nexa
By thread
nexa@server-nexa.polito.it
By month
Messages by month
- ----- 2026 -----
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
April 2022
- 40 participants
- 130 messages
Opinion | What You Don’t Know About Amazon - The New York Times
by J.C. DE MARTIN
https://www.nytimes.com/2022/04/21/opinion/amazon-product-liability.html
(Sent from my wireless device; please excuse brevity and typos (if any))
April 21, 2022
"Scoring the U.S. working class: expropriation and digitalization"
by J.C. DE MARTIN
Scoring the U.S. working class: expropriation and digitalization
/Originally published: /Focaal Blog
<https://www.focaalblog.com/2022/03/28/don-nonini-scoring-the-u-s-working-cl…>
on March 28, 2022 by Don Nonini (more by Focaal Blog
<https://mronline.org/guest-author/cap-focaal-blog/>) - Posted Apr 18, 2022
Introduction
Working-class people in the United States are now at a turning
point–whether to compliantly return to the pre-Covid conditions capital
set for them, or to shift toward a new militancy toward capitalism. Now,
two years into the pandemic, they have suffered severe personal
hardships due to Covid-related illness, hospitalizations and deaths, and
sudden loss of employment. These traumas have occurred even as they have
experienced an historically unprecedented hiatus of relative economic
security, given the Covid-related payments and protections they received
from the U.S. state, while many have been praised as “essential
workers.” This essay seeks to review what has happened to them over the
last four decades that has made this into such a turning point.
Anthropologists speak of the period since the 1970s as one of
neoliberalism. Instead, in this essay I adopt a different perspective by
exploring the conditions prevailing under the transition from the
liberal nation-state to the corporate-oligarchic state that has occurred
widely with the integration of platform-surveillance capitalism into
state administration and the use of massive databases by corporations
and governments to govern populations (Kapferer and Gold 2018). Freedom
and enslavement in the contemporary United States are linked to two now
converging phenomena. One is digitalization; the other is the expansion
of expropriation as a mechanism of capital accumulation beyond its
historically racially marked boundaries to encompass the racially
dominant white population. These changes have taken place with the rise
to domination of finance capitalism in the world economy, a new period
of economic decline and social crisis in the West.
First, as to digitalization. It has not only led to unprecedented levels
of economic inequality among the population, but also to new mechanisms
of accumulation organized around the generalized dispossession of
working-class people made possible by their indebtedness combined with
corporate and state deployment of digital technologies with large-scale
predictive capabilities. The rise of surveillance capitalism and its
integration into the corporate state has taken the form of a massive,
commercialized apparatus of surveillance–“a single behemoth of a data
market; a colossal marketplace for personal data” (Harcourt 2015, 198).
The ascendance of finance capital has come to operate in tandem with a
racialized corporate state formation using an apparatus of analog
surveillance and control of working people combined with digital
surveillance over them. This apparatus has come to rationally extract
and then realize large volumes of surplus value from them outside the
capitalist workplace. This apparatus employs digital technologies (i.e.,
artificial intelligence) to increase the hyper-exploitation and
expropriation of racially vulnerable groups, but also extends to the
racially dominant white population. I focus my attention on the United
States because its relentless attachment to new forms of financialized
repression of working people through capitalizing (on) their debt
repayment and petty income streams leads the way for capitalist regimes
in other “advanced industrialized” countries undergoing economic decline.
[...]
continua qui:
https://mronline.org/2022/04/18/scoring-the-u-s-working-class/
April 21, 2022
fantasmi abusivi a Venezia (Codice Qr come il Green pass per entrare: sperimentazione in estate)
by 380°
Buongiorno nexiane,
https://www.ilgazzettino.it/nordest/venezia/codice_qr_green_pass_turisti_ve…
--8<---------------cut here---------------start------------->8---
VENEZIA - Prenotare una visita a Venezia sarà come riservare una camera
d’albergo o un appartamento sui portali turistici: su una pagina del
Comune che sarà a questo dedicata si sceglie la data, si inserisce il
numero di persone e si va al “carrello”. Nessun pagamento, per
quest’anno, poiché l’applicazione del Contributo d’accesso è slittata al
2023, ma comunque al costo di euro zero, si riceverà un numero di Qr
code (il “bollino” diventato famoso con il green pass) pari al numero
dei visitatori e con quella si potrà godere di alcuni incentivi che
potranno essere sconti o priorità su alcuni servizi gestiti dal Comune o
dalle sue partecipate. Ad esempio, una riduzione o un salta coda il
trasporto pubblico o i musei, tanto per capirci. Vantaggi che chi non
prenoterà la visita in giornata non potrà avere, anzi potrebbe avere dei
rincari o farsi lunghe code.
