Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Friday, May 23, 2025

Russia to use Phones to Track Foreigners

News:
The Russian government has introduced a new law that makes installing a tracking app mandatory for all foreign nationals in the Moscow region.

The new proposal was announced by the chairman of the State Duma, Vyacheslav Volodin, who presented it as a measure to tackle migrant crimes.

"The adopted mechanism will allow, using modern technologies, to strengthen control in the field of migration and will also contribute to reducing the number of violations and crimes in this area," stated Volodin.

Using a mobile application that all foreigners will have to install on their smartphones, the Russian state will receive the following information:

Residence location
Fingerprint
Face photograph
Real-time geo-location monitoring

"If migrants change their actual place of residence, they will be required to inform the Ministry of Internal Affairs (MVD) within three working days," the high-ranking politician explained.

This seems outrageous, and foolish for a country that wants tourism.

And yet I think it is inevitable that most countries with do something like this. The technology is cheap, easy, and efficient.

Most tourists are not going to secret locations, or anything like that. My guess is that soon most will not mind.

The USA desperately needs to better monitor millions of people. Mainly, criminals on parole or probation, and foreigners on temporary visas or claiming asylum or without authorization. Nearly all have smart phones, and they could be tracked.

Tuesday, November 19, 2024

Revisiting the Crypto Wars

Cryptology professor Dan Bernstein criticizes Meredith Whittaker on her lecture, AI, Encryption, and the Sins of the 90s.

The argument is that strong end-to-end encryption made certain kinds of spying harder, but actually helped mass surveillance.

The big argument of the 1990s crypto wars was between strong and weak encryption. The technology for strong encryption had become available, making code breaking intractable. With weak encryption, there is the possibility that a well-funded spy agency could crack it. USA had favored weak encryption for international communications.

While I was on the side of strong encryption, it is difficult to make the economic case for it. That is, what were the economic losses from use of weak encryption, in dollars? Did any businesses actually lose money using weak encryption?

No. For most people, the most common use of encryption was to secure passwords in web browsers, and to secure credit card numbers for online purchases. Some browsers used weak encryption, and that was adequate for the purpose.

Even with strong encryption, spy agencies might still figure out with whom you are communicating.

There is still a debate in many countries over whether law enforcement should have the ability to crack encrypted communications.

For some people, privacy is very important. Most people do not care much, and are happy to give up some privacy so that Facebook or Google can deliver more targeted ads.

Monday, October 02, 2023

Big Tech Buried Face Recognition

Everyone is excited about new AI technologies being released, but here is one that the big tech companies have buried:
As early as 2011, a Google engineer revealed he had been working on a tool to Google someone’s face and bring up other online photos of them. Months later, Google’s chairman, Eric Schmidt, said in an onstage interview that Google “built that technology, and we withheld it.”

“As far as I know, it’s the only technology that Google built and, after looking at it, we decided to stop,” Mr. Schmidt said.

Advertently or not, the tech giants also helped hold the technology back from general circulation by snapping up the most advanced start-ups that offered it. In 2010, Apple bought a promising Swedish facial recognition company called Polar Rose. In 2011, Google acquired a U.S. face recognition company popular with federal agencies called PittPatt. And in 2012, Facebook purchased the Israeli company Face.com. In each case, the new owners shut down the acquired companies’ services to outsiders. The Silicon Valley heavyweights were the de facto gatekeepers for how and whether the tech would be used.

Facebook, Google and Apple deployed facial recognition technology in what they considered to be relatively benign ways: as a security tool to unlock a smartphone, a more efficient way to tag known friends in photos and an organizational tool to categorize smartphone photos by the faces of the people in them.

There are some privacy concerns with face recognition, but there are also useful applications, and I don't think Google should have the power to kill them.

Tuesday, March 28, 2023

Freud is Making a Comeback

The NY Times reports:
Sigmund Freud is enjoying something of a comeback. A new generation of analysts and patients are embracing the father of psychoanalysis — in memes, magazines and many long hours on the couch.
I see stories like this every few years.

Freudian psychoanalysis is just weird stuff that Jews believe in.

More mainstream psychology was on display in the Johnny Depp Amber Heard trial. Heard claimed that she had been psychologically damaged, and Depp was allowed to rebut that in court, so he could get a psychologist to evaluate her. See this Shannon Curry interview for more details. Curry gave Heard the standard 567 true/false question Minnesota personality inventory test, and testified with an interpretation that was very damaging to Heard.

