Thursday, March 11, 2010

Ford: First Online Road Devices

Or maybe First Online Road Death? That last is a little unlikely, but in the realm of possibility. Ford is bringing a new meaning to "mobile device," and adding to the list of web-enabled devices. With Microsoft, Ford developed Sync and started putting it in some Ford vehicles in 2008. Sync allows you to connect bluetooth phones or USB devices like MP3 players to your car and control them with voice commands. It's a really neat bit of technology, but Ford wasn't satisfied to rest on their laurels.

Kevin Spiess report on Neoseeker.com, "Ford to use Windows CE in some 2011 models." With the functionality of a full OS, Sync will become more powerful, offer more control options, and will provide wifi connectivity for web browsing when parked. As delivered from the factory the web browsing will only work when the vehicle is in park, but I figure about 2 weeks (or less) after the first wifi enabled Ford is delivered there will be a way to activate browsing while driving.

But as surprising and innovative as wifi enabling a car may be, what is more impressive is that Ford is thinking about security long before implementing wifi in the cars - both to protect users data and to protect the system from malware that might endanger the car and it's occupants. That's important since connectivity will include social networks and other high risk locales.

The security features are pretty decent. A hardware firewall between the engine computer and the entertainment computer is one nice thing. They can't totally separate the two because they need to share things like GPS data and highway speed, to name a couple of things. To help protect from malware Sync will only accept software from Ford, and it won't allow installation through the wifi connection. There are other features to keep your data safe in your car.

And the security doesn't just cover electronic assets. There are features that will make Ford vehicles with Sync unattractive to thieves, too. Engine immobilizer keeps the engine from turning over unless a coded key is used, and a keycode allows the car to be opened even if the keyfob is left in the car.

Ford is taking a lead position in bringing the automobile to the internet, and vice-versa. It will be interesting to see where this trend goes over the next few years.

Wednesday, March 10, 2010

United States national worker ID card

From Laura Meckler at the Wall Street Journal:
"Lawmakers working to craft a new comprehensive immigration bill have settled on a way to prevent employers from hiring illegal immigrants: a national biometric identification card all American workers would eventually be required to obtain."

Really neat idea, except that it won't work. It won't even be an improvement on the current method. People paying illegals cash under the table will continue to do so. This ID card won't do anything to change that. It will give the government increasing ability to monitor law-abiding citizens without doing anything to affect the problem it's supposed to solve.

While this should be self evident, Senator Chuck Schumer (D., N.Y.) obviously thinks that biometrics are magically going to force all employers to check employees eligibility and pay by traceable means that make it necessary for all employees to be legal. He actually believes that requiring a biometric card is more effective than requiring a Social Security Card. Talking about illegal immigration he says,  "If you say they can't get a job when they come here, you'll stop it."  The only problem is, we say that now, and it's patently a lie.

Of course, not everyone thinks a national employee ID is a bad thing. The Christian Science Monitor is very much a believer in a national employee ID. In an editorial entitled "Immigration reform rests on a national worker ID" the CSM editorial board states:
"Obama could quickly reduce the nation’s high jobless rate with passage of a law requiring legal residents and Americans, even teenagers, to obtain a federal ID as legal workers. Migrants working outside the law would then be forced to come clean on their illegal activity, leave the country, and perhaps properly apply for a US visa – as millions of law-abiding people do around the world who wait years to enter the US.

To reach full employment, Obama needs to create about 8 million jobs – or nearly the number of illegal immigrants in the US."

I have two problems with that quote. The first regards illegal workers having to come clean. Why? What is this ID going to do that will force illegal workers (or their employers) to suddenly 'fess up? Even assuming most illegals bother with forged or stolen Social Security numbers, what's to keep employers from paying in cash and misreporting their number of employees anyway? Admittedly, if you're paying more than two or three employee’s cash can be problematic.

The other is the figure of 8 million illegals. That may be the suspected or deduced number, but it is impossible to prove. Even if it's correct, to say that all 8 million are working is a stretch.

On Foxnews.com, Alex Nowrasteh's article, "5 Reasons Why America Should Steer Clear of a National ID Card" gives a very clear, thought out explanation of the problems inherent in a national ID card. Briefly, they are:
1. Workers would have to ask the Federal Government before getting a job.

2. National ID's are perfect for controlling citizens movements: "Your papers, please."

3. The system will accidentally exclude millions of legal workers and fail to catch the majority of illegal ones.

4. The scanners are up to $800 - or employers can make a trip down to the local DMV to check their workers ID.

5. Law abiding citizens are treated like criminals - we will have to divulge information that the government cannot require of us now because we are not criminals. (That's the biometric data, in case you're wondering).

There is one way the national employee ID card would work. It would require a fundamental change in the way we live, not to mention being a harbinger of the end times. If we move to an entirely electronic economy we get rid of all but an insignificant amount of illegal alien employees. If we go to an entirely electronic economy and make your biometric employee ID your bankcard, too, then the only way to buy anything is with your employee ID card. It can be tied to your credit cards, debit cards, and all of your accounts. Utilities, insurance, gym memberships, all pulled from your national employee ID card. It would solve so many problems. It would be much harder for illegal aliens to find employment, it would encourage employers to hire U.S. citizens or legal aliens, and it would give the government what it wants - a way to track all citizens at all times. All you have to do is surrender your privacy and freedom.

Tuesday, March 9, 2010

Maryland students teach teachers

The Washington Post reports that a group of students at Potomac high school stole teachers passwords and were changing their grades for several months  before they were caught.

They used keylogging software to capture the passwords, then logged on to the teachers computers and change grades. Because of the computer system and the way it was accessed there is no way to discover who changed the grades. Instead of punishing all the students whose grades were changed (some may have been red herrings), the school is just changing them back to the original grades.

The tools the students used to log passwords is easily and  cheaply available online. To prevent this kind of problem students need to be locked out of adding software and of mounting or running .exe files from USB drives - in fact, flash drives, or any USB drive shouldn't mount from teacher or student accounts. If schools don't take these kinds of steps we eventually won't be able to trust our schools to truly teach our kids the things they need to grow - up, or to trust anything they tell us about how well the students are doing their learning.

Monday, March 8, 2010

Privacy vs Security at RSA conference

Brian Prince of eWeek Europe reports that U.S. Cyber Defense experts agreed on two things: U.S. cyber security needs beefing up, and doing that while protecting privacy won't be easy. Former head of U.S. Homeland Security Michael Chertoff saw the situation as a balancing act:
“You don’t want necessarily to have the government literally sitting there and operating the internet and opening and closing doors because it’s not hard to imagine a situation like you have in other countries where someone makes a decision that the threat isn’t just an attack by a botnet but an attack on ideas the government doesn’t like. So the key is to build a system that allows a sharing of information that does put on critical infrastructure a responsibility to maintain itself…but preserves a certain gate between them and a certain amount of accountability so that the government can’t simply just roughshod over the privacy.”

That's an important statement - and one that very neatly sums up the difficulty of providing security while maintaining privacy. The rest of the panel discussion showed a real concern and understanding of the importance - and complexity - of maintaining privacy while ensuring security.

Chertoff was one of a three member panel. The other two members were Marc Rotenberg, executive director of the Electronic Privacy Information Center ( EPIC ), and former special advisor on Cyber Security for George W. Bush, Richard Clarke. Richard Clarke is now chairman of Good Harbor Consulting. To be honest, I was a little surprised at the attitude shown by Mr. Chertoff and Mr. Clark. Hearing Mr. Chertoff, co-author of the Patriot Act, talk about the importance of limiting governments ability to invade citizens online privacy was unexptected.

Of course, not everything they said was so pretty. Clark wants a system that is flexible enough that it isn't compromised when some companies don't keep up with the latest patches and malware protections. His idea? Have Tier 1 ISP's do deep packet inspection to detect illicit activity. This is just a liiiiiittle bit contradictory to Mr. Chertoffs statement above. Deep packet inspection would mean they see everything everybody does that goes through a Tier 1 ISP. A lot of traffic will never hit a Tier 1 ISP, but the fact that US citizens would be being treated as criminals with no evidence that they are would be a major constitutional problem. Of course, it should be a major constitutional problem with the nationwide phone tapping that's still going on, and we know how that went. Not surprising at all that Rotenberg saw a slippery slope, "If we go down this road you really have to be very careful because one rationale easily collapses into another."

It was encouraging that Clarke felt the U.S. government had discredited itself over the past ten years where privacy is concerned. He also felt that the agency best equipped to protect the country, both military and civilian, is the NSA. But in an amazing twist, he feels that the NSA is not the agency that should be protecting the private sector. The problem is, there isn't anyone looking out for the private sector:
“The problem is right now no one is defending the private sector,” he continued. “The theory of the Obama administration seems to be cyber-command defends the military, DHS (Department of Homeland Security) – which can’t do it yet – defends the .gov community, and the rest of us are on our own.”