--8<---------------cut here---------------end--------------->8---
Ovviamente si tratta /solo/ di una prenotazione per poter entrare a
Venezia, è da molto tempo che se ne parla... ma di questi tempi ogni QR
code diventa "Green Pass" :-O
A tal propositi, pare che la recente vacanza pasquale sia stata
particolarmente affollata a Venezia, addirittura c'è stata una vera e
propria /emergenza/ di infestazione di fantasmi che si aggiravano per le
calli:
https://corrieredelveneto.corriere.it/venezia-mestre/cronaca/22_aprile_20/v…
«Venezia, 20mila turisti-fantasma sono in città ma non risultano: le tracce dei
telefoni li inchiodano»
--8<---------------cut here---------------start------------->8---
Posti letto e presenze: i conti non tornano. «La prenotazione ostacolerà
gli abusivi»
Almeno ventimila turisti fantasma che nei giorni di Pasqua hanno
sicuramente dormito a Venezia ( l’aggancio dei cellulari alle celle dei
ripetitori non mente), ma non si sa dove.
Il numero dei posti letto (ufficiali) non torna
C’è in effetti un problema: tra centro storico, isole e terraferma non
ci sono 101 mila e passa posti letto. Secondo i dati ufficiali ci sono
81.849 posti nell’intero territorio comunale, di cui 32.562 in hotel e
49.287 nell’extra-alberghiero, ossia bed and breakfast, affittacamere e
case vacanza. E in centro storico, sono 18.898 i letti negli alberghi e
40.491 nel ricettivo modello Airbnb. Qualcuno potrebbe pensare che i
numeri della Smart control room non siano precisi, ma non è così: il
sistema (nel rispetto delle norme sulla privacy) riesce a vedere
qualsiasi cellulare sia in città. E per capire chi soggiorna in laguna
si contano gli smartphone presenti alle 4 di notte. Se ne riesce a
comprendere la provenienza (per dire, a Pasquetta c’erano 35.990
residenti a casa) e dove si trovano. Il margine di errore c’è: chi non
ha il cellulare (come i bambini) o lo tiene spento sfugge al
conteggio. Per gli altri non c’è scampo. Sorge dunque il dubbio che
qualcuno abbia cercato di assicurarsi un guadagno esentasse. «Dovremo
fare verifiche sulla congruità dei dati», dice il comandante dei vigili
Marco Agostini. «Riprenderemo i controlli», aggiunge la Guardia di
finanza.
Prenotazioni per far luce sui «coni d’ombra»
Per il futuro, molti contano che l’obbligo di prenotazione faccia luce
sui coni d’ombra del turismo veneziano: prenotando la visita tutto sarà,
per forza di cose, trasparente. «La prenotazione dà una sicurezza in più
a tutti — commenta Salvatore Pisani, Confindustria Turismo Venezia — in
particolare ai turisti che avranno certezza di avere servizi
adeguati». Approva la decisione di introdurre dall’estate il booking a
Venezia l’onorevole dem Nicola Pellicani: «Non entro nel merito del
provvedimento dell’amministrazione che ancora non è pubblico — precisa —
ma prenotare la visita è la strada giusta, al contrario di proposte
improbabili come i tornelli». Fermo restando che la decisione spetta al
Comune e che «da noi i turisti sono sempre ben accetti», per il
presidente del Veneto Luca Zaia «Venezia è sotto pressione e andrà
prenotata» come si fa con musei, ristoranti e mezzi pubblici.
--8<---------------cut here---------------end--------------->8---
Quindi fatemi capire, amministratori veneziani: niente tornelli di
ingresso ma obbligo di prenotazione per poter stare a Venezia con la
«certezza di avere servizi adeguati»? ...mumble, mumble, mumble.
Turisti furbetti, non avrete scampo, i vostri QR code vi /inchioderanno/
(cit. dal titolo del corriere riportato sopra): sapremo /se/ potete
stare a Venezia [1], quando e dove entrate, mangiate, andate in bagno,
dormite e uscite dalla città (nel rispetto delle norme sulla
privacy). :-O
Saluti, 380°
[1] controlli a campione? Multe per accesso non autorizzato? Obbligo
di presentazione del pass per accedere ai servizi?
P.S.: gli amministratori di un qualsiasi parco divertimenti o villaggio
turistico avrebbero sicuramente un sacco di consigli da fornire agli
amministratori di Venezia su come gestire la folla di visitatori
(compresi i famosissimi biglietti salta-coda), tenendo a debita distanza
gli /abusivi/.
P.P.S.: vorrei avere anche io i dati della "Smart control room" di
Venezia, così, giusto per capire quanti giorni all'anno Venezia è così
affollata da rappresentare un pericolo per l'ordine pubblico da
giustificare una limitazione alla circolazione.
--
380° (Giovanni Biscuolo public alter ego)
«Noi, incompetenti come siamo,
non abbiamo alcun titolo per suggerire alcunché»
Disinformation flourishes because many people care deeply about injustice
but very few check the facts. Ask me about <https://stallmansupport.org>.
April 21, 2022
GitHub suspends accounts of Russian devs at sanctioned companies
by 380°
Buongiorno nexiane,
https://www.bleepingcomputer.com/news/security/github-suspends-accounts-of-…
«GitHub suspends accounts of Russian devs at sanctioned companies»
--8<---------------cut here---------------start------------->8---
Russian software developers are reporting that their GitHub accounts are
being suspended without warning if they work for or previously worked
for companies under US sanctions.
According to Russian media outlets, the ban wave began on April 13 and
didn't discriminate between companies and individuals.
