#DataAreLiability

Doc Edward Morbius ⭕​dredmorbius@toot.cat
2023-03-04

@danyork There's also Farhad Manjoo's article at the NYT: "Why Alex Murdaugh’s Quick Conviction Worries Me"

[P]rosecutors reconstructed a tight timeline of the crime using lots and lots of data. Among other sources, they extracted information from Alex, Maggie and Paul Murdaugh’s iPhones, call records of family and friends, location and speed data from Murdaugh’s S.U.V., entry logs from his office security system, images from automatic license plate readers mounted on public roads, communications on social networks and messaging apps, reams of financial data and video and audio recorded on Murdaugh’s 911 call .... [P]rosecutors in the Murdaugh case claimed to find many deeper truths in the digital record. And it’s in their interpretations of the data that they sometimes lost me. Often, they seemed to be finding patterns in the data that didn’t necessarily hold true, and this made me wary that the authorities can build outlandish stories from our data.

nytimes.com/2023/03/03/opinion

Surveillance capitalism melds with the surveillance state. Sure, this case seems to be a highly-plausible murderer convicted through digital forensics, but far more mundane or harmful possibilities loom.

Cardinal Richelieu's (apocryphal) "six lines" quip comes to mind.

@pluralistic @jonkeegan

#Privacy #Surveillance #SurveillanceCapitalism #SurveillanceState #AlexMurdaugh #FarhadManjoo #SixLines #CardinalRichelieu #DataSmog #DigitalBreadcrumbs #DataAreLiability

Doc Edward Morbius ⭕​dredmorbius@toot.cat
2022-11-02
Doc Edward Morbius ⭕​dredmorbius@toot.cat
2022-06-28

In light of the #DobbsVJackon case in the US, as well as other fascistic tendencies elsewhere, it's worth noting once again that the vast troves of personal information which are gathered and held by Internet monopolists such as #Google, #Facebook, #Amazon, #Apple, and #Netflix, telcos of both telephony and Internet services (ISPs) including #ATT, #Verizon and #Comcast, location data, payment processors (#Visa, #Mastercard, #Stripe, ...), and a vast seething cesspit of "consumer data" brokers (#Equifax, #TransUnion, #Experian, #LexisNexis, #ADP, #Bloomberg, and many, many, many more) represent an increasingly severe, potentially existential threat.

#EFF have warned of part of this recently, though it's far worse than their linked article here states.

eff.org/deeplinks/2022/06/effs

#Kristallnacht #Facebook #Instagram #WhatsApp #Oculus #DataAreLiability #Surveillance #SurveillanceState #SurveillanceCapitalism

Doc Edward Morbius ⭕​dredmorbius@toot.cat
2021-10-05

Web Scrapers Claim to Possess and Sell Personal Data on 1.5 Billion Facebook Users on a Hacker Forum

The private and personal information of over 1.5 billion Facebook users is being sold on a popular hacking-related forum, potentially enabling cybercriminals and unscrupulous advertisers to target Internet users globally. ...

#Facebook #DataAreLiability #Kristallnacht #DataBreaches #surveillance #SurveillanceCapitalism #SurveillanceState

privacyaffairs.com/facebook-da

Doc Edward Morbius ⭕​dredmorbius@toot.cat
2021-10-05
A black-and-white photograph of the aftermath of Kristallnacht, 9--10 November 1938, when Nazi SA brownshirt thugs smashed and looted Jewish shops, buildings, and synagogues throughout Germany.

Passersby and onlookers look at damaged storefronts.  Shattered glass covers the street and pavement.  A woman facing the camera smiles.
Doc Edward Morbius ⭕​dredmorbius@toot.cat
2021-08-31

@CCC The answer to "who watches the watchmen" has been answered.

At least in Afghanistan: it's the Taliban.

#surveillance #SurveillanceState #SurveillanceCapitalism #afghanistan #taliban #QuisCustodietIpsosCustodes #QuisCustodiet #DataAreLiability

Doc Edward Morbius ⭕​dredmorbius@toot.cat
2021-08-21
A black & white photograph shows the aftermath of Kristallnacht, 9--10 November 1938, when Nazi SA thugs smashed and looted Jewish shops, buildings, and synagogues throughout Germany.

