nexa
By thread
nexa@server-nexa.polito.it
By month
Messages by month
- ----- 2026 -----
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
June 2020
- 35 participants
- 210 messages
Re: [nexa] Cloud act e sovranità dei dati
by Giacomo Tesio
Ma che bello pensare che lo zio Sam proteggerà gli interessi delle nazioni
straniere dalla propria polizia!
Non vi sentite già meglio?
Viene quasi voglia di dimenticarsi di Echelon, del controllo statunitense
sul sistema DNS rafforzato (in non della privacy!) dall'introduzione del
DNS-over-HTTPS, al controllo statunitense degli exit mode Tor, alla
profilazione psicologica tramite Analytics...
Insomma, con il Cloud Act potrete dormire tutti tranquilli ed asciutti, che
lo zio Sam vi protegge... da sé stesso!
Peraltro propaganda come questa verrà accolta con favore e sollievo da
moltissime aziende che la useranno per lavarsene le mani.
Un po' come al Nord anni fa accoglievano con sollievo le aziende della
Camorra che "smaltivano i rifiuti tossici" sotterrandoli sotto le scuole:
sulla carta era tutto "CLEAN".
Già oggi viene citata la locazione dei dati in Europa come garanzia di
sicurezza e privacy.
Quando leggo queste sciocchezze mi chiedo se chi le scrive è sommamente
incompetente o in mala fede.
Ed il fatto che talvolta sieda su cattedre universitarie non facilita la
risposta.
Quanti secondi ci vogliono a trasferire dati interessanti oltre oceano
senza cancellarli dai server europei?
E come potrebbe accorgersene u funzionario governativo?
Affidarsi a leggi che impongono promesse da marinaio per tutelare i
cittadini^W governi^W^W la libertà^W democrazia^W privacy è come scrivere
una legge che impone ai fiumi di risalire le montagne.
È ridicolo.
Eppure è... la norma.
Giacomo
June 8, 2020
Sono secoli che l'automazione bara
by Antonio Casilli
Articolo davvero ben fatto (si tratta in realtà di un book review essay) di Edward Jones-Imhotep apparso nella rivista universitaria History and Technology. Attraverso un'analisi della "metafisica della agency" degli automi del XVIII secolo, riesce a dire cose molto interessanti sui pretesi exploits dell'IA contemporanea e sul miraggio del lights-out manufacturing (o fabbrica senza operai).
The ghost factories: histories of automata and artificial life
Edward Jones-Imhotep
20 May 2020
https://tandfonline.com/doi/full/10.1080/07341512.2020.1757972
Cheers,
--a
--
Antonio A. Casilli
Professor, Telecom Paris, Institut Polytechnique de Paris
Member, Interdisciplinary Institute for Innovation (i3 UMR 9217 CNRS)
Associate Member, LACI-IIAC (EHESS)
Faculty Fellow, Nexa Center for Internet & Society
*We respect your right to disconnect. This email send time is due to my own workflow efficiency. You are in no obligation to take action or reply to it outside your office hours.*
June 8, 2020
Cloud act e sovranità dei dati
by Diego Giorio
https://www.corrierecomunicazioni.it/digital-economy/cloud/tutta-la-verita-…
Buona settimana a tutti
[https://d110erj175o600.cloudfront.net/wp-content/uploads/2020/06/daskal-.jpg]<https://www.corrierecomunicazioni.it/digital-economy/cloud/tutta-la-verita-…>
Tutta la verità sul Cloud Act, la legge che solleva timori sulla sovranità dei dati - CorCom<https://www.corrierecomunicazioni.it/digital-economy/cloud/tutta-la-verita-…>
In un contributo esclusivo per CorCom, Jennifer Daskal, docente presso l'American University Washington College of Law spiega nel dettaglio ambiti di applicazioni e limiti della norma. "Non è ...
www.corrierecomunicazioni.it
June 8, 2020
Re: [nexa] Covid-19 tracking apps, or: how to deal with a pandemic most unsuccessfully - about:intel
by Giacomo Tesio
Articolo molto lucido.
Ho letto molti "esperti" emozionarsi per la qualità della codebase di
Immuni, confrontandola con il fallimento di StopCovid ma perdendo
completamente di vista la questione complessiva.
Le conclusioni però sono estremamente ingenue.
