28 ms·
CCC captures U.S. military biometrics database
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- just_steve_h 4y agoThis article highlights the responsibility that ALL technical workers share. We must be ethical in our actions at all times. For example: Is it ethical to create a biometrics capture & storage system that does not encrypt the data it stores?
- sschueller 4y agoThe biggest problem in these situations is that people are highly dependent an their current job (especially in the US) and of the boss says do it you do it. The lack of a safety net and your insurance being tied to your job makes this sadly a very easy choice. I was fortunate enough that out of college I could decline working for defense contractors unlike many of my colleagues. There would need to be some protection for workers like there is for whistleblowers but smaller things like this don't count as whistle blowing.
- H8crilA 4y agoThe truth is most people would operate just fine in any environment, including Nazi Germany, justifying it like you just did. It's plain luck that they aren't. In this specific case it's very easy to morally justify such data collection to yourself, after all your friend was just torn to pieces by an IED placed by partisans, and another one two weeks ago. Russians are really "good" at this counter-insurgency game, they simply torture, run concentration camps, ethnically cleanse by sending to Siberia. Worked in Chechnya, works now in Ukraine.
- jamil7 4y agoI wonder if more and more of these ethical issues will be what pushes tech workers to unionise rather than working conditions.
- landemva 4y agoDidn't help the rail union workers. https://www.voanews.com/a/biden-signs-bill-to-block-us-railroad-strike-/6860131.html https://www.voanews.com/a/biden-signs-bill-to-block-us-railr... '... Biden administration this week used the provisions of a 96-year-old labor law to force unions representing thousands of railway workers to accept a contract ...'
- jamil7 4y agoThanks for the article, I’m not American nor do I live there so I’m not so well versed on US labour law and unions. From reading the article however it seems this issue was particular to rail union workers? > Unlike the National Labor Relations Act, he said, which leaves both labor and management with "economic weapons" they can threaten to use (strikes for unions, and lockouts for management), the Railway Labor Act has a provision allowing the government to block a strike from taking place.
- landemva 4y agoUnions aren't like in western Europe, for example, where they are more considered in the business. Just two years ago OSHA (worker safety regulator) crammed down a vaccinated-or-fired mandate to nearly all companies and unions didn't help much. The only safety is to financially be able to quit.
- paganel 4y ago> The biggest problem in these situations is that people are highly dependent an their current job (especially in the US) It's not only that, it's also that the money is really good, comparatively speaking. One of my close friends is a tech guy and works for the biggest European defence company, which is mostly a French-German alliance (they're also in the business of making planes), and two of his last job stints abroad have been in Afghanistan and in Saudi Arabia. There's no way he could have made the sort of money that he made had he decided to work for a local, very boring company (I live in an Eastern European capital city).
- landemva 4y ago> people are highly dependent an their current job It is often voluntary lifetime debt slavery to have payments on the latest gadgets/car/timeshare/oversized house. Recently train workers union had working conditions crammed down on them by no less than Biden. If the workers were not in debt slavery they could have quit. Biden showed a union they don't have a choice when their members are debt slaves. Your protection will arrive when you change your lifestyle to get out of debt slavery.
- retSava 4y ago-Hey PM, I'm worried about this. We don't have the resource allocation to ensure the on-device data can't fall into the wrong hands. It's not even encrypted! -I hear your concerns and agree. There are strong protocols set in place to make sure devices are taken care of after use, and only personnel trained on this device may use and access it. Don't worry, they know what they are doing. We can add that encryption into firmware v2 so relax. Did you sign up for that conference in Florida btw? It's going to be the bomb, sunshine, fun like no tomorrow!
- layer8 4y agoI have refused working on projects I deemed unethical, explaining my reasoning. You can too.
- maerF0x0 4y agoI've been called a trouble maker and low performer for discovering and insisting on fixes to security flaws. I thought my concentration in Infosec would have been an asset to my career, but so far it's been a liability.
- serf 4y agoI would've stopped at 'Is it ethical to create a biometrics capture & storage system ' , thus highlights the problem with allowing technical workers to judge the morality of their own actions.
