Category: security | 保衛 | 정보 보안 | 情報セキュリティー

According to Wikipedia security can be defined:

Security is protection from, or resilience against, potential harm (or other unwanted coercive change) caused by others, by restraining the freedom of others to act. Beneficiaries (technically referents) of security may be of persons and social groups, objects and institutions, ecosystems or any other entity or phenomenon vulnerable to unwanted change. Security mostly refers to protection from hostile forces, but it has a wide range of other senses: for example, as the absence of harm (e.g. freedom from want); as the presence of an essential good (e.g. food security); as resilience against potential damage or harm (e.g. secure foundations); as secrecy (e.g. a secure telephone line); as containment (e.g. a secure room or cell); and as a state of mind (e.g. emotional security).

Back when I started writing this blog, hacking was something that was done against ‘the man’, usually as a political statement. Now breaches are part of organised crime’s day to day operations. The Chinese government so thoroughly hacked Nortel that all its intellectual property was stolen along with commercial secrets like bids and client lists. The result was the firm went bankrupt. Russian ransomware shuts down hospitals across Ireland. North Korean government sanctioned hackers robbed 50 million dollars from the central bank of Bangladesh and laundered it in association with Chinese organised crime.

Now it has spilled into the real world with Chinese covert actions, Russian contractors in the developing world and hybrid warfare being waged across central Europe and the middle east.

  • Ikea Symfonisk speaker and other things that caught my eye this week

    A great YouTube teardown of the Ikea Symfonisk bookshelf speaker. The speaker works with a Sonos equipped home and was designed in conjunction with Sonos. The Symfonisk bookshelf speaker is part of a range. They’re built for convenience rather than high fidelity.

    Don’t expect it to last long after its warranty is over. The Sonos product design on which it’s based doesn’t deserve the premium that has been put on it historically. The Symfonisk looks like a low quality product which exists to help Ikea and Sonos cross-sell and upsell consumers on other products.

    The Trump supporters protest ‘Stop the Steal ‘looked to an outsider like an absurdist performative art performance that went wrong with criminal damage and five dead at the time of writing.

    https://twitter.com/dublonothing/status/1347078502412009476

    If like me, you were left wondering what just happened? And then asking yourself what on earth is QAnon? Bellingcat has you covered.

    At the moment American politicians are calling it a coup attempt and asking for the participants to be locked up and prosecuted to the full extent of the law. I get it. What the politicians are failing to do is come up with the better, more attractive belief system than QAnon. I think that’s a problem. It’s why over 25 years after the Oklahoma City bombing, the far right is stronger than ever.

    Jailing participants creates as many problems as it solves. It provides martyrs to a cause, like McVeigh became. But not jailing them says that their conduct is within the realm of respectability. As for a better idea, you could do worse than look at the Depolarization Project.

    Stop The Steal, January 6, 2021 St. Paul, Minn.
    Protestors out side the Governors residence in St Pauls, Minnesota as part of the Stop The Steal protests / coup attempt.

    Drum and Bass seems to be having a renaissance, with it getting more prominence in the likes of Mixmag and elsewhere. A great example is this recent guest mix by Carl Cox for Edible Beats.

    Sony’s Trinitron was a byword for the best quality TV experience when CRTs ruled display technology. This history of the technology shows Sony at its engineering best for decades.

  • Knowledge economy + more things

    How does the UK rank as a knowledge economy? – Soft MachinesThe big story is the huge rise of China, and in this context, inevitable that the rest of the world’s share of the advanced economy has fallen. But the UK’s fall is larger than competitors (-46%, cf -19% for the USA and -13% for rest of EU) – the definition of knowledge economy used in the research doesn’t play to the UK’s strengths in areas like financial services, education, legal services, accounting services and advertising. But there is no denying the overall pattern, that the UK failed to make the knowledge economy work for it in the same way that China, the US or the EU have managed to do over the last decade

    Do You Want to Buy Less Stuff? Three People Tell Us How – The New York Times – a few things about this. Ms Chai has a lot of nice things, it would be harder to do this if you were starting off with Ikea furnishing for instance

