Privacy lost...

WBahn

Joined Mar 31, 2012
33,040
While the fine details weren't disclosed, it seems like the approach that was used in the case in question was pretty reasonable. They asked for anonymized information about phones that were within a pretty small area within a pretty small time window. I don't know if either of those could have reasonably been made smaller as I don't know the granularity of the location data that is retained. They then worked with that anonymized data to narrow things down further (that's what would be far more interesting to see) and eventually asked for the identifying information for only three individuals. That strikes me as a pretty focused approach that respected privacy rights on par with normal investigative techniques -- investigators routinely start with much larger pools of potential suspects, by name, and do considerably more intrusive digging in order to winnow the list down.

I'm far more concerned about broader data surveillance and pattern analysis.

Shifting gears, it reinforces the notion that many/most people that commit crimes are far from criminal masterminds. You are going to rob a bank, yet you are going to carry your cellphone with you while you do it? Then again, how many folks have gotten caught because they posted selfies of themselves on public social media accounts showing off the items they stole?
 

nsaspook

Joined Aug 27, 2009
16,399
https://arstechnica.com/gadgets/202...lg-monitors-installing-mcafee-ads-on-windows/

The app, LG Monitor App Installer, installs itself through a Windows Update alongside monitor driver updates. LG Monitor App Installer then pushes ads for a 30-day free trial for McAfee, as well as other software, via a pop-up on affected systems, multiple users have reported.

This has drawn negative attention recently, with complaints surfacing on Reddit and a subsequent video from YouTube channel Gamers Nexus. In the video, editor-in-chief Steve Burke said that the publication paid $1,200 for an LG UltraGear 3GX900A-B gaming monitor (the monitor’s price dropped to $600 two days later, Burke said) for testing and replicated the behavior “several times” across “multiple” Windows 11 systems.

After LG Monitor App Installer was installed, a pop-up appeared on the screen’s lower-right corner “on every single boot,” Burke said. Most of the time, the pop-up was a McAfee ad. The publication also reported seeing ads for LG Switch, LG Calibration Studio, LG Dual Controller, and LG Channels on rare occasions.
The automatic installation feature does not provide a notification to the user when the app is installed. Some users may find this experience confusing and frustrating and give your app a bad rating.
 

WBahn

Joined Mar 31, 2012
33,040
Oh no! I guess I have to go to Linux and destroy all my hard drives :)

This actually has good and bad points. BAD in that you (we) can't be completely anonymous, GOOD in that criminals cannot be completely anonymous.
Yes and no. As the bad guys become aware of this, they can take steps to mitigate it by simply using multiple machines to isolate and mask their activities. That's not something that very many legitimate users would seriously consider.
 

nsaspook

Joined Aug 27, 2009
16,399
https://techcrunch.com/2026/07/24/u...using-a-duress-password-during-border-search/
The motion said that the border agents claimed they did not need a warrant to search Tunick’s phone because he had not yet crossed the U.S. border. The U.S. government has long claimed it can search and seize people’s devices without a search warrant or court order until they are permitted entry to the United States.

When Tunick provided his passcode and the authorities entered it, “the screen went blank, flashed several times and the phone appeared to restart.” The authorities seized his phone anyway, before telling him that he was free to go and could enter the United States.

Prosecutors later charged Tunick under a federal statute that makes it unlawful to knowingly destroy or damage property to prevent authorities from seizing it. Tunick has pleaded not guilty.
 

WBahn

Joined Mar 31, 2012
33,040
Back when the first license plate readers were installed (here in Colorado) on the E-470 toll road, people raised concerns that the information could and would be used to track people's movements in addition to their intended purpose of assessing tolls (and, originally, in order for that to happen you had to register with the toll company in order for them to link your plate to the owner for billing purposes). We were told repeatedly and emphatically that this couldn't and wouldn't ever happen. Basically, we were told, "Trust us. There's no privacy concerns here. We heard you and we promise to only use the information for toll purposes." Not too long after that, they eliminated the toll booths entirely because they linked the information gathered to the state's DMV (and now national) data base so that they can match a plate to the owner even if they've never driven on the tollway previously. And we routinely hear about how this person or that person was tracked down and caught with the help of license plate readers. Now, of course, we are told how this makes us so much safer and we shouldn't have a problem if we don't have anything to hide. Well, I have a problem with it, regardless of whether I have anything specific to hide. But I also don't see any hope that it's going to stop -- that ship has well and truly sailed. Plus, any steps to curtail it will run up against the right of people to observe and share what they observe with others. If I can't put a camera on a pole that I own and record what's going on in a public space and share that information because it might violate someone's privacy, then I also give up the right to record things like government agents breaking the law and sharing that information on the exact same grounds. With the good comes the bad. The best we can hope for, most likely, is that legislation will be passed and court rulings will be handed down that limit what that data can be used for, particularly with regards to its admissibility as evidence in court or other proceedings or that of evidence obtained as a result of using it.

