Tag Archives: Data

A legislative system shock

Today the Guardian brings us the news regarding the new legislation on personal data. The interesting starts with the image of Google and not Microsoft, which is a first item in all this. I will get back to this. The info we get with ‘New legislation will give people right to force online traders and social media to delete personal data and will comply with EU data protection‘ is actually something of a joke, but I will get back to that too. You see, the quote it is the caption with the image that should have been at the top of all this. With “New legislation will be even tougher than the ‘right to be forgotten’ allowing people to ask search engines to take down links to news items about their lives“, we get to ask the question who the protection is actually for?

the newspapers gives us this: “However, the measures appear to have been toughened since then, as the legislation will give people the right to have all their personal data deleted by companies, not just social media content relating to the time before they turned 18“, yet the reality is that this merely enables new facilitation for data providers to have a backup in a third party sense of data. As I personally see it, the people in all this will merely be chasing a phantom wave.

We see the self-assured Matt Hancock standing there in the image and in all this; I see no reason to claim that these laws will be the most robust set of data laws at all. They might be more pronounced, yet in all this, I question how facilitation is dealt with. With “Elizabeth Denham, the information commissioner, said data handlers would be made more accountable for the data “with the priority on personal privacy rights” under the new laws“, you see the viewer will always respond in the aftermath, meaning that the data is already created.

We can laugh at the statement “The definition of “personal data” will also be expanded to include IP addresses, internet cookies and DNA, while there will also be new criminal offences to stop companies intentionally or recklessly allowing people to be identified from anonymous personal data“, it is laughable because it merely opens up venues for data farms in the US and Asia, whilst diminishing the value of UK and European data farms. The mention of ‘include IP addresses‘ is funny as the bulk of the people on the internet are all on dynamic IP addresses. It is a protection for large corporations that are on static addresses. the mention of ‘stop companies intentionally or recklessly allowing people to be identified from anonymous personal data‘ is an issue as intent must be shown and proven, recklessly is something that needs to be proven as well and not on the balance of it, but beyond all reasonable doubt, so good luck with that idea!

As I read “The main aim of the legislation will be to ensure that data can continue to flow freely between the UK and EU countries after Brexit, when Britain will be classed as a third-party country. Under the EU’s data protection framework, personal data can only be transferred to a third country where an adequate level of protection is guaranteed“, is this another twist in anti-Brexit? You see none of this shows a clear ‘adequate level of protection‘, which tends to stem from technology, not from legislation, the fact that all this legislation is all about ‘after the event‘ gives rise to all this. So as I see it, the gem is at the end, when we see “the EU committee of the House of Lords has warned that there will need to be transitional arrangements covering personal information to secure uninterrupted flows of data“, it makes me wonder what those ‘actual transitional arrangements‘ are and how come that the new legislation is covering policy on this.

You see, to dig a little deeper we need to look at Nielsen. There was an article last year (at http://www.nielsen.com/au/en/insights/news/2016/uncommon-sense-the-big-data-warehouse.html), here we see: “just as it reached maturity, the enterprise data warehouse died, laid low by a combination of big data and the cloud“, you might not realise this, but it is actually a little more important than most realise. It is partially seen in the statement “Enterprise decision-making is increasingly reliant on data from outside the enterprise: both from traditional partners and “born in the cloud” companies, such as Twitter and Facebook, as well as brokers of cloud-hosted utility datasets, such as weather and econometrics. Meanwhile, businesses are migrating their own internal systems and data to cloud services“.

You see, the actual dangers in all that personal data, is not the ‘privacy’ part, it is the utilities in our daily lives that are under attack. Insurances, health protection, they are all set to premiums and econometrics. These data farms are all about finding the right margins and the more they know, the less you get to work with and they (read: their data) will happily move to where ever the cloud takes them. In all this, the strong legislation merely transports data. You see the cloud has transformed data in one other way, the part Cisco could not cover. The cloud has the ability to move and work with ‘data in motion’; a concept that legislation has no way of coping with. The power (read: 8 figure value of a data utility) is about being able to do that and the parties needing that data and personalised are willing to pay through the nose for it, it is the holy grail of any secure cloud environment. I was actually relieved that it was not merely me looking at that part; another blog (at https://digitalguardian.com/blog/data-protection-data-in-transit-vs-data-at-rest) gives us the story from Nate Lord. He gives us a few definitions that are really nice to read, yet the part that he did not touch on to the degree I hoped for is that the new grail, the analyses of data in transit (read: in motion) is cutting edge application, it is what the pentagon wants, it is what the industry wants and it is what the facilitators want. It is a different approach to real time analyses, and with analyses in transit those people get an edge, an edge we all want.

