GPS data is pretty accurate outdoors, but the second you step inside a store the trace goes completely haywire and bounces round hundreds of meters in all directions. So any warnings will end up so broad as to be useless. Even if just 0.1% of a population are infected, you’ll end up with everyone getting multiple alerts everyday. How does that improve our situation?
HN user
p01926
Some nuance, but still a biased hit piece. Particularly ugly is when the author dismisses Glenn Greenwald's journalist status, which is beyond doubt, and designates him a mere digital-privacy activist.
The Economist have a history of publishing polarising articles, for and against, regarding Snowden. This book review is likely the work of Edward Lucas (TE's Energy Editor) who has himself written a book alleging Snowden has ties to the FSB (Russian intelligence, formerly the KGB).
Does anyone know where to find a copy of the torrent DB? I think kat had copies on their app page, but the new mirrors omit this.
I dream about a tool like this every time I need to look something up, which only happens about a hundred times every day. I NEED THIS IN MY LIFE.
But reading the kite.com/privacy doc is absolutely gutting. They copy and keep all your code, permanently. That's fine for an open-source project, but it's a deal breaker for anything else. So thanks for the brilliant idea, but I'll wait for it to be implemented in a way compatible with my everyday workflow.
They're really hitting the "nobody should be above the law" talking point hard. How fortunate for us — it sounds good but doesn't survive even casual scrutiny. Crypto might interfere with investigations, but that is very different from being above the law. There are huge numbers of cases where some perp used encryption and was still bought to justice.
The best analogy I can think of is the document shredder. As a society we accept that individuals can protect their personal privacy and safety even if this occasionally frustrates law enforcement investigations. Shedder manufacturers aren't forced to limit how good a job they do to potentially aid LE as this would do more harm than good. And, after all, if you banned shredders, criminals would still be able to just burn their incriminating papers.
It stinks that the case ended like this — without setting a sensible precedent — but I think there is still some upside:
FBI director Comey's "Going Dark" narrative no longer holds water with anyone who's paying attention. He cried wolf so loud he's been heard on every continent. If and when he tries this again, he'll get a ton more blowback.
Similarly, Obama's jibes about security "absolutism" now appear ridiculous. As are his criticism of impenetrable black boxes protecting child molesters. What he really wants is for the Emmental-like extensions of our brains to have even more holes. That's an obviously un-winnable argument.
Also, the bar for proving you've tried all possible alternatives for gaining access just got a lot higher in applying the All Writs Act. It took three months plus a month of major international news stories specifically about this court case to gain entry — something that might really be impossible to achieve next time. But now everyone knows when they swore under oath many times in multiple public venues that they couldn't gain access, what they really meant was "not yet" and not "it's impossible".
Finally, Apple should now be motivated to remove themselves as the weak link in their security ecosystem. System updates shouldn't be possible without first wiping the information needed to derive the encryption key or first supplying that key. I can also dream about them open sourcing their code to allow security researchers to bug hunt (an impossible dream). And maybe they'll change their minds on bug bounties. Whatever happens, it's now beyond doubt that foreign entities are exploiting vulnerabilities in the iPhone and we all expect Apple to beef up their security accordingly — regardless of how this may hinder law enforcement.
The supposed middle ground is that you force the naval engineers to, against their will, build the submarine with just a few extra holes.
Security is only as good as the weakest link. If you can bypass actual crypto and fallback to the world's justice systems, you've made a catestrophic compromise somewhere. In such a security system any crypto is pure deception. This is untenable in 2016.
"I am leaving it as I found it. Take over. It's yours." Ellis Wyatt
If you feel you're being compelled to act immorally, remember non-compliance — whatever the immediate consequences to yourself — is the only acceptable course of action. When we decide to spend our days building powerful tools, we enter into an implicit agreement not to let them fall into the wrong hands. If the government comes knocking, BURN IT DOWN. Make good on your debt to humanity.
There's a similar game on iOS — Infinite Primes.
https://itunes.apple.com/us/app/infinite-primes/id1063881848...