Depp was not similarly evaluated, because he made no claims about himself being damaged.

I wonder how much the jury was persuaded by this expert testimony. The idea is that Heard's personality can be diagnosed from correlations with the thousands or maybe millions who have taken this test. It is largely voodoo.

It was a bit like having a Black man on trial for a crime, and bringing in an expert to explain how race is correlated with criminal behavior. Yes, correlations are there, but they do not prove anything about a particular individual.

That being said, Curry's analysis of Heard's psychological disorders was plausible. Heard can pass as a normal person most of the time, but some of her behavior is so far outside acceptable behavior that it is hard for me to assess what she could have been thinking. I might have found Curry's theorizing helpful.

I have taken this test, and several similar ones. The results were fairly boring. You might have gotten similar results from just interviewing me for half an hour.

If the tests really worked as well as Curry described, then there might be social value in making everyone take them and letting courts, employers, credit agencies, and others use the results. That would also be very invasive, and lead to a lot of complaints about accuracy and prejudice.

Thursday, February 16, 2023

Your Mental Health Records are for Sale

NBC News reports:
Sensitive mental health data is for sale by little-known data brokers, at times for a few hundred dollars and with little effort to hide personal information such as names and addresses, according to research released Monday.

The research, conducted over two months at Duke University’s Sanford School of Public Policy, which studies the ecosystem of companies buying and selling personal data, consisted of asking 37 data brokers for bulk data on people’s mental health. Eleven of them agreed to sell information that identified people by issues, including depression, anxiety and bipolar disorder, and often sorted them by demographic information such as age, race, credit score and location.

I wonder if it is time to give up on privacy. We have some medical privacy laws, but they are an ineffective nuisance.

Mentally ill people are a big drain on our society. If they could be more readily identified, they could be monitored for criminal activity, prevented from owning guns, and kept out of trusted positions. And those with personal relationships could be warned.

Tracking people is big business. Either we shut down those businesses, or continue into an open society where all info can be bought and sold.

Banks get your credit score before lending you money. A car buyer gets Carfax to get your vehicle history before buying your used car. You should be able to get someone's mental health history before hiring her or going on a date.

You might say that tracking mental illness would discourage people from getting treatment. But that might be a good thing, as a lot of mental health treatment is destructive.

The NY Times reports:

Aidan, 18, developed involuntary tics after watching videos on TikTok posted by teenagers claiming to have Tourette’s syndrome. “It looked like Aidan was going crazy,” recalled their mother, Rhonda.

… Four out of five of the adolescents were diagnosed with a psychiatric disorder, and one-third reported past traumatic experiences, according to a study from the University of Calgary that analyzed nearly 300 cases from eight countries. In new research that has not yet been published, the Canadian team has also found a link to gender: The adolescents were overwhelmingly girls, or were transgender or nonbinary — though no one knows why.

These kids are going crazy.

The London Daily Mail reports:

A mother has admitted regretting letting her four-year-old son socially transition to a girl - and said realizing her mistake was like 'leaving a cult'.

Rose, who wishes to stay anonymous, raised her two sons as gender neutral with her wife, which was reflected in their clothes, toys and language.

When her four-year-old son said he felt like a girl, the mother encouraged him in his new identity - which she has now admitted was a 'mistake' that 'haunts' her. ...

'This experience for me has felt like leaving a cult, a cult that would have me sacrifice my child to the gods of gender ideology, in the name of social justice and collective liberation. I have left this cult, and I am never turning back.'

As the two boys grew up, the parents used 'he/him' for their pronouns but did not tell them they were boys.

In Rose's essay - called 'True Believer' - she said this meant she was 'primed to look for clues' that her children could be transgender.

This lesbian mom appears to be mentally ill, and susceptible to cult thinking. I would like to believe that she has recovered, but most do not.

