SLIDE 1 go out and fix privacy!
SLIDE 2 @KirilsSolovjovs, 2019. https://kirils.org
Some citizens complain about being under surveillance, but they are told that if they have nothing to hide, they have nothing to fear.
SLIDE 3 @KirilsSolovjovs, 2019. https://kirils.org
Still, news media regularly cover cases where citizens with unusual behaviour are put on suspicion lists, even though they have broken no laws.
SLIDE 4 @KirilsSolovjovs, 2019. https://kirils.org
Jesper Lund
SLIDE 5 @KirilsSolovjovs, 2019. https://kirils.org
∀(p criminal) p hiding ∈ → ∈ |- ∀(p hiding) p criminal ∈ → ∈
SLIDE 6 @KirilsSolovjovs, 2019. https://kirils.org
- Autonomous right to choose
– who processes my info – how is my info processed – what info is processed
- Right to decide who I interact with
– right to be left alone
What even is privacy?
SLIDE 7 @KirilsSolovjovs, 2019. https://kirils.org
Schrödinger’s video camera
SLIDE 8 @KirilsSolovjovs, 2019. https://kirils.org
Reactions
SLIDE 9 @KirilsSolovjovs, 2019. https://kirils.org
Reactions
Why are you presenting this without a face mask? You give up your own privacy on Facebook every day, why worry about someone tracking you? Interesting and also not worth it at all. Your time
you know. Your phone tracks you anyway It’s pointless, I’ve got nothing to hide. I'm feeling like you with recaptcha What do we do now?
SLIDE 10 @KirilsSolovjovs, 2019. https://kirils.org
Got something to hide
23 September 2019, Twitter
SLIDE 11 @KirilsSolovjovs, 2019. https://kirils.org
Got something to hide
23 September 2019, Twitter
SLIDE 12 @KirilsSolovjovs, 2019. https://kirils.org
Got nothing to hide?
SLIDE 13 @KirilsSolovjovs, 2019. https://kirils.org
– Blackmail, impersonation
Got nothing to hide?
SLIDE 14 @KirilsSolovjovs, 2019. https://kirils.org
many people not hiding anything make the few stand out more and draw suspicion
Got nothing to hide?
SLIDE 15 @KirilsSolovjovs, 2019. https://kirils.org
- Today’s authority might become totalitarian or inhumane
Got nothing to hide?
SLIDE 16 @KirilsSolovjovs, 2019. https://kirils.org
Movement tracking
13 Jun 2019, QUARTZ
SLIDE 17 @KirilsSolovjovs, 2019. https://kirils.org
Government wants in on the data
30 October 2019, VICE
SLIDE 18 @KirilsSolovjovs, 2019. https://kirils.org
CCTV
SLIDE 19 @KirilsSolovjovs, 2019. https://kirils.org
Facial recognition
16 May 2019, METRO
SLIDE 20 @KirilsSolovjovs, 2019. https://kirils.org
4 November 2019, Mac Pierce
Facial recognition
SLIDE 21 @KirilsSolovjovs, 2019. https://kirils.org
Facial recognition
18 November 2019, MailOnline
SLIDE 22 @KirilsSolovjovs, 2019. https://kirils.org
WiFi without a phone number
7 December 2019, Twitter
SLIDE 23 @KirilsSolovjovs, 2019. https://kirils.org
4 October 2019, POLITICO
Copy – paste
SLIDE 24 @KirilsSolovjovs, 2019. https://kirils.org
28 October 2019, La Quadrature du Net
All is not lost
SLIDE 25 @KirilsSolovjovs, 2019. https://kirils.org
22 August 2019, EDPB
All is not lost
SLIDE 26 @KirilsSolovjovs, 2019. https://kirils.org
News from Riga
BB - 1 9 8 4
SLIDE 27 @KirilsSolovjovs, 2019. https://kirils.org
“Privacy is dead” — 2018
16 May 2018, Twitter
SLIDE 28 @KirilsSolovjovs, 2019. https://kirils.org
Enter 2019!