For example, the GitHub accounts of Sberbank Technology, Sberbank AI
Lab, and the Alfa Bank Laboratory had their code repositories initially
disabled and are now removed from the platform.
# Blocked repository or flagged company (habr.com)
Considering that these companies were sanctioned by the U.S. Treasury
last week and Microsoft owns GitHub, an American company, the action is
not unexpected.
However, suspending the private accounts of dozens of individuals that
host no content connected to any sanctioned entities is quite
surprising.
[...] Bleeping Computer has reached out to GitHub asking for a comment
on the reported suspension wave, and a spokesperson of the platform has
responded with the following:
Like any company that does business in the U.S., GitHub may have to
restrict users and customers identified as Specially Designated
Nationals (SDNs) or other denied or blocked parties under U.S. and
other applicable sanctions laws, or that may be using GitHub on behalf
of blocked parties.
At the same time, GitHub’s vision is to be the global platform for
developer collaboration, no matter where developers reside. We examine
government sanctions thoroughly to be certain that users and customers
are not impacted beyond what is required by law. - GitHub
According to this, the suspended private accounts are either affiliated,
collaborating, or working with/for sanctioned entities. However, even
those who previously worked for a sanctioned company appear to be
suspended by mistake.
This means that Russian users, in general, can suddenly find their
projects wiped and accounts suspended, even if those projects have
nothing to do with the sanctioned entities.
--8<---------------cut here---------------end--------------->8---
Saluti, 380°
--
380° (Giovanni Biscuolo public alter ego)
«Noi, incompetenti come siamo,
non abbiamo alcun titolo per suggerire alcunché»
Disinformation flourishes because many people care deeply about injustice
but very few check the facts. Ask me about <https://stallmansupport.org>.
April 21, 2022
Re: [nexa] Planting Undetectable Backdoors in Machine Learning Models
by Stefano Quintarelli
beh, puo' essere fatto anche da un insider
ciao, s.
On 21/04/22 11:45, Marco Ciurcina wrote:
> Given the computational cost and technical expertise required to train machine
> learning models, users may delegate the task of learning to a service
> provider. We show how a malicious learner can plant an undetectable backdoor
> into a classifier. On the surface, such a backdoored classifier behaves
> normally, but in reality, the learner maintains a mechanism for changing the
> classification of any input, with only a slight perturbation. Importantly,
> without the appropriate "backdoor key", the mechanism is hidden and cannot be
> detected by any computationally-bounded observer. We demonstrate two
> frameworks for planting undetectable backdoors, with incomparable guarantees.
> ...
>
> https://arxiv.org/abs/2204.06974
>
>
> _______________________________________________
> nexa mailing list
> nexa(a)server-nexa.polito.it
> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
April 21, 2022
Planting Undetectable Backdoors in Machine Learning Models
by Marco Ciurcina
Given the computational cost and technical expertise required to train machine
learning models, users may delegate the task of learning to a service
provider. We show how a malicious learner can plant an undetectable backdoor
into a classifier. On the surface, such a backdoored classifier behaves
normally, but in reality, the learner maintains a mechanism for changing the
classification of any input, with only a slight perturbation. Importantly,
without the appropriate "backdoor key", the mechanism is hidden and cannot be
detected by any computationally-bounded observer. We demonstrate two
frameworks for planting undetectable backdoors, with incomparable guarantees.
...
https://arxiv.org/abs/2204.06974
April 21, 2022
97° Nexa Lunch Seminar | 27 Aprile 2022 | Modalità Telematica
by Nexa Media
Gentilissimi,
vi segnaliamo che il 97° Nexa Lunch Seminar,
/*"La nuova strategia europea in materia di dati"*/,
con ospite *Giacomo Conti* (Project Manager Centro Nexa),
si svolgerà *mercoledì 27 aprile, dalle ore 13.00 alle ore 14.00*, in
modalità telematica, utilizzando la piattaforma di videoconferenza
BigBlueButton.
Sarà possibile partecipare al seminario connettendosi al seguente
indirizzo: https://didattica.polito.it/VClass/NexaEvent
Nexa Center for Internet and Society Newsletter
Se non visualizzi correttamente questo messaggio clicca qui
<https://nexa.polito.it/lunch-97>
NEXA
97° Nexa Lunch Seminar
Mercoledì 27 aprile 2022, ore 13.00 - 14.00
https://nexa.polito.it/lunch-97
La nuova strategia europea in materia di dati
Speaker
Giacomo Conti (Project Manager Centro Nexa)
This event will be webcast live: https://nexa.polito.it/nexa-hangout-on-air
*PARTECIPA ONLINE ALL'INCONTRO:
https://didattica.polito.it/VClass/NexaEvent*
Le operazioni di ogni tipo sui dati sono ormai all’ordine del giorno nel
mondo di oggi. Scambi, compravendite e semplici raccolte di enormi
quantità di dati sono azioni quotidiane sia per imprese private che per
enti pubblici. L’Unione Europea, e nella fattispecie la Commissione
Europea, ha recentemente pubblicato la sua */New European Data
Strategy/*: una pianificazione di atti normativi composta
fondamentalmente da tre regolamenti, che intende rendere l’UE un mercato
libero e sicuro nel quale scambiare i dati.
