sony-Encourages-Linux-On-Their-Phones?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Sony Encourages Linux On Their Phones

"Sony has been in the news a lot lately — from the PSN downtime and the identity theft issue that came with it, to the numerous court cases launched to try and quell the PS3 hacking scene. It may come as a surprise to many, then, that Sony's mobile smartphone division has taken an almost polar-opposite approach — they're actively encouraging developers to create, modify and install customized Linux kernels into their latest lineup of phones, including the Xperia Play, the device that was once known as the 'PlayStation Phone.'"



The changing face of techie education. This is my kind of student project! (Can I get a cut of the profits?)

http://news.slashdot.org/story/11/05/07/2153246/The-Stanford-Class-That-Built-Apps-and-Made-Fortunes?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

The Stanford Class That Built Apps and Made Fortunes

The NY Times has a story about a group of students who took a 2007 course in app development at Stanford that turned out far better than any of them expected. Quoting:

"... by teaching students to build no-frills apps, distribute them quickly and worry about perfecting them later, the Facebook Class stumbled upon what has become standard operating procedure for a new generation of entrepreneurs and investors in Silicon Valley and beyond. ... Early on, the Facebook Class became a microcosm of Silicon Valley. Working in teams of three, the 75 students created apps that collectively had 16 million users in just 10 weeks. Many of those apps were sort of silly: Mr. De Lombaert’s, for example, allowed users to send “hotness” points to Facebook friends. Yet during the term, the apps, free for users, generated roughly $1 million in advertising revenue."


(Related)

http://gaming.icrontic.com/article/nea-video-games-are-an-art-form/

NEA: video games are an art form

The US federal government, by way of the National Endowment for the Arts (NEA), now considers video games a form of art, making a true step toward recognition for the oft under-recognized form.

The NEA is a program under the federal government which has the mission of deciding which grand artistic projects are worthy of receiving Federal funding. Artists around the country can submit applications to the agency for works which will enhance the public good. It allows artists who are creating outside of the commercial art world to work and live, through grants of up to $200k; artists who otherwise would have to either enter the profit-centered world of commercial art, or stop creating (or starve, I suppose).



Still might be fun for my Statistics students to play with...

http://www.bespacific.com/mt/archives/027205.html

May 07, 2011

University of Texas Releases Faculty Productivity Data

Release of Faculty-Productivity Data Roils U. of Texas, By Audrey Williams June, Chronicle of Higher Education

  • "How much professors in the University of Texas system earn and how many courses and students they teach were parts of a vast data file that system officials compiled at the request of a newly formed task force on productivity and excellence and released publicly on Thursday. Professors immediately voiced concerns that the information would be used to incorrectly gauge their efficiency on the job. However, system officials stressed that the data in the 821-page spreadsheet, which covers nine institutions, was in draft form and "is incomplete and has not yet been fully verified or cross referenced," according to a statement issued by Anthony P. de Bruyn, the system's director of public affairs. "In its present raw form, it cannot yield accurate analysis, interpretations, or conclusions."



For my Computer Security students. Keep the link, not the software!

http://www.makeuseof.com/tag/find-elusive-malware-pc-microsoft-safety-scanner/

Find Elusive Malware On Your PC With Microsoft Safety Scanner

Do emergency scans of your computer with Microsoft’s latest free download. Microsoft Safety Scanner, a portable application that can examine any PC, can’t replace a full-blown anti-virus program, but it is a great tool to have around should infections pop up. Best of all – because it doesn’t need to be installed, you can easily download it on one computer, stick it on a thumb drive and clean up another computer.

… This tool is Microsoft’s answer to scan-only tools such as Malwarebytes and Combofix: tools intended to clean up existing messes, not prevent future ones. As such, this is less something every home user should download than something they should be aware of should something go wrong.

Take note that Safety Scanner cannot update itself. As such, you’ll need to re-download it every ten days if you want to make regular use of it.

The first thing you need to do is head over to the Safety Scanner download page and grab the program.

… The file you will download is an .exe file. There’s nothing to install; you’re ready to start scanning if you’d like.


Saturday, May 07, 2011

For my Ethical Hackers. This is why I (like Sargent Schultz) want to “know nothing!”

http://news.cnet.com/8301-1009_3-20060661-83.html

Sony considers offering reward to help catch hackers

Still coping with the aftereffects of a pair of attacks that has compromised as many as 100 million accounts and which caused two online gaming services to be taken offline, Japanese electronics giant Sony is considering offering a reward for information leading to the arrest and prosecution of the attackers, people familiar with the matter say.

