Thursday, November 20, 2014

Declassified FISA court documents declassified under FOIA illustrate a wealth of Government activities

1500 pages of Documents Yahoo's case against their National Security Letters in 2008 have recently become declassified.

I guess the law is one thing and the interpretation of it is something completely different, especially where there is no oversight or public inspection.  If activities can be performed and judged  by the government, with no opposing council or public inspection, how can they not get out of control? 


The first document (64 pages) shows this in spades, where the FISA court justices can't understand that tapping the phones of provably innocent people isn't constitutional because they aren't aware of it.  A good article about it is (as usual) on Techdirt.

 It also shows contradictory statements of facts
'"There is no database," says Gregory Garre, before having to admit a few sentences later, that incidental data is retained (and distributed)'
[page 8] In the following quote, the Yahoo attorney (Zwillinger) is relating that in spite of monetary compensation for their time and effort they are still injured.

Justice Arnold: Well, if this order is enforced, and it's secret, how can you [yahoo] be hurt?  The people don't know that -- that they're being monitored in some way.

Tuesday, November 18, 2014

Awesome! Uber crying that media is mean to them, suggests "Digging up dirt on journalists"


Update #7 - 20-June because AUATT (below) - The FTC is investigating them?

Update #6 - 14-June-2017 - As a matter of fact, this blog is "All Uber all the time".  After Emil Michael's and Travis Kalanick's LOA departures, board member David Bonderman in a discussion with Adriana Huffington - 'who was speaking about the need for more female representation on Uber’s board. When “there’s one woman on the board, it’s much more likely that there will be a second woman on the board,” Huffington said, to which Bonderman shot back “what it shows is that it’s much more likely to be more talking.” - Bonderman was out in about the time it takes to say "Do we need to call security?"

Update #5 - 12-June-2017 - Eric Holder report released soon, likely not good.   Travis Kalanick on LOA after a family tragedy (we're truly sorry and our thoughts and prayers for the family), oh, and Emil Michael out
 
Update #4: The Verge:  Can Uber be saved from itself?

Watch for:  Ryan Graves (employee #1) to take the fall for the latest things, both the Misogyny from Susan Fowlers blog (sub watch - are they investigating her personally? ) and Greyball (Verge again) 

Update #3a:
Uber allegedly has a pretty horrible culture of sexual harassment, per engineer-author Susan Fowler who isn't afraid to blow the whistle under her own name, and there's a really good blog post at Global Nerdy that deconstructs and validates the claims


Kara Swisher from Recode/Decode had a podcast about Uber that posted the day after Susan’s blog post went viral named “Self-driving cars are an ‘existential crisis’ for Uber, ‘Upstarts’ author Brad Stone says”

Here’s Kara’s blog post about the leather jacket


Update #2:  CNN-  Uber limits employee access to God mode

Update #1:  Washington Post blog has insight on their privacy and least privilege policy

 AKA - Let's DOX our customers, that'll show them

So correct me if I'm wrong, Buzzfeed article, linked from Drudge:

According to Buzzfeed article uber-executive-suggests-digging-up-dirt-on-journalists :
  1. Uber thinks journalists are being mean, especially pando writer Sarah Lacey writing about them after a Buzzfeed article accusing them of sexism (awesome example of just that BTW)
  2. VP of Black Bag Jobs, er "business", Emil Michael, suggests opposition research including aforementioned digging up dirt
  3. Immediate spin control, an Uber spokes droid states (from the article) "the company does not do “oppo research” of any sort on journalists, and has never considered doing it. She also said Uber does not consider Lacy’s personal life fair game, or believe that she is responsible for women being sexually assaulted."
  4.  Even though (from the article again) "the general manager of Uber NYC accessed the profile of a BuzzFeed News reporter, Johana Bhuiyan, to make points in the course of a discussion of Uber policies."
  5.  SO a new economy taxi company is on record of using it's data against journalists and anybody still uses them?!
  6. Update:  Amy Keyishian at Re/code had the first link to Seth Meyers clip with the "That Boober Guy" nickname for Travis Kalanick, some great advice on the difference in truth in public and private speech, and equating the Emil Michael quotes with Valdemort speaking to Hogwarths.  





Sunday, November 9, 2014

Yes, now you can see the dumbest agreement on earth

This is what EMS sports wants you to agree to before you post a review of their stuff:

http://www.powerreviews.com/legal/terms_of_use_en_US.html

I guess "Power Reviews" is running their review site.

An excerpt that will probably get me in trouble:

What you are promising by submitting UGC: By submitting UGC you represent and warrant that: (i) you are the sole owner of the UGC; (ii) the UGC is accurate; (iii) you are at least thirteen (13) years old; and, (iv) the UGC you submit does not violate these Terms of Use. Because you are solely responsible for what you post, you also agree to indemnify PowerReviews and PowerReviews's clients for a breach of your representations and warranties.
Where you can find additional information on PowerReviews's use of the UGC: PowerReviews's use of any UGC you submit is subject to PowerReviews's Privacy Policy, which can be found at http://www.powerreviews.com/legal/privacy_policy_en_US.html.

