Linux Privacy - Page 40
We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.
We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.
Occasionally a criminal is so, well, clever that you have to admire him even as you wish that he spends the rest of his life in jail. Take Arnold Rothstein, for instance. One of the kingpins of organized crime in New York City during Prohibition and before, the "Great Brain," as he was termed, was more than likely behind the infamous Black Sox scandal, in which the 1919 World Series was fixed in favor of the Cincinnati Reds. He is also widely credited with inventing the floating crap game immortalized in Guys and Dolls. Like some character out of a Damon Runyon story, Rothstein's "office" was outside of Lindy's Restaurant, at Broadway and 49th Street, and he associated with gangsters whose names still trip off the tongue three-quarters of a century later: Meyer Lansky, Legs Diamond, Lucky Luciano, Dutch Schultz. When it comes to colorful, clever criminals, Rothstein is at the top of the heap. And then, on the other end of the scale, today we have the phishers. Scumbags of the Web, phishers vomit out emails to as many millions of people as they can possibly reach, hoping that a tiny few will respond to their fraudulent request to update their account information at PayPal, eBay, or CitiBank (or just about any other bank you can imagine). This is an enormous problem, and it's not getting any better. I recently read a fascinating study that shows just why that's the case.
Identity management is a security issue which is becoming increasingly challenging as the perimeter of the network crumbles. This is well illustrated by the DTI Information Security Breaches Survey of 2006, which shows that one in five larger businesses had a security breach associated with weaknesses in their identity management, with the number of incidents being less for smaller companies.
The Y-M-C-A of Greater Providence is reporting that one of its two missing laptop computers contains members information. The non-profit organization that provides a range of educational, social and recreational services says it discovered last week that the computers were missing.
A study on workplace privacy found that less than half of the people surveyed believe their employers are doing a good job protecting the privacy of their personal information. The independent study, "Americans' Perceptions about Workplace Privacy," was conducted by Elk Rapids, Mich.-based Ponemon Institute LLC, which looks at information and privacy management practices in business and government. The report, which was released yesterday, is based on 945 responses from adults across the U.S. who work for companies with at least 1,000 employees.
The European Commission today issued a report that calls for greater education on IT security, and the creation of a common framework for collecting incident data. In its report, the EC states that European spending on IT security "represents only around 5 to 13 percent of IT expenditure, which is alarmingly low." The commission calls for a cross-border effort to educate users about security and to unify disjointed national efforts to track exploits.
Increasing numbers of university systems are becoming targets for hackers. The recent incident involves the Fairfield, Connecticut-based Sacred Heart University. The university's system containing information on 135,000 individuals was hacked recently and data consisting of personal information like names, addresses, and Social Security numbers were stolen.
Internet crime often starts with phishing, the practice of duping a user into revealing bank account or log-in credentials via a fraudulent Web site. Phishers send out reams of e-mail bait that say users' account information has expired or needs updating. The e-mail includes links to a site that may look very similar to their bank Web site, but isn't. Once those credentials are obtained, criminals use the information in a variety of creative and costly scams.
The U.S. public wants stronger federal data security legislation as its confidence wanes in current laws intended to protect them on the Internet, according to a new survey the Cybersecurity Industry Alliance released today. The April survey of 1,150 adults found that only 18 percent – less than one in five – believe that existing laws are sufficient to protect them on the Internet.
This month USA Today reported that the National Security Agency has been compiling and searching a massive database of Americans' telephone call records and data mining it for suspicious patterns. NPR reported that this activity was part of the same eavesdropping program The New York Times revealed in April.
Mark Diamond, consultant with Contoural Inc., said a survey of clients showed 29% found email archiving for the long term less risky, in terms of compliance, than attempting to reduce data, while 21% thought deleting data on a regular basis was less risky. Forty-two percent answered that they are not sure. A convincing case for long-term retention, however, was found when Diamond offered insight into the inner workings of a lawyers mind in a presentation to Chicago's storage networking user group Wednesday morning.