Visto che non si può dimostrare che tutte le rappresentazioni di
un'informazione sono state distrutte (ovvero tutte le copie dei dati che la
rappresentano, cancellate), non c'è alcun modo di garantire che a fine
epidemia verranno cancellati.
Non è possibile alcuna supervisione reale dei processi.
Non è possibile impedire che in futuro quei dati vengano de-anonimizzati.
Non è nemmeno possibile garantire che rimangano esclusivamente nelle mani
dello Stato, sia per la complessità della sua organizzazione (che, ad
esempio, è notoriamente infiltrata dalla criminalità organizzata), sia
talvolta per i limiti tecnologici.
On Sunday, 7 June 2020, Alberto Cammozzo <ac+nexa(a)zeromx.net> wrote:
> In Europe, it will be difficult to find
> national solutions to limit the power of the transnational guild of
> digital technology professionals.
In Italia, ci abbiamo mai provato?
> Our greatest hope may come from
> listening seriously to the warnings of constitutional and human rights
> lawyers
Non me ne vogliano gli avvocati in lista, ma in questo caso hanno preso una
enorme cantonata aprendo anche solo alla possibilità che un App di
tracciamento automatico di massa potesse essere utile.
D'altronde è stato un errore condiviso con molti tecnici.
Per quel che conta, fu questa la ragione principale per cui scelsi di non
firmare, a suo tempo, l'appello di Nexa, pur apprezzando moltissimo gli
autori.
L'informatica può fare molto per la medicina. Ma non così.
Giacomo
June 7, 2020
Covid-19 tracking apps, or: how to deal with a pandemic most unsuccessfully - about:intel
by Alberto Cammozzo
Red herring, anche per Didier Bigo.
<https://aboutintel.eu/covid-digital-tracking/>
[...]
Unity in the folly of technological solutionism
Despite the diversity of situations in Europe — we have clearly seen
structural differences in terms of public health and economic robustness
— a kind of consensus has emerged. It revolves around a form of
“technological solutionism” and presents digital tracing applications as
a way to overcome all the problems this pandemic has tossed at us. In
his book on the moral consequences of digital technologies, Morozov
already brought to light this shared “folly” of technological
solutionism. This is the belief that the digital supersedes the physical
and that you can solve every problem with a click.
In the field of security, ranging from sanitary emergencies to defence
and police, a similar belief has emerged. I have previously shown this
to be a product of a transnational guild of digital technology
professionals involved in security matters and of their influence over
power circles to manage border controls, security, and interoperability.
As this group — which includes strategic communications and advertising
companies — is involved at the highest level of government in different
EU countries, its influence on managing the crisis ends up superseding
the influence of health professionals. In the absence of a vaccine, they
turned social acceptance of the confinement measures (and their
rebranding of it) into something radically new. The priority
communicated in the media seemed to be that the positive news of a
digital solution should make up for the bad news of high death tolls,
and so the countries worst hit by the pandemic were most keen on
counterbalancing their poor performance with a brand-new and ever-so
promising app.
A collective belief that the internet, algorithms, and artificial
intelligence will beat the virus
Hundreds of proposals came from all over the world. The computer
industry — from the most powerful players (GAFAM in the lead, but also
industries involved in cyber defence) to young “start-ups” — is now
promising to be able to track individuals. They propose to do so by
identifying and geolocalising them, tracking the actions of their data,
reconstructing their past activities on the net and elsewhere, and
especially by associating these data with health profiles. This might
suggest whether these individuals were, or are, sick (declared or not)
and if they are in low- or high-risk areas as the virus spreads, even if
in such models there is hardly any area free of risk.
Following the spread of the virus will therefore be based on data from
multiple web servers, centralised or not, through the use of mapping
tools and linking the status of a specific person with their travel via
a specific application — either with a smartphone or an autonomous
Bluetooth card, as considered in New Zealand. Some applications envisage
to also have real-time “flags” about the status of individuals who are
obliged to move and have contact with the public. While some countries
are (considering) making participation mandatory, most democracies are
pursuing voluntary applications based on “privacy by design” to respect
the GDPR and more generally the privacy rights of its citizens. But the
fact that they therefore choose to anonymise the data collected is not
proof that privacy will not be affected or that discrimination will not
occur.