Tuesday, January 18, 2022

Bad Computer Security at Financial Firms

You would think that financial firms would have good login security, but read this from several years ago:
An angry Vanguard customer had called her to say he was able to log into his account, even though he'd deliberately provided a misspelled security answer, Brock explained to her tech colleague, named Mike, who took her call on May 7, 2013.
The company is weird. They put in a security image in the login process, telling customers to refuse to login if the right image is not seen. Then it just dropped the feature, without telling anyone. So if you followed their own security instructions, you would never login.
On a dozen occasions in recent months, I have logged into my own Vanguard account despite dropping letters and introducing other typographical errors to my security answers. On several occasions, I was able to reset my password after entering typos of between one and two characters into three separate security answers. The process did require that I provide my date of birth, zip code, the last four digits of my Social Security number and email address. But security experts say such information is easily stolen or found online, making accurate security answers critical.
So what is it doing? This is fairly standard:
During an hour-long interview with Sherlock and three other Vanguard officials in late July, the company stressed that it has made strides in customer safety that include the launch in December of an enhanced security option to make customers' login process safer. Its so-called "two-factor authentication" service requires not only that a customer enter a user name and password, but that they also submit a 6-digit code that Vanguard sends by text message to the customer's cellphone.
Okay, but here is the message that Vanguard sent me:
Vanguard won't contact you for this code: 894581. Don't share it with anyone. Reply HELP for help, STOP to cancel, Msg&Data Rates May Apply
Why would it say that? The whole purpose of the code is to submit it when Vanguard contacts me and asks for it. I am unable to login unless I share the code with Vanguard. Or maybe I should say logon, as that is what Vanguard calls it.

Currently, I cannot even login to Vanguard with my Firefox or Chrome browsers. They used to work fine.

Thursday, April 05, 2018

Facebook spies on your messages

Bloomberg reports:
Facebook Inc. scans the links and images that people send each other on Facebook Messenger, and reads chats when they’re flagged to moderators, making sure the content abides by the company’s rules. If it doesn’t, it gets blocked or taken down.

The company confirmed the practice after an interview published earlier this week with Chief Executive Officer Mark Zuckerberg raised questions about Messenger’s practices and privacy. Zuckerberg told Vox’s Ezra Klein a story about receiving a phone call related to ethnic cleansing in Myanmar. Facebook had detected people trying to send sensational messages through the Messenger app, he said.

“In that case, our systems detect what’s going on,” Zuckerberg said. “We stop those messages from going through.”
Google automatically scans gmail messages, and has occasionally reported users to the police.

It is funny that Facebook has been selling users' private data to advertisers and political campaigns for years, but the press only gets excited about it when it is revealed that the data was possibly used for Trump's benefit.

Do you really want Facebook taking sides in a civil war in Burma?

What did you think was happening when you click a "Like" button? That button exists for the purpose of selling your privacy to marketers.

Tuesday, June 20, 2017

Cars will punish jaywalkers

Treehugger.com warns:
In January, Carlton Reid wrote that Makers of driverless cars want cyclists and pedestrians off the roads. He quotes Renault CEO Carlos Ghosn, who says pesky cyclists "don't respect any rules usually." ...

In the Guardian, Laura Laker describes Street wars 2035: can cyclists and driverless cars ever co-exist? She worries that, because AVs are designed to recognize and not run over pedestrians or cyclists, chaos will ensue. ...

Proposed solutions include RFID beacons built into bicycles to warn AVs (and perhaps our cellphones, talking to lamp posts and cars, as we showed a few years ago) or criminalizing walking in front of cars, which would take a photo and send it to the police department, who “will come and arrest you for annoying an autonomous vehicle.”
This is plausible. Pedestrians and others will learn that they can take advantage of autonomous cars being programmed to avoid pedestrians at all costs. So jaywalking will become popular. But then the car lobby will demand that the cars become a jaywalking police force, and videorecording all bad behavior by pedestrians and others and reporting to police. Maybe if you even just make an obscene gesture on the sidewalk, a self-driving car will record it and report it. We have red-light cameras now, but this will be 100x more intrusive.

I suspect that we will also see Mohammedans reprogramming the autonomous cars to be deadly weapons, and to run over pedestrians. These cars will not have secure operating systems, the necessary code will be downloadable from ISIS.

Saturday, June 03, 2017

Cars will double as security cameras

Many new technologies are privacy-invading, and most of the companies like Google and Facebook try to hide this problem. Intel just revealed one problem.

CNBC reports:
The benefits of having self-driving cars go far beyond automatic parking or fewer accidents, Intel CEO Brian Krzanich told CNBC on Thursday.

Among those other benefits: Driverless cars will double as security cameras, he said from the sidelines of the Code Conference in California.

"I always say that the cars are going to be out there looking, so the next time an Amber alert comes up and they're looking for a license plate, the cars should be able to find that license plate quite rapidly," said Krzanich.

