Showing posts with label Technology. Show all posts
Showing posts with label Technology. Show all posts

03 February, 2016

In Which The Telegraph Smears Tor


Been a long time since I talked about the Telegraph here.  But yesterday, I came across this particular piece of bullshit reporting from that 'journalistic' organisation, and felt compelled to say something.

That headline above, is frankly...a lie.  First off, Tor is a network, or a technology, not a browser, even if the browser download is the way in which most users will experience Tor these days.  The browser download, being a simplified bundle of the core Tor & proxying software with a modified version of Firefox.  Secondly, the study in question doesn't in any way speak to to the 'overwhelming use' of the Tor browser, but specifically to the use of the so-called Dark Web.  Back to the Telegraph...
There is an "overwhelming" amount of illicit and illegal content on the dark web, a new study shows.
That statement might seem self-evident. But the Tor browser - also known as the dark web or deep web - was created to protect the anonymity of vulnerable people online. It is a web browser just like Google Chrome or Internet Explorer, but it masks the identity of who is browsing and what they're looking at.
The Tor browser is perhaps known as 'the dark web or deep web' -- by fucking idiots !  The so-called 'dark web' is a fear-mongering slur utilised by the government for any services over the internet that in any way bypass conventional IP/HTTP routing, and thus implicitly threaten governmental control and surveillance thereof.  Tor is one of many services that can be used for such means, in this case, via the use of .onion addresses, that are only routeable via the Tor network.  It is not the only technology providing such hidden services, the hidden services are not the primary purpose of the Tor network, and in fact, the hidden services component was a much later addition to Tor.

Don't believe me, that the hidden services, the 'dark web' are not the primary purpose of the Tor network ?  Well, let's look at the study in question, shall we ?
The Tor architecture provides two services – anonymous browsing (property 3), and hosting of anonymous information exchanges (property 5) – through one piece of software, the so-called ‘Tor Browser’. Although distinct, both services employ roughly the same protocols and rely on the same distributed infrastructure. But that is where their mutual dependency ends. There is no technical requirement for anonymous browsing and anonymous hosting to be bundled. Indeed, browsing is overwhelmingly more popular than hosting. Most Tor users have never visited any hidden website at a *.onion address; hidden services account for around 3–6% of overall Tor traffic.27 Most users instead use the software merely to browse the internet's conventional address space more securely or anonymously. An analogy illustrates the significance of anonymous browsing. Alice, who lives in a small town, wants to buy a pregnancy test, but doesn't want to be seen doing so by the shop owner, Bob, a friend of Alice's father. Rather than simply going to the store, Alice wears a mask, walks a detour, and pays in cash. Bob will not be able to identify her or trace her. Alice's privacy and anonymity are assured. Anonymous browsing is not part of the ‘dark web’; it is a legitimate and laudable service that Tor provides.
This is from the very study upon which the Telegraph's scary misleading headline is based.  It says right there that most users have never visited any .onion 'dark web' sites at all, and that hidden services account for around 3–6% of overall Tor traffic.  Three to fucking six percent !  Hell, I've been familiar with Tor since long before there was such a thing as a 'Tor Browser', and I don't think I've ever visited or had reason to visit any hidden 'dark web' sites via Tor myself.  Because...why the fuck would I ?  Tor's primary purpose is, and always has been, simply to provide a modicum of anonymity in browsing the Internet, and the vast majority of users are most likely using Tor in entirely legitimate ways, in entirely legitimate pursuits.

In fact, the US government has repeatedly promoted the use of Tor for such purposes as enabling dissidents and human rights-activists living in authoritarian regimes, to communicate freely, bypassing restrictive governmental policies and controls, to promote liberal Western-style values.  The US government continues to this very day to provide a vast amount of the funding for the Tor project, and to utilise the network itself, and the Tor software was originally in fact invented by the United States Naval Research Laboratory & DARPA.

