GPS data is pretty accurate outdoors, but the second you step inside a store the trace goes completely haywire and bounces round hundreds of meters in all directions. So any warnings will end up so broad as to be useless. Even if just 0.1% of a population are infected, you’ll end up with everyone getting multiple alerts everyday. How does that improve our situation?
Some nuance, but still a biased hit piece. Particularly ugly is when the author dismisses Glenn Greenwald's journalist status, which is beyond doubt, and designates him a mere digital-privacy activist.
The Economist have a history of publishing polarising articles, for and against, regarding Snowden. This book review is likely the work of Edward Lucas (TE's Energy Editor) who has himself written a book alleging Snowden has ties to the FSB (Russian intelligence, formerly the KGB).
I dream about a tool like this every time I need to look something up, which only happens about a hundred times every day. I NEED THIS IN MY LIFE.
But reading the kite.com/privacy doc is absolutely gutting. They copy and keep all your code, permanently. That's fine for an open-source project, but it's a deal breaker for anything else. So thanks for the brilliant idea, but I'll wait for it to be implemented in a way compatible with my everyday workflow.
They're really hitting the "nobody should be above the law" talking point hard. How fortunate for us — it sounds good but doesn't survive even casual scrutiny. Crypto might interfere with investigations, but that is very different from being above the law. There are huge numbers of cases where some perp used encryption and was still bought to justice.
The best analogy I can think of is the document shredder. As a society we accept that individuals can protect their personal privacy and safety even if this occasionally frustrates law enforcement investigations. Shedder manufacturers aren't forced to limit how good a job they do to potentially aid LE as this would do more harm than good. And, after all, if you banned shredders, criminals would still be able to just burn their incriminating papers.
It stinks that the case ended like this — without setting a sensible precedent — but I think there is still some upside:
FBI director Comey's "Going Dark" narrative no longer holds water with anyone who's paying attention. He cried wolf so loud he's been heard on every continent. If and when he tries this again, he'll get a ton more blowback.
Similarly, Obama's jibes about security "absolutism" now appear ridiculous. As are his criticism of impenetrable black boxes protecting child molesters. What he really wants is for the Emmental-like extensions of our brains to have even more holes. That's an obviously un-winnable argument.
Also, the bar for proving you've tried all possible alternatives for gaining access just got a lot higher in applying the All Writs Act. It took three months plus a month of major international news stories specifically about this court case to gain entry — something that might really be impossible to achieve next time. But now everyone knows when they swore under oath many times in multiple public venues that they couldn't gain access, what they really meant was "not yet" and not "it's impossible".
Finally, Apple should now be motivated to remove themselves as the weak link in their security ecosystem. System updates shouldn't be possible without first wiping the information needed to derive the encryption key or first supplying that key. I can also dream about them open sourcing their code to allow security researchers to bug hunt (an impossible dream). And maybe they'll change their minds on bug bounties. Whatever happens, it's now beyond doubt that foreign entities are exploiting vulnerabilities in the iPhone and we all expect Apple to beef up their security accordingly — regardless of how this may hinder law enforcement.
The supposed middle ground is that you force the naval engineers to, against their will, build the submarine with just a few extra holes.
Security is only as good as the weakest link. If you can bypass actual crypto and fallback to the world's justice systems, you've made a catestrophic compromise somewhere. In such a security system any crypto is pure deception. This is untenable in 2016.
"I am leaving it as I found it. Take over. It's yours." Ellis Wyatt
If you feel you're being compelled to act immorally, remember non-compliance — whatever the immediate consequences to yourself — is the only acceptable course of action. When we decide to spend our days building powerful tools, we enter into an implicit agreement not to let them fall into the wrong hands. If the government comes knocking, BURN IT DOWN. Make good on your debt to humanity.
> Should the government be able to access citizen's digital data with a court order? And if so, how can that be enabled without compromising the general security of the device?
No. And that's both impossible and a massive compromise.
This case helps us tackle that first question. Here the murderer's personal phone and computer hard drives were destroyed — rendering them "above/beyond the law". Just because some data is digital doesn't place it in some special legal realm more important than shreddable/burnable paper or the air secret conversations were spoken into. There are fundamental limits to recoverability. If technology companies are to be forced to maintain vulnerabilities because governments see all their customers as potential terrorists, the industry is doomed.
The real problem here is although terrorism will never touch the average citizen anywhere near the extent of other tragedies like illness, accidents or natural disasters, the media treat it like it's the single most important issue — making people fear for their lives is good business. I'd die before sacrificing freedom of speech every time, but the news business just seems too like racketeering. We need to fight the fear.
So why is Microsoft fighting us.gov regarding access to data stored in another country? Isn't that, to the layman, just another variety of ribbon-wrapped box. Gates should know that, just like extra-jurisdictional data retrieval, signed malware data retrieval is dangerous, bad business and awful precedent. He must publicly set the record straight for his company's stance to have any credibility.
See this FT article [1] (a admittedly biased competitor) from late last month. Their cash shrank from £840M to £740M in the last year, and they're planning to cut "costs" by 20%.
That's a tragedy at such a great newspaper, but it does color their analysis regarding the companies most responsible for their decline.
You can almost hear the Guardian's business leader writers rubbing their hands at the prospect. Which is as shameful and shortsighted as it is atypical for the Guardian. I would guess the team behind this article are acutely aware of the rate their owners are burning through cash and are anticipating massive layoffs soon. Perhaps they're looking for a lifeboat with the Apple-despising Financial Times?
Wow. This is the first HN submission to exceed 5,000 points!
To honour Tim, and his advocacy for our industry, I'm going to spend the rest of my week developing privacy/security projects. I encourage everyone else to do likewise.
Ludicrous authoritarianism masquerading as a solution to a problem.
Given that all laser pointers fall into a couple of very narrow bandwidths, surely it would be more practicable to filter these at the cockpit window. That way you solve the problem in every country where you fly your plane and also deal with the billions of laser diodes already in circulation that are essential most aspects of our modern existence. But that would cost air carriers directly, not the public, so I guess it's unacceptable to them.
Why 9? It's spookily reminiscent of the "Nine Eyes" organisation who're the Orwellian bad guys in the latest Bond film, but I see no technical reason the keys cannot be split between 8 or 10 parties. And how much more security do multiple identical servers provide? If one can be hacked — which is frankly a given — so can all the rest.
There is nothing in this article that makes me think a system of split keys is any more desirable than when FBI Director Comey proposed the same thing last year. It's just a bit more terrifying coming from the so-called "Father of Online Anonymity".
This is like in WWII, when Churchill and Turing gave so many newspaper interviews re: how awful it was they couldn't crack Hitler's encryption anymore that he finally gave in, went back to the 3-rotor Enigma machines and we won the war.
Think about what happens when you hit theverge.com: 40-odd requests sent sites you've never heard of. So-called internet connection records are a huge mess of noise even without considering obfuscation.
It is trivial for anyone to embed hidden iframes or send silent ajax requests to child abuse and terrorist forums without giving the visiter the slightest clue what's happening. In the case of iframes, there would probably be cached 'evidence' left on the target's pc. Try explaining that as your defence in court when you get set up by some script kiddie.
The London Times got a guided tour of a the once-secret UK intelligence headquarters and left behind their journalistic integrity. They are being used to disseminate propaganda ahead of the introduction of draconian surveillance legislation. "Snowden did enormous damage", "tiny bit of data", "only metadata", etc.
Letting in a journalist is an astute move on behalf of GCHQ and the government, but, in this instance, they have accidentally chosen a stenographer instead. The absence of a single challenging question regarding the dangers of mass-surveillance is embarrassing.