Oops: Cops Distributing Spyware To Families As “Internet Safety” Tool


Over the last couple of decades, internet safety has become as much if not more of a concern for many parents and families as physical safety. To help, many local police departments have given out free safety software to families as “the first step” to keeping their children safe online. Sounds great, right? Sure… except that “safety software” is really a keylogger that sends your family’s every word zipping unencrypted over the internet, ripe for anyone to steal. Oops.

The ComputerCOP software, as the Electronic Frontier Foundation reports in a detailed investigation, is usually handed out at “internet safety” events. Police, sheriffs, and district attorneys doing community outreach buy the software, then have it rebranded with their own agency name, logos, and imagery before handing it out to local families at schools and libraries.


However, as the EFF explains, “as official as it looks,” the contents of the disc are just spyware, purchased in bulk from a company in New York that exists solely market and distribute ComputerCOP to government agencies.


If it seems like a CD of supposed safety software is a relic of the era when you got “the internet” from an AOL 3.0 disc they handed out at Staples, you’re right. In the name of child safety, it has two major functions: a hard drive search and a keystroke logger. The idea is that parents can use the software to keep an eye on the images, text, and websites their children are encountering.


The search tool runs from the CD without installation, and checks out all the files on the hard drive for thousands of terms related to gangs, hate groups, drug use, and of course sex. The EFF tested the searches, however, and found them deeply unreliable. Results were routinely laden with false positives, including “items as innocuous as raw computer code.” Meanwhile, actual files that did have words like “drugs” in them were not found but still turned up on standard Mac or Windows searches.


And image searches, meanwhile, can’t differentiate between downloaded or cached content and all the images that exist on a computer as part of the software installed on it — that’s everything from Office clipart to the preview images some graphics card driver updaters use — and so returns so many tens of thousands of hits as to be useless.


ComputerCOP also claims that it will let you view a history of your child’s web visits, but as might be expected for a relic of an earlier age it’s extremely browser-limited and only works on Internet Explorer or Safari.


The keylogging program, however, does work — and that’s a problem. Once installed, the EFF writes, “if the user isn’t careful, it will collect keystrokes from all users of the computer, not just children.” On a Windows computer, ComputerCOP stores the full keystroke logs completely unencrypted on the hard drive. (On a Mac, the log is encrypted but can be decrypted with the ComputerCOP default password.)


Parents can set up the software to e-mail them an alert whenever a certain word, like “marijuana” or “sex,” is typed in. But to generate those e-mail alerts, the software sends the unencrypted key logs to a third-party server that then sends the e-mail.


So the police have been cheerfully handing out free keyloggers to anybody who wants one for over a decade, and it’s easy as pie to use them illegally on people who aren’t your kids. Which is a problem. But even aside from that, the unencrypted data itself is an enormous vulnerability. As the EFF explains:


Security experts universally agree that a user should never store passwords and banking details or other sensitive details unprotected on one’s hard drive, but that’s exactly what ComputerCOP does by placing everything someone types in a folder. The email alert system further weakens protections by logging into a third-party commercial server. When a child with ComputerCOP installed on their laptop connects to public Wi-Fi, any sexual predator, identity thief, or bully with freely available packet-sniffing software can grab those key logs right out of the air.

The EFF contacted ComputerCOP by e-mail about these issues. Their head of operations, Stephen DelGiorno, responded, “ComputerCOP software doesn’t give sexual predator or identity thieves more access to children’s computers, as our .key logger works with the existing email and Internet access services that computer user has already engaged,” which is a completely useless non-answer that has nothing to do with the problems at hand.


ComputerCOP’s history, as unearthed by the EFF, is also not encouraging. DelGiorno also told the EFF that the keylogging feature was a recent addition to the software, but the EFF found references to it going back as far as 2001.


ComputerCOP also claims in its marketing materials to law enforcement agencies that it has received endorsements from the ACLU and the National Center for Missing and Exploited Children. The NCMEC did enter a one-year agreement allowing ComputerCOP to use their name in 1998. However, as a spokesperson told the EFF, the agreement was not renewed and the two organizations have had no contact with each other in the past 15 years. When the NCMEC found out, via the EFF’s queries, that ComputerCOP was still using their name, an attorney for the organization said that they would tell ComputerCOP to stop immediately.


