Google Street View Battle Highlights Privacy Challenge

Google is being sued by a Swiss watchdog agency for allegedly failing to take adequate measures to protect privacy. The debate in Switzerland is over Google's Street View image indexing. The legal battle in Switzerland is just the latest in a long line of privacy issues with Google and illustrates the challenge of providing as much information as possible without violating privacy concerns.

Hanspeter Thuer, the Swiss Federal Data Protection and Information Commissioner (FDPIC) made recommendations to Google to address concerns with Street View images displaying car license plates and people's faces. This isn't the first time Street View has gotten into trouble over privacy. Google claims it has taken strides to comply with those recommendations, but the FDPIC doesn't feel Google has done enough. Google has also faced backlash over Street View in the United Kingdom, Canada, Greece, and Japan. Greece is distressed by how long Google plans to maintain the Street View images in its database.

One concern in Japan, which has been echoed in Switzerland, is that the height of the car-mounted Street View cameras is capable of seeing over fences and into homes. Google's privacy issues are not restricted to the Street View images, though. Google recently launched a new feature allowing you to set up alerts that can notify you when a friend is nearby. Google Latitude, a GPS mapping and tracking service, keeps track of your location in real-time and maintains a mapped database of previous locations. The cool factor is tempered with a creepy Big Brother vibe. There are privacy issues related to Google Social Search, Google recently modified indexing of Gmail messages to address concerns over transcribed Google Voice emails showing up in the search engine, and even the embryonic Chrome OS has raised privacy concerns.

The list goes on and on. Google recently unveiled the Google Dashboard to address privacy concerns. But, the Google Dashboard itself also has privacy and security implications as well. The Google Dashboard displays all of the information associated with your Google profile, providing you with an at-a-glance resource to see just how much Google knows about you. It is a difficult balance for Google to manage.

Technology has brought us to the point where, unless you live in an unmarked cabin in the Rockies and live off the land, data about you is being indexed virtually everywhere. If you read books like Database Nation by Simson Garfinkel, or The Soft Cage by Christian Parenti, you come to the realization that privacy is largely an illusion at this point. Privacy is a myth. On the contrary, perhaps it suggests we need to be more vigilant about protecting what little privacy we might have left. That doesn't mean we should all just give up and accept that we have no privacy. Google has to struggle with the conflict of interest between indexing all of the data in the world, and protecting privacy.

My fellow PC World writer David Coursey has pointed out that Google has not yet done anything to lead us to believe it has evil intentions for our data, but the data is still there on the Google Servers. Not only that, but Google must also to tailor its indexing and business practices on a country by country basis to comply with local data protection and privacy regulations. Coursey ponders what might happen following another 9/11-caliber terrorist attack "Would Google provide information it has about suspects? If it did, how long would it be before we knew? Use its data and profiling capability to find more suspects?

And where, exactly, is the line between patriotism and invasion of privacy?" That is a valid question. Tony Bradley tweets as @PCSecurityNews, and can be contacted at his Facebook page . Google has to continue strike a balance between information and privacy, and users need to grasp that the convenience provided by Google's products and services comes at a cost.

Do collaboration tools enable collaboration?

At the recent IT Roadmap conference in Washington D.C. there was a panel discussion about how the younger generation uses tools such as texting to stay in touch with friends. Another implication was that as the younger generation enters the workforce, they will bring their collaborative approach with them to the workforce and this will drive the existing workforce to be more collaborative. One of the implications of the discussion was that the younger generation is more facile with collaboration than is the current workforce. We want to use this newsletter to express an alternative opinion.

However, most people that we know that are currently in the workforce also text – perhaps not as much as the younger generation, but they do. Ford driving Exchange 2010 into collaboration plans There is no doubt that the younger generation, the kids that are currently in grammar school and high school, are very facile with collaboration tools such as texting. Hence, we do not see that age is a barrier that keeps the current generation of workers from texting. In fact, in some cases, they seem to prefer to send texts back and forth vs. having a conversation. One concern that we have is that young people often use texting as an alternative to face-to-face communications.

Is this really collaboration or is it running away form collaboration? That is a form of collaboration – but a very low level form. Collaboration tools such as texting, instant messaging, and twitter are well suited to support a simplex or at best half duplex conversation, such as sending a text to inform someone that you will be late for a meeting. Let's set up a hypothetical situation. The company pulls together a project team comprised of people in different organizations, including someone from the WAN organization, from the software development group, security and compliance, and one or more business units. A company is considering using a software-as-a-service provider for some new application.

