Tag Archives: nonrepudiation

Fear of being right

That is what I face at times. I get that my ‘idea’ of safety is a little overdrawn, but I have seen the stupidity of greed driven and how those seeking the stupid and greedy are willing to exploit that. I am of course referring to the really organised criminals (criminals with Filofaxes). That is the expected setting and on February 11th 2024 I wrote ‘Don’t take my word’ (at https://lawlordtobe.com/2024/02/11/dont-take-my-word/) I was considering the danger that a place like Funnel was presenting itself to be. And the presented advertising (a lot of it on LinkedIn)

showed a setting that I feared and guess what? I was partially right. I was right because that side was exploited and I was wrong as it was not Funnel who gave the setting. It was a place called Mixpanel where we see “more than 200 million premium users that their data may have been exposed when hackers breached third-party analytics provider Mixpanel” and last month we were given ‘Data breach at OpenAI through analytics provider Mixpanel platform’, which was seen (at https://securitybrief.com.au/story/data-breach-at-openai-through-analytics-provider-mixpanel-platform) you can wallow as much as you like that I was wrong, but that another platform provider is the first to fall, does not mean that I was wrong. The setting of ‘ease’ safety which they called “Hey marketer, tired of wasting time downloading and cleaning data from all your advertising platforms? It’s time to meet

Funnel. Save time, improve performance, get better insights with Funnel.” As I personally see it ‘tired of downloading’ should be seen as ‘safety towards your data’ and “cleaning data” often implies “validating and verifying the data you are using”, so if there are people that are thinking I am a proverbial shit bucket, consider the image below.

Where we see that in the proverbial instant. That resulted in the loss of some “200 million users have data and search history stolen” and yes, the 200 million records could see the setting that these 200,000,000 million users will get phased and the companies they optionally worked for too. That is the larger setting of being lazy, or being contemplated towards the security they never really had. Why did they not have that security? Because certain settings negate safeties that are and as I see it, Mixpanel who by the opinion of some is seen as “a product analytics platform that helps businesses track user interactions on their websites and apps to understand behavior, improve products, and drive growth” and as I see it, it is driving growth for the really organised criminals and now as we see (at https://securitybrief.com.au/story/data-breach-at-openai-through-analytics-provider-mixpanel-platform) we are given “The incident was related to unauthorised access to a dataset within Mixpanel’s systems. OpenAI reported that an attacker exported data containing certain identifiable information of API account users. Details potentially exposed included names provided on API accounts, email addresses, approximate location information, operating system and browser details, referring websites, and the organisation or user IDs linked to the API accounts. OpenAI emphasised that no chat logs, API requests, passwords, keys, payment details or sensitive identification documents were accessed. The data breach affected only information collected for analytics purposes through Mixpanel.” I get that this is the OpenAi answer, but it seems shallow, short, and perhaps that is all it is, but there is a second setting. Either the ‘provider’ who sounds like Promohub is giving us a larger pool of users, or some clever person might be insightful enough to combine the data of two pools of data and see what could be linked, because any person whose ‘shortcomings’ are exposed will seek other ways to hide the ‘shortfall’ and that is exactly what criminals are banking on. OK, this is speculation but if I had these two pools of data, I the first thing I would do is to seek a common ground (like an email address) and see what else I can find. This is how I found the weakness towards the Pentagon using the HOP+1 solution (which is wrongly analyzed by what some call AI) it was the first thing I did last month. And now again I am right. To be clear, the article on Funnel was about Funnel and as far as I know it was never transgressed upon. It was merely a fear I held and the fear was shown correctly at Mixpanel, not Funnel.

So whilst OpenAI correctly gives us “Information potentially accessed through Mixpanel may expose users to an increased risk of phishing or social engineering attempts.

Names, email addresses, and user identifiers were among the details exposed. OpenAI has advised all customers and users to remain vigilant for any suspicious or unsolicited communications that could be related to this incident. The company reiterated that it does not request sensitive information such as passwords, API keys, or verification codes via email, text, or chat. Users have also been encouraged to enable multi-factor authentication as an additional protective measure for their accounts.