Il *Data Governance Act*, il *Digital Service Act* ed il *Digital
Markets Act* sono i tre regolamenti che, nelle intenzioni della
Commissione, dovrebbero rivoluzionare il mercato dei dati in Europa.
Quali saranno i vantaggi di queste potenziali nuove norme? E quali le
problematiche?
Inoltre, occorre considerare l’Unione Europea non come un soggetto
assoluto, ma al contrario insito in un mercato globale, costretto a
fronteggiare la concorrenza di altri Paesi, primo fra tutti gli Stati
Uniti, dotato di un sistema normativo completamente diverso (ed
inaspettatamente forse ancora più complicato) di quello europeo.
BIOGRAFIA - e informazioni supplementari
[Lunch97]
*Giacomo CONTI*, laureato in Giurisprudenza e grande appassionato di
informatica, riveste attualmente il ruolo di Project Manager presso il
Centro Nexa. Il suo ambito primario di competenza è la responsabilità
nell'uso del software e i problemi di privacy derivanti dalle nuove
tecnologie. Amante dei videogiochi, è fondatore del sito di critica e
approfondimento MMO.it. È iscritto all'Ordine dei Giornalisti del
Piemonte dal 2016.
*Letture consigliate e link utili:*
* Commissione Europea, /Una Strategia Europea per i dati/, Bruxelles,
19 febbraio 2020, LINK
<https://eur-lex.europa.eu/legal-content/IT/TXT/HTML/?uri=CELEX:52020DC0066&…>
* Commissione Europea, /Strategia europea in materia di dati/, LINK
<https://ec.europa.eu/info/strategy/priorities-2019-2024/europe-fit-digital-…>
* World Economic Forum, /Personal Data: The Emergence of a New Asset
Class/, 2011, LINK
<https://www3.weforum.org/docs/WEF_ITTC_PersonalDataNewAsset_Report_2011.pdf>
* Commissione Europea, /Proposta di Regolamento del Parlamento Europeo
e del Consiglio relativo alla governance europea dei dati (DGA)/,
Bruxelles, 25 novembre 2020, LINK
<https://eur-lex.europa.eu/legal-content/IT/TXT/HTML/?uri=CELEX:52020PC0767&…>
* Commissione Europea, /Proposta di Regolamento del Parlamento Europeo
e del Consiglio relativo a un mercato unico dei servizi digitali
(legge sui servizi digitali) e che modifica la direttiva
2000/31/CE/, Bruxelles, 15 dicembre 2020, LINK
<https://eur-lex.europa.eu/legal-content/IT/TXT/PDF/?uri=CELEX:52020PC0825&f…>
* Commissione Europea, /Regolamento […] relativo a mercati equi e
contendibili nel settore digitale (legge sui mercati digitali)/,
Bruxelles 15 dicembre 2020, LINK
<https://eur-lex.europa.eu/legal-content/IT/TXT/PDF/?uri=CELEX:52020PC0842&f…>,
Capo II.
Che cosa sono il Centro Nexa e i cicli di incontri “Mercoledì di Nexa” e
“Nexa Lunch Seminar”
<https://www.facebook.com/nexa.center/> <https://twitter.com/nexacenter>
<https://www.youtube.com/user/NexaCenter>
<https://www.instagram.com/nexa_center/>
<https://www.linkedin.com/company/3054864/admin/>
#nexalunchseminar
<https://twitter.com/search?q=%23nexalunchseminar&src=typd>
#EuropeanCommission <https://twitter.com/EU_Commission>
Il Centro Nexa su Internet & Società del Politecnico di Torino
(Dipartimento di Automatica e Informatica) dal 2006 è un centro di
ricerca indipendente e interdisciplinare che, in collaborazione con
l'Università di Torino, studia Internet (e più in generale le Tecnologie
digitali) e i suoi rapporti con la società. Maggiori informazioni
all'indirizzo: http://nexa.polito.it/about.
Durante i “*Mercoledì di Nexa*”, che si tengono *ogni 2° mercoledì del
mese* alle *ore 18 in punto*, il Centro Nexa su Internet e Società apre
le sue porte non solo agli esperti e a tutti coloro i quali lavorano con
Internet, ma anche a semplici appassionati e cittadini. Il ciclo di
incontri intende approfondire, con un linguaggio preciso ma accessibile,
i temi legati alla Rete: motori di ricerca, Creative Commons, social
networks, open source/software libero, neutralità della rete, libertà di
espressione, privacy, file sharing, big e open data, smart cities e
molto altro.
Al centro di quasi tutti gli incontri un ospite pronto a dialogare con i
direttori del Centro Nexa, il Prof. Juan Carlos De Martin del
Politecnico di Torino e il Prof. Marco Ricolfi dell'Università di
Torino, nonché lo staff e i Fellows del Centro Nexa.
Maggiori informazioni sui Mercoledì di Nexa, incluso un elenco di tutti
i “Mercoledì” passati, sono disponibili all'indirizzo:
http://nexa.polito.it/mercoledi.
