<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-37642592</id><updated>2012-01-21T11:49:16.310-08:00</updated><category term='Android'/><title type='text'>TRUST in the News</title><subtitle type='html'>News items about the &lt;a href="http://www.truststc.org"&gt;team for Research in Ubiquitous Secure Technology (TRUST)&lt;/a&gt;</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://trust-website-news.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default?start-index=101&amp;max-results=100'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>132</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-37642592.post-4899085714084242477</id><published>2012-01-21T11:38:00.000-08:00</published><updated>2012-01-21T11:49:16.331-08:00</updated><title type='text'>Internet is still vulnerable to cyber-criminals</title><content type='html'>A January 21, 2012 San Francisco Chronicle article "&lt;a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2012/01/21/BU6U1MRLBQ.DTL"&gt;Internet is still vulnerable to cyber-criminals&lt;/a&gt;" by James Temple discusses Mark Bowden's book "&lt;a href="http://www.amazon.com/Worm-First-Digital-World-War/dp/0802119832"&gt;Worm: The First Digital World War&lt;/a&gt;," which describes the October 21, 2002 attack on the Internet Domain Name Servers.&lt;br /&gt;&lt;br /&gt;The SF Chronicle article states:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;Internet Protocol version 6, will create more root name servers and add other security protections.&lt;br /&gt;&lt;br /&gt;&lt;p&gt;"But the general consensus today is that it's still pretty fragile," said Doug Tygar, professor of computer science at UC Berkeley.&lt;/p&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;See also the October 3, 2011 &lt;a href="https://www.nytimes.com/2011/10/04/books/mark-bowdens-worm-about-conficker-review.html?_r=1"&gt;review of 'Worm'&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-4899085714084242477?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4899085714084242477'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4899085714084242477'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2012/01/internet-is-still-vulnerable-to-cyber.html' title='Internet is still vulnerable to cyber-criminals'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-4034981608121141477</id><published>2011-12-13T10:09:00.001-08:00</published><updated>2011-12-13T10:24:26.727-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Android'/><title type='text'>Android apps and advertising: A bit too cozy</title><content type='html'>A Tech Republic blog entry "&lt;a href="http://www.techrepublic.com/blog/security/android-apps-and-advertising-a-bit-too-cozy/7003"&gt;Android apps and advertising: A bit too cozy&lt;/a&gt;" features the research of TRUST Ph.D. student &lt;a href="http://www.cs.berkeley.edu/%7Eafelt/"&gt;Adrienne Porter Felt&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Adrienne asked non-computer scientists: “Do you think the advertiser can use the app’s permissions?”  Twelve people answered with:&lt;br /&gt;&lt;br /&gt;Yes: 5&lt;br /&gt;No: 2&lt;br /&gt;I don’t know: 5&lt;br /&gt;&lt;br /&gt;It turns out that the answer is not that simple.&lt;br /&gt;&lt;br /&gt;Adrienne's blog entry "&lt;a href="http://www.adrienneporterfelt.com/blog/?p=357"&gt;Advertising and Android Permissions&lt;/a&gt;" states:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;"Can an advertiser use an app’s permissions?"&lt;br /&gt;&lt;br /&gt;"When you see an advertisement in an application, there are three parties.  First, there’s the application itself, which asks the user for permissions.  Second, there’s the advertising library, which is shoved into the application and therefore gains access to all of the app’s permissions.  Third, the advertising library displays the advertisement itself.  The advertisement can’t directly use any of the permissions, but the advertising library might share information with the company that is running the ad.  So if you see an REI ad while playing a game, you should know that the invisible ad library gets all of the game’s permissions, and it might share information like your location with REI."&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Adrienne is a student of Berkeley Professor &lt;a href="http://www.cs.berkeley.edu/~daw/"&gt;David Wagner&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-4034981608121141477?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4034981608121141477'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4034981608121141477'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2011/12/android-apps-and-advertising-bit-too.html' title='Android apps and advertising: A bit too cozy'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-3898054268169606051</id><published>2011-12-05T07:46:00.000-08:00</published><updated>2011-12-05T07:55:32.386-08:00</updated><title type='text'>Carrier IQ cell phone monitor software is a nightmare</title><content type='html'>TRUST Professor &lt;a href="http://wisl.ece.cornell.edu/wicker/"&gt;Stephen Wicker&lt;/a&gt; was quoted in a NetworkWorld article, "&lt;a href="https://www.networkworld.com/news/2011/120211-cornell-carrieriq-253696.html?hpg1=bn"&gt;Cornell Prof: Carrier IQ affair 'my worst nightmare'&lt;/a&gt;".  Carrier IQ is software present on various cell phones that provides call quality and other feedback to cell phone companies.&lt;br /&gt;&lt;br /&gt;&lt;p&gt;The article quotes Professor Wicker:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;"This is my worst nightmare," says Stephen Wicker, a professor of electrical and computer engineering at Cornell. "As a professor who studies electronic security, this is everything that I have been working against for the last 10 years. It is an utterly appalling invasion of privacy with immense potential for manipulation and privacy theft that requires immediate federal intervention.&lt;br /&gt;&lt;br /&gt;&lt;p&gt;"Carrier IQ claims that the collected data is 'anonymized.' Let's give this a moment's thought -- about all that it deserves. How hard would it be to 'de-anonymize' a pile of text messages between me and my wife? My mother? My children? Banking IDs with passwords?" &lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;The article was also picked picked in a &lt;a href="http://yro.slashdot.org/story/11/12/03/2112220/carrier-iq-drama-continues"&gt;Slashdot article&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-3898054268169606051?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/3898054268169606051'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/3898054268169606051'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2011/12/carrier-iq-cell-phone-monitor-software.html' title='Carrier IQ cell phone monitor software is a nightmare'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-162696167611838042</id><published>2011-10-05T16:31:00.000-07:00</published><updated>2011-10-05T16:43:55.604-07:00</updated><title type='text'>White House Honors Cornell's Salman Avestimehr with PECASE</title><content type='html'>TRUST investigator and Cornell Professor &lt;a href="http://www.truststc.org/people/directory/avestime"&gt;Salman Avestimehr&lt;/a&gt; was named a recipient of the &lt;b&gt;Presidential Early Career Award for Scientists and Engineers&lt;/b&gt;, the highest honor bestowed by the United States government on science and engineering professionals in the early stages of their research careers.&lt;br /&gt;&lt;br /&gt;Nominated by the National Science Foundation, Prof. Avestimehr was recognized as one of the Nation's "most meritorious scientists and engineers whose early accomplishments show the greatest promise for assuring America's preeminence in science and engineering and contributing to the awarding agencies' missions." The award includes a multi-year research grant.&lt;br /&gt;&lt;br /&gt;The press release from the White House, which includes the full list of recipients, is available &lt;a href="http://www.whitehouse.gov/the-press-office/2011/09/26/president-obama-honors-outstanding-early-career-scientists"&gt;here&lt;/a&gt;.  A press release from the Cornell University School of Electrical and Computer Engineering is available &lt;a href="http://www.ece.cornell.edu/peo-fac-showAward.cfm?awardID=147"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-162696167611838042?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/162696167611838042'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/162696167611838042'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2011/10/white-house-honors-cornells-salman.html' title='White House Honors Cornell&apos;s Salman Avestimehr with PECASE'/><author><name>Larry Rohrbough</name><uri>http://www.blogger.com/profile/01122887820002175089</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-7864170785924390935</id><published>2011-08-09T16:12:00.000-07:00</published><updated>2011-08-09T17:14:00.483-07:00</updated><title type='text'>"The Science of Cyber Security"</title><content type='html'>US News and World Report's article, "&lt;a href="http://www.usnews.com/science/articles/2011/08/04/the-science-of-cyber-security"&gt;The Science of Cyber Security&lt;/a&gt;" by &lt;a href="http://www.linkedin.com/pub/marlene-cimons/6/796/16a"&gt;Marlene Cimons&lt;/a&gt; gives an overview of the &lt;a href="http://www.truststc.org"&gt;Team for Research in Ubiquitous Secure Technology (TRUST)&lt;/a&gt;.  Dean Shankar Sastry is quoted:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;"“We no longer can afford to be reactive in our attitudes about cyber security,” ...&lt;br /&gt;&lt;br/&gt;“Our current approach is bolt-on, rather than built-in patches, bolted on, like an afterthought. We need to be proactive.”&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-7864170785924390935?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7864170785924390935'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7864170785924390935'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2011/08/science-of-cyber-security.html' title='&quot;The Science of Cyber Security&quot;'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-6216205802510278028</id><published>2011-08-09T16:03:00.000-07:00</published><updated>2011-08-09T16:09:35.117-07:00</updated><title type='text'>Erika Chin: "Seven ways to hang yourself with Google Android"</title><content type='html'>The research work of &lt;a href="http://www.eecs.berkeley.edu/~emc/"&gt;Erika Chin&lt;/a&gt;, an EECS graduate student studying smartphone security was featured in a Consumer Reports online magazine article titled "&lt;a href="http://news.consumerreports.org/electronics/2011/08/def-con-19-android-apps-ask-for-too-much-power.html"&gt;Def Con 19: Android apps ask for too much power&lt;/a&gt;". Erika and principal researcher &lt;a href="http://yekaterinatsipenyukoneil.sys-con.com/"&gt;Yekaterina Tsipenyuk O’Neil&lt;/a&gt; reported that after studying dozens of Android apps, 30 percent of them were over privileged and creates a larger security risk to your personal information and phone.&lt;br /&gt;(&lt;i&gt;Based on text by Miyoko Tsubamoto&lt;/i&gt;) &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-6216205802510278028?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6216205802510278028'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6216205802510278028'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2011/08/erika-chin-seven-ways-to-hang-yourself.html' title='Erika Chin: &quot;Seven ways to hang yourself with Google Android&quot;'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-6003826743253543061</id><published>2011-06-13T22:56:00.000-07:00</published><updated>2011-06-13T23:19:39.357-07:00</updated><title type='text'>Stanford's Dan Boneh Receives Dean's Award for Industry Education Innovation</title><content type='html'>TRUST researcher and Stanford University Professor &lt;a href="http://www.truststc.org/people/directory/dabo"&gt;Dan Boneh&lt;/a&gt; was awarded the School of Engineering &lt;b&gt;Dean's Award for Industry Education Innovation&lt;/b&gt;. The award is given for "outstanding teaching and exemplary leadership in industry education" and Dan was recognized for his leadership of the Stanford &lt;a href="http://scpd.stanford.edu/public/category/courseCategoryCertificateProfile.do?method=load&amp;certificateId=1145836#searchResults"&gt;Advanced Computer Security Certificate&lt;/a&gt; program as well as teaching courses on computer systems security and cryptography.  These courses are offered by the &lt;a href="http://scpd.stanford.edu/publicViewHome.do?method=load"&gt;Stanford Center for Professional Development&lt;/a&gt; which focuses on connecting working professionals worldwide to the research and teaching of Stanford University faculty in the School of Engineering and related academic departments.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-6003826743253543061?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6003826743253543061'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6003826743253543061'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2011/06/stanfords-dan-boneh-receives-deans.html' title='Stanford&apos;s Dan Boneh Receives Dean&apos;s Award for Industry Education Innovation'/><author><name>Larry Rohrbough</name><uri>http://www.blogger.com/profile/01122887820002175089</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-7065898602083423137</id><published>2011-06-10T16:45:00.000-07:00</published><updated>2011-06-10T16:56:58.950-07:00</updated><title type='text'>TRUST Researchers to Lead Intel Security Center</title><content type='html'>Intel Labs announced the creation of the &lt;a href="http://istcsc.cs.berkeley.edu/"&gt;Intel Science and Technology Center for Secure Computing (ISTCSC)&lt;/a&gt; to be led by UC Berkeley with partner institutions Carnegie Mellon, Drexel, Duke, and Illinois.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;The center's work will focus on making personal computers safer from malware, securing mobile devices, and protecting personal data when it is distributed across the Internet by giving people more control over it. The center is the second announced by Intel as part of their 5-year, $100 million ISTC program that will increase university research, accelerate innovation, and encourage tighter collaboration between university thought leaders and Intel.  The ISTCSC will be funded at a level of $2.5 million per year for five years.&lt;br /&gt;&lt;br /&gt;The center will be co-led by TRUST investigator and UC Berkeley Professor &lt;a href="http://www.truststc.org/people/directory/daw"&gt;David Wagner&lt;/a&gt; and Intel Senior Principal Engineer John Manferdelli.  Among the faculty researchers participating in the center are TRUST investigators &lt;a href="http://www.truststc.org/people/directory/adj"&gt;Anthony Joseph&lt;/a&gt;, &lt;a href="http://www.truststc.org/people/directory/vern"&gt;Vern Paxson&lt;/a&gt;, &lt;a href="http://www.truststc.org/people/directory/dawnsong"&gt;Dawn Song&lt;/a&gt;, and &lt;a href="http://www.truststc.org/people/directory/tygar"&gt;Doug Tygar&lt;/a&gt; from UC Berkeley and &lt;a href="http://www.truststc.org/people/directory/adrian"&gt;Adrian Perrig&lt;/a&gt; from Carnegie Mellon.&lt;br /&gt;&lt;br /&gt;Intel released a &lt;a href="http://newsroom.intel.com/community/intel_newsroom/blog/2011/06/07/intel-labs-collaborative-efforts-speed-technological-breakthroughs-shape-future-of-computing"&gt;press statement&lt;/a&gt; announcing the creation of the center and the center’s website contains a &lt;a href="http://istcsc.cs.berkeley.edu/docs/ISTC-SC-Whitepaper.pdf"&gt;white paper&lt;/a&gt; describing the center’s research agenda.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-7065898602083423137?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7065898602083423137'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7065898602083423137'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2011/06/trust-researchers-to-lead-intel.html' title='TRUST Researchers to Lead Intel Security Center'/><author><name>Larry Rohrbough</name><uri>http://www.blogger.com/profile/01122887820002175089</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-8277636164610727192</id><published>2011-06-03T10:07:00.000-07:00</published><updated>2011-06-03T10:14:33.922-07:00</updated><title type='text'>Audio Captchas defeated</title><content type='html'>Stanford Professor &lt;a href="http://theory.stanford.edu/people/jcm/"&gt;John Mitchell&lt;/a&gt;, postdoctoral research &lt;a href="http://elie.im/"&gt;Elie Bursztein&lt;/a&gt; and their colleagues have developed a way to defeat the audio version of Captchas.  See &lt;a href="http://www.theregister.co.uk/2011/05/23/microsoft_yahoo_captchas_busted/"&gt;The Register&lt;/a&gt; and the &lt;a href="http://news.stanford.edu/news/2011/may/captcha-security-flaw-052311.html"&gt;Stanford News&lt;/a&gt; coverage.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-8277636164610727192?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8277636164610727192'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8277636164610727192'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2011/06/audio-captchas-defeated.html' title='Audio Captchas defeated'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-209850371788272409</id><published>2011-04-22T10:40:00.000-07:00</published><updated>2011-04-22T10:46:56.620-07:00</updated><title type='text'>Stephen Wicker on iOS user privacy</title><content type='html'>&lt;a href="http://wisl.ece.cornell.edu/wicker/"&gt;Professor Stephen Wicker&lt;/a&gt; was quoted in Network World's article "&lt;a href="http://www.networkworld.com/news/2011/042111-iphone-data-cornell.html?hpg1=bn"&gt;Cornell prof warns iPhone, iPad users: "We're selling our privacy&lt;/a&gt;" about the recently &lt;a href="http://www.guardian.co.uk/technology/2011/apr/20/iphone-tracking-prompts-privacy-fears"&gt;reported&lt;/a&gt; location logging by the iPhone and iPad.  The Network World article quotes Professor Wicker:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;"It is vitally important to recognize that cellular telephony is a surveillance technology, and that unless we openly discuss this surveillance capability and craft appropriate legal and technological limits to that capability, we may lose some or all of the social benefits of this technology, as well as a significant piece of ourselves," says Stephen Wicker, Cornell professor of electrical and computer engineering. "Most people don't understand that we're selling our privacy to have these devices."&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-209850371788272409?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/209850371788272409'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/209850371788272409'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2011/04/stephen-wicker-on-ios-user-privacy.html' title='Stephen Wicker on iOS user privacy'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-3383696079292418557</id><published>2011-02-26T16:36:00.000-08:00</published><updated>2011-02-26T16:47:47.602-08:00</updated><title type='text'>Doug Tygar on the LinkedIn outage in China</title><content type='html'>Bloomberg's February 25, 2011 article &lt;br /&gt;"&lt;a href="http://www.bloomberg.com/news/2011-02-25/linkedin-accessible-in-beijing-after-jasmine-disruption.html"&gt;LinkedIn Service Is Restored in Beijing After `Jasmine' 24-Hour Disruption&lt;/a&gt;" discusses how LinkedIn was blocked in China after a user posted comments about how "Tunisia’s Jasmine Revolution should spread to the Asian nation that’s been ruled by the Communist Party since 1949." The article quotes &lt;a href="http://www.truststc.org"&gt;TRUST's&lt;/a&gt; &lt;a href="http://www.truststc.org/people/directory/tygar"&gt;Doug Tygar&lt;/a&gt;:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;“Often, this is done as a sort of a warning signal -- sort of a shot across the bow,” said Doug Tygar, professor of computer science at the University of California at Berkeley. “A portion of that is symbolic.” &lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;The quote was also printed on page D-1 of the San Francisco Chronicle, "&lt;a href="http://www.sfgate.com/cgi-bin/article.cgi?f=%2Fc%2Fa%2F2011%2F02%2F25%2FMN7I1HUUFU.DTL"&gt;Business Report - The Chronicle with Bloomberg&lt;/a&gt;."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-3383696079292418557?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/3383696079292418557'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/3383696079292418557'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2011/02/doug-tygar-on-linkedin-outage-in-china.html' title='Doug Tygar on the LinkedIn outage in China'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-8393484816596000515</id><published>2011-02-23T16:33:00.000-08:00</published><updated>2011-02-23T16:40:07.835-08:00</updated><title type='text'>Cornell's Hakim Weatherspoon Awarded Sloan Fellowship</title><content type='html'>TRUST investigator and Cornell University &lt;a href="http://www.truststc.org/people/directory/hweather"&gt;Prof. Hakim Weatherspoon&lt;/a&gt; was named a recipient of the 2011 &lt;a href="http://www.sloan.org/fellowships"&gt;Sloan Research Fellowship&lt;/a&gt; of the &lt;a href="http://www.sloan.org/"&gt;Alfred P. Sloan Foundation&lt;/a&gt;.&lt;br /&gt;&lt;p&gt;Sloan Research Fellowships seek to stimulate fundamental research by early-career scientists and scholars of outstanding promise and are awarded yearly to researchers in recognition of distinguished performance and a unique potential to make substantial contributions to their field.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;A press release of the 2011 fellowship awards is available &lt;a href="http://www.sloan.org/assets/files/press_releases/apsloan_foundation_honors_young_scholars.pdf"&gt;here&lt;/a&gt;.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-8393484816596000515?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8393484816596000515'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8393484816596000515'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2011/02/cornells-hakim-weatherspoon-awarded.html' title='Cornell&apos;s Hakim Weatherspoon Awarded Sloan Fellowship'/><author><name>Larry Rohrbough</name><uri>http://www.blogger.com/profile/01122887820002175089</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-103287890433075086</id><published>2011-01-18T07:08:00.000-08:00</published><updated>2011-01-18T09:15:49.028-08:00</updated><title type='text'>Car Theft by Antenna</title><content type='html'>According to new research to be presented at the &lt;a href="http://www.isoc.org/isoc/conferences/ndss/11/"&gt;Network and Distributed System Security Symposium&lt;/a&gt; next month in San Diego, California, car thieves of the future might be able to get into a car and drive away without forced entry and without needing a physical key.