Tuesday, May 27, 2014

I was afraid this would happen.
http://www.pcworld.com/article/2159460/apple-devices-held-hostage-using-find-my-iphone.html
Apple devices held hostage using Find My iPhone
Hackers appear to be exploiting Apple’s “Find My iPhone” service to lock up phones and tablets and send ransom demands to their owners.
A number of reports on Apple’s support forum tell of devices displaying messages that they have been hacked by “Oleg Pliss” and demanding payment of a US$100 ransom via PayPal to unlock them. Most of the reports were from Australians but there were also reports from a Briton and a Canadian.
The hackers seem to have used the “Find My iPhone” feature or its equivalent for other Apple gadgets to lock the devices and send the message, according to the forum posts that were first highlighted by Australian newspaper The Age.


Wrong strategy or poor management?
http://www.securityweek.com/cyber-failures-spark-search-new-security-approach
Cyber Failures Spark Search for New Security Approach
With cybersecurity's most glaring failures in the limelight, many experts say it's time for a new approach.
In recent weeks, the security community has been rocked by news of a massive breach at online giant eBay affecting as many as 145 million customers, following another that hit as many as 110 million at retailer Target.
A US indictment earlier this month accused members of a shadowy Chinese military unit for allegedly hacking US companies for trade secrets, a charge denied by Beijing.
The incidents highlight huge gaps in cybersecurity, or the ease in which malicious actors can break into a single computer and subsequently penetrate a network or cloud.
… One of the dilemmas is that when people have a choice between security and utility, they often choose utility."
A survey released Wednesday by the security firm Trustwave said it identified 691 breaches across 24 countries last year, with the number of incidents up 53.6 percent over 2012.
… A report by security firm Symantec found a 91 percent increase in targeted "spearphishing" attacks in 2013 and said more than 552 million identities were exposed via breaches.
IBM recently unveiled a new cyber defense system aimed at thwarting attacks before they happen, with predictive analytics.


I have been teasing my lawyer friends – telling them I was working on an App to replace lawyers. That may be something to seriously consider if they change law schools like this paper suggests.
http://www.bespacific.com/legal-academy-erasure/
The Legal Academy Under Erasure
by Sabrina I. Pacifici on May 26, 2014
Redding, Richard E., The Legal Academy Under Erasure (2014). Catholic University Law Review, Forthcoming. Available at SSRN: http://ssrn.com/abstract=2433266
“We hear much about the crisis in legal education: high tuition costs, steep declines in law school enrollment, and graduates unprepared for practice who cannot find jobs. Proposals to address the crisis appear to enjoy wide support and may be poised to dramatically change the landscape of legal education. Such reforms will harm law students and the legal profession, placing the legal academy “under erasure,” by:
(1) reorienting it from an academically-grounded education towards vocational training,
(2) requiring just two years of study for the J.D. degree,
(3) allowing graduates of non-ABA accredited law schools to sit for the bar examination, thereby rendering accreditation a toothless mechanism for ensuring academic quality, and
(4) gutting faculty scholarship.
Instead, we must make the value of legal education worth its cost by doing a better job of educating and training our students. Legal education is broken because it fails to prepare students for the demands of modern law practice, which is more complex and interdisciplinary than ever before. We need a three-year program that is more robust, one that teaches the core first-year subjects as well as applications of other disciplines (e.g., accounting, economics, psychology) to everyday law practice, exposes students to a reasonable range of specialty areas, and integrates skills training (e.g., client counseling, advocacy, drafting) throughout the curriculum. To accomplish these goals, we should adapt the medical school model to legal education. This would entail a curriculum that provides a comprehensive foundation in basic legal subjects and legally relevant other disciplines, culminating in a series of clinical rotations where the basic doctrinal and interdisciplinary knowledge is applied in practice. I also explain why we should not gut support for faculty scholarship in the hopes that doing so will cut costs and encourage professors to focus on teaching. Contrary to popular claims, engaged scholars are better teachers, and legal scholarship can contribute meaningfully and substantially (though often in ways not readily apparent) to law practice and legal reform efforts. Finally, I suggest that we address the employment problem and improve educational quality by having fewer but better law schools, producing fewer attorneys.”

(Related)
http://blogs.hbr.org/2014/05/business-school-professors-should-be-like-movie-directors/
Business School Professors Should Be Like Movie Directors
As business school professors, we always ask ourselves why we are needed. Because we train future leaders and shape how organizations create value for societies. But will students need us in the same capacity in the future? Not if we don’t change to meet shifting educational needs.
A January Economist article on the Future of Jobs quoted experts saying that 47% of all job categories, including high-skill professions in medicine and law, will be automated within two decades. Among the professions that were said to be safe from automation (for the moment) are those that require human interaction and emotive and social competencies, such as management; those that rely on craft mastery, such as recreational therapists and actors; and those that involve understanding complex systems of human and institutional interaction, such as economists.


