Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > alt.os.development > #9324 > unrolled thread
| Started by | James Harris <james.harris.1@gmail.com> |
|---|---|
| First post | 2016-03-29 15:09 +0100 |
| Last post | 2016-04-27 07:44 +0100 |
| Articles | 20 on this page of 37 — 7 participants |
Back to article view | Back to alt.os.development
The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-29 15:09 +0100
Re: The morality of operating system security JJ <jj4public@vfemail.net> - 2016-03-30 00:03 +0700
Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-03-29 19:39 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-30 23:54 +0100
Re: The morality of operating system security JJ <jj4public@vfemail.net> - 2016-03-31 06:16 +0700
Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-03-29 20:01 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-30 23:59 +0100
Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-03-31 17:47 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 08:11 +0100
Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-04-01 18:25 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 23:10 +0100
Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-04-02 14:18 +0200
Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-04-01 09:58 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 10:06 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-29 17:39 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-31 00:13 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-30 23:18 -0400
Re: The morality of operating system security "Alexei A. Frounze" <alexfrunews@gmail.com> - 2016-03-31 00:31 -0700
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-31 16:57 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 09:22 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-01 20:24 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-09 18:25 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-09 18:57 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-26 09:07 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-26 23:58 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-27 07:01 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-27 05:42 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-03 00:05 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-03 16:55 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-04 09:00 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-04 17:22 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-05 17:02 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-05 17:55 -0400
Re: The morality of operating system security "Kerr Mudd-John" <admin@127.0.0.1> - 2016-05-09 14:58 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-12 17:46 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-15 00:11 +0100
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-27 07:44 +0100
Page 1 of 2 [1] 2 Next page →
| From | James Harris <james.harris.1@gmail.com> |
|---|---|
| Date | 2016-03-29 15:09 +0100 |
| Subject | The morality of operating system security |
| Message-ID | <nde25k$bkn$1@dont-email.me> |
Recently the US government wanted to extract data from an Apple phone that had belonged to a terrorist because that information might help the government prevent further terrorist attacks. Apple did not want to produce any software or system that could do this because they wanted to sell phones which were known to keep users' data private from anyone and everyone. AIUI some bright spark had an idea of how to break Apple's security and took it to the US security people. And that person was proven right. As a result, the US security services have got access to the data on that phone. Consequentially, Apple have been somewhat embarrassed that their security has been broken. They will almost certainly change their phone security now to try to make future phones unbreakable. This will lead to the same moral issues again. So, what are your views on this kind of issue with operating system security? Where is the line to be drawn between users' privacy and people's safety? Any thoughts? -- James
[toc] | [next] | [standalone]
| From | JJ <jj4public@vfemail.net> |
|---|---|
| Date | 2016-03-30 00:03 +0700 |
| Message-ID | <lxqmep70413u$.bzvwpx5519l6.dlg@40tude.net> |
| In reply to | #9324 |
On Tue, 29 Mar 2016 15:09:35 +0100, James Harris wrote: > > So, what are your views on this kind of issue with operating system > security? Where is the line to be drawn between users' privacy and > people's safety? Any thoughts? It's people's right to have both security and privacy. That I agree. But those that don't want the government to be messing with theirs for whatever reason, clearly doesn't give a crap about 9/11 event. That being said, there's always a possibility of a conspiracy. So, food for thought. My personal opinion is that, my way of life is to trust others before they give their trust to you. So, I'd trust my government (not yours) if they need my personal data for the right reason, and as long as they ask first and not getting the data without consent.
[toc] | [prev] | [next] | [standalone]
| From | "wolfgang kern" <nowhere@never.at> |
|---|---|
| Date | 2016-03-29 19:39 +0200 |
| Message-ID | <ndehmd$24s$1@gioia.aioe.org> |
| In reply to | #9325 |
"JJ" <jj4public@vfemail.net> schrieb im Newsbeitrag news:lxqmep70413u$.bzvwpx5519l6.dlg@40tude.net... > On Tue, 29 Mar 2016 15:09:35 +0100, James Harris wrote: >> >> So, what are your views on this kind of issue with operating system >> security? Where is the line to be drawn between users' privacy and >> people's safety? Any thoughts? > > It's people's right to have both security and privacy. That I agree. But > those that don't want the government to be messing with theirs for > whatever > reason, clearly doesn't give a crap about 9/11 event. That being said, > there's always a possibility of a conspiracy. So, food for thought. > > My personal opinion is that, my way of life is to trust others before they > give their trust to you. So, I'd trust my government (not yours) if they > need my personal data for the right reason, and as long as they ask first > and not getting the data without consent.
[toc] | [prev] | [next] | [standalone]
| From | James Harris <james.harris.1@gmail.com> |
|---|---|
| Date | 2016-03-30 23:54 +0100 |
| Message-ID | <ndhl91$5p2$1@dont-email.me> |
| In reply to | #9325 |
On 29/03/2016 18:03, JJ wrote: > On Tue, 29 Mar 2016 15:09:35 +0100, James Harris wrote: >> >> So, what are your views on this kind of issue with operating system >> security? Where is the line to be drawn between users' privacy and >> people's safety? Any thoughts? > > It's people's right to have both security and privacy. That I agree. But > those that don't want the government to be messing with theirs for whatever > reason, clearly doesn't give a crap about 9/11 event. That being said, > there's always a possibility of a conspiracy. So, food for thought. > > My personal opinion is that, my way of life is to trust others before they > give their trust to you. So, I'd trust my government (not yours) if they > need my personal data for the right reason, and as long as they ask first > and not getting the data without consent. Asking first would give the person time to delete/wipe the data wouldn't it? -- James
[toc] | [prev] | [next] | [standalone]
| From | JJ <jj4public@vfemail.net> |
|---|---|
| Date | 2016-03-31 06:16 +0700 |
| Message-ID | <ikb6on43lmj6.qwausmjlcpnk$.dlg@40tude.net> |
| In reply to | #9333 |
On Wed, 30 Mar 2016 23:54:04 +0100, James Harris wrote: > > Asking first would give the person time to delete/wipe the data wouldn't it? Yes, unfortunately. But without that, governments would have absolute power over everything. Like shoot first, ask later. Such governments are bound to fall sooner or later.
