Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > alt.os.development > #9324 > unrolled thread

The morality of operating system security

Started byJames Harris <james.harris.1@gmail.com>
First post2016-03-29 15:09 +0100
Last post2016-04-27 07:44 +0100
Articles 20 on this page of 37 — 7 participants

Back to article view | Back to alt.os.development


Contents

  The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-29 15:09 +0100
    Re: The morality of operating system security JJ <jj4public@vfemail.net> - 2016-03-30 00:03 +0700
      Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-03-29 19:39 +0200
      Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-30 23:54 +0100
        Re: The morality of operating system security JJ <jj4public@vfemail.net> - 2016-03-31 06:16 +0700
    Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-03-29 20:01 +0200
      Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-30 23:59 +0100
        Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-03-31 17:47 +0200
          Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 08:11 +0100
            Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-04-01 18:25 +0200
              Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 23:10 +0100
                Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-04-02 14:18 +0200
        Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-04-01 09:58 +0200
          Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 10:06 +0100
    Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-29 17:39 -0400
      Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-31 00:13 +0100
        Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-30 23:18 -0400
          Re: The morality of operating system security "Alexei A. Frounze" <alexfrunews@gmail.com> - 2016-03-31 00:31 -0700
            Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-31 16:57 -0400
          Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 09:22 +0100
            Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-01 20:24 -0400
              Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-09 18:25 +0100
                Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-09 18:57 -0400
                  Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-26 09:07 +0100
                    Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-26 23:58 -0400
                      Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-27 07:01 +0100
                        Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-27 05:42 -0400
                          Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-03 00:05 +0100
                            Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-03 16:55 -0400
                              Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-04 09:00 +0100
                                Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-04 17:22 -0400
                                  Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-05 17:02 +0100
                                    Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-05 17:55 -0400
                                      Re: The morality of operating system security "Kerr Mudd-John" <admin@127.0.0.1> - 2016-05-09 14:58 +0100
                                    Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-12 17:46 -0400
                                      Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-15 00:11 +0100
                      Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-27 07:44 +0100

Page 1 of 2  [1] 2  Next page →


#9324 — The morality of operating system security

FromJames Harris <james.harris.1@gmail.com>
Date2016-03-29 15:09 +0100
SubjectThe morality of operating system security
Message-ID<nde25k$bkn$1@dont-email.me>
Recently the US government wanted to extract data from an Apple phone 
that had belonged to a terrorist because that information might help the 
government prevent further terrorist attacks.

Apple did not want to produce any software or system that could do this 
because they wanted to sell phones which were known to keep users' data 
private from anyone and everyone.

AIUI some bright spark had an idea of how to break Apple's security and 
took it to the US security people. And that person was proven right. As 
a result, the US security services have got access to the data on that 
phone.

Consequentially, Apple have been somewhat embarrassed that their 
security has been broken. They will almost certainly change their phone 
security now to try to make future phones unbreakable. This will lead to 
the same moral issues again.

So, what are your views on this kind of issue with operating system 
security? Where is the line to be drawn between users' privacy and 
people's safety? Any thoughts?

-- 
James

[toc] | [next] | [standalone]


#9325

FromJJ <jj4public@vfemail.net>
Date2016-03-30 00:03 +0700
Message-ID<lxqmep70413u$.bzvwpx5519l6.dlg@40tude.net>
In reply to#9324
On Tue, 29 Mar 2016 15:09:35 +0100, James Harris wrote:
> 
> So, what are your views on this kind of issue with operating system 
> security? Where is the line to be drawn between users' privacy and 
> people's safety? Any thoughts?

It's people's right to have both security and privacy. That I agree. But
those that don't want the government to be messing with theirs for whatever
reason, clearly doesn't give a crap about 9/11 event. That being said,
there's always a possibility of a conspiracy. So, food for thought.

My personal opinion is that, my way of life is to trust others before they
give their trust to you. So, I'd trust my government (not yours) if they
need my personal data for the right reason, and as long as they ask first
and not getting the data without consent.

[toc] | [prev] | [next] | [standalone]


#9326

From"wolfgang kern" <nowhere@never.at>
Date2016-03-29 19:39 +0200
Message-ID<ndehmd$24s$1@gioia.aioe.org>
In reply to#9325
"JJ" <jj4public@vfemail.net> schrieb im Newsbeitrag 
news:lxqmep70413u$.bzvwpx5519l6.dlg@40tude.net...
> On Tue, 29 Mar 2016 15:09:35 +0100, James Harris wrote:
>>
>> So, what are your views on this kind of issue with operating system
>> security? Where is the line to be drawn between users' privacy and
>> people's safety? Any thoughts?
>
> It's people's right to have both security and privacy. That I agree. But
> those that don't want the government to be messing with theirs for 
> whatever
> reason, clearly doesn't give a crap about 9/11 event. That being said,
> there's always a possibility of a conspiracy. So, food for thought.
>
> My personal opinion is that, my way of life is to trust others before they
> give their trust to you. So, I'd trust my government (not yours) if they
> need my personal data for the right reason, and as long as they ask first
> and not getting the data without consent. 

[toc] | [prev] | [next] | [standalone]


#9333

FromJames Harris <james.harris.1@gmail.com>
Date2016-03-30 23:54 +0100
Message-ID<ndhl91$5p2$1@dont-email.me>
In reply to#9325
On 29/03/2016 18:03, JJ wrote:
> On Tue, 29 Mar 2016 15:09:35 +0100, James Harris wrote:
>>
>> So, what are your views on this kind of issue with operating system
>> security? Where is the line to be drawn between users' privacy and
>> people's safety? Any thoughts?
>
> It's people's right to have both security and privacy. That I agree. But
> those that don't want the government to be messing with theirs for whatever
> reason, clearly doesn't give a crap about 9/11 event. That being said,
> there's always a possibility of a conspiracy. So, food for thought.
>
> My personal opinion is that, my way of life is to trust others before they
> give their trust to you. So, I'd trust my government (not yours) if they
> need my personal data for the right reason, and as long as they ask first
> and not getting the data without consent.

Asking first would give the person time to delete/wipe the data wouldn't it?

-- 
James

[toc] | [prev] | [next] | [standalone]


#9336

FromJJ <jj4public@vfemail.net>
Date2016-03-31 06:16 +0700
Message-ID<ikb6on43lmj6.qwausmjlcpnk$.dlg@40tude.net>
In reply to#9333
On Wed, 30 Mar 2016 23:54:04 +0100, James Harris wrote:
> 
> Asking first would give the person time to delete/wipe the data wouldn't it?

Yes, unfortunately. But without that, governments would have absolute power
over everything. Like shoot first, ask later. Such governments are bound to
fall sooner or later.