It apparently pays Microsoft to keep updating businesses that won’t pay to keep their software up to date.
http://www.theregister.co.uk/2014/05/26/german_tinkerer_gets_around_xpocalypse/
Windows XP fixes flaws for free if you turn PCs into CASH REGISTERS
A German web noticeboard has published instructions on how to keep getting the free Windows XP updates that enterprises are having to pay for.
According to this thread at Sebjik.com, all that's needed for 32-bit Windows XP installs is to edit the registry so that it tells Microsoft you're using POSReady 2009.
As Betanews notes, with the registry edit in place, you should receive updates for “Windows Embedded Industry (formerly known as Windows Embedded POSReady). This is based on Windows XP Service Pack 3”.


Roll your own Apps!
AppGyver Composer
http://www.appgyver.com/composer
– is the fastest way to bootstrap high-quality mobile apps. Drag and drop elements, lightning fast data integration and visual logic editing are just part of what makes Composer the fastest way to bootstrap your ideas. Direct access to the phone’s hardware features and native UI give you power to create beautiful apps without compromising in features, or quality.

Monday, May 26, 2014

Some of the unanswered questions resulting from some very poorly managed breach announcements. Perhaps Congress will ask these questions for us?
The eBay Data Breach: What You Need To Know
In what is one of the biggest breaches of user data yet, eBay has revealed that in March 2014 its servers were compromised. Other than confirming that staff accounts were co-opted and advising eBay account holders to change their passwords, it is revealing nothing else.


How do I surveil thee?
Let me count the ways...
The Transparency Reports Database – Government Requests for Users Data
by Sabrina I. Pacifici on May 25, 2014
Silk Transparency Project - “An increasing number of Internet and telecommunication companies are publishing reports detailing the number of government requests for user interaction data the companies have received in a given period of time. Technology and telecommunications companies store data on all user interactions. This includes “non-content data” (also called metadata). Metadata consists of login times, user location and IP addresses of users involved in the communication. Technology and telecom companies sometimes store actual content – recordings or copies of emails, chats, video chats, and voice calls. Governments file requests for this data for anti-terrorism surveillance but also for drug investigations and other law enforcement purposes. Called “Transparency Reports”, these reports also state how often the company complies with the government request. Silk collected all Transparency Reports from major service providers and normalized them into a comprehensive data resource for investigating government requests for users’ data. You can Explore the different Country / Company / Reporting Period pages to research specific queries or click here for our findings on:


I wonder if my Criminal Justice students would find this interesting? Should be no Privacy implications, since all the data is public – right?
Searching Social Media – Googling Facebook, Searching Twitter
by Sabrina I. Pacifici on May 25, 2014
Stosh Jonjak, Part 1, | Part 2 “Have you experienced an increase in social media search requests? As attorneys become more likely to turn to social media during their informal discovery processes, I have found an uptick in questions like: “could you please do a social media background check on this person?” This is a growing information need I believe law librarians are excellently suited to fill, and really the next generation of public records search requests. Through conducting these searches and by leaning on the expertise of others I have put together my own toolkit on tricks to use. [Here] I list methods incorporating Google advanced search terms to conduct searches on Facebook [and Twitter] quickly and with high relevancy.”


Should be simple to check the “best source” for revisions. Are there enough to support a “Corrections and Revisions Blog?”
New Paper – The (Non) Finality of Supreme Court Opinions
by Sabrina I. Pacifici on May 25, 2014
Adam Liptak, New York Times: “The Supreme Court has been quietly revising its decisions years after they were issued, altering the law of the land without public notice. The revisions include “truly substantive changes in factual statements and legal reasoning,” said Richard J. Lazarus, a law professor at Harvard and the author of a new study examining the phenomenon. The court can act quickly, as when Justice Antonin Scalia last month corrected an embarrassing error in a dissent in a case involving the Environmental Protection Agency. But most changes are neither prompt nor publicized, and the court’s secretive editing process has led judges and law professors astray, causing them to rely on passages that were later scrubbed from the official record. The widening public access to online versions of the court’s decisions, some of which do not reflect the final wording, has made the longstanding problem more pronounced. Unannounced changes have not reversed decisions outright, but they have withdrawn conclusions on significant points of law. They have also retreated from descriptions of common ground with other justices, as Justice Sandra Day O’Connor did in a major gay rights case.”


After Outsourcing and Off-shoring raised wages in other countries, this makes sense. (Video interview)
The Reshoring Wave: It’s Taking America by Storm
… There are many factors fueling this move, including labor costs, transportation, quality issues and patriotism, among others. Hal Sirkin, a senior partner at Boston Consulting Group, has been examining this trend for years and admits that the recent surge in reshoring has shocked even experts and researchers. Knowledge@Wharton sat down with Sirkin to discuss the different elements contributing to the reshoring trend and how it affects global business dynamics, the labor market and even the U.S.-Mexico relationship.