Notice how quickly policymakers have officially accepted and launched
media campaigns that the internet, algorithms, and artificial
intelligence can block the advance of the virus. Maybe they think that
even if the selected apps will not really work in practice, they might
nevertheless assuage the critics of severe confinement and create some
hope in the public that it will recover (parts of) its mobility.
Costs of compliance and other hidden motives
Unfortunately, this mobility is not a sign of freedom of movement
enjoyed as a right. Rather it comes with the cost of compliance,
including the cost of providing personal data and accepting surveillance
measures for the greater good. Tracing applications do not contribute
much to public health, however, if they are not combined with widespread
testing. Instead, they can also be seen as a building block in the
management of public opinion, as if participating in the (voluntary)
application was de facto a poll in favour of the government and an
acceptance of its emergency powers.
A ‘bio-digital-surveillance’ has emerged from the Covid-19 outbreak as
the only political ‘option’ ostensibly suited to relax confinement, even
in democratic settings. But this political thinking has simultaneously
created confusion about the functions of the digital apps and the
medical strategies they are supposed to implement. Their purposes are
multifold and not always oriented towards health. Some of these
surveillance tools are tracing and localising sick individuals, while
others are preventing them from moving without warning. Some are also
designed beyond the scope of individual movement to trace personal
encounters, with the possibility of demanding that a visit be paid to
the hospital, police station, or town hall to register as potentially
sick. Some of the apps also intend to identify via algorithms all
possible unexpected encounters with a sick person (still without
symptoms) and to transform these different encounters into cases of
“suspicion”, without the cooperation of the individuals.
This digital tracing is presented as a great innovation, but in fact it
is everything but new. Its digitality certainly conveys the image of
instantaneity and efficiency, but the logic at work is old. Since the
cholera epidemics of the 19th century, contact tracing has been
considered a better, more targeted, and therefore more democratic
practice than generalised confinement. It emerged from the production of
specific knowledge about virus ecology and replaced the types of plague
confinements we had before. In 1854, John Snow — one of the founders of
modern epidemiology — established a cartography to validate his
hypothesis of the role of water in the spread of cholera. But to track
the virus, yesterday like today, it is necessary to collect much more
data on the individuals who are infected.
What drives this grand digital strategy?
The key factor in discerning between the blind confinement of all people
in a given area, be they sick or not, and the selective confinement of
sick individuals is the visibility of transmission and its mechanisms.
This is what eliminates false correlations and enables areas to
“reopen”, at least for healthy individuals.
Data collection, mapping, and population tracing are only meaningful if
they are followed by a systematic screening through tests that are
applied to everyone and periodically renewed. Without this two-step
strategy, of which the second is crucial, there is no point to develop
the first.
As I have pointed out in my book “Data Politics”, raw data do not exist.
Instead, politicians construct how to collect and organise data and the
data in turn construct policies on knowledge foundations that are being
built up and based on differentiated premises (data politics).
This is true also for health. Tracing apps do not directly oppose the
free movement of individuals and are not based on their absolute
confinement; they aim to create personal security belts around each
circulating individual to avoid contamination. But they are a question
of temporality as much as of space.
If there is one characteristic of modern pandemics, it is that in the
absence of a vaccine, it is now instead possible — thanks to the speed
of digital technology and data networking — to know more or less in real
time the “channels” of viral propagation. These can be correlated with
modes of transmission, identifying risk populations in real time and
thus avoiding bureaucratic slowness (as Google Flu did, but
unsuccessfully so). In theory, this enables authorities to anticipate
the spread so that medical infrastructure is there when it’s needed, or
at least faster than before (although, in the case of the Ebola
epidemic, big data was actually of no help at all).
It is therefore not surprising that all states with tech industry
capabilities are seeking to combine digital traceability with the
imperatives of non-contamination in order to restore a degree of
conditional freedom of movement. The freedom to work is deemed to be of
particular importance in that regard, in order to limit the economic
effects of containment.
It can also be argued that the focus on the digital is all the more
emphasised since the resilience of the hospital sector has previously
been so weakened by austerity policies (a card France and the UK seem to
be playing). The focus on the digital becomes a “mask” for past failures
and risks being a pure simulation policy if digital tracing is not
linked to a generalised testing policy. This is because digital data are
not capable of detecting anything if they are not accompanied by
concrete and widespread measures, such as the test booths used in South
Korea.
