16 ms·
Surveillance too cheap to meter
- exikyut 5y agoSideline question: > My phone spends four to five seconds trying to tell Google about incoming calls, then raises a notification about its failure, resulting from my failure to configure it correctly, and only then does it activate the ringtone. What would have been configured incorrectly here?
- tgsovlerkhgsel 5y agoIs this actually true? "If you write an app for either platform, you have to publish it through the respective walled garden, and you can do so for free—but then it must contain built-in advertisements that provide Apple and Google with surveillance data of your users. If you want to protect your users from that, you must sell the app for money and hand over a cut to compensate Apple and Google for the missing advertisement and surveillance revenue." I remember back in the early days uploading a free app with no ad frameworks to the play store, and I believe there are plenty of third party ad networks (that I'd assume don't share data with Apple/Google)
- flax 5y agoNo, it is not true. You must pay to release any app on either store. Google charges a one-time $25 fee, Apple charges $100 per year. You may release a free app with no advertisements. In fact, that is the easiest configuration, since charging for the app means setting up payment information. And including ads means payment information and integrating ad serving code into your app. It is not "built in" on either platform.
- hackerfromthefu 5y agoYet it seems the vast majority of apps include ads.
- avianlyric 5y agoIt’s almost like the majority of developers write code to make money.
- raxxorrax 5y agoBut now you successfully filtered most of the people that don't. And there is tons of quality software without a business incentive aside from the fun to create said software. Happens, since part of software development is a creative (non commercial) enterprise. I would write more free software too if I didn't need to pay rent. Of course free software cannot be the only model, but as I said, you won't find much of that in app stores.
- hansel_der 5y agothey sure do. kinda sad that they mostly use functionality from the foss ecosystem created by the minority that doesn't.
- btdmaster 5y agoIn either case it is requiring the users to make an account with the violators, which is a problem in itself.
- dane-pgp 5y agoAny process with enough friction to prevent spammers/scammers also has enough friction to allow government censorship. Even if governments do end up allowing alternative app stores, I imagine the laws will include some sort of liability clause that means the store owner is responsible for censoring any apps that the government blacklists. This may not be relevant now, but when Western nations start banning E2EE chat apps and VPNs, I think people will become more aware of what a choke-point the app store model is.
- runnerup 5y agoThey’ve already bannned truly effective E2EE. Lavabit, TrueCrypt, Skype all RIP. I suspect the new E2EE protocols like signal may secure past communications to some degree but further forward communications can be wiretapped via federal order. No one seems to care.
- spzb 5y agoTruecrypt lives on as Veracrypt
- bigfudge 5y agoCan you explain how a Signal conversation with a verified correspondent can be wiretapped? My understanding was that their safety code would change and you would have to revalidate if anything untoward happened, but perhaps I’m wrong…
- runnerup 5y agoI figured an NSL could require Google Play to issue an “update” for that user which was just a backdoored client. Or similarly, require Signal to do something like that. As lavabit was pressured to do.
- kornhole 5y agoAnything you get from Google play store is wrapped with Google's trackers. This ensures that Google knows what you are using at a minimum. Then the promiscuous Google Play Services provides even greater visibility as it processes all your notifications. You can check the trackers here. https://reports.exodus-privacy.eu.org/en/ https://reports.exodus-privacy.eu.org/en/ Apple's store and OS is more opaque. Others may be better able to explain their mechanisms. A small minority of us don't have Google Play Services on our phones and get all apps from F-droid. So he is not referring to us. As a developer and system administrator I would have added to this piece how costly it is to actually delete data. It is usually far cheaper to store everything even well after it has legitimate use because developing archiving routines and strategies that don't break other things is work that few IT organizations bother with among all their other priorities.
- IanCal 5y ago> It is usually far cheaper to store everything even well after it has legitimate use This is true and one of the key reasons for GDPR. The cost for keeping data beyond the legitimate use needs to be increased.
- oblib 5y agoThere is a bit of a conundrum with this issue. Just last week I went over user accounts for one of my apps and deleted those that had expired for longer than 6 months on the live server. So, their data is off the live server but still on weekly backups that are rotated out and deleted after 4 weeks. But I also have snapshots of that server that go back years and it would be some work to delete a user's data on those. And other users might need to recover data, so I can't just delete the snapshots.
- WrtCdEvrydy 5y agoWait till you get a deletion request for a specific user... we've had to mount snapshots as DBs just to have an automated query purge their record from the snapshot, delete the snapshot and retake the snapshot.