[toc] | [prev] | [next] | [standalone]
| From | "wolfgang kern" <nowhere@never.at> |
|---|---|
| Date | 2016-03-29 20:01 +0200 |
| Message-ID | <ndehme$24s$2@gioia.aioe.org> |
| In reply to | #9324 |
James Harris posted: > Recently the US government wanted to extract data from an Apple phone > that had belonged to a terrorist because that information might help the > government prevent further terrorist attacks. > Apple did not want to produce any software or system that could do this > because they wanted to sell phones which were known to keep users' data > private. I'd agree here with Apple. Privacy is a main issue for all of us who like to keep their private oppinion about whatsoever even shown. > AIUI some bright spark had an idea of how to break Apple's security and > took it to the US security people. And that person was proven right. As > a result, the US security services have got access to the data on that > phone. If Apple would give up, then we all become victims to everyone who like to see us in an unprotected world like MSN or Google... > Consequentially, Apple have been somewhat embarrassed that their > security has been broken. They will almost certainly change their phone > security now to try to make future phones unbreakable. This will lead to > the same moral issues again. I hope that this never happens, but we should be aware of it ! > So, what are your views on this kind of issue with operating system > security? Where is the line to be drawn between users' privacy and > people's safety? Any thoughts? sure. many ideas are already around. but it's easy to protect your own OS from any attacks from this side. The main idea is to never trust anything which you didn't youself and never execute code which is not marked as compatible and/or not doubtfree. __ wolfgang safety got a price(costs), but a smart OS wont ever encounter an issue.
[toc] | [prev] | [next] | [standalone]
| From | James Harris <james.harris.1@gmail.com> |
|---|---|
| Date | 2016-03-30 23:59 +0100 |
| Message-ID | <ndhljn$7d5$1@dont-email.me> |
| In reply to | #9327 |
On 29/03/2016 19:01, wolfgang kern wrote: > James Harris posted: > >> Recently the US government wanted to extract data from an Apple phone >> that had belonged to a terrorist because that information might help >> the government prevent further terrorist attacks. > >> Apple did not want to produce any software or system that could do >> this because they wanted to sell phones which were known to keep >> users' data private. > > I'd agree here with Apple. Privacy is a main issue for all of us who > like to keep their private oppinion about whatsoever even shown. I would not want Apple or any commercial company to get access to our private files. If some data could help prevent terrorist acts, though, isn't it wrong to keep the data hidden? >> AIUI some bright spark had an idea of how to break Apple's security >> and took it to the US security people. And that person was proven >> right. As a result, the US security services have got access to the >> data on that phone. > > If Apple would give up, then we all become victims to everyone who like > to see us in an unprotected world like MSN or Google... Not necessarily. You can drink a glass of water without drowning and you can open data to designated security services without letting everyone have access. No? -- James
[toc] | [prev] | [next] | [standalone]
| From | Bernhard Schornak <schornak@web.de> |
|---|---|
| Date | 2016-03-31 17:47 +0200 |
| Message-ID | <ndjgkk$eum$2@dont-email.me> |
| In reply to | #9334 |
James Harris wrote: > On 29/03/2016 19:01, wolfgang kern wrote: >> >> If Apple would give up, then we all become victims to everyone who like >> to see us in an unprotected world like MSN or Google... > > Not necessarily. You can drink a glass of water without drowning and you can open data to designated > security services without letting everyone have access. No? No. Those who want to commit crimes have opportunities to hide their masterplans from the eyes of companies as well as from any secret service, but all "average people" with no criminal background will lose a piece of their freedom and privacy. Buying safety comes at the cost of giving up your freedom. LEWER DOOD AS SLAAV (Better dead than slave...) Greetings from Augsburg Bernhard Schornak
[toc] | [prev] | [next] | [standalone]
| From | James Harris <james.harris.1@gmail.com> |
|---|---|
| Date | 2016-04-01 08:11 +0100 |
| Message-ID | <ndl6q3$u0v$1@dont-email.me> |
| In reply to | #9339 |
On 31/03/2016 16:47, Bernhard Schornak wrote: > James Harris wrote: > > >> On 29/03/2016 19:01, wolfgang kern wrote: >>> >>> If Apple would give up, then we all become victims to everyone who like >>> to see us in an unprotected world like MSN or Google... >> >> Not necessarily. You can drink a glass of water without drowning and >> you can open data to designated >> security services without letting everyone have access. No? > > > No. Those who want to commit crimes have opportunities to > hide their masterplans from the eyes of companies as well > as from any secret service, but all "average people" with > no criminal background will lose a piece of their freedom > and privacy. Buying safety comes at the cost of giving up > your freedom. I would counter that by saying that - at least in the free world - the security services are not interested in "average people" so we would not lose our privacy. This is not the Stasi. https://en.wikipedia.org/wiki/Stasi That said, an OS can be used by people suffering under repressive regimes. And, if a benevolent government can get into an OS maybe a repressive one can too. It may be impossible to allow, say, the Austrian government to access data without also preventing the North Koreans from accessing the same data. > LEWER DOOD AS SLAAV > > (Better dead than slave...) :-( That is not the choice! -- James
[toc] | [prev] | [next] | [standalone]
| From | Bernhard Schornak <schornak@web.de> |
|---|---|
| Date | 2016-04-01 18:25 +0200 |
| Message-ID | <ndm77l$b09$2@dont-email.me> |
| In reply to | #9344 |
James Harris wrote: > On 31/03/2016 16:47, Bernhard Schornak wrote: >> James Harris wrote: >> >>> On 29/03/2016 19:01, wolfgang kern wrote: >>>> >>>> If Apple would give up, then we all become victims to everyone who like >>>> to see us in an unprotected world like MSN or Google... >>> >>> Not necessarily. You can drink a glass of water without drowning and >>> you can open data to designated >>> security services without letting everyone have access. No? >> >> No. Those who want to commit crimes have opportunities to >> hide their masterplans from the eyes of companies as well >> as from any secret service, but all "average people" with >> no criminal background will lose a piece of their freedom >> and privacy. Buying safety comes at the cost of giving up >> your freedom. > > I would counter that by saying that - at least in the free world - the security services are not > interested in "average people" so we would not lose our privacy. This is not the Stasi. > > https://en.wikipedia.org/wiki/Stasi > > That said, an OS can be used by people suffering under repressive regimes. > > And, if a benevolent government can get into an OS maybe a repressive one can too. It may be > impossible to allow, say, the Austrian government to access data without also preventing the North > Koreans from accessing the same data. http://tinyurl.com/ndh5y68 http://www.cbsnews.com/feature/nsa-surveillance-exposed/ http://tinyurl.com/mgsuu4z And these guys are claiming to be the good ones. Now: Imagine what a(ny) government might do with the collected data. It is not a question of "if these data were used", it is a question of "when will the first bureauctrat (ab)use these data". Have a look at the news, and you will know we *crossed* this point a long time ago. They always know where you are and what you're doing, and the latest gadgets like "smart watches" provide even more control over those who follow "hypes" without thinking: With personal data (like your heartbeat) they can calculate if you're doing allowed things or if you are going to do something illegal (a good evaluation software can interpret data like an increased pulse and predict what a person is doing with high accuracy). I'm surely no one who believes in urban legends or conspiracy theories - I prefer knowledge over beliefs and speculations - but we should walk around with open eyes and see the obvious. It's not about secret societies, it is about human nature and logical thinking: As long as there is a faint chance to abuse something, there will be someone who takes this chance sooner or later... >> LEWER DOOD AS SLAAV >> >> (Better dead than slave...) > > :-( > > That is not the choice! Maybe not your's. This sentence is part of *some* old Frisian emblems. I could not find pages with English translation, so: https://de.wikipedia.org/wiki/Liewer_d%C3%BCd_a%C3%9F_Slaawe "The motto *LEWER DOOD AS SLAAV* (umlaut-free version) is a Frisian political motto from the 19th century. ..." For myself - I really preferred death over a life as property of someone else. It is the European dream to live our life in dignity and enjoy our freedom, isn't it? Have a nice weekend! Bernhard Schornak
[toc] | [prev] | [next] | [standalone]
| From | James Harris <james.harris.1@gmail.com> |
|---|---|
| Date | 2016-04-01 23:10 +0100 |
| Message-ID | <ndmrf7$tu1$1@dont-email.me> |
| In reply to | #9356 |
On 01/04/2016 17:25, Bernhard Schornak wrote: > James Harris wrote: > > >> On 31/03/2016 16:47, Bernhard Schornak wrote: >>> James Harris wrote: >>> >>>> On 29/03/2016 19:01, wolfgang kern wrote: ... > http://tinyurl.com/ndh5y68 > http://www.cbsnews.com/feature/nsa-surveillance-exposed/ > http://tinyurl.com/mgsuu4z Thanks. The first and last links were interesting. I don't mind the NSA or the UK police getting tracking records for my phone. But I don't want Microsoft or Google or any commercial company to know how where my phone goes and when. Unfortunately, AIUI, they do, and I expect they use it for commercial profiling. ... >>> LEWER DOOD AS SLAAV >>> >>> (Better dead than slave...) >> >> :-( >> >> That is not the choice! > > > Maybe not your's. ... > For myself - I really preferred death over a life as property > of someone else. It is the European dream to live our life in > dignity and enjoy our freedom, isn't it? As said, I don't want commercial companies getting personal profiling data but I don't mind my government's security services getting it. For me, the choice is not between death and slavery (that is far too melodramatic) but it is a choice between privacy and safety. I don't mind us losing some privacy (to very specific governmental agencies only) if it will help to keep us safe. This is one of those false choices. People ask if we are willing to have the government access our private data. What they don't mention is the limits on what they can see or who can see it, or that most of us are totally uninteresting to the security services. Nor do they mention how it helps protect us from lethal threats - and also, for that matter, helps protect us from legitimate fear of danger so that we can go about our lives without worrying about where trouble is to strike next. IIRC they said that _ten_ terror attacks were prevented last year in the UK due to intelligence gathering. How would we feel if there had, instead, been ten terrorist attacks? That's a long way of explaining why I say that, to me, the choice is nothing at all to do with slavery(!) but is between privacy and safety. -- James
[toc] | [prev] | [next] | [standalone]
| From | Bernhard Schornak <schornak@web.de> |
|---|---|
| Date | 2016-04-02 14:18 +0200 |
| Message-ID | <ndod4d$biu$4@dont-email.me> |
| In reply to | #9363 |
James Harris wrote: > On 01/04/2016 17:25, Bernhard Schornak wrote: >> James Harris wrote: >> >>> On 31/03/2016 16:47, Bernhard Schornak wrote: >>>> James Harris wrote: > >> http://tinyurl.com/ndh5y68 >> http://www.cbsnews.com/feature/nsa-surveillance-exposed/ >> http://tinyurl.com/mgsuu4z > > Thanks. The first and last links were interesting. > > I don't mind the NSA or the UK police getting tracking records for my phone. But I don't want > Microsoft or Google or any commercial company to know how where my phone goes and when. > Unfortunately, AIUI, they do, and I expect they use it for commercial profiling. I do not like if *anyone* tries to track me or my neighbors or anybody else. Technologies enabling governments to track their citicens are not developed by the government. In general, most technologies (including software!) are developed by commercial companies who want to generate profit with their products. The most profits can be made with virtual wares like tracking data of a representative quantity collected from all social classes populating the country. I bet the big IT companies have a much denser sieve collecting *much more* data than governments ever can collect. Data will replace money in the long term. >>>> LEWER DOOD AS SLAAV >>>> >>>> (Better dead than slave...) >>> >>> :-( >>> >>> That is not the choice! >> >> >> Maybe not your's. > > ... > >> For myself - I really preferred death over a life as property >> of someone else. It is the European dream to live our life in >> dignity and enjoy our freedom, isn't it? > > As said, I don't want commercial companies getting personal profiling data but I don't mind my > government's security services getting it. > > For me, the choice is not between death and slavery (that is far too melodramatic) but it is a > choice between privacy and safety. I don't mind us losing some privacy (to very specific > governmental agencies only) if it will help to keep us safe. > > This is one of those false choices. People ask if we are willing to have the government access our > private data. What they don't mention is the limits on what they can see or who can see it, or that > most of us are totally uninteresting to the security services. > > Nor do they mention how it helps protect us from lethal threats - and also, for that matter, helps > protect us from legitimate fear of danger so that we can go about our lives without worrying about > where trouble is to strike next. > > IIRC they said that _ten_ terror attacks were prevented last year in the UK due to intelligence > gathering. How would we feel if there had, instead, been ten terrorist attacks? > > That's a long way of explaining why I say that, to me, the choice is nothing at all to do with > slavery(!) but is between privacy and safety. Wrong. The Belgian autorities and police *got* information and warnings about planned attacks from secret services and police of several countries. Nevertheless, they ignored that evidence and watched how those plans were fulfilled. As long as we live in democratic countries (in accordance with the rule of law), we have to obey our laws and cannot allow to observe and track citicens without enactment of an independent judge. I'm pretty sure no judge ever enacted the "data mining" of the NSA or equivalent services in Europe. Safety is the one face of the coin, breaking laws the other one. We cannot claim to be the good ones as long as we do not respect our own laws, and we cannot demand that terrorists have to obey our law when we do not obey its rules ourselves. I agree to observe those who act in a suspiciuos way, if there is evidence they plan any criminal acts. I never will agree to observe the entire population and collect all data we can get, because these data *might* become handy if we want to look for criminal acts (including terrorist attacks). Allowing data preservation for entire countries turns the rule of "General Presumption Of Innocence" into "General Suspicion" (Generalverdacht). I don't think anyone wants such a thing: It undermines our rights and assumes everyone is a criminal until the accused can provide evidence s/he is innocent (exactly the opposite of the rule of law practised in civilised countries). Greetings from Augsburg Bernhard Schornak