Let’s give you another clear example that shows the value (and the futility of legislation). Traders get profit by being the first, which is the start of real wealth. So whoever has the fastest connection is the one getting the cream of the trade, which is why trade houses pay millions upon millions to get the best of the best. The difference between 5ms and 3ms results in billions of profit. Everyone in that industry knows that. So every firm has a Bloomberg terminal (at $27,000 per terminal), now consider the option that they could get you that data a millisecond faster and the automated scripts could therefor beat the wave of sales, giving them a much better price, how much are they willing to pay suddenly? This is a different level of armistice, it is weaponised data. The issue is not merely the speed; it is the cutting edge of being able to do it at all.

So how does this relate?

I am taking you back to the quote “it would amount to a “right to be forgotten” by companies, which will no longer be able to get limitless use of people’s data simply through default “tick boxes” online” as well as “the legislation will give people the right to have all their personal data deleted by companies“. The issue here is not to be forgotten, or to be deleted. It is about the data not being stored and data in motion is not stored, which now shows the futility of the legislation to some extent. You might think that this is BS, consider the quote by IBM (at https://www.ibm.com/developerworks/community/blogs/5things/entry/5_things_to_know_about_big_data_in_motion?lang=en), it comes from 2013, IBM was already looking at matters in different areas close to 5 years ago, as were all the large players like Google and Microsoft. With: “data in motion is the process of analysing data on the fly without storing it. Some big data sources feed data unceasingly in real time. Systems to analyse this data include IBM Streams “, here we get part of it. Now consider: “IBM Streams is installed on nearly every continent in the world. Here are just a few of the locations of IBM Streams, and more are being added each year“. In 2010 there were 90 streams on 6 continents, and IBM stream is not the only solution. As you read that IBM article, you also read that Real-time Analytic Processing (RTAP) is a real thing, it already was then and the legislation that we now read about does not take care of this form of data processing, what the legislation does in my view is not give you any protection, it merely limits the players in the field. It only lets the really big boys play with your details. So when you see the reference to the Bloomberg terminal, do you actually think that you are not part in the data, or ever forgotten? EVERY large newspaper and news outlet would be willing to pay well over $127,000 a year to get that data on their monitors. Let’s call them Reuter Analytic Systems (read: my speculated name for it), which gets them a true representation of all personalised analytical and reportable data in motion. So when they type the name they need, they will get every detail. In this, the events that were given 3 weeks ago with the ITPRO side (at http://www.itpro.co.uk/strategy/29082/ecj-may-extend-right-to-be-forgotten-ruling-outside-the-eu) sounds nice, yet the quote “Now, as reported by the Guardian, the ECJ will be asked to be more specific with its initial ruling and state whether sites have to delete links only in the country that requests it, or whether it’s in the EU or globally” sounds like it is the real deal, yet this is about data in rest, the links are all at rest, so the data itself will remain and as soon as HTML6 comes we might see the beginning of the change. There have been requests on that with “This is the single-page app web design pattern. Everyone’s into it because the responsiveness is so much better than loading a full page – 10-50ms with a clean API load vs. 300-1500ms for a full HTML page load. My goal would be a high-speed responsive web experience without having to load JavaScript“, as well as “having the browser internally load the data into a new data structure, and the browser then replaces DOM elements with whatever data that was loaded as needed“, it is not mere speed, it would allow for dynamic data (data in motion) to be shown. So when I read ‘UK citizens to get more rights over personal data under new laws‘, I just laughed. The article is 15 hours old and I considered instantly the issues I shown you today. I will have to wait until the legislation is released, yet I am willing to bet a quality bottle of XO Cognac that data in motion is not part of this, better stated, it will be about stored data. All this whilst the new data norm is still shifting and with G5 mobile technologies, stored data might actually phase out to be a much smaller dimension of data. The larger players knew this and have been preparing for this for several years now. This is also an initial new need for the AI that Google wants desperately, because such a system could ascertain and give weight to all data in motion, something IBM is currently not able to do to the extent they need to.

