Showing posts with label identity. Show all posts
Showing posts with label identity. Show all posts

Monday, October 16, 2017

So Long Stabranja


Maybe it's all this Equifax bonanza stuff going down, but I thought a post about identity and security and automated account attacks would be appropriate.

I was very excited to be able to see my facebook account hacked in a (perhaps) methodical, slow attack that has left me unable to verify my own identity, i.e., access the account. I say perhaps because, perhaps, there is no method-making person behind this; maybe it's just a program following instructions. Regardless, I got to watch it happen, and I'd like to share.

In preface, it should be noted that here at Network Address, we certainly don't present ourselves as digital liberators, that is, computer hackers. However, the world that surrounds the activities of such folk are very interesting to us. Listening to Off the Hook on 99.5 WBAI and attending the HOPE conference at the Hotel Pennsylvania are a great source of the material seen on this site. If interested yourself, please look into these, they're very much worth it (The next HOPE is summer 2018, check it out...https://hope.net/).

Back to the matter. I wonder how common this is. I plan to do some research on this dating site that requires your fb as entry. I have many facebook accounts, and many from back in the day before you had to use real names. This one is Stabranja Bones, part of a project from  almost 10 years ago, about hick-hop (at the time this was something we made up, but it's apparently a thing now) and bronix (same, although it was called Brocabulary by reddit). So I access this dating site using one of my facebook accounts, unfortunately, a favorite that I'm sad to see taken away from me. Although, I'm glad I got to see it happen firsthand.

I'm on this dating site for a couple days, that's all I need. You know how these sites work, btw - if you leave your account vacant it will be used as a bot. There's no such thing as deactivating or deleting an account. Content has value and will not go to waste, no matter what you think or want. (Remember, when things are free, you're the one giving the value, not taking it.) We used to call this a zombie I guess, like you killed the account but someone else uses the empty shell, the carcass, to impersonate a real person. This makes the site look like they have more people than they really do, which makes the prospects of finding a date better, which makes the site more attractive, which makes it more likely that you'll pay for a subscription after your free trial. (If you're new to all this, just look into the Ashley Madison scandal, "angels" and "engagers" and etc.) So, I get into the habit of at least deleting all the uploaded pictures on the dating site account, posting new picutres of people that are certainly not me, and then "deactivating" it. I did this.

About a week later, I get a message from a friend of mine, one of the few people I have connected to the hacked fb account, and a person who, unlike myself, is active on facebook and notices these things - he asks me, in real life via text message, if I changed the profile picture on the facebook page. I did not. I assume that my tooling around with the dating site via the fb site had caused some inadvertent change. In the back of my mind, because I don't trust anything, I thought there was a possiblity that everything was already compromised.

About a week or two later I check back into the dating site, just to check up on things, since I was suspicious. I see a chubby Middle Eastern man has taken the place of my profile picture (which until then was a photo of a college friend of mine in drag), and yes, the dating site is still using my profile/account, but with this new chubby Middle Eastern guy as the primary avatar. I log back into fb and delete this guy's pic, and reinstate my old profile pic.

A month goes by. I then get an email stating that my password has been changed, if I didn't do that, I should check into it. I do. They're asking me to confirm my identity. They show me some pictures of "friends" to test whether I know them or not. Hmmm. Some of these people I don't recgnize (I only had 3 friends, this was a bogus account we did for fun, after all.) I fail the test. I try again. I fail again. I don't know these people. I'm locked out of the account forever.

I go back to my email account (a second account that I use for bogus accounts etc.). Gmail separates "social" emails to another page, so I haven't been seeing the updates from fb etc. I go into this "social" page of emails and see that my fb avatar has been accumulating friends for the past month. I imagine that friend requests are sent out by the hundreds, and someone, be they either real or not, is accepting. Now I have a whole bunch of "friends" who I don't know. And if this is going on for a month, and I'm not doing anything about it, then whoever is doing this (see me giving agency to an algorithm here?) is like "great, nobody's at the wheel, let's take control." My password gets changed.

I recall some time ago, my credit card company called me about potential fraud. Have you been to Florida recently, they asked. No. That's what we thought, you have some fraudulent charges, we're going to take them off and give you a new card number. How did you know, I asked. They bought hard hats from a Home Depot in Florida, and we thought that was strange. ... I thought it was strange that they thought that was strange. Anyway, they know this stuff better than I do, because once someone has stolen your credit card number, the first thing they do is to test it; they buy some stuff and see if they get flagged. They see if there's anyone behind the wheel. If not, it's all their's.

And now Stabranja is all theirs, whoever they are.


