Categories
Writing

I need to create responses to the above security questions before I can purchase items through Apple’s digital stores. The problem: I actually don’t know the (legitimate/real) answers to any of the questions.

Admittedly the best security procedure, in the face of any vendor authentication questions, is to produce garbage/unrelated responses to any authentication questions that vendors ask. This said, it’s a a bit insane that I have to do this for the questions Apple has provided. Now, is this a problem that most people can overcome? Of course. They just write in answers and (somewhere) they write down their responses. I actually could use 1Password for this, a terrific password and identity manager that I highly recommend. This said, I’m not going to bother. Purchasing the $20 piece of software just isn’t worth the effort for me: in effect, Apple has succeeded in dissuading me from making an impulse purchase. That’s really not great for the business of app developers (Apple, really, doesn’t care that much given the relative amount that the app store contributes to their overall yearly profits).

You might wonder why these questions are being asked. I suspect they’re largely in response to the Mat Honan hack. In short, a Wired reporter’s Apple, Amazon, Twitter, and Google accounts were hacked so a third-party could masquerade as Mat on Twitter. This led to a ridiculous level of criticism in the press concerning how Apple authenticated users’ identities. I have no doubt that these questions – again, pictured above – are largely meant to better authenticate users and thus avoid identity fraud.

The problem of authentication fraud can be devilishly hard for companies to address. In the case of Apple, there is no option for the user to generate their own questions and responses. This might be seen as good security amongst ‘professionals’ – it prevents really, really crappy questions and easily found responses – but it creates an incredibly poor user experience. While writing down passwords isn’t the horrific nightmare scenario that some security analysts declare, expecting people to find those responses when they’re in trouble – such as their accounts have been hacked – will meet mixed results at best. Further, given how other companies tend to follow Apple’s lead(s) it’s only a matter of time until more and more (less security conscious) companies adopt similar or identical security questions/answers. Such adoptions will limit the relative novelty of Apple’s authentication questions and thus reduce their capability to genuinely authenticate users’ identities. Consequently, such questions (in the short and long terms) will likely just leave its customers frustrated.

Ultimately, this kind of authentication really is less than ideal; more nuanced and (to the user) transparent analytics protocols to detect aberrant behaviours and then recover accounts would be far, far superior to what Apple is presently rolling out. Hopefully it doesn’t take further authentication failures, on Apple’s part, for them to realize the error of their ways and correct it.

Categories
Links

Dispelling Some Mistruths Surrounding Lawful Access

David Fraser has a terrific breakdown of the Canadian Association of Chiefs of Police’s recent argument for lawful access legislation. If you’re Canadian you should definitely check out what he has to say.

Categories
Links Writing

Question to SCOTUS: Can we even bring legal action over warrantless spying?

The EFF continues it’s long slog to challenge the US government’s warrantless wiretapping. At this point a series of cases have been dismissed, though the Supreme Court is now hearing a case to ascertain whether those who have been affected by the dragnet surveillance – lawyers, journalists, human rights lawyers – can challenge the statute given that it “prevents them from doing their job without taking substantial measures when communicating to overseas witnesses, sources and clients.”

This is an incredibly serious case. The outcome will not decide the legality of the statute itself but just whether it can be challenged. By anyone. A dismissal of the case – that is, a decision declaring that no one clearly has standing to challenge the statute – would prevent the existing intelligence operations from ever being challenged so long as the government avoids bringing warrantlessly-accessed data into a trial as evidence.

Watch this case; if it goes sideways then the American government will have (effectively) been given license by the highest court in the land to surveil Americans, without warrant, and without an effective means to prevent the surveillance.

Categories
Quotations

2012.10.30

It’s very complicated. It’s very cumbersome. There’s a lot of numbers involved with it.

Gov. Nikki Haley’s reason for why social security numbers stolen by a hacker weren’t encrypted
Categories
Links

While at first blush Lincoln Alexander has little to do with technology, the words that we exchanged when I received my first degree from Guelph continue to shape my engagement with technology. He also, in just a few sentences, gave me some of the best professional advice I’ve ever received in my life. Though our exchange at convocation wasn’t anywhere close to my first time speaking with Lincoln, nor would it be the last, it was the deepest and most significant. Alastair’s ‘goodbye’ captures my thoughts about Lincoln in as sincere a way as I’ve ever seen; I highly recommend watching Alastair’s address.

Categories
Videos

The many UI nightmares associated with Windows 8

Categories
Links

iMessage and ‘Secure’ Communications

Matthew Green has a good piece that discusses some of the security concerns around iMessage. Specifically he speaks to how, despite Apple’s assurances that it employs “secure end-to-end encryption,” the company still hasn’t properly explained how its encryption processes are established or deployed. Green does a good job explaining these concerns for a very non-technical audience. Highly recommended, especially if you happen to be using iMessage.

Categories
Links

When It Comes to Human Rights, There Are No Online Security Shortcuts

Patrick Ball has a good and highly accessible article over on Wired about why certain means of securing communications are problematic. It’s highly recommended. Rather than leave you with the overview of “this is what is said and why it’s important,” let me leave you with a key quotation from the article that (to my mind) nicely speaks to the author’s general mindset: “Good security is about not trusting people. It’s about studying math and software and assuring that the program cannot be turned to bad intent.”

Categories
Quotations

2012.8.13

Whenever we feel the urge to say “human values” or “social values,” perhaps we should immediately substitute a phrase closer to our intended meaning. If we mean “motives,” then let’s talk about them. If we mean “consumer preferences,” then say so. If we mean “the norms of a particular group in society,” then talk about those. If we mean “general moral principles that ought to guide our action,” then explore, define, and defend those principles. What we will find, I believe, is that these more specific topics are an improvement over the vague label, and that once we’ve begun using them, the word “values” can never again substitute meaningfully for more substantial terms and questions.

Langdon Winner, The Whale and the Reactor
Categories
Aside

Data Never Sleeps

How much media is generated every minute