The company hasn't reached a final decision concerning whether it will offer a reward, and may decide not to do it at all, but the option is on the table, sources told me today.

… Word of a possible reward offering comes as the Financial Times reported that two members of the hacking group Anonymous have informed the FBI that members of the loosely associated group of activist hackers carried out the attacks that compromised the system and prompted Sony to shut down two of its online gaming services.

… Meanwhile, Sony denied assertions by computer security expert Gene Spafford during a Congressional hearing Thursday that it had been running outdated versions of Web server software and had not been using a firewall on its servers. In a statement from Patrick Seybold, Sony's senior director, Corporate Communications and Social Media, that's expected to be published on Sony's PlayStation blog, the company was using updated software and had "multiple security measures in place."

… Separately, Sony President Kaz Hirai sent a letter to Connecticut senator Richard Blumenthal containing a detailed timeline of the attack and Sony's response to it. The letter contains previously undisclosed details about the attack and the hardware Sony uses to run its gaming services.

… Sony's letter to Sen. Blumenthal is here.

[From the letter:

The basic sequence of events is as follows:

On Tuesday, April 19, 2011, the Sony Network Entertainment America (SNEA) network team discovered that several PlayStation Network servers unexpectedly rebooted themselves and that unplanned and unusual activity was taking place on the network.

On the afternoon of April 20th, SNEA retained a recognized security and forensic consulting firm to mirror the servers to enable a forensic analysis.

On Thursday, April 21, SNEA retained a second recognized security and forensic consulting firm to assist in the investigation.

Among other things, the intruders deleted log files in order to hide the extent of their work and activity within the network

… on Sunday, April 24 (Easter Sunday) decided that it needed to retain a third forensic team with highly specialized skills to assist with the investigation. Specifically, this firm was retained to provide even more manpower for forensic analysis in all aspects of the suspected security breach and, in particular, to use their specialized skills to determine the scope of the data theft.

… Throughout the process, SNEA was very concerned that announcing incomplete, tentative or potentially misleading information to consumers could cause confusion and lead them to take unnecessary actions. SNEA felt that it was important - and that it was in keeping with the mandate of state law - that any information SNEA provided to customers be corroborated by meaningful evidence.

Indeed, many state statutes (e.g., AZ, CT, CO, DE, FL, ID, ME, MD, MS, NE, VT, WI, WY) essentially require disclosure without unreasonable delay once an investigation has been done to identify the nature and scope of what happened and who was affected.

In your letter you suggest that sending 500,000 emails an hour is not expeditious; however this limitation exists because these emails are not "batch" e-mails. The e-mails are individually tailored to our consumers' accounts.

… Unfortunately, our forensic teams still have not been able to rule out that credit card data was taken.

… You have questioned why SOE did not disclose this loss of data from its servers until May 2. The reason was because SOE did not discover that theft until May 1. The intruder carefully covered his or her tracks in the server systems. In fact, as noted above, the discovery was made only after SOE rechecked their machines -- which earlier showed no evidence of theft – using information developed by our forensic experts working in collaboration with our technical teams.

… ln addition to offering this identity theft protection, SNEA has announced a series of steps that it will take – most of which were in progress before this theft occurred – to enhance security before the service is restored. SOE has taken or will take similar steps. Those steps are:

  • additional automated software monitoring and configuration management to help defend against new attacks;

  • enhanced levels of data protection and encryption;

  • enhanced capabilities to detect software intrusions within the network, unauthorized access and unusual activity patterns;

  • implementation of additional firewalls;

  • expediting a planned move of the system to a new data center in a different location with enhanced security; and

  • . appointment of a new Chief Information Security Officer.



It's for your protection!

http://www.pogowasright.org/?p=22740

Domestic Intelligence Surveillance Grew in 2010

May 6, 2011 by Dissent

Steven Aftergood writes:

By every available measure, the level of domestic intelligence surveillance activity in 2010 increased from the year before, according to a new Justice Department report to Congress on the Foreign Intelligence Surveillance Act.

“During calendar year 2010, the Government made 1,579 applications to the Foreign Intelligence Surveillance Court (hereinafter ‘FISC’) for authority to conduct electronic surveillance and/or physical searches for foreign intelligence purposes,” according to the new report (pdf). This compares to a reported 1,376 applications in 2009. (In 2008, however, the reported figure — 2,082 — was quite a bit higher.)

