Friday, January 15, 2010
Scans sans naughty-bits - maybe
Of course, spending millions of dollars on a technology that may not even address the problem it is supposed to solve is equally negligent. But I suppose I shouldn't be too surprised. We did it after 9/11 and we'll probably do it after the next successfull attack.
Thursday, January 14, 2010
Contactless card breach
It may not seem like a big deal, but its important to know how the switch happened. It's unlikely that the switch was caused by the cards. I've never liked RFID enhanced cards, be they ID's or credit cards. But this time I'm fairly certain the card is not the culprit. It is most likely either human error - which seems to be the official line - or a computer error. I'm sure the hope is that human error really is to blame. Then the solution is training or replacement. If it's computer error, it might not be fixable until the next system upgrade - and that could be bad news. System upgrades might be years down the road. Meanwhile, your metaphorical tail is left swingin in the breeze.
As we see more of these stories, will we come to realize that we would have been wiser to slow down and make sure things work the way we think they will before becoming very dependent on them for our wellbeing?
Wednesday, January 13, 2010
Eternal Ignorance
The original poster (OP) was looking for cheap software:
[caption id="attachment_640" align="alignnone" width="419" caption="Seeking deals in spam"]
Everything about this deal screams "SCAM". Others agreed.
[caption id="attachment_643" align="alignnone" width="466" caption="Pointing out his error"]
OP disagreed with everyone (there were many more, "Don't Do it!" posts.
[caption id="attachment_656" align="alignnone" width="432" caption="Does he really believe this?"]
Did anyone actually read the first graphic? Do you remember him saying his VISA card was compromised in December, and he has no idea why.
I finally tried to explain why he was wrong. It didn't do any good.
[caption id="attachment_661" align="alignnone" width="600" caption="I weigh in"]
The moderator killed the thread, but not before it was obvious that, no matter the risk, this guy was going to try to buy from spammers. Of course, part of the problem was his definition of spam. To him, any mention of a product in an electronic medium is spam. I know this because he used a thread about the Magic Jack internet phone service as an example of legitimate spam.
The rest of his problem was he didn't want to be educated. He asked for advice, then completely disregarded it. I'm sure one day he will be wondering how somebody found out enough about him to rack up hundreds of thousands of dollars worth of debt. Or maybe only tens of thousands. Either way, he could have gone a long way toward avoiding it by just not using spam to shop with.
Oh, and that link to check websites is: http://www.siteadvisor.com/
Enter the URL of the site you want to check in the box on the right:
[caption id="attachment_664" align="alignnone" width="600" caption="One useful tool"]
Of course, if you are using current versions of most browsers, many have built in sitecheckers. But it's hard to overtest these things.
Hope this was helpful. Keep your eyes open and keep safe
Tuesday, January 12, 2010
Eternal Vigilance!
Once, years ago I almost fell for exactly this type of scam. I caught myself in time, but it was a near thing. Remember that if your credit card, bank, or anyone else who has enough information to pretend to be you ever calls asking for you to prove who you are, hang up and get the number off the back of your credit card or out of the phone book and call them. If they still say your information has been stolen, you can take the appropriate steps. But never give personally identifying information in direct response to a phone call, email, or mail.
Cartoon used with permission.
Monday, January 11, 2010
Airport romance never pays
But I watched the video of the his transgression (well, I watched the 6 minute unedited video), and it is obvious that he did know what he was doing was wrong. He waited around for several minutes, even after the guard asked him to move on. And I would think his girlfriend should be held responsible as well. She waited until the security guard was gone and came back for her boyfriend, then walked with him to the 'secure area.'
The guard is also culpable in this fiasco. He should not have left his post unattended. If he had some serious business he needed to attend to he should have called for relief.
How much trouble should they be in? I'm not sure. Unless he's been an exemplary employee for a long time, I would strongly recommend firing the guard. There is too much relying on his vigilance to let a slip like that slide. The lovebirds? I'm a little torn. I think they need more severe penalties than the crime he is being charged with carries (she isn't being held responsible, AFAIK), but I don't really want to ruin to lives over what might have gone entirely unnoticed a few short weeks ago.
That's the kicker, of course. And perhaps the damning bit that's missing. These two have been carrying on a long distance relationship for a year or so. How many times have they played exactly this scenario when she visits? Or when he visits? As I said earlier, he was obviously waiting, and it appears that she was, too. It looked like they had either done this many times, or planned it very carefully.
His reaction when he found out the police were at his house is also interesting. Almost like he was expecting it eventually. According to a story in the NY Daily News, he said, "You got me." It doesn't sound like there was any surprise at all. That just leaves the question, why is he the only one being charged?
Why does the girl go free when she went to get him - knowing he wasn't supposed to cross the secure barrier? The guard is facing disciplinary action, the boyfriend is being charged, however lightly, and the girlfriend walks. Doesn't sound right to me.
Sunday, January 10, 2010
Full body scans: Trading privacy for illusion of security?
In the past she has been against full body scanners and profiling in airports. Then she sat six seats in front of a young Nigerian man on Christmas day, 2009, and she remembers the sound of the detonator, the flash, and the terrorist being led down the aisle with no clothes on below the waste.
Her experience that day changed her view of how airport security should be handled. In an article in the Detroit Free Press she says: "I'm always standing up for rights and privacy concerns, but now I hope that body scans will be mandatory," Aref, 27, said Wednesday. "Balanced against national security, it's worth the invasion of privacy. And I acknowledge the fact that there has to be attention paid to Muslims."
Coming close to death is a life changing experience, but often after some time has passed and the fear moves further away people revert to their previous opinions and attitudes. Only time will tell us if Miss Aref will continue to favor body scanners and profiling. But her story, moving as it may be, is just another emotional appeal, and emotional appeals are poor things to build policy on. Granted emotional appeals are the stuff that shapes public opinion, but they're still bad for building policy.
One of the more interesting quotes on full body scanning and privacy came from an article in the Washington Post on January 4, 2009. It was about the images generated. It said,
"They're virtual. Passengers walk through the machines fully clothed; the resulting image appears on a monitor in a separate room and conceals passengers' faces and sensitive areas."
Correct me if I'm wrong, but I believe "sensitive areas" refers to the breasts and groin on women and the groin on men. If the groin area is concealed, how are we protected from an underwear bomb?
