Visit www.barracudasecurity.com

Legend

Location Of Theft in AQUA BLUE
URL Of Linked Article In STEEL BLUE or GREEN
Full Content Of Article In BLACK
Theft Description In Body Of Article in RED

Friday, February 17, 2006

MASSACHUSETTS COMPUTERS STOLEN FROM BUSINESSES TownOnline.com - Local News: Laptop larcenies on the rise

Watertown Police are investigating the seventh in a string of stolen laptops which have occurred in the past month and a half.

Since late December, seven laptops, valued in total at close to $11,000, have gone missing from area businesses, mainly in Watertown Square.

The latest reported theft was on Feb. 9 at Vayusa Inc. at 85 Main St.

According to police, the $1,300 Compact Presario laptop was left at the office at 2:30 p.m., but when the owner returned, about an hour later, the laptop was missing.

The first reported incident occurred on Dec. 27 at Escort Limousine at 95 Arsenal St. The store manager allegedly left the store at 11 a.m. and returned at 11:35 a.m. to find a $1,000 laptop gone, police said.

Since then laptops have been stolen on a regular basis from Sasaki Associates, Omni Media, Video Link and the US Educational Group.

"We think they're [the thefts] connected," said Watertown Police Det. Lt. Michael Lawn. "Just from witnesses and video surveillance."

Police describe the suspect as a black male, 5 feet 10 inches, with a mustache.

Lawn said police are distributing pictures of the suspect to area businesses.

The suspect enters the businesses with an excuse, Lawn said, telling people he is looking for a job or needs to use the bathroom, but his main focus is to look for unattended laptops.

Lawn said he was unable to speculate why the man is so intent on laptops, outside of the obvious monetary reasons.

Laptop and computer theft is an "ongoing trend," Lawn said, saying similar thefts are taking place all over the country.

Anyone with information is encouraged to call police at 617-972-6500.

Christopher Loh can be reached at cloh@cnc.com.

MISSISSIPPI COMPUTERS STOLEN FROM SCHOOL Clarksdale Press Register

Over $6,500 worth of goods were stolen from an unlocked classroom at Oakhurst Middle School over the weekend.Calls to the school were diverted to Dr. Wilma Wade, superintendent of Clarksdale Municipal Schools, who had no knowledge of the report.

According to police, the grand larceny on the 100 block of West Second Street netted two computers, a window unit air conditioner, a T.V., a musical instrument, two scanners, three VCRs, a digital camera, two printers, a disc player, a camcorder and a boombox.Increased security measures have lessened break-ins at area schools, but police reported this particular classroom was unlocked.Other incidents reported Tuesday included a grand larceny on the 600 block of South State Street. Some money was stolen.An auto burglary was also reported on the 400 block of Mooney. A CD player was stolen

Thursday, February 16, 2006

NEW YORK MOUNT ST MARY'S HOSPITAL COMPUTERS CONTAINING PATIENTS PERSONAL INFORMATION STOLEN 2 On Your Side - News - Mount St. Mary's Warning On Information Theft

Updated: 2/16/2006 6:25:09 PM

Mount St. Mary's Hospital in Lewiston is warning about 17,000 of its former patients that their personal information was on laptop computers stolen in an armed robbery in New Jersey.

Hospital officials sent out letters which advise some patients who were admitted between 2001 through 2004 that data with their names, addresses, dates of birth, and social security numbers was on files in the laptops. But the letter also points out that the laptops and the data files have security passwords which would probably prevent access of the files.

The robbery occurred at the New Jersey office of a national consulting firm which is doing business with Mount St. Mary's and other hospitals. The worker's wallet was stolen along with the laptops by a suspect who was already identified by police. There is a warrant for his arrest.

The hospital is advising the affected former patients to contact one of three credit reporting firms so they can place a free fraud alert on their credit file to prevent any possible identity theft issues. Those patients can also request a free credit report from one of the firms. Those firms are Equifax at 1-800-525-6285 or Experian at 1-888-397-3742 or Trans Union at 1-800-680-7289.

Patients with concerns can also contact the Mount St. Mary's Hospital Assistance Line at 298-2000 Monday through Friday from 10 AM to 3 PM.

VIRGINIA COMPUTERS STOLEN IN 3 STATES The Floyd Press Thieves hit three states: "Thieves hit three states
Computers, cameras taken from Turman's


Roger Mannon
The Floyd Press
Thursday, February 16, 2006


Two men have been charged in a theft spree that covered three states and included four counties. Michael Lee Cline, 22, and Clyde Matthew Stanley, 26, both of Statesville, NC were charged by Carroll County Sheriff Warren Manning."

Cline is now in custody in New River Valley Region Jail. Stanley remains at large. They are charged with thefts from homes and businesses in Carroll, Pulaski, Wythe and Grayson Counties.

One of the local businesses victimized was Turman Log Homes. Ryan Turman said the location on Route 100 in Sylvatus was hit on Tuesday, February 7.

“They took two drafting computers, two lap top computers and two digital cameras,” Turman told the Press. “Apparently they had been driving along the interstate and taking an exit and driving until they found a desolate area with low security.”

After a tip from a Carroll County resident, Cline was arrested in Wythe County Friday.

Several stolen items were found in the trunk of his car. Other stolen items were found in Cline’s residence in Statesville.

Among stolen items that were recovered were tools, firearms, ammunition, U.S. currency, watches jewelry, amps, DVDs, cameras and other items, Manning said.

Turman said his company’s items have not been recovered. “We were fortunate to have some back ups. But it has hurt productivity.”

At the times these crimes were committed, Cline was under bond in Iredell County, North Carolina for armed robbery, and in McDowell County, West Virginia for the same crimes that were committed in Southwest Virginia.

CALIFORNIA COMPUTERS STOLEN FROM SCHOOL School loses computer equipment to thieves - - SENTINEL STAFF REPORT - February 16, 2006

February 16, 2006

School loses computer equipment to thieves

Principal Ian MacGregor hopes he's seen the last of thefts at Cesar Chavez Middle School.

The middle school at 440 Arthur Road has been broken into at least twice in the past two weeks with computers stolen each time, the last time being Sunday, MacGregor said.

Watsonville police arrested three men in connection with the latest robbery after they were seen carrying computer equipment from the building by a First Alarm security guard patrolling a nearby construction site.

Detectives used surveillance video and other evidence to locate the three men and found some of the stolen equipment at their residence in the 300 block of Pennsylvania Avenue, according to Capt. Eddie Rodriguez.

The school has a security system and motion detectors and has upgraded its security efforts since the break-ins, MacGregor said.

"We definitely hope that this is the end of it," he said.

Rodriguez said the Pajaro Valley school district continually faces problems with people breaking into classrooms with computers being the most popular item to steal.

Sheriff's deputies recently made arrests in connection with break-ins at schools in the north sector of the district, he said.

Detectives continue to investigate the other thefts to determine if the three arrested Sunday — Daniel Barron, 20, Larry Najar, 20, and a 17-year-old, all of Watsonville — were involved in the previous break-ins

JAMAICA COMPUTERS PRSENTED TO LIBRARY TO REPLACE COMPUTERS STOLEN PREVIOUSLY Hanover Parish Library Receives Three Computers - Jamaica Information Service

MONTEGO BAY, (JIS):Thursday, February 16, 2006

Three computers worth approximately US$2,500 were presented to the Hanover Parish Library on February 14 by the Trench Foundation, which is based in the parish.

This resulted from a recent Jamaica Information Service (JIS) report, which noted that the parish library, located in the capital, Lucea, was broken into by burglars in July of last year and four computers were stolen.

At that time, Senior Librarian in the Hanover Parish Library, Marvetta Stewart had lamented that the theft had seriously affected the Information Technology services that the library offered to the public.