Read more on FAS.

[From the report:

Of these 1,5 1 1 applications, five were withdrawn by the Government. The EISC did not deny any applications in whole, or in part.

… In 2010, the FBI made 24,287 NSL requests (excluding requests for subscriber infomation only) for information concerning United States persons. These sought information pertaining to 14,212 different United States persons.



This could be a handy way to call up all the pages I need to show my students at the start of each class!

http://www.freetech4teachers.com/2011/05/scrible-highlight-annotate-and-bookmark.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+freetech4teachers%2FcGEY+%28Free+Technology+for+Teachers%29

Friday, May 6, 2011

Scrible - Highlight, Annotate, and Bookmark Webpages

Scrible is a new service offering a nice set of tools for highlighting, annotating, and bookmarking webpages. Scribble offers browser bookmarklets for Firefox, Chrome, Safari, and Internet Explorer. With the Scrible bookmarklet installed, anytime you're on a page just click the bookmarklet to launch a menu of bookmarking tools. The Scrible tool set includes highlighters, sticky notes, and font change tools. When you annotate and bookmark a page in Scrible it is saved as it appeared to you when you were done altering it. And as you would expect from a web-based bookmarking tool, you can share your bookmarked pages with others.


Friday, May 06, 2011

For my Computer Security students, who seem amazed at how many laptop thefts have been reported since class started...

http://www.databreaches.net/?p=18148

CT: Police laptop stolen from cruiser parked at dealership

May 6, 2011 by admin

Elizabeth Dinan reports:

A police department laptop computer containing “a fair amount of records” was stolen from a marked cruiser and an on-board camera was damaged while the cruiser was left at an auto dealership for service, said Chief Jon Tretter.

The theft from and damage to the “brand new” cruiser occurred last week when it was parked overnight at Portsmouth Chevrolet where it was left for work on decorative trim, said Tretter. The police chief said he’s been advised that it’s unlikely anyone could access personal information stored on the stolen laptop because the battery is so old it barely functions without a companion power cord. [That's a new one. Bob]

Right. No one could possibly have a power cord.

Read more on Seacoastline.com


(Related)

http://www.symantec.com/business/resources/articles/article.jsp?aid=20110414_safeguard_stolen_laptops

Combine Encryption, Anti-Theft Technology to Safeguard Stolen Laptops

According to one study, some 2 million laptops are stolen each year.¹ And researchers at the Ponemon Institute estimate that 12,000 laptops are stolen at airports every week.²



Facts would seem to support rumor in this case.

http://news.cnet.com/8301-17852_3-20060335-71.html

Did Sony know its security was outdated?

When things go wrong in large institutions, one question that is often asked is: "What did they know and when did they know it?"

In the case of Sony--now confronted not only with two data breaches, but with the threat of a third, more destructive attack--that very question was posed this week in a House of Representatives subcommittee.

The answer given by Gene Spafford, a security expert and professor of computer science at Purdue University, raises troubling thoughts.

In written testimony to the House Subcommittee on Commerce, Manufacturing and Trade, Spafford highlighted recent data breaches at Sony and at Epsilon.

He wrote: "Both companies are large enough that they could have afforded to spend an appropriate amount on security and privacy protections of their data; I have no information about what protections they had in place, although some news reports indicate that Sony was running software that was badly out of date, and had been warned about that risk."

The Consumerist reported that in oral testimony on Wednesday to the subcommittee, Spafford amplified these comments.

He reportedly said Internet forums openly discussed that the Apache Web server software used by Sony was "unpatched and had no firewall installed." He also reportedly said that these concerns were debated in an open forum that was monitored by Sony employees. [and hackers everywhere. Bob]

… However, one more sentence in the response may offer a clue about Sony's previous priorities. The company is planning to create a brand-new position: chief information security officer.


(Related) This seems to be an escalation of coverage for Identity Theft victims. On the other hand, here's another company that has all your Personal Information (or they don't know what to look for...)

http://news.cnet.com/8301-31021_3-20060256-260.html

Sony CEO Stringer apologizes for PlayStation breach

Sony has made a deal with identity-protection firm Debix to offer a service called AllClear ID Plus for free to U.S. customers registered with PlayStation Network or Qriocity prior to the attack two weeks ago, Sony spokesman Patrick Seybold wrote in a blog post today.

… Stringer emphasized that the identity-theft monitoring program the company is offering customers has a "$1 million identity-theft insurance policy" included. Customers will be able to enroll in the program through an activation e-mail they'll receive "over the next few days." Registration will be open till June 18.