The idea could bring up concerns about privacy, but Krzanich has already thought of how to minimize those worries.

"We'll have to put limitations on it," he said. "We'll have to encrypt that data and make sure I can't tell that it's John's [car] necessarily," said Krzanich.

"I think there will be rules and new areas we'll have to explore, but the amount of social good that can come from that far outweighs those concerns," he said. "We just have to deal with them."
Most Amber alerts are based on a dad seeing his child outside the court-approved hours, and the mom calling the cops on him.

For that, we will have 10 million cars video recording everyone in public, and keeping a record of where everyone is at all times. In a few years, you will not be able to go anywhere without your trip being recorded in a database accessible to law enforcement, advertisers, credit bureaus, insurance companies, and subpoenas in civil lawsuits. Get used to it.

Monday, May 01, 2017

Web to support encrypted content

Tim Berners-Lee of the W3C writes:
The question which has been debated around the net is whether W3C should endorse the Encrypted Media Extensions (EME) standard which allows a web page to include encrypted content, by connecting an existing underlying Digital Rights Management (DRM) system in the underlying platform. Some people have protested “no”, but in fact I decided the actual logical answer is “yes”.
Much as leftist web activists hate DRM, the logical answer is indeed yes.

I am all in favor of wanting control over my own machines. That is why I don't like advertisers running javascript in my browser, and why I don't like Apple and Facebook. I appreciate tools for blocking javascript, ads, and itunes. But I also want to watch movies that cost millions to make, so I want DRM-capable hardware and software.

For related reasons, the Apple and Linux folks are ideologically opposed to using technologies like TPM to help secure your computer. They make it impractical to securely store info on those computers. So enterprise customers buy Microsoft.

Thursday, April 06, 2017

Privacy experts owned by Google and FB

The NY Times attacks some Trump policies, and adds:
Broadband companies, privacy experts said, occupy a different position than internet companies. Google and Facebook, they noted, are corporate giants with plenty of market clout. But they are not a fundamental pathway to the internet the way the broadband providers are. And, privacy experts said, there is little or no competition for broadband service in many markets.

“You can live without Google or Facebook,” said Dallas Harris, a legal and policy fellow at Public Knowledge, a nonprofit consumer group. “It’s pretty difficult to walk away from internet service altogether.”
Most consumers can use alternatives like satellite or cellular. They can also mask their activities by using VPNs.

But it is much harder to avoid Google and Facebook spying on you, and selling your info thru ad clicks. Even if you try to avoid Google and Facebook, most of the other sites on the web have Google and Facebook spy buttons on them. And you cannot very well use something like a VPN to hide what you are doing, because Facebook requires your real identity and Google services require your email and your location.

The internet has done well with minimal regulation, and maybe it ought to stay that way. Or maybe some regulations ought to force ISPs to offer basic privacy protections. But I cannot agree with these so-called "privacy experts" who say that Google and Facebook should be allowed to spy on you and sell your info all they want, but other ISPs like phone companies cannot.

Monday, April 03, 2017

Google and FB lobby for protection

The Google-Facebook lackeys are complaining about Trump:
The decision to bring up the highly contested issue of net neutrality, especially in the same week that Congress voted to get rid of privacy protections for ISPs, would usually be an odd one, but seems to follow the Trump Administration's scorched-earth approach to policy-making. ...

Regardless, the decision to revoke net neutrality has caused immediate reaction. The World Wide Web Foundation (W3C) put out a statement just hours later complaining that the Trump Administration had "promised to drive economic progress for all and defend freedom of speech."

Maintaining net neutrality rules – which make it illegal for companies to discriminate between different types of internet traffic – would "preserve the internet as it should be," as well as "be key to delivering on these promises," the W3C claimed.

It went on: "Congress and the FCC have a choice to make. Keeping net neutrality is a commitment towards offering today's entrepreneurs the same opportunities the founders of Google or Paypal had, ensuring everyone can have a voice online, and guaranteeing that poorer or rural communities can enjoy the same quality of content as wealthy urban dwellers."
No, this is nonsense.

The biggest censors and privacy invaders on the internet are Google and Facebook, and they have been exempt from the privacy and neutrality rules. Why regulate some internet service providers, and not Google or Facebook?