Here are a few other quotes from the same article:
"It covers up the dirty bits," said James Carafano, a homeland security expert at the conservative Heritage Foundation.
"I don't think it's any different than if you go to the beach and put on a bikini," said Brandon Macsata, who started the Association for Airline Passenger Rights.
"It covers up the dirty bits," and it's the same as a bikini ... that sounds to me like the primary area of concealment - the crotch, will be concealed by software in the scanner. That makes it kind of hard for the human viewing the image to see if anythings been added to the area.
I've read that the full body scanners are not designed to detect the types of explosives used in most terrorist attacks. According to an article at newsdaily.com, Dutch Interior Minister Guusje ter Horst said that there is no 100% gaurantee that the new detectors would have caught the underwear bomber.
Adding fuel to the fire - or not, since there's been almost no mention of it anywhere else, the Independent ran an article, Are planned airport scanners just a scam? on January 3rd reporting that British research into full body scanners showed that they would not detect an explosive of the type used by the crotchbomber. According the to article,
"But Ben Wallace, the Conservative MP, who was formerly involved in a project by a leading British defence research firm to develop the scanners for airport use, said trials had shown that such low-density materials went undetected.
Tests by scientists in the team at Qinetiq, which Mr Wallace advised before he became an MP in 2005, showed the millimetre-wave scanners picked up shrapnel and heavy wax and metal, but plastic, chemicals and liquids were missed. "
Other interesting claims are made. Supposedly American experts have stated that traditional airport pat downs wouldn't have stopped Mr. Abdulmutallab from getting on the plane. There's a really simple reason for it. In the U.S. the security people aren't allowed to frisk sensitive areas. Not that frisking those areas will stop everyone. I was with a friend going into "The Who's Last" concert in Dallas in 1983...I think that was the concert...anyway, they were frisking everyone. My friend had a recorder with the mike in his pants. The officer hit the mike,
"What's that!"
"My d**k."
The officer got a surprised look on his face and waved him through. I still wonder if anyone managed to get something more dangerous in that way?
For me the scanner issue isn't really about privacy, although that is important. It's really about using unproven technology without making sure the measures we already have in place are working. To be honest they usually do work, but we need a lot of improvement. And before we spend $165 million on scanners we should spend a few hundred thousand making sure they do what is claimed.
Does anyone remember the bomb sniffing machines they spent millions on after 911? The machines that are mostly decommissioned because they didn't work as claimed, and spent more time broken than working? We don't want that to happen again - but it's probably already to late, because they've already ordered them. And they may not even detect the explosive they're being bought to protect us from.
The more things change the more they stay the same.
[Edited at 12:21 to improve headline by Bert]
Saturday, January 9, 2010
Well, Duh...
Don't get me wrong, the headline is accurate, but to anyone who's been watching these things, and I suspect many who haven't, that's kind of like saying fire is hot. Apparently 1 in 6 people in Massachusetts have been victim of identity theft, and that is what brought this problem to their attention.
1 in 6 people. With the number and scope of data breaches that have happened just in the last two years it's a little surprising it's not 1 in 4 or even 1 in 3. I know 2 people whose identities may have been compromised, and 1 whose identity was most definitely stolen. Identity theft is a big problem, I'm just surprised it took Credit.com this long to realize it.
Friday, January 8, 2010
Obama shoulders responsibility
Thursday, January 7, 2010
Bono's hurting because of music pirates?
There are a few things he is ignoring, however. There is a thriving indy music industry based on internet distribution. Many young artists have started their careers using the internet and are quite happy as regional sensations. Other types of content providers have discovered that carefully managed free distribution increases sales instead of decreasing them. Baen books started an experiment in 1999 or 2000. Instead of trying to stop internet sharing, they embraced it. They put some of the older titles of authors who were willing to give away a book or two online as free downloads. They're still doing it today. I'll give you three guesses why.
If you are a fan of fantasy and science fiction, check out the Baen Free Library. And see how intelligence and forward thinking handle new "problems". And after picking up a book or two by an author you've never read before, if you like it, buy something else by the same author. After all, he was nice enough to give you an enjoyable free read, and he's got bills the same as you and I.
Wednesday, January 6, 2010
Facebook Frightened?
Another service, Power.com, allows you to access many social networking sites from one, making social networking easier. Again, Facebook is taking legal action. I can understand this one. Facebook makes money from ads. No visits to your Facebook page, no ads displayed or clicked, no money.
Last, we have Suicide Machine, a service which will completely remove you from Facebook. You cannot simply log back in, you will have to create a whole new Facebook profile after using Suicide Machine. Facebook is blocking the Suicide Machine IP, so right now the service isn't available.
The amusing (sic) thing about Facebooks reaction to these services is that they claim to be doing it out of concern for users privacy. They obviously think being concerned with privacy = being soft in the head. How can my choosing to use one of these services be more hazardous to my privacy than Facebook making the default "privacy" setting for everything "Share with the world"?
Double standards. Gotta luv 'em.
Monday, January 4, 2010
Full body scan - shield or show?
Privacy groups are against the full body scanners, saying they are invasive and demeaning. Flyersrights.org and the ACLU are both against the scanners. In a release on its website the ACLU says:
"We should be focusing on evidence-based, targeted and narrowly tailored investigations based on individualized suspicion, which would be both more consistent with our values and more effective than diverting resources to a system of mass suspicion," said Michael German, national security policy counsel with the ACLU Washington Legislative Office and a former FBI agent. "Overbroad policies such as racial profiling and invasive body scanning for all travelers not only violate our rights and values, they also waste valuable resources and divert attention from real threats."
I have to admit, I lean more toward the ACLU position. Yes, I know that a full body scan might have caught the explosive in the bombers undies - although there are claims that the bomb would have made it through a scanner. But that isn't really the issue. The issue is that we don't need to add any new security measures, we need to properly use the ones we have.
I can't say it enough. The system is broken. People are saying, "We need full body scans to keep anyone else from getting through." No, we need to start making full use of the intel we're gathering. Bush dropped the ball when he didn't follow through on his order that the U. S. intelligence agencies, FBI, CIA, NSA, etc. share information, and Obama is following his example.
