nexa
By thread
nexa@server-nexa.polito.it
By month
Messages by month
- ----- 2026 -----
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
May 2024
- 43 participants
- 164 messages
MEMENTO | 172° Mercoledì di Nexa | 8 maggio 2024, ore 17.00
by Nexa - Media
Gentilissime, gentilissimi,
Vi ricordiamo che mercoledì 8 maggio, alle ore 17.00, si terrà il 172° Mercoledì di Nexa
con un incontro dal titolo " Evitare la trappola comportamentista e la confusione tra sistemi human-like e human-level in Intelligenza Artificiale con la Minimal Cognitive Grid".
Ospite dell'incontro: Antonio Lieto (Università di Salerno).
L'incontro si terrà IN PRESENZA e ONLINE.
SEDE FISICA dell'incontro: Centro Nexa su Internet e Società, Politecnico di Torino, Via Boggio 65/a, Torino (1° piano).
Per accedere alla sala si raccomanda di suonare al citofono Portineria e di seguire le indicazioni segnalate lungo il percorso.
QUI<https://nexa.polito.it/contatti> maggiori informazioni su come raggiungerci.
STANZA VIRTUALE dell'incontro: https://didattica.polito.it/VClass/NexaEvent
Maggiori informazioni alla pagina: https://nexa.polito.it/mercoledi-172
Cordiali saluti,
--
Valeria Bergantino
Communication Officer
Nexa Center for Internet & Society
Politecnico di Torino - DAUIN
Via Pier Carlo Boggio, 65/A - 10138 Torino
web: https://nexa.polito.it/
mail: valeria.bergantino(a)polito.it<mailto:valeria.bergantino@polito.it>
tel: 3473443585
May 6, 2024
DoJ closing arguments vs Google
by J.C. DE MARTIN
Jason Kint: "Department of Justice has now posted its hundreds of great
slides from closing arguments. I’ll share 13 slides that tell story imho
captured by this list."
https://twitter.com/jason_kint/status/1787185056345444735?s=61&t=EHwcK0mTbq…
Sequenza disponibile qui:
https://threadreaderapp.com/thread/1787185056345444735.html
jc
May 6, 2024
Re: [nexa] il buco è il protocollo SS7 (was "Il buco nella rete telefonica...")
by Damiano Verzulli
Il 05/05/24 7:36 PM, Cosmo Carabellese ha scritto:
> [...] da inesperto, mi chiedo come mai certe persone che sono
> ricercate, non da un malintenzionato qualsiasi ma addirittura da
> grandi potenze mondiali per eliminarle, non riescano a farlo così
> agevolmente.
Il motivo è presto detto (...riferito al thread che stiamo discutendo):
ad essere ricercate, sono le *PERSONE* (...e *NON* i loro cellulari...)
Dico questo, in quanto la premessa alla sua domanda, ossia questa:
> Buonasera, ho appreso da questa serie di e-mail della facilità con la
> quale può essere localizzato qualsiasi utilizzatore di uno smartphone...
è errata!
Il tema della vulnerabilita' di SS7, *NON* implica "/...la facilita' con
la quale puo' essere localizzato un utilizzatore di uno smartphone.../".
Implica soltanto "/...la facilita' con la quale puo' essere localizzato
uno smartphone [attivo].../"
Se l'utilizzatore reale (l'umano) riesce ad adoperarsi per far si che il
dispositivo mobile che sta utilizzando *NON* sia a lui riconducibile...
il problema è risolto. Se, viceversa, si distrae... e --magari senza
rendersene conto-- produce evidenze che associano il terminale mobile a
se stesso (persona), a quel punto il danno è fatto.... (grazie alla
vulnerabilita' di SS7 [...ed al "potere" di Google e Apple] [...e,
magari, a qualche APP che sbadatamente potrebbe aver installato]) e puo'
essere localizzato rapidissimamente.
La questione potrebbe sembrare sottile ma... non lo è: il primo altro
esempio che mi viene in mente è quello dei bitcoin. Tutti sventagliano a
destra ed a manca l'utilizzo di bitcoin come strumento utilissimo nelle
frodi finanziarie, in quanto, di fatto, "anonimo". Tuttavia il concetto
stesso di blockchain porta con se i massimi livelli di "tracciabilita'"
e di "verita'" nelle rispettive transazioni. Di fatto, quindi, un
"bitcoin" è anonimo soltanto fino a quando il relativo detentore riesce
a *NON* far scoprire a nessuno che è lui a tenerlo nel proprio wallet.
