Thursday, June 07, 2007

Is MySpace A Piece In The Kelsey Smith Murder Puzzle?

Did Edwin R. Hall actually know Kelsey Smith? Or, did he find her through MySpace? Or, was she a random victim? It seems that Edwin has a MySpace account (corrected link)-- stating he lives in Overland Park (although his address at the time of arrest was officially Olathe, KS.). His profile has been deleted, so we can't learn anything else from it. Other bloggers have said that Hall's wife, Aletha, was linked to his MySpace page. There is also information saying the Halls have a four year old son. I sure hope the link to the MySpace page is bogus.

Kelsey Smith also had a MySpace page -- stating she lived in Overland Park. Could Edwin have been stalking Kelsey via MySpace? It is a possibility. One thing that is kinda creepy is that Hall's MySpace account shows he logged in sometime yesterday -- shortly before he was arrested for aggravated kidnapping and first-degree murder. FWIW, Kelsey did not have Edwin Hall listed as a "friend" on MySpace. I'm not trying to make a connection where one is not present, BUT the question of MySpace is one the needs to be answered.

I'm sure we'll learn more in the coming hours and days, but questions are large and beg to be answered. The biggest question looming in my mind is WHY? Why abduct and murder a vibrant young lady who just graduated high school and was about to set off for college and adult life? Why?!? Weren't your video games enough? Weren't movies like Hostel and Saw and Hannibal enough? Didn't the Internet satisfy your bloodlust?

Now, some defense attorney will set out to go far beyond the mandate of lawyers to make sure their clients get a fair trial. That attorney will try to wiggle and squirm and circumvent his way around the facts in an attempt to get Mr. Hall acquitted. ARGH! It makes me furious just to think about the whole ordeal -- especially for Greg and Missy Smith.

See the video of Edwin Hall's arraignment here, courtesy of scaredmonkeys.com.

My prayers go out to them, along with Stevie, Cody, Zack and Kelsey's boyfriend John Biersmith. They will all live the tragedy of Kelsey kidnapping and murder many times over.

Police Find Missing Kansas Teen's Body, Suspect Arrested

Sources: KCTV, MSN & SalemNews.com
Picture of Ed Hall from his MySpace page (corrected link)
A suspect was arrested [as I predicted] Wednesday evening in the slaying of a teenage Kansas girl believed abducted from the parking lot of an Overland Park Target store. Edwin R. Hall, 26, of Olathe, Kansas, is expected to be charged this morning with premeditated first-degree murder and aggravated kidnapping, Overland Park Police Chief John Douglass said. Johnson County prosecutor Phill Kline said his office would file formal charges early Thursday or, at the latest, Friday morning. "Tomorrow morning [Thursday] the Johnson County district attorney's office will file premeditated first-degree murder and aggravated kidnapping* charges against Edwin Hall, 26 years of age, with the disappearance and death of Kelsey Smith," Kline said Wednesday. "This community has lost a vibrant and promising life and a family has suffered unimaginable tragedy." Kline said it was premeditated murder and is requesting a $5 million bond for Hall.

Kelsey Smith, 18, had been missing since Saturday night, when she went to a Target store to buy a gift for her boyfriend. Surveillance video showed her being forced into her car, and the car drove off. It was found in a nearby mall parking lot about two hours later. Douglass said Hall matched the description of a man seen on surveillance video walking into the store soon after Smith entered. Police also found a vehicle that matched the description of a dark mid-1970s Chevrolet pickup that was seen entering the Target parking lot shortly after Smith's car, he said. The truck was in Edwin Hall's possession.

A man who lives near the area where Smith's body was found told KMBC that he saw a vehicle in the park at about 9 p.m. Saturday, which matches the police time line. The man, who didn't want his name used, said he doesn't know what type of vehicle it was, but he remembers seeing headlights behind a locked gate on the road.