[toc] | [prev] | [next] | [standalone]


#9327

From"wolfgang kern" <nowhere@never.at>
Date2016-03-29 20:01 +0200
Message-ID<ndehme$24s$2@gioia.aioe.org>
In reply to#9324
James Harris posted:

> Recently the US government wanted to extract data from an Apple phone 
> that had belonged to a terrorist because that information might help the 
> government prevent further terrorist attacks.
 
> Apple did not want to produce any software or system that could do this 
> because they wanted to sell phones which were known to keep users' data 
> private.

I'd agree here with Apple. Privacy is a main issue for all of us who 
like to keep their private oppinion about whatsoever even shown. 
 
> AIUI some bright spark had an idea of how to break Apple's security and 
> took it to the US security people. And that person was proven right. As 
> a result, the US security services have got access to the data on that 
> phone.

If Apple would give up, then we all become victims to everyone who 
like to see us in an unprotected world like MSN or Google...

> Consequentially, Apple have been somewhat embarrassed that their 
> security has been broken. They will almost certainly change their phone 
> security now to try to make future phones unbreakable. This will lead to 
> the same moral issues again.

I hope that this never happens, but we should be aware of it !

> So, what are your views on this kind of issue with operating system 
> security? Where is the line to be drawn between users' privacy and 
> people's safety? Any thoughts?

sure. many ideas are already around.
but it's easy to protect your own OS from any attacks from this side.

The main idea is to never trust anything which you didn't youself 
and never execute code which is not marked as compatible and/or not 
doubtfree.

__
wolfgang 
safety got a price(costs), but a smart OS wont ever encounter an issue.
 

[toc] | [prev] | [next] | [standalone]


#9334

FromJames Harris <james.harris.1@gmail.com>
Date2016-03-30 23:59 +0100
Message-ID<ndhljn$7d5$1@dont-email.me>
In reply to#9327
On 29/03/2016 19:01, wolfgang kern wrote:
> James Harris posted:
>
>> Recently the US government wanted to extract data from an Apple phone
>> that had belonged to a terrorist because that information might help
>> the government prevent further terrorist attacks.
>
>> Apple did not want to produce any software or system that could do
>> this because they wanted to sell phones which were known to keep
>> users' data private.
>
> I'd agree here with Apple. Privacy is a main issue for all of us who
> like to keep their private oppinion about whatsoever even shown.

I would not want Apple or any commercial company to get access to our 
private files. If some data could help prevent terrorist acts, though, 
isn't it wrong to keep the data hidden?

>> AIUI some bright spark had an idea of how to break Apple's security
>> and took it to the US security people. And that person was proven
>> right. As a result, the US security services have got access to the
>> data on that phone.
>
> If Apple would give up, then we all become victims to everyone who like
> to see us in an unprotected world like MSN or Google...

Not necessarily. You can drink a glass of water without drowning and you 
can open data to designated security services without letting everyone 
have access. No?

-- 
James

[toc] | [prev] | [next] | [standalone]


#9339

FromBernhard Schornak <schornak@web.de>
Date2016-03-31 17:47 +0200
Message-ID<ndjgkk$eum$2@dont-email.me>
In reply to#9334
James Harris wrote:


> On 29/03/2016 19:01, wolfgang kern wrote:
>>
>> If Apple would give up, then we all become victims to everyone who like
>> to see us in an unprotected world like MSN or Google...
>
> Not necessarily. You can drink a glass of water without drowning and you can open data to designated
> security services without letting everyone have access. No?


No. Those who want to commit crimes have opportunities to
hide their masterplans from the eyes of companies as well
as from any secret service, but all "average people" with
no criminal background will lose a piece of their freedom
and privacy. Buying safety comes at the cost of giving up
your freedom.

„LEWER DOOD AS SLAAV“

(Better dead than slave...)


Greetings from Augsburg

Bernhard Schornak

[toc] | [prev] | [next] | [standalone]


#9344

FromJames Harris <james.harris.1@gmail.com>
Date2016-04-01 08:11 +0100
Message-ID<ndl6q3$u0v$1@dont-email.me>
In reply to#9339
On 31/03/2016 16:47, Bernhard Schornak wrote:
> James Harris wrote:
>
>
>> On 29/03/2016 19:01, wolfgang kern wrote:
>>>
>>> If Apple would give up, then we all become victims to everyone who like
>>> to see us in an unprotected world like MSN or Google...
>>
>> Not necessarily. You can drink a glass of water without drowning and
>> you can open data to designated
>> security services without letting everyone have access. No?
>
>
> No. Those who want to commit crimes have opportunities to
> hide their masterplans from the eyes of companies as well
> as from any secret service, but all "average people" with
> no criminal background will lose a piece of their freedom
> and privacy. Buying safety comes at the cost of giving up
> your freedom.

I would counter that by saying that - at least in the free world - the 
security services are not interested in "average people" so we would not 
lose our privacy. This is not the Stasi.

https://en.wikipedia.org/wiki/Stasi

That said, an OS can be used by people suffering under repressive regimes.

And, if a benevolent government can get into an OS maybe a repressive 
one can too. It may be impossible to allow, say, the Austrian government 
to access data without also preventing the North Koreans from accessing 
the same data.

> „LEWER DOOD AS SLAAV“
>
> (Better dead than slave...)

:-(

That is not the choice!

-- 
James

[toc] | [prev] | [next] | [standalone]


#9356

FromBernhard Schornak <schornak@web.de>
Date2016-04-01 18:25 +0200
Message-ID<ndm77l$b09$2@dont-email.me>
In reply to#9344
James Harris wrote:


> On 31/03/2016 16:47, Bernhard Schornak wrote:
>> James Harris wrote:
>>
>>> On 29/03/2016 19:01, wolfgang kern wrote:
>>>>
>>>> If Apple would give up, then we all become victims to everyone who like
>>>> to see us in an unprotected world like MSN or Google...
>>>
>>> Not necessarily. You can drink a glass of water without drowning and
>>> you can open data to designated
>>> security services without letting everyone have access. No?
>>
>> No. Those who want to commit crimes have opportunities to
>> hide their masterplans from the eyes of companies as well
>> as from any secret service, but all "average people" with
>> no criminal background will lose a piece of their freedom
>> and privacy. Buying safety comes at the cost of giving up
>> your freedom.
>
> I would counter that by saying that - at least in the free world - the security services are not
> interested in "average people" so we would not lose our privacy. This is not the Stasi.
>
> https://en.wikipedia.org/wiki/Stasi
>
> That said, an OS can be used by people suffering under repressive regimes.
>
> And, if a benevolent government can get into an OS maybe a repressive one can too. It may be
> impossible to allow, say, the Austrian government to access data without also preventing the North
> Koreans from accessing the same data.


http://tinyurl.com/ndh5y68
http://www.cbsnews.com/feature/nsa-surveillance-exposed/
http://tinyurl.com/mgsuu4z

And these guys are claiming to be the good ones. Now: Imagine
what a(ny) government might do with the collected data. It is
not a question of "if these data were used", it is a question
of "when will the first bureauctrat (ab)use these data". Have
a look at the news, and you will know we *crossed* this point
a long time ago.