Faccio un esempio concreto: il 1707/2019 ho ricevuto una mail in cui un
cattivone sosteneva di aver violato i miei account e di aver "rubato" un
sacco di miei dati personali. Per non diffonderli mi chiedeva di pagare
250€ a questo "indirizzo": 18oAbhvp7ib8e1zNSVGFR3v8YmqiCeBoFu
Bene, a 5 anni di distanza, è possibile vedere come sebbene io *NON*
abbia pagato, quell'indirizzo è stato oggetto di due transazione "in
ingresso" (incassi) il 20/07/2019 [per complessivi ~1612 $] e due mesi
piu' tardi, il 26/09/2019 l'indirizzo è stato "svuotato":
https://www.blockchain.com/explorer/addresses/btc/18oAbhvp7ib8e1zNSVGFR3v8Y…
Di queste transazione è possibile conoscere tutti i dettagli e cosi',
ricorsivamente, è possibile analizzare le transazioni dei
mittenti/destinatari. Affinché tutto resti "anonimo" è fondamentale che
non si arrivi ad associare l'indirizzo al detentore... esattamente come
nel caso del cellulare.
Saluti,
DV
--
Damiano Verzulli
e-mail:damiano@verzulli.it
---
possible?ok:while(!possible){open_mindedness++}
---
"...I realized that free software would not generate the kind of
income that was needed. Maybe in USA or Europe, you may be able
to get a well paying job as a free software developer, but not
here [in Africa]..." -- Guido Sohne - 1973-2008
http://ole.kenic.or.ke/pipermail/skunkworks/2008-April/005989.html
May 5, 2024
The Current Villain: Eben Moglen & SFLC (parte 1)
by 380°
Buongiorno,
mi sono distratto (consapevolmente) un po' e non ero a conoscenza degli
ultimi sviluppi di questo capitolo del mega-drama che stiamo vivendo.
A prima vista, ma anche a seconda, potrebbe sembrare OT ma unendo i
puntini credo di intravedere una specie di trama che avvolge il mondo
del software libero.
Brevissima (ehrm) nota di contesto: il 3 Nov 2017 Software Freedom
Conservancy [1] (SFC) annuncia [2] che Software Freedom Law Center
(SFLC) [3] ha avviato il procedimento 92066968 al United States Patent
and Trademark Office (USPTO) per richiedere la cancellazione del marchio
di SFC [4]. La cosa creò non poco scompiglio [5] perché SFC è stata
avviata da SFLC nel 2006 e le due hanno tagliato i ponti all'inizio del
2011. Tre giorni dopo SFLC risponde [5] dicendo che avrebbero
volentieri conciliato prima di avviare quel procedimento ma che per tre
anni i vertici di SFC si sono rifuitati di discutere quella e altre
questioni. Il 22 Dic dello stesso anno SFLC propone pubblicamente un
accordo a SFC che prevede l'uso gratuito del marchio a patto di un
accordo di mutua non denigrazione (non-disparagement), aggiungendo che
le dichiarazioni rese nella richiesta di registrazione del marchio SFC
sono false e il marchio ottenuto in modo fraudolento [7], concludendo
con la reiterazione di un invito a conciliare nei termini indicati.
Sono passati più di sei anni all'avvio del procedimento e ancora USPTO
non è arrivata al dunque, nel frattempo la faccenda è montata a tal
punto da diventare non una montagna ma un'intera catena montuosa.
Finalmente, ecco l'ultimo episodio (articolo lunghissimo, estraggo i
punti a mio avviso salienti):
https://ebb.org/bkuhn/blog/2023/10/11/moglen-sflc.html
«Eben Moglen & SFLC — abusive employer & LGBTQIA+ unfriendly»
Wednesday 11 October 2023 by Bradley M. Kuhn
--8<---------------cut here---------------start------------->8---
[...]
With great trepidation, I have decided to make this public statement
regarding the psychological abuse, including menacing, that I
suffered, perpetrated by Eben Moglen, both while I was employed at his
Software Freedom Law Center (SFLC) from 2005-2010, and in the years
after he fired me. No one revels in having psychological injuries and
mistreatment they've suffered paraded to the public. I'll be frank
that if it were not for Moglen's use of the USA Trademark Trial and
Appeal Board (TTAB) as a method to perpetrate further abusive
behavior, I wouldn't have written this post. Furthermore, sadly,
Moglen has threatened in recent TTAB filings his intention to use the
proceeding to release personal details about my life to the public
(using the litigation itself as a lever). I have decided to
preemptively make public the facts herein first myself — so that I can
at least control the timing and framing of the information.
This post is long; the issues discussed in it are complicated,
nuanced, and cannot be summed up easily. Nevertheless, I'm realistic
that most people will stop reading soon, so I'll summarize now as best
I can in a few sentences: I worked initially with, and then /for/,
Eben Moglen for nearly a decade — during which time he was
psychologically abusive and gaslighted me (under the guise of training
and mentoring me). I thought for many years that he was one of my best
friends (— in retrospect, I believe that he tricked me into believing
that he was). As such, I shared extremely personal details about
myself to him — which he has used both contemporaneously and in years
hence to attempt to discredit me with my colleagues and
peers. Recently, Moglen declared his plans to use current TTAB
proceedings to force me to answer questions about my mental health in
deposition. Long ago, I disclosed key personal information to Moglen,
I therefore have a pretty good idea of what his next move will be
during that deposition questioning. Specifically, I believe Moglen was
hoping to out me as omni/bisexual as part of my deposition in this
proceeding. As such, I'm outing myself here first (primarily) to
disarm his ability to use what he knows about my sexual orientation
against me. Since that last sentence makes me already out, Moglen will
be unable to use the biggest “secret” that Moglen “has on me” in his
future psychological and legal attacks.