But at least an agreement did once exist, back when the parents of today’s web-using children were themselves still kids in school. The ACLU, however, never endorsed it at all. The closest they came was a 2005 story in the Detroit Free Press where the head of the ACLU’s Michigan office “[endorsed] the idea that parents should take responsibility for monitoring their children as opposed to relying on the government to act as a babysitter,” the EFF reports.


The deputy director of the Michgan ACLU confirmed to the EFF, “I can say unequivocally that it was not an endorsement of the product. Our position as an organization is not to endorse technology like this.”


Being super-shady, however, has not stopped ComputerCOP from becoming widespread. The list of participating agencies that distribute copies is definitely not small, and agencies at every level — city, county, state, and federal — are among them. The EFF’s full listing includes over 245 agencies in 35 states, as well as the U.S. Marshals. And it’s not cheap: cash-strapped agencies are spending tens of thousands of of tax or grant dollars on every set of discs they order.


Adding up the purchased batches, the EFF estimates that anywhere from several hundred thousand to well over a million copies of ComputerCOP have been purchased by law enforcement. It’s impossible to say how many of those actually wound up being given to families, and then to guess how many of those families installed and regularly use the software. Still, if the number is greater than zero, it’s clearly too many.


Should you happen to use a computer that has this hot mess installed on it, the EFF also provides detailed instructions for removal.


ComputerCOP: The Dubious ‘Internet Safety Software’ That Hundreds of Police Agencies Have Distributed to Families [Electronic Frontier Foundation]




by Kate Cox via Consumerist

4 Things We Learned About The Psychology Of Costco’s Free Samples


Anyone familiar with Costco knows about the wide variety of free food samples that shoppers can score when pushing their oversized carts around one of the wholesale clubs. But as you’ve probably guessed, these samples aren’t just about providing free piecemeal lunches to customers.

The Atlantic’s Joe Pinsker recently took a look at the psychological underpinnings of free samples at Costco. Of course, since the company is so tight-lipped about a lot of the things it does, he had to rely on research and observations of others.


Here are some of the highlights from the Atlantic piece…


1. The samples may engender a sense of obligation in consumers

When you snack on that free sample of summer sausage, or wash it down with some free coconut water, there’s a chance you might feel like you should buy something.


“Reciprocity is a very, very strong instinct,” explains Dan Ariely, a behavioral economist at Duke University. “If somebody does something for you… you really feel a rather surprisingly strong obligation to do something back for them.”


2. The samples might lead you to buy something similar

Maybe that coconut water didn’t knock your socks off, but it might have caused you think about another beverage that you do want, but that you hadn’t planned on buying.


“What samples do is they give you a particular desire for something,” says Ariely. “If I gave you a tiny bit of chocolate, all of a sudden it would remind you about the exact taste of chocolate and would increase your craving.”


Sure, the company that is sponsoring the samples might care that you buy something else, but for Costco, an impulse purchase is a definite win.


3. You’re more likely to buy when others are around

Pinsker cites a 2011 study from the UK on sampling that found that “Samplers with a heightened awareness of the presence of others at the sampling station may feel a level of social ‘pressure’ to make a post-sample purchase.”


So if a sample table just had free cookie bites sitting there without anyone to smile and hand them to you, shoppers wouldn’t feel as pressured to buy.


4. It’s ultimately about creating a distinct “Costco” atmosphere

Sure, other stores give out samples, but few are as linked to the notion of sampling as Costco. It’s something fun that brings shoppers back and makes the shopping experience more pleasant. Much like many Costco shoppers look forward to bargain (but reasonably tasty) hot dogs and pizza during their visit, they have come to associate the samples with a day at the ‘Co.


You should definitely check out Pinsker’s entire article for more insights on sampling and its role in Costco’s identity.




by Chris Morran via Consumerist

Air Canada Pilots Warned To Stop Sneaking Porn Into The Cockpit, Because Seriously?


Perhaps there’s something about the name that makes it a tempting locale to stash porn, but Air Canada pilots have been warned to stop sneaking porn into the cockpit, after several incidents where the airline found explicit content on planes. Because you know, there are other things to concentrate on when you’re flying a ginormous piece of metal through the sky, thousands of feet above the ground.

According to News.com.au, the airline sent an internal email about the problem last year, but it was only recently obtained by CBC News. It’s the first we’ve heard about it, I’ll say that.


