Risk Factor iconRisk Factor

IRS IT Improvement Speeds Rebate Checks


In a bit of good news, Government Computer News reports that a new Internal Revenue Service (IRS) computer program upgrade allowed the taxpayer rebate checks to be sent out a week earlier than expected. The initial schedule called for the checks to be sent this Friday, 2 May, but now they are going out today.

Some 130 million taxpayers are expected to receive a total of $110 billion starting now and running into July. The checks, which will be (depending on income) $600 per taxpayer, $1200 per couple and $300 per child, will be sent out according to the last two numbers of a person's Social Security number.

The IRS is also warning of likely scams in regard to the rebates as well. As noted on the IRS website:

"Some people have received phone calls about the economic stimulus payments, in which the caller impersonates an IRS employee. The caller asks the taxpayer for their Social Security and bank account numbers, claiming that the IRS needs the information to complete the processing of the taxayer's payment. In reality, the IRS uses the information contained on the taxpayer's tax return to process stimulus payments, rather than contacting taxpayers by phone or e-mail."

"An e-mail claiming to come from the IRS about the '2008 Economic Stimulus Refund' tells recipients to click on a link to fill out a form, apparently for direct deposit of the payment into their bank account. This appears to be an identity theft scheme to obtain recipients' personal and financial information so the scammers can clean out their victims' financial accounts. In reality, taxpayers do not have to fill out a separate form to get a stimulus payment or have it directly deposited; all they had to do was file a tax return and provide direct deposit information on the return."

So, spend wisely and avoid the scammers.

And kudos to the IRS.

Hey, I Just Won a Million Pounds!


It must be my lucky day! I just got an email saying I won a £1,000,000.00 GBP. All I had to do to collect was to provide a few personal details at the "winners' " website.

Earlier in the week, I got an emails from people in the Republic of Western Sahara, Scotland, South Africa and the Philippines all having money burning in their pockets that they were wishing to share with me.

I must be one lucky guy, eh?

My collection of unique phishing emails now approaches 120. I got a new one this morning that was in Italian - my first - stating (if my translation was correct) that my account at some website had some incorrect data and I needed to immediately sign in and fix it.

I am curious - does anyone have a real funny or different phishing email to share?

Want a $400,000 IT Job?


The London Times is reporting that the UK National Health Service (NHS) is looking for two senior executives to take over the job of leading its electronic health record project National Programme for IT (NPfIT). The salary is $400,000 or possibly more, with the "exact package to be negotiated and agreed with the successful candidates."

The two jobs cover the work covered by Richard Granger who resigned as Director-General, NHS IT, last year after five years.

Anyone interested? You have until the 28th of April to apply.

Congrats to Baker College for Winning Cyber Defense Competition

IEEE Spectrum editor Joshua Romero let me know about the conclusion of a recent cyber competition.

Baker College of Flint, Michigan, defeated last yearâ''s champion Texas A&M University in the 3rd annual National Collegiate Cyber Defense Competition (CCDC) held April 18-20 at the Airport Hilton Hotel in San Antonio. The University of Louisville took third place honors.

According to the CCDC, its program is the first cyber defense competition allowing teams of full-time college students from across the country to apply their information assurance and information technology education in a competitive environment. While similar to other cyber defense competitions, CCDC competitions are unique because they focus on business operations and incorporate the operational aspect of managing and protecting an existing network infrastructure. The teams inherited an "operational" network from a fictional business complete with e-mail, Web sites, data files, and users.

Each team was required to correct problems on their network, perform typical business tasks, and defend their networks from a red team that generates live, hostile activity throughout the competition. The teams were then scored on their performance in those three areas.

The CCDC program has grown from five participating schools in 2005 to 56 schools in 2008 with six regional competitions taking place nationwide. Let's hope more participate next year.

Thank Goodness for Photoshop?

The London Telegraph ran a story recently about how fashion magazines, who used to make fashion models look thinner, are now "fattening up" their skinny models to make them look "fuller-figured." According to the Telegraph, "The move is a response to critics who blame images of so-called 'size zero' models for the rise in eating disorders in young girls."

The story says that Nicky Eaton, the head of press and PR at Condé Nast, which publishes Vogue, GQ, and Glamour,confirmed that images of models were enhanced to make them appear fuller-figured.

Eaton is quoted as saying, "There have been cases where models are booked way ahead of a shoot and then they turn up two months later looking less healthy and perhaps a bit underweight. We wouldn't be happy showing them that way, so it is then that we would need that person to look a little bit fuller."

What's interesting is that Eaton's quote is very similar to that an editor at Allure magazine said in 2006 - that models keep showing up too thin from the time of their booking to the photo shoot. Maybe the magazines need the models' contracts to stipulate a "shoot weight" at the time of the booking, or better yet, just to hire "fuller figured" models in the first place.

Australian and UK Health IT Program Problems


The Australian reported that State of Victoria's health IT HealthSMART program aimed at replacing the information systems and technology running Victoria's hospitals and health clinics will not be completed by June 2009 as promised, which was already two years later than the originally promised completion date of June 2007. Victoria's Auditor-General Des Pearson has found that 57% of the HealthSMART A$323 million budget has been spent, but that only 25% of the project has been completed. He blamed much of the problem on over-ambitious project objectives.

The Auditor-General also noted that it is not known how much more will be needed to complete the project (although at least an additional A$61 would be be needed to subsidize health care providers until the system was up and running), nor what the new estimated completion date would be. Surprisingly (or maybe not), he also said that Victoria's Department of Human Services has not yet informed the government that the system was going to be late.