i
16 Jan 2019, Twitter 27 Sep 2019, Twitter
SLIDE 29 @KirilsSolovjovs, 2019. https://kirils.org
27 September 2019, The Wall Street Journal
SLIDE 30 @KirilsSolovjovs, 2019. https://kirils.org
Spying on our kids
22 October 2019, The Guardian
SLIDE 31 @KirilsSolovjovs, 2019. https://kirils.org
22 October 2019, The Guardian
REASON
SLIDE 32 @KirilsSolovjovs, 2019. https://kirils.org
22 October 2019, The Guardian
REACTION TIME
SLIDE 33 @KirilsSolovjovs, 2019. https://kirils.org
22 October 2019, The Guardian
SCOPE
SLIDE 34 @KirilsSolovjovs, 2019. https://kirils.org
22 October 2019, The Guardian
JUSTIFICATION
SLIDE 35 @KirilsSolovjovs, 2019. https://kirils.org
22 October 2019, The Guardian
EFFECTS
SLIDE 36 @KirilsSolovjovs, 2019. https://kirils.org
22 October 2019, The Guardian
MILITARY TECH
SLIDE 37 @KirilsSolovjovs, 2019. https://kirils.org
26 April 2007, Lorelei / Merriam-Webster dictionary
gag verb
- to prevent from exercising freedom of speech
- r expression
- to restrict use of the mouth of by inserting
something into it to prevent speech or outcry
- to pry or hold open with a gag
SLIDE 38 @KirilsSolovjovs, 2019. https://kirils.org
The end-of-end-to-end-encryption
SLIDE 39 @KirilsSolovjovs, 2019. https://kirils.org
“warrant-proof” encryption
31 July 2019, computing.co.uk
GCHQ has suggested that tech firms' communication services should be able to surreptitiously add intelligence agents to conversations or group chats 'Five Eyes' member countries have called for technology firms to help intelligence agencies by providing them with special, backdoor access to WhatsApp and other encrypted communications. The group has also warned that failing to do so would put lives of thousands of people at risk. "The Five Eyes are united that tech firms should not develop their systems and services, including end-to-end encryption, in ways that empower criminals or put vulnerable people at risk," British home secretary, Priti Patel, said at the conclusion of the two-day meeting of Five Eyes member countries in London.
SLIDE 40 @KirilsSolovjovs, 2019. https://kirils.org
28 October 2019, Boing Boing
“warrant-proof” encryption
SLIDE 41 @KirilsSolovjovs, 2019. https://kirils.org
WhatsApp
SLIDE 42 @KirilsSolovjovs, 2019. https://kirils.org
9 Mar 2019, India Today
No secure apps, please
SLIDE 43 @KirilsSolovjovs, 2019. https://kirils.org
WhatsApp
SLIDE 44 @KirilsSolovjovs, 2019. https://kirils.org
Watching porn anonymously
29 October 2019, Twitter
SLIDE 45 @KirilsSolovjovs, 2019. https://kirils.org
7 September 2019, Ars Technica
Facebook dating
SLIDE 46 @KirilsSolovjovs, 2019. https://kirils.org
Facebook
When someone is expressing thoughts of suicide, it’s important to get them help as quickly as possible. Because friends and family are connected through Facebook, we can help a person in distress get in touch with people who can support them. Last year, we began to use machine learning to expand our ability to get timely help to people in need. This tool uses signals to identify posts from people who might be at risk, such as phrases in posts and concerned comments from friends and family.
