Consolidated Running Online Privacy/Social Media Issues thread

Started by bayonetbrant, March 25, 2018, 02:55:45 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

mirth

Quote from: airboy on April 12, 2018, 07:43:22 AM
But hey, the big social media companies are "content neutral" right?  While they sell all your information.

Sure. Just like the big ISPs.
"45 minutes of pooping Tribbles being juggled by a drunken Horta would be better than Season 1 of TNG." - SirAndrewD

"you don't look at the mantelpiece when you're poking the fire" - Bawb

"Can't 'un' until you 'pre', son." - Gus


Barthheart

Quote from: mirth on April 12, 2018, 08:02:36 AM
Quote from: airboy on April 12, 2018, 07:43:22 AM
But hey, the big social media companies are "content neutral" right?  While they sell all your information.

Sure. Just like the big ISPs.

And why would think they had to be neutral...

mirth

"45 minutes of pooping Tribbles being juggled by a drunken Horta would be better than Season 1 of TNG." - SirAndrewD

"you don't look at the mantelpiece when you're poking the fire" - Bawb

"Can't 'un' until you 'pre', son." - Gus


mirth

"45 minutes of pooping Tribbles being juggled by a drunken Horta would be better than Season 1 of TNG." - SirAndrewD

"you don't look at the mantelpiece when you're poking the fire" - Bawb

"Can't 'un' until you 'pre', son." - Gus

Pete Dero

And we tried to stop them in court : https://www.theregister.co.uk/2018/02/16/facebook_told_to_stop_tracking_belgian_folks_or_face_fines_of_250000_a_day/

Facebook's answer : if you are not a facebook user you no longer have access to facebook pages (full page popups asking you to register appear).

Barthheart


Staggerwing

Vituð ér enn - eða hvat?  -Voluspa

Nothing really rocks and nothing really rolls and nothing's ever worth the cost...

"Don't you look at me that way..." -the Abyss
 
'When searching for a meaningful embrace, sometimes my self respect took second place' -Iggy Pop, Cry for Love

... this will go down on your permanent record... -the Violent Femmes, 'Kiss Off'-

"I'm not just anyone, I'm not just anyone-
I got my time machine, got my 'electronic dream!"
-Sonic Reducer, -Dead Boys

JasonPratt

https://www.the-parallax.com/2018/04/05/deletefacebook-7-steps-delete-facebook/

Haven't done it yet because I don't particularly care (or not yet -- I think it's amusing they consider me "very conservative". When they shadowban me, that'll change.  :knuppel2: I'm not remotely even distantly that important tho.)

Still, worth comparing to other delete FB checklists.
ICEBREAKER THESIS CHRONOLOGY! -- Victor Suvorov's Stalin Grand Strategy theory, in lots and lots of chronological order...
Dawn of Armageddon -- narrative AAR for Dawn of War: Soulstorm: Ultimate Apocalypse
Survive Harder! -- Two season narrative AAR, an Amazon Blood Bowl career.
PanzOrc Corpz Generals -- Fantasy Wars narrative AAR, half a combined campaign.
Khazâd du-bekâr! -- narrative dwarf AAR for LotR BfME2 RotWK campaign.
RobO Q Campaign Generator -- archived classic CMBB/CMAK tool!

mirth

"45 minutes of pooping Tribbles being juggled by a drunken Horta would be better than Season 1 of TNG." - SirAndrewD

"you don't look at the mantelpiece when you're poking the fire" - Bawb

"Can't 'un' until you 'pre', son." - Gus

mirth

"45 minutes of pooping Tribbles being juggled by a drunken Horta would be better than Season 1 of TNG." - SirAndrewD

"you don't look at the mantelpiece when you're poking the fire" - Bawb

"Can't 'un' until you 'pre', son." - Gus

jamus34

In a similar vein the company I work for has announced new "well being programs" basically involving them doing "wellness testing" and if you are considered in "good health" you can "save some money on your insurance"

I am using the air quotes because if you are a smoker they will automatically tack on $5 weekly to your benefit costs and you can "opt out" at a cost of $10 per week.

Now, this is beyond insulting already, and  the part that really kills me (and is pertinent to this conversation) is that this is all handled by a third party company. Guaranteed they will be selling you personal information out.



Guess we are just getting one step closer to having a chip in everyone.
Insert witty comment here.

bayonetbrant

Encryption & Privacy

https://www.eff.org/deeplinks/2018/05/bring-nerds-eff-introduces-actual-encryption-experts-us-senate-staff

Quote
Earlier today in the U.S. Capitol Visitor Center, EFF convened a closed-door briefing for Senate staff about the realities of device encryption. While policymakers hear frequently from the FBI and the Department of Justice about the dangers of encryption and the so-called Going Dark problem, they very rarely hear from actual engineers, cryptographers, and computer scientists. Indeed, the usual suspects testifying before Congress on encryption are nearly the antithesis of technical experts.

The all-star lineup of panelists included Dr. Matt Blaze, professor of computer science at the University of Pennsylvania, Dr. Susan Landau, professor of cybersecurity and policy at Tufts University; Erik Neuenschwander, Apple's manager of user privacy; and EFF's tech policy director Dr. Jeremy Gillula.