&lt;br /&gt;&lt;br /&gt;Researchers successfully attacked eight car manufacturers' passive keyless entry and start systems—wireless key fobs that open a car's doors and start the engine by proximity alone. Because a car won't open or start if the signal from its key takes too long to arrive, the researchers devised a way to speed communication between their their antennas. They were able to keep the signals in analog format, which reduced their delay from microseconds to nanoseconds, making their attack more difficult to detect. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;David Wagner&lt;/b&gt;,professor of computer science at the University of California at Berkeley who has studied the cryptographic systems used in keyless entry systems, says the research "should help car manufacturers improve auto security systems in the future." Wagner doesn't think the research ought to make car owners anxious. "There are probably easier ways to steal cars," he says. But, he adds, a "nasty aspect of high-tech car theft" is that "it doesn't leave any sign of forced entry," so if a thief did use this method to steal a car, he says, it might be hard for police and insurance companies to get sufficient evidence of what happened. Wagner believes that manufacturers, police, and insurance companies all need to prepare for this eventuality.&lt;br /&gt;&lt;br /&gt;See full article in &lt;a href="http://www.technologyreview.com/computing/27037/?mod=chthumb"&gt; Technology Review&lt;/a&gt;, published by MIT.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-103287890433075086?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/103287890433075086'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/103287890433075086'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2011/01/car-theft-by-antenna.html' title='Car Theft by Antenna'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-525049625082188358</id><published>2011-01-07T16:34:00.000-08:00</published><updated>2011-01-07T16:38:59.262-08:00</updated><title type='text'>Commerce announces new shop to oversee online security</title><content type='html'>&lt;a href="http://www.nextgov.com"&gt;NextGov.com's&lt;/a&gt; article "&lt;a href="http://www.nextgov.com/nextgov/ng_20110107_2695.php?oref=topstory"&gt;Commerce announces new shop to oversee online security&lt;/a&gt;" covers &lt;a href="http://www.commerce.gov/about-commerce/commerce-leadership/secretary-gary-locke"&gt;Commerce Secretary Gary Locke's&lt;/a&gt; announcement that&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;The Obama administration is creating an office that will coordinate with the private sector to establish a secure pathway for people, organizations and computer programs to execute online transactions...&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Locke spoke at an industry forum sponsored by many groups, including &lt;a href="http://www.truststc.org"&gt;TRUST&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-525049625082188358?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/525049625082188358'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/525049625082188358'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2011/01/commerce-announces-new-shop-to-oversee.html' title='Commerce announces new shop to oversee online security'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-888365300621075476</id><published>2010-11-16T11:47:00.000-08:00</published><updated>2010-11-16T11:52:39.632-08:00</updated><title type='text'>White House Honors Vanderbilt's Bradley Malin</title><content type='html'>TRUST investigator and Vanderbilt University Professor &lt;a href="http://www.truststc.org/people/directory/malin"&gt;Bradley Malin&lt;/a&gt; was named a recipient of the &lt;b&gt;Presidential Early Career Award for Scientists and Engineers&lt;/b&gt;, the highest honor bestowed by the United States government on science and engineering professionals in the early stages of their research careers.&lt;br /&gt;&lt;br /&gt;Nominated by the National Institutes of Health and Department of Health and Human Services, Prof. Malin was recognized as one of the Nation's "most meritorious scientists and engineers whose early accomplishments show the greatest promise for assuring America's preeminence in science and engineering and contributing to the awarding agencies' missions."  The award includes a multi-year research grant.&lt;br /&gt;&lt;br /&gt;The press release from the Office of Science and Technology Policy (OSTP), which includes the full list of recipients, is available &lt;a href="http://www.whitehouse.gov/administration/eop/ostp/pressroom/11052010"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-888365300621075476?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/888365300621075476'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/888365300621075476'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2010/11/white-house-honors-vanderbilts-bradley.html' title='White House Honors Vanderbilt&apos;s Bradley Malin'/><author><name>Larry Rohrbough</name><uri>http://www.blogger.com/profile/01122887820002175089</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-758254698267480105</id><published>2010-10-21T12:06:00.000-07:00</published><updated>2010-10-21T12:30:14.641-07:00</updated><title type='text'>"Fabric" To Weave Security into Code</title><content type='html'>Cornell computer science faculty, &lt;b&gt;Fred Schneider&lt;/b&gt; and Andrew Meyers are developing a new computer platform, dubbed &lt;i&gt;Fabric&lt;/i&gt;, that offers a way to build security into computer systems from the start by incorporating security in the language used to write the programs.&lt;br /&gt;&lt;br /&gt;Professor Schneider states that until now, computer security has been reactive; when hackers discover a way in, we patch it.&lt;blockquote&gt;"Our defenses improve only after they have been successfully penetrated," he explained.&lt;/blockquote&gt;Fabric's programming language, an extension of the widely used Java language, builds in security as the program is written. Fabric is still a prototype, being tested on a database of Cornell computer science students.&lt;br /&gt;&lt;br /&gt;Schneider and Myers plan to scale it up for very large distributed systems, provide for more complex security restrictions on objects and enable "mobile code" — programs that can reside on one node of a network and be run on another with assurance that they are safe and do what they claim to do. And perhaps most important (and perhaps hardest), they hope to provide formal mathematical proof that a system is really secure.&lt;br /&gt;&lt;br /&gt;See article in &lt;br /&gt;&lt;a href="http://www.drdobbs.com/java/227900404"&gt; Dr. Dobb's, The World of Software Development&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-758254698267480105?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/758254698267480105'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/758254698267480105'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2010/10/fabric-to-weave-security-into-code.html' title='&quot;Fabric&quot; To Weave Security into Code'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-4313387102381843387</id><published>2010-09-29T01:23:00.000-07:00</published><updated>2010-09-29T02:07:50.920-07:00</updated><title type='text'>UC Berkeley's Dawn Song Awarded MacArthur Fellowship</title><content type='html'>TRUST researcher and UC Berkeley Professor &lt;a href="http://www.truststc.org/people/directory/dawnsong"&gt;Dawn Song&lt;/a&gt; was named a &lt;a href="http://www.macfound.org/site/c.lkLXJ8MQKrH/b.959463/k.9D7D/Fellows_Program.htm"&gt;2010 MacArthur Fellow&lt;/a&gt; by the &lt;a href="http://www.macfound.org/"&gt;John D. and Catherine T. MacArthur Foundation&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The so-called "genius award" is given to individuals "who have shown extraordinary originality and dedication in their creative pursuits and a marked capacity for self-direction" as well as "exceptional creativity, promise for important future advances based on a track record of significant accomplishment, and potential for the fellowship to facilitate subsequent creative work."  Prof. Song, one of 23 recipients of this year's award, was cited for her work in applying "rigorous theoretical methods to understand the deep interactions of software, hardware, and networks that make computer systems vulnerable to attack or interference."&lt;br /&gt;&lt;br /&gt;Details on Prof. Song's work and her award are available &lt;a href="http://www.macfound.org/site/c.lkLXJ8MQKrH/b.6241285/k.E229/Dawn_Song.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-4313387102381843387?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4313387102381843387'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4313387102381843387'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2010/09/uc-berkeleys-dawn-song-awarded.html' title='UC Berkeley&apos;s Dawn Song Awarded MacArthur Fellowship'/><author><name>Larry Rohrbough</name><uri>http://www.blogger.com/profile/01122887820002175089</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-4482229892504970770</id><published>2010-09-21T09:22:00.000-07:00</published><updated>2010-09-21T12:22:05.294-07:00</updated><title type='text'>TRUST Autumn 2010 Conference: Nov. 10-11, 2010</title><content type='html'>The next TRUST Conference will be held November 10-11, 2010 at the &lt;a href="http://engineering.stanford.edu/visit/huang_center/index.html"&gt;Jen-Hsun Huang Engineering Center&lt;/a&gt; on the campus of &lt;a href="http://www.stanford.edu/"&gt;Stanford University&lt;/a&gt;.  The conference will run from approximately 8:00 AM to 5:00 PM both November 10 and 11.&lt;br /&gt;&lt;br /&gt;This event will provide attendees with an opportunity to hear firsthand about the work of TRUST faculty and students-specifically activities that:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Advance a leading-edge research agenda to improve the state-of-the art in cyber security and critical infrastructure protection;&lt;br /&gt;&lt;br&gt;&lt;li&gt;Develop robust education and diversity plans to teach the next generation of computer scientists, engineers, and social scientists; and&lt;br /&gt;&lt;br&gt;&lt;li&gt;Pursue knowledge transfer opportunities to transition TRUST results to end users within industry and the government.&lt;/ul&gt;&lt;br /&gt;For more information, see the &lt;a href="http://www.truststc.org/conferences/10/FallConference"&gt;TRUST Autumn 2010 Conference Page&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-4482229892504970770?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4482229892504970770'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4482229892504970770'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2010/09/next-trust-conference-will-be-held.html' title='TRUST Autumn 2010 Conference: Nov. 10-11, 2010'/><author><name>Larry Rohrbough</name><uri>http://www.blogger.com/profile/01122887820002175089</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-3475457950347356009</id><published>2010-09-20T10:46:00.000-07:00</published><updated>2010-09-20T10:51:13.904-07:00</updated><title type='text'>WSJ: "J.P. Morgan Wrestles Web Snarl</title><content type='html'>UC Berkeley Professor &lt;a href="http://www.tygar.net"&gt;Doug Tygar&lt;/a&gt; was quoted in a September 15, 2010 Wall Street Journal website article, "&lt;a href="http://online.wsj.com/article/SB10001424052748703743504575493752756026016.html?mod=googlenews_wsj"&gt;J.P. Morgan Wrestles Web Snarl&lt;/a&gt;."  The article discusses an outage at &lt;a href="http://chase.com"&gt;chase.com&lt;/a&gt;.  Professor Tygar is quotes as stating, ""if they have so much trouble with a software failure, what happens with an actual attack?"&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-3475457950347356009?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/3475457950347356009'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/3475457950347356009'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2010/09/ws-jp-morgan-wrestles-web-snarl.html' title='WSJ: &quot;J.P. Morgan Wrestles Web Snarl'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-4244806645719843732</id><published>2010-08-18T10:07:00.000-07:00</published><updated>2010-08-18T10:19:49.309-07:00</updated><title type='text'>UC Berkeley's Pamela Samuelson wins IP3 Award</title><content type='html'>UC Berkeley Law Professor and renowned scholar &lt;b&gt;Pamela Samuelson&lt;/b&gt; is one of four winners of this year's IP3 Award from the Washington-based public interest group &lt;i&gt;Public Knowledge&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;As a director of the Berkeley Center for Law &amp; Technology, Samuelson is being acknowledged for her work in information policy, particularly in such areas as privacy, copyright, freedom of expression, intellectual property and consumer protection.&lt;blockquote&gt;"Public Knowledge has been the most important voice for public-spirited intellectual property and Internet policy,” says Samuelson. “I’m pleased that this organization believes I have made contributions to these same policies worthy of being named to this award."&lt;/blockquote&gt;&lt;br /&gt;See more in the&lt;a href="http://www.law.berkeley.edu/9218.htm"&gt; Berkeley Law News Archive.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-4244806645719843732?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4244806645719843732'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4244806645719843732'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2010/08/uc-berkeleys-pamela-samuelson-wins-ip3.html' title='UC Berkeley&apos;s Pamela Samuelson wins IP3 Award'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-7405761376455210211</id><published>2010-08-10T10:59:00.000-07:00</published><updated>2010-08-10T11:17:19.350-07:00</updated><title type='text'>Web add-ons compromise 'private browsing'</title><content type='html'>A &lt;a href="http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html"&gt; study&lt;/a&gt; by &lt;b&gt;Dan Boneh&lt;/b&gt; of Stanford University claims that many browser add-ons or website security measures stop the 'private browsing' mode from working correctly.&lt;br /&gt;&lt;br /&gt;Boneh and team examined the private browsing functions on Mozilla's Firefox, Microsoft Internet Explorer, Google Chrome and Apple's Safari and discovered all four were affected.  Moreover, they discovered that all browsers retained the generated key pair even after private browsing ends which could  leak the site's identity to an attacker.&lt;blockquote&gt;"We found that private browsing was more popular at adult web sites than at gift shopping sites and news sites, which shared a roughly equal level of private browsing use," Boneh said in the report.&lt;br /&gt;&lt;br /&gt;"This observation suggests that some browser vendors may be mischaracterising the primary use of the feature when they describe it as a tool for buying surprise gifts."&lt;/blockquote&gt;&lt;br /&gt;Boneh and his researchers say they believe they are the first to show that 'private browsing' can be compromised.&lt;br /&gt;&lt;br /&gt;See full article at &lt;a href="http://www.pcadvisor.co.uk/news/index.cfm?newsid=3234529"&gt;PC Advisor&lt;/a&gt;. Related articles appear at &lt;a href="http://www.thinq.co.uk/2010/8/6/browser-porn-modes-exposed/"&gt; THIN!.co.uk&lt;/a&gt; and &lt;a href="http://www.bbc.co.uk/news/technology-10891355"&gt; BBC NEWS&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-7405761376455210211?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7405761376455210211'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7405761376455210211'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2010/08/web-add-ons-compromise-private-browsing.html' title='Web add-ons compromise &apos;private browsing&apos;'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-1971979316483844825</id><published>2010-06-28T10:33:00.000-07:00</published><updated>2010-06-28T10:45:08.870-07:00</updated><title type='text'>Patents seen as low priority for software firms</title><content type='html'>Tom Abate's San Francisco Chronicle article, "&lt;a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2010/06/22/BU6J1E37U0.DTL"&gt;Patents seen as low priority for software firms&lt;/a&gt;" discusses the paper written by Stuart J. H. Graham, Robert P. Merges, &lt;a href="http://people.ischool.berkeley.edu/%7Epam/"&gt;Pamela Samuelson&lt;/a&gt; and Ted M. Sichelman, "&lt;a href="http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1429049"&gt;High Technology Entrepreneurs and the Patent System: Results of the 2008 Berkeley Patent Survey&lt;/a&gt;."&lt;br /&gt;&lt;br /&gt;The article quotes Pamela Samuelson:&lt;br /&gt;"More than 80 percent of the biotech, medical device and hardware firms we surveyed have or have applied for patents. . . About two-thirds of software firms have no patents and have not applied for any."&lt;br /&gt;&lt;br /&gt;The study is also discussed by &lt;a href="http://www.physorg.com/news196533327.html"&gt;Phyorg&lt;/a&gt;,  &lt;a href="http://broadbandbreakfast.com/2010/06/study-patents-not-a-top-priority-at-software-and-internet-start-ups/"&gt;Broadbandbreakfast&lt;/a&gt; and &lt;a href="http://www.canadaviews.ca/2010/06/25/survey-challenges-popular-beliefs-about-high-tech-startup-patents/"&gt;Canadaviews&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-1971979316483844825?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/1971979316483844825'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/1971979316483844825'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2010/06/patents-seen-as-low-priority-for.html' title='Patents seen as low priority for software firms'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-7081377791024909062</id><published>2010-05-31T23:19:00.000-07:00</published><updated>2010-05-31T23:36:46.587-07:00</updated><title type='text'>Vanderbilt medical researchers, engineers play major role in new national center established to secure the privacy of electronic health information</title><content type='html'>The Vanderbilt University News Network released an article on Friday announcing the $15 million awarded to create a new center for health information and privacy.  The center, headquartered at the University of Illinois, will include researchers from Vanderbilt University; University of California, Berkeley; Carnegie Mellon University; Dartmouth College; Harvard Medical School; Johns Hopkins University; Northwestern Memorial Hospital; Stanford University; University of Massachusetts, Amherst and the University of Washington. &lt;br /&gt;&lt;br /&gt;It is one of four health care research centers established and funded for four years with American Recovery and Reinvestment Act of 2009 funds as part of the $60 million &lt;i&gt;Strategic Healthcare Information Technology Advanced Research Projects on Security&lt;/i&gt;  (SHARPS) program.&lt;br /&gt;&lt;blockquote&gt;“Our participation in the new SHARPS center reflects the fact that Vanderbilt has become highly visible in the field of health care security and privacy,” said &lt;b&gt;Janos Sztipanovits&lt;/b&gt;, director of the Institute for Software Integrated Systems (ISIS) at Vanderbilt’s School of Engineering.&lt;/blockquote&gt;Vanderbilt has gained experience in this area through its participation in the &lt;i&gt;TRUST Science and Technology Center&lt;/i&gt; founded in 2006 by the National Science Foundation. The $40 million &lt;b&gt;TRUST Center&lt;/b&gt;, whose core members are the University of California, Berkeley; Carnegie Mellon University; Cornell University; Stanford University; and Vanderbilt University, is one of the nation’s leading research consortiums focusing on the scientific foundations of system security and privacy. Vanderbilt has headed up TRUST’s health-care-related program.&lt;br /&gt;&lt;br /&gt;See full article at &lt;a href="http://sitemason.vanderbilt.edu/news/releases/2010/05/28/vanderbilt-medical-researchers-engineers-play-major-role-in-new-national-center-established-to-secure-the-privacy-of-electronic-health-information.116663"&gt; VUCast&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-7081377791024909062?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7081377791024909062'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7081377791024909062'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2010/05/vanderbilt-medical-researchers.html' title='Vanderbilt medical researchers, engineers play major role in new national center established to secure the privacy of electronic health information'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-6204529988074042568</id><published>2010-05-20T16:41:00.000-07:00</published><updated>2010-05-20T16:45:42.119-07:00</updated><title type='text'>Andrew Myers net radio interview: "Build security into applications"</title><content type='html'>Cornell Associate Professor &lt;a href="http://www.truststc.org/people/directory/andru"&gt;Andrew Myers&lt;/a&gt; was interviewed on FederalNewsRadio about "&lt;a href="http://www.federalnewsradio.com/?sid=1960702&amp;nid=56"&gt;Build security into applications&lt;/a&gt;":&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;"His theme: Software developers generally go about writing programs all wrong, when it comes to cyber security."&lt;br /&gt;&lt;br /&gt;&lt;p&gt;"He has come up with a concept called 'secure by design and construction' that designs out cybersecurity vulnerabilities."&lt;br /&gt;&lt;br /&gt;&lt;p&gt;"He recently presented his research to the House Subcommittee on Science and Technology."&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-6204529988074042568?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6204529988074042568'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6204529988074042568'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2010/05/andrew-myers-net-radio-interview-build.html' title='Andrew Myers net radio interview: &quot;Build security into applications&quot;'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-7768324025716607317</id><published>2010-04-13T14:57:00.000-07:00</published><updated>2010-04-13T15:22:41.741-07:00</updated><title type='text'>Keeping Medical Data Private</title><content type='html'>Researchers at Vanderbilt University have developed an algorithm that simultaneously protects privacy of patients while allowing medical records to be used for research on the genetics of disease.&lt;br /&gt;&lt;br /&gt;The new method, published online April 12 in the &lt;i&gt; Proceedings of the National Academy of Sciences&lt;/i&gt;, simply disguises parts of the medical history data that are not relevant to a geneticist’s specific research question using an algorithm that looks through health records and makes some aspects of them more general. &lt;br /&gt;&lt;blockquote&gt; “We’re hoping that it’s a game-changer,” says &lt;b&gt;Bradley Malin&lt;/b&gt;, a biomedical informatics specialist from Vanderbilt University in Nashville who helped develop the method. The problem is, it's not all that difficult to follow a specific set of codes backward and identify a person, says Malin.