Should the government be able to access citizen's digital data with a court order? And if so, how can that be enabled without compromising the general security of the device?
No. And that's both impossible and a massive compromise.
This case helps us tackle that first question. Here the murderer's personal phone and computer hard drives were destroyed — rendering them "above/beyond the law". Just because some data is digital doesn't place it in some special legal realm more important than shreddable/burnable paper or the air secret conversations were spoken into. There are fundamental limits to recoverability. If technology companies are to be forced to maintain vulnerabilities because governments see all their customers as potential terrorists, the industry is doomed.
The real problem here is although terrorism will never touch the average citizen anywhere near the extent of other tragedies like illness, accidents or natural disasters, the media treat it like it's the single most important issue — making people fear for their lives is good business. I'd die before sacrificing freedom of speech every time, but the news business just seems too like racketeering. We need to fight the fear.
So why is Microsoft fighting us.gov regarding access to data stored in another country? Isn't that, to the layman, just another variety of ribbon-wrapped box. Gates should know that, just like extra-jurisdictional data retrieval, signed malware data retrieval is dangerous, bad business and awful precedent. He must publicly set the record straight for his company's stance to have any credibility.
See this FT article [1] (a admittedly biased competitor) from late last month. Their cash shrank from £840M to £740M in the last year, and they're planning to cut "costs" by 20%.
That's a tragedy at such a great newspaper, but it does color their analysis regarding the companies most responsible for their decline.
[1] http://www.ft.com/fastft/2016/01/25/guardian-to-cut-costs-by...
You can almost hear the Guardian's business leader writers rubbing their hands at the prospect. Which is as shameful and shortsighted as it is atypical for the Guardian. I would guess the team behind this article are acutely aware of the rate their owners are burning through cash and are anticipating massive layoffs soon. Perhaps they're looking for a lifeboat with the Apple-despising Financial Times?
Wow. This is the first HN submission to exceed 5,000 points!
To honour Tim, and his advocacy for our industry, I'm going to spend the rest of my week developing privacy/security projects. I encourage everyone else to do likewise.
[Airbus partners with Lamda Guard to evaluate an innovative laser strike protection](http://www.airbus.com/newsevents/news-events-single/detail/a...)
Ludicrous authoritarianism masquerading as a solution to a problem.
Given that all laser pointers fall into a couple of very narrow bandwidths, surely it would be more practicable to filter these at the cockpit window. That way you solve the problem in every country where you fly your plane and also deal with the billions of laser diodes already in circulation that are essential most aspects of our modern existence. But that would cost air carriers directly, not the public, so I guess it's unacceptable to them.
Why 9? It's spookily reminiscent of the "Nine Eyes" organisation who're the Orwellian bad guys in the latest Bond film, but I see no technical reason the keys cannot be split between 8 or 10 parties. And how much more security do multiple identical servers provide? If one can be hacked — which is frankly a given — so can all the rest.
There is nothing in this article that makes me think a system of split keys is any more desirable than when FBI Director Comey proposed the same thing last year. It's just a bit more terrifying coming from the so-called "Father of Online Anonymity".
This is like in WWII, when Churchill and Turing gave so many newspaper interviews re: how awful it was they couldn't crack Hitler's encryption anymore that he finally gave in, went back to the 3-rotor Enigma machines and we won the war.
Think about what happens when you hit theverge.com: 40-odd requests sent sites you've never heard of. So-called internet connection records are a huge mess of noise even without considering obfuscation.
It is trivial for anyone to embed hidden iframes or send silent ajax requests to child abuse and terrorist forums without giving the visiter the slightest clue what's happening. In the case of iframes, there would probably be cached 'evidence' left on the target's pc. Try explaining that as your defence in court when you get set up by some script kiddie.
The London Times got a guided tour of a the once-secret UK intelligence headquarters and left behind their journalistic integrity. They are being used to disseminate propaganda ahead of the introduction of draconian surveillance legislation. "Snowden did enormous damage", "tiny bit of data", "only metadata", etc.
