Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Wednesday, April 13, 2016

They Just Don't Get It (Or: Magical-Thinking Strikes Again)

Earlier this week, I wrote to my state Senators to express my disapproval of the forthcoming Burr-Feinstein encryption bill. Today, I got back a form response ...not that I was expecting a personal response - it's not like I'm a million-dollar donor:
Dear Mr. Jones,
     Thank you for contacting me regarding digital security and encryption policy. I appreciate hearing your views on this complex subject, which involves multiple competing security interests.

     While the debate over government access to encrypted communications has long been a contentious subject, the issue has received increased attention and scrutiny in the wake of the terrorist attacks in Paris and San Bernardino and, more recently, the ongoing legal battle between Apple Inc. and the Federal Bureau of Investigation (FBI) over access to the iPhone of one of the alleged perpetrators of the terrorist attack in San Bernardino, California. As these attacks showed us, terrorists have become increasingly sophisticated in their use of technology. Social media platforms have become prominent tools for recruitment and radicalization. And when individuals show interest in terrorists' cause, they move their communications to encrypted applications and other secure platforms to evade detection. This presents an extraordinary security challenge for the United States and our allies, leading to warnings by law enforcement officials that conventional tools to track and apprehend these criminals have become increasingly ineffective.

     Frustratingly, there are no easy answers. The same tools that terrorists and criminals are using to hide their nefarious activities are those that everyday Americans rely on to safely shop online, communicate with friends and family, and run their businesses. On top of that, technological innovation changes rapidly and, frequently, beyond the reach of U.S. law. Thousands of new apps are submitted to mobile apps stores daily, most of them utilizing some level of encryption, and a majority of them are developed overseas. Moreover, the fundamental architecture of the Internet is a decentralized and resilient one.

     In order to better understand the issues we're facing and explore potential solutions, Rep. Michael McCaul (R-TX), Chairman of the House Homeland Security Committee, and I introduced S.2604/H.R. 4651, the Digital Security Commission Act of 2016 on February 29, 2016. This legislation would create a national commission on security and technology challenges in the digital age. The Commission would convene a body of experts representing all of the interests at stake so we can evaluate and improve America's security posture as technology — and our adversaries — evolve.

     Our proposal will convene the brightest minds from the technology sector, the legal world, computer science and cryptography, academia, civil liberties and privacy advocates, law enforcement and intelligence to collaboratively explore the intersection of technology and security.

     This would not be a group of politicians debating one another. Nor would the commission be like other blue-ribbon panels, quickly established but soon forgotten. Rather, it would be charged with generating much-needed data and developing a range of actionable recommendations that can protect privacy and public safety. That is why this commission has been endorsed by a wide range of stakeholders – from the technology sector, to respected academic and legal experts, and distinguished national security figures.

     The threats we face with regards to digital security are real. They will not be met easily or dispensed with quickly. But I have no doubt that we are capable of overcoming these challenges if we convene the brightest minds in our country and work together.

     Again, thank you for contacting me. For further information or to sign up for my newsletter please visit my website at http://www.warner.senate.gov.

Sincerely,
MARK R. WARNER
United States Senator
So, while the form-mail isn't saying "I plan to vote for this (Burr-Feinstein) important bill", the text really isn't any less disturbing.

The "best minds" thing, by itself is disturbing. The "best minds" have already very publicly told you that what's being asked for isn't possible. Or, more specifically/technically-correct - it's not possible to both make encrypted data accessible to law enforcement without also making it as easily accessible to entities seeking illegal access. But never mind that, they're apparently just not trying hard enough! Technology is fucking magic and if one bit of magic is possible, any given bit of magic is possible if we just wish hard enough.

Even better is the farce of "we'll get a group of all the stakeholders together to work on this." There have been many such "gatherings of stakeholders to solve a difficult problem" exercises. Usually, the way it works out is that the differences between the stakeholders are irreconcilable. Then, the process either completely falls apart or the stakeholders who just aren't trying hard enough are dropped from the process or otherwise ignored. Only one outcome is acceptable - soundness of that outcome be damned.

So, with all due respect, Mr. Warner (or whichever drone you had compose this steaming pile of response), you're a completely clueless fucking tool. You are not worthy of being in a position to make decisions that affect the security of my personal data. You are not worthy of being voted for.

Sunday, November 28, 2010

Am I Too Skeptical

I am a StumbleUpon user. It's an unbelievably efficient time-suck. Any time you press that Stumble! button, you get taken to some random page that, four times out of five, appeals to you. Granted there's a crapton of junk. And, sometimes the things you get, you're not really sure "what interest did I click that I got this page??"

I think, somewhere, I must have clicked some mislabled "conspiracy theory" interest button. Frequently, I get Stumbles that are purportedly factual, but, if you question the content, there's little corroborating content available. And, no, I don't consider other unknown/fringe sources to be either reliable or corroborating.

