Monday, December 12, 2011


According to Google, this is my 2,000th Blog entry.
Since I only post once a day, that also means I've been at this for 2,000 days (285.714286 weeks, 65.7098224 months, 5.47581853 years). I probably write about 10+ articles every day, so that means I've made 20,000 snarky little comments. To get those articles I probably scan about 200 articles a day via my RSS reader – that means I've read 400,000 articles.
None of this takes into account the years of emails before I started the Blog and the years of actual paper clippings before that.
I still have the dream that someday all of this will make sense...


My kind of Blog post!
Copyright and Your Face
December 11, 2011 by Dissent
A terrific post by Derek Bambauer on PrawfsBlawg begins:
The Federal Trade Commission recently held a workshop on facial recognition technology, such as Facebook’s much-hated system, and its privacy implications. The FTC has promised to come down hard on companies who abuse these capabilities, but privacy advocates are seeking even stronger protections. One proposal raised was to provide people with copyright in their faceprints or facial features. This idea has two demerits: it is unconstitutional, and it is insane. Otherwise, it seems fine.
Go read it. It’s the type of blawging that gives us non-lawyers a better grasp of what the law says and what the legal issues are without a ton of legal terminology.


Since this law is paid for and written by Netflix, the answer is “Gutting It!” Mostly... Of course, tape is no longer the medium...
Updating Video Privacy or Gutting It?
December 11, 2011 by Dissent
Danielle Citron writes:
The video rental business is among a few sectors of the U.S. economy with strong federal limits on the collection and sharing of consumer data. Under the Video Privacy Protection Act, which was passed in 1988, “video tape service providers” generally are not permitted to share a consumer’s video usage information without “the informed, written consent of the consumer given at the time the disclosure is sought.” VPPA also prohibits companies from retaining personal information beyond the period prompting its initial collection. Companies like Blockbuster ran afoul of VPPA by sharing its users’ rental information with social network contacts, without their consent, and by retaining personal information, including credit card numbers, of users who canceled their accounts. In September, Facebook began making it easier for millions of U.S. customers to effortlessly share, via a new timeline, more of their online activities, such as the music they’re enjoying and the articles they’re reading. Left off the timeline: the details of the movies they’re renting–due to VPPA’s requirement that consumers explicitly consent at the time of disclosure. Thus began Netflix’s renewed lobbying efforts to amend VPPA, so that Facebook users could automatically share their Netflix rental activity without requiring their rental-by-rental consent.
Those efforts have begun to pay off.
Read more on Concurring Opinions.


It's not tomorrow, its today. (Health and Politics seem to be the biggest areas of of interest.)
December 11, 2011
Brookings - Ten Facts about Mobile Broadband
Ten Facts about Mobile Broadband, Darrell M. West, Vice President and Director, Governance Studies - December 08, 2011. The Brookings Institution
  • "Mobile broadband is reshaping society, communications, and the global economy. With smart phone usage surpassing that of personal computers, there has been a sea change in the way consumers access and share information. Powerful mobile devices and sophisticated digital applications enable users to build businesses, access financial and health care records, conduct research, and complete transactions anywhere. This revolution in how consumers and businesses access information represents a fundamental turning point in human history. For the first time, people are able to reach the Internet in a relatively inexpensive and convenient manner. Regardless of geographic location, they can use mobile broadband for communications, education, health care, public safety, disaster preparedness, and economic development. In this report, I review ten facts about mobile broadband. I show how the mobile economy is reshaping the global landscape. Both in developed and emerging markets, there are major opportunities to create jobs, and create social and economic connections. With the mobile industry generating $1.3 trillion in revenues, it is important to understand how telephony is affecting the way people relate to one another."

(Related) How can Doctors get the best technology in the shortest time?
iPad: ‘Wild West’ of Medical Apps Seeks Sheriff
Mark Cain got his big break on June 9, 2008. The chief technology officer at a little-known medical software company, MIM Software, Cain was invited onstage at Apple’s Worldwide Developer Conference to promote his company’s iPhone app, a way for doctors to view incredibly detailed scans of their patients.
It was a cool demo of what the iPhone’s great graphics and touchscreen interface could really do. With hordes of international press looking on, Cain moved through a three-dimensional iamge of a human body, toggling between a CT scan and a PET scan.
… But the fun was short lived. Two months after the demo, the U.S. Food and Drug Administration told MIM Software to remove their app from Apple’s store, saying it needed to be cleared for medical use. That process took more than two years. And it cost about $150,000.
But that’s not what bugs Cain. What bothers him is that there are so many other medical imaging apps out there — many of them similar to Mobile MIM — that are being bought and sold without FDA supervision.


It's just a matter of when. (Don't judge the article by the picture. Students are not that ignorant.)
"Students and teachers in grade school through higher education are using the iPad to augment their lessons or to replace textbooks. Jennifer Kohn's third grade class at Millstone Elementary School in Millstone, New Jersey, mastered the iPad with minimal training. For the most part, the students didn't need to be taught how to use their apps, Kohn says. College students are also turning to the iPad to do what they do instinctively well: saving themselves money. Marianne Petit, a New York University staff member, recently began taking credits in pursuit of another certification, and uses her iPad in place of textbooks. 'The price of the iPad pays for itself after a single semester,' Petit said. 'iPad books cost so much less it's a legal alternative for students who are using BitTorent [to pirate books].' Like the PC before it, Kohn noted that the iPad isn't a panacea for educators: It has its appropriate time and place. 'I don't use them with every lesson or even day. It's not always appropriate to lesson or objective of what I'm trying to teach,' Kohn noted."