[toc] | [prev] | [next] | [standalone]
| From | "wolfgang kern" <nowhere@never.at> |
|---|---|
| Date | 2016-04-01 09:58 +0200 |
| Message-ID | <ndl9pg$b50$1@gioia.aioe.org> |
| In reply to | #9334 |
James Harris wrote: >>> Recently the US government wanted to extract data from an Apple phone >>> that had belonged to a terrorist because that information might help >>> the government prevent further terrorist attacks. >>> Apple did not want to produce any software or system that could do >>> this because they wanted to sell phones which were known to keep >>> users' data private. >> I'd agree here with Apple. Privacy is a main issue for all of us who >> like to keep their private oppinion about whatsoever even shown. > I would not want Apple or any commercial company to get access to our > private files. If some data could help prevent terrorist acts, though, > isn't it wrong to keep the data hidden? Sure, but what would my clients say if I'd hand the government a program which overrides admin passwords and encription keys ? Such a program will fail anyway because only the owner can alter admin rights, so even I cannot bypass the wall I once created by using morphing algos depending on the admins key (min.512 byte). On a 4GHz machine it takes only 1e35 years to break it. >>> AIUI some bright spark had an idea of how to break Apple's security >>> and took it to the US security people. And that person was proven >>> right. As a result, the US security services have got access to the >>> data on that phone. >> If Apple would give up, then we all become victims to everyone who >> like to see us in an unprotected world like MSN or Google... > Not necessarily. You can drink a glass of water without drowning and you > can open data to designated security services without letting everyone > have access. No? Whom would you trust...? MI5? __ wolfgang
[toc] | [prev] | [next] | [standalone]
| From | James Harris <james.harris.1@gmail.com> |
|---|---|
| Date | 2016-04-01 10:06 +0100 |
| Message-ID | <ndldhq$2s2$1@dont-email.me> |
| In reply to | #9346 |
On 01/04/2016 08:58, wolfgang kern wrote: ... > Whom would you trust...? MI5? __ No, no organisation. That is too large a group of people. I think I would rather there was a dedicated team somewhere and they were the only ones in the country who had access to our data. They would be selected for their intelligence, sense and probity. They would be professionally trained for the role and undergo continuous assessment. I would, however, allow slightly wider access (e.g. by a larger team including certain government officials such as the Home Secretary, Prime Minister and Foreign Secretary) to metadata such as who has called whom and when. Just my view. -- James
[toc] | [prev] | [next] | [standalone]
| From | Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> |
|---|---|
| Date | 2016-03-29 17:39 -0400 |
| Message-ID | <20160329173929.65060450@_> |
| In reply to | #9324 |
On Tue, 29 Mar 2016 15:09:35 +0100 James Harris <james.harris.1@gmail.com> wrote: > Recently the US government wanted to extract data from an Apple phone > that had belonged to a terrorist because that information might help > the government prevent further terrorist attacks. > > Apple did not want to produce any software or system that could do > this because they wanted to sell phones which were known to keep > users' data private from anyone and everyone. Yes, even though bypassing the password lockout was probably only a two to three byte memory/code patch to a branch, or the equivalent of a NOP on a memory load instruction for the variable with the lockout count, or a change to a hard coded lockout value. I seriously doubt that this required any serious coding to modify. No encryption or complex processes is involved with this aspect. > AIUI some bright spark had an idea of how to break Apple's security > and took it to the US security people. And that person was proven > right. As a result, the US security services have got access to the > data on that phone. U.S. media here are saying that the rumors are it was an Israeli forensic data recovery firm known as Cellebrite. Supposedly, they copied out the contents of the NAND flash memory chips, much like copying a hard drive or floppy disk or the contents of an EEPROM. AIR, the phones also had some type of chip with a unique serial number or encryption key which was speculated would pose a problem. > Consequentially, Apple have been somewhat embarrassed that their > security has been broken. I don't know if they're embarrassed, yet. Apple got what they wanted, not to be forced to do something by the courts and FBI. Apple didn't have to spend any money on the FBI's demands. The FBI had to pay a company to solve their problem. If Apple was forced by warrant or court order to comply, the FBI would have got what they wanted for free and maybe the FBI would've set a new legal precedent too. If the technique used required hardware modification, i.e., un-soldering the memory chips to copy their contents, then this is a side-channel attack, which means it didn't attack the encryption itself. So, the software/hardware encryption may still be secure. It's just that the phone isn't. At the moment, Apple is suing to find out what technique was used. I don't see them as having any legal standing to find out. > They will almost certainly change their phone security now to > try to make future phones unbreakable. This will lead to the > same moral issues again. As I said once before, criminals and terrorists use whatever is available. If you make everything 100% private, they'll use that privacy to hide their crimes. If you make everything 100% open, they'll use that openness to find more victims. Compare the openness of entry used by terrorists in the Brussels attack versus the issue of privacy used by terrorists with Apple's phones. That's a complete dichotomy. Society can't have things both ways. They can't have both privacy and total safety. Society must make a tough choice as to which one is more beneficial over the long-term. Privacy has the benefit of preventing people from becoming victims in the first place. Governments want openness, so that you can't hide from taxation. > So, what are your views on this kind of issue with > operating system security? Personally, I know that any backdoor will be used by both governments and criminals. It