&lt;/blockquote&gt;&lt;br /&gt;See articles in &lt;a href="http://www.sciencenews.org/view/generic/id/58248/title/Hiding_patients_in_plain_sight"&gt; Science News&lt;/a&gt; and MIT's &lt;a href="http://www.technologyreview.com/biomedicine/25061/page2/"&gt; Technology Review&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-7768324025716607317?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7768324025716607317'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7768324025716607317'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2010/04/keeping-medical-data-private.html' title='Keeping Medical Data Private'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-8313418730380390347</id><published>2010-04-12T10:52:00.000-07:00</published><updated>2010-04-12T11:37:08.166-07:00</updated><title type='text'>Loose Clicks Sink Ships</title><content type='html'>Since it is possible to analyze audio recordings of keystrokes, computer scientists have been able to reconstruct accurate transcripts of what is being typed, including passwords.  By contrast with more sophisticated types of espionage, it is very easy to do.  All that is needed is a cheap microphone and a desktop computer.&lt;br /&gt;&lt;br /&gt;While past attempts at writing software to decipher the recorded keyboard sounds have only been at most 80% successful, &lt;b&gt;Doug Tygar&lt;/b&gt; and colleagues at the University of California, Berkeley have developed software that achieves 96% accuracy. The software can decode anything, including scrambled ten-character passwords.&lt;br /&gt;&lt;br /&gt;Dr. Tygar suggests simply turning up the radio to thwart these auditory invasions. However, since background noise will be ultimately overcome with more sophisticated recording, Tygar recommends that typed passwords be phased out, to be replaced with biometric checks or multiple types of authorization that combine a password with silent verification (e.g., clicking on a pre-selected image in an array of images).&lt;br /&gt;&lt;br /&gt;See full article in &lt;a href="http://www.economist.com/science-technology/technology-monitor/displaystory.cfm?story_id=15894494"&gt; The Economist&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-8313418730380390347?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8313418730380390347'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8313418730380390347'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2010/04/loose-clicks-sink-ships.html' title='Loose Clicks Sink Ships'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-8498347769262695064</id><published>2010-04-09T09:27:00.000-07:00</published><updated>2010-04-09T09:35:44.779-07:00</updated><title type='text'>"How Lenders Overlook the Warning Signs of ID Theft"</title><content type='html'>Brad Stone's NY Times Blog entry "&lt;a href="http://bits.blogs.nytimes.com/2010/04/07/how-lenders-overlook-the-warning-signs-of-id-theft/"&gt;How Lenders Overlook the Warning Signs of ID Theft&lt;/a&gt;" discusses &lt;a href="http://www.law.berkeley.edu/php-programs/faculty/facultyProfile.php?facID=6494"&gt;Chris Hoofnagle's&lt;/a&gt; paper "&lt;a href="http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1585564"&gt;Internalizing Identity Theft&lt;/a&gt;.  The abstract for that paper says:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;"Why has identity theft remained so prevalent, in light of the development of ever more sophisticated fraud detection tools? Identity theft remains at 2003 levels – 9.9 million Americans fell victim to the crime in 2009."&lt;br /&gt;&lt;br /&gt;&lt;p&gt;"One faction explains the identity theft as a problem of a lack of control over personal information. Another argues conversely that identity theft may be caused by a lack of access to personal information by credit grantors. This article presents data from a small sample of identity theft victims to explore a different dimension of the crime, one that suggests alternative interventions."&lt;br /&gt;&lt;br /&gt;&lt;p&gt;"Drawing upon victim and impostor data now accessible because of updates to the Fair Credit Reporting Act, the data show that identity theft impostors supply obviously erroneous information on applications that is accepted as valid by credit grantors. Thus, the problem does not necessarily lie in control nor in more availability of personal information, but rather in the risk tolerances of credit grantors. An analysis of incentives in credit granting elucidates the problem: identity theft remains so prevalent because it is less costly to tolerate fraud. Adopting more aggressive and expensive anti-fraud measures is extremely costly and jeopardizes customer acquisition efforts."&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Stone's article gives an overview of how lenders approved credit applications, "one victim found four of six fraudulent applications submitted in her name contained the wrong address; two contained the wrong phone number and one the wrong date of birth."&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Stone's article was also picked up by &lt;a href="http://yro.slashdot.org/story/10/04/09/1155259/Why-Lenders-Overlook-Warning-Signs-of-ID-Theft"&gt;Slashdot&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-8498347769262695064?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8498347769262695064'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8498347769262695064'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2010/04/how-lenders-overlook-warning-signs-of.html' title='&quot;How Lenders Overlook the Warning Signs of ID Theft&quot;'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-2854802520135766286</id><published>2010-04-01T17:09:00.000-07:00</published><updated>2010-04-01T17:35:41.836-07:00</updated><title type='text'>'MULE' Prototype Uses Location for Authentication</title><content type='html'>Researchers at CMU (Carnegie Mellon University) have constructed a location-based encryption model for protecting data in lost or stolen laptops with little or no user interaction or IT administrative overhead.&lt;br /&gt;&lt;br /&gt;The so-named Mobile User Location Specific Encryption (MULE) method encrypts only sensitive files on a user's laptop.&lt;br /&gt;&lt;br /&gt;In a paper entitled &lt;a href="http://sparrow.ece.cmu.edu/group/pub/studer_wisec10.pdf"&gt; Mobile User Location-specific Encryption (MULE): Using Your Office as Your Password&lt;/a&gt; researchers say &lt;blockquote&gt;Our goal is to remove user effort associated with encryption technology while achieving the same or better security comparedto traditional password-based approaches. For example, with MULE, a user can securely store encrypted copies of bank records and tax returns on a laptop, and automatically gain access when opening those files in the home office, CMU CyLab technical director Adrian Perrig and CMU graduate student Ahren Studer write in their paper on MULE. "After a thief steals the laptop, the only way to recover the files is to break into the user's home."&lt;/blockquote&gt;&lt;br /&gt;See &lt;i&gt;Tech Center: Insider Threat&lt;/i&gt; article in &lt;a href="http://www.darkreading.com/insiderthreat/security/encryption/showArticle.jhtml?articleID=224201102"&gt; Dark Reading &lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-2854802520135766286?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2854802520135766286'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2854802520135766286'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2010/04/mule-prototype-uses-location-for.html' title='&apos;MULE&apos; Prototype Uses Location for Authentication'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-6632936029198270198</id><published>2010-02-09T10:26:00.000-08:00</published><updated>2010-02-09T16:39:53.604-08:00</updated><title type='text'>Security flaw exposed on Home Shopping Network</title><content type='html'>When a possible security flaw exposing customers of a large television shopping network to credit card fraud was encountered by a user, ABC's &lt;span style="font-style:italic;"&gt;7 On Your Side&lt;/span&gt; contacted computer security expert at UC Berkeley &lt;span style="font-weight:bold;"&gt; Doug Tygar&lt;/span&gt;, who suggested that they find out for themselves if her fears were founded.&lt;br /&gt;&lt;br /&gt;The customer tried the 'Shop by Remote' feature on Home Shopping Network but directed her order to be shipped to her sister's address and found she could do so without her sister even knowing about it. This result was brought back to Tygar. &lt;blockquote&gt;"I didn't believe it," he said. "I was shocked that you could do that, that such an obvious and large hole would be left open." &lt;/blockquote&gt;Tygar says requiring passwords is an industry standard. It is true that HSN requires both a user name and password when customers shop online.  However, neither are required with HSN's "Shop by Remote" feature.&lt;blockquote&gt;"I would imagine they would be able to deploy a password mechanism in a matter of days. It shouldn't take that much effort," Tygar said. &lt;/blockquote&gt;&lt;br /&gt;See full article at &lt;a href="http://abclocal.go.com/kgo/story?section=news/7_on_your_side&amp;id=7265660"&gt; 7 on Your Side &lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-6632936029198270198?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6632936029198270198'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6632936029198270198'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2010/02/security-flaw-exposed-on-home-shopping.html' title='Security flaw exposed on Home Shopping Network'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-2814065098694914245</id><published>2009-11-16T11:53:00.000-08:00</published><updated>2009-11-16T15:00:08.636-08:00</updated><title type='text'>Breaking the Botnet Code</title><content type='html'>UC Berkeley Professor &lt;b&gt; Dawn Song &lt;/b&gt; co-presented a talk on Malware and Bots at  the Association for Computing Machinery's &lt;a href="http://www.sigsac.org/ccs/CCS2009/index.shtml"&gt; Conference on Computer and Communications Security &lt;/a&gt; this week.&lt;br /&gt;&lt;br /&gt;Networks of compromised computers controlled by a central server, known as 'botnets' can be used to systematically spew spam, host malicious code, or flood a network to cut off its access to the Web. Researchers presented a tool at the conference that can decipher the structure and purpose of communications between a control server and its bots through automatic reverse engineering. The researchers parlayed the technique into a tool called &lt;i&gt;Dispatcher&lt;/i&gt; that will analyze botnet network communications and even inject new information into the communications stream.&lt;br /&gt;&lt;br /&gt;The researchers note that such automated tools are not yet needed for analyzing most malware since more than 90 percent of all botnets use easy-to-break encryption with their communications, making manual techniques rather easy and fast.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Yet botnets will continue to evolve, says UC Professor Song. "Botnet programs are becoming more complicated," she says. "They are using various obfuscation techniques and so on. So maybe manual analysis can work for now, but in the future, we will need better tools."&lt;/blockquote&gt;&lt;br /&gt;See article in &lt;a href="http://www.technologyreview.com/computing/23924/?a=f"&gt; Technology Review&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-2814065098694914245?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2814065098694914245'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2814065098694914245'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/11/breaking-botnet-code.html' title='Breaking the Botnet Code'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-7718635260030601993</id><published>2009-10-23T14:18:00.000-07:00</published><updated>2009-10-23T15:10:44.105-07:00</updated><title type='text'>UC Berkeley computer science professor and privacy expert, Doug Tygar,  consulted  about security flaws in CalJOBS website</title><content type='html'>When "CBS 5 Investigates" discovered a state-run website may be putting hundreds of thousands of Californians at risk of identity theft, they asked UC Berkeley Computer Science professor and privacy expert &lt;b&gt;Doug Tygar&lt;/b&gt; to take a look at a problem experienced by laid off worker Tom Diederich.&lt;br /&gt;&lt;br /&gt;Diederich had posted his resume on CalJOBS, the state's job site, as is required for getting unemployment benefits.  However, when Diederich logged back in to the site the next day, he saw someone else's information, including their name, where they live, email and phone number.  The next time, he got someone else's information and the following 5 or 6 times he logged in, he saw the same info about those other  people. &lt;blockquote&gt;Professor Tygar said, "I consider that to be a serious security breach." Moreover, Tygar was able to get into the site and look at other applicants' supposedly private data.  "I was able to access other people's personal information including their address, their phone numbers, email, personal details," Tygar said. Just by changing a few numbers in the URL, he was able to go in and change information on peoples' resumes.  "I would in fact have been able to go through and change that if I were a malicious attacker," he said.&lt;/blockquote&gt;&lt;br /&gt;The glitch that allowed Diederich to click on his bookmark and read other peoples' resumes appears to be fixed. EDD said their web site team is now following up on the other possible vulnerabilities identified by CBS 5 Investigates. They say if such vulnerabilities are found, they will correct them immediately.&lt;br /&gt;&lt;br /&gt;See full story at &lt;a href="http://cbs5.com/local/caljobs.security.breach.2.1265861.html"&gt; CBS News&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-7718635260030601993?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7718635260030601993'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7718635260030601993'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/10/uc-berkeley-computer-science-professor.html' title='UC Berkeley computer science professor and privacy expert, Doug Tygar,  consulted  about security flaws in CalJOBS website'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-5086444070104266377</id><published>2009-10-23T13:59:00.000-07:00</published><updated>2009-10-23T14:16:44.990-07:00</updated><title type='text'>UC Berkeley Professor David Wagner contracted by the state to investigate voting logs</title><content type='html'>The state of California is conducting a months-long investigation into audit logs inside the state's electronic voting systems after reports of serious problems with the logs, even to the point where an election official or someone else could delete votes while leaving no electronic trail of such action.&lt;br /&gt;&lt;br /&gt;According to Secretary of State Debra Bowen, the investigation is examining what the audit logs actually record and whether they can be easily altered or deleted. Bowen, appearing at an event concerning an open source voting project in development, told &lt;i&gt;Threat Level&lt;/i&gt; that the state had contracted with &lt;b&gt;David Wagner&lt;/b&gt;, a computer scientist with the University of California at Berkeley to investigate what the logs on the Premier/Diebold e-voting system, as well as every other voting system used in California, do and do not record.&lt;br /&gt;&lt;br /&gt;See full article in &lt;a href="http://www.wired.com/threatlevel/2009/10/audit-log/"&gt; THREAT LEVEL&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-5086444070104266377?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/5086444070104266377'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/5086444070104266377'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/10/uc-berkeley-professor-david-wagner.html' title='UC Berkeley Professor David Wagner contracted by the state to investigate voting logs'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-3563843688289202155</id><published>2009-09-23T10:58:00.000-07:00</published><updated>2009-09-23T11:32:20.947-07:00</updated><title type='text'>TRUST Executive Director at launch of UK's new cybersecurity center</title><content type='html'>The United Kingdom's lead center for cyber security research opens today at Queen's University Belfast. The &amp;pound;30 million Centre for Secure Information Technologies (CSIT) will become the UK's principal center for the development of technology to combat malicious cyber attacks and is one of the first Innovation and Knowledge Centres (IKCs) created in the UK.&lt;br /&gt;&lt;br /&gt;Attendance at the Centre's launch of some of the most respected national and international figures in the field of cyber-security, including &lt;b&gt;&lt;i&gt;Larry Rohrbough&lt;/b&gt;&lt;/i&gt;, Chief Executive of TRUST, the United States' major center in the area of cyber-security at the University of California at Berkeley, highlights the significance of the new Centre to the global communications and IT industries.&lt;br /&gt;&lt;br /&gt;Professor John McCanny, CSIT principal investigator says&lt;blockquote&gt;"The approach adopted within CIST contrasts with the more conventional way academic research is undertaken. Our starting points tend to be larger "mission-driven" projects involving sizeable teams for which ambitious and challenging end goals have been identified".&lt;/blockquote&gt;&lt;br /&gt;See press release at &lt;a href="http://www.eurekalert.org/pub_releases/2009-09/qub-uc092309.php"&gt; EurekAlert!&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-3563843688289202155?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/3563843688289202155'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/3563843688289202155'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/09/trust-executive-director-at-launch-of.html' title='TRUST Executive Director at launch of UK&apos;s new cybersecurity center'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-366999487821578489</id><published>2009-08-26T14:15:00.000-07:00</published><updated>2009-08-26T15:16:33.928-07:00</updated><title type='text'>UC Berkeley Professor Ruzena Bajcsy  receives Technical Leadership Award</title><content type='html'>The winner of the Anita Borg Technical Leadership Award, awarded to a woman that has inspired the women's technology community through outstanding technological and social contributions, is &lt;b&gt;&lt;i&gt;Ruzena Bajcsy&lt;/b&gt;&lt;/i&gt;, Professor of Electrical Engineering at the University of California, Berkeley as well as Director Emerita of the Center for Information Technology Research in the Interest of Society (CITRIS). Dr. Bajcsy has spearheaded new research fields, guided national policy regarding social issues and lead the computing community in addressing them.&lt;br /&gt;&lt;br /&gt;See press release at &lt;a href="http://www.marketwatch.com/story/anita-borg-institute-announces-the-2009-anita-borg-social-impact-technical-leadership-and-denice-denton-emerging-leader-award-winners-2009-08-26"&gt; MarketWatch&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-366999487821578489?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/366999487821578489'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/366999487821578489'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/08/uc-berkeley-professor-ruzena-bajcsy.html' title='UC Berkeley Professor Ruzena Bajcsy  receives Technical Leadership Award'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-6933333727390637352</id><published>2009-08-12T08:25:00.000-07:00</published><updated>2009-08-12T08:59:45.901-07:00</updated><title type='text'>Sequoia e-voting machine commandeered by clever attack</title><content type='html'>Using a method known as return-oriented programming, computer scientists have figured out how to trick a widely used electronic voting machine machine into altering tallies by bypassing measures that are supposed to prevent unauthorized code from running on it.&lt;br /&gt;&lt;br /&gt;The &lt;b&gt;Sequoia AVC Advantage&lt;/b&gt; machine is programmed to execute code only when it's stored on read-only memory chips that are difficult to install and remove. By expressly forbidding running code in random access memory, the intention was to make it impossible for attackers to inject malicious programs that might compromise the integrity of an election.&lt;br /&gt;&lt;br /&gt;However, a computer science research team from Princeton, UC San Diego and the University of Michigan succeeded with an attack by reverse engineering first the hardware on a legally purchased Sequoia AVC Advantage and then also reverse engineer the software it ran by analyzing the ROM. The research was presented this week at the &lt;a href="http://www.usenix.org/event/evtwote09/"&gt; 2009 Electronic Voting Technology Workshop/Workshop on Trustworthy Elections&lt;/a&gt;.&lt;br /&gt;&lt;blockquote&gt;"It's excellent research," said David Wagner, a computer scientist from the University of California at Berkeley who attended the conference. "The research is significant because it illustrates that attacks get better over time and it shows just how difficult it is to protect paperless voting systems." ®&lt;/blockquote&gt;&lt;br /&gt;See article in &lt;a href="http://www.theregister.co.uk/2009/08/12/sequoia_evoting_machine_felled/"&gt; &lt;i&gt;The Register&lt;/i&gt;&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-6933333727390637352?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6933333727390637352'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6933333727390637352'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/08/sequoia-e-voting-machine-commandeered.html' title='Sequoia e-voting machine commandeered by clever attack'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-6504171294382875445</id><published>2009-07-29T09:05:00.000-07:00</published><updated>2009-07-29T09:22:10.494-07:00</updated><title type='text'>Creating the New Cybersecurity Pro;  Interview with Cornell Computer Science Professor Fred Schneider</title><content type='html'>Samuel B. Eckert Professor of Computer Science at Cornell University &lt;b&gt;Fred Schneider&lt;/b&gt; believes the future of the IT profession is handicapped by a shortage of academics to provide the training for needed IT security skills.&lt;br /&gt;&lt;br /&gt;In an interview with GovInfoSecurity.com, Schneider contends that to produce not only the teachers, but the practitioners themselves, American universities need to create innovative graduate-level programs that provide training that encompasses not only an understanding of IT security technologies, but an understanding of &lt;i&gt;why&lt;/i&gt; the technology is needed as well. &lt;br /&gt;&lt;br /&gt;Schneider, also a member of the federal government's Information Security and Privacy Advisory Board and co-chair of Microsoft's Trustworthy Computing Academic Advisory Board, says&lt;blockquote&gt; "In the longer term, when you make cybersecurity technology decisions, you want to make it within the context of things like knowing its effect on privacy, knowing whether the economics of the situation support the kinds of changes you are making and understanding about business models." &lt;/blockquote&gt; &lt;br /&gt;See full story and interview transcriptin &lt;a href="http://www.govinfosecurity.com/articles.php?art_id=1657"&gt; GovInfoSecurity.com&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-6504171294382875445?