Assange in 2011: "They have automated the process."
thenextweb.com
thenextweb.com
What we need are tools that allow us to connect in ways that are difficult not only to detect but also to make sense of (not necessarily encryption, but an ad-hoc format that can't be easily parsed and aggregated). We need the ability to use the network for our own particular, peculiar interests rather than having to fit our interactions into some other authority's template for their interests. The idea that social networking never occurred before Friendster, FB, MySpace is ridiculous -- it just happened more informally before.
I'd like to see a return to this informal mode of using TCP/IP, where the internet itself is the social network rather than merely a transport layer for some centralized system. This may make it harder for everyday people to benefit, but it also means they learn how to drive before they use the roads. Social networking's hyped-up promise has always been to passively connect people, but the promise of the internet has always been to allow people to actively connect (or not connect). Once we have a broader suite of tools for this latter purpose, we'll see people reject centralized dossier services like FB.
Which would also make it much more difficult to use and less useful. We've organized our info this way because we like it and it makes sense, it's no surprise that it's useful to the government as well. In other words, I think the value to us and the value to them are very tightly coupled.
And the thing is, outside of the hardcore techie bubble, most people don't care. So what if the government can see their friends and pictures, even track them to some degree? Why should they care? They're not going to migrate to some convoluted unstructured system just for the abstract and esoteric benefit of privacy.
Maybe. As somebody who's worked in content management system design for a great deal of his career, I'm not at all convinced that the ongoing enclosure of information into systems of formatting serves people. Instead, what you find is people jumping through hoops to fit their information into the format chosen by others. Paul Goodman critiqued the tyranny of format 50 years ago, and Douglas Rushkoff authored the natural extension of this critique in his seminal "Program or Be Programmed". The promise of the internet has to be more than giving people text boxes, or I give up. :)
> We've organized our info this way because we like it and it makes sense, it's no surprise that it's useful to the government as well.
Really? The users of FB have decided that this is the way they'd like to organize their information? Surprising. I never recall in my use of FB being given the ability to structure the format as I and my friends see fit. I must have missed something.
In all seriousness, I think we need to look very carefully at this coupling of value you speak of. There are almost certainly areas where the format chosen by an authority (a corporation, a government, any institution really) is that that free individuals would choose. But not every area, and as the information gets more personal, the format becomes more restrictive. I'm not sure where the line between sharing on one's own terms and another's terms gets crossed, but any network that can aggregate detailed information about BILLIONS of people has certainly crossed it. The question is simply whether or not we should be content with this situation.
In aggregate, by choosing to use Facebook, and by providing feedback and usage data that shapes how it changes. I realize that there is a certain stickyness and network effect at play, but at some level we have chosen this platform and format, and many (most?) are content with it.
I can't really wrap my head around a useful replacement that has no enforced formatting/is difficult to aggregate and parse. If you have any more concrete ideas or examples I would be interested.
>In aggregate, by choosing to use Facebook, and by providing feedback and usage data that shapes how it changes.
I simply draw a different conclusion from that than you do. At some level we have chosen it, yes. I'm not denying that, but instead trying to figure out whether that level is necessary. I appreciate the pushback!
All I'm suggesting is that we design the keys ourselves. If that makes communication more difficult, perhaps it's also true that not all communication needs to be universally legible.
But we now live in a completely online world, where nearly all communication and files are conveyed and hosted by third parties, and soon it will take several minutes for even a geek to mentally count up the number of internet-connected computers in their house.
I am comforted by the idea that Jack Bauer and Chloe have timely access to information to stop the bad guys, and that US secret agencies have little motivation or bandwidth to use this information for anything but national security threats (and hopefully kidnapping and such). Bad actors in these agencies can obviously do a lot of harm to individuals, but those cases will probably be personal and few, widespread malicious use of this data by agency employees would be easier to uncover.
What I find most troubling is the ease with which the government can view my information and how I've steadily made it easier for them over the past five years by getting that iPhone, using Dropbox and Gmail. But, my life has seemed safe, prosperous and peaceful over that time and these services I use have had a profound impact on the efficiency and convenience with which I perform my daily routine.
