Monday, May 09, 2016

This summary is not available. Please click here to view the post.

Sunday, May 08, 2016

An observation.  Today’s Election section of the Google News page is all Donald Trump.  There are no articles on Hillary Clinton until you page down.  No matter what else you may think, the Donald does know how to lead the media by the nose.


One of the “benefits” of Office365?   


How can these devices remain undetected for months?  Do watch the video!
Large Credit Card Breach at Walmart in Fredericksburg
Fredericksburg City Police says a "large number" of debit/credit card users at the Central Park Walmart had their card information stolen, with dozens of reports of fraudulent cash withdrawls.
Walmart Global has confirmed an unspecified number of cards have been compromised.
It's believed the suspects obtained the card information by placing overlay devices on credit card readers at checkout counters in March and April.
   In a statement to Patch, Walmart spokesperson Deisha Barnett said the company took steps to protect customers as soon as they were alerted to the fraudulent activity.
   Fredericksburg City Police also released a video to show how quickly a skimmer device is placed on a credit/debit card readers. [Not at Walmart, but still interesting.  Bob]


We don’t track smartphones as closely as we track airbags.
Lucian Constantin reports:
A vulnerability in an Android component shipped with phones that use Qualcomm chips puts users’ text messages and call history at risk of theft.
The flaw was found by security researchers from FireEye and was patched by Qualcomm in March.  However, because the vulnerability was introduced five years ago, many affected devices are unlikely to ever receive the fix because they’re no longer supported by their manufacturers.
Read more on Computerworld.


We have become a nation of terrified, gullible, ignorant sheep.
Dark, Curly Haired Man With Olive Skin Suspected of Terrorism After Intensely Scribbling Strange Script Aboard Plane. But There’s Just One Problem.
   An airline agent told the man he was suspected of terrorism, the Post said — mostly because of whatever it was his former seatmate had seen him intensely scribbling (but his look and accent apparently gave her pause, too).
The man under investigation laughed, the paper said.
He wasn’t scribbling in Arabic or penning code for a terrorist plot — he was in the middle of a math equation.
Guido Menzio hails from Italy and is a well-regarded economist who’s an associate professor at the University of Pennsylvania.
   Menzio told the paper he was “treated respectfully throughout” but is unimpressed by a “broken system that does not collect information efficiently.”  He added to the Post that airline security protocol “is too rigid — in the sense that once the whistle is blown everything stops without checks – and relies on the input of people who may be completely clueless.”

Saturday, May 07, 2016

There goes that Guinness World Record.
Garbage in, garbage out: Why Ars ignored this week’s massive password breach
Earlier this week, mass panic ensued when a security firm reported the recovery of a whopping 272 million account credentials belonging to users of Gmail, Microsoft, Yahoo, and a variety of overseas services.  "Big data breaches found at major email services" warned Reuters, the news service that broke the news.  Within hours, other news services were running stories based on the report with headlines like "Tech experts: Change your email password now."
Since then, both Google and a Russia-based e-mail service unveiled analyses that call into question the validity of the security firm's entire report.
"More than 98% of the Google account credentials in this research turned out to be bogus," a Google representative wrote in an e-mail.  "As we always do in this type of situation, we increased the level of login protection for users that may have been affected."  According to the report, the compromised credential list included logins to almost 23 million Gmail accounts.