may take criminals a bit longer to discover backdoors than the governments, but they eventually find out about anything that the government knows about. I also know that governments don't always have their citizen's best interest at heart and shouldn't be trusted. But, they are more beneficial than the criminals and terrorists. I happen to not like giving up freedoms in the name of safety or security. I would rather accept the rare risk, than give up my freedom. IMO, most willingly gave up their freedom in exchange for perceived safety from rather rare events. > Where is the line to be drawn between users' privacy > and people's safety? Any thoughts? The U.S. is founded upon the idea that the rights of the majority must defer to the rights of the individual. We call it "freedom" and "individualism." If the majority doesn't defer, then you have suppression and oppression. However, given recent terrorist events and a large increase in school attacks, the latter of which have plagued America from the start, much of America has come to accept some limits on their modern freedoms, albeit begrudgingly and reticently. Most of them were trivial, but some are harsh, unnecessary, and were forced upon the people by the U.S. government, e.g., TSA. Many who accepted this were convinced by others that this state of affairs was a temporary arrangement, and are still angry over the fact that it seems that it was not temporary, but permanent change. Many, many Americans want their lost or forfeited rights back. America is experiencing a conundrum of sorts. Certain rights are shifting toward the group while others that were historically in favor of the group are shifting towards individuals. Rod Pemberton
[toc] | [prev] | [next] | [standalone]
| From | James Harris <james.harris.1@gmail.com> |
|---|---|
| Date | 2016-03-31 00:13 +0100 |
| Message-ID | <ndhme3$9p5$1@dont-email.me> |
| In reply to | #9330 |
On 29/03/2016 22:39, Rod Pemberton wrote: > On Tue, 29 Mar 2016 15:09:35 +0100 > James Harris <james.harris.1@gmail.com> wrote: ... >> Consequentially, Apple have been somewhat embarrassed that their >> security has been broken. > > I don't know if they're embarrassed, yet. Well, their argument was that they wanted their phone encryption to be (known as) unbreakable. But someone broke it. ... >> They will almost certainly change their phone security now to >> try to make future phones unbreakable. This will lead to the >> same moral issues again. > > As I said once before, criminals and terrorists use whatever > is available. If you make everything 100% private, they'll > use that privacy to hide their crimes. If you make everything > 100% open, they'll use that openness to find more victims. > Compare the openness of entry used by terrorists in the Brussels > attack versus the issue of privacy used by terrorists with > Apple's phones. That's a complete dichotomy. Society can't > have things both ways. They can't have both privacy and total > safety. Society must make a tough choice as to which one is > more beneficial over the long-term. Privacy has the benefit > of preventing people from becoming victims in the first place. > Governments want openness, so that you can't hide from taxation. Yes, except that, to me the question is not so much one of open or closed but restricting who can have access to certain information. To illustrate, there was a story of some admin person burning the records of thousands of people onto two CDs and then popping them in the post. :-( That was a stupid thing to do and the CDs went missing. The problem, IMO, was permitting that admin person to see the data in the first place, and allowing any kind of copy to be made. Another story was of admin workers - in India, IIRC - who acquired customer details and built up their own database. They then sold this info on the black market. My view is I don't mind specific security services accessing anything on my computers if it saves my life and that of my family from terrorism but I don't want my info to be seen by anyone else. I would not even want the head of the government to see it without a court order. But there are people whose job it is to prevent terrorist attacks and one main reason they foil plots is because of accessing sensitive information. >> So, what are your views on this kind of issue with >> operating system security? > > Personally, I know that any backdoor will be used by > both governments and criminals. It may take criminals > a bit longer to discover backdoors than the governments, > but they eventually find out about anything that the > government knows about. That's a good point. If there is a way in then it is possible that someone other than a government agency will find it. I wonder if there is any way to restrict access to authorised officials. I cannot think of one. -- James
[toc] | [prev] | [next] | [standalone]
| From | Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> |
|---|---|
| Date | 2016-03-30 23:18 -0400 |
| Message-ID | <20160330231852.794ac607@_> |
| In reply to | #9335 |
On Thu, 31 Mar 2016 00:13:49 +0100 James Harris <james.harris.1@gmail.com> wrote: > On 29/03/2016 22:39, Rod Pemberton wrote: > > On Tue, 29 Mar 2016 15:09:35 +0100 > > James Harris <james.harris.1@gmail.com> wrote: > >> Consequentially, Apple have been somewhat embarrassed that their > >> security has been broken. > > > > I don't know if they're embarrassed, yet. > > Well, their argument was that they wanted their phone encryption to > be (known as) unbreakable. But someone broke it. I'm still not sure that the encryption was broken, only that the data was accessed through indirect means. > Yes, except that, to me the question is not so much one of open or > closed but restricting who can have access to certain information. > > To illustrate, there was a story of some admin person burning the > records of thousands of people onto two CDs and then popping them in > the post. :-( That was a stupid thing to do and the CDs went missing. > The problem, IMO, was permitting that admin person to see the data in > the first place, and allowing any kind of copy to be made. 1) how exactly does one administrate a computer system without also having access to user/customer/patient data? In order for the administrator of the computer systems to not have access to customer data, the data would have to be encrypted, that administrator would have to not have access to those encryption keys. This implies that there would need to be a second "administrator" for controlling the encryption keys for the restricted data and perhaps passwords for the account that could decrypt the data. Needing an extra employee is an extra expense, unless some other employee is given the duty. Most systems are not set up this way, i.e., the sole administrator usually has full access to everything. Apparently, the system Edward Snowden accessed was set up similarly, i.e., even the administrator was restricted as to what he could access, but he conned people into giving up their passwords, allowing decrypted access, whenever they had a computer problem. The brokerage I worked for had to set up two computer systems to mostly keep user data separate, but that only worked to ensure customer privacy from most employees, not everyone, Perhaps, 70% to 90% of the employees were blocked, I don't have exact figures. The people administering the customer account computer system, and the employees managing the customer accounts on behalf of