Surveillance too cheap to meter
queue.acm.org
queue.acm.org
Electromechanical end exchanges did not log call data for local calls. Some of them counted it, with racks of little counters, read once a month. Toll switches had a logging system involving a wide paper tape. No cheap storage devices existed in the electromechanical era.
What's now referred to as a "pen register" is today an extract from switch logs. But at one time, it was a real physical device. A device that put dashes on a paper tape to log dial pulses. I own one, and it's the one shown in Wikipedia.[1] Mine is hooked up to a dial and some circuitry for demos. You wind it up with a big brass key. The first dial pulse starts the clockwork moving, and it continues to run until there have been no dial pulses for a few seconds. Someone had to hook one of these up to a specific line to track what was being dialed.
That's what the Supreme Court was talking about when, in Smith vs. Maryland, Justice Blackmun wrote "Given a pen register's limited capabilities, therefore, petitioner's argument that its installation and use constituted a "search" necessarily rests upon a claim that he had a "legitimate expectation of privacy" regarding the numbers he dialed on his phone."
The "limited capabilities" are a lot less limited today than they were in the wind-up era.
If the New York telephone didn't like what the FBI was doing, that's the most passive aggressive thing I've ever heard of.
I've never researched it, it's too good to prove wrong. It does seem pretty plausible though, the cops and/or judge that ordered monitoring it would be pretty annoyed if it got cut off.
https://www.nzherald.co.nz/nz/suspicion-over-dotcom-net-glit...
> The data showed the internet signal had previously taken two steps before going offshore - but was now taking five.
> Information held by the Herald shows Gen-I studied data showing the amount of time it took information on the internet connection to reach the Xbox server. It went from 30 milliseconds to 180 milliseconds - a huge increase for online gamers.
There’s just no realistic way that bouncing the connection around New Zealand would introduce a ~100ms delay. It sounds like he just started getting bad routes to the gameserver, which is par for the course for Oceania, but unlikely to result from LI.
Maybe the people doing the intercept made a mistake. It sounds like they made a legal mistake, so maybe a technical mistake isn't that far fetched either.
Intercepts aren’t hard, it’s a feature built into regular ISP hardware.
I’d guess this was just a separate, unrelated routing error.
The federal government is notorious for paying its suppliers years behind schedule.
This shows a couple of things:
- Back then extensive surveillance would have been hard to conceal because it would have been noticed by the large workforce needed to physically maintain the system.
- At that point members of parliament could reason correctly about the internal details of the telephone network, because it was simpler, and because many MPs had become MPs via the unions and so had experience of a trade.
Millions of hard drives run 24/7 in thousands of data-centres around the world. Millions are discarded and replaced annually. System security is inversely proportional to the demands and power of surveillance actors (NSO for example), so we all lose money when we tolerate surveillance. By 2025 cyber-security will cost the world about $10.5 trillion per annum, and a significant amount of that will directly result from the existence of a concomitant surveillance industry.
The cost to society and business in damaged trust and lost opportunity must run to dozens of trillions over the past decade.
No! Surveillance is cheap to tiny minority who inflict a colossal economic externality onto the rest of society.
> IT nerds tend to find technological solutions for all sorts of > problems—economic, political, sociological, and so on. Most of the > time, these solutions don't make the problems that much worse, but > when a problem is of a purely economic nature, only solutions that > affect the economics of the situation can possibly work.
This is insightful. Let's start changing the economics around surveillance. Let's make it very, very expensive again.
That is a small goal of GDPR.
Still a massive improvement over the previous status quo, data collection is now much more transparent which makes it easier to oppose.
I would love to know how much potential energy that could manifest in negative physical behaviors in the future is currently sitting idle in the minds of people, waiting to be triggered by some event. I would say that the trucker convoys in Canada are one example of this, as was the election of Donald Trump.
For context, the world needs $4T/yr[0] to transition to a zero carbon economy. It is kinda crazy to think about when you compare these two, considering how massive of a problem one is and how we often don't think about the other.
[0] https://txtify.it/https://www.wsj.com/articles/why-financing...
But to answer your question historically...
> and all this for what?!
I would argue that it's for Pax Americana, a very complex thing which the world has largely benefited from and yet we all hate on it.
But I definitely agree we could get rid of war. We've been in long peace. It seems very possible.