    Cultural institutions in crisis | Financial TimesFinancial losses from Covid-19 are not the only challenges museums face. Well before the pandemic, environmental and social activists were holding western institutions vigorously to account. Museums were already struggling with issues of diversity — both in staffing and, more importantly, in representation in their collections — the status of objects in those collections and calls for restitution. The situation is further complicated by criticism of many traditional sources of philanthropic funding and ongoing concern for the environment. The Black Lives Matter movement and other world events put a renewed spotlight on racism, illuminating the “white gaze” of western institutions. Even as museums scrambled to promise that change was afoot, they found themselves ensnared in further criticism. “Did our lives matter when you STOLE ALL OUR THINGS?” retorted writer Stephanie Yeboah when Hartwig Fischer, director of the British Museum, tweeted solidarity for Black Lives Matter (paywall)

    As Understanding of Russian Hacking Grows, So Does Alarm – The New York TimesBy staging their attacks from servers inside the United States, in some cases using computers in the same town or city as their victims, according to FireEye, the Russians took advantage of limits on the National Security Agency’s authority. Congress has not given the agency or homeland security any authority to enter or defend private sector networks. It was on these networks that S.V.R. operatives were less careful, leaving clues about their intrusions that FireEye was ultimately able to find. By inserting themselves into the SolarWinds’ Orion update and using custom tools, they also avoided tripping the alarms of the “Einstein” detection system that homeland security deployed across government agencies to catch known malware, and the so-called C.D.M. program that was explicitly devised to alert agencies to suspicious activity (paywall)

    Why Markets Boomed in a Year of Human Misery – The New York Times – the jobs lost were low wages compared to the knowledge workers who benefited from home working with increased savings

    Tesla blasts ‘ridiculously fabricated’ report raising quality concerns at Shanghai plantgiga sweatshop is quite a catchy sound bite

    The way we train AI is fundamentally flawed | MIT Technology Review 

    Why 2021 will be a bumper year for M&A | Vogue Businessthe big three trends for M&A in 2021: conglomerates looking for an opportunity to consolidate, luxury brands stepping up vertical integration by investing in distressed parts of their supply chain, and a focus on investment in digital expertise and the APAC region. – more luxury related content here.

  • CD ROM history + more news

    CD ROM reflections

    How “God Makes God” is a 1993 CD ROM about probability, game theory, genetic algorithms, and evolutionary strategies | Boing Boing – I remember having my mind blown by this CD ROM at college. It reminded me of Jostein Gaarder’s book Sophie’s World in terms of its approach to making philosophy entertaining and accessible. I remember reading Sophie’s World around the same time as having played How God Makes God. There was something about HyperCard and the CD ROM authoring tools that followed. Amidst all the brochureware there were creators who drove extraordinary media projects, most notably for me was the game Myst, which I don’t think has been bettered. I suspect part of it was the excitement of new ‘hyper-media’, the limitations of the tools (though 640MB storage at the time seemed vast when I was using an Apple PowerBook 165 with 4MB of RAM and an 80MB hard drive at the time) and the media economics of the time. CD-ROM authoring tools were becoming more sophisticated. CD manufacturing plants were proliferating, lowering the cost per CD ROM disk and CD recordable drives were relatively affordable in the price range of $10,000 – $20,000. Still eye wateringly expensive, but this was a vast improvement from just two years before and allowed for better prototyping, small production runs and testing across devices.

    Design

    3D printed IKEA hack experiences by Uppgradera on Etsy – really interesting aspects to the designs

    Ethics

    Instacart Is a Parasite and a Sham | The New RepublicThe gig economy company, like many of its peers, has seen business skyrocket during the pandemic—while exploiting workers and even failing to turn a profit. That last bit reminds me a lot of the first generation dot com companies who tried to break through the wall of economics and succeed by moving at internet speed. This time they seem to have supplemented the usual ‘throw money at it’ approach with a lack of morality

    Ideas

    How Claude Shannon’s Information Theory Invented the Future | Quanta Magazine – the idea of binary encrypted signals

    Innovation

    Activist Firm Urges Intel to ‘Explore Alternatives’ to Manufacturing Its Own Chips – ExtremeTech – there are national security issues with this. I suspect this is just an opening salvo by Dan Loeb

    Regulators tell Jack Ma’s Ant Group to rectify five problemsthe five areas included: Ant’s inadequate governance; regulatory negligence; unlawful profit-seeking; monopolistic practices and; infringement of consumer rights, said China’s central bank vice governor Pan Gongsheng.

