HazDat
28Sep/09

The problem is, banks have too many humans.

What do you call the sacrifice of one person's privacy in an attempt to save the privacy of over 1300? If you're a bank, you call it collateral damage.

rmb-logoWhen I was a kid I earned my first paycheck passing out fliers for a neighbor who was starting a pool cleaning business. With my first $13 in hand, my grandfather took me to the a bank in walking distance to my home, got me a tour of the vault from the branch manager, a neat pouch to hold all my coin, a full explanation of the principals of savings and loans, and helped me open my very first savings account. Believe it or not, back then, all my account information was stored on a double-sided index card behind the teller.

Today, things are much more complicated. Gone are the index cards and passbooks, most of the employees, tellers and branches, a good deal of the service, interest-bearing accounts with only $13 in them, and a lot of the customers' money. Today, it's all computerized, and most banks even attach various penalties to discourage human contact.

I know an awful lot about electronic data systems, but I don't pretend to fully understand how the modern banking system works. Sometimes, I think I do--from a mechanical (as opposed to financial) perspective. But then something convinces me that I don't. For instance, you know how every so often your bank emails its customers' names, addresses, Social Security numbers, and loan information to Gmail? ... CONTINUE READING »

10Sep/09

Let’s play $100 Password!

$100 Dollar Password

You probably won't find much sympathy for Elane Cioni. A mistress scorned, she's been convicted of hacking into the email account of her former-boss, the man with whom she was having an affair, and then his wife, his other girlfriends, and even his kids. (I suppose, that doesn't engender much sympathy for her main-target either.) But, you might be surprised to find out Cioni's not a very good hacker.

You might also be surprised to learn that there's a market for professional hacking and, similar to many legitimate professions, the jobs are going offshore. When it comes to password hacking, those who can, do. Those who can't, outsource. When Cioni wanted back into her boyfriend's life she turned to one of an increasing number of web sites with offers like this:

"Need to monitor your Child? Your Spouse? Your Boyfriend/Girlfriend? We Hack Passwords for $100 USD. We Crack all major web based emails. This include Hotmail, Yahoo! AOL and Gmail. We Provide Proofs Before payment." ... CONTINUE READING »

9Sep/09

Electronic privacy is for the birds.

Source: Wikipedia

Source: Wikipedia

In a match between Bird-brain vs. broadband, you might be surprised to see who wins.

An old friend of mine pointed out what sounded like an interesting story out of South Africa. Tired of slow download speeds, a South African call center pitted a racing pigeon against Telkom South Africa Ltd.’s ADSL data service to see which could move a 4GB file faster. In total it took just under three hours for the bird to fly approximately 50 miles--about 30 times faster than the ADSL service, which had only downloaded 4% of the file in the same time.

I'm afraid we're not really comparing apapane to apapane, or even apapane to ostriches. I doubt, for instance, that the pigeon would fair quite as well over, say, a 500 or 5000 mile "data run". ... CONTINUE READING »

4Sep/09

Wi-Fi security — gone in 60 seconds, AGAIN.

Wi-Fi_ZoneYou're not one of those people who leave their wi-fi network open to anyone who passes by, are you? You realize, of course, that--beside the obvious security risks to your computers, your network, your passwords, email, accounting files, your bank account, private identity, maybe even sensitive medical information--that anything someone else does on your network will be traced back to you--the resident and ISP subscriber? Say, for example, the kid next door decides to use your "lightning fast DSL" to download, or worse--share--his music collection via Bit Torrent. The RIAA subpoena will be addressed to you. Or, suppose someone driving by decides to stop and explore his sexual curiosities where they can't be traced back to his network. The search warrant will be addressed to you.

But, that's not your problem, right? Because your wi-fi network is encrypted, right? I remember, back in the day, I used to brag that it would be easier to poach my cable connection from the street than hack my wi-fi, because I was using WEP encryption (cracked in 2001), a MAC filter (easily spoofed), AND I cloaked my SSID (worthless). Since then, came WPA, and more recently WPA2.