customers, or those handling customer account problems had access to the customer's personal and account information. Some employees have to be trusted, typically many. 2) how do you prevent CDs or backups from being made? Most computers have CDs in them. Those same computers use the CDs, or laser-discs, or tape, etc, to make backups. It's usually the admin's job to make those backups. I'm not familiar with the particulars of the example you cite, but it was probably his job to do that, and then mail them to secure storage. He could have diverted the CDs, or they could have been lost, misplaced, or stolen. It's up to authorities to find out. > Another story was of admin workers - in India, IIRC - who acquired > customer details and built up their own database. They then sold this > info on the black market. All industries have these problems. Bank employees have access to your personal info and financial info. Hospitals have access to your personal info and health records. The human resources or personnel department at work has all your personal info, employment info, some insurance info and some health info. The government has access to all your personal info and tax records. This is an employee trust issue, and/or a process trust issue. Society needs way, way too many people in the loop of trust. :-( AISI, the real problem is either: 1) company's aren't willing to pay for good security 2) company's are ignorant of the ease with which computer security is breached by otherwise unskilled individuals > My view is I don't mind specific security services accessing > anything on my computers if it saves my life and that of my > family from terrorism Why would you be a target of terrorism? I mean, other than a random event, you wouldn't likely be targeted in advance by terrorists. You might be targeted in advance by criminals. So, why would your computer have anything related to terrorism on it which could be used by law enforcement to save your life? This is a "non sequitur" for me. Explain please. While in college, I roomed with a friend. We were in a large apartment complex, multiple buildings with many floors. In one of the adjacent buildings, one criminal found out where another lived and murdered him. My roommate immediately freaked out and decided he was going to move as soon as possible. The event had nothing to do with him or me. It wasn't even in our building. It was nearby in the same complex. It was a completely random event. I pointed this out to him. He still moved. Reason couldn't break his fear. From my perspective, this was an overreaction, but people respond to nearby terrorism in much the same way. What is the likelihood that a train station will have a repeat terrorist attack after law enforcement enhances their presence? It's slim to none. How long is it before people become comfortable with visiting that train station? Many years ... I had an an airplane flight just a couple of weeks after 9/11. I think there were maybe five or six people on the plane, not including the crew. I wouldn't doubt it if half the passengers were law enforcement. That flight would've been packed weeks earlier with hundreds of people. What was the probability that terrorists managed to attack a plane immediately after 9/11? It was slim to none. There are about 350 million people in the U.S. Look at the response of the U.S. government for only a few thousand killed. Homicide in the U.S. had four times as many deaths in 2001 as the 9/11 attacks. Homicide ranked as the 19th cause of death in 2001, well below the 1st ranked heart disease of 610,638. I'm not trivializing the 9/11 tragedy, loss of life, loss of loved ones, or that America was attacked, but we spent billions and lost as many or more soldiers as the terrorists killed. If that's not an overreaction, I don't know what is. And, we're financially responsible for rebuilding the countries we invaded in response to 9/11. And, those that survived our onslaught in the middle east will be our lethal enemies for generations. I don't see how this benefits the U.S. > but I don't want my info to be seen by anyone else. Don't encrypt the home computer. Don't put a password on it. Then, law enforcement can access it in an emergency situation. However, criminals would have full access too, if you were the victim of a break in. But, why they would steal the home computer is beyond me. They want stuff which is non-traceable, liquid, and easily salable, e.g., cash, credit cards, common jewelry, smartphones, GPS devices. In general, they don't want gold coin, rare coins, stamps, gold bars, exquisite jewelry, because all that stuff is unique, sometimes marked with a serial number, and is easily tracked by law enforcement via pawn shops or jewelry stores. Recent legal changes here even require people selling scrap for cash to provide their personal info on a form to the state to help prevent or reduce thefts. It's big brother. Everybody and everything will be tracked. After Brussels, they're trying to prohibit buying or using a smartphone without providing your personal information, i.e., no "burner" smartphones or pre-paid cash cellphones. Big Brother. Total government surveillance and tracking. > I would not even want the head of the government to > see it without a court order. Good choice. Can you enforce it? We found out we couldn't. I.e., rights of ordinary U.S. civilians were violated by a secret court, with the good intent of chasing terrorists, but the government still violated our rights in the process. The U.S. people have not, and probably will never, see any redress. > But there are people whose job it is to prevent terrorist > attacks and one main reason they foil plots is because of > accessing sensitive information. Didn't the Nazi's use similar rationale when they got everyone to snitch on the Jews in hiding? I.e., the Jews were a threat and it was the Nazi's job to get the information to prevent the threat? Or somesuch, ... Governments can rationalize anything. We see China as being authoritarian and oppressive, much like Nazi Germany. China sees themselves as enforcing the laws. Rod Pemberton
[toc] | [prev] | [next] | [standalone]
| From | "Alexei A. Frounze" <alexfrunews@gmail.com> |
|---|---|
| Date | 2016-03-31 00:31 -0700 |
| Message-ID | <f8f1171e-c351-4c6e-80ff-b2041a767781@googlegroups.com> |
| In reply to | #9337 |
On Wednesday, March 30, 2016 at 8:18:21 PM UTC-7, Rod Pemberton wrote: > But, why they would steal the home > computer is beyond me. They want stuff which is non-traceable, > liquid, and easily salable, e.g., cash, credit cards, common > jewelry, smartphones, GPS devices. In general, they don't want > gold coin, rare coins, stamps, gold bars, exquisite jewelry, > because all that stuff is unique, sometimes marked with a serial > number, and is easily tracked by law enforcement via pawn shops > or jewelry stores. While computers and cell phones have a bunch of unique IDs (serial numbers and whatnot, e.g. MAC addresses), they still get stolen and resold. And the police won't provide much help unless it's an interesting case for them (like with that San Bernardino terrorist). Those IDs must be traçable and if the victim doesn't have them on hand (not everyone writes them down (or keeps documentation with them) or sometimes they're on labels that wear off (common for laptops) and become unreadable, so it may be a bit too late to write them down sometimes), they should be obtainable through other means (tracing purchase orders, looking up the data that the ISP has stored, etc). But nobody will do that or even suggest that that may be done in order to identify the device when it turns up in some pawn shop if it's an ordinary theft, of which there are many. So, your laptop may be gone forever and the case eventually closed. Cars have license plates and VINs. There are many cams these days to track the plates. And yet your car can get stolen and then found moths later abandoned somewhere and somehow all this time it would be "under the radar" as if instantaneously vanishing and then instantaneously reappearing out of nowhere. Risky and stupid thefts, true. But apparently some thugs get away with them. Alex