The system is about to get shocked into a largely new format, that has always been the case with evolution. It is just that actual data evolution is a rare thing. It merely shows to me how much legislation is behind on all this, perhaps I will be proven wrong after the summer recess. It would be a really interesting surprise if that were the case, but I doubt that will happen. You can see (read about that) for yourself after the recess.

I will follow up on this, whether I was right or wrong!

I’ll let you speculate which of the two I am, as history has proven me right on technology matters every single time (a small final statement to boost my own ego).

 

Leave a comment

Filed under Finance, IT, Law, Media, Politics, Science

Fear is a tool

It started with a thought, one I have had for a little while and one that had been voiced in the past. Today, in the Guardian we see part of this in the article called ‘How we sold our souls – and more – to the internet giants‘ (at http://www.theguardian.com/technology/2015/may/17/sold-our-souls-and-more-to-internet-giants-privacy-surveillance-bruce-schneier). I respectfully disagree with parts of this.

The first premise is the important one.

Did we sell our souls, or were governments on a global scale lacks and slow regarding the rights of privacy?

That is an important question as it is linked all over the place. We tend to look (as I have mentioned numerous times) regarding the information the intelligence community gets, but at the same time we allow ourselves to get mined and exploited by every social network available. A nice example that the article uses is the Hello Barbie. The Washington Post gave us loads of information in March (at http://www.washingtonpost.com/blogs/the-switch/wp/2015/03/11/privacy-advocates-try-to-keep-creepy-eavesdropping-hello-barbie-from-hitting-shelves/), but it did not get the global visibility it required to have.

You see, there is nothing wrong with an interactive toy. I reckon that as programs became more and more interactive, then so would toys and the Hello Barbie doll is the premium evolution for children. The big issue is not the toy, but this simple line: “As the doll ‘listens’, audio recordings travel over the Web to a server where the snippets of speech are recognized and processed. That information is used to help form Hello Barbie’s responses” Why? Why use the web? Why not connect to a device that has the software installed? The answer is simple, this is only in one part about the doll, it is a lot more about collected data and data is value (their marketing department will come with some “it’s  all so much easier via the web answer”). Collecting the questions of children gives way to trendsetting and to marketable exploitation. Of course, in that light the adult edition, where the answer to every question becomes “not now darling, I have a headache” is likely only 6 months away.

You think I am kidding? Data is the core of value, marketability of data is the new ‘O’ for industrials. Knowing how to push the button by answering the not asked questions in advertisement is the rage, the El Dorado of the marketing industry. So when we see the quote at the end of the article “Mattel and ToyTalk, the San Francisco-based start-up that created the technology used in the doll, say the privacy and security of the technology have been their top priority“, we should state that if security and safety were such important parts, you would have kept these issues local and not via the web. As for security, if hackers can take down Sony, then Mattel might not be that much of a challenge and in that light, that collected data would be worth a fortune, so people will get that data one way or another.

Beyond the toy need of a child is the need for health. That part is dealt with in “Many medical devices are starting to be internet-enabled, collecting and reporting a variety of biometric data. There are – or will be soon – devices that continually measure our vital signs, moods and brain activity“, now we get to the juicy stuff! You see in the UK there is the Data Protection Act 1998. Yet here we see the following issue:

Section 36 gives us: ‘Personal data processed by an individual only for the purposes of that individual’s personal, family or household affairs (including recreational purposes) are exempt from the data protection principles and the provisions of Parts II and III’. So Barbie is already exempt in this case.

Even though section 2 gives us in section 11 ‘Right to prevent processing for purposes of direct marketing’, which is in part II, so Barbie is again exempt.

