PRISMBREAK
The value of online identities
Frank Ackermann, November 2013
PRISMBREAK The value of online identities Frank Ackermann, November - - PowerPoint PPT Presentation
PRISMBREAK The value of online identities Frank Ackermann, November 2013 disclaimer This talk is focused on security awareness. This talk does not contain proof of concepts, shell code, scripts or other in-depth technical details. The
The value of online identities
Frank Ackermann, November 2013
2 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
disclaimer
This talk does not contain proof of concepts, shell code, scripts or other in-depth technical details.
security safety measures of current or former employers.
3 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
who am i
“Security is not my job – it is my passion!”
Specialist over a decade, focused on Security Management, Consulting and Architecture
4 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
agenda
Data gathering is becoming surveillance
Identities are becoming one of the future currencies
5 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
spin doctors & motivators
June 2013 (→ 'Prism' Break)
6 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
thesis I
Data gathering is becoming surveillance The
7 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
Prism
Source: [2]
8 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
Prism II
Source: [2]
9 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
and identify criminals
–
fbi.gov/news/stories/2009/january/ngi_012609
–
fbi.gov/about-us/cjis/fingerprints_biometrics/ngi/ngi2/
not only Prism ...
10 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
agile cyber solutions to derive actionable information from optical and electronic signals.”
commercial products
Source: [4]
11 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
surveillance society
mobile-users, automatic envelope-scanning, flight bookings, analyzing money-transactions... These are indicators of a surveillance society!
recognition (→ face move → picture tagging)
large groups (e.g. football match) is widely used
12 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
situation
Mark Greene, Fair Isaac's chief executive, told investors earlier this year
"The more data we have access to, the more insight we have."
and decision management
13 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
history – isolated silos
shared in private forums
Private data Military/Intelligence Private enterprise
14 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
breakup of boundaries
(big data, platforms, cloud, ...)
Private data Private enterprise Military / Intelligence
15 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
affected future I
reactions
Private data Private enterprise Military / Intelligence
16 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
affected future II
'I'm going to destroy America and dig up Marilyn Monroe': British pair arrested in U.S. on terror charges over Twitter jokes
17 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
conclusion thesis I
mechanisms to analyze and predict behavior
18 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
thesis II
Identities are becoming
The
19 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
the value of an identity
publishers-, producers or developers identity
– e.g. news- and market-feed (financial) – e.g. product reviewer in a shopping-platform – e.g. political blogs or opinion-makers
20 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
blog and identity
– Micro-blogging (e.g. Twitter, Facebook) – Online Journalism (e.g. news, weather) – Consumer generated advertising (e.g. Amazon-
reviews, George Masters iPod adds, CokeLight/Mentos → www.eepybird.com)
– Video- and audio blogging (e.g. YouTube)
21 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
making money with blogs
– Affiliate marketing (per print/print-out, per lead, …) – Pay per click – Link-selling – Advertisement / banner to your blogs.
22 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
– selbstaendig-im-netz.de stated 4-5K€ / month – blog.rankseller.de stated in their research that 13%
– mongabay.com makes $15-18K / month – problogger.net made $250K in 2007
$$$
23 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
value of Facebook fan$
– 1 fan of a product ≥ $150 for product owner. – Value (of each products fan to a product) is
reflected in the actions and interactions of each fan.
– Social (and social networking) is a core
marketing strategy
24 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
interactions and values
with others
and visible/traceable – therefore interactions themselves become more valuable
+ A B
B A B vs
25 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
Amazon reviewer
Total Reviews Helpful Votes Percent Helpful Hall of fame!
26 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
Platform Tool
content and usage I
and rated by other users
User A User B
Content
Like Follow Rate
27 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
Platform Tool Rate
content and usage II
and analyzation of identities, behavior, content
Identity user A User B
Content
Vendor User A Employees Analyze identity and content of e.g. user A
28 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
chances for business
data analysis have only just begun
Source: [1]
29 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
challenges for business I
– data driven R&D (involve customers in dev. & test) – selling and trading data as a new revenue stream – process automation (e.g. Oyster Card, London) – enhanced data analyzing of shared sources
30 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
challenges for business II
– increase privacy control for users – display how the data is used (transparency) – build data-driven organizations, not IT
identities and supports the sustainability and accuracy of data!
31 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
attack surface I
platforms and tools & issues with the basics!
– Java → affects all web-platforms and tools like
Tumblr, Twitter, Facebook
– browser and browser-plugins – bloggers: WordPress & WordPress Plugins – web-content, links, XSS → advertising, fraud – internet and IPv4/v6 – local applications and installations including OS
32 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
attack surface II
user knowledge & activity tools & techniques vulnerabilities & attackers … growing … reaching
features #1 #2
33 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
twitter-hacks
hacking-group attacked the twitter-accounts of #FIFA and FIFA-president #Joseph Blatter
(OTP via SMS, 2FA) in 2013 … but is not a default setting!
34 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
f8ke acc0unts
This enables social engineering
→ This all affects the plausibility of content and platform
35 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
data might be wrong
religious or political bias, misquoting, inaccuracy gathering or reporting ...
motivation of the source is discovered
36 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
there ain't no such thing as a free lunch
future currency
perceived benefits (e.g. freemail services)
37 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
conclusion thesis II
customers data
highly valuable and can be taken as currency
functionalities and benefits
38 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
→ Do not leave your brain unattended!
company's terms of use, cookie usage +++
Offer control possibilities; allow less details
what's left [5]
summed up
39 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
Thank you. Contact prism.break@gmx.de
40 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
references
–
Online news and feeds (e.g. Wall Street journal, FAZ, BBC, Mail, ...)
–
'The nature of the future', Marina Gorbis
–
The value of a facebook fan 2013, Syncapse
–
[1] The value of our digital identity, 2012, BCG Group
–
Official sites (e.g. NSA, FBI, …)
–
[2] http://en.wikipedia.org/wiki/PRISM_(surveillance_program)
–
[3] http://www.hd-gbpics.de/blog/contentbilder/neuland-2.jpg http://newsfromneuland.tumblr.com/post/53360376853
–
[4] http://www.glimmerglass.com
–
[5] 2013 Data breach investigation report, Verizon
–
YouTube: Richard French: Surveillance Nation: Your Identity Exposed
–
YouTube: Homegrown Radicalization -- How Data Analytics Can Help Prevent Terrorism
–
faz.net/aktuell/feuilleton/debatten/ueberwachung/im-zeitalter-von-big-data-wir-wollen-nicht- 12545592.html
41 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
backup
42 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
identity-value
surveillance and control are increasing
value $$$ popularity surveillance 3? 1 2 value $$$ amount of meta-data 3? 1 2
43 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
meme I
ˈ ː behavior, or style that spreads from person to person within a culture."
→ viral marketing
44 PrismBreak, Frank Ackermann, prism.break@gmx.de, November 2013
meme II
'Das Internet ist für uns alle Neuland'
significance of an individual may transform into uncontrollable content
Source: [3]