Category: Privacy

  • U.S. Government Wants to Spy on Internet Use

    The federal government wants to peer into your computer communications, forcing companies to design, or redesign, their networks to accommodate surveillance. The FCC gave broadband Internet service and voice-over-Internet Protocol services, or VoIP, 18 months to ensure that their networks are wiretap-ready.

    Is this the Patriot Act at work?  Actually its a different act called Communications Assistance for Law Enforcement Act (CALEA)in 1994, requiring telephone companies to build surveillance capability into their networks.

    I agree with EFF:

    Lee Tien, senior staff attorney for the Electronic Frontier Foundation, a civil liberties group focusing on technology issues, said: “It doesn't authorize wiretaps. It does something much more intrusive: It dictates the design of technologies from law enforcement's standpoint.”

    read more | digg story

  • Schools Crack Down on Students' Blogs

    “Some schools are punishing students for things written on their personal Web pages, raising questions about how far a principal's oversight should reach.”

    This sounds like a privacy issue. 

    “It's inappropriate that they're telling my daughter how to behave when she's not at school,” said Joseph Iacovacci, Ms. Iacovacci's father, of the Web posting. “It was such a violation of the First Amendment.” 

    I must agree with the parent.  I do believe that there has to be some kind of control.  But that control should be done through the parent.

    read more | digg story

  • Spyware Can Constitute illegal Trespass On Home Computers

    In the case of Sotelo v. DirectRevenue, the plantiff filed a complaint against various defendants claiming that they download and/or installed software on his computer without his consent.  I bet the creators of DirectRevenue did see THIS is their risk analysis.. getting sued by potential costumers.

    This seems to be a growing trend.  Just look at Mr. Braver, he won $10 Million dollars.  And it this tort happy world I suspect there will me much more.  Lawsuits seem to be like the new lottery.  Some people even do it for a living or a health plan.  Don't get me wrong, I want to kill spam at the roots, I'm just wondering how far lawsuits will take us in the right direction.  Unlike the RIAA, I don't think that lawsuit are the answer to life, the universe and every thing.  Hopefully,

    A federal trial court in Chicago has ruled recently that the ancient legal doctrine of trespass to chattels (meaning trespass to personal property) applies to the interference caused to home computers by spyware.

    read more | digg story

  • Surf web anonymous

    This sounds like a great way to surf:

    Mezzy bravely explores the user requested web page and uses his super
    powers to perform a number of essential security functions, such as
    neutralizing dangerous web elements, (Adware, Spy ware and potential
    viruses) all while protecting your Internet identity.

    read more | digg story

  • Disposable e-mail address roundup: mailiminator and others

    Here's a pretty nice roundup of some of the services available to create throwaway e-mail addresses to keep your inbox free from spam.

    There is a spam coutner-culture growing fast on the web.  With sites like mailiminator agressive on the front lines against spam I feel pretty good about the future.

    Here is how mailiminator works:  Say you see a really interesting $100K per day offer on the Internet! Surely, you can't pass it up.. this could be your big break.  The site even says so. The site wants you to simpply submit your email and the cash will come rolling in.   But your not sure because the last site you submited your email to offered $200K per day and as soon as you entered you email address you recieved 300K emails per day. 

    So instead of entering your address you just make up some junk mailiminator account and have all the traffic sent there instead.

    That is a good idea and here are many more antispam tools for you: 

    read more | digg story

  • Fingerprint Payment System Becoming a Reality.. privacy issues

    O.k.  Imagine walking into WalMart, gathering $10 in groceries and then instead of swipping your card, you press your finger in to a finger sized scanner. 

    German grocery chain Edeka introduced a new method of pay system, the so-called 'digiProof' late in 2004 and into 2005.  And now an American company called Pay By Touch is doing the exact samething.   

    A San Francisco start-up, Pay By Touch Solutions, is expected to announce today $130 million in fresh financing for a novel way of paying for groceries and other goods and services: a machine that reads your fingerprint.

    This is very Cyberpunk.  Depending on the implementation, this may even be more difficult for ID Theft criminals to take advantage of.  If everything goes in that direction, house hold phones could actually get the devices and you could make authenticated bill payments from your house and get rid of all your credit cards.     

    Then again since the fingerprint is translated into a number, I imagine criminals could still get ahold of the information the traditional way (unless the number can only be accessed with the original persons print):

    Here's how it works: Customers sign up once, by registering a checking account or a credit card, and showing government identification such as a driver's license. The Pay by Touch technology records the lines and ridges of their fingerprints, and translates the data into a numerical algorithm that is stored in a secure database. The customers thereafter never have to carry a wallet or purse back to the store, and can use their finger to pay for goods across the Pay By Touch network, which now includes stores in 10 states.