The point in this is not that a scanner would have stopped this guy before he could turn himself into a eunich. It is that he should never have made it to the point where he would have to go through a scanner. We had more than enough info to forbid this guy to get on a plane. He was on a watch list, then his father notified the U.S. Embassy that he had been radicalized and might do something dangerous. That would have put him in a "watch very closely" list for me. Not for the U.S. government. According to examiner.com:
"On November 20th the embassy sent a "Visas Viper cable" to the State Department which detailed the father's warning. The information was then given to the Counter-Terrorism Center in Washington D.C. which ruled that their was insufficient information present to revoke Mutallab's visa."
While people are screaming for more measures to limit our freedoms and take away our rights, the real problem is that the information we are gathering has everything we need to stop these terrorists, if we would only use it. Putting scanners in the mix will not make us safer, it will only be one more layer of false security.
No matter what methods we devise to detect explosives at the airport, our first and best line of defense will always be gathering data to stop terrorists before they can get a ticket. And the evidence shows we're doing a good job of gathering it, we just aren't using what we're getting.
Sunday, January 3, 2010
Rockyou sue
I suppose it's not too surprising that the RockYou data breach is ranked as one of the top 5 (or should that be bottom5?) data breaches of 2009 by PCWorld, but the sad thing is that in today's day and age they should have been the worst. PCWorld didn't actually rank the top 5, just picked the worst 5 and listing them. But several qualify as worse, either for the number of people affected or the length of time it took to report the breach. One company took six months to notify anyone of a data breach. As long as companjies try to stall like that, notification laws will be needed.
Saturday, January 2, 2010
What is cloud computing?
That seems pretty harmless. But protecting email is one thing. Protecting major financial, medical, or other sensitive data is quite another. And we have problems protecting the email. There are ways of analyzing memory usage to steal data when two programs are running on the same computer and operating system. Theoretically it should work for two virtual computers running on the same server, but with dozens or hundreds of them running on a server, it was believed that actually isolating useful data that way was very unlikely.
Technology Review ran a story on cloud security called "Security in the Ether". One of the first things it talked about was three researchers who had shown that it is possible to monitor virtual machines the same way. They did their research on Amazon's cloud servers, but Amazon says they have taken steps to make sure that data can't be stolen by that method anymore.
But that isn't the only concern about cloud computing. There are concerns over downtime, application security, data security, the human factor. Perhaps you've heard that the more people who know a secret, the less likely it is to remain secret? There's a cloud computing corollary. The more people in the cloud, the more likely there will be a breach. And cloud computing is only economical if lots of people are using it.
Friday, January 1, 2010
"The Cloud" is easy to fall through
In the NY Times "Bits" blog, Nick Bilton asks if your data is safe in the cloud. And with good reason. He's just read an article by David Talbot that examines what types of problems exist in cloud security. He finds two researchers whose work shows that it isn't all that difficult to gather data from the cloud. The article goes on to ask a lot more questions, but the gist is that data in the cloud can be very easy to access. The risks are high, and that data will be compromised is almost certain. Before we leap willy-nilly into this thing called cloud computing, it would be a good idea to understand it a lot better, and work on it's drawbacks. But it doesn't look like that's on anyone's agenda, and some things are going to have to go radically wrong before it gets put there.
Tomorrow I'll be looking at what exactly cloud computing and how it works - and how that effects your data in the cloud.
The obligatory New Years Prediction
Does this mean that our state governments are trusting Google with sensitive information? Not necessarily. In fact, probably not. But it does mean that there is a lot of information being entrusted to Google that wasn't just a few months ago. And there is no way to ensure that sensitive data won't be sent through Googles servers, and that brings us to my prediction: This year there will be a data breach of unrivaled severity, and it will be through Googles cloud computing services. It will massively slow down the adoption of SAAS (software as a service) as companies and individuals realize the security models we have today are not suited to the cloud. It will strengthen Microsofts position (supposedly threatened by Google Docs) in the enterprise as organizations trip over each other to get away from Google Docs and back to Microsoft.
Such a breach could be a good thing in the long run if it makes us look at cloud computing and reexamine our security paradigms in light of the new and unique requirements of protecting data in the cloud. But depending on what is breached, in the short term it could be very ugly.
Thursday, December 31, 2009
"Reasonable Expectation" of email privacy extended to workplace
* DOJ's computer use policy did not prohibit personal use of the DOJ email system.
* The employee took steps to delete the privileged emails promptly.
* The employee was not aware that DOJ's system retained a copy of the emails after he had deleted them.
This is a good thing, but it has downside. If you're employers make it clear that company policy prohibits personal use of company email, absolutely any email sent through your company is fair game. If you don't delete the emails promptly, they could become fair game, even if there is no policy against personal use of email.
The best way to handle the pitfalls of using company email to send personal messages is, don't, but if you have to, this gives you some possibilty of keeping the messages private.
Wednesday, December 30, 2009
He should work for Homeland Security
Tuesday, December 29, 2009
Transportation Insecurity revisited
HIS OWN FATHER REPORTED HE MIGHT BE DANGEROUS!!!!!!!
I could understand not placing much weight on allegations by a business rival, former lover, or something like that, but this was the mans father. If that doesn't warrant extra consideration, what does it take, setting off a bomb?
Oh, wait, that is what it took.
We don't need more manpower for our security. We probably don't need more money. We need fewer people but with more brains.
UPDATE: Two of the Yemeni Al Qaeda leaders responsible for this attack were released from Guantánamo Bay in 2007. They released into Saudi custody, where they underwent (unsuccessful?) rehabilitation. Is closing it Gitmo really a good idea, Mr. President?
Update II: President Obama has recognized the danger. In a statement reported by the AP (via yahoo news) he says,
"It now appears that weeks ago this information was passed to a component of our intelligence community but was not effectively distributed so as to get the suspect's name on a no-fly list. Even without this one report, there were bits of information available within the intelligence community that could have and should have been pieced together."
Again, the problem isn't lack of information, it's communication between agencies and departments within agencies. 8+ years later, and we're still fighting this problem.
[edited at 8:10 am with new information by Bert]
[edited again at 5:05 pm to include Obama quote]
Monday, December 28, 2009
Do you have the skills?
