Posts

Showing posts with the label security

Data, Privacy and Security - WEIRD Topics

When it comes to Big Data, privacy and security, India’s view is totally different than that of the West. The difference is due to the answer to the following question – Do the benefits and applications of analyzing large data outweigh the privacy and security risks? And it’s not just India, all countries without pre-existing well-functioning systems look at data sets, AI and machine learning favourably since they enable better systems and better governance.   It reminded me of that term WEIRD - Western, Educated, Industrialized, Rich, and Democratic. It was used a lot to refer to the Western view of how things should be, how studies and research should be done etc is unconsciously skewed since they didn’t know or understand non-Western (or non-WEIRD) countries and cultures. Today, more and more people think that the Western views on privacy and security should be added to the list of WEIRD worldview topics , i.e., matters where Western views are inapplicable to non-WEIRD coun...

Security Issues in Software

Systems getting hacked. Ransomware. (Computer) viruses. Why are these so commonplace? Marc Goodman has a pretty good answer(s) in his book, Future Crimes . A lifetime ago, computers weren’t everywhere; nor was the Internet. While all that has changed, the Westphalian system of sovereignty hasn’t. What’s that? It was a treaty signed in 1648 that agreed that (Western) countries were “sovereign in their territory, with no role for outside authorities to meddle in a nation’s domestic affairs”. “(It) was preserved through a system of borders, armies, guards, gates, and guns.” (It’s the de facto standard for all countries today).   But today? “Bits and bytes flow freely from one country to the next without any border guards, immigration controls, or customs declarations…” A (digital) crime’s victim may be in one country, the perpetrator in a second, and the money transferred to a third. Who exactly has jurisdiction in such cases? And most countries don’t cooperate with other...

Security of all Things Internet

Security expert, Bruce Schneier, did this podcast which can be summed up in two words: interesting throughout. The term Internet of Things (IoT) refers to objects around us that “talk” via the Internet. While this opens up opportunities (your fridge tells Alexa that the milk is running out, who then tells you, and you then tell Alexa to order some milk), it opens up security risks all around. The root cause for these security risks, explains Schneier, is as simple as it may sound horrifying today: the Internet was never designed with security in mind! Because it was designed for mostly inconsequential usage, and only by academics at that. In other words, it was a conscious choice to not care about security. And boy, have those chickens come home to roost today. Ok, but why can’t security be incorporated today? Aha, there are many reasons: 1)       Complex systems are inherently hard to secure. Your smartphone is a highly complex device. And suppl...

The Net Ain't Secure

The Internet is like the Wild Wild West. The rules of the game aren’t (can’t be?) defined upfront. Rather, we evolve them as we go along because it’s impossible to know what opportunities, situations and loopholes may come up on this frontier. There’s this site called Ashley Madison whose by-line is “Life is short. Have an affair.” The site facilitates exactly that: “Have an Affair today on Ashley Madison. Thousands of cheating wives and cheating husbands signup everyday looking for an affair…. With Our affair guarantee package we guarantee you will find the perfect affair partner.” No, this isn’t a joke. It’s for real! The site has 40 million registered users. And then the site got hacked. The hackers, who call themselves the Impact Team, demanded that the site be taken down. Or else? “We will release all customer records, including profiles with all the customers’ secret sexual fantasies and matching credit card transactions, real names and addresses, and employee do...