Australia is not the only one with health IT problems.

Over in the UK, ComputerWeekly has said that there have been problems with the NPfIT new Choose and Book appointment system. According to the UK National Health Service (NHS), "Choose and Book is a national electronic referral service which gives patients a choice of place, date and time for their first outpatient appointment in a hospital or clinic. Patients can choose their hospital or clinic, and then book their appointment to see a specialist with a member of the practice team at the GP surgery, or at home by telephone or over the internet at a time more convenient to them."

Unfortunately, according to ComputerWeekly, a glitch in the Choose and Book software meant that nearly 350 patients received wrong information about appointments for about a week. Some people got incorrect appointments while others didn't get told of their appointments.

A planned upgrade to the Choose and Book software was postponed until the reason for the problem was discovered.

Phishing for CEOs


There was a story this past week in the New York Times that tells of a new phishing attack aimed at corporate senior executives. The phish, according to the Times, appears "to be official subpoenas from the United States District Court in San Diego. Each message includes the executiveâ''s name, company and phone number, and commands the recipient to appear before a grand jury in a civil case."

Phish has been emailed to thousands of executives across the country and contains a link purporting to be a copy of the full subpoena, which if clicked on, installs keystroke recording and remote control software. According to the story, less than 40% of percent of commercial antivirus programs were able to recognize and intercept the attack.

Heathrow Terminal 5 Update: Only a Few Bags Being Lost


British Airways (BA) officials are saying that only a "handful of bags" are being lost now at their new Terminal 5 at London Heathrow airport, although they don't say exactly how many a "handful" really means.

Furthermore, most of the 28,000 or so bags that didn't accompany their owners have found their way home, although some are still missing in action. These include many of the bags trucked from Terminal 5 to Milan for sorting, and are now being trucked back to the UK for more sorting.

In addition, the insurance companies who said they wouldn't cover passenger bags going through Terminal 5 have changed their minds, after pressure from the government and consumer groups.

Finally, there is speculation that BA may need to rebuild part of the baggage system to increase the amount of storage for bags in case of future problems. The baggage system design assumption appears to have been that system problems would only last a few minutes, and that the numbers of bags not being able to be successfully transferred between flights would be significantly reduced because all BA flights would be operating out of the same terminal.

Alas, as events have shown, the assumption was incorrect.

DNA To Predict Your Future Behavior?


There was an interesting and disturbing article in Sunday's Washington Post about the increasing use of DNA to predict a person's future behavior or life possibilities (e.g., longevity) in court. The article said that, "... defense attorneys are asking judges to admit test results suggesting that their clients have a genetic predisposition for violent or impulsive behavior, adding a potential 'DNA defense' to a legal system that until now has held virtually everyone accountable for their actions except the insane or mentally retarded."

The article goes on, "Some gene tests are even being touted for their capacity to help judges predict the likelihood that a convict, if released, will break the law again -- a measure of 'future dangerousness' that raises questions about how far courts can go to abort crimes that have not yet been committed."

In addition, courts are being asked to reduce or increase civil awards because a person's DNA make them genetically disposed to certain diseases. For example, "In once case, a mother sued a doctor and a hospital, claiming that negligence during her labor and delivery caused her daughter permanent brain injuries. A geneticist suspected that the girl had Angelman syndrome, a rare disease caused by a defective chromosome. The trial court ordered a DNA test, but the mother refused, resulting in her not only losing the case but also being held in civil contempt."

While it may take a while, the article suggests that courts may in the future routinely allow a person's DNA to "testify" about them - for good and bad.

That potential trend creates a set of risks that haven't been fully addressed by governments engaged in creating DNA databases of its citizens. The UK has been actively involved in creating DNA databases, and there are some there who are advocating that every person's DNA be recorded in it.

The US government has just changed its policy to collect DNA not only on those convicted of a federal crime, but also arrested for a felony (in the UK anyone arrested can have their DNA collected). Thirteen states already do so now and turn the data over to the government, and many others are considering following suit.

Anyone care to speculate on how long it will be before some government decides to use their DNA database to identify people prone to "future dangerousness?"

And if they do, will they require them to wear some sort of brain-activity box which will indicate when they are contemplating something the government dislikes?

Like bloggers who ask these types of questions?

Georgia Health Insurance Records On Web For Weeks


The New York Times reported that on the 12th of February, WellCare Health Plans Inc inadvertently posted the names, Social Security numbers, birth dates, and dates of eligibility for some 71,000 adults and children enrolled in Medicaid or PeachCare for Kids insurance programs in Georgia. WellCare Health Plans was hired by the State of Georgia to administer health benefits for low-income patients.

The information was on the web for seven weeks. WellCare was notified on 28 March that the information was publicly accessible, but it took another 5 days for the information to be removed.

WellCare Health Plans, which has sent out letters to those patients affected, is offering to pay them for credit monitoring services for a year.

This is the second time that Georgia's Medicaid and PeachCare for Kids participants have had their data compromised. Last year, Affiliated Computer Services lost a computer disk in the mail containing data on 2.9 million recipients.


Risk Factor

IEEE Spectrum's risk analysis blog, featuring daily news, updates and analysis on computing and IT projects, software and systems failures, successes and innovations, security threats, and more.

Robert Charette
Spotsylvania, Va.
Willie D. Jones
New York City
Load More