This is an interesting idea. I read this as the potential for an almost real time survey on any question you can properly format. Perhaps my statistics students could try it. (Okay, probably not but I can dream.)
Online and social media data as a flawed continuous panel survey – Microsoft
by Sabrina I. Pacifici on May 25, 2014
“There is a large body of research on utilizing online activity to predict various real world outcomes, ranging from outbreaks of influenza to outcomes of elections. There is considerably less work, however, on using this data to understand topic-specific interest and opinion amongst the general population and specific demographic subgroups, as currently measured by relatively expensive surveys. Here we investigate this possibility by studying a full census of all Twitter activity during the 2012 election cycle along with comprehensive search history of a large panel of internet users during the same period, highlighting the challenges in interpreting online and social media activity as the results of a survey. As noted in existing work, the online population is a non-representative sample of the offline world (e.g., the U.S. voting population). We extend this work to show how demographic skew and user participation is non-stationary and unpredictable over time. In addition, the nature of user contributions varies wildly around important events. Finally, we note subtle problems in mapping what people are sharing or consuming online to specific sentiment or opinion measures around a particular topic. These issues must be addressed before meaningful insight about public interest and opinion can be reliably extracted from online and social media data.” Latest version (May 15, 2014)

(Related) If you don't know why you should be doing something like the survey described in the previous post. Read these.
6 Free Social Media Guides All Business Owners Should Read


Another reason for Google to improve its translation tool.
Chinese agencies announce open-access policies – Nature
by Sabrina I. Pacifici on May 25, 2014
“China has officially joined the international push to make research papers free to read. On 15 May, the National Natural Science Foundation of China (NSFC), one of the country’s major basic-science funding agencies, and the Chinese Academy of Sciences (CAS), which funds and conducts research at more than 100 institutions, announced that researchers they support should deposit their papers into online repositories and make them publicly accessible within 12 months of publication. The policies, which went into effect the same day they were announced, are similar to the mandate set by the US National Institutes of Health (NIH). Xiaolin Zhang, director of the National Science Library at the CAS in Beijing, says that another major research-funding agency, the national ministry of science and technology, is also researching open-access policies. He expects that its policy will take a similar line. (The ministry had not provided comment by the time this article was published.) Richard Van Nordeen, 19 May 2014, corrected May 20 2014.


For my student Vets. Because we remember.
VA National Gravesite Locator Tool
by Sabrina I. Pacifici on May 25, 2014
“The database of burial information is updated each day. Search for burial locations of veterans and their family members in VA National Cemeteries, state veterans cemeteries, various other military and Department of Interior cemeteries, and for veterans buried in private cemeteries when the grave is marked with a government grave marker. The Nationwide Gravesite Locator includes burial records from many sources. These sources provide varied data; some searches may contain less information than others. Information on veterans buried in private cemeteries was collected for the purpose of furnishing government grave markers, and we do not have information available for burials prior to 1997. Erroneous information can be corrected, but we are unable to add to the information contained in the existing record. If your search returns incorrect information about a veteran or family member buried in a national cemetery, please contact the cemetery directly to discuss your findings. To report incorrect information about a veteran buried in a private cemetery, click on “Contact Us” at the top of this page. Names cannot be added to the listing if a government grave marker was not furnished for the grave, or if the existing government grave marker was furnished prior to 1997. For more complete information concerning individual records, we suggest you contact the cemetery or local officials.”

Sunday, May 25, 2014

“We're here. We have the tools and we know how to use them.” The problem is they are still thinking like pre-internet strategists – “What's nearby so I can begin my conquest of the world?” In the Internet Age, everything is nearby.
D. Frank Smith reports:
Colleges have consistently been a prime target for hackers. In 2013, the University of Wisconsin sustained up to 100,000 hacking attempts each day, according to The New York Times. And research released May 20 by the EDUCAUSE Higher Education Information Security Council shows that the education sector topped the charts in a survey of security breaches across seven industries.
The survey analyzed digital security breaches in which records were illegally obtained. In the education sector, 73 percent of breaches resulted in stolen records.
Read more on EdTech.


Another risk from the Internet of (Hackable) Things!
Smart TVs Are A Growing Security Risk: How Do You Deal With This?
… If you have a Smart TV, then yes, it can be hacked.
The good news is that it isn’t a rampant phenomenon… yet. The day is soon coming, however, when you may need to install anti-virus and anti-malware software onto your TV to keep it safe.
… What is a Smart TV? James was pretty thorough with his Smart TV overview which also explains whether or not you should even purchase one. Long story short, a Smart TV is the hybrid child of the television and the computer. It can browse the web, install and run apps, respond to voice commands, and more.
Again, let me restate: Smart TVs are not inherently compromised in terms of security. You only need to worry if you have a Smart TV that actively uses the Internet.