The governments inability to pay competitive salaries is hurting our ability to protect important data. The problem isn't being able to figure out how the bad guys might get at it, it's in figuring out how to close the holes we can find. And the ability to respond to a breach varies widely from department to department. The State Department has well equipped and trained staff who can respond quickly, determine the attack vector, and plug the hole, then analyze and determine was to prevent similar attacks in the future. The Commerce Department, which handles data every bit as sensitive as State, lacks similar equipment and training. Both suffered serious breaches. State was able to determine how it was done and prevent data theft. Commerce was never able to determine how the attack was pulled off, although they say no data was compromised. But they still replaced hundreds of workstations.
This is a serious problem. Organized crime and hostile governments (note: in this context, all other governments are hostile) are marshalling major resources at cracking the security in U.S. government and private corporate facilities. It is not the governments place to protect private companies (nor should it be), it is of paramount importance that government agencies are able to keep data safe from prying eyes. Their databases contain information that could do irreparable damage to our ability to compete in the marketplace. They contain data on research in all types of technology that we would not want falling into enemy, and maybe not even friendly, hands. If there is any one area we cannot afford for our government to skimp on, it is national security, and part of that is making sure that we have the best cybersecurity experts providing the best policies and procedures for preventing breaches, and when they do occur, detecting, plugging, and cleaning up after quickly and efficiently.
Thursday, December 24, 2009
Merry Christmas, everyone
Wednesday, December 23, 2009
I guess he's never heard of blinds...
I'm no lawyer, but when people see you from the street it seems to me that you should either be putting on clothes or buying drapes. And you definitely shouldn't be singing loudly or rattling things around. And I almost hope an appeals court gives him some jail time and a fine, because he obviously needs to be educated on how to respond to a lenient court.
Tuesday, December 22, 2009
Twitter hacked via email
Monday, December 21, 2009
Netflix: Outing the Gay and Lesbian community since 2006.
It seems the problem stems from a contest Netflix launched in 2006. It released two sets of data for contestants to manipulate. The goal was for someone to design an algorithm that would be 10% better at predicting the reviews a person would make for other movies based on the review they gave movie(s) in the data sets. The problem is, video rental data is legally among the most protected in the U.S. The allegation is that by releasing the "anonymized" data Netflix violated those laws. One of the plaintiffs is an in-the-closet lesbian mother who fears that the data released could out her and have bad effects on her ability to support her family. She has good reason to be concerned. The Netflix context took place a few months after "anonymized" data from AOL was used by reporters to identify AOL users. So it really wasn't very surprising that just a few weeks after Netflix started it's contest researchers were able to identify Netflix users - along with their political leanings and sexual orientation. Oops.
The second part of the lawsuit seeks to prevent the launch of the next contest. Living proof that stupidity is a life long problem (and corporations can live a long time), Netflix wants to provide more "anonymized" data this time. And that data will include zip code, age, and gender. When you combine that with the movie ratings and ID numbers it will be more than enough data to ID Netflix customers. Again.
The bad thing about all of this...well, one of the bad things, is that it has been obvious for years that the traditional 'scrubbing' of data is no longer adequate for anonymizing. Mark Dixon looks into the history of re-identifying data and sees that if data continues to be handled the way it is now, every time any company releases anonymized data they are releasing re-identifiable data.
Unless you are up for canonization by the Catholic Church, that should scare the bejeezus out of you.
It seems the problem stems from a contest Netflix launched in 2006. It released two sets of data for contestants to manipulate. The goal was for someone to design an algorithm that would be 10% better at predicting the reviews a person would make for other movies based on the review they gave movie(s) in the data sets. The problem is, video rental data is legally among the most protected in the U.S. The allegation is that by releasing the "anonymized" data Netflix violated those laws. One of the plaintiffs is an in-the-closet lesbian mother who fears that the data released could out her and have bad effects on her ability to support her family. She has good reason to be concerned. The Netflix context took place a few months after "anonymized" data from AOL was used by reporters to identify AOL users. So it really wasn't very surprising that just a few weeks after Netflix started it's contest researchers were able to identify Netflix users - along with their political leanings and sexual orientation. Oops.
The second part of the lawsuit seeks to prevent the launch of the next contest. Living proof that stupidity is a life long problem (and corporations can live a long time), Netflix wants to provide more "anonymized" data this time. And that data will include zip code, age, and gender. When you combine that with the movie ratings and ID numbers it will be more than enough data to ID Netflix customers. Again.
The bad thing about all of this...well, one of the bad things, is that it has been obvious for years that the traditional 'scrubbing' of data is no longer adequate for anonymizing. Mark Dixon looks into the history of re-identifying data and sees that if data continues to be handled the way it is now, every time any company releases anonymized data they are releasing re-identifiable data.
Unless you are a very unusual individual, that should scare the bejeezus out of you.
Saturday, December 19, 2009
Catching phish
Phishing - the art of crafting a bogus email in such a way that significant numbers of people will click on links inside it, even when they should know the email did not come from the person or group it claims to represent.
First, lets take a look at the information you see when you first glance at the email:
- The simple things to look for
This one is actually pretty obvious. I've never worked for Schlumberger or belonged to their employee credit union (they do have one), so I can safely assume I have no account data to verify. But if that wasn't enough, looking at the actual 'from' address. The email is supposedly from Schlumberger, but the email address is rrluee@accounts.net. Unlikely to be an address used by Schlumberger. Additionally, the 'to' address isn't my address, but service@orange.fr.
That's all good in a case like this, but what if it's not so obvious? Phishers can forge links, 'to' and 'from' headers, and even the golden 'security lock' that's supposed to tell you when you're connected to a secure site. What if you get emails claiming to be from eBay, or PayPal that don't seem right, but look really good? There are a couple of rules to go by in a situation like that:
First, if they are asking you to click a link to verify an account, they are probably bogus.
Second, never click a link in an email that is asking you to verify anything. Look the companies number up and call them or look up their website in a search engine, but don't use the links or any other contact information given in an email.
Third, if you do click on a link, check the URL in your browser. If you were going to Paypal and get http://www.getstuff.com/paypal you're probably on a bogus site.
I hope this was helpful. Remember, if they want you to provide information via email or a link from email, be wary.