Douglass said Hall was interviewed mid-afternoon Wednesday after police acted on a tip that matched Hall and a vehicle to surveillance video from the Target store parking lot in suburban Kansas City where Smith was abducted Saturday evening. He said he had no information why Smith was targeted, or if Hall was believed to have acted alone. Police said Hall's vehicle matched the description of a dark mid-1970s Chevrolet pickup that was seen entering the Target parking lot shortly after Smith's car. Police found Smith's body in a wooded area near Grandview, Mo., about 20 miles east of the Target store. Authorities did not say how she died.

According to Chief Douglass, "Mr. Hall faces 25 years to life minimum sentence on the premeditated murder charge, 147 months minimum sentence on the aggravated kidnapping charge. There is a distinct possibility of an amendment for more severe charges in the future."

* = Aggravated kidnapping charge is defined as kidnapping with "great bodily harm". As I commented on yesterday, Kelsey was likely rendered unconscious or even dead at the time of her was kidnapping (in the Target parking lot or car as they left the store) -- not later on. If that is the case, it would account for the surprise that Kelsey did not fight back (as her father and sister said she would have done).
The aggravated kidnapping charge likely came from the visible effects of damage to Kelsey's body -- which may have accounted for the delay in identifying her body when she found yesterday around 1:30pm.

Wednesday, June 06, 2007

Search For A Killer!?!

Steph Watts, of On the Record from FNC, has confirmed that the police DO have a suspect in the Kelsey Smith murder case. They are looking for him now. Watts also reports that no information on a motive or cause of death.

BTW, one reason the FBI is active in the investigation is that Kelsey was transported from Kansas into Missouri. Unfortunately, the federal presence didn't make any difference in the outcome of Kelsey's abduction.

SPECULATION: When the guy attacked Kelsey in the Target parking lot, she may have been rendered unconscious. Therefore, her attacker had to leave her in the car and vacate the area. If he killed her when he forced her into the car, he may have panicked and took her straight to the Longview Lake Park to discard the body.
Kelsey's body was dumped under a bridge, in a shallow creek. Her murderer may have intended to go back and bury Kelsey's body... but the police found her before he could act on the remainder of his plan. We don't yet know the condition of Kelsey's body, but I suspect she may have been damaged in the head or face area. The water of the creek or attacker may have caused the damage -- I'm not sure.

Who Killed Kelsey Smith?

Photo from FOX25 in Kansas City
As the story of young Kelsey Smith's abduction and murder unfolds, Overland Park Police Chief John Douglass has told the public that a "person of interest" is now a suspect. This person, who remains unnamed, reportedly lives approx. two miles from where Kelsey Smith's body was found. He also has what police call "an extensive criminal record". So, who is this person / suspect?

Sources in Kansas City tells me that someone with the surname of Beach or Beech is being sought by law enforcement. I have heard the first names of Timothy, Jeremiah and/or John. I must emphasize that the name is speculation, but does come from the local area -- and local area information is normally better than what we are told on the evening news. I learned that in the cases of Immette St. Guillen's murder and the Virginia Tech slayings.