Californians are about to collide with the Internet of Things! I've been thinking that this is the electronic equivalent of having a chauffeur. Have we skipped over the electronic butler and maid because cleaning a house is more complicated than driving on California highways? How about e-Gardeners and all those other Downton Abbey characters?
California Will Allow Self-Driving Cars on the Road This Fall
Be prepared to see driverless cars on California roads after Sept. 16. That's when the DMV will allow self-driving cars to begin testing on public roads. The move comes two months after California held public hearings on the technology.
In order to test self-driving cars companies must apply for a permit and purchase a $5 million insurance bond. If any of the cars get in an accident, it has to be reported within 10 days. Additionally, researchers have to report if the car's self-driving functions are turned off for safety reasons.


This article nicely summarizes my concerns. Now we can pay into another fund that will never get spent for its intended purpose.
FCC gets approval for plan to subsidize fast rural internet access
At long last, the FCC can move forward with reforming its rural connection subsidies for the broadband era. A federal appeals court has upheld the agency's Connect America Fund after challenges from smaller carriers, which were worried that the shift from subsidizing phone calls to fast internet access would hurt their bottom line. Their arguments were either "unpersuasive" or were blocked from legal consideration in the first place, the court says.
The fund still faces criticism from those worried that the $4.5 billion in subsidies will hike phone bills through growing fees; there's also concerns that the occasional fraud seen in existing programs might carry over to Connect America.


Coming soon to a state near me.
Kentucky Wins Hemp Seed Release from Federal Government


Something to amuse my students?
Learn New Words With The Collins Twictionary [Weird & Wonderful Web]
New words are being invented all the time, both online and offline. The Internet is responsible for a host of new words and phrases, many of which end up making it into dictionaries.
Having previously looked at 10 Internet phrases we would like to see die in a fire, it’s high time we balanced things out with a look at a collection of new words currently vying for inclusion in the next Collins English Dictionary.
… The Twictionary is Collins’ attempt to utilize the power of Twitter to decide which Internet-originated words should make it into the twelfth edition of the Collins English Dictionary.
[My Favorite: Adorkable – Dorky in an adorable way.


Once again Dilbert connects on many levels.

Saturday, May 24, 2014

A good summary of several breaches and the lack of investor response. Profits, not privacy.
Eric Chemi reports:
On May 21, Ebay revealed that it had suffered a cyber attack and data security breach, and users’ information—names, account passwords, e-mail addresses, physical addresses, phone numbers, and birth dates—was exposed to hackers. While security experts, the news media, and actual EBay users may have all been alarmed, the stock investors weren’t. EBay’s stock finished trading virtually unchanged that day, dropping all of 8 pennies to $51.88.
That’s been the trend among companies that have suffered cyber attacks—the stock market practically ignores them.
Read more on Bloomberg Businessweek.


Google fiber is already much, much faster than Comcast's cable, so this isn't a problem – except I can't get Google fiber.
Google Gives Netflix Free Access to Fiber Fast Lane, Calls It a "Win-Win" Situation
Google Fiber's approach is the exact opposite of Comcast's Net neutrality is one of the biggest topics on the web right now, and lest anyone thing it's being overstated, see the spat between Netflix and Comcast. In short, Netflix inked a multi-year agreement with Comcast to ensure that its traffic is pumped into homes at the fastest speed possible to avoid buffering, low quality video, dropouts, and other undesirable effects of slowed connections. Not long after, Netflix announced it was increasing its subscription by $1 for new subscribers. In other words, it's the customers that ultimately foot the bill when big companies fight, which is why it's refreshing to see Google take a different approach.
… Having Google as your ally is a pretty big deal, but will it be enough to sway other ISPs to follow suit? Don't hold your breath.


For my Forensic and Ethical Hacking students.
How To Find What Program Is Using Your Webcam
You’re sitting in front of your computer, minding your own business, when you suddenly notice the webcam light is on. Something is looking at you — maybe even recording or broadcasting online. But what? You don’t have Skype running, and you close the browser just to make sure. The light won’t go off! What’s using that webcam?
Here’s how to tell.
[You can get the Sysinternals Suite here: http://technet.microsoft.com/en-us/sysinternals/bb842062


Something to bore my Statistics students with... Just because it talks about Z-scores
The Top 10 (And Counting) Education Systems In The World
… If you want to toy around with the statistics and see what factors are influencing each country in each area, you can take a few minutes to play around with the interactive graphic of cognitive skills and educational attainment.


