10 ms·
I remember back in the 90's, when Intel was going to introduce a unique identifier in their processors that could be used for authentication purposes, it caused
by binarymax 7y ago
I remember back in the 90's, when Intel was going to introduce a unique identifier in their processors that could be used for authentication purposes, it caused a huge uproar and Intel backed down. [0]
Having a hardware embedded unique ID that can be (is) used for tracking a known persons location at all times is probably the most intrusive privacy violation we've ever had. That we willingly carry these things around and naively throw the repercussions out the window is the result of the death by a thousand cuts.
We've long lost the war on privacy.
[0] https://www.wired.com/1999/01/intel-on-privacy-whoops/ https://www.wired.com/1999/01/intel-on-privacy-whoops/
- NotPaidToPost 7y agoThe IMEI identifies a device. It is, or should be, useful to lock stolen phones, though it can obviously be used to track someone who keeps the same phone even if they change SIM card. The IMSI identifies the subscriber (and/or the SIM card) even if you change phone. As long as people are able to call and be called and as long as people need to be billed there has to be a reliable form of identification. This is not an "intrusive privacy violation", it is, as you point out, a technical requirement of our willingness to be reachable and most people think that the benefits far outweigh the very limited drawbacks.
- salawat 7y agoUsername checks out. Unfortunately, truth is spoken. This is the danger inherent to full enumeration of the technologically enabled envelope. This is also the danger of the "market"; as it incentivized the ability to clearly specify the "who" of the customer. It's why I've been getting increasingly uncomfortable with the economic push away from cash as the primary medium of economic exchange. The death of the payphone marked the beginning of the end for infrastructure that wasn't in some way dependent or useful as a means of user surveillance.
- mindslight 7y ago> As long as people are able to call and be called and as long as people need to be billed there has to be a reliable form of identification. Secrecy of user nyms is trivially solved by existing mix networks (eg TOR onion services). Network access/billing could be solved by blinded signature tokens or some other untraceable bearer instrument. Implementing latter would take cooperation from the network provider, or at least an MVNO and SIM manufacturer, but it is indeed possible.
- moftz 7y agoIntel ME already can spit out the UUID of the chip and has been able to do it for over a decade.
- amluto 7y agoSo can SGX (under certain circumstances). So can your hard disk, your NIC, and probably your firmware via DMI.
- binarymax 7y agoYes. Hence the 'death by a thousand cuts'. We couldn't fight every battle. We lost.
- stcredzero 7y agoHence the 'death by a thousand cuts'. We couldn't fight every battle. We lost. So does the future belong to those who can administer the "thousand cuts?" In 2019, that means those who own the Cloud server farms and control the organizations that hire hordes of programmers. Does that mean that privacy is dead by an inexorable process? Doesn't that imply that individual liberty is also, eventually, dead? How can we, the people, administer the thousand cuts?
- sbierwagen 7y ago>Does that mean that privacy is dead by an inexorable process? Yes. >Doesn't that imply that individual liberty is also, eventually, dead? Yes. >How can we, the people, administer the thousand cuts? Stop carrying a cell phone. There was a brief period of time, from 1990 to 8:40 AM, September 11th, 2001, when you could do all sorts of stuff online, and the powers that be either didn't, or couldn't, monitor it. That's changed, and that freedom will never come back. However, no matter how bad the modern surveillance state gets, contrast it to the ancestral environment: a village of 50 to 200 people, most of whom are related to you, watch your every move, and can determine if you live or die. Hunter gatherers don't even have a word for "privacy". It would take real creativity for things to get that bad today.
- neilv 7y agoThe opposition to that, Clipper chip, and V-chip are three of the specific examples that come to mind when I think of cultural changes among CS techies. My impression is that there used to be more awareness, concern, and forward-looking/vision about such things. (I even recall techies being shunned for doing the tiniest fraction of invasiveness/recklessness that some major companies do today, yet those companies are now regarded as prestigious places for techies to work.)
