“those who desire to give up freedom in order to gain...

16
1 Ben Franklin “Those who desire to give up freedom in order to gain security will not have, nor do they deserve, either one.”

Upload: vantuong

Post on 24-Nov-2018

213 views

Category:

Documents


0 download

TRANSCRIPT

Page 2: “Those who desire to give up freedom in order to gain ...mjborlan/SYDE261/pdf/S2/03-03-11-Security_vs... · Bank of America On 18 December, Bank of America announced it would "not

2

SYDE261 - W2011

Security versus Privacy

vs

Page 3: “Those who desire to give up freedom in order to gain ...mjborlan/SYDE261/pdf/S2/03-03-11-Security_vs... · Bank of America On 18 December, Bank of America announced it would "not

3

http://en.wikipedia.org/wiki/Security

Relevant Readings

http://en.wikipedia.org/wiki/Privacy

Page 4: “Those who desire to give up freedom in order to gain ...mjborlan/SYDE261/pdf/S2/03-03-11-Security_vs... · Bank of America On 18 December, Bank of America announced it would "not

4

Security is the degree of protection against danger, damage, loss, and criminal activity. Security as a form of protection are structures and processes that provide or improve security as a condition.

What is Security?

[Wikipedia]

Page 5: “Those who desire to give up freedom in order to gain ...mjborlan/SYDE261/pdf/S2/03-03-11-Security_vs... · Bank of America On 18 December, Bank of America announced it would "not

5

Perception of security may be poorly mapped to measurable objective security. For example, the fear of earthquakes has been reported to be more common than the fear of slipping on the bathroom floor although the latter kills many more people than the former.[1] Similarly, the perceived effectiveness of security measures is sometimes different from the actual security provided by those measures. The presence of security protections may even be taken for security itself. For example, two computer security programs could be interfering with each other and even cancelling each other's effect, while the owner believes s/he is getting double the protection.

So what does security mean to you in your daily lives?

http://urbanlegends.about.com/b/2005/06/29/are-vending-machines-deadlier-than-sharks-repost.htm

[Wikipedia]

Page 6: “Those who desire to give up freedom in order to gain ...mjborlan/SYDE261/pdf/S2/03-03-11-Security_vs... · Bank of America On 18 December, Bank of America announced it would "not

6

Security conceptsCertain concepts recur throughout different fields of security:■Assurance - assurance is the level of guarantee that a security system will behave as expected■Countermeasure - a countermeasure is a way to stop a threat from triggering a risk event■Defense in depth - never rely on one single security measure alone■Exploit - a vulnerability that has been triggered by a threat - a risk of 1.0 (100%)■Risk - a risk is a possible event which could cause a loss■Threat - a threat is a method of triggering a risk event that is dangerous■Vulnerability - a weakness in a target that can potentially be exploited by a threat security

[Wikipedia]

Page 7: “Those who desire to give up freedom in order to gain ...mjborlan/SYDE261/pdf/S2/03-03-11-Security_vs... · Bank of America On 18 December, Bank of America announced it would "not

7

Privacy (from Latin: privatus "separated from the rest, deprived of something, esp. office, participation in the government", from privo "to deprive") is the ability of an individual or group to seclude themselves or information about themselves and thereby reveal themselves selectively. The boundaries and content of what is considered private differ among cultures and individuals, but share basic common themes.

- who here values their privacy?

What does privacy mean to you as 21st century adults?

- do you have a right to privacy?

---

[Wikipedia]

Page 8: “Those who desire to give up freedom in order to gain ...mjborlan/SYDE261/pdf/S2/03-03-11-Security_vs... · Bank of America On 18 December, Bank of America announced it would "not

8

Somewhere on some server, in some SAN your life is cached. We are living a cached life. And it is going to get even more cached, as we turn to always-on wireless devices. Our RSS will be cached somewhere. So will be our thoughts that appear on blogs. Our TiVo watching patterns to music listening patterns in iTunes, and other such new conveniences are part of a new cached, convenient albeit less private life.

http://gigaom.com/2006/01/21/living-a-cached-life/

The internet has raised serious issues around privacy and the security of our personal information

Are you concerned about this information storage?

Can you do anything about it?

Page 9: “Those who desire to give up freedom in order to gain ...mjborlan/SYDE261/pdf/S2/03-03-11-Security_vs... · Bank of America On 18 December, Bank of America announced it would "not

9

Garfinkel says we need to rethink privacy in the 21st Century. “It’s not about the man who wants to watch pornography in complete anonymity over the Internet. It’s about the woman who’s afraid to use the Internet to organize her community against a proposed toxic dump - afraid because the dump’s investors are sure to dig through her past if she becomes too much of a nuisance,” Garfinkel writes.

http://www.msnbc.msn.com/id/3078854/

One argument is: - Well what are you afraid of? - What have you got to hide?- Are you just worried about being embarrassed by your interest in some weird thing?

Page 10: “Those who desire to give up freedom in order to gain ...mjborlan/SYDE261/pdf/S2/03-03-11-Security_vs... · Bank of America On 18 December, Bank of America announced it would "not

10

- I’ve got nothing to hide, go ahead and read my emails...

- I’ve got nothing to hide, but I have the right to private communications...

- Just a second...I’ve got to delete some things...

How do you feel about the government reading your emails?

Answer on the TOPHAT poll!

What about Google’s adsense “scanning” your

emails and providing targeted advertising?

Page 11: “Those who desire to give up freedom in order to gain ...mjborlan/SYDE261/pdf/S2/03-03-11-Security_vs... · Bank of America On 18 December, Bank of America announced it would "not

11

Please put up your hand if you are a member of Anonymous.

