<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HazDat &#187; Privacy</title>
	<atom:link href="http://hazdat.com/category/privacy/feed/" rel="self" type="application/rss+xml" />
	<link>http://hazdat.com</link>
	<description>YOUR GADGETS ARE SPYING ON YOU</description>
	<lastBuildDate>Mon, 21 Jun 2010 23:10:21 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>FTC Queues-in on Netflix Member Privacy</title>
		<link>http://hazdat.com/ftc-queues-in-on-netflix-member-privacy/</link>
		<comments>http://hazdat.com/ftc-queues-in-on-netflix-member-privacy/#comments</comments>
		<pubDate>Mon, 15 Mar 2010 02:44:02 +0000</pubDate>
		<dc:creator>Jeff M. Fischbach</dc:creator>
				<category><![CDATA[Big Brother]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[Crime]]></category>
		<category><![CDATA[Future Proof]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Search & Seizure]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Society]]></category>
		<category><![CDATA[Surveillance]]></category>
		<category><![CDATA[TV]]></category>
		<category><![CDATA[Tracking]]></category>

		<guid isPermaLink="false">http://hazdat.com/?p=1202</guid>
		<description><![CDATA[
			
				
			
		
Attn. MPAA: There are much worse ways to copy movies than with a computer.
In 2007 prosecutors in Anchorage Alaska accused 34 year old stripper  of plotting a murder based on the 1994 movie "". Life so closely imitated art, said prosecutors, that they even tried to have the movie played for the jury.
In 2008 [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fhazdat.com%2Fftc-queues-in-on-netflix-member-privacy%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fhazdat.com%2Fftc-queues-in-on-netflix-member-privacy%2F&amp;source=HazDat&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<h2><a href="http://hazdat.com/wp-content/uploads/2010/03/netflix-logo.jpg" ><img class="alignleft size-medium wp-image-1201" title="netflix-logo" src="http://hazdat.com/wp-content/uploads/2010/03/netflix-logo-300x179.jpg" alt="" width="300" height="179" /></a>Attn. MPAA: There are much worse ways to copy movies than with a computer.</h2>
<p>In 2007 prosecutors in Anchorage Alaska accused 34 year old stripper <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Mechele Linehan', '');">Mechele Linehan</a> of plotting a murder based on the 1994 movie "<a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('The Last Seduction', '');">The Last Seduction</a>". <strong>Life so closely imitated art, said prosecutors, that they even tried to have the movie played for the jury.</strong></p>
<div id="attachment_1204" class="wp-caption alignright" style="width: 160px"><a href="http://hazdat.com/wp-content/uploads/2010/03/grandtheft-11248235-high.jpg" ><img class="size-thumbnail wp-image-1204" title="Rockstar Games Grand Theft Auto" src="http://hazdat.com/wp-content/uploads/2010/03/grandtheft-11248235-high-150x150.jpg" alt="" width="150" height="150" /></a><p class="wp-caption-text">Rockstar Games Grand Theft Auto</p></div>
<p>In 2008 a <a href="http://news.zdnet.com/2100-9595_22-214284.html" title="ZDNet: Thailand halds 'Grand Theft Auto' sales after murder"  target="_blank">teenager confessed</a> that he was trying to imitate scenes from the video game "<a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Grand Theft Auto', '');">Grand Theft Auto</a>" when he robbed a murdered a taxicab driver in <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Bangkok', '');">Bangkok</a> <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Thailand', '');">Thailand</a>. Movies like "<a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('The Deer Hunter movie', '');">The Deer Hunter</a>" (1978) are even believed to have inspired several "copycat" suicides in the late 1970's and early 80's.</p>
<p>All of this may seem like fodder for <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('censorship', '');">censorship</a> advocates, but that debate has largely come and gone in favor preserving the <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('First Amendment', '');">First Amendment's</a> right to <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('free speech', '');">free speech</a>. Wise as the framers of the <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('U.S. Constitution', '');">U.S. Constitution</a> may have been, few would accuse them of being <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('clairvoyant', '');">clairvoyant</a>. After all, who could have predicted the impact the Internet would some day have on both the precept of <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('free speech', '');">free speech</a> and the concept of privacy?</p>
<p>Though many speak of <strong>the "<a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('right to privacy', '');">right to privacy</a>", it is not, at least as far as the <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('U.S. Constitution', '');">U.S. Constitution</a> is concerned, a right at all</strong>. It is, nonetheless, an ethos that has long been coveted by Americans, and is implicit in the <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Fourth Amendment', '');">Fourth Amendment's</a>:</p>
<blockquote><p><em>...right of the people to be secure in their persons,   houses, papers, and effects, against unreasonable searches and seizures... </em></p></blockquote>
<p>Of course, mention the term "search" to most people today, and it's far more likely to conjure thoughts of friends lists", home pages and e-books, than <em>actual</em> people, houses and papers. And while, in just the past few years, popular culture has come to embrace the sharing of intimate, private and personal details with virtual strangers, the desire to remain "secure" seems to be very much alive in the 21st Century. In fact, more than any other, the <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Fourth Amendment', '');">Fourth Amendment</a> has played a central, albeit contested, role in the litigation of hi-tech criminal evidence.</p>
<h3>I know what you watched last summer...</h3>
<p>So, what does all this have to do with your <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Netflix queue', '');">Netflix queue</a>? Though Americans, and many other people around the world, may be willing to voluntarily divulge personal information, either in trade for modern conveniences and services, or increasingly, for a sense of online significance, we're not quite as enthusiastic when it's taken from us and shared without any tangible return. It's no longer a secret that the monetary value of data has been pre-calculated into the <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('return on investment', '');">return on investment (ROI)</a> of so many of today's business models, but consumers still tend to expect a certain level of security. In recent years the bar has been set pretty low. Still, it may surprise many to learn that<strong> "anonymous" usage data can be deciphered into personally-identifiable intelligence</strong>, as <a href="pair of researchers at the University of Texas" target="_blank">proven by a pair of researchers at the University of Texas</a> using what was thought to be anonymous user data provided to contestants in the three-year <a href="http://www.netflixprize.com/"  target="_blank">$1 million "Netflix Prize"</a> to improve the site's recommendation results.</p>
<p>The <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('University of Texas', '');">UT</a>'s results brought both unwanted attention from the <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Federal Trade Commission', '');">Federal Trade Commission</a> and a lawsuit from a private firm, resulting in <strong><a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Netflix', '');">Netflix's</a>  decision last week to cancel a planned sequel to the <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Netflix Prize', '');">prize</strong> awarded last year</a>.</p>
<p><strong>It's not hard to imagine how this sort of data could be exploited to peddle shoes to people who have rented all six seasons of "<a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Sex in the City', '');">Sex in the City</a>"</strong>, or <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('BestBuy', '');">BestBuy</a> ads targeted at fans of NBC's "<a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Chuck (TV series)', '');">Chuck</a>".</p>
<div id="attachment_1225" class="wp-caption alignleft" style="width: 310px"><a href="http://hazdat.com/wp-content/uploads/2010/03/minority-report-ui-29787-20090331-3.jpg" ><img class="size-medium wp-image-1225" title="Dreamworks Minority Report (2002)" src="http://hazdat.com/wp-content/uploads/2010/03/minority-report-ui-29787-20090331-3-300x200.jpg" alt="" width="300" height="200" /></a><p class="wp-caption-text">Dreamworks Minority Report (2002)</p></div>
<p>It's no longer extraordinary to see similar data exploited in the process of investigating crimes either. Certainly the viewing interests and habits of the individuals mentioned above have been considered relevant discovery by law enforcement. In these cases, there's little, if anything, to decipher.  <strong>Anything that <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Netflix', '');">Netflix</a> knows about you, your account, and your viewing habits, is subject to a </strong><a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('search warrant', '');">warrant</a>, and, with or without much imagination, could be incriminating. How many of us haven't seen a good fictional car case, a well-written murder plot, a scripted street-fight, or a perfectly executed crime? The consumption of such fiction could be hazardous to your defense, if it proceeds similar accusations.</p>
<p>Now, imagine the same evidence available to anyone, without a <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('search warrant', '');">warrant</a>, <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('subpoena', '');">subpoena</a>, or <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('probable cause', '');">probable cause</a>. <strong>Perhaps someone at the <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Federal Trade Commission', '');">FTC</a> had the movie "<a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Minority Report (film)', '');">Minority Report</a>" in <em>their</em> queue.</strong></p>
<div id="textwise_suggestions"><h4 id='twBlogs'>Similar Blog & News Articles</h4><ul><li><a target="_blank" href="http://techliberation.com/2010/02/25/laptop-spying-and-the-fourth-amendment/" >Laptop Spying and the Fourth Amendment</a> :: <em><a target="_blank" href="http://techliberation.com" >Technology Liberation Front</a></em></li><li><a target="_blank" href="http://feedproxy.google.com/~r/wired27b/~3/litBSELpFvY/" >NetFlix Cancels Recommendation Contest After Privacy Lawsuit</a> :: <em><a target="_blank" href="http://www.wired.com/threatlevel" >Wired: Threat Level</a></em></li></ul><h4 id='twWiki'>Similar Wikipedia Articles</h4><ul><li><a target="_blank" href="http://en.wikipedia.org/wiki/Process%20of%20the%20accused%20person" >Process of the accused person</a></li><li><a target="_blank" href="http://en.wikipedia.org/wiki/Netflix" >Netflix</a></li><li><a target="_blank" href="http://en.wikipedia.org/wiki/Exclusionary%20rule" >Exclusionary rule</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://hazdat.com/ftc-queues-in-on-netflix-member-privacy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Infidelity &#8212; There&#8217;s a map for that.</title>
		<link>http://hazdat.com/infidelity-theres-a-map-for-that/</link>
		<comments>http://hazdat.com/infidelity-theres-a-map-for-that/#comments</comments>
		<pubDate>Fri, 13 Nov 2009 04:22:36 +0000</pubDate>
		<dc:creator>hazdat</dc:creator>
				<category><![CDATA[Big Brother]]></category>
		<category><![CDATA[Cellular]]></category>
		<category><![CDATA[Future Proof]]></category>
		<category><![CDATA[GPS]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Society]]></category>
		<category><![CDATA[Surveillance]]></category>