Yeah, I loved 24, but thank god its a wonderful fantasy and not real.
Oh, forgive me, but what was the episode where Jack and co got the bad guys by looking at facebook?
Of course you don't care about privacy, why should you? You're just a peaceful flock member. never acting against the power of the status quo. But look around and see what happens to the people that actually do confront power and you'll see why privacy is important.
Really, you just have to pay attention.
In both cases their laptops/cameras/etc were searched and confiscated for a time. Neither person seems to have been detained overnight.
This is just the government being thorough. This is not disturbing to me.
https://chronicle.com/article/Why-Privacy-Matters-Even-if/12...
I wonder if anyone else would part with cold hard cash though, or is it just me? There maybe a niche there.
They're probably in all of our computers already. I've been operating a windows7 honeypot as my "main" computer for several years, generating what appears to be legit "personal" traffic. You wouldn't believe the shit I've found, and it doesn't appear to be your garden variety cyber criminals or foreign state actors. And I'm not even that smart.
Unfortunately this is not exactly my particular area of expertise, so for me it's like glimpsing a shadow through smoke and a moving window, mostly an impression but something that has become more and more sophisticated despite my attempts to prevent it via traditional and modern methods of forensics, and even weird things like audible and inaudible platter noise when there shouldn't be heavy (this is the key for me) disk io.
a) How are you identifying the processes? 2) How are you determining that they are inspecting the filesystem?
Process of elimination as far as the processes are concerned. Basically I have been paring back the processes that are visible to me in memory until it should be a bare minimum for a functional Windows kernel in memory, and stubbing out the non-essential processes I find with empty "stubs" so that the hooks are still there but non-functional. Then observing disk io and memory usage, and repeating. Not very scientific, but again, I'm an amateur.
The stuff about disk platter noise is simply recording the audible and inaudible frequencies generated from the platter (I haven't upgraded to a ssd for the system disk yet), and then running regressions on the wave forms to detect anomalies via the noise generated by the platter and the reading head interacting. I was interested in looking into the inaudible frequencies because it seemed like a good way to cloak disk io from the average user.
As far as the botnet stuff, I've done some MITM packet analysis and some simple stuff like tracerts and observing changes in routing. Right now the box is routing all name service through what appears to be another compromised box in the US state of Georgia, though I'm hesitant to do much network topology due to port-scanning being considered the same as cracking.
This is all just a hobby, and I'm sure some of the stuff I've mentioned about is either very crazy sounding or perhaps already known to people more knowledgeable than me. I grew up when pcs were still a weird hobby for society, and so this sort of stuff seems like things we should be able to do without fearing repercussions.
Also, I only posted this to give context to what I had posted before, so take it for whatever you want to. I'm interested in non-violent solutions to improving society and I don't want to jeopardize that.
A lot of this stuff is sort of ephemeral and I don't have any credentials to really convince anyone. That's why I would post this, maybe someone else knows more than me. Like I said, take this as anecdotal and perhaps incorrect... You'll notice a lot of assumptions by me.
If you are genuinely concerned I think it is pretty simple to contact real professionals with whatever data you have.
On the other hand you would be fully up to date at all times on the evils of vaccines and water fluoridation.
Though I wonder when dissemination of vaccines will be more of a science instead of "We know this strand of virus is going around, everyone come here and get a shot of xyz because it is good for you and will protect you all", especially since overdosage of the massess will eventually lead to resistant strands.
It would be really cool to have a personal 23andMe api where people can test themselves without sending data to a 3rd party.
There is also a decrease in "herd immunity" when a population has been flooded with a drug to the point where such immunizations have no effect à la "superbugs".
I'd be the first to admit I am no expert so if you have real interest in the topic I would go looking for someone better qualified to talk to than me.
These transferable genes often carry resistance to many antibiotics.
