Archive for the year 2010
Biometric waste in Iraq
The US military has been collecting millions of biometric samples from Iraqi citizens, both good guys and bad guys. Now that the US is leaving, what should be done with the biometric waste? There are real risks that the records could be used to determine who worked with the US forces during the occupation, or to identify members of rival tribes. And can the new Iraqi government be trusted to use the records properly?
As the war draws down, however, the collection of so much personal information has raised questions about how data gathered during wartime should be used during times of peace, and with whom that information should be shared.
via Questions arise about use of data gathered in Iraq war – The Boston Globe.
Posted: August 31st, 2010 under Security & privacy.
Comments: 1 |
8 views
Canadian universities making little from licencing
Michael Geist has an interesting article on the income that Canadian universities are making from licencing intellectual property. He questions whether an open distribution model might be better than the current traditional commercialization model.
The latest report is based on survey data from 2008 which finds that the total IP income (primarily from licencing) at reporting Canadian universities was $53.2 million. The cost of generating this income? The reporting institutions employed 321 full-time employees in IP management for a cost of $51.1 million. In other words, after these direct costs, the total surplus for all Canadian universities was $2.1 million.
Posted: August 31st, 2010 under Uncategorized.
Comments: none |
6 views
Brain scan lie detection excluded from court
Wired Science is reported that a Tennessee court has thrown out lie detection “evidence” from brain scans because it was unscientific. The defendant had offered the scans as proof that he was not lying about defrauding the government over Medicare payments.
The defense tried to use brain scans of the defendant to prove its client had not intentionally defrauded the government. In a 39-page opinion, Judge Tu Pham provided both a rebuke of this kind of fMRI evidence now, and a roadmap for how future defendants may be able to satisfy the Daubert standard, which governs the admissibility of scientific evidence.
It is particularly important to note that the company actually violated their own protocols during the scan. After two tests produced different results, the testing was repeated a third time until the desire result was obtained.
“Dr. Semrau risked nothing in having the testing performed, and Dr. Laken himself testified that had the results not been favorable to Dr. Semrau, they would have never been released,” Pham noted.
Posted: June 2nd, 2010 under Skepticism & beliefs.
Comments: none |
30 views
Tips for effective lying
Lying is hard, but some people are particularly good at it. Psychology Today offers 10 tips for effective lying.
…human beings have an innate skill at dishonesty. And with good reason: being able to manipulate the expectations of those around us is a key survival trait for social animals like ourselves. Indeed, a 1999 study by psychologist Robert Feldman at the University of Massachusetts showed that the most popular kids were also the most effective liars.
Posted: May 14th, 2010 under Human nature.
Comments: none |
84 views
Security skills in demand
Employers are looking for specific skills when hiring security professionals, and these mirror the most common issues are threats seen today.
So what do employers in the federal and private sectors want in a security pro today? The most in-demand qualifications basically mirror the types of attacks, breaches, and threats these organizations face today, as well as the regulations that help dictate their defenses: They’re looking for experience in incident-handling and response, compliance, risk management, business-side acumen, security clearance for sensitive government work, and leadership.
Posted: May 14th, 2010 under Security & privacy.
Comments: none |
35 views
Researchers hack car computer systems
Researchers will be presenting a paper at the IEEE security conference in Oakland next week that demonstrates various attacks against the computer systems in modern cars. These attacks allow someone to control a variety of systems, including the breaks, and even erase all evidence of the attacks. We know a lot about building safety critical systems, but we seem to also be good at ignoring the lessons.
Over a range of experiments, both in the lab and in road tests, we demonstrate the ability to adversarially control a wide range of automotive functions and completely ignore driver input — including disabling the brakes, selectively braking individual wheels on demand, stopping the engine, and so on. We find that it is possible to bypass rudimentary network security protections within the car, such as maliciously bridging between our car’s two internal subnets.
The paper is available here.
Media coverage can be read here.
Posted: May 14th, 2010 under Security & privacy.
Comments: none |
44 views
Denial-of-Phone While Draining Accounts
Here is an interesting attack method: launch a denial-of-phone attack to prevent communication with a bank while draining the accounts. Apparently, fake VoIP accounts were setup to phone the victim repeatedly while the bad guys transferred thousands of dollars out of the accounts. This is an example of a cross-over attack using different types of technologies to perform the fraud.
The FBI says the calls were a diversionary tactic, meant to tie up Thousand’s line so that Ameritrade couldn’t reach him to authenticate the money transfer requests.
via Posted: May 13th, 2010 under Security & privacy.
Comments: none |
18 views
fMRI lie detection still not admissable
Courts continue to flirt with admitting fMRI evidence into court. While brain imaging techniques are uncovering great new information, it is not clear to me if they will ever be accurate enough to distinguish truth-telling from lying.
Wired Science has covered a legal case where fMRI brain scan lie detection data was offered as evidence. While the lawyer was initially hopeful, it was ruled inadmissible by the judge on the basis that judgements of witness credibility by the jury should be based on their impression of the witness.
via Mind Hacks: fMRI lie detection and the Wonder Woman problem.
Posted: May 10th, 2010 under Human nature.
Comments: none |
8 views
Fake Bomb Detectors
A military supplier has been making lots of money selling dowsing-like devices to troops in Iraq that are supposed to detect explosives and other nasty materials. They devices come equipped with different programming cards to customize the substances they search for.
There has been speculation that the devices are fake and the programming cards don’t do anything. Now comes an analysis of the cards by careful dis-assembly, and the results are predictable…
There is no way in which this device could be programmed to distinguish the many different substances that the ADE651 manufacturer claimed it could, not to mention that any useful interaction with such an LC circuit would require a transmitter antenna, a power source, and lots of other components that the ADE651 appears to lack.
Posted: January 23rd, 2010 under Security & privacy, Skepticism & beliefs.
Comments: 1 |
61 views
Funding available for privacy research in Canada
My new employer, The Office of the Privacy Commissioner of Canada, is again calling for research and public education proposals for its contributions programs.
Research into the privacy implications of information technologies is one of the four priority areas for funding support under this year’s program. Emerging information technologies can threaten the privacy of Canadians or enhance it – and sometimes both simultaneously. For that reason, the Office is especially interested in receiving funding applications from researchers examining, from a scientific or technical standpoint, the impact of information technologies on privacy.
Not-for-profit organizations, including education institutions, industry and trade associations, consumer, voluntary and advocacy organizations are all eligible under the program. Up to $50,000 is available for successful projects. The deadline for submitting applications is February 26, 2010.
More information is available at:
Posted: January 21st, 2010 under Security & privacy.
Comments: 1 |
69 views