However, we do see protection under part one section 8. Here we see: ‘Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data’. Yet the danger here is that this regards ‘personal data‘, the definition under part one states: “personal data means data which relate to a living individual who can be identified”, which is not the part that is transferred, so it does not count. The personal data is what mommy, daddy or junior enter within a website or social media, outside of the UK (or Commonwealth), so that they can receive a much more personal ‘experience‘ with Miss Barbie. This is at the core of the problem, but it is only one factor. The same applies in 99% of the cases to healthcare and fitness equipment that connects through the Bluetooth, Wi-Fi and the web link. All this gets collected. So when we wonder regarding the excuses on software on cheaper through the online experience, several parts give clear indication that this is about collecting data, because data is the new gold. How much do you think a health care provider is willing to pay, so that they have data that allows to cut off, or additionally charge the riskiest 10%? Even though those people are already paying premium, to have a check on the safest group and to flag the least safe group is worth a bundle. Anyone selling that data for less than a 9 figure number is getting royally screwed.

And it goes on beyond the mere computer and the internet. More precisely your smartphone. The apps you install track you here as well. They track your location and sometimes download your address book, calendar, bookmarks and search history. Not to mention a host of other parts. The most annoying part of it all is that you the user gets to pay for your bandwidth, so if your data gets downloaded, you are likely to see background usage of the data and the bandwidth used goes to your total usage.

The gem of the Guardian article is shown near the end “And it’s all possible because laws have failed to keep up with changes in business practices

This has been the number one issue for well over 4 years now and the lawmakers have basically been sitting on their hands, pretty much all over the commonwealth I might add, because data is money and those captains of industry require overhead (read data profits). It comes down to the same issue with the laughingly disturbing discussion on movie piracy. Telco’s rely on bandwidth, without that, there profits go down to the basement, in that same light their reliance on data seems to hinder governments to react in a timely manner. Research, investigations and commissions. We have seen data issues since before Edward Snowden. Yes, in all these years, how many successful alterations were made to the Data Protection Act 1998, via either legislation and/or the House of Lords? You do the math, yet the answer is simple. As I see it, look at your two hands and do not use the 10 fingers that is how often, a mere ZERO times! Just like the internet consumer change, the internet data change has seen just as many evolutions.

The worst is however yet to come!

You see, the newer mobile phones often have the capacity that surpasses many laptops and tablets. I witnessed just 4 days ago how a friend used his mobile as a SharePoint because he had to update his PS4. What He had not realised is that the PS4 also started to update his installed games. It took him less than two minutes to realise this and in that time his 2GB bandwidth was gone! Welcome to 4G bandwidth!

He’ll lose an additional $10, so he did not think it was a biggie, but now consider how much data can be passed over to wherever the applications decides. So when we get these small messages, when we are lulled into a sense of ‘security’ consider where your data is and who else has access. That is at the heart of the matter, as well as the heart of the legislative failing. Who else has access! When data is stored at any third party provider, the app maker might guarantee that THEY will not allow access to the data, but that does not state that this is the case, you see, if they have the data parked in any other provider, what does the rules of those providers stipulate? Only they? Only the executing service agents? The world of data is quite literally the new Wild West of Business and IT, a reasonable untapped frontier and we all forgot that we think that data is there and only we can access our little field of data, whilst in reality and corporation with a tractor can get to any part of that data field. It is all nicely settled in the line “are exempt from the data protection principles”, so as we consider our data and why we are not keeping it local, consider one final ‘deletable’ part, which is also in the Guardian article “In 2009, Amazon automatically deleted some editions of George Orwell’s Nineteen Eighty-Four from users’ Kindles because of a copyright issue. I know, you just couldn’t write this stuff anymore ironically“, yet even though the irony is out there, consider that your data is also on the cloud. So what happens when that gets deleted? Not by you or by the provider, but by a third party who got around it all? You might wonder why that is an issue, if you do then consider the final question in this dilemma: ‘Who is the owner of a deleted file?’

So here is the fear part:

Where is your data?
Who ‘owns’ it?
Who has access to it (besides you)?

These are one side of the fear equation, on the other side you have the data local storage, which you must personally manage, you must backup this data and you must keep track whether it is all backed up. Some users feel uncomfortable with that. A nice example can always be found when someone in your vicinity cries over a crashed mobile and all contacts lost (I saw that a few times happen to people I know in 2014).

One fear or another, they’re gonna getcha!

