Apple and Google announced in short succession that they will be
turning on encryption by default for all of their devices and the
reaction from law enforcement (and some press elements who pander to
them) is nothing short of incendiary. The nexus of national security,
organised crime, think-of-the-children and technology concpepts barely
understood by laypeople is fascinating to watch but one thing stands out
that makes this posturing baffling: Law enforcement already knows what
the limitations are of modern cryptography on mobile devices, and
they're borderline lying when they decry this latest move.
Encryption on Android devices at least is very strong relying on the deep structures in the Linux kernel and associated tools to create and manage encrypted storage devices. Apple have improved things a bit
in iOS8 but they've a ways to go. The announcements change nothing
about the capabilities of these devices that law enforcement don't
already worry about but that hasn't stopped them from launching a PR
push in an attempt to show they're actually doing something - anything -
to tackle the problems under their purview.
There is a
serious flaw in this. The announcements merely indicate the starting
position of the state of a new device, in that existing methods for
securing the device will be turned on by default. Any savvy user who
cares for their privacy (and unscrupulous ones probably more so) will
have long ago figured out how to activate these features. In the grand
tradition of DRM, where normal users were left exposed or under-served
while underhanded consumers found the best release schedules by simply
downloading as they wanted, viewing on devices that pleased them, and
avoided limitations like being forced to watch ads or in formats
sub-optimal; regular users of mobile devices were left woefully
underprotected despite the facility being there to enhance their device
security for the good while the security conscious (and I will keep
admitting not always those with high-minded intentions) could exploit
these features for their own protection.
Law enforcement knows this. Their hand-waving (and predictable, think-of-the-childrenness)
responses are at best facile and at worst outright lies. If they did
not know these devices were already capable of encryption then they are
not competent, and if not but think this default setting changes the
landscape for law enforcement then they are certainly dishonest -
someone choosing to hide data from law enforcement already has those
tools. These decisions are security for the rest of us.
This
is not new. I used to have respect for Dianne Feinstein, the present
(as of October 2014) chair of the US Senate Select Committee on
Intelligence. She once remarked that Edward Snowden should have come
forward with his concerns privately, even directly to her, rather than
disclosing his information to the public; that this would still have
resulted in the reforms and protections now underway at the NSA, CIA and
other intelligence bodies in the US. Again, either incompetent in
thinking the level of scandal this information would cause would be
outweighed to safeguard individual rights in an environment of total
secrecy (it won't) or posturing for effect and misleading the public
about what she knows to be a false tale of her and her colleagues'
desires to curtail intelligence gathering if it infringes those rights
(it would never). Cue outrage when the CIA is found to be violating
those rights, this time hers. She cannot be taken seriously.
Neither
can any government official who says that the two largest smartphone OS
vendors are hurting law enforcement because of a non-technical change.
They are posturing, lying or showing incompetence (at best because of
bad advice, but unlikely). They would like to intentionally leave us
exposed to data theft, privacy violations based on the flimsiest of
evidence, insufficient safeguards for that data and abuse by criminals
who use government and law enforcement's own tools and methods.
I
don't blame them for this as it's their job to pretend we're all at
risk, that their job is hard, and that we should trust them. I know this
and can't fault them (too much) for it.
My true outrage is with media outlets that don't just blindly parrot their talking points, but add on their own ill-informed scaremongering flourishes.
None of these articles mention the present availability of these
techniques, and in the omission imply that this is a new level of
crime-friendly protection with no benefit for ordinary users. If these
tech journalists stand by their stories and insist government needs to
take action to cripple security or mandate backdoors, history has a lesson for you, as do real tech journalists.
A few rambling comments on Enterprise Architecture, Infrastructure, trends and pitfalls. I'm a keen follower of Linux and Free and Open Source Software (FOSS) while being a solidly Microsoft-focused design and consulting professional, and I hope this blog helps find a happy medium between the two. Please do leave a comment or two on any articles you like (or don't).
Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts
Monday, 13 October 2014
Monday, 7 October 2013
How to Make Your Customers Feel Like Meat in a Tube
Few things annoy me more than web-based forms for initiating customer contact. My experience of them ranges from poor to dismal, and even when I point out that I expect companies to fail in their response I am rarely surprised by brilliance (or even adequacy).