Afterword

The next time you hear something like "Facebook has reached x million users," be aware that these are not real people. They're empty shells. Their "likes" are empty as well. Also, the next time you are deciding whether it's worth it to pay for a subscription to that dating site, many of those people are not real. That is to say, they may have been real at one time, but they are no longer; they are also empty shells. 

Post Script

etymology of Stabranja Bones:
Stabroned (brain + stoned) + ganja. Yup. Producer of Brody Lambone, hick-hop sensation.

The Semibots Are Coming
Network Address, 2015

Monday, August 7, 2017

Deanonymity Reanonymity


It is easy to expose users' secret web habits, say researchers
July 2017, BBC News

"Two German researchers say they have exposed the porn-browsing habits of a judge, a cyber-crime investigation and the drug preferences of a politician." -BBC

This isn't news. (So why am I writing about it?)

Despite what you might think, there is really no such thing as anonymous data, that is, when you have enough data.

Four data points is all it takes to identify or de-anonymize anonymous data, and this goes back to 2006. In other words, if I were to take a bunch of people and assign them serial numbers instead of their names and track every website they went to, all I would need is four websites from one particular serial number, and I would be able to identify who that individual is.

We forget so easily, but over ten years ago, AOL released a bunch of search data, and then took it back down the same day. They realized that you could pretty easily, no, very easily identify, or re-identify the people behind the search data. Then there was a competition to prove it, done on Netflix users, then Twitter users. Now, ten years later, we have already forgotten. Or perhpas, a tech writer at BBC is just looking for clicks. Or maybe he's just tyring to remind us.

There is no privacy on the internet.

On a positive note, your mom was right, you are special and unique and there's nobody else in the world exactly like you (and that's why it's so easy to re-identify your anonymized self).


Notes:
AOL subscribers sue over data leak
Ars Technica, 2006

AOL Proudly Releases Massive Amounts of Private Data
Tech Crunch, 2006

How hard is it to 'de-anonymize' cellphone data?
MIT News, 2013

Unique in the Crowd: The privacy bounds of human mobility.
Yves-Alexandre de Montjoye, César A. Hidalgo, Michel Verleysen & Vincent D. Blondel. Scientific Reports 3, Article number: 1376 (2013). doi:10.1038/srep01376

The official paper:
Paul Ohm. Broken Promises of Privacy: Responding to the Surprising Failure of Anonymization. UCLA Law Review, Vol. 57, p. 1701, 2010
U of Colorado Law Legal Studies Research Paper No. 9-12.
link

image credit: link

Sunday, June 12, 2016

Ahh Headlines



 Mar 24, 2016 report:

(Phys.org)—A female cichlid hybrid fish has been observed to have grown male reproductive organs, impregnate itself and then to have offspring, a team of researchers in the U.K. are reporting in a paper published in the ...

And in other news:

BBC News, March 2016

BBC News, March 2016

Yup.

Monday, January 19, 2015



Self-deceived individuals deceive others better
phys.org, Aug 2014

"These findings suggest that people don't always reward the most accomplished individual but rather the most self-deceived."

Over confident people can fool others into believing they are more talented than they actually are, a study has found.

These 'self-deceived' individuals could be more likely to get promotions and reach influential positions in banks and other organisations. And these people are more likely to overestimate other people's abilities and take greater risks, possibly creating problems for their organisations.

-from Newcastle University and the University of Exeter 

Sunday, January 18, 2015

When a Rose is no longer a Rose


("Rose" is her real name)


Google+ abandons need to use real names
phys.org, July 2014

Google+ apologized Tuesday and stopped requiring people to use their real names while mingling in the online social network, as it looks to gain ground on market leader Facebook.

Sunday, September 14, 2014

On Irony Ad Infinitum




Curtis Kullig, LoveMe, on the subject of intellectual property and consumerism:

…all literally my exact Love Me lifted. No permission, no compensation, no deviation from what I had made. … the only real way to perfect what I created is to launch it in larger platforms. … I had to start putting out product in different categories in order to prevent someone from taking it. The irony is that there are critics who will tell you I’m a sellout, or that I came up too quick, but really, am I just supposed to bend over and let massive brands co-opt what I created without even asking or paying?

“No way”, he says….

Juxtapoz, March 2013


Wednesday, March 6, 2013

Software

The software program who publishes papers in mathematics journals
Annalee Newitz, 1 Mar 2013, io9

Over at the Simons Foundation, Natalie Wolchover has a terrific article about how computer programs are slowly becoming part of math departments — sometimes even as colleagues. ...
[source]

what do you write? -Graffiti

Is this the first time a headline refers to software as a person in this way?