    China orders Ant Group to rein in unfettered expansion as regulators put up fences around financial risks | South China Morning PostAnt must return to its origins in online payments and prohibit irregular competition, protect customers’ privacy in operating its personal credit rating business, establish a financial holding company to manage its businesses, rectify any irregularities in its insurance, wealth management and credit businesses, and run its asset-backed securities business in accordance with regulations, the People’s Bank of China’s deputy governor Pan Gongsheng said in a statement on Sunday.

    Luxury

    From TikTok to Depop: Fashion’s new trend funnel | Vogue Businesstrends like leather, feathers, neutrals or hot pinks, were relatively easy to follow: the trend funnel moved from runway to rack, with some help from popular culture along the way. This year, Gen Z users on TikTok and Depop jumpstarted a new trend funnel, quickly giving rise to aesthetics like “cottagecore” and “dark academia”, influencing young shoppers’s purchases. “If one of your favourite [TikTok] creators changes their aesthetic due to a particular trend, a whole style can be born out of it,” says Yazmin How, TikTok’s content lead. “The fashion industry is no longer the only voice directing the new season’s trends. People are tapping into TikTok to see what emerging styles are ‘in’ and what previously popular trends are coming back around.” TikTok trends manifest into purchases on Depop, where 90 per cent of users are Gen Z. In step with the rise of the cottagecore trend on TikTok, search for the term on Depop rose 900 per cent between March to August, when it reached its peak. Greater connectivity and increased time at home has boosted the amount of these consumer-led movements, and brands whose aesthetics fit the trends are benefiting, like LoveShackFancy, who specialises in the prairie dresses and gingham blouses associated with cottagecore’s countryside aesthetic – reminds me a bit of the Harajuku trends from the past 30 years. Culture and the trends that come out of it, are now massively parallel in nature

    Online

    FarmVille Once Took Over Facebook. Now Everything Is FarmVille. – The New York Times – legacy is in growth hacking techniques used to make it popular in the first place

    Why Bella Poarch’s “M to the B” video was the top TikTok of 2020 – VoxTikTok automates the mix of all these topics, going farther than any other platform to mimic the human editor.” At the same time, he says, it’s also “an eternal channel flip, and the flip is the point: there is no settled point of interes t to land on. Nothing is meant to sustain your attention.” The result, he argues, is what essentially amounts to “soft censorship,” or a feed that becomes as “glossy, appealing, and homogenous as possible rather than the truest reflection of either reality or a user’s desires.” How did a perfectly average competitive dancer become the No. 1 internet celebrity in the world? Why did half a billion people watch Poarch’s face bob up and down? Because these two women are the logical endpoint of the world’s most powerful entertainment algorithm: young people centering their conventional attractiveness in easily repeatable formats

    Retailing

    Amazon and the Rise of the Retail “Sniffer” Algorithm | The Fashion Lawthe “sniffer algorithm” – or better yet, “one or more” sniffer algorithms that not only sniff out topics that a speaker is potentially interested in but that also “attempt to identify trigger words in the voice content, which can indicate a level of interest of the user.” For example, as Amazon’s patent application states, “A keyword that is repeated multiple times in a conversation might be given assigned a higher priority than other keywords, tagged with a priority tag.” At the same time, “a keyword following a ‘strong’ trigger word, such as ‘love’ might be given a higher priority or weighting than for an intermediate trigger word such as ‘purchased.’” – when does assistance become creepy?

    Security

    NSO used real people’s location data to pitch its contact-tracing tech, researchers say | TechCrunch – and here is the original report on which the article is based Nso Group’s Breach Of Private Data With ‘fleming’, A Covid-19 Contact-tracing Software ← Forensic Architecture 

    Insecure wheels: Police turn to car data to destroy suspects’ alibis | NBC Newsinvestigators have realized that automobiles — particularly newer models — can be treasure troves of digital evidence. Their onboard computers generate and store data that can be used to reconstruct where a vehicle has been and what its passengers were doing. They reveal everything from location, speed and acceleration to when doors were opened and closed, whether texts and calls were made while the cellphone was plugged into the infotainment system, as well as voice commands and web histories. But that boon for forensic investigators creates fear for privacy activists, who warn that the lack of information security baked into vehicles’ computers poses a risk to consumers and who call for safeguards to be put in place

    Web of no web

    Tencent backs Chinese healthcare portal DXY in $500M round | TechCrunch – China has done a lot of work to move towards telemedicine and technology augmented health. Tencent’s WeChat was used by local governments for their COVID certificates, tracking and tracing applications. More Tencent related content here.

