Friday, June 6, 2008

Study secretly tracks cell phone users - Wireless- msnbc.com



WASHINGTON - Researchers secretly tracked the locations of 100,000 people outside the United States through their cell phone use and concluded that most people rarely stray more than a few miles from home.

The first-of-its-kind study by Northeastern University raises privacy and ethical questions for its monitoring methods, which would be illegal in the United States.

It also yielded somewhat surprising results that reveal how little people move around in their daily lives. Nearly three-quarters of those studied mainly stayed within a 20-mile-wide circle for half a year.

The scientists would not say where the study was done, only describing the location as an industrialized nation.

Researchers used cell phone towers to track individuals' locations whenever they made or received phone calls and text messages over six months. In a second set of records, researchers took another 206 cell phones that had tracking devices in them and got records for their locations every two hours over a week's time period.

The study was based on cell phone records from a private company, whose name also was not disclosed.
Study co-author Cesar Hidalgo, a physics researcher at Northeastern, said he and his colleagues didn't know the individual phone numbers because they were disguised into "ugly" 26-digit-and-letter codes.
Issue of locational privacy
That type of nonconsensual tracking would be illegal in the United States, according to Rob Kenny, a spokesman for the Federal Communications Commission. Consensual tracking, however, is legal and even marketed as a special feature by some U.S. cell phone providers.
The study, to be published Thursday in the journal Nature, opens up the field of human-tracking for science and calls attention to what experts said is an emerging issue of locational privacy.
"This is a new step for science," said study co-author Albert-Lazlo Barabasi, director of Northeastern's Center for Complex Network Research. "For the first time we have a chance to really objectively follow certain aspects of human behavior."
Barabasi said he spent nearly half his time on the study worrying about privacy issues. Researchers didn't know which phone numbers were involved. They were not able to say precisely where people were, just which nearby cell phone tower was relaying the calls, which could be a matter of blocks or miles. They started with 6 million phone numbers and chose the 100,000 at random to provide "an extra layer" of anonymity for the research subjects, he said.
Barabasi said he did not check with any ethics panel. Hidalgo said they were not required to do so because the experiment involved physics, not biology. (Northeastern University later said the U.S. Navy-funded study did undergo institutional review.)

Ethicists might have given the researchers an earful, suggested bioethicist Arthur Caplan at the University of Pennsylvania.
"There is plenty going on here that sets off ethical alarm bells about privacy and trustworthiness," Caplan said.
Studies done on normal behavior at public places is "fair game for researchers" as long as no one can figure out identities, Caplan said in an e-mail.
"So if I fight at a soccer match or walk through 30th Street train station in Philly, I can be studied," Caplan wrote. "But my cell phone is not public. My cell phone is personal. Tracking it and thus its owner is an active intrusion into personal privacy."
Concerns about Big BrotherPaul
Stephens, policy director at the Privacy Rights Clearinghouse in San Diego, said the nonconsensual part of the study raises the Big Brother issue.
"It certainly is a major concern for people who basically don't like to be tracked and shouldn't be tracked without their knowledge," Stephens said.
Study co-author Hidalgo said there is a difference between being a statistic — such as how many people buy a certain brand of computer — and a specific example. The people tracked in the study are more statistics than examples.
"In the wrong hands the data could be misused," Hidalgo said. "But in scientists' hands you're trying to look at broad patterns.... We're not trying to do evil things. We're trying to make the world a little better."
Knowing people's travel patterns can help design better transportation systems and give doctors guidance in fighting the spread of contagious diseases, he said.
The results also tell us something new about ourselves, including that we tend to go to the same places repeatedly, he said.
"Despite the fact that we think of ourselves as spontaneous and unpredictable ... we do have our patterns we move along and for the vast majority of people it's a short distance," Barabasi said.
The study found that nearly half of the people in the study pretty much keep to a circle little more than six miles wide and that 83 percent of the people tracked mostly stay within a 37-mile wide circle.
But then there are the people who are the travel equivalent of the super-rich, said Hidalgo, who travels more than 150 miles every weekend to visit his girlfriend. Nearly 3 percent of the population regularly go beyond a 200-mile wide circle. Less than 1 percent of people travel often out of a 621-mile circle.
But most people like to stay much closer to home. Hidalgo said he understands why: "There's a lot of people who don't like hectic lives. Travel is such a hassle."
Sphere: Related Content

Latest 'lost' laptop holds treasure-trove of unencrypted AT&T payroll data | NetworkWorld.com Community

Latest 'lost' laptop holds treasure-trove of unencrypted AT&T payroll data NetworkWorld.com Community

It's just another in a long line of stolen laptops ... unless you work in management at AT&T and you're worried about your social security number falling into the hands of identity thieves. Or, you're worried that your coworkers might find out how much -- or how little -- you actually earn.

