Stationary section mostly ready

There's some stuff to augment; mainly, IoT like smart TVs.

* slides.org (Stationary): Mostly ready.
* sapsf.bib (insecam): Change entry date to match screenshot.
* images/insecam-ss.png: insecam.org screenshot.
* images/tp/remote-list: Add ACLU tracked paper title page image.
* images/tp/SHA256SUM: Include hash of new image.
master
Mike Gerwitz 2017-03-19 23:58:29 -04:00
parent 4a30b85b20
commit e3d8a282e7
5 changed files with 92 additions and 59 deletions

Binary file not shown.

After

Width:  |  Height:  |  Size: 235 KiB

View File

@ -6,6 +6,7 @@ ca51e8ba23a87140b1f2cf573d4761df888d7f939947823c695004ce5d3f31f7 replicant.png
4b0050a377af1fcd72f14863408eef44d40e7ba6fe31e2121ec7c3a51781a752 alpr-capture.png 4b0050a377af1fcd72f14863408eef44d40e7ba6fe31e2121ec7c3a51781a752 alpr-capture.png
31597ba3731e6eccf2e68ae8b91ad25b2e6e4685814e723333d9ea1d2579b635 alpr-pips.png 31597ba3731e6eccf2e68ae8b91ad25b2e6e4685814e723333d9ea1d2579b635 alpr-pips.png
e7029f70524f420ef32044aeae8280434d5b03ddbab4e90188409a93597c0726 sf-cameras.jpg e7029f70524f420ef32044aeae8280434d5b03ddbab4e90188409a93597c0726 sf-cameras.jpg
67483c5d78b168782b787765284937b8a269ae6d87d4effbb58f4a7d603d8997 aclu-tracked.jpg
9edddcac31bbb09e4ba9f6fea5d36e5298ec65ce88d4c015121fc27edd466947 silverpush-logo.png 9edddcac31bbb09e4ba9f6fea5d36e5298ec65ce88d4c015121fc27edd466947 silverpush-logo.png
cfda12117815c35bfc51266d9e8227b1645dcd5ffe054c4ae9922e75595f09b9 ga-dashboard.png cfda12117815c35bfc51266d9e8227b1645dcd5ffe054c4ae9922e75595f09b9 ga-dashboard.png
d905d3b378daea4c002c873a4ad8192246959cb6df6fb470e29ade9f2b2354c9 piwik-dashboard.png d905d3b378daea4c002c873a4ad8192246959cb6df6fb470e29ade9f2b2354c9 piwik-dashboard.png

View File

@ -6,6 +6,7 @@ alpr-mounted.png https://web.archive.org/web/20170318173251/https://www.eff.org/
alpr-capture.png https://web.archive.org/web/20170318173346/https://www.eff.org/files/2015/10/20/paxton_captures.png alpr-capture.png https://web.archive.org/web/20170318173346/https://www.eff.org/files/2015/10/20/paxton_captures.png
alpr-pips.png https://web.archive.org/web/20170318173427/https://www.eff.org/files/2015/10/15/pipscam9_redacted.png alpr-pips.png https://web.archive.org/web/20170318173427/https://www.eff.org/files/2015/10/15/pipscam9_redacted.png
sf-cameras.jpg https://web.archive.org/web/20170318173846/https://cbssanfran.files.wordpress.com/2015/09/san_francisco_surveillance_cameras_092315.jpg sf-cameras.jpg https://web.archive.org/web/20170318173846/https://cbssanfran.files.wordpress.com/2015/09/san_francisco_surveillance_cameras_092315.jpg
aclu-tracked.jpg https://web.archive.org/web/20170320025735/https://www.aclu.org/sites/default/files/styles/content_area_full_width/public/field_media_media_image/web15-feature-alpr-report-580x535.jpg?itok=n_JYZGN5 -crop 410x535+170+0
silverpush-logo.png https://web.archive.org/web/20160623032522/http://1.bp.blogspot.com/-r9WGkxWE3RI/Vk9wK_RisSI/AAAAAAAAAy0/ZydFsogCrnc/s640/silverpush.png silverpush-logo.png https://web.archive.org/web/20160623032522/http://1.bp.blogspot.com/-r9WGkxWE3RI/Vk9wK_RisSI/AAAAAAAAAy0/ZydFsogCrnc/s640/silverpush.png
ga-dashboard.png https://web.archive.org/web/20170315055350/https://www.google.com/analytics/images/analytics/features/hero_1x.png -crop 580x370+115+35 ga-dashboard.png https://web.archive.org/web/20170315055350/https://www.google.com/analytics/images/analytics/features/hero_1x.png -crop 580x370+115+35
piwik-dashboard.png https://web.archive.org/web/20170310025254/https://piwik.org/wp-content/themes/piwik/assets/img/piwiklaptop.png -crop 730x520+225+85 piwik-dashboard.png https://web.archive.org/web/20170310025254/https://piwik.org/wp-content/themes/piwik/assets/img/piwiklaptop.png -crop 730x520+225+85

