Live data from Hacker News

China has wealth of data on what individuals are doing at a micro level

cbc.ca

191–200 of 250 posts

Re: China has wealth of data on what individuals are doing at a micro level

#191
post #190

Earlier quoted context omitted.

Signal is not intended to protect from government surveillance, nor is it able to.

You have the source code to Signal. You can see exactly how it protects you from government (and other) surveillance. To be clear: it does better than anything else you can find in an app store.

I can do the same with Telegram.

I can’t verify the source code of the server, or run my own federated server (Moxie doesn’t do federation), and I can’t trust that Moxie’s server doesn’t relay metadata to a government.

> To be clear: it does better than anything else you can find in an app store.

Wrong, proof by counterexample: Conversations.im is also in appstores, is also open source, but, because it’s an XMPP client, I can run my own servers, and federate, and ensure the servers are also secure.

Re: China has wealth of data on what individuals are doing at a micro level

#192

Earlier quoted context omitted.

Signal is not intended to protect from government surveillance, nor is it able to.

I thought that was exactly the point? Who is it intended to protect you from?

There’s a few levels of protection that you might want from a chat system.

#1 Protection from a dumb attacker doing MitM: This is done by anything that uses HTTPS.

#2 Protection from an attacker that can get fake SSL certs: This is done by anything using certificate pinning.

#3 Protection from an attacker that controls the app store: This can’t be easily done by Signal – and they don’t do it.

#4 Protection from an attacker that can take over the servers running the application: This is NOT done by Signal, and is hard to achieve (even with true E2E, unless you do multicast, you usually can extract metadata here, although there are chat applications protecting against it).

If your enemy is the US government, you’re automatically EOL, due to #4. If your enemy is another government, you’re likely EOL, due to #3, unless you actually build the app from source yourself.

This is not a fault from Signal – nor can they easily fix it – but it’s a realistic problem.

Re: China has wealth of data on what individuals are doing at a micro level

#193
post #151

Earlier quoted context omitted.

From June 2017 there will be no extra dataroaming charges in the EU. So you could buy a non-registered SIM card in The Netherlands (you can even buy them at the checkout counter at the supermarket) and use it all over EU member states. Strange situation...

The world can't wait -- but I'd not call it strange. I hadn't been to Europe since 2004, and on my subsequent visit in 2011, I just casually told my wife "we'll just buy SIMs at the first country we go to, surely they've sorted out this stupid roaming-when-you-travel-a-few-hundred-miles thing by now." WRONG. So glad this is coming to an end. I've wasted far too much time and money country-hopping and having to spend…

Yeah, it took them long enough all right!

What I meant by "strange" is that European countries differ in their approach to unregistered SIM cards (due to safety/antiterrorism) but now agree on ending insane dataroaming charges. Any safety advantages to mandatory registration when buying a SIM card (IF there are any, which I doubt) are essentially nullified by this deal. A potential terrorist who wants a burner phone can buy a couple of SIM cards here in The Netherlands and take them to Belgium, for instance. European politics at its finest!

Re: China has wealth of data on what individuals are doing at a micro level

#194

> Now every picture posted, every comment made, every driving infraction could go into a central database to produce a person's 'trustworthiness' score. How is this China-only ? Can't Facebook do the same ? Can't the government force Facebook, Microsoft, etc to give out all the information that we generate in their networks ? Can't they compute such a "trustworthiness" score and sell it to your (potential) employer ?…

In the EU you can instruct a company to divulge everything it knows about you. Facebook will give it to you on a DVD (or at least they used to).

As an instrument of control and coercion, however, there is a massive difference between a government collecting data and not telling you, and a government collecting the data and telling you they use it to calculate your worth to society. The latter seems utterly tyrannical.

Re: China has wealth of data on what individuals are doing at a micro level

#195
post #171
post #151

Earlier quoted context omitted.

The world can't wait -- but I'd not call it strange. I hadn't been to Europe since 2004, and on my subsequent visit in 2011, I just casually told my wife "we'll just buy SIMs at the first country we go to, surely they've sorted out this stupid roaming-when-you-travel-a-few-hundred-miles thing by now." WRONG. So glad this is coming to an end. I've wasted far too much time and money country-hopping and having to spend…

There are several providers doing EU-wide roaming already. I use Orange Spain which I've found to be good. If Spain isn't your first port of call you can buy an Orange Spain SIM on ebay. I think Aldi in Germany also does EU-wide roaming, and I've seen ads for others in other countries.

It's not the dataroaming itself, that has been possible for very long. The big deal about the agreement is that phone companies can't charge you extra anymore for dataroaming.