In the email titled “Inappropriate Material in the Embraer Flight Deck,” the chief pilot writes that this is an ongoing problem and it’s time to cut it out.


“I am disappointed to have to raise this issue once again but unfortunately we have some people that have yet to understand the message,” he wrote, adding that the airline was trying to find the people responsible.


“Once they are identified they will be subject to discipline to the full extent of the law and our corporate policies.”


That warning email — the second of two sent in about a year — didn’t stop all the smut smuggling, apparently, as porn was reportedly discovered on a jet as recently as February. Add all the way back six years ago, a female pilot claimed she saw pornographic images glued and tucked into parts of the cockpit, including some violent images.


At that time, Air Canada found “evidence of racial or ethnic prejudice as well as sexual materials in the workplace.”


It’s not a violation of safety rules, however, but Transport Canada’s aviation health and safety occupational officer says the agency did try to get Air Canada to take things more seriously. Because yes, it is hazardous to have that stuff around on the job, and not just because of distractions in the nether regions.


“Pilots are stuffing paper material inside compartments where electrical wiring is and that this is a hazard not to mention that this is a form of workplace violence,” she says.


Air Canada says it was just one plane recently, however, with a spokesman telling CBC News: “The material in question consisted almost entirely of inappropriate business cards and was confined mainly to one aircraft type and route, our Embraer E-90s operating to Las Vegas.”


Oh, well, if it was on the way to Las Vegas, that explains it. But not really.


Air Canada porn: pilots warned to stop sneaking material into the cockpit [News.com.au]




by Mary Beth Quirk via Consumerist

McDonald’s Japan Also Gets Into The Black Burger Game

(Twitter: @elitedaily)

(Twitter: @elitedaily)



Because there is nothing more appealing than a slab of dark gray meat on a dark gray bun, McDonald’s Japan has followed Burger King’s lead and introduced a burger that doesn’t look like anything you’d really want to eat.

McDonald’s “Halloween” burger is a limited-time offer that follows only weeks after BK Japan unveiled its black Kuro Burger to much Internet buzz.


The McD’s offering is slightly more colorful than the BK competitor, since it uses good ol’ yellow cheese instead of the eerie jet-black slices. Additionally, the sesame seeds on the bun add some variation to the grayscale breading.


The above photo, Tweeted by Elite Daily, doesn’t seem to show it, but this other photo of the McDonald’s ads for the burger indicate some sort of black sauce between the beef patties and the bottom bun:



As the NY Daily News points out, while McDonald’s might be trailing behind BK on this particular promotion, the company has used squid ink to darken its burgers before. In 2013, its Hong Kong restaurants sold a Black Burger with two beef patties, mashed potatoes and truffle sauce on a squid ink bun.




by Chris Morran via Consumerist

Firefighters Rescue Unconscious Man, Finish Mowing The Lawn For Him

FIrefighter tidying up cut grass like a boss. A nice boss. (CBS Los Angeles)

FIrefighter tidying up cut grass like a boss. A nice boss. (CBS Los Angeles)



When something needs to get done, it needs to get done. And it’s awfully nice to hear that lately, local law enforcement have been stepping up to help finish jobs that can’t finish themselves. There were the cops who delivered a pizza after the delivery driver was in a car crash, and now some friendly firefighters have put themselves forward as lawn guys, mowing a man’s front yard after he lost consciousness.

Emergency personnel called to the scene in Corona, Calif., first provided lifesaving treatment to a man who had passed out while mowing the high grass on his lawn in the sun, reports CBS Los Angeles.


“I was cutting grass here, I feel dizzy a little bit, so I stand over by the car here,” the man remembers, noting that the grass was “so, so high.”


That’s when he fell face forward in the driveway, prompting someone to call for help.


After the ambulance pulled away to take the man to the hospital, the firefighters on the scene decided to stay at his house for a while.


“We all kind of looked at each other, kind of looked around at the lawn equipment and realized this family was going through a very traumatic event right now and they need some simple acts of kindness,” said a Fire Dept. Engineer.


So the five firefighters there finished mowing his lawn and cleaning up the grass, to the great appreciation of the man who says he fainted due to the heat and effort of mowing.


“I never had the experience like that before. I feel like safe,” he said.


It’s sort of like when I fall asleep eating cheese and wake to find that my cat has done me a solid and finished the job. But much, much better and kindhearted. Kudos, nice people of the world!


