HNHacker News
TopNewBestAskShowJobs

kenbaylor

443 karma · joined October 14, 2015

submissionscomments
kenbaylor··on The U.S. cracked a $3.4B crypto heist and Bitcoin’s anonymity
Likely on this basis: https://www.bbc.com/news/technology-35038971.amp
kenbaylor··on Google faces first investigation by its European lead authority over GDPR
If it's not exposed to the internet no problem. Not true unfortunately under the GDPR nor it's predecessor, if the notes are publicly available:

Bodil Lindquist v Åklagarkammaren (2003) Mrs. Lindquist (whose purposes were mostly charitable and religious) published on a private home page personal data about her colleagues, including telephone numbers and information about a coworker’s injured foot and medical leave. This case raised the question if a private home page accessible to only those who have the address is permitted under one of the exclusions (household activity). The European Court of Justice ruled that it is not.

kenbaylor··on Google faces first investigation by its European lead authority over GDPR
Not true unfortunately under the GDPR nor it's predecessor, if the notes are publicly available:

Bodil Lindquist v Åklagarkammaren (2003) Mrs. Lindquist (whose purposes were mostly charitable and religious) published on a private home page personal data about her colleagues, including telephone numbers and information about a coworker’s injured foot and medical leave. This case raised the question if a private home page accessible to only those who have the address is permitted under one of the exclusions (household activity). The European Court of Justice ruled that it is not.

kenbaylor··on [dead]
Major privacy honeypot...enter your number, have it PRINTED ON THE WEBPAGE for millions of other visitors to see, add to spam lists etc, they could at least mask the number....
kenbaylor··on Google loses ‘right to be forgotten’ case
It's been going on since 2010 in the Costeja case

and they lost the case in 2014 (https://en.wikipedia.org/wiki/Google_Spain_v_AEPD_and_Mario_...), and 'interpreted it' as 'we'll just limit the results from Europe'. This was a landmark case, and they just keep losing them.

kenbaylor··on VC from Asia is skyrocketing
This may be the one you are looking for: Cybersecurity law: https://assets.kpmg.com/content/dam/kpmg/cn/pdf/en/2017/02/o...
kenbaylor··on Google loses ‘right to be forgotten’ case
San Francisco was one of the few places in the world to try to address that with it's 'ban the box ' initiative. Crimes must be relevant to disqualify a candidate. https://www.shrm.org/resourcesandtools/legal-and-compliance/...
kenbaylor··on Google loses ‘right to be forgotten’ case
This is a big point of confusion. A background check will check the court records, where your convictions will still be listed (unless protected from disclosure e.g. California background checks generally don't show convictions > 7 years https://www.goodhire.com/california/background-checks).

A real con artist can just fake someone's ID, for them it's pretty trivial.

The issue is less than 1% of convictions ever make it to the Internet, and those people currently will be stigmatized forever, unlike the other 99%, unless they have this mechanism. Google's plea was 'we will self police, but we won't tell you how. We will ignore court orders, because we choose to'. The court objected to that approach.

If you are convicted of new crimes, no matter how long ago, then your sentence may be significantly increased as a repeat offender.

kenbaylor··on Google loses ‘right to be forgotten’ case
You are correct, and they will likely change that or face heavy fines, now that they have lost this case.
kenbaylor··on GDPR and the End of the Internet’s Grand Bargain
GDPR will have a massive effect no matter where you are. The trickle-down affects are key.

Many large companies do business with Europe. Many of them are implementing GDPR-like controls and/or adopting Privacy Shield. Other US companies doing business with them must adhere to the new vendor controls these US-companies have adopted, or lose that business.

Across the world, (e.g. Singapore, Philippines and Japan) Privacy laws are being re-written to align parts of local law to GDPR.

The US has limited privacy laws generally (e.g. dat breach notification laws in CA and MA), but has adopted specific protections depending on industry (HIPAA for healthcare, GLBA for Banking). More like likely occur.

kenbaylor··on Google loses ‘right to be forgotten’ case
They have started to pass laws. The GDPR covers the processing of criminal convictions here: https://gdpr-info.eu/art-10-gdpr/

While mankind has not needed a right to be forgotten previously, it didn't have the omnipresent Google to deal with either. These are just the opening shots in the Privacy battle that will spread from GDPR.

Other search engines are affected too, but Google has a massive market share and has a long litigation history in Europe.

kenbaylor··on Google loses ‘right to be forgotten’ case
Some of the factors that come into this include the very nature of criminal sentencing: A judge looks at the facts of the case, aggravating factors, previous convictions and sentencing guidelines, and determines an appropriate sentence.

Then along comes a search engine and doubly punishes someone in what may be a disproportional way; e.g. it's highly unlikely you will come across the convictions of John Smith when you google him, but when you look up someone with a non-common name, it may be the very first search result; disproportionally disadvantaging them for jobs, business and even dating partners.

The issue in this case was Google wanted to be the sole arbiter of what they would remove and what they would leave in, with no oversight from anyone. This would have crippled the GDPR even before it began.

That said, it's early days for the right to be forgotten.

kenbaylor··on Ask HN: Using Tor implies guilt?
This is a really good time for him to shut up and lawyer up.

