If You're Not Paranoid, You're Crazy
theatlantic.com
theatlantic.com
I don't see how the author makes the connection here.
How does searching for an art gallery on Google Maps translate into spam emails? Is he accusing Google of selling your email address and search information to spammers?
The guy is obviously talking out of his ass. Which is a shame because he's trying to make a good point.
I even remember seeing back in the day questions with valid answers on stackoverflow about how to get the email associated with a device without requesting the accounts permission, but some other close ones.
I also made the mistake of using a personal account with my first Android phone. I had zero spam on that account. 2 months later I was getting about 10 emails a day. (not targeted though since I didn't live in an very active area)
Or, more legally, the advertisers could be part of a specific email retargeting campaign where they give us your email addresses, and then we can establish the mapping in a more direct way.
Obviously there must have been more shading goings on in this case, but the principle is the same.
Once you have the email addresses(see unshift's comment above) you upload them to Google and then target the addresses with specific ads.
1: http://blogs.msdn.com/b/oldnewthing/archive/2006/05/08/59235...
This helps solve the issue for advertisers using retargeting where cookies don't have a long shelf life. So they leverage 2nd party data sources to basically set those cookies again for them so they can continue retargeting.
They can also work with vendors to upload their hashed email lists from their CRMs and gain access to the relevant cookies in the pool to market to them.
Onboarding vendors like this tend to pay a CPM rate based on the number of matches they can make with their cookie pool, so really all that matters is that you have a massive number of people authenticating with email addresses.
Alternate theory: someone at AA sold an email list to a shady marketer.
Art galleries are not typically considered sensitive topics.
What probably happened is that Gmail was showing targeted ads based on his searching and he was shocked to see this in his email client, when in fact the two are joined.
It's a very minor point in a big article. I'm not sure it's worth reading too much into.
I can think of a few very expensive ways, but those are also ways in which Google is allowing erosion of their competitive advantage by allowing that information to leak. That, by the way, is why I don't feel particularly paranoid about Google sharing my information everywhere. Google is strongly incentivized to keep it closely guarded so other people can't monetize it in ways that cause Google to lose out.
The tech companies just need to connect one little "key" and they've got the query. The cost of being wrong is low, so there is almost no Type II error. Every consumer website out there has some sort of bloatware / spyware tracking pixel or ad network or analytics pack. They record the headers, the fonts, etc. They make a statistical fingerprint that is very tight.
For the Google Maps example I can think of 10 different ways that the user profile leaked ranging from a single installed key logger (virus), to a toolbar, to his clicking on the website.
"But how could they know it is him or his email?"
There are tons of tricks they use. Just log onto a single social network, bam. There was also a time that you could put down a LinkedIn iFrame to have:
"Zach Aysan" has looked at your profile.
Sent to your inbox.Sure the occasional hacker is smart enough to only install a select number of pluggins, and to watch downloaded programs very carefully, and to install HTTPS Everywhere, and to install an ad blocker, and Privacy Badger, and to reinstall the OS every couple months, etc. But there are tons of people running Windows XP which gets hacked so frequently you need to assume people on those systems have viruses.
My point is this: A discussion on whether Google is the one leaking information begs the question. It doesn't matter if it is Google or another party. The question is this:
"Is there a reasonable chance that a non-technical user will have his searches online leaked to a global network of advertisers and INT personal?"
The answer is a resounding yes. My parents were both programmers 30 years ago, and neither of them can trust the devices that they have to not phone home about them.
The basic pattern is: Get user to trigger re-targeting campaign, use re-targeted ads to read a tracking cookie or browser fingerprint from the user, use that to look up user info in your customer profile database you bought (or bought API access to) from a data broker, send targeted email, package up your new piece of customer profile data (Walter Kirn went to an art gallery in Hollywood) for later resale/trade.
The specifics for each step change all the time.
The author wrote this piece in a style where he defaults to paranoia in the face of all coincidences to mirror the subject matter so it was not an accusation. But this one is actually feasible.
Does Google Maps even embed display ads? I don't think there's any way to get a cookie, pixel, etc etc in there for just a query.
Often it's not even the same group doing all these steps either, there are opportunities to buy your way in and/or cash out partway through.