These things seem fairly apparent:
1) The guy seen in the Target store video entered the store shortly after Kelsey entered.
2) The same guy was seen on surveillance cameras within Target. He was near Kelsey on at least three occasions.
3) This same person is thought to be the driver of the 1970s Chevrolet pickup that police are seeking.
4) The Target store guy is seen leaving within seconds of Kelsey exiting the store.
5) The person who ran up to Kelsey in the parking - and apparently pushed her into her car - looks to be the same person (a 20-ish year old white male with a goatie; wearing dark shorts, white t-shirt, low-top Converse sneakers).
6) From video not publicly shown, but referenced by police, the pickup truck was left in the parking lot of Target until around 9:00pm Saturday night.
7) Kelsey's car was seen leaving the parking lot around 7:08pm. It was found across the street in the Macy's parking lot (at Overland Mall) around 9:00pm that night.
8) Police believe the kidnapping and murder was a one-man operation -- which fits with the car being used to drive away; the truck being left at Target; and Kelsey's Buick showing up about the same time as the truck leaves the Target lot.
9) Police have narrowed down their suspect list (although not official publicly) down to either a few select persons of interest or this one suspect.
10) Since no details of the state of Kelsey's body were offered, and no immediate identification was made, AND police told the clergy before they told the family, law enforcement officials have at least inferred that Kelsey's body was somehow damaged in a way that made it at least a bit difficult to ID her. [Pure conjecture on my part, but I've done a lot of research on cases like this.]
11) Kelsey was not likely killed in her car.
12) She was not likely in the pickup truck at any time. Nonetheless, the truck could be a key piece for evidence collection.
13) Kelsey was likely murdered within the first 60-90 minutes after her abduction.
14) Kelsey's boyfriend (John Biersmith) is not now, nor has he been a suspect (as some folks have suggested). He was actually at the Smith home awaiting Kelsey's arrival when she was abducted from the Target store parking lot.
15) IF, and I repeat, IF the guy in the surveillance video is her killer, he is not a very bright individual. Along with the dumb moves he made to stalk, follow and kidnap her, he will likely brag to some friends about his "adventure". If he hasn't committed suicide somewhere in the woods, he will be caught rather quickly -- I can almost guarantee it.
16) Lastly, law enforcement officials are NOT telling us everything they know. That fact is more than obvious. I respect them for keeping certain aspects of the case private -- out of respect for the Smith family and/or for the future court case.

Our prayers go out to Greg, Missy, Stevie, Lindsay, Cody and Zack Smith -- along with John Biersmith (Kelsey's boyfriend) and his family.

BTW, I just googled the name "kelsey smith" and beach or timothy and beech. My blog is the ONLY one reporting this information. That makes me a bit nervous as I don't want anyone to decide someone they know in the Kansas City area is guilty of the heinous crimes against Kelsey. Offering a potential name is merely a way to try and learn more about who the suspect really is -- and hopefully assist with his capture and prosecution.

More Details on Kelsey Smith's Abduction & Murder

INITIAL POST: 5:06pm
LAST UPDATE: 5:42pm

As pastors meet with the Greg Smith family in Overland Park (near Kansas City), we now know the body of their daughter, Kelsey Smith, was found south of Longview Lake Park. The police spokesman, Chief John Douglass, is taking questions at a press conference, as I type.

The suspect has not been arrested. The chief says they are talking to "several people at this point". The police say they do not have the name of the person in the Target store video, but all of the POIs look like the person seen leaving the store just behind Kelsey Smith. Other news sources say the person law enforcement believes is THE suspect is a 20-ish white male who lives within two miles of the spot where Kelsey's body was found. Furthermore, these sources are saying that the suspect has an extensive criminal record. At this time, they have not said the suspect is the owner or driver of the pickup truck shown several times on news broadcasts.

Eleven teams fanned out across the Longview Lake Park area early this morning. One of those teams found Kelsey's body in a shallow creek, near Highgrove and Raytown roads around 2:00pm CT. They were "lead" to the specific area by Kelsey's cell phone "pinging" a local cell tower. Police took her cell account's LUDs and analyzed them. The results came back Tuesday morning -- and police immediately started their search.
The cell phone analysis showed that the phone passed through certain telephone cells located on I-35 to I-435, then east to south 71 highway, and from there to an area in the vicinity of Longview Lake Park.
Photos from WPBF FOX25 and FOX4

Kelsey Smith's Body has Been Found

INITIAL POST: 3:15pm EDT
LAST UPDATE: 4:57pm
(Updating every few minutes, so refresh the page often...)

Kelsey Smith's body has been found.
It's 3:12pm and the body was found south of Longview Lake, in SE Grandview, MO. The body was found in a shallow creek. A tarp covers the area as I type...