Oh by the way, they sey this in their thank you message:

Hello @comcast.net. Here is a list of the reviews we have connected to your email address. Currently, we have a limited set of managing options for your reviews:

Deleting a review: Unfortunately, we do not allow deletion of reviews as they become our property upon submission. However, if you would like to disconnect the review from your identity and unlink it from your email address, please feel free to do so at any time. Unlink a review.

Removing media: If you would like to remove an image or video you've shared along with a review, you can do so by finding the review in question below and clicking on the "Remove" button directly underneath the item.

SO - I'm solely responsible for what I post, but posts are their property!?

sheesh.  Please, someone put them out of their misery

Tuesday, October 28, 2014

Good Techdirt analysis of Applepay and CurrentC situation

States that retailers want to cut out Mastercard and Visa, and want ultimate tracking of their customers that they had when they used their old tracking cards

https://www.techdirt.com/articles/20141027/07065628950/payment-wars-how-merchants-carriers-are-trying-to-block-payment-systems-they-cant-track.shtml

Grab the popcorn, IMHO, this will be an utter and dismal failure, because the members of PCI won't correctly use their previous lessons learned to make a system that protects customers, instead they will greedily grab all the data they can on their customers, attempt to protect their shopkeeper members, but fail because they're cheaping out on the infrastructure, creating something even worse than PCI.

Seriously, Rite Aid and CVS are creating a payment system that will be more secure than Google, Apple and Mastercard/VISA?  OMG what are they thinking other than sheer greed.  I won't boycott, though, expecially CVS, I truly want to support a company that went out on a limb and stopped selling tobacco.

Don't use CurrentC, it will be even riskier than debit cards - the QR codes will be found to be awful security, and there will be people burned by the automatic debit behavior of the system. Even if they use something clever like Steve Gibson's SQRL , they won't be able to implemment something secure enough to handle the amounts of cash it needs to.

Please just use credit cards or cash at these merchants

Monday, October 27, 2014

Truth finally? Rutgers paper about e-voting - Don't do it

Slashdot talked about a paper generated when Rutgers university did an analysis of the emergency e-voting that was done after hurricane Sandy, and it was apparently another disaster.

Just pulling interesting things from the table of contents: 

VII. INTERNET VOTING IS NOT SAFE, SHOULD NOT BE MADE LEGAL, AND SHOULD NEVER BE INCORPORATED INTO EMERGENCY MEASURES

VIII. INTERNET ATTACKS ON U.S. INFRASTRUCTURE AND BUSINESSES ARE SO PREVALENT THAT IT IS NAÏVE TO BELIEVE THAT U.S.ELECTIONS WOULD NOT BE OF INTEREST TO HACKERS


So let's jump right to the conclusion:

CONCLUSION
After Superstorm Sandy, there was no structure in place to make sure that emergency voting directives were followed. There was mass confusion among county officials and voters, alike. Emergency measures such as Internet and fax voting not only violated New Jersey law, but also left votes vulnerable to on-line hacking. Internet voting should never be permitted, especially in emergencies when governmental infrastructure is already compromised.

As the May 2014 National Climate Assessment issued by the U.S. government makes all too clear, New Jersey is highly likely to be impacted negatively by more Superstorm Sandy-like disasters in the near future.265 This means that it is critical for New Jersey to enact and implement emergency voting procedures that comply with existing election law, and that protect every vote. As such, those emergency measures should not include Internet and fax voting as an option, under any circumstance.

Friday, October 24, 2014

Verizon tracking its users (again)



As the biggest fine ever ( http://www.fastcompany.com/3035193/fast-feed/fcc-fines-verizon-74-million-for-using-private-data-to-market-to-customers )
didn't make enough of an impression, 

Verizon is now tracking the browsing of its wireless users with a new token, according to Ars Technica - http://arstechnica.com/security/2014/10/verizon-wireless-injects-identifiers-link-its-users-to-web-requests/

More information can be found here:

Or you can test it yourself here:

Browsing from the work/desktop network shows no X-UIDH header, but from a (Work) Verizon cell phone shows the header, and links to an NBC news site with opt-out information.  According to people on Twitter (https://twitter.com/search?f=realtime&q=verizon%20uidh ) ,   opting out doesn’t always work.  I haven’t tested it yet.

Using HTTPS supposedly prevents this information from being sent, but there may not be a way to I don’t know whether this information uniquely identifies 

(* TODO *) I wonder whether setting up an apache server as a proxy, with HTTPS in and http out would prevent the headers?



Monday, October 20, 2014

(Updated) There's this web site/app called "Whisper" that wants you to "to anonymously share their innermost thoughts, secrets, and feelings."

Whisper (bad), not Whisper Systems (good, Moxie Marlinspike)

Yeah. 

Do I have to say DON'T DO IT?!

They Geolocate, which can't be turned off, concentrates on US military bases, and Intelligence agency locations, and also use the IP address

Whisper:  Lies! (the guardian)

US Senate: Oh really?  Why don't we chat about that? (The Verge)