Shop windows stand smashed, glass litters the street, passersby look on, a man and woman facing the camera both smile.
Doc Edward Morbius ⭕​dredmorbius@toot.cat
2021-08-19

Dumb Phone

...There’s also the increasingly evident problem that having all your critical data on a communications device is a fundamental and intractable risk. The dis-integrated business telephony environment of the 1950s–1990s maintained data isolation between elements. Telephone numbers served as the reasonably-viable data-exchange-and-linking interface between components (map a name or address to a number, enter the number on a calendar or correspondence, etc.).

It’s almost as if putting your filing system, personal diary, correspondence, photo album, and directory on a surveillance and exfiltration device was a Bad Idea. ...

joindiaspora.com/posts/6ce9970

#telephony #telephones #risk #AirGap #data #DataAreLiability #UIUX #Usability #SmartPhones #DumbPhones #computers #communications #privacy #security #surveillance

Doc Edward Morbius ⭕​dredmorbius@toot.cat
2021-08-18

Dear Googles: I hope you're giving a lot of hard thought to brownshirt-proofing your vast troves of personal data.

Just sayin.

Originally: web.archive.org/web/2017060410

(Obviously: all data collection and brokering services and systems are addressed.)

#Kristallnacht #DearGoogles #DataAreLiability #Surveillance #SurveillanceState #SurveillanceCapitalism

A black-and-white photograph of the aftermath of Kristallnacht, 9--10 November 1938, when Nazi SA brownshirt thugs smashed and looted Jewish shops, buildings, and synagogues throughout Germany.

Passersby and onlookers look at damaged storefronts.  Shattered glass covers the street and pavement.  A woman facing the camera smiles.
Doc Edward Morbius ⭕​dredmorbius@toot.cat
2021-08-04

The debate on who has control over data typically creates two parties: the individual user who it is related to, and the corporation providing the platform or product.

We ought to add another party: the public. Perhaps data should be able to be used for the public good, and we should be able to participate in deciding what data is collected and how data is used.

-- lilactown @ HN
news.ycombinator.com/item?id=2

#data #DataAreLiability #Privacy #Surveillance #SurveillanceCapitalism #SurveillanceState #PublicInterest #CommonWeal #Facebook #HNComments

Doc Edward Morbius ⭕​dredmorbius@toot.cat
2021-05-23

@galaxis I made a similar point aboout the execution of Kim Jung-nam:

Data are Liability: Book your Assassination Now

Travel and hospitality databases are widely accessible and shared amongst a tremendous number of organisations. State intelligence organisations might readily have access through their own state-run airline, or through private operations or plants within same. Similarly for terrorist, narco-criminal, money-laundering, or other organisations. Financial, banking, and payment-processing systems, only slightly less so. A P.I. license or position on a fraud or abuse desk at a major online retailer, or any skip-tracing agency, can have access to such information.

What is your threat model?

old.reddit.com/r/dredmorbius/c

#DataAreLiability #Belarus #kidnapping #assassination #ThreatModels

Doc Edward Morbius ⭕​dredmorbius@toot.cat
2020-12-17

Hunting the Hunters: How We Identified Navalny's FSB Stalkers

... Due to porous data protection measures in Russia, it only takes some creative Googling (or Yandexing) and a few hundred euros worth of cryptocurrency to be fed through an automated payment platform, not much different than Amazon or Lexis Nexis, to acquire telephone records with geolocation data, passenger manifests, and residential data. For the records contained within multi-gigabyte database files that are not already floating around the internet via torrent networks, there is a thriving black market to buy and sell data. The humans who manually fetch this data are often low-level employees at banks, telephone companies, and police departments. Often, these data merchants providing data to resellers or direct to customers are caught and face criminal charges. For other batches of records, there are automated services either within websites or through bots on the Telegram messaging service that entirely circumvent the necessity of a human conduit to provide sensitive personal data.

