NSA: Please Turn off the Lights When You Leave. Nothing to See Here.

Linux Advocate Dietrich Schmitz shows how the general public can take action to truly protect their privacy using GnuPG with Evolution email. Read the details.

Mailvelope for Chrome: PGP Encrypted Email Made Easy

Linux Advocate Dietrich Schmitz officially endorses what he deems is a truly secure, easy to use PGP email encryption program. Read the details.

Step off Microsoft's License Treadmill to FOSS Linux

Linux Advocate Dietrich Schmitz reminds CIOs that XP Desktops destined for MS end of life support can be reprovisioned with FOSS Linux to run like brand new. Read how.

Bitcoin is NOT Money -- it's a Commodity

Linux Advocate shares news that the U.S. Treasury will treat Bitcoin as a Commodity 'Investment'. Read the details.

Google Drive Gets a Failing Grade on Privacy Protection

Linux Advocate Dietrich Schmitz puts out a public service privacy warning. Google Drive gets a failing grade on protecting your privacy.

Email: A Fundamentally Broken System

Email needs an overhaul. Privacy must be integrated.

Opinion

Cookie Cutter Distros Don't Cut It

Opinion

The 'Linux Inside' Stigma - It's real and it's a problem.

U.S. Patent and Trademark Office Turn a Deaf Ear

Linux Advocate Dietrich Schmitz reminds readers of a long ago failed petition by Mathematician Prof. Donald Knuth for stopping issuance of Software Patents.

Showing posts with label Yahoo. Show all posts
Showing posts with label Yahoo. Show all posts

Tuesday, January 7, 2014

Insidious Chromebook, Mega Email Preview, Smartwatches, Pirate Bay Decentralizes, CES 2014

by Dietrich Schmitz

Insidious Chromebook

Yet another major PC vendor has tossed its hat into the Chromebook ring.  Toshiba announced their very own Chromebook.  What a chuckle.  Oh, a 'Flying Chair Alert' memo has been issued at One Microsoft Way.  Be careful if you work there.  Toshiba's unit has 13 inch display, for the amazingly economical price of US$280.  What a chuckle.  I've stopped keeping count -- how many vendors are making Chromebooks now?  Enough said.



Mega Email Preview

I have attempted to reach out to Kim DotCom (born Kim Schmitz) himself in the hopes that I can have a chat with him on his views regarding Privacy.  His intent to further advocating privacy for the masses is clear: Mega Cloud ISP is now out of beta, over a year old, and provides free 50GB of Zero Knowledge Encrypted storage.  Kim DotCom continues to raise the bar and has become, despite his travails with MegaUpload, an iconic 'hero' and source of hope for obtaining true privacy on the Internet.

Most recently, news leaked onto the Internet about Mega's newest project: ZKE Encrypted Email (see screenshot below).  For those who may not grasp its significance, it is, for example, not the case that Google Gmail is encrypted.  In fact, the aged RFC specification for email doesn't even consider encryption and by virtue of its age includes defects that foster wholesale email forgery (it is child's play to insert a forged sender's email address, for example), which is why there is spam in your spam folder.  It can't be stopped without revising the specification.


A leaked screenshot of the soon-to-be-released Mega ZKE Email/Chat system

It is outrageous to contemplate that, despite the recent disclosure of the NSA having taken up camp on the inside of Google's firewall to cherry-pick the public's data (Drive, Gmail) with impunity, Google has not thus far publicly stated any intention to encrypt consumer services data.  Other ISPs, including Yahoo and Microsoft have gone on public record with statements that they intend to shore up their services with strong encryption.

On the point of ZKE, only a few cloud storage providers currently offer encryption (Mega, Wuala and SpiderOak--promulgator of ZKE and their open source ZKE developer SDK framework).  Other initiatives for encrypted email are few that support ZKE, but, most notably, Mega and SilentCircle are hot on the trail to developing a system that will ensure 100% privacy--meaning the ability to crack/decode messages will effectively become impossible.  Those following this topic will recall SilentCircle initially provided email but found the level of harassment from the government for access to be a breach of the public's privacy and so pulled the plug on that service.  Now, they have stated it will be reopened and reimplemented with ZKE in mind. 

Such luxury comes currently at a cost with, for example, Symantec Corporation (merged with PGP Corporation) providing to Corporations hosted PGP-encrypted email service.

As for the masses, the Government willingly follows 'convention' in accepting US Postal Service mailed parcels and letters in envelopes with both an expressed and implied assurance that your privacy is protected on delivery to its endpoint recipient.  Federal criminal liability is defined for any tampering with your mail even.  Yet, they have no motivation to provide the same level of expectation for privacy with your Internet email.  That stands out ever-more boldly in the backdrop of the NSA PRISM/Snowden disclosure in 2013 and punctuates all the more an unmet need to provide strong encryption on the Internet for not just commercial but consumer privacy.