Linksys settings for WPA2 wireless secruity.

Linksys settings for WPA2 wireless secruity.

If I lost you at "lighting fast DSL", then the following probably is your problem: Computer scientists in Japan have developed a way to break the WPA encryption system used in wireless routers in just one minute. For those keeping up, presumably you upgraded your router firmware some time back, or purchased and configured a new router to utilize WPA2--which is, so far, considered to be secure. ... CONTINUE READING »

31Aug/09

U.S. Gov. authorizes long-layovers for laptops.

DHSIt's sometimes hard to remember, but it wasn't that long ago that most carry-on's bypassed so much as an x-ray screening. Then came the obligatory laptop and shoe removal. And, eventually, the "drink 'em or lose 'em" rule, accompanied by the ever-perplexing debate over what constitutes a "liquid", and how many ounces of it you can carry through a TSA line.

(I once overheard a TSA agent explaining to a traveler that, "anything that can be liquefied is a liquid". I felt compelled to explain that, at the right temperature, the whole airplane could be liquefied--but kept my mouth shut, for fear of missing my flight.)

In recent months, some international travelers have been greeted with an indignity that makes the "patdown" look like a "fist-bump". In the past 10 months, over 1000 people had their laptop computers "detained" and subsequently searched. Most would assume that this was with probable cause, but, the DHS maintains that probable cause is not required for such a search. ... CONTINUE READING »

28Aug/09

Win Ben Bernanke’s Money (Irony)

It looks like, for some, the stimulus package wasn't enough. In an ironic twist, the man often criticized for moving Trillions from the Federal Reserve Bank into the hands of failing corporations has had a far lesser sum removed from his personal bank account.

Conan O'Brien"Federal Reserve Chairman Ben Bernanke has been a victim of identity theft. His credit card company became suspicious when they noticed repeated purchases of large, failing American car companies."

- Conan O'Brien (Aired August 27, 2009)

Just days after President Obama announced Bernanke's renomination to the Federal Reserve, officials revealed that Fed Chairman Ben Bernanke was a victim of a wide-spread identity theft ring ... CONTINUE READING »

19Aug/09

DNA hacking: the ultimate identity theft

DNAIsraeli scientists are declaring war on DNA evidence. According to a paper published today in the journal, Forensic Science International: Genetics, scientists in Tel Aviv have have demonstrated that it is in fact possible to fabricate DNA evidence, opening up an entirely new avenue of reasonable doubt.

As quoted to the New York Times by lead author, Dr. Dan Frumkin, “You can just engineer a crime scene. Any biology undergraduate could perform this.” ... CONTINUE READING »

13Aug/09

Palm’s Pre has you covered — like an enemy of the state

VZ_Network_thumbHey, Verizon customers -- ever get tired of having "The Network" following you around everywhere you go? It's such a hassle, especially when you have to use the restroom, or spend some "alone time" with your significant other.

Well, Sprint's Palm prē has you covered. Palm's latest smart phone is so smart, the network can find YOU -- ANY TIME THEY WANT!

Palm Pre_FrontClosed-CardViewGoogleMaps-300-100

INFORMATION SENT TO PALM: { "errorCode": 0, "timestamp": 1249855555954.000000, "latitude": 36.594108, "longitude": -82.183260, "horizAccuracy": 2523, "heading": 0, "velocity": 0, "altitude": 0, "vertAccuracy": 0 }

The news was released on Joey Hess' blog. Hess, a programmer, noticed a log file on his Palm prē was being sent to http://ps.palmws.com on a daily basis. Among other things, the log file contained his GPS coordinates (in this case, his home address) in the form of longitude and latitude. This information is derived from the built in GPS common to most cellular telephones on the market today.

In addition to his location, the log file also recorded the name of every application he used, when, and for how long.