For example, to find a huge collection of personal information for Anatoliy Chepiga — one of the two GRU officers involved in the poisoning of Sergey Skripal and his daughter — we only need to use a Telegram bot and about 10 euros. Within 2-3 minutes of entering Chepiga’s full name and providing a credit card via Google Pay or a payment service like Yandex Money, a popular Telegram bot will provide us with Chepiga’s date of birth, passport number, court records, license plate number, VIN number, previous vehicle ownership history, traffic violations, and frequent parking locations in Moscow. A sample of the baseline information provided can be seen below, with key personal details censored. ...

bellingcat.com/resources/2020/

#surveillance #DataAreLiability #SurveillanceCapitalism #SurveillanceState #bellingcat #privacy #russia

Doc Edward Morbius ⭕​dredmorbius@toot.cat
2020-11-24

44 bits

So, a redditor tracked down the location of a monolith placed in the Utah desert a few years ago, recently discovered by authorities, who did not disclose where it was.[1]

It's relatively well known that 33 distinct bits is enough to uniquely identify any individual person now alive on Earth.[2]

Geospatially, assuming 10m2 resolution, 44 bits is enough to identify any unique region on Earth's land surface (46 bits buys you the oceans).

Searching for a ~1m2 monolith visually within a 10m2 square is reasonable.

GNU units:

You have: ln((.3 * 4 * (earthradius^2) * pi)/10m^2)/ln(2)
Definition: 43.798784
You have: ln((1 * 4 * (earthradius^2) * pi)/10m^2)/ln(2)
Definition: 45.535749

49 bits buys 1m accuracy, 63 1cm, 69 1mm. Anywhere on Earth, land or sea.

For comparison, cellphone positioning accuracy is typically 8--600m:

  • 3G iPhone w/ A-GPS ~ 8 meters
  • 3G iPhone w/ wifi ~ 74 meters
  • 3G iPhone w/ Cellular positioning ~ 600 meters

communityhealthmaps.nlm.nih.go

gps.gov/systems/gps/performanc

The power of disparate data traces to rapidly narrow down search spaces on a specific item, individual, or location, is what makes #BigData aggreggation so powerful, and terrifying.

Notes:

  1. old.reddit.com/r/geoguessr/com news.ycombinator.com/item?id=2

  2. web.archive.org/web/2016030401

#privacy4 #location #33bits #44bits #data #deanonimization #DataAreLiability #surveillance #SurveillanceState #SurveillanceCapitalism

Doc Edward Morbius ❌​dredmorbius@mastodon.cloud
2020-02-19

Why Amazon Knows So Much About You

...One database contains transcriptions of all 31,082 interactions my family has had with the virtual assistant Alexa. Audio clips of the recordings are also provided. The 48 requests to play Let It Go, flag my daughter’s infatuation with Disney’s Frozen.
Other late-night music requests to the bedroom Echo, might provide a clue to a more adult activity....

bbc.co.uk/news/extra/CLQYZENMB

#amazon #surveillanceCapitalism #dataAreLiability #privacy

Doc Edward Morbius ❌​dredmorbius@mastodon.cloud
2020-01-05

#DataAreLiability GOP voter suppression / gerrymandering edition

Dead "redistricting consultant" secret files released by his daughter.

npr.org/2020/01/05/785672201/d

Doc Edward Morbius ❌​dredmorbius@mastodon.cloud
2019-10-21

What you need is to be forced, on penalty of imprisonment, to treat all customer data as if they were medical records -- or, better yet, nuclear waste.

(Thread-ending response to "We need better data privacy self-regulation", at HN.)

news.ycombinator.com/item?id=2

#privacy #SurveillanceCapitalism #DataAreLiability

Doc Edward Morbius ❌​dredmorbius@mastodon.cloud
2019-10-15

@clacke Again, that's been my default position for some time. #DataAreLiability being a frequently-used hashtag / phrase here and elsewhere.

I'm considering the alternative as a counterpoint / falsifiable premise.

Doc Edward Morbius ❌​dredmorbius@mastodon.cloud
2019-09-10

#DataAreLiability Vancouver Coastal Health edition.

Patient data -- including names, ages, conditions, and free-form text fields -- transmitted by radio over the air unencrypted since at least November 2018.

openprivacy.ca/blog/2019/09/09

#privacy #healthcare #vancouver #VancouverCostalHealth

Doc Edward Morbius ❌​dredmorbius@mastodon.cloud
2019-02-21

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst