One of the most fascinating revelations from the Snowden documents was the story of "fourth party collection," which is when the NSA hacks the spy agency of a friendly nation to suck up all the spy data it has amassed on its own people.

https://t.co/8WZ6WJigjU

1/

It's a devilishly effective spying technique and it surfaces a major risk of mass domestic surveillance - if your internal police get hacked by another nation, then that country can get all of your data. The secret police say they're spying to protect you - some protection!

2/
Even more mind-blowing is the existence of "fifth-party collection" (spying on a spy agency that's spying on another spy agency) and "SIXTH-party collection" (spying on a spy agency that's spying on another spy agency that's spying on another spy agency) .

3/
It's also fascinating because it's so obvious in retrospect. Willie Sutton robbed banks "because that's where the money is." Spooks spy on other spooks because that's where the kompromat is: gathered, sorted, filed and analyzed.

4/
This week, Google's Threat Analysis team published a warning to security researchers to be vigilant about a sophisticated threat-actor that is targeting the infosec community.

https://t.co/dlueiQsDbK

5/
Google says the attacker is working from North Korea (which strongly implies that they are working on behalf of the DPRK itself).

6/
An analysis of the attack recounts how the hackers would ingratiate themselves to infosec professionals, ask them to collaborate on interesting problems, and then slip them a poisoned software library that would take over their systems.

https://t.co/ne0Oyiri90

7/
Like fourth-party collection, this is a highly leveraged attack. Security researchers tend to have a lot of proof-of-concept malware, notes on vulnerabilities, and other juicy tools and intel that could be weaponized to attack high-level systems.

8/
Image: Cryteria (modified)
https://t.co/ICebVcdH1f

CC BY:
https://t.co/5YJhpDj3vT

eof/

More from Cory Doctorow #BLM

There are lots of problems with ad-tech:

* being spied on all the time means that the people of the 21st century are less able to be their authentic selves;

* any data that is collected and retained will eventually breach, creating untold harms;

1/


* data-collection enables for discriminatory business practices ("digital redlining");

* the huge, tangled hairball of adtech companies siphons lots (maybe even most) of the money that should go creators and media orgs; and

2/

* anti-adblock demands browsers and devices that thwart their owners' wishes, a capability that can be exploited for even more nefarious purposes;

That's all terrible, but it's also IRONIC, since it appears that, in addition to everything else, ad-tech is a fraud, a bezzle.

3/

Bezzle was John Kenneth Galbraith's term for "the magic interval when a confidence trickster knows he has the money he has appropriated but the victim does not yet understand that he has lost it." That is, a rotten log that has yet to be turned over.

4/

Bezzles unwind slowly, then all at once. We've had some important peeks under ad-tech's rotten log, and they're increasing in both intensity and velocity. If you follow @Chronotope, you've had a front-row seat to the
Today's Twitter threads (a Twitter thread).

Inside: Planet Money on HP's myriad ripoffs; Strength in numbers; and more!

Archived at: https://t.co/esjoT3u5Gr

#Pluralistic

1/


On Feb 22, I'm delivering a keynote address for the NISO Plus conference, "The day of the comet: what trustbusting means for digital manipulation."

https://t.co/Z84xicXhGg

2/


Planet Money on HP's myriad ripoffs: Ink-stained wretches of the world, unite!

https://t.co/k5ASdVUrC2

3/


Strength in numbers: The crisis in accounting.

https://t.co/DjfAfHWpNN

4/


#15yrsago Bad Samaritan family won’t return found expensive camera https://t.co/Rn9E5R1gtV

#10yrsago What does Libyan revolution mean for https://t.co/Jz28qHVhrV? https://t.co/dN1e4MxU4r

5/

More from Society

You May Also Like