Page 12: “Those who desire to give up freedom in order to gain ...mjborlan/SYDE261/pdf/S2/03-03-11-Security_vs... · Bank of America On 18 December, Bank of America announced it would "not

12

Anonymous (used as a mass noun) is an Internet meme originating 2003 on the imageboard 4chan, representing the concept of many on-line community users simultaneously existing as an anarchic, digitized global brain.[1] It is also generally considered to be a blanket term for members of certain Internet subcultures, a way to refer to the actions of people in an environment where their actual identities are not known.[2]In its early form, the concept has been adopted by a decentralized on-line community acting anonymously in a coordinated manner, usually toward a loosely self-agreed goal, and primarily focused on entertainment. Beginning with 2008, the Anonymous collective has become increasingly associated with collaborative, international hacktivism, undertaking protests and other actions, often with the goal of promoting internet freedom and freedom of speech. Actions credited to "Anonymous" are undertaken by unidentified individuals who apply the Anonymous label to themselves as attribution.[3]Although not necessarily tied to a single on-line entity, many websites are strongly associated with Anonymous. This includes notable imageboards such as 4chan and Futaba, their associated wikis, Encyclopædia Dramatica, and a number of forums.[4] After a series of controversial, widely-publicized protests and distributed denial of service (DDoS) attacks by Anonymous in 2008, incidents linked to its cadre members have increased. [5] In consideration of its capabilities, Anonymous has been posited by CNN to be one of the 3 major successors to WikiLeaks.[6]

[Wikipedia]

Page 13: “Those who desire to give up freedom in order to gain ...mjborlan/SYDE261/pdf/S2/03-03-11-Security_vs... · Bank of America On 18 December, Bank of America announced it would "not

13

http://colbertreport.thecomedynetwork.ca/#player-areaFeb 24th, 2011 @ 3:45 - 11:16

- is Anonymous justified in these kinds of actions?

- is the Justice Department justified?

- are 40 year old men who play WOW weird?

- HBGary tries to attack Wikileaks and Journalists sympathetic to Wikileaks- Anonymous strikes back against HBGary, infiltrating email accounts, twitter, and even wiping computer data

Page 14: “Those who desire to give up freedom in order to gain ...mjborlan/SYDE261/pdf/S2/03-03-11-Security_vs... · Bank of America On 18 December, Bank of America announced it would "not

14

Bank of AmericaOn 18 December, Bank of America announced it would "not process transactions of any type that we have reason to believe are intended for Wikileaks," citing "Wikileaks might be engaged in activities … inconsistent with our internal policies for processing payments". WikiLeaks responded in a tweet by encouraging their supporters who were BoA customer to close their accounts. Bank of America has long been believed to be the target of WikiLeaks' next major release.[258]Late in 2010, Bank of America approached the law firm of Hunton & Williams to put a stop to WikiLeaks. Hunton & Williams assembled a group of security specialists, HBGary Federal, Palantir Technologies, and Berico Technologies. They decided upon a campaign of dirty tricks, which included "false documents, disinformation, and sabotage." HBGary Federalʼs CEO Aaron Barr wrote Palintir that security companies should track and intimidate people who donate to WikiLeaks. "Security firms need to get people to understand that if they support the organisation we will come after them."[259]During the 5th and 6th of February 2011, Anonymous hacked HBGary's web site, copied tens of thousands of documents from HBGary, posted tens of thousands of company emails online, and usurped Barr's Twitter account in revenge. Some of the documents taken by Anonymous show HBGary Federal was working on behalf of Bank of America to respond to Wikileaks' planned release of the bank's internal documents. Emails detailed a supposed business proposal by HBGary to assist Bank of America's law firm, Hunton & Williams, revealed the companies were willing to break the law to bring down WikiLeaks and Anonymous."CEO Aaron Barr thought heʼd uncovered the hackersʼ identities and like rats, theyʼd scurry for cover. If he could nail them, he could cover up the crimes H&W, HBGary, and BoA planned, bring down WikiLeaks, decapitate Anonymous, and place his opponents in prison while collecting a cool fee. He thought he was 88% right; he was 88% wrong."[259] ^ a b Lundin, Leigh (2011-02-20). "WikiLicks". Crime. Orlando: Criminal Brief.

WIKILEAKS and BIG BUSINESS

[Wikipedia]

Page 15: “Those who desire to give up freedom in order to gain ...mjborlan/SYDE261/pdf/S2/03-03-11-Security_vs... · Bank of America On 18 December, Bank of America announced it would "not

15

WikiLeaks is an international non-profit organisation that publishes submissions of private, secret, and classified media from anonymous news sources and news leaks. Its website, launched in 2006 under The Sunshine Press[5] organisation,[6] claimed a database of more than 1.2 million documents within a year of its launch.[7] WikiLeaks describes its founders as a mix of Chinese dissidents, journalists, mathematicians, and start-up company technologists from the United States, Taiwan, Europe, Australia, and South Africa.[8] Julian Assange, an Australian Internet activist, is generally described as its director.[9] The site was originally launched as a user-editable wiki, but has progressively moved towards a more traditional publication model and no longer accepts either user comments or edits.

- Does the government have the right to keep secrets?- Are there times when governments are justified in withholding information in the interest of the public?- Has the internet and technological advances created these kinds of situations?

[Wikipedia]

Page 16: “Those who desire to give up freedom in order to gain ...mjborlan/SYDE261/pdf/S2/03-03-11-Security_vs... · Bank of America On 18 December, Bank of America announced it would "not

16

Group Activity

Answer these simple questions as YES or NO!

- Should the government be able to keep secrets from the public?

- Should the government be able to read your emails?

In groups of 5 or 6 take 10 minutes to discuss the following:

- Should Wikileaks be allowed to publish anything it wants, even if it endangers people’s lives (like soldiers, or diplomats).

Send one person to explain your answers.