		<guid isPermaLink="false">http://hazdat.com/?p=1168</guid>
		<description><![CDATA[
			
				
			
		
How Google might know what you did last summer -- even if you forgot.
 is a service that allows users to see and share their location on a  live and in real-time. The service runs on most smart-phones, regardless of service provider, including , , the , and, of course, . Latitude relies on [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fhazdat.com%2Finfidelity-theres-a-map-for-that%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fhazdat.com%2Finfidelity-theres-a-map-for-that%2F&amp;source=HazDat&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<h2>How Google might know what you did last summer -- even if you forgot.</h2>
<p><img class="alignleft size-medium wp-image-1172" title="google-latitude-781430" src="http://hazdat.com/wp-content/uploads/2009/11/google-latitude-781430-225x300.jpg" alt="google-latitude-781430" width="225" height="300" /><a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Google Latitude', '');">Google Latitude</a> is a service that allows users to see and share their location on a <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Google map', '');">Google map</a> live and in real-time. The service runs on most smart-phones, regardless of service provider, including <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Apple iPhone', '');">Apple's iPhone</a>, <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Windows Mobile', '');">Windows Mobile</a>, the <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Palm Pre', '');">Palm Pre</a>, and, of course, <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Google Android', '');">Google's Android</a>. Latitude relies on a combination of <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('GPS', '');">GPS</a>, <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('cellular tower triangulation', '');">cellular tower triangulation</a>, and <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('wi-fi triangulation', '');">wi-fi triangulation</a>. Having brushed-up on the service for a recent <a href="http://hazdat.com/location-location-location/" >National Public Radio (NPR) Interview</a>, I have since considered Latitude one-part creepy, and two-parts cool. However, the creepy / cool ratio may be shifting.</p>
<p>This week Google introduced a <em>new and improved</em> Google Latitude -- with enhanced features like "Location History".  With Location History <strong>Latitude users can go back in time retrace their footsteps</strong>, and even see where they stayed-put, and for how long. Kind of cool...yet, very creepy. But practical?</p>
<p>Imagine, for example, you're the owner of a Palm Pre on <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Sprint Now Network', '');">Sprint's 3G Now Network</a><em> </em>, having trouble remembering where your were when you told your spouse you were somewhere else? Now, there's a map for that!</p>
<p>But wait -- there's more! How about "Location Alerts"? Certainly, a application that would alert you when a particular individual, say a family member, has left work or school, would be very practical. After a while of being alerted every time someone <em>is</em>, or <em>has </em>arrived, exactly where you would expect them to be, however, could get old. So, Google's geniuses stepped it up a notch. According to Google, <strong>Latitude will learn user's patterns and behavior so that alerts can be issued when a person has strayed from their routine</strong> -- left at a different time, or arrived at a different place.</p>
<p>For example, if you decide to <em> </em><a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('staycation', '');">staycation</a> with your mistress, you can receive a handy alert when your spouse leaves the office earlier than usual. Or, if traffic is particularly light, Latitude will let you know when it's time for a quick window-exit.</p>
<p>Best of all, when the jig is up, no one has to know, because -- for now -- Google is making all these free services available to you, and no one else... at least, without subpoena powers.</p>
<p>This is deception... on the Now Network.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="295" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/Lo3spGfg7D8&amp;hl=en_US&amp;fs=1&amp;" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="480" height="295" src="http://www.youtube.com/v/Lo3spGfg7D8&amp;hl=en_US&amp;fs=1&amp;" allowfullscreen="true" allowscriptaccess="always"></embed></object></p>
<div id="textwise_suggestions"><h4 id='twBlogs'>Similar Blog & News Articles</h4><ul><li><a target="_blank" href="http://mashable.com/2009/11/10/google-latitude-features/" >Google Latitude Now Tracks Location History, Alerts You to Nearby Friends</a> :: <em><a target="_blank" href="http://mashable.com" >Mashable!</a></em></li><li><a target="_blank" href="http://www.eweek.com/c/a/Mobile-and-Wireless/Google-Cranks-Creepy-Meter-with-Latitude-Location-History-Alerts-764971/?kc=rss" >Google Cranks Creepy Meter with Latitude Location History, Alerts</a> :: <em><a target="_blank" href="http://www.eweek.com" >eWeek - RSS Feeds</a></em></li><li><a target="_blank" href="http://feeds.gawker.com/~r/lifehacker/full/~3/-Z4r5NfOgg0/google-latitude-adds-location-history-alerts-you-when-friends-are-nearby" >Google Latitude Adds Location History, Alerts You When Friends Are Nearby Google Maps</a> :: <em><a target="_blank" href="http://lifehacker.com" >Lifehacker</a></em></li><li><a target="_blank" href="http://www.technewsworld.com/rsstory/68623.html" >Google Latitude Lets Users Follow Their Own Footprints</a> :: <em><a target="_blank" href="http://www.technewsworld.com" >TechNewsWorld</a></em></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://hazdat.com/infidelity-theres-a-map-for-that/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Location, Location, Location.</title>
		<link>http://hazdat.com/location-location-location/</link>
		<comments>http://hazdat.com/location-location-location/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 01:44:52 +0000</pubDate>
		<dc:creator>Jeff M. Fischbach</dc:creator>
				<category><![CDATA[Big Brother]]></category>
		<category><![CDATA[Cellular]]></category>
		<category><![CDATA[Crime]]></category>
		<category><![CDATA[Future Proof]]></category>
		<category><![CDATA[GPS]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Society]]></category>
		<category><![CDATA[Surveillance]]></category>
		<category><![CDATA[Tracking]]></category>

		<guid isPermaLink="false">http://hazdat.com/?p=1161</guid>
		<description><![CDATA[
			
				
			
		
Recently, I had a wonderful opportunity to play a game of hi-tech "phone tag" on the streets of San Francisco with Reporter Martin Kaste from  "". Late last Summer I was  asked if I would be willing to sit down for an interview for a story he was researching about location privacy. But, instead of agreeing to meet Kaste, [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fhazdat.com%2Flocation-location-location%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fhazdat.com%2Flocation-location-location%2F&amp;source=HazDat&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Recently, I had a wonderful opportunity to play a game of hi-tech "phone tag" on the streets of San Francisco with Reporter <a href="http://www.npr.org/templates/story/story.php?storyId=2100722"  target="_blank">Martin Kaste </a>from <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('National Public Radio', '');">NPR's</a> "<a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('NPR All Things Considered', '');">All Things Considered</a>". Late last Summer I was  asked if I would be willing to sit down for an interview for a story he was researching about location privacy. But, instead of agreeing to <em>meet</em> Kaste, I told him he had to <em>find me</em>.</p>
<p>With the aid of his <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('GPS', '');">GPS</a>-equipped smart-phone, some software, a little patience, and a good pair of walking shoes, he <em>was</em> able to "tag" me sipping a latte outside a <a href="http://maps.google.com/maps?q=coffee+bean+market+st.+san+francisco&amp;hl=en&amp;cd=1&amp;ei=QfLoSvDhFJfEswOk0JGrDA&amp;sig2=kFkQwdF8WwNwLUmkXM77ug&amp;ie=UTF8&amp;view=map&amp;cid=2396659131338718014&amp;iwloc=A"  target="_blank">coffee shop on Market St.</a> Of course, with my own GPS, and software-equipped smart-phone, I was able to see him coming. What follows are the fruits of that encounter:</p>
<h2>Digital Bread Crumbs: Following Your Cell Phone Trail</h2>
<blockquote><p><em>Jeff Fischbach is a little bit like those guys in The Matrix — when he puts on his shades and looks at the world, he sees data.</em></p>
<p><em>Walking down the street in San Francisco, he points out all the devices that record people's comings and goings: digital parking meters, apartment intercom systems, digital security cameras...</em></p></blockquote>
<a class='wpaudio wpaudio_readid3' href='<a'><a</a>
<p>Audio and transcript: <a target="_blank" href="http://www.npr.org/templates/story/story.php?storyId=114241860&amp;ft=1&amp;f=1019" >http://www.npr.org/templates/story/story.php?storyId=114241860&amp;ft=1&amp;f=1019</a></p>
<div id="textwise_suggestions"><h4 id='twBlogs'>Similar Blog & News Articles</h4><ul><li><a target="_blank" href="http://www.npr.org/templates/story/story.php?storyId=114241860&ft=1&f=1003" >Digital Bread Crumbs: Following Your Cell Phone Trail</a> :: <em><a target="_blank" href="http://www.npr.org/templates/story/story.php?storyId=1003&ft=1&f=1003" >NPR Topics: U.S.</a></em></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://hazdat.com/location-location-location/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The problem is, banks have too many humans.</title>
		<link>http://hazdat.com/bank-emails-customer-records-to-wrong-gmail-account/</link>
		<comments>http://hazdat.com/bank-emails-customer-records-to-wrong-gmail-account/#comments</comments>
		<pubDate>Mon, 28 Sep 2009 15:30:47 +0000</pubDate>
		<dc:creator>Jeff M. Fischbach</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Crime]]></category>
		<category><![CDATA[Duh]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Search & Seizure]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://hazdat.com/?p=1061</guid>
		<description><![CDATA[
			
				
			
