Thursday, January 31, 2013

Compete, Inc. Collected Personal Data Including Keystrokes

Compete "captured information consumers entered into websites, including consumers’ usernames, passwords, and search terms, and also some sensitive information such as credit card and financial account information, security codes and expiration dates, and Social Security Numbers."

Two analytics companies to settle charges for online user tracking
http://www.net-security.org/secworld.php?id=13820

Compete Inc. Settles FTC Privacy Charges
http://www.esecurityplanet.com/network-security/compete-inc.-settles-ftc-privacy-charges.html

Compete Inc. is owned by Taylor Nelson Sofres, which is in turn owned by WPP plc.

http://en.wikipedia.org/wiki/Compete.com

You can own WPP. The shares are publicly traded on the London (WPP.L) and NASDAQ (WPPGY) exchanges. 

Slashdot story and comments:

The penalties seem extremely light, considering that Compete Inc. (and hence WPP) violated the Computer Fraud and Abuse Act (CFAA) by committing fraud involving Protected Computers, which is a felony.

Facebook Graph Search Reveals All

Amusingly contradictory "likes" revealed!

Actual Facebook Graph Searches
http://actualfacebookgraphsearches.tumblr.com/
shows:
Mothers of Jews who like Bacon
Married people who like Prostitutes
Current employees of Tesco who like horses
Current employers of people who like Racism

Facebook Graph searches: Hooker hunger and other delish data
http://news.cnet.com/8301-1023_3-57565460-93/facebook-graph-searches-hooker-hunger-and-other-delish-data/
shows:
Mothers of Catholics from Italy who like Durex

But:
Facebook Graph Search: 4 big reasons it matters
http://news.cnet.com/8301-1023_3-57564801-93/facebook-graph-search-4-big-reasons-it-matters/

How Generation Y really feels about online privacy
http://ces.cnet.com/8301-34435_1-57563194/how-generation-y-really-feels-about-online-privacy/
Summary of their attitude and message: "we live in public."
But then, this is a panel of people who are on stage in front of a huge audience, being recorded, miked, and with giant video overhead. Clearly they aren't shy, or are perhaps even to the other extreme.

But! People are really amusing! Lamebook!
http://www.lamebook.com/

And Facebook can resurrect the dead!
When Facebook Resurrected the Dead
http://www.youtube.com/watch?v=Zf6C-pZ3heY

Additional Links on Aaron Swartz Case

22 PowerPoint slides at Slideshare showing the legal filing terminating the legal case.
http://www.slideshare.net/DeepDude/usa-v-aaron-swartz-terminated

Memorial for Aaron Swartz at the Internet Archive. Text by Carl Malamud.
https://public.resource.org/aaron/army/

Slashdot report on Dan Kennedy's re-publication of a Massachusetts Lawyers Weekly article saying that State prosecutors had planned to let Swartz off with a warning.

http://yro.slashdot.org/story/13/01/29/0219239/prosecution-of-swartz-typical-for-the-sick-culture-pervading-the-doj

Kennedy's article:
http://dankennedy.net/2013/01/24/the-swartz-suicide-and-the-sick-culture-of-the-justice-dept/

Tuesday, January 22, 2013

Your Computer is a "Protected Computer"

As was made plain by the recent Aaron Swartz scandal, the Computer Fraud and Abuse Act can be used to prosecute alleged violators at a high level for minor transgressions. The law, "18 USC § 1030 - Fraud and related activity in connection with computers" defines several forms of violations, all of which involve what the National Information Infrastructure Protection Act of 1996 defines as a protected computer:

a computer—
(A) exclusively for the use of a financial institution or the United States Government, or, in the case of a computer not exclusively for such use, used by or for a financial institution or the United States Government and the conduct constituting the offense affects that use by or for the financial institution or the Government; or
(B) which is used in interstate or foreign commerce or communication, including a computer located outside the United States that is used in a manner that affects interstate or foreign commerce or communication of the United States.

This is a rather wide definition, as any computer used to buy from Amazon or perform online banking with an out of state bank then immediately qualifies as being "used in interstate commerce." Also, anyone sending an email to any other person in another state would then also be using the computer for interstate communications, again meeting the standard.

What this means is that your personal computer is a protected computer, and any transgression against your computer then qualifies for a criminal complaint at the Federal level. More on this tomorrow.