I used to side with the internet privacy advocates, but they have all been co-opted by Google-FB money and propaganda. They seem to have some sort of paranoid hatred of the phone and cable companies, while letting Google and Facebook intrude on us. As a practical matter, it is much easier to hide my activities from the phone and cable companies than from Google and Facebook.

Tuesday, January 17, 2017

Facebook can spy on your messages

Ars Technica reports:
The Guardian roiled security professionals everywhere on Friday when it published an article claiming a backdoor in Facebook's WhatsApp messaging service allows attackers to intercept and read encrypted messages. It's not a backdoor — at least as that term is defined by most security experts. ...

Critics of Friday's Guardian post, and most encryption practitioners, argue such behavior is common in encryption apps and often a necessary requirement. Among other things, it lets existing WhatsApp users who buy a new phone continue an ongoing conversation thread.
No. I am an encryption practitioner, and such behavior is neither common nor necessary.

Since Facebook refuses to fix this problem, it should not be promising "end-to-end encryption". Facebook has engineered in a system for spying on messages.

Facebook/WhatsApp argue that their system is more convenient than true end-to-end encryption. That may be. It may also turn out to be useful for law enforcement to track possible terrorists or child molesters. Most users do not need to be concerned about this vulnerability. They are happy to give up some privacy in order to get some free services. But I would not recommend the system for high-security messages.

Update: Bruce Schneier concludes:
How serious this is depends on your threat model. If you are worried about the US government -- or any other government that can pressure Facebook -- snooping on your messages, then this is a small vulnerability. If not, then it's nothing to worry about.
It is a little strange that Facebook/Whatsapp refuses to fix it.

Thursday, November 24, 2016

Fear of Trump spying on your cellphone

Crytography advocate and professor Susan Landau writes:
We have elected a President who does not believe in the First Amendment protections of a free press and who urged the hacking of his opponent's email, including by Russia. Our President-elect has also repeatedly said that he will throw his opponent in jail over issues that the FBI Director, after a long investigation, determined did not present evidence of criminal activity. We are in unchartered territory. We have a president-elect who does not appear to respect the protections enshrined in the Bill of Rights. Those who disagree with President-elect Trump feel threatened not just by the policies he espouses, but by the hatred and dictatorial stances he has been supporting. ...

There is a risk that President-elect Trump means what he says. Given the President-elect's authoritarian statements, I no longer feel confident that the surveillance of journalists, the political opposition, or of protesters will not occur in this country. The President-elect has explicitly said that he wished he had the power to hack into the accounts of his political enemies.

Protecting the privacy of speech is crucial for preserving our democracy. We live at a time when tracking an individual — a journalist, a member of the political opposition, a citizen engaged in peaceful protest — or listening to their communications is far easier than at any time in human history.
I am inclined to agree with her about ppl having rights to private communication, but she seems to suffer from some delusions. Almost everything she says about Trump is wrong.

The chief threats to privacy come from the leftists at Google and Facebook. Trump supporters are being shut down while Trump-haters are not. The leftists currently complain about "fake news" and use that as an excuse to censor news.

Her complaints are hollow. She does not say what is so terrible about listening to communications of citizens engaged in peaceful protests. I would think that such citizens would want to be heard!

In some ways we have less privacy today, but in others we have more. It is easier than ever to organize a peaceful protest, and such protests are not inhibited by govt spying.

This recent TED talk got 700k views:
The smartphone you use reflects more than just personal taste ... it could determine how closely you can be tracked, too. Privacy expert and TED Fellow Christopher Soghoian details a glaring difference between the encryption used on Apple and Android devices and urges us to pay attention to a growing digital security divide. "If the only people who can protect themselves from the gaze of the government are the rich and powerful, that's a problem," he says. "It's not just a cybersecurity problem — it's a civil rights problem."
This whole thing is strangely misguided.

First, there is no significant security difference between Apple and Android phones. Apple famously refused to cooperate with an FBI investigation of a Moslem terrorist, but the FBI used an off-the-shelf tool to get into the phone anyway.

Second, the rich have better house, cars, lifestyles, and everything else, so why shouldn't they have better phones also? Ppl should be able to pay more for a better phone.

Third, the major privacy invasions come from Facebook and other leftist companies, not FBI investigations of Moslem terrorists. Why do these supposed civil rights advocates devote so much energy to defending Moslem terrorists when Facebook is spying on a billion ppl.

Landau obviously suffers from Trump derangement syndrome. Both have some leftist blind spots about what privacy is.

