Apple and their form of privacy

Apple's smug new iPhone ad says privacy matters, just ...

Ummmm right…

I get Apple are more private about data than others like Google (which pings Android phones so much people are suing for data charges) but there is something about misplaced trust with Apple which always bugs me. These latest adverts and recent news stories say it all.

Downloads outage down issues which is all around Apples Gatekeeper privacy and Apple’s latest OS update Big sur network traffic bypass.

Of course this is all clear reasons why I’m very much in the open source camp. Maybe I won’t understand the code, but someone will and can inspect it or track down the issue without signing an NDA. I urge for people to not blindly trust. Always look out for open code, zero-knowledge security, no logging, transparency, etc

Amazon halo…be afraid be very afraid

There is so much I wanted to say about the Amazon Halo health/fitness tracker. The Twit.tv video above pretty much sums up my thoughts. I haven’t read through the halo privacy policy yet, but others are picking bit out already.

Amazon Halo privacy concerns

Wherever there are body scans, always-on microphones and a tech giant in the same service, there’s bound to be security concerns. Amazon knows this, and has already outlined what privacy will look like for future Halo users.

Halo health data is encrypted in transit and in the cloud, and sensitive data, like body scan images, are deleted once processed. Meanwhile, voice analysis is processed entirely on the user’s smartphone and deleted after. Nothing is recorded for playback — users can’t even listen to their own speech samples.

All Amazon Halo data can be managed and deleted in the Halo app. Your Halo account is also separate from your Amazon Prime one, so anyone you share your Prime account with won’t be able to access your private health information.

This for me is one of the things people in the Quantified Self movement were always worried about.

Do you trust Amazon with this much personal data?
Whats the actual pay off?
Is it all actually worth it?

Then you have to ask the question what makes it different from other quantified self devices and systems?

Signal what are you up to?

I love Signal and never used Whatsapp because of many reasons included in this great opinion piece. Its gotten better and better but the recent pin number is a worry. I’m not the only one.

“Notably, things we don’t have stored include anything about a user’s contacts (such as the contacts themselves, a hash of the contacts, any other derivative contact information), anything about a user’s groups (such as how many groups a user is in, which groups a user is in, the membership lists of a user’s groups), or any records of who a user has been communicating with,” Signal wrote in 2016.

That, according to critics, has now changed.

“They should have a dumb network that knows nothing because it can’t be compromised then,” The Grugq told Motherboard. “[Having contacts] is a lot. It isn’t messages, sure. But I don’t like it. I don’t want them to have anything. Make the networks dumb and the clients smart.”

I do understand why they have done it, but I don’t know where its going next. Marlnspike (head dev of Signal) replies.

Marlinspike defended the decision to enable PINs and give users a way to migrate to a new device and keep certain data, and will increase the security of users’ metadata, “new features Signal users have been asking for.”

“The purpose of PINs is to enable upcoming features like communicating without sharing your phone number. When that is released, your Signal contacts won’t be able to live in the address book on your phone anymore, since they may not have phone numbers associated with them,” Marlinspike told Motherboard. “For most users, this also increases the security of their metadata. Most people’s address book is syncing with Google or Apple, so this change will prevent Google and Apple from having access to your Signal contacts.”

Smartphone use
Photo by Gilles Lambert on Unsplash

The changes Signal has made show how there can be a tension between messenger usability and feature set and security. It’s too early to say whether you should stop using the messenger. For most users’ threat models, it’s still one of the best options. But one of the key things that set Signal apart—that it collects almost no information about its users, appears to be changing.

Convenience is the enemy of security and I would say privacy. I wouldn’t be surprised if signal gets forked.

It was always clear to me Twitter direct messages was never secure in anyway, hence why I tried to move private conversations over to another medium. If thats not email or signal what else? Recently I have been looking at a couple others…

Session which is decentralised messaging and Criptext, which is actually secure email. Both need work but have decent security.

The Houseparty is over, time for the GDPR to kick in the front door?

houseparty gdpr request email

I requested my GDPR personal data from Houseparty/Epic games over a 2 months ago when I signed up under my spam email and slight social pressure from friends. I read the privacy policy and almost spat out my tea.

However I found I could use houseparty in a clean browser (chromium) – app.houseparty.com. as there was absolutely no way I was going to install the app on my pixel phone. After trying to play a game with friend I found the video worked but not the actual game.