Monday, January 21, 2013

France Proposes Personal Information Tax

Slashdot reports that the New York Times reports that France is considering a tax on companies that collect personal information.

France Proposes a Tax On Personal Information Collection
http://tech.slashdot.org/story/13/01/21/1253219/france-proposes-a-tax-on-personal-information-collection

France Proposes an Internet Tax
http://www.nytimes.com/2013/01/21/business/global/21iht-datatax21.html

The rationale in part is that "...users of services like Google and Facebook are, in effect, working for these companies without pay by providing the personal information that lets them sell advertising." Touché

The tax would be based on the number of users tracked, not by the quantity of information. Unfortunately, this would give internet companies further incentive to thwart anonymous and pseudonymous accounts. Fortunately, this would give the French government an incentive to allow anonymous and pseudonymous accounts, as the extra accounts would drive up tax collections.

Judge: Wash Post and Agence France-Presse Stole Photos

A judge has granted a summary judgment stating that defendants Washington Post and AFP improperly used without license photographs owned by photographer Daniel Morel. Morel took photographs within hours of the Haiti earthquake in 2010 and posted links to them on Twitter. AFP had argued that any photos posted on the internet and linked to from Twitter were available for all to use without licence.

News outlets improperly used photos posted to Twitter: judge
http://www.reuters.com/article/2013/01/15/us-socialmedia-copyright-ruling-idUSBRE90E11P20130115

The case is not yet concluded, as determination of willfulness and damages will be determined at trial.

The case highlights the evolving area of copyright law as applied to photographs used in social media. While Twitter's service terms do allow the reposting and rebroadcasting of users' images in certain circumstances, such as "retweeting," they do not apply to commercial use.

There is a tendency in the social media business and photographic support businesses, such as printing of digital photographs, to treat consumer photos as "not copyrighted" even though existing copyright law states explicitly that all photographs are protected by copyright from the moment of capture, and that the copyright is owned by the photographer.

Although this law applies even to supposedly non-professional photographs, it is in the interest of social media companies such as Google+, Facebook, Instagram, and LinkedIn to insist upon unlimited distribution rights as a non-negotiable part of their Terms of Service. Instagram recently changed their TOS to take a right to use customer photographs for any purpose, which could have included advertising, without compensating the owner of the photograph.

More on Instagram's TOS:
Instagram's TOS Go Into Effect Today
Terms of Use • Instagram
What Instagram’s New Terms of Service Mean for You

The TOS of companies that make prints from digital photographs also overreach in most cases. The actual wording of the contracts makes it clear that when you upload photographs to Sams Club, Costco, Wal-Mart, Target, SnapFish, SmugMug, Mpix, Wolf Camera, Shutterfly, Flickr, and so on that the company gains a perpetual license to reproduce your photograph, with no compensation to you.

Sams Club TOS

Excerpt from the Sams Club TOS:
"You grant to samsclub.com a non-exclusive, royalty-free, perpetual, irrevocable, unrestricted, world-wide right and license to access, use, copy, reproduce, distribute, transmit, display, perform, communicate to the public, modify, adapt, publish, translate, create derivative works from, and otherwise use such Materials (in whole or in part) in connection with the Site and/or the Products, using any form, media or technology now known or later developed, without providing compensation to you or any other person, without any liability to you or any other person, and free from any obligation of confidence or other duties on the part of samsclub.com, its affiliates and their respective licensees;"

In short, you must be extremely vigilant when getting prints made from your better photographs, because some larger businesses are looking to monetize your content. To avoid losing rights to your own pictures, insist on a new, separate contract that grants a right to the print-making company to copy your files and photos only for the purpose of making prints for you as customer, and limits the time frame on the license to no more than 30 days.

North Korea: "It's like The Truman Show, at country scale"

Google chief Eric Schmidt,  who said at one time that everything you do should be posted on line*, visited North Korea with his daughter Sophie. Sophie blogged about the visit in a post titled It might not get weirder than this. Everything she says in her article is surprising. I highly recommend reading it, especially if you like traveling.

Networkworld's Ms. Smith's take: Bugged guesthouse: Eric Schmidt's daughter reveals North Korea trip details.

