Search This Blog

Wednesday, May 30, 2012

Well, we have seen many good things come out of social media and we have discussed how we have to endure the bad along with the good.

The recent news of the parent, upset with his son's iPod being confiscated, is an extremely disturbing story (link included at end of post). In reality, what was this guys defense strategy in court? I am not going to state that he lacked motivation, but the punishment should always fit the crime. Due to his poor judgement and acting out in this extremely malicious manner, this guy is looking at serious jail time. Forget about the civil suit that this principal is going to have, no matter if this parent is able to pay it or not, he will walk around life with a default judgement, having to operate under the radar in every job opportunity that he potentially may have in his future life.

Of course as you read this article, you probably don't care much about the offenders job outlook, nor do I.

When I read about how FM magazines blog (in Clay Sharky's book "Here Comes Everybody"), I thought it difficult to imagine how young girls could actually post methods to remain anorexic and offer bulimia tips. This is much more than self mutilation. This incident potentially could have caused an innocent man (if his sons iPad was confiscated or not), to have his good name dragged through the mud. This didn't just include the mans reputation as a principal, it also included his wife and family. There is a saying in the courts, "once you ring the bell, you can't un-ring it."

Well, at least justice was served in this case and the now two time felon is off to sit and think about his own life.

Read about this article at http://www.newkerala.com/news/newsplus/worldnews-27368.html#.T8Xy77BYvSg

Wednesday, May 23, 2012

another two cents


Just read a great article in Wired Magazine titled #Crowd Control. (Wasik 2012) It is about how social media fuels social unrest. It gives a timeline of the unrest that social media has caused in 2011. It covers how some 20,000 people gather for a “day of rage,” in Yemen to Athens Greece where up to 100,000 revolt against pay and pension cuts to how in Boston where a kid on Facebook invited and had hundreds of kids show up at a late-night beach party; forcing for a SWAT team to be called in.

The article lists 26 incidents that gathered people together throughout the world, for some cause good or bad, all who got the message from a social network or a SMS or email transmission.

I personally identify with the opening statement, “Why pack into Target when Amazon can speed the essentials of life to your door? Why approach strangers at parties or bars when dating sites like OKCupid … can more efficiently shuttle potential mates into your bed? Why sit in a cinema when you can stream? Why cram into arena seats when you can pay per view? We declare the obsolescence of ‘bricks and mortar,’ but let’s be honest: What we usually want to avoid is flesh and blood…”

I do not think I could have said it any better than that and that is exactly how I feel. Don’t get me wrong, I am the first one to want to have dinner and drinks with friends, but only with those friends that I have already met. I suppose I have enough friends already and really do not care who I meet at the supermarket. I have a 50” flat screen with surround sound, why would I go to the movies just to pay $14 for popcorn and a coke, let alone the price of the ticket when I can have Netflix stream directly to me. It saves me the hassle of walking on the sticky theater floor, sitting next to the people that do not stop talking and even better, when I want another Coca-Cola, I can pause, go to my frig and get one that cost me .42 cents at Costco.com.
Did the convenience of social networking cause me to have societal anxiety that I do not need to be around them? I doubt it is the cause, but it certainly showed me that there is a better way to buy everything from Mother’s Day presents to computers (as I type on my new Dell Alienware Aurora X79 with Dual Layer Blue-ray reader, dual 23” wide screen monitors and 2 TB RAID hard drive that I custom built online from Dell) to products from Walmart.com (even though Walmart is only 5 minutes away).

One of the best things is when I find a vendor out of state that offers free shipping and no sales tax! Maybe it’s just laziness, because I KNOW that Target would have a problem with me if I went in their store and shopped in my pajamas. My two cents again. – Chris.




Saturday, May 19, 2012

my two cents on Facebook IPO


I think that all of the hype behind the Facebook IPO is the primary reason that it only closed .6 percent higher at $38.23 than its open of $38. This still was the single largest IPO for any technology company. Still shadowed behind the one day IPO of Google in 2004 that had an 18 percent return.

It still is hard for me to romance a stock that is based on something that in reality doesn’t exist. I mean, Intel manufacturer’s chips, Dell and HP put out computers and we can see and touch them. In addition, many people are viewing FB as a fad. Look what happened to MySpace, it almost doesn’t exist anymore compared to what it used to be.

According to Bloomberg.com, the U.S. Securities and Exchange Commission (SEC) is investigating into why initial trading the stock took a half-hour longer than NASDAQ OMX Group Inc.’s forecast. The underwriters of the stock, which numbered more than 30 of which included Goldman Sach’s (GS),(remember, they were the ones that avoided BK during the subprime mortgage meltdown due to the fact that the U.S. Treasury Dept.’s head chief was an ex-GS executive…Hmmmm) purchased the stock to keep it from dropping below its IPO price.

This IPO made FB more expensive than every stock in the S&P 500 except Amazon and Equity Residential. FB sold 421.2 million shares, raising $16 billion dollars. Not bad for a Harvard drop out who is only 28 years old.

I used to be an avid day trader, spending more time watching the ticker on my screen while at work than actually doing the work that I was paid for. I would never buy a stock that traded at 107 times trailing monthly earnings.

Without question, anyone who WAS able to buy this stock did so mostly because of emotional reasons. I guess I am still stuck on buying something that isn’t tangible, even though Amazon, eBay and Google are also virtual company stocks, they all offer something that I can either get an answer from, buy new plants for my garden or purchase a book. That’s my two cents on this subject.

