<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:georss="http://www.georss.org/georss" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0"><id>tag:blogger.com,1999:blog-25971470</id><updated>2009-09-15T10:50:56.635-07:00</updated><title type="text">TRUST Security and Privacy Blog</title><subtitle type="html">Security and Privacy news items</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://trust-news.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/" /><link rel="hub" href="http://pubsubhubbub.appspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default?start-index=26&amp;max-results=25" /><author><name>Marci Meingast</name><email>noreply@blogger.com</email></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>381</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><link rel="self" href="http://feeds.feedburner.com/TrustSecurityAndPrivacyBlog" type="application/atom+xml" /><feedburner:browserFriendly></feedburner:browserFriendly><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><entry><id>tag:blogger.com,1999:blog-25971470.post-6846313027423665219</id><published>2009-09-15T10:45:00.001-07:00</published><updated>2009-09-15T10:50:56.647-07:00</updated><title type="text">Nonprofit for collecting info on SCADA &amp; PCS security incidents</title><content type="html">The &lt;a href="http://catless.ncl.ac.uk/Risks/25.78.html#subj10"&gt;Risks Digest&lt;/a&gt; has an item that refers to &lt;a href="http://www.managingautomation.com/maonline/news/read/NonProfit_Targets_CyberSecurity_in_Plants_33037"&gt;Stephanie Neil's article in "Managing Automation", 12 Sep 2009&lt;/a&gt; that discusses the &lt;a href="http://www.securityincidents.org/"&gt;http://www.securityincidents.org&lt;/a&gt;, "a newly formed non-profit group that provides public access to its Repository of Industrial Security Incidents (RISI)".  This group is targeted towards SCADA and process control security incidents.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-6846313027423665219?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/6846313027423665219" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/6846313027423665219" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2009/09/nonprofit-for-collecting-info-on-scada.html" title="Nonprofit for collecting info on SCADA &amp; PCS security incidents" /><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="14163372461661555249" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-5439012117588354673</id><published>2009-09-10T16:52:00.000-07:00</published><updated>2009-09-10T17:10:25.551-07:00</updated><title type="text">How much are you worth on the black market?</title><content type="html">&lt;a href="http://yro.slashdot.org/story/09/09/10/1837233/How-Much-Is-Your-Online-Identity-Worth"&gt; &lt;i&gt;Slashdot&lt;/i&gt;&lt;/a&gt; reports a new tool being developed by Symantec intended to raise consumer awareness about cybercrime.  By answering a few questions about personal Internet use, the tool calculates your net worth on the black market calculations in three areas: how much your online assets are worth, how much your online identity would sell for on the black market, and your risk of becoming a victim of identity theft.  &lt;br /&gt;&lt;br /&gt;Norton's Online Risk Calculator is not intended to promote software or instill fear but to raise awareness about cybercrime, according to Marian Merritt, Internet security advocate for Symantec.  Merritt pointed out that cybercrime is now larger than the international drug trade. Nearly 10 million people have reported identity theft in United States in the past 12 months and one in four households have already been victimized, she said.&lt;br /&gt;&lt;br /&gt;Cybercrime is well reported in the IT space, but the message doesn't often reach the general public, according to Merritt. "You turn on the news and they are talking about capturing drug dealers going across the border, but they rarely show a hacker in handcuffs," she said.&lt;br /&gt;&lt;br /&gt;See more in &lt;a href="http://www.itworld.com/software/77238/how-much-are-you-worth-black-market"&gt; IT WORLD&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-5439012117588354673?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/5439012117588354673" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/5439012117588354673" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2009/09/how-much-are-you-worth-on-black-market.html" title="How much are you worth on the black market?" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-3874023067047524178</id><published>2009-08-16T16:24:00.000-07:00</published><updated>2009-08-16T16:32:31.722-07:00</updated><title type="text">NIST Releases Security Standards for Federal Systems</title><content type="html">The &lt;a href="http://www.nist.gov/index.html"&gt;National Institute of Standards and Technology&lt;/a&gt; (NIST) released &lt;a href="http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final.pdf"&gt;Special Publication 800-53&lt;/a&gt;, titled &lt;i&gt;Recommended Security Controls for Federal Information Systems and Organizations&lt;/i&gt;.  This document addresses information security standards and guidelines, including minimum requirements for federal information systems.  Released as part of NIST’s statutory responsibilities under the Federal Information Security Management Act (FISMA), this publication is geared toward information system and information security professionals who develop, implement, operate, manage, or assess/monitor federal information systems.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-3874023067047524178?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/3874023067047524178" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/3874023067047524178" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2009/08/nist-releases-security-standards-for.html" title="NIST Releases Security Standards for Federal Systems" /><author><name>Larry Rohrbough</name><uri>http://www.blogger.com/profile/01122887820002175089</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02880242644530164295" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-1173282041917509306</id><published>2009-07-23T16:46:00.000-07:00</published><updated>2009-07-23T17:44:57.465-07:00</updated><title type="text">Adobe Vulnerability Targeted in Drive-by Attacks</title><content type="html">eWEEK.COM is running a story about a new zero-day vulnerability affecting Adobe's Flash Player software that is being exploited by attackers via drive-by downloads.&lt;br /&gt;&lt;br /&gt;Adobe first warned about the vulnerability July 21, then issued an updated advisory the next night.  The issue affects current versions of Flash Player on Windows, Mac and Linux platforms.&lt;br /&gt;&lt;br /&gt;According to the U.S. Computer Emergency Response Team (US-CERT), an attacker can trigger an overflow by luring a user into opening a malicious Flash (SWF) file that is either hosted or embedded on a Web page or contained in a PDF file.  Then the attacker could either trigger a system crash or take full control of a vulnerable system.