Sunday, March 06, 2016

More bad arguments for privacy

Bruce Schneier argues:
The FBI wants the ability to bypass encryption in the course of criminal investigations. This is known as a "backdoor," because it's a way at the encrypted information that bypasses the normal encryption mechanisms. I am sympathetic to such claims, but as a technologist I can tell you that there is no way to give the FBI that capability without weakening the encryption against all adversaries. This is crucial to understand. I can't build an access technology that only works with proper legal authorization, or only for people with a particular citizenship or the proper morality. The technology just doesn't work that way.

If a backdoor exists, then anyone can exploit it. All it takes is knowledge of the backdoor and the capability to exploit it. And while it might temporarily be a secret, it's a fragile secret. Backdoors are how everyone attacks computer systems.

This means that if the FBI can eavesdrop on your conversations or get into your computers without your consent, so can cybercriminals. So can the Chinese. So can terrorists.
I am sympathetic to his privacy goals, but sooner or later the public is going to figure out this argument is incorrect. Backdoor technology is feasible.

The SSL/TLS protocol that everyone uses for secure web pages has backdoors. There are about 150 root certificates with super-secret keys in private hands. If a bad guy got access to one of these and intercepted web traffic, then he could subvert the system.

The system depends on the holders of these super-secret keys keeping them secret. No, they cannot be guessed and they are extremely difficult to steal. Some bad certificates have been issued, but the system works pretty well.

The US Govt can and does keep some military secrets very well.

Nate Cardoza, a staff attorney for the EFF, said on NPR Radio Ashbrook On Point:
Every computer scientist, every mathematician, every cryptographyer that has looked at the question has said: You cannot give the FBI what it is asking for here without endangering the security of all of us.
No, this is false.

Apple's main argument against the current subpoena is that it would be burdensome to assign a programmer to spend a couple of weeks supplying what the FBI wants. (Apple also argues that it has a free speech right to not comply with federal regulations, but I cannot see a court accepting that.)

Once Apple customizes its unlock program for the FBI, Apple complains that it will have no good argument against future subpoenas. That is, the work will have already been done, and so Apple cannot claim that it is burdensome.

Apple has a crappy argument. It makes about $200B a year on iphones, so I don't see how it can be burdensome to spend a couple of programmer-weeks to comply with the FBI. It is spending millions on lawyers and public relations on this issue.

I am all for individual privacy rights. But Apple is anti-privacy, and is fighting this on the basis of maximizing its profits. Apple has conned the public on this issue, and conned the leftist privacy groups as well.

Famous Israeli crypto expert Adi Shamir sides with the FBI over Apple.

I do not think that the govt should force any backdoors, but when companies like Apple put backdoors in for business reasons, they should comply with govt warrants.

Friday, March 04, 2016

Stanford crypto boys get Turing Award

The NY Times reports:
Mr. Diffie would spend the next several years pursuing that challenge and in 1976, with Martin E. Hellman, an electrical engineer at Stanford, invented “public-key cryptography,” a technique that would two decades later make possible the commercial World Wide Web.

On Tuesday, the Association for Computing Machinery announced that the two men have won this year’s Turing Award. The award is frequently described as the Nobel Prize for the computing world and since 2014, it has included a $1 million cash award, after Google quadrupled its size.
Some later developments by MIT professors (RSA) got a Turing Award in 2002.

It is strange for the ACM to omit credit to their Stanford colleague, Ralph Merkle. Merkle independently invented public key cryptography and submitted it to an ACM journal, but the journal refused to publish it for several years.

I happened to get the inside story on this, when Merkle and were on opposite sides of a lawsuit. I read all of his rejection letters. One letter criticized him for not having any references to previous work in the field. He wrote back that there had been no work in the field because he was solving a problem that no one had ever considered before.

One referee report said that he had a simple advance in computational complexity, but that he should omit all the fluff about computer security.

That fluff about computer security is the basis of most computer connections today.

The MIT/RSA work seems to be more famous, and got the Turing prize 13 years earlier. But the Stanford-Diffie-Hellman-Merkle work was earlier, more fundamental, and had all the essential ideas for SSL/TLS secure computer connections.

Considering that the ACM cheated Merkle out of credit by rejecting his brilliant paper, it should have made up for it by making him a co-winner of the Turing Award.

