HNHacker News
TopNewBestAskShowJobs

ideophobia

172 karma · joined November 2, 2016

submissionscomments
ideophobia··on Palantir is using War on Terror tools to track American citizens
From what I recall all activity is logged. We also had numerous external databases/tools that were essentially API connections to reduce the number of separate logins we'd have to do, and each of those databases had their own audit mechanisms. Long before we ever had Palantir in my department, we did have an employee who had misused a database for personal reasons. They were initially terminated but that was undone upon appeal. They were reprimanded either way and lost access to various tools/databases going forward for a long time. I know of many stories of police, for example, getting fired for abusing the NCIC databases for personal gain. Sadly it often falls on the agencies to self-police these issues, and most don't have anyone dedicated to this effort. So it really falls on the first line supervisors, of which some are great about it and some couldn't be bothered. I am of the opinion that all security, intelligence, and LE agencies should have an internal team solely focused on audit & review actions for internal abuse/misuse/privacy concerns, but that is a minority opinion from my experience.
ideophobia··on Palantir is using War on Terror tools to track American citizens
I was frustrated with management in my department and ended up leaving for private sector.
ideophobia··on Palantir is using War on Terror tools to track American citizens
You can search on or around nearly anything. That's one of their selling points to customers. The search function is multi-faceted, in that 1) it can index the data of any files you upload to Palantir (making everything text searchable), 2) Analysts can indicate specific attributes of an entity just by highlighting text in a file and marking it as a DOB or SSN or whatever. 3) The # of attributes is nearly limitless.

One of the primary screens in Palantir is a simple search page designed to work (and look) like Google, to search upon your entire database however you'd like. You can enhance the search function via the various attributes built into your installation or using advanced search tools. So I guess a "fishing expedition" in the traditional sense is very easy, as it's limited by the data you have, not the system itself.

ideophobia··on Palantir is using War on Terror tools to track American citizens
I used to be intelligence analyst that utilized Palantir on a daily basis. Ask me anything.
ideophobia··on What's the Difference Between a Frat and a Gang?
Slightly anecdotal, but I used to be a gang intelligence analyst for law enforcement. In the Commonwealth of Virginia, gangs are defined as having: 1) a shared identifiable name or shared identifying sign or symbol, 2) members who individually or collectively have engaged in the commission of[..] two or more predicate criminal acts, at least one of which is an act of violence, and 3) have committed criminal acts which are in furtherance of the gang. The predicate acts are defined separately as a bunch of things, some logical and some less so.

The Boy Scouts of America, for example, meet criteria 1, but don't meet criteria 2 or 3 (I hope), so are therefore not a gang.

Alternatively, a person who associates with a known criminal gang and commits a violent robbery in order to obtain food for their kids, would not have their actions treated as gang-related crime because the act was not made in furtherance of the gang, but rather in furtherance of their person. If the same act was committed as a gang initiation, than it could be considered as gang-related crime.

A traditional Frat does not meet the criteria, in my mind, because there is insufficient evidence that they are committing violent acts in furtherance of the organization rather than for their own personal gain. You would have to argue that assaulting women is specifically perpetuated as part of that particular Frat's culture (not just Frats in general), and that members knowingly commit sexual assault in order share in or improve upon that Frat's culture and it's success.

I would also argue that a sub-group of wrong-doers who are part of a larger group of non-wrong-doers does not inherently define a gang. A group of bad cops doing bad things isn't inherently a gang, nor does it make cops a gang. A better example would be the CRASH cops from Rampart who essentially created distinct group within the police department, with names and symbols, who committed a variety of violent and non-violent crime in furtherance of the group itself, not the individuals or the police in general.

ideophobia··on Startup Ideas We'd Like to Fund (2008)
i'm imagining the better statement is 'music ownership became less relevant'
ideophobia··on EFF: Accessing Publicly Available Information on the Internet Is Not a Crime
I agree with this, but I feel like I've also seen the EFF and similar advocates cry foul when companies or governments use tools to mass monitor publicly visible user information on the internet. Genuinely asking: Is there a discernible difference between scraping LinkedIn data in this instance vs. scraping Twitter data about protests or threats against politicians?
ideophobia··on Ask HN: How you prevent accidental leaks of your company's data?
It largely depends on the size of your company and the nature of your data. There are probably 4 simplified aspects to tackle this issue from, in my opinion. I work in data protection for a Fortune 500 company.

1. Data tagging or classification - identify and tag your sensitive data, then use the tags to control/monitor what happens to it. If done fully and correctly, you only have to worry about the data that matters, not someone's chili recipe or their kid's soccer schedule. The industry term is Crown Jewels, which represents the data that is absolutely critical to your success and would be catastrophic if lost. Secure your CJ, and your biggest risk is mitigated.

2. Egress monitoring - establish tools or processes to monitor what data is leaving your company, where it is going, and how it is getting there. Look for anomalies, abuses, and undesired activities. Perhaps your intellectual property should never be in China.. uploads to 163.com or message attachments to QQ messenger addresses might be concerning.

3. Technical controls - Does your company need USB drive access? If not, block them all from moving data via USB. Does anyone in your organization burn data to CD/DVD media? No? Block it. Turn off the egress vectors that aren't needed at a user/team/site/org level. The most common egress vectors are USB, CD/DVD, Email, Network Upload, Print, and wireless transfer like bluetooth. There are others, but these are the most encompassing. You can do things like block all emails going to personal email domains like gmail or yahoo; limit print amounts to 20 pages per user per day; or block access to all domains/IP's in specific countries or regions on the network.

4. Security Awareness - Employees need to be fully informed about the data protection requirements you have in place, and the related consequences for breaking acceptable use policies. Education and awareness campaigns are key, and probably the most overlooked option available. I personally believe informing employees about real life cases of data loss/theft, whether they are your own or just in your industry, is crucial in making the risk seem more real.

I can't recommend any specific products, but in general I would say look for tools that can give you things like: data tagging, network activity logging, end-point monitoring, anomaly detection, live response, data loss prevention solutions, and/or critical data protection.

ideophobia··on Show HN: iOS music player, like a virtual record collection
I like the look and style, and I think you really nailed the vinyl aesthetic. Unfortunately, I've abandoned music on my iPhone in favor of Spotify+Amazon. But, I would love to see this for non-iOS devices. If you could get it to run on a touch screen powered by a Raspberry Pi, I would totally use it for a home jukebox-stlye device. I think the album art elements and other mechanics would be awesome in that regard.
ideophobia··on Ask HN: People who are here- are you on Reddit too?
yes, but reddit now more for funny stuff or random news. HN is slowly becoming my daily driver for just general reading/topics of interest.
ideophobia··on Ask HN: Should I create a new HN for Technology related to Geopolitics?
Seems almost bizarrely niche in my opinion. I wouldn't pursue a HN clone unless you already have a really good grasp on an existing audience looking for this exact type of stuff. If you believe this is information that we truly all should know, or at least be aware of, it would seem to me that you'd benefit from distributing it in places that people already visit, rather than some place no one has heard of yet.
ideophobia··on Geofeedia cuts half of staff after losing access to Twitter, Facebook
They knew it was a social media aggregation tool which collects publicly shared information. They also knew it was used by law enforcement, public safety, emergency management, first responders, ambulance authorities, search and rescue orgs, and other people who benefit from a tool which streamlines the deluge of openly and decidedly public info people post online during emergency, crisis, and potentially criminal incidents. Sound like decent folk to me..
← PreviousPage 2 of 2