- _moof 5y agoWith all due respect to phk, that he has gotten such a basic fact so howlingly wrong makes me wonder what else in the article needs attention.
- agallant 5y agoIt's perhaps worth steelmanning the argument here - though technically one can release an app for free, it is generally the case that any app with significant investment (warranting monetization) will take one of the two paths he described, and this describes the majority of popular apps.
- dotancohen 5y agoThis sentence: > but then it must contain built-in advertisements Could just as easily have been: > but then it most likely contains built-in advertisements In a technical article there may be many reasons for simplifying an explanation, but there is no excuse for lying.
- Helloyello 5y ago
- deleted 5y ago[deleted]
- sideshowb 5y agoI've lost battles with an editor (of a popular publication) that ultimately led to inaccuracies like this creeping in. They just cared about readability far more than truth.
- raxxorrax 5y agoI think the larger context is that you need to pay a fee to upload an app and have it reviewed. If you don't want to shoulder the cost you need to reimburse yourself through advertising income if you want to have it available for free for yourself and your customers. So I don't believe this is a harrowing mistake...
- woah 5y agoAlso this one: "There is objectively no reason why Apple or Google should know every single time you make a phone call or send a message, but since their profits are built on them knowing, you will not find it easy to configure your mobile phone to not tell them" I could see it being true about Google, but Apple?
- hackerfromthefu 5y agoI recall a recent HN post that showed that in terms of bytes of data, iphones send more to Apple than android phones to Google.
- avianlyric 5y agoI would also like to see some citations on this. He mentions experiences with Android, but nothing for iOS. It makes me wonder if the author is speaking from a place of knowledge, or just speculation.
- Animats 5y agoBefore CALEA, surveillance was not "built in" to the phone system. Back when Guliani was a prosecutor, taking down the New York mafia, he wrote in his book that the FBI had to pay New York Telephone for a wired connection into any phone they wanted to tap. It really was a wired connection, manually wired onto the main distributing frame, and billed as a private line to a third location. On one occasion the FBI didn't pay their bill, and New York Telephone billed the party being wiretapped. That was part of the motivation behind CALEA. Electromechanical end exchanges did not log call data for local calls. Some of them counted it, with racks of little counters, read once a month. Toll switches had a logging system involving a wide paper tape. No cheap storage devices existed in the electromechanical era. What's now referred to as a "pen register" is today an extract from switch logs. But at one time, it was a real physical device. A device that put dashes on a paper tape to log dial pulses. I own one, and it's the one shown in Wikipedia.[1] Mine is hooked up to a dial and some circuitry for demos. You wind it up with a big brass key. The first dial pulse starts the clockwork moving, and it continues to run until there have been no dial pulses for a few seconds. Someone had to hook one of these up to a specific line to track what was being dialed. That's what the Supreme Court was talking about when, in Smith vs. Maryland, Justice Blackmun wrote "Given a pen register's limited capabilities, therefore, petitioner's argument that its installation and use constituted a "search" necessarily rests upon a claim that he had a "legitimate expectation of privacy" regarding the numbers he dialed on his phone." The "limited capabilities" are a lot less limited today than they were in the wind-up era. [1] https://en.wikipedia.org/wiki/Pen_register https://en.wikipedia.org/wiki/Pen_register
- Helloyello 5y ago
- generalizations 5y ago> On one occasion the FBI didn't pay their bill, and New York Telephone billed the party being wiretapped If the New York telephone didn't like what the FBI was doing, that's the most passive aggressive thing I've ever heard of.
- 5y ago
- FridayoLeary 5y agoIndividuals have far more freedom then ever, but at the same time their actions are increasingly becoming more recorded. The reality where every facet of a persons life becomes known to government is almost completely upon us. It will soon become impossible to commit the smallest of crimes without law enforcement being notified. The data is almost complete, all that's standing in the way is existing privacy laws and the inherent difficulty of compiling the data. Flimsy barriers to dystopia.
- Helloyello 5y ago
- glenda 5y agoI am curious if individuals do actually have more freedom now than before.
