Live data from Hacker News

The privacy wars are about to get a whole lot worse

locusmag.com

121–130 of 170 posts

Re: The privacy wars are about to get a whole lot worse

#121

Earlier quoted context omitted.

> Companies can still track me, my data's still out there. I don' think this is right. When you were being a "luddite" you probably had less data collected about you, but you couldn't see that. All you can see is the cool tech stuff you are missing out on, so you feel that keenly. I think the reason a lot of people give up their privacy is that they feel like they have lost it already, so they might as well "Get what…

Yes, I think this is right. I have very privacy-conscious tech habits, and companies have some data on me, but probably far less than on the typical user of modern services. Some ways I protect myself: 1. Google account - I have one because it's required for Android, but I have never used Gmail, do not search from my Google account or ever log into it from my browser. 2. Facebook or any subsidiaries - never. 3. Gener…

It's such an uphill battle, though. There are many clever ways you can be tied across websites.

Unless you are using some sort of VPN or proxy that's constantly changing your IP as you're browsing, and a browser that consistently changes or masks fingerprintable information and wipes all persistent tracking beacons, then what you're doing is not even remotely sufficient to evade tracking by any entity. What you're doing is definitely not enough to avoid Google or Facebook.

At this time I believe nothing can do this with 100% effectiveness. The closest would be to use Tor Browser and never disable NoScript and only use sites that don't rely on JS... but even then there are many theoretical workarounds, many more to come in the future, and probably various unknown techniques currently being tested or deployed.

I know enough about the technology to realize it saves me a lot of time, effort, and stress to just accept my fate. I no longer include ad networks or big tech companies in my personal threat model, even though I dislike what they're doing.

Re: The privacy wars are about to get a whole lot worse

#122

Earlier quoted context omitted.

There's a famous saying along the lines of "If you are rich, hire two accountants. One to keep track of your books, and another to keep track of the first guy" If you provide sensitive information to anyone that you don't have legal recourse against, then I don't really have any sympathy for you. If you make a bad business decision and it leaks my info, I'm not upset because someone took it without your approval, I'm…

"If you are rich, hire two accountants. One to keep track of your books, and another to keep track of the first guy" Brilliant, I hadnt heard of/thought of that. "There's a cost/benefit risk to everything. If you want to take the route of working with contractors, you have to weight the risks for that as well." True, I would just like to point out that hiring your own staff might no work out either...

Oh absolutely. The other side isn't necessarily better, it just comes with a different set of risks/costs/benefits. You have to weigh those against each other to see which makes more sense for your situation.

But if you take the less safe/secure option, you can't expect much sympathy.

Re: The privacy wars are about to get a whole lot worse

#123
post #120

Earlier quoted context omitted.

"I think in this case the credit card companies should be liable." Maybe? I didnt see anything about home depot suing the contractors? Really, they should be held financially and criminally liable.(if they werent) The public ledger part of bitcoin is great also. You can see where the stolen money went. Maybe if they added a way to flag money, so spending stolen bitcoin would trigger an alert at the merchant, the same…

re: the contractors being liable, currently the way things work is, when my credit card is used fraudulently the credit card company owns that and pays me back, which is the least they could do. I don't even know if they attempt to work with law enforcement to catch the actual fraudsters, but I sure hope they do. Maybe I should be more proactive about that? I don't know. EDIT: I should point out I don't know any deta…

I guess the details are still not known? I was confused by the target hack in my earlier comment(sorry). That was where hvac contractors had their credentials stolen, and malware was installed on their pos system. The home depot hack was malware suspected to have been installed on their self checkout machines[1].

" it shouldn't be the customers who suffer when this happens. The people that made it so easy for my personal information to leak, the ones who necessitated that my personal information even be required as part of the transaction, should be the ones feeling the pain"

I get what you mean about some services collecting everything they can, and not taking the best possible care of it. I agree with you there. I was trying to point out an exception where there isnt anything that can be done. For example, try and stop finfisher :)[2] Companies will get hacked, and it is not always negligence. I was trying to point out that you wouldn't blame a shopkeeper if an armed robber stole credit card info, but if he left it in an unlocked room then we should. And I dont think either home depot or target were collecting more than they needed to.