That's not true. France for example still has strong military. So does UK, Israel... Not saying it's a good thing that these military institutions exist, but except maybe in Ukraine nobody in Europe would feel (more) unsafe if the USA military would disappear overnight.
> But I definitely agree we could get rid of war. We've been in long peace. It seems very possible.
I agree it's very possible given the right mindset/circumstances. But we're far off from it. War feeds from countries with mafia-like governments who take all the people's money under securitarian pretexts, and these governments have never stopped waging war. In some countries like France, the government has even pushed for military patrols in the streets (since the 80s), training for kids in schools to anticipate attacks (since 2015) and the return of mandatory military service (or so-called universal national service, since 2019 i believe).
The US is still at war in several countries, and so is France. We don't feel it on the mainland because the propaganda is really strong here (whenever we're talking about it it's along the lines of "don't ask questions, we're just killing terrorists") and the consequences are very remote. But war is still really real for many people on this planet, and is still (mostly, though not only) caused by western imperialist powers imposing their will on the rest of the planet (see for example what France is doing in Mali to exploit all the riches in the north) or by the governments they arm (see what Saudi Arabia is doing in Yemen).
To be fair, i'm not saying Russian or Chinese military are any better. I just don't understand how we could stop wars when the military establishment is stronger than ever in our own countries, and still causing wars and suffering abroad. Such criticism can still be interpreted to be illegal, as France has banned insulting national symbols (since Sarkozy), and anti-imperialists militants such as Jean-Marc Rouillan can still be condemned (after spending decades in prison) for denouncing the lies of the propaganda of the french empire.
That's a lot of money. A quick google search points to this: https://cybersecurityventures.com/cybercrime-damages-6-trill... but I'm not sure that's the same as the claim. Source?
2011: Europe 27bn UK Detica et al., 2011
2015: Global $400bn Center of Strategic and International Studies
2019: US growth 17% BRC Crime Survey 2019
2021: Global 1tn Barclay Ballard
2021: Global $5tn Cyber Security Ventures
2022 growth looks like between 20 and 30 percent!
2022 Global 10.5tn by 2025 Cybersecurity Ventures claim
Looks like an exagerated/pessimistic claim based on a growth of over 20%
Sources:
2016 Estimating the costs of consumer-facing cybercrime: A tailored instrument and representative data for six EU countries (Riek and Bohme)
2019 Measuring the Changing Cost of Cybercrime (Anderson et al)
The industry is fundamentally broken. NSO is the smallest part here, they are even consistent with their approach. Surveillance was legitimized by governments and every small fry that complains about NSO specifically is not worth your vote. They are hypocritical liars and probably ordered their software or were about to do that.
In the EU for example there is no opposition to track connection information of everybody, nor is there one on national levels. It is a sad and settled reality, only solution is to escape to other countries which mostly do not fare much better. Even with NSA activity the US is probably a good alternative.
Telcos at first didn't want to store this information, although they probably would have as the economic benefits became clearer. You cannot explain mass surveillance to the fearful bloke politician. There are a few that are smarter, but they don't have the numbers. While it has to become expensive, we also need to see out people that champion this destructive surveillance. It is against the spirit of many constitutions and restricting any compliance is a step for civil disobedience.
There is a strategic component. If everyone does collect info but me, I am at a disadvantage. There is a political component to it. But it does not justify the crimes politicians have comitted in the last two decades. And they are nothing else but crimes.
- The incremental costs of surveilling an additional individual are low. This is the classic economic distinction between fixed and marginal costs.
- The cost of breaking out of the surveillance-capitalism-state industrial complex is high. Devices, networks, applications, servers, services, institutions, business models, protocols, hardware, communications methods, directories ... ALL are fundamentally grounded in surveillance.
If you want to break out, you've got to break out on all fronts simultaneously.
And that turns out to be very, very, very hard.
The merchants repeatedly find that once smart dust (tiny swarms of nanomachines) are developed, governments inevitably use them for ubiquitous surveillance, which inevitably causes societal collapse. <https://blog.regehr.org/archives/255>
This meant that your location remained private -- even from triangulation attacks! Not even satellite pagers have this feature; they all require that you transmit first (often with a GPS coordinate included).
With the collapse of the POCSAG networks (at least in the US -- the vast majority are now off the air), we have lost something valuable.
