Lunchtime listen: NPR on California Voting Machines

As you know, we've been tracking e-voting and the CA story for a while. Today's lunchtime listen is from NPR's Talk of the Nation, August 3, 2007. In this 17 minute segment, NPR interviews Matt Bishop, co-director, Computer Security Laboratory; professor, department of computer science at UC Davis, the leader of the hacking effort of e-voting machines certified for use in CA. His red team was able to compromise the security of all the systems tested! Particularly interesting was his description of "social engineering" which is sort of like phishing in which people are manipulated into performing actions or divulging confidential information. In other words, the *technology* can be easily hacked out of human or social weakness! Continue reading →

Continue Reading →

Increased NSA wiretap powers AND censure resolutions? BOOM!

Can you hear the sound of my head exploding over the intertubes? Anyone got a twist-tie?! First there was the news over the weekend that Congress passed the Protect America Act of 2007 which changes the 1978 Foreign Intelligence Surveillance Act (FISA) and provides new powers to the National Security Agency to monitor communications that enter the United States and involve foreigners who are the subjects of a national security investigation (read the FAQ; listen to analysis from Glenn Greenwald, Marjorie Cohn, and Amy Goodman). But now I just read that Democrats in the House and Senate have introduced resolutions calling for the censure (non-binding of course) of President Bush, Vice President Dick Cheney and Attorney General Alberto Gonzales for misleading the country in pursuing war with Iraq and for undermining the rule of law. How can that be that the same Congress that would give National Intelligence Director Mike McConnell and Attorney General Alberto Gonzales joint authority to approve the monitoring of calls and e-mails, rather than the 11-member Foreign Intelligence Surveillance Court (basically making legal the warrentless domestic spy program) could be the same legislative body that calls for censure of top administration officials including the Attorney General who will have the increased authority to undermine the rule of law?!

[Thanks PS Mueller!] Continue reading →

Continue Reading →

Data Sharing between Agencies: FDA/DOD and VA/DOD

Two stories today on agencies sharing data: 1. FDA, Defense Department Share Data to Enhance Medical Product Safety Reviews http://www.fda.gov/bbs/topics/NEWS/2007/NEW01675.html 2. DOD and VA open a new medical data spigot http://govhealthit.com/article103423-08-03-07-Web In both cases there are clear advantages to sharing the data. In the case of the FDA, they can get access to much larger pools of results on clinical trials and actual use of drugs and medical devices; in the case of the DOD/VA share, doctors will be able to get a better picture of their patients' overall health and care since the VA and DOD populations overlap substantially. One obvious advantage would be the ability to prevent bad drug interactions because doctors would know everything prescribed to their patients. Differences in the two sharing projects are that the first will be designed as a shared structure from the ground up while the DOD/VA project will work with pre-existing systems. Initially, the VA/DOD systems will not be fully compatible across software, but in time the Bidirectional Health Information Exchange (BHIE) program will evolve into Clinical Data Repository/Health Data Repository (CHDR) which will allow direct input/querying/reporting of health data. I think we can assume that breaches of patient data will occur, especially as the data is restructured and/or designed from the beginning to facilitate interoperability. After all, one of the agencies above is the VA. So, are the benefits (well-described data is also more easily published and potentially more easily located data) worth the risk of leaked patient data? Many, many people take multiple medications every day - some which interact, some which have detrimental effects that only become apparent after usage in groups far larger than those included in clinical trials. At the same time, data is lost on a regular basis by many agencies (see GAO's Personal Information: Data Breaches...). Yet, evidence of actual harm from data breaches is limited (although GAO notes that absence of evidence doesn't equal evidence of absence). The GAO report on Personal Information says

For example, more than 570 data breaches were reported in the news media from January 2005 through December 2006, according to lists maintained by private groups that track reports of breaches. ... The extent to which data breaches have resulted in identity theft is not well known, largely because of the difficulty of determining the source of the data used to commit identity theft. However, available data and interviews with researchers, law enforcement officials, and industry representatives indicated that most breaches have not resulted in detected incidents of identity theft, particularly the unauthorized creation of new accounts. For example, in reviewing the 24 largest breaches reported in the media from January 2000 through June 2005, GAO found that 3 included evidence of resulting fraud on existing accounts and 1 included evidence of unauthorized creation of new accounts. For 18 of the breaches, no clear evidence had been uncovered linking them to identity theft; and for the remaining 2, there was not sufficient information to make a determination.
Continue reading →

Continue Reading →

Tough Government Documents Make Librarians Tougher

A coworker tipped me off to a law-lib posting by Brent Johnson about a panel at the American Association of Law Librarians annual meeting that sounds like it was a riot: GD-SIS Program: Tough Librarians Rise to the Challenge with Tough Government Documents Andrew P. Evans gave a talk on Combative and Military Government Documents that offered these citizen benefits to reading military docs:

  • The military’s ability to evolve combat techniques.
  • Real world application
  • Gun and knife safety.
  • Question the techniques- it’s your civic duty
He illustrates the last point with a number of critiques on a hand-to-hand combat manual from civilian martial arts experts. Their advice - some things shouldn't be tried on the battlefield, much less at home! SaraJean Petite shared on Dangers of Open Water Swimming that One Can Avoid, which among other things offered advice to people who row themselves to work as a friend of mine does. Brent Johnson himself presented on National and State Park Government Documents, which he suggested could be of interest to the "Sierra Club, hiking clubs, mountain bikers, rafting groups, and anyone looking for “active rest.”" His presentation started off with finding a park, mapping it, and then showing the different things you can do at a park with each use illustrated with a presumably public domain park photo. What all three presentations had in common is that they brought government documents within the sphere of everyday interest. People these days want to defend themselves, often swim, and usually need somewhere to get away from it all. All three of the librarians figured out to take the eye-glazing subject of govdocs and make it relevant to an audience. Let's give them a hand and think about how we can do the same. Because if we can't make documents relevant, no one will care. Continue reading →

Continue Reading →

Putting the State Agency Database Registry to Work

Now that the 50-State agency database registry has annotated content from most of the fifty states, it is becoming possible to put it to some interesting uses. For example, one can start to explore common state interests by using the search feature of the ALA GODORT wiki. If you do a search for "film" in the wiki, you'll find that New Mexico and Tennessee have film promotion offices that produce databases. Tennessee will help you find locals in almost any category you can think of for your film production. New Mexico has a similar resource, plus they have a location finder database as well. In a similar way, a search using the word "buildings" shows you that Ohio, South Dakota and Washington all have resources to help business choose commercial or industrial real estate properties. What can you discover through browsing or searching the database registry? Let us know in comments. Continue reading →

Continue Reading →

Archives

Powered by WordPress / Academica WordPress Theme by WPZOOM