Although there has been some speculation that this information is only recorded when the device crashes, Hess has shown that, even though Palm's WebOS makes a record of device crashes, this is supplemental to the daily GPS location, and usage-tracking that is sent to Palm every day. (All of which, for now, he has disabled by hacking a file in the operating system.)

Palm's response to this shocking revelation?

RTPP: Read The Privacy Policy. In a statement released by Palm, "Our privacy policy is like many policies in the industry and includes very detailed language about potential scenarios in which we might use a customer's information, all toward a goal of offering a great user experience."

In preparation for this posting, I read Palm's Privacy Policy (08-13-2009). Focusing strictly on users' private location data, the only mention of  location-based information being collected and transmitted is as follows:

"When you use location based services, we will collect, transmit, maintain, process, and use your location and usage data (including both real time geographic information and information that can be used to approximate location) in order to provide location based and related services, and to enhance your device experience."

This policy specifically addresses use of this data when "provid[ing] location-based and related services". That does not explain why they are collecting and transmitting GPS data as part of a daily log.

Frankly, I have some issues with Palm's right to this data, even if it has been disclosed. Although, arguably, Sprint has to process this data through their network to provide service to it's customers, Palm sells hardware and software, not network service, or even traffic and directions. As an individual who collects and analyzes similar data for criminal cases on a daily basis, I see no justification in Palm's Policy, or in terms of the way the equipment operates, for the transmittal of location-specific data to their company.

Read more @ InformationWeek (http://www.informationweek.com/news/security/privacy/showArticle.jhtml?articleID=219300120)

{ "errorCode": 0, "timestamp": 1249855555954.000000, "latitude": 36.594108, "longitude": -82.183260, "horizAccuracy": 2523, "heading": 0, "velocity": 0, "altitude": 0, "vertAccuracy": 0 }
12Aug/09

Opt-out — for good!

TheOnion has posted this report on what they call "Google's Op-Out Village".

Via TWiT's Leo Laporte (http://leo.tumblr.com/post/161380154/google-opt-out-feature-lets-users-protect-privacy?dsq=14729616#comment-14729616)

11Aug/09

Is the new Cookie Diet just a lot of Flash?

So, you gave up cookies back when you were still using Netscape 4.0? If you're like me, you've tried slimming down with fad browsers like Dillo and HotJava. I can't tell you how many times I've jumped from one crashed browser to the next. You've turned off cookies and scripting and ActiveX controls, to no avail. I've even purged a few times, and my cache is still bloated.

FlashI'm here to tell you--It's not your fault! Blame Adobe.

While you were painstakingly avoiding every cookie that came your way, web sites all over the Internet were secretly getting you hooked on Flash Cookies. Yes, Flash Cookies!

While you may have diligently banned cookies in your browser settings, Flash Cookies can't be controlled through privacy settings in your browser. What's worse, some are even able to store and reinstate traditional cookies, even after you've dumped them.

Open Share Icon

Open Share Icon

Even the ever-popular "AddThis" button (not to be confused with the "AddToAny", AKA, "Share/Save" button below) found on many blogs, utilizes a Flash Cookie that, while providing continuity across various web sites that a user may visit, can also be used to track a user's browsing habits, interests, and predilections across an endless cycle of browsing sessions.

Or friends over at the Berkeley Center for Law & Technology and the Social Science Research Center (SSRN) have submitted a report to the White House Office of Science & Technology Policy (OSTP) outlining their findings and general concern over the proliferation of undisclosed Flash cookies, and the lack of browser controls for users to protect their privacy.

Read more @ Wired (http://www.wired.com/epicenter/2009/08/you-deleted-your-cookies-think-again/)

Join the conversation...

Join the conversation on Twitter

Join the conversation on Facebook

disquslogo_180 Subscribe to RSS feed

Join the Google conversaton…

Get email updates:

Geo Visitors Map