The Trench Foundation, which was formed in 2005 by the Trench family members, who have roots in the parish, had previously donated cash to the Mount Hannah Methodist Church and the Mount Hannah Basic School in the parish.

The computers were presented by Treisha Trench on behalf of the Head of the Foundation, Dr. Kurt Trench, who lives in the United States.

Miss Stewart told JIS News that the computers could not have come at a better time.

"This gift will go a far way, because it is replacing some of the computers that we actually lost last year, and there is a promise to continue to donate other items to us," she said.

Miss Stewart explained that the Lucea library would now be able to bring back its Information Technology service to a high level.

"The kind of service we offer here is not offered elsewhere, as elsewhere it is just a profit-making thing, but here we give the public a general service. We assist them in all ways possible," she said.

Expressing thanks for the computers, Miss Stewart revealed that there are plans within the Hanover Library service to expand the Information Technology section at the Lucea library to keep up with the great demand for the service.

Hanover has five branch libraries, in addition to the parish library which is located in the capital Lucea, supported by a book mobile service that makes some 42 stops in communities and schools throughout the parish on a regular basis

FLORIDA COMPUTERS STOLEN MiamiHerald.com 02/16/2006 Police Report: "NIXON SMILEY PINELAND PRESERVE AREA

A vandal stole a Dell computer, monitor and rims after breaking into a house through the front door and cutting the phone line and alarm in the 13200 block of Southwest 131st Street between 1:30 a.m. and noon Feb. 5."

A burglar stole a watch, gold rings, computer and camera valued at $2,860 after smashing a master bedroom sliding glass door in the 12900 block of Southwest 218th Street between 6:40 a.m. and 6:50 p.m. Jan. 27.

Five porcelain figurines valued at $1,000, computer equipment, four cellphones, jewelry valued at $3,860 and $1,500 cash were stolen from the 27300 block of Southwest 138th Court between midnight and 4 a.m. Jan. 30 after someone entered the unlocked front door.

NEW JERSEY COMPUTERS STOLEN FROM THREE BUSINESSES Daily Record - Local News - Cops targeting Morristown burglars: " Three businesses at 12 Cattano Ave. on Nov. 26, where coins, digital cameras and computers were stolen."

FLORIDA COMPUTERS STOLEN FROM CONSTRUCTION SITE MiamiHerald.com 02/16/2006 POLICE REPORT: "SUNNY ISLES BEACHA thief broke into a construction site at Trump Colony, 16001 Collins Ave., between 7 p.m. Jan. 30 and 6 a.m. Jan. 31. The thief cut a hole in the construction trailer and took two computers and a drill valued at $375. On the scene, police found a license plate reported stolen from Miami on Jan. 21."

NEW YORK TWO COMPUTERS STOLEN FROM CLASSROOM February 16, 2006 - Two laptops stolen from classroom

February 16, 2006
Two Apple laptops were reported stolen from the Center for Natural Sciences Room 206 on Jan. 28, investigator Tom Dunn said.

Charlie Tilton, a lab specialist in CNS, discovered the theft while checking the pilot physics classroom, said Michael Rogers, assistant professor of physics. The theft took place between Jan. 16 and Jan. 25, Dunn said.

The two Macintosh G4 Powerbooks were valued at around $2,000 each, said Luke Keller, assistant professor of physics.

Rogers said the laptops in CNS were secured to the tables by computer locks, and it appeared the computer locks had been wrenched out of the laptops in order to remove them from the room. Rogers said the computers might have been damaged in the theft.

“They were cabled to a table — you can’t just take it off,” he said. “I haven’t seen a laptop that had the cable forcefully removed from it, but I’d imagine that it would cause some damage.”

One laptop was already stolen from the physics department in the fall semester, Keller said. He said though the laptops are insured, the department will have to pay a $500 deductible for each laptop to be replaced.

The computers were stolen from a pilot collaborative classroom designed by the physics department to be conducive for group projects.

After the January thefts, the physics department removed the laptops from the classroom.

Students who need a laptop will have to check them out from a “secured location,” Rogers said. The computers will be replaced in the lab next fall, and he said the department is “rethinking the security” of the room to prevent further thefts.

Dunn said in the fall semester, several computers belonging to the college worth a total of $7,190 were stolen on campus. One of those computers, valued at $2,500, was recovered.

Before the thefts, the pilot room featured six round tables with laptops attached to them. The finished room will be completed next fall, will be able to hold 99 students and include another classroom and a closet.

Roger said the thefts were frustrating.

“The classroom is being designed for students, for their learning, and now these resources are being taken away,” he said.

Keller said the thefts probably occurred because the classroom is supposed to be kept locked but is used by professors who do not have keys to the room and cannot lock it after their classes.

Any information about the laptops should be reported to Public Safety at 274-3333.

USA MANUFACTURERS MUST RESPOND TO ELECTRONIC THREATS TO THEIR NETWORKS AND DATA RISK FROM INVISIBLE ENEMIES IndustryWeek : Responding To Risk: Invisible Enemies

Responding To Risk: Invisible Enemies Manufacturers must find ways to prevent electronic threats to their networks and data.
By Doug Bartholomew

March 1, 2006 -- Spam. Computer viruses. Network worms. Lost laptops. Stolen handhelds. Penetration of wireless networks by unauthorized users.

Manufacturers have always had security risks, but they could be minimized by taking steps to protect the physical plant and equipment. Today's invader sneaks in unseen over an electronic network and threatens a company's computers, data, and information flows -- ultimately, putting the business itself at risk. What's more, the barriers companies put up to protect against online intruders aren't always effective.

"Most companies put up firewalls in the late 1990s," says Greg Fitzgerald, vice president of marketing at Tipping Point, the security division of 3Com Inc. "But the threats are evolving, and the attacks have continued to get through these technologies." Adds Steve Phillips, senior vice president and CIO at electronics distributor Avnet Inc., "I see many of the same issues and challenges, but the threats have changed."

How are manufacturers coping with this new level of IT risk? Most are beefing up their spending on a host of new technologies aimed at providing more and greater levels of security for networks, servers, desktop PCs, and even mobile devices such as the Blackberry.

Better Security, Higher Productivity

One manufacturer hustling to stay ahead of the IT risk wave is Plantronics, a $560 million maker of headsets. "The world of the network perimeter has certainly changed," says Tom Gill, vice president and CIO at the Santa Cruz, Calif.-based manufacturer that operates plants in Tijuana and Shanghai. "We are very conscious of it, and we're doing our best to protect the enterprise."

An effective security strategy, most experts say, should be fluid, constantly adapting to meet the latest form of e-threat to networks and data while striving to stay a step or two ahead of it. "The manufacturer's goal today is to stay ahead of the attacks by putting a process in place that fixes vulnerabilities before they are exploited," says Mark Nicolett, research director in the information security group at Gartner Group, an IT research firm in Stamford, Conn.

Effective security systems to guard against IT asset risk don't come cheaply, judging from how much corporations are spending on security technologies. Worldwide sales of network security appliances and software hit $1 billion in 2005's third quarter alone, according to Infonetics Research. Virtual private network and financial appliance sales accounted for 77% of the total. Sales of intrusion detection and prevention systems composed 14%, and sales of gateway and anti-virus products accounted for 9%.

Corporations spent an estimated $1.9 billion last year just trying to shore up their e-mail security. Plantronics, for instance, contracts with a hosting service from Postini Corp. that effectively cleanses all of its inbound e-mail of viruses and worms, while eliminating unwanted, intrusive and offensive spam. Messages that have a real business purpose but might have been flagged by the security service are quarantined -- i.e., held for possible later use as requested.

"The result is that our employees have a more productive day, and people are not receiving messages that are inappropriate," Gill says. To keep pace with the shifting security landscape, Plantronics conducts periodic security audits.