Thursday, February 25, 2016

Cook doubles down for Apple backdoors

Apple's Tim Cook has doubled down in its protection of a dead Moslem terrorist. NPR radio reports:
"The only way to get information — at least currently, the only way we know — would be to write a piece of software that we view as sort of the equivalent of cancer. We think it's bad news to write. We would never write it. We have never written it — and that is what is at stake here," Cook said. "We believe that is a very dangerous operating system."

The government has said that the software key would be limited in scope, but Cook rejected that characterization.

"This case is not about one phone. This case is about the future," Cook said. "If we knew a way to get the information on the phone — that we haven't already given — if we knew a way to do this, that would not expose hundreds of millions of other people to issues, we would obviously do it. ... Our job is to protect our customers."

Following the federal magistrate's ruling, Cook posted a statement on Apple's website which argued the government was effectively ordering Apple to put its customers at risk by compromising their privacy. "We can find no precedent for an American company being forced to expose its customers to a greater risk of attack," Cook wrote.

But that's not exactly true, NPR tech reporter Aarti Shahani says.
Yes, Cook is lying.

Cook pretends that he is standing for customer ownership of its own data, for privacy, and against universal crypto backdoors, but the truth is the opposite.

In this case, the customer is a state agency, and it wants its own data. Cook is refusing. The terrorist is dead, and has no privacy rights.

According to published reports, Apple has the ability to update the firmware of a particular iphone by using a digitally signed data file that is customized for the serial number of that phone, and such that the update will not work on a phone with any other serial number. The signature prevents the file from being modified to work on another phone. So the update file could not be used for any other purpose by the FBI or anyone else. It also has been reported that Apple could do tne update itself, so the FBI does not need to get that update file.

Assuming that is true, then Cook is lying and no other users or phones are at risk. If it is not true, then Apple has specifically engineered the phone to have a universal backdoor. No one ever required Apple to have a universal backdoor, so it would have had to make a deliberate decision to do that for its own business purposes.

So Cook's position is that Apple and Apple alone owns customer iphone data, and that it has the right to install backdoors for its own business purposes while thwarting a Moslem terrorist investigation.

Cook's previous political stances have all had to do with promoting LGBT activism and his own homosexuality. But he does not really stand for individual gay rights, and instead stands against the religious freedom of others. He is a leftist creep who wants everyone else to be forced to accept his gay-leftist values.

Cook is damaging the cause of personal data privacy. Cook is going to lose this court case, and the public is going to conclude that Apple is being unreasonable. The privacy organizations are controlled by leftists who have been baited into supporting Apple, and that means they are against any sort of real personal data autonomy. Leftism is all about control, and Apple wants control of your data.

Rush Limbaugh is an Apple fanboy, and he suggests that Apple may configure the upcoming iphone 7 so that the user can set a password that not even Apple is able to break. That would be legal for Apple to do, even if it loses the current case. Whether Apple chooses to do this is purely a business decision, Rush says, but Apple may not do it because of the unhappy customers who forget their passwords. Apple does not want to lose those customers.

I do not know whether Apple's business interest is to offer genuine privacy in the iphone 7 or not. But it does not make any sense to me to have a system where Apple can recover data, but the FBI cannot see that data in a court-ordered Moslem terrorist investigation.

Wednesday, February 24, 2016

Polls favor the FBI over Apple

A new Pew poll reports:
As the standoff between the Department of Justice and Apple Inc. continues over an iPhone used by one of the suspects in the San Bernardino terrorist attacks, 51% say Apple should unlock the iPhone to assist the ongoing FBI investigation. Fewer Americans (38%) say Apple should not unlock the phone to ensure the security of its other users’ information; 11% do not offer an opinion on the question.
The poll details are here.

A new Reuters poll reports:
When asked if the U.S. government should be able to look at data on Americans' phones to protect against terror threats, 46 percent agreed, 42 percent disagreed and the rest said they were not sure.
Rush Limbaugh reported this poll as favoring Apple, because it found 46% agreeing with Apple's decision to contest the court order.

It appears to me that the DoJ, FBI, and the judge also wanted Apple to contest this order. The case was chosen as one where Apple was sure to lose in a higher court. All of the circumstantial factors favor the FBI -- the crime was terrible, the guilt is certain, the terrorism inguiry is necessary, it is easy for Apple to comply, it was a government phone, there is no privacy at stake, etc. Both Apple and the FBI seemed to agree to make a big public show of this case.