PS, if anyone has a link as to how we can be more proactive about working with law enforcement to catch the fraudsters, I would love to see it. Either from the point of view of a consumer, or service provider.

1. http://krebsonsecurity.com/2014/09/home-depot-56m-cards-impa...

2. http://news.softpedia.com/news/finfisher-s-account-of-how-he...

Re: The privacy wars are about to get a whole lot worse

#124
post #22

I'm waiting to see if this gets traction on HN. In case it doesn't, and so I can propose something only to the few who dig to the bottom of the comments: The problem is social. A technological solution will not suffice.

The problem is trust. Technological solutions exist that embody trust. People must trust technological solutions through social means...a type of prisoner's dilemma if there ever was one.

Re: The privacy wars are about to get a whole lot worse

#125

> Eventually, some lawyer is going to convince a judge that, say, 1% the victims of a deep-pocketed company’s breach will end up losing their houses to identity thieves as a result of the data that the company has leaked, and that the damages should be equal to 1% of all the property owned by a 53 million (or 500 million!) customers whom the company has wronged. It will take down a Fortune 100 company, and transfer b…

"They're portraying the negligent company as the victim!" While I agree that things like sql injection are negligent, there were also credit card hacks/leaks(and an nsa leak) that were the result of malicious contractors. Saying "dont hire bad people" is easy, but how do you do that? And the standard for best practices is constantly moving in our industry, how do we decide when it is negligence, and when there was no…

> there were also credit card hacks/leaks(and an nsa leak) that were the result of malicious contractors.

Wouldn't the negligence just be that they had access to the unencrypted credit card numbers?

Re: The privacy wars are about to get a whole lot worse

#126
post #116

Earlier quoted context omitted.

In the specific hacks I was thinking of, they didnt hoard and store any info. Equipment was installed that siphoned credit card info from their payment systems. I cant think of a way to run a store without passing credit card info through your payment processing system to the banks.

Agreed, credit cards are a ridiculous necessity. I think in this case the credit card companies should be liable. I am continually amazed by the simple solution bitcoin provides to this problem: instead of me giving you an account number that you (or anyone who gets the number) pull(s) money from, you give me a number that I push money to. It's going to be a long time before that kind of change in our payment systems…

> It's going to be a long time before that kind of change in our payment systems can be widely implemented.

That's how bank transfers work, though.

Re: The privacy wars are about to get a whole lot worse

#127
post #125

Earlier quoted context omitted.

"They're portraying the negligent company as the victim!" While I agree that things like sql injection are negligent, there were also credit card hacks/leaks(and an nsa leak) that were the result of malicious contractors. Saying "dont hire bad people" is easy, but how do you do that? And the standard for best practices is constantly moving in our industry, how do we decide when it is negligence, and when there was no…

> there were also credit card hacks/leaks(and an nsa leak) that were the result of malicious contractors. Wouldn't the negligence just be that they had access to the unencrypted credit card numbers?

Ok, so I was confusing the home depot hack mentioned in the article with the target hack, but I dont want to edit my comment after so much discussion. I also want to point out that i was trying to show an exception, not to say that noone should ever be held accountable for a breach.

In the target hack, hvac contractors had their credentials stolen, and malware was installed on their pos system. The home depot hack was malware suspected to have been installed on their self checkout machines[1].

So no, they never allowed anyone access to the unencrypted credit card numbers. Negligence is failure to exercise reasonable care.[2] Bad things happen, and even more so when sophisticated criminals are attacking you. It is impossible to create a fully hack proof system. I would say allowing a sql injection is negligence, but when people are using sohpisticated attacks, there is nothing you can do.

1. http://krebsonsecurity.com/2014/09/home-depot-56m-cards-impa...

2. https://en.wikipedia.org/wiki/Negligence

Re: The privacy wars are about to get a whole lot worse

#128

Earlier quoted context omitted.

"They're portraying the negligent company as the victim!" While I agree that things like sql injection are negligent, there were also credit card hacks/leaks(and an nsa leak) that were the result of malicious contractors. Saying "dont hire bad people" is easy, but how do you do that? And the standard for best practices is constantly moving in our industry, how do we decide when it is negligence, and when there was no…

> How do we decide when it is negligence, and when there was nothing that could be done? This isn't an insoluble issue: courts deal with similar decisions in car crashes, medical malpractice, and many other scenarios. A plaintiff could argue that the respondent should have been aware of certain vulnerabilities because they were widely disseminated, or that certain practices are explicitly warned against in common tra…

Very true, but courts arent known for being up to date with tech.