[From the blog:

The details of the program include, but are not limited to:

  • Cyber monitoring and surveillance of the Internet to detect exposure of an AllClear ID Plus customer’s personal information, including monitoring of criminal web sites and data recovered by law enforcement.

  • Priority access to licensed private investigators and identity restoration specialists.

  • A $1 million identity theft insurance policy per user to provide additional protection in the event that an AllClear ID Plus customer becomes a victim of identity theft.


(Related) Having all that Personal Information must be valuable, huh?

http://www.pogowasright.org/?p=22736

Nintendo revises privacy policy

May 6, 2011 by Dissent

Ben Parfitt reports:

As the industry continues to come to terms with the wider implications of the PSN breach, Nintendo has contacted Club Nintendo members about the introduction of a new privacy policy.

As part of it, the company asks permission to gather information from users. Users who don’t check or agree to the new policy will from May 31st be unable to spend any Stars in their personal Stars Catalogue and their membership will be cancelled.

Read more on MCV.

At first I thought I must have misunderstood – would Nintendo really cancel accounts if people declined to share their information? Seems like they will, though. As another site reports, here’s what the email to users said:

Please review our new Privacy Policy by logging into your Club Nintendo account. Once you have read the information displayed upon logging in, please use the appropriate buttons to either ACCEPT or DECLINE this new Privacy Policy.

Please note that if we haven’t received your answer by 31st May, 2011, or if you choose to DECLINE our new Privacy Policy, you will from that day onwards no longer be able to use your Stars in the Stars Catalogue, as we will be forced to deactivate your Club Nintendo membership. No matter what you decide, you can still use your Stars and enjoy all the other benefits of Club Nintendo membership until 31st May, 2011.

So Nintendo has seemingly implemented an “opt-in or f**k off, bugger!” privacy policy. We’ll see how that works out for them.



A new way to rat out your boss?

http://www.pogowasright.org/?p=22732

Don’t Leak to the Wall Street Journal’s New Wikileaks Knockoff

May 6, 2011 by Dissent

With some fanfare, the Wall Street Journal launched a new whistleblower site, SafeHouse. It didn’t take long for Jake Appelbaum to find the holes in it and if you were on Twitter yesterday, you could see a steady stream of tweets from @ioerror (Appelbaum), pointing out concerns. Adrian Chen writes:

The Wall Street Journal is trying to make a play for whistleblowers with its very own Wikileaks clone, SafeHouse. But SafeHouse is the opposite of safe, thanks to basic security flaws and fine print that lets the Journal rat on leakers.

SafeHouse, which launched today to much fanfare, promises to let leakers “securely share information with the Wall Street Journal,” by uploading documents directly to its servers, just like Wikileaks! But unlike Wikileaks, SafeHouse includes a doozy of a caveat in its Terms of Use:

Read more on Gawker.



We have the tools for ubiquitous surveillance.

http://www.bespacific.com/mt/archives/027192.html

May 05, 2011

The Deciders: Facebook, Google, and the Future of Privacy and Free Speech

The Deciders: Facebook, Google, and the Future of Privacy and Free Speech, Jeffrey Rosen

  • "Open Planet [24/7 ubiquitous surveillance system] is not a technological fantasy. Most of the architecture for implementing it already exists, and it would be a simple enough task for Facebook or Google, if the companies chose, to get the system up and running: face recognition is already plausible, storage is increasing exponentially; and the only limitation is the coverage and scope of the existing cameras, which are growing by the day. Indeed, at a legal Futures Conference at Stanford in 2007, Andrew McLaughlin, then the head of public policy at Google, said he expected Google to get requests to put linked surveillance networks live and online within the decade. How, he, asked the audience of scholars and technologists, should Google respond?"



Will it be possible for citizens to decide to stop using the cards? How would any government react to a “Privacy Spring?”

http://www.pogowasright.org/?p=22734

Cn: Party magazine touts new blanket ID card

May 6, 2011 by Dissent

Zhang Han reports:

China is working on creating a more comprehensive national identity card and database for mainland citizens to improve the efficiency of maintaining social order, a Communist Party-run magazine has reported.

It was time for systematic “perfection of citizen identification registration and management,” wrote Zhou Yongkang, a member of the Standing Committee of the Political Bureau of the Central Committee of the Communist Party of China (CPC) in the latest issue of Qiushi, a biweekly official journal of the CPC Central Committee.

[...]

