Wednesday, March 05, 2008

RateMyCop

RateMyCop.com is a new website that allows you to rate individual police officers on the basis of your interactions with them, on the attributes of authority, fairness, and satisfaction, for which you can rate them poor, average, or good, and leave specific comments about your interactions. The site describes itself like this:
Welcome to RATEMYCOP.com, the online watchdog organization serving communities nationwide. RATEMYCOP.com is not affiliated with any government agency; we are an independent, privately managed organization.

Our mission is to compile information on cops’ performance and to provide a forum where users can freely share individual accounts. Good, bad or indifferent. Most of all, we would like to hear your stories. Your appreciation and your disapproval. Did you witness a cop doing a good deed, or were you involved in an unfortunate altercation? Tell us about it. Tell others about it. Let it out. Don’t feel intimidated by the badge to remain quiet.

While we respect their authority we are also free to question it. You have the right to remain informed.
The site has lists of 120,000 individual police officers from 450 departments around the country, which the site obtained directly from police departments, asking only for the names of patrol officers who work with the general public, not undercover officers. There are no photos, addresses, or telephone numbers, only names.

The city of Tempe has expressed disapproval and its intention to try to remove this information from the site, according to an ABC 15 News story which claims the site is a danger to officers. Tempe Police Department Officer Tony Miller is quoted in the story raising issues about undercover officers, and the article says that he "feels as though officers like him are scrutinized enough." The article also states that "Tempe officer Brandon Banks says the department's chief, human resources and even the city's prosecutor are looking into the website and fighting it." I don't see that they have a case, this information should all be a matter of public record.

It seems to me that there is potential for abuse (especially in the form of inaccurate ratings and comments, just as on teacher rating websites), but less so than there is from other kinds of public records about all of us that are published on the web. I disagree with Officer Miller's opinion that there is already sufficient accountability for police officers; this blog's previous posts in the "police abuse and corruption" category and the far more numerous and detailed posts from Radley Balko's The Agitator blog and his article "Overkill" are overwhelming evidence to the contrary.

It's worth noting that the courts have repeatedly ruled that there is no duty of police officers to protect individual members of the public, and many states have statutes which prevent individual officers and departments from being held civilly liable for a failure to provide adequate protection, a fact often used by gun advocates to argue for widespread gun ownership for individual protection (e.g., here, here, and here). The U.S. Supreme Court also eliminated a major protection against police abuse in 2006, when it ruled in Hudson v. Michigan (PDF) that evidence from an illegal no-knock raid need not be excluded from trial, because police officers have entered a new realm of "professionalism" in which they recognize civil liberties and can be trusted to investigate and deter their own abuses. In the wake of such decisions and continuing abuses, a website such as RateMyCop.com seems to me like a good idea.

What the site seems to be missing, though, is a way to quickly find officers who have received ratings (very few seem to have any yet), and to sort those in order to find those with favorable or unfavorable ratings.

UPDATE (March 12, 2008): Apparently GoDaddy has pulled the plug on RateMyCop.com's website without notice to the owner, allegedly first for "suspicious activity" and then for exceeding bandwidth limits, and the site is up with a new web hosting provider.

It looks like the ratings are now on a single category, and you can see a list of the most-rated and most-recently-rated on the front page. Another feature that would be nice would be a way to allow registered users to rate the raters for reliability, similar to the way Amazon.com book reviews can be rated as helpful or not helpful. That way, ratings could be weighted based on judgments of the reliability of the raters from the user base, and ratings from those with a personal axe to grind could have their weight minimized.

Looks like Rackspace has also refused to host ratemycop.com.

Interestingly, apparently Gino Sesto of RateMyCop.com was a Bush voter.

Tuesday, March 04, 2008

McCain thankful for support of raving nutcase

John McCain is "very honored" for the endorsement of Pastor John Hagee of Christians United for Israel, a televangelist who thinks that the Jews provoked the Holocaust, that the Illuminati is engaged in conspiratorial control of the world's governments, that the Catholic Church is the "whore of Babylon" in the Book of Revelations, that George Washington hid a picture of a menorah in the tailfeathers of the eagle on the dollar bill, and that a U.S. invasion of Iran is prophesied by the Bible.

Ed Brayton has discussed Hagee's views, and Troutfishing at Daily Kos has some videos documenting Hagee absurdity.

UPDATE (May 22, 2008): Finally, McCain has repudiated Hagee's endorsement, claiming that he's only just learned of his nastier views and remarks.

