Category Archives: Security

Surveillance is the new black

Many moons ago, 1991 to be exact, I found Ivar being installed in Macintosh labs. It was an extension to System 6 that gave remote control of the audio. The attacker had to use a fake “bomb” prompt to get users to restart their system and load the extension (a camouflaged opt-in method), but otherwise it was a silent and easy way to listen and even speak to remote users without them knowing.

I treated it as malware and removed it, but lets just say it also was great for practical jokes.

“This is your computer speaking…I need a break! Please shut me down.”

This WEEK in TECH (TWiT) now reports similar surveillance “apps” for smart phones have been found in the wild. Today, however, it is no laughing matter as apps are developed and driven by large marketing companies who intend to surreptitiously collect as much information as possible because (ironically) they don’t really know who they are dealing with.

Robert Scoble …it actually is listening to the audio, it’s not recording audio but it’s recording a fingerprint of the audio signature of the room.

Becky Worley What?

Robert Scoble So you can tell. Yeah here is why they’re doing that. He says that what we’re trying to do is make it possible for a lot people to go to, let’s say, a Lady Gaga concert and all these shooting pictures will know where the performer is because everybody is aiming at the same place and we’re listening to the audio signature of the room to join everybody into a one Color space and they expect to be able to show you why the closest picture that’s being taken of that event.

Leo Laporte Oh that’s interesting.

Robert Scoble So if somebody is in the front row, the big people in the back row will see pictures that the front row is shooting.

Leo Laporte What do you think of the argument that that is all a red herring and that really the reason they got $41 million is because they figured out a way to collect all sorts of info – it really scares me that they got the mic on, all sorts of information about their users which they will be able to sell, I mean it’s – there’s no sense in the $41 million unless you assume they are up to something clever.

That’s a lot of lettuce just to spy on random people. I wonder if the Shazam app developers are double-checking their ethics.

The TWiT team clearly object to the opt-out surveillance of these new apps; they even call it a flaw in Apple security! Heh, well, users are choosing to download and install them. Unlike the Ivar extension, where we had to infiltrate a system the old fashioned way, surveillance now is being engineered as a service — bundled with a giant carrot.

Leo Laporte I have to tell you I – as soon as I thought about it for half a minute I erased Color immediately and I would recommend anybody who listens this show to immediately erase that program.

Brian Brushwood Nobody under 25 will hear that advice, that’s…

Leo Laporte Because there is a – now that I know that it’s also doing sound analysis, that really creeps me out. This is a real flaw in Apple’s permissions system, at no point where we informed that this program was turning on the microphone. I don’t care if they say they’re not using it they’re turning on the microphone in my phone and they never told me that. That’s bad news.

Robert Scoble Well I told you on my show on Thursday.

Becky Worley They didn’t tell me that when I downloaded the Grey’s Anatomy iPad app.

Leo Laporte What? It listens to YouTube?

Becky Worley It listens to the TV to figure out where it is in the show so that it can sync, it simulcast of iPad information to where you are in the show.

Brian Brushwood Wow.

Ok, this is where I put on my giant hat of contrariness.

I predict people under 25 not only anticipate this better than those who are over 25, they already have more natural countermeasures from growing up within the system.

Humans have a natural instinct for freedom of thought. It is nonsense to suggest that those under 25 lack the desire to resist authority.

Those who are raised under a constant surveillance threat will more easily adopt methods like phone swapping, temporariness, and sharing. They will intentionally break the bonds of information that older generations have a hard time protecting or letting go.

In other words, the first generation to taste the surveillance carrots probably will see something worth the trade-off in privacy — even if it is just to do something cool and new and different. Subsequent generations will not be so easily fooled.

PCI DSS Effective – According to Breach Reports

The new data is in. When I presented for the PCI Security Alliance and SafeNet at RSA in 2009 I used breach data in datalossdb.org to show that PCI DSS was working and we could prove it.

The following two reports explain this trend in much greater detail. I will handle them individually later, but for now here are a couple highlights:

Verizon has posted the “2011 Data Breach Investigations Report

After four years of increasing losses culminating in 2008’s record-setting 361 million, we speculated whether 2009’s drop to 144 million was a fluke or a sign of things to come. 2010’s total of less than four million compromised records seems to suggest it was a sign.

Imperva has posted “PCI’s Impact on Security Quantified

PCI is very effective in reducing breaches but it seems many companies don’t believe it.

USAID sends Elmo to Pakistan

You might have noticed my post the other day about USAID.

The agency is “waiving” iPads through security requirements straight into field use by government officials.

I wondered what they possibly could be doing with the iPads, besides trying to annoy Secretary of State Clinton. Now I get it. They have drafted Elmo into service.

U.S. officials are taking a different approach, hoping that “Sesame Street” can instill education values in very young Pakistani children, arming them with the learning tools to fend off extremism later in life.

[…]

The format will be largely the same as the U.S. version, with each episode highlighting one letter and number for children to learn. Like the U.S. version, the program will also have strong female characters, with the subtle aim of promoting tolerance and gender equality. But it’s not slated to touch on any political themes outright.

Slated to touch? If that’s not a giant hint, I don’t know what is. Elmo needs a distribution channel. I mean how will Elmo reach all those impressionable children across rural Pakistan?

Obviously iPads (slates with touch) will be dropped from the sky. Elmo will be playing on them as they fall, saying “I come without any political themes outright”.

This sounds a lot like the modern equivalent of Para leer al Pato Donald (How to Read Donald Duck) published in Chile in 1972

…the world shown in the comics [sent to Latin America from the US], according to the thesis, is based on ideological concepts, resulting in a set of natural rules that lead to the acceptance of particular ideas about capital, the developed countries’ relationship with the third world, gender roles, etc.

Phase two, after the youth Elmo-isation is complete, US soldiers will deploy in Elmo suits to blend in and win local support.


Look Mr. Chief! Look Everybody! Elmo is your friend!

FlyNano Safety Concerns

The recent announcement of a recreational ultralight aircraft in Europe called FlyNano has raised some concerns about safety. Critics doubt whether the “Harley of the Sky” can really avoid a pilot license requirement just because of its weight.

It is in truth more of a flying jet-ski than a motorbike, since it can only land on water, but its unique quality is its weight – at just under 70 kilos (154 pounds), it beats certain international regulations for license-only aircraft. This could potentially make it the ideal option for the recreational flyer who lacks the means to get a full pilot’s license.

FlyNano

Unlicensed inexpensive planes that take-off and land on water? I can see half of Tiburon trying to commute to San Francisco with these across complex shipping lanes and weather patterns. What could go wrong? Perhaps if it really takes off (pun not intended) in popularity they should rename it the jet-flea.