So you the user have gone with the flow and the privacy for billions is up for grabs because no one wondered, asked or pressured, now that part is almost indefinitely gone, only by adjusting the laws can we see a restoration of proper privacy of data and information, but those who rely on the value of data are extremely intent on not letting those changes happen. Consider this part from an earlier Guardian article “Facebook places tracking cookies on users’ computers if they visit any page on the facebook.com domain, including fan pages or other pages that do not require a Facebook account to visit“, do you think Google is any different? So as you are tracked and as data is combined from social media, from websites, devices and even toys. How much privacy do you think you are enjoying at present?

Now we get to a truly speculative part. Consider Google with its Nexus range. Now the new Nexus 6 looks nice (way out of my budget range), there is a 32GB and a 64GB version. No issues here! In all aspects a decent game changer for the Nexus fan. Now we get to the Nexus 9, the tablet. Before I give my view, let’s refer you to Forbes, here we see some interesting details (at http://www.forbes.com/sites/ewanspence/2013/01/29/apples-128GB-ipad-just-gave-every-android-tablet-manufacturer-a-headache/), an important fact is that this is a January 2013 review, so more than two years old! In that regard the specs do not seem to have changed! So this ‘new’ tablet is only to be begotten in a 16GB or 32GB version. So it has a lot less storage than the Nexus 6 mobile phone. It has a few more weaknesses, but basically, as Apple already had a 128GB edition, Google remains at 25%. In my view this was intentional! The machine was released late November 2014. Why would they not have a version that is at least 64GB? My iPad 1 (yes version One) which I bought in 2011 already had 64GB). This is not a mere oversight from a bungling manager, as I see it this is an intentional drive to get people towards Google drive, with data stored in a place where some might have access (the non-user that is). Remember, this is pure speculation on my side! Google could have made a contender and is offering nothing more than a consolation price. Offering it at a very competitive price, but it comes with the foresight that people will be driven to the Google Drive, sooner rather than later!

Please feel free to reject this notion, but ask yourself, in the fight between IOS and Android, why would Google not offer a machine a lot more competitive? This is at the heart of the matter, this is as I see it the crux of it. There is of course a danger that we make ‘relationships’ between fiction and facts in events that are a figment of our imagination, but in the competitive industry that is called ‘mobile devices’ to remain behind to this extent to that degree calls for questions, does it not?

There is one part to add, the Guardian article was originally adapted (by the Guardian) from ‘Data and Goliath’ by Bruce Schneier, Bruce Schneier is a security technologist and CTO of Resilient Systems Inc. He can also be found tweeting his heart out as @schneierblog.

 

Leave a comment

Filed under IT, Law

Last Clooney of the year

My idea of stopping my writing until the new year has truly been bombarded into a sense of that what is not meant to be, so back to the keyboard I go. One reason is the article ‘‘Nobody stood up’: George Clooney attacks media and Hollywood over Sony hack fallout’ (at http://www.theguardian.com/film/2014/dec/19/george-clooney-sony-pictures-hack-the-interview), which I missed until this morning. So has the actor from ER become this outspoken because of his marriage to Human rights lawyer Amal Alamuddin? Nah! That would be incorrect, he has been the champion of major causes for a long time, outspoken, thinking through and definitely a clever cookie with a passion for Nespresso!

The article kicks off with a massive strike towards to goal of any opponent “George Clooney has spoken of his frustrations with the press and his Hollywood peers at failing to contain the scandal around The Interview, which Sony has pulled from cinema release as well as home-video formats“. It goes a lot deeper then he spoke it does, perhaps he fathomed the same issues I have had for some time now, some mentioned in my previous blog ‘When movies fall short‘ (at https://lawlordtobe.com/2014/12/15/when-movies-fall-short/), two weeks ago.

I will take it one-step further, several players (not just Sony) have been skating at the edge of competence for some time now, as I see it, they preferred contribution (revenue minus costs) regarding issues of security. It remains debatable whether this was intentional or just plain short-sightedness, that call requires levels of evidence I have no access to.

By the way, Mr. Clooney, you do realise that this topic has the making of an excellent movie, not unlike the largely unnoticed gem ‘Margin Call‘ with Kevin Spacey, Paul Bettany and Zachary Quinto.