Sunday, December 30, 2012

Anagrammatic Palindromization of Fetishes


(^) visual parquet deformation
(v) textual parquet deformation

Black Fetishization of White Power
White Fetishization of Black Style

Bcalk Wtihe of Fetiazihstion Pewor
Wtihe Bcalk of Fetiazihstion Slyte

Rewop Etihw of Feitazihsiton Kcalb
Elyts Kcalb of Feitazihsiton Etihw

Elyts Kcalb of Feitazihsiton Etihw
Rewop Etihw of Feitazihsiton Kcalb

Wtihe Bcalk of Fetiazihstion Slyte
Bcalk Wtihe of Fetiazihstion Pewor

White Fetishization of Black Style
Black Fetishization of White Power

-Naomi Klein, No Logo, 1999

Board of Frozen Chi-Holders

Spiro Agnew - Grow a Penis

Anagram Maximus


Saturday, November 24, 2012

Just What You Want to Hear


To be popular with your fellow man, tell him what he wants to hear. He wants to hear about himself. So tell him about himself. But not what you know to be true about him. Oh no! Never tell him the truth. Rather, tell him what he would like to be true about himself.

“Cold Reading: How to Convince Strangers that You Know All About Them”, Ray Hyman, Skeptical Inquirer, Spring/Summer 1977.

found on p98 of Metamagical Themas
Douglas R. Hofstadter, 1985

Friday, November 23, 2012

Authentication


Laurie Lipton_Illusion-of-Control Tower_2010

Growing up in an era when [graffiti] artists were trying just as hard not to get figured out, as they were trying to get famous, and when the handwritten signature became a document-insertable jpeg, I watched the concept of authentication twitch and struggle to redefine itself in a world of increasingly evaporating identity.

I just finished reading Albert-Laszlo Barabasi’s Bursts. To grossly gloss, it says that humans are painfully predictable. If, for example, you give me access to a couple weeks of reasonable frequent mobile data, I can predict your whereabouts on any given day to an accuracy of at least 80%. Let’s also remember things like the fact that even Target can figure out you’re pregnant before you do. (Not really, but almost.)

One day I got a call from my credit card company:
“You buying some hardhats?”
“No.”
“Okay, we didn’t think so. We’re gonna open up a fraud claim and send you a new card.”
How did they know that it wasn’t me buying a couple hardhats at home depot?
People are predictable, that’s how.

Finally, this brings me to the recent Wired article,
I wonder then, what does one benefit in offering more personal data in exchange for a more robust, accurate prediction analysis that can be used by authentication services?

notes:
Kill the Password: Why a String of Characters Can’t Protect Us Anymore
Mat Honan 11.15.12

Bursts, Albert-Laszlo Barabasi, 2010

How Companies Learn Your Secrets
CHARLES DUHIGG, February 16, 2012

Gotcha

Friday, September 21, 2012

Fakebook



The Taliban Is Using Facebook Profiles Of Hot Chicks To Gather US Intelligence
Geoffrey Ingersoll | Sep. 8, 2012, 9:00 PM

The Taliban is using pictures of cute girls to lure Ausies, and Coalition Forces, into giving up secrets.

Australian defense analysts are briefing their troops to be careful on Facebook because the Taliban is using pictures of cute girls to lure Ausies, and Coalition Forces, into giving up secrets.
A Defence Analysis called "Review of Social Media And Defense," which is based almost solely on a patchwork of American Defense Department information, had this to say:
Fake profiles – media personnel and enemies create fake profiles  to gather information. For example, the Taliban have used pictures of attractive women as the front of their Facebook profiles and have befriended soldiers.
http://www.businessinsider.com/the-taliban-is-using-facebook-profiles-of-hot-chicks-to-gather-us-intelligence-2012-9#ixzz276bIfLh5

REVIEW OF SOCIAL MEDIA AND DEFENCE:
reviews into aspects of Defence and Australian Defence Force Culture
Commonwealth of Australia 2011
report by George Patterson Y&R

The Hot Girl That Just Added You On Facebook Is a Terrorist
Posted by Daniel_Stuckey on Monday, Sep 10, 2012

PART 2

New York Police Dept. issues first rules for use of social media during investigations
Rocco Parascandola
Tuesday, September 11, 2012

The NYPD has for the first time laid out rules for using social media during investigations — but critics say the guidelines raise questions about privacy issues.

The five-page memo issued by Police Commissioner Raymond Kelly last week says officers involved in probes involving social media may register their aliases with the department and use a department-issued laptop whose Internet-access card can’t be traced back to the NYPD.
http://www.nydailynews.com/new-york/new-york-police-dept-issues-rules-social-media-investigations-article-1.1157122#ixzz276d50HIz

The NYPD Gives Us Another Great Reason To Update Our Facebook Privacy Settings
Posted by Michael_Arria on Sunday, Sep 16, 2012