It had become urgent to establish a system to identify a citizen solely by a single identity card, Zhou argued, including information such as social security, family planning status, housing status, education, taxation, commercial and other financial information.

Related departments should deploy the identification card system to establish a national database, “to better manage and serve the country’s citizens,” Zhou wrote.

Read more on Global Times.



An interesting legal question. Perhaps there are limits to Copyright?

http://www.wired.com/threatlevel/2011/05/firefox-add-on-redirect/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

Feds Demand Firefox Remove Add-On That Redirects Seized Domains

The Department of Homeland Security has requested that Mozilla, the maker of the Firefox browser, remove an add-on that allows web surfers to access websites whose domain names were seized by the government for copyright infringement, Mozilla’s lawyer said Thursday.

But Mozilla did not remove the MafiaaFire add-on, and instead has demanded the government explain why it should. Two weeks have passed, and the government has not responded to Mozilla’s questions, including whether the government considers the add-on unlawful and whether Mozilla is “legally obligated” to remove it. The DHS has also not provided the organization with a court order requiring its removal, the lawyer said.

… The add-on in question redirects traffic from seized domains to other domains outside the United States’ reach. Since last year, the U.S. government has seized at least 120 domains in an antipiracy assault known as “Operation in Our Sites.” The domains are taken under the same federal statute used to seize drug houses.



For my Computer Forensics students... Worthy of a careful read...

http://news.cnet.com/8301-31921_3-20060321-281.html

Bin Laden's computers will test U.S. forensics

For the U.S. government, the raid on Osama bin Laden's compound in Pakistan represents a unique opportunity to test advanced computer forensics techniques called "media exploitation" that it's developed over the last few years.

The military's acronym for the process is DOMEX, which one Army team in Iraq cheekily sums up with this motto: "You check their pulse, we'll check their pockets."

The electronic gear hauled away by an assault team of Navy SEALs reportedly included five computers, 10 hard drives, and scores of removable media including USB sticks and DVDs. Some reports say the forensic analysis is taking place at the CIA's headquarters in Langley, Va., while others have placed it at a "secret location in Afghanistan." (See list of related CNET stories.)

While the U.S. government isn't exactly volunteering what's happening now, the Army has confirmed in the past that it provides "tactical DOMEX teams" to troops in Afghanistan. And a Defense Department directive (PDF) from January 2011 says the National Media Exploitation Center, or NMEC, will be the "central DoD clearinghouse for processing DoD-collected documents and media," a category that would include the bin Laden files.

… The NMEC support job, which requires a Top Secret security clearance, calls for "complete training in EnCase Forensic Software up through the EnCase Advanced training course or equivalent." A bachelor's degree in computer engineering is preferred. So is proficiency in "creating databases in MS Access and SQL."

[Wikipedia entry:

https://secure.wikimedia.org/wikipedia/en/wiki/Document_Exploitation_%28DOCEX%29



Is you innocent or is you ain't?

http://www.bespacific.com/mt/archives/027194.html

May 05, 2011

New on LLRX.com - The Age of Innocence: Actual, Legal and Presumed

Via LLRX.com - The Age of Innocence: Actual, Legal and Presumed: Ken Strutin reasons that any accounting of the justice system would put the presumption of innocence at the top of the ledger. The premise underlying this evidentiary rule is that no one should be found guilty of a crime unless the state has convinced a jury with proof beyond a reasonable doubt. The materials Ken has researched and documented for this guide focus on the drift from unitary innocence, which encompasses all possible claims to a wrongful conviction, to factual innocence rooted in exoneration jurisprudence. According to some scholars, factual exonerations may have confounded the wisdom behind the Blackstone Ratio and its overarching message, i.e., criminal law and procedure ought to be weighted in favor of innocence to avoid wrongful conviction, even if there is a chance that the guilty will benefit as well. In other words, a system of justice that is fair to all and seeks to protect the innocent from wrongful prosecutions must apply safeguards that will be over inclusive. The calculations of truth and fairness are rooted in a system of justice based on due process (or a presumption of due process). The scholarship collected here attempts to address questions of whether the concept of innocence is selective or categorical.