(Related)
Here's how I verify data breaches


A continuous process.  Nothing new there.  Perhaps if we combine IBM’s Watson with their Quantum Computer…
Mohit Kumar writes:
Defense Advanced Projects Agency (DARPA) is offering funding for security researchers who can help the agency to develop algorithms that can identify hackers under its new game-changing initiative called ‘Enhanced Attribution Program’.
Although organizations and countries give their best to identify cyber campaigns who infiltrated their critical infrastructure, tracking down the culprits has always been a difficult task — thanks to TOR, Virtual Private Networks (VPNs), and other methods used to hide the attack source.
However, through this new initiative, the United States military research agency DARPA hopes that agencies would quickly track and identify sophisticated hackers or criminal groups by monitoring their exact behavior and physical biometrics.
The aim of Enhanced Attribution program is to track personas continuously and create “algorithms for developing predictive behavioral profiles.
“The goal of the Enhanced Attribution (EA) program is to develop technologies for generating operationally and tactically relevant information about multiple concurrent independent malicious cyber campaigns, each involving several operators; and the means to share such information with any of a number of interested parties without putting at risk the sources and methods used for collection,” reads the project’s official site.
In other words, the Enhanced Attribution Program will not only help the government characterize the cyber criminal but also share the criminal’s modus operandi with potential victims and predict the attacker’s next target.
Read more on The Hacker News.
Wait… “without putting at risk the sources and methods used for collection?”  That sounds to me like a response to recent court cases where the government has dismissed cases rather than reveal their surveillance methods


Does Congress know about this?  Do computers have a “Right to Privacy?”  Perhaps a “Right to be left alone?” 
Lindsay Tonsager writes:
In a blog post published on the Federal Trade Commission (FTC) website, Jessica Rich, Director of the FTC’s Bureau of Consumer Protection, recently stated that:
“we regard data as ‘personally identifiable,’ and thus warranting privacy protections, when it can be reasonably linked to a particular person, computer, or device.  In many cases, persistent identifiers such as device identifiers, MAC addresses, static IP addresses, or cookies meet this test.”
The post (which reiterates Ms. Rich’s remarks at the Network Advertising Initiative’s April meeting) suggests a shift in the FTC’s treatment of IP addresses and other numbers that identify a browser or device.   The FTC previously has taken the position that browser and device identifiers are deserving of privacy protections, but the FTC generally has avoided classifying these identifiers as equivalent to personally identifiable information (such as name, email, and address) except in the narrow context of children’s privacy.
Read more on Covington & Burling Inside Privacy.


I don’t post much from Kellogg.  I’m not sure why that is.
Is Reading Someone’s Emails Like Entering Their Home?
   In the late nineteenth century, when considering laws about intercepting confidential messages, Congress debated whether the telegraph was comparable to the postal service.  Protecting the privacy of a telegram, after all, only made sense if everyone agreed that telegrams were analogous to personal letters—a view that, though it never became an official act of Congress, was eventually supported by state laws.
But the rise of electronic communications has made this analogical reasoning even more of a headache.  By 1995, courts were debating whether encryption software belonged on a list of regulated munitions (alongside bombs and flamethrowers) or whether encryption was in fact a “language act” protected by the first amendment.


Wouldn’t this fall under the same exemption as your fingerprints?  It’s pretty hard NOT seeing your face, does a photograph make that much of a difference?
Defeat for Facebook in Court Is Bad News for Firms That Scan Faces
Who owns your face?
A California judge on Thursday ruled against Facebook in a lawsuit that says the company violated user privacy by scanning their faces without permission and inviting others to “tag” them in photographs.
The case is significant because it’s one of the first to test the boundaries of how companies use facial recognition software, a rapidly-advancing technology that treats faces as the modern-day equivalent of a fingerprint.  (At Facebook, the company has internally referred to the tool as a “faceprint.”)
   In the ruling, which you can read here, U.S. District Judge James Donato agreed that Facebook’s scanning and tagging feature qualified as a use of biometric identifier covered by the statute.  On a key procedural issue, he refused Facebook’s request to decide the case under California law, where companies don’t face restrictions on the use of biometrics.


Statistically backed assertions. 
   How large is this secret ECPA docket?  Extrapolating from a Federal Judicial Center study of 2006 federal case filings, I have estimated that more than 30,000 secret ECPA orders were issued that year alone.  Given recent DOJ disclosures, the current annual volume is probably twice that number.  And those figures do not include surveillance orders obtained by state and local authorities, who handle more than 15 times the number of felony investigations that the feds do.  Based on that ratio, the annual rate of secret surveillance orders by federal and state courts combined could easily exceed half a million.  Admittedly this is a guess; no one truly knows, least of all our lawmakers in Congress.  That is precisely the problem.