Monday, May 14, 2012

Social Dilemma


Social Dilemmas

I found the social dilemmas the Shirky discussed in chapter 8 (Shirky 2008) to be extremely profound in two areas. First, the blog that was created within what was FKA for Young Miss, and then Your Magazine, then just YM, was extremely disturbing. Naturally, as the father of four sons and two step-sons, there never would have been a reason that I would have even visited this site, let alone know of the popularity of taking pride in young girls who got together to discuss how to remain anorexic (Shirky states that they became known as Pro-Ana) as well as bulimia and other mental disorders These disorders YM did not want to be affiliated with, therefore shutting down their blog.

One thing that I believe that YM could have done however, is monitored their website closer, putting into their code that every post that contained certain keywords, which other blogs and chat rooms have in place that automatically either redirect an email address to one within their own, or even censor keywords, this case pro-ana, anorexia, bulimia and other such terms would show up as **&&^%&** to block such content, then that user would simply be eliminated. At this point, as their IT director, I would have made it mandatory for a cookie to be dropped on their IP Address and prevent that person from logging on under a different identity. Although this has a simple “go around,” many users do not understand how to do it and thereby would be shut down by default.

“Sorting the good from the bad is challenging in part because we’re used to social disapproval making it hard for groups to form.” (Shirky 2008) He speaks of social loss and how these new found freedoms, due to the Internet[i], are often stymied. Governmental interference, such as that of the Singapore government blocking content of blogging prior to a 2005 loses all respect for mankind’s most basic freedom, Freedom of Speech. This is similar to how content is blocked/ restricted in countries such as China, North Korea and others where state owned media controls/ owns the Internet providers.

Reference




[i] Shirky uses the word Internet without being capitalized. As an avid reader and past high school teacher of English, Internet is a proper noun and I am not sure how the editors allowed for this word to be published without capitalization. This I would like to get clarification on. 

Saturday, May 12, 2012

Personnel and social media


Personnel and Social Media

Is it Legal?

Many employers cross the line when they perform their due diligence on prospective employers. Although it is hard to check on the employers hiring methods, the question of the legality of the proposed possibility that an employer can be looking at criteria other than just personality and intelligence to fit the right job to the right person. Federal Equal Employment Laws prohibit employment discrimination against qualified individuals with disabilities, and prohibit bias based race, color, religion, sex or national origins, age, as well as other considerations. (Greenstein 2010)

The purpose of social media in hiring practices should be limited to an effort to improve hiring decisions. The good trained HR person can consistently and accurately assess important organizational characteristics such as personality, intelligence, and performance when utilizing social networking web sites. (Kluemper and Rosen 2009)However, it is easy to find out other information that they normally would not be able to ask in an interview due to breaking of equal opportunity laws.

An article in the NY Times detailed an event whereas an employer used Facebook to review information about a recent graduate of the University of Illinois. The employer found on his page a description of his interests: “smokin’ blunts, shooting people and obsessive sex, all described in vivid slang. (Finder 2006) “A lot of it makes me think, what kind of judgment does this person have?” said the company’s president, Brad Karsh. “Why are you allowing this to be viewed publicly, effectively, or semipublicly?”

Employers may make it a common practice to utilize social networking, however those employers continue to inadvertently learn about matters such as candidates age, marital status and other topics typically that are off limits.(Kluemper and Rosen 2009)

References

               
               



Friday, May 11, 2012



Reward systems Marketing
Entrepreneurial orientation has positive influence on customer orientation and competitor orientation, market-based reward system has positive influence on customer orientation and competitor orientation, customer orientation positively to marketing performance, while competitors do not have a positive orientation towards marketing performance. (Soederiman 2011)
The following is an example of reward systems marketing used by Schmidt and Ralph; “Slater's 50/50 is a burger restaurant located in Anaheim, CA is currently running a promotion in Facebook. They want to increase their "like" count in Facebook. Facebook users often refer to the "like" count as a recommendation for or against a company. As a restaurant, a high "like" count would indicate a great option for an individual that is looking for a new place to eat or a place to eat in a town they are visiting. To increase their like count they have started a promotion stating that the Friend that gives them their 1000th like will receive a "SURPRISE". The promotion sends out a message updating the count in an attempt to get more people to "like".(Schmidt and Ralph 2011) The surprise would be the market-based reward system.
Networking is not new to the business world. Networking has been able to create a new medium within social media. Social networks, blogs, micro blogs such as Twitter and really simple syndication (RSS feeds) all have had a deep impact on how promotion of the organization can be utilized. These tools require different approaches in order to be effective, efficient and successful.(Schmidt and Ralph 2011)

References


               


transaction costs


When we speak of groups that do the organizing..." (Shirky 2008) Shirky spoke of following a $300 telephone to the new found owner. Did the transaction of obtaining the phone decrease or increase? It is apparent that the data involved was much more valuable than the phone itself. Therefore, did the transaction cost of regaining said lost phone exceed "We use the word 'organization' to mean both the state of being organized and the its original cost? Perhaps not, as we weigh into the matter that the data was far more valuable than the hardware itself.

What is the tangible effect on transaction cost if we weigh into the matter such items as operational efficiency and employee engagement? (Jue, Marr et al. 2010) If we utilize an internal social media presence, such as Oracle did, we can understand without reservation the connection to success that our employees believe are needed. In itself, these connections may not be met via a personal interview, but left alone to its own creation; the employee appears to become more engaged in its effort to provide success to the relationship.