I suspect some folks will stop reading here, but I really urge that
you keep reading this post, and also to read the unrelated statement
made by [Conservancy] and [FSFE]. The details are important and
matter. I am admittedly embarrassed to talk publicly about how Moglen
exacerbated, expanded, and caused new symptoms of my Post-Traumatic
Stress Disorder (PTSD) — which I already suffered from when I met
him. But, I feel it is important to talk about these issues publicly
for many reasons [...]
The primary recent catalyst for this situation is as follows: Moglen
has insisted that, as part of the ongoing [trademark cancellation
petition that SFLC filed against my employer, Software Freedom
Conservancy] in the [TTAB], that Moglen both personally be allowed to
be present at, and to actually /take/ the depositions of me and my
colleague, Karen Sandler.
This kind of behavior is typical of how abusers use litigation to
perpetuate their abuse. The USA legal system is designed to give
everyone “their day in Court”. Frankly, many of the rules established
for Court proceedings did not contemplate that the process could be
manipulated by abusers, and it remains an open problem on how to
repair the rules that both preserve the egalitarian nature of our
legal system, but also does not make it easy for abusers to misuse
those same rules. Depositions, in particular, are a key tool in
abusers' arsenals. [...]
The only method (which is quite clunky as a legal tool) to curtail the
harassment somewhat is called a /protective order/. However, Moglen has
been smart enough to use the very process of the protective order
application to further perpetuate abusive behavior.
[...] Moglen has attempted to use the proceeding as a method to harass
and attack me and my colleague, Karen Sandler — regarding issues wholly
unrelated to the trademarks. The recent arguments have been about our
depositions — mine and Karen's.
After some complex legal back-and-forth, Judge [Elgin ordered that I
was legally required to sit for a deposition with and by Moglen]. This
is the point where a catch-22 began for me.
• Option 0: Sit in a room for 8+ hours with a person who had spent
years verbally abusing me and let him ask me /any question he wants/
— under penalty of perjury and contempt of Court if I refuse.
• Option 1: Give Conservancy's lawyers permission to talk openly, in
public documents, about the details of the abuse I suffered from
Moglen and the psychological harm that it caused me (which is the
necessary backup document for a protective order motion).
IOW, the only way to get a protective order that would prevent me from
being legally required to suffer further psychological abuse from
Moglen was to publicly talk about the past abuse 😩. I reluctantly
chose Option 1. [...]
Fortunately, that aforementioned sworn testimony was sufficient to
convince Judge Elgin to at least entertain reconsidering her decision
that I have to sit for a deposition with Moglen. However, submitting
the official motion /then/ required that I give even /more/
information about why the deposition with Moglen will be
psychologically harmful. In particular, I had little choice but to add
a letter from my (highly qualified) mental health provider speaking to
the psychological dangers that I would face if deposed by Moglen
personally and/or in his presence. I reluctantly asked my therapist to
[provide such a letter]. [...]
As can be seen in Moglen's response filing, [Moglen directly attacks
my therapist's credentials — claiming she is not credible nor
qualified]. Moglen's argument is that because my therapist is a
licensed, [AASECT]-certified sex therapist, she is not qualified to
diagnose PTSD. Of course, Moglen's argument is without merit: my
therapist's sex therapy credentials are in addition to her many other
credentials and certifications — all of which is explained on her
website that Moglen admits in his filing he has reviewed.
As I mentioned, at one time, I foolishly and erroneously considered
Moglen a good friend. As such, I told Moglen a lot about my personal
life, including that I was omni/bisexual, and that I was (at the time)
closeted. So, Moglen already knows full well the reason that I would
select a therapist who held among her credentials a certification to
give therapy relating to sexuality. Moglen's filing is, in my view, a
veiled threat to me that he's going to disclose publicly what he knows
about my sexuality as part of this proceeding. So, I've decided —
after much thought — that I should simply disarm him on this and say
it first: I have identified as bisexual/omnisexual since 1993 [...]
Despite the serious psychological abuse I've suffered from Moglen,
until this recent filing, I wouldn't have imagined that Moglen would
attempt to use the secrecy about my LGBTQIA+ status as a way to
further terrorize me. [...]
The fact that he [goes on to further claim that the mere fact that she
has such certification makes her unqualified] to treat my other mental
health illness — some of which Moglen himself (in part) personally
caused — is unconscionable. [...]
Moglen has insisted now that my therapy has been brought up in the
proceeding, that [he has a legal right to force me to be evaluated by a
therapist of his choosing] (as if I were a criminal defendant). [...]