And why am I now up in arms? Because I got the word through another source relating to another vendor and that implies that there are at least three data sources exposed and those with connected data will be at risk. As such there is little risk for OpenAI and its users if it is used correctly, but when is that the case and it falls back on the users, not on OpenAI. There is an old premise that I usually phrase. If 5 vendors have a 10% loss, the customer is at risk of losing 50% and that is what the danger is here. And when this is applied to 200,000,000 users, the losses could be close to astronomical. 

Now we can argue that there is no such risk, but that answer is coming mostly from people claiming to have no P#Hub account. Do they? I cannot tell, but they know if they have or not. And to also be clear, there is absolutely nothing wrong with having multi-factor authentication on any account you have. Those people are as I personally see it the least in danger.  But that is the setting that we are avoiding to look at. As I have said (way too often) that nonrepudiation is the way to go is showing to be the correct setting yet again. 

Have a great day all, only 11 hours until Friday, or in Hobbit terms Frododay, the day you have two breakfasts and three lunches until the beer o clock chimes.

Leave a comment

Filed under IT, Media, Science

Call it like it is

That is how I usually flow, it doesn’t make me loved or at times even appreciated, but that is me, oversimplifying problems on the handle, or is that off the handle? So whilst I was watching the BS wannabe influencers going all out on Elon Musk and Grok. There are two settings. The first is some have a case, but others do not, they are all out to get the maximum out of Grok (and its owner). I tend to take a less obvious course of action. You see, what everyone is ‘ignoring’ (intentional or not) is that AI doesn’t yet exist. So this is all DML and with an optional setting of LLM. And they are powerful tools, but they are programmed and that is what some want to avoid looking at. The programmer has no or little wealth and in law Torts tells us to go after the money and that was a fact long before Donoghue v Stevenson 1932 AC 562. And that setting is still used today, where these plaintiffs go after the money. Yet I am of a different stroke. I want the issue stopped. One thing to do this is to use the risen of nonrepudiation. You and only you could have done this. So we address that in the software, there are legitimate reasons and non-legitimate reasons and ALL have to submit there data and whilst that is done, (not unlike Meta) we capture all the data we can as such we have a batter of data and it is connected to (or imbedded) into the picture, but that is not enough. The provider keeps a copy of the image with a hidden watermark (an encryption technique I designed for other reasons) and that goes with every picture. It is there hidden and that is how nonrepudiation works. We might not prevent a lot, but now we can do something about it, not tomorrow, not next week or next year. But now. And the people who don’t want to do that, they can find another solution. But this fleecing Elon Musk and whatever company he has now needs to stop because those who want to go the ‘Torts’ way are part of the problem and not part of the solution. This is how I see it.

And lets be clear, some actions like ‘nudifying’ a famous person is wrong, even if you are the husband. And lets be clear, that act is also set to a 90% likely that you are not capturing the whole and correct image, so there is that too. And weirdly enough there are plenty of stars showing off their priceless pairs in fashion shows (example: Olivia Wilde) and they are ‘willing’ to do that, so save that picture for all its worth, but leave the others alone. Now, I get it, there is always a horny teenager that wants to show off that ‘he’ and ‘he’ alone was ‘given’ an image from his star and showing this off to his friends (who are likely using the same solution) and they have their own starlet, its like the Generation Alpha version on who has the biggest dick. 

And when they realise what they have done, that usually comes when their wives are giving birth to a daughter, reality hits. That is in 15 years and something needs to be done now, as such add nonrepudiation to this equation makes people wonder what to do. Some will wipe the image, but if the provider have the copy and connected data that will not be enough. When the hidden data is added to whatever that person gives is verified, we see the first red flags erupt and that is how the game is changed and those ‘privacy’ geeks out there, there is no privacy on nudifying images and as such the woman in question gets to have the right to prosecute and the maker of the image is to be prosecuted, not Elon Musk, Not Grok because there is a whole range of reasons why a filter was created, some are funny (like the Shrek faces on everyone in a video) and a few others, some filters are there to correct like remove dopey dodger photobombing away from a photo, but to remove clothing from a person is not. 