One big challenge for manufacturers is balancing the need for IT security against the need that employees, suppliers, and customers have to access and interact with company information. "Our suppliers need to interact with us on how to make our products more manufacturable," says Tony Ciorciari, executive vice president of operations at IGT Corp., a manufacturer of slot machines in Reno, Nev.

To achieve the proper balance between security and access needs, the company depends on the combination of a strong firewall and a sophisticated authentication system to ensure that only those who are granted access to various data are able to get it.

"We do need the proper balance," remarks Rayleen Cudworth, vice president of Information Systems at IGT. "You want the most secure environment to protect your information and intellectual property, but at the same time, you don't want to inhibit the ability of employees to do their jobs."

For e-mail, IGT depends on a pair of staff e-mail administrators to manage the company's filtering software and make sure all incoming e-mail is virus-free. "Right now 80% of the e-mail coming into the company is spam," Cudworth points out. "Managing e-mail can be overwhelming for employees, who otherwise would have tons of spam, which is neither productive nor safe."

Monitoring Remote Devices

Managing remote use of company information via networks and the Internet poses another potential risk. For remote access, employees connect using an IGT laptop only. Remote access cards enable employees to connect with secure authentication. For handhelds, remote workers use Blackberrys that are password protected. All remote connections must go through the company's firewalls. Finally, to provide an additional layer of protection for home access, the company sets up personal firewall devices in each mobile worker's home.

On the company's production lines, hundreds of workers use handheld wireless devices for various operations. Each device communicates with the network using an industrial-strength data encryption system. "There are eight steps a worker has to perform to do a transaction," Cudworth says. "We are very tight on security when it comes to the wireless technologies." Adds Ciorciari, "That encryption protection is very critical to our operations."

As far as staying ahead of the risk curve, IGT performs regular security audits and is constantly on the lookout for weak access points. "We have to stay ahead of the game," Cudworth says.

All-Encompassing Approach

Some large manufacturers are taking a more offensive tack toward tracking down potential security problems that could arise on their networks. Toyota Motor Europe is a case in point. The company is using 3Com's Tipping Point Intrusion Prevention System to assess whether network traffic is posing any threat to undermine the system's availability or confidentiality. The system uses network devices to provide detailed analysis of the network's status with almost no delay, a capability not available just a few years ago.

"Any network traffic that is going to pose a security problem is just blocked," explains Richard Cross, corporate security officer at Toyota Motor Europe in Brussels. "It's just as if the network traffic is purified before it passes on to our networks -- attacks are blocked and prevented from spreading. We just get the reports about how much. It's simple and effective, but we don't trust anything to be foolproof."

The notion of setting up layers of security, in fact, instead of relying on a single firewall or a lone preventive system, is widely accepted as the only way to go. "In Sun's view of systemic security, the goal is a reinforcing security architecture," says Glenn Brunette, distinguished engineer and chief security architect at Sun Microsystems, a leading manufacturer of computer servers and workstations. "That way, if you experience one point of failure, you are still protected."

Sun recommends to its corporate customers that they adopt a policy that everyone on the outside of their network is "untrusted" until it's proven otherwise. "You can keep certain user communities away from your IT infrastructure, but still provide services such as portals that will connect them," Brunette explains. "This way, you are not providing them with total access to your network."

In other words, while a key customer could be allowed access to check basic information regarding the status of a shipment, a different set of rules and access requirements would be needed to cancel a shipment.

Not surprisingly, most computer hardware and software vendors have beefed up the security capabilities of their products. Dell, for instance, has embedded support in most of its consumer and notebook computers for an optional security package called Computrace from Absolute Software, which enables customers to protect sensitive data and recover lost or stolen machines. Most Dell business notebooks such as the Latitude and Dell Precision mobile workstations also include an integrated Smart Card reader.

Similarly, Sun's Solaris 10 operating system has a variety of security features built in. Likewise, software firm Novell's Zen network management suite of applications includes security for authentication purposes for servers, desktop machines and mobile devices.

"People seem to lose PDAs the most," notes Justin Taylor, chief strategist for digital identity and security at Novell's engineering center in Provo, Utah. Novell's Zen system for handhelds enables companies to disable or wipe a PDA clean of all data if the security authentication is not completed correctly within three tries.

Despite all these efforts, the best technologies by themselves aren't enough to reduce the level of risk facing most IT infrastructures. Employees have to do their part as well to make the technologies effective. "We have found that people sometimes do not understand the relevance of security to their job or the role they play in making company security effective," says Sun's Brunette. "Everyone needs to understand how to protect information, both company information and customer information."

Brunette recalls an incident involving a customer who called in a panic regarding a system outage. A disgruntled systems administrator had quit, leaving behind a "time bomb" that would erase the discs at 180 company servers all at once. "A single person destroyed their entire environment, and the company didn't even know who it was until they did an investigation," he says. "This organization had failed to have a security administrator whose role is to monitor all actions being taken on the system."

The company also failed to have an effective backup and disaster recovery system in place in the event of such a failure. Having these kinds of checks built into the system is a basic security management issue, not a technological one. "Someone could have noticed, through basic audit controls, that this person had made these changes to the system," Brunette adds.

One company that monitors all activity on its company systems is Avnet Inc., a $13 billion distributor of electronic components and computers. "We have a dedicated director of IT security, and we monitor our systems 24/7, looking for any unusual activity across all platforms," says Phillips of Avnet, which is based in Phoenix. "If we get updates or patches for our systems from the software vendors, we track our ability to apply those patches in minutes."

IT asset risk, of course, also extends to the natural realm, where earthquakes or weather-related catastrophes can wreak havoc on a company's systems and ability to do business. "You need to make sure that if a disaster happens in one of your operational hubs, that you know what to do," Phillips says. "Our systems are able to recover to a failover system, and we can resend data messages to our trading partners."

Production Floor Challenges

With the advent of the Internet, manufacturers have had to come to grips with a new risk -- the systems on the production floor. While in the past, these systems were self-contained, today many production control and other shop-floor systems are connected to the company network and the outside world.
"As manufacturers upgraded their equipment and systems on the shop floor, they were more likely to have network connections and to be remotely controlled," observes Gartner's Nicolett. "That exposes the production line in a way it hasn't been exposed in the past."

"Process control networks used to be running on their own, but not any more, and this new connectivity brings with it some vulnerabilities that our other systems have," agrees Rich Mogull, research vice president in the information security and risk group at Gartner Group.

Mogull suggests manufacturers avoid intermingling the process control system with other networks that are more exposed to the outside. "Manufacturers have the option to keep their process control system separate," he says. "We do not recommend giving a manager a desktop machine to do e-mail while that person is managing the production network, because one slip up and you can give somebody outside the company control of the system."

Another way to limit the risk of a process-control system intrusion is to lock it off from the rest of the network with a "virtual air lock." In effect, this means placing a third system in the middle that allows one-way-out flow of communication for data reporting. "That way, you have no communications coming into the system from the outside," Mogull says.

WISCONSIN COMPUTERS STOLEN FROM BUSINESS JS Online:Milwaukee County Police Report - South: "FRANKLIN
Burglary
Someone tried to pry open the door at We Energies, 4800 W. Rawson Ave., between 11 p.m. Feb. 7 and 7 a.m. Feb. 8. A magnetic lock prevented entry. We Energies has reported several other burglaries to other properties, in which someone took copper, aluminum and laptop computers. "

Wednesday, February 15, 2006

NIGERIA COMPUTER SECURITY AND WEAPONS FOR CYBER CRIME PREVENTION The Tide Online: "Weapons for cyber crime prevention
Wednesday, Feb 15, 2006
During the out gone week, the headquarters of the Corporate Affairs Commission (CAC) Abuja announced that Information Technology would begin to propel the activities of her operations.Incidentally, I was in Abuja for most of the week, where I was a regular visitor to the commission's headquarters in Wuse, zone 5.