Friday, December 18, 2009
Privacy Rx: Never answer "account verification" emails
Well this is a short blurb today, but tomorrow we will go over a phishing email and see how you can detect one.
Who's watching the watchers? The Insurgents.
What confuses me is that the drone feeds are not encrypted. I know military intelligence is supposed to be an oxymoron, but even if interception is unlikely you have to expect it to happen and take steps to either prevent it or make the intercepted data worthless. By strong encryption, for example. So this statement boggles my mind:
The U.S. government has known about the flaw since the U.S. campaign in Bosnia in the 1990s, current and former officials said. But the Pentagon assumed local adversaries wouldn't know how to exploit it, the officials said.
Ok. You've known about this for more than 10 years, but assumed that the local yokels could not, and would never be able to figure out how to capture your streaming data. Now that's "military intelligence."
To be fair, adding encryption isn't like installing some software, and there are concerns that encryption might cause difficulties in rapid interpretation of the feed data, and in sharing data between services. And that's enough fairness. They've known about the vulnerability for 10+ years, and not only have you not fixed it in the current drone model, it's still part of the design in the new model that is about to go into production. I can see the difficulties of modifying the current design, but to not put encryption on the new model boggles the mind. Hopefully, now that we know people are accessing the drone feeds the new drones will be updated to have encryption.
Thursday, December 17, 2009
rockyou stoned, Facebook infiltrated
Our users' privacy and data security have always been a priority for RockYou and we strive to keep them secure. Our users have confidence in our services and we will continue to ensure that confidence is deserved.
Sounds very nice and up-front. And I suppose it is the truth, since it only addresses the services, not the security of the services. Historically, rockyou has been a lot more concerned with talking about how concerned they are with privacy and security than they have been with actually providing it. In September of 2008 they embarrassed and outraged hundreds of companies that produce Facebook apps by cc'ing them all on an email. They were very apologetic:
On the behalf of RockYou, I want to apologize to all of our publishers for the slip. While it was unintended, it was a material mistake. We take privacy of all our partners very seriously and have reviewed and corrected the process that enabled this. We continue to work hard to maximize results but its apparent we will also need to work even harder to regain and maintain trust. For those of you affected, please email me directly with any questions, issues or concerns. My email is ro@rockyou.com (ro at rockyou.com – yes, i’m willing to share in the pain).
Very nice, and very full of bovine excrement. They did the same thing on November 25th of 2008, and again in Januarly 2009.
As if it's not bad enough to have one of the companies heavily involved with Facebook apps proving that, while ignorance is curable, stupidity is a life long problem, Facebook is being besieged by a new variant of the Koobface worm. Hopefully by now (it was announced a week ago) all of the anti-virus vendors have updated their definitions - if yours hasn't, get a different A/V package. Hopefully all Facebook users have up to date anti-virus. Yeah, right. I'll believe that when I hit the lotto 3 weeks running.
The important details are that the virus is spread by placing a "Christmas video" on your wall. When you click on the video it loads "koobface.GK" and installs it. Then it pops up a captcha for you to solve. It won't go away until you solve the captcha, even if you shutdown and restart. The captcha is actually the last step in creating a new Facebook account, which proceeds to spread the worm.
By their nature Facebook, Myspace, LinkedIn, etc. are high risk, dangerous places. They encourage blind trust in the site, and in other users. Unfortunately that trust plays right into the hands of the bad guys. It is best to put as litte information about yourself as possible and treat links on your wall the way you would treat links in email from people you don't know. Don't "Friend" with someone just because they know someone you do, and use as few apps as possible so you don't sell your friends out. Social networks are fun and a great way to stay in touch with old friends, but like a bazarr in Baghdad, it pays to keep your guard up while you're there.
Wednesday, December 16, 2009
Data Breach Bill passes House
This bit of news got lost in the face of Facebook changes and Google CEO pronouncements. It deserves more attention, and after I've read more about it I will come back to it. Since the bill is going to the Senate, now would be a good time to contact your senator and provide your thoughts on data breach notification.
Tuesday, December 15, 2009
Google CEO scoffs at privacy
Asa Dotzler, Mozilla's chief of community development feels the same way. In his blog he tells people to add Bing to Firefox. You know if Mozilla, one of the opponents Microsoft couldn't quite kill, is suggesting a Microsoft product they have serious concerns. The add-on he links to is here. He also says that the Bing privacy policy is better than Googles, but I don't really see a whole lot of difference on a quick read of both.
I'm sure I'll keep using Google search, if only because I use multiple search engines already. The webs a big place, and most search engines hit spots that others don't - even if it only shows up 4 or 5 pages down - yes, I often go that far down in search results.
The truth is, as much as I don't like Mr. Schmidt's attitude toward privacy, until someone comes up with a new way to do search that out-googles Google, you can't afford to ignore it. But you can let them know what you think about it and hurt they're bottom line by using other search engines more.
Monday, December 14, 2009
Guess who wants to copy Facebook
Facebook still needs to do some work - how much depends on who you talk to - before their privacy settings will pass muster with most privacy advocates and many users. But the concepts behind them address issues that the medical industry has been saying could not be done. That is, huge numbers of accounts can have individualized settings. With the living proof that Facebook has provided, we may see hospitals and insurance companies providing online records similar to the offerings provided by Google and Microsoft, but with the information entered for you by your health providers. And those providers have more (and more binding) reason to protect your data.
Sunday, December 13, 2009
Facebook's new privacy settings not popular
There are a couple of other options (or lack of options) that are cause for concern. You used to be able to hide things like your hometown and your birthday, but now the only way to hide them is to remove them from your profile. It also used to be possible to tell Facebook not to share information with Facebook apps. That option is no longer available, so now when one of your friends starts playing a game like Mafia Wars it can suck not only their information, but yours, too. That means, of course, that anytime you use a Facebook app you could be giving up all the information of everyone you have on your Friends list. So while overall the changes may have been good, the fact that you can compromise yourself and your friends by loading a facebook app is unforgivable. To make matters worse, the new privacy policy seems to be full of doublespeak that removes privacy assurances while appearing to give them.