[toc] | [prev] | [next] | [standalone]
| From | Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> |
|---|---|
| Date | 2016-03-31 16:57 -0400 |
| Message-ID | <20160331165744.1e845a26@_> |
| In reply to | #9338 |
On Thu, 31 Mar 2016 00:31:31 -0700 (PDT) "Alexei A. Frounze" <alexfrunews@gmail.com> wrote: > On Wednesday, March 30, 2016 at 8:18:21 PM UTC-7, Rod Pemberton wrote: > > But, why they would steal the home > > computer is beyond me. They want stuff which is non-traceable, > > liquid, and easily salable, e.g., cash, credit cards, common > > jewelry, smartphones, GPS devices. In general, they don't want > > gold coin, rare coins, stamps, gold bars, exquisite jewelry, > > because all that stuff is unique, sometimes marked with a serial > > number, and is easily tracked by law enforcement via pawn shops > > or jewelry stores. > > While computers and cell phones have a bunch of unique IDs > (serial numbers and whatnot, e.g. MAC addresses), they still > get stolen and resold. Yes, mostly, they get exported to other countries, usually poor countries, especially if they were stolen near port cities in California, New York or New Jersey, or around the Mississippi river. They're usually collected by gangs in trade for drugs. > Cars have license plates and VINs. There are many cams these > days to track the plates. And yet your car can get stolen > and then found moths later abandoned somewhere and somehow > all this time it would be "under the radar" as if > instantaneously vanishing and then instantaneously reappearing > out of nowhere. In the port cities, they'll be exported to Africa, especially from California, New York, and New Jersey. Criminal groups typically have undue influence on unionized dock workers. The government closely monitors imports for terrorism and criminality, but lacks funds to thoroughly vet exports, which allows for stolen product, e.g., stolen cars via New York mafia, and trade-based money laundering, e.g., imported Chinese clothing via Mexican cartels paid for with U.S. drug money. In other states, cars are reduced to parts. In such states, the stripped car body with VIN constitutes the car. So, the car parts, e.g., doors, engine, transmission, etc, once stripped from a stolen car, don't constitute stolen parts, and are perfectly legal to sell ... The stolen car body is quickly crushed for recycling. Other states classify car parts as stolen if the car was stolen. Of course, the owner has the right to sell parts from their car in all states. The mixing of stolen parts, legally removed parts, and legal parts removed from stolen cars, obscures criminal activity. Most of the time, these parts don't have serial numbers. The parts are typically shipped throughout the country to repair shops or to someone buying a part for repair, e.g., from a junk yard or from a car repair shop or found at a parts swap. Junk yards do a huge amount of business this way with legally obtained cars. One automotive junk yard near me does such a thorough job of breaking down cars, that you can literally buy a bag of all the nuts, bolts, screws, and connectors for any specific make and model of car, SUV, or truck, minus any damaged parts. Two of them literally have all the car parts, like doors, engines, transmissions, wheels, tires, etc hanging from the ceiling or placed on shelves. One of them even has a fully computerized inventory system like a modern auto parts store. There is no need to go out into a muddy field to remove parts or bring tools. Cash and carry. Rod Pemberton
[toc] | [prev] | [next] | [standalone]
| From | James Harris <james.harris.1@gmail.com> |
|---|---|
| Date | 2016-04-01 09:22 +0100 |
| Message-ID | <ndlavp$85d$1@dont-email.me> |
| In reply to | #9337 |
On 31/03/2016 04:18, Rod Pemberton wrote: > On Thu, 31 Mar 2016 00:13:49 +0100 > James Harris <james.harris.1@gmail.com> wrote: > >> On 29/03/2016 22:39, Rod Pemberton wrote: >>> On Tue, 29 Mar 2016 15:09:35 +0100 >>> James Harris <james.harris.1@gmail.com> wrote: > >>>> Consequentially, Apple have been somewhat embarrassed that their >>>> security has been broken. >>> >>> I don't know if they're embarrassed, yet. >> >> Well, their argument was that they wanted their phone encryption to >> be (known as) unbreakable. But someone broke it. > > I'm still not sure that the encryption was broken, only > that the data was accessed through indirect means. OK. >> Yes, except that, to me the question is not so much one of open or >> closed but restricting who can have access to certain information. >> >> To illustrate, there was a story of some admin person burning the >> records of thousands of people onto two CDs and then popping them in >> the post. :-( That was a stupid thing to do and the CDs went missing. >> The problem, IMO, was permitting that admin person to see the data in >> the first place, and allowing any kind of copy to be made. > > 1) how exactly does one administrate a computer system without > also having access to user/customer/patient data? I don't know. I have a nebulous idea but I don't know how practical it is. More below. > In order for the administrator of the computer systems > to not have access to customer data, the data would have > to be encrypted, that administrator would have to not have > access to those encryption keys. Administrators don't supply keys on demand but they interact with data by means of software. If anything, a program which had to display the data would have to have the key(s). Wouldn't it be feasible to say that a certain administrator, using a certain terminal and a particular program, could access a specific piece of data in a limited way? That way, access to the data could be limited by login id, terminal authorisation and accessing program. Then the terminal could be authorised by some means that suited the company, the program could be authorised by testing, and the data could thus be kept secure. Anyone accessing the data without authorisation would get gibberish. > This implies that there > would need to be a second "administrator" for controlling > the encryption keys for the restricted data and perhaps > passwords for the account that could decrypt the data. There would, at least, need to be someone to oversee the permissions-approval process but once approvals had been given and accesses were set up to be audited, normal operations could proceed without needing another person's input. > Needing an extra employee is an extra expense, unless some > other employee is given the duty. Most systems are not set > up this way, i.e., the sole administrator usually has full > access to everything. Apparently, the system Edward Snowden > accessed was set up similarly, i.e., even the administrator > was restricted as to what he could access, but he conned > people into giving up their passwords, allowing decrypted > access, whenever they had a computer problem. OK. I don't think any of is know whether Snowden's claims were real or false. The security services have a policy of neither confirming nor denying reports of what they can do. Snowden may have been making it up. > The brokerage I worked for had to set up two computer systems > to mostly keep user data separate, but that only worked to > ensure customer privacy from most employees, not everyone, > Perhaps, 70% to 90% of the employees were blocked, I don't have > exact figures. The people administering the customer account > computer system, and the employees managing the customer accounts > on behalf of customers, or those handling customer account > problems had access to the customer's personal and account > information. Some employees have to be trusted, typically many. > > > 2) how do you prevent CDs or backups from being made? > > Most computers have CDs in them. Those same computers use the CDs, > or laser-discs, or tape, etc, to make backups. It's usually the > admin's job to make those backups. I'm not familiar with the > particulars of the example you cite, but it was probably his job > to do that, and then mail them to secure storage. He could > have diverted the CDs, or they could have been lost, misplaced, > or stolen. It's up to authorities to find out. That illustrates that people who "need" access generally get access to entire files of information - and that there is no restriction on what they can do with those files. OSes have file permissions and that is simply not adequate. IMO it would be better to give people permission to specific fields of data. And, as above, if the program accessing the data has to be authorised to do so, that program can limit itself to, say, displaying data on a screen, and not provide an option to do anything else with the data. That would prevent administrators making copies. When info that has been certified to be publicly readable is stored on disc it can be stored unencrypted. All other info should be stored in an encrypted form. ... > AISI, the real problem is either: > 1) company's aren't willing to pay for good security How would they spend more money to improve security? > 2) company's are ignorant of the ease with which computer > security is breached by otherwise unskilled individuals Definitely. >> My view is I don't mind specific security services accessing >> anything on my computers if it saves my life and that of my >> family from terrorism > > Why would you be a target of terrorism? I mean, other than > a random event, you wouldn't likely be targeted in advance > by terrorists. You might be targeted in advance by criminals. > So, why would your computer have anything related to terrorism > on it which could be used by law enforcement to save your life? > This is a "non sequitur" for me. Explain please. Sorry, I don't mean me specifically. I was using "my" as a proxy for us as a population. To rephrase, I don't mind security services accessing our computers if it saves our lives from terrorism. I cannot actually think of a negative effect of allowing security services access to our computers. They would not be interested in most of us, only of people who might be a threat. I don't mind a limited group of people seeing my web browsing history or my emails or my texts etc. What I don't want is that info to escape and become visible to the wider public. > While in college, I roomed with a friend. We were in a large > apartment complex, multiple buildings with many floors. In > one of the adjacent buildings, one criminal found out where > another lived and murdered him. My roommate immediately > freaked out and decided he was going to move as soon as possible. > The event had nothing to do with him or me. It wasn't even in > our building. It was nearby in the same complex. It was a > completely random event. I pointed this out to him. He still > moved. Reason couldn't break his fear. From my perspective, > this was an overreaction, but people respond to nearby terrorism > in much the same way. > > What is the likelihood that a train station will have a repeat > terrorist attack after law enforcement enhances their presence? > It's slim to none. How long is it before people become > comfortable with visiting that train station? Many years ... Yes. It annoys me a little that security is visibly beefed-up _after_ a terrorist incident. I know they want to reassure. I suspect they also want to be seen to be doing something. But by then it is too late. Unfortunately, there have recently apparently been _thousands_ of jihadi fighters brought into Europe mixed in with other migrants. That concerns me far more. > I had an an airplane flight just a couple of weeks after 9/11. > I think there were maybe five or six people on the plane, not > including the crew. I wouldn't doubt it if half the passengers > were law enforcement. That flight would've been packed weeks > earlier with hundreds of people. What was the probability that > terrorists managed to attack a plane immediately after 9/11? > It was slim to none. Agreed, completely. > There are about 350 million people in the > U.S. Look at the response of the U.S. government for only a > few thousand killed. Homicide in the U.S. had four times as > many deaths in 2001 as the 9/11 attacks. Homicide ranked as > the 19th cause of death in 2001, well below the 1st ranked heart > disease of 610,638. I'm not trivializing the 9/11 tragedy, loss > of life, loss of loved ones, or that America was attacked, but > we spent billions and lost as many or more soldiers as the > terrorists killed. If that's not an overreaction, I don't know > what is. And, we're financially responsible for rebuilding the > countries we invaded in response to 9/11. And, those that > survived our onslaught in the middle east will be our lethal > enemies for generations. I don't see how this benefits the U.S. IMV the wars themselves are not to blame as much as people say. The problems were caused principally by the barbarous teachings within Islam. And secondarily by the West's lack of appreciation of the Islamic problems and what to do more than just win the battles. ... >> But there are people whose job it is to prevent terrorist >> attacks and one main reason they foil plots is because of >> accessing sensitive information. > > Didn't the Nazi's use similar rationale when they got > everyone to snitch on the Jews in hiding? I.e., the > Jews were a threat and it was the Nazi's job to get > the information to prevent the threat? Or somesuch, ... > Governments can rationalize anything. We see China > as being authoritarian and oppressive, much like Nazi > Germany. China sees themselves as enforcing the laws. Yes, good point. If one government's designated security services can access data what about the security services of another government? It would be difficult for an OS provider to have to decide which governments could have access! Actually, I am surprised that Apple is not subject to US laws which make it compulsory for them to allow the US security services to access their products. AIUI no one can export strong encryption from the US. Maybe that also gives the lie to Edward Snowden's claims about the Smurfs he alleges to be contained within people's phones...? -- James
[toc] | [prev] | [next] | [standalone]
Page 1 of 2 [1] 2 Next page →
Back to top | Article view | alt.os.development
csiph-web