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6504171294382875445'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6504171294382875445'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/07/creating-new-cybersecurity-pro.html' title='Creating the New Cybersecurity Pro;  Interview with Cornell Computer Science Professor Fred Schneider'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-2940817654499039262</id><published>2009-07-22T08:51:00.000-07:00</published><updated>2009-07-22T09:03:12.753-07:00</updated><title type='text'>Academic: Wireless sensors can easily measure caloric intake</title><content type='html'>Shankar Sastry, Dean of Engineering at the University of California Berkeley, was recently interviewed along with Senior Director of Manhattan Research, Monica Levy,  by the California Healthcare Foundation's iHealthBeat. Both Sastry and Levy discuss the current state and the promise of wireless-enabled healthcare tools.&lt;blockquote&gt;“The cell phone is perfect because it’s like a wrist watch you carry around, I think the idea of having access to electronic medical records is transformational in that it changes electronic medical records to be personal health records,” Sastry said. ”So I think that going forward there will be a huge consumer push to be able to both record and analyze data and the cell phones are gradually becoming not just a place for repository and also for analyzing data, but also as a distributive sensor network in the sense that the cell phone can interrogate other sensors which are attached to your body.” &lt;br /&gt;&lt;/blockquote&gt;&lt;blockquote&gt;“It’s reasonably easy for us to measure the [caloric] in-take — the out-take has always been way, way difficult, partly because we have such different metabolic rates,” Sastry said. “But I do think with the sensing though you do get a handle on those metabolic rates. So That I think is huge: To be able to then get sense of how much you are burning up in addition to how much you are taking in.”&lt;/blockquote&gt;&lt;br /&gt;See more at &lt;a href="http://mobihealthnews.com/3360/academic-wireless-sensors-can-easily-measure-caloric-intake/"&gt; mobilehealthnews.com&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-2940817654499039262?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2940817654499039262'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2940817654499039262'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/07/academic-wireless-sensors-can-easily.html' title='Academic: Wireless sensors can easily measure caloric intake'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-3839855156005844313</id><published>2009-06-15T14:38:00.000-07:00</published><updated>2009-06-15T15:25:34.114-07:00</updated><title type='text'>Dr. Ruzena Bajcsy  to receive   HP Innovation Award</title><content type='html'>Dr. Ruzena Bajcsy, EECS Professor at the University of California, Berkeley, was among  Professors selected from around the world to receive an award as part of the second annual HP Labs Innovation Research Program.&lt;br /&gt;&lt;br /&gt;The Program is designed to create opportunities for colleges, universities and research institutes for conducting breakthrough collaborative research with HP. Given the significant contributions achieved in last year's program, which includes 61 published papers and 13 invention disclosures, HP extended a second year of funding to 31 professors in 2009.&lt;br /&gt;&lt;br /&gt;Awardees will work with HP Labs' researchers on fundamental research areas like intelligent infrastructure, immersive interaction and cloud computing, which includes social computing.&lt;br /&gt;&lt;br /&gt;See complete article at &lt;a href="http://www.tradingmarkets.com/.site/news/Stock%20News/2374323/"&gt; TRADINGMARKETS.COM.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-3839855156005844313?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/3839855156005844313'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/3839855156005844313'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/06/dr-ruzena-bajcsy-to-receive-hp.html' title='Dr. Ruzena Bajcsy  to receive   HP Innovation Award'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-2759506997963725035</id><published>2009-06-09T09:29:00.000-07:00</published><updated>2009-06-09T09:41:19.723-07:00</updated><title type='text'>National cyber security: Cornell's Fred Schneider will testify  before Congress</title><content type='html'>Cornell University Computer Science Professor &lt;b&gt;Fred Schneider&lt;/b&gt;, a noted expert on cyber security, will testify at the Hearing on Cyber Security Research and Development on Wednesday, June 10,  organized by the Committee on Science and Technology, U.S. House of Representatives.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;See announcement in &lt;a href="http://media-newswire.com/release_1092497.html"&gt; &lt;i&gt;Media Newswire&lt;/i&gt;&lt;/a&gt;,&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-2759506997963725035?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2759506997963725035'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2759506997963725035'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/06/national-cyber-security-cornells-fred.html' title='National cyber security: Cornell&apos;s Fred Schneider will testify  before Congress'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-7593461632901440145</id><published>2009-05-28T16:37:00.000-07:00</published><updated>2009-05-28T16:45:13.980-07:00</updated><title type='text'>Stanford's Dawson Engler Receives 2008 Grace Hopper Award</title><content type='html'>TRUST researcher and Stanford University Professor &lt;a href="http://www.truststc.org/people/directory/engler"&gt;Dawson Engler&lt;/a&gt; was awarded the&lt;br /&gt;&lt;a href="http://www.acm.org/"&gt;Association for Computing Machinery&lt;/a&gt; &lt;b&gt;Grace Murray Hopper Award&lt;/b&gt; for 2008.&lt;br /&gt;&lt;br /&gt;This prestigious award is given annually to the "outstanding young computer professional of the year" who is selected based on a "single recent major technical or service contribution".  Prof. Engler was cited for his groundbreaking work in developing advanced tools and techniques that automate program checking to identify software errors.  His approaches based on static analysis, model checking, and symbolic execution have proven very successful at finding bugs in large and complex applications.&lt;br /&gt;&lt;br /&gt;Technical papers describing this research are available on Prof. Engler's &lt;a href="http://www.stanford.edu/%7Eengler/"&gt;homepage&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-7593461632901440145?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7593461632901440145'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7593461632901440145'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/05/stanfords-dawson-engler-receives-2008.html' title='Stanford&apos;s Dawson Engler Receives 2008 Grace Hopper Award'/><author><name>Larry Rohrbough</name><uri>http://www.blogger.com/profile/01122887820002175089</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-240281065733766564</id><published>2009-05-11T08:49:00.000-07:00</published><updated>2009-05-11T09:17:22.128-07:00</updated><title type='text'>Personal information of thousands of UC Berkeley students, alumni hacked</title><content type='html'>Approximately a decade's worth of information on current and former UC Berkeley students was stolen by hackers, as announced by the University last Friday.  The infractions concerned records dating back to 1999 at the school's health center that included Social Security numbers, health insurance information, immunization history and the names of treating physicians.&lt;br /&gt;&lt;br /&gt;The thefts were initially discovered about a month ago, but system administrators did not realize the scope of the attack until April 21.&lt;br /&gt;&lt;br /&gt;University Associate Vice Chancellor for Information Technology Shelton Waggener said the hackers disguised their work as routine operations and then left taunting messages for UC Berkeley employees. Waggener says that the thieves accessed the information through the University web site.&lt;br /&gt;&lt;br /&gt;Stanford University Professor of Computer Science &lt;b&gt;John Mitchell&lt;/b&gt; said that thieves worldwide have set up black markets to sell stolen data, adding that Asia, Eastern Europe and Nigeria have particularly active hackers.  Mitchell also stated that the taunting messages left by the Berkeley thieves may indicate they are amateurs.&lt;blockquote&gt;"If your intent is to steal information and sell it on the black market, you're probably not going to call attention to yourself like that," he said. "It could be that these are kids."&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;See more in &lt;a href="http://www.insidebayarea.com/dailyreview/localnews/ci_12326391"&gt;The Daily Review&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-240281065733766564?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/240281065733766564'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/240281065733766564'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/05/personal-information-of-thousands-of-uc.html' title='Personal information of thousands of UC Berkeley students, alumni hacked'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-1805809478668247884</id><published>2009-04-29T14:28:00.000-07:00</published><updated>2009-04-29T15:00:21.768-07:00</updated><title type='text'>Momentum Shifts Against Google in Old Books Controversy</title><content type='html'>&lt;a href="http://industry.bnet.com/media/10001983/momentum-shifts-against-google-in-old-books-controversy/"&gt; BNET media&lt;/a&gt; relates several new developments in the class action suit between &lt;span style="font-weight:bold;"&gt;Google&lt;/span&gt; and some authors over who will control publishing rights of millions of out-of-print books.&lt;br /&gt;&lt;br /&gt;One of the leading legal experts on issues of intellectual property rights, &lt;b&gt;UC Berkeley Professor Pamela Samuelson&lt;/b&gt; has written a&lt;a href="http://www.scribd.com/doc/14744864/Samuelson-Letter-to-Judge-Chin-42709"&gt; powerful argument&lt;/a&gt; to the presiding judge in the case, U.S. District Judge Denny Chin.  Judge Chin himself has also announced that he is extending the deadline for those wishing to oppose the settlement by four months, from May 4 to September 4.&lt;br /&gt;&lt;br /&gt;The Justice Department is checking out the antitrust implications of the arrangements  made between &lt;b&gt;Google&lt;/b&gt; and groups representing publishers and authors, where it would be possible for millions more books to be included in &lt;i&gt;Google Book Search&lt;/i&gt; unless the copyright holders take steps to opt out.&lt;br /&gt;A larger issue to those who were not party to the deal concerns the large number of "orphan works", those whose rights holders cannot be identified.&lt;blockquote&gt;“The proposed settlement of this lawsuit is a privately negotiated compulsory license primarily designed to monetize millions of orphan works,” wrote &lt;b&gt;Professor Samuelson&lt;/b&gt;. “[It] would give Google a monopoly on the largest digital library of books in the world. It and BRR, which will also be a monopoly, will have considerable freedom to set prices and terms and conditions for Book Search’s commercial services. … Google will also be the only service lawfully able to sell orphan books and monetize them through subscriptions.”&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;See more on this story at &lt;a href="http://blogs.siliconvalley.com/gmsv/2009/04/feds-checking-out-google-books-deal.html"&gt; Good Morning Silicon Valley&lt;/a&gt;, &lt;a href="http://latimesblogs.latimes.com/technology/2009/04/google-book-settlement-justice-antitrust.html"&gt; Los Angeles Times&lt;/a&gt;, and &lt;a href="http://www.siliconbeat.com/2009/04/28/federal-judge-postpones-google-book-settlement-hearing/"&gt; Silicon Beat&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-1805809478668247884?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/1805809478668247884'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/1805809478668247884'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/04/momentum-shifts-against-google-in-old.html' title='Momentum Shifts Against Google in Old Books Controversy'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-678248223074381887</id><published>2009-04-20T08:27:00.000-07:00</published><updated>2009-04-20T08:44:25.693-07:00</updated><title type='text'>Google Books Rival Objects to Settlement</title><content type='html'>San Francisco's digital library &lt;a href="http://www.archive.org/index.php"&gt; Internet Archive&lt;/a&gt; opposes the current 125 million dollar Google settlement with authors and publishers that gives Google the rights to scan and sell books on the Internet.&lt;br /&gt;&lt;br /&gt;Dismay at the fate of orphan works, estimated at some 70 percent of books being scanned, is mounting as the May 5 deadline for objections to the settlement nears.&lt;br /&gt;&lt;br /&gt;UC-Berkeley School of Law professor &lt;b&gt;Pamela Samuelson&lt;/b&gt; said the issue of orphaned works should be handled by legislators, not as a settlement in a class action. &lt;blockquote&gt;"Usually if you want a compulsory license you have to go to Congress," she said.&lt;/blockquote&gt;Professor Samuelson favors a scenario in which the Internet Archieve as well as other digital libraries in addition to Google, would get a license to scan the boks and make them available online.&lt;blockquote&gt;"I hadn't expected them to intervene," she said. "It's an interesting development -- it's going to be interesting to see how it turns out." &lt;/blockquote&gt;&lt;br /&gt;See more at &lt;a href="http://www.law.com/jsp/article.jsp?id=1202430018507"&gt; Law.com &lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-678248223074381887?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/678248223074381887'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/678248223074381887'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/04/google-books-rival-objects-to.html' title='Google Books Rival Objects to Settlement'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-8221383746313078723</id><published>2009-04-10T20:56:00.000-07:00</published><updated>2009-04-10T21:31:31.321-07:00</updated><title type='text'>Copyright Scholar Challenges RIAA/DOJ Position</title><content type='html'>&lt;a href="http://news.slashdot.org/article.pl?sid=09/04/10/2313233&amp;art_pos=1"&gt; Slashdot &lt;/a&gt; refers to an article in &lt;i&gt;New York Country Lawyer&lt;/i&gt; about UC Berkeley Professor &lt;b&gt;Pamela Samuelson&lt;/b&gt;, leading copyright law scholar, publishing a 'working paper' that argues directly against the stand taken by the US Department of Justice in RIAA cases on the constitutionality of the RIAA's statutory damages theories.  The Department of Justice has argued that the Court should follow a 1919 United States Supreme Court case upholding the constitutionality of a statutory damages award that was 116 times the actual damages borne, under a statute that gave consumers a right of action against railway companies.&lt;br /&gt;&lt;br /&gt;The paper discusses, in depth, a number of issues regarding statutory damages under the Copyright Act and also concludes that the &lt;i&gt;State Farm/Gore&lt;/i&gt; due process test is applicable to statutory damage awards under the Copyright Act.&lt;br /&gt;&lt;br /&gt;This position is consistent with that taken in the &lt;i&gt;amicus curiae&lt;/i&gt; filed by the Free Software Foundation in earlier RIAA case defending the defendant's Due Process defense to the RIAA's claim for statutory damages and contradicts the Department of Justice briefs, arguing that the Gore due process test applies.&lt;br /&gt;&lt;br /&gt;See the complete working paper, &lt;a href="http://beckermanlegal.com/pdf/?file=/Lawyer_Copyright_Internet_Law/090408SamuelsonWorkingPaper.pdf"&gt; Statutory Damages in Copyright Law:  A Remedy in Need of Reform, by Pamela Samuelson and Tara Wheatland &lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The DOJ's intervention last month on behalf of the RIAA was covered in a Slashdot posting &lt;a href="http://news.slashdot.org/article.pl?sid=09/03/22/184221&amp;tid=123"&gt; Obama DOJ Sides with RIAA&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-8221383746313078723?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8221383746313078723'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8221383746313078723'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/04/copyright-scholar-challenges-riaadoj.html' title='Copyright Scholar Challenges RIAA/DOJ Position'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-4041377321276375743</id><published>2009-04-07T17:38:00.000-07:00</published><updated>2009-04-07T17:54:30.118-07:00</updated><title type='text'>Google’s Plan for Out-of-Print Books Is Challenged</title><content type='html'>&lt;a href="http://tech.slashdot.org/article.pl?sid=09/04/06/1515255"&gt; Slashdot&lt;/a&gt; mentions an article in the New York Times about a growing tide of complaints against Google in response to an extensive settlement that some feel will grant the mammoth company too much control over the "orphan books" they have been scanning into digital format. The settlement could give Google near-exclusivity with respect to the copyright of books that the author and publisher have basically abandoned.  They may be out of print but while they remain under copyright, the rights holders are unknown or cannot be found.&lt;blockquote&gt;“No other company can realistically get an equivalent license,” said &lt;b&gt;Pamela Samuelson&lt;/b&gt;, a professor at the University of California, Berkeley, and co-director of the Berkeley Center for Law and Technology. &lt;/blockquote&gt; Critics say that without the orphan books, no competitor will ever be able to compile the comprehensive online library Google intends to create. Without competition, Google will be able to charge universities and others a high price for access to its database.&lt;br /&gt;&lt;br /&gt;While most of the critics, including copyright specialists, antitrust scholars and some librarians, agree that the public will benefit,  they say others should also have rights to orphan works.&lt;br /&gt;&lt;br /&gt;See complete article in the &lt;a href="http://www.nytimes.com/2009/04/04/technology/internet/04books.html?pagewanted=1&amp;_r=1"&gt; &lt;i&gt;New York Times&lt;/i&gt;&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-4041377321276375743?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4041377321276375743'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4041377321276375743'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/04/googles-plan-for-out-of-print-books-is.html' title='Google’s Plan for Out-of-Print Books Is Challenged'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-9000276074388278380</id><published>2009-03-09T16:21:00.000-07:00</published><updated>2009-03-09T17:39:34.950-07:00</updated><title type='text'>Do Breach Notification Laws Work?</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Deirdre Mulligan&lt;/span&gt;, professor of information technology law and policy at UC Berkeley's School of Information was one of several speakers at a Security Breach Notification symposium held in Berkeley last Friday.  The symposium's directive was to try to answer the question of whether breach notification laws are actually working.  &lt;br /&gt;&lt;br /&gt;California passed the first data breach notification law in 2003, which quickly became the standard for the rest of the country. While it is clear that the laws have made the public more aware of the vulnerability of their data and have exposed poor security practices at many a business, it is unclear what other benefits the laws have had.  Breach notifications should, in theory, reduce incidence of identity theft or fraudulent charges to credit cards if consumers take proper precautions when they receive a notification, as with a fraud alert or a freeze on their credit account because of suspicious transactions.  &lt;br /&gt;&lt;br /&gt;There are also other questions to ask about what effect breach notifications have on the relationship between the customer and the breached organization. While consumers often express anger and mistrust toward companies that lose their data, it is unclear how often that mistrust actually translates to action.  &lt;br /&gt;&lt;br /&gt;According to &lt;span style="font-weight:bold;"&gt;Professor Mulligan&lt;/span&gt;, a Ponemon study found that about 20 percent of respondents claimed to have terminated their relationship with a company after discovering the company experienced a breach. But a separate survey of companies found that the percentage of customers who actually do terminate their relationship is less than 7 percent.  Both numbers need to be taken with a grain of salt. &lt;blockquote&gt;"Consumers have a tendency to say they're going to do one thing when they actually do another," says Mulligan, "and companies also can't be relied on to honestly report the numbers of customers they lose from a breach."&lt;/blockquote&gt;&lt;br /&gt;See full article in &lt;a href="http://blog.wired.com/27bstroke6/2009/03/experts-debate.html"&gt; &lt;span style="font-style:italic;"&gt;Wired&lt;/span&gt;&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-9000276074388278380?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/9000276074388278380'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/9000276074388278380'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/03/do-breach-notification-laws-work.html' title='Do Breach Notification Laws Work?'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-8770495969593881930</id><published>2009-03-02T14:07:00.000-08:00</published><updated>2009-03-02T16:14:11.815-08:00</updated><title type='text'>Shankar Sastry interviewed on Federal News Radio</title><content type='html'>Dr. &lt;span style="font-weight:bold;"&gt;Shankar Sastry&lt;/span&gt;, Dean of of the College of Engineering at the University of California, Berkeley, was interviewed by Tom Temin for '&lt;span style="font-style:italic;"&gt;Federal Security Spotlight&lt;/span&gt;' on &lt;span style="font-weight:bold;"&gt;Federal News Radio&lt;/span&gt; in his role as director of the Team for Research in Ubiquitous Secure Technologies (TRUST).