As scary as that is, it's better than being watched by the NSA. And I'm happy that all three panel members seem to agree with that sentiment.

.

Friday, March 5, 2010

Facebook, Twitter used to scam brides-to-be, vendors

This is an interesting tale. Setup a Facebook page, garner followers (real or not), get a Twitter account, and rake in the dough. These internet entrepreneurs created a facebook account and tweeted about a nonexistent bridal show, and sold upwards of 5000 tickets, plus getting booth fees from hopeful vendors and a free radiospot in exchange for a reduced booth rental. Not a bad scam. I first read of the scam on Ars Technica in an article by Jacqui Cheng.

It seems that almost $150,000 was scammed from attendees and vendors with this scam. The Facebook page is down, and the twitter account probably is, too. The bad thing is, short of calling the convention center to see if the event is really scheduled, I don't know how you could see through this scam. Maybe the fact that payment was taken through paypal? That's not really an indicator. I'm sure we'll see more about this, and more examples of similar scams in the future.

Thursday, March 4, 2010

TMI - some info shouldn't be realtime

February 2009 - "Just landed in Baghdad" tweeted Peter Hoekstra while on a 'secret' trip to Iraq. The media was aware of the trip, but agreed to embargo the information until after they arrived back in the U.S. for the safety of the congressmen. Since the congressman started tweeting before they left, the newspapers needn't have bothered.

March 3, 2010 - "On Wednesday we clean up Qatanah, and on Thursday, god willing, we come home," the soldier wrote on his Facebook page, refering to a West Bank village near Ramallah. That's from a story on Haaretz.com regarding a Facebook security breach. The mission the young man (he may not be a soldier, now) mentioned has been scrapped. According to Robert Mackey on the The Lede such details as the units name and the time of the raid were also revealed.

In the first case, Senator Hoekstra was former head, and senior member of the House intelligence committee. You would think a man with that kind of background would have more sense than to tweet details of his Baghdad itinerary. In the second, you would think a young soldier would be aware that posting details of an upcoming mission on Facebook would be a severe security breach - and could even be considered treason. But I wonder. How many of us actually realize how available things we put on Facebook and twitter really are? Do we really understand that what we put on Twitter and Facebook can be seen by just about anyone? With all the foolish things being put up on Facebook and Twitter, the real surprise isn't that two people posted national security breaking info on social networking sites, it's that we don't see a lot more of this happening.

I'm sure that most of my readers aren't in a position to spill national secrets, but spilling your own secrets can be bad enough. Think before you post on any site, and avoid the embarrassment of foot in mouth.

Tuesday, March 2, 2010

High school predator stalks Facebook

In Wisconsin a darker side of Facebook was revealed last December when Anthony Stanci plead no contest to two felonies. It must have been a plea bargain, because the 19 year old had blackmailed at least seven of his fellow students for sex. Between 2007 and 2008 he had a Facebook page that he used to trick male classmates into sending him nude pictures of themselves. He pretended to be a girl, and after classmates exchanged pictures with him (it's not hard to find nude pictures of girls on the internet), he threatened to post the boys pictures online unless they had sex with him.

Stanci might still be blackmailing teens for sex, if he hadn't been greedy. One of his victims had been unwilling to speak up to protect himself, but when Stanci wanted pictures of the young mans brother that was too much. He went to his parents, and the police were called.

Last week Stanci was sentenced to 15 years in prison. According to his lawyer, that is a fair sentence, and will give him time to rebuild his life after he gets out. That's really great, but I wonder who is making sure the youngsters who were victimized by Stanci get their lives rebuilt?

It's important we make sure our children know that they cannot assume that they know someone online. And that we remember it ourselves. Otherwise we make it too easy for predators to prey on us.

Monday, March 1, 2010

Ensured privacy: Data with a lifespan

In a video report entitled, "The Future of Data Encryption" ZDNET's Sumi Das tells us about a budding technology that will, it is hoped, make sure that any online data you don't want coming back to bite you in the buttocks will die a graceful death. A team of researchers at the University of Washington: Seattle is developing an encryption scheme that will make sure data will eventually become inaccessible. Called Vanish, it encrypts selected data and sends portions of the key to different computers on peer to peer networks. As computers drop off the network, the data becomes inaccessible.

It's an interesting concept. I see a few problems, and it will be interesting to see how they overcome them. First, what's to keep someone from copying the data? A copy made using copy and paste wouldn't be encrypted, so wouldn't be affected by the Vanish software. There are also screenshots. Of course, it is possible to block copying and screenshots, but I have to wonder if doing that wouldn't actually make people less likely to use the software. One thing we like to have is control of the data we received on our computers.

Another problem is getting people to use it. PGP has been around for almost 20 years, and it's open source cousin, GPG, has been around for a little over 10, but neither has been embraced by the general web using public. The twin problems of setting yourself up and getting your friends and colleagues to use it and setting them up is more than most people want to deal with.

Of course, a simple way to get it to work would be to get a major OS or email client to integrate Vanish and have millions of instant users. Microsoft is the logical choice, but Apple would do for a start.

Friday, February 26, 2010

FTC: Beware P2P Breach

The Federal Trade Commission is warning 100 companies and organizations that their data has been compromised by P2P software. According to the FCC press release data on both employees and customers is involved.

The release also indicates that the breach is not because of any new exploit, but because of poorly configured P2P clients. Some P2P clients, like Limewire, set a specific share folder and only make files in that folder available to the network by default. Others share the entire hard drive by default. If you are using a client that shares the entire drive by default and don't set it to only show one specific folder, anything on your HD can be seen and downloaded by anyone else on the network.

This is nothing new, but it is obviously something that is still relevant. FTC Chairman Jon Leibowitz said,
“Unfortunately, companies and institutions of all sizes are vulnerable to serious P2P-related breaches, placing consumers’ sensitive information at risk. For example, we found health-related information, financial records, and drivers’ license and social security numbers--the kind of information that could lead to identity theft,”

I remember being amazed at what I could find with gnutella way back when. Sadly, it's not surprising that more than a decade since I first noticed really neat stuff that obviously shouldn't be on a P2P network the neat stuff that shouldn't be there still is. P2P is really neat, and really useful (not just for sharing music). But if you are a business, and you use P2P, or one of your employees decides he needs to use P2P on his work computer and it shares the wrong folder or the whole drive you could find yourself in violation of laws such as the Gramm-Leach-Bliley Act or HIPAA. As an individual, you know that Quicken or Microsoft Money file that has all of your banking info and can connect to your bank account? Your neighbors 14 year old in now has access to all your money. And all he wanted was music.

The FTC isn't just talking about the users of P2P software. The say that it's just as important that companies who "distribute P2P programs, for their part, should ensure that their software design does not contribute to inadvertent file sharing. The easy way to do that is to have the P2P software's default setting "share this folder." And that's what you need to do if you are developing P2P software.

Thursday, February 25, 2010

British growing leary of government spying

http://www.no2id.net/

http://eideard.wordpress.com/2009/02/04/britains-id-card-system-in-action-a-lesson-in-incompetence/

http://www.trevor-mendham.com/civil-liberties/identity-cards/index.html

More fallout from PlainsCapital vs Hillary Machinery

Last week Hillary Machinery filed it's counter to PlainsCapitals lawsuit. The PlainsCapital suit seeks nothing from Hillary (other than legal fees and court costs), but wants a judge to rule that PlainsCapitals security measures were commercially reasonable at the time of the bogus transfers. Hillary is seeking the return of the unrecovered monies and legal costs.

Most of the security community, or the most of the portion making their opinion known, seem to believe Hillary is in the right. But not everyone is ready to pick a side just yet. Benjamin Wright, an expert in data security and cyber investigations law has pointed out in his blog that we only have Hillary's side of things, so until PlainsCapital has it's say, any conclusions we come to are speculation.

But as things have developed, PlainsCapital's say may be too little, too late. Hillary has not stood still and has not played the quiet game. They have told their story loudly to anyone willing to listen, and it is a compelling story. Even if PlainsCapital had security measures in place that Hillary hasn't mentioned, the Banks reputation has been tarnished, and this incident will probably pop up when least expected for years to come. And regardless of who wins, both litigants will probably both find the way they handle financial transfers changed forever when this is over, because real fallout from this whole event is not going to hit just PlainsCapital or Hillary Machinery. It could change the way banks do business, and that will affect anyone who deals with banks.

DarkReading.com reports that at next weeks RSA Security conference Authentify, Inc. (who are consulting with Hillary) will be asking security professionals to sign a petition to Congress in an effort to force banks to establish better security for business customers. I don't think anyone wants more government regulation, but the fact is that what happened to Hillary Machinery and PlainsCapital isn't unique, or even unusual, even if the lawsuit is. Apparently small and medium size banks haven't done anything to correct the situation. With the attention of Washington being called to it, the government probably will.

