Earlier quoted context omitted.
Is that the case for both govt and private corporate surveillance? How widespread is the use of Alexa in your area?
The key difference is that you can decide not to buy corporate products you do not want, but have to comply with the laws. I am a lot less concerned about stupid things done by a majority for convenience (and I can choose whether to do participate or not) than about the law that forces the same stupidity down my throat. My 2c.
Edward Snowden: Permanent Record
401–410 of 459 posts
Re: Edward Snowden: Permanent Record
#402Earlier quoted context omitted.
you can decide not to buy corporate products That's a fallacy by both choice and externality. There are cases in which there is no choice but to use specific corporate products, or in which choices are made without an individual's consent or involvement. Karen Sandler, co-host (with former FSF directory Bradley Kuhn) of the "Free as in Freedom" podcast has an implanted, closed-source proprietary medical device. She c…
You cannot escape it completely but you can certainly reduce your exposure. I don't think the parent was talking in binary terms.
Re: Edward Snowden: Permanent Record
#403Earlier quoted context omitted.
"That's actually the opposite of good practice" Good security practice is considering all devices as insecure until proven otherwise. Also, mitigating known unknowns where a general problem happens a lot. Devices snooping on you, misleading you, interdiction, hacks on firmwate, etc. Then, you mitigate it in situations where you're unsure of what's going on just in case. So, long as mitigation isn't too costly. I used…
> until proven otherwise Well that's impossible (see also the halting problem) so that's pretty clearly not good security practice. Nothing in that says anything about what your threat model is. What risk are you mitigating by doing this? This sounds like the type of "ignore the words and listen to the sound of my voice" security espoused by management and vendor sales people. It sounds like you have a diverting past…
No it's not. It's been done many times. The halting problem applies to a more general issue than the constrained proofs you need for specific, computer programs. If you were right, tools like RV-Match and Astree Analyzer wouldn't be finding piles of vulnerabilities with mathematical analyses. SPARK Ada code would be as buggy as similar C. Clearly, the analyses are working as intended despite not being perfect.
"Security is about identifying and mitigating specific risks. "
Computer security, when it was invented in the 1970's, was about proving that a system followed a specific, security policy (the security goals) in all circumstances or failed safe. The policy was usually isolation. There's others, such as guaranteed ordering or forms of type safety. High-assurance security's basic approach was turned into certification criteria applied to production systems as early as 1985 with SCOMP being first certified. NSA spent five years analyzing and trying to hack that thing. Most get about two years with minimal problems. I describe some of the prescribed activities here in my own framework from way back when:
I eventually made a summary of all the assurance techniques I learned from studying these commercial/government products and academic projects:
Note that projects in the 1960's were hitting lower defect rates than projects achieve today. For higher cost-benefit, I identified the combination of Design-by-Contract, Cleanroom (optional), multiple rounds of static analysis by tools with lower false positives, test generators (esp considering the contracts), and fuzzing w/ contracts in as runtime checks (think asserts). That with a memory-safe language should knock out most major problems with minimal effort on developers' part (some annotations). Most of it would run in background or on build servers.
https://www.win.tue.nl/~wstomv/edu/2ip30/references/design-b...
https://web.archive.org/web/20190428052851/http://infohost.n...
Meanwhile, the state of development for a major OS leads to about 10,000 bugs that even a fuzzer can find:
https://events.linuxfoundation.org/wp-content/uploads/2017/1...
Modern OS's, routers, basic apps, etc aren't as secure as software designed in 1960's-1980's. People are defining secure as mitigates some specific things hackers are doing (they'll do something else) instead of properties the systems must maintain in all executions on all inputs. We have tools and development methods to do this but they're just not applied in general. Some still do, like INTEGRITY-178B and Muen Separation Kernel. Heck, even IRONSIDES DNS and TrustDNS done in SPARK Ada and Rust respectively. Many tools to achieve higher quality/security are free. Don't pretend like it's just genius mathematicians or Fortune 25 companies that can, say, run a fuzzer after developing in a disciplined way with Ada or Rust.