UPDATE (May 23, 2008): Hume's Ghost points out the difference between McCain's relationship with Hagee and Parsley, and Obama's relationship with Wright, as well as the extremely nasty anti-Semitic remarks from Hagee that prompted McCain's repudiation (all Jews have "dead souls," for example).

Pat Boone's Limitless Stupidity

Pat Boone writes a column in which he imagines a conversation between himself and Thomas Jefferson, in which he completely misrepresents Jefferson's views and quite a few facts. Ed Brayton supplies a critique. (You can find the link to Boone's column there.)

Saturday, March 01, 2008

Jeremy Jaynes loses appeal on spamming case

Jeremy Jaynes, the spammer who was convicted and sentenced to nine years in prison in 2003 for violating Virginia's anti-spam law, has lost his appeal before the Virginia Supreme Court in a 4-3 ruling. Several of the dissents claimed that Virginia's anti-spam law, which criminalizes unsolicited bulk email with falsified headers, even if it is political or religious in content rather than commercial, is a violation of the First Amendment. The quotations from Justice Elizabeth Lacy and Jaynes' attorney Thomas M. Wolf both state that the law has diminished everyone's freedom by criminalizing "bulk anonymous email, even for the purpose of petitioning the government or promoting religion."

Both Lacy and Wolf misrepresent the law, which makes it a crime to "Falsify or forge electronic mail transmission information or other routing information in any manner in connection with the transmission of unsolicited bulk electronic mail through or into the computer network of an electronic mail service provider or its subscribers."

There is a difference between forging headers and sending anonymous email--the latter does not require the former, and the latter is not prohibited by the law. Jaynes wasn't just trying to be anonymous--he was engaged in fraud, and falsifying message headers and from addresses to try to avoid the consequences of his criminality. He wasn't using anonymous remailers to express a political or religious message, and if he had been, he wouldn't have been able to be charged under this law.

UPDATE (September 12, 2008): The Virginia Supreme Court has reversed itself and struck down Virginia's anti-spam law as unconstitutional, on the grounds that prohibiting false routing information on emails infringes upon the right to anonymous political or religious speech. This is a very bad decision for the reasons I gave above. There are ways to engage in anonymous speech without doing what Jaynes did, falsifying message headers and domain names. The court's argument that one must falsify headers, IP addresses, and domain names in order to be anonymous is factually incorrect. Anonymity doesn't require header falsification, it only requires *omission* of identifying information.

Thursday, February 28, 2008

1 in 100 American adults are in prison

The United States has now reached an incarceration rate of 1 in every 99.1 adults, the highest rate in the world. We're spending an enormous amount of money to train people to be hardened criminals by throwing people convicted of nonviolent drug-related crimes into prisons with real criminals.

Finland, by contrast, has one of the lowest incarceration rates in the world, which has been in place for over 30 years. There is no correlation between crime rates and incarceration rates. In my opinion, we should decriminalize drug use, get rid of mandatory minimums, and adopt a model much closer to Finland's, where only violent offenders are imprisoned. Those who cause other kinds of harm to others should be required to make restitution to their victims.

Phoenix Flippers in Trouble

I'd seen similar blogs for California cities, now I'm glad to see there's one for Phoenix. The site lists homes currently for sale at a loss, ordered from greatest total loss to least. Most of these homes have been flipped multiple times before the current flipper got stuck with it.

Despite what a realtor might tell you, when you see homeowners repeatedly reducing prices like this, it is not a good time to buy. It's a good time to wait and watch prices continue to drop. When you start seeing prices go back up for a while, then it might be a good time to buy--it's much better to buy after things have bottomed out and started to increase again than it is to buy on the way down. That's sometimes referred to as "catching a falling knife."

I wouldn't consider buying anything until 2010 at the earliest. We haven't yet even seen the peak of subprime ARM resets, which should hit in the next few months. Then we still have Alt-A ARM resets to peak after that.

Tuesday, February 26, 2008

Arizona #4 for January foreclosures

Nationwide, foreclosures are up 57% for January 2008 vs. January 2007 (and up 8% vs. December 2007), and the top states for foreclosures in January (on a per-capita basis) were:

1. Nevada
2. California
3. Florida
4. Arizona
5. Colorado
6. Massachusetts
7. Georgia
8. Connecticut
9. Ohio
10. Michigan

Repossessions are up 90% or January 2008 compared to January 2007.

Of course I'm right

I do try to be accurate and correct my mistakes. I was happy to read on the Village Voice's blog that I'm "right." But I think they mean politically right. In some cases, I'm sure I'm to the right of the Village Voice. In others, I'm sure I'm right there with them on the left.