If you visit non-Google websites, it's technically possible for people to discover relationships and target e-mails (e.g. if you entered your email address on website A and then visited website B, cookies can correlate the visits and, among other things, trigger e-mail; also malware and other privacy leakages), but Google does not use its information in the way alleged.
Disclaimer: I work for Google in privacy engineering, but I'm only speaking for myself based on information Google releases: https://privacy.google.com/#google-information.
I'm not being pedantic, I've seen a lot of arguments recently from actual paranoid conspiracy theorists that feel smug in the wake of Snowden. I'd hate to see people start to confuse real paranoia with informed caution.
This needs a little bit of tweaking on a per-site basis, but works really well at blocking most things.
*/ Hide most everything that isn't the content. /*
:not(.main-content) {
display: none !important;
}
.main-content > * {
display: block !important;
}
Combined with bookmarklets to disable CSS and strip images: http://pastebin.com/etLwqx5AI can read content more or less marketing/fluff free. I then add several styles to make things a bit more legible (font size, a specific font I prefer, body width 85%, line height, and less-contrasting colors).
When I have some spare time on a future weekend I plan to find a way to combine all of them into a single Firefox add-on or a one-click-to-do-everything bookmarklet.
(Readability was built into Safari 5 but is a standalone bookmarklet/add-on as well. Was actually a big inspiration for me fixing things how I want them.)
"Oh, it's reasonable that this app wants access to my text messages, that way when it sends me a confirmation code it can automatically read it."
"Oh, it's reasonable that this app wants access to my mic, maybe it will implement voice chat in a coming update."
"Oh, it's reasonable that this app wants access to my call history and whatnot, that way it can mute itself or pause itself when I get a phone call."
... oh, I guess it's reasonable that if I text, or talk with my phone nearby, about walnuts I'll start seeing targeted ads for walnuts.
It's not about "us" the HN readers. It's about everyone else, and that's what's scary.
Just because I'm a really good driver doesn't mean I won't get into a car crash.
I think it should have been that way from the beginning forcing app developers to handle cases where some permissions aren't granted. It makes for much better visibility when some data is used and to some degree for what.
One massive concern is the 'secret' second operating system that every phone carries on the baseband modem: http://www.extremetech.com/computing/170874-the-secret-secon...
It's getting better, too: Android's new permission model is more granular, like iOS's.
Oh, and one of the most invasive, the "Phone state", which includes unique IDs and called/calling numbers, is required by nearly everyone under the guise of "Needed to pause when phone call comes in". Which is either completely moronic (what, Android couldn't have a "getIsUserInCall" function) or just shows how busted it is.
It's the same on the web, most web sites aren't exactly malicious, they're just (maybe willingly) oblivious about what badness is in their ads.
But yep I garee it's all pretty busted.
While a lot of those examples are true instances of tracking and inference, in some cases I think author is imagining things. People have a scary capability to see patterns and intelligent agents where none exists. It's incredibly easy to cause this.
I'm running a simple IRC bot that "pretends to be human" by means of hand-tailored regular expressions matching input and some witty responses. I can't count the times I tricked people into believing they were talking to human. It's like, write out some simple regexes and you're 90% way to passing a Turing test. People prime and then fool themselves.
So yeah, I'm betting those results in the part I quoted were caused just by "seduction techniques" search. And if he clicked on that Ashley Madison banner, he basically sealed his fate.
"I know I'm paranoid, but am I paranoid enough?"
I was aware of government surveillance before the Snowden leaks. I was always considered a "crazy conspiracy theorist". I didn't have concrete proof, but strong evidence. Looking back, I find it was odd that I was really dismissive of the FBI Spy Planes [0] that I had occasionally heard about. They seemed inefficient and far-fetched and I considered those people to be crazy conspiracy theorists. Woops.
After the Snowden leaks, I stopped being so dismissive of conspiracy theorists. I don't necessarily take them very seriously or believe them - but I don't treat them like they are claiming leprechauns exist. Unless there's a more reasonable or scientific explanation available, such as with "chemtrails". I'm still readily dismissive of that theory... just normal contrails.
[0] http://www.huffingtonpost.com/2015/06/02/fbi-surveillance-fl...