Something to make my students think! (Sorry for using the “T” word )
December 11, 2011
NYT Timeline Predicting the Future of Computing
Predicting the Future of Computing: "Since no supercomputer can yet predict the future, we need your help. Readers are invited to make predictions and collaboratively edit this timeline, which is divided into three sections: a sampling of past advances, future predictions that you can push forward or backward in time (but not, of course, into the past), and a form for making and voting on predictions. The most prescient prophet might receive an iPad 2 in 2050. But if the past is any guide, this prediction will almost surely be wrong."
  • See also Everyone Speaks Text Message: "For the vast majority of the world, the cellphone, not the Internet, is the coolest available technology. And they are using those phones to text rather than to talk. Though most of the world’s languages have no written form, people are beginning to transliterate their mother tongues into the alphabet of a national language. Now they can text in the language they grew up speaking."


This reminds me of a certain law professor I know...
He Has A (Power)Point


Lots of cool geeky stuff!
… That metaphor also extended to the administration’s proposal for a new education technology agency: ARPA-ED. $90 million was earmarked in the President’s 2012 budget for the new agency, which according to the Department of Education, would fund both private and public research by industry, universities, and other organizations to work on projects such as personalized digital tutors, adaptive learning platforms, and game-based learning (PDF).
… STEM skills are likely to permeate all jobs — we don’t simply need more scientists and engineers; we all need to become technologists. (See Georgetown University’s Center on Education and the Workforce for detailed statistics on jobs, education, and earnings released this year.)
… MIT’s Scratch continued to be a popular choice for introducing young students to programming and computational thinking. Scratch hit a major milestone this year too, with over 2 million Scratch projects uploaded to its community site. Scratch was the inspiration behind Stencyl, a game creation studio for Flash games, that launched this year. Microsoft also released its own game-building tool Kodu to help kids learn to build XBox games, holding its first annual Kodu Cup competition (You can read my interview with the winner, 10-year-old Hannah Wyman here). And while Google’s Android App Inventor gave me a bit of a scare this year when it appeared as though the project was getting the ax with the closure of Google Labs, Google ended up donating App Inventor — the code and the project — to MIT, along with some cash to seed a new Center for Mobile Learning.
2011 wasn’t just a good year for getting kids exposed to software development. There were several exciting new hardware projects too that were aimed at young engineers: Raspberry Pi — a $25 ARM/GNU Linux box. littleBits — snap-together circuit boards. Arduino — open source hardware and software. All of these are meant to provide an affordable and accessible way to learn.
… A number of education/technology startups launched in 2011 aiming to help anyone learn to program: Treehouse, Codecademy, Code Academy, and General Assembly, to name a few.


For my Geeks...
DOWNLOAD Think Different: How To Build Your Own Hackintosh


For my students and my fellow teachers...
Sunday, December 11, 2011
Bookboon is a free service offering free full-length textbooks, travel guides, and business books in digital form. The textbook section of Bookboon offers more than 500 digital textbooks. On Bookboon there are etextbooks available for twenty-five subjects, but the bulk of the etextbooks are focused on Economics, Engineering, and IT. You can browse the title lists to find a book you want or you can search Bookboon by keyword. Bookboon hosts books written in five languages. All of the books are free to download. The only catch is that you have to provide an email address before you can download the books.
Bookboon's books are targeted to university students, but that doesn't mean that some of the books couldn't be used with high school students. And since the books are free it wouldn't hurt to download one that you think might work for your class and use excerpts of it to supplement other materials that you are already using in your classroom.

Sunday, December 11, 2011


A simple illustration. Many organizations are not able to go back to manual processes. e.g. could any company calculate a payroll without the computers?
"The Atlanta Journal Constitution newspaper is reporting that a hospital with campuses in Lawrenceville and Duluth, Georgia turned ambulances away after the discovery of 'a system-wide computer virus that slowed patient registration and other operations.' They're only currently accepting patients with 'dire emergencies.' A spokeswoman for the hospital said the diversion happened because 'it's a trauma center and needs to be able to respond rapidly.' The situation began on Thursday afternoon and is expected to last through the weekend."
[From the article:
Patients were waiting longer at registration on Friday, and the virus also was affecting departments such as the pharmacy, radiology and labs. A system of runners are dealing with a variety of tasks, such as running orders down to the pharmacy or delivering X-rays to doctors


Something to watch. If employees use their computers as they use the phones on their desks (for personal reasons) have they committed a crime?
When Computer Misuse Becomes a Crime
December 10, 2011 by Dissent
Ginny LaRoe has a helpful article on the upcoming rehearing en banc of United States v. Nosal , a Ninth Circuit Court of Appeals case that asks whether violating an employer’s computer use policy is a violation of the Computer Fraud and Abuse Act, a law that started life as an anti-hacking statute.
A few years ago, Bay Area federal prosecutors took up a white-collar case that wasn’t particularly sexy, indicting a handful of employees of an executive recruiting firm who had tapped an internal database to get information to start a competing business. The U.S. attorney’s office quickly cut deals with two of the lower-level employees before indicting its main target, David Nosal, an executive at Korn/Ferry International, charging him and a woman named Becky Christian with a slew of crimes, including trade secret theft.
And they invoked the Computer Fraud and Abuse Act, the 1980s anti-hacking statute.
What started as a routine prosecution stemming from an employment dispute has turned into a heated battle — with national implications — over civil liberties in the digital age. At oral argument on Thursday, an en banc panel of the Ninth Circuit U.S. Court of Appeals will sort out whether the CFAA allows for the federal prosecution of employees who so much as check a ballgame score on a work computer or fib on Facebook in violation of a terms of use agreement.
Read more on Law.com. Nosal’s petition for rehearing en banc can be found here.