Urgent need for a citizen design protocol to prevent a control society
As Dominique Boullier has forcefully pointed out in his comparison of
the citizen-centred design in different applications: What is crucial to
understand is that digital applications are therefore not a solution to
the pandemic in and of themselves, but rather need to be connected with
a health strategy of testing and a citizen-oriented design. If not, the
applications may create a whole series of additional problems in
addition to the lack of free movement by depriving citizens of other
liberties, as well as by contributing to the progressive installation
(by ratchet effect) of a control society that jeopardises privacy and
fundamental rights by default.
That is why it must be stressed that current proposals for tracing
applications must in no way be judged on their technical performances
(including privacy design only). They must be judged by following a
“citizen design” protocol, which in this case must start from a genuine
clinical definition of health objectives. If we are not careful,
Covid-19 applications could become routine surveillance measures for the
purpose of overseeing compliance with the rules, including progressive
deconfinement of a part of the population, as well as punishment for
patients who do not declare themselves. This would be a most
successfully failed ultra-solution in the sense that Watzlawick has
proposed. In this case, these ultra-solutions would add mass
surveillance of populations and discrimination to the suppression of
individual freedom of movement.
Conclusions
Those countries which were least prepared for the pandemic have sought
the most refuge in digital techno-solutionism, trying to divert
attention from the catastrophe they failed to prevent. Tracing
applications have also become quite popular in countries which hope to
step up their digital sovereignty by propping up their own technological
industry. Strategic communications companies have instrumentalised these
sentiments in order to help governments convince the public to
participate in the collection of their health data in the name of
national health. To slow the pace of, or to prevent, a control society,
it would be necessary to at least create strong sunset clauses and
oversight mechanisms for the entire process, with the possibility to
stop the collection of data after the emergency.
We must order the destruction of sensitive data that are stored during
the pandemic and refuse that the process is repurposed for other
reasons. The laws and decrees which are legitimating these applications
certainly have to rely on existing oversight mechanisms: data
protection, ethics guidelines, sanitary codes, and/or ombudspersons.
This is badly needed to avoid having only ad hoc technical oversight.
The various governments genuinely ready to pursue a citizen-centred
design and to safeguard privacy must also enhance the collaboration
between these oversight structures and reinforce their powers,
including, for example, sanctions against data brokers should they be
using these data for commercial interests.
Therefore, what matters in the long-term is which digital platforms will
manage the applications after the pandemic has been brought under
medical control, which public-private assemblages will have consolidated
their power and profits, and which uses of health data will continue
after the crisis. There is every reason to believe that the
implementation of applications whose data are certainly anonymised
during the process, but are later sent to interoperable systems, will
finally connect the health data of individuals with police and
border-crossing data identification systems. This is likely to integrate
different spaces, from the most local (municipalities) to the
transnational spaces of the global North (airports, train stations,
etc.). This dystopian scenario needs to be rejected without ambiguity by
organising a reinforcement of human rights legislation both internally
and at the EU level.
De-anonymisation mechanisms through cross-referencing of data are
increasingly effective, and data brokerage companies have shown that
they can already know our private information and personal thoughts
without necessarily needing our name (Cambridge Analytica). If sensitive
health data is circulating and is a source of profit, then it is likely
that the routine use of such applications for surveillance purposes, and
the dependence of free movement on authorisation, is a serious risk for
democratic societies as a whole. In Europe, it will be difficult to find
national solutions to limit the power of the transnational guild of
digital technology professionals. Our greatest hope may come from
listening seriously to the warnings of constitutional and human rights
lawyers, as well as pushing the European courts via strong civic
mobilisation to have their say in this debate. After all, it concerns
the very core of our democratic societies.
[...]
June 7, 2020
Re: [nexa] in browser port scanning... altro?
by Giacomo Tesio
Aggiungo una nota Giovanni, anche se so che a te sembrerà scontata.
L'aspetto più grave di questa classe di attacchi via JavaScript è che
ovviamente sono personalizzabili se si è in condizione di indentificare
l'utente.
Ed in un Web come quello mainstream, in cui ogni sito Web integra script
provenienti da decine di sorgenti (e CDN) è possibile attaccare un
visitatore di un sito completamente ignaro.