The various members of the team have different, and in some cases, conflicting goals.  For example, the people who represent the business units want to get the solution running as soon as possible; the security and compliance people are worried that they will not be able to pass an audit if the solution is deployed; the person from the software organization feels their organization is being bypassed, and the person from the WAN organization is concerned about how much extra traffic will now transit the WAN. The disparate goals of the project team members will not be resolved by sending text messages, IMs, or tweets. One IT professional we talked with told us that his organization had used traditional videoconferencing for years. That is not to say that there are not collaboration tools that can help. He added that he believes that telepresence is more powerful than traditional videoconference in part because the picture quality allows you to see body language and facial expressions as well as you could in person. It does, however, have a better chance of succeeding than a text that reads: OMG, c u @ 10:15.

Of course, telepresence does place a tremendous burden on the WAN. Just seeing body language and facial expression may not resolve the fact that the project team members have disparate goals.

Vendor group forms cloud storage initiative

The Storage Networking Industry Association (SNIA) announced today the formation of the Cloud Storage Initiative (CSI) in order to establish a lexicon of cloud-computing terminology, publish use cases, white papers and technical specifications, and to create reference implementation models for grid-storage architectures. The organization also plans to perform market outreach highlighting the virtues of cloud storage. The CSI will coordinate and deliver educational materials for cloud storage vendors and user communities. The group is developing a single specification as part of its efforts.

The SNIA made the announcement at the Storage Networking World conference, which is co-sponsored by Computerworld . "Part of the challenge with cloud is where does the data live? The Cloud Data Management Interface (CDMI) will be an application programming interface to which vendors can write management software that will allow interoperability between heterogeneous cloud storage offerings, according to Wayne Adams, SNIA's chairman emeritus. And how are you able to manage it once it's in the cloud, and can you get it back in the same format that you now have," said Mark Carlson, a SNIA Technical Council member said. "There's this idea of how portable is my data that once I get it out there can I get it back in a format that can be ingested by another vendor?" Carlson said the CSI will focus on disseminating information about technology to build both public cloud service, such as Amazon's S3 service, and private cloud architectures in data centers. The CSI will complement the technical innovation and de velopment from the SNIA Cloud Storage Technical Working Group , which has more than 140 members representing over 50 commercial vendors, service providers and educational institutions. CSI published cloud storage cases and requirements for cloud storage in June.

The CSI will aid the Technical Working Group in bringing specifications and technical developments to international standards development organizations. It is also releasing a joint white paper with the Open Grid Forum (OGF) focused on cloud storage for cloud computing all developed by the working group. "It's both encouraging and timely to see this new initiative from SNIA," said Simon Robinson, research director of storage for research firm The 451 Group. "It's gratifying to see this co-operative effort around standards and education, since those are two of the current impediments to fast adoption as technologies mature and become integrated into more vendor offerings." For example, the CSI will promote and deliver a new cloud storage tutorial to be unveiled at Storage Networking World this week.

Restaurants sue vendors after point-of-sale hack

When Keith Bond bought a computerized cash register system for his Broussard, Louisiana, restaurant, he thought he was modernizing his restaurant. His story reads like a warning for small businesses, who in connecting their businesses to the Internet, have also become prey for sophisticated cyber-criminals. Today, he believes he was unwittingly opening a back door for Romanian hackers who have now cost him more than US$50,000. Bond's is one of more than a half-dozen Louisiana restaurants that have sued the makers of their point-of-sale system, alleging that the companies that made and resold the systems are the ones who should be responsible for fines levied by payment processors following the hack.

Bond says that systems at his Mel's Diner, Part II, were hacked, along with several other restaurants in the region, sometime around March 2008. Investigators told him that the systems were compromised by Romanian hackers who used the devices' remote access software to steal credit card numbers from the systems. The criminals took those credit card numbers and then used them to make fraudulent purchases throughout the U.S., he said. This software let Bond's reseller, Computer World, provide remote support to the systems. In the class-action lawsuit, Bond and the other plaintiffs allege that their point-of-sale systems were out of compliance with the Payment Card Industry Data Security Standard (PCI DSS), which defines how secure the big credit card companies expect their merchants' computers to be. He was then assessed tens of thousands of dollars in fines and chargeback fees generated by the 699 credit card numbers that were stolen from his three point-of-sale devices. "Our clients are restaurants," said Bond's lawyer, Charles Hoff, in a statement. "They are food experts, not technologists.

