Tag Archives: Hop+1

Fear of being right

That is what I face at times. I get that my ‘idea’ of safety is a little overdrawn, but I have seen the stupidity of greed driven and how those seeking the stupid and greedy are willing to exploit that. I am of course referring to the really organised criminals (criminals with Filofaxes). That is the expected setting and on February 11th 2024 I wrote ‘Don’t take my word’ (at https://lawlordtobe.com/2024/02/11/dont-take-my-word/) I was considering the danger that a place like Funnel was presenting itself to be. And the presented advertising (a lot of it on LinkedIn)

showed a setting that I feared and guess what? I was partially right. I was right because that side was exploited and I was wrong as it was not Funnel who gave the setting. It was a place called Mixpanel where we see “more than 200 million premium users that their data may have been exposed when hackers breached third-party analytics provider Mixpanel” and last month we were given ‘Data breach at OpenAI through analytics provider Mixpanel platform’, which was seen (at https://securitybrief.com.au/story/data-breach-at-openai-through-analytics-provider-mixpanel-platform) you can wallow as much as you like that I was wrong, but that another platform provider is the first to fall, does not mean that I was wrong. The setting of ‘ease’ safety which they called “Hey marketer, tired of wasting time downloading and cleaning data from all your advertising platforms? It’s time to meet

Funnel. Save time, improve performance, get better insights with Funnel.” As I personally see it ‘tired of downloading’ should be seen as ‘safety towards your data’ and “cleaning data” often implies “validating and verifying the data you are using”, so if there are people that are thinking I am a proverbial shit bucket, consider the image below.

Where we see that in the proverbial instant. That resulted in the loss of some “200 million users have data and search history stolen” and yes, the 200 million records could see the setting that these 200,000,000 million users will get phased and the companies they optionally worked for too. That is the larger setting of being lazy, or being contemplated towards the security they never really had. Why did they not have that security? Because certain settings negate safeties that are and as I see it, Mixpanel who by the opinion of some is seen as “a product analytics platform that helps businesses track user interactions on their websites and apps to understand behavior, improve products, and drive growth” and as I see it, it is driving growth for the really organised criminals and now as we see (at https://securitybrief.com.au/story/data-breach-at-openai-through-analytics-provider-mixpanel-platform) we are given “The incident was related to unauthorised access to a dataset within Mixpanel’s systems. OpenAI reported that an attacker exported data containing certain identifiable information of API account users. Details potentially exposed included names provided on API accounts, email addresses, approximate location information, operating system and browser details, referring websites, and the organisation or user IDs linked to the API accounts. OpenAI emphasised that no chat logs, API requests, passwords, keys, payment details or sensitive identification documents were accessed. The data breach affected only information collected for analytics purposes through Mixpanel.” I get that this is the OpenAi answer, but it seems shallow, short, and perhaps that is all it is, but there is a second setting. Either the ‘provider’ who sounds like Promohub is giving us a larger pool of users, or some clever person might be insightful enough to combine the data of two pools of data and see what could be linked, because any person whose ‘shortcomings’ are exposed will seek other ways to hide the ‘shortfall’ and that is exactly what criminals are banking on. OK, this is speculation but if I had these two pools of data, I the first thing I would do is to seek a common ground (like an email address) and see what else I can find. This is how I found the weakness towards the Pentagon using the HOP+1 solution (which is wrongly analyzed by what some call AI) it was the first thing I did last month. And now again I am right. To be clear, the article on Funnel was about Funnel and as far as I know it was never transgressed upon. It was merely a fear I held and the fear was shown correctly at Mixpanel, not Funnel.

So whilst OpenAI correctly gives us “Information potentially accessed through Mixpanel may expose users to an increased risk of phishing or social engineering attempts.

Names, email addresses, and user identifiers were among the details exposed. OpenAI has advised all customers and users to remain vigilant for any suspicious or unsolicited communications that could be related to this incident. The company reiterated that it does not request sensitive information such as passwords, API keys, or verification codes via email, text, or chat. Users have also been encouraged to enable multi-factor authentication as an additional protective measure for their accounts.

And why am I now up in arms? Because I got the word through another source relating to another vendor and that implies that there are at least three data sources exposed and those with connected data will be at risk. As such there is little risk for OpenAI and its users if it is used correctly, but when is that the case and it falls back on the users, not on OpenAI. There is an old premise that I usually phrase. If 5 vendors have a 10% loss, the customer is at risk of losing 50% and that is what the danger is here. And when this is applied to 200,000,000 users, the losses could be close to astronomical. 