They always know where you are and what you're doing, and the
latest gadgets like "smart watches" provide even more control
over those who follow "hypes" without thinking: With personal
data (like your heartbeat) they can calculate if you're doing
allowed things or if you are going to do something illegal (a
good evaluation software can interpret data like an increased
pulse and predict what a person is doing with high accuracy).

I'm surely no one who believes in urban legends or conspiracy
theories - I prefer knowledge over beliefs and speculations -
but we should walk around with open eyes and see the obvious.
It's not about secret societies, it is about human nature and
logical thinking: As long as there is a faint chance to abuse
something, there will be someone who takes this chance sooner
or later...


>> „LEWER DOOD AS SLAAV“
>>
>> (Better dead than slave...)
>
> :-(
>
> That is not the choice!


Maybe not your's. This sentence is part of *some* old Frisian
emblems. I could not find pages with English translation, so:

https://de.wikipedia.org/wiki/Liewer_d%C3%BCd_a%C3%9F_Slaawe

"The motto *„LEWER DOOD AS SLAAV“* (umlaut-free version) is a
  Frisian political motto from the 19th century.

  ..."

For myself - I really preferred death over a life as property
of someone else. It is the European dream to live our life in
dignity and enjoy our freedom, isn't it?


Have a nice weekend!

Bernhard Schornak

[toc] | [prev] | [next] | [standalone]


#9363

FromJames Harris <james.harris.1@gmail.com>
Date2016-04-01 23:10 +0100
Message-ID<ndmrf7$tu1$1@dont-email.me>
In reply to#9356
On 01/04/2016 17:25, Bernhard Schornak wrote:
> James Harris wrote:
>
>
>> On 31/03/2016 16:47, Bernhard Schornak wrote:
>>> James Harris wrote:
>>>
>>>> On 29/03/2016 19:01, wolfgang kern wrote:

...

> http://tinyurl.com/ndh5y68
> http://www.cbsnews.com/feature/nsa-surveillance-exposed/
> http://tinyurl.com/mgsuu4z

Thanks. The first and last links were interesting.

I don't mind the NSA or the UK police getting tracking records for my 
phone. But I don't want Microsoft or Google or any commercial company to 
know how where my phone goes and when. Unfortunately, AIUI, they do, and 
I expect they use it for commercial profiling.

...

>>> „LEWER DOOD AS SLAAV“
>>>
>>> (Better dead than slave...)
>>
>> :-(
>>
>> That is not the choice!
>
>
> Maybe not your's.

...

> For myself - I really preferred death over a life as property
> of someone else. It is the European dream to live our life in
> dignity and enjoy our freedom, isn't it?

As said, I don't want commercial companies getting personal profiling 
data but I don't mind my government's security services getting it.

For me, the choice is not between death and slavery (that is far too 
melodramatic) but it is a choice between privacy and safety. I don't 
mind us losing some privacy (to very specific governmental agencies 
only) if it will help to keep us safe.

This is one of those false choices. People ask if we are willing to have 
the government access our private data. What they don't mention is the 
limits on what they can see or who can see it, or that most of us are 
totally uninteresting to the security services.

Nor do they mention how it helps protect us from lethal threats - and 
also, for that matter, helps protect us from legitimate fear of danger 
so that we can go about our lives without worrying about where trouble 
is to strike next.

IIRC they said that _ten_ terror attacks were prevented last year in the 
UK due to intelligence gathering. How would we feel if there had, 
instead, been ten terrorist attacks?

That's a long way of explaining why I say that, to me, the choice is 
nothing at all to do with slavery(!) but is between privacy and safety.

-- 
James

[toc] | [prev] | [next] | [standalone]


#9376

FromBernhard Schornak <schornak@web.de>
Date2016-04-02 14:18 +0200
Message-ID<ndod4d$biu$4@dont-email.me>
In reply to#9363
James Harris wrote:


> On 01/04/2016 17:25, Bernhard Schornak wrote:
>> James Harris wrote:
>>
>>> On 31/03/2016 16:47, Bernhard Schornak wrote:
>>>> James Harris wrote:
>
>> http://tinyurl.com/ndh5y68
>> http://www.cbsnews.com/feature/nsa-surveillance-exposed/
>> http://tinyurl.com/mgsuu4z
>
> Thanks. The first and last links were interesting.
>
> I don't mind the NSA or the UK police getting tracking records for my phone. But I don't want
> Microsoft or Google or any commercial company to know how where my phone goes and when.
> Unfortunately, AIUI, they do, and I expect they use it for commercial profiling.


I do not like if *anyone* tries to track me or my neighbors or
anybody else. Technologies enabling governments to track their
citicens are not developed by the government. In general, most
technologies (including software!) are developed by commercial
companies who want to generate profit with their products. The
most profits can be made with virtual wares like tracking data
of a representative quantity collected from all social classes
populating the country. I bet the big IT companies have a much
denser sieve collecting *much more* data than governments ever
can collect. Data will replace money in the long term.


>>>> „LEWER DOOD AS SLAAV“
>>>>
>>>> (Better dead than slave...)
>>>
>>> :-(
>>>
>>> That is not the choice!
>>
>>
>> Maybe not your's.
>
> ...
>
>> For myself - I really preferred death over a life as property
>> of someone else. It is the European dream to live our life in
>> dignity and enjoy our freedom, isn't it?
>
> As said, I don't want commercial companies getting personal profiling data but I don't mind my
> government's security services getting it.
>
> For me, the choice is not between death and slavery (that is far too melodramatic) but it is a
> choice between privacy and safety. I don't mind us losing some privacy (to very specific
> governmental agencies only) if it will help to keep us safe.
>
> This is one of those false choices. People ask if we are willing to have the government access our
> private data. What they don't mention is the limits on what they can see or who can see it, or that
> most of us are totally uninteresting to the security services.
>
> Nor do they mention how it helps protect us from lethal threats - and also, for that matter, helps
> protect us from legitimate fear of danger so that we can go about our lives without worrying about
> where trouble is to strike next.
>
> IIRC they said that _ten_ terror attacks were prevented last year in the UK due to intelligence
> gathering. How would we feel if there had, instead, been ten terrorist attacks?
>
> That's a long way of explaining why I say that, to me, the choice is nothing at all to do with
> slavery(!) but is between privacy and safety.