As we moved on to using boardgamearena.com. I decided I wanted to delete my account and got interested to know how much data they had collected about me in my short time in houseparty.

Outcomes my GDPR request, I send it to data-requests@lifeonair.com and nothing. I resend it to support@houseparty.com and get my response. Back and forth then finally…

Houseparty Support

May 08, 2020, 20:46 +0100

Hello Ian,

Thank you for your response.

I’m glad that you’ve reached us regarding your request. We received your data request. Our team is working on pulling the data, and you will receive your data within 30 days.

Please feel free to contact us if you need any further assistance.

Regards,
Romeo Tango

As you see can see the date of May 8th was 34 days ago and yes I get Covid19 but I’m not expecting the much data back. Unless there is a ton coming my way?

Either way I’m annoyed at being messed around at the start and also them not taking it seriously. I’m still not convinced Romeo Tango is real to be honest.

ICO submission

So enough, I’ll let the ICO deal with it all.

 

I lost all trust for Zoom yesterday…

British PM on Zoom
Wonder how many people have tried to dial into that zoom id?

Yesterday I was on a zoom call which was hijacked or zoombombed with something not just horrible but totally illegal. Because of this I have pretty much lost all trust in zoom.

This is of course very difficult as its what we use at work and of course being in the middle of the covid19 lockdown, makes things tricky. Because of this, I’m going to still use it but with much more caution and I’m going to be a lot more forceful about the hosting side of it.

Its clear war-dialers for public Zoom meetings is so easy and well used by inscrutable groups of people. Zoom could make sharable links much more difficult to war dial, similar to the way Google docs uses combinations of characters and numbers to make a much longer url, a lot harder to war-dial.

The defaults of Zoom, is setup for a semi trusted corporate environment. I understand the covid-19 pandemic changed everything but there has been many updates and only now is the defaults only just safe. Their share prices have rocketed but they are only now focused on security ahead of more features?

Their idea of end to end encryption is a total dump on top of the security findings saying some calls are being routed via China.. Today they announce you can choose your routing but you need to pay for it. More governments and companies are blocking zoom because they just don’t trust it.

Likewise neither do I… but I will use it… with caution.

I have been thinking about an equivalent, and thought about two.

  1. I lost trust in Facebook a long while ago but still use it for volleyball events and the occasional post about something I feel could be important for friends, family and the public who don’t read my blog (as its posted on the internet already, I post publicly adopting the indieweb Posse approach, much to the surprise of some friends). For example I posted what happened on zoom yesterday there today.
    Facebook was hardly trustworthy to start with and over and over again they took the living daylights with our data.
  2. There was a point when Windows Vista pushed as the step/edition of Windows XP and I didn’t like what Microsoft had done to it. To be fair I didn’t trust them and saw shadows of where things were heading. So I switched to Ubuntu.I know the new Microsoft is quite different of course but the damage was done.

If you are hosting a Zoom call, please do lock it down theres a number of guides to help including this one.

Dropping Rescuetime for ActivityWatch

Activity Watch logo

I tend to weigh up different systems and applications I use every once in a while. Especially weighing up the benefits to me.

One such application is Rescue time.

I used it in the past and over the last few months reinstalled it again. However this time I tried to automate the reports out of the free account and pretty much failed. The only way I could really do it is if I paid for the pro account at the cost of (a discounted) $6.75 per month.

So enough I thought… A little look around alternative to and decided to give Activity Watch a try.

ActivityWatch is an app that automatically tracks how you spend time on your devices.

It is open sourceprivacy-firstcross-platform, and a great alternative to services like RescueTime, ManicTime, and WakaTime.

It can help you keep track of time spent on different projects, kick bad screen habits, or just understand how you spend your time.

Its pretty good and doesn’t drain my laptop while watching my laptop. Of course being local and under my control only, I don’t really need to worry so much about whats collected. You can of course limit things as you go, turn off tracking or just delete the data any time.

I have it on my Dell XPS laptop and on my work phone and its good except one thing. Currently there is no sync server, so each device has its own server. But they are working on this… Once they do, I’ll likely install it on my server and put the client on more of my devices.

The other thing I’m hoping for is to see more use of the stopwatch activity watch bucket (buckets are the pools of data collected). Since Project hamster is currently being rethought and I like to track my work progress alongside my activity.