That's right, this evil evil 'dark web' software, the users of which the Telegraph apparently wishes to smear, was created by, and continues to be funded by the government of the United States of America.

So, in case you're not familiar with how Tor works, and is used by, as noted above, the vast vast majority of its users, here are some illustrations from the EFF.




Tor doesn't provide uncrackable security, certainly not for the likes of the NSA or other US govt. security agencies, and that much more certainly not when they have been involved in its creation and funding of its development from day one.  It simply obfuscates the path of traffic through a random series of nodes, making it difficult for a would-be adversary to monitor the traffic, without control of, and therefore the ability to monitor traffic through, all the nodes in question.  It isn't that inherently secure, even if you trust that the US government hasn't inserted its own backdoors into the system, and any one relying solely on Tor to run, say an international drug-smuggling operation, without detection, would be very stupid indeed.  Of course, the vast majority of users aren't doing anything of the sort.

Back to the Telegraph...
In the first study of its kind, researchers at King's College London found that 57 per cent of sites on Tor facilitate criminal activity, including drugs, illicit finance, and extreme pornography.

The findings are not unexpected - if anything that figure is lower than expected. Tor has been associated with child pornography, gun trading and murder long before now. 
"We expected something along these lines," said Thomas Rid, professor of Security Studies at King's College London and co-author of the study. "Previous studies have established that it's a pretty nasty place."  
Scary, scary fucking stuff indeed !  Child pornography, murder, drugs, extreme pornography !  Sounds pretty nasty huh ?

Did we mention that the 'dark web' sites in question were a product of a secondary (and not inherently illegitimate*) function of Tor, not even utilised by the vast majority of Tor users ?
Tor offers anonymous browsing to people across the world. Users in countries with strict censorship laws, like China or Iran, can use it to access mainstream sites - like Facebook - securely. Rid and Moore found that the vast majority of material on Tor was not just illegal in places like China or Iran, but in more liberal jurisdictions too.
Here, in the same fucking paragraph, the Telegraph conflates the anonymous browsing (such as use of fucking Facebook), which is the sole usage of the vast majority of users with the hosting of illegal materials on so-called 'dark web' sites.
The sites included marketplaces for drugs, fire arms and weapons, and explicit, illegal pornography. The study found a "near-absence" of Islamic extremist sites on Tor.
"Militants and extremists don't seem to find the Tor hidden services infrastructure very useful. So there are few jihadis and militants in the darknet," said Rid. "It's used for criminal services, fraud, extreme, illegal pornography, cyber attacks and computer crime."
Know why that is ?  Because, they're not fucking stupid !  Because they know full well, that if the US government wants to find them on an US-govt-designed and funded network of mild anonymity, it can, and will.  The US government could crush the Tor network any time it wanted to, but insofar as a) Tor isn't any meaningful threat to security-services, b) Dissidents in foreign competitor states utilise Tor, and c) Agents of the US govt. itself utilise Tor, it has no compelling reason to do so.

What the US government, and its proxy poodle in Westminster, would like to do, is utilise fearmongering rhetoric about 'terror' attacks, to convince the public, and technology-companies, that it is in the public interest that the privacy of Western citizens be intentionally compromised, via the dilution of encryption technology, and the building of government-accessible backdoors into common security software.  The sort of breathless hyperbole in which right-wing publications such as the Telegraph specialise is perfect for such a purpose.
Rid and Moore commend Tor for offering vulnerable people access to anonymous browsing. But they said Tor needs to work harder to encourage its community to build a safe and legitimate browsing experience.
Did they say that ?  I must have missed it...
"The developers made Tor for a different purpose - they wanted security, not crime. It's up to them to change the direction," said Rid. "It's up to them to have a sensible discussion about ways to reduce crime, to get more legitimate users in." 
Now here, I can only assume the quotation is the result of an interview (what, the Telegraph doing actual reporting...like actual journalists ?), as I don't see such language in the report.  Regardless, this is shit.  We've already established that the vast majority of usage is merely anonymous browsing (which is, in the authors' words, 'a legitimate and laudable service that Tor provides'), and how the hell can Tor's developers be held responsible for the content provided by the 'hidden services' on their network, without fundamentally compromising the relative anonymity that is the whole raison d'etre of the Tor network to begin with ?