    The capital raised — $55 million of it in convertible notes and $75 million in loans — will help the company build out its finger-reading payment systems at several nationwide retailers, including in California in the first quarter of next year.

    This may also be a much better way to track people by there fingerprints and accounts.  Could this raise privacy issues?!  After all, fingerprints could link criminal records if you have any.  And wasn't there something in the bible about this…?  Oh, no.. that was 666.

    It may be harder to hack but it will eventually be broken.  But that doesn't mean its no good.

    read more | digg story

  • RIAA Sued for Hacking

    A 41-year old disabled single mother has counter-sued the RIAA for
    Oregon RICO violations, fraud, invasion of privacy, abuse of process,
    electronic trespass, violation of the Computer Fraud and Abuse Act, and
    negligent misrepresentation.

    read more | digg story

  • Security Issues May Be a High Priority for Internet 2

    Security is one of the main focuses on Internet2. But realistically:

    Security and transparency can be
    expected in any future network. But computer experts like to remind the
    public that there is no such thing as a completely bug free computer
    except, as the joke goes, “one that is encased in concrete and sitting
    at the bottom of the ocean.”

    Some might say it is impossible to secure Internet2.  In some ways
    I would say that they were correct.  Or let me put it this way, it
    could be secured but I couldn't really be called the Internet any
    more.  I guess if they did something like in which all systems
    were connect with Peer to Peer VPN connections like Tor connections in
    which all data is encrypted and digitally signed.  I suspect that
    eventually even the encryption would get cracked  since all crypto
    eventually meets its processor match.

    It could be called the CryptoNet!  Anyone logging on would have to
    sign on with a digital signature stored on some sort of Certifing
    Authority (CA).  Of course, this would make it possible to do
    MITM, man in the middle, attacks unless it was an enclave network in
    which ALL nodes with IPs had to have a digital signature.

    Such an implementation would greatly reduce the speed of connection but
    would give incredible nonrepudiation, confidentiality, and
    integrity.  The availability would suffer big time.

    Frankly, a “CryptoNet” would only be good for all the important
    transactions such as banks, hospitals and time sheets.  I would
    not want something like that for 95% of what I do on the Internet.

    Does anybody have any information on how I can get the hook up on “testing” the Internet2?

    read more | digg story

  • Wardriving Tools

    Great site that lists the best software for finding and decrypting wireless AP's.

    Morality of Wardriving tools.
    I do not personally wardrive but I think it is a great way to do an
    assessment of the security of your area.  I know some people
    wardrive just to find a free spot to surf.  This is the equivalent
    to walking up to every door in your neigborhood and twisting the knob
    to see if the door is unlocked.  Then walking in and watching
    cable on their couch and eating popcorn.  It is not right. 
    And I can not pretend that it is.

    Privacy of Publically dispensed Wireless Data
    But at the sametime, having a wireless service and NO security is like
    having a house with no walls.  How can there be a crime or theft
    of data and service when the data and service is spilling out freely
    into the air like a public water fountain. 

    Paying for Service and then serving it to the Public
    I pay for the water service at my house so if anyone else walks into my
    yard to use my water hose they are wrong.  But if I put that same
    hose into a nearby public park and turn it on, how guilty is anyone
    going to feel about taking a sip or splashing their face with it?

    So if you feel strongly about people NOT wardriving and not stealing
    service than do something about it.  I think that wardriving will
    dry up when the masses finally get wind of wireless security, until
    then “Surfs up.”

    read more | digg story

  • ID Theft and Finacial Fraud on companies and YOU

    You may have read numerous articles about how to protect yourself
    against Identity Theft and financial fraud by very practical and
    important methods such as shredding all mail with account information,
    but currently one of the greatest threats to your Identity is out of
    your hands.

    As stated in a July 2005 Newsweek
    article by Steven Levy and Brad Stone, “sometimes being careful is not
    enough when it comes to Identity Theft.”

    Many of the incidents of Financial Fraud and Identity Theft stem from
    security breaches and criminal activity at the corporations and
    financial institutions which we entrust our personal information too.
    Whi e it is important to be proactive by shredding billing mail or
    guarding your social security number, it is also important to be aware
    of what companies have “dropped the ball” and know how to react if your
    Identity is stolen.

    ID Theft & Finacial Fraud statistics:
    According the Federal Trade Commission, “Identity theft affects
    approximately 10 million Americans each year.”

    Identity theft takes many forms. The Federal Trade Commission (FTC)
    reports that in 2004 the most common type of identity theft was credit
    card fraud (28% of total complaints) followed by phone or utilities
    fraud (19%), bank fraud (18%), and employment fraud (13%).