Wide area broadcasting might not be as bandwidth-efficient as cellular schemes, but if you just want to receive a kilobit-sized notification (which might be of the form "you have a message from XYZ", prompting you to go online) that isn't a big deal.
We could go from always-on surveillance to letting people decide on a per-notification basis if declaring their location is worth receiving the rest of the message. Or if they should move to a different location before doing so.
Besides, you should not rely on physical infrastructure providers for encryption. TLS is done by the endpoints, not the ISPs, for a very good reason.
Could a similar capability be built on a local LoRA mesh?
The lowest-frequency LoRA transmitters are still UHF, and they can't be used from towers or hilltops due to HAAT restrictions: https://en.m.wikipedia.org/wiki/Height_above_average_terrain
You really want something VHF or below. Like a chunk of the former analog TV bands. A really really tiny sliver is enough.
LoRA is a horrifically bandwidth-inefficient protocol. It craps on a gigantic swath of frequencies in order to send a few bits of data. They call it a "chirp", not a "crap". The only reason anybody gets away with such a wasteful modulation scheme is that it happens in the garbage band.
You would think that pager service would be significantly cheaper to provide than something like 4/5G...
In almost every way, except the forcing function of using an expensive resource (radio spectrum) less efficiently.
"If you write an app for either platform, you have to publish it through the respective walled garden, and you can do so for free—but then it must contain built-in advertisements that provide Apple and Google with surveillance data of your users. If you want to protect your users from that, you must sell the app for money and hand over a cut to compensate Apple and Google for the missing advertisement and surveillance revenue."
I remember back in the early days uploading a free app with no ad frameworks to the play store, and I believe there are plenty of third party ad networks (that I'd assume don't share data with Apple/Google)
You may release a free app with no advertisements. In fact, that is the easiest configuration, since charging for the app means setting up payment information. And including ads means payment information and integrating ad serving code into your app. It is not "built in" on either platform.
Even if governments do end up allowing alternative app stores, I imagine the laws will include some sort of liability clause that means the store owner is responsible for censoring any apps that the government blacklists.
This may not be relevant now, but when Western nations start banning E2EE chat apps and VPNs, I think people will become more aware of what a choke-point the app store model is.
No one seems to care.
Apple's store and OS is more opaque. Others may be better able to explain their mechanisms.
A small minority of us don't have Google Play Services on our phones and get all apps from F-droid. So he is not referring to us.
As a developer and system administrator I would have added to this piece how costly it is to actually delete data. It is usually far cheaper to store everything even well after it has legitimate use because developing archiving routines and strategies that don't break other things is work that few IT organizations bother with among all their other priorities.
This is true and one of the key reasons for GDPR. The cost for keeping data beyond the legitimate use needs to be increased.
Just last week I went over user accounts for one of my apps and deleted those that had expired for longer than 6 months on the live server.
So, their data is off the live server but still on weekly backups that are rotated out and deleted after 4 weeks. But I also have snapshots of that server that go back years and it would be some work to delete a user's data on those. And other users might need to recover data, so I can't just delete the snapshots.
Thank you for putting in the effort and deleting properly.
App bundles are terrible, but if the developer uses apk, the signature makes sure no one, including Google, can tamper with its contents.
https://android-developers.googleblog.com/2021/06/the-future...
> but then it must contain built-in advertisements
Could just as easily have been: > but then it most likely contains built-in advertisements
In a technical article there may be many reasons for simplifying an explanation, but there is no excuse for lying.So I don't believe this is a harrowing mistake...
"There is objectively no reason why Apple or Google should know every single time you make a phone call or send a message, but since their profits are built on them knowing, you will not find it easy to configure your mobile phone to not tell them"
I could see it being true about Google, but Apple?
My dad and I spoke about this a few years ago. When we lived in NYC I used to go to work with him for a week or two in the summer. The only evidence recorded of that was my name on the visitor log taken by the receptionist.
That visit today is almost certainly auditable. The subway trip is via payment card, and our entry in and out of stations are almost certainly captured by MTA and NYPD cameras. Street surveillance is pervasive in Manhattan from any number of entities. The NYPD network has facial recognition capability.
Entry into the building is logged by swipe card, every time you go pee in the bathroom in the public area, there’s often a badge swipe.