Si segnala inoltre che dal maggio 2012 *ogni 4° mercoledì* del mese
*dalle ore 13 alle ore 14* il Centro Nexa organizza anche i "*Nexa Lunch
Seminar*". Una lista di tutti i “Lunch Seminar” passati è disponibile
all'indirizzo: http://nexa.polito.it/lunch-seminars.
See our events calendar <http://nexa.polito.it/events> if you're curious
about future luncheons, discussions, lectures, and conferences not
listed in this email. Our events are free and open to the public, unless
otherwise noted.
Responsabile Comunicazione Centro Nexa su Internet & Società: *Anita
Botta*, tel: +39 011 090 7219, Mob: +39 347 131 3903, anita.botta(a)polito.it.
Maggiori informazioni sui Mercoledì di Nexa e i Nexa Lunch Seminar, sono
disponibili all'indirizzo: http://nexa.polito.it/events. Weekly Events
Newsletter. Sign up <http://nexa.polito.it/mailing-lists> to receive
this newsletter if this email was forwarded to you. To manage your
subscription preferences, please click here
<https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa>.
Connect & get involved: Jobs, internships, and more
<http://nexa.polito.it/get-involved>.
Cordiali saluti,
--
Anita Botta
Communication Manager
Nexa Center for Internet & Society
Politecnico di Torino – DAUIN
Corso Duca degli Abruzzi, 24 - 10129 Torino
web: https://nexa.polito.it/
mail: anita.botta(a)polito.it
tel: 011 090 7219
April 21, 2022
Hong Kong: "YouTube terminates CE nominee John Lee’s campaign channel, citing US sanctions"
by J.C. DE MARTIN
*YouTube terminates CE nominee John Lee’s campaign channel, citing US
sanctions**
*
Local | 20 Apr 2022 3:27 pm
YouTube took down the campaign channel of HK chief executive candidate
John Lee Ka-chiu on Wednesday, as its parent company Google said to
comply with the US sanctions against the HK former number-two official.
This came a day after Lee’s campaign office started to live broadcast
Lee’s meeting with Hong Kong deputies to the NPC and CPPCC on Facebook
and YouTube on Tuesday, and was originally planning to broadcast the
meeting with the Sports, Performing Arts, Culture and Publication sector
today.
Upon request for comments, a Google spokesman said the company complies
with applicable US sanctions laws and enforces related policies under
its Terms of Service.
[...]
continua qui:
https://www.thestandard.com.hk/breaking-news/section/4/189329/YouTube-termi…
April 21, 2022
EU: Policing: France proposes massive EU-wide DNA sweep, automated exchange of facial images - European Digital Rights (EDRi)
by Alberto Cammozzo
EU: Policing: France proposes massive EU-wide DNA sweep, automated
exchange of facial images
The French Presidency of the Council is seeking EU-wide comparisons of
every DNA profile held by police forces against all those held by other
national police forces, as well as EU policing agency Europol, as part
of plans to upgrade the ‘Prüm’ network of police databases. It also
hopes to automate the police exchange of facial images by eliminating
requirements for human review.
By Statewatch · April 20, 2022
<https://edri.org/our-work/eu-policing-france-proposes-massive-eu-wide-dna-s…>
*Networking police databases*
The proposals come in an amended version of a proposal
<https://www.statewatch.org/media/3247/eu-council-prum-presidency-proposals-…>
(pdf) originally published by the European Commission in December 2021,
which will upgrade the Prüm network of DNA, fingerprint and vehicle
registration databases to include facial images and “police records”, as
well as driving licence data
<https://www.statewatch.org/news/2022/february/eu-got-a-driving-licence-you-…>,
if the Council has its way.
The Prüm system currently allows law enforcement authorities to compare
a DNA profile – for example, taken from a criminal suspect or found at a
crime scene – and use it to run a search against all other participating
member states’ DNA databases. As well as EU member states, this also
includes the UK
<https://www.statewatch.org/brexit-goodbye-and-hello-the-new-eu-uk-security-…>.
*Mass DNA searches*
But the Presidency’s plan goes much further: under the revamped Prüm
system, a central “router” would be set up to manage interconnections
between different national databases, simplifying the current system
which requires mutual interconnections between every participating state
<https://www.statewatch.org/media/3249/eu-council-prum-notifications-declara…>
(pdf).
The Presidency now aims to use that router for the mass comparison of
DNA profiles (emphasis added in all quotes):
/“Member States shall, at the initial connection to the router via their
national contact points, *conduct an automated search by comparing all
their DNA profiles, with all DNA profiles stored in all other Member
States’ databases and Europol*. Member States and Europol shall agree
bilaterally on the modalities of these automated searches.”/
The same article goes on to say that such mass searches could be a
regular undertaking:
/“*Member States may agree bilaterally to conduct automated searches
also at a later stage* by comparing DNA profiles, with all DNA profiles
stored in all other Member States’ databases and Europol. Member States
and Europol shall agree bilaterally on the modalities of these automated
searches.”/
The Presidency has somehow managed to include these provisions prior to
one that says:
/“*Searches may be conducted only in individual cases* and in respect of
the same guarantees and safeguards that are required for similar
searches at national level.”