Now we can argue that there is no such risk, but that answer is coming mostly from people claiming to have no P#Hub account. Do they? I cannot tell, but they know if they have or not. And to also be clear, there is absolutely nothing wrong with having multi-factor authentication on any account you have. Those people are as I personally see it the least in danger.  But that is the setting that we are avoiding to look at. As I have said (way too often) that nonrepudiation is the way to go is showing to be the correct setting yet again. 

Have a great day all, only 11 hours until Friday, or in Hobbit terms Frododay, the day you have two breakfasts and three lunches until the beer o clock chimes.

Leave a comment

Filed under IT, Media, Science

Thoughts of a different streak

That is what is bothering me. You see I had a weird ‘daydream’ there could be all kinds of reasons to have this dream, but it struck me as weird at the time. You see I was offered a sweet position in the Starlink program in tech support and I was placed in Abu Dhabi, there were two other tech support locations. Toronto and Sydney these three centers give reasons for 24 hours support and I was added to the Abu Dhabi station (from Sydney). It was a nice dream of having a decently paid job, but that was not the part that was bugging me. In the dream The US Department of War had taken control of Starlink (I have no idea why) and its was supposed to be a short term one. But the issue kept nagging on me. Why would they even need it? And these aren’t facts. It was a dream I had, a day dream no less, no nothing factual.

My brain has seemingly connected the fact “Astronomy Disruption: This leakage disrupts radio telescope observations, specifically in the 10.7 to 12.7 GHz range, making it harder for astronomers to observe the universe” as well as “Starlink satellites are emitting unintended, low-level electromagnetic radiation that interferes with radio astronomy” but my brain (not to most obliging element in this universe) is connecting this to an old intrusion solution I devised. It was the Hop+1 solution I thought through when we saw the news on the Sony Intrusion and we now see “refers to the major 2014 cyberattack on Sony Pictures Entertainment (SPE), where hackers (Guardians of Peace) stole massive amounts of sensitive data, leaked unreleased films, and disrupted operations, linked to North Korea due to the film The Interview. There were also significant breaches involving the PlayStation Network (PSN) in 2011 (77 million accounts) and 2014, and a 2023 incident affecting Sony employees via a MOVEit vulnerability. ” I was of the mindset (as North Korea was pointed at) that they lacked the knowledge to do this. I wrote this piece on September 30th 2017 in ‘The Good, the Bad, and North Korea’ (at https://lawlordtobe.com/2017/09/30/the-good-the-bad-and-north-korea/). The article has a few other points, but my mind started to think that this was most likely an inside job, but in other setting how could it be done and with the Defence department and the NSA in mind, I created HOP+1. I make some mention of it in there. The insides were a little too well working (in my mind) to publish it out there, no need to give hackers any more handles. But then mind might have been mulling over, that if there is leakage and disruption, it might be used in other ways too. It might not have the desired initial effect, but as I see it, these satellites will have been set to a reengineered setting of Cisco solutions. And that would make sense and as such HOP+1 would be back in business.

Is it that simple? I have no idea, but my brain is trying to tell me something that I cannot yet see (or I am blatantly ignoring myself) and in part there is a setting that HOP+1 relied on an inside intrusion (or break-in) at a location that in on the hop path, no bunnies required and the outcome is usually successful as I have seen the laziness of IT people all over the lands (Netherlands, UK, Germany, Sweden, USA and Australia) as such I feel that my HOP+1 would work, but in Starlink, these blighters cannot be reached with a normal staircase, so I have no idea, but I think my mind has worked out what could be done with a program approach in the setting from 10.7 to 12.7 GHz range, but I am fishing here (my brain won’t tell me what it has figured out. Perhaps it is making me go through the motions. 

Well that is it for now, perhaps there will be another sequence on this if I figure out what I had figured out. It is almost midnight (70 minutes from now) so have a great day I will turn the Sahara forests into a desert by snoring all the wood away.