  • Private sector control + more things

    China’s Xi Ramps Up Control of Private Sector. ‘We Have No Choice but to Follow the Party.’ – WSJIn some cases, it is taking charge entirely of companies it regards as undisciplined, absorbing them into state-owned enterprises. – Push driven by a concern over the private sector business owners being unpredictable and not trusted. They think a centrally planned complex economy is the way forward; with the private sector playing a subservient role at best. This view has been strengthened by the state engineered swift recovery from COVID-19. I presume that they consider that China’s place in global supply chains, big data and machine learning will solve a lot of the problems that bedevilled previous centralised economic planning systems like what happened in the Soviet Union. More economics related content here.

    Party Committees See Rising Prevalence in Private Sector | Marco Polo – China clamping down on private sector

    Google AMP gets a shock to its system as advisor quits, lawsuit claims foul play • The Register 

    Quick Thoughts on the Russia Hack – Lawfare  – interesting post on the SolarWind hack based attacks

    North American Semiconductor Equipment Industry Posts November 2020 Billings – Semiconductor Digest – this looks good in terms of world economic growth

    China-Europe Trade Forum Canceled After China Sought to Bar Critics – WSJOfficials familiar with the exchange say the two people Beijing wanted to exclude from this year’s virtual event were Reinhard Bütikofer, the European Parliament’s chairman of the EU-China caucus who has publicly criticized Beijing over Hong Kong and its treatment of the Uighur minority; and Mikko Huotari, the head of Merics, a German think tank critical of the Chinese Communist Party. – China is depriving itself of unvarnished information about how it is viewed. A recipe for miscalculation in policymaking. Mainland Chinese contacts fail to understand why they don’t seem to have friendly relations with other nations anymore, despite Chinese achievements

    Huawei, 5G, and the Man Who Conquered Noise | WIRED – Steven Levy explains Erdal Arikan’s breakthrough in information theory well. What’s interesting is how the west has abandoned long term research projects. Arikan took 20 years for his breakthrough. In an American university you wouldn’t get, or maintain tenure doing that

    ‘Made in Hong Kong’ prestige provides springboard for retailers Watsons, Sa Sa to find success in Greater Bay Area | South China Morning Post‘Made in Hong Kong’ prestige provides springboard for retailers Watsons, Sa Sa to find success in Greater Bay Area. Well-known Hong Kong retailers are aggressively expanding in the bay area, where the prestige of their brands makes them a hit with mainland consumers. The city’s retail sector has been devastated by the coronavirus keeping deep-pocketed mainland tourists away – if true, I don’t seeing it being a defensible differentiation in the medium to long term

    MindGeek: the secretive owner of Pornhub and RedTube | Financial TimesPorn pioneered elements of the global online advertising industry such as targeted advertising, pay-per-click and email marketing and is today a substantial part of the internet economy

    Gen Z: the rising power in Chinese market and their 7 digital lifestyles – ChoZan – not the greatest guide to life stage trends in China

  • Caribbean phone networks + more

    Revealed: China suspected of spying on Americans via Caribbean phone networks | US news | The Guardian – China is alleged to have used Caribbean phone networks to conduct its surveillance. I’d imagine that they aren’t the only people to do this – At the heart of the allegations are claims that China, using a state-controlled mobile phone operator, is directing signalling messages to US subscribers, usually while they are travelling abroad. Signalling messages are commands that are sent by a telecoms operators across the global network, unbeknownst to a mobile phone user. They allow operators to locate mobile phones, connect mobile phone users to one another, and assess roaming charges. But some signalling messages can be used for illegitimate purposes, such as tracking, monitoring, or intercepting communications.– always use a VPN when roaming whether it’s Caribbean phone networks or elsewhere. We don’t know which Caribbean phone networks are vulnerable, could it be Digicel? More security related posts here.