Wednesday, February 24, 2010

Facebook giveth, and Facebook taketh away

As we become more social on the Internet, it is inevitable that the online world have more, and more influential interactions with the physical realm. And sometimes that interaction can be quite amusing. Take these two stories:

Facebook Bullies SNL


It seems that the fame of Superbowl advertising combined with a fanbase spanning 3/4 of a century - some of them aware of the power of online social networking - can lead to a gig hosting Saturday Night Live. On "an Improvised Blog" Jason Chin reports that SNL may have Betty White host, or co-host, a "Women of comedy" night. And according to an article he links to on Entertainment Weekly, it's at least partly because of the Facebook group, Betty White to host SNL (Please?)! Quite an accomplishment for a Facebook group - not only to be noticed by, but to influence guest host choices for SNL. And for the worthy cause of having Betty White host the show.

But it's not all happiness and light:

Nickelback Loses Facebook Popularity Battle To Random Pickle


It seems that Nickelback's reputation on Facebook is in a bit of a pickle. Or has been pickled, or something. AllFacebook.com reports that a woman named Carol Anne decided she could one-up Nickelback and created the “Can this pickle get more fans than Nickleback?” fan page. She started the group on February 3rd, and on February 19th - just over 2 weeks - she topped Nickelback's 1,428,801 fans. As of 12:00am February 24th, the pickle has 1,478,755 fans.

What does this have to do with privacy and security? Nothing, directly. It's more of something to provoke thought. The Betty White to Host SNL (Please?)! page was started around January 29th and gathered 400,000+ fans in roughly 3 weeks. It apparently influenced SNL to consider Betty White as a host, and has actually generated more interest and hype than her official Facebook page.

The Pickle that beat Nickelback's Facebook fans garnered enough fans in two weeks that, if it were to record an album and sell 1 copy to each of it's fans it would have a platinum album. If only slightly  more than 1/3 of it's fans were to buy, the album would still be gold.

In a sense these are extreme cases - but looked at another way, they are atypical, but not extreme at all. Online social networks can be used to create change, something entertainers have vaguely realized for some time, and something that no politician has really gotten until Barack Obama's campaign. The Internet made communication and collaboration between universities and corporations easier. The World Wide Web made it possible for the common man to quickly and cheaply made his voice heard, and social networking has made it possible to ignite worldwide passion for a cause in less time than it took for Paul Revere to ride from Boston to Lexington in 1775.

This isn't bad, and it isn't good. It just is. How we handle this new power to mold and shape opinion determines the good or bad of it. It can be used for good - look at all the aid for Haiti generated through Facebook, Twitter and other social networks, not to mention all the websites that facilitate donations for Haiti relief. Look at families who haven't seen each other for years reunited. But look also at the careers ruined because of careless or malicious posts online and the predators who use the web as their playground.

What I'm trying to say, and what I want people to do when they're online is, think about what you're doing and what it may lead to. You may still decide it's the best course, but at least you won't get caught flatfooted if it blows up on you.

Tuesday, February 23, 2010

Big Brother's on the way

Fosters.coms Aaron Sanborn reports that in Dover, NH the police are going to be installing 23 cameras in various public buildings. The cameras aren't going to be constantly monitored but will be used to provide evidence in the case of crime. Sanborn talked to Dover Police Chief Anthony Colarusso.
"In general the security cameras are a deterrence that will hopefully prevent anything from happening," Colarusso said. "If people know a camera is in a certain area, they may be less likely to commit a crime."

Really? How many bank robberies occur every day in the U.S.? Are they more or less per capita than they were before the advent of cameras? Is there any evidence that they really are deterrent?

Well, the answer to that is a resounding "?".

Some studies show the cameras to be effective, some show them to be ineffective. Some show them to be effective, but closer study shows camera installation coincided with increased patrols - so which was the bigger deterrent? The questionable track record combined with the expense to setup and maintain and the privacy concerns of cameras should weigh heavily in the consideration of any camera deterrent program. But it doesn't. The appearance of doing something often trumps all other considerations.

For a very good article on "Police Cameras" check out the article at Howstuffworks.com. Or you can check out my original post on the subject - it says much the same thing, but howstuffworks.com has even more supporting links.

Monday, February 22, 2010

Jamere Holland latest facebook casualty

If you're like me, you may not know who Jamere Holland is. The former Oregon Ducks receiver was kicked off the team for his strong statements on Facebook. From a curse laden tirade regarding the booting of Kiko Alonso  as reported by Buster Blogger Brad Young to a statement reported in the Ducks Beat Blog regarding having white people as Facebook friends, Mr. Holland provides a prime example of not thinking before posting on his Facebook page. And he also needs to change his privacy settings. I'd never heard of Jamere Holland until today, but I was able to go to his Facebook page and take a screenshot of his wall:

[caption id="attachment_1061" align="center" width="500" caption="How to make and influence Facebook friends"]Jamere makes friends and influences people[/caption]


I don't know, but I see more than one thing that probably shouldn't have been said. And Mr. Holland is paying a price for his outburst - an outburst that was at least premature, since the friend he was defending had not been kicked off the team. How this will affect his future, both on and off the field, probably won't be very obvious for a long time, but in the short term, he's provided one more example of how a short temper and a Facebook page can put you in hot water.

Friday, February 19, 2010

School administrations are not police

Just days after telling you about the student who successfully sued her school for violating her free speech rights when they punished her for her Facebook page we see a new lawsuit filed, this time alleging invasion of privacy by school officials. If true, it is truly a case of school officialdom run amok.
In the Lower Merion School District each high school student was issued a laptop to improve and engage the students more fully in their education. The laptops were equipped with webcams and had software installed on them that allowed the webcam on a stolen laptop to be activated remotely, sending a still picture of whoever was using the laptop back to the school.

That's all well and good, but the students and their parents were not informed of this feature. Even that might not have been a big deal, but in at least one instance a picture was taken of a student whose laptop had not been stolen. And the student (and his family) learned of this when an assistant principal called the boy into the office and informed him that he was engaged in inappropriate activity at home. For proof he produced the picture taken using the webcam.

One has to wonder how many photos were taken, and showing what. The school had no right to be taking pictures of the students. Even if they thought the student was involved in something illegal, they had no right to activate the camera. Even the police would have had to prove probable cause to a judge and gotten a warrant.

Thursday, February 18, 2010

http://pleaserobme.com/

It's not a joke. Do you use one of the numerous services that let you tweet or otherwise post your location for the world to see? pleaserobme.com searches twitter and posts the tweets that give away the tweeters location.

It's not as nefarious as it sounds (or as it could be). The site was developed by three guys to demonstrate that we have some very bad habits, security-wise. The actual address data appears to be substituted with data from lands far away from the original poster. But that doesn't change the fact that large numbers of people are making their locations known. And part of knowing where you are is knowing where you're not. Which is exactly the information a burglar wants. Not to mention stalkers, psycho exes and assorted crazies.

Do you tweet your location? How often have you said something like, "Going to the game, hope we win. Go Tech!" How many hours would that give a crook to burglarize your home?

Wednesday, February 17, 2010

Just a quick Google Buzz observation

A coworker of mine received a buzz on his cell phone, It was a comment by a guy he didn't know. Ok, that's what Google Buzz does. The neat (or scary if it was unintentional) thing is that along with his buzz was his location overlaying Google Maps. And it actually gave the name and address of his apartment complex! It's really neat, but if you read my old blog you may recall my concern about similar fun things in the past that used Twitter and Facebook to allow friends (and others) to track your whereabouts. Great stuff for stalkers. Enjoy your social internet, but be careful what you're letting people know.

Facebook speech protected (sometimes)

Katherine Evans probably wasn't thinking about being part of a landmark case in online Free Speech when she created her Facebook rant against a teacher in 2007. She didn't keep it up long - apparently she was one of the few who didn't like the teacher - but the principal took exception anyway, took her out of her advanced placement classes and suspended her for three days.

In todays Miami Herald Hannah Sampson reports that a Magistrate Judge Barry Garber ruled that the Facebook page falls under the umbrella of Free Speech:
``Evans' speech falls under the wide umbrella of protected speech,'' Garber wrote. ``It was an opinion of a student about a teacher, that was published off-campus, did not cause any disruption on-campus, and was not lewd, vulgar, threatening, or advocating illegal or dangerous behavior.''

This is a very good ruling, in my opinion. The judge recognizes that the schools cannot, and should not, be able to dictate students life off campus. But at the same time it recognizes that there may be cases that Facebook or other online speech would not be protected.

As the internet continues to mature and governments start putting more effort into taming this beast cases like this one will define what we can and can't say online. And in the era of social media, what we can say online will be a defining factor in having a free society.