Kelsey Smith was apparently kidnapped from the Target store parking lot in Overland Park (suburb of Kansas City) at 7:07pm Saturday night. A 20-ish looking white male is seen running up behind Kelsey and forcing her into her 1987 Buick Regal. The car is seen backing out of the parking space and leaving the lot.
A little over two hours later, Kelsey's car was found in the Macy's parking -- across the street at the Overland Mall. Police have been searching for the 18 year old high school graduate since that time.

Just a few minutes ago, the story broke on FOX4 in KC --
"Police have located the body of a young girl, police and the independent search company on the scene told a FOX News Channel producer for 'On the Record' with Greta that it was the body of Kelsey."

A half-mile radius was being deeply searched after Kelsey's cell phone pinged a local tower in the southeast Jackson County area. Tire tracks were found -- leaving the road and going into the woods. A search team went into the area -- and found Kelsey Smith's body within a few minutes by the Equi-Search team.

Update: 4:07pm -- The search has been called off. The medical examiner has arrived on the scene. Although not officially confirmed, these are definitive inferences that the body is Kelsey Smith. The local enforcement will have a live press conference at 5:00pm EDT.

Also, the person of interest whom police were trying to locate, lives near the area, according to Steph Watts, a FOXNews On The Record producer.

FWIW, and it may be worth NOTHING -- I am hearing the names Timothy Beach (or Beech) or... Jerimiah John Beach (or Beech) as a potential suspect. Someone also says that the suspected perp (the "person of interest") lives within two miles of where Kelsey's body was found. Police are trying to track him down -- with even more interest now. A rather slumy apartment complex is located near 71 highway and 155th St. -- not far from Longview Lake Park. I've heard someone with the last name of Beach / Beech lives near there... and MAY be a suspect.

As for the truck, I am hearing "live" that a mid-1970s Chevy pickup truck has been found -- and police think it is the one seen in the Target parking lot Saturday just before Kelsey was abducted.

Photos from FOX4 and Kelsey's MySpace page

A press conference is scheduled for 3 minutes from now. I'll post more during and after the press conference.

Monday, June 04, 2007

Online Tunes Are More Risky Than Web Porn - When It Comes to Malware

About 9% of adult sites produce spyware, adware or spam, compared with 19% of digital music sites found in a study by McAfee.

By Joseph Menn / Times Staff Writer
Whatever threat online pornography might pose to society's morals, online music might pose a bigger threat to society's computers. A study scheduled to be released today found that about 9% of adult sites that turned up high in search-engine rankings had such PC-damaging problems or annoyances as spyware, adware and spam associated with them. Yet searching for digital music was twice as risky — more than 19% of the sites produced by such queries were risky for computer users, according to the study by McAfee Inc., a Santa Clara, California-based company that makes computer-security software.

Other risky searches included those for electronic gadgets and for background "wallpaper" to decorate computer screens. Researchers have one idea why looking for porn appears to be safer: The business side of that industry works even without the extra hustling. Since it's harder to make a living selling digital music, those hawking such items are far more likely to attach programs that spew unwanted ads or worse. "The tier-one adult sites are doing phenomenally well as businesses, and because of that they very much have their house in order," said McAfee Senior Product Manager Mark Maxwell.

The digital music searches studied include those for such file-sharing programs as BearShare, which often include intrusive advertising programs. BearShare took the honors as the single riskiest search term, returning unsafe sites at a 46% rate. Other findings from McAfee's database were not included in the study, including the news that Britney Spears is slightly more dangerous to search for than Lindsay Lohan. The former couple of Brad Pitt and Jennifer Aniston, meanwhile, are a 36% more hazardous combination than the current pair of Pitt and Angelina Jolie.

The study is the third of its kind from McAfee, which owns a popular free service called SiteAdvisor. It rates millions of websites as red for risky, yellow for somewhat risky and green for safe, warning Web surfers before they click through. The latest paper also found that sponsored search results, which are paid for by advertisers, are twice as likely to be risky as regular search results. It also compared the five most popular search engines, finding that Yahoo Inc. had the safest unpaid results and the riskiest paid results.

