Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > alt.os.development > #9337
| From | Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> |
|---|---|
| Newsgroups | alt.os.development |
| Subject | Re: The morality of operating system security |
| Date | 2016-03-30 23:18 -0400 |
| Organization | Aioe.org NNTP Server |
| Message-ID | <20160330231852.794ac607@_> (permalink) |
| References | <nde25k$bkn$1@dont-email.me> <20160329173929.65060450@_> <ndhme3$9p5$1@dont-email.me> |
On Thu, 31 Mar 2016 00:13:49 +0100 James Harris <james.harris.1@gmail.com> wrote: > On 29/03/2016 22:39, Rod Pemberton wrote: > > On Tue, 29 Mar 2016 15:09:35 +0100 > > James Harris <james.harris.1@gmail.com> wrote: > >> Consequentially, Apple have been somewhat embarrassed that their > >> security has been broken. > > > > I don't know if they're embarrassed, yet. > > Well, their argument was that they wanted their phone encryption to > be (known as) unbreakable. But someone broke it. I'm still not sure that the encryption was broken, only that the data was accessed through indirect means. > Yes, except that, to me the question is not so much one of open or > closed but restricting who can have access to certain information. > > To illustrate, there was a story of some admin person burning the > records of thousands of people onto two CDs and then popping them in > the post. :-( That was a stupid thing to do and the CDs went missing. > The problem, IMO, was permitting that admin person to see the data in > the first place, and allowing any kind of copy to be made. 1) how exactly does one administrate a computer system without also having access to user/customer/patient data? In order for the administrator of the computer systems to not have access to customer data, the data would have to be encrypted, that administrator would have to not have access to those encryption keys. This implies that there would need to be a second "administrator" for controlling the encryption keys for the restricted data and perhaps passwords for the account that could decrypt the data. Needing an extra employee is an extra expense, unless some other employee is given the duty. Most systems are not set up this way, i.e., the sole administrator usually has full access to everything. Apparently, the system Edward Snowden accessed was set up similarly, i.e., even the administrator was restricted as to what he could access, but he conned people into giving up their passwords, allowing decrypted access, whenever they had a computer problem. The brokerage I worked for had to set up two computer systems to mostly keep user data separate, but that only worked to ensure customer privacy from most employees, not everyone, Perhaps, 70% to 90% of the employees were blocked, I don't have exact figures. The people administering the customer account computer system, and the employees managing the customer accounts on behalf of customers, or those handling customer account problems had access to the customer's personal and account information. Some employees have to be trusted, typically many. 2) how do you prevent CDs or backups from being made? Most computers have CDs in them. Those same computers use the CDs, or laser-discs, or tape, etc, to make backups. It's usually the admin's job to make those backups. I'm not familiar with the particulars of the example you cite, but it was probably his job to do that, and then mail them to secure storage. He could have diverted the CDs, or they could have been lost, misplaced, or stolen. It's up to authorities to find out. > Another story was of admin workers - in India, IIRC - who acquired > customer details and built up their own database. They then sold this > info on the black market. All industries have these problems. Bank employees have access to your personal info and financial info. Hospitals have access to your personal info and health records. The human resources or personnel department at work has all your personal info, employment info, some insurance info and some health info. The government has access to all your personal info and tax records. This is an employee trust issue, and/or a process trust issue. Society needs way, way too many people in the loop of trust. :-( AISI, the real problem is either: 1) company's aren't willing to pay for good security 2) company's are ignorant of the ease with which computer security is breached by otherwise unskilled individuals > My view is I don't mind specific security services accessing > anything on my computers if it saves my life and that of my > family from terrorism Why would you be a target of terrorism? I mean, other than a random event, you wouldn't likely be targeted in advance by terrorists. You might be targeted in advance by criminals. So, why would your computer have anything related to terrorism on it which could be used by law enforcement to save your life? This is a "non sequitur" for me. Explain please. While in college, I roomed with a friend. We were in a large apartment complex, multiple buildings with many floors. In one of the adjacent buildings, one criminal found out where another lived and murdered him. My roommate immediately freaked out and decided he was going to move as soon as possible. The event had nothing to do with him or me. It wasn't even in our building. It was nearby in the same complex. It was a completely random event. I pointed this out to him. He still moved. Reason couldn't break his fear. From my perspective, this was an overreaction, but people respond to nearby terrorism in much the same way. What is the likelihood that a train station will have a repeat terrorist attack after law enforcement enhances their presence? It's slim to none. How long is it before people become comfortable with visiting that train station? Many years ... I had an an