So are we less free? I don’t know. We’re more watched. But then again talking to my cousins on the phone in California was a major family event. And my dad would have to dodge out of work to take out cash for the weekend. A few weeks ago we took a long weekend in Florida with 4 hours notice and travelled without luggage.
They have more things to keep them entertained, more tv channels, millions if not billions of websites to choose from, so much content on streaming platforms like Youtube, you would need millions of lifetimes to watch everything.
You see, if you know enough about humans or any other animal you can manipulate them, like throwing a dog a stick to fetch, this means they dont have freedom not even freedom of thought.
Newspaper headline writers are wordsmiths, but now science can predict what words and phrases will hook different types of people to get them to read their output. Just look at the Trump relection & Bidens election, using adverts to identify floating voters ie those who have not made up their mind and then targeting them to manipulate them to vote a certain way.
I can usually pick out the next US president from a year before the elections, done this Bush.
Its like right now, people give out data which when datamined can be used to track and identify people across multiple websites, work out your working patterns, holiday preferences and then from there you can be targeted remotely or in the flesh.
We get little nuggets of information released which give us clues as to the level of surveillance and scope. One example. https://en.wikipedia.org/wiki/AT%26T#Privacy_controversy
Another example although this is more access to property, but its a tool you can find in Locksmiths toolkits and first responders tool kits. In other words this is a deliberate bug in a security system. Link is already cued. https://www.youtube.com/watch?v=U5-qy2tbDG8&t=119s
This is a real eyeopener. https://cryptome.org/
When you look at the legislation that exists and does not exist, you can identify the area's where state criminality can occur, but the official secrets which released by countries annually will always hold back some stuff as national security. This can include things like techniques still valid for use today, ie stuff thats been used for hundreds of years and stuff that is fairly recent but still in use today.
When you look at the legislation that exists, like people haved said we are a product of google, we are also a product of the state.
This applies to organized crime, street crime of the petty or violent kind and of course to purely digital crime. In some cases, the absence of being caught is because of simple corruption (especially with organized crime) but in many if not most, it's still down to old fashioned police ineptitude, indifference and ironically, more crimes than ever being reported specifically because of wider surveillance and easier means of calling public social media attention to criminal activities.
If anything, these factors in many places just saturate police into inactivity, instead of causing greater punitive measures, and all this, despite widespread surveillance. A simple first world example: San Francisco. No shortage of social, technological and police surveillance resources, but good luck getting an iota of investigative attention even if someone openly steals something from you, unless you're well connected or lucky.
If it was that simple, I would applaud the new era of surveillance. Unfortunately, some people will be above the law, while others will be subjected to it.
If privacy laws were actually repealed, and everyone saw what everyone else was doing, it might not be so bad. It’s the unfairness of it that really stinks.
This is a big problem, but hardly the only one.
There’s plenty of things illegal in various places right now which I don’t believe should be illegal. And some other things which were illegal and socially unacceptable when I was young and which are now not only perfectly legal but also socially normalised such that having a problem with it marks one as a bigot.
But even for the things which I do wish to remain illegal, almost all of them will need significantly reduced penalties in a world of omniscient surveillance.
To give a specific example of how the status quo would break if we had perfect surveillance but didn’t change anything else: In the UK, the minimum penalty is a £100 fine and 3 points on your license, and if you get 12 points within a 3 year period you can be disqualified from driving. Enforce that perfectly, how fast would everyone in the UK lose their licenses?
Phones had navigation before they had GPS chips based on cell location. Standalone GPS navigation devices with similar form factors to phones existed as well. And GPS dongles for laptops allowed turn-by-turn navigation back when an iPhone was a bulky thing that sat on a desk and dialed into a landline ISP.
There wouldn’t have been Uber, Yelp or Pokémon Go before location was just an API call.
> My phone spends four to five seconds trying to tell Google about incoming calls, then raises a notification about its failure, resulting from my failure to configure it correctly, and only then does it activate the ringtone.
What would have been configured incorrectly here?
$ vim awesometelephonesystem.conf
[logging]
logpath=/dev/null
Done. No need to redesign anything about the system itself. Data comes in, data gets thrown away.I am merely pointing out that, once the law permits doing so, actually not storing something is quite easy.
Absurd and dangerous simplification of democracy. You will not get anywhere with that kind of thinking.