Corona Firefighters Save Man — And Then Finish Mowing His Lawn [CBS Los Angeles]




by Mary Beth Quirk via Consumerist

Sears To Sell Sears Canada Stake To Raise More Cash


Sears Holdings Corporation, the company that runs Sears and Kmart, needs to raise some cash to get through the rest of the year. When a person needs cash, they look around the house for things to sell. Sears did that, and what it saw was Sears Canada. The company announced today that it will sell part of its 51% stake in the company to current Sears Canada shareholders. You’ll never guess who’s buying!

Sears is selling its shares in a rights offering, which is when current shareholders have the opportunity to buy more shares at a special low price. For each share they currently own, shareholders can buy one share at the discounted price.


ESL Investments is one of the Sears Canada shareholders taking advantage of this deal, and will scoop up about half of the newly available shares. That name might sound familiar to you: ESL Investments is the hedge fund managed by Eddie Lampert, the manifesto-writing CEO of Sears Holdings. Yes, that would be the same ESL Investments that is lending Sears about $400 million, about one-tenth of what the company needs to maybe pull itself out of a retail death spiral.


The last month or so has been messy for Sears Canada: Sears Holdings tried to auction off its entire stake, but no one was interested. That’s what led to the $400 million loan, and then the CEO of Sears Canada announced last week that he will leave the company at the end of 2014 or when a new CEO is appointed, whichever happens first.


Sears expects to raise about $380 million from the sale of Sears Canada shares, $168 million of which will come from ESL Investments.


Sears to sell most of its Sears Canada stake through rights offering [Globe and Mail]

Sears to Sell Most of Stake in Canada Unit to Shore Up Liquidity [Wall Street Journal]




by Laura Northrup via Consumerist

Comcast Charged For Unlisted Phone Numbers, Listed Them Anyway

Starting in July 2010, Comcast accidentally shared thousands of California customers' unlisted phone numbers, even though those subscribers paid to keep their info hidden from the public.

Starting in July 2010, Comcast accidentally shared thousands of California customers’ unlisted phone numbers, even though those subscribers paid to keep their info hidden from the public.



When you pay to have your phone number unlisted, you would expect that the company you pay would honor this request. You’d also expect that if that company screwed up and accidentally published half of its unlisted customers’ numbers in the state of California, it might notice. This week, the California Public Utilities Commission is holding a hearing to determine if Comcast violated the law when it screwed up and shared more than 74,000 phone numbers, names, and addresses that were supposed to be unlisted, including info for customers who were victims of domestic violence or hiding from criminals.

CBS13 in Sacramento first reported on Comcast’s inability to keep unlisted numbers unlisted back in 2012, when a viewer demonstrated on-camera that she could easily call up 411 and request the phone number she was paying Comcast a monthly fee to keep off these directories.


At the time, Comcast apologized and refunded her the fees, saying it was a rare occurrence. But then in early 2013, it revealed to the CPUC that, during a 27-month period starting in July 2010, it had goofed and allowed the 74,000 unlisted numbers to be shared with third-party phone directories.


According to CPUC documents [PDF], the problem arose after Comcast implemented a new process for producing and disseminating listing information for its residential phone customers. The new system pulled information from a Comcast billing data table so that it could be shared with third party publishers, directory assistance providers, and in Comcast’s online directory.


Problem is, this data table didn’t include whether subscribers’ numbers were unlisted or not, so the lists sent out by Comcast to third parties included the confidential information of subscribers who had paid Comcast for an unlisted telephone number.


While many people have their numbers unlisted just out of a desire for privacy, there are those with more dire concerns about keeping their information out of the public eye.


“I have paid for unpublishing my information for years as I testified in a murder trial,” reads the complaint of one California Comcast customer. “Now, my wife, children, and I are all in danger; and I have nowhere to turn.”


Another customer asks how she is supposed to protect herself from a man that has previously threatened to kill her.


What makes the Comcast case even more intriguing is that, while the CPUC says “there does not appear to be any essential difference” between the CBS13 case from 2012 and the 74,000 other names that were revealed, Comcast maintains that the CBS viewer’s issue is “not the same” as the one being investigated by CPUC, but apparently did not give an explanation how the two are different.


Which makes us wonder how frequently, and in how many different ways, Comcast has failed to keep customers’ information secret.


