4 ms·
The problem now is that they're all a it. "In only the last three days Google [0], Apple [1], and Microsoft [2] have each been the subject of dispiriting secur
by nonrandomstring 2y ago
The problem now is that they're all a it.
"In only the last three days Google [0], Apple [1], and Microsoft [2]
have each been the subject of dispiriting security news stories
exposing their deceit and fundamental lack of trustworthiness."
I wrote the above here [3] yesterday in the context of how we approach
the problem of not just big-tech monopolies - among whom who we might
theoretically decide who to trust more - but a coordinated data
trading cartel made up of a network of treacherous entities and
"partners".
Staying on-topic, in the current context of email, with all of the big
three providers now unashamedly looting though your private
correspondence, either at their server or your endpoints, is email
effectively dead for business?
Using a more trustworthy provider like Proton or Tuta, or even running
your own mail servers only kicks the can down the road, since any
messages To: or Cc: recipients at defective providers is a leak.
[0] https://time.com/6962521/google-incognito-lawsuit-data-settlement/ https://time.com/6962521/google-incognito-lawsuit-data-settl...
[1] https://www.aalto.fi/en/news/keeping-your-data-from-apple-is-harder-than-expected https://www.aalto.fi/en/news/keeping-your-data-from-apple-is...
[2] https://www.schneier.com/blog/archives/2024/04/surveillance-by-the-new-microsoft-outlook-app.html https://www.schneier.com/blog/archives/2024/04/surveillance-...
[3] https://cybershow.uk/blog/posts/principles https://cybershow.uk/blog/posts/principles
- 7thaccount 2y agoI bought something on my phone recently and I'm guessing Gmail saw the email from the vendor or something and a few seconds later the Microsoft web browser on my work computer started advertising for precisely that item. I felt more than a little violated. People used to call you crazy for saying this was tracked and it's all normalized now. It's more than a little dystopian.
- withinboredom 2y agoI know a guy who worked on scanning SMS messages for keywords to do marketing with. They had some huge telecoms they worked with. This was also a long time ago. Terrifying stuff; who knows what they do these days.
- mschuster91 2y agoThey cooperate with providers and act as a middleman between them and advertising buyers... visit a site of a cooperation partner of utiq (e.g. Süddeutsche Zeitung) on a phone and a banner of them pops up. Probably kicks in once the tracker sees you're coming from a network range that matches a phone ISP. [1] https://utiq.com/ https://utiq.com/
- quantified 2y agoFacebook suggests friending people that I've only texted with and are only a couple thousand miles away. Definitely still happening at least.
- ben_w 2y agoFacebook suggests friending someone I worked with at once place 18 years ago and never spoke to or messaged since, and they show me adverts for both breast enlargements and erectile disfunction, and for hyper-local events in countries I don't live in and for people with citizenships I don't have. They might have just guessed.
- rprospero 2y agoWhat I find extra-annoying about the tracking is that it stopped pretending to be helpful. I remember chatting with my spouse on Google Messenger around 2012. We were discussing what to have for dinner when whatever the google assistant was called at the time popped up a message "Traffic is unusually heavy right now due to an accident on Kirkwood. If you want to pick up a pizza from Avers and be home by six, you should leave work in the next seven minutes." Was it creepy? Hell yes, but at least it was useful. The companies haven't cut back on spying on me, but, in an effort to pretend that they aren't, they've stopped sharing the useful information with me. Instead, they keep it to themselves to mine for the perfect car advertisement to send to a guy who doesn't have a license.
- nonrandomstring 2y agoAccidentally revealing your intelligence gathering capability is a famous trade-off problem. The Allies in WW2 occasionally had to let a ship get sunk rather than make it obvious that the Enigma had been cracked [0]. Plausible alternatives are usually assured to be in place, for example radar in the above case, or parallel construction in modern law enforcement. Bigtech are likely increasingly careful about making it too obvious that certain technologies (for de-anonymisation and correlation) are in use. Most people will still believe in unlikely coincidences rather than sophisticated behavioural analysis and covert monitoring of audio systems etc. [0] https://en.wikipedia.org/wiki/Cryptanalysis_of_the_Enigma https://en.wikipedia.org/wiki/Cryptanalysis_of_the_Enigma
- godzillabrennus 2y agoThe problem is people in general won’t pay for privacy.
- squarefoot 2y agoI would rather make companies that violate people's privacy pay as they're the only entities making profits here.
- pacifika 2y agoBusiness should be paying me to use my data instead.
- nonrandomstring 2y agoThere's a complete blind-spot in this debate that I rarely see discussed even in security circles. Grubbing through personal emails to target advertising is unseemly. But we accept companies like Microsoft, Google and Apple as the squalid little filchers they are and take such snooping as a part of life in the digital world now. We should not... be we do accept it. However, few people sincerely ask how did Google, Microsoft and Apple get so big? The fool says "by recruiting smart people and working hard at innovation". At best that's a microscopic part of the answer. A slightly wiser take is that they acquired every competitor and used every trick in the book to sabotage competition. But, again that's only part of the picture. The answer is that over the past 30 years they've engaged in the biggest, most egregious programme of industrial espionage in history. There isn't a single business in the Western hemisphere who BigTech have not had a total heads-up on their R&D, recruiting, internal development, marketing strategy, trade secrets and financial affairs. Keeping this conversation limited to whether or not Mavis cares whether Microsoft know what shoes she buys - is part of the trick. Sure no individual will pay for privacy. That's not where anyone who cares about liberal democracy and free markets should be looking.
- delfinom 2y agoI wouldn't trust Tuta like Proton Tuta ran a blog post about how Microsoft was out to get them because users of Tuta couldn't create Microsoft accounts. The kick? It's because Tuta was incompetent and we're using the same domain for public users of their service as for internal corporate use. They registered the domain as an azure tenant to that point. Then we're confused why users of @tuta couldn't create Microsoft accounts. The best part is disallowing "personal accounts" with azure tenant domains is a tenant setting. But they already committed multiple levels of security breakage by mixing anonymous and corporate use of the same domain. I even tested that they infact had an azure tenant with the very domain they claimed Microsoft blocked.