Home Surveillance: Governments Tell Google's Nest to Hand Over Data 300 Times
forbes.com
forbes.com
I remember the brief period when teaching internet literacy involved teaching people that any text, photo, or video, uploaded to the internet should be considered public, regardless of how the access was limited at the time of upload. Now, people[0] are buying smart devices and uploading all kinds of stuff without even thinking about it.
To a lesser degree, we see the same situation with Event Data Recorders in cars. They record data that can be used against the user in the event of a crash. Are most people aware of this? I doubt it. Having sat on a couple of juries, I've witnessed how ruthless lawyers can be about picking apart an innocuous action to support the case they're making, whether there's malice/negligence/whatever behind it or not.
Maybe we ought to treat creating data as a special case of "Don't talk to the police"[1]
[0] Lay people, the HN crowd is probably making an informed choice. We aren't the majority though.
While it has teeth, it does nothing to physically stop a bad (or unconcerned) actor from don't something you don't want with that data, and once they have it you can't put Pandora back in the box.
Ideologically, this is difficult for some people to accept. If your fortune has been based on stopping people from copying information, it is an inconvenient truth indeed. If you earn your living by preventing copying, the only options are to change everything, or deny everything.
Copy killers, Cory Doctorow
Also, GDPR does not apply to Intelligence Services, their legal limitations are dodgy at best (on purpose).
No PrivaCorp? Make / fund PrivaCorp and migrate after a stable Beta
Normally we don’t care about our online privacy (proof is in the pudding with facebook et. al) so historically there isn’t a big enough market online for megacorp-level privacy-oriented web-product stickiness and growth... But I think a very tangible line is crossed inside the home that consumers can resonate with as networked home devices start to become ubiquitous.
Online is so abstract. But at home? That’s where your wife sleeps. That’s where your baby sleeps. We won’t spend a dime on a password manager but we will spend a good amount on fencing and window curtains and locks and home security systems.
On my home I use a few cameras for our little one plus the cats. I use a VPN on my router, and the cameras cannot connect beyond the router. I can however connect from e.g. a smartphone (with WLAN or 4G) to the VPN and access the cameras. As long as your cameras utilise standards such as RTSP this shouldn't be difficult to set up.
If you save your surveillance data to a disk in your home, it’s subject to the traditional old fashioned warrant process. Once a third party has access, you have given up your rights in many ways.
Cloud for these use cases is dumb for many reasons. You don’t need cloud compute, don’t need cloud storage for the use case. I was able to do what these consumer cloud products do with raspberry pi type hardware a few years ago.
honestly don't know why anyone uploads to the cloud. there's tons of reasons not to, starting from the icloud hacks to [your favorite app]'s RCE bug.
it takes 5 seconds & $30 (pi) to spin up your own server. it's fun to do and at least you know the only possible F-up is between you, your linux server & your comprisable ISP
See their marketing video to police on the portal here:
https://www.dropbox.com/s/x83gyclt497fi8t/Ring%20Neighborhoo...
This is how China operates. The police merely 'request' footage before an owner hands it over right?
Either way this shouldn't be deployed with our law enforcement because it's fundamentally not a secure application. It's not encrypted, there are no controls in place for need to know for access to make these civilian requests and can be hacked by an 11 year old. Police didn't buy this product or ask for it on the market....Ring just gave it to them...from the ukraine.
thats weird.
I've participated in adjacent niche markets where consumers 1) most likely work in tech 2) have needs that 99.9% of people don't care about 3) are willing to pay a premium 4) have the means to pay that premium.
It's too bad that there are so few businesses willing to tap into this market. Part of me believes this is a marketing issue, though. I've yet to see a campaign that really nails our core concerns and does so elegantly.
From your smartphones to your cars to your watches to everything else, it seems like the economy is about getting as much information about you to advertisers/corporations/governments. And data collection looks to be accelerating if anything.
It's like the system is giving us the rope and we are mindlessly putting it around our necks.
The orwellian nightmare was that big brother was going to forcibly install telescreens and listening devices all over your home to deprive you of an ounce of privacy. He never imagined it'd be us installing the telescreens and microphones all over our homes to deprive ourselves of privacy.
Privacy secured.
Also, just because engineers have to jump through hoops to be able to run SELECT on a database, doesn't mean marketroids and sales don't get free rein on using it (or passing it to other parties).
Perhaps: Pay/reward for data sharing, decentralized training, differential privacy, local training and submitting the weights, local fine-tuning of pre-trained model, marketplace of third-party (open source) models, ...
The obsession with cloud-based machine learning is creating half of these problems.
The minute you allow a device you do not 100% control to send data to a service provider, you should not consider that information private. The service provider has no legal obligation to keep the information or data private- I assume somewhere buried in the Terms of Service it says as much.
Are any of you Ring/Dropcam/Nest users thinking of switching?
The furthest you could go is something like an app that reads data on the free icloud / google drive allotment they have. Then you'll have to deal with instances of losing their password / changing their broken devices / etc and all the lock out situations that happen.
You start to say fuck it and provide your own backend and now you're back at status quo.
I understand they mostly do it “because they can”, but that was the same reason that cell carriers locked down phones & controller the installed software pre-iPhone. There is precedent, and thus hope, to break this logjam.
Because they can, and they don't give a fuck whether you like it or not. Compare yesterday's article, "I Pay for News; Why Do I Still See Intrusive Ads?"[0].
There is some merit to argument that "non-techies can't manage their infrastructure", but I question its general validity. For one, an IoT device or a companion box can serve as a local endpoint, things don't have to go into the cloud. For two, a configurable device using open APIs could enable community-level support. I.e. my mother won't be able to set up a server for her smart thermostat data, but I can do that for her, and for her neighbours.
Alas, most IoT equipment is sold as loss leader, meant to lock you into whatever bullshit "platform" the vendor is pushing, and to hold your data hostage. Personally, I avoid IoT because of that - companies are just disrespectful. The design of their products is one big middle finger in the face of the potential customers.
--
I wish there were more IoT style systems that cared about privacy and portability.