3 ms·
My company will sponsor $5,000 for the best idea submission for mitigation techniques against these types of systems. Any suggestion on the best service to use
by d0ne 14y ago
My company will sponsor $5,000 for the best idea submission for mitigation techniques against these types of systems. Any suggestion on the best service to use host this / receive submissions?
We will:
1) Open source all submitted ideas.
2) Let the community choose the top 5 and we will hold an internal review process for the top spot.
3) Fly the winner(s) to our office in Atlanta, GA to discuss the winning submission in details with some of the top information security experts in the world.
4) Work to get press around the winning idea.
5) If we get north of 50 submissions we will help seed (with an additional $5,000) an IndieGoGo campaign to see the idea developed.
Email me (adam | socialfortress.com) or respond here to discuss.
- jacquesm 14y ago> Fly the winner(s) to our office in Atlanta, GA to discuss the winning submission in details with some of the top information security experts in the world. That may be a bit prohibitive, given that they will still have to use air travel, possibly to and at least within the USA. I figure the people that come up with a mitigation against a system like this would be very smart to stay the hell away from claiming credit for it. And the top information security experts in the world are working for what we'll loosely designate 'the other side' here, I don't think they'll be on your discussion panel.
- mindcrime 14y agoAnd the top information security experts in the world are working for what we'll loosely designate 'the other side' here I think that would be accurate if it read: And some of the top information security experts in the world are working for what we'll loosely designate 'the other side' here There are some pretty goddamned smart people in the cypherpunk / hacker community, who would (and do) find this kind of surveillance crap abhorrent and who will work to resist it. I certainly would not say that all of the best people are on "the other side". Maybe time will prove me wrong, but I doubt it.
- jacquesm 14y agoI'm with you on the 'some', I should have been more careful with the wording there. Yes, there are indeed lots of smart people who find this crap abhorrent and who will work to resist it. But I don't think they're the majority. Not even close. Individuals such as Phil Zimmerman are making a real difference. But money is a powerful motivator. Lots of people will do very stupid things when offered enough money. Governments print money. Nationalism is another such powerful motivator. Press the combined buttons of nationalism and piles of cash and a lot of people will start seeing things your way. The NSA is currently the largest employer of mathematicians in the United States, and that probably makes them the largest employer of mathematicians planet wide. There are lots of counterparts of the NSA in other countries. And those mathematicians are not too upset about not being able to publish their results, so I'm thinking there is something to counterbalance that, such as abundant financial compensation. For now this is an unbalanced situation.
- mindcrime 14y agoFor now this is an unbalanced situation. Agreed. I was just trying to point out that there are at least a few talented folks on "our side".
- d0ne 14y agoHi there, That is optional for the winner(s) :) However, our company actually does have some of the foremost information security experts as investors (Founders / CTOs / CEOs of PGP Corp, Internet Security Systems, CipherTrust, PureWire, NitroSecurity among others). We also work closely with some of the leading researchers at the leading engineering universities in the area of cyber security. Always open to suggestion regarding the structure of the overall process for an event such as this! Thank you.
- Strshps1MoreTim 14y agoGreat idea d0ne. I hope you do understand, that what the boys in Washington hate most, are people thinking they have rights and taking actions to protect them. If this gets any coverage, don't be surprised by the pressure to give up (tax audits, no-flight list, credit ratings).
- javajosh 14y agoThere are two basic approaches to mitigating massive data collection efforts: reduce your digital footprint, or add noise to your digital footprint. The latter is far more effective, as you fuck them in three ways: you hide your data, you have plausible deniability, and you spam their databases with crap. However, the "data flak" approach has limits. It is only doable with discretionary data, and even that might be problematic. But it would work well to make access logs useless. While I don't want the system to spam hacker news with nonsense posts about building nuclear weapons, I might be able to harmlessly incorporate intentionally explosive phrases in a post just to annoy them (hah, see what I did there?) For things like flights and credit card usage, there is no way to introduce flak, or really minimize exposure. Of course, the best mitigation technique is to raise Cain over this and get the entire system dismantled. There is simply no excuse to be doing this sort of thing. The fact is that it would be pretty hard to organize an attack and not trigger (local) alarms. Local police have a feel for the community, for what's what. They can call in the feds if they need to. Systems like this are going to always have three serious problems: a) bringing the hammer down on the innocent (false positives), b) failing to detect actual plots (false negatives), c) be abused (used as a weapon for politically or personally motivated attacks). And in the long run a) and c) are going to grow monotonically, and that is not acceptable. It's one thing to have the asshole local cop bust down your door for no good reason, it's quite another to have a bunch of feds fly in to nab you based on some data in their computers. They've never met you, don't know you, don't know your relationships to the people around you - but based on data will ruin your life. That's a nightmare scenario if I've ever heard one!