E naturalmente, con un header HTTP di Cache-Control appropriato, puoi
cancellare qualsiasi traccia dell'attacco dal PC della vittima ricaricando
i file dell'attacco con versioni innocue. Se fai attenzione a preservare la
dimensione dei file, nemmeno negli eventuali log del proxy HTTP rimarrà
alcuna anomalia osservabile.
Giacomo
On Sunday, 7 June 2020, Giacomo Tesio <giacomo(a)tesio.it> wrote:
> Lo fa anche il governo Russo.
> E sì permette anche di mappare una rete interna.
>
> Si tratta di un attacco che ho ideato 2 anni fa, come esempio di una
> vasta classe di attacchi possibili su un browser, visto che mi si
> chiedeva un Proof-of-concept.
> O meglio, qui si fanno le cose complicate: basta cercare di caricare
> una GIF e misurare il tempo in cui ricevi l'errore.
>
> La segnalazione a Mozilla (e successivamente a Chrome) è qui:
>
> https://bugzilla.mozilla.org/show_bug.cgi?id=1487081
>
> L'attacco in questione fu uno dei primi che mi venne in mente e lo
> descrissi qui:
>
> https://dev.to/shamar/the-meltdown-of-the-web-4p1m
>
> Successivamente, uno dei miei tanti detrattori inziali si accorse che
> ci si poteva appunto mappare l'intera rete
>
> https://rain-1.github.io/in-browser-localhostdiscovery
>
> Ma in realtà, in un mondo di IoT con telecamere accessibili via HTTP,
> ci si può fare molto di più! ;-)
>
> D'altronde è solo uno dei possibili attacchi che appartengono a quella
classe.
> Ne descrissi altri, in varie sedi, ma sembrava che a nessuno fregasse
niente.
>
> Peraltro, se è venuto in mente a me due anni fa, probabilmente era già
> molto diffuso in rete perché io sono solo un programmatore competente,
> non un ethical hacker esperto in penetration tests!
> Non sono mica un "esperto", io... ;-)
>
>
> DUE anni dopo questi attacchi sono ancora possibili.
> D'altronde, come mi risposero da Mozilla nella issue,
>
> "this is the Web functioning as designed"
>
>
> E vedrai quando tutti useranno il DNS-over-HTTPS di Cloudflare!
> Avremo un canale cifrato ed insospettabile per inviare ad un server
> DNS tutti i dati sottratti attraverso questi trucchetti!
>
>
>
> Giacomo
>
June 7, 2020
Re: [nexa] in browser port scanning... altro?
by Giacomo Tesio
Lo fa anche il governo Russo.
E sì permette anche di mappare una rete interna.
Si tratta di un attacco che ho ideato 2 anni fa, come esempio di una
vasta classe di attacchi possibili su un browser, visto che mi si
chiedeva un Proof-of-concept.
O meglio, qui si fanno le cose complicate: basta cercare di caricare
una GIF e misurare il tempo in cui ricevi l'errore.
La segnalazione a Mozilla (e successivamente a Chrome) è qui:
https://bugzilla.mozilla.org/show_bug.cgi?id=1487081
L'attacco in questione fu uno dei primi che mi venne in mente e lo
descrissi qui:
https://dev.to/shamar/the-meltdown-of-the-web-4p1m
Successivamente, uno dei miei tanti detrattori inziali si accorse che
ci si poteva appunto mappare l'intera rete
https://rain-1.github.io/in-browser-localhostdiscovery
Ma in realtà, in un mondo di IoT con telecamere accessibili via HTTP,
ci si può fare molto di più! ;-)
D'altronde è solo uno dei possibili attacchi che appartengono a quella classe.
Ne descrissi altri, in varie sedi, ma sembrava che a nessuno fregasse niente.
Peraltro, se è venuto in mente a me due anni fa, probabilmente era già
molto diffuso in rete perché io sono solo un programmatore competente,
non un ethical hacker esperto in penetration tests!
Non sono mica un "esperto", io... ;-)
DUE anni dopo questi attacchi sono ancora possibili.
D'altronde, come mi risposero da Mozilla nella issue,
"this is the Web functioning as designed"
E vedrai quando tutti useranno il DNS-over-HTTPS di Cloudflare!