Is the argument that as the functionality of hidden services could theoretically be used for ill purposes, that it should be removed ?  The same is true of the anonymous browsing functionality, innocent as the vast majority of usage may be/probably is.  The same is true of all technology.  Hell, in the US, special constitutional protections are given to the ownership of tools (i.e. guns, firearms), whose primary if not sole purpose is to murder living beings.  But the fact that a subset of the functionality of a mildly anonymising technology might be used for illicit purposes, that...that is a reason for ripping apart what little guarantee of privacy is currently available to us on the internet ?
Tor's example will no doubt be used in the encryption debate that is circulating around the snoopers' charter, according to Rid and Moore. 
"Tor's ugly example should loom large in technology debates," Rid and Moore conclude. "The line between utopia and dystopia can be disturbingly thin."
This is just...WTF ?  Wait, why am I still quoting the fucking Telegraph ?
The other quandary is how to deal with darknets. Hidden services have already damaged Tor, and trust in the internet as a whole. To save Tor – and certainly to save Tor's reputation – it may be necessary to kill hidden services, at least in their present form. Were the Tor Project to discontinue hidden services voluntarily, perhaps to improve the reputation of Tor browsing, other darknets would become more popular. But these Tor alternatives would lack something precious: a large user base. In today's anonymisation networks, the security of a single user is a direct function of the number of overall users. Small darknets are easier to attack, and easier to de-anonymise. The Tor founders, though exceedingly idealistic in other ways, clearly appreciate this reality: a better reputation leads to better security.85 They therefore understand that the popularity of Tor browsing is making the bundled-in, and predominantly illicit, hidden services more secure than they could be on their own. Darknets are not illegal in free countries and they probably should not be. Yet these widely abused platforms – in sharp contrast to the wider public-key infrastructure – are and should be fair game for the most aggressive intelligence and law-enforcement techniques, as well as for invasive academic research. Indeed, having such clearly cordoned-off, free-fire zones is perhaps even useful for the state, because, conversely, a bad reputation leads to bad security. Either way, Tor's ugly example should loom large in technology debates. Refusing to confront tough, inevitable political choices is simply irresponsible. The line between utopia and dystopia can be disturbingly thin.
Less oblique, less misleading, less blatantly crass government-propaganda.  Still crap.

But, now I'm getting into the realm of disputing the report's findings & conclusions, which wasn't where I started, with the Telegraph's blatantly misleading headline.  So, let's step back a bit...



See those results above, from Google News ?  The bottom three accurately characterise the report's findings, and the subject thereof.  Only the one at the top from the Telegraph manages, unintentionally or not, to completely conflate the lesser functionality of 'hidden services' with the wholly legitimate purpose of 'anonymous browsing', and to smear the vast majority of Tor users as a result.  Fuck, I hate the Telegraph...


* Imagine say Iranian or Chinese dissidents, wanting to not merely communicate freely over Tor, without detection of government authorities, but also wanting to provide a stable hosting source of shared documentation within their groups.

13 September, 2015

Jimmy Kimmel on the New iPhone


This is telling.  Though...a little lazy to recycle your own jokes.

FWIW, they're right on the form-factor.  Who the hell can fit those things in a pocket ?

22 July, 2015

Why Worry ?

