Live data from Hacker News

Edward Snowden: Permanent Record

amazon.com

401–410 of 459 posts

Re: Edward Snowden: Permanent Record

#401
post #109

Earlier quoted context omitted.

Is that the case for both govt and private corporate surveillance? How widespread is the use of Alexa in your area?

The key difference is that you can decide not to buy corporate products you do not want, but have to comply with the laws. I am a lot less concerned about stupid things done by a majority for convenience (and I can choose whether to do participate or not) than about the law that forces the same stupidity down my throat. My 2c.

Not true. Choice is only as good as your options and also depends on the choices of other people around you. My phone records people standing next to me. They might not have chosen to install the apps on my phone, but they’re subject to the surveillance of my device for example.

Re: Edward Snowden: Permanent Record

#402

Earlier quoted context omitted.

you can decide not to buy corporate products That's a fallacy by both choice and externality. There are cases in which there is no choice but to use specific corporate products, or in which choices are made without an individual's consent or involvement. Karen Sandler, co-host (with former FSF directory Bradley Kuhn) of the "Free as in Freedom" podcast has an implanted, closed-source proprietary medical device. She c…

You cannot escape it completely but you can certainly reduce your exposure. I don't think the parent was talking in binary terms.

Each year you can do less and less to limit your exposure. That argument will not old up over time. When IOT and 5G puts more devices online all of these things can be used for surveillance. This argument is not fair or realistic when looking forward a year or two.

Re: Edward Snowden: Permanent Record

#403

Earlier quoted context omitted.

"That's actually the opposite of good practice" Good security practice is considering all devices as insecure until proven otherwise. Also, mitigating known unknowns where a general problem happens a lot. Devices snooping on you, misleading you, interdiction, hacks on firmwate, etc. Then, you mitigate it in situations where you're unsure of what's going on just in case. So, long as mitigation isn't too costly. I used…

> until proven otherwise Well that's impossible (see also the halting problem) so that's pretty clearly not good security practice. Nothing in that says anything about what your threat model is. What risk are you mitigating by doing this? This sounds like the type of "ignore the words and listen to the sound of my voice" security espoused by management and vendor sales people. It sounds like you have a diverting past…

"Well that's impossible (see also the halting problem) so that's pretty clearly not good security practice."

No it's not. It's been done many times. The halting problem applies to a more general issue than the constrained proofs you need for specific, computer programs. If you were right, tools like RV-Match and Astree Analyzer wouldn't be finding piles of vulnerabilities with mathematical analyses. SPARK Ada code would be as buggy as similar C. Clearly, the analyses are working as intended despite not being perfect.

"Security is about identifying and mitigating specific risks. "

Computer security, when it was invented in the 1970's, was about proving that a system followed a specific, security policy (the security goals) in all circumstances or failed safe. The policy was usually isolation. There's others, such as guaranteed ordering or forms of type safety. High-assurance security's basic approach was turned into certification criteria applied to production systems as early as 1985 with SCOMP being first certified. NSA spent five years analyzing and trying to hack that thing. Most get about two years with minimal problems. I describe some of the prescribed activities here in my own framework from way back when:

https://pastebin.com/y3PufJ0V

I eventually made a summary of all the assurance techniques I learned from studying these commercial/government products and academic projects:

https://pastebin.com/uyNfvqcp

Note that projects in the 1960's were hitting lower defect rates than projects achieve today. For higher cost-benefit, I identified the combination of Design-by-Contract, Cleanroom (optional), multiple rounds of static analysis by tools with lower false positives, test generators (esp considering the contracts), and fuzzing w/ contracts in as runtime checks (think asserts). That with a memory-safe language should knock out most major problems with minimal effort on developers' part (some annotations). Most of it would run in background or on build servers.

https://www.win.tue.nl/~wstomv/edu/2ip30/references/design-b...

https://web.archive.org/web/20190428052851/http://infohost.n...

Meanwhile, the state of development for a major OS leads to about 10,000 bugs that even a fuzzer can find:

https://events.linuxfoundation.org/wp-content/uploads/2017/1...

Modern OS's, routers, basic apps, etc aren't as secure as software designed in 1960's-1980's. People are defining secure as mitigates some specific things hackers are doing (they'll do something else) instead of properties the systems must maintain in all executions on all inputs. We have tools and development methods to do this but they're just not applied in general. Some still do, like INTEGRITY-178B and Muen Separation Kernel. Heck, even IRONSIDES DNS and TrustDNS done in SPARK Ada and Rust respectively. Many tools to achieve higher quality/security are free. Don't pretend like it's just genius mathematicians or Fortune 25 companies that can, say, run a fuzzer after developing in a disciplined way with Ada or Rust.

