Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Thursday, February 25, 2016

Apple's on the right side of this one




"There is nothing new in the realization that the Constitution sometimes insulates the criminality of a few in order to protect the privacy of us all."

A quote from a Supreme Court Justice known for being so conservative that Pat Buchanan looks like flower child by comparison. 

He got it, so why doesn't the FBI?

Yes I'm talking about Apple and more specifically Tim Cook's refusal to assist with the unlocking of an Iphone connected to the San Bernardino terrorist case. 

Over the past week or so I've watched as the FBI, Justice Department and other members of law enforcement trot out the same tired straw man of national security that gave us the Patriot Act.

Their argument is still just as flawed.  Worse it's still based on a fundamental misunderstanding of technology that heralds from the days of floppy disks and dial-up modems. 

The media coverage hasn't helped either by incorrectly framing the controversy as the loss of a "back door" in the previous incarnation of IOS ( IOS 7).    "Back doors" are the stuff of 80's flicks like Wargames and Tron not 21st century mobile devices.

Before IOS 8 it's true that Apple did have the capability to unlock an encrypted phone after being presented with  the proper legal documents.  Which was exactly the position Apple didn't want to be in.  By which I mean being constantly pestered by requests to invalidate Apple's own security features. Not exactly good for business and definitely counter to a more progressive view of the world.

So with the advent of IOS 8 Apple removed this capability (and themselves) from the equation by eliminating the code that allowed them to unlock an encrypted phone.  Well, at least that's what they thought until San Bernardino happened.

Law enforcement has long wished for a more "limited" interpretation of the fourth Amendment.  In their view we'd all be so much safer if only they could just flip a switch and listen in on the bad guys at a moment's notice. 

"The nine most terrifying words in the English language are: I'm from the Government, and I'm here to help."

They stop just short of levying charges of treason when denied such powers but never miss an attempt to try to shame Apple (or anyone else that offers some deference to privacy rights) into compliance by claiming such defiance of the "Rule of Law" only helps criminals and terrorists.

"If Apple wants to be the official smartphone of terrorists and criminals, there will be a consequence"

Here's the core of the problem....

"Power tends to corrupt and absolute power corrupts absolutely"

Nobody is suggesting that criminals or terrorists should be allowed to run about unhindered.  But what happened to good old fashioned detective work?  Edward Snowden's revelations may now be called "exaggerated" but the fact remains that there's ample resources available to law enforcement without potentially short circuiting the 4th Amendment.

The country was founded on a system of checks and balances for a reason.  It extends not only to the three branches of government but little stuff like trial by jury and the right to not incriminate one's self.

You're a fool if you believe that anyone with unfettered access to your private data isn't going to abuse the privilege. 

Remember Richard Nixon?  He had to leave the presidency precisely because of just such an abuse of power.  He felt benevolent leadership required keeping tabs on everybody.

Nobody thinks about individual liberties until their own is threatened. 

Hey, I'm not a big fan of Apple or their products.  Personally I don't care much for benevolent overlords that reign over walled gardens.  So I find it ironic that Tim Cook is on the right side of this issue.

Perhaps it's because he understands the difference between selling products and selling out civil liberties.


A distinction the FBI chooses to ignore.

Wednesday, February 18, 2015

Commercials: Barometer of a society


Have you been watching TV lately?

I don't mean becoming one with your comfy couch binging on entire seasons of Game of Thrones.  No I'm talking about plain old TV, commercials and all.

In a world where just about everything is on Demand from your dinner to your favorite sitcom you probably haven't noticed the latest trends in advertising.  With the curated experience of services like Netflix and Amazon Instant video you'd be excused if you haven't seen a commercial in months.

The vast majority of viewers, however, aren't completely detached from the advertiser-driven TV experience.  That means there's still an audience to watch somebody's commercial.  

Regardless of how irrelevant they may be to you, commercials aren't created in a vacuum.  Whatever they're selling,  you can be sure somebody wants it.

Ok, so we're all used to ads from everything from cars we can't afford to phones we don't really need and food we really shouldn't be eating.  I don't care about those.  I'm more interested in the filler commercials.  The ones about things like prescription drugs and ambulance chasing attorneys.  The ones you see far more often.

In the past few years I've seen more commercials about one-off gambling casinos, lottery games, settlement funding and prescription drugs for every ill than anything else.  Even the ambulance chasers have upped their game from simple fender-bender litigation to multi-billion dollar payouts from big pharma.

That there are so many means the U.S. isn't as much about consumption anymore.  It's more about want.  We're underpaid, poorly fed and sick and we can't seem to find relief.

We can't count on much these days.  Careers are transient and so are people.  It seems the ground is ever shifting under our feet. 

They sell us the promise of stability, the righting of a wrong or just something to make us feel a little better about our situation.

Maybe that's the classic advertising formula, sell a belief instead of a product.

The trouble is, what they sell is a reflection of the world we live in.  A world where needs can only be met by indebtedness to monoliths that profit from continuing our suffering.

We want the lottery win, the big settlement, the freedom from worry and want.  That desire has become an industry in itself.

We are a country forever searching for the light at the end of the tunnel but the tunnel never ends.  The joke has long been that the light is an oncoming train.  That's wrong.  Were that the case at least there'd be some hope of an end but the light seems ever out of reach.

So am I making too much out of a bunch of stupid ads? 
I don't think so. 

If the "product" is security and freedom from want then it stands to reason that those are commodities we're sorely lacking.  I don't find it acceptable to be "sold" on a dream of self-sufficiency.  I shouldn't "need" a mason jar full of pills to live another day or settlement funding to catch up on my bills. 

Trading on fear is a dark negotiation. 