Just for me.
… Stuart Magruder, an LA architect who’s been an outspoken opponent of LAUSD’s plans to use school construction bonds to pay for its iPad initiative, found his reappointment to the LAUSD school board blocked by other board members.
… Paris Gray, vice president of her about-to-graduate class, was suspended because of her quote in the school yearbook: “When the going gets tough, just remember to Barium, Carbon, Potassium, Thorium, Astatine, Arsenic, Sulfur, Uranium, Phosphorus.” It took the school a while to decode her message, but when they did, they were angry that she was smart and because she was female and black, they felt compelled to punish her, I guess.
… The fallout continues from last week’s firing of a University of Saskatchewan tenured professor. This week, the provost resigned. The VP of Academic Design resigned. And then the board of governors fired the university president.
… Edukwest suggests that Google’s recent acquisition of Divide will “boost BYOD in schools.”

Friday, May 23, 2014

Attention hackers! Pretend to be eBay and the phishing is great!
By E-Mailing Hacking Victims, EBay Opens Users Up to More Risk of Attack
After hackers stole e-mail addresses and other user data from EBay's network, the company announced today that it would e-mail users to suggest they change their passwords. That doesn't make a whole lot of sense.
The problem with this approach is that the hours immediately following a breach are prime time for hackers. Cyber-criminals are consummate opportunists. They scrutinize the news looking for ways to craft fraudulent and timely messages to trick people into clicking on them. The millions of EBay users who may have caught wind of the breach after seeing a headline today are more likely to fall for an e-mail scam prompting them to click a link and input their log-in information. A similar technique was used by Chinese military officers to hack into U.S. companies, showing that in cyber-security, people are their own worst enemies.
Instead of e-mailing the auction site's more than 145 million active buyers worldwide, EBay could have immediately done something that Adobe Systems, LinkedIn and Evernote all did after their recent high-profile hacks: change users' passwords. Automatically resetting accounts is becoming a "common courtesy" after many breaches, says Lysa Myers, a researcher with Slovakian security firm ESET.


Ignorance is not bliss. Should I buy an emergency generator because my electric utility was hacked? Or should I stock up on firewood because I could lose gas service? Will my sewer back up? And don't give me that, “There are some things man was not meant to know!”
An American Utility's Control System Was Hacked
The control system for a U.S. public utility was compromised. The Department of Homeland Security did not specify which utility was affected in the agency's Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) report.
… Details of these cyber attacks are rarely revealed to the public, and even more rarely do they provide details into the matter. What we do know: this particular attack was on a utility that was previously hacked and the hackers used the employee access portal to get in.


Perspective
Most 2013 Data Breaches Affected E-Commerce and POS Systems: Trustwave
The new study is based on data gathered from 691 breach investigations and focuses on security threats, cybercrime and data breaches. Payment card data continues to be the top type of data that's compromised in breaches. However, the percentage of data thefts involving confidential, non-payment card data has reached 45 percent in 2013. This represents a 33 percent increase compared to the previous year.
Around 54 percent of the attacks that took place in 2013 targeted e-commerce systems. Point-of-sale (POS) attacks are next with 33 percent. In fact, experts believe that these two types of breaches will dominate the landscape in the upcoming years.
… You can download the full 2014 Trustwave Global Security Report from Trustwave’s website.


Please send your “Money-like things” to Bob, care of this Blog.
The Future of Money-Like Things
While we rarely think of it in this way, the payment system we use every day is among the most widespread and functional examples of an Internet of Things. It is an array of objects embedded with chips, magnetic stripes, scanners, and touchpads. These things are coordinated through networking protocols used to move information and, ultimately, monetary value.
In payment systems, as flights of imagination get grounded in real infrastructures, interoperability has gone hand in hand with technological inertia. Payment systems have to work, and they have to work everywhere. When you swipe your credit card, it works. No matter where you are in the U.S., if you have money or credit in physical or electronic form, you can pay for stuff.


Who wants your data? Just about everyone! ...and it's easy to see why.
Your Banker Wants To Know If You Are Pregnant
Your banker wants to know if your wife has thrown you out of the house. Or if one of your parents has died. Or if you are expecting a child.
Because banks typically make more money when they know clients better, they are stepping up efforts to learn more personal information. For example, in recent weeks HSBC has been writing its Premier clients and encouraging them to share details about themselves.
… According to Wells Fargo presentations earlier this week, “building relationships around individuals” leads to 65% higher revenue. Active customers there are 2.2 times more profitable than less active ones, the bank estimates.

(Related)
McKinsey – The seven habits of highly effective digital enterprises
by Sabrina I. Pacifici on May 22, 2014
May 2014 | by’Tunde Olanrewaju, Kate Smaje, and Paul Willmott
“The age of experimentation with digital is over. In an often bleak landscape of slow economic recovery, digital continues to show healthy growth. E-commerce is growing at double-digit rates in the United States and most European countries, and it is booming across Asia. To take advantage of this momentum, companies need to move beyond experiments with digital and transform themselves into digital businesses. Yet many companies are stumbling as they try to turn their digital agendas into new business and operating models. The reason, we believe, is that digital transformation is uniquely challenging, touching every function and business unit while also demanding the rapid development of new skills and investments that are very different from business as usual. To succeed, management teams need to move beyond vague statements of intent and focus on “hard wiring” digital into their organization’s structures, processes, systems, and incentives. There is no blueprint for success, but there are plenty of examples that offer insights into the approaches and actions of a successful digital transformation. By studying dozens of these successes—looking beyond the usual suspects—we discovered that highly effective digital enterprises share these seven habits…”