		
What do you call the sacrifice of one person's privacy in an attempt to save  the privacy of over 1300? If you're a bank, you call it collateral damage.
When I was a kid I earned my first paycheck passing out fliers for a neighbor who was starting a pool cleaning business. With my first [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fhazdat.com%2Fbank-emails-customer-records-to-wrong-gmail-account%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fhazdat.com%2Fbank-emails-customer-records-to-wrong-gmail-account%2F&amp;source=HazDat&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<h2>What do you call the sacrifice of one person's privacy in an attempt to save  the privacy of over 1300? If you're a bank, you call it collateral damage.</h2>
<p><a href="http://hazdat.com/wp-content/uploads/2009/09/rmb-logo.jpg" ><img class="alignright size-medium wp-image-1063" title="rmb-logo" src="http://hazdat.com/wp-content/uploads/2009/09/rmb-logo-300x162.jpg" alt="rmb-logo" width="300" height="162" /></a>When I was a kid I earned my first paycheck passing out fliers for a neighbor who was starting a pool cleaning business. With my first $13 in hand, my grandfather took me to the a bank in walking distance to my home, got me a tour of the vault from the branch manager, a neat pouch to hold all my coin, a full explanation of the principals of savings and loans, and helped me open my very first savings account. Believe it or not, back then, all my account information was stored on a double-sided index card behind the teller.</p>
<p>Today, things are much more complicated. Gone are the index cards and <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('passbooks', '');">passbooks</a>, most of the employees, tellers and branches, a good deal of the service, interest-bearing accounts with only $13 in them, and a lot of the customers' money. <strong>Today, it's all computerized</strong>, and most <strong>banks even attach various penalties to discourage human contact.</strong></p>
<p>I know an awful lot about electronic data systems, but I don't pretend to fully understand how the modern banking system works. Sometimes, I think I do--from a mechanical (as opposed to financial) perspective. But then something convinces me that I don't. For instance, <strong>you know how every so often your bank emails its customers'  names, addresses, Social Security numbers, and loan information to Gmail?</strong><span id="more-1061"></span></p>
<p>To be completely honest, I didn't know they did that either, until I found out recently that <strong>The Rocky Mountain Bank in Wyoming had sent 1,325 such records to the <em>wrong</em> Gmail account.</strong> (Mind you, most would have trouble imagining who could <em>possibly</em> be the <em>right</em> recipient.) Once the error was noticed, the bank attempted to contact the recipient to request immediate destruction of the email and its attachment. When the bank received no response, a request was made to Google for the recipient's identity. <strong>Citing its privacy policy, Google refused to provide the information requested, and the bank filed suit.</strong></p>
<p>According to <a target="_blank" href="http://www.wired.com/images_blogs/threatlevel/2009/09/rocky-mountan-bank-v-google.pdf" >court documents</a>:</p>
<blockquote><p>"On August 12, 2009, Plaintiff received a request from one of its customers for Plaintiff to send certain loan statements to a third-party representative of that customer. That same day, an employee of Plaintiff attempted to send the requested information to the customer’s representative via email. The next day, <strong>Plaintiff discovered that its employee had inadvertently sent the email to the wrong Gmail email address. In addition, Plaintiff discovered that attached to the email was a file containing confidential customer information for 1,325 individual and business customer accounts</strong> for customers other than just the customer who requested information. The confidential information includes names, addresses, tax identification numbers, and loan information for each of the 1,325 customer accounts.</p>
<p>After learning of its inadvertent disclosure of confidential customer information, Plaintiff tried to recall the email without success. It then sent another <strong>email to the Gmail address, instructing the recipient to immediately delete the prior email and the attached file in its entirety without opening or reviewing it.</strong> Plaintiff also <strong>requested that the recipient contact Plaintiff to discuss his or her actions.</strong> The recipient has not responded to Plaintiff’s email."</p></blockquote>
<p>Ironically, in a case that pits the privacy interests of innocent parties against each other, the protagonists of this story had some privacy concerns of their own. <strong>The Bank's lawyers attempted to file their suit <a target="_blank" href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Record_sealing', '');">under seal</a></strong> -- which was denied by <span>the U.S. District Court. Though not mentioned in the court's ruling on this issue, <strong><a href="http://www.ncsl.org/Default.aspx?TabId=13489" >most states</a> have <a target="_blank" href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Security_breach_notification_laws', '');">security breach notification laws</a> </strong>that <em>require </em>disclosure of any records that may have gotten into the hands of unauthorized individuals. Wyoming does, indeed, have such a law (</span><a href="http://legisweb.state.wy.us/statutes/compress/title40.doc" >40-12-502. "Computer security breach; notice to affected persons"</a>)<span>. It states:</span></p>
<blockquote><p>"(a)  An individual or commercial entity that conducts business in Wyoming and that owns or licenses computerized data that includes personal identifying information about a resident of Wyoming shall, when it becomes aware of a breach of the security of the system, conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal identifying information has been or will be misused.  If the investigation determines that the misuse of personal identifying information about a Wyoming resident has occurred or is reasonably likely to occur, the individual or the commercial entity shall give notice as soon as possible to the affected Wyoming resident."</p></blockquote>
<p><span>While the bank was compounding errors by ignoring its obligations to its customers and state law, their case against Google was being reviewed by <strong>another judge who ordered Google to disable the account, and disclose the recipient's identity. </strong></span></p>
<p>The Rocky Mountain Bank<span> maintains that it contacted the recipient more than once and requested that the individual respond to requests to "</span>discuss his or her actions". <strong>The implication is that, had the recipient responded, this whole matter could have been handled amicably and honorably -- among gentlemen</strong>, as it were. I wonder if, from the perspective of the bank, its customers, or even the email recipient, a "discussion" would have really sufficed. I know, as a bank customer, John Doe's <em>word</em> that he had deleted all my personal information from his Gmail account wouldn't satisfy <em>me </em>at all. If I were in charge of bank security, I don't think I'd be very satisfied either. In either case, I suppose I would be demanding <em>proof</em> that had been deleted, never copied, forwarded, or printed, and probably some kind of connotative memory-wipe.</p>
<p>Years ago, I was consulted by a judge after a District Attorney's office "accidentally" obtained access to a defense lawyer's hard drive (quotes inserted to cite the provided explanation, not my personal feelings about the explanation). The negotiated remedy and order was an extensive forensic search of the DA's hard drives, and a complete wipe of their contents -- even when the search turned up no conclusive evidence that the DA had ever examined any privileged materials. But I doubt any accidental recipient would agree to that -- especially a civilian. And why should they?</p>
<p>Of course, no one knows, at this point, if the recipient ever saw the message. <strong>Many reading this web site would likely have dismissed it, and any subsequent messages from the bank as a <a target="_blank" href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('phishing', '');">phishing</a> scam. </strong>The Rocky Mountain Bank even has a <a href="https://www.rockymountainbank.com/home/fiFiles/static/documents/PhishingAlert.pdf" >link</a> to an oddly nondescript PDF addressing the subject of phishing scams.</p>
<p>There's really no reason to believe that the bank ever considered litigation to be an entirely avoidable option, no matter how cooperative the recipient might have been. Nor am I convinced that the court's decision has provided any comfort to the individual's who's privacy has been sacrificed -- including <strong>the one who's email account has been disabled, and personal information shared with a bank that's already demonstrated that they can't be trusted with the information.</strong></p>
<p>So, if suing Google won't assure its customers' privacy and financial security, what should the bank have done? That's an easy one. Ask any programmer. They'll tell you: <strong>The only way to fix a <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('1D10T', '');">1D10T</a> error is to upgrade your <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Wetware_(brain)', '');">wetware</a> and reboot.</strong></p>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 619px; width: 1px; height: 1px;"><!--[if gte mso 9]><xml> <w:WordDocument> <w:View>Normal</w:View> <w:Zoom>0</w:Zoom> <w:TrackMoves /> <w:TrackFormatting /> <w:PunctuationKerning /> <w:ValidateAgainstSchemas /> <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid> <w:IgnoreMixedContent>false</w:IgnoreMixedContent> <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText> <w:DoNotPromoteQF /> <w:LidThemeOther>EN-US</w:LidThemeOther> <w:LidThemeAsian>X-NONE</w:LidThemeAsian> <w:LidThemeComplexScript>X-NONE</w:LidThemeComplexScript> <w:Compatibility> <w:BreakWrappedTables /> <w:SnapToGridInCell /> <w:WrapTextWithPunct /> <w:UseAsianBreakRules /> <w:DontGrowAutofit /> <w:SplitPgBreakAndParaMark /> <w:DontVertAlignCellWithSp /> <w:DontBreakConstrainedForcedTables /> <w:DontVertAlignInTxbx /> <w:Word11KerningPairs /> <w:CachedColBalance /> </w:Compatibility> <w:BrowserLevel>MicrosoftInternetExplorer4</w:BrowserLevel> <m:mathPr> <m:mathFont m:val="Cambria Math" /> <m:brkBin m:val="before" /> <m:brkBinSub m:val="&#45;-" /> <m:smallFrac m:val="off" /> <m:dispDef /> <m:lMargin m:val="0" /> <m:rMargin m:val="0" /> <m:defJc m:val="centerGroup" /> <m:wrapIndent m:val="1440" /> <m:intLim m:val="subSup" /> <m:naryLim m:val="undOvr" /> </m:mathPr></w:WordDocument> </xml><![endif]--><!--[if gte mso 9]><xml> <w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"   DefSemiHidden="true" DefQFormat="false" DefPriority="99"   LatentStyleCount="267"> <w:LsdException Locked="false" Priority="0" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Normal" /> <w:LsdException Locked="false" Priority="9" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="heading 1" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9" /> <w:LsdException Locked="false" Priority="39" Name="toc 1" /> <w:LsdException Locked="false" Priority="39" Name="toc 2" /> <w:LsdException Locked="false" Priority="39" Name="toc 3" /> <w:LsdException Locked="false" Priority="39" Name="toc 4" /> <w:LsdException Locked="false" Priority="39" Name="toc 5" /> <w:LsdException Locked="false" Priority="39" Name="toc 6" /> <w:LsdException Locked="false" Priority="39" Name="toc 7" /> <w:LsdException Locked="false" Priority="39" Name="toc 8" /> <w:LsdException Locked="false" Priority="39" Name="toc 9" /> <w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption" /> <w:LsdException Locked="false" Priority="10" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Title" /> <w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font" /> <w:LsdException Locked="false" Priority="11" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Subtitle" /> <w:LsdException Locked="false" Priority="22" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Strong" /> <w:LsdException Locked="false" Priority="20" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Emphasis" /> <w:LsdException Locked="false" Priority="59" SemiHidden="false"    UnhideWhenUsed="false" Name="Table Grid" /> <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text" /> <w:LsdException Locked="false" Priority="1" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="No Spacing" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 1" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 1" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 1" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 1" /> <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision" /> <w:LsdException Locked="false" Priority="34" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="List Paragraph" /> <w:LsdException Locked="false" Priority="29" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Quote" /> <w:LsdException Locked="false" Priority="30" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Intense Quote" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 1" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 1" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 1" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 1" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 1" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 2" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 2" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 2" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 2" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 2" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 2" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 2" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 2" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 2" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 3" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 3" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 3" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 3" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 3" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 3" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 3" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 3" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 3" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 4" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 4" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 4" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 4" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 4" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 4" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 4" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 4" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 4" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 5" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 5" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 5" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 5" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 5" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 5" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 5" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 5" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 5" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 6" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 6" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 6" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 6" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 6" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 6" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 6" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 6" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 6" /> <w:LsdException Locked="false" Priority="19" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis" /> <w:LsdException Locked="false" Priority="21" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis" /> <w:LsdException Locked="false" Priority="31" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference" /> <w:LsdException Locked="false" Priority="32" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Intense Reference" /> <w:LsdException Locked="false" Priority="33" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Book Title" /> <w:LsdException Locked="false" Priority="37" Name="Bibliography" /> <w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading" /> </w:LatentStyles> </xml><![endif]--><!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman","serif"; 	mso-fareast-font-family:"Times New Roman";} span.section 	{mso-style-name:section; 	mso-style-unhide:no; 	mso-ansi-font-size:12.0pt; 	font-family:"Courier New"; 	mso-ascii-font-family:"Courier New"; 	mso-hansi-font-family:"Courier New";} span.mspace 	{mso-style-name:mspace; 	mso-style-unhide:no; 	mso-style-parent:""; 	mso-ansi-font-size:12.0pt; 	font-family:"Courier New"; 	mso-ascii-font-family:"Courier New"; 	mso-hansi-font-family:"Courier New";} p.L1, li.L1, div.L1 	{mso-style-name:L1; 	mso-style-unhide:no; 	margin:0in; 	margin-bottom:.0001pt; 	text-indent:.2in; 	mso-pagination:widow-orphan; 	mso-layout-grid-align:none; 	punctuation-wrap:simple; 	text-autospace:none; 	font-size:12.0pt; 	mso-bidi-font-size:10.0pt; 	font-family:"Courier New"; 	mso-fareast-font-family:"Times New Roman"; 	mso-bidi-font-family:"Times New Roman";} span.sectioncatch 	{mso-style-name:sectioncatch; 	mso-style-unhide:no; 	mso-ansi-font-size:12.0pt; 	font-family:"Courier New"; 	mso-ascii-font-family:"Courier New"; 	mso-hansi-font-family:"Courier New";} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	font-size:10.0pt; 	mso-ansi-font-size:10.0pt; 	mso-bidi-font-size:10.0pt;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --><!--[if gte mso 10]> <mce:style><!   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} --> <!--[endif]--></p>
<p class="L1"><span class="section"><strong><span>40‑12‑502.</span></strong></span><span class="mspace"><strong><span> </span></strong></span><span class="sectioncatch"><strong><span>Computer security breach; notice to affected persons.</span></strong></span></p>
</div>
<div id="textwise_suggestions"><h4 id='twBlogs'>Similar Blog & News Articles</h4><ul><li><a target="_blank" href="http://feedproxy.google.com/~r/wired27b/~3/YmIt1olUtkc/" >Bank Sends Sensitive E-mail to Wrong Gmail Address, Sues Google</a> :: <em><a target="_blank" href="http://www.wired.com/threatlevel" >Wired: Threat Level</a></em></li><li><a target="_blank" href="http://news.cnet.com/8301-27080_3-10362913-245.html?part=rss&subj=news&tag=2547-1_3-0-20" >Google, bank resolve issue over misfired e-mail</a> :: <em><a target="_blank" href="http://news.cnet.com/" >CNET News.com</a></em></li><li><a target="_blank" href="http://feedproxy.google.com/~r/wired27b/~3/LaajhHHDecc/" >Judge Orders Gmail Account Deactivated After Bank Screws Up</a> :: <em><a target="_blank" href="http://www.wired.com/threatlevel" >Wired: Threat Level</a></em></li><li><a target="_blank" href="http://mashable.com/2009/09/24/bank-sues-google-identity/" >Bank Sends Email to Wrong Gmail User, Sues Google For His Identity</a> :: <em><a target="_blank" href="http://mashable.com" >Mashable!</a></em></li><li><a target="_blank" href="http://mashable.com/2009/09/25/bank-sues-google/" >Judge Rules Against Gmail User After Bank Screws Up</a> :: <em><a target="_blank" href="http://mashable.com" >Mashable!</a></em></li><li><a target="_blank" href="http://www.computerworld.com/s/article/9138403/Bank_sues_Google_for_ID_of_Gmail_user?source=rss_news" >Bank sues Google for ID of Gmail user</a> :: <em><a target="_blank" href="http://www.computerworld.com/" >Latest from Computerworld</a></em></li><li><a target="_blank" href="http://www.mercurynews.com/business/ci_13396534?source=rss" >Bank snafu sets up privacy clash with Google</a> :: <em><a target="_blank" href="http://www.mercurynews.com/business/" >Business</a></em></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://hazdat.com/bank-emails-customer-records-to-wrong-gmail-account/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>You Tweet, therefore: YOU ARE HERE.</title>
		<link>http://hazdat.com/twitter-to-scrub-location-data-after-14-days/</link>
		<comments>http://hazdat.com/twitter-to-scrub-location-data-after-14-days/#comments</comments>
		<pubDate>Wed, 23 Sep 2009 21:25:57 +0000</pubDate>
		<dc:creator>Jeff M. Fischbach</dc:creator>
				<category><![CDATA[Big Brother]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[Crime]]></category>
		<category><![CDATA[Future Proof]]></category>
		<category><![CDATA[GPS]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Search & Seizure]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Society]]></category>
		<category><![CDATA[Surveillance]]></category>
		<category><![CDATA[Tracking]]></category>