The first problem with these forms is actually the result: Your enquiry ends up not as an e-mail for a person, but a record in a database. Some forms are worse than others in betraying this, but if you even have to select your company size or decision-making company role you can be sure you're being slotted into a Customer Spamming Service machine.
From there, around four out of five responses make no reference to your original query. Unlike e-mail, where you can save your initial contact in your Sent folder, and typically hiting Reply generates a new mail on top of your original one, the first response you receive almost always has no history, so you're left scratching your head wondering if you really forgot to mention your product's model number, even when you remember having to look up the unicode for the unnecessarily accented é in the product name.Whether a human typed out your reply, selected a form response or some machine logic matched your keywords to information already available in the FAQ, I will offer odds, without knowing who the company is, that the original question is not included for reference.
It's a pain to fill in forms like these repeatedly for each individual question, so you might be tempted to put more than one question in your query. Beware traveller - the company will choose which answer most closely matches their prepared form responses and send that to you, regardless of the amount of prominence you try to give to the one you really need answered first.
Errors on the form? How about not residing in the US so skipping the "state" field, only to be told the field is mandatory. OK, I live in Wyoming, Netherlands. Ah, the form now tells me having a state filled in outside the US in an invalid choice? Check the dropdown - yep, only US states available and no way to not pick one. Don't bother complaining about the logic in your actual request - you see, the people choosing stock responses to send that don't adequately deal with your query, they're in no way connected with the end of the sausage maker that ruins your customer contact experience from the start. They just turn the handle.
While sending an enquiry to a prominent software vendor, I happened to have NoScript turned on and found the form broken beyond use. This is simply not justifiable. Oh well, I'll enable the site for JS, but lo! The form fails to complete again. This time it is because a piece of code from a marketing firm has not arrived. So prominent, it even has the name market in its' name - answering my question vs completing my digital profile for a third party: Which do you think they care about most?
All this from an IT Security company, that sells products to control mobile phone policies to stop users from doing things like installing untrusted software that sends their data to unknown parties, without telling you.
Why am I running a marketing company's JavaScript to collect my personal information to initiate an evaluation of your products?
I am just meat in a sausage to you people, aren't I?
The first problem with these forms is actually the result: Your enquiry ends up not as an e-mail for a person, but a record in a database. Some forms are worse than others in betraying this, but if you even have to select your company size or decision-making company role you can be sure you're being slotted into a Customer Spamming Service machine.
From there, around four out of five responses make no reference to your original query. Unlike e-mail, where you can save your initial contact in your Sent folder, and typically hiting Reply generates a new mail on top of your original one, the first response you receive almost always has no history, so you're left scratching your head wondering if you really forgot to mention your product's model number, even when you remember having to look up the unicode for the unnecessarily accented é in the product name.Whether a human typed out your reply, selected a form response or some machine logic matched your keywords to information already available in the FAQ, I will offer odds, without knowing who the company is, that the original question is not included for reference.
It's a pain to fill in forms like these repeatedly for each individual question, so you might be tempted to put more than one question in your query. Beware traveller - the company will choose which answer most closely matches their prepared form responses and send that to you, regardless of the amount of prominence you try to give to the one you really need answered first.
Errors on the form? How about not residing in the US so skipping the "state" field, only to be told the field is mandatory. OK, I live in Wyoming, Netherlands. Ah, the form now tells me having a state filled in outside the US in an invalid choice? Check the dropdown - yep, only US states available and no way to not pick one. Don't bother complaining about the logic in your actual request - you see, the people choosing stock responses to send that don't adequately deal with your query, they're in no way connected with the end of the sausage maker that ruins your customer contact experience from the start. They just turn the handle.
While sending an enquiry to a prominent software vendor, I happened to have NoScript turned on and found the form broken beyond use. This is simply not justifiable. Oh well, I'll enable the site for JS, but lo! The form fails to complete again. This time it is because a piece of code from a marketing firm has not arrived. So prominent, it even has the name market in its' name - answering my question vs completing my digital profile for a third party: Which do you think they care about most?
All this from an IT Security company, that sells products to control mobile phone policies to stop users from doing things like installing untrusted software that sends their data to unknown parties, without telling you.
Why am I running a marketing company's JavaScript to collect my personal information to initiate an evaluation of your products?
I am just meat in a sausage to you people, aren't I?
Labels:
CRM,
Customer Service,
Infosec,
JavaScript,
mobile,
Privacy
Subscribe to:
Posts (Atom)