&lt;br /&gt;&lt;br /&gt;Sastry described how TRUST, funded by the National Science Foundation and housed at the University of California at Berkeley, as a team of some of the best minds from UC Berkeley, Vanderbilt, Cornell, Carnegie-Mellon, and Stanford Universities  with Smith, San Jose State University and Mills College as outreach partners, was formed to examine the interconnection between cyber infrastructure and physical infrastructure.  The complex interplay of component technology, policy, law, privacy issues and economic considerations are the motivations for putting together the TRUST Center.&lt;br /&gt;&lt;br /&gt;Prof. Sastry described how initially it was the internet that was the primary security concern with various worms and viruses emerging, but as time went on, power, water, telecommmunications and other physical infrastructures also became implicated in security concerns. &lt;br /&gt;&lt;br /&gt;Temin raised the issue of security and health-care concerns with electronic medical records/personal health records. The issues, according to Prof. Sastry, are about trying to make sure that (a) we can collect this information and (b) we can make the information available without all the paperwork.  Having the data available to the patient is also an objective.&lt;br /&gt;&lt;br /&gt;"The issues of privacy and selective disclosure is a subject of some debate", says Sastry.  "I think there are legitimate needs for the medical industry to learn about, say, the efficacy of certain drugs", but there is also a tension between personal and medical records that are seen by many entities, billing, pharmaceuticals, different kinds of doctors, he says.  Sastry observed the need to stop any 'mining' of this information and a need to be able to stop a 'fishing expedition' in this area.&lt;br /&gt;&lt;br /&gt;Trust research is focusing on both the security and the privacy of patients as well as the possibility of a patient 'customizing' their records to make some records available to their doctors only. &lt;br /&gt;&lt;br /&gt;Another area of research involves wireless networking vulnerabilities.  Sastry describes a scenario where we will literally have a 1000 radios around people, controlling the physical environment by means of embedded rfid's and wireless sensor networks, evolving to a future of computation on wireless devices. Dr. Sastry says we need a reliable and secure medium for a wireless network.  Wireless airwaves are not as reliable as a wired infrastructure because they are susceptible to jamming, to retransmission, etc. &lt;br /&gt;&lt;br /&gt;A secure communications medium interacts with privacy and security.  The privacy agenda enters in subtle ways in that by anonymizing the data, for example with real-time traffic monitoring via cellphone, it is not subverted as a means of tracking someone as they are driving in traffic.  Cellphones will be used more and more as sensor networks.&lt;br /&gt;&lt;br /&gt;Sastry described TRUST's mission as deriving security solutions in a principled way that is not reactive, as with the cat-and-mouse pattern of attacks followed by solutions followed by new attacks as has been the case thus far.&lt;br /&gt;&lt;br /&gt;To listen to the complete interview (in 3 parts), go to &lt;a href="http://www.federalnewsradio.com/?nid=56&amp;sid=1596866"&gt; Federal News Radio&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-8770495969593881930?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8770495969593881930'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8770495969593881930'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/03/shankar-sastry-interviewed-on-federal.html' title='Shankar Sastry interviewed on Federal News Radio'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-5385727057692196178</id><published>2009-02-11T08:00:00.000-08:00</published><updated>2009-02-11T08:16:44.247-08:00</updated><title type='text'>D.A. considers 211 cases of possible voter fraud</title><content type='html'>The Orange County, California District Attorney's Office is investigating 211 possible cases of voter fraud in the November 4th presidential election. Registrar of Voters Neal Kelley sent the list after his office used computer databases to search for cases where one person submitted more than one ballot. Kelley says that history shows that most instances of double voting are unintentional as with a voter that submits two absentee ballots, or an absentee ballot in addition to voting at the polls.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;UC Berkeley Professor David Wagner&lt;/span&gt;, who studies electronic voting security says that post-election audits across the state have improved recently under the heightened scrutiny of state and local officials.&lt;blockquote&gt;"It's important for transparency because it gives voters more confidence that the right person won," Wagner said. "The big picture is the whole state of California is in good shape." &lt;/blockquote&gt; Wagner stated that these registration errors should be fixed for future elections but that it is not someting that's going to affect the outcome of an election since it is an issue of such small scale.&lt;br /&gt;&lt;br /&gt;See complete article in &lt;a href="http://www.ocregister.com/articles/election-state-voter-2301856-kelley-county"&gt; OC Register&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-5385727057692196178?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/5385727057692196178'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/5385727057692196178'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/02/da-considers-211-cases-of-possible.html' title='D.A. considers 211 cases of possible voter fraud'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-873260469061113491</id><published>2009-01-26T08:17:00.000-08:00</published><updated>2009-01-26T08:36:48.464-08:00</updated><title type='text'>Phone security  is much better, says UC Berkeley Professor</title><content type='html'>The Akron Beacon Journal relayed comments by UC Berkeley Professor David Wagner, regarding current telephone security.  When asked if there were any difference in security between using a corded phone and a cell phone, Wagner replied &lt;blockquote&gt;"Assuming your cell phone is digital, there's not enough difference to worry about. Back when cell phones were analog, eavesdropping was easy." However today most cell phones are digital and while eavesdropping with a digital cell phone is possible, "it's pretty much out of the reach of casual interception," he said.&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Wagner notes that wired phones aren't completely secure either, but said both digital cell phones and wired phones are secure enough for most people to use for everyday business. In truth, the weakest aspect of cell-phone use is the frequency of having sensitive conversations in public places without thinking about being overheard.&lt;br /&gt;&lt;br /&gt;See more at &lt;a href="http://www.ohio.com/lifestyle/home_garden/38264094.html"&gt; Ohio.com&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-873260469061113491?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/873260469061113491'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/873260469061113491'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2009/01/phone-security-is-much-better-says-uc.html' title='Phone security  is much better, says UC Berkeley Professor'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-4181931169589180155</id><published>2008-12-19T10:18:00.000-08:00</published><updated>2008-12-19T10:36:44.905-08:00</updated><title type='text'>Experts debate:  Is DRM good or bad for consumers?</title><content type='html'>COMPUTERWORLD ran a story about the FTC's discussion about the controversial DRM (digital rights management) technology possibly benefiting consumers because it could give them more choices for downloading or buying copyrighted content. Others on a panel discussion about new technology products are not convinced however.&lt;blockquote&gt;Until DRM matured, consumers had control over how they used digital content, noted &lt;b&gt;Deirdre Mulligan&lt;/B&gt;, director of the Samuelson Law, Technology and Public Policy Clinic at the University of California, Berkeley, Law School. DRM is creating a "permission culture" where consumers have to ask the copyright owner's permission to play a piece of music on both a home computer and a car stereo, she said.&lt;br /&gt;&lt;br /&gt;Until DRM, "there was a lot of breathing space in copyright law," she added.&lt;br /&gt;&lt;br /&gt;In addition, many consumers don't understand DRM restrictions, and they're surprised when a CD that works on a home stereo can't be played somewhere else, she said. Vendors offer "little disclosure about how consumers can use" DRM-protected content, she said.&lt;/blockquote&gt;&lt;br /&gt;See full article at &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyId=17&amp;articleId=9004909&amp;intsrc=hm_topic"&gt; COMPUTERWORLD&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-4181931169589180155?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4181931169589180155'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4181931169589180155'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/12/experts-debate-is-drm-good-or-bad-for.html' title='Experts debate:  Is DRM good or bad for consumers?'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-6609592345522008328</id><published>2008-11-14T15:10:00.000-08:00</published><updated>2008-11-14T15:33:18.389-08:00</updated><title type='text'>Shankar Sastry to discuss UC Berkeley's intiatives at its first Global Technology Leaders Conference</title><content type='html'>A press release came out yesterday in the Wall Street Journal's online &lt;span style="font-style:italic;"&gt;MarketWatch &lt;/span&gt; announcing UC Berkeley as host of the inaugural A. Richard Newton Global Technology Leaders Conference on Thursday, November 20th. &lt;br /&gt;&lt;br /&gt;The conference will bring together notable entrepreneurs, scientists and researchers to discuss the world's most overarching challenges and ascertain pathways to solution in the health sciences, energy and technology fields. Dean of UC Berkeley's College of Engineering, Shankar Sastry, will discuss Berkeley's initiatives in these areas.  Alberto Sangiovanni-Vincentelli, professor in Electrical Engineering and Computer Sciences at Berkeley, will deliver the keynote address, "The Future of the Future."&lt;br /&gt;&lt;br /&gt;The conference is being held during Global Entrepreneurship Week and is sponsored by the Ewing Marion Kauffman Foundation and the goal for the group is to develop a roadmap leading to new industries in energy, technology and health care.&lt;blockquote&gt;"It is fitting to launch this annual series during a week that seeks to inspire young people to be innovative and entrepreneurial," said Lesa Mitchell, vice president, Advancing Innovation, Kauffman Foundation. &lt;/blockquote&gt;&lt;br /&gt;See complete story in &lt;a href="http://www.marketwatch.com/news/story/Academics-Entrepreneurs-Come-Together-Address/story.aspx?guid={343B7F2C-89DB-494A-A0DE-F5DDA64A809E}"&gt; MarketWatch&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-6609592345522008328?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6609592345522008328'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6609592345522008328'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/11/shankar-sastry-to-discuss-uc-berkeleys.html' title='Shankar Sastry to discuss UC Berkeley&apos;s intiatives at its first Global Technology Leaders Conference'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-2781503009308352762</id><published>2008-11-13T08:34:00.000-08:00</published><updated>2008-11-13T09:02:16.473-08:00</updated><title type='text'>Improving the Count; Prof. David Wagner, others pose solutions for better election system</title><content type='html'>&lt;span style="font-style:italic;"&gt;The Boulder Daily Camera&lt;/span&gt; ran an article Sunday regarding problems with voting systems in general and in Boulder County specifically. Although Boulder County Commissioners agreed to spend $1.4 million on optical scanning equipment in 2004, in didn't take long for problems that still follow the county's election process showed up.  In August 2004, Boulder County lagged hours behind other Colorado counties. Worse, poorly printed ballots delayed election results for 72 hours in November, 2004.&lt;br /&gt;&lt;blockquote&gt;“If the proper maintenance and everything else is being done to (the scanners), this is the voting system we should be using,” said John Gideon, co-director of VotersUnite!, a non-partisan group that has been logging errors on all kinds of voting machines.&lt;/blockquote&gt;Computer scientist &lt;span style="font-weight:bold;"&gt;David Wagner&lt;/span&gt; of the University of California at Berkeley who studies electronic voting machines, agrees.&lt;blockquote&gt;“Right now, I think optical scan systems are probably the most mature, reliable technology on the market,” he said. “Boulder got the best technology on the market. ... None of the voting systems are perfect, and they all have their limitations.”&lt;/blockquote&gt;&lt;br /&gt;See full story in &lt;a href="http://www.dailycamera.com/news/2008/nov/09/improving-count/"&gt; The Boulder Daily Camera&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-2781503009308352762?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2781503009308352762'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2781503009308352762'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/11/improving-count-prof-david-wagner.html' title='Improving the Count; Prof. David Wagner, others pose solutions for better election system'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-2560129086360878772</id><published>2008-11-12T15:46:00.000-08:00</published><updated>2008-11-12T16:21:27.206-08:00</updated><title type='text'>Profitability of spam finally measured</title><content type='html'>ZDNet posted an article about a key paper presented at this year's ACM Conference on Computer and Communication Security. A team of researchers, including &lt;span style="font-weight:bold;"&gt;UC Berkeley Professor Vern Paxson&lt;/span&gt;, used somewhat aggressive tactics to collect data that measures the conversion rate, or the rate at which an advertising impression results in a products sale, for spam.  They essentially hijacked a portion of the notorious Storm botnet to inject spam that contained links to domains and storefronts they controlled.&lt;br /&gt;&lt;br /&gt;The team's data has shown that generating 28 sales at an average of $100 each of various "male-enhancement" products required 350 million separate spam messages.  This provides a yearly revenue rate of the Storm botnet for the sale of pharmaceuticals at around $3.5 million dollars.&lt;br /&gt;&lt;br /&gt;See complete article at &lt;a href="http://www.crime-research.org/news/12.11.2008/3658/"&gt; ZDNet&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-2560129086360878772?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2560129086360878772'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2560129086360878772'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/11/profitability-of-spam-finally-measured.html' title='Profitability of spam finally measured'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-7040705961178422604</id><published>2008-11-04T16:16:00.000-08:00</published><updated>2008-11-04T16:39:05.954-08:00</updated><title type='text'>What Could Possibly Go Wrong?</title><content type='html'>An article came out today in PCWorld regarding the progress of E-voting technology since the 2000 U.S. presidential election, although it has taken a rather zig-zagged path.  After Congress passed the 2002 Help America Vote Act (HAVA), counties spent billions of dollars upgrading to new electronic voting machines, many of which were dumped when it was determined that they were either unusable or untrustworthy.&lt;br /&gt;&lt;br /&gt;Machine malfunctions, touch-screen calibration errors, training problems with unskilled poll workers or human error on the part of the voter all impact on an election's outcome. All of the above notwithstanding, University of California computer science professor David Wagner states that bad design choices could be ferreted out if the federal government included user-interface testing as part of the certification process.&lt;br /&gt;&lt;br /&gt;Proposed next-generation voting standards would require this type of testing, but it is not clear that these standards will be adopted, Wagner said.  The Berkeley professor also said he will be watching these voter registration databases closely today.&lt;blockquote&gt;"I don't know what to expect," he said. "Everything could go smoothly, or we could have a substantial fraction of voters who show up on Election Day, think they're registered and are told that there is some problem with their registration."&lt;/blockquote&gt;&lt;br /&gt;See article today in &lt;a href="http://www.pcworld.com/businesscenter/article/153234/nov_4_2008_what_could_possibly_go_wrong.html"&gt; PCWorld&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-7040705961178422604?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7040705961178422604'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7040705961178422604'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/11/what-could-possibly-go-wrong.html' title='What Could Possibly Go Wrong?'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-2932859748227199254</id><published>2008-10-29T10:14:00.000-07:00</published><updated>2008-10-29T10:55:07.664-07:00</updated><title type='text'>David Wagner quoted in article on new trend in voting technology</title><content type='html'>In an article written by freelance technology journalist Cyrus Farivar, the concept of using cryptography for what is being called end-to-end voter-verifiability is described and analyzed.  &lt;br /&gt;&lt;br /&gt;In order for public officials to definitively show that the proposed cryptography works as it should, they would have to provide an advanced mathematical proof, or "zero-sum proof" as it is known, whose sheer size would preclude printing it on the ballot.&lt;br /&gt;&lt;br /&gt;Among the several academics Farivar interviewed about the new cryptographic approach involved in  voter-verifiable systems, Farivar quotes UC Berkeley Professor David Wagner who asks&lt;blockquote&gt;"Will voters accept something that uses mathematics that they won't understand?"&lt;/blockquote&gt;&lt;br /&gt;See details in &lt;a href="http://machinist.salon.com/blog/2008/10/23/crypto_voting/"&gt;&lt;span style="font-style:italic;"&gt;machinist&lt;/span&gt;&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-2932859748227199254?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2932859748227199254'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2932859748227199254'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/10/david-wagner-quoted-in-article-on-new.html' title='David Wagner quoted in article on new trend in voting technology'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-5741687662640114101</id><published>2008-09-16T09:10:00.000-07:00</published><updated>2008-10-24T09:20:29.721-07:00</updated><title type='text'>Stephen Maurer quoted in New Scientist on DNA and Terrorism</title><content type='html'>&lt;a href="http://www.truststc.org/people/directory/smaurer"&gt;Stephen Maurer&lt;/a&gt;, Director of the Goldman School Project on Information Technology and Homeland Security ("ITHS") and member of &lt;a href="http://www.truststc.org"&gt;TRUST&lt;/a&gt; was quoted in the New Scientist September 14, 2008 article, "&lt;a href="http://www.newscientist.com/channel/life/genetics/mg19926733.500-dna-firms-step-up-security-over-bioterrorism-threat.html"&gt;DNA firms step up security over bioterrorism threat&lt;/a&gt;" that discusses efforts to counter fears that terrorists could make deadly viruses by ordering genetic material from corporations.  Maurer is quotes as saying, "The fact that they're going to share their experiences is really important." Maurer helped write the industry guidelines.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-5741687662640114101?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/5741687662640114101'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/5741687662640114101'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/09/stephen-maurer-director-of-goldman.html' title='Stephen Maurer quoted in New Scientist on DNA and Terrorism'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-6870858694521729380</id><published>2008-09-11T15:59:00.000-07:00</published><updated>2008-09-11T16:17:04.986-07:00</updated><title type='text'>UC Berkeley Professor Doug Tygar called in as expert witness for the defense</title><content type='html'>&lt;a href="http://it.slashdot.org/article.pl?sid=08/09/11/1355224"&gt; Slashdot&lt;/a&gt; recounts a story published in NETWORKWORLD about the latest twist in the bizarre story of the rogue network administrator that hijacked the city's network in the last two months.  With costs estimated at $1 million, city officials say they are trying to locate a mysterious networking device hidden somewhere in the network.&lt;br /&gt;&lt;br /&gt;This device, which is referred to as a "terminal server" in court documents actually appears to be a router that was installed to provide remote access to the city's Fiber WAN network, which connects municipal computer and telecommunication systems throughout the city.  The router was discovered on Aug. 28.  When investigators tried to log in to the device, they were greeted with what appears to be a router login prompt and warning message saying "This system is the personal property of Terry S. Childs."  Childs, a network administrator with DTIS was arrested June 12 on charges of network tampering after he refused to provide his superiors with administrative access to the city of San Francisco's network, which he'd managed for the past five years.&lt;br /&gt;&lt;br /&gt;In a report filed before the city disclosed the hidden router, a court-appointed expert witness for the defense wrote that DTIS could easily prevent Childs from accessing the networks.&lt;blockquote&gt;"I have seen no evidence that Mr. Childs is a 'computer hacker,' and by taking a number of simple steps, DTIS could block access by Mr. Childs to San Francisco networks," wrote Doug Tygar, a University of California, Berkeley computer science professor.&lt;/blockquote&gt;&lt;br /&gt;Childs next appearance is set for September 24th, when he'll face up to seven years in prison if convicted.&lt;br /&gt;&lt;br /&gt;For complete story, see &lt;a href="http://www.networkworld.com/news/2008/091008-san-francisco-hunts-for-mystery.html?page=2"&gt; NETWORKWORLD &lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-6870858694521729380?