View File

@ -264,7 +264,7 @@
@online{insecam, @online{insecam,
title = {Insecam - World biggest online cameras directory}, title = {Insecam - World biggest online cameras directory},
url = {http://insecam.org}, url = {http://insecam.org},
urldate = {2017-03-12}, urldate = {2017-03-19},
annotation = {Load the HTTP (non-HTTPS) site, otherwise mixed content is annotation = {Load the HTTP (non-HTTPS) site, otherwise mixed content is
blocked and thumbnails will not work.} blocked and thumbnails will not work.}
} }

View File

@ -519,20 +519,21 @@ So even with Replicant,
** REVIEWED Stationary [0/6] ** AUGMENT Stationary [5/5]
*** REVIEWED Introduction [0/1] :B_ignoreheading: *** READY Introduction [1/1] :B_ignoreheading:
:PROPERTIES: :PROPERTIES:
:BEAMER_env: ignoreheading :BEAMER_env: ignoreheading
:END: :END:
**** REVIEWED Introduction :B_fullframe: **** READY Introduction :B_fullframe:
:PROPERTIES: :PROPERTIES:
:DURATION: 00:00:15 :DURATION: 00:00:15
:BEAMER_env: fullframe :BEAMER_env: fullframe
:END: :END:
#+BEGIN_QUOTE #+BEGIN_QUOTE
``If you've got nothing to hide, you've got nothing to \large
fear.''\cite{rosen:naked,solove:nothing-to-hide,metro:goebbels} ``If you've got nothing to hide, you've got nothing
to\nbsp{}fear.''\cite{rosen:naked,solove:nothing-to-hide,metro:goebbels}
#+END_QUOTE #+END_QUOTE
#+BEGIN_COMMENT #+BEGIN_COMMENT
@ -545,8 +546,8 @@ There's certain things that are nearly impossible to avoid.
This quote. We'll get back to it. This quote. We'll get back to it.
#+END_COMMENT #+END_COMMENT
*** REVIEWED Surveillance Cameras [0/6] *** READY Surveillance Cameras (CCTV) [5/5]
**** REVIEWED Unavoidable Surveillance **** READY Unavoidable Surveillance
:PROPERTIES: :PROPERTIES:
:DURATION: 00:00:10 :DURATION: 00:00:10
:END: :END:
@ -567,7 +568,7 @@ Traffic cameras.
Cameras on streets to deter crime. Cameras on streets to deter crime.
#+END_COMMENT #+END_COMMENT
**** REVIEWED Private Cameras in Plain View; Tinerloin, SF **** READY Private Cameras in Plain View; Tinerloin, SF
:PROPERTIES: :PROPERTIES:
:DURATION: 00:00:30 :DURATION: 00:00:30
:END: :END:
@ -581,7 +582,7 @@ Cameras on streets to deter crime.
#+BEGIN_QUOTE #+BEGIN_QUOTE
``The idea that you can sort of meet in a public place and quietly have a ``The idea that you can sort of meet in a public place and quietly have a
conversation that were sort of accustomed to from spy movies, that is conversation that were sort of accustomed to from spy movies, that is
really not realistic anymore,'' ---Nadia Kayyali, EFF really not realistic anymore,'' ---Nadia Kayyali, EFF\cite{cbs:sf-smile}
#+END_QUOTE #+END_QUOTE
#+BEGIN_COMMENT #+BEGIN_COMMENT
@ -589,7 +590,7 @@ This is a map of private surveillance cameras in plain view around SF's
Tenderloin neighborhood. Tenderloin neighborhood.
Obviously your city or town might be different. Obviously your city or town might be different.
Could be worse, even. Could be worse, even.
And again, these are just the ones that the DA's office found in And these are just the ones that the DA's office found in
/plain view/! /plain view/!
According to them, According to them,
@ -601,9 +602,9 @@ Alright, so a bunch of private entities have you on camera;
#+END_COMMENT #+END_COMMENT
**** REVIEWED Access to Data **** READY Access to Data
:PROPERTIES: :PROPERTIES:
:DURATION: 00:01 :DURATION: 00:00:45
:END: :END:
- <1-> Data can be obtained with a warrant or subpoena - <1-> Data can be obtained with a warrant or subpoena
@ -639,7 +640,7 @@ The best form of privacy is to avoid having the data be collected to begin
#+END_COMMENT #+END_COMMENT
**** REVIEWED Domain Awareness System (Intro) :B_fullframe: **** READY Domain Awareness System (Intro) :B_fullframe:
:PROPERTIES: :PROPERTIES:
:DURATION: 00:00:30 :DURATION: 00:00:30
:BEAMER_env: fullframe :BEAMER_env: fullframe