    The Department of Justice calls ID theft the nation's fastest-growing financial crime.

    ID Theft at the Corporate level:

    DSW: 1.4 Million credit cards + 96,000 Check transactions

    Between November 2004 and February 2005, the DSW Show Warehouse
    database was accessed by thieves who stole 1.4 million credit card
    numbers plus 96,000 check transactions and the names on each of those
    accounts from 108 stores in 25 states.  DSW announced the incident
    in March 2005.
    /7550562/
    http://news.zdnet.com/2100-1009_22-5676211.html

    CardSystem: 40 Million

    On 17 June 2005, a payment processing center called CardSystem
    Solutions was robbed of data on 40 Million Credit Card.
    Now It\'s 40 Million Credit Cards

    http://elamb.blogharbor.com/blog/_archives/2005/9/28/1265301.html

    BJ: 40,000 accounts.
    BJ\'s Wholesale Club Inc operates 150 warehouse stores and 78 gas
    stations in 16 states.  The company went public in March 2004 with
    information on approximately 40 thousand credit card being possibly
    compromised.
    The FTC charged that BJ\'s engaged in a number of practices which,
    taken together, did not provide reasonable security for sensitive
    customer information. Specifically, the agency alleges that BJ\'s:
    Failed to encrypt consumer information when it was transmitted or
    stored on computers in BJ\'s stores;
    Created unnecessary risks to the information by storing it for up to
    30 days, in
    violation of bank security rules, even when it no longer needed the
    information;
    Stored the information in files that could be accessed using commonly
    known default user IDs and passwords;
    Failed to use readily available security measures to prevent
    unauthorized wireless connections to its networks; and
    Failed to use measures sufficient to detect unauthorized access to the
    networks or to conduct security investigations.
    http://www.ftc.gov/opa/2005/06/bjswholesale.htm

    “,1]
    );
    //–>http://msnbc.msn.com/id/7550562/

    http://news.zdnet.com/2100-1009_22-5676211.html

    CardSystem: 40 Million

    On 17 June 2005, a payment processing center called CardSystem
    Solutions was robbed of data on 40 Million Credit Card. Now It's 40
    Million Credit Cards

    http://elamb.blogharbor.com/blog/_archives/2005/9/28/1265301.html

    BJ: 40,000 accounts.

    BJ's Wholesale Club Inc operates 150 warehouse stores and 78 gas
    stations in 16 states.  The company went public in March 2004 with
    information on approximately 40 thousand credit card being possibly
    compromised.

    The FTC charged that BJ's
    engaged in a number of practices which, taken together, did not provide
    reasonable security for sensitive customer information. Specifically,
    the agency alleges that BJ's:

    Failed to encrypt consumer information when it was transmitted or stored on computers in BJ's stores;
    Created unnecessary risks to the information by storing it for up to 30
    days, in violation of bank security rules, even when it no longer
    needed the information;
    Stored the information in files that could be accessed using commonly known default user IDs and passwords;
    Failed to use readily available security measures to prevent unauthorized wireless connections to its networks;
    Failed to use measures sufficient to detect unauthorized access to the networks or to conduct security investigations.



    D([“mb”,”http://www.google.com/search?hl=en&lr=&c2coff=1&q=Bj%27s+Wholesale+club+credit+card

    Tips on being proactive and reactive to ID Theft and Financial Fraud:
    Pay attention to All your accounts.  Know the Who, What, When, Where
    and How of every transaction you make.  This means bank, and credit
    card account frequently and keeping a ledger or check book and
    receipts.
    Points of contact for watching your credit cards:
    Equifax, 800-997-2493, Disclosure Dept., P.O. Box 740241, Atlanta, GA
    30374; TransUnion, 800-888-4213, P.O. Box 1000, Chester, PA 19022; and
    Experian, 888-397-3742, P.O. Box 2104, Allen, TX 75013. Report errors
    promptly and in writing.
    freecreditreport.com

    Give as little information as possible.  Your digital fingerprint
    consists of your DOB, SSN, Phone Number, Address, Mothers Maiden name.
     All are usually asked of credit card companies when money is pulled
    out or address is changed.

    More on your digital fingerprint:
    Credit Card
    CW2
    Credit Report
    SSN
    Driver\'s License
    ATM cards
    Telephone carlling
    Mortgage
    DOB
    Password/PINS
    Home Address
    Phone Number

    Do NOT share your information with "other financial institutions."
    Often the financial institutions we bank with get credit from or the
    like will ask us if they can share your information with their
    "partners."  The answer is NO.
    Also opt out of pre-approved credit offers by calling the Credit
    Reporting Industry Pre-Screening Opt-Out Number at 888-567-8688.