What is the purpose? If it's just raising money, then “per mile” is sufficient. If it is to “encourage us to 'go green' then an MPG factor and a 'rush hour' surcharge will be added. Of course, states (counties, cities, school districts, etc.) will want to pile on. Sounds like a real boondoggle...

http://politics.slashdot.org/story/11/05/05/1735244/Draft-Proposal-Would-Create-Agency-To-Tax-Cars-By-the-Mile?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Draft Proposal Would Create Agency To Tax Cars By the Mile

"The Hill reports that the Obama administration has floated a transportation authorization bill that would require the study and implementation of a plan to tax automobile drivers based on how many miles they drive. The plan is a part of the administration's 'Transportation Opportunities Act,' and calls for spending $200 million to implement a new Surface Transportation Revenue Alternatives Office tasked with creating a 'study framework that defines the functionality of a mileage-based user fee system and other systems.' The office would be required to consider four factors — the capability of states to enforce payment, the reliability of technology, administrative costs, and 'user acceptance' — in field trials slated to begin within four years at unspecified sites. Forbes suggests the so-called vehicle miles traveled (VMT) tax should be called the Rube Goldberg Gas Tax, because while its objective is the same as the gas tax, the way it collects revenue is extremely complex, costly and cumbersome."

The disclaimers are thick on the ground, though; note, this is an "early draft," not pending legislation.



For my Geeks... (and a problem for my Computer Security students)

http://mobile.slashdot.org/story/11/05/06/0253203/Canadian-Researchers-Create-Thin-Film-Flexible-Paperphone?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Canadian Researchers Create Thin-Film Flexible Paperphone

"Researchers from the Human Media Lab at Canada's Queen's University have created a fully-functioning floppy E-Ink smartphone, which they also refer to as a paper computer. Like its thicker, rigid-bodied counterparts, the Paperphone can do things like making and receiving calls, storing e-books, and playing music. Unlike them, however, it conforms to the shape of its user's pocket or purse, and can even be operated through bending actions."

[From the article:

When not actually being operated, the Paperphone consumes no electricity. Vertegaal's team have also created a similar device, the Snaplet, which can be worn like a wristband. It operates as a watch when in a convex state, becomes a PDA when flat, and can be used as a phone when turned concave.


(Related) Small (and cheap) is good! ...sometimes.

http://tech.slashdot.org/story/11/05/06/122233/A-25-PC-On-a-USB-Stick?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

A $25 PC On a USB Stick

"[Game developer David] Braben has developed a tiny USB stick PC that has an HDMI port on one end and a USB port on the other. You plug it into an HDMI socket and then connect a keyboard via the USB port, giving you a fully functioning machine running a version of Linux. The cost? $25. The hardware being offered is no slouch either. It uses a 700MHz ARM11 processor coupled with 128MB of RAM and runs OpenGL ES 2.0, allowing for decent graphics performance with 1080p output confirmed. … We can expect it to run a range of Linux distributions, but it looks like Ubuntu may be the distro it ships with. That means it will handle web browsing, run office applications, and give the user a fully functional computer to play with as soon as it's plugged in. All that and it can be carried in your pocket or on a key chain."



Perspective. Apparently, having immediate access to a global market is good for business...

http://www.wired.com/epicenter/2011/05/commentary-grouponomics/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

Commentary: Grouponomics of the Deal

18 months ago, Groupon didn’t exist. Today, it has over 70 million users in 500-odd markets, is making more than a billion dollars a year, has dozens if not hundreds of copycat rivals, and is said to be worth as much as $25 billion.

But first it’s worth looking at the innovation in the name of the company: the idea that coupons only become activated once a certain minimum number of people have signed up for them. This is essentially a guarantee for the merchant that the needle will be moved, that their effort won’t be wasted. With traditional advertising or even with old-fashioned coupons, a merchant never has any guarantee that they will be noticed or make any difference.

But with a Groupon, you know that hundreds of people will be so enticed by your offer that they’re willing to pay real money to access it. That kind of guaranteed engagement is hugely valuable, and more or less unprecedented in the world of marketing and advertising.


Thursday, May 05, 2011

Sony's letter to Congress:

http://www.flickr.com/photos/playstationblog/sets/72157626521862165/


(Related)

http://www.scmagazineuk.com/sony-blames-anonymous-for-playstation-hack-but-confirms-it-has-not-identified-those-responsible/article/202140/

Sony blames Anonymous for PlayStation hack but confirms it has not identified those responsible

In a letter to the US Congress, Kazuo Hirai, Sony Computer Entertainment chairman of the board of directors, claimed that Sony had been investigating the intrusion around the clock and what had become ‘more and more evident is that Sony has been the victim of a very carefully planned, very professional, highly sophisticated criminal cyber attack designed to steal personal and credit card information for illegal purposes'.