Yesterday, I stumbled a Mashable article about DHS/ICE supposedly seizing a bunch of piracy-oriented web sites. The content of the article struck me as odd, because, the last I'd heard from sources like EFF (and similar sites), COICA had not been passed by the last Congress or Senate, nor had it made it to Obama's desk for signing. It was my understanding that COICA was being formulated because the federal government currently couldn't act as the various IP-holders' (RIAA, MPAA, etc.) proxy as they'd never been delegated the power.

The Mashable article did reference a NY Times article, but that was the closest to a "known" news site I could find. The rest were various left-field sites whose coverage consisted mostly of quoting the Mashable and NY Times articles (and with miles-long "comments" sections). I've yet to see anything from EFF - at their website, via their FaceBook group or even their Twitter feed - on the subject. I've not even seen anything posted, yet, by Declan McCullagh. Both sources tend to be pretty on top of and vocal about news stories in this vein.

Absent the other usual suspects' mention, I became suspicious. I mean, while the TSA and other organizations frequently trample on the 4th Amendment, they at least try to make it look like they aren't. And, when they do, EFF, ACLU and other organizations are generally pretty vocal and public with their opposition. Secondly, governmental seizures are usually the domain of the DoJ and FBI, not DHS and certainly not ICE. DHS is usually "terrorism" oriented and ICE is generally immigration oriented. Piracy-enabling websites wouldn't really seem to logically fall under either of those domains.So, I started digging.

First of all, the sites that were supposedly taken down by ICE are all redirected to seizedservers.com. This seems odd, to me. I mean, if these were truly the result of governmental actions, wouldn't they have redirected to seizedservers.GOV, instead. So, I poked about a bit more.

I did an IP lookup on the seizedservers.com web site. Using `nslookup`, I found that the IP associated with that site was "74.81.170.109". Next, I queried the ARIN to see who owned that IP address. The results indicated that the IP address was owned by a Carolina-based ISP.

Curiouser and curiouser: why would the IP be owned by a Charlotte-area ISP rather than some government agency. I mean, it's not like the Federal government's short on IP addresses they could delegate to DHS or ICE. After all, both Senate.Gov and House.Gov are run off of Federal IP ranges. And, yes, I get that many of the Federal government's public webhosting is done through external providers (I used to work for a site that hosted USPS's stuff). However, most of the sites I've done lookups against that are externally hosted, seem to be hosted by Akamai, these days. For example, both the White House and the main DHS web site seemed to be hosted by them. ICE, as a sub-department of DHS would, logically, have similar hosting arrangements. 

Lastly, seizedservers.com was only registered on November 24th of this year and just days prior to the supposed domain seizures. I've done a lot of work with governmental groups over the years. None of them go from "just registered" to actively working in less than a week (usually, you're talking months, quarters or even years).

I realize I could easily be wrong, but none of it seems to "add up". To me, it looks more like it's either a hoax to get the file-sharing community up in arms or that the sites got their domains stolen (by "hackers", not the US government). Can anyone provide definitive proof that this is "for real". It seems like a pretty big story for the mainstream news outlets and the various rights and privacy groups to be asleep at the wheel on.

Friday, November 19, 2010

Do Poll-Quoters Even Understand the Polls They Quote?

Ok, so, I've now seen references to two different polls that claim to support the TSA's enhanced pat-downs. One is the one that the TSA cites in their blog and one was one cited in the LA Time's news blog. In both cases, the people claiming the polls support their view didn't seem to actually read how the polls were structured.

The poll cited by the TSA in their blogs was what statisticians would refer to as a "non-representative sample". The poll was a random sampling of the population-at-large. It was not a sampling of the traveling-population. In other words, the sample population could be be heavily skewed towards respondents not directly effected by the new policies. If the TSA wanted to be more convincing, they'd have polled actual travelers - particularly frequent-travelers. Then there might be something resembling validity in the results.

The poll cited in the LA Time's news blog uses the misleading claim of "travel professionals". It's used in a way to make the un-careful reader think they're referring to people that fly, on a frequent basis, as part of their job. However, if one bothers to read rather than just skimming (or even just taking a headline at face value), one discovers that the "travel professionals" polled were the people making travel arrangements. It wasn't a poll of people that use those travel arrangements. Much like the poll cited by the TSA, it's not a poll of those directly impacted by the TSA policies.

Unfortunately, there's far too many people out there who take things at face value. There's far too many skimmers. There's far too many "headlines-only" readers. Simply put, there's too many people that are simply lazy in how they choose to inform themselves. News organizations, corporations and anyone in the spin business knows this and take advantage of it.

Friday, November 12, 2010

Alternative Screening Methods

So, the fascists at TSA are trying to push the use of the backscatter scanners by making them the lesser of two evils. Basically, they've instructed their hoards of Barney Fifes to go so far down the path of invasiveness with their pat-downs as to qualify for sexual assault in any other context. They've done this to make the alternative to being scanned even more embarrassing and annoying than being run through the backscatter scanners.