While AT&T has declined to disclose the number of management employees put at risk by the May 15 theft from an employee's car, one manager who is among them tells me he knows of others located throughout every corner of AT&T's vast empire in the U.S. "I have found one individual who was not impacted," says the manager, who asked not to be named. "This is probably big, but not everyone."

"I'm very disappointed in my company," he adds. "Eight days passed before we were notified ... and it took up to another 10 days to be informed about requesting a fraud alert and to be given instructions for signing up for credit watch."

I've asked AT&T for comment. At the end of this post is a long excerpt from a Q&A the company provided to employees, who learned of the breach via an e-mail, which reads in part:

"This is to alert you to the recent theft of an AT&T employee's laptop computer that contained AT&T management compensation information, including employee names, Social Security numbers, and, in most cases, salary and bonus information. ... We deeply regret this incident. You will soon hear about additional steps we're taking to reinforce our policies to safeguard sensitive personal information and ensure strict compliance in order to avoid incidents like this in the future."

Regrets were not enough to allay the anger of this manager.

"It is pathetic that the largest telecom company in the world -- with more than 100 million customers -- doesn't encrypt basic personal information," he says.


Failure to encrypt and otherwise better protect such data is inexcusable at this point in time, agrees Kelly Todd, a staff member at attrition.org, a security site that maintains a database of data-breach incidents.

"Lack of encryption of personal data is generally troubling, especially when the data is being stored on any mobile device with a 'steal me' bulls-eye on it," says Todd. "According to part of the AT&T e-mail, 'It was not encrypted, but the laptop was password protected. AT&T is currently in the process of encrypting such systems.' Good for them, but larger companies can sometimes have tens of thousands of systems to identify, plan for, and then execute an encryption process. It seems to me that they should have been 'in the process' a year ago.

"Even more troubling is that AT&T mentions that the laptop was password protected in their letter," he adds. "It might make some people feel better, but just password protection alone is generally considered a security joke."

The AT&T manager whose data was exposed sees an even larger issue in play here.

"I receive company internal e-mails reminding me to contact our legislators about relieving the company of the burdens of regulation," he says. "What happened here shows the company isn't ready to have those burdens lifted."
Sphere: Related Content

New crypto virus a looming threat

The emergence of a variant on a virus that encrypts the victim's data with a strong 1,024-bit algorithm so the victim can't unscramble it without paying a ransom has begun to spread, potentially posing a major threat, according to the antimalware firm which discovered it.

Kaspersky Lab says the new variant of the Windows-based encryptor virus Gpcode, which hasn't been spotted for about 1 ½ years, is more of a threat than it was in the past because this time it is using strong encryption that so far has defied efforts to crack it. (Check out our antivirus buyer's guide.)
Up until now, we were able to crack the algorithms," says Roel Schouwenberg, senior antivirus researcher at Kaspersky Lab.

Earlier versions of Gpcode — which first appeared about 3 ½ years ago — used far weaker encryption than what it has today, plus it wasn't well implemented, making it fairly easy to crack, Schouwenberg says.

But Gpcode.AK, with its RSA 1,024-bit encryption, is proving hard to break. He adds that computer users should be making an effort to back up their data vigorously in the face of this new threat.

The Gpcode.ak is hard to detect because it attempts to self destruct after encrypting, according to Kaspersky Lab. So far only a handful of computers with files that have been maliciously encrypted have been identified so far. Most evidence about it is originating in Russian-speaking countries, Europe and Africa, he says, but it may be spreading further.

So far, the primary means it uses to spread is unclear, but Kaspersky Lab believes it's a form of "social engineering" that may involve trickery to induce computer users to make use of software they shouldn't.

