Dec
17
2007
This post is an ongoing collection of articles, surveys, and research about computer forensics.
Surveys & Research:
Dec
17
2007
This post is an ongoing collection of articles, surveys, and research about data governance and privacy.
General references:
- The EFF has a page that gives a status update on pending legislation and court cases related to privacy rights.
Specific references:
- Privacy Rights Clearinghouse has a chronology that documents data breaches since 2005. The grand total - 216 Million records in the USA from 2005 to present. A number of these are organizations that sell information security products and/or services and have failed to “eat their own dog-food”.
- MySpace suffered a security breach recently that allowed hackers to download a massive amount of private photos. Those have recently showed up on BitTorrent.
Dec
17
2007
This post is an ongoing collection of articles, surveys, and research about electronic voting.
General, non-partisan references:
General, partisan references:
- Bev Harris of Blackboxvoting.org is the authority on the challenges surrounding electronic voting.
Specific references by recognized, non-partisan experts:
- The Ohio Secretary of State recently issued the EVEREST report which also found numerous critical flaws in electronic voting systems.
- The California Secretary of State sponsored a “top to bottom” review of electronic voting and decided to decertify several models.
- The Colorado Secretary of state followed suit and decertified the voting machines on 12/18/07.
- One of the most respected security experts, Bruce Schneier, posted an insightful article about electronic voting.
- An AP article documenting the conviction of election workers for rigging the 2004 Ohio recount.
Specific, partisan references:
I don’t endorse the conclusions reached by the materials below, though I do find the information to be thought provoking. While the impact of the systematic weaknesses in voting systems is hotly debated and quickly devolves into conspiracy theories, the fact that they are inexcusably weak is not contested.
- Youtube has a controversial video of a programmer giving testimony that he designed a program to “fix” elections.
- The Washington Post summarized a controversial book by Professor Steve Freeman that compares the security and regulation over slot machines to electronic voting systems.
- Rolling Stone Magazine published two articles by Robert F. Kennedy Jr. about electronic voting.
Dec
17
2007
This post is an ongoing collection of articles, surveys, and research about IT General Controls.
- The Royal Bank of Canada suffered major downtime due to a failed upgrade of their computer systems in 2004.
Dec
17
2007
This post is an ongoing collection of articles, surveys, and research about mortgage fraud and the credit bubble.
General References:
- Rachel Dollar’s and the Prieston Group’s blogs focus on mortgage fraud.
- John Maudlin publishes my favorite investing and economic analysis newsletter. He’s had some great discussion of the credit bubble, sub-prime crisis, and mortgage fraud.
- Efinancedirectory.com has a great segment on the housing bubble. I’ve been reading them for several years. They liberally quote from credible sources such as Credit-Suisse.
- Patrick.net is a great resource for housing information specific to the Bay Area, CA.
Specific References:
- Read about mortgage fraud in Miami condos.
- The BBC has a great article with graphical explanations of the subprime mess.
- The FBI’s most recent mortgage fraud report was issued in 2006. There’s a shorter article specific to mortgage fraud updated on 5/2007.
- Countrywide underwriters sued by NY pension funds for mortage fraud.
- FBI opens investigation into 14 banks related to possible mortgage and securities fraud.
Dec
14
2007
This post is an ongoing collection of articles, surveys, and research about the cybercrime economy.
Surveys & Research:
- The FBI’s most recent cybercrime report was issued in 2006.
- The US Secret Service published two reports on cybercrime.
Articles:
Dec
14
2007
This post is an ongoing collection of articles about identity theft.
General References:
- Privacy Rights Clearinghouse has an identity theft page with lots of content.
Specific References:
- FaceBook source code was leaked during summer 07.
- A judge was defamed by a fake MySpace profile.
- According to this MSNBC article, 3% of US households suffer identity theft.
- Identity theft is often close to home.
- The FBI’s most recent identity theft report was issued in 2006.
- Fly by night trend followers are piling into the identity theft protection market. They are making bold claims that don’t live up to scrutiny. Eat your own dogfood?
- Top Gear host ridicules the identity theft threat and gets stung.
Dec
14
2007
This post is a collection of articles and research related to insider threats.
Surveys & Research:
- The US Secret Service published the Insider Threat Study in 2003 and 2005.
Articles:
Dec
14
2007
This post is a collection of articles, surveys, and research related to internal controls & fraud.
Surveys & Research:
Articles:
- There is a correlation between high stock-option compensation and financial fraud.
- Financial fraud requires collaboration to circumvent internal controls.
Dec
14
2007
Wired has a story about a virtual bank scam in Second Life (SL). Technology review has a more detailed one. Valleywag has a great post on the bigger picture of doing business in SL. I suppose events like this are what Charles Stross based Halting State on.
- Update 1/9/08: Linden Labs is banning the charging of interest without a banking license.
- Update 1/16/08: Security Focus has an interview about the state of online gaming security.