"If you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him."
EDIT: seriously. This quote most definitely doesn't mean people should stop writing out of fear of execution.
I'm not sure about this, but I haven't heard that many serious arguments against to offset the potential benefits. I think we either have to go all-in or all-out; hesitation and aiming for middle ground will give too much power to wrong actors while leaving the society powerless.
#Majority of people post photo of friends on Facebook without understand facial recognition always scans.
#Prefer convenient over privacy, such as Toll Tag on cars.
#Follow trends.
Without better end-node security, individuals and the entire internet are always at risk. (I'm primarily looking at you Windows...). In other words, IMO big government and corporate overreach are minor problems compared to the active-assault going on to dominate the non-technical end-user computers.
If someone keeps their Twitter handle disambiguated from their personal life, is there a reason why they can't #followallthehashtags?
most traffic condition on map rely on Toll Tag to measure travel time and speed between points, on normal highway.
Unless you have a detachable tag, otherwise your tag ID will appear on every single major interception, with time, speed between blocks. Most of Tag will ship to your house, and/or auto fill by credit card once the balance is low.
People probably imagine they will be erased after few years, but $sudo happeneds.
http://www.dailykos.com/story/2015/08/17/1412811/-AT-T-and-N...
In principle there's no reason the same thing couldn't happen with license plate readers in all but the most dense of traffic. The tags likely make it easier, but with plate-reader technology it should still be possible to do just using license plates.
There are a few cases in the news; here's the first one that popped up on my search engine: https://en.wikipedia.org/wiki/Melanie_McGuire
I don't really know what the linked story has to do with toll RFID tags or automobile tracking; I was expecting some kind of source that supported your claim.
These are the kinds of discussions we need to have more often: not only what's going on and what it means in practical terms, but also how today's surveillance explosion changes who we are and how we relate to ourselves.
One of the interesting themes is that everyone is surveilled totally and intimately down to even their feelings, but it's not the point of the book and the protagonist treats it as totally normal and it's never really discussed nor is there any suggestion it would be better if that wasn't the case.
I really enjoyed the trilogy but as someone who's pro-privacy it was a strange read.
Which is? Are you denying manipulation being an objective?
> unless you'd like to dismantle all television networks, newspapers, magazines, Google, Facebook, and put a huge dent in the earnings of every company that gets a return on its advertising investment
I said "advertisement in the way it's employed most of the time". Admittedly this is vague, and I've have to think more about it to be precise, but I didn't say "advertisting, period" on purpose, because I do acknowledge the general idea to get honest information out to potential customers. But let's not use that as a fig leaf.
Television, newspapers and magazines get destroyed and become destructive anyway to the degree they are beholden to advertisers. It might reduce the variety of products peddling the same things worded slightly differently, but since there IS a demand for information and entertainment, the remaining ones providing value might be able to live from, you know, getting paid for the work they do by the people they do it for. Are you for example saying there have been no newspapers in the US before 1840? ( http://library.duke.edu/digitalcollections/eaa/timeline/ )
And Google and Facebook are so new, my response is "maybe, so what?" You're talking about a business model, not technology. Besides, I think the web really needs to ponder some form of micropayments or subscriptions again, either way. Advertisement allows the situation that there are readers for something, but no advertisers. So in a way it's a middleman, that often enough is as manipulative as it can get away with. It's not a sustainable situation IMHO.
> put a huge dent in the earnings of every company that gets a return on its advertising investment
Again, so? If there is a "huge dent" across the board, it ends up as no dent at all. And maybe it wouldn't be across the board, maybe it would be a huge dent for those who live on manipulation of emotions, people identifying with brands and so on, and a huge boon for those who make the better products...? Who knows?
The issue is that there's no way to have a huge dent across the board because we now live in a global economy. Advertising-based businesses would have to be dismantled globally. Frankly, I think this is unrealistic and not really worth speculating about.
If democracy is being subverted through this kind of surveillance then society is in danger. If society is in danger, then you are in danger by extension.
It's not that I feel warm to communism, but that I want the liberty to adhere to an unorthodox idea should I encounter a sufficiently compelling on. If there are socioeconomic penalties for the development (not necessarily the expression of or action upon) such unorthodox beliefs, then we're in an era or soft Orwellian thoughtfcrime.