Now, /even if/ the judge grants Conservancy's motion to exclude Moglen
from my deposition, Moglen will instruct his attorneys to ask me those
questions about my therapy and my sexual orientation — with the obvious
goal of seeking to embarrass me by forcing me to reveal such things
publicly. [...]
I am aghast that Moglen is trying to shame me for seeking help
from a mental health provider who could help me overcome my
internalized shame regarding my sexual orientation. I also want
people to know that I did not feel safe as a queer person when I
worked for Eben Moglen at SFLC. But I also know Moglen doesn't
represent what our FOSS community and software freedom is about. I
felt I needed to make this post not only to disarm the power
Moglen held to “out me” before I was ready, but also to warn
others that, in my opinion, Software Freedom Law Center (SFLC) as
an organization that is *not* a safe space for LGBTQIA+
folks. Finally, I do know that Moglen is also a tenured professor
at Columbia Law School. I have so often worried about his students
— who may, as I did, erroneously believe they can trust Moglen
with private information as important as their LGBTQIA+ status. I
simply felt I couldn't stay silent about my experiences in good
conscience any longer.
――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――
Footnote added *2023-10-12, 19:00 US/Eastern*: Since I posted this
about 30 hours ago, I've gotten so many statements of support
emailed to me that I can't possibly respond to them all, but I'll
try. Meanwhile, a few people have hinted at and/or outright asked
what policy disagreements Moglen actually has with me. I was
reluctant to answer because the point I'm making in this post is
that /even if/ Moglen thought every last thing I've ever done in
my career was harmful policy-wise, it *still would not justify*
these abusive behaviors. Nevertheless, I admit that if this post
were made by someone else, I'd be curious about what the policy
disagreements were, so I decided to answer the question. I think
that my overarching policy disagreement with Eben Moglen is with
regard to how and when to engage in enforcement of the GPL and
other copyleft licenses through litigation. I think Moglen
explains this policy disagreement best in [his talk that the Linux
Foundation contemporaneously promoted (and continues to regularly
reference) entitled “Whither (Not Wither) Copyleft”]. In this
talk, Moglen states that I (among others) are “on a jihad for free
software” (his words, direct quote) because we continued to pursue
GPL enforcement through litigation. While I agree that [litigation
should still remain the last resort], I do think it remains a
necessary step often. Moglen argues that even though litigation
was needed in the past, it should never be used again for copyleft
and GPL enforcement. As Moglen outlines in his talk, he supports
the concept of “spontaneous compliance” — a system whereby there
is no regulatory regime and firms simply chose to follow the rules
of copyleft because it's so obviously in their own best
interest. I've not seen this approach work in practice, which is
why I think we must still sometimes file GPL (and LGPL) lawsuits —
[even today]. Moglen and I have plenty of other smaller policy
disagreements: from appropriate copyright assignment structures
for FOSS, to finer points of how GPLv3 should have been drafted,
to tactics and strategy with regard to copyleft advocacy, to how
non-profits and charities should be structured for the betterment
of FOSS. However, I suspect all these smaller policy disagreements
stem from our fundamental policy disagreement about GPL
enforcement. However, I conclude by (a) saying again *no policy
disagreement with anyone justifies abusive behavior toward that
person — not ever*, and (b) please do note the irony that, in that
2016-11-02 speech, Moglen took the position that lawsuits should
no longer be used to settle disputes in FOSS, and yet — less than
10 months later — [Moglen sued Conservancy (his former client) in
the TTAB].
Posted on Wednesday 11 October 2023 at 13:15 by Bradley M. Kuhn.
Submit comments on this post to [[<mailto:bkuhn@ebb.org>][]].
--8<---------------cut here---------------end--------------->8---
[1] https://en.wikipedia.org/wiki/Software_Freedom_Conservancy
[2] https://sfconservancy.org/blog/2017/nov/03/sflc-legal-action/
[3] https://en.wikipedia.org/wiki/Software_Freedom_Law_Center
[4] https://ttabvue.uspto.gov/ttabvue/v?qt=adv&procstatus=All&pno=92066968
[5] https://www.theregister.com/2017/11/20/foss_sflc_sfc_gpl_trademark/
[6] https://softwarefreedom.org/blog/2017/nov/06/conservancy-stmt/
[7] https://softwarefreedom.org/blog/2017/dec/22/conservancy/
--
380° (Giovanni Biscuolo public alter ego)
«Noi, incompetenti come siamo,
non abbiamo alcun titolo per suggerire alcunché»
Disinformation flourishes because many people care deeply about injustice
but very few check the facts. Ask me about <https://stallmansupport.org>.
May 5, 2024
Re: [nexa] il buco è il protocollo SS7 (was "Il buco nella rete telefonica...")
by Cosmo Carabellese
Buonasera, ho appreso da questa serie di e-mail della facilità con la quale
può essere localizzato qualsiasi utilizzatore di uno smartphone, tuttavia,
da inesperto, mi chiedo come mai certe persone che sono ricercate, non da
un malintenzionato qualsiasi ma addirittura da grandi potenze mondiali per
eliminarle, non riescano a farlo così agevolmente.