Re: Edward Snowden: Permanent Record
#404Earlier quoted context omitted.
Corporate surveillance is only a problem because it will sooner or later feed in to government surveillance. If I could wave a wand and stop that happening I'd be fine with corporate surveillance; I'm annoyed but not threatened by the idea that someone will study my every movement trying to sell me things I want. I'm threatened if the extremely arbitrary government decides that I'm an undesirable for some reason. > c…
> ... trying to sell me things I want. "want". Do you actually desire them, or were you persuaded/tricked into it? :) Also do not underestimate the influence of corporations: * https://en.wikipedia.org/wiki/William_Randolph_Hearst#Spanis... * https://www.newyorker.com/news/daily-comment/kochland-examin...
It seems to me that if an advertiser can convince me to spend money then I wish they'd done it sooner. I can easily imagine having bought my first smartphone after seeing an ad. It wouldn't be a trick.
Corporations are worth keeping an eye on, but governments are more unreliable, less governable and generally have larger professional military. And if a corporation acts it is usually in concert with a government.
Re: Edward Snowden: Permanent Record
#405Earlier quoted context omitted.
Okay, let's try a concrete example: Gmail. Let us agree that the point of Gmail is to read people's email so it can send targeted adds. That automating the process (since human employees don't directly read that email) makes the thing more efficient, and thus worse , as well as easier to misuse. Let us agree that I can indeed avoid having a Gmail account. Can I realistically avoid sending email to a Gmail user? Nope.…
That automating the process (since human employees don't directly read that email) makes the thing more efficient, and thus worse, as well as easier to misuse. While I agree with your larger point, I don't agree with this subjective value judgement and am not sure why it's necessary to lump it in with the rest of your (valid) points. Why do I want to see ads for things I'm not interested in? How is that in any way "b…
And now they have a mighty powerful pattern matching machine, they can easily ask more than where I could possibly spend money. They could ask for my political affiliations, or my sexual orientation, my social network (who knows, I may be related to the second or third degree to some nefarious terrorist?).
That last one is very worrying. Especially since recently, my country (France) is being eerily harsh with political opponents. I've just read a story about a journalist (whose income happens to come from YouTube & donations), who is being judged for… gang theft (the pun also works in French), risking up to 75.000€ in fines and 5 years of imprisonment, just because he covered the unhooking of a 8€ portrait of our current president in a Town Office (which usually have president's portraits, but this is not mandatory). Unhooking, they reportedly did not even take the portrait.
So yeah, I'm more and more worried about giving our governments the means to apply their increasing insanity. Sure, having an individual reading my private email is unacceptable, but that risk is getting smaller and smaller, in comparison, to the mass surveillance that automation enables.
Re: Edward Snowden: Permanent Record
#406Earlier quoted context omitted.
> "...disparaging things about Obama..." When we start using the word disparaging to describe facts and truth we are ALL in a lot of trouble. So as well-meaning as you believe you might have been with your downvote, you wording has only confirmed the general problem / bias. Irony that just pointing these things out will get more DVs is Chapelle-funny.
So the part where I actually agree with many of the concerns about the man and his administration is ... what? Noise? Doesn't matter, because I didn't use the "right" word? Real talk: we haven't even begun unpacking the ironies here, dude. EDIT: No, that's not an invitation. This conversation isn't going anywhere useful to anyone, and I have both a meeting, and deadlines. Have a good day.
I point out that truth.
I point out how that further proves the point I and the parent were making.
You get all bias'ed and upset (read: subjective) and try to paint me and the facts as the bad guy.
Don't you recognize the downward spiral of your "logic"?
Thx for taking the time to vindicate the original theory (on NH "inconsistencies").
Re: Edward Snowden: Permanent Record
#407Earlier quoted context omitted.