I encourage you to go to Facebooks site governance page and tell them you don't approve the removal of privacy option and demand that we be given control of all of our information. Insist that the defaults should err on the side of privacy, not full disclosure. The ACLU also has a petition going to get the privacy settings changed. i would recommend signing it, as well.
Saturday, December 12, 2009
Google Public DNS - Is it worth it?
First, it helps to understand what DNS is. DNS stands for Doman Name Service, and is the reason we are able to remember to type http://www.walmart.com instead of having to remember http://161.170.244.20/. Sites on the internet are actually mapped by IP number. Since groups of 12 numbers can be hard to remember, the Domain Name Service, aka DNS was devised. DNS takes the easy to remember www.walmart.com and connects it to the real IP address of 161.170.244.20. The web wouldn't work nearly as well without DNS. With it, if I don't know a companies web address, I can make a few guesses and probably figure it out. If I had to guess an actual IP address, I'd probably die before I got it right.
The reason this is a privacy issue is that while Google knows an incredible amount about us already because of our searches, they only know what we search for and what we links we click in the results. If you make Google Public DNS your DNS provider, they know everything you do on the web. Every site you go to, every file you download, every streaming video you watch. It will all pass through Google. Google claims they are not going to share that information except in aggregate - meaning statistical groupings, ie males between the ages of 18 and 25 are more likely to go to gamespot.com than females between the ages of 40 and 50. Given the ad earning potential of such information, I'm not surprised Google is getting into the DNS business. With a world wide presence Google would be instant king of the information world. Well, Google is already king so I guess the next step up would be promotion to emperor.
I know that Googles stated reason to run DNS servers is to improve everyones internet experience, but does that really hold water? If you select the Google as your DNS provider you have to go through your ISP's servers before you can reach Googles, plus however many hops there are between you ISP and Google servers. Plus your speed getting to Google servers will be affected by the condition, settings and traffic on all of the servers between you and Google. I doubt you'll see much improvement over your ISP's servers. Of course, since the differences will be measured in a few milliseconds, even if Googles DNS is faster, I doubt you'll be able to tell. Is that worth turning every single bit of data your web surfing generates over to Google? I don't think so.
Friday, December 11, 2009
The Transportation (in)Security Administration
According to the TSA the information in that was posted is old and the manual was never even made available to TSA staff. But there was a lot of sensitive information in that document. From the easily duplicated ID cards for various agencies (Including CIA) to information on the x-ray machines that could be used to find a way to fool them, there is plenty there to put anyone on their guard.
The TSA seems to be poo-pooing the incident. That's understandable, if annoying. You can't reveal any more about how weak your defences are than the bad guys already have. But this is a serious breach of national security. Using this document it is possible that another group of terrorists could come into the US using fake documents that would wisk them through airport security with little or no security checks. It might make it possible for weapons to be smuggled onto planes in carry-on luggage. It may not be the worst threat to national security we've ever seen, but it's not a good one. Fortunately this breach has caught the attention of congressional leaders and others, so whatever error caused the manual to be posted may be found and cleared, and steps put in place to find and prevent similar errors in the future.
*redacted - sensitive information removed prior to release
[edited @ 9:56am because there's no reason for most people to know what 'redacted' means - Bert]
Thursday, December 10, 2009
Taming the Facebook Beast, pt 3
[caption id="attachment_230" align="alignnone" width="214" caption="First, go to Settings-Privacy"]
Once you click on "Privacy" things look a little different:
[caption id="attachment_274" align="alignnone" width="586" caption="Facebooks new consolidated privacy page"]
Today we're going to go over the new interface, and finish our Facebook tutorial in the process. That's made possible because now everything is accessed in one spot, and all of the settings are controlled in almost exactly the same way. There's no need to relearn how to do anything we've already gone over, only where it's at. The first group of settings is the Profile Page, which we'll take in two parts because my screen isn't large enough to get the whole page at once :)
[caption id="attachment_281" align="alignnone" width="600" caption="Top portion of the new Profile privacy page"]
[caption id="attachment_291" align="alignnone" width="600" caption="Bottom portion of the new profile privacy page"]
You can see that the controls are more specific, giving you more options for controlling what is viewable by whom. The privacy pull down menus are the same as before. But the "Custom" option is greatly simplified.
[caption id="attachment_284" align="alignnone" width="502" caption="It's easy to setup multiple exclusions"]
There are two privacy settings that are different from the others on the Profile privacy page. The first is the "Photo Albums" setting. Clicking on "Edit Settings" brings up the album privacy page. Both the album privacy page and the custom privacy settings are the same as before:
[caption id="attachment_300" align="alignnone" width="600" caption="The album privacy settings haven't changed"]
The second is the "Allow Friends to post on my wall" setting. It is either on or off. To me this is the setting that most needs to be configurable. Sure, if someone insists on posting annoying things on my wall I can unfriend them, but I want to leave that as a last resort. I want to be the same configurable interface I use to say who can see my birthday.
The next option is the "Contact Information" and it handles things like phone numbers and IM info:
[caption id="attachment_334" align="alignnone" width="600" caption="Control who can see your email address, IM, etc."]
The privacy pull down menus work exactly the same as on the Profile privacy page.
After the contact information comes the "Application and Website" privacy section:
[caption id="attachment_309" align="alignnone" width="602" caption="The privacy settings for Applications and Web pages"]
The first selection, "What you share" is just an overview of how sharing works in Facebook. The second section, "What your friends can share about you" is a series of checkboxes:
[caption id="attachment_311" align="alignnone" width="627" caption="Uncheck anything you don't want your friends to share about you."]
You can be as wide open or as close mouthed as you want to be, which is a good thing. The next section is blocked applications - the Facebook help says to go to the applications about page, but I haven't found a link to an about on any application I use, so I can't tell you much about blocking apps. It's something I'll be looking into in the next week or so.
Search is the next setting:
[caption id="attachment_317" align="alignnone" width="601" caption="Simple and clear."]
Exactly as it used to be, to keep from being submitted to Google and other search engines, make sure that "Public Search Results" is NOT checked.
Notice the request for a password. I have been gone from my computer for hours with Facebook up and nothing locked. Now after a short time of inactivity you have to give your password to get back into Facebook. That is another good change in the way Facebook does things.