As a whole the project has a lot of potential and worth the wait I hope for the features expressed above.

Public Service Internet monthly newsletter (Oct 2019)

Carole Cadwalladr & Paul-Olivier Dehaye's deep dive into the great hackCarole Cadwalladr & Paul-Olivier Dehaye's deep dive into the great hack

We live in incredible times with such possibilities that is clear. Although its easily dismissed by looking down at our feet or at the endless twitter fighting.

To quote Buckminster Fuller “You never change things by fighting the existing reality. To change something, build a new model that makes the existing model obsolete.

You are seeing aspects of this happening with Matt Mullenweg’s comments about a open and diverse web after buying tumblr.

Don’t forget if you find this useful, you will find “Public Spaces, Private Data: can we build a better internet?” at the RSA London on 21st October  2019, right up your street.

 

Watching the labrats scurrying away

Ian thinks: Recently read Labrats book after seeing Dan Lyons at Thinking Digital. Its quite a raw insider view on silicon valley culture, the laughable and the horrific sides in equal lashings.

The Great Hack Workshop from Mydata 2019

Ian thinks: This was one of the highlights of Mydata 2019. Carole Cadwalladr & Paul-Olivier Dehaye’s deep dive into the build up to the great hack was fascinating. Lots of useful resources were revealed.

Are Boris Johnson’s PR People Manipulating Google Search?

Ian thinks: True or not, our dependence on a single search engine/service makes any potential manipulating even more impactful.

Ted Nelson on Hypertext, Douglas Englebart and Xanadu

Ian thinks: Its always amazing to see pioneers who narrowly missed out pushing concepts which were too early, but could come back.

Look out here comes the hyperledgers

Ian thinks: More ledger/blockchain projects to power your projects than you can shake a stick at. Very happy at least some are open-source.

ReasonTV’s look at the Decentralised web

Ian thinks: I was expecting something light touch but having Cory Doctorow mainly interviewed means its got some depth.

Etiquette and privacy in the age of IoT

Ian thinks: Etiquette tends to be forgotten in the advancement of  technology. I don’t consider it rude to shut off a Alexa, I’m sure others will disagree.

Tipping etiquette set by user interface

Ian thinks: Talking about etiquette, very interesting to see norms set by user interface design decisions. Obviously set to benefit the company but its stuck now.

Exploiting technology or exploited by technology?

Ian thinks: Curious tale, but it does raise a question about digital access and backups. Least we forget about power and when things go technically wrong.

Public Service Internet monthly newsletter (Sept 2019)

johnny mnemonic

We live in incredible times with such possibilities that is clear. Although its easily dismissed by looking down at our feet or watch how democracy is being gamed and broken. To quote Buckminster Fuller “You never change things by fighting the existing reality. To change something, build a new model that makes the existing model obsolete.

With a focus on new models in business, technology, society, policy, processes, etc. I present my public service internet newsletter.

You are seeing aspects of this happening as people rethink public transport.

Don’t forget if you find this useful, you will find “Public Spaces, Private Data: can we build a better internet?” at the RSA London on 21st October  2019, right up your street.

Reflections on capitalism gone wild system

Ian thinks: Rushkoff’s monologue at Betaworks Studio is breathless, funny, tragic and worth every minute of your time.

Ghosts in the smart home

Ian thinks: Lancaster University’s short about smart homes, is a design fiction which is fun, informative and enjoyable to watch. Sure some the living room of the future and petras workstream had a influence?

Black lives matter’s alternative systems

Ian thinks: Theres a question later about the media, Alicia talks about creating their own systems not just relying on what already exists.

Surveillance systems head to head 

Ian thinks: Cambridge Analytica’s whistle blower and Russian investigative journalist, go head to head discussing surveillance capitalism and government surveillance.

Suicide Is an epidemic and therapy apps are not helping

Ian thinks: As we turn to apps for everything a thoughtful look at therapy apps market good and bad. Theres not an app for everything.

The real johnny mnemonic (contains surgery pictures)

Ian thinks: Ever since Quantified Self people started embedding NFC under the skin, I wondered how far it would go. Perfect name for the software

We are not ready, privacy in 2019

Ian thinks: Really good list of the leaks, abuses, dumps and thoughts if we are ready for even more? Question is how many more before the end of year?