The text file that the criminals leave tells the victim that the file has been encrypted and offers to sell them a "decryptor." Kaspersky Lab would advise against yielding to blackmailers in any ransomware situation.

Kaspersky Lab says efforts are continuing along with others in the antivirus industry to analyze Gpcode.ak further for technical weaknesses, but that users should now be extra careful in opening files and Web activity.
Sphere: Related Content

Thursday, June 5, 2008

Read me first: Taking your laptop into the US? Be sure to hide all your data first | Technology | The Guardian

Read me first: Taking your laptop into the US?Guardian:



"Taking your laptop into the US? Be sure to hide all your data first"


US court ruled that border agents can search your laptop, or any other electronic device, when you're entering the country. They can take your computer and download its entire contents, or keep it for several days. Customs and Border Patrol has not published any rules regarding this practice, and I and others have written a letter to Congress urging it to investigate and regulate this practice.

But the US is not alone. British customs agents search laptops for pornography. And there are reports on the internet of this sort of thing happening at other borders, too. You might not like it, but it's a fact. So how do you protect yourself?

Encrypting your entire hard drive, something you should certainly do for security in case your computer is lost or stolen, won't work here. The border agent is likely to start this whole process with a "please type in your password". Of course you can refuse, but the agent can search you further, detain you longer, refuse you entry into the country and otherwise ruin your day.

You're going to have to hide your data. Set a portion of your hard drive to be encrypted with a different key - even if you also encrypt your entire hard drive - and keep your sensitive data there. Lots of programs allow you to do this. I use PGP Disk (from pgp.com). TrueCrypt (truecrypt.org) is also good, and free.
While customs agents might poke around on your laptop, they're unlikely to find the encrypted partition. (You can make the icon invisible, for some added protection.) And if they download the contents of your hard drive to examine later, you won't care.

Be sure to choose a strong encryption password. Details are too complicated for a quick tip, but basically anything easy to remember is easy to guess. (My advice is at tinyurl.com/4f8z4n.) Unfortunately, this isn't a perfect solution. Your computer might have left a copy of the password on the disk somewhere, and (as I also describe at the above link) smart forensic software will find it.

So your best defence is to clean up your laptop. A customs agent can't read what you don't have. You don't need five years' worth of email and client data. You don't need your old love letters and those photos (you know the ones I'm talking about). Delete everything you don't absolutely need. And use a secure file erasure program to do it. While you're at it, delete your browser's cookies, cache and browsing history. It's nobody's business what websites you've visited. And turn your computer off - don't just put it to sleep - before you go through customs; that deletes other things. Think of all this as the last thing to do before you stow your electronic devices for landing. Some companies now give their employees forensically clean laptops for travel, and have them download any sensitive data over a virtual private network once they've entered the country. They send any work back the same way, and delete everything again before crossing the border to go home. This is a good idea if you can do it.

If you can't, consider putting your sensitive data on a USB drive or even a camera memory card: even 16GB cards are reasonably priced these days. Encrypt it, of course, because it's easy to lose something that small. Slip it in your pocket, and it's likely to remain unnoticed even if the customs agent pokes through your laptop. If someone does discover it, you can try saying: "I don't know what's on there. My boss told me to give it to the head of the New York office." If you've chosen a strong encryption password, you won't care if he confiscates it.

Lastly, don't forget your phone and PDA. Customs agents can search those too: emails, your phone book, your calendar. Unfortunately, there's nothing you can do here except delete things.
I know this all sounds like work, and that it's easier to just ignore everything here and hope you don't get searched. Today, the odds are in your favour. But new forensic tools are making automatic searches easier and easier, and the recent US court ruling is likely to embolden other countries. It's better to be safe than sorry.

· Bruce Schneier is a security technologist and author: schneier.com/blog Sphere: Related Content

Five free penteration-testing tools

Security assessment and deep testing don't require a big budget. Some of most effective security tools are free, and are commonly used by professional consultants, private industry and government security practitioners. Here are a few to start with.

For scanning in the first steps of a security assessment or pen test, Nmap and Nessus share the crown. Nmap is a simple, powerful and very well-reviewed scanner that one finds in the toolbox of any serious security consultant. Nmap and its Zenmap graphical interface are free and available at nmap.org for virtually any platform from Vista and OS X to AmigaOS, and will happily run on low-power systems.