		<guid isPermaLink="false">http://hazdat.com/?p=998</guid>
		<description><![CDATA[How Twitter says they'll hide your location from twits with subpoenas.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fhazdat.com%2Ftwitter-to-scrub-location-data-after-14-days%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fhazdat.com%2Ftwitter-to-scrub-location-data-after-14-days%2F&amp;source=HazDat&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<h2><a href="http://hazdat.com/wp-content/uploads/2009/09/TwitterMap.jpg" ><img class="alignright size-medium wp-image-1001" title="TwitterVision" src="http://hazdat.com/wp-content/uploads/2009/09/TwitterMap-300x215.jpg" alt="TwitterVision" width="300" height="215" /></a>How Twitter says they'll hide your location from twits with subpoenas.</h2>
<p>Recently, <strong><a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Twitter', '');">Twitter</a> announced that they would be adding <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('geolocation', '');">geolocation</a> features to their service</strong>, allowing users to embed their physical location in their Twitter feed. As not to alarm: Twitter has always maintained that this would be an opt-in feature. But, frankly, <strong><em>any </em>web site you visit is privy to some information about your physical location</strong> by virtue of the <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('IP address', '');">IP address</a> assigned to your computer by your <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Internet Service Provider ', '');">Internet Service Provider </a>(ISP) from a group of IP addresses reserved for your neighborhood. The logs kept by a web server, combined with a <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('subpoena', '');">subpoena</a> to the appropriate ISP, usually yield a street address for the subscriber assigned that IP address.</p>
<p><a target="_blank" href="http://smarterware.org/" >SmarterWare's</a> <a target="_blank" href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Gina Trapani', '');">Gina Trapani</a> (formerly of <a href="http://lifehacker.com/" >Lifehacker.com</a>) is attending the <a target="_blank" href="http://parnassusgroup.com/twitterconference/" >Twitter Conference in LA</a>. She's <a target="_blank" href="http://smarterware.org/3419/details-on-twitters-imminent-geolocation-support-launch" >posted updates</a> explaining how Twitter plans to deploy this service and how they intend to protect its <a target="_blank" href="http://blog.twitter.com/2009/08/location-location-location.html" >Twitter geolocation</a> users from subpoenas. According to Gina, "<strong>Twitter will scrub geo-data stored in tweets more than 14 days old to avoid getting subpoena’d about a user’s location in the past.</strong> They will outright delete the location information from their database, not just anonymize."<span id="more-998"></span></p>
<p>She also reports that while,</p>
<blockquote><p>"Twitter usually encourages developers and applications to cache data, in the case of geo, <strong>they recommend dropping historical location data so that application developers don’t become a subpoena target, either.</strong> They also recommend 'fuzzing' location and time data, so that instead of knowing that Joe Smith was at 8th avenue and 15th street at 2:11PM Eastern time on March 7, 2008, you only show that Joe was in Brooklyn on that day. The geodata-scrubbing isn’t a permanent solution. <strong>They are looking into ways to store this data in a 'safe' (anonymized?) way in the future, so they won’t always scrub +14 day old data</strong>, just at first."</p></blockquote>
<p>Purging data that isn't mission critical, but likely to be subpoenaed makes a lot of sense. After all, no one writes "Satisfy search warrants in a timely, efficient, and effective manner" into their corporate <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('mission statement', '');">mission statement</a>.</p>
<p>While I'm convinced that Twitter's motivation is for the sanctity of the corporation, rather than its user-base, it is a step in the right direction. In fact, the direction is <em>so</em> right that <strong>one has to wonder why <em>all </em>personally identifiable user data isn't "scrubbed" every 14 days from most online services</strong>. Of course, Twitter's <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('raison d'être', '');">raison d'être</a>, is -- among other things -- to give it's user's messages some life and legacy. It's likely that most of those users would also like to take credit for their various flashes of 140 character brilliance.</p>
<p>Not so, however, every time an individual fires off an <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('instant message', '');">instant message</a> (IM), or searches Google. Most instant messaging services, for instance, don't store messages after they are sent, but they <em>do </em>store the sender and recipient's IP addresses, with their account information, and the time they logged in. While <strong>Google relies on demographic data, such as geography, income, and search interests, in order to sell ads, it doesn't need to be personally attributable to me. </strong>Companies like Google, Yahoo!, Facebook, MySpace and AOL are not in the subpoena response business. But, all of these companies employ <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('subpoena compliance', '');">subpoena compliance</a> personnel, who add to the cost of doing business, but contribute nothing to the bottom-line. Worse yet, where nearly every individual in these companies, in some way, does something, either directly or indirectly, to add to the end-user experience, subpoena compliance often works in direct opposition to that objective.</p>
<p>As many companies learn when they're sued, s<strong>ubpoena compliance is often so expensive that it's cheaper to settle. </strong>A company can't be forced to produce what they don't have. And, with some significant exceptions, <strong>a company can't be forced to archive what they don't need</strong>.</p>
<p>By the way, I'm not just an end-user of all the services listed above, I'm also one of the twits writing the subpoenas.</p>
<div id="textwise_suggestions"><h4 id='twBlogs'>Similar Blog & News Articles</h4><ul><li><a target="_blank" href="http://mashable.com/2009/09/22/twitter-local-api/" >Twitter's Location Aware Platform Going Live "Any Day Now"</a> :: <em><a target="_blank" href="http://mashable.com" >Mashable!</a></em></li><li><a target="_blank" href="http://www.eweek.com/c/a/Search-Engines/Twitter-Gets-More-BusinessLike-With-New-Terms-of-Service-470366/?kc=rss" >Twitter Gets More Businesslike with New Terms of Service</a> :: <em><a target="_blank" href="http://www.eweek.com" >eWeek - RSS Feeds</a></em></li><li><a target="_blank" href="http://mashable.com/2009/09/23/twitter-local-opt-in/" >Twitter's Location Features Will Be Completely Opt-In</a> :: <em><a target="_blank" href="http://mashable.com" >Mashable!</a></em></li><li><a target="_blank" href="http://www.eweek.com/c/a/Search-Engines/Twitter-Still-Working-on-Geolocation-API-250128/?kc=rss" >Twitter Still Working on Geolocation API</a> :: <em><a target="_blank" href="http://www.eweek.com" >eWeek - RSS Feeds</a></em></li></ul><h4 id='twWiki'>Similar Wikipedia Articles</h4><ul><li><a target="_blank" href="http://en.wikipedia.org/wiki/Twitter" >Twitter</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://hazdat.com/twitter-to-scrub-location-data-after-14-days/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Let&#8217;s play $100 Password!</title>
		<link>http://hazdat.com/lets-play-100-password/</link>
		<comments>http://hazdat.com/lets-play-100-password/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 20:18:20 +0000</pubDate>
		<dc:creator>Jeff M. Fischbach</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Crime]]></category>
		<category><![CDATA[Future Proof]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Search & Seizure]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://hazdat.com/?p=872</guid>
		<description><![CDATA[
			