Probably not, but interesting to speculate who had the tech skills and why they might want to create a tool like this...
"Despite the U.S. and Israel being widely assumed to be responsible for Stuxnet, Russia is the more likely culprit, says U.S. Air Force cyber analyst. The nuclear gangsterism of the past 20 years gives it plenty of motive. Quoting: 'So what better way to maintain Russian interests, and innocence, than to plant a worm with digital U.S.-Israeli fingerprints? After all, Russian scientists and engineers are familiar with the cascading centrifuges whose numbers and configuration – and Siemen’s SCADA PLC controller schematics – they have full access to by virtue of designing the plants. ... the observers of the virus could alert the Iranians before full nuclear catastrophe struck. The Belarusian computer security experts who 'discovered' the code seemingly played that role well. They didn't seem too preoccupied with reverse engineering the malicious code to see what it was designed to do.'"


When you are on a jury, you can't use social networks for any reason? Is that realistic? I can see a problem with using your smartphone while evidence/arguments are going on, but before or after it should be okay to complain about the coffee...
"The Arkansas Supreme Court had overturned a murder conviction due to a juror tweeting during the trial. Erickson Dimas-Martinez was convicted in 2010 of killing a teenager and was sentenced to death. His lawyers appealed the case on account of a juror tweeting his musings during the trial and because another juror nodded off during the presentation of evidence. Tweets sent include 'The coffee here sucks' and 'Court. Day 5. here we go again.' In an opinion, Associate Justice Donald Corbin wrote 'because of the very nature of Twitter as an... online social media site, Juror 2's tweets about the trial were very much public discussions.' Dimas-Martinez is to be given a new trial."


(Completely unrelated) Is this unexpected given the differing cultures of the users of these technologies?
December 09, 2011
Pew - Twitter and the Campaign
  • "A detailed examination of more than 20 million Tweets about the race for president finds that the political discussion on Twitter is measurably different than the one found in the blogosphere — more voluminous, more fluid and even less neutral. But both forms of social media differ markedly from the political narrative that Americans receive from news coverage, according to a new study by the Pew Research Center’s Project for Excellence in Journalism, which examines campaign coverage and the online conversation from May 2-November 27. One distinguishing factor about the campaign discourse on Twitter is that it is more intensely opinionated, and less neutral, than in both blogs and news. Tweets contain a smaller percentage of statements about candidates that are simply factual in nature without reflecting positively or negatively on a candidate. In general, that means the discourse on Twitter about the candidates has also been more negative."


For my Ethical Hackers
"Can you play an MP3 file? Then you can jailbreak the new Kindle Touch. A new hack was posted this morning that roots the Kindle Touch/K5 and opens the way for future hacks. The hacker also reveals that the K5 runs on HTML5, which should make it a lot easier to come up with new apps. Epub, anyone?"


For my Math students...
Desmos Calculator is a free to use web tool that comes as an app for Google Chrome. The tool’s interface is completely online and loads up once you click on the app’s icon in Chrome. You can choose to plot normal graphs or polar graphs by typing in the equation of your fun ctions. You can also plot sample plots on the graph. You can plot multiple equations on a single graph and choose custom colors for each. Your graphs can be exported to PNG files for sharing.


Yes, it's trivial and useless... What's your point?
Get Your PC Into The Snowy Christmas Spirit With DesktopSnowOK
DesktopSnowOK is an incredibly lightweight, portable, no-installation-required piece of software that can turn your Windows desktop or laptop from summer in Florida to winter in Colorado in just a second.


Geeky stuff
Live USB Install Puts Linux On Your Thumb Drive With Ease
Boot one of over a hundred Linux distros from a USB disk. With Live USB, software you can run on both Windows and Linux computers, it only takes a couple of clicks to make your USB disk a bootable Linux disk. The live CD just might be the most useful tool in any geek’s arsenal – we’ve pointed out 50 uses for live CDs in the past and plan on showing you many more. As time goes on, however, CD drives become less common. That’s why booting from a USB drive is useful: it works on notebooks and other devices without optical drives.
Linux Live USB Creator, a similar program, can help create live USB drives, but it only works on Windows.
… Ready to try this out? If so, head over to the Live USB download page. You’ll find a DEB package there for Ubuntu and source code for other Linux distributions. You’ll also find the Windows download.


Gary Alexander sends something for my Computer Security troops...
January is Data Privacy Month: Free Webinars and Easy Ways to Increase Awareness
During the month of January, EDUCAUSE is expanding on Data Privacy Day to provide an entire month’s worth of activities and resources to help raise data privacy awareness. You can participate by attending the upcoming webinars and creating a plan to increase awareness on your campus with the easy-to-implement suggestions listed below. You can also visit the EDUCAUSE Data Privacy Month page for additional resources and information.

Saturday, December 10, 2011


This is unlikely to stop another “Arab Spring,” iPhones are too easy to use.
"Hot on the heels of recently passed legislation further restricting Freedom of Assembly, the National Front-led Malaysian Government is now working to make the registration of all tech workers mandatory, making it an offence punishable by a stiff fine and jail for anyone to plan, deploy, service and maintain any computing system without a license. A leaked draft of the legislation has ignited a backlash among the IT community, which fear the law, when passed, will be devastating to the tech industry in Malaysia."