Nessus performs scans and up-to-date vulnerability testing in one interface, through a purchased "feed" of vulnerability modules for the freely downloadable application. A free but delayed noncommercial "home feed" of updates will continue to be available at nessus.org after Tenable Inc. changes the Nessus license this coming July.


The Metasploit Framework provides more operating system and application exploit information than most analysts would know what to do with. Recently rewritten in Ruby with a graphical interface, it comes with several hundred common exploit modules in the basic download available at metasploit.com. For testing Web applications specifically, the well-regarded Nikto has also undergone recent updates and is available at cirt.net/nikto2.

Wireshark provides top-notch network protocol capture and analysis, and its filtering and search functions make a good noninvasive tool for beginners interested in TCP/IP. This high-quality successor to the long-running Ethereal tool is available for Windows, Linux and Mac. The "Buy" button at wireshark.org leads to a happy reminder that it's free and open source.

KisMAC's simple interface belies its powerful wireless assessment and penetration testing features. This OS X application is available at trac.kismac-ng.org, where one can also find an active support community. Kismet, its more powerful but less friendly progenitor, is available at kismetwireless.net for Linux and Windows. There are active communities and numerous add-ons for each.

For more information, Fyodor, the author of Nmap, maintains a somewhat dated but good list at sectools.org of the top hundred open-source and low-cost security tools other than Nmap.
Sphere: Related Content

Hong Kong, China Web domains cited as "most dangerous" - Network World


Hong Kong and China are the "most dangerous" places to surf the Web based on country domain, according to McAfee's annual assessment of the riskiest and safest places in cyberspace.

"We looked at the major categories, including exploits by drive-by downloads, spam, and downloads that come with malware such as viruses," says McAfee analyst Shane Keats about the security company's new report, titled "Mapping the Mal Web Revisited." He describes the report as a bit like a "Lonely Planet" travel guide for the Web, adding, "Danger on the Web is very fluid."

The report, based on the Web-crawling and analysis technologies that power McAfee's SiteAdvisor tool for safe Web surfing, looked at 9.9 million heavily trafficked Web sites in 265 countries ending in country domain codes, such as .br for Brazil.McAfee also analyzed the
malware consequences of visiting the more generic top-level domains, such as .com and .org. While McAfee doesn't claim to have crawled over the entire Web, it believes it viewed 95% of Web traffic in the top 74 countries where the Web is used the most.

While the "Information" (.info) domain name is judged by McAfee to be the most dangerous among the generic ones with 11.7% risky sites, it's Hong Kong and China that stand out in this year's study as dangerous on the country level.

Hong Kong (with its .hk domain) had ranked 28th in last year's study but jumped to No. 1 to gain the "most dangerous" title. China, which had ranked #11 in last year's report, jumped to the #2 spot for riskiest this year. The McAfee report says 19.2% of all sites tested associated with .hk were dangerous and 11.2% associated with .cn were.

As to why the situation in Hong Kong worsened over the past year, McAfee pointed to statements provided by Bonnie Chun, an official with the Hong Kong Domain Name Registration Company, about decisions that might have inadvertently encouraged scammers.

Among the statements attributed to Chun were making the Hong Kong online registration process "more user-friendly" by allowing registration of several domains at one time as well as "buy-one, get-two domains." As a consequence, "phishers usually registered eight or more domains at one time." Hong Kong last year began to tighten policies to rectify the situation.China may have soared to the top spot because the country is among the most inexpensive places to register, with the wholesale price for .cn "now being about 15 cents," according to the McAfee report.

Keats adds that China may have "poor controls" on domain registration as well. Registering an e-mail address at a Chinese (.cn) Web site is "dramatically more risky than it was last year," the McAfee report states. "Test registrations receiving high-volume, spammy e-mail more than doubled, from 17.2% to 39.7%"

Last year's No. 1 riskiest domain was associated with the tiny island nation of Tokelau (.tk) which had made Web registration there free. But the nation now no longer offers free anonymous registration — bringing an improvement of 85.8% under the McAfee rating system.