As Kelly stated, communication is not just a sector of the economy, communication IS the economy. (Kelly 1998) So given the phenomenal success of Amazon and eBay as an example, do their simple suggestions of what “others like you” have purchased weigh into the strategy of permissible marketing? Obviously they do as their continued success of marketing in this low cost forum will endure many profits into the future and far beyond.

References
               
               
               


Saturday, April 23, 2011


What are the technical AND economic transformations that are making the new emerging media practices possible? Be specific—not just internet, but how, what capacities, materials, etc. Think about other technologies, roads, satellites, phone, and alternative energy sources, 

            Without question, the single most technical transformation is the SmartPhone. Everyone has one, everyone needs one. The current world wide ratio of cell phones is 2 cell phones for every single land line. (Maxwell, 2009) Since the SmartPhone is needed to make and receive calls, people usually sleep with the phone by their bed, let alone carry it wherever they go. The economic transfer is in lowered cost of parts, mainly the chips that run the OS. Take a picture on your SmartPhone, click a button and there it is on Facebook for everyone to see. The same can be done with Twitter as well as other social media sites.
Alternative energy sources would be my number one economic transformation outside of the Internet. Solar and wind power have yet to be harvested in an economical and practical fashion. Yes, they exist, but they are very expensive to produce and put into operation. Additionally, their size alone would preclude most people from having them in their homes. This in a sorted way leads to both economical as well as material capacities. If renewable energy were to be able to advance in the scientific portion of production as the computer did, it would eliminate the need for fossil fuels, thereby destroying OPECs grip on the world, let alone the emissions leaving the environment. With the renewable energy sources would come the materials needed to create the devices. We have seen companies such as IBM, Intel and others make billions of dollars from chips as small as or smaller than the tip of a pen. If this could materialize whereas it was feasible to create these alternate energy sources at a cheaper price, an entire new market would open up.
New emerging media practices are not new concepts however. People meet on Match.com and eHarmony.com; they meet on Facebook and other sites. How is this different than meeting someone in a gym, a nightclub or even a supermarket? The concept is the same; however the venue has changed due to the immediate ability and anonymity that people have with the Internet. The downside to meeting someone on the Internet was depicted in a cartoon that I recently read; there was a picture of a young girl with the caption of “meet 12 year old Cindy.” Below it was a sleazy old man in a dirty t-shirt with a cigar in his mouth that read, “Meet Cindy’s Internet 12 year old girl friend.” Therefore, the concept has basically remained the same, the threats that the Internet bring sometimes outweigh the good.
Reference
Maxwell, B. (2009). COUNTRIES WITH THE HIGHEST RATIO OF CELL PHONES TO LAND LINE TELEPHONES. Retrieved April 2011, from Geography Lists: http://www.geographylists.com/list21n.html



Understanding New Media
     Mediacy, hypermediacy and remediation can be used as terms to describe different types of media as well as the same type of media. The Sports Illustrated video is a prime example of this. Using the inter-active video in its new interactive format, the magazine offers the perception of immediacy for its new format, but also acts as a manifestation of the journals hypermediacy. At the same time, Grusin also claims that is premeditation because two very different markets are being advertised in one, the iPad and the new format for Sports Illustrated.

     Jenkins and Bolter offer up an example of remediation as a multi-media CD ROM whereas all information is self contained within the CD itself without having to look at outside sources for information. This is an example of an older form of media. Grusin on the other hand states that remediation does not have to be self contained and may contain a hybrid or mixed media that replicate other media.
Jenkins discusses premeditation as well in the sense of the Sports Illustrated video by having the iPad play the app, but then also has the ability to play a game while the user is reviewing the magazine, thereby deeming it preprogrammed interactivity.

      The video Gold Digger was also discussed as a form of remediation due to the look and style of pin-up magazine covers in the background while the video plays. Both Jenkins and Grusin agree that within remediation, there is a fine line to cross of undermining the premeditated type of all of our media interactions.
The article was very interesting and it did take a few times to read due to the fact that the two gentlemen contradicted each other on several accounts and obviously spoke in opinion, of which this topic is. It took several readings to realize that many forms of Mediacy can be crossed and mixed. I especially liked how they explained the terminology with the associated videos, however even there they had a few different opinions and some very grey areas. It is obvious however that both men took a lot of effort to not only develop their opinions, but their interview was well played. (Jenkins, 2011)

Jenkins, H. (2011, March 7). A remediated, premediated, and transmediated conversation with Richard Grusin (part I & II). Retrieved 2011, from Confession of an Aca-Fan: http://henryjenkins.org/2011/03/a_remediated_premediated_and_t.html



Thursday, April 21, 2011

The purpose of this assignment was to discuss Comment on Murray’s four properties of the computer and give examples for each. Murray’s four properties of the computer, encyclopedic, participatory, procedural, and spatial.