So bring in the headsman and do it all at once!
"The Transportation Security Administration is getting a lot of negative attention, much of it from the U.S. government itself. A recent congressional report blasted the TSA for being incompetent and ineffective (PDF). A bill to force the TSA to reduce its screening of active duty U.S. military members and their families was approved unanimously by the House of Representatives. After a TSA employee was arrested for sexually assaulting a woman while in uniform, a bill has been introduced to prevent TSA agents from wearing police-style uniforms and badges or using the title 'officer.' The bill's sponsor calls these practices 'an insult to real cops.' The FBI is getting involved by changing its definition of rape [Rape is a federal crime? Bob] in a way that might expose the TSA's 'enhanced pat-down' screeners to prosecution. Lastly, public support for the TSA's use of X-ray body scanners drops dramatically when people realize there is a cancer risk."


Simple answer. RIAA runs the anti-piracy division of the Justice Department and they don't need no stinking constitution!
Senator Wants Answers from DHS Over Domain Name Seizures
Sen. Ron Wyden (D-Oregon) said Friday he would demand answers from the Department of Homeland Security about its domain seizure program known as Operation in Our Sites after it was revealed that the government kept a hip-hop music review site’s name for a year without affording the owner a chance to challenge the seizure.
Wyden also wants to know why there was no court record of the case, other than the initial seizure filing a year ago.


Cue the theme from Mission Impossible...
6 Holiday Gifts That Are Perfect For The Amateur Spy


Hey! Look what 'whats-his-name' is proposing! Project for my Ethical Hackers: De-anonymize his medical record (if it is on the database)
By Dissent, December 9, 2011
Earlier this week the Government announced proposals (40-page / 2.1MB PDF) to change the NHS Constitution so that information stored about patients would be automatically shared with life sciences researchers via a new anonymised database unless patients elect for their details not to be included.
While welcomed by the life sciences industry as a boost to research, the proposals raised concerns about the use of patient data.
[...]
“Let me be clear, this does not threaten privacy, it doesn’t mean anyone can look at your health records, but it does mean using anonymous data to make new medical breakthroughs,” Cameron said in a speech detailing the Government’s plans, according to a report by the BBC.
Mr. Cameron may firmly believe that, but studies on re-identifying supposedly “anonymized” data make it clear that data are often not as “anonymized” as one might think or home when the data are combined with other data often readily available in public databases.
The article also quotes Paul Ohm, who has been instrumental of increasing awareness about the risks of relying on “anonymization:”
Academic Paul Ohm, Associate Professor at University of Colorado Law School, told Out-Law.com in 2009 that research had shown that it is possible to use anonymised data to identify individuals. He said at the time that misplaced trust in anonymisation had been enshrined in privacy legislation.
“Virtually every privacy law allows you to escape the strictures and requirements of the privacy law completely once you’ve anonymised your data,” he said. “Every policy maker who has ever encountered a privacy law, and that’s in every country on earth, will need to re-examine the core assumptions they made when they wrote that law.”
Ohm said at the time that, in some fields of research such as health, it would be possible to open up much more data than is currently permitted as long as access to the information was controlled.
“We can’t trust technology any more but at the same time we don’t want to keep this information from researchers. So my solution is that we shift our trust from the technology to the people,” he said. “We write down the rules of trust among health researchers … [we say] you can get my data but only on a need to know basis,” he said.
Read more on Out-Law.com
Part of determining trustworthiness of a research clearly needs to be assessing their security and privacy protections, as the researcher may be professionally trustworthy, but if they outsource their database security to another party, well….


Interesting article...
The Future of Context: Mobile Reading from Google to Flipboard to FLUD
Reading is changing. And arguably, even more than e-readers, tablets, or “readers’ tablets,” smartphones are changing it.


Gee, I got them all right. Perhaps the school board member was a math-phobic?
New submitter newslash.formatb points to this Washington Post blog post, which
"discusses the National Assessment of Educational Progress test (specifically, the math part). One of the school board members took it and was unable to answer any of the 60 math questions, though he guessed correctly on 10 of them. He then goes on to claim that the math isn't relevant to many people. P.S. — if you want to feel like Einstein, check out some sample questions."
Maybe this is mostly about the kind of life skills that are sufficient to succeed in management.


Tools & Techniques
Quick Screen Share is a simple yet effective online web service that helps you instantly share screen activity with friends without having to download any software or extra add-ons. To get started, visit the site and check the “Your Screen” or “Their Screen” option; then enter your name to start the process. Note that you must have Java to make use of this service.
Once this is done, you will be given a URL you can send to the person who’d like to share the screen with you.


Anyone know where I can get a used Steinway? Yes, Mr. Bach, there's an app for that.
Etude is a must-have iPad application for all those users who want to learn piano using different digital tools.
Once installed, all you have to do is find the song which you want to learn and it will show you all the keys which you should press at each moment.
In case of pros, they can carry all their collections in one device rather than carrying piles of papers and books.


Gosh, I feel smarter already!
2 Ways To Easily Download TED Videos To Your Desktop


So they're not growling at me?
'Vocal Fry' Creeping Into U.S. Speech
A curious vocal pattern has crept into the speech of young adult women who speak American English: low, creaky vibrations, also called vocal fry. Pop singers, such as Britney Spears, slip vocal fry into their music as a way to reach low notes and add style. Now, a new study of young women in New York state shows that the same guttural vibration—once considered a speech disorder—has become a language fad.
Vocal fry, or glottalization, is a low, staccato vibration during speech, produced by a slow fluttering of the vocal chords (listen here).