- lucb1e 4y ago> The entire population of Afghanistan was biometrically catalogued -- supported by the German Bundeswehr. I wonder if an affected individual could bring this before the European Court of Human Rights for privacy (article 8 ECHR).
- codetrotter 4y agoSeems that article 8 of ECHR could be relevant indeed. > S and Marper v United Kingdom [2008] ECHR 1581 – Retention of DNA information in respect of persons arrested but not convicted of an offence was held to breach Article 8. https://en.wikipedia.org/wiki/Article_8_of_the_European_Convention_on_Human_Rights https://en.wikipedia.org/wiki/Article_8_of_the_European_Conv... (section “Case law”)
- lucb1e 4y agoTo add a bit, obviously this was outside of Germany's borders and direct jurisdiction. Does that mean a German citizen can use German public money to perform actions that are against the convention on human rights abroad? And, similar to how the getaway vehicle provider gets a different sentence than the mastermind who also held the gun, probably there is reduced responsibility here. But is there none at all? And all this is still besides the question whether the employment was necessary and the least-invasive method possible. If you can prove a need greater than the lost privacy, as well as the lack of an alternative option, if I understand how the system works correctly, then it's perfectly legal also inside of Germany.
- Grollicus 4y agoGerman law knows no jurisdiction boundary for german citizens. A german that breaks german law but can't be charged in the country were they did it can still be charged in germany. (Weltrechtsprinzip)
- davrosthedalek 4y agoThe Weltrechtsprinzip only applies for a limited set of laws. I am not sure this would fall under them.
- defrost 4y ago> "The irresponsible handling of this high-risk technology is unbelievable," said Matthias Marx, who led the CCC research group. The consequences are life-threatening for the many people in Afghanistan who were abandoned by the western forces. > "It is inconceivable to us that the manufacturer and former military users do not care that used devices with sensitive data are being hawked online," Marx continued. I dare say this will be met by many in the west with <shrug> > And yet all of this was predictable, because biometric databases cannot be effectively or permanently secured against illegitimate interests. > What happened in Afghanistan is just a foretaste of the many biometric databases that will fall into the wrong hands in the future. This might stir a few people though - when it becomes commonplace for roaming police in the US, UK, Australia, Germany, etc to carry hand held devices with compressed offline usable biometric ID scanners ... What could go wrong?
- coldtea 4y ago>I dare say this will be met by many in the west with <shrug> Given that they shrugged off the wrong false accusation, bombing, invasion, and occupation of the same place, it's a sure bet
- some_furry 4y agoUnfortunately, the framing also matter a lot. When the Cambridge Analytica story blew up and Facebook was the main character of the week, I spent an entire 3 hours in a weird state of shock. Not because of the contents of the story. I was shocked because this story had broken like eight months prior and everybody shrugged then. But then it was framed politically, and suddenly people gave a shit. It was surreal. So if you want to get people to talk about it, and be emotionally invested, simply frame it as evidence of [Specific Politician] mishandling [Specific Element of News Story]. It doesn't matter much which politician you slot in there, but current and former presidents on opposite parties can work with different audiences. For example, make unsubstantiated allusions to an alleged stolen laptop and connect the dots through some vague sense of poor data security practices and you can get them to repeat it with fervor. For prior art, look at how that "litter boxes in public schools" hoax got started: https://soatok.blog/2022/04/06/the-dark-truth-about-the-furry-protocol/#origins https://soatok.blog/2022/04/06/the-dark-truth-about-the-furr... (I realize I'm risking devolving this thread into a politics discussion here. I'd like to avoid that if possible. I'm more interested in the "how to motivate people to care about this story" angle, with references to prior art, rather than the specifics of any particular party, person, or scandal.)
- ngcc_hk 4y agoPrivacy is the least current concern for A people?
- H8crilA 4y agoSadly, but remember that privacy there is often the difference between making it past the next regime change, or not making it.