Murray’s four properties of the computer
The assignment was to discuss the four properties of Murray’s view of properties of the computer. Without headers listing the four properties, I found more than four, therefore I will engage all that I read and give examples of what I believe that the author speaks of.
In the beginning, the author speaks of confusion as to where digital medium is headed. She speaks of “enhanced video games and television.” Then she compares this to the vast variety of formats that are now available, and without stating it directly, questions as to where this is going? The Internet is now used on an iPad to watch TV, on an Xbox to compete against other warriors in fictional characters across the world, but is also used as an agent to learn, seek information, both current and historical. When the automobile was first invented, it was done so to seek an alternative to horse pulled carriages, but soon developed into crude race cars. One idea came from another and they were developments spawning from the same invention, as is the Internet. I believe that no matter what the invention is, there will be offspring that was not thought of in its inception, but developments that will bring many hybrids of the same design.
Murray then discusses the fact that the traditional library with books is being greatly outpaced by the Internet. She discusses that the library very may in fact be an obscure or even extinct entity due to the technology that exists on the Internet. Both Borges and Bush do not think of the computer as a replacement to the library, but instead it must create a change in how our minds think in relevance to how we seek out information. That we are looking for short cuts to gain this information as fast as we can.  I remember when I was younger; our town had an evening newspaper. The town was not small by averages of other towns in the U.S., but it was the only paper. Therefore, for this paper to go to print, it had to begin early in the A.M. As this paper was phased out and the entire countywide area gravitated to a paper owned by a large conglomerate, it became an A.M. paper available at most newsstands by 5 A.M. This meant that all of the information that was printed could have been reported up until late the evening before, giving an entire day’s head start on the evening rival. Eventually the evening paper closed and we are now left with still one local paper. The Internet though has beaten the current paper hands down. With an RSS feed, a text message can be sent from a murder scene describing the details within 30 minutes of the reporter receiving notification. Did I need to know this information this quickly? When the evening paper came out I didn’t, but now that I can receive an RSS feed on my SmartPhone, I can’t live without it. I believe this is what Murray describes in the differences of Borges and Bush.
A very interesting point that is bought up is about how information is pooled by many people via the Internet, making us smarter people. Not just in current and potential future events, but in historical events such as WWI and WWII, seemingly putting us in the midst of the battle with its descriptions and pictures. All of this done with a mouse and keyboard instead of looking through an endless sea of books and references. Although I personally am not a gaming aficionado, I imagine that many of the games that are sold now that simulate war, both on foreign soil and domestic gang fights give the user the same type of experience without actually being there.
The article ends with how in the 1960’s, the computer was used primarily for scientific and economic uses of extremely large databases. Murray likens the time when Douglas Englebart (who had devoted his lifetime work and career to developing the computer for everyday use), to that of Michelangelo, seeking what he deems as a “computer renaissance.” Instead, early in the years of computers and without the time needed to develop what we have today, Murray likens Englebart to DaVinci with much work to do, but left incomplete due to lack of time. Murray also believes that it might be possible one day that we in fact will have outthought ourselves and our humanity with the further advancements that computers may take.  (Murray)
Reference
Murray, J. H. (n.d.). Inventing the medium, http://www.ctudoctoral.net/file.php/615/EM820_Spring2011/Murray_Inventing_the_Medium.pdf. Retrieved 2011, from from CTU doctoral library.

Thursday, March 10, 2011

RFID and privacy

     There are a number of various types of uses for radio frequency identification units (RFID). The purpose of the chapter from Digital Privacy(Acquisti, Gritzalis, Lambrinoudakis, & Vimercati, 2008) was not necessarily to discuss the numerous applications, but to discuss the issues surround privacy concerns. However, discussing some of the applications may make the privacy issue easier to understand.

     The entire point of the RFID is to track, locate and identify an object. That object being a piece of clothing, an animal or a piece of machinery. From there, different attributes can be allocated to their purpose. In the case of clothing, a merchandiser can determine size, color and other customer traits, especially when associating them with some type of charge card.

     RFID can track inventory, streamlining shipments as they arrive and their location. RFID is used by local municipalities (in the northeast, EZ-Pass as an example). The use of EZ-Pass is the first type of RFID that I thought of that could invade privacy, as did thousands of others in its inception. If doing the speed limit between exist should take 45 minutes and I arrive in 20 minutes, does law enforcement have the right to use the EZ-Pass to give me a speeding ticket. I did several searches on this topic and found numerous similar concerns, but no actual prosecuted case of it in any state.

     My concern with this chapter is how the author details the RFID as a potential threat to privacy and civil liberties. I believe that this is overkill, however upon further reading; someone with malicious intentions could in fact use this against an individual.

     He lists several features of privacy violations;

• No tag presence awareness – I could understand if the tag is used outside of a store, but while merchandise is still unpaid for, I do not see this as a privacy violation.

• No reader presence awareness – if a customer intends on stealing an item, why should they know where the reader is located? Again, I do not see this as a privacy violation.

• Silent readings – again, as long as the merchandise is still owned by the store, no violation.

• Line of sight – same as silent readings.

     Where I do see the privacy threats as a concern is since there are no line of sight requirements, there is technology that exists that can identify items that an individual is wearing or carrying. Thereby making personal theft an easy target.

     If the RFID is not killed upon purchase, then there is a direct violation as a merchant can track the movements of a potential consumer.

     The author states that there is a school of thought in favor of RFID technology and that the privacy community has exaggerated its effect. I tend to agree with this school of thought.

      Where I believe the largest privacy violation can occur is where there are unauthorized readers. The author uses the example of someone stopping b briefly by the window of a sex shop and a reader took the information from a charge card in his pocket, identified him and is now on a mailing list of sex related items, when the individual may have only spent seconds at the window.

