Skip to content

Latest commit

 

History

History
306 lines (183 loc) · 18.4 KB

inercia2019-demoparty.md

File metadata and controls

306 lines (183 loc) · 18.4 KB

Privacy bit: How to flip it to 1

Privacy Lx logo

[email protected]

PGP: 2DC1 FCEA FA18 E37D E871 EF41 5D23 7CAB ED63 7DDA

                Disclaimer: Not a demo talk

Identifying the problem

Privacy (and security) issues.

Come on, we 've heard this before!

On average we read at least once daily about privacy issues and companies that sold our precious private data.

Do you really know what's happening?

Why privacy matters (video)

Source: La Quadrature du Net - "Reclaim Our Privacy"

Note: La Quadrature du Net publishes "Reclaim Our Privacy", a three-minute movie that explains the threat to, the importance of protecting, and the tools to reclaim our privacy online. Source: https://www.invidio.us/watch?v=AW7aU3zv-4M Are you sure?

Motivation of the selection

So many horrible services and companies!

Note: Inercia.pt website, Facebook event, Google form for registration that requires to log in

Big Brother Facebook image

Source: MidEastPosts.com

Note: Internet privacy, such as use of a widespread "like" button on third-party websites tracking users,[1][2] possible indefinite records of user information,[3] automatic facial recognition software,[4][5] and its role in the workplace, including employer-employee account disclosure.[6] Source: https://en.wikipedia.org/wiki/Criticism_of_Facebook

Screenshot_Advocacy_Groups_Ask_Facebook_for_More_Privacy_Changes.png

Source: Pcworld.com

Screenshot_Facebook’s_facial_recognition_software_is_now_as_accurate_as_the_human_brain.png

Source: Extermetech.com

Screenshot_How_Sticky_Is_Membership_on_Facebook_Just_Try_Breaking_Free.png

Source: Nytimes.com

Screenshot_Facebook_hired_people_to_transcribe_voice_calls_made_on_Messenger.png

Source: Cnbc.com

Note: On August 13, 2019, it was revealed that the company had in fact enlisted contractors to create and obtain transcripts of users, which were then analyzed to help spread political messages.[46][47][48] Source: https://en.wikipedia.org/wiki/Criticism_of_Facebook

Facebook is not your friend

  • Cooperation with government requests
  • Data mining
  • Cambridge Analytica data scandal

Note: Government and local authorities rely on Facebook and other social networks to investigate crimes and obtain evidence to help establish a crime, provide location information, establish motives, prove and disprove alibis, and reveal communications. In 2018, Facebook admitted[146][147] that an app made by Global Science Research and Alexandr Kogan, related to Cambridge Analytica, was able in 2014[148] to harvest personal data of up to 87 million Facebook users without their consent, by exploiting their friendship connection to the users who sold their data via the app.[149] Sources:

Screenshot_Revealed_Facebook’s_global_lobbying_against_data_privacy_laws.png

Source: Theguardian.com

Note: In early 2019, it was reported that Facebook had spent years lobbying extensively against privacy protection laws around the world, such as the General Data Protection Regulation (GDPR).[187] [188] Source: https://en.wikipedia.org/wiki/Criticism_of_Facebook#International_lobbying_against_privacy_protections

Screenshot_Facebook_stored_hundreds_of_millions_of_passwords_unprotected.png

Source: Theguardian.com

Note: In March 2019, Facebook admitted that it had mistakenly stored "hundreds of millions" of passwords of Facebook and Instagram users in plaintext (as opposed to being hashed and salted) on multiple internal systems accessible only to Facebook engineers, dating as far back as 2012. Facebook stated that affected users would be notified, but that there was no evidence that this data had been abused or leaked.[189][190] Source: https://en.wikipedia.org/wiki/Criticism_of_Facebook#Unencrypted_password_storage

Screenshot_Facebook_now_says_its_password_leak_affected_millions_of_Instagram.png

Source: Techcrunch.com

Note: In April 2019, Facebook admitted that its subsidiary Instagram also stored millions of unencrypted passwords.[191]

Screenshot_A_Facebook_content_moderator_died_after_suffering_heart_attack_on_the_job.png

Source: Mysanantonio.com

Note: Content moderator Keith Utley, who was employed by Cognizant, experienced a heart attack during work in March 2018; the office lacked a defibrillator, and Utley was transported to a hospital where he died.[239][242] Source: https://en.wikipedia.org/wiki/Criticism_of_Facebook#Moderators

Screenshot-Facebook_fuels_broad_privacy_debate_by_tracking_non-users.png

Source: Reuters.com

Note: Facebook collects data from non-users.

Google Surveillance graffiti

Source: Downtherabbitholemedia.com

Note: We can most probably have a weekend presentation only about the privacy issues of Google. I will provide some pointers to understand the level of atrocity. Source: http://www.downtherabbitholemedia.com/wp-content/uploads/2019/04/Google-800-x-450-800x445.jpg

how-google-tracku.jpeg

Source: TheBestVPN.com - What Does Google Know About You: A Complete Guide

how-google-knowsu.jpeg

Source: TheBestVPN.com - What Does Google Know About You: A Complete Guide

google-everywhere.jpeg

Source: TheBestVPN.com - What Does Google Know About You: A Complete Guide

google-friends.jpeg

Source: TheBestVPN.com - What Does Google Know About You: A Complete Guide

google-preferences.jpeg

Source: TheBestVPN.com - What Does Google Know About You: A Complete Guide

google-future.jpeg

Source: TheBestVPN.com - What Does Google Know About You: A Complete Guide

google-life.jpeg

Source: TheBestVPN.com - What Does Google Know About You: A Complete Guide

What's the danger?
  • Political manipulation
  • User discrimination
  • Advertisements & Surveillance = ♥
  • Centralization ate the cat :(
(meta)data
  • Sell/hand over data to other companies, governments and authorities
  • We can get killed based on metadata
  • Data acquisition is toxic