In an apparent double standard, Google has feathered their own nest, by ensuring that commercial security standards are being met by providing encryption for their Google Cloud service.

Be assured, if Google take no action on this issue, I will exit using Google Gmail/Drive just as soon as Mega ZKE Email arrives.


Smart Watches

Pedestrian1: "Excuse me, Do you have the correct time?"
Pedestrian2: (Proudly brandishes his smartwatch) "Yes I can give it to you to the millisecond and in any time zone.  Oh, if you like, I can tell you the value of pi with 12 decimal places of precision!  Oh wait.  Someone is calling me on my watch."

Sound far-fetched?  Maybe a little.  But if things continue the way they are unfolding (image right: Samsung Smartwatch), we'll see the end of Swiss Watches with ruby jewel-pivot accuracy and a flood of what appear to be silicon-laden wrist watches that condense on their ASIC chipsets all manner of technology providing yet more techno-lust in a smaller, lightweight form-factor, with convergence of smart phone and any other imaginable application that can run in the current nanometer-realm.  There doesn't seem to be any constraint as memory capacity continues to increase, SSD form factor gets smaller, and ARM processors with reduced power consumption grow in power (processor arrays) and operating systems containing a Linux kernel continue to pervade all corners of our lives.


Pirate Bay Decentralizes

Let me be clear.  I am strictly against the theft of Intellectual Property or Copyrighted material.   But I do feel strongly that revision to laws on a country-by-country basis need to keep pace with the level of change occurring around us.  Real-world personal habits have changed, and technology has single-handedly changed our lives in many positive ways that could not have been imagined 50 years ago or more when the laws were originally framed and enacted.  

By virtue of how the Internet works, there is an increased desire and tendency to share.  People conduct sharing on many levels (texting, email, pictures, documents, music, video) and given how easy it can be to do, they do it often without giving any thought to the legal implications.  Generally speaking I think people know when they are doing something wrong, but I maintain, 'fair use' should come into play when doing certain kinds of sharing on the Internet.

By the same token, enforcement of laws governing IP and Copyright Ownership should not preclude consideration for if and when censorship should be applied.   Enforcement efforts have been in effect for some time.  The MPAA and RIAA have rolled out a Six Strikes and You are Out enforcement plan with the assistance of Internet Service Providers (ISP) to 'monitor' user Internet activities.  (Not all ISPs have agreed to participate in this program.  Please check with your Internet Service Provider's policy on this issue.)

This is, to my mind, wrong and smacks of a total breach to the public's right to privacy as well as an overreach of censorship.  How effective their plan has been is not clear, but many new software technologies are coming to bear to provide users with the needed tools and resources to ensure their activities remain private such as ZKE, RetroShare, Mega, Wuala and SpiderOak.

The NSA scandal of 2013 has now galvanized public awareness and catalyzed a renewal of initiatives to offer strong encryption across all Internet services for both consumer and commercial use.

The Pirate Bay has clearly been the target for long-standing IP and Copyright theft.  That cannot be disputed.  Yet, despite what happened to their founders (jailed) and what happened to MegaUpload (take down of central servers) the Pirate Bay lives on. They are now are embarking on a plan to decentralize their network to beat censorship.  At the very least, new technology that curbs inappropriate censorship is needed until the gray area between 'fair use' sharing and outright theft is clearly defined.  This is all complicated by a 'borderless' Internet which doesn't see country borders or know about treaties to offer recognition for differing treatment of existing international laws.

CES 2014

The annual Computer Electronics Show begins today, January 7 and goes through January 10.
I was an avid follower of this event going back to 2006 when many new technologies were first revealed.  In 2007 I recall the level of anticipation was palpable surrounding new technology paradigms like the Nokia N95 (I bought one) and the first generation Apple iPhone (I didn't buy one -- hate it to this very day -- Android is King).

Anyhow be tuned over the next few days for product announcements.  I'll be watching closely.

--Dietrich




Enhanced by Zemanta

Friday, December 6, 2013

Google: Don't try to change the law. ENCRYPT GMAIL/DRIVE!

by Dietrich Schmitz

Okay so Google are pushing today for changes to be made to Internet request for access to their data infrastructure by third party entities, namely, our Government.

I think this is the wrong way to go about it, and I won't sign their petition (below). (Image credit: zeroknowledgeprivacy.org)

If Google can encrypt their 'Google Cloud' product, then they should apply the same standard for the general consumer (public) of their Gmail/Drive services.

If software vendors like SpiderOak, Wuala, and now Microsoft and Yahoo can muster the requisite technology to facilitate encrypting all of consumers' private data, there is no excuse for Google not following suit.