The duty of the prosecution is to prove their case in court. The fact that they have seized his computer(s) and carried out forensics already, means they are looking hard for a conviction. If they freak him out with this sort of circumstantial evidence, he will say something, and it's never a good thing.

https://www.youtube.com/watch?v=d-7o9xYp7eE

Legal precedent depends on jurisdiction and you haven't shared that. Connecting to Tor is a 'fact'. What value that fact has is up to the prosecution to prove. Relevancy is key. Best to wait and see what they alleged happened and then challenge just those set of facts.

If he says nothing, they have a lot to prove. In many places in the US, they will come in with multiple felonies then accept all sorts of plea bargains as it drags on and on and on, like a bad used sales car man.

kenbaylor··on Ask HN: GDPR and gaming analytics
Start with the basics: Personal data (PD). The GDPR applies to 'personal data' meaning any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier.

How is the consumer (data subject) linked to the ID? aka how does a human prove ownership of the account (email address etc??) This is where your PD is.

The solution is pretty easy. You create a table where a user is mapped to an ID. Then you create the rest of the game just as normal, only using the ID.

You WILL need a privacy notice showing data subject rights and detailing what you are collecting and why, and other third parties that you share data with. Also how to contact you to enforce those rights. This should be on the website and wherever the game is (mobile app etc).

If there's a data request, you give them the mapping of their PD to your ID, and that's really it.

If they invoke their right to be forgotten, then you update that row of the table with something other than PD being mapped to the ID. Effectively, they are forgotten.

You can collect data once you tell them what data you are collecting and why, if you are relying on informed consent. They can either give it and play, or not give it and not play.

kenbaylor··on It’s Time to Make Our Privacy Tools Easier to Find
Under GDPR, that would be a yes if the key is truly lost, and the personal data is not recoverable by anyone.

If it is recoverable, then it falls into the ominous term: Pseudonymous : https://www.wsgrdataadvisor.com/2015/09/personal-data-anonym...

kenbaylor··on It’s Time to Make Our Privacy Tools Easier to Find
I wish they would give more clarity on what 'delete' means. Is it a) It's deleted from your timeline etc or b) It is really deleted from Facebook's servers

If it's a) then that's either a 'hidden' toggle which does not meet GDPR needs. If it's a 'hidden' and do not process further, it is questionable (unless a right to be forgotten is invoked).

Also if it's a) then everything is discoverable by someone with legal authority, even years after you believe you have deleted it.

kenbaylor··on EU GDPR – Another reason for SaaS to reconsider on-premise
There is a process to be followed. If you have the response from the DPO and a reasonable suspicion based on evidence, you can absolutely to to the DPA. If your evidence is strong, that may proceed on that. If not but there are many other similar complaints, they can formally ask the company to 'clarify' issues....which is a very dangerous thing if you are a company that is evasive.
kenbaylor··on EU GDPR – Another reason for SaaS to reconsider on-premise
Most of the EU litigation has been against Facebook.

They have spent many millions in EU GDPR projects (such as the ability to download all records, which is in the news cycle right now).

Under the current legislation, they can be sued by each regulator in each country separately (this has happened to them multiple times). Under the GDPR, they will mostly be sued by just the Irish Data Protection Authority (other EU regulators will funnel issues to the Irish DPA first).

kenbaylor··on EU GDPR – Another reason for SaaS to reconsider on-premise
This is a key reason why there are data protection officers under GDPR. They report to the highest level of management (mostly the board) and are independent. They are also called mini-regulators. They ensure the company is compliant.

If they are not doing their job, (and you are not content with their reply), you then appeal to the Data Protection Authority (DPA, Privacy Regulator in the country). The DPA has full powers of subpoena (and a whole lot more), and are not to be trifled with.

kenbaylor··on EU GDPR – Another reason for SaaS to reconsider on-premise
For any company that is compliant with GDPR (after 25th May 2018), the answers your 4 questions (2 on data collection, other 2 on data subject rights) must already be in their privacy notice on their website, with instructions for how to contact their data protection officer.
kenbaylor··on Guccifer 2.0 Slipped Up and Revealed He Was a Russian Intelligence Officer
Something like this?

"“With UMBRAGE and related projects the CIA cannot only increase its total number of attack types, but also misdirect attribution by leaving behind the ‘fingerprints’ of the groups that the attack techniques were stolen from,” Wikileaks said in a statement."

https://www.usatoday.com/story/news/2017/03/07/wikileaks-cia...

and for remote control:

"In April this year, WikiLeaks disclosed a brief information about Project Hive, revealing that the project is an advanced command-and-control server (malware control system) that communicates with malware to send commands to execute specific tasks on the targets and receive exfiltrated information from the target machines. Hive is a multi-user all-in-one system that can be used by multiple CIA operators to remotely control multiple malware implants used in different operations."

https://thehackernews.com/2017/11/cia-hive-malware-code.html

kenbaylor··on Guccifer 2.0 Slipped Up and Revealed He Was a Russian Intelligence Officer
Hopefully I addressed it in the section above.

