In completely unrelated news, OVH, Europe's biggest hosting provider, has announced a new partnership : OVH is going to use Google's closed(?) source software, Anthos, for its "Hosted Private Cloud" offering.
In completely unrelated news, OVH, Europe's biggest hosting provider, has announced a new partnership : OVH is going to use Google's closed(?) source software, Anthos, for its "Hosted Private Cloud" offering.
Cory Doctorow:
https://old.reddit.com/r/privacy/comments/j444u4/how_to_dest...
- You're emitting side-channel metadata all the time, most especially location and activity data (especially if you have any mobile devices) which is 1) useful 2) identifying and 3) very expensive to spoof.
- Purchase and other commercial / financial activity likewise. These are literally expensive, and hence credible signals.
- Unless you're spamming your contacts regularly, your social networks and interactions are also highly reliable and difficult to spoof.
- Dang would not be pleased by a sudden influx of GPT-3 posters on HN. Similar reactions likely for other online services.
- So long as your legitimate / semantically significant activity is present with minimal obfuscation, that signal exists and is easy to tease out.
- If your activities are interactive and responsive, rather than scheduled, poisoning is less viable and more visible.
Data fuzzing / poisoning works fairly well (though not even always then) for systems such ss numbers stations: broadcast-mode distribution, regularly-timed transmissions, consistently encrypted (no cleartext), no location or movement signals from recipients, and no transactional activities --- whether financial mor social.
For all else, not so much.
I could see some value to, say, search-engine spamming (with spurious searches), or ads networks (fake clicks). For the rest, it's just plain hard.
Think threat models; what are you hoping to accomplish/protect, from whom, at what cost(s)?
I guess it's going to pretty expensive and impossible technically to protect oneself from a State player, and also very expensive and near-impossible to protect against a big "infrastructure" provider (Google, Apple, Big telecom, etc.). However, it should be doable if we could protect us from malevenent apps or non-state crackers.
Pretty much. Ultimately this is a problem of law, markets, and norms rather than code (to draw on Lessig's four laws) or individual choice.
Code itself may help with the backing of other factors, the more so if technical protections are legally required. A huge problem is in establishing both the harms and relationships.
It struck me a few weeks ago that the major ills of information technology most often discussed --- censorship, propaganda, surveillance, and manipulation --- have one common root: monopoly.
https://joindiaspora.com/posts/7bfcf170eefc013863fa002590d8e...
Discussed on HN: https://news.ycombinator.com/item?id=24771470
(Not entirely original, though I'm unaware of anyone who's put all four together. Tim Wu nailed surveillance in 2013 https://www.newyorker.com/tech/annals-of-technology/why-mono...)
And I'm not willingly accepting the fact, though attempting to avoid tracking and surveillence is hard and carries real costs. As with security generally, you can simply raise the costs of tracking, which is effective against most casual or commercially-motivated actors, though not a determined political or personal antagonist.
Ultimately making exploitation sufficiently expensive or painful may be necessary. Friends, and lots of them, with capacity to act.
> Not entirely original, though I'm unaware of anyone who's put all four together.
Looks like Cory Doctorow beat you by a mere couple of months :
https://onezero.medium.com/how-to-destroy-surveillance-capit...
(Well, as I remember it, I don't really have time to re-read this whole book now. And it's great to have a synthetic post about the same issue !)
I'm very surprised that nobody seems to have linked that in those discussions, especially you !
https://toot.cat/@dredmorbius/105023745888827646
Doctorow also mentions the monopoly-surveillance link. We're both beat by Wu by years, and arguably Zuboff by decades, on that one element. Though Doctorow does spend a lot of time talking abbout AdTech (mostly dismissing its significance, incorrectly IMO), and while he's certainly discussed both censsorsship and propaganda in his work generally, he doesn't quite bring the monopoly aspect and combined interreationship into focus.
Some cursory searching through the literature also seems to find this connection missing, though I'd be happy to be shown wrong.
(The Wu piece was found after my initial postings, and is absolutely a piece of this.)
It doesn't suggest anything without evidence.
If we're lucky, we'll only get actual evidence after many decades, like with Crypto AG.
(But of course we already have some evidence, for instance about ECHELON and PRISM (Skype...))
If we're unlucky, black hats (criminals and/or anti-West countries) are going to lay their hands on those backdoors first, like with the NSA/Shadow Brokers leak :
We have substantial evidence from this very article:
* There exist agencies that are trying to compromise your communications.
* They have no scruples.
* They are actively causing people to lie about what products do.
* They are willing to act through corporations.
Waiting until there is overwhelming evidence of a specific act of wrongdoing is a strategy so ineffective it may as well just be saying "I don't care about securing my communications". Not to say that no strategy is unreasonable, maybe people don't care.
Assuming everyone is telling the truth about being honest and ruling them out one by one when there is a large report or a Snowden-style leak is all but guaranteed to have the same result as ignoring the problem. Evidence is coming to light years after the event, and the spies in this article used Switzerland as part of a strategy of targeting the most trusted places for corruption.
Now consider the fact how one of the top search results for "Intel me NSA" is this article [2] telling people how they can totally disable that nasty ME thanks to the apparently very well meaning NSA.
I don't claim to be nearly well versed enough to understand if that NSA advise is actually useful, but I'm sure as hell skeptical enough when a burglar wants to tell me how to best secure my home from break-ins.
[0] https://www.tomshardware.com/news/cisco-backdoor-hardcoded-a...
[1] https://www.schneier.com/blog/archives/2005/07/cisco_harasse...
[2] https://www.csoonline.com/article/3220476/researchers-say-no...
> I don't claim to be nearly well versed enough to understand if that NSA advise is actually useful
Why do you think that it's thanks to the NSA, and not despite what the NSA wanted ? What NSA advice ?
Also, Dell supposedly can sell you IME-disabled (?) (thanks to this?) Intel CPU computers if you're a large enough organization.
Of course it could be that it's actually a fake way to disable IME – can we really know without having the firmware source and checking the hardware, which is likely to be a monumental task considering the level of miniaturization these days ..?
Video by Brendan O'Connell showing how Intel is infiltrated and compromised. He would be considered fringe, but there's plenty of info to be gleamed. Don't shoot the messenger
In the timeline where flat earthers hold annual conventions, why are you surprised?
edit: Having watched about 10min of the video please don't take my defence of the title screen as defence of the contents of the video.