Tuesday, February 16, 2010

Google's Buzz: Sign of things to come?

Last week Google announced their first foray into the social networking battlefield. Termed Google Buzz, it immediately generated huge amounts of, for want of a better term, buzz. Of course, most of the initial buzz was about the horrid default privacy settings. I don't know if anyone actually lost their job or their marriage, but the way Buzz shared information definitely made such a result possible.

Google quickly responded to the hue and cry, but the real surprise wasn't that Google responded quickly and changed the default settings, it's that they made the mistakes in the first place. How could a savvy company like Google repeat the mistakes made by Facebook? And not only repeat, but expand on them. An article on Tech News World, "Google Buzzes Privacy Breach is a Sign of Things to Come" suggests that Google planned it that way. Not only that, but that opening services with wide open privacy settings, then pulling back only as much as public outcry demands will probably become the norm for social networking rollouts.

As much as I'd like to disagree with that, it rings true. Google, like Facebook, doesn't make money directly off it's users. It makes money off of their data and ad revenue. As new social sharing sites come along, they will probably use the same basic methods to make money. And they will probably use the same methods of getting as much data as possible from their users. Put it all out and when the users scream, step back only as far as absolutely necessary.

That's not acceptable. It should be standard practice to put out no information and give the user the option of putting out as much as he wants.

Monday, February 15, 2010

The lighter side of data breaches

Apparently a Swiss bank has been the victim of a data breach. Erik Kirschbaum reports through Reuters that German tax dodgers are running scared after data breach. The report says that which bank it was is unknown, but the German government seeing a huge increase in the number of tax dodgers turning themselves in. There is a good reason it's happening. German tax law says that a tax dodger can avoid prosecution if he turns himself in before the government starts to investigate him.

It seems there are a lot of German tax evaders with money in Swiss banks. But they may not have even noticed if the German government wasn't willing to pay 2.5 million Euros for the data. Which allows great quotes like this:



"There's been a delightful rise in tax compliance," said Daniel Abbou, spokesman for the finance department in the city of Berlin after 74 people volunteered this week to pay back taxes on previously undeclared income.


Great stuff.

Friday, February 12, 2010

Obama = Bush

Now that I've got your attention, yes, I mean that. When it comes to citizens privacy rights, I can see no discernable difference between their administrations. Obama is continuing the national phone monitoring that was started by the Bush Adminstration. A program that is unconstitutional and does little if anything to benefit national security.

If that wasn't bad enough, last night I saw two articles talking about a case being argued today in Philidelphia. The first was at Cato-at-liberty.org and was pretty short. The headline says it all:
The Government Can Monitor Your Location All Day Every Day Without Implicating Your Fourth Amendment Rights

The second was an opinion piece by Catherine Crump at the Philadelphia Enquirer. It began with,
"If you own a cell phone, you should care about the outcome of a case scheduled to be argued in federal appeals court in Philadelphia tomorrow. It could well decide whether the government can use your cell phone to track you - even if it hasn't shown probable cause to believe it will turn up evidence of a crime."

The Obama administration is asserting that U.S. citizens have no reasonable expectation of privacy when it comes to their cell phones. This premise comes from the "third party doctrine." The third party doctrine is controversial to say the least, and in the modern age the equivalent of completely removing all Fourth Amendment protections without the pesky need to actually repeal it.

The third party doctrine says that once you knowingly give information to a third party you lose the right to the Fourth Amendment protections. Just to help keep things clear, the Fourth Amendment says:
Fourth Amendment – Protection from unreasonable search and seizure.

The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.

The third party doctrine is based on the premise that, since the phone company, your ISP, and any other company you may give data to is not within the four walls of your home or on your person, that data is no longer protected by the Fourth Amendments clause against unreasonable searches and seizures.

Forget whether or not you are doing anything illegal. Under the third party doctrine the government can subpoena your browsing history from your ISP without having to prove probable cause. Anything you put on Facebook (not that Facebook is private), and possibly even anything you backup to Carbonite or other online backup service.  I say possibly to the backup services because they are usually encrypted, so a "reasonable expectation of privacy" can be argued. The same can't be said for email, cell phones, text messages or almost anything sent over the internet.

I don't know about you, but almost everything I do that doesn't involve direct, face to face communication goes through a third party before reaching it's destination. There is almost nothing I do that the government can't look into for no other reason than curiosity using the third party doctrine. Knowing the history of the American colonies and the revolution, I know the founding fathers never intended the government to have that kind of power.

Thursday, February 11, 2010

Better secure that wireless

A recent post by Thomas O'Toole of the Ecommerce and Techlaw blog reports that a federal court in Oregon has decided that if your network is not secured, you have given up your right to privacy. So, according to the judge evidence taken from the defendants computer was admissable, even though the sheriff searched without a warrant - because he accessed the computer over the open wireless network in the defendants home.

With no more information than that, I would say the defendant, John Henry Ahrndt, was right. But there is a lot more to tell. Mr. Ahrndt had an unsecured network, sharing a folder using limewire, and sharing his iTunes library. A neighbor often had trouble with her internet connection, and her modem would automatically pickup Mr. Ahrndts network and connect to it. One day she noticed a shared iTunes library, also with no password. She looked at it, saw some things that looked wrong to her, and reported it. A sheriff's deputy responded, and she repeated what she had done before. Based on what was found, a series of warrants were issued that culminated in seizing the defendants router, computer and a variety of storage devices.

O'Toole has no problem with the decision. He doesn't believe it breaks any new ground. Mike Masnick at Techdirt disagrees. He is concerned because having an open wireless network appears to mean you have surrendered your right to privacy on your computer.

I read the decision, and it appears to be completely in line with similar decisions regarding technologies like cordless phones and cell phones. And I can't really find any fault with it. Not only is the decision in accord with similar cases regarding analogous technologies, the judge explicitly states that having an open wireless network does not, by itself, remove your constitutional privacy protections:
Society's recognition of a lower expectation of privacy in unsecured wireless networks, however, does not alone eliminate defendant's right to privacy under the Fourth Amendment. In order to hold that defendant had no right to privacy, it is also necessary to find that society would not recognize as reasonable an expectation of privacy in the contents of a shared iTunes library available for streaming on an unsecured wireless network.

I can't speak for society, but for myself the combined facts that the guy was running an unsecured wireless network and broadcasting a shared, unprotected iTunes library on it pretty much removes any right to privacy on his computer. Claiming invasion of privacy in such a case is kind of like building a glass house, not putting up curtains and complaining if someone sees you naked.

I might feel differently Mr. Ahrndt were not a convicted sex offender and the evidence gathered wasn't pictures of children as young as five. But I doubt it.

[This is the second time I've had a post not publish when it's supposed to. What's going on?]

Wednesday, February 10, 2010

Home shopping by remote-pleasure or pain?

The Home Shopping Network (HSN) has a nifty little tool for those of us who don't have a computer and just don't want to be bothered with a phone call - and who have Dish Network. It's called Shop by Remote (SbR). A report by Michael Finney on KGO-TV San Francisco details a security flaw in the SbR system. According to the story, all you have to do is enter a little information and your address and credit card info will just pop up. The reason your information pops up is because you have to have an account with Home Shopping Network to use Shop by Remote. As you type information it is compared to info in their database. When there is enough to positively identify you, it pops your data up on the screen.

They were right about there being no security. HSN's SbR info page says that you have to have an HSN account, but really doesn't give any other information. Except for an 800 number to call if you have any other questions or wish to sign up. Well, there's an 800 number for questions, so I called it.

It was a very disappointing call. When I asked about security, I was told, "You have an account number that no one else knows."

So if anyone does get your account number, there is nothing else to protect you. And if you enter the right information into SbR, the system pops up your name, address and credit card number on the TV screen. So it appears if I can locate an HSN account number that is tied to SbR I can get the account holders name, address and credit card numbert. I asked about usernames and passwords again and was told that if I didn't trust Shop by Remote, I could just give the information to her to make the order.

Shop by remote is a pretty neat idea, but one that is far too insecure. Account numbers are often easy to find. Without some other type of authentication you might even find yourself victimized by a crook using a random number generator - all he needs is the format of HSN account numbers. So I told the associate that I wasn't interested, and hung up.

You can't use a credit card without making it possible that some one may steal your info. But Home Shopping Networks Shop by Remote makes it easy. Stay away until they add some security to it.

Tuesday, February 9, 2010

Our Changing Facebook

Facebook has decided to rearrange the home page, and I'm seeing a lot of complaints. Some are funny, some are whiny. My favorite is "Let's tell yo-mamma jokes about the new Facebook layout."