				
			
		

You probably won't find much sympathy for Elane Cioni. A  scorned,  she's been convicted of  into the email account of her former-boss, the man with whom she was having an affair, and then his wife, his other girlfriends, and even his kids. (I suppose, that doesn't engender much sympathy for her main-target [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fhazdat.com%2Flets-play-100-password%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fhazdat.com%2Flets-play-100-password%2F&amp;source=HazDat&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-888" title="$100 Dollar Password" src="http://hazdat.com/wp-content/uploads/2009/09/100_Dollar_Password_5001.png" alt="$100 Dollar Password" width="500" height="190" /></p>
<p>You probably won't find much sympathy for Elane Cioni. A <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('mistress', '');">mistress</a> scorned,  she's been <strong>convicted of <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('hacking', '');">hacking</a> into the email account of her former-boss, the man with whom she was having an affair, and then his wife, his <em>other </em>girlfriends, and even his kids</strong>. (I suppose, that doesn't engender much sympathy for her main-target either.) But, you might be surprised to find out Cioni's <em>not </em>a very good hacker.</p>
<p>You might also be surprised to learn that there's a market for professional hacking and, similar to many legitimate professions, the jobs are going offshore. When it comes to password hacking, those who can, do. Those who can't, outsource. When Cioni wanted back into her boyfriend's life she turned to one of an increasing number of web sites with offers like this:</p>
<blockquote><p><em>"Need to monitor your Child? Your Spouse? Your Boyfriend/Girlfriend? </em><em><strong>We Hack Passwords for $100</strong> USD. We Crack all major web based emails. This include Hotmail, Yahoo! AOL and Gmail. We Provide Proofs Before payment."<span id="more-872"></span></em></p></blockquote>
<div id="attachment_890" class="wp-caption alignright" style="width: 310px"><a href="http://hazdat.com/wp-content/uploads/2009/09/YourHackerz_full.jpg" ><img class="size-medium wp-image-890 " title="Passwords for $100" src="http://hazdat.com/wp-content/uploads/2009/09/YourHackerz_SM2-300x134.jpg" alt="Passwords for $100" width="300" height="134" /></a><p class="wp-caption-text">Passwords for $100</p></div>
<p>One particular web site even states:<em> "This unique service is 100% legal".</em></p>
<p>The <a target="_blank" href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Washington Post', '');">Washington Post</a> conducted an <a href="http://www.washingtonpost.com/wp-dyn/content/article/2009/09/06/AR2009090602238.html" >interview</a> with the FBI to find out why these services remain online. "The FBI is aware of these illegal services," spokesman Paul Bresson said, "and we have been successful in the past in identifying criminal activity and working with prosecutors to bring indictments. Users of these services should know that just because a product is marketed on the Internet doesn't mean it's legal."</p>
<blockquote><p><em> </em></p></blockquote>
<p>While Cioni had an agenda, the same password could have granted her <strong>access to her victims' bank accounts, insurance policies--access to practically any service that allows individuals to "log in"</strong>. Once access has been gained, she could have reassigned passwords, and even rerouted email communications, effectively <strong>allowing her to assume the individual's identities</strong>. Fortunately, that wasn't <em>her</em> agenda. But, <strong>it's unknown how many of the nation's tens-of-millions of identity theft victims had their passwords purchased</strong>.</p>
<p>Making a case against Cioni wasn't very difficult. Of course, it helped that she mentioned things to her boyfriend that only someone who would have read his email would have known.  And, she used her own <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('PayPal', '');">PayPal</a> account to pay for the password hacking service. In case that wasn't enough, <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('IP address', '');">IP address</a> records were subpoenaed from her Internet Service Provider (ISP), and her computer was searched to find fragments of her targets' email <em> </em><a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('cache', '');">cached</a> to her hard drive.</p>
<p>Then again, Elane Cioni is not a very good hacker.</p>
<p>You can listen to below an <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('NPR', '');">NPR</a> interview on this topic, and hear more about this story:</p>
<a target="_blank" href="http://public.npr.org/anon.npr-mp3/npr/totn/2009/09/20090909_totn_04.mp3?dl=1" class='wpaudio wpaudio_readid3' >20090909_totn_04.mp3?dl=1</a>
<p>Washington Post (<a target="_blank" href="http://www.washingtonpost.com/wp-dyn/content/article/2009/09/06/AR2009090602238.html" >http://www.washingtonpost.com/wp-dyn/content/article/2009/09/06/AR2009090602238.html</a>)</p>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 44px; width: 1px; height: 1px;">
<h1><span class="style2">EMail Hacking Passwords Hacking </span></h1>
<p class="style4">We Hack Passwords for $100 USD<br />
We Crack all major web based emails<br />
This include Hotmail, Yahoo! AOL and Gmail<br />
We Provide Proofs Before payment.</p>
</div>
<div id="textwise_suggestions"><h4 id='twBlogs'>Similar Blog & News Articles</h4><ul><li><a target="_blank" href="http://www.npr.org/templates/story/story.php?storyId=112679747&ft=1&f=1019" >Hackers Have It Easy</a> :: <em><a target="_blank" href="http://www.npr.org/templates/story/story.php?storyId=1019&ft=1&f=1019" >NPR Topics: Technology</a></em></li><li><a target="_blank" href="http://feeds.washingtonpost.com/click.phdo?i=5f5e70bd1a22ae0257bb984a0297a8d8" >Services' E-Mail Hacking Illegal, but Officials Need More Than That to Prosecute</a> :: <em><a target="_blank" href="http://www.washingtonpost.com/wp-dyn/content/technology/index.html?wprss=rss_technology" >Wash Post Technology</a></em></li><li><a target="_blank" href="http://feedproxy.google.com/~r/livecrunch/technology/~3/5aG-6zF5VbU/" >Email Passwords? $20</a> :: <em><a target="_blank" href="http://www.livecrunch.com" >@LiveCrunch</a></em></li><li><a target="_blank" href="http://feeds.lexblog.com/~r/ediscoverylaw/klgates/~3/X9lP_HSb8rA/" >Previously Opened Emails Stored for Less than 181 Days in Web-Based Account May be Obtained by Trial Subpoena</a> :: <em><a target="_blank" href="http://www.ediscoverylaw.com/" >Electronic Discovery Law</a></em></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://hazdat.com/lets-play-100-password/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Electronic privacy is for the birds.</title>
		<link>http://hazdat.com/electronic-privacy-is-for-the-birds/</link>
		<comments>http://hazdat.com/electronic-privacy-is-for-the-birds/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 04:38:58 +0000</pubDate>
		<dc:creator>Jeff M. Fischbach</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Duh]]></category>
		<category><![CDATA[Future Proof]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[Off-Topic]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Search & Seizure]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Surveillance]]></category>

		<guid isPermaLink="false">http://hazdat.com/?p=864</guid>
		<description><![CDATA[
			
				
			
