6 ms·
While I understand the argument being made, the fact that the data was apparently split across two machines with a relatively small number of data points (just
by theCrowing 4y ago
While I understand the argument being made, the fact that the data was apparently split across two machines with a relatively small number of data points (just over 2000) does suggest that the databases were specifically structured for the task at hand. Therefore, the assertion that the data of the whole afghan population is readily accessible seems somewhat exaggerated, and as a member of the CCC, I would have expected a more nuanced approach in communication. I like linus but since he took over as the defacto press officer all the releases get a bit sensationalized.
- Y_Y 4y agoOf course, these were just the devices they managed to buy on (presumably) eBay. There may well be a big pile of them being held by the Afghan equivalent of CCC or some other organisation that isn't publicising it. If you see a mouse in your house it doesn't mean there's one, it means there's loads.
- theCrowing 4y agoYou are as speculative in your comment as the press release its just bad manner. Why not just be truthful and communicate something "We expect that the data of the whole afghan population is compromised but we can't be sure at this moment." Just don't paint your suspicions as facts if you have no way to validate them.
- tommek4077 4y agoThe problem the CCC is presenting, is that now the Taliban probably can identify workers that helped the US. And everyone knows what they do with every single one of them. They don't need to find all.
- theCrowing 4y agoNo, we don't it's mostly assertions and I hate it. We don't know about how these two machines were used and were they come from despite ebay. The whole release should have used way less absolute wording because in the end the CCC could look like a clown show just because of assumptions.
- samus 4y agoWhat more do we need to know? The devices were found and they contained unencrypted and unobfuscated biometric data. There's so many things about these devices that should never have happened at all.
- theCrowing 4y agoAbsolutely right but the fact still stands that we have no valid data to paint it as a fact that the data of the entire population is compromised. It's a communication 101 that you never communicate in absolutes if you can't verify your findings.
- sally_glance 4y agoSkimming a couple of the sources mentioned in the article and the linked german government Q&A it seems they scanned a) collaborators and b) "potentially dangerous" afghan citizens. So we can reasonably assume that biometric data of those two population groups was leaked by left behind devices. Not the entire population, but the two most sensitive groups. Sounds pretty bad imo.
- theCrowing 4y agoAs I said before you are absolutely right it's fucking bad and repulsive but you can still communicate facts without making assumptions especially with a serious topic like this.
- rschneid 4y agoReading this polite exchange I couldn't help but be reminded of the classic: https://youtu.be/3m5qxZm_JqM https://youtu.be/3m5qxZm_JqM :) Glad we're all nice to each other in this corner of the web!
- deleted 4y ago[deleted]
- 4y ago
- daneel_w 4y agoDoes something in this raw data distinctly separate collaborators from "common people"? It's a travesty that they left the devices and the data behind, but I can't see anything in the article clearly stating that the 2632 identities found in those devices either all belonged to collaborators, or was "tagged" in order to discern them. So how would the Taliban positively identify them without having access to the complete refined/processed database that these raw biometrics went into?
- dmix 4y agoIt’s a signal. The database is a giant signal the people were of interest to the US gov. The Taliban will be able to figure out if they were criminals or Taliban or not. That leaves a small group of people they can torture to figure out the rest. Just have to hand out these same bioscanners to local police then hand off any matches to the higher organs. This device had a few thousand people. They can collect hundreds of these devices and rebuild the whole database.
- Abimelex 4y ago--> One of the devices contained biometric data on more than 2600 people, some of which had entries such as "Volunteer Background Checks," "Host Nation Police," or "Host Nation Military." https://twitter.com/BR_AILab/status/1607707952147992579 https://twitter.com/BR_AILab/status/1607707952147992579
- daneel_w 4y ago"Some of which" isn't the same as "all of them", and none of those three categories exclude being an islamist. I get that it's a serious case of recklessness, but the reactions here are too alarmist.
- iudqnolq 4y agoYour reply makes no sense. Not every Afghani collaborated, and plenty of collaborators follow Islam. This is obvious. This doesn't make those who collaborated any safer. You don't even need to know any specifics: it's a well-known humans tend to punish traitors even if they have a lot in common.
- lucb1e 4y ago> the assertion that the data of the whole afghan population is readily accessible seems somewhat exaggerated I don't see where they say that everyone's biometrics are supposed to be on a single ebay-purchasable device. To me, it sounds like separate statements: 1. Those devices contain biometrics of various individuals and were left behind as well as being sold online without being wiped as part of decommissioning 2. The entire population was catalogued in general, and I imagine is stored on some servers somewhere (or, for more privacy, in the cloud)
- theCrowing 4y agoI never said that they say that the data is available on a single-ebay purchasable device. You did. I said that the writing insinuates that the data is available at all but there is no certain way of knowing it.