Bond and others blame the maker of his Aloha point-of-sale system, Radiant Systems, and its Louisiana reseller, Computer World (Computer World is not related to IDG's ComputerWorld magazine). After the hack, Bond had to spend close to $20,000 to audit his systems. When major players in the hospitality industry such as Radiant Systems and its distributors say their software and business practices are PCI-DSS compliant, our clients trust them." The class-action lawsuit was filed in October but was not widely known until the privacy blog DataBreaches.net disclosed it last week. Citing company policy, a Radiant spokeswoman declined to comment on the lawsuits, but in an e-mailed statement, she said that the company believes that the allegations are without merit. "These customers were victims of criminal acts almost two years ago. Another similar lawsuit was filed against Radiant and Computer World in April by plaintiffs in Georgia. Unfortunately, in today's world criminal acts like these are not uncommon in the restaurant industry," the statement read.

There's no level of responsibility with the processor, the reseller or with Visa Mastercard. Bond doesn't buy that. "You're buying an expensive point-of-sale system," he said. "But when you're compromised, Visa and Mastercard come after the merchant. So the merchant is the person who is suffering." The lawsuit claims that Visa warned Radiant and Computer World that they were not PCI compliant the year before the hack, but that merchants were never notified of these problems, even though they were the ones who ultimately had to pay big fines. The alert warned Aloha users to disable a Remote Desktop feature on their equipment if it's not being used to provide remote support to the point-of-sale system. That's a real problem, said Avivah Litan, an analyst with the Gartner research firm. "Merchants should be notified directly when Visa or MasterCard issue alerts about non-compliant software," she said in an e-mail interview. "Restaurants are in the business of selling food; they should not be expected to be experts in the intricacies of credit card processing certification processes, especially when they are not even privy to most of the communications surrounding them." Radiant warned about the problem, according to a security alert posted by a San Francisco Bay Area Radiant reseller.

The plaintiffs in Bond's lawsuit say they received no such alert. According to Bond, Computer World used this Remote Desktop feature to access his systems. Computer World did not respond to a request for comment on this article. To make matters worse, Computer World had set up his and other restaurants with the same default password: "Computer," Bond said.

Lawsuit claims HP PCs suffer constant lockups, crashes

A Colorado man has sued Hewlett-Packard, saying that its Pavilion Elite desktop computers are "inherently defective," and constantly lock up within 10-20 minutes of use. Pegatron Technology is a subsidiary of Taiwan-based Asustek Computer, which is best known for its ASUS line of netbooks. "After operating the [Pavilion Elite] e9150t for approximately two weeks, Plaintiff's computer began experiencing repeated disruptive failures including lock-ups, freezes, and blue screen errors, requiring him to reboot the computer," read the suit, which was filed on behalf of Michael Kent of Arvada, Colo. The lawsuit, which was filed with a California federal court last Thursday, seeks class-action status that, if granted, would open the case to all HP customers who have purchased one of the allegedly defective PCs. According to the lawsuit, HP's Pavilion Elite e9150t, e9180f, e9180t, m9600t and m9650f, when equipped with the "Truckee" motherboard from Pegatron Technology and Intel's i7 quad-core processor, crash or lock up soon after they're powered on.

Kent purchased the Pavilion Elite e9150t in late July 2009. "Since that time, Plaintiff experiences the aforementioned errors on an almost daily basis. Kent's lawyers cited 20 messages posted on an HP support forum as proof that others have complained of the same problem. These errors occur most frequently within 10 to 20 minutes after a 'cold boot,'" the lawsuit continued. The lawsuit also included a link to a support thread that as of Monday ran 288 pages, and boasted nearly 2,900 messages submitted by customers. Others on the thread said that although HP had replaced either the CPU or the entire computer, they were still seeing frequent crashes or lock-ups of the Pavilion. "Even though HP is replacing the e9150t models with the upgraded e9180 models and including faster, more costly processors, the computers still exhibit the same defects," Kent's lawsuit read. The thread is the most-heavily-trafficked of all those on the HP support forum dedicated to lockups and freezes . On the Pavilion Elite e9150t lock-up thread, users said that they had tried several different HP-suggested remedies, including installing a BIOS update, a tack Kent claimed he also tried to no avail.

