Categories
Aside Links

RCMP use of data may spark probe

RCMP use of data may spark probe:

At this point, there is a Supreme Court of Canada case concerning warrantless disclosure of data, a constitutional challenge being mounted against the section of Canadian commercial privacy law authorizing such disclosures, newspaper editorials calling for a Royal Commission on Spying (based, in part, on these warrantless disclosures), along with additional (related) legal, policy, and advocacy efforts to reform contemporary surveillance in Canada. Something in the current regime has to give.

Categories
Aside Links

CCLA Challenges Federal Privacy Legislation

What may likely be a long, and very interesting, case to follow.

Categories
Aside Links

Four weeks on, huge swaths of the Internet remain vulnerable to Heartbleed

Four weeks on, huge swaths of the Internet remain vulnerable to Heartbleed:

With the media off (most) companies’ backs there’s just no way/reason that these remaining companies are going to patch the heartbleed vulnerability. One can only hope that civil suits are launched against these remaining companies to show via the market that patching is a requirement for contemporary digitally-enabled businesses.

Categories
Aside

Surveillance Debate Tickets

Stage tickets for tomorrow’s surveillance debate!

Categories
Humour Videos

A brilliant interview between John Oliver and General Keith Alexander

Categories
Videos

Why the Cyberbullying Law is a Lie

Definitely one of the better (and more accessible) discussions of Bill C-13, aka the federal government of Canada’s lawful-access-in-disguise-legislation. Of note: that piece of legislation is “now under a time allocation order that will likely see it sent to committee by mid-week.” If the Committee is rushed, then it’s entirely plausible the legislation could be passed into law before this session of parliament closes for the summer.

Categories
Aside Quotations

2014.4.28

Students who acquire large debts putting themselves through school are unlikely to think about changing society. When you trap people in a system of debt, they can’t afford the time to think.

Noam Chomsky (via zeitgeistrama)

Post-secondary education is neither necessary nor sufficient to change society. Those of us with degrees need to stop acting like university uniquely equips us to improve or transform the institutions in which we operate. On average, we’re less indebted and more able to pay off that debt as a share of our income than those without degrees, so I’d suggest their debt loads are more of an urgent problem.

(via jakke)

I think that the problem is less “time to think” than “time to act.” If you believe that highly educated people can bring useful skills to bear on pressing problems, but that there are often minimal financial resources to pay educated workers to bring those skills to bear, then debt loads may preclude spending time focusing on those particular problems. In effect, if you can’t pay people to do the work then the socially-pressing work may not be done by those best suited to do it.

To contextualize: when I finished my degree there was a minimum amount of income I had to make to service my debt loads while simultaneously surviving in whatever city I ended up living in. That minimum income immediately meant that a series of jobs that would have been politically and intellectually engaging had to be set aside on the basis of insufficient monetary remuneration. It’s this kind of issue that Chomsky is getting at.

Categories
Aside Links

Ethical hackers say government regulations put information at risk

Ethical hackers say government regulations put information at risk:

The chilling effect of vulnerability disclosure stems from potential legal liability for reporting vulnerabilities to software vendors. While it’s often (though not always) the case that technical staff understand the problems and may work to mitigate them, things can go to hell pretty quickly once non-technical staff such as legal or public relations get involved.

In effect, the incentive model for White Hats to come forward to help the commons of software users breaks down incredibly quickly in the face of harsh penalties for individuals ‘breaking digital locks’ or found to violate terms of service, penalties that corporate vendors can (and do) leverage in order to maintain their public reputations.

Categories
Aside Links

Canada Bought $50 Million Worth of ‘Secure’ Phone Systems from the NSA

Canada Bought $50 Million Worth of ‘Secure’ Phone Systems from the NSA:

It’s certainly interesting (and newsworthy) that Canada is buying cryptographically-secure systems from the NSA, though not necessarily surprising: the NSA is recognized as a leader in this technical space and has economies of scale that could reduce the cost of the equipment. These isn’t, however, any indication whether CSEC examines or tests the devices for backdoors. Presuming that the math hasn’t been compromised, and the phones and faxes aren’t being compromised by our close ally, then there are presumably (relatively) few worries with the Canadian procurement strategy and lots of benefits.

Categories
Aside Links

Tech giants, chastened by Heartbleed, finally agree to fund OpenSSL

Tech giants, chastened by Heartbleed, finally agree to fund OpenSSL:

OpenSSL’s bare-bones operations are in stark contrast to some other open source projects that receive sponsorship from corporations relying on their code. Chief among them is probably the Linux operating system kernel, which has a foundation with multiple employees and funding from HP, IBM, Red Hat, Intel, Oracle, Google, Cisco, and many other companies. Workers at some of these firms spend large amounts of their employers’ time writing code for the Linux kernel, benefiting everyone who uses it.

That’s never been the case with OpenSSL, but the Linux Foundation wants to change that. The foundation today is announcing a three-year initiative with at least $3.9 million to help under-funded open source projects—with OpenSSL coming first. Amazon Web Services, Cisco, Dell, Facebook, Fujitsu, Google, IBM, Intel, Microsoft, NetApp, Qualcomm, Rackspace, and VMware have all pledged to commit at least $100,000 a year for at least three years to the “Core Infrastructure Initiative,” Linux Foundation Executive Director Jim Zemlin told Ars.

To be clear, the money will go to multiple open source projects—OpenSSL will get a portion of the funding but likely nowhere close to the entire $3.9 million. The initiative will identify important open source projects that need help in addition to OpenSSL.

This is really excellent news: the large companies and organizations that rely on open-source critical infrastructure projects need to (ideally) contribute back through either code contributions of financial support. Hopefully we’ll not just see money but efforts to improve and develop the code of these projects, projects which often are the hidden veins that enable contemporary Internet experiences.