Grazie.
Cosmo Carabellese.
Il giorno ven 3 mag 2024 alle ore 16:16 380° <g380(a)biscuolo.net> ha scritto:
> Buongiorno,
>
> interessante inchiesta, grazie.
>
> A nessuno che si occupi di telecominicazioni dovrebbe essere concesso il
> lusso di _questa_ ignoranza :-)
>
> A nessuno che possieda un telefono cellulare dovrebbe essere concesso il
> lusso di ignorare che quel dispositivo può essere _facilissimamente_
> tracciato ormai da qualsiasi "ladro di polli".
>
> Le scene dei film nelle quali le spie usano cellulari usa e getta non
> sono /fantasy/ :-D
>
> "J.C. DE MARTIN" <juancarlos.demartin(a)polito.it> writes:
>
> [...]
>
> > Nonostante gli addetti ai lavori ne siano al corrente da anni, le
> > vulnerabilità della rete telefonica continuano a non essere mitigate,
> > permettendo ad attori malevoli di geolocalizzare un’utenza telefonica
> > nel mondo
> >
> > 03.05.24
>
> [...]
>
> > continua qui:
> >
> https://irpimedia.irpi.eu/setelefonando-reti-telefoniche-telefoni-geolocali…
>
> --8<---------------cut here---------------start------------->8---
>
> L’inchiesta in breve
>
> * Con qualche migliaio di dollari chiunque può comprare l’accesso alla
> rete telefonica e diventare titolare di servizi di gestione un tempo
> pensati solamente per i grandi operatori
>
> * Tra questi servizi c’è anche l’accesso ai nodi di rete che comunicano
> con il protocollo SS7, una serie di istruzioni che facilitano anche il
> funzionamento di un’utenza telefonica in un Paese estero, nel caso del
> cosiddetto roaming
>
> * Sfruttando in modo illegittimo il protocollo SS7 un dispositivo mobile
> rischia di essere geolocalizzato ovunque nel mondo: è intorno a questa
> caratteristica che è sorto negli anni un vero e proprio mercato in cui
> le società di sorveglianza fanno da padroni
>
> * Purtroppo però nessuno sembra voler risolvere il problema: la rete è
> così configurata in quanto pensata per pochi attori affidabili ma
> l’accesso a soggetti terzi è aumentato con il tempo
>
> * Nonostante il problema sia noto da anni non è chiaro quante compagnie
> telefoniche adottino misure di sicurezza adeguate e quante svolgano una
> corretta due diligence sui locatari a cui forniscono l’accesso
>
> * L’Agenzia dell’Unione europea per la cybersicurezza collaborerà con
> gli Stati membri per sensibilizzare su questo tipo di attacchi e
> garantire che gli operatori di telecomunicazioni adottino misure
> adeguate per prevenirli.
>
> [...] «gli spyware sono solo la punta dell’iceberg della sorveglianza»
> poiché molte altre vulnerabilità della rete telefonica sono sfruttate
> impunemente da attori malintenzionati.
>
> [...] La possibilità di localizzare un numero di telefono non è dovuta a
> una vera e propria vulnerabilità informatica ma piuttosto a una
> questione di fiducia e di design del sistema di interconnessione tra gli
> operatori telefonici.
>
> [...] Il problema non si è risolto nemmeno nel 2012 con l’introduzione
> del 4G e del protocollo Diameter, che svolge le stesse funzioni di SS7
> ma ne eredita anche i problemi.
>
> [...] In Italia a monitorare sugli operatori di telecomunicazioni sarà
> l’Agenzia per la Cybersicurezza Nazionale (Acn) che già se ne occupa
> nell’ambito del Codice delle comunicazioni elettroniche.
>
> Acn ha respinto una richiesta di commento sullo stato della sicurezza
> degli operatori telefonici italiani, riguardo a eventuali statistiche
> sul numero di attacchi che sono stati notificati e su quanti operatori
> hanno introdotto firewall e sistemi per filtrare messaggi SS7 sospetti.
>
> --8<---------------cut here---------------end--------------->8---
>
> Eh sì, le "Agenzie" fanno chiacchiere, tante chiacchiere, solo
> chiacchiere... anzi no _propaganda_ (dobbiamo difenderci dagli stati
> canaglia!)
>
> Intanto /ingenuamente/ mi chiedo se mai qualcuno di quelli pizzicati a
> fare - o a favorire - sorveglianza _illegale_ siano mai stati condannati
> anche solo a scrivere 50 volte sulla lavagna "non lo faccio più" :-O
>
> Io so solo che per avere una cavolo di SIM _devo_ identificarmi e mi
> beccherebbero /prima/ di commettere un reato indossando il mio
> cellulare.