Friday, December 09, 2011


So you took “naked or partially dressed” pictures of an under-aged female, and you're upset with her?
Lower Merion Laptop Lawsuit Redux: Robbins Family Sues School District Again
December 8, 2011 by Dissent
Thomas J. Walsh reports:
Charging that she was remotely monitored while naked or partially dressed, another webcam lawsuit has been filed against the Lower Merion School District—this time by Paige Robbins, 18, the sister of Harriton High School student Blake Robbins, who sued the district two years ago for invasion of privacy and other charges, eventually accepting a $175,000 settlement.
The Lower Merion School District (LMSD) fired back immediately Thursday, saying it appeared Paige Robbins purposefully waited until she turned 18 to file the suit as an adult, to win a separate payday of her own.
Read more on Patch.com


Not intended to be public, still what kind of “internal website” would this have been ? Customer service? Why would it even be possible to make this database accessible outside the company?
Telstra internal website made public, releasing account details of up to one million customers
December 9, 2011 by admin
Michelle Ainsworth reports:
Account details of up to one million Telstra customers have possibly been breached after an internal website was made public. The website listed Telstra customers on bundle plans and included their names, plan types, contact they had had with Telstra customer service and in some instances their account passwords, the Herald Sun reported.
It was found by a Telstra customer who had googled looking for a customer service phone number.
Read more on The Herald Sun.
Asher Moses and Ben Grubb of The Age provide additional details, including customer reactions:
Another customer and freelance writer, Emily Eklund of Rozelle in NSW, said she was “frustrated” that her username, password, credit check history and extensive correspondence with a Telstra staff member was available when she checked if her information was accessible on the Telstra site at 4.30pm AEDST today.
“My concern was that [anyone who knew about the site] had access to my email with a password,” she said. “They could have accessed any of my personal emails which could include details to other important information of mine.


Hacking US POS terminals from the comfort of your vacation home in beautiful Romania.
http://www.databreaches.net/?p=22065
Four Romanian nationals indicted for hacking Subway and 50 other merchants’ POS systems
December 8, 2011 by admin
The U.S. Dept. of Justice has issued a press release about an indictment that may relate to some breaches involving Subway Restaurant previously reported on this blog. The case was filed May 4, but the indictment has just been unsealed.
Four Romanian nationals have been charged in federal court for their alleged participation in an international multimillion dollar scheme to remotely hack into and steal payment card data from hundreds of U.S. merchants’ point of sale (POS) computer systems.
Adrian-Tiberiu Oprea, 27, of Constanta, Romania; Iulian Dolan, 27, of Craiova, Romania; Cezar Iulian Butu, 26, of Ploiesti, Romania; and Florin Radu, 23, of Rimnicu Vilcea, Romania, were charged in a four-count indictment filed in the District of New Hampshire with conspiracy to commit computer fraud, wire fraud and access device fraud. Oprea was arrested last week in Romania and is currently in custody there. Dolan and Butu were arrested upon their entry into the United States on Aug. 13 and Aug. 14, 2011, respectively, and remain in United States custody. Radu remains at large.
According to the indictment, from approximately 2008 until May 2011, Oprea, Dolan, Butu and Radu conspired to remotely hack into more than 200 U.S.-based merchants’ POS systems in order to steal customers’ credit, debit and gift card numbers and associated data. The indictment alleges that as part of the conspiracy, the members remotely scanned the internet to identify vulnerable POS systems with certain remote desktop software applications (RDAs) installed on them, and using these RDAs, the conspirators logged onto the targeted POS systems over the internet, either by guessing the passwords or using password-cracking software programs. The failure of a number of installers and users to change the default login credentials on such RDAs has been a factor in other cases reported on this blog in the past and Visa has repeatedly advised merchants to disable RDAs unless absolutely necessary. In this case, the members also allegedly installed keyloggers and a backdoor to allow them further access to the systems over time. Prosecutors allege that the conspirators repeatedly “downloaded a hacker tool that is designed to evade detection, “xp.exe,” from the “kitsite.info” “dump site” onto victims’ POS terminals.” Data were stored on domestic and non-U.S. servers including ftp.shopings.info, ftp.justfuckit.info, ftp.cindarella.info, ftp.kitsite.info, ftp.tushtime.info, ftp.canadasite.info, and sendspace.com. The dump sites also included compromised internet-connected computers belonging to unsuspecting small business owners or individuals, including a computer server owned by a small business in Pennsylvania. Many of the dump sites were registered with GoDaddy.com.
Merchant victims include more than 150 Subway restaurant franchises (which is less than 1 percent of all Subway restaurants), located throughout the United States, including in the District of New Hampshire, as well as more than 50 other identified retailers. According to the indictment, members of the conspiracy have compromised the credit card data of more than 80,000 customers, and millions of dollars of unauthorized purchases have been made using the compromised data. The other merchants were not named in the indictment.
If convicted, the defendants face a maximum of five years in prison for each count of conspiracy to commit computer related fraud, 30 years in prison for each count of conspiracy to commit wire fraud and five years in prison for each count of conspiracy to commit access device fraud. They also face fines up to twice the amount of the fraud loss and restitution.
Although it didn’t garner much media coverage, this blog had reported incidents involving card fraud at Subway locations in California and New York in 2009 and May 2010. Without knowing the identities of the other merchants, it’s unclear whether we knew about any of their breaches at the time or whether they ever notified affected customers.


Sure, why not? Some of my “financially challenged' students “Shop” for USBs in the school's lost & found. Also, If I “conduct security research” by examining a few dozen USB drives, I'll have plenty of 'stocking stuffers.'
AU: Railcorp blunder as personal details offered in rail sale
December 9, 2011 by admin
Finders, keepers? Can you just auction off lost USB drives left on trains without regard to whether they contain sensitive information? Maureen Shelley reports:
A bunch of USB memory sticks, which hold private photos and data, left by passengers on Sydney trains were sold by Railcorp at a lost property auction.
Computer security company Sophos, which bought the sticks, said they contained thousands of photographs, work projects, minutes of meetings and university assignments as well as a job application and resum aac (sic).
NSW Information and Privacy deputy commissioner John McAteer said that his office was investigating a possible breach of the Privacy Act by RailCorp and whether it had kept passengers’ private data safeguarded.
Read more on The Daily Telegraph.