Wrong. The Belgian autorities and police *got* information and
warnings about planned attacks from secret services and police
of several countries. Nevertheless, they ignored that evidence
and watched how those plans were fulfilled.

As long as we live in democratic countries (in accordance with
the rule of law), we have to obey our laws and cannot allow to
observe and track citicens without enactment of an independent
judge. I'm pretty sure no judge ever enacted the "data mining"
of the NSA or equivalent services in Europe. Safety is the one
face of the coin, breaking laws the other one. We cannot claim
to be the good ones as long as we do not respect our own laws,
and we cannot demand that terrorists have to obey our law when
we do not obey its rules ourselves.

I agree to observe those who act in a suspiciuos way, if there
is evidence they plan any criminal acts. I never will agree to
observe the entire population and collect all data we can get,
because these data *might* become handy if we want to look for
criminal acts (including terrorist attacks).

Allowing data preservation for entire countries turns the rule
of "General Presumption Of Innocence" into "General Suspicion"
(Generalverdacht). I don't think anyone wants such a thing: It
undermines our rights and assumes everyone is a criminal until
the accused can provide evidence s/he is innocent (exactly the
opposite of the rule of law practised in civilised countries).


Greetings from Augsburg

Bernhard Schornak

[toc] | [prev] | [next] | [standalone]


#9346

From"wolfgang kern" <nowhere@never.at>
Date2016-04-01 09:58 +0200
Message-ID<ndl9pg$b50$1@gioia.aioe.org>
In reply to#9334
James Harris wrote:

>>> Recently the US government wanted to extract data from an Apple phone
>>> that had belonged to a terrorist because that information might help
>>> the government prevent further terrorist attacks.

>>> Apple did not want to produce any software or system that could do
>>> this because they wanted to sell phones which were known to keep
>>> users' data private.

>> I'd agree here with Apple. Privacy is a main issue for all of us who
>> like to keep their private oppinion about whatsoever even shown.

> I would not want Apple or any commercial company to get access to our 
> private files. If some data could help prevent terrorist acts, though, 
> isn't it wrong to keep the data hidden?

Sure, but what would my clients say if I'd hand the government a 
program which overrides admin passwords and encription keys ?  

Such a program will fail anyway because only the owner can alter 
admin rights, so even I cannot bypass the wall I once created by 
using morphing algos depending on the admins key (min.512 byte).
On a 4GHz machine it takes only 1e35 years to break it.

>>> AIUI some bright spark had an idea of how to break Apple's security
>>> and took it to the US security people. And that person was proven
>>> right. As a result, the US security services have got access to the
>>> data on that phone.

>> If Apple would give up, then we all become victims to everyone who 
>> like to see us in an unprotected world like MSN or Google...
 
> Not necessarily. You can drink a glass of water without drowning and you 
> can open data to designated security services without letting everyone 
> have access. No?

Whom would you trust...?  MI5? 
__
wolfgang 

[toc] | [prev] | [next] | [standalone]


#9349

FromJames Harris <james.harris.1@gmail.com>
Date2016-04-01 10:06 +0100
Message-ID<ndldhq$2s2$1@dont-email.me>
In reply to#9346
On 01/04/2016 08:58, wolfgang kern wrote:

...

> Whom would you trust...?  MI5? __

No, no organisation. That is too large a group of people. I think I 
would rather there was a dedicated team somewhere and they were the only 
ones in the country who had access to our data. They would be selected 
for their intelligence, sense and probity. They would be professionally 
trained for the role and undergo continuous assessment.

I would, however, allow slightly wider access (e.g. by a larger team 
including certain government officials such as the Home Secretary, Prime 
Minister and Foreign Secretary) to metadata such as who has called whom 
and when.

Just my view.

-- 
James

[toc] | [prev] | [next] | [standalone]


#9330

FromRod Pemberton <NoHaveNotOne@bcczxcfre.cmm>
Date2016-03-29 17:39 -0400
Message-ID<20160329173929.65060450@_>
In reply to#9324
On Tue, 29 Mar 2016 15:09:35 +0100
James Harris <james.harris.1@gmail.com> wrote:

> Recently the US government wanted to extract data from an Apple phone 
> that had belonged to a terrorist because that information might help
> the government prevent further terrorist attacks.
> 
> Apple did not want to produce any software or system that could do
> this because they wanted to sell phones which were known to keep
> users' data private from anyone and everyone.

Yes, even though bypassing the password lockout was
probably only a two to three byte memory/code patch
to a branch, or the equivalent of a NOP on a memory
load instruction for the variable with the lockout
count, or a change to a hard coded lockout value.
I seriously doubt that this required any serious
coding to modify.  No encryption or complex processes
is involved with this aspect.

> AIUI some bright spark had an idea of how to break Apple's security
> and took it to the US security people. And that person was proven
> right. As a result, the US security services have got access to the
> data on that phone.

U.S. media here are saying that the rumors are it was
an Israeli forensic data recovery firm known as Cellebrite.
Supposedly, they copied out the contents of the NAND
flash memory chips, much like copying a hard drive or
floppy disk or the contents of an EEPROM.  AIR, the phones
also had some type of chip with a unique serial number
or encryption key which was speculated would pose a problem.

> Consequentially, Apple have been somewhat embarrassed that their 
> security has been broken.

I don't know if they're embarrassed, yet.  Apple got what
they wanted, not to be forced to do something by the courts
and FBI.  Apple didn't have to spend any money on the FBI's
demands.  The FBI had to pay a company to solve their problem.
If Apple was forced by warrant or court order to comply, the
FBI would have got what they wanted for free and maybe the
FBI would've set a new legal precedent too.

If the technique used required hardware modification, i.e.,
un-soldering the memory chips to copy their contents, then
this is a side-channel attack, which means it didn't attack
the encryption itself.  So, the software/hardware encryption
may still be secure.  It's just that the phone isn't.  At the
moment, Apple is suing to find out what technique was used.
I don't see them as having any legal standing to find out.

> They will almost certainly change their phone security now to
> try to make future phones unbreakable. This will lead to the
> same moral issues again.