“'Tis a puzzlement” The King of Siam Facebook Users
Is Facebook taking privacy more seriously?
… Facebook is worried that you will start sharing less - or maybe even move to more anonymous services - unless it helps you better manage your private information. On Thursday, the company announced that it would give a privacy checkup to every one of its 1.28 billion users worldwide.
Facebook, which is based in Menlo Park, California, will also change how it treats new users by initially setting their posts to be seen only by friends. Previously, those posts were accessible to anyone.
And it will explain to both current and new users that setting their privacy to "public" means that anyone can see their photos and posts.
The change in default settings and the person-by-person review is a sharp reversal for Facebook, whose privacy settings are famously complicated. Some users may be shocked when they see just how widely their personal information has been shared.


Microsoft challenged, that's good. But only once and only because it made no difference?
Microsoft Challenged Secret FBI Request for Data About Business Customer
Microsoft Corp. last year challenged a secret request for data about a business customer from the Federal Bureau of Investigation. The government backed down—but only after it got the information it sought without the software giant’s help, according to documents unsealed Thursday.
… Little is known about the facts behind the request Microsoft challenged. On a still-secret date last year, the FBI asked Microsoft for user information on a single employee at a large business customer, according to court records. The customer, whose name was redacted, used Microsoft’s Office 365 service, which stores customer data in Microsoft data centers—not servers controlled by the customer.
… After Microsoft objected, the FBI obtained the data it wanted by approaching Microsoft’s customer directly, according to court documents.


See? It can be done. But why would a monopoly want to?
Cox to offer residential gigabit speeds
Cox Communications – the third-ranked US cable MSO – has revealed plans to roll out gigabit Internet speeds across its markets nationwide. The company will start with new residential construction projects and new and existing neighbourhoods in Phoenix, Las Vegas and Omaha. In all Cox locations, the company will begin market-wide deployment of gigabit speeds by the end of 2016.

Thursday, May 22, 2014

Some confusion too. There was a message on the PayPal Blog that they took down after a short time. Guess they should have left it up.
eBay tells all users to reset passwords after security breach
Time for another password change, folks – at least, if you’re an eBay user.
The e-commerce giant on Wednesday strongly recommended all users to reset their password for the site after it was discovered hackers had compromised a database containing encrypted passwords and other non-financial data.
The company reassured users that following “extensive” tests, there was no evidence so far of any unauthorized activity on the site, and no evidence of any unauthorized access to financial or credit card information, which it said it holds separately in encrypted formats.
… The compromised database, which included eBay customers’ names, encrypted passwords, email addresses, mail addresses, phone numbers, and dates of birth, was hacked between late February and early March, eBay said, adding that it was only recently discovered.


Far cheaper than nukes.
Iran's Cyber Attack Capabilities Growing Quickly: Experts
When it comes to cyber-espionage and nation-state attacks, the accusing finger generally points at China. Last week's report from FireEye indicates that China is not alone, as Iranian cybersecurity capabilities continue to grow, posing a greater threat to U.S. interests.
Iranian cyber-attackers are increasingly moving away from politically motivated attacks such as Website defacement to cyber-espionage, targeting the U.S. defense industry sector, FireEye researchers outlined in the "Operation Saffron Rose" report. What was lost—or glossed over—in the rush to discuss the actual tactics used by these attack groups was the fact that this shift in sophistication has striking similarities with how Chinese attack groups evolved over the past few years.


So this is why their CEO was fired – not the breach, the lost profits.
Associated Press reports:
Target cut its annual profit outlook Wednesday and said its first-quarter earnings fell 16 percent as it took another hit from a massive customer data breach and a troubled expansion in Canada.
The third-largest U.S. retailer, based in Minneapolis, also issued a second-quarter projection that was below analysts’ expectations.
Read more on Telegram.com


The logical extension of an Internet of Things, and Internet of Advertising.
Yikes! Google seems to think ads everywhere is the future...even on thermostats, fridges, glasses and watches
If the companies behind the massive Internet of Things initiative get their way, in the next 10 years everything you own will be connected to the Internet. With that being the case, Google thinks all that connected real estate represents a prime opportunity for advertising.
In a etter to the Securities and Exchange Commission, Google clearly sees that this ever-evolving connected world can be filled ... with ads.
… "In a short period of time, the meaning of 'mobile' at Google has shifted dramatically to 'handset' from 'tablet + handset'," the letter states. "We expect the definition of 'mobile' to continue to evolve as more and more 'smart' devices gain traction in the market. For example, a few years from now, we and other companies could be serving ads and other content on refrigerators, car dashboards, thermostats, glasses, and watches, to name just a few possibilities."