Avremo un canale cifrato ed insospettabile per inviare ad un server
DNS tutti i dati sottratti attraverso questi trucchetti!
Giacomo
June 7, 2020
in browser port scanning... altro?
by Giovanni Biscuolo
Cari nexiani,
un amico molto tecnico mi segnala questo articolo molto tecnico, che in
buona sostanza rivela come Ebay e molti altri clienti di LexisNexis
utilizzino *anche* la tecnica del port scanning del PC sul quale
funziona il browser (via Javascript) per profilare i visitatori.
Il port scanning è una tecnica che serve per sapere quali porte sono
"aperte" su un host e di conseguenza stabilire quali servizi sono in
funzione sul quell'host.
Siamo sicuri che una tecnica analoga non possa essere usata anche per
**esporre** un'intera rete locale attraverso un reverse tunnell "in
browser" sfruttando questa tecnica: https://github.com/MDSLab/wstun?!?
(chiedo scusa se ai non addetti ai lavori sembra arabo)
Qualche esperto websocket/Javascript in lista può dirmi se sono
eccessivamente paranoico?
«Ebay is port scanning visitors to their website - and they aren't the only
ones», by Dan Nemec, 24 May 2020
https://blog.nem.ec/2020/05/24/ebay-port-scanning/
--8<---------------cut here---------------start------------->8---
[...] actually discussing a different type of port scanning, one
initiated directly by a website the target loads in their browser. It’s
an ingenius, if not insidious, technique that allows would-be port
scanners to paradrop straight into an internal network and scan it using
Javascript from within the browser context.
As an aside, this is something that a browser extension could block,
however the company behind the port scanning uses techniques to prevent
widespread blocking of their trackers, as we’ll see later.
How Browser Port Scanning Works
While modern browsers allow Javascript to make requests to other domain
names than the one you’re currently visiting (e.g. www.ebay.com) they
layer on security controls to ensure the target data allows the calling
website to access it. This prevents, for example, a malicious website
from requesting the account details from you bank’s website. However,
even without knowing the contents of the remote site, details about the
connection itself (such as the time it takes to connect or time out) can
be used to infer whether or not a website exists at the given host and
port. A bit of Javascript code can wrap that into a package and allow
any site to scan a user’s internal network, determining which IP
addresses and ports have services running. Further, because many
well-known services are commonly available on the same port (there is a
registration page, but it’s more of a guideline than a hard and fast
rule), it’s possible to also infer some programs that a user may be
running on their network depending on whether the port is open or not.
[...]
In trying to load Ebay locally I found that I couldn’t replicate the
behavior in Linux even after spoofing a Windows User Agent and disabling
all of my extensions. There must be some check hidden in the Javascript,
but as of yet I haven’t found one. After that, I loaded a Windows VM,
installed the latest Edge, fired up https://www.ebay.com, and I finally
replicated the port scanning behavior. However, I had some trouble
replicating the behavior reliably, and after some trial and error I
found that https://signin.ebay.com/ was far more reliable for triggering
the port scanning.
[...]
To summarize what we’ve found so far:
* Ebay collects data on whether certain ports are open on your local PC
* This data is shipped to an Ebay domain, but does not seem to be used
* otherwise Additional data like User Agent and IP are also sent
[...] the domain where data is exfiltrated is not a subdomain of
ebay.com - it’s ebay-us.com. Still, a quick check shows that it’s owned
by somebody at Ebay, so at the very least it isn’t phishing malware.
Twitter user Armchair IR pointed out that similar behavior has been seen
by Facebook and it traced to a company called ThreatMetrix, an identity
tracking/anti-fraud company. Checking the DNS records for
src.ebay-us.com, sure enough it’s a CNAME to h-ebay.online-metrix.net, a
domain owned by ThreatMetrix Inc.
[...] It’s not just Ebay scanning your ports, there is allegedly a
network of 30,000 websites out there all working for the common aim of
harvesting open ports, collecting IP addresses, and User Agents in an
attempt to track users all across the web. And this isn’t some rogue
team within Ebay setting out to skirt the law, you can bet that
LexisNexis lawyers have thoroughly covered their bases when extending
this service to their customers (at least in the U.S.).
--8<---------------cut here---------------end--------------->8---
Saluti, Giovanni.