At least when the Godfather said, “It's business, Sonny, it's not personal,” you knew the target wasn't civilians...
All she wants for Christmas is for us – and Congress – to ignore human rights
December 8, 2011 by Dissent
Tatiana Lewis, World Program Director of Intelligence Support Systems in Virginia, wrote a letter to the editors of the Wall Street Journal that is so simultaneously ludicrous and pathetic that I don’t know whether to spit, laugh, or suggest she take a course on human rights. Here’s her letter, and I’ll meet you on the other side:
The article “Document Trove Exposes Surveillance Methods” (page one, Nov. 19) will have a negative effect on job creation in the U.S. as attention of this kind makes U.S. manufacturers gun shy about developing, and eventually exporting, anything that can remotely be used to support government surveillance.
Based on our work with customers from around the globe, we expect that most countries outside the U.S. and Western Europe will begin to place intercept mandates on social networks, [“begin to?” Bob] especially following the Arab Spring. This would give U.S. companies an opportunity to develop such tools and thus create jobs.
We are concerned that the article and others like it contribute to an atmosphere where Congress isn’t likely to pass an updated lawful-interception law. The law would require social-networking companies to deploy special features to support law enforcement. Without the update, the opportunity for U.S. companies to develop and launch intercept products domestically for eventual export will be greatly curtailed.
Additionally, in some countries U.S. companies are already refusing to provide intercept support and are banned from doing business. But Chinese equivalents, with lawful-intercept features, crop up in their absence. [Lawful under whose laws? Bob] Like it or not, many countries will adopt the Chinese model, leaving U.S. companies and job growth behind.
So, to be clear, Ms. Lucas is arguing that we should throw human rights out the window to enable American businesses to make huge profits by supporting unconscionable surveillance of human rights activists. We should not put pressure on American businesses to behave ethically because, well hey, there’s big money to be made, and if American businesses don’t make it, Chinese businesses will. If people are going to be surveyed, tortured, and imprisoned anyway, we should just lie back and allow American businesses to make a profit off it.
Think again, Ms. Lucas.
And then again.
You seem to have an ethical screw that’s seriously loose.

(Related) My God, she's right! We'll have to move the business to China!
"The European Union is asking companies that sell surveillance and law enforcement tech to repressive regimes to stop doing so. The EU is not taking concrete action yet, but has warned that sanctions may be applicable. All this comes little more than a week after Wikileaks published the Spy Files, a name-and-shame list of the companies offering tools for mass surveillance and interception to despotic regimes, but also to Western governments."


Now this is smart! Proof you copied the game (often all a hacker wants is bragging rights) Still it shows off the game, perhaps enticing a purchase?
The developer of Serious Sam 3 came up with some creative DRM.
Pirates can play but not for long, as they are up against an invincible scorpion.
No mercy, let them bleed to death.


This is not really new. Microsoft has been pushing software “updates” to your computer for years.
"The terms of service for Microsoft's newly launched Windows Store allows the seller [not just Microsoft? Bob] to remotely kill or remove access to a user's apps for security or legal reasons. The story also notes that MS states purchasers are responsible for backing up the data that you store in apps that you acquire via the Windows Store, including content you upload using those apps. If the Windows Store, an app, or any content is changed or discontinued, your data could be deleted or you may not be able to retrieve data you have stored."


I'll take “Prior Art” for a $Billion, Alex. (“We don't need no stinking Patent Lawyers.” )
"IBM's Watson is made of many parts: speech recognition, natural language processing, machine learning, and data mining. All of these factors were perfectly combined to beat Ken Jennings in Jeopardy, and now each of these components are slowly finding their way into other applications. Health plan company WellPoint, for example, is using Watson to investigate patient records to improve diagnosis, and in a self-referential, possibly universe-destroying twist, IBM itself is using Watson to help sell Watson (and other IBM products) to other companies. Now, using Watson's data mining and natural language talents, IBM has created the Strategic IP Insight Platform, or SIIP, a tool that has already scanned millions of medical patents and journals for the sake of improving drug discovery — and in the future, it's easy to see how the same tool could be used to battle patent trolling, too."


This could be handy. I'll add it to the “portable Firefox” on my thumb drive for use at school. Be sure to watch the video!
CC:to me is one of those bookmarklets that you are elated to have discovered, and also makes you wonder why an idea as simple as this wasn’t implemented by anyone earlier. As the name suggests, it allows you to email stuff to yourself via a bookmarklet. The best part – you can drag and drop text, images, videos and more from the web onto it and it emails them flawlessly along with the link. It’s free at the moment (sign up needed), and the pro accounts (coming soon) will bring goodies like multiple recipients and more.