I believe that intelligence agencies are targeted all the time, and keeping machines clean is not that easy. Certain governments (like Singapore) adopted an air-gap approach, so the machines you use for work don't touch the internet.

But even then, it would be a lot easier to infect that persons's home machine.....Many of the people visiting Guccifers site were normal people, some were from intelligence agencies (proportionally probably a lot more than visit a normal site).

Assuming you had AWESOME undetectable malware, you'd have to infect the lot, get them to report in, and ferret out the interesting ones. Not exactly a weekend project, but if this was your passion in life, very achievable.

Spear phishing these guys is hard, watering hole may be easier.

kenbaylor··on Guccifer 2.0 Slipped Up and Revealed He Was a Russian Intelligence Officer
Great question: Apologies if I wasn't being clear.

For example: the Chinese government has been waging war against the Free Tibet movement for years: https://www.google.com.sg/search?q=chinese+malware+free+tibe...

There's a bunch of articles there. One technique is they put up a pro-Free Tibet site, and put malware on it. The visitors get infected and they have an insight into who is interested in that topic and their IP addresses for basic geo location, and maybe remote control of their machines.

If we pick a topic that's super interesting for government intelligence people (like the Guccifer blog site itself), and put some awesome non-detectable malware on there, you could potentially infect multiple intelligence officers from multiple countries.

When the bots phone home, they will report username, domain name, email addresses, visited URLs, security certificates (or basically anything you want). So you now have a rolodex of machines you can manipulate. Mossad did it...nope....North Korea....nope CIA...nope FBI etc etc

Now this is super hard to do in practice. But you only have to be lucky once.

kenbaylor··on Guccifer 2.0 Slipped Up and Revealed He Was a Russian Intelligence Officer
Here you go....from my 2012 Blackhat presentation. It then shows the issues of attribution as everything comes from the infected machine...sorry it's dated but nothing has really changed

https://www.youtube.com/watch?v=XvoiI5gJ7-0

kenbaylor··on Guccifer 2.0 Slipped Up and Revealed He Was a Russian Intelligence Officer
It's called a watering hole attack. You infect many of the devices way ahead of time (that are interested in whatever subject area you targeted), and pick your victim when you need to. If you haven't prosecuted these cases, you'd be surprised how often it happens:

https://www.cyberscoop.com/winter-olympics-hack-attribution-...

https://krebsonsecurity.com/2017/08/blowing-the-whistle-on-b...

https://blog.trendmicro.com/trendlabs-security-intelligence/...

https://blog.talosintelligence.com/2018/02/who-wasnt-respons...

kenbaylor··on Guccifer 2.0 Slipped Up and Revealed He Was a Russian Intelligence Officer
It really is super easy. Even since 2007, malware like Zeus and SpyEye, and a million different Remote Access Tools (RATs) take over your machine and allow all activity to emanate from it. Very easy to plant a false flag or incriminating evidence.

and please note the careful wording: "Working off the IP address, U.S. investigators identified Guccifer 2.0 as a particular GRU officer working out of the agency’s headquarters on Grizodubovoy Street in Moscow. "

interpretation 1: The guy accessed the device from his GRU office

Interpretation 2: The IP belongs to a guy (maybe his residential connection), and he happens (from other sources) to work at the GRU office. Assuming the GRU device is relatively secure, is it possible that other devices on his home have malware on them? If the latter, all the devices would appear as coming from that same residential IP address.

I work in this field and false attribution happens all the time. Evidence is really easy to fake.

kenbaylor··on The Nightmare Letter: A Subject Access Request Under GDPR
Each country will have a Data Protection Authority (DPA) which is the regulator in the country. The ICO is the one in the UK.

The last letter of the GDPR is Regulation. A regulation is very different than than a Directive (the pre-GDPR law is based on a directive). There is very little wiggle-room with a Regulation, even between countries. The ICO also works with other DPAs currently as part of Working Party 29, which ensures the DPAs are working in Sync.

So the ICO advice is worthy of close study, especially if your local DPA (assuming you have one) has not commented or given guidance on a certain matter.

kenbaylor··on The Nightmare Letter: A Subject Access Request Under GDPR
The reason why this is such a great letter is because it questions the competence of the recipient DPO. The data subject has a right to some of the information, but by no means all of it.

If the DPO complies with all of it, they will breach the GDPR (e.g. Request 9b). Of course a data subject also has no right to know what security controls (request 8) you have in place, other than they are 'commercially reasonable'.

A regulator can require this information, but not a consumer (data subject). This could be the basis of a great interview test for selecting your DPO.

kenbaylor··on The Nightmare Letter: A Subject Access Request Under GDPR
You can ask, but the recipient company does not have to comply. The tax authorities have a legal obligation to keep the data, and they will. Reference: https://ico.org.uk/for-organisations/guide-to-the-general-da...
kenbaylor··on How the Irish Teach Us to Die
Thoroughly agree. Ireland has many accents, many of them very strong. This is common in cultures where people stay in a locality for most of their lives. There is recent mobility (in the last 50 years for work, education etc) but most families have been stationary in their home towns for multiple generations. Even the Irish spoken in each area is distinctive.
Page 1 of 3Next →