     Probably the best forms of legitimate use to not violate privacy are utilizing a kill command (rendering the device useless) or an active jamming device.

      I understand that there is the potential for privacy invasion with these devices, and I am not suggesting that the thought is irrational, just highly improbable due to the cost of mitigating the problem if caught violating privacy vs. its actual practicality.

Reference

Acquisti, A., Gritzalis, S., Lambrinoudakis, C., & Vimercati, S. D. C. d. (Eds.). (2008). Digital Privacy: Theory, Technologies, and Practices. New York: Auerbach Publications.





Thursday, March 3, 2011

Privacy-Preservation Techniques in data mining




Privacy Preservation in Data Mining

Data mining has an ultimate goal of prediction. (Acquisti, Gritzalis, Lambrinoudakis, & Vimercati, 2008) Data mining has many uses in today’s organizations, specifically in consumer focused companies such as financial, retail and marketing to name a few.

Data mining gathers and is the process of analyzing data from different perspectives and summarizing it into useful information. The information could be used to increase sales, decrease overhead or even find correlations of information that were not known to exist. If a company wants to properly target their advertising dollars, they are going to data mine. By applying predictive data mining, you will find the proper target audience and further, find out what their likes, dislikes and habits are. (Anissimov, 2011)

There are several types of algorithms that are utilized in data mining. To name a few, clustering algorithms are given a set of data that may or may not have any meaning, the clustering algorithm thereby clusters the data in several methods that may have not been recognized by the naked eye. The K-means clustering is a method of cluster analysis which takes into consideration a number of observations and puts them into K clusters; the expected result is an attempt to find the center of natural clusters in the data as well as a clarification of the differences of the different sets of data. (Wagner, Cardie, Rogers, & Schroedl, 2001)

A primary concern for data mining research is the development of data collection methods that incorporate the privacy of the individual. A productive direction for future data mining research will be the development of techniques that incorporate privacy concerns. Specifically, we address the following question; Since the primary task in data mining is the development of models about aggregated data, can we develop accurate models without access to precise information in individual data records? With data mining, a retailer could use point-of-sale records of past purchases to send targeted promotions on an individual’s purchase history.

In the corporate world, data mining is used most frequently to determine trends and predict the future. It is used to build models and decision support systems that give management information they can use to sell their products more efficiently. Data mining however is used in retail as well as pharmaceutical sales and even by the Department of Defense to predict with greater accuracy the likelihood of an attack. (Palace, 1996)

In regard to preserving the privacy of personal information, it is important to note that the privacy of individuals should never be sacrificed. The text gives an example of insurance companies sharing the data of patient records with the doctor’s office. Some data needs to be kept unique, while others can be shared. Sensitive information about an individual could be shared with law enforcement by an airline without the entire passenger list being violated. There have been many cases whereas different law enforcement agencies didn’t collaborate their information and in fact, with data mining could have shared information without giving away the entire portfolio that they have on record of the individual in question, thereby making the identification and apprehension an easier task. (Acquisti, et al., 2008)

References

Acquisti, A., Gritzalis, S., Lambrinoudakis, C., & Vimercati, S. D. C. d. (Eds.). (2008). Digital Privacy: Theory, Technologies, and Practices. New York: Auerbach Publications.

Anissimov, M. (2011). What is data mining? , 2011, from http://www.wisegeek.com/what-is-data-mining.htm

Palace, B. (1996). Data Mining Technology Note prepared for Management 274A : Anderson Graduate School of Management at UCLA UCLA.

Wagner, K., Cardie, C., Rogers, S., & Schroedl, S. (2001). Constrained K-means clustering iwth background knowledge. Proceedings of the Eighteenth International Conference on Machine Learning, 2001.





Monday, February 7, 2011

review of Forcing Firms to Focus: Is secure software in your future?

In the chapter Forcing Firms to Focus, Jim Routh the author gives an actual scenario of a company that he was the CISO of, how he progressed beginning with the stakeholders all the way through gaining the trust and respect of the developers. He uses a generic name, but of course I had to find out who the company was that he worked for and was discussing. The company that he was working for was American Express.(Anonymous, 2011a) As a major financial institution with a large working budget, it was obvious that he had little convincing to do on the part of the stakeholders and the board of directors.


He discusses previous security measures and modern methodologies of security as well as potential threats. He mentions the Melissa virus (Ellis-Christensen, 2011) as a modern virus that virtually shut down Microsoft servers by attaching itself to either WORD or Outlook and picking the first 40 names in the address book and re-sending the virus. Fortunately, Microsoft realized this right away and created a patch for it, which now exists in all aspects of MS Office in versions beginning with Office 2000. He explains that it is usually web applications that are how intruders gain access to the servers and can obtain multiple amounts of data including identity theft from the end user. (Oram & Viega, 2009)

The author lists a statistic form a survey that was conducted by McAfee where approximately two thirds of mothers that were end users, ranked their teenager’s online safety as important as or more important than drunk driving or drug use. I personally could not find this survey, but for the matter of record, I find this a bit far-fetched and wonder how the survey was conducted.

The author tells us that we can find the 10 top favorite hacking techniques by going to the website of The Open Web Application Security Project (OWASP), which lists the number one hacking technique (at time of publishing Beautiful Security)as cross-site scripting (Oram & Viega, 2009), but as of today it is listed as number two with number one being injection. The technical aspects of injection are “Injection can result in data loss or corruption, lack of accountability, or denial of access. Injection can sometimes lead to complete host takeover.” (Anonymous, 2011b) On this website, the reader can find Threat Agents, Attack Vectors, Security Weakness, Technical Impacts and Business Impacts for most known security threats.