As I said once before, criminals and terrorists use whatever
is available.  If you make everything 100% private, they'll
use that privacy to hide their crimes.  If you make everything
100% open, they'll use that openness to find more victims.
Compare the openness of entry used by terrorists in the Brussels
attack versus the issue of privacy used by terrorists with
Apple's phones.  That's a complete dichotomy.  Society can't
have things both ways.  They can't have both privacy and total
safety.  Society must make a tough choice as to which one is
more beneficial over the long-term.  Privacy has the benefit
of preventing people from becoming victims in the first place.
Governments want openness, so that you can't hide from taxation.

> So, what are your views on this kind of issue with
> operating system security?

Personally, I know that any backdoor will be used by
both governments and criminals.  It may take criminals
a bit longer to discover backdoors than the governments,
but they eventually find out about anything that the
government knows about. I also know that governments
don't always have their citizen's best interest at heart
and shouldn't be trusted.  But, they are more beneficial
than the criminals and terrorists. I happen to not like
giving up freedoms in the name of safety or security.
I would rather accept the rare risk, than give up my freedom.
IMO, most willingly gave up their freedom in exchange for
perceived safety from rather rare events.

> Where is the line to be drawn between users' privacy
> and people's safety? Any thoughts?

The U.S. is founded upon the idea that the rights of the
majority must defer to the rights of the individual.  We
call it "freedom" and "individualism."  If the majority doesn't
defer, then you have suppression and oppression.  However,
given recent terrorist events and a large increase in school
attacks, the latter of which have plagued America from the
start, much of America has come to accept some limits on their
modern freedoms, albeit begrudgingly and reticently.  Most of
them were trivial, but some are harsh, unnecessary, and were
forced upon the people by the U.S. government, e.g., TSA.
Many who accepted this were convinced by others that this
state of affairs was a temporary arrangement, and are still
angry over the fact that it seems that it was not temporary,
but permanent change.  Many, many Americans want their lost
or forfeited rights back.  America is experiencing a conundrum
of sorts.  Certain rights are shifting toward the group while
others that were historically in favor of the group are
shifting towards individuals.


Rod Pemberton

[toc] | [prev] | [next] | [standalone]


#9335

FromJames Harris <james.harris.1@gmail.com>
Date2016-03-31 00:13 +0100
Message-ID<ndhme3$9p5$1@dont-email.me>
In reply to#9330
On 29/03/2016 22:39, Rod Pemberton wrote:
> On Tue, 29 Mar 2016 15:09:35 +0100
> James Harris <james.harris.1@gmail.com> wrote:

...

>> Consequentially, Apple have been somewhat embarrassed that their
>> security has been broken.
>
> I don't know if they're embarrassed, yet.

Well, their argument was that they wanted their phone encryption to be 
(known as) unbreakable. But someone broke it.

...

>> They will almost certainly change their phone security now to
>> try to make future phones unbreakable. This will lead to the
>> same moral issues again.
>
> As I said once before, criminals and terrorists use whatever
> is available.  If you make everything 100% private, they'll
> use that privacy to hide their crimes.  If you make everything
> 100% open, they'll use that openness to find more victims.
> Compare the openness of entry used by terrorists in the Brussels
> attack versus the issue of privacy used by terrorists with
> Apple's phones.  That's a complete dichotomy.  Society can't
> have things both ways.  They can't have both privacy and total
> safety.  Society must make a tough choice as to which one is
> more beneficial over the long-term.  Privacy has the benefit
> of preventing people from becoming victims in the first place.
> Governments want openness, so that you can't hide from taxation.

Yes, except that, to me the question is not so much one of open or 
closed but restricting who can have access to certain information.

To illustrate, there was a story of some admin person burning the 
records of thousands of people onto two CDs and then popping them in the 
post. :-( That was a stupid thing to do and the CDs went missing. The 
problem, IMO, was permitting that admin person to see the data in the 
first place, and allowing any kind of copy to be made.

Another story was of admin workers - in India, IIRC - who acquired 
customer details and built up their own database. They then sold this 
info on the black market.

My view is I don't mind specific security services accessing anything on 
my computers if it saves my life and that of my family from terrorism 
but I don't want my info to be seen by anyone else. I would not even 
want the head of the government to see it without a court order. But 
there are people whose job it is to prevent terrorist attacks and one 
main reason they foil plots is because of accessing sensitive information.

>> So, what are your views on this kind of issue with
>> operating system security?
>
> Personally, I know that any backdoor will be used by
> both governments and criminals.  It may take criminals
> a bit longer to discover backdoors than the governments,
> but they eventually find out about anything that the
> government knows about.

That's a good point. If there is a way in then it is possible that 
someone other than a government agency will find it. I wonder if there 
is any way to restrict access to authorised officials. I cannot think of 
one.

-- 
James

[toc] | [prev] | [next] | [standalone]


#9337

FromRod Pemberton <NoHaveNotOne@bcczxcfre.cmm>
Date2016-03-30 23:18 -0400
Message-ID<20160330231852.794ac607@_>
In reply to#9335
On Thu, 31 Mar 2016 00:13:49 +0100
James Harris <james.harris.1@gmail.com> wrote:

> On 29/03/2016 22:39, Rod Pemberton wrote:
> > On Tue, 29 Mar 2016 15:09:35 +0100
> > James Harris <james.harris.1@gmail.com> wrote:  

> >> Consequentially, Apple have been somewhat embarrassed that their
> >> security has been broken.  
> >
> > I don't know if they're embarrassed, yet.  
> 
> Well, their argument was that they wanted their phone encryption to
> be (known as) unbreakable. But someone broke it.

I'm still not sure that the encryption was broken, only
that the data was accessed through indirect means.

> Yes, except that, to me the question is not so much one of open or 
> closed but restricting who can have access to certain information.
> 
> To illustrate, there was a story of some admin person burning the 
> records of thousands of people onto two CDs and then popping them in
> the post. :-( That was a stupid thing to do and the CDs went missing.
> The problem, IMO, was permitting that admin person to see the data in
> the first place, and allowing any kind of copy to be made.

1) how exactly does one administrate a computer system without
also having access to user/customer/patient data?

In order for the administrator of the computer systems
to not have access to customer data, the data would have
to be encrypted, that administrator would have to not have
access to those encryption keys.  This implies that there
would need to be a second "administrator" for controlling
the encryption keys for the restricted data and perhaps
passwords for the account that could decrypt the data.
Needing an extra employee is an extra expense, unless some
other employee is given the duty. Most systems are not set
up this way, i.e., the sole administrator usually has full
access to everything.  Apparently, the system Edward Snowden
accessed was set up similarly, i.e., even the administrator
was restricted as to what he could access, but he conned
people into giving up their passwords, allowing decrypted
access, whenever they had a computer problem.