What this development means is that the CAC has opened its doors to online registration of companies in Nigeria, thereby making a journey to Abuja for that purpose unnecessary. And as with most online services, this will be available 24 hours a day, and 7 days a week. Many people will hopefully take advantage of this opportunity and undoubtedly, Cyber criminals will think in the same direction as well; cracking their brains on how to break into such networks and wreck unimaginable damage.

This is because the Internet is an Information Super Highway and as with all highways, the good, the bad and the ugly ply along those routes at varying speeds and with separate motives. Anyone who gets on the highway unmindful of others might just get crushed. The same scenario is also applicable to the Information Super Highway.

This is where computer security readily comes into Focus. Last Wednesday on this column, I had x-rayed cyber crime and how it is perpetrated, with a promise to present security options available to computer users.

Computer Security comprises of some techniques developed to safeguard information stored on PCs. Computers and the information they contain are often considered confidential systems because their use is typically restricted to a limited number of users. But this confidentiality can often be compromised in a variety of ways.

For example, hackers violate confidentiality by impersonating authorised users of computers in order to gain access to the users’ systems. They invade computer databases to steal the identities of other people by obtaining private, identifying information about them. Cyber criminals also engage in software piracy and deface Web sites on the Internet.

But the most serious threats to the integrity and authenticity of computer information come from those who have been entrusted with usage privileges and yet commit computer fraud. For example, authorised persons may secretly transfer money in financial networks, alter credit histories, sabotage information, or commit payroll fraud. Modifying, removing, or misrepresenting existing data threatens the integrity and authenticity of computer information.

Malicious hackers are increasingly developing powerful software crime tools, such as automatic computer virus generators, Internet eavesdropping sniffers, password crackers, vulnerability testers, and computer service saturators. For instance, an Internet eavesdropping sniffer intercepts internet messages on traffic. A password cracker tries millions of combinations of characters in an effort to guess a users password. Vulnerability testers look for software weaknesses. These crime tools are also valuable security tools used for testing the security of computers and networks.

In fact, it would be difficult to count all of the spam sent across the Internet each day. Some experts estimate that more than seven hundred million spam messages are sent around the world each day. Some experts say more than half of all e-mail sent is spam. This has gradually become a major problem for a lot of computer users. Many angry people have begun to fight back. Among these are private citizens, Internet service provider companies and even governments. The federal government is also considering a bill to check computer and internet related crimes. This bill known as the Cyber crime bill is now before the National Assembly, and has received inputs from the Economic and Financial Crimes Commission EFCC.

Meanwhile, a variety of simple techniques can help prevent computer crimes, such as protecting computer screens from observation, keeping printed information and PCs in locked facilities, backing up copies of data files and software, and clearing desktops of sensitive information and materials. Increasingly, however, more sophisticated methods are needed to prevent computer crimes. These include using encryption techniques, establishing software usage permissions, mandating passwords, and installing firewalls and intrusion detection systems. In addition, controls within application systems and disaster recovery plans are also necessary.

Storing backup copies of data and having backup computers are important basic safeguards because the data can then be restored if it was altered or destroyed by a computer crime.

Another technique to help prevent abuse and misuse of electronic data is to limit the use of computers and data files to approved persons. Security software can verify the identity of users and limit their privileges to use, view, and alter files. The software also securely records their actions to establish record of usage.

Passwords are confidential sequences of characters that allow approved persons to make use of specified computers, software, or information. To be effective, passwords must be difficult to guess and crack. Effective passwords must not be less than 7 characters, which must also include not only alphabets, but also numbers and symbols. To thwart imposters, computer systems usually limit the number of attempts and restrict the time it takes to enter the correct password.

Firewall protects computers that are linked to a network. Computers connected to the Internet, are particularly vulnerable to electronic attack because so many people have access to them. The firewall actually examines, filters, and reports on all information passing through the network to ensure its appropriateness.

Generally, organisations and businesses that rely on computers need to institute disaster recovery plans that are periodically tested and upgraded. It should also be noted that no security system is totally safe if the individuals managing it fail to enforce the measures that ensures its safety.

UK SECURITY SYSTEMS FOR HAND HELD COMPUTERS Security systems for handheld computers: "Whilst many educators are in favour of the concept of providing 1:1 ICT access on a 24/7 basis there have been some concerns put forward about the possible security issues around every child or student having one. There's already been a lot of discussion in the media about mobile phone theft so could we be facing a future potential problem if every student has a bling bling handheld computer?

Ideally there would be away of making a stolen or lost device completely useless once out of the hands of its rightful owner thus making theft pointless. However any software solution on current devices would be overcome by a simple hard reset, so manufacturers interested in providing devices for the education sector might want to agree on a security standard and then build this into the firmware.

There's an interesting article on Techworld.com that discusses some of the issues and possible solutions:"

ARIZONA COMPUTERS STOLEN FROM NON PROFIT ORGANIZATION Records, clothes stolen from Navajo non-profit: "The Arizona Republic
Feb. 15, 2006 12:00 AM

CENTRAL PHOENIX - A burglary is a major and upsetting event for anyone, but for the newly established Phoenix Dine organization, a weekend burglary was something of a catastrophe.

Phoenix Dine Director Melinda Tomchee said the year-old organization serves as a resource center for the estimated 25,000 Navajos (Dine) who live in the Valley.

The non-profit organization helps Navajo folks find jobs, scholarships and public assistance, and it also serves as a cultural center.

But when Tomchee walked into the office at 802 N. Fifth Ave. in Phoenix on Monday morning, she says she knew "that a lot of our work was going to be on hold for a while."

Tomchee saw that burglars had stolen a small safe with records inside, three desktop computers, a laptop computer, four printers, one video recorder, a digital camera and a projector and sound system used for PowerPoint presentations.

"We haven't backed-up our computer files for about two months, so a lot is probably lost," Tomchee said. "We were just getting ourselves really organized, and this is a considerable setback."

Cultural activity coordinator Suzette Numkena said losing the computers and their records was bad enough, but losing 20 bags of clothing recently sent by the Navajo Nation perhaps was in some ways worse.

Insurance will cover most of the electronic wares loss, "but we have families with small children who were expecting and needing the clothing this week," Numkena said. "We have to tell them it's just gone."

Tomchee said she and her board of directors are "absolutely determined" to get the center up and running again soon.

"Not only do we have many Navajo people living here now, but we will have many more in the near future," she said. "With unemployment at 42 percent on the reservation, young people are leaving and going to urban areas at an increasing rate. They are looking for new economic and employment opportunities.

"We not only act as a resource for jobs and things like that, but we are also their tie to their culture, to their language, to things that must not be lost."

Police had made no arrests in the burglary case as of Tuesday evening.

Anyone wishing to provide assistance to Phoenix Dine can call (602) 254-2891.

WISCONSIN RECENT COMPUTER THEFTS FROM BUSINESSES MAY BE RELATED The Sheboygan Press - Computer thefts may be related: "Posted February 15, 2006

Computer thefts may be related

Sheboygan County Sheriff's Department investigators believe that recent thefts of laptop computers and other equipment from businesses here are related to other business break-ins in Saukville, Grafton, Port Washington, Manitowoc and Green Bay.

'It seems to be related to the I-system (Interstate 43),' Detective David Obremski said Tuesday.

Twenty-four or more laptop computers, a video projector, a digital camera and computer software were reported stolen Feb. 6 from Earth Tech at 4135 Technology Parkway, according to the sheriff's department. The same day, four laptop computers, each valued at $2,500, were reported stolen from Aero-Metric Inc. at 4020 Technology Parkway.

