reigning in the data (fosscon 2014) - ephemeral messaging and privacy in post snowden era

40
Reigning In The Data The Need for “Ephemeral” Content And the Social Impacts of the Privacy Crisis In the Post- Snowden Era FOSSCON 2014 Andrew Schwabe

Upload: andrew-schwabe

Post on 22-Jun-2015

174 views

Category:

Internet


0 download

DESCRIPTION

2014 FOSSCON Presentation on the state of Privacy in the post-Snowden Era, Ephemeral Messaging and Social Challenges

TRANSCRIPT

Page 1: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

Reigning In The Data

The Need for “Ephemeral”

Content

And the Social Impacts of the

Privacy

Crisis In the Post-Snowden Era

FOSSCON 2014 Andrew Schwabe

Page 2: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

A Copy of this Presentation

• Will be linked via twitter:

• Follow me at @aschwabe

• Posted on my blog:

PainInTheApps.com

Page 3: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

Background

• Tech Entrepreneur

• 20 yrs in Encryption + Data

Security

• Mobile, Social, Privacy focus now

• Assisted FBI for online predator

hunts

• Founder of Point.io

• Hackr #001 at new startup: STASH

• Privacy + OSS Advocate

Page 4: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

• Launched August 2014

• First announced at FOSSCON!

• The worlds first peer-validation

ephemeral messaging platform

• http://Stash.My

Page 5: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

Ahhhhh the Internet!

Page 6: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

Ignorance *was* bliss

• A smartphone was just a phone with

email and junk and stuff

• We didn’t care if our kids uploaded pictures and

shared where they were during the day (every

day?)

• We didn’t think twice about emailing sensitive or

private stuff to ourselves or friends, even in

gmail…

Page 7: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

Then…

Page 8: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

1.2 Billion Usernames and passwords compromised

Hacked!

Page 9: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

SPIED ON!

Page 10: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

NO PRIVACY!

Page 11: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

Welcome to a new Era!

Page 12: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

Used to be… …the government would protect your

privacy

Page 13: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era
Page 14: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

and stealing your secrets… …took effort and some paper moon

trickery…

<Cthon98> hey, if you type in your pw, it will show as stars<Cthon98> ********* see!<AzureDiamond> hunter2<AzureDiamond> doesnt look like stars to me<Cthon98> <AzureDiamond> *******<Cthon98> thats what I see<AzureDiamond> oh, really?<Cthon98> Absolutely…<AzureDiamond> oh, ok.

Page 15: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

So What Happened???• Mobile devices got powerful and

complex

• Social media exploded onto the

scene

• Consumerization of IT

• … and we didn’t know what was

going on…

Page 16: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era
Page 17: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

The Privacy Crisis

• We can at least be concerned that the NSA

have cracked and monitor:

– SSL (HTTPS) website activity

– RSA encryption certificates (public/private keys)

– 4G mobile networks (voice and data)

– VoIP voice services

– And any websites/etc. that use the above

Page 18: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

NSA security coverage

• Means that they *can* (not will)

hack/monitor most of the services we

rely on daily

• These all use the same core security

tech

Page 19: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

Google, Microsoft, otheremail scans

What is next ?

Page 20: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

Data creation explosion

We are creating

huge amounts of

digital content,

much of which lives

longer in the cloud

than we intended

or have use for.

Page 21: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

Data creation

• A large portion of what we create will live on

disk somewhere beyond our use for it

• The last decade was spent schooling people on

having backups

Page 22: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

People know enough to be concerned

Page 23: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era
Page 24: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

Google’s Right to be Forgotten

Page 25: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

We SHOULD…

• Be concerned about

– what gets shared

– with whom

– And how long it lasts

Page 26: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

Apps that are helping

• Snapchat

• Wickr

• Spideroak

• All focused on being a “place” where

your stuff is secure

Page 27: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

Ephemeral

• What does it mean?

• Origin: greek word “ephĕmeros”

• “lasting for a very short time”

• The new “bucket” for technology that

manages the life of digital content

Page 28: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

How does it help

• Personal privacy

• Corporate Risk

• Facebook vs snapchat models

• The opposite of Big Data ?

Page 29: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

Is it enough?

• The concept is still new

• People are building “apps” more than

broad sweeping “solutions”

• It doesn’t address the issue of being

monitored/collected by NSA/Others

(strong encryption)

Page 30: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

True anonymity ?

• Maybe the answer is anonymous

communication??

• Only available for *some* activity online

• Whistleblowers – do we want to enable

WikiLeaks and Snowdens ?

• But isn’t true anonymity the….

Page 31: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

Dark Side of the Internet

Page 32: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

Tools exist for anonymity• “Leak” website lets you send untrackable anonymous

emails.

– Inappropriate emails anybody ?

– Harrassment, abuse ?

• Tor lets you encrypt your web traffic and make you difficult

to track

– Porn and pirated content

• Bitcoin exists to keep the banks out of your financial

dealings

– Silk Road. BUSTED.

Page 33: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

But Still Enable Naughty Activity

• Gov’ts around the world cracking down on

porn and sex trafficking

• FBI Infecting Tor users with Malware

• Google and Microsoft scan emails, etc. and

report questionable content to authorities

• Evil begets evil

Page 34: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

Accountability

• There is no way to make everybody

behave

• As a global society we need new

ways to encourage law abiding

netizens

Page 35: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

OMG I’m Scared

• What should I do?

– Know the risks

– Use technologies to protect yourself

– Don’t associate with those who don’t

behave

Page 36: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

What we [might] need (the Future?)

• Anonymous peer validation for data

integrity

• Anonymous submissions to known

entities only for whistleblowing

• Social content stays social and never

collected for “Big Data”

Page 37: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

In Summary

• We are in a new era

• Keep Calm

• Stay Educated

• Don’t Share unless you know the risks

• Use the right tech for your

security/privacy needs

Page 38: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

For Some Fun Reading

• “Cryptonomicon” by Neal

Stephenson

– A futuristic take on:

– Underground Data Haven

– Anonymous Internet Banking

– Digital Gold Currency

Page 39: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

Q&A

Page 40: Reigning in the Data (FOSSCON 2014) - Ephemeral Messaging and Privacy In Post Snowden Era

Thank you for coming!• Presentation will be shared via

twitter:

• Follow me at @aschwabe

• AND Posted on my blog:

PainInTheApps.com