OT: That's not really interesting data, it's flashy data at most. In those situation, we have a very specific image what data we expect to see - it would be more puzzling if someone big sports event didn't cause a spike in mobile connections from the stadium.
But I don't see how any new knowledge is generated from this stuff despite press releases telling everyone what they already know.
I have been using a $5 vps for setting a simple vpn for family. it is super easy to ru your own vpn now. Some sites dont work because they have dumb ip blocklists but most do or give hcaptcha.
Imo, 1. The more we use vpn, the higher the cost of surveillance. 2. Sites using dumb techniques like hcaptcha and ip blocking will see a drop in traffic and have to wise up or lose out
Are the records not useful in this case, for the client to defend themselves against the third party?
Warantless surveillance may be a problem, but the data has legitimate uses. I wish people would spend more time trying to change how it is used rather than trying to stop the collection.
Essentially my tv is bricked outside of traditional cable.
I dont use or set up voice commands but the privacy agreement allows them to store my voice for voice commands without setup.
If I dont agree to the privacy statement I cant use my paid for streaming services.
Life in this century is a total joke.
I will never get another smart tv and I hope the trend dies.
It always seems like many an HN or other commenter from around the web/internet are keen to argue that Apple's platform is different and is not architected on an economy of surveillance. If anyone reading doubts this, I can dredge up some examples. In any event, these folks like to focus on differences rather than similarities. There are similarities. Lots of them.
Here, PHK says Apple's platform is architected on an economy of surveillance, just like Google's. I must agree with PHK on this one.
"There is objectively no reason why Apple or Google should know every single time you make a phone call or send a message, but since their profits are built on them knowing, you will not find it easy to configure your mobile phone to not tell them-and you will be constantly pestered by ominous warnings and notifications if you manage to do so."
With NetGuard on non-rooted Android, one can block all Wifi and Mobile connections on a per app basis and per domain+protocol if desired. One can block everything and whitelist selected apps.
How does Google track calls and messages in spite of NetGuard.
"If you write an app for either platform, you have to publish it through the respective walled garden, and you can do so for free-but then it must contain built-in advertisements that provide Apple and Google with surveillance data of your users."
Is this true. What about repositories or applications like F-Droid.
"This takes an incredible amount of RTTs (round-trip times), which is why work on HTTP in the past 10 years has had a laser-like focus on avoiding TCP's three-way handshake by any means imaginable, while at the same time trying to obscure-as much as possible-precisely how much and which surveillance data the big platforms are collecting."
Is he referring to HTTP/2 and HTTP/3. Observing outgoing traffic does appear to be more difficult under these revised HTTP protocols. Intentional or merely a side effect. You make the call.
"Whenever you see one of those "Share this on Facebook" icons on a web page, your browser makes a DNS request and an HTTP request directly to Facebook's servers to get that little image."
To solve this problem, some web pages just use a locally-hosted image for the icon, not one hosted by Facebook. No lookups required. It really is quite sneaky the way that Facebook places those icons on millions of web pages. What looks like a harmless buttton is truly a surveillance gimmick. It is sad that so many websites play along with the game. Perhaps they are not even aware of what they are supporting.
Could you expand on this? Making such a statement, then not providing a modicum of evidence isn’t the best way to make a point.
https://news.ycombinator.com/item?id=30342336
The same sort of phony differentiation could be applied call and messaging surveillance. Apple and Google both collect similarly gargantuan amounts of user call and messaging data and store it in enormous datacenters.
Again you’re making assertions with zero evidence.
Please provide actual citations for Apple collecting “gargantuan amounts of user call and messaging data”, not just links to people misunderstanding what features Android provides.
https://bgr.com/tech/iphone-call-data-icloud/
https://theintercept.com/2016/11/17/iphones-secretly-send-ca...
https://www.macworld.com/article/229163/apple-saves-iphone-c...
https://fortune.com/2016/11/17/apple-call-data-icloud-elcoms...
https://www.wired.com/2011/04/apple-iphone-tracking/
"The zip file contained mostly Excel spreadsheets, packed with information that Apple stores about me. None of the files contained content information -- like text messages and photos -- but they do contain metadata, like when and who I messaged or called on FaceTime."
https://www.zdnet.com/article/apple-data-collection-stored-r...
None of your links indicate that’s happening.