There is a likelihood of me missing out on a few items and that is fine but the setting I needed to give is here, we need to prosecute and shame the ones doing the deed, that is overlooked by pretty much all the writers of the anti-Grok brigade. None of them is holding these people to account and adding nonrepudiation is doing just that, taking care of the culprits and those mommies and daddies saying that they were merely kids having fun need to realise that there is no innocence in that setting, they failed as educators. 

So have a great day and consider what can happen when we go after the transgressors. 

Leave a comment

Filed under IT, Law, Media

The alternative way

I was contemplating the issues of Data privacy and particular the issues around US customs and their intrusion on your data issues. I had a few issues with that and as America is now the least reliable side of the matter I decided on a few techniques that might allow evasion of this. This morning I decided to look a few things up and I paused at Wired (at https://www.wired.com/2017/02/guide-getting-past-customs-digital-privacy-intact/) and I got to ‘How to Enter the US With Your Digital Privacy Intact’ where my suspicions were greeted with the ideas that had not been thought of. You see I am a great fan of ‘non-repudiation’ and that gave me the idea. What if you had the greatest of data insights? What if part of this locking and unlocking the data is for example your library card? This gave me two settings. The first is the magnetic strip, you see, you never think of this and it is what YOU make of it. The first setting is that a bank card has three tracks on a magnetic strip and they are for the most employed by banks when they need it (like ATM), but that setting could be altered for YOUR needs. The second part is what the card looks like. We can use these two elements to take a new page out of a book. 

So this leaves us the corporate way and the personal way. 

As a first, we get to copy the details you need (like a contact list, app list and personal lists). The second part becomes copying hat you need to a corporate server, encrypted data that is merely there, like a backup. So how is that dat secure? Well we get to the next stage, we take one or two cards you have on you. One with a magnetic strip, one as a card (could be business card, could be staff access card, or even your library card). You will keep it on you at all time. And third a personal access number (up to 12 digits) This gives you the setting of non-repudiation.

Now we travel to a ‘no one cares where’ place in America and you pass through customs, without phones or laptops. Just a regular joey. And in the American office you go to the security office and download the essentials. Now this merely makes sense for the people who needs this. So it is not for everyone in the first stage.

You pass the credits to a scanner and there is your data, your essential data that is. Kept safe from peeking eyes, and there is a growing concern that this is becoming more and more essential. We seemingly are ‘held’ to the dangers of YOUR data, but I reckon that America is now gaining an essential need of Digital IP that they can ‘embrace’ for their broke settings soon enough. Only for you to lose the fact that your IP was hijacked and no one knows who or where. But that is the setting that I am seeing now. They need IP to survive the next year and why should they be allowed your data? At present we see nearly everyone giving us “Chinese theft of American IP currently costs between $225 billion and $600 billion annually.” But I am not so sure. We get the ‘victims’ that Nokia and other brands, all whilst Huawei is far beyond what players like Nokia and others can produce. Is there IP theft? Yes, I know there is but from fashion brands like Gucci (it might be IP brands) but the markets are making a killing on $15000 Gucci bags, now for sale in the markets at $179 dollars. As I see it, the new settings allows for America to steal what they need to avoid having to not pay their interest bills. Now this is allegedly, I have no evidence. But the setting as I see it is quite real, as such I devised a way to avoid becoming a victim. The best option is to avoid America all together. Possible for me, but not for everyone and should I get that decently paying technical support job, then I will end up working for a US firm (hopefully avoiding the US altogether) but I am not holding my breath on that. 

As such I came up with this, a first in this task. There are two settings. The first is the data and the second is the hardware. The data I describes and I am a firm believer in non-repudiation. The hardware is different. You se, the movies have this nice clean crisp solution, but we are barely there. There was Ultraviolet (2006) where we see a foam phone printed and folded. We are already at that stage where we can do that. The printed foam cover is possible, there is still the setting of the battery, but that could be overcome. We merely set the LCD print board to include the display, you won’t have a camera setting, but that wouldn’t be needed. We get the setting that the devices go back to their original platform. So you have (if needed) a camera, a battery, and whatever more you need. The printed phone will interact with it all if needed. And wouldn’t it be nice if Huawei gives you all that? American stupidity forces China to give us the next need to innovate. That is irony the size of the Titanic (in action). 