The brokerage I worked for had to set up two computer systems
to mostly keep user data separate, but that only worked to
ensure customer privacy from most employees, not everyone,
Perhaps, 70% to 90% of the employees were blocked, I don't have
exact figures.  The people administering the customer account
computer system, and the employees managing the customer accounts
on behalf of customers, or those handling customer account
problems had access to the customer's personal and account
information.  Some employees have to be trusted, typically many.


2) how do you prevent CDs or backups from being made?

Most computers have CDs in them.  Those same computers use the CDs,
or laser-discs, or tape, etc, to make backups.  It's usually the
admin's job to make those backups.  I'm not familiar with the
particulars of the example you cite, but it was probably his job
to do that, and then mail them to secure storage.  He could
have diverted the CDs, or they could have been lost, misplaced,
or stolen.  It's up to authorities to find out.

> Another story was of admin workers - in India, IIRC - who acquired 
> customer details and built up their own database. They then sold this 
> info on the black market.

All industries have these problems.  Bank employees have access
to your personal info and financial info.  Hospitals have access
to your personal info and health records.  The human resources or
personnel department at work has all your personal info, employment
info, some insurance info and some health info.  The government
has access to all your personal info and tax records.  This is
an employee trust issue, and/or a process trust issue.  Society
needs way, way too many people in the loop of trust.  :-(

AISI, the real problem is either:
1) company's aren't willing to pay for good security
2) company's are ignorant of the ease with which computer
security is breached by otherwise unskilled individuals

> My view is I don't mind specific security services accessing
> anything on my computers if it saves my life and that of my
> family from terrorism

Why would you be a target of terrorism?  I mean, other than
a random event, you wouldn't likely be targeted in advance
by terrorists.  You might be targeted in advance by criminals.
So, why would your computer have anything related to terrorism
on it which could be used by law enforcement to save your life?
This is a "non sequitur" for me.  Explain please.

While in college, I roomed with a friend.  We were in a large
apartment complex, multiple buildings with many floors.  In
one of the adjacent buildings, one criminal found out where
another lived and murdered him.  My roommate immediately
freaked out and decided he was going to move as soon as possible.
The event had nothing to do with him or me.  It wasn't even in
our building.  It was nearby in the same complex.  It was a
completely random event. I pointed this out to him.  He still
moved.  Reason couldn't break his fear.  From my perspective,
this was an overreaction, but people respond to nearby terrorism
in much the same way.

What is the likelihood that a train station will have a repeat
terrorist attack after law enforcement enhances their presence?
It's slim to none.  How long is it before people become
comfortable with visiting that train station?  Many years ...

I had an an airplane flight just a couple of weeks after 9/11.
I think there were maybe five or six people on the plane, not
including the crew.  I wouldn't doubt it if half the passengers
were law enforcement.  That flight would've been packed weeks
earlier with hundreds of people.  What was the probability that
terrorists managed to attack a plane immediately after 9/11?
It was slim to none.  There are about 350 million people in the
U.S.  Look at the response of the U.S. government for only a
few thousand killed.  Homicide in the U.S. had four times as
many deaths in 2001 as the 9/11 attacks.  Homicide ranked as
the 19th cause of death in 2001, well below the 1st ranked heart
disease of 610,638.  I'm not trivializing the 9/11 tragedy, loss
of life, loss of loved ones, or that America was attacked, but
we spent billions and lost as many or more soldiers as the
terrorists killed.  If that's not an overreaction, I don't know
what is.  And, we're financially responsible for rebuilding the
countries we invaded in response to 9/11.  And, those that
survived our onslaught in the middle east will be our lethal
enemies for generations.  I don't see how this benefits the U.S.

> but I don't want my info to be seen by anyone else.

Don't encrypt the home computer.  Don't put a password on it.
Then, law enforcement can access it in an emergency situation.

However, criminals would have full access too, if you were
the victim of a break in.  But, why they would steal the home
computer is beyond me.  They want stuff which is non-traceable,
liquid, and easily salable, e.g., cash, credit cards, common
jewelry, smartphones, GPS devices.  In general, they don't want
gold coin, rare coins, stamps, gold bars, exquisite jewelry,
because all that stuff is unique, sometimes marked with a serial
number, and is easily tracked by law enforcement via pawn shops
or jewelry stores.  Recent legal changes here even require
people selling scrap for cash to provide their personal info
on a form to the state to help prevent or reduce thefts.
It's big brother.  Everybody and everything will be tracked.
After Brussels, they're trying to prohibit buying or using
a smartphone without providing your personal information, i.e.,
no "burner" smartphones or pre-paid cash cellphones.  Big
Brother.  Total government surveillance and tracking.

> I would not even want the head of the government to
> see it without a court order.

Good choice.  Can you enforce it?  We found out we couldn't.
I.e., rights of ordinary U.S. civilians were violated by
a secret court, with the good intent of chasing terrorists,
but the government still violated our rights in the process.
The U.S. people have not, and probably will never, see any
redress.

> But there are people whose job it is to prevent terrorist
> attacks and one main reason they foil plots is because of
> accessing sensitive information.

Didn't the Nazi's use similar rationale when they got
everyone to snitch on the Jews in hiding?  I.e., the
Jews were a threat and it was the Nazi's job to get
the information to prevent the threat?  Or somesuch, ...
Governments can rationalize anything.  We see China
as being authoritarian and oppressive, much like Nazi
Germany.  China sees themselves as enforcing the laws.


Rod Pemberton

[toc] | [prev] | [next] | [standalone]


#9338

From"Alexei A. Frounze" <alexfrunews@gmail.com>
Date2016-03-31 00:31 -0700
Message-ID<f8f1171e-c351-4c6e-80ff-b2041a767781@googlegroups.com>
In reply to#9337
On Wednesday, March 30, 2016 at 8:18:21 PM UTC-7, Rod Pemberton wrote:
> But, why they would steal the home
> computer is beyond me.  They want stuff which is non-traceable,
> liquid, and easily salable, e.g., cash, credit cards, common
> jewelry, smartphones, GPS devices.  In general, they don't want
> gold coin, rare coins, stamps, gold bars, exquisite jewelry,
> because all that stuff is unique, sometimes marked with a serial
> number, and is easily tracked by law enforcement via pawn shops
> or jewelry stores. 