Myself, I don't have a problem with it. I like having a logout button rather than going to a menu, but other than that, it's ok. What is more interesting to me are the requirements Facebook is enforcing on third party advertisers. The policies have been in place for months, but Facebook recently spelled them out again, and is now requiring advertisers to agree to them. In his February 3rd Inside Facebook column, Eric Eldon gives a synopsis of the new requirements. But put simply, the reuirements boil down to, the ad providers will strictly adhere to Facebook guidelines regarding gathering, holding, and disseminating Facebook user information. They will also provide information to Facebook on their employees and just about any other information Facebook asks for. There are several other requirements that show Facebook is making a serious effort to protect users data.

Now if they would just give us more ability to protect it ourselves.

Monday, February 8, 2010

$50,000 for lost hard drive - almost wish I knew where it is.

$50,000. According to Government Technology, that's what the National Archives and Records Administration values a hard drive with personal information of Clinton era staffers - and one of Al Gore's daughters. So far over 175,000 letters have been sent out to people who may be affected by the lost data. With that much data missing, I don't think I'd want to admit I knew where the drive is. I'd forget the reward and leave the drive on the Whitehouse steps with a note, "Sorry, my bad, won't happen again." Better yet, do a 7 or more pass overwrite, drill holes in the drive, and throw it off a bridge. They still have the original data, so why risk getting arrested turning it back in?

Sunday, February 7, 2010

Punk'd, Facebook style

A few students at the University of Lethbridge, Canada decided to see how easy it was to create a bogus Facebook account and fool people with it. Valerie Fortney of the Calgary Herald reported her story, U of L Facebook prank a lesson in privacy. She quickly pointed out that Facebook is used for many good things before moving on to the point of the story.

But there is a dark side to Facebook, and that is what prompted the students to try their little experiment - apparently as part of a class, but it's never explicitly stated. It was an eye opener. In 24 hours the 'girl' was getting asked out, and having chats with people - some of them involving personal information. In 48 hours, fearful of what could happen if it went on too long, deleted the account. They then went to their class and revealed what they had done. I agree with Ms. Fortney, who says she would have paid money to be there.

Could a similar thing be automated? U of L professor Mary Dyck, an expert on cyberbullying, feels sure that it is already being done. Do you have any friends who are really computers?

At the end of the article, the author notices that an ad on her Facebook page was targeting "48 year old women" who wanted to test Ugg boots. It seems that 2 weeks earlier she'd been checking out Ugg boots on eBay. But she'd never mentioned that, or her age, on Facebook.

This will be my last Sunday post. Starting tomorrow I will post 5 days a week, Monday thru Friday.

Saturday, February 6, 2010

Facebook page = expel

Frustration can be very motivating. From the Miami Herald we learn that motivation without careful direction can be dangerous.

Alex Fuentes was frustrated because he was going to graduate with honors from a low ranked school in Florida, so he made a Facebook page. When the school found out about it, he was booted from the National Honor Society. Alex had taken a pledge to show loyalty to his school, and they felt naming a Facebook page, "Wesley Chapel High = Fail" did not qualify as a display of loyalty. Especially when it becomes an online hangout where students criticize the school.

I think the teachers on the NHS board over reacted. Giving other students a place to voice their frustration with their school could be a good thing, and I would have encouraged Alex to use that argument with them. But he apparently found moving to another school a better option, even though he was a senior with only a few months before graduation. So he gets to be another example of why you should be very careful of what you do online, especially on Facebook.

Starting Monday I will be posting 5 days a week, Monday thru Friday. Thanks for reading.

Friday, February 5, 2010

Should LEDA sue PlainsCapital?

It's amazing how much bad publicity one little lawsuit can generate. And PlainsCapital, formerly of Lubbock, has managed to put it's foot in it good. If I was in investor I would be seriously questioning the leadership of the company right now. And if I were part of the Lubbock Economic Development Alliance I would be looking at damage control for Lubbock's reputation.

From the Denver Post: Lewis: Firm sued for being robbed

Why would I be looking at damage control? Because some of the authors of national stories about PlainsCapital suing Hillary Machinery don't know that PlainsCapital is now based in Dallas. So  the stories talk about Lubbock based PlainsCapital, and proceed to make PlainsCapital - and Lubbock - look like a bunch of ignorant hicks.

ComputerWorld: Bank sues victim of $800,000 cybertheft

Of course, unless they had security measures in place that they aren't mentioning and someone just messed up, PlainsCapital acted like ignorant hicks, then acted more ignorant by trying to sue for vindication. I said it in the comments of my original post on this subject that email is not a secure verification method, and that point is being made by other observers. It's not like an expensive, high tech solution was needed. A simple requirement that no transfers be made without a phone call to verify they're legit would have prevented this.

From the codetechnology blog: Authentication issue at heart of lawsuit

So what would LEDA sue PlainsCapital for? Or maybe it should be the City of Lubbock suing them? I'm thinking defamation of character, damage to their brand, brand dillution...shoot, I don't know, but surely there's some stupid lawsuit they can hit them with that won't be as stupid as PlainsCapitals suit against Hillary.

From BankinfoSecurity.com: Texas Bank Sues Customer After $800,000 Scam

And a few more just because four stories don't demonstrate how widely this is being reported:

From Foxnews: A video clip

From Dallas Morning News: PlainsCapital suing customer Hillary Machinery over cybersecurity

From the e-business blog: Cybertheft victim gets sued by bank

From Techdirt: Bank Sues Identity Fraud Victim After $800,000 Removed From Its Account

And from the forums at Barrelhorseworld.com: We were cyber attacked/robbed...

Enjoy your weekend.

Thursday, February 4, 2010

Anatomy of a Craigslist scam

Our van went belly up a couple weeks ago, and we need another one. A friend sent me a link to a van for sale on Craigslist for $300.  Here is the listing:

$300 OR BEST OFFER
1996 CHRYSLER TOWN & COUNTRY LX MINIVAN
MOVING SOON & I CAN'T BRING IT WITH ME

- 106,970 MILES
- SECOND & 3RD ROW CUP HOLDERS ON BOTH SIDES
- SEPARATE REAR HEAT & AC
- AC/HEAT
- SEVEN PASSENGER
- NEWLY REBUILT AUTOMATIC TRANSMISSION
- ROOF RACK
- 3.8 LITER V6
- DUAL FRONT AIR BAGS
- AUDIOVOX 12.1 INCH DROP-DOWN DVD PLAYER
- GREY UPHOLSTERY
- METALLIC GREEN
- TINTED WINDOWS
- TWO SLIDING DOORS
- STEREO WITH CD & CASSETTE PLAYER
- HAS NO MECHANICAL PROBLEMS
- SECOND ROW FOLD-IN-FLOOR BUCKET SEATS
- FWD
- NEW TIRES
- POWER STEERING, WINDOWS, SEATS & DOORS

CONTACT ME @xxxxxx@yahoo.com

What makes this a classic scam is the appeal to our greed, in this case our desire to get something really good for as close to nothing as we can manage. Looking at the listing again, there was an obvious clue this was bogus from the start: 1996 Chrysler vans didn't have fold in the floor 2nd row seats. I know this because the van that died was a loaded 1998 Caravan. But not noticing that, this was still obviously too good to be true. It was probably a typo, though, so I checked it out. I clicked on the email address and sent a query. Shortly I received this email:

[caption id="attachment_875" align="alignnone" width="500" caption="Odd name for a personal website..."]Odd name for a personal website...[/caption]

The URL seems a little odd for a personal website, but I'll check it out...

[caption id="attachment_878" align="alignnone" width="500" caption="Appears to be a graphic, except for the phone entry fields"]Appears to be a graphic, except for the phone entry...[/caption]

Here's where the warning bells become intolerable. Some of this may be my own paranoia, but...

  • He's holding a raffle to see who gets to look at his van?

  • He's using a graphic for text - classic scam move. It's a lot more work than simply typing the text in - unless you're creating a bunch of ads. Then it's easier to create one document to upload instead of two or three (text and art)

  • He's using the Craigslists automated phone system to set this up? If he really works for them, he's fired.

  • He wants me to give him my phone number so Craigslists APS can text me?

  • I can give him as many textable numbers as I want to, he doesn't mind.


I checked the page source, and the only thing the page did is make sure you actually put something in the fields. It didn't check what you put in, just that the fields weren't empty. so I entered u, u, u. It worked. It sent me to a 5 second countdown page, which I think was setting up a hotmail account to email my phone number to. It then sent me here:

[caption id="attachment_885" align="alignnone" width="500" caption="Same page, but single code entry field now."]Same page except for single text field[/caption]

Just the blank field I'm supposed to wait and fill in when I get texted. The other hole in the blue is some of the 'text' that has a bit of cloudiness around it. That's a visual clue it's an image file, not actual text.