		
In a match between Bird-brain vs. broadband, you might be surprised to see who wins.
An old friend of mine pointed out what sounded like an interesting story out of South Africa. Tired of slow download speeds, a South African call center pitted a racing pigeon against Telkom South Africa Ltd.’s ADSL data service to see [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fhazdat.com%2Felectronic-privacy-is-for-the-birds%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fhazdat.com%2Felectronic-privacy-is-for-the-birds%2F&amp;source=HazDat&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<div class="wp-caption alignright" style="width: 210px"><img class="tw_selimg " title="Homing_pigeon.jpg" src="http://upload.wikimedia.org/wikipedia/commons/e/ee/Homing_pigeon.jpg" alt="Source: Wikipedia" width="200" height="161" /><p class="wp-caption-text">Source: Wikipedia</p></div>
<h2>In a match between Bird-brain vs. broadband, you might be surprised to see who wins.</h2>
<p>An old friend of mine pointed out what sounded like an interesting story out of South Africa. Tired of slow download speeds, a South African call center <strong>pitted a racing pigeon against Telkom South Africa Ltd.’s ADSL data service to see which could move a 4GB file faster</strong>. In total it took just under three hours for the bird to fly approximately 50 miles--about 30 times faster than the ADSL service, which had only downloaded 4% of the file in the same time.</p>
<p>I'm afraid we're not really comparing <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('apapane', '');">apapane</a> to <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('apapane', '');">apapane</a>, or even <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('apapane', '');">apapane</a> to <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('ostriches', '');">ostriches</a>. I doubt, for instance, that the pigeon would fair quite as well over, say, a 500 or 5000 mile "data run".<span id="more-864"></span></p>
<p>The experiment, however, raises what is perhaps a more relevant conclusion: You <strong>probably couldn't find a more secure method for moving data than via <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('carrier pigeon', '');">carrier pigeon</a></strong>. While <strong>all Internet traffic is subject to both warranted, and illicit intercept and monitoring</strong> at multiple <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('internet gateway', '');">gateways</a>, <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('routers', '');">routers</a>, <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('peering', '');">interconnection points</a>, and <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('internet host', '');">hosts</a>, <strong>one would be hard pressed to serve a warrant on--or even physically intercept--a carrier pigeon</strong>. Not to mention, even if they occasionally drop a "<a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Quality of service', '');">packet</a>", it's hard to argue with their wireless range.</p>
<p><em>It's certainly something to think about.</em></p>
<p>Thanks Ron!</p>
<p>More at:</p>
<p>Bloomberg (<a target="_blank" href="http://www.news.com.au/technology/story/0,28348,26053119-5014239,00.html" >http://www.bloomberg.com/apps/news?pid=20601116&amp;sid=aB5JSWQt0XYY</a>)</p>
<p>News.com.au (<a target="_blank" href="http://www.news.com.au/technology/story/0,28348,26053119-5014239,00.html" >http://www.news.com.au/technology/story/0,28348,26053119-5014239,00.html</a>)</p>
<div id="textwise_suggestions"><h4 id='twBlogs'>Similar Blog & News Articles</h4><ul><li><a target="_blank" href="http://us.rd.yahoo.com/dailynews/rss/oddlyenough/*http://news.yahoo.com/s/nm/20090909/od_nm/us_safrica_pigeon" >Pigeon transfers data faster than South Africa's Telkom (Reuters)</a> :: <em><a target="_blank" href="http://news.yahoo.com/i/583" >Yahoo! News: Oddly Enough - Reuters</a></em></li></ul><h4 id='twWiki'>Similar Wikipedia Articles</h4><ul><li><a target="_blank" href="http://en.wikipedia.org/wiki/Pigeon%20racing" >Pigeon racing</a></li><li><a target="_blank" href="http://en.wikipedia.org/wiki/Internet%20in%20South%20Africa" >Internet in South Africa</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://hazdat.com/electronic-privacy-is-for-the-birds/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Taking a dump 21st Century style.</title>
		<link>http://hazdat.com/taking-a-dump-21st-century-style/</link>
		<comments>http://hazdat.com/taking-a-dump-21st-century-style/#comments</comments>
		<pubDate>Tue, 08 Sep 2009 01:00:33 +0000</pubDate>
		<dc:creator>Jeff M. Fischbach</dc:creator>
				<category><![CDATA[Big Brother]]></category>
		<category><![CDATA[Future Proof]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Surveillance]]></category>
		<category><![CDATA[Tracking]]></category>

		<guid isPermaLink="false">http://hazdat.com/?p=658</guid>
		<description><![CDATA[
			
				
			
		
Every time Microsoft researcher  takes a dump he learns something about himself. For instance, he know knows that he's visited 221,173 web sites in the last 8 years, and written or received 156,041 emails. He also knows how well his heart is pumping, how many miles he's walked, where he's been, and even with [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fhazdat.com%2Ftaking-a-dump-21st-century-style%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fhazdat.com%2Ftaking-a-dump-21st-century-style%2F&amp;source=HazDat&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<div id="attachment_834" class="wp-caption alignright" style="width: 160px"><a href="http://hazdat.com/wp-content/uploads/2009/09/gordon_bell.jpg" ><img class="size-thumbnail wp-image-834" title="Gordon Bell (Source: Gizmodo)" src="http://hazdat.com/wp-content/uploads/2009/09/gordon_bell-150x150.jpg" alt="Gordon Bell (Source: Gizmodo)" width="150" height="150" /></a><p class="wp-caption-text">Gordon Bell (Source: Gizmodo)</p></div>
<p><strong>Every time Microsoft researcher <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Gordon Bell', '');">Gordon Bell</a> takes a dump he learns something about himself.</strong> For instance, he know knows that he's visited 221,173 web sites in the last 8 years, and written or received 156,041 emails. He also knows how well his heart is pumping, how many miles he's walked, where he's been, and even with whom he's spoken and visited. In fact, from what most of us consider a waste product, Bell can even decipher how many songs he's listened to, and see pictures videos of the places he's been and the things he's seen.</p>
<p>Fantastic as this may sound, <strong>Bell is not the only person on earth who can do this. The same product is flushed from nearly every person every day in North America</strong>, and other industrialized nations. More significantly, while most of us are ignorant or deny the very possibility, <strong>the government and large corporations are secretly extracting much the same information from each of us that Bell collects himself.<span id="more-658"></span></strong></p>
<div id="attachment_838" class="wp-caption alignleft" style="width: 310px"><a href="http://hazdat.com/wp-content/uploads/2009/09/SenseCamPics.jpg" ><img class="size-medium wp-image-838" title="SenseCam (Source: Microsoft)" src="http://hazdat.com/wp-content/uploads/2009/09/SenseCamPics-300x201.jpg" alt="SenseCam (Source: Microsoft)" width="300" height="201" /></a><p class="wp-caption-text">SenseCam (Source: Microsoft)</p></div>
<p>What bell flushes he calls MyLifeBits. It's a <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Microsoft Research', '');">Microsoft Research</a> project inspired by an <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Memex', '');">idea</a> that dates back to 1945. The modern iteration of the memory index (<a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('memex', '');">memex</a>) uses a variety of ever-shrinking devices to capture, store, and index an individual's daily life into what some call a <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('lifelog', '');">lifelog</a>.</p>
<p style="text-align: center;">
<p><strong>To some extent, many of of us have become <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('lifeloggers</strong>', '');">lifeloggers</strong></a> through a variety of mechanisms including blogs and social networking. What's notably different about Bell's approach, compared to <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('social networking', '');">social networking</a>, <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('life-streaming', '');">life-streaming</a>, <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('life-blogging', '');">life-blogging</a>, or what Toronto Professor <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Steve Mann', '');">Steve Mann</a> has termed <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Sousveillance', '');">Sousveillance</a>, is that MyLifeBits is a personal storage and indexing mechanism, as opposed to a social interaction or broadcast. It is, if you will, a diary of perspective, but not of opinion.</p>
<p>Whereas social networks provide a platform for one to share thoughts, experiences, feelings, opinions and emotions with others, <strong>Bell's objective appears to be a personal one</strong>, devoid of any of these attributes. Few, if carefully considered, would argue that social networks produce factual content. To the contrary, <strong>these <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('meme', '');">memes</a> allow individuals to represent themselves, not as they are, but as they might like the world, or even just a few individuals, to see them--at least, at that moment.</strong></p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="324" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="flashvars" value="linkUrl=http://www.cbsnews.com/video/watch/?id=2666250n&amp;releaseURL=http://cnettv.cnet.com/av/video/cbsnews/atlantis2/player-dest.swf&amp;videoId=50022828,50072101,50072093,50071994,50071933,50071899&amp;partner=news&amp;vert=News&amp;autoPlayVid=false&amp;name=cbsPlayer&amp;allowScriptAccess=always&amp;wmode=transparent&amp;embedded=y&amp;scale=noscale&amp;rv=n&amp;salign=tl" /><param name="src" value="http://cnettv.cnet.com/av/video/cbsnews/atlantis2/player-dest.swf" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="324" src="http://cnettv.cnet.com/av/video/cbsnews/atlantis2/player-dest.swf" allowfullscreen="true" flashvars="linkUrl=http://www.cbsnews.com/video/watch/?id=2666250n&amp;releaseURL=http://cnettv.cnet.com/av/video/cbsnews/atlantis2/player-dest.swf&amp;videoId=50022828,50072101,50072093,50071994,50071933,50071899&amp;partner=news&amp;vert=News&amp;autoPlayVid=false&amp;name=cbsPlayer&amp;allowScriptAccess=always&amp;wmode=transparent&amp;embedded=y&amp;scale=noscale&amp;rv=n&amp;salign=tl"></embed></object></p>
<div id="textwise_suggestions"><h4 id='twBlogs'>Similar Blog & News Articles</h4><ul><li><a target="_blank" href="http://emilychang.com/2009/08/total-recall-your-e-memory/" >Total Recall: Your E-Memory</a> :: <em><a target="_blank" href="http://emilychang.com" >Emily Chang - Strategic Designer</a></em></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://hazdat.com/taking-a-dump-21st-century-style/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>U.S. Gov. authorizes long-layovers for laptops.</title>
		<link>http://hazdat.com/u-s-gov-authorizes-long-layovers-for-laptops/</link>
		<comments>http://hazdat.com/u-s-gov-authorizes-long-layovers-for-laptops/#comments</comments>
		<pubDate>Tue, 01 Sep 2009 02:54:26 +0000</pubDate>
		<dc:creator>Jeff M. Fischbach</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Search & Seizure]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://hazdat.com/?p=746</guid>
		<description><![CDATA[
			
				
			