While computers and cell phones have a bunch of unique IDs
(serial numbers and whatnot, e.g. MAC addresses), they still
get stolen and resold. And the police won't provide much help
unless it's an interesting case for them (like with that
San Bernardino terrorist). Those IDs must be traçable and if
the victim doesn't have them on hand (not everyone writes them
down (or keeps documentation with them) or sometimes they're
on labels that wear off (common for laptops) and become
unreadable, so it may be a bit too late to write them down
sometimes), they should be obtainable through other means
(tracing purchase orders, looking up the data that the ISP has
stored, etc). But nobody will do that or even suggest that
that may be done in order to identify the device when it turns
up in some pawn shop if it's an ordinary theft, of which there
are many. So, your laptop may be gone forever and the case
eventually closed.
Cars have license plates and VINs. There are many cams these
days to track the plates. And yet your car can get stolen
and then found moths later abandoned somewhere and somehow
all this time it would be "under the radar" as if
instantaneously vanishing and then instantaneously reappearing
out of nowhere.
Risky and stupid thefts, true. But apparently some thugs get
away with them.

Alex

[toc] | [prev] | [next] | [standalone]


#9340

FromRod Pemberton <NoHaveNotOne@bcczxcfre.cmm>
Date2016-03-31 16:57 -0400
Message-ID<20160331165744.1e845a26@_>
In reply to#9338
On Thu, 31 Mar 2016 00:31:31 -0700 (PDT)
"Alexei A. Frounze" <alexfrunews@gmail.com> wrote:

> On Wednesday, March 30, 2016 at 8:18:21 PM UTC-7, Rod Pemberton wrote:

> > But, why they would steal the home
> > computer is beyond me.  They want stuff which is non-traceable,
> > liquid, and easily salable, e.g., cash, credit cards, common
> > jewelry, smartphones, GPS devices.  In general, they don't want
> > gold coin, rare coins, stamps, gold bars, exquisite jewelry,
> > because all that stuff is unique, sometimes marked with a serial
> > number, and is easily tracked by law enforcement via pawn shops
> > or jewelry stores.   
> 
> While computers and cell phones have a bunch of unique IDs
> (serial numbers and whatnot, e.g. MAC addresses), they still
> get stolen and resold. 

Yes, mostly, they get exported to other countries, usually poor
countries, especially if they were stolen near port cities in
California, New York or New Jersey, or around the Mississippi
river.  They're usually collected by gangs in trade for drugs.

> Cars have license plates and VINs. There are many cams these
> days to track the plates. And yet your car can get stolen
> and then found moths later abandoned somewhere and somehow
> all this time it would be "under the radar" as if
> instantaneously vanishing and then instantaneously reappearing
> out of nowhere.

In the port cities, they'll be exported to Africa, especially
from California, New York, and New Jersey.  Criminal groups
typically have undue influence on unionized dock workers.  The
government closely monitors imports for terrorism and criminality,
but lacks funds to thoroughly vet exports, which allows for stolen
product, e.g., stolen cars via New York mafia, and trade-based money
laundering, e.g., imported Chinese clothing via Mexican cartels paid
for with U.S. drug money.  In other states, cars are reduced to parts.
In such states, the stripped car body with VIN constitutes the car.
So, the car parts, e.g., doors, engine, transmission, etc, once
stripped from a stolen car, don't constitute stolen parts, and are
perfectly legal to sell ...  The stolen car body is quickly crushed
for recycling.  Other states classify car parts as stolen if the car
was stolen.  Of course, the owner has the right to sell parts from
their car in all states.  The mixing of stolen parts, legally removed
parts, and legal parts removed from stolen cars,  obscures criminal
activity.  Most of the time, these parts don't have serial numbers.
The parts are typically shipped throughout the country to repair
shops or to someone buying a part for repair, e.g., from a junk yard
or from a car repair shop or found at a parts swap.  Junk yards do a
huge amount of business this way with legally obtained cars.  One
automotive junk yard near me does such a thorough job of breaking
down cars, that you can literally buy a bag of all the nuts, bolts,
screws, and connectors for any specific make and model of car, SUV,
or truck, minus any damaged parts.  Two of them literally have all
the car parts, like doors, engines, transmissions, wheels, tires,
etc hanging from the ceiling or placed on shelves.  One of them
even has a fully computerized inventory system like a modern auto
parts store.  There is no need to go out into a muddy field to
remove parts or bring tools.  Cash and carry.


Rod Pemberton

[toc] | [prev] | [next] | [standalone]


#9347

FromJames Harris <james.harris.1@gmail.com>
Date2016-04-01 09:22 +0100
Message-ID<ndlavp$85d$1@dont-email.me>
In reply to#9337
On 31/03/2016 04:18, Rod Pemberton wrote:
> On Thu, 31 Mar 2016 00:13:49 +0100
> James Harris <james.harris.1@gmail.com> wrote:
>
>> On 29/03/2016 22:39, Rod Pemberton wrote:
>>> On Tue, 29 Mar 2016 15:09:35 +0100
>>> James Harris <james.harris.1@gmail.com> wrote:
>
>>>> Consequentially, Apple have been somewhat embarrassed that their
>>>> security has been broken.
>>>
>>> I don't know if they're embarrassed, yet.
>>
>> Well, their argument was that they wanted their phone encryption to
>> be (known as) unbreakable. But someone broke it.
>
> I'm still not sure that the encryption was broken, only
> that the data was accessed through indirect means.

OK.

>> Yes, except that, to me the question is not so much one of open or
>> closed but restricting who can have access to certain information.
>>
>> To illustrate, there was a story of some admin person burning the
>> records of thousands of people onto two CDs and then popping them in
>> the post. :-( That was a stupid thing to do and the CDs went missing.
>> The problem, IMO, was permitting that admin person to see the data in
>> the first place, and allowing any kind of copy to be made.
>
> 1) how exactly does one administrate a computer system without
> also having access to user/customer/patient data?

I don't know. I have a nebulous idea but I don't know how practical it 
is. More below.

> In order for the administrator of the computer systems
> to not have access to customer data, the data would have
> to be encrypted, that administrator would have to not have
> access to those encryption keys.

Administrators don't supply keys on demand but they interact with data 
by means of software. If anything, a program which had to display the 
data would have to have the key(s).

Wouldn't it be feasible to say that a certain administrator, using a 
certain terminal and a particular program, could access a specific piece 
of data in a limited way? That way, access to the data could be limited 
by login id, terminal authorisation and accessing program.

Then the terminal could be authorised by some means that suited the 
company, the program could be authorised by testing, and the data could 
thus be kept secure.

Anyone accessing the data without authorisation would get gibberish.

> This implies that there
> would need to be a second "administrator" for controlling
> the encryption keys for the restricted data and perhaps
> passwords for the account that could decrypt the data.