Emotional and erotic intelligence for an enlighten future (NSFW)

Ian thinks: Although a talk about sextech is uncomfortable for people, the subject of intimacy, human connection and self reflection are so much more important than our personal discomfort.

Danilo Milovanović public space interventions

Ian thinks: Excellent to see more thoughtful playful artistic interventions in the public realm.

Facebook cafe with free drinks and privacy check-ups?

https://twitter.com/wearesorryfor/status/1162346869017763853

When I saw Jasmine’s reply to Claires tweet. I thought exactly the same thing. Its the ethical dilemma cafe, only 5 years out too late.

Facebook is looking to take the initiative in the social media privacy debate by opening a network of pop-up cafes around the UK. Each will offer patrons free drinks and a privacy checkup, to help assuage consumer concerns about their privacy online.

Facebook Café will run from 28 August to 5 September in a bid to encourage Britons to get on top of their digital footprint, helped along by free-flowing caffeine.

One of these will be located within The Attendant on Great Eastern Street, London, in response to surveys indicating that 27% of Londoners have no idea how to personalise their social media privacy parameters.

Free coffee (what kind) and teas in exchange for? Privacy advice from Facebook, Wifi snooping like most, a honeypot, or maybe a bit of social engineering from FB staff (Scientology style)?

Is it worth it? I very much doubt it but it would be fun to mess with the FB cafe staff and systems. Don’t you think?

What is Web 3.0 and Why Do We Need It?

Web 3, Parity, Polkadot, Substrate, ipfs, blockchain? Wtf?

While visiting Republica 2019 and writing my presentation about it, I was trying to make sense of the deeper decentralised web stack. Jutta Steiner gave a talk at Republica but I was a little lost in what she was talking about. It was clear it was important but I was lost in the terms.

Watching her talk from tech open air (TOA19) was a lot clearer.

She also reminded me about the web3 summit, which I wish I could attend but always felt like I might not be quite the right person for it. I look forward to hearing what comes out of it however because its clear as Jutta says

…The first time I interacted with the web like everything was open and somehow that was the the perception like we now have this great tool and sort of thought like it’s not this these closed intranets. But it’s the information superhighway we can do whatever we want but what happened really over the 30 or so years afterwards was we replicated or built a ton of intermediaries that basically sit between us and anybody we want to interact on the with on the web online, be that through what’s that when we text to someone through Facebook, venmo, whatever you use you buy anything there’s always an intermediary for something that really should be a general p2p interaction. So the problem with this really is what’s underneath this and what led to this mass these mass centralization and of power and data in the hands of very few people is the fact that we had to do this in a very centralized way because this is just how the Internet technologies of where to work so we have an underlying architecture with centralized servers where all the data is gathered because of network effect the power accumulates and accumulates, and this is a very fraught way of doing things because you have a central point of failure and that was massively exposed by the Snowden revelations I mean partly because also backdoors are built into it but partly because it’s it’s centralized architecture…

Clear reason why web 3, I think…

#web30: The world wide web at 30 years old

We owe a lot to Sir Tim Berners-Lee on the 30th Anniversary of the web.

Tim Berners-Lee helped invent the world wide web 30 years ago. And he has consistently pointed out that the original dream that gave rise to it is under threat.

It is exactly 30 years since Sir Tim submitted a paper to his colleagues at CERN, suggesting a way of sharing data across networks, under the title “Information Management: A Proposal”. The humble title belies the importance of what was contained inside, which included a complete sketch for the networked information system that would on to become the internet we know today.

But its really important to think about the next 30 years.

Surveillance capitalism and governmental/state control are hot topics which very much threaten the fabric of the web. But so does our use of the web and the way we treat each other.

I had a really good 10min talk with Sir Tim Berners-Lee during the last Mozilla Festival, while talking about Solid, Databox and data trust. What got me as we talked, was ultimately we were talking about power and where it lies. Power in the hands of governments (Chinese model) , corporations (American model) or people? (could be the European model?)

I think remembering their are humans, not eyeballs, not lefties/rightwingers, etc is so important. Lets celebrate the people of the web!

https://twitter.com/whynotadoc/status/1105400124447039489

Airbnb illegal audio monitoring?