Seven other businesses, five in the City of Sheboygan and two in the Town of Sheboygan, reported similar thefts Jan. 23.

A laptop computer valued at $1,600 was reported stolen Monday from Lakeshore Fleet Maintenance at 4024 Highway 42 in the Town of Sheboygan, Obremski said. The sheriff's department is unsure if that theft is related to the others. "

Tuesday, February 14, 2006

UTAH OVER 20 COMPUTERS STOLEN FROM SCHOOL The Spectrum, St. George - www.thespectrum.com -: "Over 20 computers stolen from elementary school
By BRIAN PASSEY
bpassey@thespectrum.com

ST. GEORGE - A burglar stole more than 20 computers from the computer lab at Bloomington Hills Elementary School during the weekend.

Sgt. Scott Lemmon, of the St. George Police Department, said the head custodian at the school notified police of the missing computers at about 6:30 a.m. Monday. Lemmon said there is no sign of a forced entry and detectives processed the scene, which included collecting fingerprints on several items."

Lemmon said there are no suspects at this time, but police still are investigating and ruling out people with access to the building during the weekend and their associates. The burglary occurred between Friday and early Monday morning, he said.

At least 20 white Apple Macintosh computers are missing. School officials still are compiling an inventory to determine the number of missing items and their total value.


Police are asking residents to watch for white Apple Macintosh computers with stickers on them indicating they are the property of the Washington County School District or Bloomington Hills Elementary School.


Lemmon said the school did not have any type of video surveillance.


"It would be nice if all the schools were able to be equipped with this type of technology to assist in investigations," he said.

UK COMPUTERS STOLEN FROM SCHOOLS Midland Daily News - News - 02/14/2006 - 18 computers stolen in school break-ins

Midland Pubic Schools students are short the use of 18 computers after three recent break-ins at school buildings.

Midland Police are investigating the crimes, which occurred at Parkdale Elementary School, 1609 Eastlawn Drive, Midland High School, 1301 Eastlawn Drive and Plymouth Elementary School, 1105 E. Sugnet Road.

At Parkdale, two computers were stolen, and the cost of replacing broken windows is estimated at $750. One computer was stolen from Midland High, though police officers found items including computer speakers, a monitor and a computer processing unit were moved from their original places in a computer lab and left near a broken window.

The Parkdale break-in was discovered early Saturday morning, and the Midland High break in was found at 7:17 a.m. Sunday. The most recent break in occurred at Plymouth Elementary, and was reported at 6:51 a.m. Monday.

In that case, officers determined the suspects tried to use a window planter to break a window, then found a log in a nearby wooded area. After breaking the window and entering the school, a pipe from a custodian's office was used to break an interior window.

Fifteen laptops were stolen from a computer cart which sustained $100 damage. The estimated cost of window replacement is $145.

The total value of the stolen computers is $19,050.

FLORIDA GOVERNOR WANTS TO GIVE 164,000 TEACHERs NEW COMPUTERS Ocala.com Star-Banner Ocala, Fla.

Feb. 14, 2006,
A laptop on every desktop?

Instead of buying 164,000 new computers - that can get broken or stolen or, sooner than later, outdated - why not simply upgrade existing classroom computers?

Gov. Jeb Bush wants to give each of Florida's 164,000 public schoolteachers a brand new laptop computer as a part of his legislative proposal to recruit and retain high quality teachers.

Overall, the $239 million recruitment and retention plan the governor unveiled last month appears to be a solid step forward for a state where teachers' salaries currently rank 29th among the 50 states and lag the national average by some $6,000 a year. Much of the initiative is worthy, including: bonuses for teachers in high-demand subject areas like math and science; $40 million to spread among the 67 school districts so they can recruit more aggressively; $8 million to reimburse teachers in critical areas up to $10,000 for student loans or to defray the cost of additional education courses; and, implementation of an "education minor" at the state's universities that would allow non-education majors to become certified to teach.

Using such techniques to find and keep good teachers is both logical and overdue. After all, Florida is expected to need nearly 32,000 new teachers for the 2006-07 school year alone.

What gives us pause, though, is the governor's push to put a laptop on every teacher's desk, an initiative dubbed T3, for Technology Tools for Teachers. We are unconvinced the need for these computers is great enough to warrant spending $188 million, or 78 percent of the total recruitment and retention package budget. Every classroom in Marion County, for instance, has at least one teacher's computer. The National Education Association reports that Florida, while near the bottom in too many educational categories to count, is actually a leader in classroom technology, providing one classroom computer for every 6.7 students. That puts it among the top 15 states.

Laptop proponents say the computers would allow teachers direct access to Sunshine Connections, a web-based system that links teachers to student data, curricular materials and other educators.

The laptop initiative, however, has not been embraced by teachers' or administration advocacy groups. Instead of new computers, what they say they need is less paperwork that steals time from teaching and lesson planning.

"It is a real problem and real drain on teachers, but I've always found that every time I get an upgrade of technology, my workload doesn't get easier," Mark Pudlow, spokesman for the Florida Education Association, told the Miami Herald. "It's kind of a Band-aid, a little gimmick that he's using to sell teachers on this."

The $188 million, anticipated revenue from Broward County's not-yet-operating slot casinos, could be more efficiently used. Instead of buying 164,000 new computers - that can get broken or stolen or, sooner than later, outdated - why not simply upgrade existing classroom computers? That would leave state education officials with a remaining windfall that could be used for sorely needed teacher training, first in reading, then in, yes, how to optimally use those computers already on their desks.

Marion County Superintendent of School Jim Yancey says our teachers would benefit far more from being paid the $1,100 the state will spend on each laptop to attend three days of intensive training to make them better reading instructors. We tend to concur with the superintendent. It would, at the same time, boost teachers' pay. It's called a win-win.

There is plenty of time to tailor Gov. Bush's recruitment and retention program to suit the needs of Florida's 67 individual school districts. As the governor himself said of the teacher shortage, "It's not a one-size-fits-all problem, so the solution can't be one-size-fits-all." We agree.

Substantially enhancing Florida's toolbox for recruiting and retaining schoolteachers is a timely undertaking that should pay dividends long term. We question, however, if buying 164,000 laptop computers is really the most effective way to meet this critical public education need. We suggest there are better ways to enlighten our teachers about the wonders of Sunshine Connections and its computerized curriculum without spending $188 million on new computers. And with our way, we can put some extra money in teachers' pockets to boot.

US TOP LAW FIRM ADDS DESKTOP AND LAPTOP SECURITY MANAGER TO COMPUTERS Security Park - Top 100 Law Firm Selects Chooses ControlGuard Endpoint Access Manager to Secure its Desktops and Laptops: "Top 100 Law Firm Selects Chooses ControlGuard Endpoint Access Manager to Secure its Desktops and Laptops

ControlGuard, an Israeli provider of enterprise-grade endpoint security solutions, has announced that Duane Morris LLP, one of the largest 100 law firms in the United States, has selected Endpoint Access Manager to manage the secure use of removable media and portable devices for its more than 1,350 lawyers, legal professionals and staff.

Duane Morris realized that commonly used removable media and portable devices, like thumb drives, CDs, iPods and cell phones, are vulnerable to a wide array of security threats. With the rise of data theft scandals plaguing corporate America, Duane Morris did not want to take any chances. The law firm selected ControlGuard to secure the use of portable devices.

ControlGuard's Endpoint Access Manager allows Duane Morris to centrally control, monitor and record how data is uploaded and downloaded from removable media and portable devices to desktop and laptop computers. Unauthorized transactions are blocked, monitored and communicated in real time to management consoles. The solutions shield networks from malware copied to endpoints and secure networks from exposure to the outside world through wireless modems, WiFi, Bluetooth and other interfaces.