Letting in a journalist is an astute move on behalf of GCHQ and the government, but, in this instance, they have accidentally chosen a stenographer instead. The absence of a single challenging question regarding the dangers of mass-surveillance is embarrassing.
It's pretty staggering that the FBI and gov.uk should choose now — a time of daily, massive security breaches dominating the headlines — to have the "your security is too good" conversation with tech companies. And, compared to the last time we went through this idiocy, they now refuse to put any specific proposals on the table. The whole enterprise is an embarrassment, and not going to happen in a million years.
But if, over the course of a year, self-driving cars are shown to be even a smidgen safer than manual cars, they are undeniably superior — even if assigning responsibility is a bit more complex. I agree that emotional detachment concerning road fatalities is unacceptable, but you have to be careful that, in your quest for justice, you don't see more road deaths as an acceptable cost.
The Economist describes open-source lisense liability terms as "untenable".
Would anybody like to predict and defend a probability above 0.00 that gov.uk will be able to meaningfully impede my ability use cryptography by 2020? Obviously politician's rhetoric, and to a large extent the law, have become unhinged from reality, so the odds of passing one more moronic, ineffectual law are a given: 1.0. But I'm asking someone to seriously state and defend even the slightest possibility that David Cameron might, in even the smallest sense, succeed. I can't.
Just assume for one second this is a genuine revelation and not recycled propaganda from mid 2013. Couldn't someone entrusted with the Snowden cache just dump it online now? If the trove is already circulating between hostile intelligence agencies, that seriously skews the risk/reward calculation regarding mass dissemination.
"we need [tech firms to do] everything possible to stop their technology being exploited by terrorists"
Such absolutism is foolish. The only way to guarantee technology cannot be used by terrorists is to never invent any technology. In the real world we need to offset the tiny benefits to an extreme minority of bogeymen against the enormous benefits to typical consumers.
If the FBI wanted car manufacturers to design seat belts and airbags with murderers and rapists in mind, it wouldn't have taken months of debate to reject the idea. Just because we've entered the domains math and CS, we get months of dithering, contemplating whether or not to force domestic companies to install complex new self-destruct functions into their products.
Al-Qaeda have been using Mujahedeen Secrets — a Windows-based encryption app — since 2007. Legislators should test whether potential new laws can have any impact on such uncontroversially abhorrent software. If, like split keys, they fail the Mujahedeen Secrets test, they can only damage our collective security.
How much longer can this continue? We have American agencies attacking American companies "because terrorism". It's been 13 years since our trauma, maybe now's the time to remove the razor blade from our wrists, look ourselves in the mirror and just carry on. Bad stuff is always going to be in our future — stuff that will increasingly appear preventable between the Internet and a lot of hindsight — but our current solution is only making things worse. The war on terror, like all the metaphorical wars, is really a civil war. It needs to stop now.
This Hawking-lead AI panic references the European colonial genocide of indigenous peoples as an analogy for how groups with different intelligences interact. As such, it is hideously offensive. Colonials and the indigenous peoples they slaughtered — like all humans — had similar intelligences. The differentiator was technology. Being on the side with inferior tech was fatal.
If America follows the recommendations in this paean for suppression of intelligence, they'll find out what it's like being on the losing side. If it is possible for computers to achieve superhuman general intelligence, it will happen regardless of regulations. 'Safeguards' like hardcoding in Asimov's laws presupposes such an entity would have inferior programming skills than its comparatively stupid creators, hence it would be pointless.
And what about the risks of not creating AI? Humanity has a host of non-theoretical existential threats contend with. A super-duper intelligence could help with those. Just imagine the example a superior being would set: it would demonstrate the bootstrapping of intelligence from nothing. Precisely opposite to the preaching of the worlds major religions. If this being of our creation doesn't kill us, it might inspire us to stop killing each other.
If the "greatest threat to humanity" is something everybody agrees neither exists nor is imminently about to be created, we are pretty lucky. I wish that were the case, but it clearly isn't.
But what I absolutely don't understand is the logic of predicting the apocalypse. You can either be wrong or dead – there is zero upside.