Some interesting (or at least amusing) speculation.
Panama Papers Source Offers to Aid Inquiries if Exempt From Punishment
The anonymous source behind the huge leak of documents known as the Panama Papers has offered to aid law enforcement officials in prosecutions related to offshore money laundering and tax evasion, but only if assured of protection from punishment.
“Legitimate whistle-blowers who expose unquestionable wrongdoing, whether insiders or outsiders, deserve immunity from government retribution,” the source, who has still not revealed a name or nationality, said in a statement issued Thursday night.


This should amuse my researching students.
OSoMe: The IUNI observatory on social media
by Sabrina I. Pacifici on
OSoMe: The IUNI observatory on social media. PeerJ Preprints 4:e2008v1 https://doi.org/10.7287/peerj.preprints.2008v1
“The study of social phenomena is becoming increasingly reliant on big data from online social networks.  Broad access to social media data, however, requires software development skills that not all researchers possess.  Here we present the IUNI Observatory on Social Media, an open analytics platform designed to facilitate computational social science.  The system leverages a historical, ongoing collection of over 70 billion public messages from Twitter.  We illustrate a number of interactive open-source tools to retrieve, visualize, and analyze derived data from this collection.  The Observatory, now available at osome.iuni.iu.edu, is the result of a large, six-year collaborative effort coordinated by the Indiana University Network Science Institute.”


Wisdom from my favorite statistical website.  (I think #4 will become critical)
The Four Things I Learned From The Donald Trump Primary
1. Don’t rule out the ahistorical when there’s little history.
2. Take a nuanced view of the polls.
3. Maybe favorability ratings aren’t as hard to change as we thought.
4. Don’t assume the party knows what it’s doing.
Let’s give some credit to Trump himself!  No, I don’t think that Trump is a strategic and tactical mastermind who planned every move he made, or even that every move was successful.  On the whole, though, more of what he did worked than didn’t work.  Trump generated a ton of free media coverage; that helped him.  He was willing to challenge Republican orthodoxy; that, at the very least, didn’t hurt him.  I don’t know whether he’s built a new political coalition or the Trump phenomenon is sui generis, but whatever the guy did, it worked.


Universities developing cybersecurity degrees to fill jobs gap
If they want to continue to protect our nation’s most valuable data from cyber-attacks, leading security practitioners need to look to the future of the security industry and develop ways to grow the talent needed to fill the looming jobs gap.


My Saturday sillies.
Hack Education Weekly News
   The Justice Department has warned North Carolina that its new anti-trans bathroom law violates the Civil Rights Act.  According to the AP, “North Carolina’s prized public universities could be the biggest losers as state leaders defend a new law limiting the rights of LGBT people.  The 17-university system, which includes the University of North Carolina at Chapel Hill and North Carolina State University as well several historically black colleges, risks losing more than $1.4 billion in federal funds if the Republicans who run the Legislature don’t reverse the law.  The U.S. Justice Department wants an answer by the end of business on Monday.”  The new head of the UNC system, “Margaret Spellings Is Caught Between Her State and the Federal Government.  Now What?” asks The Chronicle of Higher Education.
   Via Inside Higher Ed: “The Federal Trade Commission announced Thursday that the operators of Gigats.com agreed to settle deception charges.  Gigats.com is an education lead-generation company based in Orlando, Fla., that claims to prescreen job applicants for employers. However, the company was instead gathering information for for-profit colleges and career training programs, according to the FTC.”