"Being one of the country's top law firms, Duane Morris deals with a large amount of very sensitive data," said John Sroka, CIO at Duane Morris. "Securing the data and preventing information leakage is high on our priority list. ControlGuard's technology enables us to manage the use of removal media and block unauthorized access."

"Law firms must be vigilant to protect the sensitive data stored in their IT systems,” said Israel Levy, CEO at ControlGuard. “Being a forward-thinking organization, Duane Morris took proactive steps to secure their endpoints by implementing ControlGuard’s solution.”

US USB STICKS AND iPODS REMAIN A THREAT IN THE WORKPLACE Security Park - USB sticks and iPods remain a threat in the workplace: "USB sticks and iPods remain a threat in the workplace

Organisations are ignoring the impact data theft can have on the business. Companies should react quickly to stop confidential information from being stolen in minutes by an employee or visitor armed with a USB stick and a motive.

Security expert Abe Usher highlighted this threat by developing a data theft tool called slurp.exe. Capable of copying thousands of document files from a computer to an iPod in less than two minutes, the virus-style programme from IT consultancy Sharp Ideas was specifically designed to demonstrate the threat posed by portable storage devices such as USB sticks and iPods. Usher, the founder of Sharp Ideas LLC, used Centennial's DeviceWall to test PCs exposed to Slurp. The software defeated the programme, heralding an alliance between Centennial and Usher.

"Data theft has become a huge concern within corporations worldwide," said Usher. "Centennial DeviceWall proved to be a foolproof solution for preventing the inappropriate usage of portable devices in a network environment. It was very easy to set up and once running, completely blocked devices running Slurp Audit."

As part of Centennial's R&D process, it has worked with Sharp Ideas to create Slurp Audit, a version of Slurp that produces a list of unprotected documents with their filenames and paths. The audit shows users how easy it would be to copy large amounts of data via the USB port and other connections, wired and wireless.

"Data theft has become a huge concern for corporations worldwide, yet they are still leaving themselves exposed by not controlling the wide range of portable media devices being brought in the front door," said Andy Burton, CEO of Centennial Software. "Slurp Audit demonstrates key weaknesses in corporate network security. Any company wanting to see first-hand how vulnerable their data is can visit our website and download it for free.” "

US/EUROPE SPECIAL REPORT: IT SECURITY AND BASEL II COMPLIANCE Security Park - Special report: IT Security and Basel II compliance

Financial Services Institutions (FSI) IT security spending represents between 24-26% of all enterprise IT security spending. Legislation and regulations such as Sarbanes Oxley, Gram Leach Bliley and Basel II will continue to drive a strong uptake of IT security solutions among FSIs.

Enterprise IT security solution providers are increasingly citing regulatory compliance as one of the key drivers for their solutions. Within Europe, Basel II has been highlighted as the most important regulation among FSIs. This special report looks at why Basel II may increase expenditure on IT security and how best to exploit this opportunity.

Most enterprise IT security solutions will help FSIs reduce their operational risk provided that the solutions are correctly integrated, configured, maintained and managed. The main focus will be on a few areas: Monitoring, detection and surveillance, information management and data security, and risk assessment solutions.

This special report on IT Security and Basel II compliance:
- Identifies areas where Basel II will affect IT security spending among FSI, and gives action points for enterprise IT security solution providers.
- Looks at the overall operational risk spending (Basel II and SOX) of US vs. Europe from 2002-2006, and identifies other regulations that concern operational risk.
- Identifies areas that most enterprise IT security solutions will help FSIs reduce their operational risk.

This IT Security and Basel II compliance special report investigates ways in which solution providers can position their offerings as an integral part of the overall Basel II compliance framework.It also investigates other factors that will increase operational risk expenditure among FSIs in other regions such as the US. Importantly, it provides easy-to-understand steps for risk management where successful solution providers can build a framework that FSIs understand and position offerings.

Table of contents:
- 4 key things you need to know about how Basel II will affect IT security spending among FSIs
- Solution providers must be able to position their offerings as an integral part of the overall Basel II compliance framework
- Solution providers must assist FSIs in creating effective risk management lifecycles and in doing so demonstrate their understanding of what is required to meet regulatory compliance
- Solution providers must understand which elements of their products and services portfolio meet the client's specific needs
- How enterprise IT security solutions can help
- While the majority of Basel II spending will be seen in Europe, other operational risk activities will make the US a more lucrative market
- SOX and operational risk
- Other regulations

Monday, February 13, 2006

CALIFORNIA RSA CONFERENCE 2006; BOOM TIMES FOR SECURITY RSA confab: Boom times for security: ZDNet Australia: News: Security

The security industry converges at the annual RSA Conference in San Francisco this week, an event that's moved far beyond its origins as a get-together for cryptogeeks and other insiders.

Though still organised by RSA Security, a company with its roots in cryptography, the confab has developed into a showcase for security companies and an annual gathering for IT professionals. This year is the 15th anniversary of the event.

"There has been significant growth," said Ray Wagner, an analyst with Gartner. "The RSA Conference four, five years ago was much more of a technician conference."

The changing face of the conference mirrors a growth in concern over security in companies large and small. Once just an extra task for an IT manager, a digital breach may now bring legal entanglements for organisations. That's one reason why concern over security has moved into boardrooms.

Driving that increasing concern is a rise in threats such as armies of zombie PCs, higher awareness of data security dangers, and a need to comply with data protection laws.

With security now printed in bold on many corporate agendas, a plethora of new companies have sprouted up to sell products. At RSA, more than 275 exhibitors will show their wares. Product announcements at the show run the gamut and include application security software, e-mail security appliances, antivirus software and encryption technology.

Charles Kolodgy, an analyst at IDC, said: "The security market is as active as I have seen it in a long time. There seems to be something for everyone."

Many of the new vendors who jumped into the market are looking to cash out, often by being acquired by a larger player. Analysts have said that some of the security start-ups deal in features, not products, and essentially exist to be taken over.

And while new players continue to enter the space, takeovers are common. Symantec, in particular, has gobbled up many small security companies. Executives at the Cupertino, California, company said last fall that they plan to make six to eight acquisitions per year, with a major deal -- such as Symantec's buy of Veritas Software -- about every 18 months.

full article AT WEBLINK...............

US THE NEXT FRONTIER IN COMPUTER SECURITY:FINGERPRINTS The next frontier in computer security: Fingerprints: "The next frontier in computer security: Fingerprints
Michael Totty
Wall Street Journal
Feb. 13, 2006 12:55 PM

Is it time to ditch all those hard-to-remember passwords for something that's impossible to forget and hard to lose?

Passwords are the first line of defense in keeping intruders out of corporate computer systems, and companies are getting more stringent about keeping them safe. They're insisting that employees use 'strong' passwords - at least six characters, using a mix of numbers and letters - and that they change them more frequently. But the sheer number of codes is a real headache for users and a productivity drain for companies, as computer-support staff face loads of calls about forgotten passwords.

'People can't remember log-in names. People can't remember passwords,' says Jarad Carleton, an analyst with Frost & Sullivan, a technology consulting firm in Palo Alto, Calif. 'There are just too many of them.'"

Companies have tried alternatives, such as smart cards or security tokens that generate a constantly changing string of numbers that can be used to replace set passwords. These work well enough, though they can be lost or left behind when traveling. So some companies are turning to a solution that's always at hand: fingerprints.

A person's "biometrics" - unique physical characteristics such as fingerprints that can be used for identification - have been used in high-security situations for a long time. San Francisco International Airport installed hand-geometry readers to control access for employees in the early 1990s. A hospital in Bavaria, Germany, uses iris-scanning technology to limit admission to its neonatal station.