I suppose it could be argued that defending InfraGard from falsehoods is "right" in both senses.

Here's the comment I posted at the Village Voice blog:
I'll happily have my blog characterized as "right" meaning "correct," but I don't think it's terribly accurate to refer to much of its content as politically right wing. I would be happy to hear that ending the war in Iraq, ending the war on drugs, legalizing gay marriage, impeaching George W. Bush, abolishing the CIA, strict separation of church and state, and free speech absolutism (all positions defended at my blog) are now endorsed by the political right--it's about time.

Thanks for the link.
(Obligatory xkcd cartoon about being right. Kat can vouch for its accuracy.)

Monday, February 25, 2008

Pakistan takes out YouTube, gets taken out in return

As ZDNet reports, yesterday afternoon, in response to a government order to filter YouTube (AS 36561), Pakistan Telecom (AS 17557, pie.net.pk) announced a more-specific route (/24; YouTube announces a /23) for YouTube's IP space, causing YouTube's Internet traffic to go to Pakistan Telecom. YouTube then re-announced its own IP space in yet more-specific blocks (/25), which restored service to those willing to accept routing announcements for blocks that small. Then Pakistan Telecom's upstream provider, PCCW (AS 3491), which had made the mistake of accepting the Pakistan Telecom /24 announcement for YouTube in the first place, shut off Pakistan Telecom completely, restoring YouTube service to the world minus Pakistan Telecom. They got what they wanted, but not quite in the manner they intended.

Don't mess with the Internet.

Martin Brown gives more detail at the Renesys Blog, including a comment on how this incident shows that it's still a bit too easy for a small ISP to disrupt service by hijacking IPs, intentionally or inadvertently. Danny McPherson makes the same point at the Arbor Networks blog, and also gives a good explanation of how the Pakistan Internet provider screwed up what they were trying to do.

Somebody still needs to update the Wikipedia page on how Pakistan censors the Internet to cover this incident.

UPDATE: BoingBoing reports that the video which prompted this censorship order was an excerpt from Dutch Member of Parliament Geert Wilders' film "Forbidden" criticizing Islam, which was uploaded to YouTube back on January 28. I've added "religion" and "Islam" as labels on this post, accordingly. The two specific videos mentioned by Reporters without Borders as prompting the ban have been removed from YouTube, one due to "terms of use violation" and one "removed by user." The first of these two videos was supposedly the Geert Wilders one; the second was of voters describing election fraud during the February 18 Parliamentary elections in Pakistan. This blog suggests that the latter video was the real source of the attempted censorship gone awry, though the Pakistan media says it was the former. So perhaps the former was the pretext, and the latter was the political motivator.

A "trailer" for Wilders' film is on YouTube here. Wilders speaks about his film on YouTube here and here. Ayaan Hirsi Ali defends Wilders on Laura Ingraham's show on Fox News here. (Contrary to the blog post I've linked to, Hirsi Ali was not in the Theo Van Gogh film "Submission Part One," which can itself be found here, rather, she wrote it. Van Gogh was murdered as a result of it. The beginning and end is in Arabic with Dutch subtitles, but most of it is in English with Dutch subtitles.)

UPDATE (February 26, 2008): This just in, from Reuters--Pakistan "might have been" the cause of the YouTube outage. Way to be on the ball with breaking news, Reuters!

The Onion weighs in on the controversy!