For thousands of popular searches, the top 500 unpaid listings were about as safe at one search engine as they were at another. Yahoo came out best with 2.7% that were red or yellow, and IAC/InterActiveCorp's Ask.com was the worst at 3.3%. The range was larger when it came to advertised results: from a low of 4.1% problematic results at Ask to 9% at Yahoo. Google Inc. has toughened its checks on advertisers and made its paid results safer in the last year, McAfee said, while Yahoo has gotten worse.

Yahoo declined an interview request. In a statement Saturday, Vice President of Marketplace Quality Reggie Davis wrote that the unpaid search results "represent the vast majority of clicked links." "We will continue to improve our performance in this area by investing in technology," Davis said. An Ask.com spokeswoman pointed to the company's sharp improvement in paid results, which boosted its overall safety performance from worst to the middle of the pack.

Many of the advertised sites that McAfee flagged are obvious scams pointed out by SiteAdvisor users, including those that make impossible claims about obtaining green cards for immigrants and repairing damaged credit. "We are struck by search engines' failure to block even the most notorious and widespread of scam ads — a decision we suspect arises out of search engines' business objectives," the study's authors wrote.

In better news, the number of the very worst sites — those that use known vulnerabilities in software to automatically install keystroke loggers and other malicious programs — remained quite small. McAfee turned up less than one in a thousand among the top search engine results. Google has begun to warn users before they go to one of those sites, and a spokeswoman said that the effort would remain the priority over fighting such lesser threats as adware and spam. "Google concentrates on Web pages that pose real danger to our users, and we are confident that we are protecting searchers from these threats," company spokeswoman Katie Watson said.

Friday, June 01, 2007

Popular add-ons to Firefox are the latest criminal attack vector

Article posted by Robert Vamosi on News.com.com
Mozilla enjoys a large development community to build add-ons for its Firefox browser. Now it seems all that development might not be a good thing. A security researcher in Indiana has found that the process used to update some of these add-ons automatically appears to be flawed, allowing criminal hackers to intercept the browser's call to the developer to see if there's a new version available. Worse, the most vulnerable add-ons aren't from vendors you've never heard of; they include brand-name sites like Google, Yahoo, Facebook, and LinkedIn.

Extensions for Firefox contain hard coded Internet addresses for updates. Mozilla provides free hosting for update at addons.mozilla.org, however, many developers choose for various reasons to serve the updates themselves from servers under their control. The servers at Mozilla all use the secure https:// protocol, but since encryption requires more resources, many developers opt to use the less secure, less resource intensive http:// instead. That's where the problem lies.
Researcher Christopher Soghoian's blog describes a scenario where a wireless user in an Internet café starts up the Firefox browser. Home users who have not changed the default password on their wireless routers are also affected. Firefox routinely checks with the extension's update servers to see if there are any updates pending and generally notifies the user. Add-ons using the secure https:// protocol are not affected; a criminal could not intercept that encrypted transmission. However, add-ons using the less secure http:// protocol are open to what's called a man-in-the-middle attack where a criminal hacker can intercept the transmission and substitute a maliciously coded update instead.
While Firefox prompts the user to install any updates, not all updates trigger the prompt. For example, Google Toolbar updates will install automatically. Soghoian says "The problem stems from design flaws, false assumptions, and a lack of solid developer documentation instructing extension authors on the best way to secure their code." He urges Firefox users to uninstall extensions not downloaded from Mozilla.
Among these, Google Toolbar, Google Browser Sync, Yahoo Toolbar, Del.icio.us Extension, Facebook Toolbar, AOL Toolbar, Ask.com Toolbar, LinkedIn Browser Toolbar, Netcraft Anti-Phishing Toolbar, and PhishTank SiteChecker.
Add-ons not vulnerable to this type of attack include NoScript, Greasemonkey, and AdBlock Plus.
Secure add-ons can be downloaded from the official Firefox Add-ons website. Soghoian says he contacted Google and other developers and told Mozilla and specific about this vulnerability on April 16, 2007. Many vendors ignored him. Mozilla did work with some vendors, such as eBay, to fix the problem and has updated its developer site to include safe coding practices to guard against this attack. Abiding by the CERT vulnerability disclosure policy, Shogoian went public 45 days after notifying CERT and the vendors affected. Soghoian is no stranger to controversy. In October, Soghoian printed his own airline tickets much to the dismay of the FAA and Department of Homeland Security. No charges were ever filed.