@ -648,10 +649,11 @@ The best form of privacy is to avoid having the data be collected to begin
#+BEGIN_CENTER #+BEGIN_CENTER
#+BEGIN_LATEX #+BEGIN_LATEX
\only<1>{What if all those cameras---including private---were connected?} \only<1>{What if all those cameras---including private---were connected?}
\only<2>{NYPD---Domain Awareness System\incite{nyc:pspg}} \only<2>{\Huge NYPD\par Domain Awareness System\incite{nyc:pspg}}
\only<3>{ \only<3>{
#+END_LATEX #+END_LATEX
#+BEGIN_QUOTE #+BEGIN_QUOTE
\large
Although NYPD documents indicate that the system is specifically designed Although NYPD documents indicate that the system is specifically designed
for anti-terrorism operations, any incidental data it collects ``for a for anti-terrorism operations, any incidental data it collects ``for a
legitimate law enforcement or public safety purpose'' by DAS can be legitimate law enforcement or public safety purpose'' by DAS can be
@ -668,14 +670,14 @@ Let's talk about the NYPD's Domain Awareness System.
It was designed in part from the usual unjustifiable and irrational response It was designed in part from the usual unjustifiable and irrational response
to terrorism threats after 9/11. to terrorism threats after 9/11.
But any ``incidental data'' can be used by law enforcement. But any data this system collects for ``legtimate'' law enforcement or
Yeah, sounds familiar; business as usual. public safety purposes can be used against you.
#+END_COMMENT #+END_COMMENT
**** REVIEWED Domain Awareness System **** READY Domain Awareness System
:PROPERTIES: :PROPERTIES:
:DURATION: 00:01 :DURATION: 00:01:15
:END: :END:
- <1-> Partnership between the NYPD and Microsoft at a cost of $230M - <1-> Partnership between the NYPD and Microsoft at a cost of $230M
@ -696,7 +698,7 @@ The Domain Awareness System is a partnership between Microsoft and the NYPD.
It's mammoth. It's mammoth.
It's pretty amazing---it's like science fiction. It's pretty amazing---it's like science fiction.
But I care about privacy, But I care about privacy,
so instead I'm going to use adjectives like ``Orwellian''. so instead I'm going to use adjectives like ``Orwellian'' and ``Kafkaesque''.
It contains over six thousand security cameras, It contains over six thousand security cameras,
over two-thirds of which are private closed-circuit cameras. over two-thirds of which are private closed-circuit cameras.
@ -725,29 +727,39 @@ In fact,
#+END_COMMENT #+END_COMMENT
*** REVIEWED Driver Surveillance *** READY Driver Surveillance [3/3]
**** REVIEWED Automated License Plate Readers (ALPRs) **** READY Automated License Plate Readers (ALPRs)
:PROPERTIES: :PROPERTIES:
:DURATION: 00:00:30 :DURATION: 00:00:30
:END: :END:
***** Images
:PROPERTIES:
:BEAMER_col: 0.50
:END:
#+BEGIN_CENTER #+BEGIN_CENTER
#+BEAMER: \only<1>{ #+BEAMER: \only<1>{
#+ATTR_LATEX: :height 1.5in [[./images/tp/alpr-mounted.png]]\par\incite{eff:alpr}
[[./images/tp/alpr-mounted.png]]\incite{eff:alpr}
#+BEAMER: } #+BEAMER: }
#+BEAMER: \only<2>{ #+BEAMER: \only<2>{
#+ATTR_LATEX: :height 1.5in [[./images/tp/alpr-capture.png]]\par\incite{eff:alpr}
[[./images/tp/alpr-capture.png]]\incite{eff:alpr} #+BEAMER: }
#+BEAMER: \only<3>{
#+ATTR_LATEX: :height 2in
[[./images/tp/aclu-tracked.jpg]]\par\incite{aclu:tracked}
#+BEAMER: } #+BEAMER: }
#+END_CENTER #+END_CENTER
***** Summary
:PROPERTIES:
:BEAMER_col: 0.50
:END:
- Scan passing cars' license plates\cite{aclu:tracked,eff:alpr} - Scan passing cars' license plates\cite{aclu:tracked,eff:alpr}
- Produce alphanumeric representation with timestamp and photograph - Produce alphanumeric representation with timestamp and photograph
#+BEGIN_COMMENT #+BEGIN_COMMENT
So before we leave the topic of government surveillance for a little bit, I want to talk about a couple issues related to driver surveillance.