/
A mass, automated search and comparison of DNA profiles is evidently not
an “individual case”.
If it were implemented now, the proposal would involve the processing of
millions of items of sensitive personal data – EU member states held a
total of almost 17 million DNA samples at the end of 2021, according to
the latest statistics on DNA databases circulated within the Council of
the EU
<https://www.statewatch.org/media/3248/eu-council-prum-statistics-2021-5436-…>
(pdf, see table below). All but two member states’ DNA databases grew
during the course of 2021, some substantially: Bulgaria’s by 30%, and
Poland’s by 38%. The intention is to have the upgraded Prüm operational
by 2027, by which time those databases will have grown even more.
The Council may also be seeking to weaken the applicable safeguards, or
at least to make them less specific: the phrase “in respect of the same
guarantees and safeguards that are required for similar searches at
national level” has been inserted in place of the previous text, which
required searches to be conducted “in compliance with the national law
of the requesting Member State.”
*Automating the exchange of facial images*
The intention is also for the upgraded Prüm network to include police
facial recognition databases, which could form the technical backbone of
a Europe-wide mass biometric surveillance system
<https://edri.org/our-work/press-release-ec-jumps-the-gun-on-prum/>.
Under the Commission’s proposal
<https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=COM:2021:784:FIN>,
member states would have submitted a facial image for a search against
all other member states’ databases, and in return would have received a
list of potential “candidates” for matches that would require human
review before any further personal data could be exchanged.
The Commission recently emphasized this point to /Wired/
<https://www.wired.com/story/europe-police-facial-recognition-prum/>,
saying that “a human will review the potential matches and decide if any
of them are correct, before any further action is taken.”
The Council, however, has other plans. The latest proposed version of
the text deletes the requirement for human review, and instead makes it
optional:
/“The national contact point of the requesting Member State may decide
to manually confirm a match between two facial images. If so decided, it
shall inform the requested Member State and shall confirm this match
with facial images reference data received from the requested Member
State.”/
The implication is, then, that the matching of facial images should
generally be done automatically.
Here, as with DNA and other types of data covered by the new Prum
system, the Council has changed the requirement for searches to be
conducted “in compliance with national law” to “in respect of the same
guarantees and safeguards that are required for similar searches at
national level.”
*National DNA database content (stains and persons), 2021*
*State* *01-Jan-21* *31-Dec-21* *% change*
Belgium 101,098.00 108,049.00 7%
Bulgaria 43,611.00 56,736.00 30%
Czechia 277,213.00 287,357.00 4%
Denmark 163,614.00 172,574.00 5%
Germany 1,244,119.00 1,198,826.00 -4%
Estonia 74,259.00 78,874.00 6%
Greece 38,408.00 42,014.00 9%
Spain 441,165.00 460,309.00 4%
France 5,594,676.00 6,025,945.00 8%
Croatia 10,085.00 10,802.00 7%
Ireland 40,250.00 47,877.00 19%
Cyprus 18,565.00 19,432.00 5%
Latvia 72,930.00 77,215.00 6%
Lithuania 140,770.00 149,523.00 6%
Luxembourg 7,835.00 9,073.00 16%
Hungary 161,306.00 167,946.00 4%
Malta 799.00 156.00 -80%
Netherlands 379,826.00 398,931.00 5%
Austria 296,422.00 309,155.00 4%
Poland 117,287.00 161,702.00 38%
Portugal 14,163.00 14,163.00 0%
Romania 57,857.00 68,466.00 18%
Slovenia 32,948.00 33,684.00 2%
Slovakia 94,482.00 99,027.00 5%
Finland 207,651.00 212,412.00 2%
Sweden 209,048.00 211,814.00 1%
UK 6,337,964.00 6,446,391.00 2%
16,178,351.00 16,868,453.00 4%
/Figures for the UK are taken from the national DNA database statistics,
available here
<https://www.gov.uk/government/statistics/national-dna-database-statistics>./
April 20, 2022
the weaponization of the device (How Democracies Spy on Their Citizens)
by 380°
Buongiorno nexiane,
un lunghissimissimissimo articolo che spiega, ancora una volta, come lo
spyware venga utilizzato in tutto il mondo per ogni tipo di
operazione... e intendo proprio per /ogni/ tipo: dalla sorveglianza dei
dissidenti o nemici politici (europei inclusi) a quella dei consorti di
persone talmente ricche da potersi permettere di acquistare spyware (e
infrastrutture dedicate) /indipendentemente/ dagli ipocriti gestori dei
permessi di commercializzazione di quel software.
Sperano di fermare il fenomeno con dei procedimenti giudiziari, ipocriti
che non sono altro.
Nessuno pensi, anche solo per temporanea distrazione, che Pegasus sia
l'unico o il peggiore, perché sarebbe oltremodo offensivo.