&lt;br /&gt;&lt;blockquote&gt;“There are reports that this vulnerability is being actively exploited in the wild via limited, targeted attacks against Adobe Reader v9 on Windows,” according to a post on the Adobe Product Security Incident Response Team blog. “We are in the process of developing a fix for the issue, and expect to provide an update for Flash Player v9 and v10 for Windows, Macintosh, and Linux by July 30, 2009(the date for Flash Player v9 and v10 for Solaris is still pending). We expect to provide an update for Adobe Reader and Acrobat v9.1.2 for Windows, Macintosh, and UNIX by July 31, 2009.” &lt;/blockquote&gt;&lt;blockquote&gt;“At the moment there (are) a low number of malicious sites serving the exploit, but we confirmed that the links have been injected in legitimate Websites to create a drive-by attack, as expected,” according to SANS Internet Storm Center. &lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;See full article at &lt;a href="http://www.eweek.com/c/a/Security/Adobe-Vulnerability-Targeted-in-Driveby-Attacks-695016/"&gt; eWEEK.COM&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-1173282041917509306?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/1173282041917509306" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/1173282041917509306" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2009/07/adobe-vulnerability-targeted-in-drive.html" title="Adobe Vulnerability Targeted in Drive-by Attacks" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-3682772571256217996</id><published>2009-07-07T17:51:00.000-07:00</published><updated>2009-07-07T18:03:39.563-07:00</updated><title type="text">Google Book Search Settlement Inquiry Announced</title><content type="html">ISEDB's article "&lt;a href="http://www.isedb.com/db/articles/2090/1/Google-Book-Search-Settlement-Inquiry-Announced/Page1.html"&gt;Google Book Search Settlement Inquiry Announced&lt;/a&gt;" includes a link to &lt;a href="http://www.truststc.org/people/directory/pam"&gt;Pam Samuelson's&lt;/a&gt; talk &lt;a href="http://bit.ly/yxjs3"&gt;Reflections on the Google Book Search Settlement&lt;/a&gt;.  See also her 4/17/09 guest blog "&lt;a href="http://radar.oreilly.com/2009/04/legally-speaking-the-dead-soul.html"&gt;Legally Speaking: The Dead Souls of the Google Booksearch Settlement&lt;/a&gt;", where she says:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;"In the short run, the Google Book Search settlement will unquestionably bring about greater access to books collected by major research libraries over the years. But it is very worrisome that this agreement, which was negotiated in secret by Google and a few lawyers working for the Authors Guild and AAP (who will, by the way, get up to $45.5 million in fees for their work on the settlement—more than all of the authors combined!), will create two complementary monopolies with exclusive rights over a research corpus of this magnitude. Monopolies are prone to engage in many abuses."&lt;br /&gt;&lt;br /&gt;&lt;p&gt;"The Book Search agreement is not really a settlement of a dispute over whether scanning books to index them is fair use. It is a major restructuring of the book industry’s future without meaningful government oversight. The market for digitized orphan books could be competitive, but will not be if this settlement is approved as is."&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Professor Samuelson points out that "nothing in the settlement agreement speaks about privacy interests of users" and that this is very different than how libraries operate.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-3682772571256217996?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/3682772571256217996" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/3682772571256217996" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2009/07/google-book-search-settlement-inquiry.html" title="Google Book Search Settlement Inquiry Announced" /><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="14163372461661555249" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-3349911122813588261</id><published>2009-05-26T16:34:00.001-07:00</published><updated>2009-05-27T09:41:06.827-07:00</updated><title type="text">Announcement:  2nd Annual Privacy Law Scholar Conference, June 4-5 2009</title><content type="html">The 2nd Annual Privacy Law Scholars Conference (PLSC) will be held at the Claremont Resort in Berkeley, CA, on June 4-5.  PLSC is an academic paper workshop, and there are no panels of boring talking heads.  Instead, we have two days of intense discussion about privacy issues.&lt;br /&gt;&lt;br /&gt;If you have students who are interested in working in the privacy field, I strongly encourage you to pass on info about the event.  It's free, and about 100 privacy academics (predominately law, but also econ and some computer science, including Peter Neumann, Chris Soghoian, and Jeff Jonas, the inventor of NORA) participate, as well as 50 leading legal practitioners.  It's a wonderful opportunity to network, share ideas,etc.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://docs.law.gwu.edu/facweb/dsolove/PLSC/"&gt;  &lt;i&gt;Schedule and information&lt;/i&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The password to all papers is &lt;code&gt;plsc2009&lt;/code&gt;.&lt;br /&gt;&lt;br /&gt;Send email to choofnagle at law.berkeley.edu if you would like to participate.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-3349911122813588261?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/3349911122813588261" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/3349911122813588261" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2009/05/announcement-2nd-annual-privacy-law.html" title="Announcement:  2nd Annual Privacy Law Scholar Conference, June 4-5 2009" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-5588579183945191038</id><published>2009-05-14T09:23:00.000-07:00</published><updated>2009-05-14T09:41:14.930-07:00</updated><title type="text">Mathematical Advances Strengthen IT Security</title><content type="html">&lt;a href="http://technews.acm.org/"&gt; ACM TechNews&lt;/a&gt; is running an article about a new cryptography approach based on the mathematical theory of elliptic curves, a leading candidate to replace the widely used RSA public key security system.&lt;br /&gt;&lt;br /&gt;Elliptic curves are equasions with two variables, e.g., x and y, including terms where both x and y are raised to powers of two or more. The possibilities for elliptic curves and other modern mathematical techniques were discussed at a recent workshop organized by the European Science Foundation (ESF).&lt;blockquote&gt;“The impact of the elliptic curve method for integer factorisation (developed by my PhD advisor Hendrik Lenstra) has played a role in introducing elliptic curves to cryptographers, albeit for attacking the underlying problem on which RSA is based (the difficulty of factoring integers),” said David Kohel, convenor of the ESF workshop, from the Institut de Mathematiques de Luminy in Marseille, France. &lt;/blockquote&gt;&lt;br /&gt;Kohel describes the advantage of elliptic curve cryptography as its immunity to the specialized attacks that have degraded the strength of RSA (smaller keys can be used to provide the same levels of protection).