Showing posts with label 1984. Show all posts
Showing posts with label 1984. Show all posts

Monday, November 10, 2008

On Internet Filtering

I was going to write a big diatribe about how this is destined for failure, and how we should all write letters to the Minister, and then Nicholas wrote an awesome letter.

I think you should go read that instead. Oh yeah, and write a letter. Cos Internet filtering is really stupid.

Friday, September 5, 2008

George Orwell

For those of you who like the work of George Orwell, I found about a blog that is putting his diaries online, each day as they were written, 70 years ago.
I quite like a bit of old EAB's work (that' wanker-talk for Eric Arthur Blair, George Orwell's human name) and personally find this to be quite interesting. Some of the entries aren't the most enthralling ie September 1: Fine and fairly warm, but the more interesting stuff is set to come online from the 7th of September, where his political ramblings enter into his writing.

This blog is pretty interesting. At the moment, Orwell is (i think) off the coast of Portugal, at Cape Vincent. You can follow his travels on a Google Maps link that the blog peoples have put up.

If you like Orwell and his stuff, get on board. If not, shoot me with a big gun.

Bye now.

Thursday, August 21, 2008

"Hacking" the Olympics: an exercise in censorship & fraud

A very interesting article came to the fore today: the "hacker" (I use this term loosely, for all he really did was come up with some specific search queries for various search engines) Stryde went through some search engines to discover that the gold medal winning gymnast, He Kexin, is potentially underage for competing in the Olympic games. The official age requirement is 16 years, where the evidence uncovered by Stryde has shown that she was in fact only 14. You can read his initial discovery here, with a follow-up here.

Now the interesting part for me isn't so much the fraud, which is yet to be commented on by anyone official, but that there is something at work busily taking these sites and documents referring to the girl's theoretical real age down, which is most likely the Chinese government. This annoys me particularly because it's just the most recent development in a line of information-barring moves they have made over the Olympics, such as blocking journalists from various Websites after saying that journalists would have unrestricted access to the Internet, cancelling press conferences because hard questions were being asked, and general restrictions on things to be reported about (no Tibet, no protesters, etc.). This worries me because of China being such an increasingly influential nation that the world is essentially tiptoeing around, wanting to get in on the opening markets, not wanting to offend anyone by mentioning dreadful human rights records, for example. And the Chinese are getting away with pressing it on us because they know they hold the balance of power (for example, China owns about 502 billion US dollars of the US national debt, the second highest foreign owner after Japan). Does this mean that China can essentially start to force its crazy censorship and other oppressive acts, such as sentencing elderly women to "re-education through labour" because they wanted a protest permit?

As a society we give up more and more of our freedom every day, through surveillance and personal information sharing, bit by bit these are whittled away by our own governments and corporations, and yet we are generally apathetic about this sort of "lack of freedom creep", as long as it doesn't upset our daily lives (and may even welcome it if it seems to improve our lives!). Perhaps we will start to see the fastest growing economy's influence increase in our own society due to our own apathy.

I hope for one that the Olympics will open the Chinese people up to the outside world and see that there are ways they can keep their unique culture but become free from oppression through access and distribution of information, and put pressure on their government to change.

(yeah, sorry about the rant, this just annoys me!)

Friday, July 25, 2008

Politicians and integrity

This topic could run on for ever, but I just read this rad thing on Victorian politicans. In particular, I would like to call your attention to this awesome factoid:

"The Government's reliance on the car came under fire in April when Premier John Brumby used a chauffeur-driven car for a 400-metre trip from Parliament House to 55 Collins Street — to sign an agreement to cut greenhouse emissions."

I don't know why, instead of getting angry about this, it just makes me feel warm inside and very smiley. Like my blood is made from puppies.

Anyone else get that feeling, or have I completely lost the plot?
Also, if anyone else finds such beautiful factoids about politicans and integrity, my eyes would like to look at them in order to maintain this PFB delusion (PFB being 'puppies-for-blood').

Thursday, July 3, 2008

Wikileaks -- when does freedom of information go too far?