I want to talk about a couple issues related to driver surveillance.
These things are a widespread, nasty threat to privacy, These things are a widespread, nasty threat to privacy,
and they don't need a sophisticated Domain Awareness System to deploy. and they don't need a sophisticated Domain Awareness System to deploy.
@ -765,7 +777,7 @@ The ACLU has an excellent report on it,
#+END_COMMENT #+END_COMMENT
**** REVIEWED Automatic Toll Readers **** READY Automatic Toll Readers
:PROPERTIES: :PROPERTIES:
:DURATION: 00:00:30 :DURATION: 00:00:30
:END: :END:
@ -773,7 +785,7 @@ The ACLU has an excellent report on it,
- <1-> In the North-East we have E-ZPass (RFID)\cite{w:ezpass} - <1-> In the North-East we have E-ZPass (RFID)\cite{w:ezpass}
- <1-> Golden Gate Bridge requires FasTrack or plate-based - <1-> Golden Gate Bridge requires FasTrack or plate-based
- <2-> /But/ they provide an option for an anonymous FasTrack account - <2-> /But/ they provide an option for an anonymous FasTrack account
using cash\cite{goldengate:anon} using cash\cite{goldengate:anon}
- <2-> (Granted, you're still captured by an ALPR) - <2-> (Granted, you're still captured by an ALPR)
- <3-> Routinely used by law enforcement\cite{baynews:fastack-data} - <3-> Routinely used by law enforcement\cite{baynews:fastack-data}
- <4-> They're not very secure, - <4-> They're not very secure,
@ -799,7 +811,7 @@ And they have their security issues;
#+END_COMMENT #+END_COMMENT
**** REVIEWED Akin To GPS Tracking **** READY Akin To GPS Tracking
:PROPERTIES: :PROPERTIES:
:DURATION: 00:00:30 :DURATION: 00:00:30
:END: :END:
@ -826,20 +838,21 @@ But it's a useful comparison against precedent.
#+END_COMMENT #+END_COMMENT
*** REVIEWED Internet of Things [0/7] *** AUGMENT Internet of Things [7/7]
**** REVIEWED Internet-Connected Cameras **** READY Internet-Connected Cameras :B_fullframe:
:PROPERTIES: :PROPERTIES:
:DURATION: 00:00:45 :DURATION: 00:00:35
:BEAMER_env: fullframe
:END: :END:
#+BEGIN_CENTER #+BEGIN_CENTER
#+BEAMER: \only<1>{Cameras used to be only physically accessible} \Huge
#+BEAMER: \only<1>{Cameras used to need physical access}
#+BEAMER: \only<2>{Today\ldots not always so much} #+BEAMER: \only<2>{Today\ldots not always so much}
#+END_CENTER #+END_CENTER
#+BEGIN_COMMENT #+BEGIN_COMMENT
In the past, these cameras were "closed-circuit"--- In the past, these cameras were on their own segregated networks.
they were on their own segregated network.
You'd _have_ to subpoena the owner or get a warrant, You'd _have_ to subpoena the owner or get a warrant,
or otherwise physically take the tape. or otherwise physically take the tape.
@ -849,20 +862,20 @@ It might be intentional---to view the camera remotely or on a device---or it
may just be how the camera is set up by default. may just be how the camera is set up by default.
Well... Well...
Let's expand our pool of cameras a bit. It's not just businesses that use Internet-connected cameras.
Because it's not just businesses that use Internet-connected cameras. They're also popular among individuals for personal/home use so that they
They're also popular among individuals for personal/home use. can view them on their smart phones and elsewhere.
Home security systems. Like home security systems.
Baby monitors. Baby monitors.
#+END_COMMENT #+END_COMMENT
**** REVIEWED The ``S'' In IoT Stands For ``Security'' **** READY The ``S'' In IoT Stands For ``Security''
:PROPERTIES: :PROPERTIES:
:DURATION: 00:01 :DURATION: 00:00:50
:END: :END:
- <1-> Shodan---IoT search engine\cite{shodan} - <1-> Shodan---IoT search engine\cite{shodan}
- <2-> You'll also find other interesting things. Secure your databases. - <2-> You'll also find other things. Secure your databases.
\cite{krebs:mongodb} \cite{krebs:mongodb}