For my Computer Security and Ethical Hacking students.
Pay What You Want for the Ethical Hacker and Pentester Pro Learning Bundle
   Anyone can start learning them with the Ethical Hacker and Pentester Pro Bundle at MakeUseOf Deals.
It combines nine high-quality video courses, and you can pay what you want for the tuition.  Read on to find out more.
   All of these courses come with lifetime access, and you can stream the lessons on desktop and mobile devices.  Best of all, you can claim a certificate of completion to put on your CV when you master each subject.
   You can name your price on the last two courses in this deal, but to unlock the full bundle, you simply need to beat the average price paid.  These nine courses are normally worth $1,431 put together, so grab the bundle now to enjoy a huge markdown!

Friday, May 06, 2016

Surely no bank is still using Windows XP? 
New Trojan Targets Banks in US, Mexico
   The Trojan, written in .NET apparently by Spanish-speaking developers, caught the attention of researchers because it relies on popular tools such as Fiddler, an HTTP debugging proxy server application, and Json.NET, a high-performance JSON framework for .NET.
The malware is delivered using an installer named “curp.pdf.exe” that is served on several compromised websites.  Once executed, the installer downloads three files to the Windows system directory: the main payload (syswow.exe), a Fiddler DLL file (FiddlerCore3dot5.dll), and a Json.Net DLL file (Newtonsoft.Json.dll).  The main payload is then executed and the installer terminates itself.
..   If the infected machine is running Windows XP or Windows Server 2003, the malware creates a registry entry for persistence, downloads a configuration file, and launches the Fiddler proxy engine.  For other Windows versions, the threat doesn’t create a registry entry, and it starts the proxy engine only after installing a Fiddler-generated root certificate.
Once it’s installed on a device, the malware collects system information and sends it back to its command and control (C&C) server, which responds with a configuration file containing different C&C locations and other instructions.  Json.NET is used to parse the server’s response and save it in an XML file.  This file contains the list of domains targeted by the malware — when users visit these domains, they are redirected to phishing websites designed to trick them into handing over their information.


A small local problem?
Kieran Nicholson reports:
State investigators are looking into a database breach at the Colorado Department of Transportation which could lead to identity thefts.
The breach of the Disadvantaged Business Enterprise program with CDOT was discovered recently and has been reported to the Colorado Bureau of Investigation, said Amy Ford, a CDOT spokeswoman.
[…]
“A probationary employee, who worked at CDOT from January 2016 to April 2016 and had access to confidential tax returns of DBE…firms, had been using personal information for improper purposes,” the notification letter, sent Wednesday, said.
Read more on Denver Post.


One way to control your music library? 
Apple Stole My Music. No, Seriously
“The software is functioning as intended,” said Amber.
“Wait,” I asked, “so it’s supposed to delete my personal files from my internal hard drive without asking my permission?”
“Yes,” she replied
   What Amber explained was exactly what I’d feared: through the Apple Music subscription, which I had, Apple now deletes files from its users’ computers.  When I signed up for Apple Music, iTunes evaluated my massive collection of Mp3s and WAV files, scanned Apple’s database for what it considered matches, then removed the original files from my internal hard drive.  REMOVED them.  Deleted.  If Apple Music saw a file it didn’t recognize—which came up often, since I’m a freelance composer and have many music files that I created myself—it would then download it to Apple’s database, delete it from my hard drive, and serve it back to me when I wanted to listen, just like it would with my other music files it had deleted.

(Related) I will have to warn my students.
Apple Music’s new student membership option discounts the service by 50%
Amid news that Apple Music is getting a makeover come this summer, Apple today launched a new plan to boost subscribers to its streaming music service and competitor to Spotify, SoundCloud, Tidal and others.  It’s introducing an Apple Music student plan which will discount the service by 50 percent for those who are enrolled in an eligible college or university.
   The student membership is rolling out now in the available markets.