Sunday, February 24, 2008

New Mexico InfraGard conference

On Friday, I attended the New Mexico InfraGard Member Alliance's "$-Gard 2008" conference in Albuquerque. It was an excellent one-day conference that should be used as a model by other chapters. The conference was open to the public, and featured an informative and entertaining two-hour seminar on fraud and white collar crimes by Frank Abagnale, author of the autobiographical Catch Me If You Can and anti-fraud books The Art of the Steal and Stealing Your Identity. (Another version of Abagnale's talk can be viewed as an online webinar courtesy of City National Bank.) Abagnale argued that fraud has become much easier today than it was when he was a criminal forger, with numerous examples, and also offered some simple and relatively inexpensive ways for businesses and individuals to protect themselves. For example, he recommended the use of microcut shredders, and observed that his own business keeps shredders near every printer, and no documents get thrown away, everything gets shredded. He recommended the use of a credit monitoring service like Privacy Guard, and that if you write checks, you use a black uniball 207 gel pen, which is resistant to check-washing chemicals. For businesses that accept cash, he recommended training employees in some of the security features of U.S. currency rather than relying on pH testing pens, which are essentially worthless at detecting counterfeit money. By recognizing where bills use optical variable ink, for example, you can easily test for its presence in the time it takes you to accept bills from a customer and transfer them into a cash register. He also recommended that businesses use bank Positive Pay services to avoid having business checks altered. Other speakers included Anthony Clark and Danny Quist of Offensive Computing, who gave a talk on "Malware Secrets," based on their research and collection of 275,000 malware samples. Their talk included an overview of the economics of malware, which I believe is essential for understanding how best to combat it. They looked at the underground economy fairly narrowly focused on malware itself, and the cycle of its production, use, reverse engineering by whitehats, the development of antivirus patterns, and then demand for new undetectible malware, and observed that in that particular cycle it's probably the legitimate security companies such as antivirus and IDS vendors who make the most money. They didn't really look at the broader features of the underground economy, such as how botnets are used as infrastructure for criminal enterprises, or the division of criminal labor into different roles to disperse risk, though they certainly mentioned the use of compromised machines for spamming and phishing attacks. They skipped over some of the technical details of their work on automating the unpacking and decryption of malware, which was probably appropriate given the mixed levels of technical background in this audience. A particularly noteworthy feature of their research was their list of features of antivirus software that should be examined when making a purchase decision--performance, detection rates, miss rates, false positive rates, system intrusiveness, a product's own security, ease of mass deployment, speed, update frequency, use of signatures vs. other detection methods, ability to clean, capabilities with various categories of malware (rootkits, trojans, worms, backdoors, spyware), and ability to detect in real time vs. during a scan. Alex Quintana of Sandia National Labs also spoke about current trends in malware, in the most frightening talk of the conference. He talked about how malware has gone from something that attacks exposed servers on the Internet to something that individual clients pull to their machines from the Internet, usually via drive-by downloads. He demonstrated real examples of malware attacks via web pages and via Shockwave Flash, PowerPoint, and Word documents, and explained how one of his colleagues has coined the word "snares" for emails or web pages that lure individuals into targeted drive-by malware downloads. There was a wealth of interesting detail in his presentation, about trojans that use covert tunnels and hiding techniques, injecting themselves into other running processes, using alternate data streams, and obfuscated information in HTTP headers and on web pages. One trojan he described rides on removable media such as USB thumbdrives and runs when inserted into a PC thanks to Windows Autorun; it drops one component that phones home to accept instructions from a command and control server, and another that causes the malware to be written out on any other removable device inserted into the machine. It's a return of the old-fashioned virus vector of moving from machine to machine via removable media rather than over the network. From law enforcement, there were presentations from Melissa McBee-Anderson of the Internet Crime Complaint Center (IC3, another public-private partnership, which acts as a clearinghouse for Internet crime complaints and makes referrals of complaints to appropriate federal, state, , local, and international law enforcement agencies) and from various agents of the Cyber Squad of the Albuquerque FBI office. These presentations were somewhat disappointing in that they demonstrated how huge the problem is, yet how few prosecutions occur. For example, after the 2004 tsunami disasters, there were over 700 fake online charities set up to prey on people's generosity after a disaster, yet only a single prosecution came of it. In 2005, the number of fake online charities for hurricanes Katrina and Rita was over 7,000, yet only five prosecutions came of those, including one in Albuquerque. Yet even that "successful" prosecution led to no jail time, only community service and probation. Frank Abagnale's presentation also included some woeful statistics about prosecutions for white collar crime and check fraud that explicitly made the same point that was implicit in several of the law enforcement presentations. To IC3's credit, however, the showed an example of a link chart generated from their crime complaint data, a very tiny portion of which was brought to them by a law enforcement agency seeking more information, the rest of which came from multiple received complaints. That link chart showed many interconnected events by five organized fraud gangs. Ms. McBee-Anderson also reported on successful international rosecutions against individuals at Lagos, Nigeria's "walking Wal-Mart," where people were selling goods purchased with stolen credit card information and using forged cashier's checks. (I'm still amazed that anyone actually falls for the Nigerian online fraud schemes, but they do.) The conference did a good job of making clear some specific threats and offering recommendations on necessary (yet unfortunately individually insufficient) defenses. It's quite clear that relying solely on law enforcement to provide you with a remedy after the fact is a bad idea. It's essential that private enterprises take preventative measures to protect themselves, and use a layered, defense-in-depth approach to do so.

UPDATE (23 October 2022): Note that Frank Abagnale's life story of con artistry turned out itself to be a con, as documented in Alan C. Logan's book, The Greatest Hoax on Earth: Catching Truth, While We Can (2020).