Staphylococcus aureus is a common germ that normally lives on your skin, but can gain entry to the body and cause abscesses, bone infections, pneumonia or infection of the heart valves. In the 1940s virtually all strains of S. aureus were susceptible to penicillin. Today, more than 90% of S. aureus strains are resistant to penicillin and many other antibiotics that were once effective against these bacteria."[0]
"One alternative, at least for some types of bacteria, is vaccination. Since Hib vaccines were introduced, the number of new cases of invasive Hib infections—both drug-sensitive and resistant—in infants and children in the U.S. has decreased by 99%."[0]
So yes, vaccines and antibiotics are different, but are meant to address the same things. From this most of the what we have seen so far has come from resistance to antibiotics, where vacancies have helping to address that void in some cases that didn't turn out to be accidental inoculation.
No vaccine is 100% effective; no vaccine is 100% safe. As with any drug, there are risks and side effects with vaccines, although serious side effects are mostly rare. However, there is a much higher standard of safety expected of preventive vaccines than for drugs because:
Vaccines are generally given to many people most of whom are healthy. People tolerate far less risk from Haemophilus influenzae type b vaccines than the antibiotics used to treat the diseases it causes, for example.
Many vaccines are given to children at the ages when developmental and other problems are being recognized for the first time. Because something happened at about the same time does not mean that one caused the other. (See Cause or Coincidence) Some vaccines are mandated by state legislatures in order to protect the health and welfare of the public. Some people think that this violates their civil rights, however."[1]
"Perception of risk depends on people’s experiences and knowledge. A person who experienced an adverse event after vaccination—or thinks that they know someone who did—will perceive vaccines as riskier than a person who has not. Conversely, one who has survived a vaccine-preventable disease—or a physician who has treated that disease—will likely be an advocate for vaccines.
Although concerns about vaccine safety are valid—and necessary—we must carefully examine each claim about the risks of immunizations"[1]
Taking the middle road on these issues is more productive than outright dismissal and becoming enraged, because it acknowledges some truth the individuals experiences/opinions or w/e that might be contrary to someone elses.
[0]: http://www.immunizationinfo.org/issues/general/vaccines-and-...
[1]: http://www.immunizationinfo.org/issues/general/vaccine-misin...
Not vaccinating people and thus allowing a disease to run rampant in the population, drive up infant mortality, and be present and breeding and thus mutating is not in any way shape or form the same thing as the over-use, mis-use, or inevitable decline in effectiveness of antibiotics. The moral and scientific issues are very, very different. That was what I was taking issue with in my original response.
I find nothing of what you wrote and quoted in the above comment to disagree with.
I don't deny the science behind the vaccines, but the motives of the people who ultimately control the process. The same people have taken away the average person privacy IMHO will as easily take away say his capability to produce children. But I guess it's easier to close your eyes and keep imagining that the elite has the same moral as yours and would never do horrible things.
I think you have to go with the certainty on that one, don't you?
So I believe there's a lot of money to be made in providing instant privacy the same way dropbox provides instant backups. Likewise as statistics + programming = data scientist, statistics + programming + security = privacy scientist
Sadly this also means that privacy will become a commodity and I can easily imagine a tiered system of privacy based on cost (eg 19.99/mo get's you a secure network + encrypted files, 99.99/mo get's you text re-structuring to avoid stylometeric identification.)
But, I think the more interesting point is that even if the system were hosted outside of US jurisdiction, or anyone's for that matter, they'll just find a way to make it difficult for you to access, as they do with thepiratebay - by blocking access through the ISPs. The inconvenience/complication of working around these ISP level filters, means that a lot of people won't know how or can't be bothered to work around them. The same would apply to a social network.
Privacy wise, the internet is dead. Just, forget it. The war is lost. They can, there for, they will. And that's that.
I mean, does any one seriously think these abilities and powers will be go, or be given up?
The bigger problem for me is that as my data is being stored in the US by US companies and my countries laws don't apply - and the safeguards provided by the US constitution also don't apply. The NSA/FBI can do whatever they want with my data and have said as much[1]:
"He said reports about Prism contained "numerous inaccuracies". While admitting the government collected communications from internet firms, he said the policy only targets "non-US persons"."
I think we might start to see companies having data centres in multiple countries and allowing you to store your data in the one you choose or the one that follows your countries laws. Otherwise there will be an exodus of users from US internet companies.
Considering the enormous amount of data being collected and the relative ease of setting up a clean trail, this kind of spying makes it even easier for low/moderate-suspicion individuals to achieve secure communications.