Users continued to post messages on the support forum today. "I hereby give up with HP 'support,'" said a user identified as "GaryJ51," in a message added to the thread Monday morning. "After dozens of calls to HP, and many broken promises, I eventually wrote to the CEO as suggested by someone on this site. My unreliable PC is still ... here, waiting for a returns box. Nothing. It's many weeks now since I began this effort to fix the thing. I don't know what else to do." "I just received a call from a Case Manager Supervisor," added "Hanspuppa" in a message posted shortly after GaryJ51's. "I explained all my issues with the two systems I purchased, and requested the defective systems be replaced with new systems, and she denied my request. $3,500.00 down the drain." Kent's lawsuit charged HP with deceptive advertising, fraud and breach of warranty, and asked the federal judge to grant the case class-action status, as well as to force HP to pay compensatory and statutory damages.

I give up. HP did not respond to a request for comment.

Microsoft's CodePlex Foundation leader soaks in stinging critique

After a stinging critique from a noted expert in establishing consortia, the leader of Microsoft's new CodePlex Foundation says such frank evaluation is welcome because the open source group's structure is a work in progress. The CodePlex Foundation's aim is to get open source and proprietary software companies working together. Sam Ramji, who is interim president of the CodePlex Foundation, was responding to last week's blog by Andy Updegrove, who said the group has a poorly crafted governance structure and looks like a sort of "alternative universe" of open source development.

Updegrove, a lawyer, noted expert on standards, and founder of ConsortiumInfo.org, laid out in a blog post five things Microsoft must change if it wants CodePlex to succeed: create a board with no fewer than 11 members; allow companies to have no more than one representative on the Board of Directors or Board of Advisors; organize board seats by category; establish membership classes with rights to nominate and elect directors; and commit to an open membership policy. He added, however, "There are some best practices [for running the boards of non-profits] that we are not as familiar with as we would want to be." Slideshow: Top 10 open source apps for Windows  Stephanie Davies Boesch, the foundation's secretary and treasurer, is the only board member with experience sitting on a non-profit's board. Despite the stinging tone in Updegrove's assessment, Ramji says he is thankful for the feedback. "Andy's been incredibly generous with his expertise and recommendations," Ramji says. "It is the kind of input and participation we were hoping to get by doing what is probably non-traditional for Microsoft but not necessarily non-traditional for non-profit foundations, which is to basically launch as a beta." For instance, Ramji says that the decision to go with only five people on the board came from Microsoft's experience that larger groups often have difficulty with decision making. Ramji says Updegrove's suggestion to have academic representation on the board was "outstanding. And basically it is re-writable.

We did not think of that." And to Updegrove's point on becoming an open membership organization, Ramji says, "our goal is to become a membership organization and Andy has some excellent recommendations for that."He says the fact that Updegrove took the time to respond "in the format that he did is more proof that there is something worth doing here." Ramji, compares the Foundation's formation to the early days of a software development project. "We have said in these first 100 days we are looking at everything as a beta. Obviously, there are some areas like contributions and licensing agreements we put a lot of time into but even those can be modified." Microsoft announced the foundation Sept. 10 with a stated goal "to enable the exchange of code and understanding among software companies and open source communities." The company seeded the group with $1 million and Microsoft employees dominated the interim board of directors and board of advisors. One is a call for a broad independent organization that can bridge cultural and licensing gaps in order to help commercial developers participate in open source. Ramji says the foundation has spent the past couple of weeks listening to feedback in "Twitter messages, email, and phone calls in order to understand what people hope this can be." Within that feedback two patterns have emerged, Ramji says. The other focuses on creating a place where open source .Net developers can gain strong backing. "Look at projects related to Mono, you also can look at NUnit, NHibernate, we really feel optimistic that the Foundation could help them gain a higher level of credibility in the open source community. Miguel de Icaza, the founder of the Mono project and the creator of the Gnome desktop, is a member of the Foundation's interim board of directors.