>
> Intanto, _tecnicamente_ le cose per il protocollo SS7 stanno male, ma
> proprio malissimo:
>
> https://en.wikipedia.org/wiki/Signalling_System_No._7#Protocol_security_vul…
>
> Mentre si stanno spendendo cifre considerevoli per passare al 5G, il
> protocollo che serve a:
>
> --8<---------------cut here---------------start------------->8---
>
> stabilire e terminare le chiamate telefoniche nella maggior parte della
> rete telefonica pubblica commutata mondiale (PSTN) [...] esegue inoltre
> la traduzione dei numeri, la portabilità dei numeri locali, la
> fatturazione prepagata, il servizio SMS (Short Message Service) e altri
> servizi.
>
> --8<---------------cut here---------------end--------------->8---
> (https://en.wikipedia.org/wiki/Signalling_System_No._7)
>
> e che è stato progettato coi piedi nel 1970 e la cui ultima versione è
> del 1993, continua ad essere utilizzato come se niente fosse, senza che
> nessuno ci metta quattro risorse per rimpiazzarlo con uno fatto bene.
>
> Sarà un caso... :-D
>
> Saluti, 380°
>
>
>
> P.S.: comunque resta il fatto che, grazie alla triangolazione radio,
> /qualcuno/ potrà sempre identificare _qualsiasi_ telefono cellulare,
> considerato che per avere una SIM occorre identificarsi... tranne se sei
> un criminale.
>
> --
> 380° (Giovanni Biscuolo public alter ego)
>
> «Noi, incompetenti come siamo,
> non abbiamo alcun titolo per suggerire alcunché»
>
> Disinformation flourishes because many people care deeply about injustice
> but very few check the facts. Ask me about <https://stallmansupport.org>.
>
--
Cosmo Carabellese
May 5, 2024
Re: [nexa] il buco è il protocollo SS7 (was "Il buco nella rete telefonica...")
by 380°
Buongiorno Andrea,
Andrea Barontini via nexa <nexa(a)server-nexa.polito.it> writes:
> che SS7 e' un colabrodo si sa da anni, forse oggigiorno e' piu' facile
> interfacciarvisi, ma non e' che la cosa fosse meno grave prima quando
> probabilmente la platea dei soggetti che potevano abusarne era piu'
> contenuta.
concordo, è che ogni tanto anche gli addetti ai lavori hanno dei vuoti
di memoria :-D
> Sicuramente ci sara' del debito tecnologico indotto da piu' o meno
> pressanti questioni di compatibilita',
chiunque sostenga seriamente questa cosa dice balle, gestiti seriamente
i problemi tecnici di SS7 avrebbero _dovuto_ essere risolti già col
3G... ma come? Con la crittografia forte basata su certificati
rilasciati dalle CA? :-O
...almeno avrebbero segato via gli usi illegali ad opera di
organizzazioni non direttamente o indirettamente affiliate con agenzie
di spionaggio di livello internazionale
poi magari, un giorno lontano lontano, qualcuno si deciderà a risolvere
seriamente la questione una volta per tutte: tecnologicamente. Spoiler:
e2e encryption a partire dal layer 5 (session) del modello ISO/OSI
(application layer del Internet protocol suite)... che implica
_connessioni_anonime_ *anche* per la telefonia (che ormai è solo VoIP da
un pezzo).
[...]
> Altri due posti in cui potrebbe essere divertente ficcare il naso in tal
> senso sono BGP
sfondi una porta aperta, qualcosa mi pare di aver scritto anche qui in
passato :-); BTW sulla schifezza che è BGP si sa già tutto da moltissimi
anni, executive summary:
--8<---------------cut here---------------start------------->8---
By design, routers running BGP accept advertised routes from other BGP
routers by default. This allows for automatic and decentralized routing
of traffic across the Internet, but it also leaves the Internet
potentially vulnerable to accidental or malicious disruption, known as
BGP hijacking. Due to the extent to which BGP is embedded in the core
systems of the Internet, and the number of different networks operated
by many different organizations which collectively make up the Internet,
correcting this vulnerability (such as by introducing the use of
cryptographic keys to verify the identity of BGP routers) is a
technically and economically challenging problem.
--8<---------------cut here---------------end--------------->8---
(https://en.wikipedia.org/wiki/Border_Gateway_Protocol#Security)
> e le informazioni societarie dietro le Certification Authority e i
> gestori VPN
ti piace giocare pesante eh :-D LOL!
[...]
Ciao, 380°
--
380° (Giovanni Biscuolo public alter ego)
«Noi, incompetenti come siamo,
non abbiamo alcun titolo per suggerire alcunché»
Disinformation flourishes because many people care deeply about injustice
but very few check the facts. Ask me about <https://stallmansupport.org>.
May 5, 2024
Google fired a software engineer over an anti-war demonstration — he says he wasn’t even protesting
by J.C. DE MARTIN
*Google fired a software engineer over an anti-war demonstration — he
says he wasn’t even protesting
*
/In an NLRB complaint filed today, more than 50 other employees have
alleged unlawful retaliation and are asking for their jobs back.