* Actually, he said something like "if you don't want anyone to know what you are doing, then maybe you shouldn't be doing it." But it amounts to the same thing. I could even prove it mathematically, except that I'm too lazy at the moment, and you probably believe me already.

1/22/13 update:
More articles about the trip, with new details:
Sophie Schmidt Recounted North Korea Trip with Her Father, Google Chairman Eric Schmidt on a Blog
SOPHIE SCHMIDT GOES TO NORTH KOREA & REPORTS BACK META
Eric Schmidt's daughter lifts lid on 'very strange' North Korea
Eric Schmidt's post on Google+



Trusteer may not be worth the CPU cycles

Trusteer's Rapport software is an application written that a number of banks have asked their customers to download onto their systems. Banks that have offered the software include Bank of America, Société Générale, INGDirect (now owned by Capital One), HSBC, NatWest, The Royal Bank of Scotland, CIBC,Ulster Bank, First Direct, Santander, Standard Bank of South Africa, Scotiabank, Bank of Montreal, Banco de Chile, and The Co-operative Bank. Reports are that the software is difficult to remove, as it has some features that resemble malware in the way it installs itself, and offers little protection against most malware. It can consume an excessive amount of CPU time and prevent some normal programs, such as screen snapshot applications, from functions. The purported purpose is to stop screen-scraping programs and keyloggers, and to verify that you are connected to the bank’s actual Web site.

Should you install it? Should you uninstall it if you already have it?

We recommend against installing it. It is not proven that the software doesn't violate privacy, and your financial institution would not take responsibility for its actions should there be data leakage or intrusions into your computer if Rapport were found to be culpable. Overall, the risks are much larger than the rewards for this particular application. The application has been found to be weak at accomplishing its goals, and it is likely well behind the current wave of malware technology being used by the bad guys. Another problem is that it has been almost three years since the last authoritative article appeared on the web analyzing Rapport.

The intent of the bankers and the company offering the application is to thwart criminals that target customer systems with malware in order to steal credentials, identities, and the contents of bank accounts. The problem is that, legally, the software is acting on behalf of the bank, not you, so you have no recourse when the software does stupid things, like consume all of your computing power, or be difficult to uninstall. A better solution is to increase your computer's defenses with better firewall, better virus and malware detection, and especially to surf the web using only a non-administrative account. Even if you are the only user on your computer, you will be safer if you create two accounts:  one for administrative functions, and the other for everything else, especially cruising the internet and online banking, which does not have the power to locally modify the registry, other computer settings, or install applications.

Businesses are usually liable for losses arising from this type of fraud. If you are in this position, we recommend this solution:  Dedicate a single computer for the purpose of online banking. Use it to connect only to your online bank web site. Make it company policy that using that computer for any other purpose is grounds for immediate dismissal.

Free Software to Protect Your Bank Account
A Closer Look at Rapport from Trusteer

Friday, January 18, 2013

Compendium for the Aaron Swartz Case

“We can rightly judge a society by how it treats its eccentrics and deviant geniuses—and by that measure, we have utterly failed.”

"Steve Jobs and Steve Wozniak in the 1970s committed crimes more damaging than Swartz's"