Re: Edward Snowden: Permanent Record

#404
post #213

Earlier quoted context omitted.

Corporate surveillance is only a problem because it will sooner or later feed in to government surveillance. If I could wave a wand and stop that happening I'd be fine with corporate surveillance; I'm annoyed but not threatened by the idea that someone will study my every movement trying to sell me things I want. I'm threatened if the extremely arbitrary government decides that I'm an undesirable for some reason. > c…

> ... trying to sell me things I want. "want". Do you actually desire them, or were you persuaded/tricked into it? :) Also do not underestimate the influence of corporations: * https://en.wikipedia.org/wiki/William_Randolph_Hearst#Spanis... * https://www.newyorker.com/news/daily-comment/kochland-examin...

I honestly don't have a problem being persuaded into wanting something and being 'tricked' is either fraud or the wrong word. I don't agree that advertising is somehow a mind control technique. It is very effective, but being persuaded to do and not do things is part of how I want to operate. If someone makes a case that something is a good idea I'll go with it.

It seems to me that if an advertiser can convince me to spend money then I wish they'd done it sooner. I can easily imagine having bought my first smartphone after seeing an ad. It wouldn't be a trick.

Corporations are worth keeping an eye on, but governments are more unreliable, less governable and generally have larger professional military. And if a corporation acts it is usually in concert with a government.

Re: Edward Snowden: Permanent Record

#405

Earlier quoted context omitted.

Okay, let's try a concrete example: Gmail. Let us agree that the point of Gmail is to read people's email so it can send targeted adds. That automating the process (since human employees don't directly read that email) makes the thing more efficient, and thus worse , as well as easier to misuse. Let us agree that I can indeed avoid having a Gmail account. Can I realistically avoid sending email to a Gmail user? Nope.…

That automating the process (since human employees don't directly read that email) makes the thing more efficient, and thus worse, as well as easier to misuse. While I agree with your larger point, I don't agree with this subjective value judgement and am not sure why it's necessary to lump it in with the rest of your (valid) points. Why do I want to see ads for things I'm not interested in? How is that in any way "b…

I live in the EU, and as such am pretty much nameless for any Google employee. It's not like they would disrupt my personal life. Automated reading however, scales. The damage to any individual is lowered, but it is also multiplied by the number of users. Reliably so.

And now they have a mighty powerful pattern matching machine, they can easily ask more than where I could possibly spend money. They could ask for my political affiliations, or my sexual orientation, my social network (who knows, I may be related to the second or third degree to some nefarious terrorist?).

That last one is very worrying. Especially since recently, my country (France) is being eerily harsh with political opponents. I've just read a story about a journalist (whose income happens to come from YouTube & donations), who is being judged for… gang theft (the pun also works in French), risking up to 75.000€ in fines and 5 years of imprisonment, just because he covered the unhooking of a 8€ portrait of our current president in a Town Office (which usually have president's portraits, but this is not mandatory). Unhooking, they reportedly did not even take the portrait.

So yeah, I'm more and more worried about giving our governments the means to apply their increasing insanity. Sure, having an individual reading my private email is unacceptable, but that risk is getting smaller and smaller, in comparison, to the mass surveillance that automation enables.

Re: Edward Snowden: Permanent Record

#406
post #249

Earlier quoted context omitted.

> "...disparaging things about Obama..." When we start using the word disparaging to describe facts and truth we are ALL in a lot of trouble. So as well-meaning as you believe you might have been with your downvote, you wording has only confirmed the general problem / bias. Irony that just pointing these things out will get more DVs is Chapelle-funny.

So the part where I actually agree with many of the concerns about the man and his administration is ... what? Noise? Doesn't matter, because I didn't use the "right" word? Real talk: we haven't even begun unpacking the ironies here, dude. EDIT: No, that's not an invitation. This conversation isn't going anywhere useful to anyone, and I have both a meeting, and deadlines. Have a good day.

There you go again. It was you who used the word disparaging, not me. Plenty of words to pick. You picked that one.

I point out that truth.

I point out how that further proves the point I and the parent were making.

You get all bias'ed and upset (read: subjective) and try to paint me and the facts as the bad guy.

Don't you recognize the downward spiral of your "logic"?

Thx for taking the time to vindicate the original theory (on NH "inconsistencies").

Re: Edward Snowden: Permanent Record

#407
post #328

Earlier quoted context omitted.