McAfee also ranked what it considers the top five "least-risky" top-level domains as Slovenia (.sl), Norway (.no), Japan (.jp), Governmental (.gov) and Finland (.fl). Each of these were said to have 0.2% or fewer domains rated as risky.
Sphere: Related Content

10 Ways Your Employees Pose a Security Risk for Your Organization

10 Ways Your Employees Pose a Security Risk for Your Organization


Employees can pose security threats to your enterprise IT infrastructure through mobile devices such as smart phones and laptops, as well as the various networks and applications with which their unsecured devices are liable to interact. Enterprise IT administrators, network administrators, and enterprise security workers and consultants should be aware of these security risks. Sphere: Related Content

Schneier on Security

Schneier on Security

The War on Photography

What is it with photographers these days?

Are they really all terrorists, or does everyone just think they are?

Since 9/11, there has been an increasing war on photography.
Photographers have been harrassed, questioned, detained, arrested or worse, and declared to be unwelcome. We've been repeatedly told to watch out for photographers, especially suspicious ones. Clearly any terrorist is going to first photograph his target, so vigilance is required.

Except that it's
nonsense. The 9/11 terrorists didn't photograph anything. Nor did the London transport bombers, the Madrid subway bombers, or the liquid bombers arrested in 2006. Timothy McVeigh didn't photograph the Oklahoma City Federal Building. The Unabomber didn't photograph anything; neither did shoe-bomber Richard Reid. Photographs aren't being found amongst the papers of Palestinian suicide bombers. The IRA wasn't known for its photography. Even those manufactured terrorist plots that the US government likes to talk about -- the Ft. Dix terrorists, the JFK airport bombers, the Miami 7, the Lackawanna 6 -- no photography.

Given that real terrorists, and even wannabe terrorists, don't seem to photograph anything, why is it such pervasive conventional wisdom that terrorists photograph their targets? Why are our fears so great that we have no choice but to be suspicious of any photographer?
Because it's a
movie-plot threat.

A movie-plot threat is a specific threat, vivid in our minds like the plot of a movie. You remember them from the months after the 9/11 attacks: anthrax spread from crop dusters, a contaminated milk supply, terrorist scuba divers armed with almanacs. Our imaginations run wild with detailed and specific threats, from the news, and from actual movies and television shows. These movie plots resonate in our minds and in the minds of others we talk to. And many of us get scared.

Terrorists taking pictures is a quintessential detail in any good movie. Of course it makes sense that terrorists will take pictures of their targets. They have to do reconnaissance, don't they? We need 45 minutes of television action before the actual terrorist attack -- 90 minutes if it's a movie -- and a photography scene is just perfect. It's our movie-plot terrorists that are photographers, even if the real-world ones are not.

The problem with movie-plot security is it only works if we guess the plot correctly. If we spend a zillion dollars defending Wimbledon and terrorists blow up a different sporting event, that's money wasted. If we post guards all over the Underground and terrorists bomb a crowded shopping area, that's also a waste. If we teach everyone to be alert for photographers, and terrorists don't take photographs, we've wasted money and effort, and taught people to fear something they shouldn't.

And even if terrorists did photograph their targets, the math doesn't make sense. Billions of photographs are taken by honest people every year,
50 billion by amateurs alone in the US And the national monuments you imagine terrorists taking photographs of are the same ones tourists like to take pictures of. If you see someone taking one of those photographs, the odds are infinitesimal that he's a terrorist.
Of course, it's far easier to explain the problem than it is to fix it. Because we're a species of storytellers, we find movie-plot threats
uniquely compelling. A single vivid scenario will do more to convince people that photographers might be terrorists than all the data I can muster to demonstrate that they're not.
Fear aside, there aren't many legal restrictions on what you can photograph from a public place that's already in public view. If you're harassed, it's almost certainly a law enforcement official, public or private, acting way beyond his authority. There's nothing in any post-9/11 law that restricts your right to photograph.

This is worth fighting. Search "photographer rights" on Google and download one of the several wallet documents that can help you if you get harassed; I found one for the
UK, US, and Australia. Don't cede your right to photograph in public. Don't propagate the terrorist photographer story. Remind them that prohibiting photography was something we used to ridicule about the USSR. Eventually sanity will be restored, but it may take a while.
Sphere: Related Content