Categories
Quotations

2017.11.29

Most fundamentally, is it in Canada’s interest to further normalize the growing use of CNA (Computer Network Attack) activities by states? Should CNA be classified as just another tool of statecraft? Should such capabilities be restricted to a deterrent role? Is cyber deterrence, whether through CNA capabilities or more conventional responses, even a practical goal, given difficulties of attribution and the inevitable overlap between CNE (Computer Network Exploitation) and CNA? Would improved defence and resilience be a preferable, or at least sufficient, response or are all three required?

Bill Robinson, “CSE to get foreign cyber operations mandate”
Categories
Quotations

2017.11.28

As effective encryption spreads, it may well be that the future of SIGINT lies increasingly in “end point” operations and other activities designed to cripple or bypass that encryption, and some of those activities could certainly benefit from HUMINT assistance. But there are also pitfalls to that approach. Using on-the-scene people in foreign jurisdictions can mean putting individuals at extreme risk, and such operations also have increased potential to go wrong in ways that could expose Canada to extreme embarrassment and even retaliation. If the government is contemplating going down that road, it should probably be open with parliament and the public about its intentions.

Informed consent. Because it’s 2017.

Bill Robinson, “CSE and Bill C-59 overview”
Categories
Aside

Christmas in Coffeeshops

I’m certain that it’ll eventually drive me mad, but at the moment I’m enjoying the holiday music that’s playing in the coffee shops I work out of. Bring on Christmas and the holidays!

Categories
Aside

I’m Not Linking to the Clickbait

The title of an article The Verge put up today — “My $2,000 iPhone X” — is the worst kind of clickbait. The article’s title is misleading (the phone was about $1500) and doesn’t actually inform the reader of the topic (the author bought extra stuff). It’s stuff like this that best exemplifies the bait and switch problems with online writing.

And no: I’m not linking to the clickbait.

Categories
Aside

Consolidation of Writing

One of the long(er) term goals of this site is to host my personal thoughts. But it’s meant consolidating stuff from medium-personal (as opposed to journal-like) sites. Today marked when I migrated + published more than 600 items. Only multiple hundred left!

Categories
Links

Metadata in Context – An Ontological and Normative Analysis of the NSA’s Bulk Telephony Metadata Collection Program

Abstract:

In the aftermath of the Snowden revelations, the National Security Agency (NSA) responded to fears about warrantless domestic surveillance programs by emphasizing that it was collecting only the metadata, and not the content, of communications. When justifying its activities, the NSA offered the following rationale: because data involves content and metadata does not, a reasonable expectation of privacy extends only to the former but not the latter. Our paper questions the soundness of this argument. More specifically, we argue that privacy is defined not only by the types of information at hand, but also by the context in which the information is collected. This context has changed dramatically. Defining privacy as contextual integrity we are able, in the first place, to explain why the bulk telephony metadata collection program violated expectations of privacy and, in the second, to evaluate whether the benefits to national security provided by the program can be justified in light of the program’s material costs, on the one hand, and its infringements on civil liberties, on the other hand.

A terrific paper from Paula Kift and Helen Nissenbaum.

Categories
Links

How severe will this flu season be?

From the Globe and Mail:

Every year, around February or March, the World Health Organization provides its recommendations on the composition of influenza vaccines for the northern hemisphere for the next flu season, based on its projections of what viruses are likely to be in circulation. But it’s hard to predict just how effective the vaccines will be.

In general, flu vaccines are around 50 per cent effective. But for the 2014-15 season, the vaccine effectiveness against H3N2 was less than 10 per cent. Flu shots are by no means perfect, but they’re still considered the best way of protecting people from getting sick.

The trivalent flu vaccine given this year, which contains three components, is comprised of an H1N1 vaccine component, an H3N2 component, and an influenza B component.

While the H1N1 component in this year’s flu shot has been updated for the coming season, the other two components have remained unchanged from last year’s flu vaccine, Skowronski says. Depending on which is the dominant strain this year, this could spell trouble.

“If it turns out to be a H3N2 season, then that means the vaccine effectiveness is likely to be suboptimal,” she says. That’s because last year, with the identical component, the vaccine effectiveness for H3N2 was around 35 to 40 per cent. And since the viruses are constantly changing and mutating, Skowronski says it’s unlikely the effectiveness of the same vaccine component will be any higher for the coming season. “That’s one of the unfortunate, concerning factors, frankly, from my perspective: that the H3N2 component is unchanged, yet we know the virus is changing.”