There would, at least, need to be someone to oversee the 
permissions-approval process but once approvals had been given and 
accesses were set up to be audited, normal operations could proceed 
without needing another person's input.

> Needing an extra employee is an extra expense, unless some
> other employee is given the duty. Most systems are not set
> up this way, i.e., the sole administrator usually has full
> access to everything.  Apparently, the system Edward Snowden
> accessed was set up similarly, i.e., even the administrator
> was restricted as to what he could access, but he conned
> people into giving up their passwords, allowing decrypted
> access, whenever they had a computer problem.

OK. I don't think any of is know whether Snowden's claims were real or 
false. The security services have a policy of neither confirming nor 
denying reports of what they can do. Snowden may have been making it up.

> The brokerage I worked for had to set up two computer systems
> to mostly keep user data separate, but that only worked to
> ensure customer privacy from most employees, not everyone,
> Perhaps, 70% to 90% of the employees were blocked, I don't have
> exact figures.  The people administering the customer account
> computer system, and the employees managing the customer accounts
> on behalf of customers, or those handling customer account
> problems had access to the customer's personal and account
> information.  Some employees have to be trusted, typically many.
 >
 >
> 2) how do you prevent CDs or backups from being made?
>
> Most computers have CDs in them.  Those same computers use the CDs,
> or laser-discs, or tape, etc, to make backups.  It's usually the
> admin's job to make those backups.  I'm not familiar with the
> particulars of the example you cite, but it was probably his job
> to do that, and then mail them to secure storage.  He could
> have diverted the CDs, or they could have been lost, misplaced,
> or stolen.  It's up to authorities to find out.

That illustrates that people who "need" access generally get access to 
entire files of information - and that there is no restriction on what 
they can do with those files. OSes have file permissions and that is 
simply not adequate.

IMO it would be better to give people permission to specific fields of 
data. And, as above, if the program accessing the data has to be 
authorised to do so, that program can limit itself to, say, displaying 
data on a screen, and not provide an option to do anything else with the 
data. That would prevent administrators making copies.

When info that has been certified to be publicly readable is stored on 
disc it can be stored unencrypted. All other info should be stored in an 
encrypted form.

...

> AISI, the real problem is either:
> 1) company's aren't willing to pay for good security

How would they spend more money to improve security?

> 2) company's are ignorant of the ease with which computer
> security is breached by otherwise unskilled individuals

Definitely.

>> My view is I don't mind specific security services accessing
>> anything on my computers if it saves my life and that of my
>> family from terrorism
>
> Why would you be a target of terrorism?  I mean, other than
> a random event, you wouldn't likely be targeted in advance
> by terrorists.  You might be targeted in advance by criminals.
> So, why would your computer have anything related to terrorism
> on it which could be used by law enforcement to save your life?
> This is a "non sequitur" for me.  Explain please.

Sorry, I don't mean me specifically. I was using "my" as a proxy for us 
as a population. To rephrase, I don't mind security services accessing 
our computers if it saves our lives from terrorism.

I cannot actually think of a negative effect of allowing security 
services access to our computers. They would not be interested in most 
of us, only of people who might be a threat.

I don't mind a limited group of people seeing my web browsing history or 
my emails or my texts etc. What I don't want is that info to escape and 
become visible to the wider public.

> While in college, I roomed with a friend.  We were in a large
> apartment complex, multiple buildings with many floors.  In
> one of the adjacent buildings, one criminal found out where
> another lived and murdered him.  My roommate immediately
> freaked out and decided he was going to move as soon as possible.
> The event had nothing to do with him or me.  It wasn't even in
> our building.  It was nearby in the same complex.  It was a
> completely random event. I pointed this out to him.  He still
> moved.  Reason couldn't break his fear.  From my perspective,
> this was an overreaction, but people respond to nearby terrorism
> in much the same way.
>
> What is the likelihood that a train station will have a repeat
> terrorist attack after law enforcement enhances their presence?
> It's slim to none.  How long is it before people become
> comfortable with visiting that train station?  Many years ...

Yes. It annoys me a little that security is visibly beefed-up _after_ a 
terrorist incident. I know they want to reassure. I suspect they also 
want to be seen to be doing something. But by then it is too late.

Unfortunately, there have recently apparently been _thousands_ of jihadi 
fighters brought into Europe mixed in with other migrants. That concerns 
me far more.

> I had an an airplane flight just a couple of weeks after 9/11.
> I think there were maybe five or six people on the plane, not
> including the crew.  I wouldn't doubt it if half the passengers
> were law enforcement.  That flight would've been packed weeks
> earlier with hundreds of people.  What was the probability that
> terrorists managed to attack a plane immediately after 9/11?
> It was slim to none.

Agreed, completely.

> There are about 350 million people in the
> U.S.  Look at the response of the U.S. government for only a
> few thousand killed.  Homicide in the U.S. had four times as
> many deaths in 2001 as the 9/11 attacks.  Homicide ranked as
> the 19th cause of death in 2001, well below the 1st ranked heart
> disease of 610,638.  I'm not trivializing the 9/11 tragedy, loss
> of life, loss of loved ones, or that America was attacked, but
> we spent billions and lost as many or more soldiers as the
> terrorists killed.  If that's not an overreaction, I don't know
> what is.  And, we're financially responsible for rebuilding the
> countries we invaded in response to 9/11.  And, those that
> survived our onslaught in the middle east will be our lethal
> enemies for generations.  I don't see how this benefits the U.S.

IMV the wars themselves are not to blame as much as people say. The 
problems were caused principally by the barbarous teachings within 
Islam. And secondarily by the West's lack of appreciation of the Islamic 
problems and what to do more than just win the battles.

...

>> But there are people whose job it is to prevent terrorist
>> attacks and one main reason they foil plots is because of
>> accessing sensitive information.
>
> Didn't the Nazi's use similar rationale when they got
> everyone to snitch on the Jews in hiding?  I.e., the
> Jews were a threat and it was the Nazi's job to get
> the information to prevent the threat?  Or somesuch, ...
> Governments can rationalize anything.  We see China
> as being authoritarian and oppressive, much like Nazi
> Germany.  China sees themselves as enforcing the laws.

Yes, good point. If one government's designated security services can 
access data what about the security services of another government? It 
would be difficult for an OS provider to have to decide which 
governments could have access!

Actually, I am surprised that Apple is not subject to US laws which make 
it compulsory for them to allow the US security services to access their 
products. AIUI no one can export strong encryption from the US.

Maybe that also gives the lie to Edward Snowden's claims about the 
Smurfs he alleges to be contained within people's phones...?

-- 
James

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | alt.os.development


csiph-web