Let's combine drive-by-wire systems in cars, with remote internet access, and no separation of key control-systems from more peripheral systems that 'need' internet-connectivity.  What could possibly go wrong ?
I WAS DRIVING 70 mph on the edge of downtown St. Louis when the exploit began to take hold.
Though I hadn’t touched the dashboard, the vents in the Jeep Cherokee started blasting cold air at the maximum setting, chilling the sweat on my back through the in-seat climate control system. Next the radio switched to the local hip hop station and began blaring Skee-lo at full volume. I spun the control knob left and hit the power button, to no avail. Then the windshield wipers turned on, and wiper fluid blurred the glass.
As I tried to cope with all this, a picture of the two hackers performing these stunts appeared on the car’s digital display: Charlie Miller and Chris Valasek, wearing their trademark track suits. A nice touch, I thought.
The Jeep’s strange behavior wasn’t entirely unexpected. I’d come to St. Louis to be Miller and Valasek’s digital crash-test dummy, a willing subject on whom they could test the car-hacking research they’d been doing over the past year. The result of their work was a hacking technique—what the security industry calls a zero-day exploit—that can target Jeep Cherokees and give the attacker wireless control, via the Internet, to any of thousands of vehicles. Their code is an automaker’s nightmare: software that lets hackers send commands through the Jeep’s entertainment system to its dashboard functions, steering, brakes, and transmission, all from a laptop that may be across the country.
To better simulate the experience of driving a vehicle while it’s being hijacked by an invisible, virtual force, Miller and Valasek refused to tell me ahead of time what kinds of attacks they planned to launch from Miller’s laptop in his house 10 miles west. Instead, they merely assured me that they wouldn’t do anything life-threatening. Then they told me to drive the Jeep onto the highway. “Remember, Andy,” Miller had said through my iPhone’s speaker just before I pulled onto the Interstate 64 on-ramp, “no matter what happens, don’t panic.”1
As the two hackers remotely toyed with the air-conditioning, radio, and windshield wipers, I mentally congratulated myself on my courage under pressure. That’s when they cut the transmission.
Immediately my accelerator stopped working. As I frantically pressed the pedal and watched the RPMs climb, the Jeep lost half its speed, then slowed to a crawl. This occurred just as I reached a long overpass, with no shoulder to offer an escape. The experiment had ceased to be fun.
...
Miller and Valasek’s full arsenal includes functions that at lower speeds fully kill the engine, abruptly engage the brakes, or disable them altogether. The most disturbing maneuver came when they cut the Jeep’s brakes, leaving me frantically pumping the pedal as the 2-ton SUV slid uncontrollably into a ditch. The researchers say they’re working on perfecting their steering control—for now they can only hijack the wheel when the Jeep is in reverse. Their hack enables surveillance too: They can track a targeted Jeep’s GPS coordinates, measure its speed, and even drop pins on a map to trace its route.
Image: Andy Greenberg/Wired
All of this is possible only because Chrysler, like practically all carmakers, is doing its best to turn the modern automobile into a smartphone.

The future will such fun be.

26 June, 2015

Steve Wozniak: Robots Will Make Us Their Pets

Apple’s co-founder: We’re all going to be robots’ pets one day
by Benjamin Snyder     @WriterSnyder     JUNE 25, 2015, 12:23 PM EDT 
Apple AAPL -0.46% co-founder Steve Wozniak thinks we’re all probably going to become robots’ pets.
Speaking at a recent technology conference, Wozniak said that at first the thought of artificially intelligent beings in charge of everything scared him. But now it’s a comforting thought.
Fast forward hundreds of years to when robots are in charge. At that time, humans will probably be treated in a similar fashion to dogs, Wozniak said during an event at the Freescale Technology Forum 2015 in Austin, Texas.
“It’s actually going to turn out really good for humans,” he added. “And it will be hundreds of years down the stream before [artificially intelligent beings would] even have the ability.”
“They’ll be so smart by then that they’ll know they have to keep nature, and humans are part of nature,” he continued. “So I got over my fear that we’d be replaced by computers.”
Wozniak believes robots will helps us because we’re the “gods originally.”
More like animals in a zoo surely ?  If the motivation is preservation of humans as a part of nature.