/
By Gaby Del Valle, a policy reporter. Her past work has focused on
immigration politics, border surveillance technologies, and the rise of
the New Right.
Apr 30, 2024, 9:57 PM GMT+2
A software engineer who was fired from Google in connection to internal
protests at the company’s offices says the company retaliated against
him for merely watching the demonstration against an Israeli defense
contract.
The former employee, who asked to remain anonymous, said he went to the
lounge on the 10th floor of Google’s New York City office around
lunchtime to check out the protest.
“When I got there, there were probably 20-ish people sitting on the
floor. I didn’t talk to any of them, I talked to folks who were standing
up, passing out flyers, doing other roles,” he said, adding that the
protesters were wearing matching T-shirts.
[...]
continua qui:
https://www.theverge.com/2024/4/30/24145680/google-workers-fired-project-ni…
May 5, 2024
Venezia, contributo di accesso e Smart Control Room - Smart Controlled - Ep1
by Fabio Alemagna
Segnalo questa interessante inchiesta giornalistica di Alberto
Puliafito e suoi collaboratori, in merito alla sorveglianza e
tracciamento delle persone, con relative implicazioni sulla privacy.
Qui il link: https://www.youtube.com/watch?v=LKFC0pvBsxA
La sinossi:
«Si può tracciare un telefono con i dati di geolocalizzazione dello
smartphone? Le "smart city" sono un rischio per la libertà e la
privacy delle persone? Il caso di Venezia: la Smart Control Room e il
contributo di accesso dal 25 aprile 2024.
La Smart Control Room di Venezia è stata finanziata anche con i fondi
della politica di coesione europea, la più grande politica di
redistribuzione della ricchezza in Europa, pensata per contrastare le
disuguaglianze, migliorare le condizioni di vita nelle aree dove ci
sono contesti di minore sviluppo, rafforzare la coesione economica,
sociale e territoriale. Ma è questo che fa la Smart Control Room? È
davvero un aiuto per tutte le persone che vivono Venezia e per la
città?»
May 4, 2024
Forum InformatikerInnen für Frieden und gesellschaftliche Verantwortung: Abbassare la soglia di inibizione attraverso il ricorso all'intelligenza artificiale è un crimine di guerra
by Daniela Tafani
Position paper (in tedesco) del forum tedesco degli scienziati informatici per la pace e la responsabilità sociale:
Il Forum scienziati informatici per la pace e la responsabilità sociale, il Gruppo di lavoro contro i droni armati e il Centro d'informazione sulla militarizzazione
chiedono che la pratica dell'uccisione mirata con sistemi di supporto come Lavender sia considerata un crimine di guerra.
Citazione in exergo:
Persone, cose ed eventi diventano "dati programmabili". Si tratta di "input" e "output", variabili, percentuali, processi e simili,
fino a quando ogni connessione con le cose concrete viene eliminata e rimangono solo grafici astratti, colonne di numeri ed espressioni.
Joseph Weizenbaum
Qui il testo:
https://blog.fiff.de/content/files/2024/04/2024_04_29_Stellungnahme-lavende…
May 4, 2024
Re: [nexa] il buco è il protocollo SS7 (was "Il buco nella rete telefonica...")
by Andrea Barontini
Buondi'
che SS7 e' un colabrodo si sa da anni, forse oggigiorno e' piu' facile
interfacciarvisi, ma non e' che la cosa fosse meno grave prima quando
probabilmente la platea dei soggetti che potevano abusarne era piu'
contenuta.
Sicuramente ci sara' del debito tecnologico indotto da piu' o meno
pressanti questioni di compatibilita', ma ritengo che -visto da quanto
si sa e la portata della cosa- sicuramente ci sia anche una componente
di inerzia volontaria e non economica. ("Ora ci pensa la UE"... vedremo...)
Altri due posti in cui potrebbe essere divertente ficcare il naso in tal
senso sono BGP e le informazioni societarie dietro le Certification
Authority e i gestori VPN
Ciauz :)
Andrea
Il 03/05/24 16:16, 380° ha scritto:
> Buongiorno,
>
> interessante inchiesta, grazie.
>
> A nessuno che si occupi di telecominicazioni dovrebbe essere concesso il
> lusso di _questa_ ignoranza :-)
>
> A nessuno che possieda un telefono cellulare dovrebbe essere concesso il
> lusso di ignorare che quel dispositivo può essere _facilissimamente_
> tracciato ormai da qualsiasi "ladro di polli".
>
> Le scene dei film nelle quali le spie usano cellulari usa e getta non
> sono /fantasy/ :-D
>
> "J.C. DE MARTIN" <juancarlos.demartin(a)polito.it> writes:
>
> [...]
>
>> Nonostante gli addetti ai lavori ne siano al corrente da anni, le
>> vulnerabilità della rete telefonica continuano a non essere mitigate,
>> permettendo ad attori malevoli di geolocalizzare un’utenza telefonica
>> nel mondo
>>
>> 03.05.24
>
> [...]