You get one republican idiot forcing the world to turn to its life long enemy (President Nixon doesn’t agree with this statement), but that is for tomorrow. There is of course the real setting. Do we still need America? They are so in denial about what is real that the current tourism news is given to you by YouTube (optionally TikTok too). 

As such my mind went wandering into the data safety setting and as the article is giving you, others have preceded me. But for now, corporations will need to adapt that same policy before they lose the data they have and personal data is currency, one that America shouldn’t possess. As such I wonder at what point these firms will avoid America altogether, setting offices up in the UAE and Saudi Arabia. And now that it seems that India is turning to Russia and China for their oil, they are likely the first to change venue towards their BRICS partners. The EU and the Commonwealth are next. As such Canada, Australia and the United Kingdom will result into making these jumps, to what extent is impossible to predict. I reckon that it depends on how they are depending of America as such. It will be a fluctuating field. But what is true is that more and more people are seeing the hardships that American corporations faces. GM has shed nearly 20,000 staff from 2018 onwards. ‘Tesla to cut 14,000 jobs as Elon Musk aims to make carmaker ‘lean and hungry’’ and that is merely in the last year. In the last 2 months we were told that Microsoft is shedding 9000 jobs. That’s over 40,000 people in merely three corporations and when we seek harder answers. Only Yesterday did Fortune give us ‘Ray Dalio says ‘most people are silent’ because they’re afraid to talk about what’s really happening with the U.S. economy’, I saw this setting months ago and the media is avoiding the issues as they are allegedly being held hostage by advertisement revenues. We aren’t given the real deals and I am not sure where the real deal stands. According to the media the setting is ‘US economy has likely stalled, with 50% risk of recession in 2 years, says Barclays’ in the meantime we are also given ‘US Economy: Jobless Claims Rise, Trade Gap Widens’ and ‘Stagflation & Recession Risks Loom Large Over US Economy’ with sources like UBS (allegedly relying on hard data), UBS gives us a 93% recession risk. If this is true, how does the Barclay setting make sense? I get it, talking about issues in two years time doesn’t mean that the risk is low in the next few months (it could be 100% by November). UBS gave three red flags, so there are all indicators. And the setting of Stagflation becomes the ‘norm’ Which gives us that growth is slowing, but the prices are rising. I am merely voicing what others are saying as I am not an economist. I reckon this is the second bullet that Canada is seemingly dodging as they elected Mark Carney (formerly Marky Mark of the British Bank). I’ll take his word over President Trump’s claims any day of the week. Moody’s speaker Mark Zandi gives us “we aren’t in a recession, but on the precipice of this recession”, OK, I am willing to go along with that, but merely as it seems sincere and I have no economic degree (Mark Zandi apparently has a stack of them). The problem is that these two sources highlight a rather large issue and the media is skating around them, they are avoiding the issue to get their alleged hands on advertisement revenue. It becomes an issue to see the real data and that is where you want to pass your IP through the borders? Not in my lifetime. I am likely to get a nice bonus if I just hand my IP to China, which sounds a lot more promising than trusting that America will do right by me. According to Zandi a third of America is already in recession or close to it and when we add the Tourism numbers I am seeing a grim picture, one that makes me plan my next vacation (whenever I can afford that one) on Yas Island in Abu Dhabi, UAE and not in America (ever). The Bank of America is blaming this on Tariffs (what a surprise). As such you might wander what one thing has to do with the other. The principle we are currently seeing at the America borders is the identification of HVT’s (High Value Targets), the second setting is IP. America needs trillions and one way to get these is by hijacking IP (making America the sole distributor of YOUR IP) Is that rally the way to go? Why don’t we ask the EU, Commonwealth and China on that issue? I think this is the one case where these three sides will speak (agree) in unison and I saw the setting coming over a decade ago and it is all over my blog. So why wasn’t the media this informative? I will let you decide.

But believe me that your IP and your personal DATA require protection and in a non-repudiating way. As such my mind went tinkering to what is possible and securing and keeping your data online was a first stop. I call it alternative way and that has a way of becoming the only or main way soon enough. 

Have a great day, I’m now a mere 90 minutes from breakfast.

Leave a comment

Filed under Finance, IT, Media, movies, Politics, Science, Tourism