Wednesday, May 30, 2007

Apple Hides Account Info in DRM-free Music, Too!

FOLLOW-UP TO EARLIER STORY...

With great power comes great responsibility, and apparently with DRM-free music comes files embedded with identifying information. Such is the situation with Apple's new DRM-free music: songs sold without DRM still have a user's full name and account e-mail embedded in them, which means that dropping that new DRM-free song on your favorite P2P network could come back to bite you.

Ken Fisher and others at arstechnica.com started examining the files this morning and noticed their names and e-mail addresses in the files, and they found corroboration of the find at TUAW, as well. But there's more to the story: Apple embeds your account information in all songs sold on the store, not just DRM-free songs. Previously it wasn't much of a big deal, since no one could imagine users sharing encrypted, DRMed content. But now that DRM-free music from Apple is on the loose, the hidden data is more significant since it could theoretically be used to trace shared tunes back to the original owner.

Read more...

Apple Debuts Unprotected Songs Online

Excerpts from chron.com
Apple Inc.'s iTunes Store started selling thousands of songs without copy protection Wednesday, marking the trendsetting company's latest coup and a model for what analysts say will likely become a pattern for online music sales.
Launching initially with songs from music company EMI Group PLC, iTunes Plus features tracks that are free of digital rights management, or DRM, technology _ copy-protection software that limits where songs or movies can be played and distributed. The unrestricted content means some songs purchased from iTunes will work for the first time directly on portable players other than Apple's iPod, including Microsoft Corp.'s Zune.
The inaugural batch of iTunes Plus songs includes music from Coldplay, The Rolling Stones, Norah Jones, Frank Sinatra, Pink Floyd and more than a dozen of Paul McCartney's classic albums. The DRM-free tracks feature a higher sound quality and cost $1.29 apiece _ 30 cents more than the usual 99-cent price of other, copy-protected songs at the market-leading online music store. If available, users could upgrade existing purchases to DRM-free versions for 30 cents a song or $3 for most albums, Apple said.
London-based EMI, the world's third-largest music company by sales, and Cupertino-based Apple announced their partnership in April to deliver the industry's first major offering of DRM-free songs, sharing a vision of what both companies say their consumers want: flexibility and CD-audio quality. Earlier this year, Apple CEO Steve Jobs called on the world's four major record companies to start selling songs online without copy-protection software. "We definitely think it's the right thing to do," Eddy Cue, Apple's vice president of iTunes, said Wednesday. "In this case, EMI's a leader and we think others will follow."

In a statement Wednesday, Jobs reiterated Apple expects that more than half of the 5 million songs on iTunes will feature a DRM-free version by the end of the year. In the meantime, Apple's iTunes Store will continue to offer songs in the same copy-protected format as today at 99-cents-per-download and encoded at 128 kilobits per second. The iTunes Plus versions are encoded at 256 kbps, which Apple says makes the audio quality on par with original recordings. Apple also will continue to encode its songs _ including EMI's DRM-free content _ in the AAC audio format, which could force some users to go through an extra step of converting tunes into a version that would be compatible with their players.

Amazon.com, by comparison, said it plans to sell songs online later this year in the DRM-free MP3 format _ the popular unrestricted audio standard that is supported by virtually any device, including Apple's best-selling iPod.