Scusate la lunghezza dell'estratto, ho cercato di includere solo quello
che ritengo significativo.
https://www.newyorker.com/magazine/2022/04/25/how-democracies-spy-on-their-…
«How Democracies Spy on Their Citizens»
--8<---------------cut here---------------start------------->8---
[...] In Catalonia, more than sixty phones—owned by Catalan politicians,
lawyers, and activists in Spain and across Europe—have been targeted
using Pegasus. This is the largest forensically documented cluster of
such attacks and infections on record. Among the victims are three
members of the European Parliament, including Solé. Catalan politicians
believe that the likely perpetrators of the hacking campaign are Spanish
officials, and the Citizen Lab’s analysis suggests that the Spanish
government has used Pegasus. A former NSO employee confirmed that the
company has an account in Spain. (Government agencies did not respond to
requests for comment.) The results of the Citizen Lab’s investigation
are being disclosed for the first time in this article. I spoke with
more than forty of the targeted individuals, and the conversations
revealed an atmosphere of paranoia and mistrust. Solé said, “That kind
of surveillance in democratic countries and democratic states—I mean,
it’s unbelievable.”
[...] According to an analysis by the Citizen Lab, phones connected to
the Foreign Office were hacked using Pegasus on at least five occasions,
from July, 2020, through June, 2021. The government official confirmed
that indications of hacking had been uncovered. According to the Citizen
Lab, the destination servers suggested that the attacks were initiated
by states including the U.A.E., India, and Cyprus. (Officials in India
and Cyprus did not respond to requests for comment.) About a year after
the Downing Street hack, a British court revealed that the U.A.E. had
used Pegasus to spy on Princess Haya, the ex-wife of Sheikh Mohammed bin
Rashid al-Maktoum, the ruler of Dubai, one of the Emirates. Maktoum was
engaged in a custody dispute with Haya, who had fled with their two
children to the U.K. Her attorneys, who are British, were also targeted.
[...] A senior European law-enforcement official whose agency uses
Pegasus said that it gave an inside look at criminal organizations:
“When do they want to store the gas, to go to the place, to put the
explosive?” He said that his agency uses Pegasus only as a last resort,
with court approval, but conceded, “It’s like a weapon. . . . It can
always occur that an individual uses it in the wrong way.”
[...] Establishing strict rules about who can use commercial spyware is
complicated by the fact that such technology is offered as a tool of
diplomacy.
[...] “Everything that we are doing, we got the permission from the
government of Israel,” Hulio (uno dei fondatori di NGO, i produttori di
Pegasus, n.d.r.) told me. “The entire mechanism of regulation in Israel
was built by the Americans.”
[...] NSO sees itself as a type of arms dealer, operating in a field
without established norms.
[...] Hulio said, “I just remember that one day the lawsuit happened,
and they shut down the Facebook account of our employees, which was a
very bully move for them to do.” He added, referring to scandals about
Facebook’s role in society, “I think it’s a big hypocrisy.” NSO has
pushed for the suit to be dismissed, arguing that the company’s work on
behalf of governments should grant it the same immunity from lawsuits
that those governments have. So far, the U.S. courts have rejected this
argument.
[...] WhatsApp’s aggressive posture was unusual among big technology
companies, which are often reluctant to call attention to instances in
which their systems have been compromised. The lawsuit signalled a
shift. The tech companies were now openly aligned against the spyware
venders. Gheorghe described it as “the moment the whole thing just
exploded.”
[...] Microsoft, Google, Cisco, and others filed a legal brief in
support of WhatsApp’s suit. Goodwin, the Microsoft executive, helped to
assemble the coalition of companies. “We could not let NSO Group prevail
with an argument that, simply because a government is using your
products and services, you get sovereign immunity,” she told me. “The
ripple effect of that would have been so dangerous.” Hulio argues that
when governments use Pegasus they’re less likely to lean on platform
holders for wider “back door” access to users’ data. He expressed
exasperation with the lawsuit. “Instead of them, like, actually saying,
‘O.K., thank you,’ ” he told me, “they are going to sue us. Fine, so
let’s meet in court.”
[...] Israel has become the world’s most significant source of private
surveillance technology in part because of the quality of talent and
expertise produced by its military. “Because of the compulsory service,
we can recruit the best of the best,” the former senior intelligence
official told me. “The American dream is going from M.I.T. to
Google. The Israeli dream is to go to 8200,” the Israeli
military-intelligence unit from which spyware venders often recruit.
[...] In 2019, NSO was saddled with hundreds of millions of dollars in
debt as part of a leveraged-buyout deal in which a London-based
private-equity firm, Novalpina, acquired a seventy-per-cent
stake. Recently, Moody’s, the financial-services firm, downgraded NSO’s
credit rating to “poor,” and Bloomberg described it as a distressed
asset, shunned by Wall Street traders.
[...] “I know there have been misuses,” Hulio said. “It’s hard for me to
live with that. And I obviously feel sorry for that. Really, I’m not
just saying that. I never said it, but I’m saying it now.” Hulio said
that the company has turned down ninety customers and hundreds of
millions of dollars of business out of concern about the potential for
abuse. But such claims are difficult to verify.
[...] Asked about the extreme abuses ascribed to his technology, Hulio
invoked an argument that is at the heart of his company’s defense
against WhatsApp and Apple. “We have no access to the data on the
system,” he told me. “We don’t take part in the operation, we don’t see
what the customers are doing. We have no way of monitoring it.” When a
client buys Pegasus, company officials said, an NSO team travels to
install two racks, one devoted to storage and another for operating the
software. The system then runs with only limited connection to NSO in
Israel.