Airbnb monitoring warning

Me and my partner decided on Airbnb for our trip to Barcelona. We found one  and booked it. Generally the flat was ok,

However there was a warning on the kitchen door, stating they are listening for noise 24 hours a day and will cancel bookings if there is loud noise. Looking around I think the device is this thing…?

Airbnb monitoring warning

It certainly put a terrible taste in our mouth and made us feel uncomfortable. Although we didn’t complain straight away and by the time we thought about it, the internet connection was down and if its really connected and not a poor joke; it was no longer going to work. Didn’t cause the host(s) to come and find out what was wrong, even with us complaining about the lack of internet (I debugged it as much as I could, but ultimately we had European roaming data and wasn’t in the flat that much)

This has to be a breach of privacy and I’ve finally complained to Airbnb. Especially after rethinking and re-reading things like this.

Update – Thursday 13th Sept

Since my tweets/toots and this blog post. I had quite a lot of people and journalists get in touch… But I still have seen nothing from Airbnb or the host. So I decided to take one of the journalists up on their offer in a form of social justice. No idea how what I wrote will come across or be edited but as I was seeking out the legal ramifications of what the host had done, I saw this on the Airbnb help site…

Rules for hosts
If you’re a host and you have any type of surveillance device in or around a listing, even if it’s not turned on or hooked up, we require that you indicate its presence in your House Rules. We also require you to disclose if an active recording is taking place. If a host discloses the device after booking, Airbnb will allow the guest to cancel the reservation and receive a refund. Host cancellation penalties may apply.

With that I rewrote to Airbnb and Airbnbhelp to demand a refund on top of everything else I previously complained about.

Sure to update everyone once I hear something….

Update – Friday 15th Sept

I was contacted by Airbnb by phone, the woman ran through a few questions and we talked about what happened again. She agreed this was clearly a breach of the Airbnb terms and could see the listening device and the warning in a few of the photos (as like me, knew what to look for). She said they would block/ban that listing which they have done. They also issued a refund to me and my partner, which is great news as our un-comfortableness certainly had a slight affect on the holiday in Barcelona.

Personally I’m glad I found the Airbnb term above, as that drove things along much quicker. Previous to that, it seemed not a lot was being done?

In our conversation, it was worth noting an Alexa, Google Home, Baby monitors, etc would count as listening devices which must be declared upfront before the guest books.

From Airbnb…

To summarize, we will follow up and investigate the host’s account following your report of a surveillance device in the listing. We take these reports very seriously, once again, thank you for bringing this issue to our attention. Your participation helps keep Airbnb a safe and trusted community.

The realm of third-party trackers on Android

Luman android root cert

I was excited to learn about Lumen Privacy Monitor, as I’ve always wondered about the apps I have installed even when I have restricted the permissions wanted from the installed app.

New research co-authored by Mozilla Fellow Rishab Nithyanand explores just this: The opaque realm of third-party trackers and what they know about us. The research is titled “Apps, Trackers, Privacy, and Regulators: A Global Study of the Mobile Tracking Ecosystem,” and is authored by researchers at Stony Brook University, Data & Society, IMDEA Networks, ICSI, Princeton University, Corelight, and the University of Massachusetts Amherst.

“This is the start of a long project to uncover all the hidden data collection and data dissemination practices on the internet,” Nithyanand explains.

“There’s a huge lack of transparency around how mobile applications behave,” adds Narseo Vallina-Rodriguez, a co-author and researcher at ICSI. “People install software, but don’t know what that software is doing.”

The paper’s introduction lays out a troubling scenario: “Third-party services inherit the set of application permissions requested by the host app, allowing them access to a wealth of valuable user data, often beyond what they need to provide the expected service.”

To study this scenario, the researchers used Lumen Privacy Monitor, an Android app they built themselves over a two-year period.

So I installed it just to see what was going on with my Android devices. But there is a problem… Best summed up in this comment from Wcat.

Not open source? TLS interception? Before you install this stop and think about TLS interception. “Those who would trade privacy for security deserve neither.”

Luman asks for permissions to install its own root certificate, and this deeply worries me. TLS inception isn’t a trivial thing to be honest, I know its needed but it had me questioning how I really want to monitor the apps? Also if I remove the app, will the certificate be removed too/how would I know?

Right now, I’m keeping an eye on the app but haven’t installed the root cert yet.