- Spooky23 5y agoDepends on how you define it. We all certainly leave much more of a paper trail. My dad and I spoke about this a few years ago. When we lived in NYC I used to go to work with him for a week or two in the summer. The only evidence recorded of that was my name on the visitor log taken by the receptionist. That visit today is almost certainly auditable. The subway trip is via payment card, and our entry in and out of stations are almost certainly captured by MTA and NYPD cameras. Street surveillance is pervasive in Manhattan from any number of entities. The NYPD network has facial recognition capability. Entry into the building is logged by swipe card, every time you go pee in the bathroom in the public area, there’s often a badge swipe. So are we less free? I don’t know. We’re more watched. But then again talking to my cousins on the phone in California was a major family event. And my dad would have to dodge out of work to take out cash for the weekend. A few weeks ago we took a long weekend in Florida with 4 hours notice and travelled without luggage.
- Terry_Roll 5y agoThey dont have freedom because science stole it. They have more things to keep them entertained, more tv channels, millions if not billions of websites to choose from, so much content on streaming platforms like Youtube, you would need millions of lifetimes to watch everything. You see, if you know enough about humans or any other animal you can manipulate them, like throwing a dog a stick to fetch, this means they dont have freedom not even freedom of thought. Newspaper headline writers are wordsmiths, but now science can predict what words and phrases will hook different types of people to get them to read their output. Just look at the Trump relection & Bidens election, using adverts to identify floating voters ie those who have not made up their mind and then targeting them to manipulate them to vote a certain way. I can usually pick out the next US president from a year before the elections, done this Bush. Its like right now, people give out data which when datamined can be used to track and identify people across multiple websites, work out your working patterns, holiday preferences and then from there you can be targeted remotely or in the flesh. We get little nuggets of information released which give us clues as to the level of surveillance and scope. One example. https://en.wikipedia.org/wiki/AT%26T#Privacy_controversy https://en.wikipedia.org/wiki/AT%26T#Privacy_controversy Another example although this is more access to property, but its a tool you can find in Locksmiths toolkits and first responders tool kits. In other words this is a deliberate bug in a security system. Link is already cued. https://www.youtube.com/watch?v=U5-qy2tbDG8&t=119s https://www.youtube.com/watch?v=U5-qy2tbDG8&t=119s This is a real eyeopener. https://cryptome.org/ https://cryptome.org/ When you look at the legislation that exists and does not exist, you can identify the area's where state criminality can occur, but the official secrets which released by countries annually will always hold back some stuff as national security. This can include things like techniques still valid for use today, ie stuff thats been used for hundreds of years and stuff that is fairly recent but still in use today. When you look at the legislation that exists, like people haved said we are a product of google, we are also a product of the state.
- nonrandomstring 5y agoSurveillance may be "too cheap to meter", but it isn't cheap. Millions of hard drives run 24/7 in thousands of data-centres around the world. Millions are discarded and replaced annually. System security is inversely proportional to the demands and power of surveillance actors (NSO for example), so we all lose money when we tolerate surveillance. By 2025 cyber-security will cost the world about $10.5 trillion per annum, and a significant amount of that will directly result from the existence of a concomitant surveillance industry. The cost to society and business in damaged trust and lost opportunity must run to dozens of trillions over the past decade. No! Surveillance is cheap to tiny minority who inflict a colossal economic externality onto the rest of society. > IT nerds tend to find technological solutions for all sorts of > problems—economic, political, sociological, and so on. Most of the > time, these solutions don't make the problems that much worse, but > when a problem is of a purely economic nature, only solutions that > affect the economics of the situation can possibly work. This is insightful. Let's start changing the economics around surveillance. Let's make it very, very expensive again.
- FridayoLeary 5y agothat's impossible with the government actively thwarting any such efforts. The self promoting and vastly overfunded security apparatus' of various countries will justify their actions and budgets with "counter-terrorism". Before that it was "communism". The uk government spent vast sums on CCTV. Obviously, they turned out to be useless without adequate funding for actual police.
- deleted 5y ago[deleted]
- Goety 5y ago>Let's make it very, very expensive again. That is a small goal of GDPR.
- raxxorrax 5y agoGDPR has enough holes that governments can continue to expand surveillance as they wish.