&lt;blockquote&gt;"In general, the cryptographer has the benefit over the cryptanalyst (the person attacking the cryptosystem) as he or she can select the key size for any desired level of security, provided everyone has the same base of knowledge of best attacks on the underlying cryptosystem," he says.&lt;/blockquote&gt;&lt;br /&gt;See details in &lt;a href="http://www.esf.org/activities/exploratory-workshops/news/ext-news-singleview/article/mathematical-advances-strengthen-it-security-579.html"&gt; &lt;i&gt;European Science Foundation&lt;/i&gt;&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-5588579183945191038?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/5588579183945191038" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/5588579183945191038" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2009/05/acm-technews-is-running-article-about.html" title="Mathematical Advances Strengthen IT Security" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-1640038329239099580</id><published>2009-04-28T09:21:00.000-07:00</published><updated>2009-04-28T09:43:35.928-07:00</updated><title type="text">Chinese Hackers Targeting NYPD Computers</title><content type="html">&lt;a href="http://news.slashdot.org/article.pl?sid=09/04/23/2025243"&gt; Slashdot&lt;/a&gt; prints an article about a network of mystery hackers, mostly based in China, making 70,000 attempts a day to break into the NYPD's sytem, according to Commissioner Raymond Kelly.  He said he suspects that his department is being targeted by foreign hackers because it has beefed up operations in the international arena since the 9/11 attacks.&lt;blockquote&gt;"We are constantly studying events worldwide and assessing their implications for New York," said Kelly, adding that the NYPD now has officers stationed in Abu Dhabi, Jordan, Great Britain, France, Spain, Canada and the Dominican Republic.&lt;/blockquote&gt; Kelly also said senior police officers have been attending lectures by foreign affairs and terrorism experts. The Commissioner's surprising revelations closely followed a Canadian report exposing a China-based electronic spy network that has invaded at least 1295 computers in 103 countries.&lt;br /&gt;&lt;br /&gt;Dubbed "GhostNet", the group of hackers have targeted embassies, foreign ministries and the Dalai Lama's offices in India, Brussels, London and New York. &lt;br /&gt;&lt;br /&gt;Toronto University's 10-month study suggests that the GhostNet is linked to Chinese government espionage agencies, which Chinese government officials deny.&lt;br /&gt;&lt;br /&gt;See complete article in the &lt;a href="http://www.nydailynews.com/news/2009/04/22/2009-04-22_international_hackers_lauching_attack_against_nypd_computers.html"&gt; New York Daily News&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-1640038329239099580?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/1640038329239099580" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/1640038329239099580" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2009/04/chinese-hackers-targeting-nypd.html" title="Chinese Hackers Targeting NYPD Computers" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-9171616822814009867</id><published>2009-04-22T17:33:00.000-07:00</published><updated>2009-04-22T17:57:07.987-07:00</updated><title type="text">Most electronic voting isn't secure, CIA expert says</title><content type="html">&lt;a href="http://catless.ncl.ac.uk/Risks/25.64.html#subj6"&gt; The Risks Digest&lt;/a&gt; points to an article about a CIA agent testifying before the Election Assistance Commission.  His position is that electronic votes are not secure and can be altered and further, are being altered already in some locales.&lt;br /&gt;&lt;br /&gt;The CIA agent, a cybersecurity expert, suggested that Venezuelan President Hugo Chavez and his allies fixed a 2004 election recount, a pronouncement that could further agitate U.S. relations with the Latin leader.&lt;br /&gt;&lt;br /&gt;In a presentation that could provide foreboding lessons for the United States, where electronic voting is becoming preeminent, Steve Stigall summarized what he described as attempts to use computers to undermine democratic elections in developing nations.  Stigall told the Election Assistance Commission that computerized electoral systems can be manipulated at five stages, from altering voter registration lists to posting results.&lt;blockquote&gt;"You heard the old adage 'follow the money,' " Stigall said, according to a transcript of his hour-long presentation that McClatchy obtained. "I follow the vote. And wherever the vote becomes an electron and touches a computer, that's an opportunity for a malicious actor potentially to . . . make bad things happen."&lt;/blockquote&gt;&lt;br /&gt;Stigall said that some countries had taken extraordinary steps that improved security.  For example, he said internet systems that encrypt vote results so they're unrecognizable during transmission "greatly complicates malicious corruption."&lt;br /&gt;&lt;br /&gt;After reviewing the agent's remarks, director of election reform for the citizens' lobby 'Common Cause, Susannah Goodman says they showed &lt;blockquote&gt;"we can no longer ignore the fact that all of these risks are present right here at home . . . and must secure our election system by requiring every voter to have his or her vote recorded on a paper ballot."&lt;/blockquote&gt;&lt;br /&gt;See complete article in &lt;a href="http://www.mcclatchydc.com/226/story/64711.html"&gt; McClatchy Newspapers&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-9171616822814009867?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/9171616822814009867" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/9171616822814009867" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2009/04/most-electronic-voting-isnt-secure-cia.html" title="Most electronic voting isn't secure, CIA expert says" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-5029753258141183022</id><published>2009-01-26T08:43:00.000-08:00</published><updated>2009-01-26T09:15:05.995-08:00</updated><title type="text">Obama Sides With Bush In Spy Case</title><content type="html">&lt;a href="http://news.slashdot.org/article.pl?sid=09/01/23/1744250"&gt; Slashdot &lt;/a&gt; picked up a story in &lt;span style="font-style:italic;"&gt;Wired&lt;/span&gt; about the Obama administration siding with the Bush administration when it urged a federal judge to set aside a ruling in a closely watched case examining whether a U.S. president may bypass Congress and establish warrantless wiretapping programs designed to spy on American citizens.&lt;br /&gt;&lt;br /&gt;With just hours left in office, President George W. Bush asked U.S. District Judge Vaughn Walker late Monday to stay enforcement of a Jan.5 ruling admitting key evidence into the case.  On Thursday, the Obama administration said in its filing with the court&lt;blockquote&gt;"The Government's position remains that this case should be stayed" &lt;/blockquote&gt;marking the first time it was clear that the new president was in agreement with the Bush administration's reasoning in this case.