3 ms·
I don't even want to know what the GDPR-implications of this are..
by ramboldio 4y ago
I don't even want to know what the GDPR-implications of this are..
- naniwaduni 4y agoHinges on how loosely a data protection authority is willing to read "filing system" because screw you, I'd think.
- themoonisachees 4y agoTechnically, it means that any system holding binaries is capable of holding data identifying a user, which has crazy gdpr implications. Practically I don't expect this to have any impact beyond state surveillance, where obtaining a binary for a virus (or, you know, drm-defeat code) can identify its creator against any public code they would have posted elsewhere.
- krageon 4y agoAnyone whose job it is to evade detection will pull their output through a scrambler. What this will catch is small-time criminals, probably in minority groups (frequently categorised as "high risk" by police).
- hyperhopper 4y agoBut is a developer a user? I think saying that is quite the jump.
- Test0129 4y agoMost malware is packed and/or obfuscated. I'd imagine this defeats fingerprinting relatively handily since the binary is rewritten. I'm sure this technique is used to catch particularly dumb adversaries, but against anyone with a hint of operational security it wouldn't work at all. Moreover, what's stopping a determined adversary from rewriting the binary with a signature that matches another person? Using this as a targeting method would have a lot of collateral damage.
- michaelmrose 4y agoNone. There is a difference between actually storing personal data and it being possible to forensically analyze data not eligible for protection and potentially correlate other similar data that in turn is tagged with metadata. The second party has the obligation not the first. Ultimately all risk of exposure of personal data derives from the second party. For example if you mail in an executable to a client and put some code on github under your own real name the holder of the exe has no obligation because it is impossible for your identity to be exposed by it or indeed an infinite number of similar executables. It is only when combined with your github profile where you willingly shared a work sample and your real info that you could possibly be exposed.