> Punitive insurance rates based on unreasonable inferences, especially for mandatory insurances. Like say doubling your auto insurance rate for buying more than a few beers per week. Or your health insurance going up from buying a power tools. Is it just supposed to be self-evident that those inferences are unreasonable? I've always thought that this was an interesting argument. If there is some form of correlation…
> If there is some form of correlation with beer consumption and and car accidents, wouldn't it make sense to adjust your estimated risk based on that information? Nope. Because it's flawed reasoning. If many people who get into accidents were driving drunk and everyone who drives drunk buys beer it might seem logical to increase rates for everyone who buys beer, but people who drive drunk are only a small percentage…
If the insurance companies could arbitrarily raise rates due to a trend that doesn't exist, than they would have already done so. These companies know their margin and they don't bid above that if they want to be competitive.
Re: Edward Snowden: Permanent Record
#408Earlier quoted context omitted.
> Punitive insurance rates based on unreasonable inferences, especially for mandatory insurances. Like say doubling your auto insurance rate for buying more than a few beers per week. Or your health insurance going up from buying a power tools. Is it just supposed to be self-evident that those inferences are unreasonable? I've always thought that this was an interesting argument. If there is some form of correlation…
Buying beer is legal. Driving while sober is legal. Assuming you have no record of driving drunk, any such alleged correlation should not be used to inflate insurance rates, unless you're also willing to say that other correlations of increased risk are also fair game, even if they're based on race or sexual orientation or income or education level or politics or any other characteristic that can be measured and grou…
It's the job of the insurance company to accurately assess risk and charge me that plus their margin. If the companies can more accurately assess risk, than that makes insurance a less volatile and therefore cheaper market.
Insurance companies don't have access to the actual root causes of accidents. They have no measure of my driving skill or risk tolerance or attention span. They just estimate based on some really primitive data they have about me. What's the harm in including more data?
Re: Edward Snowden: Permanent Record
#409Earlier quoted context omitted.
> Punitive insurance rates based on unreasonable inferences, especially for mandatory insurances. Like say doubling your auto insurance rate for buying more than a few beers per week. Or your health insurance going up from buying a power tools. Is it just supposed to be self-evident that those inferences are unreasonable? I've always thought that this was an interesting argument. If there is some form of correlation…
The problem is that "correlation" seems objective and mechanical, but the model itself carries the bias by choosing which overly simplistic factors are relevant. Directing focus at "people who drink a lot of beer" means considering people who who drink a lot of beer at home as guilty by association, ultimately due to the subjective priorities of whomever pushed for that model. Obviously in the expected value sense, c…
Why would we reject that zip codes are more likely to default on a loan? Seems like information I would like to be aware of if I was a home lender.
I certainly look at crime rates of a community before I live there. While a bad crime rate certainly doesn't make potential neighbors "guilty by association", it certainly increases the likelihood that one of my neighbors might be actually guilty.
Re: Edward Snowden: Permanent Record
#410Earlier quoted context omitted.
> If there is some form of correlation with beer consumption and and car accidents, wouldn't it make sense to adjust your estimated risk based on that information? Nope. Because it's flawed reasoning. If many people who get into accidents were driving drunk and everyone who drives drunk buys beer it might seem logical to increase rates for everyone who buys beer, but people who drive drunk are only a small percentage…
This is assuming that auto insurance isn't a competiitve industry. If a company attempts to raise rates because of a trend that doesn't actually exist, they will inevitably not be competitive with companies that recognize that the trend doesn't exist, and thus it won't change prices for the consumer. If the insurance companies could arbitrarily raise rates due to a trend that doesn't exist, than they would have alrea…
that assumes that all companies involved aren't doing the same thing. Corporations figured out a long time ago that when one of their competitors does something that makes them more money at the expense of their customers they could start doing the same thing to their own customers and profits increase for everyone without risking prices being driven down by a truly competitive market. The insurance industry in particular is has a long history of shady practices from good old fashioned collusion and price fixing to new techniques like data mining to charge customers different rates depending on where they live, what jobs they have, or how often they're willing to change insurance companies.