Try all 6, the price is right!
6 Best Desktop eBook Readers For Reading At Home (Or At Work)
… reading on a computer is nice because it’s a device you already have. Buying expensive hardware just to do one thing can be pricey, especially when computers can do pretty much everything those devices can (and more).
Calibre: The Ultimate eBook Software
Calibre is the ultimate way to manage your collection on a desktop computer. It’s compatible with seemingly every known ebook format on the planet, and supports sending books to a wide variety of handheld ereaders and smartphones.
This program does too much for me to describe here, so find out all about Calibre in Open Book: Managing Your eBooks With Calibre, a free MakeUseOf download.
Google Books
Prefer using something in your browser? You might not be able to install software on your work computer, or you might switch computers regularly. Whatever your reason, you should check out Google Books, which gives you access to an eBook reader in your browser.
Firefox EPUB Extension
Do you want to read in your browser, but have already downloaded the EPUB files you want to read? You’re in luck! A Firefox extension for reading EPUB files works really well, and is free to install right now.
Magic Scroll
Upload your EPUB file so you can read it in your browser. MagicScroll is a great web-based eBook reader, featuring a very minimal interface and intuitive keyboard shortcuts.
Kindle
Do you already own a Kindle eReader, or make use of the Kindle app on your smartphone? Make sue you install the Kindle software for your desktop computer, then. You’ll be able to read your Kindle eBooks on your desktop. Best of all, your pages and bookmarks will stay in sync with your device.
Kobo
Own a Kobo instead of a Kindle? Me too! Good news: Kobo’s desktop software gives you access to thousands of free eBooks, and it’s free to download.
Nook
Are you a Nook user? You should check out the Nook software then. Like the above two programs, this eBook reader gives you access to books you’ve purchased at its respective store, and syncs.

Thursday, December 08, 2011


Big win, temporarily?
Heartland gets most of banks’ claims dismissed over its massive data breach
December 7, 2011 by admin
Bonnie Barron reports that Heartland Payment Systems succeeded in getting a federal court judge to agree to dismiss most of the claims in a consolidated lawsuit filed by nine banks following a massive breach that affected millions of customers.
Rosenthal granted the banks leave to amend the dismissed claims for breach of contract, breach of implied contract, express misrepresentation, negligent misrepresentation based on nondisclosure, and violations of the California Unfair Competition Law, the Colorado Consumer Protection Act, the Illinois Consumer Fraud and Deceptive Business Practices Act and the Texas Deceptive Trade Practices-Consumer Protection Act.
Heartland failed only in its bid to dismiss the claim that it violated the Florida Deceptive and Unfair Trade Practices Act. The processor had argued that the act applies only to consumers, not banks, but the Florida Legislature substituted “person” for “consumer” when it amended the act in 2001.
Read more on Courthouse News.


Looks like another successful test of the “Make the election turn out correctly” app!
Report: About 60,000 E-Votes Uncounted in NY Election Last Year
… The report (.pdf), released by the Democracy Program at New York University’s Brennan Center for Justice, says that instructions displayed on new optical scan machines confused voters who cast too many votes in the gubernatorial race, causing some 20,000 votes to be spoiled in that race.
… New York recently switched to optical scan machines, after the state was ordered to replace its antiquated mechanical lever voting machines. With optical scan machines, voters select their candidates on a paper ballot, which is then fed into the optical scanner.
The problem occurred with voters who chose more than one candidate in a race, called “overvoting.”


No surprise. Same for laptops, tablets, smartphones, etc.
"Antivirus firm Sophos acquired a passel of USB sticks lost by commuters on trains in the Greater Sydney metro area at an auction organized by the Rail Corporation New South Wales. The company analyzed 50 USB sticks and found that not a single one was encrypted and 33 of them were infected with at least one type of malware."


Interesting, if confused. I guess they see things differently in Texas.
Federal district court rules student has cause of action for violation of privacy rights after school officials disclosed sexual orientation to her mother
December 7, 2011 by Dissent
Here’s a follow-up on a case previously mentioned on this blog: Wyatt v. Kilgore Indep. Sch. Dist., No. 10-674 (E.D. Tex. Nov. 30, 2011)
Abstract: A federal district court in Texas has ruled that a student has stated a valid cause of action for violation of her substantive due process right to privacy based on school officials’ disclosure of her sexual orientation to her mother. It rejected school officials’ assertion of qualified immunity as a defense to the privacy claim, as factual disputes remained regarding whether school officials acted in an objectively reasonably manner and violated the student’s clearly established right to privacy.
The district court also upheld the validity of the student’s claim of municipal liability based on the school district’s failure to properly train employees and having a policy of disclosing a student’s sexual orientation. As with the privacy claim, it found that there were factual disputes regarding whether the school district has a policy of disclosing students’ sexual orientation and whether the district was deliberately indifferent to its duty to properly train employees to keep students’ sexual orientation confidential.
Read more on NSBA Legal Clips. Note that this has nothing to do with FERPA, which only protects education records.


They really see things differently. I look at virtual training as a place for soldiers to make mistakes, without dying or killing the wrong people. Corrections (true training) happen outside the virtual world.
Could Playing Videogames Be a War Crime?
Is your Xbox illegal under the Geneva Convention? Could you be hauled before the International Criminal Court for playing shooter games like Battlefield 3 or Call of Duty?
Absolutely not, says a spokesman for the International Committee of the Red Cross. “War crimes are serious violations of the laws of war committed in real life situations, not on virtual battlefields,” the ICRC’s Bijan Frederic Farnoudi tells Danger Room.
But Farnoudi’s colleagues aren’t quite so sure. They believe that virtual worlds and real war crimes could conceivably be linked — especially if an army uses a virtual world to train its troops.
… Christian Rouffaer, head of the ICRC’s international humanitarian law and videogames project, says that “a soldier trained on a computer or by any other means to shoot wounded enemy combatants would probably not be the only one to be prosecuted as it is primarily the responsibility of his commander to train, educate and to give him lawful orders.” In other words according to Rouffaer, military training that violates the Geneva Conventions is still a crime — even if that training is virtual.