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6870858694521729380'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6870858694521729380'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/09/uc-berkeley-professor-doug-tygar-called.html' title='UC Berkeley Professor Doug Tygar called in as expert witness for the defense'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-3914775005170542347</id><published>2008-09-04T08:10:00.000-07:00</published><updated>2008-09-29T08:21:57.829-07:00</updated><title type='text'>Samuelson quoted about copyright and electronic access to CA laws</title><content type='html'>In a September 3, 2008 Santa Rosa Press Democrat article, "&lt;a href="http://www.pressdemocrat.com/article/20080903/NEWS/809030309/1036/NEWS07&amp;title=Downloading_the_law__one_document_at_a_time"&gt;He's giving you access, one document at a time&lt;/a&gt;," concerning efforts to make California laws more accessible on-line, Professor Pam Samuelson was quoted&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;"If it's the law, the public should have access to it," she said.&lt;br /&gt;&lt;br /&gt;Samuelson points out that the idea of copyright was established to provide people incentive to create. People are given exclusive legal rights to their paintings, writings and other works because by selling those rights they can attempt to make a living.&lt;br /&gt;&lt;br /&gt;There is no similar need for financial incentives to establish standards such as building codes, Samuelson said. For the most part, volunteers spend long hours drafting proposed standards for things like plumbing and building. Governments often take those standards and adopt them into law.&lt;br /&gt;&lt;br /&gt;Once the standards become law, she doesn't think people can claim copyright protections. But like Malamud, she sees the courts making the final ruling.&lt;br /&gt;&lt;br /&gt;"I don't think it's an airtight case for either side. But I think the law favors that if something is a law, it's in the public domain," she said.&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;9/29/08 Update: This article has been picked up by the &lt;a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/09/26/BAAH134FI4.DTL"&gt;San Francisco Chronicle (9/27/08)&lt;/a&gt; and the &lt;a href="http://www.nytimes.com/2008/09/29/business/media/29link.html?ref=business"&gt;NY Times (9/29/08)&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-3914775005170542347?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/3914775005170542347'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/3914775005170542347'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/09/samuelson-quoted-about-copyright-and.html' title='Samuelson quoted about copyright and electronic access to CA laws'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-5797178753964440533</id><published>2008-08-29T11:53:00.000-07:00</published><updated>2008-08-29T14:17:55.182-07:00</updated><title type='text'>TRUST Supports Undergraduate Security Research Experience</title><content type='html'>&lt;a href="http://www.dailycal.org/"&gt;The Daily Californian&lt;/a&gt; ran &lt;a href="http://www.dailycal.org/article/102306/summer_program_gives_undergraduates_a_graduate_res"&gt;an article&lt;/a&gt; on the UC Berkeley Summer Undergraduate Program in Engineering Research at Berkeley (SUPERB) program, including a group hosted by the &lt;a href="http://www.truststc.org/"&gt;TRUST Center&lt;/a&gt;.  Led by &lt;a href="http://www.cs.berkeley.edu/%7Edaw/"&gt;Professor David Wagner&lt;/a&gt; and a group of graduate graduate student mentors, the SUPERB-TRUST participants got firsthand experience conducting research into security vulnerabilities of software applications as well as general exposure to working in a university research environment.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-5797178753964440533?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/5797178753964440533'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/5797178753964440533'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/08/trust-supports-undergraduate-security.html' title='TRUST Supports Undergraduate Security Research Experience'/><author><name>Larry Rohrbough</name><uri>http://www.blogger.com/profile/01122887820002175089</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-8925730477412515726</id><published>2008-08-25T10:24:00.000-07:00</published><updated>2008-08-25T10:45:49.643-07:00</updated><title type='text'>Plug-in opens door for self-signed SSL certs in Firefox 3</title><content type='html'>An online posting of an article in &lt;a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1326622,00.html"&gt; INFORMATION SECURITY MAGAZINE&lt;/a&gt; appeared Friday about the release of a software plugin developed by CMU Professors Adrian Perrig and Dave Anderson along with Ph.D. student Dan Wendlandt.  The plugin, as part of a system called &lt;span style="font-style:italic;"&gt;Perspectives&lt;/span&gt;, was designed to relieve some of the anxiety surrounding Mozilla Corp's decision to not display sites with either self-signed or expired SSL digital certificates in Firefox 3.&lt;br /&gt;&lt;br /&gt;The Perspectives system works from a series of servers that monitor website connections recording public encryption keys over time.  If the servers can authenticate that the same key has been returned for a requested site for a predetermined period of time, Perspectives will override Firefox 3's default block on the site and allow the user to proceed.&lt;br /&gt;&lt;br /&gt;See &lt;a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1326622,00.html"&gt; SearchSecurity.com &lt;/a&gt;  for details.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-8925730477412515726?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8925730477412515726'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8925730477412515726'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/08/plug-in-opens-door-for-self-signed-ssl.html' title='Plug-in opens door for self-signed SSL certs in Firefox 3'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-2743443734389314090</id><published>2008-08-15T13:06:00.000-07:00</published><updated>2008-08-15T13:18:22.613-07:00</updated><title type='text'>University of California, Berkeley Prof. Bajcsy wins Innovation Research Award</title><content type='html'>Hewlett Packard announced the 41 professors it has chosen to receive its HP Labs Innovation Research Awards, which fund joint research projects between academic research institutions throughout the world and HP Labs.&lt;br /&gt;&lt;br /&gt;Drs. Ruzena Bajcsy and Van P. Carey, of the University of California, Berkeley were among the 41 professors selected.&lt;blockquote&gt;"Deepening HP Labs' strategic collaboration with those in academia, government and the commercial sector ensures HP's research endeavors result in high-impact research that meets the scientific and business objectives of HP and its partners," said Prith Banerjee, senior vice president, Research, HP, and director, HP Labs. "The professors' deep technical expertise, HP Labs researchers' domain and industry knowledge, and governments' abilities to fund innovative research will come together to address the world's most complex IT challenges." &lt;br /&gt;&lt;/blockquote&gt;See complete story at &lt;a href="http://www.marketwatch.com/news/story/hp-selects-41-professors-innovation/story.aspx?guid=%7BE97F73E4-F22E-45D6-B24B-9B4F7B403D7B%7D&amp;dist=hppr"&gt; MarketWatch&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-2743443734389314090?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2743443734389314090'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2743443734389314090'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/08/university-of-california-berkeley-prof.html' title='University of California, Berkeley Prof. Bajcsy wins Innovation Research Award'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-612751672732675340</id><published>2008-08-15T11:02:00.000-07:00</published><updated>2008-08-15T11:44:45.620-07:00</updated><title type='text'>Transit agency wants MIT students to stay gagged</title><content type='html'>The Electronic Frontier Foundation is providing legal defense for three MIT students prohibited from discussing vulnerabilities they discovered in subway card security by an order given to the Massachusetts Bay Transportation Authority by a District Court Judge.&lt;br /&gt;&lt;br /&gt;The EFF has enlisted some high-profile academics, including UC Berkeley's David Wagner, to strengthen the case that the restraining order is antithetical to security research.&lt;br /&gt;&lt;br /&gt;Security researchers are watching this case carefully because it could ultimately set a precedent weighing First Amendment rights to publish freely against a vendor's desire to keep embarrassing and potentially explosive details secret.&lt;br /&gt;&lt;br /&gt;Prof. Wagner and several other high-profile academics have signed a letter to the judge on Monday that says:&lt;blockquote&gt;We are concerned that the pall cast by the temporary restraining order will stifle research efforts and weaken academic computing research programs. In turn, we fear the shadow of the law's ambiguities will reduce our ability to contribute to industrial research in security technologies at the heart of our information infrastructure. We urge that you reconsider and remove the temporary restraining order issued on August 10, 2008. &lt;br /&gt;&lt;/blockquote&gt;See full story at &lt;a href="http://news.cnet.com/8301-1009_3-10016114-83.html"&gt; cnet.news.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-612751672732675340?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/612751672732675340'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/612751672732675340'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/08/transit-agency-wants-mit-students-to.html' title='Transit agency wants MIT students to stay gagged'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-3406626169877000264</id><published>2008-08-13T05:50:00.000-07:00</published><updated>2008-08-13T05:54:09.931-07:00</updated><title type='text'>Research improves recognition software</title><content type='html'>On August 12, 2008,  Allen Yang was featured on KGO TV in a segment titled, "&lt;a href="http://abclocal.go.com/kgo/story?section=news/drive_to_discover&amp;id=6319540"&gt;Research improves recognition software&lt;/a&gt;".&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-3406626169877000264?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/3406626169877000264'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/3406626169877000264'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/08/research-improves-recognition-software.html' title='Research improves recognition software'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-226166679658549557</id><published>2008-08-11T08:52:00.000-07:00</published><updated>2008-08-11T09:14:18.764-07:00</updated><title type='text'>NIST Advisory Group Welcomes Berkeley Professor</title><content type='html'>It was recently  announced that electrical engineering and computer science professor at the University of California, Berkeley, &lt;span style="font-weight:bold;"&gt;Ruzena Bajcsy&lt;/span&gt;, has been selected to serve on the primary private-sector policy advisory body of the National Institute of Standards and Technology (NIST). Dr. Bajcsy's appointment to the agency's Visiting Committee on Advanced Technology (VCAT) was announced by NIST's deputy director, James M. Turner.&lt;br /&gt;&lt;br /&gt;Bajcsy's research areas include artificial intelligence, robotics, biosystems and computational biology, and human-computer interaction. She is director emeritus of the Center for Information Technology Research in the Interest of Society (CITRIS), a UC Berkeley-based public-private partnership that develops information technology solutions to social, environmental and health care issues.&lt;br /&gt;&lt;br /&gt;See press release in &lt;a href="http://news.thomasnet.com/companystory/547923"&gt; ThomasNet Industrial Newsroom&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-226166679658549557?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/226166679658549557'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/226166679658549557'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/08/nist-advisory-group-welcomes-berkeley.html' title='NIST Advisory Group Welcomes Berkeley Professor'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-7419479941367621881</id><published>2008-06-04T11:01:00.000-07:00</published><updated>2008-08-11T17:25:35.508-07:00</updated><title type='text'>Professor  Anthony Joseph elected to the ACM</title><content type='html'>UC Berkeley Professor Anthony Joseph has been elected to the &lt;a href="http://www.acm.org/acmelections/acm-general-election"&gt;Association for Computing Machinery Council&lt;/a&gt; as Member-At-Large. Elected member are recognized for significant accomplishments or for achieving significant impact on the computing field.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-7419479941367621881?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7419479941367621881'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7419479941367621881'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/06/professor-anthonyjoseph-elected-to-acm.html' title='Professor  Anthony Joseph elected to the ACM'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-4284658188195001108</id><published>2008-04-30T14:27:00.000-07:00</published><updated>2008-04-30T14:59:25.357-07:00</updated><title type='text'>UC Berkeley Professor Ruzena Bajcsy elected to American Academy of Arts &amp; Sciences</title><content type='html'>A press release issued by &lt;a href="http://www.berkeley.edu/news/media/releases/2008/04/28_AAA.shtml"&gt; UCBerkeleyNews&lt;/a&gt; announced that University of California Berkeley Professor Ruzena Bajcsy has been elected to the American Academy of Arts &amp; Sciences. &lt;blockquote&gt;"The Academy honors excellence by electing to membership remarkable men and women who have made preeminent contributions to their fields, and to the world," academy president Emilio Bizzi said in a prepared statement.&lt;/blockquote&gt;The American Academy of Arts &amp; Sciences is one of the nation's oldest and most prestigious honorary societies and independent policy research centers.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-4284658188195001108?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4284658188195001108'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4284658188195001108'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/04/bajcsy-elected-to-american-academy-of.html' title='UC Berkeley Professor Ruzena Bajcsy elected to American Academy of Arts &amp; Sciences'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-136101744427607610</id><published>2008-04-25T17:32:00.000-07:00</published><updated>2008-04-25T17:47:01.283-07:00</updated><title type='text'>Automatic Patch-Based Exploit Generation is Possible: Techniques and Implementations</title><content type='html'>A paper by David Brumley, Pongsin Poosankam, &lt;a href="http://www.truststc.org/people/directory/dawnsong"&gt;Dawn Song (TRUST) &lt;/a&gt; and Jiang Zheng, "&lt;a href="http://www.truststc.org/pubs/381.html"&gt;Automatic Patch-Based Exploit Generation is Possible: Techniques and Implications&lt;/a&gt;" is getting quite a bit of press:&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://it.slashdot.org/article.pl?sid=08/04/18/1459225"&gt;Slashdot&lt;/a&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://www.schneier.com/blog/archives/2008/04/reverseengineer.html"&gt;Bruce Schneier's Cryptogram&lt;/a&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://www.pcworld.com/article/id,145050/article.html"&gt;PC World&lt;/a&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://www.theregister.co.uk/2008/04/25/patches_security_risk/"&gt;The Register&lt;/a&gt;&lt;br /&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-136101744427607610?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/136101744427607610'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/136101744427607610'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/04/automatic-patch-based-exploit.html' title='Automatic Patch-Based Exploit Generation is Possible: Techniques and Implementations'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-2871847845496849288</id><published>2008-04-14T10:15:00.000-07:00</published><updated>2008-04-17T08:45:35.994-07:00</updated><title type='text'>Electronic Voting at the RSA Conference</title><content type='html'>The &lt;a href="http://www.rsaconference.com/"&gt;RSA Conference&lt;/a&gt; April 7-11, 2008 in San Francisco resulted in a few news items about the work of &lt;a href="http://www.cs.berkeley.edu/~daw/"&gt;David Wagner&lt;/a&gt;.&lt;br /&gt;&lt;li&gt; On April 10, CNet's article, "&lt;a href="http://www.news.com/8301-10784_3-9916426-7.html?tag=nefd.top"&gt;Expert says flawed e-voting systems need constant audits&lt;/a&gt;," discusses Wagner's voting machine audit proposal.&lt;br /&gt;&lt;li&gt; On April 10, SecurityFocus' article, "&lt;a href="http://www.securityfocus.com/brief/720"&gt;Researchers tell voting firms, time for a truce&lt;/a&gt;," discusses efforts by security researchers and voting machine vendors to work together.  Wagner is quoted: "Voting system vendors are, today, where Microsoft was ten years ago."&lt;br /&gt;&lt;li&gt; On April 11, &lt;a href="http://www.abcnews.go.com/Technology/PCWorld/story?id=4630624"&gt;ABC News&lt;/a&gt; had an article about threats to the upcoming US Presidential Election.  The same article appears at &lt;a href="http://www.pcworld.com/businesscenter/article/144431/us_presidential_election_can_be_hacked.html"&gt;PC World&lt;/a&gt;.&lt;br /&gt;&lt;li&gt; &lt;i&gt;Update:&lt;/i&gt; On April 11, The Register's article, "&lt;a href="http://www.theregister.co.uk/2008/04/11/evoting_panel/"&gt;Where were you when you learned e-voting was unreliable?&lt;/a&gt; presents another view on the conference.&lt;br /&gt;&lt;li&gt;&lt;i&gt;Update:&lt;/i&gt; On April 16, Cringley discusses the issue with, "&lt;a href="http://weblog.infoworld.com/robertxcringely/archives/2008/04/voting_accident.html"&gt;Voting accidents and other avoidable tragedies&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-2871847845496849288?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2871847845496849288'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2871847845496849288'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/04/electronic-voting-at-rsa-conference.html' title='Electronic Voting at the RSA Conference'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-8310791759496660948</id><published>2008-03-25T15:49:00.000-07:00</published><updated>2008-03-25T16:29:25.865-07:00</updated><title type='text'>Engineers Test Highly Accurate Face Recognition</title><content type='html'>The work of postdoctoral researcher Allen Yang, of Professor Shankar Sastry's Heterogeneous Sensor Network (HSN) group at the University of California, Berkeley, is the subject of an article in Wired magazine where a new facial-recognition algorithm was created by Yang with the help of researchers at both UC Berkeley and the University of Illinois at Urbana-Champaign.&lt;br /&gt;&lt;br /&gt;"Most algorithms use what's known as meaningful facial features to recognize people-things like the eyes, nose and mouth," says Dr. Yang.  "But that's incredibly limiting because you're only looking at pixels from a designated portion of the face and those pixels end up being much smaller than the whole image.  Our algorithm shows that you only need to randomly select pixels from anywhere on the face.  If you select enough of them, you can produce extremely high accuracy."&lt;br /&gt;&lt;br /&gt;Yang's new algorithm may signal a quantum leap in face-recognition technology. Professor Ssstry, dean of UC Berkeley's College of Engineering notes that Yang's new method obsolesces years of research in this field.  &lt;br /&gt;&lt;br /&gt;Nonetheless, the new technique could have profound impact in many areas, with new models for online advertising, new ways of annotating video and still images, and new techniques for identifying people in public places.&lt;br /&gt;&lt;br /&gt;See the complete article in &lt;a href="http://www.wired.com/science/discoveries/news/2008/03/new_face_recognition"&gt; Wired&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-8310791759496660948?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8310791759496660948'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8310791759496660948'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/03/engineers-test-highly-accurate-face.html' title='Engineers Test Highly Accurate Face Recognition'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-754442944218029261</id><published>2008-03-20T09:51:00.000-07:00</published><updated>2008-03-20T11:38:51.211-07:00</updated><title type='text'>Debugging Election Codes</title><content type='html'>An announcement on UC Berkeley's&lt;a href="http://www.eecs.berkeley.edu/"&gt; Electrical Engineering and Computer Sciences&lt;/a&gt; website tells of an article featuring David Wagner in the March issue of a Berkeley Engineering publication about his work reviewing voting machine systems code.&lt;br /&gt;&lt;br /&gt;Professor Wagner, as the Principal Investigator of a joint UC Berkeley-UC Davis project commissioned by California Secretary of State Debra Bowen, led a team whose comprehensive examination found major vulnerabilities in voting machine systems.&lt;br /&gt;&lt;br /&gt;While the machines were questioned immediately by grassroots activists, mainstream politics and media viewed their concerns about voting machine security as mere lunatic fringe behavior.  However, according to Wagner, forward-thinking election officials changed this opinion. "Some elections officers took the activists' concerns seriously and forced these vendors to pry open the covers and hand over the source code," Wagner recalls.  "That's what made it real; we could actually examine the code, so it wasn't just speculation anymore."&lt;br /&gt;&lt;br /&gt;While Wagner's review prompted Bowen to limit the machines to one per polling place, a well-designed electronic voting machine could be a benefit to democracy.&lt;br /&gt;&lt;br /&gt;See details in &lt;a href="http://innovations.coe.berkeley.edu/vol2-issue3-mar08/electioncodes"&gt; Innovations&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-754442944218029261?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/754442944218029261'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/754442944218029261'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/03/debugging-election-codes.html' title='Debugging Election Codes'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-2047338484466185493</id><published>2008-03-07T14:01:00.000-08:00</published><updated>2008-03-07T14:36:09.908-08:00</updated><title type='text'>Ranking Corporate America on Identity Theft</title><content type='html'>&lt;a href="http://bits.blogs.nytimes.com/2008/02/27/ranking-corporate-america-on-identity-theft/?ref=technology"&gt; &lt;br /&gt;The New York Times&lt;/a&gt; covered a report compiled by Chris Hoofnagle at the Berkeley Center for Law and Technology at the University of California at Berkeley on the institutions most frequently cited by consumers in fraud complaints.