As it usually occurs, Routh described that at American Express [1] developers were not as much concerned with the security vulnerabilities as they could be dealt with in future enhancements. He then goes on to describe how he convinced American Express that the development of the code must include the thought of security threats while being developed.

The author was aware of new regulations that were coming through, and in 2008 the first guidelines were issued by the Office of the Comptrollers of the Currency (OCC) (Corporate, 2011) He stated that the cost for compliance was significant, but at this point American Express had no choice in the matter. They put in place a software development process that they used both internally as well as a mandatory guidance for their vendors. To be assured that they were in compliance, they used a third party vendor to check their code as well as the code of the vendor. This vendor, Verify is a worldwide known organization that is used for multiple security purposes and has clients such as many U.S. governmental departments. (Anonymous, 2011c)

The author concludes that his effort has saved his organization 11% in productivity by eliminating security vulnerabilities early on in the lifecycle of the development of their software instead of spending those dollars to fix problems after they occur. (Oram & Viega, 2009)

References

Anonymous. (2011a). InformIT Network. 2011, from http://www.informit.com/authors/bio.aspx?a=2211919B-476B-40AE-84B5-4AE2FE6239D7

Anonymous. (2011b). OWASP top ten project. 2011, from http://www.owasp.org/index.php/Top_10_2010-A1-Injection

Anonymous. (2011c). Verify homepage. 2011, from https://www.vscnet.com/Default.aspx

Corporate. (2011). Office of the comptroller of currency. 2011, from http://www.occ.treas.gov/index.html

Ellis-Christensen, T. (2011). What is the Melissa Virus? WiseGeek.com, from http://www.wisegeek.com/what-is-the-melissa-virus.htm

Oram, A., & Viega, J. (Eds.). (2009). Beautiful security: O'Reilly Media, Inc.
_____________________________________

[1] assuming that my research is correct and American Express is the actual name for his fictious name of Acme


Tuesday, February 1, 2011

week VII Privacy-enhancing technologies

Users of the Internet may or may not be aware that every post that they make to a blog, a wiki, an email or even Web pages that are viewed, can be viewed and saved without the users knowledge. Let’s assume for a second that we are not talking about spying on credit card or bank information, social security numbers or even home addresses. We need instead to talk about the very basics of why privacy is extremely important.


The authors of Digital Privacy: Theory, Technologies and Practices discusses a wide array of privacy issues including but not limited to email, remailers and privacy enhancing technologies. They go on to say that identity theft is the number one growing crime in America today. (Acquisti, Gritzalis, Lambrinoudakis, & Vimercati, 2008) Another alarming fact is that databases are shared between government and private organizations.

The text discusses various types of remailers. Basically, a remailer is a computer service which renders your email private, as technology changed, so did the abilities of the remailer to hide the origin of the original sender. Why would someone want to hide their identity in email? Suppose someone is sending an email within an organization that they know that the head of their department is going to be fired by week’s end? If that department head were to be able to access and read that email, it may jeopardize many other jobs. In many countries, such as China and Iran as examples, monitor their government run Internet Service Providers (ISP), every web page visited is recorded and they review emails to see if there are dissidents within their jurisdiction and act as an actual Big Brother [1] .

The most famous remailer that was shut down was anon.penet.fi (Acquisti, et al., 2008) . I looked up this remailer, along with others such as alpha.c2.org and found that they were in fact, shut down for legal reasons. Anon.penet.fi was founded by Julf Helsingius . (Anonymous, 1996) An example of why someone would want to use a re-mailer, Helsingius told Wired Magazine that he used the debate of caller ID on a regular phone. When it first became popular, people were upset that the person being called would be able to know who was calling.

Many people believe that the same thing applies to email, that the privacy of the sender must remain anonymous. Unfortunately, there is a dark side to having an anonymous email. Since the email is encrypted and/ or stripped of its headers, less than scrupulous people can come up with a plethora of reasons why they would not want to be known.

Ironically, there are many websites that utilize remailers and the non-technical person is usually not aware of its presence. Websites such as www.craigslist.com, dating sites such as www.eharmony.com and www.match.com all use pseudo anonymous remailers. This means that they are using an email such as joestud@match.com but is then forwarded to Harold Smith’s (false name) actual Yahoo! or Gmail account.

I researched a few remailers that exist right now, including the two included in the text book. PGP Desktop and Gnu PG were what were included in the text as ideal remailers, which appear to be honest organizations with integrity. The problem that I saw with both of those examples was that they are both installed programs on the computers hard drive, whereas a company such as www.hushmail.com is a remailer that is web based. Having the ability to utilize email on any computer is more convenient in my eyes, but it is a personal preference.

Hush mail claims on its website that it is the most secure email system in the world. It also discloses however that if it finds out that any illegal activity is discovered, they will report the incident to the proper authorities. It goes on to say that it will only comply with any subpoena that is part of, or a reciprocating member of the government of British Columbia, Canada.

I personally utilize MS Outlook to access my POP3 Gmail account. Outlook comes already setup so that all email sent is encrypted. This however, does not preclude the ISP from unencrypting the message.