Do the right thing Google.  ENCRYPT GMAIL/DRIVE with Zero Knowledge Encryption technology.  -- Dietrich




Enhanced by Zemanta

Wednesday, November 6, 2013

Google: You've Been Owned. Fix Your F'ing Security

by Dietrich Schmitz


Theatrics.  That's all it is.  We see blustering, cries of 'outrage' by Eric Schmidt in a public reaction of 'surprise' to the fact that the NSA penetrated their firewall and set up camp reading any and all of their 'clear text' data files with impunity.

This same company, prides itself on selling Chromebooks with an unblemished record at Pwnium 2013 of no successful hack which resulted in fully owning the ChromeOS operating system.

How is it that so much effort can be put forth to develop ChromiumOS with a sincere intent to make security a prime order of concern yet Google's data centers store data in clear text?

This isn't being discussed in any of the media stories.

The real 'top dog' priority for Google is advertising revenue.  And, they know full well that if they encrypted the public's data they could no longer parse it to exploit, mine, for advertising purposes and that would put a major choke hold on a part of their revenue stream they so cherish.

The public's trust, good faith, and right to privacy takes a 'back seat' to Google's penchant for profit.  Google is colliding directly with 'Do No Evil' as they continue to change their ways with a clear intent to take major portions of their technology base proprietary. 

That is the bottom line and there is no clear indication from them policy-wise, one way or another, as to what they plan to do at this point, if at all, other than public 'feel good' talk and expletives from Google Engineers seen in today's news.

Google.  You've been owned real bad and at the Public's expense.  It's time for you to fix your F'ing security.  I think you just might have screwed the pooch this time.

-- Dietrich
Enhanced by Zemanta

Thursday, October 31, 2013

Tyranny Will Gain a Foothold if People of Good Conscience Remain Silent

by Dietrich Schmitz

A good Friend, +Yie-Ming Chen wrote in a Google Plus post of mine today:

"All tyranny needs to gain a foothold is for people of good conscience to remain silent." - Edmund Burke 
Tyranny is at our door knocking.  Today's news included a story in the Washington Post NSA Infiltrates links to Google, Yahoo, worldwide, Snowden documents say.  (Image credit: Washington Post)

Another revelation has been made that the NSA have been camping out on the inside of the Google cloud firewall, cherry picking data -- yours -- like taking candy from a baby -- the method for how the NSA exploit to break through the front-end SSL server is documented in slides like the one shown above.

Sadly, the data fest has been going on for quite some time and Google and Yahoo officially disclaim any knowledge that such activities have been occurring.

It's too bad because the entire cloud behind the firewall has been 'clear text' as shown in the above slide, which means your data isn't encrypted and directly human readable.

Why hasn't Google taken steps to protect your Drive data with encryption?

The truth of the matter is: MONEY

Advertising revenue is obtained by parsing your documents and positioning adverts in the gutter margins as users of Google services like Drive and Gmail go about their daily business.  If Google were to encrypt your data, then they could not read it and run adverts any more.   

It is outrageous that Google chose not to take action because of this and I would suspect the same pertains for Yahoo.

This is a major error of negligence and abrogation of responsibility on the part of Google to protect the public's right to privacy.

The technology has been available right along which is now routinely used by other cloud services like SpiderOak, Wuala, and Kim Dot Com's Mega to encrypt the entire data stream of data space in the cloud.  It's not difficult to implement and even SpiderOak have now offered their own software framework, Crypton.io, for Developers to implement Zero-Knowledge Encryption (ZKE) at any Cloud ISP.

This is no longer an option.  ZKE should be considered a mandate and, as such, consumers and businesses should insist upon having it or boycott using the respective Cloud ISP's services.  If we all insist on it, we will have power in numbers and can have an effect on the outcome hopefully in a positive way.

The benefit to the user of rented Cloud data space employing ZKE is that all data stored in the Cloud is first encrypted locally (in the memory space of the user's PC) and a private key is maintained locally by the user not physically present on the Cloud data drive.  This makes the data on the Cloud transparent and as such the ISP will have Zero Knowledge of what is being stored other than an encrypted byte stream written to a block level drive.

With ZKE for a third party to request access would then require their serving the owner of said data with a warrant before viewing the personal and privately protected information.  Good citizens presented with a warrant will comply and unlock their data if the warrant is justified by a Court Judge as having 'probable cause' for issuance.  That has always been historically the case up to 9/11 but with the Patriot Act, the erosion of the U.S. Constitution was begun.

Today, some twelve years hence, the degree to which the law has been disregarded is allowing unobstructed intrusion into all corners of our private electronic communications.

I am drawing the line here.  Google must take steps immediately to adopt ZKE for all of their media storage used by consumers and businesses or I will no longer support and use any of their services whatsoever.

They have two weeks to come up with a clear public plan to protect the public's data from unwarranted access or I will end it.  Boycott Google Cloud services if they fail to act.

 -- Dietrich 
Enhanced by Zemanta