I look at the pagesource on this page and find a couple of interesting tidbits. There is a hotmail address and a password that I think are auto-generated every time someone enters data into the fields on the previous page. I'm pretty sure that's the case because the hotmail account is different every time. Yes, I clicked on it several times. Was that smart? Not really. I'm as protected as I can be, but there's no guarantee the doesn't have something new on his site that could compromise my computer.

Am I being paranoid? Craigslist didn't think so. By the time my friend saw the ad and told me, it had already been pulled off the site. It still showed up as a result in searches, but when you tried to go to it a page saying the ad had been marked for deletion popped up.

So what was he trying to accomplish? At first I thought he was just generating phone lists to sell. After all, all he asked for was a phone number. Then I realized what he really wanted was numbers to cell phones. SMS messaging capable cell phones that he could send simple little, "your code is: xxxxx" sms messages - at 9.99 per message. If the ad appeared in 10 cities long enough to get 1000 valid, textable numbers in each city that would be roughly $100,000 to the conman. Not a bad morning for a crook.

UPDATE: Once I was someplace I could log into hotmail, I went through the process again and tried the hotmail account and password that were on the page. Not only did it create a hotmail account, there was an email from Craigslist - it had created a new account on Craigslist. I imagine it also placed more ads. I'm bordering legality here (the scammer sent me the account info in the source code of the page), so I'm not going any further, but I suspect that the account on craigslist may have the same username and password as the hotmail account. Of course, this is all automated, so it doesn't have to be the same.

Wednesday, February 3, 2010

Facebook: Help Haiti gag and more

It's amazing the things people will do on Facebook. For some reason they think that, even though everyone they friend (and most people they don't) can see their posts, the posts are private. Here are a few examples:

A story in the Register today shows us that the Swedes are a generous people - and every bit as gullible as any other nationality. Swedes joining the group "2 kronor per member to earthquake victims in Haiti" expected 2 kronor to be donated to Haiti relief when membership reached 200,000. Imagine the surprise when, after 200,000 was reached, the group announed it was actually the Swedish Necropilia Association. The perpetrators of the hoax said they were wanting to get a good laugh and teach people about critically reviewing their sources. Since no one had to actually donate any money, I guess I can see the humor, and the lesson. But some of their material was reportedly pretty graphic, so I can't help but think someone's going to get into some kind of trouble over this.

AP writer Thomas Watkins tells us, "Use of Twitter, Facebook rising among gang members." That may be a good thing. It's enabling the capture of more violent criminals as they put incriminating evidence up on the social media sites.

A teen drinker, Ashley M. Sullivan, was about to be sentenced as a minor for the negligent homicide of her boyfriend while driving under the influence. The the judge saw a picture of a drunk Sullivan on her Facebook page. He sentenced her as an adult.

Three Illinois high school students were suspended for their Facebook videos. Other students reported the videos because they were frightened by them.

Tuesday, February 2, 2010

GAO to TSA: Test those scanners first!

In a report by Jaikumar Vijayan on pcworld.com we learn that the Government Accountability Office (GAO) has told the TSA to make sure they properly test the full body scanners they are trying to deploy. The GAO reminds the TSA that another technology, Explosive Trace Portals, was rushed to deployment, and performed so abysmally that only about 1/2 the units purchased were installed, and by the end of 2009 all but 9 were out of service. Those 9 will be gone by the end of the year.

The GAO says that the TSA had not tested the full body scanners by October 2009, but claims to have finished testing by the end of that year. The problem, according to the GAO, is there is no verification that real world tests, ie tests trying to fool or bypass the scanners, were done.

Without such tests - carried out with a sincere desire to get past the scanners - there is no guarantee that the scanners are effective. It's easy to find something carelessly hidden. It's another thing to catch something carefully hidden by someone with a good idea of how to hide it.

If some of the things I've read are correct, as little as a millimeter of skin will keep  these scanners from finding something. Having the amount of skin necessary for a bomb pulled up and sewn down over high explosives doesn't seem very attractive, but we're talking about people who are not expecting to be in one piece for much longer when this is done. Of course, there are less violent ways to hide a bomb inside the body. People smuggle drugs that way all the time.

This really comes down to a cost benefit analysis. The cost of the methods required to get around full body scanners - apparently very low. The cost of the scanners? A very high $130,000 to $170,000 each. Unless the TSA can show the scanners can effectively reduce terrorist attempts, the cost outweighs the benefit. From the information available now, that seems unlikely.

Monday, February 1, 2010

Lifestyles of the rich and famous

KABC-TV in Los Angeles ran a story Friday about an actress who was fighting city hall over the height of her privacy gate. Three years ago a stalker started sending letters to actress Eva La Rue that were frighteningly detailed. She responded by having her gate and columns made taller, among other things.  She started the work without permits, but later got a variance and went on with her life.

Then a neighbor complained, and the variance was overturned. Le Rue appealed, and her private address became part of public court records. She received a letter from the old stalker saying, "I know where you live now."

The neighbors complain that the height is not allowed by city ordinance (La Rue was given a variance) and they like the opennes of their neighberhood.

La Rue has had to move out of her house because of the stalker.

Is it right that these people endanger the life of anyone, because they want to be able to see into her yard? NO!!!

It's too late now. The cats out and Miss La Rue is out a house. The nosy neighbors should have to buy her house at fair market, splitting the cost between them.

Maybe they could rent it to the stalker.

Sunday, January 31, 2010

Facebook Twist: Anti-social networking

The Times Online reports that Colin Gunn, a notorious British godfather, has had free access to the internet, and has been using it to intimidate and terrorize via Facebook. He claims to have been given permission for it by prison officials. The suspicion is that they gave him access fearing refusal would be called a human rights violation. On the face of it, this seems silly, but it was only last June that the French version of the Supreme Court declared Internet access to be a fundamental human right. I'm sure they never intended for convicted felons to be able to access the internet from prison and continue to run their gangs. That is exactly what Gunn did, using his Facebook account to send intimidating messges, such as:
“It’s good to have an outlet to let you know how I am, some of you will be in for a good slagging, some have let me down badly, and will be named and shamed, f****** rats.”

Such an endearing character.

This actually isn't a post against Facebook. Facebook had no control over this, and probably shouldn't. The problem here is the idea that internet use is a "human right." If it is any kind of right at all, it is a citizens right, and like many other citizens rights, can be lost once you are convicted of a crime. Matt Asay makes some good points on the subject in his article, "Is Internet access a 'fundamental right'?" from May of last year. As Matt points out, there are rights and responsibilities. It's important not to confuse the two.

Saturday, January 30, 2010

Lot-o-links: Articles on Facebook, Google, Supreme Court and more

From Businessweek:  New EU Privacy Laws Could Hit Facebook - Mark Zuckerbergs mouth paints a target on Facebook

Exchangemag.com: Google Social Search Hits Privacy Snag on Facebook - Maybe Facebooks privacy settings are better than we thought.

Mediapost.com: Google Scores Partial Victory In Street View Lawsuit - Google streetview photographing view of house ok. Entering private drive to do it, not so much.

U.S. News: Should Supreme Court Uphold the Quon Case on Worker Privacy? Should workers expect email and other electronic communication on company equipment be private? Take the poll.

PCWorld.com: EFF:Browsers Can Leave a Unique Trail on the Web - Find out how much information your browser gives without even being asked. With suggestions on how to obscure your trail.

RDMag.com: How Can Policymakers Promote Innovation and Strengthen Privacy? - Policy always lags behind technology, trick is protecting privacy without stifling innovation.

Hope you find the reading interesting.

Friday, January 29, 2010

Bev Stayart = Levitra?

Have you ever heard of Bev Stayart? To be honest, I hadn't, either. But looking at privacy news this evening I saw her name in a headline, "Bev Stayart Sues Yahoo Again For Violating Her Privacy Rights" and had to check it out. The story was on Techdirt, and tells the sad tale of Ms. Stayart, who sued Yahoo because she did a search for her name and didn't like what came up. That case was understandably thrown out of court, er, I mean dismissed. So here we are a year later, and Yahoo finds itself the target of Bev's lawyers once again.

Why?

It seems that now if you go to Yahoo and type in "bev stayart" the search "bev stayart lavitra" is suggested. If you choose to leave off "levitra" then on the results page it asks if you want to search for "Bev Stayart Levitra."

I'll refrain from making any of the bad jokes I'm thinking of at the moment.

Well, if you actually perform the search for "bev stayart levitra" you find that the association is made because most of top results are from her year old lawsuit with Yahoo. Well, they were, now they are from all the stories and blogs about this lawsuit AND her year old lawsuit.

Congratulations, Ms. Stayart, you are well on your way to permanently tying your name to both Yahoo and Levitra.