For high suspicion individuals, this kind of surveillance makes it easy to create disinformation that appears to be real intel.
The workflow required to leave a realistic "clean" trail while simultaneously engaging in secure communication could be designed into a purpose-built linux distro.
That seems to be the intent of Tails [1]; see also [2].
I'm more excited about these recent revelations than shocked and appalled, because now it is finally a national conversation with real outrage behind it. I've been waiting for this for years. Being called crazy, paranoid, anti-American, etc for years for voicing concerns about this has led me to a position of vindication on some level; however small or petty that may be.
- In the case of a social network, have it decentralised and have user profiles and information hosted on the user's computer, and only accessible when logged into the social network and only by those that you have granted permission for. - Messaging could be directly between users, over an encrypted channel. If user A sends a message to user B it does not arrive until they connect their device to the internet. Only then does the secure exchange of a message occur. Group messaging is a more difficult problem. - Cloud storage: if storage devices get bigger, smaller and cheaper there's no reason why it couldn't become normal for people to have physical backup solutions built into their devices. Alternatively, completely encrypted cloud storage where only the user has the keys could become the norm.
The problem lies in consumer acceptance, education and also convenience. If nobody understands the technologies they use to power their lives, it's hard to communicate why things should be done alternatively. The EFF does a fantastic job of trying to protect our rights when it comes to technology, but I don't think consumers get it. More needs to be done. The analogy of a man coming into your house and reading your mail that's been posted through your door springs to mind. And finally, it has to be easy to do all these things in a private way. Better tools need to be created to allow us to securely store our information, communicate and perform tasks.
Out of these, I only have a gmail account. No personal data in it is real. I never email anyone I know in person from that account, nor I give it to anybody who knows me.
I think I'm on the safe side.
I operate similarly with my phone and basically everything else.
Fast forward ten years and an increasing number of people vomit their entire life online, constantly.
First it was the iMac era, then the iPhone era, now the iPad era. With every era, a new demographic is being pushed into this new data reality and our calls from the beginnings go unheard.
The thing is - we would really like to say "told you so", but it seems overly cynical by now. Especially considering that it's not just our wildest dreams, but also our worst nightmares coming true at an exponential pace.
And even more than that - we really like people getting onto "our thing", so calling for caution now has a whiff of asking for exclusivity after our nice little in-crowd thing was blown out of proportion.
I guess I should be more concerned with gmail...
Will these NSA spy revelations hurt US internet companies? If I am German or Russian or Brazilian... do I really want to go out of my way to feed the U.S. intelligence beast?
Second: that kind of thinking could be a nice way to "motivate" the creation of alternative products out side of the us of a.
Third: but how realistic are such endeavors in today's world?
> Third: but how realistic are such endeavors in today's world?
It is entirely possible to develop a product outside of the US of A. And it does indeed happen.
Geez!
[1] http://www.theonion.com/video/cias-facebook-program-dramatic...;
We need more public spying on the government....
Are there public databases that collect information on officers/ agents?
If not what kinds of information would be valuable (to the public) to collect/ what kind of processes would be good to use(crowd-sourcing, web-scraping, .gov apis, etc)?
Even with legislation do you expect it not to be easy for any agency to just gather the information? At worst we will get an "Online Users Bill of Rights" which will only codify their rights to our privacy.
He's been labeled a rapist, a crackpot, or even an agent of the evil, with little regard to atrocities exposed by the Wikileaks.
Yet like our beloved RMS, if you read the early texts, it is clear that they had seen it coming way before us - sane, normal people.
+ I'm perfectly fine if they take my data — till its serving in the good interests of my family and people's safety.
+ It should only be in the good interests of our system and society.
+ But such credible data, should not be misused by the govt bodies or elected representatives!
Once they have amassed all this data about you they can mine it to their heart's content and use it to make predictions - those books you read before the "incident" that seemed innocent now get you flagged as a potential terrorist.
And Life goes by Hope and Positivity!
And positivity is useless if you just think everything can be fine as long as you have a positive outlook. That's foolishness. You SHOULD have alacrity towards this issue, but if you don't, that's your choice.
In ten years, you will look back and wish you did something. Mark my damned words.