Apple can lose this case, and use the court decision as a justification for spying on its users. There could well be a lot of people who agree with Apple contesting this case, and then losing it.

Apple is not helping the cause of privacy. It retains the power to spy on us while also thwarting prosecution of Moslem terrorists.

Rush defends Apple on this issue, as he is an Apple fanboy. He regularly praises Apple products, even tho he admits to having to spend many hours each week chasing down bugs and performance issues. He says that his device only last about 4 hours on a full charge, and he has spent weeks trying to figure out what was draining his batteries. His time would be better spent getting Donald Trump elected President. Trump is not siding with Apple and the Moslem terrorists.

Thursday, February 18, 2016

Apple sides with Moslem terrorists

I am a privacy advocate, and I believe that people have a right to private communication, but I cannot agree with Apple in its current FBI dispute. I am relying on this analysis:
Based on my initial reading of the request and my knowledge of the iOS platform, I believe all of the FBI’s requests are technically feasible.
Apple has been telling the public that it does not have the ability to comply with police requests, but that is not what it told the court. It has engineered the iphone to allow itself to break into it.

There is no real privacy issue in this case. The phone was a govt phone being used by an Islamic terrorist. The phone's contents should be available to the employer, a state govt agency.

Apple and Google take the position that they have a right to your data, but they also have a right to not comply with FBI investigations. They are putting their own business interests ahead of both privacy and law enforcement.

American law has always held that individuals do not have to testify against themselves in a criminal case, but any evidence in the hands of others can be subpoenaed for use in court (with rare exceptions, such as attorney-client privilege).

In this case, it is possible that the suspect used an option for a long alphanumeric password to protect the data. If so, then maybe Apple cannot the data, and some other issues might be in play. But as it stands, I cannot see any good legal reason for Apple to refuse.

Separately, Google has just announced that it is ceasing its service for offline photo editing, and requiring its users to upload all their photos to Google servers. It is motivated by the fact that its AI servers can now spy on those photos and pull valuable info for its advertisers. Maybe this is an efficient business arrangement, so I have no quarrel with that. But people should know that Google sometimes reports illegal activities to law enforcement, and has a legal obligation to comply with subpoenas.

A Si Valley newspaper story says:
The government is asking Apple to hack our own users," Cook said starkly.

Sundar Pichai, the chief executive of Google, which makes the popular Android mobile operating system, tweeted Wednesday afternoon that "forcing companies to enable hacking could compromise users' privacy."

He also said that "requiring companies to enable hacking of customer devices & data" could be "a troubling precedent."

Of course, the government has a legitimate interest in the contents of Farook's iPhone. It wants to fully solve a crime and prevent others.

Yet, if Apple is forced to come up with a way to unlock it, will a line be irrevocably crossed?

I think so.
No, this is misleading pro-Apple editorializing. Apple would not be hacking its users. It would be using an Apple-designed feature to recover data for its customer, the state agency.

I guess Cook wants to help gays keep their gay lovers secret, but this is not the way to do it.

Update: It has now been revealed that Apple has complied with dozens of similar FBI requests in the past. The difference this time is that the case is public, and Apple has business reasons for denying its ability and willingness to spy on its users.

Tuesday, December 15, 2015

Feds refuse to look at terrorist Facebook pages

I posted below about academic leftists pretending to take a great and good moral stance by opposing govt surveillance. Now we have a good example of how such stances are killing people. ABC News reports:
Fearing a civil liberties backlash and “bad public relations” for the Obama administration, Homeland Security Secretary Jeh Johnson refused in early 2014 to end the secret U.S. policy that prohibited immigration officials from reviewing the social media messages of all foreign citizens applying for U.S. visas, according to a former senior department official.

“During that time period immigration officials were not allowed to use or review social media as part of the screening process,” John Cohen, a former acting under-secretary at DHS for intelligence and analysis. Cohen is now a national security consultant for ABC News.
I am all in favor of privacy and civil liberties, but we have jihadi Ialamic terrorists applying for visas to come to the USA, and declaring their allegiance to ISIS on their Facebook pages, and our immigration officials are not allowed to check it out!

This is really sick. People are saying that it is against common sense, but that understates the problem. We have shitlibs, cuckservatives, and leftist elites who are doing everything to destroy this country. I hate to think what electing Hillary Clinton in 2016 could do.