Not the mark of a healthy society.


Think about it...

Tuesday, January 14, 2014

Maricopa Community Colleges: An "insecure" letter...



Got a letter the other day and it said this...

"On October 19th, 2013 we determined that your information including: your name, address, phone number, e-mail address, Social Security number, date of birth, certain demographical information and enrollment, academic and financial aid information may have been accessed without authorization.  The system did not contain credit card information or personal health information."

Oh, well that's a relief, at least they didn't get the credit cards...Oh wait, did I shop at Target last month?

The Maricopa Community College District (MCCD) is the largest community college district in the state of Arizona and one of the largest in the nation serving  over 200,000 students every year. 

I signed up for a class with them once.  I know I applied for employment on more than one occasion as well.   Why anyone needed an SSN or Date of Birth for either considering I was never employed or completed that class is a mystery.

There's other far less personal information that can identify a person and cause far less damage if compromised.  Ahh, but I forgot, in the post 911 era we're expected to lay ourselves bare trusting that the recipients of our most personal of information will be good stewards.  Of course, all in the name of security.

Which makes it ironic that "security" is the very thing that's failed us.

They didn't get the credit card information... Who cares!  Whomever benefitted from this "info-heist" now has enough information to create scores of false identities and cause irreparable harm to the victims of the breach.

People get a bit too cavalier about their personal information sometimes.  I live in Arizona and around the time I was getting my first driver's license, the state actually encouraged motorists to use their SSN as their driver's license number.  Of course that was back in the day when credit card numbers were stolen off discarded carbon paper not the Internet.

People are admonished to carefully control access to their private information but increasingly we're asked to give that responsibility over to private and public institutions that aren't worthy of that trust.

It needs to stop.  Along with credit checks on job applications and the requirement to give your SSN for anything but obtaining a loan or starting, not applying for,  a new job.  In those cases at least you know the chain of custody of your information.

It's your PERSONAL information and you shouldn't be ostracized for protecting it.  Especially when those demanding it obviously can't be trusted to keep it safe. 


Support measures like Senator Elizabeth Warren's "Equal Employment for All Act" that blocks the requirement for credit reports on job applications.  That measure would also prevent the haphazard collection of SSN's and other personal information as well.

Sunday, September 15, 2013

If technology is the tool, why am I the one getting used?


Technology's great isn't it. 

"There's an app for that" and increasingly there's hardware for it. too.  The next decade promises an explosion of technical doodads that will be able to do anything from having your favorite latte' ready when you wake to alerting you to failing health.

Ain't it grand.  Our entire lives, every need, every whim, every action collected, recorded, monitored and stored.  Today, a newborn baby can expect a record of everything they've ever done from cradle to grave.

How convenient, how secure, how exciting this gilded cage we're making for ourselves.  Until we found out about the antics of the NSA recently, the concept could be brushed off as the ramblings of a crank.  Regardless of the level of technical expertise governments may or may not have, the event shocked a technology addicted populace even if only for a moment.

For the next few months at least, anyone selling anything with the word "privacy" is sure to do well until the next shiny bauble comes along.

Short of an EMP pulse from space knocking us back to the 19th century, change never happens overnight.  It's gradual no matter how exponential Moore's law becomes.  Today it's a fingerprint reader on an Iphone or the convenience of storing your private data in the cloud.  Most people wouldn't give a second thought to what it really means to swap out an Android phone and find all their personal data and settings automatically downloaded to its replacement. 

It's just  cool because it's so convenient.  Never mind someone else has control of your stuff...

All you have to do is stress the utility of that new toy and privacy goes out the window.  That anyone who uses a  Smartphone expects the data on it to be private in the first place is laughable but they do. 

 You can choose not to participate but soon find yourself ostracized.  Socialization, personal economy and even careers increasingly demand you jump on the bandwagon.

Technology isn't a bad thing so long as it remains a tool but it seems we're moving toward an age where the tool is used against us.

Consider a world where your smartphone snitches to your health insurance company via its NFC payment capability while your car verifies your location via GPS.  There's no denying it, you got the supersized fries and your health premium is going up because of it.

Consider your car insurance company monitoring every mile and basing your premium on what they find out.  It's already happening with at least one major insurance carrier.

Maybe you get a discount for driving 5 miles under the speed limit and ordering the salad instead of the burger.  That makes it all ok, right?

It's the small changes in what is considered acceptable that gradually erode personal freedoms and liberties.  Consider that for your discounted premiums you've essentially subjected yourself to a set of values you may not share.  As it becomes a more accepted practice you become more powerless.

Companies are essentially demanding compliance from their customers.  What happened here?  Since when does a customer have to justify themselves to  the cashier?

It's simple really. 

You're a prisoner, worse, you pay dearly for the privilege while the whole time doggedly defending your right to treated as such.

Technology is seductive, slowly evolving our dependency to the point where it's inconceivable for most to live without it.  We're convinced we need it even if we don't.  We must be continually connected and have instant access to everything.

We even create workflows of nonsense just to justify having it.  Is it really that important to be able to talk to Google?  What if all your queries were recorded, compiled and used to create a profile about you that you knew nothing about?

The sad fact is that the services we rely on often don't have our best interests at heart.  Profit and  Philanthropy make poor bedfellows.  So does power.

Once governments discover this voluntary abdication of civil liberties it's nothing for them to exercise control over our cherished providers of our technological fix.

And it is a fix.  If you can't imagine a day without your smartphone you're just as addicted as anyone on crack cocaine.  You think you need it but in reality you don't.

Technology is a tool but there's no reason you should allow yourself to be used by it.  Get your context straight and you won't have to worry about privacy or security.