I recently completed Barack Obama’s A Promised Land (a partial account of his presidency), and he mentions in his book that although he wanted to reform mass surveillance, it looked a little different once he was actually responsible for people’s safety. I often think about this when I drive past Flock cameras or walk into grocery stores; our leaders seem more enticed by the power of this technology than they are afraid of vague abuses happening in _not here_. It seems like no one sees a cost to just not addressing the issue.
By analogy, I feel that reporting on the dangers of fire isn’t really as effective as reporting on why we don’t have arson laws and fire alarms and social norms that make our society more robust to abuse of a useful capability. People who like cooked food aren’t going to engage with anti-fire positions if they just talk about people occasionally burning each other alive. We need to know more about what can be done to protect the average person from downsides of fire, as well as who is responsible for regulating fire and what their agenda for addressing it is. I’d love to see an article identifying who is responsible for installing these Flock cameras in my area, why they did so, and how we can achieve the positive outcomes desired from them (e.g. find car thieves) without the negatives (profiling, stalking, tracking non-criminals, etc).
An ideal government with total surveillance is the best case. You get the benefits of low crime without the drawback of corruption and ideology. The problem is in practice:
- Large institutions aren’t good at exercising fine control: even if the leaders have truly good intentions, corrupt mid-level employees and inaccurate data lead to bad outcomes.
- Good leaders seem to often pick bad successors, and unless they frequently pick better successors, someone will eventually pick a corrupt one.
- Corrupt leaders seem to be good at ousting or sidelining good leaders, more than vice versa, perhaps because good leaders are less passionate about gaining and keeping power.
Perhaps there are other reasons. Not just ideal governments, but even self-preserving governments don’t tend to last. Hence, although decentralization and privacy are never ideal, they should exist at least for backup, “just in case” (inevitably in practice) the centralized surveillance system goes rouge.
This is a cowardly excuse. It's another way of saying that if you reform mass surveillance you'll be blamed for anything bad that subsequently happens, regardless of whether the mass surveillance would have prevented it. And bad things happen on a regular basis with or without mass surveillance, so then the politically risk-averse move is to not solve the problem you promised to solve and not expose yourself.
Which is cowardly specifically because the candidate's original position was correct. You can solve crimes without mass surveillance, or prevent them by reducing poverty etc. If you do those things then the chances of something bad happening go down instead of up.
And it will still not be zero -- it won't be zero no matter what you do -- but in that case you're only worried about adversarial pundits blaming you for things that weren't your fault, and adversarial pundits are going to do that regardless.
"Citizens will be on their best behavior because we are constantly recording and reporting everything that’s going on." -- Larry Ellison (who should not be anthropomorphized)
And Ellison is not even a politician, he doesn't even has any kind of immunity. Meanwhile, EU politicians want to impose Chat Control on everyone except them.
The core issue is that they see themselves as different from us.
Politics should not be a career. It should be something a person does for 5, at most 10 years max and after that they are back to being like everyone else, with 0 benefits (and with potentially more surveillance, I think politicians' finances should be under extra scrutiny for the rest of their lives).
Surveillance makes their jobs easier, so there's a kind of natural tendency towards authoritarianism. We've known about this for a long time, the 4th Amendment was created to put limits on government surveillance.
If you're wondering why the government would allow private businesses to spy on everybody when the government itself isn't allowed to, that's because this allows for the government to effectively bypass the 4th Amendment. The government spying on everybody is against the Constitution, but a private business spying on everybody and selling the data to the government is "legal".
Assuming that he was sincere about wanting reform in the first place (and that's a big if for any book like this! The best you can say for Obama vs. most other politicians, is that he at least likely wrote it himself), what it means was that he was persuaded that mass surveillance was useful. He doesn't say how, or by who, he just vaguely waves at the burden of command.
It's the same "impose a small but poorly defined cost on everybody and act as though it's worth it because it maybe saves one defined life and therefore anyone who wants to call you out has an uphill battle" model you see used by bad people and dishonest comment section types the world over.
