Pentagon Now Sees Big Data as 'National Security Threat'
killerapps.foreignpolicy.com
killerapps.foreignpolicy.com
I'll save them some time and say its possible, and if they are just inquiring into this, they are already behind the game… Using wikipedia, one can get a list most of the oil refineries in the united states (for the world for that matter), and from some api queries using either popular or open-source map/geocoding services, obtain gps coordinates within 100's of feet of those locations, within a matter of seconds.
If you scrape cryptome/other places every so often of the lists uncovered (often with contact info[numbers|emails|names|addresses]) of people, map them against other lists to find connections (this takes a matter of seconds as well), it is not unheard of that one could automate emails/calls/send mail to people to uncover attack surfaces to exploit.
And even until more recently, one could access public all posts on facebook via https://graph.facebook.com/search without authentication, and with some well crafted queries, one was able to get specific information about people that one wouldn't think would be possible to obtain.
The list goes on.
http://www.zyn.com/sbir/sbres/sbir/dod/darpa/darpasb133-002....
They are right to be worried about the attack surface presented by the mobile & display ad ecosystem.
The key to any attack, of course, is de-anonymizing the data, in the sense of being able to identify corresponding entities across disparate sources of data. This is the technical challenge that a large chunk of the ad-tech industry has been working on.
This is difficult to do reliably --- but the reliability (or otherwise) of a particular technique may be moot if you have a population of several thousands of individuals that you can target -- sooner or later somebody will carry out the actions that your attack assumes, and you will be able to make the connections that you need. The attacker needs only think of the problem in terms of "matched filters" to make headway -- just discard anything that does not match.
Of course, characterising the target is only part of the story -- exploiting the information advantage comes next.
Funnily enough, the proliferation of open communications channels also offers a potential attack vector - the use of individually crafted messages and disinformation to direct attention and manipulate behaviour of the target -- similar in concept to the social engineering techniques that are used in spear phishing attacks.
Paste of text.
2. Hey, thanks!
:)
Wow. JavaScript is so ubiquitous now, that running NoScript must be like television without ... television. I mean, NoScript makes sense -- there are any number of scams that require JavaScript to be active -- but so much online content, online experience, now relies on it.
Most JS is bad JS. Activating it when needed on some sites (such as interacting w/ some buttons) is pretty quick. Plus you can whitelist certain things like Disqus and common sites.
Overall the security/speed benefits are worth it.
Probably true, and as often as you say. Here are two counterexamples:
http://arachnoid.com/mandelbrot_set/index.html#Mandelbrot_Ge...
Governments the world over are finding out that their secret airbases, their secret flights, their buildings and purchases are just "private".
You really have to work at keeping secrets. So instead of pretending you can keep everything secret, try being open by default. You will find it a lot easier to concentrate on the things you want to keep secret then. Oh - and never ever let your secret near anything digital
2. They see links to other articles from that site (e.g. "Most Popular on FP")
3. They decide to post that article to HN