- TMWNN 5y agoVernor Vinge's A Deepness in the Sky depicts a human interstellar civilization thousands of years in the future, in which superluminal travel is impossible (for the humans), so travelers use hibernation to pass the decades while their ships travel between systems. Merchants, including the ones the book portrays, often revisit systems after a century or two, so see great changes in each visit. The merchants repeatedly find that once smart dust (tiny swarms of nanomachines) are developed, governments inevitably use them for ubiquitous surveillance, which inevitably causes societal collapse. <https://blog.regehr.org/archives/255 https://blog.regehr.org/archives/255>
- octoberfranklin 5y agoIn the old alphanumeric pager networks you could receive a notification without having to transmit anything. This meant that your location remained private -- even from triangulation attacks! Not even satellite pagers have this feature; they all require that you transmit first (often with a GPS coordinate included). With the collapse of the POCSAG networks (at least in the US -- the vast majority are now off the air), we have lost something valuable. Wide area broadcasting might not be as bandwidth-efficient as cellular schemes, but if you just want to receive a kilobit-sized notification (which might be of the form "you have a message from XYZ", prompting you to go online) that isn't a big deal. We could go from always-on surveillance to letting people decide on a per-notification basis if declaring their location is worth receiving the rest of the message. Or if they should move to a different location before doing so.
- jcims 5y agoWell, to be fair, POCSAG is plaintext and scoopable with a $20 USB radio and some software. But your point stands.
- octoberfranklin 5y agoNothing stopped you from encrypting messages before sending them. This isn't ham radio. Besides, you should not rely on physical infrastructure providers for encryption. TLS is done by the endpoints, not the ISPs, for a very good reason.
- walterbell 5y ago> We could go from always-on surveillance to letting people decide on a per-notification basis if declaring their location is worth receiving the rest of the message. Or if they should move to a different location before doing so. Could a similar capability be built on a local LoRA mesh?
- octoberfranklin 5y agoLoRA will always have spotty coverage. There might be a lot of spots all over the place, but they're still just little spots. For short messages, you need much lower frequency. Then you can cover entire cities from one or two sites. The lowest-frequency LoRA transmitters are still UHF, and they can't be used from towers or hilltops due to HAAT restrictions: https://en.m.wikipedia.org/wiki/Height_above_average_terrain https://en.m.wikipedia.org/wiki/Height_above_average_terrain You really want something VHF or below. Like a chunk of the former analog TV bands. A really really tiny sliver is enough. LoRA is a horrifically bandwidth-inefficient protocol. It craps on a gigantic swath of frequencies in order to send a few bits of data. They call it a "chirp", not a "crap". The only reason anybody gets away with such a wasteful modulation scheme is that it happens in the garbage band.
- s1mon 5y agoI was surprised that the post didn't mention anything about the main reason we were told that mobile phones needed GPS - for emergency location services. Sure this has also enabled unwanted and illicit surveillance, but it's also added countless mapping and location based services that weren't even considered when mobile phones first got GPS chips. https://en.wikipedia.org/wiki/Enhanced_9-1-1 https://en.wikipedia.org/wiki/Enhanced_9-1-1
- nitrogen 5y agoweren't even considered Phones had navigation before they had GPS chips based on cell location. Standalone GPS navigation devices with similar form factors to phones existed as well. And GPS dongles for laptops allowed turn-by-turn navigation back when an iPhone was a bulky thing that sat on a desk and dialed into a landline ISP.
- s1mon 5y agoYes, those existed at some level, but once GPS was built in, it became “free” and easy to get location. Assisted GPS (using cell position and downloaded ephemeris) also meant you didn’t need a couple minutes for a dedicated GPS to go from a cold start. There wouldn’t have been Uber, Yelp or Pokémon Go before location was just an API call.
- 1vuio0pswjnm7 5y ago"On the other side of the wireless connection, there are only two games in town: Either you are Apple, or you put Google's Android smartphone software on your product. Both platforms are architected on an economy of surveillance." It always seems like many an HN or other commenter from around the web/internet are keen to argue that Apple's platform is different and is not architected on an economy of surveillance. If anyone reading doubts this, I can dredge up some examples. In any event, these folks like to focus on differences rather than similarities. There are similarities. Lots of them. Here, PHK says Apple's platform is architected on an economy of surveillance, just like Google's. I must agree with PHK on this one. "There is objectively no reason why Apple or Google should know every single time you make a phone call or send a message, but since their profits are built on them knowing, you will not find it easy to configure your mobile phone to not tell them-and you will be constantly pestered by ominous warnings and notifications if you manage to do so." With NetGuard on non-rooted Android, one can block all Wifi and Mobile connections on a per app basis and per domain+protocol if desired. One can block everything and whitelist selected apps. How does Google track calls and messages in spite of NetGuard. "If you write an app for either platform, you have to publish it through the respective walled garden, and you can do so for free-but then it must contain built-in advertisements that provide Apple and Google with surveillance data of your users." Is this true. What about repositories or applications like F-Droid. "This takes an incredible amount of RTTs (round-trip times), which is why work on HTTP in the past 10 years has had a laser-like focus on avoiding TCP's three-way handshake by any means imaginable, while at the same time trying to obscure-as much as possible-precisely how much and which surveillance data the big platforms are collecting." Is he referring to HTTP/2 and HTTP/3. Observing outgoing traffic does appear to be more difficult under these revised HTTP protocols. Intentional or merely a side effect. You make the call. "Whenever you see one of those "Share this on Facebook" icons on a web page, your browser makes a DNS request and an HTTP request directly to Facebook's servers to get that little image." To solve this problem, some web pages just use a locally-hosted image for the icon, not one hosted by Facebook. No lookups required. It really is quite sneaky the way that Facebook places those icons on millions of web pages. What looks like a harmless buttton is truly a surveillance gimmick. It is sad that so many websites play along with the game. Perhaps they are not even aware of what they are supporting.