And our last stop on our whirlwind tour of the new Facebook privacy policies is the people blocker:
[caption id="attachment_322" align="alignnone" width="580" caption="Block people by name or email address"]
Very simple, just enter the name or email of the person you want to block. And that concludes our basic overview of securing yourself on Facebook.
This new strategy of putting more options in the main windows and simplifying the settings custom windows has made the privacy interface cleaner, easier to navigate, and more intuitive. It's a major improvement, and hopefully one that will encourage people to make use of the privacy settings.
Wednesday, December 9, 2009
Taming Facebook: pause for update
When you set your privacy settings for tagging photos you can prevent others from tagging you in photos, but you cannot keep them from downloading your photos from your profile, and you can't keep them from posting photos of you. All you can do is keep them from tagging you in the photo. So even if you only let your friends see a photo, nothing prevents them from downloading it and posting it on their own Facebook page. Of course, if you spend much time with them they probably already have plenty of photos you woudn't want the world to see.
I will work on some more Facebook privacy settings for tomorrow and finish either tomorrow or Friday.
Tuesday, December 8, 2009
Taming the Facebook Beast pt 2
1. Configurable friend lists
2. Ability to remove yourself from Facebook search
3. Remove yourself from Google
4. Avoid photo/video tags
5. Protect your albums
6. Prevent stories from showing up in your news feeds
7. Control Application published stories.
8. Make contact information private
9. Avoid embarrassing wall posts
10. Keep friendships private
We briefly went over 1-3. Today we're going to look at 4 and 5, and maybe 6 if I'm fast enough.
4. Controlling photo and video tags.
a. Go to Settings-Privacy
[caption id="attachment_230" align="alignnone" width="214" caption="First, go to Settings-Privacy"]
b. Go to Profile
c. There you will see the privacy page. Go to the second group of 3 pull down menus.[caption id="attachment_238" align="alignnone" width="550" caption="Go to the second group of three pull down menus"]
d. On "Photos tagged of you" select "Customize".
[caption id="attachment_240" align="alignnone" width="531" caption="Select \"Customize\""]
e. The Customize box is similar to the one for your Basic and Profile data, but there are a few differences. I've tried illustrate a little of what can be done. Note: If a friend is in two Friend Lists, he will be given the most restrictive access between the two. So if he belongs to "Family" and "Know from Work" he will not be able to see any photo that "Know from Work" isn't allowed to see, even if "Family" is.
[caption id="attachment_244" align="alignnone" width="410" caption="Enter the Friends you want to see tagged images"]
5. Protect your albums
a. For some reason this privacy setting is not with the others. That may change soon.
[caption id="attachment_249" align="alignnone" width="497" caption="Follow the numbers for privacy settings"]
b. The options for the next two screen shots are the same as the methods for limiting access to posts and photos, so I'm just going to show them without comment. If anyone has any questions, feel free to ask.
[caption id="attachment_251" align="alignnone" width="477" caption="Access options for photo albums"]
Tomorrow a few more Facebook privacy settings.
Monday, December 7, 2009
Taming the Facebook Beast pt. 1
1. Configurable friend lists
2. Ability to remove yourself from Facebook search
3. Remove yourself from Google
4. Avoid photo/video tags
5. Protect your albums
6. Prevent stories from showing up in your news feeds
7. Control Application published stories.
8. Make contact information private
9. Avoid embarrassing wall posts
10. Keep friendships private
Let's look at these in a little more detail:
1. Configurable friend lists
Friend lists allow you to put your friends into groups according to your own preference. You can group your friends by how you know them (work, church, social group, etc.) and then set what you want each group to see. The steps to limiting what a list see are:
a. Go to the Settings Menu and select "Privacy Settings"
[caption id="attachment_199" align="alignnone" width="214" caption="Go to Settings-Privacy Settings"][/caption]
b. Select "Profile"
[caption id="attachment_213" align="alignnone" width="376" caption="Select Profile"][/caption]
c. Select the pull down menu next to the type of info you want to limit access to, then "Customize"
[caption id="attachment_205" align="alignnone" width="270" caption="Select the data type: Customize"][/caption]
d. In the Custom dialog set who you want to see your info, and set any friend or list you want to keep from seeing it in the "except these people" field.
[caption id="attachment_208" align="alignnone" width="405" caption="Use the custom dialog to limit access"][/caption]
2 & 3. Remove yourself from Facebook and Google search.
It's important to note that if you don't tell Facebook you don't want to be listed in Google searches shortly after signing up for Facebook, you will be listed on Google. But once you choose not to be in Google search you will gradually sink down in the listings. Of course, if people search for your name, even being low down the listings may still have you on the first page. To tell Facebook not to release your information to Google:
a. Go to Settings-Privacy Settings again.
b. Select Search
[caption id="attachment_215" align="alignnone" width="376" caption="Select Search"][/caption]
c. Choose who you want to be able to find you and what they can see.
d. If you have "Everyone" selected in the "Search Visibility" field, you will also have the option to allow your profile to appear in Google searches. If you don't want to appear on Google, uncheck the box.
That should be enough to swallow for one day. We'll cover 4 & 5 tomorrow - Wednesday if I'm too strapped for time. There will be some type of post Tuesday either way.
Sunday, December 6, 2009
Is privacy dead?
The quality or condition of being free from unsanctioned intrusion. Person should be sure that the personal information provided will not be used in any other purposes then those the user needs.
Whether or not they abide by that definition I couldn't say, but I like it. Bob Blakely of the Burton Group identity blog has a different, but related, take on privacy. In his entry, "Gartner Gets Privacy Dead Wrong" he tells us that privacy does not equal secrecy. As long as you don't tell anyone your information, you don't have a privacy problem. Once you tell information to someone, then you have a privacy problem.
That makes a lot of sense. Privacy doesn't involve keeping things secret, but controlling who accesses them, and how. I like that idea, and it dovetails nicely with the emailmarketingpro definition. One of the problems with social networks is that people surrender too much control over their information. Well it turns out that it doesn't have to be that way, and Facebook is putting more safeguards in place for people to use to give them even more control over who sees their information. The trick is getting users to use the controls.
I can't make people use them, but I can make the information readily available. Over the next few days I'll be looking at some of the ways you can control your information on Facebook. Nothing can protect you completely, but the first step to greater security is controlling how others access your data.