airplane flight just a couple of weeks after 9/11. I think there were maybe five or six people on the plane, not including the crew. I wouldn't doubt it if half the passengers were law enforcement. That flight would've been packed weeks earlier with hundreds of people. What was the probability that terrorists managed to attack a plane immediately after 9/11? It was slim to none. There are about 350 million people in the U.S. Look at the response of the U.S. government for only a few thousand killed. Homicide in the U.S. had four times as many deaths in 2001 as the 9/11 attacks. Homicide ranked as the 19th cause of death in 2001, well below the 1st ranked heart disease of 610,638. I'm not trivializing the 9/11 tragedy, loss of life, loss of loved ones, or that America was attacked, but we spent billions and lost as many or more soldiers as the terrorists killed. If that's not an overreaction, I don't know what is. And, we're financially responsible for rebuilding the countries we invaded in response to 9/11. And, those that survived our onslaught in the middle east will be our lethal enemies for generations. I don't see how this benefits the U.S. > but I don't want my info to be seen by anyone else. Don't encrypt the home computer. Don't put a password on it. Then, law enforcement can access it in an emergency situation. However, criminals would have full access too, if you were the victim of a break in. But, why they would steal the home computer is beyond me. They want stuff which is non-traceable, liquid, and easily salable, e.g., cash, credit cards, common jewelry, smartphones, GPS devices. In general, they don't want gold coin, rare coins, stamps, gold bars, exquisite jewelry, because all that stuff is unique, sometimes marked with a serial number, and is easily tracked by law enforcement via pawn shops or jewelry stores. Recent legal changes here even require people selling scrap for cash to provide their personal info on a form to the state to help prevent or reduce thefts. It's big brother. Everybody and everything will be tracked. After Brussels, they're trying to prohibit buying or using a smartphone without providing your personal information, i.e., no "burner" smartphones or pre-paid cash cellphones. Big Brother. Total government surveillance and tracking. > I would not even want the head of the government to > see it without a court order. Good choice. Can you enforce it? We found out we couldn't. I.e., rights of ordinary U.S. civilians were violated by a secret court, with the good intent of chasing terrorists, but the government still violated our rights in the process. The U.S. people have not, and probably will never, see any redress. > But there are people whose job it is to prevent terrorist > attacks and one main reason they foil plots is because of > accessing sensitive information. Didn't the Nazi's use similar rationale when they got everyone to snitch on the Jews in hiding? I.e., the Jews were a threat and it was the Nazi's job to get the information to prevent the threat? Or somesuch, ... Governments can rationalize anything. We see China as being authoritarian and oppressive, much like Nazi Germany. China sees themselves as enforcing the laws. Rod Pemberton
Back to alt.os.development | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-29 15:09 +0100
Re: The morality of operating system security JJ <jj4public@vfemail.net> - 2016-03-30 00:03 +0700
Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-03-29 19:39 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-30 23:54 +0100
Re: The morality of operating system security JJ <jj4public@vfemail.net> - 2016-03-31 06:16 +0700
Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-03-29 20:01 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-30 23:59 +0100
Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-03-31 17:47 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 08:11 +0100
Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-04-01 18:25 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 23:10 +0100
Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-04-02 14:18 +0200
Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-04-01 09:58 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 10:06 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-29 17:39 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-31 00:13 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-30 23:18 -0400
Re: The morality of operating system security "Alexei A. Frounze" <alexfrunews@gmail.com> - 2016-03-31 00:31 -0700
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-31 16:57 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 09:22 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-01 20:24 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-09 18:25 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-09 18:57 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-26 09:07 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-26 23:58 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-27 07:01 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-27 05:42 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-03 00:05 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-03 16:55 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-04 09:00 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-04 17:22 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-05 17:02 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-05 17:55 -0400
Re: The morality of operating system security "Kerr Mudd-John" <admin@127.0.0.1> - 2016-05-09 14:58 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-12 17:46 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-15 00:11 +0100
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-27 07:44 +0100
csiph-web