Another security issue are anti-phishing tools that I found to be important. Phishing is when an attack happens to a user when they visit a site that was disguised as a known site without the user’s knowledge. (Acquisti, et al., 2008) I have installed on my personal computer Mozilla, Internet Explorer (my default browser by choice) and Firefox. What I found interesting is that Firefox 3.6.13 comes with McAfee site advisor as part of the program. It checks the security certificate of every site that is visited. Also, when loaded, it checks software that may need updates.

As technology develops programs such as MS Outlook with built-in encryption and Firefox’s security checks will be part of all future programs, both web based and installed program.


References

Acquisti, A., Gritzalis, S., Lambrinoudakis, C., & Vimercati, S. D. C. d. (Eds.). (2008). Digital Privacy: Theory, Technologies, and Practices. New York: Auerbach Publications.

Anonymous. (1996). Press Release. http://w2.eff.org/Privacy/Anonymity/960830_penet_closure.announce.

--------------------------------------------------------------------------------

[1] Big Brother was a term used to characterize the government spying on citizens in George Orwell’s book, 1984. Ironically, this and other terms were written in this book that was first written in 1949.






Saturday, January 29, 2011

EM835 week VI Infosecurity Lawyers

     I have to begin with the fact that when first reading this chapter; I felt I was not going to like it. In fact, disdain it, the pages and even the ink on the pages. After all, in my former career, an attorney was involved in every transaction that we were involved with and compliance was a department that was locked away in a secret place. I have heard every attorney joke that exists. Basically, attorneys were a necessary evil.


     Then I did a search on security breaches and found a website from a non-profit organization called Privacy Rights Clearinghouse listing every U.S. security breach bought to litigation from 2005 until its updated date of today’s writing (January 29th, 2011). Up to this date, of all cases that were litigated, the total amount was 512,334,164. (Clearinghouse, 2011)It included items such as breaches of securities by doctors signing off on patient files that they never saw, billing them and leaving their files unsecure to a simple laptop stolen from a University that contained students information, including address and social security numbers.

     My idea on security breaches were mostly going to be in large corporations that were hacked and 40 million credit card numbers were stolen, or maybe a government server was attacked that contained vital U.S. security information. Ironically in local news, Wikileaks is which immediately came to mind. It actually was in fact started as a wiki but not longer accepts edits to its sites. (Editorial, 2011) This site has been blacklisted by most web hosting companies, banks and viewed as a national threat to many countries. Those are the major items that I believe most people think of, on this type of grand scale. It is staggering to think about the amount of money that is lost, or should I say not realized lost, due to security breaches.

     The chapter 12 of Beautiful Security lists a case that went before a judge in 1944 where a barge that was unmanned, broke loose in NY Harbor and caused damage. The judge came up with a formula to determine what the liability of this case would be. The formula B is less than P times L, where B is the burden, P is the probability and L is the injury. Therefore, the burden (B) would be based on if it is lower than P times L. The author translates this case to state that “the burden on an organization to prevent an information security breach or lapse is less than the probability of that breach multiplied by the damages that could result, that organization should seriously consider taking on that burden.” (Oram & Viega, 2009) They then go on to say on how should they determine the return on security investment (ROSI). Does the organizations security dollars match their potential liability? Without going into detail of the ensuing formula, my initial thoughts were how you determine the ROSI in 2009, when a new security breach possibility arises in 2010, then re-determining the ROSI in 2010 for a new breach to raise its ugly head in 2011 and so forth. I would expect that based upon the solution cost or the cost of mitigation, the ROSI will have to be re-visited on a regular basis.

     Does an organization take a pragmatic approach to their potential security breach exposure, or wait until there is an actual problem and attempt to mitigate the problem then? I believe that the latter was the norm in early technology years and the former is now the driving forces of both IT and compliance departments. An organization can follow all of the rules and guidelines so as to comply with their state and federal regulations and still be breached, just as a company that does not comply with the laws, and remain unscathed. It is apparent to me that if an organization is going to flourish in today’s changing worlds; IT and compliance have to be best friends, even if they are a necessary evil.

References

Clearinghouse, P. R. (2011). Chronology of Data Breaches Security Breaches 2005-Present

from Privacy Rights Clearinghouse: http://www.privacyrights.org/data-breach#CP

Editorial. (2011). Wikileaks. New York Daily News. Retrieved from http://www.nydailynews.com/topics/WikiLeaks.org

Oram, A., & Viega, J. (Eds.). (2009). Beautiful security: O'Reilly Media, Inc.










EM835 week V

     In the chapter Beautiful Log Handling, the author states “Today’s growing log standard efforts (such as MITRE’s Common Event Expression or CEE) will lead first to the creation of log standards and ultimately to their adoption.” (Oram & Viega, 2009) In fact, the author’s example of MITRE Corporation already currently provides and partners security efforts such as Malware (MAEC), Attack Patterns (CAPEC) and Vulnerabilities (CVE) among other standards that are partnered with and/ or co-sponsored by such agencies as the National Cyber Security Division of the U.S. Department of Homeland Security. (Mitre, 2011) In fact, if not for the threat of malicious attacks on the part of other countries (in regard to the security of the U.S.), attacks on retail competitors (as an example) and the important data that is stored, how the logs are handled is critical. In fact, an example that the author uses is the need to abide by laws such as the Health Insurance Portability and Accountability Act. (HIPPA, 2011)


     It might seem obvious to have log standards that would account for any deviations among items such as public servers of an organization that are placed in a DMZ so as to separate their Internet presence from their LAN, thereby not compromising the integrity of data within the rest of the organization. Then I began to think about why in today’s technology world, why would large companies have an issue with maintaining proper logs. Using a retail example as the author did in Beautiful Security, I thought of the merger in 2005 of Sears Roebuck and Kmart stores. Without having specific knowledge of their issues of combining the data into one source, I am sure that both of them operated on two very different legacy systems that had issues with converting the data, thereby making accurate logs virtually impossible.