An interesting thought experiment to explore the notion of original intent of the Constitution, image that it was common place for some towns to have people record the names and comings and goings of everyone that entered the town. They didn't do anything beyond that, just made and kept a record. These records were then used to solve crimes by identifying potential suspects and witnesses. Would the framers of the Bill of Rights written them so as to make sure that this was not allowed? Or would they have seen at as acceptable practice. Based on my study of the writings of the authors and critiques, I think they would have made sure that the Fourth Amendment made clear that maintaining persistent records of people's activities without a warrant is not acceptable because they went to great lengths to restrict arbitrary government authority and require individualized authorization for impacting a person's life.
 

nsaspook

Joined Aug 27, 2009
16,399
Humans are still the weak link.
https://wpde.com/news/local/surfsid...ntractors-constangy-brooks-smith-prophete-llp

SURFSIDE BEACH, S.C. (WPDE) — The Town of Surfside Beach says an independent forensic investigation found no evidence that its internal computer systems or Microsoft 365 accounts were compromised during a payment fraud scheme that redirected more than $545,000 intended for a contractor.

According to the town, the investigation was launched after Wildcat Contractors reported on April 28 that it had not received a $545,598.30 ACH payment issued by the town on March 13.
...
Instead, investigators determined the fraudsters used spoofed and typo-squatted email domains, including surfsidesbeach.org, to impersonate town officials and redirect the payment. The fraudulent domain was created March 9 and was used to help conceal the scheme, according to investigators.

 

MrAl

Joined Jun 17, 2014
13,751
Yes and no. As the bad guys become aware of this, they can take steps to mitigate it by simply using multiple machines to isolate and mask their activities. That's not something that very many legitimate users would seriously consider.
You reminded me of another situation where there were good and bad effects of the new 'security' measures being implemented. I was talking to some others about this recently.

The institution had a 4 digit pin code for accessing a certain asset (I don't want to name names). You could use any 4 numbers 0 through 9 for any of the 4 digits. That means 1111 was legal, 1122 was legal, 1234 was legal, etc.
Then, they changed the rules. I don't remember them all right now but one I did remember is the double-digit ban. 1111 is no longer legal, 1122 no longer, 5656 not legal, no double digits or repeat digits.
What is funny about this is that now the hacker does not have to try those combinations (haha) so it makes it a little easier to guess.
Normally there are 10000 combinations they would have to try if they were extremely unlucky in guessing so they had to wait until the last one they tried. Once some of the combinations are banned, the explore space gets smaller. If we eliminate half of the space to avoid various combinations, the search would only have to be for 5000 combinations which makes it easier to guess, in the worst case of course.

We did some simple calculations to figure this out, but there is a more profound reason for the bans.
That is because a lot of users were using double digits and simple combinations like 1234, and a lot of accounts were being compromised. By eliminating those simpler combinations, it forces the hacker to try less common pin codes and most of the time the account would get locked because there was also a maximum "try" times before it gets locked. I think those measures should reduce the hacking success overall.

So the pure math says one thing, but human nature says another.
 

WBahn

Joined Mar 31, 2012
33,040
You reminded me of another situation where there were good and bad effects of the new 'security' measures being implemented. I was talking to some others about this recently.