If it changes the population, it directly affects me.
I'm not sure what you're not getting.
What I suspect is that it affects the population via emotional response, which in turn affects you, so you have a kind of second-order response.
Have you ever picked your nose when others are watching? Or is there something innately offputting about doing so? Have you ever tried to "sneak" it when you thought nobody was watching?
What if you always thought someone was watching?
If you won't do something as harmless as picking your nose while being watched - what other human behaviors do you think are affected when people think they are being watched? Maybe they don't want others to know they attend a dance class. Maybe they're embarrassed to buy condoms or other contraceptives. Maybe they don't want others to see them buying medicine they need for an embarrassing medical condition.
It's not about personal threat it's about privacy.
– William S. Burroughs
But you gave HN a lot of information other than the hacking facts - specifically, your exact adderal dosage, and also feeling ill physically.
I initialled replied by asking about who would have a motive to send you that email - but after I saw the linked Reddit article about the CO2 poisoning guy, I decided that it's probably more important for you to lower your adderall usage and make sure you're not physically ill. I mean what are the downsides to not taking so much adderal? None. People specifically pointed out the effects that you describe matching the adderall dosage, and also I think what you said about your family being concerned is a BIG clue. After all, I doubt the author's family (of the Atlantic article in this thread) is concerned about him for writing it (as a point of comparison). So what I mean is that just because you believe you're being hacked doesn't mean you would tell your whole family - their conern doesn't come from the facts, it comes from your behavior. So that to me also said that it is likely that you should get the primary things that might be causing this into check.
All that said, I found the facts you reported to be completely plausible. But, like, so what? The matrix of reward/loss for you looks like this:
There are two questions: are you temporarily ill, and are you being hacked. You now have two choices: explore your possible illness or ignore it. Here is the reward table:
Expl = explore possibility of illness
Being hacked?
No Yes
Ill? No [ Expl.: -30 Ignore: 0 ] [Expl: -30 Ignore: 0]
Yes [ Expl.: -30 Ignore: -10000 ] [Expl: -30 Ignore: -10000]
If the above boxes are taken in this order:
1 2
3 41: You're not being hacked and not ill. Simply mistaken. In this case, exploring illness will take you time and trouble, denoted by -30. If you ignore the possibility of illness (and the possibility of being hacked) you suffer no consequences.
2: In this case you ARE being hacked, and not ill. You're correct about feeling like you're being hacked. In this case, exploring illness possibility takes you the same -30. But if you ignore the possibility of illness, you suffer no negative consequences, EVEN THOUGH you're actively being hacked.
3: This is what happened to C02 guy. He has permanent brain damage now. He was NOT "being hacked" but was very seriously ill. In your story, this is a possibility since you reported physical illness, since your family was worried (even though if you wre genuinely being hacked you would have no reason to share with them, since it would be obvoius to you that it would sound paranoid), and you were taking huge adderal dosage. In addition, you could have some genuine issue like CO2 poisoning - for example is there a fireplace in the place you moved to? Is it ventilated. This is just one possibility, there are many other illnesses you could have contracted in the recent past, or external causes of your feeling.
4: The situation is EXACTLY THE SAME if you actually are under surveillance. if you ignore and don't treat your illness, you are under the exact same risks, even if at the same time your surveillance or being hacked is real. You gain nothing from not exploring the possibility of illness.
Why do I put -10,000 into the illness box?
Because this is what Co2 guy reports (after reddit successfully diagnosed him and his Co2 meter was off the charts): "Likely permanent damage. I can't work. I get confused watching movies. I can't remember anything. I confuse my reflection for a different person." [1] If he hadn't told reddit, today he would very likely be dead.
What happenes if you're being hacked? Nothing. So given the barest glance at the matrix above, it should seem completely obvious that you MUST explore health-related possibilities while completely ignoring the possibility that you're being hacked. You get no benefit from deciding this now, rather than after you're feeling normal.
I very strongly advise you to follow up as everyone suggested!
[1] https://www.reddit.com/r/legaladvice/comments/3iycro/fl_i_am...