    Cary as little ID as necessary when traveling.  Do you really need
    your Social Security card, and Birth Certificate where every your go?

    Shred ALL information with to many parts of your digital fingerprint
    “,1]
    );
    //–>
    Tips on being proactive and reactive to ID Theft and Financial Fraud:

    Pay attention to All your accounts.
     Know the Who, What, When, Where and How of every transaction you
    make.  This means bank, and credit card account frequently and
    keeping a ledger or check book and receipts.
    Points of contact for watching your credit cards:
    Equifax, 800-997-2493, Disclosure Dept., P.O. Box 740241, Atlanta, GA
    30374; TransUnion, 800-888-4213, P.O. Box 1000, Chester, PA 19022; and
    Experian, 888-397-3742, P.O. Box 2104, Allen, TX 75013. Report errors
    promptly and in writing. freecreditreport.com

    Give as little information as possible.  Your digital fingerprint
    consists of your DOB, SSN, Phone Number, Address, Mothers Maiden
    name.  All are usually asked of credit card companies when money
    is pulled out or address is changed.

    More on your digital fingerprint:
    Credit Card
    CW2
    Credit Report
    SSN
    Driver's License
    ATM cards
    Telephone carlling
    Mortgage
    DOB
    Password/PINS
    Home Address
    Phone Number

    Do NOT share your information with “other financial institutions.”
    Often the financial institutions we bank with get credit from or the
    like will ask us if they can share your information with their
    “partners.”  The answer is NO. Also opt out of pre-approved credit
    offers by calling the Credit Reporting Industry Pre-Screening Opt-Out
    Number at 888-567-8688.

    Cary as little ID as necessary when traveling.  Do you really need your Social Security card, and Birth Certificate where every your go?

    “,”
    Take mail with lots of your digital fingerprint (such as bill
    payments) to the post office.

    Allow waiters, and clerks to see your credit card and/or debit
    information as little as possible.
    Crooks can use a handheld card reader to copy the information from
    your card\'s magnetic strip.

    Beware strange ATMs. Avoid using private or strange-looking automated
    teller machines, because they may be rigged to skim data off your
    card\'s magnetic strip. Six- or seven-character PINs (personal
    identification numbers) are harder to crack than shorter ones, but you
    may not be able to use them at machines abroad.

    No surfing allowed. Watch out for "shoulder surfers" when using pay
    phones or public Internet access; use your free hand to shield the
    keypad. Don\'t use cordless phones to conduct sensitive financial or
    medical business, because eavesdroppers on other phones and those
    using eavesdropping equipment may be able to overhear your
    conversations.

    Build a wall. Install firewalls and virus-detection software on your
    home computers to discourage hackers.

    Log off. Quit your browser and log off after using public
    Internet-access computers in libraries, Internet cafes, and the like.
    Don\'t pay bills, bank, or conduct other financial transactions on
    public computers. If you have a high-speed Internet connection at
    home, unplug the computer\'s cable or phone line when you are not using
    it to discourage hackers.

    Deal only with reputable Web sites. Check privacy and security
    policies of Web sites before making purchases, trading stocks, or
    banking online. A professional-looking Web site is no guarantee of
    security. Don\'t respond to unsolicited e-mail requests for personal
    information.

    Get complicated. Consider password-protecting all your bank and
    brokerage accounts. Create passwords at least eight characters long.

    Check your workplace. Ask how your employer safeguards employee
    “,1]
    );
    //–>Shred ALL information with to many parts of your digital fingerprint.

    Take mail with lots of your digital fingerprint (such as bill Payments) to the post office.

    Beware strange ATMs. Avoid
    using private or strange-looking automated teller machines, because
    they may be rigged to skim data off your card's magnetic strip. Six- or
    seven-character PINs (personal identification numbers) are harder to
    crack than shorter ones, but you may not be able to use them at
    machines abroad.

    Surf safely on the InternetEnsure you have set up a firewall to protect your network.  All online banking and medical transactions must have secure means of trasfering information such as SSL or https to encrypt the data. 
    Secure transaction will forward you to a secure page “https” and
    usually have a symbol of a tiny lock in the corner. 

    Trust your digital signature to only reputable Web sites.

    Use secure passwords and password management techniques.

    Get involved. If you are interested in asking Congress to pass
    stronger financial privacy protections, visit
    www.financialprivacynow.org.

    Resources to battle Identity theft:
    http://www.privacyrights.org/
    http://www.idtheftcenter.org/index.shtml