Meanwhile in Portugal

O site a que pretende aceder encontra-se
bloqueado na sequência do cumprimento
de ordem judicial ou administrativa.

    http://mobilegen.vodafone.pt/denied/dn

OONI Explorer - uber.com

Source: OONI Explorer

Note: OONI Explorer showing network blocking excerpt of Uber.com in Vodafone ISP in Portugal

guardia-civil-blockpage.jpg

Note: In a neighbored country, Internet censorship expands. A block page from the Spanish Civil Guard

google-blocks-catalan-info-app.png

Source Rt.com

GitHub government takedown (Spain)

Tsunami Democratic app and other git repos

commit 983f257e63903280bf2f306da45bf467e7bc6f3c
Author: Hubot <[email protected]>
Date:   Tue Oct 29 17:08:49 2019 -0400

    Publish notice.

diff --git a/Spain/2019/2019-10-23-GuardiaCivil.md b/Spain/2019/2019-10-23-GuardiaCivil.md
new file mode 100644
index 0000000..6bccde1
--- /dev/null
+++ b/Spain/2019/2019-10-23-GuardiaCivil.md
@@ -0,0 +1,29 @@
+Dear Sir or Madam,
+
+This is the official e-mail account of the Lawful Interception Unit of the Guardia Civilwhich is one of the Spanish Law Enforcement Agencies. Since 1999, our unit has been working as the Guardia Civil's Single Point of Contact with Internet Service Providers and every other Online Service Provider that uses the telecommunication network in order to provide any service. Our main task is to request them important information or any other action regarding judicial investigations carried out by our investigation teams.
+
+In Spain, judicial authorities are responsible for the supervision and control of websites in order to prevent the dissemination of criminal content as it is specified in the article 35 of our Law 34/2002 and the article 13 of our Criminal Procedure Code.
+
+As you may have seen in the international media, Spain is currently facing a series of riots involving serious public disorder and main infrastructure's sabotage. There is an ongoing investigation being carried out by the National High Court where the movement Tsunami Democratic has been confirmed as a criminal organization driving people to commit terrorist attacks. Tsunami Democratic's main goal is coordinating these riots and terrorist actions by using any possible mean.
+
+Among them, they have developed an app that provides information about those riots and allows their users to communicate between themselves in order to coordinate those actions. This app has been uploaded in GitHub by the user [private] ([private]), where people that want to participate in riots can access his repository ([private]) and install different versions of this app in their devices. Moreover, other repositories with the same information have been created to prevent the content being withheld.
+
+Concerning this situation, and in compliance with the Law, we send this e-mail with a national court warrant attached in order to request both withholding the content and data related to the aforementioned investigation. This is the same procedure that we follow with other service providers located in the United States, such as Microsoft or Google.
+
+Yours faithfully,
+
+------------------------------------------------------------------------------------------
+
+Estimado señor o señora,
+
+Esta es la cuenta de correo electrónico oficial del Grupo de Interceptación de las Telecomunicaciones de la Guardia Civil, que es una de las agencias policiales españolas. Desde 1999, nuestra unidad ha estado trabajando como Punto de contacto único de la Guardia Civil con proveedores de servicios de Internet y cualquier otro proveedor de servicios en línea que utiliza la red de telecomunicaciones para proporcionar cualquier servicio. Nuestra tarea principal es solicitarles información importante o realizar cualquier otra acción relacionada con las investigaciones judiciales llevadas a cabo por nuestros equipos de investigación.
+
+En España, las autoridades judiciales son responsables de la supervisión y el control de los sitios web con el fin de evitar la difusión del contenido delictivo, tal como se especifica en el artículo 35 de nuestra Ley 34/2002 y el artículo 13 de nuestro Código de Procedimiento Penal.
+
+Como puede haber visto en los medios internacionales, España se enfrenta actualmente a una serie de disturbios violentos que involucran graves desórdenes públicos y el sabotaje de infraestructuras críticas. La Audiencia Nacional está llevando a cabo una investigación en la que el movimiento Tsunami Democratic ha sido confirmado como una organización criminal que impulsa la comisión de ataques terroristas. El objetivo principal de Tsunami Democratic es coordinar estos disturbios y acciones terroristas usando cualquier medio posible.
+
+Entre ellos, han desarrollado una aplicación que proporciona información sobre esos disturbios y permite a sus usuarios comunicarse entre ellos para coordinar esas acciones. Esta aplicación ha sido cargada en GitHub por el usuario [private] ([private]), donde las personas que desean participar en disturbios pueden acceder a su repositorio ([private]) e instale diferentes versiones de esta aplicación en sus dispositivos. Además, se han creado otros repositorios con la misma información para evitar que el contenido se retenga.
+
+Con respecto a esta situación, y de conformidad con la Ley, enviamos este correo electrónico con una orden judicial nacional adjunta para solicitar la retención del contenido y los datos relacionados con la investigación antes mencionada. Este es el mismo procedimiento que seguimos con otros proveedores de servicios ubicados en los Estados Unidos, como Microsoft o Google.
+
+Atentamente,

Source: GitHub

We need have alternatives

Degooglify your Internet

Source: Framasoft

Note: Degooglify your Internet find user-friendly tools.

PrivacyLx community

Thank you!

Participate/find more info:

https://privacylx.org/community/