&lt;br /&gt;&lt;br /&gt;The legal hubbub concerns Walker's decision to admit a classified document as evidence that allegedly shows that two American lawyers for a now-defunct Saudi charity were electronically eavesdropped on without warrants in 2004.&lt;br /&gt;&lt;br /&gt;The Obama administration is in agreement with the previous administration in its legal defense of July legislation that immunizes the nation's  telecommunications companies from lawsuits accusing them of complicity in Bush's eavesdropping program, according to testimony last week by incoming Attorney General Eric Holder.&lt;br /&gt;&lt;br /&gt;A separate case requiring a decision on the constitutionality of the immunity legislation (which Obama voted for as a U.S. Senator from Illinois) brought by the Electronic Frontier Foundation is pending before Judge Walker.&lt;br /&gt;&lt;br /&gt;See details in &lt;a href="http://blog.wired.com/27bstroke6/2009/01/obama-sides-wit.html"&gt; Wired&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-5029753258141183022?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/5029753258141183022" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/5029753258141183022" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2009/01/obama-sides-with-bush-in-spy-case.html" title="Obama Sides With Bush In Spy Case" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-6387826707999041088</id><published>2009-01-21T15:50:00.001-08:00</published><updated>2009-01-21T16:09:31.848-08:00</updated><title type="text">Privacy Groups Want Strong Security Measures for Electronic Health Records</title><content type="html">&lt;a href="https://www.sans.org/newsletters/newsbites/newsbites.php?vol=11&amp;issue=5#sID201"&gt; SANS Institute&lt;/a&gt;  summarizes an article about US privacy rights and civil liberties advocacy groups writing legislators and asking them to ensure that any adoption of electronic health records include substantial security measures. Such letters from the American Civil Liberties Union, the National Association of Social Workers and Patient Privacy rights request that patients have control over how their medical records are used and that they be protected from organizations that share and sell medical information. &lt;blockquote&gt;"We all want to innovate and improve health care, but without privacy our system will crash as any system with a persistent and chronic virus will," Patient Privacy Rights executive director Ashley Katz said at a Capitol Hill briefing.&lt;/blockquote&gt; Chairman of Senate Health, Education, Labor and Pensions, Edward Kennedy and ranking member Michael Enzi submitted a bill in the 110th Congress and have worked with Judiciary Chairman Patrick Leahy to beef up its privacy provisions. However, Senate Small Business ranking member Olympia Snowe does not believe the measure went far enough, and together with Rep. Edward Markey, D-Mass., and Rep. Lloyd Doggett, D-Texas, offered letters of support for the privacy groups' call to action.&lt;blockquote&gt;"Without robust safeguards, the health IT systems we are planning for today could turn the dream of integrated, seamless electronic health networks into a nightmare for consumers," Markey said in a statement.&lt;/blockquote&gt;&lt;br /&gt;For complete article, see &lt;a href="http://www.nextgov.com/nextgov/ng_20090115_7415.php"&gt; nextgov&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-6387826707999041088?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/6387826707999041088" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/6387826707999041088" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2009/01/privacy-groups-want-strong-security.html" title="Privacy Groups Want Strong Security Measures for Electronic Health Records" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-7283395495007876960</id><published>2009-01-13T09:10:00.000-08:00</published><updated>2009-01-13T09:55:18.669-08:00</updated><title type="text">CWE/SANS TOP 25 Most Dangerous Programming Errors</title><content type="html">Yesterday, the SysAdmin, Audit, Network, Security (&lt;span style="font-style:italic;"&gt;SANS&lt;/span&gt;) Institute announced that in Washington D.C., experts from more than 30 U.S. and international cyber security organizations jointly released a list of the 25 most dangerous programming errors that bring about security bugs permitting cyber espionage and cyber crime. The project is a significant component of an overall national security initiative. &lt;br /&gt;&lt;br /&gt;The impact of such errors is extensive, where just two errors led to more than 1.5 million web site security breaches in 2008.  Those breaches then cascaded onto the computers of people who visited those websites.&lt;br /&gt;&lt;br /&gt;The people and organizations that provided input to the project are among the most respected security experts, coming from an extensive range of leading organizations such as Symantec, Microsoft, DHS's National Cyber Security Division, and NSA's Information Assurance Division to the Japaneses IPA, to the University of California at Davis and Purdue University.&lt;br /&gt;&lt;br /&gt;Remarkably, all the experts quickly came to agreement, despite some intense discussion.&lt;blockquote&gt;"There appears to be broad agreement on the programming errors," says SANS Director, Mason Brown, "Now it is time to fix them. First we need to make sure every programmer knows how to write code that is free of the Top 25 errors, and then we need to make sure every programming team has processes in place to find, fix, or avoid these problems and has the tools needed to verify their code is as free of these errors as automated tools can verify."&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;See complete Announcement in &lt;a href="http://www.sans.org/top25errors//"&gt; SANS&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-7283395495007876960?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/7283395495007876960" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/7283395495007876960" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2009/01/cwesans-top-25-most-dangerous.html" title="CWE/SANS TOP 25 Most Dangerous Programming Errors" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-1773273683455907471</id><published>2009-01-08T16:03:00.000-08:00</published><updated>2009-01-08T16:22:49.871-08:00</updated><title type="text">State Secrets Defense Rejected in Wiretapping Case</title><content type="html">&lt;a href="http://yro.slashdot.org/article.pl?sid=09/01/06/2056249"&gt; Slashdot&lt;/a&gt; references a report in Ars Technica of a federal judge ruling that a lawsuit filed by an Islamic charity alleging illegal wiretapping by the National Security Agency may proceed.&lt;br /&gt;&lt;br /&gt;The case, &lt;i&gt;Al Haramain v. Bush&lt;/i&gt;, stands out in that unlike the Electronic Frontier's more widely publicized suits agains the NSA and cooperating telecoms, the plaintiffs here know that the directors of the charity were specifically subjected to warrantless surveillance, thanks to a government faux pas that put a classified memo in the hands of the charity's lawyers.