I wonder, though: were I to wear a rubber gimp-suit to go through TSA screening, would they still need to grope or scan me? I mean, it's not like I'd be able to hide anything under such attire. With those things, can tell just how fit you are, just how hung you are ...hell, they can practically tell what your religion is. Certainly, there's no possibility of hiding a pack of sugar, let alone contraband or explosives.

But, it's not about that, really, is it? It's about showing the little people who's in power and that they're helpless to do anything about it.

Monday, October 25, 2010

Opt-Out

Not sure how much faith I place in it, but NAI's website/tool supposedly allows you to opt out of targeted adverts.

Monday, September 13, 2010

What I Want in My Next Cell Phone

Ok, I'm not quite a conspiracy nut, but, I do like my privacy. I want to know that, if I choose to store sensitive things on my cell phone - either in its memory or on an inserted memory card - I can know that the data is safe. I want it safe from pranksters. I want it safe from device thieves. I want it safe from curious law enforcement types that don't have a properly executed warrant. Given the litany of headlines, I think that I'm probably in greatest danger from "legal" abuse of my privacy than I am from people that don't have a badge.

A number of phones have the ability to remote-wipe data. Some phones also have the ability to set it up such that, if someone fails to guess the password some configurable number of times, the phone will auto-nuke. However, I haven't really seen any phone makers addressing the issue of someone simply ganking the memory card from your phone and reading it in another device. For that, you need to protect the data on the memory card, itself. Two possible options for that seem workable: encryption of the entire SD card (or a "partition" on it) using a cross-platform filesystem (e.g., ECryptFS); individual encryption of each file stored on the card (preferably including the ability to set this as the default storage option).

I'd also like to see a phone that I can use as a pure data device. At this stage of the game, it seems kind of pointless for smart phones to require a voice plan. Given a sufficiently sized data plan, a cell device with a good, native SIP application would obviate the need for a voice plan. It's all just data, any way. Why not go the next logical step. Hell, some carriers already give you the ability to use Skype, but it's typically crippled to prevent its use for "local calls". Other than to protect the voice-plan model, what the fuck is the point of that?

As a bonus of going "data-only", if the person I'm talking to and I are both using SIP devices, we can encrypt the channel if we want to. I'm sure there's plenty of businesses out there that would appreciate the corporate espionage deterrent such a capability would offer. Would also be nice to know that some info-thief out there can't just crack the local cell tower and sniff "interesting conversations." In the end, it's not that I have anything to hide, but it is the principle of things. It was always my understanding that privacy - the right to be secure in ones own possessions, property and communications - was one of the founding principals of my country. Reading headlines, lately, seems to indicate that, unless one goes to extra lengths to assert a desire for privacy, we no longer have "a reasonable expectation of privacy" when we participate in technology.

There's also some things that I don't really want in my next phone. When people know you have certain capabilities - whether you want to use them or not - there easily becomes the expectation that you'll use them. My phone is for my benefit. If it benefits others, that's nice, but it ain't why I'm buying myself a piece of technology.

For starters, I don't need to have two cameras or a video-phone application on my phone. The idea - and even the ability - to have video phones has been around for a long time. It's never taken off. I'd wager that a significant reason for this not happening, previously, is, in large part, due to the fact that, often times, it's nice to NOT have to worry what you look like when you're taking a phone call. You can be damned sure that if you wake my happy ass up at oh-dark-thirty, I ain't going to want to have a video chat. Fuck that. If I really want to face-time with you, I'll go to my computer and fire up Skype (or similar). Even better, I'll figure out where we can meet and talk face-to-face. Just assume that if I ain't standing in front of you, it's because I don't want a face-to-face (I'm not really a fan of the formal video teleconferencing stuff at work, either, so...). And, if I do, but geography's the issue, figure that I'll find some way that doesn't involve my handset. Besides, given the screen size on a practical handset, it's not like I'm going to be doing presentations. So, why have it and the expectation of its use?

I also don't really need the ability to stream or watch video. I have a widescreen HD TV in my living room for a reason: I like to actually be able to see things. Watching movies on a screen smaller than the display on my car's GPS just seems stupid.

Streaming music is one of those "iffy" things. As a stand-alone device, cell phones eat batteries quickly enough. Add in trying to treat it as a music outlet, and that battery's gonna die quick. I don't particularly want to not have my phone usable because I killed the batteries on music. It's part of why, when I was traveling and wanted music, I carried a cellphone and a music device, even though my phone had room for several GB of music. That said, it could be useful in my car: I could have the phone in a charger-dock, obviating the need for things like Sirius/XM and I wouldn't have to subject myself to the audio-crime that is broadcast radio.

Meh... In some ways, it seems like cell phones are becoming like office productivity software. There's really only so much useful stuff you can add to something before it becomes pointless featurism (this was always why I was a vi guy and not an EMACS guy). I can see the value of a lot of the convergence stuff, but I just don't get the utter lack of the personal security/privacy components.