> Punitive insurance rates based on unreasonable inferences, especially for mandatory insurances. Like say doubling your auto insurance rate for buying more than a few beers per week. Or your health insurance going up from buying a power tools. Is it just supposed to be self-evident that those inferences are unreasonable? I've always thought that this was an interesting argument. If there is some form of correlation…

> If there is some form of correlation with beer consumption and and car accidents, wouldn't it make sense to adjust your estimated risk based on that information? Nope. Because it's flawed reasoning. If many people who get into accidents were driving drunk and everyone who drives drunk buys beer it might seem logical to increase rates for everyone who buys beer, but people who drive drunk are only a small percentage…

This is assuming that auto insurance isn't a competiitve industry. If a company attempts to raise rates because of a trend that doesn't actually exist, they will inevitably not be competitive with companies that recognize that the trend doesn't exist, and thus it won't change prices for the consumer.

If the insurance companies could arbitrarily raise rates due to a trend that doesn't exist, than they would have already done so. These companies know their margin and they don't bid above that if they want to be competitive.

Re: Edward Snowden: Permanent Record

#408
post #328

Earlier quoted context omitted.

> Punitive insurance rates based on unreasonable inferences, especially for mandatory insurances. Like say doubling your auto insurance rate for buying more than a few beers per week. Or your health insurance going up from buying a power tools. Is it just supposed to be self-evident that those inferences are unreasonable? I've always thought that this was an interesting argument. If there is some form of correlation…

Buying beer is legal. Driving while sober is legal. Assuming you have no record of driving drunk, any such alleged correlation should not be used to inflate insurance rates, unless you're also willing to say that other correlations of increased risk are also fair game, even if they're based on race or sexual orientation or income or education level or politics or any other characteristic that can be measured and grou…

It's not illegal to be a male, and my insurance premium still raises because of it.

It's the job of the insurance company to accurately assess risk and charge me that plus their margin. If the companies can more accurately assess risk, than that makes insurance a less volatile and therefore cheaper market.

Insurance companies don't have access to the actual root causes of accidents. They have no measure of my driving skill or risk tolerance or attention span. They just estimate based on some really primitive data they have about me. What's the harm in including more data?

Re: Edward Snowden: Permanent Record

#409
post #328

Earlier quoted context omitted.

> Punitive insurance rates based on unreasonable inferences, especially for mandatory insurances. Like say doubling your auto insurance rate for buying more than a few beers per week. Or your health insurance going up from buying a power tools. Is it just supposed to be self-evident that those inferences are unreasonable? I've always thought that this was an interesting argument. If there is some form of correlation…

The problem is that "correlation" seems objective and mechanical, but the model itself carries the bias by choosing which overly simplistic factors are relevant. Directing focus at "people who drink a lot of beer" means considering people who who drink a lot of beer at home as guilty by association, ultimately due to the subjective priorities of whomever pushed for that model. Obviously in the expected value sense, c…

Your model sucks if you are arbitrarily choosing factors. You choose the factors with the most significant correlations, because those correlations are least likely to be "overly simplistic".

Why would we reject that zip codes are more likely to default on a loan? Seems like information I would like to be aware of if I was a home lender.

I certainly look at crime rates of a community before I live there. While a bad crime rate certainly doesn't make potential neighbors "guilty by association", it certainly increases the likelihood that one of my neighbors might be actually guilty.

Re: Edward Snowden: Permanent Record

#410
post #407

Earlier quoted context omitted.

> If there is some form of correlation with beer consumption and and car accidents, wouldn't it make sense to adjust your estimated risk based on that information? Nope. Because it's flawed reasoning. If many people who get into accidents were driving drunk and everyone who drives drunk buys beer it might seem logical to increase rates for everyone who buys beer, but people who drive drunk are only a small percentage…

This is assuming that auto insurance isn't a competiitve industry. If a company attempts to raise rates because of a trend that doesn't actually exist, they will inevitably not be competitive with companies that recognize that the trend doesn't exist, and thus it won't change prices for the consumer. If the insurance companies could arbitrarily raise rates due to a trend that doesn't exist, than they would have alrea…

> If a company attempts to raise rates because of a trend that doesn't actually exist, they will inevitably not be competitive with companies that recognize that the trend doesn't exist,

that assumes that all companies involved aren't doing the same thing. Corporations figured out a long time ago that when one of their competitors does something that makes them more money at the expense of their customers they could start doing the same thing to their own customers and profits increase for everyone without risking prices being driven down by a truly competitive market. The insurance industry in particular is has a long history of shady practices from good old fashioned collusion and price fixing to new techniques like data mining to charge customers different rates depending on where they live, what jobs they have, or how often they're willing to change insurance companies.

Post reply on HN