Reddit: On the Death of Aaron Schwartz
http://www.reddit.com/r/technology/comments/16hzpx/on_the_death_of_aaron_schwartz/
Aaron's Law: Violating a Site's Terms of Service Should Not Land You in Jail
http://www.theatlantic.com/national/archive/13/01/aarons-law/267247/#
Prosecutor as bully
http://lessig.tumblr.com/post/40347463044/prosecutor-as-bully
Reddit: I'm Rep Zoe Lofgren & I'm introducing "Aaron's Law" to change the Computer Fraud and Abuse Act (CFAA)
http://www.reddit.com/r/technology/comments/16njr9/im_rep_zoe_lofgren_im_introducing_aarons_law_to/
Aaron's Fight is Our Fight
http://www.rootstrikers.org/
US Government Ups Felony Count In JSTOR/Aaron Swartz Case From Four To Thirteen
http://www.techdirt.com/articles/20120917/17393320412/us-government-ups-felony-count-jstoraaron-swartz-case-four-to-thirteen.shtml
How the Legal System Failed Aaron Swartz—And Us
http://www.newyorker.com/online/blogs/newsdesk/2013/01/everyone-interesting-is-a-felon.html
Thanks To The Lori Drew Case, I Can Make Each Of You A Criminal
http://www.techdirt.com/articles/20081201/0252082984.shtml
Thomas J. Dolan, Ortiz' husband, attacked Swartz's parents, saying on Twitter: "Truly incredible that in their own son’s obit they blame others for his death and make no mention of the 6-month offer."
http://www.huffingtonpost.com/2013/01/15/tom-dolan-aaron-swartz_n_2479980.html
Many on Twitter were outraged by Dolan's attack on Swartz and his family:
http://betabeat.com/2013/01/tom-dolan-defends-carmen-ortiz-aaron-swartz-twitter/
Tom Dolan bio:
http://en.wikipedia.org/wiki/Thomas_J._Dolan
Punitive Damages, Remunerated Research, and the Legal Profession
http://www.stanfordlawreview.org/print/article/punitive-damages-remunerated-research-and-legal-profession
Carmen Ortiz, lead prosecutor of Aaron Swartz
http://en.wikipedia.org/wiki/Carmen_Ortiz
Aaron Swartz indicted on charges of "wire fraud, computer fraud" etc.
http://kottke.org/11/07/aaron-swartz-indicted-on-charges-of-wire-fraud-computer-fraud-etc
JSTOR Prosecutes User for Downloading Too Much
http://vorpaltrade.blogspot.com/2011/10/jstor-prosecutes-user-for-downloading.html
Another example of prosecutorial overreach:
http://www.wbur.org/2012/11/14/tewksbury-motel-owner-fights-property-seizure
Aaron Swartz's Lawyer: Prosecutor Stephen Heymann Wanted 'Juicy' Case For Publicity
http://www.huffingtonpost.com/2013/01/14/aaron-swartz-stephen-heymann_n_2473278.html
Carmen Ortiz and Stephen Heymann: accountability for prosecutorial abuse
http://www.guardian.co.uk/commentisfree/2013/jan/16/ortiz-heymann-swartz-accountability-abuse
After Aaron Swartz's Death, the Focus Now Falls On the Prosecutors
http://yro.slashdot.org/story/13/01/16/239259/after-aaron-swartzs-death-the-focus-now-falls-on-the-prosecutors
Prosecutor in Aaron Swartz 'hacking' case comes under fire
http://news.cnet.com/8301-13578_3-57564212-38/prosecutor-in-aaron-swartz-hacking-case-comes-under-fire/
Aaron Swartz Lawyer: I Warned Prosecutors Of Suicide Risk
http://www.techweekeurope.co.uk/news/aaron-swartz-lawyer-suicide-104262
"...prosecutors only responded by saying Swartz would have been safe in jail..."

Added 1/21/13:
Harvard Business Review blog: Aaron Swartz's "Crime" and the Business of Breaking the Law
http://www.bloomberg.com/news/2011-11-21/former-synthes-executive-huggins-sentenced-in-bone-cement-marketing-case.html

This article makes reference to dis-proportionality of punishment in two cases:
Ex-Synthes Officials Get Prison Terms in Bone Drug Case
http://www.bloomberg.com/news/2011-11-21/former-synthes-executive-huggins-sentenced-in-bone-cement-marketing-case.html
A number of patients were killed when the company decided to evade medical device testing ethics.

Outrageous HSBC Settlement Proves the Drug War is a Joke
http://www.rollingstone.com/politics/blogs/taibblog/outrageous-hsbc-settlement-proves-the-drug-war-is-a-joke-20121213
British mega-bank HSBC (former owner of The Money Store, Household Finance, GM Card) managed to avoid all criminal prosecution for multiple, extensive money-laundering schemes. If you would rather have a more sober description of the matter, try Wikipedia's entry on HSBC.

Added 1/21/13:
O'Reilly Giving Away Open Government As Aaron Swartz Tribute
http://news.slashdot.org/story/13/01/21/1644254/oreilly-giving-away-open-government-as-aaron-swartz-tribute
We’re releasing the files for O’Reilly’s Open Government book
http://radar.oreilly.com/2013/01/open-government-files-released.html

Edward Tufte's Defense of Aaron Swartz and the "Marvelously Different"
http://news.slashdot.org/story/13/01/20/1823256/edward-tuftes-defense-of-aaron-swartz-and-the-marvelously-different