I have an unlimited calls/SMS plan with 11.5GB data a month. It costs me EUR45,-. When I travel 40 miles east from where I live my current data plan is no longer valid, and I have to pay EUR3.49 per 100MB/minutes/SMS. Yes, hundred MB. Not thousand. Those charges are insane!

Re: China has wealth of data on what individuals are doing at a micro level

#196
post #112

I often wonder what's missing to create and simulate a detailed economic model down to the individual level for and entire country or even the world. There are only 7 billion people to simulate, that doesn't actually sound like that much anymore. Obviously one would not simulate every individual with realistic human-like AI, but with a statistical economic model. How much and what kind of data would one need for this…

You’re going to love reading “Red Plenty” https://www.amazon.co.uk/Red-Plenty-Francis-Spufford/dp/0571...

:)

Re: China has wealth of data on what individuals are doing at a micro level

#197
post #78

This is what comes out of Google allowing apps to read phone IMEI in Android. I have no concrete proof, but the reason why all major Chinese apps snoop after phone IMEI is said to be that the commies have secretly demanded Chinese dotcoms to collect and report phone IMEIs. For example if you have a 6.0 or later Android, Alibaba app will block you if you disabled the permission to read IMEI or it detects spoofing. htt…

> Google allowing apps to read > phone IMEI in Android An unpopular sentiment, but this is why I love iOS. I genuinely don't think any of my apps can meaningfully spy on me without my having told them they may. I even get reminders if I've let an app read my location in the background, to check that's what I want to do.

[deleted]

Re: China has wealth of data on what individuals are doing at a micro level

#198
post #194

> Now every picture posted, every comment made, every driving infraction could go into a central database to produce a person's 'trustworthiness' score. How is this China-only ? Can't Facebook do the same ? Can't the government force Facebook, Microsoft, etc to give out all the information that we generate in their networks ? Can't they compute such a "trustworthiness" score and sell it to your (potential) employer ?…

In the EU you can instruct a company to divulge everything it knows about you. Facebook will give it to you on a DVD (or at least they used to). As an instrument of control and coercion, however, there is a massive difference between a government collecting data and not telling you, and a government collecting the data and telling you they use it to calculate your worth to society. The latter seems utterly tyrannical…

I prefer to know. If intelligence agencies are collecting data of citizens without their knowledge, how can they protest it?

What was noteworthy about Edward Snowden leak was the confirmation of the data collection. He made public something that everybody knew.

Re: China has wealth of data on what individuals are doing at a micro level

#199

Earlier quoted context omitted.

I thought that was exactly the point? Who is it intended to protect you from?

There’s a few levels of protection that you might want from a chat system. #1 Protection from a dumb attacker doing MitM: This is done by anything that uses HTTPS. #2 Protection from an attacker that can get fake SSL certs: This is done by anything using certificate pinning. #3 Protection from an attacker that controls the app store: This can’t be easily done by Signal – and they don’t do it. #4 Protection from an at…

With Signal, you can verify fingerprints. So, what you're saying is:

#4 if some agency "takes over" the Signal servers, they can extract metadata. But only that?

#3 if the binary is not what its supposed to be, then, yes, all bets are off. That's a whole other can of worms, but a) is there any evidence that's ever happened? and b) that much affects any smartphone chat app, so does not help you to decide between Signal and WeChat.

Re: China has wealth of data on what individuals are doing at a micro level

#200
post #127
post #104

Earlier quoted context omitted.

When going overseas, all of those are required anyways: 1. The DB wants to see id (that they can verify) for Eurorail passes. The DB or the Belgian rail people require seeing the purchasing CC. 2. Buying a sim in europe requires a passport. 3. Most things you sign up for in the US requires a phone number. Loyalty programs certianly do. 3.1 Walgreens requires your ID in hand to scan it to verify that you're "over 21"…

1. Yes, I've always had to use my passport with my Eurail passes; though often it's to prove I'm an American who is eligible for the cheaper pass. 2. No, only in certain countries. I've bought SIMs from vending machines in Iceland and Denmark. In Italy the merchant made me seriously promise, I really mean it to send him a photo of my passport as soon as I returned home with my SIM. He gave me his personal gmail addre…

  I remember in Poland and I think the Czech Republic they actually hold your passport
Not in the Czech Republic. I've worked in Prague for a year in 2006 and have stayed in lots of hotels through that time. I'm still visiting the city 10 - 12 times a year and usually stay in hotels.

They normally want to see your passport, or id upon check-in, but I never, ever experienced that they kept it after the check-in process.

Countries where I experienced this where mostly in Asia. Like Laos, or Cambodia. Not even in Vietnam they kept my passport after checking in.

Post reply on HN