(Related) Our dogs already have an ID chip injected under their skin. No doubt when this product shrinks to injectable size, we'll do that too. After all, dogs can slip out of their collars.
Now, GPS device that will keep track of your pooch
… Whistle, the San Francisco startup that's become known in recent months for its somewhat handy "FitBit for dogs" gadget, announced that it's adding some key new features to the newest generation of its on-collar device to make it so that you never lose track of your pooch, Tech Crunch reported.
The new product, dubbed WhistleGPS, uses both GPS and sub-GHz cellular technology to add on-demand location monitoring to Whistle's flagship activity tracking gadget that syncs with iOS or Android devices.

(Related)
Consumer Reports: 85% of Shoppers Oppose Internet Ad Tracking
by Sabrina I. Pacifici on May 21, 2014
EPIC: “According to a recent study by Consumer Reports, consumers overwhelmingly object to having their online activities tracked for advertising purposes. The report found that 85% of consumers would not trade even anonymized personal data for targeted ads. Additionally, 76% of consumers said that targeted advertising adds “little or no value” to their shopping activities. For more information, see EPIC: Public Opinion on Privacy, EPIC: Privacy and Consumer Profiling, EPIC: Online Tracking and Behavioral Profiling, EPIC: Practical Privacy Tools.”


Another piece of your profile?
Facebook wants to 'listen' to your music and TV
If the song or show is recognised by the app, users can publish the information on their profile or to selected friends.
The service hopes to take advantage of the "second screen" trend, which sees fans of TV shows in particular sharing their experiences on social networks.
… The feature, which will be available in a few weeks' time, uses the microphones inside users' smartphones to detect nearby music or TV shows.
… Facebook says the feature can be turned off at any time, the audio recording is not stored anywhere and the device cannot identify background noise or conversations.


Perspective. “Just because FedEx and UPS and all those other services can do it doesn't mean an organization that's run like a government agency can do it.”
US House committee approves bill to curb doorstep mail delivery
The move, which would echo the strategy already being implemented across the border in Canada, could save the US Postal Service about $2bn in operating costs each year according to the Republicans who control the House.
It would require those homes receiving mail at the doorstep to have items delivered either to a roadside mailbox or a community mailbox.


Perspective. Even spaghetti sauce is a billion dollar business.
Unilever to Sell Ragú Brand to Japan’s Mizkan
Unilever will sell its North American pasta-sauces business under the Ragú and Bertolli brands to Japan's Mizkan Group for $2.15 billion.


For my “starving students”
– Get cash back when you buy your favourite brands. Install the app for either iOS or Android to see how much you can save on groceries this week. First, browse the offers that are updated every Thursday, buy the products from any store, then take a photo of your receipt to redeem your deal. Once your account reaches $20 in savings, they will mail you a cheque.


For my student vets
The 2014 Season of Blue Star Museums kicks off!
NEA Acting Chairman Joan Shigekawa and Blue Star Families CEO Kathy Roth-Douquet announced the fifth annual launch of Blue Star Museums, a collaboration among the National Endowment for the Arts, Blue Star Families, the Department of Defense, and more than 2,000 museums across America to offer free admission to the nation’s service members, including National Guard and Reserve, and their families from Memorial Day through Labor Day 2014. Leadership support has been provided by MetLife Foundation through Blue Star Families. The program provides families an opportunity to enjoy the nation's cultural heritage or learn more about their new communities after completing a military move. The complete list of participating museums is available at www.bluestarfam.org/bluestarmuseums.

Wednesday, May 21, 2014

The kind of article I'm hoping our student “Computer Security Club” will start producing.
How Easy Is It For Someone To Hack Your Webcam?
Without wishing to scare you, the short answer is: it’s very easy for anyone to view your webcam. The long answer is: some networked webcams require nothing more than a secret URL, while most USB or built-in laptop webcams would need the computer to be compromised first.
Here are three ways of viewing a webcam without your knowledge.


Nothing new here – unfortunately.
Trend Micro Analyzes Targeted Attack Trends
In a new report, researchers at Trend Micro found the majority of exploits involved in these incidents during the second half of 2013 focused on vulnerabilities that had patches available, including some that were patched as early as 2009.
… Nearly 60 percent of the time the malware used in targeted attacks are Trojans or spyware. Next in line were backdoors (22 percent) used to establish command and control communications.
"Spear phishing is still the most seen entry point for targeted attacks," Irinco continued. "These email messages use relevant-sounding subjects that trick users into opening it and the file attachments therein that serve as malware carriers. In our 2014 prediction, we noted that mobile devices will also be leveraged by threat actors to gain entry to networks."
The full report can be read here.