The one quote I object to (to some extent) is “With just a little bit of work, you could have found out that it wasn’t just probably North Korea; it was North Korea … It’s a serious moment in time that needs to be addressed seriously, as opposed to frivolously”. You see, the inside job is a much more likely part. Yes, perhaps it was North Korea (requiring evidence), yet this would still not be the success they proclaim it to be without the inside information from disgruntled (or greedy) employees. In addition to the faltering security Sony has needed to ‘apologise’ for twice now (the Sony PSN hack of 2011), none of which was correctly covered by the press regarding this instance either. There was the press gap of November 2013, so we have at least two events where the press catered with silence, but at the price (read: reward) of….?

Yet the part: “He joins others who voiced their dismay at Sony’s decision, including Stephen King, Judd Apatow and Aaron Sorkin. Rob Lowe, who has a small role in The Interview, compared Sony to British prime minister Neville Chamberlain and his capitulation to Nazi Germany before the second world war“, is more than just a simple truth, it shows a fear of venue, cater to the profit. Chamberlain was from the old era and he failed to perceive the evil that Adolf Hitler always was. That view was partially shown by Maggie Smith in ‘Tea with Mussolini‘ too, yet the opposite was strongly shown in Remains of the Day, when Christopher Reeve as Jack Lewis states: “You are, all of you, amateurs. And international affairs should never be run by gentlemen amateurs. Do you have any idea of what sort of place the world is becoming all around you? The days when you could just act out of your noble instincts, are over. Europe has become the arena of realpolitik, the politics of reality. If you like: real politics. What you need is not gentlemen politicians, but real ones. You need professionals to run your affairs, or you’re headed for disaster!

This hits the Sony issue straight on the head. Not that the Gigabytes of data are gone, but that they got access to this data at all. IT requires a new level of professionals and innovator, a lesson that is yet to be learned by those having collected Exabyte’s of data. It is a currency that is up for the taking with the current wave of executives that seem to lack comprehension of this currency. Almost like the 75-year-old banker who is introduced to a bitcoin, wondering where the gold equivalent is kept. The new order will be about IP, Data and keeping both safe. So, it is very much like the old Chamberlain and Hitler equation, we can see Chamberlain, but we cannot identify the new Hitler because he/she is a virtual presentation of an identity somewhere else. Likely, a person in multiple locations, a new concept not yet defined in Criminal Law either, so these people will get away with it for some time to come.

Yet the final part also has bearing “Clooney was one of the Hollywood stars embarrassed by emails being leaked as part of the hack. Conversations between him and Sony executives showed his anxiety over the middling reception for his film The Monuments Men, with Clooney writing: “I fear I’ve let you all down. Not my intention. I apologize. I’ve just lost touch … Who knew? Sorry. I won’t do it again.”“, personally he had no reason to be embarrassed, when your boss spills the beans (unable to prevent security), do you blame the man or the system that is this flawed?

Why has it bearing? Simple, he shows to be a man who fights and sometimes fails. He states to do better, just as any real sincere person would be, a real man! By the way, since 2011 Sony still has to show such levels of improvement. A lacking view from the people George Clooney served in a project, so we should not ignore the need to look at those behind the screens and the press should take a real hard look at what they report and on where their sources are, that same press that has not scrutinised its sources for some time. When was the last time we asked the press to vouch for ‘sources told us‘?

Consider the quote “We cannot be told we can’t see something by Kim Jong-un, of all fucking people … we have allowed North Korea to dictate content, and that is just insane“. As I mentioned in the previous blog, with the bulk of the intelligence community keeping their eyes on North Korea, why is there no clear evidence that North Korea did this? Not just the US both United Kingdom and France have access to an impressive digital arsenal, none have revealed any evidence. Consider that the École polytechnique under supervision of French defence is rumoured to be as savvy as GCHQ, can anyone explain how those three cannot see clearly how North Korea did this? So, either, North Korea is innocent and just surfing the waves of visibility, or the quote by George Clooney in the Guardian “the world just changed on your watch, and you weren’t even paying attention” would be incorrect. The quote would be “the world just changed on your watch, and those in charge do not comprehend the change“. In my view of Occam’s razor, the insider part is much more apt, the other option is just way to scary, especially as the IT field is one field where North Korea should be lacking on several fronts.

I will let you decide, have a wonderful New Year’s eve!

Leave a comment

Filed under Finance, IT, Law, Media, Military, Politics