The discussion focused on renewed calls by the FBI and DOJ to create mechanisms to enable "exceptional access" to encrypted devices. EFF's legislative analyst India McKinney opened the briefing by assuring staff that the goal of the panel was not to attack the FBI's proposals from the perspective of policy or ideology. Instead, our goal was to give a technical description of how device encryption actually works and answer staff questions about the risks that exceptional access mechanisms necessarily introduce into the ecosystem.

Dr. Blaze framed his remarks around what he called an undeniable "cybersecurity crisis" gripping the critical information systems we all rely on. Failures and data breaches are a daily occurrence that only come to the public's attention when they reach the catastrophic scale of the Equifax breach. As Blaze pointed out, "security is hard," and the presence of bugs and unintended behavior in software is one of the oldest and most fundamental problems in computer science. These issues only become more intense as systems get complex, giving rise to an "arms race" between those who find and fix vulnerabilities in software and those who exploit them.

According to Blaze, the one bright spot is the increasing deployment of encryption to protect sensitive data, but these encryption mechanisms remain "fragile." Implementing encryption at scale remains an incredibly complex engineering task. Blaze said that computer scientists "barely have their heads above water;" and proposals that would mandate law enforcement access to encrypted data would effectively take away one of the very few tools for managing the security of infrastructure that our country has come to depend on. These proposals make the system more complex and drastically increase the surface for outside attackers.

Blaze noted the CLEAR key escrow system put forth by former Microsoft CTO Ray Ozzie recently written up in Wired only covers a cryptographic protocol—"the easy part"—which itself has already been demonstrated to be flawed. Even if those flaws could be satisfactorily addressed, it would still leave the enormous difficulty of developing and implementing it in complex systems. Surmounting these challenges, Blaze said, would require a breakthrough so momentous that would it lead to the creation of a Nobel Prize in computer science just so it could be adequately recognized.

Professor Landau began her remarks by pointing out that this was not at all a new debate. And she noted that Professor Blaze was one of the technical experts who broke the NSA's Clipper Chip proposal of the 1990s. And key escrow, as it was described by the Clipper Chip, really isn't much different from modern calls for extraordinary access. Turning to the most current key escrow proposal, Ozzie's CLEAR, Professor Landau noted that the way crypto algorithms get built is by exhaustive peer review. However, CLEAR had its most public presentation in Wired Magazine and has yet to be subjected to rigorous peer review, even though only a tiny portion of the systems problem that "exceptional access" presents are actually addressed by CLEAR, and the proposal has already been found to have a flaw.

Professor Landau concluded by noting that the National Academies of Sciences study showed that the very first two questions that we need to ask about an "extraordinary access" mechanism are: does it work at scale, and what security risks does it impose. The FBI has steadfastly ignored both those problems.

"We're not looking at privacy versus security. Instead, we're looking at efficiency of law enforcement investigations versus security, and there are other ways of improving the efficiency of investigations without harming security," Landau said. "Complexity is the enemy of security. If you want a phone that's unlockable by any government, you might as well not lock the phone in the first place."

Apple's Neuenschwander presented an on-the-ground look at how Apple weighs tradeoffs between functionality and user privacy. In the case of encryption of iPhones, he echoed the concerns raised by both Blaze and Landau about the complexity of implementing secure systems, noting that Apple must continually work to improve security as attackers become more sophisticated. As a result, Apple determined that the best—and only—way to secure user data was to simply take itself out of the equation by not maintaining control of any device encryption keys. By contrast, if Apple were to have a store of keys to decrypt users' phones, that vault would immediately become a massive target, no matter what precautions Apple took to protect it. Though the days of the Wild West are long gone, Neuenschwander pointed out that bank robberies remain quite prevalent, 4,200 in 2016 alone. Why? Because that's where the money is. All exceptional access proposals would take Apple from a regime of storing zero device encryption keys to holding many and making itself ripe for digital bank robbery.

EFF's Dr. Gillula spoke last. He opened by explaining that getting encryption right is hard. Really hard. That's not because cryptographers spend years working on a particular cryptographic mechanism and succeeding. Rather they spend years and years on working systems that other cryptographers are able to break in mere minutes. Sometimes those flaws are in the encryption algorithm, but much more often in the engineering implementation of that algorithm.

And that's what companies like Cellebrite and Grayshift do. They sell devices that break device security—not by breaking the encryption on the device—but by finding flaws in implementation. Indeed, there are commercial tools available that can break into every phone on the market today. The recent OIG report acknowledged exactly that: there were elements within the FBI that knew that there were options other than forcing Apple to build an exceptional access system.

In conclusion, Gillula noted that in the cat-and-mouse game that is computer security, mandating exceptional access would freeze the defenders' state of the art, while allowing attackers to progress without limit.

We were impressed by the questions the Senate staffers asked and by their high level of engagement. Despite the fact that we've entered the third decade of the "Crypto Wars," this appears to be a debate that's not going away any time soon. But we were glad for the opportunity to bring such powerful panel of experts to give Senate staff the unfiltered technical lowdown on encryption.
The key to surviving this site is to not say something which ends up as someone's tag line - Steelgrave

"their citizens (all of them counted as such) glorified their mythology of 'rights'...and lost track of their duties. No nation, so constituted, can endure." Robert Heinlein, Starship Troopers

mirth

"45 minutes of pooping Tribbles being juggled by a drunken Horta would be better than Season 1 of TNG." - SirAndrewD

"you don't look at the mantelpiece when you're poking the fire" - Bawb

"Can't 'un' until you 'pre', son." - Gus