And even if the robots did treat us like dogs, a lot of us treat dogs...really really horribly.  And if they treated us the way the more 'humane' in society treat dogs, they would still be...restricting our population, neutering us to control our breeding, restricting our movements, controlling out interaction with other humans, strictly controlling our diets, and euthanising us when we got sick or old.  Awesome future you've got mapped out for us there, Woz !

And the 'we're the "gods originally"' stuff is just wishful thinking, as is the rest of it.

What Wozniak really needs to conquer his existential angst, and what this is a form of, is religion.  In this case, it's one involving the fetishisation & worship of technology, and the faith in technology always being there for us, always leading to a brighter future.  A common, but often disappointing faith.

I'd suggest maybe...Buddhism instead ?

30 May, 2015

First World Fabrics

Google working with Levi Strauss to make smart clothes
SAN FRANCISCO - Google announced Friday that it is working with iconic U.S. jean maker Levi Strauss to make clothing from specially woven fabric with touch-screen control capabilities.
The Internet titan used its annual developers conference in San Francisco to reveal its so-called Project Jacquard and to spotlight Levi Strauss as its first partner.
...
The special threads can be woven into a wide array of fabrics, and be made to visually stand out or go unnoticed depending on designers' wishes.
Conductivity can be limited to desired parts of fabric or spread across entire cloth.
"It is stretchable; it is washable," Karagozler said as people controlled lights or computer screens with finger strokes on a blue cloth covering a table in the display area behind him.
"It is just like normal fabric."
Project Jacquard makes it possible to weave touch and gesture interactivity into any textile using standard, industrial looms, according to Google.
Anything involving fabric, from suits or dresses to furniture or carpet, could potentially have computer touch-pad style control capabilities woven
...
"In our hyper-digital world, people constantly struggle to be physically present in their environment while maintaining a digital connection," said Levi Straus's head of global product innovation Paul Dillinger, who took part in a Google presentation at the gathering.
"The work that Google and Levi's are embarking upon with Project Jacquard delivers an entirely new value to consumers with apparel that is emotional, aspirational and functional."

This is how we choose to use our technical prowess in the twenty-first century.  And what we think wealthy consumers will want to spend their excess cash on.  At least the actual technology is transferable, even if the application is frivolous.  Surely the most ridiculous story of the day...

09 March, 2015

Open (Stupid) Question

With the recent FCC Net Neutrality rulings, and with every (real- or pretend-) broadband carrier spending ridiculous amounts of money proclaiming their own exponential speed increases, how is it that ad-supported services like YouTube still by default push video worthy of sub-56k modems ?  Not asking for or expecting actual answers.

Nirvana: Lithium


Oh how I wish Microsoft would have wised up decadesyears ago and just built a GUI on top of a proven *NIX OS with access to the standard shells.  Couldn't see a way to clearly eliminate the duplicate files via iTunes, so nuked them with a forfiles command, which leaves me wondering a) whether Nile will just re-download them all over again at some point, and b) will Lemon at some point wise up to the fact that the underlying files are gone, and remove the duplicate listings without my having to manually clean them up ?  Got the disk space back at any rate, fuckers.

08 March, 2015

Cradle of Filth: From the Cradle to Enslave

Have been avoiding attending in any detail the damage a certain (river-named) tech. company's service did to my library, and....shit.  Sorta thing I could do with scripting maybe, but fuck, I don't want to waste my time learning how the library is organised and how (if it is even possible) to manipulate it.  Although it I did take the time to figure that out, maybe I'd have a fix if/when they fuck it up all over again.  Assholes !


06 March, 2015

Dear Amazon

Dear Amazon, thanks ever so much for re-downloading, without asking, huge swathes of my music library, creating massive duplication, and sucking up precious disk space.  That was just oh so awesome and thoughtful of you guys.  The geniuses that created your new downloader app. deserve a payrise, really they do.  Kiss kiss and hugs to all...