- <2-> Can search for specific devices - <2-> Can search for specific devices
- <2-> If you are vulnerable, someone will find you - <2-> If you are vulnerable, someone will find you
@ -895,15 +908,32 @@ Followed by "Cams", "Netcam", and "default password".
#+END_COMMENT #+END_COMMENT
**** REVIEWED Who's Watching? **** READY Who's Watching?
:PROPERTIES: :PROPERTIES:
:DURATION: 00:00:15 :DURATION: 00:00:20
:END:
***** Screenshot
:PROPERTIES:
:BEAMER_col: 0.30
:END:
#+BEGIN_CENTER
#+ATTR_LATEX: :height 2.25in
[[./images/insecam-ss.png]]\par\incite{insecam}
#+END_CENTER
***** Summary
:PROPERTIES:
:BEAMER_col: 0.70
:END: :END:
- Insecam is a directory of Internet-connected surveillance - Insecam is a directory of Internet-connected surveillance
cameras\cite{insecam} cameras\cite{insecam}
- Live video feeds (browser connects directly to cameras) - Live video feeds (browser connects directly to cameras)
#+BEGIN_COMMENT #+BEGIN_COMMENT
But Shodan isn't the only thing out there. But Shodan isn't the only thing out there.
Anyone heard of Insecam? Anyone heard of Insecam?
@ -916,10 +946,10 @@ I can tell you personally that you feel like a scumbag looking at the site.
#+END_COMMENT #+END_COMMENT
**** REVIEWED Insecam Example 1 :B_fullframe: **** READY Insecam Example 1 :B_fullframe:
:PROPERTIES: :PROPERTIES:
:BEAMER_env: fullframe :BEAMER_env: fullframe
:DURATION: 00:00:30 :DURATION: 00:00:40
:END: :END:
#+BEGIN_CENTER #+BEGIN_CENTER
@ -957,10 +987,10 @@ Somewhat cool, even.
Let's get a little more personal. Let's get a little more personal.
#+END_COMMENT #+END_COMMENT
**** REVIEWED Example 2 :B_fullframe: **** READY Example 2 :B_fullframe:
:PROPERTIES: :PROPERTIES:
:BEAMER_env: fullframe :BEAMER_env: fullframe
:DURATION: 00:01 :DURATION: 00:01:00
:END: :END:
#+BEGIN_CENTER #+BEGIN_CENTER
@ -1002,14 +1032,14 @@ These people are unaware.
And these manufactuers set them up for this. And these manufactuers set them up for this.
Even if you can't find a camera on this site, Even if you can't find a camera on this site,
Shodan might have indexed it Shodan might have indexed it;
just connect. just connect.
#+END_COMMENT #+END_COMMENT
**** REVIEWED ALPRs Wide Open **** READY ALPRs Wide Open
:PROPERTIES: :PROPERTIES:
:DURATION: 00:00:15 :DURATION: 00:00:20
:END: :END:
#+BEGIN_CENTER #+BEGIN_CENTER
@ -1035,9 +1065,9 @@ In both cases,
#+END_COMMENT #+END_COMMENT
**** REVIEWED Biometrics **** READY Biometrics
:PROPERTIES: :PROPERTIES:
:DURATION: 00:00:45 :DURATION: 00:01:00
:END: :END:
- <1-> Humans no longer need to scour video - <1-> Humans no longer need to scour video
@ -1070,7 +1100,7 @@ Don't have a face?
You can also be identified by your gait. You can also be identified by your gait.
No gait? No gait?
Facebook famously got even creepier by saying it could recognize people by Facebook famously got even creepier by saying it could recognize people by
their dress, posture, and hair, without seeing their face. their dress, posture, and hair, without even seeing their face.
Your fingerprints and iris data can even be extracted from high-resolution Your fingerprints and iris data can even be extracted from high-resolution
photos; photos;
@ -1081,8 +1111,8 @@ We'll come back to it.
#+END_COMMENT #+END_COMMENT
*** REVIEWED Social Media [0/1] *** READY Social Media [1/1]
**** REVIEWED Collateral Damage **** READY Collateral Damage
:PROPERTIES: :PROPERTIES:
:DURATION: 00:00:45 :DURATION: 00:00:45
:END: :END:
@ -1112,6 +1142,7 @@ What they're actually doing is inflicting collateral damage.
If I'm off in the background when you take a picture of your friends in the If I'm off in the background when you take a picture of your friends in the
foreground, foreground,
I'm still in the photo. I'm still in the photo.
Just something to consider when taking photos of others..
#+END_COMMENT #+END_COMMENT