- sour-taste 5y agoI think this is wrong. It's not free for Google or Apple to log data from their app stores/call logs. It costs massive amounts of storage, it costs training for employees on dealing with personal information, it costs engineering time and money to run the systems. It's absurd to say that it's cheaper for these companies to do this than not do it. They're making a decision to do it because it helps them make money (directly through monetizing the data or indirectly through running another service). I get where the author is coming from, I agree that privacy is important, but the thesis is wrong(for these examples, idk about the telcos one)
- bryanrasmussen 5y agoI suppose though once you have invested the money in doing all that (setting up storage, making training materials, code to do various things) it might be cheaper to keep doing it (in any particular financial year) then to do the work needed to dismantle all that.
- xg15 5y ago> Third, it is truly interesting data. AT&T used to send out press releases about how many holiday calls they had handled each year; similarly, modern telcos often boast how many handsets have been at sports events and stadium concerts. OT: That's not really interesting data, it's flashy data at most. In those situation, we have a very specific image what data we expect to see - it would be more puzzling if someone big sports event didn't cause a spike in mobile connections from the stadium. But I don't see how any new knowledge is generated from this stuff despite press releases telling everyone what they already know.
- eternityforest 5y ago"Never mind that today, nearly all contracts are fixed price and people complain only when they get hit with predatory charges from third parties, cruise-ship networks, in-game purchases, etc." Are the records not useful in this case, for the client to defend themselves against the third party? Warantless surveillance may be a problem, but the data has legitimate uses. I wish people would spend more time trying to change how it is used rather than trying to stop the collection.
- pinephoneguy 5y agoClosed software is impossible to predict and pathological behavior is too profitable. You should never use closed software.
- usrbinbash 5y agoSo it is more costly not to store surveillance data than to store it? $ vim awesometelephonesystem.conf [logging] logpath=/dev/null Done. No need to redesign anything about the system itself. Data comes in, data gets thrown away.
- vaylian 5y agoIf you are required by law to store the data, then the lawsuits can cost you more than what you save by not buying hard drives. And yes, that is absurd.
- usrbinbash 5y agoIf its required by law, then telcos need to comply, that isn't in question. If that is not what the majority wants, they need to elec governments committed to change these laws. I am merely pointing out that, once the law permits doing so, actually not storing something is quite easy.
- Hakashiro 5y ago"If you don't like surveillance just vote for another party" Absurd and dangerous simplification of democracy. You will not get anywhere with that kind of thinking.
- usrbinbash 5y ago"Elect government" doesn't necessarily mean "vote for the another party". Candiate c1 may support issue X, while candidate c2 does not, so I vote c1, if X is an important enough issue for me, and if I trust c1 to actually make good on the promise of B.
- spacexsucks 5y agohttps://github.com/subspacecommunity/subspace#setup https://github.com/subspacecommunity/subspace#setup I have been using a $5 vps for setting a simple vpn for family. it is super easy to ru your own vpn now. Some sites dont work because they have dumb ip blocklists but most do or give hcaptcha. Imo, 1. The more we use vpn, the higher the cost of surveillance. 2. Sites using dumb techniques like hcaptcha and ip blocking will see a drop in traffic and have to wise up or lose out
- Goety 5y agoI cant even access my streaming services without being snooped on per the 'privacy agreement.' Essentially my tv is bricked outside of traditional cable. I dont use or set up voice commands but the privacy agreement allows them to store my voice for voice commands without setup. If I dont agree to the privacy statement I cant use my paid for streaming services. Life in this century is a total joke. I will never get another smart tv and I hope the trend dies.