HN user

eivarv

1,131 karma

Privacy engineering and security research. Cyber Security Manager with background as software developer and architect.

Norway.

https://www.eivindarvesen.com

eivind dot arvesen at gmail dot com

https://github.com/EivindArvesen

https://twitter.com/EivindArvesen

Posts37
Comments491
View on HN
arxiv.org 4y ago

Echos Are Heard: Tracking, Profiling, and Targeting in the Amazon Ecosystem

eivarv
1pts0
www.whitehouse.gov 4y ago

US and EU Commission Joint Statement on Trans-Atlantic Data Privacy Framework

eivarv
2pts1
arxiv.org 4y ago

Bugs in Our Pockets: The Risks of Client-Side Scanning

eivarv
4pts1
techcrunch.com 5y ago

International coalition joins the call to ban ‘surveillance advertising’

eivarv
2pts0
www.forbrukerradet.no 5y ago

In­ter­na­tio­nal coalition calls for AC­tion against surveil­lance-based ad­s

eivarv
3pts2
www.reuters.com 5y ago

Norway's parliament hit by new hack attack

eivarv
2pts0
www.eivindarvesen.com 5y ago

SSL/TLS-Decryption and the GDPR

eivarv
1pts9
www.eivindarvesen.com 5y ago

My reflections on Smittestopp (Norwegian Covid-app)

eivarv
2pts0
www.eivindarvesen.com 6y ago

A rose by any other name – Norwegian parliament passes mass surveillance bill

eivarv
2pts0
www.eivindarvesen.com 6y ago

Smittestopp – Summarizing the expert group report on the Norwegian Covid-19 app

eivarv
2pts0
www.eivindarvesen.com 6y ago

Smittestopp – Summarizing the expert group report on the Norwegian Covid-19 app

eivarv
1pts0
news.ycombinator.com 6y ago

Ask HN: Disease Tracking Privacy Issues

eivarv
2pts0
www.bbc.com 6y ago

UK coronavirus app 'must respect privacy rights'

eivarv
1pts0
securitylab.github.com 6y ago

GitHub Security Lab

eivarv
4pts0
www.theregister.co.uk 6y ago

Stallman's final interview as FSF president

eivarv
2pts0
stallman.org 6y ago

RMS Quits GNU Project

eivarv
70pts24
cleave.app 6y ago

Show HN: Cleave (coming soon) – Enabling human context switching

eivarv
1pts1
cleave.app 7y ago

Show HN: Cleave (coming soon) – Enabling human context switching

eivarv
2pts2
eivind88.github.io 7y ago

Terroriser – Why the Counter-Terrorism and Border Security Bill Is Dumb

eivarv
1pts0
www.eivindarvesen.com 7y ago

Lucene Indexes and GDPR

eivarv
1pts0
www.eivindarvesen.com 7y ago

Lucene Indexes and GDPR

eivarv
2pts0
www.eivindarvesen.com 7y ago

Elasticsearch and GDPR

eivarv
1pts3
www.eivindarvesen.com 7y ago

Elasticsearch and GDPR

eivarv
1pts1
github.com 7y ago

Show HN: Dankenstein – Markov Chain Twitter Bot Generator

eivarv
72pts4
www.eivindarvesen.com 8y ago

Paging Dr. Dankenstein

eivarv
2pts0
www.nytimes.com 8y ago

What Is Sadness, and What Is Depression?

eivarv
2pts0
www.eivindarvesen.com 9y ago

Opening Sublime Text Settings in a Standard Tab

eivarv
1pts0
www.youtube.com 9y ago

President Obama: FULL INTERVIEW – Real Time with Bill Maher (HBO)

eivarv
1pts0
translate.google.com 10y ago

Gene mutations pointing toward Alzheimer solution – VG [translation]

eivarv
1pts1
translate.google.com 10y ago

Orange glasses may be the solution for bipolar – NRK

eivarv
1pts1

Yes – and not only for government and organizations:

In 1999, NetBus was used to plant child pornography on the work computer of a law scholar at Lund University. The 3,500 images were discovered by system administrators, and the law scholar was assumed to have downloaded them knowingly. He lost his research position at the faculty, and following the publication of his name fled the country and had to seek professional medical care to cope with the stress. He was acquitted from criminal charges in late 2004, as a court found that NetBus had been used to control his computer.

https://en.wikipedia.org/wiki/NetBus

No, it does not – for two reasons:

  - Two wrongs don't make a right: Someone behaving unethical does not excuse unethical behavior from someone else.
  - There is a difference in the power dynamics of the relationships: Consumer and service provider VS citizen and state.
If anything, laws and right should be strengthened to explicitly ban this behavior.

https://cleave.app

Cleave lets users persist OS state as a "context" - saving and loading all open applications, their windows (and their positions), tabs, open files/documents and so on. Think of it as a workspace or project manager from an IDE, but on the OS-level; Alternatively as "tab-groups", but encompassing multiple apps.

I started working on it because of frequent multitasking of heavy work with limited resources; Made it because I wanted to switch between studying, working, reading, looking for an apartment, etc. without manually managing all states or consuming all resources.

I'll release an Open Beta (macOS) as soon as I finish license verification and delta updates, but I keep getting sidetracked...

In the meantime, I've used various browser extensions to save and restore open tabs.

I find it interesting (particularly from an HCI-perspective) that there hasn't been more research into the concept on an OS-level, as I can think of many times maintaining a set of application states for continued or re-use makes sense.