&lt;br /&gt;&lt;br /&gt;Judge Vaughn Walker, who has been handling a raft of suits concerning the NSA's super-secret &lt;i&gt;Stellar Wind&lt;/i&gt; program decided that the charity could seek to show they'd been spied upon using public evidence.&lt;blockquote&gt;"Without a doubt," he wrote, plaintiffs have alleged enough to plead 'aggrieved persons' status so as to proceed to the next step in proceedings."&lt;/blockquote&gt;The Justice Department repeatedly tried to try to block the suit by invoking national security concerns.  At one point, Walker described the government's argument "without merit" and characterized another argument as "circular".&lt;br /&gt;&lt;br /&gt;See complete report at &lt;a href="http://arstechnica.com/news.ars/post/20090106-judge-doesnt-buy-state-secrets-privilege-oks-wiretap-suit.html"&gt; Ars Technica&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-1773273683455907471?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/1773273683455907471" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/1773273683455907471" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2009/01/state-secrets-defense-rejected-in.html" title="State Secrets Defense Rejected in Wiretapping Case" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-3842431770750733063</id><published>2008-12-24T10:58:00.000-08:00</published><updated>2008-12-24T11:48:06.402-08:00</updated><title type="text">Congress in the Cyber-Crosshairs</title><content type="html">&lt;a href="http://technews.acm.org/#391938"&gt; ACM TechNews&lt;/a&gt; points out the cover story of National Journal about what it will take to keep the next invader out of Congressional computers.&lt;br /&gt;&lt;br /&gt;Two years ago, 15 House panels and members' offices were invaded by malware whose nature suggest the intrusions originated in China. One target, the office of House Representative Frank Wolf (R-Va) argued before the House that the fear of admitting vulnerability might be a reason underlying U.S. intelligence and national security's reluctance ro publicize the breaches sooner.&lt;blockquote&gt;"I strongly believe that the appropriate officials, including those from the Department of Homeland Security and the FBI, should brief all members of Congress in a closed session regarding threats from China and other countries against the security of House technology, including our computers, BlackBerry devices, and phones," he said.&lt;/blockquote&gt;While it appears that there is little interest from members of Congress in discussing cyber vulnerabilities, it is likely because they have little understanding of them.  Former director the DHS' Cyber Security Division Amit Yoran says &lt;blockquote&gt;"As a member of Congress, you have so many issues competing for your attention and, historically, cyber-security hasn't been one that's won out. It's not an issue that is particularly well tracked by their constituents."&lt;/blockquote&gt;In a recent study prepared by the Center for Strategic and International Studies concluded for President-elect Barack Obama that Congress is unsuited for managing executive-branch cybersecurity due to the inconsistency and fragmentation of its oversight. The study group recommended that Obama take charge of cybersecurity and establish a new office for cyberspace in the Executive Office of the President that would collaborate closely with the National Security Council, "managing the many aspects of securing our national networks while protecting privacy and civil liberties."&lt;br /&gt;&lt;br /&gt;See complete article at &lt;a href="http://www.nationaljournal.com/njmagazine/cs_20081220_6787.php"&gt; National Journal Magazine&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-3842431770750733063?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/3842431770750733063" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/3842431770750733063" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2008/12/congress-in-cyber-crosshairs.html" title="Congress in the Cyber-Crosshairs" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-5876634213596631709</id><published>2008-12-08T16:11:00.000-08:00</published><updated>2008-12-08T16:28:53.634-08:00</updated><title type="text">U.S. Is Losing Global Cyberwar, Commission Says</title><content type="html">&lt;a href="http://technews.acm.org/#390398"&gt; ACM TechNews&lt;/a&gt; summarizes an article in Business Week about how ill prepared the United States is for the challenges of 21st century cybersecurity. This woeful conclusion comes from a new report issued by the U.S. Commission on Cybersecurity.  &lt;blockquote&gt;The damage from cyber attack is real," states the cybersecurity group's report, referring to intrusions last year at the departments of Defense, State, Homeland Security, and Commerce as well as at NASA and the Natoinal Defense University in 2007.&lt;/blockquote&gt;The report calls for the creation of a Center for Cybersecurity Operations that would act as a regulator of computer security in both the public and private sectors.&lt;blockquote&gt; "We're playing a giant game of chess now and we're losing badly," says commission member Tom Kellermann, a former World Bank security official who now is vice-president of Security Awareness at Core Security.&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;See full story in &lt;a href="http://www.businessweek.com/bwdaily/dnflash/content/dec2008/db2008127_817606.htm"&gt; BusinessWeek&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-5876634213596631709?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/5876634213596631709" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/5876634213596631709" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2008/12/us-is-losing-global-cyberwar-commission.html" title="U.S. Is Losing Global Cyberwar, Commission Says" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-6988191575258693813</id><published>2008-12-05T15:43:00.000-08:00</published><updated>2008-12-05T16:21:29.108-08:00</updated><title type="text">Who Protects the Internet?</title><content type="html">&lt;a href="http://tech.slashdot.org/article.pl?sid=08/12/03/2350256"&gt; Slashdot&lt;/a&gt; calls attention to an interview with General Kevin Chilton , U.S. STRATCOM commander and the head of all military cyberwarefare appearing in TechCrunch, a technical weblog that profiles and reviews Internet products and companies.&lt;br /&gt;&lt;br /&gt;The interview brings to light the critical question: Is the internet actually protected?  Who protects us? &lt;blockquote&gt;"Basically no one", says Jonathan Zittrain, American law professor, researcher and author. "At most, a number of loose confederations of computer scientists and engineers who seek to devise better protocols and practices — unincorporated groups like the Internet Engineering Task Force and the North American Network Operators Group. But the fact remains that no one really owns security online, which leads to gated communities with firewalls — a highly unreliable and wasteful way to try to assure security."