The ethics of intelligence services. Long debated, long resolved. The answer is “it depends.”
Should U.S. Hackers Fix Cybersecurity Holes or Exploit Them?
There’s a debate going on about whether the U.S. government—specifically, the NSA and United States Cyber Command—should stockpile Internet vulnerabilities or disclose and fix them. It's a complicated problem, and one that starkly illustrates the difficulty of separating attack and defense in cyberspace.
… If vulnerabilities are plentiful—and this seems to be true—the ones the U.S. finds and the ones the Chinese find will largely be different. This means that patching the vulnerabilities we find won’t make it appreciably harder for criminals to find the next one. We don’t really improve general software security by disclosing and patching unknown vulnerabilities, because the percentage we find and fix is small compared to the total number that are out there.


Sic 'em, Steve! (An open letter!)
Steve Wozniak to the FCC: Keep the Internet Free


Perhaps the Privacy Foundation could work with local entrepreneurs to suggest a few areas for development? (They also moved their HQ to Switzerland)
Proving there’s money in privacy these days, secure communications firm Silent Circle has announced a $30 million funding round from investors including Ross Perot Jr. and Cain Capital. What’s more, Perot and Sir Peter Bonfield, once upon a time the head of British Telecom, have joined Silent Circle’s advisory board.
Silent Circle is most notable for the Blackphone, a privacy-centric handset, produced alongside manufacturer Geeksphone, that uses an Android fork called PrivatOS and comes loaded with all sorts of security tools including Silent Circle’s encrypted voice and text communications tools. The much-anticipated device will start shipping in June, probably mostly to enterprise and government customers.
The firm is also working with shuttered secure email service Lavabit on “Email 3.0″, which will supposedly be both secure and easy to use, and leak less metadata than today’s encrypted email protocols.

(Related) Because it occurs to me that we had discussed each of these points at one Privacy Foundation seminar or another...
Harrison Weber reports:
The National Security Agency and the FBI teamed up in October 2010 to develop techniques for turning Facebook into a surveillance tool.
Documents released alongside security journalist Glenn Greenwald’s new book, “No Place To Hide,” reveal the NSA and FBI partnership, in which the two agencies developed techniques for exploiting Facebook chats, capturing private photos, collecting IP addresses, and gathering private profile data.
According to the slides below, the agencies’ goal for such collection was to capture “a very rich source of information on targets,” including “personal details, ‘pattern of life,’ connections to associates, [and] media.”
Read more on VentureBeat.


Trust me, this is worth looking at even if just for the Internet of Things section.
Gartner's Hype Cycle report for smart-city technologies
City planners will have access to an amazing collection of technologies to build their smart cities of the future. But what technologies are coming, and when, and how will they be used? Gartner separates hype from reality with its largest Hype Cycle report.
Read Gartner's report The report is free and ungated. No sign-up required


Brief article suggesting that there are companies who can move with the times/technology. (Looks like that's good for the CEO too)
Burberry Struts Ahead With Tech Transformation Begun By Apple's Angela Ahrendts
Burberry – the high-end fashion brand and retail chain – has posted record results, aided by an advanced digital transformation. That effort was begun eight years ago by former CEO Angela Ahrendts, now the retail boss at Apple.


No doubt this will result in a bunch of “Google doesn't pay taxes!” stories. I see it as yet another indication that the tax system isn't allowing US firms to be as flexible as firms in other countries.
Google plans international acquisitions worth up to $30B, it tells SEC
Google plans to spend US$20 billion to $30 billion of its of its accumulated international profits to fund potential acquisitions of non-U.S. companies and technology rights.
The company disclosed its plans to the U.S. Securities and Exchange Commission (SEC) last year, in a document that was published Tuesday. The SEC had asked Google to describe its plans for reinvesting its undistributed earnings in greater detail.
In 2012, Google generated about half its revenue in non-U.S. markets.


Can't wait to hear what my wife says about this App. Looks like it is targeted to mixed breed owners – after all, one collie looks pretty much like another.
PetMatch uses machine vision technology to help you replace your beloved pet
… Unlike Superfish’s Windowshopper app, PetMatch offers a more benign and benevolent alternative for your wallet. Just upload an image of your pet, or even someone else’s pet and let the app match you up with a nearby puppy or kitten. The app acts as an intelligent learning machine, so theoretically, it might improve your chances over time.


I get a bit cranky when I run into companies that insist on a fax rather than an email attached document. Tools/services like this keep me from running around looking for someone with antique machines. (Remember, the fax predates the phone by at least 25 years.)
No Fax Machine? No Problem — Easily Sign And Send Faxes From Your Computer
Faxing is an out-dated mode of communication, but it still lingers around at some places for one reason or another. Until we can finally kill off this antiquated machine of the past, you might need to send a fax every once in a while but find yourself without a fax machine — try HelloFax.
We have covered HelloFax briefly in the past, and even took a look at 5 other online fax services, but things have changed in the years since then, and it’s time to take an in-depth look at the best free online faxing service there is.