He went on to say that when data being stolen was discovered, a file was also found on the server that was named ‘Anonymous' with the words ‘we are Legion'.

… Sony went on to confirm that unauthorised activity was detected on the afternoon of Tuesday 19th April, with a discovery that data had been transferred off the servers without authorisation the next day, causing the shut down of the network. [So they “discovered” a problem but were unable to stop the theft of data? Bob] The FBI was notified on 22nd April and details were given to law enforcement on Wednesday 27th April.

… Robin Adams, director of security, fraud and risk management at The Logic Group, said: “I wonder if Sony are aware of the Payment Card Industry Data Security Standard (PCI DSS) since they are very effectively stating their non-compliance? The PCI DSS control 3.1 states that cardholder data must be kept to a minimum and that a data retention and deletion policy must be implemented, which involves a process for the secure deletion of cardholder data when it is no longer required. I would suggest outdated credit card databases fall fairly under this category.

“Not only that but the PCI DSS Prioritised Approach categorises the 220 plus controls into six risk levels and control 3.1 is one of only eight controls considered severe enough to be put in at risk level 1. In these litigious days one can only assume that the Sony lawyers and Marcom staff who proofread this statement had been missing during the security awareness training.”


(Related)

http://kotaku.com/?_escaped_fragment_=5798846/report-new-york-state-subpoenas-sony-over-breach#!5798846/report-new-york-state-subpoenas-sony-over-breach

Report: New York State Subpoenas Sony Over Breach


(Related) ..and interesting idea. Behavioral Advertisers do it, why not criminals?

http://www.computerweekly.com/Articles/2011/05/05/246587/Data-breaches-show-cyber-criminals-switching-tactics-says.htm

Data breaches show cyber criminals switching tactics, says SecurEnvoy

The massive data breaches at Sony and the US organisers of the X-Factor reality television show, indicate cyber criminals may be changing tactics, says security firm SecureEnvoy.

The hack of the Fox television network's database of competition entrants is the latest in a string of attacks on corporate servers to extract personal data, suggesting cybercriminals are now building information profiles on people, rather than developing frauds around available credentials, says Andy Kemshall, technical director of SecurEnvoy.

Attacks on Sony's PlayStation Network and Online Entertainment services and the Epsilon systems are the most high-profile reports of corporate servers being hacked, he says, but there have been many more less-reported intrusions, suggesting cybercriminals are now actively compiling data on large numbers of people for longer-term fraud.

… Andy Kemshall says it is easy to see a pattern emerging in these attacks. "Previously, frauds were card-centric and built around opportunistic database hacks, but the sheer volume of the system hacks in recent months suggests a longer-term strategy."

Security researchers are already reporting that names and unique identifiers such as social security/national insurance and address details, are being bought and sold on underground forums, along with dates-of-birth, e-mail addresses and other personal data.

"Our observations suggest this data is being compiled into one or more databases, meaning low-level frauds can be carried out on a steady basis, bursting into periods of high activity when the people's debit or credit card details become available," said Kemshall.


(Related)

http://www.bespacific.com/mt/archives/027180.html

May 04, 2011

Hearing on The Threat of Data Theft to American Consumers

Via CDT - The Threat of Data Theft to American Consumers: "Two high profile data (Sony's Playstation and Epsilon) breaches have grabbed headlines lately because of their recency, data breach is a major longstanding problem for consumers, businesses and government. According to Privacy Rights Clearinghouse, a staggering 600 million records have been breached due to the roughly 2,460 data breaches made public since 2005. According to a 2010 Ponemon benchmark study, the cost of data breaches to businesses – in terms of preventing, detecting, and notifying individuals of breach, as well as legal defense and lost business opportunities – have risen considerably over the past several years. Consumers whose personal information is lost or stolen in data breaches face increased risks of identity theft, spam and phishing attacks, reduced trust toward services on which they depend, and sometimes humiliating loss of privacy over sensitive medical conditions."



With so many passwords to remember, lots of us store our passwords online. That makes these systems a BIG target... Note that they are following at least a few Best Practices...

http://blog.lastpass.com/2011/05/lastpass-security-notification.html

LastPass Security Notification

We noticed an issue yesterday and wanted to alert you to it. As a precaution, we're also forcing you to change your master password.

We take a close look at our logs and try to explain every anomaly we see. [Yes! Bob] Tuesday morning we saw a network traffic anomaly for a few minutes from one of our non-critical machines. These happen occasionally, and we typically identify them as an employee or an automated script.