    Robinhood faces legal action over ‘gamification’ of investing | FT – not terribly surprised by this. I wouldn’t be surprised if they were adopting B.J. Fogg’s dark principles in his work Persuasive Technology

    LS Keynote Shanghai 2020: The Digital Transformation of International Brands in Chinastudies by Boston Consulting Group for the luxury sector showed that 93 per cent of purchases in China are influenced by digital touchpoints – which is significantly higher compared to the 60 per cent observed in the global market. This makes developing digital offerings in China more significant for luxury brands. On top of its external transformation, it is also crucial for brands to establish an effective organisational structure and infrastructure internally. When it comes to creating omnichannel experiences, the development of online channels should be done so in tandem with offline touchpoints, opined Liang. Any projects that straddle online and offline must be supported by frontline staff – something he sees as a key challenge for luxury brands today – interesting stuff from Luxury Society

    Facebook says French and Russian disinformation trolls spar in Africa | Financial Times – this is fascinating. It is interesting that western agencies are trying to beat Russia at its own game

    To the moon and back, Chinese R&D is leaving the US behind | Financial TimesOnce upon a time, the US government invested heavily in research. US federal R&D spending surged after the Soviets launched Sputnik, peaking in 1965 at 11.7 per cent of federal spending and at 2.2 per cent of gross domestic product. Frontier discoveries from that time led to the internet and GPS, the global navigation system. But in the decades since putting a person on the moon, US government investment in ideas has waned. In constant dollars, Nasa spending had fallen by more than half by the early 1970s; it has been flat ever since. By 2019, total federal R&D spend constituted just 2.8 per cent of all federal spending and just 0.6 per cent of GDP — the lowest since the start of the cold war.

    What to do when the UN human rights office may have violated human rights? | South China Morning Post – UN shopped human rights activists to China, exposing them to retribution

    US orders emergency action after huge cyber security breach | Financial TimesHundreds of thousands of organisations around the world use SolarWinds’ Orion platform. The US department of Homeland Security’s cyber security arm ordered all federal agencies to disconnect from the platform, which is used by IT departments to monitor and manage their networks and systems. FireEye, a leading cyber security company that said it had fallen victim to the hack last week, said it had already found “numerous” other victims including “government, consulting, technology, telecom and extractive entities in North America, Europe, Asia and the Middle East”.

    ‘This Feels Uncomfortable’: Nike Tackles Racism In Japanobservers criticised Nike for misunderstanding or disrespecting its host country — as if racial prejudice were somehow a component of Japanese culture that should not be challenged. The issue is more complex than both the content and the censure suggest, but the reaction was a reminder that Japan is still less accustomed to ‘purpose-driven’ brand work than many economically advanced markets. It also underscored that extreme right-wing views exist in Japanese society, even if people rarely give voice to them in an offline environment. For some ordinarily bold brands, it is likely to prompt a round of second-guessing before adopting a sensitive social topic as part of their marketing efforts. “People think discrimination isn’t part of Japanese life, but it is,” said one Japanese in-house communications head at a multinational consumer-facing company, who wanted to remain anonymous. She added that she did not see the work as offensive but as helping to raise awareness of unconscious bias. At the same time, she said she would weigh the risks with extra care before embarking on any diversity-oriented campaign

    Finnish Data Theft and Extortion – Schneier on Security – when the ransomware hustle didn’t work on a Finnish mental health clinic, the hackers looked to extort employees and patients

    China pulls back from the world: rethinking Xi’s ‘project of the century’ | Financial Timestwo Chinese banks lent $462bn, just short of the $467bn extended by the World Bank, according to the Boston University data. In some years, lending by the Chinese policy banks was almost equivalent to that by all six of the world’s multilateral financial institutions — which along with the World Bank include the Asian Development Bank, the Inter-American Development Bank, the European Investment Bank, the European Bank for Reconstruction and Development and the African Development Bank — put together. In global development finance, such a sharp scaling back of lending by the Chinese banks amounts to an earthquake. If it persists, it will exacerbate an infrastructure funding gap that in Asia alone already amounts to $907bn a year, according to Asian Development Bank estimates. In Africa and Latin America — where Chinese credit has also formed a big part of infrastructure financing — the gap between what is required and what is available is also expected to yawn wider. China’s retreat from overseas development finance derives from structural policy shifts, according to Chinese analysts. “China is consolidating, absorbing and digesting the investments made in the past,” says Wang Huiyao, an adviser to China’s state council and president of the Center for China and Globalisation, a think-tank. – there are limits to what even China can do to defy economic laws. Overall the infrastructure costs of the British empire were much higher than is generally realised