Earlier quoted context omitted.
Replace the "te" with "l"
I'm still lost?
The "te with l" tip was for the original "'criminate" and not very clear.
211–220 of 302 posts
I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course. Same idea as the ethics courses taught to junior law students. The internet is already fucked up enough with governments and rogue corporations messing with its AS-adjacency topology in non-free ways at OSI layers 1-3 , before you even get into stuff like writing backd…
None of these answer practical issues like what happens when the law is bad or when one's livelihood is on the line. None of these give practical advice on how to fix a society where ethical behavior is not inherently incentivized.
Earlier quoted context omitted.
In a large company, a useful thing to do if something fishy is going on is to go see the company's general counsel.[1] If they didn't know about it, they should be told. Their job is to keep the company out of legal trouble. In many cases they have a legal obligation to do something about it. An attorney will rarely tell you to do something illegal; they can be disbarred for that. If they tell you it's OK, then they'…
In the case of NSLs, or UK orders from the security services, it may be illegal to tell anyone who isn't mentioned in the order. Including the company's general counsel. In the event that you are asked to do something illegal, it may be illegal or inadmissible to mention that you were ordered to do so by the government (Matrix-Churchill trial passim)
- CEO gets a Letter. Does the CEO start learning Python/C++/PHP and Cisco configuration? Or does he tell a worker bee "Shhh! And read this Letter" ?
- Worker bee starts making changes to production code and systems. Suddenly he starts needing automated code reviews, and reconfiguration alerts go out when he frobs the firewalls. These changes are indistinguishable from an infiltrator with the worker-bee's credentials and ideally things are set up so that changes are generally shared around, a normal review process, to catch out-of-control worker bees.
- The build lab scripts are modified (by who?) to insert bad code. Oh, but the build checkers catch this ("Hey, we found a compiler bug!" / "Umm, no you didn't..."). Everybody starts handing around links to "Reflections on Trusting Trust".
- Things get even more exciting when the internal monitoring systems discover (say) equipment attached to the network that ain't supposed to be there. "Wot's all this then," says the network engineer, and he yanks the cables to the SkankSec-1000 that someone hot-wired into a rack. "Oh yeah, blue fiber is for NSA, green is for CIA, yellow is for GCHG, and black is for Russians, what else?" He leaves it unplugged. Let's ignore the security camera footage in the datacenter, since this is a thought experiment.
In an environment with self-monitoring for health and intrusion detection, applying changes for user surveillance requires quite a lot of internal cooperation and communication. No wonder the Yahoo stuff looked like a Bad Guy who got in.
We can probably extend the internal defenses to alerting on odd access patterns to sensitive database rows, too . . .
Earlier quoted context omitted.
PRISM (Yahoo joined 2nd in 2008 after Microsoft in 2007) would basically defeat the purpose of doing this without permission... Did Yahoo Mail even use HTTPS? In that case a FISA warrant would just be an extra level of assurance that they got everything from that person's inbox (plus inboxes of 3 hops of everyone they ever emailed). Otherwise they were just an XKeyscore query, probably filtered by US geodata, away fr…
I feel like everyone has forgotten about PRISM. All the big companies denied they participated in PRISM. Is it real, and if so, why have Americans been so complacent about its existence?
Earlier quoted context omitted.
In a large company, a useful thing to do if something fishy is going on is to go see the company's general counsel.[1] If they didn't know about it, they should be told. Their job is to keep the company out of legal trouble. In many cases they have a legal obligation to do something about it. An attorney will rarely tell you to do something illegal; they can be disbarred for that. If they tell you it's OK, then they'…
I'd suggest following up any conversation of substance with general counsel (or even the likes of HR for that matter) with an email detailing the conversation you just had. Don't do it in an obtuse manner; let them know in advance that you will be sending it following the meeting, maybe even get them to suggest the wording of it if you aren't convinced of the security of internal mail. It's easy for either side to fo…