(Related) Also, something for my geeky ex-military students to think about?
"DARPA has a problem on its hands: Satellites, unmanned drones (UAVs), and myriad other worldwide sensors are now so ubiquitous and omnipotent that the Department of Defense (DOD) doesn't actually know how to make the best use of them. In other words, the hardware is there, but the software isn't. To tackle this particularly tricky issue, DARPA is looking for smartphone app developers to help build 'sophisticated, adaptive applications.' Yes, DARPA wants to give smartphone developers access to the DOD's fleet of Hellfire missile-equipped UAVs. Instead of using a single, remote pilot to fly just one UAV, DARPA imagines 'an app [...] that allows a swarm of small deployed UAVs to be controlled as a single unit (a hive [mind] so to speak).' DARPA also wants app developers to help out with easy-to-use app interfaces, novel uses of smartphone-like sensors (accelerometers, cameras, gyros) — and ultimately, it wants to make a War Market where a soldier can simply log in with his DOD-issued smartphone or tablet and download Angry UAVs, Nuke Ninja, and other battlefield apps."


It matters to me!
Oregon media shield law did not protect blogger from having to reveal her sources (updated)
December 7, 2011 by Dissent
Evan Brown reports on a case in Oregon that will be of interest to bloggers: Obsidian Finance Group, LLC v. Cox, 2011 WL 5999334 (D.Or. November 30, 2011)
Evan writes:
Plaintiff filed a defamation lawsuit against defendant, who self-identified as an “investigative blogger” and a member of the “media.” Defendant asked the court to protect her from having to turn over the identity of the sources she spoke with in connection with drafting the allegedly defamatory content. She claimed that she was covered under Oregon’s media shield law, which provides in relevant part that:
No person connected with, employed by or engaged in any medium of communication to the public shall be required by … a judicial officer … to disclose, by subpoena or otherwise … [t]he source of any published or unpublished information obtained by the person in the course of gathering, receiving or processing information for any medium of communication to the public[.]
The court gave two reasons for finding that defendant was not covered by the shield law.
Read what the reasons were on Internet Cases.


I thought they had all these nifty “get by the censors” apps they distributed...
"Less than 12 hours after the U.S. launched a virtual embassy for Iran, the Iranian government blocked access to the website, directing visitors to a government page proclaiming the site illegal. The White House condemned the move, calling Iran's internet policies 'an electronic curtain of surveillance and censorship around its people.'"


Do we now generally accept electronic signatures?
House Votes to Make Netflix Playlist Sharing Easier
The House of Representatives on Tuesday easily passed legislation that updates video privacy laws to make it easier for online rental services such as Netflix to share information about customers’ viewing habits with user consent.
Current law requires written consent to share video records, but the new law would allow companies to obtain consent over the web.


An interesting look at reality. Perhaps Cloud Computing isn't the “Perfect Solution?”
December 07, 2011
CSC Cloud Usage Index
"Independent research firm TNS surveyed more than 3,500 cloud computing users in eight countries around the world to find answers to these and other timely questions. The survey focused on capturing user information about outcomes and experiences rather than predictions and intentions. While much remains to be discovered about how cloud can transform enterprises, the findings of the CSC commissioned Cloud Usage Index are nonetheless informative — and often surprising."
  • News release: "A survey of information technology (IT) decision makers around the globe found that the shift to cloud computing is driven primarily by a desire to connect employees through the multitude of computing devices in use today. Turning conventional wisdom on its head, 33 percent of survey respondents cited accessibility to information through multiple devices as the most important reason for their decision to adopt cloud computing."

(Related) Employees probably have a cellphone...
December 07, 2011
Americans and Mobile Computing: Key Trends in Consumer Research
Americans and Mobile Computing: Key Trends in Consumer Research, by Aaron Smith. December 7, 2011 at the Government Mobility Forum
  • "The Gadget Landscape - The Rise of Ubiquitous Mobile Connectivity
  • How Americans Use Their Phones - Engagement With Mobile Activities and Applications
  • The Meaning of Mobile - What is the Value Users Place on Their Mobile Devices?"


This gets filed in my “Wow, that's a lot of data” and “Who cares?” folders. Still, it does have the potential to keep today's 12-year-old from being elected president in 2042 based on some snarky tweet he or she made.
"The Library of Congress and Twitter have signed an agreement that will see an archive of every public Tweet ever sent handed over to the library's repository of historical documents. 'We have an agreement with Twitter where they have a bunch of servers with their historic archive of tweets, everything that was sent out and declared to be public,' said Bill Lefurgy, the digital initiatives program manager at the library's national digital information infrastructure and preservation program. Researchers will be able to look at the Twitter archive as a complete set of data, which they could then data-mine for interesting information."


Tools for teachers?
http://www.makeuseof.com/tag/5-easy-ways-download-convert-online-videos/
5 Easy Ways To Download & Convert Online Videos
But the opposite is also true. Sometimes sending a link or embedding a video is not enough, and we need the actual file, or only its soundtrack. And when that happens, the default FLV file format rarely cuts it. Luckily, there are several downloaders-converters out there that make it easy as pie to download videos and convert them into almost every possible format.


All I could think of was a new definition for “Blue screen of death.” After Fukashima, this is probably the only market for nuclear power...
"Microsoft Corp. co-founder Bill Gates says he is in discussions with China to jointly develop a new kind of nuclear reactor. During a talk at China's Ministry of Science & Technology Wednesday, the billionaire said: 'The idea is to be very low cost, very safe and generate very little waste.' Gates backs Washington-based TerraPower, which is developing a nuclear reactor that can run on depleted uranium."


A reading list...
The Open Laboratory 2012 – the final entries
… we are ready to announce the 50 essays and 1 poem that will be published in the sixth annual anthology of the best science writing online.