Leave a comment

Filed under IT, Law, Military, Politics, Science

In retrospect

I (for the most) react to facts, as I do now, but the results are not anticipated new facts, what comes next is pure speculation, no matter how correct I think I am, it is speculation and that needs to be said up front. Even as I start now, my mind is racing through speculative ideas and options in other realms (science realms no less), but I digress. The thoughts started with a Reuter article called ‘Analysis: Biden’s COVID-19 strategy thwarted by anti-vaxxers, Delta variant’, the article (at https://www.reuters.com/world/us/bidens-covid-19-strategy-thwarted-by-anti-vaxxers-delta-variant-2021-07-29/) gives us “Dr. Peter Hotez, a vaccinologist and dean of the National School of Tropical Medicine at Baylor College of Medicine, said the Biden administration’s acknowledgement of the “terrible impact” of the anti-vaccine movement was important, but he said the government could do more. “Anti-science is arguably one of the leading killers of the American people, and yet we don’t … treat it as such. We don’t give it the same stature as global terrorism and nuclear proliferation and cyber attacks,” he said”, it might be a mere quote, it might be the paraphrasing from the article writer, which is not a negative view, but it got me thinking. When we see the anti-vaxxer movements in the US and EU, they are uncannily effective, they are almost too effective. For the most and proven since the 90’s, the anti-vaxxers are either religiously inclined like the Dutch people in Giethorn (their ‘sort of’ version of Amish) or loons (often people who are one shade away from being absolutely bug-nuts). In the first, these people are driven and they are also self isolationists, it is merely about them and their community, it makes them a danger to themselves, not to others. The second group is a danger to all, but often so stupid they merely hit other stupid people. These anti-vaxxers are driven, not merely by intelligent people, no, they are driven like they are terrorist tools, like biological DOS agents and they are growing. These people are not accepting any scientific evidence, they forward non-scientific papers as ‘their’ evidence and they are not merely more effective, they are almost centrally driven by a similar source. 

In the UK the Guardian is giving visibility to Kate Shemirani, in the USA we see Alabama Curt Carpenter and the list grows. Someone is somehow fuelling this, yes this is speculative and this is not merely the power of social media, someone had months to prepare the weaker minded and target them in a direction, limelight seeking nobodies all wanting their limelight with as large as an audience as possible. The evidence is not clear and as such this is speculation, yet consider the timelines of each of these Anti-vaxxers, what their audience was a year ago and each month after that. This goes beyond buying likes on places like Facebook. Some people are fuelling these ‘bright’ illumination spots and they are not done, even as they are retracting their ‘assistance’ there is still a digital footprint and it is now diminishing. Yes, I admit upfront that my view is speculative, but my speculation fits the profile, are the US and the EU under attack from bio-terrorists? You might think that they are not the same, but there you would be wrong. In this I grasp back to a writing from 2012 called ‘A Proposed Universal Medical and Public Health Definition of Terrorism’. Here we see “We propose the following universal medical and public definition of terrorism: The intentional use of violence — real or threatened — against one or more non-combatants and/or those services essential for or protective of their health, resulting in adverse health effects in those immediately affected and their community, ranging from a loss of well-being or security to injury, illness, or death”, in this, if even one of my speculations are proven, these anti-vaxxers become complicit in acts of terrorism. Did you even consider that? Now, there is a dangerous fence. I am not debating THEIR right to be anti vaccinated. If they die, they only have themselves to thank, just like Curt Carpenter. Yet by attacking science by non-science and debunked non-facts, the setting changes and that is where we are now. What should have been a straight path to recovery is now a much larger issue. The delay is not on President Biden, and now that we can optionally see that the US is yet again under terrorist attack his priorities need to change, attacking big-tech is futile and counter productive, the laws needs adjusting free speech, it needs to be validated by accountability. 

And for the love of god, can some well trained data analyst please take a look at the timeline of these anti-vaxxers? I think it is time to look at timelines here and that is when my brain went into some sort of overdrive. It goes back when I designed an intrusion system that stayed one hop away from a router table between two points and to infect one of the routers to duplicate packages from that router on that path, one infection tended to not be enough, 2-3 infections needed to be made so that the traffic on that route between two points could be intercepted, I called it the Hop+1 solution, I came up with it whilst considering the non-Korean Sony hack. That  thought drove me to think of an approach to find the links. In the first we most likely need to find on where and when they accessed the dark web, then we see another part, because if we can find their access, we can optionally see others too, when we have that list and we can correlate it to other anti-vaxxers we have an optional pattern for action. No matter how this is seen it will be staged towards my speculation, something that needs proof, proof is required to give validity to actions that follow. I believe that I am correct, but I admit that it is a speculative push in a path towards thinking something is what I personally think it is, not a path towards evidence, evidence needs to be found and the evidence that is made to fit the solution, is no evidence, it is like stating that there is a linear relationship when you only have two plot points. A pattern of evidence is required, it is always about the patterns. 

So when I look at the ‘in retrospect’ part, I am wondering when the connections were there in the early stages and I also wonder why the others are not on that path yet (or seemingly yet). The media is only partly to blame, yes they give limelight, but that was their job from the early days, like the people exploiting Google cookies, the media can be exploited too, seeking the limelight is not a crime, but in conjunction with a terrorist agenda we are on new shaky grounds, and that is the problem, any law eagerly over-quick created is pointless whilst inaction is useless, caught between two rocks whilst the floor is not lava it is the ever exploiting media, exploiting for clicks, for visibility and circulation, whilst calling it ‘the people have a right to know’. This has the option of heading into a really bad direction soon enough. Will it? I have absolutely no idea.

Leave a comment

Filed under IT, Military, Politics, Science