In this case, we couldn't find that root cause. After delving into the anomaly we found a similar but smaller matching traffic anomaly from one of our databases in the opposite direction (more traffic was sent from the database compared to what was received on the server). Because we can't account for this anomaly either, we're going to be paranoid and assume the worst: that the data we stored in the database was somehow accessed. We know roughly the amount of data transfered and that it's big enough to have transfered people's email addresses, the server salt and their salted password hashes from the database. We also know that the amount of data taken isn't remotely enough to have pulled many users encrypted data blobs.

… For those of you who are curious: we don't have very much data indicating what potentially happened and what attack vector could have been used and are continuing to investigate it. We had our asterisk phone server more open to UDP than it needed to be which was an issue our auditing found but we couldn't find any indications on the box itself of tampering, the database didn't show any changes escalating anyone to premium or administrators, and none of the log files give us much to go on.

We don't have a lot that indicates an issue occurred but it's prudent to assume where there's smoke there could be fire. We're rebuilding the boxes in question and have shut down and moved services from them in the meantime. The source code running the website and plugins has been verified against our source code repositories, and we have further determined from offline snapshots and cryptographic hashes in the repository that there was no tampering with the repository itself.



A warning of things to come? An opportunity for my Computer Security students? Clearly a victory of Marketing over Customer Service – “We'll sell it to you, but you're too ignorant to use it?”

http://yro.slashdot.org/story/11/05/04/2154227/Vendors-Say-Data-Protection-Software-Too-Complicated-To-Use?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Vendors Say Data Protection Software Too Complicated To Use

"With a series of major data breaches over the past few months, you'd think more and more companies would be investing in data protection software, which can help keep data secure even on systems that have been compromised. Unfortunately, even organizations that have paid good money for this software often don't use it, because, as one of the vendors admits, it's often too complicated to use."



For my Geeks. (Sony won't like this hack either.)

http://games.slashdot.org/story/11/05/05/0548246/Gitbrew-Releases-OtherOS-PS3-Linux-Dual-Boot?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29

Gitbrew Releases OtherOS++ PS3 Linux Dual Boot

"Gitbrew has proudly released otherOS++ Linux Dual Boot v1.0b1, enabling PS3 users to install an alternative OS to their console with full access to all system hardware, including all 8 CELL cores (making the PS3 the world's most affordable supercomputer). For more information check out the installation instructions and source code."



So, who made this call – the FBI or DOJ?

http://www.pogowasright.org/?p=22700

FBI Chastised by Court for Lying About Existence of Surveillance Records

May 4, 2011 by Dissent

Jennifer Lynch writes:

An order last week from the U.S. District Court for the Central District of California has revealed the FBI lied to the court about the existence of records requested under the Freedom of Information Act (FOIA), taking the position that FOIA allows it to withhold information from the court whenever it thinks this is in the interest of national security. Using the strongest possible language, the court disagreed: “The Government cannot, under any circumstance, affirmatively mislead the Court.” Islamic Shura Council of S. Cal. v. FBI (“Shura Council I”), No. 07-1088, 3 (C.D. Cal. April 27, 2011) (emphasis added).

Read more on EFF.



Trying to get a sense of scale...

http://techcrunch.com/2011/05/04/facebook-one-third-online-ads/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

comScore: Facebook Now Serves One Third Of Online Ads In U.S.

… In the first quarter of 2011, comScore estimates that 1.1 trillion ads were served to U.S. Internet users, and 346 billion of those (or 31 percent) were on Facebook.

… Facebook has the volume, but it is also beginning to experiment with new forms of ads which are themselves more social. These ads look more like News items shared by friends than typical display ads. Until those start kicking in, however, Facebook can just keep putting display ads on its ever-growing share of pages people look at on the Internet.



A tool for deeper research? All the news that doesn't fit?

http://www.makeuseof.com/tag/documentcloud-direct-access-documents-news/

DocumentCloud: Direct Access To The Documents Behind The News

Want to know what’s really going on? Read the documents behind the news. Journalists strive to summarize complex documents, but sometimes its nice to read source material in its entirety. Thanks to DocumentCloud, a web service partnered with various media organizations, now you can.

… DocumentCloud aims to give media organizations a place to submit their own news documents source material for the public to view it. It’s a supplement to what you get from the newspaper or television, not an alternative to it.

… DocumentCloud is unique in that it allows media organizations to partner with it. Current partners are listed here, and include a lot of big names in North American journalism.