&lt;br /&gt;&lt;br /&gt;The country's largest banks and phone companies showed up most frequently, of course. To account for size, Mr. Hoofnagle factored in the total amount of deposits per institution as of Dec. 31, 2006. &lt;br /&gt;&lt;br /&gt;Mr. Hoofnagle said he believe the study was an important step in creating an "identity theft marketplace" for consumers.&lt;br /&gt;&lt;br /&gt;"I've been working for years to try to spark a market, a true market, for competition on preventing fraud," he said.  "Some of these institutions have attempted to compete based on advertisements, but I'm a real believer in the idea that if you give consumers information, they can make better decisions."&lt;br /&gt;&lt;br /&gt;For the complete report, see &lt;a href="http://repositories.cdlib.org/bclt/lts/44/"&gt; Measuring Identity Theft at Top Banks&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-2047338484466185493?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2047338484466185493'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2047338484466185493'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/03/ranking-corporate-america-on-identity.html' title='Ranking Corporate America on Identity Theft'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-5828686177248134714</id><published>2008-02-01T00:07:00.000-08:00</published><updated>2008-02-01T00:16:41.453-08:00</updated><title type='text'>Demands for Personal Information Controls on Social Networking Sites Increase</title><content type='html'>A &lt;a href="http://www.wsj.com/"&gt;Wall Street Journal&lt;/a&gt; &lt;a href="http://online.wsj.com/article/SB120164900173426771.html"&gt;article&lt;/a&gt; discusses the effects to online privacy introduced by services offered on social networking sites such as &lt;a href="http://www.facebook.com/"&gt;Facebook&lt;/a&gt; and &lt;a href="http://www.myspace.com/"&gt;MySpace&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;In the article, TRUST security and privacy researcher and clinical research specialist at the &lt;a href="http://www.berkeley.edu/"&gt;UC Berkeley&lt;/a&gt; &lt;a href="http://www.law.berkeley.edu/clinics/samuelson/"&gt;Samuelson Law, Technology &amp;amp; Public Policy Clinic&lt;/a&gt; &lt;a href="http://people.ischool.berkeley.edu/%7Ejenking/"&gt;Jennifer King&lt;/a&gt; weighs in on the data-sharing implications of such sites and advice to users about keeping their personal information and online activity more private.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-5828686177248134714?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/5828686177248134714'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/5828686177248134714'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/02/demands-for-personal-information.html' title='Demands for Personal Information Controls on Social Networking Sites Increase'/><author><name>Larry Rohrbough</name><uri>http://www.blogger.com/profile/01122887820002175089</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-252217430893907519</id><published>2008-01-31T11:45:00.000-08:00</published><updated>2008-01-31T11:46:08.869-08:00</updated><title type='text'>TRUST Spring 2008 Conference: April 2-3, 2008</title><content type='html'>The next TRUST Conference to be held April 2-3, 2008 at the &lt;a href="http://www.claremontresort.com/"&gt;Claremont Resort &amp;amp; Spa&lt;/a&gt; in Berkeley, CA.&lt;br /&gt;&lt;br /&gt;The schedule is to have a full day (~8:00 AM to 5:00 PM) April 2 and a half day (~8:00 AM to 12:00 PM) April 3.&lt;br /&gt;&lt;br /&gt;This event will provide you with an opportunity to hear firsthand about the work of TRUST faculty and students-specifically activities that:&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt; Advance a leading-edge research agenda to improve the state-of-the art in&lt;br /&gt;cybersecurity and critical infrastructure protection;&lt;br /&gt;&lt;br /&gt;&lt;li&gt; Develop a robust education plan to teach the next generation of computer scientists, engineers, and social scientists; and &lt;br /&gt;&lt;br /&gt;&lt;li&gt; Pursue knowledge transfer opportunities to transition TRUST results to end users within industry and the government.&lt;br /&gt;&lt;/ul&gt;&lt;br /&gt;For more information, see the &lt;a href="http://www.truststc.org/conferences/08/SpringConference/"&gt;Conference Page&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-252217430893907519?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/252217430893907519'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/252217430893907519'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2008/01/trust-spring-2008-conference-april-2-3.html' title='TRUST Spring 2008 Conference: April 2-3, 2008'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-1024595553864522650</id><published>2007-12-17T09:41:00.000-08:00</published><updated>2007-12-17T10:09:56.644-08:00</updated><title type='text'>A Legal Analysis of the Sony BMG Rootkit Debacle</title><content type='html'>Deirdre Mulligan and Aaron Perzanowski of the Berkeley Center for Law &amp; Technology published an &lt;a href="http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1072229"&gt; article &lt;/a&gt; on Sony BMG's deployment of digital rights management (DRM) systems that threaten the security of its customer's computers and the integrity of the information infrastructure in general.The DRM systems were released by Sony BMG on millions of Compact Discs in late 2005.&lt;br /&gt;&lt;br /&gt;A summary of the article can be found in &lt;a href="http://yro.slashdot.org/yro/07/12/17/0314218.shtml"&gt; Slashdot&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-1024595553864522650?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/1024595553864522650'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/1024595553864522650'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/12/legal-analysis-of-sony-bmg-rootkit.html' title='A Legal Analysis of the Sony BMG Rootkit Debacle'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-2884786902908025949</id><published>2007-12-14T10:22:00.000-08:00</published><updated>2007-12-14T10:33:10.598-08:00</updated><title type='text'>CPO Panel Highlights Privacy Challenges</title><content type='html'>On Wednesday, December 12, &lt;a href="http://www.truststc.org/"&gt;TRUST&lt;/a&gt; Policy Director &lt;a href="http://www.truststc.org/people/directory/dkm"&gt;Deirdre K. Mulligan&lt;/a&gt; participated in a panel of privacy experts for a discussion on &lt;a href="http://www.sun.com/aboutsun/media/presskits/2007-1212/index.jsp#about”"&gt;&lt;b&gt;&lt;i&gt;Privacy and the Network of You&lt;/b&gt;&lt;/i&gt;&lt;/a&gt;. The event was hosted by &lt;a href="http://www.sun.com/"&gt;Sun Microsystems&lt;/a&gt; and moderated by National Public Radio’s &lt;a href="http://www.technation.com/pages/GunnBio.html"&gt;Dr. Moira Gunn&lt;/a&gt;. Panelists from industry, academia, and the State of California discussed a number of challenges to personal privacy, data protection, and information security as well as recent events such as the large number of data breach incidents and identity theft cases.&lt;br /&gt;&lt;br /&gt;Prof. Mulligan, the Director of the &lt;a href="http://www.law.berkeley.edu/clinics/samuelson/"&gt;Samuelson Law, Technology &amp;amp; Public Policy Clinic&lt;/a&gt; and a Clinical Professor of Law at UC Berkeley, was joined by Chief Privacy Officers from &lt;a href="http://www.agilent.com/"&gt;Agilent&lt;/a&gt;, &lt;a href="http://www.intuit.com/"&gt;Intuit&lt;/a&gt;, and &lt;a href="http://www.sun.com/"&gt;Sun&lt;/a&gt; as well the Chief of the &lt;a href="http://www.privacy.ca.gov/"&gt;California Office of Privacy Protection&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-2884786902908025949?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2884786902908025949'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2884786902908025949'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/12/cpo-panel-highlights-privacy-challenges.html' title='CPO Panel Highlights Privacy Challenges'/><author><name>Larry Rohrbough</name><uri>http://www.blogger.com/profile/01122887820002175089</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-6425928316859645064</id><published>2007-12-10T15:59:00.000-08:00</published><updated>2007-12-10T16:09:17.553-08:00</updated><title type='text'>CSO Perspective on Security Breach Notification Laws</title><content type='html'>The &lt;a href="http://www.law.berkeley.edu/clinics/samuelson/"&gt;Samuelson Law, Technology &amp;amp; Public Policy Clinic&lt;/a&gt; at UC Berkeley released a &lt;a href="http://www.law.berkeley.edu/clinics/samuelson/cso_study.pdf"&gt;study&lt;/a&gt; on the effects of security breach notification laws in the United States. The study, co-funded by &lt;a href="http://www.truststc.org/"&gt;TRUST&lt;/a&gt;, is based on a thorough literature review as well as in-depth interviews with several Chief Information Security Officers (or their equivalents) from various industries. The CISO interviews provide insight into internal organizational structure around security investment decisions, regulatory and market factors that affect investment decisions, organizational responses to the enactment of security breach notification laws, market effects of security breaches, and industry best practices. This study is part of an ongoing effort to inform public policy with research into how businesses are affected by privacy law.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-6425928316859645064?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6425928316859645064'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6425928316859645064'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/12/cso-perspective-on-security-breach.html' title='CSO Perspective on Security Breach Notification Laws'/><author><name>Larry Rohrbough</name><uri>http://www.blogger.com/profile/01122887820002175089</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-8106917341698641413</id><published>2007-12-10T09:19:00.000-08:00</published><updated>2007-12-10T09:35:39.238-08:00</updated><title type='text'>Engineers Learning People Skills, Too</title><content type='html'>Shankar Sastry is quoted in an article in the &lt;a href="http://ap.google.com/article/ALeqM5jvMnxIDB4ae4c98pz4zwZI8hJwugD8TE418O0"&gt;Associated Press&lt;/a&gt;  yesterday about a change in producing engineering grads that are not only technically capable but able to communicate their expertise effectively.&lt;br /&gt;&lt;br /&gt;Dean of the College of Engineering and Director of TRUST, Sastry is asking professors to take a more Socratic approach to teaching, that is, more discussion and less rote drilling. &lt;br /&gt;&lt;br /&gt;"The days of boot camp -- where we say "Thou shalt study physics and mathematics and, oh by the way, you'll find out what's going to come out of this next year or the year after' -- I think are gone," says Sastry.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-8106917341698641413?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8106917341698641413'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8106917341698641413'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/12/engineers-learning-people-skills-too.html' title='Engineers Learning People Skills, Too'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-2631743884923256568</id><published>2007-12-04T15:34:00.000-08:00</published><updated>2008-01-31T11:43:29.994-08:00</updated><title type='text'>Applications for SECuR-IT,  WISE and SUPERB available until January 31, 2008</title><content type='html'>Applications to three summer TRUST programs are now being taken.  The closing date for applications is January 31, 2008.  The three programs are:&lt;br /&gt;&lt;br /&gt;Summer Experience, Colloquium and Research in Information Technology at Stanford University and San Jose State University (&lt;a href="http://www.truststc.org/securit"&gt;SECuR-IT&lt;/a&gt;)&lt;br /&gt;June 2 to August 8, 2008: Stanford &amp; San Jose&lt;br /&gt;Deadline for applications: &lt;b&gt;January 31, 2008&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Summer Undergraduate Program in Engineering Research at Berkeley (&lt;a href="http://www.truststc.org/superb"&gt;SUPERB&lt;/a&gt;)&lt;br /&gt;June 9 - August 01, 2008: Berkeley&lt;br /&gt;Deadline for applications: &lt;b&gt;January 31, 2008&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Women’s Institute in Summer Enrichment (&lt;a href="http://www.truststc.org/wise"&gt;WISE&lt;/a&gt;)&lt;br /&gt;June 8th through 13th, 2008: Ithaca, New York&lt;br /&gt;Deadline for applications: &lt;b&gt;March 31, 2008&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-2631743884923256568?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2631743884923256568'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2631743884923256568'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/12/applications-for-secur-it-wise-and.html' title='Applications for SECuR-IT,  WISE and SUPERB available until January 31, 2008'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-3852031938178484194</id><published>2007-11-16T09:53:00.000-08:00</published><updated>2007-11-16T11:44:59.508-08:00</updated><title type='text'>FaceBook: Giving Personal Info for Profit?</title><content type='html'>Facebook, the Internet social networking site, has decided to allow companies to create personalized ads for account holders (which number more than 50 million active users) with their friends' profile pictures attached.  Professor Ken Birman, computer science, and a member of the Team for Research in Ubiquitous Secure Technology (TRUST) thinks that Facebook's announcement is another step on an already slippery slope toward a lack of social privacy. &lt;br /&gt;&lt;br /&gt;Professor Birman said "I worry that we're gradually creating the world of Minority Report", referring to the futuristic sci-fi film where passersby are tracked as they move and are assailed with personalized advertising projected on walls.  "We're witnessing a massive erosion of privacy, and society as a whole seems to be accepting this trend without even questioning it."&lt;br /&gt;&lt;br /&gt;For the complete article see the Nov. 14th issue of the &lt;a href="http://cornellsun.com/node/26014"&gt; &lt;i&gt;Cornell Daily Sun&lt;/i&gt; &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-3852031938178484194?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/3852031938178484194'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/3852031938178484194'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/11/facebook-giving-personal-info-for.html' title='FaceBook: Giving Personal Info for Profit?'/><author><name>Mary Stewart</name><uri>http://www.blogger.com/profile/12297903454408422755</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-7987558609785722012</id><published>2007-10-25T07:49:00.000-07:00</published><updated>2007-10-25T08:00:56.291-07:00</updated><title type='text'>Stanford/TRUST faculty offer Advanced Computer Security Certificate Online: What You Don’t Know Can Hurt You</title><content type='html'>&lt;a href="http://www.truststc.org"&gt;TRUST&lt;/a&gt; faculty &lt;a href="http://www.truststc.org/people/directory/dabo"&gt;Dan Boneh&lt;/a&gt; and &lt;a href="http://www.truststc.org/people/directory/jcm"&gt;John Mitchell&lt;/a&gt; have developed an&lt;br /&gt;Advanced Computer Security Certificate that can be taken as online classes.  The &lt;a href="http://home.businesswire.com/portal/site/google/index.jsp?ndmViewId=news_view&amp;newsId=20071018005812&amp;newsLang=en"&gt; BusinessWire article states&lt;/a&gt;&lt;blockquote&gt;"Specific topics covered include secure software design, buffer overflows, SQL injection attacks, authentication, access control, data integrity, symmetric encryption, public-key cryptography, and more. The Advanced Computer Security certificate program requires six courses three core and three electives. The instructors regularly update the content. Each course is self- paced and approximately six hours long, and is available at any time. Detailed information about the program is found at &lt;a href="http://proed.stanford.edu/?security"&gt;http://proed.stanford.edu/?security&lt;/a&gt;."&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-7987558609785722012?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7987558609785722012'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7987558609785722012'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/10/stanfordtrust-faculty-offer-advanced.html' title='Stanford/TRUST faculty offer Advanced Computer Security Certificate Online: What You Don’t Know Can Hurt You'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-5254262022040350950</id><published>2007-10-25T07:32:00.000-07:00</published><updated>2007-10-25T07:39:43.407-07:00</updated><title type='text'>Security Focus Interviews Adam Barth about DNS Rebinding</title><content type='html'>Security Focus has an interview with &lt;a href="http://www.truststc.org"&gt;TRUST's&lt;/a&gt; &lt;a href="http://www.truststc.org/people/directory/abarth"&gt;Adam Barth&lt;/a&gt;.  The interview, "&lt;a href="http://www.securityfocus.com/columnists/455"&gt;Rebinding attacks unbound&lt;/a&gt;."  Adam is quoted as saying:&lt;blockquote&gt;"I'm a Ph.D. student at Stanford University and a member of the Stanford Web Security Lab. Collin Jackson, Andrew Bortz, Weidong Shao, Dan Boneh, and I are presenting &lt;a href="http://crypto.stanford.edu/dns/"&gt;a paper&lt;/a&gt; at the 2007 ACM Conference on Computer and Communications Security, detailing how to protect browsers from DNS rebinding attacks."&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-5254262022040350950?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/5254262022040350950'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/5254262022040350950'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/10/security-focus-interviews-adam-barth.html' title='Security Focus Interviews Adam Barth about DNS Rebinding'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-8004393229401658021</id><published>2007-10-17T08:00:00.000-07:00</published><updated>2007-10-17T08:17:36.813-07:00</updated><title type='text'>Adrian Perrig Leads Research Team Dedicated To Analyzing and Disrupting  Internet Attackers' Black Markets</title><content type='html'>Trust researcher &lt;a href="http://www.truststc.org/people/directory/adrian"&gt;Adrian Perrig's&lt;/a&gt; work is highlighted in a CMU press release: "&lt;a href="http://www.cmu.edu/news/archive/2007/October/oct15_internetblackmarkets.shtml"&gt;Carnegie Mellon's Adrian Perrig Leads Research Team Dedicated To Analyzing and Disrupting Internet Attackers' Black Markets&lt;/a&gt;."  The work, done in conjuction with &lt;a href="http://www.truststc.org/people/directory/vern"&gt;Vern Paxson&lt;/a&gt; and others is described as:&lt;blockquote&gt;To stem the flow of stolen credit cards and identity data, Carnegie Mellon researchers proposed two technical approaches to reduce the number of successful market transactions, including a slander attack and another technique, which were aimed at undercutting the cyber-crooks verification or reputation system.     &lt;br /&gt;&lt;br /&gt;"Just like you need to verify that individuals are honest on E-bay, online criminals need to verify that they are dealing with 'honest' criminals," Franklin said.&lt;br /&gt;&lt;br /&gt;In a slander attack, an attacker eliminates the verified status of a buyer or seller through false defamation. "By eliminating the verified status of the honest individuals, an attacker establishes a lemon market where buyers are unable to distinguish the quality of the goods or services," Franklin said.&lt;br /&gt;&lt;br /&gt;The researchers also propose to undercut the burgeoning black market activity by creating a deceptive sales environment.&lt;br /&gt;&lt;br /&gt;Perrig's team developed a technique to establish fake verified-status identities that are difficult to distinguish from other-verified status sellers making it hard for buyers to identify the honest verified-status sellers from dishonest verified-status sellers.&lt;br /&gt;&lt;br /&gt;"So, when the unwary buyer tries to collect the goods and services promised, the seller fails to provide the goods and services. Such behavior is known as 'ripping.' And it is the goal of all black market site's verification systems to minimize such behavior," said Franklin.&lt;/blockquote&gt;The work has also been featured in a &lt;a href="http://it.slashdot.org/it/07/10/16/176255.shtml"&gt;Slashdot&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-8004393229401658021?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8004393229401658021'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8004393229401658021'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/10/adrian-perrig-leads-research-team.html' title='Adrian Perrig Leads Research Team Dedicated To Analyzing and Disrupting  Internet Attackers&apos; Black Markets'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-2326882522286194093</id><published>2007-10-05T09:14:00.000-07:00</published><updated>2007-10-05T09:18:22.665-07:00</updated><title type='text'>The "Profiles in Team Science" document and website covers TRUST</title><content type='html'>Deborah Illman's, "&lt;a href="http://depts.washington.edu/teamsci"&gt;Profiles in Team Science&lt;/a&gt;," has a nicely done &lt;a href="http://www.truststc.org/pubs/288.html"&gt;overview&lt;/a&gt; of the &lt;a href="http://www.truststc.org"&gt;Team for Research in Ubiquitous Secure Technology (TRUST)&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-2326882522286194093?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2326882522286194093'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/2326882522286194093'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/10/profiles-in-team-science-document-and.html' title='The &quot;Profiles in Team Science&quot; document and website covers TRUST'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-4757604808316521777</id><published>2007-09-27T07:52:00.000-07:00</published><updated>2007-09-27T07:55:26.477-07:00</updated><title type='text'>Deirdre Mulligan: Data breach laws have had positive effect</title><content type='html'>Deirdre Mulligan is quoted in Silicon.com's article, "&lt;a href="http://management.silicon.com/itdirector/0,39024673,39168303,00.htm?r=1"&gt;Data breach laws 'make companies serious about security'&lt;/a&gt;." &lt;blockquote&gt;&lt;br /&gt;The legislation has had a positive effect on security, according to Deirdre Mulligan, clinical professor of law at the UC Berkeley School of Law.