Suicide prevention
SLIDE 47 @KirilsSolovjovs, 2019. https://kirils.org
Facebook
Suicide prevention
SLIDE 48 @KirilsSolovjovs, 2019. https://kirils.org
Facebook
Suicide prevention
SLIDE 49 @KirilsSolovjovs, 2019. https://kirils.org
“Data reuse”
18 June 2019, The New York Times
SLIDE 50 @KirilsSolovjovs, 2019. https://kirils.org
Web browsing
SLIDE 51 @KirilsSolovjovs, 2019. https://kirils.org
Web browsing
SLIDE 52 @KirilsSolovjovs, 2019. https://kirils.org
Web browsing
SLIDE 53 @KirilsSolovjovs, 2019. https://kirils.org
Web browsing
SLIDE 54 @KirilsSolovjovs, 2019. https://kirils.org
Web browsing
SLIDE 55 @KirilsSolovjovs, 2019. https://kirils.org
Practical experiments with GDPR
SLIDE 56 @KirilsSolovjovs, 2019. https://kirils.org
SMS spam
SLIDE 57 @KirilsSolovjovs, 2019. https://kirils.org
Getting postal mail
Latvijas Pasts / C3POST
SLIDE 58 @KirilsSolovjovs, 2019. https://kirils.org
Mobile apps
SLIDE 59 @KirilsSolovjovs, 2019. https://kirils.org
Yandex.Taxi privacy policy
Yandex
SLIDE 60 @KirilsSolovjovs, 2019. https://kirils.org
Yandex.Taxi privacy policy
Yandex
SLIDE 61 @KirilsSolovjovs, 2019. https://kirils.org
Mobile apps
SLIDE 62 @KirilsSolovjovs, 2019. https://kirils.org
Mobile apps
SLIDE 63 @KirilsSolovjovs, 2019. https://kirils.org
Mobile apps
SLIDE 64 @KirilsSolovjovs, 2019. https://kirils.org
Prepaid debit cards
SLIDE 65 @KirilsSolovjovs, 2019. https://kirils.org
Prepaid debit cards
SLIDE 66 @KirilsSolovjovs, 2019. https://kirils.org
Public transport
SLIDE 67 @KirilsSolovjovs, 2019. https://kirils.org
Airport scanners
SLIDE 68 @KirilsSolovjovs, 2019. https://kirils.org
Boarding passes in shops
SLIDE 69 @KirilsSolovjovs, 2019. https://kirils.org
Fingerprints in passports
- “We don’t need your fingerprint”
- “We only store fingerprint in your passport”
- “We also store its «hash» in a database”
– wsq (FBI’s Wavelet Scalar Quantization algo)
SLIDE 70 @KirilsSolovjovs, 2019. https://kirils.org
Fingerprints in passports
- “We don’t need your fingerprint”
- “We only store fingerprint in your passport”
- “We also store its «hash» in a database”
– wsq (FBI’s Wavelet Scalar Quantization algo)
- “Hey, that’s my whole fingerprint!”
SLIDE 71 @KirilsSolovjovs, 2019. https://kirils.org
Fingerprints in passports
- “We don’t need your fingerprint”
- “We only store fingerprint in your passport”
- “We also store its «hash» in a database”
– wsq (FBI’s Wavelet Scalar Quantization algo)
- “Hey, that’s my whole fingerprint!”
SLIDE 72 @KirilsSolovjovs, 2019. https://kirils.org
- User demand ☹
- Cookie law 😑
- GDPR for “big data” ☹
- GDPR ☺
- Surveillance tech ☹
- Encryption 😑
Status quo
{
EU only
SLIDE 73 @KirilsSolovjovs, 2019. https://kirils.org
- User demand ☹
- Cookie law 😑
- GDPR for “big data” ☹
- GDPR ☺
- Surveillance tech ☹
- Encryption 😑
How can you fix it?
SLIDE 74 @KirilsSolovjovs, 2019. https://kirils.org
- A privacy zealot, obviously
- Lead researcher at Possible
Security, Latvia
- Hacking and breaking things:
–
Network flow analysis & RE
–
Social engineering
–
Legal dimension
@KirilsSolovjovs Follow me! It’s free¹ ;-)
Who was that guy?
¹ free as in speech² ² no, there is no free beer