I read with great interest this article on wikileaks.org, a fascinating site that allows whistle-blowers to do their thing. As the article mentions, it's already played a huge part in several astonishing cases around the world -- disclosure of information about the looting of Kenya by a former president, money laundering by a Swiss bank, and US interrogation procedures in Guantanamo Bay.

The article looks at criticism of its "free-for-all" policy, publishing actors' tax bills with their SSNs, or scripts for upcoming movies, and for its publishing of Scientology and other secretive religious documents.

All this got me wondering, where should the line be drawn? The old saying "information wants to be free" seems to be the key ethic of wikileaks itself, but how is publishing movie scripts or innocuous tax bills at all useful?

I'm all for freedom of information, but if there's no greater good to be gained from the publishing of it, it seems purely malicious and somewhat counterproductive to the aims of wikileaks itself (establishing it as a reputable source for information, for example). There are certain industries where whistleblowing, although legal, will get you in a lot of trouble if you go through the official channels, and wikileaks adds a good level of anonymous abstraction to the process which can certainly be used for a lot of good.

What do you think?

Wednesday, April 16, 2008

Phorm: like a human organ farm for advertisements

While I'm busy being outraged, here's something interesting I found today, a BBC article discussing a new advertising company called Phorm.

This is the rub:


Phorm works by connecting a users' web surfing habits to a series of advertising channels in order to target adverts.

Keywords in websites visited by a user are scanned and connected to advertising categories, and then matched to particular adverts.

It means a user who has been visiting web pages with lots of references to cars, for example, could then see adverts for cars when visiting a website that has signed up to Phorm's service.


So basically it builds up a profile of your browsing habits while essentially snooping on you, then presents you with targeted advertisements.

If that's starting to sound a little evil, then here comes the clincher: it uses anonymous ISP data, that is, information taken from the ISP -- you don't have to install anything on your computer.

But it's opt-in, which is good... and they don't store or personalise any data, which is good... however to sweeten the deal (and to make ISPs possibly start to require it for their subscribers), they add in a bunch of useful things like phishing and fraud protection.

It could, however, be illegal, because it's intercepting information between the ISP and the user. But IT specialist Alexander Hanff went one step further:

"What Phorm is trying to do is to turn people into products - a global warehouse selling pieces of us to the highest bidders."


I'm really not sure how to feel about this one, except for a vague sense of uneasiness, because this is almost like a lime cordial maker paying the water company to put lime cordial directly into the pipelines that go to peoples' houses. And that makes me a bit upset.

Tuesday, April 15, 2008

Follow-up to employee email snooping article

So the water becomes a little muddier here -- turns out the Attorney-General's office is quite well renowned for attempting to bring in crazy authoritarian initiatives to restrict Australians under the guise of anti-terrorism solutions.

According to Crikey today (subscription possibly required), some of the A-G's secretary's recent efforts include attempting to silence criticism of ASIO after they wrongly detained Izhar ul-Haque (rejected by the commission), others in the office helped Howard with his infamous "children overboard" mess and providing the false allegations of weapons of mass destruction that dragged Australia into war. Apparently it seems that this lot quite enjoy close relations with the private sector.

Bernard Keane writes in the above article:


The private sector, across areas such as transport, communications, IT and energy, is a willing participant in the process of establishing a system for monitoring and protecting their facilities and the public infrastructure they use, all in the name of preventing or effectively responding to terrorism. After all, the process allows companies access to government funding for the maintenance and upgrading of monitoring and information-collection systems they would otherwise have to invest in themselves, enables – in the name of greater security – the development of new regulatory requirements that raise the barriers to entry for possible competitors, and transfers an element of operational risk to taxpayers.


Still think this is all about keeping Australians safe?

P.S. for some fun acronym bureaucracy in the world of Critical Infrastructure Security (CIS), this is a good read.

Monday, April 14, 2008

Is losing employee consent the price to be paid for cyber-terrorism safety?