[...] The competition, Hulio argued, is far more frightening. “Companies
found themselves in Singapore, in Cyprus, in other places that don’t
have real regulation,” he told me. “And they can sell to whoever they
want.” The spyware industry is also full of rogue hackers willing to
crack devices for anyone who will pay. “They will take your computers,
they will take your phone, your Gmail,” Hulio said. “It’s obviously
illegal. But it’s very common now. It’s not that expensive.” Some of
the technology that NSO competes with, he says, comes from state actors,
including China and Russia. “I can tell you that today in China, today
in Africa, you see the Chinese government giving capabilities almost
similar to NSO.” According to a report from the Carnegie Endowment for
International Peace, China supplies surveillance tools to sixty-three
countries, often through private firms enmeshed with the Chinese
state. “NSO will not exist tomorrow, let’s say,” Hulio told me. “There’s
not going to be a vacuum. What do you think will happen?”
[...] Last month, the European Parliament formed a committee to look
into the use of Pegasus in Europe. Last week, Reuters reported that
senior officials at the European Commission had been targeted by NSO
spyware. The investigative committee, whose members include Puigdemont,
will convene for its first session on April 19th. Puigdemont called
NSO’s activities “a threat not only for the credibility of Spanish
democracy, but for the credibility of European democracy itself.”
[...] “People can survive and can adapt to almost any situation,” Hulio
once told me. NSO Group must now adapt to a situation in which its
flagship product has become a symbol of oppression. “I don’t know if
we’ll win, but we will fight,” he said. One solution was to expand the
product line. The company demonstrated for me an artificial-intelligence
tool, called Maestro, that scrutinizes surveillance data, builds models
of individuals’ relationships and schedules, and alerts law enforcement
to variations of routine that might be harbingers of crime. “I’m sure
this will be the next big thing coming out of NSO,” Leoz Michaelson, one
of its designers, told me. “Turning every life pattern into a
mathematical vector.”
[...] On his mother’s phone, which had been hacked eight times, the
researchers found a new kind of zero-click exploit, which attacked
iMessage and iOS’s Web-browsing engine. There is no evidence that
iPhones are still vulnerable to the exploit, which the Citizen Lab has
given the working name Homage. When the evidence was found,
Scott-Railton told Campo, “You’re not going to believe this, but your
mother is patient zero for a previously undiscovered exploit.”
--8<---------------cut here---------------end--------------->8---
bla bla bla bla... tutto /dovrebbe/ essere riassunto con questo unico
paragrafo:
--8<---------------cut here---------------start------------->8---
The exploit triggered two video calls in close succession, one joining
the other, with the malicious code hidden in their settings. The process
took only a few seconds, and deleted any notifications immediately
afterward. The code used a technique known as a “buffer overflow,”
[...] The company concluded that NSO had injected malicious code into
files in Adobe’s PDF format. It then tricked a system in iMessage into
accepting and processing the PDFs outside BlastDoor.
--8<---------------cut here---------------end--------------->8---
Ecco appunto, siamo fermi alla /preistoria/ dell'informatica, quando gli
exploit si attivavano con dei banalissimi buffer overflow e i documenti
binari potevano essere /eseguiti/ come codice macchina... bah?!?
Governanti, vi è mai venuto in mente di spendere almeno un decimo di
quello che spendete per /tentare/ di proteggere i dispositivi dei vostri
amici, o un centesimo di quello che spendete per attaccare i dispositivi
dei vostri nemici, per finanziare lo sviluppo di sistemi operativi
migliori (la sicurezza degli applicativi verrebbe via /gratis/)?... che
tra l'altro già ci sono :-O
Possibile che in questo regime chi sfrutta abili programmatori
sociopatici, che stanno svegli per due giorni di fila per trovare il
bit, sia in grado di fare soldi a palate nel settore
dell'informatica?... e chi non fa spyware fa software per profilare e
/controllare/ i comportamenti dei propri urtenti, mentre decine di
migliaia di hacker in tutto il mondo fanno cose che farebbero volentieri
a meno di fare e non riescono a dedicarsi a ciò che desiderano?!?
Gli spyware e i malware [1] non sono armi, sono /solo/ software, opere
letterarie, basta saperle leggere per comprenderle... e comprendere dove
non funzionano. C'è un sacco di gente che lo saprebbe fare e ancora di
più che saprebbe imparare a farlo, se solo ne avesse la possibilità.
Governanti, siete troppo pieni di voi per comprendere, non c'è altra
spiegazione.
Saluti, 380°
[1] https://www.gnu.org/proprietary/proprietary.html.en
«As of April, 2022, the pages in this directory list around 550
instances of malicious functionalities (with more than 650 references to
back them up), but there are surely thousands more we don't know about.»
--
380° (Giovanni Biscuolo public alter ego)
«Noi, incompetenti come siamo,
non abbiamo alcun titolo per suggerire alcunché»
Disinformation flourishes because many people care deeply about injustice
but very few check the facts. Ask me about <https://stallmansupport.org>.
April 20, 2022