Saturday, December 5, 2009
Just a quick one
In the "deserves more attention, but I'm short on time department" we have Congress declaring hearings because two wannabe reality show stars manage to sneak into a state dinner - two people who are not unknown in Washington circles, from what I've seen - a week after the event. A month after 13 people are killed and many more injured in the Fort Hood (terrorist) attack they're still putting a hearing off. I don't understand.
Friday, December 4, 2009
NSA: Still listening with Presidential approval
Amendment IV
The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.
It really is important that we let our elected representatives know that we will not stand for this. Every freedom we let go, every right we let them take away, is one step closer to letting them take away all our freedoms and all our rights. I can't say it any better than James Madison:
I believe there are more instances of the abridgement of freedom of the people by gradual and silent encroachments by those in power than by violent and sudden usurpations.
Thursday, December 3, 2009
Facebook not necessary for self incrimination
It seems a teacher made an anonymous comment on the local papers website responding to the question, "What's the craziest thing you've ever eaten?" He responded with a word occasionally found before the word cat.
Apparently being the impatient type he couldn't wait to get home and posted his anonymous response from the school. Then when it was deleted he reposted. The editor of the paper either noticed the post was made from the school, and contacted them to report that someone from the school was posting lewd comments. The school was able to determine who made the post and when confronted he resigned or was fired.
This was clearly an overreaction by the paper. When they asked for the craziest thing you've eaten, they had to know someone was going to post that response. When it appeared again they shouldn't have been surprised. Frankly, I think being stupid enough to ask that question warrants some type of disciplinary action.
On the other hand, what kind of idiot posts obscenities from work? Twice. Even anonymously, you risk someone noticing as you post it.
What do you think? Should the editor have contacted the school? Should the guy have been fired?
And remember kiddies, there is no such thing as anonymity online. If they want to bad enough, there is almost always a way to find out who you are.
[Edited for better title]
Tuesday, December 1, 2009
The fallacy of "crime prevention" cameras
In Dallas they have had cameras for a while. It's interesting to take a look at 3 snapshots in time:
March 21, 2008 - Dallas News reports that cameras placed around the Dallas area have reduced crime. Among items reported as also having an effect in some areas are increased police presence and active neighborhood watch. For some reason their effect on crime is barely acknowledged.
April 27, 2009 - the Grit for Breakfast blog looks at the reported improvement in crime statistics and reveals that while crime was down 11% in camera monitored areas, it was down 18.7% in the rest of Dallas. The author wonders whether a decrease in one areas crime is really a decrease if the rest of the city decreases more. He also points out that Dallas recently changed it's crime reporting policy, and the effect of that has not been factored in.
December 1, 2009 - cbs11tv reports that the cameras have been ineffective deterring crime. In one area the cameras were placed in crime actually increased - and none of the crime was caught on camera.
Crime cameras are not tools of a legitimate republic. They are the tools of totalitarian regimes and serve best as a means to monitor law abiding citizens, not criminals. Criminals will figure out where the cameras are and make sure not to expose themselves. Law abiding citizens will become the monitored while criminals go around the not-so-deterrent.
Health, the web, and HIPAA
Enter two companies not exactly renown for their respect of privacy: Microsoft and Google. Google Health and Microsoft's Healthvault allow you to put your medical records, prescriptions, shot records, etc online and share them with your pharmacy and various healthcare providers. This sounds like a really good idea. It makes your records readily available for new doctors and makes it easy for you to share with a trusted family member or friend. Here is a short examination of both services.
First we'll look at Google Health. From the page you go to on that link:
Take charge of your health information
It's safe, secure and free
* Organize your health information all in one place
* Gather your medical records from doctors, hospitals, and pharmacies
* Share your information securely with a family member, doctors or caregivers
Google stores your information securely and privately, but you always control how it's used. We will never sell your data. You are in control. You choose what you want to share and what you want to keep private. View our privacy policy to learn more.
The privacy policy looks pretty good, but under the "How Google uses your information" section, #3 states:
Google will use aggregate data to publish trend statistics and associations. For example, Google might publish trend data similar to what is published in Google Trends. None of this data can be used to personally identify an individual.
I don't like my data being shared even "in aggregate." It's supposed to just be information like "x number of persons making between 45,000 and 100,000 a year are members." But I'm paranoid, especially about my health data. That is data that can be very damaging in the wrong hands.
The "Sharing your information" section is encouraging. The first thing they do after telling you that you can share information, see a list of who you are sharing it with, and revoke the right of someone on the list to see your information is to warn you that they may still have a copy of it, even if they can't access it to get new information. Now if only people would actually read the policy it would save some headaches later.
One encouraging thing about Google's offering is that it complies with Safe Harbor guidelines. By the nature of their business Google is not the worlds biggest privacy watchdog, but they appear to understand the importance of privacy when it comes to health records.
Now for a look at Microsoft Healthvault:
HealthVault lets you …
* Organize your health information, with everything in one place
* Simplify your life: enter health info once, use it in many ways
* Gain insight with data that helps you make informed decisions
Microsoft Healthvault is HONCode and Truste certified. Health On the Net was founded in 1995 and "promotes and guides the deployment of useful and reliable online health information, and its appropriate and efficient use." You can verify Healthvaults certification here, but right now they are actually undergoing annual review. It comforts me that they are reviewed annually.
The Healthvault privacy policy is longer and wordier than Google Health's but says essentially the same thing. Your data will only be released in aggregate, except for the people you release your own info to.
The question that burned in my brain when I heard about this was, "What about HIPAA? How can this be legal?"
Actually, because neither business is a medical provider, they fall through the cracks of HIPAA. They are providing a service to the consumer and have no affiliations with hospitals or doctors. So they can do things a doctor or hospital would not be able to do when it comes to your data. You might want to think about that before joining either of these services. But despite what looks like a service I would avoid at first glance, I would recommend either of these for someone who has medical conditions that require multiple specialists. My experience is that there usually isn't as much communication between doctors as you would expect. But they have to give you your records if you ask, and putting the records in a service like this means you can make sure every doctor has access to everything going on. These services don't remove control of your information from you, they give you control you've never before had of your healthcare. That is a good thing.
[Edited 7:40am to add to last paragraph]