- arianvanp 4y agoIt's not. These lists could be used to track down people who worked with the US government. They will be executed for this. These lists were a scandal a few months ago in Netherlands already as people who worked for the Dutch army in Afghanistan were scared for their lives when the government in A fell and NL was not able to get them out quickly enough and NL didn't destroy the records in the Ambasassy
- nyolfen 4y agodespite accusatory inferences, nothing in this suggests the data says whether someone worked with the US govt. the entire point of the project was to catalog the entire country, everyone got scanned at some point or another
- deleted 4y ago[deleted]
- usrusr 4y agoYou're certainly on to something in so far as this is why it happened: in an environment where it's a regular occurrence that bystanders die in violent clashes between one side that exposes itself in uniform and another that disguises themselves as (and/or considers themselves) regular people, "some PII" seems to be a very low price to pay for untangling the bloody mess a little. But as evidenced here, that PII won't go away and the consequences can be just as bloody as what it helped preventing, or worse. This is not about brandishing haughty principles, this is about difficult decisions and learning in a maze of known und unknown unknowns. Expect mistakes to be made and try to find the right balance between fostering a blame culture where too much is swept under the rug to learn and a careless culture where too much is blanketly forgiven.
- theCrowing 4y agoWhile I understand the argument being made, the fact that the data was apparently split across two machines with a relatively small number of data points (just over 2000) does suggest that the databases were specifically structured for the task at hand. Therefore, the assertion that the data of the whole afghan population is readily accessible seems somewhat exaggerated, and as a member of the CCC, I would have expected a more nuanced approach in communication. I like linus but since he took over as the defacto press officer all the releases get a bit sensationalized.
- Y_Y 4y agoOf course, these were just the devices they managed to buy on (presumably) eBay. There may well be a big pile of them being held by the Afghan equivalent of CCC or some other organisation that isn't publicising it. If you see a mouse in your house it doesn't mean there's one, it means there's loads.
- theCrowing 4y agoYou are as speculative in your comment as the press release its just bad manner. Why not just be truthful and communicate something "We expect that the data of the whole afghan population is compromised but we can't be sure at this moment." Just don't paint your suspicions as facts if you have no way to validate them.
- tommek4077 4y agoThe problem the CCC is presenting, is that now the Taliban probably can identify workers that helped the US. And everyone knows what they do with every single one of them. They don't need to find all.
- theCrowing 4y agoNo, we don't it's mostly assertions and I hate it. We don't know about how these two machines were used and were they come from despite ebay. The whole release should have used way less absolute wording because in the end the CCC could look like a clown show just because of assumptions.
- kleiba 4y agoThis is why I don't understand all the funding that goes into cyber security research and related technology: in so many cases, the technology is not even the weakest link.
- nicce 4y agoSomebody could argue that it is part of the research to identify all links in the chain, whether they are related to tech or not.
- lima 4y agoIt's a technology problem too: the devices should have been encrypted such that it wouldn't matter if they fall into the wrong hands. Of course, it all comes down to organizational issues in the end (they knew about the risk and ignored it), but this seems like exactly the kind of thing that politics want to prevent when they throw around money for "cybersecurity".
- 2-718-281-828 4y agoi fear somebody just won a free ticket to the us ...
- _8j50 4y agoIs ccc worth attending remotely this year? Use to be my favorite con but it is mostly german (I don't know the language) and I haven't seen anything that stands out last year or for this years' schedule. Been watching since 26c3.
- dbrgn 4y agoYou mean the congress? It's not taking place this year: https://events.ccc.de/category/37c3/#no-congress-2022-en https://events.ccc.de/category/37c3/#no-congress-2022-en Instead they defer to decentralized events across Europe: https://events.ccc.de/ https://events.ccc.de/ Many of them offer livestreams.
- _8j50 4y agoYeah, the decentralized streams. Would have been nice if they centrally organized something.
- hanemile 4y agoThe collection of decentralized streams are organized centrally here: https://streaming.media.ccc.de/jev22 https://streaming.media.ccc.de/jev22
- Phelinofist 4y agoIs there something like the Fahrplan again? Because the linked page does not really give any info about what will be streamed
- bbbbb5 4y ago> It's not taking place this year: https://events.ccc.de/category/37c3/#no-congress-2022-en https://events.ccc.de/category/37c3/#no-congress-2022-en What's this hygiene stuff they're talking about? Did they get in trouble with the venues over attendees not showering or something?