Society has no good way to reason about these "it's not much individually but when you do it to all of society it adds the F up" type downsides.
Like if you could save one life per year at the cost of making it take everyone an extra minute per day that's obviously not worth it at the scale of the united states because you're actually losing more life than you're saving.
But replace the "one minute" with something more subjective and nobody calls it out.
Obama didn't swear an oath to safety, but he did swear an oath to protect the constitution. He is an oath breaker and not a man of integrity, but if we choose to trust his excuse then maybe we can forgive him as an individual for being frightened by the horror stories told to him by power hungry three letter agencies, but we should never forgive him as a president for his failure to uphold his oath. Obama studied and taught constitutional law. He knew exactly how important the oath he took was and what would be at risk if the constitution was ignored.
It will always be more "safe" to take people's freedom and control them. Safety is just not an acceptable excuse to take away the freedoms of every American.
If the police need your google search history thats ok as long as they can get a warrant showing they have justification and then perhaps at a delayed time, the account owner should be notified that this happened.
If they need access to your phone, rather than hacking it they should just take it off you and get the password from you.
This limits tracking since this is a fairly disruptive and visible thing and prevents just passive tracking of everyone all the time.
Businesses who use facial recognition for loss prevention should be legally required to only use their data for this purpose and never for marketing and analytics. They must not ever sell the data and delete it within a reasonable time.
It boils down to one thing that allows these surveillance technologies to exist: public apathy.
Power corrupts.
That seems highly disingenuous or just ignorant. We publicly had this problem starting in the 1990s. The NSA used to have a program that would capture data but then encrypt it and protect it from random access. They discontinued that program and instituted a new one that had zero privacy protections in it.
This was right at the turn when the "war on terror" started. Which was the excuse then used to abandon the better program for the egregious one since it was projected to be better for this particular use case. It's debatable whether that was true or not.
> Flock cameras or walk into grocery stores
Record it if you want. Law enforcement, at any level, should require an actual warrant to access it in any form. This isn't a binary. You can enhance security and privacy at the same time.
You mean to ask questions ? No way. /s
> Phone networks need to know where users are in order to route text messages and phone calls. Operators exchange signalling messages to request, and respond with, user location information. The existence of these signalling messages is not in itself a vulnerability. The issue is rather that networks process commands, such as location requests, from other networks, without being able to verify who is actually sending them and for what purpose.
> These signalling messages are never seen on a user’s phone. They are sent and received by “Global Titles” (GTs), phone numbers that represent nodes in a network but are not assigned to subscribers.
'Fun' fact: "other networks" includes all foreign networks with a roaming partnership. It's possible to abuse SS7 to track people across borders, from half the world away.
the group:
- dragged its feet on resolving SS7 security vulnerabilities
- repeatedly ignored input from DHS technical experts
- [identified] best practices.. using different filtering systems
- [but] pushed.. to rely on voluntary complianceBut it is highly ironic that these companies specialize in surveillance, tracking, and security, and then have a tendency to leave the data that they steal from others open to the Internet in a very amateurish security lapse that in turn leads to everyone stealing from them.
https://www.lighthousereports.com/methodology/surveillance-s...
Femtocells and Fake Base Stations Attackers deploy femtocells — small cellular base stations — or fake base stations, commonly known as IMSI catchers, to intercept SS7 traffic. A modified femtocell can act as a man-in-the-middle, capturing signaling messages between a phone and the network.
Fake base stations mimic legitimate cell towers, tricking devices into connecting and relaying SS7 messages to the attacker’s system.
IMSI catchers exploit a known security vulnerability in the GSM specification, which requires the handset to authenticate to the network but does not require the network to authenticate to the handset. They broadcast a stronger signal than legitimate cell towers to lure mobile phones into connecting. Once connected, an IMSI catcher can force the transmission of the International Mobile Subscriber Identity (IMSI) and compel the connected mobile station to use no encryption or easily breakable encryption.