&lt;/blockquote&gt;&lt;br /&gt;See more in &lt;a href="http://www.techcrunch.com/2008/12/02/who-protects-the-internet/"&gt; TechCrunch&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-6988191575258693813?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/6988191575258693813" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/6988191575258693813" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2008/12/who-protects-internet.html" title="Who Protects the Internet?" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-8723659402637462125</id><published>2008-12-03T16:02:00.000-08:00</published><updated>2008-12-04T07:22:57.654-08:00</updated><title type="text">You're Leaving a Digital Trail.  What About Privacy?</title><content type="html">&lt;a href="http://technews.acm.org/#389623"&gt; ACM TechNews&lt;/a&gt; picked up an article published in The New York Times on how new technologies and the Internet's incursion into every aspect of life is creating what is coming to be called 'collective intelligence'.&lt;br /&gt;&lt;br /&gt;While collective intelligence offers powerful capabilities, such as improving the efficiency of advertising or giving community groups new organizational capabilities, it is clear to all that, if misused, collective intelligence tools could create an Orwellian future on an unprecedented scale. Collective intelligence could be used by insurance companies, for example, to covertly identify people suffering from a particular disease and then deny them insurance coverage. Or the government or law enforcement could identify members of a protest group by monitoring social networks.&lt;blockquote&gt; “There are so many uses for this technology — from marketing to war fighting — that I can’t imagine it not pervading our lives in just the next few years,” says Steve Steinberg, a computer scientist who works for an investment firm in New York. &lt;/blockquote&gt; Steinberg argues in a well-known Web posting that there were significant chances it would be misused, "This is one of the most significant technology trends I have seen in years; it may also be one of the most pernicious.”&lt;br /&gt;&lt;br /&gt;See more in &lt;a href="http://www.nytimes.com/2008/11/30/business/30privacy.html?_r=1"&gt; The New York Times&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-8723659402637462125?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/8723659402637462125" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/8723659402637462125" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2008/12/youre-leaving-digital-trail-what-about.html" title="You're Leaving a Digital Trail.  What About Privacy?" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-7168129865259386308</id><published>2008-11-24T15:36:00.000-08:00</published><updated>2008-11-24T15:58:04.933-08:00</updated><title type="text">Obama Administration to Inherit Tough Cybersecurity Challenges</title><content type="html">&lt;a href="http://technews.acm.org/#388430"&gt;ACM TechNews&lt;/a&gt; remarks on the status of the initiatives launched in the current administration and what U.S. President-elect Barack Obama will need to take on to improve cybersecurity.  Many of the current initiatives are still works in progress, including the Homeland Security Presidential Directive-12 (HSPD-12) which aspires to improve the security of government facilities and computer networks by requiring federal agencies to issue new smart card identity credentials to all employees and contractors by the end of October. Meeting that goal is at least two years away however.&lt;br /&gt;&lt;br /&gt;The need is critical for the Obama administration to stop tying federal cybersecurity responses so closely to the post-9/11 war against terror, says analyst at Gartner Inc., John Pescatore.&lt;blockquote&gt;"The terrorist attacks of 2001 sent the Bush administration in the wrong direction" on the cybersecurity front, Pescatore said. There's been too much of tendency to view cyberthreats in the same light as physical terrorism threats and to respond to them in the same manner. In the process, some of the more immediate threats to government data and networks have been somewhat overlooked, he said &lt;/blockquote&gt;.&lt;br /&gt;See full story in &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9120918"&gt; COMPUTERWORLD&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-7168129865259386308?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/7168129865259386308" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/7168129865259386308" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2008/11/obama-administration-to-inherit-tough.html" title="Obama Administration to Inherit Tough Cybersecurity Challenges" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-6225416922387998715</id><published>2008-11-21T14:26:00.001-08:00</published><updated>2008-11-21T14:50:55.936-08:00</updated><title type="text">Minnesota Senate Race Could Hinge on Scanning Machine Mistakes</title><content type="html">&lt;a href="http://technews.acm.org/#388576"&gt; ACM TechNews&lt;/a&gt; notes that according to an article in &lt;span style="font-weight:bold;"&gt;cnet news&lt;/span&gt;, the U.S. Senate race in Minnesota is yet undecided and that a hand recount could reveal that several thousand votes were mistakenly rejected by optical-scan voting machines.  The outcome of the Senate race may depend on whether scanning machines made mistakes two weeks ago when tabulating ballots. Republican Senator Norm Coleman holds only a 200 vote lead over his opponent, Democrat Al Franken.  With Coleman's lead being under a margin of 0.5 percent of the more than 2.9 million votes cast in the race on November 4th, the state automatically starts a hand recount of every ballot.&lt;br /&gt;&lt;br /&gt;Director of governmental affairs for the Minnesota secretary of state's office Beth Fraser says the optical scanning machines used to read paper ballots could have mistakenly rejected enough ballots to affect the outcome of the race.&lt;br /&gt;&lt;br /&gt;Although the optical scanning machines may have rejected some crucial votes, Fraser said the machines are still the best option for counting votes.&lt;blockquote&gt;"It speeds up the counting but gives us the paper ballots to count on, so the results are fully auditable," she said. &lt;/blockquote&gt;&lt;br /&gt;See entire article in &lt;a href="http://news.cnet.com/8301-13578_3-10101827-38.html"&gt; cnet news&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-6225416922387998715?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/6225416922387998715" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/6225416922387998715" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2008/11/minnesota-senate-race-could-hinge-on.html" title="Minnesota Senate Race Could Hinge on Scanning Machine Mistakes" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-2654968319934623912</id><published>2008-11-17T16:01:00.000-08:00</published><updated>2008-11-17T16:24:37.574-08:00</updated><title type="text">Feds Can Locate Cell Phones Without Telcos</title><content type="html">&lt;a href="http://yro.slashdot.org/yro/08/11/17/2218209.shtml"&gt; Slashdot&lt;/a&gt; flags on Ars Technica report about the release of documents obtained under the Freedom of Information Act suggesting that "triggerfish" technology can be used to pinpoint cell phones without involving the cell phone providers at all. Triggerfish are cell-tower spoofing devices that can trick cell phones into giving up their location and other identifying information without notifying the carrier or the user. This may be significant because the legal rulings requiring law enforcement to meet a high "probable cause" standard before acquiring cell location records have so far pertained to requests for information from providers. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The Justice Department's electronic surveillance manual explicitly suggests that triggerfish may be used to avoid restrictions in statutes like CALEA (Communications Assistance for Law Enforcement Act) that bar the use of pen register or trap-and-trace devices...&lt;br /&gt;&lt;br /&gt;It is therefore somewhat surprising that it is only with the passage of the USA PATRIOT Act in 2001 that the government has needed any kind of court order to use triggerfish.  Although previously the statutory language governing pen register and trap-and-trace orders did not appear to include location tracking technology, the updated definition explicitly includes any "device or process which records or decodes dialing, routing, addressing, and signaling information."&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;See full story in &lt;a href="http://arstechnica.com/news.ars/post/20081116-foia-docs-show-feds-can-lojack-mobiles-without-telco-help.html"&gt; Ars Technica&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-2654968319934623912?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/2654968319934623912" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/2654968319934623912" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2008/11/feds-can-locate-cell-phones-without.html" title="Feds Can Locate Cell Phones Without Telcos" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-3981990835134158408</id><published>2008-11-14T16:16:00.000-08:00</published><updated>2008-11-14T16:28:54.822-08:00</updated><title type="text">Why Veins Could Replace Fingerprints and Retinas as Most Secure Form of ID</title><content type="html">&lt;a href="http://technews.acm.org/#387505"&gt; ACM TechNews&lt;/a&gt; mentions the fact that finger vein authentication is starting to gain traction in Europe. Widely introduced by Japanese banks in the past two years, it is claimed to be the fastest and most biometric method of authentication.  Companies in Europe have also begun to roll out this advanced biometric system from Japan, which identifies people from the unique patterns of veins inside their fingers. &lt;br /&gt;&lt;br /&gt;Hitachi developed the technology, which captures the pattern of blood vessels by transmitting near-infrared light at different angles through the finger, then turning it into a digital code to match it against preregistered profiles.  Unlike fingerprints that can be "lifted" and retinas scanned without an individual realizing it, its is extremely unlikely that people's finger vein profiles can be taken withouth them being aware of it. &lt;br /&gt;&lt;br /&gt;Easydentic Group in France says it will use finger vein security for door access systems in the United Kingdom and other European markets.&lt;br /&gt;&lt;br /&gt;For full story, see &lt;a href="http://technology.timesonline.co.uk/tol/news/tech_and_web/article5129384.ece"&gt; London Times Online&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-3981990835134158408?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/3981990835134158408" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/3981990835134158408" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2008/11/why-veins-could-replace-fingerprints.html" title="Why Veins Could Replace Fingerprints and Retinas as Most Secure Form of ID" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-8640225670216902995</id><published>2008-11-05T16:05:00.001-08:00</published><updated>2008-11-05T18:21:29.843-08:00</updated><title type="text">Obama, McCain Campaigns Both Hacked, FIles Compromised</title><content type="html">&lt;a href="http://it.slashdot.org/it/08/11/05/221222.shtml"&gt; Slashdot&lt;/a&gt; writes of post-election news coming out of both campaigns on what transpired behind closed doors.  Apparently both Obama's and McCain's campaigns had their systems hacked over the summer -- and not by each other.&lt;br /&gt;&lt;br /&gt;Technology experts detected what they initially thought was a case of "phishing" at the Obama headquarters in midsummer.  However, by the next day both the FBI and Secret Service came to the campaign with an ominous warning:&lt;blockquote&gt;"You have a problem way bigger than what you understand," an agent told Obama's team. "You have been compromised, and a serious amount of files have been loaded off your system."&lt;/blockquote&gt;Obama's aides were told by the Feds in late August that the McCain campaign's computer system and been similarly infiltrated.The campaign's computer system had been hacked and the FBI had become involved, as per the confirmation of a top McCain official to NEWSWEEK.&lt;br /&gt;&lt;br /&gt;White House and FBI officials told the Obama campaign that they believed a foreign entity or organization had been seeking information on the evolution of both camps policy positions-information that might prove useful in negotiations with a future administration.  Obama technical experts later speculated that the hackers were Russian or Chinese.&lt;br /&gt;&lt;br /&gt;See &lt;a href="http://www.newsweek.com/id/167581/page/1"&gt;Newsweek&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-8640225670216902995?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/8640225670216902995" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/8640225670216902995" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2008/11/obama-mccain-campaigns-both-hacked.html" title="Obama, McCain Campaigns Both Hacked, FIles Compromised" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-8490355722629896989</id><published>2008-11-03T15:36:00.000-08:00</published><updated>2008-11-03T16:25:49.952-08:00</updated><title type="text">E-Voting Groups Are Watching a Handful of States</title><content type="html">&lt;a href="http://technews.acm.org/#385833"&gt; ACM TechNews&lt;/a&gt; summarizes an article on potential problems with electronic voting in several states.  Pamela Smith, president of Verified Voting and long a critic of electronic voting machines, is more worried about the long lines on election day.  Any sort of equipment failure in places like Pennsylvania and Virginia will create additional problems because they do not have polls open for early voting despite the record number of new voter registrations, particularly among Democrats.&lt;br /&gt;&lt;br /&gt;Further, Pennsylvania and Virginia do not mandate paper-trail backups for their touch-screen electronic voting machines.  Critics of e-voting say that without that paper trail, there is no way to audit the results of a touch-screen machine.&lt;br /&gt;&lt;br /&gt;Several states do not have adequate numbers of voting machines in place to back up malfunctioning equipment.&lt;br /&gt;&lt;br /&gt;As Smith points out &lt;blockquote&gt;"This is an election that will sort of stress-test the [election] systems," she says. "Any problem that's going to come up is going to be amplified."&lt;/blockquote&gt;&lt;br /&gt;See full article in &lt;a href="http://www.pcworld.com/businesscenter/article/153186/evoting_groups_are_watching_a_handful_of_states.html"&gt; PCWorld&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-8490355722629896989?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/8490355722629896989" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/8490355722629896989" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2008/11/e-voting-groups-are-watching-handful-of.html" title="E-Voting Groups Are Watching a Handful of States" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-689481177312581953</id><published>2008-10-24T15:25:00.000-07:00</published><updated>2008-10-24T16:02:28.424-07:00</updated><title type="text">A Really Secret Ballot</title><content type="html">&lt;a href="http://technews.acm.org/#384570"&gt; ACM TechNews &lt;/a&gt; highlights a voting and encryption article in The Economist about the search for a way of voting that is both reliable and trustworthy. Encrypting people's votes might achieve some trustworthiness.&lt;br /&gt;&lt;br /&gt;Dr. Peter Ryan, computer scientist at the University of Newcastle upon Tyne in England may have found one way of doing this.  Ryan calls his development "Pret a Voter". The gist of his approach is that paper ballots are used that are in two halves.  The candidates' names are on one side and the the tick boxes are on the other.  The voter ticks the boxes he wants and divides the paper, putting only the half with the tick boxes on it in the ballot box.  The ballots are then scanned by optical reader.  The 'trick' part is that the candidates are listed in random order on each ballot paper. &lt;br /&gt;&lt;br /&gt;While anyone looking at the deposited half of the ballot paper cannot determine in whose interest the votes were cast, the machine &lt;span style="font-style:italic;"&gt;can&lt;/span&gt; because each deposited half also carries a cryptographic cipher containing the candidate order on that particular ballot.&lt;br /&gt;&lt;br /&gt;A second approach elaborates on Ryan's system.  Ben Adida and Ron Rivest, of the Massachusetts Institute of Technology, have created what they call "Scratch &amp; Vote".  The ballot paper looks the same as that used in Ryan's 'Pret a Voter', but with an additional scratch-off area that acts as an extra level of security.&lt;br /&gt;&lt;br /&gt;David Chaum, a computer scientist and cryptographer who, among other things, invented the idea of digital cash, has created a third idea called Scantegrity II. In this approach, a voter fills in an oval-shaped space instead marking an 'x' next to a candidate's name.  With Scantegrity however, the voter uses a special pen whose "ink" reacts with a pattern of two chemicals that has been printed inside the oval-shaped space.&lt;br /&gt;&lt;br /&gt;While none of these solutions has been widely tested yet meaning American voters will not see them in process for this election, there is a good chance they will be offered in the next election, especially if scandals emerge in the coming election.&lt;br /&gt;&lt;br /&gt;For details on the 3 approaches, see full write-up in &lt;a href="http://www.economist.com/science/tm/displaystory.cfm?story_id=12455414"&gt; The Economist&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-689481177312581953?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/689481177312581953" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/689481177312581953" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2008/10/really-secret-ballot.html" title="A Really Secret Ballot" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry><entry><id>tag:blogger.com,1999:blog-25971470.post-1814559972386113718</id><published>2008-10-22T15:10:00.000-07:00</published><updated>2008-10-22T15:40:26.806-07:00</updated><title type="text">US's First Internet Votes To Be Cast This Friday</title><content type="html">&lt;a href="http://yro.slashdot.org/article.pl?sid=08/10/22/1924256"&gt; &lt;span style="font-style:italic;"&gt;Slashdot&lt;/span&gt;&lt;/a&gt; is running an article today about the nation's first Internet-based voting system, which goes online this Friday.&lt;br /&gt;&lt;br /&gt;Between Oct. 24 and Nov. 2, an estimated six to seven hundred U.S. citizens will use PCs with no hard drive and other disabled components (hardened laptops to remove security risks) located at specific kiosks in Germany, Japan and the U.K. to cast their votes for president.  The Okaloosa Distance Ballot Piloting (ODBP) test program could help change the current bureaucratic obstacle course now affecting roughly 6 million overseas residents who must register earlier than other voters and whose mail-in absentee ballots could be mishandled.&lt;br /&gt;&lt;br /&gt;Despite the favorable results of Director of the Security and Assurance in Information Technology (SAIT) Laboratory Alec Yasinac's security analysis, the mere fact that a wider computer security community has not been asked to evaluate the ODBP program has resulted in a multitude of unanswered questions.&lt;blockquote&gt;"We should not go ahead until full details of the system have been disclosed," says David Dill, a professor of computer science at Stanford University, who has testified before Congress about electronic voting. Dill praises Okaloosa County's program for attempting to create a secure, verifiable system that includes the use of paper Voter Choice Records (VCRs) to allow for a 100 percent audit against the electronic votes. Other locations have adopted less secure alternatives for overseas voters, allowing them to send ballots in by fax or e-mail. Still, he believes the pitfalls outnumber the benefits. "If not for the VCRs, this entire proposal would be completely unacceptable," Dill says. "But if the goal is to hand count every one of them, that seems like a lot of overhead for what amounts to a complicated way to fill out paper absentee ballots. The way I look at it, the entire Internet voting part of this scheme is confusing and possibly harmful."&lt;/blockquote&gt;&lt;br /&gt;See more in &lt;a href="http://www.popularmechanics.com/technology/industry/4288327.html"&gt; &lt;span style="font-style:italic;"&gt; Popular Mechanics&lt;/span&gt;&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25971470-1814559972386113718?l=trust-news.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/1814559972386113718" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/25971470/posts/default/1814559972386113718" /><link rel="alternate" type="text/html" href="http://trust-news.blogspot.com/2008/10/uss-first-internet-votes-to-be-cast.html" title="US's First Internet Votes To Be Cast This Friday" /><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="09764063352242537940" /></author></entry></feed>