- autoexec 7y ago> I even recall techies being shunned for doing the tiniest fraction of invasiveness/recklessness that some major companies do today I remember uninstalling software and dismissing it as spyware for just phoning home. The very idea of a program regularly pinging some remote host to indicate the your machine was turned on and connected to the internet was offensive. Now basically every program does this, usually excused as checking for updates. I think a lot of the problem was as it got easier for people to get online more and more people were using the internet who didn't understand the technology or how it could be used against them. They didn't care about anything but checking sports scores and online shopping and it let companies get away with taking advantage of them in ways the old nerds would never have accepted and once those nerds were vastly outnumbered by people who didn't know or care about privacy abuses the nerds no longer mattered.
- jxramos 7y agoI think this assessment is very apt, I've long wanted to get the chops to visualize all the action taking place on my network access. It's all so hidden and under the hood, it would be very revealing for a YouTuber to do a walkthrough to show how leaky apps and websites are and what sort of payloads are coming off their devices to remote targets.
- autoexec 7y ago> I've long wanted to get the chops to visualize all the action taking place on my network access. It's all so hidden and under the hood You should look for tutorials on Wireshark or better yet get a Pi-hole and block ads over your entire network while you get trustworthy stats on where your traffic is going. That's probably the easier and more useful option. Casual packet inspection used to be much easier. Common traffic like HTTP, DNS, or SMTP are increasingly encrypted, but it used to be that you'd see everything pass over the wire plainly. A lot of the data companies send home is encrypted too so you might be able to identify which apps or programs are generating the most traffic or sending it to same shady destinations, but don't expect to see what data they are collecting from watching the network.
- segfaultbuserr 7y agoLooking back, it was unbelievable to see how huge the storm caused by Intel's "processor serial number" in Pentium 3 was, that even forced Intel to withdrew it. Meanwhile, nobody has ever said anything about the serial numbers of hard drives, GPUs, motherboards, RAM modules, Ethernet MAC address, etc, etc, etc. Nowadays, basically everything comes with one UUID. Pretty illogical, isn't it? > We've long lost the war on privacy. Agree. I understand UUID is important in engineering for many purposes, but the fact that nobody is talking about it anymore (because they are nothing when compared to more severe issues like fingerprinting) indicates we've long lost the war on privacy.
- Scoundreller 7y agoWould love to see a YouTube channel or blog where somebody systemically takes apart their computer and starts reflashing every serial number in flash/EEPROM with 0x00. It’s not like any of these are phoning home (I hope), or married together, so there’s nothing to kill clones.
- dmos62 7y ago> It’s not like any of these are phoning home (I hope) Firmware is largely closed-source, so all you can do is hope.
- segfaultbuserr 7y ago> reflashing every serial number in flash/EEPROM with 0x00. It will be an amazing video, but good luck if the device in question has (very likely): * a mask-ROM / OTP-ROM for a serial number - almost all microcontrollers and EEPROMs sold nowadays has at least one permanent and unchangable UUID for hardware tracking and DRM implementation (security-through-obscurity tricks to prevent rogue competitors from copying your firmware). * "firmware read-protection" - which means the only way to dump the EEPROM is performing a full-chip erase and destroy the entire firmware, commonly used in embedded systems to stop rogue competitors from copying your firmware.
- Scoundreller 7y ago
- blablabla123 7y agoI also still cannot believe that people question the need for privacy so much. There is always the assumption that only people up for something evil are supposed to have something to hide. But data can always be abused and obviously privacy advocates have been repeating over and over again what bad things could happen. And then people go to extremes with Tor, Noscript, Bitcoin and the like which would be completely unnecessary if the basic privacy requirements were fulfilled.
- RandomBacon 7y agoBitcoin isn't extreme - it's very public and trackable. Monero on the otherhand isn't.
- oneepic 7y ago>We've long lost the war on privacy. A bit of unnecessary FUD alarmism here. Seems like today's answer is no, probably not. It's just very difficult, requiring (i.e.) policy changes and mass adoption and transparent phone companies willing to not do dirty things with cellphones. I still think humanity can figure something out, people just have to step up.
- themacguffinman 7y agoIf you're fighting against identification technology, of course you're going to lose. Identifiers have real benefits and as we've seen with American SSNs, identification, uh, finds a way. We should be fighting to exercise jurisprudence to prevent and limit abuses of identification, not dismissing unique IDs.
- exabrial 7y agoJust wait for ipv6 then, where Nat is no longer providing casual anonymity.