>
>> continua qui:
>> https://irpimedia.irpi.eu/setelefonando-reti-telefoniche-telefoni-geolocali…
>
> --8<---------------cut here---------------start------------->8---
>
> L’inchiesta in breve
>
> * Con qualche migliaio di dollari chiunque può comprare l’accesso alla
> rete telefonica e diventare titolare di servizi di gestione un tempo
> pensati solamente per i grandi operatori
>
> * Tra questi servizi c’è anche l’accesso ai nodi di rete che comunicano
> con il protocollo SS7, una serie di istruzioni che facilitano anche il
> funzionamento di un’utenza telefonica in un Paese estero, nel caso del
> cosiddetto roaming
>
> * Sfruttando in modo illegittimo il protocollo SS7 un dispositivo mobile
> rischia di essere geolocalizzato ovunque nel mondo: è intorno a questa
> caratteristica che è sorto negli anni un vero e proprio mercato in cui
> le società di sorveglianza fanno da padroni
>
> * Purtroppo però nessuno sembra voler risolvere il problema: la rete è
> così configurata in quanto pensata per pochi attori affidabili ma
> l’accesso a soggetti terzi è aumentato con il tempo
>
> * Nonostante il problema sia noto da anni non è chiaro quante compagnie
> telefoniche adottino misure di sicurezza adeguate e quante svolgano una
> corretta due diligence sui locatari a cui forniscono l’accesso
>
> * L’Agenzia dell’Unione europea per la cybersicurezza collaborerà con
> gli Stati membri per sensibilizzare su questo tipo di attacchi e
> garantire che gli operatori di telecomunicazioni adottino misure
> adeguate per prevenirli.
>
> [...] «gli spyware sono solo la punta dell’iceberg della sorveglianza»
> poiché molte altre vulnerabilità della rete telefonica sono sfruttate
> impunemente da attori malintenzionati.
>
> [...] La possibilità di localizzare un numero di telefono non è dovuta a
> una vera e propria vulnerabilità informatica ma piuttosto a una
> questione di fiducia e di design del sistema di interconnessione tra gli
> operatori telefonici.
>
> [...] Il problema non si è risolto nemmeno nel 2012 con l’introduzione
> del 4G e del protocollo Diameter, che svolge le stesse funzioni di SS7
> ma ne eredita anche i problemi.
>
> [...] In Italia a monitorare sugli operatori di telecomunicazioni sarà
> l’Agenzia per la Cybersicurezza Nazionale (Acn) che già se ne occupa
> nell’ambito del Codice delle comunicazioni elettroniche.
>
> Acn ha respinto una richiesta di commento sullo stato della sicurezza
> degli operatori telefonici italiani, riguardo a eventuali statistiche
> sul numero di attacchi che sono stati notificati e su quanti operatori
> hanno introdotto firewall e sistemi per filtrare messaggi SS7 sospetti.
>
> --8<---------------cut here---------------end--------------->8---
>
> Eh sì, le "Agenzie" fanno chiacchiere, tante chiacchiere, solo
> chiacchiere... anzi no _propaganda_ (dobbiamo difenderci dagli stati
> canaglia!)
>
> Intanto /ingenuamente/ mi chiedo se mai qualcuno di quelli pizzicati a
> fare - o a favorire - sorveglianza _illegale_ siano mai stati condannati
> anche solo a scrivere 50 volte sulla lavagna "non lo faccio più" :-O
>
> Io so solo che per avere una cavolo di SIM _devo_ identificarmi e mi
> beccherebbero /prima/ di commettere un reato indossando il mio
> cellulare.
>
> Intanto, _tecnicamente_ le cose per il protocollo SS7 stanno male, ma
> proprio malissimo:
> https://en.wikipedia.org/wiki/Signalling_System_No._7#Protocol_security_vul…
>
> Mentre si stanno spendendo cifre considerevoli per passare al 5G, il
> protocollo che serve a:
>
> --8<---------------cut here---------------start------------->8---
>
> stabilire e terminare le chiamate telefoniche nella maggior parte della
> rete telefonica pubblica commutata mondiale (PSTN) [...] esegue inoltre
> la traduzione dei numeri, la portabilità dei numeri locali, la
> fatturazione prepagata, il servizio SMS (Short Message Service) e altri
> servizi.
>
> --8<---------------cut here---------------end--------------->8---
> (https://en.wikipedia.org/wiki/Signalling_System_No._7)
>
> e che è stato progettato coi piedi nel 1970 e la cui ultima versione è
> del 1993, continua ad essere utilizzato come se niente fosse, senza che
> nessuno ci metta quattro risorse per rimpiazzarlo con uno fatto bene.
>
> Sarà un caso... :-D
>
> Saluti, 380°
>
>
>
> P.S.: comunque resta il fatto che, grazie alla triangolazione radio,
> /qualcuno/ potrà sempre identificare _qualsiasi_ telefono cellulare,
> considerato che per avere una SIM occorre identificarsi... tranne se sei
> un criminale.
>
May 3, 2024