They feel they have been lacking that strong moral support," Ramji says. From a high level, Ramji says the Foundation stands as a sort of enabler that helps independent developers, companies and developers working for those companies navigate the nuances and practices of open source development so they can either contribute source code to projects or open source their own technologies. "One suggestion has been that the Foundation should house all the best practices we have seen software companies and open source communities use," said Ramji. "We want to have a place where everyone interested in how to participate can come and read and if they choose they can use our license agreements or can use the legal structure of the Foundation to grant patent licenses and copyrights for developers and derivative works." Those licensing agreements have a distinct focus, Ramji said, on the rights that are related to code that is being contributed and on how to contribute the patent rights on that code. Ramji says the goal is to service multiple projects, multiple technologies and multiple platforms rather than having one specific technology base, which is how most current open source foundations are structured. "It's early days and we have received a lot of good ideas from experts in a variety of fields from law to code to policy that is what we had hoped for," says Ramji. "Someone wrote it is nice to see Microsoft engaging early on without all the answers and to have the community solve what they would like to see. Once those issues are settled, code would be submitted using existing open source licenses. That is satisfying for me and refreshing to others.

This is the right way to proceed." Follow John on Twitter

The six greatest threats to US cybersecurity

It's not a very good day when a security report concludes: Disruptive cyber activities expected to become the norm in future political and military conflicts. From the GAO: "The growing connectivity between information systems, the Internet, and other infrastructures creates opportunities for attackers to disrupt telecommunications, electrical power, and other critical services. But such was the case today as the Government Accountability Office today took yet another critical look at the US federal security systems and found most of them lacking.

As government, private sector, and personal activities continue to move to networked operations, as digital systems add ever more capabilities, as wireless systems become more ubiquitous, and as the design, manufacture, and service of information technology have moved overseas, the threat will continue to grow. " Within today's report, the GAO broadly outline the groups and types of individuals considered to be what it called key sources of cyber threats to our nation's information systems and cyber infrastructures. According to the Director of National Intelligence, a growing array of state and nonstate adversaries are increasingly targeting—for exploitation and potential disruption or destruction—information infrastructure, including the Internet, telecommunications networks, computer systems, and embedded processors and controllers in critical industries. From the GAO: Foreign nations: Foreign intelligence services use cyber tools as part of their information gathering and espionage activities. Criminal groups: There is an increased use of cyber intrusions by criminal groups that attack systems for monetary gain. While remote cracking once required a fair amount of skill or computer knowledge, hackers can now download attack scripts and protocols from the Internet and launch them against victim sites.

Hackers: Hackers sometimes crack into networks for the thrill of the challenge or for bragging rights in the hacker community. Thus, attack tools have become more sophisticated and easier to use. These groups and individuals overload e-mail servers and hack into Web sites to send a political message. Hacktivists: Hacktivism refers to politically motivated attacks on publicly accessible Web pages or e-mail servers. Disgruntled insiders:The disgruntled insider, working from within an organization, is a principal source of computer crimes.

The insider threat also includes contractor personnel. Insiders may not need a great deal of knowledge about computer intrusions because their knowledge of a victim system often allows them to gain unrestricted access to cause damage to the system or to steal system data. Terrorists: Terrorists seek to destroy, incapacitate, or exploit critical infrastructures to threaten national security, cause mass casualties, weaken the U.S. economy, and damage public morale and confidence. The Central Intelligence Agency believes terrorists will stay focused on traditional attack methods, but it anticipates growing cyber threats as a more technically competent generation enters the ranks. However, traditional terrorist adversaries of the United States have been less developed in their computer network capabilities than other adversaries. Testifying before the Senate Judiciary Committee, Subcommittee on Terrorism and Homeland Security today, FBI Deputy Assistant Director, Cyber Division said that while the FBI has not yet seen a high level of end-to-end cyber sophistication within terrorist organizations, it is aware of and investigating individuals who are affiliated with or sympathetic to al Qaeda who have recognized and discussed the vulnerabilities of the U.S. infrastructure to cyber attack; who have demonstrated an interest in elevating their computer hacking skills; and who are seeking more sophisticated capabilities from outside of their close-knit circles. "In addition, it is always worth remaining mindful that terrorists do not require long term, persistent network access to accomplish some or all of their goals.

The likelihood that such an opportunity will present itself to terrorists is increased by the fact that we, as a nation, continue to deploy new technologies without having in place sufficient hardware or software assurance schemes, or sufficient security processes that extend through the entire lifecycle of our networks," Chabinsky said. Rather, a compelling act of terror in cyberspace could take advantage of a limited window of opportunity to access and then destroy portions of our networked infrastructure.