It's not the pentester's job to fix social policy, merely to point out that threats can come from a variety of vectors that people don't expect.
3,517 karma · joined February 3, 2014
It's not the pentester's job to fix social policy, merely to point out that threats can come from a variety of vectors that people don't expect.
1. There was no one place that held all the data one was expected to know. Regs were strewn over legislative artifacts, departmental implementatikn documents, best practice documents, and international standards. Also, more than one class of regulations potentially covered efforts in the space. There was also no one site listing the locations of everything.
2. The regulations had evolved from an earlier time where an existing regulatory framework was adopted to try to fit new classes of things, and the mapping didn't work perfectly.
3. The regulations were written in a very high level manner to allow freedom of implementation and to make sure that the regulations didn't constrain tech development. Unfortunately, that meant that there were no suggested implementations which made it difficult for new entrants to the space (especially startups who can't afford to hire consultants) to understand how to actually comply simply.
4. There was ambiguity about what systems fit into which regulatory class as systems were advancing quickly and were changing state over time (ie updates) so traditional regulatory class lines were blurring.
That is where we stepped in. We were making a product that was ambiguously regulated and so we pulled the regs to understand them. Once we figured out how time consuming this was, we tried to make a software system to provide suggested basic implementations to be compliant and which helped companies properly bin their products into regulatory classes. Ultimately the entire regulatory system was changed rendering our product irrelevant, but I hope this shows why the system was as complicated as it was and helps demonstrate that the complexity was not a function of large players going for regulatory barriers to entry but rather a result of natural evolution and technical advancement over time which rendered existing regulations poorly suited for the current environment.
Alternatively, you could set up a bridge by hardwiring the device to a raspberry pi and then use the pi's WiFi to connect to your existing network. You then set up traffic forwarding across the NICs, man in the middle all the traffic, and only allow certain traffic in and out. This avoids the need to create a new network.
> I dislike gross displays of privilege.
You appear to simply dislike people who have much more money than you.
* The device is hardwired to light up whenever it is listening so you can't be eavesdropped on without some indicator.
* The device only transmits when it is in listening mode. This has been validated independently by multiple people.
* The device has a mute function (granted, software).
* The device can be registered under a bogus account.
* You can turn off all phone call capabilities / external listening capabilities.
* You can pihole it so it won't reach back to Amazon's ad services.
* You can delete any conversation you don't want stored manually, including one click deleting your entire history.
* You can have all content automatically deleted after X days.
So what exactly are people concerned about? Out of all the convos someone could have, a negative one just happens to probabilistically be recorded, you don't notice, and within 90 days someone in law enforcement or entity X figures it out and uses it against you? Someone at Amazon decides to look through your stored conversations and sees you turn on the lights at 5 PM each day?
I'm not saying there are 0 privacy implications with this device, as any device that has a mic and can record remotely has privacy implications. I just feel like the level of angst generated by smart speakers isn't warranted in the grander scheme of things.
Do people realistically think attackers are going to start burning zero days against these things to listen to the average Joe's kitchen conversations or bedroom chatter? What is the threat model here?
The good guys have a non-transparent approval mechanism for permission which no one can audit. In reality, you have no basis for claiming it's an effective overall control mechanism because none of us can see most of the data. Further, there have been numerous documented cases of abuse like intelligence officials spying on their significant others, parallel reconstruction on cases where secret data shouldn't have been used, etc.
An administrative policy control where application of the control is handled by the people holding the data with 0 auditing by anyone outside the system is not a strict control. Do I trust American intelligence more than the Chinese government or Huawei? Definitely, but that does not let American intelligence off the hook or justify what they are doing with mass data collection.
Granted, an average user will not be able to figure out how to do this and a standard private VLAN guest network is going to prevent this from working.
There were attempts made to bus in people from outside but they were fought tooth and nail by families across the income spectrum in the district because the perception was that it was unfair that they had to work extremely hard to get access to these resources but other people could simply show up and get it for free.
Reputation matters a lot.
I applied to one company and got a response back which was effectively "we really like you as a candidate, but it doesn't seem like you would be the right fit for this job / it doesn't seem like the interests you expressed in your interviews [which they correctly restated] matched up well with the duties we would have you perform. We will likely have jobs opening up which would align with what you like and you will be on the shortlist of candidates if you apply for those". Was it truthful? Who knows, but it left me feeling happy about how things went and I would consider applying there again.
Similarly, earlier on in my career after taking a few CS classes I applied for a different job, and the response was effectively "You are smart but you don't have the skills we require yet which are [x, y, z]. Come back when you do". What they said was true and I appreciated the feedback.
Contrast that with the myriad companies I applied to and never heard a response back from or didn't get a response back for many months from. I will never apply to these places again because it is clear that they don't respect prospective employees enough to even send a perfunctory email. Boiler plate rejections aren't as irritating but they are definitely still irritating. If you don't provide reasons for not hiring then employees will construct their own reasons, and they may not be true and / or favorable towards your company.
Did you have to Port forward or set up a VPN for local viewing? Just that will stop 95% of users.
In this specific case, I don't know. Perhaps rotating through ephemeral ports is done to mess with simple traffic filtering rules on firewalls?
The government / employers simply don't want to put their money where their mouth is.
It's also not like there was no piracy before scihub showed up. When I encountered a paper I didn't have access to back in the day, I would ping all of my friends at various universities / companies / hospitals and request that they check if they had access. If so, I would ask that they download it and send it to me. They would do the same when appropriate. Even doing this was more efficient than going through official channels, and every time this was done it represents another lost sale. From a user perspective, the piracy has nothing to do with money and is instead entirely about friction.
Personally, I'm willing to accept a level of risk from terrorism and crime if it means that I get to live my life the way I want to without being constantly monitored by government.
Regarding checks and balances, it's extremely hard to have robust authorization when the group calibrating and performing the authorizations is the same group or adjacent to the group who wants to look at the data. To do it well you need true, apolitical, independence between gatekeepers and users, and users can never be in possession of the actual data because access control can be easily bypassed if this is the case. We have never had that in this country, countermeasures against misuse always seem to be non-transparent and policy based rather than technical (ie secret courts and warrants that no one can actually audit), and data is repeatedly misused over and over with no consequences (eg parallel reconstruction, people spying on partners, people spying on celebs, etc).
Also, schools frequently are in charge of public transportation in the form of shuttles, buses, safe rides, etc.
Regarding subsidies, yes everyone should pay because it's a community and that's how communities maintain large collections of shared infrastructure equitably. Spreading the costs over a large group keeps them down for the individual users. Also, you can extend that logic infinitely. Why did I have to pay for football fields I never got to play on? Why did I have to pay for performing arts theaters I never used? Why did I have to pay for community facilities that weren't targeted towards my race or religion? Why did I have to pay for expensive research labs in departments other than mine? If you abandon the community model then everyone ends up getting slammed with highly variable usury taxes that they may not be able to pay.