After all, the initial Comcast report to CPUC only indicated that around 50,000 unlisted numbers had been published. It wasn’t until later that the company realized that the problem went back even further than it thought, resulting in the total of 74,000 numbers being compromised.


This is the same company that thinks it can handle another 10 million subscribers?





by Chris Morran via Consumerist

Police: Grocery Store Worker Walked Out With $1,200 Worth Of Meat Stuffed In His Pants


There are often questions involved in shoplifting incidents — why that particular product? Or what makes a store employee steal from his or her place of employment? And how come meat seems to be the most popular product one can shove down one’s pants (and again, though sometimes it’s puppies)? More mysteries remain to be solved, I’m afraid.

Police in Croton-on-Hudson, N.Y. have pinned a meaty crime on a supermarket employee, saying the man walked out of work with $1,200 worth of meat stuffed in his pants, reports the Associated Press.


It’s unclear what kind of meat he’s accused of taking, but I am pretty sure at least seven people subsequently made the joke, “Is that $1,200 worth of meat down your pants or are you just happy to see me?” Because what else can you do?


Police have charged the man with fourth-degree grand larceny, after arresting him on Tuesday for the reported theft on Monday. A state police spokeswoman said she’s not sure if his meat excavation involved more than one trip out of the store, or if the jackpot was loaded out in one go.


He’s due back in court on Friday, where he could plead not meaty. Okay, that was a cheap pun, he’s entered no plea as of yet. But when there’s meat in the pants involved, the riffs have to happen. They just have to.


Hang on — forgot about this one, and then we have this meat theft and ah yes, don’t forget to bring home the bacon. In your pants.


POLICE: WORKER HID $1,200 WORTH OF MEAT IN PANTS [Associated Press]




by Mary Beth Quirk via Consumerist

NFL Sunday Ticket To Remain A DirecTV Exclusive

sundayticket Millions of football fans now have a reason to not ditch DirecTV. After months of negotiations, the satellite service has finally renewed its deal to be the exclusive carrier for NFL Sunday Ticket.


DirecTV has been the sole pay-TV source for Sunday Ticket, which shows all Sunday afternoon out-of-market football games… for the price of several hundred dollars a year per subscriber.


Neither the NFL nor DirecTV is saying exactly how much the new deal is worth, but ESPN’s Darren Rovell reports that it will cost the satellite company about $1.5/year for the next eight years.


If true, that’s more than DirecTV earns from the fees it charges to Sunday Ticket subscribers, but the company knows that many of these customers might consider switching switch to cable — or simply drop pay-TV service altogether — if it weren’t for being able to see their favorite teams play each week.


Additionally, the exclusivity deal allows DirecTV to continue selling online-only versions of Sunday Ticket to non-satellite customers. AT&T has already expressed interest in packaging a wireless version to its customers, though it’s unclear if that would conflict with the deal between NFL and Verizon Wireless that allows for live-streaming of in-market games.


This is why Sunday Ticket has been such a key piece of DirecTV’s pending merger with AT&T. If the negotiations had failed, AT&T would have been able to walk away from the acquisition.


After all, DirecTV customers who want high-speed broadband service generally get it a cable TV company. If a cable customer drops her pay-TV service, she’ll still be paying for Internet. If a satellite customer gets rid of his TV package, that’s the end of their financial relationship.


The goal of the AT&T merger is to ultimately bring some sort of broadband solution to DirecTV customers that doesn’t come from a third party. AT&T says it has the technology to deploy a relatively high-speed wireless broadband service to rural areas, but has yet to reveal details on price, availability or timing.


With the country’s most-watched sport locked in as an exclusive for the better part of a decade, DirecTV is likely to maintain a healthy number of subscribers, giving AT&T time to deploy a wireless broadband offering and to hopefully continue building out its new gigabit fiber service.




by Chris Morran via Consumerist

Los 20 Peores Errores en Twitter de Empresas #infografia #infographic #socialmedia

Hola:


Una infografía con los 20 Peores Errores en Twitter de Empresas. Vía


Un saludo


Los 20 Peores Errores en Twitter de Empresas

Los 20 Peores Errores en Twitter de Empresas





Archivado en: Infografía, Redes Sociales, Sociedad de la información Tagged: Infografía, Marketing, redes sociales, tic, Twitter



from TICs y Formación http://ift.tt/1xDbtaZ

via Alfredo Vela Posteado por www.bscformacion.com