Even so, just because this year’s flu shot contains two out of three of the same components as last year’s, don’t think you won’t need to get vaccinated again if you got the shot last year. The updated influenza A component may help protect you in an influenza A outbreak, Warshawsky says. Plus, she adds, “We also know that the duration of protection doesn’t necessarily last well from one year to another. So relying on last year’s vaccine will not necessarily carry over protection to this year.”

The amount of information covered in the Globe and Mail’s article is really, really impressive. I learned a lot about the flu, vaccination, and how different vaccines interact with flu. Highly recommended.

Categories
Links

Data breaches, phishing, or malware? Understanding the risks of stolen credentials

New research from Google:

In this paper, we present the first longitudinal measurement study of the underground ecosystem fueling credential theft and assess the risk it poses to millions of users. Over the course of March, 2016–March, 2017, we identify 788,000 potential victims of off-the-shelf keyloggers; 12.4 million potential victims of phishing kits; and 1.9 billion usernames and passwords exposed via data breaches and traded on blackmarket forums. Using this dataset, we explore to what degree the stolen passwords—which originate from thousands of online services—enable an attacker to obtain a victim’s valid email credentials—and thus complete control of their online identity due to transitive trust. Drawing upon Google as a case study, we find 7–25% of exposed passwords match a victim’s Google account. For these accounts, we show how hardening authentication mechanisms to include additional risk signals such as a user’s historical geolocations and device profiles helps to mitigate the risk of hijacking. Beyond these risk metrics, we delve into the global reach of the miscreants involved in credential theft and the blackhat tools they rely on. We observe a remarkable lack of external pressure on bad actors, with phishing kit playbooks and keylogger capabilities remaining largely unchanged since the mid-2000s.

Categories
Links

Intro to Mitigating Contemporary DDOS Attacks

From Cloudflare:

As the capacity of networks like Cloudflare continue to grow, attackers move from attempting DDoS attacks at the network layer to performing DDoS attacks targeted at applications themselves.

For applications to be resilient to DDoS attacks, it is no longer enough to use a large network. A large network must be complemented with tooling that is able to filter malicious Application Layer attack traffic, even when attackers are able to make such attacks look near-legitimate.

The pace of change in how DDOS attacks are being conducted, and efforts to use best and worst security practices alike to threaten Internet-connected resources, is a serious and generally under appreciated problem.

Categories
Roundup Writing

The Roundup November 19-24, 2017 Edition

It’s another week closer to the end of the year, and another where high profile men have been identified as having engaged in absolutely horrible and inappropriate behaviours towards women. And rather than the most powerful man in the world — himself having self-confessed to engaging in these kinds of behaviour — exhibiting an ounce of shame, he’s instead supporting an accused man and failing to account for his past activities.


I keep going back and forth as to whether I want to buy a new Apple Watch; I have zero need for one with cellular functionality and, really, just want an upgrade to take advantage of some more advanced heart monitoring features. The initial reviews of the Apple Watch Series 3 were…not inspiring. But Dan Seifert’s review of the Apple Watch Series 3 (non-LTE) is more heartening: on the whole, it’s fast and if you already have a very old Apple Watch and like it, it’s an obviously good purchase. I just keep struggling, though, to spend $600 for a device that I know would be useful but isn’t self-evidently necessary. Maybe I’ll just wait until Apple Canada starts selling some of the refurbished Series 3 models…


While photographers deal with Gear Acquisition Syndrome (GAS), which is usually fuelled by the prayer that better stuff will mean better photos, I think that writers deal with the related Software Acquisition Syndrome (SAS). SAS entails buying new authoring programs, finding new places to write, or new apps that will make writing easier, faster, and more enjoyable. But the truth is that the time spent learning the new software, getting a voice in the new writing space, or new apps tend to just take away from time that would otherwise be spent writing. But if you’re feeling a SAS-driven urge to purchase either Ulysses or iA Writer, you should check out Marius Masalar’s comprehensive review of the two writing tools. (As a small disclosure, I paid for Ulysses and use it personally to update this website.)


New Apps and Great App Updates from this Week

Great Photography Shots

If tapeworms are your thing then there’s some terrific shots of them included as part of an interview with tapeworm experts. A few gems include:

Music I’m Digging

Neat Podcast Episodes

Good Reads for the Week