- 4y ago
- xg15 4y agoUSA: "Federal ID would be literally 1984!" Also USA: > The entire population of Afghanistan was biometrically catalogued - supported by the German Bundeswehr. The motivation for this systematic collection of fingerprints, irises, faces and DNA was to enable the distinction between good and bad people. Programs such as the Automated Biometric Identification System (ABIS) were designed to identify known criminals, as well as local collaborators or Afghan security forces, at any time.
- horns4lyfe 4y agoYes and the same people (ie feds) would do it and other worse things they’ve done overseas to American citizens, always worth remembering. These people aren’t your friends, and they certainly don’t have your best interest in mind.
- thinkalittlebit 4y ago[flagged]
- Vt71fcAqt7 4y ago>Who are these “feds”? Anyone who knew what Snowden did and did not report it is a fed. There are no two ways about it. DoD, Congress, the executive branch (CIA, FBI, NSA) are all feds.
- dsfyu404ed 4y agoInstitutions tend to trend toward power consolidation and authoritarianism over time. It's just how it is. Free society needs to constantly work to prevent it. I'm far more concerned about the Americans, many here, who's knee jerk reaction is to engage in all sorts of mental gymnastics to give the government the undeserved benefit of the doubt and minimize the significance when these things come to light. If I wanted to give them the same undeserved benefit of the doubt they give government I would say they are ignorant of the danger.
- 4y ago
- davrosthedalek 4y agoSlightly OT, but I just wanted out how remarkable the CCC is. Is there any organization in the world that is similar in size and impact?
- TechBro8615 4y agoFor context, this was a known threat when the US evacuated Afghanistan. It was just one aspect of the mess that occurred at that time so it didn't get much attention, but here's an article from August 2021. [0] The main worry was that we basically handed the Taliban a list of Afghan translators and US cooperators. It's been 18 months since then. Does anyone know if there were consequences for those people? Has the Taliban acted on this database to enact retribution? [0] https://www.technologyreview.com/2021/08/30/1033941/afghanistan-biometric-databases-us-military-40-data-points/ https://www.technologyreview.com/2021/08/30/1033941/afghanis...
- notadev 4y agoThe headline should be edited to specify the database was specific to Afghanistan citizens. I recommend this because when I read the headline I assumed it was referring to the Defense Biometric Identification System (DBIDS) which is the central system used to verify US military, dependents, contractors, GS civilians, etc., when accessing US military bases or other secure areas.
- walterbell 4y agoAnnie Jacobsen wrote a book on biometrics in Afghanistan, "First Platoon: A Story of Modern War in the Age of Identity Dominance", https://thestrategybridge.org/the-bridge/2022/1/18/reviewing-first-platoon https://thestrategybridge.org/the-bridge/2022/1/18/reviewing... > Jacobsen's gripping account of how a platoon's deployment revolved around biometrics and how it ultimately led to a grave betrayal of justice is a must-read. Jacobsen fails to substantiate her connection between counterinsurgency and domestic policing norms. Nonetheless, she makes a compelling case for why deliberate thought must go into how governments use biometrics in the future. She rightly points out that citizens of the U.S. must be wary of the creep of battlefield biometrics into everyday policing. Questions still exist as to who should own biometric data of populations, what rights individuals have over their biometric fingerprint, and who should have access to such databases, especially when a war is over. Perhaps a future Geneva Convention-like treatment of biometrics is the answer in our ever-connected world.
- theptip 4y agoInteresting, thanks! I had no idea this level of biometric monitoring was going on, so a deep dive is called for. Given the well-known cascade of surplus military equipment to domestic police forces, it seems wise to be aware of this trend.
- walterbell 4y agoThe author's Twitter account is worth following, https://twitter.com/anniejacobsen/status/1607034427665960961 https://twitter.com/anniejacobsen/status/1607034427665960961