Yes, if you mean true anonymization – i.e. not pseudonymization (e.g. replacing names with a pseudonym) or in any other way retaining personal data (internal identifiers, usage patterns or attributes that combined result in a unique enough fingerprint to identify a specific person, etc.)

Out of curiosity: How does any argument become more or less logical depending on its context?

Your comment reads to me as if the concept of logical fallacies is only useful or valid within the framework of rhetorical competitions – or alternatively that logically invalid reasoning is useful if you're only interested in making a decision, rather than making a correct or well-informed one.

Exactly – this is currently a regulatory problem, and blockchains, decentralized identity, etc. won't solve anything in this space. On the contrary, it will by definition enable identification in some types of data.

This makes me conclude that these types of solutions are really more about portability and making some sort of political point (the only thing users realistically control is first party authorization – nothing else); They certainly don't have any security or privacy-related guarantees.

    could protect against all sorts of abuse...
Could it, though? What's to stop someone that gains access to user data (by legitimate means) to make a copy?

I wish the field of psychiatry was mature and used different words for depression caused by [...]

Isn't this covered by "situational depression" (adjustment disorder with depressed mood) VS "clinical depression" (major depressive disorder), and the fact that diagnosis entails excluding physical conditions that cause similar symptoms?

None of the various depressive disorders (nor other psychiatric disorders) deal with defining a cause, but with describing a set of symptoms.

    Could someone tell me how that inspection works? Are there researchers who are given the source code?
It doesn't (with the exception of an exclusive program[0]). Not only do they generally make security work on their devices difficult – they have a history of suing companies that facilitate it [1].

[0] https://developer.apple.com/programs/security-research-devic...

[1] https://www.theverge.com/2021/8/11/22620014/apple-corellium-...

That's not an argument that deals with whether climate change is real or not – but whether it's reasonable to believe it is, based on one's own lack of understanding in combination with making (reasonable) assumptions.

I too would trust a climate scientist as a legitimate authority on climate change over a religious leader or a PR person – but that's not what I'm discussing.

I'm saying global warming isn't true because scientists believe it to be true (this would be a fallacious argument).

Does it actually matter?

An argument doesn't get any more or less fallacious based on who believes in it (the authority, in this case) – that's not an argument in itself.

It might be reasonable (a useful heuristic) to lean to the side of the expert, but the fact that an expert believes something doesn't in itself make the conclusion correct.

My own speculation basically boils down to: Human minds are primarily meaning-seeking machines, to such a large extent that we even create meaning where there is none (apophenia).

Take pareidolia, for instance – it's likely been more evolutionary advantageous to see faces where there are none (and thus flee tot often), as opposed to not seeing faces where there are faces (and thus be eaten).

And in evolutionary terms, not everything that exists has some benefit. Some features just haven't been subject to evolutionary pressures; Not selected for, just not selected against. Vestigial features are prime examples of this.

And by extension, fallacious reasoning means that you have no good reason to take what the reasoner is arguing as true (unless they can a non-fallacious argument) – right?

The fact that an argument is fallacious doesn't necessarily mean that the conclusion is wrong, but there does (logically, by necessity) exist (at least) a non-fallacious argument for a correct conclusion.

Compared to virtual desktops, this allows you to close down apps (consume less resources) as well as maintain multiple working context-specific application states.

I'm currently trying to solve this and more in an application called Cleave.

https://cleave.app

Cleave lets users persist OS state as a "context" - saving and loading open applications, their windows (and their positions), tabs, open files/documents and so on. Think of it as a workspace or project manager from an IDE, but on the OS-level.

I started working on it because of frequent multitasking of heavy work with limited resources; Made it because I wanted to switch between studying, working, reading, looking for an apartment, etc. without manually managing all states or consuming all resources.

I'll release an Open Beta (macOS) as soon as I finish license verification and delta updates, but I keep getting sidetracked...

In the meantime, I've used various browser extensions to save and restore open tabs.

One Bad Apple 5 years ago

... but the link between user and photo obviously exists somewhere in Apple's system.

One Bad Apple 5 years ago

Legality aside – how is this not a privacy risk? Privileged users of the infrastructure can gain information about users (whether they possess CSAM that's in the hash-database... for now).

Maybe not, but you could show it to people whose context reveal that they might be interested – e.g. searching for "IDE" or "Elixir", reading about developer tools, etc.

This is known as contextual advertising.

Surveillance is not essential to internet advertising – in fact neither ROI, effectiveness or perceived relevance (when compared to all alternatives, including contextual advertising) has never been proven.

In the cases you list, you have other legal basis for processing than consent – i.e. legitimate interest – but that doesn't mean it's not personal data.

Indeed, IP-addresses are considered [0] personal data in some cases – which only really means that you need to follow the GDPR: have a legal basis for processing, do not process the data for reasons other than that for which you have a legal basis, delete it as soon as you no longer need it, implement protective measures, etc.

[0] https://www.whitecase.com/publications/alert/court-confirms-...

I'm currently trying to solve this and more in an application called Cleave.

https://cleave.app

Cleave lets users persist OS state as a "context" - saving and loading open applications, their windows (and their positions), tabs, open files/documents and so on. Think of it as a workspace or project manager from an IDE, but on the OS-level.

I started working on it because of frequent multitasking of heavy work with limited resources; Made it because I wanted to switch between studying, working, reading, looking for an apartment, etc. without manually managing all states or consuming all resources.

I'll release an Open Beta (macOS) as soon as I finish license verification and delta updates, but I keep getting sidetracked...