[edited title to be more informative by Bert]

Thursday, January 28, 2010

TOR cracked to catch child pornographers

Tuesday I wrote about TOR, The Onion Router. Wednesday in ZDNets "Zero Day" blog I read about a TOR server patch written for the purpose of catching child pornographers. Not just to the geographic location they are operating from, but to the computer they are working at. A worthy endeavor. But since the author, HD Moore of Metasploit fame, is releasing the source code, modified versions of the patch can be created to track anyone using TOR. This means TOR as a standalone item has become useless for protecting people who need protecting, i.e. human rights activists in oppressive countries, journalists and police under cover, and anyone with a legitimate need to keep their location hidden.

Moore (arguably) had good reason to do this. In Germany, at least, TOR is being heavily used, or is suspected of being heavily used, to traffic in child pornography, and the German authorities have been cracking down on TOR servers. But is the possible benefit in one admittedly important area worth the cost in several other important areas?

But there is an alternative the the TOR package by itself. It is also cross platform, and free. It will run on Intel Macs, Windows, and Linux. It is called JanusVM and runs in a virtual machine. It plugs the holes used by Moore's patch, and keeps your location obscured. From the Janus website:
JanusVM is powered by VMware, built on the Linux 2.6.14 kernel, and brings together openVPN, Squid, Privoxy, and Tor, to give you a transparent layer of security and privacy that is compatible with all your TCP based applications. DNS request are also passed through Tor so even your ISP doesn't know what web site you are looking at.

JanusVM is free, cross platform, and can take a little more setup than the basic TOR package, depending on how your network is setup. But if you need anonymity online, it's the best thing going now.

Wednesday, January 27, 2010

A little more Facebook, good and bad

Facebook, like most tools, can be good or bad. When it's good, it can be really good, like gathering aide for Haiti, or as reported by the Economic Times, a father and daughter who haven't seen each other in almost half a century find each other through Facebook.

But it can be very bad, too. According to the Crime Scene KC blog, Micheal Cowley plead guilty to posing as a 17 year old girl in order to get naked pictures  from teenage boys. This type of activity is unavoidable as long as Facebook doesn't do more ... More? Facebook doesn't do anything to verify who you are when you sign up. The surprise here isn't that someone posed as a teenager on Facebook to get naked pictures of other teens, it's that we don't hear of it more often. I would say I'm glad we don't, but I have to wonder how many just aren't getting caught. And it concerns me because I have teenagers and kids who are going to be teenagers in a few years. Do you know all of your kids Facebook friends?

Tuesday, January 26, 2010

TOR: Peeling the onion

One way you can enhance your privacy protection on the internet is to use TOR (The Onion Router). TOR is the second generation implementation of onion routing. Onion routing is done by encrypting the data in several layers, like an onion. You run a TOR client on your computer and it encrypts your queries then sends your internet traffic to the nearest TOR proxy, which then routes it through at least 2 more TOR proxies. To the computer you are sending data to, whether it is a web site, ftp server, or whatever, it looks like your data is coming from the TOR server your data exited the network from.

Just as with any security system, there are things you need to be aware of, and the TOR download page lists some. One other gotcha that is mentioned somewhere on the website, but I can't find it at the moment, is the bandwidth and processing overhead required. Your web queries are being encrypted on the fly by your computer, and every query you send has have one level of encryption removed by each TOR server it goes through. That takes a little time, which means your queries take a little longer to reach the server you're sending them to. I'm using an older 1.33 GHz Powerbook, and TOR is useable, but the processor hit is noticeable. The bigger problem for me is the loss of javascript and Flash. You don't know how many sites you go to use those until you try to do without them.

But despite the imperfections, if your main goal is to obsure the origin of your web traffic, TOR is a useful tool. If you plan to just use it for browsing the web the default install bundles work great with Firefox. There are bundles for Windows, Mac and Linux, and they are preconfigured with additional software to make using TOR as easy as possible, even for people who aren't that technically inclined.

You can download a TOR bundle that pretty much sets you up for browsing with Firefox here (you have to install Firefox).

Check these pages on Wikipedia for more information on TOR and Onion Routing.

[Updated at 7:25 am for clarity by Bert]

[Updated at 11:45 am for clarity and spelling (Linux doesn't have an 's') by Bert]

Monday, January 25, 2010

Cost of music piracy: $2,250 per song.

Are you one of the people still sharing your music over peer to peer networks like Limewire? In the 'Threat Level' blog for Jan 22, David Kravits tell us about Jammi Thomas-Riset, who was fined 1.92 million for sharing 24 songs. That's $80,000 a song! Jammi's lawyer asked that the price be reduced. The judge agreed, and reduced it to the minimum allowed, $750 per song x 3. The judge called the original amount "shocking."

The RIAA is a fear-mongering bully, and they need to be forcd to disband and allow artists to do their thing. The premise that internet sharing reduces CD sales is hogwash, and 70's folk singer Janis Ian makes a good case for the opposite here, and Eric Flint of the Baen Free Library makes a similar case here and amplifies on it here. Ian's article is also published in "Prime Palaver" on the Baen Free Library website. Both people can demonstrate that offering things free (including having your music pirated) leads to more - not less - sales.

It's inevitable the entrenched businesses with "strategies that work" will react violently to any new model that makes their way of doing business obsolete. But it's getting old. The iTunes music store has demonstrated quite well that legal online sales are not only feasable, but can be highly lucrative. But they still want to alienate their users by suing them. I'll never understand the corporate mind.

Sunday, January 24, 2010

What's coming up

Over the next couple of weeks we'll look at a couple of the more involved things you can do to protect your privacy as you go about your online life. For starters we'll look at TOR (The Onion Router) and GPG (Gnu Privacy Guard), the open source version of PGP (Pretty Good Privacy). A little later we'll look into other secure email and web surfing options. We'll also be looking at little things like the FBI's illegal tapping of phones without any kind of warrant or proof of need.

Saturday, January 23, 2010

And the loser is...

Remember the RockYou breach I told you about back in December? There may have been a beneficial result. Since the hacker published all 32,000,000 passwords he stole, it was possible for the people at Imperva to analyze them and find out what the most common passwords are. Of course, being the most common, they are the worst possible passwords to use. The free report is available here.

The report is worth reading, if only for the top 20 list. Here's a sample:

#1 123456

I think that is the first thing tried after 'password' when trying to guess passwords

#20 QWERTY

And this is probably about #10 on the list of passwords to try when guessing.

Remember to use strong passwords. Imperva estimates that it would be possible for an attacker to crack 1000 RockYou accounts every 17 minutes. That would be all 32,000,000 accounts cracked in less than 2 weeks.  Ok, not all accounts, because there were some strong passwords among them.

Strong passwords consist of at least 8 characters and are made of upper and lower case letters, numbers and special characters. Make all your passwords strong passwords.

Friday, January 22, 2010

PlainsCapital vs Hillary Machinery

tx_plow_boy asked what I though about "my bank" after the revelations by Hillary Machinery. Hillary is alleging that negligence on the part of PlainsCapital led to the theft of over $800,000 from Hillary Machinery's account. $600,000 was recovered, but Hillary Machinery wants PlainsCapital to admit that they are responsible and pay up.


I've read Walt Nett's article,  "Company, bank blame each other," in the Avalanche-Journal. I've read what Hillary Machinery says in the news section on their website, and I've read the two stories about similar breaches they link to directly from their site. I'm going to take a closer look at the info we have on the Hillary Machinery breach and see what I can come up with. Most of the information I'm using will be straight from their website. As we look at this the circumstances of this theft, keep in mind that I am not a lawyer, and I have only the information I've read (and linked to for you) to go by.


Looking at the info provided by Hillary Machinery on their website, here is what we have. To shorten this a little, I'll take it point by point.


1. In November 2009 PlainsCapital became the target of cybercriminals. They used vulnerabilities in PlainsCapitals internet banking system and initiated fraudulent wire and automated clearinghouse transfers.


Since I can find no mention of similar data breaches at PlainsCapital, I would probably classify the bank as a victim. It appears that the target was actually Hillary Machinery. For the same reason, I would say that the bank was not where the vulnerabilities were exploited. The normal scenario when an institution gets breached is to grab as much information as possible, or in the case of banks, grab money in small amounts from as many accounts as possible. Grabbing a large amount of money from one account points to the exploited vulnerability being at Hillary Machinery.


2. Even though the transactions were not authorized by a representative of Hillary Machinery Inc and inconsistent with Hillary's the bank still allowed them to occur.


The "not authorized by a representative of Hillary Machinery" is a bit of a red herring. If the perp stole the needed information from Hillary Machinery, the bank woudln't know that it wasn't someone from Hillary until the transaction was set in motion, and even then maybe not until two or three had been made. At that point the bank should have contacted the company to make sure the transactions were legit.


3. To make matters worse, PlainsCapital Bank has yet to take responsibility for the stolen funds claiming that their Internet banking systems are "reasonably secure."


Face it. The bank can't admit any culpability. The second they admit any kind of fault they will be sued out of business. If this case ends the way these things usually do it will be settled out of court with PlainsCapital paying some undisclosed amount without admitting any fault.


I don't think the lions share of blame goes to PlainsCapital on this one. It looks like Hillary was breached, whether by a virus, a trojan, or social engineering. Any share of the blame that goes to PlainsCapital goes after Hillary recognizes their own part in this very expensive fiasco.


I hope that answers your question, tx_plow_boy.

Thursday, January 21, 2010

Microsoft, Champion of Privacy?

Microsoft has a pattern in the way it does things. When it wants something done a certain way, it does it, and damn anyone who tries to go another direction. Now Microsoft has decided that it's time to let go of information instead of hording it. In a column at Information Week, Microsoft Boosts Bing Search Privacy, Thomas Claburn tells us that Microsoft is going to remove the IP data from searches after six months rather than the eighteen that Google does. But Microsoft falls short of Yahoos commitment to delete most search info after 3.

And there lies the rub. Microsoft is used to being the big dog on the block when it decides on a move. According the seoconsultants.com Bing is third in the search engine race. Google is first with over 70% of the search engine traffic. Yahoo is a very distant 2nd with a little under 15%, and Bing is relatively close behind Yahoo at a little under 10%. In other endeavors Microsoft can bring it's massive OS dominance to bear. In search that dominance is less helpful. If they can't give the results that Google or even Yahoo can, they won't dominate.

Search isn't the only area Microsoft is coming forth as a privacy champion. Cloud computing, which is an area Microsoft might be able to influence, is another area the Redmond giant is preparing to address. In her PCMag.com article, Microsoft Urges Cloud-Computing Privacy Bill, Chloe Albanesius reports that Microsoft's lead council, Brad Smith, lobbied (she said urged - sounds nicer) Congress for a modern privacy bill and unveiled a report that shows the vast majority of people are worried about their data in the cloud. In a keynote at the Brookings Institute in Washington D.C. he said:
"As we move to embrace the cloud, we should build on that success and preserve the personalization of technology by making sure privacy rights are preserved, data security is strengthened and an international understanding is developed about the governance of data when it crosses national borders."

He went on to say that the government needs to modify and pass laws to protect data and privacy as we move to cloud computing.

This all sounds very good. Microsoft may have realized that protecting data in the cloud is in it's own best interest. Crooks might go after my data, but they're more likely to go after Microsofts if we are both equally insecure. Only time will tell if Microsoft legitimately wants better privacy controls, or if they're preparing to exploit loopholes.

Wednesday, January 20, 2010

Facebook: More bad, a little good

The Bad


As if it weren't already dangerous enough to be on Facebook, Ellinor Mills writes in her column on CNET that researchers have found Facebook is vulnerable to click-jacking. In essence, click-jacking is putting an invisible layer over a legitimate web page. When a link on the legitimate page is clicked, the invisible layer hijacks the click and sends the person somewhere they didn't want to go. The same researchers also noted that Facebook allows third party apps to access user data without warning them. I've talked about this before - most recently in response to a comment yesterday. Facebook had a response to this problem:
"The only information apps can access without first showing the 'Allow' screen is publicly available information (the limited set of info that includes name, profile picture, gender, networks, friend list, and pages) and information set to be visible to everyone on the Internet," Facebook spokesman Simon Axten said.

The "limited set of info" seems overly broad. Does mafia war really need to know the networks I belong to and every friend I have on Facebook? And the default for all information on Facebook is now "set to be visible to everyone on the internet," so Facebook tells the apps I use everything I have on Facebook, unless I've changed the defaults. And they don't tell me they're doing it. It would be interesting to know how many people tighten their privacy on their Facebook accounts. I bet it's a pretty low percentage.

The Columbus Dispatch carried an article by Bridget Carey highlighting the many ways you risk identity theft by using Facebook. They range from viruses to fake friend requests. The problem is only made worse by the tendency to be more trusting on sites like Facebook.

The Good


The Tech Chronicles blog notes that Facebook is warning users about Haiti relief hoaxes. If you want to help Haiti through Facebook, go to the Facebook Global Disaster Relief Page.

A cnn.com story informs us that caller id spoofing company spoofem.com is going to be giving 2 super bowl tickets away to people who become fans of their Facebook page.

Well, that's the good and the bad today.

Tuesday, January 19, 2010

More Facebook woes...

I've been saying Facebook is dangerous for years - to be fair, I'm not the only one - but it's amusing to see three stories about three different risks of using Facebook in one day. Well, they weren't all written the same day, but I saw them all on the same day.

PC World tells us: Job Seekers, Watch Your Walls -- Employers Check Facebook Among the other stats provided in the article: 53% of employers check social networking sites like Facebook when vetting potential employees and more plan to start. A lot of employers have let people go because of what's on their Facebook page, too.

From IndyPosted: AT&T Error Allowed Unauthorized Facebook Access. Apparently there is a problem with how cell phones connect to the internet - there is no indication of whether it's only on AT&T's network. The problem caused a family to be sent someone elses Facebook login info. [Update: According to CNET's Insecurity Complex column AT&T has fixed the problem.]

The Security Watch blog at PCMag.com asks the question, Is Facebook privacy a sham? And with good reason. Facebook supplies a public link for you to give to people who are not members. It allows people who are not members of Facebook to look at pictures that you have labeled "Me Only". Does no one at Facebook see the problem in this?

I don't hate Facebook. Social networks can be a great tool. I even have an account. But I am concerned that even the people who try to keep most of their info on Facebook private are doomed to expose far more than they intend because Facebook doesn't really allow users to keep anything private.

Monday, January 18, 2010

Lincoln National: Weak security, strong customer care

Lincoln National discovered last August that there were several shared usernames and passwords that had been created in 2002 for the purpose of making it easier for staff to perform administrative duties. I can't say from intimate knowledge of Lincoln Nationals employees, but I imagine the thinking went something like this:
It will save a lot of time if we don't have to log out every time we leave a computer so other people log in if they need to...If we just make a few logins and share the information it'll save tons of time."

Of course, this goes against PCI and Sarbanes Oxley compliance because it ruins accountability. If more than one person uses a login it becomes almost impossible to prove who did what with it. Most companies I know check for shared logins (also known as generic logins) on at least a quarterly basis and get audited annually, so I'm not sure how this little snafu went on so long.

The company says that there is no evidence of improper use of the shared logins, but since there is no way to prove that no data was compromised Lincoln National is notifying state agencies and customers voluntarily and offering customers free credit monitoring.

It's nice to see a company that steps up to the plate and does the right thing when they screw up. I have a feeling there may still be an investigation and maybe some fines, but it won't hurt Lincoln National's case that they looked after their customers when a problem was discovered.

Sunday, January 17, 2010

Facebook gives McAfee away

Facebook seems to have realized it has problem. The Tech Chronicles blog tells the tale. To help curb runaway viruses and software Facebook has forged an alliance with McAfee to provide McAfee software free to Facebook users for 6 months to protect their computers. You have to go to the McAfee fan page, join up, and download the software.

If you already have security software and aren't having any problems I'd say don't worry about it. But be glad Facebook is showing signs of beginning ot understand that it is responsible for the well-being of it's users. I'm not real hopeful, but at least the appearances of concern are there.

Saturday, January 16, 2010

How's your Online Rep?

I was going through my alerts today, and a Smart Planet blog caught my eye. Titled, "How to build and manage an online reputation," it's a good primer, and has some good links at the end of the article. We'll go over some of what they say, and some of what some other people say, but I recommend checking out all of the sites linked today. They all have a lot more to say than I can repeat here.

According to the article at Smart Planet, the first thing you need to do is find out what's out there about you. Just a few years ago the only people who really had to worry about their online rep were people who'd reached a certain status level in certain technical fields. Today almost any job you go to will check out your Facebook page and/or hit the search engines.

Have you googled your own name lately?

Some privacy advocates say googling yourself is a bad idea. Frankly, you can't afford not to google yourself - and Yahoo and Bing yourself (that last one just doesn't sound right, does it?).  What you see is what potential employers are going to see, and each search engine give slightly different results.

Another blog entry at onlinereputationedge.com brings up a good, but seldom talked about point - what you say about other people online usually says a whole lot more about you than about the person you're talking about. So be careful what you say. And remember, once you put something online, it will never be gone, so the bad impression you create today could come back to haunt you thirty years from now.

Onlinerepmanagement.com uses Kanye West to teach us that even the biggest blunders - or group of blunders - can be mitigated by an active online presence. Because he is very active online you won't see much negative about him when you search for his name, even after 2009's gaffs. It's amazing what an active online presence can take care of.

That's it for now. Stay safe and work on that online rep.