But biometrics has been slow to make headway for day-to-day business uses. Part of the problem is that biometrics readers have been expensive - fine for locking a few doors but too costly to place on every computer in an organization. Smaller and less-expensive sensors were available, but users complained they were unreliable.

In the past couple of years, though, fingerprint scanners and the necessary software have become cheaper and more reliable, and have begun showing up on desktop and notebook computers. So far, the technology is found mostly among leading adopters, like health-care and financial-services companies. But, security experts say, if they're used properly, fingerprint log-ons can be easier to use and more secure than passwords. Using fingerprints to verify a computer user's identity, Mr. Carleton says, "is a technology that is ready for prime time."

Lenovo Group Ltd., which last year bought the PC operations of International Business Machines Corp., says it has sold more than one million laptop computers with built-in fingerprint readers since it began offering the product in October 2004. Ten-year-old Digital Persona Inc., of Redwood City, Calif., boasts 25 million users of its fingerprint systems, which use a plug-in reader about the size of a small computer mouse.

To be sure, not everyone is convinced. Peter Schwartz, chairman of Global Business Network Inc., an Emeryville, Calif., consulting firm, says he disabled the fingerprint reader on his new Lenovo laptop after he couldn't sign in when trying to make a presentation before 300 people. "It's not ready for prime time," Mr. Schwartz says. (Lenovo says that you can expect to get falsely rejected only three times in 10,000, assuming that in some cases it might take three tries to log in successfully.)

What's more, these systems don't eliminate passwords entirely; they just fix it so you don't have to type them every time you log on. Users first create passwords for their computer and store them in one central management program. Then they set up the fingerprint system by sliding their fingers over an optical scanner - either built-in or attached - which converts the image into a unique mathematical formula that represents the fingerprint.

After that, every time users scan their fingerprint, the computer unlocks the password manager and the required password is entered automatically. Besides making sign-ins more convenient, fingerprint systems also make it possible to create much stronger passwords, with 20 or more random characters, that would otherwise be impossible to remember.

As is often the case with technologies just beginning to break out, fingerprint readers are being rolled out in settings where they can have the biggest effect. Sisters of Mercy Health System, a Chesterfield, Mo., health-care organization, began testing fingerprint readers in the emergency department of one of its St. Louis medical centers in July 2005. It now has about 40 devices in the emergency department and another 40 in administrative offices.

In the emergency department, where several physicians and nurses share the same PC, it was too time-consuming for individual users to log on and off every time they needed to pull a patient record or other information. But that meant that records could be viewed by people who didn't have authorization - a potential violation of a federal law that protects patients' medical information.

The fingerprint readers are used in combination with identification badges. When, say, a doctor approaches the station, the computer recognizes her badge and automatically logs her in, using a system put together by Sentillion Inc., of Andover, Mass. The doctor then verifies her identity using the fingerprint reader. If the doctor then leaves the computer, the machine senses this and automatically logs her out. What's more, if she left any files open on the screen, the machine will remember and open them automatically the next time she logs in.

Mick Murphy, the hospital system's chief technology officer, says that with the old system, it took almost five minutes to access a particular record, but that has been cut to about a minute. "It lets clinicians focus on patients" instead of computers, he says.

Another common use for fingerprint scanners is locking down portable devices, such as notebook computers and PDAs. Concentra Inc., a manager of occupational health services in Addison, Texas, last year began testing about 400 fingerprint-enabled laptops from Lenovo among its mobile case managers, and so far has found that the systems make logging in a lot faster and easier. Users can access the computer and any other protected programs just by sliding their finger over the built-in reader to unlock the required password. "For the people who use it, it's indispensable," says Laura Ciavola, Concentra's chief information officer.

UK CHANCELLOR GORDON BROWN'S SPEECH ON TERROISM Guardian Unlimited Politics Special Reports Gordon Brown's speech on terrorism:



WEBLOG EDITOR'S Note: This FOURTH part of the speech included below deals with IDENTITY THEFT

FOR Full text of the speech given by the chancellor to the Royal United Services Institute in London go to weblink........

"Identity

Fourth,
the requirements for security in identity. There is a common thread running through the new security challenges - and that is the growing importance, and the obvious vulnerability, of identity. The risk to me and you as individuals is that our identities are stolen for terrorist or other reasons and used against us and what we stand for. The risk is also that, using false identities or without proper investigation of who they are, people enter and abuse our country.

This matters in Britain when we know that as many as one in four criminals use false identities and that as many as one in five companies could be hit by identity fraud.

The economic and social cost of identity fraud is into the billions of pounds and growing, with a new estimate from the Home Office of ?1.7 billion.

Just as we have been facing new threats and evolving new responses in national and international security, analogous developments in the private sector - in banking and finance - to ensure the protection of consumers identities show both the need for and the opportunity to change.

Already we have moved on from signatures to requiring, as from tomorrow, a PIN for all debit and credit card transactions. And by 2010, according to the forecasts of Bill Gates, people will, through biometrics, access their phone, email, computer, and bank - through a fingerprint touch of a screen anywhere in the world.

Already one million people have bought and use an IBM laptop which uses fingerprint recognition to control access - and for the future, manufacturers are looking at the same fingerpint recognition technology to make mobile phones and MP3 players worthless if stolen. Today Californian supermarket shoppers are paying with a finger-scan at the checkout new schemes mean people can pay for their goods just by placing their finger on a scanner and without having to carry a card; and Japanese cash machines are asking for a finger-scan rather than a PIN."

The reason is simple: they are more secure against fraud and theft. And across the world in very different cultures most people seem happy to use biometric schemes when they see direct value in greater security, greater convenience, and lower cost.

So it is likely in future that a supermarket or bank may hold your biometrics, but at the moment those charged with the protection of your security - indeed the people who can actually protect your security - do not. As a customer you would, under the private sector initiatives being developed, have biometrics stored, but as citizen you would not.

So the issue is not whether advances in biometrics are being put to use - identity information about us to protect our security is being given voluntarily to credit card and computer companies to safeguard access to finance and computers and now being used also for employment and employee recognition. For example, biometrics are increasingly being used to control access to buildings with particular needs for security. And with passports now requiring biometrics, a necessity people understand, 80 per cent of the adult population will have to register their biometrics to ensure our borders are secure and so they can travel freely across the world. In each case safeguards must be built in to protect misuse of information.

So the question is whether we move to the next stage - to extend this system from the private sector and the borders to a national biometric scheme including an identity card.

And would most people not agree that if there are acceptable safeguards to protect civil liberties in these areas, there are advantages in a national identity scheme that could not just help us disrupt terrorists and criminals travelling on forged or stolen identities - but, more fundamentally, protect each citizen's identity and prevent it being forged or stolen?

The advantages are clear. An identity scheme will not just make the necessary security checks easier for all of us as we travel abroad for our work and leisure, but prevent people already in the country exploiting your identity or mine, and using multiple identities for terrorist, criminal or other purposes. One of the central features of terrorists' activity is their use of multiple identities to avoid laying tracks or patterns for us to spot. One September 11 hijacker used 30 false identities to obtain credit cards and one quarter of a million dollars of debt. Since then, the problem has worsened: over the last few years, the major terrorist suspects arrested typically had up to 50 identities each.

If people cannot so easily operate under multiple identities we can potentially disrupt the modus operandi of terrorists or criminals that rely on multiple or false identities. The key point is that, if someone is in our country and is travelling on multiple identities or running bank accounts in multiple names, we should be in a position to pick this up early. The front line experience of both Sir Ian Blair, Chief of the Metropolitan Police, and Eliza Manningham-Buller, the head of the Security Service, have led them to say that a national biometric scheme would help them do their job and make reliance on multiple identities very difficult.