&lt;br /&gt;&lt;br /&gt;She told silicon.com: "I believe that the law has heightened the attention paid to information security. The initial impact of the law was likely to make incidents public but the lasting effect should be to reduce the number and severity of breaches by creating incentives to invest in security."&lt;br /&gt;&lt;br /&gt;Mulligan said her research had shown that security breaches drive information exchange among security professionals - for example some chief security officers summarised news reports from breaches at other organisations and circulated them to staff with 'lessons learned' from each incident.&lt;br /&gt;&lt;br /&gt;She said: "The goal of the law was to improve security practices, not provide notices. Research and anecdote both suggest that it has improved practices along many dimensions. As practices improve, notices should decrease."&lt;br /&gt;&lt;br /&gt;Some organisations have a 'that could have been us' moment and patch systems with similar vulnerabilities to the organisation that had a breach. The introduction of the legislation has meant an improved focus on security and better information about costs of failure, which allows for sounder investments, she added.&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-4757604808316521777?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4757604808316521777'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4757604808316521777'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/09/deirdre-mulligan-data-breach-laws-have.html' title='Deirdre Mulligan: Data breach laws have had positive effect'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-947944119300340668</id><published>2007-09-27T07:43:00.000-07:00</published><updated>2007-09-27T07:51:57.305-07:00</updated><title type='text'>Pam Samuelson named a Berkman Center Fellow</title><content type='html'>Pam Samuelson was named a fellow to the &lt;a href="http://cyber.law.harvard.edu"&gt;Berkman Center for Internet &amp; Society&lt;/a&gt;.  Professor Samuelson will be presenting the keynote on October 10 to the &lt;a href="http://www.charityadvantage.com/RSA_US/IntellectualPropertyLaw.asp#Cambridge"&gt;IP and the Trend towards Openness&lt;/a&gt; conference.  Details about Berkman fellows may be found in: "&lt;a href="http://www.maximsnews.com/107mnunseptember09berkmancenterannounces07_08fellows.htm"&gt;UN: Berkman Center Announces 07-08 Fellows&lt;/a&gt;."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-947944119300340668?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/947944119300340668'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/947944119300340668'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/09/pam-samuelson-named-berkman-center.html' title='Pam Samuelson named a Berkman Center Fellow'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-8448176742064526253</id><published>2007-09-26T07:51:00.000-07:00</published><updated>2007-09-26T07:58:38.393-07:00</updated><title type='text'>Engineering a new curriculum</title><content type='html'>CNet's article, "&lt;a href="http://www.news.com/Engineering-a-new-curriculum/2100-1008_3-6206799.html"&gt;Engineering a new curriculum&lt;/a&gt;," discusses an interview with UC Berkeley Dean of Engineering &lt;a href="http://www.truststc.org/people/directory/sastry"&gt;Shankar Sastry&lt;/a&gt;.  Dean Sastry discusses changes in the engineering curriculum, including mixing soft sciences such as sociology and economics with engineering.  This work is also part of the mission of the &lt;a href="http://www.truststc.org"&gt;Team for Research in Ubiquitous Secure Technology (TRUST)&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-8448176742064526253?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8448176742064526253'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8448176742064526253'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/09/engineering-new-curriculum.html' title='Engineering a new curriculum'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-192836745033920149</id><published>2007-09-09T17:07:00.000-07:00</published><updated>2007-09-09T17:20:16.461-07:00</updated><title type='text'>Trust Autumn 2007 Conference</title><content type='html'>The TRUST Autumn 2007 Conference October 10-11, 2007 will be held in Ithaca, NY and hosted by TRUST partner institution Cornell University.&lt;br /&gt;&lt;menu&gt;&lt;br /&gt;&lt;li&gt;Conference Information - The latest information on the event can be found on the conference page of the TRUST website at &lt;a href="http://www.truststc.org/conferences/07/FallRetreat/"&gt;http://www.truststc.org/conferences/07/FallRetreat/&lt;/a&gt;.  Please check back frequently as this page will be updated as more information is available.&lt;br /&gt;&lt;li&gt;&lt;a href="http://www.truststc.org/trust/private/5.html"&gt;Conference Hotel Information&lt;/a&gt; &lt;i&gt;Trust website account required, see &lt;a href="http://www.truststc.org/trust/faq/5.html"&gt;How can I request a login account on this website?&lt;/a&gt;&lt;/i&gt;&lt;br /&gt;&lt;li&gt; Registration - In order to plan for your arrival and have an accurate headcount of attendees, please register to let us know you will be attending the conference. You may &lt;a href="http://www.truststc.org/trustj/servlet/WorkshopRegistration?workshopID=12"&gt;register online&lt;/a&gt;.&lt;br /&gt;&lt;li&gt;Schedule - We are still finalizing the conference agenda and schedule of events.  The conference will run from ~8:30 AM to 5:30 PM on October 10 and ~8:30 AM to 12:00 PM on October 11.  Breakfast and lunch will be provided both days and we are organizing a dinner for the evening of October 10.  Please check the conference page of the TRUST website for the latest information and agenda.&lt;br /&gt;&lt;li&gt;The conference will feature TRUST researchers who are advancing a leading-edge agenda to improve the state-of-the art in cybersecurity and critical infrastructure protection.  It will provide you with an opportunity to hear firsthand about research, education, outreach, and technology transition activities within the TRUST center.  We hope you will join us for this exciting event!  If you have any questions or need additional information, please contact Sally Alcala, the TRUST Program Coordinator, at salcala at eecs dot berkeley edu or 510-643-8425.&lt;br /&gt;&lt;/menu&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-192836745033920149?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/192836745033920149'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/192836745033920149'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/09/trust-autumn-2007-conference.html' title='Trust Autumn 2007 Conference'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-65975931847036473</id><published>2007-09-09T17:02:00.000-07:00</published><updated>2007-09-09T17:06:12.031-07:00</updated><title type='text'>Symatec Graduate Fellowship</title><content type='html'>Darren Shou, Senior Manager at Symantec Research Labs writes:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;[...]we're now accepting applicants for our 2008 Symantec Fellowship. This is a multiple award, one year fellowship for graduate students pursuing innovative research related to information security and availability. It provides a $20,000 stipend, plus tuition and fees and is distinguished by an opportunity to work along-side our leading researchers.&lt;br /&gt;&lt;p&gt;&lt;a href="http://www.symantec.com/about/careers/college/fellowship.jsp&lt;br /&gt;"&gt;http://www.symantec.com/about/careers/college/fellowship.jsp&lt;/a&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-65975931847036473?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/65975931847036473'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/65975931847036473'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/09/symatec-graduate-fellowship.html' title='Symatec Graduate Fellowship'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-8739930013416135998</id><published>2007-08-15T07:33:00.000-07:00</published><updated>2007-08-15T07:36:52.290-07:00</updated><title type='text'>UK House of Lords report, "Personal Internet Security," includes TRUST talk summaries</title><content type='html'>TRUST faculty briefed the UK House of Lords Science and Technology committee when they visited UC Berkeley on March 7, 2007. Summaries of their talks can be found on pages 103-106 of the final report, "&lt;a href="http://www.truststc.org/pubs/281.html"&gt;Personal Internet Security&lt;/a&gt;."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-8739930013416135998?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8739930013416135998'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8739930013416135998'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/08/uk-house-of-lords-report-personal.html' title='UK House of Lords report, &quot;Personal Internet Security,&quot; includes TRUST talk summaries'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-6196278392233667253</id><published>2007-07-30T04:45:00.000-07:00</published><updated>2007-07-30T04:50:23.820-07:00</updated><title type='text'>Shankar Sastry named Dean of UCB College of Engineering</title><content type='html'>Shankar Sastry has been named &lt;a href="http://www.berkeley.edu/news/media/releases/2007/07/19_sastry.shtml"&gt;Dean of the College of Engineering&lt;/a&gt; at UC Berkeley.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-6196278392233667253?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6196278392233667253'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6196278392233667253'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/07/shankar-sastry-name-dean-of-ucb-college.html' title='Shankar Sastry named Dean of UCB College of Engineering'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-4596146617725077112</id><published>2007-07-30T04:23:00.000-07:00</published><updated>2007-07-30T04:45:20.141-07:00</updated><title type='text'>Ken Goldberg named director of Center for New Media</title><content type='html'>UC Berkeley Professor &lt;a href="http://goldberg.berkeley.edu/"&gt;Ken Goldberg&lt;/a&gt; has been &lt;a href="http://www.berkeley.edu/news/media/releases/2007/06/28_goldberg.shtml"&gt;named director of the Center for New Media&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-4596146617725077112?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4596146617725077112'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/4596146617725077112'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/07/ken-goldberg-named-director-of-center.html' title='Ken Goldberg named director of Center for New Media'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-3730314073412631628</id><published>2007-07-16T14:33:00.000-07:00</published><updated>2007-07-16T14:39:44.525-07:00</updated><title type='text'>Beyond SCADA Research Strategies and Roadmap</title><content type='html'>"&lt;a href="http://www.truststc.org/pubs/262/BeyondSCADA_Annual.Report07.pdf"&gt;National Workshop on Beyond SCADA: Networked Embedded Control for Cyber-Physical Systems (NEC4CPS): Research Strategies and Roadmap,&lt;/a&gt;" by Bruce Krogh, Marija Ilic and S. Shankar Sastry is available for download by &lt;a href="http://www.truststc.org/trust/faq/5.html"&gt;TRUST Members&lt;/a&gt;.&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;This annual report is a draft version of the final report to be published by the  National Coordination Office (NCO) of the NITRD. The final version of this report will also be the final report for the NSF grant to support the two workshops:&lt;br /&gt;&lt;ol&gt;&lt;br /&gt;&lt;li&gt; &lt;a href="http://www.truststc.org/conferences/06/ScadaWashington/index.htm"&gt;National Planning Workshop, March 16, 17, 2006&lt;/a&gt; and&lt;br /&gt;&lt;li&gt; &lt;a href="http://www.truststc.org/conferences/06/ScadaPittsburgh/"&gt;Final National Workshop held November 8,9, 2006.&lt;/a&gt;&lt;br /&gt;&lt;/ol&gt;&lt;br /&gt;The details of the participants, program, and the presentations at the workshop and discussions on a Wiki site are available at &lt;a href="http://www.truststc.org/scada"&gt;http://truststc.org/scada&lt;/a&gt; (See also Appendix 1 and 2 of this report for this information for the second of the workshops).&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-3730314073412631628?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/3730314073412631628'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/3730314073412631628'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/07/beyond-scada-research-strategies-and.html' title='Beyond SCADA Research Strategies and Roadmap'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-1949760612514752452</id><published>2007-07-14T17:39:00.000-07:00</published><updated>2007-07-14T17:42:37.315-07:00</updated><title type='text'>EUUS High Confidence Evolutionary Embedded Systems Annual Report</title><content type='html'>Professor Shankar Sastry has released the &lt;a href="http://www.truststc.org/pubs/259/euus-tekes-LongTermChallengesInHighConfidenceEvolutionaryEmbeddedSystems_0607AnnualReport.pdf"&gt;"Annual Progress Report, Joint EU-US-Tekes Workshop, "Long Term Challenges in High Confidence Evolutionary Embedded Systems", Grant No CNS-06369330".&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-1949760612514752452?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/1949760612514752452'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/1949760612514752452'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/07/euus-high-confidence-evolutionary.html' title='EUUS High Confidence Evolutionary Embedded Systems Annual Report'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-38075687531364707</id><published>2007-06-20T12:10:00.000-07:00</published><updated>2007-06-20T12:15:53.054-07:00</updated><title type='text'>Intellectual Property Scholars Conference: August 8 and 9: Chicago</title><content type='html'>&lt;a href="http://www.law.berkeley.edu/institutes/bclt/"&gt;The Berkeley Center for Law and Technology&lt;/a&gt; is one of the sponsors of the &lt;a href="http://www.law.depaul.edu/institutes_centers/ciplit/ipsc/default.asp"&gt;Intellectual Property Scholars Conference&lt;/a&gt; to be held August 8 &amp; 9 at DePaul in Chicago.  &lt;a href="http://www.truststc.org/people/directory/aburstein"&gt;Aaron Burstein&lt;/a&gt; will present &lt;a href="http://www.law.depaul.edu/institutes_centers/ciplit/ipsc/pdf/Aaron_Burstein.pdf"&gt;Toward a Culture of Cyber Security Research&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-38075687531364707?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/38075687531364707'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/38075687531364707'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/06/intellectual-property-scholars.html' title='Intellectual Property Scholars Conference: August 8 and 9: Chicago'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-1299104217721296443</id><published>2007-06-13T14:20:00.000-07:00</published><updated>2007-06-13T15:43:55.323-07:00</updated><title type='text'>Technology and Privacy Workshop, Berkeley, June 22</title><content type='html'>&lt;a href="http://www.law.berkeley.edu/institutes/bclt/"&gt;The Berkeley Center for Law and Technology&lt;/a&gt; and the &lt;a href="http://www.truststc.org"&gt;Team for Research in Ubiquitous Secure Technology (TRUST)&lt;/a&gt; are hosting a &lt;a href="http://www.truststc.org/conferences/07/TechnologyAndPrivacyBerkeley.htm"&gt;day-long workshop&lt;/a&gt; for academics and advocates to discuss technology and privacy issues on Friday, June 22nd at the University of California, Berkeley, &lt;a href="http://www.law.berkeley.edu/administration/visitors/directions.html"&gt;Boalt Hall School of Law Goldberg Room&lt;/a&gt;.&lt;br /&gt;&lt;p&gt;The main goals of this workshop are:&lt;br /&gt;&lt;ol&gt;&lt;br /&gt;&lt;li&gt; to help academics identify research opportunities in privacy law&lt;br /&gt;&lt;li&gt; to help academics engage the policy process, and&lt;br /&gt;&lt;li&gt; to help advocates identify existing research for use in their work.&lt;br /&gt;&lt;/ol&gt;&lt;br /&gt;It will be an excellent opportunity to develop strategy, identify empirical data for more research, and to think about theoretical frameworks of privacy.  The format will be a directed discussion, with panels of civil liberties advocates, technologists, and consumer privacy experts.  A full schedule and agenda will be posted soon.&lt;br /&gt;&lt;p&gt;Please let &lt;a href="http://www.law.berkeley.edu/faculty/profiles/facultyProfile.php?facID=\&lt;br /&gt;6494"&gt;Chris Hoofnagle (choofnagle at law.berkeley.edu)&lt;/a&gt; know if you'd like to attend.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-1299104217721296443?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/1299104217721296443'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/1299104217721296443'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/06/technology-and-privacy-workshop.html' title='Technology and Privacy Workshop, Berkeley, June 22'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-642047732961486025</id><published>2007-06-10T20:42:00.000-07:00</published><updated>2007-06-10T20:43:51.155-07:00</updated><title type='text'>June 22: 3rd Trustworthy Interfaces for Passwords and Personal Information (TIPPI) Workshop</title><content type='html'>On June 22, Stanford will host the &lt;a href="http://crypto.stanford.edu/TIPPI/"&gt;3rd Trustworthy Interfaces for Passwords and Personal Information (TIPPI) Workshop&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-642047732961486025?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/642047732961486025'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/642047732961486025'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/06/june-22-3rd-trustworthy-interfaces-for.html' title='June 22: 3rd Trustworthy Interfaces for Passwords and Personal Information (TIPPI) Workshop'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-1707366341015437491</id><published>2007-06-08T11:00:00.000-07:00</published><updated>2007-06-08T11:03:42.166-07:00</updated><title type='text'>EU-US Workshop on Wirelessly Networked Embedded Systems</title><content type='html'>The &lt;a href="http://euusworkshop07.specknet.org"&gt;EU-US Workshop on Wirelessly Networked Embedded Systems&lt;/a&gt; will occur on 10 July, 2007, in University of Edinburgh. This workshop is the fourth in the series of themed EU-US workshops after &lt;a href="http://www.artist-embedded.org/docs/Events/2005/IST-NSF"&gt;Paris (2005)&lt;/a&gt;, &lt;a href="http://www.truststc.org/euus/wiki/Euus/WashingtonMeeting"&gt;Washington (March 2006)&lt;/a&gt; and &lt;a href="http://www.truststc.org/euus/wiki/Euus/HelsinkiMeeting"&gt;Helsinki (June 2006)&lt;/a&gt;. The theme of the Edinburgh workshop is "Cyber-Physical Systems and Beyond".&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-1707366341015437491?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/1707366341015437491'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/1707366341015437491'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/06/eu-us-workshop-on-wirelessly-networked.html' title='EU-US Workshop on Wirelessly Networked Embedded Systems'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-6848497665059767740</id><published>2007-06-05T16:55:00.000-07:00</published><updated>2007-06-05T17:27:06.201-07:00</updated><title type='text'>TRUST 2006-2007 Annual Report Available</title><content type='html'>The &lt;a href="http://www.truststc.org/pubs/257.html"&gt;TRUST 2006-2007 Annual Report&lt;/a&gt; is now available.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-6848497665059767740?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6848497665059767740'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/6848497665059767740'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/06/trust-2006-2007-annual-report-available.html' title='TRUST 2006-2007 Annual Report Available'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-8278588574245396292</id><published>2007-05-09T16:58:00.000-07:00</published><updated>2007-05-09T17:37:45.491-07:00</updated><title type='text'>California Voting Computer review panel includes David Wagner</title><content type='html'>The California Secretary of State's website has an article, "&lt;a href="http://www.ss.ca.gov/elections/elections_vsr.htm"&gt;Top-To-Bottom Review&lt;/a&gt;," that says:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;Secretary of State Debra Bowen will begin a thorough top-to-bottom review of the voting machines certified for use in California the week of May 14, 2007. The review is designed to restore the public's confidence in the integrity of the electoral process and is designed to ensure that California voters are being asked to cast their ballots on machines that are secure, accurate, reliable, and accessible. &lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;The panel will include &lt;a href="http://www.truststc.org"&gt;TRUST&lt;/a&gt; members &lt;a href="http://www.eecs.berkeley.edu/~daw"&gt;David Wagner&lt;/a&gt;, &lt;a href="http://www.law.berkeley.edu/faculty/profiles/facultyProfile.php?facID=1018"&gt;Deirdre Mulligan&lt;/a&gt; and &lt;a href="http://josephhall.org/"&gt;Joseph Lorenzo Hall&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-8278588574245396292?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8278588574245396292'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/8278588574245396292'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/05/california-voting-computer-review-panel.html' title='California Voting Computer review panel includes David Wagner'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-37642592.post-7112677698808448958</id><published>2007-05-09T06:56:00.000-07:00</published><updated>2007-05-09T07:02:58.199-07:00</updated><title type='text'>David Wagner testifies on Electronic Voting</title><content type='html'>&lt;a href="http://www.cs.berkeley.edu/~daw/"&gt;David Wagner&lt;/a&gt; supplied written testimony, "&lt;a href="http://votetrustusa.org/index.php?option=com_content&amp;task=view&amp;id=2435&amp;Itemid=26"&gt;Testimony on Voting System Testing and Cerification&lt;/a&gt;," to the &lt;a href="http://oversight.house.gov/subcommittees.asp"&gt;Committee on Oversight and Government Reform&lt;/a&gt;, Subcommittee on Information Policy, Census, and National Archives on May 7, 2007.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/37642592-7112677698808448958?l=trust-website-news.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7112677698808448958'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/37642592/posts/default/7112677698808448958'/><link rel='alternate' type='text/html' href='http://trust-website-news.blogspot.com/2007/05/david-wagner-testifies-on-electronic.html' title='David Wagner testifies on Electronic Voting'/><author><name>Christopher Brooks</name><uri>http://www.blogger.com/profile/03042907938411870505</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://ptolemy.eecs.berkeley.edu/image/ptolemySmall.gif'/></author></entry></feed>