Re: The privacy wars are about to get a whole lot worse

#129

Earlier quoted context omitted.

There are far too many ToSes for any person to be able to read them, let alone negotiate each. This problem was solved in an earlier age of commerce through a Uniform Commercial Code (throughout most of the US), or equivalent statutory or case law in other domains. Essentially, contracts were reduced to a common set of standard components. Exceptions might be allowed for specific cases, including unilateral "contract…

I like the point about the UCC. I have thought about standardized contracts myself, though I didnt think to compare it to the UCC. "But until terms of service are both standardised and codified with users' interests in mind" But what about sites with a different revenue model? Say an image hosting site meant for personal photos, and an image sharing site meant as a platform for artists to sell their work. You would n…

There was an attempt to come up with a UCC for services, within the US, though it failed to garner sufficient support: UCITA.

It's not clear to me how some breadth of interests couldn't be addressed. The usual T&C generally address limits on liability of the site's owners, occasionally try to impose binding arbitration or limits on class action suits (among my complaints against the so-called "Kinder, gentler Reddit", Imzy), jurisdiction, reverse-engineering clauses, etc.

Allowing users to specify licenses for submitted works would address much of your concerns. A standard set of merchandise clauses, including, say, escrow, liability, and chargeback terms, might be among the boilerplate additions to a standard contract which might be made.

But the point is to make the contracts themselves standard and modular. There might be a base services contract, a base merchant contract, and a base rights-for-sale contract, but not infinite variations on each. Also limits on what sites or users might carve out as grantable or transferable rights.

My point in noting that ordinary commerce is limited to a single sale transaction is just that: that these are simple transactions and hence the associated legal binding is also simple. Ongoing relationships are inherently more complex.

There are alternatives to advertising and subscriptions, including non-market constructs.

In the example I posed, the value of the drivers license as a hire surity is that the hirer is quitely likely to return for it. The disadvantage, today, is that the license has not only the attributes of "valuable to the owner", but "hive of data which can be used to draw additional relations".

Some years ago I discovered that the purchase of certain over-the-counter medications required, by store policy though not by local law, presentation of a drivers license. I held up my license for the clerk to visually examine. He tried to take it from my hand, which I refused. He wouldn't close the sale without scanning the card. I walked off without paying and without product.

I've been insisting on respecting my privacy rights for some time, and am not above forgoing business, taking my business elsewhere, or making others pointedly uncomfortable for asking questions I won't answer. Sadly, I am an exception.

Re: The privacy wars are about to get a whole lot worse

#130

from the article - "Notice and consent is an absurd legal fiction." it shouldn't be. "Notice and consent" should instead be a class taught in high schools. The ability to read, understand and NEGIOTIAGE these agreements should be within the mental grasp of everyone.

There are far too many ToSes for any person to be able to read them, let alone negotiate each. This problem was solved in an earlier age of commerce through a Uniform Commercial Code (throughout most of the US), or equivalent statutory or case law in other domains. Essentially, contracts were reduced to a common set of standard components. Exceptions might be allowed for specific cases, including unilateral "contract…

> for any person to be able to read them

This should be exploited by challenging the mutuality of the agreement. Unless there is an understanding by both parties about the basic features and requirements - a "meeting of the minds" - then there isn't a contract.

Currently the "yes, I read that" buttons are used as an indication of having read and understood the contract, but as you said, actually reading all that legalese would take a long time. It may have been hard to prove otherwise in the past, but today we have another option.

We now have algorithms that estimate a given text's reading level. Using that kind of technique we can algorithmically estimate how long it should take for someone to read a document, from which a conservative estimate of the minimum reading time can be derived. It would be short enough that practically everybody exceeds the estimated time. This needs to be purely mechanical.

With a minimum reading time established, every contract should be nullified unless each party was given and used at least that much time to read the document. That is, allowing anybody to "sign" an EULA before $MINIMUM minutes have elapsed should be prima facie evidence that no contact exists.

Post reply on HN