But the key point is that we should do all in our power to prevent you or I having our identity stolen or abused, and to ensure that, for each of us, our identity is secure and protected. Some have suggested the use of biometrics in identity cards in Britain is a fundamental and unacceptable "change of relationship between state and individual." In the past securing your identity rested on you being given a National Insurance number, on being required to have a birth certificate, being required to fill in the census, and, for travel abroad, being obliged to hold a passport. So the question is not whether we have a national register identity - we have had so for years - but whether we are prepared to consider the most up to date and the most secure means to protect our identity from being stolen.

I believe it is possible in this new world of terrorist threats to build a national consensus around our proposals by showing that there are proper safeguards and proper accountability. In addition to the Data Protection Act an Independent Commissioner should have oversight of the database and how it is used - testing it against data protection laws, ensuring individuals will have the right to see the information held on them and with, in the British way, proper accountability to Parliament, including reports published and laid before Parliament. And it may be right also to consider for the future whether the Commissioner should report to Parliament, taking an overarching look across both the public and private uses of biometrics, so ensuring the proper safeguards.

The legislation coming before the Commons today already builds in important safeguards. Private companies will not be able to see the national database, nor will government departments in their routine business - only for the prevention of crime or the protection of national security. Only if they are accredited and if they have the person's consent will government departments and private companies be entitled to ask to check that person's identity against the database.

And the British way is to write in not just safeguards for the individual but to ensure accountability to Parliament, with the limits to use of the data enshrined in Parliamentary legislation - and a requirement that there can be no additions to the information held or extensions to how the database is used without returning to Parliament for approval. As Charles Clarke has said, any decision on moving from a voluntary to compulsory scheme will require explicit approval of Parliament through primary legislation.
Mechanics matter too. Building a national scheme will take years, but that is hardly a good argument for not starting now. It will be important to build upon our current proposals in two ways. First, I believe that a joint private public partnership in investigating the next stage - involving banks, financial institutions, computer companies, employers generally - can both contribute to the general security efforts of all and release substantial savings in a potential scheme. So I propose a forum of private and public sectors to examine for not just fraud but security a joint project to release the best technology and value for money. On this basis we will report regularly to Parliament on costs as well as benefits.

Second, as part of our public expenditure review, we should take the measures necessary now to bridge the gap before a complete national scheme is in place: including improving the quality of our databases together with their transparency and accountability - making it easier to intercept terrorists and criminals and to spot fraud while also ensuring people have trust in how the necessary information is protected.

Opponents of the identity scheme like to suggest that its motivation is to enhance the power of the state. In fact it starts from the rights of the individual, the right to have your identity protected and secure and to achieve that, the right to have the most modern and secure way of doing so and - as I suggest - the right to have this done so with safeguards for individuals and the accountability of the state.

CALIFORNIA COMPUTERS STOLEN FROM CHAMBER OF COMMERCE thedesertsun.com Chamber of Commerce attacked twice this year

Chamber of Commerce attacked twice this year
Communication system targeted, says president

Marcel Honoré
The Desert Sun
February 13, 2006

For the second time in just over a month, burglars broke into the Coachella Chamber of Commerce, stealing a computer and sabotaging communications equipment.

On Sunday morning, thieves shattered the Sixth Street office's glass entrance and windows. Chamber president Mark Weber said a modem and a computer with members' contact information was taken.

"They sent a visible message," Weber said. He added he thought the culprit probably wanted information and "obviously wanted to cause some damage."

In January, culprits entered through the ceiling and lifted a printer, a fax and a computer without any confidential data.

"I have a feeling they came back to finish the job," chamber executive director Jacqueline Lopez said.
This time, burglars left the chamber's new fax machine - but they severed its cord, rendering it inoperable.

"It looked like they were trying to limit our communication ability," Weber said.

He added that the stolen computer with the contact information was worth no more than $750.

Lopez said the burglars declined to take her purse on the desk next to the stolen computer.

Weber said the chamber's alarm sounded twice Sunday morning - first at 3:40 a.m and then 7:20 a.m.

Sheriff's deputy Juan Zamora said an officer investigated the first alarm and found no evidence of foul play.

Zamora said police still have no leads, and the case would be assigned to a special enforcement unit.

Board member Rudy Hernandez said the chamber would be open today, and it still plans to hold its "State of the City Address" with mistress of ceremonies Rep. Mary Bono, R-Palm Springs, later this month.

Said Lopez, "This is a minor setback. We're going to keep moving forward and continue our mission."

If you have information about the incident, call Crime Stoppers at 341-7867, or the Coachella Chamber of Commerce at 465-5388

UK COMPUTERS STOLEN FROM SCHOOLS : "Schools hit by burglars

SCHOOL security patrols have been stepped up after a spate of raids which netted burglars thousands of pounds of equipment.
A total of 13 Shropshire schools, including classrooms in Market Drayton, Telford, Shrewsbury and Oswestry, have been broken into since January 18.

The burglars have stolen property including computer equipment and projectors.
West Mercia Police believe the thefts may be linked and have now launched a major inquiry.

February 12, 2006"

Sunday, February 12, 2006

WISCONSIN COMPUTERS STOLEN FROM H&R BLOCK
H&R Block reports stolen computers, but client info safe: "2/11/2006 5:45:00 PM Email this article • Print this article
Comment on this article
H&R Block reports stolen computers, but client info safe

By Casey White
of the East Oregonian

PENDLETON — Four computers from H&R Block were stolen Thursday night, and company officials want local clients to know their personal information is safe despite the theft.

The 203 S.W. Emigrant Ave. business was broken into sometime between 8 p.m. Thursday and 7 a.m. Friday, said Pendleton Police Chief Stuart Roberts. He said entry into the building was gained through the east door facing Southwest Second Street, which was kicked in.

“The investigation is pretty preliminary at this time,” Roberts said. No suspects have been arrested. “Detectives were able to pick up some forensic evidence left behind, though.”

This is one of the busier times of the year for H&R Block, a national company that prepares income tax returns, since state and federal taxes are due by April 17, Roberts said. However, he said he wouldn’t be able to speculate if that’s related to the break-in.

In a statement from H&R Block, officials claim to be working with police on the investigation, and said police have told them such crimes are commit"

CONTINUED at weblink.........

MINNESOTA COMPUTER STOLEN FROM BUSINESS St. Paul Pioneer Press | 02/12/2006 | SOUTH ST. PAUL: "Commercial burglaries: A computer was reported stolen after a forced-entry burglary at Viking Exteriors, 901 Concord St. N., on Wednesday. A plasma television and several tools were reported stolen Feb. 4 after a burglary at Marie Avenue Service, 103 Fifth Ave. N."

MINNESOTA COMPUTERS STOLEN FROM BUSINESS AND CHURCH The Austin Daily Herald: The Newspaper That Cares About Austin: "Mid-Town, church burglar suspect charged

By Josh Verges/Austin Daily Herald

Charges were filed last week against an Austin man suspected of burglarizing and stealing a truck and other items from Mid-Town Car Wash and Christ Episcopal Church.

Darren Eugene Morrison, 20, was arrested in central Illinois early Feb. 3 after a high-speed pursuit ended in a crash, according to a Mower County District Court complaint warrant. Authorities there found items linking him to three burglaries; he has thus far been charged for two of them.

Austin police were called to Mid-Town at 8:15 a.m. Feb. 2. Someone had done $350 in damage by breaking a window in a steel door, another garage door window, and splitting an office door to gain access to the building. Reported stolen were a 2003 Chevy Silverado, a laptop computer, printer, computer checks, $30 cash and a surveillance tape, with a total estimated value of $16,980.

Police believed the burglary was an inside job. Morrison was suspected because he lived nearby, recently began working at the business, had worked on the truck and had taken the day off work.

Twenty-five minutes after the Mid-Town call, Christ Episcopal called police on another burglary. Reported stolen there were a DVD player, desktop computer"