- lucb1e 4y agoI presume that's what the document linked in that sentence (https://dserver.bundestag.de/btd/17/068/1706862.pdf https://dserver.bundestag.de/btd/17/068/1706862.pdf) is supposed to back up, but I don't read German so I just take "The entire population of Afghanistan was biometrically catalogued" at face value and don't assume they base it on any device when they really have no way of knowing. If I have now understood what you're saying in the second instance.
- theCrowing 4y agoThe document says the bundeswehr did participate in the data collection as part of their EUSAF mandate and that it was close to the entire population. It doesn't say anything about how the database was stored. I wouldn't have said anything if the wording wasn't as absolute at it is in the PR but the part about that all of the data is compromised just because it got collected just stinks.
- prhrb 4y agoThere is evidence for that https://dserver.bundestag.de/btd/17/068/1706862.pdf https://dserver.bundestag.de/btd/17/068/1706862.pdf
- theCrowing 4y agoThat's just evidence that the Bundeswehr did indeed participate in the collection of the data.
- aa-jv 4y ago[flagged]
- theCrowing 4y agoIt is unethical to attribute words to someone that they did not use, especially when presented as a quote. Misuse of technology can have tragic consequences, and it is important to remain factual in our statements in order to accurately convey the gravity of such situations. Every life lost due to the misuse of technology is deeply reprehensible, and it is crucial that we strive for honesty and accuracy in our discourse, and this means both sides of the discussion. You and me.
- aa-jv 4y ago>It is unethical to attribute words to someone that they did not use, especially when presented as a quote. In a discussion about the use of technology that can be used to effect ethnic cleansing, you want to argue about the ethics of "attributing words to someone they did not use" as a straw man .. ? An attempt was made to minimize the impact of this crime against humanity - thats what it is, a crime against humanity - and I made the comparison with other attempts to minimize crimes against humanity in order to indicate the fallacy of the position that "this is not a crime against humanity". That's called a rhetoric method, and if it upset your sensibilities, it might be more due to the fact that your sensibilities on this issue are completely out of whack. It is a fact that the mass collection of biometric data always leads to abuse and further crimes against humanity. So why justify its collection?
- theCrowing 4y agoIt appears that your perspective on the matter at hand diverges from mine, and I suspect that you may have ulterior motives beyond simply discussing the factual information that is relevant to the conversation. Regardless, I hope you have a pleasant day.
- aa-jv 4y ago
- riedel 4y agoCan you quote the sentences your are concerned about. While one could maybe make some non-sequitur conclusions by reading quickly, I do not see that much sensational reporting. The question really is what 'large amounts' mean when speaking of PII (when talking about single site I assume thousands is relatively large). But I agree that such subjective measures could easily be replaced by numbers. >Some devices were left behind during the hasty withdrawal of NATO troops. CCC researchers found large amounts of biometric and other personal data when analyzing such devices
- theCrowing 4y ago> The extracted data was all the more impressive: The various devices shopped online contained names and biometric data of two U.S. military personnel, GPS coordinates of past deployment locations, and a massive biometrics database with names, fingerprints, iris scans and photos of 2,632 people. The device containing this database had last been used somewhere between Kabul and Kandahar in mid-2012. That means from six devices there was only one with an intact database and the one with the database wasn't used since 2012. Concluding that the device in question was indeed captured after the retreat and that there is a massive amount of unwiped devices out there without providing data about the other devices is at least misleading because their very own anecdotal evidence speaks against them.
- Zacharias030 4y ago2632 is massive for info this sensitive. The rest of your inference is unclear, and not directly supported by the passage you cite.
- deleted 4y ago[deleted]
- theCrowing 4y agoWhat's unclear exactly? Also please stop putting words in my mouth nowhere did I say that the leak of 2632 of extremely personal and identifiable information is anything but massive and why do you not make your affiliation with the release and the CCC clear, Zach? Fucking child's play.
- Noujin 4y agoI always loved the CCC and what its members are doing, but the "new" face (including Fluepke, Lilith) make them look inexperienced, naive, loud without being constructive and everything feels a bit unscientific. Also they don't really respond to any critique and just say they don't want to talk about the stuff they're criticizing.
- pxtail 4y ago> the "new" face (including Fluepke, Lilith) make them look inexperienced, naive, loud This characteristic can describe most of young human beings and people listed above are young human beings. It's not reasonable to expect "fresh blood" in the scene to be experienced, young and worldly at the same time. When it comes to "being loud" - could also be attributed to the age but being "social media native" and being able to use it as a tool also is an useful (and potentialy powerful) skill
- Noujin 4y agoYes I understand this, but with great power comes great responsibility. They should know this & not abuse it. Somebody that tries to educate the general public should not just shout, but take part in a dialogue.
- acomjean 4y agoI can’t believe the data sits on there unencrypted.
- squarefoot 4y agoPlus leaving the devices containing the data at the mercy of the Talibans. I can't believe they hadn't planned for collecting back all devices, or at the very least render them FUBAR to prevent information extraction and/or reverse engineering; those are US Military property just like weapons, they must have had instructions on how to deal with them.