The institution had a 4 digit pin code for accessing a certain asset (I don't want to name names). You could use any 4 numbers 0 through 9 for any of the 4 digits. That means 1111 was legal, 1122 was legal, 1234 was legal, etc.
Then, they changed the rules. I don't remember them all right now but one I did remember is the double-digit ban. 1111 is no longer legal, 1122 no longer, 5656 not legal, no double digits or repeat digits.
What is funny about this is that now the hacker does not have to try those combinations (haha) so it makes it a little easier to guess.
Normally there are 10000 combinations they would have to try if they were extremely unlucky in guessing so they had to wait until the last one they tried. Once some of the combinations are banned, the explore space gets smaller. If we eliminate half of the space to avoid various combinations, the search would only have to be for 5000 combinations which makes it easier to guess, in the worst case of course.

We did some simple calculations to figure this out, but there is a more profound reason for the bans.
That is because a lot of users were using double digits and simple combinations like 1234, and a lot of accounts were being compromised. By eliminating those simpler combinations, it forces the hacker to try less common pin codes and most of the time the account would get locked because there was also a maximum "try" times before it gets locked. I think those measures should reduce the hacking success overall.

So the pure math says one thing, but human nature says another.
It's even more complicated than that, because the answer depends on subtle details usually omitted from the question.

The question might be, "What can we do to increase account security?" But what is meant by "account security"? Is it individual or collective? Implementing the "no repeated digits" rule might decrease the collective rate of compromised accounts, but at the same time increase the likelihood that an individual that is taking proper precautions gets compromised. Essentially what is being done is to improve the security of the lazy people by reducing the security of the diligent people. Is that the tradeoff we want? Maybe. But it's something that should be considered but that seldom is.

Also, I say that the new rule "might" help protect the lazy people, but it might not. The person that was so lazy that they used 1234 is still a lazy person and, collectively, the lazy people will gravitate toward a new set of patterns that the bad guys will figure out and create a new dictionary for the new rules.

Back when password complexity rules were increasing all the time, I used to joke that eventually the rules would be so strict that the bad guys would only need to memorize the twelve remaining legal passwords.
 

nsaspook

Joined Aug 27, 2009
16,399
https://www.theregister.com/securit...ny-easier-to-exploit-despite-the-hype/5279637

AI-found bugs aren't proving any easier to exploit despite the hype
VulnCheck says fewer than 2% of AI-assisted vulnerability discoveries have been weaponized, casting doubt on claims frontier models are handing attackers a major advantage

In research shared with The Register, VulnCheck analyzed 1,061 publicly attributed AI-assisted vulnerability discoveries from Anthropic's Project Glasswing and the Berkeley Vulnerability Research Initiative, then cross-referenced them against its Known Exploited Vulnerability (KEV) database.

The result: just 14 vulnerabilities, or 1.3 percent, have been confirmed as exploited in the wild, almost identical to the rate across all vulnerabilities in VulnCheck's dataset.

That's a far cry from the narrative that frontier AI is dramatically tilting the balance in attackers' favor by churning out instantly weaponizable bugs. Instead, the data suggests that AI is currently better at increasing the volume of vulnerabilities researchers can uncover than at increasing the proportion that attackers actually exploit.
 
Last edited by a moderator:

WBahn

Joined Mar 31, 2012
33,040
The article is for subscribers only, which I'm not (and won't be).

Any system that can be abused, will be abused. It doesn't matter what the intent is, or what the laws are, or what the policies are. If it is physically possible to abuse it, people WILL abuse it. Minimizing abuse requires enforceable access, process, and audit mechanisms combined with appropriate sanctions for misuse to both make it technically difficult to misuse without a high risk of getting caught and sufficiently costly when caught to be a strong disincentive for even making the attempt. There will still be misuse, but it is manageable, provided there is the recognition of the problem and the will to address it. Unfortunately, it is usually the case that neither of those are in place. The bureaucrats are satisfied by drafting a policy in the employee handbook forbidding improper use and people that get caught are slapped on the wrist and told not to do it again. The very small handful of cases that, for whatever reason, result in harsher sanctions are two few and far between to have much of a deterrent effect.

As significant as this kind of abuse -- individuals tracking romantic interests, for instance -- is, it is retail. The bigger problem is the wholesale abuse that happens at the institutional level, either by using the system beyond what it is authorized for, or, even worse, the creeping expansion of what it is authorized for over time, which very regularly ends up doing exactly the very things that the public was promised it would never be used for when it was introduced.
 
Top