		
It's sometimes hard to remember, but it wasn't that long ago that most  bypassed so much as an . Then came the obligatory laptop and shoe removal. And, eventually, the "drink 'em or lose 'em" rule, accompanied by the ever-perplexing debate over what constitutes a "liquid", and how many ounces of it you can [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fhazdat.com%2Fu-s-gov-authorizes-long-layovers-for-laptops%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fhazdat.com%2Fu-s-gov-authorizes-long-layovers-for-laptops%2F&amp;source=HazDat&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><img class="alignright size-medium wp-image-754" title="DHS" src="http://hazdat.com/wp-content/uploads/2009/08/DHS_S_WR-300x300.gif" alt="DHS" width="300" height="300" />It's sometimes hard to remember, but it wasn't that long ago that most <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('carry-on luggage', '');">carry-on's</a> bypassed so much as an <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('airport security', '');">x-ray screening</a>. Then came the obligatory laptop and shoe removal. And, eventually, the "drink 'em or lose 'em" rule, accompanied by the ever-perplexing debate over what constitutes a "liquid", and how many ounces of it you can carry through a <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('transporation security administration', '');">TSA</a> line.</p>
<p>(I once overheard a TSA agent explaining to a traveler that, "anything that <em>can </em>be liquefied is a liquid". I felt compelled to explain that, at the right temperature, the whole airplane <em>could</em> be liquefied--but kept my mouth shut, for fear of missing my flight.)</p>
<p>In recent months, some international travelers have been greeted with an indignity that makes the "<a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('patdown', '');">patdown</a>" look like a "fist-bump".<strong> In the past 10 months, over 1000 people had their laptop computers "detained" and subsequently searched.</strong> Most would assume that this was with <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('probable cause', '');">probable cause</a>, but, the <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('DHS', '');">DHS</a> maintains that probable cause is not required for such a search.<span id="more-746"></span></p>
<p>What some might consider an electronic <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('cavity search', '');">cavity search</a>, became policy in 2008 when the Department of Homeland Security's U.S. Customs and Border Enforcement published their "<a href="http://hazdat.com/?file_id=19" >Policy Regarding Border Search of Information</a>" (July 16, 2008), which, among other things,<strong> allowed Custom's Agents broad discretion to detain "<em>electronic devices, or copies thereof, for a reasonable period of time to perform a thorough border search.</em>"</strong> Though protocols were established for an "expeditious" response time by assisting agencies, no definition for <em>"reasonable period"</em> was provided.</p>
<p>The rationale cited for this policy, is described in its fourth paragraph, "Review of Information in the Course of Border Search":  <em>"In the course of a border search, and <strong>absent individualized suspicion, officers can review and analyze the information transported by any individual attempting to enter, reenter, depart, pass through, or reside in the United States</strong>..." </em>While, in the past, this objective could be met with a visual inspection, computers, iPods, smart-phones, and the like, require complex procedures, software and hardware to preserve the integrity of the data being examined. Therefore, such a search is typically conducted in a laboratory setting, and not something that cannot likely be accomplished during even the longest of layovers.</p>
<p>The DHS provides the following <a href="http://hazdat.com/?file_id=22"  target="_blank">definition</a> of a "detention":</p>
<blockquote><p>"<strong>A detention occurs when <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('CBP', '');">CBP</a> or <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('ICE ', '');">ICE </a>determines that the devices need to be kept for further examination to determine if there is probable cause </strong>to seize as evidence of a crime and/or for forfeiture. This is a temporary detention of the device during an ongoing border search. Many factors may result in a detention, for example, time constraints due to connecting flights, the large volume of information to be examined, the need to use off-site tools and expertise during the search (e.g., an ICE forensic lab), or the need for translation or other specialized services to understand the information on the device. <strong>In a detention, CBP or ICE will keep either the original device (e.g., the laptop) or an exact duplicate copy of the information stored on the device, so as to allow the traveler to proceed with the original device.</strong> Once the border search has concluded, the device will be returned to the traveler unless there is probable cause to seize the device. Any copies of the information in the possession of CBP or ICE will be destroyed unless retention of the information is necessary for law enforcement purposes and appropriate within CBP or ICE Privacy Act systems of records."</p></blockquote>
<p>Effectively, <strong>a "detention" is a seizure without probable cause</strong>, followed by an unwarranted search. Fortunately, the CBP has taken measures to assure that it only retains information from "detained" devices that are consistent with probable cause, as outlined in Section D:</p>
<blockquote><p>"Absent probable cause, CBP may only retain documents relating to immigration matters, consistent with the privacy and data protection standards of the system in which such information is retained."</p></blockquote>
<p>And,</p>
<blockquote><p>"Except as noted in this section, if after reviewing information, there exists no probable cause to seize the information, CBP will retain no copies of the information."</p></blockquote>
<p>Which should make passengers a little less uncomfortable, if not a little less violated--were it not for the following:</p>
<blockquote><p>"Officers may encounter information in documents or electronic devices that is in a foreign language and/or encrypted. To assist CBP in determining the meaning of such information, CBP may seek translation and/or decryption assistance  from other Federal agencies or entities."</p></blockquote>
<p>The <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('FBI', '');">FBI</a> could, for example, aid in this circumstance. But:</p>
<blockquote><p>At the conclusion of the requested assistance, all information must be returned to CBP as expeditiously as possible. In addition, the assisting Federal agency or entity must certify to CBP that all copies of the information transferred to that agency or entity have been<br />
destroyed... In the event that any original documents or devices are transmitted, they must not be destroyed; <strong>they are to be returned to CBP unless seized based on probable cause by the assisting agency</strong>.</p></blockquote>
<p>And that, of course, reads like an invitation to <strong>convert a random search without probable cause from one agency, into a "<a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('line of sight', '');">line of sight</a>" search by another</strong>.</p>
<p>Now, more than a year later, come <a href="http://hazdat.com/?file_id=21"  target="_blank">new rules</a> intended to preserve passengers' rights and insure domestic tranquility. On August 20, 2009 DHS Secretary <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('Janet Napolitano', '');">Janet Napolitano</a> announced new directives said to "strike the balance between respecting the civil liberties and privacy of all travelers while ensuring DHS can take the lawful actions necessary to secure our borders."</p>
<p>Unfortunately, the new rules won't change much, <em>other than </em>the definition of "reasonable period". According to a "Privacy Impact Assessment for the<br />
Border Searches of Electronic Devices", published by the DHS:</p>
<blockquote><p>"For CBP, the detention of devices ordinarily should not exceed five (5) days, unless extenuating circumstances exist."</p></blockquote>
<p>Devices may, however, be released to Immigration and Customs Enforcement Agents for further examination.</p>
<blockquote><p>"As federal criminal investigators, ICE Special Agents are empowered to make investigative decisions based on the particular facts and circumstances of each case... The ICE Directive requires that Special Agents complete the border search of any detained electronic device or information in a reasonable time, but typically no longer than 30 days, depending on the facts and circumstances of the particular search. The length of detention depends on several factors, but primarily the amount of information requiring review and the format of that information, which can greatly affect the amount of time necessary to complete a search."</p></blockquote>
<p>What about sensitive, say <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('attorney-client privilege', '');">attorney-client privileged</a> or classified materials?</p>
<blockquote><p>"Officers may encounter materials that appear to be legal in nature, or an individual may assert that certain information is protected by <strong>attorney-client or attorney work product privilege</strong>. <strong>Legal materials are not necessarily exempt from a border search</strong>, but they may be subject to the following special handling procedures: If an Officer suspects that the <strong>content of such a material may constitute evidence of a crime</strong> or otherwise pertain to a determination within the jurisdiction of CBP, the Officer must seek advice from the CBP Associate/Assistant Chief Counsel before conducting a search of the material..."</p></blockquote>
<p>Of course, one would anticipate that many lawyers might carry "<em>evidence </em>of a crime", or multiple crimes, on their laptops. Though, quite honestly, I doubt that this is the intention, the ambiguity should not be taken lightly.</p>
<p>Effectively, little has changed, except perhaps the use of <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('FedEx', '');">FedEx</a> and <a href="#wikipopFrame" class="wikipopLink" onclick="setFrameSrc('UPS', '');">UPS</a> by people who <em>really</em> have something to hide.</p>
<p style="text-align: center;"><table cellpadding="0" width="100%" border="0">
  <tr>
    <td width="35" style="vertical-align: top;">
      <a href="http://hazdat.com/?file_id=19" ><img src="http://hazdat.com/wp-content/plugins/downloads-manager/img/icons/pdf.gif" alt="http://hazdat.com/wp-content/plugins/downloads-manager/img/icons/pdf.gif"></a>
    </td>
    <td>
      <H5><a href="http://hazdat.com/?file_id=19" >USCBP: Policy Regarding Border Search of Information (2008)</a> <br /></H5>
      <em>U.S. Customs and Border Protection
Policy Regarding Border Search of Information (July 16, 2008)</em><br />
      <b>size:</b> 160.67KB 
      <b>added:</b> 31/08/2009 
      <b>popularity:</b> 1
    </td>
  </tr>
</table></p>
<p style="text-align: center;"><table cellpadding="0" width="100%" border="0">
  <tr>
    <td width="35" style="vertical-align: top;">
      <a href="http://hazdat.com/?file_id=20" ><img src="http://hazdat.com/wp-content/plugins/downloads-manager/img/icons/pdf.gif" alt="http://hazdat.com/wp-content/plugins/downloads-manager/img/icons/pdf.gif"></a>
    </td>
    <td>
      <H5><a href="http://hazdat.com/?file_id=20" >USCBP: Inspection of Electronic Devices (Tearsheet)</a> <br /></H5>
      <em>U.S. Customs & Border Protection: "Inspection of Electronic Devices". </em><br />
      <b>size:</b> 39.52KB 
      <b>added:</b> 31/08/2009 
      <b>popularity:</b> 0
    </td>
  </tr>
</table></p>
<p style="text-align: center;"><table cellpadding="0" width="100%" border="0">
  <tr>
    <td width="35" style="vertical-align: top;">
      <a href="http://hazdat.com/?file_id=21" ><img src="http://hazdat.com/wp-content/plugins/downloads-manager/img/icons/pdf.gif" alt="http://hazdat.com/wp-content/plugins/downloads-manager/img/icons/pdf.gif"></a>
    </td>
    <td>
      <H5><a href="http://hazdat.com/?file_id=21" >USCBP: Border Search of Information (2009)</a> <br /></H5>
      <em>U.S. Customs & Border Protection: Border Search of Information (August 20, 2009)</em><br />
      <b>size:</b> 4.87MB 
      <b>added:</b> 31/08/2009 
      <b>popularity:</b> 1
    </td>
  </tr>
</table></p>
<p style="text-align: center;"><table cellpadding="0" width="100%" border="0">
  <tr>
    <td width="35" style="vertical-align: top;">
      <a href="http://hazdat.com/?file_id=22" ><img src="http://hazdat.com/wp-content/plugins/downloads-manager/img/icons/pdf.gif" alt="http://hazdat.com/wp-content/plugins/downloads-manager/img/icons/pdf.gif"></a>
    </td>
    <td>
      <H5><a href="http://hazdat.com/?file_id=22" >Privacy Impact Assessment for the Border Searches of Electronic Devices (2009)</a> <br /></H5>
      <em>Department of Homeland Security Privacy Impact Assessment for the Border Searches of Electronic Devices
(August 25, 2009)</em><br />
      <b>size:</b> 5.64MB 
      <b>added:</b> 31/08/2009 
      <b>popularity:</b> 2
    </td>
  </tr>
</table></p>
<p style="text-align: center;"><table cellpadding="0" width="100%" border="0">
  <tr>
    <td width="35" style="vertical-align: top;">
      <a href="http://hazdat.com/?file_id=23" ><img src="http://hazdat.com/wp-content/plugins/downloads-manager/img/icons/pdf.gif" alt="http://hazdat.com/wp-content/plugins/downloads-manager/img/icons/pdf.gif"></a>
    </td>
    <td>
      <H5><a href="http://hazdat.com/?file_id=23" >ICE: Border Searches of Electronic Devices (2009)</a> <br /></H5>
      <em>Immigration and Customs Enforcement Policy for Border Searches of Electronic Devices (August 18, 2009)</em><br />
      <b>size:</b> 452.57KB 
      <b>added:</b> 31/08/2009 
      <b>popularity:</b> 0
    </td>
  </tr>
</table></p>
<p style="text-align: center;"><table cellpadding="0" width="100%" border="0">
  <tr>
    <td width="35" style="vertical-align: top;">
      <a href="http://hazdat.com/?file_id=26" ><img src="http://hazdat.com/wp-content/plugins/downloads-manager/img/icons/setup.gif" alt="http://hazdat.com/wp-content/plugins/downloads-manager/img/icons/setup.gif"></a>
    </td>
    <td>
      <H5><a href="http://hazdat.com/?file_id=26" >TrueCrypt</a> <br /></H5>
      <em>Real-time on-the-fly industry-recognized encryption of entire hard drive, portion, or removable media. (FREE / Peer-Reviewed / Multi-OS)</em><br />
      <b>size:</b>  
      <b>added:</b> 01/09/2009 
      <b>popularity:</b> 110
    </td>
  </tr>
</table></p>
<div id="textwise_suggestions"><h4 id='twBlogs'>Similar Blog & News Articles</h4><ul><li><a target="_blank" href="http://feedproxy.google.com/~r/AnalyticalChemistryA-pages/~3/kUMb-gr9Ots/8722cover.html" >Keepers Of The Gate</a> :: <em><a target="_blank" href="http://pubs.acs.org/page/action/showNews?type=onlineNewsroom&journalCode=ancham" >Analytical Chemistry News</a></em></li><li><a target="_blank" href="http://news.cnet.com/8301-13578_3-10320116-38.html?part=rss&subj=news&tag=2547-1_3-0-20" >Laptop border searches to continue</a> :: <em><a target="_blank" href="http://news.cnet.com/" >CNET News.com</a></em></li><li><a target="_blank" href="http://feedproxy.google.com/~r/AbcNews_US/~3/MVI3OzkkAvk/wireStory" >Tighter Oversight on Border Laptop Searches</a> :: <em><a target="_blank" href="http://abcnews.go.com/US/" >ABC News: U.S.</a></em></li><li><a target="_blank" href="http://feedproxy.google.com/~r/tripso/~3/t-TNB4KavYk/" >Customs and Border Patrol agents are still randomly confiscating laptops - is yours next?</a> :: <em><a target="_blank" href="http://www.consumertraveler.com" >Consumer Traveler</a></em></li><li><a target="_blank" href="http://www.infoworld.com/d/security-central/aclu-files-lawsuit-border-laptop-searches-214?source=rss_infoworld_news" >ACLU files lawsuit on border laptop searches</a> :: <em><a target="_blank" href="http://www.infoworld.com/news" >Infoworld News</a></em></li></ul><h4 id='twWiki'>Similar Wikipedia Articles</h4><ul><li><a target="_blank" href="http://en.wikipedia.org/wiki/Computer%20Assisted%20Passenger%20Prescreening%20System" >Computer Assisted Passenger Prescreening System</a></li><li><a target="_blank" href="http://en.wikipedia.org/wiki/Airport%20security" >Airport security</a></li><li><a target="_blank" href="http://en.wikipedia.org/wiki/Registered%20Traveler" >Registered Traveler</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://hazdat.com/u-s-gov-authorizes-long-layovers-for-laptops/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win Ben Bernanke&#8217;s Money (Irony)</title>
		<link>http://hazdat.com/win-ben-bernankes-money-irony/</link>
		<comments>http://hazdat.com/win-ben-bernankes-money-irony/#comments</comments>
		<pubDate>Sat, 29 Aug 2009 02:48:15 +0000</pubDate>
		<dc:creator>Jeff M. Fischbach</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Society]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://hazdat.com/?p=715</guid>
		<description><![CDATA[
			