Philip R. Zimmermann wants to protect online privacy. Who could object to that? He has found out once already. Trained as a computer scientist, he developed a program in 1991 called Pretty Good Privacy, or PGP, for scrambling and unscrambling e-mail messages. It won a following among privacy rights advocates and human rights groups working overseas — and a three-year federal criminal investigation into whether he had violated export restrictions on cryptographic software. The case was dropped in 1996, and Mr. Zimmermann, who lives in Menlo Park, Calif., started PGP Inc. to sell his software commercially.
The Veterans Affairs Department announced today that a computer containing personal, identifying data for as many as 26 million American veterans has been stolen from a VA employee's home. A VA employee took files home as part of department work. Subsequently, someone broke into the employee’s home and stole the computer containing the files. Officials said the employee was not authorized to take the files home.
BellSouth is demanding that USA Today retract a story claiming it and two other carriers were under contract to the National Security Agency to surrender call records for a domestic anti-terrorism surveillance program. BellSouth claims the story's assertion that it was under contract to provide massive call record data to the NSA is untrue.
The most common retort against privacy advocates -- by those in favor of ID checks, cameras, databases, data mining and other wholesale surveillance measures -- is this line: "If you aren't doing anything wrong, what do you have to hide?" Some clever answers: "If I'm not doing anything wrong, then you have no cause to watch me." "Because the government gets to define what's wrong, and they keep changing the definition." "Because you might do something wrong with my information." My problem with quips like these -- as right as they are -- is that they accept the premise that privacy is about hiding a wrong. It's not. Privacy is an inherent human right, and a requirement for maintaining the human condition with dignity and respect.
The number of companies reporting a spyware infestation has increased by almost half in the past 12 months, according to a new survey. In addition, 17 percent of companies with more than 100 employees have spyware such as a keylogger on their networks, said the authors of the annual Websense Web@Work survey, published on Tuesday. "This is almost 50 percent growth in the instances of keyloggers that organizations are reporting back," said Joel Camissar, a manager for Internet security specialist Websense.
A Home Office department is fingerprinting under-fives, and may include babies, in a biometrics ID scheme. The trial ends the department’s technological taboo on enrolling very young children in identity checks. Details of the scheme emerged after the Home Office released an internal report under the Freedom of Information Act, which contained a section on fingerprinting under-fives. The UK could be one of the first countries to fingerprint under-fives – and possibly the first. When Malaysian police last year proposed fingerprinting of babies there were strong protests from civil liberties groups in the country.
The night Cindy M.* disappeared, she ate dinner with her parents and older brother in the family’s two-story suburban Pittsburgh home, then went to her room and promised to come back for apple-walnut pie. The pretty 13-year-old with dark blond hair and blue-green eyes never returned. When her parents checked her room, they found neither a note nor a sign of forced entry. It was New Year’s Day, 2002, and their daughter was simply gone. Pittsburgh police spent almost two days interviewing Cindy’s friends and family, while neighbors scoured nearby fields and gullies, but everyone came up empty.
To her fellow students, Hu Yingying appears to be a typical undergraduate, plain of dress, quick with a smile and perhaps possessed of a little extra spring in her step, but otherwise decidedly ordinary. And for Hu, in her second year at Shanghai Normal University, coming across as ordinary is just fine, given the parallel life she leads. For several hours each week she repairs to a little-known on-campus office crammed with computers, where she logs on, unsuspected by other students, to help police her university's Internet forums.
LOS ANGELES (Reuters) - A 20-year-old who prosecutors say highjacked computers to damage computer networks and send waves of spam across the Internet was sentenced on Monday to nearly five years in prison. Jeanson James Ancheta, a well-known member of the "Botmaster Underground" who pleaded guilty in January to federal charges of conspiracy, fraud and damaging U.S. government computers, was given the longest sentence for spreading computer viruses, federal prosecutors said.
Malicious software coded by cyber criminals for financial gain accounted for some 70 percent of all malware detected during the first quarter of 2006, according to a report released today. According to a new study from anti-virus developer Panda Software, the new malware dynamic saw financial profit become malicious software creators' top priority. Of all malware detected by the company's free online scanner, about 40 percent was spyware. Some 17 percent of the total was made up by trojans, including banker trojans that steal confidential data related to bank services and "droppers" or "downloaders" that download malicious applications onto systems.