I read with some initial horror this morning that the Federal Attorney-General, Robert McClelland, has proposed amendments to the Telecommunications (Interceptions) Act among other legislature to be introduced in order to combat cyber-terrorism. These amendments apparently (I can't find the original documents for all the searching I have done so far today after trawling the parliament website, all I could find is a proposed amendment from February that just expands warrant powers) allow companies and others who run critical infrastructure (apparently the financial system, stock exchange, electricity grid, transport system, etc.) to monitor employee use of the internet including email and other communications without their consent. The Act so far only allows those working in security agencies to be monitored without consent.

McClelland and Julia Gillard have spoken out to say that these amendments will help in securing Australia's infrastructure against cyber-terrorism, because a terrorist attack on critical infrastructure would "reap far greater economic damage than would be the case of a physical attack", according to McClelland, which Gillard backed up soon after.

Why do the A-G and Julia Gillard suppose that cyber-terrorists are likely to be working from within an infrastructure company? McClelland used the example of the Estonian hackers which used a bot-net of thousands of external zombie computers to take down the system. This isn't something that will be fixed by monitoring, all it requires is decent Distributed Denial of Service (DDoS) attack prevention mechanisms, which are available. And even if they still think that insider jobs facilitate terrorist attacks, why do they think that cyber-terrorists that may happen to be inside the company are likely to be stupid enough to communicate through company channels?


I'm also interested in what sort of mechanisms they are putting in place to avoid situations where employers with a grudge could use this law to poke into private affairs of their employees who are in no way a danger to the company or Australia's infrastructure, and how they are proposing that employers effectively monitor their employees for terrorist activity. What sort of delegation of these powers would there need to be to, say, someone employed by the company to monitor other employees? What sort of checks and balances are there for this? It seems like it would be detrimental to Australia's security if employers could act as if they were security experts and identify likely threats from innocuous emails.

Another thing that needs to be asked is why consent needs to be taken away. Consent can be construed as a waiver of normative expectations, according to Neil Manson and Onora O'Neill (and my upcoming thesis on informed consent in ICT will explain why I think this is a reasonable model to apply to ICT). It seems here that by legislating consent out of a workplace agreement that the government here is almost attempting to make workplace surveillance the norm. This surprises me coming from a supposedly liberal government! Why is not having an employee's consent important to this bill? Surely we can have a bill that allows for all the other parts with explicit knowledge of the employee. Many companies already have internet use policy agreements with their employees, which involve degrees of surveillance. Legislating this sort of thing is fine, but surely, like collecting tax file information or as part of a standard contract for employment, the legislation could include some sort of policy for detailing the surveillance and obtaining consent from the employee?

McClelland has said that information from these communications could be used in "for instance, disciplinary matters regarding the employees' conduct or any other privacy issues. In other words, you're not interested in communications from employees' friends, their children, other family members." I fail to understand why this sort of thing isn't already covered by the existing legislation though, or why it is necessary to remove consent from the equation, or put employers (and/or the person delegated to deal with these matters) in charge of judging the relevance of personal communication.

I agree that infrastructure is a juicy target for potential cyber-terrorist attack, but this set of laws is not the way to protect infrastructure. Infrastructure needs good solid protection through careful construction and management and contingency plans, not the ability for employers to be able to monitor their employees' internet use. If that's not what this is about, then terrorism needs to be fully disconnected from the discourse about this law. Otherwise, it's just fear-mongering, something more suited to the dim dark past of Australian government history.

New Policy Proposes That Work Emails Be Screened For Threats

Our friends of the Governmentmental variety are proposing new legislation to access personal work emails in order to prevent attacks on vital infrastructure.
http://www.theage.com.au/news/national/gillard-backs-workplace-snoop-law/2008/04/14/1208025033663.html

Now many of you paranoid types may see this as an infringement on privacy or some other such things. Some of you may even go so far as to devote years of your life writing thaecis on such things.
Anyway, my reason for posting is not to rant about this, but the hope that if people are interested in this, that they post new info and or links about this policy, if it becomes enacted etc.

That is all.