     There is a very large Healthcare facility in the town that I live in with over 100 doctors of various practices. This facility is owned and operated by a larger corporation, which owns other such facilities. They grew this large by acquisition of other practices and like facilities. There is no doubt that there had to be a major undertaking to have all of the data merged into one system so as to abide by the HIPPA law. I tried to find an example of a major intrusion of a corporation due to improper log information, but that data seemed to be too vague since I wasn’t exactly sure what I was looking for. So, in the case of the local healthcare facility, I am sure that their IT staff is highly trained in the conversion of data and the challenges with keeping accurate logs.

     In any case, world governments and Fortune 100 companies realize the need to rid themselves of the legacy systems of their past, and get the data onto one platform so that proper logging can take place to not only prevent an invasion, abide by certain laws but to also perform due diligence in identifying the culprit of the attack.

References

HIPPA. (2011). Health Information Privacy. 2011, from http://www.hhs.gov/ocr/privacy/

Mitre. (2011). A Standardized Common Event Expression (CEE) for Event Interoperability. 2011, from http://cee.mitre.org/

Oram, A., & Viega, J. (Eds.). (2009). Beautiful security: O'Reilly Media, Inc.





Friday, January 28, 2011

Wireless Networking


I recently saw a movie where a safecracker worked for a company that in fact, manufactured safes. Their reasoning was simple, if this safecracker could bypass the security of their safes, or any other safe for that matter, then that flaw must be remedied. In Beautiful Security, the author discusses how part of his job is to do just that, find flaws with wireless systems. (Oram & Viega, 2009) Never thinking of this as a solution to avoid hackers, it makes a lot of sense to have someone that can find the flaws in wireless security systems.

After all, it is widely known what is at stake by having a wireless network attacked. Companies in all of the modern business era have sought out personal data so that they could more readily market to them. What is at stake here is much greater as the “pirate” is seeking the information for personal financial gain.

One major issue that needs to be addressed is the security issues that exist in Third World countries where they do not have the technology or resources to crack down on this pirate access. It was estimated that in 2000, over $2 billion was lost due to pirated software. (Bhasin, 2002) Where the tide is now shifting to mostly Internet downloaded software, the case of increased security and awareness is much greater. Bhasin talks about software; very few were concerned because, after all, did it matter to you or me if Microsoft, Oracle or Sun lost a few dollars? Now with the advent of the new age of Internet users, people have become more familiar and comfortable with purchasing items online. This means placing orders with a credit card. Sure, any merchant that is worth anything will have the check out cart secured and the data encrypted when sent, but what can be encrypted can be unencrypted.

I remember reading about how having open source software to prevent a lot of software privacy, this may be true, however there are still dangers with this as well in regard to wireless connections. Android, who is owned by Google, is an operating system that is based largely on a Java platform. Java in itself is largely open sourced; therefore does it mean that apps can be written and utilized to capture important data from Smartphone’s? In addition, Google owns Android; does this mean that Google can capture the data transmitted on Smartphone’s? Microsoft, after an unsuccessful bid to purchase Yahoo! created a 10 year agreement to allow Microsoft to use its vast presence to advertise in exchange for a 12% profit of the revenue associated with its advertising efforts. (Oreskovic, 2011) EBay owns PayPal; the list is staggering of the sharing of the information among companies and their holdings.

Every time a hacker comes up with a new virus or worm, Norton, McAfee, et al come up with a cure for it, only to turn around and find out another malicious individual creating chaos. With the advent and extreme popularity among Smartphone owners (many of which are NOT tech savvy), how many cures are there going to be in the future for the prevention of hacking a wireless communication device?

The twists on the legal issues surrounding wireless and the Internet are mind boggling. When a user signs on to Facebook, they are doing so with their private logon and password. Recently, a Federal judge ordered it legal to subpoena Facebook, MySpace, Twitter and other social networks information that may be relevant in a criminal proceeding. (Grow, 2011) Many cases have been won on this decision. How many people access their favorite social network site via their Smartphone? Does that in fact now become part of the same legal decision? Cell phones for years have, if believed to have been involved in a crime, are admissible as evidence. What happens if a hacker accesses a person’s status page and creates a situation whereas they could potentially incriminate innocent people?

Wireless networking is inevitable and is here to stay. As technology develops, it is obvious that any and all flaws be realized in their research and development and creates a fix for them prior to their release. Maybe it even makes sense for Google and PayPal and Microsoft to hire some of the convicted pirate criminals to find if they can in fact, hack their network.



References



Bhasin, S. (2002). Software Piracy- A challenge to E-world. SANS Institute InfoSec Reading Room.

Grow, B. (2011). In U.S. courts, Facebook posts become less private. Reuters.

Oram, A., & Viega, J. (Eds.). (2009). Beautiful security: O'Reilly Media, Inc.

Oreskovic, A. (2011). Yahoo warns of weak Q1, more cost cuts planned. Reuters,