				
			
		
It looks like, for some, the stimulus package wasn't enough. In an ironic twist, the man often criticized for moving Trillions from the Federal Reserve Bank into the hands of failing corporations has had a far lesser sum removed from his personal bank account.
"Federal Reserve Chairman Ben Bernanke has been a victim of identity theft. [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fhazdat.com%2Fwin-ben-bernankes-money-irony%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fhazdat.com%2Fwin-ben-bernankes-money-irony%2F&amp;source=HazDat&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>It looks like, for some, the stimulus package wasn't enough. In an ironic twist, the man often <a target="_blank" href="http://latimesblogs.latimes.com/money_co/2009/08/while-much-or-most-of-wall-street-seems-to-believe-that-ben-s-bernanke-deserves-a-second-term-as-federal-reserve-chairman-2.html" >criticized</a> for moving Trillions from the Federal Reserve Bank into the hands of failing corporations has had a far lesser sum removed from his personal bank account.</p>
<blockquote><p><strong><img class="alignleft size-full wp-image-717" title="Conan O'Brien" src="http://hazdat.com/wp-content/uploads/2009/08/conan_75.jpg" alt="Conan O'Brien" width="75" height="75" /></strong><em>"Federal Reserve Chairman Ben Bernanke has been a victim of identity theft. <strong>His credit card company became suspicious when they noticed repeated purchases of large, failing American car companies</strong>."</em></p>
<p>- Conan O'Brien (Aired August 27, 2009)</p></blockquote>
<p>Just days after President Obama announced Bernanke's renomination to the Federal Reserve, officials revealed that <strong>Fed Chairman Ben Bernanke was a victim of a wide-spread identity theft ring<span id="more-715"></span></strong> that used, "<strong>stolen personal identifying information, bank and bank record information, personal checks</strong>, and other access devices belonging to individual victims, to impersonate those victims at various bank branches throughout the country," according to the U.S. Attorney's Office.</p>
<p>"Identity theft is a serious crime that affects millions of Americans each year," Mr. Bernanke said through a Fed spokesman. "<strong>Our family was but one of 500 separate instances traced to one crime ring.</strong>"</p>
<p>Though there's really nothing funny about identity theft, it just goes to prove that the problem is so pervasive that anyone can fall victim.</p>
<div id="textwise_suggestions"><h4 id='twBlogs'>Similar Blog & News Articles</h4><ul><li><a target="_blank" href="http://feedproxy.google.com/~r/theseminal/news/~3/uqHlf80zSaw/7601" >Bernanke Struck By Identity Theft</a> :: <em><a target="_blank" href="http://seminal.firedoglake.com" >The Seminal :: Independent Media And Politics</a></em></li><li><a target="_blank" href="http://www.shoppingblog.com/blog/8270916" >Fed Chief Ben Bernanke Victim of Identity Theft</a> :: <em><a target="_blank" href="http://www.shoppingblog.com/" >ShoppingBlog.com</a></em></li><li><a target="_blank" href="http://rss.cnn.com/~r/rss/money_latest/~3/Bxx_I3PIqr4/index.htm" >Think ID theft can't happen to you?</a> :: <em><a target="_blank" href="http://money.cnn.com/rssclick/?section=money_latest" >Latest financial news - CNNMoney.com</a></em></li><li><a target="_blank" href="http://rss.cnn.com/~r/rss/money_latest/~3/0OnBsXlbY-c/index.htm" >Bernanke: I was identity theft victim</a> :: <em><a target="_blank" href="http://money.cnn.com/rssclick/?section=money_latest" >Latest financial news - CNNMoney.com</a></em></li><li><a target="_blank" href="http://feedproxy.google.com/~r/AbcNews_Business/~3/gTFP4IR2G5k/story" >Fed Chief Victim of Identity Theft</a> :: <em><a target="_blank" href="http://abcnews.go.com/Business/" >ABC News: Money</a></em></li></ul><h4 id='twWiki'>Similar Wikipedia Articles</h4><ul><li><a target="_blank" href="http://en.wikipedia.org/wiki/Credit%20card%20fraud" >Credit card fraud</a></li><li><a target="_blank" href="http://en.wikipedia.org/wiki/Bank%20fraud" >Bank fraud</a></li><li><a target="_blank" href="http://en.wikipedia.org/wiki/Federal%20Reserve%20System" >Federal Reserve System</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://hazdat.com/win-ben-bernankes-money-irony/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	
	<div style="display: none;" id="wikipopFrame"><iframe id="theFrame" style="border: none;" name="theFrame" width="340" height="400" src=""></iframe></div>

</channel>
</rss>