For 3G and LTE networks, sophisticated IMSI catcher attacks may involve downgrading the connection to less secure non-LTE network services to bypass enhanced security features. For example, a hacker might deploy a fake base station near a target to capture their IMSI and initiate SS7 queries.
https://www.how2lab.com/tech/mobile-communication/ss7-vulner...
SS7: Locate. Track. Manipulate. [2014] https://media.ccc.de/v/31c3_-_6249_-_en_-_saal_1_-_201412271...
For example, this post could have been a product of just probing a particular group of people to understand if they are interested in the subject and what they have to say about it.
That can be done indirectly, by suggesting someone (offering a link or planting an idea) that is already known to be interested in surveillance and prone to share interesting discoveries (in other words, the poster might not even be aware he could be an asset).
Think about the many ways someone could know your interests and how prone you are to react to something and how that could be used. If you are in tech, think about all the silly ways that kind of information can leak publicly.
People often disregard the possibility that they could be an active part of a surveillance network (as an unkowingly asset), instead focusing on more fantastical ideas such as technological hacks or coding wizardry.
Why not HIBP (Have I Been Pwned) style site to check against the database if your number is in?
- Almost everyone has a phone.
- Almost everyone takes their phone wherever they go.
- All SIM-cards have been forcefully (by law) linked to people's identities.
- Almost all people are therefore being tracked.
If your device privacy is a mess, mobile ID links you to all the good and bad things you do on a phone.
Had no idea this was part of the tool options, but backbone cell network makes sense.
Other TTPs I’d read about was variations on geo-fenced adserving to phish a mobile ID basically via user interaction or scroll past the ad. Small enough geofence and do it a few times, one could safely figure out the user being the ID. Googling “RTB surveillance” or “DSP surveillance” are ways into the topic.
Scary stuff! Pair that with this tech has been working for years, and is international. Frames a bit differently every action by a public figure - also at risk via the same threat model.
Also long have wondered what data analysis like this is done on technical forums… ran by a VC firm… with a lot of insider context (product market fit?) in the comments.
https://www.giosec.uk/specialist-services---geo-location.htm...
Reminder that around the same time a joint venture of Nokia+Siemens had been developing and deploying deep packet inspection and surveillance systems in Egypt and Iran. They got called out by human rights organisations and posted an "oops sorry\" press release.
Political figures being there I somewhat understand, but a Netflix producer? Why would anyone need to track a Netflix producer?
Even the WAP part of the name makes me wonder[2].
I know I have some futile questions, but why does seem France so untouched? [3]
[1] <https://www.1rstwap.com>
[2] <https://en.wikipedia.org/wiki/Wireless_Application_Protocol>
[3] <https://i0.wp.com/www.lighthousereports.com/wp-content/uploa...>
There is mention of fake antenna but I don't think they cover entire country with that, how do they do?
As for article, imagine, at those times and for thousands years after in most places humans were still hunting-gathering..
The new reality is that the surveillance state is part of the ride. If you are not a rapist or pedophile then why would you be concerned about cameras in Public anyways? If nobody is trying to smuggle children then why do we keep losing them? These ideas would not get so much traction if they were not a legitimate response to a real world stimuli.
Favouring any argument made by non citizens and/or “the naysayers” tends to be labeled as “Anti” which is a dangerous label
I would assume anyone who has kids would support the idea of tracking programs because it implies a higher level of operational security and access denial. I am truly curious who's voices these are calling for transparency and open security, because they are trying to rape your daughter. Prove me wrong, prove me wrong. I repeat, only a rapist, thief, terrorist or spy would be alarmed about the development of this “Surveillance State” technological paradigm. So when the trolls try to argue Philosophy as some generic excuse to protest scrutiny, take another look. What does he have to hide. What business is it of theirs to speak for you about cyber security or domestic opsec? And in fact who are you to care about that stuff at all either?