HazDat
28Sep/09

The problem is, banks have too many humans.

What do you call the sacrifice of one person's privacy in an attempt to save the privacy of over 1300? If you're a bank, you call it collateral damage.

rmb-logoWhen I was a kid I earned my first paycheck passing out fliers for a neighbor who was starting a pool cleaning business. With my first $13 in hand, my grandfather took me to the a bank in walking distance to my home, got me a tour of the vault from the branch manager, a neat pouch to hold all my coin, a full explanation of the principals of savings and loans, and helped me open my very first savings account. Believe it or not, back then, all my account information was stored on a double-sided index card behind the teller.

Today, things are much more complicated. Gone are the index cards and passbooks, most of the employees, tellers and branches, a good deal of the service, interest-bearing accounts with only $13 in them, and a lot of the customers' money. Today, it's all computerized, and most banks even attach various penalties to discourage human contact.

I know an awful lot about electronic data systems, but I don't pretend to fully understand how the modern banking system works. Sometimes, I think I do--from a mechanical (as opposed to financial) perspective. But then something convinces me that I don't. For instance, you know how every so often your bank emails its customers' names, addresses, Social Security numbers, and loan information to Gmail? ... CONTINUE READING »

23Sep/09

You Tweet, therefore: YOU ARE HERE.

TwitterVisionHow Twitter says they'll hide your location from twits with subpoenas.

Recently, Twitter announced that they would be adding geolocation features to their service, allowing users to embed their physical location in their Twitter feed. As not to alarm: Twitter has always maintained that this would be an opt-in feature. But, frankly, any web site you visit is privy to some information about your physical location by virtue of the IP address assigned to your computer by your Internet Service Provider (ISP) from a group of IP addresses reserved for your neighborhood. The logs kept by a web server, combined with a subpoena to the appropriate ISP, usually yield a street address for the subscriber assigned that IP address.

SmarterWare's Gina Trapani (formerly of Lifehacker.com) is attending the Twitter Conference in LA. She's posted updates explaining how Twitter plans to deploy this service and how they intend to protect its Twitter geolocation users from subpoenas. According to Gina, "Twitter will scrub geo-data stored in tweets more than 14 days old to avoid getting subpoena’d about a user’s location in the past. They will outright delete the location information from their database, not just anonymize." ... CONTINUE READING »

17Sep/09

“Blood in the Birdcage” (Forensics: You Decide, Discovery Channel)

Investigation_Discovery_300One body. One suspect. Two theories. A laptop. A birdcage. A bloody crime scene. Two trials. Two hung juries. No convictions. One unsolved mystery.

From Investigation Discovery:

"When a beloved music professor -- David Stagg -- discovers the dead body of his long-time partner, Bill Jennings, he claims he's walked into the aftermath of a tragic suicide. But as investigators descend on the scene, they immediately realize that this reported suicide is clearly a homicide. Is it possible the professor is behind this vicious crime, or has he been falsely accused? The forensic experts on each side battle it out. Which side will you agree with?" (60 min. - First aired 9/14/2009 on Investigation Discovery / Discovery ID's "Forensics: You Decide)

Suicide letter, or coverup?

Suicide letter, or coverup?

Friends from the couple's active social group were in total disbelief. Few could imagine David Stagg involved in the murder of his long-time partner. Forensic evidence was inconclusive. Though blood evidence was found throughout the crime scene, no blood or defensive wounds could be found on David Stagg. An unknown set of fingerprints were found at the scene. Computer evidence from Jennings' laptop showed--at least from Jennings' perspective--a tumultuous relationship. But, enough to justify a motive for murder?

There were also a series of suicidal emails and typed letters left by Jennings that charted a history of both love for Stagg, and deep emotional turmoil. And, one final letter--typed on April 24, 2004, the night of the murder--would become one of the most contested pieces of evidence that two juries would have to consider.

On one thing, both sides agreed: Bill Jennings did not take his own life. ... CONTINUE READING »

12Sep/09

Germany, you’ve been Punk’d!

You've been punked!!!

You've been punked!!!

How German filmmakers hijacked part of California, stole its identity, and used it to scam an entire country.

I think I've finally figured out the origin of the expression, "If you believe that, I've got a bridge to sell you": Bluewater, California.

The "bridge" to which I refer crosses the Colorado River, and connects Bluewater, California with its sister-city, Bluewater, Arizona. According to the city's web site, downtown Bluewater offers a range of bars and restaurants where you can dine on seafood fished from local waters, get locally-grown produce from the Farmer's Market every Wednesday and Saturday, and enjoy summer poetry in the park.

Imagine the shock when KVPK7, Bluewater's own local news channel reported that the tiny city had become the target of an attempted suicide bombing ... CONTINUE READING »

11Sep/09

Twitter sends mixed messages

twitter-icon-by-diwa-fernandez

Source: PoeticPixel.info

Twitter's co-founder says your tweets belong to you. Now read the fine print.

For as long as there's been a World Wide Web, there has been debate surrounding the question, "Who owns what users post online?"

Adding fuel to the fire, popular sites like Facebook have written (and withdrawn,) controversial statements into their Terms of Service (ToS) that seemed to suggest that they were asserting ownership over users' content, including photographs, and it's users' "likeness and image". After a massive user outcry, and even some backlash, Facebook was forced to rewrite its TOS, and even allowed users to vote between two versions.

Now, in an apparent attempt to get in front of this kind of momentum, Twitter co-founder Biz Stone announced in a blog post that new changes to the company's ToS would assure that -- though Twitter is allowed to "use, copy, reproduce, process, adapt, modify, publish, transmit, display and distribute" its user's Tweets -- "they are your tweets and they belong to you". ... CONTINUE READING »

10Sep/09

Let’s play $100 Password!

$100 Dollar Password

You probably won't find much sympathy for Elane Cioni. A mistress scorned, she's been convicted of hacking into the email account of her former-boss, the man with whom she was having an affair, and then his wife, his other girlfriends, and even his kids. (I suppose, that doesn't engender much sympathy for her main-target either.) But, you might be surprised to find out Cioni's not a very good hacker.

You might also be surprised to learn that there's a market for professional hacking and, similar to many legitimate professions, the jobs are going offshore. When it comes to password hacking, those who can, do. Those who can't, outsource. When Cioni wanted back into her boyfriend's life she turned to one of an increasing number of web sites with offers like this:

"Need to monitor your Child? Your Spouse? Your Boyfriend/Girlfriend? We Hack Passwords for $100 USD. We Crack all major web based emails. This include Hotmail, Yahoo! AOL and Gmail. We Provide Proofs Before payment." ... CONTINUE READING »

9Sep/09

Electronic privacy is for the birds.

Source: Wikipedia

Source: Wikipedia

In a match between Bird-brain vs. broadband, you might be surprised to see who wins.

An old friend of mine pointed out what sounded like an interesting story out of South Africa. Tired of slow download speeds, a South African call center pitted a racing pigeon against Telkom South Africa Ltd.’s ADSL data service to see which could move a 4GB file faster. In total it took just under three hours for the bird to fly approximately 50 miles--about 30 times faster than the ADSL service, which had only downloaded 4% of the file in the same time.

I'm afraid we're not really comparing apapane to apapane, or even apapane to ostriches. I doubt, for instance, that the pigeon would fair quite as well over, say, a 500 or 5000 mile "data run". ... CONTINUE READING »

4Sep/09

Wi-Fi security — gone in 60 seconds, AGAIN.

Wi-Fi_ZoneYou're not one of those people who leave their wi-fi network open to anyone who passes by, are you? You realize, of course, that--beside the obvious security risks to your computers, your network, your passwords, email, accounting files, your bank account, private identity, maybe even sensitive medical information--that anything someone else does on your network will be traced back to you--the resident and ISP subscriber? Say, for example, the kid next door decides to use your "lightning fast DSL" to download, or worse--share--his music collection via Bit Torrent. The RIAA subpoena will be addressed to you. Or, suppose someone driving by decides to stop and explore his sexual curiosities where they can't be traced back to his network. The search warrant will be addressed to you.

But, that's not your problem, right? Because your wi-fi network is encrypted, right? I remember, back in the day, I used to brag that it would be easier to poach my cable connection from the street than hack my wi-fi, because I was using WEP encryption (cracked in 2001), a MAC filter (easily spoofed), AND I cloaked my SSID (worthless). Since then, came WPA, and more recently WPA2.

Linksys settings for WPA2 wireless secruity.

Linksys settings for WPA2 wireless secruity.

If I lost you at "lighting fast DSL", then the following probably is your problem: Computer scientists in Japan have developed a way to break the WPA encryption system used in wireless routers in just one minute. For those keeping up, presumably you upgraded your router firmware some time back, or purchased and configured a new router to utilize WPA2--which is, so far, considered to be secure. ... CONTINUE READING »

2Sep/09

Good news for bad behavior: Cyberbullying mom aquitted.

Source: Reuters

Source: Reuters

Lori Drew will likely forever be known as the mom found guilty of "cyberbullying" and taunting teenager Megan Meier to commit suicide. Nothing, however, could be further from fact. Drew was, in fact, found guilty of violating MySpace's terms of service (ToS), by posing as a fictitious teenage boy, AKA "Josh Evans". A victory, perhaps, far greater for the software industry than for the Meier family.

Similar to convicting Al Capone for income tax evasion, ToS violations are more commonly associated with hacker prosecutions. US District Judge George Wu has now overturned the ruling, saying that the conviction could have set a dangerous precedent for other legal cases. ... CONTINUE READING »

31Aug/09

U.S. Gov. authorizes long-layovers for laptops.

DHSIt's sometimes hard to remember, but it wasn't that long ago that most carry-on's bypassed so much as an x-ray screening. Then came the obligatory laptop and shoe removal. And, eventually, the "drink 'em or lose 'em" rule, accompanied by the ever-perplexing debate over what constitutes a "liquid", and how many ounces of it you can carry through a TSA line.

(I once overheard a TSA agent explaining to a traveler that, "anything that can be liquefied is a liquid". I felt compelled to explain that, at the right temperature, the whole airplane could be liquefied--but kept my mouth shut, for fear of missing my flight.)

In recent months, some international travelers have been greeted with an indignity that makes the "patdown" look like a "fist-bump". In the past 10 months, over 1000 people had their laptop computers "detained" and subsequently searched. Most would assume that this was with probable cause, but, the DHS maintains that probable cause is not required for such a search. ... CONTINUE READING »

Join the conversation...

Join the conversation on Twitter

Join the conversation on Facebook

disquslogo_180 Subscribe to RSS feed

Join the Google conversaton…

Get email updates:

Geo Visitors Map