--
Giovanni Biscuolo
June 7, 2020
COMMUNIA Copyright Directive Webinars
by Federico Leva (Nemo)
Penso che questo possa interessare a molti da queste parti. Secondo me è
particolarmente utile per quei "copyright geek" che hanno seguito la
direttiva copyright ma non hanno avuto tempo di (ri)leggere tutto il
testo della direttiva e le migliaia di pagine di studi connessi.
Iscrivetevi:
<https://centrumcyfrowe.pl/en/communia-copyright-directive-webinars/>
Ricordo che abbiamo anche una sintesi della situazione in Italia:
https://www.notion.so/Italy-ef314e69e7ef42d1893efe5ef0ee39f8
Federico
-------- Messaggio inoltrato --------
Oggetto: [Implementation] COMMUNIA Copyright Directive Webinars
Dear All,
The process of implementation of the new Copyright Directive is speeding up
in various countries (see our Implementation Tracker
<https://www.notion.so/communia/DSM-Directive-Implementation-Tracker-361cfae…>).
Therefore, COMMUNIA has decided to organize a series of webinars aimed at
explaining the different provisions of the new Copyright Directive and
making suggestions on what to advocate for during the implementation
process of those provisions at the national level, to expand and strengthen
user rights.
The Copyright Directive Webinars are aimed at local advocates and national
policymakers and will be conducted by COMMUNIA members and experts that
were involved in preparing our Implementation Guidelines
<https://www.notion.so/DSM-Directive-Implementation-Guidelines-45233be9c0e14…>
.
We will hold four webinars of one hour each, as follows:
16/06 (Tuesday) – Press Publishers’ Right (Art. 15): Dimitar Dimitrov
17/06 (Wednesday) – Text and Data Mining and Education Exceptions (Arts.
3-5): Benjamin White and Teresa Nobre
23/06 (Tuesday) – Use of Content by Online Platforms (Art. 17): Teresa
Nobre and Paul Keller
24/06 (Wednesday) – Cultural Heritage Provisions (Arts. 6, 8-11, 14):
Stephen Wyber, Ariadna Matas and Paul Keller
*All webinars will take place from 10.00am to 11.00am CET. You can register
for the webinars of your choice here
<https://centrumcyfrowe.pl/en/communia-copyright-directive-webinars/>.
Remember to register for the seminar up to 24 hours before it starts. We
have a limit of 30 participants at each seminar, so please don’t register
if you don’t plan to show up. The access info will be shared with those who
signed up.*
Have a nice day,
Natalia Mileszyk
Centrum Cyfrowe
June 7, 2020
More than 140 Zuckerberg-funded scientists call on Facebook to rein in Trump | Technology | The Guardian
by Alberto Cammozzo
<https://www.theguardian.com/technology/2020/jun/06/mark-zuckerberg-facebook…>
More than 140 scientists funded by Mark Zuckerberg have said Facebook should not be letting Donald Trump use the social media platform to “spread both misinformation and incendiary statements”.
The researchers, who include more than 60 professors at leading US research institutions and one Nobel laureate, sent the Facebook CEO a letter on Saturday asking him to “consider stricter policies on misinformation and incendiary language that harms people”, especially during the current turmoil over racial injustice.
The letter calls the spread of “deliberate misinformation and divisive language” contrary to the researchers’ goals of using technology to prevent and eradicate disease, improve childhood education and reform the criminal justice system.
Their mission “is antithetical to some of the stances that Facebook has been taking, so we’re encouraging them to be more on the side of truth and on the right side of history, as we’ve said in the letter”, said Debora Marks of Harvard Medical School, one of three professors who organized it.
The others are Martin Kampmann of the University of California, San Francisco, and Jason Shepherd of the University of Utah. All have grants from a Chan Zuckerberg Initiative program working to prevent, cure and treat neurodegenerative disorders including Alzheimer’s and Parkinson’s disease.
They said the letter had more than 160 signatories. Shepherd said about 10% were employees of foundations run by Zuckerberg and his wife, Priscilla Chan.
The letter objects specifically to Zuckerberg’s decision not to act on a post by Trump that stated “when the looting starts, the shooting starts”. The letter’s authors called the post “a clear statement of inciting violence”.
[...]
June 7, 2020