Think about those little secondary issues?
Cheryl Clark reports:
When Sharp Grossmont Hospital officials realized anesthesia drugs were disappearing from surgery carts, they turned to video surveillance to catch those responsible.  In the process, they also captured many images of women undergoing surgery.
The video surveillance has raised questions about patient privacy and how well the hospital managed its storage of dangerous drugs.
Read more on KPBS.


Useful backgrounder?  Something our App students could build? 
How Shops Track You Using Your Smartphone


Coming soon to a law firm near you?
Gabe Friedman reports:
The privacy focused class-action law firm Edelson P.C. announced it has filed a federal class-action under seal that targets a Chicago-based regional law firm for data security holes.
On Thursday morning, name partner Jay Edelson tweeted that he had filed a motion to unseal the complaint against the unnamed firm.
[…]
In an interview with Big Law Business in March, Edelson explained that his firm had conducted a year-long investigation and identified 15 major law firms with inadequate cybersecurity.  He said his firm planned to file a series of lawsuits that target data security vulnerabilities at law firms on behalf of firm clients who have concerns about how their data is being protected.
Read more on Bloomberg BNA.
I’m hard-pressed to see how any such civil suit could prevail if there’s been no actual hack or data compromise of the defendants’ systems, but the FTC could sure as hell investigate or take action if infosecurity is that bad.
Either way, this will be one to watch.  If nothing else, if the lawsuit is unsealed, this could become a name and shame situation to get law firms off the dime to bring their A game on security.


Will this impact our student portal?  Possibly.
Joey Bunch reports:
A bill to protect students’ online privacy while they are doing their school work is on its way to the governor’s desk to be signed into law.
The Colorado House gave it final passage Thursday with a 65-0 vote.  House Bill 1423 would prevent educational software and app makers from collecting any data that can be linked directly back to an individual student.
Read more on Denver Post.

(Related)  Same question.  Different state.
Rep. Cristin McCarthy Vahey (D-Fairfield) praised passage of legislation that would protect student privacy by imposing certain restrictions on the use and sharing of student data.  HB 5469, AN ACT CONCERNING STUDENT DATA PRIVACY, was passed by the Senate Wednesday evening.  The bill now goes to the Governor’s desk.
The legislation would restrict how student information may be used by contractors, consultants, and operators of websites, online services, and mobile applications for schools.  Companies would be required to specify how they will secure student data and would be prohibited from using student data for advertising unless authorized by the contract.
Read more on Fairfield Sun.


Lacking demonstrable intelligence themselves (real or artificial) it amazes me that politicians are addressing these issues.  Were they frightened by the Terminator movie? 
White House worries about bad A.I. coding
   President Barack Obama's administration released a report this week that examines the problem associated with poorly designed systems that, increasingly, are being used in automated decision making.
   A second effort looks at our algorithmic future through a series of four workshops held across the U.S. to examine A.I.'s impact on society.
   The U.S. will produce an A.I. report after it holds workshops beginning May 24 in Seattle.  That will be followed by meetings in Washington, Pittsburgh and New York City in July.


For some old school types. 
How to Get RSS Feed Updates Straight to Your Email Inbox
Maybe it’d be better to receive those RSS updates as emails.
Fortunately, this is possible!  You’ll need to know how to use IFTTT, which is a lovely web service that can perform all kinds of actions based on certain triggers.  In our case, whenever our RSS feed updates, we want IFTTT to send it to us as email.


Good news for the employability of my Computer Security students?
After ISIS, Americans Fear Cyberattacks Most


Perfect timing.  Today’s Computer Security lecture is on Networks.
Interop: 12 killer (and free) tools for network engineers
Visibility is key to troubleshooting network woes, but getting such access can be expensive.  To help out, a veteran networking pro shared with attendees of the Interop conference in Las Vegas his list of a dozen mostly free “killer” tools.


A real concern.  Likely to have a serious negative impact no matter who wins. 
Americans’ Distaste For Both Trump And Clinton Is Record-Breaking


I can predict which if my students will become this employee!